Network anomaly behavior protection method and device, computer device and storage medium
By using a cleaning center and cloud servers in a collaborative manner, data requests are cleaned and filtered using protection information generated by the client servers. This solves the problem of limited protection for network operators, effectively protects against DDoS attacks, and ensures the stability of client servers.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2023-03-23
- Publication Date
- 2026-07-10
Smart Images

Figure CN116346470B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, computer device, storage medium, and computer program product for protecting against abnormal network behavior. Background Technology
[0002] A distributed denial-of-service (DDoS) attack involves multiple computers sending a large number of requests, exhausting the target server's computing resources or network bandwidth, causing the target server to stop providing services, or even compromising the target server's data security.
[0003] In related technologies, DDoS requests sent to the corresponding area are protected by the network operator. However, the attack protection provided by the network operator has limitations, which can cause DDoS requests to penetrate the network operator's protection and pose security risks to the target server. Summary of the Invention
[0004] Therefore, it is necessary to provide a method, device, computer equipment, computer-readable storage medium, and computer program product for protecting against abnormal network behavior, which can improve the protection effect against abnormal network behavior.
[0005] Firstly, this application provides a method for protecting against abnormal network behavior. The method includes:
[0006] Receive data requests from network operators for the target network segment; the target network segment is the network segment corresponding to the network address of the client server; obtain protection information corresponding to the network address and generated by the client server according to business needs; perform data cleaning on the data request based on the protection information to obtain the cleaned data request; send the cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0007] Secondly, this application also provides a protective device for abnormal network behavior. The device includes:
[0008] The data request receiving module is used to receive data requests corresponding to the target network segment forwarded by the network operator; the target network segment is the network segment corresponding to the network address of the client server.
[0009] The first protection information acquisition module is used to acquire protection information corresponding to the network address and generated by the client server according to business requirements.
[0010] The first cleaning module is used to clean the data request based on the protection information to obtain the cleaned data request.
[0011] The data request sending module after cleaning is used to send a data request after cleaning to the cloud server, instructing the cloud server to filter the data request after cleaning based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0012] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:
[0013] Receive data requests from network operators for the target network segment; the target network segment is the network segment corresponding to the network address of the client server; obtain protection information corresponding to the network address and generated by the client server according to business needs; perform data cleaning on the data request based on the protection information to obtain the cleaned data request; send the cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0014] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:
[0015] Receive data requests from network operators for the target network segment; the target network segment is the network segment corresponding to the network address of the client server; obtain protection information corresponding to the network address and generated by the client server according to business needs; perform data cleaning on the data request based on the protection information to obtain the cleaned data request; send the cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0016] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:
[0017] Receive data requests from network operators for the target network segment; the target network segment is the network segment corresponding to the network address of the client server; obtain protection information corresponding to the network address and generated by the client server according to business needs; perform data cleaning on the data request based on the protection information to obtain the cleaned data request; send the cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0018] The aforementioned methods, devices, computer equipment, storage media, and computer program products for protecting against network anomalies involve a data cleaning center receiving data requests corresponding to the target network segment forwarded by the network operator. The cleaning center obtains protection information corresponding to the network address of the client server. This protection information is generated by the client server based on its business needs. The cleaning center cleans the data requests using this protection information and sends the cleaned data requests to a cloud server. The cloud server filters the cleaned data requests using the protection information, obtaining the target data request after filtering out data requests with anomalies. This target data request is then sent to the client server. Both the cleaning center and the cloud server perform data cleaning using protection information, ensuring that the protection against data requests with anomalies is adapted to the actual business needs of the client server. Therefore, data requests with anomalies can be effectively cleaned at the cleaning center. The cloud server then performs a second cleaning on the cleaned data requests to filter out a small number of data requests with anomalies that penetrate the cleaning center, resulting in the target data request after filtering out data requests with anomalies. This ensures the stability of the client server's business and improves the effectiveness of protecting against network anomalies.
[0019] Sixthly, this application provides a method for protecting against abnormal network behavior. The method includes:
[0020] Based on the business needs of the client server, determine the protection information corresponding to the network address; the network address is the address of the network where the client server is located; send the protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address; receive the cleaned data request sent by the cleaning center, and filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types; send the target data request to the client server.
[0021] Seventhly, this application also provides a protection device for abnormal network behavior. The device includes:
[0022] The second protection information acquisition module is used to determine the protection information corresponding to the network address based on the business requirements of the client server; the network address is the address of the network where the client server is located.
[0023] The protection information and network address sending module is used to send protection information and network addresses to the cleaning center, instructing the cleaning center to receive data requests corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data requests based on the protection information, and obtain the cleaned data requests; the target network segment is the network segment corresponding to the network address;
[0024] The second cleaning module is used to receive the post-cleaning data request sent by the cleaning center, and to filter the post-cleaning data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types.
[0025] The target data request sending module is used to send target data requests to the client server.
[0026] Eighthly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to perform the following steps:
[0027] Based on the business needs of the client server, determine the protection information corresponding to the network address; the network address is the address of the network where the client server is located; send the protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address; receive the cleaned data request sent by the cleaning center, and filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types; send the target data request to the client server.
[0028] Ninthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:
[0029] Based on the business needs of the client server, determine the protection information corresponding to the network address; the network address is the address of the network where the client server is located; send the protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address; receive the cleaned data request sent by the cleaning center, and filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types; send the target data request to the client server.
[0030] Tenthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, performs the following steps:
[0031] Based on the business needs of the client server, determine the protection information corresponding to the network address; the network address is the address of the network where the client server is located; send the protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address; receive the cleaned data request sent by the cleaning center, and filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types; send the target data request to the client server.
[0032] The aforementioned methods, devices, computer equipment, storage media, and computer program products for protecting against abnormal network behavior involve a cloud server obtaining protection information corresponding to the network address of the client server and sending the protection information and network address to a cleaning center. The cleaning center receives data requests corresponding to the target network forwarded by the operator. The cleaning center cleans the data requests using the protection information configured by the client server according to business needs. Thus, data requests of abnormal behavior types can be effectively cleaned at the cleaning center. The cloud server then performs a second cleaning on the cleaned data requests using the protection information to filter out a small number of abnormal behavior types of data requests that penetrate the cleaning center, resulting in the target data requests after filtering out abnormal behavior types. This ensures the stability of the client server's business and improves the protection effect against abnormal network behavior. Attached Figure Description
[0033] Figure 1 This is an application environment diagram of a method for preventing abnormal network behavior in one embodiment;
[0034] Figure 2 This is a flowchart illustrating a method for protecting against abnormal network behavior in one embodiment;
[0035] Figure 3 This is a schematic diagram of a method for protecting against abnormal network behavior in a scenario embodiment.
[0036] Figure 4 This is a flowchart illustrating a method for protecting against abnormal network behavior in another embodiment;
[0037] Figure 5 This is a flowchart illustrating a method for protecting against abnormal network behavior in yet another embodiment;
[0038] Figure 6 This is a schematic diagram of a protection configuration page in one embodiment;
[0039] Figure 7 This is a schematic diagram of a protection service purchase page in one embodiment;
[0040] Figure 8 This is a schematic diagram of the EIP application page of the protection platform in one embodiment;
[0041] Figure 9 This is a schematic diagram of the protection service management page in one embodiment;
[0042] Figure 10 This is a schematic diagram of a protection configuration page in one embodiment;
[0043] Figure 11 This is a schematic diagram of a protection overview page in one embodiment;
[0044] Figure 12 This is a schematic diagram of a method for protecting against abnormal network behavior in another scenario embodiment;
[0045] Figure 13 This is a schematic diagram of a method for protecting against abnormal network behavior in another scenario embodiment;
[0046] Figure 14 This is a flowchart illustrating a method for protecting against abnormal network behavior in yet another embodiment;
[0047] Figure 15 This is a structural block diagram of a method and apparatus for preventing abnormal network behavior in one embodiment;
[0048] Figure 16 This is a structural block diagram of a method and apparatus for preventing abnormal network behavior in another embodiment;
[0049] Figure 17 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0050] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0051] The network abnormal behavior protection method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, the cleaning center 102 communicates with the cloud server 104 via a network, and the cloud server 104 communicates with the client server 106 via a network. The data storage system can store the data that the cloud server 104 needs to process. The data storage system can be integrated onto the cloud server 104 or onto other servers.
[0052] The cleaning center 102 receives data requests corresponding to the target network segment forwarded by the network operator, obtains protection information corresponding to the network address of the client server 106 and generated by the client server 106 according to business needs, and makes data requests based on the protection information to obtain the cleaned data request. The cleaning center 102 can send the cleaned data request to the cloud server 104. The cloud server 104 filters the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types. The cloud server 104 can send the target data request to the client server 106.
[0053] The cleaning center 102 can be implemented using a cluster of multiple cleaning nodes; the cloud server 104 can be implemented using a standalone cloud server or a cluster of multiple cloud servers. The client server 106 can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, or a server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0054] In some embodiments, such as Figure 2 As shown, a method for protecting against abnormal network behavior is provided, which is based on the method described above. Figure 1 Taking the cleaning center in China as an example, the process includes the following steps:
[0055] Step 202: Receive the data request corresponding to the target network segment forwarded by the network operator; the target network segment is the network segment corresponding to the network address of the client server.
[0056] In this context, the network operator is the entity that operates the network and provides services. Multiple Internet Protocol (IP) addresses may belong to the target network segment. In practice, for two IP addresses, their subnet masks can be used to determine whether they belong to the same network segment. The client server's network address is the IP address belonging to the target network segment.
[0057] In some embodiments, when an access device accesses a client server based on a network address, the access device sends a data request to the network operator. The data request carries the network address of the client server. The network operator forwards the data request to the scrubbing center corresponding to the target network segment according to the target network segment to which the network address belongs. The scrubbing center receives the data request forwarded by the network operator.
[0058] In some embodiments, the scrubbing center and the network operator are located in the same geographical area. For example, the scrubbing center is deployed in region A, and the network operator provides network operation services to region A. Access devices located in region A send data requests to the network operator in region A, and the network operator in region A forwards the data requests to the scrubbing center deployed in region A.
[0059] In some embodiments, the scrubbing center that receives the data request forwarded by the network operator is the scrubbing center closest to the network operator among the scrubbing centers in each region. In other words, the scrubbing centers in each region can perform near-source scrubbing. For example, if scrubbing centers are deployed in regions A, B, and C, the network operator in region A will forward the requested data to the scrubbing center in region A. Since region D is closest to region C, the network operator in region D can forward the data request to the scrubbing center in region C.
[0060] In some embodiments, the method for protecting against abnormal network behavior further includes: receiving the network address of the client server sent by the cloud server, obtaining the corresponding target network segment based on the network address, and broadcasting the target network segment to the network operator, wherein the network operator and the cloud server are located in the same geographical area.
[0061] In some embodiments, the client server binds its network address to the cloud server. The cloud server sends the client server's network address to the cleaning center. The cleaning center determines the target network segment based on the network address and its subnet mask. The cleaning center then routes the target network segment so that the network operator forwards data requests with IP addresses belonging to the target network segment to the cleaning center. Since the client server's network address belongs to the target network segment, the cleaning center can receive data requests to access the client server.
[0062] In one implementation, the routers of multiple regional scrubbing centers broadcast the target network segment using unicast, so that the scrubbing centers in multiple regions receive data requests forwarded by the network operators in their respective regions. In another implementation, the routers of multiple regional scrubbing centers broadcast the target network segment using anycast, so that if a scrubbing center in a certain region fails, the network operator in that region can find the nearest scrubbing center.
[0063] It should be noted that the router in the cleaning center can also broadcast the target network segment using multicast or groupcast. The broadcast method of the target network segment can be set according to the business needs of the customer server, and this application embodiment does not limit this.
[0064] In the above embodiment, the cleaning center broadcasts the target network segment to which the network address of the client server belongs to the network operator. Then, the network operator forwards the data requests whose destination address belongs to the target network to the cleaning center, so that the cleaning center can obtain the data requests to access the client server, so as to clean the data requests in the future.
[0065] Step 204: Obtain the protection information corresponding to the network address, which is generated by the client server based on business requirements.
[0066] Among them, the protection information is generated by the client server based on business needs. The protection information is used to reflect the data request method of the abnormal behavior type. Through the protection information, data requests that access the network address of the client server can be filtered.
[0067] Protection information may include, but is not limited to, protection lists, blocked transmission protocols, and port information. Protection information may also include at least one of these three types. Protection lists can filter data requests whose source address belongs to the protection list; blocking transmission protocols can filter data requests whose transmission protocol is a blocked transmission protocol; and port information can filter data requests whose source port belongs to the specified port information.
[0068] In some embodiments, the client server generates protection information corresponding to network addresses based on business requirements. For example, if the client server receives a large number of abnormal data requests using the UDP (User Datagram Protocol) transport protocol, which is a message-oriented transport layer protocol, the protection information can be configured to block transport protocols, including UDP, thereby filtering UDP data requests. In practical applications, the client can configure the protection settings through a protection configuration page based on the client server's business requirements, sending configuration information to the client server. The client server then generates the protection information corresponding to the network addresses based on this configuration information.
[0069] The cleaning center obtains the protection information corresponding to the network address, and then cleans the data requests according to the protection information configured on the customer's server.
[0070] In some embodiments, step 204 includes: receiving protection information corresponding to a network address sent by a cloud server; the protection information is generated by the client server based on business requirements.
[0071] In one implementation, the client server sends protection information to the cloud server, the cloud server sends protection information to the cleaning center, and the cleaning center receives the protection information sent by the cloud server. In another implementation, the cloud server sends the client server's network address to the cleaning center at the same time as sending protection information, and the cleaning center receives the network address and the corresponding protection information.
[0072] In the above embodiments, the cleaning center receives protection information sent by the cloud server, so that the cleaning center and the cloud server have the same protection information. Moreover, the protection information is configured by the client server according to business needs, so that the cleaning center and the cloud server can perform targeted protection for data requests according to the protection information configured by the client server.
[0073] Step 206: Clean the data request based on the protection information to obtain the cleaned data request.
[0074] In some embodiments, the cleaning center determines candidate data requests corresponding to the network address of the client server in the data request, determines data requests with abnormal behavior types based on the protection information corresponding to the network address, filters data requests with abnormal behavior types, and obtains cleaned data requests, thereby improving the cleaning effect of data requests.
[0075] Since the cleaning center receives data requests corresponding to the target network segment, the data requests may include data requests whose destination address is not the network address of the client server. Therefore, the cleaning center needs to filter out the data requests corresponding to the network address of the client server and then clean the data requests corresponding to the network address. Step S206 includes: obtaining the five-tuple information based on the data request; determining the candidate data requests corresponding to the network address based on the five-tuple information in the data requests corresponding to the target network segment; cleaning the candidate data requests based on the protection information to obtain the cleaned data requests.
[0076] The 5-tuple information includes the source address, source port, destination address, destination port, and transport layer protocol.
[0077] In some embodiments, for a data request corresponding to a target network segment, the cleaning center obtains the five-tuple information of the data request, determines candidate data requests whose destination address is a network address based on the destination address included in the five-tuple information, cleans the candidate data requests using protection information, and obtains the cleaned data request.
[0078] In some embodiments, the scrubbing center includes multiple routers and multiple gateway nodes. The multiple routers receive data requests corresponding to the target network segment forwarded by the operator. Based on the five-tuple information of the data request, the routers forward the data request to the gateway node according to load balancing, so that data with the same destination address is aggregated to the same gateway node. In turn, the candidate data requests corresponding to the network address of the client server are aggregated to a gateway node. The gateway node is configured with protection information corresponding to the network address, and the candidate data requests corresponding to the network address are scrubbed using the protection information corresponding to the network address.
[0079] In some embodiments, the router forwards the data request to the gateway node according to load balancing based on the 5-tuple information of the data request. This includes: the router determining the hash result based on the 5-tuple information of the data request; for a previously forwarded data request and a data request to be forwarded, if the hash results of the previously forwarded data request and the data request to be forwarded are the same, the router selects the forwarding path of the previously forwarded data request and forwards the data request to be forwarded to the corresponding gateway node; if the hash results of the previously forwarded data request and the data request to be forwarded are different, the router selects an idle path and forwards the data request to be forwarded to the corresponding gateway node. In practical applications, the hash of the source address IP in the 5-tuple information can be used as the hash result of the 5-tuple information.
[0080] In some embodiments, protection information is integrated into the gateway node in the form of a .so library. The gateway node corresponding to the network address of the client server calls the .so library to clean the candidate data request. The .so library is a dynamic link library.
[0081] For example, UDP-flood is a type of DDoS attack. UDP-flood refers to sending a flood of UDP requests to a target device in a short period of time, causing the target device to be unable to respond to normal requests. In order to protect against UDP-flood, the client server is configured with protection information to block the UDP transport protocol. The cleaning center integrates the protection information into the gateway node in the form of a .so library. When the gateway node determines through the .so library that the candidate data request includes a large number of UDP requests, it filters out the UDP requests in the packet, so that the UDP-flood is effectively mitigated in the cleaning center.
[0082] In the above embodiments, the cleaning center determines the candidate data request corresponding to the network address of the client server based on the five-tuple information of the data request, cleans the candidate data request through protection information, and obtains the cleaned data request. By using the protection information configured on the client server, the center can perform targeted cleaning of the candidate data request corresponding to the network address of the client server, thereby improving the cleaning effect of the data request.
[0083] Step 208: Send a cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0084] Among them, data requests of abnormal behavior type are data requests determined based on protection information. When the protection information includes a protection list, data requests of abnormal behavior type can be data requests whose source address belongs to the protection list. When the protection information includes blocking transmission protocols, data requests of abnormal behavior type can be data requests whose transmission protocol is a blocked transmission protocol.
[0085] In some embodiments, the gateway node of the cleaning center can transmit the cleaned data request to the cloud server through a physical leased line or a GRE tunnel; the physical leased line is a dedicated communication line for data transmission between the cleaning center and the cloud server, and GRE (General Routing Encapsulation) is a general routing encapsulation protocol.
[0086] The cloud server filters the cleaned data requests using the protection information corresponding to the network address of the client server, obtains the target data request, and sends the target data request to the client server through the cloud network.
[0087] It should be noted that the candidate data requests corresponding to the network address undergo the first cleaning at the cleaning center and the second cleaning on the cloud server. The protection information used in both is configured by the customer's server according to business needs. The cloud server filters the cleaned data requests using the protection information, which is the same process as the cleaning center filtering the candidate data requests using the protection information.
[0088] In the above embodiment, the cleaning center receives data requests corresponding to the target network segment forwarded by the network operator, obtains protection information corresponding to the network address of the client server (this protection information is generated by the client server based on business needs), cleans the data requests using this protection information, and sends the cleaned data requests to the cloud server. The cloud server filters the cleaned data requests using the protection information to obtain the target data requests after filtering out abnormal behavior types, and then sends the target data requests to the client server. Both the cleaning center and the cloud server perform data cleaning using protection information, ensuring that the protection against abnormal behavior types of data requests is adapted to the actual business needs of the client server. Therefore, abnormal behavior types of data requests can be effectively cleaned at the cleaning center. The cloud server then performs a second cleaning on the cleaned data requests to filter out a small number of abnormal behavior types that penetrate the cleaning center, resulting in the target data requests after filtering out abnormal behavior types. This ensures the stability of the client server's business and improves the protection effect against abnormal network behavior.
[0089] In some embodiments, the protection information includes a protection list; cleaning candidate data requests based on the protection information to obtain cleaned data requests includes: obtaining the source address corresponding to the candidate data request; obtaining a first data request to be cleaned whose source address belongs to the protection list from the candidate data requests; cleaning the first data request to be cleaned to obtain cleaned data requests.
[0090] The protection list includes protected source addresses, which are the source addresses that are not allowed to access the client server.
[0091] In some embodiments, the gateway node of the cleaning center obtains the source address of the candidate data request based on the five-tuple information of the candidate data request. When the source address of the candidate data request is a protected source address included in the protection list, the candidate data request is taken as the first data request to be cleaned, and the first data request to be cleaned in the candidate data request is cleaned to obtain the cleaned data request. It should be noted that the first data request to be cleaned belongs to the data request of abnormal behavior type.
[0092] In the above embodiments, the protection list is set by the client server according to business needs. The cleaning center cleans the cleaned data requests according to the protection list, so that data requests with the source address of the protection source address cannot be sent to the client server, thereby improving the protection effect against abnormal network behavior.
[0093] In some embodiments, the protection information includes blocking transmission protocols; cleaning candidate data requests based on the protection information to obtain cleaned data requests includes: if the traffic of a candidate data request is greater than a traffic threshold, obtaining a second data request to be cleaned from the candidate data requests whose transmission protocol belongs to a blocked transmission protocol; cleaning the second data request to be cleaned to obtain cleaned data requests.
[0094] The blocking transmission protocol may include at least one of the following: UDP transmission protocol, TCP transmission protocol, or ICMP transmission protocol. TCP (Transmission Control Protocol) is a connection-oriented, reliable, byte-stream-based transport layer communication protocol; ICMP (Internet Control Message Protocol) is a connectionless protocol.
[0095] Blocking the transport protocol includes UDP, which can protect against UDP-flood DDoS attacks; blocking the transport protocol includes TCP, which can protect against TCP-flood DDoS attacks; and blocking the transport protocol includes ICMP, which can protect against ICMP-flood DDoS attacks. TCP-flood refers to sending a flood of TCP requests to a target device in a short period, causing the target device to be unable to respond to normal requests. ICMP-flood refers to sending a flood of ICMP requests to a target device in a short period, causing the target device to be unable to respond to normal requests.
[0096] The traffic threshold can be set by the client server according to business needs, or it can be determined by the cleaning center through deep learning of historical records of network anomaly protection using neural networks.
[0097] In some embodiments, the cleaning center acquires the traffic of candidate data requests. When the traffic of a candidate data request exceeds a traffic threshold, the center determines the transmission protocol of the candidate data request based on the 5-tuple information of the candidate data request. Candidate data requests with a transmission protocol of blocking protocol are designated as second data requests to be cleaned. The cleaning center then cleans these second data requests from the candidate data requests to obtain cleaned data requests. It should be noted that the second data request to be cleaned is a data request exhibiting abnormal behavior.
[0098] For example, in order to protect against TCP-flood and ICMP-flood, the client server is configured to block protection information for the transmission protocols including TCP and ICMP; the cleaning center determines the traffic of candidate data requests. When the traffic of candidate data requests exceeds the traffic threshold, the cleaning center determines the second data request to be cleaned from the candidate data requests that uses TCP and ICMP transmission protocols, and cleans the second data request to be cleaned to obtain the cleaned data request.
[0099] In some embodiments, the protection information includes a protection list and blocked transmission protocols. Based on the protection information, candidate data requests are cleaned to obtain cleaned data requests, including: obtaining the source address corresponding to the candidate data request; obtaining a first data request to be cleaned whose source address belongs to the protection list from the candidate data requests; if the traffic of the candidate data request is greater than a traffic threshold, obtaining a second data request to be cleaned whose transmission protocol belongs to a blocked transmission protocol from the candidate data requests; and cleaning the first and second data requests to be cleaned to obtain cleaned data requests.
[0100] In other words, the cleaning center determines the first data request to be cleaned from the candidate data requests based on the protection list, and determines the second data request to be cleaned from the candidate data requests based on the blocking transmission protocol. The first and second data requests to be cleaned are then filtered out, so as to achieve data request cleaning by combining multiple protection information.
[0101] In some embodiments, the protection list further includes a non-protection list and a blocked transmission protocol. The non-protection list includes non-protected source addresses. Based on the protection information, candidate data requests are cleaned to obtain cleaned data requests, including: when the traffic of a candidate data request is greater than a traffic threshold, a second data request to be cleaned is obtained from the candidate data requests whose transmission protocol belongs to a blocked transmission protocol; a third data request to be cleaned is determined from the second data request to be cleaned whose source address does not belong to the non-protection list; the cleaning center cleans the third data request to be cleaned to obtain cleaned data requests.
[0102] In some embodiments, to avoid filtering out data requests with non-protected source addresses, only the third data requests in the second list of data requests to be cleaned, whose source address is not a non-protected source address, are cleaned. The non-protected source addresses in the non-protected list are set by the client server according to business needs, allowing data requests with non-protected source addresses to access the client server.
[0103] In the above embodiments, the blocking transmission protocol is set by the client server according to business needs. The cleaning center can clean a large number of data requests with at least one of the transmission protocols of UDP, TCP or ICMP according to the blocking transmission protocol, thereby protecting against at least one of the DDoS attacks of UDP-flood, TCP-flood or ICMP-flood type, and improving the protection effect against abnormal network behavior.
[0104] In some embodiments, the method for protecting against abnormal network behavior includes: receiving a test request sent by a cloud server; receiving a blocking instruction sent by the cloud server when the response to the test request times out; and stopping the broadcast of the target network segment to the network operator based on the blocking instruction.
[0105] Among them, dialing is a method of testing network link quality. The dialing request is used to test the link of the cleaning center. The dialing request can be a Ping request, and the Ping (Packet Internet Groper) request is a network exploration request.
[0106] A timeout in responding to a test request refers to a response time exceeding a specified threshold. For example, if a cloud server sends a test request but does not receive a response within the specified threshold, the test request response is considered to have timed out.
[0107] In some embodiments, the cloud server may periodically send Ping requests to the cleaning center. The cleaning center receives and responds to the Ping request. If the cleaning center's response to the Ping request times out, it indicates that the link to the requesting center is abnormal. The cloud server then sends a blocking instruction to the cleaning center. The cleaning center receives the blocking instruction and stops broadcasting the target network segment to the network operator according to the blocking instruction.
[0108] In some embodiments, the scrubbing center can receive and respond to a test request sent by a test node. If the test node determines that the scrubbing center's response to the test node times out, it determines that there is a link anomaly in the scrubbing center. The test node then feeds back the test result indicating that there is a link anomaly in the scrubbing center to the cloud server. The cloud server sends a blocking instruction to the scrubbing center, and the scrubbing center stops broadcasting the target network segment to the network operator according to the blocking instruction.
[0109] In some embodiments, after the scrubbing center stops broadcasting the target network segment to the network operator, it can perform link maintenance operations. If the scrubbing center's link is restored, the scrubbing center can continue to broadcast the target network segment to the network operator.
[0110] In some embodiments, after a scrubbing center stops broadcasting the target network segment to a network operator, the network operator can locate the nearest scrubbing center and forward the data request to that center. For example, network operator A in region A forwards the requested data to scrubbing center A in region A. If scrubbing center A experiences a link failure and stops broadcasting the target network segment to network operator A, network operator A can forward the data request to the scrubbing center in region B, which is the closest scrubbing center to scrubbing center A.
[0111] In some embodiments, after the cloud server sends a blocking instruction to the cleaning center, it sends a routing broadcast instruction to another cleaning center to instruct the other cleaning center to broadcast the target network segment, so that the network operator forwards the data request corresponding to the target network segment to the other cleaning center.
[0112] In related technologies, data requests are cleaned through internal cleaning nodes of the network operator. However, the cloud server cannot promptly detect link anomalies in these cleaning nodes, leading to data request scheduling issues and impacting the stability of client server services. In the above embodiment, the cloud server can perform probe testing on the cleaning center to promptly determine its link status. When a cleaning center experiences a link anomaly, the cloud server uses a blocking command to control the cleaning center to stop broadcasting the target network segment to the network operator. Consequently, the network operator will not forward data requests to the faulty cleaning center and can instead forward data requests to other cleaning centers, achieving data request scheduling, ensuring client server service stability, and improving disaster recovery capabilities.
[0113] In some embodiments, methods for protecting against abnormal network behavior can be applied to Figure 3 In the application scenario shown, cleaning centers and cloud servers are deployed in regions A, B, and C, respectively, and the client server is located in region B; the cleaning centers and cloud servers in each region have the same protection information for the client server.
[0114] Access devices in region A initiate data request Q11. Cleaning center A in region A receives data request Q11 forwarded by network operator A in region A. Cleaning center A cleans the candidate data request Q12 corresponding to the network address in data request Q11 using the protection information corresponding to the network address of the client server, and obtains cleaned data request Q13. Cleaned data request Q13 is forwarded to cloud server A in region A. Cloud server A cleansed data request Q13 using the protection information, and obtains target data request Q14. Cloud server A sends target data request Q14 to cloud server B in region B. Cloud server B sends target data request Q14 to the client server.
[0115] Access devices in region B initiate data request Q21. The scrubbing center B in region B receives data request Q21 forwarded by the network operator B of region B. The scrubbing center B uses protection information to scrub the candidate data request Q22 corresponding to the network address in data request Q21, resulting in a cleaned data request Q23. The cleaned data request Q23 is then forwarded to the cloud server B in region B. The cloud server B uses protection information to scrub the cleaned data request Q23, resulting in the target data request Q24. The cloud server B then sends the target data request Q24 to the client server.
[0116] Cleaning center C and cloud server C in region C send the target data obtained from cleaning to the client server in the same way as cleaning center A and cloud server A.
[0117] In some embodiments, such as Figure 4 As shown, methods for protecting against abnormal network behavior include:
[0118] Step 401: The cleaning center receives the network address of the client server sent by the cloud server; obtains the corresponding target network segment based on the network address; broadcasts the target network segment to the network operator; the network operator and the cloud server are located in the same geographical area.
[0119] Step 402: The cleaning center receives the data request corresponding to the target network segment forwarded by the network operator.
[0120] In some embodiments, the client server binds its network address to the cloud server. The cloud server sends the client server's network address to the cleaning center. The cleaning center determines the target network segment based on the network address and its subnet mask. The cleaning center then routes the target network segment so that the network operator forwards data requests with IP addresses belonging to the target network segment to the cleaning center. Since the client server's network address belongs to the target network segment, the cleaning center can receive data requests to access the client server.
[0121] Step 403: The cleaning center receives the protection information corresponding to the network address sent by the cloud server; the protection information is generated by the customer server based on business requirements.
[0122] In some embodiments, the client server generates protection information corresponding to network addresses based on business needs. For example, if the client server's network address receives a large number of abnormal behavior-type data requests, including many data requests belonging to the UDP transport protocol, the protection information can be configured to include blocking the transport protocol, specifically the UDP transport protocol. This protection information filters data requests using the UDP transport protocol. The scrubbing center receives the protection information sent by the cloud server, ensuring that the scrubbing center and the cloud server have the same protection information.
[0123] Step 404: The cleaning center obtains the quintuple information based on the data request, and determines the candidate data request corresponding to the network address in the data request corresponding to the target network segment based on the quintuple information.
[0124] In some embodiments, for a data request corresponding to a target network segment, the cleaning center obtains the five-tuple information of the data request, determines candidate data requests whose destination address is a network address based on the destination address included in the five-tuple information, cleans the candidate data requests using protection information, and obtains the cleaned data request.
[0125] Step 405A: The protection information includes a protection list; the cleaning center obtains the source address corresponding to the candidate data request, obtains the first data request to be cleaned whose source address belongs to the protection list from the candidate data requests, cleans the first data request to be cleaned, and obtains the cleaned data request.
[0126] The protection list includes protected source addresses, which are the source addresses that are not allowed to access the client server.
[0127] Step 405B: The protection information includes the blocking transmission protocol. If the traffic of the candidate data request is greater than the traffic threshold, the cleaning center obtains the second data request to be cleaned from the candidate data requests, whose transmission protocol belongs to the blocked transmission protocol, and cleans the second data request to be cleaned to obtain the cleaned data request.
[0128] The blocking transmission protocol may include at least one of the following: UDP transmission protocol, TCP transmission protocol, or ICMP transmission protocol.
[0129] Step 406: The cleaning center sends a post-cleaning data request to the cloud server to instruct the cloud server to filter the post-cleaning data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0130] In some embodiments, the cloud server filters the cleaned data request using the protection information corresponding to the network address of the client server to obtain the target data request, and then sends the target data request to the client server through the cloud network.
[0131] Step 407: The cleaning center receives a test request from the cloud server. If the response to the test request times out, it receives a blocking instruction from the cloud server. Based on the blocking instruction, it stops broadcasting the target network segment to the network operator.
[0132] In some embodiments, the cloud server may periodically send Ping requests to the cleaning center. The cleaning center receives and responds to the Ping request. If the cleaning center's response to the Ping request times out, it indicates that the link to the requesting center is abnormal. The cloud server then sends a blocking instruction to the cleaning center. The cleaning center receives the blocking instruction and stops broadcasting the target network segment to the network operator according to the blocking instruction.
[0133] In the above embodiments, the cleaning center receives data requests corresponding to the target network segment forwarded by the network operator, obtains protection information corresponding to the network address of the client server, the protection information is generated by the client server according to business needs, the cleaning center cleans the data requests using the protection information, and sends the cleaned data requests to the cloud server, the cloud server filters the cleaned data requests using the protection information, obtains the target data requests after filtering out data requests with abnormal behavior types, and sends the target data requests to the client server. Both the cleaning center and the cloud server perform data cleaning using protective information, ensuring that the protection against abnormal behavior data requests is adapted to the actual business needs of the client server. Thus, abnormal behavior data requests are effectively cleaned at the cleaning center, and then a second cleaning is performed on the cloud server to filter out a small number of abnormal behavior data requests that penetrate the cleaning center. This results in the target data requests after filtering out abnormal behavior data requests, ensuring the stability of the client server's business and improving the protection against network anomalies. Furthermore, in related technologies, routing is broadcast through the network operator, and the method and area of routing are fixed and cannot be adjusted according to the client server's business needs. In the above embodiment, routing is broadcast to the network operator through the cleaning center, allowing the method and area of routing to be adjusted according to the client's business needs, thus meeting the client server's business access latency requirements.
[0134] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0135] In some embodiments, such as Figure 5 As shown, a method for protecting against abnormal network behavior is provided, which is based on the method described above. Figure 1 Taking the execution of a cloud server as an example, the following steps are included:
[0136] Step 502: Determine the protection information corresponding to the network address based on the business requirements of the client server; the network address is the address of the network where the client server is located.
[0137] In some embodiments, the client server configures protection information corresponding to the network address according to business requirements, sends the protection information to the cloud server, and the cloud server receives the protection information sent by the client server.
[0138] In some embodiments, the client performs configuration operations on the protection configuration page of the protection platform to send configuration information to the client server. The client server generates protection information corresponding to the network address based on the configuration information. The protection information may include, but is not limited to: protection list, blocked transmission protocols, and port information.
[0139] like Figure 6 As shown, the protection configuration page 601 includes: a network address selection area 602 for DDoS protection, and a configuration area 603 for DDoS protection. The network address selection area 602 includes the network address of the client server; the configuration area 603 includes configuration areas corresponding to various protection information, such as: protection list configuration area, protocol blocking configuration area, and port filtering configuration area. When the network address of the client server is selected in the protection configuration page, various protection information can be configured through the configuration area 603 to obtain the protection information corresponding to the network address.
[0140] For example, the client server's network address is 111.***, and this network address is selected. The protection list configuration area includes a description of the protection function of the protection list 6031. In response to a trigger operation on the setting control 6032 in the protection list configuration area, the client displays the protection list settings page, where protected source addresses can be added. The port filtering configuration area includes a description of the protection function of port filtering 6033. In response to a trigger operation on the setting control 6034 in the port filtering configuration area, the client displays the port filtering configuration settings page, where filtered source port information can be added. The protocol blocking configuration area includes a description of the protection function of protocol blocking 6035. In response to a trigger operation on the setting control 6036 in the protocol blocking configuration area, the client displays the protocol blocking settings page, where blocked transport protocols can be added.
[0141] It should be noted that, Figure 6The content displayed on the protection configuration page is only an example of this application. In practical applications, the protection configuration page may also include a configuration area for other protection information, as well as other content related to DDoS protection. This application embodiment does not limit this.
[0142] The client configures various protection information on the protection configuration page to obtain the configuration information, and sends the configuration information to the client server. The client server generates protection information corresponding to the network address based on the configuration information and sends the protection information corresponding to the network address to the cloud server.
[0143] Step 504: Send protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address.
[0144] In some embodiments, the cloud server sends its network address and corresponding protection information to the scrubbing center. After receiving the network address and corresponding protection information from the cloud server, the scrubbing center receives data requests forwarded by the network operator.
[0145] In some embodiments, sending protection information and a network address to the cleaning center to instruct the cleaning center to receive data requests corresponding to the target network segment forwarded by the network operator includes: sending protection information and a network address to the cleaning center to instruct the cleaning center to obtain the corresponding target network segment based on the network address, broadcasting the target network segment to the network operator, and receiving data requests corresponding to the target network segment forwarded by the network operator; the network operator and the cloud server are located in the same geographical area.
[0146] In some embodiments, the specific process of the scrubbing center obtaining the corresponding target network segment based on the network address, broadcasting the target network segment to the network operator, and receiving the data request corresponding to the target network segment forwarded by the network operator can be referred to the description of the scrubbing center receiving the data request corresponding to the target network segment forwarded by the network operator in the above embodiments.
[0147] The cleaning center receives data requests corresponding to the target network segment forwarded by the operator, cleans the data requests based on the protection information, and obtains the cleaned data requests. The process is the same as step 204 in the above embodiment. Therefore, the process of step 504 can be found in the detailed description of step 204 in the above embodiment.
[0148] Step 506: Receive the post-cleaning data request sent by the cleaning center, and filter the post-cleaning data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types.
[0149] In some embodiments, the protection information includes a protection list. The cloud server filters the cleaned data requests based on the protection information to obtain the target data request after filtering out data requests with abnormal behavior types. This includes: the cloud server obtaining the source address corresponding to the cleaned data request; obtaining the fourth data request to be cleaned whose source address belongs to the protection list from the cleaned data request; and cleaning the fourth data request to be cleaned to obtain the target data request after filtering out data requests with abnormal behavior types.
[0150] In some embodiments, the protection information includes blocking transmission protocols; the cloud server filters the cleaned data requests based on the protection information to obtain the target data requests after filtering out data requests with abnormal behavior types, including: when the traffic of the cleaned data requests is greater than the traffic threshold, the cloud server obtains a fifth data request to be cleaned from the cleaned data requests whose transmission protocol belongs to the blocked transmission protocol; cleans the fifth data request to be cleaned to obtain the target data requests after filtering out data requests with abnormal behavior types.
[0151] In some embodiments, the protection information includes a protection list and blocked transmission protocols. The cloud server filters the cleaned data requests based on the protection information to obtain the target data request after filtering out data requests with abnormal behavior types. This includes: the cloud server obtaining the source address corresponding to the cleaned data request; obtaining a fourth data request to be cleaned whose source address belongs to the protection list from the cleaned data requests; if the traffic of the cleaned data request is greater than the traffic threshold, obtaining a fifth data request to be cleaned from the cleaned data requests whose transmission protocol belongs to the blocked transmission protocol, and cleaning the fourth and fifth data requests to be cleaned to obtain the target data request after filtering out data requests with abnormal behavior types.
[0152] In some embodiments, the protection information includes a non-protection list and blocked transmission protocols; the cloud server filters the cleaned data requests based on the protection information to obtain the target data requests after filtering out data requests with abnormal behavior types, including: when the traffic of the cleaned data requests exceeds the traffic threshold, the cloud server obtains a fifth data request to be cleaned from the cleaned data requests whose transmission protocol belongs to a blocked transmission protocol; in the fifth data request to be cleaned, a sixth data request to be cleaned is determined whose source address does not belong to the non-protection list, and the cleaning center cleans the sixth data request to be cleaned to obtain the cleaned data requests.
[0153] Step 508: Send the target data request to the client server.
[0154] In the aforementioned method for protecting against abnormal network behavior, the cloud server obtains the protection information corresponding to the network address of the client server and sends the protection information and network address to the cleaning center. The cleaning center receives data requests corresponding to the target network forwarded by the operator. The cleaning center cleans the data requests using the protection information, which is configured by the client server according to business needs. Thus, data requests of abnormal behavior types can be effectively cleaned in the cleaning center. The cloud server then performs a second cleaning on the cleaned data requests using the protection information to filter out a small number of abnormal behavior types of data requests that penetrate the cleaning center, resulting in the target data requests after filtering out the abnormal behavior types of data requests. This ensures the stability of the client server's business and improves the protection effect against abnormal network behavior.
[0155] In some embodiments, the method for protecting against abnormal network behavior further includes: sending a dial-up test request to the cleaning center; and, if the cleaning center times out responding to the dial-up test request, sending a blocking instruction to the cleaning center to instruct the cleaning center to stop broadcasting the target network segment to the network operator.
[0156] In some embodiments, the cloud server may periodically send a test request to the cleaning center. The cleaning center receives and responds to the test request. If the cleaning center's response to the test request times out, it is determined that the link of the requesting center is abnormal. The cloud server sends a blocking instruction to the cleaning center. The cleaning center receives the blocking instruction and stops broadcasting the target network segment to the network operator according to the blocking instruction.
[0157] In some embodiments, after the cloud server sends a blocking instruction to the cleaning center, it sends a routing broadcast instruction to another cleaning center to instruct the other cleaning center to broadcast the target network segment broadcast by the cleaning center that received the blocking instruction, so that the network operator forwards the data request corresponding to the target network segment to the other cleaning center.
[0158] In related technologies, data requests are cleaned through internal cleaning nodes of the network operator. However, the cloud server cannot promptly detect link anomalies in these cleaning nodes, leading to data request scheduling issues and impacting the stability of client server services. In the above embodiment, the cloud server can perform probe testing on the cleaning center to promptly determine its link status. When a cleaning center experiences a link anomaly, the cloud server uses a blocking command to control the cleaning center to stop broadcasting the target network segment to the network operator. Consequently, the network operator will not forward data requests to the faulty cleaning center and can instead forward data requests to other cleaning centers, achieving data request scheduling, ensuring client server service stability, and improving disaster recovery capabilities.
[0159] In some embodiments, before determining the protection information corresponding to the network address based on the business needs of the client server, the method further includes: in response to an association request sent by the client server, establishing an association relationship between the network address of the client server and the cloud server; the network address is an address with protection attributes requested based on the protection services provided by the client server.
[0160] In some embodiments, a client can purchase protection services for a client server on a protection platform. Based on the protection services provided by the client server, a network address with protection attributes is requested. This network address is an Elastic IP address (EIP). The requested network address is then associated with the server.
[0161] For example, such as Figure 7 As shown, on the protection service purchase page 701 of the protection platform, protection services are purchased according to the business needs of the customer's server. The protection service purchase page 701 includes description information 702 for the protection service, which includes the bandwidth type and protected objects. The protection service purchase page also includes a protection zone selection control 703, for example... Figure 7 The system includes selection controls for regions A, B, C, and D, allowing users to choose a protection region based on the network address of the client server. The protection service purchase page 701 also includes a control 704 for selecting the number of protected network addresses, allowing users to choose the number of protected network addresses according to business needs. The client responds to the confirmation purchase control 705 on the protection service purchase page 701 by completing the purchase of the protection service, thus equipping the client server with protection services. It should be noted that... Figure 7 This is just one example of a protection service purchase page. The protection service purchase page may also include other related content, such as the validity period of the protection service, the bandwidth of the protection service, etc. This application embodiment does not limit the specific content of the protection service purchase page.
[0162] like Figure 8 As shown, on the EIP application page 801 of the protection platform, select the EIP corresponding to the type of protection service purchased. The selection control 802 corresponding to the protection service type is selected. Protection against DDoS attacks can be performed by selecting the protection service type. Select the service area corresponding to the protection service, for example... Figure 8 The selected service area for the protection service is designated as Region A. The EIP application page 801 of the protection platform also allows you to set the bandwidth limit for the protection service. It should be noted that... Figure 8 The EIP application page shown is just an example. In actual applications, the EIP application page may include more relevant content or be displayed in other styles. This application embodiment does not limit this.
[0163] After completing the EIP application, you obtain a network address with protection attributes. Then, you configure the protection service through the protection service management page of the protection platform. For example... Figure 9 As shown, the protection service management page 901 includes a description of the protection service, purchase information for the protection service, a description of the network address, and a protection object management control 902. The protection object management control 902 is used to establish an association between the client's server's network address and the cloud server. It should be noted that... Figure 9 The protection service management page shown is just an example. In actual applications, the protection service management page may include more related content and may be displayed in other styles. This application embodiment does not limit this.
[0164] The client responds to a triggered action on the protected object management control by displaying the protected object management page; such as Figure 10 As shown, the protected object management page 1001 includes network address description information 1002, associated device selection control 1003, candidate device area 1004, selected device area 1005, and confirmation control 1006. In response to a trigger operation on the associated device type selection control 1003, the client displays a list of associatable device types in the candidate device area 1004. This list includes each candidate cloud server and its corresponding related information. In response to a selection operation on a candidate cloud server, the client displays the selected cloud server and its related information in the selected device area 1005. In response to a trigger operation on the confirmation control 1006 in the protected object management page 1001, the client server sends an association request to the selected cloud server. The client server forwards the association request to the selected cloud server, and the cloud server responds to the association request, establishing an association between the client server's network address and the cloud server.
[0165] In the above embodiments, the cloud server establishes an association between the network address of the client server and the cloud server based on the association request sent by the client server. This enables the cloud server to communicate with the public network through the network address, clean the cleaned data request through the protection information corresponding to the network address, and send the target data request to the client server.
[0166] In some embodiments, the method for protecting against abnormal network behavior further includes: receiving cleaning information sent by a cleaning center after cleaning the data request; responding to a protection overview instruction sent by a client server, obtaining the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time based on the cleaning information; sending the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client server to instruct the client server to send the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client, so that the client can display the protection overview page according to the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time.
[0167] The protection overview command can be sent from the client to the client server, and then from the client server to the cloud server.
[0168] The cleaning information includes the type of abnormal behavior corresponding to the data request for data cleaning, as well as the number of requests and the time of the request corresponding to the abnormal behavior type. Abnormal behavior types include, but are not limited to: UDP-flood, TCP-flood, and ICMP-flood types; the number of requests corresponding to the abnormal behavior type is the number of data requests of the abnormal behavior type cleaned by the cleaning center, and the abnormal behavior time is the moment when the cleaning center identified the abnormal behavior type.
[0169] In some embodiments, after the cleaning center cleans the data request, it obtains the cleaning information corresponding to this protection and sends the cleaning information to the cloud server. In response to the trigger operation of the protection overview control on the protection service control page, the client sends a protection overview instruction to the client server. The client server forwards the protection overview instruction to the cloud server. In response to the protection overview instruction, the cloud server sends the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client server based on the cleaning information. The client server sends the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client. The client displays the protection overview page according to the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time.
[0170] For example, such as Figure 11 As shown, the protection overview page 1101 includes an attack status area, which includes: the abnormal behavior type is UDP-flood, the abnormal behavior time corresponding to the UDP-flood type is: YMD, 12:00:00, and the number of requests corresponding to the UDP-flood type is: 10**; the attack status area may also include other relevant information about DDoS attacks, such as the peak traffic of the DDoS attack.
[0171] In some embodiments, the protection overview page 1101 further includes a protection status area, which includes: the number of DDoS attacks, the number of DDoS attacks suffered by the client server's network address, and the duration of each DDoS attack. The number of DDoS attacks and the duration of each DDoS attack can be displayed using a protection trend line graph, as shown in the example below. Figure 11 As shown in 1102.
[0172] In some embodiments, when the protection service of the client server requests multiple network addresses with protection attributes, the protection overview area also includes the number of network addresses with protection attributes, and the number of network addresses with protection attributes that have been subjected to DDoS attacks.
[0173] In the above embodiment, the cloud server sends the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client server. The client server then sends the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client. The client can view the specific details of DDoS attack protection on the protection overview page, allowing the client to more intuitively browse the data on network abnormal behavior protection.
[0174] In some embodiments, methods for protecting against abnormal network behavior can be applied to, for example... Figure 12 The scenario is illustrated. A network anomaly protection architecture is constructed using network operators, a scrubbing center, cloud servers, and client servers. This architecture includes an access layer, a protection layer, and a back-to-origin layer. The access layer includes the routers of the network operator and the scrubbing center, as well as the core controller of the cloud server. The protection layer includes the gateway node and data aggregation center of the scrubbing center. The back-to-origin layer includes the client server and the cloud-based scrubbing system of the cloud server.
[0175] At the access layer, the routers in the scrubbing center connect to the network operator and broadcast the target network segment to the network operator. This broadcasting can be done through the BGP routing protocol. BGP is an inter-autonomous system routing protocol that can detect routing loops and make routing decisions based on performance priorities and policy constraints. The routers communicate with the core controller through interfaces. The core controller can control the target network segment broadcast by the routers. For example, if there is a link anomaly in the scrubbing center, the core controller can control the routers to stop broadcasting the target network segment.
[0176] For the protection layer, the protection information is integrated into the gateway node of the cleaning center in the form of a .so library. Each gateway node of the cleaning center aggregates the candidate data requests corresponding to the network address to a single gateway node. The gateway node of the cleaning center cleans the candidate data requests corresponding to the network address. After cleaning the candidate data requests, the gateway node reports the cleaning information to the data aggregation center. The data aggregation center can send the cleaning information to the cloud server, and then send it to the client server through the cloud server.
[0177] For the origin layer, the gateway node of the cleaning center injects the cleaned data requests back to the cloud server. The cloud cleaning system on the cloud server cleans the cleaned data requests according to the protection information, and then sends the cleaned target data requests to the client server.
[0178] In some embodiments, methods for protecting against abnormal network behavior can be applied to, for example... Figure 13 The scenario is illustrated. A method for protecting against abnormal network behavior is implemented jointly by the client, client server, scrubbing center, and cloud server; the cloud server includes a gateway, DDoS backend service, network address backend service, and a cloud-based scrubbing system.
[0179] The client can configure the protection services available on the client server on the protection platform. The client purchases protection services on the protection platform, requests a network address with protection attributes based on the available protection services, and performs a binding operation between the protection service and the network address. The client generates a binding request based on this binding operation and sends the binding request to the client server. The client server transmits the binding request to the cloud server through the cloud server's gateway. The protection service information and network address included in the binding request are verified by the DDoS backend service and the network address backend service. If it is determined that the network address is a network address with protection attributes based on the protection service request, the cloud server binds the protection service and the network address.
[0180] The cloud server obtains the protection information corresponding to the network address of the customer server, and sends the network address and corresponding protection information to the cloud cleaning system of the cloud server through the DDoS background service. The cloud cleaning system then distributes the network address and corresponding protection information to the cleaning center, so that both the cleaning center and the cloud server have the protection information corresponding to the network address of the customer server. The cloud cleaning system and the cleaning center can send cleaning information to the DDoS background service through message queues.
[0181] The cloud-based cleaning system and cleaning center can store protection information and DDoS attack protection data in a MySQL database to improve data query efficiency. MySQL is a relational database. The cloud-based cleaning system and cleaning center can also cache DDoS attack protection requests in Redis, a high-performance, open-source, C-language non-relational database.
[0182] In some embodiments, such as Figure 14 As shown, methods for protecting against abnormal network behavior include:
[0183] Step 14O1: In response to the association request sent by the client server, the cloud server establishes an association between the client server's network address and the cloud server; the network address is an address with protection attributes requested based on the protection services provided by the client server.
[0184] In some embodiments, the client purchases protection services for the client server from the protection platform. Based on the network address of the protection service request provided by the client server, the client sends an association request to the client server. The client server forwards the association request to the selected cloud server. The cloud server responds to the association request and establishes an association between the network address of the client server and the cloud server.
[0185] Step 14O2: The cloud server determines the protection information corresponding to the network address based on the business needs of the customer server; the network address is the address of the network where the customer server is located.
[0186] The protection information may include, but is not limited to: protection lists, blocked transmission protocols, and port information.
[0187] Step 1403: The cloud server sends protection information and network address to the cleaning center, instructing the cleaning center to obtain the corresponding target network segment based on the network address, broadcast the target network segment to the network operator, and receive data requests corresponding to the target network segment forwarded by the network operator; the network operator and the cloud server are located in the same geographical area.
[0188] In some embodiments, the cloud server sends protection information and network address to the cleaning center. The cleaning center obtains the corresponding target network segment based on the network address, broadcasts the target network segment to the network operator, and receives data requests corresponding to the target network segment forwarded by the network operator.
[0189] Step 1404: The cloud server receives the post-cleaning data request sent by the cleaning center, and filters the post-cleaning data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types.
[0190] In some embodiments, the protection information includes a protection list; the cloud server obtains the source address corresponding to the cleaned data request; the fourth data request to be cleaned whose source address belongs to the protection list is obtained from the cleaned data request; the fourth data request to be cleaned is cleaned to obtain the target data request after filtering out data requests with abnormal behavior types.
[0191] In some embodiments, the protection information includes blocking transmission protocols; when the traffic of the cleaned data request exceeds the traffic threshold, the cloud server obtains the fifth data request to be cleaned from the cleaned data requests whose transmission protocol belongs to the blocked transmission protocol; the fifth data request to be cleaned is cleaned to obtain the target data request after filtering out data requests with abnormal behavior types.
[0192] Step 14O5: The cloud server sends the target data request to the client server;
[0193] Step 14O6: The cloud server receives cleaning information sent by the cleaning center after cleaning the data request. In response to the protection overview instruction sent by the client server, it obtains the abnormal behavior type, the corresponding request quantity, and the request time based on the cleaning information. It then sends the abnormal behavior type, the corresponding request quantity, and the request time to the client server, instructing the client server to send the abnormal behavior type, the corresponding request quantity, and the abnormal behavior time to the client, so that the client can display the protection overview page based on the abnormal behavior type, the corresponding request quantity, and the abnormal behavior time.
[0194] The protection overview command can be sent from the client to the client server, and then from the client server to the cloud server. The cleaning information includes the abnormal behavior type corresponding to the data cleaning request, as well as the number of requests and the request time corresponding to each abnormal behavior type. Abnormal behavior types include, but are not limited to: UDP-flood, TCP-flood, and ICMP-flood. The number of requests corresponding to each abnormal behavior type is the number of data requests that the cleaning center cleans for that abnormal behavior type, and the abnormal behavior time is the moment the cleaning center identifies the abnormal behavior type.
[0195] In some embodiments, after the cleaning center cleans the data request, it obtains the cleaning information corresponding to this protection and sends the cleaning information to the cloud server. In response to the trigger operation of the protection overview control on the protection service control page, the client sends a protection overview instruction to the client server. The client server forwards the protection overview instruction to the cloud server. In response to the protection overview instruction, the cloud server sends the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client server based on the cleaning information. The client server sends the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client. The client displays the protection overview page according to the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time.
[0196] Step 14O7: The cloud server sends a test request to the cleaning center; if the cleaning center times out in response to the test request, the cloud server sends a blocking command to the cleaning center to instruct the cleaning center to stop broadcasting the target network segment to the network operator.
[0197] In some embodiments, the cloud server may periodically send a test request to the cleaning center. The cleaning center receives and responds to the test request. If the cleaning center's response to the test request times out, it is determined that the link of the requesting center is abnormal. The cloud server sends a blocking instruction to the cleaning center. The cleaning center receives the blocking instruction and stops broadcasting the target network segment to the network operator according to the blocking instruction.
[0198] In the aforementioned method for protecting against abnormal network behavior, the cloud server obtains the protection information corresponding to the network address of the client server and sends the protection information and network address to the cleaning center. The cleaning center receives data requests corresponding to the target network forwarded by the operator. The cleaning center cleans the data requests using the protection information, which is configured by the client server according to business needs. Thus, data requests of abnormal behavior types can be effectively cleaned in the cleaning center. The cloud server then performs a second cleaning on the cleaned data requests using the protection information to filter out a small number of abnormal behavior types of data requests that penetrate the cleaning center, resulting in the target data requests after filtering out the abnormal behavior types of data requests. This ensures the stability of the client server's business and improves the protection effect against abnormal network behavior.
[0199] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0200] Based on the same inventive concept, this application also provides a network anomaly protection device for implementing the network anomaly protection method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations in one or more network anomaly protection device embodiments provided below can be found in the limitations of the network anomaly protection method described above, and will not be repeated here.
[0201] In some embodiments, such as Figure 15 As shown, a network anomaly protection device is provided, comprising: a data request receiving module 1501, a first protection information acquisition module 1502, a first cleaning module 1503, and a cleaned data request sending module 1504; wherein,
[0202] The data request receiving module 1501 is used to receive data requests corresponding to the target network segment forwarded by the network operator; the target network segment is the network segment corresponding to the network address of the client server.
[0203] The first protection information acquisition module 1502 is used to acquire protection information corresponding to the network address and generated by the client server according to business requirements.
[0204] The first cleaning module 1503 is used to clean the data request based on the protection information to obtain the cleaned data request.
[0205] The data request sending module 1504 after cleaning is used to send a data request after cleaning to the cloud server, instructing the cloud server to filter the data request after cleaning according to the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server.
[0206] In some embodiments, the protection device against abnormal network behavior further includes:
[0207] The target network segment broadcasting module is used to receive the network address of the client server sent by the cloud server, obtain the corresponding target network segment based on the network address, and broadcast the target network segment to the network operator; the network operator and the cloud server are located in the same geographical area.
[0208] In some embodiments, the protection device against abnormal network behavior further includes:
[0209] The first testing module is used to receive testing requests sent by the cloud server; if the response to the testing request times out, it receives a blocking instruction sent by the cloud server; based on the blocking instruction, it stops broadcasting the target network segment to the network operator.
[0210] In some embodiments, the first protection information acquisition module 1502 is specifically used to receive protection information corresponding to the network address sent by the cloud server; the protection information is generated by the client server according to business requirements.
[0211] In some embodiments, the first cleaning module 1503 includes:
[0212] The candidate data request determination unit is used to obtain 5-tuple information based on the data request; and to determine the candidate data request corresponding to the network address based on the 5-tuple information in the data request corresponding to the target network segment.
[0213] The data cleaning unit is used to clean candidate data requests based on protection information to obtain cleaned data requests.
[0214] In some embodiments, the protection information includes a protection list; a data cleaning unit is specifically used to obtain the source address corresponding to the candidate data request; obtain the first data request to be cleaned whose source address belongs to the protection list from the candidate data requests; clean the first data request to be cleaned to obtain the cleaned data request.
[0215] In some embodiments, the protection information includes a blocking transmission protocol; a data cleaning unit is specifically used to, when the traffic of a candidate data request is greater than a traffic threshold, obtain a second data request to be cleaned from the candidate data requests whose transmission protocol belongs to a blocked transmission protocol; clean the second data request to be cleaned to obtain a cleaned data request.
[0216] In some embodiments, such as Figure 16 As shown, a network anomaly protection device is provided, comprising: a second protection information acquisition module 1601, a protection information and network address sending module 1602, a second cleaning module 1603, and a target data request sending module 1604; wherein,
[0217] The second protection information acquisition module 1601 is used to determine the protection information corresponding to the network address based on the business requirements of the client server; the network address is the address of the network where the client server is located.
[0218] The protection information and network address sending module 1602 is used to send protection information and network address to the cleaning center, instructing the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address;
[0219] The second cleaning module 1603 is used to receive the post-cleaning data request sent by the cleaning center, and to filter the post-cleaning data request according to the protection information to obtain the target data request after filtering out the data requests with abnormal behavior types.
[0220] The target data request sending module 1604 is used to send the target data request to the client server.
[0221] In some embodiments, the protection information and network address sending module 1602 is specifically used to send protection information and network address to the cleaning center, so as to instruct the cleaning center to obtain the corresponding target network segment based on the network address, broadcast the target network segment to the network operator, and receive the data request corresponding to the target network segment forwarded by the network operator; the network operator and the cloud server are located in the same geographical area.
[0222] In some embodiments, the network abnormal behavior protection device further includes: a second dialing test module, used to send a dialing test request to the cleaning center; and in the event that the cleaning center times out responding to the dialing test request, sending a blocking instruction to the cleaning center to instruct the cleaning center to stop broadcasting the target network segment to the network operator.
[0223] In some embodiments, the protection device against abnormal network behavior further includes: an association module;
[0224] The association module is used to respond to association requests sent by the client server and establish an association between the client server's network address and the cloud server; the network address is an address with protection attributes requested based on the protection services provided by the client server.
[0225] In some embodiments, the protection device against abnormal network behavior further includes: a cleaning information sending module;
[0226] The cleaning information sending module is used to receive cleaning information sent by the cleaning center after cleaning the data request; in response to the protection overview command sent by the client server, it obtains the abnormal behavior type, the corresponding request quantity, and the abnormal behavior time based on the cleaning information; and sends the abnormal behavior type, the corresponding request quantity, and the abnormal behavior time to the client server to instruct the client server to send the abnormal behavior type, the corresponding request quantity, and the abnormal behavior time to the client, so that the client can display the protection overview page according to the abnormal behavior type, the corresponding request quantity, and the abnormal behavior time.
[0227] The modules in the aforementioned network anomaly protection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0228] In some embodiments, a computer device is provided, which may be a cleaning center or a cloud server, and its internal structure diagram may be as follows: Figure 17 As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores data requests, protection information, and network addresses. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When executed by the processor, the computer program implements a method for protecting against abnormal network behavior.
[0229] Those skilled in the art will understand that Figure 17 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0230] In some embodiments, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0231] Receive data requests from network operators for a target network segment; the target network segment is the network segment corresponding to the client server's network address; obtain protection information corresponding to the network address, generated by the client server based on business needs; perform data cleaning on the data request based on the protection information to obtain a cleaned data request; send the cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server; or...
[0232] Based on the business needs of the client server, determine the protection information corresponding to the network address; the network address is the address of the network where the client server is located; send the protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address; receive the cleaned data request sent by the cleaning center, and filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types; send the target data request to the client server.
[0233] In some embodiments, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0234] Receive data requests from network operators for a target network segment; the target network segment is the network segment corresponding to the client server's network address; obtain protection information corresponding to the network address, generated by the client server based on business needs; perform data cleaning on the data request based on the protection information to obtain a cleaned data request; send the cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server; or...
[0235] Based on the business needs of the client server, determine the protection information corresponding to the network address; the network address is the address of the network where the client server is located; send the protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address; receive the cleaned data request sent by the cleaning center, and filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types; send the target data request to the client server.
[0236] In some embodiments, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0237] Receive data requests from network operators for a target network segment; the target network segment is the network segment corresponding to the client server's network address; obtain protection information corresponding to the network address, generated by the client server based on business needs; perform data cleaning on the data request based on the protection information to obtain a cleaned data request; send the cleaned data request to the cloud server to instruct the cloud server to filter the cleaned data request based on the protection information, obtain the target data request after filtering out data requests with abnormal behavior types, and send the target data request to the client server; or...
[0238] Based on the business needs of the client server, determine the protection information corresponding to the network address; the network address is the address of the network where the client server is located; send the protection information and network address to the cleaning center to instruct the cleaning center to receive the data request corresponding to the target network segment forwarded by the network operator, perform data cleaning on the data request based on the protection information, and obtain the cleaned data request; the target network segment is the network segment corresponding to the network address; receive the cleaned data request sent by the cleaning center, and filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types; send the target data request to the client server.
[0239] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data shall comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0240] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0241] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0242] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for protecting against abnormal network behavior, characterized in that, The method is applied to a cleaning center, where the router of the cleaning center is connected to the network operator, and includes: Under the control of the core controller of the cloud server, the router broadcasts the target network segment corresponding to the network address of the client server to the network operator; wherein, after the client server binds its network address to the cloud server, the cloud server sends the network address of the client server to the scrubbing center, so that the scrubbing center can determine the target network segment corresponding to the network address. The router receives data requests corresponding to the target network segment forwarded by the network operator. Based on the five-tuple information of the data request, it determines the hash result. For a previous data request and a data request to be forwarded, if the hash results of the previous data request and the data request to be forwarded are the same, the forwarding path of the previous data request is selected, and the data request to be forwarded is forwarded to the corresponding gateway node. If the hash results of the previous data request and the data request to be forwarded are different, an idle path is selected, and the data request to be forwarded is forwarded to the corresponding gateway node, so that data with the same destination address is aggregated to the same gateway node. Candidate data requests corresponding to the network address of the client server are aggregated to one gateway node. The data request is sent to the network operator by the accessing device when accessing the client server based on the network address. Each gateway node in the cleaning center obtains protection information corresponding to the network address and generated by the client server according to business requirements; the protection information is integrated into the gateway node of the cleaning center; the data request is cleaned based on the protection information to obtain the cleaned data request; wherein, after cleaning the candidate data request corresponding to the network address, each gateway node of the cleaning center reports the cleaning information to the data aggregation center, so that the data aggregation center sends the cleaning information to the cloud server, and then sends it to the client server through the cloud server; The gateway node injects the cleaned data request back to the cloud server. The access device, the cleaning center, and the cloud server are located in the same geographical area. The cleaned data request instructs the cloud server to filter the cleaned data request according to the protection information to obtain the target data request after filtering out data requests with abnormal behavior types. The target data request is then sent to the client server through the cloud server located in the same geographical area as the client server. Upon receiving a blocking instruction from the cloud server, the router, under the control of the core controller, stops broadcasting the target network segment to the network operator, and the cloud server instructs another scrubbing center to broadcast the target network segment.
2. The method according to claim 1, characterized in that, The method further includes: Receive the network address of the client server sent by the cloud server; Obtain the corresponding target network segment based on the network address.
3. The method according to claim 2, characterized in that, The method further includes: Receive the test request sent by the cloud server; If the response to the dial-up test request times out, a blocking instruction sent by the cloud server is received.
4. The method according to claim 1, characterized in that, The step of obtaining the protection information corresponding to the network address and generated by the client server according to business requirements includes: The client server receives protection information corresponding to the network address sent by the cloud server; the protection information is generated by the client server based on business requirements.
5. The method according to claim 1, characterized in that, The step of cleaning the data request based on the protection information to obtain the cleaned data request includes: Based on the data, request the quintuple information; In the data request corresponding to the target network segment, a candidate data request corresponding to the network address is determined based on the five-tuple information; The candidate data request is cleaned based on the protection information to obtain the cleaned data request.
6. The method according to claim 5, characterized in that, The protection information includes a protection list; the step of cleaning the candidate data requests based on the protection information to obtain cleaned data requests includes: Obtain the source address corresponding to the candidate data request; In the candidate data request, obtain the first data request to be cleaned whose source address belongs to the protection list; The first data request to be cleaned is cleaned to obtain the cleaned data request.
7. The method according to claim 5, characterized in that, The protection information includes blocking transmission protocols; the step of cleaning the candidate data requests based on the protection information to obtain cleaned data requests includes: If the traffic of the candidate data request exceeds the traffic threshold, a second data request to be cleaned, whose transport protocol belongs to the blocked transport protocol, is obtained from the candidate data requests. The second data request to be cleaned is cleaned to obtain the cleaned data request.
8. A method for protecting against abnormal network behavior, characterized in that, Applied to cloud servers, the method includes: The protection information corresponding to the network address is determined based on the business requirements of the client server; the network address is the address of the network where the client server is located. The system sends the protection information and the network address to the cleaning center, instructing the cleaning center to receive data requests corresponding to the target network segment forwarded by the network operator, and to perform data cleaning on the data requests based on the protection information to obtain cleaned data requests. The target network segment corresponds to the network address of the client server and is broadcast to the network operator by the router of the cleaning center under the control of the core controller of the cloud server. The data request is sent to the network operator by the access device when accessing the client server based on the network address. The access device, the cleaning center, and the cloud server are located in the same geographical area. The protection information is integrated into the gateway node of the cleaning center. The client server displays its network address. After the address is bound to the cloud server, the cloud server sends the network address of the client server to the cleaning center, enabling the cleaning center to determine the target network segment corresponding to the network address. Each gateway node of the cleaning center is used to obtain protection information corresponding to the network address and generated by the client server according to business needs. The protection information is integrated into the gateway nodes of the cleaning center. Based on the protection information, the data request is cleaned to obtain the cleaned data request. Among them, after each gateway node of the cleaning center cleans the candidate data request corresponding to the network address, it reports the cleaning information to the data aggregation center, so that the data aggregation center sends the cleaning information to the cloud server, and then sends it to the client server through the cloud server. The system receives the post-cleaning data request from the gateway node of the cleaning center and filters the post-cleaning data request based on the protection information to obtain the target data request after filtering out data requests with abnormal behavior types. If the cloud server and the client server are not in the same geographical region, the target data request is forwarded to the cloud server located in the same geographical region as the client server, and the cloud server sends the target data request to the client server. A blocking command is sent to the cleaning center, and the core controller controls the router of the cleaning center to stop broadcasting the target network segment to the network operator; Instruct another cleaning center to broadcast the target network segment.
9. The method according to claim 8, characterized in that, Sending the protection information and the network address to the cleaning center to instruct the cleaning center to receive data requests corresponding to the target network segment forwarded by the network operator includes: The system sends the protection information and the network address to the cleaning center, instructing the cleaning center to obtain the corresponding target network segment based on the network address, broadcast the target network segment to the network operator, and receive data requests corresponding to the target network segment forwarded by the network operator; the network operator and the cloud server are located in the same geographical area.
10. The method according to claim 9, characterized in that, The method further includes: Send a test request to the cleaning center; If the cleaning center times out in response to the dialing request, a blocking command is sent to the cleaning center to instruct the cleaning center to stop broadcasting the target network segment to the network operator.
11. The method according to claim 8, characterized in that, Before determining the protection information corresponding to the network address based on the client server's business requirements, the process also includes: In response to the association request sent by the client server, an association relationship is established between the network address of the client server and the cloud server; the network address is an address with protection attributes requested based on the protection services provided by the client server.
12. The method according to claim 8, characterized in that, The method further includes: Receive cleaning information sent by the cleaning center after cleaning the data request; In response to the protection overview command sent by the client server, the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time are obtained based on the cleaning information; The abnormal behavior type, the corresponding number of requests, and the abnormal behavior time are sent to the client server to instruct the client server to send the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client, so that the client can display the protection overview page based on the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time.
13. A protective device for abnormal network behavior, characterized in that, The device is used in a cleaning center, where the router of the cleaning center connects to the network operator. The device includes: The target network segment broadcast module is used to broadcast the target network segment corresponding to the network address of the client server to the network operator through the router under the control of the core controller of the cloud server; wherein, after the client server binds its network address to the cloud server, the cloud server sends the network address of the client server to the cleaning center, so that the cleaning center can determine the target network segment corresponding to the network address. The data request receiving module is used to receive data requests corresponding to the target network segment forwarded by the network operator through the router; determine the hash result based on the five-tuple information of the data request; for a previously forwarded data request and a data request to be forwarded, if the hash results of the previously forwarded data request and the data request to be forwarded are the same, select the forwarding path of the previously forwarded data request and forward the data request to be forwarded to the corresponding gateway node; if the hash results of the previously forwarded data request and the data request to be forwarded are different, select an idle path and forward the data request to be forwarded to the corresponding gateway node, so that data with the same destination address are aggregated to the same gateway node, wherein candidate data requests corresponding to the network address of the client server are aggregated to one gateway node; the data request is sent to the network operator by the access device when accessing the client server based on the network address. The first protection information acquisition module is used to acquire protection information corresponding to the network address and generated by the client server according to business requirements through each gateway node of the cleaning center; the protection information is integrated into the gateway node of the cleaning center. The first cleaning module is used to clean the data request based on the protection information through each gateway node of the cleaning center to obtain the cleaned data request; wherein, after cleaning the candidate data request corresponding to the network address, each gateway node of the cleaning center reports the cleaning information to the data aggregation center, so that the data aggregation center sends the cleaning information to the cloud server, and then sends it to the client server through the cloud server. The post-cleaning data request sending module is used to inject the post-cleaning data request back to the cloud server through the gateway node. The access device, the cleaning center, and the cloud server are located in the same geographical area. The post-cleaning data request instructs the cloud server to perform data filtering on the post-cleaning data request based on the protection information to obtain the target data request after filtering out data requests with abnormal behavior types, and to send the target data request to the client server through the cloud server located in the same geographical area as the client server. The target network segment broadcasting module is also used to, after receiving a blocking instruction sent by the cloud server, under the control of the core controller, stop broadcasting the target network segment to the network operator through the router, and instruct another cleaning center to broadcast the target network segment by the cloud server.
14. The network abnormal behavior protection device according to claim 13, characterized in that, The target network segment broadcasting module is also used to receive the network address of the client server sent by the cloud server; and to obtain the corresponding target network segment based on the network address.
15. The network abnormal behavior protection device according to claim 14, characterized in that, The device further includes a first testing module, which is used to receive a testing request sent by the cloud server; and to receive a blocking instruction sent by the cloud server if the response to the testing request times out.
16. The network abnormal behavior protection device according to claim 13, characterized in that, The first protection information acquisition module is also used to receive protection information corresponding to the network address sent by the cloud server; the protection information is generated by the client server according to business requirements.
17. The network abnormal behavior protection device according to claim 13, characterized in that, The first cleaning module includes: A candidate data request determination unit is used to obtain five-tuple information based on the data request; and to determine, based on the five-tuple information, a candidate data request corresponding to the network address in the data request corresponding to the target network segment. The data cleaning unit is used to clean the candidate data request based on the protection information to obtain the cleaned data request.
18. The network abnormal behavior protection device according to claim 17, characterized in that, The protection information includes a protection list; the data cleaning unit is also used to obtain the source address corresponding to the candidate data request; obtain the first data request to be cleaned whose source address belongs to the protection list from the candidate data request; clean the first data request to be cleaned to obtain the cleaned data request.
19. The network abnormal behavior protection device according to claim 17, characterized in that, The protection information includes blocking transmission protocols; the data cleaning unit is also used to, when the traffic of the candidate data request is greater than the traffic threshold, obtain a second data request to be cleaned from the candidate data requests whose transmission protocol belongs to the blocked transmission protocol. The second data request to be cleaned is cleaned to obtain the cleaned data request.
20. A protective device for abnormal network behavior, characterized in that, The device, applied to a cloud server, includes: The second protection information acquisition module is used to determine the protection information corresponding to the network address based on the business requirements of the client server; the network address is the address of the network where the client server is located. The protection information and network address sending module is used to send the protection information and network address to the cleaning center, instructing the cleaning center to receive data requests corresponding to the target network segment forwarded by the network operator, and to perform data cleaning on the data requests based on the protection information to obtain cleaned data requests; the target network segment corresponds to the network address of the client server, and is broadcast to the network operator by the router of the cleaning center under the control of the core controller of the cloud server; the data request is sent to the network operator by the access device when accessing the client server based on the network address; the access device, the cleaning center, and the cloud server are located in the same geographical area; the protection information is integrated into the gateway node of the cleaning center; the client... After the server binds its network address to the cloud server, the cloud server sends the client server's network address to the cleaning center, enabling the cleaning center to determine the target network segment corresponding to the network address. Each gateway node of the cleaning center is used to obtain protection information corresponding to the network address and generated by the client server according to business needs. The protection information is integrated into the gateway nodes of the cleaning center. Based on the protection information, the data request is cleaned to obtain the cleaned data request. Among them, after each gateway node of the cleaning center cleans the candidate data request corresponding to the network address, it reports the cleaning information to the data aggregation center, which then sends the cleaning information to the cloud server, and the cloud server sends it to the client server. The second cleaning module is used to receive the cleaned data request injected back by the gateway node of the cleaning center, and to filter the cleaned data request according to the protection information to obtain the target data request after filtering out the data request with abnormal behavior type. The target data request sending module is used to forward the target data request to the cloud server located in the same geographical area as the client server when the cloud server and the client server are not in the same geographical area, and the cloud server sends the target data request to the client server. The protection information and network address sending module is also used to send a blocking instruction to the cleaning center, control the router of the cleaning center to stop broadcasting the target network segment to the network operator through the core controller, and instruct another cleaning center to broadcast the target network segment.
21. The network abnormal behavior protection device according to claim 20, characterized in that, The protection information and network address sending module is also used to send the protection information and the network address to the cleaning center, so as to instruct the cleaning center to obtain the corresponding target network segment based on the network address, broadcast the target network segment to the network operator, and receive the data request corresponding to the target network segment forwarded by the network operator; the network operator and the cloud server are located in the same geographical area.
22. The network abnormal behavior protection device according to claim 21, characterized in that, The device further includes a second testing module, which is used to send a testing request to the cleaning center; if the cleaning center times out in response to the testing request, the second testing module sends a blocking instruction to the cleaning center to instruct the cleaning center to stop broadcasting the target network segment to the network operator.
23. The network abnormal behavior protection device according to claim 20, characterized in that, The device further includes an association module, which is used to establish an association between the network address of the client server and the cloud server in response to an association request sent by the client server; the network address is an address with protection attributes requested based on the protection service provided by the client server.
24. The network abnormal behavior protection device according to claim 20, characterized in that, The device further includes a cleaning information sending module, which is used to receive cleaning information sent by the cleaning center after cleaning the data request; in response to the protection overview command sent by the client server, it obtains the abnormal behavior type, the corresponding number of requests and the time of abnormal behavior based on the cleaning information; The abnormal behavior type, the corresponding number of requests, and the abnormal behavior time are sent to the client server to instruct the client server to send the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time to the client, so that the client can display the protection overview page based on the abnormal behavior type, the corresponding number of requests, and the abnormal behavior time.
25. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 12.
26. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 12.
27. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Large-scale DDoS (Distributed Denial of Service) attack defense system and method based on two-level linkage mechanism
CN101924764A
Network security protection method, device and system
CN112351012A