Network switch security monitoring method, device and medium based on artificial intelligence
By adopting artificial intelligence-based security monitoring methods on network switches, using RSA and AES encryption technology to ensure data security, and optimizing task processing through custom allocation algorithms, the problems of limited resources and data security risks of network switches are solved, and timely task processing and load balancing are achieved.
Patent Information
- Application Number
- CN202210421831.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-21
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2042-04-21
AI Technical Summary
When a network switch handles tasks sent by multiple terminals, limited resources lead to delay in task processing, and data may be leaked during transmission, which poses a security risk.
Using artificial intelligence-based network switch security monitoring method, task data is encrypted through RSA public key and AES key to ensure data security. At the same time, use a custom allocation algorithm to dynamically allocate resources, optimize the task queue, and ensure that tasks are processed in a timely manner according to priority.
It effectively improves the security of network switch data transmission, avoids data leakage, and ensures timely processing of tasks through dynamic resource allocation, maintains the balance of network switch load.
Smart Images

Figure CN114710288B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence technology, and in particular to an artificial intelligence-based network switch security monitoring method, device and medium. Background Art
[0002] Artificial Intelligence (AI) is a technology that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, collect information, acquire knowledge, and use the learned knowledge to process the collected information to obtain the best results.
[0003] With the popularization of the Internet, network switches are widely used. When terminal devices transmit data through network switches, if the data is not strictly encrypted and protected, it may lead to data leakage and cause security risks.
[0004] When multiple terminals send task information to the network switch to request the network switch to process it, due to the limited resources of the network switch, it is impossible to process all tasks in a timely manner at the same time, which can easily cause the tasks sent by the terminals to be delayed, resulting in an unbalanced load on the network switch.
[0005] Therefore, how to ensure that the tasks received by the network switch are processed in a timely manner while ensuring the data security of the network switch. Summary of the invention
[0006] In view of this, the present invention provides an artificial intelligence-based network switch security monitoring method, device and medium, which can not only ensure the data security of the network switch, but also ensure that the tasks received by the network switch are processed in a timely manner.
[0007] To solve the above technical problems:
[0008] In a first aspect, the present invention provides a network switch security monitoring method based on artificial intelligence, which is used for a network switch, comprising the steps of:
[0009] Receive task information sent by the client, parse any received task information to obtain a corresponding parsing result, and generate an initial task queue according to the parsing result;
[0010] Allocating the resources of the network switch to the tasks in the initial task queue according to a custom allocation algorithm, and after the resources are allocated, obtaining the resource allocation results of the tasks in the initial task queue according to the resource allocation situation;
[0011] And, according to the resource allocation result, the tasks of the corresponding initial task queue are allocated to the distributed task queue and the undistributed task queue;
[0012] Adding newly added tasks to the undistributed task queue, dynamically assigning priorities to the tasks in the undistributed task queue according to preset rules, optimizing the tasks in the undistributed task queue according to their priorities, and obtaining an optimized task queue;
[0013] The priority of a task to be executed is the ratio of the resources required to be consumed by the task to the total resources required to be consumed by all tasks to be executed;
[0014] Among them, the newly added tasks are the tasks sent by the client that are received in real time by the network switch;
[0015] The tasks in the optimization task queue are executed in order of priority from high to low to obtain the execution results of the tasks;
[0016] Perform corresponding operations based on the execution results of the task.
[0017] Preferably, any received task information is parsed to obtain a corresponding parsing result, specifically:
[0018] Receive task information sent by the client;
[0019] Parsing the received task information to obtain the first encrypted data in the request header of the task information and the encrypted task data;
[0020] Decrypt the first encrypted data using the RSA private key to obtain an AES key;
[0021] The encrypted task data is decrypted using the AES key to obtain the decrypted task data.
[0022] Through the above technical solution, the task data sent by the client is encrypted by the AES key and the RSA public key. The double encryption technology improves the security of data transmission and avoids the leakage of task data.
[0023] Preferably, generating an initial task queue according to the parsing result includes:
[0024] The decrypted task data is the task to be executed after parsing;
[0025] A task queue is formed by all the tasks to be executed obtained by parsing, and the priority of each task to be executed in the task queue is calculated;
[0026] After determining the priority of each task to be executed, all tasks to be executed are arranged in descending order of priority to form an initial task queue;
[0027] The parsing result includes the first encrypted data, the encrypted task data and the decrypted task data.
[0028] Through the above technical solution, after receiving the task information, the received task information is parsed to obtain the decrypted task data. By parsing all the received task information, the decrypted task data is obtained. Among them, the decrypted task data includes the type of resources required to execute the task and the amount of resources required.
[0029] All parsed tasks are added to the task queue to be processed, and the ratio of the amount of resources consumed by each task to the amount of resources consumed by all tasks is calculated to determine the priority of each task.
[0030] The tasks to be processed are sorted from high to low according to their priorities, thereby generating an initial task queue. The tasks in the initial task queue are arranged from high to low according to their priorities, so that the tasks can be executed in order of priority.
[0031] Preferably, resources allocated to any task in the distributed task queue meet the execution requirements of the task.
[0032] Through the above technical solution, according to the custom allocation algorithm, the tasks in the initial task queue are allocated resources. Among them, some tasks are allocated sufficient resources to meet the needs of task execution. Such tasks are classified into the distributed task queue. The tasks in the distributed task queue are allocated sufficient resources and can be executed in time, thereby achieving timely response to the task information sent by the client.
[0033] Preferably, no resources are allocated to the tasks in the undistributed task queue or the allocated resources do not meet the execution requirements of the tasks.
[0034] Through the above technical solution, when the tasks in the initial task queue are not allocated resources, or the allocated resources cannot meet the task execution needs, the tasks are classified into the undistributed task queue. The priority of the tasks in the undistributed task queue is relatively low, and they are not allocated enough resources and cannot be executed in time. The tasks will be appropriately delayed. Since the priority of the tasks in the undistributed task queue is relatively low, they are not in a hurry to be executed, and appropriate delays will not cause system failures.
[0035] Preferably, the custom allocation algorithm includes:
[0036] For any task, determine the priority of the task in the initial task queue;
[0037] Allocate resources to tasks in the initial task queue based on task priority and resource requirements;
[0038] Compare the amount of resources allocated to a task with the amount of resources required by the task to determine whether the resources allocated to the task meet the requirements;
[0039] If the amount of resources allocated to a task cannot meet the resource needs of the task, the resources allocated to the task are updated according to the priority of the task and the resource needs of the task;
[0040] If the amount of resources allocated to a task can satisfy the resource requirements of the task, the resources allocated to the task are not updated.
[0041] Through the above technical solution, resources are allocated accordingly according to the priority of the task and the amount of resources required by the task, so that tasks with higher priority can be allocated resources that meet their needs and be executed in time, thereby improving the timeliness of the response to the client task.
[0042] After the task is allocated system resources, by comparing the amount of resources required by the task with the amount of resources allocated to the task, it is determined whether the task has been allocated resources that meet its needs, and corresponding adjustments are made so that the task can be executed in a timely manner, improving the timeliness of the network switch's response to the task information sent by the client and avoiding some tasks being prolonged.
[0043] Preferably, the priority is dynamically assigned to the tasks in the undistributed task queue based on preset rules, specifically: the priority of the task is updated based on the amount of resources required to execute a task, the amount of resources still lacking after the task is allocated resources, and the queuing time T of the task in the undistributed task queue.
[0044] Through the above technical scheme, a comprehensive evaluation of the task is achieved by comprehensively considering the amount of resources required to execute a task, the amount of resources still lacking to execute the task, and the queuing time T of the task in the undistributed task queue, thereby giving a task a reasonable priority, which facilitates the timely execution of the task while taking into account the allocation of resources.
[0045] Preferably, performing corresponding operations according to the task execution result comprises the steps of:
[0046] Determine whether the task has been completed based on the task execution results;
[0047] If the task is completed, the task execution result is sent to the client in response to the task information sent by the client;
[0048] If the execution of a task is interrupted, the interrupted task is put into the undistributed task queue for the next resource allocation.
[0049] Through the above technical solution, when the task is completed, the task execution result is sent to the corresponding client in time, so as to achieve timely response to the task execution. When the task execution is interrupted, the interrupted task is put into the undistributed task queue as an unexecuted task, and resources are reallocated. According to whether the task is completed, corresponding operations are taken to achieve timely processing of the task.
[0050] Second, the network switch security monitoring device based on artificial intelligence includes:
[0051] The initial task queue generation module is used to receive the task information sent by the client, parse any of the received task information to obtain a corresponding parsing result, and generate an initial task queue according to the parsing result;
[0052] A task resource allocation module, used to allocate resources to the tasks in the initial task queue according to a custom allocation algorithm, and after the resources are allocated, obtain the resource allocation results of the tasks in the initial task queue according to the resource allocation situation;
[0053] And, according to the resource allocation result, the tasks of the corresponding initial task queue are allocated to the distributed task queue and the undistributed task queue;
[0054] A dynamic priority allocation module is used to add newly added tasks to the undistributed task queue, dynamically allocate priorities to the tasks in the undistributed task queue according to preset rules, and optimize the tasks in the undistributed task queue according to the priorities to obtain an optimized task queue;
[0055] A task execution module, used to execute the tasks in the optimization task queue in order of priority from high to low, and obtain the execution results of the tasks;
[0056] The task execution result judgment module is used to perform corresponding operations according to the task execution results.
[0057] In a third aspect, the present invention provides a storage medium, in which program instructions are stored. When the program instructions are executed, they are used to implement the artificial intelligence-based network switch security monitoring method described in the first aspect.
[0058] The beneficial effects of the above technical solution of the present invention are as follows:
[0059] (1) The artificial intelligence-based network switch security monitoring method of the present application encrypts the data between the client and the network switch through the RSA public key and the AES key, thereby improving the security of data interaction between the client and the network switch and avoiding data leakage.
[0060] (2) The artificial intelligence-based network switch security monitoring method of the present application dynamically allocates resources for tasks sent by clients based on a custom allocation algorithm to keep the load of the network switch balanced, ensuring that tasks sent by each client can be processed within a reasonable time and avoiding excessive delays in tasks.
[0061] The artificial intelligence-based network switch security monitoring method of the present application can effectively ensure data security, while dynamically allocating resources according to task priorities, ensuring that the network switch is responsible for maintaining balance and reducing security risks during the operation of the network switch. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 A flowchart of the network switch security monitoring method based on artificial intelligence of the present invention;
[0063] Figure 2 A flowchart of the present invention for parsing any received task to obtain a parsing result;
[0064] Figure 3 A flowchart of generating an initial task queue according to the parsing results of the present invention;
[0065] Figure 4 A flowchart of a custom allocation algorithm of the present invention;
[0066] Figure 5 It is a flow chart of performing corresponding operations according to the task execution results of the present invention. DETAILED DESCRIPTION
[0067] To make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the following will be combined with the appended drawings of the embodiments of the present invention. Figure 1-5 , the technical scheme of the embodiment of the present invention is clearly and completely described. Obviously, the described embodiment is a part of the embodiment of the present invention, not all of the embodiments. Based on the described embodiment of the present invention, all other embodiments obtained by ordinary technicians in this field belong to the scope of protection of the present invention.
[0068] Network switches generally face two security risks in actual use. On the one hand, there is the risk of information leakage caused by imperfect encryption measures. On the other hand, the tasks received by the network switch cannot be processed in time, resulting in unbalanced load on the network switch. Therefore, how to ensure the data security of the network switch and ensure that the task information sent by the client received by the network switch is processed in time, so that the load of the network switch remains balanced and reliable is a technical problem that needs to be solved urgently.
[0069] Before sending task data to the network switch, the client encrypts the task data to be sent to the network switch according to the encryption algorithm (RSA encryption and AES encryption) to ensure the security of the task data. The specific process is as follows:
[0070] The network switch uses a key generation tool to generate an AES key. The key generation tool is keytool, which is a key and certificate management tool. Keytool is used to generate an AES key and use the AES key to encrypt the task data to be transmitted. Since the AES algorithm is a well-known technology, it will not be described in detail in this solution.
[0071] An RSA public key is generated according to an RSA algorithm, and the AES key is encrypted using the RSA public key to obtain first encrypted data, and the first encrypted data is put into a request header of the task data to generate task information.
[0072] Since the RSA algorithm is a well-known technology, its encryption process will not be described in detail in this solution. The request header can be an http request header. The http protocol is a hypertext transfer protocol, which is an application layer protocol for transmitting hypermedia documents. At the same time, since the http protocol is a stateless protocol, no data will be retained between the client and the network switch. At this point, the client can send task information to the network switch.
[0073] The above encryption method not only considers the security of task data, but also takes into account the performance of the network switch system. Since the RSA algorithm has a slow operation speed when encrypting data, directly encrypting all task data to be transmitted with RSA will lead to slow network communication and reduced data transmission speed. Since AES in the symmetric key cryptographic system has a fast operation speed and high security, using AES keys to encrypt the transmitted task data can effectively improve the transmission efficiency of task data.
[0074] In this embodiment, the client may be a mobile phone or a computer.
[0075] After receiving the task information sent by the client, the network switch processes it as follows.
[0076] See attached Figure 1 and attached Figure 2 , a network switch security monitoring method based on artificial intelligence, used for a network switch, comprises the steps of:
[0077] Step S1: The network switch receives task information sent by the client, parses any received task information to obtain a corresponding parsing result, and generates an initial task queue according to the parsing result.
[0078] The step of parsing any received task information to obtain a corresponding parsing result includes the following steps:
[0079] Step S11: The network switch receives the task information sent by the client.
[0080] Step S12: The network switch parses the received task information to obtain the first encrypted data in the request header of the task information and the encrypted task data.
[0081] Step S13: The network switch uses the RSA private key to decrypt the first encrypted data to obtain an AES key.
[0082] Step S14: The network switch uses the AES key to decrypt the encrypted task data to obtain decrypted task data.
[0083] See attached Figure 3 , the generating of the initial task queue according to the parsing result includes:
[0084] Step S15: The decrypted task data is the task to be executed obtained by parsing.
[0085] Step S16: All the tasks to be executed obtained by parsing form a task queue, and the priority of each task to be executed in the task queue is calculated.
[0086] Step S17: After determining the priority of each task to be executed, all tasks to be executed are arranged in order of priority from high to low to form an initial task queue.
[0087] The parsing result includes the first encrypted data, the encrypted task data and the decrypted task data.
[0088] The priority of a task to be executed is the ratio of the resources required to be consumed by the task to the total resources required to be consumed by all tasks to be executed.
[0089] The larger the ratio corresponding to a task is, the higher the priority of the task is. The higher the priority of a task is, the more resources are consumed when executing the task, and the more threads are allocated when the task is executed.
[0090] All tasks to be executed are added to the task queue to be processed in order of priority from high to low, thereby generating the initial task queue.
[0091] In one embodiment, the network switch receives multiple tasks to be processed at the same time, and sorts the multiple tasks to be processed according to their priorities to generate an initial task queue. After parsing the task information and obtaining the decrypted task data, the network switch sends a response message to the client that sent the task information to notify the client that the task information has arrived at the network switch.
[0092] After the client sends the task information to the network switch, in order to ensure that the processing result of the task can be obtained smoothly, it will send a heartbeat request to the network switch according to the preset period to obtain heartbeat information, and judge whether the communication connection with the network switch is maintained based on the heartbeat information.
[0093] If the client and the network switch maintain a communication connection, the client continues to send a heartbeat request to the network switch according to a preset period to obtain heartbeat information.
[0094] If the communication between the client and the network switch is interrupted, the client sends a TCP connection request to the network switch to re-establish the communication connection between the client and the network switch.
[0095] In one embodiment, the heartbeat information is a fixed message sent to the network switch at fixed intervals according to a preset code script, for example, a query message (for example, the number 1) is sent every minute (the preset period is 1 minute), and the network switch replies with a preset response message (for example, the number 1) after receiving the query message. If the client does not receive the response message from the network switch within one minute, the network switch and the client do not maintain a communication connection.
[0096] Step S2: Allocate resources to the tasks in the initial task queue according to a custom allocation algorithm. After the resources are allocated, obtain the resource allocation results of the tasks in the initial task queue according to the resource allocation situation.
[0097] Furthermore, according to the resource allocation result, the tasks of the corresponding initial task queue are allocated to the distributed task queue and the undistributed task queue.
[0098] The resources allocated to any task in the distributed task queue all meet the execution requirements of the task. For example, if a task requires 10 CPU resources and the task is allocated 10 CPU resources, the CPU resources obtained by the task meet the task execution requirements and the task is allocated to the distributed task queue.
[0099] The tasks in the undistributed task queue are not allocated resources or the allocated resources do not meet the execution needs of the tasks. For example, if a task requires 10 CPU resources and the task is allocated 5 CPU resources, the CPU resources obtained by the task cannot meet the task execution needs, and the task is allocated to the undistributed task queue.
[0100] See attached Figure 4 , the custom allocation algorithm includes:
[0101] Step S21: For any task, determine the priority of the task in the initial task queue.
[0102] Step S22: Allocate the resources of the network switch to the tasks in the initial task queue according to the priorities of the tasks and the resource requirements of the tasks.
[0103] Step S23: Compare the amount of resources allocated to a task with the amount of resources required by the task to determine whether the resources allocated to the task meet the requirements.
[0104] Step S24: If the amount of resources allocated to a task cannot meet the resource requirements of the task, the resources allocated to the task are updated according to the priority of the task and the resource requirements of the task.
[0105] Step S25: If the amount of resources allocated to a task can satisfy the resource needs of the task, the resources allocated to the task will not be updated.
[0106] In one embodiment, the resource is a CPU resource of a network switch, and the CPU resource is allocated to the tasks in the initial task queue according to a custom allocation algorithm. An example of allocating resources according to a custom allocation algorithm is as follows.
[0107] For example, there are five tasks to be executed in the initial task queue, the demands of the five tasks to be executed for CPU resources are 1, 2, 2, 4 and 14 respectively, and the priorities of the five tasks to be executed are 2, 3.5, 3, 0.5 and 1 respectively.
[0108] The priorities of the above five tasks to be executed are standardized, that is, the smallest priority is set to 1, and the priorities of the remaining tasks to be executed are updated in the same proportion, so the priorities of the five tasks to be executed are updated to 4, 7, 6, 1, and 2 respectively.
[0109] For the priorities of the five tasks to be executed after the update, the sum of the priorities of the five tasks is calculated to be 20. In this embodiment, the priorities and resource allocations are proportionally corresponding, corresponding to the sum of the priorities being 20, the CPU resources of the network switch are equally divided into 20 parts, and the five tasks obtain 4, 7, 6, 1, and 2 parts of the CPU resources respectively.
[0110] The five tasks require 1, 2, 2, 4, and 14 CPU resources respectively. The first task requires 1 CPU resource and is allocated 4 CPU resources, so the first task gets 3 more CPU resources. Similarly, the second task requires 2 CPU resources and is allocated 7 CPU resources, so the second task gets 5 more CPU resources. The third task requires 2 CPU resources and is allocated 6 CPU resources, so the third task gets 4 more CPU resources. Therefore, the first, second, and third tasks get a total of 12 more CPU resources.
[0111] The fourth task requires 4 CPU resources, but is allocated 1 CPU resource. The fourth task lacks 3 CPU resources. The fifth task requires 14 CPU resources, but is allocated 2 CPU resources. The fourth task lacks 12 CPU resources.
[0112] The fourth task lacks 3 CPU resources, and the fifth task lacks 12 CPU resources. The corresponding priority of the fourth task is 1, and the corresponding priority of the fifth task is 2. The 12 extra system CPU resources are distributed in equal proportion to the priorities of the fourth and fifth tasks. When the 12 extra system CPU resources are redistributed, the fourth task is allocated 12x1 / (1+2)=4 CPU resources, and the fifth task is allocated 12x2 / (1+2)=8 CPU resources.
[0113] Before the CPU resources are reallocated, the fourth task lacks 3 CPU resources. 4 CPU resources are allocated to the fourth task again, so the fourth task is allocated 1 more CPU resource.
[0114] Before the CPU resources are reallocated, the fifth task lacks 12 shares of system resources. 8 shares of CPU resources are allocated to the fifth task again, and the fifth task still lacks 4 shares of CPU resources. The 1 share of CPU resources that was allocated to the fourth task is transferred to the fifth task, completing the CPU resource allocation process.
[0115] In one embodiment, after CPU resource allocation, the first task, the second task, the third task and the fourth task all obtain the required system resources. The CPU resources allocated to the fifth task do not meet the needs of task execution, and the required system resources are not fully obtained. The first task, the second task, the third task and the fourth task belong to the distributed task queue, and the fifth task belongs to the undistributed task queue.
[0116] Step S3, adding the newly added tasks to the undistributed task queue, dynamically assigning priorities to the tasks in the undistributed task queue according to preset rules, optimizing the tasks in the undistributed task queue according to priorities, and obtaining an optimized task queue.
[0117] Among them, for the tasks in the undistributed task queue, the priority of the task in the undistributed task queue is determined according to the priority determination rule, and the tasks are reordered in order from high to low priority. The new task queue obtained is the optimized task queue.
[0118] Therefore, the priority of the re-determined task in the undistributed task queue is the priority of the task in the optimized task queue.
[0119] Among them, the newly added tasks are the tasks sent by the client and received by the network switch in real time.
[0120] In one embodiment, since the tasks in the undistributed task queue are not allocated CPU resources that meet their requirements, the tasks cannot be processed by the CPU. As the number of newly added tasks increases, the following problems arise:
[0121] If the priority of a task in the undistributed task queue is relatively low, the task may not obtain the CPU resources it needs and will remain in the undistributed task queue for a long time.
[0122] Therefore, it is necessary to dynamically allocate the priority of the task in the described undistributed task queue so that the task in the described undistributed task queue can obtain the CPU resource it needs in time, and prevent the task in the described undistributed task queue from being delayed for a long time. Therefore, it is necessary to dynamically allocate priority according to preset rules to the task in the described undistributed task queue and the newly added task.
[0123] The dynamically allocating priorities to the tasks in the undistributed task queue according to preset rules is specifically:
[0124] The priority of the task is updated according to the amount of resources consumed to execute a task, the amount of resources still lacking after the task is allocated resources, and the queuing time T of the task in the undistributed task queue.
[0125] In one embodiment, the preset rule is: dynamically update the priority of the corresponding task in the undistributed task queue according to the amount of resources A consumed to execute a task, the amount of resources B still lacking after the corresponding task is allocated resources, and the queuing time T of the corresponding task in the undistributed task queue. For details, refer to the following formula (1) and formula (2).
[0126] (1);
[0127] in, It is the priority obtained by the i-th task in the undistributed task queue after dynamic allocation with the queuing time T.
[0128] Here, Ai is the amount of resources that the i-th task in the undistributed task queue needs to consume.
[0129] in, It is the total amount of resources consumed by all tasks in the undistributed task queue.
[0130] Wherein, Bi is the amount of resources lacking for the i-th task in the undistributed task queue.
[0131] in, The amount of resources that are lacking for all tasks in the undistributed task queue.
[0132] in, It means that the less the amount of resources lacked by the i-th task in the undistributed task queue, the higher its corresponding priority;
[0133] Among them, the larger the value of the queuing time T, the larger the value of Mi, and the longer the queuing time of a task, the higher the priority assigned to the task.
[0134] In one embodiment, the undistributed task queue is taken as a whole and participates in resource allocation together with the newly added tasks, and the priority G of the entire queue of the undistributed task queue is calculated accordingly. The priority G of the entire queue satisfies the following formula (2).
[0135] (2);
[0136] Wherein, N represents the total number of tasks in the undistributed task queue.
[0137] Formula (2) shows that as the number of tasks in the undistributed task queue increases, the priority of the overall queue will increase. At the same time, as time goes by, , which in turn causes the priority of the overall queue to gradually increase.
[0138] As the priority of the overall queue increases, and as the priority of the tasks in the undistributed queue increases, the tasks in the undistributed queue are preferentially allocated the system resources they need, to avoid the tasks in the undistributed queue waiting too long and being seriously delayed.
[0139] For example, suppose that at the current moment, there are 3 tasks in the undistributed queue, and the priorities of the 3 tasks are 1, 2 and 3 respectively. According to the above formula (2), the overall queue priority of the undistributed task queue is 6.
[0140] The priorities of the three newly added tasks are 3, 5 and 0.5 respectively. The three newly added tasks are added to the undistributed task queue and resources are allocated uniformly.
[0141] According to the priority 6 of the overall queue of the undistributed task queue and the priorities 3, 5 and 0.5 of the three tasks in the initial task queue, CPU resources are allocated to the tasks according to a custom allocation algorithm.
[0142] The specific process is as follows: After standardizing the priorities of the tasks, they are 12, 6, 10, and 1 respectively, that is, the resources are divided equally into 29 parts.
[0143] Based on the overall queue priority of the undistributed task queue of 6, the undistributed task queue is allocated 12 resources, wherein the three tasks in the undistributed queue are allocated 2, 4 and 6 resources respectively.
[0144] For the three newly added tasks, the priorities of the three tasks are 3, 5 and 0.5 respectively, so the resources allocated to the three newly added tasks are 6, 10 and 1 respectively.
[0145] See attached Figure 5 ,Step S4, execute the tasks in the optimization task queue in order of priority from high to low to obtain the execution results of the tasks.
[0146] Step S5: Perform corresponding operations according to the execution result of the task, including the following steps:
[0147] Step S51: Determine whether the task is completed based on the task execution result.
[0148] Step S52: If the task is completed, the task execution result is sent to the client in response to the task information sent by the client.
[0149] Step S53: If the task execution is interrupted, the interrupted task is placed in the undistributed task queue for the next resource allocation.
[0150] In one embodiment, the network switch executes the tasks in the optimization task queue in sequence according to the resources allocated to the optimization task queue, and the task execution results include task execution completion and task execution interruption.
[0151] If the task execution result is defined as 0, it means that the task execution is interrupted and the corresponding task is not completed. If the task execution result is defined as 1, it means that the task execution is completed.
[0152] The task execution result can be used to determine whether the task has been completed.
[0153] If the task execution result is 0, it indicates that the task execution is interrupted, indicating that the corresponding task request has not yet obtained the required system resources, and then the task is put into the undistributed task queue for the next system resource allocation.
[0154] If the task execution result is 1, indicating that the task execution is completed, the task execution result is sent to the client to complete the response of the network switch to the task sent by the client.
[0155] In this embodiment, a series of encryption methods are used to improve the security of data interaction between the network switch and the client in the application system, and then the system resources of the network switch are dynamically allocated to the authenticated clients to keep the system load balanced and reasonable.
[0156] Afterwards, the corresponding priority is assigned according to the task requests of each client to ensure that the task requests of each client can be processed within a reasonable time, avoiding the security risks caused by the task requests waiting for too long.
[0157] It can not only prevent the risk of information leakage caused by imperfect system encryption measures, but also effectively reduce the risk of system failure caused by unbalanced system load, thereby improving the security of the system.
[0158] The embodiment of the present application provides a network switch security monitoring device based on artificial intelligence, including:
[0159] The initial task queue generation module is used to receive the task information sent by the client, parse any of the received task information to obtain a corresponding parsing result, and generate an initial task queue according to the parsing result;
[0160] A task resource allocation module, used to allocate resources to the tasks in the initial task queue according to a custom allocation algorithm, and after the resources are allocated, obtain the resource allocation results of the tasks in the initial task queue according to the resource allocation situation;
[0161] And, according to the resource allocation result, the tasks of the corresponding initial task queue are allocated to the distributed task queue and the undistributed task queue;
[0162] A dynamic priority allocation module is used to add newly added tasks to the undistributed task queue, dynamically allocate priorities to the tasks in the undistributed task queue according to preset rules, and optimize the tasks in the undistributed task queue according to the priorities to obtain an optimized task queue;
[0163] A task execution module, used to execute the tasks in the optimization task queue in order of priority from high to low, and obtain the execution results of the tasks;
[0164] The task execution result judgment module is used to perform corresponding operations according to the task execution results.
[0165] The artificial intelligence-based network switch security monitoring method can be implemented in the form of software and sold or used as an independent product, and can be stored in a computer-readable storage medium. The technical solution of the present application can essentially be embodied in the form of a software product, or the part that contributes to the prior art or all or part of the technical solution. The computer software product is stored in a storage medium, including several instructions for a network device to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), disk or optical disk and other media that can store program code.
[0166] In the present invention, unless otherwise clearly stipulated and limited, for example, it can be a fixed connection, a detachable connection, or an integrated one; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, it can be the internal connection of two elements or the interaction relationship between two elements. Unless otherwise clearly defined, for ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to the specific circumstances.
[0167] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A network switch security monitoring method based on artificial intelligence, used for a network switch, characterized in that: Includes steps: Receive the task information sent by the client, and parse any of the received task information to obtain the corresponding parsing result, specifically: Receive task information sent by the client; Parsing the received task information to obtain the first encrypted data in the request header of the task information and the encrypted task data; Decrypt the first encrypted data using the RSA private key to obtain an AES key; Decrypting the encrypted task data using the AES key to obtain the decrypted task data, and generating an initial task queue according to the parsing result; Allocating the resources of the network switch to the tasks in the initial task queue according to a custom allocation algorithm, and after the resources are allocated, obtaining the resource allocation results of the tasks in the initial task queue according to the resource allocation situation; The custom allocation algorithm includes: For any task, determine the priority of the task in the initial task queue; Allocate resources to tasks in the initial task queue based on task priority and resource requirements; Compare the amount of resources allocated to a task with the amount of resources required by the task to determine whether the resources allocated to the task meet the requirements; If the amount of resources allocated to a task cannot meet the resource needs of the task, the resources allocated to the task are updated according to the priority of the task and the resource needs of the task; If the amount of resources allocated to a task can satisfy the resource requirements of the task, the resources allocated to the task are not updated; Furthermore, according to the resource allocation result, the tasks of the corresponding initial task queue are allocated to the distributed task queue and the undistributed task queue; the resources allocated to any task in the distributed task queue meet the execution requirements of the task; the tasks in the undistributed task queue are not allocated resources or the allocated resources do not meet the execution requirements of the task; Add the newly added tasks to the undistributed task queue, and dynamically assign priorities to the tasks in the undistributed task queue according to preset rules, specifically: Update the priority of the task according to the amount of resources consumed to execute a task, the amount of resources still lacking after the task is allocated resources, and the queuing time T of the task in the undistributed task queue; Optimizing the tasks in the undistributed task queue according to their priorities to obtain an optimized task queue; The priority of a task to be executed is the ratio of the resources required to be consumed by the task to the total resources required to be consumed by all tasks to be executed. The larger the ratio corresponding to a task, the higher the priority of the task. Among them, the newly added tasks are the tasks sent by the client that are received in real time by the network switch; The tasks in the optimization task queue are executed in order of priority from high to low to obtain the execution results of the tasks; Perform corresponding operations based on the execution results of the task.
2. The network switch security monitoring method based on artificial intelligence according to claim 1, characterized in that: The generating of the initial task queue according to the parsing result includes: The decrypted task data is the task to be executed obtained by parsing; A task queue is formed by all the tasks to be executed obtained by parsing, and the priority of each task to be executed in the task queue is calculated; After determining the priority of each task to be executed, all tasks to be executed are arranged in descending order of priority to form an initial task queue; The parsing result includes the first encrypted data, the encrypted task data and the decrypted task data.
3. The network switch security monitoring method based on artificial intelligence according to claim 1, characterized in that: The method of performing corresponding operations according to the task execution result includes the following steps: Determine whether the task has been completed based on the task execution results; If the task is completed, the task execution result is sent to the client in response to the task information sent by the client; If the execution of a task is interrupted, the interrupted task is put into the undistributed task queue for the next resource allocation.
4. A network switch security monitoring device based on artificial intelligence, characterized in that: include: The initial task queue generation module is used to receive the task information sent by the client, and parse any of the received task information to obtain the corresponding parsing result, specifically: Receive task information sent by the client; Parsing the received task information to obtain the first encrypted data in the request header of the task information and the encrypted task data; Decrypt the first encrypted data using the RSA private key to obtain an AES key; Decrypting the encrypted task data using the AES key to obtain the decrypted task data, and generating an initial task queue according to the parsing result; A task resource allocation module, used to allocate resources to the tasks in the initial task queue according to a custom allocation algorithm, and after the resources are allocated, obtain the resource allocation results of the tasks in the initial task queue according to the resource allocation situation; The custom allocation algorithm includes: For any task, determine the priority of the task in the initial task queue; Allocate resources to tasks in the initial task queue based on task priority and resource requirements; Compare the amount of resources allocated to a task with the amount of resources required by the task to determine whether the resources allocated to the task meet the requirements; If the amount of resources allocated to a task cannot meet the resource needs of the task, the resources allocated to the task are updated according to the priority of the task and the resource needs of the task; If the amount of resources allocated to a task can satisfy the resource requirements of the task, the resources allocated to the task are not updated; Furthermore, according to the resource allocation result, the tasks of the corresponding initial task queue are allocated to the distributed task queue and the undistributed task queue; the resources allocated to any task in the distributed task queue meet the execution requirements of the task; the tasks in the undistributed task queue are not allocated resources or the allocated resources do not meet the execution requirements of the task; The dynamic priority allocation module is used to add newly added tasks to the undistributed task queue and dynamically allocate priorities to the tasks in the undistributed task queue according to preset rules, specifically: Update the priority of the task according to the amount of resources consumed to execute a task, the amount of resources still lacking after the task is allocated resources, and the queuing time T of the task in the undistributed task queue; Optimizing the tasks in the undistributed task queue according to their priorities to obtain an optimized task queue; The priority of a task to be executed is the ratio of the resources required to be consumed by the task to the total resources required to be consumed by all tasks to be executed. The larger the ratio corresponding to a task, the higher the priority of the task; The task execution module is used to execute the tasks in the optimization task queue in order of priority from high to low to obtain the execution results of the tasks; The task execution result judgment module is used to perform corresponding operations according to the task execution results.
5. A storage medium, characterized in that The storage medium stores program instructions, which, when executed, are used to implement the method according to any one of claims 1 to 3.
Citation Information
Patent Citations
Multi-queue multi-priority big data task management system and method for achieving big data task management by utilizing system
CN104657214A
Dynamic thread pool based service processing method and apparatus
CN107341050A