Early warning method of multi-cloud scene and corresponding device
By receiving and aggregating gradient update data in a multi-cloud environment, and using early warning knowledge graph to train attack detection models, the unified detection and analysis problems of cross-cloud attacks are solved, and timely and accurate security warning and dynamic adjustment are achieved.
Patent Information
- Application Number
- CN202510630727.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-07-25
AI Technical Summary
In multi-cloud environments, it is difficult for the existing technology to achieve unified detection, identification and analysis of cross-cloud attacks, resulting in delays in early warnings or missing the best time for disposal, and lack of dynamic adjustment capabilities, affecting the accuracy and timeliness of security detection.
By receiving gradient update data from multiple cloud platforms, using early warning knowledge graphs for gradient aggregation, generating global gradient update data, and training attack detection models when meeting preset conditions, realizing timely and accurate early warnings for each cloud platform.
It has achieved good security detection effect in multi-cloud environments, can conduct security early warnings in a timely and accurate manner, adapt to the characteristics of different cloud platforms, and improves the dynamic adjustment ability of early warnings.
Smart Images

Figure CN120378186A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of cloud computing and communication technologies, and particularly relates to a warning method and corresponding device for a multi-cloud scenario. Background Art
[0002] In the face of a multi-cloud environment, there are differences in security settings, interfaces, protocols, etc. of different cloud platforms, and there is a lack of unified standards and specifications. In view of the above differences between different cloud platforms and the information gap between cloud platforms, attackers may switch attack targets between different cloud platforms, and single-cloud security solutions are difficult to uniformly detect, identify, and analyze cross-cloud attacks.
[0003] For example, when an abnormal behavior is detected by a certain vehicle networking node, it cannot make a decision immediately and needs to rely on cloud analysis, which easily leads to warning delays and even misses the best opportunity to handle security incidents. Summary of the Invention
[0004] To this end, the present invention provides a warning method and corresponding device for a multi-cloud scenario to achieve effective warning for a multi-cloud scenario.
[0005] To achieve the above object, a first aspect of the present invention provides a warning method for a multi-cloud scenario, which is applied to a coordination node. The warning method includes:
[0006] Receiving gradient update data sent by multiple cloud platforms, where the gradient update data is data generated by the corresponding cloud platform during the process of training a local attack detection model, and at least part of the attack detection models of the cloud platforms are connected to the warning knowledge graph corresponding to the cloud platform;
[0007] Performing gradient aggregation according to the model gradient data of the multiple cloud platforms to obtain global gradient update data, and distributing the global gradient update data to the multiple cloud platforms, where the global gradient update data is used for the multiple cloud platforms to update the local attack detection model;
[0008] When a preset stop condition is met, obtaining the trained attack detection models of the multiple cloud platforms for the multiple cloud platforms to perform warning based on their respective trained attack detection models.
[0009] Further, the warning knowledge graph is a knowledge graph determined according to the business data of the cloud platform for reflecting the association relationship of attack events, and the warning knowledge graph is used to assist in adjusting the gradient of the attack detection model;
[0010] For any cloud platform in each gradient iteration process, the gradient update data is determined according to the global gradient update data obtained in the previous gradient iteration process, the current gradient data of the cloud platform, and the current migration weight, and the migration weight is determined according to the warning knowledge graphs of multiple cloud platforms.
[0011] To achieve the above object, a second aspect of the present invention provides a warning method for a multi-cloud scenario, which is applied to a cloud platform. The warning method includes:
[0012] Receiving the data to be processed sent by the edge node, where the data to be processed is data used to characterize the operation of the target system to be detected;
[0013] Processing the data to be processed based on the warning knowledge graph to obtain embedded data;
[0014] Processing the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result;
[0015] When the detection result indicates that there is an attack event against the target system, determining an attack pattern matching the attack event according to the warning knowledge graph;
[0016] Generating and publishing a warning message according to the matching attack pattern.
[0017] Further, the processing the data to be processed based on the warning knowledge graph to obtain embedded data includes:
[0018] Determining a first node corresponding to the data to be processed;
[0019] Determining a second node corresponding to the first node in the warning knowledge graph;
[0020] Extracting context data of the second node from the warning knowledge graph;
[0021] Obtaining the embedded data according to the context data of the second node.
[0022] Further, the processing the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result includes:
[0023] Fusing the data to be processed and the embedded data to obtain fused data;
[0024] Inputting the fused data into the attack detection model to obtain the detection result;
[0025] Among them, the attack detection model is pre-trained, and the inference of the attack detection model satisfies a preset constraint condition, and the constraint condition is determined based on the early warning knowledge spectrum graph.
[0026] Further, the edge node is configured with a decision tree model, and the data to be processed is sent by the edge node when it determines that the target system has abnormal operation based on the decision tree model.
[0027] Further, the method further includes:
[0028] Analyze historical attack events to determine frequent itemsets;
[0029] Determine early warning rules according to the frequent itemsets;
[0030] Send the early warning rules to the edge nodes within the current cloud platform service scope, and the early warning rules are used for the edge nodes to perform early warning analysis.
[0031] Further, the method further includes:
[0032] Dynamically adjust the early warning rules according to the business scenario, and send the adjusted early warning rules to the edge nodes within the current cloud platform service scope.
[0033] To achieve the above object, a third aspect of the present invention provides an early warning device for a multi-cloud scenario, which is applied to a coordination node. The early warning device includes:
[0034] A first receiving module, configured to receive gradient update data sent by multiple cloud platforms. The gradient update data is data generated by the corresponding cloud platform during the process of training its local attack detection model, and at least part of the attack detection models of the cloud platforms are connected to the early warning knowledge graph corresponding to the cloud platform;
[0035] An aggregation module, configured to perform gradient aggregation according to the model gradient data of multiple cloud platforms to obtain global gradient update data, and distribute the global gradient update data to multiple cloud platforms for the multiple cloud platforms to update their respective local attack detection models based on the global gradient update data;
[0036] An obtaining module, configured to obtain the trained attack detection models of multiple cloud platforms when a preset stop condition is satisfied.
[0037] To achieve the above object, a fourth aspect of the present invention provides an early warning device for a multi-cloud scenario, which is applied to a cloud platform. The early warning device includes:
[0038] A second receiving module, configured to receive the data to be processed sent by an edge node, where the data to be processed is data used to characterize the operation of a target system to be detected;
[0039] A processing module, configured to process the data to be processed based on a warning knowledge graph to obtain embedded data;
[0040] A detection module, configured to process the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result;
[0041] A determination module, configured to, when the detection result indicates that there is an attack event against the target system, determine an attack pattern matching the attack event according to the warning knowledge graph;
[0042] A generation module, configured to generate and publish a warning message according to the matching attack pattern.
[0043] The present invention has the following advantages:
[0044] The warning method for a multi-cloud scenario provided by the present invention receives gradient update data sent by multiple cloud platforms. The gradient update data is data generated by the corresponding cloud platform during the process of training a local attack detection model, and at least some of the attack detection models of the cloud platforms are connected to the warning knowledge graph corresponding to the cloud platform; gradient aggregation is performed on the model gradient data of multiple cloud platforms to obtain global gradient update data, and the global gradient update data is distributed to multiple cloud platforms. The global gradient update data is used for multiple cloud platforms to update local attack detection models; when a preset stop condition is met, trained attack detection models of multiple cloud platforms are obtained for multiple cloud platforms to perform warnings based on their respective trained attack detection models. It can be seen that the present application can obtain an attack detection model with a good security detection effect and matching the characteristics of the cloud platform, so as to realize timely and accurate security warnings for the cloud platform. Description of the Drawings
[0045] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the following specific embodiments, they are used to explain the present invention, but do not constitute a limitation to the present invention.
[0046] Figure 1 is a flowchart of a warning method for a multi-cloud scenario provided by an embodiment of the present application.
[0047] Figure 2 is a schematic diagram of a warning method for a multi-cloud scenario provided by an embodiment of the present application.
[0048] Figure 3 is a flowchart of a warning method for a multi-cloud scenario provided by an embodiment of the present application.
[0049] Figure 4 It is a schematic flowchart of a warning method for a multi-cloud scenario provided by an embodiment of the present application.
[0050] Figure 5 It is a block diagram of the composition of a warning device for a multi-cloud scenario provided by an embodiment of the present application.
[0051] Figure 6 It is a block diagram of the composition of a warning device for a multi-cloud scenario provided by an embodiment of the present application. Detailed implementation manners
[0052] The following will describe the detailed implementation manners of the present invention with reference to the accompanying drawings. It should be understood that the detailed implementation manners described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0053] Although current cloud security technologies have made certain progress in aspects such as access control, log auditing, and encrypted storage, there are still the following deficiencies when dealing with security threats in a multi-cloud environment, especially in scenarios such as the vehicle networking system (TSP Cloud).
[0054] First, static security rules are difficult to cope with complex attack methods. In related technologies, security detection methods mainly rely on static policies and threshold settings, such as access frequency limits based on fixed rules or anomaly recognition based on single features. However, in systems such as vehicle networking, attack methods are becoming increasingly complex, involving issues such as identity forgery, distributed attacks (such as malicious over-the-air (OTA) flashing controlled by the cloud), and progressive data leakage. Strategies that simply rely on fixed rules often cannot effectively cope. For example, for counterfeiting TSP terminals, an attacker can simulate the identity of a legitimate vehicle terminal, repeatedly attempt to access the storage system in different cloud regions, and use the "low-frequency + long-term" strategy to avoid threshold detection. Another example is that an attacker may first obtain cloud storage access rights through SQL injection or low-privilege account vulnerabilities, and then gradually penetrate using the stolen credentials. Traditional rules are difficult to associate attack behaviors in different stages, resulting in delayed or ineffective alarms.
[0055] Second, the existing threat intelligence is not fully utilized, and it is difficult to form accurate warnings. Current cloud security solutions usually only rely on internal data, such as access logs, operation behavior records, etc., and do not fully utilize external threat intelligence (such as MITRE ATT&CK, CVE vulnerability database, blacklist IP intelligence, etc.) to enhance security analysis capabilities.
[0056] Secondly, data quality issues can also affect the accuracy of anomaly detection. For example, in the vehicle networking system, the data sources are diverse, including vehicle sensor data, TSP management platform logs, edge computing node analysis results, etc. These data may be incomplete or of degraded quality due to factors such as network jitter, acquisition delay, and device anomalies, thereby affecting the reliability of anomaly detection.
[0057] In addition, the distributed early warning architecture lacks the ability of collaborative analysis. Currently, when performing security detection, it mainly relies on the cloud for centralized computing and analysis. Edge nodes usually can only perform basic log collection and preliminary filtering and lack the ability of intelligent analysis. In other words, edge computing nodes cannot issue early warnings independently and still need to rely on cloud analysis, which may lead to early warning delays and even miss the best opportunity for handling security incidents. Moreover, attackers may switch attack targets among different cloud platforms (such as Azure, AWS, and Tencent Cloud), and traditional single-cloud security solutions are difficult to uniformly model and analyze cross-cloud attacks, resulting in limited early warning capabilities.
[0058] Finally, the early warning rules are fixed and difficult to adjust dynamically. Most of the existing security policies adopt predefined rules and lack the ability of adaptive optimization, making it difficult to adjust dynamically according to changes in the business environment. For example, in the vehicle networking system, vehicles may perform a large amount of data interaction during certain time windows (such as during batch OTA upgrades). If the early warning strategy fails to be adjusted dynamically, it may lead to frequent false alarms and affect the normal operation of the system. Another example is that in some cases, the access mode of a specific vehicle model may change due to software version upgrades. If it cannot automatically learn and adapt to this change, it will result in a decrease in detection ability or an increase in false alarms.
[0059] In view of this, the present application provides an early warning method for a multi-cloud scenario, which receives gradient update data sent by multiple cloud platforms. The gradient update data is data generated by the corresponding cloud platform during the process of training the local attack detection model, and the attack detection models of at least some cloud platforms are connected to the warning knowledge graph corresponding to the cloud platform; gradient aggregation is performed according to the model gradient data of multiple cloud platforms to obtain global gradient update data, and the global gradient update data is distributed to multiple cloud platforms. The global gradient update data is used for multiple cloud platforms to update the local attack detection model; when a preset stop condition is met, the trained attack detection models of multiple cloud platforms are obtained for multiple cloud platforms to perform early warnings based on their respective trained attack detection models. It can be seen that the present application can obtain an attack detection model with good security detection effect and matching the characteristics of the cloud platform, thereby realizing timely and accurate security early warnings for the cloud platform.
[0060] The first aspect of the present application provides an early warning method for a multi-cloud scenario, and this method can be applied to a coordination node.
[0061] Figure 1It is a flowchart of a warning method for a multi-cloud scenario provided by an embodiment of the present application. As Figure 1 shown, this method can be applied to a coordination node and may include the following steps.
[0062] Step S11, receiving gradient update data sent by multiple cloud platforms.
[0063] Among them, the gradient update data is data generated by the corresponding cloud platform during the process of training the local attack detection model, and the attack detection models of at least some cloud platforms are connected to the warning knowledge graph corresponding to the cloud platform.
[0064] For example, if there are N cloud platforms, the coordination node can receive N gradient update data, and the N gradient update data correspond one-to-one to the N cloud platforms, where N is an integer greater than 1. Among them, M cloud platforms have corresponding warning knowledge graphs (M ≤ N), and the attack detection models of the M cloud platforms are respectively connected to their respective warning knowledge graphs. The warning knowledge graph is a structured and semantic way of representing warning knowledge, which represents knowledge in the warning field such as entities, relationships, and attributes in a graphical form.
[0065] In some optional embodiments, the warning knowledge graph is a knowledge graph determined according to the business data of the cloud platform and used to reflect the association relationship of attack events.
[0066] In some optional embodiments, the warning knowledge graph can be established based on the following method: First, collect a large amount of data from various data sources (such as the system logs of the cloud platform, historical attack event data, etc.), including information such as entities, relationships, and attributes, and clean and preprocess the collected data (such as removing duplicate data, formatting data, unifying data, etc.), and extract entities from the processed data, and classify and label the entities. Further, extract the relationships between entities from the data, and classify and label the relationships, and extract the attributes of the entities and relationships from the data, and classify and label the attributes. Finally, convert the extracted information such as entities, relationships, and attributes into a graphical warning knowledge graph.
[0067] In some optional embodiments, the warning knowledge graph can be used to assist in adjusting the gradient of the attack detection model.
[0068] In some alternative embodiments, the early warning knowledge graph has at least a feature enhancement effect and an inference guidance effect. For example, some feature extraction and other processing can be performed on the training data based on the early warning knowledge graph to obtain embedded data corresponding to the training data, and the context understanding of the input sample data by the attack detection model can be enhanced through this embedded data. For example, logical rules can be generated based on the event causal chain in the early warning knowledge graph, and corresponding constraint conditions can be determined based on these logical rules, so that the output of the attack detection model can be constrained or corrected based on these constraint conditions. Among them, the event causal chain is a link determined by several nodes and the association relationships between the nodes in the early warning knowledge graph, which can represent the causal relationship of certain attack events.
[0069] In some alternative embodiments, the gradient update data can be values such as gradient difference data, gradient differential data, or gradient difference percentage, rather than the value of the gradient itself.
[0070] For example, for an attack detection model in a certain cloud platform, the gradient value obtained after the (i - 1)-th round of iterative update is g(i - 1). After a new round of data processing, the new gradient value obtained is g(i). Based on this, the gradient update data can be determined as G(i) = Δg = g(i) - g(i - 1), and G(i) is sent to the coordination node so that the coordination node can perform corresponding data processing, thereby instructing the cloud platform to execute the (i + 1)-th round of iterative update.
[0071] Furthermore, in some alternative embodiments, for the consideration of reducing the data transmission volume and lowering the bandwidth cost, after obtaining Δg = g(i) - g(i - 1), the Δg can be compared with a preset gradient update threshold. If Δg is greater than or equal to the gradient update threshold, then Δg is determined as the gradient update data and transmitted to the coordination node. If Δg is less than the gradient update threshold, it is considered that the gradient update amount is small, and this Δg is not used as the gradient update data to be transmitted to the coordination node.
[0072] Similarly, in some alternative embodiments, for a certain cloud platform, after obtaining all the gradient update data, all the gradient update data can also be sorted according to the numerical size (i.e., the absolute value of the gradient update data) to obtain a gradient update data sequence, and a target sequence is intercepted from this gradient update data sequence according to a preset interception ratio (such as 30%, 50%, etc.). The target sequence includes the part of the gradient update data with larger values, and the ratio between the number of gradient update data corresponding to the target sequence and the number of gradient update data corresponding to the entire gradient update data sequence is equal to the preset interception ratio. For example, if the total number of gradient update data is 100 and the preset interception ratio is 30%, then the number of gradient update data corresponding to the target sequence is 30.
[0073] In some alternative embodiments, the gradient can be characterized based on the weight values of the model. Correspondingly, for an attack detection model in a certain cloud platform, the weight value obtained after the (i-1)-th round of iterative update is w(i-1), and after a new round of data processing, the new weight value obtained is w(i). Based on this, the corresponding gradient update data can be determined as W(i)=Δw = w(i)-w(i-1), and W(i) is sent to the coordination node so that the coordination node can perform corresponding data processing, thereby instructing the cloud platform to perform the (i + 1)-th round of iterative update.
[0074] In some alternative embodiments, the gradient update data can be data encrypted by the cloud platform, thereby enhancing data security and reducing the risk of data leakage.
[0075] For example, the coordination node, as a neutral third party or a blockchain node, can generate a homomorphic encryption public key and distribute it to each cloud platform. When the cloud platform interacts with the coordination node for data, for data security, the homomorphic encryption public key can be used to encrypt the data.
[0076] It can be seen from this that in the embodiments of the present disclosure, there are multiple cloud platforms in a multi-cloud scenario, and each cloud platform is locally configured with its own attack detection model to detect attack events on the cloud platform, so as to achieve timely and accurate early warning.
[0077] In some alternative embodiments, an initial attack detection model can be pre-constructed and distributed to each cloud platform, so as to obtain the attack detection models of each cloud platform locally. On this basis, these attack detection models are trained according to the method of the embodiments of the present disclosure to obtain the trained attack detection models of each cloud platform, so as to identify attack events based on their respective attack detection models and give early warnings in a timely manner.
[0078] In some alternative embodiments, considering that the data types to be processed by different cloud platforms are different and the tasks to be executed are also different, therefore, the attack detection models of each cloud platform can be pre-trained in advance. On this basis, based on the method of the embodiments of the present disclosure, these pre-trained models are secondarily trained or fine-tuned, so as to further improve the accuracy of these attack detection models and their matching with the corresponding cloud platforms, and enhance the processing performance of the attack detection models for specific tasks (such as the tasks to be processed by the cloud platform where they are located).
[0079] Step S12: Aggregate the model gradient data of multiple cloud platforms to obtain global gradient update data, and distribute the global gradient update data to multiple cloud platforms.
[0080] Among them, the global gradient update data is used for multiple cloud platforms to update the local attack detection models.
[0081] In some alternative embodiments, the purpose of gradient aggregation is to aggregate gradients among multiple cloud platforms to obtain global gradient information, so as to update the model parameters of the attack detection models of each cloud platform.
[0082] It should be noted that the above manners of gradient aggregation are only illustrative examples, and the embodiments of the present disclosure are not limited thereto.
[0083] In some alternative embodiments, the mean value can be calculated based on the model gradient data of multiple cloud platforms to achieve gradient aggregation, so as to obtain global gradient update data, and distribute the global gradient update data to each cloud platform. For any one cloud platform, it can update its local attack detection model according to the received global gradient update data to obtain a new attack detection model.
[0084] In some alternative embodiments, for any one cloud platform in each gradient iteration process, the gradient update data is determined according to the global gradient update data obtained in the previous gradient iteration process, the current gradient data of the cloud platform, and the current migration weight, and the migration weight is determined according to the warning knowledge graphs of multiple cloud platforms.
[0085] That is to say, considering that the data distributions of different cloud platforms are different (for example, AWS logs focus on API calls, and Azure logs focus on storage access), therefore, transfer learning can be used to fine-tune the global model.
[0086] For example, for any one cloud platform, its gradient update process can be characterized as: W 本地 (i) = W 全局 (i - 1) + α × [W 本地 (i - 1) - W 全局 (i - 1)], where i represents the i-th iteration, i - 1 represents the (i - 1)-th iteration, W 本地 represents the gradient data of the local attack detection model of this cloud platform, W 全局 represents the global gradient data corresponding to the coordination node, α represents the migration weight, and it can be dynamically adjusted according to the similarity between the data corresponding to the cloud platform. Based on this, the gradient update data for the i-th iteration can be determined as W 本地 (i) - W 本地 (i - 1).
[0087] In some alternative embodiments, the Threshold Signature Scheme (TSS) technology can also be used. That is, after distributing the global gradient update data to multiple cloud platforms, at least K cloud platforms (K ≤ N, where N represents the total number of cloud platforms) are required to jointly decrypt the global gradient update data, thereby preventing single-point key leakage.
[0088] Step S13: When the preset stopping condition is met, obtain the trained attack detection models of multiple cloud platforms for the multiple cloud platforms to issue early warnings based on their respective trained attack detection models.
[0089] Among them, the preset stopping condition is a condition for determining whether to stop model training.
[0090] In some alternative embodiments, the preset stopping condition includes that the number of training times is greater than or equal to the preset iteration number threshold, the loss value is less than or equal to the preset loss threshold, the model performance reaches the preset performance requirement, etc. The embodiments of the present disclosure do not limit this.
[0091] It can be seen that in each round of iteration, each cloud platform first obtains the gradient update data locally, and then sends the gradient update data to the coordination node. The coordination node aggregates the gradients according to the multiple gradient update data to obtain the global gradient update data, and distributes the global gradient update data to each cloud platform. Each cloud platform performs gradient update according to the global gradient update data to obtain new gradient update data, and repeats the above process. Until the preset stopping condition is met, stop the model training, and each cloud platform obtains the locally trained attack detection model.
[0092] It should be noted that in the above process, at least some cloud platforms are pre-configured with an early warning knowledge graph, and the early warning knowledge graph is connected to the local attack detection model of the cloud platform. When performing gradient update locally on the cloud platform, the early warning knowledge graph will also participate, playing roles such as feature enhancement and inference guidance, thereby improving the quality of gradient update.
[0093] In summary, in the embodiments of the present disclosure, gradient update data sent by multiple cloud platforms is received. The gradient update data is data generated by the corresponding cloud platforms during the process of training the local attack detection model, and the attack detection models of at least some cloud platforms are connected to the warning knowledge graph corresponding to the cloud platforms. Gradient aggregation is performed on the model gradient data of multiple cloud platforms to obtain global gradient update data, and the global gradient update data is distributed to multiple cloud platforms. The global gradient update data is used for multiple cloud platforms to update the local attack detection model. When the preset stop condition is met, the trained attack detection models of multiple cloud platforms are obtained for multiple cloud platforms to issue warnings based on their respective trained attack detection models. It can be seen from this that the present application can obtain an attack detection model with good security detection effect and matching the characteristics of the cloud platform, so as to realize timely and accurate security warnings for the cloud platform.
[0094] Figure 2 It is a schematic diagram of a warning method for a multi-cloud scenario provided by an embodiment of the present application. As Figure 2 shown, the coordination node is connected to a total of N cloud platforms, namely cloud platform 10, cloud platform 11,..., cloud platform 1N. Among them, the local attack detection model 101 and the warning knowledge graph 102 are configured in cloud platform 10, and the attack detection model 101 and the warning knowledge graph 102 are connected. Similarly, the local attack detection model 111 and the warning knowledge graph 112 are configured in cloud platform 11, and the attack detection model 111 and the warning knowledge graph 112 are connected,..., the local attack detection model 1N1 and the warning knowledge graph 1N2 are configured in cloud platform 1N, and the attack detection model 1N1 and the warning knowledge graph 1N2 are connected.
[0095] In some optional embodiments, for any gradient update process, cloud platform 10 generates gradient update data 103 based on the attack detection model 101 and the warning knowledge graph 102, and sends the gradient update data 103 to the coordination node 20. Similarly, cloud platform 11 generates gradient update data 113 based on the attack detection model 111 and the warning knowledge graph 112, and sends the gradient update data 113 to the coordination node 20,..., cloud platform 1N generates gradient update data 1N3 based on the attack detection model 1N1 and the warning knowledge graph 1N2, and sends the gradient update data 1N3 to the coordination node 20.
[0096] For the coordination node, it aggregates gradients based on the received gradient update data 103, gradient update data 113, …, gradient update data 1N3 to obtain global gradient update data 201, and distributes the global gradient update data 201 to cloud platforms 10, cloud platforms 11, …, cloud platforms 1N, so that each cloud platform updates the gradients of its local attack detection model based on the global gradient update data, thereby obtaining a new round of gradient update data and realizing iterative update of the gradients.
[0097] The second aspect of this application provides a warning method for a multi-cloud scenario, and this method can be applied to a cloud platform.
[0098] Figure 3 It is a flowchart of a warning method for a multi-cloud scenario provided by an embodiment of this application. As Figure 3 shown, this method can be applied to a cloud platform and may include the following steps.
[0099] Step S31, receive the data to be processed sent by the edge node.
[0100] Among them, the data to be processed is data used to characterize the operation of the target system to be detected.
[0101] In some optional embodiments, the edge node is configured with a decision tree model, and the data to be processed is sent by the edge node when it determines that the target system has abnormal operation based on the decision tree model. That is to say, when the edge node identifies a suspicious event of abnormal operation, it sends the corresponding data to be processed to the cloud platform. Since the edge node is configured with a decision tree model, the edge node has certain data processing capabilities. Therefore, the edge node can initially judge whether there is abnormal operation. If it judges that there is abnormal operation, it will send the data to be processed to the cloud platform. If it judges that there is no abnormal operation, it will not send data to the cloud platform. Therefore, it can effectively relieve the data processing volume of the cloud platform and reduce the data processing pressure.
[0102] Step S32, process the data to be processed based on the warning knowledge graph to obtain embedded data.
[0103] In some optional embodiments, the warning knowledge graph has a feature enhancement effect. By processing the data to be processed through the warning knowledge graph, embedded data corresponding to the data to be processed can be obtained. Through this embedded data, the attack detection model's understanding of the context of the data to be processed can be enhanced, and the model processing effect can be improved.
[0104] In some alternative embodiments, the data to be processed is processed based on the warning knowledge graph to obtain embedded data, including: determining a first node corresponding to the data to be processed; determining a second node corresponding to the first node in the warning knowledge graph; extracting context data of the second node from the warning knowledge graph; and obtaining embedded data according to the context data of the second node.
[0105] Exemplarily, by analyzing the data to be processed, an entity node corresponding thereto (such as a certain known vulnerability) can be determined as the first node, and a node corresponding to the entity node is searched from the warning knowledge graph as the second node, and then the context data of the second node (such as the attribute information of the second node and / or the relevant information of the nodes having an association relationship with the second node, etc.) is extracted, and the embedded data is obtained according to the context data.
[0106] Step S33: Process the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result.
[0107] In some alternative embodiments, the data to be processed and the embedded data are processed based on a preset attack detection model to obtain a detection result, including: fusing the data to be processed and the embedded data to obtain fused data; inputting the fused data into the attack detection model to obtain a detection result; wherein the attack detection model is pre-trained, and the inference of the attack detection model satisfies a preset constraint condition, and the constraint condition is determined based on the warning knowledge graph.
[0108] In some alternative embodiments, the data to be processed and the embedded data can be concatenated to obtain fused data, or the data to be processed and the embedded data can be superimposed as fused data, and the embodiments of the present disclosure do not limit this.
[0109] In some alternative embodiments, a connection between the warning knowledge graph and the attack detection model can be established in advance. Correspondingly, when giving a warning, only the data to be processed needs to be input into the attack detection model. Data processing processes such as obtaining embedded data based on the data to be processed and the warning knowledge graph, and obtaining fused data based on the embedded data and the data to be processed are all internal data processing processes of the model and do not require external operations.
[0110] In some alternative embodiments, the attack detection model can be represented as:
[0111] L(x) = ||x - x_hat||^2
[0112] Among them, \(\hat{x} = \text{Decoder}(\text{Encoder}(x))\), where \(x\) represents the input data (equivalent to the fused data, which can be data representing vehicle logs, data of interface calls, etc.), \(\text{Encoder}\) represents an encoder that is used to compress \(x\) into a low-dimensional latent representation \(z\), i.e., \(z=\text{Encoder}(x)\), and \(\text{Decoder}\) represents a decoder that is used to reconstruct the data based on \(z\), and the reconstructed data can be represented as \(\hat{x}=\text{Decoder}(z)\). \(L(x)\) represents the reconstruction error, which can measure the difference between the input data \(x\) and the reconstructed data \(\hat{x}\). The larger the error, the more likely the data is abnormal.
[0113] Exemplarily, the original data can be represented as Table 1.
[0114] Table 1 Original Data
[0115]
[0116] Based on the above original data, the data to be processed is \(x = [0.8, 30, 5.0, 200]\). After inputting this data to be processed into the attack detection model, through a series of operations such as context extraction, encoding, and decoding by the warning knowledge graph connected to it, a reconstruction error can be obtained, and based on this reconstruction error, a detection result can be obtained, and based on this detection result, it is judged whether there is an attack event against the target system.
[0117] Furthermore, the data output by the encoder can be represented as \(z=\text{Encoder}(x)=[0.5, -0.3]\), and the data reconstructed by the decoder can be represented as \(\hat{x}=\text{Decoder}(z)=[0.78, 28, 4.8, 195]\). Based on this, the reconstruction error can be obtained as \(L(x)=(0.8 - 0.78)\) 2 +(30 - 28) 2 +(5.0 - 4.8) 2 +(200 - 195) 2 = 0.0004 + 4 + 0.04 + 25 = 29.04. Further, if the preset warning threshold is assumed to be 30, then since the reconstruction error is less than the warning threshold, no alarm is triggered, and it is determined to be normal behavior, and there is no attack event.
[0118] Exemplarily, the original data can be represented as Table 2.
[0119] Table 2 Original Data
[0120]
[0121] Based on the above raw data, the data to be processed can be obtained as x = [0.8, 200, 5.0, 200]. When this data to be processed is input into the attack detection model, the data output by the encoder can be characterized as z = Encoder(x) = [1.2, 0.6], and the data reconstructed by the decoder can be characterized as x^ = Decoder(z) = [0.75, 50, 4.5, 180]. Based on this, the reconstruction error can be obtained as L(x) = (0.8 - 0.75) 2 +(200 - 50) 2 +(5.0 - 4.5) 2 +(200 - 180) 2 = 0.0025 + 22500 + 0.25 + 400 = 22900.25. Further, if it is assumed that the preset warning threshold is 30, then since the reconstruction error is greater than the warning threshold, an alarm is triggered, and it is determined that there is an attack event against the target system.
[0122] Step S34, in the case where the detection result indicates the existence of an attack event against the target system, determine the attack pattern matching the attack event according to the warning knowledge graph.
[0123] In some alternative embodiments, the attack patterns include attack patterns against storage security, attack patterns against abuse of interface calls, etc., and the embodiments of the present application do not limit this.
[0124] In some alternative embodiments, when it is determined that there is an attack event, the warning knowledge graph can be used to determine the attack pattern corresponding to the attack event, so as to facilitate more accurate and targeted issuance of warnings.
[0125] Step S35, generate and issue a warning message according to the matching attack pattern.
[0126] In some alternative embodiments, the cloud platform can issue a warning message to the edge node or to other cloud platforms.
[0127] For example, if the cloud platform determines according to the matching attack pattern that the attack event only targets the current cloud platform, it can only issue a warning message to its edge node.
[0128] For example, if the cloud platform determines according to the matching attack pattern that the attack event may target other cloud platforms in addition to the current cloud platform, it can not only issue a warning message to the edge node of the current cloud platform, but also issue a warning message to other cloud platforms.
[0129] In some alternative embodiments, the early warning method may further include: analyzing historical attack events to determine frequent item sets; determining early warning rules based on the frequent item sets; and sending the early warning rules to edge nodes within the current cloud platform service scope, where the early warning rules are used for the edge nodes to perform early warning analysis.
[0130] That is to say, some early warning rules for judging whether there are abnormal operating conditions can be summarized from historical attack events, enabling the edge nodes to perform attack detection operations more accurately and flexibly.
[0131] Exemplarily, frequent item sets of historical attack events can be extracted based on algorithms such as Apriori, and early warning rules can be generated in combination with deep learning (for example, "abnormal login + high-frequency remote unlocking of the vehicle" belongs to an early warning rule).
[0132] In some alternative embodiments, early warning rules can be determined based on the support degree, confidence degree, etc. of the frequent item sets. Among them, support degree (X) = (number of transactions containing X) / (total number of transactions), and its function is to screen out frequently occurring combinations, such as screening "preparation actions often taken by attackers before an attack", and confidence degree (X→Y) = support degree (X∪Y) / support degree (X), and its function is to measure the accompanying probability of Y when X occurs, such as "the possibility of data leakage after an abnormal login".
[0133] Table 3 shows an example of the support degree and confidence degree of frequent item sets.
[0134] Table 3 Example of the support degree and confidence degree of frequent item sets
[0135] Frequent itemset Support Confidence {Abnormal login, High-frequency query} 12% 85% {OTA anomaly, API high concurrency} 8% 92%
[0136] In some alternative embodiments, the log fragments of the target system are shown in Table 4:
[0137] Table 4 Log fragments
[0138] Log ID Event combination (X ∪ Y) 1 Abnormal login, High-frequency query, Data download 2 Abnormal login, Data download 3 High-frequency query, API error 4 Abnormal login, High-frequency query, Data download
[0139] By analyzing the above log fragments, it can be determined whether data leakage is associated after an abnormal login.
[0140] First, calculate the support degree of "abnormal login + data download". Among them, the number of transactions containing the combination = 3 (corresponding to Log 1, Log 2, and Log 4), and the total number of transactions = 4. Therefore, the support degree = 3 / 4 = 75%.
[0141] Secondly, calculate the confidence level of "abnormal login + data download". Among them, the support degree of ("abnormal login + data download") = 75%, and the support degree of ("abnormal login") = 3 / 4 = 75% (abnormal logins exist in Log 1, Log 2, and Log 4). Therefore, the confidence level = 75% / 75% = 100%.
[0142] It can be seen from this that as long as an abnormal login occurs, data download will be triggered 100%. Therefore, it is determined that there is a relatively high risk of abnormal login, and an immediate warning is required, and the data download channel is blocked.
[0143] It should be noted that the formulation and distribution of the above warning rules is a dynamic process, that is, the warning rules can be updated regularly or irregularly according to requirements, and when the warning rules change, they are synchronized to each edge node in a timely manner, so as to effectively improve the risk identification ability of the edge node.
[0144] In some alternative embodiments, the warning method may further include: dynamically adjusting the warning rules according to the service scenario, and distributing the adjusted warning rules to the edge nodes within the scope of the current cloud platform service.
[0145] In some alternative embodiments, the warning rules can be optimized based on reinforcement learning (RL). For example, some thresholds used to determine whether there is abnormal operation can be adjusted according to the service scenario (such as during the peak period of OTA update and remote operation during bad weather).
[0146] The process of reinforcement learning can be characterized as: Q(s,a) = Q(s,a) + α × [r + γ × max(Q(s',a')) - Q(s,a)]. Through reinforcement learning, the cloud platform can learn to automatically select the best threshold to adjust the warning strategy in different states, minimizing the false alarm rate and the missed alarm rate.
[0147] Among them, in reinforcement learning, the state s can represent the service scenario (such as "peak period of OTA upgrade"), the action a represents adjusting the API call threshold (such as "threshold + 20%" or "threshold - 10%"), the reward r is the immediate reward, representing the direct return of the current action, and can be calculated according to the false alarm rate and the attack detection rate, etc. (such as r increases when the false alarm rate decreases, and r decreases when the missed alarm rate increases), Q(s,a) represents the long-term revenue expectation of selecting action a in state s (such as "relaxing the threshold during the peak period of OTA upgrade, what is the total revenue"), α represents the learning rate, γ represents the discount factor, representing the importance of future revenue (such as γ = 0.9 means emphasizing long-term revenue, and γ = 0.1 means only looking at the immediate reward), and max(Q(s',a')) is the maximum expected revenue of the next state s' (such as "the potential revenue of the next optimal action").
[0148] Exemplarily, the initial state s = OTA peak period, current Q value: Assume that the initial state has not been learned, Q(s, threshold + 20%) = 0, action selection: Try "threshold + 20%".
[0149] After executing the action, the observation result: If the false alarm rate decreases, the reward r = +0.5. If one attack is missed, the reward r = -1. The corresponding total immediate reward r = 0.5 - 1 = -0.5. Subsequently, enter the new state s' = normal period: The OTA upgrade ends and the traffic returns to normal.
[0150] Calculate the future benefit: Assume that in the state s' (normal period), the known optimal action is "threshold - 10%", and its Q value is Q(s', threshold - 10%) = 2. Future benefit: γ × max(Q(s', a')) = 0.9 × 2 = 1.8. Therefore, γ = 0.9, indicating that long-term benefits are valued.
[0151] Update the Q value: Q(s, threshold + 20%) = 0 + 0.1 · [-0.5 + 1.8 - 0] = 0.1 · 1.3 = 0.13.
[0152] Among them, the learning rate α = 0.1, indicating a small update of the Q value to avoid single errors interfering with historical experience. The final result shows that it is of certain value to relax the threshold during the OTA peak period, but further verification is needed.
[0153] Table 5 shows a learning process.
[0154] Table 5 Schematic Table of the Learning Process
[0155]
[0156] According to Table 5, the action "threshold + 20%" has obtained positive rewards many times during the OTA peak period, and the Q value gradually increases. It belongs to the preferred action. The action "threshold + 30%" has a slow increase in the Q value due to excessive relaxation resulting in missed attacks. The final conclusion is: Moderately relax the threshold (+20%) during the OTA peak period and tighten the threshold (-10%) during the normal period.
[0157] In this way, the warning rules can be adjusted in a timely manner to make the warning rules more compatible with the current operating state and improve the rationality of the warning.
[0158] In the embodiments of the present application, the cloud platform receives the data to be processed sent by the edge node, where the data to be processed is data used to characterize the running status of the target system to be detected; processes the data to be processed based on the early warning knowledge graph to obtain embedded data; processes the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result; in the case where the detection result indicates the existence of an attack event against the target system, determines an attack pattern matching the attack event according to the early warning knowledge graph; generates and publishes an early warning message according to the matching attack pattern. It can be seen from this that the cloud platform can detect attack events in a timely and accurate manner based on the early warning knowledge graph and the attack detection model, improving the accuracy of early warning.
[0159] In summary, in the embodiments of the present disclosure, a decision tree model is configured locally at the edge node, so that the edge node can perform local real-time detection based on the decision tree model, discover abnormal behaviors in a timely manner and report them to the cloud platform. An attack detection model and an early warning knowledge graph are configured on the cloud platform. Based on the attack detection model and the early warning knowledge graph, the data to be processed reported by the edge node is analyzed and processed, so as to discover potential threats.
[0160] Figure 4 is a schematic flowchart of an early warning method for a multi-cloud scenario provided by an embodiment of the present application. As Figure 4 shown, this method can be applied to a cloud platform and may include the following steps.
[0161] Step S401, when the edge node determines that the target system has abnormal operation based on the locally configured decision tree model, it sends the data to be processed used to characterize the running status of the target system to the cloud platform.
[0162] Step S402, the cloud platform receives the data to be processed sent by the edge node.
[0163] Step S403, the cloud platform determines the first node corresponding to the data to be processed, and determines the second node corresponding to the first node in the early warning knowledge graph.
[0164] Step S404, the cloud platform extracts the context data of the second node from the early warning knowledge graph, and obtains embedded data according to the context data of the second node.
[0165] Step S405, the cloud platform fuses the data to be processed and the embedded data to obtain fused data.
[0166] Step S406, the cloud platform inputs the fused data into the attack detection model to obtain a detection result.
[0167] Step S407, in the case where the detection result indicates the existence of an attack event against the target system, the cloud platform determines an attack pattern matching the attack event according to the early warning knowledge graph.
[0168] Step S408: The cloud platform generates and publishes a warning message according to the matched attack pattern.
[0169] Among them, the warning message can be synchronized by the current cloud platform to other cloud platforms in a multi-cloud scenario, so as to perform cross-cloud warning in a timely manner, improving the security of the multi-cloud scenario.
[0170] It can be seen that in the embodiment of the present application, a collaborative analysis architecture of edge computing + cloud knowledge graph is adopted, effectively improving the real-time performance and accuracy of risk detection. Among them, the edge node adopts a lightweight decision tree model, which can detect abnormal behaviors (such as abnormal API calls, high-frequency remote operations, etc.) in the local environment (such as in-vehicle terminals, etc.); the cloud can match attack patterns based on the knowledge graph, associate data such as IP addresses, device IDs, and historical attack records, and improve the attack recognition ability.
[0171] The step division of the above various methods is only for clear description. When implemented, they can be combined into one step or some steps can be split into multiple steps. As long as the same logical relationship is included, they are all within the protection scope of this patent; adding insignificant modifications to the algorithm or process or introducing insignificant designs, but not changing the core design of its algorithm and process are all within the protection scope of this patent.
[0172] The third aspect of the present application provides a warning device for a multi-cloud scenario, and this device can be applied to a coordination node.
[0173] Figure 5 It is a block diagram of the components of a warning device for a multi-cloud scenario provided by an embodiment of the present application. As Figure 5 shown, the warning device 500 for the multi-cloud scenario may include the following modules.
[0174] The first receiving module 501 is used to receive gradient update data sent by multiple cloud platforms. The gradient update data is data generated by the corresponding cloud platform during the process of training the local attack detection model, and the attack detection models of at least some cloud platforms are connected to the warning knowledge graph corresponding to the cloud platform.
[0175] The aggregation module 502 is used to perform gradient aggregation according to the model gradient data of multiple cloud platforms to obtain global gradient update data, and distribute the global gradient update data to multiple cloud platforms for the multiple cloud platforms to update their respective local attack detection models based on the global gradient update data.
[0176] The obtaining module 503 is used to obtain the trained attack detection models of multiple cloud platforms when a preset stop condition is met.
[0177] The warning device provided in this embodiment receives gradient update data sent by multiple cloud platforms through the first receiving module. The gradient update data is data generated by the corresponding cloud platform during the process of training the local attack detection model, and the attack detection models of at least some cloud platforms are connected to the warning knowledge graph corresponding to the cloud platform. Through the aggregation module, gradient aggregation is performed based on the model gradient data of multiple cloud platforms to obtain global gradient update data, and the global gradient update data is distributed to multiple cloud platforms for the multiple cloud platforms to update their respective local attack detection models based on the global gradient update data. Through the obtaining module, when the preset stop condition is met, the trained attack detection models of multiple cloud platforms are obtained. It can be seen that this application can obtain an attack detection model with good security detection effect and matching the characteristics of the cloud platform, so as to realize timely and accurate security warning for the cloud platform.
[0178] The fourth aspect of this application provides a warning device for a multi-cloud scenario, and this device can be applied to a cloud platform.
[0179] Figure 6 It is a block diagram of the components of a warning device for a multi-cloud scenario provided in an embodiment of this application. As Figure 6 shown, the warning device 600 for the multi-cloud scenario may include the following modules.
[0180] The second receiving module 601 is configured to receive the data to be processed sent by the edge node, and the data to be processed is data used to characterize the running status of the target system to be detected.
[0181] The processing module 602 is configured to process the data to be processed based on the warning knowledge graph to obtain embedded data.
[0182] The detection module 603 is configured to process the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result.
[0183] The determination module 604 is configured to, when the detection result indicates the existence of an attack event against the target system, determine an attack pattern matching the attack event according to the warning knowledge graph.
[0184] The generation module 605 is configured to generate and publish a warning message according to the matching attack pattern.
[0185] The warning device provided in this embodiment receives the data to be processed sent by the edge node through the second receiving module, where the data to be processed is data used to characterize the operating conditions of the target system to be detected; through the processing module, the data to be processed is processed based on the warning knowledge graph to obtain embedded data; through the detection module, the data to be processed and the embedded data are processed based on a preset attack detection model to obtain a detection result; through the determination module, when the detection result indicates that there is an attack event against the target system, the attack pattern matching the attack event is determined according to the warning knowledge graph; through the generation module, a warning message is generated and published according to the matching attack pattern. It can be seen that the cloud platform can detect attack events in a timely and accurate manner based on the warning knowledge graph and the attack detection model, improving the accuracy of warning.
[0186] It is worth mentioning that each module involved in this embodiment is a logical module. In practical applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, in order to highlight the innovative part of the present invention, units that are not closely related to solving the technical problems proposed by the present invention are not introduced in this embodiment, but this does not mean that there are no other units in this embodiment.
[0187] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principles of the present invention, but the present invention is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also regarded as the protection scope of the present invention.
Claims
1. A warning method for a multi-cloud scenario, characterized in that, Applied to a coordination node, the method includes: Receiving gradient update data sent by multiple cloud platforms, where the gradient update data is data generated during the local training of the attack detection model by the corresponding cloud platforms, and the attack detection models of at least some of the cloud platforms are connected to the warning knowledge graph corresponding to the cloud platforms; Performing gradient aggregation based on the model gradient data of the multiple cloud platforms to obtain global gradient update data, and distributing the global gradient update data to the multiple cloud platforms, where the global gradient update data is used for the multiple cloud platforms to update the local attack detection model; When a preset stop condition is met, obtaining the trained attack detection models of the multiple cloud platforms for the multiple cloud platforms to issue warnings based on their respective trained attack detection models.
2. The method according to claim 1, wherein The warning knowledge graph is a knowledge graph determined based on the business data of the cloud platform for reflecting the association relationship of attack events, and the warning knowledge graph is used to assist in adjusting the gradient of the attack detection model; For any one of the cloud platforms during each gradient iteration process, the gradient update data is determined according to the global gradient update data obtained in the previous gradient iteration process, the current gradient data of the cloud platform, and the current migration weight, where the migration weight is determined according to the warning knowledge graphs of the multiple cloud platforms.
3. A warning method for a multi-cloud scenario, characterized in that, Applied to a cloud platform, the method includes: Receiving data to be processed sent by an edge node, where the data to be processed is data used to characterize the operation of the target system to be detected; Processing the data to be processed based on the warning knowledge graph to obtain embedded data; Processing the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result; When the detection result indicates the existence of an attack event against the target system, determining an attack pattern matching the attack event according to the warning knowledge graph; Generating and publishing a warning message according to the matching attack pattern.
4. The method according to claim 3, characterized in that, The processing the data to be processed based on the warning knowledge graph to obtain embedded data includes: Determining a first node corresponding to the data to be processed; Determining a second node corresponding to the first node in the warning knowledge graph; Extracting context data of the second node from the warning knowledge graph; Obtaining the embedded data according to the context data of the second node.
5. The method according to claim 3, wherein The processing the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result includes: Fusing the data to be processed and the embedded data to obtain fused data; Inputting the fused data into the attack detection model to obtain the detection result; Wherein, the attack detection model is pre-trained, and the inference of the attack detection model satisfies a preset constraint condition, and the constraint condition is determined based on the warning knowledge spectrum graph.
6. The method according to claim 3, wherein The edge node is configured with a decision tree model, and the data to be processed is sent by the edge node when it determines that the target system has abnormal operation based on the decision tree model.
7. The method according to claim 3, wherein The method further includes: Analyzing historical attack events to determine frequent item sets; Determine a warning rule according to the frequent item set; Send the warning rule to edge nodes within the scope of the current cloud platform service, and the warning rule is used for the edge nodes to perform warning analysis.
8. The method according to claim 7, characterized in that, The method further includes: Dynamically adjust the warning rule according to the business scenario, and send the adjusted warning rule to edge nodes within the scope of the current cloud platform service.
9. An early warning device for a multi-cloud scenario, characterized in that, Applied to a coordination node, the device includes: A first receiving module, configured to receive gradient update data sent by multiple cloud platforms, where the gradient update data is data generated by the corresponding cloud platform during the process of training a local attack detection model, and at least part of the attack detection models of the cloud platforms are connected to the warning knowledge graph corresponding to the cloud platforms; An aggregation module, configured to perform gradient aggregation according to the model gradient data of multiple cloud platforms to obtain global gradient update data, and distribute the global gradient update data to multiple cloud platforms for the multiple cloud platforms to update their respective local attack detection models based on the global gradient update data; An obtaining module, configured to obtain the trained attack detection models of the multiple cloud platforms when a preset stop condition is satisfied.
10. An early warning device for a multi-cloud scenario, characterized in that, Applied to a cloud platform, the device includes: A second receiving module, configured to receive data to be processed sent by an edge node, where the data to be processed is data used to characterize the running status of a target system to be detected; A processing module, configured to process the data to be processed based on a warning knowledge graph to obtain embedded data; A detection module, configured to process the data to be processed and the embedded data based on a preset attack detection model to obtain a detection result; A determination module, configured to determine an attack pattern matching the attack event according to the warning knowledge graph when the detection result indicates that there is an attack event against the target system; A generation module, configured to generate and publish a warning message according to the matching attack pattern.
Citation Information
Patent Citations
Federation defense method based on AIoT-oriented security
CN111625820A
Model training method, device and equipment for multi-level system and storage medium
CN114124522A
Cloud edge cooperative attack identification method and system, computer equipment and storage medium
CN117478379A
Methods and systems for multi-cloud breach detection using ensemble classification and deep anomaly detection
US20240146747A1
Cited By
Video monitoring vulnerability detection method and device based on knowledge graph, and medium
CN121309219A
A knowledge graph-based video monitoring vulnerability detection method, device and medium
CN121309219B