Network detection method and device and related equipment

By acquiring network data information from cloud servers through target detection equipment and performing network isolation analysis, combined with automated command execution component verification, the problem of high resource consumption and low efficiency in detecting network isolation of cloud servers is solved, achieving efficient and accurate network isolation detection.

CN121056162APending Publication Date: 2025-12-02TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410698124.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-05-30
Publication Date
2025-12-02

AI Technical Summary

Technical Problem

In existing technologies, when cloud servers need to detect network isolation through their own installed agent programs, it leads to excessive consumption of computing resources and low detection efficiency, affecting the execution of other services.

Method used

Network isolation analysis is performed by acquiring network data information from cloud servers through target detection equipment, avoiding detection on cloud servers. Analysis is conducted using initial network configuration information and traffic mirroring data, and verification is performed in conjunction with automated command execution components.

Benefits of technology

It reduces the impact of network isolation detection on cloud servers, improves detection efficiency and accuracy, reduces interference with business operations, and avoids inaccurate analysis caused by users deploying additional security measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121056162A_ABST
    Figure CN121056162A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network detection method and device and related equipment, and can be applied to the technical field of data processing. The method comprises the following steps: acquiring first network data information of a first cloud server and second network data information of a second cloud server; both the first network data information and the second network data information comprise initial network configuration information configured by the cloud platform service equipment; based on initial network configuration information in the first network data information and initial network configuration information in the second network data information, performing network isolation analysis on the first cloud server and the second cloud server to obtain a first type of network isolation analysis result; and if the first type of network isolation analysis result indicates that network connection exists between the first cloud server and the second cloud server, performing network connection verification on the first cloud server and the second cloud server to obtain a network verification result. By adopting the embodiment of the invention, the efficiency of network isolation detection can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology, and in particular to network detection methods, apparatus and related equipment. Background Technology

[0002] Currently, the network isolation between yourself and other cloud servers (e.g., server X2) with the agent program installed can be detected through the agent program installed on the cloud server (e.g., server X1).

[0003] However, the inventors discovered in practice that both cloud servers (e.g., server X1 and server X2) require their own installed agent programs to perform network isolation detection. For example, cloud server X1 needs to send query commands to other cloud servers X2 through its installed agent program to check the isolation between cloud server X1 and cloud server X2. This means that once a server (e.g., server X1) needs to detect whether it has network isolation with a large number of other servers, the agent program on server X1 will send a large number of query commands to a large number of cloud servers, and may also receive a large number of query commands from cloud servers, before finally determining which servers it is currently network isolated from. Obviously, this will consume and occupy server X1's computing resources excessively to a certain extent. This will not only affect the execution of other services on the cloud server, but also reduce the efficiency of network isolation detection for cloud servers. Summary of the Invention

[0004] This application provides a network detection method, apparatus, and related equipment. The network data information of the cloud server can be obtained by a target detection device different from the cloud server for network isolation analysis. This eliminates the need to perform network isolation detection on the cloud server, thereby reducing the impact of network isolation detection on the cloud server and improving the efficiency of network isolation detection.

[0005] One embodiment of this application provides a network detection method, which is executed by a target detection device for network isolation detection of N cloud servers, including a first cloud server and a second cloud server. The method includes:

[0006] Obtain first network data information of the first cloud server and second network data information of the second cloud server; both the first network data information and the second network data information include initial network configuration information configured by cloud platform service devices associated with N cloud servers;

[0007] Based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, network isolation analysis is performed on the first cloud server and the second cloud server to obtain the first type of network isolation analysis results;

[0008] Wherein, the initial network configuration information in the first network data information is the first initial network configuration information, and the initial network configuration information in the second network data information is the second initial network configuration information; the first initial network configuration information includes the first network connection information of the first private network to which the first cloud server belongs; the second initial network configuration information includes the second network connection information of the second private network to which the second cloud server belongs.

[0009] Based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, network isolation analysis is performed on the first cloud server and the second cloud server to obtain the first type of network isolation analysis results, including:

[0010] When the first private network and the second private network are different private networks, the private network that is allowed to access the first private network is determined from the first network connection information, and the private network that is allowed to access the second private network is determined from the second network connection information.

[0011] Based on the private networks that are allowed to access the first private network and the private networks that are allowed to access the second private network, the network association relationship between the first private network and the second private network is determined; the network association relationship includes the network isolation relationship; the network isolation relationship is determined when the second private network is not included in the private networks that are allowed to access the first private network, and the first private network is not included in the private networks that are allowed to access the second private network.

[0012] If the network association relationship is a network isolation relationship, then the first analysis result is determined to indicate that there is network isolation between the first cloud server and the second cloud server, and the first analysis result is used as the first type of network isolation analysis result.

[0013] The network association includes network connectivity; the network connectivity is determined when the private network that allows access to the first private network includes the second private network, and the private network that allows access to the second private network includes the first private network; the first initial network configuration information includes the access control list information of the first subnet to which the first cloud server belongs, and the first subnet belongs to the first private network; the second initial network configuration information includes the access control list information of the second subnet to which the second cloud server belongs, and the second subnet belongs to the second private network;

[0014] The method also includes:

[0015] If the network association between the first private network and the second private network is a network connectivity relationship, then the first subnet outgoing rules and the first subnet incoming rules of the first subnet are determined from the access control list information of the first subnet, and the second subnet outgoing rules and the second subnet incoming rules of the second subnet are determined from the access control list information of the second subnet.

[0016] Based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the subnet configuration association relationship between the first cloud server and the second cloud server is determined; the subnet configuration association relationship includes the subnet configuration isolation relationship.

[0017] If the subnet configuration association relationship is a subnet configuration isolation relationship, then the first analysis result used to indicate that there is network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the first type of network isolation analysis result.

[0018] Specifically, based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the subnet configuration association between the first cloud server and the second cloud server is determined, including:

[0019] Based on the first subnet outgoing rules and the second subnet incoming rules, the first subnet configuration relationship between the first cloud server and the second cloud server in the first transmission direction is determined; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server.

[0020] Based on the first subnet inbound rules and the second subnet outbound rules, the second subnet configuration relationship between the first cloud server and the second cloud server in the second transmission direction is determined; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

[0021] If the first subnet configuration relationship indicates that there is network isolation in the first transmission direction, and the second subnet configuration association relationship indicates that there is network isolation in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration isolation relationship.

[0022] If the first subnet configuration relationship indicates that there is network connectivity in the first transmission direction, and the second subnet configuration association relationship indicates that there is network connectivity in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration connectivity relationship.

[0023] The subnet configuration association includes the subnet configuration connectivity; the first initial network configuration information includes the first security group information of the first cloud server; and the second initial network configuration information includes the second security group information of the second cloud server.

[0024] The method also includes:

[0025] If the subnet configuration association between the first cloud server and the second cloud server is a subnet configuration connectivity relationship, the first outgoing rule and the first incoming rule of the first cloud server are determined from the first security group information, and the second outgoing rule and the second incoming rule of the second cloud server are determined from the second security group information.

[0026] Based on the first outgoing rule, the first incoming rule, the second outgoing rule, and the second incoming rule, the first type of network isolation analysis results are determined.

[0027] Among them, based on the first outgoing rule, the first incoming rule, the second outgoing rule, and the second incoming rule, the first type of network isolation analysis results are determined, including:

[0028] Based on the first outgoing rule and the second incoming rule, a first transmission relationship is determined in the first transmission direction of sending data from the first cloud server to the second cloud server.

[0029] Based on the first inbound rule and the second outbound rule, a second transmission relationship is determined in the second transmission direction when data is sent from the second cloud server to the first cloud server.

[0030] If the first transmission relationship indicates that there is network isolation in the first transmission direction, and the second transmission relationship indicates that there is network isolation in the second transmission direction, then a first analysis result is determined to indicate that there is network isolation between the first cloud server and the second cloud server, and the first analysis result is used as the first type of network isolation analysis result.

[0031] If the first transmission relationship indicates that there is network connectivity in the first transmission direction, and the second transmission relationship indicates that there is network connectivity in the second transmission direction, then a second analysis result indicating that there is network connectivity between the first cloud server and the second cloud server is determined, and the second analysis result is used as the first type of network isolation analysis result.

[0032] The first initial network configuration information includes the access control list information of the first subnet to which the first cloud server belongs, and the first subnet belongs to the first private network; the second initial network configuration information includes the access control list information of the second subnet to which the second cloud server belongs, and the second subnet belongs to the second private network.

[0033] The method also includes:

[0034] When the first private network and the second private network are the same private network, and the first subnet and the second subnet are different subnets under the same private network, the first subnet outgoing rules and the first subnet incoming rules of the first subnet are determined from the access control list information of the first subnet, and the second subnet outgoing rules and the second subnet incoming rules of the second subnet are determined from the access control list information of the second subnet.

[0035] Based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the subnet configuration association relationship between the first cloud server and the second cloud server is determined; the subnet configuration association relationship includes the subnet configuration isolation relationship.

[0036] If the subnet configuration association relationship is a subnet configuration isolation relationship, then the first analysis result used to indicate that there is network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the first type of network isolation analysis result.

[0037] The methods also include:

[0038] If the first type of network isolation analysis result indicates that there is network isolation between the first cloud server and the second cloud server, then the first type of network isolation analysis result is determined as the network isolation detection result corresponding to the first cloud server and the second cloud server.

[0039] The first network data information includes the first traffic mirror data of the first cloud server, and the second network data information includes the second traffic mirror data of the second cloud server.

[0040] The method also includes:

[0041] Based on the first traffic mirror data and the second traffic mirror data, network isolation analysis is performed on the first cloud server and the second cloud server to obtain the second type of network isolation analysis results.

[0042] If the second type of network isolation analysis result indicates that there is network isolation between the first cloud server and the second cloud server, then network isolation verification is performed on the first cloud server and the second cloud server to obtain the network verification result for the second type of network isolation analysis result.

[0043] Specifically, based on the first and second traffic mirror data, network isolation analysis is performed on the first and second cloud servers to obtain the second type of network isolation analysis results, including:

[0044] Search for traffic log data of data interaction between the first cloud server and the second cloud server in the first traffic mirror data and the second traffic mirror data to obtain the log search results;

[0045] If the log lookup result indicates that no traffic log data for data interaction was found, then the first analysis result indicating that there is network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the second type of network isolation analysis result.

[0046] If the log lookup result indicates that traffic log data for data interaction has been found, then a second analysis result is determined to indicate that there is a network connection between the first cloud server and the second cloud server, and the second analysis result is used as the second type of network isolation analysis result.

[0047] Among them, network connectivity verification was performed on the first cloud server and the second cloud server to obtain network verification results for the first type of network isolation analysis, including:

[0048] Obtain the automated command execution component, call the automated command execution component to notify the first cloud server and the second cloud server to execute the network isolation query command respectively, and obtain the corresponding command query results;

[0049] Receive the command query results returned by the first cloud server and the second cloud server respectively, and determine the network verification result for the first type of network isolation analysis result based on the received command query results.

[0050] Specifically, the automated command execution component is invoked to notify the first and second cloud servers to execute network isolation query commands respectively, obtaining the corresponding command query results, including:

[0051] The automated command execution component is invoked to notify the first cloud server to execute the first query command and obtain the first query result corresponding to the first query command. The first query command is used to instruct the first cloud server to query the isolation in the first transmission direction. The first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server.

[0052] The automated command execution component is invoked to notify the second cloud server to execute the second query command and obtain the query result corresponding to the second query command. The second query command is used to instruct the second cloud server to query the isolation in the second transmission direction. The second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

[0053] Among them, the command query result returned by the first cloud server is the first command query result, and the command query result returned by the second cloud server is the second command query result;

[0054] Based on the received command query results, determine the network verification results for the first type of network isolation analysis, including:

[0055] If the query result of the first command indicates that there is network isolation in the first transmission direction, and the query result of the second command indicates that there is network isolation in the second transmission direction, then the first verification result used to indicate that there is network isolation between the first cloud server and the second cloud server in both the first and second transmission directions is determined, and the first verification result is determined as the network verification result.

[0056] If the query result of the first command indicates that there is network connectivity in the first transmission direction, and the query result of the second command indicates that there is network connectivity in the second transmission direction, then a second verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in both the first and second transmission directions, and the second verification result is determined as the network verification result.

[0057] If the query result of the first command indicates that there is network connectivity in the first transmission direction, and the query result of the second command indicates that there is network isolation in the second transmission direction, then a third verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction, and the third verification result is determined as the network verification result.

[0058] The first type of network isolation analysis results includes a third analysis result indicating that the first cloud server and the second cloud server have network connectivity in the first transmission direction and network isolation in the second transmission direction; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

[0059] Network connectivity verification was performed between the first cloud server and the second cloud server, yielding network verification results for the first type of network isolation analysis, including:

[0060] If the first type of network isolation analysis result is the third analysis result, then obtain the automated command execution component;

[0061] The automated command execution component is invoked to notify the first cloud server to execute the first query command and obtain the first command query result corresponding to the first query command; the first query command is used to instruct the first cloud server to query the isolation in the first transmission direction;

[0062] Receive the query result of the first command returned by the first cloud server;

[0063] If the query result of the first command indicates that there is network connectivity in the first transmission direction, then a third verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction, and the third verification result is determined as the network verification result.

[0064] If the query result of the first command indicates that there is network isolation in the first transmission direction, then the first verification result used to indicate that there is network isolation between the first cloud server and the second cloud server in both the first and second transmission directions is determined, and the first verification result is determined as the network verification result.

[0065] The methods also include:

[0066] When a verification task associated with a verification account is obtained, N cloud servers to be isolated for verification are determined based on the verification task; N is a positive integer; the verification account has the role permissions of the target role; the target role is configured based on the target management account, and the role permissions of the target role include data access permissions to obtain network data information of N cloud servers;

[0067] Determine any two cloud servers from the N cloud servers as the first cloud server and the second cloud server.

[0068] The acquisition of first network data information from the first cloud server and second network data information from the second cloud server includes:

[0069] Call the cloud service interface to send a network data acquisition request to the cloud platform service device;

[0070] Receive the request result data returned by the cloud platform service device based on the network data acquisition request, parse the network request result data to obtain the network data information of each of the N cloud servers, determine the network data information of the first cloud server as the first network data information, and determine the network data information of the second cloud server as the second network data information.

[0071] One embodiment of this application provides a network detection device, which operates on a target detection device for network isolation detection of N cloud servers, including a first cloud server and a second cloud server. The device includes:

[0072] The network data acquisition module is used to acquire first network data information of the first cloud server and second network data information of the second cloud server; both the first network data information and the second network data information include initial network configuration information configured by cloud platform service devices associated with N cloud servers;

[0073] The network isolation analysis module is used to perform network isolation analysis on the first cloud server and the second cloud server based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, and obtain the first type of network isolation analysis results;

[0074] The network verification module is used to verify the network connectivity between the first cloud server and the second cloud server if the first type of network isolation analysis result indicates that there is a network connection between the first cloud server and the second cloud server, and obtain the network verification result for the first type of network isolation analysis result; the network verification result may be the same as or different from the first type of network isolation analysis result.

[0075] One aspect of this application provides a computer-readable storage medium storing a computer program adapted to be loaded and executed by a processor, so that a computer device having the processor performs the method provided in this application.

[0076] One aspect of this application provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the method provided in this application.

[0077] In this embodiment, a target detection device, distinct from the cloud server itself, acquires network data information from the cloud server (e.g., a first cloud server and a second cloud server) to perform network isolation analysis. This eliminates the need to process large amounts of data on the cloud server for network isolation detection, thereby reducing the impact of network isolation detection on the cloud server's business operations and improving its efficiency. Furthermore, when initial network configuration information from the network data indicates network connectivity between cloud servers, further network connectivity verification can be performed on the cloud servers (e.g., the first and second cloud servers). This avoids inaccurate analysis results based on initial network configuration information due to additional security measures (e.g., firewalls) deployed by users on business servers, improving the accuracy of network isolation detection. Moreover, network connectivity verification only needs to be performed on cloud servers with existing network connectivity, reducing the amount of data processing required for network isolation detection on the cloud server and thus minimizing the impact of network isolation detection on other services on the cloud server. Therefore, by adopting the embodiments of this application, network isolation analysis is performed by obtaining network data information of the cloud server from a target detection device that is different from the cloud server. This eliminates the need to perform network isolation detection on the cloud server, which helps to reduce the impact of network isolation detection on the cloud server and improve the efficiency of network isolation detection. Attached Figure Description

[0078] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0079] Figure 1 This is a schematic diagram of the network architecture of a data processing system provided in an embodiment of this application;

[0080] Figure 2 This is a schematic diagram of a network isolation detection method provided in an embodiment of this application;

[0081] Figure 3 This is a schematic flowchart of a network detection method provided in an embodiment of this application;

[0082] Figure 4 This is a schematic diagram of a process for determining network relationships provided in an embodiment of this application;

[0083] Figure 5 This is a schematic diagram of a process for determining subnet configuration associations provided in an embodiment of this application;

[0084] Figure 6 This is a schematic diagram of a process for determining network isolation analysis results provided in an embodiment of this application;

[0085] Figure 7 This is a schematic diagram of a network isolation analysis process provided in an embodiment of this application;

[0086] Figure 8 This is a schematic diagram illustrating the effect of a cloud server provided in an embodiment of this application;

[0087] Figure 9 This is a schematic flowchart of a network isolation detection method provided in an embodiment of this application;

[0088] Figure 10 This is a schematic flowchart of a network detection method provided in an embodiment of this application;

[0089] Figure 11 This is a schematic diagram of a network connectivity verification process provided in an embodiment of this application;

[0090] Figure 12 This application provides a schematic diagram of a network connectivity verification process.

[0091] Figure 13 This is a schematic diagram of a network isolation detection process provided in an embodiment of this application;

[0092] Figure 14 This is a schematic flowchart of a network detection method provided in an embodiment of this application;

[0093] Figure 15 This is a schematic diagram of the structure of a network detection device provided in an embodiment of this application;

[0094] Figure 16 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation

[0095] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0096] The following describes some technical terms used in the embodiments of this application:

[0097] A Virtual Private Cloud (VPC) is a logically isolated network space built by a user (such as an enterprise, organization, or individual) for their own use. It allows users to define their own network environment, routing tables, security policies, etc. Different VPCs are completely logically isolated from each other. By default, different VPCs are not interconnected when created. However, they can be connected through various methods (such as peering) to enable communication. For example, VPC1 and VPC2 can be connected via peering, allowing VPC1 to access VPC2 (i.e., cloud servers in VPC1 can access cloud servers in VPC2), and vice versa. Understandably, a private network must have at least one subnet. When a private network is created, an initial subnet is created simultaneously. If multiple services need to be deployed on different subnets, or if existing subnets do not meet business requirements, new subnets can be created within the private network. Subnetting further strengthens isolation within a VPC. By creating subnets within a VPC, resources can be isolated according to purpose, business department, or security level. Each subnet within a private network can include at least one cloud server (also called a cloud host). This cloud server can be a physical device or a virtual machine; there are no restrictions here.

[0098] A Network Access Control List (ACL) is a network security technology used to control the rules governing incoming and outgoing network traffic; it's a subnet-level security policy. ACLs provide a more granular traffic filtering mechanism at the subnet level, controlling the rules governing traffic entering and leaving the subnet. ACLs support allow and deny rules, providing an additional layer of security for each subnet, defining the protocol type, source port (or destination port), and source IP address (or destination IP address) of traffic data that can reach or leave the subnet. ACL information can include subnet inbound rules and subnet outbound rules. Subnet inbound rules control traffic entering the subnet; for example, subnet inbound rules for subnet sub1 can instruct which cloud servers are allowed or denied access to which ports of cloud servers within subnet sub1. Subnet outbound rules control traffic leaving the subnet; for example, subnet outbound rules for subnet sub1 can instruct which cloud servers within subnet sub1 are allowed or denied access to which cloud servers through which ports.

[0099] Security groups (SGs) are security policies for cloud servers. They are functions within a cloud platform used to set up and manage network access control for cloud servers. They define rules for allowing or denying inbound and outbound network traffic, and are used for cloud server-level traffic control. Security groups define information such as the protocol type, source port (or destination port), and source IP address (or destination IP address) of traffic data that can reach or leave the cloud server. Security group information can include outbound and inbound rules for the cloud server. Inbound rules for the cloud server control traffic entering the cloud server; for example, inbound rules for cloud server C1 can indicate which cloud servers are allowed or denied access to which ports of cloud server C1. Outbound rules for the subnet control traffic leaving the cloud server; for example, outbound rules for cloud server C1 indicate which cloud servers are allowed or denied access to which cloud servers through which ports.

[0100] Traffic mirroring, also known as shadow traffic, refers to a backup of cloud server traffic. This traffic mirror can be a copy of the real traffic in the cloud server to a mirror service (i.e., a service provided by the cloud platform server device to manage the traffic mirroring of the cloud server). By obtaining the traffic mirror from the cloud platform service device, it is possible to perform specific analysis on the traffic or request content without affecting the operation of the cloud server. For example, network isolation detection of the cloud server can be performed based on the traffic mirror.

[0101] Please see Figure 1 , Figure 1 This is a schematic diagram of the network architecture of a data processing system provided in an embodiment of this application. Figure 1As shown, the data processing system includes a target detection device 100a, a cloud platform service device 110a, and a collection of cloud servers under a private network (such as...). Figure 1 (As shown in 200a). It should be understood that the target detection device 100a here can be a device used to detect the network isolation of a cloud server. This target detection device can be a server, such as a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms; there are no limitations here. The target detection device can also be a terminal device, including but not limited to mobile phones, computers, smart voice interaction devices, smart home appliances, vehicle terminals, aircraft, smart speakers, etc.; there are no limitations here. The target detection device can also be other devices used for network isolation detection; there are no limitations here.

[0102] The target detection device 100a can obtain network data information for network isolation detection from the cloud platform service device 110a, such as by calling the cloud API to obtain network data information from the cloud platform server device. The cloud platform service device 110a can manage various cloud servers, such as configuring security policies for each cloud server and storing network configuration information, traffic mirroring information, etc., for detecting the network isolation of each cloud server. The target detection device can also communicate with various cloud servers; for example, the target detection device can use an automated command execution component to instruct the cloud server to execute certain commands.

[0103] It should be understood that the embodiments of this application can be used to detect the network isolation between cloud servers in various private networks. For example, the private network may include private network 120a, private network 130a, etc. Private network 120a and private network 130a may be isolated from each other, or they may be connected through peer-to-peer connections, thereby enabling network connectivity between private network 120a and private network 130a (i.e., there is no network isolation). Each private network may include corresponding subnets. For example, private network 120a may include subnets 121a and 122a, where subnet 121a may include cloud servers 11a, 12a, 13a, etc., and subnet 122a may include cloud servers 14a, 15a, 16a, etc. Private network 130a may include subnets 131a and 132a. Subnet 131a may include cloud servers such as cloud server 21a, cloud server 22a, and cloud server 23a, while subnet 132a may include cloud servers such as cloud server 24a, cloud server 25a, and cloud server 26a. It should be understood that corresponding security policies can be configured for each subnet to achieve subnet-level traffic control, i.e., through access control lists (ACLs). Furthermore, corresponding security policies can be configured for the cloud servers within each subnet to achieve cloud server-level traffic control, i.e., through security groups.

[0104] It is understandable that the connection relationships and security policies (i.e., access control lists and security groups) between the aforementioned private networks can be obtained by the cloud platform service provider (i.e., the cloud vendor) through network configuration based on the business needs of users (such as enterprises, individuals, or organizations). For example, the cloud platform service provider (i.e., the cloud vendor) may configure the network according to the business needs of user U1 (which can be provided by user U17), such as creating private network 120a for area 1 and private network 130a for area 1, establishing peer-to-peer connections between the two private networks, and ensuring that the subnets under each private network are connected. The cloud platform service provides network configurations for the private networks of user U1 (such as private network 120a and private network 130a), and configures the network connectivity relationships (such as network connectivity or network isolation relationships) between the private networks of user U1 (such as private network 120a and private network 130a), as well as the security policies (i.e., access control lists) for subnets under the private network and the security policies (i.e., security group information) for cloud servers under the subnet. The network configurations performed by the cloud platform service for the private network can be referred to as the initial network configuration information for cloud servers in the private network. Understandably, in some scenarios, users (such as enterprises, individuals, or organizations) may deploy additional firewalls on cloud servers, thereby creating network isolation between these cloud servers that are configured to be connected through platform service devices. The configuration of these firewalls may not be recorded on the cloud platform. Therefore, when analyzing the isolation between cloud servers based on initial network configuration information, the additional firewalls configured by these users are not considered, potentially leading to inaccurate network isolation analysis. Therefore, when network isolation analysis based on initial network configuration information indicates network connectivity between cloud servers, further network connectivity verification is needed to ensure that network connectivity does indeed exist between the cloud servers and that network isolation is not caused by additional firewalls deployed by users on the cloud servers.

[0105] Please see Figure 2 , Figure 2 This is a schematic diagram illustrating a scenario of a network isolation detection method provided in an embodiment of this application. The multiple cloud servers to be tested for network isolation may include, for example... Figure 2 The cloud servers C1, C2, ..., Cn in 220a can belong to the same private network or different private networks; this is not limited here. Furthermore, the target detection device 100a can obtain network data information (such as...) from the cloud platform service device 110a from each cloud server. Figure 2(S211a in the text). The network data information can refer to the data information used to detect the network isolation between cloud servers, such as the network configuration information (i.e., the initial network configuration information) made by the cloud vendor (i.e., the cloud platform service provider) for each cloud server through the cloud platform service equipment.

[0106] In this context, the network data information of cloud server C1 is network data information W1, the network data information of cloud server C2 is network data information W2, and the network data information of cloud server Cn is network data information Wn. Here, we take the detection of network isolation between cloud server C1 and cloud server C2 as an example to illustrate the process of network isolation detection.

[0107] Specifically, initial network configuration data K1 can be determined from network data information W1. This initial network configuration data K1 can be information about network configuration performed on cloud server C1 by the cloud platform service device, such as configuration at the private network level (i.e., network connection information for the private network), subnet level configuration (such as access control list information configured for the subnet), and cloud server level configuration (such as security group information configured for the cloud server). Similarly, initial network configuration data K2 can be determined from network data information W2. This initial network configuration data K2 can be information about network configuration performed on cloud server C2 by the cloud platform service device.

[0108] Furthermore, network isolation analysis can be performed on cloud server C1 and cloud server C2 based on the initial network configuration data K1. This involves analyzing whether network isolation exists between cloud server C1 and cloud server C2 (or whether network connectivity exists between the cloud servers). It should be understood that network isolation analysis based on the initial network configuration data (such as initial network configuration data K1) can be performed step-by-step, analyzing configurations at the private network level (i.e., network connection information for the private network), subnet level (such as access control list information for the subnet), and cloud server level (such as security group information for the cloud server). This allows determining whether cloud server C1 can access cloud server C2 (i.e., whether network isolation exists in the transmission direction from cloud server C1 to cloud server C2), and whether cloud server C2 can access cloud server C1 (i.e., whether network isolation exists in the transmission direction from cloud server C2 to cloud server C1), thus determining whether network isolation exists between the two cloud servers.

[0109] It should be understood that in some cases, users (such as enterprises renting cloud servers, also known as tenants) can add additional security measures (such as firewalls or other methods) to the cloud server based on the initial network configuration information. For example, a tenant can add a firewall to cloud server C1, which changes the relationship between cloud servers configured by the cloud provider (i.e., the cloud platform service provider) to have network connectivity with cloud server C1 to network isolation (i.e., no connectivity). Therefore, when performing network isolation detection, if it is determined that there is network connectivity between two cloud servers based on the initial network configuration information, it cannot be completely certain that there is actually a network connection between the two cloud servers. Therefore, it is necessary to further detect whether the two cloud servers configured by the cloud platform service device to have network connectivity (i.e., no network isolation) are actually connected (i.e., no network isolation) to improve the accuracy of network isolation detection.

[0110] Based on this, network isolation analysis can be performed on cloud server C1 and cloud server C2 based on the initial network configuration data mentioned above to analyze whether network isolation exists (step S212a), which can also be called analyzing whether network connectivity exists (i.e., analyzing whether there is network isolation or network connectivity between cloud servers). If network isolation is found between cloud server C1 and cloud server C2, it is directly determined that there is network isolation between cloud server C1 and cloud server C2. That is, the final result of the network isolation detection of cloud server C1 and cloud server C2 is: there is network isolation between cloud server C1 and cloud server C2.

[0111] If analysis indicates that there is no network isolation between cloud server C1 and cloud server C2, further network connectivity verification is required to obtain the network verification result. During network connectivity verification, an automated command execution component can be invoked to instruct the cloud server to execute a network isolation query command (step S214b). The target detection device can then determine the network verification result based on the command result returned by the cloud server for the network isolation query command. This network isolation query command can be a command executed by the cloud server to query whether there is connectivity (i.e., whether there is network isolation or network connectivity) with another cloud server. For example, the automated command execution component can instruct cloud server C1 to execute the following network isolation query command: telnet 192.168.3.480. Telnet is a protocol used for remote login and management of network devices. It verifies network isolation by sending a connection request to the target host. This allows querying whether cloud server C1 can access port 80 of cloud server C2 (IP address 192.168.3.4). If the query result indicates that cloud server C1 can access cloud server C2 (e.g., returning the message "connnet to 192.168.3.4"), then cloud server C1 can access cloud server C2, indicating network connectivity in the transmission direction where cloud server C1 can access cloud server C2. Similarly, this same query can be used to check whether cloud server C2 can access cloud server C1, thus determining whether cloud server C2 can access cloud server C1, indicating network connectivity in the transmission direction where cloud server C2 can access cloud server C1.

[0112] Furthermore, the existence of network isolation can be verified based on the command results (step S214a), that is, it can be verified that there is network isolation or network connectivity between the cloud servers. When network isolation is verified between cloud server C1 and cloud server C2, it can be determined that there is network isolation between cloud server C1 and cloud server C2 (step S213a). In other words, the final result of the network isolation test (i.e., the isolation test result) for cloud server C1 and cloud server C2 is: there is network isolation between cloud server C1 and cloud server C2. The difference between the verified result and the analysis result may be due to the tenant configuring security measures such as firewalls for cloud server C1 or cloud server C2. When network connectivity is verified between cloud server C1 and cloud server C2, it can be determined that the final result of the network isolation test (i.e., the isolation test result) for cloud server C1 and cloud server C2 is: there is network connectivity between cloud server C1 and cloud server C2 (step S215a). Therefore, by adopting the embodiments of this application, users can achieve accurate and efficient detection of network isolation between cloud servers without installing additional agent software for network isolation detection on the cloud server, thereby improving the efficiency of network isolation detection and reducing the impact of network isolation detection on the business operation of the cloud server itself.

[0113] It should be understood that if there is network connectivity between two cloud servers (which can also be described as a connection between two cloud servers), i.e., there is no network isolation (which can also be described as isolation between two cloud servers), then the two cloud servers can communicate with each other. Specifically, this could mean that the two cloud servers can communicate with each other, or that only one server can actively access the other cloud server. If there is network isolation between two cloud servers (which can also be described as isolation between two cloud servers), i.e., there is no network connectivity (which can also be described as no connectivity between two cloud servers), then the two cloud servers cannot communicate with each other. Specifically, this could mean that communication is not possible in any transmission direction.

[0114] It should be understood that this application embodiment is an agentless network isolation detection method between cloud hosts (i.e., cloud servers). Agentless can refer to a method that does not require the installation of agent programs on cloud hosts, but obtains configurations through cloud APIs to perform network isolation detection. This application embodiment can be applied to east-west (i.e., the direction of communication between cloud servers) attack threat scenarios in a cloud-native environment. Through role authorization, the target management account (such as the account of the administrator of enterprise Q1 renting cloud servers) is configured with relevant permissions for the verification account (such as the account of the personnel of enterprise Q2 who are performing network maintenance on enterprise Q1's cloud servers). Then, the verification account uses the permissions provided by the target management account to call the cloud API, detect the configuration of VPC (private network), subnet ACL (access control list information of subnet), and SG (security group information). Finally, an automated command execution component notifies the cloud server to execute a command to detect whether the port is connected, thereby verifying whether network isolation exists between hosts (i.e., cloud servers). In this embodiment, permissions can be configured for verification accounts through role-based authorization, enabling cross-account authorization (both the target management account and the verification account can be the main account). Users can clearly see which resources (i.e., they can view the resources authorized to the verification account) and what permissions (i.e., they can view the permissions configured for the verification account) have been granted to the verification account through the target management account. The account under test can manage permissions at any time. Furthermore, this embodiment uses an agentless configuration acquisition method, obtaining network configurations (such as private network configurations, subnet ACLs, and security group information) based on the APIs (cloud service interfaces) provided by the cloud platform (also known as cloud products). This eliminates the need to install agent programs on the cloud host to obtain the cloud host's network configuration and execute related commands. Additionally, this embodiment can perform network isolation detection based on network configuration. For example, it can obtain network configurations from the cloud platform via cloud APIs, perform configuration parsing, and determine whether hosts are network isolated. Further, this embodiment can perform network connectivity verification based on automated command execution components. This allows for further verification of cloud servers that do not exhibit network isolation based on network configuration analysis, thereby improving the accuracy of network isolation analysis.

[0115] It is understood that the embodiments of this application relate to the field of cloud network security, and can detect the risk of unisolated host networks, which helps cloud service users (such as enterprises, individuals, or organizations) reduce the risk of their rented cloud servers being attacked from east to west. For example, in some scenarios, the network isolation between enterprise Q1's cloud servers can be detected through the embodiments of this application. If cloud server C1 in enterprise Q1 is maliciously attacked at some point, it can quickly identify cloud servers that are not network isolated from cloud server C1. For example, if it is detected that there is no network isolation between cloud server C1 and cloud server C2, security measures (such as installing a firewall) can be added to cloud server C2 so that cloud server C2 is no longer connected to cloud server C1 (i.e., there is network isolation), preventing malicious attacks from spreading from cloud server C1 to cloud server C2, thereby improving the network security between cloud servers.

[0116] It should be noted that this application may display prompt interfaces, pop-ups, or output voice prompts before and during the collection of user data. These prompt interfaces, pop-ups, or voice prompts are used to inform the user that their data is being collected. This ensures that the application only begins the steps for collecting user data after receiving confirmation from the user regarding the prompt interface or pop-up; otherwise (i.e., without user confirmation), the steps for collecting user data end, meaning no user data is collected. In other words, all user data collected in this application is collected with the user's consent and authorization, and the collection, use, and processing of related user data must comply with the relevant laws, regulations, and standards of the relevant countries and regions.

[0117] It is understood that the above scenarios are merely examples and do not constitute a limitation on the application scenarios of the technical solutions provided in the embodiments of this application. The technical solutions of this application can also be applied to other scenarios. For example, as those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.

[0118] Further, please see Figure 3 , Figure 3 This is a flowchart illustrating a network detection method provided in an embodiment of this application. The method can be executed by a target detection device used to perform network isolation detection on N cloud servers. For example, the target detection device is... Figure 1 The target detection device 100a in the method includes N cloud servers, including a first cloud server and a second cloud server. The method may include at least the following steps S101-S103.

[0119] S101. Obtain the first network data information of the first cloud server and the second network data information of the second cloud server; both the first network data information and the second network data information include the initial network configuration information configured by the cloud platform service device associated with the N cloud servers.

[0120] In this context, both the first cloud server and the second cloud server can be cloud servers within a private network. For example, the private network to which the first cloud server belongs is denoted as the first private network, and the private network to which the second cloud server belongs is denoted as the second private network. The first private network and the second private network can be the same or different; that is, the first cloud server and the second cloud server can belong to the same private network or different private networks, without limitation. For example, the first cloud server can belong to private network VPC1, the second cloud server can belong to private network VPC2, or both the first cloud server and the second cloud server can belong to private network VPC1.

[0121] It is understood that the first cloud server and the second server can be any two different cloud servers from the N cloud servers to be tested for network isolation. It should be understood that the N cloud servers can refer to the cloud servers to be tested for network isolation, where N is a positive integer greater than 1. It should be understood that the N cloud servers can be cloud servers in the same private network or cloud servers in different private networks; this is not limited here.

[0122] It is understandable that the N cloud servers can be determined based on the verification task obtained by the target detection device. This verification task can refer to a task used to detect the network isolation between cloud servers in the set of cloud servers to be tested. It should be understood that the set of cloud servers to be tested can indicate the set of cloud servers for which network isolation testing is required. This set of cloud servers to be tested can be specified by the task configuration object when the verification task is configured. The task configuration object can be an object used to configure the verification task, such as personnel in the enterprise renting the cloud servers (which can be called tenants). For example, when configuring a verification task, the task configuration object specifies the set of cloud servers to be tested as: {cloud server C1, cloud server C2, cloud server C3}. Then the above N cloud servers are: {cloud server C1, cloud server C2, cloud server C3}. The first server and the second server are any two cloud servers in {cloud server C1, cloud server C2, cloud server C3}. For example, the first cloud server is C1 and the second cloud server is C2, or the first cloud server is C1 and the second cloud server is C3, or the first cloud server is C2 and the second cloud server is C3.

[0123] It should be understood that this verification task is published on a verification account. This verification account can refer to the account corresponding to the business object (denoted as the verification object) used to execute the verification task. The verification object can refer to the object actually executing the verification task, such as personnel in a company that provides network operation and maintenance services to tenants, or personnel performing network operation and maintenance in a company that rents cloud servers (which can be called a tenant). Furthermore, the verification object can log in to the verification account on the client of the cloud platform running the target detection device, and then view the verification task published on that verification account on the page used to display verification tasks in the client. In other words, only when a verification account is logged in on the target detection device can the verification task published on that verification account be started and executed through the target detection device. This verification account has the necessary permissions to execute the verification task, such as the permission to obtain network data information from the aforementioned N cloud servers. It should be understood that the verification object and the aforementioned task configuration object can be the same object. For example, object U1 configures verification task Y1 through its own account Z1, and object U1 executes verification task Y1 through account Z1. In this case, both the task configuration object and the verification object are object U1. It should be understood that the verification object and the task configuration object mentioned above can be different objects. For example, object U1 configures verification task Y1 through its own account Z1 and specifies that the configured verification task Y1 is executed by the account Z1 corresponding to object U2. In this case, the task configuration object is object U1 and the verification object is Y1, which are different objects.

[0124] The verification task can be manually started by the business object corresponding to the verification account, or it can be automatically started when the system time of the target detection device reaches the task's start time (i.e., the time when the verification task begins execution). There is no limitation here. For example, if the task configuration object specifies the task's start time as T1 when configuring the verification task, then the verification task will automatically start when the system time of the target detection device reaches T1, so that the verification task can be executed through the target detection device. As another example, if the task configuration object specifies the verification task as a periodically executed task, such as executing the verification task at 00:00 every day, then the verification task will automatically start when the system time of the target detection device reaches 00:00 every day, so that the verification task can be executed through the target detection device.

[0125] It should be understood that network data information from each of the N cloud servers can be obtained. This network data information can refer to data used to detect the network isolation between cloud servers. The first network data information refers to the network data information of the first cloud server, which can be used to detect the network isolation between the first cloud server and other cloud servers. The second network data information refers to the network data information of the second cloud server, which can be used to detect the network isolation between the second cloud server and other cloud servers.

[0126] It should be understood that this network data information may include initial network configuration information configured by cloud platform service devices associated with N cloud servers. The cloud platform service devices can be service devices corresponding to the cloud platform used to manage the cloud servers, such as those mentioned above. Figure 1 The cloud platform service device 110a.

[0127] The initial network configuration information refers to the network configuration information performed by the cloud service provider on the cloud server through the cloud platform service device. It should be understood that in some cases, tenants (such as enterprises renting cloud servers) can add security measures (such as firewalls or other methods) to the network configuration between cloud servers based on the initial network configuration information. For example, adding a firewall between cloud servers configured to have network connectivity by the cloud service device can change the network isolation (i.e., disconnection) between cloud servers that were previously configured to have network connectivity. Therefore, when performing network isolation detection, if it is determined that there is network connectivity between two cloud servers based on the initial network configuration information, it is possible to further detect whether the two cloud servers configured to have network connectivity (i.e., connectivity) by the cloud platform service device are actually connected (i.e., there is no network isolation), thus improving the accuracy of network isolation detection.

[0128] The initial network configuration information of any cloud server may include network connection information of the private network to which the cloud server belongs. Network connection information can refer to information about other private networks connected to the private network. A private network's network connection information may include private networks that are allowed to access the private network, or it may include private networks that are allowed to access the private network. For example, if the private network to which cloud server C1 belongs is VPC1, then the network connection information of VPC1 can be obtained from the cloud platform service device via the cloud API. For instance, this network connection information may indicate that the private networks allowed to access VPC1 are VPC2 and VPC3, and that VPC1 is allowed to access VPC2. This indicates that VPC1 and VPC2 are interconnected (also called interconnected), and that there is a one-way connection between VPC1 and VPC3, allowing only VPC3 to access VPC1.

[0129] The initial network configuration information of any cloud server may also include access control list (ACL) information for the subnet to which the cloud server belongs. ACL information is a network security technology used to control the inbound and outbound traffic rules for a subnet; that is, this ACL information is used for subnet-level traffic control. ACL information can include subnet-inbound rules and subnet-outbound rules. Subnet inbound rules refer to rules used to control traffic entering a subnet. For example, the subnet inbound rule for subnet sub1 can be used to indicate which cloud servers (i.e., the affected servers) are allowed or denied (i.e., the affected information) to access which ports of the cloud servers in subnet sub1 (i.e., the affected ports). In other words, subnet inbound rules can include information such as the affected information (allow or deny), the affected cloud servers (e.g., the IP address of the cloud server), and the affected ports (e.g., port 80). Subnet outbound rules refer to rules used to control traffic flowing out of a subnet. For example, the subnet outbound rule for subnet sub1 can be used to indicate which cloud servers (i.e., the affected servers) in subnet sub1 are allowed or denied (i.e., the affected information) to access which cloud servers (i.e., the affected ports) through. In other words, subnet outbound rules can include information such as the affected information (allow or deny), the affected cloud servers (e.g., the IP address of the cloud server), and the affected ports (e.g., port 80).

[0130] The initial network configuration information for any cloud server may also include the cloud server's security group information. A security group is a feature in the cloud platform used to set up and manage network access control for cloud servers. It defines rules for allowing or blocking inbound and outbound network traffic, and is used for cloud server-level traffic control. This security group information may include outbound and inbound rules for the cloud server. Inbound rules for cloud servers refer to rules used to control traffic entering the cloud server. For example, inbound rules for cloud server C1 can be used to indicate which cloud servers (i.e., the affected servers) are allowed or denied (i.e., the affected information) to access which ports of cloud server C1 (i.e., the affected ports). In other words, inbound rules for cloud servers can include information such as allow or deny, the affected cloud servers (e.g., the cloud server's IP address), and the affected ports (e.g., port 80). Outbound rules for subnets refer to rules used to control traffic flowing out of the cloud server. For example, outbound rules for cloud server C1 can be used to indicate which cloud servers (i.e., the affected servers) are allowed or denied (i.e., the affected information) to access through which cloud server C1 (i.e., the affected ports). In other words, outbound rules for cloud servers can include information such as allow or deny, the affected cloud servers (e.g., the cloud server's IP address), and the affected ports (e.g., port 80).

[0131] It is understandable that the network connection information of the private network, the access control list information of the subnet, and the security group information of the private network in the initial network configuration information can be obtained uniformly when the verification task is started, or it can be obtained only when the corresponding data is needed during the execution of the verification task. There is no limitation here.

[0132] Specifically, obtaining the first network data information of the first cloud server and the second network data information of the second cloud server may include the following steps: calling the cloud service interface to send a network data acquisition request to the cloud platform service device; receiving the request result data returned by the cloud platform service device based on the network data acquisition request; parsing the network request result data to obtain the network data information of each of the N cloud servers; determining the network data information of the first cloud server as the first network data information; and determining the network data information of the second cloud server as the second network data information.

[0133] The cloud service interface can be an interface used to obtain network data information from the cloud server, such as an API interface. It is understood that when obtaining the network connection information of the private network, the access control list information of the subnet, and the security group information in the initial network configuration information mentioned above, these can be obtained separately through the corresponding cloud server interfaces.

[0134] In this context, a network data acquisition request can refer to a request to obtain network data information from a cloud server. It should be understood that after receiving such a request, the cloud platform service device can query the corresponding data from its own database based on the request to determine the requested result data, and then return the result data to the designated target detection device.

[0135] It's understandable that obtaining network data information from cloud servers (such as initial network configuration information) can be done by calling the cloud API (i.e., the cloud server interface). Specifically, depending on the verification task configuration, the verification account can call the cloud API to obtain the relevant network configuration. For example, if the verification task is used to instruct the verification of the network isolation status of cloud hosts instance-C1 and instance-C2 under region area1 (parameter ap-area1 in the cloud API), when calling the cloud API to obtain the network configuration, ap-area1 (i.e., the region parameter), instance-C1 (e.g., the IP address of instance-C1), and instance-C2 (e.g., the IP address of instance-C2) can be used as parameters when calling the cloud API.

[0136] Furthermore, after acquiring the request result data, the target detection device can parse the request result data to obtain the network data information of each of the N cloud servers. It can be understood that parsing the request result data means finding relevant fields associated with the network data information within the request result data, and then determining the network data information based on the field data of these relevant fields.

[0137] For example, the following is the security group information returned for a cloud server (in a simplified response body), which indicates that any IP address is allowed to enter or exit traffic through port 80 using any protocol.

[0138]

[0139]

[0140] S102. Based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, perform network isolation analysis on the first cloud server and the second cloud server to obtain the first type of network isolation analysis results.

[0141] Network isolation analysis can be used to indicate the network isolation between cloud servers based on network data information. The first type of network isolation analysis result refers to the analysis result obtained based on the initial network configuration information in the network data. It can be understood that this first type of network isolation analysis result can be used to indicate that there is network isolation between the first cloud server and the second cloud server, or it can be used to indicate that there is network connectivity between the first cloud server and the second cloud server. For ease of description, the analysis result obtained during network isolation analysis indicating that there is network isolation between the first cloud server and the second cloud server can be called the first analysis result, and the analysis result obtained during network isolation analysis indicating that there is network connectivity between both the first cloud server and the second cloud server can be called the second analysis result. It is understandable that in some cases, when there is network connectivity between the first cloud server and the second cloud server, the connection between the first cloud server and the second cloud server can be unidirectional. For example, the first type of network isolation analysis result may include: an analysis result indicating that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction (referred to as the third analysis result), or an analysis result indicating that there is network isolation between the first cloud server and the second cloud server in the first transmission direction and network connectivity in the second transmission direction (referred to as the fourth analysis result).

[0142] Understandably, when performing network isolation analysis on the first cloud server and the second cloud server, it is possible to directly determine whether network isolation exists between the two servers based on the security group information between the first cloud server and the second cloud server.

[0143] Understandably, when performing network isolation analysis on the first and second cloud servers, to improve computational efficiency, it's advisable to first determine whether they belong to the same private network (or different private networks that are interconnected). If they do, then it's further possible to determine whether they belong to the same subnet (or different subnets that are interconnected). If they do, then it's necessary to further determine whether there is network connectivity between the two cloud servers (i.e., whether there are connected ports) based on security group information. Conversely, if the two cloud servers are different private networks with network isolation, a first analysis result indicating network isolation between the first and second cloud servers can be directly obtained without further determining whether they belong to the same subnet (or different subnets that are interconnected). This allows for a more rapid identification of two cloud servers with network isolation by analyzing network configuration information at each level, from private network to subnet to security group. This improves the efficiency of network isolation analysis, especially when dealing with a large number of cloud servers. It avoids the need to check for port connectivity between any two cloud servers using security group information, thus reducing the computational load and improving the efficiency of network isolation analysis.

[0144] Specifically, the initial network configuration information in the first network data information is the first initial network configuration information, and the initial network configuration information in the second network data information is the second initial network configuration information; the first initial network configuration information includes the first network connection information of the first private network to which the first cloud server belongs; the second initial network configuration information includes the second network connection information of the second private network to which the second cloud server belongs; therefore, based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, performing network isolation analysis on the first cloud server and the second cloud server to obtain the first type of network isolation analysis result may include the following steps: when the first private network and the second private network are different private networks, from the first network connection information... The system identifies private networks that are allowed to access the first private network from the first private network and private networks that are allowed to access the second private network from the second network connection information. Based on the private networks that are allowed to access the first private network and the private networks that are allowed to access the second private network, the system determines the network association relationship between the first private network and the second private network. The network association relationship includes the network isolation relationship. The network isolation relationship is determined when the private networks that are allowed to access the first private network do not include the second private network, and the private networks that are allowed to access the second private network do not include the first private network. If the network association relationship is the network isolation relationship, the system determines a first analysis result to indicate that there is network isolation between the first cloud server and the second cloud server, and uses the first analysis result as the first type of network isolation analysis result.

[0145] Here, the first private network refers to the private network belonging to the first cloud server, and the second private network refers to the private network belonging to the second cloud server. The first network connection information refers to the network connection information of the first private network, that is, the information of other private networks connected to the first private network. The second network connection information refers to the network connection information of the second private network, that is, the information of other private networks connected to the second private network. For a more detailed explanation of network connection information, please refer to the above description; it will not be repeated here.

[0146] It should be understood that network association can refer to the isolation relationship between two private networks. For example, this network association can be a network isolation relationship or a network connectivity relationship. A network isolation relationship means that two private networks are isolated from each other, meaning they cannot communicate. For instance, private network VPC1 cannot access private network VPC2, and private network VPC2 cannot access private network VPC1. Therefore, the network association between private network VPC1 and private network VPC2 is a network isolation relationship. A network connectivity relationship means that two private networks are connected (i.e., there is no isolation). Network connectivity relationships can include network interconnection relationships and one-way network connections. A network interconnection relationship indicates that two private networks can access each other. For instance, private network VPC1 can access private network VPC2, and private network VPC2 can access private network VPC1. Therefore, the network association between private network VPC1 and private network VPC2 is a network interconnection relationship. A one-way network connection indicates that only one private network can access the other private network. For example, private network VPC1 can access private network VPC2, but private network VPC2 cannot access private network VPC1, or private network VPC1 cannot access private network VPC2, but private network VPC2 can access private network VPC1. In this case, the network association between private network VPC1 and private network VPC2 is a one-way network connection.

[0147] It is understandable that, based on the private networks that allow access to the first private network and the private networks that allow access to the second private network, determining the network association between the first private network and the second private network may include: if the private networks that allow access to the first private network do not include the second private network, and the private networks that allow access to the second private network do not include the first private network, then the network association between the first private network and the second private network is determined to be a network isolation relationship; if the private networks that allow access to the first private network include the second private network, and the private networks that allow access to the second private network include the first private network, then the network association between the first private network and the second private network is determined to be a network interconnection relationship; if the private networks that allow access to the first private network include the second private network, and the private networks that allow access to the second private network do not include the first private network, or if the private networks that allow access to the first private network do not include the second private network, and the private networks that allow access to the second private network include the first private network, then the network association between the first private network and the second private network is determined to be a unidirectional network connection relationship.

[0148] It should be understood that if there is isolation between two private networks (i.e., the network relationship between the two private networks is a network isolation relationship), it means that the cloud servers in these two private networks are network isolated, and thus a first analysis result can be obtained to indicate that there is network isolation between the first cloud server and the second cloud server.

[0149] For example, see Figure 4 , Figure 4 This is a schematic diagram illustrating a process for determining network relationships provided in an embodiment of this application. For example... Figure 4 As shown, the cloud servers to be tested for network isolation include cloud server C1 and cloud server C2. Cloud server C1 belongs to subnet sub1 in private network VPC1, and cloud server C2 belongs to subnet sub2 in private network VPC2. Therefore, during network isolation analysis, the network connection information of private network VPC1 can be obtained (such as...). Figure 4 As shown in 401a), and the network connection information of the private network VPC2 (such as... Figure 4 As shown in 402a). It should be understood that in network connection information 401a, the private networks allowed to access VPC1 may include: private network VPC2 and private network VPC3, and in network connection information 402a, the private networks allowed to access VPC2 may include: private network VPC1 and private network VPC3. It can be seen that since the private networks allowed to access VPC1 include private network VPC2, and the private networks allowed to access VPC2 include private network VPC1, the network association between VPC1 and VPC2 is: network connectivity relationship (e.g., ...). Figure 4 As shown in 403a), the network association between VPC1 and VPC2 can specifically be a network interconnection relationship.

[0150] Furthermore, when there is no isolation between the private networks to which the first cloud server and the second cloud server belong (i.e., the network relationship is either interconnected or unidirectional), it is necessary to further determine whether there is isolation between their respective subnets. It should be understood that if the first cloud server and the second cloud server belong to different private networks, then they must belong to different subnets.

[0151] Specifically, network association relationships include network connectivity relationships; network connectivity relationships are determined when the private network that allows access to the first private network includes the second private network, and the private network that allows access to the second private network includes the first private network; the first initial network configuration information includes the access control list information of the first subnet to which the first cloud server belongs, and the first subnet belongs to the first private network; the second initial network configuration information includes the access control list information of the second subnet to which the second cloud server belongs, and the second subnet belongs to the second private network; embodiments of this application may further include the following steps: if the network association relationship between the first private network and the second private network is a network connectivity relationship, then from the first The access control list information of a subnet determines the first subnet outgoing rules and the first subnet incoming rules of the first subnet. The access control list information of the second subnet determines the second subnet outgoing rules and the second subnet incoming rules of the second subnet. Based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the subnet configuration association relationship between the first cloud server and the second cloud server is determined. The subnet configuration association relationship includes the subnet configuration isolation relationship. If the subnet configuration association relationship is a subnet configuration isolation relationship, then a first analysis result is determined to indicate that there is network isolation between the first cloud server and the second cloud server, and the first analysis result is used as the first type of network isolation analysis result.

[0152] The first subnet is the subnet to which the first cloud server belongs, and this first subnet belongs to the first private network; the second subnet refers to the subnet to which the second cloud server belongs, and this second subnet belongs to the second private network.

[0153] It should be understood that, based on the above description, Access Control List (ACCR) information is a network security technology used to control the rules governing traffic entering and leaving a subnet. ACCR information can include subnet inbound rules and subnet outbound rules. For an explanation of subnet inbound and outbound rules, please refer to the relevant descriptions above; they will not be repeated here. Specifically, the first subnet outbound rule refers to the subnet outbound rule of the first subnet, and the first subnet inbound rule refers to the subnet inbound rule of the first subnet; the second subnet outbound rule refers to the subnet outbound rule of the second subnet, and the second subnet inbound rule refers to the subnet inbound rule of the second subnet.

[0154] It should be understood that subnet configuration association can refer to the isolation determined by the network configuration (i.e., access control list) of the subnet to which the cloud server belongs. For example, this subnet configuration association can be a subnet configuration isolation relationship or a subnet configuration connectivity relationship. Specifically, a subnet configuration isolation relationship can mean that the cloud servers are isolated (i.e., not connected) based on the network configuration (i.e., access control list) of their respective subnets. A subnet configuration connectivity relationship can mean that the cloud servers are connected (i.e., not isolated) based on the network configuration (i.e., access control list) of their respective subnets.

[0155] Specifically, when determining the subnet configuration association between the first cloud server and the second cloud server based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the relationship in the transmission direction (i.e., the first transmission direction) of the first cloud server accessing the second cloud server can be determined based on the first subnet outgoing rules and the second subnet incoming rules (e.g., whether there is an isolation relationship in the first transmission direction). The relationship in the transmission direction (i.e., the second transmission direction) of the second cloud server accessing the first cloud server can be determined based on the first subnet incoming rules and the second subnet outgoing rules (e.g., whether there is an isolation relationship in the second transmission direction). Thus, based on the determined relationship in these two transmission directions, the isolation between the first cloud server and the second cloud server obtained based on the network configuration for their respective subnets can be determined. If the first cloud server and the second cloud server are isolated based on the network configuration of their respective subnets, it means that there is network isolation between the first cloud server and the second cloud server. If the first cloud server and the second cloud server are connected based on the network configuration of their respective subnets, it is necessary to further determine whether there is indeed a network connection between the first cloud server and the second cloud server based on the network configuration at the cloud server level (i.e., security group).

[0156] Specifically, based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the subnet configuration association relationship between the first cloud server and the second cloud server is determined. This includes: determining the first subnet configuration relationship between the first cloud server and the second cloud server in the first transmission direction based on the first subnet outgoing rules and the second subnet incoming rules; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server; determining the second subnet configuration relationship between the first cloud server and the second cloud server in the second transmission direction based on the first subnet incoming rules and the second subnet outgoing rules; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server; if the first subnet configuration relationship indicates network isolation in the first transmission direction, and the second subnet configuration association relationship indicates network isolation in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration isolation relationship; if the first subnet configuration relationship indicates network connectivity in the first transmission direction, and the second subnet configuration association relationship indicates network connectivity in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration connectivity relationship.

[0157] It should be understood that the first transmission direction can refer to the direction in which the first cloud server sends data to the second cloud server, that is, the direction in which the first cloud server accesses the second cloud server. The second transmission direction can refer to the direction in which the second cloud server sends data to the first cloud server, that is, the direction in which the second cloud server accesses the first cloud server. It should be understood that the first and second transmission directions here are merely used to describe different communication directions between the first and second cloud servers and do not have a sequential relationship.

[0158] The first subnet configuration relationship can refer to the existence of isolation (connectivity) in the first transmission direction, as determined by the network configuration (access control list) of the subnet to which it belongs. The second subnet configuration relationship can refer to the existence of network isolation (connectivity) in the second transmission direction, as determined by the network configuration (access control list) of the subnet to which it belongs.

[0159] Specifically, determining the first subnet configuration relationship in the first transmission direction for sending data from the first cloud server to the second cloud server, based on the first subnet outgoing rule and the second subnet incoming rule, may include: if the first subnet outgoing rule indicates that each cloud server (e.g., the first cloud server) within the first subnet is allowed to access the second cloud server, and the second subnet incoming rule indicates that each cloud server (e.g., the second cloud server) within the second subnet is allowed to access the first cloud server, then a first subnet configuration relationship indicating connectivity in the first transmission direction is determined. If the first subnet outgoing rule indicates that each cloud server (e.g., the first cloud server) within the first subnet is not allowed to access the second cloud server, or the second subnet incoming rule indicates that each cloud server (e.g., the second cloud server) within the second subnet is not allowed to access the first cloud server, then a first subnet configuration relationship indicating isolation in the first transmission direction is determined.

[0160] Specifically, determining the second subnet configuration relationship in the second transmission direction for sending data from the second cloud server to the first cloud server, based on the first subnet inbound rule and the second subnet outbound rule, may include: if the first subnet inbound rule indicates that each cloud server (e.g., the first cloud server) within the first subnet allows the second cloud server to access it, and the second subnet outbound rule indicates that each cloud server (e.g., the second cloud server) within the second subnet is allowed to access the first cloud server, then a second subnet configuration relationship indicating network connectivity in the second transmission direction is determined. If the first subnet inbound rule indicates that each cloud server (e.g., the first cloud server) within the first subnet does not allow the second cloud server to access it, or the second subnet outbound rule indicates that each cloud server (e.g., the second cloud server) within the second subnet is not allowed to access the first cloud server, then a second subnet configuration relationship indicating isolation in the second transmission direction is determined.

[0161] For example, see Figure 5 , Figure 5 This is a schematic diagram illustrating a process for determining subnet configuration associations provided in an embodiment of this application. For example... Figure 5As shown, the cloud servers to be tested for network isolation include cloud server C1 and cloud server C2. Cloud server C1 belongs to subnet sub1, and cloud server C2 belongs to subnet sub2 (subnet sub1 and subnet sub2 can be different subnets within the same private network, or subnets within different private networks with network connectivity). During network isolation analysis, access control list information 501a and 502a for subnet sub1 can be obtained. It should be understood that in access control list information 501a, the subnet outbound rule indicates: deny cloud server C2 (i.e., cloud server C1 is not allowed to access cloud server C2), and the subnet inbound rule indicates: deny cloud server C2 (i.e., cloud server C1 does not allow cloud server C2 to access). It should be understood that in access control list information 502a, the subnet outgoing rule indicates: deny cloud server C1 (i.e., cloud server C2 is not allowed to access cloud server C1), and the subnet incoming rule indicates: deny cloud server C1 (i.e., cloud server C2 is not allowed to access cloud server C1). Therefore, based on the subnet outgoing rule in access control list information 501a and the subnet incoming rule in access control list information 502a, the subnet configuration relationship in the transmission direction of cloud server C1 → cloud server C2 (i.e., the transmission direction of data transmission from cloud server C1 to cloud server C2) can be determined to be: network isolation exists (e.g., ...). Figure 5 (As shown in 503a). Similarly, based on the subnet inbound rules in access control list information 501a and the subnet outbound rules in access control list information 502a, the subnet configuration relationship in the transmission direction of cloud server C2 → cloud server C1 (i.e., the transmission direction of data transmission from cloud server C2 to cloud server C1) can be determined as follows: network isolation exists (e.g., Figure 5 (As shown in 504a). Furthermore, in the transmission direction from cloud server C1 to cloud server C2, the subnet configuration associations in both transmission directions from cloud server C2 to cloud server C1 indicate isolation. Therefore, the subnet configuration association between cloud server C1 and cloud server C2 can be determined as: subnet configuration isolation relationship (e.g., ...). Figure 5 (as shown in 505a).

[0162] Furthermore, if both the first and second subnet configuration relationships indicate isolation in the corresponding transmission direction, it means that there is network isolation between the first cloud server and the second cloud server, thus yielding the first analysis result. If either the first or second subnet configuration relationship indicates network connectivity in the corresponding transmission direction, the isolation between the first and second cloud servers can be further determined using the cloud server's security group information.

[0163] Specifically, the subnet configuration association relationship includes the subnet configuration connectivity relationship; the first initial network configuration information includes the first security group information of the first cloud server; the second initial network configuration information includes the second security group information of the second cloud server; then, the embodiments of this application may further include the following steps: if the subnet configuration association relationship between the first subnet and the second subnet is a subnet configuration connectivity relationship, determine the first outgoing rule and the first incoming rule of the first cloud server from the first security group information, and determine the second outgoing rule and the second incoming rule of the second cloud server from the second security group information; based on the first outgoing rule, the first incoming rule, the second outgoing rule and the second incoming rule, determine the first type of network isolation analysis result.

[0164] As mentioned above, security group information can be used for traffic control at the cloud server level. The first security group information can refer to the security group information of the first cloud server, and the second security group information can refer to the security group information of the second cloud server. Specifically, the first outgoing rule refers to the outgoing rule in the first security group information for the first cloud server, the first incoming rule refers to the incoming rule in the first security group information for the first cloud server, the second outgoing rule refers to the outgoing rule in the second security group information for the second cloud server, and the second incoming rule refers to the incoming rule in the second security group information for the second cloud server.

[0165] It should be understood that when determining the first type of network isolation analysis result based on the first outgoing rule, the first incoming rule, the second outgoing rule, and the second incoming rule, the transmission relationship in the transmission direction (i.e., the first transmission direction) of the first cloud server accessing the second cloud server can be determined based on the first outgoing rule and the second incoming rule (e.g., whether there is an isolation relationship in the first transmission direction), and the transmission relationship in the transmission direction (i.e., the second transmission direction) of the second cloud server accessing the first cloud server can be determined based on the second outgoing rule and the first incoming rule (e.g., whether there is an isolation relationship in the second transmission direction). Thus, based on the determined transmission relationship in these two transmission directions, the isolation between the first cloud server and the second cloud server can be determined.

[0166] Specifically, determining the first type of network isolation analysis result based on the first outgoing rule, the first incoming rule, the second outgoing rule, and the second incoming rule may include the following steps: determining a first transmission relationship in a first transmission direction for sending data from the first cloud server to the second cloud server based on the first outgoing rule and the second incoming rule; determining a second transmission relationship in a second transmission direction for sending data from the second cloud server to the first cloud server based on the first incoming rule and the second outgoing rule; if the first transmission relationship indicates network isolation in the first transmission direction and the second transmission relationship indicates network isolation in the second transmission direction, then a first analysis result indicating network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the first type of network isolation analysis result; if the first transmission relationship indicates network connectivity in the first transmission direction and the second transmission relationship indicates network connectivity in the second transmission direction, then a second analysis result indicating network connectivity between the first cloud server and the second cloud server is determined, and the second analysis result is used as the first type of network isolation analysis result.

[0167] Here, the first transmission direction can refer to the direction in which the first cloud server sends data to the second cloud server, i.e., the direction in which the first cloud server accesses the second cloud server. The second transmission direction can refer to the direction in which the second cloud server sends data to the first cloud server, i.e., the direction in which the second cloud server accesses the first cloud server. It should be understood that the first and second transmission directions here are merely used to describe different communication directions between the first and second cloud servers and do not have a sequential relationship.

[0168] The first transmission relationship is used to indicate whether an isolation (i.e., connectivity) relationship exists in the first transmission direction based on the network configuration (i.e., security group information) for the cloud server. The second transmission relationship is used to indicate whether an isolation (i.e., connectivity) relationship exists in the second transmission direction based on the network configuration (i.e., security group information) for the cloud server.

[0169] Specifically, determining the first transmission relationship in the first transmission direction for sending data from the first cloud server to the second cloud server based on the first outgoing rule and the second incoming rule may include: if the first outgoing rule indicates that the first cloud server is allowed to access the second cloud server, and the second incoming rule indicates that the second cloud server allows the first cloud server to access, then a first transmission relationship indicating network connectivity in the first transmission direction is determined. If the first outgoing rule indicates that the first cloud server is not allowed to access the second cloud server, or the second incoming rule indicates that the second cloud server does not allow the first cloud server to access, then a first transmission relationship indicating network isolation in the second transmission direction is determined.

[0170] Specifically, determining the second transmission relationship in the second transmission direction for sending data from the second cloud server to the first cloud server based on the first inbound rule and the second outbound rule may include: if the first inbound rule indicates that the first cloud server allows the second cloud server to access, and the second outbound rule indicates that the second cloud server is allowed to access the first cloud server, then a relationship indicating network connectivity in the second transmission direction is determined. If the first inbound rule indicates that the first cloud server does not allow the second cloud server to access, or the second outbound rule indicates that the second cloud server is not allowed to access the first cloud server, then a relationship indicating network isolation in the second transmission direction is determined.

[0171] Furthermore, if both the first and second transmission relationships indicate network isolation in the corresponding transmission directions, it means that there is network isolation between the first cloud server and the second cloud server, thus yielding the first analysis result. If both the first and second transmission relationships indicate network connectivity in the corresponding transmission directions, it means that there is network connectivity between the first cloud server and the second cloud server in both the first and second transmission directions, thus yielding the second analysis result.

[0172] It should be understood that if the first transmission relationship indicates network connectivity and the second transmission relationship indicates network isolation, a third analysis result is obtained indicating that the first cloud server and the second cloud server have network connectivity in the first transmission direction and network isolation in the second transmission direction. If the first transmission relationship indicates network isolation and the second transmission relationship indicates network connectivity, a fourth analysis result is obtained indicating that the first cloud server and the second cloud server have network isolation in the first transmission direction and network connectivity in the second transmission direction. It should be understood that any of the second, third, and fourth analysis results can indicate that there is network connectivity between the first cloud server and the second cloud server. In other words, if either the first or second transmission relationship indicates network connectivity in the corresponding transmission direction, it indicates that there is network connectivity between the first cloud server and the second cloud server.

[0173] For example, see Figure 6 , Figure 6 This is a schematic diagram of a process for determining network isolation analysis results provided in an embodiment of this application. Figure 6As shown, the cloud servers to be tested for network isolation include cloud server C1 and cloud server C2. Both cloud server C1 and cloud server C2 belong to subnet sub1. Therefore, during network isolation analysis, security group information 601a for cloud server C1 and security group information 602a for cloud server C2 can be obtained. It should be understood that in security group information 601a, outgoing rules indicate: deny cloud server C2 (i.e., cloud server C1 is not allowed to access cloud server C2), and incoming rules indicate: deny cloud server C2 (i.e., cloud server C1 does not allow cloud server C2 to access). It should be understood that in security group information 602a, outgoing rules indicate: deny cloud server C1 (i.e., cloud server C2 is not allowed to access cloud server C1), and incoming rules indicate: deny cloud server C1 (i.e., cloud server C2 does not allow cloud server C1 to access). Therefore, based on the outgoing rules in security group information 601a and the incoming rules in security group information 602a, the transmission relationship in the transmission direction from cloud server C1 to cloud server C2 (i.e., the transmission direction in which cloud server C1 sends data to cloud server C2) can be determined as follows: Isolation exists (e.g., ...). Figure 6 (As shown in 603a). Similarly, based on the inbound rules in security group information 601a and the outbound rules in security group information 602a, the transmission relationship in the transmission direction of cloud server C2 → cloud server C1 (i.e., the transmission direction of data transmission from cloud server C2 to cloud server C1) can be determined as follows: isolation exists (e.g., as shown in 603a). Figure 6 (As shown in 604a). Furthermore, in the transmission direction from cloud server C1 to cloud server C2, and in both transmission directions from cloud server C2 to cloud server C1, the transmission relationships indicate the existence of isolation. Therefore, the network isolation analysis results between cloud server C1 and cloud server C2 indicate that network isolation exists (e.g., ...). Figure 6 (As shown in 605a).

[0174] It should be understood that when the first cloud server and the second cloud server belong to the same private network (i.e., the first private network and the second private network are the same private network), it is possible to determine whether the first cloud server and the second cloud server belong to the same subnet, that is, to determine whether the first subnet and the second subnet are the same subnet. If they belong to different subnets, it is possible to further determine whether there is network isolation between the first cloud server and the second cloud server based on the access control list information of the subnet.

[0175] Specifically, the first initial network configuration information includes the access control list information of the first subnet to which the first cloud server belongs, and the first subnet belongs to the first private network; the second initial network configuration information includes the access control list information of the second subnet to which the second cloud server belongs, and the second subnet belongs to the second private network; the embodiments of this application may further include: when the first private network and the second private network are the same private network, and the first subnet and the second subnet are different subnets under the same private network, determining the first subnet outgoing rule and the first subnet incoming rule of the first subnet from the access control list information of the first subnet, and determining the second subnet outgoing rule and the second subnet incoming rule of the second subnet from the access control list information of the second subnet; determining the subnet configuration association relationship between the first cloud server and the second cloud server based on the first subnet outgoing rule, the first subnet incoming rule, the second subnet outgoing rule and the second subnet incoming rule; the subnet configuration association relationship includes the subnet configuration isolation relationship; if the subnet configuration association relationship is the subnet configuration isolation relationship, then determining the first analysis result used to indicate that there is network isolation between the first cloud server and the second cloud server, and using the first analysis result as the first type of network isolation analysis result.

[0176] The method for determining the subnet configuration association between the first cloud server and the second cloud server based on the first subnet outgoing rule, the first subnet incoming rule, the second subnet outgoing rule, and the second subnet incoming rule can be referred to the relevant description above, and will not be repeated here.

[0177] It should be understood that when the first cloud server and the second cloud server belong to the same private network (i.e., the first private network and the second private network), it is possible to determine whether the first cloud server and the second cloud server belong to the same subnet, that is, to determine whether the first subnet and the second subnet are the same subnet. If they belong to the same subnet, it is possible to directly determine whether the first cloud server and the second cloud server have network isolation based on the security group information of the cloud server.

[0178] Specifically, the embodiments of this application may further include: when the first private network and the second private network are the same private network, and the first subnet and the second subnet are the same subnet under the same private network, determining the first outgoing rule and the first incoming rule of the first cloud server from the first security group information, and determining the second outgoing rule and the second incoming rule of the second cloud server from the second security group information; and determining the first type of network isolation analysis result based on the first outgoing rule, the first incoming rule, the second outgoing rule and the second incoming rule.

[0179] The network isolation analysis process is illustrated here. Please refer to the diagrams. Figure 7 , Figure 7 This is a schematic diagram of a network isolation analysis process provided in an embodiment of this application. Figure 7As shown, any two cloud servers can be selected from the N cloud servers to be tested for network isolation, and then the network connection information of the private networks to which the two cloud servers belong can be obtained (e.g., Figure 7 As shown in S701a), it can then determine whether the two cloud servers are on the same private network (e.g., Figure 7 As shown in S702a), if they belong to the same private network, it can be further determined whether the two cloud servers belong to the same subnet (e.g., Figure 7 As shown in S704a), if they belong to the same subnet, the security group information of the two cloud servers can be obtained (e.g., ...). Figure 7 As shown in S707a), it is possible to determine whether the security group information indicates the presence of isolation (such as...). Figure 7 As shown in S708a). If the security group information indicates that isolation exists, the analysis results indicating network isolation between the two cloud servers are obtained (e.g., Figure 7 As shown in S709a), if the security group information indicates that network connectivity exists, then the analysis results indicating that network connectivity exists between the two cloud servers are obtained (e.g., ...). Figure 7 (As shown in S710a).

[0180] Additionally, if the two cloud servers do not belong to the same private network, it is possible to further determine whether network isolation exists between the private networks based on their network connection information (e.g., Figure 7 As shown in S703a), if there is network isolation between the private networks (such as...) Figure 7 As shown in S703a), the analysis results indicating network isolation between the two cloud servers can be directly obtained (e.g., Figure 7 As shown in S709a). If there are network connections between the private networks (such as...) Figure 7 As shown in S703a), the access control list information of the subnets to which the two cloud servers belong can be obtained (e.g., Figure 7 As shown in S705a), it then determines whether isolation exists between the two servers based on the subnet's access control list information, that is, it determines whether the access control list information indicates whether isolation exists (e.g., ...). Figure 7 As shown in S706a), if the access control list information indicates that there is isolation between two servers, then the analysis results indicating network isolation between the two cloud servers can be directly obtained (e.g., Figure 7 As shown in S709a). If the access control list information indicates that there is a network connection between the two servers, then the security group information of the two cloud servers can be obtained (e.g., ...). Figure 7 As shown in S707a), it is possible to determine whether the security group information indicates the presence of isolation (such as...). Figure 7As shown in S708a). If the security group information indicates that isolation exists, the analysis results indicating network isolation between the two cloud servers are obtained (e.g., Figure 7 As shown in S709a), if the security group information indicates that network connectivity exists, then the analysis results indicating that network connectivity exists between the two cloud servers are obtained (e.g., ...). Figure 7 (As shown in S710a).

[0181] Additionally, when two cloud servers belong to the same private network but different subnets within that same private network, it is possible to obtain the access control list information (such as...) of the subnets to which the two cloud servers belong (e.g.,...). Figure 7 As shown in S705a), it then determines whether isolation exists between the two servers based on the subnet's access control list information, that is, it determines whether the access control list information indicates whether isolation exists (e.g., ...). Figure 7 As shown in S706a), if the access control list information indicates that there is network isolation between two servers, then the analysis results indicating that there is network isolation between two cloud servers can be directly obtained (e.g., Figure 7 As shown in S709a). If the access control list information indicates that there is a network connection between the two servers, then the security group information of the two cloud servers can be obtained (e.g., ...). Figure 7 As shown in S707a), it is possible to determine whether network isolation exists as indicated by security group information (e.g., Figure 7 As shown in S708a). If the security group information indicates that network isolation exists, the analysis results indicating that network isolation exists between the two cloud servers are obtained (e.g., Figure 7 As shown in S709a), if the security group information indicates that network connectivity exists, then the analysis results indicating that network connectivity exists between the two cloud servers are obtained (e.g., ...). Figure 7 (As shown in S710a).

[0182] For example, see Figure 8 , Figure 8 This is a schematic diagram illustrating the effect of a cloud server provided in an embodiment of this application. Figure 8The diagram illustrates connectivity between cloud server C1 and cloud server C2 within the same subnet (sub1) of the same private network (VPC1). Security group information SG1 is configured for cloud server C1, and security group information SG2 is configured for cloud server C2. SG1 on cloud server C1 indicates that cloud server C2 is allowed to access port 80, allowing cloud server C2 to send data to port 80 of cloud server C1. Similarly, SG2 on cloud server C2 indicates that cloud server C1 is allowed to access port 3036, allowing cloud server C1 to send data to port 3306 of cloud server C2.

[0183] S103. If the first type of network isolation analysis result indicates that there is a network connection between the first cloud server and the second cloud server, then perform network connectivity verification on the first cloud server and the second cloud server to obtain a network verification result for the first type of network isolation analysis result; the network verification result may be the same as or different from the first type of network isolation analysis result.

[0184] It should be understood that, based on the above description, if the first type of network isolation analysis results indicate that there is network connectivity between the first cloud server and the second cloud server, it means that the cloud platform has configured the first cloud server and the second cloud server to have network connectivity (i.e., connectivity). However, the tenant may have deployed some security measures (such as firewalls) on the first cloud server and the second cloud server, which may result in network isolation (i.e., disconnection) between the first cloud server and the second cloud server. Therefore, it is necessary to further verify the isolation between the first cloud server and the second cloud server to improve the accuracy of network isolation detection.

[0185] It is understandable that the network verification result refers to the result obtained from verifying network connectivity between the first cloud server and the second cloud server. This network verification result can indicate that network isolation exists between the first and second cloud servers. In this case, the network verification result differs from the first type of network isolation analysis result, meaning the tenant may have configured an additional firewall on the cloud server. Alternatively, the network verification result can indicate that network connectivity exists between the first and second cloud servers. In this case, the network verification result is the same as the first type of network isolation analysis result, meaning the tenant has not configured an additional firewall on the cloud server. Furthermore, the network verification result can be defined as the network isolation detection result corresponding to the first and second cloud servers.

[0186] Specifically, determining the network verification result for the first type of network isolation analysis result can be achieved by calling the automated command execution component provided by the cloud platform to notify the cloud server to execute a network isolation query command in order to determine whether the cloud servers are truly connected.

[0187] The automated command execution component provides a way to execute commands on a cloud server without logging in. Also known as an automation assistant, it's a native cloud server operation and maintenance deployment tool. This allows target detection devices to automatically execute network isolation query commands on the cloud server. For example, the automated command execution component deployed on the target detection device can send a notification to the cloud server, enabling the cloud server to automatically execute the task indicated in the notification (such as executing a network isolation query command). This network isolation query command can be executed by the cloud server to check whether there is connectivity (i.e., network isolation) with another cloud server. For instance, the automated command execution component can instruct the first cloud server to execute the following network isolation query command: `telnet 192.168.3.4 80`. This checks whether the first cloud server can access port 80 of the cloud server with IP address 192.168.3.4.

[0188] Understandably, when it is determined that there is network isolation between the first cloud server and the second cloud server based on the initial network configuration information, the analysis result of the network isolation between the first cloud server and the second cloud server can be directly determined as the final result of the network isolation detection, without the need for further network connectivity verification.

[0189] Specifically, if the first type of network isolation analysis result indicates that there is network isolation between the first cloud server and the second cloud server, then the first type of network isolation analysis result is determined as the network isolation detection result corresponding to the first cloud server and the second cloud server.

[0190] Please see Figure 9 , Figure 9 This is a schematic flowchart of a network isolation detection method provided in an embodiment of this application. Figure 9 As shown, the initial network configuration information of the two cloud servers to be tested for network isolation can be obtained (step S801a). Then, based on the initial network configuration information of the two cloud servers, network isolation analysis can be performed (step S802a). The specific network isolation analysis process can be referred to the above. Figure 7The process described in detail here is not elaborated. It is understandable that during network isolation analysis, an analysis result indicating the existence of network isolation can be obtained (step S803a), thus directly determining the final network isolation detection result as: network isolation exists (step S808a). During network isolation analysis, an analysis result indicating the existence of network connectivity can also be obtained (step S804a). Then, network connectivity verification can be performed through an automated command execution component (step S805a), and a verification result indicating the existence of network isolation can be obtained through network connectivity verification (step S806a). Based on this verification result, the final network isolation detection result can be determined as: network isolation exists (step S808a). If network connectivity verification is performed, a verification result indicating the existence of network connectivity can be obtained (step S807a), and based on this verification result, the final network isolation detection result can be determined as: network connectivity exists (step S809a). Therefore, network connectivity verification can be performed through an automated command execution component, improving the accuracy of network isolation detection.

[0191] It should be understood that, in this embodiment, the method for network isolation analysis and network connectivity verification between the first and second cloud servers described above can be used to detect the network isolation between any two cloud servers among N cloud servers. This allows for the determination of the network isolation detection result between any two cloud servers among the N cloud servers, and the determination of the task execution result for the verification task based on this result. Furthermore, the task execution result can be sent to the target management account and the verification account. It should be understood that when determining the task execution result for the verification task based on the network isolation detection result between any two cloud servers among N cloud servers, the cloud servers with network isolation and those with network connectivity can be counted to obtain the task execution result, facilitating the target management object and the verification object to view the network isolation among the N cloud servers. Optionally, a task result graph can be constructed based on N cloud servers, including those with network isolation and those with network connectivity. This task result graph can include multiple nodes, with each node corresponding to a cloud server. The edges between nodes indicate that there is network connectivity between the cloud servers. If there is no edge between two nodes, it indicates that there is network isolation between the corresponding servers. This allows the target management object and the verification object to more intuitively view the network isolation between the N cloud servers.

[0192] Further, please see Figure 10 , Figure 10This is a flowchart illustrating a network detection method provided in an embodiment of this application. The method can be executed by a target detection device used to perform network isolation detection on N cloud servers. For example, the target detection device is... Figure 1 The target detection device 100a in the method includes N cloud servers, including a first cloud server and a second cloud server. The method may include at least the following steps S201-S204.

[0193] S201. Obtain first network data information of the first cloud server and second network data information of the second cloud server; both the first network data information and the second network data information include initial network configuration information configured by cloud platform service devices associated with N cloud servers.

[0194] It should be understood that, based on the above description, the N cloud servers can be determined based on the verification task.

[0195] Optionally, embodiments of this application may further include the following steps: when a verification task associated with a verification account is obtained, N cloud servers to be isolated for verification are determined based on the verification task; N is a positive integer; the verification account has the role permissions of the target role; the target role is configured based on the target management account, and the role permissions of the target role include data access permissions to obtain network data information of the N cloud servers; any two cloud servers among the N cloud servers are determined as the first cloud server and the second cloud server.

[0196] The target management account can be an account used for account management. For example, in some scenarios, the target management account can be the account of an administrator in enterprise Q1, where enterprise Q1 is a tenant of a cloud server, and the verification account is the account of a person in enterprise Q2 who manages the cloud server rented by enterprise Q1. In this case, the target management account can authorize the verification account by binding a role to the verification account, thereby achieving authorization across the main account (i.e., the target management account and the verification account).

[0197] However, it should be understood that the verification account possesses the role permissions of the target role; in other words, the verification account is used to assume the target role (or the target role is bound to the verification account). The target role can be a role used for network isolation verification, and this target role has corresponding role permissions. For example, the target role's role permissions may include data access permissions to obtain network data information from N cloud servers. This target role is configured through the target management account. For instance, enterprise personnel can use the target management account to configure data access permissions for this target role to obtain network data information from N cloud servers.

[0198] Specifically, methods for authorizing verification accounts through target management accounts may include: creating a target role for the verification account, configuring permission policies for the target role, and binding the verification account to the target role that has the permission policies.

[0199] Cloud vendors' (such as cloud platform service providers) access management (CAM) mechanisms typically include role functionality. Roles can be created through the access management console or via the CAM API (Access Management API interface). For example, a role named ForNetWorkRole can be created using the target management account 123456, with the role carrier being the verification account 456789. The verification account can then assume this role, allowing it to operate on the resources configured for that role by the target management account and obtain network configuration information according to the policies bound to that role. An example of parameters for creating a role via the cloud API is shown below:

[0200]

[0201]

[0202] Furthermore, policies can be bound to the created roles. Access management for cloud service providers (i.e., cloud vendors) typically includes policy functionality, which is a collection of permissions. Policies can be created in the access management console or through the CAM API (Access Management API interface), and then bound to roles. For example, a policy can be created to allow VPC permissions for a specific region (e.g., area1), with the following content:

[0203]

[0204] Furthermore, the above strategy can be bound to the ForNetWorkRole role created above through CAM APIs (such as the AttachRolePolicy interface).

[0205] Furthermore, the verified account assumes a role, meaning a role with configured policies is bound to the verified account. Adding policies to a verified account allows it to assume a role, thereby gaining the relevant permissions provided by the policy to which the role is bound. For example, verified account 456789 assumes the ForNetworkRole role of the target administrator account 123456, with the following policy:

[0206]

[0207]

[0208] S202. Based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, perform network isolation analysis on the first cloud server and the second cloud server to obtain the first type of network isolation analysis results.

[0209] Step S202 can be referred to the relevant description of step S102 above, and will not be repeated here.

[0210] S203. If the first type of network isolation analysis result indicates that there is no network isolation between the first cloud server and the second cloud server, then obtain the automated command execution component, call the automated command execution component to notify the first cloud server and the second cloud server to execute the network isolation query command respectively, and obtain the corresponding command query result.

[0211] It should be understood that, based on the above description, the automated command execution component can be a way to execute commands on a cloud server without needing to log in. Network isolation query commands can be referred to the relevant descriptions above, and will not be repeated here.

[0212] It should be understood that, in the embodiments of this application, when the automated command execution component is invoked to notify the first cloud server and the second cloud server to execute network isolation query commands respectively, the first cloud server can be notified to execute a network isolation query command to query whether the first cloud server can access the second cloud server, and the second cloud server can be notified to execute a network isolation query command to query whether the second cloud server can access the first cloud server.

[0213] Specifically, invoking the automated command execution component to notify the first cloud server and the second cloud server to execute network isolation query commands respectively and obtain the corresponding command query results may include the following steps: Invoking the automated command execution component to notify the first cloud server to execute a first query command and obtain the first command query result corresponding to the first query command; the first query command is used to instruct the first cloud server to query the isolation in a first transmission direction; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server; Invoking the automated command execution component to notify the second cloud server to execute a second query command and obtain the second command query result corresponding to the second query command; the second query command is used to instruct the second cloud server to query the isolation in a second transmission direction; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

[0214] The first transmission direction refers to the transmission direction of data from the first cloud server to the second cloud server, and the second transmission direction refers to the transmission direction of data from the second cloud server to the first cloud server. For details, please refer to the above descriptions, which will not be repeated here.

[0215] It should be understood that the first query command can be a network isolation query command executed by the first cloud server. The first query command instructs the first cloud server to query the isolation in the first transmission direction, that is, to query whether the first cloud server can access the second cloud server. The first command query result refers to the result of the first query command executed by the first cloud server. This first command query result can be used to indicate whether network isolation or network connectivity exists between the first cloud server and the second cloud server in the first transmission direction. Specifically, the first query command can determine whether the first cloud server can access the second cloud server. If the query indicates that the first cloud server can access the second cloud server, then network connectivity exists in the first transmission direction; if the query indicates that the first cloud server cannot access the second cloud server, then network isolation exists in the first transmission direction.

[0216] The second query command can be a network isolation query command executed by the second cloud server. This command instructs the second cloud server to query the isolation in the second transmission direction, specifically whether the second cloud server can access the first cloud server. The query result indicates whether network isolation or connectivity exists between the first and second cloud servers in the second transmission direction. Specifically, the second query command can determine whether the second cloud server can access the first cloud server. If the second cloud server can access the first cloud server, network connectivity exists in the second transmission direction; if the second cloud server cannot access the first cloud server, network isolation exists in the second transmission direction.

[0217] For example, the IP address of the first cloud server is 192.168.3.4, and the IP address of the second cloud server is 192.168.3.10. The first query command executed on the first cloud server could be: `telnet 192.168.3.1080`. This would query whether the first cloud server can access port 80 of the second cloud server (IP address 192.168.3.10), thus determining whether there is network isolation between the first and second cloud servers in the first transmission direction. If the first cloud server can determine through this first query command that it can access the second cloud server, then there is network connectivity between the first and second cloud servers in the first transmission direction; otherwise, network isolation exists. The second query command executed on the second cloud server can be: telnet 192.168.3.4 3306. This will query whether the second cloud server can access port 3306 of the first cloud server with IP address 192.168.3.4, thus determining whether there is network isolation between the first cloud server and the second cloud server in the second transmission direction. If the second cloud server can determine through this second query command that it can access the first cloud server, then it is determined that there is network connectivity between the first cloud server and the second cloud server in the second transmission direction; otherwise, it is determined that there is network isolation.

[0218] S204. Receive the command query results returned by the first cloud server and the second cloud server respectively, and determine the network verification result for the first type of network isolation analysis result based on the received command query results.

[0219] It should be understood that, based on the above description, the first cloud server and the second cloud server can be notified to execute network isolation query commands respectively, and the query results returned by the first cloud server and the second cloud server can be received. Then, based on the received query results between the two cloud servers, the isolation verification result between the first cloud server and the second cloud server is determined. It should be understood that this network verification result may be the same as or different from the first type of network isolation analysis result; this will not be elaborated upon here.

[0220] Specifically, the command query result returned by the first cloud server is the first command query result, and the command query result returned by the second cloud server is the second command query result. Based on the received command query results, determining the network verification result for the first type of network isolation analysis result can include the following steps: If the first command query result indicates network isolation in the first transmission direction, and the second command query result indicates network isolation in the second transmission direction, then a first verification result indicating network isolation exists between the first cloud server and the second cloud server in both the first and second transmission directions is determined, and this first verification result is identified as the network verification result. If the first command query result indicates network connectivity in the first transmission direction, and the second command query result indicates network connectivity in the second transmission direction, then a second verification result indicating network connectivity exists between the first cloud server and the second cloud server in both the first and second transmission directions is determined, and this second verification result is identified as the network verification result. If the first command query result indicates network connectivity in the first transmission direction, and the second command query result indicates network isolation in the second transmission direction, then a third verification result indicating network connectivity exists between the first cloud server and the second cloud server in the first transmission direction, and network isolation exists in the second transmission direction is determined, and this third verification result is identified as the network verification result.

[0221] It should be understood that the first verification result can refer to a verification result indicating that there is network isolation between the first cloud server and the second cloud server in both the first and second transmission directions. The second verification result can refer to a verification result indicating that there is no network isolation between the first cloud server and the second cloud server in both the first and second transmission directions. The third verification result can refer to a verification result indicating that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction.

[0222] It should be understood that if the query result of the first command indicates that there is network isolation in the first transmission direction and network connectivity in the second transmission direction (i.e., there is no network isolation), then the fourth verification result used to indicate that there is network isolation between the first cloud server and the second cloud server in the first transmission direction and network connectivity in the second transmission direction is determined, and the third verification result is determined as the network verification result.

[0223] It should be understood that the verified network verification result can be determined as the final result of the network isolation test between the first cloud server and the second cloud server (i.e., the network isolation test result).

[0224] For example, see Figure 11 , Figure 11This is a schematic diagram of a network connectivity verification process provided in an embodiment of this application. It can be understood that the cloud servers to be verified for network connectivity are cloud server C1 and cloud server C2. When performing network isolation analysis, cloud server C1 and cloud server C2 determine that there is network connectivity between them based on network configuration information. Further, target detection device 100a can invoke an automated command execution component to notify cloud server C1 to execute a first query command (i.e., step S1001a). Then, cloud server C1 can return a command query result J1 to target detection device 100a (i.e., step S1002a). This command query result J1 can refer to the command query result obtained by cloud server C1 executing the first query command. Furthermore, the target detection device 100a can invoke the automated command execution component to notify the cloud server C2 to execute the second query command (i.e., step S1003a). Subsequently, the cloud server C2 can return the command query result J2 to the target detection device 100a (i.e., step S1004a). This command query result J2 can refer to the command query result obtained by the cloud server C2 executing the second query command. Further, based on the received command query result J1 and command query result J2, the target detection device 100a can determine whether network isolation exists between the cloud server C1 and the cloud server C2, thus obtaining the final result of the network isolation detection.

[0225] Optionally, in some cases, if network isolation analysis shows that the first cloud server and the second cloud server are unidirectionally connected, such as network isolation in the first transmission direction and network connectivity in the second transmission direction, then network connectivity verification is only performed on the isolation in the transmission direction with network connectivity. This can further reduce the amount of computation, improve the efficiency of network isolation detection, and reduce the impact of network isolation detection on the services on the cloud server itself.

[0226] Specifically, the first type of network isolation analysis result includes a third analysis result indicating that the first cloud server and the second cloud server have network connectivity in the first transmission direction and network isolation in the second transmission direction; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server; network connectivity verification is performed on the first cloud server and the second cloud server to obtain a network verification result for the first type of network isolation analysis result, including: if the first type of network isolation analysis result is the third analysis result, then obtaining an automated command execution component; invoking the automated command execution component to notify the first cloud server to execute a first query command, and obtaining the result corresponding to the first query command. The first command query result; the first query command is used to instruct the first cloud server to query the isolation in the first transmission direction; the first command query result returned by the first cloud server is received; if the first command query result indicates that there is network connectivity in the first transmission direction, then a third verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction, and the third verification result is determined as the network verification result; if the first command query result indicates that there is network isolation in the first transmission direction, then a first verification result is determined to indicate that there is network isolation between the first cloud server and the second cloud server in both the first and second transmission directions, and the first verification result is determined as the network verification result.

[0227] The method of calling the automated command execution component to notify the first cloud server to execute the first query command can be referred to the above description, and will not be repeated here.

[0228] For example, see Figure 12 , Figure 12 This application provides a schematic flowchart for network connectivity verification. It is understood that the cloud servers to be verified for network connectivity are cloud server C1 and cloud server C2. The first type of network isolation analysis results obtained by cloud server C1 and cloud server C2 during network isolation analysis can be referred to as follows... Figure 12As shown in the first type of network isolation analysis result 1101a, in the transmission direction from cloud server C1 to cloud server C2, there is network connectivity; in the transmission direction from cloud server C2 to cloud server C1, there is network isolation. This allows for further verification of the isolation in the transmission direction from cloud server C1 to cloud server C2. Specifically, target detection device 100a can invoke the automated command execution component to notify cloud server C1 to execute the first query command (i.e., step S1102a). Cloud server C1 can then return the command query result J3 to target detection device 100a (i.e., step S1003a). This command query result J3 refers to the command query result obtained by cloud server C1 executing the first query command. Furthermore, the target detection device 100a can determine the isolation between cloud server C1 and cloud service C2 in the transmission direction from cloud server C1 to cloud server C2 based on the received command query result J3. Thus, based on the isolation between cloud server C2 and cloud server C1 in the transmission direction from cloud server C2 to cloud server C1 in the first type of network isolation analysis result 1101a and the verified isolation between cloud server C1 and cloud server C2, the network isolation between cloud server C1 and cloud server C2 is determined.

[0229] Similarly, the first type of network isolation analysis results include a fourth analysis result indicating that the first cloud server and the second cloud server are network isolated in the first transmission direction and network connected in the second transmission direction; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server; network connectivity verification is performed on the first cloud server and the second cloud server to obtain network verification results for the first type of network isolation analysis results, including: if the first type of network isolation analysis result is the fourth analysis result, then obtaining the automated command execution component; invoking the automated command execution component to notify the second cloud server to execute the second query command, and obtaining the result corresponding to the second query command. The second command query result; the second query command is used to instruct the second cloud server to query the isolation in the second transmission direction; receive the second command query result returned by the second cloud server; if the second command query result indicates that there is network connectivity in the second transmission direction, then determine the fourth verification result used to indicate that there is network isolation between the first cloud server and the second cloud server in the first transmission direction, and that there is network connectivity in the second transmission direction, and determine the fourth verification result as the network verification result; if the second command query result indicates that there is network isolation in the second transmission direction, then determine the first verification result used to indicate that there is network isolation between the first cloud server and the second cloud server in both the first and second transmission directions, and determine the first verification result as the network verification result.

[0230] This section illustrates the entire network isolation detection process with illustrations. Please refer to [link / reference]. Figure 13 , Figure 13 This is a schematic diagram of a network isolation detection process provided in an embodiment of this application. Figure 13 As shown, the target management object (such as...) Figure 13 As shown in 1201a, this can be for personnel in enterprises renting cloud servers, and the target management objects can be managed through target management devices (such as...). Figure 13 As shown in 1204a), on the cloud platform (such as...) Figure 13 Log in to the target management account (as shown in 1202a) to access the cloud platform's access management mechanism (such as...). Figure 13 As shown in 1203a, authorization is granted for the verification account. The target management object can then configure verification tasks and view the configured verification tasks through the target management device 1204a. Furthermore, the target management object can distribute the configured verification tasks to the target detection device (such as...) through the target management device. Figure 13 As shown in 1205a), the target detection device can be logged into with a verified account, which can be an account corresponding to a user specifically used for network isolation detection.

[0231] Furthermore, the target detection device 1205a can call cloud server interfaces (such as...). Figure 13 As shown in 1206a) from the cloud platform (such as Figure 13 As shown in 1207a, the network data information obtained can be described in the above descriptions and will not be repeated here. It should be understood that the target detection device can perform network isolation analysis based on the obtained network data information. Therefore, when the analysis reveals a network connection between two cloud servers, it can invoke automated command execution components (such as...) Figure 13 As shown in 1208a), notify the cloud server (such as...). Figure 13 As shown in 1209a, executing the network isolation query command should be understood in detail above, and will not be repeated here. Based on this, the target detection device can determine the final network isolation detection result between cloud servers by executing the network isolation query command, thereby accurately determining the network isolation between cloud servers while ensuring detection efficiency.

[0232] Optionally, in this embodiment of the application, the network isolation analysis between the first cloud server and the second cloud server can also be determined based on the traffic mirroring data in the network data information of the cloud server.

[0233] Further, please see Figure 14 , Figure 14This is a flowchart illustrating a network detection method provided in an embodiment of this application. The method can be executed by a target detection device used to perform network isolation detection on N cloud servers. For example, the target detection device is... Figure 1 The target detection device 100a in the method includes N cloud servers, including a first cloud server and a second cloud server. The method may include at least the following steps S301-S303.

[0234] S301. Obtain first network data information of the first cloud server and second network data information of the second cloud server; the first network data information includes first traffic mirror data of the first cloud server and the second network data information includes second traffic mirror data of the second cloud server.

[0235] The first traffic mirror data refers to the traffic mirror data of the first cloud server, and the second traffic mirror data can be the traffic mirror data of the second cloud server. It should be understood that this traffic mirror data can be obtained by the target detection device from the cloud platform server device by calling the corresponding cloud service interface.

[0236] It's understandable that traffic mirroring data can record traffic logs for cloud servers. Traffic logs refer to records of incoming and outgoing traffic to cloud servers. For example, traffic mirroring data for cloud server C1 can record each time cloud server C1 actively accesses another cloud server, generating a traffic log entry to record which port of which cloud server C1 accessed, the protocol used, and other information. Similarly, each time cloud server C1 is accessed by another cloud server, a traffic log entry can be generated to record which port of cloud server C1 was accessed by which cloud server, that is, which port of cloud server C1 received data sent from which cloud server, and the protocol used, etc.

[0237] However, it should be understood that the traffic mirroring data obtained for network isolation analysis refers to traffic mirroring data within a relatively recent period (e.g., a period of time less than or equal to a certain threshold) from the current time (i.e., the time the request for traffic mirroring data was made). For example, it could be traffic mirroring data from the last 3 days. Generally, traffic mirroring data from a period too far removed from the current time will not be obtained, as the network configuration of the cloud server may change during this period. Therefore, it is necessary to ensure the timeliness of the obtained traffic mirroring data to improve the accuracy of network isolation analysis.

[0238] S302. Based on the first traffic mirror data and the second traffic mirror data, perform network isolation analysis on the first cloud server and the second cloud server to obtain the second type of network isolation analysis results.

[0239] Among them, the second type of network isolation analysis results can be the analysis results obtained by performing network isolation analysis on the first cloud server and the second cloud server based on traffic mirroring data. It should be understood that when performing network isolation analysis on the first and second cloud servers based on traffic mirroring data, the analysis can involve searching for traffic log data showing communication between the two cloud servers. If such data is found, it indicates a network connection between the two cloud servers, thus confirming the network isolation detection result between them. If no such data is found, it suggests potential network isolation (i.e., potential network connection). This could be due to missing traffic log data or the two connected cloud servers not actually exchanging data. Therefore, when the second type of network isolation analysis indicates network isolation between the two cloud servers, further network isolation verification should be performed using an automated command execution component to verify whether network isolation truly exists between the cloud servers identified as having it based on traffic mirroring. Finally, based on the network isolation verification result obtained from the second type of network isolation analysis (i.e., the network verification result), the final detection result between the two cloud servers can be determined.

[0240] Specifically, based on the first and second traffic mirror data, network isolation analysis is performed on the first and second cloud servers to obtain a second type of network isolation analysis result. This can include the following steps: Searching for traffic log data indicating data interaction between the first and second cloud servers in the first and second traffic mirror data to obtain log search results; if the log search results indicate that no traffic log data indicating data interaction was found, then a first analysis result indicating network isolation exists between the first and second cloud servers is determined, and this first analysis result is used as the second type of network isolation analysis result; if the log search results indicate that traffic log data indicating data interaction was found, then a second analysis result indicating network connectivity exists between the first and second cloud servers is determined, and this second analysis result is used as the second type of network isolation analysis result.

[0241] The log search result refers to the result obtained by searching for traffic log data of data interaction between the first cloud server and the second cloud server in the first traffic mirror data and the second traffic mirror data. The log search result can be used to indicate that no traffic log data of data interaction was found, or it can be used to indicate that traffic log data of data interaction was found.

[0242] Specifically, when the log search results indicate that no traffic log data for data interaction was found, this can mean that no traffic log data showing successful access from the first cloud server to the second cloud server was found in the first traffic mirror data, and no traffic log data showing successful access from the second cloud server to the first cloud server was found in the second traffic mirror data. The absence of traffic log data showing successful access from the first cloud server to the second cloud server in the first traffic mirror data could mean that no traffic log data showing access from the first cloud server to the second cloud server was found, or it could mean that only traffic log data showing the first cloud server denied access to the second cloud server was found. Similarly, the absence of traffic log data showing successful access from the second cloud server to the first cloud server in the second traffic mirror data could mean that no traffic log data showing access from the second cloud server to the first cloud server was found, or it could mean that only traffic log data showing the second cloud server denied access to the first cloud server was found.

[0243] Specifically, when the log search result indicates that traffic log data for data interaction has been found, it can mean that the traffic log data of the first cloud server being successfully accessed by the second cloud server was found in the first traffic mirror data, or that the traffic log data of the second cloud server being successfully accessed by the first cloud server was found in the second traffic mirror data.

[0244] S303. If the second type of network isolation analysis result indicates that there is network isolation between the first cloud server and the second cloud server, then perform network isolation verification on the first cloud server and the second cloud server to obtain the network verification result for the second type of network isolation analysis result.

[0245] It should be understood that, for the second type of network isolation analysis results, there may be situations such as lost traffic log data, or that two cloud servers that are actually connected to the network may not be interacting with each other. Therefore, when the second type of network isolation analysis results indicate that there is network isolation between two cloud servers, it is necessary to further verify the network connectivity through an automated command execution component.

[0246] The method for verifying network connectivity between the first cloud server and the second cloud server to obtain the network verification result for the second type of network isolation analysis can be referred to the relevant description above, and will not be repeated here.

[0247] Please see Figure 15 , Figure 15 This is a schematic diagram of the structure of a network detection device provided in an embodiment of this application. Figure 15As shown, the network detection device 1 can be a computer program (including program code) running on a target detection device (e.g., the target detection device 100a described above) used for network isolation detection of N cloud servers. For example, the network detection device 1 is an application software, and the N cloud servers include a first cloud server and a second cloud server. It is understood that the network detection device 1 can be used to execute the corresponding steps in the network detection method provided in the embodiments of this application. Figure 15 As shown, the network detection device 1 may include: a network data acquisition module 11, a network isolation analysis module 12, and a network verification module 13;

[0248] The network data acquisition module 11 is used to acquire first network data information of the first cloud server and second network data information of the second cloud server; both the first network data information and the second network data information include initial network configuration information configured by the cloud platform service device associated with N cloud servers.

[0249] Network isolation analysis module 12 is used to perform network isolation analysis on the first cloud server and the second cloud server based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, and obtain the first type of network isolation analysis results;

[0250] The network verification module 13 is used to verify the network connectivity between the first cloud server and the second cloud server if the first type of network isolation analysis result indicates that there is a network connection between the first cloud server and the second cloud server, and obtain a network verification result for the first type of network isolation analysis result; the network verification result may be the same as or different from the first type of network isolation analysis result.

[0251] Wherein, the initial network configuration information in the first network data information is the first initial network configuration information, and the initial network configuration information in the second network data information is the second initial network configuration information; the first initial network configuration information includes the first network connection information of the first private network to which the first cloud server belongs; the second initial network configuration information includes the second network connection information of the second private network to which the second cloud server belongs.

[0252] Network isolation analysis module 12 includes: network correlation analysis unit 121;

[0253] Network Relationship Analysis Unit 121 is specifically used for:

[0254] When the first private network and the second private network are different private networks, the private network that is allowed to access the first private network is determined from the first network connection information, and the private network that is allowed to access the second private network is determined from the second network connection information.

[0255] Based on the private networks that are allowed to access the first private network and the private networks that are allowed to access the second private network, the network association relationship between the first private network and the second private network is determined; the network association relationship includes the network isolation relationship; the network isolation relationship is determined when the second private network is not included in the private networks that are allowed to access the first private network, and the first private network is not included in the private networks that are allowed to access the second private network.

[0256] If the network association relationship is a network isolation relationship, then the first analysis result is determined to indicate that there is network isolation between the first cloud server and the second cloud server, and the first analysis result is used as the first type of network isolation analysis result.

[0257] The network association includes network connectivity; the network connectivity is determined when the private network that allows access to the first private network includes the second private network, and the private network that allows access to the second private network includes the first private network; the first initial network configuration information includes the access control list information of the first subnet to which the first cloud server belongs, and the first subnet belongs to the first private network; the second initial network configuration information includes the access control list information of the second subnet to which the second cloud server belongs, and the second subnet belongs to the second private network;

[0258] The network isolation analysis module 12 also includes: a subnet configuration relationship analysis unit 122;

[0259] Subnet configuration relationship analysis unit 122 is specifically used for:

[0260] If the network association between the first private network and the second private network is a network connectivity relationship, then the first subnet outgoing rules and the first subnet incoming rules of the first subnet are determined from the access control list information of the first subnet, and the second subnet outgoing rules and the second subnet incoming rules of the second subnet are determined from the access control list information of the second subnet.

[0261] Based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the subnet configuration association relationship between the first cloud server and the second cloud server is determined; the subnet configuration association relationship includes the subnet configuration isolation relationship.

[0262] If the subnet configuration association relationship is a subnet configuration isolation relationship, then the first analysis result used to indicate that there is network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the first type of network isolation analysis result.

[0263] The subnet configuration relationship analysis unit 122 is specifically used for:

[0264] Based on the first subnet outgoing rules and the second subnet incoming rules, the first subnet configuration relationship between the first cloud server and the second cloud server in the first transmission direction is determined; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server.

[0265] Based on the first subnet inbound rules and the second subnet outbound rules, the second subnet configuration relationship between the first cloud server and the second cloud server in the second transmission direction is determined; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

[0266] If the first subnet configuration relationship indicates that there is network isolation in the first transmission direction, and the second subnet configuration association relationship indicates that there is network isolation in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration isolation relationship.

[0267] If the first subnet configuration relationship indicates that there is network connectivity in the first transmission direction, and the second subnet configuration association relationship indicates that there is network connectivity in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration connectivity relationship.

[0268] The subnet configuration association includes the subnet configuration connectivity; the first initial network configuration information includes the first security group information of the first cloud server; and the second initial network configuration information includes the second security group information of the second cloud server.

[0269] The network isolation analysis module 12 also includes a security group analysis unit 123.

[0270] Security group analysis unit 123 is specifically used for:

[0271] If the subnet configuration association between the first cloud server and the second cloud server is a subnet configuration connectivity relationship, the first outgoing rule and the first incoming rule of the first cloud server are determined from the first security group information, and the second outgoing rule and the second incoming rule of the second cloud server are determined from the second security group information.

[0272] Based on the first outgoing rule, the first incoming rule, the second outgoing rule, and the second incoming rule, the first type of network isolation analysis results are determined.

[0273] The security group analysis unit 123 is specifically used for:

[0274] Based on the first outgoing rule and the second incoming rule, a first transmission relationship is determined in the first transmission direction of sending data from the first cloud server to the second cloud server.

[0275] Based on the first inbound rule and the second outbound rule, a second transmission relationship is determined in the second transmission direction when data is sent from the second cloud server to the first cloud server.

[0276] If the first transmission relationship indicates that there is network isolation in the first transmission direction, and the second transmission relationship indicates that there is network isolation in the second transmission direction, then a first analysis result is determined to indicate that there is network isolation between the first cloud server and the second cloud server, and the first analysis result is used as the first type of network isolation analysis result.

[0277] If the first transmission relationship indicates that there is network connectivity in the first transmission direction, and the second transmission relationship indicates that there is network connectivity in the second transmission direction, then a second analysis result indicating that there is network connectivity between the first cloud server and the second cloud server is determined, and the second analysis result is used as the first type of network isolation analysis result.

[0278] The first initial network configuration information includes the access control list information of the first subnet to which the first cloud server belongs, and the first subnet belongs to the first private network; the second initial network configuration information includes the access control list information of the second subnet to which the second cloud server belongs, and the second subnet belongs to the second private network.

[0279] The subnet configuration relationship analysis unit 122 is specifically used for:

[0280] When the first private network and the second private network are the same private network, and the first subnet and the second subnet are different subnets under the same private network, the first subnet outgoing rules and the first subnet incoming rules of the first subnet are determined from the access control list information of the first subnet, and the second subnet outgoing rules and the second subnet incoming rules of the second subnet are determined from the access control list information of the second subnet.

[0281] Based on the first subnet outgoing rules, the first subnet incoming rules, the second subnet outgoing rules, and the second subnet incoming rules, the subnet configuration association relationship between the first cloud server and the second cloud server is determined; the subnet configuration association relationship includes the subnet configuration isolation relationship.

[0282] If the subnet configuration association relationship is a subnet configuration isolation relationship, then the first analysis result used to indicate that there is network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the first type of network isolation analysis result.

[0283] The network detection device 1 further includes: a result determination module 14;

[0284] The result determination module 14 is used to determine the first type of network isolation analysis result as the network isolation detection result corresponding to the first cloud server and the second cloud server if the first type of network isolation analysis result indicates that there is network isolation between the first cloud server and the second cloud server.

[0285] The first network data information includes the first traffic mirror data of the first cloud server, and the second network data information includes the second traffic mirror data of the second cloud server.

[0286] The network detection device 1 also includes: a mirror data analysis module 15 and a mirror analysis verification module 16;

[0287] The mirror data analysis module 15 is used to perform network isolation analysis on the first cloud server and the second cloud server based on the first traffic mirror data and the second traffic mirror data, and obtain the second type of network isolation analysis results.

[0288] The mirror analysis verification module 16 is used to perform network isolation verification on the first cloud server and the second cloud server if the second type of network isolation analysis result indicates that there is network isolation between the first cloud server and the second cloud server, and obtain the network verification result for the second type of network isolation analysis result.

[0289] The mirror data analysis module 15 is specifically used for:

[0290] Search for traffic log data of data interaction between the first cloud server and the second cloud server in the first traffic mirror data and the second traffic mirror data to obtain the log search results;

[0291] If the log lookup result indicates that no traffic log data for data interaction was found, then the first analysis result indicating that there is network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the second type of network isolation analysis result.

[0292] If the log lookup result indicates that traffic log data for data interaction has been found, then the second analysis result indicating that there is no network isolation between the first cloud server and the second cloud server is determined, and the second analysis result is taken as the second type of network isolation analysis result.

[0293] The network verification module 13 includes: an automated execution unit 131 and a result verification unit 132;

[0294] The automated execution unit 131 is used to obtain the automated command execution component, call the automated command execution component to notify the first cloud server and the second cloud server to execute the network isolation query command respectively, and obtain the corresponding command query results.

[0295] The result verification unit 132 is used to receive the command query results returned by the first cloud server and the second cloud server respectively, and determine the network verification result for the first type of network isolation analysis result based on the received command query results.

[0296] The automated execution unit 131 is specifically used for:

[0297] The automated command execution component is invoked to notify the first cloud server to execute the first query command and obtain the first query result corresponding to the first query command. The first query command is used to instruct the first cloud server to query the isolation in the first transmission direction. The first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server.

[0298] The automated command execution component is invoked to notify the second cloud server to execute the second query command and obtain the query result corresponding to the second query command. The second query command is used to instruct the second cloud server to query the isolation in the second transmission direction. The second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

[0299] Among them, the command query result returned by the first cloud server is the first command query result, and the command query result returned by the second cloud server is the second command query result;

[0300] Specifically, the result verification unit 132 is used for:

[0301] If the query result of the first command indicates that there is network isolation in the first transmission direction, and the query result of the second command indicates that there is network isolation in the second transmission direction, then the first verification result used to indicate that there is network isolation between the first cloud server and the second cloud server in both the first and second transmission directions is determined, and the first verification result is determined as the network verification result.

[0302] If the query result of the first command indicates that there is network connectivity in the first transmission direction, and the query result of the second command indicates that there is network connectivity in the second transmission direction, then a second verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in both the first and second transmission directions, and the second verification result is determined as the network verification result.

[0303] If the query result of the first command indicates that there is network connectivity in the first transmission direction, and the query result of the second command indicates that there is network isolation in the second transmission direction, then a third verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction, and the third verification result is determined as the network verification result.

[0304] Specifically, when the first type of network isolation analysis result indicates that there is no network isolation between the first cloud server and the second cloud server, the first type of network isolation analysis result includes a third analysis result indicating that the first cloud server and the second cloud server have network connectivity in the first transmission direction and network isolation in the second transmission direction; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

[0305] The automated execution unit 131 is further configured to, if the first type of network isolation analysis result is the third analysis result, obtain the automated command execution component; call the automated command execution component to notify the first cloud server to execute the first query command, and obtain the first command query result corresponding to the first query command; the first query command is used to instruct the first cloud server to query the isolation in the first transmission direction;

[0306] The result verification unit 132 is also used to receive the first command query result returned by the first cloud server;

[0307] If the query result of the first command indicates that there is network connectivity in the first transmission direction, then a third verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction, and the third verification result is determined as the network verification result.

[0308] If the query result of the first command indicates that there is network isolation in the first transmission direction, then the first verification result used to indicate that there is network isolation between the first cloud server and the second cloud server in both the first and second transmission directions is determined, and the first verification result is determined as the network verification result.

[0309] The network detection device 1 also includes a task acquisition module 17.

[0310] Task acquisition module 17 is specifically used for:

[0311] When a verification task associated with a verification account is obtained, N cloud servers to be isolated for verification are determined based on the verification task; N is a positive integer; the verification account has the role permissions of the target role; the target role is configured based on the target management account, and the role permissions of the target role include data access permissions to obtain network data information of N cloud servers;

[0312] Determine any two cloud servers from the N cloud servers as the first cloud server and the second cloud server.

[0313] The network data acquisition module 11 is specifically used for:

[0314] Call the cloud service interface to send a network data acquisition request to the cloud platform service device;

[0315] Receive the request result data returned by the cloud platform service device based on the network data acquisition request, parse the network request result data to obtain the network data information of each of the N cloud servers, determine the network data information of the first cloud server as the first network data information, and determine the network data information of the second cloud server as the second network data information.

[0316] Please see Figure 16 , Figure 16 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 16 As shown, the computer device 1000 may include a processor 1001, a network interface 1004, and a memory 1005. Furthermore, the computer device 1000 may also include a user interface 1003 and at least one communication bus 1002. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen and a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 1005 may also be at least one storage device located remotely from the processor 1001. Figure 16 As shown, the memory 1005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a device control application.

[0317] In such Figure 16 In the computer device 1000 shown, the network interface 1004 provides network communication functionality; the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application stored in the memory 1005 to execute the data processing method described in any of the corresponding embodiments above, which will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.

[0318] Furthermore, it should be noted that this application also provides a computer-readable storage medium storing a computer program executed by the aforementioned network detection device 1. The computer program includes program instructions, which, when executed by the processor, enable the execution of the data processing method described in the preceding embodiments; therefore, they will not be repeated here. Additionally, the beneficial effects of using the same method will not be repeated here either. For technical details not disclosed in the embodiments of the computer-readable storage medium involved in this application, please refer to the description of the method embodiments of this application.

[0319] The aforementioned computer-readable storage medium can be the internal storage unit of the network detection device provided in any of the foregoing embodiments or the computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium can also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device. Furthermore, the computer-readable storage medium can include both internal storage units and external storage devices of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0320] Furthermore, it should be noted that this application also provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. The processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the method provided in any of the preceding corresponding embodiments. Additionally, the beneficial effects of using the same method will not be repeated here. For technical details not disclosed in the embodiments of the computer program product or computer program involved in this application, please refer to the description of the method embodiments of this application.

[0321] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0322] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.

[0323] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.

[0324] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.

Claims

1. A network detection method, characterized in that, The method is executed by a target detection device for network isolation detection of N cloud servers, wherein the N cloud servers include a first cloud server and a second cloud server, and the method includes: Obtain first network data information of the first cloud server and second network data information of the second cloud server; both the first network data information and the second network data information include initial network configuration information configured by the cloud platform service device associated with the N cloud servers; Based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, network isolation analysis is performed on the first cloud server and the second cloud server to obtain the first type of network isolation analysis results; If the first type of network isolation analysis result indicates that there is a network connection between the first cloud server and the second cloud server, then network connectivity verification is performed on the first cloud server and the second cloud server to obtain a network verification result for the first type of network isolation analysis result; the network verification result may be the same as or different from the first type of network isolation analysis result.

2. The method according to claim 1, characterized in that, The initial network configuration information in the first network data information is the first initial network configuration information, and the initial network configuration information in the second network data information is the second initial network configuration information; the first initial network configuration information includes the first network connection information of the first private network to which the first cloud server belongs; the second initial network configuration information includes the second network connection information of the second private network to which the second cloud server belongs. The method of performing network isolation analysis on the first cloud server and the second cloud server based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information to obtain a first type of network isolation analysis result includes: When the first private network and the second private network are different private networks, the private network that is allowed to access the first private network is determined from the first network connection information, and the private network that is allowed to access the second private network is determined from the second network connection information. Based on the private networks that are allowed to access the first private network and the private networks that are allowed to access the second private network, a network association relationship between the first private network and the second private network is determined; the network association relationship includes a network isolation relationship; the network isolation relationship is determined when the second private network is not included in the private networks that are allowed to access the first private network, and the first private network is not included in the private networks that are allowed to access the second private network. If the network association relationship is the network isolation relationship, then a first analysis result is determined to indicate that there is network isolation between the first cloud server and the second cloud server, and the first analysis result is used as the first type of network isolation analysis result.

3. The method according to claim 2, characterized in that, The network association relationship includes network connectivity relationship; the network connectivity relationship is determined when the private network that allows access to the first private network includes the second private network, and the private network that allows access to the second private network includes the first private network; the first initial network configuration information includes access control list information of the first subnet to which the first cloud server belongs, and the first subnet belongs to the first private network. The second initial network configuration information includes the access control list information of the second subnet to which the second cloud server belongs, and the second subnet belongs to the second private network; The method further includes: If the network association between the first private network and the second private network is a network connectivity relationship, then the first subnet outgoing rule and the first subnet incoming rule of the first subnet are determined from the access control list information of the first subnet, and the second subnet outgoing rule and the second subnet incoming rule of the second subnet are determined from the access control list information of the second subnet. Based on the first subnet outgoing rule, the first subnet incoming rule, the second subnet outgoing rule, and the second subnet incoming rule, the subnet configuration association relationship between the first cloud server and the second cloud server is determined; the subnet configuration association relationship includes the subnet configuration isolation relationship. If the subnet configuration association relationship is the subnet configuration isolation relationship, then a first analysis result is determined to indicate that there is network isolation between the first cloud server and the second cloud server, and the first analysis result is used as the first type of network isolation analysis result.

4. The method according to claim 3, characterized in that, The step of determining the subnet configuration association between the first cloud server and the second cloud server based on the first subnet outgoing rule, the first subnet incoming rule, the second subnet outgoing rule, and the second subnet incoming rule includes: Based on the first subnet outgoing rules and the second subnet incoming rules, the first subnet configuration relationship between the first cloud server and the second cloud server in the first transmission direction is determined; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server. Based on the first subnet inbound rules and the second subnet outbound rules, the second subnet configuration relationship between the first cloud server and the second cloud server in the second transmission direction is determined; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server. If the first subnet configuration relationship indicates that there is network isolation in the first transmission direction, and the second subnet configuration association relationship indicates that there is network isolation in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration isolation relationship. If the first subnet configuration relationship indicates that there is network connectivity in the first transmission direction, and the second subnet configuration association relationship indicates that there is network connectivity in the second transmission direction, then the subnet configuration association relationship between the first cloud server and the second cloud server is determined to be a subnet configuration connectivity relationship.

5. The method according to claim 3, characterized in that, The subnet configuration association includes the subnet configuration connectivity; the first initial network configuration information includes the first security group information of the first cloud server; The second initial network configuration information includes the second security group information of the second cloud server; The method further includes: If the subnet configuration association between the first cloud server and the second cloud server is a subnet configuration connectivity relationship, the first outgoing rule and the first incoming rule of the first cloud server are determined from the first security group information, and the second outgoing rule and the second incoming rule of the second cloud server are determined from the second security group information. Based on the first outgoing rule, the first incoming rule, the second outgoing rule, and the second incoming rule, the first type of network isolation analysis result is determined.

6. The method according to claim 5, characterized in that, The determination of the first type of network isolation analysis result based on the first outgoing rule, the first incoming rule, the second outgoing rule, and the second incoming rule includes: Based on the first outgoing rule and the second incoming rule, a first transmission relationship is determined in the first transmission direction of sending data from the first cloud server to the second cloud server. Based on the first inbound rule and the second outbound rule, a second transmission relationship is determined in the second transmission direction of sending data from the second cloud server to the first cloud server. If the first transmission relationship indicates network isolation in the first transmission direction and the second transmission relationship indicates network isolation in the second transmission direction, then a first analysis result indicating network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is used as the first type of network isolation analysis result. If the first transmission relationship indicates that there is network connectivity in the first transmission direction, and the second transmission relationship indicates that there is network connectivity in the second transmission direction, then a second analysis result indicating that there is network connectivity between the first cloud server and the second cloud server is determined, and the second analysis result is used as the first type of network isolation analysis result.

7. The method according to claim 1, characterized in that, The first network data information includes the first traffic mirror data of the first cloud server, and the second network data information includes the second traffic mirror data of the second cloud server; The method further includes: Based on the first traffic mirror data and the second traffic mirror data, network isolation analysis is performed on the first cloud server and the second cloud server to obtain the second type of network isolation analysis results. If the second type of network isolation analysis result indicates that there is network isolation between the first cloud server and the second cloud server, then network isolation verification is performed on the first cloud server and the second cloud server to obtain the network verification result for the second type of network isolation analysis result.

8. The method according to claim 7, characterized in that, The network isolation analysis is performed on the first cloud server and the second cloud server based on the first traffic mirroring data and the second traffic mirroring data to obtain a second type of network isolation analysis result, including: In the first traffic mirror data and the second traffic mirror data, search for traffic log data of data interaction between the first cloud server and the second cloud server to obtain log search results; If the log lookup result indicates that no traffic log data for data interaction was found, then the first analysis result indicating that there is network isolation between the first cloud server and the second cloud server is determined, and the first analysis result is taken as the second type of network isolation analysis result. If the log lookup result indicates that traffic log data for data interaction has been found, then a second analysis result indicating that there is network connectivity between the first cloud server and the second cloud server is determined, and the second analysis result is taken as the second type of network isolation analysis result.

9. The method according to claim 1, characterized in that, The network connectivity verification between the first cloud server and the second cloud server, to obtain network verification results for the first type of network isolation analysis results, includes: Obtain the automated command execution component, and invoke the automated command execution component to notify the first cloud server and the second cloud server to execute the network isolation query command respectively, and obtain the corresponding command query results; Receive the command query results returned by the first cloud server and the second cloud server respectively, and determine the network verification result for the first type of network isolation analysis result based on the received command query results.

10. The method according to claim 9, characterized in that, The invocation of the automated command execution component notifies the first cloud server and the second cloud server to execute network isolation query commands respectively, obtaining the corresponding command query results, including: The automated command execution component is invoked to notify the first cloud server to execute the first query command and obtain the first command query result corresponding to the first query command; the first query command is used to instruct the first cloud server to query the isolation in the first transmission direction; the first transmission direction refers to the transmission direction in which the first cloud server sends data to the second cloud server; The automated command execution component is invoked to notify the second cloud server to execute the second query command and obtain the second command query result corresponding to the second query command; the second query command is used to instruct the second cloud server to query the isolation in the second transmission direction; the second transmission direction refers to the transmission direction in which the second cloud server sends data to the first cloud server.

11. The method according to claim 9 or 10, characterized in that, The command query result returned by the first cloud server is the first command query result, and the command query result returned by the second cloud server is the second command query result. The determination of the network verification result based on the received command query result for the first type of network isolation analysis result includes: If the first command query result indicates that there is network isolation in the first transmission direction, and the second command query result indicates that there is network isolation in the second transmission direction, then a first verification result is determined to indicate that there is network isolation between the first cloud server and the second cloud server in both the first transmission direction and the second transmission direction, and the first verification result is determined as the network verification result. If the first command query result indicates that there is network connectivity in the first transmission direction, and the second command query result indicates that there is network connectivity in the second transmission direction, then a second verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in both the first transmission direction and the second transmission direction, and the second verification result is determined as the network verification result. If the first command query result indicates that there is network connectivity in the first transmission direction, and the second command query result indicates that there is network isolation in the second transmission direction, then a third verification result is determined to indicate that there is network connectivity between the first cloud server and the second cloud server in the first transmission direction and network isolation in the second transmission direction, and the third verification result is determined as the network verification result.

12. The method according to claim 1, characterized in that, The method further includes: When a verification task associated with a verification account is obtained, N cloud servers to be isolated for verification are determined based on the verification task; N is a positive integer; the verification account has the role permissions of the target role; the target role is configured based on the target management account, and the role permissions of the target role include data access permissions to obtain network data information of the N cloud servers; Any two of the N cloud servers are designated as the first cloud server and the second cloud server.

13. A network detection device, characterized in that, The device operates on a target detection device used for network isolation detection of N cloud servers, wherein the N cloud servers include a first cloud server and a second cloud server, and the device includes: The network data acquisition module is used to acquire first network data information of the first cloud server and second network data information of the second cloud server; both the first network data information and the second network data information include initial network configuration information configured by the cloud platform service device associated with the N cloud servers. The network isolation analysis module is used to perform network isolation analysis on the first cloud server and the second cloud server based on the initial network configuration information in the first network data information and the initial network configuration information in the second network data information, and obtain a first type of network isolation analysis result; The network verification module is used to perform network connectivity verification between the first cloud server and the second cloud server if the first type of network isolation analysis result indicates that there is a network connection between the first cloud server and the second cloud server, and obtain a network verification result for the first type of network isolation analysis result; the network verification result may be the same as or different from the first type of network isolation analysis result.

14. A computer device, characterized in that, Including memory and processor; The memory is connected to the processor, the memory is used to store computer programs, and the processor is used to invoke the computer programs so that the computer device performs the method according to any one of claims 1-12.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program adapted to be loaded and executed by a processor to cause a computer device having the processor to perform the method of any one of claims 1-12.