A computer cluster security protection method and system

By building an abnormal traffic detection model, protection strategy generation model and resource scheduling model, combined with deep learning, reinforcement learning and group intelligence algorithms, the problems of low detection accuracy, single protection strategy and unreasonable resource scheduling of computer clusters when facing malicious attacks are solved, efficient and flexible security protection and resource scheduling are achieved, ensuring the stability and rapid response capabilities of computer clusters.

CN119182595BActive Publication Date: 2025-05-13BEIJING XIAOYOU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411284717.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-13
Publication Date
2025-05-13
Estimated Expiration
2044-09-13

AI Technical Summary

Technical Problem

Computer clusters are vulnerable to malicious attacks during operation. The existing technology has low detection accuracy, single protection strategy and unreasonable resource scheduling, resulting in missed reports, high false alarm rates, low resource utilization rates and poor system stability.

Method used

Build an abnormal traffic detection model, protection strategy generation model and resource scheduling model, combine deep learning, reinforcement learning and group intelligence algorithms, dynamically detect abnormal traffic, generate adaptive protection strategies and optimize resource scheduling, and deploy Hfish honeypot chain network to capture real-time access traffic data.

Benefits of technology

It improves detection accuracy and identification capabilities of new attacks, enhances the flexibility and effectiveness of protection strategies, optimizes resource utilization, and ensures the rapid response and stability of computer clusters when facing threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119182595B_ABST
    Figure CN119182595B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of security protection, and discloses a computer cluster security protection method and system. The method comprises the following steps: constructing an abnormal traffic detection model, a protection strategy generation model and a resource scheduling model in a computer cluster; using the Hfish honeypot chain network in the computer cluster to capture real-time access traffic data; using the abnormal traffic detection model to perform abnormal traffic detection based on the real-time access traffic data; using the protection strategy generation model to generate a protection strategy based on the real-time abnormal traffic detection result; using the resource scheduling model to generate a resource scheduling plan based on the real-time protection strategy; performing resource scheduling in the computer cluster based on the real-time resource scheduling plan to obtain a computer cluster after resource scheduling, and executing a real-time protection strategy based on the computer cluster after resource scheduling. The present invention solves the problems of low detection accuracy, single protection strategy and unreasonable resource scheduling in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of security protection, and in particular relates to a computer cluster security protection method and system. Background Art

[0002] With the rapid development of the Internet, computer clusters are increasingly used in various fields. However, computer clusters are vulnerable to malicious attacks during operation, and how to improve the security protection capabilities of computer clusters has become an urgent problem to be solved.

[0003] Defects of the prior art:

[0004] 1) Low detection accuracy: Due to the diversification and continuous evolution of attack methods, the existing attack detection methods cannot effectively identify new attacks, resulting in high rates of missed reports and false positives. In addition, when processing large-scale, high-dimensional network traffic data, the detection accuracy may be reduced due to improper feature selection or insufficient model complexity.

[0005] 2) Single protection strategy: The existing security protection methods use fixed defense strategies, which are incapable of coping with complex and changing network attacks and cannot take the best defense measures for different attack types;

[0006] 3) Unreasonable resource scheduling: Existing resource scheduling methods often adopt static allocation strategies and cannot dynamically adjust resources according to real-time load and security requirements, resulting in low resource utilization and lack of global optimization perspective. This may cause key services to not receive sufficient support when resources are tight, affecting the stability and security of the entire cluster. Summary of the invention

[0007] In order to solve the problems of low detection accuracy, single protection strategy and unreasonable resource scheduling in the prior art, the present invention aims to provide a computer cluster security protection method and system.

[0008] The technical solution adopted by the present invention is:

[0009] A computer cluster security protection method comprises the following steps:

[0010] Construct abnormal traffic detection models, protection strategy generation models, and resource scheduling models in computer clusters;

[0011] Deploy Hfish honeypot chain network in the computer cluster and use Hfish honeypot chain network to capture real-time access traffic data;

[0012] According to the real-time access traffic data, an abnormal traffic detection model is used to perform abnormal traffic detection to obtain real-time abnormal traffic detection results;

[0013] According to the real-time abnormal traffic detection results, a protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy;

[0014] According to the real-time protection strategy, the resource scheduling model is used to generate a resource scheduling plan to obtain a real-time resource scheduling plan;

[0015] According to the real-time resource scheduling scheme, resource scheduling is performed in the computer cluster to obtain a computer cluster after resource scheduling, and a real-time protection strategy is executed based on the computer cluster after resource scheduling.

[0016] Furthermore, an abnormal traffic detection model, a protection strategy generation model, and a resource scheduling model are constructed in a computer cluster, including the following steps:

[0017] Based on any computer node in the computer cluster, a number of historical access flow data are collected, and the number of historical access flow data are preprocessed to obtain a number of preprocessed historical access flow data;

[0018] Based on some pre-processed historical access traffic data, a deep learning algorithm is used to build an abnormal traffic detection model, and several historical abnormal traffic detection results and corresponding historical key dimension features are generated;

[0019] Based on several historical abnormal traffic detection results and several corresponding historical key dimension features, a reinforcement learning algorithm is used to build a protection strategy generation model, generate several historical protection strategies and several historical protection strategy generation experiences, and store several historical protection strategy generation experiences in the experience playback pool of the protection strategy generation model;

[0020] Based on several historical protection strategies, a fusion algorithm is used to build a resource scheduling model;

[0021] Deploy the abnormal traffic detection model, protection strategy generation model and resource scheduling model as corresponding abnormal traffic detection service, protection strategy generation service and resource scheduling model service;

[0022] Provide corresponding abnormal traffic detection service API interface, protection strategy generation service API interface and resource scheduling model service API interface for abnormal traffic detection service, protection strategy generation service and resource scheduling model service;

[0023] The abnormal traffic detection service API interface, the protection strategy generation service API interface and the resource scheduling model service API interface are published to the computer cluster.

[0024] Furthermore, the abnormal traffic detection model is built based on the N-GAN-Attention-LSTM algorithm;

[0025] The protection strategy generation model is built based on the DQN algorithm;

[0026] The resource scheduling model is built based on the BiLSTM-ICPO algorithm.

[0027] Furthermore, deploying the Hfish honeypot chain network in the computer cluster and using the Hfish honeypot chain network to capture real-time access traffic data includes the following steps:

[0028] Download the Hfish warehouse to each computer node in the computer cluster, collect the operating system information of each computer node, and generate the corresponding honeypot elements based on the operating system information;

[0029] According to the honeypot elements corresponding to each computer node, the corresponding Hfish honeypot is constructed, and several Hfish honeypots are distributedly connected to obtain the initial Hfish honeypot chain network;

[0030] Construct an Hfish honeypot management node, and connect the Hfish honeypot management node to each Hfish honeypot in the initial Hfish honeypot chain network to obtain the intermediate Hfish honeypot chain network;

[0031] A flow probe is set in each Hfish honeypot in the middle Hfish honeypot chain network, and the flow probe is connected to the Hfish honeypot management node to obtain the final Hfish honeypot chain network;

[0032] Use any traffic probe in the final Hfish honeypot chain network to collect the real-time access traffic data of the corresponding Hfish honeypot, and send the real-time access traffic data to the Hfish honeypot management node.

[0033] Furthermore, according to the real-time access traffic data, an abnormal traffic detection model is used to perform abnormal traffic detection to obtain a real-time abnormal traffic detection result, including the following steps:

[0034] The real-time access traffic data is input into the abnormal traffic detection model, and N real-time key dimension features of the real-time access traffic data are extracted using the abnormal traffic detection model;

[0035] According to the preset attention weights, N real-time key dimension features are spliced ​​to obtain real-time spliced ​​features;

[0036] According to the real-time splicing features, abnormal traffic detection is performed to obtain real-time abnormal traffic detection results.

[0037] Furthermore, according to the real-time abnormal traffic detection result, a protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy, including the following steps:

[0038] If the real-time abnormal traffic detection result is that abnormal traffic exists, the corresponding N real-time key dimension features are input into the protection strategy generation model;

[0039] According to the real-time abnormal traffic detection results, the historical protection strategy generation experience is retrieved from the experience playback pool of the protection strategy generation model to obtain several matching historical protection strategy generation experiences;

[0040] Based on several matching historical protection strategy generation experiences, the action space of the protection strategy generation model is updated, and based on N real-time key dimension features, the state space of the protection strategy generation model is updated;

[0041] Based on the updated action space and the updated state space, a protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy.

[0042] Furthermore, according to the real-time protection strategy, a resource scheduling model is used to generate a resource scheduling plan to obtain a real-time resource scheduling plan, including the following steps:

[0043] Use the resource scheduling model to analyze the real-time protection strategy and obtain the corresponding real-time resource demand information, real-time action priority, and real-time impact range;

[0044] Define the objective function of the resource scheduling model based on real-time resource demand information, real-time action priority, and real-time impact range;

[0045] Based on the objective function, a resource scheduling plan is generated to obtain a real-time resource scheduling plan including a real-time protection strategy and a real-time resource allocation strategy.

[0046] Furthermore, based on the objective function, a resource scheduling scheme is generated to obtain a real-time resource scheduling scheme including a real-time protection strategy and a real-time resource allocation strategy, including the following steps:

[0047] Encoding the resource scheduling solution generation problem to obtain an encoding vector including a protection strategy indicator and a resource allocation strategy indicator;

[0048] The encoding vector is used as the ICPO individual of the ICPO optimization algorithm, several initial solutions of the ICPO optimization algorithm are generated, and the objective function is used as the fitness function of the ICPO optimization algorithm;

[0049] According to several initial solutions and fitness functions, ICPO optimization algorithm is used to perform iterative optimization and retain the best individual;

[0050] If the number of iterations of iterative optimization reaches the maximum number of iterations or the fitness value of the optimal individual meets the requirements, the optimal solution corresponding to the optimal individual is output;

[0051] The optimal solution is decoded to obtain a real-time resource scheduling solution including a real-time protection strategy and a real-time resource allocation strategy.

[0052] Further, according to the real-time resource scheduling scheme, resource scheduling is performed in the computer cluster to obtain a computer cluster after resource scheduling, and based on the computer cluster after resource scheduling, a real-time protection strategy is executed, including the following steps:

[0053] According to the real-time resource allocation strategy in the real-time resource scheduling scheme, the protection resources of the computer cluster are allocated to the corresponding protection services to obtain the computer cluster after resource scheduling;

[0054] Based on the resource-scheduled computer cluster, the real-time protection strategy in the real-time resource allocation strategy is executed, and real-time performance indicator data is collected;

[0055] According to the real-time performance indicator data, the real-time resource scheduling plan is adjusted to obtain an adjusted real-time resource scheduling plan, and resource scheduling is continued according to the adjusted real-time resource scheduling plan.

[0056] A computer cluster security protection system is used to implement a computer cluster security protection method. The system includes a model building unit, a flow collection unit, an abnormal flow detection unit, a protection strategy generation unit, a resource scheduling solution generation unit and a security protection unit.

[0057] The beneficial effects of the present invention are:

[0058] The invention discloses a computer cluster security protection method and system. The abnormal flow detection model constructed by using a deep learning algorithm can automatically learn and extract complex features from a large amount of network flow data, improve the detection accuracy and the recognition ability of unknown attacks, can effectively identify new attacks, and reduce the missed and false alarm rates; the protection strategy generation model constructed by using a reinforcement learning algorithm can dynamically generate protection strategies, can adaptively adjust protection measures according to threats and environmental changes detected in real time, and enhance the flexibility and effectiveness of the protection strategies; the resource scheduling model constructed by introducing a swarm intelligence algorithm can perform adaptive resource scheduling, optimize resource allocation, improve resource utilization, and improve system performance under the premise of ensuring safety; the Hfish honeypot chain network is deployed to capture real-time access flow data, avoid attacks directly invading the computer cluster, and ensure the stability and security of the entire cluster; the abnormal flow detection model of deep learning, the protection strategy generation model of reinforcement learning and the resource scheduling model of the swarm intelligence algorithm are combined to form a multi-level and multi-angle security protection system; the entire security protection method emphasizes real-time and dynamic, can detect abnormal flow, generate protection strategies and perform resource scheduling in real time, and ensure the rapid response of the computer cluster when facing threats.

[0059] Other beneficial effects of the present invention will be further described in the specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] Figure 1 It is a flowchart of the computer cluster security protection method in the present invention.

[0061] Figure 2 It is a structural block diagram of the computer cluster security protection system in the present invention. DETAILED DESCRIPTION

[0062] The present invention will be further explained below in conjunction with the accompanying drawings and specific embodiments.

[0063] Embodiment 1:

[0064] like Figure 1 As shown, this embodiment provides a computer cluster security protection method, including the following steps:

[0065] S1: Construct an abnormal traffic detection model, a protection strategy generation model, and a resource scheduling model in a computer cluster, including the following steps:

[0066] S1-1: Based on any computer node in the computer cluster, a number of historical access flow data are collected, and the number of historical access flow data are preprocessed to obtain a number of preprocessed historical access flow data;

[0067] Preprocessing includes data cleaning, data screening and standardization in sequence, removing erroneous data and duplicate data and unifying the format to improve data quality and provide data support for subsequent model training;

[0068] S1-2: Based on some pre-processed historical access traffic data, use the N-Generative Adversarial Networks (GAN)-Attention-Long Short-Term Memory (LSTM) algorithm to build an abnormal traffic detection model and generate some historical abnormal traffic detection results and some corresponding historical key dimension features;

[0069] The abnormal traffic detection model includes N key dimension feature extraction modules based on the GAN network, an attention weight generation module based on the Attention mechanism, and an abnormal traffic detection module based on the LSTM network. N is the total number of key dimensions, including network traffic pattern dimension, abnormal traffic detection score dimension, known attack type and frequency dimension, and system resource usage dimension.

[0070] The key dimension feature extraction module includes a generator and a discriminator. The goal of the generator is to generate sufficiently real data, while the goal of the discriminator is to distinguish between real data and data generated by the generator. In the key dimension feature extraction, GAN can be used to generate data that matches the real data features to achieve feature extraction of key dimensions. The attention weight generation module uses the preset attention weights to achieve splicing of key dimension features and integrate scattered features. The LSTM network is a special recurrent neural network. The special cell state design makes it perform well in processing and predicting time series data. It can capture long-term dependencies and is suitable for data with time correlation. It is used to predict spliced ​​data features.

[0071] S1-3: Based on several historical abnormal traffic detection results and several corresponding historical key dimension features, a protection strategy generation model is constructed using a deep Q network (DQN), several historical protection strategies and several historical protection strategy generation experiences are generated, and several historical protection strategy generation experiences are stored in the experience playback pool of the protection strategy generation model, including the following steps:

[0072] S1-3-1: Use the protection strategy to generate problems as the simulation environment of the DQN algorithm, and build the intelligent agent and experience replay pool;

[0073] S1-3-2: Define the state space of the DQN algorithm according to each attack state type corresponding to the historical key dimension characteristics, and the parameters of the state space correspond to each attack state;

[0074] S1-3-3: Define the action space of the DQN algorithm according to the actions that the protection strategy needs to output; the action space includes no action (maintaining the current strategy), modifying firewall rules, enabling / disabling certain services, reconfiguring network resources, and sending alarms or notifying administrators, etc.

[0075] S1-3-4: Based on the possible impact of each action in the action space, define the reward function of the DQN algorithm to evaluate the quality or impact of the action;

[0076] S1-3-5: Construct the input layer, several hidden layers, and output layer of the deep Q network, connect the input layer to the state space, and connect the output layer to the action space;

[0077] S1-3-6: Based on the state space, action space and reward function, according to several historical abnormal traffic detection results and corresponding several historical key dimension features, the deep Q network and intelligent agent are optimized and trained to build a protection strategy generation model, and several historical protection strategy generation experiences are generated;

[0078] S1-3-7: storing several historical protection strategy generation experiences into the experience playback pool of the protection strategy generation model;

[0079] S1-4: Based on several historical protection strategies, a resource scheduling model is constructed using the Bi-directional Long Short-Term Memory (BiLSTM)-Improved Crested Porcupine Optimizer (ICPO) algorithm;

[0080] The resource scheduling model includes a protection strategy analysis module based on the BiLSTM network and a resource scheduling solution generation module based on the ICPO optimization algorithm;

[0081] The protection strategy analysis module uses the deep structure of the BiLSTM network to explore the potential connection between the protection strategy and the resource demand situation, analyze the protection strategy, and predict the corresponding resource demand information, action priority, and impact range. The resource scheduling plan generation module optimizes in the search space based on the objective function constructed based on resource demand information, action priority, and impact range, ensuring the efficient use of network cluster resources and the maximization of protection effects as the optimization goals, ensuring that the implementation of the protection plan is both efficient and adaptable.

[0082] S1-5: deploy the abnormal traffic detection model, the protection strategy generation model, and the resource scheduling model as corresponding abnormal traffic detection services, protection strategy generation services, and resource scheduling model services;

[0083] S1-6: Provide corresponding abnormal traffic detection service application programming (Application Programming Interface,) API interface, protection strategy generation service API interface and resource scheduling model service API interface for abnormal traffic detection service, protection strategy generation service and resource scheduling model service;

[0084] S1-7: publish the abnormal traffic detection service API interface, the protection strategy generation service API interface and the resource scheduling model service API interface to the computer cluster;

[0085] The model is deployed as a service on a specific node and is called by other nodes through an API interface or other service interface. Then other nodes in the cluster can use the model, but the model is not run directly on each node, which reduces the hardware configuration requirements of the computer node and ensures that each computer node can use these models;

[0086] S2: Deploy the Hfish honeypot chain network in the computer cluster and use the Hfish honeypot chain network to capture real-time access traffic data, including the following steps:

[0087] S2-1: Download the Hfish warehouse to each computer node in the computer cluster, collect the operating system information of each computer node, and generate the corresponding honeypot elements according to the operating system information;

[0088] S2-2: According to the honeypot elements corresponding to each computer node, the corresponding Hfish honeypot is constructed, and several Hfish honeypots are distributedly connected to obtain the initial Hfish honeypot chain network;

[0089] S2-3: construct an Hfish honeypot management node, and connect the Hfish honeypot management node to each Hfish honeypot in the initial Hfish honeypot chain network to obtain the intermediate Hfish honeypot chain network;

[0090] S2-4: Set a flow probe in each Hfish honeypot in the middle Hfish honeypot chain network, and connect the flow probe to the Hfish honeypot management node to obtain the final Hfish honeypot chain network;

[0091] S2-5: Use any traffic probe in the final Hfish honeypot chain network to collect the real-time access traffic data of the corresponding Hfish honeypot, and send the real-time access traffic data to the Hfish honeypot management node;

[0092] By using the Hfish honeypot chain network to attract attacks and capture the traffic data generated by the attacks, the protection level and security are improved;

[0093] S3: Based on the real-time access traffic data, use the abnormal traffic detection model to perform abnormal traffic detection and obtain real-time abnormal traffic detection results, including the following steps:

[0094] S3-1: input the real-time access traffic data into the abnormal traffic detection model, and use the key dimension feature extraction module of the abnormal traffic detection model to extract N real-time key dimension features of the real-time access traffic data;

[0095] S3-2: splicing N real-time key dimension features according to the preset attention weight of the attention weight generation module to obtain a real-time splicing feature;

[0096] S3-3: Use the abnormal traffic detection module to perform abnormal traffic detection according to the real-time splicing features to obtain real-time abnormal traffic detection results;

[0097] S4: Based on the real-time abnormal traffic detection result, a protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy, including the following steps:

[0098] S4-1: If the real-time abnormal traffic detection result is that abnormal traffic exists, the corresponding N real-time key dimension features are input into the protection strategy generation model;

[0099] S4-2: According to the real-time abnormal traffic detection results, historical protection strategy generation experience is retrieved from the experience playback pool of the protection strategy generation model to obtain several matching historical protection strategy generation experiences;

[0100] S4-3: Based on some matching historical protection strategy generation experience, update the action space A'=[a' 1 ,...,a' j" ,...,a' I ], based on the N real-time key dimension features, update the state space S'=[s' 1 ,...,s' i" ,...,s' I' ], where a' j" is the updated j-th action value, j is the action indicator, I is the total number of action space dimensions, s' i" is the updated i'th state value, i' is the state indicator, and I' is the total number of state space dimensions;

[0101] S4-4: Based on the updated action space and the updated state space, a protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy, including the following steps:

[0102] S4-4-1: Update the state space S' = [s' 1 ,...,s' i' ,...,s' I ] as the input of the protection strategy generation model, using the deep Q network to generate an updated action space A' = [a' 1 ,...,a' j' ,...,a' I ] is the Q value of each possible action;

[0103] S4-4-2: Use the reward function to obtain the reward value of each possible action in the updated action space, and update the Q value of the possible action according to the reward value to obtain the updated Q value of the possible action;

[0104] The formula is:

[0105] Q(s' p' ,a' p')=(1-α")·Q(s p' ,a p' )+α"·(R(s p' ,a p' ,s' p' )+γ·Q max (s p' ,a p' ))

[0106] In the formula, Q(s' p' ,a' p' ) is the updated state value s' p' and the updated action value a' p' The corresponding updated Q value; Q(s p' ,a p' ) is the state value s p' and action value a p' The corresponding predicted Q value; α" is the learning rate; Q max (s p' ,a p' ) is the highest predicted Q value; p' is the comprehensive indicator; γ is the update parameter;

[0107] S4-4-3: Repeat the above steps until the iteration number threshold is reached, use the greedy strategy, take the possible action corresponding to the highest updated Q value as the execution action, and output the execution action as the real-time protection strategy;

[0108] S5: According to the real-time protection strategy, a resource scheduling plan is generated using a resource scheduling model to obtain a real-time resource scheduling plan, including the following steps:

[0109] S5-1: Use the resource scheduling model to analyze the real-time protection strategy and obtain the corresponding real-time resource demand information, real-time action priority and real-time impact range;

[0110] Mapping the strategies output by the real-time protection strategy to actual resource requirements, including converting actions (such as adjusting firewall rules, enabling / disabling services) into specific resource consumption (such as CPU usage, memory requirements, bandwidth consumption, etc.), analyzing the importance of different operations according to the real-time protection strategy, and implementing this by analyzing the frequency characteristics of different operations in the strategy. The higher the frequency, the higher the priority may be. Analyzing the impact of each operation on the overall security of the network cluster, and implementing this by evaluating the characteristics of the operation on network service availability, data integrity, user privacy, etc., thereby providing a basis for subsequent resource scheduling implementation. In this application, predictions are made based on the potential relationship between the characteristics of the real-time protection strategy and resource requirements, action priority, and impact range, thereby improving analysis efficiency and accuracy;

[0111] S5-2: Define the objective function of the resource scheduling model based on real-time resource demand information, real-time action priority, and real-time impact range;

[0112]

[0113] Where F is the objective function of the resource scheduling model; R i is the demand for resource i; P a is the priority of executing action a; C i is the action cost of resource i; I a is the impact range of action a; i is the resource indicator; a is the action indicator; n is the total number of resources; m is the total number of actions; resources include server resources, bandwidth resources and storage resources; W R , W p , W c are resource requirement weight, action priority weight, and action cost weight;

[0114] S5-3: Based on the objective function, a resource scheduling scheme is generated to obtain a real-time resource scheduling scheme including a real-time protection strategy and a real-time resource allocation strategy, including the following steps:

[0115] S5-3-1: Encode the resource scheduling solution generation problem to obtain a coding vector including a protection strategy indicator and a resource allocation strategy indicator;

[0116] S5-3-2: Use the encoding vector as the ICPO individual of the ICPO optimization algorithm, initialize it using the Circle chaotic mapping sequence, generate several initial solutions of the ICPO optimization algorithm, and use the objective function as the fitness function of the ICPO optimization algorithm;

[0117] The formula is:

[0118]

[0119] In the formula, It is the initial ICPO individual of Circle chaos mapping; is the randomly generated initial ICPO individual; i' is the ICPO individual indicator;

[0120] S5-3-3: Based on several initial solutions and fitness functions, use the ICPO optimization algorithm to perform iterative optimization and retain the best individual, including the following steps:

[0121] S5-3-3-1: Set ICPO population parameters and maximum number of iterations of ICPO optimization algorithm;

[0122] S5-3-3-2: Introduce a cyclic population reduction mechanism to limit the number of individuals in the ICPO population parameters and obtain updated ICPO population parameters for the next iteration;

[0123] The formula is:

[0124]

[0125] In the formula, S t+1 is the number of individuals in the ICPO population parameter of the t+1th iteration; S t is the number of individuals in the ICPO population parameter of the tth iteration; S min is the minimum number of individuals in the ICPO population parameter; a' is the function evaluation parameter; V is the function evaluation cycle parameter; V max is the maximum function evaluation loop parameter; t is the number of iterations indicator;

[0126] S5-3-3-3: Calculate the initial fitness value of the initial ICPO individuals in the initial ICPO population according to the fitness function;

[0127] S5-3-3-4: According to the initial fitness value and the updated ICPO population parameters, the first defense strategy, the second defense strategy, the third defense strategy and the fourth defense strategy are used to update the initial ICPO population to obtain an updated ICPO population;

[0128] The formula for the first defense strategy is:

[0129]

[0130] In the formula, For the updated ICPO individuals within the first defense range; is the initial ICPO individual within the first defense range; τ 1 is a random number based on normal distribution; τ 2 is a random value in the interval [0,1]; It is the optimal solution within the first defense range; is the vector generated between the true optimal solution within the first defense range and the optimal solution randomly selected from the ICPO population; i' is the ICPO individual indicator; t is the iteration indicator;

[0131] The formula for the second defense strategy is:

[0132]

[0133] In the formula, For the updated ICPO individuals within the second defense range; The initial ICPO individual within the second defense range; is the search upper limit vector of the second defense range; τ 3 is a random value in the interval [0,1]; are the r1th and r2th initial ICPO individuals respectively; r1 and r2 are two random integers between [1, S]; is the vector generated between the true optimal solution within the second defense range and the optimal solution randomly selected from the ICPO population;

[0134] The formula for the third defense strategy is:

[0135]

[0136] In the formula, For the updated ICPO individuals within the third defense range; The initial ICPO individual within the third defense range; is the search upper limit vector of the third defense range; are the r2th and r3th initial ICPO individuals respectively; r3 is a random integer between [1, S]; The odor diffusion factor defined for the fitness function; λ t It is a defense factor; Control parameters for search direction;

[0137] The formula for the fourth defense strategy is:

[0138]

[0139] In the formula, For the updated ICPO individuals within the fourth defense range; The initial ICPO individual within the fourth defense range; is the optimal solution within the fourth defense range; τ 4 , τ 5 are all random values ​​in the interval [0,1]; t It is a defense factor; Control parameters for search direction; is the average force affecting the search direction; a' is the convergence speed factor;

[0140] S5-3-3-5: Use the dynamic reverse learning algorithm to perform dynamic reverse learning on the updated ICPO population to generate a dynamic reverse ICPO population;

[0141] The formula is:

[0142]

[0143] In the formula, is the ICPO individual in dynamic reverse direction; γ' is the decreasing inertia coefficient; L max , L min are the maximum and minimum values ​​of the vector space respectively; For the updated ICPO individual;

[0144] S5-3-3-6: According to the fitness function, calculate the fitness values ​​of all ICPO individuals in the updated ICPO population and the dynamically reversed ICPO population, take the ICPO individual with the minimum fitness value as the optimal individual, and retain the optimal individual;

[0145] S5-3-4: If the number of iterations of iterative optimization reaches the maximum number of iterations or the fitness value of the optimal individual meets the requirements, the optimal solution corresponding to the optimal individual is output;

[0146] S5-3-5: Decode the optimal solution to obtain a real-time resource scheduling solution including a real-time protection strategy and a real-time resource allocation strategy;

[0147] S6: According to the real-time resource scheduling scheme, resources are scheduled in the computer cluster to obtain a computer cluster after resource scheduling, and a real-time protection strategy is executed based on the computer cluster after resource scheduling, including the following steps:

[0148] S6-1: Allocate the protection resources of the computer cluster to the corresponding protection services according to the real-time resource allocation strategy in the real-time resource scheduling scheme, and obtain the computer cluster after resource scheduling;

[0149] S6-2: Based on the resource-scheduled computer cluster, the real-time protection strategy in the real-time resource allocation strategy is executed, and real-time performance indicator data is collected;

[0150] S6-3: Adjust the real-time resource scheduling plan according to the real-time performance indicator data to obtain an adjusted real-time resource scheduling plan, and continue resource scheduling according to the adjusted real-time resource scheduling plan.

[0151] Embodiment 2:

[0152] like Figure 2 As shown, this embodiment provides a computer cluster security protection system for implementing a computer cluster security protection method, the system includes a model building unit, a traffic collection unit, an abnormal traffic detection unit, a protection strategy generation unit, a resource scheduling solution generation unit and a security protection unit;

[0153] A model building unit, used to build an abnormal traffic detection model, a protection strategy generation model and a resource scheduling model in a computer cluster;

[0154] Traffic collection unit, used to deploy Hfish honeypot chain network in computer clusters and use Hfish honeypot chain network to capture real-time access traffic data;

[0155] The abnormal traffic detection unit is used to perform abnormal traffic detection based on the real-time access traffic data and use the abnormal traffic detection model to obtain a real-time abnormal traffic detection result;

[0156] A protection strategy generation unit, used to generate a protection strategy based on the real-time abnormal traffic detection result using a protection strategy generation model to obtain a real-time protection strategy;

[0157] A resource scheduling scheme generating unit is used to generate a resource scheduling scheme according to a real-time protection strategy and using a resource scheduling model to obtain a real-time resource scheduling scheme;

[0158] The security protection unit is used to perform resource scheduling in a computer cluster according to a real-time resource scheduling scheme, obtain a computer cluster after resource scheduling, and execute a real-time protection strategy based on the computer cluster after resource scheduling.

[0159] The invention discloses a computer cluster security protection method and system. The abnormal flow detection model constructed by using a deep learning algorithm can automatically learn and extract complex features from a large amount of network flow data, improve the detection accuracy and the recognition ability of unknown attacks, can effectively identify new attacks, and reduce the missed and false alarm rates; the protection strategy generation model constructed by using a reinforcement learning algorithm can dynamically generate protection strategies, can adaptively adjust protection measures according to threats and environmental changes detected in real time, and enhance the flexibility and effectiveness of the protection strategies; the resource scheduling model constructed by introducing a swarm intelligence algorithm can perform adaptive resource scheduling, optimize resource allocation, improve resource utilization, and improve system performance under the premise of ensuring safety; the Hfish honeypot chain network is deployed to capture real-time access flow data, avoid attacks directly invading the computer cluster, and ensure the stability and security of the entire cluster; the abnormal flow detection model of deep learning, the protection strategy generation model of reinforcement learning and the resource scheduling model of the swarm intelligence algorithm are combined to form a multi-level and multi-angle security protection system; the entire security protection method emphasizes real-time and dynamic, can detect abnormal flow, generate protection strategies and perform resource scheduling in real time, and ensure the rapid response of the computer cluster when facing threats.

[0160] The present invention is not limited to the above optional implementations, and anyone can derive other various forms of products under the enlightenment of the present invention. The above specific implementations should not be understood as limiting the scope of protection of the present invention. The scope of protection of the present invention should be based on the definition in the claims, and the description can be used to interpret the claims.

Claims

1. A computer cluster security protection method, characterized in that: The steps include: Constructing an abnormal traffic detection model, a protection strategy generation model, and a resource scheduling model in a computer cluster includes the following steps: Based on any computer node in the computer cluster, a number of historical access flow data are collected, and the number of historical access flow data are preprocessed to obtain a number of preprocessed historical access flow data; Based on some pre-processed historical access traffic data, a deep learning algorithm is used to build an abnormal traffic detection model, and several historical abnormal traffic detection results and corresponding historical key dimension features are generated; The abnormal traffic detection model is built based on the N-GAN-Attention-LSTM algorithm; Based on several historical abnormal traffic detection results and several corresponding historical key dimension features, a reinforcement learning algorithm is used to build a protection strategy generation model, generate several historical protection strategies and several historical protection strategy generation experiences, and store several historical protection strategy generation experiences in the experience playback pool of the protection strategy generation model; The protection strategy generation model is constructed based on the DQN algorithm; Based on several historical protection strategies, a fusion algorithm is used to build a resource scheduling model; The resource scheduling model is constructed based on the BiLSTM-ICPO algorithm; Deploy the abnormal traffic detection model, protection strategy generation model and resource scheduling model as corresponding abnormal traffic detection service, protection strategy generation service and resource scheduling model service; Provide corresponding abnormal traffic detection service API interface, protection strategy generation service API interface and resource scheduling model service API interface for abnormal traffic detection service, protection strategy generation service and resource scheduling model service; Publishing the abnormal traffic detection service API interface, the protection strategy generation service API interface, and the resource scheduling model service API interface to the computer cluster; Deploy the Hfish honeypot chain network in a computer cluster and use the Hfish honeypot chain network to capture real-time access traffic data, including the following steps: Download the Hfish warehouse to each computer node in the computer cluster, collect the operating system information of each computer node, and generate the corresponding honeypot elements based on the operating system information; According to the honeypot elements corresponding to each computer node, the corresponding Hfish honeypot is constructed, and several Hfish honeypots are distributedly connected to obtain the initial Hfish honeypot chain network; Construct an Hfish honeypot management node, and connect the Hfish honeypot management node to each Hfish honeypot in the initial Hfish honeypot chain network to obtain the intermediate Hfish honeypot chain network; A flow probe is set in each Hfish honeypot in the middle Hfish honeypot chain network, and the flow probe is connected to the Hfish honeypot management node to obtain the final Hfish honeypot chain network; Use any traffic probe in the final Hfish honeypot chain network to collect the real-time access traffic data of the corresponding Hfish honeypot, and send the real-time access traffic data to the Hfish honeypot management node; According to the real-time access traffic data, an abnormal traffic detection model is used to perform abnormal traffic detection to obtain real-time abnormal traffic detection results; According to the real-time abnormal traffic detection results, a protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy; According to the real-time protection strategy, the resource scheduling model is used to generate a resource scheduling plan to obtain a real-time resource scheduling plan; According to the real-time resource scheduling scheme, resource scheduling is performed in the computer cluster to obtain a computer cluster after resource scheduling, and a real-time protection strategy is executed based on the computer cluster after resource scheduling.

2. A computer cluster security protection method according to claim 1, characterized in that: According to the real-time access traffic data, an abnormal traffic detection model is used to perform abnormal traffic detection to obtain a real-time abnormal traffic detection result, including the following steps: The real-time access traffic data is input into the abnormal traffic detection model, and N real-time key dimension features of the real-time access traffic data are extracted using the abnormal traffic detection model; According to the preset attention weights, N real-time key dimension features are spliced ​​to obtain real-time spliced ​​features; According to the real-time splicing features, abnormal traffic detection is performed to obtain real-time abnormal traffic detection results.

3. A computer cluster security protection method according to claim 2, characterized in that: According to the real-time abnormal traffic detection results, the protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy, including the following steps: If the real-time abnormal traffic detection result is that abnormal traffic exists, the corresponding N real-time key dimension features are input into the protection strategy generation model; According to the real-time abnormal traffic detection results, the historical protection strategy generation experience is retrieved from the experience playback pool of the protection strategy generation model to obtain several matching historical protection strategy generation experiences; Based on several matching historical protection strategy generation experiences, the action space of the protection strategy generation model is updated, and based on N real-time key dimension features, the state space of the protection strategy generation model is updated; Based on the updated action space and the updated state space, a protection strategy generation model is used to generate a protection strategy to obtain a real-time protection strategy.

4. A computer cluster security protection method according to claim 1, characterized in that: According to the real-time protection strategy, the resource scheduling model is used to generate a resource scheduling plan to obtain a real-time resource scheduling plan, including the following steps: Use the resource scheduling model to analyze the real-time protection strategy and obtain the corresponding real-time resource demand information, real-time action priority, and real-time impact range; Define the objective function of the resource scheduling model based on real-time resource demand information, real-time action priority, and real-time impact range; Based on the objective function, a resource scheduling plan is generated to obtain a real-time resource scheduling plan including a real-time protection strategy and a real-time resource allocation strategy.

5. A computer cluster security protection method according to claim 4, characterized in that: Based on the objective function, a resource scheduling scheme is generated to obtain a real-time resource scheduling scheme including a real-time protection strategy and a real-time resource allocation strategy, including the following steps: Encoding the resource scheduling solution generation problem to obtain an encoding vector including a protection strategy indicator and a resource allocation strategy indicator; The encoding vector is used as the ICPO individual of the ICPO optimization algorithm, several initial solutions of the ICPO optimization algorithm are generated, and the objective function is used as the fitness function of the ICPO optimization algorithm; According to several initial solutions and fitness functions, ICPO optimization algorithm is used to perform iterative optimization and retain the best individual; If the number of iterations of iterative optimization reaches the maximum number of iterations or the fitness value of the optimal individual meets the requirements, the optimal solution corresponding to the optimal individual is output; The optimal solution is decoded to obtain a real-time resource scheduling solution including a real-time protection strategy and a real-time resource allocation strategy.

6. A computer cluster security protection method according to claim 5, characterized in that: According to the real-time resource scheduling scheme, resources are scheduled in the computer cluster to obtain a computer cluster after resource scheduling, and based on the computer cluster after resource scheduling, a real-time protection strategy is executed, including the following steps: According to the real-time resource allocation strategy in the real-time resource scheduling scheme, the protection resources of the computer cluster are allocated to the corresponding protection services to obtain the computer cluster after resource scheduling; Based on the resource-scheduled computer cluster, the real-time protection strategy in the real-time resource allocation strategy is executed, and real-time performance indicator data is collected; According to the real-time performance indicator data, the real-time resource scheduling plan is adjusted to obtain an adjusted real-time resource scheduling plan, and resource scheduling is continued according to the adjusted real-time resource scheduling plan.

7. A computer cluster security protection system, used to implement the computer cluster security protection method according to any one of claims 1 to 6, characterized in that: The system includes a model building unit, a traffic collection unit, an abnormal traffic detection unit, a protection strategy generation unit, a resource scheduling solution generation unit and a security protection unit; A model building unit, used to build an abnormal traffic detection model, a protection strategy generation model and a resource scheduling model in a computer cluster; Traffic collection unit, used to deploy Hfish honeypot chain network in computer clusters and use Hfish honeypot chain network to capture real-time access traffic data; The abnormal traffic detection unit is used to perform abnormal traffic detection based on the real-time access traffic data and use the abnormal traffic detection model to obtain a real-time abnormal traffic detection result; A protection strategy generation unit, used to generate a protection strategy based on the real-time abnormal traffic detection result using a protection strategy generation model to obtain a real-time protection strategy; A resource scheduling scheme generating unit is used to generate a resource scheduling scheme according to a real-time protection strategy and using a resource scheduling model to obtain a real-time resource scheduling scheme; The security protection unit is used to perform resource scheduling in a computer cluster according to a real-time resource scheduling scheme, obtain a computer cluster after resource scheduling, and execute a real-time protection strategy based on the computer cluster after resource scheduling.

Citation Information

Patent Citations

  • Deception defense method and device based on reinforcement learning high attack and defense interaction in multi-honeypot scene

    CN117938473A