System service security detection method and device, electronic equipment and storage medium
By acquiring resource usage data of network nodes and utilizing a target service identification model, the problem of locating complex and ever-changing attack sources is solved, enabling timely detection and dynamic assessment of network attacks, and improving the system's protection capabilities and response speed.
Patent Information
- Application Number
- CN202411503614.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-25
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-10-25
AI Technical Summary
Existing technologies struggle to pinpoint complex and ever-changing attack sources and can only provide single-point protection, making them ineffective in responding to cyberattacks.
By acquiring resource usage data of network nodes, the system uses a target service identification model to determine whether the system is under attack, identify the source of the attack, and calculate the system security index to quantify the security status.
It enables timely detection and location of complex and ever-changing network attacks, dynamically assesses system security status, and improves protection capabilities and response speed.
Smart Images

Figure CN119382972B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a system service security detection method and device, electronic equipment and a storage medium. BACKGROUND
[0002] In a modern network environment, target systems (such as servers, network devices, etc.) often face various security threats, especially service attacks (such as DDoS attacks, SYN Flood attacks, etc.).
[0003] In related technologies, security protection measures often rely on fixed rules, which are difficult to cope with complex and variable attack methods. In addition, attackers often use multiple network nodes to launch attacks, making single-point protection ineffective. SUMMARY
[0004] The present application provides a system service security detection method, device, electronic equipment and storage medium to solve the problem that it is difficult to locate complex and variable attack sources and only single-point protection in related technologies.
[0005] According to an aspect of the present application, a system service security detection method is provided, which comprises:
[0006] Obtaining resource occupation data of network nodes connected to a target system at multiple time points, determining resource change data according to the resource occupation data at multiple time points;
[0007] Determining a service attack state of the target system corresponding to the target system by the resource change data and a target service identification model, wherein the service attack state is used to represent whether the target system is attacked by a target service rejected by the target system;
[0008] In the case where the target system is attacked by a target service rejected by the target system, determining a target network node in multiple network nodes that initiates the target service;
[0009] Determining the number of initiations of the target service initiated by each target node and the number of nodes of the target network node, and determining a system security index of the target system according to the number of nodes and the number of initiations.
[0010] According to another aspect of the present application, a system service security detection device is provided, which comprises:
[0011] A node resource monitoring module for obtaining resource occupation data of network nodes connected to a target system at multiple time points, and determining resource change data according to the resource occupation data at multiple time points;
[0012] a service attack identification module, configured to determine a service attack state of the target system by the resource variation data and a target service identification model, wherein the service attack state is used to represent whether the target system is attacked by a target service rejected by the target system;
[0013] a target node determination module, configured to determine a target network node initiating the target service from a plurality of network nodes in a case where the target system is attacked by the target service rejected by the target system;
[0014] a system security determination module, configured to determine an initiating number of the target node initiating the target service and a node number of the target network node, and determine a system security index of the target system according to the node number and the initiating number.
[0015] According to another aspect of the present application, an electronic device is provided, which comprises:
[0016] at least one processor; and
[0017] a memory connected with the at least one processor in communication; wherein,
[0018] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the system service security detection method according to any one of the embodiments of the present application.
[0019] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to implement the system service security detection method according to any one of the embodiments of the present application when executed by the processor.
[0020] The technical scheme of the embodiment of the application first acquires resource occupation data of a network node connected with a target system at multiple time points, determines resource change data according to the resource occupation data at the multiple time points, can detect resource use change in real time, and discovers abnormal behavior in time; then determines a service attack state corresponding to the target system according to the resource change data and a target service identification model, can accurately determine whether the target system is attacked, since the service attack state is used to represent whether the target system is attacked by a target service rejected by the target system; next, in the case that the target system is attacked by a target service rejected by the target system, determines a target network node of the multiple network nodes that initiates the target service, can quickly locate an attack source and accurately identify a network node that initiates the attack; finally, determines an initiation frequency of the target node that initiates the target service and a node quantity of the target network node, determines a system security index of the target system according to the node quantity and the initiation frequency, can quantify a system security state, solves the problems that an attack source is difficult to locate and only single-point protection can be achieved in the related art, not only can the attack source be located in time, but also the security state of the system can be dynamically evaluated, the protection capability and response speed of the system are improved, and complex and changeable network attacks can be effectively coped with.
[0021] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the application, nor is it used to limit the scope of the application. Other features of the application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.
[0023] Figure 1 is a flow chart of a system service security detection method provided by the first embodiment of the application;
[0024] Figure 2 is a flow chart of a system service security detection method provided by the second embodiment of the application;
[0025] Figure 3 is a structural schematic diagram of a system service security detection device provided by the third embodiment of the application;
[0026] Figure 4 is a structural schematic diagram of an electronic device for implementing the system service security detection method of the embodiment of the application. DETAILED DESCRIPTION
[0027] In order to make the personnel in the technical field better understand the present application scheme, the technical scheme in the embodiment of the present application will be described clearly and completely in the following combined with the drawings in the embodiment of the present application. Obviously, the described embodiment is only a part of the embodiment of the present application, not all. Based on the embodiment in the present application, all other embodiments obtained by the person skilled in the art without creative labor should belong to the scope of protection of the present application.
[0028] It should be noted that the terms "first", "second" and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0029] It should be noted that the modification of "one" or "multiple" mentioned in the present disclosure is illustrative but not restrictive, and those skilled in the art should understand that unless otherwise explicitly indicated in the context, it should be understood as "one or more".
[0030] The names of the messages or information exchanged between the plurality of devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.
[0031] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type, use range, use scenario and the like of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained through appropriate means according to relevant laws and regulations.
[0032] For example, in response to receiving the user's active request, the user is sent prompt information to explicitly prompt the user that the operation requested to be performed will require the acquisition and use of the user's personal information. Thus, the user can voluntarily choose whether to provide personal information to the electronic device, application program, server or storage medium, etc. software or hardware that performs the operation of the technical solutions of the present disclosure according to the prompt information.
[0033] As an optional but non-limiting implementation, in response to receiving the active request of the user, the manner of sending the prompt information to the user may be, for example, a pop-up window manner in which the prompt information may be presented in a textual manner. In addition, the pop-up window may also carry a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0034] It can be understood that the above notification and user authorization obtaining process is only illustrative and does not limit the implementation of the present disclosure, and other manners meeting the relevant laws and regulations can also be applied to the implementation of the present disclosure.
[0035] It can be understood that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the relevant laws and regulations and the relevant provisions.
[0036] Embodiment one
[0037] Figure 1 A flowchart of a system service security detection method is provided for the present embodiment one, and the present embodiment can be applicable to the case that a system needs to detect and defend network attacks in real time. The method can be executed by a system service security detection device, which can be realized in the form of hardware and / or software. Optionally, the system service security detection device can be realized by an electronic device, which can be a mobile terminal, a PC terminal, or a server, etc.
[0038] As shown in Figure 1 , the method can specifically include:
[0039] S110, acquiring resource occupation data of a network node connected to a target system at multiple time instants, and determining resource variation data according to the resource occupation data at the multiple time instants.
[0040] The target system can be understood as a specific computer system or server that needs to be detected and protected, and the target system can be subject to security threats from the outside or the inside. The network node can be understood as each component in the network, and each device connected to the network can be referred to as a network node. The network node can include but is not limited to servers, workstations, routers, switches, etc., and the network nodes can communicate with each other through network protocols. The resource occupation data can be understood as data of various resources consumed by the target system during operation, including but not limited to CPU utilization, memory usage, and disk read / write speed, etc. The resource occupation data reflects the current working state and load condition of the target system. The resource variation data can be understood as the usage trend or difference of the resource occupation data obtained by comparing and analyzing the resource occupation data at different time instants. The resource variation data is used to indicate whether the target system is subject to abnormal attacks or loads.
[0041] In S120, a service attack state of the target system is determined based on the resource change data and the target service identification model, where the service attack state is used to represent whether the target system is under attack of the target service that is rejected by the target system.
[0042] The target service identification model can be understood as a pre-trained algorithm or model, which is used to identify a specific type of service request and determine whether the service request is normal. The target service identification model can learn normal request patterns from historical data, thereby effectively distinguishing between legitimate service requests and potential attack behaviors. The service attack state can be understood as state information indicating whether the target system is under attack of a certain form of service attack. The service attack can be understood as an attempt to make the target service unavailable or reduce the service quality. For example, the service attack can be a DDoS attack (Distributed Denial of Service attack) and the like. The target service can be understood as a service that is attempted to be utilized or interfered by an attacker. For example, the target service can include, but is not limited to, an HTTP service, an FTP service, a database service, and the like. It can be understood that in some cases, the target service can be a service that is explicitly rejected by the target system, that is, the system is configured to not allow to provide such service.
[0043] In S130, in a case where the target system is under attack of the target service that is rejected by the target system, a target network node that initiates the target service among the plurality of network nodes is determined.
[0044] The target network node can be understood as a network node that is identified as initiating the attack in the case where the service attack is confirmed. For example, the target network node can be a botnet controlled by a hacker, or a device infected by malicious software, or a legal user device that is utilized by an attacker to amplify the attack effect, and the like, which is not limited here.
[0045] On the basis of the above scheme, after determining the target network node that initiates the target service among the plurality of network nodes, the target service is intercepted, and the system resources allocated to the target network node are reduced according to the number of times that the target network node initiates the target service.
[0046] In an optional embodiment, when it is detected that a certain target network node initiates a target service that is considered as an attack, the system takes measures to prevent the target service request from reaching the target system, which can be achieved by firewall rules, intrusion prevention systems (IPS) or other security mechanisms, etc., with the purpose of preventing the attacker from further exploiting the target service to cause damage. In addition, in order to alleviate the impact of the attack, the system can reduce the system resources of the target network node. For example, resources such as bandwidth, CPU time and memory allocated to the target network node can be reduced, or service response can be completely stopped.
[0047] By reducing the allocation of system resources of the target network node, the above scheme can effectively reduce the ability of the attacker to exploit the target network node to launch an attack, thereby reducing the pressure on the target system and improving the overall security and stability of the system.
[0048] S140, determine the number of initiations of the target service initiated by each of the target network nodes and the number of nodes of the target network nodes, and determine the system security index of the target system according to the number of nodes and the number of initiations.
[0049] The number of initiations can be understood as the number of times each target network node initiates a target service request to the target system. It can be understood that a high frequency of the number of initiations may be a sign of an attack. The number of nodes can be understood as the total number of target network nodes participating in the attack. It can be understood that a larger number of attack nodes means stronger attack capability. The system security index can be understood as a quantitative index determined according to factors such as the number of nodes of the target network nodes and the number of initiations of each node, which is used to evaluate the overall security of the target system. It can be understood that the higher the system security index, the greater the threat to the target system, and more stringent protective measures need to be taken.
[0050] On the basis of the above scheme, the system security index of the target system can be determined according to the number of nodes and the number of initiations based on the following formula:
[0051]
[0052] In the formula, F represents the system security index of the target system, M represents the number of nodes of the target network nodes, γ n represents the weight coefficient of the nth network node, N represents the total number of network nodes connected to the target system, 1≤n≤N, n is a positive integer, A n represents the number of initiations of the target service initiated by the nth target network node.
[0053] An optional embodiment determines the total number N of all network nodes connected to the target system, identifies which network nodes are target network nodes (i.e., nodes initiating attacks), and records the number M of these nodes. For each target network node, the number A of times it initiates the target service is recorded n A weight coefficient γ is set for each target network node n The weight coefficient can be determined according to historical data, the importance of the node, or other factors. For example, if a network node frequently initiates attacks, a higher weight coefficient can be set for it. The system security index of the target system is calculated using the formula.
[0054] The technical scheme of the embodiment of the present application first acquires resource occupation data of network nodes connected to a target system at multiple time points, determines resource change data according to the resource occupation data at multiple time points, can detect changes in resource usage in real time, and discover abnormal behavior in a timely manner; then determines the service attack state of the target system through the resource change data and a target service identification model, since the service attack state is used to represent whether the target system is attacked by the target service rejected by the target system, the target system can be accurately determined whether it is attacked; next, in the case where the target system is attacked by the target service rejected by the target system, the target network node initiating the target service among the multiple network nodes is determined, which can quickly locate the attack source and accurately identify the network node initiating the attack; finally, the number of initiations of the target service by each target node and the number of nodes of the target network node are determined, and the system security index of the target system is determined according to the number of nodes and the number of initiations, which can quantify the system security state, solve the problem that it is difficult to locate complex and variable attack sources in related technologies, and only single-point protection can not only timely discover and locate the attack source, but also dynamically evaluate the security status of the system, improve the protection capability and response speed of the system, and effectively cope with complex and variable network attacks.
[0055] Embodiment two
[0056] Figure 2A flowchart of a system service security detection method provided for the second embodiment of the present application, this embodiment is based on the above-mentioned embodiments, and further refines the determination of the service attack state of the target system through the resource variation data and the target service identification model. Optionally, the determination of the service attack state of the target system through the resource variation data and the target service identification model comprises: determining abnormal variation data in the resource variation data, inputting the abnormal variation data into the target service identification model to obtain the service attack state corresponding to the target system, wherein the target service identification model is obtained by training a deep learning model based on sample resource data and a service attack state corresponding to the sample resource data. The specific implementation can be seen from the description of this embodiment. Wherein, the same or similar technical features as the foregoing embodiments are not described here.
[0057] As shown in Figure 2 , the method can specifically include:
[0058] S210, acquiring resource occupation data of a network node connected to a target system at multiple time points, and determining resource variation data according to the resource occupation data at multiple time points;
[0059] S220, determining abnormal variation data in the resource variation data, inputting the abnormal variation data into a target service identification model to obtain a service attack state corresponding to the target system.
[0060] Wherein, the abnormal variation data can be understood as data different from the normal change mode in the resource variation data. The abnormal variation data can indicate that the system is experiencing abnormal resource usage, which may be caused by an attack or other abnormal events. The target service identification model can be a pre-trained algorithm or model, which can be obtained by training a deep learning model based on sample resource data and a service attack state corresponding to the sample resource data. The sample resource data can be understood as historical resource usage data used to train the target service identification model. The service attack state can be understood as a state label indicating whether the system is actually under attack under the condition of collecting sample resource data. The service attack state can be binary (such as "attack" or "normal"), or multi-class (such as "DDoS attack", "SYN Flood attack", "normal", etc.), which is not limited here. The deep learning model can be trained through a large amount of sample resource data and corresponding service attack states, gradually adjusting the model parameters to minimize the prediction error, for detecting and classifying new resource variation data to determine whether the system is under attack.
[0061] On the basis of the above scheme, optionally, the determining of the abnormal change data in the resource change data comprises: in a case where the resource change data satisfies a preset abnormality detection condition, determining the resource change data as abnormal change data, wherein the abnormality detection condition is:
[0062]
[0063] D t+1 = D t + μ (D t - D t-1 ) + θ t+1 D t+1 represents the resource occupation data of the network node to the target system at the t+1 time, D t D t represents the resource occupation data of the network node to the target system at the t time, D t ≠ 0, μ represents an error coefficient of resource data, and θ represents a preset constant.
[0064] The abnormality detection condition can be used as a standard for judging whether the resource change data is abnormal. It can be understood that, in a case where the resource change data satisfies the abnormality detection condition, the resource change data is considered to be abnormal. The error coefficient can be understood as an adjustment factor for adjusting the sensitivity of resource change. It can be understood that a larger error coefficient will make the abnormality detection more relaxed, and a smaller error coefficient will make the abnormality detection more strict. The preset constant can be understood as a threshold for judging whether the resource change data is abnormal. It can be understood that, in a case where the calculation result of the resource change data is greater than or equal to the preset constant, the resource change data is considered to be abnormal.
[0065] The above scheme can timely and accurately identify abnormal changes in resource use, reduce false positives and false negatives, quickly discover potential attacks or faults, improve the security and stability of the system, optimize resource allocation, and ensure the normal operation of key services by using the abnormality detection condition.
[0066] On the basis of the above scheme, optionally, before the abnormal change data is input into the target service identification model, the method further comprises: acquiring sample resource data of a sample system of the same type as the target system; determining a service attack state corresponding to the sample resource data; and training a deep learning model according to the sample resource data and the service attack state corresponding to the sample resource data to obtain a target service identification model.
[0067] The sample resource data can be understood as resource usage data collected from a sample system, including but not limited to CPU usage, memory usage, disk I / O rate, network bandwidth, etc., for training a deep learning model to enable the model to learn and identify normal and abnormal resource usage patterns. The sample resource data is the change data of the resources occupied by the sample nodes connected to the sample system when initiating services rejected by the sample system, and the change data of the resources occupied by the sample nodes when initiating normal services. The sample system can be understood as another system of the same type or similar characteristics as the target system, which is used to collect data required for training a deep learning model. The sample nodes can be understood as network nodes connected to the sample system, which can be servers, workstations, routers, switches, etc. The service requests initiated by the sample nodes are used to generate sample resource data to help the deep learning model identify normal and abnormal behaviors.
[0068] In an optional implementation, a sample system of the same type or similar characteristics as the target system is selected, resource occupation data of the sample system is collected at multiple time points, including CPU usage, memory usage, disk I / O rate, network bandwidth, etc., resource change data when sample nodes initiate services rejected by the sample system is recorded, and resource change data when sample nodes initiate normal services is recorded; the service attack state (such as "attack" or "normal") corresponding to each sample resource data is determined through manual annotation or existing security systems, these labels are associated with the corresponding sample resource data to form a labeled data set; the deep learning model is trained using the labeled data set, the model parameters are adjusted to minimize the prediction error, the performance of the model is evaluated through cross-validation and test set to ensure the accuracy and generalization ability of the deep learning model; after training, the trained model is saved as a target service identification model.
[0069] The above scheme trains a deep learning model to obtain a target service identification model by collecting resource change data of a sample system of the same type as the target system and labeling the service attack state, which not only improves the ability of the deep learning model to identify abnormal change data in a timely and accurate manner, but also effectively discovers and responds to potential attacks, enhances the security and stability of the system, and ensures the normal operation of critical services.
[0070] Based on the above scheme, after obtaining the target service identification model, the sample resource data is updated, and the target service identification model is updated according to the updated sample resource data.
[0071] An optional implementation, obtaining a target service identification model; periodically or under certain conditions (such as detecting a new attack pattern) re-collecting resource usage data of the sample system; retraining or fine-tuning the existing target service identification model using the new sample resource data.
[0072] The above scheme can ensure that the target service identification model always maintains the latest attack detection capability, timely adapts to new attack means and system changes, improves the accuracy and generalization ability of the model, thereby more effectively identifying and responding to potential security threats, and enhancing the security and stability of the system.
[0073] S230, in the case where the target system is attacked by the target service rejected by the target system, determining a target network node initiating the target service among the plurality of network nodes;
[0074] S240, determining the number of initiations of the target network node initiating the target service and the number of nodes of the target network node, and determining the system security index of the target system according to the number of nodes and the number of initiations
[0075] The technical scheme of the embodiment of the application determines resource change data to timely discover abnormal behavior, secondly, uses a target service identification model based on deep learning to accurately judge whether the system is attacked and identify the network node initiating the attack, furthermore, periodically updates sample resource data and the model to ensure the accuracy and generalization ability of the model and adapt to new attack means, finally, calculates the system security index to quantify the security state of the system, helps the administrator to timely take protective measures, can accurately identify and respond to complex network attacks in real time, improves the protection ability and response speed of the system, and ensures the normal operation of the key service.
[0076] Embodiment three
[0077] Figure 3 A structural schematic diagram of a system service security detection device provided by the third embodiment of the application is shown in FIG. 3. Figure 3 As shown in the figure, the device comprises a node resource monitoring module 310, a service attack identification module 320, a target node determination module 330, and a system security determination module 340.
[0078] The node resource monitoring module 310 is configured to acquire resource occupation data of network nodes connected to a target system at multiple time points, and determine resource variation data according to the resource occupation data at the multiple time points; the service attack identification module 320 is configured to determine a service attack state of the target system by using the resource variation data and a target service identification model, wherein the service attack state is used to represent whether the target system is attacked by a target service that is rejected by the target system; the target node determination module 330 is configured to determine a target network node that initiates the target service from the network nodes in a case where the target system is attacked by the target service that is rejected by the target system; and the system security determination module 340 is configured to determine an initiation frequency of the target service initiated by each target node and a node quantity of the target network node, and determine a system security index of the target system according to the node quantity and the initiation frequency.
[0079] The technical scheme of the embodiment of the application first acquires resource occupation data of network nodes connected to a target system at multiple time points by using the node resource monitoring module 310, and determines resource variation data according to the resource occupation data at the multiple time points, so that the resource usage change can be detected in real time, and abnormal behaviors can be found in time; then the service attack identification module 320 is used to determine a service attack state of the target system by using the resource variation data and a target service identification model, so that whether the target system is attacked can be accurately determined, because the service attack state is used to represent whether the target system is attacked by a target service that is rejected by the target system; next, the target node determination module is used to determine a target network node that initiates the target service from the network nodes in a case where the target system is attacked by the target service that is rejected by the target system, so that the attack source can be quickly located, and the network node that initiates the attack can be accurately identified; finally, the system security determination module 340 is used to determine an initiation frequency of the target service initiated by each target node and a node quantity of the target network node, and determine a system security index of the target system according to the node quantity and the initiation frequency, so that the system security state can be quantified, the problem that the attack source is difficult to locate in the related art and only single-point protection can be solved, not only the attack source can be found and located in time, but also the security state of the system can be dynamically evaluated, the protection capability and the response speed of the system are improved, and the complex and changeable network attack can be effectively coped with.
[0080] On the basis of the above scheme, optionally, the service attack identification module comprises a service attack state obtaining sub-module.
[0081] The service attack state obtaining submodule is configured to determine abnormal variation data in the resource variation data, input the abnormal variation data into a target service identification model, and obtain a service attack state corresponding to the target system, wherein the target service identification model is obtained by training a deep learning model based on sample resource data and a service attack state corresponding to the sample resource data.
[0082] Based on the above scheme, the service attack identification module can further include a sample resource data obtaining submodule and a target service identification model obtaining submodule.
[0083] The sample resource data obtaining submodule is configured to obtain sample resource data of a sample system of the same type as the target system, wherein the sample resource data is variation data of resources occupied by a sample node connected to the sample system when the sample node initiates a service that is rejected by the sample system, and variation data of resources occupied by the sample node when the sample node initiates a normal service; and the target service identification model obtaining submodule is configured to determine a service attack state corresponding to the sample resource data, and train a deep learning model based on the sample resource data and the service attack state corresponding to the sample resource data to obtain a target service identification model.
[0084] Based on the above scheme, the service attack identification module can further include a target service identification model updating submodule.
[0085] The target service identification model updating submodule is configured to update the sample resource data after the target service identification model is obtained, and update the target service identification model based on the updated sample resource data.
[0086] Based on the above scheme, the determination of the abnormal variation data in the resource variation data can include: in a case where the resource variation data satisfies a preset abnormality detection condition, determining the resource variation data as abnormal variation data, wherein the abnormality detection condition is:
[0087]
[0088] In the formula, D t+1 D t+1 represents resource occupation data of the network node to the target system at the t+1 time point, D t D t represents resource occupation data of the network node to the target system at the t time point, D t ≠0, and μ represents an error coefficient of resource data, and θ represents a preset constant.
[0089] Based on the above scheme, optionally, the system service security detection device further comprises:
[0090] System resource reduction module.
[0091] The system resource reduction allocation module is configured to intercept the target service after determining the target network node in the plurality of network nodes that initiates the target service, and reduce the system resource allocated to the target network node according to the number of times that the target network node initiates the target service.
[0092] Based on the above scheme, optionally, the system service security detection device further comprises: determining the system security index of the target system according to the number of nodes and the number of initiations based on the following formula:
[0093]
[0094] In the formula, F represents the system security index of the target system, M represents the number of nodes of the target network node, γ n represents the weight coefficient of the nth network node, N represents the total number of network nodes connected to the target system, 1≤n≤N, n is a positive integer, A n represents the number of initiations of the target service initiated by the nth target network node.
[0095] The system service security detection device provided by the embodiment of the application can execute the system service security detection method provided by any embodiment of the application, and has the corresponding function modules and beneficial effects of the execution method.
[0096] Embodiment four
[0097] Figure 4 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the applications described and / or claimed in this document.
[0098] As Figure 4As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., connected to the at least one processor 11 in communication. The memory stores a computer program executable by the at least one processor 11, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded into the random access memory (RAM) 13 from the storage unit 18. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0099] Various components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0100] The processor 11 can be various general and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as a system service security detection method.
[0101] In some embodiments, a system service security detection method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of a system service security detection method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform a system service security detection method by any other appropriate means, such as by means of firmware.
[0102] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0103] Computer programs used to implement the processes of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program
[0104] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0105] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0106] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0107] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0108] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be executed in parallel, executed in sequence, or executed in a different order, as long as the desired results of the present disclosure are achieved, and the present disclosure is not limited herein.
[0109] The specific embodiments described above are not intended to be limiting, and persons skilled in the art will appreciate that various modifications, combinations, sub-combinations and alternatives can be made to the specific embodiments without departing from the spirit and principles of the disclosure. Accordingly, the disclosure is not limited to the specific embodiments described above, but only by the scope of the appended claims.
Claims
1. A system service security detection method, characterized by, The method comprises: obtaining resource occupation data of network nodes connected to a target system at multiple time points, and determining resource variation data according to the resource occupation data at the multiple time points; determining a service attack state of the target system corresponding to the target system by using the resource variation data and a target service identification model, wherein the service attack state is used to represent whether the target system is attacked by a target service rejected by the target system; in the case that the target system is attacked by the target service rejected by the target system, determining a target network node initiating the target service in a plurality of network nodes; determining the number of nodes of each target network node initiating the target service and the number of times of initiation of the target service, and determining a system security index of the target system according to the number of nodes and the number of times of initiation.
2. The method of claim 1, wherein, The method comprises: determining abnormal variation data in the resource variation data, inputting the abnormal variation data into a target service identification model to obtain the service attack state corresponding to the target system, wherein the target service identification model is obtained by training a deep learning model based on sample resource data and a service attack state corresponding to the sample resource data.
3. The method of claim 2, wherein, Before the abnormal variation data is input into the target service identification model, the method further comprises: obtaining sample resource data of a sample system of the same type as the target system, wherein the sample resource data is variation data of resources occupied by a sample node connected to the sample system when the sample node initiates a service rejected by the sample system, and variation data of resources occupied by the sample node when the sample node initiates a normal service; determining a service attack state corresponding to the sample resource data, and training a deep learning model according to the sample resource data and the service attack state corresponding to the sample resource data to obtain a target service identification model.
4. The method of claim 3, wherein, After the target service identification model is obtained, the method further comprises: updating the sample resource data, and updating the target service identification model according to the updated sample resource data.
5. The method of claim 2, wherein, The method comprises: in the case that the resource variation data satisfies a preset abnormality detection condition, determining the resource variation data as abnormal variation data, wherein the abnormality detection condition is: In the formula, D t+1 D represents the resource occupation data of the target system at the t+1 time by the network node, D t D represents the resource occupation data of the target system at the t time by the network node, D t ≠0, μ represents the error coefficient of the resource data, and θ represents a preset constant.
6. The method of claim 1, wherein, After the target network node initiating the target service in the plurality of network nodes is determined, the method further comprises: intercepting the target service, and reducing system resources allocated to the target network node according to the number of times of initiation of the target service by the target network node.
7. The method of claim 1, wherein, The system security index of the target system is determined according to the number of nodes and the number of times of initiation based on the following formula: In the formula, F represents a system security index of the target system, M represents a node quantity of the target network node, γ n represents a weight coefficient of the nth network node, N represents a total quantity of network nodes connected with the target system, 1≤n≤N, n is a positive integer, A n represents an initiation quantity of the target service initiated by the nth target network node.
8. A system service security detection apparatus characterized by comprising: The method comprises: a node resource monitoring module, configured to obtain resource occupation data of network nodes connected to a target system at multiple time points, and determine resource variation data according to the resource occupation data at the multiple time points; The service attack identification module is configured to determine a service attack state of the target system by using the resource variation data and a target service identification model, wherein the service attack state is used to represent whether the target system is attacked by a target service which is rejected by the target system. The target node determination module is configured to determine a target network node which initiates the target service from a plurality of network nodes in a case that the target system is attacked by the target service which is rejected by the target system. The system security determination module is configured to determine an initiation frequency of the target service initiated by each target node and a node quantity of the target network node, and determine a system security index of the target system according to the node quantity and the initiation frequency.
9. An electronic device, comprising: The electronic device comprises: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores a computer program which can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the system service security detection method in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions, and the computer instructions are used to enable the processor to implement the system service security detection method in any one of claims 1-7 when executed.
Citation Information
Patent Citations
Abnormal change detection method and device, equipment and storage medium
CN115391160A
Information risk assessment method suitable for power distribution network security defense
CN117544366A