A cloud resource pool security management system and method for network security
By identifying the load status differences and security risk associations between sub-pools of the cloud resource pool, generating and evaluating alternative switching paths, the problem of operational instability of the cloud resource pool in a high-load, high-risk environment is solved, the coordination of load recovery and security incident termination is achieved, and the overall stability and security of the resource pool is improved.
Patent Information
- Application Number
- CN202510932868.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-07-08
AI Technical Summary
Existing cloud resource pool security management methods make it difficult to achieve load coordination and coordinated prevention and control of security risks across resource sub-pools, resulting in increased operational instability and security governance risks in resource pools under high-load, high-risk environments.
By analyzing the response delay data series and security event logs of resource sub-pools, identifying the correlation between load status differences and security risks, generating multiple alternative resource sub-pool switching paths, and evaluating their stability, the path with the highest stability score is selected for switching operations to achieve coordination between load recovery and security event termination.
It achieves refined monitoring and rapid and stable recovery of the resource pool load status under high load conditions, enhances security warning and protection capabilities, avoids the chain reaction of security incidents, and improves the overall operational stability and security reliability of the resource pool.
Smart Images

Figure CN120455462B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and in particular to a cloud resource pool security management system and method for network security. Background Art
[0002] With the widespread adoption of cloud computing, enterprises are gradually migrating their business systems to cloud resource pools to improve computing resource utilization and business processing capabilities. However, as the scale and complexity of cloud resource pools continue to grow, load imbalances can occur between different resource regions or sub-pools. This can significantly increase resource response latency instability, especially during peak business hours. This load fluctuation not only reduces business processing efficiency but can also severely degrade user experience.
[0003] At the same time, with the increasing sophistication and scale of cyberattacks, resource pool security management faces increasingly severe challenges. Attackers often exploit the uneven security measures across different regions or sub-pools within a resource pool to rapidly infiltrate through the propagation pathways of security incidents, thereby seriously threatening the security and stability of the entire resource pool. Especially when resource pools lack coordinated protection and proactive response mechanisms across regions or sub-pools, once a sub-pool is compromised, the risk to other sub-pools increases significantly, creating a chain reaction and bringing more widespread and serious security risks.
[0004] Currently, mainstream resource pool security management methods focus on the isolated protection of a single area or sub-pool, making it difficult to achieve load coordination and joint prevention and control of security risks across resource sub-pools. In addition, when scheduling and switching resources, they fail to fully consider the efficiency of load recovery and the timing of the effectiveness of security risk blocking measures. This leads to a lack of systematic and coordinated resource switching decisions, further exacerbating the operational instability and security governance risks of the resource pool.
[0005] Therefore, there is an urgent need to propose a more effective network security cloud resource pool security management method to take into account both load status and security risk factors, and improve the overall effectiveness of resource pool operation stability and security protection in high-load, high-risk environments. Summary of the Invention
[0006] The purpose of the present invention is to provide a cloud resource pool security management system and method for network security to solve the problems in the above-mentioned background technology.
[0007] In order to achieve the above object, the present invention provides the following technical solutions:
[0008] In a first aspect, the present invention provides a method for securely managing a cloud resource pool for network security, comprising:
[0009] Determine the load status difference and security risk association between any two resource sub-pools based on the response delay data sequence and security event log of the resource sub-pools;
[0010] Based on the determined load state differences and security risk associations, multiple candidate resource sub-pool switching paths are generated, and specific triggering conditions for each candidate resource sub-pool switching path are obtained;
[0011] Determine the load recovery characteristics and security event termination characteristics based on historical response delay recovery data and security event propagation termination data after resource subpool switching.
[0012] Based on the aforementioned load recovery characteristics and security event termination characteristics, evaluate the stability of the switching paths of each candidate resource subpool;
[0013] The path with the highest stability score is determined from all candidate resource sub-pool switching paths as the target switching path. When the current state of the resource sub-pool meets the specific triggering conditions of the target switching path, the resource sub-pool switching operation is executed.
[0014] In a second aspect, the present invention provides a network security cloud resource pool security management system, which is implemented by the above-mentioned network security cloud resource pool security management method, including:
[0015] An acquisition module is used to determine the load status difference and security risk association relationship between any two resource sub-pools based on the response delay data sequence and security event log of the resource sub-pools;
[0016] A generation module is used to generate multiple alternative resource sub-pool switching paths based on the determined load state difference and security risk association relationship, and obtain specific triggering conditions for each alternative resource sub-pool switching path;
[0017] a determination module, configured to determine load recovery characteristics and security event termination characteristics respectively based on historical response delay recovery data and security event propagation termination data after resource subpool switching;
[0018] An evaluation module, configured to evaluate the stability of the switching paths of each candidate resource sub-pool based on the load recovery characteristics and security event termination characteristics;
[0019] The management module is used to determine the path with the highest stability score from all candidate resource sub-pool switching paths as the target switching path, and execute the resource sub-pool switching operation when the current state of the resource sub-pool meets the specific triggering conditions of the target switching path.
[0020] In the above technical solution, the technical effects and advantages provided by the present invention are:
[0021] By analyzing the response delay data sequences of resource sub-pools, the present invention effectively identifies significant differences in the load status of resource sub-pools and promptly captures specific periods of frequent load fluctuations, thereby achieving refined monitoring and quantification of the load status of resource pools. This helps to quickly identify resource sub-pools with relatively stable performance under high-load conditions, providing efficient data support for load scheduling and resource allocation.
[0022] By further exploring the propagation patterns of security incidents among multiple resource sub-pools, we can accurately identify the propagation paths and security risk correlations of typical security incidents, thereby effectively predicting and identifying potential security threat propagation channels between resource pools in the early stages of an attack, significantly enhancing the overall security warning and protection capabilities of the resource pool, and effectively avoiding the chain reaction and large-scale propagation risks of security incidents.
[0023] In addition, by comprehensively evaluating the load recovery characteristics and security event termination characteristics of each alternative resource sub-pool switching path, the time coordination between path load recovery and the effectiveness of security protection measures and the security protection capabilities are determined, thereby realizing dynamic optimization and intelligent scheduling of switching paths, effectively ensuring that the resource pool's load performance recovers quickly and stably after executing the resource switching operation, and simultaneously achieving rapid and effective blocking of security incidents, thereby improving the overall operational stability and security reliability of the resource pool in complex environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments described in the present invention. For ordinary technicians in this field, other drawings can also be obtained based on these drawings.
[0025] Figure 1 This is a flow chart of a method for securely managing a cloud resource pool for network security according to the present invention;
[0026] Figure 2 This is a framework diagram of a cloud resource pool security management system for network security according to the present invention. DETAILED DESCRIPTION
[0027] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in a variety of forms and should not be construed as limited to the examples set forth herein; rather, these example embodiments are provided so that the description of this disclosure will be more comprehensive and complete, and will fully convey the concepts of the example embodiments to those skilled in the art. The accompanying drawings are merely schematic illustrations of the disclosure and are not necessarily drawn to scale. Identical reference numerals in the figures indicate identical or similar parts, and thus any repetitive description thereof will be omitted.
[0028] In addition, the described features, structures or characteristics can be combined in one or more example embodiments in any suitable manner. In the following description, many specific details are provided to provide a full understanding of the example embodiments disclosed in this application. However, those skilled in the art will appreciate that the technical solutions disclosed in this application can be practiced while omitting one or more of the specific details, or other methods, components, steps, etc. can be adopted. In other cases, well-known structures, methods, implementations or operations are not shown or described in detail to avoid obscuring the various aspects disclosed in this application.
[0029] Example 1
[0030] like Figure 1 As shown, this embodiment discloses a method for securely managing a cloud resource pool for network security, including:
[0031] S101: Determine the load status difference and security risk association relationship between any two resource sub-pools based on the response delay data sequence and security event log of the resource sub-pools;
[0032] In implementation, the method for determining the load state difference includes:
[0033] Calculate the delay difference between consecutive data points in the response delay data series during the peak service period of each resource subpool. When two or more consecutive delay differences change from positive to negative, or from negative to positive, the corresponding moment is determined as the turning point of the delay trend.
[0034] The response delay data series during the resource sub-pool business peak period consists of data points collected at fixed time intervals (for example, 1 minute), and the series format is:
[0035] ;
[0036] Where: Represents the response delay data sequence of resource subpool P during the business peak period, is the i-th sampling time point, The delay value corresponding to the time point;
[0037] The delay difference between adjacent data points is calculated as follows:
[0038] ;
[0039] For example, if the response delay data sequence is:
[0040] ;
[0041] The corresponding difference sequence is:
[0042] ;
[0043] According to the above trend turning point determination rules:
[0044] First, a negative value appears after two consecutive positive values (i.e., +4 → +6 → -3), and the time point of the third item in the sequence (value 110) is determined to be the turning point of the delayed upward trend;
[0045] Subsequently, a positive value appeared after two consecutive negative values (i.e., -3 → -4 → +5), and the time point of the fifth item in the sequence (value 103) was determined to be the turning point of the delayed downward trend;
[0046] By analogy, there was a continuous rise before the 7th item (value 113), so the time point corresponding to the 7th item is also a turning point;
[0047] Therefore, the turning point time points identified by the resource sub-pool are specifically the time points corresponding to items 3, 5, and 7;
[0048] Divide the response delay data series of the resource subpool into multiple sliding time windows of fixed length, count the number of delay trend turning points in each time window, and when the number of turning points in a time window exceeds the frequent turning threshold of the number of turning points in the same window length of historical data, determine the corresponding multiple turning points in the window as a combination of frequent continuous turning points;
[0049] Specifically, the response delay data sequence is divided into windows of length A set of sliding time windows (e.g. 5 minutes):
[0050] ;
[0051] For each time window , count the number of turning points contained in it, recorded as At the same time, the average number of turning points under the same window length is calculated in the historical data and standard deviation , and then set the frequent turning judgment threshold as:
[0052] ;
[0053] Wherein, λ is the empirical adjustment coefficient, which is determined based on experience or experimental data, for example, the value is 1.5;
[0054] If the current window The number of turning point time points meets , then the window is considered to belong to the area of rapid response delay fluctuation, and all the turning time points marked in the window together constitute a combination of frequent and continuous turning time points;
[0055] For example, if the average number of turning points in the 5-minute time window in historical statistics is , the standard deviation is , if λ=1.5, the frequent turning threshold is:
[0056] ;
[0057] If the time window of a resource sub-pool is within the current business peak period If the number of turning point time points recorded is 5, then: , so the window The corresponding multiple turning time points are a combination of frequent and continuous turning time points;
[0058] Based on the response delay data series for the period corresponding to each combination of frequent and continuous turning point time points, the difference between the maximum and minimum delay values within the combination is calculated as the stability change amplitude corresponding to the frequent and continuous turning point time point combination. The average stability change amplitude of all frequent and continuous turning point time point combinations is further calculated and determined as a quantitative indicator of the resource subpool load status difference.
[0059] Specifically, for a certain combination of frequent continuous turning point time points, the delayed data sequence in the corresponding period is recorded as:
[0060] ;
[0061] The stability variation range is defined as:
[0062] ;
[0063] If there are multiple frequent continuous turning combinations , then calculate its average stability change range, which is recorded as:
[0064] ;
[0065] For example, two frequent transition combinations are identified in a resource subpool, with delay data of [120, 126, 123, 121] and [135, 140, 138, 133] respectively. Then:
[0066] The first combination fluctuation amplitude A_1=126-120=6ms;
[0067] The second combination has an amplitude of A_2 = 140-133 = 7ms;
[0068] The average stability change amplitude is A_avg=(6+7) / 2=6.5ms;
[0069] In implementation, the method for determining the security risk association relationship includes:
[0070] From the resource sub-pool security event logs, extract the time when each type of security event first occurs in each resource sub-pool during a given business peak period, and sort the first occurrence time of each resource sub-pool in ascending order to form a security event propagation sequence;
[0071] Security events refer to information security-related incidents such as suspicious access, abnormal traffic, and intrusion behaviors that occur during the operation of a resource subpool. These security events are generated from logs of system modules such as WAF, IDS, and HIDS. The structure of the security event log includes fields such as event type, occurrence timestamp, resource subpool ID, attack source IP address, and event interception status.
[0072] For example, the first triggering time of a certain type of security event in each resource sub-pool during the business peak period is:
[0073] ;
[0074] The security event propagation sequence is: ;
[0075] From the propagation sequence of the same type of security incidents in multiple business cycles, determine the propagation sequence of security incidents that occur repeatedly and with a frequency higher than a preset threshold, and identify it as a typical security incident propagation path;
[0076] It should be noted that over multiple business cycles (e.g., the past 7 days), for the same security incident type, the system counts the frequency of occurrence of security incident propagation sequences and identifies the propagation subsequences with higher frequency as typical security incident propagation paths;
[0077] Specifically, the system first constructs a set of propagation sequences, which can be expressed as:
[0078] ;
[0079] Then, a sequential pattern mining algorithm (such as the PrefixSpan algorithm) is used to extract the occurrence frequencies higher than the preset threshold from the above set. The propagation subsequence of the typical security incident propagation path set is determined as follows:
[0080] ;
[0081] For each resource sub-pool in a typical security incident propagation path, the ratio of the number of security incidents effectively blocked to the total number of security incidents is calculated to determine the effectiveness ratio of the protection measures in each resource sub-pool. The variation in the effectiveness ratio of protection measures between adjacent resource sub-pools along the typical security incident propagation path is further calculated.
[0082] It should be noted that if a resource subpool has security policies, throttling rules, or intrusion detection rules deployed, and successfully blocks the further propagation of a security incident during its propagation, the system considers it as "effective protection";
[0083] Specifically, for resource subpools , if it is in the typical security incident propagation path The CCP emerged , where the number of successful interception events is times, then the protection effectiveness ratio of the resource sub-pool is defined as:
[0084] ;
[0085] Furthermore, for two adjacent resource sub-pools that appear consecutively in a typical security event propagation path, , the change range of the effectiveness ratio of protective measures is defined as:
[0086] ;
[0087] For adjacent resource sub-pools along a typical security incident propagation path, if the change in the effectiveness ratio of their protective measures exceeds a preset security risk association threshold, a security risk association relationship is determined to exist between the adjacent resource sub-pools.
[0088] Specifically, the system sets the security risk association threshold in advance as , if the protection effectiveness variation between adjacent resource sub-pools on a path Requirements:
[0089]
[0090] The system determines the resource subpool There is a potential security risk transmission correlation between them, thus establishing a security risk correlation relationship between the two;
[0091] For example, if the security risk association threshold is set , and typical security incident propagation paths The change range of the effectiveness ratio between adjacent resource sub-pools is , the system will resource sub-pool Mark the resource sub-pool pairs with high risk of propagation for subsequent generation and optimization of switching strategies.
[0092] S102: Based on the determined load state difference and security risk association relationship, generate multiple candidate resource sub-pool switching paths, and obtain specific triggering conditions for each candidate resource sub-pool switching path;
[0093] In implementation, the method for generating multiple candidate resource sub-pool switching paths includes:
[0094] According to the load state difference indicator, if the load state difference between any two resource sub-pools exceeds a preset load difference threshold, the two resource sub-pools are determined as candidate resource sub-pool switching paths;
[0095] In the specific implementation, the system pre-sets the load difference threshold (for example, 8 milliseconds), which is recorded as ;
[0096] For any two resource subpools and , if the load state difference index calculated in step S101 is ) satisfy:
[0097] ;
[0098] Then the resource subpool as an alternative resource sub-pool switching path identified based on load differences;
[0099] According to the security risk association relationship, if a security risk association relationship exists between any two resource sub-pools, the two resource sub-pools are determined as candidate resource sub-pool switching paths;
[0100] In step S101, when two adjacent resource sub-pools Changes in the effectiveness ratio of safety protection measures between The following conditions are met:
[0101] ;
[0102] Then the resource subpool As an alternative resource sub-pool switching path identified based on security risk association;
[0103] Merging the alternative resource sub-pool switching paths determined based on load status differences and security risk associations to form multiple alternative resource sub-pool switching paths;
[0104] In the specific implementation, the system will merge all resource sub-pools determined based on load differences and security risk associations, remove duplicates, and obtain the final set of candidate resource sub-pool switching paths, which is recorded as:
[0105] ;
[0106] In implementation, the method for obtaining the specific triggering condition includes:
[0107] Extract the periods of abnormal response delays during peak business hours for each resource subpool, as well as the periods of high-frequency security incidents. Identify the overlapping parts of these periods as high-risk overlapping periods.
[0108] Periods of abnormal response delays Defined as the period when the resource subpool response delay continuously exceeds the preset delay threshold (e.g. 100ms);
[0109] Periods when security incidents frequently occur It is defined as the period when the number of security events per unit time exceeds the preset high-frequency threshold (e.g. 5 times);
[0110] Take the intersection of the above two periods to obtain the high-risk overlapping period ;
[0111] For example, assuming that the average response delay value per minute of a resource subpool exceeds a preset delay threshold (e.g., 100 milliseconds) from 13:00 to 13:06 during the peak business period, the abnormal delay time interval of the resource subpool is specifically recorded as:
[0112] ;
[0113] At the same time, if SQL injection events that meet the preset high-frequency threshold condition (for example, 5 cumulative occurrences) are recorded between 13:03 and 13:08, the high-frequency occurrence time interval of the corresponding security event is specifically recorded as:
[0114] ;
[0115] Then, the system determines that the high-risk overlapping period of the resource subpool is the intersection of the above two periods, specifically:
[0116] ;
[0117] The duration of high-risk overlap periods that occurred during successful handover operations in the past is counted, and their mean and standard deviation are calculated. If the duration of the currently monitored high-risk overlap period exceeds the typical overlap pattern threshold of the weighted sum of the mean and standard deviation, it is determined to be a typical high-risk overlap period;
[0118] In the specific implementation, the duration of the high-risk overlapping period corresponding to all successful switching operations in history is counted and recorded as a set:
[0119] ;
[0120] The duration of the overlapping period corresponding to the i-th historical record is specifically defined as:
[0121] ;
[0122] On this basis, the system further calculates the average duration of the above historical overlapping periods and standard deviation , specifically defined as:
[0123] ;
[0124] Then, the system further sets the judgment threshold of typical overlapping patterns, which is specifically defined as:
[0125] ;
[0126] Among them, the parameter 𝜆 is the empirical adjustment factor. The specific value can be determined based on actual experimental data. It generally ranges from 1.0 to 1.5 and is used to adjust the system's sensitivity to the overlapping risk window.
[0127] In the actual business cycle, when the system monitors the duration of the overlapping period, it is specifically recorded as , and meet the conditions:
[0128] ;
[0129] This period is determined to be a typical high-risk overlapping period;
[0130] When the resource subpools involved in the candidate resource subpool switching path currently experience a typical high-risk overlapping period and any of the following conditions are met, the specific triggering conditions for the candidate resource subpool switching path are obtained:
[0131] The load status difference between the resource sub-pools corresponding to the paths exceeds the preset load difference threshold;
[0132] The security risk association relationship between the resource sub-pools corresponding to the path exceeds the preset security risk association threshold;
[0133] In a specific implementation, when the system detects that the source resource subpool involved in a candidate resource subpool switching path is currently in a typical high-risk overlap period, it further checks whether the candidate path meets any of the following trigger conditions:
[0134] Significant difference in load status: load status difference index ,or
[0135] Safety risk correlation is obvious: that is, the change in the effectiveness ratio of protective measures ;
[0136] When any of the above conditions is met, this condition is marked as a specific triggering condition for the switching path of the candidate resource sub-pool, and is used in the subsequent dynamic switching decision process.
[0137] S103: Determine load recovery characteristics and security event termination characteristics based on historical response delay recovery data and security event propagation termination data after resource subpool switching;
[0138] In implementation, the method for determining the load recovery characteristic includes:
[0139] Extracting a response delay recovery data sequence from the historical records after the resource subpool switch operation is completed; the response delay recovery data sequence starts at the time the resource subpool switch operation is completed and is collected at a fixed sampling interval until the response delay returns to a normal range or the first delay rebound occurs;
[0140] In the specific implementation, the response delay recovery data sequence is defined as the time from the switching completion moment to the resource sub-pool switching completion moment. Starting from the time when the delay is at its peak, delay data is collected at fixed sampling intervals (for example, every minute) to form a delay recovery sequence:
[0141] ;
[0142] The data sequence acquisition termination conditions are: the response delay returns to the normal range (for example, below 100 milliseconds); or the delay rebounds significantly for the first time (that is, the delay value rises significantly again after reaching the lowest point);
[0143] For example, the delayed recovery data sequence after a resource sub-pool switch is (unit: ms): ,Since the latency rebounded from the lowest point of 85ms to 90ms in the 4th minute, ,the collection was stopped;
[0144] Determine the time and delay value corresponding to the lowest point of the response delay based on the response delay recovery data sequence, detect the time when the delay first rebounds significantly from the lowest point, record the delay value corresponding to that time, and calculate the rebound amplitude of the first delay rebound relative to the lowest point and the duration of the delay rebound;
[0145] In the specific implementation, the minimum delay value of the response delay recovery data sequence is recorded as , and the corresponding time point is recorded as , then it is specifically defined as:
[0146] ;
[0147] Then, from the moment After that, the moment of the first obvious delayed rebound is determined to be , and record the delay value corresponding to this time point as ;
[0148] Further calculation:
[0149] Delayed rebound amplitude: ;
[0150] Delayed rebound duration: ;
[0151] For multiple historical switching records, the average delay rebound amplitude and delay rebound duration are calculated respectively to determine the load recovery characteristics of the resource subpool switching path;
[0152] In the specific implementation, the delay rebound amplitude is calculated for multiple historical resource sub-pool switching paths. and the duration of delayed rebound (where k represents the kth historical record), and further calculates the average value as the path load recovery feature:
[0153] Average latency bounce:
[0154] ;
[0155] Average delayed bounce duration:
[0156] ;
[0157] In implementation, the method for determining the termination characteristics of the security event includes:
[0158] Extract security incident propagation termination data from historical security incident propagation records;
[0159] The security event propagation termination data specifically includes the resource sub-pool node where the security event was last triggered during the propagation process, the time when the event was successfully blocked, the type of security protection measures taken during the blockage, and any records of the security event not continuing to propagate to other resource sub-pools after the event was blocked.
[0160] In specific implementation, the system extracts relevant data from the security event log for each security event that ultimately stopped propagating, forming a propagation termination data set. This data includes: the resource subpool node ID where the event terminated, the specific time the event was successfully blocked, the specific type of protection measure used when the event was blocked (for example, WAF throttling, intrusion detection blocking, dynamic blacklisting, etc.), and log records of the security event not continuing to propagate within a set period of time (for example, 30 minutes) after blocking, as evidence of successful blocking.
[0161] Based on the security incident propagation termination data, the number of times each resource sub-pool node ultimately blocked a security incident during the security incident propagation process is counted. The resource sub-pool whose final blocking number exceeds the set threshold is identified as a typical security incident termination node.
[0162] In the specific implementation, the system counts the number of times each resource sub-pool successfully blocks security incidents. ; Set the number of typical termination nodes threshold (For example, 10 times), the resource subpool that meets the following conditions is determined as the typical security incident termination node: ;
[0163] Collect statistics on the types of security protection measures used by typical security event termination nodes when blocking security events, and determine the security protection measures whose usage frequency exceeds the set threshold as typical security protection measures;
[0164] For typical security incident termination nodes, the system counts the number of times each type of security protection measure is used. Protection measures with a frequency exceeding a threshold (for example, the number of times used exceeds 60% of the total number of node blockages) are identified as typical security protection measures.
[0165] Calculate the time interval from the implementation to the effectiveness of a typical security protection measure type when a typical security incident termination node blocks the security incident. Further calculate the average effectiveness time interval of all typical security incident termination nodes to determine the average effectiveness time of the security protection measure.
[0166] In the specific implementation, when the system uses typical security protection measures in the process of historical security event propagation for typical security event termination nodes, it clearly records the time when each protection measure starts to be implemented (that is, the time when the protection measure is started or deployed, recorded as ) and the moment when the protective measures take effect (that is, the moment when the security incident is actually successfully blocked and does not spread again, recorded as ), and then calculate the effective time interval of each protective measure:
[0167] ;
[0168] Furthermore, for each node among all typical security event termination nodes, the system calculates the average time interval of effectiveness of all typical security protection measures recorded in its history:
[0169] For typical security incident termination nodes :
[0170] ;
[0171] in, For nodes The number of samples that used typical security protection measures to successfully block security incidents in history;
[0172] Then, the total average of the above-mentioned effective time intervals of all typical security event termination nodes is further calculated, that is, the average effective time of the security protection measures:
[0173] ;
[0174] Where M is the total number of nodes where typical security incidents terminate;
[0175] The termination nodes of typical security incidents, typical security protection measures types, and average effective time of security protection measures are collectively determined as the security incident termination features;
[0176] Typical security incident termination nodes: These nodes represent resource sub-pools that have demonstrated strong security incident propagation blocking capabilities and frequently successfully terminated security incident propagation during the historical security incident propagation process.
[0177] Typical security protection measure types: These represent specific protection measures that are commonly used and effective in blocking the spread of security incidents in resource sub-pools in actual business scenarios.
[0178] Average time it takes for security protection measures to take effect: This clearly quantifies the average time it takes for typical security protection measures to be deployed and actually successfully block the spread of security incidents, serving as a key indicator of the security protection measures' ability to take effect quickly.
[0179] S104: Evaluate the stability of the switching paths of each candidate resource sub-pool based on the load recovery characteristics and security event termination characteristics;
[0180] In implementation, the stability assessment method comprises:
[0181] For each candidate resource subpool switching path, extract the corresponding load recovery characteristics and security event termination characteristics from the historical records;
[0182] Based on the delay rebound duration in the load recovery feature and the average security protection measure effectiveness time in the security event termination feature, the absolute value of the difference between the two is calculated and determined as the time coordination indicator between load recovery and security event termination.
[0183] In the specific implementation, the system explicitly calculates the load recovery delay index in its historical records for each alternative resource sub-pool switching path (i.e., the duration of the delay rebound, recorded as ) and the security incident termination index (i.e., the average time for security protection measures to take effect, recorded as ), and then calculate the time coordination index between load recovery and security event termination:
[0184] ;
[0185] It should be noted that the time coordination index The smaller the value, the better the synchronization between load recovery and security event termination, and the higher the synergy between load recovery and security protection in the alternative resource subpool switching path.
[0186] Based on the delay rebound amplitude in the load recovery characteristics, the average delay rebound amplitude of all candidate resource subpool switching paths is calculated. For each candidate path, the deviation between its delay rebound amplitude and the average value is calculated as the load recovery stability indicator.
[0187] In the specific implementation, the system first counts the delay rebound amplitude of all candidate resource sub-pool switching paths in the historical records (denoted as ), and then calculate the overall average of these delay bounces:
[0188] ;
[0189] Where N is the total number of switching paths in the alternative resource sub-pool;
[0190] Furthermore, for each candidate path, the absolute deviation between its delay rebound amplitude and the average value is calculated as the load recovery stability indicator of the path:
[0191] ;
[0192] It should be clearly stated that the load recovery stability index The smaller it is, the closer the fluctuation amplitude of load recovery on this path is to the overall average level, and the higher the load recovery stability is.
[0193] For each candidate resource subpool, switch paths and determine the security incident termination capability of the path.
[0194] In specific implementation, the system further determines whether the target resource subpool of each alternative path meets the following two conditions:
[0195] Condition 1: The target resource subpool belongs to the typical security event termination node determined in step S103;
[0196] Condition 2: The security protection measures implemented by the target resource subpool clearly include typical security protection measures;
[0197] If both of the above conditions are met, the system will clearly mark the alternative path as having a high security incident termination capability; if either condition is not met, it will be marked as having a moderate security incident termination capability; if neither condition is met, it will be marked as having a low security incident termination capability.
[0198] The comprehensive stability score of each candidate resource subpool switching path is calculated based on the time coordination index between load recovery and security incident termination, the load recovery stability index, and the security incident termination capability. A higher comprehensive stability score indicates a more stable path.
[0199] In specific implementation, the system uses the following formula to explicitly calculate the comprehensive stability score of each candidate resource sub-pool switching path:
[0200] ;
[0201] in, It is the time coordination index. The smaller the index is, the higher the score is. It is the load recovery stability index, the smaller the index, the higher the score; Score the security incident termination capability, defined as:
[0202] If the security incident termination capability is high, then ;
[0203] If the security incident termination capability is average, then ;
[0204] If the security incident termination capability is low, ;
[0205] Parameters α, β, and γ are weight coefficients, which are determined by actual business importance and experience. For example: .
[0206] S105: Determine the path with the highest stability score from all candidate resource sub-pool switching paths as the target switching path, and execute the resource sub-pool switching operation when the current state of the resource sub-pool meets the specific triggering conditions of the target switching path;
[0207] For example, suppose the system calculates the comprehensive stability scores of the three candidate resource sub-pool switching paths as follows: The score is 0.87, the path The score is 0.79, the path The score is 0.75, then the path with the highest score is selected. Switch paths as the target.
[0208] Example 2
[0209] like Figure 2 As shown, the parts not described in detail in this embodiment are as shown in Example 1. This embodiment discloses a cloud resource pool security management system for network security, including:
[0210] Acquisition module 201, configured to determine a load status difference and a security risk association relationship between any two resource sub-pools based on the response delay data sequence and security event log of the resource sub-pools;
[0211] A generating module 202 is configured to generate a plurality of candidate resource sub-pool switching paths based on the determined load state difference and security risk association relationship, and obtain a specific triggering condition for each candidate resource sub-pool switching path;
[0212] A determination module 203 is configured to determine a load recovery feature and a security event termination feature respectively based on the response delay recovery data and the security event propagation termination data after the historical resource sub-pool switching;
[0213] Evaluation module 204, configured to evaluate the stability of the switching paths of each candidate resource sub-pool based on the load recovery characteristics and security event termination characteristics;
[0214] The management module 205 is configured to determine the path with the highest stability score from all candidate resource sub-pool switching paths as the target switching path, and execute the resource sub-pool switching operation when the current state of the resource sub-pool meets the specific triggering conditions of the target switching path.
[0215] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters, weights and thresholds in the formulas are set by technicians in this field according to actual conditions.
[0216] The above embodiments can be implemented in whole or in part via software, hardware, firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are fully or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, the computer instructions can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless network. The computer-readable storage medium can be any available medium accessible by a computer, or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, or magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0217] The above description is merely illustrative of certain exemplary embodiments of the present invention. It goes without saying that those skilled in the art will be able to modify the described embodiments in various ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the scope of protection of the claims.
Claims
1. A cloud resource pool security management method for network security, characterized by: Determine the load status difference and security risk association between any two resource sub-pools; The method for determining the load state difference includes: Calculate the delay difference between consecutive data points in the response delay data series during the peak service period of each resource subpool. When two or more consecutive delay differences change from positive to negative, or from negative to positive, the corresponding moment is determined as the turning point of the delay trend. Divide the response delay data series of the resource subpool into multiple sliding time windows of fixed length, count the number of delay trend turning points in each time window, and when the number of turning points in a time window exceeds the frequent turning threshold of the number of turning points in the same window length of historical data, determine the corresponding multiple turning points in the window as a combination of frequent continuous turning points; Based on the response delay data series for the period corresponding to each combination of frequent and continuous turning point time points, the difference between the maximum and minimum delay values within the combination is calculated as the stability change amplitude corresponding to the frequent and continuous turning point time point combination. The average stability change amplitude of all frequent and continuous turning point time point combinations is calculated and determined as a quantitative indicator of the resource subpool load status difference. The method for determining the security risk association relationship includes: From the resource sub-pool security event logs, extract the time when each type of security event first occurs in each resource sub-pool during a given business peak period, and sort the first occurrence time of each resource sub-pool in ascending order to form a security event propagation sequence; From the propagation sequence of the same type of security incidents in multiple business cycles, determine the propagation sequence of security incidents that occur repeatedly and with a frequency higher than a preset threshold, and identify it as a typical security incident propagation path; For each resource sub-pool in a typical security incident propagation path, calculate the ratio of the number of security incidents effectively blocked to the total number of security incidents, determine the effectiveness ratio of the protection measures in each resource sub-pool, and calculate the variation in the effectiveness ratio of the protection measures between adjacent resource sub-pools along the typical security incident propagation path; For adjacent resource sub-pools along a typical security incident propagation path, if the change in the effectiveness ratio of their protective measures exceeds a preset security risk association threshold, a security risk association relationship is determined to exist between the adjacent resource sub-pools. Based on the determined load state differences and security risk associations, multiple candidate resource sub-pool switching paths are generated, and specific triggering conditions for each candidate resource sub-pool switching path are obtained; Determine the load recovery characteristics and security event termination characteristics based on historical response delay recovery data and security event propagation termination data after resource subpool switching. Based on the aforementioned load recovery characteristics and security event termination characteristics, evaluate the stability of the switching paths of each candidate resource subpool; The path with the highest stability score is determined from all candidate resource sub-pool switching paths as the target switching path. When the current state of the resource sub-pool meets the specific triggering conditions of the target switching path, the resource sub-pool switching operation is executed.
2. The network security cloud resource pool security management method according to claim 1, characterized in that: The method for generating multiple candidate resource sub-pool switching paths includes: According to the quantitative index of the resource sub-pool load state difference, if the load state difference between any two resource sub-pools exceeds a preset load difference threshold, the two resource sub-pools are determined as candidate resource sub-pool switching paths; According to the security risk association relationship, if a security risk association relationship exists between any two resource sub-pools, the two resource sub-pools are determined as candidate resource sub-pool switching paths; The alternative resource sub-pool switching paths determined based on the load state difference and the security risk association relationship are merged to form multiple alternative resource sub-pool switching paths.
3. The network security cloud resource pool security management method according to claim 2, characterized in that: The method for obtaining the specific triggering conditions of the candidate resource sub-pool switching path includes: Extract the periods of abnormal response delays during peak business hours for each resource subpool, as well as the periods of high-frequency security incidents. Identify the overlapping parts of these periods as high-risk overlapping periods. The duration of high-risk overlap periods that occurred during successful handover operations in the past is counted, and their mean and standard deviation are calculated. If the duration of the currently monitored high-risk overlap period exceeds the typical overlap pattern threshold of the weighted sum of the mean and standard deviation, it is determined to be a typical high-risk overlap period; When the resource subpools involved in the candidate resource subpool switching path currently experience a typical high-risk overlapping period and any of the following conditions are met, the specific triggering conditions for the candidate resource subpool switching path are obtained: The load status difference between the resource sub-pools corresponding to the paths exceeds the preset load difference threshold; The security risk association relationship between the resource subpools corresponding to the path exceeds the preset security risk association threshold.
4. The network security cloud resource pool security management method according to claim 3 is characterized in that: The method for determining the load recovery characteristic includes: Extracting a response delay recovery data sequence from the historical records after the resource subpool switch operation is completed; the response delay recovery data sequence starts at the time the resource subpool switch operation is completed and is collected at a fixed sampling interval until the response delay returns to a normal range or the first delay rebound occurs; Determine the time and delay value corresponding to the lowest point of the response delay based on the response delay recovery data sequence, detect the time when the delay first rebounds significantly from the lowest point, record the delay value corresponding to that time, and calculate the rebound amplitude of the first delay rebound relative to the lowest point and the duration of the delay rebound; For multiple historical switching records, the average values of the delay rebound amplitude and the delay rebound duration are calculated respectively, and are determined as the load recovery characteristics of the resource sub-pool switching path.
5. The network security cloud resource pool security management method according to claim 4 is characterized in that: The method for determining the termination feature of the security event includes: Extract security incident propagation termination data from historical security incident propagation records; Based on the security incident propagation termination data, the number of times each resource sub-pool node ultimately blocked a security incident during the security incident propagation process is counted. The resource sub-pool whose final blocking number exceeds the set threshold is identified as a typical security incident termination node. Collect statistics on the types of security protection measures used by typical security event termination nodes when blocking security events, and determine the security protection measures whose usage frequency exceeds the set threshold as typical security protection measures; Calculate the time interval from the implementation to the effectiveness of typical security protection measures when blocking security incidents at the termination nodes of typical security incidents. Calculate the average effectiveness time interval of all typical security incident termination nodes to determine the average effectiveness time of security protection measures. The above typical security incident termination nodes, typical security protection measures types and average effective time of security protection measures are collectively determined as security incident termination features.
6. The network security cloud resource pool security management method according to claim 5, characterized in that: The stability assessment method comprises: For each candidate resource subpool switching path, extract the corresponding load recovery characteristics and security event termination characteristics from the historical records; Based on the delay rebound duration in the load recovery feature and the average security protection measure effectiveness time in the security event termination feature, the absolute value of the difference between the two is calculated and determined as the time coordination indicator between load recovery and security event termination. Based on the delay rebound amplitude in the load recovery characteristics, the average delay rebound amplitude of all candidate resource subpool switching paths is calculated. For each candidate path, the deviation between its delay rebound amplitude and the average value is calculated as the load recovery stability indicator. For each candidate resource subpool, switch paths and determine the security incident termination capability of the path. The comprehensive stability score of each alternative resource subpool switching path is calculated by combining the time coordination index of load recovery and security incident termination, the load recovery stability index, and the security incident termination capability.
7. A network security cloud resource pool security management system, implemented based on the network security cloud resource pool security management method according to any one of claims 1 to 6, characterized in that: include: An acquisition module is used to determine the load status difference and security risk association relationship between any two resource sub-pools based on the response delay data sequence and security event log of the resource sub-pools; A generation module is used to generate multiple alternative resource sub-pool switching paths based on the determined load state difference and security risk association relationship, and obtain specific triggering conditions for each alternative resource sub-pool switching path; a determination module, configured to determine load recovery characteristics and security event termination characteristics respectively based on historical response delay recovery data and security event propagation termination data after resource subpool switching; An evaluation module, configured to evaluate the stability of the switching paths of each candidate resource sub-pool based on the load recovery characteristics and security event termination characteristics; The management module is used to determine the path with the highest stability score from all candidate resource sub-pool switching paths as the target switching path, and execute the resource sub-pool switching operation when the current state of the resource sub-pool meets the specific triggering conditions of the target switching path.
Citation Information
Patent Citations
Resource pool switching method and device, mobile terminal, network side equipment and medium
CN111246433A
Cloud data attack detection based on cloud security posture and resource network path tracing
US11575696B1