Attacked executable body identification method, output voting device, device and storage medium

By introducing target alternate executors into the output voting device and voting multiple times to identify the attacked isomer executors, the problem that the prior art cannot accurately identify the attacked executors is solved, and the accuracy of subsequent operations and system performance is improved.

CN115314289BActive Publication Date: 2025-05-16BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210943457.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-08
Publication Date
2025-05-16
Estimated Expiration
2042-08-08

AI Technical Summary

Technical Problem

The prior art cannot accurately identify which isomeric executors are attacked or have vulnerabilities, which affects the accuracy of subsequent cleaning, scheduling and request packet issuance.

Method used

By introducing the target backup execution body into the output voting device, multiple online heterogeneous execution bodies are obtained to vote on the execution results of the request message. When more than half of the execution results are consistent, the execution results of the target backup execution body are obtained and the attacked execution body is determined.

Benefits of technology

Effectively identify which of the multiple online isomer execution bodies are attacked, ensure the accuracy of subsequent cleaning, scheduling and request packet issuance, and improve system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115314289B_ABST
    Figure CN115314289B_ABST
Patent Text Reader

Abstract

The present application provides an attacked executor identification method, output voter, device and storage medium. The method includes: obtaining the execution results of multiple online heterogeneous executors on a request message; voting on the execution results of multiple online heterogeneous executors, and when the voting result is that the execution results of more than half of the online heterogeneous executors are the same, obtaining the execution result of the target standby executor on the request message; performing a secondary vote on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors to determine the identification results of multiple online heterogeneous executors. This method can effectively identify which of the multiple online heterogeneous executors are attacked through the configured target standby executor, thereby ensuring the accuracy of subsequent cleaning, scheduling and request message delivery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method for identifying an attacked executable body, an output voter, a device and a storage medium. Background Art

[0002] With the rapid development of information technology, network security has attracted more and more attention. In response to the endless security issues in the cyberspace environment, a mimicry defense mechanism with dynamic heterogeneous redundancy as the core idea has been proposed in recent years. Mimicry defense changes the staticity and determinism of the target system through dynamics and randomness. Through heterogeneous redundant multi-mode adjudication design, it can identify and shield unknown attacks and unknown threats, thereby enhancing the security of cyberspace.

[0003] The mimicry defense mechanism is composed of multiple mimicry components, including heterogeneous executors, input distributors, output voters, feedback controllers, etc. The input distributor is responsible for copying and distributing the request messages sent by the client to multiple heterogeneous executors, the output voter is responsible for comparing and judging the response information received from each heterogeneous executor, and the feedback controller is responsible for scheduling and cleaning heterogeneous executors.

[0004] However, the existing technology cannot know which specific executable bodies are attacked or have vulnerabilities, which may affect the accuracy of subsequent cleaning, scheduling and request message sending. Summary of the invention

[0005] The purpose of the embodiments of the present application is to provide a method for identifying attacked executable bodies, an output voter, a device and a storage medium, so as to effectively determine which online heterogeneous executable bodies are attacked and ensure the accuracy of subsequent cleaning, scheduling and request message sending.

[0006] The present invention is achieved in that:

[0007] In a first aspect, an embodiment of the present application provides an attacked executor identification method, which is applied to an output voter, including: obtaining execution results of multiple online heterogeneous executors on a request message; voting on the execution results of the multiple online heterogeneous executors, and when the voting result is that the execution results of more than half of the online heterogeneous executors are the same, obtaining the execution result of the target standby executor on the request message; performing a secondary vote on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors to determine the identification results of the multiple online heterogeneous executors; wherein, when the execution result of the target standby executor is consistent with the execution results of more than half of the online heterogeneous executors, it indicates that the remaining online heterogeneous executors among the multiple online heterogeneous executors are under attack; when the execution result of the target standby executor is inconsistent with the execution results of more than half of the online heterogeneous executors, it indicates that more than half of the online heterogeneous executors are under attack.

[0008] In the embodiment of the present application, when the output voter determines that the execution results of more than half of the online heterogeneous executors are the same, it will obtain the execution result of the target standby executor on the request message, and then perform a secondary vote on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors. When the results are consistent, it is determined that the remaining online heterogeneous executors in the online heterogeneous executors are attacked, and when the results are inconsistent, it is determined that more than half of the online heterogeneous executors are attacked. It can be seen that this method can effectively identify which of the multiple online heterogeneous executors are attacked through the configured target standby executor, thereby ensuring the accuracy of subsequent cleaning, scheduling and request message delivery.

[0009] In combination with the technical solution provided in the first aspect above, in some possible implementations, before obtaining the execution result of the target standby executor, the method also includes: determining the target standby executor from M standby executors based on a heterogeneity maximization algorithm; wherein the target standby executor is the standby executor with the greatest heterogeneity with more than half of the online heterogeneous executors; and M is a positive integer.

[0010] It should be noted that the greater the difference between heterogeneous executors, the less likely it is that the same attack will cause two heterogeneous executors to fail at the same time. Therefore, in the embodiment of the present application, the target backup executor is the backup executor with the greatest heterogeneity between it and more than half of the online heterogeneous executors among the M backup executors, so that it can be effectively determined whether more than half of the online heterogeneous executors are under attack.

[0011] In combination with the technical solution provided in the first aspect above, in some possible implementation methods, before obtaining the execution result of the target backup executor, the method also includes: based on a weight priority algorithm, determining the target backup executor from M backup executors; wherein, the target backup executor is the backup executor with the largest weight value among the M backup executors, and the weight values ​​of the M backup executors represent the safety factors of the M backup executors; and M is a positive integer.

[0012] In the embodiment of the present application, the respective weight values ​​are determined in advance based on the safety factor of each backup executor. The higher the safety factor of the backup executor, the larger the weight value. Therefore, in the embodiment of the present application, by selecting the backup executor with the largest weight value among the M backup executors as the target backup executor, the credibility and accuracy of the secondary voting can be improved.

[0013] In combination with the technical solution provided in the first aspect above, in some possible implementations, the method further includes: voting on the execution results of the multiple online heterogeneous executors, and simultaneously receiving the execution results of the M standby executors on the request message.

[0014] In an embodiment of the present application, after receiving the execution results of multiple online heterogeneous executors for the request message, the output voter can directly vote on the execution results of multiple online heterogeneous executors without waiting until the execution results of M standby executors are received. In this way, efficiency can be improved, system time can be shortened, and system performance can be improved.

[0015] In combination with the technical solution provided in the first aspect above, in some possible implementations, when the voting result is that the execution results of the multiple online heterogeneous executors are the same, or the execution results of less than half of the online heterogeneous executors are the same, the method also includes: triggering the standby executors among the M standby executors that have not received the request message to stop executing and processing the request message.

[0016] In an embodiment of the present application, when the voting result is that the execution results of multiple online heterogeneous executors are the same, or the execution results of less than half of the online heterogeneous executors are the same, there is no need to determine which online heterogeneous executors are attacked. Therefore, the standby executors that have not received the request message among the M standby executors are triggered to stop executing and processing the request message, thereby reducing unnecessary processing processes and improving system performance.

[0017] In combination with the technical solution provided in the first aspect above, in some possible implementations, after determining the identification results of the multiple online heterogeneous executors, the method also includes: sending a control instruction to a feedback controller so that the feedback controller cleans the attacked online heterogeneous executors based on the control instruction.

[0018] In the embodiment of the present application, since it has been effectively identified which of the multiple online heterogeneous executors are attacked, in the subsequent cleaning process, only the attacked online heterogeneous executors can be cleaned, without cleaning all online heterogeneous executors. That is, this method can selectively and accurately determine the objects that need to be cleaned, and trigger the feedback controller to perform cleaning, which can shorten the cleaning time and improve system performance.

[0019] In combination with the technical solution provided in the first aspect above, in some possible implementations, when the identification result of the multiple online heterogeneous executors is that the remaining online heterogeneous executors are attacked, it indicates that no majority consistent mimicry escape event has occurred, and the method further includes: continuing to send the request message; when the identification result of the multiple online heterogeneous executors is that more than half of the online heterogeneous executors are attacked, it indicates that a majority consistent mimicry escape event has occurred, and the method further includes: terminating the sending of the request message.

[0020] In the embodiment of the present application, when the identification result of multiple online heterogeneous executors is that more than half of the online heterogeneous executors are attacked, indicating that a majority consistent mimicry escape event has occurred, the sending of the request message will be terminated. It can be seen that through this method, the ability to identify mimicry escape events can be improved, and a more accurate theoretical guarantee can be provided for whether the request message is sent.

[0021] In a second aspect, an embodiment of the present application provides an output voter, comprising: an acquisition module, used to obtain execution results of multiple online heterogeneous executors on a request message; a voting module, used to vote on the execution results of the multiple online heterogeneous executors, and when the voting result is that the execution results of more than half of the online heterogeneous executors are the same, obtain the execution result of the target standby executor on the request message; an identification module, used to perform a secondary vote on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors to determine the identification results of the multiple online heterogeneous executors; wherein, when the execution result of the target standby executor is consistent with the execution results of more than half of the online heterogeneous executors, it indicates that the remaining online heterogeneous executors among the multiple online heterogeneous executors are under attack; when the execution result of the target standby executor is inconsistent with the execution results of more than half of the online heterogeneous executors, it indicates that more than half of the online heterogeneous executors are under attack.

[0022] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a processor and a memory, wherein the processor and the memory are connected; the memory is used to store programs; the processor is used to call the programs stored in the memory to execute the method provided in the above-mentioned first aspect embodiment and / or in combination with some possible implementation methods of the above-mentioned first aspect embodiment.

[0023] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, executes a method provided in the embodiment of the first aspect above and / or in combination with some possible implementations of the embodiment of the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0025] Figure 1 A module block diagram of a mimicry defense architecture provided in an embodiment of the present application.

[0026] Figure 2 A flowchart of the steps of the first method for identifying an attacked executable body provided in an embodiment of the present application.

[0027] Figure 3 A flowchart of the steps of a second method for identifying an attacked executable body provided in an embodiment of the present application.

[0028] Figure 4 A flowchart of the steps of a third method for identifying an attacked executable body provided in an embodiment of the present application.

[0029] Figure 5 A module block diagram of an output voter provided in an embodiment of the present application. DETAILED DESCRIPTION

[0030] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0031] At present, the mimicry defense mechanism is composed of multiple mimicry components, including heterogeneous executors, input distributors, output voters, feedback controllers, etc., among which the input distributor is responsible for copying and distributing the request message sent by the client to multiple heterogeneous executors, the output voter is responsible for comparing and judging the response information received from each heterogeneous executor, and the feedback controller is responsible for scheduling and cleaning the heterogeneous executors. However, the prior art cannot know which specific executors are attacked or have vulnerabilities, so it may affect the accuracy of subsequent cleaning, scheduling and request message issuance. For example, under a specific ruling mode (such as majority unanimous ruling), when most heterogeneous executors are attacked by the same type or have the same type of vulnerabilities, there is a possibility of mimicry escape events, that is, in the majority unanimous ruling, the output voter will determine that most heterogeneous executors are normal, which will lead to mimicry escape events. For another example, at present, since it is impossible to know which specific executors are attacked or have vulnerabilities, all heterogeneous executors can only be cleaned and scheduled during subsequent cleaning and scheduling.

[0032] In view of the above problems, the inventors of the present application have proposed the following embodiments to solve the above problems after long-term research.

[0033] See also Figure 1 , Figure 1 The module block diagram of the mimic defense architecture provided in the embodiment of the present application specifically includes an input distributor, multiple online heterogeneous executors, a backup executor, an output voter, and a feedback controller.

[0034] Among them, the input distributor is connected to multiple online heterogeneous executors and a standby executor respectively, multiple online heterogeneous executors and the standby executor are all connected to the output voter, and the feedback controller is connected to the output voter, multiple online heterogeneous executors and the standby executor respectively.

[0035] It should be noted that the main improvement of the above-mentioned mimic defense architecture is the addition of a backup executor. Among them, the backup executor is also a heterogeneous executor. The number of backup executors can be one or more, which is not limited in this application. Correspondingly, the number of multiple online heterogeneous executors can also be set according to actual conditions, such as 3, 5, 10, etc., which is not limited in this application.

[0036] The above-mentioned input distributor, multiple online heterogeneous executors, standby executors, output voter and feedback controller can be implemented by software, hardware, or a combination of software and hardware, and this application does not limit them. Since the above-mentioned input distributor, multiple online heterogeneous executors, output voter and feedback controller are well known in the art, they are not described in detail here.

[0037] It should be noted that the above-mentioned mimic defense architecture can be configured in an electronic device, which may be, but not limited to, an industrial gateway, a router, a web server, a firewall, etc. Structurally, the electronic device may include a processor and a memory.

[0038] The processor and the memory are directly or indirectly electrically connected to realize data transmission or interaction. For example, these elements can be electrically connected to each other through one or more communication buses or signal lines. The processor can be used to execute the attacked executable body identification method provided in the embodiment of the present application.

[0039] The processor may be an integrated circuit chip with signal processing capability. The processor may also be a general-purpose processor, for example, a central processing unit (CPU), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a discrete gate or transistor logic device, or a discrete hardware component, which may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. In addition, the general-purpose processor may be a microprocessor or any conventional processor, etc.

[0040] The memory may be, but is not limited to, a random access memory (RAM), a read only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), and an electric erasable programmable read-only memory (EEPROM). The memory is used to store a program, and the processor executes the program after receiving an execution instruction.

[0041] See also Figure 2 , Figure 2 A flowchart of the steps of the method for identifying an attacked executable body provided in an embodiment of the present application, the method is applied to Figure 1 It should be noted that the method for identifying the attacked executable body provided in the embodiment of the present application is not based on Figure 2 The order shown below is limited, and the method includes: step S101-step S103.

[0042] Step S101: Obtain the execution results of multiple online heterogeneous execution bodies on the request message.

[0043] Among them, multiple online heterogeneous executors are heterogeneous executors configured in the mimic defense architecture for providing services online. Assume that the number of online heterogeneous executors is N+1. N is a positive integer greater than or equal to 2. When the input distributor receives the request message, it copies the request message N times for distribution, that is, a total of N+1 request messages are included, and each request message is distributed to an online heterogeneous executor. Each online heterogeneous executor executes a response based on the request message to obtain an execution result. Then, the output voter obtains the execution results of all online heterogeneous executors.

[0044] Step S102: voting on the execution results of multiple online heterogeneous executors. When the voting result shows that the execution results of more than half of the online heterogeneous executors are the same, obtaining the execution result of the target standby executor on the request message.

[0045] It should be noted that the same execution results of more than half of the online heterogeneous executors indicate a majority consensus. In this case, in order to identify whether the majority of online heterogeneous executors or the remaining minority of online heterogeneous executors are under attack, a target standby executor is introduced in the embodiment of the present application for identification.

[0046] The target backup executor mentioned above may be a predetermined heterogeneous executor with a higher safety factor.

[0047] When there is a target standby executor, after receiving the request message, the input distributor will copy the request message N+1 times for distribution, that is, a total of N+2 request messages are included. The request message is distributed to N+1 online heterogeneous executors and the target standby executor, and the output voter obtains the execution result of the target standby executor while obtaining the execution result of the request message by multiple online heterogeneous executors. Of course, it is also possible that the output voter determines that the voting result is the same as the execution result of more than half of the online heterogeneous executors, and then obtains the execution result of the request message by the target standby executor. In addition, it is also possible that the output voter obtains the execution result of the request message by the target standby executor during the process of voting on the execution results of multiple online heterogeneous executors. This application is not limited to this.

[0048] Step S103: performing a secondary vote on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors to determine the identification results of the multiple online heterogeneous executors.

[0049] When the execution result of the target standby executor is consistent with the execution result of more than half of the online heterogeneous executors, it indicates that the remaining online heterogeneous executors among the multiple online heterogeneous executors are under attack; when the execution result of the target standby executor is inconsistent with the execution result of more than half of the online heterogeneous executors, it indicates that more than half of the online heterogeneous executors are under attack.

[0050] That is, by introducing the execution results of the target standby executor to verify the execution results of more than half of the online heterogeneous executors, it is determined whether the majority of online heterogeneous executors are attacked or the remaining minority of online heterogeneous executors are attacked. It can be seen that this method can effectively identify which of the multiple online heterogeneous executors are attacked through the configured target standby executor.

[0051] After determining the identification results of the multiple online heterogeneous executors, the output voter can record the attacked online heterogeneous executors and send control instructions to the feedback controller, so that the feedback controller cleans the attacked online heterogeneous executors based on the control instructions.

[0052] It should be noted that, since it has been effectively identified which of the multiple online heterogeneous executors are attacked, in the subsequent cleaning process, only the attacked online heterogeneous executors can be cleaned, without cleaning all online heterogeneous executors. That is, this method can selectively and accurately determine the objects that need to be cleaned, and trigger the feedback controller to perform cleaning, which can shorten the cleaning time and improve system performance.

[0053] In addition, since it has been effectively identified which of the multiple online heterogeneous executors are under attack, in the scheduling process of subsequent executors, only the attacked online heterogeneous executors can be scheduled and replaced, and this application does not limit this.

[0054] It can be seen that through the above method, it is possible to effectively identify which of the multiple online heterogeneous executors are attacked based on the configured target standby executors, thereby ensuring the accuracy of subsequent cleaning and scheduling.

[0055] In another case, when the voting result is that the execution results of all online heterogeneous executors are the same, it is determined that all online heterogeneous executors are not attacked. When the voting result is that the execution results of less than half of the online heterogeneous executors are the same, it is not necessary to identify which online heterogeneous executor is attacked, but to record that all online heterogeneous executors are attacked, and then clean all online heterogeneous executors.

[0056] In one embodiment, M standby executable bodies may be preconfigured, and then the target standby executable body may be determined from the M standby executable bodies, where M is a positive integer.

[0057] As an optional determination method, the determination process may specifically include: determining a target standby executor from the M standby executors based on a heterogeneity maximization algorithm.

[0058] The target standby executor is the standby executor with the greatest heterogeneity with more than half of the online heterogeneous executors. That is, the heterogeneity maximization algorithm is used to determine the standby executor with the greatest heterogeneity with more than half of the online heterogeneous executors from the M standby executors.

[0059] It should be noted that the greater the difference between heterogeneous executors, the less likely it is that the same attack will cause two heterogeneous executors to fail at the same time. Therefore, in the embodiment of the present application, the target backup executor is the backup executor with the greatest heterogeneity between it and more than half of the online heterogeneous executors among the M backup executors, so that it can be effectively determined whether more than half of the online heterogeneous executors are under attack.

[0060] As another optional determination method, the determination process may specifically include: determining a target standby executable body from the M standby executable bodies based on a weight priority algorithm.

[0061] The target backup executor is the backup executor with the largest weight value among the M backup executors, and the weight values ​​of the M backup executors represent the safety factors of the M backup executors. That is, the weight priority algorithm is used to determine the backup executor with the largest weight value from the M backup executors.

[0062] It can be seen that in the embodiment of the present application, the respective weight values ​​are determined in advance based on the safety factor of each backup executor. The higher the safety factor of the backup executor, the larger the weight value. Therefore, in the embodiment of the present application, by selecting the backup executor with the largest weight value among the M backup executors as the target backup executor, the credibility and accuracy of the secondary voting can be improved.

[0063] The safety factor of the standby executor can be determined by its historical usage information. For example, if it has been attacked once during use, its safety factor will be reduced once. Specifically, the number of attacks on each online heterogeneous executor can be determined by the attacked executor identification method provided in the embodiment of the present application, and then the safety factor can be determined based on the number of attacks. Subsequently, the online heterogeneous executor with a high safety factor can be determined as a standby executor. It can be seen that the embodiment of the present application can also improve the theoretical basis for the weight priority algorithm and improve the accuracy of the algorithm.

[0064] When M standby executors are pre-configured, since the output voter also needs to receive the execution results of the standby executors, in order to improve efficiency, shorten system time consumption, and improve system performance, step S102 may specifically include: voting on the execution results of multiple online heterogeneous executors, and receiving the execution results of the M standby executors on the request message at the same time.

[0065] Specifically, by adding a timer, while N+1 online service-providing executors are voting, the execution results of the request messages from the M standby executors can continue to be received, without waiting for the execution results of the request messages from the M standby executors before voting.

[0066] In addition, when the voting result is that the execution results of multiple online heterogeneous executors are the same, or the execution results of less than half of the online heterogeneous executors are the same, the method also includes: triggering the standby executors among the M standby executors that have not received the request message to stop executing and processing the request message.

[0067] It should be noted that when the voting result is that the execution results of multiple online heterogeneous executors are the same, or the execution results of less than half of the online heterogeneous executors are the same, there is no need to determine which online heterogeneous executors are attacked. Therefore, the standby executors that have not received the request message among the M standby executors are triggered to stop executing and processing the request message, thereby reducing unnecessary processing processes and improving system performance.

[0068] Optionally, the attacked executable body identification method provided in the embodiment of the present application can also be used to identify the mimicry escape event. Specifically, when the identification result of multiple online heterogeneous executable bodies is that the remaining online heterogeneous executable bodies are attacked, it indicates that the majority consistent mimicry escape event has not occurred. At this time, the method also includes: continuing to send the request message.

[0069] When the identification result of the multiple online heterogeneous executors is that more than half of the online heterogeneous executors are attacked, indicating that a majority consistent mimicry escape event has occurred, the method further includes: terminating the sending of the request message.

[0070] It can be seen that this method can improve the ability to identify mimic escape events and provide a more accurate theoretical guarantee for whether the request message is sent.

[0071] The above-mentioned embodiment is described below with reference to specific examples.

[0072] See also Figure 3 , the identification process of the attacked executor is explained with the number of online heterogeneous executors being 3 and the number of standby executors being 2.

[0073] The input distributor sends the request message to three online heterogeneous executors and two standby executors respectively. When the three online heterogeneous executors complete the response execution, the output voter performs the first vote on the execution results of the three online heterogeneous executors. If the voting result is that the execution results of the three online heterogeneous executors are consistent, the vote is passed. If the voting result is that the execution results of the three online heterogeneous executors are different, the vote is not passed, and all online heterogeneous executors are recorded to be attacked, and the three online heterogeneous executors need to be cleaned. If the voting result is that the execution results of two online heterogeneous executors are the same, for example, the execution results of online heterogeneous executors A and online heterogeneous executors B are the same, and the execution results of online heterogeneous executors C are different from the execution results of online heterogeneous executors A and online heterogeneous executors B. Then the executor that is attacked may be online heterogeneous executors A and online heterogeneous executors B, or online heterogeneous executors C. At this time, the target standby executor is determined by the heterogeneity maximization algorithm or the weight priority algorithm, and a secondary vote is performed based on the execution results of the target standby executor and the execution results of the online heterogeneous executor A and the online heterogeneous executor B. If the vote is passed, it indicates that the online heterogeneous executor C is under attack. If the vote is not passed, it indicates that the online heterogeneous executor A and the online heterogeneous executor B are under attack. After the secondary vote, the request is terminated and no request message is sent. The output voter records the attacked online heterogeneous executor and informs the feedback controller of the attacked online heterogeneous executor so that it can take the attacked online heterogeneous executor offline for cleaning.

[0074] See also Figure 4 , the identification process of majority consistent mimicry escape events is explained with 3 online heterogeneous executors and 2 standby executors.

[0075] The input distributor sends the request message to three online heterogeneous executors and two standby executors respectively. When the three online heterogeneous executors complete the response execution, the output voter votes on the execution results of the three online heterogeneous executors. If the voting result is that the execution results of the three online heterogeneous executors are consistent, the vote is passed. If the voting result is that the execution results of the three online heterogeneous executors are different, the vote fails, and all online heterogeneous executors are recorded as being attacked, and the three online heterogeneous executors need to be cleaned. Notify the feedback controller. If the voting result is that the execution results of two online heterogeneous executors are the same, for example, the execution results of online heterogeneous executors A and online heterogeneous executors B are the same, and the execution results of online heterogeneous executors C are different from the execution results of online heterogeneous executors A and online heterogeneous executors B. Then the executor that is attacked may be online heterogeneous executors A and online heterogeneous executors B, or online heterogeneous executors C. At this time, the target backup executor is determined by the heterogeneity maximization algorithm or the weight priority algorithm, and a secondary vote is performed based on the execution results of the target backup executor and the execution results of the online heterogeneous executor A and the online heterogeneous executor B. If the vote is passed, it indicates that the online heterogeneous executor C is attacked, indicating that the majority consistent mimicry escape event has not occurred, and the request message will continue to be sent. If the vote is not passed, it indicates that the online heterogeneous executor A and the online heterogeneous executor B are attacked, indicating that the majority consistent mimicry escape event has occurred, and the sending of the request message is terminated at this time. The output voter records the attacked online heterogeneous executor and informs the feedback controller of the attacked online heterogeneous executor so that it can take the attacked online heterogeneous executor offline for cleaning.

[0076] See also Figure 5 Based on the same inventive concept, the embodiment of the present application further provides an output voter 100, the output voter 100 comprising:

[0077] The acquisition module 110 is used to obtain the execution results of multiple online heterogeneous execution bodies on the request message.

[0078] The voting module 120 is used to vote on the execution results of the multiple online heterogeneous executors, and when the voting result is that the execution results of more than half of the online heterogeneous executors are the same, obtain the execution result of the target standby executor on the request message.

[0079] The identification module 130 is used to perform a secondary vote on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors to determine the identification results of the multiple online heterogeneous executors; wherein, when the execution result of the target standby executor is consistent with the execution results of more than half of the online heterogeneous executors, it indicates that the remaining online heterogeneous executors among the multiple online heterogeneous executors are under attack; when the execution result of the target standby executor is inconsistent with the execution results of more than half of the online heterogeneous executors, it indicates that more than half of the online heterogeneous executors are under attack.

[0080] Optionally, the output voter 100 further includes: a determination module. The determination module is used to determine the target standby executor from the M standby executors based on a heterogeneity maximization algorithm before obtaining the execution result of the target standby executor; wherein the target standby executor is the standby executor with the greatest heterogeneity with more than half of the online heterogeneous executors; and M is a positive integer.

[0081] Optionally, the output voter 100 further includes: a determination module. The determination module is used to determine the target backup executor from the M backup executors based on a weight priority algorithm before obtaining the execution result of the target backup executor; wherein the target backup executor is the backup executor with the largest weight value among the M backup executors, and the weight values ​​of the M backup executors represent the safety factors of the M backup executors; and M is a positive integer.

[0082] Optionally, the voting module 120 is further configured to vote on the execution results of the multiple online heterogeneous executors, and simultaneously receive the execution results of the M standby executors on the request message.

[0083] Optionally, the voting module 120 is also used to trigger the M standby executors that have not received the request message to stop executing the request message when the voting result is that the execution results of the multiple online heterogeneous executors are the same, or the execution results of less than half of the online heterogeneous executors are the same.

[0084] Optionally, the output voter 100 further includes: a control module. The control module is used to send a control instruction to the feedback controller after determining the identification results of the plurality of online heterogeneous executors, so that the feedback controller cleans the attacked online heterogeneous executors based on the control instruction.

[0085] Optionally, the identification module 130 is also used to, when the identification result of the multiple online heterogeneous executors is that the remaining online heterogeneous executors are attacked, indicate that no majority consistent mimicry escape event has occurred, and continue to send the request message; or, when the identification result of the multiple online heterogeneous executors is that more than half of the online heterogeneous executors are attacked, indicate that a majority consistent mimicry escape event has occurred, and terminate the sending of the request message.

[0086] It should be noted that, since technicians in the relevant field can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0087] Based on the same inventive concept, an embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed, the method provided in the above embodiment is executed.

[0088] The storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more available media. The available medium may be a magnetic medium (such as a floppy disk, a hard disk, a tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).

[0089] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0090] In addition, the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0091] Furthermore, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist independently, or two or more modules may be integrated to form an independent part.

[0092] In this document, relational terms such as first and second, etc. are used merely to distinguish one entity or operation from another entity or operation, but do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0093] The above description is only an embodiment of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for identifying an attacked executable body, characterized in that: Applicable to output voting devices, including: Obtain the execution results of multiple online heterogeneous execution bodies on the request message; Voting on the execution results of the multiple online heterogeneous executors, and when the voting result shows that the execution results of more than half of the online heterogeneous executors are the same, obtaining the execution result of the target standby executor on the request message; A secondary vote is performed on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors to determine the identification results of the multiple online heterogeneous executors; wherein, when the execution result of the target standby executor is consistent with the execution results of more than half of the online heterogeneous executors, it indicates that the remaining online heterogeneous executors among the multiple online heterogeneous executors are under attack; when the execution result of the target standby executor is inconsistent with the execution results of more than half of the online heterogeneous executors, it indicates that more than half of the online heterogeneous executors are under attack; Before obtaining the execution result of the target standby executable body, the method further includes: Based on the heterogeneity maximization algorithm, the target standby executor is determined from the M standby executors; wherein the target standby executor is the standby executor with the greatest heterogeneity with more than half of the online heterogeneous executors; M is a positive integer; Or, based on a weight priority algorithm, the target backup executor is determined from M backup executors; wherein the target backup executor is the backup executor with the largest weight value among the M backup executors, and the weight values ​​of the M backup executors represent the safety factors of the M backup executors; and M is a positive integer.

2. The method according to claim 1, characterized in that The method further comprises: Voting is performed on the execution results of the multiple online heterogeneous executors, and at the same time, the execution results of the M standby executors on the request message are received.

3. The method according to claim 2, characterized in that When the voting result is that the execution results of the plurality of online heterogeneous executors are all the same, or the execution results of less than half of the online heterogeneous executors are the same, the method further includes: The standby execution body that has not received the request message among the M standby execution bodies is triggered to stop executing and processing the request message.

4. The method according to claim 1, characterized in that: After determining the identification results of the multiple online heterogeneous executables, the method further includes: A control instruction is sent to the feedback controller, so that the feedback controller cleans the attacked online heterogeneous execution body based on the control instruction.

5. The method according to claim 1, characterized in that When the identification result of the plurality of online heterogeneous executors is that the remaining online heterogeneous executors are attacked, it indicates that no majority consistent mimicry escape event occurs, and the method further includes: Continue to send the request message; When the identification result of the multiple online heterogeneous executors is that more than half of the online heterogeneous executors are attacked, indicating that a majority of consistent mimicry escape events have occurred, the method further includes: Terminate sending of the request message.

6. An output voting device, characterized in that: include: An acquisition module is used to obtain the execution results of multiple online heterogeneous execution bodies on the request message; A voting module, configured to vote on the execution results of the plurality of online heterogeneous executors, and when the voting result shows that the execution results of more than half of the online heterogeneous executors are the same, obtain the execution result of the target standby executor on the request message; an identification module, configured to perform a secondary vote on the execution result of the target standby executor and the execution results of more than half of the online heterogeneous executors to determine the identification results of the multiple online heterogeneous executors; wherein, when the execution result of the target standby executor is consistent with the execution results of more than half of the online heterogeneous executors, it indicates that the remaining online heterogeneous executors among the multiple online heterogeneous executors are under attack; and when the execution result of the target standby executor is inconsistent with the execution results of more than half of the online heterogeneous executors, it indicates that more than half of the online heterogeneous executors are under attack; A determination module is used to determine the target backup executor from M backup executors based on a heterogeneity maximization algorithm before obtaining the execution result of the target backup executor; wherein the target backup executor is the backup executor with the greatest heterogeneity with more than half of the online heterogeneous executors; M is a positive integer; or, the determination module determines the target backup executor from M backup executors based on a weight priority algorithm before obtaining the execution result of the target backup executor; wherein the target backup executor is the backup executor with the largest weight value among the M backup executors, and the weight values ​​of the M backup executors represent the safety factors of the M backup executors; M is a positive integer.

7. An electronic device, characterized in that: include: A processor and a memory, the processor and the memory being connected; The memory is used to store programs; The processor is used to run the program stored in the memory to execute the method according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a computer, the method according to any one of claims 1 to 5 is executed.

Citation Information

Patent Citations

  • Voting method, device and system for eliminating common-mode error of multi-heterogeneous executor

    CN110188317A

  • Mimicry defense judgment method and system based on partial homomorphic encryption algorithm

    CN110995409A