Communication processing method and apparatus, and device, system and readable storage medium
Patent Information
- Application Number
- PCT/CN2023/137950
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-12-12
- Filing Date
- 2023-12-11
- Publication Date
- 2025-06-12
AI Technical Summary
In the existing technology, virtualized network element manufacturers each deploy micro-isolation systems, resulting in complex operation and maintenance, conflicting security policies, difficulty in monitoring and managing traffic between virtual machines and containers, and increased operation and maintenance costs.
By building an agent unit into the virtualized network element, traffic information is collected and reported to the micro-isolation management center to analyze and generate security policies. This avoids the installation of third-party agents and the deployment of multiple micro-isolation management platforms, and realizes the control of virtualized networks. Real-time monitoring of intra-unit traffic and update of security policies.
It simplifies the operation and maintenance process, reduces operation and maintenance costs, improves security policy coordination and overall traffic monitoring capabilities between virtualized network elements, and reduces the delayed discovery time of security events.
Smart Images

Figure CN2023137950_12062025_PF_FP_ABST
Abstract
Description
Communication processing method, device, equipment, system and readable storage medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This application is based on the Chinese patent application with application number 202211596896.5 and application date of December 12, 2022, and claims the priority of the Chinese patent application. The entire content of the Chinese patent application is hereby introduced into this application as a reference. Technical Field
[0003] The embodiments of the present application relate to the field of communication technology, and specifically to a communication processing method, apparatus, device, system, and readable storage medium. Background Art
[0004] One of the existing technologies for honeycomb adaptive micro-isolation is a host agent solution, which is used in public and private clouds and can collect traffic information of virtual machines and containers. Since traditional communication technology (CT) manufacturers provide virtualized network elements, and the operating system (guest OS) of virtualized network elements has a certain degree of privacy, virtualized network element manufacturers are reluctant to install third-party manufacturers' agents in their own virtualized network elements. The agent needs to monitor traffic and ports and be able to block them through access control lists (ACLs), so it needs to obtain root permissions. There is a risk that normal processes will be tampered with by the host agent or the host belt will be compromised, affecting all network elements. In addition, after the agent is installed, once a problem occurs with the virtualized network element, there will be a problem with multiple manufacturers, making it difficult to locate and determine the responsibility for the security issue.
[0005] As shown in Figure 1, currently each network element manufacturer only supports the management of its own network elements. The way each manufacturer deploys micro-segmentation agents and management platforms separately will result in each network element manufacturer deploying a micro-segmentation management platform in a network cloud resource pool to monitor and manage the traffic and ports of its own network elements, which may lead to security policy conflicts. Therefore, a first-level micro-segmentation management platform is required to manage and coordinate the traffic monitoring and management of each manufacturer's micro-segmentation platform, draw an overall traffic and port view of the network elements in the entire resource pool, and coordinate the security policy of the entire network, making the solution complex and the operation and maintenance cost high.
[0006] Summary of the Invention
[0007] The embodiments of the present application aim to provide a communication processing method, apparatus, device, system and readable storage medium to solve the problem of complex operation and maintenance caused by each virtualized network element manufacturer providing a micro-isolation system.
[0008] In a first aspect, a communication processing method is provided, applied to a first device, including:
[0009] Obtaining first flow information reported by at least one first unit within the VNF;
[0010] According to the first traffic information reported by the at least one first unit, at least one of the following is executed: updating a security policy, generating a handling policy, and generating alarm information.
[0011] Optionally, the method further includes:
[0012] Obtaining second flow information reported by the at least one first unit;
[0013] generating a security policy and / or network topology information based on at least one of the second flow information, the flow and / or the port access whitelist;
[0014] The security policy is sent to the first unit.
[0015] Optionally, obtaining first traffic information reported by at least one first unit within the VNF includes:
[0016] Obtain at least one first flow information reported by one or more first units within the VNF and forwarded by the second device;
[0017] and / or,
[0018] The sending the security policy to the first unit includes:
[0019] The security policy is forwarded through the second device and sent to the first unit.
[0020] Optionally, performing at least one of the following according to the first traffic information reported by the at least one first unit: updating a security policy, generating a handling policy, and generating alarm information includes:
[0021] Based on the first traffic information, it is determined that the abnormal traffic and / or abnormal port is caused by an attack, a handling strategy and / or alarm information is generated, and the handling strategy / or alarm information is sent to the first unit through the second device.
[0022] Optionally, the method further includes:
[0023] Obtain at least one of network topology information, expansion information, reduction information, and migration information sent by the second device;
[0024] The step of performing at least one of the following steps based on the first traffic information reported by the at least one first unit: updating a security policy, generating a handling policy, and generating alarm information includes:
[0025] determining, based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, whether the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration, updating the security policy, and issuing the updated security policy to the first unit via the second device;
[0026] or,
[0027] Based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, determine whether the abnormal traffic and / or abnormal port is caused by an attack, generate a disposal strategy and / or alarm information, and send the disposal strategy and / or alarm information to the first unit through the second device.
[0028] Optionally, the method further includes:
[0029] A first subscription request is sent to the second device, where the first subscription request is used to request subscription to at least one of an access whitelist of traffic and / or ports, network topology information, expansion information, reduction information, and migration information.
[0030] Optionally, the method further includes:
[0031] A second subscription request sent by a second device is received, where the second subscription request is used to request subscription to at least one of a security policy, a handling policy, and alarm information.
[0032] Optionally, the method further includes:
[0033] The alarm information is sent to a third device, where the third device is at least one of a situational awareness platform, a traffic monitoring system, and an advanced persistent threat (APT) protection system.
[0034] In a second aspect, a communication processing method is provided, which is applied to a second device, including:
[0035] Obtaining first flow information reported by at least one first unit within the VNF;
[0036] The first flow information reported by the at least one first unit is sent to the first device, and the at least one first flow information is used by the first device to execute at least one of the following: updating a security policy, generating a disposal policy, and generating alarm information.
[0037] Optionally, the method further includes:
[0038] Obtaining second flow information reported by the at least one first unit;
[0039] Sending the second flow information reported by the at least one first unit to the first device, where the at least one second flow information is used by the first device to generate a security policy and / or network topology information;
[0040] Acquire the security policy sent by the first device, and send the security policy to the first unit.
[0041] Optionally, the method further includes:
[0042] Obtaining a handling strategy and / or alarm information sent by the first device, where the handling strategy and / or alarm information is generated by the first device when it determines, based on the first traffic information, that the abnormal traffic and / or abnormal port is caused by an attack;
[0043] The handling strategy and / or alarm information are sent to the first unit.
[0044] Optionally, the method further includes:
[0045] Obtaining an updated security policy sent by the first device, where the updated security policy is generated when the first device determines, based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration;
[0046] sending the updated security policy to the first unit;
[0047] or,
[0048] Obtaining a handling strategy and / or alarm information sent by the first device, where the handling strategy and / or alarm information is generated when the first device determines, based on at least one of the first traffic information, network topology information, capacity expansion information, capacity reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by an attack;
[0049] The handling strategy and / or alarm information is sent to the first unit.
[0050] Optionally, the method further includes:
[0051] Receive a first subscription request sent by the first device, where the first subscription request is used to request subscription to at least one of an access whitelist of traffic and / or ports, network topology information, expansion information, reduction information, and migration information.
[0052] Optionally, the method further includes:
[0053] A second subscription request is sent to the first device, requesting to subscribe to at least one of a security policy, a handling policy, and alarm information.
[0054] According to a third aspect, a communication processing apparatus is provided, applied to a first device, including:
[0055] A first acquisition module is configured to acquire first flow information reported by at least one first unit within the VNF;
[0056] The execution module is used to execute at least one of the following according to the first traffic information reported by the at least one first unit: updating the security policy, generating a disposal policy, and generating alarm information.
[0057] In a fourth aspect, a communication processing apparatus is provided, applied to a second device, including:
[0058] a fourth acquisition module, configured to acquire first flow information reported by at least one first unit within the VNF;
[0059] The fourth sending module is used to send the first flow information reported by the at least one first unit to the first device, and the at least one first flow information is used by the first device to execute at least one of the following: updating security policy, generating disposal policy, and generating alarm information.
[0060] In a fifth aspect, a communication device is provided, comprising a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the method described in the first aspect or the second aspect.
[0061] In a sixth aspect, a readable storage medium is provided, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect or the second aspect are implemented.
[0062] In an embodiment of the present application, the first device can obtain the first flow information reported by at least one first unit located in the VNF; based on the first flow information reported by the at least one first unit, execute at least one of the following contents: update the security policy, generate the disposal policy, and generate the alarm information, thereby avoiding the problem of complex operation and maintenance caused by each virtualization network element manufacturer providing a micro-isolation system, simplifying operation and maintenance, and reducing procurement costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Various other advantages and benefits will become apparent to those skilled in the art upon reading the detailed description of the preferred embodiment below. The accompanying drawings are for illustration purposes only and are not to be considered as limiting the present application. The same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0064] Figure 1 is a schematic diagram of how each vendor deploys their micro-isolation system;
[0065] FIG2 is a schematic diagram of a communication processing method according to an embodiment of the present application;
[0066] FIG3 is a second schematic diagram of a communication processing method provided in an embodiment of the present application;
[0067] FIG4 is a third schematic diagram of the communication processing method provided in an embodiment of the present application;
[0068] FIG5 is a schematic diagram of a micro-isolation framework with inherent security provided by an embodiment of the present application;
[0069] FIG6 is a flowchart of security policy generation and security monitoring provided by an embodiment of the present application;
[0070] 7 is a flowchart of security policy update when expanding or shrinking capacity according to an embodiment of the present application;
[0071] FIG8 is a schematic diagram of a communication processing device according to an embodiment of the present application;
[0072] FIG9 is a second schematic diagram of a communication processing device provided in an embodiment of the present application;
[0073] FIG10 is a schematic diagram of a communication device provided in an embodiment of the present application;
[0074] FIG11 is a framework diagram of the micro-isolation solution provided in an embodiment of the present application. DETAILED DESCRIPTION
[0075] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0076] The term "comprise" and any variations thereof in the specification and claims of this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such process, method, product, or apparatus. In addition, the use of "and / or" in the specification and claims to indicate at least one of the connected objects, such as A and / or B, means that A alone, B alone, and both A and B are included.
[0077] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0078] With the deep integration of Internet technology (IT) and communication technology (CT), carrier networks are now adopting cloud-based deployment. The virtualized network functions of the fifth-generation core network (5GC) are deployed on general-purpose servers and virtual layers, enabling on-demand provisioning, expansion, and reduction of virtualized network functions. Virtualization and cloudification enable rapid network deployment, improving network flexibility and operational efficiency. To further enhance resource utilization, carriers generally build telecom clouds using centralized resource pools to improve resource utilization and operational efficiency. This resource pool includes various virtualized network elements from multiple provinces, such as the virtualized Call Session Control Function (CSCF) of the IP Multimedia Subsystem (IMS) network in Province A, the Access and Mobility Management Function (AMF) and Session Management Function (SMF) of the 5G network, and the virtualized PDN Gateway (PGW) and virtualized AMF in Province B. Because virtualized network elements (NEs) within a resource pool are typically provided by the same vendor, and their operating systems are typically based on open-source operating systems, the guest operating systems (OSs) of these virtual machines are highly homogeneous. This makes it easy to launch lateral attacks within the resource pool if a single NE is compromised. For example, if a worm infects a NE, it can quickly spread across the resource pool. Firewalls deployed at data center egresses, designed to primarily detect north-south traffic attacks, struggle to detect east-west traffic attacks in a timely manner, nor can they quickly locate the attack source and take action.
[0079] Traditional public clouds also face east-west attacks within data centers, such as cross-tenant attacks. To achieve east-west isolation in data centers, the industry has proposed micro-segmentation solutions. These solutions are mainly classified into the following categories:
[0080] (1) Independent physical security devices: By deploying physical security devices, such as firewalls, at the boundaries of security domains, different security domains can be isolated. This will lead to the deployment of a large number of physical security devices. In addition, the network of the data center is dynamic and has no fixed physical boundaries. Therefore, statically deployed physical security devices will lead to a large amount of traffic diversion and security policy configuration work.
[0081] (2) Host Agent: Install agent software on each virtual machine to inspect traffic entering and leaving the virtual machine, as well as the applications and content within the virtual machine. This method is dependent on the virtual machine operating system. When the virtual machine guest OS and the agent are from different manufacturers, compatibility must be maintained.
[0082] (3) Virtual switch: Virtual local area networks (VLANs) are divided on the virtual switch in the virtualization layer and / or ACLs are set through security groups. This method requires high performance from the virtual switch. In addition, in the NIC pass-through mode (such as using SR-IOV (Single Root I / O Virtualization) technology), the traffic of the virtual machine does not pass through the virtual switch in the virtualization layer, which makes some traffic unmonitorable.
[0083] (4) Traffic diversion: divert the traffic of the virtual machine that needs to be protected to a security virtual machine or physical security device that is specialized for security analysis. This method does not rely on the virtual environment and requires a traffic diversion mechanism. When the network scale is large, traffic diversion will affect the performance of switches and controllers. The convergence of all traffic to the security virtual machine will also make the security virtual machine performance a bottleneck.
[0084] Related technologies propose using a micro-segmented security management platform to subscribe network element topology and log information to an operations and maintenance center (OMC) and a log server, respectively. The micro-segmented security management platform then analyzes and learns from the network element topology and log information, generating a baseline for network connectivity and port availability, and monitoring east-west traffic based on the baseline. This solution introduces a separate micro-segmented security management platform to connect to the OMC and log server, eliminating the need for agent installation. However, this approach can lead to delayed security monitoring due to the OMC and log server not reporting network topology and logs in a timely manner. Furthermore, when network elements are deployed using virtual machine containers, the containers are not publicly visible, so the OMC cannot obtain the topology of the containers within the VM. Consequently, it cannot monitor traffic between pods (the smallest unit of Kubernetes scheduling, consisting of one or more containers) within the VM. Although pods within a VM belong to a single virtualized network element, any attacks between pods within the VM will ultimately manifest themselves on the VM itself. However, this delays the discovery of security incidents, potentially impacting normal business operations.
[0085] Referring to Figure 2, an embodiment of the present application provides a communication processing method, which is applied to a first device. The first device may include but is not limited to: a management data analysis function (MDAF), a network data analysis function (NWDAF), a management data analysis function (MDAF), a micro-isolation management center, and at least one of a micro-isolation management platform. The specific steps include: step 201 and step 202.
[0086] Step 201: Obtain first traffic information reported by at least one first unit within a virtualized network function (VNF);
[0087] In this embodiment, there is no limit on the number of first units within the VNF, nor is there a limit on the amount of first traffic information reported by each first unit.
[0088] The above-mentioned VNF can be a VNF from different manufacturers, and the above-mentioned first unit can also be called a traffic information reporting unit. The first unit can include a micro-isolation execution unit and at least one of the agents. See Figure 5. The first unit can include an agent in the vNEF in the network element of manufacturer A, an agent in the vAMF, and an agent in the vSMF, as well as an agent in the vNEF, an agent in the vAMF, and an agent in the vSMF in the network element of manufacturer B.
[0089] Optionally, obtaining the first flow information reported by at least one first unit within the VNF includes one of the following:
[0090] Method 1: obtaining at least one first flow information directly reported by one or more first units within the VNF;
[0091] Method 2: Obtain at least one first flow information reported by one or more first units located in the VNF and forwarded by the second device.
[0092] That is, the reporting in step 201 may be that several first units report the first flow information directly to the first device, or may be that several first units forward the first flow information to the first device through the second device.
[0093] Optionally, the virtual machine or container of the virtualized network element has a built-in first unit, which captures the first flow information of the virtual machine or container group (pod) and reports it to the second device. The second device aggregates the first flow information reported by one or more first units, and then reports the aggregated first flow information to the first device non-periodically or periodically.
[0094] Optionally, using the first unit as an agent, the virtualized network element manufacturer can provide an agent built into the virtualized network element. This can better optimize the agent's CPU and memory usage, thereby optimizing virtualized network element performance and avoiding the workload of interfacing with third-party agents, as well as the difficulty of locating and assigning responsibility after problems arise. This agent can be embedded in the virtualized network element's image or instantiation parameters and installed when the virtualized network element is instantiated. Compared to third-party agents, which require batch installation using tools after the network element is instantiated, the NE's built-in agent instantiation is more efficient.
[0095] The above-mentioned first traffic information is the traffic information obtained when determining whether there is abnormal traffic and / or abnormal port (i.e., the security monitoring stage). The first traffic information includes: at least one of the virtualization network element name, virtual machine name, pod name, five-tuple (for example, source / destination IP, source / destination port, protocol), etc.
[0096] Step 202: Execute at least one of the following actions based on the first traffic information reported by the at least one first unit: update a security policy, generate a handling policy, and generate alarm information.
[0097] The above security policy may include an access whitelist of traffic and / or ports, and updating the security policy includes updating the access whitelist of traffic and / or ports.
[0098] For example, the first device analyzes the first traffic information and monitors whether there is abnormal traffic and / or ports in combination with the machine learning model of the previous traffic and / or port whitelist generation stage.
[0099] Optionally, the whitelist of traffic and / or ports may include at least one of: a virtualized network element name, a pod name, a virtual machine name, a source / destination IP address allowed for communication, a source / destination port, a protocol, etc.
[0100] In one embodiment of the present application, the method also includes: obtaining second traffic information reported by the at least one first unit; generating security policy and / or network topology information based on at least one of the second traffic information, traffic and / or port access whitelist; and sending the security policy to the first unit.
[0101] Optionally, the second traffic information includes at least one of a virtualized network element name, a virtual machine name, a pod name, a five-tuple (such as source / destination IP, source / destination port, protocol), etc.
[0102] In this embodiment, the first device sending the security policy to the first unit includes one of the following:
[0103] Method 1: The first device directly sends the security policy to the first unit;
[0104] Method 2: The first device forwards the security policy through the second device and sends it to the first unit.
[0105] In one embodiment of the present application, performing at least one of the following based on the first traffic information reported by the at least one first unit: updating a security policy, generating a handling policy, and generating alarm information includes:
[0106] Based on the first traffic information, it is determined that the abnormal traffic and / or abnormal port is caused by an attack, a handling strategy and / or alarm information is generated, and the handling strategy is sent to the first unit through the second device.
[0107] Optionally, the second device may be an operation and maintenance center (OMC).
[0108] When the second device is an OMC, the above solution expands the management data analysis function defined by the existing 3rd Generation Partnership Project (3GPP) and the interface between the OMC and the data analysis function to realize a micro-isolation management center connecting to multiple micro-isolation execution units provided by different manufacturers. The micro-isolation management center is decoupled from the micro-isolation execution unit, making the implementation more flexible.
[0109] In one embodiment of the present application, the method further includes:
[0110] Obtain at least one of network topology information, expansion information, reduction information, and migration information;
[0111] The step of performing at least one of the following steps based on the first traffic information reported by the at least one first unit: updating a security policy, generating a handling policy, and generating alarm information includes:
[0112] Mode 1: Based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, determining whether the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration, updating the security policy, and issuing the updated security policy to the first unit via the second device;
[0113] Method 2: Based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, determine whether the abnormal traffic and / or abnormal port is caused by an attack, generate a handling strategy and / or alarm information, and send the handling strategy and / or alarm information to the first unit through the second device
[0114] For example, there is a new virtual machine name or virtual machine pod, and traffic is sent, or a new open port is added, but the expansion notification of the second device is not received, and the local network topology has not changed. The first device can give a disposal strategy based on the security policy library (such as closing abnormal ports, discarding all traffic with source and destination IP of xx.xx.xx.xx, etc.) and generate an alarm message.
[0115] Optionally, the expansion information, contraction information, and migration information can be VNF expansion information, contraction information, and migration information, such as the expansion information, contraction information, and migration information of a VNF VM or pod. Each VM is configured with a first unit. If a VM includes multiple pods, each pod is configured with a first unit. Each first unit reports the expansion information, contraction information, and migration information to the second device, which then sends it to the first device as needed.
[0116] In one embodiment of the present application, the method further includes:
[0117] A first subscription request is sent to the second device, requesting to subscribe to at least one of a traffic and / or port access whitelist, network topology information, expansion information, reduction information, and migration information.
[0118] In one embodiment of the present application, the method further includes:
[0119] A second subscription request sent by the second device is received, for requesting to subscribe to at least one of the security policy, the handling policy, and the alarm information.
[0120] In one embodiment of the present application, the method further includes:
[0121] The alarm information is sent to a third device, where the third device is at least one of a situational awareness platform, a traffic monitoring system, and an advanced persistent threat (APT) protection system.
[0122] In an embodiment of the present application, the first device can obtain the first flow information reported by at least one first unit located in the VNF; based on the first flow information reported by the at least one first unit, execute at least one of the following contents: update the security policy, generate the disposal policy, and generate the alarm information, thereby avoiding the problem of complex operation and maintenance caused by each virtualization network element manufacturer providing a micro-isolation system, simplifying operation and maintenance, and reducing procurement costs.
[0123] 3 , an embodiment of the present application provides a communication processing method, which is applied to a second device, including but not limited to an OMC. The specific steps include: step 301 and step 302 .
[0124] Step 301: Obtain first traffic information reported by at least one first unit within the VNF;
[0125] In this embodiment, there is no limit on the number of first units within the VNF, nor is there a limit on the amount of first traffic information reported by each first unit.
[0126] Step 302: Send the first flow information reported by the at least one first unit to the first device, and the at least one first flow information is used by the first device to execute at least one of the following: update the security policy, generate a disposal policy, and generate alarm information.
[0127] In one embodiment of the present application, the method further includes:
[0128] Obtaining second flow information reported by the at least one first unit;
[0129] Sending the second flow information reported by the at least one first unit to the first device, where the at least one second flow information is used by the first device to generate a security policy and / or network topology information;
[0130] Acquire the security policy sent by the first device, and send the security policy to the first unit.
[0131] In one embodiment of the present application, the method further includes:
[0132] Obtaining a handling strategy and / or alarm information sent by the first device, where the handling strategy and / or alarm information is generated by the first device when it determines, based on the first traffic information, that the abnormal traffic and / or abnormal port is caused by an attack;
[0133] The handling strategy and / or alarm information are sent to the first unit.
[0134] In one embodiment of the present application, the method further includes:
[0135] Obtaining an updated security policy sent by the first device, where the updated security policy is generated when the first device determines, based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration;
[0136] sending the updated security policy to the first unit;
[0137] or,
[0138] Obtaining a handling strategy and / or alarm information sent by the first device, where the handling strategy and / or alarm information is generated when the first device determines, based on at least one of the first traffic information, network topology information, capacity expansion information, capacity reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by an attack;
[0139] The handling strategy and / or alarm information is sent to the first unit.
[0140] In one embodiment of the present application, the method further includes:
[0141] Receive a first subscription request sent by the first device, where the first subscription request is used to request subscription to at least one of an access whitelist of traffic and / or ports, network topology information, expansion information, reduction information, and migration information.
[0142] In one embodiment of the present application, the method further includes:
[0143] A second subscription request is sent to the first device, requesting to subscribe to at least one of a security policy, a handling policy, and alarm information.
[0144] In an embodiment of the present application, the first device can obtain the first flow information reported by at least one first unit located in the VNF; based on the first flow information reported by the at least one first unit, execute at least one of the following contents: update the security policy, generate the disposal policy, and generate the alarm information, thereby avoiding the problem of complex operation and maintenance caused by each virtualization network element manufacturer providing a micro-isolation system, simplifying operation and maintenance, and reducing procurement costs.
[0145] Referring to Figure 4, the specific steps include:
[0146] Step 401: At least one first unit reports first flow information to a second device;
[0147] Step 402: The second device reports at least one first flow information to the first device;
[0148] Step 403: Based on the first traffic information reported by the at least one first unit, the first device performs at least one of the following: updating a security policy, generating a handling policy, and generating alarm information;
[0149] Step 404: The first device sends at least one of the updated security policy, handling policy, and alarm information to the second device;
[0150] Step 405: The second device sends at least one of the updated security policy, handling policy, and alarm information to at least one first unit.
[0151] It can be understood that, for the same contents in the embodiment shown in FIG. 4 as those in the embodiments shown in FIG. 2 and FIG. 3 , reference can be made to the embodiments shown in FIG. 2 and FIG. 3 , and no further description is given here.
[0152] In this application, based on the micro-isolation mechanism of intrinsic security, there is no need to install a third-party agent in the network element, nor is there a need to deploy micro-isolation management platforms of multiple network element manufacturers. Traffic information is collected through the first unit (for example, the agent built into each virtualized network element) and reported to the micro-isolation management center (for example, NWDAF). The micro-isolation management center can analyze, learn and / or perform security monitoring on the traffic information reported by the first unit, provide disposal recommendations and / or alarm information for security incidents, perceive the expansion or reduction of virtualized network elements, and update the access whitelist of traffic and / or ports.
[0153] Take the example of a first network element including an agent for a vendor's virtualized network element. As shown in Figure 5, each vendor's own agent is installed in the virtual machine or container of the virtualized network element. The agent periodically collects the second flow information of the virtual machine or container and reports the second flow information to the second device, which then sends the second flow information and other information to the first device. The first device analyzes the second flow information, identifies the flow connection status and / or port open status of the virtual network element, and generates security policies and / or network topology information based on the flow connection status and / or port open status, and sends them to the second device, which then performs security configuration on the corresponding first unit. After the security policy takes effect, the first device analyzes the first flow information reported by the second device, implements security monitoring of the operating status of the flow and / or port, and executes at least one of updating the security policy, generating a handling policy, and generating an alarm message. Once an abnormality is detected, the handling policy and / or alarm message is sent to the second device. Alarm information can also be sent to a third device that has subscribed to security alerts / events, such as a situational awareness platform, a traffic monitoring system, or an advanced persistent threat (APT) protection system, for further data analysis. The specific process includes the security policy generation phase, the security monitoring phase, and the security policy update phase. These processes are shown in Figures 6 and 7, respectively.
[0154] Figure 6 illustrates the security policy generation phase and the security monitoring phase. The specific steps are as follows:
[0155] Step 1a: The first device subscribes to at least one of a traffic and / or port access whitelist, network topology information, expansion information, reduction information, and migration information from the second device.
[0156] Optionally, the network topology information includes at least one of a virtualized network element name (such as vnfInstanceID), a virtual machine name, a pod name, a connection relationship of the virtualized network element, etc.
[0157] Optionally, the first device may also subscribe to at least one of the traffic and / or port access whitelist, network topology information, expansion information, reduction information, and migration information from each first unit. This will result in exchanges between the first device and multiple first units. Compared with directly subscribing to the second device, there are more interaction objects and more interaction messages, and high performance requirements for the first device. Therefore, it is recommended that the second device collect at least one of the traffic and / or port access whitelist, network topology information, expansion information, reduction information, and migration information and report it to the first device. In this way, the first device only needs to subscribe to the second device of different manufacturers, and the second device collects at least one of the traffic and / or port access whitelist, network topology information, expansion information, reduction information, and migration information reported by the first network element of the same manufacturer managed by the second device.
[0158] Step 1b: The second device subscribes to at least one of the security policy, the handling policy, and the alarm information from the first device.
[0159] This step is optional. If the first device has virtualized network element topology information stored locally, it does not need to subscribe.
[0160] Step 2: One or more first units report the second flow information to the second device.
[0161] Optionally, when the virtualized network element is deployed in a virtual machine, the second traffic information is the traffic information of the virtual machine, such as at least one of the virtualized network element name, the virtual machine name, and quintuple information.
[0162] Optionally, when the virtualized network element is deployed in a virtual machine container, the second traffic information is the traffic information of the pod in the virtual machine, such as at least one of the virtualized network element name, virtual machine name, pod name, five-tuple information, etc.
[0163] Optionally, the first unit may obtain and report the second flow information in real time, or periodically, for example, once every five minutes. During the security monitoring phase, if an abnormality is found, the second flow information may be reported promptly.
[0164] Step 3: The second device aggregates the second flow information reported by one or more first units.
[0165] Step 4: The first device analyzes the second traffic information reported by the first unit and, through machine learning, learns about relationships between traffic flows, port openness, and other information. When the learning results stabilize, it generates security policies and / or network topology information. The security policies may include at least one of the following: the virtualized network element name, the pod name, the virtual machine name, the source / destination IP addresses, source / destination ports, and protocols for permitted communication.
[0166] Step 5: The first device sends the security policy to the second device that has subscribed to the security policy.
[0167] Optionally, the message also includes information identifying the object to which the security policy belongs, such as a virtualized network element name, a virtual machine name, or a pod name.
[0168] Optionally, the first device generates network topology information based on the second flow information, flow and / or at least one of the access whitelists of the port, and can display the network topology to achieve flow visualization.
[0169] Step 6: The second device is configured according to the security policy received from the first device.
[0170] Step 7: After the security policy configuration is completed, the security monitoring phase begins, reporting the first flow information to the second device.
[0171] Optionally, the first traffic information includes at least one of: a virtualized network element name, a virtual machine name, a pod name, a five-tuple (source / destination IP, source / destination port, protocol), etc.
[0172] Step 8: The second device reports the received first traffic information to the first device that has successfully subscribed to the first traffic information.
[0173] Step 9: The first device determines, based on the first traffic information, that the abnormal traffic and / or abnormal port is caused by an attack, and generates a handling strategy and / or alarm information.
[0174] If there is abnormal traffic and / or port, such as a newly added virtual machine name or virtual machine pod, and traffic is sent, or a new open interface is added, but no expansion notification is received from the OMC, and the local network topology has not changed, the first device gives a handling strategy based on the security policy library (such as closing the abnormal port, discarding all traffic with source and destination IP of xx.xx.xx.xx, etc.) and generates an alarm message. For example, the alarm message is used to indicate at least one of abnormal traffic and / or port, security risk, etc.
[0175] Optionally, the security policy library may include a security policy generated based on the traffic and / or port access whitelist of the virtualized network element, and the security policy makes the traffic and / or port behavior of the virtualized network element comply with the traffic and / or port access whitelist.
[0176] Step 10: The first device sends the handling policy and / or alarm information to the second device that has successfully subscribed to the handling policy and / or alarm information.
[0177] Optionally, in addition to the handling strategy and / or alarm information, the message from the first device to the second device may also include a virtualized network element identifier, a virtual machine identifier, and a pod to identify the object to which the handling suggestion and / or alarm belongs.
[0178] Step 11: The second device configures the corresponding first unit according to the handling strategy and / or alarm information.
[0179] Step 12: When the third device subscribes to the alarm information from the first device, the first device reports the alarm information to the third device.
[0180] Optionally, the third device includes at least one of a situational awareness platform, a traffic monitoring system, an advanced persistent threat (APT) protection system, etc.
[0181] Figure 7 shows the security policy update process. The specific steps are as follows:
[0182] Step 0: The first device subscribes to at least one of a traffic and / or port access whitelist, network topology information, expansion information, reduction information, and migration information.
[0183] Optionally, the first device can order capacity expansion or contraction information from the second device. If the order is successful, the second device will report the capacity expansion or contraction information of the virtualized network element to the first device after the virtualized network element is expanded or contracted. After receiving the capacity expansion or contraction information of the virtualized network element, the first device updates the local network topology.
[0184] Step 1: The second device performs service configuration on the expanded virtualized network element or performs service configuration on the reduced virtualized network element to complete the expansion or reduction of the virtualized network element.
[0185] Step 2: The first unit reports the first flow information to the second device.
[0186] Optionally, the first traffic information includes at least one of: a virtualized network element name, a virtual machine name, a pod name, a five-tuple (source / destination IP, source / destination port, protocol), etc.
[0187] Step 3: The second device summarizes the received first traffic information and reports it to the first device.
[0188] Step 4a: The first device determines whether the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, and updates the security policy.
[0189] For example, when the first device discovers that a virtualized network element in the local network topology has shrunk, or receives the shrinkage information of the virtualized network element from the OMC, it performs analysis and machine learning based on the traffic information to update the whitelist of the traffic and / or port of the virtualized network element.
[0190] Step 5a: The first device sends the updated security policy to the second device that has successfully subscribed to the security policy.
[0191] Step 6a: The second device performs security policy configuration according to the updated security policy.
[0192] Step 4b: Based on at least one of the first traffic information, network topology information, capacity expansion information, capacity reduction information, and migration information, determine whether the abnormal traffic and / or abnormal port is caused by an attack, and generate a handling strategy and / or alarm information;
[0193] For example, if the first device finds that there is no capacity expansion, but there are new virtualized network element names, virtual machine names or pod names and related new traffic and open ports, it is considered an abnormality and an alarm information and / or handling strategy is generated.
[0194] Steps 5b-6b: Send the handling strategy and / or alarm information to the first unit via the second device.
[0195] The following is an introduction using an example in which the first device is the micro-isolation management center in MDAF, the second device is the OMC, and the first unit is the micro-isolation execution unit.
[0196] 5G networks have introduced data analysis capabilities, including NWDAF and MDAF. Research on these capabilities is ongoing as networks evolve. Micro-segmentation management primarily involves analyzing traffic information to generate network topology and traffic security policies. By integrating the micro-segmentation management center's functionality into the data analysis capabilities and leveraging the existing SBA interface, secure east-west traffic monitoring of VNFs within the 5G core network within the resource pool can be achieved. This addresses the issue of the inability to directly generate a full network topology and traffic monitoring view when multiple vendors provide network elements in the resource pool. Figure 11 illustrates the micro-segmentation solution framework, including the micro-segmentation management center functionality within MDAF.
[0197] In this embodiment, the micro-segmentation execution unit is provided by the network element manufacturer and built into the network element; the micro-segmentation management center, as a functional module of MDAF, can implement security control of east-west traffic of network elements and hosts. The main process includes:
[0198] (1) The MDAF micro-segmentation management center can subscribe to at least one of the following: virtualized network element traffic information, network element traffic and / or port access whitelists, virtualized network element network topology information, and virtualized network element expansion, contraction, or migration information from the OMC. The OMC can subscribe to at least one of the VNF security policy and handling policy from the MDAF micro-segmentation management center.
[0199] (2) The micro-isolation execution unit in the VNF collects traffic information and reports it to the OMC, which then reports it to the MDAF that has subscribed to the traffic information.
[0200] (3) The micro-segmentation management center in MDAF learns based on the received traffic information, generates the network topology, and tags the assets, such as the type of virtualized network elements.
[0201] (4) The micro-segmentation management center generates a security policy for the east-west traffic of the VNF in the resource pool based on traffic learning and sends it to the OMC that has subscribed to the VNF security policy. The OMC then sends it to the corresponding micro-segmentation execution unit. When the OMC has preset the traffic access whitelist of the network element, the MDAF can generate a security policy for the east-west traffic of the VNF in the resource pool by subscribing to the preset traffic and / or port access whitelist from the OMC and combining the traffic and / or port access whitelist during traffic learning.
[0202] (5) The micro-isolation execution unit collects traffic information in real time and reports it periodically. When abnormal traffic is detected, the abnormal traffic information and / or alarm information are immediately reported to the micro-isolation management center.
[0203] (6) After receiving the traffic information from the OMC, the micro-isolation center analyzes it and identifies whether the abnormal traffic is caused by the scaling or migration of the VNF's virtual machine (VM) or pod, or by an attack on the VNF's VM or pod. When the micro-isolation management center identifies that the abnormal traffic is caused by the scaling or migration of the VNF's VM or pod based on the VNF's VM or pod scaling or migration information obtained after subscription from the OMC, it updates the security policy and sends it to the OMC, which then sends the security policy to the micro-isolation execution unit in the corresponding VM or Pod. When the micro-isolation management center identifies that the abnormal traffic is caused by the attack on the VNF's VM or pod, it generates a handling policy and alarm, and after manual confirmation, sends the handling policy to the micro-isolation execution unit through the OMC.
[0204] (7) After receiving the traffic information from the OMC, the micro-isolation center first determines whether it has obtained the information on the expansion, contraction, or migration of the VM or pod of the VNF subscribed from the OMC. If the above information is obtained, the abnormal traffic is analyzed to determine whether it is caused by the expansion, contraction, or migration of the VNF VM or pod, or the abnormality is caused by the attack on the VNF VM or pod. If the abnormal traffic is caused by the expansion, contraction, or migration of the VNF VM or pod, the micro-isolation management center updates the security policy and sends it to the OMC, which then sends the security policy to the micro-isolation execution unit in the corresponding VM or Pod. Otherwise, the micro-isolation management center generates a disposal policy and alarm information, and after manual confirmation, sends the disposal policy to the micro-isolation execution unit through the OMC.
[0205] (8) When the micro-isolation management center does not obtain the information on the expansion, contraction, or migration of the VM or pod of the VNF subscribed from the OMC, it identifies the abnormal traffic as attack traffic, generates a disposal strategy and / or alarm information, and after manual confirmation, sends the disposal strategy to the micro-isolation execution unit through the OMC.
[0206] The above solution extends the management data analysis function defined by 3GPP and the SBA interface between OMC and data analysis function to enable a micro-isolation management center to connect to multiple micro-isolation execution units provided by different manufacturers. The micro-isolation management center is decoupled from the micro-isolation execution unit, making implementation more flexible.
[0207] 8 , an embodiment of the present application provides a communication processing apparatus, applied to a first device, wherein the apparatus 800 includes:
[0208] A first acquisition module 801 is configured to acquire first traffic information reported by at least one first unit within the VNF;
[0209] The execution module 802 is configured to execute at least one of the following according to the first traffic information reported by the at least one first unit: updating a security policy, generating a handling policy, and generating alarm information.
[0210] In one embodiment of the present application, the device further comprises:
[0211] A second acquisition module, configured to acquire second flow information reported by the at least one first unit;
[0212] A first generating module, configured to generate a security policy and / or network topology information according to at least one of the second flow information, the flow and / or the port access whitelist;
[0213] The first sending module is configured to send the security policy to the first unit.
[0214] In one embodiment of the present application, the first acquisition module 801 is further configured to acquire at least one first flow information reported by at least one first unit located in the VNF and forwarded by the second device;
[0215] and / or,
[0216] The first sending module is further configured to forward the security policy via the second device and send the security policy to the first unit.
[0217] In one embodiment of the present application, the execution module 802 is further used to determine whether the abnormal traffic and / or abnormal port is caused by an attack based on the first traffic information, generate a disposal strategy and / or alarm information, and send the disposal strategy / or alarm information to the first unit through the second device.
[0218] In one embodiment of the present application, the device further comprises:
[0219] A third acquisition module is configured to acquire at least one of the network topology information, expansion information, reduction information, and migration information sent by the second device;
[0220] The execution module 802 is further configured to determine, based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, whether the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration, update the security policy, and send the updated security policy to the first unit via the second device;
[0221] or,
[0222] The execution module 802 is further used to determine whether the abnormal traffic and / or abnormal port is caused by an attack based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, generate a disposal strategy and / or alarm information, and send the disposal strategy and / or alarm information to the first unit through the second device.
[0223] In one embodiment of the present application, the device further comprises:
[0224] The second sending module is used to send a first subscription request to the second device, where the first subscription request is used to request subscription to at least one of an access whitelist of traffic and / or ports, network topology information, expansion information, reduction information, and migration information.
[0225] In one embodiment of the present application, the device further comprises:
[0226] The first receiving module is configured to receive a second subscription request sent by a second device, where the second subscription request is used to request subscription to at least one of a security policy, a handling policy, and alarm information.
[0227] In one embodiment of the present application, the device further comprises:
[0228] The third sending module is used to send the alarm information to a third device, where the third device is at least one of a situational awareness platform, a traffic monitoring system, and an advanced persistent threat (APT) protection system.
[0229] The device provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 2 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0230] 9 , an embodiment of the present application provides a communication processing apparatus, applied to a second device, wherein the apparatus 900 includes:
[0231] The fourth obtaining module 901 is configured to obtain first flow information reported by at least one first unit within the VNF;
[0232] The fourth sending module 902 is used to send the first flow information reported by the at least one first unit to the first device, and the at least one first flow information is used by the first device to execute at least one of the following: updating security policy, generating disposal policy, and generating alarm information.
[0233] In one embodiment of the present application, the device further comprises:
[0234] a fifth acquiring module, configured to acquire the second flow information reported by the at least one first unit;
[0235] a fifth sending module, configured to send the second flow information reported by the at least one first unit to the first device, where the at least one second flow information is used by the first device to generate a security policy and / or network topology information;
[0236] A sixth acquisition module is configured to acquire the security policy sent by the first device and send the security policy to the first unit.
[0237] In one embodiment of the present application, the device further comprises:
[0238] a seventh acquisition module, configured to acquire a handling strategy and / or alarm information sent by the first device, wherein the handling strategy and / or alarm information is generated by the first device when it determines, based on the first traffic information, that the abnormal traffic and / or abnormal port is caused by an attack;
[0239] A sixth sending module is configured to send the handling strategy and / or alarm information to the first unit.
[0240] In one embodiment of the present application, the device further comprises:
[0241] an eighth acquisition module, configured to acquire an updated security policy sent by the first device, where the updated security policy is generated when the first device determines, based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration;
[0242] a seventh sending module, configured to send the updated security policy to the first unit;
[0243] or,
[0244] a ninth acquisition module, configured to acquire a handling strategy and / or alarm information sent by the first device, the handling strategy and / or alarm information being generated when the first device determines, based on at least one of the first traffic information, network topology information, capacity expansion information, capacity reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by an attack;
[0245] An eighth sending module is configured to send the handling strategy and / or alarm information to the first unit.
[0246] In one embodiment of the present application, the device further comprises:
[0247] The second receiving module is used to receive a first subscription request sent by the first device, where the first subscription request is used to request at least one of subscription traffic and / or port access whitelist, network topology information, expansion information, reduction information, and migration information.
[0248] In one embodiment of the present application, the device further comprises:
[0249] The ninth sending module is used to send a second subscription request to the first device, requesting to subscribe to at least one of the security policy, the handling policy and the alarm information.
[0250] The device provided in the embodiment of the present application can implement each process implemented by the method embodiment shown in Figure 3 and achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0251] As shown in FIG10 , an embodiment of the present application further provides a communication device 1000, including a processor 1001, a memory 1002, and a program or instruction stored in the memory 1002 and executable on the processor 1001. When the program or instruction is executed by the processor 1001, the various processes of the method embodiments of FIG2 or FIG3 are implemented, and the same technical effects can be achieved. To avoid repetition, they are not described here.
[0252] An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the method embodiment shown in Figure 2 or Figure 3 above are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
[0253] The processor is the processor in the terminal described in the above embodiment. The readable storage medium includes a computer-readable storage medium, such as a computer read-only memory (ROM), random access memory (RAM), a magnetic disk, or an optical disk.
[0254] The steps of the method or algorithm described in conjunction with the contents disclosed in this application can be implemented in hardware or by executing software instructions on a processor. The software instructions can be composed of corresponding software modules, and the software modules can be stored in RAM, flash memory, ROM, EPROM, EEPROM, registers, hard disk, mobile hard disk, read-only optical disk or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be carried in an ASIC. In addition, the ASIC can be carried in a core network interface device. Of course, the processor and the storage medium can also exist in the core network interface device as discrete components.
[0255] Those skilled in the art will appreciate that, in one or more of the examples above, the functions described herein may be implemented using hardware, software, firmware, or any combination thereof. When implemented using software, these functions may be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. The storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0256] The specific implementation methods described above further illustrate the purpose, technical solutions and beneficial effects of this application. It should be understood that the above description is only the specific implementation methods of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solutions of this application should be included in the scope of protection of this application.
[0257] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the embodiments of the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0258] The present application embodiment is described with reference to the flow chart and / or block diagram according to the method, device (system) and computer program product of the embodiment of the present application.It should be understood that each flow process and / or box in the flow chart and / or block diagram and the combination of the flow process and / or box in the flow chart and / or block diagram can be realized by computer program instructions.These computer program instructions can be provided to the processor of general-purpose computer, special-purpose computer, embedded processing machine or other programmable data processing equipment to produce a machine, so that the instruction executed by the processor of computer or other programmable data processing equipment produces the device for realizing the function specified in one flow chart flow chart or multiple flow charts and / or one block or multiple blocks of block diagram.
[0259] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0260] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0261] Obviously, those skilled in the art may make various changes and modifications to the embodiments of the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include such modifications and variations.
Claims
1. A communication processing method, applied to a first device, characterized in that: include: Obtaining first flow information reported by at least one first unit within a virtualized network function VNF; According to the first traffic information reported by the at least one first unit, at least one of the following is executed: updating a security policy, generating a handling policy, and generating alarm information.
2. The method according to claim 1, characterized in that The method further comprises: Obtaining second flow information reported by the at least one first unit; generating the security policy and / or network topology information according to at least one of the second flow information, the flow and / or the port access whitelist; The security policy is sent to the first unit.
3. The method according to claim 1 or 2, characterized in that The obtaining of first flow information reported by at least one first unit within the VNF includes: Obtain first traffic information reported by at least one first unit located in the VNF and forwarded by the second device.
4. The method according to claim 2 or 3, characterized in that The sending the security policy to the first unit includes: The security policy is forwarded through the second device and sent to the first unit.
5. The method according to claim 3 or 4, characterized in that The step of performing at least one of the following steps based on the first traffic information reported by the at least one first unit: updating a security policy, generating a handling policy, and generating alarm information includes: Based on the first traffic information, it is determined that the abnormal traffic and / or abnormal port is caused by an attack, a handling strategy and / or alarm information is generated, and the handling strategy / or alarm information is sent to the first unit through the second device.
6. The method according to claim 3 or 4, characterized in that The method further comprises: Obtain at least one of network topology information, expansion information, reduction information, and migration information sent by the second device; The step of performing at least one of the following steps based on the first traffic information reported by the at least one first unit: updating a security policy, generating a handling policy, and generating alarm information includes: determining, based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, whether the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration, updating the security policy, and issuing the updated security policy to the first unit via the second device; or, Based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, determine whether the abnormal traffic and / or abnormal port is caused by an attack, generate a disposal strategy and / or alarm information, and send the disposal strategy and / or alarm information to the first unit through the second device.
7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: A first subscription request is sent to the second device, where the first subscription request is used to request subscription to at least one of an access whitelist of traffic and / or ports, network topology information, expansion information, reduction information, and migration information.
8. The method according to any one of claims 1 to 7, characterized in that: The method further comprises: A second subscription request sent by a second device is received, where the second subscription request is used to request subscription to at least one of a security policy, a handling policy, and alarm information.
9. The method according to any one of claims 1 to 8, characterized in that The method further comprises: The alarm information is sent to a third device, where the third device is at least one of a situational awareness platform, a traffic monitoring system, and an advanced persistent threat (APT) protection system.
10. A communication processing method, applied to a second device, characterized in that: include: Obtaining first flow information reported by at least one first unit within the VNF; The first flow information reported by the at least one first unit is sent to the first device, where the first flow information is used by the first device to execute at least one of the following: updating a security policy, generating a disposal policy, and generating alarm information.
11. The method according to claim 10, characterized in that The method further comprises: Obtaining second flow information reported by the at least one first unit; Sending the second flow information reported by the at least one first unit to the first device, where the second flow information is used by the first device to generate a security policy and / or network topology information; Acquire the security policy sent by the first device, and send the security policy to the first unit.
12. The method according to claim 10 or 11, characterized in that The method further comprises: Obtaining a handling strategy and / or alarm information sent by the first device, where the handling strategy and / or alarm information is generated by the first device when it determines, based on the first traffic information, that the abnormal traffic and / or abnormal port is caused by an attack; The handling strategy and / or alarm information are sent to the first unit.
13. The method according to claim 10 or 11, characterized in that The method further comprises: Obtaining an updated security policy sent by the first device, where the updated security policy is generated when the first device determines, based on at least one of the first traffic information, network topology information, expansion information, reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by at least one of expansion, reduction, and migration; sending the updated security policy to the first unit; or, Obtaining a handling strategy and / or alarm information sent by the first device, where the handling strategy and / or alarm information is generated when the first device determines, based on at least one of the first traffic information, network topology information, capacity expansion information, capacity reduction information, and migration information, that the abnormal traffic and / or abnormal port is caused by an attack; The handling strategy and / or alarm information is sent to the first unit.
14. The method according to any one of claims 10 to 13, characterized in that: The method further comprises: Receive a first subscription request sent by the first device, where the first subscription request is used to request subscription to at least one of an access whitelist of traffic and / or ports, network topology information, expansion information, reduction information, and migration information.
15. The method according to any one of claims 10 to 14, characterized in that: The method further comprises: A second subscription request is sent to the first device, requesting to subscribe to at least one of a security policy, a handling policy, and alarm information.
16. A communication processing device, applied to a first device, characterized in that: include: A first acquisition module is configured to acquire first flow information reported by at least one first unit within the VNF; The execution module is used to execute at least one of the following according to the first traffic information reported by the at least one first unit: updating the security policy, generating a disposal policy, and generating alarm information.
17. A communication processing device, applied to a second device, characterized in that: include: a fourth acquisition module, configured to acquire first flow information reported by at least one first unit within the VNF; The fourth sending module is used to send the first flow information reported by the at least one first unit to the first device, and the at least one first flow information is used by the first device to execute at least one of the following: updating security policy, generating disposal policy, and generating alarm information.
18. A communication device, characterized in that: The method comprises a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the method according to any one of claims 1 to 15.
19. A readable storage medium, characterized in that The readable storage medium stores a program or instruction, and when the program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 15 are implemented.