A method, device, medium and program product for managing a security service chain
Patent Information
- Application Number
- CN202611272558.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-21
- Publication Date
- 2026-09-22
AI Technical Summary
[0008]根据本发明的另一方面,提供了一种计算机可读存储介质,所述计算机可读存储介质存储有计算机程序,所述计算机程序用于使处理器执行时实现本发明任一实施例所述的安全服务链的管理方法。
Smart Images

Figure CN122802135A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of marine cybersecurity technology, and in particular to a management method, device, medium, and program product for a security service chain. Background Technology
[0002] Ship network security is one of the key technologies for ensuring the stable operation of ships. In a Software Defined Network (SDN) / Virtual Network Function (VNF) network architecture, security capabilities such as firewalls, intrusion detection / prevention systems, web application firewalls, sandboxes, and data loss prevention are typically deployed in the form of VNFs or virtualized security nodes. The SDN controller then generates flow table entries, tunnel encapsulations, service path identifiers, or service function chain forwarding identifiers based on security policies, ensuring that service traffic passes through designated security nodes sequentially.
[0003] Currently, existing security service chain management methods typically employ a process of security policy orchestration, service function chain deployment, online service chain updates, and application software release to update security policies. However, in ship networks, the current approach of directly issuing candidate defense policies may lead to problems such as false blocking of critical services, missed attack flows, service chain disconnections, VNF overload, sudden increases in link latency, and policy conflicts, thereby affecting the reliability of ship networks. Summary of the Invention
[0004] This invention provides a method, device, medium, and program product for managing a security service chain, which can pre-verify candidate defense strategies, avoid the impact of abnormal security strategies on the real business of the ship network, improve the reliability of the ship network, and enhance the stability of security service chain management.
[0005] According to one aspect of the present invention, a method for managing a secure service chain is provided, comprising: Establish a digital twin model corresponding to the current stable strategy, and obtain the candidate strategy version, candidate service function chain mapping and candidate flow table intent corresponding to the candidate defense strategy; Generate the verification identifier, candidate version metadata, and candidate version flow table identifier corresponding to the candidate policy version, and generate shadow flow table entries according to the candidate flow table intent; Candidate strategies are pre-verified on-network based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification indicators; When the verification indicator meets the preset verification pass conditions, the differential flow table change set is obtained according to the candidate defense strategy and the current stable strategy. The differential flow table change set is then distributed in a gray-scale manner according to the preset strategy, the state machine, the candidate service function chain mapping, the candidate version metadata, and the candidate version flow table identifier, so that the candidate defense strategy takes effect.
[0006] According to another aspect of the present invention, a management device for a secure service chain is provided, comprising: The model building module is used to build a digital twin model corresponding to the current stable strategy, and to obtain the candidate strategy version, candidate service function chain mapping and candidate flow table intent corresponding to the candidate defense strategy. The flow table entry generation module is used to generate the verification identifier, candidate version metadata and candidate version flow table identifier corresponding to the candidate policy version, and generate shadow flow table entries according to the candidate flow table intent; The policy verification module is used to perform on-network pre-verification of candidate policies based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification indicators. The flow table distribution module is used to obtain a differential flow table change set according to the candidate defense strategy and the current stable strategy when the verification indicator meets the preset verification pass conditions, and to distribute the differential flow table change set in a gray-scale manner according to the preset strategy, the state machine, the candidate service function chain mapping, the candidate version metadata and the candidate version flow table identifier, so as to make the candidate defense strategy effective.
[0007] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor, which enables the at least one processor to perform the secure service chain management method according to any embodiment of the present invention.
[0008] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program configured to cause a processor to execute and implement the secure service chain management method according to any embodiment of the present invention.
[0009] According to another aspect of the present invention, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the secure service chain management method described in any embodiment of the present invention.
[0010] The technical solution of this invention establishes a digital twin model corresponding to the current stable strategy and obtains the candidate strategy version, candidate service function chain mapping, and candidate flow table intent corresponding to the candidate defense strategy; generates a verification identifier, candidate version metadata, and candidate version flow table identifier corresponding to the candidate strategy version, and generates shadow flow table entries based on the candidate flow table intent; performs on-network pre-verification of the candidate strategy based on the shadow flow table entries, candidate service function chain mapping, digital twin model, and verification identifier to obtain verification indicators; when the verification indicators meet the preset verification pass conditions, obtains the differential flow table change set based on the candidate defense strategy and the current stable strategy, and distributes the changes according to the preset strategy gray-scale distribution status. The system uses a combination of methods, including canary distribution of the differential flow table change set, candidate service function chain mapping, candidate version metadata, and candidate version flow table identifier, to enable candidate defense strategies to take effect. By setting verification identifiers, candidate version metadata, and candidate version flow table identifiers, and performing on-network pre-verification based on shadow flow table entries, candidate service function chain mappings, digital twin models, and verification identifiers before the official distribution of candidate defense strategies, the impact of abnormal security strategies on the actual business of the ship network can be avoided, thus improving the reliability of the ship network. Furthermore, by canary distribution of the differential flow table change set after successful pre-verification, the amount of data transmission can be reduced, improving the efficiency of security policy updates.
[0011] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0013] Figure 1 This is a flowchart of a security service chain management method provided according to Embodiment 1 of the present invention; Figure 2 This is a schematic diagram of the hierarchical structure of the digital twin model provided in Embodiment 1 of the present invention; Figure 3 This is a schematic diagram of the state transition and structure of a shadow flow table entry according to Embodiment 1 of the present invention; Figure 4 This is a flowchart of a security service chain management method provided according to Embodiment 2 of the present invention; Figure 5This is a complete state transition diagram of the strategy grayscale distribution state machine provided in Embodiment 2 of the present invention; Figure 6 This is a schematic diagram of the parallel isolation mechanism and batch deletion process provided in Embodiment 2 of the present invention; Figure 7 This is a complete interactive timing diagram of grayscale distribution and abnormal rollback provided in Embodiment 2 of the present invention; Figure 8 This is a schematic diagram of the audit strategy version chain provided in Embodiment 2 of the present invention; Figure 9 This is a schematic diagram of the structure of a security service chain management device provided according to Embodiment 3 of the present invention; Figure 10 This is a schematic diagram of the structure of an electronic device that implements the security service chain management method of the present invention. Detailed Implementation
[0014] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0015] It should be noted that the terms "first," "second," "target," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms can be used interchangeably where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0016] Example 1 Figure 1This is a flowchart illustrating a secure service chain management method according to Embodiment 1 of the present invention. This embodiment is applicable to the canary deployment of software-defined secure service chains for ship networks. The method can be executed by a secure service chain management device, which can be implemented in hardware and / or software. Typically, the secure service chain management device can be configured in electronic devices, such as computer equipment or servers on a ship. Figure 1 As shown, the method includes: S110. Establish a digital twin model corresponding to the current stable strategy, and obtain the candidate strategy version, candidate service function chain mapping and candidate flow table intent corresponding to the candidate defense strategy.
[0017] The current stable strategy is the security strategy currently in use by the ship network; the candidate defense strategy is the security strategy to be implemented, i.e., the replacement strategy for the current stable strategy. A digital twin model refers to a digital mirror model constructed in virtual space, based on a real physical entity (or system, business process) and integrating multi-dimensional information such as geometric structure, physical mechanism, operating rules, and historical operating data. This model can maintain a dynamic bidirectional mapping with the physical entity throughout its entire lifecycle and possesses simulation and state prediction capabilities. In this embodiment, a digital twin model corresponding to the current stable strategy can be established based on the associated information of the current stable strategy and a preset model data structure.
[0018] Then, the received candidate defense strategies can be parsed to generate corresponding candidate strategy versions, candidate Service Function Chain (SFC) mappings, and candidate flow table intents. The candidate strategy version can be generated based on the strategy version corresponding to the current stable strategy and preset version iteration rules. For example, if the strategy version corresponding to the current stable strategy is V1, then the candidate strategy version is V2.
[0019] Candidate Service Function Chain (SFC) mappings are path orchestration rules for candidate defense strategies at the security service chain layer. They define the order of security function nodes that eligible traffic must pass through, the path identifiers, and the tunnel correspondences. Candidate Flow Table Intents are the logical execution rules for candidate defense strategies at the SDN forwarding layer. They are abstract descriptions of forwarding requirements after the higher-layer security policies are decomposed but before being converted into standard flow table entries that can be directly executed by the switch. In this embodiment, based on preset construction rules and the content parsing results of the candidate defense strategies, corresponding candidate SFC mappings and candidate flow table intents can be generated.
[0020] Optionally, establishing a digital twin model corresponding to the current stable strategy may include: Acquire the status data of the ship network, and based on the status data, establish a digital twin model corresponding to the current stabilization strategy; The digital twin model includes at least one of the following: an asset node set, a business path set, an entry classifier set, an exchange node set, a security function node set, a production flow table and a candidate flow table set, a service function chain sequence set, a session state set, a policy version set, a protocol field mapping set, a risk indicator set, and an audit record set.
[0021] Specifically, firstly, status data of the ship network is collected, including asset nodes, service paths, ingress switching nodes, SDN switching nodes, VNF security function nodes, production flow tables, table numbers, matching fields, action fields, priorities, flow table identifiers, metadata usage, service function chain order, tunnel mapping, session status, VNF configuration versions, policy version numbers, and risk indicators. Then, based on this status data, a digital twin model corresponding to the current stable policy is established, and the mapping relationship between service flows, ingress switching nodes, production flow tables, service function chain path identifiers, VNF configuration versions, and session policy versions is established within the model.
[0022] In this embodiment, the digital twin model can be represented as DT(v,t)=<A,B,I,S,V,F,C,Sess,P,M,R,H> Where A represents the set of asset nodes, B represents the set of business paths, I represents the set of entry classifiers, S represents the set of SDN exchange nodes, V represents the set of VNF security function nodes, F contains the set of production flow tables and candidate flow tables, C represents the set of service function chain sequences, Sess represents the set of session states, P represents the set of policy versions, M represents the set of OpenFlow field mappings, R represents the set of risk indicators, and H represents the set of audit records.
[0023] For example, the hierarchical structure of a digital twin model can be as follows: Figure 2 As shown, from top to bottom, the layers are: Risk Indicator Layer, OpenFlow Protocol Field Layer, Policy Version Layer, Session State Layer, Service Function Chain Layer, Virtual Network Functional Safety Capability Layer, SDN Forwarding Layer, Ingress Classification Layer, Business Path Layer, and Asset Layer. Each layer is labeled with its core fields. The OpenFlow Protocol Field Layer records at least the candidate version metadata key-value pair, candidate version flow table identifier (cookie) field, candidate version flow table identifier mask (cookie_mask), table number, priority, barrier confirmation status, and flow table counter reference, enabling the verification, gray-scale deployment, and rollback processes of candidate defense strategies to be traced back to specific protocol fields.
[0024] The advantage of the above settings is that they can improve the integrity of the digital twin model and provide data support for the verification of candidate strategies.
[0025] S120. Generate the verification identifier, candidate version metadata and candidate version flow table identifier corresponding to the candidate policy version, and generate shadow flow table entries according to the candidate flow table intent.
[0026] Specifically, based on preset identifier configuration rules, a unique validation identifier (validation_id), metadata, cookie, and cookie_mask are assigned to each candidate policy version. The validation_id is used for shadow flow table matching and isolation during the pre-validation phase, the metadata is used for selecting candidate traffic during the canary rollout phase, and the cookie and cookie_mask are used for batch matching, deletion, or invalidation of candidate version flow tables during the rollback phase. Then, according to the candidate flow table intent and the preset flow table data structure, candidate version flow tables are generated as shadow flow table entries.
[0027] The shadow flow table entry can contain information such as exchange node identifier, table number, matching field, action field, priority, timeout, validation_id, candidate policy version number, rollback version, expected SFC path, cookie, cookie_mask, and metadata. In this embodiment, the validation_id corresponds one-to-one with the candidate policy version number and is bound to the lifecycle of the shadow flow table entry. After the candidate policy pre-validation ends, validation fails, validation times out, or is manually revoked, the SDN controller causes the shadow flow table entry with the corresponding validation_id to time out, delete, or enter an invalid state, preventing residual shadow flow tables from being mistakenly matched in subsequent policy changes.
[0028] S130. Perform on-network pre-verification of candidate strategies based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification indicators.
[0029] Specifically, based on the digital twin model, shadow flow table entries, and candidate service function chain mapping, the validation traffic written to validation_id is processed to obtain shadow flow table hit count, twin link path record, VNF detection log, service chain traversal record, and controller conflict detection result. Based on the aforementioned processing results, validation indicators such as false blocking rate, false detection rate, service chain integrity rate, link latency, policy conflict number, and VNF health status are calculated.
[0030] For example, the SDN switching nodes, SFC path topology, and VNF node configurations affected by candidate defense strategies can be extracted from the digital twin model. Shadow flow table entries and candidate SFC mappings are then distributed to the affected switching nodes, and verification traffic with the `validation_id` is input into these nodes. The verification traffic hits the shadow flow table entries in the switching nodes and flows through the corresponding VNF security nodes according to the rules of the candidate defense strategy, completing real firewall interception, intrusion detection, and other security processing. The SDN controller can collect the processing and result data of the verification traffic and calculate each verification metric based on its calculation function and the collected data.
[0031] It should be noted that validation_id serves as the matching condition for shadow flow table entries. Ordinary ship network traffic that does not carry this validation_id cannot hit these shadow flow table entries. Only validation traffic that has validation_id written to it can hit the entry, thereby achieving on-network stealth verification of candidate defense strategies on ship network switches.
[0032] Optionally, performing on-network pre-validation of candidate strategies based on the shadow flow table entry, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification metrics may include: Obtain initial verification traffic, and generate target verification traffic based on the initial verification traffic and the verification identifier; Candidate strategies are pre-validated on the network based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the target verification traffic to obtain verification indicators; The matching field of the shadow flow table entry includes the verification identifier.
[0033] In this embodiment, firstly, mirrored traffic from the ship's network, de-identified historical normal traffic, historical attack traffic with attack tags, or synthetic probe traffic can be collected as initial verification traffic. Verification identifiers are written into this initial verification traffic to generate target verification traffic. Then, the target verification traffic is input into a digital twin model. Based on the model's topology mapping, flow table rules, SFC path logic, and VNF simulation capabilities, the forwarding path, security detection actions, packet loss, and latency changes of the traffic are fully simulated. Simultaneously, the target verification traffic is input into a switching node with shadow flow table entries and candidate SFC mappings installed, and realistic security processing is performed according to real policy rules. Finally, based on the simulation results and the actual verification results, various verification indicators are calculated.
[0034] In this embodiment, the `validation_id` field is forcibly added as a matching condition to the matching field of the shadow flow table entry. Ordinary ship network traffic, which does not carry `validation_id`, will not hit this shadow flow table entry. Thus, absolute isolation is achieved at the forwarding rule level. For example, the state transitions and structure of the shadow flow table entry can be as follows: Figure 3 As shown, this describes the complete lifecycle of a shadow flow table entry, from creation, validation, and approval to canary deployment, as well as the batch deletion triggered when validation fails, times out, or an exception occurs and rolls back. The structure section lists the key fields that make up a shadow flow table entry.
[0035] For example, the formula for calculating the false blocking rate (FBR) can be expressed as FBR = N drop,normal / N normal The formula for calculating the false negative rate (MDR) can be expressed as MDR = N miss,attack / N attack The Service Chain Completeness (SCR) can be calculated as SCR = N match,SFC / N verify The formula for calculating link delay offset (LD) can be expressed as LD = T candidate -T stable Among them, N drop,normal N represents the number of validation streams whose labels are normal and whose action result is discard. normal N represents the total number of normal label verification streams. miss,attac N represents the number of verification flows labeled as attacks that were not alerted or blocked by VNF. attack N represents the total number of attack label verification flows. match,SFC N represents the number of verification streams whose actual VNF sequence matches the expected SFC sequence. verify T represents the total number of existing verification flows. candidate and T stable These represent the candidate path delay and the stable path delay, respectively.
[0036] The advantages of the above settings are that they can achieve rule isolation and traffic isolation, enable on-network stealth verification of candidate defense strategies, and avoid impacting normal business operations.
[0037] S140. When the verification indicator meets the preset verification pass conditions, according to the candidate defense strategy and the current stable strategy, the differential flow table change set is obtained, and according to the preset strategy, the state machine, the candidate service function chain mapping, the candidate version metadata and the candidate version flow table identifier are distributed in a gray-scale manner to make the candidate defense strategy effective.
[0038] Among them, the preset verification pass conditions can be preset conditions that need to be met to determine whether the verification is passed. For example, it can be that all verification indicators are within the corresponding preset value range.
[0039] Specifically, if all verification metrics reach preset thresholds, the candidate defense strategy and the current stable strategy are compared to obtain differential flow table entries, which are then used to form a differential flow table change set. Next, the state machine is deployed in a canary rollout according to the preset strategy, distributing the candidate service function chain mapping, candidate version flow table identifier, and differential flow table change set to the vessel network. The vessel network installs the candidate service function chain mapping, candidate version flow table identifier, and differential flow table change set to deploy the candidate defense strategy. The candidate version metadata serves as the matching condition for the candidate version flow table.
[0040] In this embodiment, the preset strategy canary deployment state machine includes at least the following states: pending verification, in twin verification, verification passed, candidate path pre-installation, barrier waiting, canary deployment, expanded canary deployment, full activation, exception rollback, and manual review. Jump conditions can be set between adjacent states.
[0041] Optionally, obtaining the differential flow table change set based on the candidate defense strategy and the current stable strategy may include: The candidate defense strategy and the current stable strategy are standardized to obtain candidate flow table tuples and stable flow table tuples. The candidate flow table tuples and stable flow table tuples are then compared by primary key to obtain newly added flow table entries, modified flow table entries, and deleted flow table entries. The differential flow table change set is generated based on the newly added flow table entry, the modified flow table entry, and the deleted flow table entry.
[0042] In this embodiment, firstly, the candidate defense strategies and the current stable strategies are standardized and uniformly converted into a standard data structure containing exchange nodes, table numbers, matching fields, action fields, priorities, service function chain path identifiers, VNF configuration versions, and strategy version numbers, to obtain candidate flow table tuples and stable flow table tuples. Then, using the exchange node, table number, matching field, and strategy scope as primary keys, the contents of the candidate flow table tuples and stable flow table tuples are compared to generate a differential flow table change set consisting of newly added flow table entries, modified flow table entries, and deleted flow table entries.
[0043] Among them, adding a flow table entry indicates a data item whose primary key exists only in the candidate flow table tuple; modifying a flow table entry indicates a data item whose primary key exists in both the candidate flow table tuple and the stable flow table tuple, but with different corresponding values; deleting a flow table entry indicates a data item whose primary key exists only in the stable flow table tuple.
[0044] The advantage of the above settings is that they enable accurate and efficient extraction of changed content, providing a data foundation for incremental updates to security policies.
[0045] The technical solution of this invention establishes a digital twin model corresponding to the current stable strategy and obtains the candidate strategy version, candidate service function chain mapping, and candidate flow table intent corresponding to the candidate defense strategy; generates a verification identifier, candidate version metadata, and candidate version flow table identifier corresponding to the candidate strategy version, and generates shadow flow table entries based on the candidate flow table intent; performs on-network pre-verification of the candidate strategy based on the shadow flow table entries, candidate service function chain mapping, digital twin model, and verification identifier to obtain verification indicators; when the verification indicators meet the preset verification pass conditions, obtains the differential flow table change set based on the candidate defense strategy and the current stable strategy, and distributes the changes according to the preset strategy gray-scale distribution status. The system uses a combination of methods, including canary distribution of the differential flow table change set, candidate service function chain mapping, candidate version metadata, and candidate version flow table identifier, to enable candidate defense strategies to take effect. By setting verification identifiers, candidate version metadata, and candidate version flow table identifiers, and performing on-network pre-verification based on shadow flow table entries, candidate service function chain mappings, digital twin models, and verification identifiers before the official distribution of candidate defense strategies, the impact of abnormal security strategies on the actual business of the ship network can be avoided, thus improving the reliability of the ship network. Furthermore, by canary distribution of the differential flow table change set after successful pre-verification, the amount of data transmission can be reduced, improving the efficiency of security policy updates.
[0046] Example 2 Figure 4 This is a flowchart illustrating a security service chain management method according to Embodiment 2 of the present invention. This embodiment is a further refinement of the above technical solution, and the technical solution in this embodiment can be combined with one or more of the above implementation methods. For example... Figure 4 As shown, the method includes: S210. Establish a digital twin model corresponding to the current stable strategy, and obtain the candidate strategy version, candidate service function chain mapping and candidate flow table intent corresponding to the candidate defense strategy.
[0047] S220. Generate the verification identifier, candidate version metadata and candidate version flow table identifier corresponding to the candidate policy version, and generate shadow flow table entries according to the candidate flow table intent.
[0048] S230. Perform on-network pre-verification of candidate strategies based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification indicators.
[0049] S240. When the verification indicator meets the preset verification pass conditions, according to the candidate defense strategy and the current stable strategy, obtain the differential flow table change set, obtain the influence exchange node corresponding to the differential flow table change set, and pre-install the differential flow table change set, the candidate version flow table identifier and the candidate service function chain mapping on the influence exchange node.
[0050] In this embodiment, the SDN switching nodes corresponding to each flow table entry in the differential flow table change set can be obtained by looking up the mapping relationships between business flows, ingress switching nodes, production flow tables, service function chain path identifiers, VNF configuration versions, and session policy versions in the digital twin model. These nodes serve as the influencing switching nodes. Then, the SDN controller can send the differential flow table change set, candidate version flow table identifiers (cookies), and candidate SFC mappings to each influencing switching node to install candidate defense policies on each node. Each influencing switching node updates its current stable version flow table based on the differential flow table change set to generate candidate version flow tables.
[0051] In this embodiment, the metadata.policy_version parameter is set to equal the candidate policy version (V_candidate) in the matching field of the candidate version flow table. Therefore, ordinary ship network traffic will not hit the candidate version flow table before the ingress classifier writes metadata to the ship network traffic.
[0052] S250. Send a barrier request to the affected exchange nodes, and enter the gray-scale distribution state upon receiving confirmation information from all the affected exchange nodes.
[0053] Next, the SDN controller sends barrier requests to the affected switching nodes. Only after receiving flow table installation confirmations or barrier confirmations from all affected switching nodes does the policy canary deployment state machine allow the process to transition from the verification passed state to the canary deployment state. It cannot proceed solely based on a unilateral timeout judgment by the SDN controller or confirmations from some nodes. For example, the complete state transition of the policy canary deployment state machine can be illustrated as follows: Figure 5 As shown, it covers the normal path from pending verification to full implementation, as well as the processing path of abnormal rollback and manual review after triggering rollback conditions at any stage, and marks the constraints of each key state transition.
[0054] S260. Obtain initial ship network traffic through the entry classifier according to preset grayscale selection conditions, and generate target ship network traffic based on the initial ship network traffic and the candidate version metadata.
[0055] After entering the grayscale distribution state, the ingress classifier writes the initial ship network traffic that meets the set grayscale selection conditions into the metadata, guiding it to hit the candidate version flow table to generate the target ship network traffic.
[0056] The grayscale selection criteria may include one or more of the following: tenant identifier, service level, source address range, destination asset, application protocol, session hash, risk label, or service function chain path identifier.
[0057] S270. Send the target ship network traffic to the influence switching node to enable the candidate defense strategy to take effect.
[0058] Finally, the target vessel network traffic written to the metadata is sent to the affected switching nodes or all switching nodes, where they perform specific security processing to ensure the candidate defense strategy takes effect. It should be noted that vessel network traffic not written to the metadata continues to match the flow table of the current stable policy. For services requiring session state maintenance, the ingress classifier binds the session hash to the metadata writing rule, ensuring that the same session consistently matches the same policy within the gray-scale observation window, thus preventing inconsistencies in VNF detection status due to policy version switching.
[0059] The technical solution of this invention involves obtaining the affected exchange nodes corresponding to the differential flow table change set, and pre-installing the differential flow table change set, candidate version flow table identifier, and candidate service function chain mapping on the affected exchange nodes; sending a barrier request to the affected exchange nodes, and entering a gray-scale distribution state upon receiving confirmation information from all affected exchange nodes; obtaining initial ship network traffic through an ingress classifier based on preset gray-scale selection conditions, and generating target ship network traffic based on the initial ship network traffic and candidate version metadata; sending the target ship network traffic to the affected exchange nodes to enable the candidate defense strategy to take effect; by entering the gray-scale distribution state upon receiving confirmation information from all affected exchange nodes, the consistency of flow tables of all affected exchange nodes can be guaranteed; by generating target ship network traffic containing candidate version metadata and sending it to the affected exchange nodes, the parallel operation of the current stable strategy and the candidate defense strategy can be realized, the gray-scale distribution of the candidate defense strategy can be achieved, and the reliability of the ship network can be improved.
[0060] Optionally, after sending the target vessel network traffic to the influence switching node to activate the candidate defense strategy, the process may further include: Acquire each grayscale operation indicator, and when it is determined that the preset rollback trigger condition is met according to each grayscale operation indicator, prohibit the ingress classifier from writing the candidate version metadata to the ship network traffic, and roll back to the current stable policy; Obtain the candidate version flow table identifier mask corresponding to the candidate policy version, generate a candidate version cleanup instruction based on the candidate version flow table identifier and the candidate version flow table identifier mask, and send the candidate version cleanup instruction to the affected exchange node so that the affected exchange node performs the candidate version cleanup operation.
[0061] In this embodiment, during the canary rollout or full rollout process, various canary rollout operation metrics can be continuously monitored, such as false blocking rate, number of critical service flow interruptions, link latency, VNF health status, number of policy conflicts, number of attack flow misses, service chain integrity rate, flow table configuration confirmation status, and state machine timeout. If any canary rollout operation metric is detected to exceed its corresponding reasonable range, it is determined that the preset rollback trigger condition has been met. Then, the SDN controller stops allocating new sessions to candidate defense policies and disables canary classification rules written to metadata in the ingress classifier, thereby preventing the ingress classifier from writing metadata to the ship network traffic.
[0062] Then, the flow tables, SFC path identifiers, VNF order, tunnel mappings, and VNF security function node configurations corresponding to the current stable policy are restored to rollback to the current stable policy. Further, the candidate version flow table identifier mask (cookie_mask) corresponding to the candidate policy version is determined, and a candidate version cleanup instruction containing the cookie and cookie_mask is generated and sent to each affected exchange node. Upon receiving the candidate version cleanup instruction, the affected exchange nodes batch clean up the candidate version flow tables corresponding to the cookie and cookie_mask to complete the rollback operation. For example, the parallel isolation mechanism between the candidate version flow table and the stable version flow table, and the batch deletion process of the cookie_mask, can be implemented as follows: Figure 6 As shown, the version is identified by the high-order field of the cookie, and the cookie_mask is used to match and delete / invalidate all flow table entries of the same version in one operation, thus achieving O(1) level batch cleanup of candidate version flow tables.
[0063] Secondly, if it is determined that the preset rollback trigger condition is not met, the grayscale ratio is gradually increased until it is fully effective, that is, the candidate defense strategy is applied to all ship network traffic, so as to completely replace the current stable strategy with the candidate defense strategy.
[0064] The advantage of the above settings is that they enable efficient and accurate rollback operations, ensuring the stability of the ship network.
[0065] Optionally, after sending the candidate version cleanup instruction to the influence exchange node to cause the influence exchange node to perform the candidate version cleanup operation, the method may further include: Obtain rollback check results through critical business probe checks and service chain integrity checks; When it is determined that the rollback check result meets the preset rollback success conditions, the deployment process data corresponding to the candidate defense strategy is obtained, and an audit strategy version chain is generated based on the deployment process data.
[0066] In this embodiment, after the rollback operation is completed or the full rollback takes effect, critical business probe checks and service chain integrity checks can be performed. If the rollback check results determine that the ingress classifier, production flow table, SFC path, VNF configuration version, and session state remain consistent after the rollback, then the preset rollback success conditions are met. Next, deployment process data can be recorded, including but not limited to the verification results of candidate defense strategies, shadow flow table summaries, differential flow table change sets, barrier confirmation results, canary deployment process, full rollback results, rollback reasons, and recovery verification results. Based on the deployment process data and the preset report format, an audit strategy version chain is generated.
[0067] Among them, the critical business probe check is a proactive detection mechanism for the availability of core businesses. For example, the controller can schedule probe nodes to proactively construct probe packets from the business source to the target asset based on a preset list of critical businesses. The business status is judged by the response results and latency statistics of the receiving end. The service function chain integrity check is a compliance verification mechanism for secure forwarding paths. For example, probe packets carrying unique identifiers can be injected into the service chain ingress. Each time the packet passes through a VNF node, the node will record the path log or add a path mark. Then, the probe packets are collected at the service chain egress, and the actual sequence of VNF nodes they have passed through is extracted and compared with the preset standard SFC path to determine whether it is complete and ordered. At the same time, the flow table counters and traffic statistics of each node can be combined to help verify whether the traffic has flowed completely through the entire link.
[0068] For example, the complete interaction sequence of canary deployment and abnormal rollback can be as follows: Figure 7 As shown, the participants include the SDN controller, two SDN switching nodes, an ingress classifier, and a VNF node. The message interaction sequence between the components is illustrated in four stages: pre-installation, barrier confirmation, canary deployment, and exception rollback. The structure of the audit policy version chain can be shown as follows: Figure 8As shown, the top section uses versions V1 to V5 as examples to illustrate the parent version pointer, production strategy pointer, grayscale marker, rollback pointer in case of anomalies, and batch deletion operation of cookie_mask. The bottom section shows the complete field structure table of the version record, including the version number, parent version number, candidate strategy summary, validation_id, candidate version metadata, candidate version cookie, cookie_mask, differential flow table change set summary, shadow flow table summary, validation report summary, barrier confirmation summary, grayscale distribution report summary, execution node, timestamp, signature, rollback reason, and recovery validation result.
[0069] The advantage of the above settings is that they allow for accurate determination of whether a rollback operation was successful, providing a data foundation for subsequent audits.
[0070] In this embodiment, before the candidate defense strategy officially affects the network traffic of ordinary ships, a verification identifier is first bound to the candidate strategy, allowing it to enter the data plane or isolate the verification data plane for on-network stealth verification. After all affected switching nodes confirm the installation of the candidate path, the ingress classifier writes the candidate version metadata and gradually redirects traffic. If an anomaly occurs during the gray-scale or full-scale implementation, the candidate version flow table is invalidated in batches through the candidate version cookie_mask, and the VNF configuration version is restored in conjunction with this.
[0071] The technical solution of this invention extends candidate strategy verification from simple offline simulation to in-network stealth verification based on validation_id. Since the shadow flow table matching field carries metadata.validation_id, ordinary ship network traffic without this identifier will not hit shadow flow table entries. Verification traffic can hit candidate defense strategies under real ship network switches, real entry priorities, real metadata occupancy, and real SFC path constraints. Compared with an independent simulation environment, this method reduces verification bias caused by differences in simulation topology, entry status, and VNF operating status, and improves the correspondence between candidate strategy verification results and the data plane.
[0072] Secondly, this solution uses barrier confirmation as a prerequisite for the ingress classifier to write to the candidate version metadata, ensuring that the timing of canary traffic introduction aligns with the readiness status of the SFC data plane path. Only after all affected switching nodes have completed the installation of the candidate version flow table and candidate SFC path will the ingress classifier write to metadata.policy_version and import canary traffic into the candidate path, thereby reducing the risks of missing intermediate node entries, service chain breaks, and path inconsistencies caused by asynchronous SDN deployment.
[0073] Furthermore, this scheme utilizes `metadata.policy_version` to enable candidate version flow tables and stable version flow tables to run in parallel and in isolation within the same vessel network. The ingress classifier only writes candidate version metadata to vessel network traffic that meets the grayscale criteria; network traffic not written to this metadata continues to use the stable version flow table. Combined with a session hash-level grayscale maintenance mechanism, this avoids switching between different policy versions for the same session, reducing the probability of inconsistent VNF detection states.
[0074] Finally, regarding flow table cleanup, this solution utilizes the mask matching capability of cookie_mask to perform batch deletion or invalidation of candidate version flow tables. Compared to deleting candidate flow tables one by one, sending batch deletion matches based on candidate version cookie_mask reduces the number of cleanup operations per node. This cleanup action is executed synchronously with the VNF security feature node configuration version rollback, which helps to achieve consistent rollback across the flow table layer, entry classification layer, SFC path layer, and VNF configuration layer, avoiding inconsistencies such as "flow tables have been rolled back but VNF is still executing the new rules."
[0075] Example 3 Figure 9 This is a schematic diagram of a security service chain management device provided in Embodiment 3 of the present invention. Figure 9 As shown, the device includes a model building module 310, a flow table entry generation module 320, a policy verification module 330, and a flow table distribution module 340; wherein, The model building module 310 is used to build a digital twin model corresponding to the current stable strategy, and to obtain the candidate strategy version, candidate service function chain mapping and candidate flow table intent corresponding to the candidate defense strategy. The flow table entry generation module 320 is used to generate the verification identifier, candidate version metadata and candidate version flow table identifier corresponding to the candidate strategy version, and generate shadow flow table entries according to the candidate flow table intent; The policy verification module 330 is used to perform on-network pre-verification of candidate policies based on the shadow flow table entry, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification indicators; The flow table distribution module 340 is used to obtain a differential flow table change set according to the candidate defense strategy and the current stable strategy when the verification indicator meets the preset verification pass conditions, and to distribute the differential flow table change set in a gray-scale manner according to the preset strategy, the state machine, the candidate service function chain mapping, the candidate version metadata and the candidate version flow table identifier, so as to make the candidate defense strategy effective.
[0076] The technical solution of this invention establishes a digital twin model corresponding to the current stable strategy and obtains the candidate strategy version, candidate service function chain mapping, and candidate flow table intent corresponding to the candidate defense strategy; generates a verification identifier, candidate version metadata, and candidate version flow table identifier corresponding to the candidate strategy version, and generates shadow flow table entries based on the candidate flow table intent; performs on-network pre-verification of the candidate strategy based on the shadow flow table entries, candidate service function chain mapping, digital twin model, and verification identifier to obtain verification indicators; when the verification indicators meet the preset verification pass conditions, obtains the differential flow table change set based on the candidate defense strategy and the current stable strategy, and distributes the changes according to the preset strategy gray-scale distribution status. The system uses a combination of methods, including canary distribution of the differential flow table change set, candidate service function chain mapping, candidate version metadata, and candidate version flow table identifier, to enable candidate defense strategies to take effect. By setting verification identifiers, candidate version metadata, and candidate version flow table identifiers, and performing on-network pre-verification based on shadow flow table entries, candidate service function chain mappings, digital twin models, and verification identifiers before the official distribution of candidate defense strategies, the impact of abnormal security strategies on the actual business of the ship network can be avoided, thus improving the reliability of the ship network. Furthermore, by canary distribution of the differential flow table change set after successful pre-verification, the amount of data transmission can be reduced, improving the efficiency of security policy updates.
[0077] Optionally, the model building module 310 is specifically used to acquire the state data of the ship network and, based on the state data, build a digital twin model corresponding to the current stabilization strategy. The digital twin model includes at least one of the following: an asset node set, a business path set, an entry classifier set, an exchange node set, a security function node set, a production flow table and a candidate flow table set, a service function chain sequence set, a session state set, a policy version set, a protocol field mapping set, a risk indicator set, and an audit record set.
[0078] Optionally, the policy verification module 330 is specifically used to obtain initial verification traffic and generate target verification traffic based on the initial verification traffic and the verification identifier; Candidate strategies are pre-validated on the network based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the target verification traffic to obtain verification indicators; The matching field of the shadow flow table entry includes the verification identifier.
[0079] Optionally, the flow table distribution module 340 includes: The entry acquisition unit is used to standardize the candidate defense strategy and the current stable strategy respectively to obtain candidate flow table tuples and stable flow table tuples, and to perform primary key comparison between the candidate flow table tuples and the stable flow table tuples to obtain new flow table entries, modified flow table entries and deleted flow table entries; The change set generation unit is used to generate the differential flow table change set based on the newly added flow table entry, the modified flow table entry, and the deleted flow table entry.
[0080] Optionally, the flow table distribution module 340 also includes: The node acquisition unit is used to acquire the impact exchange node corresponding to the differential flow table change set, and pre-install the differential flow table change set, the candidate version flow table identifier and the candidate service function chain mapping on the impact exchange node; The request sending unit is used to send a barrier request to the affected exchange nodes, and enter the gray-scale distribution state when it receives confirmation information from all the affected exchange nodes; The traffic generation unit is used to obtain the initial ship network traffic through the ingress classifier according to the preset grayscale selection conditions, and to generate the target ship network traffic according to the initial ship network traffic and the candidate version metadata. A traffic transmission unit is used to send the target ship network traffic to the influence switching node so that the candidate defense strategy can take effect.
[0081] Optionally, the management device for the secure service chain also includes: The write prohibition module is used to obtain various gray-scale operation indicators, and when it is determined that the preset rollback trigger condition is met according to each gray-scale operation indicator, it prohibits the ingress classifier from writing the candidate version metadata to the ship network traffic and rolls back to the current stable policy. The instruction generation module is used to obtain the candidate version flow table identifier mask corresponding to the candidate policy version, generate a candidate version cleanup instruction based on the candidate version flow table identifier and the candidate version flow table identifier mask, and send the candidate version cleanup instruction to the affected exchange node so that the affected exchange node performs the candidate version cleanup operation.
[0082] Optionally, the management device for the secure service chain also includes: The inspection execution module is used to obtain rollback inspection results through key business probe inspection and service chain integrity inspection; The strategy version chain acquisition module is used to acquire the deployment process data corresponding to the candidate defense strategy when it is determined that the rollback check result meets the preset rollback success conditions, and generate an audit strategy version chain based on the deployment process data.
[0083] The security service chain management device provided in this embodiment of the invention can execute the security service chain management method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0084] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0085] Example 4 Figure 10 A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device 40 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device 40 can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0086] like Figure 10 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the read-only memory 42 or loaded from the storage unit 48 into the random access memory 43. The RAM 43 can also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0087] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0088] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, central processing units, graphics processing units, various special-purpose artificial intelligence computing chips, various processors running machine learning model algorithms, digital signal processors, and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as the management methods of secure service chains.
[0089] In some embodiments, the secure service chain management method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the secure service chain management method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the secure service chain management method by any other suitable means (e.g., by means of firmware).
[0090] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays, application-specific integrated circuits (ASICs), application-specific standard products (ASICs), system-on-a-chip (SoCs), complex programmable logic devices, computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0091] Computer programs used to implement the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs can be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0092] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory, optical fibers, portable compact disk read-only memory, optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0093] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device 40, which includes: a display device (e.g., a cathode ray tube or liquid crystal display) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device 40. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0094] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0095] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact via a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server.
[0096] This embodiment may also include a computer program product, which includes a computer program that, when executed by a processor, implements the security service chain management method provided in any embodiment of the present invention.
[0097] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0098] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for managing a secure service chain, characterized in that, include: Establish a digital twin model corresponding to the current stable strategy, and obtain the candidate strategy version, candidate service function chain mapping and candidate flow table intent corresponding to the candidate defense strategy; Generate the verification identifier, candidate version metadata, and candidate version flow table identifier corresponding to the candidate policy version, and generate shadow flow table entries according to the candidate flow table intent; Candidate strategies are pre-verified on-network based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification indicators; When the verification indicator meets the preset verification pass conditions, the differential flow table change set is obtained according to the candidate defense strategy and the current stable strategy. The differential flow table change set is then distributed in a gray-scale manner according to the preset strategy, the state machine, the candidate service function chain mapping, the candidate version metadata, and the candidate version flow table identifier, so that the candidate defense strategy takes effect.
2. The method according to claim 1, characterized in that, Establish a digital twin model corresponding to the current stable strategy, including: Acquire the status data of the ship network, and based on the status data, establish a digital twin model corresponding to the current stabilization strategy; The digital twin model includes at least one of the following: an asset node set, a business path set, an entry classifier set, an exchange node set, a security function node set, a production flow table and a candidate flow table set, a service function chain sequence set, a session state set, a policy version set, a protocol field mapping set, a risk indicator set, and an audit record set.
3. The method according to claim 1, characterized in that, Candidate strategies are pre-validated online based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the verification identifier to obtain verification metrics, including: Obtain initial verification traffic, and generate target verification traffic based on the initial verification traffic and the verification identifier; Candidate strategies are pre-validated on the network based on the shadow flow table entries, the candidate service function chain mapping, the digital twin model, and the target verification traffic to obtain verification indicators; The matching field of the shadow flow table entry includes the verification identifier.
4. The method according to claim 1, characterized in that, Based on the candidate defense strategy and the current stable strategy, obtain the differential flow table change set, including: The candidate defense strategy and the current stable strategy are standardized to obtain candidate flow table tuples and stable flow table tuples. The candidate flow table tuples and stable flow table tuples are then compared by primary key to obtain newly added flow table entries, modified flow table entries, and deleted flow table entries. The differential flow table change set is generated based on the newly added flow table entry, the modified flow table entry, and the deleted flow table entry.
5. The method according to claim 1, characterized in that, Based on the preset strategy of canary deployment of the state machine, the candidate service function chain mapping, the candidate version metadata, and the candidate version flow table identifier, the differential flow table change set is canary deployed to enable the candidate defense strategy to take effect, including: Obtain the impact exchange node corresponding to the differential flow table change set, and pre-install the differential flow table change set, the candidate version flow table identifier, and the candidate service function chain mapping on the impact exchange node; Send a barrier request to the affected exchange nodes, and enter the gray-scale distribution state upon receiving confirmation information from all the affected exchange nodes; The initial ship network traffic is obtained by the ingress classifier according to the preset grayscale selection conditions, and the target ship network traffic is generated according to the initial ship network traffic and the candidate version metadata. The target vessel's network traffic is sent to the influence switching node to activate the candidate defense strategy.
6. The method according to claim 5, characterized in that, After sending the target vessel network traffic to the influencing switching node to activate the candidate defense strategy, the process further includes: Acquire each grayscale operation indicator, and when it is determined that the preset rollback trigger condition is met according to each grayscale operation indicator, prohibit the ingress classifier from writing the candidate version metadata to the ship network traffic, and roll back to the current stable policy; Obtain the candidate version flow table identifier mask corresponding to the candidate policy version, generate a candidate version cleanup instruction based on the candidate version flow table identifier and the candidate version flow table identifier mask, and send the candidate version cleanup instruction to the affected exchange node so that the affected exchange node performs the candidate version cleanup operation.
7. The method according to claim 6, characterized in that, After sending the candidate version cleanup instruction to the impact exchange node, causing the impact exchange node to perform the candidate version cleanup operation, the method further includes: Obtain rollback check results through critical business probe checks and service chain integrity checks; When it is determined that the rollback check result meets the preset rollback success conditions, the deployment process data corresponding to the candidate defense strategy is obtained, and an audit strategy version chain is generated based on the deployment process data.
8. An electronic device, characterized in that, The electronic device includes: At least one processor, and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor to enable the at least one processor to perform the management method of the secure service chain according to any one of claims 1-7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the management method of the secure service chain according to any one of claims 1-7.
10. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the management method of the secure service chain according to any one of claims 1-7.