A mimicry security system and a cloud platform security operation and maintenance method
By dynamically managing heterogeneous execution entities through a mimicry security system, and utilizing deep learning models and high-security data protection technologies, the passive nature of cloud platform security operations and maintenance is solved, enabling proactive defense and rapid response to unknown threats, thereby improving the security and reliability of the cloud platform.
Patent Information
- Application Number
- CN202310252995.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-07
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2043-03-07
AI Technical Summary
Existing cloud platform security systems suffer from passive management in security operations and maintenance, making it difficult to effectively address unknown vulnerabilities and uncertain threats.
By adopting a mimicry security system, heterogeneous executors are dynamically managed and scheduled through the distribution of decision services, a unified service engine, and runtime node agents. Deep learning models are used for policy adjustment, and high-security data protection technology is combined to achieve the cleaning, recovery, or reconstruction of abnormal executors.
It improves the proactiveness and reliability of cloud platform operation and maintenance, enables timely detection and repair of vulnerabilities, enhances the ability to resist unknown attacks, and ensures the safe and stable operation of the system.
Smart Images

Figure CN116248404B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a quasi-state security system and a cloud platform security operation and maintenance method. BACKGROUND
[0002] With the continuous highlighting of cloud computing on high-performance computing support capabilities, new computing, storage, network and other infrastructure are rapidly iterated, and the huge infrastructure base, complex computing and storage architecture, and highly integrated software tools and environment bring great challenges to cloud platform network security operation and maintenance. The current cloud platform security system operation and maintenance technology mainly uses business data in the fields of data warehouse, BI (Business Intelligence, Business Intelligence) and other fields to conduct special operation and maintenance data analysis and mining. Data from monitoring systems, automation operation, CMDB (Configuration Management Database, Configuration Management Database), log files and various professional operation and maintenance tools are collected, cleaned, integrated and structured to support enterprise operation and maintenance data intelligent analysis. Using common systems to conduct special operation and maintenance data analysis and mining makes the management of cloud platform security operation and maintenance more passive. Therefore, the existing security system used by the cloud platform has the problem of passive management in security operation and maintenance. SUMMARY
[0003] The present application provides a quasi-state security system and a cloud platform security operation and maintenance method to at least solve the problem of passive management of the security system used by the cloud platform in security operation and maintenance.
[0004] According to a first aspect of an embodiment of the present application, a quasi-state security system is provided, which comprises a distribution decision service, a unified service engine and a running node agent; the running node agent receives a service request sent by the distribution decision service, controls a plurality of heterogeneous execution bodies to execute operations corresponding to the service request, and generates a service request result according to the states of the plurality of heterogeneous execution bodies after executing the operations corresponding to the service request; the unified service engine receives the service request result and controls the running node agent to clean, recover or reconstruct abnormal heterogeneous execution bodies according to the service request result.
[0005] Optionally, the system further comprises a running management service, the running management service sends a running strategy to the running node agent, the running node agent generates a strategy running result after executing the running strategy and feeds back to the running management service, and the running management service dynamically adjusts the running strategy based on a deep learning model according to the strategy running result.
[0006] Optionally, the running node agent is further configured to monitor states of the plurality of heterogeneous executors, and send the states of the plurality of heterogeneous executors to the running management service, wherein the monitoring of the states of the plurality of heterogeneous executors comprises: collecting outputs of the plurality of heterogeneous executors and listening to resources of the plurality of heterogeneous executors.
[0007] Optionally, the distribution decision service, the unified service engine, and the running management service are applications on a cloud platform, the running node agent is an agent of the plurality of heterogeneous executors built on the cloud platform, and the applications on the cloud platform and the agent of the plurality of heterogeneous executors on the cloud platform interact through a communication network.
[0008] According to a second aspect of the embodiments of the present application, a cloud platform security operation and maintenance method using the metasomatism security system of any one of the first aspect of the embodiments of the present application is further provided, and the method comprises: using the metasomatism security system to perform security operation and maintenance on the cloud platform.
[0009] Optionally, the security operation and maintenance on the cloud platform using the metasomatism security system comprises: making decisions and performing scheduling management on heterogeneous executors in the cloud platform based on the metasomatism security system; and performing access on dynamic data and heterogeneous data in the cloud platform based on high-security data protection technology.
[0010] Optionally, the making decisions and performing scheduling management on the heterogeneous executors in the cloud platform based on the metasomatism security system comprises: making decisions on the heterogeneous executors in the cloud platform based on a self-evolution model decision technology; and performing cleaning, recovery, or reconstruction on abnormal heterogeneous executors based on heterogeneous executor rapid scheduling management and cleaning recovery technology, wherein the reconstruction comprises changing components or background tasks of the heterogeneous executors.
[0011] Optionally, the making decisions on the plurality of heterogeneous executors based on the self-evolution model decision technology comprises: obtaining historical running strategies and strategy running results of the plurality of heterogeneous executors; training a deep learning model according to the historical running strategies and the strategy running results; and dynamically adjusting a running strategy using the trained deep learning model.
[0012] Optionally, the performing access on the dynamic data and the heterogeneous data based on the high-security data protection technology comprises: performing access on the dynamic data in a segmented structure using a segmented protection strategy; and performing access on heterogeneous data among the plurality of heterogeneous executors using data distribution and state synchronization technology.
[0013] According to a third aspect of the embodiments of the present application, a computer readable storage medium is further provided, and the storage medium stores a computer program, wherein the computer program is configured to execute the method steps in any one of the above embodiments when running.
[0014] In the embodiment of the present application, the service request sent by the distribution decision service is received by the running node agent, a plurality of heterogeneous execution bodies are controlled to execute the operation corresponding to the service request, and the service request result is generated according to the state of the plurality of heterogeneous execution bodies after executing the operation corresponding to the service request; the unified service engine receives the service request result, and controls the running node agent to clean, recover or reconstruct the abnormal heterogeneous execution body according to the service request result. Since the plurality of heterogeneous execution bodies receive the service request such as a WEB request, the service request result, that is, the state or output information of the heterogeneous execution body after executing the service request, is sent to the unified service engine, the unified service engine diagnoses the heterogeneous execution body according to the service request result, and cleans, recovers or creates a new heterogeneous execution body to ensure the safe operation of the system. That is, the paratopic defense system is an active defense system that can detect and locate vulnerabilities and repair them in time, thereby solving the passive management problem of the security system used by the existing cloud platform in safe operation.
[0015] In the embodiment of the present application, the paratopic security system is used to fuse cloud networks, use the decision-making technology based on the self-evolution model to dynamically adjust the decision-making strategy in the paratopic security system by using the deep learning framework, improve the intelligence and accuracy of the decision-making strategy, improve the defense system of the paratopic security system based on the rapid scheduling management and cleaning and recovery of unknown attack characteristics, and use the high-security data protection technology to use the segmented data security protection technology to build a dynamic data and heterogeneous data multi-element data protection architecture. Even if the cloud platform is attacked, it can ensure normal operation while processing abnormalities, and can resist and handle unknown risks, thereby improving the initiative and reliability of cloud platform operation and maintenance. BRIEF DESCRIPTION OF DRAWINGS
[0016] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present application and, together with the specification, serve to explain the principles of the application.
[0017] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, for those skilled in the art, other drawings can also be obtained without creative labor.
[0018] Figure 1 is a schematic diagram of an optional paratopic security system according to an embodiment of the present application;
[0019] Figure 2 is another optional paratopic security system schematic diagram according to an embodiment of the present application;
[0020] Figure 3is an optional cloud platform schematic diagram according to an embodiment of the present application;
[0021] Figure 4 is an optional cloud network integration distributed mimetic security architecture schematic diagram according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] In order to make the personnel in the art better understand the present application scheme, the technical scheme in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by the person skilled in the art without creative labor should belong to the scope of protection of the present application.
[0023] It should be noted that in the description of the present application, the terms "first", "second", etc. are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices. The terms "mount", "connect", "connect" should be understood broadly, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium, or it can be the internal communication of two elements, it can be wireless connection, or it can be wired connection. For the person skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0024] According to a first aspect of an embodiment of the present application, a mimetic security system is provided. The system comprises a distribution decision service, a unified service engine and a running node agent; the running node agent receives a service request sent by the distribution decision service, controls a plurality of heterogeneous executors to execute an operation corresponding to the service request, and generates a service request result according to the state of the plurality of heterogeneous executors after executing the operation corresponding to the service request; the unified service engine receives the service request result, and controls the running node agent to clean, recover or reconstruct an abnormal heterogeneous executor according to the service request result.
[0025] Optionally, as Figure 1As shown, the running node agent is an agent of a plurality of heterogeneous executors for managing and controlling the plurality of heterogeneous executors. The running node agent receives a service request, i.e., an operation to be performed, and a scheduling decision method sent by the distribution decision service, and feeds back a service request result, such as a state or output information of the heterogeneous executor after executing the service request, to the unified service engine. Exemplarily, the distribution decision service sends a plurality of copies of a certain service request to the running node agent, and the running node agent sends the plurality of service requests to the plurality of heterogeneous executors, respectively. Due to the dynamic, heterogeneous and redundant design of the heterogeneous executors, vulnerabilities and backdoors among the heterogeneous executors are dispersed, so that even if the heterogeneous executors are attacked by unknown attacks, there is always a normally running heterogeneous executor at any moment. For the abnormal heterogeneous executors after being attacked, the unified service engine analyzes and diagnoses the service request result, and then controls the running node agent to clean up, recover or reconstruct the abnormal heterogeneous executors. The reconstruction of the heterogeneous executors includes generating a new heterogeneous executor functionally equivalent, and also can replace some components in the existing heterogeneous executors, such as reconfiguring resources by replacing components in the current heterogeneous executors, or adding or reducing background tasks of the heterogeneous executors, changing the running scene of the heterogeneous executors, etc.
[0026] In the embodiment of the application, since the plurality of heterogeneous executors send the service request result, i.e., the state or output information of the heterogeneous executor after executing the service request, to the unified service engine after receiving the service request such as a WEB request, the unified service engine diagnoses the heterogeneous executors according to the service request result, cleans up and recovers the abnormal heterogeneous executors, or creates a new heterogeneous executor to ensure the safe operation of the system. That is, the paratopic defense system is an active defense system that can detect and locate vulnerabilities and repair them in time, thereby solving the problem of passive management in the security operation of the security system used by the existing cloud platform.
[0027] As an optional embodiment, the system further comprises a running management service, the running management service sends a running strategy to the running node agent, the running node agent generates a strategy running result after executing the running strategy and feeds back the strategy running result to the running management service, and the running management service dynamically adjusts the running strategy based on a deep learning model according to the strategy running result.
[0028] Optionally, the running management service belongs to a feedback control component, sends the running strategy of the heterogeneous execution body to the running node agent, and dynamically adjusts the running strategy according to the strategy running result fed back by the running node agent. Specifically, the historical running strategy and the strategy running result are used to train and learn the model by using a deep learning framework, the weight parameter of the abnormal field type in the running strategy is adjusted according to the running result, so as to realize the intelligentization and precision of the running strategy. For example, using majority decision, majority and minority are only a kind of probability expression, when lacking some priori knowledge or third party opinion, it is difficult to get specific conclusion. However, since the quasi-state decision uses multiple voting strategies and the result weight of auxiliary decision parameter for re-voting, when the auxiliary decision parameter contains the factor of past voting result, such as using the deep learning model to adjust the decision parameter in the running strategy, the quasi-state decision has the meaning of time and space feedback. In the embodiment of the present application, the deep learning framework is used to dynamically adjust the running strategy, which realizes the purpose of providing necessary conditions for the safe and stable running of the heterogeneous execution body, improves the safety, stability and reliability of the system, and reduces the risk of quasi-state escape, that is, prevents the internal sensitive information of the system from being reproduced.
[0029] As an optional embodiment, the running node agent is also used for monitoring the states of the plurality of heterogeneous execution bodies, and sending the states of the plurality of heterogeneous execution bodies to the running management service. The monitoring of the states of the plurality of heterogeneous execution bodies includes: collecting outputs of the plurality of heterogeneous execution bodies and listening to resources of the plurality of heterogeneous execution bodies.
[0030] Optionally, the running node agent is also responsible for monitoring the plurality of heterogeneous execution bodies, specifically including listening to the resource states of the heterogeneous execution bodies, collecting the outputs of the heterogeneous execution bodies, and sending the above information to the running management service, so that the running management service manages the states of the heterogeneous execution bodies or uses the monitored information to help adjust the running strategy. It should be noted that the running node agent can also obtain the abnormal state, process state, system configuration and log of the heterogeneous execution body, and send the above information to the unified service engine to assist the unified service engine in diagnosing the heterogeneous execution body. In the embodiment of the present application, the states and output information of the heterogeneous execution are obtained by monitoring the plurality of heterogeneous execution bodies, which helps to adjust the running strategy or manage the heterogeneous execution body, and further improves the safety, stability and reliability of the system.
[0031] As an optional embodiment, the distribution decision service, the unified service engine and the running management service are applications on the cloud platform, and the running node agent is a proxy of the plurality of heterogeneous execution bodies built on the cloud platform. The applications on the cloud platform and the proxy of the plurality of heterogeneous execution bodies on the cloud platform interact through a communication network.
[0032] Optionally, the quasi-state security system is deployed on the cloud platform, such as Figure 3As shown, the mimic cloud manager, i.e., a running management service, is used for managing a heterogeneous container execution body pool, i.e., a running node agent, which is a proxy of multiple heterogeneous execution bodies built on a cloud platform. The mimic security running support component includes a distribution decision service and a unified service engine, which are both applications on the cloud platform. In addition to scheduling the heterogeneous execution bodies in the heterogeneous container execution body pool, the mimic cloud manager is also responsible for application deployment, service orchestration, monitoring and management of the mimic security running support component and the heterogeneous container execution body pool. In the embodiment of the present application, the mimic security system is deployed on the cloud platform, and the parts interact with each other through a communication network, thereby improving the resistance of the cloud platform to unknown vulnerabilities and uncertain threats.
[0033] According to the second aspect of the embodiment of the present application, a cloud platform security operation and maintenance method using the mimic security system of any one of the first aspect of the embodiment of the present application is also provided, and the method comprises: using the mimic security system to perform security operation and maintenance on the cloud platform. Optionally, existing cloud platforms are mostly passive defense based on prior knowledge, such as using known virus features to establish a virus library against the virus, and patching the system through known vulnerabilities. Such passive defense is difficult to resist unknown vulnerabilities or backdoors and other uncertain threats. After the cloud platform uses the mimic security system, the heterogeneous execution bodies, i.e., the nodes on the cloud platform, have the characteristics of dynamicity, heterogeneity and redundancy, thereby improving the fault tolerance and reliability of the system, making it difficult for attackers to effectively probe and coordinate attacks. Moreover, each node is scheduled through a running strategy, can timely discover abnormalities, repair them, and maintain the balance and stability of the system. In the embodiment of the present application, the cloud platform is subjected to security operation and maintenance based on the mimic security system, thereby improving the reliability, security and resistance to unknown attacks of the cloud platform.
[0034] As an optional embodiment, the security operation and maintenance of the cloud platform using the mimic security system comprises: making decisions and scheduling management of the heterogeneous execution bodies in the cloud platform based on the mimic security system; and accessing dynamic data and heterogeneous data in the cloud platform based on high-security data protection technology. Optionally, the security operation and maintenance of the cloud platform using the mimic security system not only relies on scheduling and decision-making and cleaning and recovery of the heterogeneous execution bodies, but also includes, based on high-security data protection technology, cutting multiple data into multiple protection parts according to business requirements and application scenarios, each protection part having a different protection strategy, so that an attack data access cannot access all data in space, thereby ensuring the security of data access on the cloud platform.
[0035] As an optional embodiment, the heterogeneous execution entities in the cloud platform are adjudicated and scheduled based on the mimicry security system, including: adjudication technology based on the self-evolution model to adjudicate the heterogeneous execution entities in the cloud platform; and cleaning, restoring or reconstructing abnormal heterogeneous execution entities based on the rapid scheduling management and cleaning and recovery technology of heterogeneous execution entities, wherein the reconstruction includes changing the components or background tasks of the heterogeneous execution entities.
[0036] Optionally, the multi-mode adjudication technology based on the self-evolution model addresses the problem of adjudicating the output results of heterogeneous executors by dynamically adjusting the multi-mode adjudication strategy. After adjudication, heterogeneous executors are often scheduled and cleaned, including the rotational deployment and cleanup recovery of heterogeneous executors in the spatiotemporal dimensions. Specifically, the rapid scheduling management and cleanup recovery technology for heterogeneous executors uses various methods such as reconstruction, reorganization, and redefinition to change the dissimilarity within the active defense system, thereby disrupting the synergy of attacks and the inheritability of phased results, rendering software and hardware vulnerabilities and backdoors ineffective or unusable. It should be noted that the objects of scheduling management and cleanup recovery include reconfigurable or software-definable heterogeneous executor entities or virtual resources. New functionally equivalent heterogeneous executors can be generated based on the degree of heterogeneity or the reconstruction and reorganization strategy. Alternatively, certain components can be replaced in existing heterogeneous executors, such as reconfiguring resources by replacing parts in the current heterogeneous executor, or adding or removing background tasks to the heterogeneous executor, changing its operating scenario, etc., to achieve the reconstruction of the heterogeneous executor.
[0037] As an optional embodiment, the adjudication technology based on the self-evolution model adjudicates multiple heterogeneous executors, including: obtaining the historical operation strategies and strategy operation results of multiple heterogeneous executors; training a deep learning model based on the historical operation strategies and strategy operation results; and dynamically adjusting the operation strategy using the trained deep learning model.
[0038] Optionally, by training a deep learning model with the historical execution strategies and results of heterogeneous executors, the adjudication parameters in the execution strategy can be dynamically adjusted. Since the adjudication operation is usually an iterative process with feedback, using a deep learning model to learn from historical data and dynamically adjust the execution strategy achieves the effect of making the execution strategy more intelligent and accurate. In addition, for the numerical and complex output results of heterogeneous executors, multiple adjudication strategies are provided, such as direct numerical comparison, data stream comparison, or field content comparison. Different fields are classified and retrieved through spanning trees and weighted methods, thereby reducing adjudication latency.
[0039] As an optional embodiment, the high-security data protection technology is used for accessing dynamic data and heterogeneous data, including: using a segmented protection strategy to access dynamic data in a segmented structure; using data distribution and state synchronization technology to access heterogeneous data among multiple heterogeneous executors. Optionally, the high-security data protection technology is based on the segmented data security protection technology of the application strategy, and constructs a dynamic data access and heterogeneous data collaboration multi-element data protection architecture with endogenous security characteristics, to form a data protection scheme with reference variables of application scene data volume, data type and read-write frequency. Specifically, for the dynamic data access architecture, the multi-element data is segmented according to business defense requirements, each segment is called a segment structure, representing each protected part after segmentation. Based on single or comprehensive dynamic, heterogeneous, redundant technology, the protection strategies of each segment structure are different, thereby ensuring the security of data access. For the heterogeneous data access collaboration architecture, the existing cloud data distribution and state synchronization technology is used to solve the data distribution and state synchronization problem of each heterogeneous body, so that each heterogeneous body can realize synchronous data access and operation, and realize the access and operation between the cloud platform storage device and the database under the quasi-defense mechanism.
[0040] As an optional embodiment, Figure 4 is a schematic diagram of a cloud network integrated distributed quasi-state security architecture according to an embodiment of the application, as Figure 4 shown, the architecture is based on an autonomous controllable software and hardware platform, uses a dynamic, heterogeneous, redundant architecture design idea, integrates the cloud platform and the communication network to realize a distributed quasi-state security architecture. The hardware layer uses heterogeneous domestic processors such as Feiteng, Kunpeng, Shenwei, etc., and the operating system uses depth, Zhongtian Kirin, Yinhe Kirin, etc., thereby forming a heterogeneous executor running environment. The vulnerabilities and backdoors among different executors are dispersed, a distribution agent, a multi-mode decision and a feedback control component are constructed based on the micro-service technology, and a time and space multi-dimensional dynamic variable quasi-state security running support environment is formed.
[0041] The four parts include a distribution decision service for sending a service request, i.e., an operation to be performed, and a scheduling decision method to a running node agent (an agent of each heterogeneous executor), wherein the scheduling decision method includes a synchronous decision, an asynchronous decision, a normal type decision, and a complex type decision. The running node agent is used to build a link between other parts and the heterogeneous executor, such as accepting the service request, performing the operation corresponding to the service request by each heterogeneous executor, collecting node data, i.e., monitoring the node state, including collecting the output of each heterogeneous executor and listening to the resources of each heterogeneous executor, and sending the service request result of the heterogeneous executor to the unified service engine. The unified service engine accesses the request result sent by each heterogeneous executor through a unified interface, and performs service request analysis, service request threat diagnosis, and service request threat cleaning according to the service request result. The heterogeneous executor that is diagnosed to have a problem is cleaned and recovered, including the creation of a secure heterogeneous executor. That is, the unified service engine controls the running node agent to perform heterogeneous executor cleaning and heterogeneous executor recovery, in addition, the running node agent is also responsible for the executor communication service.
[0042] The running management service belongs to a feedback control component, and is responsible for a running management portal, a mimicry strategy management, a mimicry strategy distribution, an executor scheduling, an executor pool management, an executor deployment, a node state management, and an executor load balancing. The running management service sends a running strategy to the running node agent, learns historical decision records by using a deep learning framework according to a strategy running result, so as to dynamically adjust the weight of an abnormal field type of a decision, and realizes the intelligentization and the precision of the decision strategy. In the embodiment of the present application, the cloud network fusion distributed mimicry security architecture is adopted, the initiative of the cloud platform security operation and maintenance is improved, the operation and maintenance of the cloud platform can be realized while the cloud platform business is operated, and the correlation of the cloud platform business and the operation and maintenance is improved.
[0043] According to a third aspect of the embodiment of the present application, a storage medium is also provided. Optionally, in the embodiment, the storage medium can be used to execute the program code of the cloud platform security operation and maintenance method.
[0044] Optionally, in the embodiment, the storage medium can be located on at least one of the plurality of network devices in the network shown in the above embodiment.
[0045] Optionally, the specific examples in the embodiment can refer to the examples described in the above embodiment, and the embodiment will not be described here.
[0046] Optionally, in the embodiment, the storage medium can include but is not limited to a U disk, a ROM, a RAM, a mobile hard disk, a magnetic disk, or an optical disk, and various media that can store program codes.
[0047] The above-mentioned serial numbers of the embodiments of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments. In the above-mentioned embodiments of the present application, the description of each embodiment is focused on, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments. The above-mentioned is only the preferred embodiment of the present application, and it should be pointed out that for ordinary skilled in the art, without departing from the principle of the present application, a number of improvements and refinements can be made, and these improvements and refinements should be regarded as the protection scope of the present application.
Claims
1. A mimicry security system, characterized by, The system comprises a distribution decision service, a unified service engine and a running node agent; The running node agent receives a service request sent by the distribution decision service, controls a plurality of heterogeneous execution bodies to execute operations corresponding to the service request, and generates a service request result according to the states of the plurality of heterogeneous execution bodies after the operations corresponding to the service request are executed; The unified service engine receives the service request result, controls the running node agent to clean, recover or reconstruct an abnormal heterogeneous execution body according to the service request result; the reconstruction of the heterogeneous execution body comprises generating a new functionally equivalent heterogeneous execution body or replacing some components in an existing heterogeneous execution body; a self-evolution model-based decision technology is used to make decisions on the heterogeneous execution bodies in the cloud platform; a self-evolution model-based multi-mode decision technology is used to make decisions on the output result discrimination problems of the heterogeneous execution bodies, dynamically adjust the multi-mode decision strategy, and schedule and clean the heterogeneous execution bodies after the decisions are made, including heterogeneous body rotation deployment and cleaning and recovery in the time and space dimensions; The system further comprises a running management service, which sends a running strategy to the running node agent, the running node agent generates a strategy running result after executing the running strategy and feeds back the strategy running result to the running management service, and the running management service dynamically adjusts the running strategy based on a deep learning model according to the strategy running result; The running node agent is further configured to monitor the states of the plurality of heterogeneous execution bodies and send the states of the plurality of heterogeneous execution bodies to the running management service, wherein the monitoring of the states of the plurality of heterogeneous execution bodies comprises collecting the outputs of the plurality of heterogeneous execution bodies and listening to the resources of the plurality of heterogeneous execution bodies; The distribution decision service, the unified service engine and the running management service are applications on the cloud platform, the running node agent is a proxy of the plurality of heterogeneous execution bodies built on the cloud platform, and the applications on the cloud platform and the proxy of the plurality of heterogeneous execution bodies on the cloud platform interact through a communication network.
2. A cloud platform security operation method using the quasistate security system of claim 1, characterized in that, The method comprises using a paratopic security system to perform security operation and maintenance on the cloud platform.
3. The cloud platform security operation and maintenance method according to claim 2, characterized in that, The use of the paratopic security system to perform security operation and maintenance on the cloud platform comprises: Making decisions on and scheduling management of the heterogeneous execution bodies in the cloud platform based on the paratopic security system; Accessing dynamic data and heterogeneous data in the cloud platform based on high-security data protection technology.
4. The cloud platform security operation and maintenance method according to claim 3, characterized in that, The making decisions on and scheduling management of the heterogeneous execution bodies in the cloud platform based on the paratopic security system comprises: Making decisions on the heterogeneous execution bodies in the cloud platform based on a self-evolution model-based decision technology; Cleaning, recovering or reconstructing an abnormal heterogeneous execution body based on a heterogeneous execution body rapid scheduling management and cleaning recovery technology, wherein the reconstruction comprises changing components or background tasks of the heterogeneous execution body.
5. The cloud platform security operation and maintenance method according to claim 4, characterized in that, The making decisions on the plurality of heterogeneous execution bodies based on the self-evolution model-based decision technology comprises: Obtaining historical running strategies and strategy running results of the plurality of heterogeneous execution bodies; Training a deep learning model according to the historical running strategies and the strategy running results; Dynamically adjusting the running strategy by using the trained deep learning model.
6. The cloud platform security operation and maintenance method according to claim 3, characterized in that, The accessing of the dynamic data and the heterogeneous data based on the high-security data protection technology comprises: The segmented protection strategy is used to access dynamic data in a segmented structure. Data distribution and state synchronization technology is used to access heterogeneous data among multiple heterogeneous executors.
7. A computer readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is executed by the processor to implement the method steps in any one of claims 2 to 6.
Citation Information
Patent Citations
Secure cloud service construction method and device based on mimic defense
CN107454082A
Emergency system safety protection strategy optimization method and device
CN109302421A
Multi-mode decision negative feedback system based on multi-objective optimization algorithm
CN114826782A