Parallel computing and distributed network access risk management and control device and management and control method
By using parallel computing and a distributed network access risk controller, cross-device data synchronization and communication are achieved, solving the problem of cross-device data synchronization and communication in traditional network security management and improving the security and management efficiency of network access.
Patent Information
- Application Number
- CN202511655776.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-12
- Publication Date
- 2025-12-09
AI Technical Summary
Existing technologies cannot effectively solve the problems of information sharing and cross-device communication between network devices, nor can they achieve data synchronization and security between multiple devices.
By constructing a network access risk controller based on parallel computing and distributed computing, and using distributed computing nodes for parallel processing, high-performance, low-latency risk analysis is achieved. Combined with a PKI system, an AI engine, and a distributed security management server, unified network security management is implemented.
It enables real-time monitoring and policy distribution of network access risks, improves the standardization and efficiency of network management, and is suitable for security protection of large-scale network access.
Smart Images

Figure CN121098643A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application belongs to the technical field of risk management and control, and particularly relates to a network access risk management and control device based on parallel computing and distributed control and a management and control method. BACKGROUND
[0002] In the current network security management field, the traditional technical framework is facing unprecedented challenges. The traditional monitoring protocols represented by SNMP, Syslog and NetFlow have been difficult to cope with the dynamics, scale and complexity of the modern network environment due to their early design and simple data processing mechanism. These protocols are essentially passive and single-point monitoring tools, lacking the ability to continuously assess the risk of terminal behavior and unable to achieve cross-device data correlation analysis.
[0003] With the evolution of network attack technology towards automation and systematization, the defense side still relies on static strategies and single-machine protection mode, leading to the increasingly prominent phenomenon of "attack-defense asymmetry" - attackers only need to find a vulnerability to break through the defense line, while the defense side needs to guard the entire system surface. This structural defect makes the existing security system particularly vulnerable in the face of AI-driven attacks. The current technology has three fundamental defects: Firstly, the "security island" phenomenon caused by the lack of systematic defense. Each security device makes independent decisions and cannot form a coordinated defense capability. When facing a complex attack across multiple network nodes, the system cannot timely perceive the threat chain and is also difficult to start joint protection. Secondly, the lack of scale expansion, the traditional centralized controller is not only easy to become a performance bottleneck when processing massive terminal access, but also can cause the entire security system to collapse due to single-point failure.
[0004] Thirdly, the problem of policy rigidity, the current network access control still adopts a "one-time authentication, whole-process effective" extensive management mode, which cannot dynamically adjust the policy according to the risk changes in the session process. This forms a fatal time difference between static protection and dynamic threats.
[0005] Based on the above current network control status and challenges, the current network access security management and control has the following bottlenecks: The technical difficulty of real-time processing of massive data needs to be overcome, and it needs to meet the multi-dimensional risk assessment of terminal behavior under the premise of ensuring low delay, to ensure the consistency and timeliness of security policies in the entire network.
[0006] Therefore, the present application provides a network access risk management and control device based on parallel computing and distributed control and a management and control method. SUMMARY
[0007] The purpose of the present application is to provide a network access risk management and control device and method based on parallel computing and distributed architecture, which provides high-performance computing support through full-switch parallel computing, and a security management and control platform based on a distributed security management and control system, which uniformly monitors the state of network access risks, analyzes risks, and issues strategies, manages and controls network events and performance in a distributed manner, and performs real-time network access risk management and control, thereby solving the challenges and bottlenecks of existing network access security management.
[0008] To solve the above technical problems, the present application is realized by the following technical solutions: As a first aspect provided by the present application, the present application is a network access risk management and control device based on parallel computing and distributed architecture, comprising: a network element device layer composed of network devices, which accesses the network management and control device through an interconnected network; at least one network management and control device, which reports abnormal information to a security management and control platform as a distributed edge security execution component, receives and executes security management and control strategies issued by the security management and control platform, and reports abnormal information to the security management and control platform for local data collection, rapid strategy execution, and joint defense and control; a security management and control platform, which is a centralized central controller for centralized management and control of network management and control devices, receives data reported by the network management and control devices, performs comprehensive risk analysis, formulates and issues global security strategies, and centrally manages and controls multiple network management and control devices; The risk management and control device is built on a full-switch parallel computing architecture for providing a virtual computing pool, which includes: a multi-node computing unit based on general computing, EHPC / HPC computing power, CPU computing power, GPU computing power, and NPU computing power, a distributed shared memory system formed by interconnecting distributed storage gateways and object storage devices, a high-speed interconnected network based on IP networks and SD-WAN; suitable for large-scale network access and application security protection, based on parallel computing to provide high-performance computing, to decompose massive security data collection, feature extraction, and risk assessment tasks, and to realize high-performance, low-latency risk analysis through distributed computing nodes.
[0009] Further, the security management and control platform integrates a PKI system-based cryptographic infrastructure module, a tool engine, an AI engine, and a distributed security management and control server, and is used for receiving data reported by the network management and control devices, collecting, storing, analyzing, and visualizing data, generating unified network security management and control strategies, and issuing the strategies to the network management and control devices, adopting a "centralized management and distributed execution" architecture, with the security management and control platform as a central controller responsible for global strategy formulation and intelligent decision-making.
[0010] Further, the security management and control platform comprises: a password infrastructure module for providing password support services based on the PKI system; a tool engine integrated with a tool set for information collection and state detection of the network element device layer; an AI engine carrying an AIGC model optimized based on the Transformer architecture, for providing network security baseline real-time generation services to the network controller through a standardized API interface under the unified network security management and control policy of the security management and control platform; a distributed security management and control server for performing security risk analysis and comprehensive processing on the information received from multiple network controllers based on the password infrastructure module, the tool engine and the AI engine, generating a unified network security management and control policy and issuing it to the network controller.
[0011] Further, the password infrastructure module of the security management and control platform comprises a security authentication system CA, a certificate distribution management system RA, a key management center KMC, a certificate / certificate revocation list storage and publishing system LDAP, and a password machine module, which are used for user management, application review, and certificate application, issuance, revocation, update, status query, key management, and hardware operation of SM1, SM2, SM3, and SM4 password algorithms.
[0012] Further, the tool set of the tool engine comprises a firewall, intrusion detection, antivirus, isolation, and vulnerability scanning tool set, which are used for network device environment information collection and network device real-time running state detection.
[0013] Further, the distributed security management and control server comprises a security management module, a security monitoring and auditing module, a configuration management module, a situation awareness module, and a continuous security evolution module, which are used for adaptive comprehensive detection, analysis, and security management control.
[0014] Further, the network controller comprises: an access authentication module for authenticating the user identity, device MAC identifier, and subnet IP address of the access network device through the PKI password of the security management and control platform; a state monitoring module for real-time monitoring of the state of the access network device and configuration integrity credibility measurement through ICMP / Ping / TCP / Telnet monitoring and SNMP monitoring, and for network topology monitoring, fault analysis, illegal device discovery and blocking, application layer protocol packet capture and traffic monitoring; A log / event collection and reporting module is configured to collect logs, Syslog / SNMP events and network traffic information of the network device, and report the information to the security management and control platform for abnormality diagnosis and early warning. A joint defense and control module supports a joint defense and control mechanism based on a secure connection security management and control protocol, and responds to detected network security events and threats.
[0015] Further, the network element device layer includes switches, routers, communication platforms and security gateways.
[0016] Further, the deployment mode of the network controller includes: Single network deployment: deploying one network controller in a single network area to uniformly manage network devices in the area; High-reliability dual-computer hot backup deployment: deploying two network controllers in a single network area based on dual-computer load balancing to continuously and uninterruptedly uniformly manage network devices in the area, and realizing high availability through dual-computer load balancing; Distributed collaborative deployment: deploying multiple network controllers on subnets of a multi-area interconnected network, and uniformly and centrally managing and controlling the network controllers by the security management and control platform.
[0017] As a second aspect provided by the present application, the present application provides a network access risk management and control method based on parallel computing and distributed computing. The method is realized based on the risk controller of the first aspect, and includes the following steps: Step S1: initial access and authentication When a network device attempts to access the network, the network controller redirects the network device to an authentication portal, and after completing identity authentication of the user, device and subnet, the security management and control platform performs preliminary authorization and issues a basic permission policy; Step S2: continuous data collection and parallel risk assessment The network controller and the security agent continuously collect data streams and report them in real time, and the parallel computing engine performs real-time and micro-batch processing mixed analysis on the data streams to generate a dynamic risk score; Step S3: dynamic policy decision and issuance The security management and control platform makes a dynamic authorization decision based on the dynamic risk score and context information, and issues corresponding network security management and control policy instructions to the corresponding network controller; Step S4: edge policy execution and feedback The network controller receives and immediately executes the issued network security management and control policy instructions, drives the access network device to change the policy locally, and feeds back the execution result and new network state data to the security management and control platform; Step S5: Cycle step S1-step S4 to perform network access risk management and control.
[0018] The present application has the following beneficial effects: The present application provides high-performance computing support through full-switch parallel computing, and a security management and control platform based on a distributed security management and control system, which performs unified state monitoring, risk analysis and policy issuing on network access risks, and performs real-time network access risk management and control through distributed network event and performance management and control, and is suitable for large-scale network access and application security protection, and is suitable for scenarios such as guarantee systems, 4+ levels such as railway ticket systems, railway electric power systems, and financial core business systems, which have extremely high requirements for information confidentiality and integrity.
[0019] Of course, any product implementing the present application does not necessarily need to achieve all the advantages described above at the same time. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0021] Figure 1 The structure diagram of the network access risk controller based on parallel computing and distributed control of the present application; Figure 2 The full-switch high-performance parallel computing architecture diagram; Figure 3 The deployment mode of the network controller Figure 1 ; Figure 4 The deployment mode of the network controller Figure 2 ; Figure 5 The deployment mode of the network controller Figure 3 . DETAILED DESCRIPTION
[0022] In the following description, specific details such as specific system structures, techniques, etc. are presented in order to thoroughly understand the embodiments of the present application, but it should be clear to those skilled in the art that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits and methods are omitted to avoid unnecessary details that hinder the description of the present application.
[0023] It should be understood that the term "includes" when used in the specification and the appended claims herein, specifies the presence of stated features, integers, steps, operations, elements, and / or components but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0024] It should also be understood that the term "and / or" when used in the specification and the appended claims herein, means any one and / or all possible combinations of one or more of the associated listed items.
[0025] As used in the specification and the appended claims herein, the term "if' can be construed to mean "when" or "once" or "in response to determining" or "in response to detecting" depending on the context. Similarly, the phrase "if it is determined" or "if [a described condition or event] is detected" can be construed to mean "once it is determined" or "in response to determining" or "once [the described condition or event] is detected" or "in response to detecting [the described condition or event]," depending on the context.
[0026] In addition, the terms "first," "second," "third," etc. as used in the description and the appended claims herein are used only to distinguish one element from another, and do not imply a relative importance or a specific order.
[0027] Reference in the specification to "one embodiment" or "some embodiments" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" or "in some embodiments" in various places in the specification are not necessarily all referring to the same embodiment, although it can. The terms "including," "comprising," "having" and variations thereof herein are meant to be open-ended terms that can cover the presence of one or more of the stated features, integers, steps, operations, elements, and / or components but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0028] Embodiment One: Please refer to Figure 1 As shown in the figure, as the first embodiment provided by the application, the application is a network access risk management controller based on parallel computing and distributed network, which comprises: A network element device layer composed of network devices, which accesses the network management controller through the interconnection network; the network element device layer comprises switches, routers, communication platforms and security gateways, and these devices and elements access the network management controller through the interconnection network and are subject to the centralized management and control of the network management controller; At least one network controller, as a decentralized edge security execution component, reports abnormal information to the security management and control platform, receives and executes the security management and control strategy issued by the security management and control platform, and is used for executing local data collection, rapid execution of strategy and joint defense and control, and reporting abnormal information to the security management and control platform. The security management and control platform, as a centralized management center controller, centrally controls the network controller; it is used for receiving the data reported by the network controller, performing comprehensive risk analysis, formulating and issuing a global security strategy, and centrally controlling a plurality of network controllers. The risk controller is constructed on a full-switch parallel computing architecture for providing a virtual computing power pool, and the architecture comprises: a multi-node computing unit based on general computing, EHPC / HPC computing power, CPU computing power, GPU computing power and NPU computing power, a distributed shared memory system formed by interconnection of a distributed storage gateway and an object storage device, and a high-speed interconnection network based on an IP network and an SD-WAN; the security protection suitable for large-scale network access and application is provided with high-performance computing power, and a large amount of security data collection, feature extraction and risk assessment tasks are decomposed and processed in parallel by distributed computing nodes, so that high-performance and low-delay risk analysis is realized.
[0029] As one embodiment provided by the application, preferably, the security management and control platform is integrated with a PKI system-based cryptographic infrastructure module, a tool engine, an AI engine and a centralized and distributed security management and control server, and is used for receiving the data reported by the network controller, performing data collection, storage, analysis and visualization, generating a unified network security management and control strategy and issuing the strategy to the network controller, and adopting a centralized management and decentralized execution architecture, wherein the security management and control platform serves as a center controller and is responsible for global strategy formulation and intelligent decision-making.
[0030] Under the support of high-performance computing power provided by the full-switch parallel computing, the security management and control platform based on the centralized and distributed security management and control system performs unified state monitoring, risk analysis and strategy issuing on network access risks, performs real-time risk control on network access through distributed network event and performance management and control, and is suitable for security protection of large-scale network access and application.
[0031] The risk controller is an advanced network security management and control execution component based on a security management and control computing system, and under the unified control of the security management and control platform, integrates risk comprehensive analysis of network topology structure discovery, network state, log and event, network traffic and the like, and through cooperative linkage control of a plurality of controllers, constructs a network security system of the controlled system.
[0032] By constructing the security management and control platform, the running state of the managed network is comprehensively controlled, the clear separation of system management responsibilities is realized, and the security administrator can easily formulate and execute unified security management strategies for the managed network with the aid of the security management and control platform, thereby effectively improving the standardization and efficiency of network management.
[0033] Embodiment two: As a second embodiment provided by the present application, please refer to Figures 1-2 As a second embodiment provided by the present application, please refer to
[0034] As an embodiment provided by the present application, preferably, a full-switch high-performance parallel computing architecture is adopted, please refer to Figure 2 As an embodiment provided by the present application, preferably, a full-switch high-performance parallel computing architecture is adopted, please refer to
[0035] As an embodiment provided by the present application, preferably, the full-switch high-performance parallel computing architecture comprises: A plurality of high-performance computing units are fused, and the computing units include general-purpose computing, EHPC / HPC computing power, GPU computing power, and NPC computing power. A distributed shared memory system is based on a distributed storage gateway GW, an object storage OSD, and interconnection to form a distributed shared memory system, and provides unified distributed storage resources, can fuse a plurality of storage systems, and includes SAN storage, NAS storage, object storage, and distributed file (LUSTRE) storage systems. A high-speed interconnection network is fused with an IP network and a high-speed interconnection SDWAN (software-defined wide area network) network to provide a high-performance interconnection network that can be flexibly expanded and can communicate on demand.
[0036] The network access risk management and control device based on the full-switch high-performance parallel computing architecture mainly realizes access authentication of network devices, monitoring of network states, and collection and reporting of logs and events of network devices, and unified security strategies based on the security management and control platform are used to jointly defend and control the networks of managed systems, thereby realizing the network security of the managed and controlled systems.
[0037] Adopting a distributed management architecture and independent of the business IP, an SD-WAN (software-defined wide area network) network is constructed by using network address translation (NAT) technology. Not only is the operation convenient for the administrator, but also the security of the operation and maintenance channel is ensured, and efficient and secure remote management of the network is achieved.
[0038] Moreover, the administrator can perform lightweight remote operation and maintenance of the network equipment dispersed in different geographic locations through the secure management network, and realize lightweight remote operation and maintenance innovation under the secure management network.
[0039] Meanwhile, the distributed management architecture ensures that the administrator can real-time understand the security dynamics of the internal network, quickly identify and respond to potential threats, and thus realize all-round and dead-angle-free security protection of the network equipment.
[0040] Under the support of high-performance computing power provided by full-switch parallel computing, a security management center platform based on the distributed security management system is constructed. The platform is responsible for unified state monitoring, risk analysis and policy issuing of network access risks, and realizes real-time control of network access risks through distributed network event and performance management.
[0041] Embodiment three As a third embodiment provided by the present application, please refer to Figure 1-3 The present application is a network access risk controller based on parallel computing and distribution, based on embodiments one to two, the distributed management architecture provides the overall management system, the security management and control platform provides the security management and control brain decision and overall management and control, adopts the architecture of "centralized management and decentralized execution", the security management and control platform as the central controller, is responsible for global policy formulation and intelligent decision. The security management and control platform as the execution platform of the security management center, centrally manages and controls all nodes in the managed system, receives the state information data of the network equipment under jurisdiction collected and reported by the network controller, completes big data collection, storage, analysis and visualization, performs comprehensive risk analysis, overall security policy formulation and issuing, and centrally controls the multiple edge execution components network controllers in real time.
[0042] As an embodiment provided by the present application, preferably, the security management and control platform processes, transmits and stores various threat data by collecting various data such as terminal / host logs, network equipment and security device logs, operating system, application system, database logs, middleware logs, network traffic and data generated by third parties, data fusion, data cleaning, data mining, feature extraction, dynamic response and prediction, machine learning of physical, network, system, application and other OSI architecture full-element information, automatically learns, models and analyzes the data to form rules, and uses the rules to perform network situation assessment, network threat assessment and network situation prediction on the cyberspace, and further to make the network space security situation visible, known, manageable, controllable, traceable and pre-warning. Thus, a multi-level, multi-angle, multi-granularity, complete and detailed management and control platform based on human, machine, material and other resource objects, time and space range, and correlation is constructed.
[0043] Embodiment Four As a fourth embodiment provided by the present application, please refer to Figure 1-3 As shown in the figure, the present application is a network access risk management and control device based on parallel computing and distributed network access, which is an edge security execution component based on embodiments one to three, responsible for local data collection, rapid execution of policies and joint defense and control. It mainly includes real-time collection and reporting of network access security events and performance state data, network topology discovery, etc.; receiving and executing security protection policies issued by the security management and control platform, performing security checks, storing abnormal conditions locally, and timely reporting to the security management and control platform, blocking illegal external connection, etc., and providing high-performance real-time security management and control of network access risks.
[0044] As an embodiment provided by the present application, preferably, the network access risk management and control device is an advanced network security management and control execution component rooted in a security management and control computing system, which, under the unified control of the security management and control platform, integrates risk comprehensive analysis of network topology structure discovery, network state, logs and events, network traffic, etc., and through the cooperation and linkage control of multiple management and control devices, constructs a network security system of the managed and controlled system. The network access risk management and control device architecture mainly includes three layers of network element device objects, network management and control devices, and security management and control platforms.
[0045] As an embodiment provided by the present application, preferably, the security management and control platform includes: A password infrastructure module for providing password support services based on a PKI system; the password infrastructure module includes a secure authentication system CA, a certificate distribution management system RA, a key management center KMC, a certificate / certificate revocation list storage and publishing system LDAP, a password machine module, and the password infrastructure module is used for user application, application review, certificate issuance, certificate revocation, key management, user management, system management and other functions, and can realize certificate application, certificate distribution, certificate download, certificate revocation, certificate update, certificate status query, key recovery, hardware operation of SM1, SM2, SM3, SM4 and other password algorithms and other password service functions. A tool engine integrated with a tool set for collecting information and detecting the state of the network element device layer; the tool set includes a firewall, intrusion detection, antivirus, isolation, and vulnerability scanning tool set, and the tool set of the tool engine is used for network device environment information collection and network device real-time running state detection to realize terminal environment information collection and terminal real-time running state detection. An AI engine as the core support of the network communication security baseline generation system, which carries an AIGC model based on the optimization of the Transformer architecture, and the AI engine is not independently operated, but deeply embedded in the collaborative scheduling system of the security management and control platform, and is used to provide network security baseline real-time generation services to the network controller through a standardized API interface under the unified network security management and control strategy of the security management and control platform, to meet the demand for large-scale network security baseline real-time generation. A distributed security management and control server for centralized management by the security management and control platform based on the password infrastructure module, the tool engine and the AI engine, receiving information reported by a plurality of network controllers deployed in a distributed manner, generating a unified network security management and control strategy through security risk analysis and comprehensive processing, and issuing the strategy to each network controller for automatic execution, disposing and blocking security events, and reducing the risk of security events to an acceptable level.
[0046] As an embodiment provided by the application, preferably, under the support of a high computing power platform, the distributed security management and control server includes a security management module, a security monitoring and auditing module, a configuration management module, a situation awareness module and a continuous security evolution module, and is used for adaptive comprehensive detection, analysis and security management control, has adaptive comprehensive detection, analysis and security management control capabilities, achieves the purpose of distributed deployment, centralized control, automation and intelligent security management and control, and meets the needs of high reliability and high efficiency of continuous security operation of complex system networks.
[0047] The network controller adopts an advanced adaptive security architecture design, which comprehensively improves the security capability from four dimensions of prediction, defense, detection and response. It can continuously monitor and analyze the configuration state, running state, network connection relationship and network traffic of the network equipment, and help customers establish a security system that can continuously respond and dynamically adjust. This key capability ensures that the managed network always maintains high vigilance and strong defense when facing evolving threats.
[0048] Embodiment five: As a fifth embodiment provided by the present application, please refer to Figure 1-3 The present application is a network access risk management and control device based on parallel computing and distributed architecture. Based on embodiments one to four, under the support of the security management and control platform, the network controller mainly assumes the role of edge execution component and connects with various network element devices of the managed network; it performs security analysis by collecting and summarizing logs, events, states, network traffic and the like of various network element devices, stores abnormal conditions locally and timely reports to the security management and control platform; the security management and control platform statistically analyzes the information reported by multiple edge execution components, performs statistical and comprehensive analysis, evaluates the risk status of network operation, generates and issues corresponding strategies, and through the coordinated control of multiple edge execution components (such as network controller, firewall, etc.), such as illegal external connection blocking, builds a network security system of the managed system. In the architecture of the network controller, the function of trusted computing is strengthened to ensure that the configuration state of the managed object is measured in real time. The configuration state of the network equipment is mainly monitored and verified through cryptographic techniques.
[0049] As an embodiment provided by the present application, preferably, the network controller comprises: An access authentication module for authenticating the user identity, device MAC identifier and subnet IP address of the access network equipment through the PKI password of the security management and control platform; A state monitoring module for monitoring the state of the access network equipment in real time and performing trusted measurement of configuration integrity through ICMP / Ping / TCP / Telnet monitoring and SNMP monitoring, and for network topology monitoring, fault analysis, illegal device discovery and blocking, application layer protocol packet capture and traffic monitoring; A log / event collection and reporting module for collecting logs, Syslog / SNMP events and network traffic information of the network equipment and reporting the information to the security management and control platform for abnormal diagnosis and early warning; A joint defense and control module supporting the joint defense and control mechanism of the security management and control protocol based on trusted connection, and responding to the detected network security events and threats.
[0050] As an embodiment provided by the present application, preferably, the access authentication module specifically comprises: Access user identity authentication: through the encryption and decryption and authentication services provided by the PKI cryptographic system of the security management and control platform, the related authentication services of the security agent and other functions, the authentication of the user identity of the access network device is realized; Access device authentication MAC: through the encryption and decryption and authentication services provided by the PKI cryptographic system of the security management and control platform, the related authentication services of the security agent and other functions, the authentication of the access network device is realized, mainly through the authentication of the device MAC identifier, the legality of the device is ensured; Access subnet authentication IP: through the encryption and decryption and authentication services provided by the PKI cryptographic system of the security management and control platform, the related authentication services of the security agent and other functions, the authentication of the access subnet is realized; mainly the legality of the IP address of the access subnet is authenticated.
[0051] As an embodiment provided by the present application, preferably, the state monitoring module specifically comprises: Network device state monitoring and trust measurement: through ICMP / Ping / TCP / Telnet monitoring, SNMP monitoring and the like, the state of the access network device is monitored in real time, and the trust measurement of the configuration integrity is carried out, so as to ensure the reliability and security of the device operation; Network topology monitoring and fault analysis: the change of the network topology is accurately monitored, the fault point is quickly located and analyzed, and the fault recovery time is effectively shortened; Illegal device discovery and blocking: the illegally accessed device is discovered and located in time, and the blocking measure is quickly taken to prevent potential security risks; Application layer protocol packet capture and traffic monitoring: the communication data of the application layer protocol is captured in real time, and the network traffic is monitored.
[0052] As an embodiment provided by the present application, preferably, the log / event collection and reporting module specifically comprises: Network device log collection and reporting: the log information of the network device is comprehensively collected, and strong support is provided for security audit and fault troubleshooting; Network device management and configuration: the flexible management and configuration of the network device are comprehensively supported, and the stability and efficiency of the network environment are ensured; Syslog / SNMP event collection and reporting: the Syslog / SNMP and other network management protocol operation events are comprehensively collected, and are reported to the security management and control platform; Network traffic anomaly diagnosis and early warning: through the packet capture analysis result, the network traffic is abnormally detected, early warned and backtracked, and the legality and security of the network communication are ensured.
[0053] As an embodiment provided by the present application, preferably, the joint defense and control module specifically comprises: Security management and control protocol joint defense and linkage: support the joint defense and linkage mechanism of the security management and control protocol based on the trusted connection, realize the comprehensive cooperative defense of the network security; Response and recovery: make a timely response to the detected network security events and threats, reduce the influence of the events through the implementation of the response strategy, and recover the normal operation of the network.
[0054] Embodiment six: As the sixth embodiment provided by the present application, please refer to Figure 1-5 The present application is a network access risk management and control device based on parallel computing and distributed system, based on the first embodiment to the fifth embodiment, the deployment mode of the network management and control device comprises: Single network deployment: deploy a network management and control device in a single network area, and uniformly manage the network equipment in the area; implement the security management and control of the network elements and the network environment in the single network area, deploy a network management and control device, and uniformly manage the network element computing environment and the network boundary connected to the network management and control device in the managed area network; High-reliability dual-computer hot backup deployment: based on dual-computer load balancing, two network management and control devices are deployed in a single network area for continuous and uninterrupted unified management of network equipment in the area, and high availability is realized through dual-computer load balancing; two network management and control devices are deployed, and through the dual-computer load balancing capability of the network management and control device, high availability of the network management and control device is realized, and when any one fails, business continuity and data loss can be guaranteed; Distributed cooperative deployment: deploy multiple network management and control devices on the subnets of multiple regional interconnected networks, and uniformly and centrally manage and control them by the security management and control platform; multiple network management and control devices are deployed on the subnets of the complex network of multiple regional interconnection, and are uniformly managed and controlled by the security management and control platform through distributed deployment, and are used for controlling the access authentication function of the network. Each region can adopt different network access control technologies according to its own network structure. By building the security management and control platform, the running state of the managed network is comprehensively controlled, and the clear separation of system management responsibilities is realized.
[0055] Embodiment seven: As the seventh embodiment provided by the present application, the present application is a network access risk management and control method based on parallel computing and distributed system, the method is realized based on the risk management and control device described in the first embodiment to the sixth embodiment, and the method comprises the following steps: Step S1: initial access and authentication: when the network device attempts to access the network, it is redirected to the authentication portal by the network controller, and after completing the identity authentication of the user, device and subnet, the security management and control platform performs preliminary authorization and issues basic permission policies; the terminal attempts to access the network, and the access device of the execution layer redirects it to the authentication portal; the user / device / subnet completes strong identity authentication (such as two-factor authentication), and the collection layer reports the authentication information to the security management and control platform; the security management and control platform performs preliminary authorization and issues basic permission policies, such as only accessing the patch server and the authentication system, and the cooperative linkage of the network controllers in the adjacent domain; Step S2: continuous data collection and parallel risk assessment: the network controller and security agent continuously collect data streams and report them in real time, and the parallel computing engine performs real-time and micro-batch processing mixed analysis on the data streams to generate a dynamic risk score; the security agent installed on the network controller and the network device start to continuously collect security data in parallel, and report them in real time through an encrypted tunnel; the parallel computing risk analysis engine starts to perform real-time and batch processing mixed analysis on the incoming data stream: real-time analysis: DPI analysis of network traffic to detect abnormal connections, DDoS attacks, etc.; micro-batch processing: every short time (such as a few seconds), a quick risk score calculation is performed on the collected process list, file hash, log event, etc. This process is distributed, with each computing node processing a part of the data; the engine integrates all analysis results to generate a dynamic risk score; Step S3: dynamic policy decision and issuance: the security management and control platform makes dynamic authorization decisions based on the dynamic risk score and context information, and issues corresponding network security management and control policy instructions to the corresponding network controller; the security management and control platform policy server makes dynamic authorization decisions based on the network real-time risk score and context information; low risk score: maintain the current status of network bandwidth or improve access rights; medium risk score: trigger enhanced authentication or limit access range (such as only accessing internal web pages); high risk score: immediately issue "isolation" or "network interruption" instruction policies to the corresponding network access device; Step S4: edge policy execution and feedback: The network controller receives and immediately executes the network security management and control policy instruction issued, drives the access network equipment to change the policy locally, and feeds back the execution result and the new network state data to the security management and control platform; the network controller receives the security policy issued by the security management and control platform, and immediately starts the executor to perform. The relevant execution actions are immediately issued to the access equipment of the managed system, and the network access equipment drives the network access equipment to perform the policy change locally in milliseconds after receiving the instruction, without the need to pass through the central controller again. This ensures the real-time performance of the management and control; the execution result and the new network state data are collected again and fed back to the network controller, and then reported to the security management and control platform for analysis and decision-making. Step S5: Circulating steps S1-S4 to perform network access risk management and control.
[0056] The network access risk management and control device and method based on parallel computing and distributed management are suitable for scenarios with high requirements for information security and integrity, such as guarantee systems, 4+ level systems such as railway ticket systems, railway electrical systems, and financial core business systems.
[0057] In the description of the present specification, the description of the terms "one embodiment", "example", "specific example" and the like means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0058] The preferred embodiments of the application disclosed above are only used to help explain the application. The preferred embodiments do not describe all the details and limit the application to the specific embodiments described. Obviously, many modifications and changes can be made according to the content of the present specification. The present specification selects and describes these embodiments in order to better explain the principles and practical applications of the application, so that those skilled in the art can well understand and utilize the application. The application is limited only by the claims and their entire scope and equivalents.
Claims
1. A network access risk controller based on parallel computing and distributed, characterized in that, Comprise: At least one network controller, as a decentralized edge security execution component, reports anomaly information to a security management and control platform, receives and executes security management and control strategies issued by the security management and control platform; A network element device layer composed of network devices accesses the network controller through an interconnected network; A security management and control platform, as a centralized management center controller, centrally manages and controls the network controller; Wherein, the risk management controller is built on a full exchange parallel computing architecture providing a virtual computing power pool, the architecture comprises: a multi-node computing unit based on general computing, EHPC / HPC computing power, CPU computing power, GPU computing power and NPU computing power, a distributed shared memory system formed by interconnecting a distributed storage gateway and an object storage device, and a high-speed interconnected network based on an IP network and an SD-WAN.
2. The network access risk manager based on parallel computing and distributed computing of claim 1, wherein, The security management and control platform integrates a PKI system-based cryptographic infrastructure module, a tool engine, an AI engine, and a centralized security management and control server, and is used to receive data reported by the network controller, and perform data collection, storage, analysis, visualization, generate unified network security management and control strategies, and issue them to the network controller. 3.The network access risk management device based on parallel computing and distribution according to claim 1, wherein, The security management and control platform comprises: A cryptographic infrastructure module for providing PKI system-based cryptographic support services; A tool engine integrating a tool set for information collection and state detection of the network element device layer; An AI engine carrying an AIGC model optimized based on the Transformer architecture, for providing network security baseline real-time generation services to the network controller through a standardized API interface under the unified network security management and control strategy of the security management and control platform; A centralized security management and control server for performing security risk analysis and comprehensive processing on information received from multiple network controllers based on the cryptographic infrastructure module, the tool engine and the AI engine, generating unified network security management and control strategies and issuing them to the network controller.
4. The network access risk manager based on parallel computing and distributed computing of claim 3, wherein, The cryptographic infrastructure module of the security management and control platform comprises a security authentication system, a certificate distribution management system, a key management center, a certificate / certificate revocation list storage and issuance system, and a cryptographic machine module, which are used for user management, application review, certificate application, issuance, revocation, update, status query, key management, and hardware operation of SM1, SM2, SM3, and SM4 cryptographic algorithms.
5. The network access risk manager based on parallel computing and distributed according to claim 3, characterized in that, The tool set of the tool engine comprises a firewall, intrusion detection, antivirus, isolation, and vulnerability scanning tool set, which is used to collect network device environment information and detect its real-time running state.
6. The network access risk manager based on parallel computing and distributed computing of claim 3, wherein, The centralized security management and control server comprises a security management module, a security monitoring and auditing module, a configuration management module, a situation awareness module, and a continuous security evolution module, which are used for adaptive comprehensive detection, analysis, and security management and control.
7. The network access risk manager based on parallel computing and distributed computing of claim 1, wherein, The network controller comprises: An access authentication module for authenticating the user identity, device MAC identification and subnet IP address of the access network device through the PKI password of the security management and control platform; A state monitoring module for monitoring the state of the access network device in real time and performing the credibility measurement of configuration integrity through ICMP / Ping / TCP / Telnet monitoring and SNMP monitoring; A log / event collection and reporting module for collecting the log, Syslog / SNMP event and network traffic information of the network device and reporting the information to the security management and control platform for abnormal diagnosis and early warning; A joint defense and control module supporting the joint defense and linkage mechanism of the security management and control protocol based on trusted connection and responding to the detected network security events and threats.
8. The network access risk manager based on parallel computing and distributed computing of claim 1, wherein, The network element device layer includes switches, routers, communication platforms and security gateways.
9. The network access risk manager based on parallel computing and distributed computing of claim 1, wherein, The deployment mode of the network controller includes: Single network deployment: deploying one network controller in a single network area to uniformly manage the network devices in the network area; High-reliability dual-machine hot backup deployment: deploying two network controllers in a single network area based on dual-machine load balancing to continuously and uninterruptedly uniformly manage the network devices in the network area; Distributed collaborative deployment: deploying multiple network controllers on the subnets of a multi-area interconnected network and uniformly and centrally managing and controlling the network controllers by the security management and control platform.
10. A network access risk management method based on parallel computing and distribution, characterized in that, The method is implemented based on the risk controller of any one of claims 1-9, and the method includes the following steps: Step S1: initial access and authentication: When the network device attempts to access the network, the network device is redirected to an authentication portal by the network controller, and after the authentication of the user, device and subnet is completed, the security management and control platform performs preliminary authorization and issues a basic permission policy; Step S2: continuous data collection and parallel risk assessment: The network controller and the security agent continuously collect data streams and report them in real time, and the parallel computing engine performs real-time and micro-batch processing mixed analysis on the data streams to generate a dynamic risk score; Step S3: dynamic policy decision and issuance: The security management and control platform makes a dynamic authorization decision based on the dynamic risk score and context information and issues corresponding network security management and control policy instructions to the corresponding network controller; Step S4: edge policy execution and feedback: The network controller receives and immediately executes the issued network security management and control policy instructions, drives the access network device to change the policy locally, and feeds back the execution result and new network state data to the security management and control platform; Step S5: repeating steps S1-S4 to control the network access risk.
Citation Information
Patent Citations
Network space security management and control system based on trusted computing
CN117319064A
Safe and credible fireproof cloud system and control method based on distributed and parallel computing
CN117997655A
Trusted management and control network platform construction method and device, electronic equipment and storage medium
CN120934918A
Cited By
Interrupt recovery method and system based on EHPC cluster deployment
CN122111574A