Mimicry defense resource allocation methods, devices, program products, equipment and media
By constructing a heterogeneous software and hardware resource pool in mimicry defense, and generating differentiated scores based on resource characteristics and reference information for resource allocation, the universality and security issues of mimicry defense resource allocation are solved, achieving higher security and resource allocation efficiency.
Patent Information
- Application Number
- CN202511270739.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-08
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2045-09-08
AI Technical Summary
The technical problem of existing mimicry defense technology is that it cannot effectively solve the problem of how to improve the universality and security of mimicry defense resource allocation. In particular, the existing mimicry defense resource allocation has poor universality and low security.
By allocating execution entities and service heterogeneous resources in heterogeneous software resource pools and heterogeneous hardware resource pools, generating differentiated scores based on resource characteristics and reference information, and allocating resources accordingly, the heterogeneity is increased, and security and universality are improved.
It improves the universality and security of mimicry defense resource allocation, enhances the overall heterogeneity of the application, reduces resource coupling, and improves the accuracy and efficiency of resource allocation.
Smart Images

Figure CN120762922B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the fields of mimicry defense and application control technology, and more specifically, to mimicry defense resource allocation methods, devices, program products, equipment and media. Background Technology
[0002] Mimicry defense technology is an active defense system based on the DHR (Dynamic Heterogeneous Redundancy) architecture. Its core is to block attackers' detection and penetration by constructing uncertain system environments, such as constructing mimicry structures, dynamic reconstruction, and negative feedback control.
[0003] In the use of mimicry defense, the overall application can be orchestrated based on the dependencies between application components and the mimicry requirements of the application. This involves scheduling the various components, such as selecting heterogeneous nodes from the cluster based on their resource load, historical scheduling statistics, heterogeneity characteristics, and the heterogeneous requirements of the mimicry application. One of these nodes, meeting preset conditions, can then be randomly chosen as the final scheduling host. If an inconsistency is detected in the return value of a heterogeneous executor, its node is marked to prevent it from participating in subsequent scheduling, and any mimicry components running on it are expelled, completing a secondary scheduling for these components. Then, based on the current resource usage information of the heterogeneous nodes, a new heterogeneous node is selected for scheduling the new heterogeneous executor, a creation operation is performed, and the binding of the mimicry brackets is updated, completing the negative feedback process of cleaning and rotation. However, this type of mimicry defense only manages the resources of the mimicry application, resulting in poor universality and low security.
[0004] In conclusion, improving the universality and security of mimicry defense resource allocation is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention
[0005] The purpose of this application is to provide a method for allocating mimicry defense resources, which addresses the technical problem of improving the universality and security of mimicry defense resource allocation. This application also provides a mimicry defense resource allocation device, a computer program product, an electronic device, and a computer-readable storage medium.
[0006] To achieve the above objectives, this application provides the following technical solution:
[0007] A method for allocating mimicry defense resources, comprising:
[0008] In response to obtaining the execution body configuration information and execution body mimicry defense control information of the mimicry application, the execution body heterogeneous resources are allocated in the pre-built heterogeneous software resource pool and heterogeneous hardware resource pool according to the execution body configuration information and the execution body mimicry defense control information, and the execution body heterogeneous resources correspond one-to-one with the execution body of the mimicry application;
[0009] In response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications, service heterogeneous resources are allocated in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the service configuration information and the service mimicry defense control information. The service heterogeneous resources correspond one-to-one with the services of the non-mimicry applications.
[0010] Preferably, allocating target heterogeneous resources in the target heterogeneous resource pool includes:
[0011] Based on the characteristics of each resource in the target heterogeneous resource pool, a differentiated score for the resources in the target heterogeneous resource pool is generated;
[0012] Generate a reference score for the resource based on the reference information of the instantiated service to the resource;
[0013] A comprehensive score for the resource is generated based on the differential score and the citation score.
[0014] Based on the comprehensive score, target heterogeneous resources are allocated in the target heterogeneous resource pool;
[0015] Wherein, when the target heterogeneous resource pool is the heterogeneous software resource pool, the target heterogeneous resources include target software resources; when the target heterogeneous resource pool is the heterogeneous hardware resource pool, the target heterogeneous resources include target hardware resources.
[0016] Preferably, based on the target configuration information and the target mimicry defense control information, target heterogeneous resources are allocated in the heterogeneous software resource pool and the heterogeneous hardware resource pool, including:
[0017] In response to performing a rotation operation, the target heterogeneous resources allocated before the rotation are excluded from the heterogeneous software resource pool and the heterogeneous hardware resource pool to obtain candidate resources;
[0018] Based on the target configuration information and the target mimicry defense control information, a substitute resource with the same function but different resources as the heterogeneous target resource allocated before the rotation is determined from the candidate resources;
[0019] Applications are hosted based on backup resources.
[0020] A mimicry defense resource allocation device, comprising:
[0021] The mimicry allocation module is used to respond to the acquisition of the execution body configuration information and execution body mimicry defense control information of the mimicry application, and then allocate heterogeneous execution body resources in the pre-built heterogeneous software resource pool and heterogeneous hardware resource pool according to the execution body configuration information and the execution body mimicry defense control information, and the heterogeneous execution body resources correspond one-to-one with the execution body of the mimicry application;
[0022] The non-mimicry allocation module is used to, in response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications, allocate heterogeneous service resources in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the service configuration information and the service mimicry defense control information, wherein the heterogeneous service resources correspond one-to-one with the services of the non-mimicry applications.
[0023] A computer program product includes a computer program / instructions that, when executed by a processor, implement the steps of the mimicry defense resource allocation method as described above.
[0024] An electronic device, comprising:
[0025] Memory, used to store computer programs;
[0026] A processor, configured to implement the steps of any of the above-described mimicry defense resource allocation methods when executing the computer program.
[0027] A computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the above-described mimicry defense resource allocation methods.
[0028] This application provides a method for allocating mimicry defense resources. In response to obtaining execution entity configuration information and execution entity mimicry defense control information for mimicry applications, heterogeneous execution entity resources are allocated in a pre-built heterogeneous software resource pool and a heterogeneous hardware resource pool based on the execution entity configuration information and execution entity mimicry defense control information. Each heterogeneous execution entity resource corresponds one-to-one with the execution entity of the mimicry application. In response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications, heterogeneous service resources are allocated in the heterogeneous software resource pool and the heterogeneous hardware resource pool based on the service configuration information and service mimicry defense control information. Each heterogeneous service resource corresponds one-to-one with the service of the non-mimicry application. In this application, software and hardware resources are heterogeneously allocated to obtain corresponding heterogeneous resources. Considering that the executor of a mimicry application may include multiple functional containers, and a non-mimicry application may include various types of services, each service can support multiple copies running, and these copies may include multiple functional containers, resource allocation can be performed on the executor level for mimicry applications and on the service level for non-mimicry applications. This increases the heterogeneity of both software and hardware resources for both mimicry and non-mimicry applications, and constructs heterogeneous software and hardware resource pools. Before application instantiation, heterogeneous software and hardware resources are selected from these pools, thereby increasing the overall heterogeneity of the service and improving application security. Furthermore, the mimicry defense resource allocation method increases resource allocation for non-mimicry applications, thus expanding the scope of heterogeneous resource allocation for mimicry defense, increasing the universality of mimicry defense, improving the security of non-mimicry applications, and ultimately enhancing the security of mimicry defense. The mimicry defense resource allocation device, computer program product, electronic device, and computer-readable storage medium provided in this application also solve the corresponding technical problems. Attached Figure Description
[0029] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0030] Figure 1 A flowchart illustrating a method for allocating mimicry defense resources, provided in an embodiment of this application;
[0031] Figure 2 This is a schematic diagram of the mimicry defense control system.
[0032] Figure 3 Create or modify flowcharts for applications;
[0033] Figure 4 This is a flowchart for the timed rotation processing;
[0034] Figure 5 This is a flowchart for handling abnormal rotations.
[0035] Figure 6 A flowchart illustrating resource allocation for multiple containers of the mimicry application's execution body using the mimicry defense control system of this application;
[0036] Figure 7 A flowchart for selecting software resources for multiple containers of an execution entity;
[0037] Figure 8 A flowchart illustrating resource allocation for multiple containers of replicas of non-mimicking applications using the mimicry defense control system described in this application;
[0038] Figure 9 A flowchart for selecting software resources for multiple replica containers;
[0039] Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application;
[0040] Figure 11 This is another structural schematic diagram of an electronic device provided in an embodiment of this application. Detailed Implementation
[0041] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0042] Please see Figure 1 , Figure 1 A flowchart illustrating a method for allocating mimicry defense resources, as provided in an embodiment of this application.
[0043] This application provides a method for allocating mimicry defense resources, which can be scheduled according to the application's lifecycle, such as being invoked during application creation, modification, rotation, etc., and may include the following steps:
[0044] Step S101: In response to obtaining the execution configuration information and execution mimicry defense control information of the mimicry application, the execution heterogeneous resources are allocated in the pre-built heterogeneous software resource pool and heterogeneous hardware resource pool according to the execution configuration information and execution mimicry defense control information. The execution heterogeneous resources correspond one-to-one with the execution of the mimicry application.
[0045] In practical applications, for mimicry applications, heterogeneity refers to the multiple execution entities of the same type of service. Each execution entity has multiple containers, and the containers with the same function among multiple execution entities use software resources with heterogeneous characteristics to achieve software heterogeneity. That is, given the execution entity configuration information and execution entity mimicry defense control information of the mimicry application, heterogeneous resources for the execution entity are allocated from a pre-built heterogeneous software resource pool and heterogeneous hardware resource pool according to the execution entity configuration information and execution entity mimicry defense control information, and the heterogeneous resources of the execution entity correspond one-to-one with the execution entity of the mimicry application. Among them, an execution entity can instantiate multiple copies to enhance its high availability. Multiple execution entities are scheduled to different nodes for instantiation according to the allocated hardware resource scheduling information. Multiple execution entities participate in the operation of the mimicry application simultaneously, obtaining input, executing, and outputting.
[0046] Step S102: In response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications, service heterogeneous resources are allocated in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the service configuration information and service mimicry defense control information. The service heterogeneous resources correspond one-to-one with the services of non-mimicry applications.
[0047] In practical applications, for non-mimetic applications, heterogeneity refers to multiple replicas of the same type of service. Each service has multiple containers, and these replicas utilize heterogeneous software resources to achieve software heterogeneity. Specifically, given the service configuration information and mimicry defense control information for the non-mimetic application, heterogeneous service resources are allocated from pre-built heterogeneous software and hardware resource pools based on this information. These heterogeneous resources correspond one-to-one with the services of the non-mimetic application. Multiple replicas are instantiated on different nodes based on the allocated hardware resource scheduling information. Each replica can then select one of the nodes to participate in the application's execution, receiving input, executing, and outputting results, based on a load balancing strategy.
[0048] It should be noted that, in the exemplary embodiments, it is possible to obtain only the execution entity configuration information and execution entity mimicry defense control information for the mimicry application, and allocate heterogeneous execution entity resources in the heterogeneous software resource pool and heterogeneous hardware resource pool based solely on the execution entity configuration information and execution entity mimicry defense control information; alternatively, it is possible to obtain only the service configuration information and service mimicry defense control information for the non-mimicry application, and allocate service heterogeneous resources in the heterogeneous software resource pool and heterogeneous hardware resource pool based solely on the service configuration information and service mimicry defense control information; alternatively, it is possible to obtain both the execution entity configuration information and execution entity mimicry defense control information for the mimicry application and the service configuration information and service mimicry defense control information for the non-mimicry application, allocate execution entity heterogeneous resources in the heterogeneous software resource pool and heterogeneous hardware resource pool based solely on the execution entity configuration information and execution entity mimicry defense control information, and allocate service heterogeneous resources in the heterogeneous software resource pool and heterogeneous hardware resource pool based solely on the service configuration information and service mimicry defense control information. It should also be noted that the execution entity configuration information refers to the configuration information required for the execution entity to run. The execution entity mimicry defense control information may include heterogeneous software resource information, software resource priority information, timed rotation strategy configuration information, abnormal rotation strategy configuration information, etc. The service configuration information refers to the configuration information required for the service to run. The service mimicry defense control information may include heterogeneous software resource information, software resource priority information, multi-container multi-replica heterogeneous information, timed rotation strategy configuration information, etc. The execution entity configuration information, execution entity mimicry defense control information, service configuration information, and service mimicry defense control information can be entered by the user as needed, or they can be preset and stored in the storage unit and retrieved by reading, etc.
[0049] In practical applications, the software and hardware resources set up for mimicry defense can be heterogeneously configured to obtain corresponding heterogeneous software resource pools and heterogeneous hardware resource pools. Subsequently, these heterogeneous software resource pools and heterogeneous hardware resource pools can be used for resource configuration and management.
[0050] In an exemplary embodiment, the software resource can be a container image used to run the application service. The software resource has software characteristics, including software specifications, programming language, architecture, operating system, middleware, compilation type, etc. In other words, a heterogeneous software resource pool refers to a collection of multiple functionally equivalent software resources, such as an image collection. The description of the heterogeneous software resource pool in this application is as follows: An image, as a software resource, has software characteristics, including software specifications, programming language, architecture, operating system, middleware, compilation type; multiple containers, such as web containers and database containers; heterogeneous construction is performed on these two containers in terms of software characteristics to form multiple functionally equivalent but different images. Multiple images form a heterogeneous software resource pool, such as the heterogeneous software resource pool of a web container {web image 1, web image 2, web image 3}, and the heterogeneous software resource pool of a database container {database image 1, database image 2, database image 3}.
[0051] In an exemplary embodiment, hardware resources can be nodes used to run application services. Hardware resources possess hardware characteristics, including architecture, operating system, runtime, region label, node specifications, etc. A heterogeneous hardware resource pool refers to a collection of multiple hardware resources, such as a set of nodes. In other words, this application heterogeneously constructs multiple hardware resources with different hardware characteristics at the hardware characteristic dimension. These multiple hardware resources form a heterogeneous hardware resource pool, meaning that each executor or service has a heterogeneous hardware resource pool. For example, a node, as a hardware resource, possesses hardware characteristics, including architecture, operating system, runtime, region label, node specifications. Heterogeneous construction at the hardware characteristic dimension forms multiple nodes with different hardware characteristics, and these multiple nodes form a heterogeneous hardware resource pool.
[0052] In practical applications, resource allocation in heterogeneous software resource pools and heterogeneous hardware resource pools can be divided into two processes: allocating target software resources corresponding to target configuration information and target mimicry defense control information in the heterogeneous software resource pool, and allocating target hardware resources corresponding to target configuration information and target mimicry defense control information in the heterogeneous hardware resource pool. When the target configuration information is execution entity configuration information, the target software resources are execution entity software resources, the target hardware resources are execution entity hardware resources, the target heterogeneous resources are execution entity heterogeneous resources, and the target mimicry defense control information is execution entity mimicry defense control information. When the target configuration information is service configuration information, the target software resources are service software resources, the target hardware resources are service hardware resources, the target heterogeneous resources are service heterogeneous resources, and the target mimicry defense control information is service mimicry defense control information.
[0053] In an exemplary embodiment, regardless of whether it is a software resource or a hardware resource, during the process of allocating target heterogeneous resources in the target heterogeneous resource pool, a differentiated score for each resource in the target heterogeneous resource pool can be generated based on the characteristics of each resource in the target heterogeneous resource pool; a reference score for the resource can be generated based on the reference information of the instantiated service to the resource; a comprehensive score for the resource can be generated based on the differentiated score and the reference score; and the target heterogeneous resource can be allocated in the target heterogeneous resource pool based on the comprehensive score. Wherein, when the target heterogeneous resource pool is a heterogeneous software resource pool, the target heterogeneous resources include target software resources; when the target heterogeneous resource pool is a heterogeneous hardware resource pool, the target heterogeneous resources include target hardware resources. In this way, the characteristics of each resource in the target heterogeneous resource pool can be converted into resource differentiation scores, so as to accurately quantify the feature differences between resources. The reference information of instantiated services to resources can be converted into resource reference scores, so as to accurately quantify the usage information of resources. Finally, if a comprehensive score of resources is generated based on the differentiation score and the reference score and resources are allocated, it is equivalent to allocating resources based on the feature differences between resources and the usage information, which expands the reference dimensions of resource allocation, improves the accuracy of resource allocation, and the whole process is carried out by scoring in digital form, which is easy to implement and can ensure the efficiency of resource allocation.
[0054] In an exemplary embodiment, software resource allocation and hardware resource allocation can be performed synchronously based on the correlation between software and hardware resources. For example, after software resources are allocated, the corresponding hardware resources can be determined based on the allocation results. Similarly, after hardware resources are allocated, the corresponding software resources can be determined based on the allocation results. Accordingly, resource allocation priority information can be set to control whether software resources or hardware resources are allocated first. That is, during the process of allocating target heterogeneous resources in heterogeneous software resource pools and heterogeneous hardware resource pools based on target configuration information and target mimicry defense control information, resource allocation priority information can be obtained, such as a Boolean value. Then, the resource allocation priority information is detected to indicate whether software resources are allocated first or hardware resources are allocated first. For example, if the software resource priority information value is true, it is determined that software resources are allocated first; if the software resource priority information value is false, it is determined that hardware resources are allocated first. In other words, in response to the resource allocation priority information representation that resource allocation is first based on software resources, then according to the target configuration information, the target software resources corresponding to the target configuration information are allocated in the heterogeneous software resource pool, and according to the target software resources, the target hardware resources corresponding to the target configuration information are allocated in the heterogeneous hardware resource pool. For example, the heterogeneous hardware resource pool may be filtered based on the target software resources before the allocation of target hardware resources. Similarly, in response to the resource allocation priority information representation that resource allocation is first based on hardware resources, then according to the target configuration information, the target hardware resources corresponding to the target configuration information are allocated in the heterogeneous hardware resource pool, and according to the target hardware resources, the target software resources corresponding to the target configuration information are allocated in the heterogeneous software resource pool. For example, the heterogeneous software resource pool may be filtered based on the target hardware resources before the allocation of target software resources. Finally, the target software resources and target hardware resources corresponding to the target configuration information are used as target heterogeneous resources.
[0055] It should be noted that, compared with determining heterogeneous software resources during orchestration, this application adds software resource heterogeneity and hardware resource heterogeneity to both non-mimicry and mimicry applications, and constructs heterogeneous software resource pools and heterogeneous hardware resource pools. Before application instantiation, the software and hardware resources with the highest heterogeneity are selected from the resource pools according to the algorithm, thereby increasing the overall heterogeneity of the service and further improving the security of the application.
[0056] In the exemplary embodiment, the software resources corresponding to the executor and the service are allocated from the heterogeneous software resources. Therefore, the principle of allocating the executor software resources corresponding to the executor configuration information in the heterogeneous software resource pool and the principle of allocating the service software resources corresponding to the service configuration information in the heterogeneous software resource pool can be the same. For example, the software resources in the heterogeneous software resource pool can be compared based on software characteristics. The comparison can be based on the differences of various software characteristics and scoring, such as different software specifications, different programming languages, different architectures, reference to basic libraries with different operating systems, middleware with the same function but different implementations, and heterogeneous and diverse compilation types. The greater the difference, the higher the score, and then the resources are allocated based on the score results.
[0057] In specific application scenarios, to facilitate software resource allocation by generating software difference comparison scores, during the allocation of target software resources corresponding to target configuration information in a heterogeneous software resource pool, each software feature in the heterogeneous software resource pool can be encoded. For example, each software feature can be encoded starting from 1 based on dimensions such as feature complexity, technical features, and evaluation, resulting in a software feature encoding value. This feature encoding value quantifies the characteristics of each software feature, facilitating subsequent software difference score calculation. Based on the software feature encoding value and the software features contained in the software resources, a software difference score is generated for the heterogeneous software resources in the heterogeneous software resource pool. The higher the software difference score, the greater the difference between the heterogeneous software resource and other heterogeneous software resources in terms of software feature dimensions. Thus, the software difference score can be used to characterize the differences between heterogeneous software resources. The number of software references to each heterogeneous software resource and each software feature by the instantiated services is obtained. The number of software references is used to analyze the usage frequency of the software features of the heterogeneous software resources by the instantiated services. The fewer times a software is used, the higher its score. This means that a software reference score is generated for heterogeneous software resources based on the number of times the software is referenced and the software characteristics it contains. A comprehensive software score is then generated based on the software differentiation score and the software reference score. For example, the software differentiation score and the software reference score are weighted to generate the comprehensive software score. The sum of the weights of the software differentiation score and the software reference score is 1, and their respective weights are flexibly determined according to the application scenario. Thus, a higher comprehensive score indicates that the software resource is referenced less and has greater differences in characteristics from the instantiated service. Finally, based on the comprehensive software score, target software resources corresponding to the target configuration information are allocated from the heterogeneous software resource pool. For example, the group of heterogeneous software resources with the highest comprehensive score is selected as candidate software resources, and a heterogeneous software resource is selected from the candidate software resources based on the application event. For example, if it is an application creation or modification event, a heterogeneous software resource from the candidate software resources is randomly selected as the target software resource.
[0058] As can be seen from the implementation process, this application allocates software resources based on the characteristic differences and usage information between heterogeneous software resources, which expands the reference dimensions for software resource allocation and can improve the accuracy of software resource allocation. Moreover, the entire process is carried out using a numerical scoring method, which is convenient to implement and can ensure the efficiency of software resource allocation. In addition, software resources can be selected based on the comprehensive software score. The higher the comprehensive software score, the fewer the software resources are referenced and the greater the difference in characteristics between them and the instantiated services, thus ensuring the heterogeneity of the allocated software resources and reducing the resource coupling of software resource allocation.
[0059] In specific application scenarios, during the process of generating software differentiation scores for heterogeneous software resources in a heterogeneous software resource pool based on software feature encoding values and the software features contained in the software resources, pairwise differentiation comparisons can be performed on the heterogeneous software resources in the pool to obtain software feature difference values. Based on these values, a basic software score for each heterogeneous software resource is generated. Finally, based on both the software feature difference value and the basic score, a software differentiation score is generated, with higher scores indicating greater differences in software features between the heterogeneous software resource and other heterogeneous software resources. In this way, for any two heterogeneous software resources, the software feature difference value can accurately quantify the differences between them; the basic score can be used to assess the characteristics of the heterogeneous software resource itself, serving as an anchor for the differentiation score; and finally, the software feature difference value and the basic score can be applied to evaluate the differences among all heterogeneous software resources, generating software differentiation scores that accurately reflect the differences between them.
[0060] It should be noted that during the software resource allocation process, the methods or formulas for generating feature difference values, base scores, differentiated scores, citation scores, and comprehensive scores can be constructed according to specific application scenarios and are not limited to the corresponding methods or formulas in the application examples below. In specific application scenarios, the software feature difference degree can be determined by weighted normalization aggregation of multi-dimensional feature differences. For example, the formula for generating software feature difference values may include:
[0061] ;
[0062] The software feature dissimilarity can also be determined by methods such as logarithmic transformation of differences, normalization, and weighted aggregation. For example, the formula for generating the software feature dissimilarity value may include:
[0063] ;
[0064] The basic software score can be determined through weighted normalization. For example, the formula for generating the basic software score value may include:
[0065] ;
[0066] Alternatively, logarithmic transformation and normalization can be used to weaken the influence of extreme values and obtain a software fundamentals score. For example, the formula for generating the software fundamentals score can include:
[0067] ;
[0068] The uniqueness of software resources in terms of feature dimensions can be quantified by weighting feature differences and nonlinear standardization, thus solving the problem of score clustering and determining differentiated software scores. For example, the formula for generating differentiated software scores can include:
[0069] ; ;
[0070] Software differentiation scores can also be determined using log-weighted variability and range standardization. For example, the formula for generating software differentiation scores can include:
[0071] ; ;
[0072] A dual penalty mechanism can be used to determine the software citation score, which includes both a decay based on the total number of resource uses and a weighted decay based on the number of uses of each feature. For example, the formula for generating the software citation score could include:
[0073] ;
[0074] Alternatively, a dual normalization mechanism combining global citation penalty and feature-weighted balancing can be used to determine the software citation score. For example, the formula for generating the software citation score could include:
[0075] ;
[0076] A weighted linear combination can be used to determine the overall software score. For example, the formula for generating the overall software score may include:
[0077] ;
[0078] Alternatively, a piecewise linear combination of differentiated scores can be used as a threshold to implement a dynamic weighting strategy and determine the overall software score. For example, the formula for generating the overall software score could include:
[0079] ;
[0080] in, Indicates heterogeneous software resources Software citation rating; This represents the i-th heterogeneous software resource; Represents the j-th software feature; This represents a logarithmic operation, used for normalization. This indicates the total number of services that have been instantiated; Indicates heterogeneous software resources The number of references to services that have already been instantiated; Indicates heterogeneous software resources Software features The number of references to the instantiated service; m represents the total number of software features; Representing software features The weights of all software features are 1; where, Indicates heterogeneous software resources heterogeneous software resources The software feature difference value between them; This represents the k-th heterogeneous software resource; Indicates heterogeneous software resources Software features The encoded value; Indicates heterogeneous software resources Software features The encoded value; Representing software features The maximum encoded value; Representing software features The minimum encoded value; Indicates heterogeneous software resources The software's basic score; Indicates heterogeneous software resources Software differentiation scoring; This represents the unprocessed software differentiation score. This represents the minimum unprocessed software differentiation score among all software resources. This represents the maximum value of the unprocessed differential score across all software resources. Indicates heterogeneous software resources The average value of the software feature difference between the software and all other heterogeneous software resources; Indicates heterogeneous software resources Overall software rating; This represents a normalization constant, such as the size of a resource pool. , , , , , Indicates weight, and , , ; The threshold representing the differential scoring.
[0081] It should be noted that the allocation result of software resources can be determined according to the type of software resources. For example, if the software resources are container images used to run application services, the heterogeneous software resource pool of a certain container can be obtained as a software resource set. Based on the software characteristics, the software resources in the software resource set of the container can be compared and scored differently to obtain a comprehensive software score. Then, the image can be allocated according to the comprehensive software score.
[0082] In the exemplary embodiment, the hardware resources corresponding to the execution entity and the service are allocated from heterogeneous hardware resources. Therefore, the principle of allocating the execution entity hardware resources corresponding to the execution entity configuration information in the heterogeneous hardware resource pool and the principle of allocating the service hardware resources corresponding to the service configuration information in the heterogeneous hardware resource pool can be the same. For example, the hardware resources in the hardware resource set can be compared based on hardware characteristics. The differences between the hardware characteristics are compared and scored. For example, different architectures, different operating systems, different container runtimes, different regions divided by tags, and different node specifications are compared. The greater the difference, the higher the score. Then, the resources are allocated based on the score results.
[0083] In specific application scenarios, to facilitate hardware resource allocation by generating hardware difference comparison scores, during the allocation of target hardware resources corresponding to target configuration information in a heterogeneous hardware resource pool, each hardware feature in the heterogeneous hardware resource pool can be encoded to obtain hardware feature encoding values. These encoding values quantify the characteristics of each hardware feature, facilitating subsequent hardware difference score calculations. Based on the hardware feature encoding values and the hardware features contained in the hardware resources, a hardware difference score is generated for the heterogeneous hardware resources in the heterogeneous hardware resource pool. A higher hardware difference score indicates a greater difference between the heterogeneous hardware resource and other heterogeneous hardware resources in terms of hardware feature dimensions, thus representing the differences between heterogeneous hardware resources. The resource status of the heterogeneous hardware resources is analyzed to obtain a status score, which quantifies the resource status of the heterogeneous hardware resources, facilitating the subsequent inclusion of the resource status of heterogeneous hardware resources in the allocation process. Finally, the number of hardware references to each heterogeneous hardware resource and each hardware feature by the instantiated services is obtained. This hardware reference count is used to analyze the impact of the instantiated services on the hardware. The hardware characteristics of a resource are scored based on usage frequency; the fewer times it is used, the higher the score. A hardware reference score is generated for heterogeneous hardware resources based on the number of hardware references and the hardware characteristics they contain. A comprehensive hardware score is generated for heterogeneous hardware resources based on hardware differentiation, status, and hardware reference scores. For example, a weighted calculation is performed on the hardware differentiation, status, and hardware reference scores to generate the comprehensive hardware score. The sum of the weights of the hardware differentiation, status, and hardware reference scores is 1, and their individual weights are flexibly determined according to the application scenario. Thus, a higher comprehensive score indicates that the hardware resource is referenced less, has a better status, and has a greater difference in hardware characteristics from the instantiated service. Based on the comprehensive hardware score, target hardware resources corresponding to the target configuration information are allocated from the heterogeneous hardware resource pool. For example, the group of hardware resources with the highest comprehensive score is selected as candidate hardware resources, and a hardware resource is selected from this group of candidate hardware resources based on application events. For example, if it is an application creation or modification event, a hardware resource is randomly selected from the candidate hardware resources as the target hardware resource.
[0084] As can be seen from the implementation process, this application allocates hardware resources based on the characteristic differences, usage information, and resource status among heterogeneous hardware resources, which expands the reference dimensions for hardware resource allocation and can improve the accuracy of hardware resource allocation. Moreover, the entire process is carried out using a numerical scoring method, which is convenient to implement and can ensure the efficiency of hardware resource allocation. In addition, hardware resources can be selected based on the comprehensive hardware score. The higher the comprehensive hardware score, the fewer the hardware resources are referenced, the better the status, and the greater the difference in hardware characteristics from the instantiated services. This ensures the heterogeneity of the allocated hardware resources and reduces the resource coupling of hardware resource allocation.
[0085] In specific application scenarios, during the process of generating hardware differentiation scores for heterogeneous hardware resources in a heterogeneous hardware resource pool based on hardware feature encoding values and the hardware features contained in the hardware resources, pairwise differentiation comparisons can be performed on the heterogeneous hardware resources in the pool to obtain hardware feature difference values. Based on these values, a basic hardware score for each heterogeneous hardware resource is generated. Finally, based on the hardware feature difference values and the basic hardware score, a hardware differentiation score is generated. A higher hardware differentiation score indicates a greater difference between the heterogeneous hardware resource and other heterogeneous hardware resources in terms of hardware features. In this way, for any two heterogeneous hardware resources, the hardware feature difference values can accurately quantify the differences between them; the basic hardware score can be used to evaluate the characteristics of the heterogeneous hardware resource itself, serving as an anchor for the differentiation score; and finally, the hardware feature difference values and the basic hardware score can be applied to evaluate the differences among all heterogeneous hardware resources, generating hardware differentiation scores that accurately reflect the differences between them.
[0086] It should be noted that during the hardware resource allocation process, the generation methods or formulas for feature difference values, basic score values, differentiated scores, reference scores, status scores, and comprehensive scores can be constructed according to specific application scenarios and are not limited to the corresponding methods or formulas in the following text application examples.
[0087] In specific application scenarios, the hardware feature difference degree can be determined by weighted normalization aggregation of multi-dimensional feature differences. For example, the formula for generating the hardware feature difference degree value includes:
[0088] ;
[0089] Hardware feature dissimilarity can also be determined through logarithmic transformation of differences, normalization, and weighted aggregation. For example, the formulas for generating hardware feature dissimilarity values include:
[0090] ;
[0091] The hardware baseline score can be determined through weighted normalization. For example, the formula for generating the hardware baseline score includes:
[0092] ;
[0093] Alternatively, logarithmic transformation normalization can be used to weaken the influence of extreme values and obtain a hardware fundamentals score. For example, the formula for generating the hardware fundamentals score includes:
[0094] ;
[0095] The uniqueness of hardware resources in terms of feature dimensions can be quantified by weighting feature differences and nonlinear standardization, thus solving the problem of score clustering and determining hardware differentiation scores. For example, the formula for generating hardware differentiation scores includes:
[0096] ; ;
[0097] Hardware differentiation scores can also be determined using log-weighted variability and range standardization. For example, the formulas for generating hardware differentiation scores include:
[0098] ; ;
[0099] The health status of hardware resources can be quantified, and a weighted linear combination can be used to determine the status score. For example, the formula for generating the status score includes:
[0100] ;
[0101] The state score can also be determined by adjusting the score contributions of the CPU and memory using non-linear functions. For example, the formula for generating the state score includes:
[0102] ;
[0103] A dual penalty mechanism can be used to determine the hardware reference score, which includes both a decay based on the total number of resource uses and a weighted decay based on the number of uses of each feature. For example, the formula for generating the hardware reference score includes:
[0104] ;
[0105] Hardware reference scores can also be determined through a dual normalization mechanism combining global reference penalty and feature-weighted balancing. For example, the formula for generating hardware reference scores includes:
[0106] ;
[0107] A weighted linear combination can be used to determine the overall hardware score. For example, the formula for generating the overall hardware score may include:
[0108] ;
[0109] Alternatively, a piecewise linear combination of differentiated scores can be used as thresholds to implement a dynamic weighting strategy to determine the overall hardware score. For example, the formula for generating the overall hardware score could include:
[0110] ;
[0111] in, Indicates heterogeneous hardware resources Status rating; This represents the t-th heterogeneous hardware resource; Indicates heterogeneous hardware resources CPU utilization; The weight representing CPU utilization; Indicates heterogeneous hardware resources The remaining memory; Indicates heterogeneous hardware resources The weight of remaining memory; Indicates heterogeneous hardware resources Total memory; Indicates heterogeneous hardware resources Hardware citation score; This represents the v-th hardware feature; This represents a logarithmic operation, used for normalization. This indicates the total number of services that have been instantiated; Indicates heterogeneous hardware resources The number of references to services that have already been instantiated; Indicates heterogeneous hardware resources Hardware features The number of references to the instantiated service; r represents the total number of hardware features; Representing hardware characteristics The weight of all hardware features is 1; Indicates heterogeneous hardware resources heterogeneous hardware resources Hardware feature difference values between them; This represents the z-th heterogeneous hardware resource; Indicates heterogeneous hardware resources Hardware features The encoded value; Indicates heterogeneous hardware resources Hardware features The encoded value; Representing hardware characteristics The maximum encoded value; Representing hardware characteristics The minimum encoded value; Indicates heterogeneous hardware resources The hardware basic score; Indicates heterogeneous hardware resources Hardware differentiation rating; This represents the unprocessed hardware differentiation score. This represents the minimum unprocessed hardware differentiation score among all hardware resources. This represents the maximum unprocessed hardware differentiation score among all hardware resources; Indicates heterogeneous hardware resources The average value of the hardware characteristic difference between the hardware and all other heterogeneous hardware resources; Indicates heterogeneous hardware resources Overall hardware score; This represents a normalization constant, such as the size of a resource pool. , , , , , , , , Indicates weight, and , , ; The threshold for hardware differentiation scoring.
[0112] It should be noted that the allocation result of hardware resources can be determined according to the type of hardware resources. For example, if the hardware resources are the nodes used to run application services, the hardware resources are a set of nodes. The heterogeneous hardware resource pool corresponding to the service is obtained as the hardware resource set. Based on the hardware characteristics, the hardware resources in the hardware resource set are compared in a differentiated manner, and the status score and reference score are performed to obtain the comprehensive hardware score. Then, the node set is allocated according to the comprehensive hardware score.
[0113] In an exemplary embodiment, if it is an application creation event or modification event, a software resource can be randomly selected from multiple candidate software resources for each adjustment object as the target software resource of the adjustment object, and a hardware resource can be randomly selected from multiple candidate hardware resources for the adjustment object as the target hardware resource of the object. The adjustment object is an executor or a service. If it is an application service rotation event, although the service can be directly deleted and rebuilt without changing its software and hardware resources, or only its hardware resources can be changed, such as moving the service to other nodes, these do not consider the change of software resources, which will reduce the difficulty of attack and thus reduce the security and reliability of the application. To avoid this situation, the process of allocating target heterogeneous resources in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the target configuration information and the target mimicry defense control information, in response to the rotation operation, the target heterogeneous resources allocated before the rotation can be excluded from the heterogeneous software resource pool and the heterogeneous hardware resource pool to obtain candidate resources; according to the target configuration information and the target mimicry defense control information, a substitute resource with the same function but different resources as the target heterogeneous resource allocated before the rotation is determined from the candidate resources; the application is carried based on the substitute resource. It should be noted that this application creates a new functionally equivalent service only during rotation, rather than instantiating multiple functionally equivalent services at the beginning of system runtime. This reduces resource consumption and improves system resource utilization.
[0114] It is understandable that in the process of allocating target software resources corresponding to target configuration information in a heterogeneous software resource pool based on software comprehensive scores, and allocating target hardware resources corresponding to target configuration information in a heterogeneous hardware resource pool based on hardware comprehensive scores, layer-by-layer application can be performed according to the application architecture. For example, for mimicry applications, when there are multiple functionally equivalent executors in a mimicry application, resource operations should be performed according to the comprehensive scores, with each executor as the resource operation object. For non-mimicry applications, when there are multiple functionally equivalent copies in a non-mimicry application, resource operations should be performed according to the comprehensive scores, with each copy as the resource operation object. Furthermore, for a single executor or copy, assuming resource allocation is performed using containers as objects, when there are multiple containers in an executor or copy, resource operations should be performed according to the comprehensive scores, with each container as the resource operation object. It should be noted that whether resource allocation and adjustment are performed on executors, copies, or containers, the corresponding resource operations are performed according to the logic of this application; only the unit of resource operation switches between executors, copies, and containers, without affecting the principle and implementation logic of resource allocation based on comprehensive scores in this application.
[0115] This application provides a method for allocating mimicry defense resources, which involves determining a pre-constructed heterogeneous software resource pool and a heterogeneous hardware resource pool; in response to obtaining execution entity configuration information and execution entity mimicry defense control information for mimicry applications, allocating heterogeneous execution entity resources in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the execution entity configuration information and the execution entity mimicry defense control information, with each execution entity heterogeneous resource corresponding one-to-one with the execution entity of the mimicry application; and in response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications, allocating service heterogeneous resources in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the service configuration information and the service mimicry defense control information, with each service heterogeneous resource corresponding one-to-one with the service of the non-mimicry application. In this application, software and hardware resources are heterogeneously allocated to obtain corresponding heterogeneous resources. Considering that the execution body of a mimicry application may include multiple functional containers, and a non-mimicry application may include various types of services, each service can support multiple copies running, and each copy may include multiple functional containers, resource allocation and adjustment can be performed on mimicry applications at the execution body level, and on non-mimicry applications at the service level. This increases the heterogeneity of both software and hardware resources for both mimicry and non-mimicry applications, and constructs heterogeneous software and hardware resource pools. Before application instantiation, heterogeneous software and hardware resources are selected from these pools, thereby increasing the overall heterogeneity of the service and improving application security. Furthermore, the mimicry defense resource allocation method increases resource allocation for non-mimicry applications, thus expanding the scope of heterogeneous resource allocation for mimicry defense, increasing the universality of mimicry defense, improving the security of non-mimicry applications, and ultimately enhancing the security of mimicry defense.
[0116] Based on the above embodiments of this application, a mimicry defense resource allocation device is also provided, the corresponding description of which can be found in the above embodiments, and may include:
[0117] The mimicry allocation module is used to respond to the acquisition of the execution body configuration information and execution body mimicry defense control information of the mimicry application, and then allocate heterogeneous execution body resources in the pre-built heterogeneous software resource pool and heterogeneous hardware resource pool according to the execution body configuration information and execution body mimicry defense control information. The heterogeneous execution body resources correspond one-to-one with the execution body of the mimicry application.
[0118] The non-mimicry allocation module is used to allocate heterogeneous service resources in the heterogeneous software resource pool and the heterogeneous hardware resource pool in response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications. The heterogeneous service resources correspond one-to-one with the services of non-mimicry applications.
[0119] To facilitate understanding of the mimicry defense resource allocation scheme provided in this application, the scheme will now be described in conjunction with a mimicry defense control system configured according to the mimicry defense resource allocation scheme provided in this application. The structure of the mimicry defense control system can be as follows: Figure 2 As shown, it includes an application orchestration module and a feedback control module. The feedback control module is responsible for the application lifecycle management and negative feedback. Negative feedback includes timed rotation processing and abnormal rotation processing. The feedback control module includes an application management submodule, a weighted heterogeneous resource selection submodule, a timed rotation scheduling submodule, and a rotation processing submodule. The applications include mimicry applications and non-mimicry applications.
[0120] 1. The application orchestration module can orchestrate both mimicry and non-mimicry applications. Specifically, the application orchestration module orchestrates applications based on mimicry defense control information and application configuration information. Then, the feedback control module deploys the application to cluster nodes with heterogeneous characteristics, completing application instantiation. An application consists of services; one or more services constitute an application. The application orchestration module can manage the entire application or a specific service. Orchestration includes the configuration information required for application operation and the control information that enables the application to have mimicry defense capabilities.
[0121] For example, for mimicry applications, the application orchestration module can arrange and integrate all its services and add mimicry defense control information to each service to achieve a mimicry application topology display, making it easy for users to intuitively understand the mimicry application. For non-mimicry applications, the application orchestration module adds service mimicry defense control information to the original configuration information required for application operation, making the orchestration method simple, clearly defined, and reducing the user's cost.
[0122] Building upon this, resource heterogeneity can occur before application orchestration. For example, based on hardware characteristics, including but not limited to architecture, operating system, runtime, region label, and node specifications, hardware resources, such as nodes, can be heterogeneously constructed to form a heterogeneous hardware resource pool, such as a node set. Based on the application's software characteristics, including but not limited to software specifications, programming language, architecture, operating system, middleware, and compilation type, application software resources, such as images, can be heterogeneously constructed to form a heterogeneous software resource pool, such as an image set. Moreover, the heterogeneous software resource pool consists of static resources that do not occupy node resources and are deployed to the nodes for execution when the service is instantiated.
[0123] 2. The application management submodule is responsible for application lifecycle management, including application creation, modification, and deletion. For example, it receives application information orchestrated by the application orchestration module, performs application creation and modification, and if the application is a mimicry application, it sends the execution configuration and control information to the weighted heterogeneous resource selection submodule to obtain the hardware and software resource information selected by the weighted heterogeneous resource selection submodule, generates the execution information, and instantiates the application. If the application is a non-mimicry application, it sends the configuration and control information of the protected service to the weighted heterogeneous resource selection submodule to obtain the hardware and software resource information selected by the weighted heterogeneous resource selection submodule, and instantiates the service. Furthermore, when an application is deleted, the application management submodule deletes the application and all resources it manages.
[0124] 3. For the weighted heterogeneous resource selection submodule, it is used to select software and hardware resources based on service configuration information and mimicry defense control information using a weighted heterogeneous resource selection algorithm. The specific resource selection process can be found in the description of the above embodiments. Furthermore, the weighted heterogeneous resource selection submodule can be applied to different events in the application. For example, for mimicry applications, algorithm processing is performed when the execution body creation or modification event occurs, and when the execution body timed rotation or abnormal rotation event occurs. For non-mimicry applications, algorithm processing is performed when the protected service copy creation or modification event occurs, and when the protected service copy timed rotation event occurs. That is, when the application service creation or modification event occurs, the weighted heterogeneous resource selection submodule is called by the application management submodule; when the application service timed rotation or abnormal rotation event occurs, the weighted heterogeneous resource selection submodule is called by the rotation processing submodule.
[0125] In an exemplary embodiment, the weighted heterogeneous resource selection algorithm includes four sub-algorithms: weighted calculation of software and hardware resources, software resource selection, hardware resource selection, and multi-container resource coordination. The weighted calculation sub-algorithm is used to determine the priority of software resource selection and hardware resource selection. The software resource selection is used to allocate software resources, and the hardware resource selection is used to allocate hardware resources. The multi-container resource coordination sub-algorithm is used to determine the software resource architecture information of other containers based on the architecture information of the software resources selected by the container. Based on this, the software resource selection sub-algorithm is called sequentially for other containers to obtain software resources, thereby completing the multi-container software resource selection.
[0126] Specifically, during the execution of the multi-container resource coordination sub-algorithm, architectural information can be obtained from the software resources acquired by the first container using the software resource selection sub-algorithm. For other containers, the heterogeneous software resource pool corresponding to the container is obtained sequentially, the software resources are filtered using the architectural information, and the filtered software resource set is used to execute the software resource selection sub-algorithm to obtain the software resources for that container. This cyclical operation can obtain the software resources of multiple containers of an executor or service. Furthermore, the processing object of the mimicry application is multiple containers of an executor, and the use of heterogeneous software resources among containers with the same function in multiple executors achieves software heterogeneity. The processing object of the non-mimicry application is multiple replicas of containers, and the use of heterogeneous software resources among containers with the same function in multiple replicas achieves software heterogeneity. This multi-container software resource heterogeneity can maximize the heterogeneity between services.
[0127] 4. For the timed rotation scheduling submodule, the timed rotation scheduling submodule is used to periodically detect applications. Based on the application's timed rotation strategy control information, it selects services to generate timed rotation resources for subsequent rotation operations. For example, for mimicry applications, timed rotation selects the execution body, and for non-mimicry applications, timed rotation selects the protected service.
[0128] 5. For the rotation processing submodule, this module handles timed or abnormal rotation resources. Abnormal rotation resources are created after the mimicry application's arbiter determines that the mimicry application's execution body is abnormal. The rotation processing submodule performs service rotation based on the rotation resource information. The rotated service can be cleaned and restored, and a new functionally equivalent service is created. During the new service creation process, the rotation processing submodule calls the weighted heterogeneous resource selection submodule to select software and hardware resources. These two resources are different from the two resources of the rotated service. The selected software and hardware resources are used to instantiate the service, replacing the rotated service.
[0129] Based on this, when it is necessary to create or modify an application, such as Figure 3 As shown, the application creation or modification process involves three modules: an application orchestration module, an application management submodule, and a weighted heterogeneous resource selection submodule, which may include the following steps:
[0130] The application orchestration module orchestrates applications, sets mimicry defense control information, and application configuration information.
[0131] The application management submodule manages the lifecycle of applications based on application orchestration information. During the creation or modification of an application, it calls the weighted heterogeneous resource selection submodule to obtain hardware and software resources, complete service configuration, and realize the instantiation and deployment of each service of the application.
[0132] The weighted heterogeneous resource selection submodule calculates the heterogeneity of software and hardware resources based on service configuration and control information, selects software and hardware resources from the heterogeneous software resource pool and the heterogeneous hardware resource pool, and returns them to the application management submodule.
[0133] When timed rotation is required, such as Figure 4 As shown, the timed rotation processing flow involves three modules: a timed rotation scheduling submodule, a rotation processing submodule, and a weighted heterogeneous resource selection submodule, which may include the following steps:
[0134] The periodic rotation scheduling submodule detects the application's periodic rotation strategy configuration information and information on multiple services to be rotated, and generates periodic rotation resources. For example, when a certain service reaches the specified rotation period, periodic rotation resources are generated based on that service. The mimicry application selects the execution body for periodic rotation, while the non-mimicry application selects the protected service for periodic rotation.
[0135] The rotation processing submodule handles timed rotation resources, cleans and restores the services involved in the timed rotation resources, and calls the weighted heterogeneous resource selection submodule.
[0136] The weighted heterogeneous resource selection submodule, based on the information of the service being rotated, calculates the heterogeneity of software and hardware resources after excluding the software and hardware resources of the service being rotated, selects software and hardware resources from the heterogeneous software resource pool and the heterogeneous hardware resource pool, and returns them to the rotation processing submodule.
[0137] The rotation processing submodule obtains the software and hardware resources selected by the weighted heterogeneous resource selection submodule, creates a functionally equivalent service, configures the service using the obtained software and hardware resources, instantiates the service, and replaces the service being rotated.
[0138] When abnormal rotation is required, such as Figure 5 As shown, the exception rotation handling process involves a rotation handling submodule and a weighted heterogeneous resource selection submodule, and may include the following steps:
[0139] The arbiter detects mimicry applications, finds anomalies in the mimicry application's execution, and generates abnormal rotation resources.
[0140] The rotation processing submodule handles abnormal rotation resources, cleans and restores the execution bodies involved in the abnormal rotation resources, and calls the weighted heterogeneous resource selection submodule.
[0141] The weighted heterogeneous resource selection submodule obtains the configuration and control information of the mimicry application executor to be rotated, and selects software and hardware resources;
[0142] The rotation processing submodule obtains the software and hardware resources selected by the weighted heterogeneous resource selection submodule, creates a functionally equivalent executor, configures the executor using the obtained software and hardware resources, instantiates the executor, and replaces the executor being rotated.
[0143] For ease of understanding, let's assume that the mimicry defense control system of this application is used to allocate resources to multiple containers of the mimicry application's execution body, such as... Figure 6 As shown, the following processes may be included:
[0144] In response to events such as the creation or modification of a mimicry application, or abnormal or timed rotation of a mimicry application, configuration information and mimicry defense control information of multiple functionally equivalent executors are obtained.
[0145] Determine if there are any executables that have not selected hardware and software resources;
[0146] If it does not exist, then the process ends;
[0147] If it exists, select the configuration information and mimicry defense control information of the executor;
[0148] The weighted calculation sub-algorithm for software and hardware resources determines the priority of software and hardware resource selection;
[0149] Determine whether software resources have a high priority;
[0150] If the software resource selection priority is high, the multi-container software resource selection process of the execution body is carried out; the hardware resource selection sub-algorithm filters the heterogeneous hardware resource pool of the execution body according to the architecture information of the software resource selection, forms the hardware resource set of the execution body, selects the set of hardware resources with the highest score, and selects one of the hardware resources according to the mimicry application event.
[0151] If the hardware resource selection priority is high, the hardware resource selection sub-algorithm uses the heterogeneous hardware resource pool of the execution entity as the hardware resource set for calculation, selects the set of hardware resources with the highest score, and selects one of the hardware resources according to the mimicry application event; and performs the execution entity multi-container software resource selection process.
[0152] The process for selecting resources for multi-container software is as follows: Figure 7 As shown, the process includes the following:
[0153] If the executor consists of multiple containers, the first container is selected;
[0154] Determine whether software resources have a high priority;
[0155] If the software resources have high priority, the heterogeneous software resource pool of the container is used as the software resource set; if the hardware resources have high priority, the heterogeneous software resource pool of the container is filtered according to the hardware resource architecture information selected by the executor to form a software resource set.
[0156] The software resource selection sub-algorithm calculates the software resource set and selects the group of software resources with the highest comprehensive score, and selects one of the software resources based on the mimicry application event;
[0157] Invoke the multi-container resource coordination sub-algorithm and determine if there are any unselected containers;
[0158] The multi-container resource coordination sub-algorithm filters the heterogeneous software resource pool of each container in the other containers according to the software resource architecture information selected by the first container, forming the software resource set of that container; and determines whether there are any unselected containers.
[0159] If there are unselected containers, select one container, use the software resource set of that container, and return the steps of the software resource selection sub-algorithm to calculate the software resource set.
[0160] If no unselected containers exist, the multi-container software resource selection process ends.
[0161] Suppose that the mimicry defense control system of this application is used to allocate resources to multiple containers of replicas of non-mimicry applications, such as Figure 8 As shown, the following processes may be included:
[0162] In response to events such as the creation or modification of non-mimicry applications or the timed rotation of non-mimicry applications, configuration information and mimicry defense control information of multiple functionally equivalent copies are obtained;
[0163] Determine if there are copies that have not undergone hardware and software resource selection;
[0164] If it does not exist, then the process ends;
[0165] If it exists, select the configuration information and mimicry defense control information of that copy;
[0166] The weighted calculation sub-algorithm for software and hardware resources determines the priority of software and hardware resource selection;
[0167] Determine whether software resources have a high priority;
[0168] If the software resource selection priority is high, the replica multi-container software resource selection process is carried out; the hardware resource selection sub-algorithm filters the heterogeneous hardware resource pool of the replica according to the architecture information of the software resource selection, forms the hardware resource set of the replica, selects the set of hardware resources with the highest score, and selects one of the hardware resources according to the non-mimicry application event.
[0169] If the hardware resource selection priority is high, the hardware resource selection sub-algorithm uses the heterogeneous hardware resource pool of the replica as the hardware resource set for calculation, selects the set of hardware resources with the highest score, and selects one of the hardware resources based on the non-mimicry application event; and performs the replica multi-container software resource selection process.
[0170] The process for selecting software resources for multiple replica containers is as follows: Figure 9 As shown, the process includes the following:
[0171] If the copy consists of multiple containers, the first container is selected;
[0172] Determine whether software resources have a high priority;
[0173] If the software resources have high priority, the heterogeneous software resource pool of the container is used as the software resource set; if the hardware resources have high priority, the heterogeneous software resource pool of the container is filtered according to the hardware resource architecture information selected by the replica to form the software resource set.
[0174] The software resource selection sub-algorithm calculates the software resource set and selects the group of software resources with the highest comprehensive score, and selects one of the software resources based on the non-mimicry application event;
[0175] Invoke the multi-container resource coordination sub-algorithm and determine if there are any unselected containers;
[0176] The multi-container resource coordination sub-algorithm filters the heterogeneous software resource pool of each container in the other containers according to the software resource architecture information selected by the first container, forming the software resource set of that container; and determines whether there are any unselected containers.
[0177] If there are unselected containers, select one container, use the software resource set of that container, and return the steps of the software resource selection sub-algorithm to calculate the software resource set.
[0178] If no unselected containers exist, the multi-container software resource selection process ends.
[0179] This application also provides an electronic device and a computer-readable storage medium, both of which have the corresponding effects of the mimicry defense resource allocation method provided in the embodiments of this application. Please refer to... Figure 10 , Figure 10 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application.
[0180] An electronic device provided in this application includes a memory 201 and a processor 202. The memory 201 stores a computer program, and when the processor 202 executes the computer program, it implements the steps of the mimicry defense resource allocation method described in any of the above embodiments.
[0181] Please see Figure 11 Another electronic device provided in this application embodiment may further include: an input port 203 connected to the processor 202 for transmitting commands input from the outside to the processor 202; a display unit 204 connected to the processor 202 for displaying the processing results of the processor 202 to the outside; and a communication module 205 connected to the processor 202 for enabling communication between the electronic device and the outside. The display unit 204 may be a display panel, a laser scanner, or the like; the communication method used by the communication module 205 includes, but is not limited to, Mobile High-Definition Link (MHL), Universal Serial Bus (USB), High-Definition Multimedia Interface (HDMI), wireless connectivity: Wireless Fidelity (WiFi), Bluetooth communication technology, Bluetooth Low Energy communication technology, and communication technology based on IEEE 802.11s.
[0182] This application provides a computer-readable storage medium storing a computer program. When executed by a processor, the computer program implements the steps of the mimicry defense resource allocation method described in any of the above embodiments.
[0183] The computer-readable storage media involved in this application include random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable disks, CD-ROMs (compact disc read-only memory), or any other form of storage media known in the art.
[0184] This application provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the mimicry defense resource allocation method described in any of the above embodiments.
[0185] For descriptions of relevant parts of the mimicry defense resource allocation device, computer program product, electronic device, and computer-readable storage medium provided in this application's embodiments, please refer to the detailed descriptions of the corresponding parts in the mimicry defense resource allocation method provided in this application's embodiments; they will not be repeated here. Furthermore, parts of the technical solutions provided in this application's embodiments that are consistent with the implementation principles of corresponding technical solutions in the prior art have not been described in detail to avoid excessive elaboration.
[0186] It should also be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0187] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for allocating mimicry defense resources, characterized in that, include: In response to obtaining the execution body configuration information and execution body mimicry defense control information of the mimicry application, the execution body heterogeneous resources are allocated in the pre-built heterogeneous software resource pool and heterogeneous hardware resource pool according to the execution body configuration information and the execution body mimicry defense control information, and the execution body heterogeneous resources correspond one-to-one with the execution body of the mimicry application; In response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications, service heterogeneous resources are allocated in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the service configuration information and the service mimicry defense control information. The service heterogeneous resources correspond one-to-one with the services of the non-mimicry applications. The allocation of target heterogeneous resources in the target heterogeneous resource pool includes: Based on the characteristics of each resource in the target heterogeneous resource pool, a differentiated score for the resources in the target heterogeneous resource pool is generated; Generate a reference score for the resource based on the reference information of the instantiated service to the resource; A comprehensive score for the resource is generated based on the differential score and the citation score. Based on the comprehensive score, target heterogeneous resources are allocated in the target heterogeneous resource pool; Wherein, when the target heterogeneous resource pool is the heterogeneous software resource pool, the target heterogeneous resources include target software resources; when the target heterogeneous resource pool is the heterogeneous hardware resource pool, the target heterogeneous resources include target hardware resources.
2. The method according to claim 1, characterized in that, Allocating target software resources in the heterogeneous software resource pool includes: Each software feature in the heterogeneous software resource pool is encoded to obtain software feature encoding values; Based on the software feature encoding value and the software features contained in the software resources, a software differentiation score is generated for the heterogeneous software resources in the heterogeneous software resource pool; Get the number of software references that instantiated services use for each heterogeneous software resource and each software feature; Based on the number of software citations and the software characteristics contained in the software resources, a software citation score for heterogeneous software resources is generated; Based on the software differentiation score and the software citation score, a comprehensive software score for heterogeneous software resources is generated; Based on the comprehensive software score, target software resources are allocated in the heterogeneous software resource pool.
3. The method according to claim 2, characterized in that, The step of generating a software differentiation score for heterogeneous software resources in the heterogeneous software resource pool based on the software feature encoding value and the software features contained in the software resources includes: Based on the software feature encoding value and the software features contained in the software resources, the heterogeneous software resources in the heterogeneous software resource pool are compared pairwise to obtain the software feature difference value. Based on the software feature encoding value and the software features contained in the software resources, a basic software score value for heterogeneous software resources is generated; Based on the software feature difference value and the software basic score value, a software differentiation score is generated for heterogeneous software resources.
4. The method according to claim 1, characterized in that, Allocating target hardware resources in the heterogeneous hardware resource pool includes: Each hardware feature in the heterogeneous hardware resource pool is encoded to obtain hardware feature encoding values; Based on the hardware feature encoding value and the hardware features contained in the hardware resources, a hardware differentiation score for heterogeneous hardware resources in the heterogeneous hardware resource pool is generated. The resource status of heterogeneous hardware resources is analyzed to obtain a status score; Get the number of hardware references of instantiated services to each heterogeneous hardware resource and each hardware feature; Based on the number of hardware references and the hardware characteristics contained in the hardware resources, a hardware reference score for heterogeneous hardware resources is generated. Based on the hardware differentiation score, the status score, and the hardware reference score, a comprehensive hardware score for heterogeneous hardware resources is generated. Based on the comprehensive hardware score, target hardware resources are allocated in the heterogeneous hardware resource pool.
5. The method according to claim 4, characterized in that, The step of generating a hardware differentiation score for heterogeneous hardware resources in the heterogeneous hardware resource pool based on the hardware feature encoding value and the hardware features contained in the hardware resources includes: Based on the hardware feature encoding value and the hardware features contained in the hardware resources, the heterogeneous hardware resources in the heterogeneous hardware resource pool are compared pairwise to obtain the hardware feature difference value. Based on the hardware feature encoding value and the hardware features contained in the hardware resources, a basic hardware score value for heterogeneous hardware resources is generated. Based on the hardware feature difference value and the hardware basic score value, a hardware differentiation score for heterogeneous hardware resources is generated.
6. The method according to claim 1, characterized in that, Based on the target configuration information and the target mimicry defense control information, target heterogeneous resources are allocated in the heterogeneous software resource pool and the heterogeneous hardware resource pool, including: In response to performing a rotation operation, the target heterogeneous resources allocated before the rotation are excluded from the heterogeneous software resource pool and the heterogeneous hardware resource pool to obtain candidate resources; Based on the target configuration information and the target mimicry defense control information, a substitute resource with the same function but different resources as the heterogeneous target resource allocated before the rotation is determined from the candidate resources; Applications are hosted based on backup resources.
7. The method according to claim 1, characterized in that, Based on the target configuration information and the target mimicry defense control information, target heterogeneous resources are allocated in the heterogeneous software resource pool and the heterogeneous hardware resource pool, including: Obtain resource allocation priority information; In response to the resource allocation priority information indicating that resource allocation is first performed based on software resources, target software resources corresponding to the target configuration information are allocated in the heterogeneous software resource pool according to the target configuration information and the target mimicry defense control information; and target hardware resources corresponding to the target configuration information are allocated in the heterogeneous hardware resource pool according to the target software resources. In response to the resource allocation priority information indicating that resource allocation is first performed based on hardware resources, target hardware resources corresponding to the target configuration information are allocated in the heterogeneous hardware resource pool according to the target configuration information and the target mimicry defense control information; and target software resources corresponding to the target configuration information are allocated in the heterogeneous software resource pool according to the target hardware resources. The target software resources and target hardware resources corresponding to the target configuration information are regarded as target heterogeneous resources; Wherein, when the target configuration information is the execution body configuration information, the target heterogeneous resource is the execution body heterogeneous resource, and the target mimicry defense control information is the execution body mimicry defense control information; when the target configuration information is the service configuration information, the target heterogeneous resource is the service heterogeneous resource, and the target mimicry defense control information is the service mimicry defense control information.
8. A mimicry defense resource allocation device, characterized in that, include: The mimicry allocation module is used to respond to the acquisition of the execution body configuration information and execution body mimicry defense control information of the mimicry application, and then allocate heterogeneous execution body resources in the pre-built heterogeneous software resource pool and heterogeneous hardware resource pool according to the execution body configuration information and the execution body mimicry defense control information, and the heterogeneous execution body resources correspond one-to-one with the execution body of the mimicry application; The non-mimicry allocation module is used to, in response to obtaining service configuration information and service mimicry defense control information for non-mimicry applications, allocate heterogeneous service resources in the heterogeneous software resource pool and the heterogeneous hardware resource pool according to the service configuration information and the service mimicry defense control information, wherein the heterogeneous service resources correspond one-to-one with the services of the non-mimicry applications; The allocation of target heterogeneous resources in the target heterogeneous resource pool includes: generating differentiated scores for resources in the target heterogeneous resource pool based on the characteristics of each resource in the target heterogeneous resource pool; generating reference scores for resources based on reference information of instantiated services; generating comprehensive scores for resources based on differentiated scores and reference scores; and allocating target heterogeneous resources in the target heterogeneous resource pool based on the comprehensive scores. Wherein, when the target heterogeneous resource pool is the heterogeneous software resource pool, the target heterogeneous resources include target software resources; when the target heterogeneous resource pool is the heterogeneous hardware resource pool, the target heterogeneous resources include target hardware resources.
9. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the mimicry defense resource allocation method according to any one of claims 1 to 7.
10. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, configured to implement the steps of the mimicry defense resource allocation method according to any one of claims 1 to 7 when executing the computer program.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the mimicry defense resource allocation method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Resource configuration method and device, electronic equipment and storage medium
CN117971499A
Container CPU resource scheduling and isolation method and apparatus, and storage medium and electronic device
WO2023045467A1