A security protection method and a security resource pool
By building a hyperconverged cluster based on three servers, adopting virtual machine migration and fault self-recovery strategies, and combining the collaborative work of the traffic splitter and orchestrator, the single point of failure problem of traditional side-mounted security resource pools is solved, and continuous security protection and high availability of business traffic are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NEW H3C SECURITY TECH CO LTD
- Filing Date
- 2026-01-29
- Publication Date
- 2026-05-26
AI Technical Summary
Traditional side-mounted security resource pools have single-point failure risks and lack redundancy design, which cannot meet the continuity requirements of production-level business.
A hyperconverged cluster based on three servers is built, employing virtual machine migration and fault self-recovery strategies, combined with the collaborative work of traffic splitters and orchestrators, to achieve distributed deployment of business traffic and end-to-end security detection.
It completely eliminates the risk of single points of failure, ensures continuous security protection for business traffic, improves the resource utilization and detection efficiency of security equipment, and realizes a highly available security resource pool.
Smart Images

Figure CN122093345A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular to a security protection method and a security resource pool. Background Technology
[0002] In building private cloud security capabilities, the side-mounted security resource pool is a low-intrusion deployment solution, and its core challenge is how to ensure the continuous security protection of business traffic.
[0003] Traditional solutions employ a single-node deployment architecture: a hyperconverged platform is deployed on a single physical server, creating a service virtual switch and binding it to a single physical network interface card (NIC) (the only connection between the server and the service switch). Virtual network elements such as traffic splitters, orchestrators, and security devices are deployed within this platform. Policy-based routing is configured on the service switch to direct traffic from protected assets to the traffic splitter, which then schedules it to the security service chain for inspection before finally relaying it back to the target server.
[0004] This solution has significant drawbacks. On the one hand, it has the risk of single point of failure. If a single physical server, a single service virtual switch, a single physical network card, or any virtual network element fails, it will directly lead to the interruption of service traffic protection. On the other hand, it lacks redundancy design. The underlying platform, network links, and virtual network elements of the entire architecture are deployed on a single node, which lacks the support of a high-availability architecture and cannot meet the continuity requirements of production-level services. Summary of the Invention
[0005] This application provides a security protection method and a security resource pool, which aims to build a side-by-side security resource pool with high availability to ensure continuous security protection of business traffic.
[0006] Specifically, this application provides the following technical solution: Firstly, this application provides a security protection method applied to the control center of a security resource pool attached to a service switch. The security resource pool includes a first server, a second server, a third server, and a management switch. The first server, the second server, and the third server are all deployed with a hyper-converged platform. The hyper-converged platform enables virtual machine migration policies and virtual machine fault self-recovery policies. The first server, the second server, and the third server are each connected to the management switch through a virtual management switch and are each connected to the service switch through a virtual service switch. The method includes: The traffic is obtained from the service switch by the traffic splitter deployed on the third server and forwarded to the orchestrator deployed on the second server. Using an orchestrator, business traffic is sequentially forwarded to corresponding security devices for security testing according to a preset security service chain. The security devices are deployed on the first server. The traffic splitter, the orchestrator, and the security devices are all virtual machines. Using an orchestrator, the service traffic that passes security checks is sent back to the service switch via a splitter.
[0007] Secondly, this application provides a security resource pool, which is deployed on a service switch in a side-mounted manner. The security resource pool includes: a first server, a second server, a third server, and a management switch. The first server, the second server, and the third server are all equipped with a hyperconverged platform. The hyperconverged platform enables virtual machine migration and virtual machine fault self-recovery strategies. The first server, the second server, and the third server are each connected to the management switch through a virtual management switch and to the service switch through a virtual service switch. The first server contains various security devices, the second server contains an orchestrator, and the third server contains a traffic splitter; all the security devices, the orchestrator, and the traffic splitter are virtual machines. The splitter is used to obtain service traffic from the service switch and forward it to the orchestrator. The orchestrator is used to forward the service traffic to the corresponding security devices in sequence according to the preset security service chain for security detection, and to send the service traffic that passes the security detection back to the service switch via the splitter.
[0008] Thirdly, this application provides an electronic device, comprising: A memory, one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, and when the computer instructions are executed by the processor, the electronic device performs the method described above.
[0009] Fourthly, this application provides a computer-readable storage medium including computer instructions that, when executed on an electronic device, cause the electronic device to perform the method described above.
[0010] Fifthly, this application provides a computer program product that, when run on a computer, causes the computer to perform the method described above.
[0011] The technical solution provided in this application has the following beneficial effects: This application constructs a hyperconverged cluster based on three servers, uniformly enabling virtual machine migration and fault self-recovery policies to eliminate single-point-of-failure risks from the ground up. Virtual service switches and virtual management switches are independently created on each server, and connected to the service and management switches respectively, achieving distributed deployment of traffic forwarding and complete isolation between management and service traffic. Through the collaborative work of the traffic splitter and orchestrator, precise scheduling and end-to-end security detection of service traffic are achieved. Finally, by constructing a highly available, side-mounted security resource pool, continuous security protection for service traffic is achieved.
[0012] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and do not limit this application. Attached Figure Description
[0013] The accompanying drawings, which are incorporated in and form part of this application, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0014] Figure 1 A flowchart illustrating the security protection method provided in this application embodiment; Figure 2 A schematic diagram of the architecture of the security resource pool provided in this application embodiment; Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0015] The technical solutions of the embodiments of this application are described below with reference to the accompanying drawings. The terminology used in the embodiments of this application is only used to describe specific embodiments of this application and is not intended to limit this application.
[0016] This application provides a security protection method and a security resource pool, which aims to build a side-mounted security resource pool with high availability. Through the full-dimensional redundancy design of the underlying architecture, network links, and virtual network elements, combined with an automated fault recovery mechanism, it completely eliminates single points of failure and ensures continuous security protection for business traffic.
[0017] The practical application of this application will be described in detail below through specific embodiments.
[0018] This application provides a security protection method applied to the control center of a security resource pool connected to a service switch.
[0019] In this context, "side-mounted" refers to a deployment method where business traffic is not directly connected in the business traffic path, but is instead introduced into the business network through policy routing for security detection, and then transmitted back to the business network after the detection is completed.
[0020] The control center (security orchestration and management center) is the core decision-making and control unit of the security resource pool. It is responsible for the unified scheduling of traffic splitters, orchestrators and various security devices, and the execution of full-process strategies such as traffic ingress, security detection and traffic backhaul.
[0021] In this application, the security resource pool includes a first server, a second server, a third server, and a management switch. The first server, the second server, and the third server are all deployed with a hyper-converged platform. The hyper-converged platform enables virtual machine migration policy and virtual machine fault self-recovery policy. The first server, the second server, and the third server are each connected to the management switch through a virtual management switch, and each is connected to the service switch through a virtual service switch.
[0022] The aforementioned hyperconverged platform is an infrastructure platform that integrates computing, storage, and network virtualization. It enables the pooling and unified management of hardware resources and supports the creation, operation, and clustered deployment of virtual machines.
[0023] Virtual machine migration strategy refers to the mechanism by which virtual machines running on a server within a cluster automatically migrate to other healthy servers and resume operation when a server fails. This application aims to ensure service continuity. Virtual machine fault self-recovery strategy refers to the ability of a hyperconverged platform to monitor the running status of virtual machines and automatically restart the virtual machine to restore service when a virtual machine fault is detected.
[0024] Understandably, because the hyperconverged platform employs the virtual machine migration and virtual machine failure self-recovery strategies described above, the locations of the traffic splitter, orchestrator, and various security devices are random in practical applications. In extreme cases, such as when any two servers fail, the traffic splitter, orchestrator, and various security devices will migrate to the only healthy server; that is, all three can appear on the same server.
[0025] Both the virtual management switch (management vswitch) and the virtual service switch (service vswitch) are virtual Layer 2 forwarding devices created within the hyper-converged platform. The virtual management switch is used to carry management traffic such as cluster management and virtual machine maintenance. It is bound to the server's management network card and connected to the management switch. The virtual service switch is used to carry service traffic and security protection traffic. It is bound to the server's service network card and connected to the service switch.
[0026] In this application, each server, service switch, and management switch is a physical device.
[0027] like Figure 1 As shown, the security protection method provided in this application includes the following steps: Step 110: Obtain service traffic from the service switch through the traffic splitter deployed on the third server and forward it to the orchestrator deployed on the second server; Step 120: Using an orchestrator, business traffic is sequentially forwarded to the corresponding security devices for security testing according to a preset security service chain. The security devices are deployed on the first server. The traffic splitter, the orchestrator, and the security devices are all virtual machines. The aforementioned security service chain refers to a traffic detection path formed by connecting multiple virtualized security devices in series. In this application, service traffic will sequentially pass through each security device on the link for security detection.
[0028] Step 130: Using the orchestrator, the service traffic that has passed the security test is sent back to the service switch via the splitter.
[0029] The security protection method of this application uses the control center as the core decision-making body, builds a hyper-converged cluster based on 3 servers, and uniformly enables virtual machine drift and fault self-recovery strategies, thereby eliminating the risk of single point of failure from the bottom layer.
[0030] That is, the above method may also include the following steps: when any server fails, perform a virtual machine migration operation through the management switch to migrate the virtual machine on the server to a normally operating server, and / or, when any virtual machine fails, perform a virtual machine failure self-recovery operation through the management switch to restart the failed virtual machine.
[0031] Specifically, when the third server carrying the traffic splitter fails, the control center automatically triggers a migration policy, migrating the traffic splitter virtual machine to the first or second server and quickly restoring the traffic import function. When the second server carrying the orchestrator fails, the control center automatically migrates the orchestrator to the first or third server, ensuring uninterrupted security service chain scheduling capabilities. When the first server carrying the security device fails, the control center automatically migrates the security device virtual machine to the second or third server, ensuring continuous online security protection capabilities. In this way, the entire security resource pool possesses production-grade high availability capabilities, meeting the continuity requirements of critical business operations.
[0032] This application independently creates virtual service switches and virtual management switches on each server, and connects them to the service switches and management switches respectively, thereby realizing distributed deployment of traffic forwarding and complete isolation between management traffic and service traffic.
[0033] Specifically, virtual service switches are interconnected through service switches, constructing a distributed traffic forwarding plane. This breaks through the bottleneck of traditional single-node virtual switches and improves traffic forwarding redundancy and reliability. Virtual management switches are interconnected through management switches, constructing an independent, highly available management plane. This ensures that cluster management and virtual machine maintenance traffic are not affected by service traffic, improving the security and stability of operations and maintenance.
[0034] This application achieves precise scheduling of service traffic and end-to-end security detection through the collaborative work of the traffic splitter and orchestrator.
[0035] Specifically, configuring the traffic splitter's policy routing ensures that only specific service traffic requiring protection (such as traffic originating from / destined for protected resources) is directed to the security resource pool, preventing irrelevant traffic from consuming security resources and improving protection efficiency. Furthermore, pre-defined security service chain rules guide traffic through each security device for sequential inspection via the orchestrator, ensuring comprehensive security protection. Simultaneously, configuring the orchestrator to support the return of response messages along the original security service chain path ensures that reverse traffic also undergoes complete security inspection, eliminating protection blind spots.
[0036] That is, the orchestrator's processing logic can be as follows: if the service traffic is a forward request message, then according to the forward path of the preset security service chain, the service traffic is forwarded to the corresponding security device for security detection in sequence; if the service traffic is a reverse response message, then according to the reverse path of the preset security service chain, the service traffic is forwarded to the corresponding security device for security detection in sequence.
[0037] Based on the virtualization features of the hyperconverged platform, this application allows for flexible expansion of the security resource pool capacity by adding physical servers or virtual machines, enabling rapid adaptation to business growth and changes in security requirements.
[0038] Optionally, a main interface and a sub-interface are configured for the traffic splitter. The traffic splitter implements steps 110 and 130 above through the main interface and the sub-interface, respectively. That is, the traffic splitter obtains service traffic from the service switch through the main interface of the traffic splitter deployed on the third server; and forwards the service traffic to the orchestrator deployed on the second server through the sub-interface of the traffic splitter.
[0039] Optionally, a first sub-interface and a second sub-interface are configured for the orchestrator. The orchestrator implements steps 120 and 130 above through the first and second sub-interfaces, respectively. That is, the orchestrator uses the first sub-interface to receive service traffic sent by the splitter; and uses the second sub-interface to forward the service traffic sequentially to the corresponding security devices for security detection according to a preset security service chain, wherein the second sub-interface corresponds one-to-one with each security device. In other words, a second sub-interface is configured for each type of security device in the orchestrator.
[0040] Optionally, to further improve availability, there may be two or more communication links between the virtual service switch and the service switch of any server, and / or, there may be two or more communication links between the virtual management switch and the management switch of any server.
[0041] For example, the security devices mentioned above include firewalls and web application firewalls.
[0042] The security protection method proposed in this application, through unified management and control by the control center, combined with a clustered high-availability architecture, distributed traffic forwarding, precise traffic scheduling, and full-link detection, achieves the following technical effects: First, the full-dimensional redundancy design from the underlying platform to virtual network elements completely solves the single point of failure problem existing in traditional solutions, ensuring continuous security protection for business traffic; Second, through precise traffic scheduling and distributed forwarding, the processing of invalid traffic is reduced, improving the resource utilization and detection efficiency of security devices; Third, management traffic is isolated from business traffic, avoiding the impact of management operations on business, and improving the security and maintainability of the entire system; Fourth, based on virtualization and clustering architecture design, the security resource pool can be flexibly expanded to adapt to constantly changing business and security requirements.
[0043] Below is a comparison Figure 2 This paper introduces the solution of this application from three aspects: underlying architecture design, security resource pool design, and traffic protection process.
[0044] 1. Underlying Architecture Design This application uses three physical servers (server 1 / 2 / 3), and deploys a hyperconverged platform on each physical server to build a virtualization cluster. The hyperconverged platform supports virtual machine migration policies and virtual machine failure self-recovery policies. This application enables virtual machine migration policies and virtual machine failure self-recovery policies on each server.
[0045] Create a management vswitch on each server and bind it to the server's network interface cards eth3 and eth4 to handle cluster management and virtual machine maintenance traffic. Each server's management vswitch is assigned an independent management address and interconnected through a management switch to form a virtualization cluster.
[0046] Create a service vswitch on each server and bind it to the server's network interface cards eth0 and eth1 to carry service traffic and security protection traffic. In this application, the service vswitch is configured to allow traffic from VLAN 10 and VLAN 20 to pass through.
[0047] In the management plane, Ge1 / 1 and Ge1 / 2 on the management switch form aggregation port 1, Ge1 / 3 and Ge1 / 4 form aggregation port 2, and Ge1 / 5 and Ge1 / 6 form aggregation port 3. These three aggregation ports are interconnected with the network interface cards (NICs) eth3 and eth4 of the three servers, achieving redundancy in the management links.
[0048] On the service plane, Ge1 / 1 and Ge1 / 2 on the service switch form aggregation port 1, Ge1 / 3 and Ge1 / 4 form aggregation port 2, and Ge1 / 5 and Ge1 / 6 form aggregation port 3. Aggregation ports 1, 2, and 3 on the service switch allow traffic from VLAN 10 and VLAN 20 to pass through. These three aggregation ports are interconnected with the network interface cards (eth0 and eth1) of three servers, achieving service link redundancy. VLAN interface 10 is created on the service switch, and the address 1.1.1.1 is assigned.
[0049] 2. Security Resource Pool Design In this application, the three service vswitches on the three servers are interconnected through service switches to build a distributed traffic forwarding plane, eliminating the single point of failure risk of the original single-node vswitch. At the same time, the management vswitches on the three servers are interconnected through a management switch to build a highly available management plane, ensuring the continuity of cluster management and virtual machine operation and maintenance traffic.
[0050] Virtual network elements are deployed in a distributed manner on different cluster nodes according to their functions, as follows: A virtual firewall (vFw) is deployed on server 1, configured with a virtual network interface card and associated with the service vswitch. Its address is 1.1.3.2 (VLAN 20), and its gateway is 1.1.3.1.
[0051] A virtualized web application firewall (vWaf) is deployed on server 1, configured with a virtual network interface card (NIC) and associated with a service vswitch. The address is 1.1.4.2 (VLAN 20), and the gateway is 1.1.4.1.
[0052] The orchestrator, deployed on server 2, is configured with three virtual network interfaces and associated with a service vswitch. The sub-interface addresses are: sub-interface 1 1.1.2.2 (VLAN 20), sub-interface 2 1.1.3.1 (VLAN 20), and sub-interface 3 1.1.4.1 (VLAN 20). These three sub-interfaces connect to the traffic splitter, vFw, and vWaf virtual network elements respectively, enabling precise scheduling of the security service chain. The orchestrator is configured with a static route 0.0.0.0 / 0, next hop 1.1.2.1, pointing to the traffic splitter, and a service chain is configured to guide traffic through vFw (1.1.3.2) and vWaf (1.1.4.2) sequentially.
[0053] The traffic splitter, deployed on server 3, is configured with two virtual network interface cards (NICs) and associated with a service vswitch. The main interface address is 1.1.1.2 (VLAN 10), and the sub-interface is 1.1.2.1 (VLAN 20). The main interface is responsible for interconnecting with the service switch and receiving raw traffic from it; the sub-interface is responsible for forwarding traffic to the orchestrator and also acts as the orchestrator's gateway. The traffic splitter is configured with a static route 0.0.0.0 / 0, next hop 1.1.1.1, and two policy routes to forward traffic with a source-to-destination address of 20.20.20.20 to the orchestrator (1.1.2.2).
[0054] The traffic forwarding strategy is configured as follows: The service switch is configured with two policy routes, setting the next hop for inbound traffic on both the uplink and downlink ports to 1.1.1.2 (the splitter address) to facilitate traffic import. The splitter is configured with two policy routes, forwarding traffic with a source-destination of 20.20.20.20 to 1.1.2.2 (the orchestrator address) to facilitate traffic scheduling.
[0055] 3. Traffic Protection Process In this application, both the forward request path and the reverse response path of the business traffic have undergone complete security service chain detection, with no blind spots in protection. The fixed addresses involved are: client 10.10.10.10 and the protected asset, i.e., server 20.20.20.20. The specific process is as follows: Forward request path (client 10.10.10.10 -> server 20.20.20.20): A1. Traffic introduction: The client initiates a request packet to the service switch, and the service switch forwards the packet to the traffic splitter through policy routing. A2. Traffic Scheduling: The traffic splitter forwards request packets to the orchestrator through policy routing; A3. Service Chain Inspection: The orchestrator forwards the request message to vFw and vWaf in sequence according to the preset security service chain for full-dimensional security inspection. A4. Traffic backhaul: Legitimate request packets that have passed security checks are backhauled along the path (i.e., vWaf -> orchestrator -> splitter) to the service switch, and finally delivered to the target server by the service switch.
[0056] Reverse response path (Server 20.20.20.20 -> Client 10.10.10.10): B1. Traffic introduction: The server generates a response message and sends it to the service switch. The service switch forwards the message to the traffic splitter through policy routing. B2. Flow scheduling: The flow splitter forwards the response message to the orchestrator; B3. Reverse Service Chain Inspection: The orchestrator forwards the response message to vWaf and vFw in sequence for security inspection according to the original return logic of the security service chain. B4. Outbound Traffic: Valid response messages that have passed security checks are transmitted back to the service switch along the path (i.e., vFw -> orchestrator -> splitter), and finally delivered to the client by the service switch.
[0057] The following explains the forward and reverse paths in more detail, including the following steps: (1) The client sends a request to the server, generating a request message with a source address of 10.10.10.10 and a destination address of 20.20.20.20. The request message is sent to the service switch.
[0058] (2) On the service switch, the request message matches policy route 1, the next hop for message forwarding is 1.1.1.2, and the request message is delivered to the splitter.
[0059] (3) On the splitter, the request message matches policy route 1, and the next hop for message forwarding is 1.1.2.2. The request message is delivered to the orchestrator.
[0060] (4) On the orchestrator, according to the service chain, the next hop for message forwarding is vFw address 1.1.3.2. The request message is delivered to vFw.
[0061] (5) After vFw processes the request message, the next hop for message forwarding is 1.1.3.1, based on vFw's gateway address. The request message is then delivered to the orchestrator.
[0062] (6) On the orchestrator, according to the service chain, the next hop for message forwarding is vWaf address 1.1.4.2. The request message is delivered to vWaf.
[0063] (7) After vWaf processes the request message, the next hop for message forwarding is 1.1.4.1, based on vWaf's gateway address. The request message is then delivered to the orchestrator.
[0064] (8) On the orchestrator, the request message has been matched with the service chain and the static route has been matched. The next hop for the message forwarding is 1.1.2.1. The request message is delivered to the splitter.
[0065] (9) On the splitter, the request message has no matching policy route, and therefore matches the static route. The message is forwarded to the next hop address 1.1.1.1. The request message is delivered to the service switch.
[0066] (10) On the service switch, the request message has no matching policy route, and then matches the regular route, and the message is sent to the server.
[0067] (11) After the server processes the request message, it generates a response message. The source address of the response message is 20.20.20.20 and the destination address is 10.10.10.10. Message forwarding is started and the response message is sent to the service switch.
[0068] (12) On the service switch, the response message matches policy route 2, and the next hop for message forwarding is 1.1.1.2. The response message is delivered to the splitter.
[0069] (13) On the splitter, the response message matches policy route 2, and the next hop for message forwarding is 1.1.2.2. The response message is delivered to the orchestrator.
[0070] (14) The orchestrator supports the return of response messages along the original service chain. The next hop for message forwarding is vWaf, and the next hop address is 1.1.4.2. The response message is delivered to vWaf.
[0071] (15) After vWaf processes the response message, it forwards the message to the next hop 1.1.4.1 based on the vWaf gateway address. The message is then delivered to the orchestrator.
[0072] (16) The orchestrator supports the return of response messages along the service chain source path. The next hop for message forwarding is vFw, and the next hop address is 1.1.3.2. The response message is delivered to vFw.
[0073] (17) After vFw processes the response message, the next-hop address for message forwarding is 1.1.3.1 according to the vFw gateway address. The response message is then delivered to the orchestrator.
[0074] (18) On the orchestrator, after the response message matches the service chain and the static route, the message is forwarded to the next hop of 1.1.2.1. The request message is delivered to the splitter.
[0075] (19) On the splitter, the response message has no matching policy route, and therefore matches the static route. The message is forwarded to the next hop address 1.1.1.1. The request message is delivered to the service switch.
[0076] (20) On the service switch, the response message has no matching policy route, and then matches the regular route, and the message is sent to the client.
[0077] Based on the same inventive concept, this application also provides a secure resource pool.
[0078] The security resource pool is deployed on the service switch in a side-mounted manner. The security resource pool includes: a first server, a second server, a third server, and a management switch. The first server, the second server, and the third server are all equipped with a hyperconverged platform. The hyperconverged platform enables virtual machine migration and virtual machine fault self-recovery strategies. The first server, the second server, and the third server are each connected to the management switch through a virtual management switch and to the service switch through a virtual service switch. The first server contains various security devices, the second server contains an orchestrator, and the third server contains a traffic splitter; all the security devices, the orchestrator, and the traffic splitter are virtual machines. The splitter is used to obtain service traffic from the service switch and forward it to the orchestrator. The orchestrator is used to forward the service traffic to the corresponding security devices in sequence according to the preset security service chain for security detection, and to send the service traffic that passes the security detection back to the service switch via the splitter.
[0079] This application provides an electronic device that may include a memory and one or more processors. The memory stores computer program code, which includes computer instructions. When the processor executes the computer instructions, the electronic device can perform various functions or steps of the method embodiments described above.
[0080] The structure of this electronic device can be referenced. Figure 3 The structure of the electronic device 100 shown.
[0081] For example, the processor mentioned above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0082] This application also provides a computer-readable storage medium including computer instructions that, when executed on an electronic device, cause the electronic device to perform the various functions or steps of the above method embodiments.
[0083] The aforementioned computer-readable storage media include, but are not limited to, any of the following: USB flash drive, portable hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, and other media capable of storing program code.
[0084] This application also provides a computer program product that, when run on a computer, causes the computer to perform various functions or steps of the above method embodiments.
[0085] The electronic devices, computer-readable storage media, and computer program products provided in this application embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0086] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various variations or substitutions can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.
Claims
1. A security protection method, characterized in that, The control center is applied to a security resource pool that is attached to a service switch. The security resource pool includes a first server, a second server, a third server, and a management switch. Each of the first, second, and third servers is equipped with a hyper-converged platform. The hyper-converged platform enables virtual machine migration policies and virtual machine fault self-recovery policies. Each of the first, second, and third servers is connected to the management switch through a virtual management switch and to the service switch through a virtual service switch. The method includes: The traffic is obtained from the service switch by the traffic splitter deployed on the third server and forwarded to the orchestrator deployed on the second server. Using an orchestrator, business traffic is sequentially forwarded to corresponding security devices for security testing according to a preset security service chain. The security devices are deployed on the first server. The traffic splitter, the orchestrator, and the security devices are all virtual machines. Using an orchestrator, the service traffic that passes security checks is sent back to the service switch via a splitter.
2. The method according to claim 1, characterized in that, If the business traffic is a forward request message, it will be forwarded to the corresponding security device for security detection in sequence according to the forward path of the preset security service chain. If the service traffic is a reverse response message, the service traffic will be forwarded to the corresponding security device for security detection in sequence according to the reverse path of the preset security service chain.
3. The method according to claim 1, characterized in that, The method further includes: In the event of a server failure, a virtual machine migration operation is performed via the management switch to migrate the virtual machines on that server to a normally functioning server.
4. The method according to claim 1, characterized in that, The method further includes: When any virtual machine fails, a virtual machine self-recovery operation is performed through the management switch to restart the failed virtual machine.
5. The method according to claim 1, characterized in that, Business traffic is obtained from the business switch through the main interface of the traffic splitter deployed on the third server; The traffic is forwarded to the orchestrator deployed on the second server via the sub-interface of the splitter.
6. The method according to claim 1, characterized in that, Receive the service traffic sent by the splitter using the first sub-interface of the orchestrator; Using the second sub-interface of the orchestrator, business traffic is forwarded sequentially to the corresponding security devices for security detection according to the preset security service chain, wherein the second sub-interface corresponds one-to-one with the security device.
7. The method according to claim 1, characterized in that, There are two or more communication links between the virtual service switch and the service switch of any server, and / or there are two or more communication links between the virtual management switch and the management switch of any server.
8. A secure resource pool, characterized in that, The security resource pool is deployed on the service switch in a side-mounted manner. The security resource pool includes: a first server, a second server, a third server, and a management switch. The first server, the second server, and the third server are all equipped with a hyperconverged platform. The hyperconverged platform enables virtual machine migration and virtual machine fault self-recovery strategies. The first server, the second server, and the third server are each connected to the management switch through a virtual management switch and to the service switch through a virtual service switch. The first server contains various security devices, the second server contains an orchestrator, and the third server contains a traffic splitter; all the security devices, the orchestrator, and the traffic splitter are virtual machines. The splitter is used to obtain service traffic from the service switch and forward it to the orchestrator. The orchestrator is used to forward the service traffic to the corresponding security devices in sequence according to the preset security service chain for security detection, and to send the service traffic that passes the security detection back to the service switch via the splitter.
9. An electronic device, characterized in that, include: A memory, one or more processors; the memory is coupled to the processors; wherein the memory stores computer program code, the computer program code including computer instructions, and when the computer instructions are executed by the processor, the electronic device performs the method as described in any one of claims 1-7.
10. A computer-readable storage medium comprising computer instructions, characterized in that, When the computer instructions are executed on the electronic device, the electronic device causes the electronic device to perform the method as described in any one of claims 1-7.
11. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the method as described in any one of claims 1-7.