Cloud environment security monitoring method and device

By using clustering algorithms and federated learning technology in cloud environments, initializing and distributing clustering parameters, and building data clustering and decision-making rules, the problems of data security monitoring and privacy protection in cross-organization collaboration are solved, and the detection and classification of secure data are realized.

CN119167432BActive Publication Date: 2025-05-06NANCHANG UNIV +3
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411667191.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-21
Publication Date
2025-05-06
Estimated Expiration
2044-11-21

AI Technical Summary

Technical Problem

When collaborating across institutions in a cloud environment, how to achieve real-time security monitoring, data sharing and electronic evidence forensics while ensuring user privacy is not compromised, and how to use clustering and federated learning across institutions to detect and classify secure data is a challenging issue.

Method used

By initializing the clustering algorithm and parameters on the central cloud server and distributing them to the participant nodes, data clustering and decision-making rules are constructed, and security decision-making and judgment are made in combination with historical data and nuclear vector decision-making information tables to ensure the security and privacy of the data.

Benefits of technology

It realizes security and privacy protection for cross-institutional data security decision-making collaboration, and effectively detects and classifies secure data through clustering and federated learning technology, solving the problems of cross-institutional data sharing and security monitoring.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119167432B_ABST
    Figure CN119167432B_ABST
Patent Text Reader

Abstract

The present invention provides a cloud environment security monitoring method and device, the method includes conditional data clustering of a training data set based on a decrypted clustering algorithm and clustering parameters to obtain a number of clustered clusters; and judging the conditional probability of security decisions according to a preset threshold; then adding all the data in the cluster to the training data set to obtain a new data set; calculating the kernel vector of the cluster, and obtaining the decision attribute value of the cluster, forming a decision rule according to the decision attribute value, calculating the consistency value of each decision rule in the cluster kernel vector decision information table, and comparing the consistency value with the preset rule conditional probability threshold; receiving and decrypting different decision information tables based on a number of participating party nodes, and calculating the distance between the new data set and the different decision information tables to obtain the decision attribute of the new data set. The present invention can solve the security and privacy issues of cross-institutional data security decision collaboration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud environment public security technology, and in particular to a cloud environment security monitoring method and device. Background Art

[0002] With the rise of big data and artificial intelligence, data is becoming a valuable strategic resource. However, the transfer of data between different institutions and departments is limited. In the field of public security in the cloud environment, ensuring data security and privacy protection is a critical task. Especially when it comes to cross-institutional collaboration, how to achieve real-time security monitoring, data sharing, and electronic evidence collection while protecting user privacy has become a complex and important issue.

[0003] Real-time security monitoring with cross-institutional privacy protection refers to technologies and processes that ensure data privacy and security when sharing data or collaborating between different organizations. This scenario has applications in many fields such as healthcare, financial services, and joint research. Federated learning is a distributed machine learning paradigm that allows multiple parties to collaborate on modeling without directly sharing data through data localization, significantly enhancing data security and privacy protection capabilities. The architecture of federated learning usually includes a central server or coordinator that is responsible for collecting, aggregating, and updating model parameters from various clients.

[0004] Clustering is a common technique in data mining and machine learning. It is an unsupervised learning method used to divide objects in a data set into multiple groups or clusters, so that data objects in the same cluster are similar to each other, while data objects in different clusters are quite different. The goal of clustering is to discover natural grouping structures in unlabeled data sets, which can maximize the mining of common features of a class of things. How to use clustering combined with federated learning to detect and classify security data across institutions is a challenging problem.

[0005] In summary, among the existing technologies, when it comes to cross-institutional collaboration, how to achieve real-time security monitoring, data sharing, and electronic forensics while protecting user privacy, and how to use clustering combined with federated learning to detect and classify security data across institutions is a challenging problem. Summary of the invention

[0006] Based on this, the purpose of the present invention is to provide a cloud environment security monitoring method and device to solve the deficiencies in the above-mentioned prior art.

[0007] In a first aspect, the present invention provides a cloud environment security monitoring method, the method comprising:

[0008] Initialize a clustering algorithm and clustering parameters based on a central cloud server, and distribute the clustering algorithm and clustering parameters to several participating nodes;

[0009] Receiving and decrypting the clustering algorithm and the clustering parameters based on a number of the participant nodes, and extracting historical data of the participant nodes to form a training data set;

[0010] Performing conditional data clustering on the training data set based on the decrypted clustering algorithm and the clustering parameters to obtain a plurality of clustering clusters;

[0011] Calculating the safety decision conditional probabilities of the clusters of the plurality of clusters, and judging the safety decision conditional probabilities according to a preset threshold;

[0012] If the safety decision condition probability is within the range of the preset threshold, all the data in the cluster are screened out, all the data in the cluster are added to the training data set to obtain a new data set, and the new data set and the historical data are combined into a new training set, so that several of the participant nodes train the corresponding local models based on the new training set;

[0013] Calculating the kernel vector of the cluster, obtaining the decision attribute value of the cluster, forming a decision rule according to the decision attribute value, and sending the decision rule to the central cloud server;

[0014] Based on the central cloud server receiving the core vector, decrypting the core vector to obtain a clustering core vector decision information table;

[0015] Calculating the consistency value of each decision rule in the cluster kernel vector decision information table, and comparing the consistency value with a preset rule condition probability threshold, so as to add each decision rule to different decision information tables, wherein the decision information tables include a safety decision table, an uncertain decision table, and a dangerous decision table;

[0016] Based on a number of the participant nodes receiving and decrypting the different decision information tables, and calculating the distance between the new data set and the different decision information tables, the decision attribute of the new data set is obtained.

[0017] Compared with the prior art, the beneficial effects of the present invention are as follows: by judging the conditional probability of safety decisions according to a preset threshold, for clusters whose conditional probabilities do not conform to safety decisions and dangerous decisions, the data extracted in combination with historical data can be re-judged, and by calculating the consistency values ​​of each decision rule in the clustering kernel vector decision information table, and comparing the consistency values ​​with the preset rule conditional probability threshold, the decision information table can be classified, and by calculating the distance between new data and each rule in different decision information tables, the decision rule that is most similar to it can be found, so as to make a decision on whether the new data is safe, thereby solving the security and privacy issues of cross-institutional data security decision-making collaboration.

[0018] Furthermore, the steps of initializing the clustering algorithm and clustering parameters based on the central cloud server and distributing the clustering algorithm and clustering parameters to several participating nodes include:

[0019] Selecting a central cloud server so that the central cloud server serves as an initiator and coordinator of federated learning;

[0020] The clustering algorithm and clustering parameters are initialized based on the central cloud server, and the initialized clustering algorithm and the initialized clustering parameters are distributed to several participant nodes based on the central cloud server.

[0021] Furthermore, the step of extracting the historical data of the participant nodes to form a training data set includes:

[0022] Obtaining historical data sets of several of the participant nodes;

[0023] Samples with binary decision attribute labels are randomly and non-repetitively extracted from the historical data set to form a training data set.

[0024] Furthermore, if the safety decision condition probability is within the range of the preset threshold, the step includes:

[0025] Calculate the safety decision conditional probability of the clusters of the plurality of clusters, the expression for calculating the safety decision conditional probability of the clusters of the plurality of clusters is:

[0026] ;

[0027] In the formula, represents the conditional probability of the safety decision, Indicates that the data sample belongs to a cluster The probability of Indicates that the sample label is safe and the sample is in the cluster The probability of

[0028] Establish a preset safety decision condition probability threshold and a dangerous decision condition probability threshold, wherein the range expressions of the safety decision condition probability threshold and the dangerous decision condition probability threshold are:

[0029] ;

[0030] In the formula, represents the conditional probability threshold of safety decision, represents the conditional probability threshold of dangerous decision;

[0031] Comparing the safety decision condition probability with the safety decision condition probability threshold and the danger decision condition probability threshold;

[0032] If the safety decision condition probability is less than or equal to the dangerous decision condition probability threshold or the safety decision condition probability is greater than or equal to the safety decision condition probability threshold, the kernel vector of the cluster is calculated, and the decision attribute value of the cluster is obtained. A decision rule is formed according to the decision attribute value, and the decision rule is sent to the central cloud server.

[0033] Furthermore, after the step of sending the decision rule to the central cloud server, the method further includes:

[0034] Randomly and non-repetitively extracting a preset number of data from the historical data of the participant node;

[0035] A preset amount of the data is added to the training data set, and conditional data clustering is performed on the training data set after the data is added.

[0036] Furthermore, the step of comparing the consistency value with a preset rule condition probability threshold to add each of the decision rules to different decision information tables includes:

[0037] Setting a safety rule conditional probability threshold and a danger rule conditional probability threshold, and comparing the consistency value with the safety rule conditional probability threshold and the danger rule conditional probability threshold;

[0038] If the consistency value is greater than or equal to the safety rule condition probability threshold, then the decision rule is added to the safety decision table;

[0039] If the consistency value is greater than the danger rule condition probability threshold and less than the safety rule condition probability threshold, then the decision rule is added to the uncertain decision table;

[0040] If the consistency value is less than or equal to the risk rule conditional probability threshold, the decision rule is added to the risk decision table.

[0041] Furthermore, the step of obtaining the decision attributes of the new data set includes:

[0042] Determining the distance between the new data set and the different decision information tables;

[0043] If the distance between the new data set and the safety decision table is the shortest, the decision attribute value of the new data set is safety;

[0044] If the distance between the new data set and the uncertain decision table is the shortest, then the decision attribute value of the new data set is uncertain;

[0045] If the new data is closest to the danger decision table, the decision attribute value of the new data set is danger.

[0046] In a second aspect, the present invention further provides a cloud environment security monitoring device, the device comprising:

[0047] An initialization module, used to initialize the clustering algorithm and clustering parameters based on the central cloud server, and distribute the clustering algorithm and the clustering parameters to several participating party nodes;

[0048] A decryption and extraction module, used for receiving and decrypting the clustering algorithm and the clustering parameters based on a number of the participant nodes, and extracting the historical data of the participant nodes to form a training data set;

[0049] A conditional clustering module, used for performing conditional data clustering on the training data set based on the decrypted clustering algorithm and the clustering parameters to obtain a plurality of clustered clusters;

[0050] A calculation and judgment module, used to calculate the safety decision condition probability of the clusters of the plurality of clusters, and judge the safety decision condition probability according to a preset threshold;

[0051] An adding module, used to determine if the safety decision condition probability is within the range of the preset threshold, then filter out all the data in the cluster, add all the data in the cluster to the training data set to obtain a new data set, and combine the new data set with the historical data to form a new training set, so that several of the participant nodes train the corresponding local models based on the new training set;

[0052] A calculation and acquisition module, used for calculating the core vector of the cluster and obtaining the decision attribute value of the cluster, forming a decision rule according to the decision attribute value, and sending the decision rule to the central cloud server;

[0053] A receiving and decrypting module, configured to receive the core vector based on the central cloud server, and decrypt the core vector to obtain a clustering core vector decision information table;

[0054] A calculation and comparison module, used for calculating the consistency value of each decision rule in the cluster kernel vector decision information table, and comparing the consistency value with a preset rule condition probability threshold, so as to add each decision rule to different decision information tables, wherein the decision information tables include a safety decision table, an uncertain decision table, and a dangerous decision table;

[0055] The decryption calculation module is used to receive and decrypt the different decision information tables based on a number of the participant nodes, and calculate the distance between the new data set and the different decision information tables to obtain the decision attribute of the new data set.

[0056] In a third aspect, the present invention further provides a readable storage medium having a computer program stored thereon, which implements the above-mentioned cloud environment security monitoring method when executed by a processor.

[0057] In a fourth aspect, the present invention further provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned cloud environment security monitoring method when executing the computer program. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 is a flow chart of a cloud environment security monitoring method in a first embodiment of the present invention;

[0059] Figure 2 is a structural block diagram of a cloud environment security monitoring device in a second embodiment of the present invention;

[0060] Figure 3 It is a structural block diagram of a computer device in the third embodiment of the present invention.

[0061] Description of main component symbols:

[0062] 11. Initialization module; 12. Decryption extraction module; 13. Condition clustering module; 14. Calculation and judgment module; 15. Adding module; 16. Calculation acquisition module; 17. Receiving and decryption module; 18. Calculation comparison module; 19. Decryption calculation module;

[0063] 10. Memory; 20. Processor; 30. Computer program.

[0064] The following specific implementation manner will further illustrate the present invention in conjunction with the above-mentioned drawings. DETAILED DESCRIPTION

[0065] In order to facilitate the understanding of the present invention, the present invention will be described more fully below with reference to the relevant drawings. Several embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive.

[0066] It should be noted that when an element is referred to as being "fixed to" another element, it may be directly on the other element or there may be a central element. When an element is considered to be "connected to" another element, it may be directly connected to the other element or there may be a central element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are for illustrative purposes only.

[0067] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which the present invention belongs. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.

[0068] Embodiment 1

[0069] See also Figure 1 , which shows a cloud environment security monitoring method in a first embodiment of the present invention, the method includes steps S1 to S9:

[0070] S1, initializing a clustering algorithm and clustering parameters based on a central cloud server, and distributing the clustering algorithm and clustering parameters to several participating nodes;

[0071] Specifically, the step S1 includes steps S11 to S12:

[0072] S11, selecting a central cloud server so that the central cloud server serves as an initiator and coordinator of federated learning;

[0073] S12, initializing a clustering algorithm and clustering parameters based on the central cloud server, and distributing the initialized clustering algorithm and the initialized clustering parameters to a plurality of participating party nodes based on the central cloud server;

[0074] It should be explained that a central cloud server G is selected as the initiator and coordinator of federated learning. The central cloud server first initializes the k-means clustering algorithm and the clustering parameters of the participating nodes. The central cloud server distributes the clustering algorithm and clustering parameters to all participating nodes. In this embodiment, the expression of all participating nodes is: , the expression of the participating node is .

[0075] S2, receiving and decrypting the clustering algorithm and the clustering parameters based on a number of the participant nodes, and extracting historical data of the participant nodes to form a training data set;

[0076] It is understandable that several participant nodes perform decryption after receiving the clustering algorithm and clustering parameters from the central cloud server;

[0077] Specifically, the step S2 includes steps S21 to S22:

[0078] S21, obtaining historical data sets of several participating party nodes;

[0079] S22, randomly and non-repetitively extracting samples with binary decision attribute labels from the historical data set to form a training data set;

[0080] It can be understood that samples with binary decision attribute labels are randomly and non-repeatedly extracted from the historical data set of the participating nodes to form a training data set. In this embodiment, the training data set can be expressed as , where for any , the data structure of this sample It can be expressed as ,in, Represents conditional attribute characteristics, It represents the decision attribute feature label, which is binary.

[0081] S3, performing conditional data clustering on the training data set based on the decrypted clustering algorithm and the clustering parameters to obtain a plurality of clusters;

[0082] It can be understood that the participating nodes perform conditional attribute clustering on the training data set through clustering algorithms and clustering parameters. After clustering is completed, the clustering results can be obtained, and x clusters can be obtained, which can be expressed as , for any , indicating that it belongs to the cluster in the clustering result , Indicates the number of the participating node, Indicates the number of the cluster. represents the number of clusters, for All elements in the do the following:

[0083] for ,calculate Conditional Probability of Safety Decisions , the calculation method of decision conditional probability P is:

[0084] ;

[0085] in, represents the probability that the data sample belongs to cluster C, Represents the probability that the sample label is T and the sample is in cluster C in the cluster, and the conditional probability set of all clusters is calculated ,in Indicates the ID of the participant.

[0086] S4, calculating the safety decision conditional probabilities of the clusters of the plurality of clusters, and judging the safety decision conditional probabilities according to a preset threshold;

[0087] S5, if the safety decision condition probability is within the range of the preset threshold, all the data in the cluster are screened out, all the data in the cluster are added to the training data set to obtain a new data set, and the new data set and the historical data are combined into a new training set, so that the nodes of the participating parties train the corresponding local models based on the new training set;

[0088] It is understandable that for any , computing clusters Conditional probability of security decision for data elements in , the expression for calculating the conditional probability of safety decision of the clusters of several clusters is:

[0089] ;

[0090] In the formula, represents the conditional probability of the safety decision, Indicates that the data sample belongs to a cluster The probability of Indicates that the sample label is safe and the sample is in the cluster The probability in .

[0091] Specifically, in this embodiment, step S5 further includes steps S51 to S54:

[0092] S51, calculating the safety decision conditional probability of the clusters of the plurality of clusters;

[0093] S52, establishing a preset safety decision condition probability threshold, and establishing a danger decision condition probability threshold, wherein the range expressions of the safety decision condition probability threshold and the danger decision condition probability threshold are:

[0094] ;

[0095] In the formula, represents the conditional probability threshold of safety decision, represents the conditional probability threshold of dangerous decision;

[0096] S53, comparing the safety decision condition probability with the safety decision condition probability threshold and the danger decision condition probability threshold;

[0097] S54, if the safety decision condition probability is less than or equal to the danger decision condition probability threshold or the safety decision condition probability is greater than or equal to the safety decision condition probability threshold, then the kernel vector of the cluster is calculated, and the decision attribute value of the cluster is obtained, a decision rule is formed according to the decision attribute value, and the decision rule is sent to the central cloud server;

[0098] It should be noted that according to the preset safety decision condition probability threshold , clusters are grouped Divide into two subsets: for any ,like The conditional probability of a safe decision , then Add to cluster collection ,like The conditional probability of a safe decision or , then Add to cluster collection , assuming that , ,right Then continue to randomly extract samples with binary decision attribute labels from the historical data set without duplication to form a training data set. Then execute step S6.

[0099] S6, calculating the core vector of the cluster, and obtaining the decision attribute value of the cluster, forming a decision rule according to the decision attribute value, and sending the decision rule to the central cloud server;

[0100] It is understandable that computing clusters The nuclear vector , the label with the most occurrences in the cluster is used as the decision attribute value , and The decision rule is formed and expressed as , the decision rules are encrypted and sent to the central cloud server.

[0101] Specifically, the step S6 includes step S61 to step S62:

[0102] S61, randomly and non-repetitively extracting a preset number of data from the historical data of the participant node;

[0103] S62, adding a preset amount of the data to the training data set, and performing conditional data clustering on the training data set after the data is added;

[0104] It is understandable that after the decision rule is encrypted and sent to the central cloud server, it is randomly and non-repeatedly Extract a certain amount of data from the historical data and add it to , and then conditional data clustering is performed on a certain amount of added data.

[0105] S7, based on the central cloud server receiving the core vector, decrypting the core vector to obtain a clustering core vector decision information table;

[0106] It can be understood that the central cloud server receives encrypted clustering core vectors from several participant nodes, decrypts and aggregates them to obtain a clustering core vector decision information table. In this embodiment, the clustering core vector decision information table is represented by IS.

[0107] S8, calculating the consistency value of each decision rule in the cluster kernel vector decision information table, and comparing the consistency value with the preset rule condition probability threshold, so as to add each decision rule to different decision information tables, wherein the decision information tables include a safety decision table, an uncertain decision table and a dangerous decision table;

[0108] It can be understood that the consistency value of each decision rule in IS is calculated for any decision rule in the decision information table. , its decision conditional probability .in , y represents the total number of decision rules, Representation and decision rules The number of decision rules with consistent condition attribute characteristics; , Representation and decision rules In the decision rules with consistent condition attribute characteristics, the decision attribute value is The number of rules with consistent decision attribute values. (Consistency: For any two decision rules, an exact match is performed on the condition attribute characteristics. If the result is true, the condition attribute characteristics of the two rules are consistent.)

[0109] Specifically, the step S8 includes steps S81 to S84:

[0110] S81, setting a safety rule conditional probability threshold and a danger rule conditional probability threshold, and comparing the consistency value with the safety rule conditional probability threshold and the danger rule conditional probability threshold;

[0111] S82, if the consistency value is greater than or equal to the security rule condition probability threshold, adding the decision rule to the security decision table;

[0112] S83, if the consistency value is greater than the danger rule condition probability threshold and less than the safety rule condition probability threshold, then add the decision rule to the uncertain decision table;

[0113] S84, if the consistency value is less than or equal to the risk rule condition probability threshold, then adding the decision rule to the risk decision table;

[0114] It should be noted that the decision conditional probabilities of all decision rules in IS , using the complementary relationship between binary decision probabilities, the consistency values ​​are further uniformly converted into decision conditional probabilities .

[0115] for All elements in , respectively execute the following three decisions:

[0116] like , then the decision rule Add to Danger Rules Table ;

[0117] like , then the decision rule Add to uncertainty rule table ;

[0118] like , then the decision rule Add to security rules table ,in, represents the conditional probability threshold of the security rule, represents the conditional probability threshold of the danger rule, and then , and Encrypted and sent to all parties .

[0119] S9, receiving and decrypting the different decision information tables based on a number of the participant nodes, and calculating the distance between the new data set and the different decision information tables to obtain the decision attribute of the new data set;

[0120] Specifically, the step S9 includes steps S91 to S94:

[0121] S91, determining the distance between the new data set and the different decision information tables;

[0122] S92, if the distance between the new data set and the security decision table is the shortest, then the decision attribute value of the new data set is security;

[0123] S93, if the distance between the new data set and the uncertain decision table is the shortest, the decision attribute value of the new data set is uncertain;

[0124] S94, if the distance between the new data and the danger decision table is the shortest, then the decision attribute value of the new data set is danger;

[0125] It needs to be explained that the participating nodes decrypt and obtain the corresponding three decision information tables , and , for a new data set (This data only has conditional attribute features and lacks decision attribute features) and calculates the new data set The distance between all rules in the three decision information tables is calculated as follows:

[0126]

[0127] In the formula, express The distance between the three decision information tables, represents the decision rule, where n represents the dimension of the conditional attribute feature, represents the conditional attribute characteristics of the decision rule, Represents the conditional attribute characteristics of new data;

[0128] The distance between the conditional attribute features of all decision rules in the three decision tables can be expressed as , where the subscript The ID of the decision rule in the set Find the element with the smallest distance , and then we can get the corresponding decision rule that is closest to the new data :

[0129] if and The rule in is closest, then the new data The decision attribute is judged to be safe;

[0130] if and The rule in is closest, then the new data The decision attribute is judged as being unable to determine whether it is safe or dangerous;

[0131] if and The rule in is closest, then the new data The decision attribute is judged as dangerous.

[0132] In summary, the cloud environment security monitoring method in the above-mentioned embodiment of the present invention judges the conditional probability of security decisions according to a preset threshold. For clusters whose conditional probabilities do not conform to security decisions and dangerous decisions, the data extracted in combination with historical data can be re-judged. The consistency values ​​of each decision rule in the clustering kernel vector decision information table are calculated, and the consistency values ​​are compared with the preset rule conditional probability thresholds, so that the decision information table can be classified. By calculating the distance between new data and each rule in different decision information tables, the decision rule that is most similar to it is found, so as to make a decision on whether the new data is safe, thereby solving the security and privacy issues of cross-institutional data security decision-making collaboration.

[0133] Embodiment 2

[0134] See also Figure 2 , which shows a cloud environment security monitoring device in a second embodiment of the present invention, the device comprises:

[0135] An initialization module 11 is used to initialize the clustering algorithm and clustering parameters based on the central cloud server, and distribute the clustering algorithm and the clustering parameters to several participating nodes;

[0136] A decryption and extraction module 12, configured to receive and decrypt the clustering algorithm and the clustering parameters based on a number of the participant nodes, and extract the historical data of the participant nodes to form a training data set;

[0137] A conditional clustering module 13, configured to perform conditional data clustering on the training data set based on the decrypted clustering algorithm and the clustering parameters to obtain a plurality of clusters;

[0138] A calculation and judgment module 14 is used to calculate the safety decision condition probability of the clusters of the plurality of clusters, and judge the safety decision condition probability according to a preset threshold;

[0139] An adding module 15 is used to determine if the safety decision condition probability is within the range of the preset threshold, then filter out all the data in the cluster, add all the data in the cluster to the training data set to obtain a new data set, and combine the new data set with the historical data to form a new training set, so that several of the participant nodes train the corresponding local models based on the new training set;

[0140] A calculation and acquisition module 16, used for calculating the core vector of the cluster, obtaining the decision attribute value of the cluster, forming a decision rule according to the decision attribute value, and sending the decision rule to the central cloud server;

[0141] A receiving and decrypting module 17, configured to receive the core vector based on the central cloud server, and decrypt the core vector to obtain a clustering core vector decision information table;

[0142] A calculation and comparison module 18 is used to calculate the consistency value of each decision rule in the cluster kernel vector decision information table, and compare the consistency value with a preset rule condition probability threshold to add each decision rule to different decision information tables, wherein the decision information tables include a safety decision table, an uncertain decision table, and a dangerous decision table;

[0143] The decryption calculation module 19 is used to receive and decrypt the different decision information tables based on a number of the participant nodes, and calculate the distance between the new data set and the different decision information tables to obtain the decision attribute of the new data set.

[0144] In some optional embodiments, the initialization module 11 includes:

[0145] A selection unit, used for selecting a central cloud server so that the central cloud server serves as an initiator and coordinator of federated learning;

[0146] An initialization unit is used to initialize the clustering algorithm and clustering parameters based on the central cloud server, and distribute the initialized clustering algorithm and the initialized clustering parameters to several participant nodes based on the central cloud server.

[0147] In some optional embodiments, the decryption extraction module 12 includes:

[0148] An acquisition unit, used to acquire historical data sets of several participant nodes;

[0149] The first extraction unit is used to randomly and non-repetitively extract samples with binary decision attribute labels from the historical data set to form a training data set.

[0150] In some optional embodiments, the adding module 15 includes:

[0151] A calculation unit is used to calculate the safety decision condition probability of the clusters of the plurality of clusters, wherein the expression for calculating the safety decision condition probability of the clusters of the plurality of clusters is:

[0152] ;

[0153] In the formula, represents the conditional probability of the safety decision, Indicates that the data sample belongs to a cluster The probability of Indicates that the sample label is safe and the sample is in the cluster The probability of

[0154] An establishing unit is used to establish a preset safety decision condition probability threshold and a dangerous decision condition probability threshold, wherein the range expressions of the safety decision condition probability threshold and the dangerous decision condition probability threshold are:

[0155] ;

[0156] In the formula, represents the conditional probability threshold of safety decision, represents the conditional probability threshold of dangerous decision;

[0157] A comparison unit, used for comparing the safety decision condition probability with the safety decision condition probability threshold and the danger decision condition probability threshold;

[0158] An execution unit is used to determine if the safety decision condition probability is less than or equal to the danger decision condition probability threshold or the safety decision condition probability is greater than or equal to the safety decision condition probability threshold, then calculate the kernel vector of the cluster, obtain the decision attribute value of the cluster, form a decision rule according to the decision attribute value, and send the decision rule to the central cloud server.

[0159] In some optional embodiments, the calculation acquisition module 16 includes:

[0160] A second extraction unit is used to randomly and non-repetitively extract a preset number of data from the historical data of the participant node;

[0161] The clustering unit is used to add a preset amount of the data to the training data set, and perform conditional data clustering on the training data set after the data is added.

[0162] In some optional embodiments, the calculation and comparison module 18 includes:

[0163] A setting unit, used to set a safety rule condition probability threshold and a danger rule condition probability threshold, and compare the consistency value with the safety rule condition probability threshold and the danger rule condition probability threshold;

[0164] A first adding unit, configured to add the decision rule to a security decision table if the consistency value is greater than or equal to the security rule condition probability threshold;

[0165] A second adding unit, configured to add the decision rule to an uncertain decision table if the consistency value is greater than the danger rule condition probability threshold and less than the safety rule condition probability threshold;

[0166] The third adding unit is used to add the decision rule to the risk decision table if the consistency value is less than or equal to the risk rule condition probability threshold.

[0167] In some optional embodiments, the decryption calculation module 19 includes:

[0168] A first judging unit, configured to judge the distance between the new data set and the different decision information tables;

[0169] A second judgment unit, configured to determine that the decision attribute value of the new data set is safe if the new data set is closest to the safety decision table;

[0170] A third judgment unit, configured to determine that if the new data set is closest to the uncertain decision table, the decision attribute value of the new data set is uncertain;

[0171] The fourth judgment unit is used to determine that the decision attribute value of the new data set is dangerous if the new data is closest to the dangerous decision table.

[0172] The functions or operation steps implemented when the above modules and units are executed are generally the same as those in the above method embodiments, and will not be repeated here.

[0173] The cloud environment security monitoring device provided in the embodiment of the present invention has the same implementation principle and technical effects as those of the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the system embodiment, reference may be made to the corresponding contents in the aforementioned method embodiment.

[0174] Embodiment 3

[0175] The present invention also provides a computer device, see Figure 3 , shown is a computer device in the third embodiment of the present invention, including a memory 10, a processor 20, and a computer program 30 stored in the memory 10 and executable on the processor 20, and the processor 20 implements the above-mentioned cloud environment security monitoring method when executing the computer program 30.

[0176] The memory 10 includes at least one type of readable storage medium, and the readable storage medium includes a flash memory, a hard disk, a multimedia card, a card-type memory (for example, an SD or DX memory, etc.), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 10 may be an internal storage unit of a computer device, such as a hard disk of the computer device. In other embodiments, the memory 10 may also be an external storage device, such as a plug-in hard disk, a smart memory card (Smart MediaCard, SMC), a secure digital (Secure Digital, SD) card, a flash card, etc. Further, the memory 10 may also include both an internal storage unit of a computer device and an external storage device. The memory 10 may be used not only to store application software and various types of data installed in the computer device, but also to temporarily store data that has been output or is to be output.

[0177] Among them, in some embodiments, the processor 20 can be an electronic control unit (Electronic Control Unit, abbreviated as ECU, also known as a vehicle computer), a central processing unit (Central Processing Unit, CPU), a controller, a microcontroller, a microprocessor or other data processing chip, used to run the program code stored in the memory 10 or process data, such as executing access restriction programs, etc.

[0178] It should be pointed out that Figure 3 The structure shown does not constitute a limitation on the computer device. In other embodiments, the computer device may include fewer or more components than shown in the figure, or combine certain components, or arrange the components differently.

[0179] An embodiment of the present invention further provides a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the cloud environment security monitoring method as described above.

[0180] Those skilled in the art will appreciate that the logic and / or steps represented in the flowchart or otherwise described herein, for example, may be considered as an ordered list of executable instructions for implementing logical functions, and may be specifically implemented in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For purposes of this specification, "computer-readable medium" may be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.

[0181] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.

[0182] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or a combination thereof: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0183] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0184] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.

Claims

1. A cloud environment security monitoring method, characterized in that: The method comprises: Initialize a clustering algorithm and clustering parameters based on a central cloud server, and distribute the clustering algorithm and clustering parameters to several participating nodes; Receiving and decrypting the clustering algorithm and the clustering parameters based on a number of the participant nodes, and extracting historical data of the participant nodes to form a training data set; Performing conditional data clustering on the training data set based on the decrypted clustering algorithm and the clustering parameters to obtain a plurality of clustering clusters; Calculating the safety decision conditional probabilities of the clusters of the plurality of clusters, and judging the safety decision conditional probabilities according to a preset threshold; If the safety decision condition probability is within the range of the preset threshold, all the data in the cluster are screened out, all the data in the cluster are added to the training data set to obtain a new data set, and the new data set and the historical data are combined into a new training set, so that several of the participant nodes train the corresponding local models based on the new training set; Calculating the kernel vector of the cluster, obtaining the decision attribute value of the cluster, forming a decision rule according to the decision attribute value, and sending the decision rule to the central cloud server; Based on the central cloud server receiving the core vector, decrypting the core vector to obtain a clustering core vector decision information table; Calculate the consistency value of each decision rule in the cluster kernel vector decision information table, and compare the consistency value with the preset rule condition probability threshold to add each decision rule to different decision information tables, the decision information tables include a safety decision table, an uncertain decision table and a dangerous decision table, wherein consistency means that any two decision rules are matched in terms of condition attribute features, and if the result is true, the condition attribute features of the two decision rules are consistent; Based on a number of the participant nodes receiving and decrypting the different decision information tables, and calculating the distance between the new data set and the different decision information tables, the decision attribute of the new data set is obtained.

2. The cloud environment security monitoring method according to claim 1, characterized in that: The steps of initializing the clustering algorithm and clustering parameters based on the central cloud server and distributing the clustering algorithm and clustering parameters to several participating nodes include: Selecting a central cloud server so that the central cloud server serves as an initiator and coordinator of federated learning; The clustering algorithm and clustering parameters are initialized based on the central cloud server, and the initialized clustering algorithm and the initialized clustering parameters are distributed to several participant nodes based on the central cloud server.

3. The cloud environment security monitoring method according to claim 1, characterized in that: The step of extracting the historical data of the participant nodes to form a training data set includes: Obtaining historical data sets of several of the participant nodes; Samples with binary decision attribute labels are randomly and non-repetitively extracted from the historical data set to form a training data set.

4. The cloud environment security monitoring method according to claim 1, characterized in that: The step of if the safety decision condition probability is within the range of the preset threshold comprises: Calculate the safety decision conditional probability of the clusters of the plurality of clusters, the expression for calculating the safety decision conditional probability of the clusters of the plurality of clusters is: ; In the formula, represents the conditional probability of the safety decision, Indicates that the data sample belongs to a cluster The probability of Indicates that the sample label is safe and the sample is in the cluster The probability of Establish a preset safety decision condition probability threshold and a dangerous decision condition probability threshold, wherein the range expressions of the safety decision condition probability threshold and the dangerous decision condition probability threshold are: ; In the formula, represents the conditional probability threshold of safety decision, represents the conditional probability threshold of dangerous decision; Comparing the safety decision condition probability with the safety decision condition probability threshold and the danger decision condition probability threshold; If the safety decision condition probability is less than or equal to the dangerous decision condition probability threshold or the safety decision condition probability is greater than or equal to the safety decision condition probability threshold, the kernel vector of the cluster is calculated, and the decision attribute value of the cluster is obtained. A decision rule is formed according to the decision attribute value, and the decision rule is sent to the central cloud server.

5. The cloud environment security monitoring method according to claim 1, characterized in that: After the step of sending the decision rule to the central cloud server, the method further includes: Randomly and non-repetitively extracting a preset number of data from the historical data of the participant node; A preset amount of the data is added to the training data set, and conditional data clustering is performed on the training data set after the data is added.

6. The cloud environment security monitoring method according to claim 1, characterized in that: The step of comparing the consistency value with a preset rule condition probability threshold to add each of the decision rules to different decision information tables includes: Setting a safety rule conditional probability threshold and a danger rule conditional probability threshold, and comparing the consistency value with the safety rule conditional probability threshold and the danger rule conditional probability threshold; If the consistency value is greater than or equal to the safety rule condition probability threshold, then the decision rule is added to the safety decision table; If the consistency value is greater than the danger rule condition probability threshold and less than the safety rule condition probability threshold, then the decision rule is added to the uncertain decision table; If the consistency value is less than or equal to the risk rule conditional probability threshold, the decision rule is added to the risk decision table.

7. The cloud environment security monitoring method according to claim 6, characterized in that: The step of obtaining the decision attributes of the new data set comprises: Determining the distance between the new data set and the different decision information tables; If the distance between the new data set and the safety decision table is the shortest, the decision attribute value of the new data set is safety; If the distance between the new data set and the uncertain decision table is the shortest, then the decision attribute value of the new data set is uncertain; If the new data is closest to the danger decision table, the decision attribute value of the new data set is danger.

8. A cloud environment security monitoring device, characterized in that: The device comprises: An initialization module, used to initialize the clustering algorithm and clustering parameters based on the central cloud server, and distribute the clustering algorithm and the clustering parameters to several participating party nodes; A decryption and extraction module, used for receiving and decrypting the clustering algorithm and the clustering parameters based on a number of the participant nodes, and extracting the historical data of the participant nodes to form a training data set; A conditional clustering module, used for performing conditional data clustering on the training data set based on the decrypted clustering algorithm and the clustering parameters to obtain a plurality of clustered clusters; A calculation and judgment module, used to calculate the safety decision condition probability of the clusters of the plurality of clusters, and judge the safety decision condition probability according to a preset threshold; An adding module, used to determine if the safety decision condition probability is within the range of the preset threshold, then filter out all the data in the cluster, add all the data in the cluster to the training data set to obtain a new data set, and combine the new data set with the historical data to form a new training set, so that several of the participant nodes train the corresponding local models based on the new training set; A calculation and acquisition module, used for calculating the core vector of the cluster and obtaining the decision attribute value of the cluster, forming a decision rule according to the decision attribute value, and sending the decision rule to the central cloud server; A receiving and decrypting module, configured to receive the core vector based on the central cloud server, and decrypt the core vector to obtain a clustering core vector decision information table; A calculation and comparison module is used to calculate the consistency value of each decision rule in the cluster kernel vector decision information table, and compare the consistency value with the preset rule condition probability threshold to add each decision rule to different decision information tables, wherein the decision information table includes a safety decision table, an uncertain decision table, and a dangerous decision table, wherein consistency means that any two decision rules are matched in terms of condition attribute features, and if the result is true, the condition attribute features of the two decision rules are consistent; The decryption calculation module is used to receive and decrypt the different decision information tables based on a number of the participant nodes, and calculate the distance between the new data set and the different decision information tables to obtain the decision attribute of the new data set.

9. A readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the cloud environment security monitoring method as described in any one of claims 1 to 7 is implemented.

10. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the cloud environment security monitoring method as described in any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Machine learning method based on federated learning, electronic device and storage medium

    CN112101579A

  • Clustering and knowledge distillation-based credible personalized federal learning method and device

    CN116862024A