A method, device and system for processing attack data packets

A processing method and data packet technology, applied in the field of communication, can solve problems such as occupying large network bandwidth and affecting data packet transmission

Active Publication Date: 2019-02-26
HUAWEI TECH CO LTD
View PDF4 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0004] However, in the above-mentioned method of preventing the attack data packets from entering the cloud server through the firewall, since the firewall can only prevent the attack data packets from entering the cloud server, the switch responsible for forwarding the data packets to the firewall will still forward these attack data packets to the firewall. , that is, the attack data packets will still be transmitted in the network, therefore, these abnormal data packets will occupy a large amount of network bandwidth, thereby affecting the transmission of normal data packets

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • A method, device and system for processing attack data packets
  • A method, device and system for processing attack data packets
  • A method, device and system for processing attack data packets

Examples

Experimental program
Comparison scheme
Effect test

Embodiment 1

[0098] Embodiments of the present invention provide a method for processing attack data packets, such as figure 2 As shown, the method may include:

[0099] S101. The management node receives the description information of the attack data packet and the attack type of the attack data packet sent by the sensing node.

[0100] Among them, the attack data packet can be understood as a data packet that poses a threat to the sensing node, such as a data packet with a malformed message, a data packet with abnormal packet fragmentation, and an invalid transmission control protocol (English: transmission control protocol, abbreviation: TCP) connection. data packets, data packets with excessive data volume, etc.

[0101] Optionally, the description information of the attack data packet may be information obtained by the sensing node from the header of the attack data packet, specifically, the source IP address of the attack data packet, the destination IP address of the attack data p...

Embodiment 2

[0147] Embodiments of the present invention provide a method for processing attack data packets, such as Figure 6 As shown, the method may include:

[0148] S401. The sensing node receives the data packet.

[0149] S402. The sensing node identifies the data packet as an attack data packet.

[0150] S403. The sensing node determines the description information of the attack data packet and the attack type of the attack data packet.

[0151] S404. The perception node sends the description information and the attack type to the management node.

[0152] Specifically, for the specific implementation of the above S401-S404, please refer to the following Figure 5 Relevant descriptions in the illustrated embodiment will not be repeated here.

[0153] S405. After receiving the description information and the attack type sent by the sensing node, the management node determines, according to the attack type, a processing policy for the attack data packet with the attack type.

[...

Embodiment 3

[0177] Such as Figure 11 As shown, the embodiment of the present invention provides a management node, and the management node may include:

[0178]The receiving unit 10 is configured to receive the description information of the attack data packet sent by the sensing node and the attack type of the attack data packet.

[0179] The determining unit 11 is configured to determine, according to the attack type received by the receiving unit 10, a processing strategy for the attack data packet having the attack type, and the processing strategy is used to instruct the switch to respond to the attack packet having the description information The packet performs the action indicated by the processing policy.

[0180] The sending unit 12 is configured to send the description information received by the receiving unit 10 and the processing strategy determined by the determining unit 11 to the switch via a software-defined network SDN controller, and the switch has The attack data p...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

Embodiments of the present invention provide a method, device, and system for processing attack data packets, which relate to the field of communication technology, can limit the network bandwidth occupied by attack data packets when they are transmitted in the network, and ensure normal data packet transmission. The method includes: The management node receives the description information of the attack data packet sent by the sensing node and the attack type of the attack data packet, determines the processing strategy for the attack data packet with the attack type according to the attack type, and sends the attack data packet to the switch via the SDN controller. The description information and the processing policy, the switch performs the operation indicated by the processing policy on the attack data packet with the description information, and the processing policy is used to instruct the switch to perform the operation indicated by the processing policy on the attack data packet with the description information. This method is applied to network security maintenance technology.

Description

technical field [0001] The present invention relates to the technical field of communications, in particular to a method, device and system for processing attack data packets. Background technique [0002] With the rapid development of cloud technology, more and more problems appear in the application of cloud technology. For example, when a server in a cloud data center (hereinafter referred to as a cloud server) performs network protocol (English: Internet Protocol, abbreviation: IP) communication, it will be attacked by various attack packets, such as distributed denial of service (English: distributed denial of service). , Abbreviation: DDoS) attacks, fake news attacks, etc. Therefore, processing attack data packets and ensuring secure communication of cloud servers has become one of the core technologies of cloud technology. [0003] Currently, a common way to process attack packets is by deploying a physical firewall on the ingress cloud server of the cloud data cent...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & AuthorityPatents(China)
IPC IPC(8): H04L29/06H04L12/24H04L45/42H04L45/74H04L47/20
CPCH04L63/1458H04L63/1441H04L45/54H04L63/0236H04L63/20H04L63/302H04L9/40G06F9/45558H04L69/22
Inventor余庆华杨欣华
OwnerHUAWEI TECH CO LTD