Software-defined-network-based cloud-edge collaborative defense system and method for unknown attacks

Through the security controller and component resource pool under the software-defined network architecture, combined with machine learning algorithms, the cloud-edge collaborative defense system can be dynamically adjusted and identify unknown attacks, solving the problem of insufficient processing power of edge devices and improving the defense effectiveness against unknown attacks.

WO2025194680A1PCT designated stage Publication Date: 2025-09-25GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +3

Patent Information

Application Number
PCT/CN2024/113082
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-20
Filing Date
2024-08-19
Publication Date
2025-09-25

AI Technical Summary

Technical Problem

The existing security access and attack defense system is unable to adjust its defense strategy in a timely and effective manner in new business terminal access scenarios, resulting in poor effectiveness of defense against unknown attacks and insufficient edge device processing capabilities to quickly identify and respond to unknown attacks.

Method used

It adopts a software-defined network architecture, uniformly manages the cloud and edge through a security controller, virtualizes security functions using a security component resource pool, and combines machine learning algorithms to identify unknown attacks and generate dynamic defense strategies to achieve cloud-edge collaborative defense.

Benefits of technology

It improves the recognition and response speed of unknown attacks, enhances network security, improves the flexibility and scalability of the system, and achieves timely and reliable defense against unknown attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024113082_25092025_PF_FP_ABST
    Figure CN2024113082_25092025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network security. Disclosed are a software-defined-network-based cloud-edge collaborative defense system and method for unknown attacks. The system comprises a main station deployed at a cloud end and a plurality of edge stations deployed at an edge end. A software defined security platform comprises a main controller, a security controller and a security component resource pool. Any one of the edge stations comprises an edge controller. The security controller is configured to receive network security information uploaded by the main controller and / or any one of the edge controllers, identify an unknown attack on the basis of the network security information, generate a corresponding defense strategy and issue the defense strategy to the security component resource pool, the main controller and / or any one of the edge controllers. The security component resource pool is configured to virtualize a security protection function into a security component, and configure the main station and / or any one of the edge stations with the security component on the basis of the network security information or the defense strategy. The problem of traditional static and rigid defense measures and strategies being unable to meet the requirements for defending against unknown attacks is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Unknown attack cloud-edge collaborative defense system and method based on software-defined network

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application is based on the Chinese patent application with application number 202410321312.6, application date March 20, 2024, and application name “Cloud-edge collaborative defense system and method for unknown attacks based on software-defined networks”, and claims the priority of the Chinese patent application. The entire content of the Chinese patent application is hereby incorporated into this application by introduction. Technical Field

[0003] The present application relates to the field of network security technology, and in particular to a cloud-edge collaborative defense system and method for unknown attacks based on software-defined networks. Background Art

[0004] In new business terminal access scenarios, unknown attack targets are random and diverse, attack paths are dynamically variable, and attack methods are heterogeneous and diverse. Existing security access and attack defense systems lack flexibility in deployment methods and protection capabilities, and are unable to adjust defense strategies in a timely and effective manner, resulting in poor effectiveness in defending against unknown attacks. The processing power of edge devices in existing cloud-edge collaborative defense systems is insufficient to provide rapid and accurate identification of unknown attacks and formulate corresponding defense strategies for these attacks, making it impossible to effectively defend against unknown attacks. Therefore, existing technologies suffer from the problem that traditional static and fixed defense measures and strategies cannot meet the needs of defending against unknown attacks.

[0005] Summary of the Invention

[0006] In view of this, the present application provides a cloud-edge collaborative defense system and method for unknown attacks based on software-defined networks to solve the problem that traditional static solidified defense measures and strategies cannot meet the needs of unknown attack defense.

[0007] In the first aspect, the present application provides a cloud-edge collaborative defense system for unknown attacks based on a software-defined network, comprising: a main station deployed in the cloud and multiple edge stations deployed at the edge, the control plane of the main station including a software-defined security platform, the software-defined security platform including: a main controller, a security controller and a security component resource pool, and any edge station including: an edge controller; the security controller is configured to receive network security information uploaded by the main controller and / or any edge controller, identify unknown attacks based on the network security information, generate corresponding defense strategies based on the identified unknown attacks, and send the defense strategies to the security component resource pool, the main controller and / or any edge controller; the security component resource pool is configured to virtualize security protection functions into security components, and configure security components for the main station and / or any edge station based on network security information or defense strategies.

[0008] In the embodiment of the present application, a software-defined network architecture is used to uniformly manage the cloud and edge through a security controller. Through information interaction and collaborative work among the security controller, main controller, edge controller, and security component resource pool, the purpose of real-time monitoring of cloud-edge network security information, timely identification of unknown attacks on the cloud and edge, and flexible adjustment of defense strategies are achieved. This solves the problem of traditional static solidified defense measures and insufficient edge device processing capabilities in a cloud-edge collaborative environment, which makes it difficult to quickly identify and respond to unknown attacks. Through the centralized management and issuance of defense strategies, the effect of improving response speed and network security is achieved. By separating the data plane and the control plane, the purpose of making network control and data forwarding independent is achieved, which improves network flexibility and facilitates expansion and upgrading. This solves the problem that traditional static solidified defense measures and strategies in related technologies cannot meet the needs of unknown attack defense.

[0009] In an optional embodiment, the data plane of the master station includes an infrastructure layer. The software-defined security platform is based on the programmability of the software-defined network architecture and interacts with the infrastructure layer through a southbound interface. The infrastructure layer includes network devices. The main controller is configured to control and manage the network devices, and transmit and interact data with the edge controller through the network devices and preset communication protocols. The main controller is also configured to obtain real-time traffic and network topology at the network boundary of the master station, and the edge controller is configured to obtain real-time network traffic and security events of the corresponding edge station.

[0010] In an embodiment of the present application, the programmability of software-defined networks is utilized to achieve the purpose of sharing network information and coordinating decisions between multiple controllers, namely the main controller and multiple edge controllers, thereby achieving the effect of cloud-edge collaboration and unified management.

[0011] In an optional embodiment, the edge station also includes an edge intelligent device, and the security components include: a security access component, a security access component, and a security monitoring component. The security access component is configured to perform identity authentication and access control on the edge intelligent device; the security access component is configured to encrypt the network traffic of the edge intelligent device and use tunnel technology for data transmission; the security monitoring component is configured to perform traffic monitoring, obtain security events and alarm information, and upload the security events and alarm information to the security controller.

[0012] In an embodiment of the present application, a security component virtualized by a security protection function is used to provide security services for the system, thereby achieving the effect of improving the convenience and security of deploying the security protection function in different environments.

[0013] In an optional embodiment, the security controller is also configured to obtain an attack feature library and an attack defense strategy library, use a machine learning algorithm to identify unknown attacks based on the attack feature library and network security information, and use a machine learning algorithm to generate a defense strategy corresponding to the unknown attack based on the attack defense strategy library and the unknown attack.

[0014] In the embodiment of the present application, the purpose of dynamic and flexible defense against scattered and random unknown attacks is achieved through the security controller, achieving the effect of timely and reliable defense against unknown attacks.

[0015] In an optional embodiment, the main controller is further configured to send the defense strategy to the network devices to dynamically adjust the network configuration and behavior.

[0016] In the embodiment of the present application, the main controller dynamically adjusts the network configuration and behavior, thereby achieving the purpose of filtering intrusion traffic and dynamically blocking intrusion behavior, thereby further improving the system security defense capability.

[0017] In an optional embodiment, the edge intelligent device is configured to intercept and handle unknown attacks according to the defense strategy and the security components configured by the security controller, obtain unknown attack information, and send the unknown attack information to the edge intelligent devices of other edge stations.

[0018] In the embodiment of the present application, by sharing unknown attack information among multiple edge stations, the effect of improving the edge intelligent device's defense capability against unknown attacks is achieved.

[0019] In the second aspect, the present application provides a method for cloud-edge collaborative defense against unknown attacks based on a software-defined network, which adopts the above-mentioned first aspect or any corresponding embodiment of the cloud-edge collaborative defense system for unknown attacks based on a software-defined network, and is applied to a security controller. The method includes: receiving network security information uploaded by the main controller and / or any edge controller; identifying unknown attacks based on the network security information; generating corresponding defense strategies based on the identified unknown attacks; sending the defense strategies to the security component resource pool, the main controller and / or any edge controller, and the security component resource pool is configured to virtualize the security protection function into a security component; controlling the security component resource pool to configure security components for the main station and / or any edge station according to the network security information or the defense strategy.

[0020] In an embodiment of the present application, the security controller achieves the purpose of timely identifying unknown attacks on the cloud edge and flexibly issuing defense strategies by receiving network security information uploaded by the cloud edge controller, i.e., the main controller and the edge controller. It solves the problem that traditional static solidified defense measures and insufficient processing capabilities of edge devices in a cloud-edge collaborative environment make it difficult to quickly identify and respond to unknown attacks, achieves the effect of improving response speed and network security, and solves the problem that traditional static solidified defense measures and strategies in related technologies cannot meet the defense needs of unknown attacks.

[0021] In an optional embodiment, network security information uploaded by the main controller and / or any edge controller is received, including: receiving real-time traffic information and network topology structure of the main station network boundary uploaded by the main controller; and / or, receiving real-time network traffic and security events of the corresponding edge station uploaded by any edge controller.

[0022] In an embodiment of the present application, by receiving network security information corresponding to the main controller and the edge controller, the purpose of real-time monitoring of the cloud and edge is achieved.

[0023] In an optional embodiment, the security component resource pool is controlled to configure security components for the main station and / or any edge station based on network security information or defense strategy, including: controlling the security component resource pool to configure security components for the main station based on defense strategy or real-time traffic information and network topology structure of the main station network boundary; and / or controlling the security component resource pool to configure security components for any edge station based on defense strategy or real-time network traffic and security events of the edge station.

[0024] In the embodiment of the present application, by configuring security components for the master station and the edge station, the purpose of flexibly configuring security protection functions for the master station and the edge station is achieved.

[0025] In an optional embodiment, after controlling the security component resource pool to configure a security component for any edge station based on a defense strategy or the real-time network traffic and security events of the edge station, the method further includes: using the security component to obtain security events and alarm information of any edge station; and using a machine learning algorithm to identify unknown attacks based on an attack feature library, network security information, security events, and alarm information.

[0026] In the embodiment of the present application, a machine learning algorithm is used to jointly identify unknown attacks based on an attack feature library, network security information, security events, and alarm information, thereby achieving the purpose of further improving the accuracy and reliability of identifying unknown attacks.

[0027] In a third aspect, the present application provides a computer-readable storage medium having computer instructions stored thereon, and the computer instructions are used to enable a computer to execute the software-defined network-based unknown attack cloud-edge collaborative defense method of the second aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] FIG1 is a schematic diagram of a cloud-edge collaborative defense system for unknown attacks based on a software-defined network according to an embodiment of the present application;

[0029] FIG2 is a schematic diagram of another software-defined network-based unknown attack cloud-edge collaborative defense system according to an embodiment of the present application;

[0030] FIG3 is a schematic diagram of another software-defined network-based unknown attack cloud-edge collaborative defense system according to an embodiment of the present application;

[0031] FIG4 is an overall schematic diagram of a cloud-edge collaborative defense system for unknown attacks based on a software-defined network according to an embodiment of the present application;

[0032] FIG5 is a flow chart of a method for cloud-edge collaborative defense against unknown attacks based on a software-defined network according to an embodiment of the present application;

[0033] FIG6 is a flow chart of another method for cloud-edge collaborative defense against unknown attacks based on a software-defined network according to an embodiment of the present application;

[0034] FIG7 is a schematic diagram of the overall framework of a software-defined security platform according to an embodiment of the present application. DETAILED DESCRIPTION

[0035] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.

[0036] It should be noted that, in the description of the present application, the terms "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices. The directions or positional relationships indicated by the terms "center", "up", "down", "left", "right", "vertical", "horizontal", "inside", "outside", etc. are based on the directions or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific direction, be constructed and operated in a specific direction, and therefore cannot be understood as limiting the present application. The terms "mounted," "connected," and "connected" should be interpreted broadly. For example, they can refer to fixed, detachable, or integral connections; mechanical or electrical connections; direct or indirect connections through an intermediary; internal communication between two components; and wireless or wired connections. Those skilled in the art will understand the specific meanings of the above terms in this application.

[0037] In addition, if "and / or" appears in this application, it includes three parallel solutions. For example, "A and / or B" includes solution A, solution B, or solutions that meet both A and B. In addition, the technical solutions of various embodiments may be combined with each other, but this must be based on the fact that they can be implemented by ordinary technicians in this field. If the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0038] According to an embodiment of the present application, an embodiment of a cloud-edge collaborative defense system for unknown attacks based on a software-defined network is provided, and FIG1 is a schematic diagram of a cloud-edge collaborative defense system for unknown attacks based on a software-defined network according to an embodiment of the present application. As shown in FIG1 , the system includes: a main station deployed in the cloud and multiple edge stations (edge ​​station 1...edge station n) deployed at the edge. The system separates the data plane and the control plane based on the software-defined network (SDN) architecture, wherein the control plane of the main station includes a software-defined security platform, which includes: a main controller, a security controller and a security component resource pool, and any edge station includes: an edge controller. It should be noted that the main controller, the edge controller, and the security controller are all SDN controllers. The security controller is configured to receive network security information uploaded by the main controller and / or any edge controller, such as real-time network traffic information, security events, network topology, etc. The security controller uses behavioral analysis, machine learning, anomaly detection and other methods based on the above network security information to identify unknown attacks on the main station and / or any edge station, generates corresponding defense strategies based on the identified unknown attacks, and sends the defense strategies to the security component resource pool, the main controller and / or any edge controller. The security component resource pool uses container technology to virtualize security protection functions into security components. The security components can implement security services such as identity authentication, access control, data encryption, and traffic monitoring. The security controller is also configured to configure security components for the main station and / or any edge station based on network security information or defense strategies.

[0039] In an embodiment of the present application, a software-defined network architecture is adopted to uniformly manage the cloud and edge through a security controller. Through information interaction and collaborative work between the security controller, main controller, edge controller and security component resource pool, the purpose of real-time monitoring of cloud-edge network security information, timely identification of unknown cloud-edge attacks and flexible adjustment of defense strategies is achieved. The problem of traditional static solidified defense measures and insufficient processing capabilities of edge devices in a cloud-edge collaborative environment making it difficult to quickly identify and respond to unknown attacks is solved. Through centralized management and issuance of defense strategies, the effect of improving response speed and network security is achieved, and the problem that traditional static solidified defense measures and strategies in related technologies cannot meet the defense needs of unknown attacks is solved.

[0040] In an optional embodiment, Figure 2 is a schematic diagram of another unknown attack cloud-edge collaborative defense system based on a software-defined network according to an embodiment of the present application. As shown in Figure 2, the data plane of the main station includes an infrastructure layer, and the infrastructure layer includes network devices such as switches and routers. The software-defined security platform interacts with the infrastructure layer through a southbound interface based on the programmability of the software-defined network architecture. The main controller is configured to control and manage the network devices, and transmit and interact data with the edge controller through the network devices and preset communication protocols. Exemplarily, the software-defined security platform interacts with infrastructure such as switches and routers in the infrastructure layer through a southbound interface. The infrastructure layer is responsible for forwarding, switching and transmitting data packets, and performs corresponding operations according to the instructions issued by the software-defined platform. The main controller is also configured to obtain real-time traffic and network topology at the network boundary of the main station, and the edge controller is configured to obtain real-time network traffic and security events of the corresponding edge station.

[0041] In an embodiment of the present application, by separating the data plane and the control plane, the purpose of making network control and data forwarding independent is achieved, thereby improving network flexibility and facilitating expansion and upgrading; by utilizing the programmability of software-defined networks, the purpose of sharing network information and coordinating decisions between multiple controllers, namely the main controller and multiple edge controllers, is achieved, thereby achieving the effect of cloud-edge collaboration and unified management.

[0042] In an optional embodiment, Figure 3 is a schematic diagram of another unknown attack cloud-edge collaborative defense system based on a software-defined network according to an embodiment of the present application. As shown in Figure 3, the edge station also includes edge intelligent devices, such as edge servers, terminals, smart phones and other devices. The security component is an abstract security component obtained by virtualizing the security protection function by using container technology such as container engine (Docker) in the security component resource pool, including: security access component, security access component and security monitoring component. It should be noted that, considering the complex security requirements and differentiated operating environments brought about by different application scenarios in the new business access environment, it is necessary to construct a large variety of various security protection function components, and there is a problem of complex deployment architecture and difficult implementation. Therefore, the security protection functions required by each edge station are virtualized using container technology and abstracted into security components to facilitate deployment in different operating environments. Among them, the security access component can perform identity authentication and access control on edge smart devices to prevent unauthorized access and attacks, that is, only devices that have passed identity authentication and access control can access the network, thereby reducing the risk of edge smart devices being attacked by unknown attacks; the security access component is configured to encrypt and tunnel the network traffic of edge smart devices to ensure the security and reliability of data transmission, wherein encryption and tunnel transmission can prevent unauthorized access and eavesdropping, thereby achieving the purpose of protecting the data security of edge smart devices; the security monitoring component can be configured to perform traffic monitoring, local monitoring, and upload the generated event alarms and security logs to the security controller, thereby achieving the purpose of protecting the security of edge smart devices. It should be noted that this embodiment does not limit the security components, that is, the system can virtualize and implement security components of other security services according to specific needs.

[0043] In an embodiment of the present application, a security component virtualized by a security protection function is used to provide security services for the system, thereby achieving the effect of improving the convenience and security of deploying the security protection function in different environments.

[0044] In an optional embodiment, the security controller is further configured to obtain an attack signature library and an attack defense policy library, and to analyze and evaluate attack information, such as network security information, based on the attack signature library using a machine learning algorithm, thereby identifying unknown attacks. In addition, the security controller is further configured to generate corresponding defense policies based on the attack defense policy library and the identified unknown attacks using a machine learning algorithm. As an example, the security controller can use a machine learning algorithm to parse the type of unknown attack and dynamically generate corresponding defense policies, such as access control rules, firewall rules, etc., based on the attack defense policy library. In an embodiment of the present application, the security controller is used to achieve the purpose of dynamic and flexible defense against scattered and random unknown attacks, thereby achieving the effect of timely and reliable defense against unknown attacks.

[0045] In an optional embodiment, the main controller is further configured to distribute defense policies to network devices, dynamically adjusting network configuration and behavior. For example, the main controller can distribute defense policies to network devices such as SDN switches, thereby filtering intrusion traffic and dynamically blocking intrusions, further enhancing the system's security and defense capabilities.

[0046] In an optional embodiment, the edge intelligent device is configured to intercept and handle unknown attacks based on the defense policy and the security components configured by the security controller, obtain unknown attack information, and send the unknown attack information to the edge intelligent devices of other edge stations. In this embodiment of the application, the edge intelligent device intercepts and handles unknown attacks based on the defense policy and the assigned security components, and can also send information related to the attack to the edge intelligent devices of other edge stations, enabling them to defend against such attacks.

[0047] In an optional embodiment, FIG4 is an overall schematic diagram of a cloud-edge collaborative defense system for unknown attacks based on a software-defined network according to an embodiment of the present application. As shown in FIG4 , the system includes a master station and multiple edge stations (edge ​​station 1...edge station n). The master station includes an application layer, a software-defined security platform, and an infrastructure layer. The software-defined security platform includes an SDN controller, i.e., a main controller, a security controller, and a security component resource pool. Any edge station includes an edge server, i.e., an edge intelligent device, and an edge SDN controller, i.e., an edge controller. Among them, the application of the master station application layer interacts with the platform through the northbound interface of the software-defined platform, and realizes network management, security management, traffic engineering optimization, and cloud service management functions through the programmability of SDN. The software-defined platform interacts with infrastructure such as switches and routers in the infrastructure layer through the southbound interface. The infrastructure layer is responsible for forwarding, switching, and transmitting data packets, and performs corresponding operations according to the instructions issued by the software-defined platform. The software-defined security platform, combined with the SDN controller, the edge SDN controller, and the security component resource pool, can realize dynamic defense against unknown attacks on edge intelligent devices and the master station network boundary. Specifically, the security controller is responsible for traffic analysis, attack detection and identification, policy orchestration and issuance, as well as monitoring and management of the resources (security components) of the security component resource pool; the SDN controller is responsible for controlling and managing switches, secure access gateways, isolation devices and other devices in the infrastructure layer SDN network, monitoring global network and topology information, receiving policy instructions (defense policies) from the security controller, and adjusting network configuration and behavior in real time; the security component resource pool uses Docker container technology to virtualize security protection functions into abstract security components, centrally storing, managing and scheduling a series of virtual security components (such as security access, secure access, security monitoring and other components) to provide security services for the system.

[0048] In the embodiment of the present application, a software-defined network architecture is adopted to realize the dynamic adjustment of defense resources and defense capabilities on the edge intelligent device side through information interaction and collaborative work among the security controller, SDN controller, edge SDN controller and security component resource pool; on the other hand, unified scheduling and control of main site layer security protection equipment such as secure access gateways and isolation devices are realized, achieving the purpose of dynamic, flexible and reliable defense against scattered random unknown attacks.

[0049] In this embodiment, a method for cloud-edge collaborative defense against unknown attacks based on a software-defined network is provided, which adopts the first aspect or any corresponding embodiment thereof. The method is applied to a security controller. FIG5 is a flow chart of the method for cloud-edge collaborative defense against unknown attacks based on a software-defined network according to an embodiment of the present application. It should be noted that although a logical order is shown in the flow chart, in some cases, the steps shown or described may be performed in a different order than here. As shown in FIG5 , the process includes the following steps:

[0050] Step S501: Receive network security information uploaded by the main controller and / or any edge controller. Optionally, the security controller can monitor the security of the master station and / or any edge station by receiving network security information uploaded by the main controller and / or any edge controller. Network security information includes real-time network traffic information, security events, network topology, etc.

[0051] Step S502: Identify unknown attacks based on network security information. Optionally, the security controller may identify unknown attacks on the master station and / or any edge station using methods such as behavior analysis, machine learning, and anomaly detection based on the network security information received in step S501.

[0052] Step S503: Generate a corresponding defense strategy based on the identified unknown attack. Optionally, the security controller generates a corresponding defense strategy based on the unknown attack identified in step S502, thereby achieving the purpose of real-time, dynamic, and flexible adjustment of the defense strategy based on the unknown attack.

[0053] In step S504, the defense policy is distributed to the security component resource pool, the main controller, and / or any edge controller. The security component resource pool is used to virtualize security protection functions into security components. Optionally, the security controller distributes the defense policy corresponding to the unknown attack generated in step S503 to the security component resource pool, the main controller, and / or any edge controller, enabling the master station and / or any edge station to perform security protection according to the dynamically adjusted defense policy.

[0054] Step S505: Control the security component resource pool to configure security components for the master station and / or any edge station based on the network security information or defense policy. Optionally, the security controller may control the security component resource pool to configure security components corresponding to the defense policy for the master station and / or any edge station based on the generated defense policy.

[0055] In an embodiment of the present application, the security controller achieves the purpose of timely identifying unknown attacks on the cloud edge and flexibly issuing defense strategies by receiving network security information uploaded by the cloud edge controller, i.e., the main controller and the edge controller. It solves the problem that traditional static solidified defense measures and insufficient processing capabilities of edge devices in a cloud-edge collaborative environment make it difficult to quickly identify and respond to unknown attacks, achieves the effect of improving response speed and network security, and solves the problem that traditional static solidified defense measures and strategies in related technologies cannot meet the defense needs of unknown attacks.

[0056] In an optional embodiment, FIG6 is a flow chart of another method for cloud-edge collaborative defense of unknown attacks based on a software-defined network according to an embodiment of the present application. As shown in FIG6 , the process includes the following steps:

[0057] Step S601: Receive network security information uploaded by the master controller and / or any edge controller. Specifically, step S601 includes: receiving real-time traffic information and network topology of the master station network boundary uploaded by the master controller, and / or receiving real-time network traffic and security events of the corresponding edge station uploaded by any edge controller.

[0058] Step S602: Identify unknown attacks based on network security information. Please refer to step S502 of the embodiment shown in FIG5 for details, which will not be repeated here.

[0059] Step S603: Generate a corresponding defense strategy based on the identified unknown attack. Please refer to step S503 of the embodiment shown in FIG5 for details, which will not be repeated here.

[0060] In step S604, the defense policy is distributed to the security component resource pool, the main controller, and / or any edge controller. The security component resource pool is used to virtualize the security protection functions into security components. For details, please refer to step S504 of the embodiment shown in Figure 5 and will not be repeated here.

[0061] Step S605 controls the security component resource pool to configure security components for the master station and / or any edge station based on network security information or defense policies. Specifically, step S605 includes: controlling the security component resource pool to configure security components for the master station based on the defense policy or real-time traffic information at the master station's network boundary and the network topology, and / or controlling the security component resource pool to configure security components for any edge station based on the defense policy or real-time network traffic and security events at the edge station. In other words, the security controller can monitor network security information for the master station and / or any edge station, generate corresponding defense policies, and control the security component resource pool to configure security components for the master station and / or any edge station based on the corresponding defense policies, so that the master station and / or any edge station can defend against unknown attacks based on the dynamically adjusted defense policies and configured security components.

[0062] In an optional embodiment, after controlling the security component resource pool to configure a security component for any edge station according to the defense strategy or the real-time network traffic and security events of the edge station in step S605, the following further comprises:

[0063] In step S606, the security component is used to obtain security events and alarm information from any edge station, and a machine learning algorithm is used to identify unknown attacks based on the attack signature library, network security information, security events, and alarm information. Optionally, after assigning a security component to any edge station, a security component, such as a security monitoring component, can be used to obtain security events and alarm information from any edge station. When identifying unknown attacks based on network security information, the security events and alarm information provided by the security component are combined for analysis, thereby further improving the accuracy and reliability of unknown attack identification.

[0064] In an optional embodiment, the steps of dynamically defending edge smart devices against unknown attacks using a software-defined network-based cloud-edge collaborative defense system include:

[0065] Step a1: System initialization. Specifically, the security controller integrates and analyzes network traffic, security events, and network topology uploaded by the edge controller to determine the security requirements of the edge station and allocate virtualized security components such as security admission, security access, and security monitoring.

[0066] Step a2: Network status monitoring. Specifically, after the edge controller obtains the security monitoring component, it collects traffic information of the edge station through the security monitoring component, including inbound / outbound traffic, transmission protocol, source IP address, and destination IP address.

[0067] Step a3: Traffic Analysis. Specifically, the security monitoring components in the security component resource pool can share detected security events and alarm information with the security controller in the master station. The security controller uses machine learning algorithms to analyze and evaluate this information based on the attack signature library to identify unknown attacks.

[0068] Step a4: Policy orchestration and delivery. Specifically, the security controller uses machine learning algorithms to parse unknown attacks based on the attack defense policy library, dynamically generates corresponding defense policies based on the analyzed attack types, and delivers the defense policies to the SDN controller and security component resource pool.

[0069] Step a5: Attack defense. Specifically, the SDN controller sends the defense policy to the edge controller. The security component resource pool updates the security components in the security component resource pool based on the defense policy and selects appropriate defense components for the edge intelligent device. The edge intelligent device intercepts and handles unknown attacks based on the defense policy and the obtained security components.

[0070] Step a6: Information sharing: Specifically, the edge intelligent device can send information related to this attack to other edge stations, enabling other edge stations to have the ability to defend against this type of attack.

[0071] In an optional embodiment, the steps of dynamically defending the master station network boundary against unknown attacks by the software-defined network-based cloud-edge collaborative defense system include:

[0072] Step b1: Network status monitoring. Specifically, the SDN controller monitors the traffic at the network boundary of the master station and obtains real-time network traffic information.

[0073] Step b2: Traffic analysis: Specifically, the security controller obtains real-time traffic information at the master network boundary from the SDN controller and uses machine learning algorithms to analyze and evaluate the real-time traffic information to identify unknown attacks.

[0074] Step b3: Policy orchestration and distribution. Specifically, the security controller uses machine learning algorithms to analyze unknown attacks based on the attack defense policy library, dynamically generates corresponding defense policies based on the attack type, and distributes the defense policies to the SDN controller and security component resource pool.

[0075] Step b4: Attack defense: Specifically, the security component resource pool dynamically configures security components based on the defense policy, and the SDN controller sends the defense policy rules to the SDN switch to filter intrusion traffic and dynamically block intrusion behaviors.

[0076] In an optional embodiment, Figure 7 is a schematic diagram of the overall framework of the software-defined security platform according to an embodiment of the present application. As shown in Figure 7, the software-defined security platform includes: a security controller, an SDN controller, and a security component resource pool. Among them, the functions of the security controller include: machine learning and network traffic analysis, storage of known attack feature libraries, security policy orchestration, etc.; the functions of the SDN controller include: discovery and management of network topology, traffic control and security policy issuance; the security component resource pool includes: security components such as security access components, security access components, and security detection components. Specifically, the security controller is configured to monitor, schedule, and manage resources of the security component resource pool, issue security policies (defense policies), issue network alarms, and receive security event uploads from the security component resource pool and the SDN controller. The SDN controller is configured to monitor traffic on the boundary side of the main station, execute and issue security policies, and issue defense policies to the edge SDN controller. The security component resource pool is configured to monitor traffic on edge smart devices and issue and deploy security components. In this embodiment, through the information interaction and collaborative work between the security controller, SDN controller and the security component resource pool, the purpose of real-time monitoring of cloud-edge network security information, timely identification of unknown cloud-edge attacks and flexible adjustment of defense strategies is achieved. The problem of traditional static solidified defense measures and insufficient processing capabilities of edge devices in the cloud-edge collaborative environment making it difficult to quickly identify and respond to unknown attacks is solved. Through the centralized management and issuance of defense strategies, the effect of improving response speed and network security is achieved, and the problem that traditional static solidified defense measures and strategies in related technologies cannot meet the defense needs of unknown attacks is solved.

[0077] The embodiments of the present application also provide a computer-readable storage medium. The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0078] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.

Claims

1. A cloud-edge collaborative defense system for unknown attacks based on software-defined networking, The system includes: a main station deployed in the cloud and multiple edge stations deployed at the edge, the control plane of the main station includes a software-defined security platform, the software-defined security platform includes: a main controller, a security controller and a security component resource pool, and any edge station includes: an edge controller; the security controller is configured to receive network security information uploaded by the main controller and / or any edge controller, identify unknown attacks based on the network security information, generate corresponding defense strategies based on the identified unknown attacks, and send the defense strategies to the security component resource pool, the main controller and / or any edge controller; the security component resource pool is configured to virtualize security protection functions into security components, and configure security components for the main station and / or any edge station based on network security information or defense strategies.

2. The unknown attack cloud-edge collaborative defense system based on software-defined networking according to claim 1, wherein: The data plane of the main station includes an infrastructure layer. The software-defined security platform is based on the programmability of the software-defined network architecture and interacts with the infrastructure layer through a southbound interface. The infrastructure layer includes network devices. The main controller is configured to control and manage the network devices, and transmit and interact data with the edge controller through the network devices and preset communication protocols. The main controller is also configured to obtain real-time traffic and network topology at the network boundary of the main station, and the edge controller is configured to obtain real-time network traffic and security events of the corresponding edge station.

3. The unknown attack cloud-edge collaborative defense system based on software-defined networking according to claim 1, wherein: The edge station also includes edge intelligent devices, and the security components include: a security access component, a security access component and a security monitoring component. The security access component is configured to perform identity authentication and access control on the edge intelligent device; the security access component is configured to encrypt the network traffic of the edge intelligent device and use tunnel technology for data transmission; the security monitoring component is configured to monitor traffic, obtain security events and alarm information, and upload the security events and alarm information to the security controller.

4. The unknown attack cloud-edge collaborative defense system based on software-defined networking according to claim 1, wherein: The security controller is also configured to obtain an attack feature library and an attack defense strategy library, use a machine learning algorithm to identify unknown attacks based on the attack feature library and network security information, and use a machine learning algorithm to generate a defense strategy corresponding to the unknown attack based on the attack defense strategy library and the unknown attack.

5. The unknown attack cloud-edge collaborative defense system based on software-defined networking according to claim 2, wherein: The main controller is also configured to send defense strategies to network devices and dynamically adjust network configuration and behavior.

6. The unknown attack cloud-edge collaborative defense system based on software-defined networking according to claim 3, wherein: The edge intelligent device is configured to intercept and handle unknown attacks according to the defense strategy and the security components configured by the security controller, obtain unknown attack information, and send the unknown attack information to the edge intelligent devices of other edge stations.

7. A method for cloud-edge collaborative defense against unknown attacks based on software-defined networks, using the cloud-edge collaborative defense system against unknown attacks based on software-defined networks according to any one of claims 1 to 6, applied to a security controller, wherein: The method comprises: Receive network security information uploaded by the main controller and / or any edge controller; identifying unknown attacks based on the network security information; Generate corresponding defense strategies based on identified unknown attacks; Sending the defense strategy to a security component resource pool, a main controller, and / or any edge controller, wherein the security component resource pool is configured to virtualize security protection functions into security components; Control the security component resource pool to configure security components for the master station and / or any edge station based on network security information or defense policies.

8. The method for cloud-edge collaborative defense against unknown attacks based on software-defined networks according to claim 7, wherein: Receiving network security information uploaded by the main controller and / or any edge controller includes: Receive real-time traffic information and network topology of the master station network boundary uploaded by the main controller; And / or, receive real-time network traffic and security events of the corresponding edge station uploaded by any edge controller.

9. The method for cloud-edge collaborative defense against unknown attacks based on software-defined networks according to claim 8, wherein: The control security component resource pool configures security components for the master station and / or any edge station according to network security information or defense strategy, including: Control the security component resource pool to configure security components for the main site based on the defense strategy or real-time traffic information of the main site network boundary and the network topology; and / or, controlling the security component resource pool to configure security components for any edge station based on defense policies or real-time network traffic and security events of the edge station.

10. The method for cloud-edge collaborative defense against unknown attacks based on software-defined networks according to claim 9, wherein: After the control security component resource pool configures a security component for any edge station according to a defense strategy or real-time network traffic and security events of the edge station, the method further includes: Use security components to obtain security events and alarm information from any edge station; A machine learning algorithm is used to identify unknown attacks based on an attack signature library, network security information, the security events, and alarm information.

11. A computer-readable storage medium, wherein: The computer-readable storage medium stores computer instructions, which are used to enable a computer to execute the software-defined network-based unknown attack cloud-edge collaborative defense method according to any one of claims 7 to 10.

Citation Information

Patent Citations

  • Unknown attack cloud edge cooperative defense system and method based on software defined network

    CN118157964A

  • CRNET (China Railcom Net) sSafe cooperative defense system for whole course communication network

    CN101938459A

  • Wireless network security defense method based on software-defined security

    CN110366170A

  • SDN-oriented cloud and fog end collaborative defense framework method

    CN112383553A

  • Intrusion detection method based on edge cloud collaboration

    CN112887326A

Cited By

  • Trusted management and control network platform construction method and device, electronic equipment and storage medium

    CN120934918A