Decentralized Network Security Detection Online Edge Task Scheduling Method and System
Through the decentralized online edge task scheduling method of network security detection, distributed edge detection nodes and decentralized communications, the problem of task delay or loss in centralized solutions under high concurrent traffic is solved, achieving more efficient, real-time and stable network attack detection.
Patent Information
- Application Number
- CN202411781778.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-05
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-12-05
AI Technical Summary
The current centralized network security detection scheme is difficult to deal with high concurrent traffic network attacks, resulting in delays or loss of tasks, affecting the timeliness of network security and attack source data detection.
The decentralized online edge task scheduling method of network security detection is adopted. By building distributed edge detection nodes and decentralized communication connections, the tasks are directly processed by edge nodes close to the threat source, realizing task scheduling and resource allocation.
It significantly reduces network latency and improves the real-time and accuracy of network attack detection. If a node lacks resources or fails, tasks can be migrated to other edge nodes in real time to improve system stability and task completion rate.
Smart Images

Figure CN119696852B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and particularly to a decentralized online edge task scheduling method and system for network security detection. Background Art
[0002] Network security detection is a key means to timely discover potential threats and take corresponding measures by monitoring, analyzing, and responding to network activities. Currently, network security detection often adopts a centralized scheme, where edge nodes are only responsible for collecting data and then transmitting it to one or more central servers (or scheduling centers), and the scheduling center completes the core functions of task allocation, resource scheduling, security detection, and threat response. Edge nodes have a strong dependence on the decisions of the central server and usually cannot independently execute task allocation or migration.
[0003] However, the forms of network attacks are evolving towards distributed denial-of-service attacks (DDoS), botnet control, edge device intrusion, etc. These threats often involve a large amount of data streams. The centralized scheme is difficult to handle such high concurrent traffic, and the central server may cause task delays or losses due to overload, resulting in the inability to identify network attacks in a timely and accurate manner, affecting network security. At the same time, these threats often originate from multiple nodes, and the centralized scheme may be difficult to capture key data for detection in places far from the attack source, and it is also easy to generate security blind spots. Summary of the Invention
[0004] In order to solve the technical problem that the current centralized scheme is difficult to cope with new network attacks and affects network security, the present invention provides a decentralized online edge task scheduling method and system for network security detection.
[0005] The technical solutions provided by the embodiments of the present invention are as follows:
[0006] First aspect:
[0007] A decentralized online edge task scheduling method for network security detection provided by an embodiment of the present invention includes:
[0008] S1: Construct distributed edge detection nodes;
[0009] S2: Establish a decentralized communication connection between each of the edge detection nodes;
[0010] S3: Obtain task data streams;
[0011] S4: Extract the task attributes of the current security detection task;
[0012] S5: Search for an edge detection node resource pool within a local range that can process the current security detection task;
[0013] S6: According to the task attributes of the task and the current resource usage status of each edge detection node in the edge detection node resource pool, perform task scheduling and schedule the current security detection task to the target edge detection node;
[0014] S7: In the target edge detection node, allocate computing resources for the current security detection task and execute the current security detection task.
[0015] Second aspect:
[0016] A decentralized online edge task scheduling system for network security detection provided by an embodiment of the present invention includes:
[0017] A processor;
[0018] A memory, on which computer-readable instructions are stored. When the computer-readable instructions are executed by the processor, the decentralized online edge task scheduling method described in the first aspect is implemented.
[0019] Third aspect:
[0020] A computer-readable storage medium provided by an embodiment of the present invention, on which a computer program is stored. When the program is executed by a processor, the decentralized online edge task scheduling method described in the first aspect is implemented.
[0021] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:
[0022] In the present invention, decentralized online edge task scheduling for network security detection is provided. The task is directly processed by the edge node close to the threat source, and key data can be captured in time without transmitting the data to the central server, significantly reducing network latency and improving the real-time performance and accuracy of network attack detection. If the resources of a certain node are insufficient or faulty, the task can be migrated to other edge nodes in real time for continued processing, improving the stability of the system and the task completion rate. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 It is a schematic flowchart of a decentralized online edge task scheduling method for network security detection provided by an embodiment of the present invention;
[0025] Figure 2Schematic diagram of a decentralized online edge task scheduling system for network security detection provided by an embodiment of the present invention. Detailed implementation manners
[0026] The technical solutions in the present invention will be described below with reference to the accompanying drawings.
[0027] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two can be selected.
[0028] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same. "of", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same.
[0029] In the embodiments of the present invention, sometimes subscripts such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meanings they express are the same.
[0030] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.
[0031] Referring to the attached specification Figure 1 shows a schematic flowchart of a decentralized online edge task scheduling method for network security detection provided by an embodiment of the present invention.
[0032] The embodiments of the present invention provide a decentralized online edge task scheduling method for network security detection. This method can be implemented by a decentralized online edge task scheduling device for network security detection, and this decentralized online edge task scheduling device can be a terminal or a server. The processing flow of the decentralized online edge task scheduling method for network security detection can include the following steps:
[0033] S1: Construct distributed edge detection nodes.
[0034] Among them, the distributed edge detection nodes are computing devices deployed at the network edge, close to the data source, and are used to collect, process, and analyze network traffic or task data in real time. These nodes can independently complete some or all of the network security detection tasks and work together through a decentralized communication method.
[0035] S2: Establish a decentralized communication connection among the edge detection nodes.
[0036] Among them, the decentralized communication connection is a network architecture in which each node can directly communicate with other nodes without relying on a central server or a central controller. Specifically, a decentralized communication connection can be established based on a peer-to-peer (P2P) network, a distributed hash table (DHT), and / or blockchain technology.
[0037] S3: Obtain the task data stream.
[0038] Among them, the task data stream refers to the set of data to be processed in the network and its related attributes, and usually includes the input of the task, the computing requirements, and the expected results. The task data stream is particularly important in network security detection and edge computing because it not only contains the content of the task itself, but also contains information related to task scheduling and resource allocation.
[0039] S4: Extract the task attributes of the current security detection task.
[0040] Among them, the task attributes include: the task arrival time, the geographical location of the end user who initiates the task, the task type, the task priority, the task uplink data volume, the task downlink data volume, and the task computing requirement volume.
[0041] Optionally, the task priority can be determined according to the importance of the task, the task complexity, the time sensitivity, etc.
[0042] S5: Search for the edge detection node resource pool that can process the current security detection task within a local range.
[0043] Optionally, the edge detection node resource pool is specifically:
[0044] Ej(k) = Ej ∪ {ei|H(ex,ei) < k, ei ∈ E, ex ∈ Ej}
[0045] Ej = {ei|D(ei,rj) ≤ fi, ei ∈ E}
[0046] Among them, E j (k) represents the edge detection node resource pool of size k that can process the j-th security detection task, k represents the size of the edge detection node resource pool, E j represents the set of edge detection nodes reachable by the signal of the j-th security detection task, ei represents the i-th edge detection node, e x represents the x-th edge detection node, H(e x , e i ), represents the number of communication hops between the x-th edge detection node and the i-th edge detection node, E represents the set of all edge detection nodes, D(e i , r j ), represents the distance between the user node that issues the j-th security detection task and the i-th edge detection node, f i represents the signal reception radius of the i-th edge detection node.
[0047] In the present invention, by defining an edge detection node resource pool and screening candidate nodes based on signal coverage and k-hop communication range, the efficiency, accuracy of task scheduling and the adaptability of the system can be significantly improved. This method is particularly suitable for real-time task processing in a distributed network environment, can better support dynamic and heterogeneous network security detection requirements, and at the same time optimizes the utilization efficiency of network and computing resources.
[0048] S6: According to the task attributes of the task and the current resource usage status of each edge detection node in the edge detection node resource pool, perform task scheduling and schedule the current security detection task to the target edge detection node.
[0049] In a possible implementation manner, S6 specifically includes sub-steps S601 and S602:
[0050] S601: Calculate the utility value of scheduling the current security detection task to each edge detection node in each edge detection node resource pool:
[0051]
[0052] Among them, φ(j, t) represents the utility value of scheduling the j-th security detection task to the i-th edge detection node, W j (t) represents the sum of the priorities of all tasks between the j-th security detection task in the task queue of the i-th edge detection node, w j represents the priority of the i-th security detection task, l ij represents the execution speed when scheduling the j-th security detection task to the i-th edge detection node for execution.
[0053] It should be noted that the calculation of the utility value combines the execution ability of the node (l ij ), the task queue load (W j (t)) and the task priority (w j ) to measure the efficiency of task completion and the satisfaction degree of task priority after scheduling the task to a certain node.
[0054] Optionally, the sum of the priorities of all tasks between the j-th security detection task in the task queue of the i-th edge detection node is W j (t), specifically:
[0055]
[0056] where r y represents the y-th security detection task, and J i (t) represents the task queue of the i-th edge detection node, and w y represents the priority of the y-th security detection task, and π(j, y) represents a Boolean function with a value range of {0, 1}, which is used to determine whether the y-th security detection task arrives at the queue before the j-th security detection task.
[0057] S602: Schedule the current security detection task to the edge detection node with the highest utility value for execution.
[0058] In the present invention, by calculating the utility value to allocate the security detection task to the edge detection node with the highest utility value, not only the task scheduling efficiency is optimized, but also the resource utilization rate and the task completion rate are improved. It can dynamically adapt to changes in node load, ensure the timely processing of high-priority tasks, and at the same time reduce system latency and scheduling conflicts. It is an efficient and flexible distributed task scheduling method.
[0059] In a possible implementation manner, S6 specifically includes sub-steps S601 and S602:
[0060] S601: With the goal of minimizing the weighted task completion time of the average task priority, construct an objective function:
[0061]
[0062] where f represents the objective function, and w j represents the priority of the j-th security detection task, T j represents the completion time of the j-th security detection task, and m represents the total number of tasks.
[0063] Optionally, the completion time of the security detection task is specifically:
[0064] T j = D j + F j + M j
[0065] where D j represents the data transmission time of the j-th security detection task, F j represents the execution time of the j-th security detection task, and M jRepresents the migration time when the j-th security detection task migrates among multiple edge detection nodes.
[0066] S602: According to the objective function, determine the optimal task scheduling scheme through the flower pollination-assisted genetic optimization algorithm and perform task scheduling.
[0067] Among them, the flower pollination-assisted genetic optimization algorithm combines the flower pollination algorithm (FPA) and the genetic algorithm. The flower pollination algorithm is an intelligent optimization algorithm based on the flower pollination behavior in nature, simulating different mechanisms in the plant flower pollination process, especially the long-distance and short-distance pollination methods, and realizing the global and local optimization of the problem through a mathematical model. The genetic algorithm (GA) is a global optimization method based on natural selection and genetic mechanisms, simulating the process of biological evolution, and continuously optimizing the population through genetic operations (selection, crossover, mutation) to find an approximate optimal solution to the problem. The genetic algorithm is good at global search but lacks local search ability. After introducing the flower pollination algorithm, the algorithm can flexibly adjust the search strategy according to the problem complexity and optimization stage.
[0068] Specifically, use the reciprocal of the objective function as the fitness function of the flower pollination-assisted genetic optimization algorithm.
[0069] Initialize the population, which contains multiple individuals, and each individual represents a feasible task scheduling scheme.
[0070] Adopt the elite selection strategy to remove 30% of the individuals with the lowest fitness values to form the first population.
[0071] Perform crossover operations on the individuals in the first population to form the second population:
[0072] Y1 = rand × X1 + (1 - rand) × X2
[0073] Y2 = rand × X2 + (1 - rand) × X1
[0074] Among them, Y1 and Y2 represent new individuals, X1 represents the first parent, X2 represents the second parent, and rand represents a random number between 0 and 1.
[0075] In the present invention, new individuals are generated through the combination of two parents, increasing the diversity of the population and preventing the algorithm from falling into an early local optimum.
[0076] Perform mutation operations on the individuals in the second population to form the third population:
[0077]
[0078] Among them, Y3 represents the new individual, X3 represents the parent, and X max represents the individual with the largest fitness value, and X min represents the individual with the smallest fitness value, and rand represents a random number between 0 and 1.
[0079] In the present invention, the difference between parents is introduced, the information of the optimal and the worst individuals is combined, and the diversity of solutions is adjusted, so as to improve the local solution.
[0080] Update the positions of the individuals in the third population according to the flower pollination optimization algorithm to form the fourth population. Randomly generate a random number, and judge whether the conversion probability is greater than the random number. If so, perform cross-pollination. Otherwise, perform self-pollination.
[0081] In the present invention, cross-pollination enhances the global search ability, and self-pollination refines the local search range. The combination of the two can balance exploration and exploitation and improve the convergence efficiency of the algorithm.
[0082] When performing cross-pollination, update the individual positions according to the Lévy flight mechanism:
[0083]
[0084] Among them, represents the position of the i-th individual at the (t + 1)-th iteration, represents the position of the i-th individual at the t-th iteration, θ represents the step size influence factor, and L represents the step size. represents the global optimal solution at the t-th iteration.
[0085]
[0086] Among them, Γ represents the standard Gamma function, λ represents the exponential parameter, and s represents.
[0087]
[0088] Among them, θ t represents the step size influence factor at the t-th iteration, q represents the scaling coefficient, and T represents the maximum number of iterations.
[0089] When performing self-pollination, update the individual positions according to the golden sine mechanism:
[0090]
[0091] x1 = -π + 2π(1 - τ)
[0092] x2 = -π + 2πτ
[0093] Among them, represents the position of the randomly selected j-th individual at the t-th iteration, represents the position of the randomly selected k-th individual at the t-th iteration, r1 and r2 represent random numbers between 0 and 2π, x1 and x2 represent self-pollination coefficients, and τ represents the golden ratio.
[0094] Merge the third population and the fourth population to form the fifth population.
[0095] Determine whether the current iteration count has reached the maximum iteration count; if so, output the task scheduling scheme represented by the individual with the highest fitness in the fifth population as the optimal task scheduling scheme; otherwise, return for continued iteration.
[0096] In the present invention, by constructing a scheduling model aiming at minimizing the priority-weighted task completion time and using the flower pollination assisted genetic optimization algorithm for solution, the efficiency of task scheduling, resource utilization rate, and system adaptability can be effectively improved. It not only meets the time requirements of critical tasks but also optimizes the performance and robustness of the entire system. It is an efficient task scheduling scheme, especially suitable for dynamic and complex distributed edge computing environments and network security detection scenarios.
[0097] S7: In the target edge detection node, allocate computing resources for the current security detection task and execute the current security detection task.
[0098] In a possible implementation manner, S7 is specifically: in the target edge detection node, according to the following formula, allocate computing resources for the current security detection task and execute the current security detection task:
[0099]
[0100] Among them, v j (t) represents the amount of computing resources allocated to the j-th security detection task at time t, W j (t) represents the sum of the priorities of all tasks between the j-th security detection task in the task queue of the i-th edge detection node, w j represents the priority of the i-th security detection task, β j (t) represents the time sensitivity coefficient of the j-th security detection task at time t, μ represents a parameter controlling the resource allocation dispersion degree, when μ increases, tasks at the end of the task queue but with higher priorities can obtain more computing resources, and W i (t) represents the sum of the priorities of all tasks in the i-th edge detection node.
[0101] It should be noted that high-priority tasks (w j large) and time-critical tasks (β j(t) is dominant in resource allocation and can be completed as soon as possible, thus reducing the response time of critical tasks.
[0102] Furthermore, the parameter μ that controls the resource allocation dispersion can prevent low-priority tasks from being completely deprived of resources. Even if resources are tilted towards high-priority tasks, low-priority tasks will still retain a certain proportion of resource allocation according to the total load of the queue, ensuring the fairness of the system.
[0103] In the present invention, allocating computing resources in the above manner can not only dynamically adapt to the priority and time sensitivity of tasks, but also balance the resource utilization efficiency of nodes and the task completion quality. Its flexibility and efficiency make it particularly suitable for distributed network security detection and edge computing scenarios, and can significantly improve the real-time performance, resource utilization rate and task success rate of the system.
[0104] Optionally, the time sensitivity coefficient is specifically:
[0105]
[0106] where t aj represents the arrival time of the j-th security detection task, and t dj represents the maximum allowable completion time of the j-th security detection task.
[0107] In the present invention, by introducing the time sensitivity coefficient, the urgency of tasks is quantified and dynamically adjusted, enabling the system to identify and prioritize critical tasks in real time. While ensuring the completion of critical tasks, the resource utilization rate of the system is optimized, the task failure rate is reduced, and the overall scheduling efficiency and fairness are improved. This mechanism is particularly suitable for distributed task scenarios with high dynamic and real-time requirements, such as edge computing and network security detection.
[0108] The beneficial effects brought by the technical solution provided in the embodiments of the present invention at least include:
[0109] In the present invention, decentralized online edge task scheduling for network security detection is provided. Tasks are directly processed by edge nodes close to the threat source, which can capture key data in a timely manner without transmitting the data to the central server, significantly reducing network latency and improving the real-time performance and accuracy of network attack detection. If the resources of a certain node are insufficient or faulty, the task can be migrated to other edge nodes in real time for continued processing, improving the stability of the system and the task completion rate.
[0110] In a possible implementation manner, the decentralized online edge task scheduling method for network security detection further includes:
[0111] S8: During the task execution process, based on the utility value enhancement mechanism or the bidding mechanism, perform online migration of the current security detection task.
[0112] In a possible implementation, online migration of the current security detection task is performed based on the utility value enhancement mechanism, which specifically includes:
[0113] During the task execution process, migration evaluation is carried out, and the utility value after migrating the current security detection task to other edge detection nodes is calculated in advance.
[0114] Judge whether the utility value after migrating to other edge detection nodes is greater than the current utility value. If so, perform online migration of the current security detection task.
[0115] In the present invention, online migration is performed based on the utility value enhancement mechanism. By dynamically evaluating and optimizing task allocation, it not only improves the completion efficiency of a single task, but also optimizes the resource utilization rate and overall performance of the system. It can flexibly respond to changes in the system state and ensure the completion of high-priority and urgent tasks. It is an efficient, flexible and reliable task scheduling strategy, especially suitable for dynamic distributed network security detection and edge computing scenarios.
[0116] It should be noted that the migration strategy based on the utility value enhancement mechanism depends on calculating the utility value of the migration target one by one, and may be less efficient in a large-scale resource pool. Therefore, a migration strategy based on the bidding mechanism can be further adopted.
[0117] In a possible implementation, online migration of the current security detection task is performed based on the bidding mechanism, which specifically includes:
[0118] Each edge detection node calculates the bid value according to the task attributes and its own state:
[0119]
[0120] where B i represents the bid value of the i-th edge detection node, φ(j,t) represents the utility value of scheduling the j-th security detection task to the i-th edge detection node, R i represents the remaining computing resource amount of the i-th edge detection node, W j (t) represents the sum of the priorities of all tasks between the j-th security detection task in the task queue of the i-th edge detection node, w j represents the priority of the i-th security detection task, and l ij represents the execution speed when scheduling the j-th security detection task to the i-th edge detection node for execution.
[0121] Migrate the current security detection task to the edge detection node with the highest bid value for execution.
[0122] In the present invention, the online migration strategy based on the bidding mechanism can efficiently optimize task allocation in a dynamic environment by comprehensively considering the utility value and the remaining resource amount. It not only improves the task completion efficiency and system resource utilization rate, but also enhances the elasticity and robustness of the system. Especially in the scenarios of distributed edge computing and network security detection, the bidding mechanism is an optimal solution with both fairness and efficiency.
[0123] Refer to the attached drawings of the specification Figure 2 , which shows a schematic structural diagram of a decentralized online edge task scheduling system for network security detection provided by the present invention.
[0124] The present invention also provides a decentralized online edge task scheduling system 20 for network security detection, which is applied to the above-mentioned decentralized online edge task scheduling method for network security detection, and includes:
[0125] A processor 201.
[0126] A memory 202, on which computer-readable instructions are stored. When the computer-readable instructions are executed by the processor 201, the decentralized online edge task scheduling method in the method embodiment is implemented.
[0127] The decentralized online edge task scheduling system 20 provided by the present invention can execute the above-mentioned decentralized online edge task scheduling method for network security detection and achieve the same or similar technical effects. To avoid repetition, the present invention will not be described in detail herein.
[0128] The beneficial effects brought by the technical solution provided in the embodiment of the present invention at least include:
[0129] In the present invention, decentralized online edge task scheduling for network security detection is provided. Tasks are directly processed by edge nodes close to the threat source, which can capture key data in a timely manner without transmitting the data to the central server, significantly reducing network latency and improving the real-time performance and accuracy of network attack detection. If the resources of a certain node are insufficient or it fails, the task can be migrated to other edge nodes in real time for continued processing, improving the stability of the system and the task completion rate.
[0130] It should be understood that the processor in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0131] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0132] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0133] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood with reference to the context.
[0134] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0135] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0136] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
[0137] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the devices, apparatuses, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0138] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0139] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0140] In addition, the functional units in various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0141] When the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0142] An embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the decentralized network security detection online edge task scheduling method as described in the method embodiment.
[0143] The computer-readable storage medium provided by the present invention can implement the steps and effects of the decentralized network security detection online edge task scheduling method in the above method embodiment. To avoid repetition, the present invention will not elaborate further.
[0144] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include:
[0145] In the present invention, based on Bayes' theorem, the posterior probability of each category label is calculated under a given feature combination, and the category with the maximum posterior probability is used as the final category of the network data asset to be recognized. The network data asset attribution recognition is completed through Bayesian causal reasoning. Bayesian causal reasoning can not only capture the correlation between features and the target, but also pay more attention to the causal relationship between features. The result output by the model has a clear causal chain, which is convenient for interpretation and tracking. The Bayesian causal reasoning model can dynamically update the network structure and parameters without frequently retraining the entire model, can adapt to the changes in the data environment, reduce the calculation and time costs, and help improve the overall efficiency and accuracy of network data asset management.
[0146] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
[0147] The following points need to be explained:
[0148] (1) The accompanying drawings of the embodiments of the present invention only relate to the structures involved in the embodiments of the present invention, and other structures may refer to the general design.
[0149] (2) For clarity, in the drawings used to describe the embodiments of the present invention, the thickness of layers or regions is enlarged or reduced, that is, these drawings are not drawn to actual scale. It can be understood that when an element such as a layer, film, region or substrate is referred to as being "on" or "under" another element, the element can be "directly" on or under the other element or there can be intervening elements.
[0150] (3) Without conflict, the embodiments of the present invention and the features in the embodiments can be combined with each other to obtain new embodiments.
[0151] The above is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. The protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A decentralized network security detection online edge task scheduling method, characterized in that: include: S1: Build distributed edge detection nodes; S2: Establishing a decentralized communication connection between each of the edge detection nodes; S3: Get task data stream; S4: extract the task attributes of the current security detection task; S5: Searching for an edge detection node resource pool in a local range that can process the current security detection task; S6: Perform task scheduling according to the task attributes of the task and the current resource usage status of each edge detection node in the edge detection node resource pool, and schedule the current security detection task to the target edge detection node; S7: In the target edge detection node, allocating computing resources for the current security detection task and executing the current security detection task; The edge detection node resource pool is specifically: Among them, E j (k) represents the edge detection node resource pool of size k that can process the j-th security detection task, k represents the size of the edge detection node resource pool, E j represents the set of edge detection nodes that can be reached by the signal of the jth safety detection task, e i represents the i-th edge detection node, e x represents the xth edge detection node, H(e x ,e i ) represents the number of communication hops between the xth edge detection node and the ith edge detection node, E represents the set of all edge detection nodes, D(e i ,r j ) represents the distance between the user node that issues the jth security detection task and the ith edge detection node, f i represents the signal receiving radius of the i-th edge detection node.
2. The decentralized network security detection online edge task scheduling method according to claim 1 is characterized in that: The task attributes include: task arrival time, geographic location of the terminal user initiating the task, task type, task priority, task uplink data volume, task downlink data volume, and task computing requirement.
3. The decentralized network security detection online edge task scheduling method according to claim 1 is characterized in that: The S6 specifically includes: S601: Calculate the utility value of scheduling the current security detection task to each edge detection node in each edge detection node resource pool: Among them, φ(j,t) represents the utility value of scheduling the jth security detection task to the i-th edge detection node, W j (t) represents the sum of the priorities of all tasks in the task queue of the i-th edge detection node that are ranked between the j-th security detection task, and w j represents the priority of the jth security detection task, l ij It represents the execution speed when the j-th security detection task is scheduled to the i-th edge detection node for execution; S602: Schedule the current security detection task to the edge detection node with the highest utility value for execution.
4. The decentralized network security detection online edge task scheduling method according to claim 1 is characterized in that: The S6 specifically includes: S601: With the goal of minimizing the average task priority weighted task completion time, construct an objective function: Where f represents the objective function, w j represents the priority of the jth safety detection task, T j represents the completion time of the jth safety detection task, and m represents the total number of tasks; S602: According to the objective function, an optimal task scheduling scheme is determined through a flower pollination-assisted genetic optimization algorithm to perform task scheduling.
5. The decentralized network security detection online edge task scheduling method according to claim 1 is characterized in that: The S7 is specifically: In the target edge detection node, computing resources are allocated to the current security detection task according to the following formula to execute the current security detection task: Among them, v j (t) represents the amount of computing resources allocated to the jth security detection task at time t, W j (t) represents the sum of the priorities of all tasks in the task queue of the i-th edge detection node that are ranked between the j-th security detection task, and w j represents the priority of the jth security detection task, β j (t) represents the time sensitivity coefficient of the jth security detection task at time t, μ represents the parameter for controlling the dispersion of resource allocation, and when μ increases, the tasks at the end of the task queue but with higher priority can obtain more computing resources, W i (t) represents the sum of the priorities of all tasks in the i-th edge detection node.
6. The decentralized network security detection online edge task scheduling method according to claim 1 is characterized in that: Also includes: S8: During the task execution process, the current security detection task is migrated online based on the utility value enhancement mechanism or the bidding mechanism.
7. The decentralized network security detection online edge task scheduling method according to claim 6 is characterized in that: Based on the utility value enhancement mechanism, the current security detection task is migrated online, including: During the task execution, migration evaluation is performed to pre-calculate the utility value after migrating the current security detection task to other edge detection nodes; Determine whether the utility value after migrating to other edge detection nodes is greater than the current utility value; if so, perform online migration of the current security detection task.
8. The decentralized network security detection online edge task scheduling method according to claim 6 is characterized in that: The current security detection task is migrated online based on the bidding mechanism, including: Each edge detection node calculates the competitive value based on the task attributes and its own status: Among them, B i represents the competitive value of the i-th edge detection node, φ(j,t) represents the utility value of scheduling the j-th security detection task to the i-th edge detection node, and R i represents the remaining computing resources of the ith edge detection node, W j (t) represents the sum of the priorities of all tasks in the task queue of the i-th edge detection node that are ranked between the j-th security detection task, and w j represents the priority of the jth security detection task, l ij It represents the execution speed when the j-th security detection task is scheduled to the i-th edge detection node for execution; Migrate the current security detection task to the edge detection node with the highest competitive value for execution.
9. A decentralized network security detection online edge task scheduling system, characterized in that: include: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the decentralized network security detection online edge task scheduling method according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Real-time image processing method and system based on edge calculation
CN118467181A
Computing task distribution system based on cloud side-end collaborative edge gateway
CN118945125A