A Trustworthiness Adaptive Method Based on Executor Heterogeneity
By quantifying the heterogeneity of the executors and dynamically adjusting the credibility, the problem of inaccurate quantification of the credibility of the executors in the mimicry defense system is solved, and the accuracy of the decision and the security of the system are improved.
Patent Information
- Application Number
- CN202310788385.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-06-30
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2043-06-30
AI Technical Summary
In existing mimicry defense systems, the credibility quantification of the executor is not accurate enough, resulting in insufficient decision accuracy and vulnerability to the risk of common-mode escape of attack traffic.
By quantifying the heterogeneity between executors, setting the initial credibility and credibility adjustment coefficient of the executors, and dynamically adjusting the credibility during the arbitration process, a credible arbitration result is output to enhance the security of the mimicry defense system.
The accuracy of executor decisions is improved, the risk of common-mode attack traffic escape is reduced, and the security of the mimicry defense system is enhanced.
Smart Images

Figure CN116781360B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, specifically the field of mimicry defense technology, and more specifically relates to a credibility adaptive method based on the heterogeneity of the execution entity. Background Technology
[0002] The rapid development of information technology, while bringing convenience to people's lives, has also brought more serious and insidious cybersecurity problems. To reduce security threats caused by vulnerabilities in individual systems or software, mimicry defense technology achieves proactive defense by deploying dynamic, redundant, heterogeneous executors for adjudication. This technology selects multiple executors for adjudication based on a scheduling algorithm, and then votes on or merges the multiple adjudication results to obtain the final decision. The accuracy of each executor's adjudication can be quantified by its credibility. Executors with low credibility are more likely to make incorrect decisions, potentially significantly reducing the security performance of the mimicry defense system. Therefore, credibility plays a crucial role in mimicry defense, and exploring how credibility can more accurately quantify the accuracy of executor adjudication is of significant research value. Summary of the Invention
[0003] The purpose of this invention is to address the shortcomings of existing technologies by providing a reliability adaptive method based on the heterogeneity of the execution entity.
[0004] The objective of this invention is achieved through the following technical solution: a reliability adaptive method based on execution heterogeneity, the method comprising the following steps:
[0005] (1) Deploy heterogeneous WAF servers and perform heterogeneous processing on the execution entity, including the following sub-steps:
[0006] (1.1) Deploy M servers S = {s i |i=1,2,...,M},where S i For the i-th server;
[0007] (1.2) On each server s i Deploy N microcontainers T = {t} j |j=1,2,...,N},wheret j Let e represent the j-th micro-container, which constructs a heterogeneous execution entity by deploying heterogeneous components. k ={(C k O k W k , D k G k )|k=1,2,...,M*N},where C k O k 、W k Dk , G k Each represents the execution body e. k The component categories of heterogeneous CPUs, deployed heterogeneous operating systems, WAF platforms, databases, and rule sets are defined, and the set of execution entities is denoted as E = {e...} k |k=1,2,...,M*N},where e k This is the k-th heterogeneous execution entity;
[0008] (2) Quantify the heterogeneity among the execution entities in the execution entity set E, and record the relationship between the heterogeneity and its associated execution entities, including the following sub-steps:
[0009] (2.1) Initialize the heterogeneity matrix H = {h i,j |0≤h i,j ≤1, i=1,2,...,M*N, j=1,2,...,M*N}, matrix element h i,j For the execution body e i and e j Component heterogeneity between components;
[0010] (2.2) Using component category as an indicator, the execution body e is calculated using XOR operation. i and the execution body e j The component heterogeneity between the two is calculated, and the overall heterogeneity h between them is calculated by weighting the components according to their weights. ij ;
[0011] (2.3) Update the heterogeneity matrix H, and change the heterogeneity h. ij Fill into the heterogeneous matrix H;
[0012] (2.4) Record the degree of isomerism h ij With the executor e i e j The relationship is denoted as L. k ={(i, j, h)} i,j )|i=1, 2, ..., M*N, j=1, 2, ..., M*N};
[0013] (3) Define the credibility r i To quantify the execution body e i The credibility of the ruling; at the beginning of system operation, r i =1; when the system is running, then e i A self-cleaning operation was performed, r i Set the initial confidence level r0 at this heterogeneity level k;
[0014] (4) When traffic flows in, k executors are randomly selected to participate in the adjudication. The adjudication result is calculated and output through relative multi-modal voting, including the following sub-steps:
[0015] (4.1) Each executor outputs the decision result U={u i |i=1, 2,...,k}, where u i For the execution body e i The ruling result, when the enforcement body passed the ruling u i If the value is 1, u is rejected. i =0;
[0016] (4.2) Calculate the fusion result ur using credibility as the weight;
[0017] (4.3) Compare ur and u i , if u i If ≥ur, then update u. i Set it to 1, otherwise update it to 0;
[0018] (4.4) Count the number of executors that pass the decision. If the number of executors is not less than k / 2, output the final decision result uf as passed; otherwise, output uf as failed.
[0019] (5) Update the credibility of the executor and the initial credibility value r0 according to the ruling result. The specific steps are as follows:
[0020] (5.1) According to the isomerism classification standard, mark e i The degree of heterogeneity κ;
[0021] (5.2) Comparison u i If it matches uf, then e is considered to be at this time. i Trustworthy, no adjustment to r i Conversely, it reduces r. i ;
[0022] (5.3) Take offline execution entities with a reliability lower than the threshold μ and add them to the self-cleaning execution entity set EW={ew i |i = 1, 2, ..., i}, ew i The i-th execution body to be self-cleaned is selected, and alternative execution bodies are brought online.
[0023] (5.4) Traversing L k Calculate the average confidence level of all execution entities associated with heterogeneity at the same level. This is the initial credibility r0 of the executor at this level;
[0024] (6) Perform a self-cleaning operation on EW, re-heterogeneize it, repeat steps (2) and (3), and add it to the set of candidate execution bodies.
[0025] Furthermore, in step (2), the higher the heterogeneity, the lower the probability of common-mode vulnerabilities occurring between the executors, and the higher the credibility of the ruling.
[0026] Furthermore, in step (2.1), the heterogeneity matrix H takes the following form:
[0027]
[0028] H is a symmetric matrix, i.e., h i,j =h j,i .
[0029] Furthermore, in step (2.2), the execution body e is calculated according to formula (2). i and e j Component heterogeneity between components:
[0030]
[0031] Where C i C j Each represents the execution body e. i e j For a component of a certain category, P(i,j) is 1 if the categories are the same, and 0 otherwise.
[0032] According to the following formula (3), the matrix element h is calculated by weighting. i,j :
[0033]
[0034] Where α1, α2, α3, α4, and α5 represent the computational weights of the heterogeneous components CPU, operating system, WAF platform, database, and rule set, respectively, and P1(i,j), P2(i,j), P3(i,f), P4(i,f), and P5(i,j) represent the execution body e, respectively. i and e j The degree of heterogeneity among heterogeneous components such as CPU, operating system, WAF platform, database and rule set.
[0035] Further, in step (4.2), the fusion result ur is calculated according to formula (4):
[0036]
[0037] Furthermore, in step (5.1), the isomerism grading criteria are as follows:
[0038]
[0039] Further, in step (5.4), the average reliability of the executor under the same heterogeneous level is calculated according to formula (8):
[0040]
[0041] Compared with existing technologies, the beneficial effects of this invention are: considering the impact of executor heterogeneity on the adjudication result, by quantifying the heterogeneity between executors, setting the initial credibility and credibility adjustment coefficient of the executor according to the heterogeneity level, and dynamically adjusting the credibility during the adjudication process, a credible adjudication result is output, achieving self-adaptation of credibility based on the mimicry architecture. This invention allows credibility to better monitor the accuracy of executor adjudication, reduces the risk of common-mode escape of attack traffic caused by overly similar heterogeneous structures, and enhances the security of the mimicry defense system. Attached Figure Description
[0042] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation
[0043] The present invention will now be described in detail with reference to the accompanying drawings. Unless otherwise specified, the features of the following embodiments and implementations can be combined with each other.
[0044] This invention provides a reliability adaptive method based on the heterogeneity of the executor. By quantifying the heterogeneity between executors, the initial reliability and reliability adjustment coefficient of the executor are set according to the heterogeneity level, and the reliability is dynamically adjusted during the adjudication process to output a reliable adjudication result.
[0045] like Figure 1 As shown, this invention provides a reliability adaptive method based on the heterogeneity of the execution entity, which specifically includes the following steps:
[0046] (1) Deploy heterogeneous WAF servers and perform heterogeneous processing on the execution entity, including the following sub-steps:
[0047] (1.1) Deploy M servers S = {s i |i=1,2,...,M},where S i For the i-th server, server s is configured using heterogeneous operating systems, virtualization tools, and microcontainer software. i Process it to make its function equivalent;
[0048] (1.2) On each server s i Deploy N microcontainers T = (t j |j=1,2,...,N},wheret j Let e represent the j-th micro-container, which constructs a heterogeneous execution entity by deploying heterogeneous components. k ={(C k O k W k , D k G k)|k=1,2,...,M*N},where C k O k 、W k D k , G k Each represents the execution body e. k The component categories of heterogeneous CPUs, deployed heterogeneous operating systems, WAF platforms, databases, and rule sets are defined, and the set of execution entities is denoted as E = {e...} k |i=1,2,...,M*N},where e k This is the k-th heterogeneous execution entity;
[0049] (2) Quantify the heterogeneity among the execution entities in the execution entity set E, and record the relationship between the heterogeneity and its associated execution entities, including the following sub-steps:
[0050] (2.1) Initialize the heterogeneity matrix H = {h i,j |0≤h i,j ≤1, i=1,2,...,M*N, j=1,2,...,M*N}, matrix element h i,j For the execution body e i and e j Component heterogeneity between components;
[0051] (2.2) Using component category as an indicator, the execution body e is calculated using XOR operation. i and the execution body e j The component heterogeneity between the two is calculated, and the overall heterogeneity h between them is calculated by weighting the components according to their weights. ij .
[0052] (2.3) Update the heterogeneity matrix H, and change the heterogeneity h. ij Fill into the heterogeneous matrix H;
[0053] (2.4) Ignore equivalence relations and record the degree of heterogeneity h. ij With the executor e i e j The relationship is denoted as L. k ={(i, j, h)} i,j The set of elements is defined as follows: | i = 1, 2, ..., M*N, j = 1, 2, ..., M*N, where the number of elements does not exceed [a certain value]. Where A = M * N.
[0054] (3) Define the credibility r i To quantify the execution body e i The credibility of the ruling is determined based on the heterogeneity level, with the initial credibility r set according to the system's operating state. i If at the beginning of system operation, r i =1; if the system is running, then ei A self-cleaning operation was performed, r i Set the initial confidence level r0 to the heterogeneity level κ.
[0055] (4) When traffic flows in, the dynamic selection module randomly selects k executors to participate in the adjudication, performs weighted calculations based on credibility, and the fusion adjudication module outputs the adjudication result through relative multi-mode voting calculation, including the following sub-steps:
[0056] (4.1) Each executor outputs the decision result U={u i |i=1, 2,...,k}, where u i For the execution body e i The ruling result, when the enforcement body passed the ruling u i If the value is 1, u is rejected. i =0;
[0057] (4.2) Calculate the fusion result ur using credibility as the weight;
[0058] (4.3) Compare ur and u i , if u i ≥ur, update u i Set it to 1, otherwise update it to 0;
[0059] (4.4) Count the number of executors that pass the decision in the executor. If it is not less than k / 2, output the final decision result uf as passed; otherwise, output uf as failed.
[0060] (5) The feature adjustment module updates the execution entity confidence level and the initial confidence level r0 based on the adjudication result and the execution entity heterogeneity level. The specific steps are as follows:
[0061] (5.1) According to the isomerism classification standard, mark e i The degree of heterogeneity κ;
[0062] (5.2) Comparison u i If it matches uf, then e is considered to be at this time. i Trustworthy, no adjustment to r i Conversely, it reduces r. i The attenuation coefficient β is determined by κ.
[0063] (5.3) Take offline execution entities with a reliability lower than the threshold μ and add them to the self-cleaning execution entity set EW={ew i |i = 1, 2, ..., i}, ew i The i-th execution body to be self-cleaned is selected, and alternative execution bodies are brought online.
[0064] (5.4) Traversing L kCalculate the average confidence level of all agents associated with the same level of heterogeneity. This is the initial credibility r0 of the executor at this level;
[0065] (6) The self-cleaning module performs a self-cleaning operation on the self-cleaning execution body set EW, re-heterogeneously processes it and sets initial features, repeats steps (2) and (3), and adds it to the candidate execution body set.
[0066] Furthermore, in step (2), the higher the heterogeneity, the lower the probability of common-mode vulnerabilities occurring between the executors, and the higher the credibility of the ruling.
[0067] Furthermore, in step (2.1), the heterogeneity matrix H takes the following form:
[0068]
[0069] H is a symmetric matrix, i.e., h i,j =h j,i .
[0070] Furthermore, in step (2.2), the execution body e is calculated according to formula (2). i and e j Component heterogeneity between components:
[0071]
[0072] Where C i C j Each represents the execution body e. i e j For a component of a certain category, P(i,j) is 1 if the categories are the same, and 0 otherwise.
[0073] According to the following formula (3), the matrix element h is calculated by weighting. i,j :
[0074]
[0075] Where α1, α2, α3, α4, and α5 represent the computational weights of the heterogeneous components CPU, operating system, WAF platform, database, and rule set, respectively, and P1(i,j), P2(i,j), P3(i,j), P4(i,f), and P5(i,j) represent the execution body e, respectively. i and e j The degree of heterogeneity among heterogeneous components such as CPU, operating system, WAF platform, database and rule set.
[0076] Furthermore, in step (2.4), the equivalence relation is defined as the association relation when the heterogeneity is the same and the two associated execution entities are also the same, i.e., (i, j, h) i,j ) = (j, i, h j,i ), L k Only one of the two will be recorded.
[0077] Further, in step (4.2), the fusion result ur is calculated according to formula (4):
[0078]
[0079] Furthermore, in step (5.1), the isomerism grading criteria are as follows:
[0080]
[0081] Furthermore, in step (5.2), the attenuation coefficient β and the isomerism level κ have the following relationship:
[0082]
[0083] The latest credibility is calculated using formula (5) as r′. i :
[0084] r′ i =(1-β)*r i (7).
[0085] Further, in step (5.4), the average reliability of the executor under the same heterogeneous level is calculated according to formula (8):
[0086]
[0087] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
[0088] The above embodiments are only used to illustrate the design concept and features of the present invention, and their purpose is to enable those skilled in the art to understand the content of the present invention and implement it accordingly. The protection scope of the present invention is not limited to the above embodiments. Therefore, all equivalent changes or modifications made based on the principles and design ideas disclosed in the present invention are within the protection scope of the present invention.
Claims
1. A reliability adaptive method based on the heterogeneity of the execution entity, characterized in that, The steps include: (1) Deploy heterogeneous WAF servers and perform heterogeneous processing on the execution entity. The specific steps are as follows: (1.1) Deploy M servers S = {s i |i=1,2,…,M}, where S i For the i-th server; (1.2) On each server s i Deploy N microcontainers T = {t} j |j=1,2,…,N}, where t j Let e represent the j-th micro-container, which constructs a heterogeneous execution entity by deploying heterogeneous components. k ={(C k O k W k D k G k )|k=1,2,…,M*N}, where C k O k w k 、D k G k Each represents the execution body e. k The component categories of heterogeneous CPUs, deployed heterogeneous operating systems, WAF platforms, databases, and rule sets are defined, and the set of execution entities is denoted as E = {e...} k |k=1,2,…,M*N}, where e k This is the k-th heterogeneous execution entity; (2) Quantify the heterogeneity among the execution entities in the execution entity set E, and record the relationship between the heterogeneity and its associated execution entities. The specific steps are as follows: (2.1) Initialize the heterogeneity matrix H = {h i,j |0≤h i,j ≤1, i=1,2,…,M*N, j=1,2,…,M*N}, matrix element h i,j For the execution body e i and e j Component heterogeneity between components; (2.2) Using component category as an indicator, the execution body e is calculated using XOR operation. i and the execution body e j The component heterogeneity between the two is calculated, and the overall heterogeneity h between them is calculated by weighting the components according to their weights. ij ; (2.3) Update the heterogeneity matrix H, and change the heterogeneity h. ij Fill into the heterogeneity matrix H; ( 2.4) Record the degree of heterogeneity h ij With the executor e i e j The relationship between them is denoted as L. ij ={(i,j,h)} i,j )|i=1,2,…,M*N,j=1,2,…,M*N}; (3) Define the credibility r i To quantify the execution body e i The credibility of the ruling; At the beginning of system operation, r i =1; when the system is running, then e i A self-cleaning operation was performed, r i Set the initial confidence level r0 to this heterogeneity level κ; (4) When traffic flows in, m executors are randomly selected to participate in the adjudication. The adjudication result is calculated and output through relative multi-modal voting. The specific steps are as follows: (4.1) Each executor outputs the decision result U={u i |i=1,2,…,m}, where u i For the execution body e i The ruling result, when the enforcement body passed the ruling u i If the value is 1, u is rejected. i =0; (4.2) Calculate the fusion result ur using credibility as the weight; (4.3) Compare ur and u i , if u i If ≥ur, then update u. i Set it to 1, otherwise update it to 0; (4.4) Count the number of executors that pass the decision in the executor. If the number of executors is not less than m / 2, output the final decision result uf as passed; otherwise, output uf as failed. (5) Update the credibility of the executor and the initial credibility value r0 according to the ruling result. The specific steps are as follows: (5.1) According to the isomerism classification standard, mark e i The degree of heterogeneity κ; (5.2) Comparison u i If it matches uf, then e is considered to be in this state. i Trustworthy, no adjustment to r i Conversely, it reduces r. i ; ( 5.3) Remove executors with a reliability lower than the threshold μ and add them to the self-cleaning executor set EW = {ew i |i=1,2,…,w},ew i The i-th execution body to be self-cleaned is selected, and alternative execution bodies are brought online. (5.4) Traversing L ij Calculate the average confidence level of all execution entities associated with heterogeneity at the same level. This is the initial credibility r0 of the executor at this level; (6) Perform a self-cleaning operation on EW, re-heterogeneize it, repeat steps (2) and (3), and add it to the set of candidate execution bodies.
2. The reliability adaptive method based on execution entity heterogeneity as described in claim 1, characterized in that, In step (2), the higher the heterogeneity, the lower the probability of common-mode vulnerabilities occurring between the executors, and the higher the credibility of the ruling.
3. The reliability adaptive method based on execution heterogeneity as described in claim 1, characterized in that, In step (2.1), the heterogeneity matrix H takes the following form: H is a symmetric matrix, i.e., h i,j =h j,i .
4. The reliability adaptive method based on execution heterogeneity as described in claim 1, characterized in that, In step (2.2), the execution body e is calculated according to formula (2). i and e j Component heterogeneity between components: Where C i C j Each represents the execution body e. i e j For a component of a certain category, P(i,j) is 1 if the categories are the same, and 0 otherwise. According to the following formula (3), the matrix element h is calculated by weighting. i,j : Where α1, α2, α3, α4, and α5 represent the computational weights of the heterogeneous components CPU, operating system, WAF platform, database, and rule set, respectively, and P1(i,j), P2(i,j), P3(i,j), P4(i,j), and P5(i,j) represent the execution body e, respectively. i and e j The degree of heterogeneity among heterogeneous components such as CPU, operating system, WAF platform, database and rule set.
5. The reliability adaptive method based on execution entity heterogeneity as described in claim 1, characterized in that, In step (4.2), the fusion result ur is calculated according to formula (4):
6. The reliability adaptive method based on execution entity heterogeneity as described in claim 1, characterized in that, In step (5.1), the isomerism grading criteria are as follows:
7. The reliability adaptive method based on execution heterogeneity as described in claim 1, characterized in that, In step (5.4), the average reliability of the executor under the same heterogeneous level is calculated according to formula (8):
Citation Information
Patent Citations
Dynamic multi-mode heterogeneous redundant industrial control security gateway system and invasion sensing method
CN108322431A
Multi-modal asynchronous judgment method of mimicry WAF executor
CN114124519A