Component-based network resilience evaluation method and device, electronic equipment and medium
By obtaining resilience assessment instructions, identifying the sub-services and components of the business system, and calculating weights and scores, the network resilience assessment of the business system is realized, solving the problem of inaccurate assessment results in existing technologies and improving the accuracy and efficiency of the assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- PURPLE MOUNTAIN LAB
- Filing Date
- 2026-01-16
- Publication Date
- 2026-06-02
AI Technical Summary
Existing technologies for assessing the network resilience of business systems only evaluate the business itself in isolation, without considering the operational relationships between components, leading to inaccurate assessment results.
By obtaining resilience assessment instructions, the sub-businesses included in the business system and their dependent components are identified. Component weights, sub-business logic processing module weights, and business weights are calculated using network resilience indicators and historical operating data. Combined with component scores and logic processing scores, a comprehensive network resilience assessment is conducted.
It improves the accuracy and comprehensiveness of network resilience assessment, enabling it to more accurately reflect the actual impact of component failures on services and enhance assessment efficiency.
Smart Images

Figure CN122137760A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of network security and information technology, and in particular to a component-based network resilience assessment method, apparatus, electronic device, and medium. Background Technology
[0002] As digital transformation progresses, business systems increasingly rely on multi-layered common components. Docker (a platform designed to help developers build, share, and run modern applications) / Kernel-based Virtual Machine (KVM) provides virtualization support, databases store core business data, and nginx (a lightweight server), tomcat (an open-source application server), and apache (an open-source web server) serve as the delivery and runtime carriers for applications. Failures in these components can directly lead to upper-layer business interruptions (e.g., Docker container crashes causing e-commerce transaction failures, database outages leading to data loss in government systems). Therefore, assessing the network resilience of business systems is particularly important.
[0003] Currently, in existing technologies, the resilience assessment of business systems is usually conducted in isolation, without considering the operational relationships between components. This fails to accurately reflect the actual impact of component failures on the business, resulting in inaccurate assessment results for the network resilience of business systems.
[0004] Therefore, there is an urgent need for a component-based network resilience assessment method to improve the comprehensiveness and accuracy of the assessment. Summary of the Invention
[0005] This invention provides a component-based network resilience assessment method, apparatus, electronic device, and medium to address the shortcomings of existing technologies that only assess services in isolation, failing to consider the operational relationships between components. This results in inaccurate assessments of network resilience of service systems due to the inability to accurately reflect the actual impact of component failures on services. The invention achieves this by obtaining resilience assessment instructions; wherein the resilience assessment instructions include service identifiers; determining at least one sub-service contained in the service system corresponding to the service identifier, and at least one component that each sub-service depends on; obtaining at least one network resilience index; and determining the component weight of each component and the component weight of each sub-service based on the network resilience index and the historical operational data of the service system within a historical time period. The system assesses the network resilience of the business system by determining the logical processing weights of the business logic processing modules for each sub-business and the business weights of each sub-business. Based on the performance of each component during the evaluation process, the system obtains the component score and the logical processing score of each business logic processing module. Finally, based on these scores, the system determines the network resilience assessment of the business system, improving the accuracy, comprehensiveness, and efficiency of the assessment.
[0006] This invention provides a component-based network resilience assessment method, comprising the following steps.
[0007] Obtain the elasticity assessment instruction; the elasticity assessment instruction includes a business identifier; Based on the resilience assessment instructions, determine at least one sub-business contained in the business system corresponding to the business identifier, and at least one component that each sub-business depends on. Obtain at least one network resilience indicator, and based on each network resilience indicator and the historical operating data of the business system within a historical time period, determine the component weight of each component, the logic processing weight of the business logic processing module of each sub-business, and the business weight of each sub-business. Based on the performance of each component during the evaluation process, obtain the component score for each component, and based on the performance of the business logic processing module of each sub-business during the evaluation process, obtain the logic processing score for each business logic processing module. Based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-business, the business weights of each sub-business, the component scores of each component, and the logic processing scores of each business logic processing module, the network resilience of the business system is assessed, and the network resilience assessment results of the business system are obtained.
[0008] According to a component-based network resilience assessment method provided by the present invention, based on various network resilience indicators and historical operational data of the business system within a historical time period, the method determines the component weight of each component, the logic processing weight of the business logic processing module of each sub-service, and the business weight of each sub-service, including: The degree of component dependency, the degree of business importance, and the business priority are determined based on the network resilience indicators and the historical operation data of the business system within the historical time period. The component weights of each component under the network resilience index are determined based on the degree of component dependency and business importance. The logical processing weights of the business logic processing modules for each sub-business are determined based on their importance. Based on the business priority of each sub-service and each network elasticity index, determine the business weight of each sub-service under each network elasticity index.
[0009] According to a component-based network resilience assessment method provided by the present invention, the component weights of each component under the network resilience index are determined based on the component dependency degree and business importance, including: For each component of each sub-business, the component failure impact coefficient is determined based on the component dependency of the corresponding sub-business on the component and the business importance of the sub-business in the business system. Based on the component failure impact coefficient and various network resilience indicators, the component weight of each component under each network resilience indicator is determined.
[0010] According to a component-based network resilience assessment method provided by the present invention, the component failure impact coefficient of a component is determined based on the component dependency of the sub-services corresponding to the component and the service importance of the sub-services in the service system, including: The component failure impact coefficient is determined by multiplying the component dependency of the corresponding sub-business on the component with the business importance of the sub-business in the business system.
[0011] According to a component-based network resilience assessment method provided by the present invention, the logical processing weights of the business logic processing modules of each sub-service are determined based on the importance of the service, including: For each sub-business, the impact coefficient of logic processing failure of the business logic processing module of the sub-business is determined based on the business importance of the sub-business in the business system; Based on the logic processing failure impact coefficient of the business logic processing module and various network resilience indicators, the logic processing weight of the business logic processing module under each network resilience indicator is determined.
[0012] According to a component-based network resilience assessment method provided by the present invention, the network resilience of a business system is assessed based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, to obtain the network resilience assessment result of the business system, including: Based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-business, the business weights of each sub-business, the component scores of each component, and the logic processing scores of each business logic processing module, the network resilience of the business system is evaluated to obtain the network resilience evaluation index score. The network resilience assessment results of the business system are determined based on the network resilience assessment index scores and the importance of the business.
[0013] According to a component-based network resilience assessment method provided by the present invention, the network resilience assessment result of a business system is determined based on network resilience assessment index scores and business importance, including: The network resilience assessment result of the business system is determined by multiplying the network resilience assessment index score by the business importance.
[0014] The present invention also provides a component-based network resilience assessment device, comprising the following modules: The instruction acquisition module is used to acquire elasticity assessment instructions; the elasticity assessment instructions include a business identifier. The component determination module is used to determine, based on the elasticity assessment instructions, at least one sub-business contained in the business system corresponding to the business identifier, and at least one component that each sub-business depends on. The weight determination module is used to obtain at least one network resilience indicator and, based on each network resilience indicator and the historical operating data of the business system within a historical time period, determine the component weight of each component, the logic processing weight of the business logic processing module of each sub-business, and the business weight of each sub-business. The scoring module is used to obtain the component score of each component based on the operation of each component during the evaluation process, and to obtain the logic processing score of each business logic processing module based on the operation of each sub-business's business logic processing module during the evaluation process. The resilience assessment module is used to assess the network resilience of the business system based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-business, the business weights of each sub-business, the component scores of each component, and the logic processing scores of each business logic processing module, and to obtain the network resilience assessment results of the business system.
[0015] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement any of the component-based network resilience assessment methods described above.
[0016] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the component-based network resilience assessment methods described above.
[0017] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the component-based network resilience assessment methods described above.
[0018] This invention provides a component-based network resilience assessment method, apparatus, electronic device, and medium. The method involves: acquiring a resilience assessment instruction, which includes a service identifier; determining, based on the resilience assessment instruction, at least one sub-service contained in the service system corresponding to the service identifier, and at least one component upon which each sub-service depends; acquiring at least one network resilience index; and determining, based on each network resilience index and historical operating data of the service system within a historical time period, the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, and the service weight of each sub-service; acquiring the component score of each component based on its operating status during the assessment process, and acquiring the logical processing score of each business logic processing module based on its operating status during the assessment process; and performing a network resilience assessment of the service system based on the component weights of each component, the logical processing weights of the business logic processing modules of each sub-service, the service weights of each sub-service, the component scores of each component, and the logical processing scores of each business logic processing module, to obtain the network resilience assessment result of the service system. The technical solution of this invention addresses the shortcomings of existing technologies that only assess services in isolation, failing to consider the operational relationships between components. This results in inaccurate assessments of network resilience of business systems due to the inability to accurately reflect the actual impact of component failures on services. The invention achieves the following: obtaining resilience assessment instructions; wherein the resilience assessment instructions include a service identifier; determining at least one sub-service within the business system corresponding to the service identifier, and at least one component upon which each sub-service depends; obtaining at least one network resilience indicator; and determining the component weight of each component and the business logic processing module of each sub-service based on each network resilience indicator and historical operational data of the business system within a historical time period. The system calculates the logical processing weights and business weights of each sub-business; it obtains component scores for each component based on their performance during the evaluation process, and logical processing scores for each business logic processing module based on their performance during the evaluation process; based on the component weights, logical processing weights, business weights, component scores, and logical processing scores of each business logic processing module, it conducts a network resilience assessment of the business system, obtains the network resilience assessment results, and determines the network resilience evaluation of the business system based on the network resilience assessment results, thereby improving the accuracy, comprehensiveness, and efficiency of the evaluation. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0020] Figure 1 This is a flowchart illustrating the component-based network resilience assessment method provided by the present invention.
[0021] Figure 2 This is a schematic diagram of the component-based network resilience assessment device provided by the present invention.
[0022] Figure 3 This is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0024] The following is combined Figure 1 The present invention describes a component-based network resilience assessment method. This method is applicable to network resilience assessment scenarios. The execution subject of this method can be an electronic device or a component-based network resilience assessment device installed in the electronic device. The component-based network resilience assessment device can be implemented by software, hardware, or a combination of both. Figure 1 This is a flowchart illustrating the component-based network resilience assessment method provided by the present invention, as shown below. Figure 1 As shown, the method includes the following steps 101, 102, 103, 104 and 105.
[0025] Step 101: Obtain the elasticity assessment instruction; wherein, the elasticity assessment instruction includes the business identifier.
[0026] In this step, the resilience assessment instruction may be, for example, an instruction determined when a resilience assessment is required in the event that the business system has been attacked, or an instruction determined when a periodic resilience assessment is conducted on the network resilience of the business system, or an instruction determined when a resilience assessment is required when the business system receives a certain request. This embodiment does not limit this.
[0027] A business identifier refers to the identifier of a business system. A business system includes at least one sub-business, and each sub-business depends on at least one component. For example, when the business system is an e-commerce business system, the e-commerce business system may include sub-businesses such as payment business, product browsing, order management, and user login. The at least one component that the sub-business depends on may be, for example, MySQL (an open-source relational database management system), Tomcat (an open-source, lightweight application server), KVM (a kernel virtual machine), Nginx (a high-performance server), Docker (an open-source application container engine), etc. This embodiment does not limit this.
[0028] Specifically, obtain the elasticity assessment instruction, which includes the business identifier.
[0029] Step 102: Determine, according to the elasticity assessment instructions, at least one sub-business contained in the business system corresponding to the business identifier, and at least one component on which each sub-business depends.
[0030] Specifically, after obtaining the elasticity assessment metrics, the business metrics included in the elasticity assessment metrics are used to determine at least one sub-business contained in the business system corresponding to the business identifier, as well as at least one component that each sub-business depends on.
[0031] For example, for a sub-business, the components that the sub-business depends on can be a component chain, such as ginx (request forwarding) → tomcat (application processing) → MySQL (order data storage) → Docker (container hosting) → KVM (virtual machine hosting - optional). This embodiment does not limit this.
[0032] Step 103: Obtain at least one network resilience indicator, and based on each network resilience indicator and the historical operating data of the business system within the historical time period, determine the component weight of each component, the logic processing weight of the business logic processing module of each sub-business, and the business weight of each sub-business.
[0033] In this step, network resilience metrics refer to the dimensions used to assess the network resilience of business systems.
[0034] Historical operational data refers to the operational data of a business system during a historical period. Component weights are weights allocated to the component layers of a business system based on the component's influence coefficient. Component weights are related to the influence coefficient; for example, a higher influence coefficient results in a higher component weight. Logic processing weights characterize the normal operation of business logic processing modules during operation. Business weights are weights obtained by allocating weights to sub-businesses according to their priorities. For a network resilience indicator, different business systems have different business priorities, leading to different sub-system business weights allocated to each business system. This embodiment does not impose limitations on this.
[0035] Specifically, when assessing the network resilience of a business system, the specific dimensions to be evaluated are mainly determined based on network resilience indicators. For example, when a business system faces a known attack, network resilience indicators might include the degree of degradation in the functionality and performance of critical functionalities, the extent to which expected baseline services are achieved, and the smoothness of the service degradation. After a business system faces a known attack and critical functionalities are compromised, network resilience indicators might include the degree of service recovery and the recovery time. The degree of service recovery includes both the degree of service function recovery and the degree of service performance recovery; this embodiment does not limit the specifics of these.
[0036] Specifically, after obtaining at least one network resilience metric, for each network resilience metric, based on the historical operating data of the business system within a historical time period, the component weight of each component, the logical processing weight of the business logic processing module of each sub-business, and the business weight of each sub-business are determined under the network resilience metric.
[0037] Step 104: Based on the performance of each component during the evaluation process, obtain the component score for each component, and based on the performance of the business logic processing module of each sub-business during the evaluation process, obtain the logic processing score for each business logic processing module.
[0038] In this step, the component score is used to characterize the health status of the component during operation; the logic processing score is used to characterize the normal operation status of the business logic processing module during operation, and this embodiment does not limit this.
[0039] Specifically, the operational status of each component during the evaluation process is determined. Based on the operational status of each component during the evaluation process, the health status of each component during operation under each network resilience index is determined, thereby obtaining the component score of each component under each network resilience index. The component scores of each component under different network resilience indices may be the same or different, and this embodiment does not limit this.
[0040] Specifically, the operational status of the business logic processing modules of each sub-business during the evaluation process is determined, and based on the operational status of the business logic processing modules of each sub-business during the evaluation process, the logic processing score of each business logic processing module under each network resilience index is determined.
[0041] Step 105: Based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-business, the business weights of each sub-business, the component scores of each component, and the logic processing scores of each business logic processing module, conduct a network resilience assessment of the business system to obtain the network resilience assessment results of the business system.
[0042] Specifically, after determining the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, the product of the component weights of each component, the business weights of each sub-service, and the component scores of each component, as well as the product of the logic processing scores of each business logic processing module and the logic processing weights of each business logic processing module, is summed to determine the index score under the network resilience index. Then, the index score is multiplied by the business importance of the sub-service in the business system to achieve network resilience assessment of the business system and obtain the network resilience assessment result of the business system.
[0043] In summary, the advantage of this technical solution lies in its ability to construct a mapping between components in the business system (such as Docker, KVM, databases, nginx, tomcat, apache, etc.) and upper-layer business applications, thereby achieving a comprehensive and accurate assessment of the network resilience of the business system. This solves the problems of common components being separated from business operations, having a single dimension, and insufficient accuracy in existing assessment methods. It improves the scientific rigor and practicality of network resilience assessment and can be widely applied to network resilience assessment of various business systems containing multi-level components.
[0044] In one specific embodiment, the network resilience assessment results of the business system can be divided into business resilience levels, including a first basic level, a second robust level, a third enhanced level, and a fourth adaptive level. This embodiment does not limit this.
[0045] In this step, the first base level can be, for example, 0-59 points, the second robust level can be, for example, 60-74 points, the third enhancement level can be, for example, 75-89 points, and the fourth adaptive level can be, for example, 90-100 points. This embodiment does not limit these.
[0046] Specifically, determine which business resilience level the network resilience assessment result belongs to. When the network resilience assessment result belongs to the first basic level, the resilience characteristics of the business system are characterized as follows: weak anti-interference capability, lack of redundancy design in common components, only able to cope with single, simple failures (such as short-term offline of a single node), requiring manual intervention for recovery after a failure, and long recovery time (greater than 2 hours); the business impact of the business system is characterized as interruption of non-core business, significant functional degradation of core business (such as payment success rate dropping below 70%), and no clear business continuity plan; the core capabilities of the business system are characterized as having basic fault detection capabilities, lacking an automatic recovery mechanism, and not clarifying the relationship between components and business.
[0047] When the network resilience assessment result is at the second robustness level, the resilience characteristics of the business system are defined as follows: it can cope with common failures (such as database master-slave switching, container restart), key components (such as MySQL, Redis) have basic redundancy, failure recovery relies on semi-automatic tools, and recovery time is moderate (30 minutes to 2 hours); the business impact of the business system is defined as the temporary degradation of non-core business (such as product recommendation delay), the core business functions are basically maintained (such as payment success rate greater than or equal to 90%), and there is a simple business continuity plan; the core capabilities of the business system are defined as the redundant deployment of key components, the ability to automatically detect and partially automatically recover from failures, and the identification of the dependencies between core components and business.
[0048] When the network resilience assessment result is at the third enhanced level, the resilience characteristics of the business system are defined as follows: it can withstand complex interference (such as cluster node failure, network partition), all common components have redundant architecture (such as Docker cluster, Kafka multiple replicas), and it can automatically recover within 15-30 minutes after a failure, with the recovery process transparent to users; the business impact of the business system is defined as non-core business being unaffected by degradation, core business being uninterrupted (such as a payment success rate greater than or equal to 99.9%), having a complete business continuity plan and conducting regular drills; the core capabilities of the business system are defined as end-to-end redundancy design, automatic failover and business switching, and the ability to optimize resilience strategies based on historical data (such as adjusting the Redis cluster size according to the failure frequency).
[0049] When the network resilience assessment result is at the fourth adaptive level, the resilience characteristics of the business system are defined as follows: it can withstand sudden and new types of interference (such as attacks from unknown vulnerabilities or large-scale traffic surges); common components have dynamic scaling and self-healing capabilities; the fault recovery time is less than 15 minutes; and it can autonomously optimize the recovery path. The business impact of the business system is defined as follows: neither core nor non-core businesses are aware of it; service availability is greater than or equal to 99.99%; and the business continuity plan can dynamically adapt to new scenarios. The core capabilities of the business system are defined as follows: it has an intelligent decision-making system that can predict potential faults and avoid them in advance (such as scaling containers based on load trends); and it can learn from faults and iterate its resilience mechanism (such as automatically updating component security policies).
[0050] The advantage of this setup is that by classifying the network resilience assessment results of the business system into business resilience levels, users can clearly understand the level of the network resilience assessment results of the business system, thus improving the user experience.
[0051] In one specific embodiment, based on various network resilience indicators and historical operating data of the business system within a historical time period, the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, and the business weight of each sub-service are determined. This includes: determining the component dependency, business importance, and business priority based on various network resilience indicators and historical operating data of the business system within a historical time period; determining the component weight of each component under the network resilience indicators based on the component dependency and business importance; determining the logical processing weight of the business logic processing module of each sub-service based on the business importance; and determining the business weight of each sub-service under each network resilience indicator based on the business priority of each sub-service and various network resilience indicators.
[0052] In this step, component dependency degree represents the degree of dependence of each component on each sub-business based on the sub-business corresponding to the component; business importance degree represents the importance of the sub-business in the business system; business priority represents the priority of each sub-business.
[0053] In this step, the importance and priority of business operations may not be the same in different business systems, and this embodiment does not impose any limitations on this.
[0054] Specifically, for each network resilience metric, the component dependency, business importance, and business priority are determined based on the historical operational data of the business system within a historical time period. Then, the component weight of each component under the network resilience metric is determined according to the component dependency and business importance; the logic processing weight of the business logic processing module of each sub-business is determined according to the business importance; and the business weight of each sub-business under each network resilience metric is determined based on the business priority of each sub-business and each network resilience metric.
[0055] For example, the business weights of each sub-business are as follows: for example, the sub-businesses include payment business, product browsing, order management and user login. The business weights of each sub-business are payment business (0.4), product browsing (0.2), order management (0.3) and user login (0.1), respectively. The sum of the business weights of all sub-businesses is 1. This embodiment does not limit this.
[0056] The weight of the business logic processing module can be, for example, 0.6. The weight of the components can be, for example, MySQL, Tomcat, KVM, Nginx, and Docker. The weight of the components can be, for example, MySQL (0.1), Tomcat (0.05), KVM (0.05), Nginx (0.05), and Docker (0.1). The weight of the components is related to the influence coefficient of the components. For example, the larger the influence coefficient, the higher the weight of the components. This embodiment does not limit this.
[0057] The advantage of this setup is that the determination of business weights is mainly based on the degree of component dependency, the importance of the business, and the priority of the business. For a given indicator, the business priorities of different business systems are different, which leads to different business weights assigned to each business system. By determining the business weights of each sub-business under each network elasticity indicator separately, the accuracy of the business weights of each sub-business is improved.
[0058] In one specific embodiment, the combined weight is the product of the component weight and the business weight. For example, the combined weight of MySQL for the payment business can be 0.1 × 0.4 = 0.04, and the combined weight of the business logic processing module for the payment business can be 0.7 × 0.4 = 0.28. This embodiment does not limit this.
[0059] In one specific embodiment, the component weight of each component under the network resilience index is determined based on the component dependency degree and the business importance, including: for each component of each sub-service, the component failure impact coefficient of the component is determined based on the component dependency degree of the corresponding sub-service to the component and the business importance of the sub-service in the business system; and the component weight of the component under each network resilience index is determined based on the component failure impact coefficient of the component and each network resilience index.
[0060] In this step, component dependency is the foundation for assessing the network resilience of the business system. Component dependency is a key indicator used to measure the vulnerability and network greed of the business system; specifically, it represents how much a component depends on the business system. Business importance refers to the degree of importance of a sub-business within the business system.
[0061] Specifically, for each component of each sub-business, the component failure impact coefficient of the component is determined based on the product of the component dependency degree of the corresponding sub-business on the component and the business importance of the sub-business in the business system; based on the component failure impact coefficient of the component and each network resilience index, the component weight of the component under each network resilience index is determined.
[0062] For example, taking an e-commerce business system as an example (including components such as Docker, KVM, MySQL, nginx, and tomcat), the dependencies between components in the business system can be, for example, nginx (reverse proxy) → tomcat in a Docker container (running the e-commerce application) → MySQL (order database) → KVM (hosting the database server). The component failure impact coefficient can be, for example, MySQL (0.9) > tomcat (0.7) > KVM (0.6) > nginx (0.4) (based on historical data, MySQL failure has the highest probability of causing payment failure), but this embodiment does not limit this.
[0063] The advantage of this setting is that the weights of components are allocated according to their failure impact coefficients; the higher the failure impact coefficient, the higher the component weight.
[0064] In one specific embodiment, the component failure impact coefficient of a component is determined based on the component dependency degree of the sub-business corresponding to the component and the business importance of the sub-business in the business system. This includes determining the component failure impact coefficient of the component based on the product of the component dependency degree of the sub-business corresponding to the component and the business importance of the sub-business in the business system.
[0065] Specifically, the component failure impact coefficient Q=MN, where M represents the component dependency and N represents the business importance.
[0066] For example, the component failure impact coefficient can be determined as follows: when the business system is an e-commerce system and the sub-business is the payment business in the e-commerce system, if the component dependency of the payment business on the component is 90% and the business importance of the payment business in the e-commerce system is 60%, then the component failure impact coefficient of the component is determined to be 0.9 × 0.6 = 0.54. This embodiment does not limit this.
[0067] The advantage of this setup is that it determines the component failure impact coefficient, and quantifies the dependency relationship between the component and sub-business through the component failure impact coefficient.
[0068] In one specific embodiment, the logical processing weight of the business logic processing module of each sub-service is determined according to the importance of the service, including: for each sub-service, determining the logical processing failure impact coefficient of the business logic processing module of the sub-service based on the importance of the sub-service in the business system; and determining the logical processing weight of the business logic processing module under each network resilience index based on the logical processing failure impact coefficient of the business logic processing module and each network resilience index.
[0069] Specifically, for each sub-business, based on the importance of the sub-business in the business system, the logic processing failure impact coefficient of the business logic processing module of the sub-business is determined; based on the logic processing failure impact coefficient of the business logic processing module and each network resilience index, the logic processing weight of the business logic processing module under each network resilience index is determined.
[0070] The advantage of this setup is that, for the business logic processing modules of sub-businesses in the business system, the logical processing weights are allocated according to the logical processing failure impact coefficient, thereby improving the accuracy of subsequent network resilience assessments of the business system.
[0071] In one specific embodiment, the network resilience of the business system is assessed based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, to obtain the network resilience assessment result of the business system. This includes: assessing the network resilience of the business system based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, to obtain the network resilience assessment index score.
[0072] Specifically, network resilience assessment index score , Representation Component Component scores, Representation Component Component weights, Sub-business Business weight, Sub-business The corresponding business logic processing module's business logic processing score. Sub-business The corresponding business logic processing weights of the business logic processing modules This indicates the total number of components in the component. This indicates the total number of business transactions for each sub-business.
[0073] For example, when there is at least one network resilience indicator, the sum of the network resilience evaluation index scores obtained under all network resilience indicators is out of 100 points. This embodiment does not limit this.
[0074] For example, assuming that in the payment business, the component scores could be Docker (60 points), Tomcat (70 points), MySQL (85 points), Nginx (90 points), and KVM (80 points); the business logic processing module scores could be: payment business (68 points), product browsing (90 points), order management (75 points), and user login (85 points); then the network elasticity assessment index score = payment business index score + product browsing index score + order management index score + user login index score; the payment business index score is (60×0.1×0.4+70×0.1×0.4+85×0.1×0.4+90×0.05×0.4+80×0.05×0.4)+(68×0.6×0.4), this embodiment does not limit this.
[0075] The advantage of this setup is that, after determining the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, the network resilience assessment index scores can be used to determine the optimal network resilience assessment index scores. Calculations are performed to determine the network resilience assessment index score for the business system. The network resilience assessment index score is used to subsequently measure the network resilience assessment of the business system in conjunction with the importance of the business.
[0076] In one specific embodiment, determining the network resilience assessment result of a business system based on the network resilience assessment index score and the importance of the business includes: determining the network resilience assessment result of the business system based on the product of the network resilience assessment index score and the importance of the business.
[0077] Specifically, network resilience assessment results , This refers to the network resilience assessment indicators. The network resilience of the business system is assessed, and the network resilience assessment index score is obtained. This refers to the network resilience assessment indicators. The importance of a sub-business within the business system.
[0078] The advantage of this setup is that by finely distinguishing the components in the evaluation object (such as Docker, KVM, database, nginx, tomcat, apache, etc.), it constructs a mapping between components and upper-layer sub-business applications. Combined with the Analytic Hierarchy Process (AHP), it builds a multi-dimensional evaluation index system. The target layer in AHP specifically determines what needs to be done, such as conducting a network resilience assessment of the business system. The network resilience index layer in AHP determines the dimensions from which the network resilience of the business system is assessed and determines the network resilience index. The quasi-side layer in AHP determines how to specifically assess it. By determining the scores and weights of components at the component layer and the business scores and weights of sub-businesses at the business layer, it achieves a comprehensive and accurate assessment of the network resilience of the business system. This solves the problems of common components being separated from business, having a single dimension, and insufficient accuracy in existing evaluation methods, improving the scientific rigor and practicality of business system resilience assessment. It can be widely applied to the resilience assessment of various business systems containing multi-level components.
[0079] In a specific implementation, for the network resilience assessment of components, the network resilience assessment scenario could be that a Docker container (carrying an upper-layer service x) suffers a known attack → the upper-layer service x is interrupted. The test steps include: (1) Recording the number of original key function points under the service and the number of Docker containers where they are located. If one key function point corresponds to multiple Docker container replicas, then only one key function point is recorded. (2) Triggering a known attack based on the known attack script provided in the known attack type list (if it is a continuous attack, then it lasts for 5 minutes). (3) Attempting to stop or tamper with the key function points under the service in the Docker container (or directly operating the service). (4) Attempting to stop / delete the Docker container where the service is located (if it is a Docker container escape, obtain the host machine's permissions). (5) Continuously launching the attack for a total of 3 times (every 5 minutes), recording 3-4 results each time (recording the current number of key function points and the number of Docker containers where they are located), and then stopping the attack. (6) Before the attack, record the original CPU usage and memory usage of the Docker container where the business is located. ① Execute docker stats --no-stream[Docker container name / ID] on the host machine to record the CPU usage and memory usage. ② Test continuously for 3 times. Every 5 minutes, calculate the original CPU usage and memory usage of the Docker container and take the average value. (7) Trigger a known attack based on the known attack script provided in the known attack type list (if it is a continuous attack, it will last for 5 minutes). Record the current CPU usage and memory usage of the Docker container where the business is located. Continue for 3 times and then stop the attack. The expected result can be that in step (5), record the number of current key function points and the number of Docker containers where the current key function points are located. Calculate the degree of functional decline according to the following description, such as (1) (current number of key function points / original number of key function points) * 100%. (2) (current number of Docker containers where the business is located / original number of Docker containers where the business is located) * 100%. In step (7), the original CPU usage and original memory usage are recorded. In step (8), the current CPU usage and current memory usage of the Docker container where the service is located are recorded, and the performance degradation is calculated according to the following descriptions: (1) (Current CPU usage - Original CPU usage) / Original CPU usage. (2) (Current memory usage - Original memory usage) / Original memory usage; Draw a line graph to show the smoothness of the functional and performance degradation; the smaller the value of the functional degradation, the higher the degradation; the larger the value of the performance degradation, the higher the degradation; this embodiment does not limit this.
[0080] This invention provides a component-based network resilience assessment method, which involves: acquiring a resilience assessment instruction, wherein the resilience assessment instruction includes a service identifier; determining, based on the resilience assessment instruction, at least one sub-service contained in the business system corresponding to the service identifier, and at least one component on which each sub-service depends; acquiring at least one network resilience indicator, and determining, based on each network resilience indicator and historical operating data of the business system within a historical time period, the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, and the business weight of each sub-service; acquiring, based on the operating status of each component during the assessment process, the component score of each component, and acquiring, based on the operating status of the business logic processing module of each sub-service during the assessment process, the logical processing score of each business logic processing module; and performing a network resilience assessment on the business system based on the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, the business weight of each sub-service, the component score of each component, and the logical processing score of each business logic processing module, to obtain the network resilience assessment result of the business system. The technical solution of this invention addresses the shortcomings of existing technologies that only assess services in isolation, failing to consider the operational relationships between components. This results in inaccurate assessments of network resilience of business systems due to the inability to accurately reflect the actual impact of component failures on services. The invention achieves the following: obtaining resilience assessment instructions; wherein the resilience assessment instructions include a service identifier; determining at least one sub-service within the business system corresponding to the service identifier, and at least one component upon which each sub-service depends; obtaining at least one network resilience indicator; and determining the component weight of each component and the business logic processing module of each sub-service based on each network resilience indicator and historical operational data of the business system within a historical time period. The system calculates the logical processing weights and business weights of each sub-business; it obtains component scores for each component based on their performance during the evaluation process, and logical processing scores for each business logic processing module based on their performance during the evaluation process; based on the component weights, logical processing weights, business weights, component scores, and logical processing scores of each business logic processing module, it conducts a network resilience assessment of the business system, obtains the network resilience assessment results, and determines the network resilience evaluation of the business system based on the network resilience assessment results, thereby improving the accuracy, comprehensiveness, and efficiency of the evaluation.
[0081] The component-based network resilience assessment device provided by the present invention is described below. The component-based network resilience assessment device described below and the component-based network resilience assessment method described above can be referred to in correspondence.
[0082] Figure 2 This is a schematic diagram of the component-based network resilience assessment device provided by the present invention, with reference to... Figure 2 As shown, the component-based network resilience assessment device 200 includes: an instruction acquisition module 201, a component determination module 202, a weight determination module 203, a score acquisition module 204, and a resilience assessment module 205; wherein, The instruction acquisition module 201 is used to acquire elasticity assessment instructions; wherein, the elasticity assessment instructions include a business identifier; The component determination module 202 is used to determine, according to the elasticity assessment instruction, at least one sub-business contained in the business system corresponding to the business identifier, and at least one component that each sub-business depends on. The weight determination module 203 is used to obtain at least one network resilience indicator, and determine the component weight of each component, the logic processing weight of the business logic processing module of each sub-business, and the business weight of each sub-business based on each network resilience indicator and the historical operation data of the business system in the historical time period. The scoring module 204 is used to obtain the component score of each component based on the operation of each component during the evaluation process, and to obtain the logic processing score of each business logic processing module based on the operation of each sub-business business logic processing module during the evaluation process. The resilience assessment module 205 is used to assess the network resilience of the business system based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-business, the business weights of each sub-business, the component scores of each component, and the logic processing scores of each business logic processing module, and to obtain the network resilience assessment results of the business system.
[0083] In one example embodiment, the weight determination module 203 is specifically used to: determine the component dependency, business importance, and business priority based on each network resilience index and the historical operating data of the business system within a historical time period; determine the component weight of each component under the network resilience index based on the component dependency and business importance; determine the logic processing weight of the business logic processing module of each sub-business based on the business importance; and determine the business weight of each sub-business under each network resilience index based on the business priority of each sub-business and each network resilience index.
[0084] In one example embodiment, the weight determination module 203 determines the component weight of each component under the network resilience index based on the component dependency degree and the business importance. Specifically, it is used to: determine the component failure impact coefficient of each component for each sub-business based on the component dependency degree of the sub-business corresponding to the component and the business importance of the sub-business in the business system; and determine the component weight of the component under each network resilience index based on the component failure impact coefficient and each network resilience index.
[0085] In one example embodiment, the weight determination module 203 determines the component failure impact coefficient of the component based on the component dependency degree of the sub-business corresponding to the component and the business importance of the sub-business in the business system. Specifically, it is used to determine the component failure impact coefficient of the component based on the product of the component dependency degree of the sub-business corresponding to the component and the business importance of the sub-business in the business system.
[0086] In one example embodiment, the weight determination module 203 determines the logical processing weight of the business logic processing module of each sub-business according to the importance of the business. Specifically, it is used to: determine the logical processing failure impact coefficient of the business logic processing module of each sub-business based on the importance of the sub-business in the business system; and determine the logical processing weight of the business logic processing module under each network resilience index based on the logical processing failure impact coefficient of the business logic processing module and each network resilience index.
[0087] In one example embodiment, the resilience assessment module 205 is specifically used to: perform network resilience assessment on the business system based on the component weight of each component, the logic processing weight of the business logic processing module of each sub-business, the business weight of each sub-business, the component score of each component, and the logic processing score of each business logic processing module, to obtain a network resilience assessment index score; and determine the network resilience assessment result of the business system based on the network resilience assessment index score and the importance of the business.
[0088] In one example embodiment, the resilience assessment module 205 determines the network resilience assessment result of the business system based on the network resilience assessment index score and the importance of the business. Specifically, it is used to determine the network resilience assessment result of the business system based on the product of the network resilience assessment index score and the importance of the business.
[0089] The apparatus of this embodiment can be used to execute the method of any embodiment in the component-based network resilience assessment method side embodiment. Its specific implementation process and technical effects are similar to those in the component-based network resilience assessment method side embodiment. For details, please refer to the detailed description in the component-based network resilience assessment method side embodiment, which will not be repeated here.
[0090] Figure 3 This is a schematic diagram of the structure of the electronic device provided by the present invention, such as... Figure 3As shown, the electronic device may include: a processor 310, a communications interface 320, a memory 330, and a communications bus 340, wherein the processor 310, the communications interface 320, and the memory 330 communicate with each other through the communications bus 340. The processor 310 can invoke logical instructions in the memory 330 to execute a component-based network resilience assessment method. This method includes: obtaining resilience assessment instructions, wherein the resilience assessment instructions include a service identifier; determining, based on the resilience assessment instructions, at least one sub-service contained in the business system corresponding to the service identifier, and at least one component on which each sub-service depends; obtaining at least one network resilience indicator, and determining, based on each network resilience indicator and historical operating data of the business system within a historical time period, the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, and the service weight of each sub-service; obtaining the component score of each component based on the operating status of each component during the assessment process, and obtaining the logical processing score of each business logic processing module based on the operating status of the business logic processing module of each sub-service during the assessment process; and performing a network resilience assessment on the business system based on the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, the service weight of each sub-service, the component score of each component, and the logical processing score of each business logic processing module, to obtain the network resilience assessment result of the business system.
[0091] Furthermore, the logical instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0092] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the component-based network resilience assessment method provided by the above methods. The method includes: obtaining a resilience assessment instruction; wherein the resilience assessment instruction includes a service identifier; determining, according to the resilience assessment instruction, at least one sub-service contained in the business system corresponding to the service identifier, and at least one component on which each sub-service depends; obtaining at least one network resilience index, and determining, according to each network resilience index and the historical operating data of the business system in a historical time period, the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, and the business weight of each sub-service; obtaining the component score of each component according to the operating status of each component during the assessment process, and obtaining the logical processing score of each business logic processing module according to the operating status of the business logic processing module of each sub-service during the assessment process; and performing a network resilience assessment on the business system according to the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, the business weight of each sub-service, the component score of each component, and the logical processing score of each business logic processing module, to obtain the network resilience assessment result of the business system.
[0093] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program is implemented to perform the component-based network resilience assessment method provided by the above methods. The method includes: obtaining a resilience assessment instruction; wherein the resilience assessment instruction includes a service identifier; determining, according to the resilience assessment instruction, at least one sub-service contained in the service system corresponding to the service identifier, and at least one component on which each sub-service depends; obtaining at least one network resilience index, and determining, according to each network resilience index and historical operating data of the service system within a historical time period, the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, and the service weight of each sub-service; obtaining the component score of each component according to the operating status of each component during the assessment process, and obtaining the logical processing score of each business logic processing module according to the operating status of the business logic processing module of each sub-service during the assessment process; and performing a network resilience assessment on the service system according to the component weight of each component, the logical processing weight of the business logic processing module of each sub-service, the service weight of each sub-service, the component score of each component, and the logical processing score of each business logic processing module, to obtain the network resilience assessment result of the service system.
[0094] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0095] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A component-based network resilience assessment method, characterized in that, include: Obtain the elasticity assessment instruction; wherein, the elasticity assessment instruction includes a business identifier; The elasticity assessment instruction determines at least one sub-service contained in the business system corresponding to the business identifier, and at least one component on which each sub-service depends. At least one network resilience indicator is obtained, and based on each network resilience indicator and the historical operating data of the business system within a historical time period, the component weight of each component, the logic processing weight of the business logic processing module of each sub-business, and the business weight of each sub-business are determined. Based on the operation of each component during the evaluation process, obtain the component score of each component, and based on the operation of the business logic processing module of each sub-business during the evaluation process, obtain the logic processing score of each business logic processing module. Based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, a network resilience assessment is performed on the business system to obtain the network resilience assessment result of the business system.
2. The component-based network resilience assessment method according to claim 1, characterized in that, The step of determining the component weight of each component, the logic processing weight of the business logic processing module of each sub-service, and the business weight of each sub-service based on each network resilience index and the historical operating data of the business system within a historical time period includes: The component dependency, business importance, and business priority are determined based on the network resilience indicators and the historical operating data of the business system within the historical time period. The component weights of each component under the network resilience index are determined based on the component dependency and the business importance. The logic processing weights of the business logic processing modules for each of the sub-businesses are determined based on the importance of the business. Based on the service priority of each sub-service and each network resilience index, determine the service weight of each sub-service under each network resilience index.
3. The component-based network resilience assessment method according to claim 2, characterized in that, The step of determining the component weights of each component under the network resilience index based on the component dependency degree and the business importance includes: For each component of each sub-service, the component failure impact coefficient is determined based on the degree of component dependency of the sub-service to the component and the degree of service importance of the sub-service in the service system. Based on the component failure impact coefficient and each of the network resilience indices, the component weight of the component under each of the network resilience indices is determined.
4. The component-based network resilience assessment method according to claim 3, characterized in that, The determination of the component failure impact coefficient based on the component's dependency on the corresponding sub-service and the sub-service's importance in the business system includes: The component failure impact coefficient is determined by multiplying the component dependency of the sub-service corresponding to the component with the importance of the sub-service in the business system.
5. The component-based network resilience assessment method according to claim 2, characterized in that, The step of determining the logic processing weight of each sub-business's business logic processing module based on the importance of the business includes: For each of the aforementioned sub-services, based on the importance of the sub-service in the business system, the logic processing failure impact coefficient of the business logic processing module of the sub-service is determined; Based on the logic processing failure impact coefficient of the business logic processing module and each of the network resilience indicators, the logic processing weight of the business logic processing module under each of the network resilience indicators is determined.
6. The component-based network resilience assessment method according to claim 2, characterized in that, The network resilience assessment of the business system is performed based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, to obtain the network resilience assessment result of the business system, including: Based on the component weights of each component, the logic processing weights of the business logic processing modules of each sub-service, the business weights of each sub-service, the component scores of each component, and the logic processing scores of each business logic processing module, the network resilience of the business system is evaluated to obtain a network resilience evaluation index score. The network resilience assessment result of the business system is determined based on the network resilience assessment index score and the importance of the business.
7. The component-based network resilience assessment method according to claim 6, characterized in that, Determining the network resilience assessment result of the business system based on the network resilience assessment index score and the business importance includes: The network resilience assessment result of the business system is determined by multiplying the network resilience assessment index score by the business importance score.
8. A component-based network resilience assessment device, characterized in that, include: The instruction acquisition module is used to acquire elasticity assessment instructions; wherein, the elasticity assessment instructions include a business identifier; The component determination module is used to determine, according to the elasticity assessment instruction, at least one sub-service contained in the business system corresponding to the business identifier, and at least one component on which each sub-service depends. The weight determination module is used to obtain at least one network resilience indicator, and determine the component weight of each component, the logic processing weight of the business logic processing module of each sub-service, and the business weight of each sub-service based on each network resilience indicator and the historical operation data of the business system in the historical time period. The scoring module is used to obtain the component score of each component based on the operation of each component during the evaluation process, and to obtain the logic processing score of each business logic processing module based on the operation of each sub-business business logic processing module during the evaluation process. The resilience assessment module is used to perform network resilience assessment on the business system based on the component weight of each component, the logic processing weight of the business logic processing module of each sub-service, the business weight of each sub-service, the component score of each component, and the logic processing score of each business logic processing module, and to obtain the network resilience assessment result of the business system.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the component-based network resilience assessment method as described in any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the component-based network resilience assessment method as described in any one of claims 1 to 7.