A Cloud Security Monitoring Task Information Interaction Method and System
Through the cloud security monitoring task information interaction method, lightweight publish/subscribe message transmission and data encryption technology are adopted, the management problems of monitoring equipment in low bandwidth and unstable network environments are solved, remote real-time management and efficient data transmission are realized, and the reliability and response speed of the system are improved.
Patent Information
- Application Number
- CN202211400767.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-09
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2042-11-09
AI Technical Summary
The existing monitoring equipment management system is difficult to achieve real-time management in low bandwidth and unstable network environments, resulting in interruption of monitoring data reporting and inability to detect and recover in time, and operation and maintenance management is difficult.
Through the cloud security monitoring task information interaction method, lightweight publish/subscribe message transmission is adopted to realize remote real-time management of monitoring devices, support data encryption and high-security data transmission channels, provide massive connections, high concurrency, and low latency monitoring device access services, and improve system response speed through asynchronous execution.
Remote real-time management of monitoring equipment is realized, the system's reliability and response speed in low bandwidth and unstable network environments are improved, and the security and stability of data transmission are ensured.
Smart Images

Figure CN115766828B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of instant messaging, and particularly relates to a method and system for cloud security monitoring task information interaction. Background Art
[0002] With the rapid development of information network technology, cloud-based wireless networks have also spread to various domestic households and public places. People have begun to enjoy the convenience brought by wireless networks to work and life. However, this convenience has also provided opportunities for lawbreakers, and more and more network illegal activities have started to be carried out through the wireless networks in public places.
[0003] Monitoring devices are responsible for the monitoring and analysis of network traffic data and play an important role in network behavior management. However, due to reasons such as the multiple application scenarios of monitoring devices and the complex network environment of the installation sites, the status of the connected monitoring devices is not stable. The traditional monitoring device management system only receives the reporting of monitoring data. The interruption of monitoring data reporting in many places cannot be detected in time, and after the operation and maintenance personnel discover the interruption of monitoring data reporting, they cannot locate the cause of the interruption to recover it in time, making the operation and maintenance management of monitoring devices very difficult. Summary of the Invention
[0004] Based on the above problems, the present invention proposes a method and system for cloud security monitoring task information interaction, which realizes remote real-time management of monitoring devices through an interaction form, facilitating users and operation and maintenance personnel to manage monitoring devices.
[0005] In view of this, the first aspect of the present invention proposes a method for cloud security monitoring task information interaction, including:
[0006] Receiving a monitoring interaction request message sent by a cloud security monitoring device, where the interaction request message includes the identity identification information of the pre-configured monitoring device, the address information of the message service module, the subscription topic information, and the monitoring interaction information;
[0007] Establishing a communication connection between the monitoring device and the message service module according to the address information;
[0008] Inputting the monitoring interaction information into the monitoring device associated with the subscription topic information;
[0009] The monitoring device verifies the monitoring interaction information to determine whether it is necessary to change the task publishing information associated with the subscription topic information;
[0010] If it is determined to be yes, writing the monitoring interaction information into a memory queue and waiting for the asynchronous thread pool module to perform a persistence operation on it;
[0011] Determine whether there is task information in the memory queue that needs to be sent to the monitoring device according to the identity identification information of the monitoring device;
[0012] If it is determined to be yes, encapsulate and encrypt the task information and send it to the monitoring device through the message service module.
[0013] Optionally, it further includes:
[0014] Receive the registration request of the monitoring device;
[0015] Receive the heartbeat message periodically sent by the monitoring device in the on state, where the heartbeat message includes the physical address information, monitoring on state information, and / or authentication on state information of the monitoring device.
[0016] Optionally, it further includes:
[0017] Receive the heartbeat information sent by the monitoring device after it is powered on or after performing any task, where the heartbeat information includes the physical address information of the monitoring device and the International Mobile Equipment Identity (IMEI) information;
[0018] Query the IMEI of the monitoring device in the database according to the physical address information of the monitoring device;
[0019] When the IMEI of the monitoring device queried from the database is the same as the IMEI carried in the heartbeat information, return the information that there is no monitoring task currently to the monitoring device;
[0020] Otherwise, send the monitoring task corresponding to the IMEI queried from the database to the monitoring device;
[0021] Configure the IMEI update information or IMEI rollback information for the monitoring device;
[0022] Write the IMEI corresponding to the IMEI update information or IMEI rollback information into the database;
[0023] Push the IMEI corresponding to the IMEI update information or IMEI rollback information to the monitoring device so that the monitoring device updates the IMEI, and increment the updated or rolled-back parameter by 1 in the status bar of the monitoring device.
[0024] Optionally, it further includes:
[0025] Receive the monitoring on state information and / or authentication on state information for the monitoring device configured by the user in the background, where the monitoring on state information configures the monitoring state of the monitoring device to the on state or off state, and the authentication on state information configures the authentication state of the monitoring device to the on state or off state;
[0026] Write the monitoring activation status information and / or authentication activation status information into the database;
[0027] Receive the heartbeat information sent by the monitoring device;
[0028] When the monitoring activation status information and / or authentication activation status information carried in the heartbeat information is inconsistent with the monitoring activation status information and / or authentication activation status information configured in the database for the monitoring device, send the corresponding monitoring switch task and / or authentication switch task to the monitoring device;
[0029] Receive the execution result of the monitoring switch task and / or authentication switch task returned by the monitoring device;
[0030] When the execution result of the monitoring switch task and / or authentication switch task is a failure, send the monitoring switch task and / or authentication switch task to the monitoring device again until the monitoring device returns information indicating a successful execution result.
[0031] Optionally, it further includes:
[0032] Perform AI anomaly warning operation on the monitoring device.
[0033] Optionally, performing an AI anomaly warning operation on the monitoring device includes:
[0034] Obtain N heartbeat messages sent by the monitoring device in N time periods, where N is greater than 1;
[0035] Set the N heartbeat information as a time series group, the time series group contains N-dimensional time series, and each time series is set with a key-value pair, and the key-value pair corresponds one-to-one with the content of the heartbeat packet;
[0036] Input the N-dimensional time series into M*N anomaly predictors respectively, where one time series corresponds to M anomaly predictors, and M is a positive integer and less than N;
[0037] Input the key-value pairs of the N time series into a symmetric residual network, and extract the first feature of the key-value pairs through the symmetric residual network;
[0038] Quantify the weights of the first feature pairs through an attention mechanism to obtain the quantified second feature;
[0039] Input the quantified second feature into a bidirectional long short-term memory network to obtain the predicted key-value pairs for the N+1th period;
[0040] Perform early warning judgment on the key-value pairs in the (N + 1)-th period. If the key-value pairs in the (N + 1)-th period exceed the preset threshold range, it is determined that the monitoring device is abnormal.
[0041] Optionally, the interaction request message is encrypted by the monitoring device using the public key provided by the server. The steps of performing decryption and decoding operations on the interaction request message specifically include:
[0042] Use the private key corresponding to the public key to decrypt the interaction request message to obtain the identity identification information of the monitoring device, the address information of the message service module, the subscription topic information, and the plain text string of the monitoring interaction information;
[0043] Judge whether the plain text string of the subscription topic information contains a preset first delimiter and whether the plain text string of the monitoring interaction information contains a preset second delimiter;
[0044] Judge whether the number of the first delimiters in the plain text string of the subscription topic information is the same as the number of the second delimiters in the plain text string of the monitoring interaction information;
[0045] When both judgments are yes, split the plain text string of the subscription topic information and the plain text string of the monitoring interaction information based on the first delimiter and the second delimiter respectively to generate a subscription topic array and an interaction information array.
[0046] Optionally, the step of inputting the monitoring interaction information into the monitoring device associated with the subscription topic information specifically includes:
[0047] Match each subscription topic in the subscription topic array with the subscription topic list stored in the database;
[0048] Determine the monitoring device corresponding to each subscription topic in the subscription topic array according to the matching result;
[0049] Input each interaction information in the interaction information array into the corresponding monitoring device.
[0050] Optionally, an embodiment of the present invention further provides a cloud security monitoring task information interaction system, including:
[0051] A receiving module, configured to receive a monitoring interaction request message sent by a cloud security monitoring device, where the interaction request message includes the identity identification information of a pre-configured monitoring device, the address information of a message service module, subscription topic information, and monitoring interaction information;
[0052] A connection module, configured to establish a communication connection between the monitoring device and the message service module according to the address information;
[0053] An input module, configured to input the monitoring interaction information into a monitoring device associated with the subscription topic information;
[0054] A judgment module, configured to verify the monitoring interaction information to determine whether it is necessary to change the task publishing information associated with the subscription topic information; if the judgment is yes, write the monitoring interaction information into a memory queue and wait for an asynchronous thread pool module to perform a persistence operation on it;
[0055] The judgment module is further configured to determine whether there is task information in the memory queue that needs to be sent to the monitoring device according to the identity identification information of the monitoring device; if the judgment is yes, encapsulate and encrypt the task information and send it to the monitoring device through the message service module.
[0056] A third aspect of the present invention provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the cloud security monitoring task information interaction method according to any one of the first aspects of the present invention.
[0057] The present invention provides a cloud security monitoring task information interaction method and system, which realizes remote real-time management of monitoring devices through an interaction form, facilitates users and operation and maintenance personnel to manage monitoring devices. At the same time, it adopts a lightweight publish / subscribe message transmission to provide reliable network services for monitoring devices in low-bandwidth and unstable network environments, and provides stable monitoring device access services with a large number of connections, high concurrency, and low latency. It supports data encryption, provides a highly secure monitoring device data transmission channel, screens and forwards monitoring device messages, and asynchronously executes by sending messages to improve the system response speed. It supports the monitoring cloud platform to issue commands to monitoring devices, and obtains the status information of monitoring devices according to different commands. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 is a flowchart of a cloud security monitoring task information interaction method provided by an embodiment of the present invention;
[0059] Figure 2 is a flowchart of a monitoring device status monitoring method provided by an embodiment of the present invention;
[0060] Figure 3 is a flowchart of a monitoring version management method provided by an embodiment of the present invention;
[0061] Figure 4 is a schematic diagram of the hardware composition of a device in an embodiment of the present invention;
[0062] Figure 5 is a schematic block diagram of a cloud security monitoring task information interaction system provided by an embodiment of the present invention. Detailed implementation manners
[0063] In order to more clearly understand the above objects, features and advantages of the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments may be combined with each other.
[0064] In the following description, many specific details are set forth in order to fully understand the present invention. However, the present invention may also be implemented in other ways different from those described herein. Therefore, the protection scope of the present invention is not limited by the specific embodiments disclosed below.
[0065] In the description of the present invention, the term "a plurality" means two or more, unless otherwise clearly defined. The orientation or positional relationship indicated by terms such as "upper", "lower", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the system or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be understood as a limitation of the present invention. Terms such as "connection", "installation", "fixation", etc. should all be understood in a broad sense. For example, "connection" may be a fixed connection, a detachable connection, or an integral connection; it may be directly connected, or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations. In addition, terms such as "first", "second", etc. are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first", "second", etc. may explicitly or implicitly include one or more of such features. In the description of the present invention, unless otherwise stated, the meaning of "a plurality" is two or more.
[0066] In the description of this specification, the description of terms such as "one embodiment", "some implementation manners", "specific embodiments", etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in a suitable manner in any one or more embodiments or examples.
[0067] Next, a cloud security monitoring task information interaction method, system and computer-readable medium provided according to some implementation manners of the present invention will be described with reference to the accompanying drawings.
[0068] As Figure 1 shown, a first aspect of the present invention proposes a cloud security monitoring task information interaction method, including:
[0069] Receive the monitoring interaction request message sent by the cloud security monitoring device, where the interaction request message includes the identity identification information of the pre-configured monitoring device, the address information of the message service module, the subscription topic information, and the monitoring interaction information;
[0070] Establish a communication connection between the monitoring device and the message service module according to the address information;
[0071] Input the monitoring interaction information into the monitoring device associated with the subscription topic information;
[0072] The monitoring device verifies the monitoring interaction information to determine whether it is necessary to change the task publishing information associated with the subscription topic information;
[0073] If the determination is yes, write the monitoring interaction information into the memory queue and wait for the asynchronous thread pool module to perform a persistence operation on it;
[0074] Judge whether there is task information in the memory queue that needs to be sent to the monitoring device according to the identity identification information of the monitoring device;
[0075] If the determination is yes, encapsulate and encrypt the task information and send it to the monitoring device through the message service module.
[0076] The cloud security monitoring task information interaction method proposed by the present invention is applied to a monitoring cloud platform, and the monitoring cloud platform interacts with monitoring devices in real time through the message publishing / subscribing mechanism of the MQTT (Message Queuing Telemetry Transport) protocol. The monitoring cloud platform and the monitoring devices use a predefined Topic (subscription topic) for cloud security monitoring interaction. Under the MQTT protocol, the message interaction modes of the interacting parties include the Publish mode and the Subscribe mode. The monitoring device can use the Publish mode to send Publish messages to the service interface of the corresponding subscription topic on the monitoring cloud platform, or use the subscription mode to subscribe to any subscription topic on the monitoring cloud platform to receive service message notifications under the subscription topic. The monitoring device can obtain application instant commands through the monitoring device command Topic cluster and report the execution results. Before returning the results, the data to be changed will be sent to the thread pool, and the asynchronous thread will send the information of the changed monitoring device to the predefined topic Topic, and then it will be sent to the monitoring device by the EMQX message service. Specifically, in the technical solutions of some embodiments of the present invention, the monitoring device encrypts the request information of the monitoring device through the encryption and encoding methods agreed upon with the monitoring cloud platform, and uses the HTTPS (HyperText Transfer Protocol over Secure Socket Layer) protocol to send the request information to the unified API (Application Programming Interface) gateway. The unified API gateway forwards the request to the monitoring device addressing system, and the monitoring device addressing system decrypts and decodes the request information, and calculates the EMQX message service address and Topic that the monitoring device needs to connect according to the configuration data of the monitoring cloud platform, so as to achieve load balancing and improve fault tolerance. After the monitoring device obtains the EMQX message service address and Topic, it creates an MQTT communication connection with the EMQX message service. After receiving the request information of the monitoring device, the EMQX message service pushes it to the monitoring device access system of the corresponding Topic. The monitoring device access system decrypts and decodes the request information, and verifies the decoded data to check whether the request information changes the information of the corresponding Topic on the monitoring cloud platform. If it needs to be changed, the data will be saved to the memory queue and consumed by the asynchronous thread pool and persisted.The monitoring cloud platform determines whether there is a task to be sent to the monitoring device based on the Mac (Media Access Control) address of the monitoring device or the monitoring device ID (Identity document), and if there is a task to be sent, the task is encapsulated and encrypted and then sent to the EMQX message service, which pushes the data to the monitoring device side.
[0077] In the technical solution of the above method, remote real-time management of the monitoring device is realized through an interactive form, which is convenient for users and operation and maintenance personnel to manage the monitoring device. At the same time, it adopts a lightweight publish / subscribe message transmission, provides reliable network services for monitoring devices in low-bandwidth and unstable network environments, and provides stable monitoring device access services with a large number of connections, high concurrency, and low latency. It supports data encryption, provides a highly secure monitoring device data transmission channel, screens and forwards monitoring device messages, and asynchronously executes by sending messages to improve the system response speed.
[0078] Such as Figure 2 shown, in the above cloud security monitoring task information interaction method, it further includes:
[0079] Receiving a registration request from the monitoring device;
[0080] Receiving the heartbeat message periodically sent by the monitoring device in the on state, where the heartbeat message includes the physical address information, monitoring on state information, and authentication on state information of the monitoring device.
[0081] After the monitoring device is registered and started, it publishes a heartbeat message carrying its own Mac address, monitoring on state, and authentication on state to the monitoring cloud platform every minute. The monitoring cloud platform records the real-time online state of the monitoring device according to the latest heartbeat message of the monitoring device, that is, whether the monitoring device is in an online state or an offline state. The display module of the monitoring cloud platform displays the online state or other state information of the monitoring device through its front-end page or back-end page.
[0082] Such as Figure 3 shown, in the above cloud security monitoring task information interaction method, it further includes:
[0083] Receiving the heartbeat message sent by the monitoring device after it is powered on or after performing any task, where the heartbeat message includes the physical address information of the monitoring device and the International Mobile Equipment Identity (IMEI) information;
[0084] Query the IMEI of the monitoring device in the database according to the physical address information of the monitoring device;
[0085] When the IMEI of the monitoring device queried from the database is the same as the IMEI carried in the heartbeat message, return the information that there is no monitoring task currently to the monitoring device; otherwise, send the monitoring task corresponding to the IMEI queried from the database to the monitoring device;
[0086] Receive the IMEI update information or IMEI rollback information for the monitoring device configured by the user in the background;
[0087] Write the IMEI corresponding to the IMEI update information or IMEI rollback information into the database;
[0088] Push the IMEI corresponding to the IMEI update information or IMEI rollback information to the monitoring device so that the monitoring device updates the IMEI, and increment by 1 the updated or rolled-back parameter in the status bar of the monitoring device, indicating that an update or rollback has been performed once.
[0089] Specifically, after the monitoring device is powered on or executes any task, it sends a heartbeat message carrying the Mac address of this monitoring device and the current monitoring IMEI to the monitoring cloud platform. After receiving this heartbeat message, the monitoring cloud platform queries the IMEI saved in the database for the corresponding monitoring device according to this Mac address, and compares it with the current IMEI in the heartbeat message. If the current IMEI is the same as the IMEI saved in the database, the monitoring cloud platform returns the information that there is no update currently to this monitoring device. If the current IMEI is inconsistent with the IMEI saved in the database, the monitoring cloud platform sends the monitoring task corresponding to the IMEI saved in the database to this monitoring device. After the monitoring device finishes executing this monitoring task, it sends a heartbeat message carrying the Mac address of this monitoring device and the current IMEI to the monitoring cloud platform again, repeating the above process until the IMEI on the monitoring device is the same as the IMEI saved in the database of the monitoring cloud platform. When the user needs to update or roll back the IMEI for a certain monitoring device, after configuring the IMEI of this monitoring device in the background of the monitoring cloud platform, the monitoring cloud platform immediately sends this IMEI to the corresponding monitoring device. Further, the user can configure the monitoring version for a batch of monitoring devices (such as monitoring devices of the same model or monitoring devices in the same location, etc.) in the background of the monitoring cloud platform, and batch send it to the corresponding monitoring devices for version change execution.
[0090] In addition, in the embodiments of the present invention, it is also necessary to perform AI anomaly warning operations on the monitoring device. Specifically, N heartbeat messages sent by the monitoring device in N time periods are obtained, where N is greater than 1; the N heartbeat messages are set as a time series group, and the time series group includes an N-dimensional time series. Each time series is set with a key-value pair, and the key-value pair corresponds one-to-one with the content of the heartbeat packet. Key-value is a storage form of a distributed storage system. The original intention of key value is to obtain a value according to a keyword. Among them, key is the keyword and value is the value. A key-value database is a database that stores data in key-value pairs. Each key corresponds to a unique value and has extremely high concurrent read and write performance. For example, if the heartbeat packet contains information A and B, then in the corresponding key-value pair, the same information needs to be included; the N-dimensional time series are respectively input into M*N anomaly predictors, where one time series corresponds to M anomaly predictors, and M is a positive integer and less than N; the key-value pairs of the N time series are input into a symmetric residual network, and the first feature of the key-value pair is extracted through the symmetric residual network; the first feature pair is weight-quantized through an attention mechanism to obtain a quantized second feature; the quantized second feature is input into a bidirectional long short-term memory network to obtain the predicted key-value pair for the (N + 1)th period; an early warning judgment is made on the key-value pair for the (N + 1)th period. If the key-value pair for the (N + 1)th period exceeds the preset threshold range, it is determined that the monitoring device is abnormal. Among them, the symmetric residual network includes a convolution module and a deconvolution module. The convolution module includes K residual blocks, and the deconvolution module includes K deconvolution blocks, where K is an integer greater than or equal to 1; extracting the first feature of the key-value pair through the symmetric residual network specifically includes:
[0091] The local feature is subjected to a convolution operation through the K residual blocks in the convolution module to obtain an intermediate feature; the intermediate feature is subjected to a deconvolution operation through the K deconvolution blocks in the deconvolution module to obtain the first feature of the access volume; the intermediate feature is subjected to a deconvolution operation through the K deconvolution blocks in the deconvolution module to obtain the first feature of the access volume.
[0092] In the above cloud security monitoring task information interaction method, it also includes:
[0093] Receiving the monitoring start status information and / or authentication start status information for the monitoring device configured by the user in the background. The monitoring start status information is to configure the monitoring status of the monitoring device to the start status or the stop status, and the authentication start status information is to configure the authentication status of the monitoring device to the start status or the stop status;
[0094] Write the monitoring activation status information and / or authentication activation status information into the database;
[0095] Receive the heartbeat message sent by the monitoring device;
[0096] When the monitoring activation status information and / or authentication activation status information carried in the heartbeat message is inconsistent with the monitoring activation status information and / or authentication activation status information of the monitoring device configured in the database, send the corresponding monitoring switch task and / or authentication switch task to the monitoring device;
[0097] Receive the execution result of the monitoring switch task and / or authentication switch task returned by the monitoring device;
[0098] When the execution result of the monitoring switch task and / or authentication switch task is a failure, send the monitoring switch task and / or authentication switch task to the monitoring device again until the monitoring device returns information indicating a successful execution result.
[0099] Specifically, the monitoring device reports the monitoring activation status and the authentication activation status each time it sends a heartbeat. If any of the two status information is different from the corresponding status information stored in the database of the monitoring cloud platform, the monitoring cloud platform sends the corresponding monitoring switch task or authentication switch task to the monitoring device until the monitoring activation status information and the authentication activation status information reported by the monitoring device are consistent with the corresponding status information stored in the database of the monitoring cloud platform. When the user needs to turn off or restart the monitoring status or authentication status of a certain monitoring device, it can be configured in the background of the monitoring cloud platform. After the monitoring cloud platform matches the configured status with the status in the heartbeat message reported by the monitoring device, it sends the corresponding switch task to make the monitoring device execute the task to change the corresponding status. Exemplarily, after receiving the monitoring activation task, the monitoring device executes the monitoring activation task and reports the execution result of the monitoring activation task to the monitoring cloud platform after completion. If the monitoring device reports a message indicating that the task execution fails, the monitoring cloud platform sends the monitoring activation task to the monitoring device again until the monitoring status reported by the monitoring device in the heartbeat message is consistent with the monitoring activation status of the monitoring device stored in the database of the monitoring cloud platform.
[0100] When the monitoring device needs to be restarted, send a restart task to the monitoring device on the monitoring cloud platform according to the Mac address of the monitoring device. After receiving the task, the monitoring device executes the restart instruction to restart.
[0101] Further, in the above cloud security monitoring task information interaction method, it further includes:
[0102] Receive the inspection instruction for the monitoring device configured by the user in the background, where the inspection instruction includes the physical address information of the monitoring device;
[0103] Send the inspection instruction to the monitoring device corresponding to the physical address information;
[0104] Receive the execution result of the inspection instruction returned by the monitoring device;
[0105] Display the execution result.
[0106] Specifically, the user inputs the Mac of the monitoring device to be inspected and the inspection command on the monitoring cloud platform. The monitoring cloud platform publishes the command to the specified monitoring device. After receiving the task, the monitoring device runs the specified command and reports the command return value to the monitoring cloud platform. The monitoring cloud platform receives the command return result and displays it to the user.
[0107] Further, in the above cloud security monitoring task information interaction method, the interaction request information is encrypted by the monitoring device using the public key provided by the server. Decryption and decoding operations are performed on the interaction request information to obtain the address information and subscription information. This step specifically includes:
[0108] Use the private key corresponding to the public key to decrypt the interaction request information to obtain the identity identification information of the monitoring device, the address information of the message service module, the subscription topic information, and the plain text string of the monitoring interaction information;
[0109] Judge whether the plain text string of the subscription topic information contains a preset first delimiter and whether the plain text string of the monitoring interaction information contains a preset second delimiter;
[0110] Judge whether the number of the first delimiters in the plain text string of the subscription topic information is the same as the number of the second delimiters in the plain text string of the monitoring interaction information;
[0111] When both judgments are yes, split the plain text string of the subscription topic information and the plain text string of the monitoring interaction information based on the first delimiter and the second delimiter respectively to generate a subscription topic array and an interaction information array.
[0112] Specifically, after the monitoring cloud platform generates a key pair, it issues the public key certificate to the monitoring device. The monitoring device uses the public key certificate obtained from the monitoring cloud platform to encrypt the monitoring interaction information, so that when it transmits the monitoring interaction information to the monitoring cloud platform, the monitoring cloud platform can decrypt it using the corresponding private key. The first delimiter and the second delimiter can be the same symbol or different symbols.
[0113] In the above cloud security monitoring task information interaction method, the method for the monitoring device to generate the interaction request information includes:
[0114] Obtain the subscription topics for which interaction request messages are to be generated and their corresponding monitoring interaction information;
[0115] When the number of subscription topics for which interaction request messages are to be generated is greater than one, group the subscription topics based on the service types corresponding to them on the monitoring cloud platform;
[0116] Use the first delimiter to sequentially splice the subscription topics in the same group to generate a plain text string of the subscription topic name;
[0117] Use the second delimiter to sequentially splice the interaction information corresponding to the subscription topics in the same group to generate a plain text string of the monitoring interaction information;
[0118] Use the public key provided by the server to encrypt the plain text string of the subscription topic name and the plain text string of the monitoring interaction information to generate the interaction request information.
[0119] Specifically, the monitoring cloud platform can run multiple different types of monitoring management service programs on the same server or multiple servers to adapt to different usage scenarios. For example, the system message processing service and the business message processing service can be separated, or the message processing services for monitoring devices in different locations can be separated, simplifying the business processing logic and avoiding data errors caused by information coupling. On the monitoring device side, based on the different service types corresponding to the monitoring interaction messages, the monitoring interaction messages are grouped and merged to reduce the redundant data in the information transmitted between the device and the monitoring cloud platform, improving the interaction efficiency.
[0120] In the above cloud security monitoring task information interaction method, the step of inputting the monitoring interaction information into the monitoring device associated with the subscription topic information specifically includes:
[0121] Match each subscription topic in the subscription topic array with the subscription topic list stored in the database;
[0122] Determine the monitoring device corresponding to each subscription topic in the subscription topic array according to the matching result;
[0123] Input each interaction information in the interaction information array into the corresponding monitoring device.
[0124] Specifically, the monitoring cloud platform stores a subscription topic list in the database and dynamically updates the subscription topic list according to the interaction with the monitoring devices. Users can maintain the subscription topic list through the background management interface of the monitoring cloud platform, including adding new subscription topics, associating subscription topics with monitoring devices, deleting subscription topics that are not subscribed by monitoring devices, and modifying subscription topics and their monitoring interaction information, etc.
[0125] In the technical solution of the above embodiment, after decrypting and decoding the interaction request information reported by the monitoring device, one or more subscription topics in the interaction request information are matched with the subscription topics in the subscription topic list, so as to determine the associated monitoring device to submit the monitoring interaction information corresponding to each subscription topic, so that the monitoring device verifies the monitoring interaction information to determine whether it is necessary to change the task release information associated with the subscription topic information.
[0126] In the above cloud security monitoring task information interaction method, after the step of matching each subscription topic in the subscription topic array with the subscription topic list stored in the database, it further includes:
[0127] When one or more subscription topics in the subscription topic array do not match the subscription topics in the subscription topic list, change the message interaction mode of the monitoring device to the publishing mode;
[0128] Add the unmatched subscription topics to the database;
[0129] Display the added subscription topics;
[0130] Receive the monitoring device information subscribed to the subscription topic configured by the user in the background, and the monitoring device information includes the physical address information of the monitoring device;
[0131] Send the monitoring interaction information of the subscription topic to the monitoring device.
[0132] Specifically, the monitoring device defaults to subscribing to the monitoring task subscription topics published in the monitoring cloud platform. When the monitoring device needs to interact with other monitoring devices for monitoring task information, it can directly carry new subscription topics in the interaction information with the monitoring cloud platform. The monitoring cloud platform will automatically change the interaction information submitting these subscription topics to the publishing mode to publish these newly added subscription topics. Users can configure the monitoring devices that need to subscribe to these subscription topics on the background management page, and then obtain the corresponding monitoring interaction information from the monitoring cloud platform.
[0133] An embodiment of the present invention provides a computer-readable medium with a computer program stored thereon. When the computer program is executed by a processor, it implements the cloud security monitoring task information interaction method described in any one of the first aspects of the present invention.
[0134] Figure 4 It is a schematic diagram of the hardware composition of the device in an embodiment. It can be understood that Figure 4 only a simplified design of the device is shown. In practical applications, the device may also separately include other necessary elements, including but not limited to any number of input / output systems, processors, controllers, memories, etc., and all devices that can implement the big data management method of the embodiments of the present application are within the protection scope of the present application.
[0135] The memory includes but is not limited to a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or a compact disc read-only memory (CD-ROM). The memory is used for relevant instructions and data.
[0136] The input system is used to input data and / or signals, and the output system is used to output data and / or signals. The output system and the input system can be independent devices or an integrated device.
[0137] The processor may include one or more processors, for example, including one or more central processing units (CPUs). In the case where the processor is a single CPU, the CPU can be a single-core CPU or a multi-core CPU. The processor may also include one or more dedicated processors, and the dedicated processors may include GPUs, FPGAs, etc., for acceleration processing.
[0138] The memory is used to store the program code and data of the network device.
[0139] The processor is used to call the program code and data in the memory and execute the steps in the above method embodiments. For details, please refer to the description in the method embodiments and will not be elaborated here.
[0140] In several embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The couplings, direct couplings, or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of systems or units can be in electrical, mechanical, or other forms.
[0141] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0142] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable systems. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired manner (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or a wireless manner (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that the computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a read-only memory (ROM), a random access memory (RAM), a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape, a magnetic disk, or an optical medium, such as a digital versatile disc (DVD), or a semiconductor medium, such as a solid state disk (SSD), etc.
[0143] As Figure 5 shown, a second aspect of the present invention proposes a cloud security monitoring task information interaction system, including:
[0144] A receiving module, configured to receive a monitoring interaction request message sent by a cloud security monitoring device, where the interaction request message includes identity identification information of a pre-configured monitoring device, address information of a message service module, subscription topic information, and monitoring interaction information;
[0145] A connection module, configured to establish a communication connection between the monitoring device and the message service module according to the address information;
[0146] An input module, configured to input the monitoring interaction information into a monitoring device associated with the subscription topic information;
[0147] A judgment module, configured to verify the monitoring interaction information to determine whether it is necessary to change task publishing information associated with the subscription topic information; if the determination is yes, write the monitoring interaction information into a memory queue and wait for an asynchronous thread pool module to perform a persistence operation on it;
[0148] The judgment module is further configured to determine whether there is task information in the memory queue that needs to be sent to the monitoring device according to the identity identification information of the monitoring device; if the determination is yes, encapsulate and encrypt the task information and send it to the monitoring device through the message service module.
[0149] Specifically, the cloud security monitoring task information interaction method proposed by the present invention is applied to a monitoring cloud platform, and the monitoring cloud platform interacts with monitoring devices in real time through the message publishing / subscribing mechanism of the MQTT (Message Queuing Telemetry Transport) protocol. The monitoring cloud platform and the monitoring devices use a predefined Topic (subscription topic) for cloud security monitoring interaction. Under the MQTT protocol, the message interaction modes of the interacting parties include the Publish mode and the Subscribe mode. The monitoring devices can use the Publish mode to send Publish messages to the service interfaces of the corresponding subscription topics on the monitoring cloud platform, or use the subscription mode to subscribe to any subscription topic on the monitoring cloud platform to receive service message notifications under that subscription topic. The monitoring devices can obtain application instant commands through the monitoring device command Topic cluster and report the execution results. Before returning the results, the data to be changed will be sent to the thread pool, and the asynchronous thread will send the information of the changed monitoring device to the predefined topic Topic, and then it will be sent to the monitoring device by the EMQX message service. Specifically, in the technical solutions of some embodiments of the present invention, the monitoring devices encrypt the request information of the monitoring devices through the encryption and encoding methods agreed upon with the monitoring cloud platform, and use the HTTPS (Hyper Text Transfer Protocol over Secure Socket Layer) protocol to send the request information to the unified API (Application Programming Interface) gateway. The unified API gateway forwards the request to the monitoring device addressing system, and the monitoring device addressing system decrypts and decodes the request information, calculates the EMQX message service address and Topic that the monitoring device needs to connect to according to the configuration data of the monitoring cloud platform, so as to achieve load balancing and improve fault tolerance. After obtaining the EMQX message service address and Topic, the monitoring devices create an MQTT communication connection with the EMQX message service. After receiving the request information of the monitoring devices, the EMQX message service pushes it to the monitoring device access system of the corresponding Topic. The monitoring device access system decrypts and decodes the request information, and verifies the decoded data to check whether the request information changes the information of the corresponding Topic on the monitoring cloud platform. If it needs to be changed, the data will be saved to the memory queue and consumed by the asynchronous thread pool and persisted.The monitoring cloud platform determines whether there is a task to be sent to the monitoring device based on the Mac (Media Access Control) address of the monitoring device or the monitoring device ID (Identity document), and if there is a task to be sent, the task is encapsulated and encrypted and then sent to the EMQX message service, which pushes the data to the monitoring device side.
[0150] In addition, in the embodiment of the present invention, the system is further configured to:
[0151] Receive the registration request of the monitoring device;
[0152] Receive the heartbeat message periodically sent by the monitoring device in the on state, where the heartbeat message includes the physical address information of the monitoring device, the monitoring on state information, and the authentication on state information.
[0153] After the monitoring device is registered and started, it publishes a heartbeat message carrying its own Mac address, monitoring on state, and authentication on state to the monitoring cloud platform every minute. The monitoring cloud platform records the real-time online state of the monitoring device according to the latest heartbeat message of the monitoring device, that is, whether the monitoring device is in an online state or an offline state. The display module of the monitoring cloud platform displays the online state or other state information of the monitoring device through its front-end page or back-end page.
[0154] In the above cloud security monitoring task information interaction process, it further includes:
[0155] Receive the heartbeat message sent by the monitoring device after it is powered on or after performing any task, where the heartbeat message includes the physical address information of the monitoring device and the International Mobile Equipment Identity (IMEI) information;
[0156] Query the IMEI of the monitoring device in the database according to the physical address information of the monitoring device;
[0157] When the IMEI of the monitoring device queried from the database is the same as the IMEI carried in the heartbeat message, return the information that there is no monitoring task currently to the monitoring device;
[0158] Otherwise, send the monitoring task corresponding to the IMEI queried from the database to the monitoring device;
[0159] Receive the IMEI update information or IMEI rollback information configured by the user for the monitoring device in the background;
[0160] Write the IMEI corresponding to the IMEI update information or IMEI rollback information into the database;
[0161] Push the IMEI corresponding to the IMEI update information or IMEI rollback information to the monitoring device so that the monitoring device updates the IMEI, and increment the updated or rolled-back parameter by 1 in the status bar of the monitoring device to indicate that an update or rollback has been performed once.
[0162] Specifically, after the monitoring device is powered on or performs any task, it sends a heartbeat message carrying the Mac address of this monitoring device and the current monitored IMEI to the monitoring cloud platform. After receiving the heartbeat message, the monitoring cloud platform queries the IMEI saved in the database for the corresponding monitoring device according to the Mac address, and compares it with the current IMEI in the heartbeat message. If the current IMEI is the same as the IMEI saved in the database, the monitoring cloud platform returns information indicating that there is no update to the monitoring device. If the current IMEI is inconsistent with the IMEI saved in the database, the monitoring cloud platform issues the monitoring task corresponding to the IMEI saved in the database to the monitoring device. After the monitoring device finishes executing the monitoring task, it sends a heartbeat message carrying the Mac address of this monitoring device and the current IMEI to the monitoring cloud platform again, repeating the above process until the IMEI on the monitoring device is the same as the IMEI saved in the database of the monitoring cloud platform. When the user needs to update or roll back the IMEI for a certain monitoring device, after configuring the IMEI of the monitoring device in the background of the monitoring cloud platform, the monitoring cloud platform immediately sends the IMEI to the corresponding monitoring device. Further, the user can configure the monitoring version for a batch of monitoring devices (such as monitoring devices of the same model or monitoring devices in the same location, etc.) in the background of the monitoring cloud platform and batch-issue it to the corresponding monitoring devices for version change execution.
[0163] In addition, in the embodiments of the present invention, the system is further configured to perform AI anomaly warning operations on the monitoring device. Specifically, N heartbeat messages sent by the monitoring device in N time periods are obtained, where N is greater than 1; the N heartbeat messages are set as a time series group, and the time series group includes an N-dimensional time series. Each time series is set with a key-value pair, and the key-value pair corresponds one-to-one to the content of the heartbeat packet. Key-value is a storage form of a distributed storage system. The original intention of key value is to obtain a value according to a keyword. Among them, key is the keyword and value is the value. A key-value database is a database that stores data in key-value pairs. Each key corresponds to a unique value and has extremely high concurrent read and write performance. For example, if the heartbeat packet contains information A and B, then the corresponding key-value pair also needs to contain the same information; the N-dimensional time series are respectively input into M*N anomaly predictors, where one time series corresponds to M anomaly predictors, and M is a positive integer and less than N; the key-value pairs of the N time series are input into a symmetric residual network, and the first feature of the key-value pair is extracted through the symmetric residual network; the first feature pair is weighted and quantified through an attention mechanism to obtain a quantified second feature; the quantified second feature is input into a bidirectional long short-term memory network to obtain the predicted key-value pair for the (N + 1)th period; an early warning judgment is made on the key-value pair for the (N + 1)th period. If the key-value pair for the (N + 1)th period exceeds the preset threshold range, it is determined that the monitoring device is abnormal. Among them, the symmetric residual network includes a convolution module and a deconvolution module. The convolution module includes K residual blocks, and the deconvolution module includes K deconvolution blocks, where K is an integer greater than or equal to 1; extracting the first feature of the key-value pair through the symmetric residual network specifically includes:
[0164] The local feature is subjected to a convolution operation through the K residual blocks in the convolution module to obtain an intermediate feature; the intermediate feature is subjected to a deconvolution operation through the K deconvolution blocks in the deconvolution module to obtain the first feature of the access volume; the intermediate feature is subjected to a deconvolution operation through the K deconvolution blocks in the deconvolution module to obtain the first feature of the access volume.
[0165] In the above information interaction process of the cloud security monitoring task, it further includes:
[0166] Receiving the monitoring start status information and / or authentication start status information for the monitoring device configured by the user in the background. The monitoring start status information is to configure the monitoring status of the monitoring device to the start status or the stop status, and the authentication start status information is to configure the authentication status of the monitoring device to the start status or the stop status;
[0167] Write the monitoring start status information and / or authentication start status information into the database;
[0168] Receive the heartbeat message sent by the monitoring device;
[0169] When the monitoring start status information and / or authentication start status information carried in the heartbeat message of the monitoring device is inconsistent with the monitoring start status information and / or authentication start status information configured in the database for the monitoring device, send the corresponding monitoring switch task and / or authentication switch task to the monitoring device;
[0170] Receive the execution result of the monitoring switch task and / or authentication switch task returned by the monitoring device;
[0171] When the execution result of the monitoring switch task and / or authentication switch task is a failure, send the monitoring switch task and / or authentication switch task to the monitoring device again until the monitoring device returns information indicating a successful execution result.
[0172] Specifically, the monitoring device reports the monitoring start status and authentication start status each time it sends a heartbeat. If any one of the two status information is different from the corresponding status information stored in the database of the monitoring cloud platform, the monitoring cloud platform sends the corresponding monitoring switch task or authentication switch task to the monitoring device until the monitoring start status information and authentication start status information reported by the monitoring device are consistent with the corresponding status information stored in the database of the monitoring cloud platform. When the user needs to turn off or restart the monitoring status or authentication status of a certain monitoring device, it can be configured in the background of the monitoring cloud platform. After the monitoring cloud platform matches the configured status with the status in the heartbeat message reported by the monitoring device, it sends the corresponding switch task to make the monitoring device execute the task to change the corresponding status. Exemplarily, after receiving the monitoring start task, the monitoring device executes the monitoring start task and reports the execution result of the monitoring start task to the monitoring cloud platform after completion. If the monitoring device reports a message indicating that the task execution fails, the monitoring cloud platform sends the monitoring start task to the monitoring device again until the monitoring status reported by the monitoring device in the heartbeat message is consistent with the monitoring start status of the monitoring device stored in the database of the monitoring cloud platform.
[0173] When the monitoring device needs to be restarted, send a restart task to the monitoring device on the monitoring cloud platform according to the Mac address of the monitoring device. After receiving the task, the monitoring device executes the restart instruction to restart.
[0174] Furthermore, in the above cloud security monitoring task information interaction process, it also includes:
[0175] Receive the inspection instruction for the monitoring device configured by the user in the background, where the inspection instruction includes the physical address information of the monitoring device;
[0176] Send the inspection instruction to the monitoring device corresponding to the physical address information;
[0177] Receive the execution result of the inspection instruction returned by the monitoring device;
[0178] Display the execution result.
[0179] Specifically, the user inputs the Mac of the monitoring device to be inspected and the inspection command on the monitoring cloud platform. The monitoring cloud platform publishes the command to the specified monitoring device. After receiving the task, the monitoring device runs the specified command and reports the command return value to the monitoring cloud platform. The monitoring cloud platform receives the command return result and displays it to the user.
[0180] Further, in the above cloud security monitoring task information interaction method, the interaction request information is encrypted by the monitoring device using the public key provided by the server. Decryption and decoding operations are performed on the interaction request information to obtain the address information and subscription information. This step specifically includes:
[0181] Use the private key corresponding to the public key to decrypt the interaction request information to obtain the identity identification information of the monitoring device, the address information of the message service module, the subscription topic information, and the plain text string of the monitoring interaction information;
[0182] Judge whether the plain text string of the subscription topic information contains a preset first delimiter and whether the plain text string of the monitoring interaction information contains a preset second delimiter;
[0183] Judge whether the number of the first delimiters in the plain text string of the subscription topic information is the same as the number of the second delimiters in the plain text string of the monitoring interaction information;
[0184] When both judgments are yes, split the plain text string of the subscription topic information and the plain text string of the monitoring interaction information based on the first delimiter and the second delimiter respectively to generate a subscription topic array and an interaction information array.
[0185] Specifically, after the monitoring cloud platform generates a key pair, it issues the public key certificate to the monitoring device. The monitoring device uses the public key certificate obtained from the monitoring cloud platform to encrypt the monitoring interaction information, so that when it transmits the monitoring interaction information to the monitoring cloud platform, the monitoring cloud platform can decrypt it using the corresponding private key. The first delimiter and the second delimiter can be the same symbol or different symbols.
[0186] In the above cloud security monitoring task information interaction method, the method for the monitoring device to generate the interaction request information includes:
[0187] Obtain the subscription topic for which the interaction request message is to be generated and its corresponding monitoring interaction information;
[0188] When the number of subscription topics for which the interaction request message is to be generated is greater than one, group the subscription topics based on the service types corresponding to the subscription topics on the monitoring cloud platform;
[0189] Use the first delimiter to sequentially splice the subscription topics in the same group to generate a plain text string of the subscription topic;
[0190] Use the second delimiter to sequentially splice the interaction information corresponding to the subscription topics in the same group to generate a plain text string of the monitoring interaction information;
[0191] Use the public key provided by the server to encrypt the plain text string of the subscription topic and the plain text string of the monitoring interaction information to generate the interaction request information.
[0192] Specifically, the monitoring cloud platform can run multiple different types of monitoring management service programs on the same server or multiple servers to adapt to different usage scenarios. For example, the system message processing service and the business message processing service can be separated, or the message processing services for monitoring devices in different locations can be separated, simplifying the business processing logic and avoiding data errors caused by information coupling. On the monitoring device side, based on the different service types corresponding to the monitoring interaction messages, the monitoring interaction messages are grouped and merged to reduce the redundant data in the information transmitted between the device and the monitoring cloud platform, improving the interaction efficiency.
[0193] In the above cloud security monitoring task information interaction method, the step of inputting the monitoring interaction information into the monitoring device associated with the subscription topic information specifically includes:
[0194] Match each subscription topic in the subscription topic array with the subscription topic list saved in the database;
[0195] Determine the monitoring device corresponding to each subscription topic in the subscription topic array according to the matching result;
[0196] Input each interaction information in the interaction information array into the corresponding monitoring device.
[0197] Specifically, the monitoring cloud platform stores a subscription topic list in the database and dynamically updates the subscription topic list according to the interaction with the monitoring devices. Users can maintain the subscription topic list through the background management interface of the monitoring cloud platform, including adding new subscription topics, associating subscription topics with monitoring devices, deleting subscription topics that are not subscribed by monitoring devices, and modifying subscription topics and their monitoring interaction information, etc.
[0198] The present invention provides a cloud security monitoring task information interaction method, system and computer-readable medium, which realizes remote real-time management of monitoring devices through an interaction form, facilitating users and operation and maintenance personnel to manage monitoring devices. At the same time, it adopts a lightweight publish / subscribe message transmission, provides reliable network services for monitoring devices in low-bandwidth and unstable network environments, and provides stable monitoring device access services with a large number of connections, high concurrency and low latency. It supports data encryption, provides a highly secure monitoring device data transmission channel, screens and forwards monitoring device messages and asynchronously executes by sending messages to improve the system response speed, supports the monitoring cloud platform to issue commands to monitoring devices, and obtains the status information of monitoring devices according to different commands.
[0199] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or monitoring device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or monitoring device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or monitoring device comprising the element.
[0200] According to the embodiments of the present invention as described above, these embodiments do not elaborate on all details, nor limit the invention to the specific embodiments described. Obviously, according to the above description, many modifications and variations can be made. The present specification selects and specifically describes these embodiments to better explain the principles and practical applications of the present invention, so that those skilled in the art can make good use of the present invention and its modifications based on the present invention. The present invention is only limited by the claims and their full scope and equivalents.
Claims
1. A cloud security monitoring task information interaction method, characterized in that Including: Receiving a monitoring interaction request message sent by a cloud security monitoring device, where the interaction request message includes the identity identification information of a pre-configured monitoring device, the address information of a message service module, subscription topic information, and monitoring interaction information; Establishing a communication connection between the monitoring device and the message service module according to the address information; Inputting the monitoring interaction information into the monitoring device associated with the subscription topic information; The monitoring device validates the monitoring interaction information to determine whether it is necessary to change the task publishing information associated with the subscription topic information; If the determination is yes, write the monitoring interaction information into a memory queue and wait for the asynchronous thread pool module to perform a persistence operation on it; Judging whether there is task information in the memory queue that needs to be sent to the monitoring device according to the identity identification information of the monitoring device; If the determination is yes, encapsulate and encrypt the task information and send it to the monitoring device through the message service module; The method further includes: Receiving a registration request from the monitoring device; Receiving a heartbeat message periodically sent by the monitoring device in the on state, where the heartbeat message includes the physical address information of the monitoring device, the monitoring on state information, and / or the authentication on state information; The method further includes: Performing an AI anomaly warning operation on the monitoring device; Among them, performing an AI anomaly warning operation on the monitoring device includes: Obtaining N heartbeat messages sent by the monitoring device in N time periods, where N is greater than 1; Setting the N heartbeat messages as a time series group, where the time series group includes N-dimensional time series, and each time series is set with a key-value pair, and the key-value pair corresponds one-to-one with the content of the heartbeat packet; Inputting the N-dimensional time series into M*N anomaly predictors respectively, where one time series corresponds to M anomaly predictors, and M is a positive integer and less than N; Inputting the key-value pairs of the N time series into a symmetric residual network, and extracting the first feature of the key-value pairs through the symmetric residual network; Performing weight quantization on the first feature pair through an attention mechanism to obtain a quantized second feature; Inputting the quantized second feature into a bidirectional long short-term memory network to obtain the key-value pair of the predicted N+1th period; Performing an early warning judgment on the key-value pair of the N+1th period. If the key-value pair of the N+1th period exceeds a preset threshold range, it is determined that the monitoring device is abnormal.
2. The cloud security monitoring task information interaction method according to claim 1, wherein It also includes: Receiving the heartbeat information sent by the monitoring device after it is powered on or after performing any task, where the heartbeat information includes the physical address information of the monitoring device and the International Mobile Equipment Identity Code (IMEI) information; Querying the IMEI of the monitoring device in a database according to the physical address information of the monitoring device; When the IMEI of the monitoring device queried from the database is the same as the IMEI carried in the heartbeat information, returning information indicating that there is no monitoring task currently to the monitoring device; Otherwise, sending the monitoring task corresponding to the IMEI queried from the database to the monitoring device; Configured IMEI update information or IMEI rollback information for the monitoring device; Write the IMEI corresponding to the IMEI update information or IMEI rollback information into the database; Push the IMEI corresponding to the IMEI update information or IMEI rollback information to the monitoring device so that the monitoring device updates the IMEI, and increment the updated or rolled-back parameter by 1 in the status bar of the monitoring device.
3. The cloud security monitoring task information interaction method according to claim 1, characterized in that It further includes: Receive the monitoring enable status information and / or authentication enable status information for the monitoring device configured by the user in the background, where the monitoring enable status information is to configure the monitoring status of the monitoring device to the enabled state or the disabled state, and the authentication enable status information is to configure the authentication status of the monitoring device to the enabled state or the disabled state; Write the monitoring enable status information and / or authentication enable status information into the database; Receive the heartbeat information sent by the monitoring device; When the monitoring enable status information and / or authentication enable status information carried in the heartbeat information is inconsistent with the monitoring enable status information and / or authentication enable status information of the monitoring device configured in the database, send the corresponding monitoring switch task and / or authentication switch task to the monitoring device; Receive the execution result of the monitoring switch task and / or authentication switch task returned by the monitoring device; When the execution result of the monitoring switch task and / or authentication switch task is a failure, send the monitoring switch task and / or authentication switch task to the monitoring device again until the monitoring device returns information indicating a successful execution result.
4. The cloud security monitoring task information interaction method according to claim 1, wherein The interaction request message is encrypted by the monitoring device using the public key provided by the server. The steps of performing decryption and decoding operations on the interaction request message specifically include: Use the private key corresponding to the public key to decrypt the interaction request message to obtain the identity identification information of the monitoring device, the address information of the message service module, the subscription topic information, and the plain text string of the monitoring interaction information; Determine whether the plain text string of the subscription topic information contains a preset first delimiter and whether the plain text string of the monitoring interaction information contains a preset second delimiter; Determine whether the number of the first delimiters in the plain text string of the subscription topic information is the same as the number of the second delimiters in the plain text string of the monitoring interaction information; When both judgments are yes, split the plain text string of the subscription topic information and the plain text string of the monitoring interaction information based on the first delimiter and the second delimiter respectively to generate a subscription topic array and an interaction information array.
5. The cloud security monitoring task information interaction method according to claim 4, wherein The step of inputting the monitoring interaction information into the monitoring device associated with the subscription topic information specifically includes: Match each subscription topic in the subscription topic array with the subscription topic list saved in the database; Determine the monitoring device corresponding to each subscription topic in the subscription topic array according to the matching result; Input each interaction information in the interaction information array into the corresponding monitoring device.
Citation Information
Patent Citations
Method for intelligent terminal to detect whether running of monitoring APP is stopped or not
CN115048262A
Method and apparatus for providing a key-value based storage interface
US20130103729A1