Mimicry defense scheduling method and device based on load balancing

By adopting a mimetic defense scheduling method based on load balancing in the mimetic defense system, the problems of large scheduling overhead, large load balancing pressure and unsafe scheduling in the prior art are solved, and load balancing, security and accuracy are improved.

CN119996033APending Publication Date: 2025-05-13STATE GRID JIANGSU ELECTRIC POWER CO LTD TAIZHOU POWER SUPPLY BRANCH +3
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510251167.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-04
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing mimicry defense scheduling methods have problems such as large scheduling overhead, large server load balancing pressure, and unsafe scheduling process.

Method used

Using a mimicry defense scheduling method based on load balancing, the switch receives traffic probes, detects whether the isomer executor is attacked, calculates the historical confidence and difference of the candidate isomer executors, determines the scheduling priority, and selects a path according to the traffic level for data transmission.

Benefits of technology

Load balancing in scheduling is realized, the security and accuracy of scheduling is improved, and the risk of isomer execution bodies being compromised is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996033A_ABST
    Figure CN119996033A_ABST
Patent Text Reader

Abstract

The invention discloses a mimicry defense scheduling method and device based on load balancing. The method comprises the steps that a switch receives a flow probe; detecting whether heterogeneous executors in the executor cluster are attacked or not; scheduling the attacked heterogeneous execution bodies to be offline, and forming an undetermined execution body set by the current execution body cluster and the corresponding candidate heterogeneous execution bodies in the execution body candidate pool; performing multi-mode judgment according to historical tasks of the candidate heterogeneous executors, and calculating historical confidence coefficients of the candidate heterogeneous executors according to judgment results; calculating the difference degree of the candidate heterogeneous executors based on the undetermined executor set; determining a scheduling priority according to the historical confidence coefficient and the difference degree of the candidate heterogeneous executors; determining a scheduling scheme according to a scheduling priority and the traffic probe; according to the method, load balancing of executor scheduling can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a mimicry defense scheduling method and device based on load balancing. Background Art

[0002] Dynamic Heterogeneous Redundancy (DHR) is a new type of generalized robust control structure proposed by Wu Jiangxing, an academician of the Chinese Academy of Engineering. It is also the core technical means to achieve mimicry defense. The intrinsic security effect generated by this structure can effectively suppress security threats caused by known or unknown vulnerabilities, backdoors, viruses, and Trojans hidden in the system.

[0003] Dynamic heterogeneous redundancy is based on the logical expression of "relative correct axioms" and closed-loop robust control. It is a closed-loop iterative multi-dimensional dynamic reconfigurable robust control structure based on policy judgment. It consists of functionally equivalent heterogeneous executors and input and output agents, policy judgments and feedback control and schedulers using iterative mechanisms. The input agent is used to distribute external input signal sequences, and the output agent and iterative judgments (composed of multiple voting algorithms) together form a normalized judgment interface. The core of the feedback control and scheduler consists of a set of pre-set scheduling strategies and intelligent learning algorithms. When receiving information that the judge has found an abnormality, the feedback scheduler is activated and instructs related components to replace, migrate, clean, reorganize, and reconstruct the current operating environment. This process is iteratively executed until the judge's abnormal situation disappears or the frequency of occurrence is lower than a certain set threshold. It should be emphasized that the elements in the DHR structure all use a non-interactive "one-way communication mechanism". Dynamic heterogeneous redundancy can provide information systems or control devices or related facilities with the trinity of "high reliability, high trustworthiness, and high availability" performance, and can also be used as a universal enabling technology for the basic structural design and integrated innovation applications of various hardware and software equipment. The mimetic server cluster is the specific application of the DHR architecture in the server cluster. For example, the patent text CN118426356A provides an execution body scheduling optimization method, device, electronic device and storage medium, and the method includes: performing abnormal identification processing and abnormal removal processing on all execution bodies to obtain multiple normal execution bodies; combining multiple normal execution bodies to obtain multiple normal execution body combinations; respectively calculating the common mode defense coefficient of each normal execution body combination, and determining the normal execution body combination whose common mode defense coefficient is lower than the preset common mode defense coefficient threshold as the execution body combination to be worked. However, this method has a series of problems such as high scheduling overhead, high server load balancing pressure, and unsafe scheduling process. Summary of the invention

[0004] The present invention provides a load balancing-based mimicry defense scheduling method and device, which can balance the load balancing pressure of a server.

[0005] A mimetic defense scheduling method based on load balancing is applied to a mimetic defense system, wherein the mimetic defense system includes a switch, an online executor cluster, and an executor candidate pool; the method includes:

[0006] The switch receives a flow probe;

[0007] Detecting whether heterogeneous executors in the executor cluster are under attack;

[0008] The attacked heterogeneous executors are scheduled offline, and the current executor cluster and the corresponding candidate heterogeneous executors in the executor candidate pool are combined into a pending executor set;

[0009] Perform multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculate the historical confidence of the candidate heterogeneous executors according to the decision results;

[0010] Calculating the difference between candidate heterogeneous executables based on the pending executable set;

[0011] Determine the scheduling priority based on the historical confidence and difference of candidate heterogeneous executors;

[0012] A scheduling scheme is determined according to the scheduling priority and the traffic probe.

[0013] Furthermore, a multi-mode decision is performed according to the historical tasks of the candidate heterogeneous executors, and the historical confidence of the candidate heterogeneous executors is calculated according to the decision results, including:

[0014] In the historical task, obtaining the local decision result of the candidate heterogeneous executor and the global decision result of all heterogeneous executors in the historical task;

[0015] Calculating the credibility of the candidate heterogeneous executor according to the local decision result and the global decision result;

[0016] Count the high threat status, service success times, and service failure times of candidate heterogeneous executors during the scheduling cycle, and calculate the high-risk perception rate and service quality coefficient respectively;

[0017] The historical confidence of the candidate heterogeneous executor is calculated according to the credibility, the high-risk perception rate and the service quality coefficient.

[0018] Further, calculating the difference degree of candidate heterogeneous executables based on the pending executable set includes:

[0019] Querying the CVE vulnerability database and performing code similarity analysis on different heterogeneous executable bodies in the pending executable body set to obtain the characteristic degree of the heterogeneous executable body;

[0020] The difference between the candidate heterogeneous executive and other online heterogeneous executives is calculated according to the characteristic degree.

[0021] Further, calculating the difference between the candidate heterogeneous executable and other online heterogeneous executables according to the characteristic degree includes:

[0022] Respectively calculating the intersection and union of the characteristic degrees of the candidate heterogeneous executive and other online heterogeneous executives, and calculating the quotient value of the intersection and the union;

[0023] The difference between 1 and the quotient is used as the difference between the candidate heterogeneous executor and other online heterogeneous executors.

[0024] Furthermore, determining the scheduling priority according to the historical confidence and difference of the candidate heterogeneous execution bodies includes:

[0025] Calculating a priority weight according to the historical confidence and difference of the candidate heterogeneous executives;

[0026] The priority weight is compared with a preset safety threshold, and the scheduling priority of the candidate heterogeneous execution body is determined according to the comparison result.

[0027] Further, the corresponding candidate heterogeneous execution bodies are respectively placed into corresponding priority queues according to the scheduling priorities;

[0028] Determining a scheduling scheme according to the scheduling priority and the traffic probe includes:

[0029] The switch calculates the bandwidth utilization of the current link based on the received traffic probes;

[0030] The switch updates the routing table of each flow probe according to the header information of the flow probe and the bandwidth utilization of the current link, wherein the table items of the routing table include reachable path information and optimal path information;

[0031] In an update cycle, after receiving all flow probes, the switch calculates a flow classification threshold according to flow probe header information, and determines a flow level of input distribution data of the heterogeneous executor according to the flow classification threshold;

[0032] According to the traffic level, a corresponding candidate isomer and path are selected from the corresponding priority queue for data transmission.

[0033] Furthermore, the header information of the traffic probe includes PathID and PathUtil;

[0034] The PathID is used to record the check value of the node passed by the flow probe, and the PathUtil is used to record the bandwidth utilization rate of the bottleneck link on the flow probe search path;

[0035] Updating the routing table of each flow probe according to the header information of the flow probe and the link bandwidth utilization includes:

[0036] Obtain a reachable path of the traffic probe according to the check value of the node passed by the PathID record, and store the reachable path in a corresponding table entry of the routing table;

[0037] The calculated bandwidth utilization of the current link is compared with the bandwidth utilization of the bottleneck link recorded by the PathUtil, and the path corresponding to the maximum value is determined as the optimal path and stored in the corresponding table entry of the routing table.

[0038] Furthermore, the priority queues include, from high to low, a first priority queue, a second priority queue, and a third priority queue;

[0039] The traffic level includes a first traffic level and a second traffic level, wherein the data flow of the first traffic level is greater than the data flow of the second traffic level;

[0040] Selecting a corresponding candidate isomer and a path from a corresponding priority queue for data transmission according to the traffic level includes:

[0041] When the input distribution data is of the first traffic level, a candidate heterogeneous executor is selected from the first priority queue and data is transmitted along the optimal path. When the input distribution data is of the second traffic level, a candidate heterogeneous executor is selected from the first priority queue or the second priority queue and a path is randomly selected for data transmission.

[0042] A load balancing-based mimetic defense scheduling device applied to the above method, the device comprising:

[0043] A receiving control module is used to control the switch to receive flow probes;

[0044] A detection module, used to detect whether the heterogeneous executives in the executive cluster are attacked;

[0045] The pending module is used to schedule the attacked heterogeneous executors offline, and form a pending executor set with the current executor cluster and the corresponding candidate heterogeneous executors in the executor candidate pool;

[0046] A decision module, used for performing multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculating the historical confidence of the candidate heterogeneous executors according to the decision results;

[0047] A difference calculation module, used for calculating the difference of candidate heterogeneous executables based on the pending executable set;

[0048] A priority determination module, used to determine the scheduling priority according to the historical confidence and difference of the candidate heterogeneous executors;

[0049] A scheduling module is used to determine a scheduling plan according to the scheduling priority and the traffic probe.

[0050] Furthermore, the decision module performs multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculates the historical confidence of the candidate heterogeneous executors according to the decision results, including:

[0051] In the historical task, obtaining the local decision result of the candidate heterogeneous executor and the global decision result of all heterogeneous executors in the historical task;

[0052] Calculating the credibility of the candidate heterogeneous executor according to the local decision result and the global decision result;

[0053] Count the high threat status, service success times, and service failure times of candidate heterogeneous executors during the scheduling cycle, and calculate the high-risk perception rate and service quality coefficient respectively;

[0054] The historical confidence of the candidate heterogeneous executor is calculated according to the credibility, the high-risk perception rate and the service quality coefficient.

[0055] Furthermore, the difference calculation module calculates the difference of the candidate heterogeneous executables based on the pending executable set, including:

[0056] Querying the CVE vulnerability database and performing code similarity analysis on different heterogeneous executable bodies in the pending executable body set to obtain the characteristic degree of the heterogeneous executable body;

[0057] The difference between the candidate heterogeneous executive and other online heterogeneous executives is calculated according to the characteristic degree.

[0058] Furthermore, the difference calculation module calculates the difference between the candidate heterogeneous executable and other online heterogeneous executables according to the characteristic degree, including:

[0059] Respectively calculating the intersection and union of the characteristic degrees of the candidate heterogeneous executive and other online heterogeneous executives, and calculating the quotient value of the intersection and the union;

[0060] The difference between 1 and the quotient is used as the difference between the candidate heterogeneous executor and other online heterogeneous executors.

[0061] Furthermore, the priority determination module determines the scheduling priority according to the historical confidence and difference of the candidate heterogeneous execution bodies, including:

[0062] Calculating a priority weight according to the historical confidence and difference of the candidate heterogeneous executives;

[0063] The priority weight is compared with a preset safety threshold, and the scheduling priority of the candidate heterogeneous execution body is determined according to the comparison result.

[0064] Further, the corresponding candidate heterogeneous execution bodies are respectively placed into corresponding priority queues according to the scheduling priorities;

[0065] The scheduling module determines a scheduling scheme according to the scheduling priority and the traffic probe, including:

[0066] The switch calculates the bandwidth utilization of the current link based on the received traffic probes;

[0067] The switch updates the routing table of each flow probe according to the header information of the flow probe and the bandwidth utilization of the current link, wherein the table items of the routing table include reachable path information and optimal path information;

[0068] In an update cycle, after receiving all flow probes, the switch calculates a flow classification threshold according to flow probe header information, and determines a flow level of input distribution data of the heterogeneous executor according to the flow classification threshold;

[0069] According to the traffic level, a corresponding candidate isomer and path are selected from the corresponding priority queue for data transmission.

[0070] Furthermore, the header information of the traffic probe includes PathID and PathUtil;

[0071] The PathID is used to record the check value of the node passed by the flow probe, and the PathUtil is used to record the bandwidth utilization rate of the bottleneck link on the flow probe search path;

[0072] The scheduling module updates the routing table of each flow probe according to the header information of the flow probe and the link bandwidth utilization, including:

[0073] Obtain a reachable path of the traffic probe according to the check value of the node passed by the PathID record, and store the reachable path in a corresponding table entry of the routing table;

[0074] The calculated bandwidth utilization of the current link is compared with the bandwidth utilization of the bottleneck link recorded by the PathUtil, and the path corresponding to the maximum value is determined as the optimal path and stored in the corresponding table entry of the routing table.

[0075] Furthermore, the priority queues include, from high to low, a first priority queue, a second priority queue, and a third priority queue;

[0076] The traffic level includes a first traffic level and a second traffic level, wherein the data flow of the first traffic level is greater than the data flow of the second traffic level;

[0077] The scheduling module selects corresponding candidate isomers and paths from corresponding priority queues for data transmission according to the traffic level, including:

[0078] When the input distribution data is of the first traffic level, a candidate heterogeneous executor is selected from the first priority queue and data is transmitted along the optimal path. When the input distribution data is of the second traffic level, a candidate heterogeneous executor is selected from the first priority queue or the second priority queue and a path is randomly selected for data transmission.

[0079] An electronic device comprises a processor and a storage device, wherein the storage device stores a plurality of instructions, and the processor is used to read the instructions and execute the above method.

[0080] The load balancing-based mimicry defense scheduling method and device provided by the present invention have at least the following beneficial effects:

[0081] (1) The scheduling method combines the priorities of candidate heterogeneous executors and network traffic conditions to achieve a balance between path selection cost and forwarding efficiency, efficiently utilize multi-path bandwidth resources, and achieve fast traffic forwarding under any network load conditions, thus achieving load balancing in scheduling.

[0082] (2) The scheduling method considers the priority of candidate heterogeneous executors comprehensively, taking into account the difference and historical confidence, avoiding the problem of focusing on a single indicator while ignoring other important factors, and achieving a wider latitude, finer granularity, and deeper level of scheduling, which can improve scheduling efficiency while ensuring scheduling accuracy. This makes scheduling more comprehensive and accurate, and applicable to more decision-making scenarios;

[0083] (3) The introduction of historical confidence and difference combined with the priority queue mechanism improves the security of scheduling and reduces the risk of heterogeneous executors being hacked due to improper scheduling. BRIEF DESCRIPTION OF THE DRAWINGS

[0084] Figure 1The present invention provides a flowchart of an embodiment of a mimicry defense scheduling method based on load balancing.

[0085] Figure 2 The present invention provides a flowchart of an embodiment of calculating historical confidence in the load balancing-based mimicry defense scheduling method.

[0086] Figure 3 The present invention provides a flowchart of an embodiment of calculating the difference degree in the load balancing-based mimicry defense scheduling method.

[0087] Figure 4 The present invention provides a flowchart of an embodiment of determining scheduling priority in the load balancing-based mimicry defense scheduling method provided by the present invention.

[0088] Figure 5 The present invention provides a flowchart of an embodiment of determining a scheduling scheme in a load balancing-based mimicry defense scheduling method.

[0089] Figure 6 A structural schematic diagram of an embodiment of a mimetic defense scheduling device based on load balancing provided by the present invention. DETAILED DESCRIPTION

[0090] In order to better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings and specific implementation methods.

[0091] refer to Figure 1 In some embodiments, a mimetic defense scheduling method based on load balancing is provided, which is applied to a mimetic defense system, wherein the mimetic defense system includes a switch, an online executor cluster, and an executor candidate pool; the method includes:

[0092] S1, the switch receives a flow probe;

[0093] S2, detecting whether the heterogeneous executors in the executor cluster are attacked;

[0094] S3, scheduling the attacked heterogeneous executor offline, and forming a pending executor set with the current executor cluster and the corresponding candidate heterogeneous executors in the executor candidate pool;

[0095] S4, performing multi-mode adjudication according to the historical tasks of the candidate heterogeneous executors, and calculating the historical confidence of the candidate heterogeneous executors according to the adjudication results;

[0096] S5, calculating the difference degree of candidate heterogeneous executables based on the pending executable set;

[0097] S6. Determine the scheduling priority according to the historical confidence and difference of the candidate heterogeneous executors;

[0098] S7. Determine a scheduling plan according to the scheduling priority and the traffic probe.

[0099] Specifically, there are at least three types of heterogeneous executors in the executor cluster and the executor candidate pool, and each type of executor is composed of three components, namely, an operating system, a database, and application service software, forming an application function entity.

[0100] Specifically, in step S1, the traffic probe is attached to the Ethernet frame header field and the IP datagram header field. The traffic probe header field occupies 4 bytes and includes the following information fields: ToRID (16 bits): records the ToR switch ID that generates the traffic probe, and other switches use this to identify the source of the probe. PathID (8 bits): records the check value of the node passed by the traffic probe, and the downstream switch uses this to distinguish different reachable paths. PathUtil (8 bits): records the bandwidth utilization of the bottleneck link on the path that the traffic probe has searched, and the switch uses this to evaluate the congestion of the path. The traffic probe generation frequency is 50ms.

[0101] Furthermore, in step S2 and step S3, it is detected whether the heterogeneous executors in the executor cluster that is executing tasks online are under attack, the attacked heterogeneous executors are scheduled offline, and at the same time, corresponding candidate heterogeneous executors are selected from the executor candidate pool to form a pending executor set with the executor cluster currently online.

[0102] Further, refer to Figure 2 In step S4, a multi-mode decision is performed based on the historical tasks of the candidate heterogeneous executors, and the historical confidence of the candidate heterogeneous executors is calculated based on the decision results, including:

[0103] S41, in the historical task, obtaining the local decision result of the candidate heterogeneous executor and the global decision result of all heterogeneous executors in the historical task;

[0104] S42, calculating the credibility of the candidate heterogeneous executor according to the local decision result and the global decision result;

[0105] S43, counting the high threat status, service success times, and service failure times of the candidate heterogeneous executors during the scheduling period, and calculating the high-risk perception rate and service quality coefficient respectively;

[0106] S44. Calculate the historical confidence of the candidate heterogeneous executor according to the credibility, high-risk perception rate and service quality coefficient.

[0107] Specifically, in step S41 and step S42, in the historical task, the candidate isomer itself is locally adjudicated, and all isomer executors in the historical task are globally adjudicated. If the local adjudication result is the same as the global adjudication result, the candidate isomer is considered to have high credibility. Otherwise, the candidate isomer is considered to have been attacked or an error has occurred, and the call to the candidate isomer should be reduced and cleaned when necessary. Let X n As a result of this global decision, x n The credibility of this partial ruling is calculated as follows:

[0108]

[0109] Among them, T (n) Indicates the credibility, 1 means that the global and local decision results are consistent, and 0 means that the global and local decision results are inconsistent.

[0110] In step S43, statistics are collected on the high threat status, service success times, and service failure times of the candidate heterogeneous executors during the scheduling cycle. High threat status includes the time of being attacked, the time of service anomalies, etc. If the candidate heterogeneous executor has output results in the task, it is considered that the service is successful, otherwise it is considered that the service is failed.

[0111] The service quality factor is calculated using the following formula:

[0112]

[0113] Wherein, ζ is the service quality coefficient, ζ(n) is the service success rate within the time difference from the n-1th to the nth calculation, FPn is the number of service failures within the time difference from the n-1th to the nth calculation, and SPn is the number of service successes.

[0114] Furthermore, the high-risk perception rate is calculated by the following formula:

[0115]

[0116] Among them, R p is the high-risk perception rate, t sum is the time when the isomer enters the high threat state, and t represents the scheduling period.

[0117] Furthermore, in step S44, regarding the historical confidence, the historical confidence of each candidate heterogeneous executor is initially set to 1. If the candidate heterogeneous executor is not selected in a task, the historical confidence of the last decision is maintained unchanged. The calculation formula of the historical confidence is as follows:

[0118]

[0119] Where hi(n) is the historical confidence of the ith candidate heterogeneous executor, S is the set of online heterogeneous executors at the time of adjudication, W1, W2, W3 are weight coefficients, ζ is the service quality coefficient, T represents the credibility, R p It is a high risk perception rate.

[0120] Further, refer to Figure 3 In step S5, the difference degree of candidate heterogeneous executables is calculated based on the pending executable set, including:

[0121] S51, querying the CVE vulnerability database and performing code similarity analysis on different heterogeneous executable bodies in the pending executable body set to obtain the characteristic degree of the heterogeneous executable body;

[0122] S52: Calculate the difference between the candidate heterogeneous executive and other online heterogeneous executives according to the characteristic degree.

[0123] Specifically, in step S51, since the vulnerabilities on the heterogeneous nodes cannot be completely known, the characteristic degree is approximated by querying the CVE vulnerability library and performing code similarity analysis. The characteristic degree can be calculated by the following formula:

[0124] S(Xi)=1 / 2α+1 / 2β;(6)

[0125] Among them, S(Xi) represents the characteristic degree of the heterogeneous executable body, α represents the result of the CVE vulnerability library, and β represents the result of the code similarity analysis. The result of the CVE vulnerability library and the code similarity analysis result can be quantitatively represented, for example, in the form of a vector or code.

[0126] Furthermore, in step S52, the difference between the candidate heterogeneous executable and other online heterogeneous executables is calculated according to the characteristic degree, including:

[0127] Respectively calculating the intersection and union of the characteristic degrees of the candidate heterogeneous executive and other online heterogeneous executives, and calculating the quotient value of the intersection and the union;

[0128] The difference between 1 and the quotient is used as the difference between the candidate heterogeneous executor and other online heterogeneous executors.

[0129] Specifically, the difference is calculated by the following formula:

[0130]

[0131] Among them, D(X a ,X b ) represents the difference between the candidate heterogeneous executor a and the online heterogeneous executor b, s(X a ) represents the characteristic degree of candidate heterogeneous execution body a, s(Xb ) represents the characteristic degree of heterogeneous executive b.

[0132] Further, refer to Figure 4 In step S6, the scheduling priority is determined according to the historical confidence and difference of the candidate heterogeneous execution bodies, including:

[0133] S61, calculating the priority weight according to the historical confidence and difference of the candidate executable body;

[0134] S62: Compare the priority weight with a preset safety threshold, and determine the scheduling priority of the candidate heterogeneous executor according to the comparison result.

[0135] Specifically, in step S61, the priority weight is calculated by combining the historical confidence and difference of the candidate heterogeneous executables, and the calculation formula is as follows:

[0136] q=D i,j +h j ; (8)

[0137] Among them, q is the priority weight of the candidate heterogeneous executor, D i,j is the difference between candidate heterogeneous executor j and online heterogeneous executor i, and hj is the historical confidence of candidate heterogeneous executor.

[0138] Further, in step S62, the priority weight is compared with a preset safety threshold. If the priority weight is within the first safety threshold range, the scheduling priority of the candidate heterogeneous executor is high. If the priority weight is within the second safety threshold range, the scheduling priority of the candidate heterogeneous executor is medium. If the priority weight is within the third safety threshold range, the scheduling priority of the candidate heterogeneous executor is low. For example, the first safety threshold range may be greater than or equal to 1.5, the second safety threshold range may be greater than or equal to 1 and less than 1.5, and the third safety threshold range may be greater than or equal to 0 and less than 1. Specifically, it can be expressed as follows:

[0139]

[0140] Among them, ts represents the scheduling priority, and q is the priority weight of the candidate heterogeneous executor.

[0141] Furthermore, according to the scheduling priority, the corresponding candidate heterogeneous executors are placed in the corresponding priority queues respectively. For example, the candidate heterogeneous executors with high scheduling priority are placed in the first priority queue, the candidate heterogeneous executors with medium scheduling priority are placed in the second priority queue, and the candidate heterogeneous executors with low scheduling priority are placed in the third priority queue.

[0142] Further, refer to Figure 5In step S7, determining a scheduling scheme according to the scheduling priority and the traffic probe includes:

[0143] S71, the switch calculates the bandwidth utilization of the current link according to the received traffic probe;

[0144] S72. The switch updates the routing table of each traffic probe according to the header information of the traffic probe and the bandwidth utilization of the current link, wherein the table items of the routing table include reachable path information and optimal path information;

[0145] S73, within an update cycle, after receiving all flow probes, the switch calculates a flow classification threshold according to flow probe header information, and determines a flow level of input distribution data of the heterogeneous executor according to the flow classification threshold;

[0146] S74. Select corresponding candidate isomers and paths from corresponding priority queues according to the traffic level for data transmission.

[0147] Furthermore, in step S71, each port of the switch receives and calculates the bandwidth utilization U of the current link, which is specifically:

[0148]

[0149] Among them, B represents the number of bytes of the data packet, Δt represents the time interval between arrivals, and ∈ is a constant that determines the sensitivity of congestion perception, which can be 500μs.

[0150] Furthermore, in step S72, the switch updates the routing table of each flow probe according to the header information of the flow probe and the bandwidth utilization of the current link, including:

[0151] Obtain a reachable path of the traffic probe according to the check value of the node passed by the PathID record, and store the reachable path in a corresponding table entry of the routing table;

[0152] The calculated bandwidth utilization of the current link is compared with the bandwidth utilization of the bottleneck link recorded by the PathUtil, and the path corresponding to the maximum value is determined as the optimal path and stored in the corresponding table entry of the routing table.

[0153] Specifically, the routing table entry includes achievable path information (availPath, nextHop) and optimal path information (bestHop, minUtil). First, the traffic probe header information is parsed, and the achievable path and port i recorded by pathID are recorded in the corresponding entry (availPath, nextHop) of the routing table. According to the calculated bandwidth utilization U of the previous link, the calculated bandwidth utilization U of the current link is compared with the bandwidth utilization of the bottleneck link recorded by the PathUtil, and the path corresponding to the maximum value is determined as the optimal path and stored in the corresponding entry (bestHop, minUtil) of the routing table.

[0154] Furthermore, in step S73, within a routing update cycle, after the switch receives all flow probes, the number of flow probes is the total number of reachable paths, and each probe carries an end-to-end complete path information and the bandwidth utilization of its bottleneck link. The calculation formula for the flow classification threshold is as follows:

[0155]

[0156] Where N is the total number of reachable paths, G l represents the bottleneck link load rate on the reachable path, W represents the inherent bandwidth of the link, It represents the remaining average available bandwidth of all reachable paths, R represents the flow classification threshold, and k is the threshold coefficient, which can be set to 0.25%.

[0157] The input distribution data of the heterogeneous executor is divided into flow levels through the flow classification threshold. For example, the flow levels include a first flow level and a second flow level, wherein the data flow of the first flow level is greater than the data flow of the second flow level, that is, the first flow level is a "large flow" and the second flow level is a "small flow".

[0158] Further, in step S74, selecting a corresponding candidate isomer and path from a corresponding priority queue for data transmission according to the traffic level includes:

[0159] When the input distribution data is of the first traffic level, a candidate heterogeneous executor is selected from the first priority queue and data is transmitted along the optimal path. When the input distribution data is of the second traffic level, a candidate heterogeneous executor is selected from the first priority queue or the second priority queue and a path is randomly selected for data transmission.

[0160] In some embodiments, bitflow can also be used to divide the "large flow" or "small flow" into smaller flows to avoid the problem of packet disorder under multi-path transmission. The definition of bitflow is, assuming that two data packets are sent in sequence at time t, and a sufficiently large sending interval T is set. bitflow In order to prevent the second data packet from arriving before the first data packet even if it is transmitted along the optimal path, a bit point is marked between the two data packets, and all data packets between the two bit points belong to the same bitflow.

[0161] refer to Figure 6 In some embodiments, a mimic defense scheduling device based on system benefits and historical confidence applied to the above method is provided, the device comprising:

[0162] The receiving control module 201 is used to control the switch to receive the flow probe;

[0163] A detection module 202, used to detect whether the heterogeneous executables in the executable cluster are attacked;

[0164] The pending module 203 is used to schedule the attacked heterogeneous executor offline, and form a pending executor set with the current executor cluster and the corresponding candidate heterogeneous executors in the executor candidate pool;

[0165] A decision module 204, configured to perform multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculate the historical confidence of the candidate heterogeneous executors according to the decision results;

[0166] A difference calculation module 205, configured to calculate the difference of candidate heterogeneous executables based on the pending executable set;

[0167] A priority determination module 206, configured to determine a scheduling priority according to the historical confidence and difference of the candidate heterogeneous execution bodies;

[0168] The scheduling module 207 is used to determine a scheduling solution according to the scheduling priority and the traffic probe.

[0169] Furthermore, the decision module 204 performs multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculates the historical confidence of the candidate heterogeneous executors according to the decision results, including:

[0170] In the historical task, obtaining the local decision result of the candidate heterogeneous executor and the global decision result of all heterogeneous executors in the historical task;

[0171] Calculating the credibility of the candidate heterogeneous executor according to the local decision result and the global decision result;

[0172] Count the high threat status, service success times, and service failure times of candidate heterogeneous executors during the scheduling cycle, and calculate the high-risk perception rate and service quality coefficient respectively;

[0173] The historical confidence of the candidate heterogeneous executor is calculated according to the credibility, the high-risk perception rate and the service quality coefficient.

[0174] Furthermore, the difference calculation module 205 calculates the difference of the candidate heterogeneous executables based on the pending executable set, including:

[0175] Querying the CVE vulnerability database and performing code similarity analysis on different heterogeneous executable bodies in the pending executable body set to obtain the characteristic degree of the heterogeneous executable body;

[0176] The difference between the candidate heterogeneous executive and other online heterogeneous executives is calculated according to the characteristic degree.

[0177] Furthermore, the difference calculation module 205 calculates the difference between the candidate heterogeneous executable and other online heterogeneous executables according to the characteristic degree, including:

[0178] Respectively calculating the intersection and union of the characteristic degrees of the candidate heterogeneous executive and other online heterogeneous executives, and calculating the quotient value of the intersection and the union;

[0179] The difference between 1 and the quotient is used as the difference between the candidate heterogeneous executor and other online heterogeneous executors.

[0180] Furthermore, the priority determination module 206 determines the scheduling priority according to the historical confidence and difference of the candidate heterogeneous executables, including:

[0181] Calculating a priority weight according to the historical confidence and difference of the candidate heterogeneous executives;

[0182] The priority weight is compared with a preset safety threshold, and the scheduling priority of the candidate heterogeneous execution body is determined according to the comparison result.

[0183] Further, the corresponding candidate heterogeneous execution bodies are respectively placed into corresponding priority queues according to the scheduling priorities;

[0184] The scheduling module 207 determines a scheduling scheme according to the scheduling priority and the traffic probe, including:

[0185] The switch calculates the bandwidth utilization of the current link based on the received traffic probes;

[0186] The switch updates the routing table of each flow probe according to the header information of the flow probe and the bandwidth utilization of the current link, wherein the table items of the routing table include reachable path information and optimal path information;

[0187] In an update cycle, after receiving all flow probes, the switch calculates a flow classification threshold according to flow probe header information, and determines a flow level of input distribution data of the heterogeneous executor according to the flow classification threshold;

[0188] According to the traffic level, a corresponding candidate isomer and path are selected from the corresponding priority queue for data transmission.

[0189] Furthermore, the header information of the traffic probe includes ToRID, PathID and PathUtil;

[0190] The ToRID is used to record the switch ID of the flow probe, the PathID is used to record the check value of the node passed by the flow probe, and the PathUtil is used to record the bandwidth utilization rate of the bottleneck link on the flow probe search path;

[0191] The scheduling module 207 updates the routing table of each flow probe according to the header information of the flow probe and the link bandwidth utilization, including:

[0192] Obtain a reachable path of the traffic probe according to the check value of the node passed by the PathID record, and store the reachable path in a corresponding table entry of the routing table;

[0193] The calculated bandwidth utilization of the current link is compared with the bandwidth utilization of the bottleneck link recorded by the PathUtil, and the path corresponding to the maximum value is determined as the optimal path and stored in the corresponding table entry of the routing table.

[0194] Furthermore, the priority queues include, from high to low, a first priority queue, a second priority queue, and a third priority queue;

[0195] The traffic level includes a first traffic level and a second traffic level, wherein the data flow of the first traffic level is greater than the data flow of the second traffic level;

[0196] The scheduling module 207 selects corresponding candidate isomers and paths from corresponding priority queues for data transmission according to the traffic level, including:

[0197] When the input distribution data is of the first traffic level, a candidate heterogeneous executor is selected from the first priority queue and data is transmitted along the optimal path. When the input distribution data is of the second traffic level, a candidate heterogeneous executor is selected from the first priority queue or the second priority queue and a path is randomly selected for data transmission.

[0198] In some embodiments, an electronic device is also provided, including a processor and a storage device, wherein the storage device stores a plurality of instructions, and the processor is used to read the instructions and execute the above method.

[0199] The load balancing-based mimicry defense scheduling method and device provided in the above embodiment have at least the following beneficial effects:

[0200] (1) The scheduling method combines the priorities of candidate heterogeneous executors and network traffic conditions to achieve a balance between path selection cost and forwarding efficiency, efficiently utilize multi-path bandwidth resources, and achieve fast traffic forwarding under any network load conditions, thus achieving load balancing in scheduling.

[0201] (2) The scheduling method considers the priority of candidate heterogeneous executors comprehensively, taking into account the difference and historical confidence, avoiding the problem of focusing on a single indicator while ignoring other important factors, and achieving a wider latitude, finer granularity, and deeper level of scheduling, which can improve scheduling efficiency while ensuring scheduling accuracy. This makes scheduling more comprehensive and accurate, and applicable to more decision-making scenarios;

[0202] (3) The introduction of historical confidence and difference combined with the priority queue mechanism improves the security of scheduling and reduces the risk of heterogeneous executors being hacked due to improper scheduling.

[0203] Although preferred embodiments of the present invention have been described, additional changes and modifications may be made to these embodiments by those skilled in the art once the basic inventive concepts are known. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention. Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A mimicry defense scheduling method based on load balancing, characterized in that: Applied to a mimicry defense system, the mimicry defense system includes a switch, an online executor cluster, and an executor candidate pool; the method includes: The switch receives a flow probe; Detecting whether heterogeneous executors in the executor cluster are under attack; The attacked heterogeneous executors are scheduled offline, and the current executor cluster and the corresponding candidate heterogeneous executors in the executor candidate pool are combined into a pending executor set; Perform multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculate the historical confidence of the candidate heterogeneous executors according to the decision results; Calculating the difference between candidate heterogeneous executables based on the pending executable set; Determine the scheduling priority based on the historical confidence and difference of candidate heterogeneous executors; A scheduling scheme is determined according to the scheduling priority and the traffic probe.

2. The method according to claim 1, characterized in that Performing multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculating the historical confidence of the candidate heterogeneous executors according to the decision results, including: In the historical task, obtaining the local decision result of the candidate heterogeneous executor and the global decision result of all heterogeneous executors in the historical task; Calculating the credibility of the candidate heterogeneous executor according to the local decision result and the global decision result; Count the high threat status, service success times, and service failure times of candidate heterogeneous executors during the scheduling cycle, and calculate the high-risk perception rate and service quality coefficient respectively; The historical confidence of the candidate heterogeneous executor is calculated according to the credibility, the high-risk perception rate and the service quality coefficient.

3. The method according to claim 1, characterized in that Calculating the difference between candidate heterogeneous executables based on the pending executable set includes: Querying the CVE vulnerability database and performing code similarity analysis on different heterogeneous executable bodies in the pending executable body set to obtain the characteristic degree of the heterogeneous executable body; The difference between the candidate heterogeneous executive and other online heterogeneous executives is calculated according to the characteristic degree.

4. The method according to claim 3, characterized in that Calculating the difference between the candidate heterogeneous executable and other online heterogeneous executables according to the characteristic degree includes: Respectively calculating the intersection and union of the characteristic degrees of the candidate heterogeneous executive and other online heterogeneous executives, and calculating the quotient value of the intersection and the union; The difference between 1 and the quotient is used as the difference between the candidate heterogeneous executor and other online heterogeneous executors.

5. The method according to claim 1, characterized in that The scheduling priority is determined according to the historical confidence and difference of the candidate heterogeneous executors, including: Calculating a priority weight according to the historical confidence and difference of the candidate heterogeneous executives; The priority weight is compared with a preset safety threshold, and the scheduling priority of the candidate heterogeneous execution body is determined according to the comparison result.

6. The method according to claim 1, characterized in that According to the scheduling priority, the corresponding candidate heterogeneous execution bodies are placed into the corresponding priority queues; Determining a scheduling scheme according to the scheduling priority and the traffic probe includes: The switch calculates the bandwidth utilization of the current link based on the received traffic probes; The switch updates the routing table of each flow probe according to the header information of the flow probe and the bandwidth utilization of the current link, wherein the table items of the routing table include reachable path information and optimal path information; In an update cycle, after receiving all flow probes, the switch calculates a flow classification threshold according to flow probe header information, and determines a flow level of input distribution data of the heterogeneous executor according to the flow classification threshold; According to the traffic level, a corresponding candidate isomer and path are selected from the corresponding priority queue for data transmission.

7. The method according to claim 6, characterized in that The header information of the flow probe includes PathID and PathUtil; The PathID is used to record the check value of the node passed by the flow probe, and the PathUtil is used to record the bandwidth utilization rate of the bottleneck link on the flow probe search path; Updating the routing table of each flow probe according to the header information of the flow probe and the link bandwidth utilization includes: Obtain a reachable path of the traffic probe according to the check value of the node passed by the PathID record, and store the reachable path in a corresponding table entry of the routing table; The calculated bandwidth utilization of the current link is compared with the bandwidth utilization of the bottleneck link recorded by the PathUtil, and the path corresponding to the maximum value is determined as the optimal path and stored in the corresponding table entry of the routing table.

8. The method according to claim 6, characterized in that The priority queues include, from high to low, a first priority queue, a second priority queue, and a third priority queue; The traffic level includes a first traffic level and a second traffic level, wherein the data flow of the first traffic level is greater than the data flow of the second traffic level; Selecting a corresponding candidate isomer and a path from a corresponding priority queue for data transmission according to the traffic level includes: When the input distribution data is of the first traffic level, a candidate heterogeneous executor is selected from the first priority queue and data is transmitted along the optimal path. When the input distribution data is of the second traffic level, a candidate heterogeneous executor is selected from the first priority queue or the second priority queue and a path is randomly selected for data transmission.

9. A load balancing-based mimicry defense scheduling device applied to the method according to any one of claims 1 to 8, characterized in that: The device comprises: A receiving control module is used to control the switch to receive flow probes; A detection module, used to detect whether the heterogeneous executives in the executive cluster are attacked; The pending module is used to schedule the attacked heterogeneous executors offline, and form a pending executor set with the current executor cluster and the corresponding candidate heterogeneous executors in the executor candidate pool; A decision module, used for performing multi-mode decision according to the historical tasks of the candidate heterogeneous executors, and calculating the historical confidence of the candidate heterogeneous executors according to the decision results; A difference calculation module, used for calculating the difference of candidate heterogeneous executables based on the pending executable set; A priority determination module, used to determine the scheduling priority according to the historical confidence and difference of the candidate heterogeneous executors; A scheduling module is used to determine a scheduling plan according to the scheduling priority and the traffic probe.

10. An electronic device, characterized in that: The method comprises a processor and a storage device, wherein the storage device stores a plurality of instructions, and the processor is used to read the instructions and execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Mimicry defense dynamic scheduling method based on multistage queues

    CN111556030A

  • Distributed multi-node mimicry defense system and security resource scheduling method thereof

    CN118337445A

  • Mimicry asynchronous judgment method based on historical confidence coefficient and breaking probability

    CN118523937A

  • Mimicry defense judgment method and device, equipment and storage medium

    CN118694584A