A Method and Device for Improving the Security of Cloud-Hosted Web Applications Based on Containers
Through a container-based jump defense mechanism, using Docker to build a MongoDB database cluster and combined with a load balancer, the security problem of cloud-hosted web applications is solved, and efficient security protection and performance maintenance is achieved under small memory.
Patent Information
- Application Number
- CN202211641017.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-20
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2042-12-20
AI Technical Summary
In the prior art, the security of cloud-hosted Web applications is difficult to effectively protect, especially the high firewall cost and the high consumption of virtual machine technology resources, resulting in complex deployment and impact productivity, and traditional methods are difficult to deal with complex network attacks.
Using a container-based jump defense mechanism, a MongoDB database cluster is built through Docker containers, a module calling algorithm is used to classify and distribute data, and a load balancer is used to realize data distribution and mapping, providing a single interface to limit the attacker's control time on a specific host.
Improve the security of cloud-hosted web applications with smaller memory consumption, reduce the degree of damage, reduce the time for attackers to control the host, and improve system performance.
Smart Images

Figure CN116048718B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet technologies, and in particular, to a method and device for improving the security of cloud-hosted Web application programs based on containers. Background Art
[0002] Due to the flexible pricing and easy management convenience, a large number of enterprise services and operations are built on cloud environments. However, as companies store more and more data in the cloud, the security of cloud servers becomes more important. To improve the security of this critical data, security personnel use methods such as more secure network protocols, updated hardware with built-in security features, and various malware detection systems. Despite these measures, hackers can still obtain critical data through the Internet, especially when Web application programs are deployed in cloud service environments. Important steps to protect Web application programs from exploitation include: using the latest encryption, requiring appropriate authentication, patching discovered vulnerabilities, and having a healthy software development environment. However, the reality is that even in a relatively strong security environment, attackers can still find vulnerabilities. In a virtual power plant, it can be refined into an integrated control carrier formed by the organic combination of distributed energy sources, controllable loads, and distributed energy storage facilities. Therefore, when building an energy management and trading platform, data storage of various distributed energy sources such as wind power generation, photovoltaic power generation, micro gas turbine generators, and small hydropower units, controllable loads such as factory energy consumption, office building energy consumption, and air conditioning energy consumption, and distributed energy storage facilities such as electric vehicles and battery energy storage can be built in different databases, thereby building a Web application cloud cluster. An emerging security concept is to deploy a Web application cloud cluster and then design a defense mechanism, leapfrog defense, using the redundancy and connectivity of these clusters in cloud servers. Leapfrog defense is based on periodically moving application program instances from one host to another host with different IP addresses or ports. Therefore, in this case, an intruder who obtains access rights to a specific host cannot control that host for a long time. This method obtains security by limiting the occupancy time of any specific host under attack and under the control of an intruder, thereby reducing the degree of damage that can be caused. This method is similar to a time-space trade-off, sacrificing a small part of performance by dynamically changing the cluster composition to obtain higher security.
[0003] The most common method for improving the security of Web application programs is a Web application firewall. Among them, a Web application firewall can protect Web application programs from malicious HTTP traffic attacks by setting up a filtering barrier between the target server and the attacker. Therefore, a Web application firewall can defend against attacks such as cross-site forgery, cross-site scripting, and SQL injection. However, firewalls require a high cost, especially the price of hardware firewalls is particularly expensive. Therefore, it is difficult for ordinary users or small projects to deploy them.
[0004] Currently, protecting vulnerable web applications is a complex task, which can be achieved through the following two conventional methods:
[0005] Firewall technologies mainly include: adopting functions such as cache acceleration, unified authentication interface, and anti-DDos to actively adapt to the continuously changing network security environment, including filtering technologies to check the header information of data packets and filtering them according to filtering rules. In the state monitoring technology of the firewall, the state table is dynamically established, which can effectively manage the temporary ports established by some complex protocols. The dynamic state table is the core of the stateful inspection firewall. After receiving a connection request sent by the client, the application proxy checks the source and destination IP addresses of the client and decides whether to allow the connection request according to the pre-set filtering rules. If the connection request is allowed, client identity verification is performed.
[0006] The second method is to deploy the web application on a virtual host. Deploying the web application in the cloud environment highly depends on virtualization. Virtualization technology is to separate physical computing devices into one or more virtual devices, and each device can be easily used and managed to execute computing tasks. In the virtual host method based on IP addresses, multiple IPs can be bound in the server, and then the web server is configured, so that multiple websites are bound to different IPs. In this method, different hostnames can be resolved to different IP addresses, thus achieving the purpose of protecting the web application.
[0007] In summary, it can be found that firewalls require high installation and maintenance costs. In addition, using firewalls will seriously affect the overall productivity of the company. Sometimes it will also prompt employees to use backdoor vulnerabilities, resulting in security problems because the data transmitted through these backdoor vulnerabilities is not correctly inspected. Although firewalls can block basic types of Trojans, they have proven to be defenseless against other types of malware. Malware can still enter the system in the form of data. For traditional virtual machine technology, each virtual machine not only includes the application program, the size of which is usually only a few hundred megabytes, but also includes the entire virtualized operating system, the size of which may be more than a dozen gigabytes or larger. Due to the large size of the files and the limitations of network and disk bandwidth, deploying a cluster based on virtual machine infrastructure may require a large amount of time and resources. SUMMARY OF THE INVENTION
[0008] The present invention aims to solve at least one of the technical problems in the related art to some extent.
[0009] To this end, the present invention proposes a method for improving the security of cloud-hosted web applications based on containers. A new security mechanism for cluster-based applications protects the security of web applications through container jumps. Use the virtual technology Docker to establish a MongoDB database cluster and use a module call algorithm to call different MongoDB database shards. By doing so, the use of virtual technology can be achieved with very little memory, and the damage to web applications can be reduced through container jumps.
[0010] Another object of the present invention is to propose an apparatus for improving the security of cloud-hosted web applications based on containers.
[0011] The third object of the present invention is to propose a computer device.
[0012] The fourth object of the present invention is to propose a non-transitory computer-readable storage medium.
[0013] To achieve the above object, on the one hand, the present invention proposes a method for improving the security of cloud-hosted web applications based on containers, including:
[0014] Build a web application and use Docker container instances in the web application to build a MongoDB database cluster; wherein, the web application includes multiple database containers;
[0015] Classify the data stored in the multiple database containers based on the types of the multiple database containers to obtain a data classification result;
[0016] Build a jump defense model according to the data classification result and the characteristics of the MongoDB database cluster, and output the distribution characteristics of the data stored in the multiple database containers in the Docker container instance;
[0017] Configure a load balancer for the MongoDB database cluster based on the distribution characteristics to perform data distribution and mapping processing to the host, so that the jump defense model provides a single interface to each database container.
[0018] In addition, the method for improving the security of cloud-hosted web applications based on containers according to the above embodiments of the present invention may further have the following additional technical features:
[0019] Further, in an embodiment of the present invention, the classifying the data stored in the multiple database containers based on the types of the multiple database containers to obtain a data classification result includes:
[0020] Establish a baseline for comparing performance in the web application;
[0021] Taking the throughput of the write requests in the multiple database containers as a performance metric, record the response time, and obtain the deviation value from the baseline; and,
[0022] Use the BCNF algorithm to classify the multiple database containers to obtain the data classification results of multiple related databases.
[0023] Further, in an embodiment of the present invention, the method further includes:
[0024] Obtain the jump frequency of the containers in the jump defense model;
[0025] Collect relevant data based on the jump frequency and analyze the proportion of the jumped containers in the MongoDB database cluster;
[0026] Obtain the number of jumped containers based on the proportion of the jumped containers, and obtain the throughput change result according to the number of jumped containers.
[0027] Further, in an embodiment of the present invention, by increasing the jump frequency and the percentage of jumped containers, a linear model is established to predict the influence result of the container jump parameters on the write throughput:
[0028] T = <F, p, C, M>
[0029] Wherein, T is the write throughput, f is the jump frequency, p is the percentage of jumped containers, C is the CPU parameter, and M is the memory.
[0030] To achieve the above object, on the other hand, the present invention proposes a device for improving the security of cloud-hosted web applications based on containers, including:
[0031] A database construction module, configured to construct a web application and use the Docker container instances in the web application to construct a MongoDB database cluster; wherein, the web application includes multiple database containers;
[0032] A data classification module, configured to classify the data stored in the multiple database containers based on the types of the multiple database containers to obtain data classification results;
[0033] A jump defense module, configured to construct a jump defense model according to the data classification results and the characteristics of the MongoDB database cluster, and output the distribution characteristics of the data stored in the multiple database containers in the Docker container instances;
[0034] Configure a load balancing module to configure a load balancer for the MongoDB database cluster based on the distribution characteristics for data distribution and mapping processing to hosts, so that the jump defense model provides a single interface to each database container.
[0035] A third aspect of the present invention provides a computer device, including a processor and a memory;
[0036] Wherein, the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory to implement a method for improving the security of cloud-hosted Web applications based on containers.
[0037] A fourth aspect of the present invention provides a non-transitory computer-readable storage medium, on which a computer program is stored, characterized in that when the program is executed by a processor, it implements a method for improving the security of cloud-hosted Web applications based on containers.
[0038] The method, device, equipment and storage medium for improving the security of cloud-hosted Web applications based on containers in the embodiments of the present invention are a new security mechanism for cluster-based applications, which protects the security of web applications through container jumps. Use the virtual technology Docker to establish a MongoDB database cluster, and use the module call algorithm to call different MongoDB database shards. It can not only implement the use of virtual technology with very little memory, but also reduce the damage degree of web applications through container jumps.
[0039] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] The above and / or additional aspects and advantages of the present invention will become apparent and be readily understood from the following description of the embodiments in conjunction with the drawings, wherein:
[0041] Figure 1 is a flowchart of a method for improving the security of cloud-hosted Web applications based on containers according to an embodiment of the present invention;
[0042] Figure 2 is a framework diagram of a jump defense model according to an embodiment of the present invention;
[0043] Figure 3 is a schematic diagram of classifying a database using the BCNF algorithm according to an embodiment of the present invention;
[0044] Figure 4Schematic structural diagram of a device for improving the security of cloud-hosted web applications based on containers according to an embodiment of the present invention;
[0045] Figure 5 Is a computer device according to an embodiment of the present invention. Detailed implementation manners
[0046] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments may be combined with each other. The present invention will be described in detail below with reference to the drawings and in conjunction with the embodiments.
[0047] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0048] The following describes a method, device, equipment, and storage medium for improving the security of cloud-hosted web applications based on containers according to an embodiment of the present invention with reference to the drawings.
[0049] Figure 1 Is a flowchart of a method for improving the security of cloud-hosted web applications based on containers according to an embodiment of the present invention.
[0050] As Figure 1 shown, the method includes but is not limited to the following steps:
[0051] S1, construct a web application, and construct a MongoDB database cluster using Docker container instances in the web application; wherein, the web application includes multiple database containers;
[0052] S2, classify the data stored in the multiple database containers based on the types of the multiple database containers to obtain a data classification result;
[0053] S3, construct a jump defense model according to the data classification result and the characteristics of the MongoDB database cluster, and output the distribution characteristics of the data stored in the multiple database containers in the Docker container instance;
[0054] S4, configure a load balancer for the MongoDB database cluster based on the distribution characteristics to perform data distribution and mapping processing to the host, so that the jump defense model provides a single interface to each database container.
[0055] The method for improving the security of cloud-hosted web applications based on containers in the embodiments of the present invention will be elaborated in detail below with reference to the accompanying drawings.
[0056] Specifically, when jumping a container, it needs to be shut down and then restarted on another host. This process may cause interruptions on the server side, especially when moving multiple containers, because some application instances will not be available again until the restart is completed. To evaluate the impact of container jumping on real applications, the embodiments of the present invention construct a web application containing multiple database containers. The experiment of the present invention is a MongoDB database cluster constructed using Docker container instances. Then, the stored information is reasonably classified by database type, and then, taking advantage of the fact that the MongoDB database is sharded, the distribution and striping characteristics of data in container instances are achieved. The constructed jump defense model requires a load balancer to handle the distribution and mapping of data to hosts in order to provide a single interface to each database. The framework of the jump defense model is as follows Figure 2 shown.
[0057] Furthermore, through the tests of multiple open-source load testing tools, the present invention finds that Apache Jmeter has the best performance to complete the statistical analysis work. The perfect MongoDB Java API and Jmeter Java API are used to write call programs to test the write and count throughput of MongoDB.
[0058] Next, a baseline for comparing performance is established, and which performance metrics to emphasize. The embodiments of the present invention will use test response time, latency, and many other parameters to find the deviation values from the baseline.
[0059] Specifically, taking the throughput of write requests as the key performance metric, the response time is recorded. During this period, the BCNF algorithm is used to classify the database, making it into multiple related databases. As Figure 3 shown.
[0060] It can be understood that BCNF, short for Boyce Codd Normal Form, is called BCNF / Boyce-Codd Normal Form in Chinese. It was proposed by Boyce and Codd and is one step further than 3NF. It is generally considered to be the modified third normal form.
[0061] Let the relational schema R<U, F> ∈ 1NF. If for every functional dependency X → Y of R, if Y is not a subset of X, then X must contain a superkey, then R ∈ BCNF. The conditions for satisfying BCNF are as follows: all non-primary attributes are fully functionally dependent on every candidate key; all primary attributes are also fully functionally dependent on every candidate key that does not contain it; no attribute is fully functionally dependent on any set of attributes that are not candidate keys. It was proposed by Boyce and Codd and is one step further than 3NF. It is usually considered the revised third normal form. The so-called third normal form is defined as follows: in the relational schema R, if there does not exist such a key X, attribute group Y, and non-primary attribute Z such that X → Y and Y → Z hold (where Y → X does not exist), then R is said to be in 3NF.
[0062] That is, when 2NF (Second Normal Form) eliminates the transitive functional dependency of non-primary attributes on the key, it is called 3NF.
[0063] Projecting a 3NF relationship will eliminate the partial and transitive dependencies of the primary attributes on the key in the original relationship, resulting in a set of BCNF relationships.
[0064] BCNF properties: all non-primary attributes are fully functionally dependent on every candidate key; all primary attributes are also fully functionally dependent on every candidate key that does not contain it; no attribute is fully functionally dependent on any set of attributes that are not candidate keys.
[0065] As an embodiment of the present invention, since R ∈ BCNF, by definition, any transitive and partial dependencies of attributes on the key are excluded, so R ∈ 3NF. However, if R ∈ 3NF, then R is not necessarily in BCNF.
[0066] I. In the relational schema STJ (S, T, J), S represents students, T represents teachers, and J represents courses. Each teacher teaches only one course. Each course has several teachers. When a certain student selects a certain course, it corresponds to a fixed teacher. From the semantics, the following functional dependencies can be obtained:
[0067] (S, J) -> T; (S, T) -> J; T -> J.
[0068] (S, J) and (S, T) are both candidate keys.
[0069] STJ is in 3NF because there is no transitive or partial dependency of any non-primary attribute on the key. However, STJ is not a BCNF relationship because T is the determinant and T is not a superkey.
[0070] II. Suppose the warehouse management relational table is StorehouseManage (warehouse ID, stored item ID, administrator ID, quantity), and there is one administrator working in only one warehouse; one warehouse can store multiple items. The following determinant relationships exist in this database table:
[0071] (Warehouse ID, Stored Item ID) → (Administrator ID, Quantity) (Administrator ID, Stored Item ID) → (Warehouse ID, Quantity);
[0072] Therefore, both (Warehouse ID, Stored Item ID) and (Administrator ID, Stored Item ID) are candidate keys for StorehouseManage. The only non-key field in the table is Quantity, and it conforms to the Third Normal Form. However, due to the following determinant relationships:
[0073] (Warehouse ID) → (Administrator ID) (Administrator ID) → (Warehouse ID);
[0074] That is, there is a situation where a key field determines another key field, so it does not conform to the BCNF paradigm.
[0075] In the embodiments of the present invention, containers are jumped at different frequencies to evaluate their impact on performance. For each experiment, multiple trials were conducted and the results were averaged. The result is that the jump of a single container, even at a speed of 1 jump per second, has little impact on the overall cluster performance. This result is due to the replica set in MongoDB, which is a master-slave property to ensure that when one instance is shut down, another instance will immediately replace it, so the throughput is not significantly affected by the jump. When moving multiple containers at an increasing frequency, the throughput will decrease. The performance of the entire cluster is only 50% when half of the containers are jumped. It is almost the same trend as when the present invention moves 1 / 3 of the container quantity. However, the negative impact on the throughput is greater. It is found that when moving more than half of the container quantity more frequently, the throughput does linearly decrease. However, the important point is that even when up to 80% of the cluster nodes are jumped at 1-second intervals, the performance of 50% of the baseline cluster can still be achieved.
[0076] Furthermore, in the embodiments of the present invention, the jump frequency is fixed and data is collected to analyze the percentage of containers jumped in the entire cluster. It is found that when more containers are jumped, the throughput will decrease, but when moving 50% or more containers, the throughput begins to level off.
[0077] In one embodiment of the present invention, assume that the present invention has a database cluster containing n containers, and a load balancer for distributing requests across the containers to the database. If a hacker gains access to Container No. 1, as long as he has the right to access the container, he can steal data from the database instance. By regularly jumping the container to another host, the present invention can cut off such unauthorized access so that the attacker only has a limited period of time to exploit the infected host. The present invention can also change a subset of configuration parameters during each move, so that the present invention can improve security by avoiding the reuse of homogeneous environment configurations. In summary, the present invention can roughly establish a linear model to predict how container jump parameters affect throughput by increasing the hopping frequency and simultaneously increasing the percentage of the total number of jumping containers.
[0078] T = <f, p, C, M>
[0079] Where T is the write throughput, f is the hopping frequency, p is the percentage of hopping containers, C is the CPU parameter, and M is the memory.
[0080] It can be understood that, in order to improve the security of cloud-hosted web applications, the present invention transfers the application instance from one host to another host, which may have different IP addresses or ports. Therefore, an attacker who obtains access to a specific host cannot control the host for a long time. The present invention obtains security by restricting the time for any specific host to be attacked and controlled by the attacker, thereby reducing the possible damage.
[0081] As an embodiment of the present invention, assume that the present invention has a database cluster with n containers, and there is a load balancer that distributes requests to the database across the containers. A MongoDB database cluster built from docker container instances. The present invention uses the BCNF algorithm to classify and organize the database into multiple databases, which means that the data is distributed among the containers and stripped. In order to provide a single interface for the database, the cluster requires a configuration server to handle the distribution of data and mapping to the host. The overall structure is as Figure 2 shown. Assume that the database n is 6, so the present invention has 6 sub-databases. Therefore, the main database is dispersed into 6 containers and used in conjunction with 3 configuration servers, including the router software. There are a total of 10 containers here.
[0082] A method for improving the security of cloud-hosted web applications based on containers according to an embodiment of the present invention is a new security mechanism for cluster-based applications, which protects the security of web applications through container jumps. Use the virtual technology Docker to establish a MongoDB database cluster, and use the module call algorithm to call different MongoDB database shards. It can not only implement the use of virtual technology with very little memory, but also reduce the damage degree of web applications through container jumps.
[0083] To implement the above embodiments, as Figure 4 shown, in this embodiment, a device 10 for improving the security of cloud-hosted web applications based on containers is further provided. The device 10 includes a database construction module 100, a data classification module 200, a jump defense module 300, and a configuration load balancing module 400.
[0084] The database construction module 100 is used to construct a web application and use the Docker container instances in the web application to construct a MongoDB database cluster; wherein, the web application includes multiple database containers;
[0085] The data classification module 200 is used to classify the data stored in multiple database containers based on the types of multiple database containers to obtain a data classification result;
[0086] The jump defense module 300 is used to construct a jump defense model according to the data classification result and the characteristics of the MongoDB database cluster, and output the distribution characteristics of the data stored in multiple database containers in the Docker container instances;
[0087] The configuration load balancing module 400 is used to configure a load balancer for the MongoDB database cluster based on the distribution characteristics to perform data distribution and mapping processing to the host, so that the jump defense model provides a single interface to each database container.
[0088] Further, the above data classification module 200 is further used for:
[0089] Establish a baseline for comparing performance in the web application;
[0090] Taking the throughput of write requests in multiple database containers as a performance metric, record the response time, and obtain the deviation value from the baseline; and,
[0091] Use the BCNF algorithm to classify multiple database containers to obtain a data classification result of multiple related databases.
[0092] Further, the device 10 further includes a throughput change module, which is used for:
[0093] Obtain the jump frequency of the container in the jump defense model;
[0094] Collect relevant data based on the jump frequency and analyze the proportion of jumped containers in the MongoDB database cluster;
[0095] Obtain the number of jumped containers based on the proportion of jumped containers, and obtain the throughput change result according to the number of jumped containers.
[0096] Furthermore, by increasing the jump frequency and the percentage of jumped containers, establish a linear model to predict the influence result of container jump parameters on the write throughput:
[0097] T = <f, p, C, M>
[0098] Wherein, T is the write throughput, f is the jump frequency, p is the percentage of jumped containers, C is the CPU parameter, and M is the memory.
[0099] The device for improving the security of cloud-hosted web applications based on containers according to an embodiment of the present invention is a new security mechanism for cluster-based applications, which protects the security of web applications through container jumps. Use the virtual technology Docker to establish a MongoDB database cluster, and use the module call algorithm to call different MongoDB database shards. It can not only implement the use of virtual technology with very little memory, but also reduce the damage degree of web applications through container jumps.
[0100] To implement the method of the above embodiment, the present invention also provides a computer device, as Figure 5 shown. The computer device 600 includes a memory 601 and a processor 602; wherein, the processor 602 runs a program corresponding to the executable program code by reading the executable program code stored in the memory 601, so as to implement each step of the method for improving the security of cloud-hosted web applications based on containers described above.
[0101] To implement the method of the above embodiment, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the method for improving the security of cloud-hosted web applications based on containers.
[0102] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.
[0103] In addition, the terms "first" and "second" are used for descriptive purposes only and cannot be construed as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one of the features. In the description of the present invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise specifically defined.
Claims
1. A method for improving the security of cloud-hosted web applications based on containers, characterized in that, Including the following steps: Construct a Web application and build a MongoDB database cluster using Docker container instances in the Web application; wherein, the Web application includes multiple database containers; Classify the data stored in the multiple database containers based on the types of the multiple database containers to obtain a data classification result; Construct a jump defense model according to the data classification result and the characteristics of the MongoDB database cluster, and output the distribution characteristics of the data stored in the multiple database containers in the Docker container instance; Configure a load balancer for the MongoDB database cluster based on the distribution characteristics to perform data distribution and mapping processing to the host, so that the jump defense model provides a single interface to each database container and periodically jumps to the host corresponding to the database container.
2. The method according to claim 1, wherein The classifying the data stored in the multiple database containers based on the types of the multiple database containers to obtain a data classification result includes: Establish a baseline for comparing performance in the Web application; Taking the throughput of write requests in the multiple database containers as a performance metric, record the response time, and obtain the deviation value from the baseline; and Use the BCNF algorithm to classify the multiple database containers to obtain a data classification result of multiple related databases.
3. The method according to claim 1, wherein The method further includes: Obtain the jump frequency of the containers in the jump defense model; Collect relevant data based on the jump frequency and analyze the proportion of the jumped containers in the MongoDB database cluster; Obtain the number of jumped containers based on the proportion of the jumped containers, so as to obtain the throughput change result according to the number of jumped containers.
4. The method according to claim 3, characterized in that, Establish a linear model to predict the influence result of container jump parameters on write throughput by increasing the jump frequency and the percentage of jumped containers: Wherein, T is the write throughput, f is the jump frequency, p is the percentage of jumped containers, C is the CPU parameter, and M is the memory.
5. A device for improving the security of cloud-hosted web applications based on containers, characterized in that, Including: A database construction module, configured to construct a Web application and build a MongoDB database cluster using Docker container instances in the Web application; wherein, the Web application includes multiple database containers; A data classification module, configured to classify the data stored in the multiple database containers based on the types of the multiple database containers to obtain a data classification result; A jump defense module, configured to construct a jump defense model according to the data classification result and the characteristics of the MongoDB database cluster, and output the distribution characteristics of the data stored in the multiple database containers in the Docker container instance; A configuration load balancing module, configured to configure a load balancer for the MongoDB database cluster based on the distribution characteristics to perform data distribution and mapping processing to the host, so that the jump defense model provides a single interface to each database container and periodically jumps to the host corresponding to the database container.
6. The device according to claim 5, wherein The data classification module is further configured to: Establish a baseline for comparing performance in the Web application; Taking the throughput of write requests in the multiple database containers as a performance metric, record the response time, and obtain the deviation value from the baseline; And, Use the BCNF algorithm to classify the multiple database containers to obtain a data classification result of multiple related databases.
7. The device according to claim 5, characterized in that, The device further includes a throughput change module for: Obtain the jump frequency of the containers in the jump defense model; Collect relevant data based on the jump frequency and analyze the proportion of jumped containers in the MongoDB database cluster; Obtain the number of jumped containers based on the proportion of jumped containers, and obtain the throughput change result according to the number of jumped containers.
8. The device according to claim 7, characterized in that By increasing the jump frequency and the percentage of jumped containers, establish a linear model to predict the influence result of container jump parameters on write throughput: Where T is the write throughput, f is the jump frequency, p is the percentage of jumped containers, C is the CPU parameter, and M is the memory.
9. A computer device, characterized in that, Comprising a processor and a memory; Wherein, the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to implement the method for improving the security of cloud-hosted Web applications based on containers according to any one of claims 1-4.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the method for improving the security of cloud-hosted Web applications based on containers according to any one of claims 1-4.
Citation Information
Patent Citations
Docker-based data packet acquisition and analysis system and method thereof
CN108616419A
Database cluster expansion method and device based on Docker
CN110633325A