A request grouping method, device, equipment and medium based on self-starting scenario

By generating mimicry tags and adding them to the output request, the problem of low request grouping and processing efficiency in self-start scenarios in mimicry defense technology is solved, and fast grouping and efficient judgment of requests in self-start scenarios is achieved.

CN116132171BActive Publication Date: 2025-05-23PURPLE MOUNTAIN LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310120077.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-15
Publication Date
2025-05-23
Estimated Expiration
2043-02-15

AI Technical Summary

Technical Problem

The existing mimic defense technology lacks the method of quickly grouping and processing requests in the self-start scenario of the execution body, resulting in inefficient adjudication.

Method used

By determining whether the execution body performs self-start operation, determining its function call information and code call levels, generating a mimetic tag, and adding it to the output request, so that after receiving the output request with the mimetic closing bracket, the request is grouped and adjudicated based on the mimetic tag.

Benefits of technology

It realizes rapid grouping of requests in self-start scenarios, improves the efficiency of mimicry adjudication, and ensures accurate adjudication for the same type of request.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116132171B_ABST
    Figure CN116132171B_ABST
Patent Text Reader

Abstract

The present application discloses a request grouping method, device, equipment and medium based on a self-starting scenario, which relates to the field of mimetic defense technology, including: determining whether the execution body is monitored to perform a self-starting operation; if so, determining the function call information of the execution body and generating a corresponding first target label value, and determining the code call level of the execution body and generating a corresponding second target label value; generating a mimetic label based on the first target label value and the second target label value, and adding the mimetic label to the output request; sending the output request to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing a mimetic ruling on the output request, the output request is grouped based on the mimetic label. In this way, the corresponding mimetic label can be generated after the execution body is self-started, so that when the mimetic right bracket receives the request, the request is grouped based on the mimetic label, which effectively improves the efficiency of mimetic ruling in the self-starting scenario.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of mimicry defense technology, and in particular to a request grouping method, device, equipment and medium based on a self-starting scenario. Background Art

[0002] Mimicry defense technology is an endogenous security technology based on the system architecture of "dynamic heterogeneous redundancy" (DHR). Mimicry defense converts network security issues caused by unknown vulnerabilities into differential mode disturbance phenomena that can be judged by the output arbitrator, and uses characteristics such as dynamics, heterogeneity and randomness to improve the security of the system.

[0003] The basic principle of mimetic defense is to group, parse, verify, and judge the data output by multiple heterogeneous executors, and use the results as the basis for adjudication. When analyzing the data output by multiple heterogeneous executors, the adjudicator needs to parse the message format of the data and compare the message content to find abnormal message content in order to discover network threats or network attacks, and the adjudication efficiency is a key factor affecting the service quality of the mimetic system. The existing technology mainly focuses on the processing of requests input from the mimetic left bracket, but for requests that are not input through the left bracket, in the scenario of the executor self-starting or self-initiating the request, there is currently a lack of methods that can quickly group and process requests in this scenario. Summary of the invention

[0004] In view of this, the purpose of the present invention is to provide a request grouping method, device, equipment and medium based on a self-starting scenario, which can quickly group requests, thereby effectively improving the efficiency of mimicry adjudication. The specific scheme is as follows:

[0005] In a first aspect, the present application discloses a request grouping method based on a self-starting scenario, which is applied to a mimic adjudication system, including:

[0006] Determine whether the actuator is detected to be performing a self-starting operation;

[0007] If so, determining function call information of the executable body and generating a first target label value based on the function call information, and determining a code call level of the executable body and generating a second target label value based on the code call level;

[0008] generating a mimetic tag based on the first target tag value and the second target tag value, and adding the mimetic tag to an output request corresponding to the execution body when performing the self-starting operation;

[0009] The output requests are sent to a mimetic right bracket, so that the mimetic right bracket groups the output requests based on the mimetic tags after receiving the output requests and before performing mimetic arbitration on the output requests.

[0010] Optionally, the determining whether the execution body is detected to be performing a self-starting operation includes:

[0011] Determine whether the code of the executable body runs spontaneously or initiates a function call, and if so, determine that the executable body performs the self-starting operation.

[0012] Optionally, determining the function call information of the executable body and generating the first target label value based on the function call information includes:

[0013] Determine a first calling function in the running code of the executable body, and use the function name of the first calling function as the first label information;

[0014] Determine whether there is a code embedding point in the executable body, and if so, determine a second calling function of the code embedding point, use the function name of the second calling function as the second label information, and determine the first label information and the second label information as the first target label value;

[0015] If not present, the first label information is directly determined as the first target label value.

[0016] Optionally, determining the code call level of the executable body and generating a second target label value based on the code call level includes:

[0017] Determine whether the code of the executable body is called by a thread, and if so, determine a first calling number of the code of the executable body, determine a request calling number in the thread, and determine the request calling number as a second calling number, so as to generate a second target label value based on the first calling number and the second calling number.

[0018] Optionally, the request grouping method based on the self-start scenario may further include:

[0019] The application environment in which the executable body is running is determined to determine the target application scenario when the executable body is running.

[0020] Optionally, the adding the mimic tag to the output request of the executable body includes:

[0021] According to the output request generated by the execution body based on the target application scenario, the mimicry tag is added to the output request accordingly.

[0022] Optionally, sending the output request to the mimetic right bracket so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic adjudication on the output request, includes:

[0023] The output request is sent to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing mimetic arbitration on the output request, requests with the same mimetic tag are grouped into the same group based on the mimetic tag in the output request.

[0024] In a second aspect, the present application discloses a request grouping device based on a self-starting scenario, which is applied to a mimic arbitration system, including:

[0025] The application monitoring module is used to determine whether the executable body is detected to perform a self-starting operation;

[0026] a data generation module, configured to, if yes, determine function call information of the executable body and generate a first target label value based on the function call information, and determine a code call level of the executable body and generate a second target label value based on the code call level;

[0027] a data adding module, configured to generate a mimetic tag based on the first target tag value and the second target tag value, and add the mimetic tag to an output request corresponding to the execution body when performing the self-starting operation;

[0028] The request sending module is used to send the output request to the mimetic right bracket, so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic arbitration on the output request.

[0029] In a third aspect, the present application discloses an electronic device, including:

[0030] Memory, used to store computer programs;

[0031] A processor is used to execute the computer program to implement the request grouping method based on the self-starting scenario as described above.

[0032] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program, wherein when the computer program is executed by a processor, the request grouping method based on the self-starting scenario as described above is implemented.

[0033] In the present application, it is first determined whether the execution body is monitored to perform a self-starting operation. If so, the function call information of the execution body is determined, and a first target label value is generated based on the function call information, and the code call level of the execution body is determined, and a second target label value is generated based on the code call level. Then, a mimetic label is generated based on the first target label value and the second target label value, and the mimetic label is added to the output request corresponding to the execution body when performing the self-starting operation. Finally, the output request is sent to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing a mimetic ruling on the output request, the output request is grouped based on the mimetic label. It can be seen that the request grouping method based on the self-starting scenario described in the present application can generate a corresponding mimetic tag after the execution body self-starts, and add the mimetic tag to the output request, so that after the mimetic right bracket receives the output request, the output request is grouped based on the mimetic tag, and the grouped requests are mimetically judged. In this way, the requests can be quickly grouped through the generated mimetic tags, and then the requests of the same type can be judged when the mimetic right bracket processes the request, which can effectively improve the efficiency of mimetic judgment. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0035] Figure 1 A flow chart of a request grouping method based on a self-starting scenario provided by this application;

[0036] Figure 2 A flowchart of a specific request grouping method based on a self-starting scenario provided by this application;

[0037] Figure 3 A timing diagram of a request grouping method based on a self-starting scenario in an HTTP scenario provided by this application;

[0038] Figure 4 A timing diagram of a request grouping method based on a self-starting scenario in a MySQL scenario provided by this application;

[0039] Figure 5 A schematic diagram of knowledge data score calculation provided for this application;

[0040] Figure 6A flowchart of a specific request grouping method based on a self-starting scenario provided by this application;

[0041] Figure 7 A schematic diagram of adding mimetic tags in an HTTP scenario provided by this application;

[0042] Figure 8 A schematic diagram of adding mimetic tags in a MySQL scenario provided by this application;

[0043] Fig. 9 A schematic diagram of a request grouping method and device structure based on a self-starting scenario provided by the present application;

[0044] Fig.10 A structural diagram of an electronic device provided for this application. DETAILED DESCRIPTION

[0045] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0046] In the prior art, when analyzing data output by multiple heterogeneous executors, the arbiter needs to parse the message format of the data and compare the message content to find abnormal message content in order to discover network threats or network attacks. In addition, the prior art mainly focuses on the processing of requests input from a simulated left bracket, but for requests that are not input through a left bracket, in the scenario where the executor self-starts the operation, there is currently a lack of methods that can quickly group and process data in this scenario.

[0047] In order to overcome the above-mentioned technical problems, the present application provides a request grouping method, apparatus, device and medium based on a self-starting scenario, which can generate a corresponding mimetic tag based on the calling information of the execution body function after the execution body is self-started, and add the mimetic tag to the output request, so that after the mimetic right bracket receives the output request, the output request is grouped based on the mimetic tag, and the grouped requests are mimetically judged. In this way, the request grouping is achieved through the generated mimetic tags, and the requests of the same type are judged when the mimetic right bracket processes the request, which can effectively improve the efficiency of mimetic judgment.

[0048] See also Figure 1 As shown, an embodiment of the present invention discloses a request grouping method based on a self-starting scenario, which is applied to a mimic arbitration system, including:

[0049] Step S11, determining whether the execution body is detected to be performing a self-starting operation.

[0050] In this embodiment, the mimetic tag injection device in the mimetic arbitration system can be used to monitor whether the executable body performs self-startup. If the mimetic tag injection device detects that the executable body in the mimetic system spontaneously runs code or makes function calls, it can be determined that the executable body performs a self-startup operation.

[0051] Step S12: If yes, determine the function call information of the executable body, and generate a first target label value based on the function call information, and determine the code call level of the executable body, and generate a second target label value based on the code call level.

[0052] In this embodiment, if it is determined that the execution body performs a self-starting operation, it is necessary to generate a corresponding label value based on the execution body. It should be noted that the label value is mainly generated based on the function call information and the code call level of the execution body, and the first label value generated based on the function call information is the call information (funcname), which mainly includes the self-starting function name, function call stack, etc. The second label value generated based on the code call level is mainly the historical call information (acStep), such as code embedding information, which is mainly information that uses the mimicry injection device to analyze and abstractly describe the execution processing level of the code transaction, request or process.

[0053] Step S13: Generate a mimetic tag based on the first target tag value and the second target tag value, and add the mimetic tag to an output request corresponding to the executable body when performing the self-starting operation.

[0054] In this embodiment, a mimetic tag is generated based on the first target tag value and the second target tag value, and the mimetic tag is added to the output request corresponding to the execution body when performing the self-starting operation. That is, in some scenarios, the execution body only initiates a function call after self-starting. At this time, it is only necessary to generate the corresponding first tag value, and directly determine the first tag information as the tag value that needs to be added to the output request. In some other scenarios, the execution body may initiate a function call after self-starting, and there is code embedding information at the same time. At this time, it is necessary to generate the first tag information based on the function call information, and it is also necessary to generate the second tag information based on the code embedding information, and determine the first tag information and the second tag information as the tag values ​​that need to be added to the output request.

[0055] It should be further explained that when generating a pseudo tag based on the tag value and adding the pseudo tag to the output request, the operating environment of the executor needs to be considered. The structure of the output request generated in different operating environments of the executor is different, and the method of adding different output request tag values ​​is also different.

[0056] Step S14: Send the output request to the mimetic right bracket, so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic adjudication on the output request.

[0057] In this embodiment, after adding the mimetic tag generated based on the tag value to the output request, the output request needs to be sent to the mimetic right bracket, so that the mimetic right bracket groups the output requests according to the funcname and acStep in the mimetic tag in the output request, and batches the grouped requests. It should be noted that funcname and acStep are used as mimetic tags, and are finally carried in the output request of the execution body, and together constitute a unique identifier for describing and judging the request. It should be further explained that the mimetic right bracket is used to dynamically intercept and judge the data output by the multiple redundant execution bodies in the dynamic heterogeneous redundant execution body pool, and select the output data of the relatively correct redundant execution body to respond to the user. For different business types, there are different types of right brackets, for example: http right brackets that support http business, and MySQL right brackets that support MySQL business. In this way, when the mimetic right bracket processes the request, the same type of request is judged, which can effectively improve the efficiency of mimetic judgment.

[0058] It can be seen that in this embodiment, it is first determined whether the execution body is monitored to perform a self-starting operation. If so, the function call information of the execution body is determined, and a first target label value is generated based on the function call information, and the code call level of the execution body is determined, and a second target label value is generated based on the code call level. Then, a mimetic label is generated based on the first target label value and the second target label value, and the mimetic label is added to the output request corresponding to the execution body when performing the self-starting operation. Finally, the output request is sent to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing a mimetic ruling on the output request, the output request is grouped based on the mimetic label. It can be seen that the request grouping method based on the self-starting scenario described in the present application can generate a corresponding mimetic tag after the execution body self-starts, and add the mimetic tag to the output request, so that after the mimetic right bracket receives the output request, the output request is grouped based on the mimetic tag, and the grouped requests are mimetically judged. In this way, the requests can be quickly grouped through the generated mimetic tags, and then the requests of the same type can be judged when the mimetic right bracket processes the request, which can effectively improve the efficiency of mimetic judgment.

[0059] Based on the above embodiments, it can be seen that in this application, before sending the output request to the mimetic right bracket, it is necessary to generate a label value first, and generate a mimetic label based on the generated label value. For this reason, this embodiment describes in detail how to generate the corresponding label value, see Figure 2 As shown, an embodiment of the present invention discloses a request grouping method based on a self-starting scenario, comprising:

[0060] Step S21, determining whether the code of the executable body runs spontaneously or initiates a function call, and if so, determining that the executable body performs a self-starting operation.

[0061] In this embodiment, it is determined whether the code of the executable body runs spontaneously or initiates a function call. If so, it is determined that the executable body performs a self-starting operation. That is, the execution of the executable body application code is monitored by using the mimic tag injection device in the mimic system, and intervention and mimic tag injection are performed when the executable body starts automatically, and the entire executable body code execution process is continued. By monitoring the running status of the executable body code and the function call status of the executable body, it is determined whether the code of the executable body runs automatically or whether the executable body automatically initiates a function call. If so, it is determined that the executable body initiates self-starting.

[0062] Step S22: determine the first calling function in the running code of the executable body, and use the function name of the first calling function as the first label information.

[0063] In this embodiment, after determining that the execution body performs the self-start operation, it is necessary to first determine the first tag information, that is, determine the funcname call information, and funcname is a variable-length string generated after the execution body self-starts or self-initiates a request, including the code call information when the self-start or self-initiates the request, such as the self-start function name, function call stack, etc. It should be noted that in different environments, due to different environments, there are also great differences in calling functions, for example, Figure 3 As shown, in an HTTP environment, when multiple heterogeneous executors self-start or self-initiate requests, the mimetic tag injection device will detect that the executor initiates a call, the calling function is handleHttp(), and there is no code embedding point, then handleHttp() is written as the value of funcname into the mimetic tag position of the executor output request, and when multiple executors initiate the same call at the same time, the value of funcname should be the same.

[0064] Step S23, determine whether there is a code embedding point in the executable body. If so, determine the second calling function of the code embedding point, and use the function name of the second calling function as the second label information, and determine the first label information and the second label information as the first target label value.

[0065] In this embodiment, after determining that the executable body performs a self-starting operation and determining the first tag information of the executable body, it is necessary to determine whether there is a code embedding point in the code of the executable body during operation. If so, it is necessary to determine the calling function related to the code embedding point, and determine the function name of the calling function as the second tag information, and then determine the determined first tag information and the second tag information as the first target tag value. For example, Figure 4 As shown, in the MySQL environment, when multiple heterogeneous executors self-start or self-initiate requests, the mimetic tag injection device will monitor the executor initiating a call, and the calling function is handleMysql(). Subsequently, it is monitored that the application sends a Mysql request through the code embedding sendMessage() function. The mimetic tag injection device records and stores the two function call information and separates them with a separator " / ", that is, handleMysql() / sendMessage() is written as the value of funcname into the mimetic tag position of the executor output request. If multiple executors initiate the same call at the same time, the value of funcname should be the same.

[0066] Step S24: If there is no code embedding point in the executable body, directly determine the first label information as the first target label value.

[0067] In this embodiment, if the executable body does not have a code embedding point, the first label information is directly determined as the first target label value. That is, if the executable body code does not have a code embedding point during the running process, the function name of the code call function of the determined executable body during the running process is directly used as the label value that needs to be written to the output request, that is, directly as funcname.

[0068] Step S25, determine whether the code of the execution body is called by the thread. If so, determine the first number of times the code of the execution body is called, and determine the number of request calls in the thread, and determine the number of request calls as the second number of calls, so as to generate a second target label value based on the first number of calls and the second number of calls.

[0069] In this embodiment, after determining the first target tag value funcname of the execution body, it is necessary to determine the second tag value of the execution body, that is, to determine the historical call acStep value of the execution body. It should be explained that the acStep value is to analyze and abstractly describe the execution processing level of the transaction, request or process of the code using the mimic injection device, and the description method is: a request flow is considered to be composed of multiple request calls, and an id is set for the request call. For example, the processing flow of the client request is regarded as a request flow, in which each request call, whether it is an HTTP call, an RPC call, a storage access or a local method call, can be regarded as a request call. The perception, organization, storage and calculation of the request call are performed by the mimic tag injection device. The present invention digitally numbers the request call in a request as the id of the request call and calls the number stepId. The numbering rule of stepId is to start counting from 0 in the same thread, and increase by 1 as the request call is generated. When a new thread is generated, stepId will start counting from 0 again, and the stepId value can be changed according to the different application code embedding points of the execution body. The cumulative record of all stepIds generated in the same request call is called acStep. For different call processes in the same request flow, the value of acStep is different. For example, Figure 5 As shown, after multiple heterogeneous service application execution bodies start up or initiate spontaneous requests, they will execute the code logic of the service application and access the backend service. In the process of executing the code logic of the application, the execution body mimic label injection device will write the generated first target label value funcname and second label value acStep into the output request message of the execution body. After receiving the request, the execution body application made three request calls in thread 1, so it is divided into three steps, and stepId is 0, 1, and 2 respectively. Then it executed two request calls in thread 2, so it is two steps, and stepId is 0 and 1 respectively. The final acStep is 01201.

[0070] Step S26: Generate a mimetic tag based on the first target tag value and the second target tag value, and add the mimetic tag to an output request corresponding to the executable body when performing the self-starting operation.

[0071] Step S27: Send the output request to the mimetic right bracket, so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic adjudication on the output request.

[0072] It should be noted that for more detailed description of step S26 and step S27, reference can be made to the aforementioned embodiment, which will not be repeated here.

[0073] It can be seen that in the present embodiment, in the process of determining the pseudo-label value of the executable body, it is first determined whether the code of the executable body runs spontaneously or initiates a function call. If so, it is determined that the executable body performs a self-starting operation, and then the first calling function in the running code of the executable body is determined, and the function name of the first calling function is used as the first label information, and it is determined whether the executable body has a code embedding point. If so, the second calling function of the code embedding point is determined, and the function name of the second calling function is used as the second label information, and the first label information and the second label information are determined as the first target label value, and if the executable body does not exist Code embedding, then the first label information is directly determined as the first target label value. After determining the first target label value, it is necessary to determine whether the code of the executable body is called by the thread. If so, the first number of times the code of the executable body is called is determined, and the number of request calls in the thread is determined, and the number of request calls is determined as the second number of times called, so as to generate a second target label value based on the first number of times called and the second number of times called, and finally generate a mimetic label based on the first target label value and the second target label value, and add the mimetic label to the output request corresponding to the executable body when performing the self-starting operation. In this way, a mimetic label is generated based on the generated first target label value funcname and the second target label value acStep, and the generated mimetic label is added to the output request, which can make the positioning and grouping of the output request more accurate, and effectively improve the accuracy and reliability of the request grouping method based on the self-starting scenario described in this application.

[0074] Based on the above embodiments, it can be seen that in this application, before sending the output request to the mimetic right bracket, it is necessary to first add the generated mimetic tag to the output request based on the running environment of the executable body. For this reason, this embodiment describes in detail how to add the mimetic tag to the output request, see Figure 6 As shown, an embodiment of the present invention discloses a request grouping method based on a self-starting scenario, comprising:

[0075] Step S31: determine whether the execution body is detected to be performing a self-starting operation.

[0076] Step S32: If yes, determine the function call information of the executable body, and generate a first target label value based on the function call information, and determine the code call level of the executable body, and generate a second target label value based on the code call level.

[0077] Step S33: Generate a mimic tag based on the first target tag value and the second target tag value.

[0078] Step S34: according to the output request generated by the execution body based on the target application scenario, the mimicry tag is added to the output request accordingly.

[0079] In this embodiment, the application scenario of the executable body is different, and the structure of the generated output request is also different. It is necessary to combine the application scenario of the executable body and add the mimetic tag to the output request in a corresponding manner. For example, if the application scenario of the executable body is an HTTP environment, the mimetic tag is added to the request header of the output request. That is, if the operating environment of the executable body is an HTTP environment, the generated output request is an HTTP request. It should be noted that the HTTP request includes a request line, a request header, and a request body. Therefore, when the operating environment of the executable body is an HTTP environment, the generated mimetic tag needs to be added to the request header of the HTTP output request, such as Figure 7 As shown, the output HTTP request of the execution body will carry the mimetic tag and be sent to the HTTP right bracket for judgment. The HTTP right bracket will be grouped according to the mimetic tag, and the requests with the same mimetic tag will be grouped together, and then the request content will be further parsed for judgment.

[0080] Furthermore, if the application scenario of the executable is a MySQL environment, the pseudo tag is added to the request header of the output request. That is, if the operating environment of the executable is a MySQL environment, the generated output request is a MySQL request. It should be noted that a MySQL request is Figure 8 As shown, when the execution environment is MySQL, the generated mimetic tag needs to be added to the request data of the MySQL output request. The output MySQL request of the execution body will carry the mimetic tag and be sent to the MySQL right bracket for judgment. The MySQL right bracket will be grouped according to the mimetic tag, and the requests with the same mimetic tag will be grouped together, and then the request content will be further parsed for judgment.

[0081] Step S35: Send the output request to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing mimetic arbitration on the output request, the mimetic right bracket groups requests with the same mimetic tag into the same group based on the mimetic tag in the output request.

[0082] It should be noted that for a more detailed description of step S31, step S32, step S33, and step S35, reference can be made to the aforementioned embodiments, which will not be repeated here.

[0083] It can be seen that in this embodiment, after generating the mimetic tag, it is necessary to judge the operating environment of the executor. Since the output request structure generated by the executor in different operating environments is different, the position where the mimetic tag needs to be added in the request is also different. In this way, by judging the operating environment of the executor and adding the mimetic tag to the corresponding position in the output request, the reliability of the request grouping based on the self-starting scenario described in this application can be effectively improved.

[0084] See also Fig. 9 As shown, an embodiment of the present invention discloses a request grouping device based on a self-starting scenario, which is applied to a mimic arbitration system, including:

[0085] The application monitoring module 11 is used to determine whether the execution body is detected to perform a self-starting operation;

[0086] A data generation module 12 is used to determine the function call information of the executable body, and generate a first target label value based on the function call information, and determine the code call level of the executable body, and generate a second target label value based on the code call level;

[0087] A data adding module 13, configured to generate a mimetic tag based on the first target tag value and the second target tag value, and add the mimetic tag to an output request corresponding to the execution body when performing the self-starting operation;

[0088] The request sending module 14 is configured to send the output request to the mimetic right bracket, so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic adjudication on the output request.

[0089] In the present application, it is first determined whether the execution body is monitored to perform a self-starting operation. If so, the function call information of the execution body is determined, and a first target label value is generated based on the function call information, and the code call level of the execution body is determined, and a second target label value is generated based on the code call level. Then, a mimetic label is generated based on the first target label value and the second target label value, and the mimetic label is added to the output request corresponding to the execution body when performing the self-starting operation. Finally, the output request is sent to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing a mimetic ruling on the output request, the output request is grouped based on the mimetic label. It can be seen that the request grouping method based on the self-starting scenario described in the present application can generate a corresponding mimetic tag after the execution body self-starts, and add the mimetic tag to the output request, so that after the mimetic right bracket receives the output request, the output request is grouped based on the mimetic tag, and the grouped requests are mimetically judged. In this way, the requests can be quickly grouped through the generated mimetic tags, and then the requests of the same type can be judged when the mimetic right bracket processes the request, which can effectively improve the efficiency of mimetic judgment.

[0090] In some embodiments, the application monitoring module 11 may specifically include:

[0091] The self-start determination unit is used to determine whether the code of the execution body runs spontaneously or initiates a function call. If so, it is determined that the execution body performs the self-start operation.

[0092] In some embodiments, the data generation module 12 may specifically include:

[0093] a label information determining unit, configured to determine a first calling function in the running code of the executable body, and use the function name of the first calling function as the first label information;

[0094] A first data determination unit is used to determine whether there is a code embedding point in the executable body, and if so, determine a second calling function of the code embedding point, use a function name of the second calling function as second label information, and determine the first label information and the second label information as a first target label value;

[0095] The second data determining unit is configured to directly determine the first tag information as the first target tag value if the first tag information does not exist.

[0096] In some embodiments, the data generation module 12 may specifically include:

[0097] The third data determination unit is used to determine whether the code of the execution body is called by the thread. If so, determine the first number of times the code of the execution body is called, determine the number of request calls in the thread, and determine the number of request calls as the second number of calls, so as to generate a second target label value based on the first number of calls and the second number of calls.

[0098] In some embodiments, the request grouping device based on the self-start scenario may further include:

[0099] The environment determination module is used to determine the application environment in which the execution body is running, so as to determine the target application scenario when the execution body is running.

[0100] In some embodiments, the data adding module 13 may specifically include:

[0101] A data adding unit is used to add the mimetic tag to the output request according to the output request generated by the execution body based on the target application scenario.

[0102] In some embodiments, the request sending module 14 may specifically include:

[0103] The request grouping unit is used to send the output request to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing mimetic arbitration on the output request, the mimetic right bracket groups the requests with the same mimetic tag into the same group based on the mimetic tag in the output request.

[0104] Furthermore, the present application also discloses an electronic device. Fig.10 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.

[0105] Fig.10 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the request grouping method based on the self-starting scenario disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0106] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.

[0107] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0108] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the request grouping method based on the self-starting scenario performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.

[0109] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the request grouping method based on the self-starting scenario disclosed above is implemented. The specific steps of the method can refer to the corresponding contents disclosed in the above embodiments, and will not be repeated here.

[0110] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.

[0111] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0112] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0113] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.

[0114] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of ​​the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A request grouping method based on a self-starting scenario, It is characterized in that Applied to the mimicry adjudication system, including: Determine whether the actuator is detected to be performing a self-starting operation; If so, determining function call information of the executable body and generating a first target label value based on the function call information, and determining a code call level of the executable body and generating a second target label value based on the code call level; generating a mimetic tag based on the first target tag value and the second target tag value, and adding the mimetic tag to an output request corresponding to the execution body when performing the self-starting operation; Sending the output request to a mimetic right bracket so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic adjudication on the output request; The step of determining whether the execution body is detected to be performing a self-starting operation includes: Determine whether the code of the executable body runs spontaneously or initiates a function call, and if so, determine that the executable body performs the self-starting operation.

2. The request grouping method based on the self-starting scenario according to claim 1, It is characterized in that The determining the function call information of the executable body and generating a first target label value based on the function call information includes: Determine a first calling function in the running code of the executable body, and use the function name of the first calling function as the first label information; Determine whether there is a code embedding point in the executable body, and if so, determine a second calling function of the code embedding point, use the function name of the second calling function as the second label information, and determine the first label information and the second label information as the first target label value; If not present, the first label information is directly determined as the first target label value.

3. The request grouping method based on the self-starting scenario according to claim 1, It is characterized in that The determining the code call level of the executable body and generating a second target label value based on the code call level includes: Determine whether the code of the execution body is called by the thread. If so, determine the first number of times the code of the execution body is called, determine the number of request calls in the thread, and determine the number of request calls as the second number of calls, so as to generate a second target label value based on the first number of calls and the second number of calls.

4. The request grouping method based on the self-starting scenario according to claim 1, It is characterized in that Also includes: The application environment in which the executable body is running is determined to determine the target application scenario when the executable body is running.

5. The request grouping method based on the self-starting scenario according to claim 4, It is characterized in that The step of adding the mimic tag to the output request of the executable body includes: According to the output request generated by the execution body based on the target application scenario, the mimicry tag is added to the output request accordingly.

6. The request grouping method based on the self-starting scenario according to any one of claims 1 to 5, It is characterized in that The sending the output request to the mimetic right bracket so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic adjudication on the output request, comprises: The output request is sent to the mimetic right bracket, so that after the mimetic right bracket receives the output request and before performing mimetic arbitration on the output request, requests with the same mimetic tag are grouped into the same group based on the mimetic tag in the output request.

7. A request grouping device based on a self-starting scenario, It is characterized in that Applied to the mimicry adjudication system, including: The application monitoring module is used to determine whether the executable body is detected to perform a self-starting operation; a data generation module, configured to, if yes, determine function call information of the executable body and generate a first target label value based on the function call information, and determine a code call level of the executable body and generate a second target label value based on the code call level; a data adding module, configured to generate a mimetic tag based on the first target tag value and the second target tag value, and add the mimetic tag to an output request corresponding to the execution body when performing the self-starting operation; a request sending module, configured to send the output request to the mimetic right bracket, so that the mimetic right bracket groups the output request based on the mimetic tag after receiving the output request and before performing mimetic adjudication on the output request; The step of determining whether the execution body is detected to be performing a self-starting operation includes: Determine whether the code of the executable body runs spontaneously or initiates a function call, and if so, determine that the executable body performs the self-starting operation.

8. An electronic device, It is characterized in that include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the request grouping method based on the self-starting scenario as described in any one of claims 1 to 6.

9. A computer-readable storage medium, It is characterized in that Used to store a computer program, which, when executed by a processor, implements the request grouping method based on the self-starting scenario as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method and device for mimicry upgrading and reconstruction of information system

    CN114915449A

  • Mimicry construction architecture based on SDI technology

    CN212463253U