A network resource configuration method and device, electronic equipment and storage medium
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA TELECOM CORP LTD
- Filing Date
- 2024-08-14
- Publication Date
- 2026-08-07
AI Technical Summary
[0004]然而,上述方式无法提供在防御攻击时如何进行资源配置
Smart Images

Figure CN118869326B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things (IoT) technology, and in particular to a network resource configuration method, apparatus, electronic device, and storage medium. Background Technology
[0002] With the development of the Internet of Things (IoT), more and more IoT devices are entering homes and businesses. However, this also brings increasing cybersecurity threats and vulnerabilities. Some IoT devices lack security measures in their design, making them vulnerable to being exposed to the network and controlled as botnets to launch cyberattacks. Distributed Denial of Service (DDoS) attacks, in particular, involve controlling a massive number of botnets to launch attacks against various targets across the network. Therefore, security measures against DDoS attacks are urgently needed.
[0003] In existing technologies, defense and control measures against DDoS attacks often focus on the sharing and blocking of blacklisted addresses.
[0004] However, the above methods do not provide information on how to configure resources when defending against attacks. Summary of the Invention
[0005] This application provides a network resource configuration method, apparatus, electronic device, and storage medium to provide how to configure resources when defending against attacks.
[0006] In a first aspect, embodiments of this application provide a first method for configuring network resources, the method comprising:
[0007] For multiple target resources corresponding to the target network, determine the occupancy information of each target resource; wherein, the multiple target resources are the resources called upon by the target network to defend against network attacks;
[0008] Based on the occupancy information of each target resource, an objective function is determined; wherein, the objective function is a convex function.
[0009] Based on the objective function and the constraints corresponding to each objective resource, the target configuration information corresponding to each objective resource is determined.
[0010] The above scheme sets multiple target resources (i.e., variable factors) that can be configured according to the resources required for network defense, thereby improving the targeting of resource allocation; based on these multiple variable factors, the occupancy information of each target resource is determined, and an objective function to be optimized is further established to determine the mapping relationship between the real physical world and the theoretical model, thereby improving the practical value of the scheme; the constraints corresponding to each target resource are determined according to the actual network situation, thereby further narrowing the optimization scope and improving the feasibility and optimization efficiency of the scheme; by solving and optimizing the objective function under constraints, the target configuration information (optimal resource combination) required to defend against attacks can be obtained when other factors are constant, thereby improving the efficiency and effectiveness of network defense.
[0011] In some alternative implementations, the plurality of target resources include bandwidth resources, computing resources, and memory resources.
[0012] In some optional implementations, if the target resource includes bandwidth resources, the bandwidth resource occupancy information is determined in the following manner:
[0013] Based on the bandwidth sensitivity of the target network, the traffic value of the network attack, and the maximum bandwidth of the target network, determine the bandwidth impact value; and based on the maximum bandwidth of the target network, the basic redundant bandwidth of the target network, and the configuration variables corresponding to the bandwidth resources, determine the bandwidth defense strength.
[0014] Based on the bandwidth impact value and the bandwidth defense strength, the bandwidth resource occupancy information is determined.
[0015] In some optional implementations, if the target resource includes computing resources, the occupancy information of the computing resources is determined in the following manner:
[0016] Based on the computational sensitivity of the target network, the resource request value of the network attack, and the maximum computational resources of the target network, the computational impact value is determined; and based on the maximum computational resources of the target network, the basic redundant computational resources of the target network, and the configuration variables corresponding to the computational resources, the computational defense strength is determined.
[0017] Based on the calculated impact value and the calculated defense strength, the occupancy information of the computing resources is determined.
[0018] In some optional implementations, if the target resource includes memory resources, the memory resource occupancy information is determined in the following way:
[0019] Based on the target network's memory sensitivity, memory correction factor, and the configuration variables corresponding to the memory resources, the memory resource occupancy information is determined.
[0020] In some optional implementations, the objective function is determined based on the occupancy information of each target resource, including:
[0021] The objective function is determined by summing the occupancy information of each target resource and the adjustment factor.
[0022] In some optional implementations, based on the objective function and the constraints corresponding to each objective resource, the target configuration information corresponding to each objective resource is determined, including:
[0023] The constraints are integrated into the objective function to construct the Lagrange function;
[0024] The target configuration information corresponding to the target resource is obtained by iterating over the Lagrange function.
[0025] Secondly, embodiments of this application provide a first network resource configuration apparatus, the apparatus comprising:
[0026] The function establishment module is used to determine the occupancy information of each target resource for multiple target resources corresponding to the target network; wherein, the multiple target resources are the resources called by the target network to defend against network attacks;
[0027] The function establishment module is further configured to determine the target function based on the occupancy information of each target resource; wherein the target function is a convex function.
[0028] The optimization module is used to determine the target configuration information corresponding to each target resource based on the objective function and the constraints corresponding to each target resource.
[0029] In some alternative implementations, the plurality of target resources include bandwidth resources, computing resources, and memory resources.
[0030] In some optional implementations, if the target resource includes bandwidth resources, the function establishment module is used to determine the bandwidth resource occupancy information in the following ways:
[0031] Based on the bandwidth sensitivity of the target network, the traffic value of the network attack, and the maximum bandwidth of the target network, determine the bandwidth impact value; and based on the maximum bandwidth of the target network, the basic redundant bandwidth of the target network, and the configuration variables corresponding to the bandwidth resources, determine the bandwidth defense strength.
[0032] Based on the bandwidth impact value and the bandwidth defense strength, the bandwidth resource occupancy information is determined.
[0033] In some optional implementations, if the target resource includes computing resources, the function establishment module is used to determine the occupancy information of the computing resources in the following ways:
[0034] Based on the computational sensitivity of the target network, the resource request value of the network attack, and the maximum computational resources of the target network, the computational impact value is determined; and based on the maximum computational resources of the target network, the basic redundant computational resources of the target network, and the configuration variables corresponding to the computational resources, the computational defense strength is determined.
[0035] Based on the calculated impact value and the calculated defense strength, the occupancy information of the computing resources is determined.
[0036] In some optional implementations, if the target resource includes memory resources, the function creation module is used to determine the memory resource occupancy information in the following ways:
[0037] Based on the target network's memory sensitivity, memory correction factor, and the configuration variables corresponding to the memory resources, the memory resource occupancy information is determined.
[0038] In some optional implementations, the function creation module is specifically used for:
[0039] The objective function is determined by summing the occupancy information of each target resource and the adjustment factor.
[0040] In some alternative implementations, the optimization module is specifically used for:
[0041] The constraints are integrated into the objective function to construct the Lagrange function;
[0042] The target configuration information corresponding to the target resource is obtained by iterating over the Lagrange function.
[0043] Thirdly, embodiments of this application provide an electronic device, including at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor performs any of the network resource configuration methods described in the first aspect above.
[0044] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program executable by a processor, which, when run on the processor, causes the processor to perform any of the network resource configuration methods described in the first aspect above. Attached Figure Description
[0045] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0046] Figure 1 This is a schematic diagram of a DDoS attack provided in an embodiment of this application;
[0047] Figure 2 A flowchart illustrating the first network resource configuration method provided in this application embodiment;
[0048] Figure 3 A flowchart illustrating the second network resource configuration method provided in this application embodiment;
[0049] Figure 4 A flowchart illustrating the third network resource configuration method provided in this application embodiment;
[0050] Figure 5 This is a schematic diagram of the network resource configuration device provided in the embodiments of this application;
[0051] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0053] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.
[0054] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the term "connection" should be interpreted broadly. For example, it can refer to a direct connection, an indirect connection through an intermediate medium, or a connection within two devices. Those skilled in the art can understand the specific meaning of the above term in this application based on the specific circumstances.
[0055] The Internet of Things (IoT) is an extension and expansion of the internet, enabling interconnection and interoperability between people, machines, and things anytime, anywhere. Some IoT devices lack security measures in their design, making them vulnerable to being exposed to the network, controlled, and turned into botnets to launch cyberattacks.
[0056] DDoS attacks, exemplified by DDoS attacks, involve controlling a massive number of botnets to launch attacks against various targets across the network. A DDoS attack occurs when multiple attackers in different locations simultaneously target one or more targets, or when a single attacker controls multiple machines in different locations and uses them to attack the victim simultaneously. See also... Figure 1 As shown, an attacker controls multiple machines located in different locations to attack routers and autonomous systems (AS).
[0057] DDoS attacks are highly dangerous, and security measures against DDoS attacks are urgently needed.
[0058] In existing technologies, defense and control measures against DDoS attacks often focus on the sharing and blocking of blacklisted addresses.
[0059] However, the above methods do not provide information on how to configure resources when defending against attacks.
[0060] In view of this, embodiments of this application propose a network resource configuration method, apparatus, electronic device, and storage medium. The method includes: determining the occupancy information of each target resource for a plurality of target resources corresponding to a target network; wherein the plurality of target resources are resources invoked by the target network to defend against network attacks; determining a target function based on the occupancy information of each target resource; wherein the target function is a convex function; and determining target configuration information corresponding to each target resource based on the target function and the constraints corresponding to each target resource.
[0061] The above scheme sets multiple target resources (i.e., variable factors) that can be configured according to the resources required for network defense, thereby improving the targeting of resource allocation; based on these multiple variable factors, the occupancy information of each target resource is determined, and an objective function to be optimized is further established to determine the mapping relationship between the real physical world and the theoretical model, thereby improving the practical value of the scheme; the constraints corresponding to each target resource are determined according to the actual network situation, thereby further narrowing the optimization scope and improving the feasibility and optimization efficiency of the scheme; by solving and optimizing the objective function under constraints, the target configuration information (optimal resource combination) required to defend against attacks can be obtained when other factors are constant, thereby improving the efficiency and effectiveness of network defense.
[0062] The technical solution of this application and how it solves the above-mentioned technical problems will be described in detail below with reference to the accompanying drawings and specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0063] Figure 2 A flowchart illustrating the first network resource configuration method provided in this application embodiment is shown below. Figure 2 As shown, it includes the following steps:
[0064] Step S201: For multiple target resources corresponding to the target network, determine the occupancy information of each target resource.
[0065] The multiple target resources are resources invoked by the target network to defend against network attacks.
[0066] In practice, DDoS attacks typically consume network resources to achieve a denial-of-service effect. To ensure that the network or services maintain effective service performance after an attack and before effective mitigation and defense measures are implemented, resources need to be allocated to mitigate the network.
[0067] Based on this, this embodiment sets up multiple target resources (i.e. variable factors) that can be configured according to the resources required for network defense, thereby improving the targeting of resource configuration.
[0068] The resources required to be accessed in different networks may be the same or different, and this embodiment does not limit this.
[0069] In some alternative implementations, the multiple target resources that need to be invoked include bandwidth resources, computing resources, and memory resources.
[0070] DDoS attacks can be broadly categorized into two types: bandwidth exhaustion attacks and resource exhaustion attacks. Mitigating network performance by allocating bandwidth, computing, and storage resources can improve service performance.
[0071] Based on this, some embodiments may set three target resources: bandwidth resources, computing resources, and memory resources.
[0072] Step S202: Determine the objective function based on the occupancy information of each target resource.
[0073] The objective function is a convex function.
[0074] In implementation, after identifying the target resources, it is also necessary to establish a mapping relationship between the real physical scenario and the abstract mathematical model. To appropriately simplify the model, based on the attacker's consumption of different target resources, these occupancy information components are determined. Then, the occupancy information of each target resource is integrated to construct an objective function, which characterizes the occupancy of various resources in a network attack.
[0075] In this embodiment, an objective function is established based on convex optimization theory, attack characteristics are used to lock down variable factors, and then the optimal solution of the convex function is found under certain constraints.
[0076] Step S203: Based on the objective function and the constraints corresponding to each objective resource, determine the target configuration information corresponding to each objective resource.
[0077] In practice, resource scheduling in the network is subject to limitations, such as the amount of resources called upon not exceeding the maximum available capacity and not falling below the intensity of an attacker's attack. By constraining the target resources in the target model, the entire model becomes closer to real-world conditions, thus increasing the practical value of the optimized resource allocation scheme.
[0078] The constraints corresponding to the target resource mentioned above are the selectable range of configuration variables for the target resource, for example: V≤B≤B max -B0, where V is the network attack traffic value, and B is the configuration variable corresponding to the bandwidth resource. max R represents the maximum bandwidth of the target network, and B0 represents the basic redundancy bandwidth of the target network; R ≤ C ≤ C max -C0, R represents the resource value requested by the network attack, C max M represents the maximum computing resources of the target network, C0 represents the basic redundant computing resources of the target network, and C represents the configuration variable corresponding to the computing resources; M≤M max M is the configuration variable corresponding to the memory resource. max This represents the maximum memory resources available to the target network.
[0079] The above scheme sets multiple target resources (i.e., variable factors) that can be configured according to the resources required for network defense, thereby improving the targeting of resource allocation; based on these multiple variable factors, the occupancy information of each target resource is determined, and an objective function to be optimized is further established to determine the mapping relationship between the real physical world and the theoretical model, thereby improving the practical value of the scheme; the constraints corresponding to each target resource are determined according to the actual network situation, thereby further narrowing the optimization scope and improving the feasibility and optimization efficiency of the scheme; by solving and optimizing the objective function under constraints, the target configuration information (optimal resource combination) required to defend against attacks can be obtained when other factors are constant, thereby improving the efficiency and effectiveness of network defense.
[0080] As described above, in some optional implementations, the target resource includes bandwidth resources, and the occupancy information of the bandwidth resources can be determined in, but is not limited to, the following ways:
[0081] Based on the bandwidth sensitivity of the target network, the traffic value of the network attack, and the maximum bandwidth of the target network, determine the bandwidth impact value; and based on the maximum bandwidth of the target network, the basic redundant bandwidth of the target network, and the configuration variables corresponding to the bandwidth resources, determine the bandwidth defense strength.
[0082] Based on the bandwidth impact value and the bandwidth defense strength, the bandwidth resource occupancy information is determined.
[0083] In practice, regarding bandwidth usage, the impact of the attacker's attack on bandwidth (i.e., the attack intensity of the network attack) and the bandwidth defense strength that the network can provide will both affect the bandwidth resource usage. Based on this, this embodiment combines the bandwidth impact value and the bandwidth defense strength to obtain bandwidth resource usage information from both attack and defense perspectives.
[0084] The bandwidth impact value is determined based on the target network's bandwidth sensitivity, the network attack traffic value, and the target network's maximum bandwidth; the bandwidth defense strength is determined based on the target network's maximum bandwidth, the target network's basic redundant bandwidth, and the configuration variables corresponding to the bandwidth resources.
[0085] For example, bandwidth resource usage information Where α(V) is the bandwidth impact value, For bandwidth defense strength;
[0086] α0 represents bandwidth sensitivity, i.e., the degree to which the service performance in the target network is sensitive to the bandwidth factor; V represents the network attack traffic value, i.e., the size of the attack traffic launched by the attacker; B max The maximum bandwidth of the target network, i.e., the maximum bandwidth that the entire network can provide;
[0087] B0 represents the basic redundant bandwidth of the target network, which can be seen as a basic level of defense in terms of bandwidth; B represents the configuration variable corresponding to the bandwidth resources, which is the bandwidth resources that need to be calculated to ultimately be used for defense.
[0088] The above formula is only an example. In practice, the formula for bandwidth resource occupancy information can be adjusted according to different combinations of target resources, as long as the corresponding influencing factors are taken into account. For example, the bandwidth defense strength can not be in logarithmic form, and the bandwidth impact value can be calculated in other ways to integrate the target network's bandwidth sensitivity, network attack traffic value, and the target network's maximum bandwidth.
[0089] As described above, in some optional implementations, the target resource includes computing resources, and the occupancy information of the computing resources can be determined in, but is not limited to, the following ways:
[0090] Based on the computational sensitivity of the target network, the resource request value of the network attack, and the maximum computational resources of the target network, the computational impact value is determined; and based on the maximum computational resources of the target network, the basic redundant computational resources of the target network, and the configuration variables corresponding to the computational resources, the computational defense strength is determined.
[0091] Based on the calculated impact value and the calculated defense strength, the occupancy information of the computing resources is determined.
[0092] In practice, the impact of attacks launched by attackers on computing resources and the strength of computing defenses provided by the network will affect the usage of computing resources. Based on this, this embodiment comprehensively calculates the impact value and the strength of computing defenses to obtain computing resource usage information from both attack and defense perspectives.
[0093] The calculated impact value is determined based on the target network's computational sensitivity, the resource request value of the network attack, and the target network's maximum computational resources; the calculated defense strength is determined based on the target network's maximum computational resources, the target network's basic redundant computational resources, and the configuration variables corresponding to the computational resources.
[0094] For example, computing resource usage information Wherein, γ(R) is the calculated influence value. To calculate defense strength;
[0095] γ0 represents computational sensitivity, i.e., the degree to which service performance in the target network is sensitive to the factor of computing resources; R represents the resource value requested by the network attack, i.e., the size of the resource requested by the attacker's malicious attack; C max The maximum computational resources for the target network;
[0096] C0 represents the basic redundant computing resources of the target network; C represents the configuration variables corresponding to the computing resources, which are the computing resources that need to be calculated and ultimately invoked for defense.
[0097] The above formula is merely an illustrative example. In practice, the formula for the above computing resource occupancy information can be adjusted according to different target resource combinations, as long as the corresponding influencing factors are taken into account. This embodiment will not elaborate further on this.
[0098] As described above, in some optional implementations, the target resource includes memory resources, and the memory resource occupancy information can be determined in, but is not limited to, the following ways:
[0099] Based on the target network's memory sensitivity, memory correction factor, and the configuration variables corresponding to the memory resources, the memory resource occupancy information is determined.
[0100] In practice, as the amount of storage resources used increases, the mitigation effect on the impact of attacks decreases, meaning that the performance improvement brought about by increasing memory is limited.
[0101] Based on this, this embodiment directly determines the memory resource occupancy information based on the target network's memory sensitivity, memory correction factor, and configuration variables corresponding to the memory resources.
[0102] For example, the memory resource usage information E = δe -βMM Where δ represents the memory sensitivity of the target network, i.e., the degree to which the service performance in the network is sensitive to the factor of memory processing resources; β M β is a memory correction factor used to control the accuracy of the model in mitigating the effects of attacks as memory usage increases. Different networks have different β values. M They can be the same or different; M is the configuration variable corresponding to the memory resource, which is the memory resource that needs to be calculated to be called for defense.
[0103] The example above calculates memory usage using exponential methods, demonstrating the diminishing marginal utility effect—that is, the performance improvement from increasing memory is limited, which is more consistent with real-world network scenarios. The β value... M As a memory correction factor, it is used to control the accuracy of the model in mitigating the effects of attacks during memory increases.
[0104] The above formula is only an example. In practice, the formula for the memory resource occupancy information can be adjusted according to different target resource combinations, such as not using exponents, or directly multiplying several parameters.
[0105] Figure 3 A flowchart illustrating the second network resource configuration method provided in this application embodiment is shown below. Figure 3 As shown, it includes the following steps:
[0106] Step S301: For multiple target resources corresponding to the target network, determine the occupancy information of each target resource.
[0107] The specific implementation of step S301 can be found in other embodiments, and will not be repeated here.
[0108] Step S302: The sum of the occupancy information of each target resource and the adjustment factor is determined as the objective function.
[0109] During implementation, attackers will occupy and consume various target resources when launching attacks. Different occupation information represents the attacker's consumption of different target resources. The final resource allocation needs to take into account these occupation information. In addition, the sum of occupation information of all target resources may be negative or deviate from the actual operating effect.
[0110] Based on this, this embodiment determines the objective function as the sum of the occupancy information of each target resource and the adjustment factor.
[0111] Taking multiple target resources, including bandwidth resources, computing resources, and memory resources, as an example, the objective function... Where A represents bandwidth resource usage information, D represents computing resource usage information, and E represents memory resource usage information.
[0112] if Substituting into the above function, we get
[0113]
[0114] Where α(V) is the bandwidth impact value, and B is the configuration variable corresponding to the bandwidth resource. max B0 is the maximum bandwidth of the target network, B0 is the basic redundancy bandwidth of the target network, γ(R) is the calculated impact value, and C is the configuration variable corresponding to the computing resources. max C0 represents the maximum computing resources of the target network, C0 represents the basic redundant computing resources of the target network, M represents the configuration variable corresponding to the memory resources, and β represents the maximum computing resources of the target network. M K is the memory correction factor, and K is the adjustment factor.
[0115] Step S303: Based on the objective function and the constraints corresponding to each objective resource, determine the target configuration information corresponding to each objective resource.
[0116] The specific implementation of step S303 can be found in other embodiments, and will not be repeated here.
[0117] The above scheme determines the objective function by summing the occupancy information of each target resource and the adjustment factors, thereby comprehensively considering the attacker's consumption of different target resources and more closely reflecting the actual operating effect.
[0118] Figure 4 A flowchart illustrating the third network resource configuration method provided in this application embodiment is shown below. Figure 4 As shown, it includes the following steps:
[0119] Step S401: For multiple target resources corresponding to the target network, determine the occupancy information of each target resource.
[0120] Step S402: Determine the objective function based on the occupancy information of each target resource.
[0121] The specific implementation of steps S401 to S402 can be found in other embodiments, and will not be repeated here.
[0122] Step S403: Integrate the constraints into the objective function to construct the Lagrange function.
[0123] In practice, after determining the objective function and constraints, it is necessary to solve the objective function in order to obtain the final value of the configuration variable, which is the target configuration information.
[0124] In this embodiment, the dual ascent method is used to solve the model based on the characteristics of multiple configuration variables.
[0125] Step S404: Iterate the Lagrange function to obtain the target configuration information corresponding to the target resource.
[0126] In this embodiment, the Lagrange multiplier is first introduced to integrate the constraints into the objective function, thus constructing the Lagrange function. Then, the iterative update relationship of each Lagrange multiplier in the dual problem variables and the iterative relationship of the configuration variables of the objective resources are solved. After the iteration is completed, the configuration variables of each objective resource at this time are output, thus obtaining the optimal allocation scheme.
[0127] In practice, the iterative process can use a dynamic step size (such as the step size for predicting the optimization, a random step size, an asymptotic convergence step size, and an adaptive step size), or a fixed step size (such as 10). This embodiment does not specifically limit this.
[0128] In addition, the iteration termination condition can be set according to the actual application, such as setting the number of iterations to be greater than the preset number (e.g., 5000) and the difference between the feasible solution and the value of the dual function during the iteration process to be less than the deviation threshold (e.g., 0.1).
[0129] The following is a specific example illustrating this, where multiple target resources include bandwidth resources, computing resources, and memory resources:
[0130] Introducing the Lagrange multiplier λ B , λ C , λ M and μ B μ C By integrating the constraints into the objective function, the Lagrangian function L is constructed:
[0131] L(B,C,M,λ B ,λ C ,λ M ,μ B ,μ C)=F(B,C,M)+λ B (BB max +B0)+λ C (C-
[0132] C max +C0)+λ M (MM max )+μ B (VB)+μ C (RC);
[0133] Where F(B,C,M) is the objective function, B is the configuration variable corresponding to the bandwidth resource, and B0 is the configuration variable corresponding to the bandwidth resource. max B0 is the maximum bandwidth of the target network, C is the basic redundant bandwidth of the target network, and C is the configuration variable corresponding to the computing resources. max C0 represents the maximum computing resources of the target network, C0 represents the basic redundant computing resources of the target network, and M represents the configuration variable corresponding to the memory resources. max Maximum computing resources for the target network
[0134] The update algorithm for Lagrange multipliers is as follows:
[0135] That is: λ B [t+1]=[λ B [t]+t(BB max +B0)] +
[0136]
[0137] That is: λ C [t+1]=[λ C [t]+t(CC max +C0)] +
[0138]
[0139] That is: λ M [t+1]=[λ M [t]+t(MM max )] +
[0140]
[0141] That is: μ B [t+1]=[μ B [t]+t(VB)] +
[0142]
[0143] That is: μ C [t+1]=[μ C [t]+t(RC)] + ;
[0144] The algorithm for updating the configuration variables in the objective function is as follows:
[0145]
[0146] Where t is the step size and k is the number of iterations.
[0147] like Figure 5 As shown in the figure, this application embodiment provides a network resource configuration device 500, which includes:
[0148] The function establishment module 501 is used to determine the occupancy information of each target resource for multiple target resources corresponding to the target network; wherein, the multiple target resources are the resources called by the target network to defend against network attacks;
[0149] The function establishment module 501 is further configured to determine the target function based on the occupancy information of each target resource; wherein the target function is a convex function;
[0150] The optimization module 502 is used to determine the target configuration information corresponding to each target resource based on the objective function and the constraints corresponding to each target resource.
[0151] In some alternative implementations, the plurality of target resources include bandwidth resources, computing resources, and memory resources.
[0152] In some optional implementations, if the target resource includes bandwidth resources, then the function establishment module 501 is used to determine the occupancy information of the bandwidth resources in the following manner:
[0153] Based on the bandwidth sensitivity of the target network, the traffic value of the network attack, and the maximum bandwidth of the target network, determine the bandwidth impact value; and based on the maximum bandwidth of the target network, the basic redundant bandwidth of the target network, and the configuration variables corresponding to the bandwidth resources, determine the bandwidth defense strength.
[0154] Based on the bandwidth impact value and the bandwidth defense strength, the bandwidth resource occupancy information is determined.
[0155] In some optional implementations, if the target resource includes computing resources, the function establishment module 501 is used to determine the occupancy information of the computing resources in the following manner:
[0156] Based on the computational sensitivity of the target network, the resource request value of the network attack, and the maximum computational resources of the target network, the computational impact value is determined; and based on the maximum computational resources of the target network, the basic redundant computational resources of the target network, and the configuration variables corresponding to the computational resources, the computational defense strength is determined.
[0157] Based on the calculated impact value and the calculated defense strength, the occupancy information of the computing resources is determined.
[0158] In some optional implementations, if the target resource includes memory resources, the function establishment module 501 is used to determine the memory resource occupancy information in the following ways:
[0159] Based on the target network's memory sensitivity, memory correction factor, and the configuration variables corresponding to the memory resources, the memory resource occupancy information is determined.
[0160] In some optional implementations, the function creation module 501 is specifically used for:
[0161] The objective function is determined by summing the occupancy information of each target resource and the adjustment factor.
[0162] In some optional implementations, the optimization module 502 is specifically used for:
[0163] The constraints are integrated into the objective function to construct the Lagrange function;
[0164] The target configuration information corresponding to the target resource is obtained by iterating over the Lagrange function.
[0165] Since this device is the same as the device in the method of this application embodiment, and the principle of the device in solving the problem is similar to that of the method, the implementation of the device can be referred to the implementation of the method, and the repeated parts will not be described again.
[0166] Based on the same technical concept, this application also provides an electronic device 600, such as... Figure 6 As shown, it includes at least one processor 601 and a memory 602 connected to at least one processor. In this embodiment, the specific connection medium between the processor 601 and the memory 602 is not limited. Figure 6 Taking the connection between processor 601 and memory 602 via bus 603 as an example. The bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 6 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0167] The processor 601 is the control center of the electronic device, capable of connecting various parts of the device via various interfaces and lines. It performs data processing by running or executing instructions stored in the memory 602 and retrieving data stored in the memory 602. Optionally, the processor 601 may include one or more processing units. The processor 601 may integrate an application processor and a modem processor. The application processor primarily handles the operating system, user interface, and applications, while the modem processor primarily handles issuing instructions. It is understood that the modem processor may not be integrated into the processor 601. In some embodiments, the processor 601 and the memory 602 may be implemented on the same chip; in other embodiments, they may be implemented on separate chips.
[0168] Processor 601 can be a general-purpose processor, such as a CPU, digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the network resource configuration method can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.
[0169] Memory 602, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 602 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 602 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 602 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.
[0170] In this embodiment, the memory 602 stores a computer program, which, when executed by the processor 601, causes the processor 601 to perform the following:
[0171] For multiple target resources corresponding to the target network, determine the occupancy information of each target resource; wherein, the multiple target resources are the resources called upon by the target network to defend against network attacks;
[0172] Based on the occupancy information of each target resource, an objective function is determined; wherein, the objective function is a convex function.
[0173] Based on the objective function and the constraints corresponding to each objective resource, the target configuration information corresponding to each objective resource is determined.
[0174] In some alternative implementations, the plurality of target resources include bandwidth resources, computing resources, and memory resources.
[0175] In some optional implementations, if the target resource includes bandwidth resources, the bandwidth resource occupancy information is determined in the following manner:
[0176] Based on the bandwidth sensitivity of the target network, the traffic value of the network attack, and the maximum bandwidth of the target network, determine the bandwidth impact value; and based on the maximum bandwidth of the target network, the basic redundant bandwidth of the target network, and the configuration variables corresponding to the bandwidth resources, determine the bandwidth defense strength.
[0177] Based on the bandwidth impact value and the bandwidth defense strength, the bandwidth resource occupancy information is determined.
[0178] In some optional implementations, if the target resource includes computing resources, the occupancy information of the computing resources is determined in the following manner:
[0179] Based on the computational sensitivity of the target network, the resource request value of the network attack, and the maximum computational resources of the target network, the computational impact value is determined; and based on the maximum computational resources of the target network, the basic redundant computational resources of the target network, and the configuration variables corresponding to the computational resources, the computational defense strength is determined.
[0180] Based on the calculated impact value and the calculated defense strength, the occupancy information of the computing resources is determined.
[0181] In some optional implementations, if the target resource includes memory resources, the memory resource occupancy information is determined in the following way:
[0182] Based on the target network's memory sensitivity, memory correction factor, and the configuration variables corresponding to the memory resources, the memory resource occupancy information is determined.
[0183] In some alternative implementations, processor 601 specifically performs:
[0184] The objective function is determined by summing the occupancy information of each target resource and the adjustment factor.
[0185] In some alternative implementations, processor 601 specifically performs:
[0186] The constraints are integrated into the objective function to construct the Lagrange function;
[0187] The target configuration information corresponding to the target resource is obtained by iterating over the Lagrange function.
[0188] Since the electronic device is the same as the electronic device in the method of this application embodiment, and the principle of the electronic device in solving the problem is similar to that of the method, the implementation of the electronic device can refer to the implementation of the method, and the repeated parts will not be described again.
[0189] Based on the same technical concept, embodiments of this application also provide a computer-readable storage medium storing a computer program executable by a processor, which, when run on the processor, causes the processor to perform the steps of the above-described network resource configuration method.
[0190] In some alternative implementations, various aspects of the network resource configuration method provided in this application can also be implemented as a program product containing computer-executable instructions. When the program product is run on a computer device, the computer-executable instructions are used to cause the computer device to perform the steps of the network resource configuration method according to the various exemplary embodiments of this application described above.
[0191] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0192] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0193] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0194] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0195] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0196] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for configuring network resources, characterized in that, The method includes: For multiple target resources corresponding to the target network, determine the occupancy information of each target resource; wherein, the multiple target resources are the resources called upon by the target network to defend against network attacks; Based on the occupancy information of each target resource, an objective function is determined; wherein, the objective function is a convex function. Based on the objective function and the constraints corresponding to each objective resource, the target configuration information corresponding to each objective resource is determined. Based on the occupancy information of each target resource, the objective function is determined, including: The objective function is determined by summing the occupancy information of each target resource and the adjustment factor. If the target resource includes bandwidth resources, the bandwidth resource occupancy information is determined in the following way: Based on the bandwidth sensitivity of the target network, the traffic value of the network attack, and the maximum bandwidth of the target network, the bandwidth impact value is determined; and based on the maximum bandwidth of the target network, the basic redundant bandwidth of the target network, and the configuration variables corresponding to the bandwidth resources, the bandwidth defense strength is determined; wherein, the bandwidth sensitivity represents the degree to which the service performance in the target network is sensitive to bandwidth. Based on the bandwidth impact value and the bandwidth defense strength, the bandwidth resource occupancy information is determined.
2. The method as described in claim 1, characterized in that, The target resources include bandwidth resources, computing resources, and memory resources.
3. The method as described in claim 1, characterized in that, If the target resource includes computing resources, the occupancy information of the computing resources is determined in the following manner: Based on the computational sensitivity of the target network, the resource request value of the network attack, and the maximum computational resources of the target network, the computational impact value is determined; and based on the maximum computational resources of the target network, the basic redundant computational resources of the target network, and the configuration variables corresponding to the computational resources, the computational defense strength is determined; wherein, the computational sensitivity represents the degree to which the service performance in the target network is sensitive to computational resources; Based on the calculated impact value and the calculated defense strength, the occupancy information of the computing resources is determined.
4. The method as described in claim 1, characterized in that, If the target resource includes memory resources, the memory resource occupancy information is determined in the following way: Based on the target network's memory sensitivity, memory correction factor, and configuration variables corresponding to the memory resources, the memory resource occupancy information is determined; wherein, the memory sensitivity represents the degree to which the service performance in the target network is sensitive to memory processing resources; the memory correction factor is used to control the accuracy of the model in mitigating the impact of attacks during memory increases.
5. The method according to any one of claims 1 to 4, characterized in that, Based on the objective function and the constraints corresponding to each objective resource, the target configuration information corresponding to each objective resource is determined, including: The constraints are integrated into the objective function to construct the Lagrange function; The target configuration information corresponding to the target resource is obtained by iterating over the Lagrange function.
6. A network resource allocation device, characterized in that, The device includes: The function establishment module is used to determine the occupancy information of each target resource for multiple target resources corresponding to the target network; wherein, the multiple target resources are the resources called by the target network to defend against network attacks; The function establishment module is further configured to determine the target function based on the occupancy information of each target resource; wherein the target function is a convex function. The optimization module is used to determine the target configuration information corresponding to each target resource based on the objective function and the constraints corresponding to each target resource. Function creation module, specifically used for: The objective function is determined by summing the occupancy information of each target resource and the adjustment factor; wherein the adjustment factor is a preset value used to adjust the occupancy information. If the target resource includes bandwidth resources, the function establishment module is used to determine the bandwidth resource occupancy information in the following ways: Based on the bandwidth sensitivity of the target network, the traffic value of the network attack, and the maximum bandwidth of the target network, determine the bandwidth impact value; and based on the maximum bandwidth of the target network, the basic redundant bandwidth of the target network, and the configuration variables corresponding to the bandwidth resources, determine the bandwidth defense strength. Based on the bandwidth impact value and the bandwidth defense strength, the bandwidth resource occupancy information is determined.
7. An electronic device, characterized in that, It includes at least one processor and at least one memory, wherein the memory stores a computer program that, when executed by the processor, causes the processor to perform the method as described in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, It stores a computer program executable by a computer, which, when run on the computer, causes the computer to perform the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Network security active defense resource configuration method and system
CN113395274A
DoS attack defense method and device for distributed network and electronic equipment
CN118139056A