Method, device, equipment, medium and product for processing business of computing power network

By assessing and evaluating the security risks of cloud platform computing nodes and formulating migration strategies for business nodes, the problem of insufficient security in ensuring the continuity of computing network services was solved, and higher migration reliability and business continuity were achieved.

CN118802916BActive Publication Date: 2026-02-24CHINA MOBILE GROUP DESIGN INST +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410709262.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-03
Publication Date
2026-02-24
Estimated Expiration
2044-06-03

AI Technical Summary

Technical Problem

In existing technologies, the business continuity assurance solutions for computing power networks have insufficient security and cannot meet the current business needs of computing power networks.

Method used

By acquiring node data from each computing node in the cloud platform, a security risk assessment is conducted to determine the risk assessment values ​​of the computing nodes and the cloud platform. A migration strategy for business nodes is then formulated, including the migration type and sequence, to ensure the secure migration of business nodes.

Benefits of technology

It improves the reliability of business node migration and the continuity of computing network services, ensuring that the impact can be effectively reduced in the event of security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802916B_ABST
    Figure CN118802916B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a kind of computing power network business processing method, device, equipment, medium and product, its method includes: obtaining the node data of each computing node in cloud platform;Wherein, node data at least includes the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, abnormal performance index information;The node data of each computing node is carried out security risk evaluation processing, and the first risk assessment value of the business node of target computing power business in computing node is determined according to the processing result;The security risk assessment of the cloud platform corresponding to the business node is carried out, and the security assessment result of cloud platform is obtained;In the case where it is determined that the business node meets the migration condition, the migration strategy of the business node is determined based on the security assessment result of cloud platform and the first risk assessment value of the business node.The present disclosure can guarantee the continuity of business in computing power network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data security, and in particular to a service processing method, apparatus, equipment, medium, and product for a computing power network. Background Technology

[0002] A computing network is a new type of information infrastructure that allocates and flexibly schedules computing, storage, and network resources on demand across the cloud, network, and edge based on business needs. The rise of computing networks has led to increased security risks, with a growing risk of attacks on computing network service nodes. When encountering security risks, ensuring the continuity of computing network services becomes paramount while minimizing their impact.

[0003] In related technologies, solutions for ensuring the continuity of computing network services are mainly divided into scanning and hardening, security posture assessment and security migration. However, the security solutions in these technologies have insufficient security and can no longer meet the current business needs of computing networks. Summary of the Invention

[0004] This disclosure provides a service processing method, apparatus, equipment, medium, and product for computing power networks.

[0005] According to a first aspect of this disclosure, a service processing method for a computing power network is provided, the method comprising:

[0006] Obtain node data for each computing node in the cloud platform; wherein, the node data includes at least the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information;

[0007] A security risk assessment is performed on the node data of each computing node, and the first risk assessment value of the business node of the target computing power service in the computing node is determined based on the processing result.

[0008] A security risk assessment is performed on the cloud platform corresponding to the business node to obtain the security assessment result of the cloud platform;

[0009] If the business node meets the migration conditions, a migration strategy for the business node is determined based on the security assessment results of the cloud platform and the first risk assessment value of the business node.

[0010] Further, the step of performing security risk assessment processing on the node data of each computing node, and determining the first risk assessment value of the business node of the target computing power service in the computing node based on the processing result, includes:

[0011] A security risk assessment is performed on each computing node based on the node data of each computing node to obtain a second risk assessment value for each computing node;

[0012] Based on the second risk assessment value of the computing node, the risk assessment value of the business node of the target computing power service is calculated to obtain the first risk assessment value.

[0013] Further, the step of performing a security risk assessment on the computing nodes based on the node data of each computing node to obtain a second risk assessment value for each computing node includes:

[0014] Determine the security evaluation value of each sub-node data of each type of node data in the node data;

[0015] Based on the security evaluation values ​​of each sub-node data, determine the overall security score of this type of node data;

[0016] The overall security score of each computing node for various types of node data is weighted and calculated to obtain the second risk assessment value of the computing node.

[0017] Further, the step of calculating the risk assessment value of the service node of the target computing power service based on the second risk assessment value of the computing node to obtain the first risk assessment value includes:

[0018] Determine the node type of the target computing nodes included in the business nodes, and determine the node security information of the target computing nodes for each node type;

[0019] The preset scoring conditions are determined based on the node security information of the target computing node of at least some of the node types.

[0020] The node security information is calculated based on the preset scoring conditions to obtain the first risk assessment value.

[0021] Furthermore, the step of conducting a security risk assessment on the cloud platform corresponding to the business node to obtain the security assessment result of the cloud platform includes:

[0022] Obtain risk monitoring data from the cloud platform; wherein the risk monitoring data includes at least one of the following: abnormal node percentage information, abnormal internal network behavior information, abnormal external related intelligence information, abnormal data outflow information, and abnormal resource consumption information;

[0023] A security assessment of the cloud platform is conducted based on the risk monitoring data to obtain the security assessment results of the cloud platform.

[0024] Furthermore, when it is determined that the business node meets the migration conditions, the migration strategy for the business node is determined based on the security assessment results of the cloud platform and the first risk assessment value of the business node, including:

[0025] If the business node meets the migration conditions, the migration type of the business node is determined based on the security assessment results and the service latency of the cloud platform; wherein, the migration type includes internal migration or external migration.

[0026] The migration order of the business nodes is determined based on the first risk assessment value of the business nodes;

[0027] Based on the migration type and the migration order, the migration strategy for the business node is determined.

[0028] Further, determining the migration order of the business nodes based on the first risk assessment value of the business nodes includes:

[0029] The migration time coefficient is determined based on the migration time tolerance threshold;

[0030] Based on the migration time coefficient and the first risk assessment value of the business node, a migration order score is determined;

[0031] The migration order of the business nodes is determined based on the migration order score.

[0032] Furthermore, after determining the migration strategy for the business node based on the security assessment results of the cloud platform and the first risk assessment value of the business node, the method further includes:

[0033] Based on the migration type in the migration strategy, determine the target business node after the migration of the business node;

[0034] The business node is added to the migration queue based on the migration order in the migration strategy, so that the cloud platform migrates the business node to the target business node in sequence according to the migration queue.

[0035] Further, adding the service node to the migration queue based on the migration order in the migration strategy includes:

[0036] When the business node is at the head of the migration queue, the computing power user stops using the business node and the business node is migrated to the target business node.

[0037] Further, adding the service node to the migration queue based on the migration order in the migration strategy includes:

[0038] During the real-time sequential scanning of the migration queue, if no user requests are received from any service node in the migration queue within a preset time, the service node will be migrated to the target service node.

[0039] According to a second aspect of this disclosure, a service processing apparatus for a computing power network is provided, the apparatus comprising:

[0040] The acquisition module is used to acquire node data of each computing node in the cloud platform; wherein, the node data includes at least the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance index information;

[0041] The first determining module is used to perform security risk assessment processing on the node data of each computing node, and determine the first risk assessment value of the business node of the target computing power service in the computing node according to the processing result.

[0042] The assessment module is used to conduct a security risk assessment on the cloud platform corresponding to the business node and obtain the security assessment result of the cloud platform.

[0043] The second determining module is used to determine the migration strategy of the business node based on the security assessment results of the cloud platform and the first risk assessment value of the business node, when it is determined that the business node meets the migration conditions.

[0044] According to a third aspect of this disclosure, an electronic device is provided. The electronic device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the program to implement the method described above.

[0045] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the methods described above.

[0046] According to a fifth aspect of this disclosure, a computer program product is provided. The computer program product includes a computer program that, when executed by a processor, implements the methods described above in this disclosure.

[0047] This disclosure provides a service processing method, apparatus, device, medium, and product for a computing power network. In this embodiment, firstly, node data of each computing node in a cloud platform is acquired; wherein the node data includes at least the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information; then, a security risk assessment is performed on the node data of each computing node, and a first risk assessment value for the service node of the target computing power service in the computing node is determined based on the processing result; subsequently, a security risk assessment is performed on the cloud platform corresponding to the service node to obtain the security assessment result of the cloud platform; finally, if it is determined that the service node meets the migration conditions, a migration strategy for the service node is determined based on the security assessment result of the cloud platform and the first risk assessment value of the service node.

[0048] As described above, by performing security risk assessments on the node data of each computing node in the cloud platform to determine the first risk assessment value of the business node for the target computing power service, and by determining the security assessment results of the cloud platform, the node risk of the business node can be assessed more accurately and reasonably. When the business node meets the migration conditions, the first risk assessment value and the security assessment results can be used to determine a more suitable migration strategy for the business node, thereby improving the reliability of the business node migration and ensuring the continuity of computing power network services. Attached Figure Description

[0049] Further details, features, and advantages of this disclosure are disclosed in the following description of exemplary embodiments in conjunction with the accompanying drawings, in which:

[0050] Figure 1 A flowchart of a service processing method for a computing network provided as an exemplary embodiment of this disclosure;

[0051] Figure 2 A schematic diagram of real-time security monitoring of computing power networks provided as an exemplary embodiment of this disclosure;

[0052] Figure 3 A schematic diagram of cloud platform security risk assessment provided for an exemplary embodiment of this disclosure;

[0053] Figure 4 A flowchart of a service processing method for a computing network provided as another exemplary embodiment of this disclosure;

[0054] Figure 5 A flowchart of a service processing method for a computing network provided as another exemplary embodiment of this disclosure;

[0055] Figure 6 A flowchart of a service processing method for a computing network provided as another exemplary embodiment of this disclosure;

[0056] Figure 7 A schematic block diagram of functional modules of a service processing apparatus for a computing network provided in an exemplary embodiment of this disclosure;

[0057] Figure 8 A structural block diagram of an electronic device provided as an exemplary embodiment of this disclosure;

[0058] Figure 9 A block diagram of a computer system provided for an exemplary embodiment of this disclosure. Detailed Implementation

[0059] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0060] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0061] The term "comprising" and its variations as used herein are open-ended, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below. It should be noted that the concepts of "first", "second", etc., used in this disclosure are only used to distinguish different devices, modules, or units, and are not intended to limit the order of functions performed by these devices, modules, or units or their interdependencies.

[0062] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0063] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0064] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.

[0065] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.

[0066] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device. It is understood that the above notification and user authorization process is merely illustrative and does not constitute a limitation on the implementation of this disclosure; other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0067] In one embodiment, such as Figure 1 As shown, a service processing method for a computing power network is provided, including the following steps:

[0068] Step 101: Obtain node data for each computing node in the cloud platform.

[0069] During user access to the computing power network, the network performs real-time security monitoring of computing nodes, acquiring node data from each node in the cloud platform. This node data includes at least the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information. The acquired node data is used by the computing power network to perform security risk assessments on each computing node, thereby determining the first risk assessment value for the business node of the target computing power service within the computing node based on the processing results. It should be noted that node data can contain more data types, and the specific data content included in the node data is not limited here.

[0070] In one possible embodiment, such as Figure 2 As shown, Figure 2 An exemplary schematic diagram of real-time security monitoring of a computing power network is shown. The computing power network performs real-time security monitoring of computing nodes. Through this real-time security monitoring, information on abnormal node behavior, abnormal data usage, abnormal network access, and abnormal performance indicators of each computing node can be obtained.

[0071] Specifically, the computing power network acquires abnormal node behavior information from each computing node by collecting threat monitoring data from the threat monitoring and traffic auditing systems of each cloud platform. Computing power users' data exists only within their own business nodes and supports automatic deletion upon expiration. Abnormal data usage information acquired by the computing power network for each computing node includes, but is not limited to, data usage on insecure computing nodes, unauthorized data access, incomplete data deletion, and data not deleted upon expiration. The computing power network also acquires abnormal network access information from each computing node by collecting traffic between business nodes of the target computing power service within the computing nodes, constructing network access relationships, generating corresponding feature models based on these relationships, and using these feature models to match new network access. The computing power network acquires abnormal network access information for each computing node; it also acquires abnormal performance metrics information for each computing node. For each cloud platform, the computing power network compiles and lists the resource utilization of each computing node, including but not limited to: CPU utilization, memory utilization, disk utilization, GPU utilization, task execution count, and FPGA utilization. Based on the resource utilization of each computing node, the computing power network acquires performance metrics for each computing node. These performance metrics are the result of a comprehensive consideration of factors such as node resource utilization, energy consumption, and load. Based on this comprehensive consideration, abnormal performance metrics information is acquired, highlighting special cases such as sudden increases in hardware utilization and short-term spikes in task execution count.

[0072] Step 102: Perform security risk assessment on the node data of each computing node, and determine the first risk assessment value of the business node of the target computing power service in the computing node based on the processing results.

[0073] Here, after acquiring the node data of each computing node in the cloud platform, the computing power network can perform security risk assessment on the node data of each computing node, and determine the first risk assessment value of the business node of the target computing power service within the computing node based on the processing results. The business node corresponding to the target computing power service can consist of multiple computing nodes.

[0074] Step 103: Conduct a security risk assessment on the cloud platform corresponding to the business node to obtain the security assessment results of the cloud platform.

[0075] Here, after the computing power network performs security risk assessment on the node data of each computing node and determines the first risk assessment value of the business node of the target computing power service in the computing node based on the processing results, the computing power network can perform security risk assessment on the cloud platform corresponding to the business node, thereby obtaining the security assessment result of the cloud platform.

[0076] In one possible embodiment, the above steps involve conducting a security risk assessment on the cloud platform corresponding to the business node to obtain the security assessment result of the cloud platform, including the following steps:

[0077] Obtain risk monitoring data from the cloud platform;

[0078] The cloud platform is assessed for security based on risk monitoring data, and the security assessment results of the cloud platform are obtained.

[0079] Specifically, such as Figure 3 As shown, Figure 3 An exemplary diagram illustrating a cloud platform security risk assessment is provided. After the computing network performs security risk assessment processing on the node data of each computing node and determines the first risk assessment value of the business node for the target computing power service within the computing nodes based on the processing results, the computing network acquires risk monitoring data from the cloud platform. This risk monitoring data includes at least one of the following: abnormal node percentage information, abnormal internal network behavior information, abnormal external correlation intelligence information, abnormal data outflow information, and abnormal resource consumption information. After acquiring the cloud platform's risk monitoring data, the computing network can perform a security assessment of the cloud platform based on the abnormal node percentage information, abnormal internal network behavior information, abnormal external correlation intelligence information, abnormal data outflow information, and abnormal resource consumption information within the risk monitoring data, thereby obtaining the cloud platform's security assessment result.

[0080] Step 104: If the business node meets the migration conditions, determine the migration strategy for the business node based on the security assessment results of the cloud platform and the first risk assessment value of the business node.

[0081] After conducting a security risk assessment of the cloud platform corresponding to the business node, the computing power network determines whether the business node meets the migration conditions. If the business node meets the migration conditions, the network determines the migration strategy based on the cloud platform's security assessment results and the business node's first risk assessment value. This migration strategy can indicate the migration type and / or migration order of the business node.

[0082] In one possible embodiment, after determining that the business node meets the migration conditions, a migration strategy for the business node is determined based on the security assessment results of the cloud platform and the first risk assessment value of the business node, including the following steps:

[0083] Once it is determined that the business nodes meet the migration conditions, the migration type of the business nodes is determined based on the security assessment results and the business latency of the cloud platform.

[0084] The migration order of business nodes is determined based on the first risk assessment value of the business nodes;

[0085] Based on the migration type and migration order, determine the migration strategy for business nodes.

[0086] Specifically, after conducting a security risk assessment on the cloud platform corresponding to the business node and obtaining the security assessment results of the cloud platform, the computing power network can determine the migration type of the business node based on the security assessment results of the cloud platform and the business latency of the cloud platform, provided that the business node meets the migration conditions. The migration type includes internal migration or external migration.

[0087] Internal migration refers to the business migration operation within the cloud platform, switching from the original business node to a new internal business node; external migration refers to the business node migration operation outside the cloud platform, switching from the original node to a new cloud platform node.

[0088] After determining the migration type of a business node, the computing power network determines the migration order of the business nodes based on the first risk assessment value of the business nodes. After determining the migration order and migration type of the business nodes, the computing power network determines the migration strategy of the business nodes based on the migration type and migration order. For example, the migration type and / or migration order can be determined as the strategy content of the migration strategy.

[0089] As described above, this application embodiment determines the first risk assessment value of the business node of the target computing power service within the computing nodes by performing security risk assessment processing on the node data of each computing node in the cloud platform, and determines the security assessment result of the cloud platform. This method can more accurately and reasonably assess the node risk of the business node. When it is determined that the business node meets the migration conditions, a more suitable migration strategy can be determined for the business node using the first risk assessment value and the security assessment result, thereby improving the reliability of the business node migration and ensuring the continuity of computing power network services.

[0090] In one embodiment, such as Figure 4 As shown, a security risk assessment is performed on the node data of each computing node, and the first risk assessment value of the business node of the target computing power service in the computing node is determined based on the processing result. Step 102 also includes the following steps:

[0091] Step 401: Perform a security risk assessment on each computing node based on the node data of each computing node to obtain a second risk assessment value for each computing node.

[0092] After acquiring node data from each computing node in the cloud platform, the computing power network performs a security risk assessment on each computing node based on the node data, and obtains a second risk assessment value for each computing node.

[0093] In one possible embodiment, the above steps involve performing a security risk assessment on each computing node based on the node data of each computing node to obtain a second risk assessment value for each computing node, including the following steps:

[0094] Determine the security evaluation value of each child node data for each type of node data in the node data;

[0095] Based on the security evaluation values ​​of each sub-node data, determine the overall security score of this type of node data;

[0096] The overall security score of each computing node for various types of node data is weighted and calculated to obtain the second risk assessment value of that computing node.

[0097] Specifically, the computing power network performs real-time security monitoring of computing nodes. After acquiring node data from each computing node in the cloud platform, which includes abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance index information, the computing power network determines the security evaluation value of each sub-node data of each type of node data in the node data.

[0098] For example, the computing power network obtains abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information for each computing node in the cloud platform. The sub-node data for the abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information are shown in the table below:

[0099]

[0100]

[0101] There are four types of node data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information. Each type of node data contains different types of sub-node data. It should be noted that the table above only shows the sub-node data of abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information as examples. The sub-node data of each node data can also include more content, and there are no restrictions on the specific content of the sub-node data.

[0102] For example, the computing power network obtains abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance index information for each computing node in the cloud platform. Among them, the abnormal data usage information includes four sub-node data: abnormal data flow, abnormal use of sensitive data, historical data not cleared in time, and data that can be recovered after clearing.

[0103] In this embodiment of the disclosure, firstly, the security evaluation value of each child node data of each type of node data in the node data is determined. The security evaluation values ​​of these four child node data are b1, b2, b3, and b4, respectively. The maximum value b among b1, b2, b3, and b4 is selected. max Except for the maximum value b max In addition, the security evaluation values ​​of the other sub-node data are taken as averages. The calculation formula is:

[0104]

[0105] Where, n 数 For abnormal data, use the information about the types of child node data, and obtain the value excluding the maximum value b. max Average percentage outside The calculation formula is:

[0106]

[0107] Where M is the total risk score of b1, b2, b3, and b4, which is a fixed value.

[0108] Then, obtain the overall security score N for the use of abnormal data. 数 The calculation formula is:

[0109]

[0110] Using the same method, the overall security score for abnormal node behavior information, abnormal network access information, and abnormal performance indicator information can be calculated as N. 节 N 网 N 性 It should be noted that the specific calculation process for the overall security score of abnormal node behavior information, abnormal network access information, and abnormal performance indicator information is different from the overall security score N for the aforementioned abnormal data usage information. 数 The calculation process is the same, and will not be repeated here.

[0111] The overall security score N obtained includes information on abnormal node behavior, abnormal data usage, abnormal network access, and abnormal performance metrics. 节 N 数 N 网 N 性 Then, the overall security score of each computing node for various types of node data is weighted and calculated to obtain the second risk assessment value of that computing node.

[0112] For example, with T as the total weight, a weighted score T is assigned to each of the following factors to comprehensively consider the impact of abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance index information on security in the computing power network.节 T 数 T 网 T 性 The overall security score for each computing node is weighted based on its abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance index information to obtain the second risk assessment value Z for that computing node. The calculation formula is as follows:

[0113]

[0114] Step 402: Based on the second risk assessment value of the computing node, calculate the risk assessment value of the business node of the target computing power service to obtain the first risk assessment value.

[0115] After the computing power network performs a security risk assessment on each computing node based on the node data of each computing node and obtains a second risk assessment value for each computing node, it can calculate the risk assessment value of the business node of the target computing power service based on the second risk assessment value of the computing node and obtain the first risk assessment value.

[0116] In one possible embodiment, the above steps, based on the second risk assessment value of the computing node, calculate the risk assessment value of the service node of the target computing power service to obtain the first risk assessment value, including the following steps:

[0117] Determine the node types of the target computing nodes contained in the business nodes, and determine the node security information of the target computing nodes for each node type;

[0118] The preset scoring conditions are determined based on the node security information of the target computing node based on at least some node types.

[0119] The node security information is calculated based on preset scoring conditions to obtain the first risk assessment value.

[0120] Specifically, after the computing power network performs a security risk assessment on the computing nodes based on the node data of each computing node and obtains a second risk assessment value for each computing node, the computing power network can determine the node type of the target computing nodes contained in the business nodes and determine the node security information of the target computing nodes for each node type.

[0121] For example, the computing power network determines the node type of the target computing nodes included in the service nodes. Node types include presentation nodes, computing nodes, database nodes, and other nodes. After classifying the target computing nodes, it determines the node security information of the target computing nodes (presentation nodes, computing nodes, and database nodes). For example, Z... 数1 The second risk assessment value of the first compute node in the database node determines the node security information of the target compute node of the database node type as follows:

[0122]

[0123] Where n is the number of database nodes in the target computing node.

[0124] Here, the same method can be used to calculate the node security information Z for both the display node and the computing node. 展 and Z 运 It should be noted that the specific calculation process for the node security information of the display node and the computing node is the same as the calculation process for the node security information of the target computing node of the database node type mentioned above, and will not be repeated here.

[0125] After determining the node security information of the target computing nodes for each node type, the preset scoring conditions that must be met are determined based on the node security information of the target computing nodes for at least some node types. Then, the node security information is calculated based on the preset scoring conditions to obtain the first risk assessment value.

[0126] In one possible embodiment, the node security information is calculated based on preset scoring conditions to obtain a first risk assessment value, including:

[0127] If the number of first target computing nodes of the first node type is greater than a first quantity and the node security information of the first target computing nodes is greater than a first threshold, the difference between the target value and the node security information of the first target computing nodes of each first node type is calculated to obtain multiple differences. The product of the multiple differences is calculated, and the difference between the target value and the product is calculated to obtain the first risk assessment value.

[0128] For example, the maximum value of the node security information of the target computing node is M. When the first node type is a display node, a computing node, or a database node, the first quantity is 1, and the first threshold is 0.6M, if the number of the first target computing nodes (display node, computing node, database node) is greater than the first quantity of 1, and the node security information of the first target computing node is greater than the first threshold of 0.6M, the difference between the target value and the node security information of the first target computing node of each first node type (1-Z) is calculated. 展 (1-Z) 运 (1-Z) 数 ), through formula Z 总 =1-(1-Z) 展 (1-Z) 运 (1-Z) 数 Calculate the first risk assessment value.

[0129] When the first node type is any two of the following: display node, computation node, and database node, for example, when the first node type is both display node and computation node, and the number of first target computation nodes for display nodes and computation nodes is greater than a first quantity of 1, and the node security information of the first target computation node is greater than a first threshold of 0.6M, the difference between the computation target value and the node security information of the first target computation node for each first node type is (1-Z). 展 (1-Z) 运 ), through formula Z 总 =1-(1-Z) 展 (1-Z) 运 Calculate the first risk assessment value.

[0130] When the first node type is any one of display node, computation node, or database node, for example, when the first node type is display node, and the number of first target computation nodes of the display node is greater than the first quantity 1, and the node security information of the first target computation node is greater than the first threshold 0.6M, the difference between the computation target value and the node security information of the first target computation node of the first node type (1-Z) 展 ), through formula Z 总 =1-(1-Z) 展 ) = Z 展 Calculate the first risk assessment value.

[0131] In another possible embodiment, when the node security information of the target computing node based on at least some node types cannot determine the satisfied preset scoring conditions, the first risk assessment value Z... 总 The average value of the node security information for all target computation nodes, i.e. It should be noted that the preset scoring criteria can also be set to other content, and there are no restrictions on the content of the preset scoring criteria here.

[0132] In this embodiment, firstly, the computing power network performs a security risk assessment on each computing node based on the node data of each computing node, and obtains a second risk assessment value for each computing node through weighted calculation. Then, based on the second risk assessment value of the computing nodes, the computing power network calculates the risk assessment value of the business nodes of the target computing power service to obtain a first risk assessment value. In this embodiment, the second risk assessment value obtained by performing a security risk assessment on each computing node is used to calculate the first risk assessment value of the entire business node. The obtained first risk assessment value can more accurately reflect the operating status of the business nodes and improve the security of the computing power network service processing method.

[0133] In one embodiment, such as Figure 5 As shown, the migration order of business nodes is determined based on the first risk assessment value of the business nodes. Step 104 also includes the following steps:

[0134] Step 501: Determine the migration time coefficient based on the migration time tolerance threshold.

[0135] When the computing power network determines that a service node meets the migration conditions, after determining the migration type of the service node based on the security assessment result and the service delay of the cloud platform, the computing power network obtains the estimated time consumed in the migration process from the historically statistical migration data, and determines the migration time coefficient according to the set migration time tolerance threshold.

[0136] In a possible embodiment, the computing power network obtains the estimated time consumed in the migration process from the historically statistical migration data, and determines the migration time coefficient according to the set migration time tolerance threshold. Exemplarily, the set migration time tolerance thresholds are N1 and N2, and the migration time coefficients are i1, i2, i3, where i1 > i2 > i3, N1 < N2. The computing power network calculates the estimated time consumed in the migration process from the historically statistical migration data. If the computing power network calculates that the estimated time consumed in the migration process is less than N1 seconds, the migration time coefficient is i1; if the computing power network calculates that the estimated time consumed in the migration process is greater than N1 seconds and less than N2 seconds, the migration time coefficient is i2; if the computing power network calculates that the estimated time consumed in the migration process is greater than N2 seconds, the migration time coefficient is i3.

[0137] Step 502: Determine the migration order score based on the migration time coefficient and the first risk assessment value of the service node.

[0138] After the computing power network determines the migration time coefficient based on the migration time tolerance threshold, it determines the migration order score based on the migration time coefficient and the first risk assessment value of the service node.

[0139] In a possible embodiment, the computing power network determines the migration order score based on the migration time coefficient and the first risk assessment value of the service node. The migration order score is the first risk assessment value of the service node of the target computing power service multiplied by the migration time coefficient. Exemplarily, the first risk assessment value of the service node of the target computing power service is Z 总 and the corresponding migration time coefficient is i3, then the migration order score of the service node of the target computing power service is Z 总 * i3. It should be noted that the migration order score can also be other algorithms, which are not limited here.

[0140] Step 503: Determine the migration order of the service node based on the migration order score.

[0141] After the computing power network determines the migration order score based on the migration time coefficient and the first risk assessment value of the service node, it determines the migration order of the service node based on the migration order score.

[0142] In one possible embodiment, the computing power network determines a migration order score based on a migration time coefficient and a first risk assessment value of the business node. Then, the computing power network determines the migration order of the business nodes according to the migration order score from high to low. For example, if the migration order score of business node 1 is 95, the migration order score of business node 2 is 96, and the migration order score of business node 3 is 88, then the migration order of the business nodes is: business node 2 — business node 1 — business node 3.

[0143] In this embodiment, firstly, the computing power network determines a migration time coefficient based on a migration time tolerance threshold. Then, the computing power network determines a migration order score based on the migration time coefficient and the first risk assessment value of the service node. Finally, the computing power network determines the migration order of the service node based on the migration order score. This embodiment determines the migration order score based on the migration time coefficient and the first risk assessment value of the service node, and determines the migration order of the service node based on the migration order score, which improves the reliability and accuracy of the migration of service nodes and ensures the continuity of computing power network services.

[0144] In one embodiment, such as Figure 6 As shown, a service processing method for a computing power network is also provided, including the following steps:

[0145] Step 601: Based on the migration type in the migration strategy, determine the target business node after the migration of the business node.

[0146] After determining the migration strategy for the business node based on the security assessment results of the cloud platform and the first risk assessment value of the business node, the computing power network determines the target business node after migration based on the migration type in the migration strategy.

[0147] In one possible embodiment, after determining the migration strategy of the business node based on the security assessment results of the cloud platform and the first risk assessment value of the business node, the computing power network determines the target business node after migration based on the migration type in the migration strategy. For example, when the migration type in the migration strategy is internal migration, the computing power network determines the target business node after migration within the cloud platform and sends the information of the target business node to the cloud platform.

[0148] In another possible embodiment, when the migration type in the migration strategy is external migration, the computing power network determines the target business node after the migration of the business node in the new cloud platform, and sends the information of the target business node to the cloud platform where the original business node is located.

[0149] Step 602: Add the business nodes to the migration queue based on the migration order in the migration strategy, so that the cloud platform can migrate the business nodes to the target business nodes in sequence according to the migration queue.

[0150] Based on the migration type in the migration strategy, the computing power network determines the target business node after the migration of the business node, and adds the business node to the migration queue according to the migration order in the migration strategy, so that the cloud platform can migrate the business node to the target business node in sequence according to the migration queue.

[0151] In one possible embodiment, adding service nodes to the migration queue based on the migration order in the migration strategy includes the following steps:

[0152] When a business node is at the head of the migration queue, stop the computing power user from using the business node and migrate the business node to the target business node.

[0153] Specifically, the computing power network determines the target business node after the migration of the business node based on the migration type in the migration strategy. Then, it adds the business node to the migration queue according to the migration order in the migration strategy. The cloud platform migrates the business nodes to the target business node in sequence according to the migration queue. When the business node is at the head of the migration queue, the computing power user stops using the business node and migrates the business node to the target business node. After the migration of the business node is completed, the computing power network migrates other business nodes in sequence according to the migration queue.

[0154] In one possible embodiment, adding service nodes to the migration queue based on the migration order in the migration strategy further includes the following steps:

[0155] During the real-time scanning of the migration queue in sequence, if there are no user requests for a business node in the migration queue within a preset time, the business node will be migrated to the target business node.

[0156] Specifically, after determining the target business node after migration based on the migration type in the migration strategy, the computing power network adds the business node to the migration queue according to the migration order in the migration strategy. The computing power network scans the migration queue in real time in sequence. If there are no user requests for a business node in the migration queue within a preset time during the real-time scanning process, the computing power network will prioritize processing the business node and migrate it to the target business node.

[0157] In this embodiment, the computing power network determines the target business node after migration based on the migration type in the migration strategy. Then, the computing power network adds the business node to the migration queue based on the migration order in the migration strategy, so that the cloud platform migrates the business node to the target business node in sequence according to the migration queue. The computing power network migrates the business node according to the migration strategy, which improves the security and reliability of the migration and ensures the continuity of computing power network services.

[0158] By dividing each function into corresponding functional modules, this disclosure provides a service processing device for a computing power network. This service processing device for a computing power network can be a server or a chip applied to a server. Figure 7 This is a schematic block diagram of the functional modules of a service processing apparatus for a computing network provided as an exemplary embodiment of this disclosure. Figure 7 As shown, the service processing device of this computing network includes:

[0159] The acquisition module 701 is used to acquire node data of each computing node in the cloud platform; wherein, the node data includes at least the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance index information.

[0160] The first determining module 702 is used to perform security risk assessment processing on the node data of each computing node, and determine the first risk assessment value of the business node of the target computing power service in the computing node according to the processing result.

[0161] The assessment module 703 is used to conduct a security risk assessment on the cloud platform corresponding to the business node and obtain the security assessment result of the cloud platform.

[0162] The second determining module 704 is used to determine the migration strategy of the business node based on the security assessment result of the cloud platform and the first risk assessment value of the business node when it is determined that the business node meets the migration conditions.

[0163] In one embodiment, the first determining module 702 includes:

[0164] The first acquisition unit is used to perform a security risk assessment on the computing node based on the node data of each computing node, and obtain a second risk assessment value for each computing node;

[0165] The second acquisition unit is used to calculate the risk assessment value of the business node of the target computing power service based on the second risk assessment value of the computing node, and obtain the first risk assessment value.

[0166] In one embodiment, the first determining module 702 includes:

[0167] The first determining unit is used to determine the security evaluation value of each sub-node data of each type of node data in the node data;

[0168] The second determining unit is used to determine the overall security score of the type of node data based on the security evaluation values ​​of each sub-node data.

[0169] The third acquisition unit is used to perform a weighted calculation of the overall security score of various types of node data for each computing node to obtain the second risk assessment value of the computing node.

[0170] In one embodiment, the first determining module 702 includes:

[0171] The third determining unit is used to determine the node type of the target computing node included in the business node, and to determine the node security information of the target computing node for each node type;

[0172] The fourth determining unit is used to determine the preset scoring conditions that are met based on the node security information of the target computing node of at least some of the node types.

[0173] The fourth acquisition unit is used to perform calculations on the node security information based on the preset scoring conditions to obtain the first risk assessment value.

[0174] In one embodiment, the evaluation module 703 includes:

[0175] The fifth acquisition unit is used to acquire risk monitoring data of the cloud platform; wherein the risk monitoring data includes at least one of the following: abnormal node percentage information, abnormal internal network behavior information, abnormal external related intelligence information, abnormal data outflow information, and abnormal resource consumption information;

[0176] An assessment unit is used to perform a security assessment on the cloud platform based on the risk monitoring data, and obtain the security assessment result of the cloud platform.

[0177] In one embodiment, the second determining module 704 includes:

[0178] The fifth determining unit is used to determine the migration type of the business node based on the security assessment results and the service latency of the cloud platform, when it is determined that the business node meets the migration conditions; wherein the migration type includes internal migration or external migration;

[0179] The sixth determining unit is used to determine the migration order of the business nodes based on the first risk assessment value of the business nodes;

[0180] The seventh determining unit is used to determine the migration strategy of the service node based on the migration type and the migration order.

[0181] In one embodiment, the second determining module 704 includes:

[0182] The eighth determining unit is used to determine the migration time coefficient based on the migration time tolerance threshold;

[0183] The ninth determining unit is used to determine the migration order score based on the migration time coefficient and the first risk assessment value of the business node;

[0184] The tenth determining unit is used to determine the migration order of the service nodes based on the migration order score.

[0185] In one embodiment, the apparatus further includes:

[0186] The third determining module is used to determine the target business node after the migration of the business node based on the migration type in the migration strategy.

[0187] The migration module is used to add the business nodes to the migration queue based on the migration order in the migration strategy, so that the cloud platform migrates the business nodes to the target business node in sequence according to the migration queue.

[0188] In one embodiment, the migration module includes:

[0189] The first migration unit is used to stop the computing power user from using the business node when the business node is at the head of the migration queue, and to migrate the business node to the target business node.

[0190] In one embodiment, the migration module includes:

[0191] The second migration unit is used to migrate a service node to the target service node if there are no user requests for a service node in the migration queue within a preset time during the process of sequentially scanning the migration queue in real time.

[0192] This disclosure also provides an electronic device, including: at least one processor; a memory for storing processor-executable instructions; wherein the at least one processor is configured to execute the instructions to implement the methods disclosed in this disclosure.

[0193] Figure 8 This is a schematic diagram of the structure of an electronic device provided as an exemplary embodiment of this disclosure. For example... Figure 8 As shown, the electronic device 800 includes at least one processor 801 and a memory 802 coupled to the processor 801. The processor 801 can perform the corresponding steps in the methods disclosed in the embodiments of this disclosure.

[0194] The processor 801 described above can also be called a central processing unit (CPU), which can be an integrated circuit chip with signal processing capabilities. Each step in the method disclosed in this embodiment can be implemented by the integrated logic circuitry in the processor 801 or by software instructions. The processor 801 can be a general-purpose processor, a digital signal processor (DSP), an ASIC, a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this embodiment can be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor. The software modules can be located in the memory 802, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The processor 801 reads information from the memory 802 and, in conjunction with its hardware, completes the steps of the method described above.

[0195] Furthermore, various operations / processes according to this disclosure, implemented via software and / or firmware, can be transmitted from a storage medium or network to a computer system with a dedicated hardware architecture, such as... Figure 9 The computer system 900 shown is equipped with the programs that constitute the software. When various programs are installed, the computer system is able to perform various functions, including functions such as those described above. Figure 9 A block diagram of a computer system provided for an exemplary embodiment of this disclosure.

[0196] Computer system 900 is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. Electronic devices can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0197] like Figure 9As shown, the computer system 900 includes a computing unit 901, which can perform various appropriate actions and processes based on a computer program stored in a read-only memory (ROM) 902 or a computer program loaded from a storage unit 908 into a random access memory (RAM) 903. The RAM 903 may also store various programs and data required for the operation of the computer system 900. The computing unit 901, ROM 902, and RAM 903 are interconnected via a bus 904. An input / output (I / O) interface 905 is also connected to the bus 904.

[0198] Multiple components in the computer system 900 are connected to the I / O interface 905, including: an input unit 906, an output unit 907, a storage unit 908, and a communication unit 909. The input unit 906 can be any type of device capable of inputting information into the computer system 900. The input unit 906 can receive input numerical or character information and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 907 can be any type of device capable of presenting information and may include, but is not limited to, a monitor, speaker, video / audio output terminal, vibrator, and / or printer. The storage unit 908 may include, but is not limited to, a hard disk and an optical disk. The communication unit 909 allows the computer system 900 to exchange information / data with other devices via a network such as the Internet, and may include, but is not limited to, a modem, network card, infrared communication device, wireless communication transceiver, and / or chipset, such as Bluetooth™ device, WiFi device, WiMax device, cellular communication device, and / or the like.

[0199] The computing unit 901 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 901 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 901 performs the various methods and processes described above. For example, in some embodiments, the methods disclosed in this disclosure can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 908. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 800 via ROM 902 and / or communication unit 909. In some embodiments, the computing unit 901 can be configured to perform the methods disclosed in this disclosure by any other suitable means (e.g., by means of firmware).

[0200] This disclosure also provides a computer-readable storage medium, wherein when the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is able to perform the methods disclosed in this disclosure.

[0201] The computer-readable storage medium in this disclosure can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. The aforementioned computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specifically, the aforementioned computer-readable storage medium may include electrical connections based on one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0202] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0203] This disclosure also provides a computer program product, including a computer program, wherein the computer program, when executed by a processor, implements the methods disclosed in the embodiments of this disclosure.

[0204] In embodiments of this disclosure, computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof. These programming languages ​​include, but are not limited to, object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network (including a local area network (LAN) or a wide area network (WAN)), or it can be connected to an external computer.

[0205] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0206] The modules, components, or units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the modules, components, or units do not necessarily limit the module, component, or unit itself.

[0207] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary hardware logic components that can be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0208] The above description is merely an embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0209] While specific embodiments of this disclosure have been described in detail by way of example, those skilled in the art should understand that the examples are for illustrative purposes only and not intended to limit the scope of this disclosure. Those skilled in the art should understand that modifications can be made to the above embodiments without departing from the scope and spirit of this disclosure. The scope of this disclosure is defined by the appended claims.

Claims

1. A service processing method for a computing power network, characterized in that, The method includes: Obtain node data for each computing node in the cloud platform; wherein, the node data includes at least the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance indicator information; A security risk assessment is performed on the node data of each computing node, and the first risk assessment value of the business node of the target computing power service in the computing node is determined based on the processing result. A security risk assessment is performed on the cloud platform corresponding to the business node to obtain the security assessment result of the cloud platform; If the business node meets the migration conditions, the migration strategy for the business node is determined based on the security assessment results of the cloud platform and the first risk assessment value of the business node. The step of performing security risk assessment processing on the node data of each computing node, and determining the first risk assessment value of the business node of the target computing power service in the computing node based on the processing result, includes: A security risk assessment is performed on each computing node based on its node data to obtain a second risk assessment value for each computing node. Determine the node type of the target computing nodes included in the business nodes, and determine the node security information of the target computing nodes for each node type; The preset scoring conditions are determined based on the node security information of the target computing node of at least some of the node types. The node security information is calculated based on the preset scoring conditions to obtain the first risk assessment value; The step of conducting a security risk assessment on the cloud platform corresponding to the business node to obtain the security assessment result of the cloud platform includes: Obtain risk monitoring data from the cloud platform; wherein the risk monitoring data includes at least one of the following: abnormal node percentage information, abnormal internal network behavior information, abnormal external related intelligence information, abnormal data outflow information, and abnormal resource consumption information; Based on the risk monitoring data, a security assessment is performed on the cloud platform to obtain the security assessment result of the cloud platform. If the business node meets the migration conditions, the migration strategy for the business node is determined based on the security assessment results of the cloud platform and the first risk assessment value of the business node, including: If the business node meets the migration conditions, the migration type of the business node is determined based on the security assessment results and the service latency of the cloud platform; wherein, the migration type includes internal migration or external migration. The migration time coefficient is determined based on the migration time tolerance threshold; Based on the migration time coefficient and the first risk assessment value of the business node, a migration order score is determined; The migration order of the business nodes is determined based on the migration order score; Based on the migration type and the migration order, the migration strategy for the business node is determined.

2. The method according to claim 1, characterized in that, The process of performing a security risk assessment on each computing node based on node data to obtain a second risk assessment value for each computing node includes: Determine the security evaluation value of each sub-node data of each type of node data in the node data; Based on the security evaluation values ​​of each sub-node data, determine the overall security score of this type of node data; The overall security score of each computing node for various types of node data is weighted and calculated to obtain the second risk assessment value of the computing node.

3. The method according to claim 1, characterized in that, After determining the migration strategy for the business node based on the security assessment results of the cloud platform and the first risk assessment value of the business node, the method further includes: Based on the migration type in the migration strategy, determine the target business node after the migration of the business node; The business node is added to the migration queue based on the migration order in the migration strategy, so that the cloud platform migrates the business node to the target business node in sequence according to the migration queue.

4. The method according to claim 3, characterized in that, The step of adding the service node to the migration queue based on the migration order in the migration strategy includes: When the business node is at the head of the migration queue, the computing power user stops using the business node and the business node is migrated to the target business node.

5. The method according to claim 3, characterized in that, The step of adding the service node to the migration queue based on the migration order in the migration strategy includes: During the real-time sequential scanning of the migration queue, if no user requests are received from any service node in the migration queue within a preset time, the service node will be migrated to the target service node.

6. A service processing device for a computing power network, characterized in that, The device includes: The acquisition module is used to acquire node data of each computing node in the cloud platform; wherein, the node data includes at least the following types of data: abnormal node behavior information, abnormal data usage information, abnormal network access information, and abnormal performance index information; The first determining module is used to perform security risk assessment processing on the node data of each computing node, and determine the first risk assessment value of the business node of the target computing power service in the computing node according to the processing result. The assessment module is used to conduct a security risk assessment on the cloud platform corresponding to the business node and obtain the security assessment result of the cloud platform. The second determining module is used to determine the migration strategy of the business node based on the security assessment result of the cloud platform and the first risk assessment value of the business node, when it is determined that the business node meets the migration conditions. The first determining module is further configured to: A security risk assessment is performed on each computing node based on its node data to obtain a second risk assessment value for each computing node. Determine the node type of the target computing nodes included in the business nodes, and determine the node security information of the target computing nodes for each node type; The preset scoring conditions are determined based on the node security information of the target computing node of at least some of the node types. The node security information is calculated based on the preset scoring conditions to obtain the first risk assessment value; The evaluation module is also used for: Obtain risk monitoring data from the cloud platform; wherein the risk monitoring data includes at least one of the following: abnormal node percentage information, abnormal internal network behavior information, abnormal external related intelligence information, abnormal data outflow information, and abnormal resource consumption information; Based on the risk monitoring data, a security assessment is performed on the cloud platform to obtain the security assessment result of the cloud platform. The second determining module is further configured to: If the business node meets the migration conditions, the migration type of the business node is determined based on the security assessment results and the service latency of the cloud platform; wherein, the migration type includes internal migration or external migration. The migration time coefficient is determined based on the migration time tolerance threshold; Based on the migration time coefficient and the first risk assessment value of the business node, a migration order score is determined; The migration order of the business nodes is determined based on the migration order score; Based on the migration type and the migration order, the migration strategy for the business node is determined.

7. An electronic device, characterized in that, include: At least one processor; Memory for storing the at least one processor-executable instruction; The at least one processor is configured to execute the instructions to implement the method as described in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the electronic device, the electronic device is enabled to perform the method as described in any one of claims 1-5.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method as described in any one of claims 1-5.

Citation Information

Patent Citations

  • Cloud platform service monitoring method, device, equipment and system and readable storage medium

    CN110191016A

  • Resource migration method and device, computer equipment, storage medium and program product

    CN115454685A

  • Migration method and system of computing power network service and cloud management platform

    CN116418876A