Method, system and device for processing secure data with an embedded data processing unit

CN117914692BActive Publication Date: 2026-09-15BEIJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311809325.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2026-09-15
Estimated Expiration
2043-12-26

AI Technical Summary

Technical Problem

[0005]本发明提供一种内置数据处理单元的安全数据的处理方法、系统及设备,用以解决内置数据处理单元的安全数据的处理方法效率低的缺陷,实现提高对安全数据处理的效率

Benefits of technology

[0032] The present invention provides a method, system, and device for processing secure data with a built-in data processing unit, applied to an edge device. The edge device includes at least one data processing unit, which has multiple built-in hardware acceleration units. Each hardware acceleration unit has different data processing functions. Based on a first hardware acceleration unit, an initial script matching the secure data is used as the processing script for the secure data. The initial script is sent by a cloud platform and includes response actions for processing historical secure data. The secure data is network data with security vulnerabilities. Based on a second hardware acceleration unit and the processing script, a processing instruction is sent to an edge-side security device. The security device executes the processing instruction to process the secure data. The hardware acceleration unit includes the first hardware acceleration unit and the second hardware acceleration unit. This invention, by processing secure data with a hardware acceleration unit, accelerates the processing speed of secure data. By automatically matching the processing script based on the initial script, it achieves automated processing of secure data, improving the efficiency of secure data processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117914692B_ABST
    Figure CN117914692B_ABST
Patent Text Reader

Abstract

The application provides a kind of security data processing method, system and equipment of built-in data processing unit, belong to network security technical field, the method includes: based on the first hardware acceleration unit, the initial script matched with security data is used as the processing script of security data;Initial script is sent by cloud platform;Based on the second hardware acceleration unit and processing script, send processing instruction to the security device of edge side;Wherein, security device executes processing instruction to process security data, hardware acceleration unit includes first hardware acceleration unit and second hardware acceleration unit.The embodiment of the application processes security data based on hardware acceleration unit, accelerates the processing speed of security data;Based on initial script, automatically match processing script, realize the automatic processing of security data, improve the efficiency of security data processing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, system, and device for processing secure data with a built-in data processing unit. Background Technology

[0002] The rapid development of IoT technology has led to increasingly higher value for IoT networks, resulting in larger networks and greater complexity. With the dramatic increase in IoT data, hackers have more incentives and means to steal information and resources, causing damage to assets and resulting in significant losses. To address these challenges, only by establishing a robust cybersecurity defense mechanism can effective information security management be achieved, providing better security services for businesses and individuals.

[0003] Existing methods for processing secure data within built-in data processing units are no longer sufficient to meet current security requirements. These methods have the following drawbacks:

[0004] The existing methods for processing security data from built-in data processing units are inefficient due to a lack of standardization, insufficient intelligent arrangement, and slow processing speed. Summary of the Invention

[0005] This invention provides a method, system, and device for processing secure data with a built-in data processing unit, which addresses the inefficiency of secure data processing methods with built-in data processing units and improves the efficiency of secure data processing.

[0006] In a first aspect, the present invention provides a method for processing secure data with a built-in data processing unit, applied to an edge device. The edge device includes at least one data processing unit, which has multiple built-in hardware acceleration units, each of which has different data processing functions, including:

[0007] Based on the first hardware acceleration unit, an initial script matching the security data is used as the processing script for the security data; the initial script is sent by the cloud platform, and the initial script includes response actions for processing historical security data; the security data is network data with security vulnerabilities.

[0008] Based on the second hardware acceleration unit and the processing script, a processing instruction is sent to the security device at the edge; wherein the security device executes the processing instruction to process the security data; the hardware acceleration unit includes the first hardware acceleration unit and the second hardware acceleration unit.

[0009] According to a method for processing secure data with a built-in data processing unit provided by the present invention, determining the processing script further includes:

[0010] When no initial script matches the security data, the security data is sent to the cloud platform, and the processing script sent by the cloud platform is received; wherein the cloud platform determines the processing script of the security data.

[0011] According to a method for processing secure data with a built-in data processing unit provided by the present invention, after sending processing instructions to a security device based on a second hardware acceleration unit and the processing script, the method further includes:

[0012] Obtain the processing status of the security data by the security device;

[0013] Based on the processing status, a security log is generated;

[0014] The security log is sent to the cloud platform; wherein, the cloud platform updates the initial script based on the security log.

[0015] According to a method for processing security data with a built-in data processing unit provided by the present invention, the step of generating a security log based on the processing status includes:

[0016] When the processing status is successful, the alarm result of the security data is verified. When the alarm result is that there is no alarm, the security data is determined to be successfully processed, and the processing success information is recorded to generate the security log.

[0017] When the processing status is processing failure, the processing failure information is recorded to generate the security log.

[0018] According to a method for processing secure data with a built-in data processing unit provided by the present invention, the method for obtaining the secure data includes:

[0019] Based on the third hardware acceleration unit, the network data sent by the security device is received, the network data is analyzed for security, and the network data with potential security risks is identified as the secure data.

[0020] Secondly, this invention provides a method for processing secure data with a built-in data processing unit, applied to a cloud platform, comprising:

[0021] Acquire historical security data, determine response actions that match the historical security data from the response action library, and orchestrate the response actions to obtain the initial script of the historical security data;

[0022] The initial script is sent to the edge device; wherein, the data processing unit of the edge device, based on the first hardware acceleration unit, takes the initial script that matches the security data as the processing script for the security data, and sends processing instructions to the security device based on the second hardware acceleration unit and the processing script; the security device executes the processing instructions to process the security data.

[0023] According to a method for processing secure data with a built-in data processing unit provided by the present invention, after sending the initial script to the end-side device, the method further includes:

[0024] Receive the security log sent by the data processing unit;

[0025] Based on the security log, the initial script is updated, and the updated initial script is sent to the edge device; wherein, the data processing unit of the edge device matches the processing script corresponding to the security data in the updated initial script.

[0026] Thirdly, the present invention provides a security data processing system with a built-in security data processing unit, which is applied to the security data processing method with the built-in data processing unit described in any of the above claims, including an end-side device, a cloud platform, and a security device. The end-side device includes at least one data processing unit, the cloud platform is connected to the data processing unit, and the data processing unit is connected to the security device.

[0027] The security device is used to monitor the network to obtain network data, preprocess the network data, and send the preprocessed network data to the data processing unit to execute processing instructions to process the security data.

[0028] The data processing unit is configured to: determine security data based on the network data using the third hardware acceleration unit; use an initial script matching the security data as the processing script for the security data using the first hardware acceleration unit; send processing instructions to the security device using the second hardware acceleration unit and the processing script; receive the processing status of the security data sent by the security device; generate a security log based on the processing status; and send the security log to the cloud platform.

[0029] The cloud platform is used to update the initial script based on the security logs and send the updated initial script to the data processing unit.

[0030] Fourthly, the present invention provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of a secure data processing method for any of the built-in data processing units described above.

[0031] Fifthly, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the secure data processing method of any of the built-in data processing units described above.

[0032] The present invention provides a method, system, and device for processing secure data with a built-in data processing unit, applied to an edge device. The edge device includes at least one data processing unit, which has multiple built-in hardware acceleration units. Each hardware acceleration unit has different data processing functions. Based on a first hardware acceleration unit, an initial script matching the secure data is used as the processing script for the secure data. The initial script is sent by a cloud platform and includes response actions for processing historical secure data. The secure data is network data with security vulnerabilities. Based on a second hardware acceleration unit and the processing script, a processing instruction is sent to an edge-side security device. The security device executes the processing instruction to process the secure data. The hardware acceleration unit includes the first hardware acceleration unit and the second hardware acceleration unit. This invention, by processing secure data with a hardware acceleration unit, accelerates the processing speed of secure data. By automatically matching the processing script based on the initial script, it achieves automated processing of secure data, improving the efficiency of secure data processing. Attached Figure Description

[0033] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0034] Figure 1 This is one of the flowcharts illustrating the secure data processing method of the built-in data processing unit provided by the present invention;

[0035] Figure 2 This is a schematic diagram of the structure of the secure data processing system with a built-in secure data processing unit provided by the present invention;

[0036] Figure 3 This is a schematic diagram of the structure of the data processing unit provided by the present invention;

[0037] Figure 4 This is a schematic diagram of the cloud platform provided by the present invention;

[0038] Figure 5 This is a schematic diagram illustrating the function of the secure data processing system with a built-in secure data processing unit provided by the present invention.

[0039] Figure 6 This is the second flowchart illustrating the secure data processing method of the built-in data processing unit provided by the present invention.

[0040] Figure 7 This is the third flowchart illustrating the secure data processing method of the built-in data processing unit provided by the present invention;

[0041] Figure 8 This is the fourth flowchart illustrating the secure data processing method of the built-in data processing unit provided by the present invention;

[0042] Figure 9 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation

[0043] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0044] It should be noted that in the description of the embodiments of the present invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element. The terms "upper," "lower," etc., indicating orientation or positional relationships based on the orientation or positional relationships shown in the accompanying drawings, are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the present invention. Unless otherwise expressly specified and limited, the terms "installed," "connected," and "linked" should be interpreted broadly, for example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two elements. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.

[0045] The terms "first," "second," etc., used in this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class, without limiting the number of objects; for example, a first object can be one or more. Furthermore, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects have an "or" relationship.

[0046] The following is combined Figures 1-9 This invention describes a method and system for processing secure data using a built-in data processing unit, as provided in embodiments of the present invention.

[0047] Figure 1 This is one of the flowcharts illustrating the secure data processing method of the built-in data processing unit provided by the present invention, such as... Figure 1 As shown, a method for processing secure data with a built-in data processing unit is applied to an edge device. The edge device includes at least one data processing unit, which has multiple built-in hardware acceleration units. Each hardware acceleration unit has different data processing functions, including but not limited to the following steps:

[0048] Step 100: Based on the first hardware acceleration unit, the initial script that matches the security data is used as the security data processing script;

[0049] The initial script is sent by the cloud platform and includes response actions for processing historical security data; the security data is network data that has security vulnerabilities.

[0050] Existing methods for processing secure data in built-in data processing units have the following drawbacks:

[0051] (1) Lack of standardization. There are no unified standards for IoT information security testing, assessment, and access. Different analysis and detection engines prioritize the same risk event differently. Furthermore, inconsistent management ultimately leads to inconsistent product security standards and frequent vulnerabilities.

[0052] (2) The scriptwriting process is not intelligent enough. Currently, scriptwriting is mainly generated manually. With the increase in IoT devices and the continuous updating and iteration of solutions, the pressure on manual labor will also increase.

[0053] (3) Slow processing speed. Each time an intrusion occurs, it is necessary to first report to the platform, then query the threat, and then call the local security equipment to respond according to the existing script. The whole process takes too long and consumes a lot of resources.

[0054] To address the aforementioned problems, embodiments of the present invention provide a method for processing secure data with a built-in data processing unit.

[0055] A Data Processing Unit (DPU) is a data-centric processor. A DPU is a dedicated processor that provides virtualization services for data center infrastructure, such as networking, storage, security, and management, all centered around data processing. For example... Figure 3 As shown, the data processor includes a hardware acceleration unit, which consists of CPUs based on architectures such as ARM / x86, and Application Specific Integrated Circuits (ASICs) / Field Programmable Gate Arrays (FPGAs). The hardware acceleration unit includes modules for atomic action engines, security data analysis, and network data acquisition. The data processing unit includes a security operations center, which comprises a DPU operating system (DPU OS) and a real-time information interaction module. The DPU OS includes an action flow engine, a process response model, and an initial script parsing module. The real-time information interaction module is used for information exchange between the DPU OSes of different data processing units.

[0056] A cloud platform is a platform for managing security incident handling. The cloud platform described in this application is a Security Orchestration Automation and Response (SOAR) cloud platform. The SOAR cloud platform can monitor security logs in the data processing unit, or receive security data sent by the data processing unit, and trigger automatic responses to mitigate the threat posed by a large amount of security data to the SOAR cloud platform simultaneously. It can also define initial scripts and processing scripts corresponding to security data, update the initial scripts, and delegate tedious and repetitive tasks to automation technology. Optionally, the cloud platform includes a visualization analysis and display module for the security data processing procedure. Scripts include security data and their corresponding response actions.

[0057] An edge device (e.g., a power station, computer, server, etc.) includes at least one data processing unit. This data processing unit primarily accelerates certain fixed data processing operations through hardware acceleration units, such as reading network data, analyzing security data, matching processing scripts to security data, and sending processing instructions to security devices. By setting up multiple data processing units and multiple hardware acceleration units, the processing pressure on the edge device's CPU can be reduced, and the processing speed can be improved.

[0058] The SOAR cloud platform generates initial scripts based on historical security data. Furthermore, these initial scripts can be defined and arranged by the user. The cloud platform can automatically distribute the initial scripts, or the distribution can be manually initiated by the user. After generating the initial scripts, the SOAR cloud platform distributes them to the edge devices.

[0059] The edge device stores the initial script in the script library. After receiving security data, the edge device allocates the security data to the data processing unit. The data processing unit, based on the first hardware acceleration unit, matches the initial script corresponding to the security data in the script library to obtain the processing script. The first hardware acceleration unit is specifically used for matching security data and the initial script.

[0060] Step 200: Based on the second hardware acceleration unit and the processing script, send processing instructions to the security device on the edge side;

[0061] The security device executes processing instructions to process security data, and the hardware acceleration unit includes a first hardware acceleration unit and a second hardware acceleration unit.

[0062] Security devices include Web Application Firewalls (WAF), Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), Security Information and Event Management (SIEM), Access Management Systems, Encryption Devices, Security Gateways, Secure Storage Devices, and so on.

[0063] After the data processing unit matches the processing script corresponding to the security data, it sends a processing instruction to the security device based on the second hardware acceleration unit and the response actions in the processing script. Upon receiving the processing instruction, the security device executes it to process the security data. For example, based on the processing instruction, the security device calls the corresponding interface to perform anti-intrusion activities on the security data, including global blocking, host isolation, and host cleanup. The second hardware acceleration unit is specifically used to send processing instructions to the security device.

[0064] The security data processing method with a built-in data processing unit provided in this invention is applied to an edge device. The edge device includes at least one data processing unit, which has multiple built-in hardware acceleration units. Each hardware acceleration unit has different data processing functions. Based on a first hardware acceleration unit, an initial script matching the security data is used as the processing script for the security data. The initial script is sent by a cloud platform and includes response actions for processing historical security data. The security data is network data with security vulnerabilities. Based on a second hardware acceleration unit and the processing script, a processing instruction is sent to an edge-side security device. The security device executes the processing instruction to process the security data. The hardware acceleration unit includes a first hardware acceleration unit and a second hardware acceleration unit. This invention accelerates the processing speed of security data by processing it with a hardware acceleration unit. It also automatically matches the processing script based on the initial script, achieving automated processing of security data and improving the efficiency of security data processing.

[0065] Based on the above embodiments, determining the processing script further includes:

[0066] Step 300: When no initial script matches the security data, send the security data to the cloud platform and receive the processing script sent by the cloud platform; wherein, the cloud platform determines the processing script for the security data.

[0067] like Figure 6 , 7 As shown, if no initial script matches the security data in the script library, it means the initial script was not matched. The security data needs to be uploaded to the cloud platform. Users then create processing scripts corresponding to the security data based on the cloud platform. Alternatively, the cloud platform can automatically match response actions from the response action library and orchestrate these actions to obtain the processing script. Another approach is for user actions to be combined with automatic analysis by the cloud platform to determine the processing script. The cloud platform then distributes the completed processing scripts to the data processing unit corresponding to the security data.

[0068] The embodiments of the present invention determine the processing script through a cloud platform, which enriches the means of determining the processing script, realizes comprehensive processing of security data, and helps to improve the efficiency of security data processing.

[0069] Based on the above embodiments, after sending processing instructions to the security device based on the second hardware acceleration unit and the processing script, the method further includes:

[0070] Step 400: Obtain information on the processing of security data by the security device;

[0071] Step 500: Generate a security log based on the processing status;

[0072] Step 600: Send security logs to the cloud platform; the cloud platform updates the initial script based on the security logs.

[0073] After executing the data processing instructions, the security device sends an execution completion message to the endpoint device. Based on this message, the endpoint device sends verification information to the security device to obtain the security device's processing status of the security data. Optionally, the endpoint device periodically sends verification information to the security device to obtain the security device's processing status of the security data.

[0074] Based on the handling situation, determine the alarm results of the security equipment data, and record the security data, handling script, handling situation, and alarm results to obtain the security log.

[0075] The edge devices periodically send security logs to the cloud platform. The cloud platform analyzes the matching between the processing scripts and security data in the security logs based on the processing and alarm information. If the processing scripts and security data in the security logs do not match, the cloud platform updates the initial scripts and sends the updated initial scripts to the edge devices. The edge devices then update their script library based on the updated initial scripts.

[0076] This invention improves the matching between the initial script and security data by sending security logs to the cloud platform and updating the initial script, thereby increasing the efficiency of security data processing.

[0077] Based on the above embodiments, and based on the processing status, a security log is generated, including:

[0078] Step 510: When the processing status is successful, verify the alarm result of the security data. When the alarm result is that there is no alarm, determine that the security data processing is successful and record the processing success information to generate a security log.

[0079] Step 520: When the processing status is processing failure, record the processing failure information to generate a security log.

[0080] like Figure 6 , 7 As shown, the edge device verifies the security device's processing of security data. When the processing status is successful, within a certain period after successful verification, it checks for any alarms corresponding to the security data. If no alarms are found, the security data processing is verified as successful; otherwise, it is verified as a failure. Information indicating successful or failed security data processing is recorded to generate a security log.

[0081] If a new alarm is received after successful security data processing, security data and a processing script are generated for the new alarm, and the new alarm is processed according to the above process. If the processing fails, the failure information is recorded directly to generate a security log.

[0082] Based on the processing status, this invention verifies security data by issuing alarms and generates security logs, thereby improving the accuracy of security logs and facilitating the improvement of the accuracy of updating the initial script.

[0083] Based on the above embodiments, obtaining security data includes:

[0084] Step 700: Based on the third hardware acceleration unit, receive network data sent by the security device, perform security analysis on the network data, and identify network data with potential security risks as secure data.

[0085] Security devices monitor the network, acquire network data, and perform standardized preprocessing on the network data, such as merging and deduplication, and false alarm detection. False alarm detection involves using a false alarm detection script to extract useless noise data from a large amount of network data, leaving only the data with actual value. The false alarm detection script is developed based on false alarm characteristics accumulated in daily security operations, business characteristics, and threat scenarios. The script can filter false alarm data before sending it uniformly to the data processing unit.

[0086] The third hardware acceleration unit in the data processing unit receives network data and identifies secure data. This unit collects network data from the security device via the System Logging Protocol. It then performs security analysis on the collected network data to determine its security status. For example, the third hardware acceleration unit may pre-store standard information for secure data; when network data meets this standard information, it is defined as secure data.

[0087] Optionally, a fourth hardware acceleration unit may be provided in the data processing unit. This fourth hardware acceleration unit is specifically designed to perform security analysis on network data to identify secure data.

[0088] The embodiments of the present invention use a third hardware acceleration unit to determine security data, thereby hardwareifying the process of determining security data and improving the efficiency of determining security data.

[0089] like Figure 8 As shown, this embodiment of the invention provides a method for processing secure data with a built-in data processing unit, applied to a cloud platform, including:

[0090] Step 800: Obtain historical security data, determine the response actions that match the historical security data from the response action library, and orchestrate the response actions to obtain the initial script of the historical security data.

[0091] The execution entity of this invention embodiment is a cloud platform, such as... Figure 4 As shown, the cloud platform includes a script management module, a response management module, and a case management module.

[0092] The script management module is used to create initial scripts, store security logs, and distribute initial scripts. The response management module is used for security data querying and response action management. The case management module is used for managing security incident cases, and analyzing and optimizing security incident cases. The SOAR cloud platform interacts with users through a user interface (UI). The cloud platform can automatically manage security data, initial scripts, response actions, and security data processing cases, or it can manage these functions based on user operations.

[0093] The cloud platform can automatically determine response actions that match historical security data from the response action library and automatically orchestrate these actions to obtain the initial script for the historical security data. Optionally, the cloud platform can receive matching information input by the user to determine the initial script for the historical security data.

[0094] Step 900: Send the initial script to the end device;

[0095] The data processing unit of the edge device, based on the first hardware acceleration unit, takes the initial script that matches the security data as the processing script for the security data, and sends processing instructions to the security device based on the second hardware acceleration unit and the processing script; the security device executes the processing instructions to process the security data.

[0096] The cloud platform sends the prepared initial script to the edge devices, which then distribute the processing scripts to the script libraries of each data processing unit. Each data processing unit on the edge device matches a processing script for the security data from its script library and sends processing instructions to the security device according to the script. The security device executes the processing instructions to process the security data. A real-time information interaction module within the data processing unit is used for information exchange between the various data processing units.

[0097] The security data processing method with a built-in data processing unit provided in this embodiment of the invention is applied to a cloud platform. It acquires historical security data, determines response actions matching the historical security data from a response action library, and orchestrates these response actions to obtain an initial script for the historical security data. The initial script is then sent to an edge device. The edge device's data processing unit, based on a first hardware acceleration unit, uses the initial script matching the security data as the security data processing script, and, based on a second hardware acceleration unit and the processing script, sends processing instructions to the security device. The security device executes the processing instructions to process the security data. This embodiment of the invention automatically generates initial scripts through a cloud platform and a response action library, improving the efficiency of initial script determination and thus enhancing the efficiency of security data processing.

[0098] Based on the above embodiments, after sending the initial script to the end device, the method further includes:

[0099] Step 910: Receive the security log sent by the data processing unit;

[0100] Step 920: Based on the security log, update the initial script and send the updated initial script to the end device;

[0101] In this process, the data processing unit of the terminal device matches the processing script corresponding to the security data in the updated initial script.

[0102] The cloud platform periodically receives and stores security logs sent by edge devices. It manages these logs and retrieves security data and its execution status. It also statistically analyzes failed executions and their associated security data. If security data fails to execute, it indicates a mismatch between the security data's processing script and the data itself, requiring a new initial script to be specified. For failed security data, the cloud platform redefines the response action and workflow. Based on the security data, its response action, and its workflow, the cloud platform derives the target script for the security data. This target script is added to the initial script, and initial scripts with failed processing records are deleted, resulting in the latest updated initial script.

[0103] Furthermore, the cloud platform generates security data cases based on security logs. A security data case includes a scenario description (security data), a solution (handling script), and execution status. The scenario description includes the case's own information and the security incident scenario. The components of a security incident case are shown in Table 1. The cloud platform analyzes the security data cases to update the initial script.

[0104] Table 1 Composition of Security Incident Cases

[0105]

[0106]

[0107] The cloud platform analyzes the matching between processing scripts and security data in the security logs based on the processing and alarm information. If the processing scripts and security data in the security logs do not match, the cloud platform updates the initial script and sends the updated initial script to the edge device. The cloud platform can update the initial script automatically or update the processing scripts according to user-configured information. The edge device updates the script library based on the updated initial script. During subsequent security data processing, the data processing unit matches the corresponding processing script based on the updated script library.

[0108] This invention improves the usability of initial scripts by updating processing scripts through security logs and timely updating initial scripts with processing failure records, which is beneficial to improving the efficiency of security data processing.

[0109] This invention also provides a secure data processing system with a built-in secure data processing unit, such as... Figure 2 As shown, Figure 2This is a schematic diagram of the structure of the security data processing system with a built-in security data processing unit provided by the present invention. It should be noted that the security data processing system with a built-in security data processing unit provided in this embodiment can execute the security data processing method of the built-in data processing unit described in any of the above embodiments during actual operation; however, this embodiment will not elaborate on this further.

[0110] Reference Figure 2 The present invention provides a secure data processing system with a built-in secure data processing unit, including an end-side device, a cloud platform, and a security device. The end-side device includes at least one data processing unit, the cloud platform is connected to the data processing unit, and the data processing unit is connected to the security device.

[0111] Security equipment is used to monitor the network, acquire network data, preprocess the network data, and send the preprocessed network data to the data processing unit to execute processing instructions for processing security data.

[0112] The data processing unit is used to determine security data based on network data based on the third hardware acceleration unit; to use the initial script matching the security data as the security data processing script based on the first hardware acceleration unit; to send processing instructions to the security device based on the second hardware acceleration unit and the processing script; to receive the processing status of the security data sent by the security device; to generate security logs based on the processing status; and to send the security logs to the cloud platform.

[0113] The cloud platform is used to update the initial script based on security logs and send the updated initial script to the data processing unit;

[0114] Furthermore, the secure data processing system with a built-in secure data processing unit of the present invention also includes a data processing unit management module and a security service module. The cloud platform, the data processing unit management module, and the security service module are all cloud-side components. The cloud-side component is used to manage the end-side devices. The data processing unit management module is connected to the data processing unit, and the security service module is connected to both the data processing unit and the security device. The data processing unit management module is used to manage the data processing unit. The security service module is used to test and evaluate the applications of the data processing unit and the security device, and to optimize the applications based on the test and evaluation results.

[0115] The cloud platform automatically processes and verifies security data in an orchestratable workflow to obtain an initial script. The initial script consists of one or more response actions. Based on expert system data, the initial script is developed on the cloud platform. This script includes a series of security data and corresponding response actions, and is distributed to the distributed data processing unit (DPU) of each edge device. Leveraging DPU intelligent offloading technology, security functions from the edge device's CPU are transferred to the distributed DPU. Repetitive actions are accelerated using hardware acceleration units, including security data acquisition and preprocessing, automated response, and reporting script defects, enabling automated invocation of local security devices for protection. The security data processing system achieves cross-domain information sharing, uploading all security logs generated by all edge devices to the SOAR cloud platform for intelligent analysis and optimization of the initial script.

[0116] The Data Processing Unit Management (DPU) module is primarily responsible for the lifecycle management of bare metal, virtual machines, and container instances, and handles network and cloud disk configuration. It implements DPU resource management, status management, service management, and DPU log management. With the introduction of the DPU, the installation location of the management system software (such as Open Stack) on the compute nodes is changed from the host-side CPU to the DPU-side CPU. The DPU must support the compilation and installation of the DPU management module. Seamless migration, deployment, and unattended deployment of the DPU management software on the DPU can be achieved through interoperability or integration between the DPU operating system (OS) and the host system (Host OS), reducing adaptation and development costs.

[0117] The security service module refers to cybersecurity services provided by independent external organizations or companies. These services include vulnerability assessment and penetration testing, security consulting and strategy development, network monitoring and intrusion detection, data backup and recovery, incident response and emergency support, etc. In other words, the security service module can assess and test the applications of data processing units and security devices to discover vulnerabilities and weaknesses, and provide corresponding remediation suggestions. The security service module can provide security consulting services to data processing units, developing corresponding security strategies and measures based on the needs of the data processing unit and risk assessment results, helping clients establish a security system suitable for their needs. It can provide 24-hour network monitoring services, monitoring the organization's network activities in real time, promptly detecting and responding to potential intrusions, and taking appropriate defensive measures. The security service module can also provide data backup and recovery services to ensure the security and integrity of the data processing unit's important data, preventing data loss or tampering. In the event of a security threat or cyberattack, the security service module can provide emergency incident response and support, assisting the data processing unit in intrusion tracing, repairing damaged systems, and taking appropriate measures to prevent similar incidents from recurring.

[0118] like Figure 5 As shown, the functions of the security data processing system with a built-in security data processing unit include network data source management, network data processing, case management, script management, orchestration engine, and security response. Network data source management includes acquiring network data through various network data sources, such as network situational awareness, Security Information and Event Management system (SIEM), Security Operations Center (SOC), security devices, emails, and work orders.

[0119] Network data processing includes network data overview, network data statistics, network data tracing, network data analysis, network data merging, and secure data uploading.

[0120] Case management includes a case overview, case response process, case trace management, case reporting, case collaboration analysis, and a case database. Case management helps users conduct structured and continuous investigation, analysis, and response to a set of related alerts. The case handling process should be able to assign different handling procedures to cases of different natures and monitor their execution; it continuously accumulates case-related incriminating evidence (IOC) and attacker tactics and techniques (TTP) information through alert management; and it allows for investigation and response through orchestration functions, enabling the tracking of all alert execution scripts or actions within a case to uncover suspicious points and extract crucial information.

[0121] Script management includes initial script editing, initial script modeling, initial script debugging, initial script optimization, and initial script distribution. Script management is a core and fundamental capability of the cross-domain security reconfigurable collaborative defense system. Scripts are geared towards the orchestrators and focus solely on the orchestration logic itself. For known security data, it can automatically handle it based on existing initial scripts. However, for new types of security data without matching initial scripts, manual handling and creation of corresponding initial scripts are required. Scripts support both built-in system configuration and manually customized orchestration methods. Automated processing and manual decision-making can complement each other. Furthermore, for newly generated security data, the system can automatically generate processing scripts using a case library and script library. Therefore, the key to achieving intelligent orchestration is the ability to intelligently generate processing scripts. Specifically, the system can use machine learning to analyze script libraries, action libraries, knowledge graphs, and the handling experience of security personnel to intelligently generate scripts. It can also simulate security events corresponding to the security data to evaluate the effectiveness of initial scripts, optimize and validate them, and ultimately generate feasible and effective initial scripts.

[0122] The orchestration engine comprises a workflow engine, response action library, automated execution engine, application and action libraries, application development kits, and application integration framework. Orchestration refers to combining the security capabilities of multiple systems or different components within a system through interfaces according to certain logical relationships to execute a specified series of security operation processes. Orchestration is the core of improving coordination and decision-making efficiency. Orchestration is expressed through initial scripts. The workflow engine supports the execution of these initial scripts. The workflow engine parses the initial scripts and calls the automated execution engine to implement the work tasks orchestrated according to the initial scripts. Application and action interfaces are uniformly encapsulated through APIs, encompassing security technologies, tools, platforms, systems, processes, and management mechanisms. The automated execution engine supports top-down implementation, automatically executing the corresponding application and action interface tasks within the workflow. The application and action libraries, application development kits, and application integration framework are used for unified application management.

[0123] Security response includes response actions, manual handling, script definition, security log uploading, and task scheduling. Security response can automatically match the required security data with the appropriate script and automatically execute the operational procedures within the script. It can also automatically link relevant devices based on the execution status to achieve protective and blocking actions. Security incident response includes alarm management, object management, work order management, and case management functions. Furthermore, isolation and remediation are crucial post-response operations. Integrating automated security verification into the cloud platform's orchestration and response system enables the solidification, accumulation, and optimization of verification experience.

[0124] The security data processing system with a built-in security data processing unit provided by this invention can automate the execution and orchestration of security workflows, including security data analysis, investigation, response, and reporting. By defining pre-defined automation rules and processes, response time can be accelerated and human error reduced. It can collect, integrate, and analyze security data and security logs from multiple security tools and data sources to quickly identify potential security data (threats). This invention designs an edge device based on DPU acceleration. The DPU includes a dedicated hardware acceleration unit for data processing, featuring highly optimized computing power and low latency. By offloading fixed operations to the hardware acceleration unit and accelerating fixed processes using the DPU, data processing speed and response time can be significantly improved, thereby accelerating the execution of the entire process. This greatly shortens the traditional security response time, while reducing energy consumption and energy costs, and also reducing hardware costs because additional general-purpose processors are no longer needed to perform these tasks. This invention, leveraging machine learning and artificial intelligence technologies, can extract insights from security logs (historical data and experience) and make intelligent decisions. Through continuous learning and optimization, it can adapt to new security data patterns and changes, improve security defense levels, and intelligently generate initial scripts. Considering script libraries, action libraries, knowledge graphs, and the experience of security personnel, it uses AI to intelligently generate initial scripts and simulate, optimize, and verify them. During the response process, it continuously updates the initial scripts based on collected security logs, addressing the problem of insufficient security experts. This invention relies on the programmability of the DPU and device virtualization capabilities to achieve automatic orchestration of device virtualization, which can be flexibly modified. By hardware-izing specific computing tasks based on the DPU, it reduces reliance on software development and maintenance. This simplifies system architecture and design and improves software maintainability and stability.

[0125] Figure 9 This is a schematic diagram of the structure of the electronic device provided by the present invention, such as... Figure 9As shown, the electronic device may include a processor 910, a communications interface 920, a memory 930, and a communication bus 940, wherein the processor 910, communications interface 920, and memory 930 communicate with each other via the communication bus 940. The processor 910 can call logical instructions in the memory 930 to execute a secure data processing method of a built-in data processing unit. This method includes: using an initial script matching the secure data as a processing script for the secure data based on a first hardware acceleration unit; the initial script is sent by a cloud platform and includes response actions for processing historical secure data; the secure data is network data with security vulnerabilities; and sending processing instructions to a security device at the edge based on a second hardware acceleration unit and the processing script; wherein the security device executes the processing instructions to process the secure data, and the hardware acceleration unit includes a first hardware acceleration unit and a second hardware acceleration unit.

[0126] Furthermore, the logical instructions in the aforementioned memory 930 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0127] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program stored on a non-transitory computer-readable storage medium, the computer program comprising program instructions, wherein when the program instructions are executed by a computer, the computer is able to execute the security data processing method of the built-in data processing unit provided in the above embodiments, the method comprising: based on a first hardware acceleration unit, taking an initial script matching the security data as a security data processing script; the initial script is sent by a cloud platform, the initial script including response actions for processing historical security data; the security data is network data with security vulnerabilities; based on a second hardware acceleration unit and the processing script, sending processing instructions to a security device on the edge side; wherein the security device executes the processing instructions to process the security data; the hardware acceleration unit includes a first hardware acceleration unit and a second hardware acceleration unit.

[0128] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program implements a method for processing secure data using the built-in data processing unit provided in the above embodiments. The method includes: using an initial script matching the secure data as a processing script for the secure data based on a first hardware acceleration unit; the initial script is sent by a cloud platform and includes response actions for processing historical secure data; the secure data is network data with security vulnerabilities; and sending processing instructions to a security device at the edge based on a second hardware acceleration unit and the processing script; wherein the security device executes the processing instructions to process the secure data; the hardware acceleration unit includes a first hardware acceleration unit and a second hardware acceleration unit.

[0129] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0130] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for processing secure data with a built-in data processing unit, characterized in that, This is applied to an edge device, which includes at least one data processing unit. The data processing unit has multiple built-in hardware acceleration units, each of which has different data processing functions, including: Based on the first hardware acceleration unit, an initial script matching the security data is used as the processing script for the security data; the initial script is sent by the cloud platform, and the initial script includes response actions for processing historical security data; the security data is network data with security vulnerabilities. Based on the second hardware acceleration unit and the processing script, a processing instruction is sent to the security device at the edge; wherein the security device executes the processing instruction to process the security data; the hardware acceleration unit includes the first hardware acceleration unit and the second hardware acceleration unit.

2. The method for processing secure data using the built-in data processing unit according to claim 1, characterized in that, Determining the processing script further includes: When no initial script matches the security data, the security data is sent to the cloud platform, and the processing script sent by the cloud platform is received; wherein the cloud platform determines the processing script of the security data.

3. The method for processing secure data using the built-in data processing unit according to claim 1, characterized in that, After sending processing instructions to the security device based on the second hardware acceleration unit and the processing script, the method further includes: Obtain the processing status of the security data by the security device; Based on the processing status, a security log is generated; The security log is sent to the cloud platform; wherein, the cloud platform updates the initial script based on the security log.

4. The method for processing secure data using the built-in data processing unit according to claim 3, characterized in that, Based on the processing status, a security log is generated, including: When the processing status is successful, the alarm result of the security data is verified. When the alarm result is that there is no alarm, the security data is determined to be successfully processed, and the processing success information is recorded to generate the security log. When the processing status is processing failure, the processing failure information is recorded to generate the security log.

5. The method for processing secure data using the built-in data processing unit according to claim 1, characterized in that, Obtaining the security data includes: Based on the third hardware acceleration unit, the network data sent by the security device is received, the network data is analyzed for security, and the network data with potential security risks is identified as the secure data.

6. A method for processing secure data with a built-in data processing unit, characterized in that, Applied to cloud platforms, including: Acquire historical security data, determine response actions that match the historical security data from the response action library, and orchestrate the response actions to obtain the initial script of the historical security data; The initial script is sent to the edge device; wherein, the data processing unit of the edge device, based on the first hardware acceleration unit, takes the initial script that matches the security data as the processing script for the security data, and sends processing instructions to the security device based on the second hardware acceleration unit and the processing script; the security device executes the processing instructions to process the security data.

7. The method for processing secure data using a built-in data processing unit according to claim 6, characterized in that, After sending the initial script to the end-side device, the process further includes: Receive the security log sent by the data processing unit; Based on the security log, the initial script is updated, and the updated initial script is sent to the edge device; wherein, the data processing unit of the edge device matches the processing script corresponding to the security data in the updated initial script.

8. A secure data processing system with a built-in secure data processing unit, characterized in that, A method for processing secure data applied to a built-in data processing unit as described in any one of claims 1 to 7, comprising an end-side device, a cloud platform, and a security device, wherein the end-side device includes at least one data processing unit, the cloud platform is connected to the data processing unit, and the data processing unit is connected to the security device; The security device is used to monitor the network to obtain network data, preprocess the network data, and send the preprocessed network data to the data processing unit to execute processing instructions to process the security data. The data processing unit is used to determine security data based on the network data, based on the third hardware acceleration unit. Based on the first hardware acceleration unit, the initial script that matches the security data is used as the processing script for the security data. Based on the second hardware acceleration unit and the processing script, processing instructions are sent to the security device; The system receives the processing status of the security data sent by the security device; generates a security log based on the processing status; and sends the security log to the cloud platform. The cloud platform is used to update the initial script based on the security logs and send the updated initial script to the data processing unit.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the secure data processing method of the built-in data processing unit as described in any one of claims 1 to 7.

10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the secure data processing method of the built-in data processing unit as described in any one of claims 1 to 7.