Executor scheduling optimization method and device for mimic defense framework

By constructing an execution set and calculating heterogeneity and security defense coefficients, the scheduling algorithm of the mimicry defense framework is optimized, which solves the problem that existing technologies cannot dynamically analyze the heterogeneity of execution sets, and improves the security and performance of the system.

WO2025246040A1PCT designated stage Publication Date: 2025-12-04GLOBAL ENERGY INTERCONNECTION RES INST CO LTD +3
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/113615
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-28
Filing Date
2024-08-21
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

Existing mimicry defense framework scheduling algorithms cannot effectively analyze the heterogeneity of the execution entity dynamically, leading to common-mode vulnerabilities and failing to effectively defend against intrusions.

Method used

By constructing multiple execution sets, calculating the heterogeneity and security defense coefficient of each execution set, using the scheduling function score to determine the final scheduling object, and dynamically updating the number of executions based on the decision result, heterogeneity and historical security evaluation indicators are introduced to optimize scheduling efficiency.

Benefits of technology

It improves system security and performance, enhances resistance to unknown attacks, ensures maximum diversity among execution entities, and achieves dynamic changes and stability in the system's internal structure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024113615_04122025_PF_FP_ABST
    Figure CN2024113615_04122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network security, and discloses an executor scheduling optimization method and device for a mimic defense framework. The method comprises: using a plurality of executors corresponding to a source program to be tested, so as to form a plurality of executor sets; calculating the heterogeneity of each executor set and a security defense coefficient of each executor set; using the heterogeneity of each executor set and the security defense coefficient of each executor set to calculate a scheduling function score of each executor set, and determining final scheduled objects on the basis of the scheduling function score of each executor set; and according to a decision result of each executor among the final scheduled objects in a mimic defense framework, updating the number of executors scheduled from among the final scheduled objects during each scheduling. In the technical solution provided by the present application, scheduling efficiency is optimized while guaranteeing the maximization of difference between executors, and the security and performance of a system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

A method and apparatus for optimizing execution entity scheduling in a mimicry defense framework.

[0001] Cross-reference to related applications

[0002] This application is based on and claims priority to Chinese Patent Application No. 202410670630.3, filed on May 28, 2024, entitled “A Method and Apparatus for Execution Module Scheduling Optimization in a Mimicry Defense Framework”, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to, but is not limited to, the field of network security technology, and specifically to an execution entity scheduling optimization method and apparatus for a mimicry defense framework. Background Technology

[0004] The mimicry defense framework is an innovative security defense concept based on the biological phenomenon of mimicry, aiming to fundamentally overcome the current strategic predicament of cyberspace being "easy to attack but difficult to defend." Its core idea lies in enabling the system itself to possess inherent security capabilities through a mimicry architecture with "dynamic, heterogeneous, redundant, and adjudicative" mechanisms. Specifically, "dynamic" refers to the system scheduling different "heterogeneous and redundant" execution units or service components according to preset rules or dynamic algorithms, ensuring the system can operate in different states, thereby confusing attackers, blocking attacks, and thus ensuring system security.

[0005] Figure 1 illustrates the basic framework of mimicry defense. When the adjudicator detects an anomaly and issues a scheduling instruction to the scheduling strategy module, the scheduling strategy module will issue a new execution entity based on the provided scheduling algorithm. However, existing scheduling algorithms, such as round-robin scheduling and random scheduling algorithms, only implement the basic functions of the mimicry framework. They cannot dynamically analyze and judge the heterogeneity of the execution entity construction, and cannot avoid the generation of common-mode vulnerabilities. Therefore, they cannot effectively defend against intrusions.

[0006] Summary of the Invention

[0007] To overcome the problems existing in the above-mentioned related technologies, this application provides an execution body scheduling optimization method and apparatus for a mimicry defense framework.

[0008] According to a first aspect of the embodiments of this application, an execution entity scheduling optimization method for a mimicry defense framework is provided, comprising:

[0009] Multiple sets of executables are constructed using several executables corresponding to the source program under test;

[0010] Calculate the heterogeneity of each execution set and the security defense coefficient of each execution set;

[0011] The scheduling function score of each execution body set is calculated by using the heterogeneity of each execution body set and the security defense coefficient of each execution body set, and the final scheduling object is determined according to the scheduling function score of each execution body set.

[0012] The number of execution bodies scheduled from the final scheduling object each time is updated according to the judgment result of each execution body in the quasipotential defense framework in the final scheduling object.

[0013] In an embodiment, the plurality of execution body sets is constructed by using a plurality of execution bodies corresponding to the source program to be tested, comprising:

[0014] An execution body pool is constructed by using a plurality of execution bodies corresponding to the source program to be tested.

[0015] A plurality of execution body sets is constructed by selecting a plurality of groups of execution bodies with a preset number from the execution body pool.

[0016] In an embodiment, the heterogeneity of each execution body set is calculated, comprising:

[0017] The heterogeneity between each execution body in each execution body set is obtained by using a code similarity measurement method.

[0018] The heterogeneity of each execution body set is calculated by using the heterogeneity between each execution body in each execution body set.

[0019] In an embodiment, the security defense coefficient of each execution body set is calculated, comprising:

[0020] The security defense coefficient of each execution body in each execution body set is determined according to the output condition of each execution body in each execution body set.

[0021] The security defense coefficient of each execution body set is calculated by using the security defense coefficient of each execution body in each execution body set.

[0022] In an embodiment, the final scheduling object is determined according to the scheduling function score of each execution body set, comprising:

[0023] The execution body set corresponding to the smallest scheduling function score is selected as the final scheduling object from all execution body sets.

[0024] In an embodiment, the number of execution bodies scheduled from the final scheduling object each time is updated according to the judgment result of each execution body in the quasipotential defense framework in the final scheduling object, comprising:

[0025] The output proportion of each type of judgment result is determined based on the judgment result of each execution body in the quasipotential defense framework in the final scheduling object.

[0026] Sort the output percentages of all types of judgment results in descending order and select the output percentage with the highest ranking as the target output percentage.

[0027] Using the target output ratio, update the number of executors scheduled from the final scheduling object each time.

[0028] In one implementation, the formula for calculating the heterogeneity of each execution set includes:

[0029] In the above formula, i∈[1,m], j∈[1,m], and m is the total number of execution bodies in the execution body set; E i For the i-th executor, E j For the j-th executor, σ(E) i E j ) represents the heterogeneity between the i-th and j-th executors, and σ* represents the heterogeneity of the set of executors.

[0030] In one embodiment, the formula for calculating the security defense coefficient of each execution entity in the execution entity set includes:

[0031] In the above formula, i∈[1,m], and m is the total number of execution bodies in the execution body set; μ i Let μ be the current security defense coefficient of the i-th execution entity in the execution entity set. i ′ represents the security defense coefficient of the i-th execution entity in the execution entity set in the previous instance. This is the update factor.

[0032] In one implementation, the formula for calculating the security defense coefficient of each execution set includes:

[0033] In the above formula, i∈[1,m], and m is the total number of execution bodies in the execution body set; μ i μ* represents the current security defense coefficient of the i-th execution entity in the execution entity set, and μ* represents the security defense coefficient of the execution entity set.

[0034] In one implementation, the formula for calculating the scheduling function score of each execution set includes: θ(E p )=σ*+μ*

[0035] In the above formula, θ(E) p ) represents the scheduling function score of the execution set, σ* represents the heterogeneity of the execution set, and μ* represents the security defense coefficient of the execution set.

[0036] In one implementation, the formula for calculating the number of executors scheduled from the final scheduling object at each scheduling time includes:

[0037] In the above formula, t∈[1, T], T is the total number of scheduling, m(t) is the number of execution bodies scheduled from the final scheduling object at the tth scheduling, a is a constant, is the target output proportion at the t-2th scheduling, is the target output proportion at the t-1th scheduling, m(t-1) is the number of execution bodies scheduled from the final scheduling object at the t-1th scheduling.

[0038] According to a second aspect of the embodiments of the present application, an execution body scheduling optimization device for a quasimodo defense framework is provided, comprising:

[0039] A construction unit is configured to construct a plurality of execution body sets by using a plurality of execution bodies corresponding to a source program to be tested.

[0040] A calculation unit is configured to calculate the heterogeneity of each execution body set and the security defense coefficient of each execution body set.

[0041] A determination unit is configured to calculate the scheduling function score of each execution body set by using the heterogeneity of each execution body set and the security defense coefficient of each execution body set, and determine the final scheduling object according to the scheduling function score of each execution body set.

[0042] An update unit is configured to update the number of execution bodies scheduled from the final scheduling object at each scheduling according to the judgment result of each execution body in the quasimodo defense framework in the final scheduling object.

[0043] According to a third aspect of the embodiments of the present application, an electronic device is provided, comprising at least one processor and a memory; the memory and the processor are connected through a bus;

[0044] The memory is configured to store one or more programs.

[0045] When the one or more programs are executed by the at least one processor, the execution body scheduling optimization method for the quasimodo defense framework is implemented.

[0046] According to a fourth aspect of the embodiments of the present application, a readable storage medium having an execution program stored thereon is provided, and when the execution program is executed, the execution body scheduling optimization method for the quasimodo defense framework is implemented.

[0047] The technical solutions provided by the present application have the following beneficial effects:

[0048] The application provides an execution body scheduling optimization method and device for a quasimodo defense framework, a plurality of execution body sets are formed by using a plurality of execution bodies corresponding to a to-be-tested source program, the heterogeneity of each execution body set and the security defense coefficient of each execution body set are calculated, the scheduling function score of each execution body set is calculated by using the heterogeneity of each execution body set and the security defense coefficient of each execution body set, and the final scheduling object is determined according to the scheduling function score of each execution body set, so that the heterogeneity is analyzed by introducing two evaluation indexes of heterogeneity and historical security, and the credibility of the security of the execution body is increased; the number of execution bodies scheduled from the final scheduling object at each time of scheduling is updated according to the judgment result of each execution body in the quasimodo defense framework in the final scheduling object, dynamic evaluation and scheduling are performed, the difference between the execution bodies is ensured, the overall security of the system is ensured, meanwhile, the required number of execution bodies is dynamically decided according to the time sequence change by combining historical data, the internal structure of the system is further dynamically changed, the ability of resisting unknown attacks is increased, and the scheduling efficiency is optimized while the difference between the execution bodies is maximized, and the security and performance of the system are improved. BRIEF DESCRIPTION OF DRAWINGS

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only some embodiments of the present application, and for those skilled in the art, other drawings can be obtained without creative labor.

[0050] Fig. 1 is a structural schematic diagram of a quasimodo defense framework provided by an embodiment of the present application;

[0051] Fig. 2 is a flowchart of an execution body scheduling optimization method for a quasimodo defense framework provided by an embodiment of the present application;

[0052] Fig. 3 is a structural block diagram of an execution body scheduling optimization device for a quasimodo defense framework provided by an embodiment of the present application;

[0053] Fig. 4 is a structural block diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0054] In order to make the purpose, technical solutions and advantages of the present application more clear, the technical solutions of the present application will be clearly and completely described below in combination with the drawings. Obviously, the following embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0055] Embodiment one of the present application

[0056] The application provides an execution body scheduling optimization method for a quasimodo defense framework, as shown in FIG. 2, which comprises the following steps:

[0057] Step 101: using a plurality of execution bodies corresponding to a source program to be tested to form a plurality of execution body sets;

[0058] Step 102: calculating the heterogeneity of each execution body set and the security defense coefficient of each execution body set;

[0059] Step 103: using the heterogeneity of each execution body set and the security defense coefficient of each execution body set to calculate the scheduling function score of each execution body set, and determining the final scheduling object according to the scheduling function score of each execution body set;

[0060] Step 104: according to the judgment result of each execution body in the quasimodo defense framework in the final scheduling object, updating the number of execution bodies scheduled from the final scheduling object each time.

[0061] In an embodiment, step 101 comprises:

[0062] Step 1011: using a plurality of execution bodies corresponding to a source program to be tested to build an execution body pool;

[0063] Step 1012: selecting a plurality of groups of execution bodies with a preset number from the execution body pool to build a plurality of execution body sets.

[0064] The application improves the existing scheduling algorithm and designs a differentiated feedback scheduling algorithm. The scheduling algorithm mainly includes two aspects: scheduling object and scheduling number.

[0065] The scheduling object is a heterogeneous execution body in the quasimodo control layer. The scheduling selects a plurality of execution bodies in the execution body pool for executing a task. The execution bodies are independent and equal to each other. The scheduling task is to dynamically select an execution body for executing a task, and the number of execution bodies n≥3. The mathematical symbols in the scheduling model are shown in Table 1.

[0066] Table 1: Mathematical symbol meaning of scheduling strategy

[0067] It is assumed that there are n execution bodies E in the execution body pool p ={E1,E2,E3,…,E i ,…,E n ,},E i represents a single execution body. The scheduling selects m execution bodies to form an execution body set, and k execution bodies are not selected, wherein n=m+k.

[0068] Each executor has three states, represented by status: status=1 indicates that the executor is selected; status=0 indicates that it is not selected but may be selected later; status=2 indicates that the executor's security defense coefficient is too low and it will not be selected later.

[0069] In mimicry defense, the greater the structural differences between the selected execution objects, the more complex the internal structure of the system becomes, reducing the likelihood of common-mode vulnerabilities in execution objects, increasing the difficulty for attackers to succeed, and achieving intrinsic security of the system's ontology. To quantify the structural differences of execution objects, this application uses a code similarity measurement method to obtain the heterogeneity σ between execution objects.

[0070] The core idea of ​​code similarity measurement methods is to obtain the similarity by combining the overall structure of the code with the similarity of statements.

[0071] Heterogeneity encompasses many aspects, such as programming language, operating system platform, and hardware architecture. Heterogeneity is a quantitative parameter used to describe the degree of heterogeneity; a smaller value indicates greater structural differences, and σ∈(0,1). The code heterogeneity matrix obtained through code similarity measurement is shown below:

[0072] Choosing an execution entity with high heterogeneity increases the difficulty for attackers. During the scheduling process, heterogeneity is set as the basis for scheduling the execution entity.

[0073] In one implementation, step 102, calculating the heterogeneity of each set of execution entities, includes:

[0074] Step 1021: Use code similarity measurement methods to obtain the heterogeneity among the execution entities in each execution entity set;

[0075] Step 1022: Calculate the heterogeneity of each execution set using the heterogeneity among the execution sets;

[0076] Specifically, the formulas for calculating the heterogeneity of each execution set include:

[0077] In the above formula, i∈[1,m], j∈[1,m], and m is the total number of execution bodies in the execution body set; E i For the i-th executor, E j For the j-th executor, σ(E) i E j ) represents the heterogeneity between the i-th and j-th executors, and σ* represents the heterogeneity of the set of executors.

[0078] It should be noted that the "code similarity measurement method is used to obtain the heterogeneity between each execution body in each execution body set", which is involved in the embodiments of the present application, is well known to those skilled in the art, and therefore the specific implementation manner is not described in detail.

[0079] The difference in the design structure of the execution body itself causes different defense capabilities. For the scheduler, the execution body with stronger security defense capability should be selected as much as possible, and the execution body cannot be selected randomly. The security defense coefficient of the execution body is defined according to the abnormal condition output by the execution body. In the initialization state, the security defense coefficients of each execution body are equal. Whether the execution body is an abnormal output is fed back through the decision maker. According to the output condition of the execution body each time, the security defense coefficient of the execution body is updated, and the smaller the value is, the safer it is. In an implementation manner, the security defense coefficients of each execution body set in step 102 are calculated, including:

[0080] Step 1023: According to the output condition of each execution body in each execution body set, the security defense coefficient of each execution body in each execution body set is determined.

[0081] Specifically, the calculation formula of the security defense coefficient of each execution body in each execution body set includes:

[0082] In the above formula, i∈[1,m], m is the total number of execution bodies in the execution body set; μ i is the current security defense coefficient of the i th execution body in the execution body set, μ i is the last security defense coefficient of the i th execution body in the execution body set, and is an update factor.

[0083] Step 1024: The security defense coefficients of each execution body set are calculated by using the security defense coefficients of each execution body in each execution body set.

[0084] Specifically, the calculation formula of the security defense coefficient of each execution body set includes:

[0085] In the above formula, i∈[1,m], m is the total number of execution bodies in the execution body set; μ i is the current security defense coefficient of the i th execution body in the execution body set, and μ* is the security defense coefficient of the execution body set.

[0086] It can be understood that the smaller the value of μ is, the higher the security is, and μ, μ*∈(0,1], and the scheduler selects the execution body set with smaller μ* value.

[0087] According to the above analysis, considering the influence of the heterogeneity of the executors and the security defense coefficient on the security defense, in an embodiment, the calculation formula of the scheduling function score of each executor set includes: θ(E p )=σ*+μ* (5);

[0088] In the above formula, θ(E p ) is the scheduling function score of the executor set, σ* is the heterogeneity of the executor set, and μ* is the security defense coefficient of the executor set.

[0089] In an embodiment, the final scheduling object is determined according to the scheduling function score of each executor set in step 103, including:

[0090] From all the executor sets, the executor set corresponding to the smallest scheduling function score is selected as the final scheduling object.

[0091] It can be understood that the smaller the values of σ* and μ* are, the better the defense performance is. The scheduling algorithm solves the minimum value of the scheduling function, and the scheduler selects the corresponding executor. The calculation formula is as follows: θ(E p )=argminσ*+μ* (6);

[0092] The executor set E m ={E1,E2,E3,…,E i ,…,E m ,} is obtained as the final scheduling object.

[0093] The quorum defense adopts the majority correct algorithm to judge the output of each executor, and the result with the largest number of the same number is taken as the final output result. The attacker needs to attack the executor set control system. The more executors, the more executors the attacker needs to attack to change the output proportion and affect the judgment result. Therefore, the number of scheduled executors directly affects the judgment result and ultimately affects the security of the system. The more executors selected by scheduling, the safer it is, but the cost is also higher. Considering comprehensively, a more reasonable scheduling number is obtained. In this paper, a scheduling number algorithm based on judgment feedback is adopted. According to the output proportion of the judgment result, the number of scheduled executors is updated each time.

[0094] In an embodiment, step 104 includes:

[0095] Step 1041: determining the output proportion of each type of judgment result based on the judgment result of each executor in the quorum defense framework in the final scheduling object;

[0096] Step 1042: sorting the output proportions of all types of judgment results in descending order, and selecting the first ranked output proportion as the target output proportion.

[0097] Step 1043: updating the number of execution bodies scheduled from the final scheduling object each time the scheduling is performed by using the target output ratio;

[0098] Specifically, the calculation formula of the number of execution bodies scheduled from the final scheduling object each time the scheduling is performed includes:

[0099] In the above formula, t∈[1,T], T is the total number of scheduling; m(t) is the number of execution bodies scheduled from the final scheduling object at the tth scheduling, a is a constant, is the target output ratio at the t-2th scheduling, is the target output ratio at the t-1th scheduling, and m(t-1) is the number of execution bodies scheduled from the final scheduling object at the t-1th scheduling.

[0100] According to the feedback module, the same output is classified into a category, and the ratio of each category of output is obtained, and the ranking of the result is obtained. U is the result ratio set, and U is: U={U 1 ,U 2 ,U 3 ,…,U L}. Among them, U 1 is the largest ratio, U 2 is the second largest ratio, U 3 is the third largest ratio, U L is the Lth largest ratio (i.e. the ratio of the last ranking), and the output of the execution body corresponding to U 1 is the final output of the decision maker.

[0101] U 1 embodies the consistency of the output results of each execution body: U 1 close to 100% indicates that the outputs of each execution body are very consistent, and the system security state is also good; when U 1 becomes smaller, it indicates that the outputs of each execution body are not consistent, the system is unstable internally, some execution bodies may be attacked and the correct output result is changed, and the system security state is poor.

[0102] Increasing the number of execution bodies is beneficial to improving the system security, and attackers need to attack more execution bodies to change the output ratio, increasing the difficulty of attackers. When the output is consistent compared with the last time, the number of schedulers is reduced, otherwise it is increased. Therefore, according to U 1The number of scheduling is updated according to the change rate of the front and rear time, and m(t) can be rounded when m(t) is calculated. The number of schedulers scheduling the executors is dynamically updated according to the front and rear changes of the proportion of the output of the executors, so that the internal structure of the system is further dynamically changed, and the endogenous safety of the system is increased.

[0103] To further illustrate the above-mentioned executor scheduling optimization method for the quasispecies defense framework, an embodiment of the present application provides a specific example, including the following steps:

[0104] Step 1: The source program to be tested is converted according to the structural characteristics such as conditional statements and function blocks to form a representation sequence and a metric list; a bubble algorithm is used to compare the structural characteristics of each module in the representation sequence, a distance function is used to compare the structural characteristics of each two programs, and the same function blocks between isomers are matched; the function blocks that have been matched are measured by a longest common subsequence algorithm to obtain the final metric analysis result σ(E i ,E j );

[0105] Step 2: Based on the isomerization degree σ(E i ,E j ) between executors obtained in step 1, all effective executors, i.e. all isomers with status ≠ 2, are constructed into an isomerization matrix according to the actual number of executors required. In the starting stage of the flow, status is set to 0. Taking the case of requiring 3 executors as an example: all possible executor isomerization matrices M{E i ,E j ,E k} are constructed.

[0106] The isomerization degree σ* of the executor set of all possible isomerization matrices M is calculated. For an initialized system, the three isomers with the lowest isomerization degree in the matrix M are selected to be activated as executors. For an updated system, an executor defense coefficient is introduced as a reference coefficient to increase the safety of the system. The specific updating method is as follows in step 3.

[0107] Step 3: For all isomers, initialize their safety defense coefficients μ to the same value. The safety defense coefficient of the executor is updated according to the output of the executor each time, and the smaller the value, the safer. After each abnormality occurs, the safety defense coefficient μ of the executor is updated by formula (3), and the safety defense coefficient μ* of the executor set can be obtained by formula (4).

[0108] Based on formula (5), considering the combined impact of the heterogeneity of the execution entity and the security defense coefficient on the overall system security, the scheduling object function score θ(E) of the candidate heterogeneous entity set p can be calculated. p ), then for the entire set of candidate isomers argmin(θ(E) p The last scheduling object is then selected.

[0109] Based on the dynamic scheduling of execution entities for security, this application uses feedback historical data to record the historical results of each heterogeneous entity, and obtains the execution entity output result classification set U based on the historical results. Considering the possible changes in the overall security of the system over time, the number of execution entities in operation is dynamically changed according to formula (7) to maintain the stability of system security.

[0110] When the feedback device detects an inconsistency in the output, the system should repeat the above steps starting from step 2 and execute the dynamic scheduling strategy.

[0111] This application provides an execution entity scheduling optimization method for a mimicry defense framework. It utilizes several execution entities corresponding to the source program under test to form multiple execution entity sets. The heterogeneity and security defense coefficient of each execution entity set are calculated. Using these scores, a scheduling function score is calculated for each execution entity set. The final scheduling object is determined based on these scores. Heterogeneity and historical security are introduced as evaluation indicators to analyze heterogeneous entities, increasing the reliability of execution entity security. By updating the number of execution entities scheduled from the final scheduling object based on the decision results of each execution entity in the mimicry defense framework, dynamic evaluation and scheduling are performed to ensure the differences between execution entities, thereby guaranteeing overall system security. Simultaneously, by combining historical data and considering temporal changes, the required number of execution entities is dynamically determined, further enabling dynamic changes in the system's internal structure and increasing its ability to resist unknown attacks. This achieves optimized scheduling efficiency while maximizing the differences between execution entities, simultaneously improving system security and performance.

[0112] Example 2 of this application

[0113] This application also provides an execution entity scheduling optimization device for a mimicry defense framework, as shown in Figure 3, comprising:

[0114] The building unit is configured to construct multiple sets of executables using several executables corresponding to the source program under test;

[0115] The computing unit is configured to calculate the heterogeneity of each execution set and the security defense coefficient of each execution set;

[0116] The determining unit is configured to calculate a scheduling function score of each execution body set by using the heterogeneity of each execution body set and the security defense coefficient of each execution body set, and determine a final scheduling object according to the scheduling function score of each execution body set.

[0117] The updating unit is configured to update the number of execution bodies scheduled from the final scheduling object each time according to a decision result of each execution body in the quasi-defense framework in the final scheduling object.

[0118] In an embodiment, the constructing unit comprises:

[0119] The first constructing module is configured to construct an execution body pool by using a plurality of execution bodies corresponding to the source program to be tested.

[0120] The second constructing module is configured to select a plurality of groups of execution bodies with a preset number from the execution body pool to construct a plurality of execution body sets.

[0121] In an embodiment, the calculating unit comprises:

[0122] The obtaining module is configured to obtain the heterogeneity between each execution body in each execution body set by using a code similarity measurement method.

[0123] The first calculating module is configured to calculate the heterogeneity of each execution body set by using the heterogeneity between each execution body in each execution body set.

[0124] In an embodiment, the calculation formula of the heterogeneity of each execution body set comprises:

[0125] In the above formula, i∈[1, m], j∈[1, m], m is the total number of execution bodies in the execution body set; E i is the i th execution body, E j is the j th execution body, σ(E i , E j ) is the heterogeneity between the i th execution body and the j th execution body, and σ* is the heterogeneity of the execution body set.

[0126] In an embodiment, the calculating unit further comprises:

[0127] The first determining module is configured to determine the security defense coefficient of each execution body in each execution body set according to the output condition of each execution body in each execution body set.

[0128] The second calculating module is configured to calculate the security defense coefficient of each execution body set by using the security defense coefficient of each execution body in each execution body set.

[0129] In an embodiment, the calculation formula of the security defense coefficient of each execution body in each execution body set comprises:

[0130] In the above formula, i ∈ [1, m], m is the total number of executors in the executor set; μ i is the current security defense coefficient of the i th executor in the executor set, and μ i is the last security defense coefficient of the i th executor in the executor set, is an update factor.

[0131] In an embodiment, the calculation formula of the security defense coefficient of each executor set includes:

[0132] In the above formula, i ∈ [1, m], m is the total number of executors in the executor set; μ i is the current security defense coefficient of the i th executor in the executor set, and μ

[0133] In an embodiment, the calculation formula of the scheduling function score of each executor set includes: θ(E p ) = σ * + μ

[0134] In the above formula, is the scheduling function score of the executor set, σ is the heterogeneity of the executor set, and μ is the security defense coefficient of the executor set.

[0135] In an embodiment, the determination unit is specifically configured to:

[0136] From all the executor sets, select the executor set corresponding to the smallest scheduling function score as the final scheduling object.

[0137] In an embodiment, the update unit includes:

[0138] The second determination module is configured to determine the output proportion of each type of judgment result based on the judgment results of each executor in the quasi-state defense framework in the final scheduling object;

[0139] The selection module is configured to sort the output proportions of all types of judgment results in descending order, and select the output proportion ranked first as the target output proportion;

[0140] The update module is configured to update the number of executors scheduled from the final scheduling object at each scheduling time by using the target output proportion.

[0141] In an embodiment, the calculation formula of the number of executors scheduled from the final scheduling object at each scheduling time includes:

[0142] In the above formula, t∈[1, T], T is the total number of scheduling; m(t) is the number of execution bodies scheduled from the final scheduling object at the tth scheduling, a is a constant, is the target output proportion at the t-2th scheduling, is the target output proportion at the t-1th scheduling, m(t-1) is the number of execution bodies scheduled from the final scheduling object at the t-1th scheduling.

[0143] It can be understood that the device embodiments provided above correspond to the method embodiments described above, and the specific contents can be mutually referred to, which will not be repeated here.

[0144] It can be understood that the same or similar parts in the above embodiments can be mutually referred to, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.

[0145] Embodiment three of the present application

[0146] As shown in FIG. 4, the present application further provides an electronic device, which can be a computer device, a single-chip microcomputer device, a smart mobile device, etc. The electronic device in the present embodiment can include a processor, a memory, a transceiver component, etc. The memory, the processor and the transceiver component are connected through a bus; the memory can be used to store an execution program, and the exemplary execution program can include instructions; the processor is used to execute the instructions stored in the memory. The memory can also be used to store data, which can be called and / or modified when the instructions are executed.

[0147] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc., which are the computing core and control core of the terminal, and are suitable for implementing one or more instructions, and are suitable for loading and executing one or more instructions in the storage medium to implement a corresponding method flow or a corresponding function, to implement the steps of the above-mentioned embodiment of the execution body scheduling optimization method for the mimetic defense framework.

[0148] Embodiment four of the present application

[0149] Based on the same inventive concept, the application further provides a readable storage medium, specifically an electronic device readable storage medium (Memory). The electronic device readable storage medium is a memory device in the electronic device, configured to store programs and data. It can be understood that the storage medium herein can include a built-in storage medium in the electronic device, and of course can also include an expansion storage medium supported by the electronic device. The storage medium provides a storage space, which stores an operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space, and the instructions can be one or more execution programs (including program codes). It should be noted that the storage medium herein can be a high-speed RAM memory or a non-volatile memory such as at least one disk memory. Loading and executing one or more instructions stored in the storage medium by the processor can realize the steps of the above-mentioned embodiment of the method for scheduling optimization of the execution body of the paradiigm defense framework.

[0150] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage, etc.) containing computer-usable program code.

[0151] The present application is described with reference to flowcharts and / or block diagrams according to the methods, devices (systems), and computer program products of the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices produce a device that implements the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.

[0152] These computer program instructions can also be stored in a computer-readable memory that can guide the computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction devices that implement the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.

[0153] These computer program instructions can also be loaded into a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart and / or block diagram block or blocks.

[0154] Finally, it should be noted that the above-mentioned embodiments are merely used to illustrate the technical solutions of the present application, but not to limit it. Although the present application has been described in detail with reference to the above-mentioned embodiments, those skilled in the art should understand that the specific embodiments of the present application can be modified or equivalent replaced without departing from the spirit and scope of the present application, and any modification or equivalent replacement without departing from the spirit and scope of the present application should be covered in the protection scope of the claims of the present application.

Claims

1. A method for execution body scheduling optimization of a mimicry defense framework, wherein, The method comprises the following steps: a plurality of execution body sets are constructed by using a plurality of execution bodies corresponding to the source program to be tested; heterogeneity of each execution body set and security defense coefficient of each execution body set are calculated; a scheduling function score of each execution body set is calculated by using the heterogeneity of each execution body set and the security defense coefficient of each execution body set, and a final scheduling object is determined according to the scheduling function score of each execution body set; the number of execution bodies scheduled from the final scheduling object each time is updated according to a judgment result of each execution body in the quasi-defense framework in the final scheduling object.

2. The method of claim 1, wherein, The plurality of execution body sets are constructed by using the plurality of execution bodies corresponding to the source program to be tested, which comprises: an execution body pool is constructed by using the plurality of execution bodies corresponding to the source program to be tested; a plurality of execution body sets are constructed by selecting a plurality of groups of execution bodies with a preset number from the execution body pool.

3. The method of claim 1, wherein, The heterogeneity of each execution body set is calculated, which comprises: the heterogeneity between each execution body in each execution body set is obtained by using a code similarity measurement method; the heterogeneity of each execution body set is calculated by using the heterogeneity between each execution body in each execution body set.

4. The method of claim 1, wherein, The security defense coefficient of each execution body set is calculated, which comprises: the security defense coefficient of each execution body in each execution body set is determined according to the output condition of each execution body in each execution body set; the security defense coefficient of each execution body set is calculated by using the security defense coefficient of each execution body in each execution body set. The final scheduling object is determined according to the scheduling function score of each execution body set, which comprises:

5. The method of claim 1, wherein, the execution body set corresponding to the smallest scheduling function score is selected as the final scheduling object from all the execution body sets. The number of execution bodies scheduled from the final scheduling object each time is updated according to a judgment result of each execution body in the quasi-defense framework in the final scheduling object, which comprises:

6. The method of claim 1, wherein, an output proportion of each type of judgment result is determined based on the judgment result of each execution body in the quasi-defense framework in the final scheduling object; output proportions of all types of judgment results are sorted in descending order, and a first-ranked output proportion is selected as a target output proportion; the number of execution bodies scheduled from the final scheduling object each time is updated by using the target output proportion. is an update factor.

7. The method of claim 1 or 3, wherein, The calculation formula of the heterogeneity of each set of executors includes: In the above formula, i ∈ [1, m], j ∈ [1, m], m is the total number of executors in the executor set; E i is the i th executor, E j is the j th executor, σ(E i , E j ) is the heterogeneity between the i th executor and the j th executor, and σ* is the heterogeneity of the executor set.

8. The method of claim 4, wherein, The calculation formula of the security defense coefficient of each execution body in each execution body set comprises: In the above formula, i∈[1, m], m is the total number of executors in the executor set; μ i μi is the current security defense coefficient of the i th executor in the executor set, i μi is the current security defense coefficient of the i th executor in the executor set, is the number of execution bodies scheduled from the final scheduling object in the t-1th scheduling by using the target output proportion of the t-1th scheduling.

9. The method of claim 1 or 4, wherein, The calculation formula of the security defense coefficient of each execution body set includes: In the above formula, i ∈ [1, m], m is the total number of executors in the executor set; μ i μi is the current security defense coefficient of the i th executor in the executor set, and μ* is the security defense coefficient of the executor set.

10. The method of claim 1, wherein, The calculation formula of the scheduling function score of each executor set includes: θ(E p ) = σ* + μ* In the above formula, θ (E p ) is the scheduling function score of the set of executors, σ* is the heterogeneity of the set of executors, and μ* is the security defense coefficient of the set of executors.

11. The method of claim 6, wherein, The calculation formula of the number of execution bodies scheduled from the final scheduling object each time the scheduling is performed includes: In the above formula, t e [1, T], T is the total number of scheduling; m(t) is the number of execution bodies scheduled from the final scheduling object at the tth scheduling, and a is a constant, target output ratio at the (t-2)th scheduling, The method comprises the following steps:

12. An execution body scheduling optimization apparatus for a quorum framework, wherein, a construction unit is configured to construct a plurality of execution body sets by using a plurality of execution bodies corresponding to the source program to be tested; a calculation unit is configured to calculate heterogeneity of each execution body set and security defense coefficient of each execution body set; a determination unit is configured to calculate a scheduling function score of each execution body set by using the heterogeneity of each execution body set and the security defense coefficient of each execution body set, and determine a final scheduling object according to the scheduling function score of each execution body set; an update unit is configured to update the number of execution bodies scheduled from the final scheduling object each time according to a judgment result of each execution body in the quasi-defense framework in the final scheduling object. The method comprises the following steps:

13. An electronic device, comprising: at least one processor and a memory; the memory and the processor are connected through a bus; ​ The memory is configured to store one or more programs; The one or more programs, when executed by the at least one processor, implement the method for scheduling optimization of an executor of a Quasi-Modular Defense Framework according to any one of claims 1-11.

14. A computer readable storage medium, wherein, The computer readable storage medium has an execution program stored thereon, and the execution program, when executed, implements the method for scheduling optimization of an executor of a Quasi-Modular Defense Framework according to any one of claims 1-11.

Citation Information

Patent Citations

  • Executive scheduling method for mimicry structure Web server

    CN110855692A

  • Mimicry API gateway implementation method and system based on mimicry defense thought

    CN116155584A

  • Mimic router execution entity scheduling method, and mimic router

    WO2021248740A1