A mimic scheduling decision method, system, electronic device, medium and product

By semantic judgment and historical information comparison of the result messages of the isomer executors, the problem of excessive number of isomer executors in the mimic scheduling judgment is solved, and higher redundancy and security are achieved, hardware cost and complexity are reduced, and system flexibility and response speed are improved.

CN119051903BActive Publication Date: 2025-09-02PURPLE MOUNTAIN LAB +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411046576.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-31
Publication Date
2025-09-02
Estimated Expiration
2044-07-31

AI Technical Summary

Technical Problem

How to reduce the number of heterogeneous executors required for mimicking scheduling judgments and reduce the hardware cost and complexity of dynamic heterogeneous redundant architectures.

Method used

By semantic judgment on the result messages of the isomer executor, the number of result messages in each category is recorded using a counter, and the counter with the largest count value is set as an alternative counter. If there are multiple alternative counters, it is marked as a suspicious isomer executor, and historical information is obtained for comparison to judge their processing results in different cycles and reduce the number of isomer executors.

Benefits of technology

Without increasing hardware costs, higher redundancy and security are achieved, reducing the hardware complexity and number of execution bodies of mimicked scheduling judgments, and improving the flexibility and response speed of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119051903B_ABST
    Figure CN119051903B_ABST
Patent Text Reader

Abstract

The present application discloses a mimetic scheduling judgment method, system, electronic device, medium and product, and the technical field to which it belongs is mimetic security defense technology. The mimetic scheduling judgment method includes: sending the current original message to each heterogeneous executor respectively; receiving m current result messages returned by all heterogeneous executors and forming a judgment unit; determining the semantics of each current result message in the judgment unit and generating a corresponding counter, and setting the count value of the counter to the number of current result messages of the corresponding category; if there are at least two counters with the largest count values, the heterogeneous executor corresponding to the alternative counter is marked as a suspicious heterogeneous executor; sending the historical original message to the suspicious heterogeneous executor so that the suspicious heterogeneous executor processes the historical original message to obtain a second historical result message, so as to determine whether the suspicious heterogeneous executor has a security risk. The present application can reduce the number of heterogeneous executors required for mimetic scheduling judgment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of mimicry security defense technology, and in particular to a mimicry scheduling decision method, system, electronic device, medium and product. Background Art

[0002] Mimic Defense (MD) is an active defense behavior that can defend against threats such as unknown vulnerabilities, backdoors, or viruses and Trojans in the network based on Dynamic Heterogeneous Redundancy (DHR).

[0003] The core hardware of mimetic defense is a mimetic scheduler with a dynamic heterogeneous redundant architecture. A single mimetic scheduler connects to multiple heterogeneous executors. After distributing packets to each heterogeneous executor for parallel computation, the mimetic scheduler makes appropriate mimetic scheduling decisions, selecting the most semantically robust result as output, thereby achieving mimetic security with multi-mode heterogeneous redundancy. In a dynamic heterogeneous redundant architecture, the greater the number of heterogeneous executors connected to the mimetic scheduler, the higher the cost.

[0004] Therefore, how to reduce the number of heterogeneous executors required for mimic scheduling decisions is a technical problem that those skilled in the art currently need to solve. Summary of the Invention

[0005] The purpose of this application is to provide a mimetic scheduling decision method, system, electronic device, medium and product that can reduce the number of heterogeneous executors required for mimetic scheduling decision.

[0006] To solve the above technical problems, the present application provides a mimetic scheduling decision method, which is applied to a mimetic scheduler of a dynamic heterogeneous redundant architecture, wherein the dynamic heterogeneous redundant architecture further includes m heterogeneous executors. The mimetic scheduling decision method includes:

[0007] Sending the current original message to each of the heterogeneous execution bodies respectively, so that the heterogeneous execution body processes the current original message to obtain a current result message;

[0008] Receive m current result messages returned by all the heterogeneous execution bodies, and form a decision unit with the m current result messages;

[0009] Determining the semantics of each of the current result messages in the decision unit, and classifying all the current result messages with the same semantics into the same category of messages;

[0010] Generate a corresponding counter for each category of the current result message, and set the count value of the counter to the number of current result messages of the corresponding category;

[0011] Set the counter with the largest count value as the candidate counter;

[0012] If there are at least two candidate counters, the heterogeneous executor corresponding to the candidate counter is marked as a suspicious heterogeneous executor, and historical information is obtained; wherein the historical information includes a historical original message sent to the suspicious heterogeneous executor in the previous cycle, and a first historical result message obtained by the suspicious heterogeneous executor processing the historical original message in the previous cycle;

[0013] Sending the historical original message to the suspicious heterogeneous execution body so that the suspicious heterogeneous execution body processes the historical original message to obtain a second historical result message;

[0014] Determine whether the suspicious heterogeneous executable meets a first condition and a second condition; wherein the first condition is that the semantics of a first historical result message and a second historical result message generated by the suspicious heterogeneous executable are consistent, and the second condition is that the number of cleaning times of the suspicious heterogeneous executable is less than a preset number;

[0015] If so, it is determined that the suspicious heterogeneous executable does not pose a security risk;

[0016] If not, it is determined that the suspicious heterogeneous executable has a security risk.

[0017] Optionally, after setting the counter with the largest count value as the candidate counter, the method further includes:

[0018] If the count value of the candidate counter is m, it is determined that there is no security risk in all the heterogeneous executables;

[0019] The current result message is set as security data, and the security data is output.

[0020] Optionally, after setting the counter with the largest count value as the candidate counter, the method further includes:

[0021] If the count value of the candidate counter is less than m and there is only one candidate counter, all heterogeneous executables corresponding to the candidate counter are marked as trusted heterogeneous executables;

[0022] It is determined that other heterogeneous executives except the trusted heterogeneous executive have security risks.

[0023] Optionally, after setting the counter with the largest count value as the candidate counter, the method further includes:

[0024] It is determined that heterogeneous execution bodies corresponding to counters other than the candidate counter have security risks.

[0025] Optionally, also include:

[0026] Clean heterogeneous executors that pose security risks;

[0027] The current result message and the decision unit are cleared, and the process proceeds to the step of sending the current original message to each of the heterogeneous execution bodies.

[0028] Optionally, also include:

[0029] If the count value of the candidate counter is m, the historical information is deleted, and the current original message and the current result message are stored as new historical information.

[0030] Optionally, also include:

[0031] Counting the number of cleaning times of each heterogeneous executive body;

[0032] If the number of cleaning times is greater than a critical value, sending messages to all the heterogeneous execution bodies is stopped, and it is determined that the heterogeneous execution body whose number of cleaning times is greater than the critical value has a security risk.

[0033] The present application also provides a mimetic scheduling decision system, which is applied to a mimetic scheduler of a dynamic heterogeneous redundant architecture, wherein the dynamic heterogeneous redundant architecture further includes m heterogeneous executors. The mimetic scheduling decision system includes:

[0034] A message sending module, configured to send the current original message to each of the heterogeneous execution bodies respectively, so that the heterogeneous execution body processes the current original message to obtain a current result message;

[0035] A message receiving module, configured to receive m current result messages returned by all the heterogeneous execution bodies, and form a decision unit with the m current result messages;

[0036] a semantic decision module, configured to determine the semantics of each of the current result messages in the decision unit, and classify all the current result messages with the same semantics into the same category of messages;

[0037] a counting module, configured to generate a corresponding counter for each category of the current result message, and set the count value of the counter to the number of current result messages of the corresponding category;

[0038] A counter setting module, used for setting the counter with the largest count value as a candidate counter;

[0039] a marking module configured to mark the heterogeneous executor corresponding to the candidate counter as a suspicious heterogeneous executor if at least two candidate counters exist, and obtain historical information; wherein the historical information includes a historical original message sent to the suspicious heterogeneous executor in a previous cycle, and a first historical result message obtained by the suspicious heterogeneous executor processing the historical original message in the previous cycle;

[0040] a comparison module, configured to send the historical original message to the suspicious heterogeneous execution body so that the suspicious heterogeneous execution body processes the historical original message to obtain a second historical result message;

[0041] A judgment module is used to judge whether the suspicious heterogeneous executor meets the first condition and the second condition; wherein, the first condition is that the semantics of the first historical result message and the second historical result message generated by the suspicious heterogeneous executor are consistent, and the second condition is that the number of cleaning times of the suspicious heterogeneous executor is less than a preset number; if so, it is determined that the suspicious heterogeneous executor does not have a security risk; if not, it is determined that the suspicious heterogeneous executor has a security risk.

[0042] The present application also provides a storage medium on which a computer program is stored. When the computer program is executed, the steps of the above-mentioned mimetic scheduling decision method are implemented.

[0043] The present application also provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of executing the above-mentioned mimetic scheduling decision method are implemented.

[0044] The present application also provides a computer program product, including a computer program / instruction, which implements the steps of the above-mentioned mimetic scheduling decision method when executed by a processor.

[0045] The present application provides a method for mimetic scheduling judgment, which can receive m current result messages returned by the heterogeneous executors after sending the current original message to each of the heterogeneous executors respectively, and then form a judgment unit with the m current result messages. The present application performs semantic judgment on the judgment unit and uses a counter to record the number of result messages of each category, and sets the counter with the largest count value as an alternative counter. If there are multiple alternative counters, it means that it is impossible to determine which heterogeneous executor corresponding to the alternative counter has a security risk. The present application marks the heterogeneous executor corresponding to the alternative counter as a suspicious heterogeneous executor, and sends the historical original message sent in the previous cycle to the suspicious heterogeneous executor again, so as to compare the processing results of the suspicious heterogeneous executor on the same message in different cycles, thereby judging whether the suspicious heterogeneous executor has a security risk. When the present application cannot judge a semantically consistent message, the result messages of different cycles are used for semantic judgment, and there is no need to introduce other heterogeneous executors for mimetic scheduling judgment. Therefore, the present application can reduce the number of heterogeneous executors required for mimetic scheduling judgment. The present application also provides a mimetic scheduling decision system, a storage medium, an electronic device and a computer program product, which have the above-mentioned beneficial effects and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0047] Figure 1 A flowchart of a mimic scheduling decision method provided in an embodiment of the present application;

[0048] Figure 2 A flowchart of another mimic scheduling decision method provided in an embodiment of the present application;

[0049] Figure 3 A flowchart of a method for processing heterogeneous executables provided in an embodiment of the present application;

[0050] Figure 4 A schematic diagram of the first dynamic heterogeneous redundancy architecture provided in an embodiment of the present application;

[0051] Figure 5 A schematic diagram of a second dynamic heterogeneous redundancy architecture provided in an embodiment of the present application;

[0052] Figure 6 A schematic diagram of the structure of a mimic scheduling decision system provided in an embodiment of the present application;

[0053] Figure 7 A schematic diagram of the implementation principle of a computer program product provided in an embodiment of the present application. DETAILED DESCRIPTION

[0054] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0055] See below Figure 1 , Figure 1 This is a flowchart of a mimic scheduling decision method provided in an embodiment of the present application.

[0056] Specific steps may include:

[0057] S101: Sending the current original message to each of the heterogeneous execution bodies respectively, so that the heterogeneous execution body processes the current original message to obtain a current result message;

[0058] This embodiment can be applied to a mimetic scheduler in a dynamic heterogeneous redundant architecture. The dynamic heterogeneous redundant architecture also includes a switch and m heterogeneous executors, with m data channels existing between the mimetic scheduler and the switch. The mimetic scheduler includes a semantic cache, a scheduler, and a control module. The control module can control the scheduler and switch. The executor of this embodiment can be the control module of the mimetic scheduler.

[0059] The mimic scheduler receives the current original message through an external interface, copies the current original message into m copies, and sends each copy to the heterogeneous executor. After receiving the current original message, the heterogeneous executor can process the current original message to obtain the current result message and return the current result message to the mimic scheduler.

[0060] S102: Receive m current result messages returned by all the heterogeneous execution bodies, and form a decision unit with the m current result messages;

[0061] Each heterogeneous executor returns a corresponding current result message after receiving the current original message. Therefore, the mimic scheduler can determine the m current result messages returned by all the heterogeneous executors and group the m current result messages into a decision unit. The decision unit is a collection of m result messages.

[0062] In related art, a dynamic heterogeneous redundant architecture typically has s heterogeneous executors, where s > m. From these s heterogeneous executors, m are selected for mimetic scheduling decisions to achieve a redundancy of s. However, this embodiment sets a smaller number of m heterogeneous executors in the dynamic heterogeneous redundant architecture, selects m heterogeneous executors for mimetic scheduling decisions, and uses historical messages to perform semantic adjudication on suspicious heterogeneous executors to achieve a redundancy of s. For example, if the heterogeneous redundant architecture in this embodiment includes two heterogeneous executors, the redundancy is 3; if the heterogeneous redundant architecture includes three heterogeneous executors, the redundancy is 5.

[0063] S103: Determine the semantics of each current result message in the decision unit, and classify all current result messages with the same semantics into the same category of messages;

[0064] This step is based on the determination of the decision unit. At this point, semantic analysis can be performed on the m current result messages in the decision unit to obtain the semantics of each current result message. This embodiment can cluster all current result messages based on semantics, so that all current result messages with the same semantics are classified into the same category. Through the above operation, at least one category and the current result message corresponding to that category can be obtained.

[0065] S104: Generate a corresponding counter for each type of current result message, and set the count value of the counter to the number of current result messages of the corresponding type;

[0066] Among them, this step can generate a corresponding counter for each category of current result messages, that is, the number of counters is consistent with the number of categories. This step can also set the count value of the counter to the number of current result messages of the corresponding category.

[0067] S105: setting the counter with the largest count value as a candidate counter;

[0068] This step is based on the fact that corresponding counters have been generated for all categories of current result messages and the count values ​​of all counters have been set. At this time, the counter with the largest count value can be queried and set as the candidate counter. The counter with the largest count value is the counter corresponding to the category containing the largest number of current result messages.

[0069] If there is only one counter with the largest count value, it means that there is a unique alternative counter. The heterogeneous execution bodies corresponding to other counters can be cleaned and restored, and then the message distribution process can be performed again until m semantically consistent result messages are obtained.

[0070] If the count values ​​of multiple counters are equal and are all maximum values, the counters with the largest count values ​​may be set as candidate counters, that is, there are multiple candidate counters.

[0071] An example to illustrate the above process:

[0072] If m=3, the semantics of the current result message A is y1, the semantics of the current result message B is y1, and the semantics of the current result message C is y2; the current result message A and the current result message B are current result messages of the y1 category, and the current result message C is the current result message of the y2 category; at this time, two counters are generated, the first counter corresponds to the y1 category, and its count value is 2; the second counter corresponds to the y2 category, and its count value is 1; the first counter can be set as a backup counter.

[0073] If m=5, the semantics of the current result message A is y1, the semantics of the current result message B is y1, the semantics of the current result message C is y2, the semantics of the current result message C is y3, and the semantics of the current result message D is y3;

[0074] Current result message A and current result message B are current result messages of category y1, current result message C is the current result message of category y2, and current result message C and current result message D are current result messages of category y3. At this time, three counters are generated. The first counter corresponds to category y1, and its count value is 2; the second counter corresponds to category y2, and its count value is 1; the third counter corresponds to category y3, and its count value is 2. The first counter and the third counter can be set as alternative counters.

[0075] S106: If there are at least two candidate counters, mark the heterogeneous executable corresponding to the candidate counter as a suspicious heterogeneous executable, and obtain historical information;

[0076] Prior to this step, an operation may be performed to determine whether the number of candidate counters is greater than or equal to 2. If so, operations S106 to S110 are executed; if not, a candidate counter is obtained. Specifically, after setting the counter with the largest count value as the candidate counter, if the count value of the candidate counter is m, it is determined that there is no security risk for all heterogeneous execution bodies; the current result message is set as security data, and the security data is output. This security data can be used in subsequent calculations.

[0077] If there are at least two alternative counters, it means that the heterogeneous execution bodies corresponding to the alternative counters have returned different current result messages. At this time, the heterogeneous execution bodies corresponding to the alternative counters can be marked as suspicious heterogeneous execution bodies, and historical information can be obtained so as to use the historical information to determine whether there are security risks in the executable body.

[0078] The above historical information includes the historical original message sent to the suspicious heterogeneous executor in the previous cycle, and the first historical result message obtained by the suspicious heterogeneous executor in processing the historical original message in the previous cycle. In this embodiment, the semantics of the first historical result message obtained by all suspicious heterogeneous executors in processing the historical original message in the previous cycle are the same.

[0079] S107: Sending the historical original message to the suspicious heterogeneous execution body so that the suspicious heterogeneous execution body processes the historical original message to obtain a second historical result message;

[0080] In this embodiment, a historical original message can be determined from historical information and sent to the suspected heterogeneous executor. After receiving the historical original message, the suspected heterogeneous executor can process the historical original message to obtain a result message and return the result message to the mimetic scheduler. In this embodiment, the result message returned by the suspected heterogeneous executor is referred to as the second historical result message. In this embodiment, a semantic comparison can be performed between the first historical result message and the second historical result message.

[0081] S108: Determine whether the suspicious heterogeneous executable meets the first condition and the second condition; if so, determine that the suspicious heterogeneous executable does not have a security risk; if not, determine that the suspicious heterogeneous executable does have a security risk.

[0082] The first condition is that the semantics of the first and second historical result messages generated by the suspicious heterogeneous executable are consistent, and the second condition is that the suspicious heterogeneous executable has been cleaned less than a preset number of times (i.e., the suspicious heterogeneous executable has been cleaned less than a preset number of times). After determining that the suspicious heterogeneous executable presents a security risk, the suspicious heterogeneous executable presenting the security risk has been cleaned.

[0083] The mimetic scheduler assigns the current original message to a heterogeneous executor and receives the current result message output by the heterogeneous executor. When each executor operates normally, a consistent current result message is obtained. However, when an executor receives an attack and produces an abnormal output, the resulting current result message will not be consistent. There will be differences in the data semantics, indicating that one or more heterogeneous executors are abnormal and unable to operate normally and output a current result message consistent with other heterogeneous executors. The mimetic scheduler can determine and identify heterogeneous executors with abnormalities, posing a security risk. When a heterogeneous executor is attacked and produces an abnormal output, this embodiment performs a cleansing and recovery operation on the abnormal executor, resetting its attacked state to a normal state, thereby achieving the purpose of resisting the attack. Furthermore, to effectively defend against coordinated or common-mode attacks, the executor needs to have a certain degree of self-recovery capability, capable of self-recovery periodically or randomly according to system policies. This embodiment can adopt a timed cleaning strategy, that is, setting a timer. When a fixed time interval is reached, a heterogeneous executor is selected for cleaning based on the trust weight. After cleaning, the trust weight of the executor is restored to the preset value.

[0084] After the present embodiment sends the current original message to each of the heterogeneous executors respectively, it can receive m current result messages returned by the heterogeneous executors, and then form a judgment unit with the m current result messages. The present embodiment performs semantic judgment on the judgment unit and uses a counter to record the number of result messages of each category, and sets the counter with the largest count value as an alternative counter. If there is a unique alternative counter, the heterogeneous executors corresponding to the other counters are cleaned and restored, and then the message distribution process is performed again until m semantically consistent result messages are obtained. If there are multiple alternative counters, it means that it is impossible to determine which heterogeneous executor corresponding to the alternative counter has a security risk. The present embodiment marks the heterogeneous executor corresponding to the alternative counter as a suspicious heterogeneous executor, and sends the historical original message sent in the previous cycle to the suspicious heterogeneous executor again, so as to compare the processing results of the suspicious heterogeneous executor on the same message in different cycles, thereby determining whether the suspicious heterogeneous executor has a security risk. When a semantically consistent message cannot be determined in this embodiment, result messages of different cycles are used for semantic determination, without introducing other heterogeneous executors for mimetic scheduling determination. Therefore, this embodiment can reduce the number of heterogeneous executors required for mimetic scheduling determination and save hardware costs.

[0085] As for Figure 1Further introduction to the corresponding embodiment: after setting the counter with the largest count value as the alternative counter, if there is a unique alternative counter and the count value of the alternative counter is less than m, the heterogeneous executors corresponding to the other counters are cleaned and restored, and the message distribution process is performed again until m semantically consistent result messages are obtained. If the count value of the alternative counter is less than m and there is only one alternative counter, it means that some heterogeneous executors have security risks. Specifically, the following operations can be performed: mark all heterogeneous executors corresponding to the alternative counters as trusted heterogeneous executors; determine that other heterogeneous executors other than the trusted heterogeneous executors have security risks; clean the heterogeneous executors with security risks; clear the current result message and the judgment unit, and enter the step of sending the current original message to each of the heterogeneous executors.

[0086] As for Figure 1 As a further introduction to the corresponding embodiment, after setting the counter with the largest count value as the candidate counter, it can also be determined that the heterogeneous executables corresponding to other counters except the candidate counter have security risks.

[0087] This embodiment can also clean heterogeneous executors that pose security risks. The current result message and the decision unit are cleared, and the current original message is sent to each heterogeneous executor to re-perform mimetic scheduling decisions on the heterogeneous executors until the candidate counter reaches m. If the candidate counter reaches m, the historical information is deleted, and the current original message and the current result message are stored as new historical information.

[0088] As for Figure 1 Further describing the corresponding embodiment, the mimetic scheduler can count the total number of purges for all heterogeneous executors; count the number of purges for each heterogeneous executor; and if the purge count exceeds a critical value, stop sending messages to all heterogeneous executors and determine that the heterogeneous executor with a purge count exceeding the critical value presents a security risk. In the above process, if the purge count for any heterogeneous executor exceeds the critical value, the dynamic heterogeneous redundancy architecture is under severe attack and cannot function. The scheduler can stop sending messages (including current and historical original messages) and determine that the heterogeneous executor with a purge count exceeding the critical value presents a security risk.

[0089] The process described in the above embodiment is explained below through an embodiment in actual application.

[0090] The intrinsic security architecture is based on the intrinsic security system of dynamic heterogeneous redundant routing and switching equipment. It introduces input agents for message distribution and policy decisions to achieve error correction output. The policy decision results are fed to the dynamic scheduling module through the feedback controller to achieve dynamic reconstruction, scheduling cleaning, and functional recovery of each executor.

[0091] Existing heterogeneous redundant mimetic scheduling algorithms require a large number of heterogeneous executors, with at least three heterogeneous executors scheduled each time, requiring at least three high-speed signal transmission channels. This scheduling decision scheme can reduce the number of heterogeneous executors scheduled in parallel, significantly reducing the complexity of the mimetic scheduling system. It can also achieve redundancy greater than the number of heterogeneous executors by running fewer heterogeneous executors, reducing the number of semantic decisions and the number of heterogeneous executors running, saving system operating resources. This embodiment uses the messages of the previous cycle and the messages of the current cycle to form a decision unit, and performs security assessments by comparing their semantic consistency. Even if there are only two heterogeneous executors, the security and reliability of the system can be enhanced through temporal redundancy (i.e., cross-cycle comparison). Specifically, if this embodiment runs two heterogeneous executors, the redundancy is 3.

[0092] The heterogeneous redundant mimetic scheduling method provided in this embodiment uses result messages from different cycles to form a decision unit for semantic decision when it is unable to determine a message with consistent data content. A special decision unit is formed for heterogeneous executors suspected of presenting security risks, and semantic decision is then determined to determine whether the heterogeneous executor is trustworthy. The original messages in each cycle are sent by the mimetic scheduler and updated in real time. The decision unit is continuously composed of result messages from the previous cycle and the current cycle for semantic decision. This not only makes the defense system more flexible and changeable, making it difficult to detect the content of the decision unit, but also significantly saves system hardware and operating costs. Compared with related technologies, this embodiment can reduce the number of heterogeneous executors, for example, to two, significantly saving various system equipment costs while implementing an intrinsically secure DHR architecture. It enriches the scheduling methods for heterogeneous executors, reduces decision time, improves the response speed of scheduling signals, and reduces the hardware implementation complexity of the heterogeneous executor mimetic scheduling decision scheme.

[0093] See Figure 2 , Figure 2 A flowchart of another mimic scheduling decision method provided in an embodiment of the present application includes the following operations:

[0094] Obtain the current result message returned by the heterogeneous executor; perform semantic judgment to determine whether the current result message is completely consistent; if completely consistent, output the winning current result message; if not completely consistent, traverse the counters to determine whether the maximum value number is unique; if the maximum value number is unique, clean up other heterogeneous executors, and control all heterogeneous executors to recalculate and execute; if the maximum value number is not unique, traverse all counters for processing. Specifically, the process of traversing all counters for processing is: set the counter with the largest count value as an alternative counter; mark the heterogeneous executor corresponding to the alternative counter as a suspicious heterogeneous executor, and obtain historical information; send the historical original message to the suspicious heterogeneous executor, so that the suspicious heterogeneous executor processes the historical original message to obtain a second historical result message; determine whether the suspicious heterogeneous executor meets the first condition and the second condition; if so, determine that the suspicious heterogeneous executor does not have a security risk; if not, determine that the suspicious heterogeneous executor has a security risk. The first condition is that the semantics of the first and second historical result messages generated by the suspicious heterogeneous execution body are consistent, and the second condition is that the number of cleanings of the suspicious heterogeneous execution body is less than a preset number. After determining that the suspicious heterogeneous execution body does not pose a security risk, it is necessary to control the heterogeneous execution body that does not pose a security risk to re-calculate and execute in order to re-determine the consistency.

[0095] At the beginning of this cycle, all heterogeneous executors are selected. The mimetic scheduler transmits the received original message to all heterogeneous executors. The heterogeneous executors perform operations on the original message and then transmit it to the mimetic scheduler. The current result message after the operation is obtained. All current result messages form a decision unit, and semantic judgment is performed on the decision unit. The current result message after judgment is stored in the semantic buffer within the scheduler. Each buffer stores messages with consistent semantic data content, and a counter records the number of stored messages.

[0096] After the adjudication is completed, the counters of the semantic memory are sorted. If the maximum value is equal to the total number of heterogeneous executors, it means that the semantic data content of the current result messages obtained by all heterogeneous executors is consistent. The corresponding current result message wins the adjudication, and the system outputs the corresponding message data.

[0097] If all current result messages are not completely consistent, it indicates that the computation results of some heterogeneous executors are different, which may pose a security risk. The mimic scheduler distributes historical information to heterogeneous executors and then receives their output to determine the correct result message (also known as data response).

[0098] When each heterogeneous executor works normally, a consistent result message will be obtained. When a certain heterogeneous executor is attacked and produces abnormal output, the result message obtained will be different, which means that one or several heterogeneous executors have an abnormality and cannot work normally to output a result message consistent with other executors. The scheduling system can determine and identify the executor abnormality and there is a security risk. This embodiment can traverse the counters of all semantic buffers, sort the values, and determine whether the maximum value is unique. If there is only one maximum value, it indicates that there are semantically consistent result messages, and the heterogeneous executors corresponding to these semantically consistent result messages are trustworthy, and the remaining heterogeneous executors have security vulnerabilities or risks. This embodiment can clean and restore the heterogeneous executors corresponding to the messages stored in the semantic buffer where the counters smaller than the maximum value are located.

[0099] See Figure 3 , Figure 3 This is a flowchart of a method for processing heterogeneous executors provided in an embodiment of the present application, comprising the following steps: determining whether multiple counter values ​​are at their maximum value; if so, reading the result message from the previous cycle and setting a suspicious flag, sending the historical original message to the suspicious heterogeneous executor, and determining whether the historical result messages returned from the previous and next cycles are consistent; if they are consistent, removing the suspicious flag from the suspicious heterogeneous executor; if they are inconsistent, purging the corresponding suspicious heterogeneous executor. If the counter value is not at its maximum value, purging the corresponding heterogeneous executor.

[0100] If there are multiple maximum values, that is, the maximum value is not unique, this embodiment can traverse the counters of all semantic buffers and identify the heterogeneous executables corresponding to the result messages stored in the semantic buffers with the maximum values ​​as suspicious heterogeneous executables. These heterogeneous executables need to be screened to determine whether they pose a security risk. Before confirming their credibility, all heterogeneous executables are marked as suspicious heterogeneous executables.

[0101] If the counter value is equal to the maximum value and the maximum value is 1, it indicates that the semantics of the multiple result messages stored in this semantic buffer are inconsistent.

[0102] If the counter value is less than the maximum value, it means that the message semantics stored in the semantic cache is inconsistent with the maximum semantic content. Even if multiple result messages are stored in the semantic cache, the heterogeneous execution bodies corresponding to these result messages also have security risks. Such heterogeneous execution bodies are cleaned and restored to a trustworthy state.

[0103] Because the system is redundant, when one or more heterogeneous executors are in a suspicious state, they can remain in this state without undergoing cleanup and recovery. This embodiment isolates heterogeneous executors that remain in a suspicious state, preventing them from participating in the next cycle. Therefore, for heterogeneous executors marked as suspicious in this cycle, although the result message of the suspicious heterogeneous executor's calculation in this cycle is suspicious, its message processing in the previous cycle is consistent and trustworthy. After the state of the suspicious heterogeneous executor is restored, the suspicious label can be removed. The mimetic scheduler stores the original message from the previous cycle and the result message processed by each heterogeneous executor for easy use in the next cycle. When a suspicious heterogeneous executor appears, the scheduler schedules and distributes the original message from the previous cycle to the suspicious heterogeneous executor. The original message from the previous cycle obtains a calculation result in the suspicious heterogeneous executor and returns it to the scheduler. Together with the calculation result of the same original message from the same heterogeneous executor in the previous cycle, it forms a decision unit. The scheduler performs semantic judgment on the judgment unit. If the semantics are consistent, that is, the suspicious heterogeneous executor obtains consistent data content by calculating the same result message in the two cycles before and after, the cleaning record of the heterogeneous executor is analyzed. Based on the previous cleaning and recovery situation and the result of this semantic judgment, it is comprehensively judged that the heterogeneous executor is trustworthy and the suspicious label of the heterogeneous executor is removed. If the semantics are inconsistent, that is, the suspicious heterogeneous executor obtains different data content by calculating the same result message in the two cycles before and after, it means that the suspicious heterogeneous executor at this time has a security risk or has been attacked. The cleaning and recovery operation is performed to initialize the heterogeneous executor to a trusted state. This embodiment can traverse the counters of all semantic buffers that store messages, repeat the above process for the suspicious heterogeneous executors corresponding to the result messages in the semantic buffers where all counters have the maximum value, and perform screening and confirmation until all suspicious heterogeneous executors are cleaned or the suspicious labels are removed. The relevant information of the heterogeneous executor cleaning operation is recorded for use in the next cycle analysis, and the current cycle operation ends.

[0104] The following uses the first dynamic heterogeneous redundant architecture as an example to illustrate the above-mentioned mimetic scheduling decision scheme.

[0105] See Figure 4 , Figure 4 This is a schematic diagram of the first dynamic heterogeneous redundant architecture provided in an embodiment of the present application. The dynamic heterogeneous redundant architecture includes an external interface, a mimetic scheduler, a switch, a PowerPC architecture computing module, and an ARM architecture computing module. The PowerPC architecture computing module and the ARM architecture computing module are heterogeneous executors. The mimetic scheduler includes a scheduler, a semantic cache, and a control switch.

[0106] The mimetic scheduler and heterogeneous executors are connected via a switch, with the data channel using the PCIe protocol. Within a single cycle, the mimetic scheduler transmits external messages uplink and receives messages downlink. It then stores the resulting messages processed by the downlink heterogeneous executors in a buffer, awaiting a decision from the decision module.

[0107] The computing modules of different system architectures serve as heterogeneous executors. The entire mimetic redundant system has a degree of redundancy of 3 and includes two heterogeneous executors, namely the PowerPC architecture computing module and the ARM architecture computing module. The two computing modules meet the heterogeneous conditions. The mimetic scheduler includes a scheduler, a cache, and a control module. The cache can also be an external storage unit, such as flash or DDR. The control module pre-sets the order of message sending and receiving, and transmits control commands to the switch and scheduler. The cache is used to store the result messages received from the external interface, as well as the messages after processing by the downstream heterogeneous executor, namely the virtual machine.

[0108] Within a cycle T, both heterogeneous executors are selected. The mimic scheduler copies two copies of the original message X (i.e., the current original message) and sends them. After receiving the original message, the heterogeneous executors process it and return the processed result messages to the scheduler, which are respectively named result messages A1 and A2 (i.e., the current result message). The scheduler then performs a semantic judgment on the result messages. If the two result messages are semantically identical, result messages A1 and A2 are stored in the semantic buffer, and the counter value is recorded as 2. If the semantic judgments for messages A2 and A1 are different, result message A1 is stored in a different semantic buffer B1, the counter is incremented by 1, and result message A2 is stored in the semantic buffer B2, and the counter is incremented by 1.

[0109] If the result message semantics after the two operations are consistent, the counters in the semantic cache are traversed and retrieved, and the counter value is equal to 2, the corresponding message content is output, and the mimetic scheduling decision process is completed.

[0110] If the semantics of the result messages after the two operations are inconsistent, the counters in the semantic cache are searched and two caches are found, each with a counter value of 1. In this case, the maximum value of the counter is 1, and the maximum value is not unique. The result messages stored in the caches with the two maximum values ​​correspond to the two heterogeneous executables, which are suspicious heterogeneous executables and need to be screened and confirmed.

[0111] The scheduler reads the buffer storing the original message from the previous cycle, copies original message Y (i.e., the historical original message), and transmits it simultaneously to the two suspicious heterogeneous executors. This results in the computation results of the suspicious heterogeneous executors, meaning the scheduler receives two processed result messages. These two result messages are combined with the result message from the same heterogeneous executor from the previous cycle to form a decision unit. Specifically, the two result messages generated by the PowerPC architecture computing module computing the same original message from the previous cycle and the current cycle form a decision unit, while the two result messages generated by the ARM architecture computing module computing the same result message from the previous cycle and the current cycle form a decision unit. The mimic scheduler performs semantic decisions on each of the two decision units. If the decision unit's decision indicates semantic consistency and the heterogeneous executor has been cleaned a small number of times in the previous cycle, the heterogeneous executor is marked as trusted. If the decision unit's decision indicates semantic inconsistency, the heterogeneous executor is cleaned and restored, and a record is kept for feedback.

[0112] After traversing the semantic cache counters for the current cycle's result messages, the two heterogeneous executors reach a trusted state through the above process. Similar to the initial moment of the current cycle, the original message X of the current cycle is replicated and distributed to the two heterogeneous executors. The corresponding computation results are then obtained for a new round of semantic adjudication. The above process repeats until a semantically consistent adjudication result is obtained and output. The original message X of the current cycle and the computation results of the two heterogeneous executors are simultaneously stored for use in subsequent cycles. The original message and computation results of the previous cycle are deleted to conserve storage space. During the cleaning and semantic adjudication process, if the number of cleanings of the two heterogeneous executors reaches a certain limit, the heterogeneous executors are judged to be under virus attack and unable to operate, and the heterogeneous executors are cleaned.

[0113] The following uses the first dynamic heterogeneous redundant architecture as an example to illustrate the above-mentioned mimetic scheduling decision scheme.

[0114] See Figure 5 , Figure 5 This is a schematic diagram of the second dynamic heterogeneous redundant architecture provided by an embodiment of the present application. The dynamic heterogeneous redundant architecture includes an external interface, a mimetic scheduler, a switch, and heterogeneous executors E1, E2, and E3. The mimetic scheduler includes a scheduler, a semantic cache, and a control switch.

[0115] The mimetic scheduler and heterogeneous executors are connected via a switch, with the data channel using the PCIe protocol. Within a single cycle, the mimetic scheduler transmits external messages uplink and receives messages downlink. It then stores the resulting messages processed by the downlink heterogeneous executors in a buffer, awaiting a decision from the decision module.

[0116] This embodiment can use computing modules with different system architectures as heterogeneous executors. The entire mimetic redundant system has a redundancy of 5 and includes three heterogeneous executors. The mimetic scheduler includes a scheduler, a cache, and a control module. The cache can also be an external storage unit, such as flash or DDR. The control module pre-sets the order of message sending and receiving and transmits control commands to the switch and scheduler. The cache is used to store the result messages received from the external interface and the messages after processing by the downstream heterogeneous executor, namely the virtual machine.

[0117] Within a cycle T, all heterogeneous executors are selected. The mimetic scheduler copies the original message X (i.e., the current original message) three times and sends them. After receiving the original message, the heterogeneous executors process it and return the processed current result message to the mimetic scheduler. The above current result messages are A1, A2, and A3 respectively. Then, semantic judgment is performed on the three current result messages and the judged result messages are stored in the corresponding semantic buffers. At the same time, the counter is operated and the counter value is set according to the number of current result messages of the same type.

[0118] Traverse the counters in the search semantic cache. If the counter value is equal to 3, it means that the semantics of the three current result messages are consistent. Output the corresponding data content and complete the mimetic scheduling decision process.

[0119] If the maximum value of the counter is 2, it means that the two current result messages stored in this semantic buffer are semantically consistent, and there will be another semantic buffer with a counter value of 1. The maximum value is unique, and the heterogeneous executors corresponding to the messages stored in the semantic buffers where the counters other than the maximum value are located are cleaned and restored. That is, the semantic buffer with a counter value of 1 stores a result message. This result message comes from the calculation result of a heterogeneous executor. The calculation result of this heterogeneous executor is different from that of the other two heterogeneous executors, posing a security risk. This heterogeneous executor is cleaned and restored to its initial trusted state. After cleaning the heterogeneous executors, the original message is sent to all heterogeneous executors again for cyclic judgment until all heterogeneous executors output the same result message.

[0120] If the maximum value of the counter is 1, it indicates that three semantic buffers each store one current result message, and these three current result messages are semantically inconsistent. The maximum value of the counter is not unique; there are three maximum values, corresponding to three heterogeneous executors, all of which are suspicious. The historical original message stored in the previous cycle is retrieved, copied, and sent to the three heterogeneous executors to obtain three historical result messages for the current cycle's calculation results. The historical result messages of the three heterogeneous executors stored in the previous cycle are retrieved and combined with the historical result messages of the current cycle's calculations to form a decision unit. There are three decision units, each containing two result messages: the historical result message of the previous cycle's calculations for the same heterogeneous executor and the historical result message of the current cycle's calculations. The mimic scheduler decision system performs semantic decisions on the three decision units. If the decision unit's decision is semantically consistent and the computation module has been cleaned a small number of times in previous cycles, the computation module is marked as trusted. If the decision result is semantically inconsistent, the computation module is cleaned and restored, and a record is fed back to the system.

[0121] After traversing the semantic cache counters for stored messages in this cycle, the three heterogeneous executors reach a trusted state through the above process. Similar to the initial moment of this cycle, the original message X of this cycle is replicated and distributed to the three heterogeneous executors. The corresponding computation results are then used for a new round of semantic adjudication. The above process repeats until a semantically consistent adjudication result is obtained and output. The original message X of this cycle and the result messages obtained by the computations of the three heterogeneous executors are simultaneously stored for use in subsequent cycles. The original message and result messages from the previous cycle are deleted to conserve storage space. During the cleaning and semantic adjudication process, if the number of cleanings for the three heterogeneous executors reaches a certain limit, the heterogeneous executors are judged to be under a virus attack and unable to operate. Further cleaning or other system recovery measures can be performed, or other diagnostics can be used to restore the heterogeneous executors to normal operation.

[0122] See Figure 6 , Figure 6 This is a schematic diagram of the structure of a mimetic scheduling decision system provided in an embodiment of the present application. The system can be applied to a mimetic scheduler of a dynamic heterogeneous redundant architecture. The dynamic heterogeneous redundant architecture also includes m heterogeneous executors. The mimetic scheduling decision system includes:

[0123] The message sending module 601 is used to send the current original message to each of the heterogeneous execution bodies respectively, so that the heterogeneous execution body processes the current original message to obtain the current result message;

[0124] The message receiving module 602 is configured to receive m current result messages returned by all the heterogeneous execution bodies and form a decision unit with the m current result messages;

[0125] A semantic decision module 603 is configured to determine the semantics of each current result message in the decision unit and classify all current result messages with the same semantics into the same category of messages;

[0126] a counting module 604, configured to generate a corresponding counter for each category of the current result message, and set the count value of the counter to the number of the current result messages of the corresponding category;

[0127] The counter setting module 605 is used to set the counter with the largest count value as a candidate counter;

[0128] a marking module 606 configured to mark the heterogeneous executor corresponding to the candidate counter as a suspicious heterogeneous executor if at least two candidate counters exist, and obtain historical information; wherein the historical information includes a historical original message sent to the suspicious heterogeneous executor in a previous cycle, and a first historical result message obtained by the suspicious heterogeneous executor processing the historical original message in the previous cycle;

[0129] The comparison module 607 is configured to send the historical original message to the suspicious heterogeneous execution body so that the suspicious heterogeneous execution body processes the historical original message to obtain a second historical result message;

[0130] The judgment module 608 is used to judge whether the suspicious heterogeneous executor meets the first condition and the second condition; wherein, the first condition is that the semantics of the first historical result message and the second historical result message generated by the suspicious heterogeneous executor are consistent, and the second condition is that the number of cleaning times of the suspicious heterogeneous executor is less than a preset number; if so, it is determined that the suspicious heterogeneous executor does not have a security risk; if not, it is determined that the suspicious heterogeneous executor has a security risk.

[0131] After the present embodiment sends the current original message to each of the heterogeneous executors respectively, it can receive m current result messages returned by the heterogeneous executors, and then form a judgment unit with the m current result messages. The present embodiment performs semantic judgment on the judgment unit and uses a counter to record the number of result messages of each category, and sets the counter with the largest count value as an alternative counter. If there is a unique alternative counter, the heterogeneous executors corresponding to the other counters are cleaned and restored, and then the message distribution process is performed again until m semantically consistent result messages are obtained. If there are multiple alternative counters, it means that it is impossible to determine which heterogeneous executor corresponding to the alternative counter has a security risk. The present embodiment marks the heterogeneous executor corresponding to the alternative counter as a suspicious heterogeneous executor, and sends the historical original message sent in the previous cycle to the suspicious heterogeneous executor again, so as to compare the processing results of the suspicious heterogeneous executor on the same message in different cycles, thereby determining whether the suspicious heterogeneous executor has a security risk. When a semantically consistent message cannot be determined in this embodiment, result messages of different cycles are used for semantic determination, without introducing other heterogeneous executors for mimetic scheduling determination. Therefore, this embodiment can reduce the number of heterogeneous executors required for mimetic scheduling determination.

[0132] Furthermore, it also includes:

[0133] The output module is used to determine that there is no security risk in all the heterogeneous execution bodies if the count value of the candidate counter is m; and is also used to set the current result message as security data and output the security data.

[0134] Furthermore, it also includes:

[0135] A processing module is used to mark all heterogeneous executables corresponding to the candidate counter as trusted heterogeneous executables if the count value of the candidate counter is less than m and there is only one candidate counter; and is also used to determine whether other heterogeneous executables other than the trusted heterogeneous executable have security risks.

[0136] Furthermore, it also includes:

[0137] The determination module 608 is further configured to, after setting the counter with the largest count value as the candidate counter, determine whether the heterogeneous executables corresponding to the other counters except the candidate counter have security risks.

[0138] Furthermore, it also includes:

[0139] The cleaning module is used to clean heterogeneous execution bodies that have security risks; it is also used to clear the current result message and the judgment unit, and start the work flow of the message sending module 601.

[0140] Furthermore, it also includes:

[0141] The historical information updating module is configured to delete the historical information if the count value of the candidate counter is m, and store the current original message and the current result message as new historical information.

[0142] Furthermore, it also includes:

[0143] The statistical module is used to count the number of cleaning times of each heterogeneous execution body; and is also used to stop sending messages to all the heterogeneous execution bodies if the number of cleaning times is greater than a critical value, and determine that the heterogeneous execution body with the number of cleaning times greater than the critical value has a security risk.

[0144] Since the embodiments of the system part correspond to the embodiments of the method part, please refer to the description of the embodiments of the method part for the embodiments of the system part, and will not be repeated here.

[0145] This application also provides a storage medium having a computer program stored thereon. When executed, the computer program can implement the steps provided in the above embodiments. The storage medium may include: a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, or other medium capable of storing program code.

[0146] The present application also provides an electronic device that may include a memory and a processor, wherein the memory stores a computer program, and when the processor calls the computer program in the memory, the steps provided in the above embodiment can be implemented. Of course, the electronic device may also include various network interfaces, a power supply, and other components.

[0147] The present application also provides a computer program product, including a computer program and / or computer instructions, which, when executed by a processor, implements the steps of the above-mentioned method for detecting heterogeneity of a dynamic heterogeneous redundant architecture. Figure 7 , Figure 7 This is a schematic diagram illustrating the implementation principles of a computer program product provided in an embodiment of the present application. The computer program product includes a message transceiver program, a counter comparison program, and a risk detection program. This computer program product is applied to a mimetic scheduler in a dynamic heterogeneous redundant architecture, which also includes m heterogeneous executors.

[0148] When the message receiving and sending program is executed by the processor, the operations implemented are: sending the current original message to each of the heterogeneous execution bodies respectively, so that the heterogeneous execution body processes the current original message to obtain a current result message; receiving m current result messages returned by all the heterogeneous execution bodies, and forming the m current result messages into a decision unit;

[0149] When the counter comparison program is executed by the processor, the operations implemented are: determining the semantics of each current result message in the decision unit, and classifying all the current result messages with the same semantics into the same category of messages; generating a corresponding counter for each category of the current result messages, and setting the count value of the counter to the number of current result messages of the corresponding category; setting the counter with the largest count value as a candidate counter;

[0150] The operations implemented when the risk detection program is executed by the processor are as follows: if there are at least two alternative counters, the heterogeneous executor corresponding to the alternative counter is marked as a suspicious heterogeneous executor, and historical information is obtained; wherein, the historical information includes the historical original message sent to the suspicious heterogeneous executor in the previous cycle, and the first historical result message obtained by the suspicious heterogeneous executor processing the historical original message in the previous cycle; the historical original message is sent to the suspicious heterogeneous executor so that the suspicious heterogeneous executor processes the historical original message to obtain a second historical result message; it is determined whether the suspicious heterogeneous executor meets the first condition and the second condition; wherein, the first condition is that the semantics of the first historical result message and the second historical result message generated by the suspicious heterogeneous executor are consistent, and the second condition is that the number of cleaning times of the suspicious heterogeneous executor is less than a preset number; if so, it is determined that the suspicious heterogeneous executor does not have a security risk; if not, it is determined that the suspicious heterogeneous executor has a security risk.

[0151] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the various embodiments can be referred to each other. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the scope of protection of this application.

[0152] It should also be noted that, in this specification, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.

Claims

1. A mimic scheduling decision method, characterized in that: A mimetic scheduler applied to a dynamic heterogeneous redundant architecture, wherein the dynamic heterogeneous redundant architecture further includes m heterogeneous executors, and the mimetic scheduling decision method includes: Sending the current original message to each of the heterogeneous execution bodies respectively, so that the heterogeneous execution body processes the current original message to obtain a current result message; Receive m current result messages returned by all the heterogeneous execution bodies, and form a decision unit with the m current result messages; Determining the semantics of each of the current result messages in the decision unit, and classifying all the current result messages with the same semantics into the same category of messages; Generate a corresponding counter for each category of the current result message, and set the count value of the counter to the number of current result messages of the corresponding category; Set the counter with the largest count value as the candidate counter; If there are at least two candidate counters, the heterogeneous executor corresponding to the candidate counter is marked as a suspicious heterogeneous executor, and historical information is obtained; wherein the historical information includes a historical original message sent to the suspicious heterogeneous executor in the previous cycle, and a first historical result message obtained by the suspicious heterogeneous executor processing the historical original message in the previous cycle; Sending the historical original message to the suspicious heterogeneous execution body so that the suspicious heterogeneous execution body processes the historical original message to obtain a second historical result message; Determine whether the suspicious heterogeneous executable meets a first condition and a second condition; wherein the first condition is that the semantics of a first historical result message and a second historical result message generated by the suspicious heterogeneous executable are consistent, and the second condition is that the number of cleaning times of the suspicious heterogeneous executable is less than a preset number; If so, it is determined that the suspicious heterogeneous executable does not pose a security risk; If not, it is determined that the suspicious heterogeneous executable has a security risk.

2. The method for mimicking scheduling decision according to claim 1, characterized in that: After setting the counter with the largest count value as the candidate counter, the method further includes: If the count value of the candidate counter is m, it is determined that there is no security risk in all the heterogeneous executables; The current result message is set as security data, and the security data is output.

3. The method for mimicking scheduling decision according to claim 1, characterized in that: After setting the counter with the largest count value as the candidate counter, the method further includes: If the count value of the candidate counter is less than m and there is only one candidate counter, all heterogeneous executables corresponding to the candidate counter are marked as trusted heterogeneous executables; It is determined that other heterogeneous executives except the trusted heterogeneous executive have security risks.

4. The method for mimicking scheduling decision according to claim 1, wherein: After setting the counter with the largest count value as the candidate counter, the method further includes: It is determined that heterogeneous execution bodies corresponding to counters other than the candidate counter have security risks.

5. The method for mimicking scheduling decision according to any one of claims 1 to 3, characterized in that: Also includes: Clean heterogeneous executors that pose security risks; The current result message and the decision unit are cleared, and the process proceeds to the step of sending the current original message to each of the heterogeneous execution bodies.

6. The method for mimicking scheduling decision according to claim 1, characterized in that: Also includes: If the count value of the candidate counter is m, the historical information is deleted, and the current original message and the current result message are stored as new historical information.

7. The method for mimicking scheduling decision according to claim 1, characterized in that: Also includes: Counting the number of cleaning times of each heterogeneous executive body; If the number of cleaning times is greater than a critical value, sending messages to all the heterogeneous execution bodies is stopped, and it is determined that the heterogeneous execution body whose number of cleaning times is greater than the critical value has a security risk.

8. A mimic scheduling decision system, characterized in that: A mimetic scheduler applied to a dynamic heterogeneous redundant architecture, wherein the dynamic heterogeneous redundant architecture further includes m heterogeneous executors, and the mimetic scheduling decision system includes: A message sending module, configured to send the current original message to each of the heterogeneous execution bodies respectively, so that the heterogeneous execution body processes the current original message to obtain a current result message; A message receiving module, configured to receive m current result messages returned by all the heterogeneous execution bodies, and form a decision unit with the m current result messages; a semantic decision module, configured to determine the semantics of each of the current result messages in the decision unit, and classify all the current result messages with the same semantics into the same category of messages; a counting module, configured to generate a corresponding counter for each category of the current result message, and set the count value of the counter to the number of current result messages of the corresponding category; A counter setting module, used for setting the counter with the largest count value as a candidate counter; a marking module configured to mark the heterogeneous executor corresponding to the candidate counter as a suspicious heterogeneous executor if at least two candidate counters exist, and obtain historical information; wherein the historical information includes a historical original message sent to the suspicious heterogeneous executor in a previous cycle, and a first historical result message obtained by the suspicious heterogeneous executor processing the historical original message in the previous cycle; a comparison module, configured to send the historical original message to the suspicious heterogeneous execution body so that the suspicious heterogeneous execution body processes the historical original message to obtain a second historical result message; A judgment module is used to judge whether the suspicious heterogeneous executor meets the first condition and the second condition; wherein, the first condition is that the semantics of the first historical result message and the second historical result message generated by the suspicious heterogeneous executor are consistent, and the second condition is that the number of cleaning times of the suspicious heterogeneous executor is less than a preset number; if so, it is determined that the suspicious heterogeneous executor does not have a security risk; if not, it is determined that the suspicious heterogeneous executor has a security risk.

9. An electronic device, characterized in that: The method comprises a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the mimetic scheduling decision method according to any one of claims 1 to 7 are implemented.

10. A storage medium, characterized in that: The storage medium stores computer-executable instructions, which, when loaded and executed by the processor, implement the steps of the mimetic scheduling decision method according to any one of claims 1 to 7.

11. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the mimetic scheduling decision method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Trust-based mimicry defense voting mechanism and system

    CN111163046A

  • Mimicry scheduling judgment method and device, equipment and storage medium

    CN118295784A