Network element security detection method and network element security related data transmission method

By transmitting network element security-related data in the data service network, the problem of management plane bandwidth occupation is solved, achieving efficient network element security detection and reducing operation and maintenance costs.

CN121151003APending Publication Date: 2025-12-16CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511167823.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-12-16

AI Technical Summary

Technical Problem

In existing technologies, the management plane bandwidth of network elements is occupied by network element security-related data, which leads to the inability to perform normal operation and maintenance. In particular, during attacks, the large amount of data affects the performance of the management plane network.

Method used

Data related to network element security is transmitted through the data service network, avoiding direct transmission at the management plane. Instead, data is received from the target device via the data channel and security testing is performed.

Benefits of technology

It reduces the bandwidth usage on the management plane, improves the efficiency and reliability of network element security detection, and reduces the workload of operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121151003A_ABST
    Figure CN121151003A_ABST
Patent Text Reader

Abstract

The invention provides a network element security detection method and a network element security related data transmission method, and relates to the technical field of network security wherein the network element security detection method comprises: receiving network element security related data of a target network element from a target device, the network element security related data being transmitted from the target network element to the target device through a data channel; and performing security detection based on the network element security related data. According to the method, the related network element security data is transmitted through the data service network instead of being transmitted on the management network of the network element, so that the occupation of the bandwidth of the management network can be reduced, and the technical effect of reducing the influence of network element security detection on the bandwidth of the management network is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the network security technical field, and particularly relates to a network element security detection method and a network element security related data transmission method. BACKGROUND

[0002] With the evolution of traditional telecom network to cloud and virtualization, general server vulnerabilities and operating system vulnerabilities are introduced into the telecom network, and the internal network security attacks are increasing. In order to detect network element security, network element security related data needs to be collected for analysis. The traditional security detection device is generally deployed at the network boundary and cannot perform security detection on all data in the internal network. In the prior art, the network element needs to transmit network element security related data to the security management terminal facing micro-isolation through the management plane for analysis, which occupies the management plane bandwidth and causes congestion of the management plane bandwidth. In particular, when an attacker launches an attack on the network element, a large amount of network element security related data will be generated, and even the normal operation and maintenance operation on the network element through the management plane may be impossible. SUMMARY

[0003] The present application provides a network element security detection method and a network element security related data transmission method, which solve the defect that the network element security detection in the prior art occupies the management plane bandwidth by transmitting network element security related data through the network element management plane, and achieve the effect of reducing the influence of network element security detection on the management plane bandwidth.

[0004] The present application provides a network element security detection method applied to a first device, comprising: receiving network element security related data of a target network element from a target device, wherein the network element security related data is transmitted from the target network element to the target device through a data channel; performing security detection based on the network element security related data.

[0005] According to the network element security detection method provided by the present application, the target device is a second device, and the receiving of the network element security related data of the target network element from the target device comprises: receiving the network element security related data forwarded by the second device; wherein the network element security related data is forwarded from a data transmission agent to the second device through a data channel between the second device and the data transmission agent; Alternatively, the network element security related data is obtained by the second device from a data storage function device, and the network element security related data is transmitted from the target network element to the data storage service device through a data channel.

[0006] According to the network element security detection method provided by the present application, the target device is a data transmission agent, and the receiving of the network element security related data of the target network element from the target device comprises: The network element security-related data is received through the data channel between the data transmission agent and the data transmission agent.

[0007] According to the network element security detection method provided in this application, the target device is a data storage service device, and the step of receiving network element security-related data of the target network element from the target device includes: After receiving the notification information, a data request is sent to the data storage service device; Receive network element security-related data sent by the data storage service device.

[0008] This application provides a network element security detection method, applied to a second device, comprising: Obtain network element security detection requirements, and determine target network elements based on the network element security detection requirements; The network element security-related data of the target network element forwarded by the data transmission agent is obtained through the data channel between the data transmission agent and the data transmission agent, and the network element security-related data is forwarded to the first device; Alternatively, a notification message may be sent to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in the data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; Alternatively, network element security-related data of the target network element can be obtained from the data storage service device, and the network element security-related data can be sent to the first device. The network element security-related data is transmitted from the target network element to the data storage service device through a data channel.

[0009] According to the network element security detection method provided in this application, the step of obtaining network element security detection requirements includes: Receive the network element security detection request sent by the third device.

[0010] According to the network element security detection method provided in this application, after obtaining the network element security detection requirements, the method includes: The type of security detection capability is determined based on the aforementioned network element security detection requirements; The step of forwarding the network element security-related data to the first device includes: The network element security-related data is sent to the first device corresponding to the security detection capability type. Sending notification information to the first device includes: The notification information is sent to the first device corresponding to the security detection capability type.

[0011] According to the network element security detection method provided in this application, before forwarding the network element security-related data to the first device or sending notification information to the first device, the method includes: Based on the network element security detection requirements, a network element data service request is determined and sent to the fourth device. The network element data service request is used to establish a data channel between the first device, the second device, or the data storage function device and the data transmission proxy.

[0012] According to the network element security detection method provided in this application, the network element data service request includes data requester information, data provider information, data transmission type, and data collection type.

[0013] According to the network element security detection method provided in this application, the data provider information includes the identifier of the target network element, and the data requester information includes the identifier of the first device, the second device, or the data storage function device.

[0014] According to the network element security detection method provided in this application, before forwarding the network element security-related data to the first device or sending notification information to the first device, the method includes: A security configuration policy is sent to the first device, and the security configuration policy is used to configure the security detection capability of the first device.

[0015] This application also provides a method for transmitting network element security-related data, applied to a fourth device, including: Obtain the network data service request sent by the second device; Based on the network data service request, a data collection task request is determined, and the data collection task request is sent to the target network element. The data collection task request is used to configure the target network element to collect network element security-related data. Based on the network data service request, a data transmission configuration is determined, and the data transmission configuration is sent to the data transmission agent. The data transmission configuration is used to construct data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

[0016] According to the network element security-related data transmission method provided in this application, the method for obtaining network element data service requests includes: Obtain the network data service request sent by the target network element or the second device.

[0017] According to the network element security-related data transmission method provided in this application, the network element data service request includes data requester information, data provider information, data transmission type, and data collection type.

[0018] According to the network element security-related data transmission method provided in this application, the data provider information includes the identifier of the target network element, and the data requester information includes the identifier of the local device.

[0019] According to the network element security-related data transmission method provided in this application, the data acquisition task request includes data acquisition type, acquisition period, reporting period and transmission channel type.

[0020] This application also provides a network element security detection system, including: A first device is configured to receive network element security-related data of a target network element from a target device, wherein the network element security-related data is transmitted from the target network element to the target device through a data channel, and to perform security detection based on the network element security-related data. The second device is configured to acquire network element security detection requirements, determine target network elements based on these requirements, acquire network element security-related data of the target network element forwarded by the data transmission agent via a data channel with the data transmission agent, and forward the network element security-related data to the first device; or, acquire the network element security-related data of the target network element from a data storage service and forward the network element security-related data to the first device, wherein the network element security-related data is transmitted from the target network element to the data storage service device via a data channel; or, send a notification message to the first device, the notification message indicating that the network element security-related data of the target network element is stored in the data storage service device, wherein the network element security-related data is transmitted from the target network element to the data storage service device via a data channel; or, acquire the network element security-related data of the target network element from the data storage service device and send the network element security-related data to the first device, wherein the network element security-related data is transmitted from the target network element to the data storage service device via a data channel.

[0021] According to the network element security detection system provided in this application, the system further includes: The fourth device is used for: Request to obtain network data information service; Based on the network data service request, a data collection task request is determined, and the data collection task request is sent to the target network element. The data collection task request is used to configure the target network element to collect network element security-related data. Based on the network data service request, a data transmission configuration is determined, and the data transmission configuration is sent to the data transmission agent. The data transmission configuration is used to construct data channels between the data transmission agent and the target network element and the target device, respectively. The target device is the first device, the second device, or a data storage service device.

[0022] According to the network element security detection system provided in this application, the system further includes: The fifth device, the fifth device being used for: Receive security alarms and security logs sent by the first device, and obtain security handling suggestions based on the security alarms and security logs; The safety action recommendations are sent to a third device.

[0023] This application also provides a network element security detection device, including: The data acquisition module is used to receive network element security-related data of the target network element from the target device. The network element security-related data is transmitted from the target network element to the target device through a data channel. The security detection module is used to perform security detection based on the network element security-related data.

[0024] This application also provides a network element security detection device, including: The data acquisition module is used to receive network element security-related data of the target network element from the target device. The network element security-related data is transmitted from the target network element to the target device through a data channel. The security detection module is used to perform security detection based on the network element security-related data.

[0025] This application also provides a network element security detection device, including: The target network element determination module is used to obtain network element security detection requirements and determine target network elements based on the network element security detection requirements. The data sending module is used for: The network element security-related data of the target network element forwarded by the data transmission agent is obtained through the data channel between the data transmission agent and the data transmission agent, and the network element security-related data is forwarded to the first device; Alternatively, a notification message may be sent to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in the data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; Alternatively, network element security-related data of the target network element can be obtained from the data storage service device, and the network element security-related data can be sent to the first device. The network element security-related data is transmitted from the target network element to the data storage service device through a data channel.

[0026] This application also provides a network element security-related data transmission device, including: The request acquisition module is used to acquire network data information service requests and determine data transmission configuration based on the network data information service requests. The request sending module is used to send a data acquisition task request to the target network element. The data acquisition task request is used to configure the target network element to collect network element security-related data. The transmission configuration module is used to send the data transmission configuration to the data transmission agent. The data transmission configuration is used to establish data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

[0027] This application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the network element security detection method and / or the network element security related data transmission method as described above.

[0028] This application also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the network element security detection method as described above and / or the network element security-related data transmission method as described above.

[0029] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the network element security detection method as described above and / or the network element security-related data transmission method as described above.

[0030] The network element security detection method and network element security-related data transmission method provided in this application receive network element security-related data of the target network element from the target device and perform security detection based on the received network element security-related data. The network element security-related data is transmitted from the target network element to the target device through a data channel, which is a data service network transmission channel. This realizes the transmission of network element security-related data through the data service network, rather than on the network element's management network, which can reduce the occupation of management plane bandwidth and achieve the technical effect of reducing the impact of network element security detection on management plane bandwidth. Attached Figure Description

[0031] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1 This is a flowchart illustrating the network element security detection method provided in this application. Figure 1 .

[0033] Figure 2 This is a flowchart illustrating the network element security detection method provided in this application. Figure 2 .

[0034] Figure 3 This is a schematic diagram of the network architecture of the network element security detection method provided in this application.

[0035] Figure 4 This is a schematic diagram of data interaction in the network element security detection method provided in this application.

[0036] Figure 5 This is a flowchart illustrating the network element security-related data transmission method provided in this application.

[0037] Figure 6 This is one of the structural schematic diagrams of the network element security detection device provided in this application.

[0038] Figure 7 This is the second structural schematic diagram of the network element security detection device provided in this application.

[0039] Figure 8 This is a schematic diagram of the network element security-related data transmission device provided in this application.

[0040] Figure 9 This is a schematic diagram of the structure of the electronic device provided in this application. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0042] It should be understood that, when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or collections thereof.

[0043] It should also be understood that the terminology used in this application specification is for the purpose of describing particular embodiments only and is not intended to limit the application. As used in this application specification and the appended claims, the singular forms “a,” “an,” and “the” are intended to include the plural forms unless the context clearly indicates otherwise.

[0044] It should also be further understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0045] As used in this specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrases "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0046] The following is combined with Figure 1 Describe the network element security detection method provided in this application. For example... Figure 1 As shown, the network element security detection method includes the following steps: S110. Receive network element security-related data from the target network element at the target device. The network element security-related data is transmitted from the target network element to the target device through a data channel. S120. Perform security testing based on network element security-related data.

[0047] Figure 1The network element security detection method shown in the figure is applied to a first device, which is a device capable of performing security detection functions. The network element security detection method provided in this application receives network element security-related data of the target network element from the target device and performs security detection based on the received network element security-related data. The network element security-related data is transmitted from the target network element to the target device through a data channel, which is a channel for transmission through a data service network. In this way, the network element security-related data is transmitted through the data service network instead of on the network element's management network, which can reduce the occupation of management plane bandwidth and achieve the technical effect of reducing the impact of network element security detection on management plane bandwidth.

[0048] Network element security-related data refers to data related to the security of network elements, such as network element traffic quintuple information, operating system version, critical files, malicious files, file hash values, security logs, etc. Figure 2 As shown, in the network element security detection method provided in this application, the target network element (as...) Figure 2 Taking the 6G network element (NF) as an example, it can have a built-in data acquisition function. This function can be used to collect at least network element security-related data. Of course, the data acquisition function can also collect other data, including network element performance data and configuration data.

[0049] In some possible implementations, the target device is a second device that receives network element security-related data from the target network element, including: Receive network element security-related data forwarded by the second device; Among them, network element security-related data is forwarded from the data transmission agent to the second device through the data channel between the second device and the data transmission agent; Alternatively, the network element security-related data is obtained by the second device from the data storage function device, and the network element security-related data is transmitted from the target network element to the data storage service device through the data channel.

[0050] In this implementation, network element security-related data is first transmitted to a second device, which then sends it to the first device. The second device performs security control functions. A data channel exists between the second device, the data storage device, and the data transmission agent. After the target network element collects network element security-related data through its built-in data acquisition function, it sends this data to the data transmission agent. The data transmission agent then sends the network element security-related data to the second device or the data storage device via the data channel. If the second device receives the network element security-related data via the data channel, it can forward the data. If the data storage device receives the network element security-related data via the data channel, it can send a notification to the second device. Upon receiving this notification, the second device requests the network element security-related data from the data storage device, which then sends the target network element's network element security-related data to the second device, which then forwards it to the first device.

[0051] In some other possible implementations, the target device is a data storage service device, which receives network element security-related data from the target network element, including: After receiving the notification information, a data request is sent to the data storage service device; Receive network element security-related data sent by data storage service equipment.

[0052] In this implementation, a data channel exists between the data storage device and the data transmission agent. After the target network element collects network element security-related data through its built-in data acquisition function, it sends the network element security-related data to the data transmission agent. The data transmission agent then sends the network element security-related data to the data storage device through the data channel. After the data storage device receives the network element security-related data through the data channel, it can send a notification message to either the first device or the second device that it has received the target network element security-related data. If the first device receives this notification message, it can further send a notification message to the second device. After receiving the notification message that the data storage device has received the target network element security-related data, the second device sends a data request to the data storage device, which then sends the network element security-related data to the first device.

[0053] By forwarding network element security-related data to the first device through the second device, or by having the second device notify the first device to request network element security-related data from the data storage device, the function of obtaining network element security-related data can be independently decoupled, reducing the difficulty of system maintenance.

[0054] In some other possible implementations, the target device acts as a data transmission proxy, receiving network element security-related data from the target network element, including: Receive network element security-related data through the data channel between the data transmission agent and the network element security agent.

[0055] In this implementation, a data channel exists between the first device and the data transmission agent. After the target network element collects network element security-related data through its built-in data acquisition function, it sends the network element security-related data to the data transmission agent. The data transmission agent then directly sends the network element security-related data to the first device through the data channel. Directly sending network element security-related data to the first device through the data transmission agent improves the efficiency of the first device in acquiring such data.

[0056] Further, please refer to Figure 2 This application also provides a network element security detection method applied to the above-mentioned second device, including the following steps: S210, obtaining network element security detection requirements, and determining the target network element based on the network element security detection requirements; S220. Obtain network element security-related data of the target network element forwarded by the data transmission agent through the data channel between the data transmission agent and the data transmission agent, and forward the network element security-related data to the first device; Alternatively, a notification message may be sent to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in the data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; Alternatively, network element security-related data of the target network element can be obtained from the data storage service device, and the network element security-related data can be sent to the first device. The network element security-related data is transmitted from the target network element to the data storage service device through a data channel.

[0057] The network element security detection method provided in this application obtains the network element security-related data of the target network element through a data channel with a data transmission agent when network element security detection is required. This enables the transmission of network element security-related data through the data service network, rather than through the network element's management network. This reduces the occupation of management plane bandwidth and achieves the technical effect of reducing the impact of network element security detection on management plane bandwidth.

[0058] The network element security detection requirements may include a unique identifier for the target network element, enabling the device that obtains the network element security detection requirements to identify the target network element. The identifier for the target network element is used to identify the target network element; for example, the network element security detection requirements may include the target network element's name, IP address, or FQDN (Fully Qualified Domain Name).

[0059] In one possible implementation of the network element security detection method provided in this application, the second device executing the network element security detection method can be a device for implementing security control functions, or it can be an integrated device for implementing security management, such as a security management terminal. Figure 3 As shown, the security management terminal is a standalone device or unit that communicates with the Operations and Maintenance Center (OCM) or the Virtualized Infrastructure Manager (VIM). (When it is a unit, it can also be referred to as...) Figure 2 (The security management unit in the application). When executing the network element security detection method provided in this application, the security management terminal obtains the network element security detection requirements based on local devices, such as reading them from a preset storage area or parsing the input content of the input device. Based on the network element security detection requirements, it determines the target network element, and receives the network element security-related data of the target network element on the data plane through the data channel between it and the data transmission agent, and sends it to the first device for security capability analysis. However, in practice, the security management terminal in network operation and maintenance also integrates other operation and maintenance functions, such as security handling based on security detection results. In this implementation method, the security management terminal integrates many functions, resulting in a large workload for operation and maintenance.

[0060] In another possible implementation of this application, the task can be performed by a separate second device for implementing security control functions. In this implementation, obtaining network element security detection requirements includes: Receive network element security detection requests sent by third-party devices.

[0061] The third device is a security management device, such as a security management terminal. In this implementation, the security control function is decoupled from the third device in the network. The third device sends the network element security detection requirements to the second device, which then executes the network element security detection method provided in this application to acquire network element security-related data and send it to the first device for security detection. Compared to integrating all network element security detection functions into the third device, this reduces the workload of the third device's operation and maintenance and improves the reliability of operation and maintenance within the network architecture.

[0062] After the target network element collects network element security-related data through its built-in data acquisition function, in some possible implementations, this data is directly sent to a data transmission proxy. The data transmission proxy then sends the data to a second device executing the network element security detection method provided in this application via a data service network data channel. Upon receiving the network element security-related data, the second device forwards it to the first device for security detection. In other possible implementations, the data transmission proxy sends the target network element security-related data to a data storage device. After receiving the data through the data channel, the data storage device can send a notification to either the first or second device that it has received the target network element security-related data. If the first device receives this notification, it can further send a notification to the second device. Upon receiving this notification, the second device sends a data request to the data storage device, which then sends the network element security-related data to the first device.

[0063] In one possible implementation, the target network element can also have built-in security capabilities to enable basic security control within the network element, such as whitelist-based traffic filtering and whitelist-based access control for critical files.

[0064] When multiple security checks are required on network elements, a large amount of network element security-related data needs to be transmitted. Furthermore, 6G networks offer integrated air-space-ground coverage and support a massive number of IoT terminals, further increasing their exposure compared to 5G. This exacerbates the risk of network elements being attacked. With the development of artificial intelligence, network security confrontations are increasing, and zero-day attacks targeting networks are also on the rise. When attackers target network elements, they generate a large number of malicious files and hashes, further increasing the volume of network element security-related data. The network element security detection method provided in this application transmits network element security-related data through a data service network. Compared to existing technologies that use the network element's associated network for transmission, this effectively reduces the bandwidth consumption of network element security-related data transmission on the management network, thus reducing the impact of network element security detection on the management network bandwidth.

[0065] Furthermore, before sending network element security detection requests to the device executing the network element security detection method provided in this application, the third device can obtain information about the network element, its built-in security capabilities, and security detection capabilities from the OMC or VIM in advance, forming network topology and security capability assets, thereby achieving more accurate and efficient network security management.

[0066] In one possible implementation of the network element security detection method provided in this application, the first device can be a device integrating multiple security detection capabilities. For example, the first device can integrate service-oriented firewall functions, IPS (intrusion-prevention system) functions, virus databases, etc. However, different security detection capabilities may have different version upgrade times. When a first device integrates multiple security detection capabilities, it will require continuous upgrades, leading to complex version management of the first device. Furthermore, an incorrect upgrade of one security detection capability may cause other security detection capabilities to fail, affecting the normal operation of network element security detection.

[0067] In another possible implementation of the network element security detection method provided in this application, a dedicated first device is set up, meaning that different first devices can correspond to different security detection capabilities. In this implementation, after obtaining the network element security detection requirements, the following steps are included: Determine the type of security detection capability based on the network element security detection requirements; Sending network element security-related data to the first device includes: Send network element security-related data to the first device corresponding to the security detection capability type; Send notification information to the first device, including: Send a notification message to the first device corresponding to the type of security detection capability.

[0068] In this implementation, the network element security detection requirements include not only the identifier of the target network element but also the type of security detection capability. Each first device corresponds to a dedicated security detection capability. The first device can be pre-registered on a second device executing the network element security detection method provided in this application, thereby enabling the second device to determine the security detection capability type corresponding to each first device. Alternatively, the first device can be pre-registered on a security management device, which then sends the security detection capability type corresponding to each first device to the device executing the network element security detection method provided in this application.

[0069] The device that performs the network element security detection method provided in this application determines the required security detection capabilities based on the network element security detection requirements. For example, if the required security detection capabilities include IDS (intrusion detection system) and virus detection, then the network element traffic in the network element security-related data is sent to the first device with the corresponding IDS capability, and the file hash value in the network element security-related data is sent to the first device with the corresponding virus detection capability.

[0070] By setting up dedicated first devices for different types of security detection capabilities, the decoupling of different security detection capabilities can be achieved. Targeted execution of security detection capabilities through dedicated first devices not only ensures the accuracy of detection results, but also ensures that upgrading one security detection capability will not affect the operation of other security detection capabilities. This improves the reliability of network element security detection. Furthermore, upgrading network element security detection functions does not involve the security management end, reducing the number of upgrades required by the security management end and alleviating the workload and cost of operation and maintenance.

[0071] In one possible implementation, before sending network element security-related data to the security detection device, the following is also included: The security configuration policy is sent to the first device, and the security configuration policy is used to configure the security detection capabilities of the first device.

[0072] Security configuration policies are sent to security detection devices to configure them for security purposes. For example, for the first device with a security detection capability type of virus detection, the virus database is updated; for the first device with a security detection capability type of intrusion detection, the behavior detection database is updated. Configuring security for these devices ensures their security detection capabilities and improves the accuracy of network element security detection results.

[0073] In existing network architectures, network operation and maintenance data (including network element security-related data) is transmitted on the management plane. However, in the network element security detection method provided in this application, network element security-related data is transmitted on the data plane, specifically through a data transmission proxy. Data channels exist on the data plane between the data transmission proxy, the target network element, and the device executing the network element security detection method provided in this application.

[0074] Data channels can be established either when the target network element is first subjected to network element security testing, before acquiring network element security-related data, and not re-established for subsequent network element security testing, or after each security testing of the target network element is completed, the newly established data channel is discarded, and re-established each time network element security testing of the target network element is required, before acquiring network element security-related data. The establishment process of data channels is explained below.

[0075] In one possible implementation, the device executing the network element security detection method provided in this application can directly establish a data channel with the data transmission agent. However, since there may be multiple network elements that need to be security detected, and different security detection capability types may correspond to different data acquisition and transmission cycles, if the data transmission control function is integrated into the device executing the network element security detection method provided in this application, when the data transmission configuration of different data channels between the device and the data transmission agent needs to be modified, it may affect the acquisition and distribution function of network element security-related data of the device executing the network element security detection method provided in this application, thereby increasing the maintenance difficulty of the device executing the network element security detection method provided in this application.

[0076] In another possible implementation of the network element security detection method provided in this application, before obtaining network element security-related data of the target network element through the data channel with the data transmission agent, the following steps are included: Based on the network element security detection requirements, a network element data service request is determined and sent to the fourth device. The network element data service request is used to establish a data channel between the first or second device's data storage function device and the data transmission agent.

[0077] In this implementation, such as Figure 4As shown, a fourth device is used to control data transmission on the data service network. This fourth device is capable of data service control functions, specifically including the control of the data channel establishment process for transmitting network element security-related data. By using a separate fourth device to control data transmission on the data service network, the data transmission control function can be decoupled. When the data transmission control function needs logical changes or upgrades, only the configuration of the fourth device needs to be modified, thereby reducing the operational and maintenance difficulty of the device executing the network element security detection method provided in this application.

[0078] In some possible implementations, the network data service request may be generated by the second device based on the network element security detection requirements, and the second device sends the network data service request to the fourth device. In other possible implementations, the network data service request may be initiated by the target network element. In this case, the target network element actively proposes to perform security detection on the target network element, thereby generating the network data service request and sending it to the fourth device.

[0079] Specifically, the network data service request includes data requester information, data provider information, data transmission type, and data collection type. The data transmission type is data service network transmission, meaning a request is made to the fourth device to transmit data over the data service network. This prompts the fourth device to configure data transmission with the data transmission agent, establishing a data channel. The data collection type reflects the type of network element security-related data required, such as all traffic from a specific IP address or port, all traffic 5-tuple information, or all file hash values. The data provider is the target network element, and its information includes the target network element's identifier, such as its name, IP address, or FQDN.

[0080] Furthermore, in one possible implementation, the network element data service request also includes a data storage configuration. This data storage configuration is used to configure the data storage service device to store network element security-related data of the target network element. In other words, when the data storage service device is required to store network element security-related data of the target network element, the network element data service request includes a data storage configuration. This allows the network element security-related data of the target network element to be collected and then sent to the data storage service device for storage through the data channel between the data transmission proxy and the data storage service device. The data storage service device can then receive requests from other devices and forward the stored network element security-related data to the corresponding devices.

[0081] In one possible implementation, the data recipient can be directly identified as a first device, a second device, or a data storage service device in the network element data service request. The data requester information includes the identifier of the first device, the second device, or the data storage service, such as the device name, IP address, or FQDN. By using the second device or data storage service as the data requester and distributing the requested network element security-related data to the corresponding first device, a single request can distribute data to multiple first devices with the same security data requirements. This avoids the bandwidth pressure on the data plane caused by multiple security detection capabilities requesting the same security data from the data plane control function, and reduces the load on the fourth device and the data transmission proxy.

[0082] Upon receiving a network data service request, the fourth device determines a data transmission configuration based on the request. This configuration establishes data channels between the data transmission agent and the target network element, as well as between the data transmission agent and the first, second, or data storage service device. The data transmission configuration includes data provider and data user information, allowing the data transmission agent to identify the data provider and data user and establish data channels with both.

[0083] After receiving the network data service request, the fourth device also generates a data acquisition task request based on the network data service request and sends it to the target network element. The target network element can register its data service with the fourth device in advance, including the type of data service (such as collecting network element security-related data), network element name, network element IP address or FQDN. After successfully authenticating the target network element, the fourth device saves the target network element's data service data, so that it can send the data acquisition task to the target network element after receiving the network data service request. The data acquisition task request includes at least the data acquisition type and the transmission channel type (data channel on the data plane), so that the target network element can determine what type of network element security-related data needs to be collected and how to send the collected network element security-related data to the data transmission agent through the data channel on the data plane.

[0084] Furthermore, in possible implementations, the data acquisition task also includes an acquisition cycle and a reporting cycle. This allows for security detection to be performed based on specific security detection capability types, specific acquisition cycles, and specific detection cycles, rather than real-time acquisition and actual detection, thereby improving the efficiency of security detection capability results.

[0085] like Figure 4 As shown, after the data channel is established, the target network element collects network element security-related data according to the configuration of the received data collection task, and sends it to the data transmission agent through the data channel. The data transmission agent then sends it to the first device, the second device, or the data storage service device.

[0086] Based on the above-described network element security detection method, this application also provides a network element security-related data transmission method, applied to the fourth device in the above-described network element security detection method, such as... Figure 5 As shown, the steps include: S510, Obtain network data information service request; S520: Determine the data acquisition task request based on the network element data service request, and send the data acquisition task request to the target network element. The data acquisition task request is used to configure the target network element to collect network element security-related data. S530. Based on the network data service request, determine the data transmission configuration and send the data transmission configuration to the data transmission agent. The data transmission configuration is used to build data channels between the data transmission agent and the target network element and the target device, respectively. The target device is the first device, the second device, or the data storage service device.

[0087] The network element security-related data transmission method provided in this application establishes a data channel between the target network element and the target device through a data service network, enabling the network element security-related data of the target network element to be transmitted to the second device through the data service network. This reduces the bandwidth consumption of the network element's management network and achieves the technical effect of reducing the impact of network element security detection on the management network bandwidth.

[0088] In some possible implementations, the network element data service request may be generated by the second device based on the network element security detection requirements, and the second device sends the network element data service request to the fourth device. In other possible implementations, the network element data service request may be initiated by the target network element itself. In this case, the target network element actively proposes to perform security detection on itself, thereby generating the network element data service request and sending it to the fourth device. In one possible implementation, the network element data service request includes data requester information, data provider information, data transmission type, and data collection type. For details, please refer to the description of the network element data service request in the implementation methods of the network element security detection method described above.

[0089] In one possible implementation, the data acquisition task request includes the data acquisition type, acquisition period, reporting period, and transmission channel type. For details, please refer to the description of the data acquisition task request in the implementation of the network element security detection method described above.

[0090] After the data channel is established, the target network element collects network element security-related data according to the configuration of the received data collection task, and sends it to the data transmission agent through the data channel. The data transmission agent then sends it to the first device, the second device, or the data storage service device. For details, please refer to the explanation of the implementation method of the network element security detection method in the previous text.

[0091] Based on the described network element security detection method, this application also provides a network element security detection system, including: The first device is used to receive network element security-related data of the target network element from the target device. The network element security-related data is transmitted from the target network element to the target device through a data channel, and security detection is performed based on the network element security-related data. The second device is used to acquire network element security detection requirements and determine target network elements based on these requirements; it acquires network element security-related data of the target network element forwarded by the data transmission agent through a data channel with the data transmission agent, and forwards the network element security-related data to the first device; or, it acquires network element security-related data of the target network element from the data storage service and forwards it to the first device, wherein the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; or, it sends a notification message to the first device, indicating that the network element security-related data of the target network element is stored in the data storage service device, wherein the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; or, it acquires network element security-related data of the target network element from the data storage service device and sends the network element security-related data to the first device, wherein the network element security-related data is transmitted from the target network element to the data storage service device through a data channel.

[0092] In the network element security detection system provided in this application, the first device is used to execute a network element security detection method provided in this application, to obtain network element security-related data of the target network element and perform security detection. The specific content can be referred to the network element security detection method described above. The second device is used to execute another network element security detection method provided in this application, to forward network element security-related data to the first device or notify the first device to obtain network element security-related data from the data storage service device.

[0093] In one possible implementation, the network element security detection system provided in this application further includes: The fourth device is used for: Request to obtain network data information service; Based on the network data service request, the data acquisition task request is determined and sent to the target network element. The data acquisition task request is used to configure the target network element to collect network element security-related data. Based on the network data service request, the data transmission configuration is determined and sent to the data transmission agent. The data transmission configuration is used to build data channels between the data transmission agent and the target network element and the target device, respectively. The target device is the first device, the second device, or the data storage service device.

[0094] In the network element security detection system provided in this application, the fourth device is used to execute the network element security-related data transmission method provided in this application and to build a data channel between the data transmission agent and the target device. For details, please refer to the network element security-related data transmission method described above.

[0095] In one possible implementation, the network element security detection system provided in this application further includes a fifth device, which is used for: Receive security alarms and security logs sent by the first device, and analyze them to obtain security handling suggestions; Send safety handling recommendations to the third device.

[0096] In this implementation, the network element security detection system provided in this application also includes a fifth device. This fifth device is a designated device capable of security analysis. After the first device performs security detection based on network element security-related data, the first device outputs security alarms and security logs, and sends these to the fifth device. The fifth device can further analyze the security alarms and security logs to generate security handling suggestions. In one possible implementation, security analysis results can be generated first based on security logs and security alarms. These results reflect the attack situation of network elements in the network architecture and may include the attack source, attack target, and cause of the security incident. Then, security handling suggestions are generated based on the security analysis results. These suggestions can be obtained from a pre-set security handling suggestion library. Specifically, the simplified security handling library can pre-store handling suggestions corresponding to different security events. Based on the received security analysis results, the corresponding security handling suggestions can be retrieved. Alternatively, safety action recommendations can be obtained based on a pre-set safety action recommendation generation model. Specifically, a safety action recommendation generation model can be pre-deployed in the fifth device. The input of this model is the safety analysis result, and the output is the safety action recommendation. This model can be obtained based on multiple sets of training data. Each set of training data includes the sample safety analysis result and the corresponding safety action recommendation label.

[0097] After receiving the safety handling recommendations, the fifth device sends them to the third device.

[0098] In this implementation of the network element security detection system provided in this application, the security analysis function is further decoupled from the third device, which can further reduce the functional integration of the third device. When the security analysis function needs to be upgraded, it will not affect the operation of other management functions in the third device, thus reducing the operation and maintenance difficulty of the third device.

[0099] After receiving the security action suggestion, the third device performs the security action, such as sending a new network element security detection request to the second device, which includes the identifier of a network element suspected of launching an attack, so that the second device performs security detection on the network element suspected of launching an attack based on the network element security detection method described above.

[0100] like Figure 4 As shown, in one possible implementation, the interaction process between the various devices involved in the network element security detection system provided in this application includes: 1. The network element and the fourth device interact with each other to complete the data acquisition service registration from the network element to the fourth device, thereby enabling the fourth device to send a data acquisition task request to the network element to collect data.

[0101] 2. The third device sends a network element security detection request to the second device that performs the network element security detection method provided in this application.

[0102] 3. The second device sends a network data service request to the fourth device.

[0103] 4. The fourth device sends the data transmission configuration to the data transmission agent.

[0104] 5. The fourth device sends a data acquisition task request to the network element.

[0105] 6. Establish a data channel between the data transmission agent, network element, and second device.

[0106] 7. The second device performs a safety configuration on the first device.

[0107] 8. The network element collects network element security-related data and reports it to the data transmission agent.

[0108] 9. The data transmission proxy forwards network element security-related data to the second device.

[0109] 10. The second device sends network element security-related data to the first device.

[0110] 11. The first device generates security events and security logs, and sends them to the fifth device.

[0111] 12. Based on the received security events and security logs, the fifth device generates security handling suggestions and sends them to the third device.

[0112] 13. The third device sends the network element security detection request to the second device.

[0113] The network element security detection device provided in this application is described below. The network element security detection device described below can be referred to in correspondence with the network element security detection method described above. For example... Figure 6As shown, the network element security detection device provided in this application includes: The data acquisition module 610 is used to receive network element security-related data from the target network element at the target device. The network element security-related data is transmitted from the target network element to the target device through a data channel. The security detection module 620 is used to perform security detection based on network element security-related data.

[0114] like Figure 7 As shown, another network element security detection device provided in this application includes: The target network element determination module 710 is used to obtain network element security detection requirements and determine target network elements based on these requirements. Data receiving module 720, used for: Used to obtain network element security detection requirements, and to determine target network elements based on these requirements; The data sending module is used for: The network element security-related data of the target network element forwarded by the data transmission agent is obtained through the data channel between the data transmission agent and the data transmission agent, and the network element security-related data is forwarded to the first device. Alternatively, a notification message may be sent to the first device. The notification message is used to indicate that the network element security-related data of the target network element is stored in the data storage service device. The network element security-related data is transmitted from the target network element to the data storage service device through the data channel. Alternatively, network element security-related data of the target network element can be obtained from the data storage service device, and the network element security-related data can be sent to the first device. The network element security-related data is transmitted from the target network element to the data storage service device through the data channel.

[0115] The following describes the network element security-related data transmission device provided in this application. The network element security-related data transmission device described below can be referred to in correspondence with the network element security-related data transmission method described above, such as... Figure 8 As shown, the network element security-related data transmission device provided in this application includes: The request acquisition module 810 is used to acquire network data service requests and determine data transmission configuration based on network data service requests. The request sending module 820 is used to send a data acquisition task request to the target network element. The data acquisition task request is used to configure the target network element to collect network element security-related data. The transmission configuration module 830 is used to send data transmission configuration to the data transmission agent. The data transmission configuration is used to establish data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

[0116] Figure 9 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 9 As shown, the electronic device may include a processor 910, a communications interface 920, a memory 930, and a communication bus 940, wherein the processor 910, communications interface 920, and memory 930 communicate with each other via the communication bus 940. The processor 910 can call logical instructions in the memory 930 to execute a network element security detection method and / or a network element security-related data transmission method. The network element security detection method includes: receiving network element security-related data of a target network element from a target device, wherein the network element security-related data is transmitted from the target network element to the target device through a data channel; and performing security detection based on the network element security-related data. Alternatively, the network element security detection method includes: obtaining network element security detection requirements, determining the target network element based on the network element security detection requirements; obtaining network element security-related data of the target network element forwarded by the data transmission agent through a data channel between the data transmission agent and the data transmission agent, and forwarding the network element security-related data to the first device; or, sending a notification message to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in a data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; or, obtaining the network element security-related data of the target network element from the data storage service device, sending the network element security-related data to the first device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel. The method for transmitting network element security-related data includes: obtaining network element data service requests; determining data acquisition task requests based on network element data service requests, and sending data acquisition task requests to the target network element. The data acquisition task requests are used to configure the target network element to acquire network element security-related data; determining data transmission configurations based on network element data service requests, and sending data transmission configurations to the data transmission agent. The data transmission configurations are used to construct data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

[0117] Furthermore, the logical instructions in the aforementioned memory 930 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0118] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to execute the network element security detection method and / or network element security-related data transmission method provided by the above methods. The network element security detection method includes: receiving network element security-related data of a target network element from a target device, wherein the network element security-related data is transmitted from the target network element to the target device through a data channel; and performing security detection based on the network element security-related data. Alternatively, the network element security detection method includes: obtaining network element security detection requirements, determining the target network element based on the network element security detection requirements; obtaining network element security-related data of the target network element forwarded by the data transmission agent through a data channel between the data transmission agent and the data transmission agent, and forwarding the network element security-related data to the first device; or, sending a notification message to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in a data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; or, obtaining the network element security-related data of the target network element from the data storage service device, sending the network element security-related data to the first device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel. The method for transmitting network element security-related data includes: obtaining network element data service requests; determining data acquisition task requests based on network element data service requests, and sending data acquisition task requests to the target network element. The data acquisition task requests are used to configure the target network element to acquire network element security-related data; determining data transmission configurations based on network element data service requests, and sending data transmission configurations to the data transmission agent. The data transmission configurations are used to construct data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

[0119] Furthermore, this application also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program is implemented to perform the network element security detection method and / or network element security-related data transmission method provided by the above methods. The network element security detection method includes: receiving network element security-related data of a target network element from a target device, wherein the network element security-related data is transmitted from the target network element to the target device through a data channel; and performing security detection based on the network element security-related data. Alternatively, the network element security detection method includes: obtaining network element security detection requirements, determining the target network element based on the network element security detection requirements; obtaining network element security-related data of the target network element forwarded by the data transmission agent through a data channel between the data transmission agent and the data transmission agent, and forwarding the network element security-related data to the first device; or, sending a notification message to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in a data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; or, obtaining the network element security-related data of the target network element from the data storage service device, sending the network element security-related data to the first device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel. The method for transmitting network element security-related data includes: obtaining network element data service requests; determining data acquisition task requests based on network element data service requests, and sending data acquisition task requests to the target network element. The data acquisition task requests are used to configure the target network element to acquire network element security-related data; determining data transmission configurations based on network element data service requests, and sending data transmission configurations to the data transmission agent. The data transmission configurations are used to construct data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

[0120] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0121] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0122] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A network element security detection method, characterized in that, Applied to the first device, including: Receive network element security-related data from the target network element at the target device, wherein the network element security-related data is transmitted from the target network element to the target device through a data channel; Security detection is performed based on the network element security-related data.

2. The network element security detection method according to claim 1, characterized in that, The target device is a second device, and the receiving of network element security-related data from the target device includes: Receive the network element security-related data forwarded by the second device; The network element security-related data is forwarded from the data transmission agent to the second device through the data channel between the second device and the data transmission agent. Alternatively, the network element security-related data is obtained by the second device from the data storage function device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel.

3. The network element security detection method according to claim 1, characterized in that, The target device is a data transmission proxy, and the receiving of network element security-related data from the target network element from the target device includes: The network element security-related data is received through the data channel between the data transmission agent and the data transmission agent.

4. The network element security detection method according to claim 1, characterized in that, The target device is a data storage service device, and the step of receiving network element security-related data from the target device includes: After receiving the notification information, a data request is sent to the data storage service device; Receive network element security-related data sent by the data storage service device.

5. A network element security detection method, characterized in that, Applied to a second device, including: Obtain network element security detection requirements, and determine target network elements based on the network element security detection requirements; The network element security-related data of the target network element forwarded by the data transmission agent is obtained through the data channel between the data transmission agent and the data transmission agent, and the network element security-related data is forwarded to the first device; Alternatively, a notification message may be sent to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in the data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; Alternatively, network element security-related data of the target network element can be obtained from the data storage service device, and the network element security-related data can be sent to the first device. The network element security-related data is transmitted from the target network element to the data storage service device through a data channel.

6. The network element security detection method according to claim 5, characterized in that, The requirements for obtaining network element security detection include: Receive the network element security detection request sent by the third device.

7. The network element security detection method according to claim 5, characterized in that, After obtaining the network element security detection requirements, the following is included: The type of security detection capability is determined based on the aforementioned network element security detection requirements; The step of forwarding the network element security-related data to the first device includes: The network element security-related data is sent to the first device corresponding to the security detection capability type. Sending notification information to the first device includes: The notification information is sent to the first device corresponding to the security detection capability type.

8. The network element security detection method according to claim 5, characterized in that, Before forwarding the network element security-related data to the first device or sending notification information to the first device, the following steps are included: Based on the network element security detection requirements, a network element data service request is determined and sent to the fourth device. The network element data service request is used to establish a data channel between the first device, the second device, or the data storage function device and the data transmission proxy.

9. The network element security detection method according to claim 8, characterized in that, The network data service request includes information about the data requester, information about the data provider, data transmission type, and data collection type.

10. The network element security detection method according to claim 9, characterized in that, The data provider information includes the identifier of the target network element, and the data requester information includes the identifier of the first device, the second device, or the data storage function device.

11. The network element security detection method according to claim 5, characterized in that, Before forwarding the network element security-related data to the first device or sending notification information to the first device, the following steps are included: A security configuration policy is sent to the first device, and the security configuration policy is used to configure the security detection capability of the first device.

12. A method for transmitting network element security-related data, characterized in that, Applied to the fourth device, including: Request to obtain network data information service; Based on the network data service request, a data collection task request is determined, and the data collection task request is sent to the target network element. The data collection task request is used to configure the target network element to collect network element security-related data. Based on the network data service request, a data transmission configuration is determined, and the data transmission configuration is sent to the data transmission agent. The data transmission configuration is used to construct data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

13. The method for transmitting network element security-related data according to claim 12, characterized in that, The request to obtain network data information service includes: Obtain the network data service request sent by the target network element or the second device.

14. The method for transmitting network element security-related data according to claim 12, characterized in that, The network data service request includes information about the data requester, information about the data provider, data transmission type, and data collection type.

15. The method for transmitting network element security-related data according to claim 12, characterized in that, The data acquisition task request includes the data acquisition type, acquisition period, reporting period, and transmission channel type.

16. A network element security detection system, characterized in that, include: A first device is configured to receive network element security-related data of a target network element from a target device, wherein the network element security-related data is transmitted from the target network element to the target device through a data channel, and to perform security detection based on the network element security-related data. The second device is used to acquire network element security detection requirements and determine target network elements based on the network element security detection requirements. The network element security-related data of the target network element forwarded by the data transmission agent is obtained through a data channel between the data transmission agent and the data transmission agent, and the network element security-related data is forwarded to the first device; or, a notification message is sent to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in a data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; or, the network element security-related data of the target network element is obtained from the data storage service device, and the network element security-related data is sent to the first device, the network element security-related data being transmitted from the target network element to the data storage service device through a data channel.

17. The network element security detection system according to claim 16, characterized in that, The system also includes: The fourth device is used for: Request to obtain network data information service; Based on the network data service request, a data collection task request is determined, and the data collection task request is sent to the target network element. The data collection task request is used to configure the target network element to collect network element security-related data. Based on the network data service request, a data transmission configuration is determined, and the data transmission configuration is sent to the data transmission agent. The data transmission configuration is used to construct data channels between the data transmission agent and the target network element and the target device, respectively. The target device is the first device, the second device, or the data storage service device.

18. The network element security detection system according to claim 16, characterized in that, The system also includes: The fifth device, the fifth device being used for: Receive security alarms and security logs sent by the first device, and obtain security handling suggestions based on the security alarms and security logs; The safety action recommendations are sent to a third device.

19. A network element security detection device, characterized in that, include: The data acquisition module is used to receive network element security-related data of the target network element from the target device. The network element security-related data is transmitted from the target network element to the target device through a data channel. The security detection module is used to perform security detection based on the network element security-related data.

20. A network element security detection device, characterized in that, include: The target network element determination module is used to obtain network element security detection requirements and determine target network elements based on the network element security detection requirements. The data sending module is used for: The network element security-related data of the target network element forwarded by the data transmission agent is obtained through the data channel between the data transmission agent and the data transmission agent, and the network element security-related data is forwarded to the first device; Alternatively, a notification message may be sent to the first device, the notification message being used to indicate that the network element security-related data of the target network element is stored in the data storage service device, and the network element security-related data is transmitted from the target network element to the data storage service device through a data channel; Alternatively, network element security-related data of the target network element can be obtained from the data storage service device, and the network element security-related data can be sent to the first device. The network element security-related data is transmitted from the target network element to the data storage service device through a data channel.

21. A network element security-related data transmission device, characterized in that, include: The request acquisition module is used to acquire network data information service requests and determine data transmission configuration based on the network data information service requests. The request sending module is used to send a data acquisition task request to the target network element. The data acquisition task request is used to configure the target network element to collect network element security-related data. The transmission configuration module is used to send the data transmission configuration to the data transmission agent. The data transmission configuration is used to establish data channels between the data transmission agent and the target network element and the target device, respectively. The target device is a first device, a second device, or a data storage service device.

22. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the network element security detection method as described in any one of claims 1 to 11 and / or the network element security-related data transmission method as described in any one of claims 12 to 15.

23. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the network element security detection method as described in any one of claims 1 to 11 and / or the network element security-related data transmission method as described in any one of claims 12 to 15.

24. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the network element security detection method as described in any one of claims 1 to 11 and / or the network element security-related data transmission method as described in any one of claims 12 to 15.