Container cloud-oriented service dynamic deployment system

By monitoring and adjusting the service status and security configuration of the computing network resource pool in real time in the container cloud, and using deep reinforcement learning algorithms to generate the optimal security configuration strategy, the problem of coordination between resource allocation and security configuration in the container cloud is solved, thereby improving defense efficiency and service quality.

CN120979690APending Publication Date: 2025-11-18Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510967050.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

In container clouds, the optimal proactive defense security configuration strategy lacks coordination with resource allocation strategy, making it difficult to balance the system's service quality under dynamic traffic requests, resulting in both defense effectiveness and service quality being affected.

Method used

The orchestration platform creates a computing network resource pool, the resource monitoring module updates service status and security configuration information, the security decision module generates the optimal security configuration policy, the control module performs dynamic deployment, and the deep reinforcement learning algorithm is used to adjust the security configuration policy in real time.

Benefits of technology

It improved defense efficiency, enhanced service security and user service quality, and achieved coordinated optimization of resource allocation and security configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979690A_ABST
    Figure CN120979690A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a container cloud-oriented service dynamic deployment system. According to one specific embodiment of the system, an arrangement platform is configured to create a computing network resource pool according to a preset service resource set and send the computing network resource pool to a resource monitoring module; the resource monitoring module is configured to update service state information and security configuration information in the received computing network resource pool to obtain updated service state information and updated security configuration information, and send the updated service state information and the updated security configuration information to the security configuration solving sub-module; the security decision module is configured in such a way that the control module is configured to dynamically deploy the received optimal security configuration strategy. According to the embodiment, the effectiveness of the defense efficiency is improved, and the service safety and the user service quality can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present disclosure relate to the technical field of computer technology, and particularly to a service dynamic deployment system for container cloud. BACKGROUND

[0002] The service dynamic deployment for container cloud is a technology for dynamically deploying services under the container cloud. At present, the commonly used way is that the container cloud optimal active defense security configuration strategy implements service dynamic deployment.

[0003] However, when the above way is used, the following technical problems often exist: The container cloud optimal active defense security configuration strategy mainly focuses on enhancing the security protection capability of the system, lacks coordination with the resource allocation strategy, and is difficult to balance the service quality of the system under dynamic traffic requests. The resource allocation strategy in the microservice will cause the change of the service quality, and affect the system configuration of the microservice. The dynamic change of the system configuration of the microservice causes adverse effects on the defense effect and the service quality, and cannot give the optimal security configuration strategy in real time.

[0004] The above information disclosed in this BACKGROUND section is only for the purpose of enhancing the understanding of the background of the present inventive concepts, and therefore, it can contain information that does not form the prior art that is already known to those of ordinary skill in the art. SUMMARY

[0005] The summary section of the present disclosure is used to introduce the concepts in a brief manner, which will be described in detail in the specific embodiments section. The summary section of the present disclosure is not intended to identify key or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.

[0006] Some embodiments of the present disclosure propose a service dynamic deployment system for container cloud to solve the technical problems mentioned in the background section.

[0007] In a first aspect, some embodiments of the present disclosure provide a container cloud-oriented service dynamic deployment system, which comprises: the above-mentioned orchestration platform is configured to: create a computing network resource pool according to a preset service resource set, and send the above-mentioned computing network resource pool to a resource monitoring module; the above-mentioned resource monitoring module is configured to: update service state information and security configuration information in the received computing network resource pool to obtain updated service state information and updated security configuration information, and send the above-mentioned updated service state information and the above-mentioned updated security configuration information to a security configuration solving submodule; the above-mentioned security decision module is configured to: generate an optimal security configuration strategy according to the received updated service state information and updated security configuration information, and send the above-mentioned optimal security configuration strategy to a control module; and the above-mentioned control module is configured to: dynamically deploy the received optimal security configuration strategy.

[0008] In a second aspect, some embodiments of the present disclosure provide an electronic device, comprising: one or more processors; a storage device having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the system described in any of the implementations of the first aspect.

[0009] In a third aspect, some embodiments of the present disclosure provide a computer readable medium having a computer program stored thereon, wherein the program is executed by a processor to implement the system described in any of the implementations of the first aspect.

[0010] The above-mentioned various embodiments of the present disclosure have the following beneficial effects: through the container cloud-oriented service dynamic deployment system of some embodiments of the present disclosure, the effectiveness of the defense efficiency is improved, and the security of the service and the quality of service of the user can be effectively increased. Specifically, based on the orchestration platform, the state information of the computing resources, network resources and storage resources of the computing nodes and the security configuration information of the service are extracted in real time, the network attack graph model is constructed by the resource monitoring module to describe the relationship between the micro-service user traffic, system configuration, security capability and service quality, the security configuration strategy of the service is solved in real time by the security decision module through the design of the deep reinforcement learning algorithm, and the generated security configuration strategy is sent to the computing network resources by the control module to dynamically adjust the security configuration strategy of the service, thereby improving the effectiveness of the defense efficiency and effectively increasing the security of the service and the quality of service of the user. BRIEF DESCRIPTION OF DRAWINGS

[0011] The above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the elements and elements are not necessarily drawn to scale.

[0012] Figure 1 is a flowchart of some embodiments of a container cloud oriented service dynamic deployment system according to the present disclosure; Figure 2 is a framework diagram of some embodiments of a container cloud oriented service dynamic deployment system according to the present disclosure; Figure 3 is a network attack diagram of some embodiments of a container cloud oriented service dynamic deployment system according to the present disclosure; Figure 4 is an ASDS-DRL overall framework diagram of some embodiments of a container cloud oriented service dynamic deployment system according to the present disclosure; Figure 5 is a structural schematic diagram of an electronic device suitable for use to implement some embodiments of the present disclosure. DETAILED DESCRIPTION

[0013] Embodiments of the present disclosure will be described below in greater detail with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be construed as being limited to the embodiments set forth herein. Rather, these embodiments are provided so that the present disclosure will be more thoroughly and completely understood. It should be understood that the drawings of the present disclosure are only for illustrative purposes and should not be construed as limiting the scope of protection of the present disclosure.

[0014] It should also be noted that only parts related to the present application are shown in the drawings for the purpose of description. The embodiments in the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0015] It should be noted that the terms "first", "second", and the like in the present disclosure are only used to distinguish different devices, modules or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules or units.

[0016] It should be noted that the terms "one", "multiple" in the present disclosure are illustrative and not restrictive, and those skilled in the art should understand that unless otherwise explicitly stated in the context, it should be understood as "one or more".

[0017] The names of the messages or information exchanged between the devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.

[0018] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.

[0019] Figure 1A flow 100 of some embodiments of a container cloud oriented service dynamic deployment system according to the present disclosure is shown. The container cloud oriented service dynamic deployment system includes the following steps: Step 101, an orchestration platform is configured to create a computing network resource pool according to a preset service resource set, and send the computing network resource pool to a resource monitoring module.

[0020] In some embodiments, the orchestration platform is configured to create a computing network resource pool according to a preset service resource set, and send the computing network resource pool to a resource monitoring module.

[0021] Here, the orchestration platform is used to extract the state information of services and respective computing nodes in real time. The orchestration platform can refer to (Kubernetes, K8s). The respective computing nodes are a set of computing resources, network resources, and storage resources provided for services. The computing network resource pool includes computing resources, network resources, and storage resources. For example, the computing resources can refer to 10 virtual machines, each virtual machine is configured with 4-core CPU and 8GB memory. The network resources can refer to 100Mbps network bandwidth. The storage resources can refer to 1TB distributed storage space. The computing network resource pool is composed of computing nodes, and the micro-service application has a total of services, the upper limit of the number of replicas of the service is . The running state of the service is . Wherein, is an integer, which refers to the number of the computing node where the replica is located. The running state of the application can be composed of the running states of all micro-services, that is, the running state of the application . Combining the running state of the current application and the security configuration, the input state data can be obtained, that is, the input state data . Wherein, represents the cleaning cycle strategy of the service, represents the number of replicas of the micro-service replica, represents the user service request rate. represents the running state of the application. The micro-service application is an application for user service request, and each application has multiple services. Wherein, represents the number of computing nodes of the computing network resource pool, represents the number of services in the micro-service application. The value range of represents the service replica. The subscript represents the current time. The preset service resource set can refer to a set of resources of the cloud platform service that is preset. For example, the preset service resource set can refer to a set of computing resources and network resources of the cloud platform service that is preset.

[0022] As an example, the above-mentioned orchestration platform creates a computing network resource pool according to the computing resources, network resources and storage resources possessed by the preset service resource set, and the computing network resource pool is uniformly managed by the orchestration platform.

[0023] In step 102, the resource monitoring module is configured to update the received service state information and security configuration information in the computing network resource pool to obtain updated service state information and updated security configuration information, and send the updated service state information and the updated security configuration information to the security configuration solving submodule.

[0024] In some embodiments, the resource monitoring module is configured to update the received service state information and security configuration information in the computing network resource pool to obtain updated service state information and updated security configuration information, and send the updated service state information and the updated security configuration information to the security configuration solving submodule.

[0025] Here, the resource monitoring module is used to obtain real-time state data, which is composed of the running state of the application and the security protection configuration. The running state of the application can be composed of the running state of all services, and the computing node number where the service is located is the running state of the service. The security configuration refers to the dynamic cleaning period provided for each service. The updated service state information can include: the number of service replicas, the request arrival rate and the replica health state. For example, the number of service replicas can mean that microservice A currently runs 3 replicas, which are deployed on virtual machine 1, virtual machine 3 and virtual machine 5. The request arrival rate can mean that the request arrival rate of microservice A is 100 times per second. The replica health state can mean that all replicas are running normally and have no faults. The updated security configuration information includes: the cleaning period and the security protection strategy. For example, the cleaning period can mean that the security cleaning period of microservice A is once per hour. The security protection strategy can mean that microservice A enables a firewall and an intrusion detection system.

[0026] Optionally, the resource monitoring module can update the received service state information and security configuration information in the computing network resource pool to obtain updated service state information and updated security configuration information by the following steps: According to a preset period, the service state information and the security configuration information are updated in real time to generate updated service state information and updated security configuration information.

[0027] Here, the preset period can refer to a preset cleaning period. For example, the preset period can refer to once per hour.

[0028] As an example, the resource monitoring module monitors and updates the state data of the input in real time According to the calling relationship between services, a network attack graph model is constructed wherein, , represents a set of n microservices, represents an edge in the graph that has a dependency relationship, represents whether a vertex in the graph has an edge relationship, 1 represents an edge relationship, and 0 represents no edge relationship. and represent two different microservices. Subscripts i and j are used to distinguish different microservices. Microservice replicas are created from the same image and have the same function. Attackers can use vulnerabilities for horizontal movement, and the weight of the edge represents the success rate of the system defense. The network attack graph model and the calling relationship between services are shown in Figure 3 . It is assumed that the attacker comes from the outside, and the attacker can attack through the application layer microservice that provides an interface to the outside and the container vulnerability where it is located. The graph describes the security threat, and the attacker can use the vulnerability of microservice A to launch an attack. After hijacking microservice A, the attacker can use the calling relationship between microservices to launch attacks on microservices C and B. In addition, the attacker can attack the container environment where microservice A is located by using poor configuration or web server, container and operating system related vulnerabilities (for example: CVE-2020-1938). When the attacker escapes from the container, the attacker hijacks the entire computing node at this time, and can further directly access the containerized microservice D located on the same computing node to achieve the purpose of successful intrusion.

[0029] In step 103, the security decision module is configured to: generate an optimal security configuration strategy according to the received updated service state information and updated security configuration information, and send the optimal security configuration strategy to the control module.

[0030] In some embodiments, the security decision module is configured to: generate an optimal security configuration strategy according to the received updated service state information and updated security configuration information, and send the optimal security configuration strategy to the control module.

[0031] Here, the security decision module includes a security configuration solving submodule and a security configuration deployment submodule, configured to run an iterative solving algorithm, generate an optimal security configuration strategy, and issue the optimal security configuration strategy to the security deployment submodule, which issues an instruction to the computing network resource pool through the resource control module for strategy deployment. For example, the optimal security configuration strategy can be that the number of replicas is 5 and the cleaning is performed once every 30 minutes.

[0032] As an example, the security decision module takes, as input, state information obtained in real time by the resource monitoring module, and performs an action of selecting an index number of a service to increase or decrease, selecting a number of replicas of the service to increase or decrease, or selecting a security configuration strategy of the service to update, and iteratively solves an optimal security configuration strategy by using an algorithm. The service can be a microservice.

[0033] Optionally, the security decision module includes a security configuration solving submodule and a security configuration deployment submodule, and The security configuration solving submodule is configured to update security configuration information and a solving algorithm according to the received updated service state information, and generate optimal state and security configuration information.

[0034] Optionally, the security configuration solving submodule updates the security configuration information and the solving algorithm according to the received updated service state information, and generates optimal state and security configuration information by the following steps: First, according to the updated service state information and the updated security configuration information, determine the number of replicas, the security configuration strategy, and the scheduling result.

[0035] As an example, the security configuration solving submodule generates the number of replicas and the security configuration strategy of the service, and simultaneously generates a scheduling result to form an input state of the algorithm.

[0036] Second, define a set of key performance indicators, wherein the set of key performance indicators includes security performance, quality of service requested by a user, and real-time defense efficiency.

[0037] Here, the overall security performance the quality of service requested by a user and the real-time defense efficiency . and represent the number of replicas of the microservice replicas. is a variable representing the response time of a single microservice. represents an attacker outside the cloud platform. represents the cleaning period of the microservice and its replicas.

[0038] ​The third step involves obtaining a reward value based on the aforementioned number of replicas, the aforementioned security configuration strategy, the aforementioned scheduling results, the deep reinforcement learning algorithm, and the actions.

[0039] Here, the aforementioned deep reinforcement learning algorithm can refer to Deep Q-Network (DQN). The operational state of each microservice is composed of information such as the number of its replicas, the compute node it resides on, and its security configuration. For the... Each microservice has a replica count of 1. The compute node where the microservice replica resides can be represented as ,in This indicates the compute node number in the cluster where the microservice replica is scheduled. Therefore, the overall runtime state of the application can be represented as follows: This refers to the collection of all microservice runtime states. At any given time, the security configuration information is determined by the current number of replicas. Cleaning cycle Composition, combined with the request arrival rate of microservices These three elements together constitute the security configuration information of the microservice at the current moment. This information can be obtained in real time by the status monitoring module through the microservice API interface. After the status monitoring module processes the initial state vector, the state data is a combination of the running state and security defense configuration, that is... The DQN algorithm determines the cleanup cycle and replica count of microservices given the current request arrival rate, which is a high-dimensional decision problem for the security policy deployment module. To solve this problem, the high-dimensional decision vector is transformed into multiple low-dimensional decision vectors. The action space contains three-dimensional operations: selecting a microservice and updating the cleanup cycle of the selected microservice. And change the number of selected microservice replicas. Finally, by progressively optimizing the reward value within the action space, the optimal security defense configuration for the current operating state is obtained.

[0040] The defined defense effectiveness when calculating the current reward. As the target of the reinforcement learning algorithm, the current state data is generated by acquiring the running state and security defense configuration of the microservices, and the effectiveness of the defense is calculated by combining the action selection. As a reward.

[0041] The fourth step is to update the parameters of the deep reinforcement learning algorithm based on the reward value to obtain the updated deep reinforcement learning algorithm.

[0042] As an example, based on the acquired reward value and new state information, the system uses the backpropagation algorithm to update the parameters of the neural network, resulting in the updated deep reinforcement learning algorithm.

[0043] In the fifth step, the optimal state and security configuration information are obtained in response to determining that the updated deep reinforcement learning algorithm has converged.

[0044] Here, when the value of the loss function is less than a preset threshold, it indicates that the algorithm has converged. The loss function reflects the gap between the current policy and the optimal policy. For example, if the value of the loss function gradually stabilizes and changes very little after multiple iterations, it indicates that the algorithm may have converged. For example, if the preset threshold is 0.01, and the current value of the loss function is less than 0.01, it indicates that the algorithm has converged.

[0045] The security configuration deployment submodule is configured to update and deploy the received optimal state and security configuration information to obtain an optimal security configuration policy.

[0046] As an example, in response to determining that the algorithm has converged, the system will obtain the optimized security defense configuration policy and the number of copies and deploy the policy through the control module. The control module will issue these policies to the computing network resource pool to dynamically adjust the running state and security configuration of the service to obtain an optimal security configuration policy.

[0047] In step 104, the control module is configured to dynamically deploy the received optimal security configuration policy.

[0048] In some embodiments, the control module is configured to dynamically deploy the received optimal security configuration policy.

[0049] Here, the above-mentioned control module is used to interact the generated optimal security decision with the orchestration platform to dynamically manage the service. When cleaning the service copies, the control module will put the cleaning event of each copy in a service into a separate queue. Only when the cleaning event is executed, the next cleaning event will be taken out from the queue and executed. Through this mechanism, it is ensured that the dynamic cleaning policy will not affect the availability of the service to achieve dynamic adjustment of the security configuration of the service.

[0050] The above-mentioned dynamic deployment can also represent adjusting the number of copies, adjusting the cleaning period, and ensuring service availability. For example, adjusting the number of copies means increasing the number of copies of microservice A from 3 to 5. The newly added copies are deployed to virtual machine 2 and virtual machine 4. Adjusting the cleaning period means that the control module updates the security configuration of microservice A to adjust the cleaning period from once every hour to once every 30 minutes. Ensuring service availability means that the control module will monitor the availability of the service during the adjustment process to ensure that the adjustment operation will not cause service interruption. For example, by gradually increasing the number of copies and verifying the response time and service quality of the service at each step.

[0051] The present disclosure provides an overall framework diagram of ASDS-DRL as follows:Figure 4 As shown, the container cloud cluster primarily uses a modified Kubernetes cluster to extract real-time orchestration details and is also responsible for real-time monitoring of the microservice cleanup cycle in the cloud. Number of copies and request delivery rate of microservices These three elements together form the initial state input vector of the ASDS-DRL framework. Based on the initial state input vector, the P3DQN algorithm, through multiple training processes, obtains the optimal decision vector for the current moment. According to the optimization objective, it solves in real-time for the optimal security deployment strategy of the microservice under the current state condition and sends the optimal security configuration decision vector to the security policy deployment module. When the state monitoring module senses a change in the microservice state, including the microservice's request arrival rate, replica count, node failure, etc., the state monitoring module resends the latest state to the P3DQN algorithm module to obtain the latest security decision vector. This guides the dynamic scaling unit in the security policy deployment module to manage the number of microservice replicas and the dynamic cleaning unit to perform replica cleaning operations. The core of ASDS-DRL lies in the fact that the decision module based on the P3DQN algorithm can quickly obtain the security configuration vector of the microservice under the current user request by inputting the initial state vector from the state monitoring module through a neural network, guiding the security configuration strategy module to optimize the deployment of microservices in the cloud.

[0052] During the training process of the DQN algorithm, state information is extracted using a neural network. Greedy strategy to select the action to be performed And record the rewards obtained. With the random selection of actions to be performed, the training process can fully learn from the unlearned actions in the early stages and incorporate the learned experience samples. The experience samples are stored in the experience replay pool. Once the pool is full, a set of experience samples is selected from it for each iteration. The loss function for training the network can be expressed as a formula at time t.

[0053] In DQN, record The parameters of the neural network are At that time, for the state and actions The output value of the neural network. The output layer is designed to contain two branches: one for estimating the value of the current state. Another advantage function used to estimate actions The specific calculation process is shown in the following formula, where... This represents the average value of the action advantage function in the action space. are parameters of the neural network. represents the learning objective of the evaluation network. represents the variance, which is used to represent the value of the loss function. In the training phase of DQN, in order to accelerate the iteration efficiency of the algorithm and improve the convergence stability of the algorithm, the training experience samples are usually extracted from the experience replay pool in a random manner, but the differences between the experience samples are not considered, thereby ignoring the importance of the experience samples. On this basis, the DQN algorithm uses a new strategy, that is, using a priority queue to store experience samples. The absolute value of the experience sample is larger, which means that the gap between the current estimated value and the target value is larger, and such experience is considered to be more valuable. Therefore, the probability of extracting experience samples with larger errors for training is higher, which helps to speed up the entire training process. is calculated as shown in the following formula, wherein is a very small but greater than zero value, which ensures that the experience sample has a chance to be extracted: In each iteration step, an action is selected based on the current state , and then the action is executed and the new state and the reward value from the environment are received, which are collected and used to update the parameters of the evaluation network to improve future decisions. represents the probability of selecting experience samples. represents the discount factor. represents the learning parameters of the neural network. The network parameters ensure that the algorithm can converge. In the algorithm execution, the number of iterations should be large enough to ensure that the neural network can converge to a stable strategy.

[0054] Reference is made below to Figure 5 , which shows a structural schematic diagram of an electronic device (e.g., a computing device) suitable for implementing some embodiments of the present disclosure. Figure 5 The electronic device shown is merely an example and should not bring any limitation to the function and use range of the embodiments of the present disclosure. As Figure 5As shown, the computer device includes a processor, a memory and a network interface connected through a system bus, wherein the memory can include a non-volatile storage medium and an internal memory. The non-volatile storage medium can store an operating system and a computer program. The computer program includes program instructions which, when executed, can cause the processor to execute any of the above systems. The processor is used to provide computing and control capabilities to support the operation of the entire computer device. The internal memory provides an environment for the operation of the computer program in the non-volatile storage medium, which, when executed by the processor, can cause the processor to execute any of the above systems. The network interface is used for network communication, such as sending assigned tasks, etc. Those skilled in the art can understand that Figure 5 The structure shown in the figure is only a block diagram of part of the structure related to the present disclosure, and does not constitute a limitation on the computer device to which the present disclosure is applied. The specific computer device can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0055] It should be understood that the processor can be a central processing unit (CPU), and the processor can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or the processor can also be any conventional processor.

[0056] Among them, in one embodiment, the processor is configured to run a computer program stored in the memory to implement the following steps: the orchestration platform is configured to create a computing network resource pool according to a preset service resource set, and send the computing network resource pool to a resource monitoring module; the resource monitoring module is configured to update the service state information and the security configuration information in the received computing network resource pool to obtain updated service state information and updated security configuration information, and send the updated service state information and the updated security configuration information to a security configuration solving submodule; the security decision module is configured to generate an optimal security configuration strategy according to the received updated service state information and updated security configuration information, and send the optimal security configuration strategy to a control module; and the control module is configured to dynamically deploy the received optimal security configuration strategy.

[0057] The embodiments of the present disclosure further provide a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program includes program instructions. When the program instructions are executed, a system is implemented. The system can refer to the container cloud oriented service dynamic deployment system according to the embodiments of the present disclosure.

[0058] The computer readable storage medium can be an internal storage unit of the computer device, for example, a hard disk or a memory of the computer device. The computer readable storage medium can also be an external storage device of the computer device, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, and the like.

[0059] It should be noted that, in this document, the terms "comprising", "containing" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, system, article or system including a list of elements not only includes those elements, but also includes other elements not explicitly listed, or inherent to such a process, system, article or system. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, system, article or system including the element.

[0060] The above description is only some of the preferred embodiments of the present disclosure and the explanation of the applied technical principles. Those skilled in the art should understand that the scope of the application involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combinations of the above technical features, and should also cover other technical solutions formed by any combinations of the above technical features or their equivalent features without departing from the above inventive concept. For example, the above features and the technical features with similar functions disclosed in the embodiments of the present disclosure (but not limited to) are replaced with each other to form a technical solution.

Claims

1. A dynamic service deployment system for container clouds, characterized in that, The service dynamic deployment system includes: an orchestration platform, a resource monitoring module, a security decision-making module, and a control module, among which: The orchestration platform is configured to: create a computing network resource pool based on a preset service resource set, and send the computing network resource pool to the resource monitoring module; The resource monitoring module is configured to: update the service status information and security configuration information received in the computing network resource pool to obtain updated service status information and updated security configuration information, and send the updated service status information and the updated security configuration information to the security configuration solving submodule; The security decision module is configured to: generate an optimal security configuration policy based on the received update service status information and update security configuration information, and send the optimal security configuration policy to the control module; The control module is configured to dynamically deploy the received optimal security configuration policy.

2. The system according to claim 1, characterized in that, The security decision module includes: a security configuration solving submodule and a security configuration deployment submodule; and The security configuration solving submodule is configured to: update the security configuration information and solving algorithm based on the received update service status information, and generate the optimal status and security configuration information; The security configuration deployment submodule is configured to update and deploy the received optimal state and security configuration information to obtain the optimal security configuration strategy.

3. The system according to claim 2, characterized in that, The security configuration solving submodule is further configured as follows: Based on the updated service status information and updated security configuration information, determine the number of replicas, security configuration policy, and scheduling result; Define a set of key performance indicators, wherein the set of key performance indicators includes: security performance, service quality of user requests, and real-time defense efficiency. Based on the number of replicas, the security configuration policy, the scheduling result, the deep reinforcement learning algorithm and actions, a reward value is obtained; Based on the reward value, the parameters of the deep reinforcement learning algorithm are updated to obtain the updated deep reinforcement learning algorithm; In response to the confirmation that the deep reinforcement learning algorithm has converged after the update, the optimal state and security configuration information are obtained.

4. The system according to claim 1, characterized in that, The resource monitoring module is further configured to: According to a preset cycle, the service status information and security configuration information are updated in real time to generate updated service status information and updated security configuration information.

5. An electronic device, characterized in that, include: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the system as described in any one of claims 1 to 4.

6. A computer-readable medium, characterized in that, It stores a computer program thereon, wherein the computer program, when executed by a processor, implements the system as described in any one of claims 1 to 4.