A multi-data center software-defined resource scheduling and security isolation method

By integrating monitoring resource pools across multiple data centers and combining data characteristics and security analysis, the monitoring resource solution was iteratively optimized, solving the problems of security vulnerabilities in monitoring plugins and decentralized resource management, and achieving precise resource scheduling and effective security isolation.

CN121441605BActive Publication Date: 2026-05-15SHANXI ZHONGXINTONG INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANXI ZHONGXINTONG INFORMATION TECHNOLOGY CO LTD
Filing Date
2025-11-11
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In existing technologies, monitoring of multiple data centers relies on internal server plugins, which poses security risks, is vulnerable to attacks, and has fragmented management of monitoring resources, making it difficult to adapt to the diverse monitoring needs in cloud-edge collaborative scenarios.

Method used

By acquiring resource pools of multiple types of monitoring resources, randomly setting monitoring resource schemes, combining data operation characteristics and monitoring security analysis, calculating monitoring adaptability, and iteratively optimizing to obtain the optimal resource scheme, resource scheduling and security isolation are achieved.

Benefits of technology

It achieves precise adaptation and efficient allocation of resources across multiple data centers, strengthens the security isolation and protection between the monitoring layer and the business layer, reduces the risk of malicious attacks, and ensures the stability and security of the data center.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121441605B_ABST
    Figure CN121441605B_ABST
Patent Text Reader

Abstract

The application discloses a kind of multi-data center software definition resource scheduling and security isolation method, it is related to network security technical field.The method includes: obtaining the multiple monitoring resource pools of multiple monitoring resources for cloud edge monitoring to multiple data centers, randomly set multiple first monitoring resource schemes for monitoring to multiple data centers;Obtain the data running characteristics of multiple data centers, carry out the monitoring security analysis of multiple monitoring resources, obtain multiple monitoring security parameter sets;According to multiple data running characteristics, carry out data importance analysis, obtain multiple data importance parameters, combine the multiple monitoring security parameter sets and multiple first monitoring resource schemes, calculate and obtain first monitoring fitness;Iterative optimization obtains multiple optimal monitoring resource schemes, carries out resource scheduling and security isolation protection.The application effectively improves the security protection capability of multiple data centers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, specifically to a method for multi-datacenter software-defined resource scheduling and security isolation. Background Technology

[0002] With the rapid development of cloud computing and big data technologies, distributed computing environments consisting of multiple data centers have become a critical infrastructure supporting large-scale applications. To achieve unified management and efficient scheduling of resources across data centers, existing technologies generally employ the method of installing agent plugins on physical servers or virtual machines to monitor hardware resources, network status, and application runtime data in real time, thereby providing decision-making basis for resource scheduling systems.

[0003] However, monitoring methods relying on internal server plugins have security vulnerabilities. The system privileges required by these plugins make them easy entry points for malicious attacks. Once a plugin is compromised, it can not only distort monitoring data but also jeopardize the security of the server and even the entire data center, directly impacting the operational security of multiple data centers. Summary of the Invention

[0004] This application provides a method for multi-datacenter software-defined resource scheduling and security isolation, aiming to solve the technical problem of high security risks in the prior art.

[0005] In view of the above problems, this application provides a method for multi-datacenter software-defined resource scheduling and security isolation, including:

[0006] Obtain multiple monitoring resource pools for cloud-edge monitoring of multiple data centers, and randomly set multiple primary monitoring resource schemes for monitoring multiple data centers;

[0007] Acquire data operation characteristics from multiple data centers, perform monitoring security analysis on various types of monitoring resources, and obtain multiple sets of monitoring security parameters;

[0008] Based on multiple data operation characteristics, data importance analysis is performed to obtain multiple data importance parameters. Combining the multiple monitoring security parameter sets and multiple first monitoring resource schemes, a first monitoring fitness is calculated. The monitoring balance demand coefficient is configured according to data importance and added to the monitoring fitness calculation.

[0009] Multiple optimal monitoring resource solutions are obtained through iterative optimization, and resource scheduling and security isolation protection are implemented.

[0010] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0011] This application provides a method for software-defined resource scheduling and security isolation in multiple data centers. By monitoring resource pooling management and dynamic scheme configuration, combined with data operation characteristic analysis and monitoring security assessment, and incorporating the design of monitoring balance requirements adapted to data importance, the optimal monitoring resource scheme is formed through iterative optimization. This achieves accurate adaptation and efficient allocation of resources in multiple data centers, strengthens the security isolation and protection between the monitoring layer and the business layer, effectively reduces the risk of malicious attacks, and ensures the stability of data center operations and data security. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 This is a flowchart illustrating a multi-datacenter software-defined resource scheduling and security isolation method provided in an embodiment of this application. Detailed Implementation

[0014] This application provides a method for multi-datacenter software-defined resource scheduling and security isolation, which is used to address the technical problem of high security risks in the prior art.

[0015] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0016] It should be noted that the terms "comprising" and "having" are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to these processes, methods, products, or devices.

[0017] Examples, such as Figure 1 As shown, this application provides a method for multi-datacenter software-defined resource scheduling and security isolation, the method comprising:

[0018] S100: Obtain multiple monitoring resource pools for cloud-edge monitoring of multiple data centers, and randomly set multiple primary monitoring resource schemes for monitoring multiple data centers.

[0019] In this embodiment, multiple monitoring resource pools are obtained to monitor multiple data centers using cloud-edge technology, and multiple first monitoring resource schemes are randomly configured to monitor these data centers. Existing multi-data center monitoring relies on server-embedded plugins, which poses a risk of security vulnerabilities and attacks. Furthermore, the dispersed management of monitoring resources makes it difficult to adapt to the diverse monitoring needs of cloud-edge collaborative scenarios. This step, through pooling and integrating monitoring resources and randomly generating initial schemes, first achieves centralized management of monitoring resources, eliminating reliance on single plugins. Then, it provides multiple initial samples for subsequent iterative optimizations, ensuring that subsequent optimizations cover a wider range of resource allocation possibilities, laying the foundation for precise scheduling and secure isolation.

[0020] Step S100 in the method provided in this application embodiment includes:

[0021] Acquire multiple monitoring resource pools for various monitoring methods and resources for cloud-edge monitoring of multiple data centers;

[0022] Within multiple monitoring resource pools, monitoring resources are randomly allocated to multiple data centers to obtain multiple first monitoring resource schemes. Each first monitoring resource scheme includes multiple resource allocation ratios for various types of monitoring resources in each data center.

[0023] First, acquire multiple monitoring resource pools for various monitoring methods and resources across multiple data centers for cloud-edge monitoring. Cloud-edge monitoring is a collaborative monitoring model combining cloud monitoring nodes and edge monitoring nodes, balancing global control with local real-time response. Cloud monitoring nodes are responsible for global monitoring data aggregation and coordination; edge monitoring nodes are deployed locally in the data centers and are responsible for collecting local operational data in real time. Monitoring resources refer to the hardware and software resources used to implement monitoring functions, including latency monitoring plugins, network traffic probes, host performance proxies, etc. A monitoring resource pool is a collection of resources that centrally integrates monitoring resources of the same type, categorized and managed according to monitoring functions for easy unified scheduling and allocation. Based on the monitoring needs of multiple data centers, determine the monitoring dimensions to be covered, integrate the total resources required for each monitoring dimension into an independent resource pool, and clarify the total monitoring capacity of each resource pool.

[0024] For example, suppose there are two data centers, DC1 and DC2, and two types of monitoring need to be implemented: temperature monitoring and latency monitoring. Temperature monitoring refers to monitoring the temperature of the server room, while latency monitoring refers to monitoring the data transmission delay across data centers. For temperature monitoring, hardware acquisition devices and computing resources are integrated, with a total acquisition capacity of 100 temperature measurements per minute, forming a temperature monitoring computing power pool. For latency monitoring, network bandwidth and analysis resources are integrated, with a total acquisition capacity of 80 latency measurements per minute, forming a latency monitoring bandwidth pool. Ultimately, two monitoring resource pools are obtained, corresponding to temperature and latency monitoring respectively, with the total resources of each pool quantified in terms of monitoring times per minute.

[0025] Secondly, within multiple monitoring resource pools, monitoring resources are randomly allocated to multiple data centers to obtain multiple first monitoring resource schemes. Each first monitoring resource scheme includes multiple resource allocation ratios for various types of monitoring resources in each data center. For each monitoring resource pool, the resource allocation ratios for each data center are randomly determined, with the sum of the ratios within the same resource pool being 1. The allocation ratios of all monitoring resource pools are combined to form a complete first monitoring resource scheme. This process is repeated to generate multiple first monitoring resource schemes.

[0026] For example, based on the aforementioned temperature monitoring computing power pool and latency monitoring bandwidth pool, the total acquisition capacity of the temperature monitoring computing power pool is 100 times / minute, and the total acquisition capacity of the latency monitoring bandwidth pool is 80 times / minute. Two first monitoring resource schemes are generated by randomly allocating resources to DC1 and DC2: Scheme 1: Temperature monitoring computing power pool: DC1 allocated 40%, i.e., 40 times / minute, DC2 allocated 60%, i.e., 60 times / minute, sum of ratios = 1; Latency monitoring bandwidth pool: DC1 allocated 30%, i.e., 24 times / minute, DC2 allocated 70%, i.e., 56 times / minute, sum of ratios = 1. Scheme 2: Temperature monitoring computing power pool: DC1 allocated 60%, i.e., 60 times / minute, DC2 allocated 40%, i.e., 40 times / minute, sum of ratios = 1; Latency monitoring bandwidth pool: DC1 allocated 50%, i.e., 40 times / minute, DC2 allocated 50%, i.e., 40 times / minute, sum of ratios = 1. Each scheme clearly defines the allocation ratio of the two data centers to the two types of monitoring resource pools, providing an initial basis for subsequent analysis of monitoring security and computational adaptability.

[0027] In this embodiment, by integrating multiple types of monitoring resources into a quantified resource pool, centralized and unified management and control of monitoring resources are achieved, improving the operability and accuracy of resource scheduling. Multiple first monitoring resource schemes are randomly generated, providing diverse initial allocation samples to avoid subsequent iterative optimization from getting stuck in local optima, laying the foundation for subsequent adaptation and optimization based on monitoring security and data importance. The allocation ratio of each data center to various types of monitoring resources is clearly defined to ensure full utilization of monitoring resources, covering the multi-dimensional monitoring needs of multiple data centers, and providing a clear initial allocation basis for resource scheduling and security isolation.

[0028] S200: Acquires data operation characteristics from multiple data centers, performs monitoring security analysis on various types of monitoring resources, and obtains multiple sets of monitoring security parameters.

[0029] In this embodiment, data operation characteristics from multiple data centers are acquired, and monitoring security analysis of various monitoring resources is performed to obtain multiple sets of monitoring security parameters. Data centers with different data types and volumes face varying monitoring security risks, and general assessments alone cannot accurately identify the security adaptability of different monitoring resources. This step, by acquiring data operation characteristics and analyzing the security of monitoring resources based on historical security records of data centers within the same data family, achieves a precise match between security assessments and data operation characteristics, providing a scientific security basis for subsequent monitoring scheme optimization.

[0030] Step S200 in the method provided in this application embodiment includes:

[0031] Obtain the data operation characteristics of multiple data centers, where each data operation characteristic includes data type and data volume;

[0032] Based on data center operation data with different data operation characteristics over a historical period, we analyze the monitoring security parameters of various monitoring resources to obtain multiple sets of monitoring security parameters.

[0033] First, the operational characteristics of data from multiple data centers are acquired. Each operational characteristic includes data type and data volume. Data operational characteristics refer to the attributes of data generated and processed during data center operation, primarily including data type and data volume. Data type includes user identity information, business transaction data, and equipment temperature logs; data volume refers to the total amount of data processed per unit time, such as 10GB / hour or 5000 records / minute. For example, through the data center business management system, operational data from each center over the past 30 days is collected, and the data type and data volume per unit time are extracted to form the data operational characteristics. DC1's data type is user payment information, with a data volume of 50GB / hour; DC2's data type is system operation logs, with a data volume of 20GB / hour.

[0034] Secondly, based on the data center operation data with different data operation characteristics over a historical period, we analyze the monitoring security parameters of various monitoring resources to obtain multiple sets of monitoring security parameters.

[0035] This involves analyzing monitoring security parameters for various types of monitoring resources based on historical data with different data operation characteristics, resulting in multiple sets of monitoring security parameters, including:

[0036] Based on the data center operation data with different data operation characteristics over a historical period, collect multiple historical monitoring security record data of the same family of data centers with the aforementioned multiple data operation characteristics;

[0037] The proportion of data leaks caused by various monitoring methods is obtained from multiple historical monitoring security records to obtain multiple sets of data threat parameters, and multiple sets of monitoring security parameters are calculated.

[0038] First, based on historical data from data centers with different data operation characteristics over a historical period, multiple historical monitoring security records are collected from data centers within the same data family that possess these characteristics. Data operation characteristics are attributes describing the main business and load status of a data center, such as business type, load level, and data sensitivity. Data centers within the same data family refer to other data centers whose historical data operation characteristics match the current data center by ≥80%, and whose monitoring security operation data has direct reference value for the current center. Historical monitoring security records refer to security event data recorded by data centers within the same data family over a specified period when using multiple types of monitoring resources. This data primarily includes records related to data leakage events caused by monitoring resources or methods, such as the time of leakage, the corresponding monitoring type, and the number of leakages.

[0039] For example, based on the data operation characteristics of each center, data centers within the same data family are matched, and monitoring records for the past year are extracted. The focus is on statistically analyzing the total number of monitoring days for each type of monitoring resource and the number of days attacked through that type of monitoring resource. For DC1, one data center within the same family, DC1-1, is matched: Latency monitoring: 100 total monitoring days, with 3 days of attack injected via a latency monitoring plugin; Temperature monitoring: 100 total monitoring days, with 5 days of attack injected via a temperature monitoring plugin. For DC2, one data center within the same family, DC2-1, is matched: Latency monitoring: 100 total monitoring days, with 1 day of attack injected via a latency monitoring plugin; Temperature monitoring: 100 total monitoring days, with 2 days of attack injected via a temperature monitoring plugin.

[0040] Secondly, by acquiring multiple historical monitoring security records, the proportion of data leaks caused by various monitoring methods is obtained to generate multiple sets of data threat parameters, and multiple sets of monitoring security parameters are calculated. The data threat parameter refers to the proportion of times a monitoring resource has caused data leaks in the historical records of the same data center relative to the total number of security events. The higher the value, the greater the potential security risk of that monitoring resource. The monitoring security parameter is a parameter calculated in reverse based on the data threat parameter, directly reflecting the security protection capability of each type of monitoring resource against the corresponding data operation characteristics of the data center. The higher the value, the stronger the security. For each type of monitoring resource, the data threat parameter = number of attack days for that resource in the same data center / total number of monitoring days for that resource, and the security parameter = 1 - data threat parameter. These are then integrated to form a parameter set.

[0041] For example, calculate the monitoring security parameter set for DC1: Latency monitoring: Attack frequency percentage = 3 days / 100 days = 3%, monitoring security parameter = 1 - 3% = 97%; Temperature monitoring: Attack frequency percentage = 5 days / 100 days = 5%, monitoring security parameter = 1 - 5% = 95%. Calculate the monitoring security parameter set for DC2: Latency monitoring: Attack frequency percentage = 1 day / 100 days = 1%, monitoring security parameter = 1 - 1% / 99%; Temperature monitoring: Attack frequency percentage = 2 days / 100 days = 2%, monitoring security parameter = 1 - 2% = 98%. In summary, the monitoring security parameter set for DC1 is [Temperature monitoring: 95%, Latency monitoring: 97%], and the monitoring security parameter set for DC2 is [Temperature monitoring: 98%, Latency monitoring: 99%].

[0042] In this embodiment, the relationship between data operation characteristics and monitoring resource security is clearly defined; based on the historical security records of data centers of the same family, a set of monitoring security parameters is quantified, making the security performance of monitoring resources measurable and comparable, providing a security basis for subsequent calculation of monitoring adaptability in conjunction with data importance; and the differences in security requirements of different data centers are distinguished, providing a precise direction for subsequent iterative optimization of resource allocation schemes and strengthening of security isolation.

[0043] S300: Based on multiple data operation characteristics, perform data importance analysis to obtain multiple data importance parameters. Combine the multiple monitoring security parameter sets and multiple first monitoring resource schemes to calculate the first monitoring fitness. The monitoring balance demand coefficient is configured according to the data importance and added to the monitoring fitness calculation.

[0044] In this embodiment, data importance analysis is performed based on multiple data operation characteristics to obtain multiple data importance parameters. Combined with multiple sets of monitoring security parameters and multiple first monitoring resource schemes, a first monitoring fitness is calculated. A monitoring balance demand coefficient is incorporated into the monitoring fitness calculation based on data importance. Differences in data importance directly affect the allocation priority of monitoring resources; highly important data requires more secure and balanced monitoring resource support. Simultaneously, the balance of resource allocation also affects the overall monitoring effect. This step quantifies parameters through data importance analysis and, combined with security parameters and the initial scheme, calculates a monitoring fitness that integrates security and balance, providing a quantifiable scheme evaluation standard for subsequent iterative optimization.

[0045] Step S300 in the method provided in this application embodiment includes:

[0046] This involves conducting data importance analysis based on multiple data operational characteristics to obtain several data importance parameters, including:

[0047] Obtain a data importance classifier, wherein the data importance classifier is constructed based on a decision tree and is obtained by running a feature set and a set of sample data importance parameters on the sample data;

[0048] The multiple data operation features are respectively input into the data importance classifier, and multiple data importance parameters are output.

[0049] First, a data importance classifier is obtained. This classifier is built based on a decision tree and is constructed using a set of sample data operation features and a set of sample data importance parameters. A decision tree is a machine learning model primarily used to learn the mapping relationship between features and output results from data. The data importance classifier is a model built based on the decision tree algorithm, taking sample data operation features as input and sample data importance parameters as output, and is used to predict the importance of the operation features of new data. The data importance parameters quantify the importance of data processed by the data center, ranging from 0 to 1. For example, the importance parameter of sensitive payment data might be 0.9, and the importance parameter of system logs might be 0.6.

[0050] For example, when constructing a data importance classifier, sample data is first collected: the sample data feature set contains 1000 sets of sample data features, each set including data type and data volume. Domain experts label the 1000 sets of sample data features with corresponding sample data importance parameters based on data sensitivity, with values ​​ranging from 0 to 1, where higher values ​​indicate more important data. Using the 1000 sets of sample data features as input and the corresponding sample data importance parameters as output, the samples are divided into training and validation sets in a 7:3 ratio to train a decision tree-based model. Mean squared error is used as the splitting criterion; training stops when the validation set error decreases by ≤0.001 for multiple consecutive rounds, ultimately yielding the data importance classifier.

[0051] Secondly, the multiple data operation features are input into the data importance classifier, and multiple data importance parameters are output. For example, the data type of DC1 is user payment information, and the data volume is 50GB / hour; the data type of DC2 is system operation log, and the data volume is 20GB / hour. Inputting the data operation features of DC1 into the classifier outputs a data importance parameter of 0.9; inputting the data operation features of DC2 into the classifier outputs a data importance parameter of 0.6.

[0052] Specifically, by combining the multiple sets of monitoring security parameters and multiple first monitoring resource schemes, a first monitoring fitness is calculated, including:

[0053] Based on the weights allocated to the multiple resource allocation ratios of each data center within the multiple first monitoring resource schemes, the multiple monitoring security parameters within each monitoring security parameter set are weighted and calculated to obtain multiple first composite monitoring security parameters.

[0054] The first integrated monitoring security parameter is obtained by weighting the multiple first composite monitoring security parameters according to the weights assigned to multiple data importance parameters.

[0055] Multiple monitoring balance demand coefficients are configured based on multiple data importance parameters, and the first integrated monitoring balance parameter is calculated by combining multiple first monitoring resource schemes.

[0056] The first monitoring fitness is calculated based on the first integrated monitoring security parameters and the first integrated monitoring balance parameters.

[0057] First, based on the weights allocated to the resource allocation ratios of each data center within multiple first monitoring resource schemes, multiple monitoring security parameters within each monitoring security parameter set are weighted and calculated to obtain multiple first composite monitoring security parameters. The composite security level of a single data center is determined by the security of the various monitoring resources allocated to it; the higher the allocation ratio of a monitoring resource, the greater its impact on composite security. For each data center, the allocation ratio of various monitoring resources in the first scheme is used as the weight to weight and sum the parameters in the monitoring security parameter set to obtain the first composite monitoring security parameter. For example, for Scheme 1 in S100, the first composite monitoring security parameter of DC1 = temperature monitoring security × allocation ratio + latency monitoring security × allocation ratio = 95% × 40% + 97% × 30% = 0.38 + 0.291 = 0.671; similarly, the first composite monitoring security parameter of DC2 can be obtained as 98% × 60% + 99% × 70% = 1.281.

[0058] Secondly, weights are assigned to the multiple data importance parameters, and the multiple first composite monitoring security parameters are weighted and calculated to obtain the first integrated monitoring security parameter. The data importance parameters are used as weights, with higher importance resulting in greater weights. The weights are calculated by summing the first composite monitoring security parameters based on the proportion of each data center's importance parameter to the total importance. For example, total importance = DC1 importance + DC2 importance = 0.9 + 0.6 = 1.5; DC1 weight = 0.9 / 1.5 = 0.6, DC2 weight = 0.6 / 1.5 = 0.4; first integrated monitoring security parameter = first composite security parameter of DC1 × DC1 weight + first composite security parameter of DC2 × DC2 weight = 0.671 × 0.6 + 1.281 × 0.4 = 0.4026 + 0.5124 = 0.915.

[0059] Furthermore, multiple monitoring balance demand coefficients are configured based on multiple data importance parameters, and combined with multiple first monitoring resource schemes, the first integrated monitoring balance parameter is calculated.

[0060] This involves configuring multiple monitoring load balancing demand coefficients based on various data importance parameters, and combining these with multiple primary monitoring resource schemes to calculate the first integrated monitoring load balancing parameters, including:

[0061] Calculate the ratio of each data importance parameter to the maximum value among multiple data importance parameters, and use it as the multiple monitoring balance demand coefficient;

[0062] Calculate the reciprocal of the variance of multiple resource allocation ratios within each first monitoring resource scheme to obtain multiple first monitoring equilibrium parameters;

[0063] The first integrated monitoring balance parameter is obtained by weighting the multiple first monitoring balance parameters according to the weights assigned to the multiple monitoring balance demand coefficients.

[0064] First, calculate the ratio of each data importance parameter to the maximum value among multiple data importance parameters, using this ratio as multiple monitoring balance demand coefficients. Data centers with higher data importance have a stronger need for balanced monitoring resource allocation. The monitoring balance demand coefficient = importance parameter of a single data center / maximum value of all data center importance parameters; the higher the ratio, the stronger the demand. For example, if the maximum value of all data center importance parameters is 0.9 for DC1, then the monitoring balance demand coefficient for DC1 = 0.9 / 0.9 = 1; the monitoring balance demand coefficient for DC2 = 0.6 ÷ 0.9 ≈ 0.67.

[0065] Secondly, the reciprocal of the variance of multiple resource allocation ratios within each first monitoring resource scheme is calculated to obtain multiple first monitoring equilibrium parameters. The more balanced the resource allocation of a single data center, i.e., the smaller the difference in the allocation ratio of various monitoring resources, the more stable the monitoring effect. The degree of equilibrium is quantified by the reciprocal of the variance of the resource allocation ratio; the smaller the variance, the larger the reciprocal, i.e., the smaller the difference in resource allocation ratio, and the larger the equilibrium parameter. For a single data center, the allocation ratio of multiple monitoring resources in the first scheme is extracted, such as the allocation ratio of temperature and latency; the variance of the allocation ratio is calculated; the first monitoring equilibrium parameter = 1 / variance.

[0066] For example, in the first monitoring resource scheme, the allocation ratio of DC1 is: temperature monitoring 40%, latency monitoring 30%; the average ratio = (0.4 + 0.3) / 2 = 0.35; the variance = [(0.4 - 0.35)² + (0.3 - 0.35)²] / 2 = (0.0025 + 0.0025) / 2 = 0.0025; the first monitoring balancing parameter = 1 / 0.0025 = 400. The allocation ratio of DC2 is: temperature monitoring 60%, latency monitoring 70%; the average ratio = (0.6 + 0.7) / 2 = 0.65; the variance = [(0.6 - 0.65)² + (0.7 - 0.65)²] / 2 = 0.0025; the first monitoring balancing parameter = 1 / 0.0025 = 400.

[0067] Furthermore, based on the weights assigned to multiple monitoring balance demand coefficients, the multiple first monitoring balance parameters are weighted and calculated to obtain the first integrated monitoring balance parameter. The overall balance of the solution must prioritize data centers with high importance; therefore, the first monitoring balance parameters of each data center are weighted and summed using the monitoring balance demand coefficient as the weight to obtain a parameter reflecting the overall balance level. The first integrated monitoring balance parameter = Σ(first monitoring balance parameter of a single center × monitoring balance demand coefficient of that center). For example, the first integrated monitoring balance parameter = first monitoring balance parameter of DC1 × monitoring balance demand coefficient of DC1 + first monitoring balance parameter of DC2 × monitoring balance demand coefficient of DC2 = 400 × 1.0 + 400 × 0.6667 ≈ 666.68. After normalization, assuming the maximum value of the integrated monitoring balance parameter is 1000, the normalized first integrated monitoring balance parameter = 666.68 / 1000 ≈ 0.667.

[0068] Finally, the first monitoring fitness is calculated based on the first integrated monitoring security parameters and the first integrated monitoring balance parameters.

[0069] The first monitoring fitness is calculated based on the first integrated monitoring security parameters and the first integrated monitoring balance parameters, including:

[0070] Obtain the highest data importance parameter of the data center within a historical period;

[0071] The ratio of the mean of the multiple data importance parameters to the maximum data importance parameter is calculated as the monitoring security weight, and the monitoring balance weight is obtained by calculation.

[0072] The first monitoring fitness is obtained by weighting the first integrated monitoring security parameter and the first integrated monitoring balance parameter using the monitoring security weight and the monitoring balance weight.

[0073] First, retrieve the highest data importance parameter for the data center within a historical period. Using the highest historical data value level as a benchmark, determine the overall importance level of the current data center, providing a reference for weight allocation. Query the data importance parameters of all similar data centers in the historical database and extract the maximum value. For example, the query from the historical database shows that the highest data importance parameter for all data centers in the past was 1.0.

[0074] Secondly, the ratio of the mean of the multiple data importance parameters to the maximum data importance parameter is calculated as the monitoring security weight, and a monitoring balance weight is obtained. The closer the current average importance of the data center is to the historical maximum value, the higher the overall value of the data, and the higher the weight should be given to the security dimension; conversely, the weight of the balance dimension should be balanced. Monitoring security weight = mean of current multiple data importance parameters / historical maximum data importance parameter; monitoring balance weight = 1 - monitoring security weight. The higher the data importance, the higher the security priority; the closer the current overall data importance is to the historical maximum level, the greater the security weight. For example, the average data importance of DC1 and DC2 = (0.9 + 0.6) / 2 = 0.75, the maximum data importance parameter = 1.0, the monitoring security weight = 0.75 / 1.0 = 0.75, and the monitoring balance weight = 1 - 0.75 = 0.25.

[0075] Finally, the first integrated monitoring security parameter and the first integrated monitoring balance parameter are weighted and calculated using the aforementioned monitoring security weight and monitoring balance weight to obtain the first monitoring fitness. The first monitoring fitness is a quantitative score that combines the first integrated monitoring security parameter and the first integrated monitoring balance parameter, ranging from 0 to 1, and is used to measure the adaptability of the initial monitoring resource scheme. First monitoring fitness = First integrated monitoring security parameter × Monitoring security weight + First integrated monitoring balance parameter × Monitoring balance weight. For example, if the first integrated monitoring security parameter is 0.915 and the first integrated monitoring balance parameter is 0.667, the first monitoring fitness = 0.915 × 0.75 + 0.667 × 0.25 ≈ 0.686 + 0.167 = 0.853. The higher the value, the stronger the comprehensive adaptability of the scheme in terms of security and balance, and the more likely it is to become the optimal scheme.

[0076] In this embodiment, a decision tree is used to quantify data importance parameters, enabling precise matching of resource allocation with data value. The fitness score is calculated by integrating three dimensions: monitoring security, data importance, and resource allocation balance. This ensures both the security priority of high-importance data centers and the stability of resource allocation, avoiding the limitations of a single dimension. Security and balance weights are calibrated using the historical maximum data importance parameter, improving scenario adaptability. The output quantitative fitness index provides a clear evaluation standard for subsequent iterative optimization, enhancing the scientific nature and operability of resource scheduling and security isolation strategies, and laying a quantitative foundation for the formation of the optimal solution.

[0077] S400: Iterative optimization yields multiple optimal monitoring resource schemes for resource scheduling and security isolation protection. Using the first monitoring fitness calculated by S300 as the initial evaluation benchmark, new monitoring resource schemes are generated through multiple rounds of iteration, and the corresponding fitness is calculated to obtain the second monitoring fitness, the third monitoring fitness, ..., the Nth monitoring fitness. Finally, the optimal scheme with the highest fitness is selected for resource scheduling and security isolation.

[0078] For example, continuing the scenario: data centers DC1 and DC2; monitoring resources are temperature monitoring and latency monitoring; initially, two first monitoring resource schemes are generated, and the fitness of the first monitoring is calculated by S300 to be 0.853 and 0.792, respectively. These two first monitoring resource schemes are used as the initial scheme set, and the fitness of the first monitoring is recorded. An iteration termination condition is set, such as the difference between the optimal fitness in two consecutive rounds ≤ 0.001. The scheme with the higher fitness of the first monitoring in the initial scheme is retained, i.e., scheme 1 is retained, and scheme 2 is eliminated. The resource allocation ratio of the retained scheme 1 is fine-tuned to generate the second-generation monitoring resource scheme: the temperature monitoring allocation ratio of DC1 is adjusted from 40% to 42%, and the latency monitoring allocation ratio is adjusted from 30% to 28%; the temperature monitoring allocation ratio of DC2 is adjusted from 60% to 58%, and the latency monitoring allocation ratio is adjusted from 70% to 72%. Calculate the fitness of the second monitoring: Evaluate the new scheme according to the S300 method, and the fitness of the second monitoring is 0.865; combine the new scheme with the retained initial scheme 1 to form the second-generation scheme set, where the optimal fitness is 0.865. Repeat the process of screening, mutation, and fitness calculation, retaining the current optimal scheme and mutating it to generate a new scheme in each round, and calculating the fitness of the corresponding round. Assuming that after the 5th iteration, the fitness of the fifth monitoring reaches 0.890, and the difference between two consecutive rounds is ≤0.001, satisfying the termination condition, then the optimal monitoring resource scheme is: DC1: 45% allocation for temperature monitoring, 35% allocation for latency monitoring; DC2: 55% allocation for temperature monitoring, 65% allocation for latency monitoring. Based on the optimal allocation of monitoring resources, DC1 receives 45% of the temperature monitoring computing power and 35% of the latency monitoring bandwidth, while DC2 receives 55% of the temperature monitoring computing power and 65% of the latency monitoring bandwidth. In conjunction with the monitoring security parameters in the scheme, isolation strategies are configured for resources with high adaptability. For example, the latency monitoring security of DC1 is 97%, and the isolation strategy is an encrypted transmission channel.

[0079] In this embodiment, by iteratively generating the second to Nth monitoring fitness scores, the resource allocation scheme is continuously optimized. This solves the potential local optima problem in the initial scheme corresponding to the first monitoring fitness score, resulting in an optimal scheme with higher fitness than the initial one, achieving precise matching between resource scheduling and data requirements. Each round of fitness calculation is linked to data importance, security, and balance, ensuring that the optimal scheme performs better in multiple dimensions. Implementing resource scheduling and isolation based on the optimal scheme not only improves the utilization efficiency of monitoring resources but also strengthens the targeted nature of security protection, effectively ensuring the stability and data security of multi-data center operation.

[0080] The embodiments of this application, through the specific implementation methods described above, achieve the following technical effects:

[0081] This application provides a software-defined resource scheduling and security isolation method for multiple data centers. By integrating various monitoring resources into a quantified resource pool, multiple initial allocation schemes are generated, laying a centralized scheduling foundation for subsequent optimization. A multi-dimensional and precise evaluation system is constructed: combining data operation characteristics with historical attack records of data centers of the same family, monitoring security parameters are quantified, breaking through the subjective limitations of traditional security assessments. A decision tree classifier accurately outputs data importance parameters, integrates security, importance, and balance dimensions to calculate fitness, and uses historical data to calibrate weights, solving the problem of single-dimensional evaluation being out of touch with actual needs. Based on multiple iterations, the optimal scheme is selected and evolved, breaking through the local optima of the initial scheme, effectively improving the fitness of the final scheme, and ensuring that resource allocation is accurately matched with data center needs. When implementing the optimal scheme, both scientific scheduling improves the utilization efficiency of monitoring resources and targeted isolation protection is implemented in conjunction with the scheme's security parameters, achieving synergistic optimization of efficient utilization of monitoring resources and stable data security operation across multiple data centers.

[0082] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0083] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0084] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.

Claims

1. A method for multi-datacenter software-defined resource scheduling and security isolation, characterized in that, The method includes: Obtain multiple monitoring resource pools for cloud-edge monitoring of multiple data centers, and randomly set multiple primary monitoring resource schemes for monitoring multiple data centers; Acquire data operation characteristics from multiple data centers, perform monitoring security analysis on various types of monitoring resources, and obtain multiple sets of monitoring security parameters; Based on multiple data operation characteristics, data importance analysis is performed to obtain multiple data importance parameters. Combining the multiple monitoring security parameter sets and multiple first monitoring resource schemes, a first monitoring fitness is calculated. The monitoring balance demand coefficient is configured according to data importance and added to the monitoring fitness calculation. Specifically, by combining the multiple sets of monitoring security parameters and multiple first monitoring resource schemes, a first monitoring fitness is calculated, including: Based on the weights allocated to the multiple resource allocation ratios of each data center within the multiple first monitoring resource schemes, the multiple monitoring security parameters within each monitoring security parameter set are weighted and calculated to obtain multiple first composite monitoring security parameters. The first integrated monitoring security parameter is obtained by weighting the multiple first composite monitoring security parameters according to the weights assigned to multiple data importance parameters. Calculate the ratio of each data importance parameter to the maximum value among multiple data importance parameters, and use it as the multiple monitoring balance demand coefficient; Calculate the reciprocal of the variance of multiple resource allocation ratios within each first monitoring resource scheme to obtain multiple first monitoring equilibrium parameters; Based on the weights assigned to multiple monitoring balance demand coefficients, the multiple first monitoring balance parameters are weighted and calculated to obtain the first integrated monitoring balance parameters. The first monitoring fitness is calculated based on the first integrated monitoring security parameters and the first integrated monitoring balance parameters. Multiple optimal monitoring resource solutions are obtained through iterative optimization, and resource scheduling and security isolation protection are implemented.

2. The multi-datacenter software-defined resource scheduling and security isolation method according to claim 1, characterized in that, Obtain multiple monitoring resource pools for cloud-edge monitoring of multiple data centers, and randomly configure multiple primary monitoring resource schemes for monitoring multiple data centers, including: Acquire multiple monitoring resource pools for various monitoring methods and resources for cloud-edge monitoring of multiple data centers; Within multiple monitoring resource pools, monitoring resources are randomly allocated to multiple data centers to obtain multiple first monitoring resource schemes. Each first monitoring resource scheme includes multiple resource allocation ratios for various types of monitoring resources in each data center.

3. The multi-datacenter software-defined resource scheduling and security isolation method according to claim 1, characterized in that, Acquire data operation characteristics from multiple data centers, perform monitoring security analysis on various types of monitoring resources, and obtain multiple sets of monitoring security parameters, including: Obtain the data operation characteristics of multiple data centers, where each data operation characteristic includes data type and data volume; Based on data center operation data with different data operation characteristics over a historical period, we analyze the monitoring security parameters of various monitoring resources to obtain multiple sets of monitoring security parameters.

4. The multi-datacenter software-defined resource scheduling and security isolation method according to claim 3, characterized in that, Based on data center operation data with different data operation characteristics over historical periods, we analyze the monitoring security parameters of various monitoring resources to obtain multiple sets of monitoring security parameters, including: Based on the data center operation data with different data operation characteristics over a historical period, collect multiple historical monitoring security record data of the same family of data centers with the aforementioned multiple data operation characteristics; The proportion of data leaks caused by various monitoring methods is obtained from multiple historical monitoring security records to obtain multiple sets of data threat parameters, and multiple sets of monitoring security parameters are calculated.

5. The multi-datacenter software-defined resource scheduling and security isolation method according to claim 1, characterized in that, Based on multiple data operation characteristics, data importance analysis is performed to obtain multiple data importance parameters, including: Obtain a data importance classifier, wherein the data importance classifier is constructed based on a decision tree and is obtained by running a feature set and a set of sample data importance parameters on the sample data; The multiple data operation features are respectively input into the data importance classifier, and multiple data importance parameters are output.

6. The multi-datacenter software-defined resource scheduling and security isolation method according to claim 1, characterized in that, Based on the first integrated monitoring security parameters and the first integrated monitoring balance parameters, the first monitoring fitness is calculated, including: Obtain the highest data importance parameter of the data center within a historical period; The ratio of the mean of the multiple data importance parameters to the maximum data importance parameter is calculated as the monitoring security weight, and the monitoring balance weight is obtained by calculation. The first monitoring fitness is obtained by weighting the first integrated monitoring security parameter and the first integrated monitoring balance parameter using the monitoring security weight and the monitoring balance weight.