Computing power resource security calling method and device, storage medium and program product

By generating virtual call information and strict authentication mechanism, the security problem of computing resources in the cloud computing platform is solved, accurate calls for legitimate users and induction of illegal users are achieved, and the security and efficiency of the system are improved.

CN120768686AActive Publication Date: 2025-10-10BEIJING ELECTRONIC DIGITAL INTELLIGENCE TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511277743.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-10-10
Estimated Expiration
2045-09-09

AI Technical Summary

Technical Problem

In cloud computing platforms, the security of computing resources is becoming increasingly prominent. Hackers can illegally log in and abuse resources by cracking SSH passwords, leading to security risks and a decline in user experience.

Method used

By obtaining the real call information of computing resource nodes, generating virtual call information, and combining it with a strict authentication mechanism, it ensures that only legitimate users obtain real information, while illegal users obtain virtual information. The honeypot proxy module is used to induce attackers to avoid resource leakage.

Benefits of technology

It improves the security and utilization efficiency of computing resources, reduces the negative impact on user experience and management complexity, reduces the possibility of system attacks, and enhances the stability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768686A_ABST
    Figure CN120768686A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a computing power resource safe calling method and device, a storage medium and a program product. The method comprises the following steps: acquiring real calling information of a computing power resource node, and generating virtual calling information of the computing power resource node based on the real calling information; receiving a computing power calling request of a user side, authenticating the computing power calling request, and determining a target computing power resource node requested by the user; if the authentication succeeds, real calling information of the target computing power resource node is sent to the user side, so that the user side calls the target computing power resource node; and if the authentication fails, virtual calling information of the target computing power resource node is sent to the user side. According to the method, whether real or virtual calling information is sent to the user side or not can be determined through authentication, the safety of computing power resources can be guaranteed, and hackers are prevented from illegally logging in and abusing.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of networks, and particularly relates to a computing power resource safe calling method and device, a storage medium and a program product. BACKGROUND

[0002] With the rapid development of artificial intelligence and cloud computing technology, cloud native platforms such as Kubernetes (K8s) have been widely used in data centers, scientific research, government and enterprise, and finance. These platforms can realize automatic discovery, elastic allocation and containerized mounting of heterogeneous hardware resources such as GPU, NPU and FPGA through standard scheduling and expansion mechanisms and DevicePlugin, thereby significantly improving resource utilization and system flexibility. However, with the widespread application of computing power resources, their security problems have become increasingly prominent.

[0003] In a computing power cloud platform, a computing power scheduling platform is used to efficiently distribute and manage AI training and inference tasks. However, hackers may illegally log in to the computing power server by cracking the SSH password and misuse the computing power resources, resulting in resource waste and potential security risks. In order to prevent such attacks, the common practice is to completely disable the SSH password login method and restrict users from directly accessing the computing power devices to improve resource isolation. Although this method improves security to some extent, it also brings down user experience, increases management complexity, and may affect the rapid response capability in emergency situations in some cases. SUMMARY

[0004] Therefore, the embodiments of the present disclosure provide a computing power resource safe calling method and device, a storage medium and a program product, which can determine whether to send real or virtual calling information to the user end through authentication, can guarantee the security of computing power resources, prevent hackers from illegal login and misuse, and do not need to completely disable SSH password login, balancing security and user experience.

[0005] In a first aspect, the embodiments of the present disclosure provide a computing power resource safe calling method, which adopts the following technical scheme: obtaining real calling information of a computing power resource node, generating virtual calling information of the computing power resource node based on the real calling information; receiving a computing power calling request of a user end, authenticating the computing power calling request, and determining a target computing power resource node requested by the user; if the authentication is successful, sending the real calling information of the target computing power resource node to the user end for the user end to call the target computing power resource node; if the authentication fails, sending the virtual calling information of the target computing power resource node to the user end.

[0006] Optionally, the real call information includes a real access path of the computing resource node; The virtual call information includes a virtual access path of the computing resource node. Analyzing a naming rule of the real access path, and determining a generation rule of the virtual access path based on the naming rule; Generating an initial virtual access path based on the generation rule; Obtaining a trigger condition of the computing resource node; When the computing resource node meets the trigger condition, updating the virtual access path based on the generation rule.

[0007] Optionally, the updating the virtual access path based on the generation rule when the computing resource node meets the trigger condition includes: Obtaining a monitoring duration of the computing resource node and an access frequency of the computing resource node; When the monitoring duration reaches an update period, or the monitoring duration does not reach the update period but the access frequency reaches a preset access frequency threshold, updating the virtual access path based on the generation rule.

[0008] Optionally, the computing resource security calling method further includes: Receiving an SSH request of the office access end, and identifying the SSH request; If the identification is successful, allowing the office access end to access the general resource; If the identification fails, not allowing the office access end to access the general resource.

[0009] Optionally, the sending the virtual call information of the target computing resource node to the user end includes: Determining a risk level of the computing resource calling request through authentication of the computing resource calling request; Judging whether the risk level exceeds a preset level threshold; If it exceeds, detecting whether the target computing resource node is configured with a honeypot proxy module; If the honeypot proxy module is configured, forcibly redirecting the computing resource calling request to the honeypot proxy module; If the honeypot proxy module is not configured, configuring the honeypot proxy module for the target computing resource node, and after the configuration is completed, forcibly redirecting the computing resource calling request to the honeypot proxy module; The honeypot proxy module gradually sends the virtual call information of the target computing resource node to the user end based on the risk level; Based on the sent virtual call information, trapping the user end.

[0010] Optionally, the sending of the virtual call information of the target computing resource node to the user terminal further includes: When the risk level does not exceed the level threshold, detecting whether the target computing resource node is configured with a honeypot proxy module; If a honeypot proxy module is configured, the honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal based on the risk level; Based on the sent virtual call information, the user terminal is trapped; If the honeypot proxy module is not configured, the virtual call information of the target computing resource node will be sent to the user end.

[0011] Optionally, the honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal based on the risk level, including: According to the risk level of the computing power call request, the honeypot proxy module determines a target trapping topology from a preset trapping topology set; The honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal according to the target trapping topology map; Among them, the trapping topology map set includes trapping topology maps of different risk levels, each node of the trapping topology map represents the sending prompt information of the virtual call information, the directed edges between the nodes indicate the sending order between the virtual call information, and the attributes of the directed edges include the triggering conditions for sending the next virtual call information.

[0012] Optionally, the computing power resource secure calling method further includes: Divide system computing resources into multiple areas and assess the attack level of each area at different time periods; Assess the importance of computing resource nodes in each region; Based on the attack level of each region and the importance level of the computing power resource nodes in the region, the risky computing power resource nodes are determined from the computing power resource nodes in all regions; Configure a honeypot proxy module for each risky computing resource node.

[0013] In a second aspect, the embodiments of the present disclosure further provide a system for securely calling computing resources, which employs the following technical solutions: A generation module is used to obtain real call information of the computing power resource node and generate virtual call information of the computing power resource node based on the real call information; The determination module is used to receive the computing power call request from the user terminal, authenticate the computing power call request, and determine the target computing power resource node requested by the user; if the authentication is successful, the calling module is executed; if the authentication fails, the sending module is executed; The calling module is used to send the real calling information of the target computing resource node to the user end so that the user end can call the target computing resource node; The sending module is used to send the virtual call information of the target computing power resource node to the user end.

[0014] In a third aspect, the embodiments of the present disclosure further provide a computer device that adopts the following technical solution: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any of the above-mentioned computing power resource security calling methods.

[0015] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute any of the above-mentioned computing power resource security calling methods.

[0016] In a fifth aspect, an embodiment of the present disclosure further provides a computer program product, comprising a computer program / instruction, which implements the steps of any of the above methods when executed by a processor.

[0017] The computing power resource security call method provided by the embodiment of the present disclosure provides an accurate data basis for the entire computing power resource call system by obtaining real call information, enabling the system to clearly understand the actual usage of each computing power resource node, and by simulating real call information to generate virtual call information, it plays a role in protecting real data. Through a strict authentication mechanism, it can ensure that only legitimate users can call computing power resources, and determining the target computing power resource node requested by the user can achieve accurate resource matching. When the authentication is successful, the real call information is sent to the user end, so that the user can accurately understand the actual situation of the target computing power resource node, thereby making efficient calls. The user can reasonably arrange computing tasks based on the real information, give full play to the performance of computing power resources, and improve computing efficiency and business processing capabilities. For illegal users who fail to authenticate, sending virtual call information can confuse attackers and avoid the leakage of real information. At this time, the virtual call information serves as a defense measure to deal with external malicious detection. The attacker cannot obtain real resource information and it is difficult to carry out targeted attacks, which increases the difficulty and cost of the attack and reduces the possibility of the system being attacked. Even if an illegal user obtains the virtual information, it cannot pose a substantial threat to the system, thereby ensuring the stability and security of the entire computing power resource call system. Furthermore, virtual call information can mislead attackers, making it more difficult for them to obtain real information and reducing the risk of system attacks. Furthermore, by generating virtual call information and strictly authenticating users, this method prevents hackers from illegally logging in and abusing computing power. This eliminates the need to completely disable SSH password logins, reducing the negative impact on user experience, management complexity, and emergency response capabilities.

[0018] The above description is only an overview of the technical solution of the present disclosure. In order to more clearly understand the technical means of the present disclosure, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present disclosure more obvious and easy to understand, the following specifically cites preferred embodiments and describes them in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0020] Figure 1 A flowchart of a method for securely calling computing resources provided in an embodiment of the present disclosure; Figure 2 A flowchart of a method for generating a virtual access path according to an embodiment of the present disclosure; Figure 3A schematic diagram of accessing the Zhisuan Cloud Platform provided in an embodiment of the present disclosure; Figure 4 A flowchart of a method for trapping a user terminal based on virtual call information provided in an embodiment of the present disclosure; Figure 5 A flowchart of a method for sending virtual call information provided by an embodiment of the present disclosure; Figure 6 A flowchart of a method for allocating honeypot proxy modules according to an embodiment of the present disclosure; Figure 7 A block diagram of the principle of a system for securely invoking computing resources provided by an embodiment of the present disclosure; Figure 8 A schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0021] The embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0022] It should be clear that the following embodiments of the present disclosure are described through specific concrete examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that the following embodiments and features in the embodiments can be combined with each other in the absence of conflict. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present disclosure.

[0023] It should be noted that various aspects of the embodiments within the scope of the appended claims are described below. It should be apparent that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on this disclosure, it should be understood by those skilled in the art that an aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, other structures and / or functionalities other than one or more of the aspects described herein can be used to implement this device and / or practice this method.

[0024] It should also be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present disclosure. The illustrations only show components related to the present disclosure and are not drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component can be changed at will, and the component layout type may also be more complicated.

[0025] Additionally, in the following description, specific details are provided to provide a thorough understanding of the examples. However, one skilled in the art will appreciate that the aspects described can be practiced without these specific details.

[0026] Reference Figure 1 The present disclosure provides a method for securely calling computing resources, comprising the following steps: S1: Obtain the real call information of the computing resource node, and generate the virtual call information of the computing resource node based on the real call information; S2: Receives the computing power call request from the user, authenticates the computing power call request, and determines the target computing power resource node requested by the user; S3: If the authentication is successful, the real call information of the target computing resource node is sent to the user terminal, so that the user terminal can call the target computing resource node; S4: If the authentication fails, the virtual call information of the target computing resource node is sent to the user end.

[0027] The method for securely calling computing resources provided by the present disclosure provides an accurate data foundation for the entire computing resource calling system by acquiring real call information, enabling the system to clearly understand the actual usage of each computing resource node, such as computing capacity occupancy rate, operating status, etc., thereby providing a basis for subsequent resource allocation and scheduling. Generating virtual call information plays a role in protecting real data. Virtual call information can disguise or distort real information to a certain extent, preventing the real call information from being leaked in certain circumstances, thereby enhancing the security and privacy of computing resource node information.

[0028] Through strict authentication mechanisms, such as identity verification and permission validation, we ensure that only legitimate users can access computing resources, preventing malicious access and abuse by unauthorized users and effectively protecting the security and availability of computing resources. Determining the target computing resource node for a user's request enables precise resource matching. The system can select appropriate computing resources for the user based on their needs and the actual conditions of each computing resource node, improving resource utilization efficiency and avoiding resource waste and conflicts. Once authentication is successful, the actual call information is sent to the user, enabling the user to accurately understand the actual conditions of the target computing resource node, enabling efficient calls. Based on this information, users can rationally schedule computing tasks, fully utilize the performance of computing resources, and improve computing efficiency and business processing capabilities. Providing accurate resource information to legitimate users avoids call failures and resource waste caused by inaccurate information, enhancing user trust and satisfaction with the system.

[0029] For unauthorized users who fail authentication, sending virtual call information can confuse attackers and prevent the leakage of real information. Virtual call information serves as a defensive measure against external malicious detection. Attackers cannot obtain real resource information, making it difficult to launch targeted attacks. This increases the difficulty and cost of attacks and reduces the likelihood of system attacks. Even if an unauthorized user obtains virtual information, it cannot pose a substantial threat to the system, ensuring the stability and security of the entire computing resource call system. Furthermore, virtual call information can mislead attackers, making it more difficult for them to obtain real information and reducing the risk of system attacks.

[0030] In addition, this method prevents hackers from illegally logging in and abusing computing power by generating virtual call information and strict authentication. There is no need to completely disable SSH password login, reducing the negative impact on user experience, management complexity and emergency response capabilities.

[0031] In S1, all computing resource nodes of the Zhisuan Cloud Platform are counted to obtain the real call information of all computing resource nodes. The real call information includes the real access path of the computing resource node and the real video memory size, computing frequency, model support, etc. By simulating the real call information, the virtual call information of the computing resource node is generated. The virtual call information includes the virtual access path of the computing resource node and other related virtual information. Figure 2 The flowchart of the virtual access path generation method shown in the figure, "Generating virtual call information of computing resource nodes based on real call information," includes the following steps: S11: analyzing the naming rules of the real access paths and determining the generation rules of the virtual access paths based on the naming rules; S12: Generate an initial virtual access path based on the generation rule; S13: Obtain the triggering conditions of the computing power resource node; S14: When the computing power resource node meets the triggering condition, the virtual access path is updated based on the generation rule.

[0032] In the above steps, a certain number of real access path samples are collected. These samples should cover as many real access paths as possible from different types and business scenarios to ensure a comprehensive analysis. The collected samples are analyzed in detail to observe the composition patterns of each part of the path, such as whether there are fixed prefixes or suffixes, whether there are parts arranged according to specific numbers or time sequence, and whether specific characters or symbols are used for separation. After analyzing the naming rules of the real access paths, the generation rules of the virtual access paths are determined based on this. The generation rules should mimic the characteristics of the real paths to a certain extent to increase the deceptiveness of the virtual paths. For example, if the real paths often use dates as part of the numbering, the virtual paths can also use a similar date numbering method. At the same time, some random elements, such as random strings or numbers, can be introduced to prevent the virtual paths from being too regular and easily detected by attackers.

[0033] Based on the established virtual access path generation rules, a corresponding code program is written. This program generates virtual access paths according to a certain logical combination of elements in the rules, such as fixed prefixes, random elements, and numbering schemes. During the generation process, a random number generator is used to generate random strings or numbers that meet the requirements of the rules and insert them into the appropriate locations. After the initial virtual access paths are generated, they are validated, including whether the paths comply with the generation rules, contain illegal characters, and conflict with existing real or virtual paths. If a path is found to not meet the requirements, it is regenerated until the conditions are met, ultimately resulting in an initial set of deceptive virtual access paths.

[0034] To accurately determine the triggering conditions for computing resource nodes, comprehensive monitoring of computing resource nodes is required. A dedicated monitoring system is established to monitor various indicators of computing resource nodes in real time, focusing on two key metrics: monitoring duration and access frequency. Monitoring duration can be measured by recording the duration from the start of monitoring a computing resource node to the current moment. Access frequency is calculated by counting the number of access requests to the computing resource node within a certain time interval. This data is stored in a database in real time for subsequent analysis and judgment.

[0035] The monitoring duration and access frequency are continuously evaluated. When the monitoring duration reaches the pre-set update cycle, it indicates that the time node for updating the virtual access path has arrived. Alternatively, even if the monitoring duration has not reached the update cycle, but the access frequency has reached the preset access frequency threshold, this means that there may be abnormal access behavior and the virtual access path needs to be updated in a timely manner. When the above trigger conditions are met, the code program that was previously written to generate virtual access paths based on generation rules is called again, and a new set of virtual access paths is regenerated according to the generation rules to replace the original virtual access paths. At the same time, the updated virtual access path information is synchronized to the relevant system modules to ensure that subsequent access requests can correctly use the new virtual path.

[0036] In S2, the super administrator performs basic security configuration in the data center, configuring SSH and operating system security policies for all computing servers. Access control is strengthened through the Match Address and Permit Root Login fields in sshd_config and firewall IP whitelisting, ensuring that only IP addresses in specific management network segments (such as bastion hosts and dedicated operations and maintenance zones) can remotely log in with root privileges. These root-privileged IP addresses can modify permissions, authorize, and perform maintenance operations on computing resource nodes (such as computing card device nodes like / dev / gpu* and / dev / npu*). For other IP zones (such as general business zones and office zones), only ordinary accounts are allowed to log in to computing servers. These ordinary accounts do not have direct access, allocation, or operation rights to computing card-related device nodes and are limited to routine non-computing resource operations such as log viewing and file management. Furthermore, udev rules and Linux ACL / group permissions are used to strictly restrict access to computing resource nodes to root or specific security groups. Regular permission audits are also implemented to ensure that unauthorized accounts or IP addresses outside the management zone cannot bypass the platform and directly access computing resources.

[0037] When a user initiates a computing power request—that is, each time a container or process requests device allocation or invocation—the GPU-Proxy module in the computing power server (implemented by rewriting the Device Plugin) begins receiving the request. Upon receiving the computing power request, the Proxy first performs a whitelist authentication process, checking whether the user initiating the computing power request or its associated identity information is on a pre-set whitelist. If not, the request is rejected. If so, the Proxy verifies the national secret signature, token, certificate, or other identity credentials in the computing power request using national secret algorithms such as SM2, SM3, and SM4 to further authenticate the computing power request. During the processing of the computing power request, the Proxy determines the target computing power resource node based on relevant information such as the requested computing power type and amount. To ensure secure access to computing resources, the system uses a "soft stand-in" mechanism for device nodes. Before the user is authenticated, the actual call information of the computing resource nodes (such as the real physical device nodes, such as / dev / nvidia0 and / dev / davinci0) is not visible or directly accessible to ordinary system users / processes. The proxy will create a "virtual device node" (such as / dev / gpu-proxy0) for the container or task that needs to access the computing power, and all operations are directed to the proxy layer.

[0038] Reference Figure 3The displayed intelligent computing cloud platform access schematic diagram can be seen that the super administrator in the machine room can directly access the CPU, set the virtual calling information and configuration whitelist of the computing power resource node, etc. For personnel using public network, they log in the intelligent computing cloud platform through webpage at user end to send computing power calling request. Since the authentication mechanism for computing power calling request and virtual calling information are combined to improve the security of user end computing power calling, the SSH login permission of office area operation and maintenance personnel can be relaxed. The operation and maintenance personnel can use SSH to log in. After receiving the SSH request of the office area access end, the SSH request is identified. After successful identification, it is confirmed that the request is from a legally authorized office area operation and maintenance personnel and meets all security requirements. The office area access end is allowed to access general resources. If the identification fails, the office area access end is not allowed to access general resources. Through this way of not blocking SSH and only limiting computing power resource access, the operation of the operation and maintenance personnel can be avoided, which is beneficial to the daily maintenance and fault diagnosis of the operation and maintenance personnel, improves the operation and maintenance efficiency, reduces the management cost and complexity. Through the authentication mechanism and virtual computing power card technology, while enhancing the security of computing power resources, the access strategy can be dynamically adjusted according to different user roles and network environments, providing flexibility of computing power resource access, especially solving the difference problem of access demand of field personnel and office personnel. Moreover, through the IP layering and permission grading access control method, the security of the bottom computing power server scheduling information can be ensured, and users with reasonable needs can obtain related information as needed, reducing the adverse effects of "only using the scheduling situation" on user use, improving the orderliness and controllability of system management.

[0039] In S3, if the authentication of the computing power calling request by the GPU-Proxy is successful, the dynamic soft connection switching mechanism is used. The virtual computing power resource node is soft linked or bound to the target computing power resource node through cloud platform authorization (such as Device Plugin or Proxy). When the container is mounted, only the virtual computing power resource node is mounted into the target container, and the target computing power resource node is hidden on the host side. The Proxy maintains the global management and dynamic switching capability of the soft connection. Then, the real calling information of the target computing power resource node, such as the specific identifier of the device, the access path, the available computing power parameters, the memory size, the calculation frequency, etc. are sent to the user end. After receiving these real calling information, the user end can call the target computing power resource node according to these information, realizing the use of computing power resources.

[0040] In S4, when the GPU-Proxy authenticates the computing power calling request, if the user end does not belong to the whitelist, or the verification of the national secret signature, Token, certificate or other identity credentials fails, that is, the authentication fails. At this time, the dynamic soft connection switching mechanism is used to point the virtual device node to / dev / null or directly remove the soft link to prevent illegal access. At the same time, the virtual calling information of the target computing power resource node is sent to the user end. These virtual information contains seemingly reasonable but actually cannot be used in reality device identification, access path and other content, which can confuse possible illegal requesters and avoid the leakage of real computing power resources.

[0041] In the process of computing power task scheduling, the Proxy will record all behaviors related to computing power resources in detail, including the allocation, access, and recovery of resources, as well as specific information about abnormal attempts and command parameters used. To meet security and compliance requirements, these logs can be encrypted and signed. Then, the Proxy will store the processed log information in the audit database, making it easy for back-end personnel to audit these information at any time to ensure the security and compliance of the computing power task scheduling process.

[0042] Further, in addition to sending virtual calling information directly to the user end when authentication fails, virtual calling information can also be used to lure the user end for monitoring and analyzing potential malicious behavior, thereby enhancing the security and defense capabilities of the system. Referring to Figure 4 The flowchart of the method of luring the user end based on virtual calling information is shown. "Sending virtual calling information of the target computing power resource node to the user end" includes: S41: Determine the risk level of the computing power calling request through authentication of the computing power calling request; S42: When the risk level exceeds the preset level threshold, detect whether the target computing power resource node is configured with a honeypot agent module; if yes, execute S43; if no, execute S44; S43: Redirect the computing power calling request to the honeypot agent module; S44: Configure the honeypot agent module for the target computing power resource node, and after the configuration is complete, redirect the computing power calling request to the honeypot agent module; S45: The honeypot agent module sends the virtual calling information of the target computing power resource node to the user end step by step based on the risk level; S46: Lure the user end based on the sent virtual calling information.

[0043] In S41, in the process of authenticating the computing power call request, in addition to the regular authentication operation, it is also necessary to conduct dynamic monitoring of the behavior pattern of the computing power call request. The specific monitoring content includes the request frequency and rhythm, the request path and sequence, and the characteristics of the request data. In terms of request frequency and rhythm, it is necessary to pay attention to whether the number of requests per unit time exceeds the normal range, whether there are high-frequency requests in a short period of time, such as whether there is behavior similar to a blasting path, that is, the attacker attempts to obtain system permissions through a large number of attempts. At the same time, it is necessary to analyze the time distribution pattern of the request to determine whether there are abnormal request intervals. For the request path and sequence, it is necessary to check whether the request follows the normal business process, whether there are abnormal jumps or bypassing necessary steps, for example, simulating a token replay attack, the attacker may use the stolen token to repeatedly initiate requests to bypass identity authentication. In terms of request data characteristics, it is necessary to analyze whether the data carried in the request conforms to the normal business logic, and whether the format, size and content of the data are reasonable. In addition, a rule base needs to be established for matching access features such as certain source IP segments, anonymous access springboards, and VPNs. If the source IP of the request is in a known high-risk IP segment, or if the access is made through an anonymous access springboard or VPN and its behavioral characteristics meet the preset risk rules, the risk assessment of the request needs to be improved. Based on the above dynamic monitoring results of the computing power call request behavior pattern and the matching of access features, the risk level of the computing power call request can be ultimately determined. A risk assessment model can be established, taking factors such as the request initiation time, request source, and operation mode as input, and training the model through a machine learning algorithm to automatically output an accurate risk level.

[0044] In S42-S44, to prevent the honeypot proxy module from occupying a large amount of memory resources, only some computing power resource nodes are pre-installed with the honeypot proxy module. Therefore, when the risk level of the computing power call request exceeds the preset level threshold, it is necessary to first detect whether the target computing power resource node of the computing power call request is configured with the honeypot proxy module. If not, it is necessary to first configure the honeypot proxy module for the target computing power resource node. After the configuration is complete, the computing power call request is forcibly redirected based on network routing control or application layer interception methods. Among them, the network routing control method can be implemented by modifying static routing or adjusting dynamic routing protocol parameters; the application layer interception method can be implemented by setting up a proxy server or deploying middleware to transfer the request to the honeypot proxy module.

[0045] In S45, refer to Figure 5 The flowchart of the virtual call information sending method is shown. The "honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal based on the risk level" includes: S451: Based on the risk level of the computing power call request, the honeypot proxy module determines a target trapping topology from a preset trapping topology set; S452: The honeypot proxy module gradually sends virtual call information of the target computing resource node to the user end according to the target trapping topology map.

[0046] Among them, the trapping topology set includes trapping topologies of different risk levels. The nodes of each trapping topology represent the sending prompt information of the virtual call information. The directed edges between the nodes indicate the sending order between the virtual call information. The attributes of the directed edges include the triggering conditions for sending the next virtual call information.

[0047] In S45 and S46, after receiving the risk level of the computing power call request, the honeypot proxy module accesses a preset set of trapping topologies. Since this set is categorized and stored according to different risk levels, the honeypot proxy module can accurately select a matching target trapping topology from the set based on the determined risk level. After obtaining the target trapping topology, the honeypot proxy module begins its operation based on the instructions of the nodes and directed edges in the graph. The honeypot proxy module calls and sends the corresponding virtual call information based on the sending prompts in the nodes. The directed edges specify the order in which the virtual call information is sent, and the honeypot proxy module sends the information to the user terminal in this order. Furthermore, the attributes of the directed edges specify the trigger conditions for sending the next virtual call information. Only when these conditions are met will the honeypot proxy module send the next information. For example, if the trigger condition is that the user terminal responds to a specific message, the honeypot proxy module will wait for this response before sending subsequent information, gradually completing the transmission of the virtual call information of the target computing power resource node, thereby guiding the user terminal to perform the corresponding operation.

[0048] Suppose an enterprise receives a high-risk computing resource request. The honeypot proxy module quickly and precisely locates a target decoy topology from a pre-set set of decoy topologies corresponding to the high-risk level. In this target decoy topology, the first node prompts the attacker to send attributes such as the virtual access path, video memory size, and driver version. Directed edges dictate that only when the client makes further requests for this information (for example, when the client attempts to access the virtual access path), the honeypot proxy module, in accordance with the topology instructions, enters "tiered decoy mode." In the first level of decoy, the honeypot proxy module sends information indicating minor anomalies, such as simulating a performance bottleneck, to inform the client that the virtual target computing resource node has performance issues and may be slow to respond. This is triggered if the client continues to attempt resource operations or data acquisition after receiving the minor anomaly feedback. Once this trigger condition is met, the second level of decoy begins, where the honeypot proxy module directs the attacker to upload a model or perform training. This can be done by sending seemingly encouraging prompts, such as notifications that the current resource is suitable for training and offers promotional offers. The trigger condition is that the attacker responds to the prompts and begins uploading a model or initiating a training request. Once the attacker begins uploading a model or executing training, the third level of trapping begins. The honeypot proxy module then sends back fabricated results to prevent the attacker from receiving valid feedback. It also forces a delay in processing. For example, it informs the attacker that model training is complete, but the results may be biased. A longer delay is set before sending the fabricated results, further enhancing the deception. This allows the attacker to gather information about their toolchain, command combinations, and uploaded data structures, guiding the user step by step through the trapping process, exposing more of the attack's operational procedures and tools. Furthermore, the process of enticing the user to operate buys time for the system's defenses.

[0049] The set of pre-set trapping topologies should not be static but should be dynamically updated based on actual conditions. Past attack cases can be collected and analyzed, and emerging attack patterns and characteristics can be incorporated into the trapping topology. For example, if a new attack method is discovered that probes computing resources through a specific request sequence, corresponding nodes and directed edges can be added to the trapping topology at the corresponding risk level to improve the effectiveness of the trap.

[0050] To enhance the effectiveness of decoys, virtual call information should be more diverse. A random number generator can be used to generate some virtual parameters, such as video memory size and computation frequency, so that they vary randomly within a certain range. In addition to the preset error codes and status responses, new error codes and response information can be dynamically generated based on different scenarios and attack types, making it difficult for attackers to distinguish between real and fake.

[0051] Furthermore, when the risk level does not exceed the level threshold, it is detected whether the target computing resource node is configured with a honeypot proxy module; if the honeypot proxy module is configured, the honeypot proxy module gradually sends virtual call information of the target computing resource node to the user end based on the risk level; based on the sent virtual call information, the user end is trapped; if the honeypot proxy module is not configured, the virtual call information of the target computing resource node is sent to the user end. Through this method, it is possible to reduce the complex trapping strategy for user ends with lower potential threats. At the same time, when the target computing resource node is not configured with a honeypot proxy module, it lacks additional trapping capabilities. Directly sending virtual call information can quickly respond to requests and meet the basic needs of users. This operation can ensure the efficiency of system request processing and reduce unnecessary processing procedures and time consumption. Although it lacks deep trapping, it can simulate real computing calls to a certain extent, maintain normal interaction of the system, and can also preliminarily observe the user's subsequent behavior. Moreover, configuring honeypot proxy modules for all computing resource nodes will consume a large amount of system memory resources and computing power resources. Through this method, system resources can be saved while ensuring system security.

[0052] Assuming a computing power request is low-risk and the target computing resource node is configured with a honeypot proxy module, the honeypot proxy module, based on the target trap topology corresponding to the low-risk level, initially responds in low-emulation mode, returning a fixed error code and simplified attribute values, such as "device not available." If the requester continues to attempt, it switches to medium-emulation mode, issuing a virtual access path and simulating complete attribute fields such as memory size and driver version, supporting partial I / O. It also uses latency simulation to add random response times to simulate slow loading or system congestion. During this time, parameters returned by the virtual device, such as memory size and computing frequency, can be switched periodically or based on the requester's behavior. The returned error code also varies between "device busy," "permission denied," and "driver failure," thereby inducing the requester to perform more operations and exposing their operational processes and tools.

[0053] During attacker tracking, detailed logs are kept of all access actions through virtual paths, including the original request IP address, port number, user identity information, command parameters, uploaded models or data files, access behavior chains, and time-series behavior traces to reconstruct attack patterns. The system uniquely identifies access sessions and integrates browser fingerprints, user agent identifiers, and naming patterns and tag types in uploaded datasets for comprehensive tracking, enabling inferences about the attacker's model domain or business scenario. All behavior logs can be integrated into SIEM and security forensics systems, supporting both local encryption and remote synchronous transmission.

[0054] Further, in the process of allocating honeypot agent modules for computing resource nodes, the occupation of system resources and the actual needs of attack prevention need to be considered. Based on this, the method also provides a honeypot agent module allocation method, which refers to Figure 6 The flowchart of the honeypot agent module allocation method is shown. The method includes the following steps: S51: Divide the system computing resources into multiple regions, and evaluate the attack level of each region at different time periods; S52: Evaluate the importance level of the computing resource nodes in each region; S53: Based on the attack level of each region and the importance level of the computing resource nodes in the region, determine the risk computing resource nodes from all the computing resource nodes in the region; S54: Configure a honeypot agent module for each risk computing resource node.

[0055] The above steps support dynamic adjustment of the deployment density of honeypot resources according to time, behavior patterns, or attack risk levels. In terms of allocation density, more honeypot agent modules can be configured in specific time periods or high-attack areas. The specific adjustment methods are: time-driven adjustment, during high-attack time periods such as night and weekends, the attack level of most regions will increase, while the importance level of the computing resource nodes usually does not change easily, therefore, the number of risk computing resource nodes increases, and the proportion of honeypot agent modules increases accordingly, so that they occupy 70-100% of the total virtual path resources; behavior-driven adjustment, when a large number of computing power path scans, model repeated uploads, abnormal scheduling frequency, etc. are detected in a short period of time in a certain region, it can be determined that the attack level of the region is high, and the number of risk computing resource nodes selected from it will be more, so the density of honeypot agent modules can be automatically increased; tenant / user-driven adjustment, for unknown identity users or risk tenants, configure a high honeypot coverage strategy, so that the paths they contact by default are disguised nodes. In addition, the deployment of honeypot agent modules in the path space supports both sparse and dense modes. The sparse mode is to uniformly distribute a small number of honeypot agent modules in the path namespace, and the dense mode is to deploy a large number of honeypots in a certain section to form a "path trapping trap". In addition, based on the importance level of the risk computing resource nodes, the priority of the honeypot agent modules allocated to them is set; the system load is evaluated in real time, and when the system load exceeds the preset load threshold, the honeypot agent modules are closed in order of priority from small to large until the system load no longer exceeds the load threshold.

[0056] In summary, the method can greatly enhance the perception and tracing ability of the platform to illegal computing power access by introducing dynamic deformation and adaptive honeypot resource control mechanism, combining hierarchical trapping and behavior tracking audit design. When the system detects that the attacker repeatedly accesses the same path, or tries to read and write, persistently mount, etc. Operation on the path will trigger the "honeypot path deformation" operation, create "environmental instability" and "unreliable hardware" false appearance, mislead the attacker's judgment of the attack behavior, force him to expose more operation processes and tools. This mechanism effectively improves the "unrecognizability" of the system, reduces the probability of the honeypot being identified, and makes the attacker face a constantly changing and unpredictable computing power environment, so that the system can actively obtain attack intent, tool chain and model data.

[0057] Reference Figure 7 The present disclosure provides a computing power resource safe calling system, comprising: The generating module 101 is configured to obtain real calling information of a computing power resource node, and generate virtual calling information of the computing power resource node based on the real calling information; The determining module 102 is configured to receive a computing power calling request of a user end, authenticate the computing power calling request, and determine a target computing power resource node requested by the user; if the authentication is successful, execute the calling module; if the authentication fails, execute the sending module; The calling module 103 is configured to send the real calling information of the target computing power resource node to the user end, so that the user end calls the target computing power resource node; The sending module 104 is configured to send the virtual calling information of the target computing power resource node to the user end.

[0058] The various variations and specific examples of the computing power resource safe calling method provided above are also applicable to the computing power resource safe calling system provided by the present disclosure. Through the foregoing detailed description of the computing power resource safe calling method, those skilled in the art can clearly understand the implementation method of the computing power resource safe calling system. For the sake of brevity of the description, it will not be described in detail here.

[0059] The computer device according to the embodiments of the present disclosure comprises a memory and a processor. The memory is configured to store non-transitory computer readable instructions. Specifically, the memory can comprise one or more computer program products, which can comprise various forms of computer readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, comprise a random access memory (RAM) and / or a cache memory (cache), etc. The non-volatile memory may, for example, comprise a read-only memory (ROM), a hard disk, a flash memory, etc.

[0060] The processor can be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and can control other components in the computer device to perform desired functions. In one embodiment of the present disclosure, the processor is used to execute the computer-readable instructions stored in the memory, causing the computer device to execute all or part of the steps of the aforementioned method for securely calling computing resources in various embodiments of the present disclosure.

[0061] Those skilled in the art should understand that in order to solve the technical problem of how to obtain a good user experience, this embodiment may also include well-known structures such as a communication bus and an interface, and these well-known structures should also be included in the scope of protection of this disclosure.

[0062] like Figure 8 The present invention provides a schematic diagram of the structure of a computer device according to an embodiment of the present invention. Figure 8 The computer device shown is only an example and should not limit the functions and scope of use of the embodiments of the present disclosure.

[0063] like Figure 8 As shown, a computer device may include a processor (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) or programs loaded from a storage device into a random access memory (RAM). The RAM also stores various programs and data required for the operation of the computer device. The processor, ROM, and RAM are connected to each other via a bus. An input / output (I / O) interface is also connected to the bus.

[0064] Typically, the following devices can be connected to the I / O interface: input devices such as sensors or visual information acquisition devices; output devices such as display screens; storage devices such as tapes and hard disks; and communication devices. The communication device can allow the computer device to communicate with other devices (such as edge computing devices) wirelessly or by wire to exchange data. Figure 8 A computer device having various devices is shown, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead.

[0065] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by the processor, all or part of the steps of the computing power resource security call method of the embodiment of the present disclosure are executed.

[0066] For detailed description of this embodiment, please refer to the corresponding description in the aforementioned embodiments, which will not be repeated here.

[0067] According to a computer-readable storage medium of an embodiment of the present disclosure, non-transitory computer-readable instructions are stored thereon. When the non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the aforementioned method for securely calling computing resources in each embodiment of the present disclosure are executed.

[0068] The above-mentioned computer-readable storage media include, but are not limited to, optical storage media (e.g., CD-ROMs and DVDs), magneto-optical storage media (e.g., MOs), magnetic storage media (e.g., magnetic tapes or mobile hard disks), media with built-in rewritable non-volatile memory (e.g., memory cards), and media with built-in ROM (e.g., ROM cartridges).

[0069] For detailed description of this embodiment, please refer to the corresponding description in the aforementioned embodiments, which will not be repeated here.

[0070] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this disclosure are merely illustrative and not restrictive, and should not be construed as necessarily possessed by each embodiment of the present disclosure. Furthermore, the specific details disclosed above are provided for illustrative purposes and to facilitate understanding, rather than as limitations. These details do not limit the present disclosure to necessarily being implemented using these specific details.

[0071] In the present disclosure, relational terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between these entities or operations. The block diagrams of the devices, devices, equipment, and systems involved in the present disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "including," "comprising," "having," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.

[0072] Additionally, as used herein, "or" used in a list of items beginning with "at least one" indicates a separate list, so that, for example, a list of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not mean that the example described is preferred or better than other examples.

[0073] It should also be noted that in the system and method of the present disclosure, each component or each step can be decomposed and / or recombined. Such decomposition and / or recombination should be regarded as equivalent solutions of the present disclosure.

[0074] Various changes, substitutions, and modifications may be made to the technology described herein without departing from the teachings defined by the appended claims. Moreover, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of things, means, methods, and actions described above. Currently existing or later developed processes, machines, manufactures, compositions of things, means, methods, or actions that perform substantially the same function or achieve substantially the same results as the corresponding aspects described herein may be utilized. Accordingly, the appended claims include within their scope such processes, machines, manufactures, compositions of things, means, methods, or actions.

[0075] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0076] The foregoing description has been presented for the purposes of illustration and description. Furthermore, the description is not intended to limit the embodiments of the disclosure to the forms disclosed herein. Although the various example aspects and embodiments have been described herein with regard to particular aspects and embodiments, those skilled in the art will recognize that certain modifications, changes, substitutions, additions and sub-combinations can be made without departing from the spirit of the disclosure.

Claims

1. A method for securely calling computing resources, characterized in that: include: Obtaining real call information of the computing power resource node, and generating virtual call information of the computing power resource node based on the real call information; Receive a computing power call request from a user, authenticate the computing power call request, and determine the target computing power resource node requested by the user; If the authentication is successful, the real call information of the target computing resource node is sent to the user end, so that the user end can call the target computing resource node; If the authentication fails, the virtual call information of the target computing resource node will be sent to the user end.

2. The method for securely calling computing resources according to claim 1, wherein: The actual call information includes the actual access path of the computing resource node; Virtual call information includes the virtual access path of the computing resource node; Analyzing the naming rules of the real access paths, and determining generation rules of virtual access paths based on the naming rules; Based on the generation rule, generating an initial virtual access path; Get the trigger conditions of computing resource nodes; When the computing power resource node meets the trigger condition, the virtual access path is updated based on the generation rule.

3. The method for securely calling computing resources according to claim 2, characterized in that: When the computing power resource node meets the trigger condition, updating the virtual access path based on the generation rule includes: Obtain the monitoring duration of computing resource nodes and the access frequency of computing resource nodes; When the monitoring duration reaches an update period, or when the monitoring duration does not reach an update period but the access frequency reaches a preset access frequency threshold, the virtual access path is updated based on the generation rule.

4. The method for securely calling computing resources according to claim 2, wherein: Also includes: Receiving an SSH request from an office area access terminal and identifying the SSH request; If the identification is successful, the office access terminal is allowed to access general resources; If the identification fails, the office area access terminal is not allowed to access general resources.

5. The method for securely calling computing resources according to claim 1, wherein: The sending of the virtual call information of the target computing resource node to the user terminal includes: Determining a risk level of the computing power call request by authenticating the computing power call request; Determining whether the risk level exceeds a preset level threshold; If it exceeds, the target computing resource node is checked to see if it is equipped with a honeypot proxy module; If a honeypot proxy module is configured, the computing power call request is forcibly redirected to the honeypot proxy module; If the honeypot proxy module is not configured, configure the honeypot proxy module for the target computing resource node. After the configuration is complete, forcefully redirect the computing power call request to the honeypot proxy module. The honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal based on the risk level; Based on the virtual call information sent, the user terminal is trapped.

6. The method for securely calling computing resources according to claim 5, characterized in that: The sending of the virtual call information of the target computing resource node to the user terminal also includes: When the risk level does not exceed the level threshold, detecting whether the target computing resource node is configured with a honeypot proxy module; If a honeypot proxy module is configured, the honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal based on the risk level; Based on the sent virtual call information, the user terminal is trapped; If the honeypot proxy module is not configured, the virtual call information of the target computing resource node will be sent to the user end.

7. The method for securely calling computing resources according to claim 6, characterized in that: The honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal based on the risk level, including: According to the risk level of the computing power call request, the honeypot proxy module determines a target trapping topology from a preset trapping topology set; The honeypot proxy module gradually sends virtual call information of the target computing resource node to the user terminal according to the target trapping topology map; Among them, the trapping topology map set includes trapping topology maps of different risk levels, each node of the trapping topology map represents the sending prompt information of the virtual call information, the directed edges between the nodes indicate the sending order between the virtual call information, and the attributes of the directed edges include the triggering conditions for sending the next virtual call information.

8. The method for securely calling computing resources according to claim 6, wherein: Also includes: Divide system computing resources into multiple areas and assess the attack level of each area at different time periods; Assess the importance of computing resource nodes in each region; Based on the attack level of each region and the importance level of the computing power resource nodes in the region, the risky computing power resource nodes are determined from the computing power resource nodes in all regions; Configure a honeypot proxy module for each risky computing resource node.

9. A computer device, characterized in that: The computer device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method for securely calling computing power resources described in any one of claims 1-8.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, which are used to enable a computer to execute the method for securely calling computing power resources as described in any one of claims 1-8.

11. A computer program product comprising computer instructions, characterized in that When the computer instruction is executed by the processor, the steps of the method for securely calling computing power resources described in any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Heterogeneous computing power management method, system and equipment and storage medium

    CN115633049A

  • Safety guarantee system and method for honeypot system

    CN117097549A

  • Attack detection method and related equipment

    CN117896124A

  • Remote access system and method

    CN118157967A

  • Virtual file honey pots for computing systems protection against ransomware attacks

    US20250106251A1