Security measurement evaluation method of self-adaptive cooperative defense mechanism facing cloud scene
By building an SRN model to evaluate defense strategies in cloud scenarios and monitoring defense and attack data in real time, the adaptability problem of the adaptive collaborative defense mechanism in cloud scenarios is solved, accurate evaluation and adaptive adjustment of defense strategies are achieved, and defense efficiency and adaptability are improved.
Patent Information
- Application Number
- CN202510688261.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-12
AI Technical Summary
In existing technologies, the adaptive collaborative defense mechanism in cloud scenarios cannot flexibly adapt to the attacker's strategy changes. There is a lack of integrated security measurement methods for static defense and adaptive defense mechanisms, which makes it impossible to accurately determine whether the current strategy is suitable for different attack environments and unable to effectively adaptively adjust.
Build an SRN model based on defense virtual machines and attack virtual machines, monitor defense and attack data in real time, simulate the task operation process, count the number of tasks, evaluate the compliance of the completion strategy through the SRN model, and generate processing methods to adaptively adjust the defense mechanism.
It achieves a fine-grained description of the attack and defense process, ensures the accuracy of the measurement, can accurately judge the task completion process of the defense virtual machine, improve the efficiency of the adaptive adjustment of the collaborative defense mechanism, and ensure the adaptability of the defense strategy in different attack environments.
Smart Images

Figure CN120639347A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing security technology, and in particular to a security metric evaluation method for an adaptive collaborative defense mechanism for cloud scenarios. Background Art
[0002] A security metric assessment method for adaptive collaborative defense mechanisms in cloud scenarios is a comprehensive evaluation framework that combines dynamic defense capabilities, collaborative response effectiveness, and cloud environment characteristics. Its core goal is to quantify the security performance of defense mechanisms in dynamic cloud environments. However, existing technologies suffer from the following shortcomings: poor adaptability of static defense strategies, a single adaptive defense strategy, and a lack of security measurement models.
[0003] Chinese patent publication number: CN114244586B, discloses an adaptive mobile target defense method and system for Web services. The system includes an OpenFlow switch, an SDN controller, a server, an adaptive startup engine, and an adaptive mobile target defense module. The adaptive startup engine includes a traffic anomaly detection module, and the adaptive mobile target defense module includes a virtual machine migration MTD submodule and a web application configuration MTD submodule.
[0004] It can be seen that the above solution has the following problems: it cannot flexibly adapt to the attacker's strategy changes, does not combine different virtual machine allocation strategies, resulting in some migration strategies being unable to effectively attack in certain situations. At the same time, there is a lack of security measurement methods for the integration of static defense and adaptive defense mechanisms, so it is impossible to accurately determine whether the currently set completion strategy can adapt to different attack environments, resulting in the inability to adaptively adjust the corresponding completion strategy when it is not suitable. Summary of the Invention
[0005] To this end, the present invention provides a security metric evaluation method for an adaptive collaborative defense mechanism for cloud scenarios, which is used to overcome the problem in the prior art that it is impossible to accurately determine whether the currently set completion strategy can adapt to different attack environments, resulting in the inability to adaptively adjust the corresponding completion strategy when it is not adapted.
[0006] To achieve the above objectives, the present invention provides a security metric assessment method for an adaptive collaborative defense mechanism for cloud scenarios, comprising:
[0007] Build several defense virtual machines and attack virtual machines for the tasks sent by users;
[0008] Determining a task completion strategy based on the defending virtual machine and the attacking virtual machine;
[0009] When executing the completion strategy, monitoring the defense data of the defending virtual machine and the attack data of the attacking virtual machine in real time;
[0010] Building an SRN model based on the monitored defense data and the attack data to simulate the operation process of the task;
[0011] Based on the running process, counting the number of completed tasks;
[0012] Determine whether the completion strategy used meets the standards based on the number of completed tasks, and when it is determined that the completion strategy does not meet the standards, generate a corresponding processing method based on the determined reason for not meeting the standards.
[0013] Furthermore, the operation process of the defense virtual machine includes: preliminarily allocating the defense virtual machine to the server according to the allocation strategy in the completion strategy; judging whether the defense virtual machine is successfully paired with the server according to the memory size of the server; if the defense virtual machine is successfully paired with the server, judging whether the defense virtual machine is attacked according to the time the defense virtual machine stays on the server; if the defense virtual machine is not attacked, judging whether the task is completed, and if not completed, repeating the above steps at least once until the task is completed or fails to be completed due to the attack.
[0014] Furthermore, the process of judging whether the defense virtual machine is successfully paired with the server based on the memory size of the server includes: comparing the memory size of the server with the memory size occupied by the task of the defense virtual machine; if the memory size of the server is greater than the memory size occupied by the task of the defense virtual machine, it is determined that the defense virtual machine is successfully paired with the server; if the memory size of the server is less than or equal to the memory size occupied by the task of the defense virtual machine, it is determined that the defense virtual machine has failed to pair with the server, and then the defense virtual machine is preliminarily allocated to the server again according to the allocation strategy in the completion strategy until the defense virtual machine is successfully paired with the server.
[0015] Furthermore, the process of determining whether the defensive virtual machine is attacked based on the time the defensive virtual machine stays on the server includes: comparing the time the defensive virtual machine stays on the server with the time the attacking virtual machine establishes a side channel; if the time the defensive virtual machine stays is greater than or equal to the time the side channel is established, determining that the defensive virtual machine is attacked; if the time the defensive virtual machine stays is less than the time the side channel is established, determining that the defensive virtual machine is not attacked.
[0016] Furthermore, the operation process of the attacking virtual machine includes: allocating the attacking virtual machine to the server according to the allocation strategy in the completion strategy; and judging whether the attacking virtual machine is successful based on the coexistence time of the attacking virtual machine and the defense virtual machine in the same server.
[0017] Furthermore, the process of judging whether the attack of the attacking virtual machine is successful based on the coexistence time of the attacking virtual machine and the defense virtual machine in the same server includes: if the attacking virtual machine and the defense virtual machine do not coexist on the same server, or the coexistence time of the attacking virtual machine and the defense virtual machine is greater than or equal to the time for the attacking virtual machine to establish a side channel, it is judged that the attack of the attacking virtual machine has failed; if the coexistence time of the attacking virtual machine and the defense virtual machine is less than the time for the attacking virtual machine to establish a side channel, it is judged that the attack of the attacking virtual machine is successful.
[0018] Furthermore, the operation process of the attack virtual machine also includes: the attack virtual machine migrates at a fixed migration cycle to attack the defense virtual machine on the next server; repeating the above steps at least once until all tasks leave the server, and the attack virtual machine ends the attack.
[0019] Furthermore, the process of determining whether the completion strategy used meets the standards based on the number of completed tasks includes: calculating the ratio of the number of completed tasks to the total number of tasks received, wherein the total number of tasks is the number of tasks sent by the user excluding the number of tasks with malicious virtual machines, wherein the malicious virtual machines are formed by attackers injecting malware into the virtual machines; determining whether the completion strategy meets the standards based on the comparison result of the ratio with the pre-stored preset completion rate; if the ratio is greater than or equal to the first preset completion rate, determining that the completion strategy meets the standards; if the ratio is less than the first preset completion rate and greater than the second preset completion rate, determining whether the completion strategy meets the standards based on the ratio of the number of tasks with malicious virtual machines to the number of tasks sent by the user; if the ratio is less than or equal to the second preset completion rate, determining that the completion strategy does not meet the standards.
[0020] Furthermore, the process of determining whether the completion strategy meets the standards based on the ratio of the number of tasks with malicious virtual machines to the number of tasks sent by users includes: comparing the ratio with a preset ratio; if the ratio is less than or equal to the preset ratio, determining that the completion strategy does not meet the standards; if the ratio is greater than the preset ratio, determining that the completion strategy meets the standards, and then reducing the preset completion rate based on the difference between the ratio and the preset ratio, and the difference is proportional to the reduction in the preset completion rate.
[0021] Furthermore, the evaluation indicators for verifying the effectiveness of the SRN model include: probability of being compromised, task completion time, average failure time, and security gain; among them, the probability of being compromised is the probability of the attack being successfully executed, the average time is the average time from the time when the attacking virtual machine does not steal any information to the time when a preset amount of private information is stolen, and the security gain is used to measure the increase in the probability of successful execution of the defense virtual machine task after the defense virtual machine implements the virtual machine migration strategy.
[0022] Compared with the prior art, the beneficial effect of the present invention lies in that an SRN model is constructed based on attack and defense data, and the task running process is simulated by the SRN model. The attack and defense process can be described in fine-grained form through the SRN model to ensure the accuracy of the measurement; at the same time, the guard function is used to further characterize the action interaction between attack, defense, and task execution, and to assign parameters, so as to comprehensively characterize the attack and defense process; further, indicators such as the probability of being attacked, task completion time, average failure time, and security gain are proposed to measure the completion of the task of the defense virtual machine and the impact on the attack, and determine whether the set completion strategy meets the standards; finally, the corresponding processing method is generated according to the reason why the completion strategy does not meet the standards, and it can accurately determine whether the currently set completion strategy can adapt to different attack environments based on the a posteriori attack situation, and more effectively adaptively adjust the corresponding completion strategy when it is not adapted.
[0023] Furthermore, the present invention can more clearly determine the task completion process of the defense virtual machine through the operation process of the defense virtual machine, thereby further improving the efficiency of the subsequent adaptive adjustment of the collaborative defense mechanism.
[0024] Furthermore, the present invention determines whether the pairing is successful by judging the memory size occupied by the task of the defense virtual machine and the memory size of the server, and can accurately judge whether the pairing is successful, thereby improving the efficiency of task completion.
[0025] Furthermore, the present invention determines whether the defending virtual machine is attacked by comparing the residence time of the defending virtual machine on the server with the length of time the coexisting attacking virtual machine establishes a side channel, which can make the judgment result more accurate and provide a basis for more effective adaptive adjustment of the collaborative defense mechanism according to the judgment result in the subsequent case of attack.
[0026] Furthermore, the present invention can more clearly determine the attack process of the attack virtual machine by attacking the running process of the virtual machine, thereby further improving the efficiency of the subsequent adaptive adjustment of the collaborative defense mechanism.
[0027] Furthermore, the present invention determines whether the attack of the attacking virtual machine is successful by the coexistence time of the attacking virtual machine and the defending virtual machine in the same server, and can more quickly determine the attack result of the attacking virtual machine, so that the collaborative defense mechanism can be adaptively adjusted more accurately according to the attack result in the subsequent process.
[0028] Furthermore, by judging whether the attacking virtual machine has ended the attack, the present invention can more timely evaluate the reliability of the existing security policy, thereby further improving the efficiency of the subsequent adaptive adjustment of the collaborative defense mechanism.
[0029] Furthermore, the present invention judges whether the completion strategy meets the standards by the ratio of the number of completed tasks to the total number of tasks received, thereby more accurately determining whether the currently set completion strategy can adapt to different attack environments, and more effectively adaptively adjusting the corresponding completion strategy if it is not adaptable.
[0030] Furthermore, the present invention breaks through the strong assumptions in static defense evaluation and establishes a more comprehensive evaluation index system, covering multiple dimensions such as the probability of being compromised, task completion time, task failure time, and security gain as core indicators, in order to optimize defense costs and improve overall security. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 This is a flowchart of the steps of a security metric assessment method for an adaptive collaborative defense mechanism for cloud scenarios according to an embodiment of the present invention;
[0032] Figure 2 The operation process of the defense virtual machine in the embodiment of the present invention;
[0033] Figure 3 The running process of attacking a virtual machine in an embodiment of the present invention;
[0034] Figure 4 A flowchart of the steps for determining the completion rate based on the comparison result of the ratio of the number of completed tasks to the total number of received tasks and a preset completion rate according to an embodiment of the present invention;
[0035] Figure 5 It is the MTTC sub-model in the embodiment of the present invention;
[0036] FIG6( a ) is a task sub-model 1 in the SRN main model according to an embodiment of the present invention;
[0037] FIG6( b ) is a task sub-model 2 in the SRN main model according to an embodiment of the present invention;
[0038] Figure 7 It is the attack sub-model in the SRN main model in the embodiment of the present invention. DETAILED DESCRIPTION
[0039] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.
[0040] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood by those skilled in the art that these embodiments are only used to explain the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0041] See also Figure 1As shown, it is a flowchart of the steps of the security metric evaluation method of the adaptive collaborative defense mechanism for cloud scenarios according to an embodiment of the present invention.
[0042] The steps in the actual operation process of the embodiment of the present invention include:
[0043] S1, builds several defense virtual machines and attack virtual machines for the tasks sent by users;
[0044] S2, determining a task completion strategy based on the defending virtual machine and the attacking virtual machine;
[0045] S3, when running the completion strategy, monitoring the defense data of the defending virtual machine and the attack data of the attacking virtual machine in real time;
[0046] S4, constructing an SRN model based on the monitored defense data and the attack data to simulate the operation process of the task;
[0047] S5, counting the number of completed tasks based on the running process;
[0048] S6, determining whether the completion strategy used meets the standards according to the number of completed tasks, and when it is determined that the completion strategy does not meet the standards, generating a corresponding processing method based on the determined reason for not meeting the standards.
[0049] Specifically, in this embodiment, whenever a new task is received, the system creates a corresponding virtual machine and assigns it to a physical server. The management node is responsible for creating virtual machines, collecting information about each server, and allocating virtual machines to specific servers based on the allocation policy. Because it is difficult for the management node to distinguish between n tasks sent by a user and m requests containing malware sent by an attacker, corresponding virtual machines will be created for each request arriving in the same batch to process the task. The management node will create n defender virtual machines and m attacker virtual machines, and assign them to s physical servers. When a task is executed on a server, it may coexist with the attacking virtual machine, during which time the attacker may attempt to establish a side channel to steal information. To avoid the risk of information leakage, the management node will dynamically migrate all virtual machines between servers during task execution.
[0050] Specifically, in this embodiment, the number of completed tasks obtained during the operation of the SRN model simulation task is used to determine whether the set completion strategy meets the standards, and an adjustment method corresponding to the completion strategy is generated according to the reason for non-compliance with the standards, so as to more effectively and adaptively adjust the defense mechanism, thereby further improving the completion rate of the task.
[0051] See also Figure 2As shown, it is the operation process of the defense virtual machine in an embodiment of the present invention. The operation process of the defense virtual machine in the embodiment of the present invention includes: according to the allocation strategy in the completion strategy, the defense virtual machine is allocated to the server; if the space of the server is greater than or equal to the memory size of the defense virtual machine, the defense virtual machine stays on the server for a preset time; if the defense virtual machine and the attack virtual machine stay in the same server, and the preset time is greater than the duration of the attack virtual machine co-resident with the defense virtual machine to establish a side channel, it is determined that the defense virtual machine is successfully destroyed and the task corresponding to the defense virtual machine is determined to have failed to complete; if the preset time is less than or equal to the duration of the attack virtual machine co-resident with the defense virtual machine to establish a side channel, it is determined that the defense virtual machine is not destroyed, and then it is determined whether the task corresponding to the defense virtual machine is completed. If the task is not completed, the above steps are repeated at least once until the task is completed or the task fails to complete.
[0052] Specifically, in this embodiment, consider a multi-tasking scenario where the system may be assigned multiple tasks simultaneously, which are executed independently within the system. Each task that enters the system can have two possible outcomes when it leaves: one is that it successfully migrates between several servers and is ultimately executed; the other is that it coexists with an attacker during the migration process, allowing information to be stolen and the task to fail. The specific steps are described below:
[0053] Step 1: The management node receives a request from the user and creates a virtual machine.
[0054] Step 2: Allocate the virtual machine to a server based on the allocation policy. If the selected server has sufficient space, proceed to the next step; otherwise, reselect a server.
[0055] Step 3: After selecting a suitable server, the virtual machine will reside there for a specified period of time. During this period, if the defending virtual machine coexists with the attacker's attacking virtual machine for longer than the time required to establish a side channel, the defending virtual machine will be compromised and information will be leaked. If the attack obtains some confidential information from the defending virtual machine, the attack is considered successful. If the defending virtual machine is successfully compromised, the corresponding task will fail immediately. Otherwise, proceed to the next step.
[0056] Step 4: If the defense VM is not actively attacked before migration is required, execution on that server has successfully completed. At this point, the task is checked to see if it has been completed. If not, the process jumps to Step 2 and migrates to the next server until the task is completed or fails due to an attack.
[0057] During this process, the task execution time T task and the migration interval T serverThe task execution time follows a certain distribution, and its cumulative distribution function cdf is denoted as F ta (t), the probability density function pdf is recorded as F ta (t). Similarly, the migration interval follows the distribution of and.
[0058] See also Figure 3 As shown, this is the operation process of the attack virtual machine in an embodiment of the present invention. In embodiment 3 of the present invention, the operation process of the attack virtual machine includes: allocating the attack virtual machine to a server according to the allocation strategy in the completion strategy; if the attack virtual machine and the defense virtual machine exist simultaneously in the server and the coexistence duration is greater than the duration for the attack virtual machine to establish a side channel, then the attack of the attack virtual machine is successful; if the attack virtual machine and the defense virtual machine do not exist simultaneously in the server, or if the attack virtual machine and the defense virtual machine exist simultaneously in the server and the coexistence duration is less than or equal to the duration for the attack virtual machine to establish a side channel, then the attack of the attack virtual machine is unsuccessful.
[0059] Specifically, in this embodiment, to increase the probability of a successful attack, the attacker may inject multiple malicious requests into the system, generating multiple attack virtual machines. After entering the system, the malicious attack virtual machines migrate between multiple servers along with the normal defense virtual machines until all tasks have left the system. When launching attack virtual machines, the attacker also has two corresponding strategies: stacking and dispersing. The stacking strategy involves launching as many virtual machines as possible at once, while the dispersing strategy involves launching virtual machines in batches, distributing the created virtual machines across as many servers as possible. The specific steps are described below:
[0060] Step 1: Similar to the creation process of the defense VM, the management node creates the attack VM after receiving the request and assigns it to find a legitimate server.
[0061] Step 2: The attacker sniffs the information in the server. If there is a co-resident defense virtual machine, then proceed to step 3. If there is no co-resident defense virtual machine, then wait for the managed node to migrate to another server.
[0062] Step 3: The attacker selects one of the defense VMs to attack, which takes time t attack After that, the side channel is successfully established. During this period, if the defending VM does not migrate, the attack is successful and the task executed in the defending VM fails. Otherwise, the defending VM avoids the attack and the attack fails.
[0063] Regardless of whether the attack succeeds or not, the attacker can continue attacking tasks still executing in the system, waiting for the management node to migrate them to other servers at a fixed migration cycle. After migration, the attacker returns to step 1 and continues the attack. If all tasks have left the system, the attack becomes meaningless and ceases.
[0064] Time t required for attack attack Contains the time required to build a side channel and steal data, which is also a random variable and follows cdf = F a (t) and pdf = F a (t) exponential distribution.
[0065] See also Figure 4 As shown, it is a flowchart of the steps of determining whether the completion strategy used meets the standards based on the comparison result of the ratio of the number of completed tasks to the total number of received tasks and the preset completion rate according to an embodiment of the present invention. The process of determining whether the completion strategy used meets the standards based on the number of completed tasks according to an embodiment of the present invention includes: calculating the ratio of the number of completed tasks to the total number of received tasks, wherein the total number of tasks is the number of tasks sent by the user excluding the number of tasks with malware; determining whether the completion strategy meets the standards based on the comparison result of the ratio and the pre-stored preset completion rate; if the ratio is greater than or equal to the first preset completion rate, determining that the completion strategy meets the standards; if the ratio is less than the first preset completion rate and greater than the second preset completion rate, determining whether the completion strategy meets the standards based on the ratio of the number of tasks with malware to the number of tasks sent by the user; if the ratio is less than or equal to the second preset completion rate, determining that the completion strategy does not meet the standards, and then determining the reason why the completion strategy does not meet the standards based on the duration of the side channel established by the attacking virtual machine.
[0066] Specifically, in this embodiment, the ratio L0 of the number of completed tasks to the total number of received tasks can be divided into a first preset completion rate L1 and a second preset completion rate L2. In the set completion rate standard, the first preset completion rate L1=0.85 and the second preset completion rate L2=0.5. It should be noted that, in other embodiments, the values of L1 and L2 can also be determined according to the security metric evaluation requirements of the relative adaptive collaborative defense mechanism; the comparison process based on the ratio L with L1 and L2 is as follows:
[0067] If the ratio L is greater than or equal to a first preset completion rate L1, it is determined that the completion strategy meets the standard;
[0068] If the ratio L is less than the first preset completion rate L1 and greater than the second preset completion rate L2, it cannot be determined whether the comparison result is caused by other factors. Then, based on the ratio P of the number of tasks containing malware to the number of tasks sent by users, it is determined whether the completion strategy meets the standard.
[0069] If the ratio L is less than or equal to the second preset completion rate L2, it is determined that the completion strategy does not meet the standard, and the reason why the completion strategy does not meet the standard is determined based on the duration Q of the attack virtual machine establishing the side channel.
[0070] Specifically, the process of determining whether the completion strategy meets the standards based on the ratio of the number of tasks containing malware to the number of tasks sent by users in an embodiment of the present invention includes: comparing the ratio with a preset ratio; if the ratio is less than or equal to the preset ratio, determining that the completion strategy does not meet the standards; if the ratio is greater than the preset ratio, determining that the completion strategy meets the standards, and adjusting the preset completion rate based on the difference between the ratio and the preset ratio.
[0071] Specifically, in this embodiment, a preset ratio P0=0.25 is set, and the comparison process between the ratio P of the number of tasks containing malware and the number of tasks sent by users and the preset ratio P0 is as follows:
[0072] If the ratio P is less than or equal to the preset ratio P0, it indicates that the determination result of the completion strategy is substantially not affected by the task with malware, and the completion strategy is determined to be not in compliance with the standard;
[0073] If the ratio P is greater than the preset ratio P0, it means that the determination result of the completion strategy is affected by the task with malware, then the completion strategy is determined to meet the standard, and the preset completion rate is adjusted based on the difference R between the ratio and the preset ratio.
[0074] Specifically, the process of adjusting the preset completion rate based on the difference between the ratio and the preset ratio in an embodiment of the present invention includes: reducing the preset completion rate based on the difference between the ratio and the preset ratio, and the difference is proportional to the reduction degree of the preset completion rate.
[0075] Specifically, in this embodiment, the preset difference R0 is set to 0.05, and the comparison process based on the difference R and the preset difference R0 is as follows:
[0076] If the difference R is less than or equal to the preset difference R0, the preset completion rate is adjusted to 0.9 times the original preset completion rate;
[0077] If the difference R is greater than the preset difference R0, the preset completion rate is adjusted to 0.7 times the original preset completion rate.
[0078] Specifically, the evaluation indicators for verifying the effectiveness of the SRN model in the embodiment of the present invention include: probability of being compromised, task completion time, average failure time, and security gain; among them, the probability of being compromised is the probability of the attack being successfully executed, the average time is the average time from the time when the attacking virtual machine does not steal any information to the time when a preset amount of private information is stolen, and the security gain is used to measure the increase in the probability of successful execution of the defense virtual machine task after the defense virtual machine implements the virtual machine migration strategy.
[0079] Specifically, in this embodiment, in addition to determining whether the completion strategy used meets the standards based on the number of completed tasks, a quantitative solution based on the SRN model was used to obtain multiple key indicators for evaluating the model's effectiveness, such as the probability of virtual machine compromise, the dynamic change in attack success rate over time, and the impact of the migration strategy on system performance. These basic indicators provide a scientific basis for the subsequent optimization of defense strategies. To further verify the effectiveness of the quantitative evaluation model, four core evaluation indicators were established: compromise probability, task completion time, mean time to failure, and security gain.
[0080] First, the probability of compromise (p_attack) refers to the probability of a successful attack and is one of the most common metrics in security analysis. Similar to the probability of successful defense, the attack success rate reflects the probability of achieving a specific attack objective. Depending on the specific analysis scenario, it can have various meanings. For example, it can represent the probability of an attacker breaching multiple layers of defense and stealing certain information, or the probability of disrupting the execution of a task. In this scenario, the probability of compromise quantifies the likelihood of an attacker obtaining sensitive data. By solving the SRN network, we can obtain the steady-state probability of each node. The steady-state probability of node P_(fail-i) is the probability of compromise of task i, and the average failure probability of all tasks represents the probability of cluster compromise, p_attack.
[0081] Second, the performance metric is the mean time to completion (MTTC). Attack-defense confrontation not only affects the probability of task completion but can also extend task execution time due to defense mechanisms, defense overhead, and attack interference. For example, when using VM hot migration technology, which migrates the executing virtual machine between different servers, the migration process itself has time overhead, and attacks can cause task restarts. Therefore, task execution time can be affected by the attack-defense confrontation and extend to varying degrees.
[0082] Taking advantage of the numerous software packages available for the SRN model to assist in calculating various metrics, we further extended the established SRN model to analyze the average time to output a correct result. This metric reflects the time it takes for a task to be responded to, and is another noteworthy performance metric besides the probability of task completion. Extending the SRN mainly involves two aspects: adding the MTTC submodel and adding absorbing states to the remaining submodels. Figure 5 The figure shows the MTTC submodel in an embodiment of the present invention. Adding absorbing states involves adding transitions t_(done-i) to each P_(suc-i) position in the task model. All added transitions are controlled by the guard function. The MTTC value is obtained using a built-in function in SPNP, which is used to calculate the average absorption time of a token.
[0083] Third, the performance metric is the mean time to failure (MTTF). If the attacker can steal a certain amount of information each time they successfully cohabit, and after cohabitation fails, the stolen information gradually becomes ineffective over time, then the cumulative amount of information successfully acquired during the attacker's multiple attacks can be considered a birth-and-death process. If the amount of private information the attacker needs to steal from the VM is L, then the attack time, or the mean time to failure of the VM, is defined as the average time from the time the attacker steals no information to the time they steal enough private information. Using the probability of a single attack success, p_attack, and the probability of a single task success, p_suc, as parameters, we obtain:
[0084] Fourth, safety gain σ: This is typically used to describe the security improvement achieved through a specific measure, technology, or strategy. In this scenario, safety gain measures the increase in the defender's probability of successful task execution after implementing the VM migration strategy. Safety gain is defined as: σ = p_(task-d) / p_(task-s), where p_(task-d) and p_(task-s) represent the task completion probabilities when using dynamic VM migration and static VM placement strategies, respectively.
[0085] In order to make the objects and advantages of the present invention more clearly understood, the present invention is further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are merely used to explain the present invention and are not intended to limit the present invention.
[0086] Example 1
[0087] In this embodiment, in the process of establishing the SRN model, a system with parameters s = 3, n = 2, m = 1, and c = 4 is used as an example to demonstrate the model establishment process. Modeling of other scenarios and different parameters can be achieved by adjusting specific guard functions and parameters based on the ideas in this section.
[0088] Please refer to Figures 6(a) and 6(b), which illustrate task submodel 1 and task submodel 2 in the SRN main model of this embodiment. In this embodiment, each task submodel represents a task executed on multiple servers. Each task model has two possible outcomes: completion and interruption due to an attack, i.e., compromise. As shown in Tables 1 and 2, these define and initialize the guard functions and delay transitions in the task submodels, respectively. This model primarily relies on behavior duration and interaction to influence outcomes, simulating the attack process by setting transition delays and guard functions, rather than relying on probabilistic input parameters. Therefore, all instantaneous transitions are triggered with the same probability and will not be described individually. In the guard function in Table 2, the number i, i∈[1,n], represents the i-th task; the number j, j∈[1,s], represents the server number selected for virtual machine placement.
[0089] Table 1 Definition of guard function in task sub-model (i∈[1,n], j∈[1,s])
[0090]
[0091] Table 2 Meaning and value assignment of delay transition in SRN model (i∈[1,n], j∈[1,s])
[0092]
[0093] In the task sub-model, each initial position P i Each has a token, indicating that the i-th task is ready to enter the system. Taking the first task sub-model as an example, when the token representing the first task in the task sub-model arrives, the transition t in-i , the token is simultaneously transferred to position P t1 and P al-1 . In P t1 The token at the position monitors whether the first task has been completed, that is, to simulate the process of executing this task without interruption. The execution will take 1 / λ suc1 (ie T task-1 ) time units. Position P al-1 The token in is used to describe the process of migrating and executing tasks across multiple servers. It is followed by three instantaneous transitions t t1-s1 , t t1-s2 and t t1-s3 Represents three optional servers, each with its own corresponding protection function policy i () represents whether the control node will choose to place the virtual machine on server i. Each task sub-model will only have one policy at the same time. i () returns true.
[0094]
[0095]
[0096] In the algorithm, AVM is the attack virtual machine and DVM is the defense virtual machine. If policy i () returns true, which means that according to the virtual machine placement policy, the system assigns the virtual machine VM1 of the first task to server i. Assuming that policy1() returns true, the management node selects the first server and the server is legal and has sufficient remaining resources. Then the token will be transferred to position P 1s1 , and stays at this position for an average of 1 / λ e-11 Unit time. Migration t e-11 Indicates that the task is executed on the first server, and its delay represents the migration interval. The task may be interrupted due to an attack, and the instantaneous transition t i-11 Describes the process of attack interrupting the task. Guard function interrupt 11 () detects whether it is under attack and controls whether the transition can be triggered immediately. If the attacker's AVM is also assigned to server 1 and the time it lives with task 1 exceeds the time required by the attacker, then the function interrupt 11 () will return true. Transient transition t i-11 will be triggered immediately, transferring the token to position P in-1 At this point, the task execution fails, the guard function fail1() returns true, and position P t1 The token is transferred to position P fail-1 , indicating that task 1 fails and leaves the system. If the token stays at position P 1s1 During this period, task 1 was not interrupted by the attacker, and the final delay transition t e-11 is triggered, the token is transferred to position P fin-11 , which means that Task 1 has successfully completed the execution cycle on Server 1 and needs to be migrated to the next server. At this time, if the token on the left is still at position P t1 , it means that task 1 has not been completed yet, and the management node will migrate the first task to the next server. In other words, the transition t next-11 Will be triggered, position P fin-11 The token is transferred back to position P al-1 , indicating that the first task is migrated to the next server for a new round of execution.
[0097] See also Figure 7As shown in Table 3, it represents the attack submodel in the SRN main model of this embodiment. In this embodiment, as shown in Tables 3 and 4, the delay transition and guard functions in the attack submodel are defined and initialized, respectively. The numbers i∈[1,n] and j∈[1,s] in the table represent task i and server j, respectively. The number of attacking virtual machines is represented by the number of attacker submodels.
[0098] Table 3 Definition of guard function in attack sub-model (i∈[1,n], j∈[1,s])
[0099]
[0100] The attack sub-model takes position P a There is a token in the initial state, which means that the management node has received the attacker's request. The management node selects a server for each created attack virtual machine according to the allocation strategy. This selection is composed of three transient transitions t a1 , t a2 and t a3 express.
[0101] When the guard function policy1() returns true, it means that the management node selects server 1 to place the attacking virtual machine. a1 will be triggered immediately and the token will be transferred to position P as1 . Connect to position P as1 The delay variation t 1s If the attacking VM does not coexist with any defending VM, it will stay here and wait for the next round of migration. as1 The number of transient changes is equal to the number of tasks executed in the entire system. So in this example, there are two transient changes: t 1c1 and t 1c2 These two transient changes represent the coexistence of the attacker with the defense virtual machine 1 and the defense virtual machine 2 respectively.
[0102] If the position P of task submodel 1 1s1 and the position P of task submodel 2 2s1 , each of them has a token, indicating that the attacker coexists with two tasks at the same time. At this time, the attacker needs to randomly select a defense virtual machine to attack, that is, t 1c1 and t 1c2 are triggered with the same probability. If position P 1s1 and position P 2s1 There is only one token in position P, which means the attacker only coexists with the corresponding task. 1s1 For example, there is a token in the example, which means that the attacker lives with task 1 and guards the function opp 11 () returns true, the attack token will be transferred to position P1c1 The attacker begins to establish a side channel and attack the defense virtual machine 1. It takes some time for the attacker to establish the side channel. During this time, the defender may be migrated, causing the current attack to fail. 1a1 and the transition t of task sub-model 1 e-11 can be triggered in different orders, indicating different completion orders for establishing the side channel and being migrated. If the task leaves this server before the information is stolen, the attack will be interrupted and fail. This interruption is indicated by the instantaneous transition t 1e1 Indicates that its guard function escape 11 () will monitor whether the cohabiting task has left, that is, whether the attack is interrupted by the migration. If the attack is completed first, the token will be transferred to position P 1a1 , the corresponding task sub-model is interrupted and the defense token is transferred to position P in-1 , indicating that the attack is successful. After the task sub-model is interrupted, the attack token will be transferred to position P 1fa , and then immediately transferred into P fina If there are some tasks still being worked on, the function working() returns true and the token returns to position P a , indicating a new round of attacks.
[0103] Example 2
[0104] In this embodiment, the security analysis shows that among the time-related parameters, the migration period t_server is the easiest for the defender to control. Three pairs of (t_attack, t_task) parameters were selected for testing, using three servers, one attack request, one task, t_attack = 0.5 hours, and no server capacity restrictions. Preliminary simulations show that the attack success rate exhibits a similar trend with increasing migration period. p_attack increases rapidly with increasing migration period t_server, reaching a maximum value before remaining stable or slightly decreasing. This is because, first, the smaller t_server, the shorter the coexistence period between the attacker and defender, leaving the attacker with less time to establish a side channel, making the attack inherently more difficult. Therefore, as t_server increases, the attacker has more time to establish a side channel, and the attack success rate increases rapidly. However, if the attacker does not coexist with any DVM after allocation, the attacker will have to wait longer to be migrated to the next server. During this waiting period, the task has a greater chance of successfully completing. Therefore, as t_server increases, p_attack reaches a maximum value and then ceases. When the migration period exceeds the task execution time, changes in the migration period lose their influence on task execution, because tasks leave the system after completion and do not need to wait for migration. Therefore, in the later stages, the migration period mainly affects the attacker, which leads to a decrease in p_attack. This also shows that the increase in the migration period affects the time attackers wait for migration, and thus affects the probability of attack success.
[0105] The maximum p_attack value occurs around t_server = 0.5 hours, indicating that the peak position is unrelated to t_task. However, the attack effect reaches its peak at t_server = 1, inferring that the time when the attack effect reaches its peak is related to t_task.
[0106] Therefore, the research results show that virtual machine migration strategies can significantly reduce the probability of compromise. By dynamically adjusting migration frequency and resource allocation, the system's mean time to failure can be effectively extended. Specifically, at high migration frequencies, attackers find it difficult to establish stable monitoring paths, significantly reducing the probability of compromise. Furthermore, under resource constraints, optimizing migration paths and resource scheduling strategies can further enhance the system's fault tolerance and maintain high performance levels.
[0107] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.
[0108] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that the present invention is susceptible to various modifications and variations. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.
Claims
1. A security metric evaluation method for an adaptive collaborative defense mechanism for cloud scenarios, characterized by: include: Build several defense virtual machines and attack virtual machines for the tasks sent by users; Determining a task completion strategy based on the defending virtual machine and the attacking virtual machine; When executing the completion strategy, monitoring the defense data of the defending virtual machine, the attack data and the attack and defense rules of the attacking virtual machine in real time; Mapping an SRN model according to the monitored defense data, the attack data, and the attack and defense rules to simulate the operation process of the task; Based on the running process, counting the number of completed tasks; Determine whether the completion strategy used meets the standards based on the number of completed tasks, and when it is determined that the completion strategy does not meet the standards, generate a corresponding processing method based on the determined reason for not meeting the standards.
2. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 1 is characterized in that: The operation process of the defense virtual machine includes: preliminarily allocating the defense virtual machine to a server according to an allocation policy in the completion policy; Determining whether the defense virtual machine is successfully paired with the server based on the memory size of the server; If the defense virtual machine is successfully paired with the server, determining whether the defense virtual machine is attacked based on the time the defense virtual machine stays on the server; If the defending virtual machine is not attacked, determine whether the task is completed. If not, repeat the above steps at least once until the task is completed or fails to be completed due to the attack.
3. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 2 is characterized in that: The process of determining whether the defense virtual machine is successfully paired with the server according to the memory size of the server includes: Compare the server's memory size with the memory size occupied by the defense virtual machine's tasks; If the memory size of the server is larger than the memory size occupied by the task of the defense virtual machine, it is determined that the defense virtual machine is successfully paired with the server; If the memory size of the server is less than or equal to the memory size occupied by the task of the defense virtual machine, it is determined that the defense virtual machine has failed to be paired with the server, and the defense virtual machine is initially allocated to the server again according to the allocation strategy in the completion strategy until the defense virtual machine is successfully paired with the server.
4. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 3 is characterized in that: The process of determining whether a defense VM is under attack based on the time it has stayed on the server includes: Comparing the time the defending virtual machine stays on the server with the time the attacking virtual machine establishes the side channel; If the dwell time is greater than or equal to the side channel establishment time, it is determined that the defense virtual machine is attacked; If the residence time is less than the duration of establishing the side channel, it is determined that the defense virtual machine has not been attacked.
5. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 4 is characterized in that: The attack virtual machine operation process includes: Allocating the attack virtual machine to a server according to the allocation strategy in the completion strategy; Whether the attack of the attacking virtual machine is successful is determined according to the coexistence time of the attacking virtual machine and the defending virtual machine in the same server.
6. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 5 is characterized in that: The process of determining whether the attack of the attacking virtual machine is successful according to the coexistence time of the attacking virtual machine and the defending virtual machine in the same server includes: If the attacking virtual machine and the defending virtual machine do not coexist on the same server, or the coexistence time of the attacking virtual machine and the defending virtual machine is greater than or equal to the time it takes for the attacking virtual machine to establish the side channel, it is determined that the attack of the attacking virtual machine has failed; If the coexistence time of the attacking virtual machine and the defending virtual machine is less than the time it takes for the attacking virtual machine to establish a side channel, it is determined that the attack of the attacking virtual machine is successful.
7. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 4 is characterized in that: The attack virtual machine's operation process also includes: The attack virtual machine migrates at a fixed migration cycle to attack the defense virtual machine on the next server; Repeat the above steps at least once until all tasks leave the server, and then the attack virtual machine ends the attack.
8. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 7 is characterized in that: The process of determining whether the completion strategy used meets the criteria based on the number of tasks completed includes: Calculate the ratio of the number of completed tasks to the total number of tasks received, where the total number of tasks is the number of tasks sent by users, excluding the number of tasks with malicious virtual machines. Malicious virtual machines are created by attackers injecting malware into virtual machines. Determining whether the completion strategy meets the criteria based on a comparison result of the ratio and a pre-stored preset completion rate; If the ratio is greater than or equal to a first preset completion rate, it is determined that the completion strategy meets the standard; If the ratio is less than the first preset completion rate and greater than the second preset completion rate, determining whether the completion strategy meets the standard based on the ratio of the number of tasks with malicious virtual machines to the number of tasks sent by users; If the ratio is less than or equal to the second preset completion rate, it is determined that the completion strategy does not meet the standard.
9. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 8 is characterized in that: The process of determining whether the completion strategy meets the standard based on the ratio of the number of tasks with malicious virtual machines to the number of tasks sent by users includes: comparing the ratio with a preset ratio; If the ratio is less than or equal to the preset ratio, it is determined that the completion strategy does not meet the standard; If the ratio is greater than the preset ratio, it is determined that the completion strategy meets the standard, and the preset completion rate is reduced based on the difference between the ratio and the preset ratio, and the difference is proportional to the reduction range of the preset completion rate.
10. The security metric evaluation method for the adaptive collaborative defense mechanism for cloud scenarios according to claim 7 is characterized in that: The evaluation indicators for verifying the effectiveness of the SRN model include: probability of being compromised, task completion time, mean time to failure, and security gain; Among them, the probability of being compromised is the probability of the attack being successfully executed, the average time is the average time from the time the attacking virtual machine does not steal any information to the time when a preset amount of private information is stolen, and the security gain is used to measure the increase in the probability of successful execution of the defense virtual machine task after the defense virtual machine implements the virtual machine migration strategy.
Citation Information
Patent Citations
An Adaptive Mobile Target Defense Method and System for Web Services
CN114244586B