Cloud Tenant Network Security With Distributed Firewall Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security management systems in public clouds face challenges in effectively managing and controlling intra-cloud attack threats, leading to vulnerabilities in network security for cloud tenants.
Innovation Solution
Implementing a distributed firewall configuration that utilizes private network-level, subnet-level, and instance-level management and control units to manage network traffic based on access control policies, distributing these policies to instances without redirecting traffic, thereby enhancing security management and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized traffic processing cluster is used to detect and control network traffic, then network security management is simplified, but the system cannot effectively manage intra-cloud attack threats and cloud tenants must redirect traffic
Solution Approach 1:
The patent segments the centralized security management function into distributed firewall capabilities at multiple levels (private network-level, subnet-level, and instance-level management and control units). Each unit independently enforces access control policies for its scope, eliminating the need for traffic redirection to a central cluster while effectively managing intra-cloud threats through localized security enforcement.
2Reliability
If traffic is redirected to an independent traffic processing cluster for security detection, then centralized security control is achieved, but network traffic management becomes complex and time-consuming
Solution Approach 1:
The patent implements self-service security control where each management and control unit (private network-level, subnet-level, instance-level) autonomously detects and enforces access control policies for its own scope. This eliminates the need for time-consuming traffic redirection to external security clusters, as security detection and control are performed in-place by the distributed firewall units themselves.
3Ease of operation
If access control policies are enforced through centralized traffic detection, then security policy management is simplified, but the system lacks adaptability to different cloud tenant scenarios
Solution Approach 1:
The patent segments security management into hierarchical levels (private network-level, subnet-level, instance-level), allowing access control policies to be customized for different scopes and cloud tenant scenarios. Each level can independently manage policies appropriate to its domain, providing both ease of management through modular structure and adaptability through scenario-specific policy enforcement at each level.
Solution Approach 2:
The patent applies local quality by enabling each management and control unit to enforce access control policies tailored to its specific scope and requirements. Private network-level units handle broad tenant policies, subnet-level units manage intermediate security requirements, and instance-level units enforce granular application-specific rules, allowing each level to be optimized for its local context while maintaining overall policy consistency.
Data Source
AI summary
A network security management method is provided. In the method, configuration data that includes at least one access control policy for a network asset of a target cloud tenant is received. The network asset includes a private network, a subnet of the private network, and a cloud instance of the subnet. A network management and control unit and an access control policy set corresponding to the network management and control unit are determined according to the configuration data. The network management and control unit includes one or more of a private network-level management and control unit, a subnet-level management and control unit, and an instance-level management and control unit. The access control policy set of the network management and control unit is transmitted to the cloud instance that is associated with the network management and control unit to manage network traffic of the cloud instance.


