A method and system for testing abnormal nodes of an edge network

By analyzing test request and response messages from cloud computing centers in edge networks, and combining LSTM and deep residual network models, malicious nodes can be identified and located, thus solving the vulnerability of malicious node detection in edge networks and achieving efficient malicious node identification and location.

CN116647362BActive Publication Date: 2026-02-24CHINA ELECTRONICS STANDARDIZATION INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310366066.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-07
Publication Date
2026-02-24
Estimated Expiration
2043-04-07

AI Technical Summary

Technical Problem

Existing malicious node detection methods are easily exploited by intruders in edge networks, leading to the consumption of network resources and system interference in cloud centers. There is a lack of effective malicious node detection methods.

Method used

The cloud computing center sends test request messages to edge nodes, generates and analyzes response messages, uses LSTM neural networks and deep residual network models to judge the node's quadruple data, determines the confidence level of candidate malicious nodes, and locates malicious nodes by combining data tampering and forwarding delay attack behaviors.

Benefits of technology

It improves the accuracy and efficiency of malicious node detection in edge networks, reduces the impact of noise, and can identify and locate malicious nodes that engage in data tampering and latency attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116647362B_ABST
    Figure CN116647362B_ABST
Patent Text Reader

Abstract

The application provides a method and system for testing abnormal nodes of an edge network, and belongs to the technical field of 5G communication. The edge network is a network composed of a plurality of edge nodes in a cloud computing network, and the cloud computing network further comprises a cloud computing center and a plurality of non-edge nodes. The method determines whether the edge nodes are malicious nodes by testing the edge nodes, and further determines the attack behavior types of the malicious nodes, including data tampering attack behavior and forwarding delay attack behavior.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of 5G communication, and particularly relates to a method and system for testing abnormal nodes of an edge network. BACKGROUND

[0002] Edge computing migrates part or all of the computing tasks of the original cloud computing model to the network edge, effectively reduces the network bandwidth and computing load of the cloud data center, and can also well solve the specific requirements of certain tasks such as high latency requirement, frequent movement, strong geographic information perception, etc. The edge computing model has also received extensive attention from the academic and industrial circles. With the deepening of the process of digital transformation of the industry, the transition of the edge computing network architecture will inevitably lead to an increasing number of security attacks on edge computing nodes such as cloud edge, edge cloud, and cloud gateway. The edge security problem has become one of the obstacles to the development of the edge computing industry.

[0003] Since the network edge side is closer to the user terminal, each edge node is also more susceptible to attacks and becomes a malicious node, etc. Edge cloud anomalies caused by malicious device intrusion and hacker intrusion will consume the network resources of the cloud center network, return incorrect task results, interfere with the operation of the entire cloud computing system, and other behaviors, which pose a threat to the entire network system. Therefore, it is necessary to develop a malicious node detection method for the edge network.

[0004] There are many methods for malicious node detection algorithms at present, such as methods based on routing protocols, hidden Markov chains, biological principles, game theory, neighbor monitoring, clustering principles, and even machine learning-based detection methods. The intrusion detection system is a main technology for preventing malicious intrusion of the cloud edge. This kind of traditional intrusion detection technology mainly detects abnormal data on the host side or the network side through monitoring and detection, and usually uses rules set by human experience for detection. The disadvantage is that it is easy to be caught by intruders. SUMMARY

[0005] In order to solve the above technical problems, the application provides a scheme for testing abnormal nodes of an edge network.

[0006] The first aspect of the present application discloses a method for testing abnormal nodes of an edge network. The edge network is a network composed of a plurality of edge nodes in a cloud computing network, the cloud computing network further comprising a cloud computing center and a plurality of non-edge nodes; the method comprises: step S1, the cloud computing center sends a test request message to a to-be-tested edge node, the to-be-tested edge node generates a test response message based on a test sequence in the test request message, and sends the test response message to the cloud computing center; step S2, after receiving the test response message, the cloud computing center determines a first candidate malicious node and a second candidate malicious node from the to-be-tested edge node based on a response sequence in the test response message; step S3, a risk network including the first candidate malicious node and the second candidate malicious node is generated, and four-tuple data of each candidate malicious node in the risk network is obtained; step S4, the four-tuple data of each candidate malicious node is used to determine a first confidence of the candidate malicious node about data tampering attack behavior and a second confidence about forwarding delay attack behavior, so as to determine a malicious node from the candidate malicious nodes.

[0007] Among them, the first candidate malicious node is a malicious node with data tampering attack behavior, and the second candidate malicious node is a malicious node with forwarding delay attack behavior.

[0008] Among them, the four-tuple data is <source port, data volume, communication protocol, time stamp>, the source port is the port address of the other candidate malicious node having a communication interaction relationship with the current candidate malicious node, the data volume is the communication data volume from the other candidate malicious node, the communication protocol is the communication protocol between the current candidate malicious node and the other candidate malicious node, and the time stamp is the time point at the peak of the communication data volume between the current candidate malicious node and the other candidate malicious node.

[0009] According to the method of the first aspect of the present invention, before step S1, the method further includes: step S01, the cloud computing center sends N standard test request messages {req, N} to N standard edge nodes, the standard edge nodes generate standard test response messages {resp, N} based on the standard test sequence req in the standard test request messages {req, N}, and send the standard test response messages {resp, N} to the cloud computing center; step S02, after receiving the standard test response messages {resp, N}, the cloud computing center determines a standard test response data reference value and a standard test transmission delay reference value based on the standard response sequence resp in the test response messages {resp, N}; wherein, the standard test sequence req includes the IP address of the standard edge node, standard test data, and a standard test request timestamp t. o The standard edge node uses its own computing resources to parse the standard test sequence req and process the standard test data; the standard response sequence resp in the standard test response message {resp, N} includes the IP address of the standard edge node, the standard response data corresponding to the standard test data, and the standard test forwarding timestamp t. o .

[0010] According to the method of the first aspect of the present invention, in step S02, determining the standard test response data reference value and the standard test transmission delay reference value specifically includes: acquiring N standard response data of the i-th standard edge node. For i = 1, 2, 3, ... N, calculate the average standard response data of the i-th standard edge node: The average of the minimum standard response data among the N standard edge nodes. and the average value of the maximum standard response data As a reference value for the standard test response data m represents the number of the standard edge node corresponding to the minimum standard response data average value, and n represents the number of the standard edge node corresponding to the maximum standard response data average value; calculate the standard test average transmission delay of N standard edge nodes. The standard test transmission delay reference value is given by j, where j represents the test number.

[0011] According to the method of the first aspect of the present invention, in step S1, the test request message has the same definition structure as the standard test request message, and the test response message has the same definition structure as the standard test response message; in step S2, the average response data ki of each edge node to be tested is calculated based on the same method as in step S02, and the mean square error Δki is further calculated; and the average transmission delay Ti of each edge node to be tested in N tests is calculated based on the same method as in step S02, and the transmission delay ratio is further calculated. In step S2, determining the first candidate malicious node and the second candidate malicious node from the edge nodes to be tested specifically includes: calculating the reputation of the i-th edge node to be tested. When Ri is less than the reputation threshold R, the i-th edge node to be tested is determined to be a candidate malicious node, and the candidate malicious node is located based on its IP address; wherein, when the average response data ki of the candidate malicious node is not in the standard test response data reference value When the average transmission delay Ti of the candidate malicious node is within the specified range, the candidate malicious node is determined to be the first candidate malicious node; wherein, when the average transmission delay Ti of the candidate malicious node is greater than Tave, the candidate malicious node is determined to be the second candidate malicious node.

[0012] According to the method of the first aspect of the present invention, in step S3, the communication interaction relationship between the current candidate malicious node and other candidate malicious nodes is obtained, the communication interaction relationship including direct communication interaction relationship and indirect communication interaction relationship realized through one-hop or two-hop relay of the non-edge node.

[0013] According to the method of the first aspect of the present invention, in step S4, determining the first confidence level and the second confidence level using the quadruple data of each of the candidate malicious nodes specifically includes: for each candidate malicious node, inputting the first triplet data <data volume, communication protocol, timestamp> into an LSTM neural network model to calculate the first confidence level {a1,…,a...} i ,…,a num The second triplet data <source port, data volume, communication protocol> is input into the deep residual network model to calculate the second confidence level {b1,…,b}. i ,…,b num}, where num represents the number of other candidate malicious nodes that have the communication interaction relationship with the current candidate malicious node.

[0014] According to the method of the first aspect of the present invention, in step S4, determining the malicious node from the candidate malicious nodes specifically includes: obtaining the convergence time t1 of the LSTM neural network model and the convergence time t2 of the deep residual network model, so as to calculate the comprehensive confidence level c of the other candidate malicious nodes that have the communication interaction relationship with the current candidate malicious node relative to the current candidate malicious node. i =t2×a i +t1×b i ; Obtain the confidence scores {c1,…,c} of num other candidate malicious nodes relative to the current candidate malicious node. i ,…,c num}, to calculate the final confidence level of the current candidate malicious node. When the final confidence level is lower than the threshold, the current candidate malicious node is determined to be the malicious node; the number of the first candidate malicious node and the number of the second candidate malicious node are obtained, and the weight w1 for the data tampering attack behavior and the weight w2 for the forwarding delay attack behavior are determined by normalizing the number; the first score of the malicious node for the data tampering attack behavior, total1 = (C s +w1)R and the second fractional value total2 = (C) regarding the forwarding delay attack behavior s +w2)R, and determine the type of attack behavior of the malicious node based on the first score and the second score.

[0015] A second aspect of the present invention discloses a system for testing abnormal nodes in an edge network. The edge network is a network composed of several edge nodes in a cloud computing network, which also includes a cloud computing center and several non-edge nodes; the system includes a processing unit, wherein:

[0016] The processing unit sends a first instruction to the cloud computing center, the cloud computing center sends a test request message to the edge node to be tested based on the first instruction, the edge node to be tested generates a test response message based on the test sequence in the test request message, and sends the test response message to the cloud computing center;

[0017] After receiving the test response message, the cloud computing center sends the test response message to the processing center. Based on the response sequence in the test response message, the processing center determines the first candidate malicious node and the second candidate malicious node from the edge nodes to be tested.

[0018] Among them, the first candidate malicious node is a malicious node that has data tampering attack behavior, and the second candidate malicious node is a malicious node that has forwarding delay attack behavior;

[0019] The processing center sends a second instruction to the cloud computing network, and the cloud computing network generates a risk network including the first candidate malicious node and the second candidate malicious node based on the second instruction. The processing center obtains the quadruple data of each candidate malicious node in the risk network.

[0020] Wherein, the quadruple data is <source port, data volume, communication protocol, timestamp>, the source port is the port address of other candidate malicious nodes that have a communication interaction relationship with the current candidate malicious node, the data volume is the communication data volume from the other candidate malicious nodes, the communication protocol is the communication protocol between the current candidate malicious node and the other candidate malicious nodes, and the timestamp is the time point at the peak of the communication data volume between the current candidate malicious node and the other candidate malicious nodes;

[0021] The processing center uses the quadruple data of each candidate malicious node to determine the first confidence level of each candidate malicious node regarding data tampering attack behavior and the second confidence level regarding forwarding delay attack behavior, so as to identify the malicious node from each candidate malicious node.

[0022] A third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method for testing abnormal nodes in an edge network as described in the first aspect of the present invention.

[0023] A fourth aspect of the present invention discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the method for testing abnormal nodes in an edge network as described in the first aspect of the present invention.

[0024] In summary, the technical solution of this invention sends test requests to each edge network node through the cloud center network node and collects relevant communication response data to determine whether the edge node is a malicious node. This method uses absolutely trustworthy edge nodes as reference nodes, and multiple tests help reduce the impact of noise in the network system. Simultaneously, it can also determine the malicious attack behavior present in malicious nodes and the corresponding IP addresses of malicious edge nodes based on the data in the reference dataset, thus locating them within the network structure. Attached Figure Description

[0025] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0026] Figure 1 A flowchart illustrating a method for testing abnormal nodes in an edge network according to an embodiment of the present invention;

[0027] Figure 2 This is a structural diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0029] The first aspect of this invention discloses a method for testing abnormal nodes in an edge network, wherein the edge network is a network composed of several edge nodes in a cloud computing network, and the cloud computing network also includes a cloud computing center and several non-edge nodes. Figure 1 This is a flowchart of a method for testing abnormal nodes in an edge network according to an embodiment of the present invention; as follows: Figure 1As shown, the method includes: Step S1, the cloud computing center sends a test request message to the edge node to be tested, the edge node to be tested generates a test response message based on the test sequence in the test request message, and sends the test response message to the cloud computing center; Step S2, after receiving the test response message, the cloud computing center determines a first candidate malicious node and a second candidate malicious node from the edge nodes to be tested based on the response sequence in the test response message (wherein, the first candidate malicious node is a malicious node with data tampering attack behavior, and the second candidate malicious node is a malicious node with forwarding delay attack behavior); Step S3, a risk network including the first candidate malicious node and the second candidate malicious node is generated, and the first candidate malicious node and the second candidate malicious node are obtained. Each candidate malicious node in the network has a quadruple data set in the risk network (wherein, the quadruple data set is <source port, data volume, communication protocol, timestamp>, the source port is the port address of other candidate malicious nodes that have a communication interaction relationship with the current candidate malicious node, the data volume is the communication data volume from the other candidate malicious nodes, the communication protocol is the communication protocol between the current candidate malicious node and the other candidate malicious nodes, and the timestamp is the time point at the peak of the communication data volume between the current candidate malicious node and the other candidate malicious nodes); Step S4: Use the quadruple data set of each candidate malicious node to determine the first confidence level of each candidate malicious node regarding data tampering attack behavior and the second confidence level of each candidate malicious node regarding forwarding delay attack behavior, so as to identify malicious nodes from each candidate malicious node.

[0030] Specifically, suppose an existing network system has a central cloud node capable of providing various necessary cloud computing and data storage services. At the edge of this network system, numerous edge servers are distributed, acting as edge nodes and forming an edge cloud system. The central cloud node can distribute some or all of its computing programs to these edge nodes, thus effectively reducing the computational load and network bandwidth of the central cloud node under massive data processing conditions, while also solving problems such as high latency. Simultaneously, each edge node connects to numerous terminal nodes, which act as data collection portals and interact directly with users.

[0031] Specifically, when a communication node is attacked by an external intruder, two main attack effects are considered: one is a malicious data tampering attack. When the node is a normal node, it communicates with the cloud center network node according to the designed communication rules, and the data traffic of the communication response is also constant. If the node is attacked, the traffic data will be tampered with, and the data forwarded to the cloud center network node will have a significant deviation. The other is a time attack. This means that the maliciously compromised node will deliberately prolong the time it takes to send data packets. The definition of time prolongation is not unique. In some instances, the node's data packet transmission delay ratio can be used to represent a node's malicious time attack behavior. After a node is maliciously compromised, it will generate a large transmission delay.

[0032] In a preferred embodiment, before step S1, the method further includes: Step S01, the cloud computing center sends N standard test request messages {req, N} to N standard edge nodes, and the standard edge nodes generate standard test response messages {resp, N} based on the standard test sequence req in the standard test request messages {req, N}, and send the standard test response messages {resp, N} to the cloud computing center; Step S02, after receiving the standard test response messages {resp, N}, the cloud computing center determines the standard test response data reference value and the standard test transmission delay reference value based on the standard response sequence resp in the test response messages {resp, N}; wherein, the standard test sequence req includes the IP address of the standard edge node, standard test data, and standard test request timestamp t. o The standard edge node uses its own computing resources to parse the standard test sequence req and process the standard test data; the standard response sequence resp in the standard test response message {resp, N} includes the IP address of the standard edge node, the standard response data corresponding to the standard test data, and the standard test forwarding timestamp t. o .

[0033] Specifically, a reference dataset is collected and threshold values ​​are set. In the described network system, N edge nodes are selected as reference nodes, ensuring they are normal nodes and not maliciously compromised. The cloud center network node broadcasts a test request message {req, N} to the N reference nodes, where req is the test sequence, containing the requesting node's IP address, test data, and request time. To reduce the impact of channel noise on the communication results, N test request messages are sent to each reference node. After receiving the test request message from the cloud center network node, the N reference nodes immediately use their computing power to parse and generate a response message {resp, N}, where resp is the response sequence, corresponding to the calculation result of the test sequence, such as {node IP address, response data K, forwarding timestamp}. The N reference nodes forward the response message {resp, N} to the cloud center network node. Cloud center computation: After receiving the response message from the reference nodes, the cloud center network node immediately performs calculations.

[0034] In a preferred embodiment, determining the standard test response data reference value and the standard test transmission delay reference value in step S02 specifically includes: acquiring N standard response data of the i-th standard edge node. And calculate the average standard response data of the i-th standard edge node: The average of the minimum standard response data among the N standard edge nodes. and the average value of the maximum standard response data As a reference value for the standard test response data m represents the number of the standard edge node corresponding to the minimum standard response data average value, and n represents the number of the standard edge node corresponding to the maximum standard response data average value; calculate the standard test average transmission delay of N standard edge nodes. The standard test transmission delay reference value is given by j, where j represents the test number.

[0035] In a preferred embodiment, in step S1, the test request message has the same defined structure as the standard test request message, and the test response message has the same defined structure as the standard test response message; in step S2, the average response data ki of each edge node under test is calculated using the same method as in step S02, and the mean square error Δki is further calculated; and the average transmission delay Ti of each edge node under test in N tests is calculated using the same method as in step S02, and the transmission delay ratio is further calculated. In step S2, determining the first candidate malicious node and the second candidate malicious node from the edge nodes to be tested specifically includes: calculating the reputation of the i-th edge node to be tested. When Ri is less than the reputation threshold R, the i-th edge node to be tested is determined to be a candidate malicious node, and the candidate malicious node is located based on its IP address; wherein, when the average response data ki of the candidate malicious node is not in the standard test response data reference value When the average transmission delay Ti of the candidate malicious node is within the specified range, the candidate malicious node is determined to be the first candidate malicious node; wherein, when the average transmission delay Ti of the candidate malicious node is greater than Tave, the candidate malicious node is determined to be the second candidate malicious node.

[0036] In a preferred embodiment, in step S3, the communication interaction relationship between the current candidate malicious node and other candidate malicious nodes is obtained. The communication interaction relationship includes direct communication interaction relationship and indirect communication interaction relationship realized through one-hop or two-hop relay of the non-edge node.

[0037] Specifically, a first group of nodes is composed of nodes with potential malicious data tampering attack behavior, a second group of nodes is composed of nodes with potential malicious time attack behavior, and a first risk network is composed of the first group of nodes and the second group of nodes. In the first risk network, based on the traffic and communication information statistics (e.g., within a period, by day or by week), when the traffic and communication information between two edge nodes exceeds a threshold, the communication relationship between each edge node is determined.

[0038] In a preferred embodiment, in step S4, determining the first confidence level and the second confidence level using the quadruplet data of each of the candidate malicious nodes specifically includes: for each candidate malicious node, inputting the first triplet data <data volume, communication protocol, timestamp> into an LSTM neural network model to calculate the first confidence level {a1,…,a...} i ,…,a num The second triplet data <source port, data volume, communication protocol> is input into the deep residual network model to calculate the second confidence level {b1,…,b}. i ,…,b num}, where num represents the number of other candidate malicious nodes that have the communication interaction relationship with the current candidate malicious node.

[0039] In a preferred embodiment, in step S4, determining the malicious node from the candidate malicious nodes specifically includes: obtaining the convergence time t1 of the LSTM neural network model and the convergence time t2 of the deep residual network model, so as to calculate the comprehensive confidence level c of the other candidate malicious nodes that have the communication interaction relationship with the current candidate malicious node relative to the current candidate malicious node. i =t2×a i +t1×b i ; Obtain the confidence scores {c1,…,c} of num other candidate malicious nodes relative to the current candidate malicious node. i ,…,c num}, to calculate the final confidence level of the current candidate malicious node. When the final confidence level is lower than the threshold, the current candidate malicious node is determined to be the malicious node; the number of the first candidate malicious node and the number of the second candidate malicious node are obtained, and the weight w1 for the data tampering attack behavior and the weight w2 for the forwarding delay attack behavior are determined by normalizing the number; the first score of the malicious node for the data tampering attack behavior, total1 = (C s +w1)R and the second fractional value total2 = (C) regarding the forwarding delay attack behavior s +w2)R, and determine the type of attack behavior of the malicious node based on the first score and the second score.

[0040] Specifically, (1) For each edge node in the first risk network: obtain the traffic data and communication data of the previous statistical period at the entrance of the edge node, parse and extract the features of the traffic data and communication data, and generate a quadruple <source port, data volume, protocol, timestamp>, where the source port identifies the data from other edge nodes in the first risk network as the source node, which of the source nodes has traffic data transmitted to the edge node, the data volume is used to estimate the amount of data transmitted to the edge node in the traffic data and communication data according to the log based on the parsing situation, the protocol is the protocol used for communication between the parsed source node and the edge node, and the timestamp is the time point when the data volume between the source node and the edge node is at its peak.

[0041] (2) Based on the above analysis, for each edge node in the first risk network: the multiple quadruplets extracted from the edge node are used to construct a time series LSTM with timestamps. The <data volume, protocol, timestamp> is input into the LSTM neural network model, and the <source port, data volume, protocol> is input into the deep residual network model. The <data volume, protocol, timestamp> is input into the LSTM neural network model to obtain the first score sequence {a1,…,a i ,…,anum-1}, where num is the number of edge nodes in the first risk network, and each score represents the confidence level of the influence of each other edge node on that edge node in the first risk network. <source port, data volume, protocol> are input into the deep residual network to obtain the second score sequence {b1,…,b i ,…,b num-1 Based on the first and second scores, a comprehensive score is obtained, which serves as the confidence level of the marginal node's influence on each other marginal node in the first risk network. The comprehensive score is calculated by determining the weights of the first and second score sequences based on the inverse ratio of the convergence times of the two models. For example, if the first model converges at time1 and the second model at time2, then after normalizing the two times, we obtain t1 and t2 respectively, which are used as the weights of the second and first score sequences. Therefore, the confidence level of the marginal node's influence on marginal node number 1 is c1 = c i =t2×a i +t1×b i Let the overall confidence level of a node be denoted as {c1,…,c i ,…,c num-1 If the final confidence level of the node is}, then the final confidence level of the node is denoted as}.

[0042] Each model is an existing model, with training samples constructed from historical data to obtain a stable LSTM neural network model and a deep residual network model. It combines the advantages of multiple models, leveraging the time-memory advantage of LSTM and using the output of the deep residual network to correct the LSTM model's tendency to get trapped in local optimization. Furthermore, by selecting different features for the same sample data, it can fully reflect various information of the sample, obtaining a high-accuracy, comprehensive confidence level.

[0043] For each edge node in the first risk network, a second reputation value is calculated based on its reputation value, according to whether it belongs to a malicious data tampering attack or a malicious time attack, and the corresponding final confidence level. Nodes with a second reputation value lower than a preset threshold are designated as final abnormal nodes. Weights w1 and w2 are determined based on the number of nodes belonging to malicious data tampering attacks and malicious time attacks, with higher weights for more nodes and lower weights for fewer nodes. The node's final reputation value is: totle1 = (C s +w1)R, where w is the weight of the node corresponding to the data tampering attack or malicious time attack type.

[0044] A second aspect of the present invention discloses a system for testing abnormal nodes in an edge network. The edge network is a network composed of several edge nodes in a cloud computing network, which also includes a cloud computing center and several non-edge nodes; the system includes a processing unit, wherein:

[0045] The processing unit sends a first instruction to the cloud computing center, the cloud computing center sends a test request message to the edge node to be tested based on the first instruction, the edge node to be tested generates a test response message based on the test sequence in the test request message, and sends the test response message to the cloud computing center;

[0046] After receiving the test response message, the cloud computing center sends the test response message to the processing center. Based on the response sequence in the test response message, the processing center determines the first candidate malicious node and the second candidate malicious node from the edge nodes to be tested.

[0047] Among them, the first candidate malicious node is a malicious node that has data tampering attack behavior, and the second candidate malicious node is a malicious node that has forwarding delay attack behavior;

[0048] The processing center sends a second instruction to the cloud computing network, and the cloud computing network generates a risk network including the first candidate malicious node and the second candidate malicious node based on the second instruction. The processing center obtains the quadruple data of each candidate malicious node in the risk network.

[0049] Wherein, the quadruple data is <source port, data volume, communication protocol, timestamp>, the source port is the port address of other candidate malicious nodes that have a communication interaction relationship with the current candidate malicious node, the data volume is the communication data volume from the other candidate malicious nodes, the communication protocol is the communication protocol between the current candidate malicious node and the other candidate malicious nodes, and the timestamp is the time point at the peak of the communication data volume between the current candidate malicious node and the other candidate malicious nodes;

[0050] The processing center uses the quadruple data of each candidate malicious node to determine the first confidence level of each candidate malicious node regarding data tampering attack behavior and the second confidence level regarding forwarding delay attack behavior, so as to identify the malicious node from each candidate malicious node.

[0051] A third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the steps of the method for testing abnormal nodes in an edge network as described in the first aspect of the present invention.

[0052] Figure 2 This is a structural diagram of an electronic device according to an embodiment of the present invention; as shown below. Figure 2 As shown, the electronic device includes a processor, memory, communication interface, display screen, and input device connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, Near Field Communication (NFC), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input device can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the device's casing, or an external keyboard, touchpad, or mouse.

[0053] Those skilled in the art will understand that Figure 2 The structure shown is merely a structural diagram of the part related to the technical solution of this disclosure and does not constitute a limitation on the electronic device to which the solution of this application is applied. The specific electronic device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0054] A fourth aspect of the present invention discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the method for testing abnormal nodes in an edge network as described in the first aspect of the present invention.

[0055] In summary, the technical solution of this invention sends test requests to each edge network node through the cloud center network node and collects relevant communication response data to determine whether the edge node is a malicious node. This method uses absolutely trustworthy edge nodes as reference nodes, and multiple tests help reduce the impact of noise in the network system. Simultaneously, it can also determine the malicious attack behavior present in malicious nodes and the corresponding IP addresses of malicious edge nodes based on the data in the reference dataset, thus locating them within the network structure.

[0056] Please note that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments have been described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification. The above embodiments only illustrate several implementation methods of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be pointed out that for those skilled in the art, several modifications and improvements can be made without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.

Claims

1. A method for testing abnormal nodes in an edge network, characterized in that, The edge network is a network composed of several edge nodes in a cloud computing network, which also includes a cloud computing center and several non-edge nodes; the method includes: Step S1: The cloud computing center sends a test request message to the edge node to be tested. The edge node to be tested generates a test response message based on the test sequence in the test request message and sends the test response message to the cloud computing center. Step S2: After receiving the test response message, the cloud computing center determines the first candidate malicious node and the second candidate malicious node from the edge nodes to be tested based on the response sequence in the test response message. Wherein, the first candidate malicious node is a malicious node that has data tampering attack behavior, and the second candidate malicious node is a malicious node that has forwarding delay attack behavior; Step S3: Generate a risk network including the first candidate malicious node and the second candidate malicious node, and obtain the quadruple data of each candidate malicious node in the risk network. Wherein, the quadruple data is <source port, data volume, communication protocol, timestamp>, the source port is the port address of other candidate malicious nodes that have a communication interaction relationship with the current candidate malicious node, the data volume is the communication data volume from the other candidate malicious nodes, the communication protocol is the communication protocol between the current candidate malicious node and the other candidate malicious nodes, and the timestamp is the time point at the peak of the communication data volume between the current candidate malicious node and the other candidate malicious nodes; Step S4: Using the four-tuple data of each candidate malicious node, determine the first confidence level of the candidate malicious node regarding data tampering attack behavior and the second confidence level regarding forwarding delay attack behavior, so as to identify the malicious node from the candidate malicious nodes; wherein, before step S1, the method further includes: Step S01: The cloud computing center sends N standard test request messages {req, N} to N standard edge nodes. The standard edge nodes generate a standard test response message {resp, N} based on the standard test sequence req in the standard test request message {req, N}, and send the standard test response message {resp, N} to the cloud computing center. Step S02: After receiving the standard test response message {resp, N}, the cloud computing center determines the standard test response data reference value and the standard test transmission delay reference value based on the standard response sequence resp in the test response message {resp, N}. The standard test sequence req includes the standard edge node IP address, standard test data, and standard test request timestamp t. o The standard edge node uses its own computing resources to parse the standard test sequence req and process the standard test data; the standard response sequence resp in the standard test response message {resp, N} includes the IP address of the standard edge node, the standard response data corresponding to the standard test data, and the standard test forwarding timestamp t1.

2. The method for testing abnormal nodes in an edge network according to claim 1, characterized in that, In step S02, determining the standard test response data reference value and the standard test transmission delay reference value specifically includes: Obtain N standard response data of the i-th standard edge node. And calculate the average standard response data of the i-th standard edge node: The average of the minimum standard response data among the N standard edge nodes. and the average value of the maximum standard response data As a reference value for the standard test response data m represents the number of the standard edge node corresponding to the minimum standard response data average value, and n represents the number of the standard edge node corresponding to the maximum standard response data average value; Calculate the standard test average transmission delay for N standard edge nodes. The standard test transmission delay reference value is given by j, where j represents the test number.

3. A method for testing abnormal nodes in an edge network according to any one of claims 1-2, characterized in that: In step S1, the test request message has the same definition structure as the standard test request message, and the test response message has the same definition structure as the standard test response message. In step S2, the average response data ki of each edge node under test is calculated using the same method as in step S02, and the mean square error Δki is further calculated; and the average transmission delay Ti of each edge node under test in N tests is calculated using the same method as in step S02, and the transmission delay ratio is further calculated. In step S2, determining the first candidate malicious node and the second candidate malicious node from the edge nodes to be tested specifically includes: Calculate the reputation of the i-th edge node to be tested. When Ri is less than the reputation threshold R, the i-th edge node to be tested is determined to be a candidate malicious node, and the candidate malicious node is located based on its IP address. Wherein, the average response data ki of the candidate malicious node is not in the standard test response data reference value. When the range is reached, the candidate malicious node is determined to be the first candidate malicious node; Specifically, when the average transmission delay Ti of the candidate malicious node is greater than Tave, the candidate malicious node is determined to be the second candidate malicious node.

4. The method for testing abnormal nodes in an edge network according to claim 3, characterized in that, In step S3, the communication interaction relationship between the current candidate malicious node and other candidate malicious nodes is obtained. The communication interaction relationship includes direct communication interaction relationship and indirect communication interaction relationship realized through one-hop or two-hop relay of the non-edge node.

5. A method for testing abnormal nodes in an edge network according to claim 4, characterized in that, In step S4, the first confidence level and the second confidence level are determined using the quadruple data of each candidate malicious node. Specifically, this includes: for each candidate malicious node, inputting the first triplet data <data volume, communication protocol, timestamp> into an LSTM neural network model to calculate the first confidence level {a1,…,a...}. i ,…,a num The second triplet data <source port, data volume, communication protocol> is input into the deep residual network model to calculate the second confidence level {b1,…,b}. i ,…,b num }, where num represents the number of other candidate malicious nodes that have the communication interaction relationship with the current candidate malicious node.

6. The method for testing abnormal nodes in an edge network according to claim 5, characterized in that, In step S4, determining the malicious node from the candidate malicious nodes specifically includes: The convergence time t1 of the LSTM neural network model and the convergence time t2 of the deep residual network model are obtained to calculate the overall confidence level c of the other candidate malicious nodes that have the communication interaction relationship with the current candidate malicious node relative to the current candidate malicious node. i =t2×a i +t1×b i ; Obtain the confidence scores {c1,…,c} of num other candidate malicious nodes relative to the current candidate malicious node. i ,…,c num }, to calculate the final confidence level of the current candidate malicious node. When the final confidence level is lower than the threshold, the current candidate malicious node is determined to be the malicious node. Obtain the number of the first candidate malicious node and the second candidate malicious node. Normalize these numbers to determine the weight w1 for the data tampering attack and the weight w2 for the forwarding delay attack. Calculate the first score of the malicious node for the data tampering attack: total1 = (C... s +w1)R and the second fractional value total2 = (C) regarding the forwarding delay attack behavior s +w2)R, and determine the type of attack behavior of the malicious node based on the first score and the second score.

7. A system for testing abnormal nodes in an edge network, characterized in that, The edge network is a network composed of several edge nodes in a cloud computing network, which also includes a cloud computing center and several non-edge nodes; the system includes a processing unit, wherein: The processing unit sends a first instruction to the cloud computing center, the cloud computing center sends a test request message to the edge node to be tested based on the first instruction, the edge node to be tested generates a test response message based on the test sequence in the test request message, and sends the test response message to the cloud computing center; After receiving the test response message, the cloud computing center sends the test response message to the processing center. Based on the response sequence in the test response message, the processing center determines the first candidate malicious node and the second candidate malicious node from the edge nodes to be tested. Wherein, the first candidate malicious node is a malicious node that has data tampering attack behavior, and the second candidate malicious node is a malicious node that has forwarding delay attack behavior; the processing center sends a second instruction to the cloud computing network, and the cloud computing network generates a risk network including the first candidate malicious node and the second candidate malicious node based on the second instruction; the processing center obtains the quadruple data of each candidate malicious node in the risk network. Wherein, the quadruple data is <source port, data volume, communication protocol, timestamp>, the source port is the port address of other candidate malicious nodes that have a communication interaction relationship with the current candidate malicious node, the data volume is the communication data volume from the other candidate malicious nodes, the communication protocol is the communication protocol between the current candidate malicious node and the other candidate malicious nodes, and the timestamp is the time point at the peak of the communication data volume between the current candidate malicious node and the other candidate malicious nodes; The processing center uses the quadruple data of each candidate malicious node to determine the first confidence level of each candidate malicious node regarding data tampering attack behavior and the second confidence level regarding forwarding delay attack behavior, so as to identify the malicious node from each candidate malicious node. Before the processing unit sends the first instruction to the cloud computing center: The cloud computing center sends N standard test request messages {req, N} to N standard edge nodes. The standard edge nodes generate standard test response messages {resp, N} based on the standard test sequence req in the standard test request messages {req, N} and send the standard test response messages {resp, N} to the cloud computing center. After receiving the standard test response message {resp, N}, the cloud computing center determines the standard test response data reference value and the standard test transmission delay reference value based on the standard response sequence resp in the test response message {resp, N}. The standard test sequence req includes the standard edge node IP address, standard test data, and standard test request timestamp t. o The standard edge node uses its own computing resources to parse the standard test sequence req and process the standard test data; the standard response sequence resp in the standard test response message {resp, N} includes the IP address of the standard edge node, the standard response data corresponding to the standard test data, and the standard test forwarding timestamp t1.

8. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of the method for testing abnormal nodes in an edge network according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of a method for testing abnormal nodes in an edge network according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Edge node anomaly detection method and device

    CN111510345A

  • Industrial internet edge computing platform-oriented security assessment method, system and product

    CN115643108A