Method, device, equipment, medium and product for scheduling computing power resources

By acquiring alarm information of computing resources, determining their security status, and formulating response strategies, the problem of insufficient security in computing resource scheduling is solved, and more secure computing resource scheduling is achieved.

CN119299397BActive Publication Date: 2026-01-20CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411352234.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-01-20
Estimated Expiration
2044-09-26

AI Technical Summary

Technical Problem

Computing resources may have high-risk vulnerabilities or be attacked, and the existing scheduling mechanism is not perfect in terms of security, which leads to risks in computing tasks.

Method used

By acquiring alarm information of the target computing resources, we can determine the node security status information, and based on this information, determine the response strategy and scheduling priority to prevent low-security computing resources from being used.

Benefits of technology

This ensures the security of computing power scheduling, avoids security risks such as data tampering, leakage, and service unavailability, and improves the security of computing tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119299397B_ABST
    Figure CN119299397B_ABST
Patent Text Reader

Abstract

The present disclosure relates to the technical field of network security, and particularly provides a computing power resource scheduling method and device, equipment, medium and product, wherein the method comprises: obtaining alarm information of a target computing power resource; wherein the alarm information is used to indicate node security state information of a node of the target computing power resource; determining a response strategy of the target computing power resource based on the alarm information; wherein the response strategy is used to indicate a scheduling mode of the target computing power resource; and scheduling the computing power resource of the target computing power resource based on the response strategy.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of network security, and in particular to a computing power resource scheduling method and device, equipment, medium and product. BACKGROUND

[0002] Computing power network is a new network architecture that deeply integrates computing and network. Computing power network can uniformly schedule and manage dispersed and heterogeneous computing power resources, and realize dynamic allocation and efficient utilization of computing power.

[0003] In related technologies, the computing power network collects node information of nodes to which the computing power resources belong through a network control plane, and allocates computing power resources for computing tasks by a distributed routing node or a central controller, thereby realizing computing optimization. However, the computing power resources may have high-risk vulnerabilities, be under attack or be extremely likely to be attacked, and be in a "dangerous" state. Therefore, the current computing power resource scheduling mechanism is not perfect in terms of security consideration. This may cause the computing task to be executed by the computing power resource with risks, thereby making the computing task dangerous. SUMMARY

[0004] The present disclosure is proposed in view of the above problems. The present disclosure provides a computing power resource scheduling method, device, equipment, medium and product.

[0005] According to one aspect of the present disclosure, a computing power resource scheduling method is provided, the method comprising:

[0006] obtaining alarm information of a target computing power resource; wherein the alarm information is used to indicate node security state information of a node to which the target computing power resource belongs;

[0007] determining a response strategy of the target computing power resource based on the alarm information; wherein the response strategy is used to indicate a scheduling mode of the target computing power resource;

[0008] scheduling the target computing power resource based on the response strategy.

[0009] In addition, according to another embodiment of one aspect of the present disclosure, the determining of the response strategy of the target computing power resource based on the alarm information comprises:

[0010] determining a response level of the target computing power resource based on the alarm information; wherein the response level is used to indicate a danger degree of the target computing power resource;

[0011] determining a scheduling priority of the computing power resource to which the target computing power resource belongs based on the response level, and determining the response strategy of the target computing power resource according to the scheduling priority.

[0012] Further, in another embodiment according to one aspect of the present disclosure, the determining the response level of the target computing resource based on the alarm information comprises:

[0013] determining an alarm type and an alarm degree of the alarm information in a case where the alarm information satisfies a preset security condition;

[0014] determining the response level of the target computing resource based on the alarm type and the alarm degree.

[0015] Further, in another embodiment according to one aspect of the present disclosure, the determining the response level of the target computing resource based on the alarm information comprises:

[0016] determining an alarm type of the alarm information in a case where the alarm information does not satisfy a preset security condition;

[0017] determining the response level of the target computing resource based on the alarm type.

[0018] Further, in another embodiment according to one aspect of the present disclosure, the determining the scheduling priority of the computing resource to which the target computing resource belongs based on the response level comprises:

[0019] adding the target computing resource to a first computing resource list in a case where the response level of the target computing resource is a first response level;

[0020] adding the target computing resource to a second computing resource list in a case where the response level of the target computing resource is a second response level; wherein the danger degree corresponding to the second response level is greater than the danger degree corresponding to the first response level, and the calling priority of the computing resource in the first computing resource list is higher than the calling priority of the computing resource in the second computing resource list.

[0021] Further, in another embodiment according to one aspect of the present disclosure, after the target computing resource is added to the first computing resource list, the method further comprises:

[0022] determining the response level of the target computing resource in a target time period;

[0023] deleting the target computing resource in the first computing resource list in a case where the response level of the target computing resource in the target time period does not reach the first response level.

[0024] Further, in another embodiment according to one aspect of the present disclosure, the obtaining the alarm information of the target computing resource comprises:

[0025] An alarm rule of the target computing resource is determined, wherein the alarm rule carries attribute values of at least one key attribute;

[0026] The alarm rule is sent to a target node.

[0027] The alarm information sent by the target node after matching the alarm rule is obtained.

[0028] In addition, in another embodiment according to one aspect of the present disclosure, the scheduling of the computing resource of the target computing resource based on the response strategy and the target computing resource comprises:

[0029] The response strategy is sent to a path decision node, so that the path decision node schedules the computing resource of the target computing resource based on the response strategy.

[0030] According to another aspect of the present disclosure, a method for scheduling a computing resource is provided, the method comprising:

[0031] A response strategy sent by a security index agent node is obtained, wherein the response strategy is determined by the security index agent node according to any one of the above methods.

[0032] The computing resource of the target computing resource is scheduled based on the response strategy.

[0033] According to another aspect of the present disclosure, a device for scheduling a computing resource is provided, comprising a security index agent node and a path decision node.

[0034] The security index agent node obtains alarm information of a target computing resource, wherein the alarm information is used to indicate node security state information of a node to which the target computing resource belongs; based on the alarm information, a response strategy of the target computing resource is determined, wherein the response strategy is used to indicate a scheduling mode of the target computing resource; and the computing resource of the target computing resource is scheduled based on the response strategy.

[0035] The path decision node is configured to receive the response strategy and schedule the computing resource of the target computing resource based on the response strategy.

[0036] According to still another aspect of the present disclosure, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement steps of a method for determining a log template.

[0037] According to still another aspect of the present disclosure, there is provided a computer readable storage medium having stored thereon computer programs / instructions which, when executed by a processor, implement the steps of a method of determining a log template.

[0038] According to still another aspect of the present disclosure, there is provided a computer program product comprising computer programs / instructions which, when executed by a processor, implement the steps of a method of determining a log template.

[0039] As will be described in detail below, according to an embodiment of the present disclosure, a method and apparatus for scheduling computing power resources, a device, a medium and a product are provided. In the embodiment of the present disclosure, by obtaining alarm information of a target computing power resource, node security state information of a node to which the target computing power resource belongs can be determined, so that the security of the target computing power resource can be determined. Therefore, based on the scheduling mode of the target computing power resource determined based on the alarm information, the security of the computing power scheduling can be ensured, and the computing power resources with low security are avoided from being called, thereby alleviating the security risk problems such as data tampering, leakage, and service unavailability of the computing task caused by the poor security of the computing power scheduling in the prior art.

[0040] It is to be understood that both the foregoing general description and the following detailed description are exemplary, and are intended to provide further explanation of the subject technology. BRIEF DESCRIPTION OF DRAWINGS

[0041] The foregoing and other objects, features and advantages of the present disclosure will become more apparent from the following detailed description, which proceeds with reference to the accompanying drawings. The drawings are provided to illustrate embodiments of the present disclosure and, together with the detailed description, serve to explain the present disclosure and do not constitute a limitation thereof. In the drawings, like reference numerals refer to like elements or steps throughout.

[0042] Figure 1 A flowchart of a method for scheduling computing power resources according to an embodiment of the present disclosure.

[0043] Figure 2 A schematic diagram of a device for scheduling computing power resources according to an embodiment of the present disclosure.

[0044] Figure 3 A schematic diagram of a scheduling architecture for computing power resources according to an embodiment of the present disclosure.

[0045] Figure 4 A schematic diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION

[0046] In order to make the objectives, technical solutions and advantages of the present disclosure more obvious, the following will describe the example embodiments according to the present disclosure in detail with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, and not all the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited to the example embodiments described herein.

[0047] It should be noted that similar reference numerals and letters refer to similar items in the following drawings, and therefore, once an item is defined in one drawing, it need not be further defined and explained in subsequent drawings.

[0048] The term "and / or" herein only describes an association relationship, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the term "at least one" herein means any one of a plurality or any combination of at least two of a plurality, for example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.

[0049] It is found through research that the computing power network is a new network architecture that deeply integrates computing and network. The computing power network can uniformly schedule and manage dispersed and heterogeneous computing power resources, and realize dynamic allocation and efficient utilization of computing power.

[0050] In the related art, by obtaining alarm information of a target computing power resource, node security state information of a node to which the target computing power resource belongs can be determined, so that the security of the target computing power resource can be determined. Therefore, based on the scheduling mode of the target computing power resource determined based on the alarm information, the security of the computing power scheduling can be ensured, and the computing power resources with low security are avoided from being called, thereby relieving the security risk problems such as data tampering, leakage, and service unavailability of the computing task caused by the poor security of the computing power scheduling in the prior art.

[0051] Based on the above research, the present disclosure provides a scheduling method of computing power resources. By obtaining alarm information of a target computing power resource, node security state information of a node to which the target computing power resource belongs can be determined, so that the security of the target computing power resource can be determined. Therefore, based on the scheduling mode of the target computing power resource determined based on the alarm information, the security of the computing power scheduling can be ensured, and the computing power resources with low security are avoided from being called, thereby relieving the security risk problems such as data tampering, leakage, and service unavailability of the computing task caused by the poor security of the computing power scheduling in the prior art.

[0052] To facilitate the understanding of the present embodiment, first, a kind of computing power resource scheduling method disclosed in the present embodiment is introduced in detail, the execution subject of the computing power resource scheduling method provided by the present embodiment is generally electronic equipment with certain computing power.In some possible implementation ways, the computing power resource scheduling method can be realized by the way that processor calls computer readable instructions stored in memory.

[0053] Referring to Figure 1 As shown in the figure, a flowchart of a computing power resource scheduling method provided by the present embodiment, the method comprises steps S101-S103, applied to security index agent node, wherein:

[0054] S101, obtain the alarm information of target computing power resource;Wherein, alarm information is used to indicate the node security state information of target computing force resource node.

[0055] In the embodiment of the present disclosure, the nodes and computing power resources (i.e., service nodes) deployed with security functions (i.e., target nodes) can determine alarm information. Wherein, the alarm information also includes: network security state information of target computing power resource belonging network.

[0056] Here, security functions include network security functions and computing power resource security functions. Wherein, network security functions, that is, security functions in network, can be deployed by computing power service operators or network providers, including but not limited to: scanning and detection type security functions. Computing power resource security functions, that is, security functions in computing power resources, can be deployed and managed by service providers, including but not limited to: various security functions.

[0057] Wherein, network security functions can collect network security state information. Wherein, network security state information includes but is not limited to: leak scanning, baseline scanning, network anomaly behavior detection function.

[0058] Wherein, computing power resource security functions can collect node security state information. Wherein, node security state information includes but is not limited to: anomaly detection, threat attack tracing, antivirus.

[0059] S102, determine the response strategy of target computing power resource based on alarm information;Wherein, response strategy is used to indicate the scheduling mode of target computing power resource.

[0060] In the embodiment of the present disclosure, the alarm information can be comprehensively analyzed by security index agent node (i.e., C-SeMA) to judge the response level of target computing power resource corresponding to alarm information;Then, the response strategy of target computing power resource can be determined based on the response level of target computing power resource.

[0061] Here, the response strategy includes but is not limited to: stopping scheduling processing on the computing power resource to which the target computing power resource belongs, and reducing the scheduling priority of the target computing power resource.

[0062] Among them, the credibility state, alarm type and alarm degree of the alarm information can be determined to comprehensively analyze the alarm information, so as to determine the response level of the alarm information.

[0063] Here, after determining the response strategy, the response strategy can be sent to the path decision node (i.e., C-PS) through the security index agent node.

[0064] S103, scheduling the target computing power resource based on the response strategy and the target computing power resource.

[0065] In an embodiment of the present disclosure, the path decision node can determine the computing power information and network information of the target computing power resource. Then, the target computing power resource can be scheduled based on the computing power information and network information of the target computing power resource and the response strategy.

[0066] Here, the network information includes at least one of the network traffic information and baseline information of the network accessed by the target computing power resource.

[0067] Here, the path decision node can preferably determine the computing power resource and network information required by the to-be-processed computing task. Then, the computing power resource satisfying the computing power resource and network information required by the to-be-processed computing task is determined in the computing power resource library.

[0068] In the case where the determined computing power resource includes the target computing power resource, it is determined whether to use the target computing power resource to process the to-be-processed computing task according to the response strategy of the target computing power resource.

[0069] In an embodiment of the present disclosure, first, the alarm information of the target computing power resource is obtained; wherein the alarm information is used to indicate the node security state information of the node to which the target computing power resource belongs; second, the response strategy of the target computing power resource is determined based on the alarm information; wherein the response strategy is used to indicate the scheduling mode of the target computing power resource; finally, the target computing power resource is scheduled based on the response strategy.

[0070] In the above embodiment, by obtaining the alarm information of the target computing power resource, the node security state information of the node to which the target computing power resource belongs can be determined, so that the security of the target computing power resource can be determined. Therefore, the scheduling mode of the target computing power resource determined based on the alarm information can ensure the security of the computing power scheduling, avoid the low-security computing power resource being called, and thus alleviate the security risk problems such as data tampering, leakage and service unavailability of the computing task caused by the poor security of the computing power scheduling in the prior art.

[0071] In an optional embodiment, the step of determining the response strategy of the target computing resource based on the alarm information comprises the following steps:

[0072] Firstly, the response level of the target computing resource is determined based on the alarm information; wherein, the response level is used to indicate the danger degree of the target computing resource.

[0073] Then, the scheduling priority of the computing resource to which the target computing resource belongs is determined based on the response level, and the response strategy of the target computing resource is determined according to the scheduling priority.

[0074] In the present disclosure, the security index agent node can determine the response level of the target computing resource based on the alarm information of the target computing resource in the target period.

[0075] Here, the security index agent node can define the trust state, type and alarm degree of the corresponding alarm information of different alarm information; then, based on the trust state, type and alarm degree of the corresponding alarm information of the alarm information, the response level of the target computing resource is determined by comprehensive analysis when the alarm information is received.

[0076] Here, different scheduling priorities can be set for different response levels. The disposition strategy (i.e. response strategy) of the target computing resource is different for different scheduling priorities of the target computing resource.

[0077] For example, in the case of the first scheduling priority (i.e. the scheduling priority corresponding to the first response level described below), the other computing resource is preferentially called in the case that there is a computing resource, network and other conditions equivalent to the conditions of the target computing resource. In the case of the second scheduling priority (i.e. the scheduling priority corresponding to the second response level described below), the target computing resource is disabled.

[0078] In an optional embodiment, the step of determining the response level of the target computing resource based on the alarm information comprises the following steps:

[0079] Firstly, the response level of the target computing resource is determined based on the alarm type and alarm degree of the alarm information in the case that the alarm information meets the preset security condition.

[0080] In the present disclosure, the preset security condition is that the alarm information does not carry untrusted attack information. In the case that the alarm information does not carry untrusted information, the alarm type and alarm degree of the alarm information can be determined, and then the response level of the target computing resource is determined according to the alarm type and alarm degree.

[0081] In implementation, first, a trusted state of the alarm information is determined; wherein the trusted state is used to indicate whether the alarm information carries untrusted attack information; then, based on the trusted state and the alarm information, a response level of the target computing resource is determined.

[0082] In embodiments of the present disclosure, the security indicator agent node can define a trusted state judgment rule of the alarm information. Then, based on the alarm information, the trusted state of the alarm information is determined through the trusted state judgment rule.

[0083] For example, the alarm information reported by the node deployed with the security function and the alarm information of the computing resource reported by the computing resource are considered as not carrying the untrusted attack information. The alarm information with the trusted state of not carrying the untrusted attack information can reflect the vulnerability and attack state of the corresponding computing resource.

[0084] The alarm information of other computing resources reported by the computing resource is considered as not carrying the untrusted attack information.

[0085] Here, in the case that the trusted state of the alarm information is considered as not carrying the untrusted attack information (i.e., in the case that the preset security condition is met), the response level of the target computing resource can be determined based on the alarm type and the alarm degree of the alarm information. In the case that the trusted state of the alarm information is considered as not carrying the untrusted attack information, the response level of the target computing resource can be determined based on the alarm type of the alarm information.

[0086] Here, first, in the case that it is determined based on the trusted state that the alarm information does not carry the untrusted attack information, the alarm type of the alarm information and the alarm degree of the alarm information are determined; second, based on the alarm type and the alarm degree, a target alarm score of the target computing resource is determined; finally, based on a first mapping relationship, a response level matched with the target alarm score is determined; wherein the first mapping relationship is used to indicate the association relationship between each alarm score and each response level.

[0087] In embodiments of the present disclosure, the security indicator agent node can set a judgment factor and a first judgment rule for the alarm information not carrying the untrusted attack information. The judgment factor includes but is not limited to the alarm type and the alarm degree of the alarm information.

[0088] Here, the security indicator agent node can set a first determination rule for the alarm degree contained in different alarm types. For example, different alarm degrees contained in the alarm type are set corresponding scores; in the case of the alarm type being a vulnerability, the corresponding alarm degree is a low-risk vulnerability, a medium-risk vulnerability, and a high-risk vulnerability. Among them, the low-risk vulnerability corresponds to 1 point, the medium-risk vulnerability corresponds to 2 points, and the high-risk vulnerability corresponds to 3 points. In the case of the alarm type being a threat attack, the corresponding alarm degree is a low-risk threat attack, a medium-risk threat attack, and a high-risk threat attack. Among them, the low-risk threat attack corresponds to 1 point, the medium-risk threat attack corresponds to 2 points, and the high-risk threat attack corresponds to 3 points.

[0089] Here, in the case that there are multiple alarm information in the first period, the corresponding scores of each alarm information can be determined. Then, based on the corresponding scores of each alarm information and the first mapping relationship, the response level matched with the target alarm score is determined.

[0090] Here, the first determination rule further includes a preset score threshold and a response level corresponding to the preset score threshold. For example, including a first preset score threshold and a second preset score threshold, in the case that the target alarm score is greater than the first preset score threshold and less than the second preset score threshold, the response level is determined to be a first response level; in the case that the target alarm score is greater than the second preset score threshold, the response level is determined to be a second response level.

[0091] Among them, the second preset score threshold is greater than the first preset score threshold, and the danger level of the computing resource corresponding to the second response level is higher than the danger level of the computing resource corresponding to the first response level.

[0092] Here, first, the alarm sub-score of each alarm type for the alarm degree in the first period can be determined; then, based on the alarm sub-score corresponding to all alarm types, the target alarm score can be determined.

[0093] In an embodiment of the present disclosure, the corresponding alarm information in the first period can be multiple, and the alarm type corresponding to each alarm information can not be the same.

[0094] Here, the alarm sub-score of the alarm type for the alarm degree of each alarm information of the target computing resource in the first period can be recorded to determine the target alarm score of the target computing resource.

[0095] Here, the alarm sub-score of the alarm type for the alarm degree of each alarm information of the target computing resource in the first period can be added to obtain the target alarm score.

[0096] For example, there are two alarm information of the target computing resource in the first period. The alarm type of the first alarm information is vulnerability, and the corresponding alarm degree is low-risk vulnerability. Therefore, the alarm sub-score of the first alarm information is 1. The alarm type of the second alarm information is threat attack, and the corresponding alarm degree is medium-risk threat attack. Therefore, the alarm sub-score of the second alarm information is 2. At this time, the target alarm score of the target computing resource is 3.

[0097] In an optional embodiment, the above step of determining the response level of the target computing resource based on the alarm information comprises the following steps:

[0098] Firstly, in the case that the alarm information does not satisfy the preset security condition, the alarm type of the alarm information is determined.

[0099] Then, the response level of the target computing resource is determined based on the alarm type.

[0100] Here, firstly, the alarm type of the alarm information can be determined in the case that the alarm information carries untrusted attack information based on the trusted state. Secondly, the number of alarm information corresponding to each alarm type in the second period can be counted. Finally, the response level of the target computing resource can be determined based on the number.

[0101] In the embodiments of the present disclosure, the security index agent node can set a second determination rule for carrying untrusted attack information. The untrusted attack information is all alarm information for the node.

[0102] Here, the security index agent node can set the second determination rule for different alarm types.

[0103] Here, in the case that there are multiple alarm information in the second period, the corresponding alarm type of each alarm information can be determined. Then, based on the alarm type corresponding to each alarm information and the second mapping relationship, the response level matched with the target computing resource is determined.

[0104] Here, the second determination rule further comprises a preset number threshold and a response level corresponding to the preset number threshold. For example, in the case that the alarm type is an attack alarm for the computing resource, it comprises a first preset number threshold and a second preset number threshold. In the case that the alarm type is an abnormal behavior alarm for the computing resource, it comprises a third preset number threshold and a fourth preset number threshold.

[0105] In a case where the number of alarm information of the alarm type of the attack alarm against the computing resource in the second period is greater than the first preset number threshold and less than the second number threshold, the response level is determined as the first response level; in a case where the number of alarm information of the alarm type of the attack alarm against the computing resource in the second period is greater than the second preset number threshold, the response level is determined as the second response level.

[0106] In a case where the number of alarm information of the alarm type of the abnormal behavior alarm against the computing resource in the second period is greater than the third preset number threshold and less than the fourth number threshold, the response level is determined as the first response level; in a case where the number of alarm information of the alarm type of the abnormal behavior alarm against the computing resource in the second period is greater than the fourth preset number threshold, the response level is determined as the second response level.

[0107] The second preset number threshold is greater than the first preset number threshold, and the fourth preset number threshold is greater than the third preset number threshold.

[0108] In an optional embodiment, the step of determining the scheduling priority of the computing resource to which the target computing resource belongs based on the response level comprises:

[0109] First, in a case where the response level of the target computing resource is the first response level, the target computing resource is added to the first computing resource list;

[0110] Then, in a case where the response level of the target computing resource is the second response level, the target computing resource is added to the second computing resource list; the danger degree corresponding to the second response level is greater than the danger degree corresponding to the first response level, and the calling priority of the computing resource in the first computing resource list is higher than the calling priority of the computing resource in the second computing resource list.

[0111] In the embodiments of the present disclosure, different response levels correspond to different disposal strategies (i.e., response strategies). The disposal strategy includes setting a first list, a second list (i.e., a first computing resource list) and a third list (i.e., a second computing resource list).

[0112] Here, the first list is a white list, that is, a list with the highest scheduling priority. The second list is a gray list, that is, a list with a lower scheduling priority than the scheduling priority corresponding to the first list. The third list is a black list, that is, a list with a lower scheduling priority than the scheduling priority corresponding to the second list.

[0113] Here, in the case of scheduling of computing resources for a computing task, the computing resource in the first list can be called in the case that there is no idle computing resource in the first list or there is no computing resource in the first list that meets the computing requirement of the computing task. Here, the computing resource in the third list can be prohibited from being called.

[0114] In an optional embodiment, after the target computing resource is added to the first computing resource list, the following steps are further included:

[0115] First, the response level of the target computing resource in the target time period is determined;

[0116] Then, in the case that the response level of the target computing resource in the target time period does not reach the first response level, the target computing resource is deleted from the first computing resource list.

[0117] In an embodiment of the present disclosure, after the target computing resource is added to the first computing resource list, a target time period can be set for the target computing resource. Then, in the case that the response level of the target computing resource in the target time period does not reach the first response level, the target computing resource is removed from the first computing resource list (i.e., the target computing resource is deleted from the first computing resource list).

[0118] Here, after the target computing resource is added to the second computing resource list, a specified time period can be set for the target computing resource. Then, in the case that the response level of the target computing resource in the specified time period does not reach the second response level, the target computing resource is removed from the second computing resource list (i.e., the target computing resource is deleted from the second computing resource list). The specified time period is longer than the target time period.

[0119] In an optional embodiment, the above step of obtaining the alarm information of the target computing resource includes the following steps:

[0120] First, the alarm rule of the target computing resource is determined; wherein the alarm rule carries the attribute value of at least one key attribute;

[0121] Secondly, the alarm rule is sent to the target node;

[0122] Finally, the alarm information sent by the target node after matching the alarm rule is obtained.

[0123] In an embodiment of the present disclosure, the security indicator agent node can determine the attribute value of the key attribute in each attribute of the security state information and the network security information.

[0124] Here, the security indicator agent node can determine the attribute value of the key attribute according to the influence degree and the danger degree of each attribute of the security state information and the network security information.

[0125] For example, the computing resource specified vulnerability information obtained through network scanning in the network security information, the computing resource specified baseline information, and the computing resource specified abnormal behavior information obtained through network traffic monitoring are determined as attribute values of the key attributes. The computing resource specified attack type, threat source IP address, domain name or MAC address, and the like in the security state information of the computing resource, the computing resource specified abnormal behavior information of the computing resource cooperating with the computing resource, and the computing resource specified vulnerability information are determined as attribute values of the key attributes.

[0126] Here, after the alarm rule is determined, the security index agent node can send the alarm rule to the target node on which the security function is deployed.

[0127] Here, after the target node receives the alarm rule, the security state information and the network security information of the detected target computing resource can be matched through the alarm rule to determine alarm information matched with the alarm rule, and the alarm information is sent to the security index agent node.

[0128] In an optional embodiment, the above step schedules the computing resource of the target computing resource based on the response strategy and the computing resource of the target computing resource, and specifically includes the following steps:

[0129] The response strategy is sent to the path decision node, so that the path decision node schedules the computing resource of the target computing resource based on the response strategy and the target computing resource.

[0130] In the embodiments of the present disclosure, in the above Figure 1 Based on the described embodiments, the method applied to the path decision node further includes the following steps:

[0131] The response strategy sent by the security index agent node is obtained;

[0132] The computing resource of the target computing resource is scheduled based on the response strategy and the target computing resource.

[0133] Here, the security index agent node can send the response strategy to the path decision node. Then, the path decision node can determine the computing resource and network information of the target computing resource. Then, in the case of receiving a computing task, the path decision node can schedule the computing resource based on the computing resource, network information and response strategy of the target computing resource. Those skilled in the art can understand that in the above method of the specific embodiment, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process, and the specific execution order of each step should be determined by its function and possible internal logic.

[0134] Based on the same inventive concept, the disclosure embodiments also provide a computing power resource scheduling device corresponding to the computing power resource scheduling method. Since the principle of the device in the disclosure embodiments solves the problem similar to the computing power resource scheduling method of the disclosure embodiments, the implementation of the device can be referred to the implementation of the method, and the repeated parts will not be described here.

[0135] The device comprises a security index agent node and a path decision node.

[0136] The security index agent node is configured to acquire alarm information of a target computing power resource, wherein the alarm information is used to indicate node security state information of a node to which the target computing power resource belongs; based on the alarm information, a response strategy of the target computing power resource is determined, wherein the response strategy is used to indicate a scheduling mode of the target computing power resource; and based on the response strategy, the computing power resource of the target computing power resource is scheduled.

[0137] The path decision node is configured to receive the response strategy and schedule the computing power resource of the target computing power resource based on the response strategy.

[0138] In the embodiments of the disclosure, both the nodes with security functions (Security function) and the computing power resources (i.e., service nodes, Service nodes) (i.e., the following target nodes) can determine alarm information.

[0139] Here, the security functions include network security functions and computing power resource security functions. Among them, the network security functions, that is, the security functions in the network, can be deployed by a computing power service operator or a network provider, including but not limited to: scanning and detection type security functions. The computing power resource security functions, that is, the security functions in the computing power resources, can be deployed and managed by a service provider, including but not limited to: various security functions.

[0140] Among them, the network security functions can collect network security state information. Among them, the network security state information includes but is not limited to: leak scanning, baseline scanning, and network anomaly behavior detection functions.

[0141] Among them, the computing power resource security functions can collect node security state information. Among them, the node security state information includes but is not limited to: anomaly detection, threat attack tracing, and antivirus.

[0142] In the embodiments of the disclosure, the alarm information can be comprehensively analyzed by the security index agent node (i.e., C-SeMA) to determine the response level of the target computing power resource corresponding to the alarm information; then, the response strategy of the target computing power resource can be determined based on the response level of the target computing power resource.

[0143] Here, the response strategies include, but are not limited to: stopping the scheduling of computing resources to which the target computing resource belongs, and reducing the scheduling priority of computing resources to which the target computing resource belongs.

[0144] This allows us to determine the reliability status, alarm type, and alarm severity of alarm information, enabling comprehensive analysis of the alarm information and thus determining the response level.

[0145] Here, after the response strategy is determined, it can be sent to the path decision node (i.e., C-PS) through the security indicator proxy node.

[0146] In the embodiments of this disclosure, the path decision node can determine the computing power resources (i.e., computing power information) and network information of the target computing power resource. Then, the computing power resources of the target computing power resource can be scheduled based on the computing power resources, network information, and response strategy.

[0147] Here, network information includes at least one of the following: network traffic information of the network to which the target computing power resource is connected, and baseline information.

[0148] Here, the path decision node can preferentially determine the computing resources and network information required for the computational task to be processed. Then, it determines the computing resources in the computing resource database that meet the requirements of the computing resources and network information needed for the computational task to be processed.

[0149] If the identified computing resources include the target computing resources, the decision on whether to use the target computing resources to process the computing task is made based on the response strategy of the target computing resources.

[0150] In the above embodiments, by obtaining alarm information of the target computing power resource, the node security status information of the node to which the target computing power resource belongs can be determined, thereby determining the security of the target computing power resource. Therefore, the scheduling method of the target computing power resource determined based on the alarm information can ensure the security of computing power scheduling, prevent low-security computing power resources from being called, and thus alleviate the security risks of data tampering, leakage, and service unavailability in computing tasks caused by poor security of computing power scheduling in the prior art.

[0151] like Figure 2 The diagram shown is a schematic of a computing resource scheduling device provided in an embodiment of this disclosure, including: a target node, a security indicator proxy node, and a path decision node, wherein:

[0152] First, the security indicator proxy node determines the alarm rules and sends them to the target node. Second, the target node identifies the alarm information matching the alarm rules and sends it to the security indicator proxy node. Next, the security indicator proxy node determines the response level of the target computing resources based on the alarm category of the alarm information. Then, the security indicator proxy node determines the response strategy for the target computing resources based on the response level and sends the response strategy to the path decision node. Next, the path decision node schedules the target computing resources based on the response strategy and the available computing resources. Then, the security indicator proxy node determines whether the response level of the target computing resources has changed within the target time period or a specified time period; if so, it updates the response level. Finally, if the response level of the target computing resources has been updated, the security indicator proxy node sends the updated response level to the path decision node.

[0153] Based on the same inventive concept, this disclosure also provides a computing resource scheduling architecture corresponding to the computing resource scheduling method. Since the principle of the architecture in this disclosure for solving the problem is similar to the computing resource scheduling method described above in this disclosure, the implementation of the architecture can refer to the implementation of the method, and the repeated parts will not be described again.

[0154] The processing flow of each node in the device and the interaction flow between each node can be described in the relevant descriptions in the above method embodiments, and will not be detailed here.

[0155] like Figure 3 The diagram shown illustrates a computing resource scheduling architecture provided in this embodiment of the present disclosure, including: clients, C-SeMA (security indicator proxy node), C-PS (path decision node), security function (target node), CATS-forwarder (request forwarding node), and Service-contact Instance (service instance interacting with clients), wherein:

[0156] Clients are used to submit computing tasks to the scheduling architecture of computing resources.

[0157] C-SeMA is used to receive alarm information about the node security status and network security status of computing resources collected by the security function, and determine the response strategy based on the alarm information; then, it sends it to C-PS with good network conditions, or CATS-forwarder.

[0158] A C-PS / CATS-forwarder is configured to schedule the target computing resource based on a response strategy and a computing resource of a computing resource.

[0159] A service-contact instance is a service instance that directly interacts with a client.

[0160] The clients, the C-SeMA, the C-PS, the security function, the CATS-forwarder, and the service-contact instance can be communicatively connected.

[0161] In the above embodiment, by obtaining the alarm information of the target computing resource, the node security state information of the node to which the target computing resource belongs can be determined, so that the security of the target computing resource can be determined. Therefore, based on the scheduling mode of the target computing resource determined based on the alarm information, the security of the computing resource scheduling can be ensured, and the computing resource with low security is avoided to be called, thereby alleviating the security risk problem of the existing technology that the computing task exists data tampering, leakage, and service unavailability due to poor security of the computing resource scheduling.

[0162] Corresponding to the inference method of the large language model in Figure 1 The present embodiment also provides an electronic device 400, as shown in Figure 4 The structure schematic diagram of the electronic device 400 provided by the present embodiment includes:

[0163] The processor 41, the memory 42, and the bus 43; the memory 42 is used to store the execution instructions, including the internal memory 421 and the external memory 422; the internal memory 421 here is also called the internal memory, which is used to temporarily store the operation data in the processor 41 and the data exchanged with the external memory 422 such as a hard disk, the processor 41 exchanges data with the external memory 422 through the internal memory 421, when the electronic device 400 is running, the processor 41 and the memory 42 communicate through the bus 43, so that the processor 41 executes the following instructions:

[0164] Obtain alarm information of a target computing resource; wherein the alarm information is used to indicate node security state information of the target computing resource and / or network security state information of a network to which the target computing resource belongs;

[0165] Determine a response strategy of the target computing resource based on the alarm information; wherein the response strategy is used to indicate a scheduling mode of a computing resource to which the target computing resource belongs;

[0166] Scheduling, based on the response strategy and the computing resource of the target computing resource, the computing resource of the target computing resource.

[0167] The above describes the basic principles of the present disclosure in combination with specific embodiments, but it should be noted that the advantages, advantages, effects, etc. mentioned in the present disclosure are only examples and not limitations, and these advantages, advantages, effects, etc. cannot be considered as necessary for each embodiment of the present disclosure. In addition, the above specific details of the disclosure are only for the purpose of example and for the purpose of understanding, and are not limited to the above specific details. The above details do not limit the present disclosure to be necessarily implemented with the above specific details.

[0168] The block diagrams of the devices, apparatuses, equipment, systems involved in the present disclosure are only illustrative examples and are not intended to require or imply the connection, arrangement, configuration shown in the block diagram. As those skilled in the art will recognize, these devices, apparatuses, equipment, systems can be connected, arranged, configured in any manner. Words such as "include", "contain", "have" and the like are open-ended words, which mean "including but not limited to", and can be used interchangeably. The words "or" and "and" used herein mean the word "and / or", and can be used interchangeably unless the context clearly indicates otherwise. The word "such as" used herein means the phrase "such as but not limited to", and can be used interchangeably.

[0169] In addition, as used herein, "or" used in the list of items starting with "at least one of indicates a separate list, so that, for example, "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e. A and B and C). In addition, the phrase "exemplary" does not mean that the described example is preferred or better than other examples.

[0170] It should also be noted that in the systems and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalents of the present disclosure.

[0171] Various changes, substitutions and alterations can be made to the technology described herein without departing from the teachings of the appended claims. In addition, the scope of the claims of the present disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of matter, means, methods and acts described above. Processes, machines, manufactures, compositions of matter, means, methods or acts currently existing or later developed that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Accordingly, the appended claims include within their scope such processes, machines, manufactures, compositions of matter, means, methods or acts.

[0172] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other aspects without departing from the scope of the disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0173] The above description has been presented to enable any person skilled in the art to make or use the disclosure. Furthermore, the purpose of the above description is not intended to limit the embodiments of the present disclosure to the form disclosed herein. Although various example aspects and embodiments have been discussed above, those of ordinary skill in the art will appreciate a variety of modifications, alternatives, permutations, additions, and sub-combinations of the described aspects and embodiments.

Claims

1. A method for scheduling computing resources, characterized in that, The method includes: Obtain alarm information for the target computing power resource; wherein, the alarm information is used to indicate the node security status information of the node to which the target computing power resource belongs; Based on the alarm information, a response strategy for the target computing power resource is determined; wherein, the response strategy is used to indicate the scheduling method of the target computing power resource; The target computing resources are scheduled based on the response strategy. Based on the alarm information, the response level of the target computing power resource is determined; wherein, the response level is used to indicate the degree of danger of the target computing power resource; Based on the response level, the scheduling priority of the target computing power resource is determined, and the response strategy of the target computing power resource is determined according to the scheduling priority; If the response level of the target computing power resource is the first response level, the target computing power resource is added to the first computing power resource list; When the response level of the target computing resource is the second response level, the target computing resource is added to the second computing resource list; wherein, the degree of danger corresponding to the second response level is greater than the degree of danger corresponding to the first response level, and the calling priority of computing resources in the first computing resource list is higher than the calling priority of computing resources in the second computing resource list.

2. The method as described in claim 1, characterized in that, Determining the response level of the target computing power resource based on the alarm information includes: If the alarm information meets the preset security conditions, the response level of the target computing power resource is determined based on the alarm type and alarm severity of the alarm information.

3. The method as described in claim 1, characterized in that, Determining the response level of the target computing power resource based on the alarm information includes: If the alarm information does not meet the preset security conditions, the response level of the target computing power resource is determined based on the alarm type of the alarm information.

4. The method as described in claim 1, characterized in that, After adding the target computing power resource to the first computing power resource list, the method further includes: Determine the response level of the target computing resources within the target time period; If the response level of the target computing power resource does not reach the first response level within the target time period, the target computing power resource is deleted from the first computing power resource list.

5. The method as described in claim 1, characterized in that, The alarm information for acquiring the target computing power resources includes: Determine the alarm rules for the target computing power resources; wherein the alarm rules carry attribute values ​​for at least one key attribute; Send the alarm rules to the target node; Obtain the alarm information sent by the target node after matching according to the alarm rules.

6. The method as described in claim 1, characterized in that, The scheduling of computing resources for the target computing resources based on the response strategy and the target computing resources includes: The response strategy is sent to the path decision node so that the path decision node can schedule the target computing resources based on the response strategy and the target computing resources.

7. A method for scheduling computing resources, characterized in that, The method includes: Obtain the response policy sent by the security indicator proxy node; wherein the response policy is determined by the security indicator proxy node according to any one of claims 1 to 6 above; The target computing resources are scheduled based on the response strategy.

8. A computing resource scheduling device, characterized in that, include: Security indicator proxy nodes and path decision nodes; The security indicator proxy node acquires alarm information of the target computing power resource; wherein, the alarm information is used to indicate the node security status information of the node to which the target computing power resource belongs; based on the alarm information, it determines the response strategy for the target computing power resource; wherein, the response strategy is used to indicate the scheduling method of the target computing power resource; and it schedules the computing power resource of the target computing power resource based on the response strategy. The path decision node is used to receive the response strategy and schedule computing resources for the target computing resources based on the response strategy. The security indicator proxy node is also used to determine the response level of the target computing power resource based on the alarm information; wherein the response level is used to indicate the degree of danger of the target computing power resource; Based on the response level, the scheduling priority of the target computing power resource is determined, and the response strategy of the target computing power resource is determined according to the scheduling priority; If the response level of the target computing power resource is the first response level, the target computing power resource is added to the first computing power resource list; When the response level of the target computing resource is the second response level, the target computing resource is added to the second computing resource list; wherein, the degree of danger corresponding to the second response level is greater than the degree of danger corresponding to the first response level, and the calling priority of computing resources in the first computing resource list is higher than the calling priority of computing resources in the second computing resource list.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 7.

11. A computer program product, comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Ubiquitous computing power management method and device for computing power network and electronic equipment

    CN115150374A

  • Computing power scheduling method and device, electronic equipment and program product

    CN117130778A