A diagnostic test method based on computer platform Vspy

By adopting diagnostic testing methods based on the Vspy platform in the virtual environment, configuring enhanced isolation strategies, generating dynamic security rules, monitoring operation behaviors in real time and verifying test results, the problem of horizontal spread risk in the virtual environment isolation mechanism is solved, and the stability and security of the system are significantly improved.

CN119718963BActive Publication Date: 2025-06-06JAINGXI ISUZU AUTOMOBILE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510227760.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-06
Estimated Expiration
2045-02-28

AI Technical Summary

Technical Problem

The existing virtual environment isolation mechanism has a risk of horizontal spread during the testing process, especially in the case of virtual machine monitor vulnerabilities, resource sharing vulnerabilities, network topology problems and incomplete isolation policies, which may cause malicious code or misconfiguration to spread to other virtual environments, affecting system stability and security.

Method used

The diagnostic testing method based on the computer platform Vspy is adopted, and by configuring a strengthened virtual environment isolation strategy, security rules are generated and dynamically adjusted, operating behaviors in the virtual environment are monitored in real time, test results are recorded and compared with preset standards to reduce the risk of horizontal spread.

Benefits of technology

It significantly improves the stability and security of the virtual environment, reduces the impact of malicious code or misconfiguration on other virtual environments or main systems, reduces the risks caused by resource contention or conflict, ensures the security of the virtual environment communication, and realizes timely detection and response of security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119718963B_ABST
    Figure CN119718963B_ABST
Patent Text Reader

Abstract

The present invention discloses a diagnostic test method based on a computer platform Vspy, and relates to the technical field of computer virtualization. The method comprises S1, configuring a reinforcement strategy based on a virtual environment isolation mechanism to prevent the risk of lateral diffusion during a test process, S2, generating security rules and dynamically adjusting the virtual environment boundary at runtime, S3, starting a diagnostic test process and monitoring the operation behavior in the virtual environment in real time, and S4, recording the test results and comparing and verifying them with preset standards. The diagnostic test method based on the computer platform Vspy can minimize the risk of system failures caused by security vulnerabilities or configuration problems in a complex test environment where multiple users or multiple processes run in parallel, thereby improving the stability and reliability of the entire system, and strengthening the configuration of the virtual environment isolation mechanism to solve the problem of lateral diffusion risks during the test process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer virtualization, and in particular to a diagnostic test method based on a computer platform Vspy. Background Art

[0002] With the rapid development of information technology, virtualization technology has been widely used in many fields, especially in computer security, network testing, diagnostic testing, etc. Virtual environments are widely used due to their flexibility and isolation. In a virtual environment, the Vspy platform, as a diagnostic tool, helps developers test and debug by simulating different operating environments. A core feature of virtualization technology is the ability to provide virtual machines or containers to create isolated execution environments. In theory, different instances or containers in a virtual environment should be independent of each other, and this isolation can effectively prevent malicious code or misconfiguration from affecting other systems during the test process. However, in actual testing and applications, the isolation mechanism of the virtual environment often has some shortcomings, resulting in the risk of lateral diffusion, that is, problems or security vulnerabilities in a virtual machine or container during the test process may spread to other virtual environments through certain channels, affecting the stability and security of the entire system.

[0003] The existing virtual environment isolation mechanism mainly achieves isolation through the following methods: hardware layer virtualization, by using hardware virtualization technology to provide an independent virtual hardware environment for each virtual machine, which can theoretically isolate resource conflicts and data access problems between different virtual machines; operating system layer virtualization, using containerization technology to provide relatively lightweight isolation, this method mainly achieves independence between virtual environments through kernel resource restrictions and namespace isolation; network isolation, by configuring virtual networks and firewall policies, ensure that network communications between different virtual environments are properly controlled to prevent malicious traffic or test data from spreading through the network. However, the existing virtual environment isolation mechanism is not completely insurmountable, especially in some specific scenarios, the risk of lateral spread still exists. These risks mainly include: virtual machine monitor vulnerabilities. The virtualization platform itself may have undiscovered vulnerabilities. Hackers or malware can attack through the virtual machine monitor, thereby breaking through the isolation boundaries between virtual machines and causing lateral spread; resource sharing vulnerabilities. In the virtualization platform, virtual machines often share the hardware resources of the physical host, such as memory, hard disk, CPU, etc. Attackers may affect other virtual environments through resource sharing vulnerabilities; network topology problems. Improperly configured virtual networks may result in too loose network access between different virtual machines, allowing malicious traffic or data to spread between multiple virtual machines, causing lateral attacks; imperfect isolation strategies. The isolation strategies of some virtualization platforms may be too loose and fail to strictly restrict the behaviors of different virtual environments, which can be easily exploited by attackers for lateral attacks. Summary of the invention

[0004] The purpose of the present invention is to provide a diagnostic test method based on a computer platform Vspy, which strengthens the configuration of a virtual environment isolation mechanism to solve the risk of lateral diffusion during the test process.

[0005] To achieve the above object, the present invention provides the following technical solution: a diagnostic test method based on a computer platform Vspy, the method comprising:

[0006] S1. Configure a reinforcement strategy based on the virtual environment isolation mechanism to prevent the risk of lateral spread during the test process, including evaluating the potential lateral spread risk by calculating the threat level of the virtual environment in the current test of the virtual environment, adjusting the isolation strength of the virtual environment of the virtual environment, and calculating the psychological boundary strength value. The specific formula is: B = A × C / D;

[0007] Among them, B represents the psychological boundary strength value, A represents the threat level of the virtual environment in the current test, C represents the isolation strength of the virtual environment, and D represents the interaction frequency between different virtual environments;

[0008] S2. Generate security rules and dynamically adjust the boundaries of the virtual environment at runtime, including generating preliminary security rules based on the load and status of the current virtual environment, inferring the existing security threats by monitoring the system's operating data, and dynamically adjusting the boundaries of the virtual environment to prevent disordered security incidents. The specific formula for calculating the effect of security rule adjustment is: ;

[0009] Among them, ΔS represents the adjustment range of the corresponding security rules, dQ represents the resource adjustment value in the virtual environment, T represents the pressure of the virtual environment, and d represents the small change amount;

[0010] S3, start the diagnostic test process and monitor the operation behavior in the virtual environment in real time;

[0011] S4. Record the test results and compare and verify them with the preset standards.

[0012] Preferably, S3 includes predicting resource allocation and cost effects caused by different operation behaviors in the virtual environment when starting the diagnostic test process, monitoring the operation behaviors in the virtual environment in real time, and calculating the effect of each operation corresponding to the operation behavior in the virtual environment, and the specific formula is: U=R / E;

[0013] Among them, U represents the effect of the operation behavior in the corresponding virtual environment, R represents the amount of resources allocated in the virtual environment, and E represents the operation cost of the virtual environment;

[0014] Prioritize actions based on their utility, and optimize behavior during testing by adjusting resource allocation and reducing operating costs within the virtual environment.

[0015] Preferably, S4 includes recording the test steps in the virtual environment in real time, including the operation efficiency and time of each virtual environment, and calculating the speed of the test process, the specific formula being V=X / Y;

[0016] Among them, V represents the passing speed of the test results, X represents the total number of steps completed by the test, and Y represents the time taken for the test;

[0017] Preset the standard speed, compare the calculated test result passing speed with the preset standard speed, ensure that the test meets the expected passing speed, adjust the test process, and ensure that all test steps can be completed within the scheduled time.

[0018] Preferably, the security rules generated in S2 include access control rules, resource isolation rules and dynamic network policies.

[0019] Preferably, the real-time monitoring of operation behaviors in the virtual environment in S3 includes dynamic changes in resource allocation in the virtual environment, process call frequency, and detection of abnormal operations.

[0020] Preferably, the test results recorded in S4 include the timestamp of the operation behavior, resource usage data, and deviation information from a preset standard.

[0021] Preferably, the access control rules in S2 include role-based access control and attribute-based access control policies, which are used to limit the scope of permissions of different users or processes in the virtual environment.

[0022] Preferably, the resource isolation rules in S2 limit the maximum allocation of CPU, memory and storage resources in the virtual environment.

[0023] Preferably, the dynamic network strategy in S2 includes dynamically adjusting the network bandwidth allocation and communication path spacing of the virtual environment according to the real-time traffic load.

[0024] Preferably, the detection of abnormal operation in S3 also includes generating alarm information in real time and taking restrictive operations on the virtual environment according to the degree of abnormality.

[0025] It can be seen from the above technical solution that the present invention has the following beneficial effects:

[0026] The diagnostic test method based on the computer platform Vspy configures a hardening strategy based on the virtual environment isolation mechanism to prevent the risk of lateral diffusion during the test process, generates security rules and dynamically adjusts the virtual environment boundary at runtime, starts the diagnostic test process and monitors the operation behavior in the virtual environment in real time, records the test results and compares and verifies with the preset standards, reduces the impact of potential threats such as malicious code and misconfiguration on other virtual environments or the main system, thereby improving the stability and security of the overall system and avoiding unnecessary risks caused by resource contention or conflict. Especially in complex test scenarios with multiple users and multiple tasks, it can better reflect the efficiency and reliability of resource allocation, prevent the spread of unauthorized traffic or the spread of malicious attacks, thereby ensuring the communication security of the virtual environment and realizing the timely discovery and response of security threats. Compared with the existing passive defense isolation mechanism, this method has higher initiative and flexibility, effectively reduces the risk of lateral diffusion, and retains the flexibility of virtualization technology while ensuring the isolation of the virtual environment, and can adapt to different test requirements and complex scenarios. Especially in areas with high security requirements such as network testing and diagnostic testing, it has better application value. It can minimize the risk of system failures caused by security vulnerabilities or configuration problems in complex testing environments where multiple users or multiple processes run in parallel, thereby improving the stability and reliability of the entire system. It can also strengthen the configuration of the virtual environment isolation mechanism to solve the risk of lateral spread during the testing process. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION

[0028] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0029] like Figure 1 As shown, the present invention provides a technical solution: a diagnostic test method based on a computer platform Vspy, the method comprising:

[0030] S1. Configure a reinforcement strategy based on the virtual environment isolation mechanism to prevent the risk of lateral spread during the test process, including evaluating the potential lateral spread risk by calculating the threat level of the virtual environment in the current test of the virtual environment, adjusting the isolation strength of the virtual environment of the virtual environment, and calculating the psychological boundary strength value. The specific formula is: B = A × C / D;

[0031] Among them, B represents the psychological boundary strength value, A represents the threat level of the virtual environment in the current test, C represents the isolation strength of the virtual environment, and D represents the interaction frequency between different virtual environments;

[0032] S2. Generate security rules and dynamically adjust the boundaries of the virtual environment at runtime, including generating preliminary security rules based on the load and status of the current virtual environment, inferring the existing security threats by monitoring the system's operating data, and dynamically adjusting the boundaries of the virtual environment to prevent disordered security incidents. The specific formula for calculating the effect of security rule adjustment is: ;

[0033] Among them, ΔS represents the adjustment range of the corresponding security rules, dQ represents the resource adjustment value in the virtual environment, T represents the pressure of the virtual environment, and d represents the small change amount;

[0034] S3, start the diagnostic test process and monitor the operation behavior in the virtual environment in real time;

[0035] S4. Record the test results and compare and verify them with the preset standards.

[0036] Specifically, the risk of lateral diffusion is tested according to Table 1:

[0037] Table 1

[0038]

[0039] Among them: A represents the threat level (a score of 1 to 10), C represents the isolation strength of the virtual environment (a score of 1 to 10), and D represents the frequency of interaction between virtual environments (times / hour);

[0040] From the test data, we can see that the greater the psychological boundary strength (B value), the stronger the isolation strength of the virtual environment is, and the lower the risk of preventing lateral spread.

[0041] The core of this implementation is to combine the real-time monitoring and dynamic adjustment mechanism of the virtual environment to achieve all-round protection of test security. In step S1, by calculating the psychological boundary strength value (B), the threat level, isolation strength and interaction frequency of the virtual environment are quantitatively analyzed, the potential risks of the current virtual environment are comprehensively evaluated, and a scientific basis is provided for subsequent adjustment strategies. In step S2, security rules are generated and the boundaries of the virtual environment are dynamically adjusted. By monitoring the load, operating status and resource pressure of the virtual environment, possible security threats are accurately identified and inferred. By adjusting ΔS (the adjustment range of the security rules), the isolation strength and boundary range of the virtual environment can be dynamically optimized to ensure the stability and security of the environment. The real-time monitoring function in step S3 further strengthens the tracking of the operation behavior of the virtual environment, can quickly respond to abnormal operations or potential risks, and ensure the orderliness of the test process. Finally, through the data recording and comparison verification in step S4, the reliability and consistency of the test results are ensured, providing comprehensive data support for subsequent optimization. The synergy of this series of steps makes the entire test process highly secure, flexible and robust. This implementation can significantly improve the security and reliability of the virtual environment test process. By calculating the psychological boundary strength value (B), the risk of lateral diffusion can be effectively quantified, and the spread of risk can be reduced by dynamically adjusting the isolation strength. Compared with the traditional fixed rule isolation method, this method can dynamically adjust the boundary strength and safety rules according to the real-time monitoring data, significantly improving the adaptability of the system, especially in high-pressure or complex interaction scenarios. In addition, the adjustment mechanism of ΔS optimizes the resource allocation strategy, reduces unnecessary resource waste, and reduces the system operation cost. With the support of real-time monitoring, abnormal behavior can be quickly identified to avoid security incidents. At the same time, the recording and verification function of the test results not only improves the accuracy and credibility of the data, but also provides a reliable basis for subsequent system optimization and improvement. Overall, this method achieves comprehensive optimization of security, stability and efficiency, and provides an innovative and practical technical solution for virtual environment diagnostic testing.

[0042] S3 includes predicting the resource allocation and cost effects caused by different operation behaviors in the virtual environment when starting the diagnostic test process, monitoring the operation behaviors in the virtual environment in real time, and calculating the effect of each operation corresponding to the operation behavior in the virtual environment. The specific formula is: U = R / E;

[0043] Among them, U represents the effect of the operation behavior in the corresponding virtual environment, R represents the amount of resources allocated in the virtual environment, and E represents the operation cost of the virtual environment;

[0044] Prioritize actions based on their utility, and optimize behavior during testing by adjusting resource allocation and reducing operating costs within the virtual environment.

[0045] Specifically, the resource allocation and cost optimization are tested according to Table 2:

[0046] Table 2

[0047]

[0048] Where: R is the amount of allocated resources (e.g., memory allocation, MB), E is the cost of the operation (unit cost);

[0049] From the test data, we can see that the larger the utility value (U), the more efficient the resource allocation and the better the operating benefits.

[0050] The core principle of this implementation is to quantify and analyze the utility of the operation behavior in the virtual environment through the formula U=R / E, and take the rationality of resource allocation and the degree of optimization of operation cost as the core indicators, so as to dynamically optimize the behavior pattern in the test process. When starting the diagnostic test process, predict the resource consumption and cost changes that may be caused by each operation behavior in the virtual environment, combine real-time monitoring means, record the actual effect of the operation behavior, and calculate its utility value U according to the formula. For operation behaviors with low utility, adjust the resource allocation strategy to reduce resource waste, or optimize the operation process to reduce the operation cost E, so as to achieve the improvement of overall utility. In addition, by dynamically evaluating the priority of virtual environment operations, the efficiency of resource allocation and the rationality of test behavior are ensured, and the operating efficiency and safety of the system are further improved. This implementation can effectively optimize the resource allocation in the virtual environment, reduce the waste of resources and cost increase caused by inefficient operation behavior, thereby significantly improving the efficiency and safety of the test process. By calculating the utility value U of the operation behavior in real time, inefficient operations can be accurately identified and adjusted, the test behavior pattern can be optimized, and resource utilization can be maximized. At the same time, the dynamic adjustment of priority mechanism ensures that resources are tilted towards efficient operation behaviors, further improving the overall performance of the test in the virtual environment. In addition, this method can also reduce operational redundancy and resource conflicts during the test process, reduce system operating costs, enhance the adaptability and reliability of the virtual environment, and provide an efficient solution for testing in complex environments.

[0051] S4 includes real-time recording of the test steps in the virtual environment, including the operating efficiency and time of each virtual environment, and calculating the speed of the test process, the specific formula is V = X / Y;

[0052] Among them, V represents the passing speed of the test results, X represents the total number of steps completed by the test, and Y represents the time taken for the test;

[0053] Preset the standard speed, compare the calculated test result passing speed with the preset standard speed, ensure that the test meets the expected passing speed, adjust the test process, and ensure that all test steps can be completed within the scheduled time.

[0054] Specifically, the test passing speed is tested according to Table 3:

[0055] Table 3

[0056]

[0057] The optimized test speed is improved to ensure that the test is completed successfully within the specified time;

[0058] This embodiment quantifies the passing speed of each test process by recording the test steps in the virtual environment in real time, and evaluates the test efficiency based on the formula V=X / Y. Among them, the total number of steps X completed by the test and the time Y used for the test are used as key parameters. By comparing the calculated passing speed V with the preset standard speed, the test process is analyzed to see if there is an efficiency deviation. When the actual passing speed is lower than the standard speed, the test efficiency is improved by adjusting the execution order of the test steps or optimizing the allocation of test resources to ensure that the test is completed on time. In addition, the real-time recording function provides detailed time and efficiency data for each test step, which helps to find bottlenecks in the test process and optimize them. By monitoring and adjusting the test speed, it can dynamically adapt to complex virtual environment changes and improve the overall test efficiency and accuracy of the system. This embodiment can effectively improve the efficiency of the test process in the virtual environment, and ensure that the test can be completed according to the predetermined time node by real-time monitoring and adjustment of the test passing speed. Compared with the traditional static test evaluation method, this method can dynamically capture the efficiency changes in the test process, quickly respond to bottleneck problems in the test, and improve the fluency and accuracy of the test process. In addition, the quantitative analysis method of the formula V=X / Y makes the efficiency evaluation of the test process more accurate, which helps to optimize the test time and steps, thereby reducing resource waste and operational redundancy. By comparing and analyzing with the preset standard speed, potential problems of the test plan in the virtual environment can also be discovered, providing data support for subsequent optimization, and further improving the stability and reliability of the test.

[0059] The security rules generated in S2 include access control rules, resource isolation rules and dynamic network policies. This implementation method ensures the security and stability of the virtual environment by generating multi-level security rules. Specifically, the access control rules are used to define the permission level of users or processes to resources in the virtual environment, restrict unauthorized access, and ensure that system resources are not maliciously or erroneously operated. Resource isolation rules use virtualization technology to logically isolate resources to prevent resource conflicts or information leakage between different virtual environments, thereby enhancing the fault tolerance and reliability of the system. Dynamic network policies combine real-time network traffic and behavior monitoring to dynamically adjust network communications to prevent external attacks or malicious data transmission, while optimizing the efficiency of network resource use. These three types of rules complement each other and work together in the virtual environment, providing a powerful security protection mechanism for the virtual environment during the test process, while ensuring the efficiency and flexibility of system operation. This implementation method significantly improves the security and resource utilization efficiency of the virtual environment. Access control rules reduce the risk of misoperation and malicious operation by limiting resource access rights, and fundamentally enhance the security protection capabilities of the system. Resource isolation rules effectively solve the resource competition problem that may occur between different virtual environments, and ensure the independence and efficiency of resource use. Dynamic network strategies can detect and respond to potential threats in the network in real time, optimize network resource allocation, and ensure the stability and security of communications during testing. This multi-level security rule design not only improves the overall operating efficiency of the virtual environment, but also enhances the robustness and adaptability of the system, enabling it to cope with complex and changing testing requirements while reducing operating costs.

[0060] Specifically, the implementation effects of access control rules, resource isolation rules, and dynamic network policies are verified according to Table 4:

[0061] Table 4

[0062]

[0063] Test data shows that after implementing dynamic network policies and resource isolation rules, the number of threats is reduced, the response time is shortened, and the overall security protection capability is improved.

[0064] The real-time monitoring of the operation behavior in the virtual environment in S3 includes the dynamic changes of resource allocation in the virtual environment, the process call frequency, and the detection of abnormal operations. This embodiment ensures the efficiency and safety of the test process by monitoring the operation behavior in the virtual environment in multiple dimensions. First, by monitoring the dynamic changes of resource allocation, the resource usage in the virtual environment is tracked in real time, whether there are abnormal fluctuations or uneven distribution of resource allocation, and the resource usage strategy is adjusted to optimize system performance. Secondly, the monitoring of process call frequency can evaluate the execution efficiency of each process in the system, and help quickly locate processes with abnormally high or low call frequencies, which are usually the manifestation of performance bottlenecks or potential problems. Finally, the abnormal operation detection function combines behavioral analysis and rule matching mechanisms to quickly identify possible illegal operations, unexpected behaviors or potential attack behaviors in the virtual environment, and ensure the safety and stability of the system by triggering alarms or automatic isolation mechanisms. This multi-dimensional monitoring method can not only accurately capture the dynamic changes in the virtual environment, but also achieve timely response to abnormal situations, providing comprehensive protection for testing. This embodiment effectively improves the management efficiency and security of the virtual environment through comprehensive monitoring of resource allocation, process call frequency and abnormal operations. Dynamic monitoring of resource allocation can optimize resource utilization, reduce resource waste, and avoid system performance degradation caused by uneven allocation. Monitoring of process call frequency helps quickly identify performance bottlenecks and potential problems, improving the efficiency and accuracy of the test process. The detection function of abnormal operations enhances the security of the system, and can promptly detect and prevent potential violations or attacks, reducing system security risks. This multi-dimensional monitoring mechanism not only improves the operating efficiency of the virtual environment, but also enhances the robustness of the system, providing a more intelligent means of protection for testing in complex environments.

[0065] The system can generate an alarm and perform restrictive operations when abnormal operations are detected. Specifically, Table 5 shows the number of abnormal operations detected and the alarm response time data:

[0066] Table 5

[0067]

[0068] From the data in Table 5, we can see that the detection and alarm generation speed of abnormal operations are improved, the execution time of restricted operations is shortened, and potential security threats are effectively prevented.

[0069] The test results recorded in S4 include the timestamp of the operation behavior, resource utilization data, and deviation information from the preset standard. This embodiment ensures the traceability of the test process and the accuracy of the results by recording the detailed data of the operation behavior. First, the timestamp of the operation behavior can accurately record the occurrence time of each operation, providing a reliable time node basis for subsequent test analysis and problem tracking. Secondly, the resource utilization data can reflect the resource allocation and usage in the virtual environment in real time, including key indicators such as CPU, memory, bandwidth, etc. By monitoring and recording these data, the changing trend and peak problem of resource utilization can be deeply analyzed. Finally, the deviation information from the preset standard can intuitively quantify the gap between the test results and the ideal goal, providing a key reference for evaluating the efficiency and accuracy of the test process. This comprehensive data recording method can not only meet the archiving requirements of the test results, but also provide a scientific basis for the optimization and improvement of the test process. This embodiment realizes the accurate recording and comprehensive analysis of the test results by recording the timestamp, resource utilization data and deviation information of the operation behavior. The timestamp data provides strong support for operation tracking and problem location, and improves the traceability and analysis depth of the test process. Detailed records of resource usage data can help technicians identify resource bottlenecks during testing, improve resource utilization, and optimize the operating efficiency of the virtual environment. The recording of deviation information makes the comparison between test results and expected goals more intuitive, providing key data support for improving the test process and optimizing performance. Overall, this recording method provides a scientific and comprehensive data foundation for virtual environment diagnostic testing, significantly improving the reliability and accuracy of the test.

[0070] The access control rules in S2 include role-based access control and attribute-based access control strategies, which are used to limit the scope of permissions of different users or processes in the virtual environment. This implementation method realizes accurate management of user and process permissions in the virtual environment by adopting role-based access control and attribute-based access control strategies. Role-based access control rules allocate permissions according to the role of the user or process. For example, administrators, ordinary users and guests have different resource access scopes and operation permissions, respectively, so as to ensure that the resource access and operation of the system meet the scope of responsibilities of the user role. The attribute-based access control strategy is based on dynamic attributes, combined with contextual information such as the operation time, geographical location, and device type of the user or process, to perform more detailed dynamic control of permissions. For example, a specific operation may only be allowed to be completed by a specific device within a specific time period. The combination of the two access control strategies can not only meet the maintainability of static rules, but also have the flexibility of dynamic adjustment, ensuring that the access rights of resources in the virtual environment are strictly allocated according to demand, thereby improving the security and resource utilization efficiency of the system. This implementation method realizes comprehensive and accurate management of permission allocation in the virtual environment by introducing role-based and attribute-based access control rules. RBAC rules simplify the configuration and management of permissions, and can quickly define and modify role-based permission allocation, greatly improving the maintainability of the system. ABAC rules use dynamic attributes to achieve flexible adjustment of permissions in complex scenarios, enhancing the dynamic adaptability of the system, especially in highly changing test environments. The combination of the two control methods not only ensures the efficiency of permission management, but also significantly improves the security of resource access, reduces security risks caused by improper permission allocation, and optimizes the operational stability of the virtual environment. In addition, this method can adapt to complex virtual environment architectures with multiple users and processes, providing strong security guarantees for virtual environment diagnostic testing.

[0071] The resource isolation rules in S2 limit the maximum allocation of CPU, memory and storage resources in the virtual environment. This implementation method sets strict allocation restrictions on the CPU, memory and storage resources in the virtual environment by setting resource isolation rules to avoid resource competition and overload problems. For CPU resources, the maximum CPU usage percentage or core number of each virtual environment is defined to ensure that multiple virtual environments can run evenly in high-load scenarios and prevent a single environment from consuming too much computing power. For memory resources, by setting the maximum threshold of memory usage, system performance degradation or crash caused by memory leaks or over-allocation is avoided. For storage resources, the disk space usage of the virtual environment is limited to ensure the reasonable allocation of storage resources and prevent insufficient storage in other virtual environments due to excessive occupation. In addition, these restrictions can be dynamically adjusted according to the priority and operation requirements of the virtual environment. For example, a high-priority environment can reserve more resources, while a low-priority environment automatically reduces the amount of resource allocation when the load is high. The implementation of this resource isolation rule can significantly improve the stability and operation efficiency of the virtual environment, while providing safe and reliable resource guarantees for the testing process. This implementation method achieves efficient resource management and isolation by limiting the maximum allocation of CPU, memory and storage resources in the virtual environment, significantly improving the operational stability of the virtual environment. The allocation limit of CPU resources avoids performance degradation caused by resource competition in high-load scenarios; the memory allocation limit can effectively prevent memory overflow or resource shortage, improving the reliability of the system; the storage resource limit ensures the rational use of disk space and avoids environmental anomalies caused by insufficient storage. Through the implementation of resource isolation rules, each virtual environment can achieve independent operation, avoiding mutual influence caused by resource contention, and can dynamically adapt to test requirements, further optimizing resource utilization efficiency. This rule design not only meets the resource management needs in complex test scenarios, but also provides a strong security guarantee for the operation of the virtual environment.

[0072] The dynamic network strategy in S2 includes dynamically adjusting the network bandwidth allocation of the virtual environment and the isolation of the communication path according to the real-time traffic load. This embodiment manages the traffic load in the virtual environment through dynamic network strategy to ensure the efficient allocation of network resources and the safe isolation of communication. The dynamic network strategy first monitors the real-time traffic in the virtual environment and analyzes the network load of each virtual environment instance. When the traffic load of a virtual environment reaches the set threshold, its network bandwidth allocation is dynamically adjusted, such as increasing the bandwidth upper limit of the high-priority virtual environment, limiting the bandwidth occupancy of the low-priority or non-critical virtual environment, and avoiding network congestion problems caused by resource competition. At the same time, the dynamic network strategy can set isolated communication paths according to the communication requirements of different virtual environments to prevent cross-communication or unauthorized communication between virtual environments. For example, the virtual environment communication of critical tasks can be isolated through a dedicated virtual network path, while ordinary tasks can share a public network path. This dynamic adjustment and isolation mechanism not only improves the communication efficiency of the virtual environment, but also significantly improves network security and reduces the potential risks brought by unexpected communication. This embodiment optimizes the network resource allocation and communication path management of the virtual environment through dynamic network strategy, significantly improving the operating efficiency and security of the system. Dynamically adjusting network bandwidth according to real-time traffic load can effectively avoid wasting network resources, alleviate network congestion problems, and ensure communication stability and efficiency of high-priority virtual environments. The isolation mechanism of communication paths prevents unauthorized communication between virtual environments, reduces potential data leakage and security threats, and enhances the security and reliability of the entire network. In addition, this strategy has real-time response capabilities, can adapt to complex and changing test requirements, maximize the utilization efficiency of network resources under limited resources, and provide strong support for virtual environment diagnostic testing.

[0073] The detection of abnormal operations in S3 also includes generating alarm information in real time and taking restrictive operations on the virtual environment according to the degree of abnormality. This embodiment realizes real-time response to potential threats in the virtual environment by enhancing the processing mechanism of abnormal operation detection. When monitoring the operation behavior of the virtual environment, the system can identify abnormal operations in real time through rule matching and behavior analysis technology, such as unauthorized resource calls, excessive process call frequency, or resource consumption surge. When an abnormal operation is detected, the system immediately generates an alarm message to prompt the operation risk and sends a detailed abnormal log to the administrator, including the type of abnormality, the time of occurrence, the resources involved, and the scope of impact. At the same time, different restrictive operations are dynamically taken according to the degree of abnormality (such as minor, medium, and severe). For example, for minor abnormalities, restrictive operations may include reducing resource usage permissions or issuing warnings; for medium abnormalities, related operations may be suspended or processes may be forcibly terminated; for severe abnormalities, the entire virtual environment may be isolated to prevent its interaction with other virtual environments to avoid risk diffusion. This hierarchical response mechanism ensures the timeliness and pertinence of abnormal handling, which can quickly contain security threats and minimize interference with normal operation. This implementation effectively improves the security and exception handling capabilities of the virtual environment by generating alarm information in real time and taking restrictive actions. The real-time generation of alarm information enables administrators to understand abnormal conditions in the first place and quickly locate the source of the problem based on detailed exception logs, thereby improving fault response efficiency. The abnormality level classification processing mechanism enables the system to take appropriate restrictive measures according to the risk level, avoiding the impact of excessive intervention on the test process, while ensuring that serious anomalies can be quickly controlled to prevent the expansion of potential risks. In addition, this implementation also enhances the robustness and security of the virtual environment, and provides a more efficient solution for operational behavior management in complex test scenarios.

[0074] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A diagnostic test method based on a computer platform Vspy, characterized in that: The method comprises: S1. Configure a reinforcement strategy based on the virtual environment isolation mechanism to prevent the risk of lateral spread during the test process, including evaluating the potential lateral spread risk by calculating the threat level of the virtual environment in the current test of the virtual environment, adjusting the isolation strength of the virtual environment of the virtual environment, and calculating the psychological boundary strength value. The specific formula is: B = A × C / D; Among them, B represents the psychological boundary strength value, A represents the threat level of the virtual environment in the current test, C represents the isolation strength of the virtual environment, and D represents the interaction frequency between different virtual environments; S2. Generate security rules and dynamically adjust the boundaries of the virtual environment at runtime, including generating preliminary security rules based on the load and status of the current virtual environment, inferring the existing security threats by monitoring the system's operating data, and dynamically adjusting the boundaries of the virtual environment to prevent disordered security incidents. The specific formula for calculating the effect of security rule adjustment is: ; Among them, ΔS represents the adjustment range of the corresponding security rules, dQ represents the resource adjustment value in the virtual environment, T represents the pressure of the virtual environment, and d represents the small change amount; S3, start the diagnostic test process and monitor the operation behavior in the virtual environment in real time; S4. Record the test results and compare and verify them with the preset standards.

2. A diagnostic test method based on a computer platform Vspy according to claim 1, characterized in that: The S3 includes predicting resource allocation and cost effects caused by different operation behaviors in the virtual environment when starting the diagnostic test process, monitoring the operation behaviors in the virtual environment in real time, and calculating the effect of each operation corresponding to the operation behavior in the virtual environment. The specific formula is: U=R / E; Among them, U represents the effect of the operation behavior in the corresponding virtual environment, R represents the amount of resources allocated in the virtual environment, and E represents the operation cost of the virtual environment; Prioritize actions based on their utility, and optimize behavior during testing by adjusting resource allocation and reducing operating costs within the virtual environment.

3. A diagnostic test method based on computer platform Vspy according to claim 1, characterized in that: The S4 includes real-time recording of the test steps in the virtual environment, including the operation efficiency and time of each virtual environment, and calculating the speed of the test process, the specific formula being V=X / Y; Among them, V represents the passing speed of the test results, X represents the total number of steps completed by the test, and Y represents the time taken for the test; Preset the standard speed, compare the calculated test result passing speed with the preset standard speed, ensure that the test meets the expected passing speed, adjust the test process, and ensure that all test steps can be completed within the scheduled time.

4. A diagnostic test method based on computer platform Vspy according to claim 1, characterized in that: The security rules generated in S2 include access control rules, resource isolation rules and dynamic network policies.

5. A diagnostic test method based on computer platform Vspy according to claim 1, characterized in that: The real-time monitoring of operation behaviors in the virtual environment in S3 includes dynamic changes in resource allocation in the virtual environment, process call frequency, and detection of abnormal operations.

6. A diagnostic test method based on computer platform Vspy according to claim 1, characterized in that: The test results recorded in S4 include the timestamp of the operation behavior, resource usage data, and deviation information from the preset standard.

7. A diagnostic test method based on computer platform Vspy according to claim 4, characterized in that: The access control rules in S2 include role-based access control and attribute-based access control policies, which are used to limit the scope of permissions of different users or processes in the virtual environment.

8. A diagnostic test method based on computer platform Vspy according to claim 4, characterized in that: The resource isolation rules in S2 limit the maximum allocation of CPU, memory and storage resources in the virtual environment.

9. A diagnostic test method based on computer platform Vspy according to claim 4, characterized in that: The dynamic network strategy in S2 includes dynamically adjusting the network bandwidth allocation of the virtual environment and the isolation of the communication path according to the real-time traffic load.

10. A diagnostic test method based on computer platform Vspy according to claim 5, characterized in that: The detection of abnormal operation in S3 also includes generating alarm information in real time and taking restrictive actions on the virtual environment according to the degree of abnormality.

Citation Information

Patent Citations

  • A security control method in cloud and virtual environments

    CN109818908A

  • Advanced cybersecurity systems for infrastructure and network vulnerability analysis

    US20240403445A1