Distributed mimicry judgment method and system based on dynamic interconnection
By designing a distributed mimicry adjudication system, utilizing a dynamic interconnected topology and modular components, the system addresses the reliability and scalability deficiencies of traditional mimicry adjudication schemes, achieving efficient and flexible information system security status determination.
Patent Information
- Application Number
- CN202510901515.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-31
AI Technical Summary
Traditional mimicry adjudication schemes have reliability risks, and mimicry defense systems lack flexibility and scalability, making it difficult to cope with changes in the number of executors.
Design a distributed mimicry adjudication system based on dynamic interconnection, including an input module, an execution module, an adjudicator module, a logic arithmetic unit module, and an output module. The system performs binary numerical consistency comparison and logical operations through a distributed adjudicator cluster and a logic arithmetic unit cluster, and dynamically generates a topology to support any number of execution entities.
It improves the robustness and flexibility of the mimicry defense system, avoids service unavailability caused by the failure of a single arbiter, and has good scalability and high availability.
Smart Images

Figure CN120880701A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a distributed mimicry adjudication method and system based on dynamic interconnection, belonging to the field of cyberspace security technology. Background Technology
[0002] Mimicry defense, based on the axiom of relative correctness, heterogeneous redundancy reliability theory and methods, and generalized robustness control theory and methods, is an integrated proactive defense technology that addresses both network security and functional safety issues. The mimicry adjudicator is the threat perception and blocking engine driving the mimicry defense system. Mimicry defense can protect against systems, components, and hardware / software modules. Functionally equivalent heterogeneous implementations of objects within the mimicry defense boundary constitute the executors. The mimicry adjudicator achieves the goal of perceiving the security status of the information system through multi-modal output vector mimicry adjudication of these executors. In high-security information systems, if the mimicry adjudicator determines that all executors respond consistently, the information system is in a secure state; otherwise, it is in a risky state. Traditional mimicry adjudication schemes based on a single adjudicator have reliability risks. When a single adjudicator operates unstablely due to workload or functional failure, the entire mimicry defense system will be in an inefficient response or operational blockage state. In addition, traditional mimicry adjudication requires the number of mimicry defense executors to be predetermined and a matching mimicry adjudication algorithm to be designed so that the number of parameters that the mimicry adjudication algorithm can handle is consistent with the number of executors. Once determined, it is difficult to modify. When the number of parameters that the mimicry adjudication algorithm can handle is inconsistent with the number of executors, the mimicry adjudicator will be unable to perform calculations, resulting in insufficient flexibility and scalability of the mimicry defense system.
[0003] Chinese patent CN 111800385 B discloses a distributed adjudication method, which deploys an adjudication exchange network and M heterogeneous adjudicators running the same adjudication algorithm. The adjudication exchange network is used to realize data communication and adjudication output among the heterogeneous adjudicators. Each heterogeneous adjudicator receives the execution results issued by N heterogeneous executors. After each heterogeneous adjudicator generates its adjudication result, the heterogeneous adjudicators obtain the adjudication results of other heterogeneous adjudicators through a consensus mechanism via the adjudication exchange network. Each heterogeneous adjudicator maintains an adjudication table, which records the adjudication results of the M heterogeneous adjudicators. Although the above method solves the problem of low reliability of single adjudicator operation in mimicry defense architecture by designing distributed adjudicators, the adjudication algorithm in the above M adjudicators must be able to process the execution results issued by N heterogeneous executors. If the parameter N is an independent variable, the adjudication algorithm is a dependent variable that needs to be adjusted according to the number of executors, resulting in additional deployment and design costs. It does not solve the flexibility and scalability requirements of mimicry defense system. Summary of the Invention
[0004] The technical problem this invention aims to solve is that traditional mimicry adjudication schemes based on a single adjudicator have reliability risks. Furthermore, traditional mimicry adjudication requires pre-determining the number of mimicry defense executors and designing a matching mimicry adjudication algorithm to ensure that the number of parameters that the mimicry adjudication algorithm can handle is consistent with the number of executors. Once determined, this is difficult to modify. When the number of parameters that the mimicry adjudication algorithm can handle is inconsistent with the number of executors, the mimicry adjudicator will be unable to perform calculations, resulting in insufficient flexibility and scalability of the mimicry defense system.
[0005] To address the aforementioned technical problems, the present invention discloses a distributed mimicry adjudication system based on dynamic interconnection, characterized in that it includes an input module, an execution module, an adjudicator module, a logic arithmetic unit module, and an output module, wherein:
[0006] The input module is used to receive parameters of the number of executors in the mimicry defense system, as well as to receive system requests and distribute the requests to the executor modules.
[0007] The execution module contains heterogeneous equivalent execution units corresponding to the number of execution unit quantity parameters received by the input module, which are used to process system requests and generate the output values of each execution unit's response;
[0008] Arbitrator module: Contains an arbitrator cluster with binary numerical consistency comparison function, used to perform pairwise consistency comparison of the execution body response output values and generate a Boolean value indicating whether the execution body response is consistent;
[0009] It also includes an arbiter number generator, which calculates the number of arbiters needed to iterate through and compare the output values of all executors in pairs.
[0010] It also includes an arbiter cluster topology interconnection generator, used to generate the interconnection topology between the executor and the arbiter cluster and establish connections;
[0011] Logic Calculator Module: Contains a cluster of logic calculators with binary Boolean logic operation capabilities, used to perform logical operations on the Boolean values generated by the arbitrator cluster;
[0012] It also includes a logic operator number generator, which is used to calculate the number of logic operators required to deduce the security state of the information system from the Boolean values generated by the arbitrator cluster;
[0013] It also includes a logic unit cluster topology interconnection generator, used to generate the interconnection topology between the arbiter cluster and the logic unit cluster and establish connections;
[0014] The output module outputs values based on the decision result of the logic unit module, which can determine the operating status of the information system and select appropriate output values.
[0015] Preferably, the method for determining the operating status of the information system is as follows: when the output value of the output module is TRUE, it indicates that the information system within the mimicry defense boundary is in a safe operating state; when the output value is FALSE, it indicates that the information system within the mimicry defense boundary has a security risk.
[0016] Another technical solution of the present invention is to provide a distributed mimicry adjudication method based on dynamic interconnection, characterized in that, based on the above-mentioned distributed mimicry adjudication system, it includes the following steps:
[0017] Step 1: The input module's custom execution body parameter receiver receives the number of execution bodies in the mimicry defense system, and the request distribution component receives system requests;
[0018] Step 2: The execution module reads the execution quantity parameter from the input module and generates the corresponding number of executions;
[0019] Step 3: The adjudicator module reads the number of execution bodies from the input module;
[0020] Step 4: The logic unit module reads the number of arbitrators from the arbitrator module;
[0021] Step 5: The input module requests the dispatch component to dispatch the system request to the execution module;
[0022] Step 6: After the execution module generates the system request response, it sends the execution response to the corresponding arbiter according to the interconnection topology dynamically constructed by the arbiter cluster interconnection structure generator.
[0023] Step 7: After the arbiter module generates a Boolean value indicating whether the executor response is consistent, it sends the arbiter Boolean value to the corresponding logic arithmetic unit according to the cascaded topology dynamically constructed by the logic arithmetic unit cluster topology interconnection structure generator.
[0024] Step 8: The logic unit module calculates the Boolean value to be output according to the cascaded topology and sends it to the output module;
[0025] Step 9: The output module can determine the operating status of the information system based on the decision result of the logic unit module.
[0026] Preferably, step 3 includes the following steps:
[0027] Step 3.1: The arbitrator quantity generator calculates the number of arbitrators that the arbitrator module should generate;
[0028] Step 3.2: The arbitrator module generates the corresponding number of arbitrators;
[0029] Step 3.3: The arbiter cluster topology interconnection generator connects to the arbiter by traversing the execution body:
[0030] Generates all pairs of execution entities, regardless of their order, for a specified number of execution entities;
[0031] Iterate through all executor combinations and connect them one by one with the arbitrators to generate the interconnection topology of the executor and arbitrator cluster.
[0032] Preferably, in step 3.1, the preset formula for the arbitrator number generator to calculate the number of arbitrators is: n represents the number of execution units.
[0033] Preferably, step 4 includes the following steps:
[0034] Step 4.1: The logic unit number generator calculates the number of logic units that the logic unit module should generate.
[0035] Step 4.2: The logic unit module generates the corresponding number of logic units;
[0036] Step 4.3: The logic unit cluster topology interconnection structure generator connects the arbiter cluster and the logic unit cluster according to the cascaded topology;
[0037] Step 4.4: The logic unit module passes the logical operation Boolean value to the output module.
[0038] Preferably, in step 4.1, the number of logic operators p = m-1, where m is the number of arbitrators.
[0039] Preferably, in step 9, the method for determining the operating status of the information system is as follows: when the output value of the system operating status evaluation component of the output module is TRUE, it indicates that the information system within the mimicry defense boundary is in a safe operating state; when the output value is FALSE, it indicates that the information system within the mimicry defense boundary has a security risk, and the appropriate execution response value is selected by the output selection component.
[0040] Compared with existing technical solutions, the innovation of this invention lies in the following aspects.
[0041] 1) This invention proposes a distributed adjudication architecture that supports mimicry adjudication by any number of executors. This architecture comprises five modules: an input module, an executor module, an adjudicator module, a logic operator module, and an output module. The adjudicator module and the logic operator module are the core functional modules of the distributed mimicry adjudication. The adjudicator module deploys an adjudicator cluster that supports binary comparison operations on the output values of the executors. This layer decomposes the single adjudicator task into a distributed computational binary value consistency comparison task. The Boolean values generated by the adjudicator cluster are submitted as input values to the logic operator module. The logic operator module deploys a logic operator cluster that supports binary comparison operations on the Boolean values of the adjudicator cluster. This layer can perform logical operations on the Boolean values of the adjudicator cluster through the interconnection structure between the logic operator clusters, efficiently assessing the security status of the information system based on the executor output values, and transmitting the assessment results to the output module. This architecture transforms the mimicry adjudication task of a single adjudicator into a distributed adjudicator cluster execution, improving the robustness of the mimicry defense system and avoiding the unavailability of the mimicry adjudication service due to the failure of a single adjudicator.
[0042] 2) This invention proposes a distributed mimicry adjudication cascade topology for information systems with high security requirements. The cascade topology is a binary tree structure, corresponding to the connection structure between the adjudicator and the logic unit. The Boolean values of the leaf nodes are subjected to pairwise logical AND operations, and the results are passed up layer by layer to perform pairwise logical AND operations with the Boolean values of the upper-level leaf nodes until the root node outputs. If any leaf node has a Boolean value of "false", the root node will output false. The root node outputs true only when all leaf nodes have a Boolean value of "true". Therefore, this structure can fully correspond to the system characteristics of information systems with high security requirements, which determine that the system is in a safe state when all the outputs of the executors are equal. It is a highly efficient and accurate distributed mimicry adjudication topology.
[0043] 3) This invention proposes a method for dynamically generating the interconnection topology of key components such as executors, adjudicators, and logic operators in a mimicry defense architecture. Firstly, it can dynamically generate the number of adjudicators and logic operators required for a distributed mimicry adjudication architecture based on the number of executors. Secondly, it supports the dynamic generation of the connection topology of key components. These functions are deployed in the component number generator and topology generator of the distributed mimicry adjudication architecture, respectively. Compared with other mimicry adjudication methods, this invention decouples the strong consistency relationship between the number of executors and the adjudication algorithm, removing the precondition of pre-setting the adjudication algorithm based on the number of executors, thus exhibiting good scalability and flexibility.
[0044] Due to the adoption of the above-mentioned innovative technical solution, the present invention has the following beneficial effects compared with the prior art:
[0045] (1) The distributed mimicry adjudication architecture designed according to this invention can ensure the high availability of the mimicry adjudication service. The mimicry adjudication architecture designed in this invention offloads the function of a single adjudicator to a distributed adjudicator cluster and a distributed logic operator cluster on the adjudicator module and logic operator module, and defines the functional composition of the adjudicator module and logic operator module based on basic components such as binary numerical consistency comparison and binary Boolean logic operation, so as to further decouple the original single adjudicator function from the complex adjudication algorithm. The distributed mimicry adjudication architecture has the characteristics of high fault tolerance and high reliability. From the architectural design, it solves the defects of the mimicry adjudication service unavailability caused by single point failures such as adjudicator function failure, communication interruption, and business blockage under the single adjudicator architecture. From the functional design, the distributed mimicry adjudication architecture deploys basic algorithms in the distributed adjudicator cluster and the distributed logic operator cluster, which has high robustness and can solve the defects of strong functional coupling and high failure rate of complex algorithms.
[0046] (2) The distributed mimicry adjudication method designed according to this invention can provide good scalability and flexibility for mimicry defense systems, enabling them to support mimicry adjudication with a custom number of executors. It decouples the strong consistency relationship between the number of executors and the adjudication algorithm, and removes the precondition of pre-setting the adjudication algorithm based on the number of executors. Based on functional components capable of handling binary parameter operations, the distributed mimicry adjudication method designed in this invention proposes a set of quantitative analysis methods for the number of adjudicators and logic operators. It can automatically calculate the number of adjudicators required for the distributed adjudicator cluster and the number of logic operators required for the distributed logic operator cluster based on the custom number of executors. Furthermore, it dynamically generates the interconnection topology between executors and adjudicator clusters, and between adjudicator clusters and logic operator clusters. This can solve the shortcomings of traditional adjudicator adjudication algorithms, which require pre-design and deployment, and suffer from poor scalability and low flexibility of mimicry adjudication services due to the tight coupling between the number of supported executors and the parameters that the adjudication algorithm can handle. Attached Figure Description
[0047] Figure 1 This illustrates a distributed mimicry adjudication system based on dynamic interconnection;
[0048] Figure 2 The diagram illustrates the number of arbitrators in the arbitrator module and the method for dynamically generating the interconnection topology;
[0049] Figure 3 The diagram illustrates the number of logic units in the logic unit module and the method for dynamically generating the cascaded topology.
[0050] Figure 4 Implementation steps diagram Detailed Implementation
[0051] The present invention will be further illustrated below with reference to specific embodiments. It should be understood that these embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. Furthermore, it should be understood that after reading the teachings of this invention, those skilled in the art can make various alterations or modifications to the invention, and these equivalent forms also fall within the scope defined by the appended claims.
[0052] One aspect of this invention is a distributed mimicry adjudication system based on dynamic interconnection, comprising an input module, an execution module, an adjudicator module, a logic arithmetic unit module, and an output module.
[0053] The input module is used to receive parameters of the number of execution entities in the mimicry defense system, as well as to receive system requests and distribute the requests to the execution entity modules.
[0054] The executor module contains heterogeneous equivalent executors corresponding to the number of executor quantity parameters received by the input module, which are used to process system requests and generate the output values of each executor's response.
[0055] Arbitrator module: Contains an arbitrator cluster with binary numerical consistency comparison function, used to perform pairwise consistency comparison of the execution body response output values and generate a Boolean value indicating whether the execution body response is consistent;
[0056] Includes an arbiter count generator, used to calculate the number of arbiters required to iterate through and compare the output values of all executors pairwise;
[0057] It includes a topology interconnection generator for arbitrator clusters, used to generate interconnection topologies between the executor and the arbitrator cluster and establish connections.
[0058] Logic Calculator Module: Contains a cluster of logic calculators with binary Boolean logic operation capabilities, used to perform logical operations on the Boolean values generated by the arbitrator cluster, including but not limited to AND, OR, XOR and other logical operations;
[0059] It includes a logic operator number generator, which is used to calculate the number of logic operators required to deduce the security state of the information system from the Boolean values generated by the arbitrator cluster;
[0060] It includes a logic unit cluster topology interconnection generator, used to generate the interconnection topology between the arbiter cluster and the logic unit cluster and establish the connection.
[0061] The output module outputs based on the decision result of the logic arithmetic module. It can determine the operating status of the information system and select an appropriate output value. The method for determining the operating status of the information system is as follows: when the output module outputs a value of TRUE, it indicates that the information system within the mimicry defense boundary is in a safe operating state; when the output value is FALSE, it indicates that the information system within the mimicry defense boundary has a security risk.
[0062] Another aspect of this invention discloses a distributed mimicry adjudication method based on dynamic interconnection implemented in the above-described system, comprising the following steps:
[0063] Step 1: Input module custom execution body parameter receiver receives the number parameter of the mimicry defense system execution body, request distribution component receives system request.
[0064] Step 2: The execution module reads the number of execution units from the input module and generates the corresponding number of execution units (using virtualization methods such as virtual machines or containers).
[0065] Step 3: The adjudicator module reads the number of execution bodies from the input module.
[0066] Step 3.1: The arbitrator quantity generator calculates the number of arbitrators the arbitrator module should generate. Since the arbitrator has a binary numerical consistency comparison function, it calculates the number of all sequentially independent combinations of two execution bodies grouped together, given a specified number of execution bodies. This number represents the number of times the arbitrator module needs to adjudicate, and is also the number of arbitrators. The default formula for the arbitrator quantity generator to calculate the number of arbitrators is:
[0067] Step 3.2: The arbiter module generates a corresponding number of arbiters (using virtualization methods such as virtual machines or containers).
[0068] Step 3.3: The arbiter cluster topology interconnection generator connects to the arbiter by traversing the executors. First, it generates all executor combinations that are paired up in pairs, regardless of their order. Then, it traverses all executor combinations and connects them to the arbiter one by one, generating the interconnection topology between the executors and the arbiter cluster.
[0069] Step 4: The logic unit module reads the number of arbitrators from the arbitrator module.
[0070] Step 4.1: The logic unit number generator calculates the number of logic units that the logic unit module should generate. To meet the requirement that a high-security information system can only determine a secure state when all executor outputs are equal, the logic units and arbiters are connected in a cascaded manner. The logic units use AND operators, and the cascaded topology uses a binary tree structure. Specifically, first, two arbiters are selected, and their Boolean values are logically ANDed using the AND operator. Then, another arbiter that did not participate in the logical AND operation is selected, and its Boolean value is logically ANDed with the result of the previous logical AND operation. This process continues until all arbiters participate in the logical AND operation exactly once. Since the logic units have binary Boolean logical operation capabilities, the total number of logical operations participated in by the arbiters is the required number of logic units, and the number of logic units p = number of arbiters - 1. Therefore, the preset formula for the logic unit number generator to calculate the number of logic units is: p = m - 1, where m is the number of arbiters.
[0071] Step 4.2: The logic unit module generates the corresponding number of logic units (using virtualization methods such as virtual machines or containers).
[0072] Step 4.3: The logic unit cluster topology interconnection structure generator connects the arbiter cluster and the logic unit cluster according to the cascaded topology.
[0073] Step 4.4: The logic unit module passes the logical operation Boolean value to the output module.
[0074] Step 5: The input module request dispatch component dispatches the system request to the execution module.
[0075] Step 6: After the execution module generates the system request response, it sends the execution response to the corresponding arbiter according to the interconnection topology dynamically constructed by the arbiter cluster interconnection structure generator.
[0076] Step 7: After the arbiter module generates a Boolean value indicating whether the executor response is consistent, it sends the arbiter Boolean value to the corresponding logic arithmetic unit according to the cascaded topology dynamically constructed by the logic arithmetic unit cluster topology interconnection structure generator.
[0077] Step 8: The logic unit module calculates the Boolean value to be output according to the cascaded topology and sends it to the output module.
[0078] Step 9: The output module can determine the operating status of the information system based on the decision result of the logic unit module. The method for determining the operating status of the information system is as follows: when the output value of the system operating status evaluation component of the output module is TRUE, it means that the information system within the mimicry defense boundary is in a safe operating state; when the output value is FALSE, it means that the information system within the mimicry defense boundary has a security risk. The appropriate execution response value is selected through the output selection component.
[0079] A feasible implementation of the above technical solution includes the following steps:
[0080] (1) Set the number of execution entities in the mimicry defense system to n=4; the execution entity module, the adjudicator module, the logic operation unit module and their internal components are all deployed in the form of containers;
[0081] (2) The execution module reads the number of execution units from the input module and generates 4 container execution units; the input module receives system requests and forwards them to the 4 container execution units for processing.
[0082] (3) The adjudicator module reads the input module execution body quantity parameter n=4, and the adjudicator quantity generator generates the quantity according to the preset formula. The arbitrator module requires six arbitrator components, which also represent four executors. There are six possible combinations of executors, grouped in pairs regardless of their order. The arbitrator module generates six arbitrator containers. The arbitrator cluster topology interconnection generator establishes connections between each executor combination and the arbitrator, generating the interconnection topology between the executors and the arbitrator cluster. The responses generated by each executor combination processing system requests are compared for consistency by the corresponding arbitrator. An example implementation of the correspondence between executor combinations and arbitrators is shown in Table 1.
[0083] Table 1. An example of the correspondence between an execution unit combination and a arbitrator.
[0084] Execution body assembly Decision Maker Serial Number (Executor 1, Executor 2) Decision Maker 1 (Executor 1, Executor 3) Decision Maker 2 (Executor 1, Executor 4) Decision Maker 3 (Executor 2, Executor 3) Decision Maker 4 (Executor 2, Executor 4) Decision Maker 5 (Executor 3, Executor 4) Decision Maker 6
[0085] (4) The logic unit module reads the number of arbitrators from the arbitrator module. The number of arbitrators is n=4, calculated by the logic unit number generator according to the preset formula p=m-1. Processing the cascaded comparison of Boolean values of m=6 arbitrator components requires 5 logic unit components. The logic unit module generates 5 logic unit containers. The logic unit cluster topology interconnection structure generator connects the arbitrator container cluster and the logic unit container cluster according to the cascaded topology. The cascaded topology adopts a binary tree structure, and the logic unit uses an AND operator. First, two arbitrator containers are selected, and the Boolean values of the arbitrators are logically ANDed using the AND operator. Then, another arbitrator that has not participated in the logical AND operation is selected, and the Boolean value of the arbitrator is logically ANDed with the result of the previous logical AND operation. This process is repeated until all arbitrators participate in the logical AND operation once and only once. An example of the implementation of the correspondence between the arbitrator container cluster and the logic unit container cluster is shown in Table 2.
[0086] Table 2. An example of the implementation of the correspondence between a arbiter container cluster and a logic unit container cluster.
[0087]
[0088] (5) The logic operation module transmits the logic container cluster operation Boolean value to the output module. The output module can determine the information system operation status based on the decision result of the logic operation module. The method for determining the information system operation status is as follows: when the logic container cluster operation Boolean value received by the output module is TRUE, it indicates that the information system within the mimicry defense boundary is in a safe operation state; when the logic container cluster operation Boolean value is FALSE, it indicates that the information system within the mimicry defense boundary has a security risk, and a suitable execution response value is selected.
Claims
1. A distributed mimicry adjudication system based on dynamic interconnection, characterized in that, It includes an input module, an execution module, a arbiter module, a logic arithmetic unit module, and an output module, wherein: The input module is used to receive parameters of the number of executors in the mimicry defense system, as well as to receive system requests and distribute the requests to the executor modules. The execution module contains heterogeneous equivalent execution units corresponding to the number of execution unit quantity parameters received by the input module, which are used to process system requests and generate the output values of each execution unit's response; Arbitrator module: Contains an arbitrator cluster with binary numerical consistency comparison function, used to perform pairwise consistency comparison of the execution body response output values and generate a Boolean value indicating whether the execution body response is consistent; It also includes an arbiter number generator, which calculates the number of arbiters needed to iterate through and compare the output values of all executors in pairs. It also includes an arbiter cluster topology interconnection generator, used to generate the interconnection topology between the executor and the arbiter cluster and establish connections; Logic Calculator Module: Contains a cluster of logic calculators with binary Boolean logic operation capabilities, used to perform logical operations on the Boolean values generated by the arbitrator cluster; It also includes a logic operator number generator, used to calculate the number of logic operators required to deduce the security state of the information system from the Boolean values generated by the arbitrator cluster; It also includes a logic unit cluster topology interconnection generator, used to generate the interconnection topology between the arbiter cluster and the logic unit cluster and establish connections; The output module outputs values based on the decision result of the logic unit module, which can determine the operating status of the information system and select appropriate output values.
2. The distributed mimicry adjudication system based on dynamic interconnection as described in claim 1, characterized in that, The method for determining the operational status of an information system is as follows: when the output module outputs a value of TRUE, it indicates that the information system within the mimicry defense perimeter is in a safe operating state; when the output value is FALSE, it indicates that the information system within the mimicry defense perimeter is at risk.
3. A distributed mimicry adjudication method based on dynamic interconnection, characterized in that, The implementation of the distributed mimicry adjudication system based on claim 1 includes the following steps: Step 1: The input module's custom execution body parameter receiver receives the number of execution bodies in the mimicry defense system, and the request distribution component receives system requests; Step 2: The execution module reads the execution quantity parameter from the input module and generates the corresponding number of executions; Step 3: The adjudicator module reads the number of execution bodies from the input module. Step 4: The logic unit module reads the number of arbitrators from the arbitrator module; Step 5: The input module requests the dispatch component to dispatch the system request to the execution module; Step 6: After the execution module generates the system request response, it sends the execution response to the corresponding arbiter according to the interconnection topology dynamically constructed by the arbiter cluster interconnection structure generator. Step 7: After the arbiter module generates a Boolean value indicating whether the executor response is consistent, it sends the arbiter Boolean value to the corresponding logic arithmetic unit according to the cascaded topology dynamically constructed by the logic arithmetic unit cluster topology interconnection structure generator. Step 8: The logic unit module calculates the Boolean value to be output according to the cascaded topology and sends it to the output module; Step 9: The output module can determine the operating status of the information system based on the decision result of the logic unit module.
4. The distributed mimicry adjudication method based on dynamic interconnection as described in claim 3, characterized in that, Step 3 includes the following steps: Step 3.1: The arbitrator quantity generator calculates the number of arbitrators that the arbitrator module should generate; Step 3.2: The arbitrator module generates the corresponding number of arbitrators; Step 3.3: The arbiter cluster topology interconnection generator connects to the arbiter by traversing the execution body: Generates all pairs of execution entities, regardless of their order, for a specified number of execution entities; Iterate through all executor combinations and connect them one by one with the arbitrators to generate the interconnection topology of the executor and arbitrator cluster.
5. The distributed mimicry adjudication method based on dynamic interconnection as described in claim 4, characterized in that, In step 3.1, the default formula for the arbitrator number generator to calculate the number of arbitrators is: n represents the number of execution units.
6. The distributed mimicry adjudication method based on dynamic interconnection as described in claim 3, characterized in that, Step 4 includes the following steps: Step 4.1: The logic unit number generator calculates the number of logic units that the logic unit module should generate. Step 4.2: The logic unit module generates the corresponding number of logic units; Step 4.3: The logic unit cluster topology interconnection structure generator connects the arbiter cluster and the logic unit cluster according to the cascaded topology; Step 4.4: The logic unit module passes the logical operation Boolean value to the output module.
7. The distributed mimicry adjudication method based on dynamic interconnection as described in claim 6, characterized in that, In step 4.1, the number of logic operators is p = m-1, where m is the number of arbitrators.
8. The distributed mimicry adjudication method based on dynamic interconnection as described in claim 3, characterized in that, In step 9, the method for determining the operating status of the information system is as follows: when the output value of the system operating status evaluation component of the output module is TRUE, it indicates that the information system within the mimicry defense boundary is in a safe operating state; when the output value is FALSE, it indicates that the information system within the mimicry defense boundary has a security risk, and the appropriate execution response value is selected through the output selection component.
Citation Information
Patent Citations
Distributed adjudication method, distributed adjudication system and mimicry architecture
CN111800385B