Security protection method and system based on container technology, and readable storage medium
Through a security protection system based on container technology, the protocol simulation module and probe module are used to monitor and analyze network traffic in real time, solving the problem of network attack monitoring in the host system and improving the security and reliability of the equipment.
Patent Information
- Application Number
- CN202510857175.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2045-06-25
AI Technical Summary
The existing technology is difficult to effectively monitor and protect cyber attacks in host systems, resulting in security threats such as data leakage and system crashes.
The security protection system based on container technology is adopted, including a security management platform, protocol simulation module and probe module, to monitor network traffic in real time, simulate attack traffic through simulation containers and analyze them, and aggregate and analyze risk values to trigger alarm processing.
It realizes effective monitoring of device network attacks, improves the security and reliability of devices, adapts to the ever-changing security environment, and provides continuous security protection.
Smart Images

Figure CN120378225B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a security protection method and system based on container technology, and a computer-readable storage medium. Background Art
[0002] With the rapid development and widespread adoption of computer technology, the connection between hosts and the internet is becoming increasingly close, bringing significant convenience to people's lives and work. However, this also exposes host systems to an increasing number of security threats. Cyber attackers may exploit vulnerabilities in host systems to launch malicious attacks, resulting in serious consequences such as data leaks and system crashes. Therefore, effectively monitoring host systems for security threats has become a pressing issue. Summary of the Invention
[0003] The purpose of this application is to provide a security protection method and system based on container technology, and a computer-readable storage medium, which can realize effective monitoring of device network attacks based on container technology, thereby improving the security and reliability of the device.
[0004] To achieve the above objectives:
[0005] In a first aspect, an embodiment of the present application provides a security protection system based on container technology, characterized in that it includes: a security management platform and a protocol simulation module and a probe module deployed in a protected computing device; wherein,
[0006] The probe module is configured to monitor the network traffic of the protected computing device in real time. If the number of threat events with a preset risk level detected within a preset time period is greater than or equal to a preset number threshold, the probe module records the attack traffic in the network traffic and forwards the attack traffic to the protocol simulation module, and reports the threat event information to the security management platform.
[0007] The protocol simulation module, including multiple simulation containers built based on container technology, is configured to distribute attack traffic to the target simulation container for protocol simulation and analysis, and report the obtained analysis results to the security management platform;
[0008] The security management platform is configured to perform aggregate analysis on the reported threat event information and analysis results to determine the risk value of the protected computing device, and trigger alarm processing when the risk value is greater than or equal to a preset risk threshold.
[0009] Optionally, the probe module is configured to:
[0010] Based on a dynamically updated rule base, network traffic characteristics are matched and analyzed to determine the risk level corresponding to threat events in the network traffic. The rule base includes the correspondence between known attack characteristics and risk levels of different threat events, and the probe module regularly pulls updates from the security management platform.
[0011] Optionally, the protocol emulation module is configured to:
[0012] Determine the target simulation container based on the protocol type of the attack traffic;
[0013] Distribute attack traffic to the target simulation container so that the target simulation container simulates real network services to respond to attack requests and records attack logs and attack behaviors;
[0014] Generate analysis results based on recorded attack logs and attack behaviors, and report the analysis results to the security management platform.
[0015] Optionally, the security management platform is configured to:
[0016] Performing aggregation and filtering analysis on the threat event information reported by the probe module and the analysis results reported by the protocol simulation module to obtain an aggregated threat event record; the aggregated threat event record includes at least one threat event and a corresponding risk level;
[0017] According to the formula Calculate the risk value of the protected computing device ; is the preset adjustment coefficient, For the The risk level of each threat event, For the The risk level of each threat event corresponds to the preset risk coefficient. is the total number of aggregated threat events.
[0018] Optionally, the probe module is further configured to:
[0019] According to the formula Calculate the anomaly score of network traffic , Indicates the currently observed network traffic value. Indicates the average value of normal traffic, represents the standard deviation of normal flow;
[0020] If the abnormal score value If the score is greater than or equal to the preset anomaly score threshold, a full-flow capture strategy is adopted to record all network traffic and forward all network traffic to the protocol simulation module.
[0021] Optionally, the probe module is further configured to:
[0022] Send a configuration information pull request to the security management platform;
[0023] If the configuration information fails to be pulled, the cumulative number of failures , according to the formula Calculate the new pull interval , and resend the configuration information pull request to the security management platform after the pull time interval; Indicates the initial pull time interval, is the preset increment coefficient, Indicates the reset cycle of the number of failures. When the number of failures reaches After that, the pull interval is reset to .
[0024] Optionally, the probe module is further configured to obtain operating indicators of the protected computing device and report the operating indicators to the security management platform; the operating indicators include CPU usage, memory usage, and disk usage;
[0025] The security management platform is also configured to Computing resource consumption index , and output an abnormal alarm message when the resource consumption index exceeds the preset resource consumption threshold and / or the CPU occupancy exceeds the preset occupancy threshold.
[0026] In a second aspect, an embodiment of the present application provides a security protection method based on container technology, which is applied to a protected computing device, wherein a protocol emulation module and a probe module are deployed in the protected computing device. The method includes:
[0027] The probe module monitors the network traffic of the protected computing device in real time. If the number of threat events with a preset risk level detected within a preset time period is greater than or equal to the preset number threshold, the attack traffic in the network traffic is recorded and forwarded to the protocol simulation module, and the threat event information is reported to the security management platform;
[0028] Through the protocol simulation module, the attack traffic is distributed to the target simulation container built based on container technology for protocol simulation and analysis, and the obtained analysis results are reported to the security management platform.
[0029] In a third aspect, an embodiment of the present application provides a container-based security protection method, which is applied to a security management platform. The method includes:
[0030] Obtain threat event information reported by a probe module deployed on the protected computing device and analysis results reported by a protocol simulation module; wherein the threat event information is generated by the probe module monitoring the network traffic of the protected computing device, and the analysis results are generated by the protocol simulation module performing protocol simulation and analysis on the attack traffic through the simulation container;
[0031] Perform aggregate analysis on threat event information and analysis results to determine the risk value of the protected computing device;
[0032] If the risk value is greater than or equal to the preset risk threshold, an alarm is triggered.
[0033] In a fourth aspect, an embodiment of the present application provides a computing device comprising: a processor and a memory storing a computer program, wherein when the processor runs the computer program, the above-mentioned security protection method based on container technology is implemented.
[0034] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the above-mentioned security protection method based on container technology is implemented.
[0035] The embodiments of the present application provide a security protection method and system based on container technology, and a computer-readable storage medium, wherein the system includes: a security management platform and a protocol simulation module and a probe module deployed in the protected computing device; wherein the probe module is configured to monitor the network traffic of the protected computing device in real time, and if the number of threat events of a preset risk level detected within a preset time period is greater than or equal to a preset number threshold, the attack traffic in the network traffic is recorded and the attack traffic is forwarded to the protocol simulation module, and the threat event information is reported to the security management platform; the protocol simulation module includes multiple simulation containers built based on container technology, and is configured to distribute the attack traffic to the target simulation container for protocol simulation and analysis, and report the obtained analysis results to the security management platform; the security management platform is configured to aggregate and analyze the reported threat event information and analysis results to determine the risk value of the protected computing device, and trigger an alarm process when the risk value is greater than or equal to the preset risk threshold. In this way, through the close cooperation of the security management platform and the protocol simulation module and probe module deployed in the protected computing device, effective monitoring of device network attacks based on container technology can be achieved, providing comprehensive protection for network security and improving the security and reliability of the device. In addition, the security management platform can flexibly configure protocol simulation modules and probe modules based on security protection needs to adapt to the ever-changing security environment and provide users with continuous security protection. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1A schematic diagram of the structure of a container-based security protection system provided in an embodiment of the present invention.
[0037] Figure 2 Schematic diagram of the process of the security protection method based on container technology provided by the embodiment of the present invention Figure 1 .
[0038] Figure 3 Schematic diagram of the process of the security protection method based on container technology provided by the embodiment of the present invention Figure 2 .
[0039] Figure 4 A schematic diagram of the structure of a computing device provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0040] Here, exemplary embodiments will be described in detail, and examples thereof are shown in the accompanying drawings. When the following description relates to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. It should be noted that, in this article, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device comprising a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device comprising the element. In addition, the parts, features, and elements with the same name in different embodiments of the present application may have the same meaning or may have different meanings, and their specific meanings need to be determined by their explanation in the specific embodiment or further in conjunction with the context in the specific embodiment.
[0041] It should be understood that, although the various steps in the flowchart in the embodiment of the present application are shown in sequence according to the indication of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and they can be performed in other orders. Moreover, at least a portion of the steps in the figure may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and their execution order is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0042] It should be noted that in this article, step codes such as S101 and S102 are used for the purpose of expressing the corresponding content more clearly and concisely, and do not constitute a substantial limitation on the order. When implementing the step, those skilled in the art may execute S102 first and then S101, etc., but these should all be within the scope of protection of this application.
[0043] It should be understood that the specific embodiments described herein are only used to explain the present application and are not intended to limit the present application.
[0044] In the subsequent description, the use of suffixes such as "module", "component" or "unit" to represent elements is only for the purpose of facilitating the description of the present application and has no specific meaning. Therefore, "module", "component" or "unit" can be used interchangeably.
[0045] See Figure 1 , is a security protection system based on container technology provided in an embodiment of the present application. The security protection system provided in this embodiment includes: a security management platform 1 and a protocol simulation module 10 and a probe module 20 deployed in a protected computing device 2; wherein,
[0046] The probe module 20 is configured to monitor the network traffic of the protected computing device 2 in real time. If the number of threat events with a preset risk level detected within a preset time period is greater than or equal to a preset number threshold, the probe module 20 records the attack traffic in the network traffic and forwards the attack traffic to the protocol simulation module 10, and reports the threat event information to the security management platform 1;
[0047] The protocol simulation module 10 includes multiple simulation containers built based on container technology and is configured to distribute attack traffic to target simulation containers for protocol simulation and analysis, and report the obtained analysis results to the security management platform 1;
[0048] The security management platform 1 is configured to perform aggregate analysis on the reported threat event information and analysis results to determine the risk value of the protected computing device, and trigger alarm processing when the risk value is greater than or equal to a preset risk threshold.
[0049] The security management platform 1 is a platform for unified security management of protected computing devices, specifically a cloud server, etc. The protected computing devices are devices that require security protection, specifically computers, etc. The probe module 20 monitors the network traffic of the protected computing device 2 in real time, and the probe module 20 may perform threat detection (also known as attack traffic detection) on the network traffic flowing into the protected computing device 2 in real time.
[0050] In one embodiment, the probe module 20 is configured to match and analyze network traffic characteristics based on a dynamically updated rule base to determine the risk level corresponding to the threat event in the network traffic; the rule base includes the correspondence between known attack characteristics and risk levels of different threat events, and is regularly updated by the probe module 20 from the security management platform 1. Among them, the probe module 20 matches and analyzes the known attack characteristics of different threat events in the rule base with the network traffic characteristics based on the rule base that is regularly updated from the security management platform 1. When the network traffic characteristics match the known attack characteristics, it indicates that there is a threat event in the network traffic and the threat event can be determined based on the matched known attack characteristics, and then the risk level corresponding to the matched known attack characteristics is determined as the risk level corresponding to the threat event in the network traffic. It should be noted that the threat events detected by the probe module 20 can be regarded as preliminary or suspected threat events. Risk levels are used to characterize the risk of threat events, and can range from low, medium, and high. For example, low-level threat events might include frequent port scans and non-sensitive directory detection, medium-level threat events might include unauthorized login attempts and abnormal protocol requests, and high-level threat events might include SQL injection, remote code execution, and sensitive data leakage. Here, the probe module 20 can detect whether there are threat events in the network traffic by matching network traffic characteristics (such as message content, frequency, source IP address, etc.) with a rule base. If a threat event exists, it can also determine the corresponding risk level.
[0051] The preset duration can be set based on actual needs, such as 1 minute or 2 minutes. The preset risk level and the preset number threshold can be combined based on actual needs, such as 5 low-level threat events, 2 medium-level threat events, or 1 high-level threat event. If the number of threat events of the preset risk level detected within the preset duration is greater than or equal to the preset number threshold, the probe module 20 will record the attack traffic in the network traffic. This allows for dynamic adjustment of the response strategy based on the severity of the attack, while avoiding resource waste (such as over-responding to occasional low-level threat events) and ensuring rapid interception of high-risk attacks. Furthermore, by only initiating attack traffic recording and forwarding when threat events reach the corresponding threshold, it effectively avoids excessive consumption of the protected computing device's performance (such as CPU, memory, and storage) by continuously capturing all traffic. Furthermore, the probe module 20 forwards the attack traffic to the protocol emulation module 10, which simulates real-world protocols and scenarios (such as HTTP and FTP). This allows the attack traffic to be directed to the simulated environment, misleading the attacker into believing a successful intrusion, thereby exposing more attack vectors (such as malicious payloads and C2 server addresses). It should be noted that attack traffic is the basic data for threat event detection, and threat event information is the analysis and judgment results of attack traffic, which may include attack traffic.
[0052] The protocol emulation module 10 acts as an isolated containerized environment, strictly isolated from other components of the protected computing device 2 through container technology. This ensures both efficient processing of attack traffic and the security of the protected computing device 2 through containerized isolation. The protocol emulation module 10 can run directly on the protected computing device 2 in containerized form (e.g., via Docker or Kubernetes), sharing the operating system kernel with the protected computing device 2 while achieving resource isolation through namespaces and control groups. A container is a lightweight process isolated within the protected computing device 2. In this embodiment, by deploying the protocol emulation module 10 and the probe module 20 within the protected computing device 2, the probe module 20 can quickly forward attack traffic to the protocol emulation module 10, reducing network latency. Furthermore, container isolation is sufficient to prevent most attacks from escaping (e.g., without kernel vulnerabilities) and allows efficient communication between the protocol emulation module 10 and the probe module 20. In practical applications, the probe module 20 can direct attack traffic to the listening port of the protocol emulation module 10 via a local loopback interface or a virtual network. The protocol emulation module 10 can then communicate with the security management platform 1 via the network interface of the protected computing device 2.
[0053] After receiving the initially identified attack traffic (such as abnormal protocol requests, malicious payloads, etc.) sent by the probe module 20, the protocol simulation module 10 will allocate the attack traffic to the target simulation container corresponding to the attack traffic for protocol simulation and analysis, and report the obtained analysis results to the security management platform. In one embodiment, the protocol simulation module 10 is configured to: determine the target simulation container based on the protocol type of the attack traffic; allocate the attack traffic to the target simulation container so that the target simulation container simulates a real network service to respond to the attack request and records the attack log and attack behavior; generate analysis results based on the recorded attack log and attack behavior, and report the analysis results to the security management platform. The protocol type of the attack traffic is used to indicate the protocol used by the attack traffic, including HTTP, FTP, TCP / IP, etc. Based on container technology, the protocol simulation module 10 can construct at least one simulation container (also called a simulation environment, such as a simulated web server, database service, etc.) for each protocol type to ensure that the attack traffic runs in an isolated environment to avoid affecting the real system. Simultaneously, based on user-preset or dynamically delivered protocol configurations (e.g., response templates and timeout policies) from the security management platform 1, the behavior of the simulation container can be configured accordingly to enhance the effectiveness of the trap. For example, the protocol simulation module 10 can simulate a vulnerable HTTP server, returning deceptive responses to lure attackers deeper into the attack and expose more information.
[0054] After receiving attack traffic, the protocol emulation module 10 identifies the emulation container corresponding to the protocol type of the attack traffic as the target emulation container. The attack traffic is then assigned to the target emulation container, which then simulates a real network service responding to the attack request and records the attack log and attack behavior. This emulation container simulates a real network service responding to the attack request and records the attack log and attack behavior. This process may include the following: 1) emulating real protocol interactions: This involves the emulation container generating protocol-compliant responses based on the configured protocol (e.g., HTTP, FTP, TCP / IP). For example, this may include returning a fake webpage or API response to HTTP requests, providing a virtual file directory for FTP connection requests, or returning a disguised authentication interface for SSH login attempts. 2) Attack behavior capture and recording: This involves parsing traffic to record attack frequency, source IP addresses, tool fingerprints (e.g., Nmap scan signatures), and attack chain steps. 3) Threat capture and behavior induction: This involves using honeypot logic to expose "vulnerabilities" or "sensitive interfaces" through emulated services, inducing attackers to perform further actions (e.g., attempting to escalate privileges or download malicious files) to capture the complete attack chain. For example, anonymous write permissions are granted in the simulated FTP service to trick attackers into uploading backdoor programs and record their actions. 4) Full traffic logging, including the storage of raw traffic data and attack logs for subsequent forensic analysis and in-depth analysis, rule matching, which compares attack behavior with a built-in threat intelligence library (such as CVE vulnerability exploitation signatures and malicious IP databases) to determine the attack type (e.g., vulnerability exploitation, brute force attack), and dynamic scoring, which calculates the threat level (e.g., low, medium, high) based on attack severity, scope, and resource usage. The protocol simulation module 10 generates analysis results (which may include attack type, source IP address, and attack chain details) based on the recorded attack logs and attack behavior, and reports these results in real time to the security management platform 1, where visual reports (e.g., charts and timelines) are generated. In this way, through containerized isolation and deep protocol simulation, the protocol simulation module 10 transforms attack traffic into actionable threat intelligence, while ensuring that attacker activities are confined to the simulated environment, preventing damage to real systems and accurately monitoring network attacks.
[0055] Among them, the security management platform 1 is responsible for the centralized management and scheduling of the protocol simulation module 10 and the probe module 20, including: deployment of the probe module 20, status monitoring (such as online status, data collection frequency) and remote start and stop operations, to ensure that the probe module 20 collects network traffic in real time and forwards attack traffic; dynamically configures the simulation container of the protocol simulation module 10 (such as creation, deletion, start and stop), monitors the running status of the container, and supports the distribution and update of the protocol configuration (such as adding new protocol packages, etc.); and binds the probe module 20 and the protocol simulation module 10 to ensure that the attack traffic is accurately routed to the simulation environment, and refreshes the traffic forwarding strategy according to the rule base.
[0056] In one embodiment, the security management platform 1 is configured as follows:
[0057] Performing aggregation and filtering analysis on the threat event information reported by the probe module 20 and the analysis results reported by the protocol simulation module 10 to obtain an aggregated threat event record; the aggregated threat event record includes at least one threat event and a corresponding risk level;
[0058] According to the formula Calculate the risk value of protected computing device 2 ; Preset adjustment coefficient, For the The risk level of each threat event, For the The risk level of each threat event corresponds to the preset risk coefficient. is the total number of aggregated threat events.
[0059] The analysis results may include attack traffic details (such as attack type, protocol type, attack source IP, attack payload) and attack behavior records (such as brute force cracking, SQL injection, protocol vulnerability exploitation, etc.). Based on the threat event information reported by the probe module 20 and the analysis results reported by the protocol simulation module 10, the security management platform 1 can perform aggregated filtering analysis based on fields such as timestamp, host IP, and attack characteristics. For example, it can merge events with the same attack source and the same attack method (such as multiple SSH brute force attempts by the same IP in a short period of time) to obtain aggregated threat event records. The aggregated threat event records include at least one threat event and the corresponding risk level.
[0060] Among them, each threat event can be assigned the following attributes according to its degree of danger: (1) Risk level ( ), including low risk (S=1): such as port scanning, low-frequency detection; medium risk (S=2): such as high-frequency requests, failed login attempts; high risk (S=3): such as SQL injection, malicious file upload, 0day vulnerability exploitation. (2) Risk factor ( ): Dynamically adjust according to the scope of attack impact (for example, L=3 for attacks on core business systems, L=1 for attacks on test environments). K It is a preset adjustment factor used to weight the impact of different threats.
[0061] Among them, after determining the risk value of the protected computing device, the security management platform 1 can compare the risk value of the protected computing device with the preset risk threshold. If the risk value is greater than or equal to the preset risk threshold, it means that the protected computing device 2 is under network attack and there is a large security risk, then the alarm processing is triggered, so that the security management platform 1 automatically performs security protection operations on the protected computing device 2. For example, taking the HTTP penetration attack scenario as an example, the probe module 20 detects SQL injection traffic through rule base matching and forwards the attack traffic to the protocol simulation module 10; the protocol simulation module 10 identifies it as the HTTP protocol and assigns it to the simulation container corresponding to the Web server, so that the simulation container simulates the database response, records the injection statement and generates an attacker IP portrait, and pushes the obtained analysis results to the security management platform 1; the security management platform 1 automatically blocks the attack IP and updates the WAF rules. For example, taking the SSH brute force cracking scenario as an example, the probe module 20 discovers high-frequency SSH connections through the anomaly detection algorithm and forwards the attack traffic to the protocol simulation module 10; the protocol simulation module 10 distributes the attack traffic to the SSH simulation container to simulate the Linux system login process. The simulation container records the attacker's password dictionary and source IP, and pushes the obtained brute force cracking analysis results to the security management platform 1; the security management platform 1 generates a brute force cracking alarm, and links the firewall to block the IP, and marks it as a high-risk threat source.
[0062] Furthermore, based on security protection requirements, the security management platform 1 can send a protocol simulation list to the protocol simulation module 10. This list includes the protocol configurations or rules to be simulated, allowing the protocol simulation module 10 to know which protocols to simulate and how to configure these simulation environments, thereby more effectively luring attackers. For example, if the security management platform 1 detects a new attack targeting a specific protocol (such as HTTP), the security management platform 1 may update the protocol simulation list, instructing the protocol simulation module 10 to add or adjust the corresponding HTTP simulation environment to better capture this attack. Furthermore, the protocol simulation list may include specific parameter settings, such as response templates, timeouts, and vulnerability simulation methods. These configurations help the protocol simulation module 10 simulate network services more realistically, increase interaction with attackers, and thus collect more attack information. Furthermore, the dynamic distribution of the protocol simulation list can also increase system flexibility and scalability. Because the system needs to adapt to the ever-changing security environment, the security management platform 1 can update the configuration of the protocol simulation module 10 in real time based on the latest threat intelligence or policy adjustments, ensuring that defense measures remain up-to-date.
[0063] In summary, the container-based security protection system provided by the above embodiment, through the close cooperation of the security management platform and the protocol simulation module and probe module deployed in the protected computing device, can achieve effective monitoring of device network attacks based on container technology, provide comprehensive protection for network security, and improve the security and reliability of the device. In addition, the security management platform can flexibly configure the protocol simulation module and probe module based on security protection requirements to adapt to the ever-changing security environment and provide users with continuous security protection.
[0064] In one embodiment, the probe module 20 is further configured to:
[0065] According to the formula Calculate the anomaly score of network traffic , Indicates the currently observed network traffic value. Indicates the average value of normal traffic, Indicates the standard deviation of normal flow;
[0066] If the abnormal score value If the score is greater than or equal to the preset anomaly score threshold, a full traffic capture strategy is adopted to record all network traffic and forward all network traffic to the protocol simulation module 10.
[0067] The preset anomaly score threshold can be set based on actual needs, for example, to 3 or 4. If the anomaly score is greater than or equal to the preset anomaly score threshold, it may indicate that the attacker is using covert or distributed attack methods to attack the protected computing device 2. In this case, a full-flow capture strategy can be implemented to record all network traffic and forward all network traffic to the protocol emulation module 10. It can be understood that capturing and recording all network traffic (including normal and abnormal traffic) ensures that attackers cannot evade detection through traffic disguise or dispersed attacks. Furthermore, advanced persistent threats (APTs) or zero-day attacks often lack obvious signatures, necessitating full-flow data to fully reconstruct the attack. For example, if an attacker splits a malicious payload into multiple packets, capturing only a portion of the traffic may result in missed detection. However, full-flow records can reconstruct the complete attack chain. Furthermore, full-flow data provides raw input for the protocol emulation module 10, enabling in-depth analysis of attack techniques, payloads, and attack paths. This means that the protocol emulation module 10 can simulate real-world protocol scenarios based on full-flow data and accurately analyze attack behaviors (such as SQL injection and vulnerability exploitation). For example, the protocol emulation module 10 can capture encrypted malicious traffic mixed in the HTTP protocol, and the full traffic record can help analyze the attack payload after decryption.
[0068] In one embodiment, the probe module 20 is further configured to:
[0069] Send a configuration information pull request to security management platform 1;
[0070] If the configuration information fails to be pulled, the cumulative number of failures , according to the formula Calculate the new pull interval , and resend the configuration information pull request to the security management platform after the pull time interval; Indicates the initial pull time interval, is the preset increment coefficient, Indicates the reset cycle of the number of failures. When the number of failures reaches After that, the pull interval is reset to .
[0071] Among them, the probe module 20 can periodically pull configuration information such as the rule base, the trigger conditions of the full-flow capture strategy, etc. from the security management platform 1 to ensure the real-time and timely security protection. Specifically, the probe module 20 sends a configuration information pull request to the security management platform 1 to request the pull of configuration information. If the configuration information pull fails, such as no configuration information is pulled or the pull result is empty, the cumulative number of failures is counted. , and then calculate the new pull time interval according to the formula , and at the pull time interval Then resend the configuration information pull request to the security management platform 1. After that, the pull interval is reset to , that is, the cumulative number of failures for When the probe module 20 is at time interval Then resend the configuration information pull request to security management platform 1. To preset the increment coefficient, it can be set to 2, etc.
[0072] In one embodiment, the probe module 20 is further configured to: obtain operating indicators of the protected computing device 2 and report the operating indicators to the security management platform 1; the operating indicators include CPU usage, memory usage, and disk usage;
[0073] The security management platform 1 is also configured to Computing resource consumption index , and output an abnormal alarm message when the resource consumption index exceeds the preset resource consumption threshold and / or the CPU occupancy exceeds the preset occupancy threshold.
[0074] The probe module 20 can obtain the operating indicators of the protected computing device 2 in real time, irregularly or periodically, and report the obtained operating indicators of the protected computing device 2 to the security management platform 1 in real time. After receiving the operating indicators of the protected computing device 2 reported by the probe module 20, the security management platform 1 can calculate the operating indicators of the protected computing device 2 according to the formula Computing resource consumption index , resource consumption index This function is used to characterize the resource consumption of protected computing device 2 and output an abnormality warning message when the resource consumption index exceeds a preset resource consumption threshold and / or the CPU occupancy exceeds a preset occupancy threshold. The preset resource consumption threshold can be set as needed, for example, to 80%. The preset occupancy threshold can also be set as needed, for example, to 85%.
[0075] See Figure 2 , a container-based security protection method provided in an embodiment of the present application, is applied to a protected computing device, in which a protocol emulation module and a probe module are deployed. The container-based security protection method provided in this embodiment includes:
[0076] Step S101: Monitor the network traffic of the protected computing device in real time through the probe module. If the number of threat events of a preset risk level detected within a preset time period is greater than or equal to a preset number threshold, record the attack traffic in the network traffic and forward the attack traffic to the protocol simulation module, and report the threat event information to the security management platform.
[0077] Step S102: The attack traffic is distributed to the target simulation container built based on container technology through the protocol simulation module for protocol simulation and analysis, and the obtained analysis results are reported to the security management platform.
[0078] In one embodiment, the real-time monitoring of network traffic of the protected computing device by the probe module includes:
[0079] The probe module matches and analyzes network traffic characteristics based on a dynamically updated rule base to determine the risk level corresponding to threat events in the network traffic. The rule base includes the correspondence between known attack characteristics and risk levels of different threat events, and the probe module regularly pulls updates from the security management platform.
[0080] In one embodiment, step S102 includes:
[0081] The protocol simulation module determines the target simulation container based on the protocol type of the attack traffic; the attack traffic is distributed to the target simulation container so that the target simulation container simulates the real network service response to the attack request and records the attack logs and attack behavior; the analysis results are generated based on the recorded attack logs and attack behavior, and the analysis results are reported to the security management platform.
[0082] In one embodiment, the method further comprises:
[0083] Through the probe module according to the formula Calculate the anomaly score of network traffic , Indicates the currently observed network traffic value. Indicates the average value of normal traffic, Indicates the standard deviation of normal flow;
[0084] If the abnormal score value If the score is greater than or equal to the preset anomaly score threshold, a full-flow capture strategy is adopted to record all network traffic and forward all network traffic to the protocol simulation module.
[0085] In one embodiment, the method further comprises:
[0086] Send a configuration information pull request to the security management platform through the probe module;
[0087] If the configuration information fails to be pulled, the cumulative number of failures , according to the formula Calculate the new pull interval , and resend the configuration information pull request to the security management platform after the pull time interval; Indicates the initial pull time interval, is the preset increment coefficient, Indicates the reset cycle of the number of failures. When the number of failures reaches After that, the pull interval is reset to .
[0088] In one embodiment, the method further comprises:
[0089] The probe module obtains the operating indicators of the protected computing device and reports them to the security management platform; the operating indicators include CPU usage, memory usage, and disk usage.
[0090] It should be noted that the specific implementation process of the above-mentioned security protection method based on container technology can refer to the description of the security protection system based on container technology in the above-mentioned embodiment, which will not be repeated here.
[0091] In summary, the container-based security protection method provided in the above embodiment, through the close cooperation of the security management platform and the protocol simulation module and probe module deployed in the protected computing device, can achieve effective monitoring of device network attacks based on container technology, provide comprehensive protection for network security, and improve the security and reliability of the device. In addition, the security management platform can flexibly configure the protocol simulation module and probe module based on security protection requirements to adapt to the ever-changing security environment and provide users with continuous security protection.
[0092] See Figure 3 , a container-based security protection method provided in an embodiment of the present application, applied to a security management platform, includes:
[0093] Step S201: Obtain the threat event information reported by the probe module deployed on the protected computing device and the analysis results reported by the protocol simulation module; wherein, the threat event information is generated by the probe module monitoring the network traffic of the protected computing device, and the analysis results are generated by the protocol simulation module through the simulation container to simulate and analyze the attack traffic protocol.
[0094] Step S202: performing aggregate analysis on the threat event information and the analysis results to determine the risk value of the protected computing device.
[0095] Step S203: If the risk value is greater than or equal to the preset risk threshold, an alarm process is triggered.
[0096] In one embodiment, step S202 includes:
[0097] Performing aggregation and filtering analysis on the threat event information reported by the probe module and the analysis results reported by the protocol simulation module to obtain an aggregated threat event record; the aggregated threat event record includes at least one threat event and a corresponding risk level;
[0098] According to the formula Calculate the risk value of the protected computing device ; is the preset adjustment coefficient, For the The risk level of each threat event, For the The risk level of each threat event corresponds to the preset risk coefficient. is the total number of aggregated threat events.
[0099] In one embodiment, the method further comprises:
[0100] Receives operating indicators reported by the probe module; operating indicators include CPU usage, memory usage, and disk usage;
[0101] According to the resource consumption formula Computing resource consumption index , and in the resource consumption index When the resource consumption exceeds the preset threshold and / or the CPU usage exceeds the preset threshold, an abnormal alarm message is output.
[0102] It should be noted that the specific implementation process of the above-mentioned security protection method based on container technology can refer to the description of the security protection system based on container technology in the above-mentioned embodiment, which will not be repeated here.
[0103] In summary, the container-based security protection method provided in the above embodiment, through the close cooperation of the security management platform and the protocol simulation module and probe module deployed in the protected computing device, can achieve effective monitoring of device network attacks based on container technology, provide comprehensive protection for network security, and improve the security and reliability of the device. In addition, the security management platform can flexibly configure the protocol simulation module and probe module based on security protection requirements to adapt to the ever-changing security environment and provide users with continuous security protection.
[0104] Based on the same inventive concept as the above embodiments, an embodiment of the present invention provides a computing device, such as Figure 4 As shown, the computing device includes: a processor 310 and a memory 311 storing a computer program; wherein, Figure 4 The processor 310 shown in the figure is not used to indicate that the number of processors 310 is one, but is only used to indicate the positional relationship of the processor 310 relative to other devices. In actual applications, the number of processors 310 may be one or more; similarly, Figure 4 The memory 311 shown in the figure has the same meaning, that is, it is only used to refer to the positional relationship of the memory 311 relative to other devices. In actual applications, the number of memories 311 can be one or more. When the processor 310 runs the computer program, the above-mentioned security protection method based on container technology is implemented.
[0105] The computing device may also include: at least one network interface 312. The various components in the computing device are coupled together via a bus system 313. It is understood that the bus system 313 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 313 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Figure 4 Various buses are labeled as bus system 313.
[0106] Memory 311 may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may include read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disk, or compact disc read-only memory (CD-ROM); magnetic surface memory may include magnetic disk or tape memory. Volatile memory may include random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory 311 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memories.
[0107] The memory 311 in this embodiment of the present invention is used to store various types of data to support the operation of the computing device. Examples of this data include: any computer programs used to operate on the computing device, such as the operating system and application programs; contact data; phone book data; messages; images; videos, etc. The operating system includes various system programs, such as the framework layer, core library layer, and driver layer, which are used to implement various basic services and handle hardware-based tasks. Application programs may include various application programs, such as media players and browsers, which are used to implement various application services. Here, the program implementing the method of the embodiment of the present invention may be included in the application program.
[0108] Based on the same inventive concept as the above-mentioned embodiment, this embodiment further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program. The computer-readable storage medium may be a magnetic random access memory (FRAM), a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, a magnetic surface memory, an optical disc, or a read-only optical disc (CD-ROM) or other memory; or it may be various devices including one or any combination of the above-mentioned memories, such as a mobile phone, a computer, a tablet device, a personal digital assistant, etc. When the computer program stored in the computer-readable storage medium is executed by the processor, the above-mentioned security protection method based on container technology is implemented. For the specific steps implemented when the computer program is executed by the processor, please refer to Figure 2 or Figure 3 The description of the illustrated embodiment will not be repeated here.
[0109] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0110] As used herein, the terms "comprises," "comprising," or any other variation thereof, are intended to cover a non-exclusive inclusion of elements other than the listed elements and may also include additional elements not specifically listed.
[0111] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A security protection system based on container technology, characterized in that: include: Security management platform and protocol simulation module and probe module deployed in protected computing devices; among them, The probe module is configured to monitor the network traffic of the protected computing device in real time. If the number of threat events with a preset risk level detected within a preset time period is greater than or equal to a preset number threshold, the probe module records the attack traffic in the network traffic and forwards the attack traffic to the protocol simulation module, and reports the threat event information to the security management platform. A protocol simulation module, including multiple simulation containers built based on container technology, is configured to determine a target simulation container based on the protocol type of the attack traffic, distribute the attack traffic to the target simulation container for protocol simulation and analysis, so that the target simulation container simulates a real network service response to the attack request, records the attack log and attack behavior, generates analysis results based on the recorded attack log and attack behavior, and reports the obtained analysis results to the security management platform; The security management platform is configured to aggregate and filter the reported threat event information and analysis results to obtain an aggregated threat event record, which includes at least one threat event and a corresponding risk level; according to the formula Calculate the risk value R of the protected computing device and trigger an alarm when the risk value is greater than or equal to the preset risk threshold. K is the preset adjustment coefficient, S i is the risk level of the ith threat event, L i is the preset risk coefficient corresponding to the risk level of the i-th threat event, and n is the total number of threat events after aggregation.
2. The system according to claim 1, wherein: The probe module is configured as follows: Based on a dynamically updated rule base, network traffic characteristics are matched and analyzed to determine the risk level corresponding to threat events in the network traffic. The rule base includes the correspondence between known attack characteristics and risk levels of different threat events, and is regularly updated by the probe module from the security management platform.
3. The system according to claim 1, wherein: The probe module is also configured to: According to the formula Calculate the abnormal score value Z of network traffic, where X represents the currently observed network traffic value, μ represents the average value of normal traffic, and σ represents the standard deviation of normal traffic; If the anomaly score value Z is greater than or equal to the preset anomaly score threshold, a full traffic capture strategy is adopted to record all network traffic and forward all network traffic to the protocol simulation module.
4. The system according to claim 2, wherein: The probe module is also configured to: Send a configuration information pull request to the security management platform; If the configuration information fails to be pulled, then according to the cumulative number of failures m, according to the formula T m =T0×D mmodM Calculate the new pull time interval T m , and resend the configuration information pull request to the security management platform after the pull time interval; where T0 represents the initial pull time interval, D is the preset increment coefficient, and M represents the reset cycle of the number of failures. When the number of failures reaches M times, the pull time interval is reset to T0.
5. The system according to claim 1, wherein: The probe module is also configured to obtain operating indicators of the protected computing device and report the operating indicators to the security management platform; the operating indicators include CPU usage, memory usage, and disk usage; The security management platform is also configured to Calculate the resource consumption index RCI and output an abnormal alarm message when the resource consumption index RCI exceeds a preset resource consumption threshold and / or the CPU occupancy exceeds a preset occupancy threshold.
6. A security protection method based on container technology, characterized in that: Applied to a protected computing device, in which a protocol simulation module and a probe module are deployed, the method includes: The probe module monitors the network traffic of the protected computing device in real time. If the number of threat events with a preset risk level detected within a preset time period is greater than or equal to the preset number threshold, the attack traffic in the network traffic is recorded and forwarded to the protocol simulation module, and the threat event information is reported to the security management platform; The protocol simulation module determines the target simulation container according to the protocol type of the attack traffic, and distributes the attack traffic to the target simulation container built based on the container technology for protocol simulation and analysis, so that the target simulation container simulates the real network service response to the attack request, records the attack log and attack behavior, generates analysis results based on the recorded attack log and attack behavior, and reports the obtained analysis results to the security management platform so that the security management platform can aggregate and filter the reported threat event information and analysis results to obtain the aggregated threat event record, which includes at least one threat event and the corresponding risk level, as well as the risk level according to the formula Calculate the risk value R of the protected computing device and trigger an alarm when the risk value is greater than or equal to the preset risk threshold. K is the preset adjustment coefficient, S i is the risk level of the ith threat event, L i is the preset risk coefficient corresponding to the risk level of the i-th threat event, and n is the total number of threat events after aggregation.
7. A security protection method based on container technology, characterized in that: Applied to a security management platform, the method includes: Acquire the threat event information reported by the probe module deployed on the protected computing device and the analysis results reported by the protocol simulation module; wherein, the threat event information is generated by the probe module monitoring the network traffic of the protected computing device, and if the number of threat events of a preset risk level detected within a preset time period is greater than or equal to a preset number threshold, then the attack traffic in the network traffic is recorded and the attack traffic is forwarded to the protocol simulation module for reporting, and the analysis results are generated by the protocol simulation module according to the protocol type of the attack traffic, and the attack traffic is allocated to the target simulation container for protocol simulation and analysis, so that the target simulation container simulates the real network service response to the attack request, records the attack log and attack behavior, and is generated based on the recorded attack log and attack behavior; Perform aggregation and filtering analysis on threat event information and analysis results to obtain aggregated threat event records, which include at least one threat event and the corresponding risk level, as well as the risk level according to the formula Calculate the risk value R of the protected computing equipment; K is the preset adjustment coefficient, S i is the risk level of the ith threat event, L i is the preset risk coefficient corresponding to the risk level of the i-th threat event, and n is the total number of threat events after aggregation; If the risk value is greater than or equal to the preset risk threshold, an alarm is triggered.
8. A computer-readable storage medium, characterized in that A computer program is stored, and when the computer program is executed by a processor, the security protection method based on container technology described in claim 6 or 7 is implemented.
Citation Information
Patent Citations
Automatic defense method based on abnormal behaviors
CN116781412A
Industrial network threat trapping system for electric power industrial scene
CN117857086A
Security protection system for cloud side end collaborative interaction of power distribution Internet of Things
CN119402235A