Abnormal behavior monitoring method and system in cloud computing

By setting up honeypot virtual machines in the cloud computing cluster to monitor abnormal behavior, the security problem of the cloud computing system is solved, effective monitoring and defense of abnormal behavior is achieved, and the security of the system is improved.

CN120371643AInactive Publication Date: 2025-07-25BEIJING JIANWEI NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510466002.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-07-25
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

There are security problems in cloud computing systems, especially threats from external attacks and unsafe applications, which lead to fatal hazards, and it is difficult for existing technologies to effectively monitor and defend against abnormal behavior.

Method used

Set up a honeypot virtual machine in a cloud computing cluster, simulate the virtual machine in the physical server through the honeypot virtual machine, collect attack behaviors, and set secure area storage access in the physical server memory area, and use the data processing module to identify abnormal behaviors.

Benefits of technology

It improves the security of cloud computing clusters, can timely monitor and identify abnormal behaviors, reduce the performance impact on physical servers, and enhance defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120371643A_ABST
    Figure CN120371643A_ABST
Patent Text Reader

Abstract

The invention discloses a method for monitoring abnormal behaviors in cloud computing, which comprises the following steps of: acquiring the number N of physical servers in the cloud computing, and setting M honeypot virtual machines according to the number N of the physical servers and the average load of the physical servers; distributing the M honeypot virtual machines to N physical servers and running the M honeypot virtual machines; a honeypot application program runs in the honeypot virtual machine; when a preset condition is met, adjusting the relationship between the honeypot virtual machine and the physical server, and migrating the honeypot virtual machine to the corresponding physical server; a security area is set in a memory area of a physical server, a honeypot application program stores the acquired access condition of a honeypot virtual machine in the security area in a text mode, and a sending thread sends data of the security area to a data processing module; and processing the sent data, and identifying abnormal behaviors. According to the method, the honeypot virtual machine is arranged in the cloud computing cluster to monitor the abnormal behavior, so that the security of the cluster is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud computing, and in particular, to a method and system for monitoring abnormal behaviors in cloud computing. Background Art

[0002] As a type of distributed computing, cloud computing provides users with required resources in a dynamic manner. A main feature of cloud computing is scalability, which is applicable not only to users but also to cloud service providers. Specifically, when a user needs more resources, the server automatically allocates more resources to the user, including but not limited to CPU cores, memory, bandwidth, etc.; and when there are many users of a cloud service provider, the cloud service provider can also expand its own servers to meet the needs of users.

[0003] Many application programs are running in cloud computing. These application programs are of different types and are deployed in different deployment environments. Some use Linux as the server operating system, and some use Windows Server. Due to this characteristic of cloud computing, more and more users choose to use cloud services. However, this also brings certain problems to cloud services, and the most important one is the security problem. If there is an external attack or an insecure application program is running on the cloud server, it will bring fatal hazards. How to improve the security of cloud computing systems is an urgent problem to be solved. Summary of the Invention

[0004] In order to improve the security of cloud computing clusters, the present invention provides a method for monitoring abnormal behaviors in cloud computing:

[0005] Obtain the number N of physical servers in cloud computing, and set M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers; allocate the M honeypot virtual machines to the N physical servers and run them; a honeypot application program is running in the honeypot virtual machine; where M and N are positive integers, and M ≤ N;

[0006] When a preset condition is met, adjust the relationship between the honeypot virtual machine and the physical server, and migrate the honeypot virtual machine to the corresponding physical server;

[0007] Set a security area in the memory area of the physical server, and the honeypot application program stores the access conditions to the honeypot virtual machine collected in text form in the security area, and the sending thread of the honeypot application program sends the data in the security area to the data processing module;

[0008] Process the sent data and identify abnormal behaviors in cloud computing access.

[0009] Preferably, setting M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers specifically includes:

[0010] Obtaining the increase in the load of a physical server caused by running a honeypot virtual machine based on historical data, calculating the difference between the physical server load threshold and the average load of the physical servers, and obtaining the maximum allowable number of honeypot virtual machines according to the difference and the increase;

[0011] If the maximum allowable number of honeypot virtual machines is greater than or equal to N, then set M = N honeypot virtual machines; otherwise, set the maximum allowable number of honeypot virtual machines as M.

[0012] Preferably, allocating the M honeypot virtual machines to N physical servers and running them specifically includes:

[0013] If M = N, then evenly allocate the M honeypot virtual machines to each physical server; otherwise, sort the physical servers in descending order according to the total access volume, and allocate the M honeypot virtual machines to the top M physical servers after sorting;

[0014] Sort the virtual machines in the physical servers allocated with honeypot virtual machines according to the access volume, and establish the correspondence relationship of virtual machine - system environment information - running time;

[0015] Set the system environment information and running time of the honeypot virtual machine according to the correspondence relationship. When the running time is reached, obtain the system environment information and running time of the next virtual machine after sorting, and set the system environment information and running time of the honeypot virtual machine, and so on, repeating continuously.

[0016] Preferably, the preset conditions are:

[0017] The virtual machine migrates between physical machines, or physical machines are added, or the interval between two adjustments of the honeypot virtual machine is greater than the time threshold.

[0018] Preferably, the calculation method of the running time is:

[0019] Calculate the ratio of the first weight of the current virtual machine to the sum of the first weights of all virtual machines in the physical server where the current virtual machine is located, and take the product of the time threshold and the ratio as the running time of the current virtual machine;

[0020] The first weight is the ratio of the historical access volume of the virtual machine in the current physical server to the running time in the current physical server.

[0021] Preferably, adjusting the relationship between the honeypot virtual machine and the physical server, and migrating the honeypot virtual machine to the corresponding physical server specifically includes:

[0022] If the preset condition is to add a physical machine, the initialization module is re-executed;

[0023] Otherwise, if M = N, randomly select M / 2 honeypot virtual machines and swap them with another M / 2 honeypot virtual machines; if M < N, select N - M physical servers with high security and running honeypot virtual machines, and migrate the honeypot virtual machines corresponding to the N - M physical servers to the servers without running honeypot virtual machines.

[0024] Preferably, the honeypot application stores the collected access situation of the honeypot virtual machine in a text manner in a secure area, specifically:

[0025] When detecting the creation or migration of a honeypot virtual machine, start a security detection thread on the physical server, and the physical server returns a pointer that can be directly mapped to the physical server memory address by the honeypot application to the security detection thread; the physical server memory area pointed to by the pointer is used as the secure area;

[0026] The honeypot application sends the text to the security detection thread associated with the honeypot virtual machine to perform security detection on the text, and determines whether the format and value of the text meet the requirements. If they do not meet the requirements, writing to the secure area is prohibited and an alarm message is issued; otherwise, the security detection thread stores the text in the secure area.

[0027] In addition, the present invention also provides an abnormal behavior monitoring system in cloud computing, and the system includes the following modules:

[0028] Initialization module, used to obtain the number N of physical servers in cloud computing, and set M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers; allocate the M honeypot virtual machines to N physical servers and run them; a honeypot application runs in the honeypot virtual machine; where M and N are positive integers, and M ≤ N;

[0029] Honeypot virtual machine adjustment module, used to adjust the relationship between the honeypot virtual machine and the physical server when the preset condition is met, and migrate the honeypot virtual machine to the corresponding physical server;

[0030] Summary module, used to set a secure area in the memory area of the physical server, the honeypot application stores the collected access situation of the honeypot virtual machine in a text manner in the secure area, and the sending thread of the honeypot application sends the data in the secure area to the data processing module;

[0031] Data processing module, used to process the sent data and identify abnormal behaviors in cloud computing access.

[0032] Preferably, setting M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers is specifically as follows:

[0033] Obtain the increase in the load of a physical server caused by running a honeypot virtual machine according to historical data, calculate the difference between the physical server load threshold and the average load of the physical server, and obtain the maximum allowable number of honeypot virtual machines according to the difference and the increase;

[0034] If the maximum allowable number of honeypot virtual machines is greater than or equal to N, set M = N honeypot virtual machines; otherwise, set the maximum allowable number of honeypot virtual machines as M.

[0035] Preferably, allocating and running M honeypot virtual machines among N physical servers is specifically as follows:

[0036] If M = N, evenly allocate M honeypot virtual machines to each physical server; otherwise, sort the physical servers in descending order according to the total access volume, and allocate M honeypot virtual machines to the top M physical servers after sorting;

[0037] Sort the virtual machines in the physical servers allocated with honeypot virtual machines according to the access volume, and establish the correspondence relationship of virtual machine - system environment information - running time;

[0038] Set the system environment information and running time of the honeypot virtual machine according to the correspondence relationship. When the running time is reached, obtain the system environment information and running time of the next virtual machine after sorting, and set the system environment information and running time of the honeypot virtual machine, and so on, repeating continuously.

[0039] Preferably, the preset conditions are:

[0040] The virtual machine migrates between physical machines, or a physical machine is added, or the interval between two adjustments of the honeypot virtual machine is greater than the time threshold.

[0041] Preferably, the calculation method of the running time is:

[0042] Calculate the ratio of the first weight of the current virtual machine to the sum of the first weights of all virtual machines in the physical server where the current virtual machine is located, and take the product of the time threshold and the ratio as the running time of the current virtual machine;

[0043] The first weight is the ratio of the historical access volume of the virtual machine in the current physical server to the running time in the current physical server.

[0044] Preferably, adjusting the relationship between the honeypot virtual machine and the physical server, and migrating the honeypot virtual machine to the corresponding physical server is specifically as follows:

[0045] If the preset condition is to increase the physical machine, the initialization module is re-executed;

[0046] Otherwise, if M = N, randomly select M / 2 honeypot virtual machines and swap them with another M / 2 honeypot virtual machines; if M < N, select N - M physical servers with high security and running honeypot virtual machines, and migrate the honeypot virtual machines corresponding to the N - M physical servers to the servers without running honeypot virtual machines.

[0047] Preferably, the honeypot application stores the collected access situation of the honeypot virtual machine in a text manner in a secure area, specifically:

[0048] When detecting the creation or migration of a honeypot virtual machine, start a security detection thread on the physical server, and the physical server returns a pointer that can be directly mapped to the physical server memory address by the honeypot application to the security detection thread; the physical server memory area pointed to by the pointer is used as the secure area;

[0049] The honeypot application sends the text to the security detection thread associated with the honeypot virtual machine to perform security detection on the text, and determines whether the format and value of the text meet the requirements. If they do not meet the requirements, writing to the secure area is prohibited and an alarm message is issued; otherwise, the security detection thread stores the text in the secure area.

[0050] The present invention uses the honeypot technology to monitor the security of cloud computing. Specifically, multiple honeypot virtual machines are set in the cloud computing cluster. The running environment in the honeypot virtual machine is similar to the running environment of the virtual machines in the physical server. The honeypot application in the honeypot virtual machine obtains the access situation of the outside world to the honeypot virtual machine, and even can set traps using the honeypot application to lure external attacks, and then realizes the monitoring of abnormal behaviors through the honeypot virtual machine. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0052] Figure 1 It is a structural diagram of a cluster in cloud computing;

[0053] Figure 2 It is a schematic diagram of a security detection thread in a physical server;

[0054] Figure 3It is a flowchart of an embodiment. Detailed implementation manners

[0055] In this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.

[0056] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0057] Security is divided into active security and passive security, also known as active defense and passive defense. The so-called active defense is a method of timely processing before the computer is damaged. Passive defense is to increase the defense method by itself, such as patching. As an important part of network security, the honeypot technology can lure attackers to attack, then record the attack behavior and take corresponding measures. Many Internet companies use the honeypot technology to enhance their own security.

[0058] There are many servers in cloud computing, and the number can reach thousands or even tens of thousands. There are multiple virtual machines running in each server, and users install application programs and related running environments through the virtual machines. Most of the objects attacked by attackers are the virtual machines in cloud computing. The present invention uses a honeypot virtual machine to simulate the virtual machine in a physical server, collect attack behaviors, and monitor abnormal behaviors.

[0059] Specifically, the present invention provides an abnormal behavior monitoring system in cloud computing, and the system includes the following modules:

[0060] An initialization module, configured to obtain the number N of physical servers in cloud computing, and set M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers; allocate the M honeypot virtual machines to the N physical servers and run them; a honeypot application program is running in the honeypot virtual machine; where M and N are positive integers, and M≤N;

[0061] Since there are many servers in cloud computing, many virtual machines and other related programs are deployed on the servers, such as Figure 1 As shown, if too many honeypot virtual machines are set in the physical server, it will increase the burden of the physical server and affect the normal execution of other programs to a certain extent. In the present invention, the number of honeypot virtual machines set in the initialization stage is not greater than the number of physical servers, and in cooperation with the honeypot virtual machine adjustment module, it is possible to achieve coverage of all physical servers.

[0062] The honeypot virtual machine adjustment module is used to adjust the relationship between the honeypot virtual machine and the physical server when a preset condition is met, and migrate the honeypot virtual machine to the corresponding physical server;

[0063] In order to reduce the impact of setting the honeypot virtual machine on the physical server, the number of set honeypot virtual machines is not greater than the number of physical servers. This results in the situation that if the honeypot virtual machine adjustment module is not set, there will always be no honeypot virtual machine running on some physical servers, and there will be loopholes in the supervision of the physical servers. When the preset condition is met, the relationship between the honeypot virtual machine and the physical server is adjusted in a timely manner, and the honeypot virtual machine is migrated to the corresponding physical server, which can cover the physical servers as much as possible and at the same time reduce the impact of the honeypot virtual machine on the performance of the physical server.

[0064] The summary module is used to set a security area in the memory area of the physical server. The honeypot application stores the access situation to the honeypot virtual machine collected in text form in the security area, and the sending thread of the honeypot application sends the data in the security area to the data processing module;

[0065] The attacks by attackers on the honeypot virtual machine involve various aspects, and the attacker will clear its own behavior log when exiting the attack. By setting a security area in the memory area of the physical server, even if the attacker completely damages the honeypot virtual machine, the administrator can still obtain the attack behavior of the attacker on the honeypot virtual machine. The attack behaviors include but are not limited to port scanning, virus implantation, vulnerability scanning, SQL injection, and DDOS attacks). The honeypot application is used to set traps to lure attackers to attack the honeypot virtual machine and collect the access situation to the honeypot virtual machine.

[0066] The data processing module is used to process the sent data and identify abnormal behaviors in cloud computing access.

[0067] The access situation to the honeypot virtual machine stored in the security area will be sent to the data processing module regularly. The data processing module analyzes the data. In a specific embodiment, a text parsing script is used to count various access behaviors and display the results in the form of a chart.

[0068] The number of honeypot virtual machines is not greater than the number of physical servers, which requires setting the corresponding relationship between the honeypot virtual machines and the physical servers. In a specific embodiment, setting M honeypot virtual machines according to the number N of the physical servers and the average load of the physical servers is specifically as follows:

[0069] Obtain the increase in the load of a physical server caused by running a honeypot virtual machine according to historical data, calculate the difference between the physical server load threshold and the average load of the physical server, and obtain the maximum allowable number of honeypot virtual machines according to the difference and the increase;

[0070] If the maximum allowable number of honeypot virtual machines is greater than or equal to N, set M = N honeypot virtual machines; otherwise, set the maximum allowable number of honeypot virtual machines as M.

[0071] Specifically, if it is obtained through historical data that the impact of a honeypot virtual machine on the physical weapon load is 1%, the load threshold of the physical server is 80%, and the current average load of the physical server is 40%, then the maximum allowable number of honeypot virtual machines is 40. If there are 100 physical servers in the current cloud computing cluster, then set N = 40. In a more specific embodiment, the load is characterized by CPU utilization and / or memory utilization.

[0072] Different physical servers run different programs and have different access volumes. The physical server with a large access volume is more likely to be attacked. Allocating the M honeypot virtual machines to N physical servers and running them is specifically as follows:

[0073] If M = N, evenly distribute the M honeypot virtual machines to each physical server; otherwise, sort the physical servers in descending order according to the total access volume, and allocate the M honeypot virtual machines to the first M physical servers after sorting;

[0074] If there are 10 physical servers, and the total access volumes of these 10 physical servers pm1 - pm10 are 1, 5, 9, 3, 12, 7, 6, 15, 10, 4 respectively, then the sorted order is: pm8, pm5, pm9, pm3, pm7, pm6, pm2, pm10, pm4, pm1.

[0075] Sort the virtual machines in the physical servers allocated with honeypot virtual machines according to the access volume, and establish the correspondence relationship of virtual machine - system environment information - running time;

[0076] After sorting, obtain the information of the virtual machines in each physical server, and establish a correspondence table of virtual machine - system environment information - running time. Taking the physical server p1 as an example, if p1 includes three virtual machines, then the correspondence table is as follows:

[0077] Virtual Machine System Environment Information Running Time VM1 Windows Server 2022, MySql 5min VM2 Centos 7, Tomcat 10min VM3 Ubuntu Server 20.04LTS, JDK7 8min

[0078] Set the system environment information and running time of the honeypot virtual machine according to the corresponding relationship. When the running time is reached, obtain the system environment information and running time of the next virtual machine after sorting, and set the system environment information and running time of the honeypot virtual machine, and so on, repeating continuously.

[0079] Among them, the running time refers to the running time of the honeypot virtual machine when the honeypot virtual machine is set to have the same system environment as the virtual machine. Still taking the above table as an example, if the honeypot virtual machine sets the system environment information to (WindowsServer2022, MySql) and runs for 5 minutes, and then the honeypot virtual machine sets the system environment information to (Centos 7, Tomcat) and runs for 10 minutes, and so on. In a specific embodiment, the calculation method of the running time is:

[0080] Calculate the ratio of the first weight of the current virtual machine to the sum of the first weights of all virtual machines in the physical server where the current virtual machine is located, and take the product of the time threshold and the ratio as the running time of the current virtual machine;

[0081] The first weight is the ratio of the historical access volume of the virtual machine in the current physical server to the running time in the current physical server.

[0082] For virtual machines with a larger access volume, the honeypot virtual machine is set to have the same system environment as the virtual machine and runs for a longer time.

[0083] In order to enable the honeypot virtual machine to execute on all physical servers in turn as much as possible, the preset condition is:

[0084] The virtual machine migrates between physical machines, or a physical machine is added, or the interval between two adjustments of the honeypot virtual machine is greater than the time threshold.

[0085] In different situations, the method of adjusting the honeypot virtual machine and the physical server is different. Specifically, adjust the relationship between the honeypot virtual machine and the physical server, and migrate the honeypot virtual machine to the corresponding physical server, specifically:

[0086] If the preset condition is to add a physical machine, re-execute the initialization module;

[0087] Otherwise, if M = N, randomly select M / 2 honeypot virtual machines and swap them with another M / 2 honeypot virtual machines; if M < N, select N - M physical servers with high security and running honeypot virtual machines, and migrate the honeypot virtual machines corresponding to the N - M physical servers to the servers without running honeypot virtual machines.

[0088] Since the honeypot application may also become a target of attack, and the attacker forges the honeypot application to send malicious code to the physical server, to prevent this situation from occurring, the access situation of the honeypot virtual machine collected by the honeypot application is stored in a secure area in text form, specifically:

[0089] When detecting the creation or migration of a honeypot virtual machine, a security detection thread is started on the physical server. As Figure 2 shown, the physical server returns a pointer that can be directly mapped to the physical server memory address by the honeypot application to the security detection thread; the physical server memory area pointed to by the pointer is used as the secure area;

[0090] The honeypot application sends the text to the security detection thread associated with the honeypot virtual machine to perform security detection on the text, and judges whether the format and value of the text meet the requirements. If they do not meet the requirements, writing to the secure area is prohibited and an alarm message is sent; otherwise, the security detection thread stores the text in the secure area.

[0091] By setting a security detection thread corresponding to the honeypot virtual machine in the physical server, isolation between the honeypot virtual machine and the physical server is achieved.

[0092] The present invention also provides an abnormal behavior monitoring method in cloud computing. As Figure 3 shown, the method includes the following steps:

[0093] Step 1, obtain the number N of physical servers in cloud computing, and set M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers; allocate the M honeypot virtual machines to N physical servers and run them; a honeypot application runs in the honeypot virtual machine; where M and N are positive integers, and M ≤ N;

[0094] Step 2, when a preset condition is met, adjust the relationship between the honeypot virtual machine and the physical server, and migrate the honeypot virtual machine to the corresponding physical server;

[0095] Step 3, set a secure area in the memory area of the physical server. The access situation of the honeypot virtual machine collected by the honeypot application is stored in the secure area in text form, and the sending thread of the honeypot application sends the data in the secure area to the data processing module;

[0096] Step 4, process the sent data and identify abnormal behaviors in cloud computing access.

[0097] The order of a method for monitoring abnormal behaviors in cloud computing is not strictly in accordance with Steps 1-4. For example, Step 2 can be after Step 3 and / or 4, or between Step 3 and 4.

[0098] In addition, the present invention also provides a computer-readable storage medium. The readable storage medium stores a computer program, and when the computer program is executed by a processor, it executes the following method:

[0099] Obtain the number N of physical servers in cloud computing, and set M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers; allocate the M honeypot virtual machines to the N physical servers and run them; a honeypot application program runs in the honeypot virtual machines; where M and N are positive integers, and M ≤ N;

[0100] When a preset condition is satisfied, adjust the relationship between the honeypot virtual machines and the physical servers, and migrate the honeypot virtual machines to the corresponding physical servers;

[0101] Set up a security area in the memory area of the physical server. The honeypot application program stores the access conditions to the honeypot virtual machines collected in text form in the security area, and the sending thread of the honeypot application program sends the data in the security area to the data processing module;

[0102] Process the sent data and identify abnormal behaviors in the cloud computing access.

[0103] Preferably, the setting of M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers is specifically:

[0104] Obtain the increase in the load of a physical server caused by running a honeypot virtual machine according to historical data, calculate the difference between the physical server load threshold and the average load of the physical server, and obtain the maximum allowable number of honeypot virtual machines according to the difference and the increase;

[0105] If the maximum allowable number of honeypot virtual machines is greater than or equal to N, set M = N honeypot virtual machines; otherwise, set the maximum allowable number of honeypot virtual machines as M.

[0106] Preferably, the allocation of the M honeypot virtual machines to the N physical servers and running them is specifically:

[0107] If M = N, evenly allocate the M honeypot virtual machines to each physical server; otherwise, sort the physical servers in descending order according to the total access volume, and allocate the M honeypot virtual machines to the first M physical servers after sorting;

[0108] Sort the virtual machines in the physical server allocated with honeypot virtual machines according to the access volume, and establish the correspondence relationship of virtual machine - system environment information - running time;

[0109] Set the system environment information and running time of the honeypot virtual machine according to the correspondence relationship. When the running time is reached, obtain the system environment information and running time of the next virtual machine after sorting, and set the system environment information and running time of the honeypot virtual machine, and so on, repeating continuously.

[0110] Preferably, the preset condition is:

[0111] The virtual machine migrates between physical machines, or a physical machine is added, or the interval between two adjustments of the honeypot virtual machine is greater than the time threshold.

[0112] Preferably, the calculation method of the running time is:

[0113] Calculate the ratio of the first weight of the current virtual machine to the sum of the first weights of all virtual machines in the physical server where the current virtual machine is located, and take the product of the time threshold and the ratio as the running time of the current virtual machine;

[0114] The first weight is the ratio of the historical access volume of the virtual machine in the current physical server to the running time in the current physical server.

[0115] Preferably, adjusting the relationship between the honeypot virtual machine and the physical server and migrating the honeypot virtual machine to the corresponding physical server specifically includes:

[0116] If the preset condition is to add a physical machine, re - execute the initialization module;

[0117] Otherwise, if M = N, randomly select M / 2 honeypot virtual machines and swap them with another M / 2 honeypot virtual machines; if M < N, select N - M physical servers with high security and running honeypot virtual machines, and migrate the honeypot virtual machines corresponding to the N - M physical servers to the servers without running honeypot virtual machines.

[0118] Preferably, the honeypot application stores the collected access situation of the honeypot virtual machine in text form in a secure area, specifically:

[0119] When detecting the creation or migration of a honeypot virtual machine, start a security detection thread on the physical server, and the physical server returns a pointer that the honeypot application can directly map to the physical server memory address to the security detection thread; the physical server memory area pointed to by the pointer is used as the secure area;

[0120] The honeypot application sends the text to a security detection thread associated with the honeypot virtual machine to perform security detection on the text, and determines whether the format and value of the text meet the requirements. If they do not meet the requirements, writing to the security area is prohibited and an alarm message is issued; otherwise, the security detection thread stores the text in the security area.

[0121] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of adding a necessary general hardware platform, and of course, can also be implemented by a combination of hardware and software. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a computer product. The present invention can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0122] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for monitoring abnormal behavior in cloud computing, characterized in that: Obtain the number N of physical servers in cloud computing, and set M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers; allocate the M honeypot virtual machines to N physical servers and run them; a honeypot application program runs in the honeypot virtual machines; where M and N are positive integers, and M ≤ N; When a preset condition is met, adjust the relationship between the honeypot virtual machine and the physical server, and migrate the honeypot virtual machine to the corresponding physical server; Set a secure area in the memory area of the physical server, and the honeypot application program stores the access situation to the honeypot virtual machine collected in text form in the secure area, and the sending thread of the honeypot application program sends the data in the secure area to the data processing module; Process the sent data and identify abnormal behavior in cloud computing access.

2. The abnormal behavior monitoring method according to claim 1, wherein The step of allocating the M honeypot virtual machines to N physical servers and running them specifically is: If M = N, evenly allocate the M honeypot virtual machines to each physical server; otherwise, sort the physical servers in descending order according to the total access volume, and allocate the M honeypot virtual machines to the first M physical servers after sorting; Sort the virtual machines in the physical servers allocated with honeypot virtual machines according to the access volume, and establish a correspondence relationship of virtual machine - system environment information - running time; Set the system environment information and running time of the honeypot virtual machine according to the correspondence relationship. When the running time is reached, obtain the system environment information and running time of the next virtual machine after sorting, and set the system environment information and running time of the honeypot virtual machine, and so on, repeating continuously.

3. The abnormal behavior monitoring method according to claim 1, characterized in that, The step that the honeypot application program stores the access situation to the honeypot virtual machine collected in text form in the secure area specifically is: When detecting the creation or migration of a honeypot virtual machine, start a security detection thread on the physical server, and the physical server returns a pointer that the honeypot application program can directly map to the physical server memory address to the security detection thread; the physical server memory area pointed to by the pointer is used as the secure area; The honeypot application program sends the text to the security detection thread associated with the honeypot virtual machine to perform security detection on the text, and judges whether the format and value of the text meet the requirements. If they do not meet the requirements, prohibit writing to the secure area and send an alarm message; Otherwise, the security detection thread stores the text in the secure area.

4. An abnormal behavior monitoring system in cloud computing, characterized in that, The system includes the following modules: An initialization module, which is used to obtain the number N of physical servers in cloud computing, set M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers; allocate the M honeypot virtual machines to N physical servers and run them; a honeypot application program runs in the honeypot virtual machines; where M and N are positive integers, and M ≤ N; A honeypot virtual machine adjustment module, which is used to adjust the relationship between the honeypot virtual machine and the physical server and migrate the honeypot virtual machine to the corresponding physical server when a preset condition is met; The summary module is used to set up a secure area in the memory area of the physical server. The honeypot application stores the access situations to the honeypot virtual machines collected in text form in the secure area, and the sending thread of the honeypot application sends the data in the secure area to the data processing module; The data processing module is used to process the sent data and identify abnormal behaviors in cloud computing access.

5. The system according to claim 4, characterized in that The step of setting M honeypot virtual machines according to the number N of physical servers and the average load of the physical servers is specifically as follows: Obtain the increase in the load of a physical server caused by running a honeypot virtual machine according to historical data, calculate the difference between the physical server load threshold and the average load of the physical server, and obtain the maximum allowable number of honeypot virtual machines according to the difference and the increase; If the maximum allowable number of honeypot virtual machines is greater than or equal to N, set M = N honeypot virtual machines; otherwise, set the maximum allowable number of honeypot virtual machines as M.

6. The system according to claim 4, wherein The step of allocating M honeypot virtual machines to N physical servers and running them is specifically as follows: If M = N, evenly distribute M honeypot virtual machines to each physical server; otherwise, sort the physical servers in descending order according to the total access volume, and allocate M honeypot virtual machines to the first M physical servers after sorting; Sort the virtual machines in the physical servers allocated with honeypot virtual machines according to the access volume, and establish the corresponding relationship of virtual machine - system environment information - running time; Set the system environment information and running time of the honeypot virtual machine according to the corresponding relationship. When the running time is reached, obtain the system environment information and running time of the next virtual machine after sorting, and set the system environment information and running time of the honeypot virtual machine, and so on, repeating continuously.

7. The system according to claim 6, wherein The preset conditions are: The virtual machine migrates between physical machines, or a physical machine is added, or the interval between two adjustments of the honeypot virtual machines is greater than the time threshold.

8. The system according to claim 7, wherein The calculation method of the running time is: Calculate the ratio of the first weight of the current virtual machine to the sum of the first weights of all virtual machines in the physical server where the current virtual machine is located, and take the product of the time threshold and the ratio as the running time of the current virtual machine; The first weight is the ratio of the historical access volume of the virtual machine in the current physical server to the running time in the current physical server.

9. The system according to claim 7, wherein The step of adjusting the relationship between the honeypot virtual machine and the physical server and migrating the honeypot virtual machine to the corresponding physical server is specifically as follows: If the preset condition is to add a physical machine, re - execute the initialization module; Otherwise, if M = N, randomly select M / 2 honeypot virtual machines and swap them with another M / 2 honeypot virtual machines; if M < N, select N - M physical servers with high security and running honeypot virtual machines, and migrate the honeypot virtual machines corresponding to the N - M physical servers to the servers without running honeypot virtual machines.

10. The system according to claim 4, wherein The honeypot application stores the access situations to the honeypot virtual machines collected in text form in the secure area, specifically as follows: When detecting the creation or migration of a honeypot virtual machine, start a security detection thread on the physical server. The physical server returns a pointer to the security detection thread that can be directly mapped to the physical server memory address by the honeypot application; the physical server memory area pointed to by the pointer is used as the security area. The honeypot application sends the text to the security detection thread associated with the honeypot virtual machine to perform security detection on the text, and judges whether the format and value of the text meet the requirements. If they do not meet the requirements, writing to the security area is prohibited and an alarm message is sent. Otherwise, the security detection thread stores the text in the security area.