[go: up one dir, main page]

CN116668097A - Mimicry HSS network element signaling processing method and system - Google Patents

Mimicry HSS network element signaling processing method and system Download PDF

Info

Publication number
CN116668097A
CN116668097A CN202310559039.6A CN202310559039A CN116668097A CN 116668097 A CN116668097 A CN 116668097A CN 202310559039 A CN202310559039 A CN 202310559039A CN 116668097 A CN116668097 A CN 116668097A
Authority
CN
China
Prior art keywords
network element
heterogeneous
hss network
element signaling
target
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN202310559039.6A
Other languages
Chinese (zh)
Inventor
王三海
王桌培
樊建勇
李振华
孙统帅
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Zhuhai Comleader Information Technology Co Ltd
Original Assignee
Zhuhai Comleader Information Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Zhuhai Comleader Information Technology Co Ltd filed Critical Zhuhai Comleader Information Technology Co Ltd
Priority to CN202310559039.6A priority Critical patent/CN116668097A/en
Publication of CN116668097A publication Critical patent/CN116668097A/en
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/14Network analysis or design
    • H04L41/145Network analysis or design involving simulating, designing, planning or modelling of a network
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L65/00Network arrangements, protocols or services for supporting real-time applications in data packet communication
    • H04L65/10Architectures or entities
    • H04L65/1016IP multimedia subsystem [IMS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02DCLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D30/00Reducing energy consumption in communication networks
    • Y02D30/70Reducing energy consumption in communication networks in wireless communication networks

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Multimedia (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Computer And Data Communications (AREA)

Abstract

The application provides a method and a system for processing a mimicry HSS network element signaling, wherein the method comprises the following steps: receiving HSS network element signaling through the input agent distributor, and distributing the HSS network element signaling to a plurality of equivalent heterogeneous executors after copying a plurality of copies; carrying out service processing on the distributed HSS network element signaling through a plurality of equivalent heterogeneous executors, and inputting the obtained pending service processing result to the output proxy resolver; the output agent arbitrator performs mimicry arbitration according to a preset arbitration algorithm, and determines a target business processing result from a plurality of business processing results to be arbitrated. According to the technical scheme of the embodiment of the application, mimicry defense can be realized through a plurality of heterogeneous executors and resolvers, the security of HSS network element signaling is improved, and the network security is improved.

Description

拟态的HSS网元信令处理方法及系统Mimic HSS network element signaling processing method and system

技术领域technical field

本发明涉及网络安全技术领域,特别涉及一种拟态的HSS网元信令处理方法及系统。The present invention relates to the technical field of network security, in particular to a method and system for processing mimic HSS network element signaling.

背景技术Background technique

IP多媒体系统(IP Multimedia Subsystem,IMS)是移动与固网融合的重要解决方案,是引入语音、数据、视频等融合的差异化业务的重要方式,其安全性是网络安全建设中的重要一环。IMS引入了归属签约用户服务器(Home Subscriber Server,HSS)功能实体,HSS负责固定、移动宽窄带各种类型接入用户的签约数据的管理维护,支持IMS业务用户IMS数据存储、认证、鉴权和寻址功能。IP Multimedia System (IP Multimedia Subsystem, IMS) is an important solution for the convergence of mobile and fixed networks. It is an important way to introduce differentiated services that integrate voice, data, and video. Its security is an important part of network security construction. . IMS introduces the Home Subscriber Server (HSS) functional entity. HSS is responsible for the management and maintenance of subscription data of various types of fixed and mobile broadband and narrowband access users, and supports IMS service user IMS data storage, authentication, authentication and addressing function.

随着IMS核心网网络部署应用的发展,针对IMS核心网的攻击频率越来越高,尤其是当攻击者利用IMS核心网元设备的未知漏洞和未知后门进行攻击时,使得传统的防范手段形同虚设,HSS网元信令的安全性无法得到保障,对网络信息安全造成重大隐患。With the development of IMS core network network deployment and application, the frequency of attacks against IMS core network is getting higher and higher, especially when attackers use unknown vulnerabilities and unknown backdoors of IMS core network element equipment to attack, making traditional defense methods useless , the security of HSS network element signaling cannot be guaranteed, causing major hidden dangers to network information security.

发明内容Contents of the invention

本发明旨在至少解决现有技术中存在的技术问题之一。为此,本发明提出一种拟态的HSS网元信令处理方法及系统,能够提高HSS网元信令的可靠性和安全性,实现拟态防御。The present invention aims to solve at least one of the technical problems existing in the prior art. Therefore, the present invention proposes a mimic HSS network element signaling processing method and system, which can improve the reliability and security of HSS network element signaling and realize mimic defense.

第一方面,本发明实施例提供了一种拟态的HSS网元信令处理方法,应用于拟态的HSS网元信令处理系统,所述拟态的HSS网元信令处理系统包括输入代理分发器、多个等价异构执行体和输出代理裁决器,所述输入代理分发器与HSS网元通信连接,多个所述等价异构执行体的执行体架构不同但业务处理功能相同,所述拟态的HSS网元信令处理方法包括:In the first aspect, the embodiment of the present invention provides a mimic HSS network element signaling processing method, which is applied to a mimic HSS network element signaling processing system, and the mimic HSS network element signaling processing system includes an input agent distributor , a plurality of equivalent heterogeneous executives and an output proxy arbiter, the input proxy distributor communicates with the HSS network element, and the plurality of equivalent heterogeneous executives have different executive structures but the same service processing functions, so The simulated HSS network element signaling processing method includes:

通过所述输入代理分发器接收HSS网元信令,将所述HSS网元信令复制多份后分发到多个所述等价异构执行体;receiving the HSS network element signaling through the input agent distributor, and distributing the multiple copies of the HSS network element signaling to multiple equivalent heterogeneous execution bodies;

通过多个所述等价异构执行体对被分发的所述HSS网元信令进行业务处理,并将得到的待裁决业务处理结果输入至所述输出代理裁决器;Perform service processing on the distributed HSS network element signaling through multiple equivalent heterogeneous executives, and input the obtained pending service processing results to the output proxy arbiter;

所述输出代理裁决器根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果。The output proxy arbiter performs a pseudo-arbitration according to a preset adjudication algorithm, and determines a target business processing result from a plurality of pending business processing results.

根据本发明的一些实施例,所述执行体架构包括宿主机和虚拟机,不同的所述等价异构执行体的所述宿主机的硬件和操作系统不同,不同的所述等价异构执行体的所述虚拟机的操作系统平台不同,所述将所述HSS网元信令复制多份后分发到多个所述等价异构执行体,包括:According to some embodiments of the present invention, the execution body architecture includes a host machine and a virtual machine, and the hardware and operating system of the host machines of different equivalent heterogeneous execution bodies are different, and the different equivalent heterogeneous execution bodies The operating system platforms of the virtual machines of the execution body are different, and the multiple copies of the HSS network element signaling are distributed to multiple equivalent heterogeneous execution bodies, including:

从多个所述等价异构执行体中确定多个目标异构执行体;determining a plurality of target heterogeneous executables from a plurality of equivalent heterogeneous executables;

根据所述目标异构执行体的数量复制多份所述HSS网元信令;Duplicating multiple copies of the HSS network element signaling according to the number of target heterogeneous executables;

向每个所述目标异构执行体分发所述HSS网元信令。Distributing the HSS network element signaling to each of the target heterogeneous execution entities.

根据本发明的一些实施例,在所述通过所述输入代理分发器接收HSS网元信令之前,所述方法还包括:According to some embodiments of the present invention, before receiving the HSS network element signaling through the input proxy distributor, the method further includes:

获取预设的历史参考置信度,所述历史参考置信度归属于历史参考异构执行体;Obtaining a preset historical reference confidence degree, which belongs to the historical reference heterogeneous execution entity;

基于所述历史参考异构执行体的所述执行体架构与所述等价异构执行体的所述执行体架构之间的相似程度,确定所述等价异构执行体的初始置信度。Based on the degree of similarity between the execution body architecture of the historical reference heterogeneous execution body and the execution body architecture of the equivalent heterogeneous execution body, an initial confidence degree of the equivalent heterogeneous execution body is determined.

根据本发明的一些实施例,所述输出代理裁决器根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果,包括:According to some embodiments of the present invention, the output agent arbiter performs mimicry adjudication according to a preset adjudication algorithm, and determines a target business processing result from a plurality of pending adjudication business processing results, including:

获取所述目标异构执行体发送的目标置信度,所述目标置信度是基于所述初始置信度迭代多次历史拟态裁决的裁决信息得到的,所述裁决信息用于指示所述目标异构执行体进行拟态裁决时的安全态势、系统资源状况、异常处理结果、被攻击的频率和历史裁决结果;Acquiring the target confidence degree sent by the target heterogeneous executive body, the target confidence degree is obtained by iterating multiple times of historical mimicry judgment judgment information based on the initial confidence degree, and the judgment information is used to indicate that the target is heterogeneous The security situation, system resource status, exception handling results, attack frequency and historical judgment results of the executive body when performing mimicry judgment;

基于多个所述目标异构执行体确定多个执行体集合,归属于同一个所述执行体集合的所述目标异构执行体所输出的所述待裁决业务处理结果相同;Determining a plurality of executive body sets based on a plurality of said target heterogeneous executive bodies, and said pending business processing results output by said target heterogeneous executive bodies belonging to the same said executive body set are the same;

将所述执行体集合中全部的所述目标异构执行体的所述目标置信度之和确定为集合置信度;determining the sum of the target confidences of all the target heterogeneous executions in the execution set as the set confidence;

将所述集合置信度最大的所述执行体集合所对应的所述待裁决业务处理结果裁决为所述目标业务处理结果。arbitrating the pending service processing result corresponding to the executive set with the highest set confidence as the target service processing result.

根据本发明的一些实施例,在所述从多个所述待裁决业务处理结果中确定目标业务处理结果之后,所述方法还包括:According to some embodiments of the present invention, after the determination of the target business processing result from the multiple pending business processing results, the method further includes:

保存本次拟态裁决的裁决信息;Save the ruling information of this mimicry ruling;

基于预设周期,所述目标异构执行体根据保存的所述裁决信息和当前的所述目标置信度进行加权迭代,得到新的目标置信度。Based on a preset period, the target heterogeneous executive executes weighted iterations according to the saved ruling information and the current target confidence to obtain a new target confidence.

根据本发明的一些实施例,所述拟态的HSS网元信令处理系统还包括反馈控制器和拟态调度模块,在所述从多个所述待裁决业务处理结果中确定目标业务处理结果之后,所述方法还包括:According to some embodiments of the present invention, the mimic HSS network element signaling processing system further includes a feedback controller and a mimic scheduling module, after determining the target service processing result from the plurality of pending service processing results, The method also includes:

所述输出代理裁决器将本次拟态裁决的裁决信息发送至所述反馈控制器;The output proxy arbiter sends the adjudication information of this mimicry adjudication to the feedback controller;

当所述反馈控制器根据所述本次拟态裁决的裁决信息确定出至少一个异常异构执行体,生成第一调度策略和第二调度策略;When the feedback controller determines at least one abnormal heterogeneous executive according to the ruling information of the current mimicry ruling, generating a first scheduling strategy and a second scheduling strategy;

将所述第一调度策略发送至所述拟态调度模块,所述拟态调度模块根据所述第一调度策略控制所述异常异构执行体下线和清理;Send the first scheduling policy to the mimic scheduling module, and the mimic scheduling module controls the abnormal heterogeneous executive body to go offline and clean up according to the first scheduling policy;

将所述第二调度策略发送至所述输入代理分发器,所述输入代理分发器根据所述第二调度策略从可选的所述等价异构执行体中删除所述异常异构执行体。sending the second scheduling strategy to the input proxy distributor, and the input proxy distributor deletes the abnormal heterogeneous execution body from the optional equivalent heterogeneous execution body according to the second scheduling strategy .

根据本发明的一些实施例,在所述拟态调度模块根据所述第一调度策略控制所述异常异构执行体下线和清理之前,所述方法还包括:According to some embodiments of the present invention, before the mimic scheduling module controls the offline and cleanup of the abnormal heterogeneous execution body according to the first scheduling policy, the method further includes:

确定所述异常异构执行体所承载的业务执行完毕;Determine that the execution of the business carried by the abnormal heterogeneous executable is completed;

或者,将所述异常异构执行体所承载的业务调度到无异常的所述等价异构执行体。Or, dispatch the service carried by the abnormal heterogeneous executable to the equivalent heterogeneous executable without abnormality.

第二方面,本发明实施例提供了一种拟态的HSS网元信令处理系统,用于执行如第一方面所述的拟态的HSS网元信令处理方法,所述拟态的HSS网元信令处理系统包括:In the second aspect, the embodiment of the present invention provides a mimic HSS network element signaling processing system, which is used to execute the mimic HSS network element signaling processing method as described in the first aspect, the mimic HSS network element signaling Order processing systems include:

输入代理分发器,用于接收HSS网元信令,将所述HSS网元信令复制多份后分发到多个等价异构执行体;The input agent distributor is used to receive the HSS network element signaling, and distribute the HSS network element signaling to multiple equivalent heterogeneous execution bodies after copying multiple copies;

等价异构执行体,用于对被分发的所述HSS网元信令进行业务处理,并将得到的待裁决业务处理结果输入至输出代理裁决器,其中,多个所述等价异构执行体的执行体架构不同但业务处理功能相同;The equivalent heterogeneous executor is used to perform service processing on the distributed HSS network element signaling, and input the obtained service processing results to be adjudicated to the output proxy arbiter, wherein a plurality of the equivalent heterogeneous The executive structure of the executive body is different but the business processing function is the same;

输出代理裁决器,用于根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果。The output proxy arbiter is configured to perform mimicry adjudication according to a preset adjudication algorithm, and determine a target business processing result from a plurality of pending adjudication business processing results.

第三方面,本发明实施例提供了一种拟态的HSS网元信令处理装置,包括少一个控制处理器和用于与所述至少一个控制处理器通信连接的存储器,所述存储器存储有可被所述至少一个控制处理器执行的指令,所述指令被所述至少一个控制处理器执行,以使所述至少一个控制处理器能够执行如上述第一方面所述的拟态的HSS网元信令处理方法,或者,包括如第二方面所述的拟态的HSS网元信令处理系统。In the third aspect, the embodiment of the present invention provides a pseudomorphic HSS network element signaling processing device, including one less control processor and a memory for communicating with the at least one control processor, and the memory stores data that can Instructions executed by the at least one control processor, the instructions are executed by the at least one control processor, so that the at least one control processor can execute the simulated HSS network element information as described in the first aspect The signaling processing method, or, including the pseudo-HSS network element signaling processing system as described in the second aspect.

第四方面,本发明实施例提供了一种计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令用于执行如上述第一方面所述的拟态的HSS网元信令处理方法。In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to perform the pseudo-HSS network element signaling processing as described in the first aspect. method.

根据本发明实施例的拟态的HSS网元信令处理方法,至少具有如下有益效果:通过所述输入代理分发器接收HSS网元信令,将所述HSS网元信令复制多份后分发到多个所述等价异构执行体;通过多个所述等价异构执行体对被分发的所述HSS网元信令进行业务处理,并将得到的待裁决业务处理结果输入至所述输出代理裁决器;所述输出代理裁决器根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果。根据本发明实施例的技术方案,能够通过多个异构化的执行体和裁决器实现拟态防御,提高了HSS网元信令的安全性,提高网络安全。The mimic HSS network element signaling processing method according to the embodiment of the present invention has at least the following beneficial effects: the HSS network element signaling is received by the input agent distributor, and multiple copies of the HSS network element signaling are distributed to a plurality of said equivalent heterogeneous executive bodies; through said plurality of said equivalent heterogeneous executive bodies, the distributed said HSS network element signaling is processed, and the obtained service processing results to be adjudicated are input into said An output proxy arbiter; the output proxy arbiter performs a mimetic arbitration according to a preset arbitration algorithm, and determines a target business processing result from a plurality of pending business processing results. According to the technical solution of the embodiment of the present invention, mimic defense can be realized through multiple heterogeneous execution bodies and arbitrators, which improves the security of HSS network element signaling and network security.

附图说明Description of drawings

图1是本发明一个实施例提供的拟态的HSS信令处理系统的结构示意图;FIG. 1 is a schematic structural diagram of a mimic HSS signaling processing system provided by an embodiment of the present invention;

图2是本发明一个实施例提供的拟态的HSS网元信令处理方法的流程图;FIG. 2 is a flow chart of a pseudo-HSS network element signaling processing method provided by an embodiment of the present invention;

图3是本发明另一个实施例提供的确定目标异构执行体的流程图;Fig. 3 is a flow chart of determining a target heterogeneous executive provided by another embodiment of the present invention;

图4是本发明另一个实施例提供的确定初始置信度的流程图;Fig. 4 is a flow chart of determining the initial confidence provided by another embodiment of the present invention;

图5是本发明另一个实施例提供的拟态裁决的流程图;Fig. 5 is a flowchart of a mimetic ruling provided by another embodiment of the present invention;

图6是本发明另一个实施例提供的更新置信度的流程图;Fig. 6 is a flow chart of updating confidence provided by another embodiment of the present invention;

图7是本发明另一个实施例提供的删除异常异构执行体的流程图;Fig. 7 is a flow chart of deleting an abnormal heterogeneous executable provided by another embodiment of the present invention;

图8是本发明另一个实施例提供的删除异常异构执行体之前确保业务不受影响的流程图;Fig. 8 is a flow chart of ensuring that services are not affected before deleting abnormal heterogeneous executives provided by another embodiment of the present invention;

图9是本发明另一个实施例提供的拟态的HSS网元信令处理装置的结构图。Fig. 9 is a structural diagram of an apparatus for processing signaling of a simulated HSS network element provided by another embodiment of the present invention.

具体实施方式Detailed ways

下面详细描述本发明的实施例,所述实施例的示例在附图中示出,其中自始至终相同或类似的标号表示相同或类似的元件或具有相同或类似功能的元件。下面通过参考附图描述的实施例是示例性的,仅用于解释本发明,而不能理解为对本发明的限制。Embodiments of the present invention are described in detail below, examples of which are shown in the drawings, wherein the same or similar reference numerals designate the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the figures are exemplary only for explaining the present invention and should not be construed as limiting the present invention.

在本发明的描述中,需要理解的是,涉及到方位描述,例如上、下、前、后、左、右等指示的方位或位置关系为基于附图所示的方位或位置关系,仅是为了便于描述本发明和简化描述,而不是指示或暗示所指的装置或元件必须具有特定的方位、以特定的方位构造和操作,因此不能理解为对本发明的限制。In the description of the present invention, it should be understood that the orientation descriptions, such as up, down, front, back, left, right, etc. indicated orientations or positional relationships are based on the orientations or positional relationships shown in the drawings, and are only In order to facilitate the description of the present invention and simplify the description, it does not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as limiting the present invention.

在本发明的描述中,若干的含义是一个或者多个,多个的含义是两个以上,大于、小于、超过等理解为不包括本数,以上、以下、以内等理解为包括本数。如果有描述到第一、第二只是用于区分技术特征为目的,而不能理解为指示或暗示相对重要性或者隐含指明所指示的技术特征的数量或者隐含指明所指示的技术特征的先后关系。In the description of the present invention, several means one or more, and multiple means more than two. Greater than, less than, exceeding, etc. are understood as not including the original number, and above, below, within, etc. are understood as including the original number. If the description of the first and second is only for the purpose of distinguishing the technical features, it cannot be understood as indicating or implying the relative importance or implicitly indicating the number of the indicated technical features or implicitly indicating the order of the indicated technical features relation.

本发明的描述中,除非另有明确的限定,设置、安装、连接等词语应做广义理解,所属技术领域技术人员可以结合技术方案的具体内容合理确定上述词语在本发明中的具体含义。In the description of the present invention, unless otherwise clearly defined, words such as setting, installation, and connection should be understood in a broad sense, and those skilled in the art can reasonably determine the specific meanings of the above words in the present invention in combination with the specific content of the technical solution.

本发明实施例提供了一种拟态的HSS网元信令处理方法及系统,其中,拟态的HSS网元信令处理方法包括:通过所述输入代理分发器接收HSS网元信令,将所述HSS网元信令复制多份后分发到多个所述等价异构执行体;通过多个所述等价异构执行体对被分发的所述HSS网元信令进行业务处理,并将得到的待裁决业务处理结果输入至所述输出代理裁决器;所述输出代理裁决器根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果。根据本发明实施例的技术方案,能够通过多个异构化的执行体和裁决器实现拟态防御,提高了HSS网元信令的安全性,提高网络安全。Embodiments of the present invention provide a mimic HSS network element signaling processing method and system, wherein the mimic HSS network element signaling processing method includes: receiving the HSS network element signaling through the input proxy distributor, and converting the The HSS network element signaling is copied in multiple copies and distributed to multiple equivalent heterogeneous executives; the distributed HSS network element signaling is processed through multiple equivalent heterogeneous executives, and The obtained business processing results to be adjudicated are input to the output proxy arbiter; the output proxy arbiter performs pseudo-judgment according to a preset ruling algorithm, and determines the target business processing result from a plurality of the pending business processing results. According to the technical solution of the embodiment of the present invention, mimic defense can be realized through multiple heterogeneous execution bodies and arbitrators, which improves the security of HSS network element signaling and network security.

首先,对本发明的拟态的HSS网元信令处理系统的结构进行示例性说明,本示例并非对系统的结构做出的限定,而是可以执行本发明技术方案的一个具体实施环境,参照图1,图1为本发明提供的拟态的HSS网元信令处理系统的结构示意图,该系统包括输入代理分发器100、多个等价异构执行体101、输出代理裁决器102、反馈控制器103和拟态调度模块104,输入代理分发器100与HSS网元通信连接。First, the structure of the simulated HSS network element signaling processing system of the present invention is exemplified. This example does not limit the structure of the system, but a specific implementation environment that can implement the technical solution of the present invention. Refer to FIG. 1 , FIG. 1 is a schematic structural diagram of a mimic HSS network element signaling processing system provided by the present invention, the system includes an input agent distributor 100, a plurality of equivalent heterogeneous executive bodies 101, an output agent arbiter 102, and a feedback controller 103 and the mimetic dispatching module 104, the input agent distributor 100 is communicatively connected with the HSS network element.

在一些实施例中,输入代理分发器100用于在接收到业务信令时,将接收到的信令消息复制成多份,并将信令分发到多个等价异构执行体101中;等价异构执行体101用于对信令消息进行业务处理,并输出处理结果发给输出代理裁决器102;输出代理裁决器102利用裁决算法将等价异构执行体101的处理结果进行拟态裁决,输出最终执行结果,并将判决信息输出到反馈控制器103;反馈控制器103根据裁决信息向拟态调度模块104发送第一调度策略和清洗指令,拟态调度模块104对本次参与拟态裁决的异构进行执行体清洗;反馈控制器103同时发送第二调度策略给输入代理分发器100,将表现异常的等价异构执行体101从代理分发器100的分发集合中删除;拟态调度模块104用于接收反馈控制器103的指令,基于调度算法对等价异构执行体101进行动态操作,包括等价异构执行体101的调度,异常状态的等价异构执行体101的清洗操作。In some embodiments, the input proxy distributor 100 is configured to, when receiving service signaling, copy the received signaling message into multiple copies, and distribute the signaling to multiple equivalent heterogeneous execution entities 101; The equivalent heterogeneous executor 101 is used to perform business processing on the signaling message, and output the processing result to the output proxy arbiter 102; the output proxy arbiter 102 simulates the processing result of the equivalent heterogeneous executor 101 by using the arbitration algorithm Judgment, output the final execution result, and output the judgment information to the feedback controller 103; the feedback controller 103 sends the first scheduling strategy and cleaning instructions to the mimetic scheduling module 104 according to the ruling information, and the mimetic scheduling module 104 is responsible for this time. Heterogeneous execution body cleaning; the feedback controller 103 sends the second scheduling policy to the input agent distributor 100 at the same time, and deletes the equivalent heterogeneous execution body 101 that behaves abnormally from the distribution set of the agent distributor 100; the mimetic scheduling module 104 It is used to receive instructions from the feedback controller 103 and perform dynamic operations on the equivalent heterogeneous executors 101 based on the scheduling algorithm, including the scheduling of the equivalent heterogeneous executors 101 and the cleaning operation of the equivalent heterogeneous executors 101 in an abnormal state.

示例性地,多个等价异构执行体101的执行体架构不同但业务处理功能相同,拟态的HSS网元信令处理系统部署了N个异构平台的宿主机,N为大于1的自然数,宿主机S={Sm|m=1,2,...M},其中Sm为第m个宿主机,其中,每个宿主机进行了硬件和操作系统异构化,硬件架构可以是X86或者ARM,操作系统可以是Centos、Ubuntu、Debian或Kylin;每个宿主机上部署了不同操作系统平台下的虚拟机,虚拟机K={Kn|n=1,2,...N},其中Kn为第n个虚拟机,虚拟机的虚拟化技术可以是KVM,容器化技术可以是Docker。在上述基础上,等价异构执行体101为第m个宿主机上的第n个虚拟机,执行体T={Tmn|m=1,2,...M;n=1,2,...N},其中Tmn为第m个宿主机上的第n个虚拟机。Exemplarily, multiple equivalent heterogeneous executive bodies 101 have different executive body structures but have the same service processing function, and the mimic HSS network element signaling processing system deploys N host machines of heterogeneous platforms, where N is a natural number greater than 1 , the host S={S m |m=1,2,...M}, where S m is the mth host, where each host is heterogeneous in hardware and operating system, and the hardware architecture can be It is X86 or ARM, and the operating system can be Centos, Ubuntu, Debian or Kylin; virtual machines under different operating system platforms are deployed on each host, and virtual machines K={K n |n=1,2,... N}, where K n is the nth virtual machine, the virtualization technology of the virtual machine can be KVM, and the containerization technology can be Docker. On the basis of the above, the equivalent heterogeneous executable body 101 is the nth virtual machine on the mth host machine, and the executable body T={T mn |m=1,2,...M; n=1,2 ,...N}, where T mn is the nth virtual machine on the mth host.

下面基于附图1所示的拟态的HSS网元信令处理系统,对本发明实施例的控制方法作进一步阐述。The control method of the embodiment of the present invention will be further described below based on the mimic HSS network element signaling processing system shown in FIG. 1 .

参照图2,图2为本发明实施例提供的一种拟态的HSS网元信令处理方法的流程图,该拟态的HSS网元信令处理方法包括但不限于有以下步骤:Referring to FIG. 2, FIG. 2 is a flow chart of a pseudo HSS network element signaling processing method provided by an embodiment of the present invention. The pseudo HSS network element signaling processing method includes but is not limited to the following steps:

S21,通过输入代理分发器接收HSS网元信令,将HSS网元信令复制多份后分发到多个等价异构执行体;S21, receiving the HSS network element signaling through the input agent distributor, copying multiple copies of the HSS network element signaling and distributing it to multiple equivalent heterogeneous execution bodies;

S22,通过多个等价异构执行体对被分发的HSS网元信令进行业务处理,并将得到的待裁决业务处理结果输入至输出代理裁决器;S22. Perform service processing on the distributed HSS network element signaling through multiple equivalent heterogeneous executives, and input the obtained pending service processing results to the output proxy arbiter;

S23,输出代理裁决器根据预设的裁决算法进行拟态裁决,从多个待裁决业务处理结果中确定目标业务处理结果。S23. The output agent arbiter performs a pseudo-award according to a preset adjudication algorithm, and determines a target service processing result from multiple pending service processing results.

需要说明的是,当输入代理分发器获取到HSS网元信令,将其复制多份分发到多个等价异构执行体,基于上述系统结构的描述,等价异构执行体的功能相同,但是架构不同,使得每个等价异构执行体的安全性、资源情况、被攻击情况不同,因此能够在同样的输入的情况下得到不同的输出,从而实现不同硬件下业务处理结果的模拟。It should be noted that when the input agent distributor obtains the HSS network element signaling, it copies and distributes it to multiple equivalent heterogeneous executives. Based on the description of the above system structure, the functions of the equivalent heterogeneous executives are the same , but the architecture is different, so that the security, resource conditions, and attack conditions of each equivalent heterogeneous execution body are different, so different outputs can be obtained under the same input conditions, so as to realize the simulation of business processing results under different hardware .

需要说明的是,输出代理裁决器获取到多个待裁决业务处理结果后,根据预设的裁决算法进行拟态裁决,从而得到最终的输出响应,裁决算法可以对多个等价异构执行体进行拟态裁决,预设的裁决算法,确定最终的目标业务处理结果,裁决算法可以是针对等价异构执行体的当前的安全态势、系统资源状况、异常处理结果、被攻击的频率和执行体的历史表现等信息加权参数进行迭代判定裁决。通过本实施例的技术方案,能够通过多个等价异构执行体进行业务处理的模拟,通过输出代理裁决器进行拟态裁决,对HSS网元信令的不同处理场景进行了拟态模拟,从而得到最优的业务处理结果,能够实现拟态防御,提高HSS网元信令的安全性。It should be noted that after the output proxy arbiter obtains multiple business processing results to be adjudicated, it performs a mimetic adjudication according to the preset adjudication algorithm to obtain the final output response. The adjudication algorithm can perform multiple equivalent heterogeneous execution bodies Mimic adjudication, a preset adjudication algorithm, determines the final target business processing result. The adjudication algorithm can be based on the current security situation, system resource status, abnormal processing results, attack frequency and execution body's performance of the equivalent heterogeneous executive body. Information weighting parameters such as historical performance are used to iteratively judge and adjudicate. Through the technical solution of this embodiment, it is possible to simulate service processing through multiple equivalent heterogeneous executives, and perform mimicry arbitration through the output proxy arbiter, and simulate different processing scenarios of HSS network element signaling, thereby obtaining The optimal service processing results can realize mimic defense and improve the security of HSS network element signaling.

另外,在一实施例中,参照图3,图2所示的步骤S22还包括但不限于有以下步骤:In addition, in one embodiment, referring to FIG. 3, step S22 shown in FIG. 2 also includes but is not limited to the following steps:

S31,从多个等价异构执行体中确定多个目标异构执行体;S31. Determine multiple target heterogeneous executables from multiple equivalent heterogeneous executables;

S32,根据目标异构执行体的数量复制多份HSS网元信令;S32, copy multiple copies of HSS network element signaling according to the number of target heterogeneous executables;

S33,向每个目标异构执行体分发HSS网元信令。S33. Distribute the HSS network element signaling to each target heterogeneous executive.

需要说明的是,由于等价异构执行体的数量可以是多个,因此输入代理分发器可以根据实际的拟态需求确定具体的数量,例如,在具体分发选择执行体时,输入代理分发器已知等价异构执行体的配置方式,因此在输入代理分发器中具备执行体池T={Tmn|m=1,2,...M;n=1,2,...N},其中,M为宿主机的数量,N为虚拟机的数量;输入代理分发器动态地从执行体池中选择k个目标异构执行体进行工作,目标异构执行体可以表示为其中i≤m,j≤n,k的具体数值可以根据实际情况需求调整,例如为了提高安全性将全部的等价异构执行体确定为目标异构执行体,又或者,为了节约资源仅采用若干个作为目标异构执行体,本实施例对k的具体数值不做限定,k为大于1的自然数即可。It should be noted that since the number of equivalent heterogeneous executives can be multiple, the input agent distributor can determine the specific number according to the actual mimicry requirements. For example, when selecting an executive body for specific distribution, the input agent distributor has already Know the configuration method of equivalent heterogeneous executives, so there is an executive pool T={T mn |m=1,2,...M; n=1,2,...N} in the input agent distributor , where M is the number of host machines, N is the number of virtual machines; the input agent distributor dynamically selects k target heterogeneous executives from the executive pool to work, and the target heterogeneous executives can be expressed as Among them, i≤m, j≤n, and the specific value of k can be adjusted according to the actual situation. For example, in order to improve security, all equivalent heterogeneous executives are determined as target heterogeneous executives, or, in order to save resources, only Several are used as target heterogeneous executables. The specific value of k is not limited in this embodiment, and k may be a natural number greater than 1.

需要说明的是,在确定k个目标异构执行体后,输入代理分发器将获取到的HSS网元信令复制成k份,向每个目标异构执行体发送一份HSS网元信令,使得每个目标异构执行体的输入相同,由它们对同一个输入进行处理后得到k个待裁决业务处理结果。It should be noted that after determining k target heterogeneous executives, the input agent distributor copies the obtained HSS network element signaling into k shares, and sends a copy of HSS network element signaling to each target heterogeneous executive , so that the input of each target heterogeneous executive is the same, and k business processing results to be adjudicated are obtained after they process the same input.

另外,在一实施例中,参照图4,在执行图2所示的步骤S21之前,方法还包括但不限于有以下步骤:In addition, in one embodiment, referring to FIG. 4, before performing step S21 shown in FIG. 2, the method further includes but is not limited to the following steps:

S41,获取预设的历史参考置信度,历史参考置信度归属于历史参考异构执行体;S41. Obtain a preset historical reference confidence degree, which belongs to the historical reference heterogeneous execution body;

S42,基于历史参考异构执行体的执行体架构与等价异构执行体的执行体架构之间的相似程度,确定等价异构执行体的初始置信度。S42. Based on the degree of similarity between the execution body structure of the historical reference heterogeneous execution body and the execution body structure of the equivalent heterogeneous execution body, determine an initial confidence degree of the equivalent heterogeneous execution body.

需要说明的是,为了实现拟态裁决,可以以每个等价异构执行体的置信度作为裁决依据,置信度越高的等价异构执行体的业务处理结果越可信,安全性越高。基于此,可以在系统初始化阶段,根据等价异构执行体的硬件架构、系统平台和历史参考置信度将等价异构执行体的初始置信度确定为{ω12,...ωM}。例如,等价异构执行体为配置有不同虚拟机的宿主机,因此可以从历史信息中查询具有相同架构的历史参考异构执行体,在架构相似的情况下,其安全态势、被攻击的频率、资源状况、异常处理结果具有一定的相似之处,将对应的历史参考置信度确定为初始置信度,使得等价异构执行体能够向输出代理裁决器提供初始的拟态裁决依据。It should be noted that in order to realize the mimetic judgment, the confidence degree of each equivalent heterogeneous executive body can be used as the basis for the judgment. The higher the confidence degree is, the more credible the business processing results of the equivalent heterogeneous executive body are, and the higher the security is. . Based on this, the initial confidence of the equivalent heterogeneous executable can be determined as {ω 12 ,... ωM }. For example, the equivalent heterogeneous execution body is a host machine configured with different virtual machines, so the historical reference heterogeneous execution body with the same architecture can be queried from the historical information. The frequency, resource status, and exception handling results have certain similarities, and the corresponding historical reference confidence is determined as the initial confidence, so that the equivalent heterogeneous executive can provide the output proxy arbiter with an initial basis for mimetic adjudication.

另外,在一实施例中,参照图5,图2所示的步骤S23还包括但不限于有以下步骤:In addition, in one embodiment, referring to FIG. 5, step S23 shown in FIG. 2 also includes but is not limited to the following steps:

S51,获取目标异构执行体发送的目标置信度,目标置信度是基于初始置信度迭代多次历史拟态裁决的裁决信息得到的,裁决信息用于指示目标异构执行体进行拟态裁决时的安全态势、系统资源状况、异常处理结果、被攻击的频率和历史裁决结果;S51. Obtain the target confidence degree sent by the target heterogeneous executive body. The target confidence degree is obtained by iterating the judgment information of multiple historical mimicry judgments based on the initial confidence degree. The judgment information is used to indicate the security of the target heterogeneous executive body when performing the mimicry judgment. Situation, system resource status, exception handling results, frequency of attacks and historical verdict results;

S52,基于多个目标异构执行体确定多个执行体集合,归属于同一个执行体集合的目标异构执行体所输出的待裁决业务处理结果相同;S52. Determine multiple execution body sets based on multiple target heterogeneous execution bodies, and the target heterogeneous execution bodies belonging to the same execution body set output the same business processing results to be adjudicated;

S53,将执行体集合中全部的目标异构执行体的目标置信度之和确定为集合置信度;S53. Determine the sum of the target confidences of all target heterogeneous executables in the execution set as the set confidence;

S54,将集合置信度最大的执行体集合所对应的待裁决业务处理结果裁决为目标业务处理结果。S54. Adjudicate the pending service processing result corresponding to the executive set with the largest set confidence as the target service processing result.

需要说明的是,根据上述实施例的描述,在具备初始置信度后,系统可以执行HSS网元信令的拟态裁决,根据每一次的拟态裁决所产生的裁决信息对等价异构执行体的置信度进行迭代,能够有效提高置信度的准确性。裁决信息可以是对裁决结果有影响的因素,例如进行拟态裁决时的安全态势、系统资源状况、异常处理结果、被攻击的频率和历史裁决结果,本领域技术人员也可以根据实际需求增加或者减少裁决信息的内容,在此不多做限定。在获取到裁决信息后,可以为裁决信息的每个参数设置加权系数,在当前的置信度的基础上进行加权迭代,从而对置信度进行更新。值得注意的是,置信度的取值区间为[0,1],后续不重复赘述。It should be noted that, according to the description of the above-mentioned embodiments, after the initial confidence is obtained, the system can execute the mimic ruling of the HSS network element signaling, and the judgment information of the equivalent heterogeneous execution body can be determined according to the ruling information generated by each mimic ruling. The confidence level can be iterated to effectively improve the accuracy of the confidence level. Ruling information can be factors that have an impact on the ruling result, such as the security situation, system resource status, exception handling results, frequency of attacks, and historical ruling results when performing mimicry rulings. Those skilled in the art can also increase or decrease according to actual needs The content of the ruling information is not limited here. After the ruling information is obtained, a weighting coefficient can be set for each parameter of the ruling information, and weighted iterations can be performed on the basis of the current confidence level, so as to update the confidence level. It is worth noting that the value interval of the confidence degree is [0,1], which will not be repeated hereafter.

需要说明的是,为了实现拟态裁决,本实施例的裁决算法为对处理结果相同的置信度进行叠加,目标异构执行体为选取出进行业务处理模拟的等价异构执行体,虽然每个目标异构执行体在架构上有不同,但是也可能出现至少两个目标异构执行体输出的待裁决业务处理结果相同,示例性的,若此刻有2x+1个目标异构执行体运行,首先将输出结果一致的目标异构执行体划分为一个执行体集合Gk,得到执行体集合的序列{G1,G2,...GK,...},K为自然数,oi=oj,/>且,∑|GK|=2x+1,fi表示第i个目标异构执行体,fj表示第j个目标异构执行体,o为目标置信度,/>为实数。在此基础上,计算每个执行体集合Gk的集合置信度/>再将将集合置信度最大的执行体集合所对应的待裁决业务处理结果裁决为目标业务处理结果,从而完成拟态裁决。It should be noted that, in order to realize the mimetic ruling, the ruling algorithm in this embodiment is to superimpose the same confidence degree of the processing results, and the target heterogeneous executive is the equivalent heterogeneous executive selected for business processing simulation, although each The target heterogeneous executors are different in architecture, but at least two target heterogeneous executors may output the same pending business processing results. For example, if there are 2x+1 target heterogeneous executors running at the moment, Firstly, divide the target heterogeneous executives with consistent output results into an executive set G k , and obtain the sequence {G 1 , G 2 ,...G K ,...} of the executive set, K is a natural number, o i = o j , /> And, ∑|G K |=2x+1, f i represents the i-th target heterogeneous executive, f j represents the j-th target heterogeneous executive, o is the target confidence, /> is a real number. On this basis, calculate the set confidence of each executive set G k /> Then adjudicate the pending business processing result corresponding to the executive set with the largest set confidence as the target business processing result, thereby completing the mimetic ruling.

需要说明的是,若存在两个执行体集合的集合置信度相同,即Wi=Wj,则随机选择一个集合的结果作为目标业务处理结果即可。It should be noted that if there are two sets of executives with the same set confidence, that is, W i =W j , the result of one set is randomly selected as the target business processing result.

另外,在一实施例中,参照图6,在执行图2所示的步骤S23之后,方法还包括但不限于有以下步骤:In addition, in one embodiment, referring to FIG. 6, after step S23 shown in FIG. 2 is performed, the method further includes but is not limited to the following steps:

S61,保存本次拟态裁决的裁决信息;S61. Save the ruling information of this mimicry ruling;

S62,基于预设周期,目标异构执行体根据保存的裁决信息和当前的目标置信度进行加权迭代,得到新的目标置信度。S62, based on a preset period, the target heterogeneous executive executes weighted iterations according to the saved ruling information and the current target confidence to obtain a new target confidence.

需要说明的是,在完成每次拟态裁决后,可以将裁决信息保存,根据预设周期对目标置信度进行加权迭代实现更新,当然,也可以在每次得到裁决信息后都进行一次更新,具体的更新频率可以根据实际需求设置。通过更新目标置信度,可以对等价异构执行体的安全性进行更好的表征,从而在后续拟态裁决时得到更加准确的裁决结果,提高HSS网元信令的安全性。It should be noted that after each mimetic judgment is completed, the judgment information can be saved, and the target confidence can be weighted and iteratively updated according to the preset cycle. Of course, it can also be updated every time the judgment information is obtained. Specifically The update frequency can be set according to actual needs. By updating the target confidence, the security of equivalent heterogeneous executives can be better characterized, so that more accurate ruling results can be obtained in the subsequent mimicry judgment, and the security of HSS network element signaling can be improved.

另外,在一实施例中,参照图7,在执行图2所示的步骤S23之后,方法还包括但不限于有以下步骤:In addition, in one embodiment, referring to FIG. 7, after step S23 shown in FIG. 2 is executed, the method further includes but is not limited to the following steps:

S71,输出代理裁决器将本次拟态裁决的裁决信息发送至反馈控制器;S71, the output agent arbiter sends the adjudication information of this mimicry adjudication to the feedback controller;

S72,当反馈控制器根据本次拟态裁决的裁决信息确定出至少一个异常异构执行体,生成第一调度策略和第二调度策略;S72. When the feedback controller determines at least one abnormal heterogeneous executive according to the ruling information of the mimicry ruling, generate a first scheduling strategy and a second scheduling strategy;

S73,将第一调度策略发送至拟态调度模块,拟态调度模块根据第一调度策略控制异常异构执行体下线和清理;S73. Send the first scheduling strategy to the mimic scheduling module, and the mimic scheduling module controls the abnormal heterogeneous execution body to go offline and clean up according to the first scheduling strategy;

S74,将第二调度策略发送至输入代理分发器,输入代理分发器根据第二调度策略从可选的等价异构执行体中删除异常异构执行体。S74. Send the second scheduling strategy to the input proxy distributor, and the input proxy distributor deletes the abnormal heterogeneous execution body from the optional equivalent heterogeneous execution body according to the second scheduling strategy.

需要说明的是,为了实现拟态防御,可以对出现异常的执行体进行清洗,本实施例在输出代理裁决器输出裁决信息后,当发现异常的执行体,并将异常告警信息携发送给反馈控制器,异常告警信息可以携带在裁决信息中发送,或者独立发送。反馈控制器确定具有异常异构执行体后,向拟态调度模块发送第一调度策略,使得拟态调度模块响应第一调度策略对被识别为异常架构执行体的等价异构执行体进行下线和清理,避免其参与后续的HSS网元信令的传输。It should be noted that, in order to realize mimic defense, the abnormal execution body can be cleaned. In this embodiment, after the output proxy arbiter outputs the judgment information, when the abnormal execution body is found, the abnormal alarm information is sent to the feedback control The abnormal alarm information can be carried in the ruling information or sent independently. After the feedback controller determines that there are abnormal heterogeneous executors, it sends the first scheduling policy to the mimic scheduling module, so that the mimic scheduling module responds to the first scheduling policy to log off the equivalent heterogeneous executor identified as the abnormal architecture executor. Clean up to prevent it from participating in the transmission of subsequent HSS network element signaling.

需要说明的是,除了对出现异常的执行体进行清洗,反馈控制器还向输入代理分发器发送第二调度策略,使得根据输入代理分发器响应第二调度策略将被确定为异常异构执行体的等价异构执行体从执行体池删除,避免再次向其发送HSS网元信令。It should be noted that, in addition to cleaning the abnormal execution body, the feedback controller also sends the second scheduling policy to the input proxy distributor, so that according to the input proxy distributor response to the second scheduling policy, it will be determined as an abnormal heterogeneous execution body The equivalent heterogeneous execution body of is deleted from the execution body pool to avoid sending HSS network element signaling to it again.

另外,在一实施例中,参照图8,在执行图7所示的步骤S73之后,方法还包括但不限于有以下步骤:In addition, in one embodiment, referring to FIG. 8, after step S73 shown in FIG. 7 is performed, the method further includes but is not limited to the following steps:

S81,确定异常异构执行体所承载的业务执行完毕;S81. Determine that the execution of the business carried by the abnormal heterogeneous executable is completed;

S82,将异常异构执行体所承载的业务调度到无异常的等价异构执行体。S82. Dispatch the service carried by the abnormal heterogeneous execution body to an equivalent non-abnormal heterogeneous execution body.

需要说明的是,在对异常异构执行体进行下线和清洗之前,需要确保异常异构执行体当前承载的业务不受影响,因此可以将承载的业务执行完,或者调度到其他无异常的等价异构执行体,在完成上述操作后对异常异构执行体进行下线、清洗等操作,直至裁决器状态回到稳定平衡状态。It should be noted that before going offline and cleaning the abnormal heterogeneous execution body, it is necessary to ensure that the business carried by the abnormal heterogeneous execution body is not affected. Equivalent heterogeneous executives, after completing the above operations, perform operations such as offline and cleaning of abnormal heterogeneous executives until the state of the arbiter returns to a stable and balanced state.

如图9所示,图9是本发明一个实施例提供的拟态的HSS网元信令处理装置的结构图。本发明还提供了一种拟态的HSS网元信令处理装置,包括:As shown in FIG. 9 , FIG. 9 is a structural diagram of an apparatus for processing signaling of a mimic HSS network element provided by an embodiment of the present invention. The present invention also provides a mimic HSS network element signaling processing device, including:

处理器901,可以采用通用的中央处理器(Central Processing Unit,CPU)、微处理器、应用专用集成电路(Application Specific Integrated Circuit,ASIC)、或者一个或多个集成电路等方式实现,用于执行相关程序,以实现本申请实施例所提供的技术方案;The processor 901 may be implemented by a general-purpose central processing unit (Central Processing Unit, CPU), a microprocessor, an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute Relevant programs to realize the technical solutions provided by the embodiments of the present application;

存储器902,可以采用只读存储器(Read Only Memory,ROM)、静态存储设备、动态存储设备或者随机存取存储器(Random Access Memory,RAM)等形式实现。存储器902可以存储操作系统和其他应用程序,在通过软件或者固件来实现本说明书实施例所提供的技术方案时,相关的程序代码保存在存储器902中,并由处理器901来调用执行本申请实施例的拟态的HSS网元信令处理方法;The memory 902 may be implemented in the form of a read only memory (Read Only Memory, ROM), a static storage device, a dynamic storage device, or a random access memory (Random Access Memory, RAM). The memory 902 can store operating systems and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 902 and called by the processor 901 to execute the implementation of this application. The simulated HSS network element signaling processing method of the example;

输入/输出接口903,用于实现信息输入及输出;The input/output interface 903 is used to realize information input and output;

通信接口904,用于实现本设备与其他设备的通信交互,可以通过有线方式(例如USB、网线等)实现通信,也可以通过无线方式(例如移动网络、WIFI、蓝牙等)实现通信;The communication interface 904 is used to realize the communication interaction between the device and other devices, and the communication can be realized through a wired method (such as USB, network cable, etc.), or can be realized through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.);

总线905,在设备的各个组件(例如处理器901、存储器902、输入/输出接口903和通信接口904)之间传输信息;bus 905, for transferring information between various components of the device (such as processor 901, memory 902, input/output interface 903 and communication interface 904);

其中处理器901、存储器902、输入/输出接口903和通信接口904通过总线905实现彼此之间在设备内部的通信连接。The processor 901 , the memory 902 , the input/output interface 903 and the communication interface 904 are connected to each other within the device through the bus 905 .

本申请实施例还提供了一种存储介质,存储介质为计算机可读存储介质,该存储介质存储有计算机程序,该计算机程序被处理器执行时实现上述拟态的HSS网元信令处理方法。The embodiment of the present application also provides a storage medium, which is a computer-readable storage medium, and the storage medium stores a computer program, and when the computer program is executed by a processor, the above-mentioned method for processing mimic HSS network element signaling is implemented.

存储器作为一种非暂态计算机可读存储介质,可用于存储非暂态软件程序以及非暂态性计算机可执行程序。此外,存储器可以包括高速随机存取存储器,还可以包括非暂态存储器,例如至少一个磁盘存储器件、闪存器件、或其他非暂态固态存储器件。在一些实施方式中,存储器可选包括相对于处理器远程设置的存储器,这些远程存储器可以通过网络连接至该处理器。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。以上所描述的装置实施例仅仅是示意性的,其中作为分离部件说明的单元可以是或者也可以不是物理上分开的,实现了以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。As a non-transitory computer-readable storage medium, memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes memory located remotely from the processor, and these remote memories may be connected to the processor via a network. Examples of the aforementioned networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof. The device embodiments described above are only illustrative, and the units described as separate components may or may not be physically separated, and may be implemented so as to be located in one place, or may also be distributed to multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

本领域普通技术人员可以理解,上文中所公开方法中的全部或某些步骤、系统可以被实施为软件、固件、硬件及其适当的组合。某些物理组件或所有物理组件可以被实施为由处理器,如中央处理器、数字信号处理器或微处理器执行的软件,或者被实施为硬件,或者被实施为集成电路,如专用集成电路。这样的软件可以分布在计算机可读介质上,计算机可读介质可以包括计算机存储介质(或非暂时性介质)和通信介质(或暂时性介质)。如本领域普通技术人员公知的,术语计算机存储介质包括在用于存储信息(诸如计算机可读指令、数据结构、程序模块或其他数据)的任何方法或技术中实施的易失性和非易失性、可移除和不可移除介质。计算机存储介质包括但不限于RAM、ROM、EEPROM、闪存或其他存储器技术、CD-ROM、数字多功能盘(DVD)或其他光盘存储、磁盒、磁带、磁盘存储或其他磁存储装置、或者可以用于存储期望的信息并且可以被计算机访问的任何其他的介质。此外,本领域普通技术人员公知的是,通信介质通常包括计算机可读指令、数据结构、程序模块或者诸如载波或其他传输机制之类的调制数据信号中的其他数据,并且可包括任何信息递送介质。Those skilled in the art can understand that all or some of the steps and systems in the methods disclosed above can be implemented as software, firmware, hardware and an appropriate combination thereof. Some or all of the physical components may be implemented as software executed by a processor, such as a central processing unit, digital signal processor, or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit . Such software may be distributed on computer readable media, which may include computer storage media (or non-transitory media) and communication media (or transitory media). As known to those of ordinary skill in the art, the term computer storage media includes both volatile and nonvolatile media implemented in any method or technology for storage of information, such as computer readable instructions, data structures, program modules, or other data. permanent, removable and non-removable media. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cartridges, tape, magnetic disk storage or other magnetic storage devices, or can Any other medium used to store desired information and which can be accessed by a computer. Furthermore, as is well known to those of ordinary skill in the art, communication media typically embody computer readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media .

以上是对本发明的较佳实施进行了具体说明,但本发明并不局限于上述实施方式,熟悉本领域的技术人员在不违背本发明精神的共享条件下还可作出种种等同的变形或替换,这些等同的变形或替换均包括在本发明权利要求所限定的范围内。The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the above-mentioned embodiment, and those skilled in the art can also make various equivalent deformations or replacements without violating the spirit of the present invention. These equivalent modifications or replacements are all within the scope defined by the claims of the present invention.

Claims (10)

1.一种拟态的HSS网元信令处理方法,其特征在于,应用于拟态的HSS网元信令处理系统,所述拟态的HSS网元信令处理系统包括输入代理分发器、多个等价异构执行体和输出代理裁决器,所述输入代理分发器与HSS网元通信连接,多个所述等价异构执行体的执行体架构不同但业务处理功能相同,所述拟态的HSS网元信令处理方法包括:1. A mimic HSS network element signaling processing method, characterized in that it is applied to a mimic HSS network element signaling processing system, and the mimic HSS network element signaling processing system includes an input agent distributor, a plurality of etc. Valence heterogeneous executives and output proxy arbitrators, the input proxy distributor communicates with HSS network elements, multiple equivalent heterogeneous executives have different executive structures but the same business processing functions, and the mimic HSS Network element signaling processing methods include: 通过所述输入代理分发器接收HSS网元信令,将所述HSS网元信令复制多份后分发到多个所述等价异构执行体;receiving the HSS network element signaling through the input agent distributor, and distributing the multiple copies of the HSS network element signaling to multiple equivalent heterogeneous execution entities; 通过多个所述等价异构执行体对被分发的所述HSS网元信令进行业务处理,并将得到的待裁决业务处理结果输入至所述输出代理裁决器;Perform service processing on the distributed HSS network element signaling through multiple equivalent heterogeneous executives, and input the obtained pending service processing results to the output proxy arbiter; 所述输出代理裁决器根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果。The output proxy arbiter performs a pseudo-arbitration according to a preset adjudication algorithm, and determines a target business processing result from a plurality of pending business processing results. 2.根据权利要求1所述的拟态的HSS网元信令处理方法,其特征在于,所述执行体架构包括宿主机和虚拟机,不同的所述等价异构执行体的所述宿主机的硬件和操作系统不同,不同的所述等价异构执行体的所述虚拟机的操作系统平台不同,所述将所述HSS网元信令复制多份后分发到多个所述等价异构执行体,包括:2. The mimic HSS network element signaling processing method according to claim 1, characterized in that, the execution body architecture includes a host machine and a virtual machine, and the host machines of different equivalent heterogeneous execution bodies The hardware and the operating system are different, and the operating system platforms of the virtual machines of the different equivalent heterogeneous execution bodies are different, and the multiple copies of the HSS network element signaling are distributed to multiple equivalent Heterogeneous executives, including: 从多个所述等价异构执行体中确定多个目标异构执行体;determining a plurality of target heterogeneous executables from a plurality of equivalent heterogeneous executables; 根据所述目标异构执行体的数量复制多份所述HSS网元信令;Duplicating multiple copies of the HSS network element signaling according to the number of target heterogeneous executables; 向每个所述目标异构执行体分发所述HSS网元信令。Distributing the HSS network element signaling to each of the target heterogeneous execution entities. 3.根据权利要求2所述的拟态的HSS网元信令处理方法,其特征在于,在所述通过所述输入代理分发器接收HSS网元信令之前,所述方法还包括:3. The pseudo HSS network element signaling processing method according to claim 2, characterized in that, before receiving the HSS network element signaling by the input agent distributor, the method further comprises: 获取预设的历史参考置信度,所述历史参考置信度归属于历史参考异构执行体;Obtaining a preset historical reference confidence degree, which belongs to the historical reference heterogeneous execution body; 基于所述历史参考异构执行体的所述执行体架构与所述等价异构执行体的所述执行体架构之间的相似程度,确定所述等价异构执行体的初始置信度。Based on the degree of similarity between the execution body architecture of the historical reference heterogeneous execution body and the execution body architecture of the equivalent heterogeneous execution body, an initial confidence degree of the equivalent heterogeneous execution body is determined. 4.根据权利要求3所述的拟态的HSS网元信令处理方法,其特征在于,所述输出代理裁决器根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果,包括:4. The HSS network element signaling processing method of mimicry according to claim 3, characterized in that, the output proxy arbiter performs a mimetic arbitrator according to a preset adjudication algorithm, and from a plurality of business processing results to be adjudicated Identify target business process outcomes, including: 获取所述目标异构执行体发送的目标置信度,所述目标置信度是基于所述初始置信度迭代多次历史拟态裁决的裁决信息得到的,所述裁决信息用于指示所述目标异构执行体进行拟态裁决时的安全态势、系统资源状况、异常处理结果、被攻击的频率和历史裁决结果;Acquiring the target confidence degree sent by the target heterogeneous executive body, the target confidence degree is obtained by iterating multiple times of historical mimicry judgment judgment information based on the initial confidence degree, and the judgment information is used to indicate that the target is heterogeneous The security situation, system resource status, exception handling results, attack frequency and historical judgment results of the executive body when performing mimicry judgment; 基于多个所述目标异构执行体确定多个执行体集合,归属于同一个所述执行体集合的所述目标异构执行体所输出的所述待裁决业务处理结果相同;Determining a plurality of executive body sets based on a plurality of said target heterogeneous executive bodies, and said pending business processing results output by said target heterogeneous executive bodies belonging to the same said executive body set are the same; 将所述执行体集合中全部的所述目标异构执行体的所述目标置信度之和确定为集合置信度;determining the sum of the target confidences of all the target heterogeneous executions in the execution set as the set confidence; 将所述集合置信度最大的所述执行体集合所对应的所述待裁决业务处理结果裁决为所述目标业务处理结果。arbitrating the pending service processing result corresponding to the executive set with the highest set confidence as the target service processing result. 5.根据权利要求4所述的拟态的HSS网元信令处理方法,其特征在于,在所述从多个所述待裁决业务处理结果中确定目标业务处理结果之后,所述方法还包括:5. The pseudo HSS network element signaling processing method according to claim 4, characterized in that, after said determining the target service processing result from a plurality of said pending service processing results, said method further comprises: 保存本次拟态裁决的裁决信息;Save the ruling information of this mimicry ruling; 基于预设周期,所述目标异构执行体根据保存的所述裁决信息和当前的所述目标置信度进行加权迭代,得到新的目标置信度。Based on a preset period, the target heterogeneous executive executes weighted iterations according to the saved ruling information and the current target confidence to obtain a new target confidence. 6.根据权利要求4所述的拟态的HSS网元信令处理方法,其特征在于,所述拟态的HSS网元信令处理系统还包括反馈控制器和拟态调度模块,在所述从多个所述待裁决业务处理结果中确定目标业务处理结果之后,所述方法还包括:6. The HSS network element signaling processing method of mimicry according to claim 4, characterized in that, the HSS network element signaling processing system of said mimicry also includes a feedback controller and a mimicry dispatching module, in the described from multiple After the target business processing result is determined in the pending business processing results, the method further includes: 所述输出代理裁决器将本次拟态裁决的裁决信息发送至所述反馈控制器;The output proxy arbiter sends the adjudication information of this mimicry adjudication to the feedback controller; 当所述反馈控制器根据所述本次拟态裁决的裁决信息确定出至少一个异常异构执行体,生成第一调度策略和第二调度策略;When the feedback controller determines at least one abnormal heterogeneous executive according to the ruling information of the current mimicry ruling, generating a first scheduling strategy and a second scheduling strategy; 将所述第一调度策略发送至所述拟态调度模块,所述拟态调度模块根据所述第一调度策略控制所述异常异构执行体下线和清理;Send the first scheduling policy to the mimic scheduling module, and the mimic scheduling module controls the abnormal heterogeneous executive body to go offline and clean up according to the first scheduling policy; 将所述第二调度策略发送至所述输入代理分发器,所述输入代理分发器根据所述第二调度策略从可选的所述等价异构执行体中删除所述异常异构执行体。sending the second scheduling strategy to the input proxy distributor, and the input proxy distributor deletes the abnormal heterogeneous execution body from the optional equivalent heterogeneous execution body according to the second scheduling strategy . 7.根据权利要求6所述的拟态的HSS网元信令处理方法,其特征在于,在所述拟态调度模块根据所述第一调度策略控制所述异常异构执行体下线和清理之前,所述方法还包括:7. The mimic HSS network element signaling processing method according to claim 6, characterized in that, before the mimic scheduling module controls the offline and cleaning of the abnormal heterogeneous execution body according to the first scheduling strategy, The method also includes: 确定所述异常异构执行体所承载的业务执行完毕;Determine that the execution of the business carried by the abnormal heterogeneous executable is completed; 或者,将所述异常异构执行体所承载的业务调度到无异常的所述等价异构执行体。Or, dispatch the service carried by the abnormal heterogeneous executable to the equivalent heterogeneous executable without abnormality. 8.一种拟态的HSS网元信令处理系统,其特征在于,用于执行权利要求1至7任意一项所述的拟态的HSS网元信令处理方法,所述拟态的HSS网元信令处理系统包括:8. A pseudomorphic HSS network element signaling processing system, characterized in that, it is used to execute the pseudomorphic HSS network element signaling processing method described in any one of claims 1 to 7, the pseudomorphic HSS network element signaling processing method Order processing systems include: 输入代理分发器,用于接收HSS网元信令,将所述HSS网元信令复制多份后分发到多个等价异构执行体;The input agent distributor is used to receive the HSS network element signaling, and distribute the HSS network element signaling to multiple equivalent heterogeneous execution bodies after copying multiple copies; 多个等价异构执行体,用于对被分发的所述HSS网元信令进行业务处理,并将得到的待裁决业务处理结果输入至输出代理裁决器,其中,多个所述等价异构执行体的执行体架构不同但业务处理功能相同;A plurality of equivalent heterogeneous executives are used to perform service processing on the distributed HSS network element signaling, and input the obtained service processing results to be arbitrated to the output proxy arbiter, wherein the plurality of equivalent Heterogeneous executives have different executive structures but the same business processing functions; 输出代理裁决器,用于根据预设的裁决算法进行拟态裁决,从多个所述待裁决业务处理结果中确定目标业务处理结果。The output proxy arbiter is configured to perform mimicry adjudication according to a preset adjudication algorithm, and determine a target business processing result from a plurality of pending adjudication business processing results. 9.一种拟态的HSS网元信令处理装置,其特征在于,包括至少一个控制处理器和用于与所述至少一个控制处理器通信连接的存储器;所述存储器存储有可被所述至少一个控制处理器执行的指令,所述指令被所述至少一个控制处理器执行,以使所述至少一个控制处理器能够执行如权利要求1至7任一项所述的拟态的HSS网元信令处理方法。9. A simulated HSS network element signaling processing device, characterized in that it includes at least one control processor and a memory for communicating with the at least one control processor; the memory stores information that can be used by the at least one control processor An instruction executed by a control processor, the instruction is executed by the at least one control processor, so that the at least one control processor can execute the simulated HSS network element information according to any one of claims 1 to 7 command processing method. 10.一种计算机可读存储介质,其特征在于,所述计算机可读存储介质存储有计算机可执行指令,所述计算机可执行指令用于使计算机执行如权利要求1至7任一项所述的拟态的HSS网元信令处理方法。10. A computer-readable storage medium, characterized in that, the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to make a computer perform the operation described in any one of claims 1 to 7. A pseudomorphic HSS network element signaling processing method.
CN202310559039.6A 2023-05-17 2023-05-17 Mimicry HSS network element signaling processing method and system Pending CN116668097A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN202310559039.6A CN116668097A (en) 2023-05-17 2023-05-17 Mimicry HSS network element signaling processing method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN202310559039.6A CN116668097A (en) 2023-05-17 2023-05-17 Mimicry HSS network element signaling processing method and system

Publications (1)

Publication Number Publication Date
CN116668097A true CN116668097A (en) 2023-08-29

Family

ID=87716355

Family Applications (1)

Application Number Title Priority Date Filing Date
CN202310559039.6A Pending CN116668097A (en) 2023-05-17 2023-05-17 Mimicry HSS network element signaling processing method and system

Country Status (1)

Country Link
CN (1) CN116668097A (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117056914A (en) * 2023-10-11 2023-11-14 井芯微电子技术(天津)有限公司 Endogenous security processing method and system based on heterogeneous operating system
CN119520108A (en) * 2024-11-21 2025-02-25 紫金山实验室 Resource calling method, device, electronic device, storage medium and product
CN120415900A (en) * 2025-06-30 2025-08-01 华东交通大学 Internet of Things gateway enhancement method and system based on traffic monitoring and mimetic feedback

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111783079A (en) * 2020-06-04 2020-10-16 河南信大网御科技有限公司 Mimicry defense device, mimicry defense method and mimicry defense framework
CN112242923A (en) * 2020-09-15 2021-01-19 中国人民解放军战略支援部队信息工程大学 System and method for realizing unified data management network function based on mimicry defense
CN113973018A (en) * 2021-12-22 2022-01-25 南京微滋德科技有限公司 Endogenous safety-based Internet of things terminal data processing method and system
CN114301650A (en) * 2021-12-21 2022-04-08 浙江大学 Mimicry WAF (wide area filter) judging method based on credibility
CN115314289A (en) * 2022-08-08 2022-11-08 北京天融信网络安全技术有限公司 Attacked executor identifying method, output voter, equipment and storage medium

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN111783079A (en) * 2020-06-04 2020-10-16 河南信大网御科技有限公司 Mimicry defense device, mimicry defense method and mimicry defense framework
CN112242923A (en) * 2020-09-15 2021-01-19 中国人民解放军战略支援部队信息工程大学 System and method for realizing unified data management network function based on mimicry defense
CN114301650A (en) * 2021-12-21 2022-04-08 浙江大学 Mimicry WAF (wide area filter) judging method based on credibility
CN113973018A (en) * 2021-12-22 2022-01-25 南京微滋德科技有限公司 Endogenous safety-based Internet of things terminal data processing method and system
CN115314289A (en) * 2022-08-08 2022-11-08 北京天融信网络安全技术有限公司 Attacked executor identifying method, output voter, equipment and storage medium

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN117056914A (en) * 2023-10-11 2023-11-14 井芯微电子技术(天津)有限公司 Endogenous security processing method and system based on heterogeneous operating system
CN117056914B (en) * 2023-10-11 2024-01-23 井芯微电子技术(天津)有限公司 Endogenous security processing method and system based on heterogeneous operating system
CN119520108A (en) * 2024-11-21 2025-02-25 紫金山实验室 Resource calling method, device, electronic device, storage medium and product
CN120415900A (en) * 2025-06-30 2025-08-01 华东交通大学 Internet of Things gateway enhancement method and system based on traffic monitoring and mimetic feedback
CN120415900B (en) * 2025-06-30 2025-09-12 华东交通大学 Internet of things gateway enhancement method and system based on flow monitoring and mimicry feedback

Similar Documents

Publication Publication Date Title
CN116668097A (en) Mimicry HSS network element signaling processing method and system
US10990516B1 (en) Method, apparatus, and computer program product for predictive API test suite selection
CN112261135B (en) Node election method, system, device and equipment based on consistency protocol
CN109768879B (en) Method and device for determining target service server and server
Bui et al. Adaptive replication management in HDFS based on supervised learning
CN110784515B (en) Data storage method based on distributed cluster and related equipment thereof
KR20190022431A (en) Training Method of Random Forest Model, Electronic Apparatus and Storage Medium
US8938648B2 (en) Multi-entity test case execution workflow
CN108572823A (en) Front and back end development management method and system based on interface engine
CN107004085B (en) Techniques for utilizing user interaction to manage security threats to computing systems
KR20150064063A (en) Secure identification of computing device and secure identification methods
US20170351723A1 (en) Managing data format of data received from devices in an internet of things network
CN107079041A (en) File credit assessment
EP3370166B1 (en) Method and apparatus for model parameter fusion
CN113438134B (en) Request message processing method, device, server and medium
CN105991596B (en) An access control method and system
US20210012001A1 (en) Storage medium, information processing method, and information processing apparatus
JP2019185781A (en) Secure re-enrollment of biometric templates using distributed secure computation and secret sharing
CN112948274A (en) Test case scoring model training method and test case selection method
CN116910524A (en) Federal learning method, apparatus, device and storage medium
CN110716730B (en) Gray release method, device, equipment and computer readable storage medium
CN112148419B (en) Mirror image management method, device and system in cloud platform and storage medium
CN115829064A (en) Method, device and equipment for accelerating federated learning and storage medium
CN115017512A (en) Blockchain-based unauthorized access vulnerability testing method and device
CN110474787B (en) Node fault detection method and device

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination