Method, device, equipment, storage medium and program product for processing link flooding attack

By calculating the entropy value of ICMP messages and generating routing strategies using a deep reinforcement learning model, the problem of detecting and mitigating link flooding attacks is solved, improving detection accuracy and system service quality.

CN116961951BActive Publication Date: 2026-06-23ZTE CORP
3 Cites 0 Cited by

Patent Information

Application Number
CN202210414864.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-04-20
Publication Date
2026-06-23
Estimated Expiration
2042-04-20

Smart Images

  • Figure CN116961951B_ABST
    Figure CN116961951B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a link flooding attack processing method, device and equipment and a storage medium, comprising: obtaining an ICMP message and calculating an information entropy value of the ICMP message; in the case that the information entropy value is less than a preset early warning threshold, locating a congestion link according to the information entropy value; obtaining current state information of the congestion link and inputting the current state information into a deep reinforcement learning model trained by a convolutional neural network and a Q-learning algorithm through historical state information and historical routing strategies to obtain a current routing strategy; and performing routing processing on the link flooding attack according to the routing strategy. Embodiments of the present application can detect the link flooding attack without increasing additional detection points and can improve the detection accuracy of the link flooding attack. Furthermore, embodiments of the present application can learn strategies from historical traffic and perform traffic engineering on data streams through deep reinforcement learning, thereby more efficiently coping with LFA attacks and improving the service quality of the system.
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • DDoS attack detection method and device

    CN110225037A

  • Method and device for detecting and recovering congested link, and medium

    CN111010330A

  • Integrated learning device and method for ICMP hidden tunnel detection in industrial control network

    CN114124834A