A power grid cloud platform security and efficiency compatible traffic traction model and application thereof
By building a traffic traction model in the power grid cloud platform and using multiple traffic paths to guide traffic to virtual security resources, the problem of differences in security protection components in a multi-cloud environment is solved, unified management and control of data flows and adaptive security protection are achieved, and the security and efficiency of the power grid cloud platform are improved.
Patent Information
- Application Number
- CN202411635465.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-15
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-11-15
AI Technical Summary
In the power grid cloud platform where multiple clouds coexist, there are differences in security protection components, making it difficult to achieve unified management and control. The traditional security protection design architecture cannot be adapted to the cloud platform, resulting in the inability to coordinate security protection capabilities and making it difficult to achieve dynamic perception of the global network security situation.
By building a traffic traction model that is compatible with the security and efficiency of the power grid cloud platform, and utilizing multiple traffic traction paths such as SDN, API, proxy, and micro-agent, traffic is directed to traditional virtual security resources and the virtual security resources of Alibaba Cloud and Huawei Cloud, achieving effective utilization and security protection of various virtual security resources, and establishing an adaptive management and control system for security protection on and off the cloud.
It has achieved unified management and control of data flows on the power grid cloud platform, improved adaptive security protection capabilities and support capabilities for cloud security operations, reduced dependence on external technologies, and enhanced data security protection on the power grid cloud platform.
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to data and information intelligent power grid technology, and particularly relates to a power grid cloud platform security and efficiency compatible traffic traction model and application thereof. BACKGROUND
[0002] In the aspect of cloud platform infrastructure construction, the State Grid Corporation has established Huawei cloud and Ali cloud basic platforms covering 27 provinces, and has basically possessed the ability to provide high-performance cloud computing. However, in the process of synchronously developing the network security protection ability of the cloud platform, the following three urgent needs exist. First, the self-research ability of cloud security protection needs to be strengthened, and a self-controllable technology system of the State Grid cloud security needs to be constructed. The State Grid cloud bears key power grid businesses related to the national economy and people's livelihood, and the safe operation of the cloud platform is the primary prerequisite for the safety of power grid businesses. Therefore, the network security protection ability of the State Grid cloud needs to be improved, and the safety of the basic platform, businesses and data needs to be ensured to continuously empower new infrastructure construction and digital transformation. Compared with traditional network security protection, the cloud security protection ability needs to be continuously improved in depth and breadth, and higher requirements are put forward for the coordination between security components. The ability integration of multiple security technical protection measures needs to be relied on to construct an integrated architecture of security technical protection measures, and the protection ability of multiple security technical protection measures on and off the cloud needs to be uniformly deployed. At the same time, by means of the elastic scalability of the cloud, different types and scales of attack scenarios can be coped with to realize the whole-process network security management and control ability of prediction, detection, response and tracing, and a more scaled and systematic adaptive ecological system of the State Grid cloud security needs to be built. Third, the ability of cloud security situation awareness needs to be improved, and a linkage defense system in the mode of confrontation needs to be constructed. With the continuous advancement of the construction of the State Grid cloud platform, data center platform and Internet of Things management platform, a large number of businesses in various forms, massive data and heterogeneous terminals are accessed, which makes the network security boundary tend to be blurred, and the cloud platform and the businesses carried thereby gradually become the main objects of attack threats. How to improve the situation awareness and linkage defense ability of the cloud platform in the mode of confrontation is an important topic of cloud security protection research.
[0003] Especially in recent years, with the construction of the cloud platform of the new power system company of the State Grid Corporation and the continuous migration of business systems to the cloud, the security protection needs of the cloud platform and the businesses on the cloud are continuously improved. The cloud platforms of the units of the State Grid Corporation differ in security protection technical architecture, security component selection and deployment, which causes the non-uniformity of the cloud security protection ability of multiple parties, the inability of the traditional security protection design architecture to adapt to the cloud platform, the difficulty of security protection components in realizing coordinated control, and the problems of the lack of key protection ability, the invalidation of part of the protection ability, the incomplete coverage of the protection ability and the existence of duplication and redundancy with the traditional technical protection system. Therefore, it is urgent to carry out the joint scheduling of security protection resources on and off the cloud to form an adaptive cloud security protection system that meets the coexistence of multiple cloud applications, the flexible deployment of components and the centralized control of protection.
[0004] Currently, the development of the project team's cloud platform system mainly faces the following challenges in the dimensions of security and efficiency: Inconsistent multi-party cloud security protection capabilities: In the complex environment of multi-party cloud coexistence and combination operation, there are differences in security protection components, making it difficult to achieve unified security control. Traditional security protection design architecture cannot adapt to the cloud platform: The traditional security protection capability and the cloud security protection capability have not realized coordination and unified control, and the technical barriers between the security protection components make it impossible to automatically arrange the security protection capability according to the scene, and the global network security situation is difficult to dynamically perceive. Security protection components are difficult to achieve coordinated control: The interface standards of cloud and non-cloud security protection components are different, the traffic cannot be uniformly controlled, and it is difficult to uniformly arrange, making it difficult for security protection components to achieve coordinated control.
[0005] Therefore, the project team decouples the capabilities of traditional security protection equipment based on the research points of joint protection on the cloud and non-cloud, and uniformly manages the capabilities of security components of Ali Cloud and Huawei Cloud, establishes a cloud and non-cloud security protection self-adaptive control system, changes the current security protection measures based on hardware or virtualization stacking protection mode, forms an adaptive cloud security protection system that meets the coexistence of multi-cloud applications, flexible component deployment, and centralized protection control, realizes unified control of power grid cloud platform data flow through multi-target and multi-path data diversion of security and technical protection resources, and improves the adaptive security protection capability and the support capability of cloud security operation business. This is an important basis for current technology development and the top priority of the development sub-item of the invention technology team. SUMMARY
[0006] The technical problem to be solved by the present application is to provide a power grid cloud platform security and efficiency compatible traffic traction model and its application, which can realize unified control of power grid cloud platform data flow through multi-target and multi-path data diversion of security and technical protection resources.
[0007] To solve the above technical problems, the technical solution adopted by the present application is as follows.
[0008] The power grid cloud platform security and efficiency compatible traffic traction model constructs the power flow traction model in combination with security and platform efficiency in the complex environment of multi-party cloud coexistence and combination operation in the construction of the power grid cloud platform, combines multiple traffic traction paths, and tracts the traffic to the traditional virtual security resources, Huawei Cloud virtual security resources, Ali Cloud virtual security resources or other cloud virtual security resources, to realize effective utilization and security protection of each cloud virtual security resource.
[0009] As a preferred technical solution of the present application, the multiple traffic traction paths include but are not limited to: SDN diversion, API diversion, proxy diversion, micro-proxy diversion and other optional traffic traction paths.
[0010] As a preferred technical solution of the present application, the initialization setting of different flow paths in the power grid cloud platform flow traction model corresponds to the basic flow traction model framework.
[0011] As a preferred technical solution of the present application, the basic flow traction model framework specifically includes: the SDN flow diversion utilizes the centralized control and flexible programmable characteristics of software-defined network, and through the controller issuing flow table rules, specific flow is accurately guided to the target virtual security resource; when detecting network flow from a region meeting the pre-set condition or having a pre-set feature, the SDN controller adjusts the flow table to guide it to the pre-set virtual security resource of Huawei cloud or Ali cloud for processing; the proxy flow diversion deploys a proxy server in the network to analyze and screen the flow and guide the flow meeting the condition to the corresponding virtual security resource according to the pre-set data rule; for the flow needing deep detection, it is guided to the pre-set traditional virtual security resource with advanced detection function through proxy flow diversion; the API flow diversion realizes interaction with different security systems and virtual security resources by means of application programming interface; dynamic allocation and guidance of flow are realized by calling API; when the security monitoring system finds abnormal flow, it is guided to the pre-set virtual security resource with specific protection capability through API instruction; the micro-proxy flow diversion adopts a lightweight micro-proxy to preliminarily screen and guide the flow at the terminal or network edge, and guides it to the corresponding virtual security resource by judging the nature and demand of the flow.
[0012] The power grid cloud platform flow traction method represents various characteristics of data flow of the power grid cloud platform by a vector based on the flow traction model, which can be named as flow characteristic vector; the flow characteristic vector contains source IP address, destination IP address, protocol type, flow size and other different dimension data information, further, for each specific flow path, a data module for making decision according to flow characteristics is constructed, wherein the SDN flow diversion, API flow diversion, proxy flow diversion and micro flow diversion and other subsequently added flow paths are decided by the corresponding data module according to the flow characteristics whether to adopt this flow diversion mode, then the decision of the flow diversion mode is combined to form a flow diversion matrix containing weight parameter data of each flow diversion mode, the flow diversion matrix directly numerically represents the target flow diversion direction, further, the iteration optimization of the flow diversion matrix (or the equivalent return to the adjustment and optimization of the related data module) corresponds to the iteration optimization of the flow traction.
[0013] As a preferred technical solution of the present application, the flow feature vector further comprises: a flow time distribution feature: flow peak value and mean value of different time periods; a flow direction feature: inflow and outflow ratio; and an application type feature: video stream, file transmission stream, webpage browsing and other data stream types.
[0014] As a preferred technical solution of the present application, for each flow diversion scheme, the specific construction of the flow diversion function is not only based on the flow feature, but also incorporates the load condition of each virtual security resource in the current network, the priority of the security policy and the historical flow diversion effect data factors as needed; wherein the SDN flow diversion function dynamically adjusts the flow diversion strategy according to the network link congestion condition monitored by the SDN controller; and the API flow diversion function determines whether to preferentially use the API method for flow diversion according to the priority rules set in the security policy data.
[0015] As a preferred technical solution of the present application, on the data, the flow diversion matrix is constructed as a weight representation architecture under multiple factors, the matching degree of the flow feature is assigned a weight w1, the load condition of the virtual security resource is assigned a weight w2, and the priority of the security policy is assigned a weight w3, and the final flow diversion matrix is obtained through weighted calculation; the iteration optimization of the flow diversion matrix corresponds to the iteration optimization of the flow traction.
[0016] As a preferred technical solution of the present application, for the optimization of the flow diversion matrix, an optimization method considering multiple targets is constructed to realize the optimization of the flow diversion matrix and determine the final flow diversion mode to realize the optimization of the flow diversion matrix.
[0017] As a preferred technical solution of the present application, for the optimization of the flow diversion matrix, on the basis of the initial constructed optimization algorithm, other optimization algorithms oriented to different targets are constructed for multiple optimization, to realize the adjustable and / or customized scheme output of the flow traction of the power grid cloud platform.
[0018] The beneficial effects produced by the above technical solution are that: the present application not only constructs a basic flow diversion model, but also further constructs a hierarchical flow diversion matrix optimization algorithm for practical application, which can perform multiple optimization for different targets to realize the adjustable and customized scheme output of the flow traction of the power grid cloud platform; the DIESO algorithm and the MCGODS algorithm are both originated from the technical team and have high application value.
[0019] Our drainage model is fully compatible with the current development trend, that is, the security components of Ali Cloud, Huawei Cloud and the like are uniformly managed into the power grid cloud platform, and a self-adaptive security protection management and control system is established on the cloud, forming a self-adaptive cloud security protection system that meets the coexistence of multi-cloud applications, flexible component deployment, and centralized protection management and control. On the basis of the current data, we realize the unified management and control of the power grid cloud platform data flow through multi-target and multi-path data drainage of various security technical protection resources, effectively improving the self-adaptive security protection capability and the support capability of cloud security operation business.
[0020] Based on the technical development of the present application, the data security of the power grid cloud platform can be effectively enhanced. The key is that we face the self-developed protection capability and build a self-controllable technical system of the power grid enterprise, independently and effectively guarantee the security of the basic platform, business and data of the power grid cloud, reduce the dependence on external technology, and enhance the resistance and self-recovery capabilities of the power grid in the face of network attacks. DETAILED DESCRIPTION
[0021] The following embodiments illustrate the present application in detail. In the description of the following embodiments, specific details such as specific system structures, techniques, etc. are presented in order to facilitate a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits and methods are omitted to avoid unnecessary details that hinder the description of the present application.
[0022] It should be understood that when used in the specification and the appended claims of the present application, the term "comprising" indicates the presence of the described features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or sets thereof.
[0023] It should also be understood that the term "and / or" used in the specification and the appended claims of the present application means any combination of one or more of the associated listed items and all possible combinations thereof.
[0024] As used in the specification and the appended claims of the present application, the term "if" can be interpreted as "when" or "upon" or "in response to a determination" or "in response to detecting" depending on the context. Similarly, the phrase "if it is determined" or "if [a described condition or event] is detected" can be interpreted to mean "upon determining" or "in response to determining" or "upon detecting [a described condition or event]" or "in response to detecting [a described condition or event]" depending on the context.
[0025] In addition, in the description of the present application and the appended claims, the terms "first", "second", "third", etc. are used only to distinguish descriptions and cannot be understood as indicating or implying relative importance.
[0026] Reference in the present application description to "one embodiment" or "some embodiments" means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrases "in one embodiment", "in some embodiments", "in other embodiments", "in additional embodiments", and so on, in various places in the specification are not necessarily all referring to the same embodiment, unless otherwise specifically stated. The terms "comprising", "including", "having" and their variants mean "including but not limited to", unless otherwise specifically stated.
[0027] Example 1, drainage model
[0028] Currently, in the power grid cloud platform architecture scheme, under the complex environment of coexistence and combination operation of multiple parties, the security protection components are different, it is difficult to realize unified security control, and the traditional security protection design architecture cannot adapt to the cloud platform, the traditional security protection capability and the cloud security protection capability have not realized cooperation and unified control, the technical barriers between security protection components, leading to the security protection capability cannot be automatically arranged according to the scene, the global network security situation is difficult to dynamically perceive. Therefore, the project team will decouple the capabilities of traditional security protection equipment based on the research points of joint protection on and off the cloud, and at the same time, the capabilities of security components of Ali Cloud and Huawei Cloud will be unified and managed, to establish a self-adaptive control system for security protection on and off the cloud, change the current security protection measures based on the protection mode of hardware or virtualization stacking, form a self-adaptive cloud security protection system that meets the requirements of multi-cloud application coexistence, flexible component deployment, and centralized protection control, and realize unified control of power grid cloud platform data flow through multi-target and multi-path data diversion of security protection resources. The leading technical route is to combine SDN diversion, API diversion, proxy diversion and micro-proxy diversion and other traffic traction schemes to divert data traffic under the power grid cloud architecture to traditional virtual security resources, Huawei Cloud, Ali Cloud and other virtual security resources to realize effective utilization and security protection of various virtual security resources.
[0029] On the basis of the above basic route architecture, the centralized control and flexible programmable characteristics of SDN are used to accurately guide specific traffic to the target virtual security resource by issuing flow table rules through the controller. When network traffic from a specific area or with specific characteristics is detected, the SDN controller quickly adjusts the flow table and directs it to the virtual security resource of Huawei Cloud or Ali Cloud for processing. With the help of API, interaction with different security systems and virtual security resources is realized, and through the calling of API, dynamic allocation and guidance of traffic are realized. When the security monitoring system discovers abnormal traffic, it is directed to the virtual security resource with specific protection capabilities through API instructions. For traffic that needs to be deeply detected, it is directed to the traditional virtual security resource with advanced detection function through the proxy (a proxy server is deployed in the network to analyze and screen the traffic, and according to the preset strategy, the traffic meeting the conditions is guided to the corresponding virtual security resource). At the same time, a light micro-proxy is set to preliminarily screen and guide the traffic at the terminal or network edge to quickly judge the nature and demand of the traffic and guide it to the most suitable virtual security resource (which can additionally improve the response speed and resource utilization efficiency).
[0030] Embodiment 2, a method for directing flow
[0031] Based on the above infrastructure, considering the digital scenario of the application end, the various characteristics of the data flow of the power grid cloud platform can be represented by a vector, which can be named as flow feature vector; our idea is to calculate the flow traction model through the combination of multiple flow tractions and virtual security resources, and then the intelligent selection can be performed according to the flow migration vector. The flow feature vector not only contains basic information such as source IP address, destination IP address, protocol type, flow size, but also includes time distribution characteristics of flow (such as flow peak value and average value in different time periods), flow direction characteristics (such as the ratio of inflow and outflow), and application type characteristics of flow (such as video stream, file transfer or web browsing, etc.). For each specific flow path, a data module (flow function) is constructed to make a decision according to the flow characteristics, in which the SDN flow, API flow, proxy flow and micro flow and other subsequent added flow paths are determined by the corresponding data module according to the flow characteristics to decide whether to use this flow method. When constructing the flow function to make specific decisions, not only the flow characteristics are considered to make decisions, but also the load of each virtual security resource in the current network, the priority of the security policy and the historical flow effect are considered; for the SDN flow function, the network link congestion monitored by the SDN controller is dynamically adjusted to adjust the flow strategy; the API flow function will decide whether to preferentially use the API method for flow according to the priority rules set in the security policy management system. The decision of the flow method is combined to form a flow matrix (the construction of the flow decision matrix will consider the weight of multiple factors, and the matching degree of the flow characteristics is assigned a weight w1, the load of the virtual security resource is assigned a weight w2, and the priority of the security policy is assigned a weight w3, and the final flow decision matrix is calculated by weighted calculation); this flow matrix directly represents the numerical value of the target flow direction, and the iteration optimization of the flow matrix (or the return to the adjustment and optimization of the related data module) corresponds to the iteration optimization of the flow traction.
[0032] Embodiment 3, flow application scenario-A
[0033] In this scenario, the final used flow method is determined by comprehensively considering the resource utilization efficiency, security protection effect and the like (basic feasible scheme).
[0034] Specifically, a 3+2 model is corresponded: three flow modes + two data targets.
[0035] Three flow methods: SDN flow (method A), API flow (method B) and proxy flow (method C).
[0036] Two data targets are defined at the same time: resource utilization efficiency (expressed in percentage) and security protection effect (expressed in score 1-10).
[0037] The following data are collected:
[0038] Method A: resource utilization efficiency is 80%, and security protection effect score is 7.
[0039] Method B: resource utilization efficiency is 70%, and security protection effect score is 8.
[0040] Method C: resource utilization efficiency is 75%, and security protection effect score is 7.5.
[0041] Algorithm idea:
[0042] For method A, if there is another drainage method that can have a security protection effect score higher than 7 while the resource utilization efficiency is not lower than 80%, then method A is not the optimal solution.
[0043] For method B, if there is another drainage method that can have a security protection effect score higher than 8 while the resource utilization efficiency is not lower than 70%, then method B is not the optimal solution.
[0044] For method C, if there is another drainage method that can have a security protection effect score higher than 7.5 while the resource utilization efficiency is not lower than 75%, then method C is not the optimal solution.
[0045] Suppose, after comparison, it is found that methods A and B are relatively optimal, then, next, according to one's own preferences for resource utilization efficiency and security protection effect, one can choose among these two optimal solutions.
[0046] If more emphasis is placed on security protection effect, choose method B; if more emphasis is placed on resource utilization efficiency, choose method A.
[0047] According to the hints of this idea, the following secondary algorithm can be constructed:
[0048] If the decision considers that the importance of security protection effect is twice that of resource utilization efficiency, then the weight of security protection effect can be set to 2, and the weight of resource utilization efficiency can be set to 1; at this time, the comprehensive score of each solution is calculated:
[0049] The comprehensive score of method A = 1 * 80% + 2 * 7 = 22
[0050] The comprehensive score of method B = 1 * 70% + 2 * 8 = 23
[0051] At this time, according to the comprehensive score, mode B is selected as the final drainage mode.
[0052] Embodiment 4, drainage application scenario-Eth
[0053] In this scenario, combined with multiple traffic traction schemes such as SDN drainage, API drainage, proxy drainage, and micro-proxy drainage, traffic is tractioned to traditional virtual security resources, Huawei Cloud, Ali Cloud, and other virtual security resources, to realize effective utilization and security protection of various virtual security resources.
[0054] At this time, there are four drainage modes: SDN drainage (mode A), API drainage (mode B), proxy drainage (mode C), and micro-proxy drainage (mode D); we consider tractioning traffic to three virtual security resources: traditional virtual security resources (resource 1), Huawei Cloud (resource 2), and Ali Cloud (resource 3); define three targets: resource utilization efficiency (expressed in percentage), security protection effect (expressed in score 110), and drainage cost (expressed in specific amount).
[0055] The data collected are as follows:
[0056] Mode A drainage to resource 1: resource utilization efficiency is 75%, security protection effect score is 7, and drainage cost is 500 yuan;
[0057] Mode A drainage to resource 2: resource utilization efficiency is 80%, security protection effect score is 8, and drainage cost is 600 yuan;
[0058] Mode A drainage to resource 3: resource utilization efficiency is 78%, security protection effect score is 7.5, and drainage cost is 550 yuan;
[0059] Mode B drainage to resource 1: resource utilization efficiency is 70%, security protection effect score is 6, and drainage cost is 450 yuan;
[0060] Mode B drainage to resource 2: resource utilization efficiency is 78%, security protection effect score is 7, and drainage cost is 500 yuan;
[0061] Mode B drainage to resource 3: resource utilization efficiency is 75%, security protection effect score is 6.5, and drainage cost is 480 yuan;
[0062] Mode C drainage to resource 1: resource utilization efficiency is 68%, security protection effect score is 6, and drainage cost is 400 yuan;
[0063] Mode C drainage to resource 2: resource utilization efficiency is 72%, security protection effect score is 7, and drainage cost is 450 yuan;
[0064] Way C: diversion to resource 3, resource utilization efficiency 70%, security protection effect score 6.5, diversion cost 420 yuan;
[0065] Way D: diversion to resource 1, resource utilization efficiency 72%, security protection effect score 6.5, diversion cost 420 yuan;
[0066] Way D: diversion to resource 2, resource utilization efficiency 76%, security protection effect score 7, diversion cost 480 yuan;
[0067] Way D: diversion to resource 3, resource utilization efficiency 74%, security protection effect score 6.8, diversion cost 450 yuan;
[0068] First, determine which combination constitutes a relatively optimal solution; way A diversion to resource 2, if there is no other diversion method and resource combination can be at least in one target at the same time, the resource utilization efficiency is not lower than 80%, the security protection effect score is not lower than 8, and the diversion cost is not higher than 600 yuan, it is a relatively optimal solution; after comparison and screening, it is assumed that way A diversion to resource 2, way B diversion to resource 3 and way D diversion to resource 2 are relatively optimal solutions.
[0069] Next, determine the final selection according to the preferences; if the decision considers that the importance of resource utilization efficiency is 0.4, the importance of security protection effect is 0.4, and the importance of diversion cost is 0.2; calculate the comprehensive score of each optimal solution:
[0070] Way A diversion to resource 2 comprehensive score = 0.4*80% + 0.4*8 + 0.2*600 = 32 + 3.2 + 120 = 155.2
[0071] Way B diversion to resource 3 comprehensive score = 0.4*75% + 0.4*6.5 + 0.2*480 = 30 + 2.6 + 96 = 128.6
[0072] Way D diversion to resource 2 comprehensive score = 0.4*76% + 0.4*7 + 0.2*480 = 30.4 + 2.8 + 96 = 129.2
[0073] According to the comprehensive score, way A diversion to resource 2 is selected as the final diversion method.
[0074] Example 5, diversion application scenario-C
[0075] The technical team of the present application newly develops a brand new algorithm (DIESO algorithm) for confirming the self-optimization algorithm of the three parameters of resource utilization efficiency importance, security protection effect importance, and diversion cost importance, which is mutually compatible with the entire diversion matrix data system constructed above (the related parameters of the data model are associated). Specifically, a dynamic importance evaluation and self-optimization algorithm, referred to as DIESO algorithm (we will name the algorithm in English as DynamicImportance Evaluation and Self-optimization Algorithm).
[0076] Regarding the DIESO algorithm, first, the historical diversion data is initialized, including the resource utilization efficiency, security protection effect, and diversion cost data of different diversion methods on different virtual security resources, as well as the related information of business demand and environmental changes. The algorithm steps include: assigning initial importance weights to resource utilization efficiency, security protection effect, and diversion cost, which can be set to 0.3, 0.3, and 0.4 first; on the basis of continuously collecting diversion data and statistical analysis, the influence degree of resource utilization efficiency, security protection effect, and diversion cost on business targets (business stability, cost control, user satisfaction, etc.) in different time periods is calculated, and according to the data analysis results, the importance weights are adjusted according to the following rules: if in a certain time period, the low resource utilization efficiency leads to serious business obstruction or significant cost increase, increase its weight; if the security protection effect is poor, leading to safety accidents or data leakage, increase the weight of security protection effect; if the high diversion cost seriously affects the project budget, reduce its weight; among them, the adjustment range can be determined according to the size of the influence degree (linear or nonlinear adjustment function can be used). At the same time, the balance of self-optimization is also considered: on the one hand, ensure that the sum of the adjusted weights is always 1 to maintain the rationality and comparability of the weights; and further introduce a balance mechanism by setting upper and lower limits of the weights to avoid too large or too small of a weight.
[0077] Example 6, diversion application scenario-D
[0078] Further, we also independently developed the following "magnetic field algorithm", MCGODS algorithm. The algorithm idea is: for the importance of resource utilization efficiency, the importance of security protection effect, the importance of flow cost, they are respectively allocated to a certain magnetic charge, three different elements have different types of magnetic charge, and the number of magnetic charge is adjustable; At the same time, a magnetic field is constructed in the whole data environment, and different types of magnetic charge will produce different forces in this magnetic field, and then through the adjustment of the magnetic field and the force of different magnetic charges, the elements carrying magnetic charges will have a certain flow tendency in the data space, and then we only need to set a "data pocket" at a specific position in the data space according to the current power grid cloud security and flow traction demand, and the data solution finally flowing into the above "data pocket" is the optimal data solution; In different environments, the position of the data pocket can be adjusted as needed.
[0079] Specifically, the following algorithm is obtained: Magnetic Charge Guided Optimal Data Solution Algorithm (English name: MCGODS algorithm). The algorithm steps include:
[0080] Element magnetic charge setting: allocate positive magnetic charge to the importance of resource utilization efficiency, the initial value of the magnetic charge quantity is set to Q1, which can be adjusted within a certain range; allocate negative magnetic charge to the importance of security protection effect, the initial value of the magnetic charge quantity is set to Q2, which can be adjusted within a certain range; allocate neutral magnetic charge to the importance of flow cost, the initial value of the magnetic charge quantity is set to Q3, which can be adjusted within a certain range;
[0081] Magnetic field construction: initialize a three-dimensional data space, and construct a magnetic field in the space; The magnetic field strength B is a function related to the spatial position, that is, B(x, y, z); For positive magnetic charge, the magnetic field produces an attractive force; For negative magnetic charge, the magnetic field produces a repulsive force; For neutral magnetic charge, the magnetic field produces a weak but adjustable force;
[0082] Magnetic charge motion and data flow: according to the action of the magnetic field and the type of the magnetic charge, the elements represented by the magnetic charge produce motion and flow in the data space; The direction and speed of motion are affected by the magnetic field strength, the number of magnetic charges and the type of magnetic charges;
[0083] Data pocket setting and optimal solution determination: according to the current power grid cloud security and flow traction demand, determine the position (x p ,y p ,z p); and, the data pocket's location can be adjusted on demand as the demand changes; after a period of magnetic charge movement and data flow, the data scheme represented by the combination of magnetic charges that eventually flow into the data pocket is determined as the optimal data solution (or as a candidate optimal solution).
[0084] We believe (objectively and factually as well) that the MCGODS algorithm has broad application value, and in specific applications, the specific needs of grid cloud security and traffic traction and their impact on the location of the data pocket, we have carried out generalized data analysis and simulation verification.
[0085] Generally speaking, the specific needs of grid cloud security and traffic traction will significantly affect the determination of the location of the data pocket in the following ways: if the current demand focuses on resource utilization efficiency, the location of the data pocket may be closer to the area where the magnetic charge movement trajectory representing resource utilization efficiency is located; if it is desired to maximize resource utilization efficiency while ensuring a certain level of security protection effect and acceptable drainage cost, the data pocket can be considered to be placed in a location where resource utilization efficiency magnetic charges are easily reached and relatively concentrated; if the focus is on improving the security protection effect, the data pocket can be considered to be placed in a location closer to the active area of the security protection effect magnetic charge; in the period of high-risk network attack threat, the data pocket is more inclined to the location where the magnetic charge combination with higher importance of security protection effect can be collected; when the drainage cost becomes a key limiting factor, the data pocket location will be closer to the area where the magnetic charge movement of the drainage cost is relatively stable and low; in the case of budget constraints, the data pocket will be more inclined to the location where the magnetic charge combination emphasizing the control of drainage cost can be captured.
[0086] Another common possibility is that if the demand is seeking a balance between the three, the location of the data pocket can be considered to be selected in a relatively central location that can simultaneously receive reasonable combinations from different magnetic charges; in the stable operation stage of grid cloud business, it is desired to ensure a certain level of security while not wasting resources excessively, and at the same time, to control costs, the data pocket will be located in a moderate position that can comprehensively attract the three kinds of magnetic charges.
[0087] In addition, secondary modeling of the data pocket can also be performed in applications, that is, a database is constructed to collect the optimal location of the data pocket under different environments and the corresponding element flow situation and fixed as a specific model, so as to facilitate direct calling (or as a data analysis reference, etc.) in the later stage.
[0088] In the above embodiments, the description of each embodiment has its own focus, and the parts not detailed or described in a certain embodiment can be referred to the related description of other embodiments.
[0089] In various embodiments, the hardware implementation of the technology can directly use existing intelligent devices, including but not limited to industrial computers, PC computers, smart phones, handheld computers, floor-standing computers, etc. The input device thereof is preferably a screen keyboard, the data storage and calculation module thereof uses existing memory, calculators, controllers, the internal communication module thereof uses existing communication ports and protocols, and the remote communication thereof uses existing gprs networks, the Internet, etc.
[0090] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual application, the above functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific names of each functional unit and module are only for easy distinction, and do not limit the protection scope of the application. The specific working process of the units and modules in the system can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0091] In the embodiments provided by the present application, it should be understood that the disclosed device / terminal equipment and method can be implemented by other ways. For example, the device / terminal equipment embodiments described above are only schematic, and the division of the modules or units is only a logical function division, and there can be another division way in actual implementation. For example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual coupling or direct coupling or communication connection between the units can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms. The units illustrated as separate components can or can not be physically separate, and the components illustrated as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0092] The various function units in the various embodiments of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit. When the integrated module / unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program includes computer program code, which can be in the form of source code, object code, executable files or some intermediate forms, etc. The computer readable medium can include any entity or device capable of carrying computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.
[0093] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.
Claims
1. A method for pulling traffic from a power grid cloud platform, characterized by: A computing power traffic traction model is constructed in a multi-cloud power grid cloud platform. Traffic is pulled to different security resources through multiple traffic traction paths. The traffic traction paths include SDN diversion, API diversion, proxy diversion, and micro-proxy diversion. The security resources include traditional security resources, Huawei Cloud, Alibaba Cloud, and other cloud security resources. The initialization settings of different diversion paths in the traffic traction model correspond to the basic traffic traction model framework. The various characteristics of the data flow of the power grid cloud platform are represented by a vector to obtain the flow characteristic vector; The traffic feature vector contains data information from different dimensions, including the source IP address, destination IP address, protocol type, traffic volume, and other dimensions. For each specific diversion path, a data module is constructed to make decisions based on traffic characteristics. For SDN diversion, API diversion, proxy diversion, and micro-proxy diversion, the corresponding data module determines whether to adopt this diversion method based on traffic characteristics. The diversion method decisions are then combined to form a diversion matrix containing weight parameters for each diversion method. This diversion matrix directly numerically represents the target diversion direction. Iterative optimization of the diversion matrix corresponds to iterative optimization of traffic traction. Each traffic diversion plan is based not only on traffic characteristics but also on the load of each security resource, the priority of security policies, or historical traffic diversion results. The SDN traffic diversion function dynamically adjusts the traffic diversion strategy according to the network link congestion monitored by the SDN controller; the API traffic diversion function decides whether to give priority to API diversion according to the priority rules set in the security policy data; three factors are defined in the traffic traction process: resource utilization efficiency, security protection effect and diversion cost; the three factors are given initial importance weights, and then the importance weights are adjusted according to the following rules: if the business is seriously obstructed or the cost increases significantly due to low resource utilization efficiency, the resource utilization efficiency weight is increased; if the security protection effect is poor, resulting in security accidents or data leakage, the security protection effect weight is increased; if the diversion cost is too high and seriously affects the project budget, the diversion cost weight is reduced.
2. The method for pulling traffic from a power grid cloud platform according to claim 1, characterized in that: in, The extent of weight adjustment is determined based on the degree of impact on business objectives, using a linear or nonlinear adjustment function.
3. The method for pulling traffic from a power grid cloud platform according to claim 1, characterized in that: in, When adjusting weights, ensure that the sum of the three weights after adjustment is always 1, and set upper and lower limits for the weights.
4. The method for pulling traffic from a power grid cloud platform according to claim 1, characterized in that: When adjusting the weights, positive magnetic charge Q1 is assigned to resource utilization efficiency, negative magnetic charge Q2 is assigned to safety protection effect, and neutral magnetic charge Q3 is assigned to drainage cost; a magnetic field is constructed in the data space, which produces an attractive force for positive magnetic charge and a repulsive force for negative magnetic charge; a weaker and adjustable force is generated for neutral magnetic charge; then, different factors represented by different magnetic charges flow in the data space, and the direction and speed of movement are affected by the magnetic field strength, the number of magnetic charges, and the type of magnetic charges; based on the current needs of power grid cloud security and traffic traction, the position of the data pocket in the data space is determined. After a period of magnetic charge movement and data flow, the data solution represented by the magnetic charge combination that finally flows into the data pocket is determined as the optimal data solution.
Citation Information
Patent Citations
Client channel drainage method based on big data recommendation algorithm
CN111127080A
Virtual network function migration method for digital twinning assisted dynamic resource demand prediction
CN116137593A