基于增量定位与标记去重的云数据灾备技术
网络出版日期: 2024-07-08
基金资助
国家自然科学基金(62172191)
版权
Cloud data disaster recovery techniques based on incremental localization and marker de-redundancy
Online published: 2024-07-08
Supported by
National Natural Science Foundation of China(62172191)
Copyright
通过云备份服务和威胁情报的结合,可以显著提升网络安全态势感知与响应能力。随着云网基础设施的不断拓展,数据量呈指数级增长,对云数据采取备份恢复措施成为威胁防御的重要环节。针对虚拟机快照备份等技术存在数据冗余严重、难以适应分布式体系的问题,面向典型的OpenStack与Kubernetes分布式云平台设计了一种基于增量云数据去重的灾备技术。首先,设计了云数据灾备防御体系,以实现对差异性数据类型的覆盖性保护。其次,设计了增量云数据去重技术,提升了备份效率并实现了对备份数据的分布式与分离管理。实验证明,在数据的定期备份中相较于基于Backy2与Duplicacy的云备份方案,基于增量去重的云数据灾备技术在备份时间上分别平均节约了46.57%和41.73%,遭遇威胁进行灾难恢复的时间平均节约了7.23%与43.73%。
杜岩冰 , 王晓锋 . 基于增量定位与标记去重的云数据灾备技术[J]. 网络空间安全科学学报, 2024 , 2(2) : 66 -75 . DOI: 10.20172/j.issn.2097-3136.240206
Through the combination of cloud backup services and threat intelligence, network security situational awareness and response capabilities were significantly improved. As the cloud network infrastructure continued to expand, the volume of data showed exponential growth, and taking backup and recovery measures for cloud data became an important part of threat defense. Targeting the problems such as serious data redundancy and difficulty in adapting to distributed systems in technologies like virtual machine snapshot backup, a disaster recovery technology based on incremental cloud data de-duplication was designed for the typical OpenStack and Kubernetes distributed cloud platforms. Firstly, a cloud data disaster recovery defense system was designed to achieve coverage protection for differentiated data types. Secondly, an incremental cloud data de-duplication technique was designed to improve backup efficiency and to achieve distributed and separate management of backup data. The experiment proved that the incremental de-duplication-based cloud data disaster recovery technology, compared with Backy2 and Duplicacy-based cloud backup solutions, saved 46.57% and 41.73% of backup time on average, and saved 7.23% and 43.73% of disaster recovery time when encountering threats, respectively, in regular data backup.
表 1 实验使用方案的主要配置Table 1 Main configurations of the experimental use program |
| 配置 | ICDD | Backy2 | Duplicacy |
| 分块算法 | 增量云数据定位 | 固定大小分块 | 变长大小分块 |
| 最大数据块大小/MB | 4 | 4 | 8 |
| 哈希算法 | blake2 | sha512 | blake2 |
| 压缩算法 | Zstd | Zstd | Zstd |
表 2 不同节点对同一虚拟机进行备份测试Table 2 Backup test of the same Virtual Machine by different nodes |
| 节点 | OpenStack 控制节点 | OpenStack 计算节点 | Ceph 存储 | 其他 节点 |
| 待备份数据量/MB | ||||
| 备份存储空间/KB | 28 | 16 | 28 | |
| 备份时间/s | 26 | 13 | 10 | 17 |
表 3 OpenStack虚拟机备份存储使用比较Table 3 Comparison of OpenStack virtual machine backup storage usage |
| 备份时刻 | 备份存储空间/MB | ||
| ICDD | Backy2 | Export-diff+ Duplicacy | |
| T0 | 520.26 | 561.00 | 517.89 |
| T1 | 34.62 | 54.00 | 36.74 |
| T2 | 102.08 | 109.00 | 102.17 |
| T3 | 167.35 | 181.00 | 167.36 |
| T4 | 129.88 | 139.00 | 129.88 |
| T5 | 135.29 | 144.00 | 135.35 |
| T6 | 186.12 | 194.00 | 186.16 |
| T7 | 162.71 | 171.00 | 162.72 |
| T8 | 206.27 | 211.00 | 206.27 |
| T9 | 200.91 | 210.00 | 200.98 |
表 4 MySQL容器备份存储使用情况比较Table 4 Comparison of MySQL container backup storage usage |
| 备份数据库 | 备份存储空间/MB | |||
| ICDD | Backy2 | Export-diff + Duplicacy | Mysqldump + Duplicacy | |
| 初始化 | 0.28 | 72.00 | 0.34 | — |
| Employee | 75.64 | 328.00 | 89.64 | 72.10 |
| World | 0.55 | 56.00 | 0.59 | 2.02 |
| Sakila | 3.56 | 100.00 | 4.97 | 3.13 |
| Menagerie | 0.06 | 48.00 | 0.06 | 3.14 |
| 1 |
KUMAR D,KUMAR K P. Artificial intelligence based cyber security threats identification in financial institutions using machine learning approach[C]//2023 2nd International Conference for Innovation in Technology (INOCON). IEEE,2023:1-6.
|
| 2 |
程光, 张家康, 陈子涵. 面向高速端边云网络的加密流量智能识别与态势感知方法[J]. 网络空间安全科学学报, 2023, 1 (1): 90- 105.
CHENG G, ZHANG J K, CHEN Z H. Intelligent identification and situational awareness method for encrypted traffic in high-speed and end-edge-cloud networks[J]. Journal of Cybersecurity, 2023, 1 (1): 90- 105.
|
| 3 |
张佳乐, 赵彦超, 陈兵, 等. 边缘计算数据安全与隐私保护研究综述[J]. 通信学报, 2018, 39 (3): 1- 21.
ZHANG J L, ZHAO Y C, CHEN B, et al. Survey on data security and privacy-preserving for the research of edge computing[J]. Journal on Communications, 2018, 39 (3): 1- 21.
|
| 4 |
KUMARI A,PRAKASH P,UMADEVI M. Prediction of Data Breaches using Classification Algorithms[C]//2021 Fifth International Conference on I-SMAC (IoT in Social,Mobile,Analytics and Cloud)(I-SMAC). IEEE,2021:1049-1054.
|
| 5 |
GUFFEY J,LI Y. Cloud service misconfigurations:Emerging threats,enterprise data breaches and solutions[C]//2023 IEEE 13th Annual Computing and Communication Workshop and Conference (CCWC). IEEE,2023:0806-0812.
|
| 6 |
于丰瑞. 网络威胁技战术情报自动化识别提取研究综述[J/OL]. 计算机工程与 应用. https://link.cnki.net/urlid/11.2127.tp.20240227.1705.002.
YU F R. A survey on automated recognition and extraction of TTPs[J/OL]. Computer Engineering and Applications. https://link.cnki.net/urlid/11.2127.tp.20240227.1705.002.
|
| 7 |
MOUSTAFA N, ADI E, TURNBULL B, et al. A new threat intelligence scheme for safeguarding industry 4.0 systems[J]. IEEE Access, 2018, 6, 32910- 32924.
|
| 8 |
ANANTHAPADMANABHAN A,ACHUTHAN K. Threat modeling and threat intelligence system for cloud using splunk[C]//2022 10th International Symposium on Digital Forensics and Security (ISDFS). IEEE,2022:1-6.
|
| 9 |
MENARD P, GATLIN R, WARKENTIN M. Threat protection and convenience: Antecedents of cloud-based data backup[J]. Journal of Computer Information Systems, 2014, 55 (1): 83- 91.
|
| 10 |
ROSA I,BATISTA R,GONÇALVES R,et al. Cyber threat intelligence architecture for applied cybersecurity scenarios:PhD Thesis Proposal in Web Science and Technology[C]//2022 17th Iberian Conference on Information Systems and Technologies (CISTI). IEEE,2022:1-6.
|
| 11 |
SNEDAKER S. Business continuity and disaster recovery planning for IT professionals[M]. Newnes,2013.
|
| 12 |
薄明霞, 唐洪玉, 张静. 云环境下威胁情报技术与应用综述[J]. 电信技术, 2017, 8 (6): 46- 48+52.
BO M X, TANG H Y, ZHANG J. Overview of threat intelligence technology and application in cloud environment[J]. Telecommunications Technology, 2017, 8 (6): 46- 48+52.
|
| 13 |
李建华. 网络空间威胁情报感知, 共享与分析技术综述[J]. 网络与信息安全学报, 2016, 2 (2): 16- 29.
LI J H. Overview of the technologies of threat intelligence sensing, sharing and analysis in cyber space[J]. Chinese Journal of Network and Information Security, 2016, 2 (2): 16- 29.
|
| 14 |
边林, 陶冶, 曹咪, 等. 电信运营商威胁情报建设与运营方法研究[J]. 信息通信技术, 2020, 14 (6): 45- 50.
BIAN L, TAO Y, CAO M, et al. Research on the construction and operation of threat intelligence in telecom operators[J]. Information and Communications Technologies, 2020, 14 (6): 45- 50.
|
| 15 |
KUMAR R, GUPTA N, CHARU S, et al. Open source solution for cloud computing platform using OpenStack[J]. International Journal of Computer Science and Mobile Computing, 2014, 3 (5): 89- 98.
|
| 16 |
DAVID BERNSTEIN. Containers and cloud: from lxc to docker to kubernetes[J]. IEEE Cloud Computing, 2014, 1 (3): 81- 84.
|
| 17 |
WEIL S A,BRANDT S A,MILLER E L,et al. Ceph:a scalable,high-performance distributed file system[C]//Proceedings of the 7th symposium on Operating systems design and implementation. 2006:307-320.
|
| 18 |
吴沛颖, 王俊峰, 崔泽源, 等. 网络威胁情报处理方法综述[J]. 四川大学学报(自然科学版), 2023, 60 (5): 7- 24.
WU P Y, WANG J F, CUI Z Y, et al. A survey of cyber threat intelligence processing methods[J]. Journal of Sichuan University (Natural Science Edition), 2023, 60 (5): 7- 24.
|
| 19 |
AL-MOHANNADI H, AWAN I, AL HAMAR J. Analysis of adversary activities using cloud-based web services to enhance cyber threat intelligence[J]. Service Oriented Computing and Applications, 2020, 14 (3): 175- 187.
|
| 20 |
ALSHAIKH A,ALANESI M,YANG D,et al. Advanced techniques for cyber threat intelligence-based APT detection and mitigation in cloud environments[C]//International Conference on Cyber Security,Artificial Intelligence,and Digital Economy(CSAIDE 2023). SPIE,2023,12718: 147-157.
|
| 21 |
AMMI M, ADEDUGBE O, ALHARBY F M, et al. Leveraging a cloud-native architecture to enable semantic interconnectedness of data for cyber threat intelligence[J]. Cluster Computing, 2022, 25 (5): 3629- 3640.
|
| 22 |
崔琳, 杨黎斌, 何清林, 等. 基于开源信息平台的威胁情报挖掘综述[J]. 信息安全学报, 2022, 7 (1): 1- 26..
CUI L, YANG L B, HE Q L, et al. Survey of cyber threat intelligence mining based on open source information platform[J]. Journal of Cyber Security, 2022, 7 (1): 1- 26..
|
| 23 |
张海涛, 蒋熠, 竺士杰, 等. 电信运营商威胁情报体系研究与应用探索[J]. 电信科学, 2022, 38 (12): 121- 132.
ZHANG H T, JIANG Y, ZHU S J, et al. Research and application exploration of threat intelligence system of telecom operators[J]. Telecommunications Science, 2022, 38 (12): 121- 132.
|
| 24 |
薄明霞, 唐洪玉, 马晨, 等. 基于大数据分析的安全威胁情报在电信运营商的落地应用[J]. 电信科学, 2020, 36 (11): 127- 133.
BO M X, TANG H Y, MA C, et al. Application of security threat intelligence based on big data analysis in telecom operators[J]. Telecommunications Science, 2020, 36 (11): 127- 133.
|
| 25 |
GONG S, LEE C. Cyber threat intelligence framework for incident response in an energy cloud platform[J]. Electronics, 2021, 10 (3): 239.
|
| 26 |
TORKURA K A,SUKMANA M I H,CHENG F,et al. Slingshot-automated threat detection and incident response in multi cloud storage systems[C]//2019 IEEE 18th International Symposium on Network Computing and Applications (NCA). IEEE,2019:1-5.
|
| 27 |
HRISTEV R,VESELINOVA M. ICT for cyber security in business[C]//IOP Conference Series:Materials Science and Engineering. IOP Publishing,2021,1099(1):012035.
|
| 28 |
KARIM U, INYIAMA H C, KARIM R. User-centric cyber disaster recovery as a service[J]. Nigerian Annals of Pure and Applied Sciences, 2019, 2, 238- 246.
|
| 29 |
YANG L X, HUANG K, YANG X, et al. Defense against advanced persistent threat through data backup and recovery[J]. IEEE Transactions on Network Science and Engineering, 2020, 8 (3): 2001- 2013.
|
| 30 |
LI J,LIU H,CUI L,et al. Irow: an efficient live snapshot system for virtual machine disk[C]//2012 IEEE 18th International Conference on Parallel and Distributed Systems. IEEE,2012:376-383.
|
| 31 |
DANIEL K. backy2-ceph rbd backup-fast open source block based backup software[EB/OL]. [2024-3-1].https://backy2.com/.
|
| 32 |
LI Z, CHEN G, DENG Y. Duplicacy: a new generation of cloud backup tool based on lock-free deduplication[J]. IEEE Transactions on Cloud Computing, 2020, 10 (4): 2508- 2520.
|
| 33 |
TORKURA K A,SUKMANA M I H,STRAUSS T,et al. Csbauditor:Proactive security risk analysis for cloud storage broker systems[C]//2018 IEEE 17th International Symposium on Network Computing and Applications (NCA) . IEEE,2018:1-10.
|
| 34 |
王晨, 郑文英, 王惟正, 等. 边缘计算数据安全保护研究综述[J]. 网络空间安全科学学报, 2023, 1 (2): 35- 45.
WANG C, ZHENG W Y, WANG W Z, et al. Survey on data security protection for edge computing[J]. Journal of Cybersecurity, 2023, 1 (2): 35- 45.
|
| 35 |
陈兴蜀, 曾雪梅, 王文贤, 等. 基于大数据的网络安全与情报分析[J]. 工程科学与技术, 2017, 49 (3): 1- 12.
CHEN X S, ZENG X M, WANG W X, et al. Big data analytics for network security and intelligence[J]. Advanced Engineering Sciences, 2017, 49 (3): 1- 12.
|
/
| 〈 |
|
〉 |