A method, device and system for processing attack data packets
A processing method and data packet technology, applied in the field of communication, can solve problems such as occupying large network bandwidth and affecting data packet transmission
- Summary
- Abstract
- Description
- Claims
- Application Information
AI Technical Summary
Problems solved by technology
Method used
Image
Examples
Embodiment 1
[0098] Embodiments of the present invention provide a method for processing attack data packets, such as figure 2 As shown, the method may include:
[0099] S101. The management node receives the description information of the attack data packet and the attack type of the attack data packet sent by the sensing node.
[0100] Among them, the attack data packet can be understood as a data packet that poses a threat to the sensing node, such as a data packet with a malformed message, a data packet with abnormal packet fragmentation, and an invalid transmission control protocol (English: transmission control protocol, abbreviation: TCP) connection. data packets, data packets with excessive data volume, etc.
[0101] Optionally, the description information of the attack data packet may be information obtained by the sensing node from the header of the attack data packet, specifically, the source IP address of the attack data packet, the destination IP address of the attack data p...
Embodiment 2
[0147] Embodiments of the present invention provide a method for processing attack data packets, such as Figure 6 As shown, the method may include:
[0148] S401. The sensing node receives the data packet.
[0149] S402. The sensing node identifies the data packet as an attack data packet.
[0150] S403. The sensing node determines the description information of the attack data packet and the attack type of the attack data packet.
[0151] S404. The perception node sends the description information and the attack type to the management node.
[0152] Specifically, for the specific implementation of the above S401-S404, please refer to the following Figure 5 Relevant descriptions in the illustrated embodiment will not be repeated here.
[0153] S405. After receiving the description information and the attack type sent by the sensing node, the management node determines, according to the attack type, a processing policy for the attack data packet with the attack type.
[...
Embodiment 3
[0177] Such as Figure 11 As shown, the embodiment of the present invention provides a management node, and the management node may include:
[0178]The receiving unit 10 is configured to receive the description information of the attack data packet sent by the sensing node and the attack type of the attack data packet.
[0179] The determining unit 11 is configured to determine, according to the attack type received by the receiving unit 10, a processing strategy for the attack data packet having the attack type, and the processing strategy is used to instruct the switch to respond to the attack packet having the description information The packet performs the action indicated by the processing policy.
[0180] The sending unit 12 is configured to send the description information received by the receiving unit 10 and the processing strategy determined by the determining unit 11 to the switch via a software-defined network SDN controller, and the switch has The attack data p...
PUM
Login to View More Abstract
Description
Claims
Application Information
Login to View More 


