Cloud asset management system
By using the tagging and connection management modules of the cloud asset management system, the security policies of cloud assets are automatically adjusted, solving the problem of low efficiency in adjusting security policies due to dynamic changes in cloud assets, and achieving efficient and secure cloud asset management.
Patent Information
- Application Number
- CN202511463597.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2026-02-24
AI Technical Summary
In existing technologies, dynamic changes in cloud assets cannot be automatically detected by security components, resulting in inefficient adjustments to security policies. Furthermore, different security components require manual maintenance, posing security risks.
Design a cloud asset management system that collects and manages tenants' cloud asset information through a cloud security management platform, dynamically adjusts security policies using a tagging management module and a connection management module, automatically establishes and adjusts the connection relationships between cloud assets, and updates security policies in real time through a security policy management module.
It improves the efficiency of security operations and maintenance, enhances the security of cloud assets, reduces the manpower cost of operations and maintenance, and ensures that security policies can respond to changes in cloud assets in a timely manner.
Smart Images

Figure CN121567347A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud security management technology, and in particular to a cloud asset management system. Background Technology
[0002] As enterprises migrate to the cloud, cloud security becomes increasingly important. A tenant may deploy multiple security components to provide different levels of protection for cloud assets. These security components include not only the security groups and network ACLs (Access Control Lists) provided by the cloud platform, but also cloud firewalls, cloud bastion hosts, and cloud WAFs purchased by the tenant. Currently, each security component under each tenant is independently operated and managed. Operations personnel need to log in to the cloud platform to configure security groups and network ACLs, and also need to log in to each security component provided by other non-cloud management systems via elastic IPs for configuration and management. The fundamental characteristics of cloud assets are dynamic migration and elastic scaling. Tenants can dynamically scale up or migrate cloud assets according to business needs. However, security components cannot detect these dynamic changes in cloud assets. Currently, when cloud assets change, operations personnel manually adjust the security policies of each security component. Different security components may require different operations personnel to handle the situation. This approach is inefficient, and security policies cannot adapt to changes in cloud assets, potentially leading to security vulnerabilities. Summary of the Invention
[0003] To address the aforementioned problems with current manual handling methods, this invention provides a cloud asset management system that dynamically adjusts cloud security policies, improving the efficiency of security operations and maintenance while simultaneously enhancing the security of cloud assets.
[0004] To achieve the above objectives, the present invention adopts the following technical solution:
[0005] In one embodiment of the present invention, a cloud asset management system is proposed, the system comprising:
[0006] The cloud security management platform is used to collect information on cloud assets under tenants, and to uniformly manage security components and security policies. It provides a unified login console for the security components of each tenant, allows for unified configuration of the security components of each tenant, and collects security logs and operation logs of security components in real time, analyzes the security logs and operation logs and triggers alarms.
[0007] The cloud platform is used to schedule and manage cloud resources throughout their entire lifecycle; it creates VPC networks, subnets, and cloud hosts according to tenants' business needs, enabling access between cloud hosts, connections between VPC networks, and interoperability between cloud and on-premises services; and it provides a unified external API gateway for the management of cloud resources.
[0008] Tenants are used to order the cloud assets they need from the cloud platform; independently manage all their own cloud assets; and order different security components in addition to the security components provided by the cloud platform according to their own business needs.
[0009] Furthermore, the cloud security management platform includes:
[0010] The asset management module is used to manage cloud assets on a tenant-by-tenant basis, monitor the operational status and change information of each tenant's cloud assets, and present them in real time.
[0011] The tag management module is used to manage tags defined by the cloud security management platform and user-defined tags;
[0012] The connection management module is used to manage the connection relationships between cloud assets and determine the complete connection relationship of cloud assets in the topology based on the topology relationship of cloud assets and the location of security components in the topology; it establishes connection relationships between cloud assets through tags; it automatically establishes connection relationships between cloud assets that meet the association rules between cloud assets and tags and other cloud assets; when a cloud asset is moved or destroyed, it automatically adjusts or deletes the connection relationship between the cloud asset and other cloud assets.
[0013] The security policy management module is used to manage the security policies of tenants in a unified manner. When cloud assets change, the module automatically adjusts the security policies according to the security components associated with the cloud assets and the connection relationships between the cloud assets, and updates the adjusted security policies to the security components; it also translates the security policies into the format required by the security components.
[0014] The security component management module is used to manage the functions of each security component through the security component business layer and to interface with security components from different manufacturers that have the same functions through the security component interface layer.
[0015] The cloud resource service module is used to connect to cloud platforms from different vendors through a cloud gateway, while providing unified business management of cloud resources for upper-layer security services.
[0016] Furthermore, the cloud platform synchronizes cloud asset information to the cloud security management platform.
[0017] Furthermore, users can manually associate cloud assets with tags, or users can set association rules between cloud assets and tags, and the cloud security management platform can automatically associate cloud assets with tags according to the association rules.
[0018] Furthermore, tags are used to identify a certain characteristic of a cloud asset; each cloud asset can be associated with multiple types of tags; each type of tag consists of multiple tag values.
[0019] Furthermore, users establish connections between cloud assets through tags; users associate connections between tags and security components and cloud assets.
[0020] Furthermore, security policies for cloud assets are established on security components through tagging; the same security policy is executed differently in different security components via CLI or external interfaces.
[0021] Beneficial effects:
[0022] 1. This invention dynamically associates cloud assets with security policies through tagging, thereby improving the security of cloud assets.
[0023] 2. This invention marks cloud assets and associates the connection between security components and cloud assets based on the marking information, thereby reducing the manpower cost of operation and maintenance. Attached Figure Description
[0024] Figure 1 This is a schematic diagram of the cloud asset management system structure of this invention;
[0025] Figure 2 This is a structural diagram of the cloud security management platform of the present invention;
[0026] Figure 3 This is a network topology diagram of a cloud security management platform, a cloud platform, and tenant A, according to an embodiment of the present invention. Detailed Implementation
[0027] The principles and spirit of the present invention will now be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided merely to enable those skilled in the art to better understand and implement the present invention, and are not intended to limit the scope of the present invention in any way. Rather, these embodiments are provided to make this disclosure more thorough and complete, and to fully convey the scope of this disclosure to those skilled in the art.
[0028] Those skilled in the art will recognize that embodiments of the present invention can be implemented as a system, device, method, or computer program product. Therefore, this disclosure can be specifically implemented in the following forms: entirely hardware, entirely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0029] According to an embodiment of the present invention, a cloud asset management system is proposed to fulfill the following three requirements:
[0030] 1. Unified management of security components;
[0031] 2. Real-time nature of cloud asset security protection;
[0032] 3. Simplify strategy management.
[0033] The principles and spirit of the present invention will be explained in detail below with reference to several representative embodiments.
[0034] Figure 1 This is a schematic diagram of the cloud asset management system structure according to an embodiment of the present invention. Figure 1 As shown, the system includes:
[0035] The cloud security management platform 101 is used to collect information on cloud assets under tenant 103, and to uniformly manage security components and security policies. It provides a unified login console for the security components of each tenant 103, performs unified configuration of the security components of each tenant 103, and collects security logs and operation logs of security components in real time, analyzes the security logs and operation logs and triggers alarms.
[0036] In practice, probes can be deployed on cloud hosts to synchronize cloud asset information to the cloud platform 102 in real time.
[0037] Alternatively, the cloud platform 102 can directly synchronize the information of the cloud asset to the cloud security management platform 101.
[0038] Cloud Platform 102 is used to schedule and manage cloud resources throughout their entire lifecycle; it creates VPC networks, subnets, and cloud hosts according to tenants' business needs, enabling access between cloud hosts, connections between VPC (virtual private cloud) networks, and interoperability between cloud and on-premises services; and it provides a unified external API gateway for cloud resource management.
[0039] Cloud platform 102 can be OpenStack, VMware, Huawei Cloud, or other third-party cloud platforms.
[0040] Tenant 103 is used to order the cloud assets required by the cloud platform; independently manages all cloud assets under its own management, including cloud hosts, virtual network cards, elastic IPs, applications on cloud hosts, operating systems, security components and network components, etc.; according to its own business needs, it orders different security components other than security groups and network ACLs provided by the cloud platform.
[0041] The cloud security management platform 101, as a core component for dynamic adjustment of security policies, mainly consists of the following components: Figure 2 As shown:
[0042] The asset management module 104 is used to manage cloud assets on a tenant-by-tenant basis, monitor the operational status and change information of each tenant's cloud assets, and present real-time information on cloud assets to tenants.
[0043] The tag management module 105 is used to manage tags defined by the cloud security management platform 101 and user-defined tags.
[0044] The cloud security management platform 101 defines different types of tags based on the common characteristics of cloud assets. The types of tags include region type, application type, asset priority, application group, and traffic type. Each type of tag consists of multiple tag values, and different types of tags are assigned to cloud assets. Each cloud asset can be associated with multiple types of tags.
[0045] Users define different types of tags based on business characteristics and assign different types of tags to cloud assets. Each cloud asset can be associated with multiple types of tags, and each type of tag consists of multiple tag values. For example, application types can be divided into web applications, database applications, and system applications; traffic types can be divided into Layer 4 traffic and Layer 7 traffic; application groups can be divided into different application groups based on the actual management of assets. Users associate the custom tags with the connection relationships between security components and cloud assets. For example, a business host or application with a Layer 7 traffic type can be associated with a cloud WAF service, and a business host or application with a WEB application type can be associated with a tamper-proof security component.
[0046] The connection management module 106 is used to manage the connection relationships between cloud assets and determine the complete connection relationships of cloud assets in the topology based on the topology relationships of cloud assets and the location of security components in the topology; it establishes connection relationships between cloud assets through tags; it automatically establishes connection relationships between cloud assets that conform to the association rules between cloud assets and tags and other cloud assets, i.e., the whitelist control policy for east-west and north-south access between cloud resources, which can simplify connection management; when a cloud asset is moved or destroyed, it automatically adjusts or deletes the connection relationships between the cloud asset and other cloud assets.
[0047] Users can manually associate cloud assets with tags, or users can set association rules between cloud assets and tags, and the connection management module 106 can automatically associate cloud assets with tags according to the association rules.
[0048] Users establish connections between cloud assets through tags; users associate tags with connections between security components and cloud assets.
[0049] Based on the topological relationships of cloud assets and the location of security components within the topology, the complete connectivity of cloud assets within the topology is determined; security policies for cloud assets on security components are established through tagging.
[0050] The security policy management module 107 is used to uniformly manage the security policies under the tenant. When cloud assets change, the security policy is automatically adjusted according to the security components associated with the cloud assets and the connection relationship between the cloud assets, and the adjusted security policy is updated to the security components. The security policy is translated according to the format required by the security components. The same security policy is executed by different CLI or external interfaces in different security components.
[0051] The security component management module 108 is used to manage the functions of each security component through the security component business layer and to interface with security components / devices from different manufacturers that have the same functions through the security component interface layer.
[0052] Cloud Resource Service Module 109 is a common management component used to connect to cloud platforms from different vendors through a cloud gateway. It also shields upper-layer security services from the differences between cloud platforms and provides unified business management of cloud resources.
[0053] It should be noted that although several modules of the cloud asset management system have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more modules described above can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.
[0054] To provide a clearer explanation of the management of the aforementioned cloud assets, a specific embodiment will be used for illustration below. However, it is worth noting that this embodiment is only for better illustrating the present invention and does not constitute an improper limitation of the present invention.
[0055] Example:
[0056] Tenant A, based on its business needs, wants to perform real-time monitoring of cloud assets and securely isolate basic business operations. It has subscribed to two security components: a situational awareness module and a cloud firewall. The vRouter (virtual router) acts as a gateway and also performs mirroring, mirroring traffic to the situational awareness security component for real-time traffic analysis. The situational awareness security component also periodically scans critical business hosts for vulnerabilities and viruses using a scanner. Tenant A's three subnets, 192.168.10.0 / 24, 192.168.20.0 / 24, and 192.168.30.0 / 24, correspond to three application groups under a specific application system. The cloud firewall isolates these three application groups. The network topology is as follows: Figure 3 As shown, vs represents a virtual switch that implements Layer 2 forwarding.
[0057] The implementation steps are as follows:
[0058] S1, the cloud security management platform manages the cloud assets of tenant networks.
[0059] In practice, probes can be deployed on cloud hosts to synchronize cloud asset information to the cloud platform in real time.
[0060] Alternatively, the cloud platform can directly synchronize the information of the cloud asset to the cloud security management platform.
[0061] S2, the cloud security management platform assigns tags to the managed cloud assets and associates the tags with security components and the connection relationships between cloud assets.
[0062] In this embodiment, tenant A establishes different application groups for cloud hosts based on the security isolation requirements of east-west access based on business, and creates three application type-based group labels: Web, App, and Db. At the same time, it is necessary to implement monitoring for key business hosts. Based on this requirement, a priority-based label pri-1 is created for cloud hosts. Cloud hosts with this label need to be scanned for vulnerabilities regularly.
[0063] The types of tags include region type, application type, asset priority, application group, and traffic type, and each type of tag consists of multiple tag values.
[0064] The connections between cloud assets consist of tags, directions (one-way or two-way), actions (pass, reject, and discard, etc.) and ports.
[0065] Cloud assets include cloud servers, virtual network interface cards (NICs), elastic IPs, applications running on cloud servers, as well as operating systems, security components, and network components.
[0066] Security components include security groups, network ACLs, cloud firewalls, cloud bastion hosts, cloud WAFs, anti-tampering measures, load balancers, and scanners.
[0067] Users can manually associate cloud assets with tags.
[0068] Users can set association rules between cloud assets and tags, and the cloud security management platform will automatically associate cloud assets with tags according to these rules.
[0069] The cloud security management platform can define different types of tags based on the common characteristics of cloud assets. For example, it can group applications by subnet and define different types of tags; it can group applications by type and define different types of tags; it can partition cloud resources by region and define different types of tags, and assign different types of tags to cloud assets. Each cloud asset can be associated with multiple types of tags.
[0070] The cloud security management platform associates cloud assets with security components and the connection relationships between cloud assets based on the type of tag and the corresponding tag value.
[0071] Users can customize different types of tags based on business characteristics. For example, a tag can be a number or a color, or a feature descriptor. Different types of tags can be assigned to cloud assets, and each cloud asset can be associated with multiple types of tags.
[0072] Users associate tags with the connections between security components and cloud assets.
[0073] In this embodiment, tenant A is defined by application type, and the association rules between the cloud assets defined by tenant A and the tags are shown in Table 1 below:
[0074] Table 1
[0075] mark Tag type Related components Association rules Rules content Web Application type Cloud Wall Subnet 192.168.10.0 / 24:8080 Db Application type Cloud Wall Subnet 192.168.20.0 / 24:3306 App Application type Cloud Wall Subnet 192.168.30.0 / 24:8090 Pri-H Priority Situational awareness Priority Web application host
[0076] Based on the above association rules, the relationship between the generated tags and cloud assets is shown in Table 2 below. In this embodiment, the application information also includes other information, such as version number and other feature information. These feature information do not affect the description of this embodiment and will not be elaborated here.
[0077] Table 2
[0078] assets Asset types mark Associated cloud server Tomcat application Web,Pri-H 192.168.10.10-15 mysql application db 192.168.20.10-20 cmp application app 192.168.30.11-15
[0079] Based on the business connections and the tags associated with the aforementioned cloud assets, the connections between the cloud assets are shown in Table 3 below:
[0080] Table 3
[0081] Serial Number Source end destination end Serve action 1 Web App TCP: 8090 allow 2 App db TCP: 3306 allow
[0082] S3, the cloud security management platform automatically synchronizes changes to cloud assets to the security policy management module based on the connection relationship between the associated security components and cloud assets.
[0083] Users establish connections between cloud assets through tags; users associate tags with connections between security components and cloud assets.
[0084] The cloud security management platform determines the complete connectivity of cloud assets in the topology based on the topological relationships of cloud assets and the location of security components in the topology; and establishes security policies for cloud assets on security components through tagging.
[0085] In practice, when a complete connection relationship passes through a security component, a security policy for the security component is established based on the connection relationship between cloud assets. When it passes through multiple security components, multiple security policies are established. That is, the connection relationship between cloud assets established by tags may be decomposed into multiple security policies. The decomposed security policies are associated with security components, and the security policies are also identified by tags.
[0086] In this embodiment, when the cloud security management platform detects a change in a cloud asset, it associates the changed cloud asset with the corresponding tag according to the association rules between cloud assets and tags. Simultaneously, it updates the tag-to-cloud asset relationship in Table 2 and the connection relationship between cloud assets in Table 3. Based on the connection relationship between the security components associated with the tag and the cloud asset, it notifies the security policy management module of the change information. For example, in this embodiment, tenant A expands its web application host, adds a cloud host 192.168.10.16, and installs Tomcat. According to the cloud asset-to-tag association rules, the tags related to this cloud asset change are "web" and "pri-H". The cloud security management platform automatically associates this host with the tags "web" and "pri-H", updating the tag-to-cloud asset relationship as shown in Table 4 below.
[0087] Table 4
[0088] assets Asset types mark Associated cloud server Tomcat application Web,Pri-H 192.168.10.10-16 mysql application db 192.168.20.10-20 cmp application app 192.168.30.11-15
[0089] In this embodiment, cloud firewall and situational awareness are used as security components. In specific implementation, when the network topology is complex, a complete connection relationship is established in combination with the network topology, and the connection relationship is decomposed into different security policies.
[0090] S4. The security policy management module dynamically adjusts the security policy based on the changes to the cloud asset and updates the adjusted security policy to the security components, thereby realizing the dynamic adjustment of the security policy and improving the security of the cloud asset and the efficiency of operation and maintenance.
[0091] When the cloud security management platform detects a new cloud asset, if the cloud asset conforms to the association rules between cloud assets and tags, then the cloud asset that conforms to the association rules between cloud assets and tags will automatically establish a connection relationship with other cloud assets. When a cloud asset is moved or destroyed, the connection relationship between the cloud resource and other cloud assets will be automatically adjusted or deleted.
[0092] When the connection relationship changes, the security policy associated with the connection relationship is then changed synchronously.
[0093] In this embodiment, the security policy management module, based on the cloud asset change information announced by tenant A, marks the security components associated with web and pri-H as situational awareness and cloud firewall. The security policy management module then notifies the situational awareness component of the cloud asset change information related to pri-H, which adds the cloud asset to the automatically monitored business host. Based on the connection relationship between the cloud assets associated with web and the associated security component cloud firewall, the security policy management module notifies the cloud asset change information on the web side to the security component cloud firewall. The cloud firewall then automatically updates the address group related to the security policy based on the newly added cloud host 192.168.10.16, thereby realizing the dynamic adjustment of cloud assets and cloud security policies.
[0094] The cloud asset management system proposed in this invention dynamically associates cloud assets with security policies through tagging, thereby improving the security of cloud assets; by tagging cloud assets and associating the connection relationship between security components and cloud assets based on the tagging information, the manpower cost of operation and maintenance is reduced.
[0095] While the spirit and principles of the invention have been described with reference to several specific embodiments, it should be understood that the invention is not limited to the disclosed specific embodiments, and the division of aspects does not imply that features in these aspects cannot be combined for benefit; such division is merely for ease of description. The invention is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims.
[0096] Regarding the limitation of the scope of protection of this invention, those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative effort based on the technical solution of this invention are still within the scope of protection of this invention.
Claims
1. A cloud asset management system, characterized in that, The system includes: The cloud security management platform is used to collect information on cloud assets under tenants, and to uniformly manage security components and security policies. It provides a unified login console for the security components of each tenant, allows for unified configuration of the security components of each tenant, and collects security logs and operation logs of security components in real time, analyzes the security logs and operation logs and triggers alarms. The cloud platform is used to schedule and manage cloud resources throughout their entire lifecycle; it creates VPC networks, subnets, and cloud hosts according to tenants' business needs, enabling access between cloud hosts, connections between VPC networks, and interoperability between cloud and on-premises services; and it provides a unified external API gateway for the management of cloud resources. Tenants are used to order the cloud assets they need from the cloud platform; independently manage all their own cloud assets; and order different security components in addition to the security components provided by the cloud platform according to their own business needs.
2. The cloud asset management system according to claim 1, characterized in that, The cloud security management platform includes: The asset management module is used to manage cloud assets on a tenant-by-tenant basis, monitor the operational status and change information of each tenant's cloud assets, and present them in real time. The tag management module is used to manage tags defined by the cloud security management platform and user-defined tags; The connection management module is used to manage the connection relationships between cloud assets and determine the complete connection relationship of cloud assets in the topology based on the topology relationship of cloud assets and the location of security components in the topology; it establishes connection relationships between cloud assets through tags; it automatically establishes connection relationships between cloud assets that meet the association rules between cloud assets and tags and other cloud assets; when a cloud asset is moved or destroyed, it automatically adjusts or deletes the connection relationship between the cloud asset and other cloud assets. The security policy management module is used to manage the security policies of tenants in a unified manner. When cloud assets change, the module automatically adjusts the security policies according to the security components associated with the cloud assets and the connection relationships between the cloud assets, and updates the adjusted security policies to the security components; it also translates the security policies into the format required by the security components. The security component management module is used to manage the functions of each security component through the security component business layer and to interface with security components from different manufacturers that have the same functions through the security component interface layer. The cloud resource service module is used to connect to cloud platforms from different vendors through a cloud gateway, while providing unified business management of cloud resources for upper-layer security services.
3. The cloud asset management system according to claim 2, characterized in that, Users can manually associate cloud assets with tags, or users can set association rules for cloud assets with tags, and the cloud security management platform will automatically associate cloud assets with tags according to the association rules.
4. The cloud asset management system according to claim 2, characterized in that, The tag is used to identify a certain characteristic of a cloud asset; each cloud asset can be associated with multiple types of tags; each type of tag consists of multiple tag values.
5. The cloud asset management system according to claim 2, characterized in that, Users establish connections between cloud assets through tags; users associate connections between security components and cloud assets through tags.
6. The cloud asset management system according to claim 2, characterized in that, Security policies for cloud assets are established on security components through tagging; the same security policy is executed differently in different security components via CLI or external interfaces.