Computing power resource management method, device and equipment
By acquiring multi-source data of the computing power network, using the target risk assessment model to identify threat types and dynamically adjust management strategies, the security and stability issues of the computing power network are solved, efficient utilization and rapid recovery of resources are achieved, and the security and stability of the system are improved.
Patent Information
- Application Number
- CN202511003040.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-21
- Publication Date
- 2025-09-12
AI Technical Summary
The existing computing power network lacks security and stability, and is unable to effectively respond to complex and changing network threats, resulting in reduced resource utilization and damaged service continuity.
By acquiring multi-source data from the computing network, using the target risk assessment model to identify threat types, and dynamically adjusting management strategies based on historical threat types and isolation measures, including isolation measures and recovery strategies, real-time threat detection and dynamic adjustment can be achieved.
It improves the security and stability of the computing network, ensures efficient use of resources, prevents the spread of threats, and quickly restores damaged resources when security incidents occur, ensuring service continuity and security.
Smart Images

Figure CN120639472A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network technology, and in particular to a computing resource management method, device and equipment. Background Art
[0002] With the rapid development of emerging technologies such as big data, cloud computing, and artificial intelligence, the demand for computing resources has exploded. Traditional computing models are no longer able to meet the growing demand for data processing. The emergence of emerging computing models such as distributed and parallel computing has provided new solutions to this problem. Computing networks, as a new computing model, achieve efficient utilization of computing resources by distributing computing tasks across multiple nodes. However, the development of computing networks also brings new challenges, particularly security concerns.
[0003] In a computing network system, once a node is attacked or fails, it may trigger a chain reaction, paralyzing the entire system. Therefore, how to improve the security and stability of the computing network while ensuring the efficient utilization of computing resources has become an important research direction in computing networks.
[0004] In existing technologies, some methods for managing computing resources in computing networks primarily rely on obtaining information about the scenarios in which user devices access the computing network. Based on this information, they then determine the computing resources required for the user devices' ongoing services. This allows them to match computing nodes within the computing network system that meet these requirements. However, these methods primarily focus on the static allocation and management of computing resources, failing to effectively address complex and ever-changing network threats and resulting in insufficient security and stability in the computing network. Summary of the Invention
[0005] The technical problem to be solved by this application is to address the above-mentioned deficiencies in the existing technology and provide a computing power resource management method, device and equipment to solve the problem of insufficient security and stability of the computing power network in the existing technology. It has real-time threat detection and dynamic adjustment capabilities, and can effectively respond to complex and changeable network threats, thereby ensuring the efficient use of computing power resources while improving the security and stability of the computing power network.
[0006] In a first aspect, the present application provides a computing resource management method, the method comprising:
[0007] Obtaining a first threat type corresponding to first multi-source data of a computing power network; the first multi-source data includes first network traffic data, first system logs, and first user behavior data;
[0008] Based on the target risk assessment model, the first threat type is processed to obtain target information corresponding to the computing power network; the target risk assessment model is obtained by training a historical sample set, the historical sample set includes multiple historical samples, the historical samples include historical training data and corresponding historical annotated data, the historical training data includes historical threat types, the historical annotated data includes historical isolation measures and historical threat priorities; the target information includes target isolation measures and target threat priorities;
[0009] Determine target management strategies based on target isolation measures and target threat priorities;
[0010] Execute a target management strategy, which is used to manage computing resources in the computing network.
[0011] In some implementations of the first aspect, obtaining a first threat type corresponding to first multi-source data of a computing power network specifically includes:
[0012] Obtain the first multi-source data of the computing power network;
[0013] Preprocessing the first multi-source data to obtain preprocessed first multi-source data, where the preprocessing includes at least one of data cleaning, data transformation, and data reduction;
[0014] The preprocessed first multi-source data is identified using a decision tree algorithm to obtain a first threat type corresponding to the first multi-source data.
[0015] In some implementations of the first aspect, processing the first threat type based on the target risk assessment model to obtain target information corresponding to the computing power network specifically includes:
[0016] Obtaining first information corresponding to the first threat type, the first information including at least one of first direct loss information, first indirect impact information, a first propagation speed, a first potential spread range, a first importance level, a first location, and a first correlation degree;
[0017] The target risk assessment model is used to process the first information and the first threat type to obtain target information of the computing power network.
[0018] In some embodiments of the first aspect, the target information further includes a target risk score;
[0019] The method further includes:
[0020] Displays the target risk score and target threat priority.
[0021] In some implementations of the first aspect, determining a target management strategy based on the target isolation measures and the target threat priority specifically includes:
[0022] Obtain target factors for the computing network; target factors include at least one of network topology, resource distribution, and business priority;
[0023] Determine target management strategies based on target isolation measures, target threat priorities, and target factors.
[0024] In some embodiments of the first aspect, after executing the management by objectives strategy, the method further comprises:
[0025] Obtain threat status data, resource status data, and environmental change data of the computing network;
[0026] Adjust the target management strategy according to the threat status data, resource status data and environmental change data to obtain an adjusted target management strategy;
[0027] Implement the adjusted target management strategy.
[0028] In some embodiments of the first aspect, after executing the management by objectives strategy, the method further comprises:
[0029] In the event of a security incident being detected, a target recovery strategy is determined based on the pre-set backup and recovery plans; the target recovery strategy includes at least one of the following: the scope of resources to be recovered, the order of recovery, the recovery method, the time required for recovery, and the resources required for recovery; the target recovery strategy is used to recover the damaged computing resources in the computing network;
[0030] Execute a targeted recovery strategy.
[0031] In some implementations of the first aspect, after executing the target recovery strategy, the method further includes:
[0032] Evaluate the recovery effect corresponding to the target recovery strategy and obtain the evaluation result;
[0033] Optimize the target recovery strategy according to the evaluation results to obtain the optimized target recovery strategy;
[0034] Execute the optimized target recovery strategy.
[0035] Based on the same inventive concept, in a second aspect, the present application provides a computing resource management device, which includes:
[0036] A first acquisition module is configured to acquire a first threat type corresponding to first multi-source data of a computing power network; the first multi-source data includes first network traffic data, first system logs, and first user behavior data;
[0037] a first determination module, connected to the first acquisition module, for processing the first threat type based on a target risk assessment model to obtain target information corresponding to the computing power network; the target risk assessment model is obtained by training a historical sample set, the historical sample set includes multiple historical samples, the historical samples include historical training data and corresponding historical annotated data, the historical training data includes historical threat types, the historical annotated data includes historical isolation measures and historical threat priorities; the target information includes target isolation measures and target threat priorities;
[0038] A first determination module, connected to the first processing module, is used to determine a target management strategy based on target isolation measures and target threat priorities;
[0039] The first execution module is connected to the first determination module and is used to execute the target management strategy, which is used to manage computing resources in the computing network.
[0040] Based on the same inventive concept, in a third aspect, the present application provides an electronic device comprising a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to implement the computing power resource management method of the first aspect mentioned above.
[0041] Based on the same inventive concept, in a fourth aspect, the present application provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the computing power resource management method of the first aspect mentioned above is implemented.
[0042] According to the computing power resource management method, device and equipment provided in the embodiment of the present application, the first threat type corresponding to the first multi-source data of the computing power network is first obtained, and then the first threat type is processed based on the target risk assessment model to obtain the target isolation measures and target threat priorities corresponding to the computing power network. Then, according to the target isolation measures and target threat priorities, the target management strategy is determined, and then the target management strategy is executed. The target management strategy is used to manage the computing power resources in the computing power network. That is, in the embodiment of the present application, by obtaining the first threat type and then processing the first threat type based on the target risk assessment model, the target isolation measures and target threat priorities of the computing power resources in the computing power network can be dynamically determined, and then according to the target isolation measures and target threat priorities, the target management strategy is dynamically determined. It has real-time threat detection and dynamic adjustment capabilities, can effectively respond to complex and changeable network threats, thereby ensuring the efficient use of computing power resources while improving the security and stability of the computing power network. In addition, since the target risk assessment model is obtained through historical threat types and historical isolation measures, the target isolation measures obtained by processing the first threat type based on the target risk assessment model can fully consider the historical threat types and their corresponding historical isolation measures, making the obtained target isolation measures more scientific and reasonable. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 A flowchart of a computing resource management method provided in an embodiment of the present application;
[0044] Figure 2 Another flowchart of the computing resource management method provided in the embodiment of the present application;
[0045] Figure 3 A schematic diagram of the structure of a computing resource management device provided in an embodiment of the present application;
[0046] Figure 4 Another structural diagram of the computing power resource management device provided in an embodiment of the present application;
[0047] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0048] In order to enable those skilled in the art to better understand the technical solution of the present application, the implementation methods of the present application will be further described in detail below with reference to the accompanying drawings.
[0049] It should be understood that the specific embodiments and drawings described herein are only used to explain the present application, rather than to limit the present application.
[0050] It can be understood that, in the absence of conflict, the various embodiments and features in the embodiments of the present application can be combined with each other.
[0051] It will be understood that, for the sake of ease of description, the drawings of this application only show the parts related to this application, while the parts not related to this application are not shown in the drawings.
[0052] It can be understood that each unit and module involved in the embodiments of the present application may correspond to only one physical structure, or may be composed of multiple physical structures, or multiple units and modules may be integrated into one physical structure.
[0053] It can be understood that the terms "first", "second", etc. in the embodiments of the present application are used to distinguish different objects, or to distinguish different processing of the same object, rather than to describe a specific order of objects.
[0054] It is understandable that, in the absence of conflict, the functions and steps marked in the flowcharts and block diagrams of the present application may occur in an order different from that marked in the drawings.
[0055] It is understood that the flowcharts and block diagrams of the present application illustrate the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the various embodiments of the present application. Each box in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified functions. Moreover, each box or combination of boxes in the block diagram and flowchart may be implemented by a hardware-based system that implements the specified functions, or by a combination of hardware and computer instructions.
[0056] It can be understood that the units and modules involved in the embodiments of the present application can be implemented by software or hardware, for example, the units and modules can be located in a processor.
[0057] Example 1
[0058] The computing power resource management method provided in the embodiment of the present application can be executed by a computing power resource management device and an electronic device, etc. The following description will be made by taking the computing power resource management method executed by an electronic device as an example.
[0059] like Figure 1 As shown, the computing power resource management method provided in the embodiment of the present application may include steps S110 to S140.
[0060] S110. Obtain a first threat type corresponding to first multi-source data of the computing power network, where the first multi-source data includes first network traffic data, first system log, and first user behavior data.
[0061] S120. Based on the target risk assessment model, the first threat type is processed to obtain target information corresponding to the computing power network; the target risk assessment model is obtained by training a historical sample set, the historical sample set includes multiple historical samples, the historical samples include historical training data and its corresponding historical annotation data, the historical training data includes historical threat types, the historical annotation data includes historical isolation measures and historical threat priorities; the target information includes target isolation measures and target threat priorities.
[0062] S130. Determine the target management strategy based on the target isolation measures and target threat priorities.
[0063] S140. Execute a target management policy, where the target management policy is used to manage computing resources in the computing network.
[0064] According to the computing resource management method provided in the embodiment of the present application, the first threat type corresponding to the first multi-source data of the computing network is first obtained, and then the first threat type is processed based on the target risk assessment model to obtain the target isolation measures and target threat priorities corresponding to the computing network. Then, according to the target isolation measures and target threat priorities, the target management strategy is determined, and then the target management strategy is executed. The target management strategy is used to manage the computing resources in the computing network. That is, in the embodiment of the present application, by obtaining the first threat type and then processing the first threat type based on the target risk assessment model, the target isolation measures and target threat priorities of the computing resources in the computing network can be dynamically determined, and then according to the target isolation measures and target threat priorities, the target management strategy is dynamically determined. It has real-time threat detection and dynamic adjustment capabilities, can effectively respond to complex and changeable network threats, thereby ensuring the efficient use of computing resources while improving the security and stability of the computing network. In addition, since the target risk assessment model is obtained through historical threat types and historical isolation measures, the target isolation measures obtained by processing the first threat type based on the target risk assessment model can fully consider the historical threat types and their corresponding historical isolation measures, making the obtained target isolation measures more scientific and reasonable.
[0065] The specific implementation methods of the above steps are introduced below.
[0066] In step S110, the computing power network may be any computing power network that requires computing power resource management.
[0067] Exemplarily, the first network traffic data includes key information such as the size, rate, protocol type, source address, and destination address of data packets entering and leaving the network.
[0068] Exemplarily, the first system log includes key events such as system startup, shutdown, error reporting, and permission changes.
[0069] Exemplarily, the first user behavior data includes specific behaviors such as user login, operation, and resource access.
[0070] Exemplarily, the first threat type includes one of network attack, virus intrusion, and abnormal behavior.
[0071] Exemplarily, the first network traffic data, the first system log, and the first user behavior data may be collected in real time through a monitoring agent deployed on a network node.
[0072] In some embodiments, obtaining a first threat type corresponding to first multi-source data of a computing power network specifically includes:
[0073] Obtain the first multi-source data of the computing power network;
[0074] Preprocessing the first multi-source data to obtain preprocessed first multi-source data, where the preprocessing includes at least one of data cleaning, data transformation, and data reduction;
[0075] The preprocessed first multi-source data is identified using a decision tree algorithm to obtain a first threat type corresponding to the first multi-source data.
[0076] As an example, preprocessing includes data cleaning; as another example, preprocessing includes data cleaning and data transformation; as yet another example, preprocessing includes data transformation and data reduction.
[0077] It is understandable that the collected first multi-source data often contains a large amount of redundancy, noise, and incomplete information, and therefore requires preprocessing. In this embodiment, by preprocessing the first multi-source data to obtain preprocessed first multi-source data, and using a decision tree algorithm to identify the preprocessed first multi-source data, the accuracy of the first threat type corresponding to the first multi-source data can be improved.
[0078] For example, data cleaning includes removing duplicate data, filling missing values, processing outliers, etc.; data transformation includes converting raw data into a form more suitable for analysis, such as encoding categorical data into numerical data; data reduction includes reducing the difficulty of analysis by compressing the data size while retaining the essential characteristics of the data as much as possible.
[0079] Exemplarily, first multi-source data of the computing power network can be acquired in real time so as to monitor threats in the computing power network in real time.
[0080] For example, a decision tree algorithm is used to identify the pre-processed first multi-source data to timely discover and identify potential security threats. Once a threat is detected, an alert is immediately generated and threat information is transmitted.
[0081] Exemplarily, the information gain formula in the decision tree algorithm includes:
[0082]
[0083] Where IG(D,A) represents the information gain of attribute A on data set D, that is, the uncertainty reduction after using attribute A to divide data set D; D represents the data set; A represents the attribute; V(A) represents all possible values of attribute A; D m represents the subset of the dataset D whose attribute A has a value of m; |D m | represents subset D m The number of samples in the dataset D; |D| represents the number of samples in the dataset D; E(D) represents the entropy of the dataset D, and entropy represents the uncertainty of the dataset; E(D m ) represents the dataset D m Entropy; Dataset D represents the entire dataset used for analysis, corresponding to the preprocessed data set. It is formed by cleaning, transforming, and reducing multiple sources of data, such as network traffic, system logs, and user behavior. Attribute A represents the feature field used for segmentation in Dataset D, which serves as the classification basis for the decision tree. It corresponds to specific feature dimensions in the preprocessed data, such as "protocol type" (e.g., Transmission Control Protocol (TCP), User Datagram Protocol (UDP)) and "source IP address anomaly" in network traffic; "event type" (e.g., permission change, error report) and "event frequency" in system logs; and "operation frequency" and "number of unauthorized resource accesses" in user behavior. Each attribute A has multiple possible values V(A). For example, the value of "protocol type" is {TCP, UDP, ICMP}. The decision tree algorithm determines the optimal splitting feature by calculating the information gain of different attributes, and then classifies the threat type. ICMP stands for Internet Control Message Protocol.
[0084] In step S120, after obtaining the first threat type corresponding to the first multi-source data of the computing power network, the electronic device may also process the first threat type based on the target risk assessment model to obtain target information corresponding to the computing power network.
[0085] Exemplarily, the target risk assessment model may be a model that can process the first threat type and obtain target information corresponding to the computing power network.
[0086] In some examples, the target information includes target isolation measures and target threat priority. In other examples, the target information also includes a target risk score.
[0087] Exemplarily, the targeted isolation measures include at least one of closing the compromised port, restricting network access, and isolating the infected device. For example, the compromised port could be TCP port 55; restricting network access could be disabling access to a specific Internet Protocol (IP) segment; and isolating the infected device could be migrating the server from the production network to a quarantine zone.
[0088] In some implementations, based on the target risk assessment model, the first threat type is processed to obtain target isolation measures corresponding to the computing power network, specifically including:
[0089] Obtaining first information corresponding to the first threat type, the first information including at least one of first direct loss information, first indirect impact information, a first propagation speed, a first potential spread range, a first importance level, a first location, and a first correlation degree;
[0090] The target risk assessment model is used to process the first information and the first threat type to obtain target information of the computing power network, where the target information includes target isolation measures corresponding to the first multi-source data.
[0091] Exemplarily, the first direct loss information is the direct loss of the first threat type to key assets such as systems, data, and users, such as the amount of data leakage and the service interruption time; the first indirect impact information may be the indirect impact of the first threat type on key assets such as systems, data, and users, such as damage to business continuity and damage to corporate reputation; the first propagation speed is the propagation speed of the first threat type in the computing power network, such as the number of infected nodes per minute; the first potential spread range may be the potential spread range of the first threat type in the computing power network, such as the regional computing power domain that may be affected; the first importance level may be the importance level of the threatened computing power resources, such as core business servers and edge computing nodes; the first position may be the position of the computing power resources in the network topology; the first degree of association may be the degree of association of the computing power resources in the network topology.
[0092] As an example, the first information includes first direct loss information; as another example, the first information includes first indirect impact information and first propagation speed; as yet another example, the first information includes first direct loss information, first indirect impact information, first propagation speed, first potential spread range, first importance level, first location and first degree of association.
[0093] For example, the target risk assessment model first processes the first information and the first threat information based on the Common Vulnerabilities and Exposures (CVE) score and the Common Vulnerability Scoring System (CVSS) score to obtain a target risk score. The target threat priority is then determined based on the target risk score. The target isolation measures are then determined based on the first threat type and the first information. CVE can reflect the severity of the vulnerability; CVSS scores can cover dimensions such as attack vectors, complexity, and impact, with a common range of 0-10 points; the target risk score can be a standardized risk score; and the target threat priority can be used to characterize the order in which the first threat type is processed. The higher the target threat priority, the higher the order in which it is processed. For example, high-risk threats (such as remote code execution vulnerabilities) are prioritized, while low-risk threats (such as configuration vulnerabilities in non-critical services) can be postponed.
[0094] For example, the mapping principle between CVSS score range and threat priority is shown in Table 1.
[0095] Table 1
[0096]
[0097] For example, when the first threat type is a network attack (such as port scanning, weak password cracking, service vulnerability exploitation), the threat relies on specific ports for communication or penetration (such as TCP 22 / 3389 remote control port, User Datagram Protocol (UDP) 53 Domain Name System (DNS) port), and the impact range is a single device or a local network (such as 3-5 servers in the same subnet), the target isolation measure is to close the threatened port; when the first threat type is a network attack (such as Distributed Denial of Service (DDoS) attack, high-frequency access of malicious IP) or abnormal behavior (such as unauthorized data crawling, illegal Application Programming Interface (API) call), the threat is characterized by spreading through network traffic or connection rules (such as cross-segment scanning, protocol abnormal traffic), and the impact range is a regional network (such as Virtual Local Area Network (VLAN)). When the primary threat type is a server cluster within a specific network (VLAN), or a business network segment), the target isolation measures include restricting network access. If the primary threat type is a virus intrusion (such as ransomware or worms) or abnormal behavior (such as botnet nodes or data tampering devices), and the device is controlled by a malicious program and actively spreads (such as scanning LAN IP addresses, encrypting shared files, or sending junk traffic), and the impact range is a local network (such as more than 10 devices on the same switch) or specific resources (such as shared storage or business databases), the target isolation measures include isolating the infected device.
[0098] It should be noted that the data in Table 1 are for illustration only and are not intended to limit this application.
[0099] Exemplarily, the historical training data also includes historical information, which includes at least one of historical direct loss information, historical indirect impact information, historical transmission speed, and historical potential spread range; the historical annotation data also includes historical risk scores.
[0100] Exemplarily, historical direct loss information refers to the direct losses caused by historical threat types to key assets such as systems, data, and users, such as the amount of data leakage and service interruption time; historical indirect impact information may be the indirect impact of historical threat types on key assets such as systems, data, and users, such as damage to business continuity and damage to corporate reputation; historical propagation speed refers to the propagation speed of historical threat types in the computing power network, such as the number of infected nodes per minute; historical potential spread range may be the potential spread range of historical threat types in the computing power network, such as the regional computing power domain that may be affected; historical importance level may be the importance level of computing power resources affected by historical threats, such as core business servers and edge computing nodes; historical location may be the historical location of computing power resources in the network topology; historical correlation degree may be the historical correlation degree of computing power resources in the network topology.
[0101] It is understandable that historical information corresponds to the first information. For example, when the historical information includes historical direct loss information, the first information includes the first direct loss information; for another example, when the historical information includes the historical propagation speed and the historical potential diffusion range, the first information includes the first propagation speed and the first potential diffusion range; for another example, when the historical information includes historical direct loss information, historical indirect impact information, historical propagation speed and historical potential diffusion range, the first information includes the first direct loss information, the first indirect impact information, the first propagation speed and the first potential diffusion range.
[0102] In some examples, the target information also includes a target risk score;
[0103] The method further includes:
[0104] Displays the target risk score and target threat priority.
[0105] In this example, the target risk score and target threat priority are displayed in the form of quantitative indicators to guide subsequent isolation and recovery operations. This allows for timely detection and response to potential security threats, effectively preventing the spread and proliferation of threats and improving system security.
[0106] In step S130, after the electronic device processes the first threat type based on the target risk assessment model and obtains the target information corresponding to the computing power network, it can also determine the target management strategy based on the target isolation measures and target threat priority.
[0107] For example, based on the target isolation measures and the target threat priority, a target management strategy is determined, specifically including:
[0108] Obtain target factors for the computing network; target factors include at least one of network topology, resource distribution, and business priority;
[0109] Determine target management strategies based on target isolation measures, target threat priorities, and target factors.
[0110] In this embodiment, target threat priorities and target isolation measures are combined with target factors to formulate a target management strategy. This strategy can be flexibly adjusted according to the severity of the threat and resource needs to ensure the effective use of resources and avoid waste and idleness of resources. For high-risk resources, they can be isolated from the network and their communication with other resources can be restricted. For low-risk resources, a more relaxed strategy can be adopted to ensure the effective use of resources. At the same time, the embodiments of this application use automated and intelligent management methods to reduce the workload and operation and maintenance costs of operation and maintenance personnel, and improve the operation and maintenance efficiency and reliability of the system.
[0111] Exemplarily, the target management policy may be an optimal isolation policy, which may include at least one of modifying network access control rules and adjusting resource allocation policies;
[0112] Exemplarily, modifying network access control rules includes adding access control list (ACL) rules and adjusting firewall configurations; adjusting resource allocation strategies includes suspending access rights to threatened computing resources and reallocating resources.
[0113] For example, in an embodiment of the present application, the objective function and constraints of the linear programming for the optimization algorithm of resource allocation and target management strategy are as follows:
[0114]
[0115] x i ≥0,i=1,2,...,n1
[0116] Where Z represents the objective function, i.e. the total value of resource allocation; c i represents the value coefficient of resource i; x i represents the allocation amount of resource i; a ij represents the coefficient in the constraint condition, that is, the degree of influence of resource i on constraint j; b j It represents the upper bound of the constraint, that is, the restriction of constraint j on resource allocation; max represents the maximum value operation; n1 represents the number of resource types; n2 represents the number of constraints.
[0117] In step S140 , after determining the target management policy according to the target isolation measures and the target threat priority, the electronic device may also execute the target management policy.
[0118] For example, automated tools and methods, such as script execution, API calls, etc., can be used to quickly and accurately execute target management policies.
[0119] In some embodiments, after executing the target management strategy, the method further comprises:
[0120] Obtain threat status data, resource status data, and environmental change data of the computing network;
[0121] Adjust the target management strategy according to the threat status data, resource status data and environmental change data to obtain an adjusted target management strategy;
[0122] Implement the adjusted target management strategy.
[0123] For example, threat status data may include dynamic changes in CVSS scores (such as the score rising from 7.0 to 9.0 after the vulnerability exploit code is made public), threat propagation speed (such as the number of infected nodes increasing by 50% within 10 minutes), and changes in attack source IP (from a single IP to a distributed attack).
[0124] For example, resource status data may include computing resource utilization (such as the CPU occupancy rate of the isolation area server exceeds 80%), business continuity indicators (such as core business delay exceeds the threshold), and resource association relationships (such as whether the isolated device is a dependent node for critical business).
[0125] For example, environmental change data may include dynamic adjustments to network topology (such as newly connected edge node clusters), changes in business priorities (such as sudden high-priority computing tasks), and updates to compliance requirements (such as upgrades to data privacy protection policies).
[0126] Exemplarily, the target management policy is adjusted according to the threat status data, resource status data, and environmental change data to obtain an adjusted target management policy, which may specifically include the following contents.
[0127] 1. Implement a three-level dynamic adjustment mechanism:
[0128] 1. Enhanced isolation when the threat escalates (e.g., CVSS score ≥ 9.0 and resource importance is high):
[0129] (1) Upgrading from "restricting network access" to "isolating devices," for example, migrating a database server infected with ransomware from the business VLAN to a physically isolated security sandbox, while automatically triggering a standby database to take over the business through an API.
[0130] (2) Adjust the objective function of the linear programming model, increase the weight of "threat spread risk" from 0.4 to 0.7, and give priority to meeting the constraints of blocking propagation (such as forcibly disconnecting all network connections of infected devices).
[0131] 2. Policy relaxation when the threat is downgraded (e.g., the CVSS score drops below 4.0 after the vulnerability is patched):
[0132] (1) Gradually lift isolation: switch from “complete isolation” to “port-level restriction”, for example, open port 80 / 443 of the isolated web server, but restrict access to only trusted IP addresses through ACL rules.
[0133] (2) Resource reallocation: Servers in the isolation zone with utilization rates below 30% are re-incorporated into the resource pool, and resource allocation strategies are modified through automated scripts to balance the computing task load.
[0134] 3. Strategy optimization when resources are tight (e.g., computing cluster utilization rate reaches over 95%):
[0135] (1) Dynamically divide the isolation granularity: Adjust "device-level isolation" to "process-level isolation" and use containerization technology to limit the threatened application process to a specific resource group to avoid occupying the entire server resources.
[0136] (2) Introducing a priority preemption mechanism: If core business resources are insufficient, temporarily reduce the isolation scope of low-priority threats (such as closing only non-critical ports instead of isolating the entire device) to ensure resource quotas for high-value businesses.
[0137] 2. Closed-loop optimization strategy:
[0138] 1. Effect evaluation indicators:
[0139] Isolation effectiveness: growth rate of infected nodes (ideal value ≤ 0%), threat spread time (time interval from detection to isolation ≤ 1 minute).
[0140] Resource efficiency: isolation zone resource utilization (target 60%-80%), business interruption duration (core business ≤ 5 minutes / time).
[0141] 2. Adaptive Optimization:
[0142] (1) When “over-isolation” (such as isolating uninfected associated devices) is detected three times in a row, the evaluation weight of the resource association relationship is automatically reduced; if the threat spread is missed, the monitoring sensitivity of the propagation speed indicator is improved.
[0143] (2) Combined with reinforcement learning algorithms, the optimal strategies (such as bandwidth limitation thresholds for DDoS attacks and isolation radius for worm viruses) are learned from historical adjustment cases, and the constraints of the linear programming model are dynamically updated.
[0144] Exemplarily, the target management policy adjustment for the worm virus scenario includes:
[0145] Initial state: A computing node is infected with a worm (CVSS 8.5, with the impact scope expanding rapidly), and device-level isolation is immediately performed (all network connections are disconnected), and the resource utilization rate of the isolation area rises to 90%; resource shortage triggers adjustment: it is detected that the core business is stuck due to insufficient resources, and the adjustment is made to "process-level isolation" (only blocking network access of worm-related processes), releasing 80% of the device resources back to the pool, and at the same time restricting the outbound traffic of the device through the firewall ACL to balance the isolation effect and resource utilization; after the threat is eliminated: the CVSS score drops to 0, all isolations are lifted, and grayscale monitoring is included (such as continuous 24-hour monitoring of abnormal traffic) to ensure that resources are fully reused and there is no residual risk; through the above mechanism, the target management strategy can dynamically balance threat containment and resource efficiency to achieve the goals of precise isolation, on-demand release, and intelligent reuse.
[0146] In other words, the isolation level of computing resources is automatically adjusted based on target information. By dynamically adjusting network access control and resource allocation strategies, threatened resources are isolated from other resources to prevent the spread of threats. Simultaneously, target management strategies are adjusted in real time based on evolving threats and resource demands to ensure efficient utilization of computing resources.
[0147] For example, after the optimal isolation strategy (i.e., the target management strategy) is executed, it is necessary to continuously monitor the isolation effect (i.e., repeatedly execute steps S110 to S120) and adjust the strategy in real time based on changes in threats and resource requirements. This includes regularly evaluating the effectiveness of the target management strategy, such as checking whether the threatened resources have been successfully isolated and whether the isolation has caused unnecessary impact on normal business operations; and timely adjusting the target management strategy based on new threat information or resource requirements, such as adding new isolation paths and adjusting isolation levels. Utilizing a real-time monitoring and feedback mechanism ensures the dynamic and flexible nature of the target management strategy.
[0148] After extensive research, the inventors discovered that while some computing network system operating methods can monitor and manage computing resources, they lack the ability to respond to and recover from security incidents. For example, when a security incident is detected, the system often only implements simple isolation measures, failing to dynamically adjust based on the severity of the threat and the actual resource situation. This results in reduced resource utilization and impaired service continuity.
[0149] Based on this, in some embodiments, after executing the target management strategy, the method further includes:
[0150] In the event of a security incident being detected, a target recovery strategy is determined based on the pre-set backup and recovery plans; the target recovery strategy includes at least one of the following: the scope of resources to be recovered, the order of recovery, the recovery method, the time required for recovery, and the resources required for recovery; the target recovery strategy is used to recover the damaged computing resources in the computing network;
[0151] Execute a targeted recovery strategy.
[0152] In this embodiment, when a security incident is detected, a target recovery strategy is determined and executed based on pre-set backup and recovery plans. This means that when a security incident occurs, the backup and recovery mechanisms are immediately activated, restoring damaged resources to a normal state using pre-configured backup strategies and recovery processes. Furthermore, based on historical data and experience, the recovery strategy can be continuously optimized to improve recovery efficiency and accuracy.
[0153] Exemplarily, the recovery method includes one of full recovery and incremental recovery.
[0154] In other words, in the event of a security incident, pre-defined backup strategies and recovery plans are utilized to ensure that recovery processes can be initiated quickly to quickly restore affected resources. Through backup and recovery mechanisms, damaged resources can be restored to a normal state, ensuring the continuity and stability of computing power services. Furthermore, recovery strategies can be optimized based on historical data and experience to improve recovery efficiency and accuracy.
[0155] For example, after developing a recovery strategy, recovery operations are immediately executed (i.e., executing the target recovery strategy). This includes restoring damaged resources from backups, repairing damaged system components, and reconstructing lost data. Automated recovery tools and methods, such as backup software and virtual machine snapshots, are utilized to quickly and accurately execute recovery operations. Key recovery information, such as recovery time, recovery status, and recovery results, can also be recorded for subsequent analysis and optimization.
[0156] In some embodiments, after executing the target recovery strategy, the method further includes:
[0157] Evaluate the recovery effect corresponding to the target recovery strategy and obtain the evaluation result;
[0158] Optimize the target recovery strategy according to the evaluation results to obtain the optimized target recovery strategy;
[0159] Execute the optimized target recovery strategy.
[0160] For example, the recovery effectiveness of the target recovery strategy is evaluated, including whether the restored resources have resumed normal operation and whether business continuity and stability have been restored. The recovery process is also evaluated to determine whether there are any problems or deficiencies, such as excessive recovery time or incomplete recovery results. Based on the evaluation results, the target recovery strategy is further optimized, such as by improving backup strategies and optimizing recovery processes, to improve recovery efficiency and accuracy.
[0161] This section involves the optimization algorithm of the recovery strategy. The formula for minimizing the recovery time is:
[0162]
[0163] Where T represents the total recovery time, that is, the total time required to recover all resources; t i represents the recovery time of resource i, that is, the time required for resource i to recover from a damaged state to a normal state; n1 represents the number of resource types.
[0164] In order to better understand the computing power resource management method provided in the embodiment of the present application, a specific implementation method is described below.
[0165] like Figure 2 As shown, the computing power resource management method provided in the embodiment of the present application includes steps S1 to S4.
[0166] S1. Through detection agents deployed on network nodes, network traffic, system logs, and user behavior data are collected in real time. Machine learning algorithms are applied to analyze and identify the data to promptly detect and report potential security threats.
[0167] S2. Receive identified and transmitted threat data, apply risk assessment models to assess the severity, scope of impact, and resource importance of the threat, and express the assessment results in the form of quantitative indicators to guide subsequent isolation and recovery operations;
[0168] S3. Dynamically adjust network access control policies and resource allocation strategies. For high-risk resources, isolate them from the network and restrict their communication with other resources. For low-risk resources, adopt a more relaxed strategy to ensure efficient resource utilization.
[0169] S4. When a security incident occurs, the backup and recovery mechanism is immediately activated. Through pre-configured backup strategies and recovery processes, the damaged resources are restored to normal state. Based on historical data and experience, the recovery strategy is continuously optimized to improve recovery efficiency and accuracy.
[0170] The embodiments of the present application improve upon the existing technology which focuses on the static allocation and management of computing resources, lacks the ability of real-time threat detection and dynamic adjustment, and cannot effectively respond to complex and changing network threats, resulting in problems such as decreased resource utilization and impaired service continuity. The embodiments of the present application, based on real-time threat detection and risk assessment results, automatically adjust the isolation level of computing resources, and can quickly restore affected resources in the event of a security incident, thereby ensuring the continuity and security of computing services.
[0171] Step 1: Real-time monitoring of threats in the computing network
[0172] Monitor various threats in the computing network, including network attacks, virus intrusions, abnormal behavior, etc. By collecting and analyzing network traffic, system logs, user behavior and other data, potential security threats can be discovered and identified in a timely manner.
[0173] 1. Data Collection
[0174] First, comprehensive data collection from multiple sources, including network traffic, system logs, and user behavior, is required. Network traffic data includes key information such as the size, rate, protocol type, source address, and destination address of packets entering and leaving the network. System logs include key events such as system startup and shutdown, error reports, and permission changes. User behavior data includes specific actions such as user logins, operations, and resource access.
[0175] 2. Data preprocessing
[0176] Collected raw data often contains a significant amount of redundancy, noise, and incomplete information, necessitating preprocessing before analysis. Data preprocessing includes data cleaning, data transformation, and data reduction. Data cleaning involves removing duplicate data, filling in missing values, and addressing outliers. Data transformation involves converting raw data into a form more suitable for analysis, such as encoding categorical data into numerical data. Data reduction involves compressing the data to reduce the difficulty of analysis while preserving the data's essential characteristics.
[0177] 3. Threat Detection and Identification
[0178] Decision tree algorithms are used to conduct in-depth analysis of pre-processed data to promptly identify and detect potential security threats. These threats may include network attacks, virus intrusions, and abnormal behavior. Once a threat is detected, an alert is immediately generated and the threat information is transmitted.
[0179] Information gain formula in decision tree algorithm:
[0180]
[0181] Where IG(D,A) represents the information gain of attribute A on data set D, that is, the uncertainty reduction after using attribute A to divide data set D; D represents the data set; A represents the attribute; V(A) represents all possible values of attribute A; D m represents the subset of the dataset D whose attribute A has a value of m; |D m | represents subset D m The number of samples in the dataset D; |D| represents the number of samples in the dataset D; E(D) represents the entropy of the dataset D, and entropy represents the uncertainty of the dataset; E(D m ) represents the dataset D m entropy.
[0182] Dataset D represents the overall data set used for analysis, which corresponds to the preprocessed data set. It is formed by cleaning, transforming, and reducing multi-source data such as network traffic, system logs, and user behavior.
[0183] Attribute A represents the feature field used for segmentation in dataset D, that is, the classification basis of the decision tree, which corresponds to the specific feature dimensions in the preprocessed data, for example: "protocol type" (such as TCP, UDP) and "abnormality of the source IP address" in network traffic; "event type" (such as permission change, error report) and "event frequency" in system logs; "operation frequency" and "number of accesses to unauthorized resources" in user behavior.
[0184] Each attribute A has multiple possible values V(A). For example, the value of "protocol type" is {TCP, UDP, ICMP}. The decision tree algorithm calculates the information gain of different attributes to determine the optimal splitting feature and then classify the threat type.
[0185] Step 2: Threat Risk Assessment
[0186] Receive identified and transmitted security threat data and assess the severity, impact, and resource importance of the threat. Through comprehensive analysis, determine the threat priority and the necessary isolation measures.
[0187] 1. Threat Impact Analysis
[0188] After receiving threat data, a risk assessment model (i.e., a target risk assessment model) allows for an in-depth analysis of the severity and scope of the threat. This includes assessing the potential direct losses and indirect impacts on key assets such as systems, data, and users, as well as the speed and potential scope of the threat's spread within the computing network. Risk assessment tools and methods, such as CVE and CVSS scores, are then used to quantitatively assess the threat.
[0189] The inputs to the risk assessment model are:
[0190] 1. Threat types identified in step 1.
[0191] 2. The direct losses (e.g., amount of data leaked, duration of service interruption) and indirect impacts (e.g., loss of business continuity, loss of corporate reputation) caused by the threat type to key assets such as systems, data, and users. The speed at which the threat propagates within the computing network (e.g., number of infected nodes per minute) and its potential spread (e.g., regional computing domains that may be affected) should be considered.
[0192] 3. The importance level of the threatened resources (such as core business servers, edge computing nodes), the location of the resources in the network topology, and the degree of relevance.
[0193] The model output is:
[0194] 1. Threat Quantification Index: A standardized risk score generated based on the CVE score (reflecting vulnerability severity) / CVSS score (covering dimensions such as attack vector, complexity, and impact, with a common range of 0-10 points).
[0195] 2. Threat prioritization: Determine the order of threat handling based on the risk score. For example, high-risk threats (such as remote code execution vulnerabilities) are handled first, while low-risk threats (such as configuration vulnerabilities in non-critical services) can be postponed.
[0196] 3. Isolation measures recommendations: Based on the threat type and impact scope, output specific action plans, such as closing the threatened port (such as TCP port 445), restricting network access (such as prohibiting access to a certain IP segment), and isolating infected devices (such as migrating the server from the production network to an isolation area).
[0197] Risk assessment model training process
[0198] 1. Data collection and annotation
[0199] Collect historical security incident data, including threat type, impact scope, handling results, etc., and mark the CVE / CVSS score and actual impact consequences of each type of threat.
[0200] Combined with the characteristics of computing power networks, additional resource importance marking is added (such as dividing server importance levels according to business priorities).
[0201] 2. Model construction and calibration
[0202] Taking the CVE / CVSS scoring system as the basic framework, the evaluation dimensions of computing power network (such as the position weight of the node in the network topology and business continuity dependency) are introduced to construct a weighted evaluation model.
[0203] Use historical data to verify the matching degree between the priority of the model output and the actual processing effect, and adjust the weight parameters (such as increasing the risk weight of core business resources).
[0204] 3. Continuous optimization mechanism
[0205] Regularly update the CVE vulnerability database and CVSS scoring standards to ensure that the model is synchronized with the latest security threat definitions.
[0206] Based on feedback from new security incidents, optimize the evaluation dimensions. For example, in DDoS attack scenarios, add "abnormal traffic growth rate" as an evaluation parameter.
[0207] Here we take the case where a computing node is detected to be attacked by ransomware as an example:
[0208] 1. Input data:
[0209] Threat Type: Virus Invasion (Ransomware), Impact: Business data stored on this node, Spread Speed: Rapidly spreads via network sharing. Resource Importance: This node hosts a core business database and is a high-priority resource.
[0210] 2. Model evaluation:
[0211] The CVSS scoring model was used to calculate the attack vector (network accessible), complexity (low), and impact (loss of data integrity), resulting in a score of 9.0 (high risk).
[0212] Taking into account the importance of resources, the weighted risk value increases to 9.5, which is determined to be the highest priority threat.
[0213] 3. Output results:
[0214] Priority: Immediate processing.
[0215] Isolation measures (i.e. target isolation measures): disconnect the node's network connection, start the backup server to take over the business, and perform integrity verification on the backup data.
[0216] 2. Determine priorities and isolation measures
[0217] Based on the results of the threat impact analysis, the threat priority is further determined. At the same time, specific isolation measures (i.e., targeted isolation measures) can be formulated based on the type, characteristics, and scope of the threat. These measures may include closing the threatened port, restricting network access, and isolating infected devices or resources.
[0218] 1. If the threat type is a network attack (such as port scanning, weak password cracking, service vulnerability exploitation), the threat relies on specific ports for communication or penetration (such as TCP 22 / 3389 remote control port, UDP 53DNS port), and the scope of impact is a single device or a local network (such as 3-5 servers in the same subnet), take measures to close the port.
[0219] 2. When the threat type is a network attack (such as a DDoS attack, high-frequency access from malicious IP addresses) or abnormal behavior (such as unauthorized data crawling, illegal API calls), the threat is characterized by spreading through network traffic or connection rules (such as cross-segment scanning, abnormal protocol traffic), and the impact range is a regional network (such as a server cluster within a VLAN, a certain business network segment), adopt measures to restrict network access.
[0220] 3. If the threat type is a virus intrusion (such as ransomware, worm virus) or abnormal behavior (such as botnet nodes, data tampering devices), the characteristics are that the device has been controlled by a malicious program and is actively spreading (such as scanning LAN IP addresses, encrypting shared files, and sending junk traffic), and the scope of impact is a local network (such as more than 10 devices under the same switch) or specific resources (such as shared storage, business databases), then implement device isolation measures.
[0221] Step 3: Automatically adjust the isolation level of computing resources
[0222] Automatically adjust the isolation level of computing resources based on the assessment results. By dynamically adjusting network access control and resource allocation strategies, the threatened resources are isolated from other resources to prevent the spread of threats.
[0223] 1. Development of Isolation Strategy (i.e., Target Management Strategy)
[0224] Based on threat priority and isolation measures, optimal isolation strategies should be developed, taking into account factors such as network topology, resource distribution, and service priorities. These strategies should ensure that the impact on normal services is minimized while effectively isolating threatened resources.
[0225] 2. Isolation policy execution
[0226] After determining the optimal isolation strategy, automated tools and methods, such as script execution and API calls, are used to quickly and accurately execute these strategies. Specifically, the optimal isolation strategy includes modifying network access control rules, such as adding ACL (access control list) rules and adjusting firewall configurations; and adjusting resource allocation strategies, such as suspending access rights to threatened resources and reallocating resources.
[0227] This part involves the optimization algorithm of resource allocation and isolation strategy. The objective function and constraints of linear programming are:
[0228]
[0229] x i ≥0,i=1,2,...,n1
[0230] Where Z represents the objective function, i.e. the total value of resource allocation; c i represents the value coefficient of resource i; x i represents the allocation amount of resource i; a ij represents the coefficient in the constraint condition, that is, the degree of influence of resource i on constraint j; b j It represents the upper bound of the constraint, i.e. the restriction of constraint j on resource allocation; max represents the maximum value operation; n1 represents the number of resource types; n2 represents the number of constraints;
[0231] 3. Isolation strategy monitoring and adjustment
[0232] After implementing the optimal isolation strategy, it's necessary to continuously monitor its effectiveness and adjust the strategy in real time based on evolving threats and resource demands. This includes regularly evaluating the effectiveness of the isolation strategy, such as checking whether the threatened resources have been successfully isolated and whether isolation has unnecessarily impacted normal operations. Based on new threat information or resource demands, the isolation strategy can be adjusted promptly, such as by adding new isolation paths or adjusting the isolation level. Real-time monitoring and feedback mechanisms ensure the dynamic and flexible nature of the isolation strategy.
[0233] At the same time, isolation strategies are adjusted in real time based on threat changes and resource requirements to ensure efficient resource utilization. Specifically, this includes:
[0234] 1. Build adjustment basis through real-time collection of three types of data:
[0235] 1. Threat status data: This includes dynamic changes in CVSS scores (e.g., the score increased from 7.0 to 9.0 after the exploit code was released), threat propagation speed (e.g., the number of infected nodes increased by 50% within 10 minutes), and changes in attack source IP addresses (from a single IP address to a distributed attack).
[0236] 2. Resource status data: computing resource utilization (such as the CPU occupancy rate of the isolated zone server exceeding 80%), business continuity indicators (such as core business delay exceeding the threshold), and resource association relationships (such as whether the isolated device is a dependent node for critical business).
[0237] 3. Environmental change data: dynamic adjustments to network topology (such as newly connected edge node clusters), changes in business priorities (such as sudden high-priority computing tasks), and updates to compliance requirements (such as upgrades to data privacy protection policies).
[0238] 2. Implement a three-level dynamic adjustment mechanism based on the coupling relationship between threat level and resource demand:
[0239] 1. Enhanced isolation when the threat escalates (e.g., CVSS score ≥ 9.0 and resource importance is high):
[0240] (1) Upgrading from "restricting network access" to "isolating devices," for example, migrating a database server infected with ransomware from the business VLAN to a physically isolated security sandbox, while automatically triggering a standby database to take over the business through an API.
[0241] (2) Adjust the objective function of the linear programming model, increase the weight of "threat spread risk" from 0.4 to 0.7, and give priority to meeting the constraints of blocking propagation (such as forcibly disconnecting all network connections of infected devices).
[0242] 2. Policy relaxation when the threat is downgraded (e.g., the CVSS score drops below 4.0 after the vulnerability is patched):
[0243] (1) Gradually lift isolation: switch from “complete isolation” to “port-level restriction”, for example, open port 80 / 443 of the isolated web server, but restrict access to only trusted IP addresses through ACL rules.
[0244] (2) Resource reallocation: Servers in the isolation zone with utilization rates below 30% are re-incorporated into the resource pool, and resource allocation strategies are modified through automated scripts to balance the computing task load.
[0245] 3. Strategy optimization when resources are tight (e.g., computing cluster utilization rate reaches over 95%):
[0246] (1) Dynamically divide the isolation granularity: Adjust "device-level isolation" to "process-level isolation" and use containerization technology to limit the threatened application process to a specific resource group to avoid occupying the entire server resources.
[0247] (2) Introducing a priority preemption mechanism: If core business resources are insufficient, temporarily reduce the isolation scope of low-priority threats (such as closing only non-critical ports instead of isolating the entire device) to ensure resource quotas for high-value businesses.
[0248] 3. Closed-loop optimization strategy:
[0249] 1. Effect evaluation indicators:
[0250] Isolation effectiveness: growth rate of infected nodes (ideal value ≤ 0%), threat spread time (time interval from detection to isolation ≤ 1 minute).
[0251] Resource efficiency: isolation zone resource utilization (target 60%-80%), business interruption duration (core business ≤ 5 minutes / time).
[0252] 2. Adaptive Optimization:
[0253] (1) When “over-isolation” (such as isolating uninfected associated devices) is detected three times in a row, the evaluation weight of the resource association relationship is automatically reduced; if the threat spread is missed, the monitoring sensitivity of the propagation speed indicator is improved.
[0254] (2) Combined with reinforcement learning algorithms, the optimal strategies (such as bandwidth limitation thresholds for DDoS attacks and isolation radius for worm viruses) are learned from historical adjustment cases, and the constraints of the linear programming model are dynamically updated.
[0255] Example: Policy adjustment for a worm virus scenario:
[0256] Initial state: A computing node is infected with a worm (CVSS 8.5, with the impact rapidly expanding). Device-level isolation is immediately performed (all network connections are disconnected), and the resource utilization rate of the isolation area rises to 90%.
[0257] Adjustments triggered by resource shortages: When it was detected that core business was stalled due to insufficient resources, the system switched to "process-level isolation" (blocking only network access for worm-related processes), releasing 80% of the device resources back to the pool. At the same time, the outbound traffic of the device was restricted through the firewall ACL to balance the isolation effect and resource utilization.
[0258] After the threat is eliminated: the CVSS score drops to 0, all isolations are lifted, and grayscale monitoring is included (such as continuous 24-hour monitoring of abnormal traffic) to ensure that resources are fully reused and there is no residual risk.
[0259] Through the above mechanism, the isolation strategy can dynamically strike a balance between threat containment and resource efficiency, achieving the goals of precise isolation, on-demand release, and intelligent reuse.
[0260] Step 4: Quickly restore affected resources
[0261] In the event of a security incident, affected resources are quickly restored. Through backup and recovery mechanisms, damaged resources are restored to their normal state, ensuring the continuity and stability of computing services. Furthermore, recovery strategies can be optimized based on historical data and experience to improve recovery efficiency and accuracy.
[0262] 1. Backup and recovery plan development
[0263] When a security incident occurs, the first step is to determine a recovery strategy based on the backup and recovery plan. This includes determining the scope of resources to be restored, the recovery sequence, the recovery method (e.g., full restore, incremental restore), and the time and resources required. Leveraging pre-defined backup strategies and recovery plans ensures that recovery can be initiated quickly in the event of a security incident.
[0264] 2. Perform recovery operations
[0265] After developing a recovery strategy, immediately execute recovery operations. This includes restoring damaged resources from backups, repairing damaged system components, and reconstructing lost data. Leverage automated recovery tools and methods, such as backup software and virtual machine snapshots, to quickly and accurately execute recovery operations. Key recovery information, such as recovery time, status, and results, can also be recorded for subsequent analysis and optimization.
[0266] 3. Recovery effect evaluation and optimization
[0267] After the recovery operation is complete, the recovery results can be evaluated and optimized. This includes checking whether the restored resources have resumed normal operation and whether business continuity and stability have been restored. It also includes assessing whether there were any issues or deficiencies in the recovery process, such as extended recovery times or incomplete recovery results. Based on the evaluation results, the recovery strategy can be further optimized, such as by refining backup strategies and optimizing the recovery process, to improve recovery efficiency and accuracy.
[0268] This section involves the optimization algorithm of the recovery strategy. The formula for minimizing the recovery time is:
[0269]
[0270] Where T represents the total recovery time, that is, the total time required to recover all resources; t i represents the recovery time of resource i, that is, the time required for resource i to recover from a damaged state to a normal state; n1 represents the number of resource types.
[0271] Specific application examples:
[0272] Taking a large cloud computing center as an example, the center has deployed the dynamic adaptive computing power resource security isolation and recovery system of this solution.
[0273] The system can monitor the network traffic and computing resource usage of the cloud computing center in real time, identify potential DDoS attacks through packet-based coarse-grained anomaly detection and flow-based fine-grained anomaly detection methods, and determine that the network threat value is high by calculation, which means that the attack has a high risk level.
[0274] Based on risk assessment results, the system automatically adjusts the isolation level of computing resources and classifies the affected computing resource areas as high-risk zones. It then implements additional isolation measures, such as restricting access control rules, to ensure that other areas remain unaffected. When a DDoS attack is detected, the system immediately triggers the isolation and recovery mechanism, isolating the affected computing resources from the network to prevent the attack from spreading. Simultaneously, backup resources are activated to ensure the continuity of computing services within the cloud computing center. During the isolation period, the system continuously monitors network status and, if the attack is weakening, restores the affected resources as appropriate based on the risk assessment results.
[0275] Through the above methods, we can successfully deal with potential DDoS attacks, ensure the continuity and security of the computing power services of the cloud computing center, and improve the security and reliability of the overall system.
[0276] It should be noted that the embodiments of the present application have at least the following beneficial effects:
[0277] 1. Use machine learning algorithms to analyze and identify data, apply risk assessment models to evaluate the severity of threats, the scope of impact, and the importance of resources, and express the assessment results in the form of quantitative indicators to guide subsequent isolation and recovery operations, so as to timely discover and respond to potential security threats, effectively prevent the spread and spread of threats, and improve system security.
[0278] 2. When a security incident occurs, the backup and recovery mechanism can be immediately activated. Through pre-configured backup strategies and recovery processes, damaged resources can be restored to normal status. At the same time, based on historical data and experience, the recovery strategy can be continuously optimized to improve recovery efficiency and accuracy.
[0279] 3. By dynamically adjusting isolation and resource allocation strategies, flexible adjustments can be made based on the severity of the threat and resource needs, ensuring efficient resource utilization and avoiding waste and idleness. High-risk resources can be isolated from the network, limiting their communication with other resources. For low-risk resources, a more relaxed strategy can be adopted to ensure efficient resource utilization. Furthermore, the present invention uses automated and intelligent management methods to reduce the workload and costs of operations and maintenance personnel, thereby improving the system's efficiency and reliability.
[0280] 4. The embodiment of the present application provides a dynamic and adaptive computing power resource security isolation and recovery method (i.e., a computing power resource management method). Through detection agents deployed on network nodes, network traffic, system logs, user behavior and other data are collected in real time, and machine learning algorithms are applied to analyze and identify the data to promptly discover and report potential security threats; a risk assessment model is applied to evaluate the severity of the threat, the scope of impact and the importance of the resource, and the assessment results are expressed in the form of quantitative indicators to guide subsequent isolation and recovery operations; based on the assessment results, the network access control policy and resource allocation policy are dynamically adjusted. For high-risk resources, they can be isolated from the network and their communication with other resources can be restricted; for low-risk resources, a more relaxed policy can be adopted to ensure the effective use of resources; when a security incident occurs, the backup and recovery mechanism is immediately started, and the damaged resources are restored to normal through pre-configured backup policies and recovery processes. At the same time, based on historical data and experience, the recovery policy is continuously optimized to improve recovery efficiency and accuracy.
[0281] Example 2
[0282] like Figure 3 As shown, the computing power resource management device provided in the embodiment of the present application includes a first acquisition module 210, a first processing module 220, a first determination module 230 and a first execution module 240.
[0283] The first acquisition module 210 is configured to acquire a first threat type corresponding to first multi-source data of the computing network; the first multi-source data includes first network traffic data, first system logs, and first user behavior data;
[0284] A first processing module 220, connected to the first acquisition module 210, is configured to process the first threat type based on a target risk assessment model to obtain target information corresponding to the computing power network; the target risk assessment model is obtained by training a historical sample set, the historical sample set including multiple historical samples, the historical samples including historical training data and corresponding historical annotated data, the historical training data including historical threat types, the historical annotated data including historical isolation measures and historical threat priorities; the target information including target isolation measures and target threat priorities;
[0285] A first determination module 230, connected to the first processing module 220, is used to determine a target management strategy based on the target isolation measure and the target threat priority;
[0286] The first execution module 240 is connected to the first determination module 230 and is used to execute a target management policy, where the target management policy is used to manage computing resources in the computing network.
[0287] According to the computing power resource management device provided in the embodiment of the present application, the first threat type corresponding to the first multi-source data of the computing power network is first obtained, and then the first threat type is processed based on the target risk assessment model to obtain the target isolation measures and target threat priorities corresponding to the computing power network. Then, according to the target isolation measures and target threat priorities, the target management strategy is determined, and then the target management strategy is executed. The target management strategy is used to manage the computing power resources in the computing power network. That is, in the embodiment of the present application, by obtaining the first threat type and then processing the first threat type based on the target risk assessment model, the target isolation measures and target threat priorities of the computing power resources in the computing power network can be dynamically determined, and then according to the target isolation measures and target threat priorities, the target management strategy is dynamically determined. It has real-time threat detection and dynamic adjustment capabilities, can effectively respond to complex and changeable network threats, thereby ensuring the efficient use of computing power resources while improving the security and stability of the computing power network. In addition, since the target risk assessment model is obtained through historical threat types and historical isolation measures, the target isolation measures obtained by processing the first threat type based on the target risk assessment model can fully consider the historical threat types and their corresponding historical isolation measures, making the obtained target isolation measures more scientific and reasonable.
[0288] In some implementations, the first acquisition module 210 is specifically configured to:
[0289] Obtain the first multi-source data of the computing power network;
[0290] Preprocessing the first multi-source data to obtain preprocessed first multi-source data, where the preprocessing includes at least one of data cleaning, data transformation, and data reduction;
[0291] The preprocessed first multi-source data is identified using a decision tree algorithm to obtain a first threat type corresponding to the first multi-source data.
[0292] In some embodiments, the first processing module 220 is specifically configured to:
[0293] Obtaining first information corresponding to the first threat type, the first information including at least one of first direct loss information, first indirect impact information, a first propagation speed, a first potential spread range, a first importance level, a first location, and a first correlation degree;
[0294] The target risk assessment model is used to process the first information and the first threat type to obtain target information of the computing power network.
[0295] In some embodiments, the target information further includes a target risk score;
[0296] The device also includes:
[0297] The display module is used to display the target risk score and target threat priority.
[0298] In some implementations, the first determining module 230 specifically includes:
[0299] Obtain target factors for the computing network; target factors include at least one of network topology, resource distribution, and business priority;
[0300] Determine target management strategies based on target isolation measures, target threat priorities, and target factors.
[0301] In some embodiments, the device further comprises:
[0302] The second acquisition module is used to obtain threat status data, resource status data and environmental change data of the computing power network;
[0303] A first adjustment module, connected to the second acquisition module, is used to adjust the target management strategy according to the threat status data, the resource status data and the environmental change data to obtain the adjusted target management strategy;
[0304] The second execution module is connected to the first adjustment module and is used to execute the adjusted target management strategy.
[0305] In some embodiments, the device further comprises:
[0306] The second determination module is configured to determine a target recovery strategy based on a preset backup and recovery plan when a security incident is detected; the target recovery strategy includes at least one of a scope of resources to be recovered, a recovery order, a recovery method, a time required for recovery, and resources required for recovery; the target recovery strategy is used to recover damaged computing resources in the computing network;
[0307] The third execution module is connected to the first determination module and is used to execute the target recovery strategy.
[0308] In some embodiments, the device further comprises:
[0309] An evaluation module is used to evaluate the recovery effect corresponding to the target recovery strategy and obtain an evaluation result;
[0310] The optimization module is connected to the evaluation module and is used to optimize the target recovery strategy according to the evaluation results to obtain the optimized target recovery strategy;
[0311] The fourth execution module is connected to the optimization module and is used to execute the optimized target recovery strategy.
[0312] For example, Figure 4 As shown, the dynamic and adaptive computing power resource security isolation and recovery system (i.e., computing power resource management device) provided in an embodiment of the present application includes a real-time threat detection module, a risk assessment module, a dynamic isolation module and a rapid recovery module connected in sequence.
[0313] The computing power resource management device provided in the embodiment of the present application is used to execute the computing power resource management method in Example 1, that is, it has the beneficial effects and implementation methods of the computing power resource management method provided in Example 1 of the present application. For details, please refer to the specific description of the computing power resource management method in the above Example 1, and this embodiment will not be repeated here.
[0314] Example 3
[0315] refer to Figure 5 This embodiment provides an electronic device, including a memory 21 and a processor 22, wherein the memory 21 stores a computer program, and the processor 22 is configured to run the computer program to execute the computing power resource management method in Example 1.
[0316] The memory 21 is connected to the processor 22 . The memory 21 may be a flash memory, a read-only memory, or other memory. The processor 22 may be a central processing unit or a single-chip microcomputer.
[0317] According to the electronic device provided in the embodiment of the present application, the first threat type corresponding to the first multi-source data of the computing network is first obtained, and then the first threat type is processed based on the target risk assessment model to obtain the target isolation measures and target threat priorities corresponding to the computing network. Then, according to the target isolation measures and target threat priorities, the target management strategy is determined, and then the target management strategy is executed. The target management strategy is used to manage the computing resources in the computing network. That is, in the embodiment of the present application, by obtaining the first threat type and then processing the first threat type based on the target risk assessment model, the target isolation measures and target threat priorities of the computing resources in the computing network can be dynamically determined, and then according to the target isolation measures and target threat priorities, the target management strategy is dynamically determined. It has the ability to detect and adjust threats in real time and dynamically, and can effectively respond to complex and changeable network threats, thereby ensuring the efficient use of computing resources while improving the security and stability of the computing network. In addition, since the target risk assessment model is obtained through historical threat types and historical isolation measures, the target isolation measures obtained by processing the first threat type based on the target risk assessment model can fully consider the historical threat types and their corresponding historical isolation measures, making the obtained target isolation measures more scientific and reasonable.
[0318] Example 4
[0319] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the computing power resource management method in the above-mentioned embodiment 1 is implemented.
[0320] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.
[0321] According to the computer-readable storage medium provided in the embodiment of the present application, the first threat type corresponding to the first multi-source data of the computing network is first obtained, and then the first threat type is processed based on the target risk assessment model to obtain the target isolation measures and target threat priorities corresponding to the computing network. Then, according to the target isolation measures and target threat priorities, the target management strategy is determined, and then the target management strategy is executed. The target management strategy is used to manage the computing resources in the computing network. That is, in the embodiment of the present application, by obtaining the first threat type and then processing the first threat type based on the target risk assessment model, the target isolation measures and target threat priorities of the computing resources in the computing network can be dynamically determined, and then according to the target isolation measures and target threat priorities, the target management strategy is dynamically determined, with real-time threat detection and dynamic adjustment capabilities, and can effectively respond to complex and changeable network threats, thereby ensuring the efficient use of computing resources while improving the security and stability of the computing network. In addition, since the target risk assessment model is obtained through historical threat types and historical isolation measures, the target isolation measures obtained by processing the first threat type based on the target risk assessment model can fully consider the historical threat types and their corresponding historical isolation measures, making the obtained target isolation measures more scientific and reasonable.
[0322] Example 5
[0323] An embodiment of the present application also provides a computer program product. When the instructions in the computer program product are executed by a processor of an electronic device, the electronic device executes the computing power resource management method as described in Example 1.
[0324] It is understood that the above embodiments are merely exemplary embodiments for illustrating the principles of the present application, and the present application is not limited thereto. Those skilled in the art may make various modifications and improvements without departing from the spirit and substance of the present application, and such modifications and improvements are also considered to be within the scope of protection of the present application.
Claims
1. A computing resource management method, characterized in that: include: Obtaining a first threat type corresponding to first multi-source data of the computing power network; The first multi-source data includes first network traffic data, first system log and first user behavior data; Based on a target risk assessment model, the first threat type is processed to obtain target information corresponding to the computing power network; the target risk assessment model is obtained by training a historical sample set, the historical sample set includes multiple historical samples, the historical samples include historical training data and corresponding historical annotation data, the historical training data includes historical threat types, the historical annotation data includes historical isolation measures and historical threat priorities; the target information includes target isolation measures and target threat priorities; Determining a target management strategy based on the target isolation measures and the target threat priority; Execute the target management policy, where the target management policy is used to manage computing resources in the computing network.
2. The method according to claim 1, characterized in that The obtaining of the first threat type corresponding to the first multi-source data of the computing power network specifically includes: Obtain the first multi-source data of the computing power network; Preprocessing the first multi-source data to obtain preprocessed first multi-source data, wherein the preprocessing includes at least one of data cleaning, data transformation, and data reduction; A decision tree algorithm is used to identify the preprocessed first multi-source data to obtain a first threat type corresponding to the first multi-source data.
3. The method according to claim 1, characterized in that The processing of the first threat type based on the target risk assessment model to obtain target information corresponding to the computing power network specifically includes: Acquire first information corresponding to the first threat type, the first information including at least one of first direct loss information, first indirect impact information, a first propagation speed, a first potential spread range, a first importance level, a first location, and a first correlation degree; The target risk assessment model is used to process the first information and the first threat type to obtain target information of the computing power network.
4. The method according to claim 1, wherein The target information also includes a target risk score; The method further comprises: The target risk score and the target threat priority are displayed.
5. The method according to claim 1, wherein Determining a target management strategy based on the target isolation measures and target threat priorities specifically includes: Obtaining target factors of the computing power network; the target factors include at least one of network topology, resource distribution, and service priority; A target management strategy is determined based on the target isolation measures, the target threat priority, and the target factors.
6. The method according to claim 1, characterized in that After executing the target management strategy, the method further includes: Obtain threat status data, resource status data, and environmental change data of the computing power network; Adjusting the target management strategy according to the threat status data, the resource status data, and the environmental change data to obtain an adjusted target management strategy; Implement the adjusted target management strategy.
7. The method according to claim 1, characterized in that After executing the target management strategy, the method further includes: In the event of a security incident being detected, a target recovery strategy is determined based on a preset backup and recovery plan; the target recovery strategy includes at least one of the following: a scope of resources to be recovered, a recovery order, a recovery method, a time required for recovery, and resources required for recovery; the target recovery strategy is used to recover the damaged computing resources in the computing network; The target recovery strategy is executed.
8. The method according to claim 7, characterized in that After executing the target recovery strategy, the method further includes: Evaluating the recovery effect corresponding to the target recovery strategy to obtain an evaluation result; Optimizing the target recovery strategy according to the evaluation result to obtain an optimized target recovery strategy; Execute the optimized target recovery strategy.
9. A computing resource management device, characterized in that: include: A first acquisition module, configured to acquire a first threat type corresponding to first multi-source data of a computing power network; The first multi-source data includes first network traffic data, first system log and first user behavior data; a first processing module, connected to the first acquisition module, configured to process the first threat type based on a target risk assessment model to obtain target information corresponding to the computing power network; the target risk assessment model is obtained by training a historical sample set, the historical sample set includes a plurality of historical samples, the historical samples include historical training data and corresponding historical annotation data, the historical training data includes historical threat types, the historical annotation data includes historical isolation measures and historical threat priorities; the target information includes target isolation measures and target threat priorities; a first determining module, connected to the first processing module, for determining a target management strategy according to the target isolation measure and the target threat priority; A first execution module is connected to the first determination module and is used to execute the target management strategy, where the target management strategy is used to manage computing resources in the computing network.
10. An electronic device, characterized in that: The electronic device includes a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to implement the computing power resource management method according to any one of claims 1 to 8.
Citation Information
Cited By
Scheduling method and device, database system, program product and storage medium
CN122173303A