Heterogeneous system self-evolution method and system based on active perception and intelligent prediction

By building a dynamic heterogeneous system environment and utilizing virtualization technology and consistency adjudication, we can achieve active perception and intelligent prediction of unknown threats, accurately locate system defects, and dynamically change the system environment to eliminate or hide defects. This solves the problem of existing technologies being unable to defend against unknown attacks and locate system defects, thereby improving system security.

CN115801339BActive Publication Date: 2025-09-12EAST CHINA INST OF COMPUTING TECH
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202211334157.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-28
Publication Date
2025-09-12
Estimated Expiration
2042-10-28

AI Technical Summary

Technical Problem

Existing technologies cannot effectively defend against unknown attacks, cannot accurately locate system defects, and existing defense methods cannot eliminate or hide system defects, resulting in the system being in a high-risk state when facing unknown threats.

Method used

By building a dynamic heterogeneous system operating environment, using virtualization technology to generate heterogeneous systems, giving each request a universal unique identification code, conducting tracking monitoring and consistency judgment, performing defect location and attack scenario reproduction, building an attack and defect knowledge base, dynamically changing the system environment to eliminate or hide defects, and performing robust execution judgment.

Benefits of technology

It realizes active perception and intelligent prediction of unknown threats, accurately locates system defects, dynamically changes the system environment, improves the system's defense effect against known and unknown attacks, reduces defect exposure time, and enhances system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115801339B_ABST
    Figure CN115801339B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for self-evolution of heterogeneous systems based on active perception and intelligent prediction, including: generating a heterogeneous system operating environment, tracking and monitoring each request, formatting and extracting the perceived sensitive information, and performing consistency judgment; locating defects and reproducing attack scenarios in defective heterogeneous system operating environments, performing defect processing, extracting corresponding features to construct an attack knowledge base and a defect knowledge base; pre-perceiving system component defects for subsequent attack requests and sensitive information generated in the system, and dynamically changing the system and its operating environment before the attack chain is completed; performing robust execution judgment for suspected malicious requests, and selecting a processing result that meets preset conditions as the request response. The present invention improves the security strength of the system and its operating environment by intelligently predicting threats, proactively and pre-emptively performing system self-evolution, and eliminating exploitable component defects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and system for self-evolution of heterogeneous systems based on active perception and intelligent prediction. Background Art

[0002] Cyberspace is an extension and outgrowth of the real world. As the frontline of real-world conflict, it has become a new battlefield for international strategic games. Warfare in cyberspace has entered a new, more open phase, with new rules of engagement and deterrence being established. Cyberspace is the command hub of modern military activities and is closely linked to the public opinion and psychological warfare of information warfare. The struggle for sovereignty in cyberspace has become an inevitable component of modern warfare and is becoming increasingly important.

[0003] Current network defenses are largely based on existing attack knowledge bases, ensuring information and system security through network firewall filtering, system vulnerability and malware scanning, and other means. This approach only protects against discovered and confirmed attacks and is unable to defend against unknown new attacks. Furthermore, scanning and filtering methods cannot eliminate system vulnerabilities and other defects. With the rapid increase in the number of system vulnerabilities, such as 14,000 Common Vulnerabilities and Events (CVEs) in the first three quarters of 2020, and the limited pace of vulnerability remediation, system defects increase over time, increasing the window of time when the system is at medium or high risk. Although artificial intelligence technology has been used in recent years to assess vulnerability risk and prioritize high-risk vulnerabilities for remediation, this does not effectively guarantee information and system security.

[0004] Furthermore, to defend against unknown attacks, attack pattern / behavior analysis and prediction methods have become widely used with the development of artificial intelligence technology. This approach analyzes known attack knowledge to identify characteristics, patterns, and other information. Based on these attack characteristics or behavior patterns, it then detects user access data, thereby achieving the goal of defending against unknown attacks. However, the effectiveness of attack characteristic and behavior pattern identification is currently insufficient. This not only fails to protect against new attack patterns or methods, resulting in missed alerts, but also leads to a large number of false alarms, increasing the workload of monitoring personnel and further weakening the effectiveness of defenses. Surveys show that among the tens of thousands of security alerts received daily, up to 45% are false alarms, and 35% of responders choose to ignore alerts when the queue is crowded. Furthermore, existing technologies generally rely on known virus and vulnerability databases for vulnerability identification, but are unable to locate system environment flaws used by unknown threats. Regarding threat protection, existing technologies typically use methods such as malicious request / behavior filtering and system resets to defend against attacks. While malicious request / behavior filtering is efficient and cost-effective, it only protects against known threats. Although the system reset method can restore the system to a working state and clear the existing attack chain, the system defects still exist after the reset and the risk is not reduced.

[0005] Patent document CN108600275A (application number: CN201810532933.3) discloses an artificial intelligence-based threat scenario perception information security active defense system, which includes: a data acquisition module for real-time collection of network events, system operation data, and network equipment operation data to obtain raw data information; a security assessment module for processing the collected raw data information and performing a security assessment on the network; a disposal module for determining a security incident handling strategy based on the assessment results of the security assessment module, thereby actively defending against threatening behaviors in the network. This patent perceives threat scenarios in the network by calculating the matching value between network description information and network description information of normal network operation pre-stored in a standard database; and the present invention traces system requests and their processing processes based on a security consensus mechanism, and completes active perception of threats by extracting sensitive information and making consistency judgments during the request processing process. This patent only determines the security incident handling strategy based on the evaluation results of the security assessment module and actively defends against threatening behaviors in the network; while the system adaptive method of the present invention adopts multiple means of defect elimination, defect concealment and defect tolerance, and prioritizes eliminating existing defects by replacing defective components, and adopts defect concealment means for defects that cannot be eliminated. After sensing the threat, the defect tolerance method can be used, providing a highly reliable request response for system requests.

[0006] Patent document CN110581852A (application number: CN201910857183.1) discloses an efficient mimicry defense system and method, wherein the system includes an input agent, a heterogeneous executor pool and an arbiter, and also includes a fault detector, a fault collector and a fault recovery module; the method includes the following steps: Step 1: The fault detector detects the operating status of the heterogeneous executor's hardware and software in real time, and sends the detected fault information to the fault collector, and then the fault collector transmits the fault information to the arbiter, the input agent and the fault recovery module; Step 2: The arbiter removes the arbitration of the faulty heterogeneous executor message; Step 3: The input agent removes the distribution of the faulty heterogeneous executor input message; Step 4: The fault recovery module issues a set command to the faulty heterogeneous executor or resets the heterogeneous executor through hardware. The patent addresses defect localization based on a fault detector designed for each heterogeneous executor. This detector monitors the operational status of the heterogeneous executor's software and hardware in real time and sends fault messages to a fault collector. In contrast, the present invention addresses defect localization by analyzing and determining the attack chain based on the dynamic generation of the heterogeneous system and its operating environment. This method accurately locates the component where the defect is located and obtains information such as the characteristics of the defective component. In the patent, security recovery is achieved through a fault recovery function. The fault recovery module receives fault information from the fault collector and issues a reset command to the faulty heterogeneous executor or resets the heterogeneous executor through hardware. If the fault recovery module receives fault information from the heterogeneous executor again within a specified timeframe, the executor is directly removed. In contrast, the present invention utilizes fault localization and fault tolerance technologies for security recovery. For a defective heterogeneous system operating environment, a component that does not contain the defect is selected from the heterogeneous resource pool to replace the defective component to eliminate the defect. Alternatively, the attack chain is promptly interrupted by frequently and dynamically switching the defective component, preventing the defect from being effectively exploited and concealing the defect, thereby further improving the system's operating environment.

[0007] Patent document CN112615862A (application number: CN202011499913.4) discloses an attack defense device, method, equipment and medium based on mimetic defense. The device includes a mimetic scheduler and several heterogeneous executors; the heterogeneous executors receive and process message data sent by the mimetic scheduler; the mimetic scheduler includes a mimetic judgment module and an attack defense module, which are used to receive message data sent by the front-end chip and forward it to the heterogeneous executor to realize data distribution, mimetic judgment and cleaning management of the heterogeneous executor; the mimetic judgment module performs mimetic judgment on the downlink data of the heterogeneous executor, and sends the result of the mimetic judgment to the attack defense module; the attack defense module collects, extracts and logs the message data sent by the front-end chip, and performs log updates, attack defense detection and attack data filtering according to the mimetic judgment result of the mimetic judgment module. This patent determines whether there is an abnormal attack by comparing and analyzing the message data with the key data stored in the log module before distributing it to the heterogeneous executor. In addition, this patent does not locate the system defects targeted by the attack when performing attack detection and defense, and cannot achieve targeted and efficient security defense based on attack diagnosis; the present invention, on the other hand, for external attack threats, builds a corresponding knowledge base for actively perceived unknown threats, and combines it with the existing knowledge base to effectively make intelligent predictions for known and unknown attack threats, effectively guide the active self-evolution of the system, and combines the extraction and consistency judgment of sensitive information in the request processing process to perceive system threats, and take measures in advance for further development of the threats, thereby realizing attack detection. In addition, the present invention accurately locates the system defects facing the attack chain based on attack reproduction technology, determines the key positions of system defense, conducts targeted defense, and improves the attack knowledge base. This patent achieves system security capability recovery through heterogeneous executor cleaning. When scheduling the executor during the security capability recovery process, a threshold is set to determine whether the number of exceptions corresponding to the heterogeneous executor is greater than the set threshold. Then, it is determined whether the extracted protocol key parameters and the key parameter values ​​in the custom log content are the same. If they are the same and the number of exceptions is higher than the threshold, the heterogeneous executor is directly filtered and other executors are scheduled for use. The present invention achieves system security capability recovery through system self-evolution technology, through threat intelligent prediction, pre-perception of threats and system defect characteristics and other information, and uses virtualization technologies such as containers to dynamically generate heterogeneous system operating environments. The dynamic automatic deployment of the system improves the generation efficiency of the system and its operating environment. According to attack prediction and defect location, heterogeneous system environment components with equivalent functions and different architectures are generated in a targeted and dynamic manner, and the system is actively self-evolved in advance to maintain safe system operation. Summary of the Invention

[0008] In view of the defects in the prior art, the purpose of the present invention is to provide a method and system for self-evolution of heterogeneous systems based on active perception and intelligent prediction.

[0009] The heterogeneous system self-evolution method based on active perception and intelligent prediction provided by the present invention includes:

[0010] Step S1: Dynamically generate a heterogeneous system operating environment through virtualization technology;

[0011] Step S2: assign a universal unique identification code to each request and track and monitor the request;

[0012] Step S3: In each heterogeneous system operating environment, the perceived sensitive information is formatted and extracted and consistency judgment is performed;

[0013] Step S4: For the heterogeneous system operating environment with defects, locate the defects, reproduce the attack scenarios, and handle the defects;

[0014] Step S5: Based on the attack scenario reproduction, extract corresponding features to build an attack knowledge base and a defect knowledge base;

[0015] Step S6: Preemptively detect system component flaws based on subsequent attack requests and sensitive information generated in the system. Dynamically change the system and its operating environment before the attack chain is completed, eliminating or hiding the flaws in advance.

[0016] Step S7: For suspected malicious requests, perform robust execution judgment and select a processing result that meets the preset conditions as the request response.

[0017] Preferably, based on the universal unique identifier of the request, the processing process of the request in the heterogeneous system operating environment is retroactively monitored, and multiple sensitive information is identified and collected. The information is formatted and submitted to the consistency arbitration architecture for voting. The threat is perceived and the request is responded to based on the voting results.

[0018] When the consistency decision is normal, the normal request processing result is obtained directly; when the consistency decision is abnormal, it is judged as a suspected malicious request, and the current request, context information, and abnormal sensitive information obtained by the request are saved.

[0019] Preferably, the attack scenario is reproduced multiple times using attack reproduction technology, and the components in the system and its operating environment are heterogeneously replaced through dynamic generation technology of the system and its operating environment. The attack is then reproduced again, and the replaced components are judged based on the attack results to determine whether there are vulnerabilities, thereby accurately locating the defects.

[0020] By comparing the features of the defective component / module with its replacement component / module, the characteristics of the defect can be obtained so that the defect can be handled in a targeted manner.

[0021] Preferably, a corresponding knowledge base is constructed for the proactively perceived threats and located defects, threat and defect characteristics are retained, and the knowledge is normalized and stored;

[0022] Extract the characteristics of unknown threats and defects, and based on the usage of threats and defects, combine the known threat and defect knowledge base to predict the trends of threats and defects. Utilize the trends of threats and combine them with filtering and scanning to improve the protection efficiency of the system. Utilize the trends of defects to actively carry out system self-evolution, change the heterogeneity and dynamics of the system, and process defects in advance to prevent defects from being used for attacks.

[0023] Preferably, based on the results of active threat perception, defect location, and intelligent prediction, defects in the system and its operating environment are addressed to eliminate or reduce the exploitability of the defects and improve the security of the system to an acceptable level;

[0024] Defect handling methods include:

[0025] Defect elimination: replacing defective components in the system and its operating environment with non-defective components that have the same functions;

[0026] Defects are hidden, defective components are frequently initialized or replaced, and the attack chain is frequently cut off in the process.

[0027] The heterogeneous system self-evolution system based on active perception and intelligent prediction provided by the present invention includes:

[0028] Module M1: Dynamically generate heterogeneous system operating environments through virtualization technology;

[0029] Module M2: Assigns a universal unique identifier to each request and tracks and monitors the requests;

[0030] Module M3: Formats and extracts the perceived sensitive information in each heterogeneous system operating environment and conducts consistency judgment;

[0031] Module M4: For heterogeneous system operating environments with defects, locate defects, reproduce attack scenarios, and perform defect resolution.

[0032] Module M5: Based on the attack scenario reproduction, extract corresponding features to build the attack knowledge base and defect knowledge base;

[0033] Module M6: Preemptively detects system component flaws based on subsequent attack requests and sensitive information generated in the system. Dynamically changes the system and its operating environment before the attack chain is complete, eliminating or concealing flaws in advance.

[0034] Module M7: For suspected malicious requests, perform robust execution judgment and select a processing result that meets the preset conditions as the request response.

[0035] Preferably, based on the universal unique identifier of the request, the processing process of the request in the heterogeneous system operating environment is retroactively monitored, and multiple sensitive information is identified and collected. The information is formatted and submitted to the consistency arbitration architecture for voting. The threat is perceived and the request is responded to based on the voting results.

[0036] When the consistency decision is normal, the normal request processing result is obtained directly; when the consistency decision is abnormal, it is judged as a suspected malicious request, and the current request, context information, and abnormal sensitive information obtained by the request are saved.

[0037] Preferably, the attack scenario is reproduced multiple times using attack reproduction technology, and the components in the system and its operating environment are heterogeneously replaced through dynamic generation technology of the system and its operating environment. The attack is then reproduced again, and the replaced components are judged based on the attack results to determine whether there are vulnerabilities, thereby accurately locating the defects.

[0038] By comparing the features of the defective component / module with its replacement component / module, the characteristics of the defect can be obtained so that the defect can be handled in a targeted manner.

[0039] Preferably, a corresponding knowledge base is constructed for the proactively perceived threats and located defects, threat and defect characteristics are retained, and the knowledge is normalized and stored;

[0040] Extract the characteristics of unknown threats and defects, and based on the usage of threats and defects, combine the known threat and defect knowledge base to predict the trends of threats and defects. Utilize the trends of threats and combine them with filtering and scanning to improve the protection efficiency of the system. Utilize the trends of defects to actively carry out system self-evolution, change the heterogeneity and dynamics of the system, and process defects in advance to prevent defects from being used for attacks.

[0041] Preferably, based on the results of active threat perception, defect location, and intelligent prediction, defects in the system and its operating environment are addressed to eliminate or reduce the exploitability of the defects and improve the security of the system to an acceptable level;

[0042] Defect handling methods include:

[0043] Defect elimination: replacing defective components in the system and its operating environment with non-defective components that have the same functions;

[0044] Defects are hidden, defective components are frequently initialized or replaced, and the attack chain is frequently cut off in the process.

[0045] Compared with the prior art, the present invention has the following beneficial effects:

[0046] (1) The present invention builds a dynamic system and its operating environment, takes advantage of the system's dynamic nature, reduces the exposure window of each system defect, cuts off the effective attack chain, and improves the protection of systems with vulnerabilities and other defects;

[0047] (2) The present invention detects unknown attacks by performing heterogeneous consistency judgment on system input and output, and ensures information and system security through system self-evolution;

[0048] (3) The present invention accurately locates the system defects used by threats and guides the self-evolution direction of the system, thereby improving the system's defense effect against known and unknown attacks;

[0049] (4) The present invention proactively conducts system self-evolution in advance through intelligent threat prediction, pre-perception of threats and system defect characteristics, eliminates exploitable component defects, and improves the security strength of the system and its operating environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Other features, objects and advantages of the present invention will become more apparent upon reading the detailed description of non-limiting embodiments with reference to the following drawings:

[0051] Figure 1 This is the architecture diagram of the system self-evolution technology solution based on active perception and intelligent prediction;

[0052] Figure 2 A technology roadmap for system self-evolution based on active perception and intelligent prediction. DETAILED DESCRIPTION

[0053] The present invention will be described in detail below with reference to specific embodiments. The following examples will help those skilled in the art to further understand the present invention, but are not intended to limit the present invention in any form. It should be noted that, for those skilled in the art, several changes and improvements can be made without departing from the scope of the present invention. These all fall within the scope of protection of the present invention.

[0054] Example 1:

[0055] like Figure 2The present invention provides a self-evolution method for heterogeneous systems based on active perception and intelligent prediction, including: step S1: dynamically generating a heterogeneous system operating environment through virtualization technology; step S2: assigning a universal unique identification code to each request, and tracking and monitoring the request; step S3: in each heterogeneous system operating environment, formatting and extracting the perceived sensitive information and performing consistency judgment; step S4: for the heterogeneous system operating environment with defects, performing defect location and attack scenario reproduction, and performing defect processing; step S5: based on the attack scenario reproduction, extracting corresponding features to construct an attack knowledge base and a defect knowledge base; step S6: for subsequent attack requests and sensitive information generated in the system, pre-perceiving system component defects, dynamically changing the system and its operating environment before the attack chain is completed, and completing defect elimination or defect hiding in advance; step S7: performing robust execution judgment for suspected malicious requests, and selecting a processing result that meets preset conditions as the request response.

[0056] Based on the universal unique identification code of the request, the processing process of the request in the heterogeneous system operating environment is retroactively monitored, and multiple corresponding sensitive information is identified and collected. This information is formatted and submitted to the consistency adjudication architecture for voting. Based on the voting results, the threat is perceived and the request is responded to. When the consistency adjudication is normal, the normal request processing result is directly obtained. When the consistency adjudication is abnormal, it is judged as a suspected malicious request, and the current request, context information and abnormal sensitive information obtained by the request are saved.

[0057] Use attack reproduction technology to reproduce the attack scenario multiple times, and through dynamic generation technology of the system and its operating environment, perform heterogeneous replacement of components in the system and its operating environment. Then reproduce the attack again. Based on the attack results, determine whether the replaced components have vulnerabilities, so as to accurately locate the defects. By comparing the characteristics of the defective component / module and its replacement component / module, the characteristics of the defect are obtained so that the defect can be handled in a targeted manner.

[0058] Build a corresponding knowledge base for proactively perceived threats and located defects, retain threat and defect characteristics, and normalize and store the knowledge; extract characteristics of unknown threats and defects, and predict threat and defect trends based on threat and defect usage, combined with known threat and defect knowledge bases. Utilize threat trends and combine filtering and scanning to improve the system's protection efficiency; utilize defect trends to proactively evolve the system, change the system's heterogeneity and dynamics, and process defects in advance to prevent them from being exploited by attacks.

[0059] Based on the results of proactive threat perception, defect location, and intelligent prediction, defects in the system and its operating environment are processed to eliminate or reduce the exploitability of the defects, thereby improving the security of the system to an acceptable level. Defect handling methods include: defect elimination, replacing defective components in the system and its operating environment with non-defective ones with the same functionality; defect concealment, frequently initializing or replacing defective components and frequently cutting off the attack chain in the process.

[0060] Example 2:

[0061] Example 2 is a preferred example of Example 1.

[0062] To effectively defend against external attacks and ensure system security, this paper proposes a system self-evolution system based on threat perception and defect location. First, a heterogeneous system operating environment is designed to process system requests. This improves the system's protection capabilities and makes the system self-evolution process more flexible. Subsequently, the threat active perception module, defect location module, intelligent prediction module, and self-evolution module are designed. The main scheme is as follows:

[0063] (1) Heterogeneous system operating environment. This environment includes multiple heterogeneous systems and their operating environments, which are used to process system requests. The heterogeneous system operating environment is dynamically generated using virtualization technologies such as containers. The system's dynamic automatic deployment improves the efficiency of generating the system and its operating environment. The heterogeneity of the system operating environment is increased by building heterogeneous resource pools of different levels and functions for use in generating the heterogeneous system operating environment. In addition, through the dynamic generation technology of the system and its operating environment, some of its components can be quickly replaced, making the system's self-evolution process more flexible and available.

[0064] (2) Threat proactive perception module. A universally unique identifier (UUID) is assigned to each request from the system, enabling the module to retroactively monitor the processing of requests in the heterogeneous system operating environment, identify and collect multiple copies of sensitive information, format this information, and submit it to the consistency adjudication architecture for voting. Based on the voting results, threats are perceived and requests are responded to. Among them, the identification and collection of sensitive information can identify sensitive information and sensitive components within the system to improve the accuracy of sensitive information positioning. The consistency adjudication of multiple copies of sensitive information can use the adjudication architecture to submit different types of information to specific or default adjudication modules for processing, and finally integrate the overall voting results.

[0065] (3) Defect location module. This module uses attack reproduction technology to reproduce the attack scenario multiple times. It also uses dynamic generation technology of the system and its operating environment to perform heterogeneous replacement of components in the system and its operating environment. It then reproduces the attack again and determines whether the replaced component has a vulnerability based on the attack results, thereby accurately locating the defect. In addition, by comparing the characteristics of the defective component / module with its replacement component / module, the characteristics of the defect can be obtained so that the defect can be handled in a targeted manner. To improve the efficiency of defect location, multiple system operating environments can be generated simultaneously for unified processing.

[0066] (4) Intelligent prediction module. This module builds a corresponding knowledge base for proactively perceived threats and located defects, and normalizes and stores the knowledge on the basis of preserving information such as threat and defect characteristics as completely as possible. In addition, this module extracts the characteristics of unknown threats and defects, and predicts the trends of threats and defects based on the use of threats and defects. By using the trends of threats, it can combine filtering and scanning to improve the protection efficiency of the system; by using the trends of defects, it can actively carry out system self-evolution, change the heterogeneity and dynamics of the system, and process defects in advance to prevent defects from being used by attacks. When predicting threats and defects, this module can combine the known threat and defect knowledge base with the knowledge of unknown attacks and defects perceived and located by the system to make more accurate intelligent predictions.

[0067] (5) Self-evolution module. Based on the results of active threat perception, defect location, and intelligent prediction, this module processes defects in the system and its operating environment, eliminates or reduces the exploitability of defects, and improves the security of the system to an acceptable level. This module can use a variety of methods to handle defects. Using the defect elimination method, the defective components in the system and its operating environment are replaced with non-defective components with the same functions, fundamentally eliminating the risks brought by the defects; using the defect hiding method, the defective components are frequently initialized or replaced to reduce the time window for defect exposure, thereby reducing system risks, and frequently cut off the attack chain in the process, making it difficult for the attack to complete, thereby ensuring system security. In addition, in order to improve the system's response speed when the existence of defects is perceived, the module uses the defect tolerance method to perform robust execution judgment on risk requests and respond with highly reliable request processing results.

[0068] In the active threat perception module, sensitive information extraction technology is used to perform consistency checks on multiple messages generated by sensitive components after formatting. The results can be divided into two scenarios: normal consistency checks and abnormal consistency checks.

[0069] (1) Consistency judgment is normal

[0070] Consistent sensitive information adjudication results indicate consistent request processing across different system environments, and this solution will deem the current request normal. Given that the same vulnerability is unlikely to coexist in multiple system components, malicious requests targeting a specific vulnerability will generate inconsistent sensitive information across different system components. The consistent sensitive information generated by the current processing indicates that the current request is non-malicious. The request processing result can be obtained normally.

[0071] (2) Abnormal consistency judgment

[0072] Sensitive information consistency judgment generates an anomaly, indicating that the current request is suspected to be a malicious request. Based on this, this solution realizes threat perception and can preliminarily determine in which heterogeneous system operating environment the vulnerability exploited by the malicious request exists. Furthermore, this solution will save the current request, context information, and the abnormal sensitive information obtained by the request to reproduce the attack scenario. At the same time, based on the defective system operating environment, this solution will use the dynamic generation technology of the operating environment to generate multiple sets of system operating environments with different components in sequence. Combined with the saved context information, the attack scenario can be reproduced in these multiple system operating environments. By further comparing the obtained sensitive information with the abnormal sensitive information, the system component with the defect in the operating environment can be located, thus achieving defect localization.

[0073] After the defect is located, for the defective heterogeneous system operating environment, components that do not have the defect are selected from the heterogeneous resource pool to replace the defective components to eliminate the defect. Alternatively, by frequently and dynamically switching the defective components, the attack chain is cut off in time, making it impossible for the defect to be effectively exploited by the attacker, thus achieving defect hiding.

[0074] Furthermore, based on the recurrence of attack scenarios, the characteristics of malicious requests and sensitive information can be further analyzed and mined to build an attack knowledge base and a defect knowledge base. Based on these two knowledge bases, this solution will use intelligent prediction to proactively detect subsequent attack requests and the sensitive information they generate in the system. This will allow us to predict the system component flaws they intend to exploit, dynamically modify the system and its operating environment before the attack chain is complete, and eliminate or conceal defects in advance.

[0075] Finally, for suspected malicious requests, this solution uses multiple system operating environments in the consistency judgment to achieve defect tolerance, analyze the request processing results, compare them with the processing results obtained in the defective operating environment, and select a reliable processing result as the request response.

[0076] The present invention has the following beneficial effects:

[0077] (1) Active threat perception. The present invention enables the system to actively perceive external attack threats during operation, especially unknown attacks that cannot be perceived by scanning and filtering, so as to trigger defense mechanisms, evolve the system, trace and analyze attacks, etc.

[0078] (2) Defect location. Through this invention, after the system is attacked and perceives the threat, it can reproduce and analyze the attack scenario, discover the system used in the attack and its operating environment vulnerabilities and other defects, and then locate the defects in the runtime system, obtain information such as the defect level and type, so as to eliminate and hide the defects, etc., and ensure system security.

[0079] (3) Intelligent prediction. This invention can build a knowledge base related to external threat information and system defect information. Based on this knowledge, it can perceive the characteristics of threats or system defects, thereby enabling system self-evolution in advance, eliminating defects that can be exploited by attacks, preventing possible attacks, and improving the survivability of the system and its operating environment under harsh attack conditions.

[0080] (4) System self-evolution. Through the implementation of this solution, after the system's threatened defects are located, the system and its operating environment can be self-evolved. By eliminating and hiding defects, external attacks can be defended, thus improving the protection of system security.

[0081] As attached Figure 1 As shown in the figure, the system self-evolution technology solution architecture based on active perception and intelligent prediction consists of a heterogeneous system operating environment and four major modules: threat active perception module, defect location module, intelligent prediction module and self-evolution module.

[0082] The heterogeneous system operating environment includes multiple heterogeneous systems and their operating environments, which are used to process system requests. The active threat perception module is used to retroactively monitor the request processing process, identify and collect multiple sensitive information, format the information and make consistency judgments, perceive threats and respond to requests based on the voting results. The defect location module reproduces the attack scenario multiple times to achieve accurate positioning of defects. The intelligent prediction module builds a knowledge base for threats and defects, normalizes and stores the knowledge. At the same time, the features of unknown threats and defects are extracted and used to predict the trends of threats and defects based on usage. The self-evolution module processes defects in the system and its operating environment based on the results of active threat perception, defect location, and intelligent prediction, including defect elimination, defect hiding, and defect tolerance, to eliminate or reduce the exploitability of defects and improve the security of the system to an acceptable level.

[0083] Those skilled in the art will appreciate that, in addition to implementing the system, device, and various modules provided by the present invention in purely computer-readable program code, it is entirely possible to implement the same program in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, embedded microcontrollers, and the like by logically programming the method steps. Therefore, the system, device, and various modules provided by the present invention can be considered a hardware component, and the modules included therein for implementing various programs can also be considered structures within the hardware component; the modules for implementing various functions can also be considered both software programs for implementing the method and structures within the hardware component.

[0084] The above describes specific embodiments of the present invention. It should be understood that the present invention is not limited to the specific embodiments described above, and those skilled in the art may make various changes or modifications within the scope of the claims, which do not affect the essence of the present invention. The embodiments of this application and the features in the embodiments may be combined with each other in any manner unless there is a conflict.

Claims

1. A self-evolution method for heterogeneous systems based on active perception and intelligent prediction, characterized by: include: Step S1: Dynamically generate a heterogeneous system operating environment through virtualization; Step S2: assign a universal unique identification code to each request and track and monitor the request; Step S3: In each heterogeneous system operating environment, the perceived sensitive information is formatted and extracted and consistency judgment is performed; Step S4: For the heterogeneous system operating environment with defects, locate the defects, reproduce the attack scenarios, and handle the defects; Step S5: Based on the attack scenario reproduction, extract corresponding features to build an attack knowledge base and a defect knowledge base; Step S6: Preemptively detect system component flaws based on subsequent attack requests and sensitive information generated in the system. Dynamically change the system and its operating environment before the attack chain is completed, eliminating or hiding the flaws in advance. Step S7: For suspected malicious requests, perform robust execution judgment and select a processing result that meets the preset conditions as the request response; Based on the request's universal unique identifier, the request's processing in the heterogeneous system operating environment is retroactively monitored, and multiple pieces of sensitive information are identified and collected. This information is formatted and submitted to the consistency arbitration framework for voting. Based on the voting results, threats are detected and responses to requests are responded to. When the consistency decision is normal, the normal request processing result is obtained directly; When the consistency decision is abnormal, it is determined to be a suspected malicious request, and the current request, context information, and abnormal sensitive information obtained by the request are saved; Use attack reproduction methods to reproduce the attack scenario multiple times. Then, through the dynamic generation of the system and its operating environment, perform heterogeneous replacement of components in the system and its operating environment. Then, reproduce the attack again. Based on the attack results, determine whether the replaced components have vulnerabilities, thereby accurately locating the defects. By comparing the features of the defective component / module with its replacement component / module, the characteristics of the defect can be obtained so that the defect can be handled in a targeted manner.

2. The method for self-evolution of heterogeneous systems based on active perception and intelligent prediction according to claim 1 is characterized in that: Build a corresponding knowledge base for proactively perceived threats and located defects, retain threat and defect characteristics, and normalize and store the knowledge; Extract the characteristics of unknown threats and defects, and use the known threat and defect knowledge base based on the use of threats and defects to predict the trend of threats and defects. Utilize the trend of threats and combine it with filtering and scanning to improve the protection efficiency of the system. By taking advantage of defect trends, the system can be actively self-evolved to change the heterogeneity and dynamics of the system, and defects can be processed in advance to prevent them from being exploited by attacks.

3. The method for self-evolution of heterogeneous systems based on active perception and intelligent prediction according to claim 1 is characterized in that: Based on the results of proactive threat perception, defect location, and intelligent prediction, defects in the system and its operating environment are addressed to eliminate or reduce their exploitability, thereby improving system security to an acceptable level. Defect handling methods include: Defect elimination: replacing defective components in the system and its operating environment with non-defective components that have the same functions; Defects are hidden, defective components are frequently initialized or replaced, and the attack chain is frequently cut off in the process.

4. A self-evolutionary system for heterogeneous systems based on active perception and intelligent prediction, characterized by: include: Module M1: Dynamically generate heterogeneous system operating environments through virtualization; Module M2: Assigns a universal unique identifier to each request and tracks and monitors the requests; Module M3: Formats and extracts the perceived sensitive information in each heterogeneous system operating environment and conducts consistency judgment; Module M4: For heterogeneous system operating environments with defects, locate defects, reproduce attack scenarios, and perform defect resolution. Module M5: Based on the attack scenario reproduction, extract corresponding features to build the attack knowledge base and defect knowledge base; Module M6: Preemptively detects system component flaws based on subsequent attack requests and sensitive information generated in the system. Dynamically changes the system and its operating environment before the attack chain is complete, eliminating or concealing flaws in advance. Module M7: Performs robust execution judgment on suspected malicious requests and selects a processing result that meets the preset conditions as the request response; Based on the request's universal unique identifier, the request's processing in the heterogeneous system operating environment is retroactively monitored, and multiple pieces of sensitive information are identified and collected. This information is formatted and submitted to the consistency arbitration framework for voting. Based on the voting results, threats are detected and responses to requests are responded to. When the consistency decision is normal, the normal request processing result is obtained directly; When the consistency decision is abnormal, it is determined to be a suspected malicious request, and the current request, context information, and abnormal sensitive information obtained by the request are saved; Use attack reproduction methods to reproduce the attack scenario multiple times. Then, through the dynamic generation of the system and its operating environment, perform heterogeneous replacement of components in the system and its operating environment. Then, reproduce the attack again. Based on the attack results, determine whether the replaced components have vulnerabilities, thereby accurately locating the defects. By comparing the features of the defective component / module with its replacement component / module, the characteristics of the defect can be obtained so that the defect can be handled in a targeted manner.

5. The heterogeneous system self-evolution system based on active perception and intelligent prediction according to claim 4 is characterized in that: Build a corresponding knowledge base for proactively perceived threats and located defects, retain threat and defect characteristics, and normalize and store the knowledge; Extract the characteristics of unknown threats and defects, and use the known threat and defect knowledge base based on the use of threats and defects to predict the trend of threats and defects. Utilize the trend of threats and combine it with filtering and scanning to improve the protection efficiency of the system. By taking advantage of defect trends, the system can be actively self-evolved to change the heterogeneity and dynamics of the system, and defects can be processed in advance to prevent them from being exploited by attacks.

6. The heterogeneous system self-evolution system based on active perception and intelligent prediction according to claim 4 is characterized in that: Based on the results of proactive threat perception, defect location, and intelligent prediction, defects in the system and its operating environment are addressed to eliminate or reduce their exploitability, thereby improving system security to an acceptable level. Defect handling methods include: Defect elimination: replacing defective components in the system and its operating environment with non-defective components that have the same functions; Defects are hidden, defective components are frequently initialized or replaced, and the attack chain is frequently cut off in the process.

Citation Information

Patent Citations

  • Artificial intelligence-based threat context awareness information security active defense system

    CN108600275A

  • AI-based threat scenario-aware proactive information security defense system

    CN108600275B

  • Efficient mimicry defense system and method

    CN110581852A

  • Attack defense device and method based on mimicry defense, equipment and medium

    CN112615862A

  • Device, method and apparatus for encapsulating heterogeneous function equivalent bodies

    CN106534063A