Safety management system based on unified configuration of micro-service resources
By building a centralized external configuration support platform, permission policy rule base, and intelligent audit module in a microservice environment, the problems of time-consuming, labor-intensive, and insufficient monitoring under traditional configuration methods are solved, achieving efficient and secure microservice management. Combined with AI and ML technologies, the stability and security of the system are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHENGJIANG PUBLIC INFORMATION
- Filing Date
- 2026-03-02
- Publication Date
- 2026-05-19
AI Technical Summary
Traditional application configuration methods in microservice environments are time-consuming and laborious to modify, lack intelligent auditing and indicator monitoring functions, and cannot meet the security and efficiency requirements of modern applications.
A security management system based on unified configuration of microservice resources is provided, including a centralized external configuration support platform, a permission policy rule base, an intelligent audit module, and an indicator monitoring service module. These modules enable centralized management, access control, intelligent monitoring, and auditing of microservice configurations.
It improves the efficiency and security of configuration management in microservice systems, enables adaptive monitoring and adjustment, ensures system stability and security, and enhances the accuracy and real-time performance of monitoring by combining artificial intelligence and machine learning technologies.
Smart Images

Figure CN122069092A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, specifically to a security management system based on unified configuration of microservice resources. Background Technology
[0002] Traditional application configuration methods primarily rely on static configuration changes (such as in traditional microservice architectures). Figure 1 As shown, users directly configure microservices and access services through the gateway (this method suffers from cumbersome and time-consuming configuration modifications). In a distributed microservice environment, modifying configurations becomes even more difficult when there are many service instances. Furthermore, traditional application configuration methods lack intelligent auditing and metric monitoring capabilities, failing to meet the security and efficiency requirements of modern applications. Summary of the Invention
[0003] This application aims to solve the problems of cumbersome static configuration modification in traditional applications, time-consuming and laborious configuration modification in distributed microservice environments, and lack of intelligent auditing and indicator monitoring functions. It provides a security management system based on unified configuration of microservice resources.
[0004] To achieve this objective, the following technical solution is adopted in this application: A security management system based on unified configuration of microservice resources is provided, including: A centralized external configuration support platform built outside of microservice modules is used to provide configuration support for each microservice and realize centralized management of microservice configuration; A permission policy rule base is used to manage user access permissions and resources to microservices; The intelligent auditing module connects the external configuration support platform and the permission policy rule base to monitor and audit the configuration and access process of each microservice. The indicator monitoring service module connects the external configuration support platform and the intelligent audit module, and is used to monitor and statistically analyze various indicators of the system.
[0005] Preferably, the external configuration support platform includes: The storage unit is used to store the configuration information of all microservices; A configuration management unit, connected to the storage unit, is used to provide users with the ability to add, delete, and modify configuration information. A configuration version management unit is connected to the storage unit and is used to manage each configuration version and support users to roll back to a historical configuration version. A configuration information push unit, connected to the storage unit and the configuration version management unit, is used to detect whether the configuration version or configuration information has changed, and when a change occurs, push the updated configuration information to the corresponding microservice. The registration and configuration information acquisition unit, connected to the storage unit, is used to determine whether the microservice is registered on the configuration platform when the microservice starts, and automatically register with the configuration platform and obtain configuration information that matches itself when it is determined that the microservice is not registered. The configuration information creation module is connected to the storage unit and is used to provide users with the ability to create or update configuration information and store it in the storage unit.
[0006] Preferably, the permission policy rule base includes: The access control policy matching unit is used to match the corresponding access control policy based on user information. An access risk assessment and access control policy dynamic adjustment unit is connected to the access control policy matching unit and is used to assess access risks based on user behavior and dynamically adjust access control policies based on the risk assessment results. The access behavior and access risk assessment result recording unit is connected to the access risk assessment and access control policy dynamic adjustment unit and is used to record the user's access behavior and access risk assessment results. The access control policy and evaluation model update unit, connected to the access behavior and access risk assessment result recording unit, is used to adaptively update the access control policy and evaluation model based on user access behavior and access risk assessment results. The access audit and monitoring unit connects to the access behavior and access risk assessment result recording unit, which is used to record users' anti-counterfeiting behavior and resource usage, and to perform access audit and access strategy optimization.
[0007] Preferably, the intelligent audit module includes: The first data collection unit is used to collect and integrate audit information from various microservices; An audit log recording unit, connected to the data collection unit, is used to record all configuration change operations as configuration process data. The data analysis unit, connected to the audit log recording unit, is used to automatically analyze and issue early warnings on configuration process data, and identify anomalies or risk points. The risk management and prediction unit, connected to the data analysis unit and / or the audit log recording unit, is used to predict future configuration risks based on historical configuration data and / or data analysis results. The data visualization unit, connected to the data analysis unit and the risk management and prediction unit, is used to visualize the data analysis results and prediction results.
[0008] Preferably, the indicator monitoring service module includes: The second data collection unit is used to collect various performance indicators of the system; The real-time monitoring unit is connected to the second data collection unit and is used to monitor the changes in performance metrics caused by each microservice in real time. The historical data storage unit is connected to the second data collection unit and is used to store the monitored performance metrics data into the database; The data analysis and trend prediction unit is connected to the historical data storage unit and is used to analyze the collected performance index data to identify the system's performance trends and potential problems. An alarm unit, connected to the data analysis and trend prediction unit, is used to issue alarms for abnormal indicators based on preset alarm thresholds or alarm conditions. An automated response unit, connected to the real-time monitoring unit, is used to automatically adjust system resources based on monitored performance indicators; The visualization unit connects the real-time monitoring unit and the historical data storage unit, and is used to visualize the real-time and historical data of system performance indicators.
[0009] This application has the following beneficial effects: By building a centralized external configuration support platform outside the microservice modules, configuration support is provided for each microservice, and a permission policy rule is established to manage user access permissions and resources. Simultaneously, an intelligent auditing module and a metrics monitoring service are integrated into the external configuration support platform. The intelligent auditing module combines artificial intelligence and machine learning technologies to automatically analyze and predict system performance, detect anomalies, and provide system administrators with a better understanding and monitoring of the microservice system's performance. The metrics monitoring service provides performance metrics for the microservice system, helping administrators better understand its performance status. These modules work together to ensure effective and secure management of microservice configurations. Furthermore, administrators can formulate different permission policy rules for different microservice modules to ensure the security of user access permissions and resources. The intelligent auditing module and the metrics monitoring service can automatically analyze and predict system performance, enabling adaptive monitoring and policy adjustments, and taking timely corrective measures to ensure efficient system operation. Attached Figure Description
[0010] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly described below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a diagram of a traditional microservice architecture; Figure 2This is a schematic diagram of the structure of a security management system based on unified configuration of microservice resources provided in an embodiment of this application; Figure 3 This is a flowchart illustrating the steps of using the security management system provided in this embodiment to uniformly configure microservice resources. Detailed Implementation
[0012] The technical solution of this application will be further described below with reference to the accompanying drawings and specific embodiments.
[0013] The accompanying drawings are for illustrative purposes only and are schematic diagrams, not actual images. They should not be construed as limiting the scope of this application. To better illustrate the embodiments of this application, some components in the drawings may be omitted, enlarged, or reduced, and do not represent the actual product dimensions. It is understandable to those skilled in the art that some well-known structures and their descriptions may be omitted in the drawings.
[0014] In the accompanying drawings of the embodiments of this application, the same or similar reference numerals correspond to the same or similar components. In the description of this application, it should be understood that if terms such as "upper," "lower," "left," "right," "inner," and "outer" indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, they are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, the terms used to describe positional relationships in the drawings are only for illustrative purposes and should not be construed as limiting this application. For those skilled in the art, the specific meaning of the above terms can be understood according to the specific circumstances.
[0015] In the description of this application, unless otherwise expressly specified and limited, the term "connection" or similar designation indicating a connection between components should be interpreted broadly. For example, it can refer to a fixed connection, a detachable connection, or an integral part; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can refer to the internal communication between two components or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0016] This application provides a security management system based on unified configuration of microservice resources. Its purpose is to achieve centralized management of microservice configurations, access control, intelligent monitoring and auditing, and indicator monitoring, thereby improving the reliability and stability of the microservice system. The technical solution provided in this embodiment includes the following technical components: 1. Build a centralized external configuration support platform outside the system's microservice modules. This centralized external configuration support platform provides configuration support for each microservice, enabling centralized management of microservice configurations and avoiding the problems of cumbersome static configuration modifications in traditional applications and the time-consuming and laborious process of modifying configurations in a distributed microservice environment.
[0017] In this embodiment, the external configuration support platform is preferably a cloud platform or an internal enterprise platform, used to manage the configuration and resources of microservices. The platform's functions include: 1. Storage Unit: Provides a centralized storage system for storing configuration information of all microservices. It adopts a combined architecture of distributed key-value storage (such as etcd / RedisCluster) and persistent storage (such as MinIO / Alibaba Cloud OSS) to balance high-concurrency read / write operations with data reliability. The key-value structure is designed according to "microservice name-environment-configuration type" (e.g., service=user-service:env=prod:config=database) to achieve dimensional partitioning of configurations. Core configurations (such as database connections and service addresses) are stored in etcd, supporting millisecond-level queries; non-core configurations (such as log templates and static parameters) are stored in object storage to reduce the pressure on key-value storage. Data redundancy backup is enabled (3 replicas in the etcd cluster + cross-region backup in object storage), and distributed consistency is guaranteed through the Raft protocol.
[0018] 2. Configuration Management Unit: Supports CRUD operations on configuration information, facilitating easy configuration management for users. Implemented based on RESTful API + access control middleware (such as Spring Security) + data validation components (such as HibernateValidator). Provides standardized REST interfaces: supports CRUD operations and single / batch operations; the interface layer integrates access control, using JWT tokens to verify whether users have the necessary permissions to perform configuration operations on the corresponding microservice (e.g., only administrators can modify production environment configurations); the data validation layer validates configuration formats and field validity (e.g., database URL format, port range, and non-empty required fields), returning standardized error codes upon validation failure; operation logs (based on AOP aspects) record the operator, operation time, and content before and after the change, storing them in an audit log database (such as Elasticsearch).
[0019] 3. A configuration version management unit is used to manage various configuration versions and support users to roll back to historical configuration versions. It employs a version number generation strategy (semantic versioning / timestamped versioning) + change log storage (MySQL / PostgreSQL) + incremental backup mechanism. When a configuration change occurs, a version number is automatically generated: a semantic version (suitable for major changes) or a timestamped version (suitable for frequent minor changes). Each version record is associated with "change type (add / modify / delete), operator, change content diff, and change reason," and stored in the version management database. During rollback, the corresponding configuration content is queried based on the target version number to verify the compatibility between the current configuration and the target version (e.g., whether there are missing dependency configurations). If the verification passes, the current configuration is overwritten, and a new rollback version record is generated.
[0020] 4. Configuration information push unit: This unit detects changes in configuration version or configuration information and pushes the updated configuration information to the corresponding microservices when changes occur. Real-time push is achieved based on a long polling + WebSocket + event-driven architecture (such as RabbitMQ / Kafka). Configuration change detection: etcd uses a Watcher mechanism to listen for configuration key change events (PUT / DELETE). When a change is detected, a configuration change event is triggered. Event distribution: The change event is routed to the dedicated queue of the corresponding microservice via RabbitMQ. Push method selection: For long-connection scenarios (such as Java microservices), the changed configuration is actively pushed via WebSocket, and the microservice hot-loads it after receiving it. For short-connection / compatibility scenarios (such as Python / Go microservices), a long polling mechanism is used. After the microservice successfully loads the configuration, it returns an ACK confirmation to the platform. Microservices that do not receive confirmation will trigger a retry.
[0021] 5. Registration and Configuration Information Acquisition Unit: This unit determines whether the microservice is registered with the configuration platform upon startup. If not, it automatically registers with the platform and retrieves matching configuration information. Upon startup, the microservice reads the service-id, env, and config-types (a list of required configuration types) from its local configuration. It then sends a registration request to the platform: POST / api / v1 / service / register. The platform verifies the registration information: it checks if service-id and env already exist; if not, it writes them to the service registry (Redis) and sets the status to "online." Based on service-id, env, and config-types, the platform queries etcd for matching configurations (exactly matching service-id, fuzzy matching config-types), packages them, and returns them to the microservice. Caching and Retrying: The microservice stores the retrieved configuration in its local memory cache. If registration / retrieval fails, it retryes 5 times (with a 1-second interval). If the retry fails, startup fails.
[0022] 6. Configuration Information Creation Module: This module provides configuration template and configuration mode selection functions, allowing users to create or update configuration information as needed, thereby improving the efficiency and accuracy of configuration management. Template Management: The platform pre-sets commonly used configuration templates (such as MySQL, Redis, RabbitMQ, log configuration, etc.). The templates use Freemarker syntax and reserve configurable variables (such as ${host}, ${port}, ${username}). Configuration Mode Definition: Configuration rules for each template are defined using JSONSchema (such as field type, required fields, value range, and default value), used for form validation and dynamic rendering. II. Establish a permission policy rule base This embodiment manages user access permissions and resources (microservice configuration information) by establishing a permission policy rule base. This rule base enables access control over microservices, ensuring system security.
[0023] Specifically, the permission policy rule base includes: 1. Access control policy matching unit, used to match the corresponding access control policy based on factors such as user attributes, role, and access time; User attributes include a user's unique identifier and other attributes that can identify the user.
[0024] Access control type definition: The types of operations that users can perform on resources (configuration information), such as read, write, delete, and modify. Rule definition: Based on five dimensions of "user attributes + role + access time + resource attributes + operation type", policies are defined using Drools rule syntax; Matching process: When a user initiates an access request, the gateway intercepts the request and extracts the request context; the rule engine loads the permission policy rule library and performs condition matching in the order of "role priority → resource sensitivity → time range"; the matching results are cached in Redis to avoid duplicate calculations.
[0025] 2. Access Risk Assessment and Dynamic Adjustment Unit for Access Control Policies: Connected to the Access Control Policy Matching Unit, this unit assesses access risks based on user behavior and dynamically adjusts access control policies according to the risk assessment results. When necessary, it allows for operational requirement overriding, and the system will appropriately relax strong access control and grant access permissions to the subject based on the definition of the access control policy.
[0026] Permissions define a user's specific access rights to resources. They link user identity, resources, and operation permissions to indicate which operations a user can perform on a particular resource.
[0027] A rule is a set of conditions used to determine whether a user has permission to perform a specific operation. Rules are preferably defined based on factors such as user identity, resource attributes, and operation type.
[0028] A policy is a set of rules used to achieve specific access control goals. For example, one policy might allow administrators to access all resources, while another policy might allow only regular users to access specific resources.
[0029] Risk indicator definition: Set multi-dimensional risk indicators and their weights.
[0030] Risk assessment: Flink consumes user access behavior streams in real time, calculates real-time risk scores based on indicators, and generates the final assessment result by combining historical risk records (cumulative scores over the past 24 hours). Dynamic strategy adjustment: High risk: Triggers strict policies (access denied + SMS alert); Medium risk: Triggering two-factor authentication (such as SMS verification code / dynamic token); Low risk: Maintain existing strategy; Operational requirement coverage: After a user submits a coverage request and it is approved, the user's permissions are temporarily relaxed through the policy update interface.
[0031] 3. User access control and management unit, used to control and manage user access; if a user's access complies with the access control policy, the system allows the user to access; if a user's access does not comply with the access control policy, the system denies the user access or restricts the user's access. Pre-permission verification: The gateway layer intercepts all configuration access requests through a custom filter, first queries the local Caffeine cache, and if a matching permission result is found, directly executes the corresponding operation; Cache miss handling: Call the access control policy matching unit to get the result, and synchronously update the local cache and Redis distributed cache; Execution permission: Allow access: The request is passed to the backend configuration service to perform the corresponding operation; Access Denied: Returns a denied message directly; Restricted access: Only grant permissions to certain fields, implemented through a field-level permission filtering component.
[0032] 4. Access behavior and access risk assessment result recording unit, used to record user access behavior and access risk assessment results; Behavior log generation: By intercepting user access operations through AOP aspects, the system records fields such as "user ID, role, access time, IP address, resource identifier, operation type, request parameters, response result, and risk score" to generate structured logs. Log delivery: Structured logs are delivered via Kafka. Data storage: Access behavior details: stored in InfluxDB, supporting queries by time range, user, resource, and other dimensions, suitable for real-time monitoring; Risk assessment results + key actions: stored in MySQL for permission auditing and historical tracing; Data archiving: Historical data exceeding 90 days is archived to MinIO object storage.
[0033] 5. Access Control Policy and Evaluation Model Update Unit: This unit adaptively updates access control policies and evaluation models to improve the accuracy and efficiency of access control. If the system detects abnormal or risky user access behavior, it will automatically adjust the access control policy and permission policy rule base to ensure system security and stability. Data collection: Historical access data is periodically extracted from MySQL / InfluxDB and used as a model training dataset; Model training: The risk assessment model is trained using SparkMLlib, with features including "access frequency, operation type distribution, IP location, access time distribution, resource sensitivity", etc., and the output is a risk prediction model. Online inference: Deploy the trained model to TensorFlowServing, and call the model in real time to calculate the risk score when the user accesses it, replacing the fixed weighted score; Policy adaptive update: When the model detects a new abnormal behavior pattern, it automatically generates a new policy rule and submits it to the administrator for review. After the review is approved, the policy version is upgraded (semantic version, such as v1.0.0→v1.1.0) and synchronized to the rule engine. The old version policy is retained for rollback. Model iteration: Offline retraining is performed every 7 days to optimize model parameters and improve the accuracy of risk identification.
[0034] 6. Access audit and monitoring unit, connected to the access behavior and access risk assessment result recording unit, is used to record users' anti-counterfeiting behavior and resource usage, and to perform access audit and access strategy optimization.
[0035] Real-time monitoring: Access behavior data is stored in InfluxDB. A monitoring dashboard can be configured through Grafana to display metrics such as "Top 10 users by access volume, high-risk access trends, number of permission denials, and statistics on access to sensitive resources". Filtering by time dimension is supported. Anomaly Alerts: Prometheus collects monitoring metrics, sets alert rules, and pushes alerts to DingTalk / email / SMS via Alertmanager when triggered; Audit Reports: Regularly generate audit reports, including "user access statistics, permission change records, risk event summaries, and policy execution effectiveness," and support exporting to PDF / Excel format; Security Analysis: Synchronize access logs to Elasticsearch, supporting full-text search (such as querying by IP, resource, or operation type), and combine with Kibana to generate security analysis dashboards to help identify potential security risks.
[0036] III. Building an Intelligent Audit Module In this embodiment, by building an intelligent auditing module and combining artificial intelligence and machine learning technologies, the system can automatically analyze, monitor, and audit the unified configuration and access process of microservice resources, promptly identify problems, and improve the reliability and stability of the system.
[0037] Specifically, the intelligent audit module includes: 1. First Data Collection Unit: Collects and integrates audit information from various microservices, including operation logs, event logs, performance data, etc. 2. Audit log recording unit, used to record and analyze all configuration change operations, including modification, deletion, addition and other operations; 3. Data analysis unit, used to automatically analyze and provide early warnings on configuration process data using machine learning algorithms and data mining techniques, and to identify anomalies or risk points; 4. Risk management and forecasting unit, used to predict future configuration risks and problems based on historical configuration data and analysis results; 5. Data visualization unit, which connects the data analysis unit, risk management and forecasting unit, is used to visualize the data analysis results and forecasting results in the form of charts, reports and other formats, so that management and technical personnel can understand the configuration status and audit results.
[0038] IV. Constructing an indicator monitoring service module In this embodiment, the purpose of constructing the indicator monitoring service module is to monitor and statistically analyze various indicators of the system, promptly identify configuration problems and take measures to ensure the normal operation of the system.
[0039] The indicator monitoring service module includes: 1. The second data collection unit is used to collect various performance metrics in the system, including CPU utilization, memory usage, disk space, network traffic, etc.; Multi-source data collection: Operation logs / event logs: Deployed on each microservice node via Filebeat, container logs (such as Docker logs) and application logs (Logback output) are collected in real time and uploaded in partitions; Performance data: Microservice performance metrics (response time, throughput, CPU / memory utilization) are collected via PrometheusExporter and pushed to Kafka on a regular basis; Configuration platform logs: Configuration operation logs are written directly to the specified Topic via the application's KafkaProducer; FlinkSQL consumes Kafka data, performing field alignment, missing value filling, and abnormal data filtering; Data storage: Cleaned structured data is written to the Hudi data lake, partitioned by "data type-date", supporting incremental updates and historical backtracking.
[0040] 2. Real-time monitoring unit: Used to monitor the performance metrics of all microservices in real time to promptly identify performance bottlenecks and potential problems; Change log collection: Intercepts all change operations (add / modify / delete) on the configuration platform through AOP aspects, recording core fields such as "operator, operation time, operation type, resource identifier, content before change, content after change, operation IP, and reason for change"; Real-time query scenario: Writes change logs to InfluxDB, partitioned by "resource_id + operation_type", supporting millisecond-level queries of the last 30 days of change records; Long-term traceability scenario: Synchronizes change logs to PostgreSQL, creates composite indexes, and supports multi-dimensional filtering and correlation analysis; Change analysis capability: Based on PostgreSQL's JSONB type support, it enables diff comparison of change content (such as extracting modified fields and new and old values) to assist in auditing and tracing.
[0041] 3. Historical data storage unit, used to store monitored performance metrics data in the database for long-term analysis and trend prediction; 4. Data Analysis and Trend Prediction Unit: This unit analyzes collected performance metrics data to identify system performance trends and potential problems. Data preprocessing includes extracting configuration process data (change records, access logs, performance data) from the Hudi data lake and performing feature engineering (such as normalization, feature encoding, and time window aggregation). It also uses Drools to define explicit anomaly rules for rapid identification of known risks. ML-based analysis employs the Isolation Forest algorithm to train an anomaly detection model and identify unknown risks. When the analysis results meet the warning threshold, a warning event is generated and pushed to the Kafka warning topic, triggering subsequent notification processes.
[0042] 5. Alarm Unit: Used to issue alarms for abnormal indicators based on preset alarm thresholds or conditions, so that timely measures can be taken to resolve the issues. Indicator Collection and Threshold Definition: Collect relevant indicators through Prometheus system / configure relevant indicators, and define multi-dimensional alarm thresholds based on business scenarios; Configure rules in Alertmanager according to alarm level, and associate indicator thresholds with trigger conditions; After an alarm is triggered, noise reduction logic is executed first (such as merging duplicate alarms and suppressing alarms during non-core periods), and then pushed to the corresponding channels according to the level; Record the alarm lifecycle, and automatically escalate high-level alarms that are not handled in time.
[0043] 6. The automated response unit is used to automatically adjust system resources based on monitored performance metrics, such as expanding or reducing the number of servers, optimizing configurations, etc., to improve system performance and stability; convert monitoring metrics into K8s custom metrics; automatically expand or shrink the number of servers based on preset rules, or call the configuration platform API to optimize configuration parameters; the adjustment operation is first executed in a gray-scale test on a portion of instances to monitor whether performance metrics improve, and automatically roll back if the target is not met; all automated adjustment behaviors are recorded in the audit log for easy traceability and rule optimization.
[0044] 7. The visualization unit is used to intuitively display real-time and historical data of system performance indicators through visualization tools such as charts and dashboards. Grafana integrates real-time indicators, time-series data, and audit / predictive data, providing a unified data query entry point; the dashboard is designed in layers according to "global overview → service dimensions → indicator dimensions", supporting multiple chart types (line chart, bar chart, pie chart, heatmap); clicking on abnormal data points in the chart allows you to drill down to detailed data and locate the cause.
[0045] In summary, as Figure 2 As shown in the figure, this embodiment provides a security management system based on unified configuration of microservice resources, including: A centralized external configuration support platform built outside of microservice modules is used to provide configuration support for each microservice and realize centralized management of microservice configuration; A permission policy rule base is used to manage user access permissions and resources to microservices; The intelligent auditing module connects to an external configuration support platform and permission policy rule base to monitor and audit the configuration and access processes of each microservice. The indicator monitoring service module connects to the external configuration support platform and the intelligent audit module to monitor and statistically analyze various indicators of the system.
[0046] For the process of implementing unified configuration of microservice resources using the security management system provided in this embodiment, please refer to [link / reference]. Figure 3 I will not go into details.
[0047] This application has the following beneficial technical effects: 1. Centralized external configuration support platform: By building a centralized external configuration support platform outside the microservice modules, the configuration of microservices can be managed in a unified manner, which improves the efficiency of configuration management.
[0048] 2. Permission Policy Rule Base: Provides configuration support for each microservice and establishes a permission policy rule base to manage user access permissions and resources, improving system security and controllability.
[0049] 3. Intelligent auditing and indicator monitoring: It integrates intelligent auditing modules and indicator monitoring services, and combines artificial intelligence and machine learning technologies to automatically analyze and predict system performance, thereby improving the accuracy and real-time performance of monitoring.
[0050] 4. Adaptive Monitoring and Adjustment Strategy: Implements adaptive monitoring and adjustment strategies to ensure secure management of microservice configurations. When performance issues or security risks are detected, the system can adjust strategies in real time to guarantee service stability and security.
[0051] Compared with existing technologies, the main innovation lies in: Highly integrated security solution: This patent integrates multiple security management functions (such as access control, intelligent auditing, and metrics monitoring) to provide a comprehensive and efficient security solution for microservice-based systems.
[0052] This application also applies artificial intelligence and machine learning technologies to intelligent auditing and indicator monitoring to automatically analyze and predict system performance, improving the accuracy and real-time performance of monitoring. It utilizes a four-layer architecture—data layer, feature layer, model layer, and application layer—to achieve intelligent auditing and indicator monitoring using AI / ML. The data layer integrates multi-source audit logs and performance indicators, which are cleaned and standardized using FlinkSQL and then stored in the Hudi data lake. The feature layer extracts three core features: time-series, behavioral, and correlation features, providing high-quality input for the model. The model layer employs a multi-model fusion system: intelligent auditing uses Isolation Forest, GNN graph anomaly detection, and LSTM+Attention to identify violations; indicator monitoring uses AE and LOF for real-time anomaly detection, Bi-LSTM and Prophet+XGBoost for short- and long-term performance prediction, and then optimizes decisions through weighted voting and reinforcement learning. The model is deployed via TensorFlow Serving, supporting high-concurrency, low-latency inference, and achieving adaptive optimization through incremental learning and periodic retraining. The application layer outputs audit reports, prediction results, and alarm responses, ultimately achieving an anomaly detection accuracy of over 92% and a streaming inference latency of ≤100ms, significantly improving monitoring accuracy and real-time performance.
[0053] This application also proposes an adaptive monitoring and adjustment strategy, enabling the system to adjust its strategy in real time when performance issues or security risks are detected, ensuring service stability and security. The data layer integrates and cleans multi-source data such as audit logs and performance metrics using FlinkSQL, storing it in the Hudi data lake; the feature layer extracts time-series, behavioral, and correlation features to provide input for the model. The model layer employs multi-model fusion: Isolation Forest, GNN, and LSTM+Attention are used for intelligent auditing; AE and LOF are used for real-time anomaly detection; Bi-LSTM, Prophet+XGBoost are used for performance prediction; and weighted voting and reinforcement learning are used to optimize decisions. The model is deployed via TensorFlowServing, supporting high-concurrency, low-latency inference, and outputting anomaly alerts and adjustment commands in real time, triggering automated responses such as resource scaling and configuration optimization. Simultaneously, incremental learning and periodic retraining enable model adaptation, ensuring that the strategy dynamically adapts to system changes, ultimately mitigating security risks and avoiding performance issues in real time, ensuring service stability and security.
[0054] Centralized External Configuration Support Platform: By building a centralized external configuration support platform outside of microservice modules, this patent improves the way microservice configuration management is managed and increases the efficiency of configuration management.
[0055] Possible future application scenarios: This patented approach can play a significant role in any system employing a microservices architecture, enhancing security and manageability. Here are some examples: Enterprise software and services: Enterprise software and services typically need to handle sensitive information and ensure high availability. This patented method can provide better security management and monitoring capabilities.
[0056] Internet of Things (IoT) and Industrial Internet: With the development of IoT and Industrial Internet, more and more devices and systems need to be connected. This patented method can ensure the security and manageability of these connections and services.
[0057] Cloud computing and cloud service providers: Cloud computing platforms typically need to provide services to multiple customers, and this patented method can help cloud service providers achieve efficient access control and resource allocation.
[0058] Financial industry: Banks, securities firms, insurance companies and other financial institutions have strict requirements for system security and data protection. This patented method can improve the security management of microservice configuration and reduce security risks.
[0059] E-commerce and online retail: Large e-commerce platforms and online retailers need to handle large amounts of user data and sensitive information. The security management method provided by this patent can ensure data security and system stability.
[0060] It should be stated that the above-described specific embodiments are merely preferred embodiments and technical principles applied in this application. Those skilled in the art should understand that various modifications, equivalent substitutions, and variations can be made to this application. However, such variations, as long as they do not depart from the spirit of this application, should be within the scope of protection of this application. Furthermore, some terminology used in this application's specification and claims is not limiting but merely for ease of description.
Claims
1. A security management system based on unified configuration of microservice resources, characterized in that, include: A centralized external configuration support platform built outside of microservice modules is used to provide configuration support for each microservice and realize centralized management of microservice configuration; A permission policy rule base is used to manage user access permissions and resources to microservices; The intelligent auditing module connects the external configuration support platform and the permission policy rule base to monitor and audit the configuration and access process of each microservice. The indicator monitoring service module connects the external configuration support platform and the intelligent audit module, and is used to monitor and statistically analyze various indicators of the system.
2. The security management system based on unified configuration of microservice resources according to claim 1, characterized in that, The external configuration support platform includes: The storage unit is used to store the configuration information of all microservices; A configuration management unit, connected to the storage unit, is used to provide users with the ability to add, delete, and modify configuration information. A configuration version management unit is connected to the storage unit and is used to manage each configuration version and support users to roll back to a historical configuration version. A configuration information push unit, connected to the storage unit and the configuration version management unit, is used to detect whether the configuration version or configuration information has changed, and when a change occurs, push the updated configuration information to the corresponding microservice. The registration and configuration information acquisition unit, connected to the storage unit, is used to determine whether the microservice is registered on the configuration platform when the microservice starts, and automatically register with the configuration platform and obtain configuration information that matches itself when it is determined that the microservice is not registered. The configuration information creation module is connected to the storage unit and is used to provide users with the ability to create or update configuration information and store it in the storage unit.
3. A security management system based on unified configuration of microservice resources according to claim 1, characterized in that, The permission policy rule base includes: The access control policy matching unit is used to match the corresponding access control policy based on user information. An access risk assessment and access control policy dynamic adjustment unit is connected to the access control policy matching unit and is used to assess access risks based on user behavior and dynamically adjust access control policies based on the risk assessment results. The access behavior and access risk assessment result recording unit is connected to the access risk assessment and access control policy dynamic adjustment unit and is used to record the user's access behavior and access risk assessment results. The access control policy and evaluation model update unit, connected to the access behavior and access risk assessment result recording unit, is used to adaptively update the access control policy and evaluation model based on user access behavior and access risk assessment results. The access audit and monitoring unit connects to the access behavior and access risk assessment result recording unit, which is used to record users' anti-counterfeiting behavior and resource usage, and to perform access audit and access strategy optimization.
4. A security management system based on unified configuration of microservice resources according to claim 1, characterized in that, The intelligent audit module includes: The first data collection unit is used to collect and integrate audit information from various microservices; An audit log recording unit, connected to the data collection unit, is used to record all configuration change operations as configuration process data. The data analysis unit, connected to the audit log recording unit, is used to automatically analyze and issue early warnings on configuration process data, and identify anomalies or risk points. The risk management and prediction unit, connected to the data analysis unit and / or the audit log recording unit, is used to predict future configuration risks based on historical configuration data and / or data analysis results. The data visualization unit, connected to the data analysis unit and the risk management and prediction unit, is used to visualize the data analysis results and prediction results.
5. A security management system based on unified configuration of microservice resources according to claim 1, characterized in that, The indicator monitoring service module includes: The second data collection unit is used to collect various performance indicators of the system; The real-time monitoring unit is connected to the second data collection unit and is used to monitor the changes in performance metrics caused by each microservice in real time. The historical data storage unit is connected to the second data collection unit and is used to store the monitored performance metrics data into the database; The data analysis and trend prediction unit is connected to the historical data storage unit and is used to analyze the collected performance index data to identify the system's performance trends and potential problems. An alarm unit, connected to the data analysis and trend prediction unit, is used to issue alarms for abnormal indicators based on preset alarm thresholds or alarm conditions. An automated response unit, connected to the real-time monitoring unit, is used to automatically adjust system resources based on monitored performance indicators; The visualization unit connects the real-time monitoring unit and the historical data storage unit, and is used to visualize the real-time and historical data of system performance indicators.