Packet detection system, method, apparatus, gateway device and storage medium

CN122316656APending Publication Date: 2026-06-30BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD
Filing Date
2024-12-30
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

How to properly integrate third-party firewall devices in a cloud computing environment to improve security, especially to achieve secure traffic protection in public cloud networks.

Method used

By using a two-layer tunnel encapsulation technology between the public cloud gateway, firewall load balancer gateway, and cloud server gateway, the original packets are distributed to the target firewall for protection and detection, and the firewall is selected through a load balancing algorithm to achieve secure and transparent forwarding of traffic.

Benefits of technology

It improves the security of the cloud computing environment, ensures the secure transmission of data in complex network environments, reduces security risks, and optimizes firewall resource utilization through load balancing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122316656A_ABST
    Figure CN122316656A_ABST
Patent Text Reader

Abstract

This invention relates to a packet inspection system, method, apparatus, gateway device, and storage medium, comprising: a public cloud gateway for encapsulating received raw packets through a first-layer tunnel and sending the encapsulated first packet to a firewall load balancing gateway; a firewall load balancing gateway for encapsulating the first packet through a second-layer tunnel and sending the encapsulated second packet to a cloud server gateway; a cloud server gateway for decapsulating the second packet through the first-layer tunnel and sending it to the target cloud virtual machine where the target firewall resides; and a target firewall for decapsulating the second packet through the second-layer tunnel to obtain the raw packet and performing protection detection on the raw packet. Thus, firewall devices can be integrated into the public cloud gateway, and the encapsulated packets can be distributed to the target firewall for protection detection via a load balancing algorithm through the firewall load balancing gateway, improving the security of the cloud computing environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of cloud computing technology, and in particular to a message detection system, method, apparatus, gateway device and storage medium. Background Technology

[0002] With the widespread adoption of cloud computing, enterprises are increasingly relying on cloud services to store and process data, which inevitably increases security risks. The main requirements for cloud security include protecting data, applications, and infrastructure in the cloud computing environment from various threats and attacks; ensuring that cloud service providers and users comply with regulations; protecting user privacy; and ensuring data integrity and availability.

[0003] However, since most cloud vendors currently lack sufficient experience and expertise in network security, they rely on third-party security products to protect cloud traffic. Therefore, how to effectively integrate third-party firewall devices into the network system of cloud services to improve the security of the cloud computing environment has become an urgent issue to be addressed. Summary of the Invention

[0004] In view of this, in order to solve the above-mentioned technical problems of improving the security of cloud computing environments, embodiments of the present invention provide a message detection system, method, apparatus, gateway device and storage medium.

[0005] In a first aspect, embodiments of the present invention provide a message detection system, including: a public cloud gateway, a firewall load balancing gateway, and a cloud server gateway, wherein the cloud server gateway contains multiple cloud virtual machines, and each cloud virtual machine contains a firewall;

[0006] The public cloud gateway is used to encapsulate the received original message through the first layer tunnel and send the encapsulated first message to the firewall load balancing gateway.

[0007] The firewall load balancing gateway is used to encapsulate the first packet through a second-layer tunnel and send the encapsulated second packet to the cloud server gateway.

[0008] The cloud server gateway is used to decapsulate the second message through the first layer tunnel and send it to the target cloud virtual machine where the target firewall is located. The target firewall is determined from the firewall cluster by the firewall load balancing gateway through a load balancing algorithm.

[0009] The target firewall is used to decapsulate the second packet through the second layer tunnel to obtain the original packet, and to perform protection detection on the original packet.

[0010] In one possible implementation, the target firewall is further configured to perform a second-layer tunnel encapsulation on the original packets after the protection detection;

[0011] The cloud server gateway is also used to encapsulate the original message after the second layer tunnel encapsulation with the first layer tunnel encapsulation to obtain the second message, and to send the second message to the firewall load balancing gateway.

[0012] The firewall load balancing gateway is also used to decapsulate the second packet through the second layer tunnel to obtain the first packet, and to send the first packet to the public cloud gateway.

[0013] The public cloud gateway is also used to decapsulate the first message through the first layer tunnel to obtain the original message after protection detection.

[0014] In one possible implementation, when encapsulating the first layer tunnel, the source address between the public cloud gateway and the firewall load balancing gateway is the address of the public cloud gateway, and the destination address is the address of the firewall load balancing gateway.

[0015] The source address between the firewall load balancing gateway and the cloud server gateway is the address of the firewall load balancing gateway, and the destination address is the address of the cloud server gateway.

[0016] When encapsulating the second layer tunnel, the source address is the address of the public cloud gateway, and the destination address is the address of the target firewall determined by the load balancing algorithm.

[0017] In one possible implementation, the cloud server gateway is specifically used to decapsulate the second packet through the first layer tunnel, obtain the destination address of the second layer tunnel, and thus obtain the address of the target firewall.

[0018] Based on the address of the target firewall, the second packet after decapsulation of the first layer tunnel is sent to the tunnel interface of the target firewall. The interface configuration of the tunnel interface of the target firewall is consistent with the interface configuration of the tunnel interface of the firewall load balancing gateway.

[0019] In one possible implementation, the firewall load balancing gateway is further configured to obtain user attribute information corresponding to the first packet, and obtain the current load information of each firewall, and determine the target firewall based on the user attribute information and the load information;

[0020] The firewall load balancing gateway is also used to expand or shrink the firewall cluster based on the current load traffic.

[0021] Secondly, embodiments of the present invention provide a packet detection method applied to a firewall load balancing gateway, the method comprising:

[0022] Receive the first message sent by the public cloud gateway. The first message is obtained by encapsulating the original message through the first layer tunnel.

[0023] The first message is encapsulated through a second-layer tunnel;

[0024] The encapsulated second packet is sent to the cloud server gateway, so that the cloud server gateway decapsulates the second packet through the first layer tunnel and sends it to the target firewall, so that the target firewall decapsulates the second packet through the second layer tunnel and performs protection detection on the original packet. The target firewall is determined from the firewall cluster through a load balancing algorithm.

[0025] In one possible implementation, the method further includes:

[0026] Receive the encapsulated second message sent by the cloud server gateway and returned by the target firewall after protection detection;

[0027] The first message is obtained by decapsulating the second message through the second layer tunnel;

[0028] The first message is sent to the public cloud gateway so that the public cloud gateway can decapsulate the first message through the second layer tunnel to obtain the original message after protection detection.

[0029] Thirdly, embodiments of the present invention provide a message detection device, comprising:

[0030] The receiving module is used to receive the first message sent by the public cloud gateway. The first message is obtained by encapsulating the original message through the first layer tunnel.

[0031] An encapsulation module is used to encapsulate the first message through a second-layer tunnel;

[0032] The sending module is used to send the encapsulated second message to the cloud server gateway, so that the cloud server gateway can decapsulate the second message through the first layer tunnel and send it to the target firewall, so that the target firewall can decapsulate the second message through the second layer tunnel and perform protection detection on the original message. The target firewall is determined from the firewall cluster through a load balancing algorithm.

[0033] Fourthly, embodiments of the present invention provide a gateway device, including: a processor and a memory, wherein the processor is configured to execute a packet detection program stored in the memory to implement the packet detection method described in any one of the second aspects above.

[0034] Fifthly, embodiments of the present invention provide a storage medium storing one or more programs, which can be executed by one or more processors to implement the message detection method described in any of the second aspects above.

[0035] The packet detection system provided in this embodiment of the invention includes a public cloud gateway, a firewall load balancing gateway, and a cloud server gateway. The cloud server gateway contains multiple cloud virtual machines, and each cloud virtual machine contains a firewall. The public cloud gateway is used to encapsulate the received original packet through a first-layer tunnel and send the encapsulated first packet to the firewall load balancing gateway. The firewall load balancing gateway is used to encapsulate the first packet through a second-layer tunnel and send the encapsulated second packet to the cloud server gateway. The cloud server gateway is used to decapsulate the second packet through the first-layer tunnel and send it to the target cloud virtual machine where the target firewall is located. The target firewall is determined from the firewall cluster by the firewall load balancing gateway using a load balancing algorithm. The target firewall is used to decapsulate the second packet through the second-layer tunnel to obtain the original packet and to perform protection detection on the original packet. Therefore, third-party firewall devices can be integrated into the public cloud gateway, and the encapsulated packets can be distributed to the target firewall through the firewall load balancing gateway using a load balancing algorithm for protection detection. While ensuring the firewall's compatibility with the public cloud VPC network, public network traffic is securely and transparently forwarded to the third-party firewall device for security detection, thereby improving the security of the cloud computing environment. Attached Figure Description

[0036] Figure 1 This is a schematic diagram of the structure of a message detection system provided in an embodiment of the present invention;

[0037] Figure 2 This is a schematic diagram of another message detection system provided in an embodiment of the present invention;

[0038] Figure 3 This is a flowchart illustrating a message detection method provided in an embodiment of the present invention;

[0039] Figure 4 A flowchart illustrating another message detection method provided in an embodiment of the present invention;

[0040] Figure 5 A flowchart illustrating another message detection method provided in an embodiment of the present invention;

[0041] Figure 6 A flowchart illustrating another message detection method provided in an embodiment of the present invention;

[0042] Figure 7This is a schematic diagram of the structure of a message detection device provided in an embodiment of the present invention;

[0043] Figure 8 This is a schematic diagram of the structure of a gateway device provided in an embodiment of the present invention. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0045] To facilitate understanding of the embodiments of the present invention, further explanations and descriptions will be provided below with reference to the accompanying drawings and specific embodiments. These embodiments do not constitute a limitation on the embodiments of the present invention.

[0046] Figure 1 This is a schematic diagram of a message detection system provided in an embodiment of the present invention, as shown below. Figure 1 As shown, the system specifically includes:

[0047] Public cloud gateway 1, firewall load balancer gateway 2, cloud server gateway 3, cloud server gateway contains multiple cloud virtual machines 4, each cloud virtual machine contains a firewall 5;

[0048] The public cloud gateway is used to encapsulate the received raw packets through the first-layer tunnel and send the encapsulated first packets to the firewall load balancing gateway.

[0049] The firewall load balancing gateway is used to encapsulate the first packet through a second-layer tunnel and send the encapsulated second packet to the cloud server gateway.

[0050] The cloud server gateway is used to decapsulate the second packet through the first layer tunnel and send it to the target cloud virtual machine where the target firewall is located. The target firewall is determined from the firewall cluster by the firewall load balancing gateway through a load balancing algorithm.

[0051] The target firewall is used to decapsulate the second packet through the second layer tunnel to obtain the original packet, and to perform protection detection on the original packet.

[0052] In this embodiment, the public cloud gateway is the load balancing gateway at the public cloud ingress, and the firewall cluster is attached to the public cloud ingress. Since the computing resources within the public cloud are isolated from each other, the internal network uses overlay tunnel forwarding. Therefore, under normal circumstances, when external traffic accesses resources within the cloud, the packet is encapsulated in a tunnel after entering the cloud network for forwarding within the VPC created by that user.

[0053] After receiving the original message (which could be a request from the application layer, such as an HTTP request or a database query), the public cloud gateway passes it through the first-layer tunnel. Figure 1 The `tunnel1` method encapsulates the original packet. Common tunneling protocols include VXLAN, GRE, and IPsec. Taking VXLAN as an example, the encapsulation method is as follows: The original packet (such as a raw Ethernet frame or IP packet) is appended to the VXLAN header. A new IP header, usually a UDP header, is added to the outside of the encapsulated packet. The UDP header contains the source address (source IP address), destination address (destination IP address), and port number. Since routing between gateway nodes within the cloud network is reachable by default, the encapsulated packet can be transmitted via the physical network's IP routing.

[0054] The encapsulated first packet is transmitted over the network, with the destination address typically being the firewall load balancing gateway. Upon receiving the first packet, the firewall load balancing gateway determines the target firewall in the backend cloud server gateway to distribute traffic based on preset load balancing strategies (such as round-robin, weighted, least connections, etc.) and information in the packet (such as the target service's IP address and port). The target firewall can be determined in the following ways: different firewall clusters are pre-configured for different users; a corresponding listener is set up for each firewall cluster; the target firewall cluster corresponding to the currently received packet is determined based on the user sending the packet; the target listener corresponding to the target firewall cluster is determined; and the target firewall is determined from the target firewall cluster using a load balancing algorithm through the target listener.

[0055] Before the firewall load balancing gateway sends packets to the cloud server, the first packet needs to be encapsulated through a Layer 2 tunnel. The Layer 2 tunnel can use the same or a different technology as the first layer tunnel. For example, assuming the first layer uses VXLAN encapsulation, the second layer might use GRE or other tunneling protocols to encapsulate the first packet again to achieve a more complex network topology. Alternatively, the second layer could use VXLAN encapsulation. During encapsulation, more tunnel header information is added to the first packet to increase metadata (such as source / destination tunnels, data forwarding labels, etc.). This data helps to more accurately control the routing and forwarding of network traffic. After encapsulation through the Layer 2 tunnel, the second packet is obtained. The encapsulated second packet is then sent to the cloud server gateway.

[0056] Furthermore, after receiving the second packet, the cloud server gateway will decapsulate the second layer tunnel, extract the first packet, and forward it to the target cloud virtual machine where the target firewall is located according to the routing rules or target address. The target firewall will then decapsulate the first layer tunnel of the first packet to obtain the original packet.

[0057] The target firewall performs traffic scrubbing and protection detection based on the customer's required security configuration policies. Traffic scrubbing mainly filters and cleans network traffic to ensure that only data conforming to security rules and specifications passes through, preventing malicious, spam, and attack traffic from entering the internal network. Traffic scrubbing includes the following steps: 1. Packet filtering: The firewall examines the header information of each packet, including source address, destination address, protocol type, port number, etc., and decides whether to allow the packet to pass based on preset rules (e.g., IP filtering: restricting access from certain IP addresses or allowing only traffic from specific IP addresses to pass through; port filtering: controlling traffic based on port number and blocking insecure port access). 2. Stateful filtering: Stateful detection tracks the state and context of connections and performs real-time analysis of traffic to prevent spoofed packets from bypassing the firewall. The firewall maintains the state of each connection and only allows packets that conform to the current session state to enter. 3. Application layer filtering: The firewall can perform more granular traffic filtering for specific application protocols (such as HTTP, FTP, DNS, etc.).

[0058] Security detection refers to the comprehensive analysis of network traffic by a firewall to detect potential attacks, abnormal behavior, unauthorized access, and other risks. Firewalls enhance network security through real-time monitoring, rule matching, and threat identification. Security detection includes the following aspects: 1. Intrusion Detection and Prevention (IDS / IPS): By analyzing abnormal behavior, malicious patterns, and known attack characteristics in network traffic, it detects the presence of network intrusions. IDS generates alerts to alert network administrators of potential threats. 2. Behavioral Analysis: Firewalls can detect abnormal activity in the network through behavioral analysis. 3. Malicious Traffic Identification.

[0059] The packet inspection system provided in this invention protects data content through dual-sided tunnel encapsulation and detects potential attacks through a firewall, thereby improving data security. Packets are distributed to the firewall via a firewall load balancing gateway, ensuring even distribution of network traffic. Multi-layer tunnel encapsulation ensures secure communication across networks and regions. Combining various network security technologies with tunnel encapsulation ensures data protection during transmission in complex cloud environments while reducing security risks.

[0060] In one possible implementation, after the target firewall performs protection detection on the original packet, the target firewall is also used to perform a second layer tunnel encapsulation on the original packet after protection detection.

[0061] The cloud server gateway is also used to encapsulate the original packet after the second layer tunnel encapsulation with the first layer tunnel encapsulation to obtain the second packet, and to send the second packet to the firewall load balancing gateway.

[0062] The firewall load balancing gateway is also used to decapsulate the second packet through the second layer tunnel to obtain the first packet, and to send the first packet to the public cloud gateway.

[0063] The public cloud gateway is also used to decapsulate the first message after the first layer of tunneling to obtain the original message after protection testing.

[0064] In this embodiment, the target firewall encapsulates the original packet after protection detection through a second-layer tunnel. After receiving the packet encapsulated through the second-layer tunnel, the cloud server gateway further encapsulates it through a first-layer tunnel to obtain a second packet, which is then sent to the firewall load balancing gateway.

[0065] The firewall load balancing gateway decapsulates the second packet using a Layer 2 tunnel, recovering the original first packet. This first packet is then sent to the public cloud gateway, which decapsulates the first tunnel, recovering the original packet after protection detection. The public cloud gateway then uses a load balancing algorithm to send the original packet, after protection detection, to different computing resources. This embodiment enables packets after protection detection to be returned to the public cloud gateway via tunnel encapsulation and decapsulation, improving the security and integrity of data transmission.

[0066] In one possible implementation, when encapsulating the first-layer tunnel, the source address between the public cloud gateway and the firewall load balancer gateway is the address of the public cloud gateway, and the destination address is the address of the firewall load balancer gateway; the source address between the firewall load balancer gateway and the cloud server gateway is the address of the firewall load balancer gateway, and the destination address is the address of the cloud server gateway; when encapsulating the second-layer tunnel, the source address is the address of the public cloud gateway, and the destination address is the address of the target firewall determined by the load balancing algorithm.

[0067] In this embodiment, as Figure 2 The diagram shown is a structural schematic of another message detection system provided in an embodiment of the present invention. Figure 2 As shown, the system specifically includes:

[0068] First level tunnel ( Figure 2 In the context of tunnel1, messages are used for communication between gateway nodes within the cloud network. Each gateway node is responsible for the encapsulation and decapsulation of its corresponding tunnel. The second layer tunnel ( Figure 2 The tunnel2 layer is used to protect the integrity of the original packets and is responsible for tunnel encapsulation and decapsulation between the firewall load balancer gateway and the firewall. Each firewall (Fwip1-Fwip3) is deployed on each cloud virtual machine (ECS01-ECS03) within the cloud server gateway. The destination and source addresses of the first-layer tunnel (inner layer) are the routing addresses between nodes of each gateway. For example, the source address between the public cloud gateway and the firewall load balancer gateway is the address of the public cloud gateway, i.e. Figure 2 In this context, GW_IP represents the destination address of the firewall load balancing gateway. Figure 2 The LB_IP in the code leads to the redirection address between the public cloud gateway and the firewall load balancer gateway as GW_IP->LB_IP. The source address between the firewall load balancer gateway and the cloud server gateway is the address of the firewall load balancer gateway, i.e. Figure 2 In this context, Local_IP refers to the destination address, which is the address of the cloud server's gateway. Figure 2From vSw_IP, we can deduce that the redirection address between the firewall load balancer gateway and the cloud server gateway is Local_IP->vSw_IP. Therefore, we obtain... Figure 2 The first layer tunnel after the first layer encapsulation is: GW_IP->LB_IP+udp+vxlan.

[0069] During the second-layer tunnel encapsulation, the firewall load balancing gateway determines the target firewall in the firewall cluster (the firewalls are deployed in a cluster behind the firewall load balancing gateway) to forward the packet to based on the load balancing algorithm. At this point, the second-layer tunnel (inner layer) is encapsulated, with the source address using GW_IP and the destination address being the determined target firewall address Fwip_n. This yields... Figure 2 After two encapsulations, the tunnel consists of two layers: the first layer is Local_IP->vSw_IP+udp+vxlan, and the second layer is GW_IP->Fw_ip+udp+vxlan. Here, udp is the protocol used, vxlan is the name of the tunneling technology used, CIP is the communication protocol, VIP is the virtual IP address, and date is the date.

[0070] In one possible implementation, the cloud server gateway is specifically used to decapsulate the second packet through the first-layer tunnel, obtain the destination address of the second-layer tunnel, and thus the address of the target firewall. Based on the address of the target firewall, the decapsulated second packet is sent to the tunnel interface of the target firewall. The interface configuration of the target firewall's tunnel interface is consistent with the interface configuration of the firewall load balancing gateway's tunnel interface to ensure that the encapsulated tunnel information can be correctly processed within the firewall. The second-layer tunnel encapsulation can be decapsulated through the tunnel interface, allowing the target firewall to obtain the original packet.

[0071] In one possible implementation, the firewall load balancing gateway is also used to obtain user attribute information corresponding to the first packet, and to obtain the current load information of each firewall, and to determine the target firewall based on the user attribute information and the load information.

[0072] Firewall load balancing gateways are also used to scale up or down firewall clusters based on current load traffic.

[0073] In this embodiment, the original packet also contains user attribute information to identify the enterprise to which the original packet belongs. Each enterprise has a pre-configured number of firewalls, and each firewall can only process packets from its corresponding enterprise. The firewall load balancing gateway can obtain the user attribute information corresponding to the packet, identify the multiple firewalls corresponding to the user attribute information, and obtain the load information for each firewall. The load information can include: CPU utilization: the CPU utilization of the firewall instance, reflecting the firewall's computational load; Memory utilization: the memory usage of the firewall instance; Network traffic: the network traffic processed by the firewall, including inbound and outbound traffic; Request processing speed or latency: the response time of the firewall in processing requests; Other resource consumption: such as disk I / O, number of connections, etc. Based on the load information, a load balancing algorithm is used to determine the target firewall to achieve load balancing among multiple firewalls. Simultaneously, if the load of some firewall instances is too high, the firewall load balancing gateway can trigger a scaling operation, starting new firewall instances and distributing packets to the new instances to avoid overloading existing firewalls. Load thresholds (such as CPU or memory utilization exceeding a certain percentage) can be set, and when the threshold is reached, new firewall instances are automatically started to distribute traffic. When the firewall load falls below a certain threshold, the firewall load balancing gateway can trigger a scaling-down operation, shutting down some firewall instances that are no longer needed. This allows for flexible expansion to meet the changing and expanding needs of the business, enabling real-time horizontal scaling of backend firewall devices to meet the security detection requirements of high bandwidth and high traffic, saving resources and costs, and improving the resource utilization of the cluster.

[0074] Figure 3 This is a flowchart illustrating a message detection method provided in an embodiment of the present invention, as shown below. Figure 3 As shown, the method specifically includes:

[0075] S11. Receive the first message sent by the public cloud gateway, wherein the first message is obtained by encapsulating the original message through the first layer tunnel;

[0076] S12. Encapsulate the first message through the second layer tunnel;

[0077] S13. The encapsulated second packet is sent to the cloud server gateway, so that the cloud server gateway decapsulates the second packet through the first layer tunnel and sends it to the target firewall, so that the target firewall decapsulates the second packet through the second layer tunnel and performs protection detection on the original packet. The target firewall is determined from the firewall cluster through a load balancing algorithm.

[0078] In this embodiment, the application is to a firewall load balancing gateway. The public cloud gateway is the load balancing gateway at the public cloud ingress, and the firewall cluster is attached to the public cloud ingress.

[0079] After receiving the original packet, the public cloud gateway encapsulates it through a first-layer tunnel (outer layer). The encapsulated first packet is transmitted over the network, with the destination address typically being the firewall load balancer gateway. Upon receiving the first packet, the firewall load balancer gateway determines the target firewall in the backend cloud server gateway to distribute traffic according to its preset load balancing policy and the information in the packet. Before sending the packet to the cloud server, the firewall load balancer gateway encapsulates the first packet through a second-layer tunnel (inner layer) to obtain the second packet. The encapsulated second packet is then sent to the cloud server gateway.

[0080] The cloud server gateway decapsulates the second-layer tunnel, extracts the first packet, and forwards it to the target cloud virtual machine where the target firewall resides, based on routing rules or the destination address. The target firewall then decapsulates the first packet from the first-layer tunnel to obtain the original packet. The target firewall then performs traffic scrubbing and protection detection according to the security configuration policies required by the customer.

[0081] After cleaning and protecting the original messages, the method further includes:

[0082] S14. Receive the encapsulated second message sent by the cloud server gateway and returned by the target firewall after protection detection;

[0083] S15. After decapsulating the second message through the second layer tunnel, the first message is obtained.

[0084] S16. The first message is sent to the public cloud gateway so that the public cloud gateway can decapsulate the first message through the second layer tunnel to obtain the original message after protection detection.

[0085] In this embodiment, the target firewall encapsulates the original packet after protection detection through a second-layer tunnel. After receiving the packet encapsulated through the second-layer tunnel, the cloud server gateway further encapsulates it through a first-layer tunnel to obtain a second packet, which is then sent to the firewall load balancing gateway.

[0086] The firewall load balancing gateway will decapsulate the second packet using the second layer tunnel to recover the original first packet. The first packet will then be sent to the public cloud gateway. The public cloud gateway will decapsulate the first layer tunnel to recover the original packet after protection detection. The original packet after protection detection will then be sent to different computing resources using the load balancing algorithm.

[0087] The packet detection method provided in this embodiment of the invention receives a first packet sent by a public cloud gateway. The first packet is obtained by encapsulating the original packet through a first-layer tunnel. The first packet is then encapsulated again through a second-layer tunnel. The encapsulated second packet is then sent to a cloud server gateway, which decapsulates the second packet through the first-layer tunnel and sends it to a target firewall. The target firewall decapsulates the second packet through the second-layer tunnel and performs protection detection on the original packet. The target firewall is determined from a firewall cluster using a load balancing algorithm. Therefore, for public cloud gateways with external firewall load balancing gateways and firewall clusters, by encapsulating the original packet through a double-layer tunnel and load balancing it before sending it to the target firewall for protection detection, it ensures that while maintaining compatibility with public cloud VPC networks, public network traffic is securely and transparently forwarded to third-party firewall devices for security detection. This improves data security, reduces the processing pressure on the public cloud, and rationally distributes traffic across multiple firewalls through load balancing.

[0088] Figure 4 The diagram shown is a flowchart of another message detection method provided by an embodiment of the present invention. The method specifically includes:

[0089] The firewall module is attached to the public cloud entry point (public network entry point). Firewall traffic redirection configurations are added as needed. The firewall is deployed on a cloud server (virtual machine), and different users create their own firewall clusters (e.g., Figure 4 The firewall virtual machine (user A) in the example is the firewall cluster corresponding to user A. Figure 4 Users A, B, and C each have their own firewall deployments. In front of each user's firewall cluster is a firewall load balancing gateway (load balancer). The load balancer contains multiple listeners, each corresponding to a user's firewall cluster. It uses a load balancing algorithm to determine the firewall corresponding to the current packet, achieving load balancing and enabling seamless service transitions by scaling up or down the firewall cluster and upgrading versions based on the current packet volume. When a packet is received, it determines whether the sending user has purchased firewall services. If so, it is sent to the load balancer to select a target firewall for protection testing. If not, it is sent to the public cloud internal network according to the content to be executed in the packet to execute internal network services (e.g., ...). Figure 4 VPC A is for AI large model and storage services, VPC B is for video services, and VPC C is for automotive services.

[0090] Figure 5 The diagram shown is a schematic flowchart of another message detection method provided in an embodiment of the present invention. Figure 6 The diagram shown is a flowchart of another message detection method provided by an embodiment of the present invention. The method specifically includes:

[0091] like Figure 5 As shown, to ensure that the original packets are delivered to the firewall with maximum preservation, two layers of tunnel information are encapsulated during forwarding within the cloud network. Because traffic undergoes DNAT (Destination Address Translation) after passing through the load balancer, the load balancer gateway performs a tunnel encapsulation layer to ensure that the original packets are delivered to the firewall intact without modification. The specific encapsulation and decapsulation processes are as follows... Figure 3 Consistent, please refer to the following for details. Figure 3 The relevant details will not be elaborated here for the sake of brevity.

[0092] like Figure 6 As shown, because firewalls need to implement security policies (ACLs, application detection, virus attack detection, etc.) based on a complete connection, all uplink and downlink traffic passing through a specific connection must hit the same firewall after passing through the load balancer gateway. When the load balancer forwards traffic to the backend, it uses a symmetric hash algorithm to ensure that two symmetrical packets (uplink and downlink packets are symmetrical in terms of 5-tuples) can be distributed to the same firewall. This way, the load balancer does not need to store connection session information, improving forwarding efficiency.

[0093] Figure 7 This is a schematic diagram of a message detection device provided in an embodiment of the present invention, as shown below. Figure 7 As shown, the device specifically includes:

[0094] The first receiving module 71 is used to receive a first message sent by the public cloud gateway. The first message is obtained by encapsulating the original message through the first layer tunnel.

[0095] Encapsulation module 72 is used to encapsulate the first message through the second-layer tunnel;

[0096] The first sending module 73 is used to send the encapsulated second message to the cloud server gateway, so that the cloud server gateway decapsulates the second message through the first layer tunnel and sends it to the target firewall, so that the target firewall decapsulates the second message through the second layer tunnel and performs protection detection on the original message. The target firewall is determined from the firewall cluster through a load balancing algorithm.

[0097] In one possible implementation, the second receiving module 74 is used to receive the encapsulated second message sent by the cloud server gateway and returned by the target firewall after protection detection;

[0098] The decapsulation module 75 is used to decapsulate the second message through the second layer tunnel to obtain the first message.

[0099] The second sending module 76 is used to send the first message to the public cloud gateway, so that the public cloud gateway can decapsulate the first message through the second layer tunnel to obtain the original message after protection detection.

[0100] The message detection device provided in this embodiment can be as follows: Figure 7 The apparatus shown can perform, for example Figure 3 All steps of the message detection method are then implemented to achieve... Figure 3 For details on the technical effectiveness of the message detection method shown, please refer to [link / reference]. Figure 3 The relevant descriptions are presented concisely and will not be elaborated upon here.

[0101] Figure 8 This is a schematic diagram of the structure of a gateway device provided in an embodiment of the present invention. Figure 8 The gateway device 800 shown includes at least one processor 801, a memory 802, at least one network interface 804, and other user interfaces 803. The various components in the gateway device 800 are coupled together via a bus system 805. It is understood that the bus system 805 is used to implement communication between these components. In addition to a data bus, the bus system 805 also includes a power bus, a control bus, and a status signal bus. However, for clarity, ... Figure 8 The general labeled all buses as Bus System 805.

[0102] The user interface 803 may include a display, keyboard, or clicking device (e.g., mouse, trackball, touchpad, or touchscreen).

[0103] It is understood that the memory 802 in the embodiments of the present invention can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDRSDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), and Direct Rambus RAM (DRRAM). The memory 802 described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0104] In some implementations, memory 802 stores elements, executable units or data structures, or subsets thereof, or extended sets thereof: operating system 8021 and application programs 8022.

[0105] The operating system 8021 includes various system programs, such as the framework layer, core library layer, and driver layer, used to implement various basic business functions and handle hardware-based tasks. The application program 8022 includes various applications, such as a media player and a browser, used to implement various application functions. The program implementing the method of this embodiment can be included in the application program 8022.

[0106] In this embodiment of the invention, by calling the program or instructions stored in the memory 802, specifically the program or instructions stored in the application program 8022, the processor 801 executes the method steps provided in each method embodiment, including, for example:

[0107] Receive the first message sent by the public cloud gateway. The first message is obtained by encapsulating the original message through the first layer tunnel.

[0108] The first message is encapsulated through a second-layer tunnel;

[0109] The encapsulated second packet is sent to the cloud server gateway, so that the cloud server gateway decapsulates the second packet through the first layer tunnel and sends it to the target firewall, so that the target firewall decapsulates the second packet through the second layer tunnel and performs protection detection on the original packet. The target firewall is determined from the firewall cluster through a load balancing algorithm.

[0110] In one possible implementation, the cloud server gateway sends a second encapsulated message that is returned by the target firewall after protection detection.

[0111] The first message is obtained by decapsulating the second message through the second layer tunnel;

[0112] The first message is sent to the public cloud gateway so that the public cloud gateway can decapsulate the first message through the second layer tunnel to obtain the original message after protection detection.

[0113] The methods disclosed in the above embodiments of the present invention can be applied to or implemented by processor 801. Processor 801 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in processor 801 or by instructions in the form of software. The processor 801 may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present invention can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software units in the decoding processor. The software units may be located in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 802. Processor 801 reads the information in memory 802 and, in conjunction with its hardware, completes the steps of the above method.

[0114] It is understood that the embodiments described herein can be implemented in hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit can be implemented in one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions described herein, or combinations thereof.

[0115] For software implementation, the techniques described herein can be implemented by units that perform the functions described herein. The software code can be stored in memory and executed by a processor. The memory can be implemented in the processor or external to the processor.

[0116] The gateway device provided in this embodiment can be as follows: Figure 8 The device shown can perform, for example Figure 3 All steps of the message detection method are then implemented to achieve... Figure 3 For details on the technical effectiveness of the message detection method shown, please refer to [link / reference]. Figure 3 The relevant descriptions are presented concisely and will not be elaborated upon here.

[0117] This invention also provides a storage medium (computer-readable storage medium). This storage medium stores one or more programs. The storage medium may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as read-only memory, flash memory, hard disk, or solid-state drive; the memory may also include combinations of the above types of memory.

[0118] One or more programs in the storage medium can be executed by one or more processors to implement the above-described message detection method executed on the device side.

[0119] The processor is used to execute a message detection program stored in the memory to implement the following steps of a message detection method executed on the device side:

[0120] Receive the first message sent by the public cloud gateway. The first message is obtained by encapsulating the original message through the first layer tunnel.

[0121] The first message is encapsulated through a second-layer tunnel;

[0122] The encapsulated second packet is sent to the cloud server gateway, so that the cloud server gateway decapsulates the second packet through the first layer tunnel and sends it to the target firewall, so that the target firewall decapsulates the second packet through the second layer tunnel and performs protection detection on the original packet. The target firewall is determined from the firewall cluster through a load balancing algorithm.

[0123] In one possible implementation, the cloud server gateway sends a second encapsulated message that is returned by the target firewall after protection detection.

[0124] The first message is obtained by decapsulating the second message through the second layer tunnel;

[0125] The first message is sent to the public cloud gateway so that the public cloud gateway can decapsulate the first message through the second layer tunnel to obtain the original message after protection detection.

[0126] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0127] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented in hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.

[0128] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A message detection system, characterized in that, include: The cloud server gateway includes a public cloud gateway, a firewall load balancing gateway, and a cloud server gateway. The cloud server gateway contains multiple cloud virtual machines, and each cloud virtual machine contains a firewall. The public cloud gateway is used to encapsulate the received original message through the first layer tunnel and send the encapsulated first message to the firewall load balancing gateway. The firewall load balancing gateway is used to encapsulate the first packet through a second-layer tunnel and send the encapsulated second packet to the cloud server gateway. The cloud server gateway is used to decapsulate the second message through the first layer tunnel and send it to the target cloud virtual machine where the target firewall is located. The target firewall is determined from the firewall cluster by the firewall load balancing gateway through a load balancing algorithm. The target firewall is used to decapsulate the second packet through the second layer tunnel to obtain the original packet, and to perform protection detection on the original packet.

2. The system according to claim 1, characterized in that, The target firewall is also used to perform a second-layer tunnel encapsulation on the original packets after the protection detection; The cloud server gateway is also used to encapsulate the original message after the second layer tunnel encapsulation with the first layer tunnel encapsulation to obtain the second message, and to send the second message to the firewall load balancing gateway. The firewall load balancing gateway is also used to decapsulate the second packet through the second layer tunnel to obtain the first packet, and to send the first packet to the public cloud gateway. The public cloud gateway is also used to decapsulate the first message through the first layer tunnel to obtain the original message after protection detection.

3. The system according to claim 2, characterized in that, When encapsulating the first layer tunnel, the source address between the public cloud gateway and the firewall load balancing gateway is the address of the public cloud gateway, and the destination address is the address of the firewall load balancing gateway. The source address between the firewall load balancing gateway and the cloud server gateway is the address of the firewall load balancing gateway, and the destination address is the address of the cloud server gateway. When encapsulating the second layer tunnel, the source address is the address of the public cloud gateway, and the destination address is the address of the target firewall determined by the load balancing algorithm.

4. The system according to claim 3, characterized in that, The cloud server gateway is specifically used to decapsulate the second packet through the first layer tunnel, obtain the destination address of the second layer tunnel, and thus obtain the address of the target firewall. Based on the address of the target firewall, the second packet after decapsulation of the first layer tunnel is sent to the tunnel interface of the target firewall. The interface configuration of the tunnel interface of the target firewall is consistent with the interface configuration of the tunnel interface of the firewall load balancing gateway.

5. The system according to claim 4, characterized in that, The firewall load balancing gateway is also used to obtain user attribute information corresponding to the first packet, and to obtain the current load information of each firewall, and to determine the target firewall based on the user attribute information and the load information. The firewall load balancing gateway is also used to expand or shrink the firewall cluster based on the current load traffic.

6. A message detection method, characterized in that, The method, applied to a firewall load balancing gateway, includes: Receive the first message sent by the public cloud gateway. The first message is obtained by encapsulating the original message through the first layer tunnel. The first message is encapsulated through a second-layer tunnel; The encapsulated second packet is sent to the cloud server gateway, so that the cloud server gateway decapsulates the second packet through the first layer tunnel and sends it to the target firewall, so that the target firewall decapsulates the second packet through the second layer tunnel and performs protection detection on the original packet. The target firewall is determined from the firewall cluster through a load balancing algorithm.

7. The method according to claim 6, characterized in that, The method further includes: Receive the second encapsulated message sent by the cloud server gateway and returned by the target firewall after protection detection; The first message is obtained by decapsulating the second message through the second layer tunnel; The first message is sent to the public cloud gateway so that the public cloud gateway can decapsulate the first message through the second layer tunnel to obtain the original message after protection detection.

8. A message detection device, characterized in that, include: The first receiving module is used to receive the first message sent by the public cloud gateway. The first message is obtained by encapsulating the original message through the first layer tunnel. An encapsulation module is used to encapsulate the first message through a second-layer tunnel; The first sending module is used to send the encapsulated second message to the cloud server gateway, so that the cloud server gateway can decapsulate the second message through the first layer tunnel and send it to the target firewall, so that the target firewall can decapsulate the second message through the second layer tunnel and perform protection detection on the original message. The target firewall is determined from the firewall cluster through a load balancing algorithm.

9. A gateway device, characterized in that, include: A processor and a memory, the processor being configured to execute a message detection program stored in the memory to implement the message detection method according to any one of claims 6 to 7.

10. A storage medium, characterized in that, The storage medium stores one or more programs, which can be executed by one or more processors to implement the message detection method according to any one of claims 6 to 7.