Scheduling control method and device for mimicry defense system

By introducing Simpson's diversity index and entropy weight method to quantify heterogeneity in the mimic defense system, and optimizing the scheduling index with the quality of service matrix, the security and service quality instability brought about by the scheduling mechanism in the mimic defense system is solved, and the defense capability of SQL injection attacks is increased, and higher reliability and stability are achieved.

CN119995991APending Publication Date: 2025-05-13STATE GRID JIANGSU ELECTRIC POWER CO LTD TAIZHOU POWER SUPPLY BRANCH +3
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510146183.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing mimicry defense systems have problems with instability in the scheduling mechanism and lack effective multi-executive body scheduling algorithm for isomer executors.

Method used

By introducing the Simpson diversity index and entropy weight method, the heterogeneity of the execution body group is quantified, and forward standardization is performed in combination with the service quality matrix, the scheduling indicators of each isomer execution body group are calculated, and the isomeric execution body group with the largest scheduling indicators is finally selected as the scheduling scheme output. In addition, an SQL validity check module has been added to perform syntax verification to prevent SQL injection attacks.

Benefits of technology

It improves the reliability and service quality of the mimic defense system, enhances the defense capabilities of SQL injection attacks, and ensures the security and stability of the scheduling mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995991A_ABST
    Figure CN119995991A_ABST
Patent Text Reader

Abstract

The invention discloses a scheduling control method and device for a mimicry defense system. The method comprises the following steps: initializing an executor set; randomly selecting a seed heterogeneous execution body from the execution body resource pool, adding the selected seed heterogeneous execution body into an execution body set, and executing the following traversal operation: traversing each heterogeneous execution body in the execution body pool, forming a union set with the execution body set, judging whether the union set meets a preset condition, and if the union set meets the preset condition, executing the following traversal operation; adding the corresponding heterogeneous executors in the executor pool into an executor set; otherwise, keeping the current executive set unchanged; after traversal is completed, if the number of the heterogeneous executors in the current executor set is smaller than a preset number, randomly selecting a seed heterogeneous executor from the executor resource pool, adding the seed heterogeneous executor into the executor set, and executing traversal operation again; and when the number of the heterogeneous executors in the current executor set is greater than or equal to a preset number, outputting a scheduling scheme according to the current executor set. The method can improve the reliability of the mimicry defense system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a scheduling control method and device for a mimicry defense system. Background Art

[0002] Cyberspace Mimic Defense (CMD) is an intrinsically secure solution, the core of which is the Dynamic Heterogeneous Redundancy (DHR) mechanism, which aims to respond to generalized uncertain network threats with a system structure that has apparent uncertainty. Figure 1 As shown in the figure, the same input is copied into n copies by the input proxy and distributed to n heterogeneous executors in the executor cluster for processing. The processing results are collected to the voter for voting to obtain a unique relatively correct output. The theoretical research direction of mimicry defense technology consists of three aspects: homogeneous and heterogeneous implementation, executor scheduling, and multi-mode arbitration. Theoretical and system testing have proved that it is difficult for attackers to achieve stable escape in the mimicry system.

[0003] Scheduling is a widely used technology. Scholars have done a lot of research on it in different fields, but there is still a lack of multi-executor scheduling algorithms for cyberspace mimicry defense. In the existing scheduling algorithms, the impact of the scheduled heterogeneous executors on the service quality of the mimicry defense system is rarely considered. The patent text CN116846589A discloses a network security defense method based on mimicry defense, which realizes dynamic defense through the mimicry defense framework to reduce the risk of being breached, and sets a confidence for each heterogeneous executor. When its confidence drops to a certain level, it is replaced. However, the application of the server cluster will inevitably have vulnerabilities, allowing malicious users to access private and confidential information without restriction. For example, attackers can exploit security vulnerabilities in Web applications and pass unexpected malicious SQL statements through Web applications, which are executed by the back-end database, seriously threatening the data security of the service. Evaluating heterogeneous executors only by confidence is not reliable. Summary of the invention

[0004] The present invention provides a scheduling control method and device for a mimicry defense system, which can improve the reliability of the mimicry defense system.

[0005] A scheduling control method for a mimetic defense system, the mimetic defense system comprising an execution body set, the execution body set comprising a plurality of heterogeneous execution bodies, wherein the online heterogeneous execution bodies constitute an execution body pool, and the offline heterogeneous execution bodies constitute an execution body resource pool, the method comprising:

[0006] Initialize the execution set;

[0007] Randomly select a seed heterogeneous executable from the executable resource pool and add it to the executable set, and perform the following traversal operation;

[0008] Traversing each heterogeneous executable in the executable pool, forming a union with the executable set, and determining whether the union satisfies a preset condition. If the preset condition is satisfied, adding the corresponding heterogeneous executable in the executable pool to the executable set; otherwise, keeping the current executable set unchanged;

[0009] After the traversal is completed, if the number of heterogeneous executables in the current executable set is less than the preset number, a seed heterogeneous executable is randomly selected from the executable resource pool and added to the executable set, and the traversal operation is performed again;

[0010] When the number of heterogeneous executable bodies in the current executable body set is greater than or equal to a preset number, a scheduling scheme is output according to the current executable body set.

[0011] Further, judging whether the union satisfies a preset condition includes:

[0012] Calculate the heterogeneity and service quality of all heterogeneous executors in the union;

[0013] When the heterogeneity and service quality of all heterogeneous executors in the union are respectively higher than the preset heterogeneity threshold and service quality threshold, it is determined that the union meets the preset condition;

[0014] The step of calculating the heterogeneity of all heterogeneous executables in the union includes:

[0015] constructing a feature vector for each heterogeneous executor, and obtaining a feature matrix about the union according to the feature vectors of the plurality of heterogeneous executors;

[0016] Calculating the heterogeneity of the union according to the characteristic matrix of the union;

[0017] Calculate the quality of service of all heterogeneous executors in the union, including:

[0018] constructing an attribute vector for each heterogeneous executor, and obtaining a service quality matrix about the union according to the attribute vectors of the plurality of heterogeneous executors;

[0019] Calculating the quality of service of the union based on the quality of service matrix;

[0020] Furthermore, a feature vector is constructed for each heterogeneous executor, including:

[0021] Numbering each component of all component groups of the heterogeneous executable;

[0022] Based on the serial number of each component, a feature vector of the heterogeneous executable is composed.

[0023] Furthermore, each row of the characteristic matrix of the union is a component number corresponding to a same component group by different heterogeneous executables;

[0024] Calculating the heterogeneity of the union according to the characteristic matrix of the union includes:

[0025] Calculate the dispersion of each component group in the feature matrix based on the Simpson diversity index;

[0026] The entropy weight method is used to determine the weight of each component group's influence on the heterogeneity of the union;

[0027] The discreteness of each component group is multiplied by the corresponding weight and then summed to obtain the heterogeneity of the union.

[0028] Furthermore, the dispersion is calculated by the following formula:

[0029]

[0030] Among them, H k represents the discreteness of the kth component group, s k is the number of different components in the kth component group, p ki is the frequency of component i in the kth component group, n ki is the number of occurrences of component i in the kth component group, N k is the number of all components in the kth component group.

[0031] Furthermore, the entropy weight method is used to determine the weight of each component group's influence on the heterogeneity of the union, including:

[0032] Calculating the entropy value of the component group;

[0033] Calculating information redundancy according to the entropy value of the component group;

[0034] The weight of each component group's influence on the union heterogeneity is calculated based on the information redundancy.

[0035] Further, the elements in the attribute vector are attribute values ​​of the heterogeneous executor service quality indicators;

[0036] Calculating the quality of service of the union based on the quality of service matrix includes:

[0037] Performing forward normalization processing on the service quality matrix;

[0038] For the service quality matrix after forward normalization, calculate the attribute score value of each attribute value;

[0039] Calculate the weight vector for each attribute value;

[0040] The service quality of the union is calculated according to the attribute score value and the weight vector.

[0041] Furthermore, a scheduling scheme is output according to the current set of execution bodies, including:

[0042] Combining heterogeneous executable bodies in the current executable body set according to the preset number to obtain a heterogeneous executable body group;

[0043] Calculate the scheduling index of each heterogeneous executor group according to the heterogeneity and service quality of the heterogeneous executor group;

[0044] The heterogeneous executor group with the largest scheduling index is selected as the scheduling solution output.

[0045] Furthermore, after outputting the scheduling plan according to the current set of execution bodies, the method further includes:

[0046] Obtaining the SQL request of each heterogeneous execution body in the scheduling scheme;

[0047] Separate the SQL request and generate a token sequence;

[0048] Determine whether the syntax of the token sequence conforms to the preset rules. If it conforms to the preset rules, determine that the corresponding SQL request is a valid request. If it does not conform to the preset rules, determine that the corresponding SQL request is a threatening SQL statement.

[0049] The heterogeneous execution bodies corresponding to the threatening SQL statements are taken offline for cleaning.

[0050] A control device for a mimicry defense system applied to the above method comprises:

[0051] Initialization module, used to initialize the execution set;

[0052] A selection module is used to randomly select a seed heterogeneous executable from the executable resource pool to add to the executable set, and perform the following traversal operation;

[0053] A traversal module, used for traversing each heterogeneous executable body in the executable body pool, forming a union with the executable body set, and judging whether the union meets a preset condition. If the preset condition is met, the corresponding heterogeneous executable body in the executable body pool is added to the executable body set; otherwise, the current executable body set is kept unchanged;

[0054] A judgment module, configured to randomly select a seed heterogeneous executable body from the executable body resource pool and add it to the executable body set after the traversal is completed, if the number of heterogeneous executable bodies in the current executable body set is less than a preset number, and perform the traversal operation again;

[0055] The scheduling module is used to output a scheduling plan according to the current set of execution bodies when the number of heterogeneous execution bodies in the current set of execution bodies is greater than or equal to a preset number.

[0056] Furthermore, the traversal module determines whether the union satisfies a preset condition, including:

[0057] Calculate the heterogeneity and service quality of all heterogeneous executors in the union;

[0058] When the heterogeneity and service quality of all heterogeneous executors in the union are respectively higher than the preset heterogeneity threshold and service quality threshold, it is determined that the union meets the preset condition;

[0059] The traversal module calculates the heterogeneity of all heterogeneous executables in the union, including:

[0060] constructing a feature vector for each heterogeneous executor, and obtaining a feature matrix about the union according to the feature vectors of the plurality of heterogeneous executors;

[0061] Calculating the heterogeneity of the union according to the characteristic matrix of the union;

[0062] The traversal module calculates the service quality of all heterogeneous execution bodies in the union, including:

[0063] constructing an attribute vector for each heterogeneous executor, and obtaining a service quality matrix about the union according to the attribute vectors of the plurality of heterogeneous executors;

[0064] Calculating the quality of service of the union based on the quality of service matrix;

[0065] Furthermore, the traversal module constructs a feature vector for each heterogeneous execution body, including:

[0066] Numbering each component of all component groups of the heterogeneous executable;

[0067] Based on the serial number of each component, a feature vector of the heterogeneous executable is composed.

[0068] Furthermore, each row of the characteristic matrix of the union is a component number corresponding to a same component group by different heterogeneous executables;

[0069] The traversal module calculates the heterogeneity of the union according to the characteristic matrix of the union, including:

[0070] Calculate the dispersion of each component group in the feature matrix based on the Simpson diversity index;

[0071] The entropy weight method is used to determine the weight of each component group's influence on the heterogeneity of the union;

[0072] The discreteness of each component group is multiplied by the corresponding weight and then summed to obtain the heterogeneity of the union.

[0073] Furthermore, the dispersion is calculated by the following formula:

[0074]

[0075] Among them, H k represents the discreteness of the kth component group, s k is the number of different components in the kth component group, p ki is the frequency of component i in the kth component group, n ki is the number of occurrences of component i in the kth component group, N k is the number of all components in the kth component group.

[0076] Furthermore, the traversal module uses an entropy weight method to determine the weight of each component group's influence on the heterogeneity of the union, including:

[0077] Calculating the entropy value of the component group;

[0078] Calculating information redundancy according to the entropy value of the component group;

[0079] The weight of each component group's influence on the union heterogeneity is calculated based on the information redundancy.

[0080] Further, the elements in the attribute vector are attribute values ​​of the heterogeneous executor service quality indicators;

[0081] The traversal module calculates the quality of service of the union based on the quality of service matrix, including:

[0082] Performing forward normalization processing on the service quality matrix;

[0083] For the service quality matrix after forward normalization, calculate the attribute score value of each attribute value;

[0084] Calculate the weight vector for each attribute value;

[0085] The service quality of the union is calculated according to the attribute score value and the weight vector.

[0086] Furthermore, the scheduling module outputs a scheduling solution according to the current set of execution bodies, including:

[0087] Combining heterogeneous executable bodies in the current executable body set according to the preset number to obtain a heterogeneous executable body group;

[0088] Calculate the scheduling index of each heterogeneous executor group according to the heterogeneity and service quality of the heterogeneous executor group;

[0089] The heterogeneous executor group with the largest scheduling index is selected as the scheduling solution output.

[0090] Furthermore, the device also includes a validity check module, which is used to obtain the SQL request of each heterogeneous execution body in the scheduling plan after outputting the scheduling plan according to the current execution body set; separate the SQL requests to generate a token sequence; determine whether the syntax of the token sequence conforms to the preset rules, if it conforms to the preset rules, determine that the corresponding SQL request is a valid request, if it does not conform to the preset rules, determine that the corresponding SQL request is a threatening SQL statement; and take the heterogeneous execution body corresponding to the threatening SQL statement offline for cleaning.

[0091] The scheduling control method and device of the mimicry defense system provided by the present invention have at least the following beneficial effects:

[0092] (1) Compared with the existing quantification methods of the heterogeneity of the actuator group, the Simpson index is introduced to quantify the complexity of the components. Compared with other diversity indices, this method has better results in quantifying the heterogeneity of the system and can better reflect the actual situation. The entropy weight method is used to determine the weight of each component group on the heterogeneity of the actuator group. It takes into account the relationship between the component groups, rather than just assigning weights to each component group separately, which helps to more comprehensively evaluate the importance of each component group.

[0093] (2) Using the ratio of the mean to the standard deviation as the attribute score of a service attribute and assigning different weights to different attributes can truly reflect the impact of different attributes on service quality. This method can effectively measure the service quality of a set of execution bodies.

[0094] (3) In addition to the heterogeneity of the executors, this method also considers the service quality of the heterogeneous executors during scheduling, solving the security and service quality instability problems caused by the scheduling mechanism;

[0095] (4) The proposed arbitrator is designed for SQL security. Compared with the existing arbitrator, it adds a SQL validity check module. Before executing the arbitrator algorithm, the SQL statement is first checked for validity, which can effectively defend against SQL injection and other attacks that threaten data security. BRIEF DESCRIPTION OF THE DRAWINGS

[0096] Figure 1This is a schematic diagram of the principles of the mimicry defense system.

[0097] Figure 2 A flowchart of an embodiment of a scheduling control method for a mimicry defense system provided by the present invention.

[0098] Figure 3 A schematic diagram of the principles of an embodiment of a scheduling control method for a mimicry defense system provided by the present invention.

[0099] Figure 4 A flowchart of another embodiment of the scheduling control method of the mimicry defense system provided by the present invention.

[0100] Figure 5 A flowchart of an embodiment of a scheduling control method for a mimicry defense system provided by the present invention. DETAILED DESCRIPTION

[0101] In order to better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0102] refer to Figure 2 , Figure 3 and Figure 4 In some embodiments, a scheduling control method of a mimetic defense system is provided, wherein the mimetic defense system includes an execution body set, wherein the execution body set includes multiple heterogeneous execution bodies, wherein the online heterogeneous execution bodies form an execution body pool, and the offline heterogeneous execution bodies form an execution body resource pool, wherein the method includes:

[0103] S1, initialize the execution body set;

[0104] S2. Randomly select a seed heterogeneous executable from the executable resource pool and add it to the executable set, and perform the following traversal operation:

[0105] S3, traversing each heterogeneous executable in the executable pool, forming a union with the executable set, and determining whether the union satisfies a preset condition. If the preset condition is satisfied, adding the corresponding heterogeneous executable in the executable pool to the executable set; otherwise, keeping the current executable set unchanged;

[0106] S4. After the traversal is completed, if the number of heterogeneous executables in the current executable set is less than a preset number, randomly select a seed heterogeneous executable from the executable resource pool and add it to the executable set and perform the traversal operation again;

[0107] S5. When the number of heterogeneous executable bodies in the current executable body set is greater than or equal to a preset number, a scheduling plan is output according to the current executable body set.

[0108] Specifically, the executor pool refers to the set of heterogeneous executors that are online at the same time and participate in voting in the heterogeneous executors (servers) in the mimic defense system, that is, the working heterogeneous executors. The other is the executor resource pool, which refers to the set of all heterogeneous executors that have gone offline, that is, all heterogeneous executors that are available but not working. Offline heterogeneous executors will be put back into the executor resource pool.

[0109] In step S1, the initialized execution volume set S is empty.

[0110] In step S2, a seed heterogeneous executor is randomly selected from the executor resource pool and added to the executor set S, and the next step is executed.

[0111] In step S3, each heterogeneous executable e in the executable pool is traversed, and a union S'=S∪{e} is formed with the executable set S, and it is determined whether the union S' satisfies the preset conditions. If the preset conditions are met, the corresponding heterogeneous executable e is added to the executable set S, the executable set S is updated, and the traversal is continued downward; if the preset conditions are not met, the current executable set is kept unchanged, and the traversal is continued downward.

[0112] In some embodiments, determining whether the union satisfies a preset condition includes:

[0113] S31, calculating the heterogeneity and service quality of all heterogeneous executors in the union;

[0114] S32: When the heterogeneity and service quality of all heterogeneous executables in the union are respectively higher than the preset heterogeneity threshold and service quality threshold, it is determined that the union meets the preset condition.

[0115] Specifically, if the heterogeneity of all heterogeneous executors in the union is lower than a preset heterogeneity threshold, or the quality of service is lower than a quality of service threshold, then the union does not meet the preset condition.

[0116] Furthermore, in step S31, the heterogeneity of all heterogeneous executables in the union is calculated, including:

[0117] S311, constructing a feature vector for each heterogeneous executor, and obtaining a feature matrix about the union according to the feature vectors of multiple heterogeneous executors;

[0118] S312. Calculate the heterogeneity of the union according to the characteristic matrix of the union.

[0119] Specifically, in step S311, constructing a feature vector for each heterogeneous execution body includes:

[0120] Numbering each component of all component groups of the heterogeneous executable;

[0121] Based on the serial number of each component, a feature vector of the heterogeneous executable is composed.

[0122] Specifically, each component of all component groups of all heterogeneous executables in the union S' is numbered. Different component groups are numbered independently, and groups may have the same number value. Within the same component group, the number of the same component must be unique. For example, in the component group of physical machine operating system, there are four types (Ubuntu, windows server, CentOS, Debian), and they can be numbered as (1, 2, 3, 4) respectively.

[0123] Furthermore, based on the component numbers obtained in the above steps, a feature vector is constructed for each heterogeneous executable: FV k =(s 1k ,s 2k ,s 3k , ..., s mk ) T Among them, FV k is the feature vector of the kth heterogeneous executive, s jk is the number of the jth component of the heterogeneous executive, and m is the number of components in the heterogeneous executive.

[0124] For example, the components of a heterogeneous executable are (X86, CentOS, Apache 2.4, Oracle11g), which correspond to the processor, physical operating system, server software, and database software respectively. According to the number of each component in its group, its corresponding feature vector may be (1, 3, 1, 2).

[0125] Furthermore, in step S311, based on the feature vectors of all heterogeneous executables in the union, a feature matrix of the entire union is constructed. Assume that the union has n heterogeneous executables and m components, that is, for n heterogeneous executables, each of them has m components. Then the feature matrix of the union is:

[0126]

[0127] Among them, FM represents the feature matrix, n represents the number of heterogeneous executors, and FV k represents the feature vector of the kth heterogeneous executable, s mn Indicates the number of the mth component of the nth heterogeneous executable.

[0128] Specifically, each column of the feature matrix of the union is a feature vector of each of the heterogeneous executables, and each row is a component number corresponding to the same component group by different heterogeneous executables.

[0129] Furthermore, in step S312, the heterogeneity of the union is calculated according to the characteristic matrix of the union, including:

[0130] S312a, calculating the dispersion of each component group in the feature matrix based on the Simpson diversity index;

[0131] S312b, using an entropy weight method to determine the weight of each component group's influence on the heterogeneity of the union;

[0132] S312c: multiply the discreteness of each component group by the corresponding weight and then sum them up to obtain the heterogeneity of the union.

[0133] Specifically, in step S312a, the discreteness of the component group is defined as the Simpson diversity property of the component group. The Simpson diversity index of each row of the feature matrix reflects the complexity of each component group. The higher the index, the greater the difference between components in the component group. For any component group, the calculation method of its discreteness is as follows:

[0134]

[0135] Among them, H k represents the discreteness of the kth component group, s k is the number of different components in the kth component group, p ki is the frequency of component i in the kth component group, n ki is the number of occurrences of component i in the kth component group, N k is the number of all components in the kth component group.

[0136] Furthermore, in step S312b, the entropy weight method is used to determine the weight of each component group's influence on the heterogeneity of the union, including:

[0137] Calculating the entropy value of the component group;

[0138] Calculating information redundancy according to the entropy value of the component group;

[0139] The weight of each component group's influence on the union heterogeneity is calculated based on the information redundancy.

[0140] Specifically, the entropy weight method is used to determine the weight w of each component group on the heterogeneity of the union. k The calculation method is as follows: First, calculate the entropy value of the component group:

[0141]

[0142] Among them, E k is the entropy value of the kth component group, s kis the number of different components in the kth component group, p ki is the frequency of component i in the kth component group. Generally speaking, 0≤E k ≤1.

[0143] According to the entropy calculation formula, the entropy values ​​of each component group are calculated as E1, E2, ... m , and then calculate the information redundancy:

[0144] R k =1-E k ; (5)

[0145] Among them, R k represents the information redundancy of the kth component group, E k is the entropy value of the kth component group.

[0146] Then, the weight of each component group's influence on the heterogeneity of the union is calculated, and the calculation method is:

[0147]

[0148] Among them, w k represents the weight of the influence of the kth component group on the heterogeneity of the union, R k represents the information redundancy of the kth component group.

[0149] Finally, the discreteness and weight of each component group are multiplied and summed to obtain the heterogeneity of the union, which is calculated as follows:

[0150]

[0151] Where D represents the degree of heterogeneity, m represents the number of component groups, and w k represents the weight of the kth component group's influence on the heterogeneity of the union, H k represents the discreteness of the kth component group.

[0152] Furthermore, in step S31, the service quality of all heterogeneous execution bodies in the union is calculated, including:

[0153] S313, constructing an attribute vector for each heterogeneous executor, and obtaining a service quality matrix about the union according to the attribute vectors of the plurality of heterogeneous executors;

[0154] S314: Calculate the quality of service of the union based on the quality of service matrix.

[0155] Specifically, in step S313, the elements in the attribute vector are attribute values ​​of the heterogeneous executor service quality indicators.

[0156] Construct the quality of service matrix of the union:

[0157]

[0158] Where Q represents the service quality matrix, q ij represents the i-th attribute vector of the j-th heterogeneous executor. Each column of the service quality matrix is ​​composed of the attribute vector of a heterogeneous executor in the union. Each element in the attribute vector is the attribute value of a certain service quality indicator of the heterogeneous executor, such as network bandwidth, throughput, response time, etc. Each row of the service quality matrix Q is the attribute value of each heterogeneous executor in the union on the corresponding service quality indicator. For example, if it is assumed that the first row of the service quality matrix Q represents the network bandwidth and the second row represents the response time, then q 11 The attribute value of the network bandwidth of heterogeneous executor 1, q 22 Indicates the attribute value of the heterogeneous executable 2 indicating the response time.

[0159] Furthermore, in step S314, the quality of service of the union is calculated based on the quality of service matrix, including:

[0160] Performing forward normalization processing on the service quality matrix;

[0161] For the service quality matrix after forward normalization, calculate the attribute score value of each attribute value;

[0162] Determine a weight vector for each attribute value;

[0163] The service quality of the union is calculated according to the attribute score value and the weight vector.

[0164] Specifically, the service quality matrix is ​​forward normalized to remove the influence of attribute dimension and attribute type (attributes can be divided into maximum value attributes, minimum value attributes and intermediate attributes). Different matrix forward normalization algorithms are used to normalize all non-extremely large data into extremely large data, which are as follows:

[0165] For very small initial data (such as response time, etc.), select one of the following for quantification:

[0166]

[0167]

[0168] Among them, n i represents the i-th attribute value in the service quality matrix, It represents the attribute value after forward normalization, and max(N) represents the maximum value of the corresponding attribute value.

[0169] If the initial data is interval data, the following formula can be used for positive normalization:

[0170] M=max(a-min(x i ),max(x i )-b); (11)

[0171]

[0172] Among them, x i is a set of interval data sequences, with a value range of [a,b], min(x i ) is the minimum value in the interval data sequence, max(x i ) is the maximum value in the interval data sequence, and M represents the maximum value of the deviation in the interval data sequence that exceeds the upper bound a and the lower bound b.

[0173] Among them, the interval data sequence may include memory utilization, CPU utilization, etc. If these data are too low, it means that the resources are idle, and if they are too high, it will lead to service overload. The interval data sequence is a sequence of attribute values ​​of each heterogeneous executor in the union on a certain interval service quality indicator (such as CPU utilization), which corresponds to a row of data in the service quality matrix.

[0174] For initial data that is intermediate data, the following formula is used for positive normalization:

[0175]

[0176] Among them, y i Represents a set of intermediate data sequences, y best represents the optimal value of the sequence, Y represents the set of all intermediate data sequences, Represents the intermediate data sequence after forward normalization.

[0177] The intermediate data sequence may include network utilization, bandwidth utilization, etc. The intermediate data sequence is a sequence of attribute values ​​of each heterogeneous executor in the union on an intermediate service quality indicator (such as bandwidth utilization), corresponding to a row of data in the service quality matrix.

[0178] The matrix standardization algorithm is calculated using the following formula

[0179]

[0180] Among them, z ij represents the element in the standardized service quality matrix, u ij Represents the elements in the original quality of service matrix after forward normalization.

[0181] For each attribute of the service quality matrix after forward normalization, calculate its attribute score AS. Each row of the service quality matrix corresponds to an attribute. For the i-th attribute vector of the service quality matrix after forward normalization, its vector representation is: Vi = (q i1 ,q i2 ,…q in ).

[0182] The attribute score calculation formula is:

[0183]

[0184] Among them, ASi represents the attribute score value of the i-th attribute, μi is the mean value of the attribute, σ i is the standard deviation of the attribute.

[0185] The attribute score comprehensively considers the average level and dispersion of the attribute, avoiding the situation where only the average value of the attribute is considered, and the average value may be large, but the attribute differences between components are large. According to the barrel effect, if the attribute differences between components are too large, the service quality will be affected by the component with the lowest attribute.

[0186] Determine the weight vector W of the service quality attribute according to the actual scenario, and calculate the service quality QS of the union. The calculation formula is as follows:

[0187]

[0188] Among them, QS represents the quality of service, W represents the weight vector of the attribute value, and AS represents the attribute score value.

[0189] Further, in step S4, after the traversal is completed, if the number of heterogeneous executable bodies in the current executable body set is less than the preset number, a seed heterogeneous executable body is randomly selected from the executable body resource pool and added to the executable body set and the traversal operation is performed again, that is, step S3 is executed again until the number of heterogeneous executable bodies in the current executable body set reaches the preset number.

[0190] Furthermore, in step S5, a scheduling scheme is output according to the current set of execution bodies, including:

[0191] S51, combining heterogeneous executables in the current executable set according to the preset number to obtain a heterogeneous executable group;

[0192] S52, calculating the scheduling index of each heterogeneous executor group according to the heterogeneity and service quality of the heterogeneous executor group;

[0193] S53: Select the heterogeneous execution body group with the largest scheduling index as the scheduling solution output.

[0194] Specifically, in step S52, the scheduling index of the heterogeneous execution body group is calculated by the following formula:

[0195] ES=D+QS+λ|D-QS|; (17)

[0196] Among them, ES represents the scheduling index, D represents the heterogeneity, QS represents the service quality, which is calculated by the above formula and will not be repeated here. λ is an artificially specified constant, and its value is less than 0.

[0197] Furthermore, after outputting the scheduling plan according to the current set of execution bodies, the method further includes:

[0198] Obtaining the SQL request of each heterogeneous execution body in the scheduling scheme;

[0199] Separate the SQL request and generate a token sequence;

[0200] Determine whether the syntax of the token sequence conforms to the preset rules. If it conforms to the preset rules, determine that the corresponding SQL request is a valid request. If it does not conform to the preset rules, determine that the corresponding SQL request is a threatening SQL statement.

[0201] The heterogeneous execution bodies corresponding to the threatening SQL statements are taken offline for cleaning.

[0202] Specifically, the mimicry defense system provided in this embodiment further includes a front-end arbiter based on multi-mode arbitration and a back-end arbiter oriented to SQL security.

[0203] The front-end arbiter votes at the semantic level to shield the differences in details of responses from heterogeneous server clusters, such as differences in the content-type and charset fields in the http request header; or differences in the number of invalid characters in the content, such as spaces, " / ", etc. These differences are non-semantic differences, and the voter needs to be designed to vote at the semantic level to avoid these differences affecting the voting results.

[0204] The backend arbiter for SQL security consists of a validity check module (EMM) and a large number-based adjudication module. The validity check module receives all SQL requests from the upper-level redundant isomers to confirm their validity and security. If the validity check module proves that the SQL request does match the specification, the validity check module will continue to send the valid query to the adjudication module. On the contrary, if it is confirmed that the SQL request violates the specification, the validity check module will mark the query as a potential SQL injection attack, thereby preventing its execution and recording basic information related to the attack, and passing the error information to the adjudication module, and performing offline cleaning of the redundant isomers corresponding to the threatening SQL statement.

[0205] The validity check module (EMM) includes the following:

[0206] 1. Pre-definition of statement specifications. Statement specifications are the basis of the validity check module. Statement specifications are a set of rules that describe the expected structure of SQL requests generated by the application. It is a collection of rules that all legal SQL requests in the entire application service should satisfy. Each original SQL statement that is expected to be executed to the backend database is scanned, parsed, and a rule is created to define its grammatical structure.

[0207] 2. Lexical analysis. Every SQL request that enters EMM will go through a lexical analysis program. During this process, each word in the statement will be separated into tokens and grouped according to its type, such as keywords (SELECT, FROM, DELETE, OR, etc.), symbols (such as +, -, <, <=, etc.), constants (for example, 123, 3.1416), variables, etc.

[0208] 3. Syntax verification of SQL requests. This is the main part of EMM, which checks the syntax correctness of the token sequence generated for each SQL request in the previous stage. If the SQL request matches a syntax rule in the statement specification defined above, it is considered valid; otherwise, if the syntax of the SQL request does not match any rule in the statement specification, the SQL statement is considered illegal.

[0209] 4. Send the detection results to the decision module. For SQL requests that pass the above detection, they are input into the decision queue; for SQL requests that fail the detection, it means that there is a high probability of SQL injection attack, and the SQL request is rejected from continuing to execute, and the decision module is notified to perform offline cleaning on the corresponding heterogeneous execution body.

[0210] The definition of the statement specification is:

[0211] Statement specifications define rules that describe the expected grammatical structure that SQL requests should follow to verify legality. The important feature of statement specifications is completeness, which should include explicit rules for each statement executed according to the application source code, and each rule should contain all possible values ​​that the SQL request may have. If there are any omissions or errors, false positives or false negatives may be introduced. The grammar of the specification needs to follow the Extended Backus-Naur Form (EBNF) notation, which is a comprehensive asynchronous notation widely used for fast context-free grammars. The specification of SQL language tokens can be easily created according to the grammar rules specified by parsing in the EBNF grammar.

[0212] Furthermore, the specific method of constructing the SQL statement specification is:

[0213] 1. Enumerate all SQL statements that may be executed in the application source code

[0214] 2. For each SQL statement, use the syntax tree to analyze its grammatical structure, and based on the Extended Backus-Naur Form (EBNF) representation, form the statement rules of the statement and add them to the statement specification.

[0215] For example, for the SQL statement:

[0216] SELECT user_id,user_level FROM USERS WHERE username='george'ANDpassword='25fdgs';

[0217] The corresponding statement rules are:

[0218]

[0219] Every SQL statement that enters EMM will pass through a lexical analysis program. During this process, each word in the statement will be separated from the statement as a token and grouped according to its type, such as keywords (SELECT, FROM, DELETE, OR, etc.), symbols (such as +, -, <, <=, etc.), constants (for example, 123, 3.1416), variables, etc.

[0220] The token sequence of each SQL statement generated by the lexical analysis will be sent to the syntax verifier to check its grammatical correctness. If the SQL statement does not violate the grammatical rules present in the corresponding specification, it is considered valid because these rules are pre-defined in the statement specification.

[0221] In some embodiments, reference Figure 5 , and also provides a control device for the mimicry defense system applied to the above method, comprising:

[0222] Initialization module 201, used to initialize the execution body set;

[0223] The selection module 202 is used to randomly select a seed heterogeneous executable from the executable resource pool to add to the executable set, and perform the following traversal operation;

[0224] The traversal module 203 is used to traverse each heterogeneous executable body in the executable body pool, form a union with the executable body set, and determine whether the union meets a preset condition. If the preset condition is met, the corresponding heterogeneous executable body in the executable body pool is added to the executable body set; otherwise, the current executable body set is kept unchanged;

[0225] The judgment module 204 is used for randomly selecting a seed heterogeneous executable body from the executable body resource pool and adding it to the executable body set after the traversal is completed, if the number of heterogeneous executable bodies in the current executable body set is less than a preset number, and performing the traversal operation again;

[0226] The scheduling module 205 is used to output a scheduling solution according to the current set of executable bodies when the number of heterogeneous executable bodies in the current set of executable bodies is greater than or equal to a preset number.

[0227] Furthermore, the traversal module 203 determines whether the union satisfies a preset condition, including:

[0228] Calculate the heterogeneity and service quality of all heterogeneous executors in the union;

[0229] When the heterogeneity and service quality of all heterogeneous executors in the union are respectively higher than the preset heterogeneity threshold and service quality threshold, it is determined that the union meets the preset condition;

[0230] The traversal module 203 calculates the heterogeneity of all heterogeneous executables in the union, including:

[0231] constructing a feature vector for each heterogeneous executor, and obtaining a feature matrix about the union according to the feature vectors of the plurality of heterogeneous executors;

[0232] Calculating the heterogeneity of the union according to the characteristic matrix of the union;

[0233] The traversal module calculates the service quality of all heterogeneous execution bodies in the union, including:

[0234] constructing an attribute vector for each heterogeneous executor, and obtaining a service quality matrix about the union according to the attribute vectors of the plurality of heterogeneous executors;

[0235] Calculating the quality of service of the union based on the quality of service matrix;

[0236] Furthermore, the traversal module 203 constructs a feature vector for each heterogeneous execution body, including:

[0237] Numbering each component of all component groups of the heterogeneous executable;

[0238] Based on the serial number of each component, a feature vector of the heterogeneous executable is composed.

[0239] Furthermore, each column of the characteristic matrix of the union is a characteristic vector of each of the heterogeneous executables;

[0240] The traversal module 203 calculates the heterogeneity of the union according to the characteristic matrix of the union, including:

[0241] Calculate the dispersion of each component group in the feature matrix based on the Simpson diversity index;

[0242] The entropy weight method is used to determine the weight of each component group's influence on the heterogeneity of the union;

[0243] The discreteness of each component group is multiplied by the corresponding weight and then summed to obtain the heterogeneity of the union.

[0244] Furthermore, the dispersion is calculated by the following formula:

[0245]

[0246] Among them, H k represents the discreteness of the kth component group, s k is the number of different components in the kth component group, p ki is the frequency of component i in the kth component group, n ki is the number of occurrences of component i in the kth component group, N k is the number of all components in the kth component group.

[0247] Furthermore, the traversal module 203 uses an entropy weight method to determine the weight of each component group's influence on the union heterogeneity, including:

[0248] Calculating the entropy value of the component group;

[0249] Calculating information redundancy according to the entropy value of the component group;

[0250] The weight of each component group's influence on the union heterogeneity is calculated based on the information redundancy.

[0251] Further, the elements in the attribute vector are attribute values ​​of the heterogeneous executor service quality indicators;

[0252] The traversal module calculates the quality of service of the union based on the quality of service matrix, including:

[0253] Performing forward normalization processing on the service quality matrix;

[0254] For the service quality matrix after forward normalization, calculate the attribute score value of each attribute value;

[0255] Calculate the weight vector for each attribute value;

[0256] The service quality of the union is calculated according to the attribute score value and the weight vector.

[0257] Furthermore, the scheduling module 205 outputs a scheduling solution according to the current set of execution bodies, including:

[0258] Combining heterogeneous executable bodies in the current executable body set according to the preset number to obtain different heterogeneous executable body groups;

[0259] Calculate the scheduling index of each heterogeneous executor group according to the heterogeneity and service quality of the heterogeneous executor group;

[0260] The heterogeneous executor group with the largest scheduling index is selected as the scheduling solution output.

[0261] Furthermore, the device also includes a validity check module, which is used to obtain the SQL request of each heterogeneous execution body in the scheduling plan after outputting the scheduling plan according to the current execution body set; separate the SQL requests to generate a token sequence; determine whether the syntax of the token sequence conforms to the preset rules, if it conforms to the preset rules, determine that the corresponding SQL request is a valid request, if it does not conform to the preset rules, determine that the corresponding SQL request is a threatening SQL statement; and take the heterogeneous execution body corresponding to the threatening SQL statement offline for cleaning.

[0262] The scheduling control method and device of the mimic defense system provided in the above embodiment have at least the following beneficial effects:

[0263] (1) Compared with the existing quantification methods of the heterogeneity of the actuator group, the Simpson index is introduced to quantify the complexity of the components. Compared with other diversity indices, this method has better results in quantifying the heterogeneity of the system and can better reflect the actual situation. The entropy weight method is used to determine the weight of each component group on the heterogeneity of the actuator group. It takes into account the relationship between the component groups, rather than just assigning weights to each component group separately, which helps to more comprehensively evaluate the importance of each component group.

[0264] (2) Using the ratio of the mean to the standard deviation as the attribute score of a service attribute and assigning different weights to different attributes can truly reflect the impact of different attributes on service quality. This method can effectively measure the service quality of a set of execution bodies.

[0265] (3) In addition to the heterogeneity of the executors, this method also considers the service quality of the heterogeneous executors during scheduling, solving the security and service quality instability problems caused by the scheduling mechanism;

[0266] (4) The proposed arbitrator is designed for SQL security. Compared with the existing arbitrator, it adds a SQL validity check module. Before executing the arbitrator algorithm, the SQL statement is first checked for validity, which can effectively defend against SQL injection and other attacks that threaten data security.

[0267] Although preferred embodiments of the present invention have been described, additional changes and modifications may be made to these embodiments by those skilled in the art once the basic inventive concepts are known. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention. Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A scheduling control method for a mimicry defense system, characterized in that: The mimic defense system includes an execution body set, the execution body set includes multiple heterogeneous execution bodies, among which online heterogeneous execution bodies form an execution body pool, and offline heterogeneous execution bodies form an execution body resource pool. The method includes: Initialize the execution set; A seed heterogeneous executable is randomly selected from the executable resource pool and added to the executable set, and the following traversal operation is performed: Traversing each heterogeneous executable in the executable pool, forming a union with the executable set, and determining whether the union satisfies a preset condition. If the preset condition is satisfied, adding the corresponding heterogeneous executable in the executable pool to the executable set; otherwise, keeping the current executable set unchanged; After the traversal is completed, if the number of heterogeneous executables in the current executable set is less than the preset number, a seed heterogeneous executable is randomly selected from the executable resource pool and added to the executable set, and the traversal operation is performed again; When the number of heterogeneous executable bodies in the current executable body set is greater than or equal to a preset number, a scheduling scheme is output according to the current executable body set.

2. The method according to claim 1, characterized in that Determining whether the union satisfies a preset condition includes: Calculate the heterogeneity and service quality of all heterogeneous executors in the union; When the heterogeneity and service quality of all heterogeneous executors in the union are respectively higher than the preset heterogeneity threshold and service quality threshold, it is determined that the union meets the preset condition; The step of calculating the heterogeneity of all heterogeneous executables in the union includes: constructing a feature vector for each heterogeneous executor, and obtaining a feature matrix about the union according to the feature vectors of the plurality of heterogeneous executors; Calculating the heterogeneity of the union according to the characteristic matrix of the union; Calculate the quality of service of all heterogeneous executors in the union, including: constructing an attribute vector for each heterogeneous executor, and obtaining a service quality matrix about the union according to the attribute vectors of the plurality of heterogeneous executors; The quality of service of the union is calculated based on the quality of service matrix.

3. The method according to claim 2, characterized in that Construct a feature vector for each heterogeneous executable, including: Numbering each component of all component groups of the heterogeneous executable; Based on the serial number of each component, a feature vector of the heterogeneous executable is composed.

4. The method according to claim 2 or 3, characterized in that: Each row of the characteristic matrix of the union corresponds to a component number corresponding to a different heterogeneous executable for the same component group; Calculating the heterogeneity of the union according to the characteristic matrix of the union includes: Calculate the dispersion of each component group in the feature matrix based on the Simpson diversity index; The entropy weight method is used to determine the weight of each component group's influence on the heterogeneity of the union; The discreteness of each component group is multiplied by the corresponding weight and then summed to obtain the heterogeneity of the union.

5. The method according to claim 4, characterized in that The dispersion is calculated by the following formula: Among them, H k represents the discreteness of the kth component group, s k is the number of different components in the kth component group, p ki is the frequency of component i in the kth component group, n ki is the number of occurrences of component i in the kth component group, N k is the number of all components in the kth component group.

6. The method according to claim 4, characterized in that The entropy weight method is used to determine the weight of each component group's influence on the heterogeneity of the union, including: Calculating the entropy value of the component group; Calculating information redundancy according to the entropy value of the component group; The weight of each component group's influence on the union heterogeneity is calculated based on the information redundancy.

7. The method according to claim 2, characterized in that: The elements in the attribute vector are attribute values ​​of the heterogeneous executor service quality indicators; Calculating the quality of service of the union based on the quality of service matrix includes: Performing forward normalization processing on the service quality matrix; For the service quality matrix after forward normalization, calculate the attribute score value of each attribute value; Calculate the weight vector for each attribute value; The service quality of the union is calculated according to the attribute score value and the weight vector.

8. The method according to claim 1, characterized in that: Output the scheduling plan based on the current set of execution bodies, including: Combining heterogeneous executable bodies in the current executable body set according to the preset number to obtain a heterogeneous executable body group; Calculate the scheduling index of each heterogeneous executor group according to the heterogeneity and service quality of the heterogeneous executor group; The heterogeneous executor group with the largest scheduling index is selected as the scheduling solution output.

9. The method according to claim 1, characterized in that: After outputting the scheduling plan according to the current set of execution bodies, it also includes: Obtaining the SQL request of each heterogeneous execution body in the scheduling scheme; Separate the SQL request and generate a token sequence; Determine whether the syntax of the token sequence conforms to the preset rules. If it conforms to the preset rules, determine that the corresponding SQL request is a valid request. If it does not conform to the preset rules, determine that the corresponding SQL request is a threatening SQL statement. The heterogeneous execution bodies corresponding to the threatening SQL statements are taken offline for cleaning.

10. A control device for a mimicry defense system used in the method according to any one of claims 1 to 9, characterized in that: include: Initialization module, used to initialize the execution set; A selection module is used to randomly select a seed heterogeneous executable from the executable resource pool to add to the executable set, and perform the following traversal operation; A traversal module, used for traversing each heterogeneous executable body in the executable body pool, forming a union with the executable body set, and judging whether the union meets a preset condition. If the preset condition is met, the corresponding heterogeneous executable body in the executable body pool is added to the executable body set; otherwise, the current executable body set is kept unchanged; A judgment module, configured to randomly select a seed heterogeneous executable body from the executable body resource pool and add it to the executable body set after the traversal is completed, if the number of heterogeneous executable bodies in the current executable body set is less than a preset number, and perform the traversal operation again; The scheduling module is used to output a scheduling plan according to the current execution body set when the number of heterogeneous execution bodies in the current execution body set is greater than or equal to a preset number.

Citation Information

Patent Citations

  • Network security defense method based on mimicry defense

    CN116846589A