Network security service operation environment generation method and device, network security service execution method and device, storage medium, program product and computer equipment

By acquiring network security service requirements, generating security service configuration data, and building a stable network security service operating environment, the problem of network security services relying on professional knowledge has been solved, achieving efficient and stable operating environment generation and improving the reliability and accessibility of network security services.

CN121508908APending Publication Date: 2026-02-10CHINA MOBILE GRP GUANGDONG CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511464642.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-14
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing technologies, the operating environment of cybersecurity services depends on the professional knowledge and development capabilities of cybersecurity service personnel, which leads to unstable reliability and limits the popularization and application of cybersecurity services.

Method used

By acquiring network security service requirements, generating security service configuration data, and utilizing pre-formatted network security service language information and environment generation models, a stable network security service operating environment is automatically constructed, including target software, hardware, network capabilities, and delivery capability information.

Benefits of technology

It enables the automated generation of efficient and stable network security service operating environments, reduces reliance on specialized knowledge, and improves the reliability and accessibility of network security services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121508908A_ABST
    Figure CN121508908A_ABST
Patent Text Reader

Abstract

The invention discloses a network security service operation environment generation method and device, a network security service execution method and device, a storage medium, a program product and computer equipment. The method comprises the steps of obtaining a network security service demand; generating security service configuration data based on the network security service demand; and generating a network security service operation environment based on the security service configuration data, so that after a network security service requirement is obtained, the security service configuration data can be automatically generated according to the network security service requirement, and then the stable and reliable security service operation environment is efficiently generated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer security technology, and in particular to a method and apparatus for generating a network security service operating environment, executing network security services, storage media, program products, and computer equipment. Background Technology

[0002] Currently, cybersecurity services are typically used to address evolving cybersecurity threats, and the normal and efficient operation of these services depends on a compatible operating environment.

[0003] In related technologies, cybersecurity service personnel typically customize and deliver the relevant security service operating environment.

[0004] However, this requires cybersecurity service personnel to have strong cybersecurity expertise and development capabilities, which results in the reliability of the security service operating environment being limited by the personnel's skill level and thus not stable enough, and restricts the popularization and application of cybersecurity services. Summary of the Invention

[0005] To address the aforementioned technical issues, this application proposes a method and apparatus for generating a network security service runtime environment and executing network security services, as well as a storage medium, program product, and computer equipment. These methods and apparatuses can efficiently generate a stable and reliable security service runtime environment, thereby facilitating the normal and efficient operation of network security services.

[0006] In a first aspect, embodiments of this application provide a method for generating a network security service runtime environment, including: Obtaining network security service requests; Based on the aforementioned network security service requirements, security service configuration data is generated; Based on the security service configuration data, a network security service runtime environment is generated.

[0007] Optionally, generating security service configuration data based on the network security service requirements includes: Based on the aforementioned network security service requirements, generate network security service language information with a preset format; Based on the network security service language information, security service configuration data is generated.

[0008] Optionally, generating a network security service runtime environment based on the security service configuration data includes: Based on the security service configuration data, obtain service target requirements and at least one scenario information, wherein the at least one scenario information includes at least one of the following: software scenario information, hardware scenario information, network capability scenario information, and delivery capability scenario information. Based on the at least one scenario information, a service cost function and an efficiency function are determined respectively, wherein the efficiency function is used to indicate the joint efficiency corresponding to the at least one scenario information; Based on the service target requirements, the service cost function, and the performance function, a network security service operating environment is generated, wherein the network security service operating environment includes at least one of the following: target software information, target hardware information, target network capability information, and target delivery capability information, wherein the delivery capability is used to characterize the service delivery standard.

[0009] Optionally, generating the network security service runtime environment based on the service target requirements, the service cost function, and the performance function includes: The constraints are determined based at least on the performance function and the service target requirements; Construct an objective function that minimizes the service cost function; Based on the constraints and the objective function, a network security service operating environment is generated through optimization.

[0010] Secondly, embodiments of this application provide a method for executing a network security service, applicable to a service execution system, the method comprising: Obtain a network security service runtime environment, wherein the network security service runtime environment is generated according to any one of the methods described in the first aspect above; The network security service is executed through the network security service runtime environment.

[0011] Optionally, the network security service includes at least one of the following: vulnerability scanning service, penetration testing service, baseline inspection service, and honeypot service.

[0012] Thirdly, embodiments of this application provide an apparatus for generating a network security service runtime environment, comprising: The requirement elicitation module is used to obtain network security service requirements. The configuration generation module is used to generate security service configuration data based on the network security service requirements. The environment generation module is used to generate a network security service runtime environment based on the security service configuration data.

[0013] Fourthly, embodiments of this application provide an execution apparatus for a network security service, applicable to a service execution system, the apparatus comprising: An environment acquisition module is used to acquire the network security service operating environment, wherein the network security service operating environment is generated according to any one of the methods in the first aspect above; The network security service execution module is used to execute network security services through the network security service runtime environment.

[0014] Fifthly, embodiments of this application provide a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method described in any of the preceding claims.

[0015] Sixthly, embodiments of this application provide a computer program product, including computer instructions that, when executed by a processor, implement the steps of the method described in any of the preceding claims.

[0016] In a seventh aspect, embodiments of this application provide a computer device including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the steps of the method described in any of the preceding claims.

[0017] In summary, the embodiments of this application have at least the following beneficial effects: By adopting the embodiments of this application, network security service requirements are obtained; security service configuration data is generated based on the network security service requirements; and a network security service runtime environment is generated based on the security service configuration data. In this way, after obtaining network security service requirements, security service configuration data can be automatically generated, and then a stable and reliable security service runtime environment can be generated efficiently. Attached Figure Description

[0018] Figure 1 This is a flowchart illustrating the method for generating a network security service runtime environment provided in this application embodiment; Figure 2 This is a flowchart illustrating the method for executing network security services provided in this application embodiment; Figure 3 This is a schematic diagram illustrating the execution of the network security service provided in an embodiment of this application; Figure 4 This is yet another schematic diagram illustrating the execution of the network security service provided in the embodiments of this application; Figure 5 This is a schematic diagram of the structure of the device for generating the network security service runtime environment provided in the embodiments of this application; Figure 6 This is a schematic diagram of the structure of the network security service execution device provided in the embodiments of this application; Figure 7 This is a schematic diagram of the structure of the computer device provided in the embodiments of this application. Detailed Implementation

[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments / examples are only a part of the embodiments / examples of this application, and not all of the embodiments / examples. Based on the embodiments / examples in this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0020] In the description of this application, the terms "first," "second," "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first," "second," "third," etc., may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "multiple" means two or more. In the description of this application, the term "comprising" and its variations are open-ended, meaning "including but not limited to." The term "based on" means "at least partially based on." The term "according to" means "at least partially according to." The term "one embodiment / example" means "at least one embodiment / example"; the term "another embodiment / example" means "at least one additional embodiment / example"; the term "some embodiments / examples" means "at least some embodiments / examples."

[0021] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.

[0022] In the description of this application, it should be noted that, unless otherwise defined, all technical and scientific terms used in this application have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this application is for the purpose of describing specific embodiments only and is not intended to limit the application. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances.

[0023] Firstly, see [the following] Figure 1 The diagram shows a flowchart of a method for generating a network security service runtime environment according to an embodiment of this application. This method for generating a network security service runtime environment can be applied to computer devices with data processing capabilities. The method includes steps S101-S103, as detailed below.

[0024] S101, Obtain network security service requirements.

[0025] In some examples, the cybersecurity service requirement can be a user-submitted / described requirement related to the requested cybersecurity service. For instance, the type and / or objectives of the required cybersecurity service can be identified through user feedback, surveys, and / or business analysis.

[0026] S102, Based on the network security service requirements, generate security service configuration data.

[0027] In some examples, the security service configuration data may refer to the security service configuration used in the network security service operating environment. The security service configuration data may be used to indicate the business processes and / or required resources of the network security service. For example, the security service configuration data may include at least one of the following: the frequency of vulnerability scanning, the target scope of penetration testing, the rules for baseline checks, etc.

[0028] In some examples, a pre-trained configuration generation model can be used to determine security service configuration data based on cybersecurity service requirements. This configuration generation model can be a trained model capable of predicting with cybersecurity service requirements as input and security service configuration data as output. During training, sample cybersecurity service requirements can be used as sample data (which also carries the expected corresponding configuration label, representing the corresponding expected security service configuration data). The model generates predicted security service configuration data based on the sample data. Based on the difference between the predicted security service configuration data and the expected security service configuration data represented by the label, a general loss function is used to calculate the loss value. A general training algorithm (such as gradient descent) is then used to train the model based on the loss value, so that the trained model can possess the aforementioned capabilities.

[0029] S103, Based on the security service configuration data, generate a network security service runtime environment.

[0030] In some examples, the network security service runtime environment may include at least one of the following: target software information, target hardware information, target network capability information, and target delivery capability information, wherein the delivery capability is at least used to characterize the service delivery standard. It is understood that the network security service runtime environment can be a software and / or hardware environment built according to the target software information, target hardware information, target network capability information, and / or target delivery capability information. This environment is adaptable to the network security service requirements, and within this environment, the network security service matching the network security service requirements can run normally and efficiently.

[0031] In some examples, an environment generation module can be used to determine the network security service operating environment based on security service configuration data. For instance, this environment generation module may contain a pre-trained environment generation model. This model can be a trained model capable of predicting network security service operating environments by taking security service configuration data as input and the network security service operating environment as output. During training, sample security service configuration data (which also carries the expected corresponding environment label, representing the corresponding expected network security service operating environment) can be used as sample data to obtain the predicted network security service operating environment generated by the model based on the sample data. Based on the difference between the predicted network security service operating environment and the expected network security service operating environment represented by the label, a general loss function is used to calculate the loss value. Then, a general training algorithm (such as gradient descent) is used to train the model based on the loss value, so that the trained model can possess the aforementioned capabilities.

[0032] In one optional implementation, generating security service configuration data based on the network security service requirements includes: Based on the aforementioned network security service requirements, generate network security service language information with a preset format; Based on the network security service language information, security service configuration data is generated.

[0033] In some examples, a predefined format language (or network security service definition language) can be used to describe the business processes and / or required resources of network security services, such as the frequency of vulnerability scanning, the target scope of penetration testing, and / or the rules for baseline checks. This language can have clear grammatical and / or semantic rules to facilitate understanding and use.

[0034] It is understood that network security service language information with a preset format can essentially refer to related languages ​​described according to a preset language format. In some embodiments, some language templates can also be pre-defined, and the information can be filled in according to the network security service requirements to generate network security service language information with a preset format.

[0035] In some examples, the following is the definition of the network security service definition language in some situations (or it can be understood as the above language template).

[0036] <cybersecurity-tasks> ::= <name-part> "|" <asset-information> "|" <location> "|" <service-description> "|" <task-plan> "|" <price-part> The specific meanings of the above items are as follows.

[0037] <name-part>It is the name of the target asset, such as: Business System 1, OA System, etc.

[0038] <asset-information>This contains detailed information about the asset, such as: XXX.168.0.0 / 24, 172.1.1.1, etc.

[0039] <location>This refers to the location information of the asset, such as: Network 1 in the equipment room on the third floor.

[0040] <service-description>This refers to the content of the required cybersecurity services, such as vulnerability scanning, penetration testing, baseline checks, etc.

[0041] <task-plan>It is the task execution plan, such as the start time, execution cycle, etc.

[0042] <price-part>It refers to the cost of performing security tasks.

[0043] In some specific examples, a concrete security service requirement defined using this language can be as follows: "OA system | XXX.168.1.0 / 24 | Third floor equipment room network 1 | Vulnerability scan | Starting May 1st at 23:00 | 1000 yuan".

[0044] In some examples, a parser module can be used to parse the network security service language information to extract information from it, thereby transforming the network security service language information into security service configuration data (security service configuration file) described by the network security service language, so as to ensure that the requirements can be better understood and implemented by the system.

[0045] In some examples, information can be extracted from network security service language information and converted into corresponding software and / or hardware configuration parameters to generate security service configuration data (security service configuration file).

[0046] In one optional implementation, generating a network security service runtime environment based on the security service configuration data includes: Based on the security service configuration data, obtain service target requirements and at least one scenario information, wherein the at least one scenario information includes at least one of the following: software scenario information, hardware scenario information, network capability scenario information, and delivery capability scenario information. Based on the at least one scenario information, a service cost function and an efficiency function are determined respectively, wherein the efficiency function is used to indicate the joint efficiency corresponding to the at least one scenario information; Based on the service target requirements, the service cost function, and the performance function, a network security service operating environment is generated, wherein the network security service operating environment includes at least one of the following: target software information, target hardware information, target network capability information, and target delivery capability information, wherein the delivery capability is used to characterize the service delivery standard.

[0047] The service target requirement may refer to the type and / or target of the aforementioned required cybersecurity services.

[0048] In some examples, security service configuration data can be passed to the environment generation module, which can then initiate subsequent security environment configuration and resource allocation processes. This is because service target requirements are generally considered when generating a network security service environment. ), service costs ( ), and software ( ),hardware( ), network capabilities ( ) and / or delivery capability ( Due to factors such as these, this embodiment adopts the following integrated network security service generation algorithm.

[0049] In this integrated network security service generation algorithm, the service target requirements can be comprehensively considered. ), service costs ( ), and software ( ),hardware( ), network capabilities ( ) and / or delivery capability ( This relates to different scenarios. It's easy to understand that in this "and / or" relationship, since a user's network security service needs may only have specific requirements for at least some scenarios, it's sufficient to obtain information for at least one scenario with specific requirements. Correspondingly, the information included in the network security service operating environment can correspond one-to-one with this at least one scenario information. If there is other scenario information without specific requirements, it doesn't need to be obtained, or it can be pre-configured standard scenario information.

[0050] First, define the variables and parameters in the algorithm.

[0051] : Select the first The number of software options ( This can be determined from software scenario information.

[0052] : Select the first Number of hardware options ( This can be determined by hardware scenario information.

[0053] : Select the first The number of network capability options ( This can be determined from network capability scenario information.

[0054] : Select the first Number of delivery capability options ( This can be determined from delivery capability scenario information.

[0055] : No. The service capabilities of a software option can be determined by the software scenario information.

[0056] : No. The service capabilities of a hardware option can be determined by hardware scenario information.

[0057] : No. The service capabilities of various network capability options can be determined by network capability scenario information.

[0058] : No. The service capabilities of each delivery capability option can be determined by the delivery capability scenario information.

[0059] : No. The cost of a software option can be determined by information about the software scenario.

[0060] : No. The cost of these hardware options can be determined from hardware scenario information.

[0061] : No. The cost of a network capability option can be determined by information about the network capability scenario.

[0062] : No. The cost of each delivery capability option can be determined from the delivery capability scenario information.

[0063] Secondly, the service cost function can be constructed. Performance function .

[0064]

[0065]

[0066] Here, software, hardware, network capabilities, and / or delivery capabilities can be used to jointly generate effectiveness, which can be relevant numerical values ​​that can be used to comprehensively measure / quantify software, hardware, network capabilities, and / or delivery capabilities. It can be a function that captures joint performance, and it can usually be nonlinear, such as the following equation.

[0067]

[0068] in, , These are preset constants.

[0069] In some examples, the target software information may include a security software package, which may include at least one of the following: a security tool, a security program, or a security component. This target software information can be used to support required security features.

[0070] In some examples, target hardware information may include a list of hardware devices that can be used to indicate the physical devices and / or hardware configurations required to meet network security requirements.

[0071] In some examples, the target network capability information may include a list of network capabilities, which can be used to indicate relevant requirements such as network connectivity, bandwidth, and / or protocol support.

[0072] In some examples, the target delivery capability information may include a list of delivery capabilities, which can be used to assess and confirm the service delivery capabilities that can be provided and / or the performance standards.

[0073] In one optional implementation, generating a network security service runtime environment based on the service target requirements, the service cost function, and the performance function includes: The constraints are determined based at least on the performance function and the service target requirements; Construct an objective function that minimizes the service cost function; Based on the constraints and the objective function, a network security service operating environment is generated through optimization.

[0074] In some examples, the objective function can be constructed using the following formula.

[0075]

[0076] In some examples, the constraint may include a first constraint ( In other words, the performance value represented by the performance function is greater than or equal to the required performance value represented by the service target demand.

[0077] In some examples, the constraint may also include a second constraint, which may include at least one of the following.

[0078]

[0079]

[0080]

[0081]

[0082]

[0083]

[0084]

[0085]

[0086] in, for The maximum value, for The maximum value, for The maximum value, for The maximum value.

[0087] In some examples, the constraint may also include a third constraint, which may include at least one of the following: Select at least one software option: .

[0088] Select at least one hardware option: .

[0089] Select at least one network capability option: .

[0090] Select at least one delivery capability option: .

[0091] In some examples, this optimization can be solved using optimization tools (such as GLPK, LP_SOLVER, etc.) or solvers (such as Lingo, Gurobi). The specific implementation will be based on actual data regarding software, hardware, network capabilities, and / or delivery capabilities.

[0092] In some examples, the network security service runtime environment can be an integrated hardware and software runtime environment. This environment may include all the hardware and software resources required to perform the network security service, such as at least one of the following: virtual machines, containers, security tools, etc.

[0093] Secondly, see Figure 2 The diagram illustrates a flowchart of a method for executing a network security service according to an embodiment of this application. This method is applicable to a service execution system and includes steps S201-S202, as detailed below.

[0094] S201, Obtain the network security service runtime environment, wherein the network security service runtime environment is generated according to any one of the methods described in the first aspect above.

[0095] S202, Execute network security services through the network security service runtime environment.

[0096] In some examples, the service execution system may obtain the network security service runtime environment from other devices, or the service execution system may directly generate the network security service runtime environment according to any one of the methods in the first aspect above. This embodiment does not specifically limit this.

[0097] In some examples, the service execution system can perform the following steps: (1) Confirm whether the critical operating system can be executed on the hardware platform related to the target hardware information.

[0098] (2) Activate the software package corresponding to the target software information and establish the initial operating environment.

[0099] (3) Activate network capabilities related to the target network capability information, such as activating network cards, modems, 4 / 5G IoT cards, etc., to realize the communication function of network security services.

[0100] (4) Provide delivery engineers with service interfaces related to target delivery capability information to assist in service delivery.

[0101] (5) Based on the service delivery implementation plan related to the target delivery capability information, perform the security services defined by the software package in an integrated manner in the target network, such as vulnerability scanning, penetration testing, baseline checks and / or honeypots.

[0102] (6) Return the report obtained from performing the security service to the user who made the request.

[0103] In some examples, the service execution system can use target software information to leverage relevant software to implement the required cybersecurity services.

[0104] In some examples, the service execution system can obtain the necessary physical support and computing power through target hardware information.

[0105] In some examples, the service execution system can acquire the necessary network connectivity and / or traffic management capabilities based on the target network capability information. The service execution system can also process network traffic and effectively deliver security services based on the target network capability information.

[0106] In some examples, the service execution system can use target delivery capability information to provide the necessary support and assurance for the implementation and maintenance of the service.

[0107] In some examples, the service execution system can be deployed in the target network, for example... Figure 3 , Figure 4 The target network 1 and target network 2 are shown.

[0108] In one optional implementation, the network security service includes at least one of the following: vulnerability scanning service, penetration testing service, baseline inspection service, and honeypot service.

[0109] Thirdly, correspondingly, the embodiments of this application also provide a device for generating a network security service operating environment, which can implement all the processes of the network security service operating environment generation method provided in the above embodiments.

[0110] See Figure 5 The diagram illustrates the structure of a network security service runtime environment generation apparatus provided in this application embodiment. The apparatus includes: The requirement acquisition module 501 is used to acquire network security service requirements. Configuration generation module 502 is used to generate security service configuration data based on the network security service requirements; The environment generation module 503 is used to generate a network security service runtime environment based on the security service configuration data.

[0111] In one optional implementation, generating security service configuration data based on the network security service requirements includes: Based on the aforementioned network security service requirements, generate network security service language information with a preset format; Based on the network security service language information, security service configuration data is generated.

[0112] In one optional implementation, generating a network security service runtime environment based on the security service configuration data includes: Based on the security service configuration data, obtain service target requirements and at least one scenario information, wherein the at least one scenario information includes at least one of the following: software scenario information, hardware scenario information, network capability scenario information, and delivery capability scenario information. Based on the at least one scenario information, a service cost function and an efficiency function are determined respectively, wherein the efficiency function is used to indicate the joint efficiency corresponding to the at least one scenario information; Based on the service target requirements, the service cost function, and the performance function, a network security service operating environment is generated, wherein the network security service operating environment includes at least one of the following: target software information, target hardware information, target network capability information, and target delivery capability information, wherein the delivery capability is used to characterize the service delivery standard.

[0113] In one optional implementation, generating a network security service runtime environment based on the service target requirements, the service cost function, and the performance function includes: The constraints are determined based at least on the performance function and the service target requirements; Construct an objective function that minimizes the service cost function; Based on the constraints and the objective function, a network security service operating environment is generated through optimization.

[0114] Fourthly, correspondingly, this application also provides an execution apparatus for network security services, which can implement all processes of the network security service execution method provided in the above embodiments.

[0115] See Figure 6 This diagram illustrates the structure of an execution device for a network security service provided in an embodiment of this application. This execution device is suitable for a service execution system and includes: The environment acquisition module 601 is used to acquire the network security service operating environment, wherein the network security service operating environment is generated according to the method described in any one of the first aspects above; The network security service execution module 602 is used to execute network security services through the network security service runtime environment.

[0116] In one optional implementation, the network security service includes at least one of the following: vulnerability scanning service, penetration testing service, baseline inspection service, and honeypot service.

[0117] Fifthly, embodiments of this application provide a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the method described in any of the preceding claims.

[0118] Sixthly, embodiments of this application provide a computer program product, including computer instructions that, when executed by a processor, implement the steps of the method described in any of the preceding claims.

[0119] In a seventh aspect, embodiments of this application provide a computer device including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the steps of the method described in any of the preceding claims.

[0120] See Figure 7 The computer device in this embodiment includes a processor 701, a memory 702, and a computer program stored in the memory 702 and executable on the processor 701, such as a program for generating a network security service runtime environment and / or executing a network security service. When the processor 701 executes the computer program, it implements the steps in the above-described embodiments of methods for generating and / or executing network security services.

[0121] For example, the computer program may be divided into one or more modules / units, which are stored in the memory 702 and executed by the processor 701 to complete this application. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the computer device.

[0122] The computer device may be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device may include, but is not limited to, a processor 701 and a memory 702. Those skilled in the art will understand that the schematic diagram is merely an example of a computer device and does not constitute a limitation on the computer device. It may include more or fewer components than illustrated, or combine certain components, or different components. For example, the computer device may also include input / output devices, network access devices, buses, etc.

[0123] The processor 701 can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, or processor 701 can be any conventional processor. The processor 701 is the control center of the computer device, connecting various parts of the entire computer device through various interfaces and lines.

[0124] The memory 702 can be used to store the computer programs and / or modules. The processor 701 implements various functions of the computer device by running or executing the computer programs and / or modules stored in the memory 702 and calling the data stored in the memory 702. The memory 702 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 702 may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0125] Wherein, if the modules / units integrated into the computer device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a non-transitory computer-readable storage medium. When the computer program is executed by the processor 701, it can implement the steps of the various method embodiments described above. Wherein, the computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc.

[0126] In summary, the embodiments of this application have at least the following beneficial effects: By adopting the embodiments of this application, network security service requirements are obtained; security service configuration data is generated based on the network security service requirements; and a network security service runtime environment is generated based on the security service configuration data. In this way, after obtaining network security service requirements, security service configuration data can be automatically generated, and then a stable and reliable security service runtime environment can be generated efficiently.

[0127] Through the above description of the embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary hardware platforms, or it can be implemented entirely by hardware. Based on this understanding, all or part of the technical solutions of this application that contribute to the background technology can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM (Read-Only Memory) / RAM (Random Access Memory), magnetic disk, optical disk, etc., including several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of this application.

[0128] The above description is the preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications are also considered to be within the scope of protection of this application. < / location> < / task-plan> < / service-description> < / location> < / asset-information> < / name-part> < / cybersecurity-tasks>

Claims

1. A method for generating a network security service runtime environment, characterized in that, include: Obtaining network security service requests; Based on the aforementioned network security service requirements, security service configuration data is generated; Based on the security service configuration data, a network security service runtime environment is generated.

2. The method according to claim 1, characterized in that, The generation of security service configuration data based on the aforementioned network security service requirements includes: Based on the aforementioned network security service requirements, generate network security service language information with a preset format; Based on the network security service language information, security service configuration data is generated.

3. The method according to claim 1, characterized in that, The step of generating a network security service runtime environment based on the security service configuration data includes: Based on the security service configuration data, obtain service target requirements and at least one scenario information, wherein the at least one scenario information includes at least one of the following: software scenario information, hardware scenario information, network capability scenario information, and delivery capability scenario information. Based on the at least one scenario information, a service cost function and an efficiency function are determined respectively, wherein the efficiency function is used to indicate the joint efficiency corresponding to the at least one scenario information; Based on the service target requirements, the service cost function, and the performance function, a network security service operating environment is generated, wherein the network security service operating environment includes at least one of the following: target software information, target hardware information, target network capability information, and target delivery capability information, wherein the delivery capability is used to characterize the service delivery standard.

4. The method according to claim 3, characterized in that, The process of generating a network security service runtime environment based on the service target requirements, the service cost function, and the performance function includes: The constraints are determined based at least on the performance function and the service target requirements; Construct an objective function that minimizes the service cost function; Based on the constraints and the objective function, a network security service operating environment is generated through optimization.

5. A method for executing a network security service, characterized in that, Applicable to service execution systems, the method includes: Obtain a network security service runtime environment, wherein the network security service runtime environment is generated according to any one of claims 1-4; The network security service is executed through the network security service runtime environment.

6. The method according to claim 5, characterized in that, The network security services include at least one of the following: vulnerability scanning service, penetration testing service, baseline inspection service, and honeypot service.

7. A device for generating a network security service operating environment, characterized in that, include: The requirement elicitation module is used to obtain network security service requirements. The configuration generation module is used to generate security service configuration data based on the network security service requirements. The environment generation module is used to generate a network security service runtime environment based on the security service configuration data.

8. An execution device for a network security service, characterized in that, Suitable for service execution systems, the apparatus includes: An environment acquisition module is used to acquire the network security service operating environment, wherein the network security service operating environment is generated by the method according to any one of claims 1-4; The network security service execution module is used to execute network security services through the network security service runtime environment.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1-6.

10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the method described in any one of claims 1-6.

11. A computer device, characterized in that, The method includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements the method of any one of claims 1-6.