Parameter adjusting method and device and electronic equipment

By monitoring firewall system resource consumption and adjusting the detection level parameter gradient, the problem of resource imbalance was solved, system consumption was reduced, and network security and stability were improved.

CN121966892APending Publication Date: 2026-05-01RUIJIE NETWORKS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
RUIJIE NETWORKS CO LTD
Filing Date
2024-10-29
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

When defending against network attacks, existing firewall systems suffer from uneven resource consumption among various security services, leading to excessive system resource consumption. This can cause network lag or outages, and skipping detection increases the risk of network attacks.

Method used

By monitoring system resource consumption, the detection level parameters corresponding to the maximum resource consumption value are selected and adjusted according to the detection level parameter gradient to reduce system resource consumption and ensure that security capabilities are not reduced.

Benefits of technology

It effectively reduces system resource consumption, avoids network lag, improves network security, ensures that secure services are not skipped, and reduces the risk of network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121966892A_ABST
    Figure CN121966892A_ABST
Patent Text Reader

Abstract

The invention provides a parameter adjustment method and device and electronic equipment, and the method comprises the steps: obtaining resource consumption values corresponding to one or more detection degree parameters, screening out the maximum resource consumption value from the one or more resource consumption values, determining a first detection degree parameter corresponding to the maximum resource consumption value, and adjusting the first detection degree parameter according to the first detection degree parameter. And adjusting the first detection degree parameter according to the detection degree parameter gradient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a parameter adjustment method, apparatus and electronic device. Background Technology

[0002] To ensure network security, various security services are integrated into firewalls. Common security services include: Intrusion Prevention System (IPS), Antivirus Server (AV), Web Application Firewall (WAF), and Threat Intelligence (TI). When using firewalls to defend against network attacks, each security service consumes different resources and has different attack detection capabilities. For example, IPS detects all network traffic, requiring significant system resources and possessing strong detection capabilities; while AV needs to reconstruct files from network traffic and then perform virus detection on those files, but it cannot effectively detect other types of attacks and requires more system resources. Summary of the Invention

[0003] Exemplary embodiments of this application provide a parameter adjustment method, apparatus, and electronic device that can adjust a first detection degree parameter corresponding to the maximum resource consumption value in the device to reduce the resources consumed by the system.

[0004] In a first aspect, embodiments of this application provide a parameter adjustment method, the method comprising:

[0005] Obtain resource consumption values ​​corresponding to one or more detection degree parameters, wherein the detection degree parameters represent the degree of detection of the network attack data by the security service under the detection category during the interception of network attack data;

[0006] The maximum resource consumption value is selected from one or more resource consumption values, and a first detection level parameter corresponding to the maximum resource consumption value is determined.

[0007] The first detection degree parameter is adjusted according to the detection degree parameter gradient.

[0008] By using the above method, the first detection level parameter corresponding to the maximum resource consumption value is determined, and the first detection level parameter is adjusted according to the detection level parameter gradient to ensure that the resource consumption on the device side can be reduced, thereby reducing the resource consumption of the system and ensuring the network security of the user side.

[0009] In one possible design, obtaining the resource consumption values ​​corresponding to one or more detection level parameters includes:

[0010] Obtain the resource utilization rate and attack detection rate corresponding to each detection level parameter in each security service. The attack detection rate represents the proportion of network attack data detected by the device corresponding to the detection level parameter to all network attack data.

[0011] The resource consumption values ​​are calculated based on the resource utilization rate and attack detection rate corresponding to each of the adjacent detection degree parameters.

[0012] Using the methods described above, resource consumption values ​​can be calculated based on detection level parameters, resource utilization, and attack detection rate. This allows for the rapid acquisition of resource consumption for security operations based on these values.

[0013] In one possible design, the resource consumption value is calculated based on the resource utilization rate and attack detection rate corresponding to each of the adjacent detection degree parameters, including:

[0014] Calculate the resource utilization difference and attack detection rate difference between each adjacent detection level parameter, and calculate the ratio between the resource utilization difference and the attack detection rate difference, wherein the ratio represents the resources consumed per unit of attack detected;

[0015] Each ratio is used as the resource consumption value for the corresponding detection level parameter.

[0016] Using the above method, the resource consumption value is calculated based on the difference in resource utilization and attack detection rate between each adjacent detection degree parameter, which helps to determine the maximum resource consumption value.

[0017] In one possible design, before filtering for the maximum resource consumption value from one or more resource consumption values, the following steps are also included:

[0018] The various detection parameters corresponding to the device are determined, as well as the actual resource utilization rate and the range of resource utilization rate corresponding to the device.

[0019] Extract the maximum resource utilization rate from the range of resource utilization rates;

[0020] If the actual resource utilization rate is greater than the maximum resource utilization rate, then the maximum resource consumption value is selected from one or more resource consumption values, and the first detection degree parameter corresponding to the maximum resource consumption value is determined.

[0021] Using the above method, when the actual resource utilization rate is greater than the corresponding maximum resource utilization rate, the detection level parameter is adjusted to ensure that the resources on the device side can be adjusted in a timely manner.

[0022] In one possible design, adjusting the first detection severity parameter according to the detection severity parameter gradient includes:

[0023] The first detection severity parameter is adjusted according to the detection severity parameter gradient, wherein the detection severity parameter gradient is a sequence of detection severity parameters sorted in descending order.

[0024] The above method ensures that the detection severity parameters can be adjusted in descending order, thus standardizing the adjustment method of the detection severity parameters.

[0025] In one possible design, adjusting the first detection severity parameter according to the detection severity parameter gradient includes:

[0026] A second detection degree parameter smaller than the first detection degree parameter is determined from the detection degree parameter gradient, and the first detection degree parameter is adjusted to the second detection degree parameter.

[0027] When the detection level parameter is the second detection level parameter, the target actual resource utilization rate of the device end, the minimum resource utilization rate in the range of resource utilization rate values ​​are determined, and the overall security capability value of all security services in the device end is determined, wherein the overall security capability value characterizes the protection capability of all security services in the device end against network attack data.

[0028] The second detection level parameter is adjusted based on the relationship between the minimum resource utilization rate and the target resource utilization rate; and / or

[0029] Based on the relationship between the overall machine safety capability value and the safety capability threshold, the second detection degree parameter is adjusted.

[0030] By using the above method, the detection level parameters are adjusted based on the minimum resource utilization rate and the overall machine safety capability value, ensuring the diversity of the detection level parameter adjustment.

[0031] In one possible design, adjusting the second detection level parameter based on the relationship between the minimum resource utilization rate and the target resource utilization rate includes:

[0032] If the target actual resource utilization rate is greater than the minimum resource utilization rate, then the second detection degree parameter is adjusted according to the detection degree parameter gradient until the target actual resource utilization rate is not greater than the minimum resource utilization rate;

[0033] If the actual resource utilization rate of the target is not greater than the minimum resource utilization rate, then the adjustment of the second detection degree parameter shall be stopped.

[0034] After adjusting the first detection level parameter to the second detection level parameter using the above method, it is necessary to determine whether further adjustment is needed based on the relationship between the target actual resource utilization rate and the minimum resource utilization rate, thus ensuring that the resource consumption on the device side can be reduced.

[0035] In one possible design, adjusting the second detection level parameter based on the relationship between the overall machine safety capability value and the safety capability threshold includes:

[0036] If the overall safety capability value is less than the safety capability threshold, the second detection degree parameter is adjusted according to the detection degree parameter gradient until the sum of the safety capability values ​​is not less than the safety capability threshold.

[0037] If the overall safety capability value is not less than the safety capability threshold, then the adjustment of the second detection level parameter shall be stopped.

[0038] By using the above method, based on the relationship between the overall safety capability value and the safety capability threshold, the conditions for stopping the adjustment of the detection degree parameter are determined, which prevents excessive resource consumption in the equipment and can effectively reduce resource consumption in the equipment.

[0039] In one possible design, determining the overall security capability value of all security services in the device includes:

[0040] Obtain at least one attack detection rate for each security service in the device, and a weight value for each security service;

[0041] Based on the weight value of each security service and the detection rate of all attacks, the security capability value corresponding to each security service is obtained. The larger the security capability value, the stronger the ability of the security service corresponding to the security capability value to intercept network attack data.

[0042] The overall security capability value is obtained by summing all the security capability values ​​in the device.

[0043] By using the above method, the security capabilities of security services are quantified through calculated security capability values, which facilitates rapid assessment of the security capabilities of security services.

[0044] In one possible design, obtaining at least one attack detection rate corresponding to each security service in the device includes:

[0045] Obtain the attack detection rate for each security service in the device under different detection categories, wherein the different detection categories include one or more of the following: detection depth, detection protocol, or detection application; or

[0046] Obtain the attack detection rate for each security service under the detection category for each detection level parameter.

[0047] By using the methods described above, we can determine at least one attack detection rate corresponding to the security business, which is helpful in quantifying the security capabilities of the security business.

[0048] In one possible design, the security capability value corresponding to each security service is obtained based on the weight value of each security service and the detection rate of all attacks, including:

[0049] Through the formula for calculating safety capabilities Obtain the security capability value corresponding to each security service;

[0050] Wherein, SFi represents the security capability value corresponding to the i-th security service, Wi represents the weight value of the i-th security service on the device side, and PL_R j This represents the attack detection rate corresponding to the j-th detection level parameter. This represents the sum of attack detection rates corresponding to the M detection level parameters.

[0051] Using the above method, the security energy value of security services is calculated based on the security capability calculation formula, thereby quantifying the security capabilities of security services on the device side.

[0052] Secondly, this application provides a parameter adjustment device, the device comprising:

[0053] The acquisition module is used to acquire the resource consumption values ​​corresponding to one or more detection degree parameters, wherein the detection degree parameters represent the degree of detection of the network attack data by the security service under the detection category during the interception of network attack data;

[0054] The determination module is used to filter out the maximum resource consumption value from one or more resource consumption values, and determine the first detection degree parameter corresponding to the maximum resource consumption value;

[0055] The adjustment module is used to adjust the first detection degree parameter according to the detection degree parameter gradient.

[0056] In one possible design, the obtaining module is specifically used to obtain the resource utilization rate and attack detection rate corresponding to each detection level parameter in each security service, and calculate the resource consumption value of each corresponding to the resource utilization rate and attack detection rate of each adjacent detection level parameter.

[0057] In one possible design, the obtaining module is further configured to calculate the resource utilization difference and the attack detection rate difference between each adjacent detection level parameter, and calculate the ratio between the resource utilization difference and the attack detection rate difference respectively, and use each ratio as the resource consumption value of the corresponding detection level parameter.

[0058] In one possible design, the determining module is specifically used to determine each detection level parameter corresponding to the device end, as well as to determine the actual resource utilization rate and resource utilization rate range value corresponding to the device end, extract the maximum resource utilization rate from the resource utilization rate range value, and if the actual resource utilization rate is greater than the maximum resource utilization rate, then the maximum resource consumption value is selected from one or more resource consumption values, and the first detection level parameter corresponding to the maximum resource consumption value is determined.

[0059] In one possible design, the adjustment module is specifically used to adjust the first detection degree parameter according to the detection degree parameter gradient, wherein the detection degree parameter gradient is a sequence of detection degree parameters sorted in descending order.

[0060] In one possible design, the adjustment module is further configured to determine a second detection degree parameter smaller than the first detection degree parameter in the detection degree parameter gradient, and adjust the first detection degree parameter to the second detection degree parameter. When the detection degree parameter is the second detection degree parameter, the module determines the target actual resource utilization rate of the device, the minimum resource utilization rate in the resource utilization rate range, and the overall security capability value of all security services in the device. The overall security capability value characterizes the protection capability of all security services in the device against network attack data. The second detection degree parameter is adjusted based on the relationship between the minimum resource utilization rate and the target resource utilization rate, and / or based on the relationship between the overall security capability value and the security capability threshold.

[0061] In one possible design, the adjustment module is further configured to adjust the second detection degree parameter according to the detection degree parameter gradient if the target actual resource utilization rate is greater than the minimum resource utilization rate, until the target actual resource utilization rate is not greater than the minimum resource utilization rate, and to stop adjusting the second detection degree parameter if the target actual resource utilization rate is not greater than the minimum resource utilization rate.

[0062] In one possible design, the adjustment module is further configured to, if the overall security capability value is less than the security capability threshold, adjust the second detection degree parameter according to the detection degree parameter gradient until the sum of the security capability values ​​is not less than the security capability threshold; if the overall security capability value is not less than the security capability threshold, then stop adjusting the second detection degree parameter.

[0063] In one possible design, the adjustment module is further configured to obtain at least one attack detection rate corresponding to each security service in the device, and a weight value corresponding to each security service; based on the weight value of each security service and all attack detection rates, obtain a security capability value corresponding to each security service; wherein, the larger the security capability value, the stronger the ability of the security service corresponding to the security capability value to intercept network attack data; and add all security capability values ​​in the device to obtain the overall security capability value.

[0064] In one possible design, the adjustment module is further configured to obtain the attack detection rate of each security service in the device under different detection categories, or to obtain the attack detection rate of each security service under each detection degree parameter in the detection category.

[0065] In one possible design, the adjustment module is further configured to calculate the security capability using a formula. Obtain the security capability value corresponding to each security service;

[0066] Wherein, SFi represents the security capability value corresponding to the i-th security service, Wi represents the weight value of the i-th security service on the device side, and PL_R j This represents the attack detection rate corresponding to the j-th detection level parameter. This represents the sum of attack detection rates corresponding to the M detection level parameters.

[0067] Thirdly, this application provides an electronic device, comprising:

[0068] Memory, used to store computer programs;

[0069] When the processor executes the computer program stored in the memory, it implements the above-described parameter adjustment method steps.

[0070] Fourthly, this application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the above-described parameter adjustment method steps.

[0071] For details on each of the above-mentioned aspects one through four, and the technical effects that each aspect may achieve, please refer to the above description of the technical effects that can be achieved for the first aspect or the various possible solutions in the first aspect. These details will not be repeated here. Attached Figure Description

[0072] Figure 1 This is a schematic diagram of the system structure provided in the embodiments of this application;

[0073] Figure 2 A flowchart illustrating the steps of a parameter adjustment method provided in this application embodiment;

[0074] Figure 3 This is a schematic diagram of the structure of a parameter adjustment device provided in an embodiment of this application;

[0075] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0076] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The specific operational methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of this application, "multiple" is understood as "at least two". "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. A connected to B can represent: A and B directly connected, and A and B connected through C. Furthermore, in the description of this application, terms such as "first" and "second" are used only for distinguishing the purpose of description and should not be construed as indicating or implying relative importance or order.

[0077] In the past, all security services were based on system resources. These system resources are limited, while network attacks can be continuous. When system resources are under high load, network lag and disconnection can occur.

[0078] To ensure the network can function properly, a central processing unit (CPU) threshold is set. When the system's current CPU exceeds the CPU threshold, security services will be skipped, meaning that network attacks will not be detected or blocked, thereby reducing the system's resource consumption. This will increase the risk of network attacks on clients.

[0079] To address the problems described above, this application provides a parameter adjustment method that enables the system to degrade security service parameters under high load, thereby preventing the system from losing its security capabilities and ensuring network security. The methods and apparatus described in this application are based on the same technical concept. Since the principles by which the methods and apparatus solve the problems are similar, embodiments of the apparatus and methods can be referred to interchangeably, and repeated details will not be elaborated further.

[0080] The embodiments of this application will now be described in detail with reference to the accompanying drawings.

[0081] The system structure diagram provided in this application embodiment is as follows: Figure 1 As shown, in Figure 1 The system comprises a resource monitoring center, a business center, and a cloud data processing center. The resource monitoring center monitors system resources in real time and sends the monitoring results to the business center. The business center includes various types of security services. When a security service is enabled, the business center can detect received network traffic and obtain detection results. These results include at least resource utilization and / or attack detection rate. The attack detection rate represents the proportion of network attack data detected by the device corresponding to the detection level parameter, which represents the degree of detection of network attack data by the security service under the detection category during the interception process. This detection category represents the dimension of network attack data detection, which can be detection protocol, detection application, detection depth, etc. The business center sends all detection results corresponding to each device to the cloud data processing center. Each device can include various types of security services. The cloud data processing center processes the data sent by the business center and returns the processed results to the business center.

[0082] In order to ensure the security and stability of the system and prevent excessive system resource consumption that could cause network lag or disconnection, this application embodiment needs to adjust the system resources consumed by the device to reduce system resource consumption.

[0083] Furthermore, different security services on the device side have different security capabilities and consume different system resources. Factors affecting security capabilities may include detection protocols, detection applications, detection depth, etc. In order to determine the system resources consumed by each security service on the device side, this application embodiment will collect the resource utilization rate and attack detection rate of each security service on each device side under each detection level parameter. The detection categories can be adjusted and modified according to the actual situation.

[0084] During the actual data collection process at the device end, devices of the same type are identified in the system. All parameters of the same device end are consistent. Each collection only changes the detection level parameter of the device end, thereby statistically obtaining a large amount of data on the resource utilization rate and attack detection rate of the same type of device end under different detection level parameters. Based on the device end type, the identified large amount of data is clustered to obtain the resource utilization rate and attack detection rate of each type of device end under each detection level parameter. Clustering methods can be Gaussian mixture clustering, etc., which will not be elaborated on here.

[0085] In this embodiment, the resource utilization rate and attack detection rate of each type of device under various detection parameters can be displayed in a table, and the cloud data processing center can distribute the table to the corresponding type of device, as shown in Table 1:

[0086]

[0087] Table 1

[0088] In Table 1 above, taking the device-side security service as an example, IPS can be used to detect this security service using different detection categories. Each detection category can correspond to multiple detection level parameters, and each detection level parameter corresponds to a resource utilization rate and an attack detection rate. If detection category 1 is detection depth, then the detection level parameters corresponding to detection depth are [L1, LMax]. L1 represents that the detection depth of this security service for network traffic is 2K, where 2K is 2000 bytes. The security service will detect the first 2000 bytes of a network traffic flow corresponding to the device. LMax represents that the detection depth of this security service for network traffic is full flow, that is, all network traffic received by the device. The security service will detect all network traffic received by the device. Other detection level parameters are similar to the example above, and the resource utilization rate and attack detection rate corresponding to other security services on the device are similar to those in Table 1 above. They are not listed in detail here.

[0089] Since security services on the device side consume system resources when performing security protection, the resource consumption value corresponding to each device side under each detection level parameter can also be calculated based on Table 1 above, as shown in Table 2:

[0090]

[0091] Table 2

[0092] In Table 2 above, taking the security service on the device side as an example, since the resource utilization rate and attack detection rate of each device side under different detection level parameters are determined, in order to determine the detection level parameter with the highest resource consumption, it is necessary to determine the adjacent resource utilization rate and attack detection rate. Initially, both the resource utilization rate and attack detection rate are 0. The difference in resource utilization rate and the difference in attack detection rate between each adjacent detection level parameter are calculated, and the ratio between the difference in resource utilization rate and the difference in attack detection rate are calculated respectively. This ratio is used as the resource consumption value of the corresponding detection level parameter. This consumption value can represent the resources required to detect a unit of network attack data. The resource consumption values ​​corresponding to each detection level parameter of other security services on this device side are shown in Table 2 above, and will not be elaborated on here.

[0093] For example, for detection category 1 in Table 2 above, when the detection level parameter is LMax-1, the resource utilization rate is 20% and the attack detection rate is 99%; when the detection level parameter is LMax, the resource utilization rate is 80% and the attack detection rate is 100%. For these two adjacent detection level parameters, the resource consumption required per unit of attack detection rate is (80%-20%) / (100%-99%) = 60.

[0094] In this embodiment, Table 2 can be sent to the corresponding device, so that each device stores the resource utilization rate, attack detection rate and resource consumption value corresponding to different detection degree parameters. Since each device can only correspond to one detection category and one detection degree parameter in actual use, when system resources are insufficient, a downgrade operation can be performed through the device with high resource consumption, thereby reducing the system's resource consumption.

[0095] Reference Figure 2 This application provides a parameter adjustment method that can reduce system resource consumption, avoid skipping security services, and thus improve the system's network security capabilities. The implementation process of this method is as follows:

[0096] Step S21: Obtain the resource consumption value corresponding to one or more detection degree parameters.

[0097] Since the device stores Table 2 above, it is possible to obtain the resource consumption values ​​corresponding to each detection level parameter of the device from Table 2. In order to adjust system resources, it is also necessary to determine the actual resource utilization rate and resource utilization rate range of the device, and extract the maximum resource utilization rate from the resource utilization rate range. When the actual resource utilization rate of the device exceeds the maximum resource utilization rate, it means that the device consumes too much system resources. In order to reduce the consumption of system resources, it is necessary to trigger the execution of steps S22-S23. This embodiment of the application needs to obtain the resource consumption value corresponding to each detection level parameter based on Table 2 above.

[0098] Step S22: Select the maximum resource consumption value from one or more resource consumption values, and determine the first detection degree parameter corresponding to the maximum resource consumption value.

[0099] After determining the resource consumption value corresponding to each detection level parameter, the maximum resource consumption value can be selected from the columns corresponding to the resource consumption values ​​in Table 2, and the first detection level parameter corresponding to the maximum resource consumption value can be determined.

[0100] Using the above method, the first detection level parameter corresponding to the maximum resource consumption value in the device can be determined, thereby enabling the adjustment of the device's resources based on the quantified first detection level parameter.

[0101] Step S23: Adjust the first detection degree parameter according to the detection degree parameter gradient.

[0102] After determining the first detection level parameter, the first detection level parameter is adjusted according to the detection level parameter gradient. The specific adjustment process is as follows:

[0103] The detection severity parameter gradient arranges the detection severity parameters in descending order, as shown in Table 3:

[0104]

[0105] Table 3

[0106] Based on Table 3 above, taking the detection category as an example, L1 corresponds to the smallest detection depth, with a detection depth of 2K, and LMax corresponds to the largest detection depth. The gradient of the detection depth parameter is a sequence of detection depths sorted from largest to smallest. Table 3 above is only an example of detection depth. Other detection categories can be referred to the examples in Table 3 above, which will not be elaborated on here.

[0107] In the gradient of detection severity parameters, a detection severity parameter smaller than the first detection severity parameter is determined. This smaller detection severity parameter is then used as the second detection severity parameter. The detection severity parameter on the device side is then adjusted from the first detection severity parameter to the second detection severity parameter, thereby achieving a downgrade adjustment of the detection severity parameter.

[0108] After adjusting the detection level parameter on the device from the first detection level parameter to the second detection level parameter, it is necessary to determine whether the second detection level parameter needs to be further adjusted. The specific determination process is as follows:

[0109] Method 1: Determine the target actual resource utilization rate of the device under the second detection level parameter, and the minimum resource utilization rate within the range of resource utilization rates of the device. If the target actual resource utilization rate is greater than the minimum resource utilization rate, adjust the second detection level parameter to a smaller value until the current target actual resource utilization rate is not greater than the minimum resource utilization rate. If the target actual resource utilization rate is not greater than the minimum resource utilization rate, stop adjusting the second detection level parameter.

[0110] Method 2: When performing the second detection level parameter, determine the overall security capability value of all security services on the device. The specific process for determining the overall security capability value is as follows:

[0111] The weight value corresponding to each security service in the device and the at least one attack detection rate corresponding to each security service are determined. The weight value can be determined according to the proportion of network attack data detected by the security service to the total amount of network attack data. For example, if security service 1 is 20%, security service 2 is 30%, and security service 3 is 50% in the device, then the weight value corresponding to security service 1 is 0.2, the weight value corresponding to security service 2 is 0.3, and the weight value corresponding to security service 3 is 0.5.

[0112] In this embodiment of the application, the security services with set weight values ​​can be displayed in tabular form, as shown in Table 4 below:

[0113]

[0114]

[0115] Table 4

[0116] Table 4 above records the weight values ​​and attack detection rates of the three security services on the device side. Here, we take security service 1, security service 2, and security service 3 as examples. Each security service corresponds to at least one detection category, which includes one or more of the following: detection depth, detection protocol, or detection application. Each detection category corresponds to at least one detection level parameter, and each detection level parameter corresponds to its own attack detection rate. The weight values ​​and attack detection rates of other devices are shown in Table 4 above and will not be elaborated on here.

[0117] By using the methods described above, the attack detection rate and weight value corresponding to each security service can be determined, which is helpful in quantifying the security capabilities of the security services.

[0118] After determining the weight value and attack detection rate for each security service, the weight value and attack detection rate are substituted into the security capability calculation formula to obtain the security capability value for each security service. The larger the security capability value, the stronger the ability of the corresponding security service to intercept network attack data. The security capability calculation formula is as follows:

[0119]

[0120] In the above security capability calculation formula, i represents the i-th security service on the device, Wi represents the weight value of the i-th security service, M represents the total number of detection categories corresponding to the i-th security service, and PL_R j This represents the attack detection rate corresponding to the j-th detection level parameter. This represents the sum of attack detection rates corresponding to the M detection level parameters.

[0121] It should be noted that after determining the security capability value of each security service based on the above security capability calculation formula, the security capability value corresponding to each security service in the device is determined, and all security capability values ​​are added together to obtain the total security capability parameter. This total security capability parameter is used as the overall security capability value of the device.

[0122] By using the above method, the security capabilities of each security service are quantified into security capability values, and the overall security capability value of the device is quantified based on the security capability values, which is beneficial for adjusting the resources consumed by the device.

[0123] After determining the overall safety capability value, the overall safety capability value is compared with the safety capability threshold. If the overall safety capability value is less than the safety capability threshold, the second detection degree parameter is adjusted according to the detection degree parameter gradient until the overall safety capability value is not less than the safety capability threshold. Since the above description explains the detailed process of adjusting the second detection degree parameter according to the detection degree parameter gradient, it will not be elaborated on here.

[0124] If the overall safety capability value is not less than the safety capability threshold, then stop adjusting the second detection level parameter.

[0125] The embodiments of this application can use method one and / or method two to adjust the second detection level parameter, thereby determining the conditions for stopping the adjustment of the detection level parameter by using the minimum resource utilization rate and the overall safety capability value, ensuring that the resource utilization rate of the equipment can be reduced and the safety protection capability of the equipment can be improved.

[0126] It should be noted that the system can be a device, and there can be multiple devices in the system, with each device corresponding to at least one security service.

[0127] Using the above method, when the resource utilization rate on the device exceeds the maximum resource utilization rate, the first detection level parameter on the device can be adjusted downward, thereby reducing the resource utilization rate of the device and the corresponding system. This solves the problem of skipping security services when the system resource utilization rate is too high, which increases network security risks and ensures the stability and security of the system.

[0128] Based on the same inventive concept, this application also provides a parameter adjustment device, which implements the function of a parameter adjustment method, as described above. Figure 3 The device includes:

[0129] The acquisition module 301 is used to acquire the resource consumption value corresponding to one or more detection degree parameters, wherein the detection degree parameters represent the degree of detection of the network attack data by the security service under the detection category during the interception of network attack data;

[0130] The determining module 302 is used to filter out the maximum resource consumption value from one or more resource consumption values, and determine the first detection degree parameter corresponding to the maximum resource consumption value;

[0131] The adjustment module 303 is used to adjust the first detection degree parameter according to the detection degree parameter gradient.

[0132] In one possible design, the obtaining module 301 is specifically used to obtain the resource utilization rate and attack detection rate corresponding to each detection level parameter in each security service, and calculate the resource consumption value of each corresponding to the resource utilization rate and attack detection rate of each adjacent detection level parameter.

[0133] In one possible design, the obtaining module 301 is further configured to calculate the resource utilization difference and the attack detection rate difference between each adjacent detection level parameter, and calculate the ratio between the resource utilization difference and the attack detection rate difference respectively, and use each ratio as the resource consumption value of the corresponding detection level parameter.

[0134] In one possible design, the determining module 302 is specifically used to determine each detection level parameter corresponding to the device end, as well as to determine the actual resource utilization rate and resource utilization rate range value corresponding to the device end, extract the maximum resource utilization rate from the resource utilization rate range value, and if the actual resource utilization rate is greater than the maximum resource utilization rate, then the maximum resource consumption value is selected from one or more resource consumption values, and the first detection level parameter corresponding to the maximum resource consumption value is determined.

[0135] In one possible design, the adjustment module 303 is specifically used to adjust the first detection degree parameter according to the detection degree parameter gradient, wherein the detection degree parameter gradient is a sequence of detection degree parameters sorted in descending order.

[0136] In one possible design, the adjustment module 303 is further configured to determine a second detection degree parameter smaller than the first detection degree parameter in the detection degree parameter gradient, and adjust the first detection degree parameter to the second detection degree parameter. When the detection degree parameter is the second detection degree parameter, the module determines the target actual resource utilization rate of the device, the minimum resource utilization rate in the resource utilization rate range, and the overall security capability value of all security services in the device. The overall security capability value characterizes the protection capability of all security services in the device against network attack data. The second detection degree parameter is adjusted based on the relationship between the minimum resource utilization rate and the target resource utilization rate, and / or based on the relationship between the overall security capability value and the security capability threshold.

[0137] In one possible design, the adjustment module 303 is further configured to adjust the second detection degree parameter according to the detection degree parameter gradient if the target actual resource utilization rate is greater than the minimum resource utilization rate, until the target actual resource utilization rate is not greater than the minimum resource utilization rate, and to stop adjusting the second detection degree parameter if the target actual resource utilization rate is not greater than the minimum resource utilization rate.

[0138] In one possible design, the adjustment module 303 is further configured to adjust the second detection degree parameter according to the detection degree parameter gradient if the overall safety capability value is less than the safety capability threshold, until the sum of the safety capability values ​​is not less than the safety capability threshold; if the overall safety capability value is not less than the safety capability threshold, then stop adjusting the second detection degree parameter.

[0139] In one possible design, the adjustment module 303 is further configured to obtain at least one attack detection rate corresponding to each security service in the device, and a weight value corresponding to each security service. Based on the weight value of each security service and all attack detection rates, a security capability value corresponding to each security service is obtained. The larger the security capability value, the stronger the ability of the security service corresponding to the security capability value to intercept network attack data. All security capability values ​​in the device are added together to obtain the overall security capability value.

[0140] In one possible design, the adjustment module 303 is further configured to obtain the attack detection rate of each security service in the device under different detection categories, or to obtain the attack detection rate of each security service under each detection degree parameter in the detection category.

[0141] In one possible design, the adjustment module 303 is further configured to calculate the security capability using a formula. The security capability value corresponding to each security service is obtained, where SFi represents the security capability value corresponding to the i-th security service, Wi represents the weight value of the i-th security service on the device side, and PL_R j This represents the attack detection rate corresponding to the j-th detection level parameter. This represents the sum of attack detection rates corresponding to the M detection level parameters.

[0142] Based on the same inventive concept, this application also provides an electronic device that can realize the function of the aforementioned parameter adjustment device. (Refer to...) Figure 4 The electronic device includes:

[0143] At least one processor 401 and a memory 402 connected to at least one processor 401. In this embodiment, the specific connection medium between the processor 401 and the memory 402 is not limited. Figure 4 The example shown is the connection between processor 401 and memory 402 via bus 400. Bus 400 is... Figure 4 The connections between other components are indicated by thick lines and are for illustrative purposes only, not as limiting information. The 400 bus can be divided into address bus, data bus, control bus, etc., for ease of representation. Figure 4 The term is represented by a single thick line, but this does not imply that there is only one bus or one type of bus. Alternatively, processor 401 can also be called a controller; there is no restriction on the name.

[0144] In this embodiment, memory 402 stores instructions executable by at least one processor 401. By executing the instructions stored in memory 402, at least one processor 401 can perform a parameter adjustment method as described above. Processor 401 can implement... Figure 3 The functions of each module in the device shown.

[0145] The processor 401 is the control center of the device. It can connect to various parts of the control device through various interfaces and lines. By running or executing instructions stored in memory 402 and calling data stored in memory 402, the processor can perform various functions and process data, thereby monitoring the device as a whole.

[0146] In one possible design, processor 401 may include one or more processing units. Processor 401 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into processor 401. In some embodiments, processor 401 and memory 402 may be implemented on the same chip; in some embodiments, they may also be implemented separately on separate chips.

[0147] Processor 401 can be a general-purpose processor, such as a central processing unit (CPU), digital signal processor, application-specific integrated circuit, field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of a parameter adjustment method disclosed in the embodiments of this application can be directly manifested as execution by a hardware processor, or as a combination of hardware and software modules within the processor.

[0148] Memory 402, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 402 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 402 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 402 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0149] By designing and programming the processor 401, the code corresponding to the parameter adjustment method described in the foregoing embodiments can be embedded into the chip, enabling the chip to execute it during operation. Figure 2 The illustrated embodiment presents a parameter adjustment step. How to design and program the processor 401 is a technique well-known to those skilled in the art and will not be described further here.

[0150] Based on the same inventive concept, embodiments of this application also provide a storage medium storing computer instructions that, when executed on a computer, cause the computer to perform a parameter adjustment method described above.

[0151] In some possible implementations, various aspects of the parameter adjustment method provided in this application can also be implemented in the form of a program product, which includes program code that, when the program product is run on a device, causes the control device to perform the steps in a parameter adjustment method according to various exemplary embodiments of this application described above.

[0152] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0153] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0154] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0155] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0156] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A parameter adjustment method, characterized in that, include: Obtain the resource consumption value corresponding to one or more detection degree parameters, wherein the detection degree parameters characterize the degree of detection of network attack data by the security service under the detection category; The maximum resource consumption value is selected from one or more resource consumption values, and a first detection level parameter corresponding to the maximum resource consumption value is determined. The first detection degree parameter is adjusted according to the detection degree parameter gradient.

2. The method as described in claim 1, characterized in that, Obtaining the resource consumption values ​​corresponding to one or more detection level parameters includes: Obtain the resource utilization rate and attack detection rate corresponding to each detection level parameter in each security service. The attack detection rate represents the proportion of network attack data detected by the device corresponding to the detection level parameter to all network attack data. The resource consumption values ​​are calculated based on the resource utilization rate and attack detection rate corresponding to each of the adjacent detection degree parameters.

3. The method as described in claim 2, characterized in that, The resource consumption value is calculated based on the resource utilization rate and attack detection rate corresponding to each of the adjacent detection degree parameters, including: Calculate the resource utilization difference and attack detection rate difference between each adjacent detection level parameter, and calculate the ratio between the resource utilization difference and the attack detection rate difference, wherein the ratio represents the resources consumed per unit of attack detected; Each ratio is used as the resource consumption value for the corresponding detection level parameter.

4. The method as described in claim 1, characterized in that, Before filtering for the maximum resource consumption value from one or more resource consumption values, the process also includes: The various detection parameters corresponding to the device are determined, as well as the actual resource utilization rate and the range of resource utilization rate corresponding to the device. Extract the maximum resource utilization rate from the range of resource utilization rates; if the actual resource utilization rate is greater than the maximum resource utilization rate, then filter out the maximum resource consumption value from one or more resource consumption values ​​and determine the first detection degree parameter corresponding to the maximum resource consumption value.

5. The method as described in claim 4, characterized in that, The adjustment of the first detection degree parameter according to the detection degree parameter gradient includes: The first detection severity parameter is adjusted according to the detection severity parameter gradient, wherein the detection severity parameter gradient is a sequence of detection severity parameters sorted in descending order.

6. The method as described in claim 1 or 5, characterized in that, The adjustment of the first detection degree parameter according to the detection degree parameter gradient includes: A second detection degree parameter smaller than the first detection degree parameter is determined from the detection degree parameter gradient, and the first detection degree parameter is adjusted to the second detection degree parameter. When the detection level parameter is the second detection level parameter, the target actual resource utilization rate of the device end, the minimum resource utilization rate in the range of resource utilization rate values ​​are determined, and the overall security capability value of all security services in the device end is determined, wherein the overall security capability value characterizes the protection capability of all security services in the device end against network attack data. The second detection level parameter is adjusted based on the relationship between the minimum resource utilization rate and the target resource utilization rate; and / or Based on the relationship between the overall machine safety capability value and the safety capability threshold, the second detection degree parameter is adjusted.

7. The method as described in claim 6, characterized in that, The adjustment of the second detection level parameter based on the relationship between the minimum resource utilization rate and the target resource utilization rate includes: If the target actual resource utilization rate is greater than the minimum resource utilization rate, then the second detection degree parameter is adjusted according to the detection degree parameter gradient until the target actual resource utilization rate is not greater than the minimum resource utilization rate; If the actual resource utilization rate of the target is not greater than the minimum resource utilization rate, then the adjustment of the second detection degree parameter shall be stopped.

8. The method as described in claim 6, characterized in that, The adjustment of the second detection level parameter based on the relationship between the overall machine safety capability value and the safety capability threshold includes: If the overall safety capability value is less than the safety capability threshold, the second detection degree parameter is adjusted according to the detection degree parameter gradient until the overall safety capability value is not less than the safety capability threshold. If the overall safety capability value is not less than the safety capability threshold, then the adjustment of the second detection level parameter shall be stopped.

9. The method as described in claim 6, characterized in that, The determination of the overall security capability value of all security services in the device includes: Obtain at least one attack detection rate for each security service in the device, and a weight value for each security service; Based on the weight value corresponding to each security service and the at least one attack detection rate, a security capability value corresponding to each security service is obtained. The larger the security capability value, the stronger the ability of the security service corresponding to the security capability value to intercept network attack data. The overall security capability value is obtained by summing all the security capability values ​​in the device.

10. The method as described in claim 9, characterized in that, Obtaining at least one attack detection rate corresponding to each security service in the device includes: Obtain the attack detection rate for each security service in the device under different detection categories, wherein the different detection categories include one or more of the following: detection depth, detection protocol, or detection application; or Obtain the attack detection rate for each security service under the detection category for each detection level parameter.

11. The method as described in claim 9, characterized in that, The security capability value corresponding to each security service is obtained based on the weight value of each security service and the detection rate of all attacks, including: Based on the safety capability calculation formula Obtain the security capability value corresponding to each security service; Wherein, SFi represents the security capability value corresponding to the i-th security service, Wi represents the weight value of the i-th security service on the device side, and PL_R j This represents the attack detection rate corresponding to the j-th detection level parameter. This represents the sum of attack detection rates corresponding to the M detection level parameters.

12. A parameter adjustment device, characterized in that, include: The acquisition module is used to acquire the resource consumption values ​​corresponding to one or more detection degree parameters, wherein the detection degree parameters represent the degree of detection of the network attack data by the security service under the detection category during the interception of network attack data; The determination module is used to filter out the maximum resource consumption value from one or more resource consumption values, and determine the first detection degree parameter corresponding to the maximum resource consumption value; The adjustment module is used to adjust the first detection degree parameter according to the detection degree parameter gradient.

13. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor, when executing a computer program stored in the memory, implements the steps of the method according to any one of claims 1 to 11.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method according to any one of claims 1 to 11.