CN109918173A - Virtual machine health examination method and system based on openstack - Google Patents

Virtual machine health examination method and system based on openstack Download PDF

Info

Publication number
CN109918173A
CN109918173A CN201910168782.2A CN201910168782A CN109918173A CN 109918173 A CN109918173 A CN 109918173A CN 201910168782 A CN201910168782 A CN 201910168782A CN 109918173 A CN109918173 A CN 109918173A
Authority
CN
China
Prior art keywords
virus
virtual machine
openstack
killing
checking
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201910168782.2A
Other languages
Chinese (zh)
Other versions
CN109918173B (en
Inventor
赵程程
张立鹏
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Suzhou Wave Intelligent Technology Co Ltd
Original Assignee
Suzhou Wave Intelligent Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Suzhou Wave Intelligent Technology Co Ltd filed Critical Suzhou Wave Intelligent Technology Co Ltd
Priority to CN201910168782.2A priority Critical patent/CN109918173B/en
Publication of CN109918173A publication Critical patent/CN109918173A/en
Application granted granted Critical
Publication of CN109918173B publication Critical patent/CN109918173B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Abstract

The present invention provides a kind of virtual machine health examination method and system based on openstack, includes the following steps: to create virus base in openstack platform;Virus base is tied to firewall rule;Checking and killing virus is carried out to virtual machine in openstack platform.System includes virus base creation module, virus base binding module and checking and killing virus module.The present invention, which is realized, carries out checking and killing virus to virtual machine without logging in virtual machine in openstack platform, does not influence user's normal use, meanwhile, it finds virus processing in time, improves efficiency;The present invention is according to heterogeneous networks needs, using virus base template generation different virus library example, realizes that virus characteristic does heterogeneous networksization processing;The virtual machine security of present invention raising cloud environment.

Description

Virtual machine health examination method and system based on openstack
Technical field
The invention belongs to virtual machine health detection fields, and in particular to a kind of virtual machine health inspection based on openstack Checking method and system.
Background technique
OpenStack is the cloud computing management platform project of an open source, is combined completion by several main components Specific works.OpenStack supports almost all kinds of cloud environment, and project objective is to provide that implementation is simple, can expand on a large scale Exhibition, the cloud computing that abundant, standard is unified manage platform.
Virtual machine (Virtual Machine) refer to by software simulate with complete hardware system function, operate in Complete computer in one completely isolated environment.
For virtual system by the new virtual mirror image of the existing operating system of generation, it has true windows system complete The same function, into after virtual system, all operations are carried out inside this completely new independent virtual system, can be with Independently installed runs software saves data, possesses the independent table of oneself, and any influence will not be generated to real system, and And there is the type operating system that can flexibly switch between existing system and virtual image.Virtual system and traditional virtual Machine (Parallels Desktop, Vmware, VirtualBox, Virtual pc) difference is: virtual system will not reduce electricity The performance of brain, starting virtual system do not need to expend the time as starting windows system, and operation program is more convenient fast It is prompt;Virtual system can only simulate environment identical with existing operating system, and virtual machine can then simulate other kinds of behaviour Make system;And virtual machine needs to simulate the hardware instruction of bottom, so slower than virtual system in the application program speed of service Much.
With the growth of information explosion formula, cloud platform has obtained more and more concerns, and OpenStack is as a open source Cloud computing manage platform, obtain the favor of many companies, but in terms of the viral diagnosis of virtual machine, none system Method, virtual machine in use, if because the maloperation of user causes virtual machine to be poisoned, it is easy to cause virtual machine without Method using and by virus infection to other virtual machines.
This is the deficiencies in the prior art, therefore, in view of the above-mentioned drawbacks in the prior art, provides one kind and is based on The virtual machine health examination method and system of openstack, is necessary.
Summary of the invention
For the viral diagnosis aspect of the above-mentioned virtual machine of the prior art, the method for none system, virtual machine makes With in the process, if because the maloperation of user causes virtual machine to be poisoned, it is easy to virtual machine be caused not to be available and will be sick The defect of other virtual machines is arrived in poison infection, and the present invention provides a kind of virtual machine health examination method based on openstack and is System, to solve the above technical problems.
In a first aspect, the present invention provides a kind of virtual machine health examination method based on openstack, including walk as follows It is rapid:
S1. virus base is created in openstack platform;
S2. virus base is tied to firewall rule;
S3. checking and killing virus is carried out to virtual machine in openstack platform.The present invention is by openstack platform to virtual Machine carries out checking and killing virus, without logging in virtual machine, does not influence with normal use virtual machine.
Further, specific step is as follows by step S1:
S11. virus base is created in openstack platform;
It S12. is each virus setting characteristic item in virus base;
S13. timing updates virus base.Virus base is updated by timing and obtains most current virus, and the timeliness of checking and killing virus is provided Property, it prevents from lagging.
Further, the virus characteristic item includes whether activation and mode of operation.Virus base characteristic item includes but unlimited In above-mentioned project.
Further, specific step is as follows by step S2:
S21. viral library template is created;
S22. it is real to be set using virus base template generation virus base example according to the safety requirements of different segment for virus base The characteristic item of each virus in example;
S23. by all virus base exemplary applications to firewall;
S24. firewall policy is set, firewall uses corresponding virus base example according to network segment where virtual machine, to void Quasi- machine carries out checking and killing virus.When virus base example generates, characteristic viral in viral library template can be repaired according to demand Change, meets the virus base diversity requirement of heterogeneous networks.
Further, specific step is as follows by step S3:
S31. the checking and killing virus period is set;
S32. according to the checking and killing virus period of setting, in the starting of openstack platform to the checking and killing virus of virtual machine;
S33. network segment where successively obtaining each virtual machine;
S34. firewall uses corresponding virus base example according to network segment where virtual machine, carries out virus to virtual machine and looks into It kills.Checking and killing virus is carried out to virtual machine in the timing of openstack platform, meanwhile, the virtual machine of different segment uses different diseases Malicious killing standard, sets according to demand in advance.
Further, before step S32 further include:
S32`. network segment is selected, virtual machine is created.When creating virtual machine, network segment first where selection virtual machine, thus indirectly The checking and killing virus standard of the virtual machine is selected.
Second aspect, the present invention provide a kind of virtual machine health check system based on openstack, comprising:
Virus base creation module, for creating virus base in openstack platform;
Virus base binding module, for virus base to be tied to firewall rule;
Checking and killing virus module, for carrying out checking and killing virus to virtual machine in openstack platform.
Further, virus base creation module includes:
Virus base creating unit, for creating virus base in openstack platform;
Characteristic item setting unit, for being each virus setting characteristic item in virus base;
Virus base updating unit, for periodically updating virus base.
Further, virus base binding module includes:
Viral library template creating unit, for creating viral library template;
Virus base example generation unit, for the safety requirements according to different segment, using virus base template generation virus Library example sets the characteristic item of each virus in virus base example;
Virus base exemplary application unit is used for all virus base exemplary applications to firewall;
Firewall policy setup unit, for setting firewall policy, firewall uses phase according to network segment where virtual machine The virus base example answered carries out checking and killing virus to virtual machine.
Further, checking and killing virus module includes:
Killing period setting unit, for setting the checking and killing virus period;
Killing start unit starts in openstack platform to virtual machine for the checking and killing virus period according to setting Checking and killing virus;
Virtual machine network segment acquiring unit, for network segment where successively obtaining each virtual machine;
Checking and killing virus unit uses corresponding virus base example according to network segment where virtual machine for configuring firewall, right Virtual machine carries out checking and killing virus.
The beneficial effects of the present invention are,
The present invention, which is realized, carries out checking and killing virus to virtual machine without logging in virtual machine in openstack platform, does not influence User's normal use, meanwhile, it finds virus processing in time, improves efficiency;The present invention utilizes virus base according to heterogeneous networks needs Template generation different virus library example realizes that virus characteristic does heterogeneous networksization processing;The virtual machine of present invention raising cloud environment Safety.
In addition, design principle of the present invention is reliable, structure is simple, has very extensive application prospect.
It can be seen that compared with prior art, the present invention implementing with substantive distinguishing features outstanding and significant progress Beneficial effect be also obvious.
Detailed description of the invention
In order to more clearly explain the embodiment of the invention or the technical proposal in the existing technology, to embodiment or will show below There is attached drawing needed in technical description to be briefly described, it should be apparent that, for those of ordinary skill in the art Speech, without creative efforts, is also possible to obtain other drawings based on these drawings.
Fig. 1 is flow chart of the method for the present invention one;
Fig. 2 is flow chart of the method for the present invention two;
Fig. 3 is system schematic of the invention;
In figure, 1- virus base creation module;1.1- virus base creating unit;1.2- characteristic item setting unit;1.3- viral Library updating unit;2- virus base binding module;2.1- virus library template creating unit;2.2- virus base example generation unit; 2.3- virus base exemplary application unit;2.4- firewall policy setup unit;3- checking and killing virus module;3.1- killing cycle set Unit;3.2- killing start unit;3.3- virtual machine network segment acquiring unit;3.4- checking and killing virus unit.
Specific embodiment
Technical solution in order to enable those skilled in the art to better understand the present invention, below in conjunction with of the invention real The attached drawing in example is applied, technical scheme in the embodiment of the invention is clearly and completely described, it is clear that described implementation Example is only a part of the embodiment of the present invention, instead of all the embodiments.Based on the embodiments of the present invention, this field is common Technical staff's every other embodiment obtained without making creative work, all should belong to protection of the present invention Range.
Embodiment 1:
As shown in Figure 1, the present invention provides a kind of virtual machine health examination method based on openstack, including walk as follows It is rapid:
S1. virus base is created in openstack platform;Platform is provided with port, and disease can be arranged by port in tester Malicious library renewal time and virus characteristic item include network type virus signature in virus base;
S2. virus base is tied to firewall rule;In firewall rule to it is activated virus carry out level-one isolation and Level-one early warning, un-activation virus carry out second level isolation and second level early warning;Mode of operation to virus includes isolation containing virus text Part and deletion contain virus document, and the mode of operation in certain virus characteristic item is arranged by port by tester;
S3. checking and killing virus is carried out to virtual machine in openstack platform;It, will be sick in openstack platform scanner virtual machine Network type virus signature is compared with virtual-machine data in malicious library, carries out killing after determining virus.The present invention passes through Openstack platform carries out checking and killing virus to virtual machine, without logging in virtual machine, does not influence with normal use virtual machine.
Embodiment 2:
As depicted in figs. 1 and 2, the present invention provides a kind of virtual machine health examination method based on openstack, including such as Lower step:
S1. virus base is created in openstack platform;Specific step is as follows:
S11. virus base is created in openstack platform;
It S12. is each virus setting characteristic item in virus base;The virus characteristic item includes whether to activate and operate shape State;
S13. timing updates virus base;
S2. virus base is tied to firewall rule;Specific step is as follows:
S21. viral library template is created;
S22. it is real to be set using virus base template generation virus base example according to the safety requirements of different segment for virus base The characteristic item of each virus in example;
S23. by all virus base exemplary applications to firewall;
S24. firewall policy is set, firewall uses corresponding virus base example according to network segment where virtual machine, to void Quasi- machine carries out checking and killing virus;
S3. checking and killing virus is carried out to virtual machine in openstack platform;Specific step is as follows:
S31. the checking and killing virus period is set;
S32`. network segment is selected, virtual machine is created;
S32. according to the checking and killing virus period of setting, in the starting of openstack platform to the checking and killing virus of virtual machine;
S33. network segment where successively obtaining each virtual machine;
S34. firewall uses corresponding virus base example according to network segment where virtual machine, carries out virus to virtual machine and looks into It kills.
Virus base is updated by timing and obtains most current virus, and the timeliness of checking and killing virus is provided, prevents from lagging;Creation is virtual When machine, network segment first where selection virtual machine, thus the indirect selections checking and killing virus standard of the virtual machine;Virus base example is raw Cheng Shi can according to demand modify to characteristic viral in viral library template, meet the virus base diversity of heterogeneous networks Demand;Checking and killing virus is carried out to virtual machine in the timing of openstack platform, meanwhile, the virtual machine of different segment is using different Checking and killing virus standard, sets according to demand in advance.
Embodiment 3:
As shown in figure 3, the present invention provides a kind of virtual machine health check system based on openstack, comprising:
Virus base creation module 1, for creating virus base in openstack platform;Virus base creation module 1 includes:
Virus base creating unit 1.1, for creating virus base in openstack platform;
Characteristic item setting unit 1.2, for being each virus setting characteristic item in virus base;
Virus base updating unit 1.3, for periodically updating virus base;
Virus base binding module 2, for virus base to be tied to firewall rule;Virus base binding module 2 includes:
Viral library template creating unit 2.1, for creating viral library template;
Virus base example generation unit 2.2, for the safety requirements according to different segment, using virus base template generation disease Malicious library example sets the characteristic item of each virus in virus base example;
Virus base exemplary application unit 2.3 is used for all virus base exemplary applications to firewall;
Firewall policy setup unit 2.4, for setting firewall policy, firewall is used according to network segment where virtual machine Corresponding virus base example carries out checking and killing virus to virtual machine;
Checking and killing virus module 3, for carrying out checking and killing virus to virtual machine in openstack platform;Checking and killing virus module 3 is wrapped It includes:
Killing period setting unit 3.1, for setting the checking and killing virus period;
Killing start unit 3.2 starts in openstack platform to virtual for the checking and killing virus period according to setting The checking and killing virus of machine;
Virtual machine network segment acquiring unit 3.3, for network segment where successively obtaining each virtual machine;
Checking and killing virus unit 3.4 uses corresponding virus base example according to network segment where virtual machine for configuring firewall, Checking and killing virus is carried out to virtual machine.
Although by reference to attached drawing and combining the mode of preferred embodiment to the present invention have been described in detail, the present invention It is not limited to this.Without departing from the spirit and substance of the premise in the present invention, those of ordinary skill in the art can be to the present invention Embodiment carry out various equivalent modifications or substitutions, and these modifications or substitutions all should in covering scope of the invention/appoint What those familiar with the art in the technical scope disclosed by the present invention, can easily think of the change or the replacement, answer It is included within the scope of the present invention.Therefore, protection scope of the present invention is answered described is with scope of protection of the claims It is quasi-.

Claims (10)

1. a kind of virtual machine health examination method based on openstack, which comprises the steps of:
S1. virus base is created in openstack platform;
S2. virus base is tied to firewall rule;
S3. checking and killing virus is carried out to virtual machine in openstack platform.
2. the virtual machine health examination method based on openstack as described in claim 1, which is characterized in that step S1 tool Steps are as follows for body:
S11. virus base is created in openstack platform;
It S12. is each virus setting characteristic item in virus base;
S13. timing updates virus base.
3. the virtual machine health examination method based on openstack as claimed in claim 2, which is characterized in that the virus Characteristic item includes whether activation and mode of operation.
4. the virtual machine health examination method based on openstack as claimed in claim 2, which is characterized in that step S2 tool Steps are as follows for body:
S21. viral library template is created;
S22. it is set in virus base example according to the safety requirements of different segment using virus base template generation virus base example The characteristic item of each virus;
S23. by all virus base exemplary applications to firewall;
S24. firewall policy is set, firewall uses corresponding virus base example according to network segment where virtual machine, to virtual machine Carry out checking and killing virus.
5. the virtual machine health examination method based on openstack as claimed in claim 4, which is characterized in that step S3 tool Steps are as follows for body:
S31. the checking and killing virus period is set;
S32. according to the checking and killing virus period of setting, in the starting of openstack platform to the checking and killing virus of virtual machine;
S33. network segment where successively obtaining each virtual machine;
S34. firewall uses corresponding virus base example according to network segment where virtual machine, carries out checking and killing virus to virtual machine.
6. the virtual machine health examination method based on openstack as claimed in claim 5, which is characterized in that step S32 it Before further include:
S32`. network segment is selected, virtual machine is created.
7. a kind of virtual machine health check system based on openstack characterized by comprising
Virus base creation module (1), for creating virus base in openstack platform;
Virus base binding module (2), for virus base to be tied to firewall rule;
Checking and killing virus module (3), for carrying out checking and killing virus to virtual machine in openstack platform.
8. the virtual machine health check system based on openstack as claimed in claim 7, which is characterized in that virus base wound Modeling block (1) includes:
Virus base creating unit (1.1), for creating virus base in openstack platform;
Characteristic item setting unit (1.2), for being each virus setting characteristic item in virus base;
Virus base updating unit (1.3), for periodically updating virus base.
9. the virtual machine health check system based on openstack as claimed in claim 7, which is characterized in that virus base is tied up Cover half block (2) includes:
Viral library template creating unit (2.1), for creating viral library template;
Virus base example generation unit (2.2), for the safety requirements according to different segment, using virus base template generation virus Library example sets the characteristic item of each virus in virus base example;
Virus base exemplary application unit (2.3) is used for all virus base exemplary applications to firewall;
Firewall policy setup unit (2.4), for setting firewall policy, firewall uses phase according to network segment where virtual machine The virus base example answered carries out checking and killing virus to virtual machine.
10. the virtual machine health check system based on openstack as claimed in claim 7, which is characterized in that checking and killing virus Module (3) includes:
Killing period setting unit (3.1), for setting the checking and killing virus period;
Killing start unit (3.2) starts in openstack platform to virtual machine for the checking and killing virus period according to setting Checking and killing virus;
Virtual machine network segment acquiring unit (3.3), for network segment where successively obtaining each virtual machine;
Checking and killing virus unit (3.4) uses corresponding virus base example according to network segment where virtual machine for configuring firewall, right Virtual machine carries out checking and killing virus.
CN201910168782.2A 2019-03-06 2019-03-06 Openstack-based virtual machine health check method and system Active CN109918173B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910168782.2A CN109918173B (en) 2019-03-06 2019-03-06 Openstack-based virtual machine health check method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910168782.2A CN109918173B (en) 2019-03-06 2019-03-06 Openstack-based virtual machine health check method and system

Publications (2)

Publication Number Publication Date
CN109918173A true CN109918173A (en) 2019-06-21
CN109918173B CN109918173B (en) 2021-11-19

Family

ID=66963463

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910168782.2A Active CN109918173B (en) 2019-03-06 2019-03-06 Openstack-based virtual machine health check method and system

Country Status (1)

Country Link
CN (1) CN109918173B (en)

Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102082802A (en) * 2011-03-01 2011-06-01 陈彪 Behavior-based mobile terminal security protection system and method
CN102195987A (en) * 2011-05-31 2011-09-21 成都七巧软件有限责任公司 Distributed credibility authentication method and system thereof based on software product library
CN103067380A (en) * 2012-12-26 2013-04-24 北京启明星辰信息技术股份有限公司 Deployment configuration method and system of virtual safety device
US20140280961A1 (en) * 2013-03-15 2014-09-18 Frank Martinez System and method for a cloud computing abstraction with multi-tier deployment policy
US20140359749A1 (en) * 2013-05-31 2014-12-04 Catbird Networks, Inc. Systems and methods for dynamic network security control and configuration
CN104732148A (en) * 2015-04-14 2015-06-24 北京汉柏科技有限公司 Distributed searching and killing method and system
US20160072815A1 (en) * 2013-06-14 2016-03-10 Catbird Networks, Inc. Systems and methods for creating and modifying access control lists
CN105407078A (en) * 2015-10-20 2016-03-16 国网四川省电力公司信息通信公司 Data transmission method and data transmission system in electric power communication system
CN106203102A (en) * 2015-05-06 2016-12-07 北京金山安全管理系统技术有限公司 A kind of checking and killing virus method and device of the whole network terminal
CN106302466A (en) * 2016-08-17 2017-01-04 东软集团股份有限公司 The management method of a kind of fire wall and system
CN106612225A (en) * 2016-12-12 2017-05-03 武汉烽火信息集成技术有限公司 Openstack based agent deployment system and method

Patent Citations (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102082802A (en) * 2011-03-01 2011-06-01 陈彪 Behavior-based mobile terminal security protection system and method
CN102195987A (en) * 2011-05-31 2011-09-21 成都七巧软件有限责任公司 Distributed credibility authentication method and system thereof based on software product library
CN103067380A (en) * 2012-12-26 2013-04-24 北京启明星辰信息技术股份有限公司 Deployment configuration method and system of virtual safety device
US20140280961A1 (en) * 2013-03-15 2014-09-18 Frank Martinez System and method for a cloud computing abstraction with multi-tier deployment policy
US20140359749A1 (en) * 2013-05-31 2014-12-04 Catbird Networks, Inc. Systems and methods for dynamic network security control and configuration
US20160072815A1 (en) * 2013-06-14 2016-03-10 Catbird Networks, Inc. Systems and methods for creating and modifying access control lists
CN104732148A (en) * 2015-04-14 2015-06-24 北京汉柏科技有限公司 Distributed searching and killing method and system
CN106203102A (en) * 2015-05-06 2016-12-07 北京金山安全管理系统技术有限公司 A kind of checking and killing virus method and device of the whole network terminal
CN105407078A (en) * 2015-10-20 2016-03-16 国网四川省电力公司信息通信公司 Data transmission method and data transmission system in electric power communication system
CN106302466A (en) * 2016-08-17 2017-01-04 东软集团股份有限公司 The management method of a kind of fire wall and system
CN106612225A (en) * 2016-12-12 2017-05-03 武汉烽火信息集成技术有限公司 Openstack based agent deployment system and method

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
FRANCO CALLEGATI等: "Performance of Network Virtualization in cloud computing infrastructures: The OpenStack case", 《2014 IEEE 3RD INTERNATIONAL CONFERENCE ON CLOUD NETWORKING(CLOUDNET)》 *
徐绕山等: "云计算系统网络安全管理与技术防护", 《信息化研究》 *

Also Published As

Publication number Publication date
CN109918173B (en) 2021-11-19

Similar Documents

Publication Publication Date Title
CN109062655A (en) A kind of containerization cloud platform and server
CN105429806B (en) A kind of device and method of the network function virtualization based on data-driven
CN102103518B (en) System for managing resources in virtual environment and implementation method thereof
CN103051710B (en) A kind of virtual cloud platform management system
CN107967316A (en) A kind of method of data synchronization, equipment and computer-readable recording medium
CN106850260A (en) A kind of dispositions method and device of virtual resources management platform
CN102571698A (en) Access authority control method, system and device for virtual machine
CN102088367A (en) Method for quickly deploying in virtualization environment
CN107741875A (en) A kind of Different data management system
CN104951694A (en) Isolation method and apparatus for management virtual machine
CN103150202B (en) Method for allowing CloudStack to be compatible with virtual machine existing in vCenter
WO2018231901A1 (en) Detecting and managing recurring patterns in device and service configuration data
CN107294771A (en) A kind of efficient deployment system and application method suitable for big data cluster
CN110365552A (en) Test method, device, storage medium and processor
CN107153529A (en) A kind of embedded software development method, device and platform
CN109672740A (en) The method of deployment configuration information is obtained in a kind of large-scale cluster environment
CN107911251A (en) A kind of method for configuring network equipment, device and medium
CN112256439B (en) Service directory dynamic updating system and method based on cloud computing resource pool
CN110138876A (en) Task deployment method, apparatus, equipment and platform
CN104967532B (en) TOC technologies operational system and application process
CN110401729A (en) A kind of cloud platform server network moving method, system, terminal and storage medium
CN104484221A (en) Method for taking over existing vCenter cluster by CloudStack
CN109918173A (en) Virtual machine health examination method and system based on openstack
CN112596711A (en) Personalized authority management setting method and system based on Web system
CN105808354A (en) Method for establishing temporary Hadoop environment by utilizing WLAN (Wireless Local Area Network)

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant