An endogenous security dynamic immune method and system for heterogeneous computing power network service zero interruption

By employing dynamic exposure surface transitions, heterogeneous voting, and zero-disruption switching methods in heterogeneous computing networks, the challenge of zero-disruption security protection in heterogeneous computing networks is solved, achieving efficient protection against unknown vulnerabilities and zero-day attacks, and ensuring business continuity and security.

CN121770909BActive Publication Date: 2026-04-28NANJING UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
NANJING UNIV OF SCI & TECH
Filing Date
2026-03-04
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing technologies struggle to achieve zero-disruption security protection in heterogeneous computing networks. In particular, when facing unknown vulnerabilities and zero-day attacks, traditional protection systems are unable to respond quickly and are prone to false alarms or service interruptions. Furthermore, they lack real-time awareness and robustness regarding attack paths.

Method used

By employing methods such as dynamic exposure surface transition, heterogeneous voting and proactive disturbance avoidance perception, uncertainty perception and threshold adaptation, and zero-interruption switching, and by controlling exposure surface changes, parallel processing of heterogeneous branches, and trusted weighted voting, combined with session stickiness, state dual writing, and idempotent replay, seamless business migration and a balance between security and quality of service are achieved.

Benefits of technology

It significantly improves the ability to resist scanning and exploitation attacks, reduces the risk of misjudgment, ensures business continuity, meets the availability and latency requirements of service level agreements, and enhances robustness against input and branch pollution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121770909B_ABST
    Figure CN121770909B_ABST
Patent Text Reader

Abstract

The application discloses a kind of isomeric computing power net service zero-interruption endogenous security dynamic immunity method and system, belong to network security technical field.The method includes using exposure surface dynamic hopping and isomeric voting active avoidance sensing cooperative mechanism, periodically or event triggered controlled change is carried out to service interface, access entrance and resource address, combined with the isomeric parallel processing of multiple hardware and multiple models, multiple discriminant is output for the same request, and trusted result is obtained by weighted voting;According to abnormal score and uncertainty evaluation, the hopping intensity and access threshold are adaptively adjusted;Under the guarantee of session and state double writing, seamless migration is completed, and zero-interruption switching is realized.The method can significantly improve the resistance of computing power network to scanning, probing and exploitation attacks without changing the upper layer business logic, while controlling resource overhead.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, specifically relating to an intrinsic security dynamic immunity method and system for zero-interruption of heterogeneous computing power network services. Background Technology

[0002] With the widespread adoption of cloud computing, edge computing, and specialized acceleration chips, business systems are evolving from single data centers to heterogeneous computing networks that collaborate across centers, edges, and terminals. Computing power and data continuously flow across multiple regions, platforms, and networks, resulting in highly dynamic, high-concurrency, and highly available operational characteristics for service interfaces, access points, and resource addresses. Against this backdrop, issues such as unknown vulnerabilities and zero-day attacks, automated scanning and enumeration, supply chain contamination, and adversarial examples are constantly increasing. Traditional protection systems based on static boundaries and fixed configurations struggle to detect and block rapidly evolving attack paths in a timely manner. Once an exposure surface is enumerated or a single point is exploited, it can easily trigger business instability or even widespread outages, failing to meet the zero-interruption / high-reliability requirements of critical businesses.

[0003] Existing technologies typically address this issue through three paths: first, perimeter protection and in-depth deployment with strong outer perimeter and weak inner perimeter, using rules configured on gateways, WAFs, IDS / IPS, and other devices for interception; second, using single-implementation or single-model detection to discriminate requests; and third, performing manual or semi-automatic address switching, canary releases, and rate limiting within a change window. However, these solutions generally have limitations: static or periodic strategies are easily circumvented by attackers through scanning and fingerprinting; single-implementation authentication links lack robustness against targeted exploitation, bypass pollution, or adversarial examples; change operations and service switching often require maintaining a window, making rapid migration without interrupting sessions difficult. Furthermore, thresholds and policies are mostly manually set, lacking the ability to adaptively adjust based on risk conditions, easily leading to frequent jitter or delayed responses driven by false alarms.

[0004] In recent years, Moving Target Defense (MTD) and diversified execution voting (such as N-version and N-variant) have been proposed to increase the cost of attacks and reduce the probability of single points of failure; service mesh provides the infrastructure for unified governance of routing and certificates.

[0005] However, existing practices still have three shortcomings: First, the changes in the exposure surface are mostly low-frequency and predetermined, making it difficult to link with real-time risk signals; second, heterogeneous parallelism is often used for fault tolerance or performance optimization, but lacks a security decision-making mechanism that incorporates branch credibility and uncertainty into weighted voting, which may lead to incorrect judgments when encountering adversarial inputs or branch contamination; third, exposure surface switching often requires session reconstruction or short-term freezing, and lacks zero-interruption guarantee measures such as state dual writing, idempotent replay, and waterline control for long connections and streaming tasks. Summary of the Invention

[0006] To address the problems mentioned in the background section, this invention proposes an intrinsic security dynamic immunity method and system for heterogeneous computing power networks with zero service interruption. This method can significantly improve the computing power network's resistance to scanning, probing, and exploitation attacks without modifying the upper-layer business logic, while controlling resource consumption.

[0007] Technical Solution: To solve the above-mentioned technical problems, the present invention adopts the following technical solution:

[0008] An intrinsic security dynamic immunization method for zero-interruption services in heterogeneous computing power networks includes the following steps:

[0009] Step 1, Dynamic Transition of Exposure Surface: Controlled changes are made to the network service interface, access point and resource address according to the set exposure surface transition strategy, and a unique resource descriptor is generated for each round of exposure surface within the validity period;

[0010] Step 2, proactive avoidance of disturbances in heterogeneous voting: incoming business requests are processed in parallel on K heterogeneous execution branches and the judgment results are output. The final result is obtained based on trusted weighted voting, and when a high risk is determined, the system proactively switches to a new exposure surface.

[0011] Step 3, Uncertainty Perception and Threshold Adaptation: Calculate the anomaly score and predict uncertainty. When either of these indicators exceeds the threshold, increase the jump frequency and tighten the access policy. When the situation remains stable, decrease the jump frequency to save resources.

[0012] Step 4, Zero-interruption handover: Complete the session migration and state replication from the old exposure surface to the new exposure surface without interrupting the session, and ensure consistent processing results through idempotent replay and sequence control;

[0013] Step 5, Closed-loop strategy adjustment: Based on feedback from decreased attack hit rate, service level agreement default rate, switching latency and resource overhead, update the jump strength, access threshold and visible entry point-address set online to achieve a balance between security and service quality.

[0014] Preferably, in step 1, the implementation process of the dynamic change of the exposed surface is as follows:

[0015] Step 1.1: Determine the switching timing and scope based on the exposure surface transition strategy;

[0016] Step 1.2: The system performs controlled replacement of semantically equivalent application programming interfaces across multiple versions to reduce the risk of a single implementation being exploited;

[0017] Step 1.3, during the window period Internal execution of entry point rotation ensures that the entry point's online probability satisfies... And an exponential backoff is used for the entry threshold to suppress enumeration;

[0018] in, This represents the probability that a certain entry point will be set to online within the current scheduling interval. This indicates the arrival rate of the entry point going live event. The function exp() represents the scheduling interval.

[0019] Step 1.4: Select a new IP address and port / protocol pair as the access address through the DNS domain name system, and bind this address to a one-time token with a validity period τ;

[0020] Step 1.5: Generate a one-time resource / request identifier (RID) based on a hash-based message authentication code, and optionally use a time-based one-time password to enhance short-term access control;

[0021] Step 1.6, in the migration window The issuance and activation of the new exposure surface were completed within the time limit.

[0022] Preferably, in step 2, the process of actively avoiding perturbation sensing in heterogeneous voting is as follows:

[0023] Step 2.1: Select two classes in the heterogeneous dimension to establish K execution branches;

[0024] Step 2.2: Run the same request independently on each branch and generate judgment results, anomaly scores, and branch uncertainty;

[0025] Step 2.3: Determine the final output category based on the credible weighted voting rules;

[0026] Step 2.4: Perform confidence filtering before voting. When a branch simultaneously satisfies... The branch road should be temporarily removed and the evidence recorded.

[0027] in, Indicates the uncertainty threshold. Indicates the branch abnormality score, This represents the set of anomaly scores for all branches. This represents the median of the entire set of branch anomaly scores. Indicates the outlier threshold. This indicates uncertainty in the branch path;

[0028] Step 2.5: After a removal occurs, the weights are renormalized according to the remaining valid branches and the weighted voting continues. When the number of valid branches is lower than the policy lower limit, a fallback is triggered to ensure service continuity.

[0029] Preferably, in step 2.3, the specific implementation process for determining the final output category based on the credible weighted voting rule is as follows:

[0030] ;

[0031] ;

[0032] Where C represents the set of candidate categories, Indicates candidate category labels, Indicates an indicator function, Indicates the first The result of branch identification; This represents the voting weight of the k-th branch; K represents the total number of parallel branches. Indicates the final output category; Indicates the historical reliability of the k-th branch. Represents runtime integrity metrics. This indicates uncertainty in the branch path; , This indicates a non-negative coefficient.

[0033] As a preferred option, the specific method for uncertainty perception and threshold adaptation in step 3 is as follows:

[0034] Step 3.1: Construct feature vectors And standardize it;

[0035] Step 3.2: Calculate the branch k anomaly score using Mahalanobis distance. ;

[0036] Step 3.3: Evaluate the uncertainty of branch k using Monte Carlo sampling or model ensemble. ;

[0037] Step 3.4: Make adaptive adjustments based on the dual thresholds;

[0038] when or At the same time, increase the jump strength When the duration is continuous and stable Reduce jump intensity if the boundary is not crossed. ;

[0039] in, Indicates the branch abnormality score, Indicates uncertainty in branch paths, and Indicates the threshold. Indicates the jump intensity of the exposed surface. and These represent the gain coefficient and the attenuation coefficient, respectively. Indicates the upper limit. Indicates the lower limit. This indicates a cooling-off period.

[0040] Preferably, in step 4, the zero-interruption switching process is as follows:

[0041] Step 4.1, in the migration window Internally, a target mapping is established for each session identifier, thereby keeping existing connections available and allowing new connections to be accessed during handover, and gradually removing old targets after stickiness expires;

[0042] Step 4.2: Each state update is simultaneously written to both the old and new versions, forming a dual-write state, and recorded as a log entry. Recording for idempotent replay;

[0043] in, Indicates the session identifier. Indicates a monotonically increasing sequence number. Represents a timestamp; Indicates the opcode; Indicates the payload;

[0044] Step 4.3: Set the water level line for the convection task and switch the data path after aligning the checkpoints to achieve one-time processing;

[0045] Step 4.4: During the switchover, enable write barriers and read tolerance windows for cross-boundary writes. If an anomaly occurs on the new exposed surface, fall back to the old path and recover based on the most recent consistent checkpoint. When the health of the new path continuously meets the threshold, close the old path to complete the switchover.

[0046] Preferably, in step 5, the implementation process of the closed-loop strategy adjustment is as follows:

[0047] Step 5.1: Collect feedback indicators and form an evaluation vector;

[0048] Step 5.2: Construct the comprehensive objective function;

[0049] Step 5.3: Based on the comprehensive objective function Changes trigger small, online updates to key strategy parameters, including the intensity of exposure surface jumps. Access threshold set Entry point online reach rate With the set of visible addresses;

[0050] when Rising and and When within budget, moderately increase And tighten ;when and If it exceeds the budget, then reduce. And relax ;

[0051] in, This indicates the decrease in the perturbation hit rate. This indicates the service level agreement (SLA) default rate. Indicates the handover delay. This represents the threshold.

[0052] An intrinsic security dynamic immune system for zero-interruption heterogeneous computing network services, implementing the intrinsic security dynamic immune method for zero-interruption heterogeneous computing network services as described in any of the above items, the system includes an exposure surface dynamic jump module, a heterogeneous voting and disturbance avoidance perception module, an uncertainty perception and threshold adaptive module, a zero-interruption switching module, and a closed-loop strategy adjustment module.

[0053] The dynamic jump module of the exposure surface: Based on the preset jump strategy, it makes controlled changes to the network service interface, access entry and resource address and generates a unique resource descriptor. Through interface replacement, entry rotation and address binding token operation, it increases the difficulty for disturbers to scan and exploit.

[0054] Heterogeneous voting and disturbance avoidance perception module: Construct K heterogeneous execution branches, allowing business requests to run independently on each branch and output judgment results. After confidence filtering, the final result is determined according to the trusted weighted voting rules. When judged as high risk, actively switch to a new exposure surface to enhance the ability to resist adversarial inputs and branch pollution.

[0055] Uncertainty perception and threshold adaptation module: Constructs and standardizes feature vectors, calculates anomaly scores through Mahalanobis distance, assesses uncertainty with the help of Monte Carlo sampling or model ensemble, and dynamically adjusts the exposure surface jump frequency and access strategy based on dual thresholds to balance system security and resource consumption.

[0056] Zero-interruption switching module: Through session identifier mapping, state dual writing, idempotent replay, streaming task waterline control and write barrier mechanism, it realizes seamless migration from old exposure surface to new exposure surface, ensuring uninterrupted session and consistent processing results, and meeting business continuity requirements.

[0057] Closed-loop strategy adjustment module: Collects feedback indicators such as disturbance hit rate decrease, SLA default rate, handover latency, and resource overhead, constructs a comprehensive objective function, and updates key parameters such as jump strength and access threshold online to achieve a dynamic balance between security and service quality.

[0058] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0059] (1) The present invention implements controlled randomization at the application programming interface, entry and Internet protocol address and port layer by dynamically changing the exposure surface, which significantly increases the cost and difficulty of scanning and replaying the disturbance.

[0060] (2) This invention independently judges multiple heterogeneous branches by heterogeneous parallelism and trusted weighted voting, and weights them according to historical reliability, runtime integrity and uncertainty, thereby suppressing misjudgment caused by the exploitation of single points and improving robustness against input and branch pollution.

[0061] (3) This invention employs session stickiness, state double writing and idempotent replay during exposure surface changes through zero-interruption switching to ensure that the migration process does not interrupt services and meets the service level agreement requirements for availability and latency.

[0062] (4) This invention is a method that combines dynamic switching of the exposure surface with the active avoidance of disturbances in heterogeneous voting: on the one hand, it significantly improves the difficulty of disturbance scanning and path construction by controlling randomization and minimum visible set at the interface, entry and address levels; on the other hand, it improves the robustness of discrimination under incomplete information and adversarial conditions by using multi-branch heterogeneous parallel output, combined with trusted weighting and uncertainty-driven threshold adaptation; at the same time, it ensures zero service interruption during the switching process by using session stickiness, state double writing and precise one-time semantics, thereby achieving an engineerable balance between security and service level protocol. Attached Figure Description

[0063] Figure 1 This is the overall flowchart of the present invention. Detailed Implementation

[0064] The present invention will be further illustrated below with reference to specific embodiments. These embodiments are implemented based on the technical solutions of the present invention, and it should be understood that these embodiments are only used to illustrate the present invention and are not intended to limit the scope of the present invention.

[0065] Example 1

[0066] This embodiment provides an intrinsic security dynamic immunity method for zero-interruption heterogeneous computing network services. This method focuses on unknown vulnerabilities and unknown disturbances, and adopts a collaborative mechanism of dynamic jump on the exposure surface and heterogeneous voting to actively avoid perception. It performs periodic or event-triggered controlled changes on service interfaces, access entry points and resource addresses. Combined with heterogeneous parallel processing of multiple hardware and multiple models, it generates multiple discriminations for the same request and obtains a reliable result through weighted voting. It adaptively adjusts the jump strength and access threshold based on anomaly scoring and uncertainty assessment. Seamless migration is completed under the protection of dual writing of sessions and states, realizing zero-interruption switching.

[0067] like Figure 1 As shown, the specific implementation process is as follows:

[0068] Step 1, Dynamic Transition of Exposure Surface: Controlled changes are made to the network service interface, access point and resource address according to the pre-set exposure surface transition strategy, and a unique resource descriptor is generated for each round of exposure surface within the validity period;

[0069] Controlled changes are generated and distributed by the control plane in rounds, creating new exposure surface configurations. The ingress gateway uses these configurations to select the interface version, switch the ingress visibility set, and switch resource addresses in a single operation, ensuring service continuity. To ensure each round of exposure surface configurations is uniquely identifiable and verifiable within its validity period, the system generates a unique resource descriptor for that round. Its fields include: interface semantic version, visible ingress set, IP address and port-protocol pair, effective time, and expiration time. A descriptor version number and a random number are also assigned to the unique resource descriptor. Based on these fields, the system calculates the unique identifier (RID) for that round using a hash-based message authentication code.

[0070] Step 1.1: Determine the switching timing and scope based on the exposure surface transition strategy;

[0071] Time-triggered events execute within a randomized interval, while event-triggered events execute during anomaly scoring. Greater than the threshold or uncertainty Greater than the threshold Execute immediately;

[0072] Step 1.2: The system performs semantically equivalent controlled replacements among multiple versions of the Application Programming Interface (API) to reduce the risk of a single implementation being exploited.

[0073] Step 1.3, during the window period Internal execution of entry point rotation ensures that the entry point's online probability satisfies... And an exponential backoff is used for the entry threshold to suppress enumeration;

[0074] in, This represents the probability that a certain entry point will be set to online within the current scheduling interval. This indicates the arrival rate of the entry point going live event. The interval represents the scheduling interval, and exp() represents the exponential function.

[0075] Step 1.4: Select a new IP address and port / protocol pair as the access address through the DNS domain name system, and bind this address to a one-time token with a validity period τ;

[0076] The validity period τ of binding the address with the one-time token means that when the system generates the access address (IP address and port / protocol pair), it simultaneously generates a one-time token and embeds the address identifier addr, the effective time nbf and the expiration time exp in the token, so that exp-nbf=τ, and the token is only valid for the address within the validity period.

[0077] Step 1.5: Generate a one-time resource / request identifier (RID) based on the hash-based message authentication code, and optionally use a time-based one-time password (TOTP) to enhance short-term access control;

[0078] One-time resource / request identifier (RID) is determined by the request key field and time slice, and is calculated using a hash-based message authentication code (HMAC) to ensure that it is not forged and does not repeat across rounds.

[0079] Specifically, the system constructs an input string `msg` for each request. `msg` contains at least the resource identifier `res_id`, the session or request identifier `req_id`, the time slice counter, and a random number `nonce`. τ represents the validity period of the one-time token binding. The start time; This is the current time.

[0080] Then, the RID is generated using the following formula:

[0081]

[0082] Where key is the key. Indicates concatenation; HMAC key This refers to a hash-based message authentication code algorithm.

[0083] When the ingress gateway or server receives a request, it recalculates the RID according to the same rules and compares the consistency. At the same time, it checks whether the counter is within the allowed time slice range and records the used RID in the short-term cache to refuse reuse, thereby achieving one-time use.

[0084] Step 1.6, in the migration window Complete the distribution and activation of the new exposure surface within the specified time, and ensure that DNS / service discovery and certificate or token rotation are completed within the validity period τ, while the jump trigger probability meets the requirements. .

[0085] Step 2, proactive avoidance of disturbances in heterogeneous voting: incoming business requests are processed in parallel on at least K heterogeneous execution branches and the judgment results are output. The final result is obtained based on trusted weighted voting, and when a high risk is determined, the system proactively switches to a new exposure surface.

[0086] Step 2.1: Select at least two classes in the heterogeneous dimension to establish K execution branches;

[0087] The heterogeneous dimension includes, but is not limited to: hardware dimensions such as CPU, GPU, and NPU; algorithm dimensions such as lightweight or heavyweight models; and implementation dimensions such as different compiler chains or security hardening configurations; where K represents the total number of parallel branches and K≥2.

[0088] Step 2.2: Run the same request independently on each branch and produce a judgment result. Abnormal scoring uncertainty of branch paths ;

[0089] Among them, the discrimination result The discriminant model of this branch is used to analyze the input feature vector. The judgment result is obtained through reasoning (by concatenating network telemetry, host metrics, and service log features). Divided into two categories: Where 0 indicates permission and 1 indicates rejection. The discriminant model can be implemented using a rule engine, linear / logistic regression, support vector machine, or neural network classifier; different implementations can be used in different branches to create heterogeneity.

[0090] Where k=1,…K; the branch anomaly score can be obtained for each branch using the calculation method in step 3. uncertainty of branch paths And output it.

[0091] Step 2.3: Determine the final output category based on the credible weighted voting rules. The formula for its calculation is:

[0092]

[0093]

[0094] Where C represents the set of candidate categories, Indicates candidate category labels, This indicates an indicator function (1 is taken when the condition inside the parentheses is true, and 0 is taken otherwise). Indicates the first The result of branch identification; This represents the voting weight of the k-th branch; K represents the total number of parallel branches. Indicates the final output category; Indicates the historical reliability of the k-th branch. Represents runtime integrity metrics. This indicates uncertainty in the branch path; , It is a non-negative coefficient.

[0095] Step 2.4: Perform confidence filtering before voting. When a branch simultaneously satisfies... The branch road should be temporarily removed and the evidence recorded.

[0096] in, Indicates the uncertainty threshold. Indicates the branch abnormality score, This represents the set of anomaly scores for all branches. This represents the median of the entire set of branch anomaly scores. Indicates the outlier threshold. This indicates uncertainty in the branch path.

[0097] Step 2.5: After a removal occurs, the weights are renormalized according to the remaining valid branches and the weighted voting continues. When the number of valid branches is lower than the policy lower limit, a fallback is triggered to ensure service continuity.

[0098] After a rejection occurs, the system first constructs a set of valid branches. It consists of the indexes of branches that have not been removed, and the number of valid branches is... The system's weights for the remaining branches. Renormalize to obtain normalized weights. Specifically:

[0099]

[0100] in, Let the voting weight of the k-th branch be... The weights used for voting after removal, and satisfying the following conditions: and The system then based on Continue with weighted voting and output the category. satisfy:

[0101]

[0102] Where C is the set of candidate categories, Indicates candidate category labels, For the first The result of branch discrimination, The weights used for voting after removal, This is an indicator function. When Triggering a downgrade rollback, where The lower bound of the strategy is defined; the degradation fallback method includes using a single branch output as the final result or using majority voting instead of weighted voting, and limiting the degradation duration to a policy window to ensure service continuity.

[0103] Step 3, Uncertainty Perception and Threshold Adaptation: Calculate the anomaly score and predict uncertainty. When either of these indicators exceeds the threshold, increase the jump frequency and tighten the access policy. When the situation remains stable, decrease the jump frequency to save resources.

[0104] Step 3.1: Construct feature vectors (Constructed from network telemetry, host metrics, and service log features), and then standardized.

[0105] The system in the same statistical time window The network telemetry feature vectors are obtained respectively. Host metric feature vector With business log feature vector And pieced together according to dimensions to form .

[0106] in, Indicates the current time; Indicates splicing, Indicates the length of the statistical time window. This is the final input feature vector. After concatenation, [the following is done / then...] Perform dimension-by-dimensional standardization, specifically as follows:

[0107]

[0108] Where x is the final input feature vector; The baseline mean. For each dimension of standard deviation; This represents the standardized feature vector.

[0109] Step 3.2: Calculate branch anomaly scores using Mahalanobis distance. Specifically:

[0110]

[0111] in, Here, x is the baseline covariance matrix; x is the final input feature vector. The baseline mean; This represents the anomaly score of the k-th branch.

[0112] Step 3.3: Evaluate branch uncertainty using Monte Carlo (MC) sampling or model ensemble. ;

[0113] Branch uncertainty The calculation formula is:

[0114]

[0115] in, For variance operators, For the output of the m-th randomization or ensemble model, The number of sampling or integration attempts.

[0116] Step 3.4: Make adaptive adjustments based on the dual thresholds;

[0117] when or At the same time, increase the jump strength When the duration of continuous stability Reduce jump intensity if the boundary is not crossed. ;

[0118] in, Indicates the branch abnormality score, Indicates uncertainty in branch paths, and For the threshold, For the jump intensity of the exposed surface, and These are the gain / attenuation coefficients, respectively. and These are the upper and lower limits. This is a time for calming down.

[0119] Step 4, Zero-interruption handover: Complete the session migration and state replication from the old exposure surface to the new exposure surface without interrupting the session, and ensure consistent processing results through idempotent replay and sequence control;

[0120] Step 4.1, in the migration window Internally, a Session Identifier (SID) is established for each session. The target mapping keeps existing connections available and allows new connections to be accessed during handover, and gradually removes old targets after stickiness expires;

[0121] Wherein, dst_old represents the old service target before the session switch; dst_new represents the new service target after the session switch. The service target is used to identify the backend instance or network address to which the session request is routed.

[0122] Step 4.2: For each state update, write to both the old and new versions simultaneously to form a dual-write state, and record it as a log entry. Recording for idempotent replay, where For session identification, It is a monotonically increasing sequence number. Indicates the opcode; Indicates the payload; This is a timestamp; press [button] after switching is complete. Remove duplicates and replay them in order to ensure consistency and idempotency.

[0123] Step 4.3: Set the water level for the convection task and switch the data path after aligning the checkpoint to achieve exactly-once processing;

[0124] Water level meets ,in, For the arrival timestamp sequence, For quantiles, The water level threshold is used; quantile represents the quantile function, used to calculate the sequence. The quantiles.

[0125] Step 4.4: During the switchover, enable write barriers and read tolerance windows for cross-boundary writes. If an anomaly occurs on the new exposed surface, fall back to the old path and recover based on the most recent consistent checkpoint. When the health of the new path continuously meets the threshold, close the old path to complete the switchover.

[0126] Step 5, Closed-loop strategy adjustment: Based on feedback such as decreased attack hit rate, service level agreement default rate, switching latency and resource overhead, update the jump strength, access threshold and visible entry point-address set online to achieve a balance between security and service quality.

[0127] Step 5.1: Collect feedback indicators and form an evaluation vector;

[0128] The system during the evaluation time window The decrease in attack hit rate is statistically analyzed separately. Service Level Agreement (SLA) Default Rate Switching delay statistics With resource expenditure And form the evaluation vector as follows:

[0129]

[0130] in, To assess the length of the time window, This indicates transpose. Indicates the current time.

[0131] Step 5.2: Construct the comprehensive objective function, specifically as follows:

[0132]

[0133] Where J represents the comprehensive objective function, The decrease in attack hit rate represents an increase in the percentage of attacks that are intercepted or evaded. The Service Level Agreement (SLA) default rate represents the percentage of service levels that exceed agreed availability / latency / throughput targets. This represents the switching latency, specifically the latency increment caused by the switching of the exposure surface to the business path. This represents resource overhead, specifically the additional computing power and bandwidth consumption caused by jumps and voting. This is a trade-off factor used to balance security benefits with service quality / cost.

[0134] Step 5.3: Based on the comprehensive objective function Changes trigger small, online updates to key strategy parameters, including the intensity of exposure surface jumps. Access threshold set Entry point online reach rate With the set of visible addresses;

[0135] when Rising and and When within budget, moderately increase And tighten ;when and If it exceeds the budget, then reduce. And relax .

[0136] To verify the effectiveness of the present invention, the following experiment was conducted in this embodiment.

[0137] 1. The experimental platform for this embodiment is as follows:

[0138] (1) Basic environment: Based on Kubernetes cluster (3× worker nodes), the service entry point adopts Envoy / Ingress gateway (for dynamic routing and certificate rotation), with 6 service replicas; the heterogeneous branches include the Central Processing Unit (CPU) inference link, the Graphics Processing Unit (GPU) inference link and the hardened compilation version link, for a total of K=3 links.

[0139] (2) Identity and Token: The Unified Key Service (KMS) generates one-time tokens (including Time-Based One-Time Password, TOTP), which are verified on the gateway side; the Domain Name System (DNS) and Service Discovery are responsible for address activation and refresh.

[0140] (3) Traffic and attack and defense: Pressure and business flow are generated by traffic replay; the attack side uses port / service scanning (nmap), password brute force and replay scripts to simulate unknown scanning and enumeration; logs and telemetry are connected to Prometheus / Grafana.

[0141] (4) Evaluation indicators:

[0142] Availability and latency: Availability and P95 latency statistics are provided by service level agreement.

[0143] Security metrics: Scan / enumeration hit rate, replay success rate.

[0144] Switching overhead: Exposure surface switching latency and packet loss rate.

[0145] Voting results: false alarm rate, false negative rate, and final judgment accuracy.

[0146] 2. Implementation steps:

[0147] (1) Baseline deployment: disable the mechanism of this invention, fix the API / entry / IP port, and use a single CPU link for discrimination; record various indicators under the mixed flow of business and disturbance for 30 minutes.

[0148] (2) Activate the method of the present invention:

[0149] a) Dynamic jump on the exposure surface: Configure jump strength for APIs, entry points, and resource addresses. Execution time is triggered within the randomized interval; when anomaly scoring occurs. or uncertainty Time-based events are executed immediately; the probability of an entry point going online is determined by... Control; address and entry point are bound to the validity period of the one-time token. .

[0150] b) Heterogeneous voting and confidence filtering: the same request in... Parallel discrimination and output of branch paths Weights according to The calculation involves first performing confidence filtering and then weighted voting to obtain the result. .

[0151] c) Zero-interruption handover: A session identifier (SID) is established during the handover process. Mapping; double-write state and idempotent replay ensure consistency; streaming tasks use watermarks Control the timing of the switch.

[0152] (3) Experiment duration and reproduction: Run for 30 minutes under the same business and disturbance intensity, repeat 3 times and take the average.

[0153] 3. Key configurations;

[0154] Jump intensity Entry point online reach rate Token validity period (where s represents seconds);

[0155] Uncertainty threshold Outlier threshold For each branch road The median deviation is 1.5 times.

[0156] 4. Experimental results;

[0157] Table 1 Comparison of Experimental Results in Example 1

[0158]

[0159] Compared to control group A (static exposure surface), the scanning / enumeration hit rate of the present invention group decreased from 14.8% to 3.2%, and the replay success rate decreased from 6.1% to 0.9%, indicating that dynamic transitions and one-time tokens can significantly increase the scanning and replay costs for attackers. Compared to control group B (transitions only), the false positive rate of the present invention group under adversarial input and branch anomaly conditions was further reduced (relatively reduced by about 28%), and the discrimination accuracy increased from 94.1% to 96.7%, indicating that heterogeneous parallelism and weighted voting can suppress the amplification of single-point misjudgments. Compared to control group C (voting only), the hit rate of the present invention group decreased more significantly in the scanning / enumeration stage, indicating that exposure surface transitions have an active avoidance effect on attack path construction.

[0160] Regarding business continuity, the switching latency of this invention group The median latency was 210 ms, and the P95 was 420 ms. During the handover, service availability remained at least 99.95%, and the packet loss rate was no higher than 0.08%. The end-to-end latency P95 increased by approximately 2.3% compared to control group A, but remained within the SLA budget. This demonstrates that the zero-disruption handover mechanism can ensure continuous service while controlling performance overhead. (In the comprehensive objective function...) Under the constraints, this invention achieves significant voltage reduction in scanning and playback, improved robustness in discrimination, and assurance of business continuity, resulting in better engineering usability and overall benefits.

[0161] Example 2

[0162] This embodiment also provides an endogenous security dynamic immune system for zero-interruption heterogeneous computing network services. The system includes an exposure surface dynamic switching module, a heterogeneous voting and disturbance avoidance perception module, an uncertainty perception and threshold adaptive module, a zero-interruption switching module, and a closed-loop strategy adjustment module.

[0163] The dynamic jump module of the exposure surface: Based on the preset jump strategy, it performs controlled changes to the computing network service interface, access entry and resource address and generates a unique resource descriptor. Through interface replacement, entry rotation and address binding token operation, it increases the difficulty for disturbers to scan and exploit.

[0164] Heterogeneous voting and disturbance avoidance perception module: Construct K heterogeneous execution branches, allowing business requests to run independently on each branch and output judgment results. After confidence filtering, the final result is determined according to the trusted weighted voting rules. When judged as high risk, actively switch to a new exposure surface to enhance the ability to resist adversarial inputs and branch pollution.

[0165] Uncertainty perception and threshold adaptation module: Constructs and standardizes feature vectors, calculates anomaly scores through Mahalanobis distance, assesses uncertainty with the help of Monte Carlo sampling or model ensemble, and dynamically adjusts the exposure surface jump frequency and access strategy based on dual thresholds to balance system security and resource consumption.

[0166] Zero-interruption switching module: Through session identifier mapping, state dual writing, idempotent replay, streaming task watermark control and write barrier mechanism, it realizes seamless migration from old exposure surface to new exposure surface, ensuring uninterrupted session and consistent processing results, and meeting business continuity requirements.

[0167] Closed-loop strategy adjustment module: Collects feedback indicators such as disturbance hit rate decrease, SLA default rate, handover latency, and resource overhead, constructs a comprehensive objective function, and updates key parameters such as jump strength and access threshold online to achieve a dynamic balance between security and service quality.

[0168] This embodiment focuses on the online inference service API carried by a heterogeneous computing power network.

[0169] In a heterogeneous computing network composed of central cloud nodes and edge nodes, services provide API interfaces to the outside world in a service mesh manner. The entry point is hosted by a unified gateway, and backend services run on at least two types of heterogeneous resources, including Central Processing Unit (CPU) nodes and Graphics Processing Unit (GPU) nodes. Furthermore, the same service provides at least two semantically equivalent API versions. The system is accessed by modules: the exposure surface dynamic transition module is connected to the entry gateway and the service discovery side; the heterogeneous voting and disturbance avoidance awareness module is accessed via parallel inference; the uncertainty awareness and threshold adaptation module collects features from the gateway, host, and log sides; the zero-interruption switching module is responsible for session and state transitions; and the closed-loop strategy adjustment module is responsible for online parameter tuning.

[0170] To highlight the advantages of this invention, a comparison group was set up under the same business traffic and attack intensity:

[0171] Comparison Group A: Static exposed surface + single branch discrimination.

[0172] Control group B: Dynamic jumps only on the exposed surface.

[0173] Comparison Group C: Heterogeneous voting only.

[0174] This invention group features: dynamic jump + heterogeneous voting + threshold adaptation + zero-interruption switching.

[0175] The performance indicators include: scan / enumeration hit rate, replay success rate, discrimination accuracy, false alarm rate and false negative rate, end-to-end latency (P95), and handover latency. SLA default rate Resource expenditure Each group was run N times within the same time window, and the average value was compared with the p95 statistic.

[0176] The statistical period is 14 consecutive days, covering peak periods on weekdays and weekends. A total of approximately 12 million business requests were processed, and approximately 1.8 million session identifiers (SIDs) were generated. The exposure surface jump trigger frequency was approximately 3.4 times per 10,000 requests.

[0177] Table 2 Comparison of Experimental Results in Example 2

[0178]

[0179] The results showed that compared with control group A, the scan / enumeration hit rate of the present invention group decreased from 9.6% to 2.4%, and the replay success rate decreased from 3.8% to 0.7%. Compared with control group B, the false alarm rate under adversarial input and branch anomaly conditions decreased from 2.9% to 1.6%, and the discrimination accuracy increased from 95.0% to 97.1%. Compared with control group C, the present invention group showed more significant suppression of scanning and path construction; the scan / enumeration hit rate of control group C was 6.8%, and the replay success rate was 1.9%, while those of the present invention group were 2.41% and 0.7%, respectively. Regarding service continuity, the handover latency... The median latency was 320ms, the P95 latency was 780ms, the service availability was no less than 99.97% during the statistical period, the SLA default rate was 0.12%, and the end-to-end latency P95 increased from 52ms to 59ms but remained within the 12ms budget.

[0180] The above results demonstrate that, under conditions of real business traffic and mixed disturbance noise, the present invention can simultaneously reduce scanning and replay risks, improve discrimination robustness, and ensure business continuity through zero-interruption switching, achieving an engineering balance between security benefits and performance overhead.

[0181] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for zero-interruption of heterogeneous computing power network services with intrinsic security dynamic immunity, characterized in that: Includes the following steps: Step 1, Dynamic Transition of Exposure Surface: Controlled changes are made to the network service interface, access point and resource address according to the set exposure surface transition strategy, and a unique resource descriptor is generated for each round of exposure surface within the validity period; Step 2, proactive avoidance of disturbances in heterogeneous voting: incoming business requests are processed in parallel on K heterogeneous execution branches and the judgment results are output. The final result is obtained based on trusted weighted voting, and when a high risk is determined, the system proactively switches to a new exposure surface. Step 3, Uncertainty Perception and Threshold Adaptation: Calculate the anomaly score and predict uncertainty. When either of these indicators exceeds the threshold, increase the jump frequency and tighten the access policy. When the situation remains stable, decrease the jump frequency to save resources. Step 4, Zero-interruption handover: Complete the session migration and state replication from the old exposure surface to the new exposure surface without interrupting the session, and ensure consistent processing results through idempotent replay and sequence control; Step 5, Closed-loop strategy adjustment: Based on feedback from decreased attack hit rate, service level agreement default rate, switching latency and resource overhead, update the jump strength, access threshold and visible entry point-address set online to achieve a balance between security and service quality.

2. The intrinsic security dynamic immunity method for zero-interruption heterogeneous computing power network services according to claim 1, characterized in that: In step 1, the implementation process of dynamic transition of the exposed surface is as follows: Step 1.1: Determine the switching timing and scope based on the exposure surface transition strategy; Step 1.2: The system performs controlled replacement of semantically equivalent application programming interfaces across multiple versions to reduce the risk of a single implementation being exploited; Step 1.3, during the window period Internal execution of entry point rotation ensures that the entry point's online probability satisfies... And an exponential backoff is used for the entry threshold to suppress enumeration; in, This represents the probability that a certain entry point will be set to online within the current scheduling interval. This indicates the arrival rate of the entry point going live event. The function exp() represents the scheduling interval. Step 1.4: Select a new IP address and port / protocol pair as the access address through the DNS domain name system, and bind this address to a one-time token with a validity period τ; Step 1.5: Generate a one-time resource / request identifier (RID) based on a hash-based message authentication code, and optionally use a time-based one-time password to enhance short-term access control; Step 1.6, in the migration window The issuance and activation of the new exposure surface were completed within the time limit.

3. The intrinsic security dynamic immunity method for zero-interruption heterogeneous computing power network services according to claim 1, characterized in that: In step 2, the process of actively avoiding perception of disturbances in heterogeneous voting is as follows: Step 2.1: Select two classes in the heterogeneous dimension to establish K execution branches; Step 2.2: Run the same request independently on each branch and generate judgment results, anomaly scores, and branch uncertainty; Step 2.3: Determine the final output category based on the credible weighted voting rules; Step 2.4: Perform confidence filtering before voting. When a branch simultaneously satisfies... The branch road should be temporarily removed and the evidence recorded. in, Indicates the uncertainty threshold. Indicates the branch abnormality score, This represents the set of anomaly scores for all branches. This represents the median of the entire set of branch anomaly scores. Indicates the outlier threshold. This indicates uncertainty in the branch path; Step 2.5: After a removal occurs, the weights are re-normalized according to the remaining valid branches and the weighted voting continues. When the number of valid branches is lower than the policy lower limit, a fallback is triggered to ensure service continuity.

4. The intrinsic security dynamic immunity method for zero-interruption heterogeneous computing power network services according to claim 3, characterized in that: In step 2.3, the specific implementation process for determining the final output category based on the credible weighted voting rule is as follows: ; ; Where C represents the set of candidate categories, Indicates candidate category labels, Indicates an indicator function, Indicates the first The result of branch identification; This represents the voting weight of the k-th branch; K represents the total number of parallel branches. Indicates the final output category; Indicates the historical reliability of the k-th branch. Represents runtime integrity metrics. This indicates uncertainty in the branch path; , This indicates a non-negative coefficient.

5. The intrinsic security dynamic immunity method for zero-interruption heterogeneous computing power network services according to claim 1, characterized in that: The specific methods for uncertainty perception and threshold adaptation in step 3 are as follows: Step 3.1: Construct feature vectors And standardize it; Step 3.2: Calculate the branch k anomaly score using Mahalanobis distance. ; Step 3.3: Evaluate the uncertainty of branch k using Monte Carlo sampling or model ensemble. ; Step 3.4: Make adaptive adjustments based on the dual thresholds; when or At the same time, increase the jump strength When the duration of continuous stability Reduce jump intensity if the boundary is not crossed. ; in, Indicates the branch abnormality score, Indicates uncertainty in branch paths, and Indicates the threshold. Indicates the jump intensity of the exposed surface. and These represent the gain coefficient and the attenuation coefficient, respectively. Indicates the upper limit. Indicates the lower limit. This indicates a cooling-off period.

6. The intrinsic security dynamic immunity method for zero-interruption heterogeneous computing power network services according to claim 1, characterized in that: In step 4, the zero-interrupt switching process is as follows: Step 4.1, in the migration window Internally, a target mapping is established for each session identifier, thereby keeping existing connections available and allowing new connections to be accessed during handover, and gradually removing old targets after stickiness expires; Step 4.2: Each state update is simultaneously written to both the old and new versions, forming a dual-write state, and recorded as a log entry. Recording for idempotent replay; in, Indicates the session identifier. Indicates a monotonically increasing sequence number. Represents a timestamp; Indicates the opcode; Indicates the payload; Step 4.3: Set the water level line for the convection task and switch the data path after aligning the checkpoints to achieve one-time processing; Step 4.4: During the switchover, enable write barriers and read tolerance windows for cross-boundary writes. If an anomaly occurs on the new exposed surface, fall back to the old path and recover based on the most recent consistent checkpoint. When the health of the new path continuously meets the threshold, close the old path to complete the switchover.

7. The intrinsic security dynamic immunity method for zero-interruption heterogeneous computing power network services according to claim 1, characterized in that: In step 5, the implementation process of the closed-loop strategy adjustment is as follows: Step 5.1: Collect feedback indicators and form an evaluation vector; Step 5.2: Construct the comprehensive objective function; Step 5.3: Based on the comprehensive objective function Changes trigger small, online updates to key strategy parameters, including the intensity of exposure surface jumps. Access threshold set Entry point online reach rate With the set of visible addresses; when Rising and and When within budget, moderately increase And tighten ;when and If it exceeds the budget, then reduce. And relax ; in, This indicates the decrease in the perturbation hit rate. This indicates the service level agreement (SLA) default rate. Indicates the switching delay. This represents the threshold.

8. An intrinsic security dynamic immune system for zero-interruption heterogeneous computing network services, realizing the intrinsic security dynamic immune method for zero-interruption heterogeneous computing network services as described in any one of claims 1 to 7, characterized in that, The system includes an exposure surface dynamic switching module, a heterogeneous voting and disturbance avoidance perception module, an uncertainty perception and threshold adaptive module, a zero-interruption switching module, and a closed-loop strategy adjustment module; The dynamic jump module of the exposure surface: Based on the preset jump strategy, it makes controlled changes to the network service interface, access entry and resource address and generates a unique resource descriptor. Through interface replacement, entry rotation and address binding token operation, it increases the difficulty for disturbers to scan and exploit. Heterogeneous voting and disturbance avoidance perception module: Construct K heterogeneous execution branches, allowing business requests to run independently on each branch and output judgment results. After confidence filtering, the final result is determined according to the trusted weighted voting rules. When judged as high risk, actively switch to a new exposure surface to enhance the ability to resist adversarial inputs and branch pollution. Uncertainty perception and threshold adaptation module: Constructs and standardizes feature vectors, calculates anomaly scores through Mahalanobis distance, assesses uncertainty with the help of Monte Carlo sampling or model ensemble, and dynamically adjusts the exposure surface jump frequency and access strategy based on dual thresholds to balance system security and resource consumption. Zero-interruption switching module: Through session identifier mapping, state dual writing, idempotent replay, streaming task waterline control and write barrier mechanism, it realizes seamless migration from old exposure surface to new exposure surface, ensuring uninterrupted session and consistent processing results, and meeting business continuity requirements. Closed-loop strategy adjustment module: Collects feedback indicators such as disturbance hit rate decrease, SLA default rate, handover latency, and resource overhead, constructs a comprehensive objective function, and updates key parameters such as jump strength and access threshold online to achieve a dynamic balance between security and service quality.

Citation Information

Patent Citations

  • Network security space surveying and mapping method, system and equipment based on multi-source data fusion

    CN120415816A

  • Mimicry defense driven network endogenous security protection method

    CN120692075A