Traffic detection method and device, and storage medium
By obtaining the security characteristic parameters and detection levels of the computing power domain, and dynamically selecting the abnormal traffic detection model, the problem of insufficient traffic detection accuracy in the computing power network is solved, and more efficient and accurate traffic detection is achieved.
Patent Information
- Application Number
- CN202311641512.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-01
- Publication Date
- 2025-06-03
AI Technical Summary
In computing power networks, traditional traffic detection technology is difficult to meet the current complex and large-scale detection needs, especially when there are differences between different computing power domains, and the accuracy is insufficient.
By obtaining the safety characteristic parameters of the computing power domain, determining its detection level, and selecting the corresponding abnormal flow detection model according to the detection level, and dynamically adjusting the detection model to achieve accurate flow detection.
It improves the accuracy and flexibility of traffic detection, and can accurately detect computing power domains of different detection levels, thereby improving the security of computing power domains.
Smart Images

Figure CN120090812A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network security technologies, and in particular, to a traffic detection method, device, and storage medium. Background Art
[0002] With the development and construction of emerging technologies such as edge computing technology, the amount of data in various industries has shown an explosive growth trend. Various data-related terminals, such as data centers, edge computing nodes, etc., jointly constitute a huge distributed computing resource network, and this distributed network is also called a computing power network. The computing power network aims to break through the computing power limitations of independent terminals such as data centers, supercomputing centers, cloud computing, and edge computing through the integration of ubiquitous computing power and network, and build a new intelligent, efficient, and on-demand computing power service system that combines computing and network to meet the current data needs and promote the development of the digital economy.
[0003] With the rise of the computing power network, various security risks such as an increased attack exposure surface, computing power abuse, and data leakage have been exposed. At the traffic level, with the increase in the scale and complexity of the computing power network, it has become increasingly difficult to detect traffic. The main reason is that in a large-scale computing power network, the traffic pattern is very complex, involving a large amount of data transmission and computing tasks, and there are significant differences between different computing power domains in the computing power network. The accuracy of traditional traffic detection technologies cannot meet the current detection requirements.
[0004] Therefore, how to cope with the current computing power network scenario and improve the accuracy of traffic detection is an urgent problem to be solved. Summary of the Invention
[0005] Embodiments of the present disclosure provide a traffic detection method, device, and storage medium, which can improve the flexibility and accuracy of traffic detection.
[0006] In a first aspect, a traffic detection method is provided, including:
[0007] Obtaining security feature parameters of a computing power domain;
[0008] Determining a detection level corresponding to the computing power domain based on the security feature parameters of the computing power domain;
[0009] Determining an abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain;
[0010] Sending the abnormal traffic detection model corresponding to the computing power domain to the computing power domain so that the computing power domain detects abnormal traffic in the computing power domain based on the abnormal traffic detection model.
[0011] In a second aspect, an electronic device is provided, including:
[0012] An obtaining module, configured to obtain security feature parameters of a computing power domain;
[0013] A determination module, configured to determine a detection level corresponding to a computing power domain based on security feature parameters of the computing power domain;
[0014] The determination module is further configured to determine an abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain;
[0015] A communication module, configured to send the abnormal traffic detection model corresponding to the computing power domain to the computing power domain, so that the computing power domain detects the abnormal traffic of the computing power domain based on the abnormal traffic detection model.
[0016] In a third aspect, another electronic device is provided, including: a memory and a processor; the memory and the processor are coupled; the memory is configured to store instructions executable by the processor; when the processor executes the instructions, it executes the traffic detection method in the first aspect above.
[0017] In a fourth aspect, a computer-readable storage medium is provided, on which computer instructions are stored. When the computer instructions run on a computer, the computer executes the traffic detection method in the first aspect above.
[0018] In the embodiments of the present disclosure, the detection level of the computing power domain is determined through the security feature parameters of the computing power domain, and the corresponding abnormal traffic detection model is selected according to the detection level. During the traffic detection process, different abnormal traffic detection models can be dynamically selected according to the different detection levels of the computing power domain, realizing precise traffic detection for computing power domains with different detection levels, so that during the traffic detection process of the computing power domain, it has pertinence, can improve the accuracy of traffic detection, and improve the security of the computing power domain. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the present disclosure, the following will briefly introduce the drawings required to be used in some embodiments of the present disclosure. Obviously, the drawings in the following description are only the drawings of some embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can also be obtained according to these drawings.
[0020] Figure 1 A scenario architecture diagram of a traffic detection provided for an embodiment of the present disclosure;
[0021] Figure 2 A flowchart of a traffic detection method provided for an embodiment of the present disclosure;
[0022] Figure 3 A flowchart of determining a trust level provided for an embodiment of the present disclosure;
[0023] Figure 4Flow chart of another traffic detection method provided by an embodiment of the present disclosure;
[0024] Figure 5 System topology diagram of a traffic detection scenario provided by an embodiment of the present disclosure;
[0025] Figure 6 Execution flow chart of a traffic detection provided by an embodiment of the present disclosure;
[0026] Figure 7 Structural flow chart of a computing and network security knowledge base provided by an embodiment of the present disclosure;
[0027] Figure 8 System architecture diagram of a traffic detection method provided by an embodiment of the present disclosure;
[0028] Figure 9 Structural schematic diagram of a node migration provided by an embodiment of the present disclosure;
[0029] Figure 10 Structural schematic diagram of an electronic device provided by an embodiment of the present disclosure;
[0030] Figure 11 Structural schematic diagram of another electronic device provided by an embodiment of the present disclosure. Detailed implementation manners
[0031] Next, the technical solutions in the embodiments of the present disclosure will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.
[0032] In the description of the present disclosure, unless otherwise specified, " / " means "or". For example, A / B may represent A or B. Herein, "and / or" is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, "at least one" means one or more, and "a plurality" means two or more. The words "first", "second", etc. do not limit the quantity and execution order, and the words "first", "second", etc. do not necessarily mean different.
[0033] It should be noted that in this disclosure, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in this disclosure should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner.
[0034] Currently, the related technologies for traffic detection in the computing power network cannot meet the current security requirements. For example, there is a cloud-edge computing power network traffic management method and system based on federated learning in the related technologies. It predicts and classifies the global traffic of the computing power network, and solves the problem of inability to ensure the privacy and security of user traffic information and data when performing cloud computing traffic management. The specific process is as follows:
[0035] Obtain local private traffic data through computing power nodes, and train the local initial traffic prediction model with the local private traffic data to obtain initial model parameters; upload the initial model parameters to the computing power controller for aggregation to obtain global model parameters, and send the global model parameters back to the local initial traffic prediction model to obtain a cloud-edge computing power network global traffic prediction model, and send the global traffic prediction model to each computing power node to predict the traffic; obtain the network traffic to be scheduled, classify the network traffic to be scheduled, obtain traffic prediction values according to different types, and calculate the path of the network traffic to achieve optimal path scheduling.
[0036] In the above technology, using the same global traffic prediction model to predict the traffic of multiple different computing power nodes cannot guarantee the accuracy of its prediction. And the above technology has insufficient scalability in the application scenario of the computing power network. The system trains local models with computing power nodes as units and uploads model parameters to the computing power controller, without considering the characteristics of large scale and wide coverage of the computing power network, and insufficient consideration in terms of training data scale and model overhead.
[0037] From the above description, it can be seen that the current related technologies for traffic detection in the computing power domain cannot effectively cope with the current computing power network scenario, and the accuracy of traffic detection cannot meet the current detection requirements.
[0038] Based on this, the embodiments of this disclosure provide a traffic detection method, which determines the detection level of the computing power domain through the security feature parameters of the computing power domain, and selects the corresponding abnormal traffic detection model according to the detection level. During the traffic detection process, different abnormal traffic detection models can be dynamically selected according to the different detection levels of the computing power domain, realizing precise traffic detection for computing power domains with different detection levels, so that during the traffic detection process of the computing power domain, it has pertinence, can improve the accuracy of traffic detection, and improve the security of the computing power domain.
[0039] Figure 1 A flow detection scenario architecture diagram provided by the present disclosure, such as Figure 1 As shown, it includes a computing power network 110 and a server 120.
[0040] A computing network refers to a computing network platform that interconnects multiple computing node clusters through a certain protocol to form a large virtual cluster and provides a unified user interface. In the computing network, there are multiple new information infrastructure measures that allocate and flexibly schedule computing resources, storage resources, and network resources on demand between clouds, networks, and edges according to business needs. The above new information infrastructure measures are also called computing domains. The computing domain deeply integrates edge computing nodes, cloud computing nodes, and various network resources including regional networks to form a computing network, realizing the intensive and coordinated computing power.
[0041] like Figure 1 As shown, the computing power network 110 includes multiple computing power domains, such as computing power domain 10, computing power domain 20, and computing power domain 30. The computing power domain may include multiple processors and processor cores. Each processor or processor core may be a computing power resource, so each computing power domain can provide computing power resources. The computing power domains are interconnected through a network, and the computing power network 110 composed of multiple computing power domains and the server 120 can also be interconnected through a network.
[0042] In some embodiments, the server 120 may be a device or network device with computing functions such as a cloud server or a network server. The server 120 may be a single server, or a server cluster consisting of multiple servers, or a cloud computing service center.
[0043] In some embodiments, the server 120 can obtain the security feature parameters of the computing power domain in the computing power network 110, and based on the security feature parameters, determine the detection level corresponding to the computing power domain, and determine the abnormal traffic detection model corresponding to the computing power domain according to the detection level of the computing power domain.
[0044] It should be noted that Figure 1 For simplicity, only three computing domains are shown in the computing network 110. In fact, the computing network 110 may include more computing domains. The server 120 is also called the computing security control center, which is not limited in this disclosure. It should also be noted that Figure 1 This is just an exemplary framework diagram. Figure 1 The number of devices included in the Figure 1 In addition to the devices shown, other devices may also be included in the scenario architecture.
[0045] The application scenarios of the embodiments of the present disclosure are not limited. The system architecture and business scenarios described in the embodiments of the present disclosure are for more clearly explaining the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those of ordinary skill in the art will know that with the evolution of the network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are equally applicable to similar technical problems.
[0046] Figure 2 FIG. shows a schematic flow chart of a traffic detection method provided by an embodiment of the present disclosure. As Figure 2 shown, it is applied to a server, and the traffic detection method includes the following steps:
[0047] S101. Obtain the security feature parameters of the computing power domain.
[0048] In some embodiments, when it is necessary to perform traffic detection on the computing power domain, the server sends a parameter request to the computing power domain to request the security feature parameters of the computing power domain.
[0049] Exemplarily, the frequency of the server sending the parameter request is correlated with the traffic detection period. The traffic detection period is the interval time for performing traffic detection on the computing power domain. For example, when the traffic detection period is set to 5 hours, the server performs traffic detection on the computing power domain every 5 hours, that is, sends a parameter request to the computing power domain every 5 hours to obtain the security feature parameters of the computing power domain. Or, every 5 hours, the computing power domain actively sends the security feature parameters to the server without the server sending a parameter request.
[0050] Among them, the security feature parameters include at least one of the following: trust level, computing power parameter, and security requirement parameter.
[0051] The trust level is used to characterize the security degree of the computing power domain, the computing power parameter is used to characterize the computing power of the computing power domain, and the security requirement parameter is used to characterize the degree of security requirements of the computing power domain.
[0052] In some embodiments, as Figure 3 shown, the trust level is determined according to the following method:
[0053] S1011. Obtain the number of attacks on the computing power domain.
[0054] In some embodiments, the number of attacks on the computing power domain is stored in the traffic historical behavior library, and the server can obtain the number of attacks on the computing power domain from the traffic historical behavior library.
[0055] Among them, the traffic historical behavior library is collected and integrated by the control nodes in the computing power domain and is used to store the historical traffic behaviors of each node in the computing power domain. The historical traffic behaviors include the number of attacks on the computing power domain.
[0056] Exemplarily, the traffic history behavior library can be established in the following manner: The control node within the computational power domain collects traffic records, extracts key features affecting the accuracy of abnormal traffic detection through feature processes, etc., and establishes a tabular dataset, that is, the traffic history behavior library. After establishment, according to the tabular data, features such as different computational power domain identifiers (CPDIs), the type of the current traffic source application, the number of attacks, and the proportion of the number of attacks in the total are extracted, and finally a complete traffic history behavior library is obtained.
[0057] Among them, the number of attacks in the computational power domain is used to represent the number of times the computational power domain successfully initiates an attack.
[0058] S1012. Determine the trust level of the computational power domain based on the number of attacks in the computational power domain.
[0059] It should be noted that the number of attacks in the computational power domain reflects the security of the computational power domain, and has a negative correlation with the security of the computational power domain. The security of the computational power domain determines the trust level of the computational power domain on the server side. Therefore, the trust level of the computational power domain can be determined based on the number of attacks in the computational power domain.
[0060] In some embodiments, the trust level of the computational power domain is determined according to the proportion of the number of attacks in the computational power domain.
[0061] Among them, the proportion of the number of attacks in the computational power domain is also the ratio of the historical number of attacks in the computational power domain to the total number of attacks in the above traffic history behavior library.
[0062] Exemplarily, the trust level of the computational power domain can be divided into the following three levels: level one, level two, and level three. When the proportion of the number of attacks in the computational power domain is less than or equal to the first attack number threshold, it is determined that the trust level of this computational power domain is level one, that is, this computational power domain is a fully trusted mode computational power domain. When the proportion of the number of attacks in the computational power domain is greater than the first attack number threshold and less than the second attack number threshold, it is determined that the trust level of this computational power domain is level two, that is, this computational power domain is a semi-trusted mode computational power domain. When the proportion of the number of attacks in the computational power domain is greater than or equal to the second attack number threshold, it is determined that the trust level of this computational power domain is level three, that is, this computational power domain is a non-trusted mode computational power domain.
[0063] Among them, for the fully trusted mode computational power domain, the confidentiality, integrity, and availability during its data calculation process are all guaranteed. Therefore, on the server side, the trust level of the fully trusted mode computational power domain is relatively high.
[0064] For the computing power domain in the non-trusted mode, during the data calculation process, the traffic security processing module responsible for data calculation needs to use a high-precision detection algorithm to perform security processing on user data. Additional security calculation methods and data processing methods will increase the amount of calculation and communication volume, resulting in its resource overhead being greater than that of the fully trusted mode computing power domain, making the efficiency of the non-trusted mode computing power domain in executing calculation tasks lower than that of the fully trusted mode computing power domain. On the server side, the trust level of the semi-trusted mode computing power domain is relatively low.
[0065] Compared with the fully trusted mode computing power domain and the non-trusted mode computing power domain, the trust level of the semi-trusted mode computing power domain on the server side is between the two.
[0066] In some embodiments, after determining the trust level of the computing power domain, the trust level of the computing power domain can be uploaded to the computing network trust level library. Among them, the computing network trust level library is used to store the trust levels of each computing power domain in the computing network.
[0067] Exemplarily, when the server needs to obtain the trust level of the computing power domain, it can first send a level request to the computing network trust level library to request the trust level of the computing power domain. When the trust level of the computing power domain exists in the computing network trust level library, the server can directly obtain the trust level of the computing power domain. When the trust level of the computing power domain does not exist in the computing network trust level library, the server can, according to the above embodiments, determine the trust level of the computing power domain based on the number of attacks on the computing power domain, and then upload the trust level of the computing power domain to the computing network trust level library for other servers to obtain and use.
[0068] In some embodiments, the computing power parameter of the computing power domain is stored in the computing network computing power library, and the server can directly obtain the computing power parameter of the computing power domain from the computing network computing power library.
[0069] Among them, the computing network computing power library is used to store the computing power parameters of each computing power domain, and each computing power domain reports its own computing power parameters to the computing network computing power library by itself.
[0070] Exemplarily, when the number of computing power nodes in the computing power domain is large and the computing power is strong, the computing power parameter of the computing power domain is higher, which also means that the carrying capacity of the computing power domain is stronger. When performing traffic detection on the computing power domain, the computing power domain can carry a larger-scale and more complex abnormal traffic detection model, and the obtained detection results are more accurate.
[0071] In some embodiments, the security requirement parameter of the computing power domain is stored in the computing network security requirement library, and the server can directly obtain the security requirement ability of the computing power domain from the computing network security requirement library.
[0072] Among them, the computing network security requirement library is used to store the security requirement parameters of each computing power domain, and each computing power domain reports its own security requirement parameters to the computing network security requirement library.
[0073] For example, the security requirement parameters of the computing domain also represent the business requirements of the computing domain. When detecting abnormal traffic, corresponding resources can be allocated according to the security requirement parameters. The server can intuitively allocate appropriate resources to the computing domain according to the security requirement parameters, while ensuring the security requirements of the computing domain.
[0074] In some embodiments, in order to ensure the real-time security feature parameters of the computing power domain, the computing network trusted level library, the computing network computing capacity library and the computing network security requirement library are periodically updated to ensure the real-time security feature parameters, so as to ensure their accuracy during the abnormal traffic detection process.
[0075] S102. Determine the detection level corresponding to the computing power domain based on the security feature parameters of the computing power domain.
[0076] Among them, the detection level is used to characterize the complexity of the abnormal traffic detection model corresponding to the computing power domain.
[0077] It should be understood that in order to ensure the accuracy and efficiency of determining the detection level corresponding to the computing power domain, each parameter in the security feature parameters can be graded during the determination process.
[0078] For example, the trust level of the computing power domain is divided into three levels. Taking T as the security level of the computing power domain, it is divided into the following three levels T = {T c ,T m ,T I Similarly, the computing power parameters and security requirement parameters of the computing power domain are also divided into three levels. Taking C as the computing power parameter of the computing power domain, there are the following three levels C={C h ,C m ,C l}, taking D as the security requirement parameter of the computing power domain, there are the following three levels D={D h ,D m ,D l}.
[0079] After the above parameters are graded, the grades corresponding to the above parameters can be directly assigned, which can further improve the accuracy of determining the detection grade corresponding to the computing power domain.
[0080] For example, as shown in Table 1, a level assignment rule provided by the present disclosure is provided. For example, if the trust level of the computing power domain is T c , that is, the fully trusted computing domain, which means that the trust level of this domain is high, so it only needs to be assigned a value of 1. On the contrary, if it is a non-trusted computing domain TI Then it needs to be assigned a value of 3, indicating that this domain is a high-risk domain. The computing power parameter is similar to the security requirement parameter. If the level of the computing power parameter is low at C l or the level of the security requirement parameter is low at D l It indicates that the computing power domain has a low ability to carry complex detection models or a low security requirement. Therefore, it is assigned a value of 1. Otherwise, it is assigned a value of 3.
[0081] Table 1
[0082] Trust level Computing power parameter Security requirement parameter Assignment <![CDATA[T c > <![CDATA[C l > <![CDATA[D l > 1 <![CDATA[T m > <![CDATA[C m > <![CDATA[D m > 2 <![CDATA[T I > <![CDATA[C h > <![CDATA[D h > 3
[0083] In some embodiments, after assigning values to the security feature parameters of the computing power domain, the detection level corresponding to the computing power domain can be directly determined according to the security feature parameters.
[0084] Exemplarily, the sum of the assigned values corresponding to the above three parameters can be used as the standard for the detection level corresponding to the computing power domain. Taking S as the sum of the assigned values corresponding to the above three parameters, the detection level is divided into three levels. When S is 3 - 5, the detection level corresponding to the computing power domain is level one. When the S value is 5 - 7, the detection level corresponding to the computing power domain is level two. When the S value is 8 - 9, the traffic detection level is level three. For example, the trust level of this computing power domain is T m and its corresponding assigned value is 2. The level of the computing power parameter of this computing power domain is C l and its corresponding assigned value is 1. The level of the security requirement parameter of this computing power domain is D h and the corresponding assigned value is 3. In summary, the sum S of the assigned values corresponding to the three parameters is 6, so the detection level corresponding to this computing power domain is level two.
[0085] In this way, by classifying each parameter in the security feature parameters of the computing power domain and assigning values to their levels, the accuracy and determination efficiency of determining the detection level corresponding to the computing power domain are improved.
[0086] In some embodiments, as Figure 4 shown, based on the security feature parameters of the computing power domain, determining the detection level corresponding to the computing power domain can be specifically implemented as the following steps:
[0087] S1021. Obtain the weight coefficient corresponding to the trust level, the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the security requirement parameter.
[0088] It should be noted that the three parameters in the security feature parameters of the computing power domain have different degrees of influence on the detection level corresponding to the computing power domain. From the above description, it can be seen that the trust level in the security feature parameters has the highest degree of influence on the detection level corresponding to the computing power domain, the computing power parameter has a lower degree of influence on the detection level corresponding to the computing power domain, and the security requirement parameter has the lowest degree of influence on the detection level corresponding to the computing power domain. If the weight coefficients corresponding to each parameter are combined to determine the detection level corresponding to the computing power domain, the determined detection level corresponding to the computing power domain can be made more accurate.
[0089] Exemplarily, the weight coefficients corresponding to the above three parameters can be preset values. When the server determines the detection level corresponding to the computing power domain, it can directly use the preset values for determination. Alternatively, the weight coefficients corresponding to the above three parameters can be determined according to the actual application. The server can determine the weight coefficients corresponding to the three parameters according to the degrees of influence of the three parameters on the detection level in the actual application.
[0090] In some embodiments, the weight coefficient corresponding to the trust level is greater than the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the computing power parameter is greater than the weight coefficient corresponding to the security requirement parameter.
[0091] It should be understood that the trust level in the security feature parameters has the highest degree of influence on the detection level corresponding to the computing power domain, the computing power parameter is the second, and the security requirement parameter is the lowest. The weight coefficients corresponding to each parameter in the security feature parameters can be determined according to the above degrees of influence. Exemplarily, the weight coefficient corresponding to the trust level is set to 3, the weight coefficient corresponding to the computing power parameter is set to 2, and the weight coefficient corresponding to the security requirement parameter is set to 1.
[0092] It should be noted that the weight coefficients corresponding to each parameter can be determined based on multiple aspects and can be set according to the actual situation in the actual application process. The present disclosure places no restrictions on this.
[0093] S1022. Based on the weight coefficient corresponding to the trust level, the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the security requirement parameter, perform weighted calculation on the trust level, the computing power parameter, and the security requirement parameter to obtain the detection level corresponding to the computing power domain.
[0094] Exemplarily, taking the weight coefficient corresponding to the trust level as 3, the weight coefficient corresponding to the computing power parameter as 2, and the weight coefficient corresponding to the security requirement parameter as 1 as an example, the assignments corresponding to each parameter and the corresponding weight coefficients satisfy the following formula S = 3T + 2D + C. The detection level is divided into three levels. When S is 6 - 8, the detection level corresponding to its computing power domain is level one. When S is 9 - 11, the detection level corresponding to its computing power domain is level two. When the S value is 12 - 18, the traffic detection level is level three. For example, the trust level of this computing power domain is T m , and its corresponding assignment is 2. The level of the computing power parameter of this computing power domain is C l , and its corresponding assignment is 1. The level of the security requirement parameter of this computing power domain is D h , and the corresponding assignment is 3. In summary, according to the above formula, the S value is obtained as 11, so the detection level corresponding to this computing power domain is level two.
[0095] In some other embodiments, based on the security feature parameters of the computing power domain, determining the detection level corresponding to the computing power domain can be specifically implemented as the following steps: Based on a preset evaluation criterion, perform an evaluation process on the security feature parameters of the computing power domain to determine the detection level corresponding to the computing power domain.
[0096] Among them, the preset evaluation criterion is used to indicate the detection level corresponding to the computing power domain corresponding to the security feature parameters, and the preset evaluation criterion can be set according to the actual application scenario.
[0097] Exemplarily, taking the case where the trust level of the computing power domain in the application scenario has a greater impact on the detection level as an example. The trust level, computing power parameter, and security requirement parameter in the security feature parameters can all be divided into three levels. Then, the preset evaluation criterion includes the following two items:
[0098] First, in the case where neither the computing power parameter nor the security requirement parameter is level three, use the trust level of the computing power domain as the detection level of the computing power domain.
[0099] Second, in the case where both the computing power parameter and the security requirement parameter are level three, use the trust level of the computing power domain + 1 as the detection level of the computing power domain.
[0100] For example, in the case where the trust level of the computing power domain is level two and both the computing power parameter and the security requirement parameter are level two, directly use the trust level of the computing power domain as the detection level of the computing power domain, that is, the detection level of the computing power domain is level two. Another example, in the case where the trust level of the computing power domain is level two and both the computing power parameter and the security requirement parameter are level three, use the trust level of the computing power domain + 1 as the detection level of the computing power domain, that is, the detection level of the computing power domain is level three.
[0101] It should be understood that the preset evaluation criteria are the criteria set according to the actual application scenario, and are mainly determined according to the influence degree of each parameter in the security feature parameters on the detection level of the computing power domain in the actual application scenario. Alternatively, it can also be determined according to the historical security feature parameters and historical detection levels of the computing power domain. Alternatively, it can also be directly determined by relevant experts, and the present disclosure does not limit this.
[0102] S103. Determine the abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain.
[0103] Among them, the abnormal traffic detection model is a random forest model, which has the characteristics of flexibility and variability, and can establish abnormal traffic detection models with different accuracies and delay overheads by adjusting the depth and number of trees.
[0104] In some embodiments, determining the abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain can be specifically implemented as the following steps: Determine the abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain and the preset corresponding relationship.
[0105] Among them, the preset corresponding relationship is used to represent the corresponding relationship between multiple detection levels and multiple abnormal traffic detection models. The multiple abnormal traffic detection models have different complexities, and the higher the detection level, the higher the complexity of the corresponding abnormal traffic detection model.
[0106] In some embodiments, the multiple abnormal traffic detection models at least include a first abnormal traffic detection model, a second abnormal traffic detection model, and a third abnormal traffic detection model.
[0107] Among them, the complexity of the third abnormal traffic detection model is higher than that of the second abnormal traffic detection model, and the complexity of the second abnormal traffic detection model is higher than that of the first abnormal traffic detection model.
[0108] Exemplarily, the depth of the first abnormal traffic detection model can be b 1 , and the number of trees is c 1 , the depth of the second abnormal traffic detection model can be b 2 , and the number of trees is c 2 , the depth of the third abnormal traffic detection model can be b 3 , and the number of trees is c 3 . Among them, the depth of the tree (max_depth) b 1 < b 2 < b 3 , the number of trees (n_estimators) c 1 < c 2 < c 3 .
[0109] In some embodiments, the preset correspondence relationship at least includes: a detection level less than the first threshold corresponds to the first abnormal traffic detection model; a detection level greater than or equal to the first threshold and less than the second threshold corresponds to the second abnormal traffic detection model; a detection level greater than or equal to the second threshold corresponds to the third abnormal traffic detection model.
[0110] Exemplarily, taking the first threshold as three and the second threshold as six as an example, the computing power domains with detection levels one and two correspond to the first abnormal traffic detection model. The computing power domains with detection levels three, four, and five correspond to the second abnormal traffic detection model. The computing power domains with detection levels greater than or equal to six correspond to the third abnormal traffic detection model.
[0111] In this way, for the computing power domains with a higher detection level, an abnormal traffic detection model with a higher complexity needs to be adopted to enhance the accuracy and reliability of detection and reduce the security risks brought by abnormal traffic. Moreover, allocating different complexity abnormal traffic detection models according to the detection level of the computing power domain can improve the utilization rate of model resources and the detection efficiency.
[0112] In some other embodiments, the preset correspondence relationship further includes: the first-level detection level corresponds to the first abnormal traffic detection model, the second-level detection level corresponds to the second abnormal traffic detection model, and the third-level detection level corresponds to the third abnormal traffic detection model.
[0113] Exemplarily, taking the example of S1022, when S is 6 - 8, the detection level corresponding to its computing power domain is the first level. When S is 9 - 11, the detection level corresponding to its computing power domain is the second level. When the S value is 12 - 18, the traffic detection level is the third level. As shown in Table 2, when S is 6 - 8, the detection level of the computing power domain is the first level, and the corresponding abnormal traffic detection model is the first abnormal traffic detection model, with its depth being b 1 , and the number of trees being c 1 . When S is 9 - 11, the detection level of the computing power domain is the second level, and the corresponding abnormal traffic detection model is the second abnormal traffic detection model, with its depth being b 2 , and the number of trees being c 2 . When S is 12 - 18, the detection level of the computing power domain is the third level, and the corresponding abnormal traffic detection model is the third abnormal traffic detection model, with its depth being b 3 , and the number of trees being c 3 . Among them, the depth (max_depth) of the tree is b 1< b 2< b 3 , and the number of trees (n_estimators) c1 < c2 < c3.
[0114] Table 2
[0115]
[0116]
[0117] It should be understood that the abnormal traffic detection model is a trained random forest model, and the training process of the abnormal traffic detection model is as follows: (1) The tabular data set established according to the traffic records collected by the control nodes in each computing power domain is divided into a training set and a test set according to a certain ratio (such as 8:2). (2) Use the above training set data to train different random forest models, with different tree depths, numbers, and model complexities. (3) Use the above test set to test it, and upload attributes such as accuracy, recall rate, and test time to the traffic detection model library. (4) Periodically repeat the above steps, and update and distribute the model parameters to the high-speed storage library in the computing power domain.
[0118] S104. Send the abnormal traffic detection model corresponding to the computing power domain to the computing power domain, so that the computing power domain detects the abnormal traffic of the computing power domain based on the abnormal traffic detection model.
[0119] Exemplarily, after the server determines the abnormal traffic detection model corresponding to the computing power domain, it sends the abnormal traffic detection model corresponding to the computing power domain to the computing power domain. Correspondingly, the computing power domain receives the abnormal traffic detection model sent by the server and detects the abnormal traffic based on the abnormal traffic detection model.
[0120] Another exemplarily, when the computing power domain detects traffic based on the corresponding abnormal traffic detection model, if the traffic passes the detection, the traffic is forwarded to the node or resource center that needs to be sent; if it fails the detection, that is, the traffic is abnormal traffic, the traffic is discarded.
[0121] In this way, through the security feature parameters of the computing power domain, the detection level of the computing power domain is determined, and the corresponding abnormal traffic detection model is selected according to the detection level. During the traffic detection process, different abnormal traffic detection models can be dynamically selected according to the different detection levels of the computing power domain, realizing the precise traffic detection of computing power domains with different detection levels, so that during the traffic detection process of the computing power domain, it is targeted, the accuracy of traffic detection can be improved, and the security of the computing power domain can be improved.
[0122] Such as Figure 5 shown, it is a system topology diagram of a traffic detection scenario provided by the present disclosure, and taking Figure 5 as an example, the traffic detection method provided by the present disclosure is introduced.
[0123] Figure 5There are a total of 6 computing power nodes, belonging to three computing power domains. Among them, computing power domain 1 is a fully trusted mode computing power domain, computing power domain 2 is a semi-trusted mode computing power domain, and computing power domain 3 is a non-trusted mode computing power domain. S1-S4 are forwarding nodes, composed of network switches. The server can be connected to and communicate with switches in all computing power domains. The computing power nodes in each computing power domain can communicate with each other and can also access other resource centers, control centers, etc. The server first needs to establish an abnormal traffic detection model and deploy it into the switch. The specific process is as follows:
[0124] (1) The server constructs a training dataset based on the historical behaviors of each computing power domain, divides the dataset into a training set and a test set, and trains the abnormal traffic detection model.
[0125] (2) Select different abnormal traffic detection model parameters, statistically classify the results of multiple trainings, divide them into three models: high accuracy and low latency, ordinary accuracy and ordinary latency, and low accuracy and low latency, and send the model parameters to the high-speed repositories in each computing power domain.
[0126] (3) Store the traffic characteristics of the computing power nodes according to the features used by the optimal performance model.
[0127] (4) When the H1 node in computing power domain 1 sends traffic to nodes in other computing power domains or resource storage centers, it needs to insert attribute information such as the identifier, identity, and location of its computing power domain into the data packet header field and forward it to S1.
[0128] (5) If H1 sends traffic to other nodes in the same computing power domain, such as H2. Then the source computing power domain identifier of the data packet extracted by S1 is the same as the destination computing power domain identifier, both being 1. It is determined that the detection level of this node is level 1. Therefore, a low-latency detection model in the traffic detection model library is matched.
[0129] (6) If H1 sends traffic to nodes in other computing power domains, such as H3. Then the source computing power domain identifier of the data packet extracted by S1 is different from the destination computing power domain identifier, and the source computing power domain identifier is 1. This computing power domain is a fully trusted mode computing power domain. Therefore, an abnormal traffic detection model with low latency and low accuracy in the traffic detection model library is matched. In the case where the traffic sent by H1 passes the detection, it is normally forwarded to other nodes. If it is detected as malicious traffic, it is discarded, and the traffic history behavior library is updated. According to the historical attack times of the computing power domain to which this node belongs, it is judged whether it is necessary to reduce the trust level of the computing power domain to which H1 belongs.
[0130] (7) When H3 in the semi-trusted mode computing power domain 2 sends traffic to other nodes or the resource storage center, it detects that the source computing power domain identifier is 2, which is a semi-trusted mode computing power domain. Therefore, it matches the medium-delay and medium-accuracy abnormal traffic detection model in the traffic detection model library. If the traffic sent by H3 passes the detection, it is normally forwarded to other nodes. If it is detected as abnormal traffic, it is discarded, and the traffic history behavior library is updated. If the malicious traffic sent by H3 reaches the corresponding threshold subsequently, the trust level of the computing power domain 2 described in (2) is downgraded to a non-trusted mode computing power domain.
[0131] (8) When H5 in the non-trusted mode computing power domain 3 sends traffic to other nodes or the resource storage center, it detects that the source computing power domain identifier is 3, which is a non-trusted mode computing power domain. Therefore, it matches the high-delay and high-accuracy abnormal traffic detection model in the traffic detection model library. If the traffic sent by H5 passes the detection, it is normally forwarded to other nodes. If it is detected as abnormal traffic, it is discarded, and the traffic history behavior library is updated.
[0132] (9) If it is found that the source of the traffic sent by an unknown node is an unknown computing power domain, by default, the trust level of the unknown computing power domain is the non-trusted mode computing power domain level, with relatively high computing power parameters and relatively high security requirement parameters, and it is recorded in the high-speed storage library.
[0133] (10) The abnormal traffic detection model is updated periodically with time T according to the communication situation in the computing power network. When updating, the above steps (2)-(3) are repeated, and at the same time, the detection level in the high-speed storage library is updated.
[0134] In the above process, the trust level of the computing power domain or node is mainly used as the main determination parameter for the abnormal traffic detection model corresponding to the computing power domain, and its accuracy is lower than that of comprehensively determining using multiple parameters in the security feature parameters. In the actual application process, relevant parameters that can be selected according to the actual situation are not limited in this disclosure.
[0135] Exemplarily, such as Figure 6As shown in the figure, an execution flow chart of traffic detection provided by the present disclosure specifically includes the following steps: (1) Perform a packet header parsing process in the forwarding execution plane of each computing power domain, and extract all packet header fields according to preset rules, including the source computing power domain identifier, the target computing power domain identifier, etc. (2) Determine the source identity of the data packet according to the computing power domain identifier CPDI, traffic source characteristics, etc. of the data packet in the entry pipeline, and use CPDI as a query pointer to query its corresponding detection level in the high-speed repository. (3) Allocate a corresponding abnormal traffic detection model according to the detection level of its computing power domain. For example, for a computing power domain with a detection level of one, allocate an abnormal traffic detection model with a short test time, low latency, and low accuracy; for a computing power domain with a detection level of three, allocate an abnormal traffic detection model with a long test time, high latency, and high accuracy. (4) When the information of the computing power domain cannot be queried through the computing power domain identifier CPDI, store it as new data in the traffic historical behavior library for subsequent update of the computing network trust level library, and set its trust level to an untrusted mode computing power domain (level three). (5) Allocate an abnormal traffic detection model corresponding to the untrusted mode computing power domain to perform traffic detection on the data packet, and determine whether to accept or discard the data packet according to the detection result.
[0136] Exemplarily, as Figure 7 shown, a schematic structural diagram of a computing network security knowledge base provided by an embodiment of the present disclosure, where the computing network security knowledge base is as Figure 7 shown, includes a computing network security requirement library, a traffic historical behavior library, a computing network trust level library, a computing network computing power library, and a traffic detection model library. The specific functions of each library can refer to the relevant descriptions of the above embodiments, and the present disclosure will not elaborate here.
[0137] Exemplarily, as Figure 8 shown, a system architecture diagram of a traffic detection method provided by an embodiment of the present disclosure. The figure includes a server, a computing power network, and the above Figure 7 computing network security knowledge base. The server first generates a computing network security knowledge base for each computing power domain and generates an abnormal traffic detection model according to relevant algorithms. When receiving traffic data, it performs traffic perception and collection, determines the identifier of the computing power domain to which the traffic belongs, queries relevant data in the computing network security knowledge base through the computing power domain identifier, determines the abnormal traffic detection model corresponding to the computing power domain, and performs traffic detection on it according to the abnormal traffic detection model, and determines whether to forward the traffic data to the corresponding node or discard it according to the detection result. Among them, the server can also be described as a computing power security control center, and the present disclosure does not limit this.
[0138] Exemplarily, to ensure the real-time performance of the abnormal traffic detection model, it is necessary to regularly update the above database and the abnormal traffic detection model. Specifically, the update process is as follows: (1) When each new traffic received by a certain computing power domain is detected, the source computing power domain identification information of the traffic and the detection result are reported to the computing network control center, and its traffic historical behavior library is updated. (2) After a time T, the number of attack times corresponding to each computing power domain in the traffic historical behavior library is used to update the computing network trust level library, and at the same time, the computing network computing power library and the computing network security requirement library are updated. (3) At the same time, every time interval T, the abnormal traffic detection model is trained and its parameters are updated. (4) If only the traffic historical behavior library is updated, while the computing network trust level library, the computing network computing power library, and the computing network security requirement library have not changed, the update result is not sent to the high-speed storage library to reduce the resource overhead during the update.
[0139] It should be understood that in the computing power network, the core computing power nodes may migrate due to reasons such as hardware failures and maintenance requirements. In addition, edge computing power nodes, such as mobile phones and laptops, may all migrate due to the migration of the user's geographical location, resulting in node migration. During the above computing power node migration process, the Internet Protocol (IP) address of the computing power node will change, and at the same time, the computing power domain (a set of nodes with specific computing or storage capabilities divided according to geographical location) will also change accordingly. At this time, when the original abnormal traffic detection model corresponding to the computing power domain faces the new computing power domain, the abnormal detection traffic strategy will fail. As Figure 9 shown, the H1 node in computing power domain 1 migrates to computing power domain 2 for some reason, that is, the H1' node. At this time, the traffic transmitted by the H1' node is detected in the following way:
[0140] (1) After the H1 node migrates to the H1' node, the computing power node H1' reports its own trust level, computing power parameters, and security requirement parameters to the in-domain manager in computing power domain 2.
[0141] (2) The in-domain manager in computing power domain 2 verifies the information provided by the H1' node
[0142] (3) After the verification is passed, all the subsequent traffic transmitted by the H1' node is regarded as the traffic of computing power domain 2. When the router S2 receives the traffic information sent by the H1' node, it first extracts the source IP address of the traffic data and the carried computing power domain serial number, and retrieves them in the high-speed storage library within the computing power domain. When S1 retrieves the H1' node, the CDPI used for the retrieval is 2. At this time, there is corresponding information in the high-speed storage library, and no update is required at this time.
[0143] (4) In the case of verification failure or when the relevant information of the computing power domain with a CDPI of 2 is successfully detected in step (3), directly classify the detection level of the computing power domain 2 as level three, use the anomaly traffic detection model with the highest complexity and accuracy for detection to ensure the traffic security of the computing power domain, and report the nodes in the computing power domain 2 to the control center.
[0144] In the above process, when a computing power node migrates to a new computing power domain, it is necessary to verify its security feature parameters and determine whether to update the information according to the verification result to ensure the traffic security of the computing power domain. Under the condition of ensuring security, the additional resource overhead is minimized as much as possible, improving the adaptability of traffic detection.
[0145] The embodiments of the present disclosure can divide the functional modules of the electronic device according to the above method embodiments. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one functional module. The above integrated module can be implemented in the form of hardware or software. It should be noted that the division of modules in the embodiments of the present disclosure is illustrative, only a logical function division, and there may be other division methods in actual implementation. The following takes the example of dividing each functional module corresponding to each function for illustration.
[0146] Figure 10 is a schematic structural diagram of an electronic device provided by the embodiments of the present disclosure. The electronic device 100 can execute the traffic detection method provided by the above method embodiments. As Figure 10 shown, the electronic device 100 includes: an acquisition module 1001, a determination module 1002, and a communication module 1003.
[0147] The acquisition module 1001 is used to acquire the security feature parameters of the computing power domain.
[0148] The determination module 1002 is used to determine the detection level corresponding to the computing power domain based on the security feature parameters of the computing power domain.
[0149] The determination module 1002 is further used to determine the anomaly traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain.
[0150] The communication module 1003 is used to send the anomaly traffic detection model corresponding to the computing power domain to the computing power domain so that the computing power domain detects the anomaly traffic of the computing power domain based on the anomaly traffic detection model.
[0151] In some embodiments, the security feature parameters include at least one of the following: trust level, computing power parameter, and security requirement parameter; the trust level is used to characterize the security degree of the computing power domain, the computing power parameter is used to characterize the computing power of the computing power domain, and the security requirement parameter is used to characterize the degree of security requirements of the computing power domain.
[0152] In some embodiments, the determining module 1002 is specifically configured to determine the abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain and the preset corresponding relationship, where the preset corresponding relationship is used to represent the corresponding relationship between multiple detection levels and multiple abnormal traffic detection models, and the multiple abnormal traffic detection models have different complexities, and the higher the detection level, the higher the complexity of the corresponding abnormal traffic detection model.
[0153] In some embodiments, the multiple abnormal traffic detection models at least include a first abnormal traffic detection model, a second abnormal traffic detection model, and a third abnormal traffic detection model. The complexity of the third abnormal traffic detection model is higher than that of the second abnormal traffic detection model, and the complexity of the second abnormal traffic detection model is higher than that of the first abnormal traffic detection model; the preset corresponding relationship at least includes: the detection level less than the first threshold corresponds to the first abnormal traffic detection model; the detection level greater than or equal to the first threshold and less than the second threshold corresponds to the second abnormal traffic detection model; the detection level greater than or equal to the second threshold corresponds to the third abnormal traffic detection model.
[0154] In some embodiments, the determining module 1002 is further configured to obtain the weight coefficient corresponding to the trust level, the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the security requirement parameter; based on the weight coefficient corresponding to the trust level, the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the security requirement parameter, perform weighted calculation on the trust level, the computing power parameter, and the security requirement parameter to obtain the detection level corresponding to the computing power domain.
[0155] In some embodiments, the weight coefficient corresponding to the trust level is greater than the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the computing power parameter is greater than the weight coefficient corresponding to the security requirement parameter.
[0156] In some embodiments, the trust level is determined in the following manner: obtain the number of attacks of the computing power domain, where the number of attacks is used to characterize the number of successful attacks of the computing power domain; based on the number of attacks of the computing power domain, determine the trust level of the computing power domain.
[0157] In some embodiments, the abnormal traffic detection model is a random forest model.
[0158] In the case where the functions of the above integrated module are implemented in the form of hardware, embodiments of the present disclosure provide another possible structure of the electronic device involved in the above embodiments. As Figure 11 shown, the electronic device 110 includes: a processor 1102 and a bus 1104. As a possible implementation, the electronic device may further include a memory 1101; as a possible implementation, the electronic device may further include a communication interface 1103.
[0159] The processor 1102 may be a device that implements or executes various exemplary logical blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 1102 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logical blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 1102 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0160] The communication interface 1103 is used to connect to other devices through a communication network. The communication network may be an Ethernet, a wireless access network, a wireless local area network (WLAN), etc.
[0161] The memory 1101 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM), or other type of dynamic storage device that can store information and instructions. It may also be an electrically erasable programmable read-only memory (EEPROM), a disk storage medium, or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0162] As a possible implementation, the memory 1101 may exist independently of the processor 1102. The memory 1101 may be connected to the processor 1102 through the bus 1104 for storing instructions or program code. When the processor 1102 calls and executes the instructions or program code stored in the memory 1101, the traffic detection method provided by the embodiments of the present disclosure can be implemented.
[0163] In another possible implementation, the memory 1101 can also be integrated with the processor 1102.
[0164] The bus 1104 can be an extended industry standard architecture (EISA) bus or the like. The bus 1104 can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 11 only a thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0165] Some embodiments of the present disclosure provide a computer-readable storage medium (for example, a non-transitory computer-readable storage medium), in which computer program instructions are stored. When the computer program instructions run on a computer, the computer is caused to execute the traffic detection method described in any one of the above embodiments.
[0166] Exemplarily, the above computer-readable storage medium may include, but is not limited to: magnetic storage devices (such as hard disks, floppy disks, or magnetic tapes, etc.), optical discs (such as Compact Disks (CDs), Digital Versatile Disks (DVDs), etc.), smart cards, and flash memory devices (such as Erasable Programmable Read-Only Memories (EPROMs), cards, sticks, or key drives, etc.). The various computer-readable storage media described in the present disclosure may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0167] The embodiments of the present disclosure provide a computer program product containing instructions. When the computer program product runs on a computer, the computer is caused to execute the traffic detection method described in any one of the above embodiments.
[0168] As described above, the above are only the specific embodiments of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present disclosure should be covered by the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be subject to the protection scope of the claims.
Claims
1. A traffic detection method, characterized in that, the method includes: obtaining security feature parameters of a computing power domain; determining a detection level corresponding to the computing power domain based on the security feature parameters of the computing power domain; determining an abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain; sending the abnormal traffic detection model corresponding to the computing power domain to the computing power domain, so that the computing power domain detects abnormal traffic of the computing power domain based on the abnormal traffic detection model.
2. The method according to claim 1, characterized in that, the security feature parameters include at least one of the following: a trust level, a computing power parameter, and a security requirement parameter; the trust level is used to represent the security degree of the computing power domain, the computing power parameter is used to represent the computing power of the computing power domain, and the security requirement parameter is used to represent the degree of security requirements of the computing power domain.
3. The method according to claim 1, characterized in that, the determining the abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain includes: determining the abnormal traffic detection model corresponding to the computing power domain based on the detection level corresponding to the computing power domain and a preset corresponding relationship, the preset corresponding relationship is used to represent the corresponding relationship between multiple detection levels and multiple abnormal traffic detection models, and the multiple abnormal traffic detection models have different complexities, and the higher the detection level, the higher the complexity of the corresponding abnormal traffic detection model.
4. The method according to claim 3, characterized in that, the multiple abnormal traffic detection models at least include a first abnormal traffic detection model, a second abnormal traffic detection model, and a third abnormal traffic detection model, the complexity of the third abnormal traffic detection model is higher than the complexity of the second abnormal traffic detection model, and the complexity of the second abnormal traffic detection model is higher than the complexity of the first abnormal traffic detection model; the preset corresponding relationship at least includes: a detection level less than a first threshold corresponds to the first abnormal traffic detection model; a detection level greater than or equal to the first threshold and less than a second threshold corresponds to the second abnormal traffic detection model; a detection level greater than or equal to the second threshold corresponds to the third abnormal traffic detection model.
5. The method according to claim 2, characterized in that, the determining the detection level corresponding to the computing power domain based on the security feature parameters of the computing power domain includes: obtaining a weight coefficient corresponding to the trust level, a weight coefficient corresponding to the computing power parameter, and a weight coefficient corresponding to the security requirement parameter; performing weighted calculation on the trust level, the computing power parameter, and the security requirement parameter based on the weight coefficient corresponding to the trust level, the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the security requirement parameter to obtain the detection level corresponding to the computing power domain.
6. The method according to claim 5, characterized in that, The weight coefficient corresponding to the trust level is greater than the weight coefficient corresponding to the computing power parameter, and the weight coefficient corresponding to the computing power parameter is greater than the weight coefficient corresponding to the security requirement parameter.
7. The method according to claim 2, wherein, the trust level is determined in the following manner: obtain the number of attacks on the computing power domain, where the number of attacks is used to characterize the number of times the computing power domain successfully launches an attack; based on the number of attacks on the computing power domain, determine the trust level of the computing power domain.
8. The method according to claim 1, wherein, the abnormal traffic detection model is a random forest model.
9. An electronic device, wherein, comprising a processor, when the processor executes a computer program, implementing the traffic detection method according to any one of claims 1 to 8.
10. A computer-readable storage medium, wherein, the computer-readable storage medium includes computer instructions; wherein, when the computer instructions are executed, implementing the traffic detection method according to any one of claims 1 to 8.