Uncertain Scheduling for Network Security Defense
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security measures are ineffective in detecting and defending against unknown risks caused by design deficiencies (loopholes) or embedded trapdoors in network space architecture, as they only respond to detected attacks and fail to anticipate unknown vulnerabilities.
Innovation Solution
A software/hardware device with uncertain service function and structural characterization, comprising a policy generator, scheduler, and heterogeneous functional equivalents, which introduces an uncertain scheduling policy to dynamically assign and manage service responses, making it difficult for attackers to exploit static loopholes or trapdoors by creating uncertainty in service function and structural characterization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a static and determinate mapping relation is used between external structural form and internal structural form, then the device structure is simple and easy to implement, but the device becomes vulnerable to attacks through detected or utilized defects and trapdoors
Solution Approach 1:
The patent applies dynamics by transforming the static mapping relation between external structural form and internal structural form into a dynamic one. The scheduler dynamically selects different heterogeneous functional equivalents based on scheduling policies, causing the mapping relation to change over time. This dynamic characteristic prevents attackers from exploiting static vulnerabilities while maintaining system reliability.
Solution Approach 2:
The patent changes the parameter of structural characterization from fixed to variable. By introducing heterogeneous functional equivalents with different structural characteristics and using scheduling policies to select among them, the system parameters (structural form) are changed dynamically. This makes it difficult for attackers to detect or utilize defects based on static structural analysis.
2Measurement precision
If traditional defensive measures are used to accurately detect safety issues, then the detection precision is high, but the system can only respond to detected attacks and cannot defend against unknown risks in advance
Solution Approach 1:
The patent implements preliminary action by proactively introducing uncertainty into the system before attacks occur. The heterogeneous functional equivalents and scheduling policies are prepared in advance to create unpredictable behavior patterns. This preliminary uncertainty generation enables the system to defend against unknown risks before they are detected or exploited by attackers.
Solution Approach 2:
The patent converts the traditional approach of seeking deterministic security into a benefit by embracing uncertainty. Instead of trying to detect and eliminate all vulnerabilities, the system uses the uncertainty from heterogeneous functional equivalents to make vulnerability detection and exploitation difficult. This converts the potential harm of unpredictable behavior into a security benefit.
3Adaptability or versatility
If heterogeneous functional equivalents with scheduling policies are introduced to create uncertainty, then the ability to defend against unknown risks is improved, but the device complexity increases
Solution Approach 1:
The patent applies universality by designing heterogeneous functional equivalents that all provide the same service function but with different structural characteristics. This multi-functionality at the structural level (different implementations of the same function) allows the system to maintain service consistency while introducing uncertainty for security purposes, managing complexity through functional equivalence.
Data Source
AI summary
The present invention discloses a software/hardware device with uncertain service function and structural characterization and a method for scheduling the same. The device comprises a policy generator, a scheduler and a plurality of heterogeneous functional equivalents with equivalent functions, wherein, the policy generator is configured for providing a scheduling policy for the heterogeneous functional equivalents to the scheduler; the scheduler is configured for receiving an external service request, determining heterogeneous functional equivalents that provide a service to the external service request according to the scheduling policy given by the policy generator, assigning the service request to the determined heterogeneous functional equivalents, and outputting a service response which has an uncertain relation with uncertain structural characterization according to a feedback and the scheduling policy given by the policy generator. Therefore, the service response provided to the service request has an uncertain correspondence relation with feedback results of the heterogeneous functional equivalents of the device, so that the effectiveness of detection or attack on an unknown loophole, trapdoor of the device is greatly lowered, and the protective ability of the software/hardware device is enhanced.


