Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /home/zhenxiangba/zhenxiangba.com/public_html/phproxy-improved-master/index.php on line 456
KR102745167B1 - Method and system for detecting and recovering firewall-related failure - Google Patents
[go: Go Back, main page]

KR102745167B1 - Method and system for detecting and recovering firewall-related failure - Google Patents

Method and system for detecting and recovering firewall-related failure Download PDF

Info

Publication number
KR102745167B1
KR102745167B1 KR1020230157250A KR20230157250A KR102745167B1 KR 102745167 B1 KR102745167 B1 KR 102745167B1 KR 1020230157250 A KR1020230157250 A KR 1020230157250A KR 20230157250 A KR20230157250 A KR 20230157250A KR 102745167 B1 KR102745167 B1 KR 102745167B1
Authority
KR
South Korea
Prior art keywords
firewall
information
dynamic
instance
failure recovery
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
KR1020230157250A
Other languages
Korean (ko)
Inventor
김윤석
박종일
Original Assignee
쿠팡 주식회사
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 쿠팡 주식회사 filed Critical 쿠팡 주식회사
Priority to KR1020230157250A priority Critical patent/KR102745167B1/en
Priority to PCT/KR2023/019234 priority patent/WO2025105560A1/en
Priority to TW112146095A priority patent/TW202520072A/en
Priority to KR1020240188130A priority patent/KR20250071211A/en
Application granted granted Critical
Publication of KR102745167B1 publication Critical patent/KR102745167B1/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0654Management of faults, events, alarms or notifications using network fault recovery
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/06Management of faults, events, alarms or notifications
    • H04L41/0654Management of faults, events, alarms or notifications using network fault recovery
    • H04L41/0663Performing the actions predefined by failover planning, e.g. switching to standby network elements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/08Monitoring or testing based on specific metrics, e.g. QoS, energy consumption or environmental parameters
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L43/00Arrangements for monitoring or testing data switching networks
    • H04L43/16Threshold monitoring
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • H04L61/5014Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • H04L63/0227Filtering policies
    • H04L63/0263Rule management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Business, Economics & Management (AREA)
  • Business, Economics & Management (AREA)
  • Environmental & Geological Engineering (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Debugging And Monitoring (AREA)
  • Computer And Data Communications (AREA)

Abstract

본 개시는 방화벽과 관련된 장애를 감지하고 복구하는 방법 및 시스템에 관한 것이다. 본 개시의 몇몇 실시예에 따른, 적어도 하나의 컴퓨팅 장치에 의하여 수행되는 방화벽과 관련된 장애 감지 및 복구 방법은, 클라우드 서비스 서버로부터 방화벽의 정책과 연관된 인스턴스에 대한 실제 IP 정보를 획득하는 단계, 상기 방화벽에 의하여 참조되는 상기 인스턴스 각각의 동적 IP 정보를 획득하되, 상기 동적 IP 정보는 외부 모듈에 의하여 제공된 것인, 단계, 상기 실제 IP 정보와 상기 동적 IP 정보를 비교하는 단계 및 상기 비교의 결과에 기초하여, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계를 포함할 수 있다.The present disclosure relates to a method and system for detecting and recovering from a failure related to a firewall. According to some embodiments of the present disclosure, a method for detecting and recovering from a failure related to a firewall, performed by at least one computing device, may include the steps of: obtaining real IP information for an instance associated with a policy of the firewall from a cloud service server; obtaining dynamic IP information of each of the instances referenced by the firewall, wherein the dynamic IP information is provided by an external module; comparing the real IP information with the dynamic IP information; and determining whether or not failure recovery related to the firewall is necessary based on a result of the comparison.

Description

방화벽과 관련된 장애 감지 및 복구 방법 및 시스템{METHOD AND SYSTEM FOR DETECTING AND RECOVERING FIREWALL-RELATED FAILURE}METHOD AND SYSTEM FOR DETECTING AND RECOVERING FIREWALL-RELATED FAILURE

본 개시는 방화벽과 관련된 장애를 감지하고 복구하는 방법 및 시스템에 관한 것이다. 보다 자세하게는, 방화벽의 정책과 연관된 인스턴스와 외부 모듈에 의해 제공되는 동적 IP 정보를 이용하여 방화벽과 관련된 장애를 감지하고 복구하는 방법 및 그 방법이 적용된 시스템에 관한 것이다.The present disclosure relates to a method and system for detecting and recovering from a failure related to a firewall. More specifically, the present disclosure relates to a method for detecting and recovering from a failure related to a firewall by using an instance associated with a policy of the firewall and dynamic IP information provided by an external module, and a system to which the method is applied.

방화벽은 방화벽의 내부로 인입되는 패킷들 또는 내부망에서 외부로 송신되는 패킷들에 대한 복수의 필터링 룰(Filtering Rule)들을 기반으로 동작할 수 있다. 이때, 복수의 필터링 룰들은 필터링의 대상이 되는 패킷의 조건을 정의하는 것이 일반적이다. 예를 들면, IP 대역을 기준으로 필터링 여부가 결정될 수 있다.A firewall can operate based on multiple filtering rules for packets entering the firewall or packets transmitted from the internal network to the outside. At this time, multiple filtering rules usually define the conditions of packets that are the target of filtering. For example, whether or not to filter can be determined based on the IP band.

다양한 상황에 따라 방화벽의 내부 또는 외부에 위치한 인스턴스의 IP는 동적으로 변경될 수 있다. 예를 들어, 클라우드 서비스 상의 인스턴스의 IP는 해당 인스턴스의 리셋 또는 클라우드 서비스의 자체적인 장애 복구나 소프트웨어 배포로 인하여 변경될 수 있다. 이때, 인스턴스의 IP가 변동되는 경우, 기존의 방화벽 룰 내지 정책이 무력화될 수 있다. 이에, 종래의 기술에 따르면, 별도의 IP 동기화 모듈을 이용하여 특정 인스턴스의 변동된 IP 주소를 동기화 하는 프로세스를 통해, 방화벽의 룰 내지 정책과 관련된 인스턴스의 IP가 변동되더라도 방화벽이 정상적으로 동작하도록 하고 있다.The IP of an instance located inside or outside the firewall may change dynamically depending on various situations. For example, the IP of an instance on a cloud service may change due to a reset of the instance, a self-failure recovery of the cloud service, or a software deployment. In this case, if the IP of the instance changes, the existing firewall rule or policy may be invalidated. Accordingly, according to the conventional technology, a process of synchronizing the changed IP address of a specific instance using a separate IP synchronization module is used to ensure that the firewall operates normally even if the IP of an instance related to the firewall rule or policy changes.

그런데, 별도의 IP 동기화 모듈에 장애가 발생하는 경우, 변동된 인스턴스의 IP 주소가 반영되지 않을 수 있고, 이에 따라 방화벽이 정상적으로 작동하지 못하는 상황이 발생할 수 있다. 즉, 방화벽이 비정상적으로 패킷들을 차단하는 상황이 발생될 수 있다. However, if a separate IP synchronization module fails, the IP address of the changed instance may not be reflected, which may cause the firewall to not function properly. In other words, the firewall may abnormally block packets.

이에, IP 동기화 모듈의 기능에 장애가 발생하더라도 방화벽이 정상적으로 동작할 수 있도록 지원할 수 있는 기술이 요구된다.Accordingly, a technology is required that can support normal operation of the firewall even if a malfunction occurs in the function of the IP synchronization module.

한국공개특허 제10-2017-0053433호(2017.05.16 공개)Korean Patent Publication No. 10-2017-0053433 (Published on May 16, 2017)

본 개시가 해결하고자 하는 기술적 과제는 방화벽과 관련된 장애를 감지하고, 장애를 자동으로 복구할 수 있는 방법 및 시스템을 제공하는 것이다.The technical problem that the present disclosure seeks to solve is to provide a method and system capable of detecting a failure related to a firewall and automatically recovering the failure.

본 개시가 해결하고자 하는 다른 기술적 과제는, 클라우드 서비스 서버로부터 획득한 인스턴스의 IP 정보와 외부 모듈로부터 획득한 동적 IP 정보를 이용하여 방화벽과 관련된 장애를 감지할 수 있는 방법 및 시스템을 제공하는 것이다.Another technical problem that the present disclosure seeks to solve is to provide a method and system capable of detecting a failure related to a firewall by using IP information of an instance obtained from a cloud service server and dynamic IP information obtained from an external module.

본 개시가 해결하고자 하는 또 다른 기술적 과제는, 클라우드 서비스 서버로부터 획득한 인스턴스의 태그 정보와 외부 모듈로부터 획득한 동적 IP 정보의 태그 정보를 이용하여 방화벽과 관련된 장애를 감지할 수 있는 방법 및 시스템을 제공하는 것이다.Another technical problem that the present disclosure seeks to solve is to provide a method and system capable of detecting a failure related to a firewall by using tag information of an instance obtained from a cloud service server and tag information of dynamic IP information obtained from an external module.

본 개시의 기술적 과제들은 이상에서 언급한 기술적 과제들로 제한되지 않으며, 언급되지 않은 또 다른 기술적 과제들은 아래의 기재로부터 본 개시의 기술분야에서의 통상의 기술자에게 명확하게 이해될 수 있을 것이다.The technical problems of the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art from the description below.

상기 기술적 과제를 해결하기 위한 본 개시의 일 실시예에 따른 방화벽과 관련된 장애 감지 및 복구 방법은, 클라우드 서비스 서버로부터 방화벽의 정책과 연관된 인스턴스에 대한 실제 IP 정보를 획득하는 단계, 상기 방화벽에 의하여 참조되는 상기 인스턴스 각각의 동적 IP 정보를 획득하는 단계, 상기 실제 IP 정보와 상기 동적 IP 정보를 비교하는 단계 및 상기 비교의 결과에 기초하여, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계를 포함할 수 있다. 이때, 상기 동적 IP 정보는 외부 모듈에 의하여 제공된 것일 수 있다.According to one embodiment of the present disclosure for solving the above technical problem, a method for detecting and recovering a failure related to a firewall may include a step of obtaining actual IP information for an instance associated with a policy of the firewall from a cloud service server, a step of obtaining dynamic IP information for each of the instances referenced by the firewall, a step of comparing the actual IP information with the dynamic IP information, and a step of determining whether or not failure recovery related to the firewall is necessary based on a result of the comparison. In this case, the dynamic IP information may be provided by an external module.

일 실시예에서, 상기 동적 IP 정보는 IP 정보 동기화 모듈에 의해 주기적으로 업데이트되는 정보일 수 있다.In one embodiment, the dynamic IP information may be information that is periodically updated by an IP information synchronization module.

일 실시예에서, 상기 실제 IP 정보와 상기 동적 IP 정보를 비교하는 단계는 상기 실제 IP 정보와 상기 동적 IP 정보를 제1 주기마다 비교하는 단계를 포함할 수 있다.In one embodiment, the step of comparing the actual IP information and the dynamic IP information may include the step of comparing the actual IP information and the dynamic IP information every first period.

일 실시예에서, 상기 제1 주기는 상기 인스턴스가 연관된 정책에 대하여 사전에 설정된 우선순위에 기초하여 상이하게 설정되는 값일 수 있다.In one embodiment, the first period may be a value that is set differently based on a pre-established priority for a policy to which the instance is associated.

일 실시예에서, 상기 제1 주기는 상기 인스턴스에 대하여 사전에 설정된 우선순위에 기초하여 상이하게 설정되는 값일 수 있다.In one embodiment, the first period may be a value set differently based on a priority set in advance for the instance.

일 실시예에서, 방화벽과 관련된 장애 감지 및 복구 방법은, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계 이후에, 상기 판단의 결과, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단된 경우, 장애 복구 프로세스를 자동으로 실행하는 단계를 더 포함할 수 있다.In one embodiment, a method for detecting and recovering a failure related to a firewall may further include, after the step of determining whether failure recovery related to the firewall is necessary, a step of automatically executing a failure recovery process if, as a result of the determination, it is determined that failure recovery related to the firewall is necessary.

일 실시예에서, 상기 장애 복구 프로세스는 상기 방화벽의 동적 IP 정보의 IP 대역을 기초로 생성된 예비 정책을 이용하여 수행되는 것일 수 있다.In one embodiment, the failure recovery process may be performed using a standby policy generated based on an IP band of dynamic IP information of the firewall.

상기 기술적 과제를 해결하기 위한 본 개시의 다른 실시예에 따른 방화벽과 관련된 장애 감지 및 복구 방법은, 클라우드 서비스 서버로부터 방화벽의 정책과 연관된 타겟 인스턴스의 제1 태그 정보를 획득하는 단계, 상기 방화벽에 의하여 참조되는 상기 타겟 인스턴스 각각의 동적 IP 정보의 제2 태그 정보를 획득하는 단계, 상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계 및 상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계를 포함할 수 있다. 이때, 상기 동적 IP 정보는 외부 모듈에 의하여 제공되는 것일 수 있다.According to another embodiment of the present disclosure for solving the above technical problem, a method for detecting and recovering a failure related to a firewall may include a step of obtaining first tag information of a target instance associated with a policy of the firewall from a cloud service server, a step of obtaining second tag information of dynamic IP information of each of the target instances referenced by the firewall, a step of comparing the first tag information with the second tag information, and a step of determining whether failure recovery related to the firewall is necessary based on a result of the comparison. In this case, the dynamic IP information may be provided by an external module.

일 실시예에서, 상기 타겟 인스턴스의 제1 태그 정보는 타겟 인스턴스의 스케일 아웃 가능 여부에 대한 정보를 포함할 수 있다.In one embodiment, the first tag information of the target instance may include information on whether the target instance is scalable.

일 실시예에서, 상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계는 상기 제1 태그 정보와 상기 제2 태그 정보를 제1 주기마다 비교하는 단계를 포함할 수 있다.In one embodiment, the step of comparing the first tag information and the second tag information may include the step of comparing the first tag information and the second tag information every first period.

일 실시예에서, 상기 제1 태그 정보와 상기 제2 태그 정보를 제1 주기마다 비교하는 단계는 상기 제1 주기마다 상기 타겟 인스턴스의 개수와 상기 동적 IP 정보의 개수의 차이를 산출하는 단계를 포함할 수 있다. 또한, 상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는 상기 타겟 인스턴스가 스케일 변동이 가능한 인스턴스인 경우, 상기 타겟 인스턴스의 개수와 상기 동적 IP 정보의 개수의 차이가 발생한 시점이 제1 기간동안 기준 횟수 이상 발생하면 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 포함할 수 있다.In one embodiment, the step of comparing the first tag information and the second tag information for each first period may include the step of calculating the difference between the number of target instances and the number of dynamic IP information for each first period. In addition, the step of determining whether or not a failure recovery related to the firewall is necessary based on the result of the comparison may include the step of determining that a failure recovery related to the firewall is necessary if the time at which a difference between the number of target instances and the number of dynamic IP information occurs more than a reference number of times during a first period when the target instance is an instance capable of being scaled.

일 실시예에서, 상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는, 상기 타겟 인스턴스가 스케일 변동이 불가능한 인스턴스인 경우, 상기 타겟 인스턴스의 개수와 상기 동적 IP 정보의 개수의 차이가 발생한 시점이 제2 기간동안 기준 횟수 이상의 차이가 발생하면 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 더 포함할 수 있다. 이때, 상기 제2 기간은 상기 제1 기간보다 짧을 수 있다.In one embodiment, the step of determining whether or not a failure recovery related to the firewall is necessary based on the result of the comparison may further include the step of determining that a failure recovery related to the firewall is necessary if, in the case where the target instance is an instance that cannot be scaled, a difference occurs between the number of target instances and the number of dynamic IP information more than a reference number of times during a second period. In this case, the second period may be shorter than the first period.

일 실시예에서, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는, 네트워크 트래픽에 대한 모니터링 결과를 더 고려하여, 제1 기간 동안의 네트워크 트래픽이 기준치 이하인 경우, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 더 포함할 수 있다.In one embodiment, the step of determining whether a failure recovery related to the firewall is necessary may further include a step of determining that a failure recovery related to the firewall is necessary if the network traffic for the first period is below a reference value by further considering the monitoring results for network traffic.

일 실시예에서, 상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계는, 상기 제1 태그 정보와 상기 제2 태그 정보를 이용하여 상기 타겟 인스턴스와 상기 동적 IP 정보의 합집합의 원소 개수와 상기 타겟 인스턴스와 상기 동적 IP 정보의 교집합의 원소 개수를 산출하는 단계를 포함할 수 있다. 또한, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는, 상기 합집합의 원소 개수와 상기 교집합의 원소 개수가 일치하지 않는 경우, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 포함할 수 있다.In one embodiment, the step of comparing the first tag information and the second tag information may include the step of calculating the number of elements of the union of the target instance and the dynamic IP information and the number of elements of the intersection of the target instance and the dynamic IP information using the first tag information and the second tag information. In addition, the step of determining whether a failure recovery related to the firewall is necessary may include the step of determining that a failure recovery related to the firewall is necessary if the number of elements of the union and the number of elements of the intersection do not match.

일 실시예에서, 상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계는, 상기 제1 태그 정보와 상기 제2 태그 정보를 이용하여 상기 타겟 인스턴스와 상기 동적 IP 정보의 차집합의 원소 개수를 산출하는 단계를 포함할 수 있다. 또한, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는, 상기 차집합의 원소 개수가 기준치 이상인 경우, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 포함할 수 있다.In one embodiment, the step of comparing the first tag information and the second tag information may include the step of calculating the number of elements of the difference set between the target instance and the dynamic IP information using the first tag information and the second tag information. In addition, the step of determining whether a failure recovery related to the firewall is necessary may include the step of determining that a failure recovery related to the firewall is necessary if the number of elements of the difference set is greater than or equal to a threshold value.

일 실시예에서, 방화벽과 관련된 장애 감지 및 복구 방법은, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계 이후에, 상기 판단의 결과, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단된 경우, 장애 복구 프로세스를 자동으로 실행하는 단계를 더 포함할 수 있다.In one embodiment, a method for detecting and recovering a failure related to a firewall may further include, after the step of determining whether failure recovery related to the firewall is necessary, a step of automatically executing a failure recovery process if, as a result of the determination, it is determined that failure recovery related to the firewall is necessary.

일 실시예에서, 상기 장애 복구 프로세스는, 상기 방화벽의 동적 IP 정보의 IP 대역을 기초로 생성된 예비 정책을 이용하여 수행되는 것일 수 있다.In one embodiment, the failure recovery process may be performed using a standby policy generated based on an IP band of dynamic IP information of the firewall.

상기 기술적 과제를 해결하기 위한 본 개시의 또 다른 실시예에 따른 방화벽과 관련된 장애 감지 및 복구 시스템은, 프로세서 및 명령어를 저장하는 메모리를 포함할 수 있고, 상기 명령어는 상기 프로세서에 의해 실행될 때, 상기 프로세서로 하여금, 클라우드 서비스 서버로부터 방화벽의 정책과 연관된 인스턴스에 대한 실제 IP 정보를 획득하는 동작, 상기 방화벽에 의하여 참조되는 상기 인스턴스 각각의 동적 IP 정보를 획득하는 동작, 상기 실제 IP 정보와 상기 동적 IP 정보를 비교하는 동작 및 상기 비교의 결과에 기초하여, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 동작을 수행하도록 할 수 있다. 이때, 상기 동적 IP 정보는 외부 모듈에 의하여 제공된 것일 수 있다. According to another embodiment of the present disclosure for solving the above technical problem, a system for detecting and recovering a failure related to a firewall may include a processor and a memory storing instructions, which, when executed by the processor, may cause the processor to perform operations of obtaining actual IP information for an instance associated with a policy of the firewall from a cloud service server, obtaining dynamic IP information of each of the instances referenced by the firewall, comparing the actual IP information with the dynamic IP information, and determining whether or not failure recovery related to the firewall is necessary based on a result of the comparison. In this case, the dynamic IP information may be provided by an external module.

상기 기술적 과제를 해결하기 위한 본 개시의 또 다른 실시예에 따른 방화벽과 관련된 장애 감지 및 복구 시스템은, 프로세서 및 명령어를 저장하는 메모리를 포함할 수 있고, 상기 명령어는 상기 프로세서에 의해 실행될 때, 상기 프로세서로 하여금, 클라우드 서비스 서버로부터 방화벽의 정책과 연관된 타겟 인스턴스의 제1 태그 정보를 획득하는 동작, 상기 방화벽에 의하여 참조되는 상기 타겟 인스턴스 각각의 동적 IP 정보의 제2 태그 정보를 획득하는 동작, 상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 동작 및 상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 동작을 수행하도록 할 수 있다. 이때, 상기 동적 IP 정보는 외부 모듈에 의하여 제공되는 것일 수 있다.According to another embodiment of the present disclosure for solving the above technical problem, a system for detecting and recovering a failure related to a firewall may include a processor and a memory storing a command, wherein the command, when executed by the processor, may cause the processor to perform an operation of obtaining first tag information of a target instance associated with a policy of the firewall from a cloud service server, an operation of obtaining second tag information of dynamic IP information of each of the target instances referenced by the firewall, an operation of comparing the first tag information with the second tag information, and an operation of determining whether failure recovery related to the firewall is necessary based on a result of the comparison. In this case, the dynamic IP information may be provided by an external module.

본 실시예에 따르면, 클라우드 서비스 서버로부터 획득한 타겟 인스턴스의 IP 정보를 참조함으로써 방화벽과 관련된 장애 복구가 필요한지 여부가 정확하게 판단될 수 있다.According to this embodiment, it can be accurately determined whether a firewall-related failure recovery is necessary by referring to the IP information of the target instance obtained from the cloud service server.

본 실시예에 따르면, 클라우드 서비스 서버로부터 획득한 타겟 인스턴스의 태그 정보를 참조함으로써 방화벽과 관련된 장애 복구가 필요한지 여부가 정확하게 판단될 수 있다. According to this embodiment, it can be accurately determined whether a firewall-related failure recovery is necessary by referring to the tag information of the target instance obtained from the cloud service server.

본 실시예에 따르면, 장애 복구 프로세스가 사용자의 수동 개입 없이 자동으로 실행됨으로써 사용자의 편의성 및 만족도가 제고될 수 있다. 또한, 사용자가 수동으로 장애 복구 프로세스를 수행함으로 인하여 소모되는 물리적 자원 및 시간적 자원을 절약할 수 있다.According to this embodiment, the user's convenience and satisfaction can be improved because the failure recovery process is automatically executed without the user's manual intervention. In addition, physical resources and time resources consumed due to the user manually performing the failure recovery process can be saved.

본 실시예에 따르면, 인스턴스의 태그 정보를 참조하여 획득한 스케일 아웃이 가능 여부의 정보에 기초하여 모니터링 주기를 상이하게 설정할 수 있고, 스케일 아웃이 불가능한 인스턴스의 경우에는 인스턴스와 연관된 모니터링 기간을 짧게 설정함으로써 불필요한 모니터링에 의해 소모되는 시스템 자원을 절약할 수 있다.According to this embodiment, the monitoring cycle can be set differently based on information on whether scale-out is possible, which is obtained by referencing tag information of the instance, and in the case of an instance for which scale-out is not possible, the monitoring period associated with the instance can be set short, thereby saving system resources consumed by unnecessary monitoring.

본 실시예에 따르면, 결제 서비스와 관련된 방화벽 정책이 적용될 경우, 방화벽과 관련된 장애가 발생하더라도 예비 정책을 이용한 장애 복구 프로세스가 자동으로 실행됨으로써 결제 서비스의 연속성이 보장될 수 있다.According to this embodiment, when a firewall policy related to a payment service is applied, even if a failure related to the firewall occurs, the continuity of the payment service can be ensured by automatically executing a failure recovery process using a standby policy.

도 1은 본 개시의 일 실시예에 따른, 방화벽과 관련된 장애 감지 및 복구 방법을 설명하기 위한 예시도이다.
도 2는 도 1에 도시된 일부 동작을 설명하기 위한 예시도이다.
도 3은 본 개시의 다른 실시예에 따른, 방화벽과 관련된 장애 감지 및 복구 방법을 설명하기 위한 예시도이다.
도 4는 도 3에 도시된 일부 동작을 설명하기 위한 상세 순서도이다.
도 5는 도 4를 참조하여 설명한 일부 동작을 설명하기 위한 예시도이다.
도 6은 본 개시의 몇몇 실시예에서 참조될 수 있는, 방화벽과 관련된 장애 복구가 필요한 것으로 판단되는 경우를 설명하기 위한 예시도이다.
도 7은 도 6을 참조하여 설명한 일부 동작을 설명하기 위한 예시도이다.
도 8은 본 개시의 몇몇 실시예들에 따른 방화벽과 관련된 장애 감지 및 복구 시스템의 하드웨어 구성도이다.
FIG. 1 is an exemplary diagram illustrating a method for detecting and recovering a failure related to a firewall according to one embodiment of the present disclosure.
Figure 2 is an exemplary diagram for explaining some of the operations illustrated in Figure 1.
FIG. 3 is an exemplary diagram illustrating a method for detecting and recovering a failure related to a firewall according to another embodiment of the present disclosure.
Figure 4 is a detailed flowchart for explaining some of the operations illustrated in Figure 3.
Figure 5 is an example diagram for explaining some of the operations described with reference to Figure 4.
FIG. 6 is an exemplary diagram illustrating a case where it is determined that a firewall-related failure recovery is necessary, which may be referenced in some embodiments of the present disclosure.
Figure 7 is an example diagram for explaining some of the operations described with reference to Figure 6.
FIG. 8 is a hardware configuration diagram of a fault detection and recovery system related to a firewall according to some embodiments of the present disclosure.

이하, 첨부된 도면을 참조하여 본 개시의 바람직한 실시예들을 상세히 설명한다. 본 발명의 이점 및 특징, 그리고 그것들을 달성하는 방법은 첨부되는 도면과 함께 상세하게 후술되어 있는 실시예들을 참조하면 명확해질 것이다. 그러나 본 발명의 기술적 사상은 이하의 실시예들에 한정되는 것이 아니라 서로 다른 다양한 형태로 구현될 수 있으며, 단지 이하의 실시예들은 본 발명의 기술적 사상을 완전하도록 하고, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 본 발명의 범주를 완전하게 알려주기 위해 제공되는 것이며, 본 발명의 기술적 사상은 청구항의 범주에 의해 정의될 뿐이다.Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. The advantages and features of the present invention, and the methods for achieving them, will become apparent with reference to the embodiments described in detail below together with the accompanying drawings. However, the technical idea of the present invention is not limited to the following embodiments, but may be implemented in various different forms, and the following embodiments are provided only to complete the technical idea of the present invention and to fully inform a person having ordinary skill in the art to which the present invention pertains of the scope of the present invention, and the technical idea of the present invention is defined only by the scope of the claims.

본 개시를 설명함에 있어, 관련된 공지 구성 또는 기능에 대한 구체적인 설명이 본 발명의 요지를 흐릴 수 있다고 판단되는 경우에는 그 상세한 설명은 생략한다.In describing the present disclosure, if it is determined that a detailed description of a related known configuration or function may obscure the gist of the present invention, the detailed description will be omitted.

다른 정의가 없다면, 이하의 실시예들에서 사용되는 용어(기술 및 과학적 용어를 포함)는 본 개시가 속한 기술분야에서 통상의 지식을 가진 자에게 공통적으로 이해될 수 있는 의미로 사용될 수 있으나, 이는 관련 분야에 종사하는 기술자의 의도 또는 판례, 새로운 기술의 출현 등에 따라 달라질 수도 있다. 본 개시에서 사용된 용어는 실시예들을 설명하기 위한 것이며 본 개시의 범주를 제한하고자 하는 것은 아니다.Unless otherwise defined, terms (including technical and scientific terms) used in the following examples may be used with a meaning that can be commonly understood by a person of ordinary skill in the art to which this disclosure belongs, but this may vary depending on the intention of a technician engaged in the relevant field, case law, the emergence of new technologies, etc. The terminology used in this disclosure is for the purpose of describing the embodiments and is not intended to limit the scope of this disclosure.

이하의 실시예들에서 사용되는 단수의 표현은 문맥상 명백하게 단수인 것으로 특정되지 않는 한, 복수의 개념을 포함한다. 또한, 복수의 표현은 문맥상 명백하게 복수인 것으로 특정되지 않는 한, 단수의 개념을 포함한다.In the examples below, singular expressions used include plural concepts unless the context clearly specifies that they are singular. In addition, plural expressions include singular concepts unless the context clearly specifies that they are plural.

또한, 이하의 실시예들에서 사용되는 제1, 제2, A, B, (a), (b) 등의 용어는 어떤 구성요소를 다른 구성요소와 구별하기 위해 사용되는 것일 뿐, 그 용어에 의해 해당 구성요소의 본질이나 차례 또는 순서 등이 한정되지는 않는다.In addition, terms such as first, second, A, B, (a), (b), etc. used in the following embodiments are only used to distinguish one component from another, and the nature, order, or sequence of the corresponding component is not limited by the terms.

이하, 첨부된 도면들을 참조하여 본 개시의 다양한 실시예들에 대하여 상세하게 설명한다.Hereinafter, various embodiments of the present disclosure will be described in detail with reference to the attached drawings.

도 1은 본 개시의 일 실시예에 따른, 방화벽과 관련된 장애 감지 및 복구 방법을 설명하기 위한 예시도이다. 단, 이는 본 개시의 목적을 달성하기 위한 바람직한 실시예일뿐이며, 필요에 따라 일부 단계가 추가되거나 삭제될 수 있음은 물론이다. 참고로, 도 1은 방화벽과 관련된 장애를 감지하는 모듈이 포함된 제1 서버에 의해 수행되는 방법의 단계/동작들을 나타내고 있다. 따라서, 이하의 설명들에서, 특정 단계/동작의 주체가 생략된 경우, 제1 서버에 의해 수행되는 것으로 이해될 수 있다.FIG. 1 is an exemplary diagram for explaining a method for detecting and recovering a failure related to a firewall according to an embodiment of the present disclosure. However, this is only a preferred embodiment for achieving the purpose of the present disclosure, and it is to be understood that some steps may be added or deleted as necessary. For reference, FIG. 1 shows steps/operations of a method performed by a first server including a module for detecting a failure related to a firewall. Therefore, in the following descriptions, if a subject of a specific step/operation is omitted, it can be understood that it is performed by the first server.

도 1에 예시된 바와 같이, 본 개시의 일 실시예에 따른, 방화벽과 관련된 장애 감지 및 복구 방법은 클라우드 서비스 서버로부터 방화벽의 정책과 연관된 인스턴스에 대한 실제 IP 정보를 획득하는 단계 S100에서 시작될 수 있다. 이때, 상기 방화벽의 정책은 방화벽의 룰에 포함된 복수의 정책들 중 하나의 정책을 의미할 수 있다. 또한, 상기 인스턴스는 가상화된 컴퓨팅 자원이 할당된 가상 머신(Virtual Machine), 컨테이너 등을 포함할 수 있다.As illustrated in FIG. 1, a method for detecting and recovering a failure related to a firewall according to an embodiment of the present disclosure may begin with step S100 of obtaining actual IP information for an instance associated with a policy of the firewall from a cloud service server. At this time, the policy of the firewall may mean one of a plurality of policies included in a rule of the firewall. In addition, the instance may include a virtual machine, a container, etc. to which virtualized computing resources are allocated.

한편, 상기 인스턴스에 대한 실제 IP 정보는 클라우드 서비스 서버로부터 직접 획득한 정보라는 점에서, 후술되는 인스턴스의 동적 IP 정보와는 구분될 수 있다. 즉, 클라우드 서비스 서버로부터 획득한 상기 실제 IP 정보와 후술되는 인스턴스의 동적 IP 정보가 상이할 경우, 상기 동적 IP 정보에 문제 내지 오류가 있는 것으로 판단될 수 있다.Meanwhile, the actual IP information for the instance can be distinguished from the dynamic IP information of the instance described below in that it is information obtained directly from the cloud service server. That is, if the actual IP information obtained from the cloud service server is different from the dynamic IP information of the instance described below, it can be determined that there is a problem or error in the dynamic IP information.

단계 S200에서, 제1 서버는 방화벽에 의하여 참조되는 인스턴스 각각의 동적 IP 정보를 획득할 수 있다. 이때, 상기 동적 IP 정보는 외부 모듈에 의하여 제공된 것일 수 있다. 보다 자세하게는, 상기 외부 모듈은 IP 정보를 동기화 하는 모듈(i.e. IP 정보 동기화 모듈)일 수 있다. 또한, 상기 동적 IP 정보는 IP 정보 동기화 모듈에 의해 주기적으로 업데이트되는 정보일 수 있다. 즉, IP 정보 동기화 모듈에 특정한 문제가 발생하지 않는다면, 동적 IP 정보는 주기적으로 업데이트되므로, 클라우드 서비스 서버로부터 획득한 인스턴스의 실제 IP 정보와 동적 IP 정보는 동일한 것으로 이해될 수 있다.In step S200, the first server can obtain dynamic IP information of each instance referenced by the firewall. At this time, the dynamic IP information may be provided by an external module. More specifically, the external module may be a module that synchronizes IP information (i.e., an IP information synchronization module). In addition, the dynamic IP information may be information that is periodically updated by the IP information synchronization module. That is, unless a specific problem occurs in the IP information synchronization module, the dynamic IP information is periodically updated, so the actual IP information of the instance obtained from the cloud service server and the dynamic IP information may be understood to be the same.

단계 S300에서, 제1 서버는 단계 S100과 단계 S200을 통해 획득한 인스턴스에 대한 실제 IP 정보와 동적 IP 정보를 비교할 수 있다. 이때, 상기 IP 정보와 상기 동적 IP 정보는 사전에 설정된 제1 주기마다 비교될 수 있다. 다만, 상기 제1 주기는 사전에 설정되어 고정된 값이 아닌, 경우에 따라 상이한 값일 수 있다.In step S300, the first server can compare the actual IP information for the instance obtained through steps S100 and S200 with the dynamic IP information. At this time, the IP information and the dynamic IP information can be compared at each first cycle set in advance. However, the first cycle may not be a fixed value set in advance, but may be a different value depending on the case.

일 실시예에서, 상기 제1 주기는 인스턴스가 연관된 정책에 대하여 사전에 설정된 우선순위에 기초하여 상이하게 설정되는 값일 수 있다. 예를 들면, 결제 서비스와 관련된 패킷을 통과시키기 위한 방화벽의 제1 정책에는 높은 우선순위가 할당될 수 있고, 상기 제1 정책과 연관된 인스턴스에 대한 실제 IP 정보와 동적 IP 정보를 비교하는 주기는 짧게 설정될 수 있다.In one embodiment, the first period may be a value set differently based on a priority set in advance for a policy associated with an instance. For example, a first policy of a firewall for passing packets related to a payment service may be assigned a high priority, and a period for comparing actual IP information and dynamic IP information for an instance associated with the first policy may be set short.

일 실시예에서, 상기 제1 주기는 인스턴스에 대하여 사전에 설정된 우선순위에 기초하여 상이하게 설정되는 값일 수 있다. 예를 들면, 제1 인스턴스에 부착된 태그에 높은 우선 순위의 키워드(e.g. #PAYMENT)가 포함되어 있는 경우, 상기 제1 인스턴스에는 높은 우선순위가 할당될 수 있고, 상기 제1 인스턴스에 대한 실제 IP 정보와 동적 IP 정보를 비교하는 주기는 짧게 설정될 수 있다.In one embodiment, the first period may be a value set differently based on a priority set in advance for the instance. For example, if a tag attached to the first instance includes a high priority keyword (e.g. #PAYMENT), the first instance may be assigned a high priority, and the period for comparing the actual IP information and the dynamic IP information for the first instance may be set short.

도 2를 참조하면, 복수의 인스턴스 각각에 대하여 우선순위가 설정되어 있음을 확인할 수 있다. 도 3 이하의 도면을 참조하여 설명하겠지만, 방화벽의 정책과 연관된 복수의 인스턴스 각각은 태그 정보를 포함할 수 있다. 이때, 태그 정보에는 인스턴스의 속성을 나타내는 키워드가 포함될 수 있다.Referring to Fig. 2, it can be confirmed that a priority is set for each of the multiple instances. As will be described with reference to the drawings below Fig. 3, each of the multiple instances associated with the firewall policy may include tag information. At this time, the tag information may include a keyword indicating the properties of the instance.

예를 들면, 표 2에 예시된 바와 같이, 인스턴스 #1(2a)의 태그 정보에는 결제 서비스와 연관되어 있음을 나타내는 키워드(e.g. #PAYMENT) 및 스케일 변동이 가능함을 나타내는 키워드(e.g. #SCALE) 등이 포함될 수 있다. 또한, 인스턴스 #2의 태그 정보에는 배송 서비스와 연관되어 있음을 나타내는 키워드(e.g. #PAYMENT) 및 스케일 변동이 가능함을 나타내는 키워드(e.g. #SCALE-xxx-ooo) 등이 포함될 수 있다.For example, as illustrated in Table 2, tag information of instance #1 (2a) may include keywords indicating that it is associated with a payment service (e.g. #PAYMENT) and keywords indicating that scale change is possible (e.g. #SCALE). In addition, tag information of instance #2 may include keywords indicating that it is associated with a delivery service (e.g. #PAYMENT) and keywords indicating that scale change is possible (e.g. #SCALE-xxx-ooo).

이때, 표 2d에 예시된 바와 같이, 결제 서비스와 연관되어 있음을 나타내는 키워드가 포함된 태그가 부착된 인스턴스 #1(2a)에는 높은 우선순위(i.e. 1순위)가 할당될 수 있고, 인스턴스 #1(2a)에 대한 실제 IP 정보와 동적 IP 정보를 비교하는 주기는 짧게 설정될 수 있다. 또한, 스케일 변동이 가능함을 나타내는 키워드가 포함된 태그가 부착된 인스턴스 #2(2b)와 스케일 변동이 가능함을 나타내는 키워드가 포함되지 않은 태그가 부착된 인스턴스 #3(2c) 중에서는 인스턴스 #2(2b)에 높은 우선순위(i.e. 2순위)가 할당될 수 있고, 인스턴스 #2(2b)에 대한 실제 IP 정보와 동적 IP 정보를 비교하는 주기는 짧게 설정될 수 있다. 이는, 스케일 변동이 가능한 인스턴스의 경우에는 방화벽과 관련된 장애의 발생 확률이 높으므로 모니터링 주기를 짧게 설정할 필요가 있기 때문이다.At this time, as illustrated in Table 2d, a high priority (i.e., 1st priority) may be assigned to instance #1 (2a) that is tagged with a keyword indicating that it is associated with a payment service, and a period for comparing the actual IP information and the dynamic IP information for instance #1 (2a) may be set short. In addition, among instance #2 (2b) that is tagged with a keyword indicating that scale change is possible and instance #3 (2c) that is tagged with a keyword not indicating that scale change is possible, instance #2 (2b) may be assigned a high priority (i.e., 2nd priority), and a period for comparing the actual IP information and the dynamic IP information for instance #2 (2b) may be set short. This is because, in the case of instances that are capable of scale change, the probability of occurrence of a firewall-related failure is high, and therefore, the monitoring period needs to be set short.

한편, 태그 정보에는 반드시 하나의 단어로 구성된 키워드가 포함되는 것은 아니며, 문자, 숫자, 기호 등의 조합으로 구성된 키워드가 포함될 수 있음은 물론이다.Meanwhile, tag information does not necessarily include a keyword consisting of a single word, and may include a keyword consisting of a combination of letters, numbers, symbols, etc.

인스턴스에 부착된 태그 정보 및 태그 정보를 이용하여 장애 복구 필요 여부를 판단하는 프로세스에 대한 자세한 설명은 도 3 이하의 도면들을 참조하여 후술하도록 한다.A detailed description of the tag information attached to an instance and the process for determining whether a failure recovery is necessary using the tag information is provided below with reference to the drawings in FIG. 3 and below.

다시 도 1을 참조하면, 단계 S400에서, 제1 서버는 단계 S300을 통한 실제 IP 정보와 동적 IP 정보의 비교 결과에 기초하여, 방화벽과 관련된 장애 복구 필요 여부를 판단할 수 있다. 보다 구체적으로, 클라우드 서비스 서버로부터 획득한, 방화벽의 정책과 연관된 인스턴스에 대한 실제 IP 정보와 외부 모듈(e.g. IP 정보 동기화 모듈)로부터 획득한 인스턴스의 동적 IP 정보가 일치하지 않는 경우, 방화벽과 관련된 장애가 발생하여 복구 프로세스가 수행될 필요가 있다고 판단될 수 있다.Referring back to FIG. 1, in step S400, the first server may determine whether a failure related to the firewall requires recovery based on the comparison result between the actual IP information and the dynamic IP information through step S300. More specifically, if the actual IP information for the instance associated with the firewall policy obtained from the cloud service server does not match the dynamic IP information of the instance obtained from an external module (e.g., IP information synchronization module), it may be determined that a failure related to the firewall has occurred and a recovery process needs to be performed.

이후, 도 1에는 도시되어 있지는 않으나, 단계 S400에서의 판단 결과, 방화벽과 관련된 장애 복구가 필요한 것으로 판단된 경우, 장애 복구 프로세스가 자동으로 실행될 수 있다. 이때, 상기 장애 복구 프로세스는 상기 방화벽의 동적 IP 정보의 IP 대역을 기초로 기 생성된 예비 정책을 이용하여 수행되는 것일 수 있다. 또한, 상기 예비 정책은, 방화벽과 관련된 장애 상황이 발생될 경우를 대비한 서브넷(subnet) 기반의 정책으로, 인스턴스의 스케일 변동 범위를 고려하여 설정된 예비적인 정책일 수 있다. 즉, 상기 예비 정책은 인스턴스가 스케일 인 또는 스케일 아웃을 통해 자동으로 생성되거나 삭제되더라도 트래픽이 허용되어 정상적인 서비스가 제공될 수 있도록 하기 위한 정책을 의미할 수 있다. Thereafter, although not illustrated in FIG. 1, if it is determined in step S400 that a failure recovery related to the firewall is necessary, a failure recovery process may be automatically executed. At this time, the failure recovery process may be performed using a preliminary policy previously created based on the IP band of the dynamic IP information of the firewall. In addition, the preliminary policy may be a preliminary policy set in consideration of the scale fluctuation range of the instance as a subnet-based policy in case a failure situation related to the firewall occurs. In other words, the preliminary policy may mean a policy for allowing traffic to be allowed so that normal service can be provided even if an instance is automatically created or deleted through scale-in or scale-out.

이에, 결제 서비스와 관련된 방화벽 정책이 적용될 경우, 방화벽과 관련된 장애가 발생하더라도 예비 정책을 이용한 장애 복구 프로세스가 자동으로 실행됨으로써 결제 서비스의 연속성이 보장될 수 있다. Accordingly, when a firewall policy related to payment services is applied, even if a firewall-related failure occurs, the continuity of payment services can be guaranteed by automatically executing a failure recovery process using a standby policy.

정리하면, 클라우드 서비스 서버로부터 획득한 방화벽의 정책과 연관된 인스턴스의 실제 IP 정보와 방화벽에 의하여 참조되는 인스턴스 각각의 동적 IP 정보(i.e. 외부 모듈로부터 제공됨)를 비교한 결과에 기초하여, 방화벽과 관련된 장애가 감지될 수 있다. 또한, 방화벽과 관련된 장애 복구가 필요하다고 판단된 경우, 예비 정책을 이용한 장애 복구 프로세스가 자동으로 실행될 수 있다. In summary, based on the result of comparing the actual IP information of the instance associated with the firewall policy acquired from the cloud service server and the dynamic IP information of each instance referenced by the firewall (i.e. provided by an external module), a failure related to the firewall can be detected. In addition, if it is determined that a failure recovery related to the firewall is necessary, a failure recovery process using a standby policy can be automatically executed.

이에, 클라우드 서비스 서버로부터 획득한 인스턴스의 실제 IP 정보를 참조함으로써 방화벽과 관련된 장애 복구가 필요한지 여부가 정확하게 판단될 수 있고, 장애 복구 프로세스가 사용자의 수동 개입 없이 자동으로 실행됨으로써 사용자의 편의성 및 만족도가 제고될 수 있다.Accordingly, by referring to the actual IP information of the instance acquired from the cloud service server, it can be accurately determined whether a firewall-related failure recovery is necessary, and the failure recovery process can be automatically executed without manual intervention by the user, thereby improving user convenience and satisfaction.

한편, 방화벽과 관련된 장애를 감지하는 프로세스는 도 1에 예시된 바와 같이, 클라우드 서비스 서버로부터 획득한 인스턴스의 실제 IP 정보와 외부 모듈로부터 획득한 동적 IP 정보를 이용하여 수행될 수 있으나, 이러한 방법에 한정되는 것은 아니다. 즉, 방화벽과 관련된 장애를 감지하는 프로세스는 클라우드 서비스 서버로부터 획득한 인스턴스의 태그 정보와 외부 모듈로부터 획득한 동적 IP 정보의 태그 정보를 이용하여 수행될 수도 있다. 이에 대한 자세한 설명은 도 3 내지 도 7을 참조하여 후술하도록 한다.Meanwhile, the process of detecting a failure related to a firewall can be performed using the actual IP information of the instance acquired from the cloud service server and the dynamic IP information acquired from an external module, as illustrated in Fig. 1, but is not limited to this method. That is, the process of detecting a failure related to a firewall can also be performed using the tag information of the instance acquired from the cloud service server and the tag information of the dynamic IP information acquired from an external module. A detailed description thereof will be described later with reference to Figs. 3 to 7.

도 3은 본 개시의 다른 실시예에 따른, 방화벽과 관련된 장애 감지 및 복구 방법을 설명하기 위한 예시도이다. 단, 이는 본 개시의 목적을 달성하기 위한 바람직한 실시예일뿐이며, 필요에 따라 일부 단계가 추가되거나 삭제될 수 있음은 물론이다.FIG. 3 is an exemplary diagram for explaining a method for detecting and recovering a failure related to a firewall according to another embodiment of the present disclosure. However, this is only a preferred embodiment for achieving the purpose of the present disclosure, and it is obvious that some steps may be added or deleted as needed.

참고로, 도 3은 도 1과 마찬가지로, 방화벽과 관련된 장애를 감지하는 모듈이 포함된 제1 서버에 의해 수행되는 방법의 단계/동작들을 나타내고 있다. 따라서, 이하의 설명들에서, 특정 단계/동작의 주체가 생략된 경우, 제1 서버에 의해 수행되는 것으로 이해될 수 있다.For reference, FIG. 3, similarly to FIG. 1, illustrates steps/operations of a method performed by a first server including a module for detecting a failure related to a firewall. Accordingly, in the following descriptions, if the subject of a specific step/operation is omitted, it can be understood that it is performed by the first server.

도 3에 예시된 바와 같이, 본 개시의 다른 실시예에 따른, 방화벽과 관련된 장애 감지 및 복구 방법은 클라우드 서비스 서버로부터 방화벽의 정책과 연관된 타겟 인스턴스의 제1 태그 정보를 획득하는 단계 S1000에서 시작될 수 있다. 이때, 상기 타겟 인스턴스의 제1 태그 정보는 인스턴스의 스케일 아웃 가능 여부에 대한 정보를 포함할 수 있다. 예를 들면, 상기 제1 태그 정보는 도 2를 참조하여 설명한 바와 같이, 특정 키워드(e.g. #SCALE)가 포함된 태그 정보일 수 있다. 한편, 단계 S1000은 도 1을 참조하여 설명한 단계 S100과 동일하므로, 중복되는 내용에 대한 설명은 생략하도록 한다.As illustrated in FIG. 3, a method for detecting and recovering a failure related to a firewall according to another embodiment of the present disclosure may start with step S1000 of obtaining first tag information of a target instance associated with a policy of the firewall from a cloud service server. At this time, the first tag information of the target instance may include information on whether the instance can be scaled out. For example, the first tag information may be tag information including a specific keyword (e.g. #SCALE), as described with reference to FIG. 2. Meanwhile, step S1000 is the same as step S100 described with reference to FIG. 1, and therefore, description of overlapping content will be omitted.

단계 S2000에서, 제1 서버는 방화벽에 의하여 참조되는 타겟 인스턴스 각각의 동적 IP 정보의 제2 태그 정보를 획득할 수 있다. 이때, 상기 동적 IP 정보는 외부 모듈에 의하여 제공된 것일 수 있고, 상기 제2 태그 정보는 상기 동적 IP 정보에 부착되어 상기 동적 IP 정보와 함께 획득되는 것으로 이해될 수 있다. 또한, 상기 제1 태그 정보와 상기 제2 태그 정보는 도 2를 참조하여 설명한 바와 같이, 인스턴스 또는 동적 IP 정보의 속성을 나타내는 키워드를 포함할 수 있다. 한편, 단계 S2000은 도 1을 참조하여 설명한 단계 S200과 동일하거나 유사하므로, 중복되는 내용에 대한 설명은 생략하도록 한다.In step S2000, the first server can obtain second tag information of each dynamic IP information of target instances referenced by the firewall. At this time, the dynamic IP information may be provided by an external module, and it may be understood that the second tag information is attached to the dynamic IP information and obtained together with the dynamic IP information. In addition, the first tag information and the second tag information may include keywords indicating properties of the instance or dynamic IP information, as described with reference to FIG. 2. Meanwhile, step S2000 is the same as or similar to step S200 described with reference to FIG. 1, and therefore, description of overlapping content will be omitted.

단계 S3000에서, 제1 서버는 단계 S1000과 단계 S2000을 통해 획득한 타겟 인스턴스의 제1 태그 정보와 동적 IP 정보의 제2 태그 정보를 비교할 수 있다. 이때, 상기 제1 태그 정보와 상기 제2 태그 정보는 사전에 설정된 제1 주기마다 비교될 수 있다. 다만, 상기 제1 주기는 사전에 설정되어 고정된 값이 아닌 경우에 따라 상이한 값일 수 있다.In step S3000, the first server can compare the first tag information of the target instance obtained through steps S1000 and S2000 with the second tag information of the dynamic IP information. At this time, the first tag information and the second tag information can be compared at each first cycle set in advance. However, the first cycle may be a different value depending on the case, rather than being a fixed value set in advance.

예를 들면, 타겟 인스턴스의 태그 정보에 높은 우선 순위의 키워드(e.g. #PAYMENT)가 포함되어 있는 경우, 상기 제1 인스턴스에는 높은 우선순위가 할당될 수 있고, 상기 제1 주기는 짧게 설정될 수 있다.For example, if the tag information of the target instance includes a high priority keyword (e.g. #PAYMENT), the first instance may be assigned a high priority and the first period may be set short.

단계 S4000에서, 제1 서버는 단계 S3000을 통한 제1 태그 정보와 제2 태그 정보의 비교 결과에 기초하여, 방화벽과 관련된 장애 복구 필요 여부를 판단할 수 있다. 이때, 다양한 방법을 이용하여 방화벽과 관련된 장애 복구 필요 여부가 판단될 수 있다. 예를 들면, 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이에 기초하여 방화벽과 관련된 장애 복구 필요 여부가 판단될 수 있다. 또한, 네트워크 트래픽을 주기적으로 모니터링한 결과에 기초하여 방화벽과 관련된 장애 복구 필요 여부가 판단될 수도 있다. 나아가, 타겟 인스턴스와 동적 IP 정보의 합집합, 교집합 및 차집합의 원소 개수에 기초하여 방화벽과 관련된 장애 복구 필요 여부가 판단될 수도 있다. 이에 대한 자세한 설명은 도 4 내지 도 7을 참조하여 후술하도록 한다.In step S4000, the first server can determine whether a failure recovery related to a firewall is necessary based on the comparison result of the first tag information and the second tag information through step S3000. At this time, whether a failure recovery related to a firewall is necessary can be determined using various methods. For example, whether a failure recovery related to a firewall is necessary can be determined based on the difference between the number of target instances and the number of dynamic IP information. In addition, whether a failure recovery related to a firewall is necessary can be determined based on the result of periodically monitoring network traffic. Furthermore, whether a failure recovery related to a firewall is necessary can be determined based on the number of elements of the union, intersection, and difference sets of the target instances and the dynamic IP information. A detailed description thereof will be described later with reference to FIGS. 4 to 7.

이후, 도 3에는 도시되어 있지는 않으나, 단계 S4000에서의 판단 결과, 방화벽과 관련된 장애 복구가 필요한 것으로 판단된 경우, 장애 복구 프로세스가 자동으로 실행될 수 있다. 이때, 상기 장애 복구 프로세스는 상기 방화벽의 동적 IP 정보의 IP 대역을 기초로 기 생성된 예비 정책을 이용하여 수행되는 것일 수 있다. 이에 대한 자세한 설명은 도 1을 참조하여 설명한 내용과 동일하므로, 중복되는 내용에 대한 설명은 생략하도록 한다.Afterwards, although not shown in Fig. 3, if it is determined in step S4000 that a failure recovery related to the firewall is necessary, a failure recovery process may be automatically executed. At this time, the failure recovery process may be performed using a preliminary policy previously generated based on the IP band of the dynamic IP information of the firewall. Since a detailed description thereof is the same as that described with reference to Fig. 1, a description of the overlapping content will be omitted.

정리하면, 클라우드 서비스 서버로부터 획득한 방화벽의 정책과 연관된 타겟 인스턴스의 제1 태그 정보와 방화벽에 의하여 참조되는 타겟 인스턴스 각각의 제2 태그 정보(i.e. 외부 모듈로부터 제공됨)를 비교한 결과에 기초하여, 방화벽과 관련된 장애가 감지될 수 있다. 또한, 방화벽과 관련된 장애 복구가 필요하다고 판단된 경우, 예비 정책을 이용한 장애 복구 프로세스가 자동으로 실행될 수 있다.In summary, based on the result of comparing the first tag information of the target instance associated with the firewall policy acquired from the cloud service server and the second tag information of each target instance referenced by the firewall (i.e. provided from an external module), a failure related to the firewall can be detected. In addition, if it is determined that a failure recovery related to the firewall is necessary, a failure recovery process using a standby policy can be automatically executed.

이에, 클라우드 서비스 서버로부터 획득한 타겟 인스턴스의 태그 정보를 참조함으로써 방화벽과 관련된 장애 복구가 필요한지 여부가 정확하게 판단될 수 있고, 장애 복구 프로세스가 사용자의 수동 개입 없이 자동으로 실행됨으로써 사용자의 편의성 및 만족도가 제고될 수 있다. 또한, 사용자가 수동으로 장애 복구 프로세스를 수행함으로 인하여 소모되는 물리적 자원 및 시간적 자원을 절약할 수 있다. Accordingly, by referring to the tag information of the target instance acquired from the cloud service server, it can be accurately determined whether a failure recovery related to the firewall is necessary, and since the failure recovery process is automatically executed without manual intervention of the user, convenience and satisfaction of the user can be improved. In addition, physical resources and time resources consumed due to the user manually performing the failure recovery process can be saved.

나아가, 결제 서비스와 관련된 방화벽 정책이 적용될 경우, 방화벽과 관련된 장애가 발생하더라도 예비 정책을 이용한 장애 복구 프로세스가 자동으로 실행됨으로써 결제 서비스의 연속성이 보장될 수 있다.Furthermore, when a firewall policy related to payment services is applied, even if a firewall-related failure occurs, the continuity of the payment service can be guaranteed by automatically executing a failure recovery process using the standby policy.

이하에서는, 타겟 인스턴스의 개수와 동적 IP 정보의 개수를 비교한 결과에 기초하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 구체적인 프로세스에 대하여 도 4 및 도 5를 참조하여 상세하게 설명하도록 한다.Below, a specific process for determining whether or not a firewall-related failure recovery is necessary based on the results of comparing the number of target instances with the number of dynamic IP information is described in detail with reference to FIGS. 4 and 5.

도 4는 도 3에 도시된 일부 동작을 설명하기 위한 상세 순서도이다. 단, 이는 본 개시의 목적을 달성하기 위한 바람직한 실시예일뿐이며, 필요에 따라 일부 단계가 추가되거나 삭제될 수 있음은 물론이다.FIG. 4 is a detailed flowchart for explaining some of the operations illustrated in FIG. 3. However, this is only a preferred embodiment for achieving the purpose of the present disclosure, and it is obvious that some steps may be added or deleted as needed.

도 4에 예시된 바와 같이, 단계 S41에서, 타겟 인스턴스의 제1 태그 정보를 이용하여 타겟 인스턴스가 스케일 변동 가능한지 여부가 판단될 수 있다. 예를 들면, 제1 태그 정보에 스케일 변동을 나타내는 키워드(e.g. #SCALE)가 포함되어 있는 경우에는 타겟 인스턴스가 스케일 변동 가능한 것으로 판단될 수 있고, 제1 태그 정보에 스케일 변동을 나타내는 키워드(e.g. #SCALE)가 포함되어 있지 않은 경우에는 타겟 인스턴스가 스케일 변동 불가능한 것으로 판단될 수 있다.As illustrated in FIG. 4, in step S41, it may be determined whether the target instance is scalable using the first tag information of the target instance. For example, if the first tag information includes a keyword indicating scale variation (e.g. #SCALE), the target instance may be determined to be scalable, and if the first tag information does not include a keyword indicating scale variation (e.g. #SCALE), the target instance may be determined to be non-scalable.

한편, 제1 태그 정보는 하나의 타겟 인스턴스에 대응되는 태그 정보일 수 있고, 제2 태그 정보는 하나의 동적 IP 정보에 대응되는 태그 정보일 수 있다. 따라서, 제1 태그 정보의 개수와 타겟 인스턴스의 개수는 동일하고, 제2 태그 정보의 개수와 동적 IP 정보의 개수는 동일한 것으로 이해될 수 있다.Meanwhile, the first tag information may be tag information corresponding to one target instance, and the second tag information may be tag information corresponding to one dynamic IP information. Accordingly, it can be understood that the number of the first tag information and the number of target instances are the same, and the number of the second tag information and the number of dynamic IP information are the same.

스케일 변동이 가능한 타겟 인스턴스의 경우, 스케일 아웃으로 인하여 타겟 인스턴스의 개수가 증가될 수 있다. 이러한 경우, IP 정보 동기화 모듈에 문제 내지 오류가 발생한다면, 동기화가 제대로 이루어지지 않아 동적 IP 정보의 개수와 타겟 인스턴스의 개수가 일치하지 않는 경우가 발생할 수 있다. 반대로, 스케일 변동이 불가능한 인스턴스의 경우에는 타겟 인스턴스의 개수가 증가될 수 없고, IP 정보 동기화 모듈에 문제 내지 오류가 발생하더라도 동적 IP 정보의 개수와 타겟 인스턴스의 개수가 일치하지 않는 경우가 발생할 가능성이 낮을 수 있다.For target instances that can be scaled, the number of target instances may increase due to scale-out. In this case, if a problem or error occurs in the IP information synchronization module, synchronization may not be performed properly, and the number of dynamic IP information and the number of target instances may not match. Conversely, for instances that cannot be scaled, the number of target instances cannot be increased, and even if a problem or error occurs in the IP information synchronization module, the number of dynamic IP information and the number of target instances may be less likely to match.

먼저, 타겟 인스턴스의 제1 태그 정보를 참조한 결과, 타겟 인스턴스가 스케일 변동 가능한 것으로 판단된 경우, 단계 S42에서 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이가 산출될 수 있다. 이후, 단계 S43에서 제1 기간동안 기준 횟수 이상의 차이가 발생하는 경우, 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수 있다.First, if the target instance is determined to be scalable based on the first tag information of the target instance, the difference between the number of target instances and the number of dynamic IP information can be calculated in step S42. Then, if the difference exceeds the reference number of times during the first period in step S43, it can be determined that a failure recovery related to the firewall is required.

예를 들면, 제1 기간동안 타겟 인스턴스의 개수와 동적 IP의 개수의 차이값이 7번 산출된 경우를 가정해볼 수 있다. 이때, 특정 기간 동안 산출된 7번의 차이값 중에서 1 이상인 차이값이 2회 발생한 경우, 방화벽과 관련된 장애가 발생하여 복구가 필요하다고 판단될 수 있다. 다만, 본 개시에 따른 방화벽 장애 감지 및 복구 방법이 상술한 예시에 한정되는 것은 아님에 유의하여야 하며, 다양한 기간과 횟수를 기준으로 장애 복구 필요 여부가 판단될 수 있다.For example, it can be assumed that the difference between the number of target instances and the number of dynamic IPs is calculated 7 times during the first period. At this time, if a difference value greater than or equal to 1 occurs twice among the 7 differences calculated during a specific period, it can be determined that a firewall-related failure has occurred and recovery is required. However, it should be noted that the firewall failure detection and recovery method according to the present disclosure is not limited to the above-described example, and whether recovery is required can be determined based on various periods and numbers of times.

다음으로, 타겟 인스턴스의 제1 태그 정보를 참조한 결과, 타겟 인스턴스의 스케일 변동이 불가능한 것으로 판단된 경우, 단계 S44에서 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이가 산출될 수 있다. 이후, 단계 S45에서 제2 기간동안 기준 횟수 이상의 차이가 발생하는 경우, 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수 있다. 이때, 상기 제2 기간은 상기 제1 기간보다 짧은 기간일 수 있다.Next, if it is determined that the scale of the target instance cannot be changed based on the first tag information of the target instance, the difference between the number of target instances and the number of dynamic IP information can be calculated in step S44. Thereafter, if a difference greater than the reference number occurs during the second period in step S45, it can be determined that a failure recovery related to the firewall is necessary. In this case, the second period may be shorter than the first period.

즉, 타겟 인스턴스의 스케일 변동이 불가능한 것으로 판단된 경우에는 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이를 산출하는 것이 큰 의미가 없으므로, 장애 복구 필요 여부를 판단하는 기준이 상이하게 적용될 필요가 있다. 즉, 타겟 인스턴스의 스케일 변동이 가능한 경우에는, 제1 기간동안 산출된 타겟 인스턴스의 개수와 동적 IP의 개수의 차이값 7개 중에서 1 이상인 차이값이 2개 발생하면 방화벽과 관련된 장애가 발생하여 복구가 필요하다고 판단되었으나, 타겟 인스턴스의 스케일 변동이 불가능한 경우에는, 제2 기간동안 산출된 타겟 인스턴스의 개수와 동적 IP의 개수의 차이값 3개 중에서 1 이상인 차이값이 1개 발생하면 방화벽과 관련된 장애가 발생하여 복구가 필요하다고 판단될 수 있다.That is, if it is determined that the scale of the target instance is impossible, calculating the difference between the number of target instances and the number of dynamic IP information does not have much meaning, so the criteria for determining whether or not a failure recovery is necessary need to be applied differently. That is, if the scale of the target instance is possible, if two out of seven differences between the number of target instances and the number of dynamic IPs calculated during the first period are greater than or equal to 1, it is determined that a failure related to the firewall has occurred and recovery is necessary. However, if the scale of the target instance is impossible, if one out of three differences between the number of target instances and the number of dynamic IPs calculated during the second period is greater than or equal to 1, it may be determined that a failure related to the firewall has occurred and recovery is necessary.

한편, 본 개시에 따른 방화벽 장애 감지 및 복구 방법이 상술한 예시에 한정되는 것은 아님에 유의하여야 하며, 다양한 기간과 횟수를 기준으로 장애 복구 필요 여부가 판단될 수 있음은 물론이다.Meanwhile, it should be noted that the firewall failure detection and recovery method according to the present disclosure is not limited to the above-described examples, and it goes without saying that the need for failure recovery can be determined based on various periods and numbers of times.

또한, 도 4를 참조하여 상술한 내용에 따르면, 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이값이 1 이상인 경우를 카운트하여 방화벽과 관련된 장애 복구 필요 여부를 판단하였으나, 필요에 따라 상기 차이값은 다양한 값으로 설정될 수 있다. 예를 들면, 단계 S43에서, 제1 기간 동안 산출된 7개의 차이값 중에서 3 이상인 차이값이 2개 존재하는 경우, 방화벽과 관련된 장애가 발생하여 복구가 필요하다고 판단될 수도 있다.In addition, according to the content described above with reference to FIG. 4, the case where the difference between the number of target instances and the number of dynamic IP information is 1 or more is counted to determine whether or not a failure related to the firewall needs to be recovered, but the difference value may be set to various values as needed. For example, in step S43, if there are two difference values that are 3 or more among the seven difference values calculated during the first period, it may be determined that a failure related to the firewall has occurred and recovery is necessary.

도 5는 도 4를 참조하여 설명한 일부 동작을 설명하기 위한 예시도이다. 보다 자세하게는, 도 5는 도 4를 참조하여 설명한, 장애 복구 필요 여부 판단 프로세스를 도식화한 예시적인 도면이다.FIG. 5 is an exemplary diagram illustrating some of the operations described with reference to FIG. 4. More specifically, FIG. 5 is an exemplary diagram schematically illustrating a process for determining whether or not a failure recovery is necessary, described with reference to FIG. 4.

먼저, 타겟 인스턴스의 제1 태그 정보를 참조한 결과, 타겟 인스턴스가 스케일 아웃 가능한 경우에 대하여 설명하도록 한다. 일 실시예에서, 방화벽과 관련된 장애 복구 필요 판단 프로세스는, 제1 기간동안 복수의 시점(5a, 5b, 5c, 5d, 5e)마다 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이를 산출하는 단계 및 차이가 발생한 시점이 기준 횟수 이상 존재하는지 여부를 판단하는 단계를 포함할 수 있다.First, let's explain a case where the target instance can be scaled out based on the result of referencing the first tag information of the target instance. In one embodiment, a process for determining the necessity of failure recovery related to a firewall may include a step of calculating the difference between the number of target instances and the number of dynamic IP information at each of a plurality of points in time (5a, 5b, 5c, 5d, 5e) during a first period, and a step of determining whether the points in time where the difference occurs exist a standard number or more.

도 5에 예시된 바와 같이, 제1 시점(5a)과 제2 시점(5b)에는 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이가 0이고, 제3 시점(5c)과 제4 시점(5d)에는 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이가 2이며, 제5 시점(5e)에는 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이가 5일 수 있다.As illustrated in FIG. 5, at the first time point (5a) and the second time point (5b), the difference between the number of target instances and the number of dynamic IP information may be 0, at the third time point (5c) and the fourth time point (5d), the difference between the number of target instances and the number of dynamic IP information may be 2, and at the fifth time point (5e), the difference between the number of target instances and the number of dynamic IP information may be 5.

만약, 제1 기간동안 산출된 5번의 차이값 중에서 1 이상인 차이값이 3회 발생하면 장애 복구 필요한 것으로 판단되는 경우라면, 제1 기간동안 차이가 1 이상인 시점이 총 3개 존재하므로, 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수 있다. 또한, 제1 기간동안 산출된 5번의 차이값 중에서 3 이상인 차이값이 3회 발생하면 장애 복구 필요한 것으로 판단되는 경우라면, 제1 기간동안 차이가 3 이상인 시점이 1개 존재하므로, 방화벽과 관련된 장애 복구가 필요하지 않은 것으로 판단될 수 있다.If, among the five differences calculated during the first period, three differences greater than or equal to 1 occur and it is determined that a failure recovery is necessary, then it can be determined that a failure recovery related to the firewall is necessary since there are three points in total where the difference is greater than or equal to 1 during the first period. In addition, if, among the five differences calculated during the first period, three differences greater than or equal to 3 occur and it is determined that a failure recovery related to the firewall is not necessary since there is one point in time where the difference is greater than or equal to 3 during the first period.

다음으로, 타겟 인스턴스의 제1 태그 정보를 참조한 결과, 타겟 인스턴스의 스케일 아웃이 불가능한 경우에 대하여 설명하도록 한다. 도 4를 참조하여 설명한 바와 같이, 타겟 인스턴스의 스케일 변동이 불가능한 경우에는 특별한 사정이 발생하지 않는 이상, 타겟 인스턴스의 개수가 증가될 수 없으므로 IP 정보 동기화 모듈에 문제 내지 오류가 발생하더라도 동적 IP 정보의 개수와 타겟 인스턴스의 개수가 일치하지 않는 경우가 없을 수 있다. Next, we will explain a case where the scale-out of the target instance is impossible based on the first tag information of the target instance. As described with reference to Fig. 4, if the scale of the target instance is impossible, the number of target instances cannot be increased unless special circumstances arise, so even if a problem or error occurs in the IP information synchronization module, there may be no case where the number of dynamic IP information and the number of target instances do not match.

즉, 도 5에 예시된 바와 같이, 타겟 인스턴스의 스케일 아웃이 불가능하므로, 제1 시점(50a) 내지 제5 시점(50e)에 산출되는 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이는 모두 0일 수 있다. 따라서, 일 실시예에서, 방화벽과 관련된 장애 복구 필요 판단 프로세스는, 제1 기간보다 짧은 제2 기간 동안의 시점(50a, 50b)들에서 타겟 인스턴스의 개수와 동적 IP 정보의 개수의 차이를 산출하는 단계 및 차이가 발생한 시점이 기준 횟수 이상 존재하는지 여부를 판단하는 단계를 포함할 수 있다.That is, as illustrated in FIG. 5, since scale-out of target instances is impossible, the difference between the number of target instances calculated at the first time point (50a) to the fifth time point (50e) and the number of dynamic IP information may all be 0. Therefore, in one embodiment, a process for determining the necessity of disaster recovery related to a firewall may include a step of calculating the difference between the number of target instances and the number of dynamic IP information at time points (50a, 50b) during a second period shorter than the first period, and a step of determining whether the number of times at which the difference occurs exists exceeds a reference number of times.

정리하면, 타겟 인스턴스의 태그 정보를 참조하여, 스케일 아웃이 가능한지 여부에 따라 제1 태그 정보와 제2 태그 정보를 비교하는 주기(e.g. 제1 기간, 제2 기간)를 상이하게 설정할 수 있다.In summary, by referring to the tag information of the target instance, the period for comparing the first tag information and the second tag information (e.g., the first period, the second period) can be set differently depending on whether scale-out is possible.

이에, 스케일 아웃이 불가능한 타겟 인스턴스의 경우에는 타겟 인스턴스와 연관된 모니터링 기간을 보다 짧게 설정함으로써 불필요한 모니터링에 의해 소모되는 시스템 자원을 절약할 수 있다.Accordingly, for target instances that cannot be scaled out, system resources consumed by unnecessary monitoring can be saved by setting a shorter monitoring period associated with the target instance.

이하에서는, 도 4 및 도 5를 참조하여 상술한 방법 외에 다양한 방법을 이용하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스에 대하여 도 6 및 도 7을 참조하여 상세하게 설명하도록 한다.Below, with reference to FIGS. 4 and 5, a process for determining whether or not a failure recovery related to a firewall is necessary using various methods other than the above-described method will be described in detail with reference to FIGS. 6 and 7.

도 6은 본 개시의 몇몇 실시예에서 참조될 수 있는, 방화벽과 관련된 장애 복구가 필요한 것으로 판단되는 경우를 설명하기 위한 예시도이다. 단, 이는 본 개시의 목적을 달성하기 위한 바람직한 실시예일뿐이며, 필요에 따라 일부 단계가 추가되거나 삭제될 수 있음은 물론이다.FIG. 6 is an exemplary diagram for explaining a case where it is determined that a failure recovery related to a firewall is necessary, which may be referenced in some embodiments of the present disclosure. However, this is only a preferred embodiment for achieving the purpose of the present disclosure, and it is obvious that some steps may be added or deleted as needed.

먼저, 네트워크 트래픽을 주기적으로 모니터링한 결과에 기초하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스에 대하여 설명하도록 한다.First, we will describe the process for determining whether a firewall-related failure requires recovery based on the results of periodic monitoring of network traffic.

도 6에 예시된 바와 같이, 단계 S61에서 네트워크 트래픽이 주기적으로 모니터링될 수 있다. 이후, 단계 S62에서 제1 기간 동안의 네트워크 트래픽이 기준치 이하인 경우, 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수 있다. 이때, 네트워크 트래픽을 고려하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스는, 타겟 인스턴스의 제1 태그 정보와 동적 IP 정보의 제2 태그 정보를 고려하지 않는다는 점에서, 도 3에 예시된 동작/단계들에 추가적으로 수행되는 단계/동작임에 유의하여야 한다. 즉, 도 3에 예시된 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는, 별도로 수행되는 네트워크 트래픽에 대한 모니터링에 대한 결과를 추가로 획득하는 단계 및 획득한 결과에 기초하여 특정 기간 동안의 네트워크 트래픽이 기준치 이하인지 여부를 고려하여 장애 복구 필요 여부를 판단하는 단계를 더 포함하는 것으로 이해되어야 한다.As illustrated in FIG. 6, network traffic may be monitored periodically in step S61. Thereafter, if the network traffic for the first period is below a reference value in step S62, it may be determined that a failure recovery related to the firewall is necessary. At this time, it should be noted that the process of determining whether a failure recovery related to the firewall is necessary by considering the network traffic is an additional step/operation performed in addition to the operations/steps illustrated in FIG. 3 in that it does not consider the first tag information of the target instance and the second tag information of the dynamic IP information. That is, it should be understood that the step of determining whether a failure recovery related to the firewall illustrated in FIG. 3 further includes a step of additionally acquiring a result of monitoring network traffic that is performed separately, and a step of determining whether a failure recovery is necessary by considering whether the network traffic for a specific period is below a reference value based on the acquired result.

다음으로, 타겟 인스턴스와 동적 IP 정보의 합집합, 교집합 및 차집합의 원소 개수에 기초하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스에 대하여 설명하도록 한다. 한편, 후술되는 프로세스는 타겟 인스턴스가 스케일 아웃이 가능한 인스턴스인 경우에 수행될 수 있다.Next, we will describe a process for determining whether a firewall-related failure recovery is necessary based on the number of elements in the union, intersection, and difference sets of the target instance and the dynamic IP information. Meanwhile, the process described below can be performed when the target instance is an instance that can be scaled out.

도 4를 참조하여 상술한 바에 따르면, 제1 태그 정보는 하나의 타겟 인스턴스에 대응되는 태그 정보일 수 있고, 제2 태그 정보는 하나의 동적 IP 정보에 대응되는 태그 정보일 수 있다. 따라서, 태그 정보는 하나의 타겟 인스턴스 또는 동적 IP 정보에 일대일 대응되는 개념이므로, 타겟 인스턴스와 동적 IP 정보의 합집합의 원소 개수와 교집합의 원소 개수는 제1 태그 정보와 제2 태그 정보를 이용하여 산출될 수 있다. 나아가, 타겟 인스턴스와 동적 IP 정보의 차집합의 원소 개수도 제1 태그 정보와 제2 태그 정보를 이용하여 산출될 수 있다.According to the above-described with reference to FIG. 4, the first tag information may be tag information corresponding to one target instance, and the second tag information may be tag information corresponding to one dynamic IP information. Accordingly, since tag information is a concept corresponding one-to-one to one target instance or dynamic IP information, the number of elements of the union and the number of elements of the intersection of the target instance and the dynamic IP information can be calculated using the first tag information and the second tag information. Furthermore, the number of elements of the difference between the target instance and the dynamic IP information can also be calculated using the first tag information and the second tag information.

일 실시예에 따르면, 단계 S63에서 타겟 인스턴스와 동적 IP 정보의 합집합의 원소 개수와 타겟 인스턴스와 동적 IP 정보의 교집합의 원소 개수가 산출될 수 있다. 이후, 단계 S64에서 합집합의 원소 개수와 교집합의 원소 개수가 일치하지 않는 경우, 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수 있다.According to one embodiment, in step S63, the number of elements in the union of the target instance and the dynamic IP information and the number of elements in the intersection of the target instance and the dynamic IP information may be calculated. Thereafter, in step S64, if the number of elements in the union and the number of elements in the intersection do not match, it may be determined that a firewall-related failure recovery is required.

이는, 타겟 인스턴스와 동적 IP 정보가 동일하다면, 합집합의 원소 개수는 타겟 인스턴스의 총 개수로 산출될 것이고, 교집합의 원소 개수도 타겟 인스턴스의 총 개수로 산출될 것이기 때문이다. 따라서, 타겟 인스턴스와 동적 IP 정보의 합집합의 원소 개수와 타겟 인스턴스와 동적 IP 정보의 교집합의 원소 개수가 일치하지 않는다면, 방화벽과 관련된 장애가 발생하여 복구가 필요한 것으로 판단될 수 있다.This is because, if the target instance and the dynamic IP information are the same, the number of elements in the union will be calculated as the total number of target instances, and the number of elements in the intersection will also be calculated as the total number of target instances. Therefore, if the number of elements in the union of the target instance and the dynamic IP information and the number of elements in the intersection of the target instance and the dynamic IP information do not match, it can be determined that a firewall-related failure has occurred and recovery is required.

일 실시예에 따르면, 단계 S65에서 타겟 인스턴스와 동적 IP 정보의 차집합의 원소 개수가 산출될 수 있다. 이후, 단계 S66에서 차집합의 원소 개수가 기준치 이상인 경우, 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수 있다.According to one embodiment, the number of elements of the difference set between the target instance and the dynamic IP information may be calculated in step S65. Thereafter, if the number of elements of the difference set is greater than or equal to a threshold value in step S66, it may be determined that a failure recovery related to the firewall is required.

타겟 인스턴스와 동적 IP 정보가 동일하다면, 차집합의 원소 개수는 0 개로 산출되어야 한다. 이에, 타겟 인스턴스와 동적 IP 정보의 차집합의 원소 개수가 0으로 산출되지 않는다면, 방화벽과 관련된 장애가 발생하여 복구가 필요한 것으로 판단될 수 있다. 다만, 반드시 차집합의 원소의 개수가 0인 경우에 한하여 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 필요는 없다. 즉, 원소 개수의 카운트 과정 또는 차집합 연산 과정에서 오류가 발생할 수 있는 가능성을 고려하여, 차집합의 원소의 개수가 기준치 이상(e.g. 2개)인 경우, 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수도 있다.If the target instance and the dynamic IP information are the same, the number of elements in the difference set should be calculated as 0. Accordingly, if the number of elements in the difference set between the target instance and the dynamic IP information is not calculated as 0, it may be determined that a firewall-related failure has occurred and recovery is required. However, it is not necessary to determine that recovery from a firewall-related failure is required only when the number of elements in the difference set is 0. That is, considering the possibility that an error may occur during the process of counting the number of elements or the process of calculating the difference set, if the number of elements in the difference set is greater than a criterion (e.g. 2), it may be determined that recovery from a firewall-related failure is required.

도 7은 도 6을 참조하여 설명한 일부 동작을 설명하기 위한 예시도이다. 보다 자세하게는, 도 7은 도 6을 참조하여 설명한, 장애 복구 필요 여부 판단 프로세스 중 일부를 도식화한 예시적인 도면이다.FIG. 7 is an exemplary diagram illustrating some of the operations described with reference to FIG. 6. More specifically, FIG. 7 is an exemplary diagram schematically illustrating some of the process for determining whether or not a failure recovery is necessary, described with reference to FIG. 6.

일 실시예에서, 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스는, 태그 정보를 이용하여 타겟 인스턴스와 동적 IP 정보의 합집합의 원소 개수와 교집합의 원소 개수를 산출하는 단계 및 합집합의 원소 개수와 교집합의 원소 개수의 일치 여부에 기초하여 장애 복구 필요 여부를 판단하는 단계를 포함할 수 있다.In one embodiment, a process for determining whether a failure recovery is necessary in relation to a firewall may include a step of calculating the number of elements in a union and an intersection of target instances and dynamic IP information using tag information, and a step of determining whether a failure recovery is necessary based on whether the number of elements in the union and the number of elements in the intersection match.

먼저, 도 7에 예시된 타겟 인스턴스(7a)와 동적 IP 정보(7b)의 합집합의 원소 개수와 교집합의 원소 개수를 이용하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스가 수행되는 경우를 가정해 볼 수 있다. 한편, 도 7에 도시된 타겟 인스턴스 A1과 동적 IP 정보 a1은 동일한 인스턴스 또는 태그 정보에 대응되는 것이므로, 원소 개수를 산출하는 과정에서 하나로 간주될 수 있다. First, it can be assumed that a process is performed to determine whether a failure recovery related to a firewall is necessary by using the number of elements of the union and the number of elements of the intersection of the target instance (7a) and the dynamic IP information (7b) illustrated in Fig. 7. Meanwhile, since the target instance A1 and the dynamic IP information a1 illustrated in Fig. 7 correspond to the same instance or tag information, they can be regarded as one in the process of calculating the number of elements.

이때, 표 7c를 참조하면, 타겟 인스턴스(7a, {A1, A2, A3, A4, B1, B2, C1, D1})와 동적 IP 정보(7b, {a1, a2, a3, a4, b1, b2, c1, d1})의 합집합은 {A1, A2, A3, A4, B1, B2, C1, D1}일 수 있고, 합집합의 원소 개수는 8개로 산출될 수 있다. 마찬가지로, 타겟 인스턴스(7a, {A1, A2, A3, A4, B1, B2, C1, D1})와 동적 IP 정보(7b, {a1, a2, a3, a4, b1, b2, c1, d1})의 교집합은 {A1, A2, A3, A4, B1, B2, C1, D1}일 수 있고, 교집합의 원소 개수는 8개로 산출될 수 있다. 이에, 합집합의 원소 개수와 교집합의 원소 개수가 8개로 일치하므로, 방화벽과 관련된 장애를 복구할 필요가 없는 것으로 판단될 수 있다.At this time, referring to Table 7c, the union of the target instance (7a, {A1, A2, A3, A4, B1, B2, C1, D1}) and the dynamic IP information (7b, {a1, a2, a3, a4, b1, b2, c1, d1}) can be {A1, A2, A3, A4, B1, B2, C1, D1}, and the number of elements of the union can be calculated as 8. Similarly, the intersection of the target instance (7a, {A1, A2, A3, A4, B1, B2, C1, D1}) and the dynamic IP information (7b, {a1, a2, a3, a4, b1, b2, c1, d1}) can be {A1, A2, A3, A4, B1, B2, C1, D1}, and the number of elements in the intersection can be calculated as 8. Accordingly, since the number of elements in the union and the number of elements in the intersection are equal to 8, it can be determined that there is no need to repair a firewall-related failure.

한편, 표 7c에 예시된 합집합과 교집합은 {a1, a2, a3, a4, b1, b2, c1, d1}, {A1, a2, A3, a4, B1, B2, c1, D1} 등 각각의 원소의 대소문자 차이는 있을 수 있으나, 원소의 개수는 항상 8개로 동일함에 유의하여야 한다. 마찬가지로, 표 7f에 예시된 합집합과 교집합을 구성하는 원소들 중에서 대소문자 차이가 있는 원소들은 동일한 원소로 취급되어, 원소의 개수가 산출되는 것으로 이해되어야 한다.Meanwhile, it should be noted that the union and intersection illustrated in Table 7c may have differences in uppercase and lowercase letters for each element, such as {a1, a2, a3, a4, b1, b2, c1, d1}, {A1, a2, A3, a4, B1, B2, c1, D1}, but the number of elements is always the same, 8. Similarly, it should be understood that elements that have differences in uppercase letters among the elements that compose the union and intersection illustrated in Table 7f are treated as the same elements, and the number of elements is calculated.

다음으로, 도 7에 예시된 타겟 인스턴스(7d)와 동적 IP 정보(7e)의 합집합의 원소 개수와 교집합의 원소 개수를 이용하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스가 수행되는 경우를 가정해볼 수도 있다.Next, it may be assumed that a process is performed to determine whether or not a failure recovery related to a firewall is necessary by using the number of elements of the union and intersection of the target instance (7d) and dynamic IP information (7e) illustrated in Fig. 7.

이때, 표 7f를 참조하면, 타겟 인스턴스(7d, {A1, A2, A3, A4, B1, B2, C1, D1})와 동적 IP 정보(7e, {a1, a2, a3, b1, c1, d1})의 합집합은 {A1, A2, A3, A4, B1, B2, C1, D1}일 수 있고, 합집합의 원소 개수는 8개로 산출될 수 있다. 반면에, 동적 IP 정보(7e)에는 A4 인스턴스와 B2 인스턴스에 대응되는 것이 존재하지 않으므로, 타겟 인스턴스(7d, {A1, A2, A3, A4, B1, B2, C1, D1})와 동적 IP 정보(7e, {a1, a2, a3, b1, c1, d1})의 교집합은 {A1, A2, A3, B1, C1, D1}일 수 있고, 교집합의 원소 개수는 6개로 산출될 수 있다. 이에, 합집합의 원소 개수가 8개이고, 교집합의 원소 개수가 6개로 일치하지 않으므로, 방화벽과 관련된 장애를 복구할 필요가 있는 것으로 판단될 수 있다.At this time, referring to Table 7f, the union of the target instance (7d, {A1, A2, A3, A4, B1, B2, C1, D1}) and the dynamic IP information (7e, {a1, a2, a3, b1, c1, d1}) can be {A1, A2, A3, A4, B1, B2, C1, D1}, and the number of elements of the union can be calculated as 8. On the other hand, since there is no corresponding A4 instance and B2 instance in the dynamic IP information (7e), the intersection of the target instance (7d, {A1, A2, A3, A4, B1, B2, C1, D1}) and the dynamic IP information (7e, {a1, a2, a3, b1, c1, d1}) can be {A1, A2, A3, B1, C1, D1}, and the number of elements in the intersection can be calculated as 6. Accordingly, since the number of elements in the union is 8 and the number of elements in the intersection is 6, it can be determined that it is necessary to repair a failure related to the firewall.

한편, 합집합과 교집합의 원소 개수가 일치하는지 여부에 따라 방화벽과 관련된 장애 복구의 필요성이 판단될 수도 있으나, 합집합의 원소 개수와 교집합의 원소 개수의 차이가 기준치 이상인지 여부에 따라 방화벽과 관련된 장애 복구의 필요성이 판단될 수도 있다. 예를 들면, 합집합과 교집합의 원소 개수가 3개 이상인 경우 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수도 있다. 이러한 경우에는, 도 7에 예시된 타겟 인스턴스(7d)와 동적 IP 정보(7e)의 차집합의 원소 개수가 2개이므로, 방화벽과 관련된 장애 복구가 필요하지 않은 것으로 판단될 수 있다.Meanwhile, the necessity of failure recovery related to a firewall may be determined based on whether the number of elements in the union and intersection are the same, but the necessity of failure recovery related to a firewall may also be determined based on whether the difference between the number of elements in the union and the number of elements in the intersection is greater than or equal to a threshold. For example, if the number of elements in the union and intersection is 3 or more, failure recovery related to a firewall may be determined to be necessary. In this case, since the number of elements in the difference between the target instance (7d) and the dynamic IP information (7e) illustrated in FIG. 7 is 2, failure recovery related to a firewall may be determined not to be necessary.

일 실시예에서, 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스는, 태그 정보를 이용하여 타겟 인스턴스와 동적 IP 정보의 차집합의 원소 개수를 산출하는 단계 및 차집합의 원소 개수에 기초하여 장애 복구 필요 여부를 판단하는 단계를 포함할 수 있다.In one embodiment, a process for determining whether a failure recovery is necessary in relation to a firewall may include a step of calculating a number of elements of a difference set between a target instance and dynamic IP information using tag information, and a step of determining whether a failure recovery is necessary based on the number of elements of the difference set.

먼저, 도 7에 예시된 타겟 인스턴스(7a)와 동적 IP 정보(7b)의 차집합의 원소 개수를 이용하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스가 수행되는 경우를 가정해 볼 수 있다. First, it can be assumed that a process is performed to determine whether or not a failure recovery related to a firewall is necessary by using the number of elements of the difference set of the target instance (7a) and the dynamic IP information (7b) illustrated in Fig. 7.

이때, 표 7c를 참조하면, 타겟 인스턴스(7a, {A1, A2, A3, A4, B1, B2, C1, D1})와 동적 IP 정보(7b, {a1, a2, a3, a4, b1, b2, c1, d1})는 각각의 원소가 모두 대응되므로, 타겟 인스턴스와 동적 IP 정보의 차집합은 공집합일 수 있고, 차집합의 원소 개수는 0개로 산출될 수 있다. 이에, 차집합의 원소 개수가 0개이므로, 방화벽과 관련된 장애를 복구할 필요가 없는 것으로 판단될 수 있다.At this time, referring to Table 7c, since each element of the target instance (7a, {A1, A2, A3, A4, B1, B2, C1, D1}) and the dynamic IP information (7b, {a1, a2, a3, a4, b1, b2, c1, d1}) corresponds, the difference between the target instance and the dynamic IP information can be an empty set, and the number of elements in the difference set can be calculated as 0. Accordingly, since the number of elements in the difference set is 0, it can be determined that there is no need to repair a failure related to the firewall.

다음으로, 도 7에 예시된 타겟 인스턴스(7d)와 동적 IP 정보(7e)의 차집합의 원소 개수를 이용하여 방화벽과 관련된 장애 복구 필요 여부를 판단하는 프로세스가 수행되는 경우를 가정해볼 수도 있다.Next, it may be assumed that a process is performed to determine whether or not a failure recovery related to a firewall is necessary by using the number of elements of the difference set of the target instance (7d) and the dynamic IP information (7e) illustrated in Fig. 7.

이때, 표 7f를 참조하면, 타겟 인스턴스(7d, {A1, A2, A3, A4, B1, B2, C1, D1})와 동적 IP 정보(7e, {a1, a2, a3, b1, c1, d1})의 차집합은 {A4, B2}일 수 있고, 차집합의 원소 개수는 2개로 산출될 수 있다. 이에, 차집합의 원소 개수가 2개이므로, 방화벽과 관련된 장애를 복구할 필요가 있는 것으로 판단될 수 있다.At this time, referring to Table 7f, the difference between the target instance (7d, {A1, A2, A3, A4, B1, B2, C1, D1}) and the dynamic IP information (7e, {a1, a2, a3, b1, c1, d1}) can be {A4, B2}, and the number of elements in the difference can be calculated as 2. Accordingly, since the number of elements in the difference is 2, it can be determined that it is necessary to repair a failure related to the firewall.

한편, 차집합의 원소 개수가 0개인지 아닌지 여부에 따라 방화벽과 관련된 장애 복구의 필요성이 판단될 수도 있으나, 차집합의 원소 개수가 기준치 이상인지 여부에 따라 방화벽과 관련된 장애 복구의 필요성이 판단될 수도 있다. 예를 들면, 차집합의 원소 개수가 3개 이상인 경우 방화벽과 관련된 장애 복구가 필요한 것으로 판단될 수 있다. 이러한 경우에는, 도 7에 예시된 타겟 인스턴스(7d)와 동적 IP 정보(7e)의 차집합의 원소 개수가 2개이므로, 방화벽과 관련된 장애 복구가 필요하지 않은 것으로 판단될 수 있다.Meanwhile, the necessity of failure recovery related to a firewall may be determined based on whether the number of elements in the difference set is 0 or not, but the necessity of failure recovery related to a firewall may also be determined based on whether the number of elements in the difference set is greater than or equal to a criterion. For example, if the number of elements in the difference set is 3 or more, it may be determined that failure recovery related to a firewall is necessary. In this case, since the number of elements in the difference set of the target instance (7d) and the dynamic IP information (7e) illustrated in FIG. 7 is 2, it may be determined that failure recovery related to a firewall is not necessary.

정리하면, 타겟 인스턴스의 태그 정보와 동적 IP 정보의 태그 정보를 참조하여, 타겟 인스턴스와 동적 IP 정보의 합집합과 교집합의 원소 개수를 산출하고, 산출된 결과에 기초하여 방화벽과 관련된 장애 복구의 필요성이 판단될 수 있다. 또한, 타겟 인스턴스와 동적 IP 정보의 차집합의 원소 개수를 산출하고, 산출된 결과에 기초하여 방화벽과 관련된 장애 복구의 필요성이 판단될 수도 있다. In summary, by referring to the tag information of the target instance and the tag information of the dynamic IP information, the number of elements in the union and intersection of the target instance and the dynamic IP information can be calculated, and the necessity of failure recovery related to the firewall can be determined based on the calculated result. In addition, the number of elements in the difference between the target instance and the dynamic IP information can be calculated, and the necessity of failure recovery related to the firewall can be determined based on the calculated result.

이에, 타겟 인스턴스와 동적 IP 정보의 합집합, 교집합 및 차집합을 하나 이상 참조함으로써 방화벽과 관련된 장애 복구가 필요한지 여부가 정확하게 판단될 수 있다.Accordingly, by referencing one or more of the union, intersection, and difference sets of the target instance and dynamic IP information, it can be accurately determined whether a firewall-related failure recovery is required.

지금까지, 도 1 내지 도 7을 참조하여 본 개시의 몇몇 실시예에 따른 방화벽과 관련된 장애 감지 및 복구 방법에 대하여 설명하였다. 본 개시의 몇몇 실시예에 따른 방화벽과 관련된 장애 감지 및 복구 방법에 따르면, 클라우드 서비스 서버로부터 획득한 방화벽의 정책과 연관된 인스턴스의 실제 IP 정보와 방화벽에 의하여 참조되는 인스턴스 각각의 동적 IP 정보(i.e. 외부 모듈로부터 제공됨)를 비교한 결과 또는 방화벽의 정책과 연관된 타겟 인스턴스의 제1 태그 정보와 방화벽에 의하여 참조되는 타겟 인스턴스 각각의 제2 태그 정보에 기초하여, 방화벽과 관련된 장애가 감지될 수 있다. 또한, 방화벽과 관련된 장애 복구가 필요하다고 판단된 경우, 예비 정책을 이용한 장애 복구 프로세스가 자동으로 실행될 수 있다. Hereinafter, a method for detecting and recovering a failure related to a firewall according to some embodiments of the present disclosure has been described with reference to FIGS. 1 to 7. According to a method for detecting and recovering a failure related to a firewall according to some embodiments of the present disclosure, a failure related to a firewall can be detected based on a result of comparing actual IP information of an instance associated with a policy of a firewall acquired from a cloud service server with dynamic IP information of each instance referenced by the firewall (i.e. provided from an external module), or based on first tag information of a target instance associated with the policy of the firewall and second tag information of each target instance referenced by the firewall. In addition, if it is determined that failure recovery related to the firewall is necessary, a failure recovery process using a standby policy can be automatically executed.

이에, 클라우드 서비스 서버로부터 획득한 타겟 인스턴스의 IP 정보 또는 태그 정보를 참조함으로써 방화벽과 관련된 장애 복구가 필요한지 여부가 정확하게 판단될 수 있다.Accordingly, by referring to the IP information or tag information of the target instance obtained from the cloud service server, it can be accurately determined whether a firewall-related failure recovery is necessary.

또한, 장애 복구 프로세스가 사용자의 수동 개입 없이 자동으로 실행됨으로써 사용자의 편의성 및 만족도가 제고될 수 있다. 또한, 사용자가 수동으로 장애 복구 프로세스를 수행함으로 인하여 소모되는 물리적 자원 및 시간적 자원을 절약할 수 있다.In addition, user convenience and satisfaction can be improved because the failure recovery process is automatically executed without the user's manual intervention. In addition, physical and time resources consumed due to the user manually performing the failure recovery process can be saved.

나아가, 결제 서비스와 관련된 방화벽 정책이 적용될 경우, 방화벽과 관련된 장애가 발생하더라도 예비 정책을 이용한 장애 복구 프로세스가 자동으로 실행됨으로써 결제 서비스의 연속성이 보장될 수 있다.Furthermore, when a firewall policy related to payment services is applied, even if a firewall-related failure occurs, the continuity of the payment service can be guaranteed by automatically executing a failure recovery process using the standby policy.

도 8은 본 개시의 몇몇 실시예들에 따른 방화벽과 관련된 장애 감지 및 복구 시스템의 하드웨어 구성도이다. 도 8에 도시된 방화벽과 관련된 장애 감지 및 복구 시스템(1000)은, 하나 이상의 프로세서(1100), 시스템 버스(1600), 통신 인터페이스(1200), 프로세서(1100)에 의하여 수행되는 컴퓨터 프로그램(1500)을 로드(load)하는 메모리(1400)와, 컴퓨터 프로그램(1500)을 저장하는 스토리지(1300)를 포함할 수 있다.FIG. 8 is a hardware configuration diagram of a fault detection and recovery system related to a firewall according to some embodiments of the present disclosure. The fault detection and recovery system (1000) related to a firewall illustrated in FIG. 8 may include one or more processors (1100), a system bus (1600), a communication interface (1200), a memory (1400) that loads a computer program (1500) executed by the processor (1100), and a storage (1300) that stores the computer program (1500).

프로세서(1100)는 방화벽과 관련된 장애 감지 및 복구 시스템(1000)의 각 구성의 전반적인 동작을 제어한다. 프로세서(1100)는 본 개시의 다양한 실시예들에 따른 방법/동작을 실행하기 위한 적어도 하나의 애플리케이션 또는 프로그램에 대한 연산을 수행할 수 있다. 메모리(1400)는 각종 데이터, 명령 및/또는 정보를 저장한다. 메모리(1400)는 본 개시의 다양한 실시예들에 따른 방법/동작들을 실행하기 위하여 스토리지(1300)로부터 하나 이상의 컴퓨터 프로그램(1500)을 로드(load) 할 수 있다. 시스템 버스(1600)는 방화벽과 관련된 장애 감지 및 복구 시스템(1000)의 구성 요소 간 통신 기능을 제공한다. 통신 인터페이스(1200)는 방화벽과 관련된 장애 감지 및 복구 시스템(1000)의 인터넷 통신을 지원한다. 스토리지(1300)는 하나 이상의 컴퓨터 프로그램(1500)을 비임시적으로 저장할 수 있다. 컴퓨터 프로그램(1500)은 본 개시의 다양한 실시예들에 따른 방법/동작들이 구현된 하나 이상의 명령어들(instructions)을 포함할 수 있다. 컴퓨터 프로그램(1500)이 메모리(1400)에 로드 되면, 프로세서(1100)는 상기 하나 이상의 명령어들을 실행시킴으로써 본 개시의 다양한 실시예들에 따른 방법/동작들을 수행할 수 있다.The processor (1100) controls the overall operation of each component of the fault detection and recovery system (1000) related to the firewall. The processor (1100) can perform operations for at least one application or program for executing methods/operations according to various embodiments of the present disclosure. The memory (1400) stores various data, commands, and/or information. The memory (1400) can load one or more computer programs (1500) from the storage (1300) to execute methods/operations according to various embodiments of the present disclosure. The system bus (1600) provides a communication function between components of the fault detection and recovery system (1000) related to the firewall. The communication interface (1200) supports Internet communication of the fault detection and recovery system (1000) related to the firewall. The storage (1300) can non-temporarily store one or more computer programs (1500). The computer program (1500) may include one or more instructions implementing methods/operations according to various embodiments of the present disclosure. When the computer program (1500) is loaded into the memory (1400), the processor (1100) may perform the methods/operations according to various embodiments of the present disclosure by executing the one or more instructions.

몇몇 실시예들에서, 도 8을 참조하여 설명된 방화벽과 관련된 장애 감지 및 복구 시스템(1000)은 가상 머신 등 클라우드 기술에 기반하여 서버 팜(server farm)에 포함된 하나 이상의 물리 서버(physical server)를 이용하여 구성될 수 있다. 이 경우, 도 9에 도시된 구성 요소 중 프로세서(1100), 메모리(1400) 및 스토리지(1300) 중 적어도 일부는 가상 하드웨어(virtual hardware)일 수 있을 것이며, 통신 인터페이스(1200) 또한 가상 스위치(virtual switch) 등 가상화된 네트워킹 요소로 구성될 수 있을 것이다.In some embodiments, the fault detection and recovery system (1000) related to the firewall described with reference to FIG. 8 may be configured using one or more physical servers included in a server farm based on cloud technology such as a virtual machine. In this case, at least some of the processor (1100), memory (1400), and storage (1300) among the components illustrated in FIG. 9 may be virtual hardware, and the communication interface (1200) may also be configured as a virtualized networking element such as a virtual switch.

지금까지 도 1 내지 도 8을 참조하여 본 개시의 다양한 실시예들 및 그 실시예들에 따른 효과들을 언급하였다. 본 개시의 기술적 사상에 따른 효과들은 이상에서 언급한 효과들로 제한되지 않으며, 언급되지 않은 또 다른 효과들은 아래의 기재로부터 통상의 기술자에게 명확하게 이해될 수 있을 것이다.Various embodiments of the present disclosure and effects according to the embodiments have been described with reference to FIGS. 1 to 8 so far. The effects according to the technical idea of the present disclosure are not limited to the effects mentioned above, and other effects not mentioned will be clearly understood by those skilled in the art from the description below.

지금까지 설명된 본 개시의 기술적 사상은 컴퓨터가 읽을 수 있는 매체 상에 컴퓨터가 읽을 수 있는 코드로 구현될 수 있다. 상기 컴퓨터로 읽을 수 있는 기록 매체에 기록된 상기 컴퓨터 프로그램은 인터넷 등의 네트워크를 통하여 다른 컴퓨팅 장치에 전송되어 상기 다른 컴퓨팅 장치에 설치될 수 있고, 이로써 상기 다른 컴퓨팅 장치에서 사용될 수 있다.The technical idea of the present disclosure described so far can be implemented as a computer-readable code on a computer-readable medium. The computer program recorded on the computer-readable recording medium can be transmitted to another computing device through a network such as the Internet and installed on the other computing device, thereby allowing it to be used on the other computing device.

도면에서 동작들이 특정한 순서로 도시되어 있지만, 반드시 동작들이 도시된 특정한 순서로 또는 순차적 순서로 실행되어야만 하거나 또는 모든 도시 된 동작들이 실행되어야만 원하는 결과를 얻을 수 있는 것으로 이해되어서는 안 된다. 특정 상황에서는, 멀티태스킹 및 병렬 처리가 유리할 수도 있다. 이상 첨부된 도면을 참조하여 본 개시의 실시예들을 설명하였지만, 본 개시가 속하는 기술분야에서 통상의 지식을 가진 자는 그 기술적 사상이나 필수적인 특징을 변경하지 않고서 본 발명이 다른 구체적인 형태로도 실시될 수 있다는 것을 이해할 수 있다. 그러므로 이상에서 기술한 실시예들은 모든 면에서 예시적인 것이며 한정적인 것이 아닌 것으로 이해해야만 한다. 본 발명의 보호 범위는 아래의 청구범위에 의하여 해석되어야 하며, 그와 동등한 범위 내에 있는 모든 기술 사상은 본 개시에 의해 정의되는 기술적 사상의 권리범위에 포함되는 것으로 해석되어야 할 것이다.Although the operations are depicted in the drawings in a particular order, it should not be understood that the operations must be performed in the particular order depicted or in a sequential order, or that all depicted operations must be performed to achieve the desired results. In certain circumstances, multitasking and parallel processing may be advantageous. While the embodiments of the present disclosure have been described above with reference to the accompanying drawings, those skilled in the art will appreciate that the present disclosure can be implemented in other specific forms without changing the technical spirit or essential characteristics thereof. Therefore, it should be understood that the embodiments described above are illustrative in all respects and not restrictive. The scope of protection of the present invention should be interpreted by the claims below, and all technical ideas within a scope equivalent thereto should be interpreted as being included in the scope of the technical ideas defined by the present disclosure.

Claims (19)

적어도 하나 이상의 컴퓨팅 장치에 의하여 수행되는 방법에 있어서,
클라우드 서비스 서버로부터 방화벽의 정책과 연관된 인스턴스에 대한 실제 IP 정보를 획득하는 단계;
상기 방화벽에 의하여 참조되는 상기 인스턴스 각각의 동적 IP 정보를 획득하되, 상기 동적 IP 정보는 외부 모듈에 의하여 제공된 것인, 단계;
상기 실제 IP 정보와 상기 동적 IP 정보를 비교하는 단계; 및
상기 비교의 결과에 기초하여, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계를 포함하되,
상기 외부 모듈은 상기 인스턴스 각각의 태그 정보에 기초하여 상기 인스턴스 각각의 동적 IP 정보를 주기적으로 업데이트하는 모듈인,
방화벽과 관련된 장애 감지 및 복구 방법.
In a method performed by at least one computing device,
A step of obtaining actual IP information for an instance associated with a firewall policy from a cloud service server;
A step of obtaining dynamic IP information of each instance referenced by the above firewall, wherein the dynamic IP information is provided by an external module;
A step of comparing the above actual IP information with the above dynamic IP information; and
Based on the results of the above comparison, a step of determining whether a failure recovery related to the firewall is necessary is included.
The above external module is a module that periodically updates dynamic IP information of each instance based on tag information of each instance.
How to detect and recover from firewall related failures.
삭제delete 제1 항에 있어서,
상기 실제 IP 정보와 상기 동적 IP 정보를 비교하는 단계는,
상기 실제 IP 정보와 상기 동적 IP 정보를 제1 주기마다 비교하는 단계를 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In the first paragraph,
The step of comparing the above actual IP information and the above dynamic IP information is:
Comprising a step of comparing the actual IP information and the dynamic IP information at each first cycle;
How to detect and recover from firewall related failures.
제3 항에 있어서,
상기 제1 주기는,
상기 인스턴스가 연관된 정책에 대하여 사전에 설정된 우선순위에 기초하여 상이하게 설정되는 값인,
방화벽과 관련된 장애 감지 및 복구 방법.
In the third paragraph,
The above first cycle is,
The above instance is a value that is set differently based on a pre-established priority for the policy associated with it.
How to detect and recover from firewall related failures.
제3 항에 있어서,
상기 제1 주기는,
상기 인스턴스에 대하여 사전에 설정된 우선순위에 기초하여 상이하게 설정되는 값인,
방화벽과 관련된 장애 감지 및 복구 방법.
In the third paragraph,
The above first cycle is,
A value that is set differently based on a priority set in advance for the above instance.
How to detect and recover from firewall related failures.
제1 항에 있어서,
상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계 이후에,
상기 판단의 결과, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단된 경우, 장애 복구 프로세스를 자동으로 실행하는 단계를 더 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In the first paragraph,
After the step of determining whether or not a failure recovery related to the above firewall is necessary,
As a result of the above judgment, if it is determined that a failure recovery related to the firewall is necessary, a step of automatically executing a failure recovery process is further included.
How to detect and recover from firewall related failures.
제6 항에 있어서,
상기 장애 복구 프로세스는,
상기 방화벽의 동적 IP 정보의 IP 대역을 기초로 생성된 예비 정책을 이용하여 수행되는 것인,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 6,
The above failure recovery process is,
It is performed using a preliminary policy generated based on the IP band of the dynamic IP information of the above firewall.
How to detect and recover from firewall related failures.
적어도 하나 이상의 컴퓨팅 장치에 의하여 수행되는 방법에 있어서,
클라우드 서비스 서버로부터 방화벽의 정책과 연관된 타겟 인스턴스의 제1 태그 정보를 획득하는 단계;
상기 방화벽에 의하여 참조되는 상기 타겟 인스턴스 각각의 동적 IP 정보의 제2 태그 정보를 획득하되, 상기 동적 IP 정보는 외부 모듈에 의하여 제공되는 것인, 단계;
상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계; 및
상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계를 포함하되,
상기 외부 모듈은 상기 인스턴스 각각의 태그 정보에 기초하여 상기 인스턴스 각각의 동적 IP 정보를 주기적으로 업데이트하는 모듈인,
방화벽과 관련된 장애 감지 및 복구 방법.
In a method performed by at least one computing device,
A step of obtaining first tag information of a target instance associated with a firewall policy from a cloud service server;
A step of obtaining second tag information of dynamic IP information of each of the target instances referenced by the firewall, wherein the dynamic IP information is provided by an external module;
A step of comparing the first tag information and the second tag information; and
Including a step of determining whether or not a failure recovery related to the firewall is necessary based on the result of the above comparison,
The above external module is a module that periodically updates dynamic IP information of each instance based on tag information of each instance.
How to detect and recover from firewall related failures.
제8 항에 있어서,
상기 타겟 인스턴스의 제1 태그 정보는,
인스턴스의 스케일 아웃 가능 여부에 대한 정보를 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 8,
The first tag information of the above target instance is:
Contains information about whether the instance can be scaled out.
How to detect and recover from firewall related failures.
제8 항에 있어서,
상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계는,
상기 제1 태그 정보와 상기 제2 태그 정보를 제1 주기마다 비교하는 단계를 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 8,
The step of comparing the first tag information and the second tag information is:
Comprising a step of comparing the first tag information and the second tag information at each first period,
How to detect and recover from firewall related failures.
제10 항에 있어서,
상기 제1 태그 정보와 상기 제2 태그 정보를 제1 주기마다 비교하는 단계는,
상기 제1 주기마다 상기 타겟 인스턴스의 개수와 상기 동적 IP 정보의 개수의 차이를 산출하는 단계를 포함하고,
상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는,
상기 타겟 인스턴스가 스케일 변동이 가능한 인스턴스인 경우, 상기 타겟 인스턴스의 개수와 상기 동적 IP 정보의 개수의 차이가 발생한 시점이 제1 기간동안 기준 횟수 이상 발생하면 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 10,
The step of comparing the first tag information and the second tag information at each first period is:
Including a step of calculating the difference between the number of target instances and the number of dynamic IP information for each of the first periods,
The step of determining whether or not a failure recovery related to the firewall is necessary based on the results of the above comparison is as follows:
If the target instance is an instance capable of scalability, a step of determining that a failure recovery related to the firewall is necessary is included when the difference between the number of target instances and the number of dynamic IP information occurs more than a standard number of times during a first period.
How to detect and recover from firewall related failures.
제11 항에 있어서,
상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는,
상기 타겟 인스턴스가 스케일 변동이 불가능한 인스턴스인 경우, 상기 타겟 인스턴스의 개수와 상기 동적 IP 정보의 개수의 차이가 발생한 시점이 제2 기간동안 기준 횟수 이상의 차이가 발생하면 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 더 포함하되,
상기 제2 기간은 상기 제1 기간보다 짧은,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 11,
The step of determining whether or not a failure recovery related to the firewall is necessary based on the results of the above comparison is as follows:
If the target instance is an instance that cannot be scaled, the step of determining that a failure recovery related to the firewall is necessary is further included when the difference between the number of target instances and the number of dynamic IP information occurs more than a standard number of times during a second period.
The above second period is shorter than the above first period,
How to detect and recover from firewall related failures.
제8 항에 있어서,
상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는,
네트워크 트래픽에 대한 모니터링 결과를 더 고려하여, 제1 기간 동안의 네트워크 트래픽이 기준치 이하인 경우, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 더 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 8,
The steps for determining whether or not the above firewall-related failure recovery is necessary are:
Further considering the monitoring results of network traffic, if the network traffic during the first period is below the reference value, the step of determining that a failure recovery related to the firewall is necessary is further included.
How to detect and recover from firewall related failures.
제8 항에 있어서,
상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계는,
상기 제1 태그 정보와 상기 제2 태그 정보를 이용하여 상기 타겟 인스턴스와 상기 동적 IP 정보의 합집합의 원소 개수와 상기 타겟 인스턴스와 상기 동적 IP 정보의 교집합의 원소 개수를 산출하는 단계를 포함하고,
상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는,
상기 합집합의 원소 개수와 상기 교집합의 원소 개수가 일치하지 않는 경우, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 8,
The step of comparing the first tag information and the second tag information is:
A step of calculating the number of elements of the union of the target instance and the dynamic IP information and the number of elements of the intersection of the target instance and the dynamic IP information using the first tag information and the second tag information,
The steps for determining whether or not the above firewall-related failure recovery is necessary are:
A step of determining that a failure recovery related to the firewall is required when the number of elements of the union and the number of elements of the intersection do not match,
How to detect and recover from firewall related failures.
제8 항에 있어서,
상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 단계는,
상기 제1 태그 정보와 상기 제2 태그 정보를 이용하여 상기 타겟 인스턴스와 상기 동적 IP 정보의 차집합의 원소 개수를 산출하는 단계를 포함하고,
상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계는,
상기 차집합의 원소 개수가 기준치 이상인 경우, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단하는 단계를 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 8,
The step of comparing the first tag information and the second tag information is:
Comprising a step of calculating the number of elements of the difference set between the target instance and the dynamic IP information using the first tag information and the second tag information,
The steps for determining whether or not the above firewall-related failure recovery is necessary are:
Including a step of determining that a failure recovery related to the firewall is necessary when the number of elements of the above difference set is greater than or equal to a criterion.
How to detect and recover from firewall related failures.
제8 항에 있어서,
상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 단계 이후에,
상기 판단의 결과, 상기 방화벽과 관련된 장애 복구가 필요한 것으로 판단된 경우, 장애 복구 프로세스를 자동으로 실행하는 단계를 더 포함하는,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 8,
After the step of determining whether or not a failure recovery related to the above firewall is necessary,
As a result of the above judgment, if it is determined that a failure recovery related to the firewall is necessary, a step of automatically executing a failure recovery process is further included.
How to detect and recover from firewall related failures.
제16 항에 있어서,
상기 장애 복구 프로세스는,
상기 방화벽의 동적 IP 정보의 IP 대역을 기초로 생성된 예비 정책을 이용하여 수행되는 것인,
방화벽과 관련된 장애 감지 및 복구 방법.
In Article 16,
The above failure recovery process is,
It is performed using a preliminary policy generated based on the IP band of the dynamic IP information of the above firewall.
How to detect and recover from firewall related failures.
프로세서; 및
명령어를 저장하는 메모리를 포함하고,
상기 명령어는 상기 프로세서에 의해 실행될 때, 상기 프로세서로 하여금,
클라우드 서비스 서버로부터 방화벽의 정책과 연관된 인스턴스에 대한 실제 IP 정보를 획득하는 동작;
상기 방화벽에 의하여 참조되는 상기 인스턴스 각각의 동적 IP 정보를 획득하되, 상기 동적 IP 정보는 외부 모듈에 의하여 제공된 것인, 동작;
상기 실제 IP 정보와 상기 동적 IP 정보를 비교하는 동작; 및
상기 비교의 결과에 기초하여, 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 동작을 수행하도록 하되,
상기 외부 모듈은 상기 인스턴스 각각의 태그 정보에 기초하여 상기 인스턴스 각각의 동적 IP 정보를 주기적으로 업데이트하는 모듈인,
방화벽과 관련된 장애 감지 및 복구 시스템.
processor; and
Contains memory for storing instructions,
The above instructions, when executed by the processor, cause the processor to:
The act of obtaining real IP information for instances associated with a firewall policy from a cloud service server;
An operation for obtaining dynamic IP information of each instance referenced by the above firewall, wherein the dynamic IP information is provided by an external module;
An operation of comparing the above actual IP information with the above dynamic IP information; and
Based on the results of the above comparison, an operation is performed to determine whether a failure recovery related to the firewall is necessary.
The above external module is a module that periodically updates dynamic IP information of each instance based on tag information of each instance.
A fault detection and recovery system related to firewalls.
프로세서; 및
명령어를 저장하는 메모리를 포함하고,
상기 명령어는 상기 프로세서에 의해 실행될 때, 상기 프로세서로 하여금,
클라우드 서비스 서버로부터 방화벽의 정책과 연관된 타겟 인스턴스의 제1 태그 정보를 획득하는 동작;
상기 방화벽에 의하여 참조되는 상기 타겟 인스턴스 각각의 동적 IP 정보의 제2 태그 정보를 획득하되, 상기 동적 IP 정보는 외부 모듈에 의하여 제공되는 것인, 동작;
상기 제1 태그 정보와 상기 제2 태그 정보를 비교하는 동작; 및
상기 비교의 결과에 기초하여 상기 방화벽과 관련된 장애 복구 필요 여부를 판단하는 동작을 수행하도록 하되,
상기 외부 모듈은 상기 인스턴스 각각의 태그 정보에 기초하여 상기 인스턴스 각각의 동적 IP 정보를 주기적으로 업데이트하는 모듈인,
방화벽과 관련된 장애 감지 및 복구 시스템.
processor; and
Contains memory for storing instructions,
The above instructions, when executed by the processor, cause the processor to:
An action of obtaining first tag information of a target instance associated with a firewall policy from a cloud service server;
An operation for obtaining second tag information of dynamic IP information of each of the target instances referenced by the firewall, wherein the dynamic IP information is provided by an external module;
An operation of comparing the first tag information and the second tag information; and
Based on the results of the above comparison, an operation is performed to determine whether a failure recovery related to the firewall is necessary.
The above external module is a module that periodically updates dynamic IP information of each instance based on tag information of each instance.
A fault detection and recovery system related to firewalls.
KR1020230157250A 2023-11-14 2023-11-14 Method and system for detecting and recovering firewall-related failure Active KR102745167B1 (en)

Priority Applications (4)

Application Number Priority Date Filing Date Title
KR1020230157250A KR102745167B1 (en) 2023-11-14 2023-11-14 Method and system for detecting and recovering firewall-related failure
PCT/KR2023/019234 WO2025105560A1 (en) 2023-11-14 2023-11-27 Method and system for detecting and recovering fault related to firewall
TW112146095A TW202520072A (en) 2023-11-14 2023-11-28 Method and system for detecting and recovering firewall-related failure
KR1020240188130A KR20250071211A (en) 2023-11-14 2024-12-17 Method and system for detecting and recovering firewall-related failure

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
KR1020230157250A KR102745167B1 (en) 2023-11-14 2023-11-14 Method and system for detecting and recovering firewall-related failure

Related Child Applications (1)

Application Number Title Priority Date Filing Date
KR1020240188130A Division KR20250071211A (en) 2023-11-14 2024-12-17 Method and system for detecting and recovering firewall-related failure

Publications (1)

Publication Number Publication Date
KR102745167B1 true KR102745167B1 (en) 2024-12-19

Family

ID=94082371

Family Applications (2)

Application Number Title Priority Date Filing Date
KR1020230157250A Active KR102745167B1 (en) 2023-11-14 2023-11-14 Method and system for detecting and recovering firewall-related failure
KR1020240188130A Pending KR20250071211A (en) 2023-11-14 2024-12-17 Method and system for detecting and recovering firewall-related failure

Family Applications After (1)

Application Number Title Priority Date Filing Date
KR1020240188130A Pending KR20250071211A (en) 2023-11-14 2024-12-17 Method and system for detecting and recovering firewall-related failure

Country Status (3)

Country Link
KR (2) KR102745167B1 (en)
TW (1) TW202520072A (en)
WO (1) WO2025105560A1 (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20070107927A (en) * 2006-05-04 2007-11-08 에스케이 텔레콤주식회사 Service Quality Measurement System and Method of Web Server
KR101518474B1 (en) * 2013-12-30 2015-05-07 주식회사 플랜티넷 Method for selectively permitting/blocking a plurality of internet request traffics sharing the public IP address on the basis of current time and system for detecting and blocking internet request traffics sharing the public IP address on the current time
KR20170053433A (en) 2015-11-06 2017-05-16 주식회사 케이티 Method for duplicating of firewall and apparatus thereof
JP2023034553A (en) * 2021-08-31 2023-03-13 富士通株式会社 Service management device, service management method, and service management program
US20230099259A1 (en) * 2021-09-30 2023-03-30 Acronis International Gmbh Managing corporate firewalls and network isolation for EDR

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101306025B1 (en) * 2011-06-23 2013-09-12 청호메카트로닉스 주식회사 Managing System For Automated Teller Machine And Method Thereof

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR20070107927A (en) * 2006-05-04 2007-11-08 에스케이 텔레콤주식회사 Service Quality Measurement System and Method of Web Server
KR101518474B1 (en) * 2013-12-30 2015-05-07 주식회사 플랜티넷 Method for selectively permitting/blocking a plurality of internet request traffics sharing the public IP address on the basis of current time and system for detecting and blocking internet request traffics sharing the public IP address on the current time
KR20170053433A (en) 2015-11-06 2017-05-16 주식회사 케이티 Method for duplicating of firewall and apparatus thereof
JP2023034553A (en) * 2021-08-31 2023-03-13 富士通株式会社 Service management device, service management method, and service management program
US20230099259A1 (en) * 2021-09-30 2023-03-30 Acronis International Gmbh Managing corporate firewalls and network isolation for EDR

Also Published As

Publication number Publication date
TW202520072A (en) 2025-05-16
WO2025105560A1 (en) 2025-05-22
KR20250071211A (en) 2025-05-21

Similar Documents

Publication Publication Date Title
US11108859B2 (en) Intelligent backup and recovery of cloud computing environment
US8880936B2 (en) Method for switching application server, management computer, and storage medium storing program
CN112199240B (en) Method for switching nodes during node failure and related equipment
US9342426B2 (en) Distributed system, server computer, distributed management server, and failure prevention method
JP5786037B2 (en) Virtual computer control method and virtual computer system
US8601493B2 (en) Application controlling apparatus and storage medium which stores software for the apparatus
JP6788178B2 (en) Setting support program, setting support method and setting support device
EP3591530B1 (en) Intelligent backup and recovery of cloud computing environment
US9244719B2 (en) Batch processing system
CN107426012B (en) Fault recovery method and device based on super-fusion architecture
JP5998577B2 (en) Cluster monitoring apparatus, cluster monitoring method, and program
US10367711B2 (en) Protecting virtual computing instances from network failures
US10754753B1 (en) Performance of virtual machine instances using machine recognition of screenshot images
CN107453888B (en) High-availability virtual machine cluster management method and device
CN111181780A (en) HA cluster-based host pool switching method, system, terminal and storage medium
Altameem Fault tolerance techniques in grid computing systems
KR102745167B1 (en) Method and system for detecting and recovering firewall-related failure
US8959383B2 (en) Failover estimation using contradiction
US10157110B2 (en) Distributed system, server computer, distributed management server, and failure prevention method
CN112905341A (en) Distributed load balancing service information continuous inheritance method and device
US8307371B2 (en) Method for efficient utilization of processors in a virtual shared environment
Mahdian et al. Considering faults in service-oriented architecture: A graph transformation-based approach
CN106354602A (en) Service monitoring method and equipment
CN110297741B (en) Background task monitoring method and device
Hasan et al. A case-based framework for self-healing paralysed components in Distributed Software applications

Legal Events

Date Code Title Description
PA0109 Patent application

Patent event code: PA01091R01D

Comment text: Patent Application

Patent event date: 20231114

PA0201 Request for examination

Patent event code: PA02011R01I

Patent event date: 20231114

Comment text: Patent Application

PA0302 Request for accelerated examination

Patent event date: 20240221

Patent event code: PA03022R01D

Comment text: Request for Accelerated Examination

PE0902 Notice of grounds for rejection

Comment text: Notification of reason for refusal

Patent event date: 20240416

Patent event code: PE09021S01D

E701 Decision to grant or registration of patent right
PE0701 Decision of registration

Patent event code: PE07011S01D

Comment text: Decision to Grant Registration

Patent event date: 20241024

GRNT Written decision to grant
PR0701 Registration of establishment

Comment text: Registration of Establishment

Patent event date: 20241217

Patent event code: PR07011E01D

PR1002 Payment of registration fee

Payment date: 20241217

End annual number: 3

Start annual number: 1

PG1601 Publication of registration