Mimicry defense actuator set isomerism measurement method for cloud native platform

By building block vulnerability diagrams and using Shannon-Winner index, the problem that traditional heterogeneity measurement methods cannot accurately measure the heterogeneity of the actuator is solved, and the security defense capabilities of cloud-native platforms are improved.

CN120162797APending Publication Date: 2025-06-17NANJING UNIV OF POSTS & TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510311558.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Traditional heterogeneity measurement methods cannot accurately measure the heterogeneity of the executor set, especially when facing attacks from unknown vulnerabilities, it is difficult to meet the security needs of cloud-native platforms.

Method used

By building a module vulnerability graph (MVM), the common-mode vulnerability distribution of the executor set is analyzed, and a comprehensive evaluation is performed using the Shannon-Winner index combined with vulnerability threat, and the vulnerability graph is dynamically updated to optimize the heterogeneity measurement results.

Benefits of technology

The security defense capabilities of cloud-native platforms are improved, and the heterogeneity of the actuator set is accurately measured, the mimicry defense strategy is optimized, and the resistance to unknown vulnerability attacks is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120162797A_ABST
    Figure CN120162797A_ABST
Patent Text Reader

Abstract

The invention discloses a mimicry defense actuator set isomerism measurement method oriented to a cloud native platform. The method comprises the following steps: firstly, selecting software modules of each level according to specific needs, acquiring vulnerability information corresponding to each software module through NVD, and constructing an MVM; randomly selecting modules from each level of software module to generate an executor set and an online executor set, analyzing the distribution condition of common-mode vulnerabilities of the executor set according to the MVM, and calculating the vulnerability threat degree. And then comprehensively evaluating the isomerism of the actuator set by using a Shannon-Wiener index in combination with the vulnerability threat degree, dynamically updating the vulnerability graph in the system operation process, and continuously optimizing an isomerism measurement result. According to the method, the vulnerability relation network of the actuator set is constructed based on the MVM, the distribution condition of common-mode vulnerabilities is analyzed, and the isomerism of the actuator set is comprehensively evaluated in combination with the Shannon-Wiener index. According to the method, dynamic updating of the vulnerability graph in the system operation process is supported, the isomerism measurement result is continuously optimized, and the security defense capability of the cloud native platform is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for measuring heterogeneity of a mimicry defense actuator set for a cloud native platform, and belongs to the technical field of information security. Background Art

[0002] With the rapid development of cloud computing and information security, cloud-native architecture has become an important foundation for modern software systems. Cloud-native technology improves the flexibility and scalability of the system through containerization, microservices, dynamic orchestration, etc. However, with the widespread application of cloud-native platforms, their security issues have become increasingly prominent, especially when facing attacks on unknown system vulnerabilities, traditional passive defense methods can no longer meet the needs. Therefore, how to enhance the security of cloud-native platforms has become an important issue that needs to be solved in the current information security field.

[0003] Mimicry defense is an active defense technology that improves system security through dynamic transformation and heterogeneous redundancy mechanisms. This technology makes it difficult for attackers to predict system behavior through the collaborative work and dynamic scheduling of multiple actuators, thereby improving the system's defense capabilities. However, the heterogeneity of the actuator set is a key factor affecting the effectiveness of mimicry defense. If there are many common-mode vulnerabilities between the actuators in the actuator set, attackers may still exploit these vulnerabilities to attack and break through the system defense. Therefore, how to accurately measure the heterogeneity of the actuator set and then optimize the mimicry defense strategy is a core issue in ensuring the security of the cloud native platform.

[0004] Traditional heterogeneity measurement methods are usually based on the differences in the software itself. Although they can measure the heterogeneity between actuators to a certain extent, they do not evaluate it from the more fundamental common mode vulnerabilities. At the same time, as the system continues to run, the vulnerability data set of the software is also expanding. Static heterogeneity measurement cannot adapt to the constantly changing vulnerability data, and the degree of automation is also low. Under the cloud native platform, when the system faces attacks against unknown vulnerabilities, traditional passive defense methods can no longer meet the needs. Mimic defense is an active defense technology that improves system security through dynamic transformation and heterogeneous redundancy mechanisms, and the heterogeneity of the actuator set is a key factor affecting the effectiveness of mimic defense. Summary of the invention

[0005] The purpose of the present invention is to address the defects and shortcomings of the above-mentioned prior art and propose a method for measuring the heterogeneity of a set of mimetic defense actuators for cloud-native platforms. The method constructs a vulnerability relationship network of the actuator set based on MVM, analyzes the distribution of common mode vulnerabilities, and comprehensively evaluates the heterogeneity of the actuator set in combination with the Shannon-Wiener index. At the same time, the method supports dynamic updating of the vulnerability graph during system operation and continuously optimizes the heterogeneity measurement results, thereby improving the security defense capabilities of the cloud-native platform.

[0006] The present invention is a method for measuring the heterogeneity of a mimic defense executor set for a cloud-native platform. This method obtains the currently known software module and vulnerability information in advance, constructs an MVM, and thereby analyzes the distribution of common-mode vulnerabilities in the executor set. Then, the Shannon-Wiener index is used to comprehensively evaluate the heterogeneity of the executor set in combination with the vulnerability threat level, and the vulnerability graph is dynamically updated during the operation of the system to continuously optimize the heterogeneity measurement result.

[0007] Method flow:

[0008] Step 1: Obtain a software module set M = {m1, m2,..., m r} and a known vulnerability set V = {v1, v2,..., v k}, where the vulnerability set V contains the known vulnerabilities of all elements in the module set M.

[0009] Step 2: Construct a module vulnerability graph (MVM) based on the software module set M and the known vulnerability set V. The module nodes are composed of tuples (m a , software level), and the vulnerability nodes are composed of tuples (v b , vulnerability exposure). If the module m a has a vulnerability v b , then there is an edge between the corresponding two nodes. There are no edges between vulnerability nodes, and there are no edges between module nodes either.

[0010] Step 3: Define an executor set A = (A1, A2,..., A n ), and a single executor A i = (x i1 , x i2 ,..., x im ). Then the executor set A is represented as

[0011]

[0012] where x ij ∈ M. For the executor A i = (x i1 , x i2 ,..., x im ), the set of vulnerabilities it contains is V i = {v j |v j ∈ V}.

[0013] Step 4: Define an online executor set with a capacity of l, where l > 1 and l is odd. For the online executor set A O and the executor set A, count the vulnerabilities they contain, denoted as

[0014]

[0015] where k i Represents the online executor set A o Contains vulnerabilities i The number of actuators, t i Indicates that the executor set A contains vulnerability v i The number of actuators, and k i ≤t i .

[0016] Step 5: For the online executor set A O Vulnerabilities in v i , its threat level d i Calculated as

[0017]

[0018] Step 6: Definition To represent the online executor set A O The value of the i-th layer module in is M i The number of categories representing the value, c j Represents X i The number of the jth class in p ij Represents X i The proportion of the jth class in Then the online executor set A O Heterogeneous representation of the i-th layer module Where K = log2(M i ).

[0019] Step 7: Online Executor Collection Heterogeneity Calculated as:

[0020]

[0021] Where α and β are weights, and the initial values ​​are α=0.8 and β=0.2.

[0022] Step 8: Select heterogeneity The largest collection of online executors O Build a mimicry defense system. If the system operation has ended, the process ends, otherwise jump to step 9.

[0023] Step 9: When element m in software module set M is found i There is a new vulnerabilityv j When the vulnerability v j If it exists in the known vulnerability set V, an edge is established between the two nodes in MVM. If it does not exist, the vulnerability v j Added to V, created vulnerability v in MVMj node, and establish an edge between node m i and node v j If no new vulnerability is found, jump to step 8.

[0024] Step 10: Define the update threshold V th and the update count V count , initialize V th = 10, V count = 0. When there is a new node or a new edge added to the MVM, V count = V count + 1. If V count ≥ V th , then V th = 1.3 × V th , V count = 0, the weights are updated to α = 0.9 × α, β = 1 - α, and jump to step 4; otherwise, jump to step 8.

[0025] Furthermore, the present invention first selects software modules at each level according to specific needs, obtains the vulnerability information corresponding to each software module through NVD, and constructs the MVM. Then, randomly select modules from the software modules at each level to generate an executor set and an online executor set, analyze the distribution of the common-mode vulnerabilities in the executor set according to the MVM, and calculate the vulnerability threat level. Then use the Shannon-Wiener index combined with the vulnerability threat level to comprehensively evaluate the heterogeneity of the executor set, and dynamically update the vulnerability graph during the operation of the system to continuously optimize the heterogeneity measurement result.

[0026] Beneficial effects:

[0027] 1. By using the module vulnerability graph (MVM) composed of software modules and vulnerabilities, the present invention obtains the corresponding relationship between vulnerabilities and software modules, and thereby calculates the number and types of common-mode vulnerabilities contained in the executor set. Then use the Shannon-Wiener index combined with the vulnerability threat level to comprehensively evaluate the heterogeneity of the executor set, and continuously improve the vulnerability graph and adjust the comprehensive evaluation of the heterogeneity in subsequent operations.

[0028] 2. The present invention constructs a vulnerability relationship network of the executor set based on the MVM, analyzes the distribution of common-mode vulnerabilities, and comprehensively evaluates the heterogeneity of the executor set in combination with the Shannon-Wiener index. At the same time, this method supports dynamically updating the vulnerability graph during the operation of the system to continuously optimize the heterogeneity measurement result, thereby improving the security defense ability of the cloud-native platform. Description of the drawings

[0029] Figure 1 is a schematic diagram of a specific application scenario of the present invention.

[0030] Figure 2This is the flowchart of the method of the present invention. Detailed implementation mode

[0031] The present invention will be further described in detail below in conjunction with the accompanying drawings of the specification.

[0032] As Figure 1 and Figure 2 shown, the present invention provides a method for measuring the heterogeneity of a mimic defense executor set for a cloud-native platform. The method includes the following steps:

[0033] Step 1: Obtain a software module set M = {m1, m2,..., m r} and a known vulnerability set V = {v1, v2,..., v k}, where the vulnerability set V contains the known vulnerabilities of all elements in the module set M.

[0034] Step 2: Construct a module vulnerability graph (MVM) according to the software module set M and the known vulnerability set V. The module nodes are composed of tuples (m a , software layer), and the vulnerability nodes are composed of tuples (v b , vulnerability exposure). If the module m a has a vulnerability v b , then there is an edge between the corresponding two nodes. There is no edge between vulnerability nodes, and there is also no edge between module nodes.

[0035] Step 3: Define an executor set A = {A1, A2,..., A n}, and a single executor A i = {x i1 , x i2 ,..., x im}. Then the executor set A is expressed as

[0036]

[0037] where x ij ∈ M. For the executor A i = (x i1 , x i2 ,..., x im ), the set of vulnerabilities it contains is V i = {v j |v j ∈ V}.

[0038] Step 4: Define an online executor set with a capacity of l, where l > 1 and is an odd number. For the online executor set A O and the executor set A, count the vulnerabilities they contain, denoted as

[0039]

[0040] where k i represents the number of actuators with vulnerability v in the online actuator set A O and t i represents the number of actuators with vulnerability v in the actuator set A, and k i represents the number of actuators with vulnerability v in the actuator set A, and k i ≤t i . i

[0041] Step 5: For the vulnerability v in the online actuator set A O , its threat degree d i is calculated as: i

[0042]

[0043] Step 6: Define to represent the value of the i-th layer module in the online actuator set A O , denote M i as the number of value categories, c j represents X i the number of the j-th category, p ij represents X i the proportion of the j-th category in X, that is Then the heterogeneity representation of the i-th layer module of the online actuator set A O is where K = log2(M i ).

[0044] Step 7: The heterogeneity of the online actuator set is calculated as:

[0045]

[0046] where α and β are weights, with initial values of α = 0.8 and β = 0.2.

[0047] Step 8: Select the online actuator set A with the maximum heterogeneity O to construct a mimic defense system. If the system operation has ended, the process ends; otherwise, jump to Step 9.

[0048] Step 9: When a new vulnerability v i is found in the element m j in the software module set M, if the vulnerability v j exists in the known vulnerability set V, then establish an edge between two nodes in the MVM; if not, add the vulnerability v j to V and establish the vulnerability v in the MVM​​​j nodes, and establish an edge between node m i and node v j . If no new vulnerability is found, jump to step 8.

[0049] Step 10: Define the update threshold V th and the update times V count , initialize V th = 10, V count = 0. When there is a new node or a new edge added to the MVM, V count = V count + 1. If V count ≥ V th , then V th = 1.3 × V th , V count = 0, update the weights to α = 0.9 × α, β = 1 - α, and jump to step 4; otherwise, jump to step 8.

[0050] The application scenarios of the present invention specifically include the following:

[0051] 1) Preparation of software modules and vulnerability data

[0052] For the specific scenario of mimic defense in the cloud-native platform, according to specific needs, determine the composition of the software at each layer of the actuator, and obtain the vulnerability information contained in the corresponding software through the National Vulnerability Database (NVD) of the United States to form the MVM. See steps 1 and 2 for details.

[0053] 2) Establishment of the actuator set and vulnerability calculation

[0054] Randomly select software modules at each layer from the software module set to form multiple actuators, establish the actuator set, and calculate the set of vulnerabilities contained in the actuators according to the software composition of each actuator and the MVM. Select an odd number of actuators from the actuator set to form the online actuator set, and count the threat level of the common-mode vulnerabilities among them. See steps 3, 4, and 5 for details.

[0055] 3) Calculation of the heterogeneity of the online actuator set

[0056] Calculate the Shannon-Wiener index of the online actuator set according to the software composition of the online actuator set, and calculate the heterogeneity of the online actuator set in combination with the vulnerability threat level. Select the online actuator set with the largest heterogeneity to form the mimic defense system, then continuously improve the MVM during the system operation, and update the weights of the Shannon-Wiener index and the vulnerability threat level when the number of MVM updates reaches the threshold, and recalculate the heterogeneity. See steps 6 - 10 for details.

[0057] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.

Claims

1. A method for measuring heterogeneity of a set of mimic defense actuators for cloud-native platforms, characterized by: The following steps are involved: Step 1: Get the software module set M = {m1,m2,...,m r } and known vulnerability set V = {v1,v2,...,v k }, where the vulnerability set V contains the known vulnerabilities of all elements in the module set M; Step 2: Construct a module vulnerability graph (MVM) based on the software module set M and the known vulnerability set V. The module node is represented by a tuple (m a , software level), the vulnerability node consists of a tuple (v b , vulnerability exposure), if module m a There is a vulnerability b , there is an edge between the corresponding two nodes, no edge between vulnerability nodes, and no edge between module nodes; Step 3: Define the executor set A = {A1, A2, ..., A n }, single actuator A i =(x i1 , x i2 , ..., x im ), then the executor set A is expressed as: where x ij ∈M, for actuator A i =(x i1 ,x i2 ,...,x im ), the vulnerability set it contains is V i = {v j |v j ∈V}; Step 4: Define the online executor set The capacity is l, l>1 and is an odd number, for the set of online executors A O And the executor set A, count the vulnerabilities it contains, recorded as: where k i Represents the online executor set A O Contains vulnerabilities i The number of actuators, t i Indicates that the executor set A contains vulnerability v i The number of actuators, and k i ≤t i ; Step 5: For the online executor set A O Vulnerabilities in v i , its threat level d i Calculated as: Step 6: Definition To represent the online executor set A O The value of the i-th layer module in is M i The number of categories representing the value, c j Represents X i The number of the jth class in p ij Represents X i The proportion of the jth class in Then the online executor set A O Heterogeneous representation of the i-th layer module Where K = log2(M i ); Step 7: Online Executor Collection Heterogeneity Calculated as: Where α and β are weights, with initial values ​​of α = 0.8 and β = 0.2; Step 8: Select heterogeneity The largest collection of online executors O Build a mimicry defense system. If the system operation has ended, the process ends, otherwise jump to step 9; Step 9: When element m in software module set M is found i There is a new vulnerabilityv j When the vulnerability v j If it exists in the known vulnerability set V, an edge is established between the two nodes in MVM. If it does not exist, the vulnerability v j Added to V, created vulnerability v in MVM j Node and establish a node m i and node v j If no new vulnerability is found, jump to step 8; Step 10: Define the update threshold V th and the number of updates V count , initialize V th =10, V count = 0, when a new node or new edge is added to MVM, V count =V count +1, if V count ≥V th , then V th =1.3×V th , V count =0, the weights are updated to α=0.9×α, β=1-α, and the process goes to step 4; otherwise, the process goes to step 8.

2. According to claim 1, a method for measuring heterogeneity of a set of mimic defense actuators for a cloud native platform is characterized in that: First, software modules at each level are selected according to specific needs, and the vulnerability information corresponding to each software module is obtained through NVD to build MVM. Then, modules are randomly selected from software modules at each level to generate executor sets and online executor sets. The distribution of common-mode vulnerabilities of the executor set is analyzed according to MVM, and the vulnerability threat degree is calculated. Then, the Shannon-Wiener index is used in combination with the vulnerability threat degree to comprehensively evaluate the heterogeneity of the executor set. The vulnerability map is dynamically updated during system operation to continuously optimize the heterogeneity measurement results.