Method and system for protecting edge virtual machines from stealth DDoS attacks
By scheduling virtual machine resources using fuzzy game theory and reinforcement learning algorithms, the reliability and quality of service issues of computing tasks in edge virtual machine environments under covert DDoS attacks are solved, and optimized resource allocation and defense strategies are realized in unstable environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-24
- Publication Date
- 2026-03-24
AI Technical Summary
Existing technologies are insufficient to effectively guarantee the reliable execution of computing tasks and resource allocation in edge virtual machine environments when facing stealth DDoS attacks, especially when the underlying virtual machine structure is not modified, and cannot guarantee the reliability and quality of service of latency-sensitive offloaded tasks.
The virtual machine is scheduled using fuzzy game theory and reinforcement learning algorithms. The virtual machine state information is evaluated by a fuzzy controller, mapped to a fuzzy space and defuzzified into preemption priority. Reinforcement learning is combined to calculate the action selection probability and optimize resource preemption decision to defend against stealthy DDoS attacks.
In uncertain virtual machine environments, highly robust resource preemption decisions are implemented, ensuring the quality of service for offloading tasks and the reliable execution of computing tasks, thereby improving the defense effect.
Smart Images

Figure CN115842672B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of Internet technology, and more specifically, relates to a method and system for protecting edge virtual machines from stealth DDoS attacks. Background Technology
[0002] Edge computing architecture provides an efficient computing model for distributed computing of tasks. Computational tasks from mobile devices are offloaded to edge nodes via base stations, and edge virtual machines (VMs) provide a processing environment for these tasks by allocating computing resources. However, due to stealth DDoS attackers injecting large amounts of unevenly distributed traffic packets into edge VMs, virtual machine resources in edge nodes are excessively consumed, hindering the reliable execution of offloaded tasks. Therefore, under stealth DDoS attacks, the execution environment of computing tasks becomes uncertain, posing a severe challenge to resource allocation for computationally intensive tasks. First, the uncertainty of stealth DDoS attacks in the offloaded task execution environment makes it difficult for resource optimizers to estimate the amount of virtual resources to be allocated, thus reducing the reliability of their resource preemption decisions. Second, under stealth DDoS attacks, the convergence and stability of virtual resource preemption algorithms are compromised. Under stealth DDoS attacks, to ensure the quality of service for offloaded tasks executed on VMs, edge VMs need to provide resource-efficient scheduling services. Scheduling VMs can reduce task execution time. Especially when the distributed unloading tasks are unevenly distributed across virtual machines, a key challenge is determining the appropriate number of virtual machine service nodes. At the same time, how to allocate virtual resource capacity to maximize the utility of edge nodes under the uncertain execution state of virtual machines.
[0003] To address the challenge of ensuring service quality when edge virtual machines are subjected to DDoS attacks, researchers have proposed several methods for detecting and defending against DDoS attacks. OAWahab et al., targeting the cunning attack strategies launched by attackers exploiting the elasticity and multi-tenancy attributes of the cloud, established a trust model and, combining subjective and objective trust sources, proposed a game theory-based algorithm for maximizing DDoS attack detection. This optimizes the distributed strategy for DDoS attack detection. However, this method does not consider the uncertainty in task execution offloading within the virtual machine environment caused by stealth DDoS attacks ("Optimal load distribution for the detection of VM-based DDoS attacks in the cloud," in IEEE Transactions on Services Computing, vol. 13, no. 1, pp. 114-129, 1 Jan.-Feb. 2020). Because multiple virtual machines share underlying virtual resources, virtual networks are vulnerable to cross-virtual machine attacks. Malicious virtual machines redirect network traffic to specific destinations. To address this type of attack, A. Saeed et al. designed corresponding attack scenarios and countermeasures. However, the drawback of this method is that it requires modification of the underlying virtual machine structure, which makes virtual machine deployment prone to failure. In addition, this method does not provide a corresponding solution for the degradation of the quality of service of offload task execution caused by stealth DDoS attacks (“A secure VMallocation strategy based on tenant behavior analysis and anomalyidentification,” in 2021 IEEE Military Communications Conference (MILCOM), 2021, pp. 721-726). C. Yang et al. proposed a dynamic VM migration method to address the problem of cross-VM side-channel attacks. This method is based on approximate integer programming and genetic algorithm to optimize the migration strategy, which overcomes the problem of VM deployment failure caused by directly modifying the VM structure. However, it does not consider VM priority selection methods to reduce the failure rate of service migration (“An effective and scalable VM migration strategy to mitigate cross-VM side-channel attacks in cloud,” in China Communications, vol.16, no.4, pp.151-171, April 2019).Y. Zhou et al. proposed a proactive defense technique based on moving targets for DDoS attacks in the Industrial Internet of Things (IIoT). This technique isolates attackers from the edge cloud by dynamically controlling device admission and replica migration. However, this method does not consider the uncertainty of offloading task execution in the virtual machine environment caused by stealth DDoS attacks (“Toward proactive and efficient DDoS mitigation in IIoT systems: A moving target defense approach,” in IEEE Transactions on Industrial Informatics, vol.18, no.4, pp.2734-2744, April 2022).
[0004] These research proposals also have the following shortcomings:
[0005] (1) The proposed solutions have given little consideration to the uncertainty of offloading task execution in edge virtual machine environments caused by covert DDoS attacks, and only consider edge task migration decisions. Under covert DDoS attacks, they cannot ensure the reliability of latency-sensitive offloading task execution in virtual machines. Therefore, the proposed solutions have limitations in the application of latency-sensitive edge computing task offloading and execution, and no corresponding protection methods have been proposed for virtual machine environments under covert DDoS attacks.
[0006] (2) The proposed solutions share virtual resources by modifying the underlying structure of virtual machines, but this causes incompatibility between platforms when deploying virtual machines. They do not consider how to defend against stealth DDoS attacks by optimizing virtual machine service priority and elastic resource preemption at the upper layer without modifying the existing system.
[0007] (3) Although the proposed solutions have put forward some methods for proactively defending against DDoS attacks, when the defenders cannot exchange defense deployment decision information, the proactive defense methods cannot achieve good defense results. In this case, the existing research solutions do not provide corresponding resource preemption decision methods. Summary of the Invention
[0008] To address the shortcomings of the above methods, this invention proposes a method and system for protecting edge virtual machines from stealth DDoS attacks based on fuzzy game theory and reinforcement learning algorithms to schedule virtual machines and preempt resources, thus ensuring the quality of service for end-edge collaborative offloading.
[0009] To achieve the above objectives, according to one aspect of the present invention, a method for protecting edge virtual machines from stealth DDoS attacks is provided, comprising the following steps:
[0010] (1) For the set of edge nodes Each edge node Its attack surface controller, deployed on the network security control node, collects the set of virtual machines that are candidates for offloading its running tasks. The status information of each virtual machine, χ t The number of virtual machines that can be unloaded for task slot t;
[0011] (2) The attack surface controller uses a fuzzy controller to map the state information of each task unloading candidate virtual machine of the edge node e obtained in step (1) to the fuzzy space, evaluate its preemption priority, and defuzzify it into virtual machine weight W. vm And evaluate the fuzzy utility of the virtual machine candidate for each task unloading;
[0012] (3) Based on the set of virtual machines that can be unloaded from the edge node e task obtained in step (2). Fuzzy utility of virtual machines as candidates for unloading tasks Obtain the preemption priority vector w of edge node e by arranging them in order of minimization. k ;
[0013] (4) Based on the preemption priority vector w of the edge node e obtained in step (3) k As the virtual machine state observed by the attack surface controller, reinforcement learning is used to calculate the action selection probability h for virtual machine i. i (a i |o i Based on the action with the highest probability, a i =(v w,i ,c w,i This causes the unloading task to preempt virtual machine resource capacity; where v w,i This indicates that the virtual machine i, c with the highest preemption priority is selected. w,i This indicates that the virtual resource capacity of virtual machine i is being preempted.
[0014] Preferably, in the method for protecting edge virtual machines from stealth DDoS attacks, the status information in step (1) includes CPU resources, storage resources, and bandwidth resources, preferably normalized CPU resources, storage resources, and bandwidth resources.
[0015] Preferably, the method for protecting edge virtual machines from stealth DDoS attacks involves collecting the status information of all virtual machines that are candidate for task offloading, and obtaining CPU resource vectors for each. Storage resource vector and bandwidth resource vector CPU resources for virtual machine i For the storage resources of virtual machine i, The bandwidth resources of virtual machine i;
[0016] Normalized CPU resources Calculate using the following method:
[0017]
[0018] Normalized CPU resources and storage resources Calculate using the following method:
[0019]
[0020] Normalized bandwidth resource value Calculate using the following method:
[0021]
[0022] Preferably, in the method for protecting edge virtual machines from stealth DDoS attacks, the fuzzy controller in step (2) is a multi-input single-output fuzzy controller, wherein each input is one of the status information of virtual machines that are candidates for task unloading, including CPU resources, storage resources, and bandwidth resources.
[0023] Preferably, in the method for protecting edge virtual machines from stealth DDoS attacks, the input fuzzy set of the fuzzy controller is specifically:
[0024] A fuzzy set of CPU resource states: low CPU resource state, medium CPU resource state, and high CPU resource state;
[0025] Fuzzy set of storage resource status: low storage resource status, medium storage resource status, high storage resource status;
[0026] The fuzzy set of bandwidth resource status includes: low bandwidth resource status, medium bandwidth resource status, and bandwidth resource status.
[0027] The output fuzzy set of the fuzzy controller is specifically: very low virtual machine preemption priority, low virtual machine preemption priority, low-medium virtual machine preemption priority, high-medium virtual machine preemption priority, high virtual machine preemption priority, and very high virtual machine preemption priority.
[0028] Preferably, in the method for protecting edge virtual machines from stealth DDoS attacks, the membership function of the fuzzy controller adopts a triangular membership function.
[0029] The fuzzy controller uses a membership function to map the state information of the virtual machines that are candidate virtual machines for task unloading into the fuzzy space to obtain the output fuzziness.
[0030] The fuzzy controller uses a membership function to defuzzify the output fuzziness into virtual machine i weights.
[0031] Preferably, in the method for protecting edge virtual machines from stealth DDoS attacks, virtual machine i employs a method that... Fuzzy effect of fuzzy controller for fuzzy numbers Calculate using the following method:
[0032]
[0033] in, For virtual machine i; The quality of service for virtual machine i is calculated as follows:
[0034]
[0035] Where ω e Let ω be the state of edge node e, which is a Bernoulli random variable. e If ∈{0,1}, and edge node e is active, then ω e =1, otherwise ω e =0; n para The number of tasks to be executed in parallel; Let be the execution rate of the task in virtual machine i on edge node e. is the attack factor for virtual machine i on edge node e, used to characterize its status under covert DDoS attacks; where:
[0036] Calculate using the following method:
[0037]
[0038] in, The resource allocation and consumption ratio for virtual machine i is calculated as follows:
[0039]
[0040] in, The resource capacity of virtual machine i under attack. To Incomplete estimates This is a bounded estimation error; The extent to which virtual machine i suffers a stealth DDoS attack is expressed as follows: Where ω e The state of edge node e, σ represents the loss of virtual resources for virtual machine i; σ is a positive constant.
[0041] Preferably, the method for protecting edge virtual machines from stealth DDoS attacks stipulates that, for each edge virtual machine, if the virtual resource loss caused by the stealth DDoS attacker is greater than the virtual resources preempted by the attack surface controller... The probability of the value being greater than a given threshold ε is defined as AF, and the AF value is expressed as follows:
[0042]
[0043] Where Pr{} is the probability function, These are virtual resources for virtual machines.
[0044] Preferably, the method for protecting edge virtual machines from stealth DDoS attacks minimizes the loss of virtual resources for any virtual machine. x∈{z,o}, where z represents the type of the edge node as a master node and o represents the type of the edge node as a slave node, calculated as follows:
[0045]
[0046] in, To represent the Rician factor, which characterizes the intensity of attacks on virtual machines, the loss of virtual resources follows a Rician distribution. The normalized constant represents the virtual resource loss caused to the virtual machine by a stealthy DDoS attacker, which is obtained by the resource monitoring system through observation. The loss of virtual resources on the parallel execution path of the task is an estimated variable that follows a standard normal distribution and is obtained from the standard normal distribution function.
[0047] Preferably, in the method for protecting edge virtual machines from stealth DDoS attacks, step (4) uses Q-learning to perform reinforcement learning to calculate the action selection probability h. i (a i |o i );
[0048] The reinforcement learning specifically refers to:
[0049] The reinforcement learning state space S is: the state space of the virtual machine environment under covert DDoS attack, S = (s ac ,s nac ) where s ac Indicates the active running status of the virtual machine, s nac This indicates that the virtual machine is inactive. t ∈S, which represents the state of time slot t;
[0050] The attack surface controller's observation space of the virtual machine. δe The number of edge nodes, o e w is the preemption priority vector for edge node e. k ;
[0051] Action Space This is the set of actions for time slot t, where each action represents the virtual machine resource capacity preempted by the defender, and the number of actions equals the number of virtual machines. The action taken against virtual machine i in the current time slot t is: a t =a i =(v w,i ,c w,i ), where v w,i This indicates that the virtual machine i, c with the highest preemption priority is selected. w,i This indicates the preemption of virtual resource capacity for virtual machine i. In each time slot, the attack surface controller uses probability h. i (a i |o i Choose one action, and
[0052] The single-step instant reward r in time slot t t For when the defender is in the current state s t Using probability h i (a i |o i Take action t At that time, the reward is the sum of the resource service quality of all virtual machines, that is:
[0053]
[0054]
[0055] The constraints are: (a) there is minimum resource utilization efficiency to maintain QoS requirements; and / or
[0056] (b) Indicate that the maximum number of virtual machines preempted does not exceed the virtual machine summary; and / or
[0057] (c) The defender cannot seize more virtual resources than their maximum value.
[0058] According to another aspect of the present invention, a protection system for edge virtual machines against stealth DDoS attacks is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the protection method for edge virtual machines against stealth DDoS attacks provided by the present invention.
[0059] In summary, compared with the prior art, the above-described technical solutions conceived by this invention can achieve the following beneficial effects:
[0060] The contents of this invention are as follows:
[0061] (1) In order to resist the fuzzy attack on edge virtual machines by stealth DDoS attackers, considering the uncertainty of the edge virtual machine environment, fuzzy numbers are introduced to quantify the state of virtual resources. The uncertain information of the virtual resource consumption of the stealth attackers is represented as fuzzy numbers, a fuzzy game model is established, and fuzzy logic is used to analyze and process it.
[0062] (2) In a dynamic virtual machine environment subject to stealth DDoS attacks, the uncertain game utility obtained in the observation space cannot be directly used for the preemption decision of virtual machine resources. This invention obtains the virtual machine scheduling priority through fuzzy reasoning, and then makes the preemption decision of virtual machine resources, thus proposing a fuzzy learning algorithm with high robustness.
[0063] (3) In fuzzy games, when the defender cannot obtain its game utility by interacting with the stealthy DDoS attacker, the defender cannot optimize its defense strategy. To address this problem, this invention proposes an enhanced fuzzy game framework. In this framework, the defender obtains its optimal defense strategy by actively interacting with the edge virtual machine environment of the task offloading execution, thereby obtaining the optimal resource allocation strategy in an unstable game environment and ensuring the service quality of the virtual machine environment of the offloading task execution. Attached Figure Description
[0064] Figure 1 This is a schematic diagram of the steps of the protection method for edge virtual machines against stealth DDoS attacks provided by the present invention;
[0065] Figure 2 This is the membership function of the virtual machine CPU resources used in this embodiment of the invention;
[0066] Figure 3 This is the membership function of the virtual machine storage resource used in this embodiment of the invention;
[0067] Figure 4 This is the membership function of virtual machine bandwidth resources used in this embodiment of the invention;
[0068] Figure 5 This is the membership function of the virtual machine weights used in this embodiment of the invention;
[0069] Figure 6 This is a schematic diagram of the enhanced fuzzy game framework provided in an embodiment of the present invention. Detailed Implementation
[0070] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. Furthermore, the technical features involved in the various embodiments of this invention described below can be combined with each other as long as they do not conflict with each other.
[0071] The method for protecting edge virtual machines from stealth DDoS attacks provided by this invention performs the following steps in time slot t:
[0072] (1) For the set of edge nodes Each edge node Its attack surface controller, deployed on the network security control node, collects the set of virtual machines that are candidates for offloading its running tasks. The status information of each virtual machine, χ t The number of virtual machines that can be unloaded for task slot t;
[0073] The status information includes CPU resources, storage resources, and bandwidth resources, preferably normalized CPU resources, storage resources, and bandwidth resources;
[0074] The process involves collecting the state information of all virtual machines that are candidate for task unloading, and obtaining CPU resource vectors for each. Storage resource vector and bandwidth resource vector CPU resources for virtual machine i For the storage resources of virtual machine i, The bandwidth resources of virtual machine i;
[0075] Normalized CPU resources Calculate using the following method:
[0076]
[0077] Normalized CPU resources and storage resources Calculate using the following method:
[0078]
[0079] Normalized bandwidth resource value Calculate using the following method:
[0080]
[0081] (2) The attack surface controller uses a fuzzy controller to map the state information of each task unloading candidate virtual machine of the edge node e obtained in step (1) to the fuzzy space, evaluate its preemption priority, and defuzzify it into virtual machine weight W. vm And evaluate the fuzzy utility of the virtual machine candidate for each task unloading;
[0082] The fuzzy controller is a multi-input single-output fuzzy controller, wherein each input is one of the state information of the virtual machine that is a candidate for task unloading, including CPU resources, storage resources, and bandwidth resources.
[0083] The input fuzzy set of the fuzzy controller is specifically as follows:
[0084] A fuzzy set of CPU resource states: low CPU resource state, medium CPU resource state, and high CPU resource state;
[0085] Fuzzy set of storage resource status: low storage resource status, medium storage resource status, high storage resource status;
[0086] The fuzzy set of bandwidth resource status includes: low bandwidth resource status, medium bandwidth resource status, and bandwidth resource status.
[0087] The output fuzzy set of the fuzzy controller is specifically: very low virtual machine preemption priority, low virtual machine preemption priority, low-medium virtual machine preemption priority, high-medium virtual machine preemption priority, high virtual machine preemption priority, and very high virtual machine preemption priority.
[0088] The membership function of the fuzzy controller adopts the triangular membership function;
[0089] The fuzzy controller uses a membership function to map the state information of the virtual machines that are candidate for task unloading to the fuzzy space to obtain the output fuzziness. Its fuzzy rules are formulated based on experience.
[0090] The fuzzy controller uses a membership function to defuzzify the output fuzziness into virtual machine i weights.
[0091] Virtual machine i adopts Fuzzy effect of fuzzy controller for fuzzy numbers Calculate using the following method:
[0092]
[0093] in, For virtual machine i; The quality of service for virtual machine i is calculated as follows:
[0094]
[0095] Where ω e Let ω be the state of edge node e, which is a Bernoulli random variable. e If ∈{0,1}, and edge node e is active, then ω e =1, otherwise ω e =0; n para The number of tasks to be executed in parallel; Let be the execution rate of the task in virtual machine i on edge node e. is the attack factor for virtual machine i on edge node e, used to characterize its status under covert DDoS attacks; where:
[0096] Calculate using the following method:
[0097]
[0098] in, The resource allocation and consumption ratio for virtual machine i is calculated as follows:
[0099]
[0100] in, The resource capacity of virtual machine i under attack. To Incomplete estimates This is a bounded estimation error; The extent to which virtual machine i suffers a stealth DDoS attack is expressed as follows: Where ω e The state of edge node e, σ represents the loss of virtual resources for virtual machine i; σ is a positive constant.
[0101] For each edge virtual machine, if the virtual resource loss caused by a stealthy DDoS attacker exceeds the virtual resources preempted by the attack surface controller... The probability of the value being greater than a given threshold ε is defined as AF, and the AF value is expressed as follows:
[0102]
[0103] Where Pr{} is the probability function, These are virtual resources for virtual machines.
[0104] Loss of virtual resources for any virtual machine x∈{z,o}, where z represents the type of the edge node as a master node and o represents the type of the edge node as a slave node, calculated as follows:
[0105]
[0106] in, To represent the Rician factor, which characterizes the intensity of attacks on virtual machines, the loss of virtual resources follows a Rician distribution. The normalized constant represents the virtual resource loss caused to the virtual machine by a stealthy DDoS attacker, which is obtained by the resource monitoring system through observation. The loss of virtual resources on the parallel execution path of the task is an estimated variable that follows a standard normal distribution and is obtained from the standard normal distribution function.
[0107] (3) Based on the set of virtual machines that can be unloaded from the edge node e task obtained in step (2). Fuzzy utility of virtual machines as candidates for unloading tasks Obtain the preemption priority vector w of edge node e by arranging them in order of minimization. k ;
[0108] (4) Based on the preemption priority vector w of the edge node e obtained in step (3) k As the virtual machine state observed by the attack surface controller, reinforcement learning is used to calculate the action selection probability h for virtual machine i. i (a i |o i Based on the action with the highest probability, a i =(v w,i ,c w,i This causes the unloading task to preempt virtual machine resource capacity; where v w,i This indicates that the virtual machine i, c with the highest preemption priority is selected. w,i This indicates the preemption of virtual resource capacity in virtual machine i; the preferred solution uses Q-learning to perform reinforcement learning to calculate the action selection probability h. i (a i |o i );
[0109] The reinforcement learning specifically refers to:
[0110] The reinforcement learning state space S is: the state space of the virtual machine environment under covert DDoS attack, S = (s ac ,s nac ) where s ac Indicates the active running status of the virtual machine, s nac This indicates that the virtual machine is inactive. t ∈S, which represents the state of time slot t;
[0111] The attack surface controller's observation space of the virtual machine. δe The number of edge nodes, o e w is the preemption priority vector for edge node e. k
[0112] Action Space This is the set of actions for time slot t, where each action represents the virtual machine resource capacity preempted by the defender, and the number of actions equals the number of virtual machines. The action taken against virtual machine i in the current time slot t is: a t =a i =(v w,i ,c w,i ), where v w,i This indicates that the virtual machine i, c with the highest preemption priority is selected. w,i This indicates the preemption of virtual resource capacity for virtual machine i. In each time slot, the attack surface controller uses probability h. i (a i |o i Choose one action, and
[0113] The single-step instant reward r in time slot t t For when the defender is in the current state s t Using probability h i (a i |o i Take action t At that time, the reward is the sum of the resource service quality of all virtual machines, that is:
[0114]
[0115]
[0116] The constraints are: (a) there is minimum resource utilization efficiency to maintain QoS requirements; and / or
[0117] (b) Indicate that the maximum number of virtual machines preempted does not exceed the virtual machine summary; and / or
[0118] (c) The defender cannot seize more virtual resources than their maximum value.
[0119] The following is an example:
[0120] The method for protecting edge virtual machines from stealth DDoS attacks provided in this embodiment is applied to an edge virtual machine service network. In this network, edge virtual machines run on edge nodes and undertake the parallel execution of offloaded tasks. Under a stealth DDoS attack, the edge virtual machines operate in an uncertain state, causing the state of the edge nodes to change dynamically, resulting in a set of edge nodes... The state of each edge node can be represented as: Where ωe ω ∈{0,1} is a Bernoulli random variable representing the state of edge node e. For example, in the current time slot, if edge node e is in an active state, then ω e =1, otherwise ω e =0. v e ∈{0,1} indicates whether an edge node is a master node. If edge node e is a master node, then v e =1, otherwise e is a secondary node, and v e =0. This represents the virtual resource capacity of edge node e, and
[0121] Attack surface controllers are deployed on network security control nodes. Since the virtual resources of edge nodes are dynamically configurable, the attack surface controllers deployed on edge nodes act as defenders, dynamically configuring the internal virtual resources of the edge nodes to defend against stealth DDoS attacks. The attack surface controller, acting as a defender, can schedule multiple edge nodes, and its overall utility is:
[0122] In a stealth DDoS attack, the attack surface controller of the stealth DDoS attacker and the defender compete for resources on the edge virtual machines. The attacker's goal is to consume these resources by sending a large number of ineffective offloading tasks, while the defender's goal is to preempt and allocate more virtual resources to complete the parallel computing tasks of offloading. The Attack Factor (AF) is used to characterize the stealth DDoS attack posture. Due to the constraints of energy, computing power, and storage resources for both the attacker and defender, a definition is... and Virtual resources representing virtual machines Virtual resources contested with attack surface controllers The maximum value.
[0123] The attack surface controller optimizes defense effectiveness by preempting and allocating resources. Based on the above analysis, when offloaded tasks are executed in parallel, the problem of edge virtual resource preemption under covert DDoS attacks is formalized as follows:
[0124] P1:maxU(f),
[0125] st(a)Φ e (f e )≥Φ th ,
[0126]
[0127]
[0128] Constraint (a) guarantees minimum resource utilization efficiency to maintain QoS requirements, Φ th The constraint (a) represents the resource utilization efficiency threshold; constraint (b) indicates the maximum number of virtual machines that can be preempted; constraint (c) ensures that the virtual resources preempted by the defender cannot exceed its maximum value. Since P1 is an NP-hard problem, solving it faces even greater challenges when considering stealth DDoS attacks. To address this challenge, this invention designs a reliable virtual resource preemption mechanism to mitigate the impact of stealth DDoS attacks on the parallel execution of offload tasks, thereby improving the service quality of offload task execution in an uncertain execution environment.
[0129] This invention utilizes fuzzy game theory to solve the aforementioned problems and designs a reliable virtual resource preemption mechanism based on fuzzy game theory. This mechanism considers uncertain resource preemption defense strategies under multiple constraints and models the P1 problem as a non-cooperative fuzzy game to optimize the resource preemption strategy.
[0130] Definition 1: A non-cooperative game is represented as: G = (N, J) i J k ,u i ,u k Let N be the set of game participants, consisting of stealthy DDoS attackers and defenders. N = (N1, N2), where N1 represents the set of stealthy DDoS attackers and N2 represents the set of attack surface controllers. i Let represent the set of preemptive actions by a stealthy DDoS attacker i, where i∈N1, represented by the capacity of the preempted virtual resources. J k Let N(k) represent the set of preemptive actions by defender k, k∈N2, denoted by the capacity of the preempted virtual resources. u i Let u represent the utility of the stealth DDoS attacker i, and u i =-QoS e (f e ), u k Let u represent the utility of defender k, and u represent the utility of defender k. k =QoS e (f e ).
[0131] Definition 2: If the utility of a game strategy action pair satisfies the following condition:
[0132]
[0133]
[0134] Then the action is It is the Nash equilibrium of game G, and and Let i and k represent the optimal actions of the stealthy DDoS attacker and defender, respectively.
[0135] Definition 3: The fuzzy game of uncertain virtual resource preemption is defined as follows:
[0136]
[0137] Based on the above definition, the problem of virtual resource preemption at the edge of a stealthy DDoS attack is reformulated as a fuzzy game. In the game, defender k maximizes its utility by preempting virtual resource capacity, and its optimal resource preemption action is represented as follows:
[0138]
[0139] st:Φ e (f e )≥Φ th .
[0140] Stealth DDoS attackers maximize their obfuscation effectiveness by preempting edge virtual machine resources, which can be represented as follows:
[0141]
[0142] st:Φ e (f e )<Φ th .
[0143] Definition 4: Fuzzy Nash Equilibrium. If the utility of a fuzzy game strategy action pair satisfies the following condition:
[0144]
[0145]
[0146] Then the action is It is a game The Nash equilibrium, and and Let i and k represent the optimal actions of the attacker and defender, respectively.
[0147] Game Theory There exists at least one Nash equilibrium solution, as proven below:
[0148] Due to game theory It is a bi-matrix game involving two types of participants, and its bi-matrix game utility matrix is represented as follows:
[0149]
[0150] Each element in the matrix represents the utility of a stealth DDoS attacker employing an attack and a defender taking defensive actions. If there exists a subset of virtual machines such that the function... and If it is concave, then it is a bi-matrix game. There exists at least one fuzzy Nash equilibrium solution. Because
[0151]
[0152] Therefore, the utility functions of stealth DDoS attackers and defenders are concave. Thus, fuzzy game theory... There exists at least one fuzzy Nash equilibrium solution.
[0153] The protection method for edge virtual machines against stealth DDoS attacks provided in this embodiment, such as... Figure 1 As shown, the following steps are performed in time slot t:
[0154] (1) For the set of edge nodes Each edge node Its attack surface controller, deployed on the network security control node, collects the set of virtual machines that are candidates for offloading its running tasks. The status information of each virtual machine, χ t The number of virtual machines that can be unloaded for task slot t;
[0155] The status information includes CPU resources, storage resources, and bandwidth resources, preferably normalized CPU resources, storage resources, and bandwidth resources;
[0156] The process involves collecting the state information of all virtual machines that are candidate for task unloading, and obtaining CPU resource vectors for each. Storage resource vector and bandwidth resource vector CPU resources for virtual machine i For the storage resources of virtual machine i, The bandwidth resources of virtual machine i;
[0157] Normalized CPU resources Calculate using the following method:
[0158]
[0159] Normalized CPU resources and storage resources Calculate using the following method:
[0160]
[0161] Normalized bandwidth resource value Calculate using the following method:
[0162]
[0163] (2) The attack surface controller uses a fuzzy controller to map the state information of each task unloading candidate virtual machine of the edge node e obtained in step (1) to the fuzzy space, evaluate its preemption priority, and defuzzify it into virtual machine weight W. vm And evaluate the fuzzy utility of the virtual machine candidate for each task unloading;
[0164] The fuzzy controller is a multi-input single-output fuzzy controller, wherein each input is one of the state information of the virtual machine that is a candidate for task unloading, including CPU resources, storage resources, and bandwidth resources.
[0165] The input fuzzy set of the fuzzy controller is specifically as follows:
[0166] A fuzzy set of CPU resource states: low CPU resource state, medium CPU resource state, and high CPU resource state;
[0167] Fuzzy set of storage resource status: low storage resource status, medium storage resource status, high storage resource status;
[0168] The fuzzy set of bandwidth resource status includes: low bandwidth resource status, medium bandwidth resource status, and bandwidth resource status.
[0169] The output fuzzy set of the fuzzy controller is specifically: very low virtual machine preemption priority, low virtual machine preemption priority, low-medium virtual machine preemption priority, high-medium virtual machine preemption priority, high virtual machine preemption priority, and very high virtual machine preemption priority.
[0170] The membership function of the fuzzy controller adopts the triangular membership function;
[0171] The fuzzy controller uses a membership function to map the state information of the virtual machines that are candidate for task unloading to the fuzzy space to obtain the output fuzziness.
[0172] The membership function used in this embodiment is a triangular membership function. The membership function for virtual machine CPU resources is as follows: Figure 2 As shown, the membership function of virtual machine storage resources is as follows: Figure 3 As shown, the membership function of virtual machine bandwidth resources is as follows: Figure 4 As shown.
[0173] The fuzzy rules used in this embodiment of the virtual machine preemption priority fuzzy inference system are as follows: Figure 1 As shown:
[0174] Table 1: Fuzzy Rules for Virtual Machine Preemption Priority Fuzzy Inference System
[0175]
[0176] The fuzzy controller uses a membership function to defuzzify the output fuzziness into virtual machine i weights.
[0177] Virtual machine preemption priority is determined by fuzzy decision-making. The final VM weights are the defuzzified output of the fuzzy controller, and the membership function of the VM weights is as follows: Figure 5 As shown.
[0178] Virtual machine i adopts Fuzzy effect of fuzzy controller for fuzzy numbers Calculate using the following method:
[0179]
[0180] in, For virtual machine i; The quality of service for virtual machine i is calculated as follows:
[0181]
[0182] Where ω e Let ω be the state of edge node e, which is a Bernoulli random variable. e If ∈{0,1}, and edge node e is active, then ω e =1, otherwise ω e =0; n para The number of tasks to be executed in parallel; Let be the execution rate of the task in virtual machine i on edge node e. is the attack factor for virtual machine i on edge node e, used to characterize its status under covert DDoS attacks; where:
[0183] Calculate using the following method:
[0184]
[0185] in, The resource allocation and consumption ratio for virtual machine i is calculated as follows:
[0186]
[0187] in, The resource capacity of virtual machine i under attack. To Incomplete estimates This is a bounded estimation error; The extent to which virtual machine i suffers a stealth DDoS attack is expressed as follows: Where ω e The state of edge node e, σ represents the loss of virtual resources for virtual machine i; σ is a positive constant.
[0188] Fuzzy Number Fuzzy numbers are used to accurately describe the virtual resource capacity of attacked edge virtual machines in the real number space, and Where ε1 and ε3 represent the offset of the virtual resource capacity offset center ε2 of the edge virtual machine, this invention uses a triangular membership function to describe the fuzzy number. as follows:
[0189]
[0190] To address the allocation problem of edge virtual resources under covert DDoS attacks with uncertain virtual resource capacity, this invention maps the changes in virtual resources to a fuzzy space and uses triangular fuzzy numbers to describe the uncertain virtual resource capacity. Specifically, the virtual resource capacity under covert DDoS attacks is obtained using membership functions, thus yielding the fuzzy utility of attacker i and defender k as follows:
[0191]
[0192]
[0193] in, This represents the fuzzy virtual resource capacity of the edge virtual machine mapped in edge node e.
[0194] For each edge virtual machine, if the virtual resource loss caused by a stealthy DDoS attacker exceeds the virtual resources preempted by the attack surface controller... The probability of the value being greater than a given threshold ε is defined as AF, and the AF value is expressed as follows:
[0195]
[0196] Where Pr{} is the probability function, These are virtual resources for virtual machines.
[0197] Loss of virtual resources for any virtual machine x∈{z,o}, where z represents the type of the edge node as a master node and o represents the type of the edge node as a slave node, calculated as follows:
[0198]
[0199] in, To represent the Rician factor, which characterizes the intensity of attacks on virtual machines, the loss of virtual resources follows a Rician distribution. The normalized constant represents the virtual resource loss caused to the virtual machine by a stealthy DDoS attacker, which is obtained by the resource monitoring system through observation. The loss of virtual resources on the parallel execution path of the task is an estimated variable that follows a standard normal distribution and is obtained from the standard normal distribution function.
[0200] Generally, the resource capacity of an attacked virtual machine is lost due to the path loss caused by the parallel execution of unloading tasks in a virtual service environment. and virtual machine resource capacity loss The product of these factors determines the resource capacity of the attacked virtual machine. Therefore, the resource capacity of the attacked virtual machine is:
[0201]
[0202] in, κ indicates that the coefficient is a constant. ρ represents the attack surface size, calculated as the ratio of the number of unattacked virtual machines to the total number of virtual machines; the larger ρ is, the smaller the attack surface. para This represents the number of tasks executed in parallel. If ρ > 0.5, then the path loss for unloading tasks and executing them in parallel is proportional to n. para Strictly decreasing, then strictly increasing if ρ < 0.5. Since stealth DDoS attackers launch targeted, persistent attacks on the target virtual machine, virtual resource losses typically follow a Rician distribution. For ease of calculation, the loss of virtual resources is uniformly represented as... x∈{z,o}, and
[0203] If the virtual resource loss caused by a stealthy DDoS attacker is greater than the virtual resource seized by the defender... Furthermore, when the threshold ε is greater than a given value, the parallel execution performance of offloading tasks in the edge virtual machine is severely impaired. The degree to which the edge virtual machine m in edge node e suffers from a stealth DDoS attack is represented as follows:
[0204]
[0205] On edge node e, the set of available allocated virtual machines is: Where δ e This indicates the number of virtual machines allocated. This represents the set of virtual machines that offload and execute tasks. When multiple stealth DDoS attackers attack multiple edge virtual machines, the attack surface controller in the edge node schedules virtual machines to help migrate tasks and preempts resources to ensure the execution of offloaded tasks. This coordinates the computational load among the attacked virtual machines, enabling edge node e to achieve the following resource utilization efficiency:
[0206]
[0207] In a mesh network structure where edge virtual machines execute offloading tasks in parallel, the computational performance of edge nodes depends not only on resource utilization efficiency but also on the number of tasks executed in parallel. Therefore, another metric is introduced: the resource service quality of edge virtual machines during task parallel execution. This metric characterizes the efficiency of multiple edge virtual machines executing offloading tasks in parallel. Consequently, the previously defined AF (Automatic Resource Service) is also considered to measure the reliability of parallel task execution under covert DDoS attacks. The resource service quality of edge virtual machines during task parallel execution is expressed as follows:
[0208]
[0209] (3) Based on the set of virtual machines that can be unloaded from the edge node e task obtained in step (2). Fuzzy utility of virtual machines as candidates for unloading tasks Obtain the preemption priority vector w of edge node e by arranging them in order of minimization. k ;
[0210] The virtual machine preemption priority update process based on fuzzy reasoning, namely steps (2) and (3), can be implemented using the following algorithm:
[0211] Algorithm 1
[0212] Input: The overall fuzzy utility of defender k for virtual machine i
[0213] Initialization: Virtual machine preemption priority vector w k
[0214] Step 1: Observe the CPU resources, storage resources, and bandwidth resources of each virtual machine and normalize them to the (0,1) interval.
[0215] Step 2: Calculate the membership degree of each virtual machine state using the triangular fuzzy function:
[0216] Step 3: Construct virtual machine preemption priority fuzzy inference system rules based on experience.
[0217] Step 4: Perform fuzzy inference to obtain virtual machine weights and calculate the overall fuzzy utility of defender k.
[0218] Step 5: Compare the utility of candidate virtual machines
[0219] Step 6: Based on the comparison results of Step 5, the virtual machine number with the higher fuzzy utility is entered into the preemption priority vector. If the number of virtual machines in the preemption priority vector is less than χ... t If so, proceed to step 4 to continue execution.
[0220] Output: A stable virtual machine preemption priority vector w k .
[0221] (4) Based on the preemption priority vector w of the edge node e obtained in step (3) k As the virtual machine state observed by the attack surface controller, reinforcement learning is used to calculate the action selection probability h for virtual machine i. i (a i |o i Based on the action with the highest probability, a i =(v w,i ,c w,i This causes the unloading task to preempt virtual machine resource capacity; where v w,i This indicates that the virtual machine i, c with the highest preemption priority is selected. w,i This indicates the preemption of virtual resource capacity in virtual machine i; the preferred solution uses Q-learning to perform reinforcement learning to calculate the action selection probability h. i (a i |o i );
[0222] The reinforcement learning specifically refers to:
[0223] The reinforcement learning state space S is: the state space of the virtual machine environment under covert DDoS attack, S = (s ac ,s nac ) where s ac Indicates the active running status of the virtual machine, s nac This indicates that the virtual machine is inactive. t ∈S, which represents the state of time slot t;
[0224] The attack surface controller's observation space of the virtual machine. δ e The number of edge nodes, o e w is the preemption priority vector for edge node e. k
[0225] Action Space This is the set of actions for time slot t, where each action represents the virtual machine resource capacity preempted by the defender, and the number of actions equals the number of virtual machines. The action taken against virtual machine i in the current time slot t is: a t =a i=(v w,i ,c w,i ), where v w,i This indicates that the virtual machine i, c with the highest preemption priority is selected. w,i This indicates the preemption of virtual resource capacity for virtual machine i. In each time slot, the attack surface controller uses probability h. i (a i |o i Choose one action, and
[0226] The single-step instant reward r in time slot t t For when the defender is in the current state s t Using probability h i (a i |o i Take action t At that time, the reward is the sum of the resource service quality of all virtual machines, that is:
[0227]
[0228]
[0229] The constraints are: (a) there is minimum resource utilization efficiency to maintain QoS requirements; and / or
[0230] (b) Indicate that the maximum number of virtual machines preempted does not exceed the virtual machine summary; and / or
[0231] (c) The defender cannot seize more virtual resources than their maximum value.
[0232] (1) To address the fuzzy game defense problem in uncertain virtual machine execution environments caused by stealth DDoS attacks, this invention further extends fuzzy game theory to an enhanced fuzzy game process. By enhancing the fuzzy game, defenders are allowed to optimize virtual machine resource preemption strategies while interacting with the virtual machine environment in edge nodes, thereby obtaining the optimal virtual machine resource preemption strategy to resist stealth DDoS attacks. All attack surface controllers act as defenders, executing virtual resource preemption actions in a distributed manner. The goal of the attack surface controllers is to maximize their own utility. The enhanced fuzzy game theory for optimizing virtual machine resource preemption strategies is defined as follows: S represents the state space of the virtual machine environment under covert DDoS attack. This represents the attack surface controller's observation space and action space over the virtual machine. It is the set of actions in time slot t, where each action represents the virtual machine resource capacity preempted by the defender. The number of actions equals the number of virtual machines, and r = r t Let P represent a single-step instantaneous reward in time slot t, and let P represent the current state s in the edge virtual machine environment. tThe action taken is a t At that time, the edge virtual machine environment changes from its current state s t Pass to the next state s t+1 The transmission probability.
[0233] P represents the current state s in the edge virtual machine environment. t The action taken is a t At that time, the edge virtual machine environment changes from its current state s t Pass to the next state s t+1 The transmission probability.
[0234] In each time slot t, the defender's goal is to use probability h i (a i |o i Take action t The goal is to maximize the reward in the current state. In this reinforced fuzzy game algorithm, the defender's primary objective is to discover an optimal strategy. And maximize the total reward of the system. Value function V π :S→r gives the defender from state s t A total reward starting at ∈S, and the value function quantifies the policy π, where the discount factor is γ, the total discounted reward is expressed as follows:
[0235]
[0236] Let Ω be the available policy space, and then optimize the policy representation as follows:
[0237]
[0238] This invention uses the Q function to approximate V. π (s t Therefore, we can conclude that:
[0239]
[0240] During Q-learning, the defender observes the current state s. t Then use probability h i (a i |o i Take action t Subsequently, the defender received a reward r t (s t ,a t And reach state s t+1 The Q-function value is updated based on the observed reward, and this process is repeated until the optimized policy π is output. * The update equation for the Q function value is as follows:
[0241]
[0242] Where α is the learning rate.
[0243] An enhanced fuzzy game framework for optimizing virtual resource preemption strategies, such as... Figure 6 As shown.
[0244] Step (4) can be optimized using a virtual resource preemption strategy based on reinforced fuzzy game theory, i.e., Algorithm 2:
[0245] Algorithm 2:
[0246] Input: Set of edge nodes Virtual machine collection Initialization: A set of random preemption actions for virtual resources.
[0247] Step 1: In time slot t, each edge node acquires indeterminate utility across all available virtual machines.
[0248] Step 2: The defender uses a membership function to map the uncertain values of each virtual machine's resource state to a fuzzy space, and obtains the current virtual machine's preemption priority vector w by executing Algorithm 1. k .
[0249] Step 3: Based on w k Calculate the action selection probability max{h i (a i |o i )}, and obtain a size of χ t The set of virtual machines M′.
[0250] Step 4: Select a virtual machine from the virtual machine set M′ and execute a t =(v w,i ,c w,i ), observation reward r t (s t ,a t And pass it to the next state s t+1 .
[0251] Step 5: Update Q t+1 (s t ,a t ).
[0252] Step 6: Calculate QoS e (f e If QoS e (f e Satisfying QoS thresholds Then output the current virtual resource preemption action a. t ,
[0253] Otherwise, proceed to step 4 until QoS is reached. e (f e The condition is satisfied if the virtual machine set M′ is empty.
[0254] Step 7: Calculate U(f). If U(f) satisfies QoS... th If the condition is met, then stop. Otherwise, t = t + 1, and go to step 1.
[0255] Output: Virtual machine resource preemption actions across all edge nodes.
[0256] In traditional game theory frameworks, strategy decisions rely on game payoffs or rewards. However, under covert DDoS attacks, the game system becomes vulnerable and cannot guarantee stable convergence across multiple rounds. Specifically, if the attack surface controller observes uncertain virtual resource capacity, it cannot directly solve fuzzy games to obtain virtual resource preemption strategies. To address this issue, in this invention, under covert DDoS attacks, the attack surface controller first observes the uncertain virtual resource capacity and maps it to a fuzzy space, implementing a learning and updating process. Through fuzzy inference, it obtains virtual machine preemption priority vectors, which represent the priority of virtual machines being occupied. Then, it further optimizes virtual resource preemption strategies for high-priority virtual machines. The main advantage of this invention is that by introducing a fuzzy space mapped by membership functions, it infers virtual machine preemption priorities and obtains the fuzzy utility of preempting virtual resource capacity. Therefore, this framework can combat the uncertainty of the virtual machine environment caused by covert DDoS attacks and ensure the robustness of resource service quality.
[0257] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for protecting edge virtual machines from stealth DDoS attacks, characterized in that, Includes the following steps: (1) For the set of edge nodes Each edge node Its attack surface controller, deployed on the network security control node, collects the set of virtual machines that are candidates for offloading the tasks it runs. The status information of each virtual machine. For time slots The number of virtual machines that can be candidates for task unloading; (2) The attack surface controller adopts a fuzzy controller based on the edge nodes obtained in step (1). The state information of each task unloading candidate virtual machine is mapped to a fuzzy space, its preemption priority is evaluated, and then defuzzified into virtual machine weights. And evaluate the fuzzy utility of the virtual machine candidate for each task unloading; The membership function of the fuzzy controller adopts the triangular membership function; The fuzzy controller uses a membership function to map the state information of the virtual machines that are candidate virtual machines for task unloading into the fuzzy space to obtain the output fuzziness. The fuzzy controller uses a membership function to defuzzify the output fuzziness into a virtual machine. Weight ; virtual machine Adopted The fuzzy effect of a fuzzy controller for fuzzy numbers, and ,in and Represents the virtual resource capacity offset center of the edge virtual machine The offset; Triangular membership function to describe fuzzy numbers as follows: , virtual machine Adopted Fuzzy effect of fuzzy controller for fuzzy numbers Calculate as follows: , in, ; virtual machine The quality of resource services is calculated as follows: , in For edge nodes The state is a Bernoulli random variable. Edge nodes If it is in an active state, then ,otherwise ; The number of tasks to be executed in parallel; Let be the execution rate of the task in virtual machine i on edge node e. For edge nodes virtual machine The attack factor is used to characterize the stealth DDoS attack situation it is subjected to; where: Calculate using the following method: , in, For virtual machines The resource allocation to consumption ratio is calculated as follows: , in, For virtual machines The capacity of the attacked resources , To Incomplete estimates This is a bounded estimation error; For virtual machines The severity of a stealth DDoS attack is expressed as follows: ,in For edge nodes state, For virtual machines The loss of virtual resources; To represent a positive constant; (3) Edge nodes obtained from step (2) Set of virtual machines as candidates for task unloading Fuzzy utility of virtual machines as candidates for unloading tasks Arrange the edge nodes in descending order. Preemption priority vector ; (4) Edge nodes obtained from step (3) Preemption priority vector The virtual machine state, observed by the attack surface controller, is calculated using reinforcement learning. Action choice probability Based on the action with the highest probability This causes the unloading task to preempt virtual machine resource capacity; among which This indicates that the virtual machine with the highest preemption priority will be selected. , This indicates that the virtual machine has been preempted. Virtual resource capacity.
2. The method for protecting edge virtual machines from stealth DDoS attacks as described in claim 1, characterized in that, The status information in step (1) includes CPU resources, storage resources, and bandwidth resources.
3. The method for protecting edge virtual machines from stealth DDoS attacks as described in claim 2, characterized in that, The status information in step (1) includes normalized CPU resources, storage resources, and bandwidth resources.
4. The method for protecting edge virtual machines from stealth DDoS attacks as described in claim 3, characterized in that, The process involves collecting the state information of all virtual machines that are candidate for task unloading, and obtaining CPU resource vectors for each. Storage resource vector and bandwidth resource vector ; For virtual machines CPU resources For virtual machines Storage resources, virtual machine Bandwidth resources; Normalized CPU resources Calculate as follows: , Normalized CPU resources and storage resources Calculate as follows: , Normalized bandwidth resource value Calculate as follows: , The fuzzy controller in step (2) is a multi-input single-output fuzzy controller, wherein each input is one of the status information of the virtual machine of the task unloading candidate, including CPU resources, storage resources, and bandwidth resources.
5. The method for protecting edge virtual machines from stealth DDoS attacks as described in claim 4, characterized in that, The input fuzzy set of the fuzzy controller is specifically as follows: A fuzzy set of CPU resource states: low CPU resource state, medium CPU resource state, and high CPU resource state; Fuzzy set of storage resource status: low storage resource status, medium storage resource status, high storage resource status; A fuzzy set of bandwidth resource statuses: low bandwidth resource status, medium bandwidth resource status, and high bandwidth resource status; The output fuzzy set of the fuzzy controller is specifically: very low virtual machine preemption priority, low virtual machine preemption priority, low-medium virtual machine preemption priority, high-medium virtual machine preemption priority, high virtual machine preemption priority, and very high virtual machine preemption priority.
6. The method for protecting edge virtual machines from stealth DDoS attacks as described in claim 4, characterized in that, For each edge virtual machine, if the virtual resource loss caused by a stealthy DDoS attacker exceeds the virtual resources preempted by the attack surface controller... And greater than a given threshold The probability of AF is defined as follows: , in, To take the probability function, These are virtual resources for virtual machines.
7. The method for protecting edge virtual machines from stealth DDoS attacks as described in claim 4, characterized in that, Loss of virtual resources for any virtual machine , , The edge node indicates that it is a master node. The type of an edge node is a secondary node, calculated as follows: , in, To represent the Rician factor, which characterizes the intensity of attacks on virtual machines, the loss of virtual resources follows a Rician distribution. The normalized constant represents the virtual resource loss caused to the virtual machine by a stealthy DDoS attacker, which is obtained by the resource monitoring system through observation. The loss of virtual resources on the parallel execution path of the task is an estimated variable that follows a standard normal distribution and is obtained from the standard normal distribution function.
8. The method for protecting edge virtual machines from stealth DDoS attacks as described in claim 1, characterized in that, Step (4) uses Q-learning to perform reinforcement learning to calculate the action selection probability. ; The reinforcement learning specifically refers to: Reinforcement learning state space State space of a virtual machine environment under covert DDoS attack. in, This indicates that the virtual machine is running actively. This indicates that the virtual machine is not running actively. , for time slot The state; The attack surface controller's observation space of the virtual machine. , The number of edge nodes, For edge nodes Preemption priority vector ; Action Space It is a time slot The set of actions, where each action represents the virtual machine resource capacity preempted by the defender, and the number of actions equals the number of virtual machines; in the current time slot For virtual machines The actions taken were: ,in This indicates that the virtual machine with the highest preemption priority will be selected. , This indicates that the virtual machine has been preempted. Virtual resource capacity; probability of attack surface controller usage in each time slot. Choose one action, and ; Time slot Single-step instant rewards For when the defender is in the current state Using probability Take action At that time, the reward is the sum of the resource service quality of all virtual machines, that is: , , The constraints are: (a) there is a minimum resource utilization efficiency to maintain QoS requirements; and / or (b) Indicates that the maximum number of virtual machines preempted does not exceed the total number of virtual machines; and / or (c) The virtual resources seized by the defender cannot exceed their maximum value.
9. A protection system for edge virtual machines against stealth DDoS attacks, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the protection method for edge virtual machines against stealth DDoS attacks as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Mobile target defense decision selection method, device and system based on Markov time game
CN110300106A
Privacy removal method and system based on generative artificial intelligence
CN115357941A