Node anomaly detection method and device, equipment, storage medium and program product
By detecting the functions of target nodes and analyzing their transmission control functions, the problem of low accuracy in detecting spoofed traffic is solved, and efficient identification of abnormal nodes and network security protection are achieved.
Patent Information
- Application Number
- CN202410530063.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-28
- Publication Date
- 2025-10-28
AI Technical Summary
In existing technologies, when spoofed traffic is used to simulate public protocols for data transmission, the detection accuracy is low, making it difficult to identify malicious uses and cyberattacks.
By obtaining the target node's current communication protocol, functional testing is performed, transmission control functions are analyzed, and it is determined whether the target node has transmission control functions, thereby confirming the compliance of its communication protocol.
It improves the accuracy of abnormal node detection, prevents illegal data transmission and network attacks, and enhances network security and reliability.
Smart Images

Figure CN120856359A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and in particular relates to a node anomaly detection method, detection device, electronic device, computer-readable storage medium, and computer program product. Background Technology
[0002] Black and gray market activities on the internet involve various obfuscated and encrypted traffic disguised as public protocols like Transmission Control Protocol (TCP) for data transmission. Because the message format of this disguised traffic is essentially identical to the simulated public protocol, detection accuracy based on the simulated public protocol message format is generally low. A large amount of undetected disguised traffic may be used for illegal purposes. For example, using disguised traffic to transmit illicit data is illegal and may endanger public health and property. Furthermore, using disguised traffic for network attacks (such as TCP flooding attacks) can lead to excessive resource consumption on servers, even causing them to malfunction. Summary of the Invention
[0003] This application aims to address at least one of the technical problems existing in the prior art. To this end, this application proposes a node anomaly detection method, detection device, electronic device, computer-readable storage medium, and computer program product, which can improve the detection accuracy of abnormal nodes.
[0004] In a first aspect, this application provides a node anomaly detection method, comprising: acquiring the current communication protocol of a target node, the current communication protocol being determined based on the target node's communication data; performing functional detection on the target node to obtain detection data, the functional detection being used to detect at least one transmission control function of the current communication protocol, the detection data including communication data sent and received by the target node during the functional detection process; analyzing and processing the detection data to determine a functional detection result, the functional detection result including whether the target node possesses the detected transmission control function during communication; and determining anomaly detection results for the target node and its associated nodes based on the functional detection results, the anomaly detection results including abnormal or normal.
[0005] Secondly, this application provides a detection device, which includes an acquisition module, a detection module, an analysis module, and a determination module. The acquisition module acquires the current communication protocol of a target node, the current communication protocol being determined based on the target node's communication data. The detection module performs functional detection on the target node to obtain detection data, the functional detection being used to detect at least one transmission control function of the current communication protocol, the detection data including communication data sent and received by the target node during the functional detection process. The analysis module analyzes and processes the detection data to determine the functional detection result, the functional detection result including whether the target node possesses the detected transmission control function during communication. The determination module determines the anomaly detection result of the target node and its associated nodes based on the functional detection result, the anomaly detection result including abnormal or normal.
[0006] Thirdly, this application provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the above-mentioned node anomaly detection method.
[0007] Fourthly, this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the above-mentioned node anomaly detection method.
[0008] Fifthly, this application provides a computer program product, including a computer program that, when executed by a processor, implements the above-mentioned node anomaly detection method.
[0009] The node anomaly detection method, detection device, electronic device, computer-readable storage medium, and computer program product provided in this application first determine the communication protocol currently used by the target node through its communication data, then perform functional detection on the target node, and finally analyze the detection data to determine whether the target node possesses the detected transmission control function during communication (i.e., the functional detection result). Compared to simulating message formats, which is less costly, simulating transmission control functions is too costly, and proprietary protocols generally do not have the transmission control functions of public protocols (such as TCP). Therefore, based on the functional detection results obtained after performing functional detection on the target node, it is possible to accurately determine whether the target node is using a proprietary protocol for communication, thereby improving the accuracy of anomaly node detection and preventing anomaly nodes from being used for illegal purposes. This not only prevents the target node from transmitting illegal data that could harm public health and property, but also defends against network attacks based on spoofed traffic, improving the security and reliability of the target node.
[0010] Furthermore, target nodes have associated nodes. When a target node is abnormal, its associated nodes are generally also abnormal. Therefore, the abnormality detection results of the target node and its associated nodes can be determined simultaneously through the functional detection results, thus achieving high detection efficiency for the target node and its associated nodes. Attached Figure Description
[0011] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which:
[0012] Figure 1 It is the protocol format of the TCP header of a TCP message;
[0013] Figure 2 It is the structure of a TCP packet;
[0014] Figure 3 This is a schematic diagram illustrating a scenario where the sending and receiving ends communicate.
[0015] Figure 4 and Figure 5 This is a schematic diagram illustrating the TCP acknowledgment and response function.
[0016] Figure 6 This is a schematic diagram illustrating the data interaction between the sending and receiving ends;
[0017] Figure 7 This is a schematic diagram illustrating the principle of TCP implementing congestion control.
[0018] Figure 8 This is a schematic diagram illustrating the scenario where TCP establishes a connection through a three-way handshake.
[0019] Figure 9 This is a schematic diagram illustrating a scenario where TCP terminates a connection using a four-way handshake.
[0020] Figure 10 This is an application scenario diagram of a node anomaly detection method provided in an embodiment of this application;
[0021] Figure 11 This is a first flowchart illustrating the node anomaly detection method provided in this application embodiment;
[0022] Figure 12 This is a schematic diagram of the second process of the node anomaly detection method provided in the embodiments of this application;
[0023] Figure 13 This is a schematic diagram of a detection scenario for the timeout retransmission function in an embodiment of this application;
[0024] Figure 14 This is a schematic diagram of a detection scenario for the fast retransmission function in an embodiment of this application;
[0025] Figure 15 This is a schematic diagram of a detection scenario for the selective retransmission function in an embodiment of this application;
[0026] Figure 16 This is a schematic diagram of the third process of the node anomaly detection method provided in the embodiments of this application;
[0027] Figure 17 This is a schematic diagram of the overall process of the node anomaly detection method provided in the embodiments of this application;
[0028] Figure 18 This is a schematic diagram of the detection device provided in the embodiments of this application;
[0029] Figure 19 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application; and
[0030] Figure 20 This is a schematic diagram of the hardware structure of the electronic device provided in the embodiments of this application. Detailed Implementation
[0031] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.
[0032] To facilitate understanding of this solution, the relevant technologies involved in this application will be introduced below:
[0033] Network layered architecture is the basic framework for network communication. It divides the functions of network communication into different layers, each with specific functions and responsibilities.
[0034] For example, the OSI model (Open Systems Interconnection Reference Model) divides network communication into seven layers, from highest to lowest: Application Layer, Presentation Layer, Session Layer, Transport Layer, Network Layer, Data Link Layer, and Physical Layer. Each layer has its specific functions and protocols, responsible for completing specific communication tasks and passing data to the next layer.
[0035] The network transport layer (also known as the network transport layer) is the fourth layer in the OSI model, located above the network layer and below the session layer. It is the most crucial layer in the entire protocol hierarchy, primarily responsible for end-to-end communication and resolving communication issues between computer programs.
[0036] Black and gray market activities on the internet involve various obfuscated and encrypted traffic masquerading as public protocols like TCP for data transmission. This masquerading traffic can be used for illicit purposes. For example, using masquerading traffic to transmit illegal data is a criminal act that could endanger public health, property, or other safety concerns. Furthermore, using masquerading traffic for cyberattacks (such as TCP flooding attacks) can lead to excessive resource consumption on servers, even rendering them unusable.
[0037] Therefore, accurate detection of spoofed traffic is a necessary means to ensure network security. To achieve accurate detection of spoofed traffic, a thorough understanding of the various public protocols used for spoofed traffic transmission is required. Since the transport layer is responsible for end-to-end communication, spoofed traffic typically simulates these public protocols for data transmission.
[0038] Transport layer protocols include public protocols such as Transmission Control Protocol (TCP), User Datagram Protocol (UDP), and Stream Control Transmission Protocol (SCTP).
[0039] This application uses the TCP protocol at the transport layer as an example to detail a method for anomaly detection of abnormal nodes transmitting spoofed traffic simulating the TCP protocol. For ease of understanding, the TCP protocol is described below:
[0040] TCP is a transport layer protocol that provides a connection-oriented, reliable byte stream service. In network communication, TCP's role is to divide data into TCP packets and transmit these TCP packets from one node to another over the network. A TCP packet generally includes a TCP segment, and the TCP packet header usually also includes an IP (Internet Protocol) header, which is used to indicate IP-related information.
[0041] I. TCP Protocol Format
[0042] Please see Figure 1 and Figure 2 , Figure 1 It is the protocol format of the TCP header of a TCP message. Figure 2 This describes the structure of a TCP segment. The TCP protocol is embodied in TCP segments, which consist of a TCP header and a TCP data portion. The TCP header includes:
[0043] Source port and destination port: used to identify the applications sending and receiving data;
[0044] Serial number: Used to ensure the orderly transmission of data;
[0045] Confirmation number: Used to confirm the receipt of data;
[0046] Data offset: Used to indicate the starting position of TCP data within a TCP segment;
[0047] Control bits: Used to identify various control information in TCP packets, such as connection requests (e.g., ... Figure 1 The SYN field in the connection confirmation (such as...) Figure 1 (such as the ACK field in the code);
[0048] Window size: Used to implement TCP flow control;
[0049] Checksum: Used to check the integrity of TCP packets;
[0050] Urgent pointer: Used to identify urgent data in a TCP packet;
[0051] Options and padding fields are used to extend the functionality of TCP packets.
[0052] II. TCP Protocol Functions
[0053] Based on the TCP packet protocol format, TCP can implement various transmission control functions. The following is a description of each transmission control function:
[0054] 1. Reliable transmission function:
[0055] (1) Acknowledgment function: When the receiving end receives a TCP packet from the sending end, it will send a TCP acknowledgment packet to the sending end to indicate that the TCP packet was successfully transmitted, thereby ensuring that the data sent by the sending end is reliably received by the receiving end.
[0056] All data transmitted within the lifetime of a TCP connection is treated as a byte stream, and each byte in the stream has a unique number, known as a sequence number. A TCP segment consists of a TCP header and a TCP data portion, which typically contains multiple bytes of data. The TCP header carries a sequence number, which is the number of the first byte in the TCP data portion of that TCP segment.
[0057] Please see Figures 3 to 5 , Figure 3 A schematic diagram illustrating a scenario where the sender and receiver communicate. Figure 4 This is a schematic diagram of the information in TCP packet a. Figure 5 This is a schematic diagram of the information in TCP acknowledgment message b.
[0058] For example, if a TCP segment 'a' sent by the sender to the receiver carries a sequence number of 101 and a data length of 100 bytes, it indicates that the data segment in TCP segment 'a' belongs to bytes 101 to 200 of the byte stream. After TCP segment 'a' arrives at the receiver, the receiver acknowledges the sequence number of the received TCP segment 'a' and returns a TCP acknowledgment segment 'b' to the sender. This TCP acknowledgment segment 'b' carries an acknowledgment number of 201, which is the sequence number expected to be carried in the next TCP segment received by the sender.
[0059] (2) Retransmission function
[0060] Because packet loss can occur during TCP stream transmission in complex networks, TCP currently employs retransmission mechanisms to address this issue. Under the retransmission mechanism, if the sender determines that a TCP segment intended for transmission to the receiver has failed, the sender retransmits the TCP segment to the receiver. TCP's retransmission functions include timeout retransmission, fast retransmission, and selective retransmission.
[0061] Timeout retransmission: When the sending end sends a TCP packet, it starts timing. If the timeout threshold is reached and no acknowledgment is received for the TCP packet, it can be considered that the packet has been lost, and the TCP packet will be sent again to achieve timeout retransmission.
[0062] Fast Retransmission (FIRST) is a data-driven retransmission method, not a time-driven one. FIRST works by retransmitting lost data before the timeout threshold is reached when the sender receives multiple TCP acknowledgment packets carrying the same acknowledgment number. This lost data includes the data indicated by the acknowledgment number carried in the TCP acknowledgment packet. The TCP acknowledgment packet that triggers FIRST is also called a duplicate acknowledgment packet.
[0063] Selective retransmission: The receiving end adds packet loss information to the option field of the TCP header of the TCP acknowledgment message. This packet loss information is used to indicate the data that has been received and the data that has not been received. The sending end only needs to retransmit the data that the receiving end has not received, thus implementing selective retransmission.
[0064] (3) Flow control function
[0065] The sending end cannot send data indefinitely because it needs to consider the size of the receiving end's buffer and its data reading capacity. If the sending speed is too fast and the receiving end cannot receive the data, frequent retransmissions will occur, wasting network resources and compromising transmission reliability. Therefore, the range of data sent by the sending end must take into account the size of the receiving end's buffer.
[0066] TCP has a window field. When establishing a TCP connection, the receiving end declares the remaining buffer size in the window field, which allows the sending end to adjust the window of data that can be sent in its own buffer, thereby achieving flow control.
[0067] For example, see Figure 6 , Figure 6 This is a diagram illustrating data exchange between the sending and receiving ends. The sending end's buffer is 8 bytes, and the receiving end's buffer is 4 bytes. After establishing a TCP connection, the sending window is set to the same length as the receiving end's buffer, which is 4 bytes.
[0068] Among them, bytes 0 and 1 are data that have been sent and received by the receiving end, bytes 2 to 5 are data to be sent in the sending window, and bytes 6 and 7 are data outside the sending window that cannot be sent at the moment.
[0069] 2. Congestion control function:
[0070] Please see Figure 7 , Figure 7 This is a schematic diagram illustrating the principle of TCP's congestion control function.
[0071] The Y-axis represents the sender's window size, and the X-axis represents the transmission round. The round is not a byte number; multiple bytes of data can be sent in one round.
[0072] Slow start: Initially, the sender sets a small sending window value. After each round of sending is completed and an acknowledgment is received from the receiver, the sending window doubles in size, increasing round by round to achieve slow start.
[0073] Congestion avoidance: When the sending window reaches the window threshold (a window limit value set for real-time network conditions, such as...) Figure X In step 16), congestion avoidance begins, increasing the sending window by a fixed value (e.g., 1 byte) each round to gradually test the network's maximum transmission capacity. If, in a certain round (e.g., ...), congestion avoidance is implemented, the sending window is increased by a fixed value (e.g., 1 byte) each round. Figure 7 In step 24), a data timeout occurs (i.e., after the data for this round is sent to the receiver, the receiver reaches the timeout threshold and does not return an acknowledgment reply), indicating that congestion is very likely to occur. At this time, slow start is performed again, and the window threshold is reduced (e.g., reduced to 20). This cycle is repeated to achieve congestion control.
[0074] It is understandable that the sending window size cannot be increased indefinitely; it must be smaller than the remaining buffer size declared by the receiving end in the window field.
[0075] Fast recovery: If multiple (e.g., 3, 4, etc.) identical acknowledgment replies are received (i.e., multiple acknowledgment messages with the same acknowledgment number), such as receiving multiple acknowledgment replies in transmission round 24, it indicates that the network situation is not good. Slow start can be restarted and the window threshold can be reduced, such as setting the window threshold to half of the original (e.g., reducing it to 10), to continue congestion avoidance and achieve fast recovery.
[0076] Quick retransmission: If you receive a packet loss message, you should retransmit the lost packet as soon as possible.
[0077] 3. Reliable connection function: TCP establishes a connection through a three-way handshake and closes the connection through a four-way handshake.
[0078] (1) Establish connection via three-way handshake
[0079] Please see Figure 8 , Figure 8 This is a schematic diagram illustrating a TCP connection establishment process using a three-way handshake. Device A sends a SYN packet S1 (label) (i.e., the SYN field in the TCP segment is set to 1) to Device B to request the establishment of a TCP connection, along with its own receive buffer information, indicating that the request has been sent and a reply is being awaited.
[0080] After receiving the request, device B records the information of device A, creates its own receive buffer, and sends a SYN+ACK composite packet S2 to device A (that is, the SYN and ACK fields in the TCP packet are both 1), indicating that it is ready and waiting for device A's reply to send data.
[0081] After receiving the composite packet, device A records the information of device B and sends an ACK packet S3 (i.e., the ACK field in the TCP packet is set to 1) to device B, indicating that it is fully ready to send and receive.
[0082] Once device B receives the ACK packet, the TCP connection is established, and data transmission can begin between device A and device B.
[0083] (2) Disconnection via 4-wave gesture
[0084] Please see Figure 9 , Figure 9This is a schematic diagram illustrating a TCP connection termination scenario using a four-way handshake. After device A finishes sending data, it requests to close the connection from device B, indicating that data transmission is complete and a FIN packet S4 (FIN field value is 1) has been sent. After receiving the FIN packet S4, device B replies with an ACK packet S5 (ACK field value is 1) to indicate receipt. However, device B may still have data to send, indicating that the other party has finished sending and requests to close the connection, and that it can close the connection after completing its own transmission. After device B finishes sending its data, it sends a FIN packet S6 (FIN field value is 1) to device B, indicating that it will wait for an ACK packet S7 to close the connection. After receiving the FIN packet S6, device A knows that device B has also finished sending and replies with an ACK packet S7, thus achieving the connection termination between the two devices.
[0085] After introducing the technical concepts related to the TCP protocol in this application, the application scenarios of this application are described below:
[0086] Please see Figure 10 , Figure 10 This is an application scenario diagram of a node anomaly detection method provided in an embodiment of this application. The application scenario provided in this application includes a terminal device 101 and a server 102, and the node anomaly detection method provided in this application can be executed by at least one of the terminal device 101 and the server 102.
[0087] The terminal devices may include, but are not limited to: smartphones (such as Android phones, iOS phones, etc.), tablets, laptops, desktop computers, smart speakers, smartwatches, portable personal computers, mobile internet devices (MIDs), smart voice interaction devices, smart home appliances, vehicle terminals, aircraft, wearable devices, etc., but this application does not limit them.
[0088] The terminal device may integrate a client, which can be a client capable of displaying data information such as text, images, audio, and video, including but not limited to browser clients, cloud service control clients, entertainment clients (e.g., game clients), multimedia clients (e.g., video clients), social clients (e.g., instant messaging clients), information clients (e.g., news clients), shopping clients, and in-vehicle clients. This client can be a standalone client or an embedded sub-client integrated into another client (e.g., a social client); there is no limitation on this.
[0089] The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. This application does not limit this.
[0090] It should be noted that Figure 10 The number of terminal devices and servers is for illustrative purposes only; the number of terminal devices and servers can be more or less, and there is no limitation herein. Terminal devices and servers can be connected directly or indirectly via wired or wireless communication, and this application does not impose any limitations on this.
[0091] It is understandable that after renting a server, unscrupulous tenants will use private protocols that emulate compliant public protocols to achieve data transmission between terminal devices and servers, thereby enabling the transmission of disguised traffic.
[0092] Among them, spoofed traffic refers to traffic that simulates a public protocol but actually uses a private protocol for data transmission.
[0093] Therefore, the node anomaly detection method of this application detects whether the target node has compliant public protocol transmission control functions by performing functional detection on the target node, thereby determining whether the target node is using private protocols to masquerade traffic transmission, and thus determining whether the target node and its associated nodes are abnormal, thereby realizing the anomaly detection of the target node and its associated nodes.
[0094] For example, if the target node does not have the transmission control function of a compliant public protocol, it is assumed that the target node is not using a compliant public protocol for communication, thus determining that the target node is using a private protocol for communication.
[0095] Optionally, a node can be a hardware facility such as a server or computer existing on a computer network, such as a server or terminal device in an application scenario. The target node is the node that needs to be detected for anomalies.
[0096] Optionally, whether the target node is abnormal can be determined by whether the target node uses a private protocol for communication. If the target node uses a private protocol for communication, the target node is abnormal. If the target node does not use a private protocol but uses a compliant public protocol for communication, the target node is normal, thereby realizing the detection of target node abnormalities.
[0097] Alternatively, a compliant public protocol refers to the public protocol used by normal nodes when communicating.
[0098] The node anomaly detection method involved in this application can be implemented using cloud technology.
[0099] Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to achieve data computing, storage, processing, and sharing.
[0100] Cloud technology is a collective term for network technologies, information technologies, integration technologies, management platform technologies, and application technologies applied to the cloud computing business model. It can form resource pools, providing flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services of technical network systems require substantial computing and storage resources, such as video websites, image websites, and many portal websites. With the rapid development and application of the internet industry, every item may have its own identification mark in the future, requiring transmission to backend systems for logical processing. Data at different levels will be processed separately, and various industry data will all require robust system support, which can only be achieved through cloud computing.
[0101] The node anomaly detection method in this application can be implemented based on cloud computing. Cloud computing is a computing model that distributes computing tasks across a resource pool composed of a large number of computers, enabling various application systems to obtain computing power, storage space, and information services as needed. The network providing these resources is called the "cloud." From the user's perspective, the resources in the "cloud" are infinitely scalable, readily available, on-demand, expandable, and pay-as-you-go.
[0102] As a provider of fundamental cloud computing capabilities, a cloud resource pool (referred to as a cloud platform, generally called an IaaS (Infrastructure as a Service) platform) is established. Various types of virtual resources are deployed in the resource pool for external customers to choose from. The cloud resource pool mainly includes: computing devices (virtualized machines containing operating systems), storage devices, and network devices.
[0103] Optionally, the target node can also be a cloud node (such as a cloud server) that the cloud platform leases to tenants.
[0104] A cloud node is a basic computing unit in cloud computing, similar to a server. A cloud node is a virtual entity created on a cloud platform using virtualization technology, and its computing power, storage, and network resources can be dynamically configured. They can be allocated and released on demand and automatically adjust to changes in computing load.
[0105] Optionally, the cloud platform (such as other cloud servers in the cloud platform) can perform functional testing on the target node, such as controlling the return packets of the target node and analyzing the communication data of the target node to achieve functional testing of the target node.
[0106] The node anomaly detection method described in this application can be applied to cloud security. Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as anomaly traffic detection (e.g., spoofed traffic, TCP flooding attack traffic), parallel processing, grid computing, and unknown virus behavior judgment. By monitoring anomalies in network communication data and software behavior, it obtains the latest information on illegal traffic, Trojans, and malicious programs on the Internet and sends it to the server for automatic analysis and processing, thereby handling illegal traffic or distributing virus and Trojan solutions to each client.
[0107] The main research directions of cloud security include: (1) Cloud computing security, which mainly studies how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection (such as protection against disguised protocol traffic), compliance auditing, etc.; (2) Cloudification of security infrastructure, which mainly studies how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security event, information collection and processing platform through cloud computing technology to realize the collection and correlation analysis of massive information and improve the ability to control network security events and risk control capabilities; (3) Cloud security services, which mainly studies various security services provided to users based on cloud computing platforms, such as anti-virus services.
[0108] Taking the target node as a server (such as a physical server or a cloud server) as an example, the cloud platform can perform functional tests on the target node to determine whether the target node has compliant public protocol transmission control functions. By using the functional test results, it can determine whether the target node and its associated nodes are abnormal. Based on the abnormality detection results, it can determine whether to demote or block the target node and its associated nodes, thereby achieving cloud security.
[0109] It is understandable that when the target node is a terminal device, the principle of anomaly detection is basically the same, and will not be elaborated here.
[0110] The node anomaly detection method of this application can also be applied to high-traffic scenarios, such as anomaly detection of nodes in a backbone network. The backbone network is a high-speed network used to connect multiple regions or areas.
[0111] The node anomaly detection method in this embodiment can be executed by an electronic device, which can be at least one of a server and a terminal device. That is, the method can be executed by the server or the terminal device alone, or by both the server and the terminal device. Therefore, the executing entity of each step will not be described again below.
[0112] It should be noted that the examples of node anomaly detection methods in the following text are based on an anomaly detection scenario where the target node is a server. Those skilled in the art can apply the node anomaly detection methods provided in the embodiments of this application to other types of scenarios (such as anomaly detection scenarios where the target node is a terminal device) based on their understanding of the following text.
[0113] Based on the above introduction of basic concepts and related scenarios, this application provides a node anomaly detection method, which will be described in detail below:
[0114] Please see Figure 1 and 11 , Figure 11 This is a first flowchart illustrating the node anomaly detection method provided in this application embodiment. The node anomaly detection method provided in this application embodiment is implemented by steps 011 to 014, which are described in detail below.
[0115] Step 011: Obtain the current communication protocol of the target node. The current communication protocol is determined based on the communication data of the target node.
[0116] Specifically, to perform functional testing on the target node, it is necessary to first obtain the communication protocol used by the target node. However, the communication protocol used by the target node may differ at different times. Therefore, during anomaly detection, it is necessary to obtain the current communication protocol of the target node. Since communication data is transmitted based on a communication protocol, the current communication protocol can be accurately determined through the target node's communication data.
[0117] Optionally, the current communication protocol is a compliant public protocol currently used by the target node.
[0118] Optionally, it can be understood that different protocols have different protocol formats, and the current communication protocol can be determined according to the protocol format of the communication data of the target node.
[0119] For example, the format of the packet header in the communication data can be matched with the header formats of various compliant public protocols to determine the corresponding public protocol. For instance, if the packet header format of the communication data is the same as the TCP header format, then it can be determined that the communication data is transmitted via TCP.
[0120] It is understandable that even if the target node's communication data is disguised traffic using a private protocol, the protocol format of the disguised traffic still simulates the corresponding public protocol. Therefore, the target node's current communication protocol can be accurately determined through its protocol format.
[0121] Step 012: Perform functional testing on the target node to obtain test data. The functional testing is used to test at least one transmission control function of the current communication protocol. The test data includes the communication data sent and received by the target node during the functional testing process.
[0122] Optionally, the communication data of the target node includes the communication data sent and received by the target node.
[0123] Optionally, for the TCP protocol, since TCP is a connection-oriented protocol, the communication data may include signaling packets transmitted between the target node and the client when establishing a connection, as well as data packets transmitted after the connection is established.
[0124] Signaling packets refer to TCP messages related to establishing or closing connections, while data packets are TCP messages used for data transmission.
[0125] For example, for TCP packets, when establishing a connection, at least one of the SYN and ACK fields in the signaling packet is 1; while when closing a connection, at least one of the FIN and SYN fields in the signaling packet is 1.
[0126] Optionally, the transmission control function can be a preset function for transmission control when communicating based on the current communication protocol.
[0127] For the TCP protocol, transmission control functions can include acknowledgment, retransmission, flow control, slow start, congestion avoidance, and reliable connection functions (such as three-way handshake for connection establishment).
[0128] Specifically, when performing functional testing on a target node, the function being tested can be one or more of the preset transmission control functions. Functional testing can be performed on each transmission control function to obtain the test data of each transmission control function, that is, the communication data sent and received by the target node during the functional testing process.
[0129] Functional testing can be designed based on the actual transmission control functions to be tested, ensuring that the functional testing can detect whether the target node has the tested function.
[0130] Step 013: Analyze and process the detection data to determine the functional detection results. The functional detection results include whether the target node has the detected transmission control function during communication.
[0131] Specifically, during the functional testing process, the communication data sent and received by the target node can be acquired as testing data. The testing data obtained when the target node possesses the tested function differs from the testing data obtained when it does not possess the tested function.
[0132] Therefore, by analyzing and processing the detection data, the functional detection result can be determined, that is, whether the target node has the detected transmission control function during communication.
[0133] Compared to simulating message formats, which is less expensive, simulating transmission control functions is prohibitively costly, and proprietary protocols generally lack the transmission control functions of public protocols. Therefore, using function detection results based on target node functional testing for anomaly detection can accurately determine whether a target node is using a proprietary protocol for communication, improving the accuracy of anomaly detection and preventing anomaly nodes from being used for illegal purposes. This not only prevents target nodes from transmitting illegal data that could harm public health and property, but also defends against network attacks based on spoofed traffic, improving the security and reliability of target nodes.
[0134] The following explanation uses TCP as the current communication protocol and focuses on testing some of its transmission control functions. The principles for testing other transmission control functions of TCP, or for testing transmission control functions (such as acknowledgment, retransmission, and heartbeat) of other public protocols such as SCTP, are basically similar and will not be elaborated here.
[0135] In some embodiments, please combine Figure 12 , Figure 12 This is a second flowchart of the node anomaly detection method provided in this application embodiment. Step 012, "perform functional detection on the target node to obtain detection data", can be implemented through step 0121, which will be explained in detail below.
[0136] Step 0121: Control the return packet data of the target node to obtain detection data.
[0137] Specifically, for reliable connection protocols (such as TCP), a retransmission function is typically designed to ensure reliability. Whether the sender retransmits depends on the receiver's response packet. Therefore, controlling the response packet data of the target node can detect the retransmission function and obtain the detection data during the retransmission detection process.
[0138] Optionally, the retransmission function includes timeout retransmission and packet loss retransmission.
[0139] Optionally, for the functional detection of the timeout retransmission function, step 0121 "controlling the return packet data of the target node to obtain detection data" can be implemented through step 01211, as explained in detail below.
[0140] Step 01211: Control the target node to stop sending back packets of the received target communication data in order to obtain the detection data.
[0141] Optionally, the target communication data can be at least one of multiple communication data received by the target node. For example, if the target node receives multiple TCP packets, the target communication data is one or more of those TCP packets.
[0142] Specifically, when the target node transmits data using the TCP protocol, it returns a TCP acknowledgment message when it receives communication data (such as TCP packets) sent by the client. At this time, by controlling the return packet data, the target node stops sending return packets for the target communication data in the received communication data (i.e., TCP packets), so that the client does not receive the TCP acknowledgment message corresponding to the target communication data. This is to detect the timeout retransmission function and the detection data during the timeout retransmission detection process.
[0143] Optionally, the detection data during the timeout retransmission detection process includes the communication data sent and received by the target node within a preset time period after the return packet is stopped.
[0144] Step 013, "Analyze and process the test data to determine the functional test results," can be achieved through step 0131, as explained below.
[0145] Step 0131: If the target communication data is still not retransmitted in the detection data after the preset time, it is determined that the target node does not have the timeout retransmission function during communication, and the preset time is longer than the retransmission time threshold of the timeout retransmission function.
[0146] Specifically, if the client and target node communicate via the TCP protocol, the client will time the transmission after sending a TCP packet. If no TCP acknowledgment packet is received after the timeout threshold of the retransmission function is reached, the client will assume that the target node has not received the TCP packet and will retransmit the TCP packet to the target node. Conversely, if the client and target node do not communicate via the TCP protocol, the client will not retransmit the TCP packet to the target node.
[0147] Therefore, if, after the preset timeout period for receiving packets, the detected data still does not contain retransmitted target communication data (i.e., retransmitted TCP packets), it is determined that the target node does not have the timeout retransmission function during communication. Conversely, if, after the preset timeout period for receiving packets, the detected data contains retransmitted target communication data (i.e., retransmitted TCP packets), it is determined that the target node has the timeout retransmission function during communication.
[0148] Optionally, the preset duration is longer than the retransmission time threshold of the timeout retransmission function. The start time of the preset duration can be the time when the return packet stops (at which point the target node has received the target communication data), to ensure that after the preset duration, the client's timer has exceeded the retransmission time threshold.
[0149] It is understandable that from the time the client retransmits the TCP packet when the retransmission time threshold is reached, to the time the target node receives the retransmitted TCP packet, there is also a transmission time required. Therefore, the preset duration can be greater than the retransmission time threshold, and the difference between the two is an empirical value that can be determined based on the network transmission speed, thereby avoiding misjudgment.
[0150] In one example, please combine Figure 13 , Figure 13 This is a schematic diagram illustrating a detection scenario for the timeout retransmission function in this application embodiment. The client sends TCP packet c to the target node and starts timing. The target node stops sending packets back. If the client's timing reaches the retransmission time threshold without receiving a packet back, the client considers TCP packet c to have timed out and been lost. If the client and the target node communicate via the TCP protocol, the client will retransmit TCP packet c. Figure 13 As shown, if the client retransmits TCP packet c within the preset time limit, it can be determined that the client has a timeout retransmission function. Similarly, it can be inferred that the target node also has a timeout retransmission function during communication. If the client and the target node do not communicate via TCP but via a proprietary protocol, the client will not retransmit TCP packet c, thus determining that the client does not have a timeout retransmission function. Similarly, it can be inferred that the target node also does not have a timeout retransmission function during communication.
[0151] Optionally, for the functional detection of the packet loss retransmission function, step 0121 "controlling the return packet data of the target node to obtain detection data" can be implemented through step 01212, as explained in detail below.
[0152] Step 01212: When the target node receives the target communication data, generate return packet data representing that the target communication data has not been received and control the target node to send a return packet based on the return packet data to obtain the detection data;
[0153] Optionally, the packet loss retransmission function may include the fast retransmission function and the selective retransmission function in TCP's retransmission function.
[0154] Specifically, for both the fast retransmission and selective retransmission functions, if packet loss occurs when the target node receives communication data, it needs to report the packet loss information to the client.
[0155] In order to perform functional testing, packet loss information can be simulated to generate return packet data that indicates that the target communication data has not been received. The target node is then controlled to send a return packet based on the return packet data, thereby obtaining the detection data in the packet loss retransmission function testing process.
[0156] Optionally, the detection data in the packet loss retransmission function detection process includes the communication data sent and received by the target node during the process of multiple return packets based on the return packet data.
[0157] Please see Figure 14 , Figure 14 This is a schematic diagram illustrating a detection scenario for the fast retransmission function in an embodiment of this application. For example, a client sends a TCP packet d (i.e., communication data, sequence number 301) to the target node. For fast retransmission, the target node can generate a TCP acknowledgment packet e (i.e., return packet data, acknowledgment number 301) with an acknowledgment number equal to the sequence number of the TCP packet d, and send the TCP acknowledgment packet e to the client to realize the return packet, thereby informing the client that the target node has not yet received the TCP packet d and expects to receive a TCP packet d with a sequence number equal to the acknowledgment number.
[0158] Please see Figure 15 , Figure 15 This is a schematic diagram illustrating a detection scenario for the selective retransmission function in an embodiment of this application. For example, when a client sends a TCP packet d (i.e., communication data) to a target node, for selective retransmission, the target node can declare packet loss information (i.e., TCP packets received and those not received by the target node) in the options field of the return packet data, and then send this return packet data to the client to achieve the return packet.
[0159] Step 013, "Analyze and process the test data to determine the functional test results," can be achieved through step 0132, as explained below.
[0160] Step 0132: If the target communication data is still not retransmitted in the detection data after multiple return packets, it is determined that the target node does not have the function of retransmitting lost packets during communication.
[0161] Specifically, if the client and the target node communicate via the TCP protocol, the client will retransmit the lost TCP packets after receiving the return data.
[0162] For fast retransmission, the lost TCP packet is typically retransmitted after receiving three TCP acknowledgment packets with the same acknowledgment number. Therefore, if, after multiple return packets (e.g., three or more), the retransmitted target communication data is still not present in the detection data, meaning the target node has not received the retransmitted target communication data from the client, it is determined that the client does not have packet loss retransmission functionality during communication. This leads to the inference that the target node also lacks packet loss retransmission functionality (specifically, it lacks fast retransmission functionality). Figure 14 As shown, if the target node receives the retransmitted target communication data (i.e., TCP packet d), it is determined that the client has the packet loss retransmission function during communication, and thus it is inferred that the target node has the packet loss retransmission function (specifically, it has the fast retransmission function).
[0163] Optionally, during fast retransmission, since the target node sends multiple TCP acknowledgment packets with the same acknowledgment number to the client, the fast recovery function can also be triggered. In this case, the fast recovery function can be detected by comparing the change in the amount of detection data received by the target node before and after the multiple retransmissions. If the amount of data decreases, and the decrease is less than a preset proportion (such as 1 / 3, 1 / 2, etc.) of the amount of data before the multiple retransmissions, it is determined that the target node does not have the fast recovery function.
[0164] With the retransmission option selected, the lost TCP packets will be retransmitted upon receiving the return packet. Therefore, in the case of multiple return packets (e.g., two or more), such as... Figure 15 As shown, if the target node still does not receive the retransmitted target communication data (i.e., TCP packet d), it can be determined that the client does not have the packet loss retransmission function, thus inferring that the target node does not have the packet loss retransmission function during communication (specifically, it does not have the selective retransmission function); if the target node receives the retransmitted target communication data, it can be determined that the client has the packet loss retransmission function, thus inferring that the target node has the packet loss retransmission function during communication (specifically, it has the selective retransmission function).
[0165] Optionally, the transmission control function may also include a congestion avoidance function.
[0166] The sending end typically performs flow control based on the receiving end's data reception capability. After packet loss occurs, it dynamically adjusts the sending window. Therefore, by controlling the corresponding return packets based on the communication data received by the target node, it is possible to simulate changes in the receiving end's data reception capability (such as increasing or decreasing the response time of the return packets), thereby causing the sending end to adjust the sending window. After adjusting the sending window, the amount of data received by the receiving end will change accordingly, thus realizing the detection of congestion avoidance function.
[0167] Optionally, for the functional detection of the congestion avoidance function, step 0121 "controlling the return packet data of the target node to obtain detection data" can be implemented through step 01213, as explained in detail below.
[0168] Step 01213: Reduce the weight of the return packets from the target node to obtain detection data. The response time of the target node to the received communication data increases after the weight reduction process.
[0169] Optionally, de-weighting can involve reducing the data processing performance or priority of a node.
[0170] For cloud servers, demotion can involve reducing the bandwidth, memory, and computing resources allocated to them, thereby reducing data processing performance and increasing the response time of demotion nodes during communication. Alternatively, lowering the priority of a cloud server can also reduce its data processing performance, as cloud platform resources are allocated according to priority. This also increases the response time of demotion nodes during communication.
[0171] For physical servers, demotion can involve limiting the server's processor frequency, bandwidth, memory, etc., thereby reducing data processing performance and increasing the response time of demotion nodes when communicating.
[0172] Specifically, by downweighting the response packets from the target node, the response time of the target node to received communication data can be increased. This increases the delay in receiving the corresponding response packets (i.e., TCP acknowledgments) after the client sends communication data (such as TCP packets), potentially exceeding the retransmission time threshold. By downweighting the target node as the receiving end, the congestion avoidance function of the sending end can be triggered, enabling the detection of the congestion avoidance function and obtaining the detection data during the congestion avoidance detection process.
[0173] Optionally, the detection data during the congestion avoidance detection process includes communication data sent and received by the target node before and after the weighting process.
[0174] Step 013, "Analyze and process the test data to determine the functional test results," can be achieved through step 0133, as explained below.
[0175] Step 0133: If, after the weight reduction process, the amount of data change in the communication data sent and received by the target node is less than the preset threshold, then it is determined that the target node does not have the congestion avoidance function during communication.
[0176] Specifically, please combine Figure 7In the TCP protocol, when a client (as the sender) experiences timeout and packet loss, the congestion avoidance mechanism reduces the sending window. This means the amount of data the client sends to the target node decreases; after weighting, the target node receives less data. Therefore, after weighting the target node's response packets, if the change in the amount of communication data received by the target node is less than a preset threshold, it is determined that the client lacks congestion avoidance functionality, and consequently, the target node also lacks congestion avoidance functionality.
[0177] It's understandable that the interaction between the client and the target node is reciprocal. Downweighting the target node's response packets will also affect the amount of data sent by the target node, thus reducing the amount of data sent. Therefore, if the changes in both the received and sent communication data at the target node are less than a preset threshold, it can be determined that the target node lacks congestion avoidance functionality during communication.
[0178] Conversely, if the amount of data change in the communication data sent and received by the target node is greater than or equal to a preset threshold, it is determined that the client has congestion avoidance function during communication, thereby inferring that the target node has congestion avoidance function during communication.
[0179] Optionally, the first data volume of communication data sent and received by the target node before the weight reduction process and the second data volume of communication data sent and received after the weight reduction process can be obtained. Then, based on whether the difference between the first data volume and the second data volume is less than a preset threshold, it can be determined whether the target node has congestion avoidance function during communication.
[0180] If the difference between the first data volume and the second data volume is less than a preset threshold, it is determined that the target node does not have congestion avoidance functionality during communication. If the difference between the first data volume and the second data volume is greater than or equal to the preset threshold, it is determined that the target node has congestion avoidance functionality during communication.
[0181] In some embodiments, see Figure 16 , Figure 16 This is a schematic diagram of the third process of the node anomaly detection method provided in the embodiments of this application. Step 012, "perform functional detection on the target node to obtain detection data", can be implemented through step 0122, which will be explained in detail below.
[0182] Step 01221: Obtain the communication data sent and received by the target node as detection data.
[0183] Specifically, for the TCP protocol, the target node establishes and terminates connections using a three-way handshake and a four-way handshake, respectively. Therefore, by analyzing the signaling packets sent and received when the target node establishes a connection, we can determine whether a three-way handshake was used; and by analyzing the signaling packets sent and received when the target node terminates a connection, we can determine whether a four-way handshake was used. This allows us to detect reliable connection functionality.
[0184] The TCP protocol has congestion control capabilities. After a connection is established, it implements a slow start function. The slow start function can be detected by analyzing the changes in the amount of data sent and received by the target node after the connection is established.
[0185] In this way, there is no need to control the return packet data of the target node. The corresponding function detection can be achieved by analyzing the historical send and receive data of the target node, which is highly efficient.
[0186] Optionally, for the functional testing of reliable connection function, step 0122 "acquire the communication data sent and received by the target node as test data" can be implemented through step 01221, and step 013 "analyze and process the test data to determine the functional test result" can be implemented through step 0134, as explained in detail below.
[0187] Step 01221: Obtain the signaling packets of the target node as detection data. The signaling packets are used to establish or terminate a connection.
[0188] Step 0134: If the signaling packet does not meet the signaling packet requirements for reliable connection function, determine that the target node does not have reliable connection function during communication. The signaling packet requirements include at least one of the following: the number of signaling packets is a preset number and the value of the field used for connection in the signaling packet is a preset value.
[0189] Specifically, the target node needs to perform a three-way handshake when establishing a connection. The process of the three-way handshake has been described in detail above and will not be repeated here. By obtaining the signaling packets of the target node, the signaling packet of the target node during connection establishment (hereinafter referred to as the first signaling packet) can be determined, and the detection data in the reliable connection function detection process can be obtained. Then, it is determined whether the first signaling packet meets the requirements for establishing a connection. If the first signaling packet meets the requirements, it is determined that the target node has the function of establishing a connection through a three-way handshake.
[0190] Optionally, the first signaling packet is required to include a preset number of first signaling packets (e.g., 3 packets) and the field used for connection in the first signaling packet is at least one of preset values.
[0191] For example, if in the three first signaling packets in the detection data, the SYN field of the first signaling packet is 1, the SYN and ACK fields of the second signaling packet are both 1, and the ACK field of the third signaling packet is 1, then it is determined that the first signaling packet in the detection data meets the requirements of the first signaling packet.
[0192] When the target node disconnects, it needs to perform a four-way handshake. The process of the four-way handshake has been described in detail above and will not be repeated here. By obtaining the signaling packets of the target node, the signaling packet of the target node at the time of disconnection (hereinafter referred to as the second signaling packet) is determined, and it is judged whether the second signaling packet meets the requirements of the second signaling packet for disconnection. Therefore, if the second signaling packet meets the requirements of the second signaling packet, it is determined that the target node has the function of disconnecting the connection through a four-way handshake.
[0193] Optionally, the second signaling packet requires that the number of second signaling packets be a preset number (e.g., 4) and that the fields used for connection in the second signaling packet be at least one of preset values.
[0194] For example, if in the four second signaling packets in the detection data, the FIN field of the first signaling packet is 1, the ACK field of the second signaling packet is 1, the FIN field of the third signaling packet is 1, and the ACK field of the fourth signaling packet is 1, then it is determined that the second signaling packets in the detection data meet the requirements for second signaling packets.
[0195] Optionally, a signaling packet that does not meet the signaling packet requirements for reliable connection functionality may include a first signaling packet not meeting the first signaling packet requirement or a second signaling packet not meeting the second signaling packet requirement.
[0196] In other words, if the target node does not have the capability to establish a connection using a three-way handshake or to terminate a connection using a four-way handshake, it is determined that the target node does not have a reliable connection capability during communication.
[0197] Optionally, for the function detection of the slow start function, step 0122 "acquire the communication data sent and received by the target node as detection data" can be implemented through step 01222, and step 013 "analyze and process the detection data to determine the function detection result" can be implemented through step 0135, as explained in detail below.
[0198] Step 0122: After establishing a connection with the target node, obtain the data packets sent and received by the target node in multiple consecutive rounds as detection data;
[0199] Step 0135: If the trend of the number of data packets sent and received by the target node in multiple consecutive rounds does not conform to the preset trend, it is determined that the target node does not have the slow start function during communication.
[0200] Specifically, when the target node communicates using the TCP protocol, it has congestion control functionality. After establishing a connection, it will perform slow start, which has been described above and will not be repeated here.
[0201] Please combine Figure 7 During slow start, because the sending window increases round by round, the amount of data received by the target node from the client (i.e., the number of data packets) or the amount of data sent to the client will also show a gradual increasing trend. Based on this characteristic, the data packets of the first few consecutive rounds after the target node establishes a connection can be obtained as detection data. Then, by analyzing the trend of the number of data packets in several consecutive rounds in the detection data, if the data volume increases round by round or shows an overall increasing trend (e.g., the data volume may decline in some rounds due to unexpected factors such as network fluctuations, but the data volume in most rounds increases round by round), it indicates that the target node is using the slow start function when sending and receiving data.
[0202] Step 014: Based on the functional test results, determine the anomaly detection results of the target node and its associated nodes. The anomaly detection results include abnormal or normal.
[0203] Optionally, the associated nodes of the target node include at least one of the following: nodes that communicate with the target node, nodes located in the same area as the target node, and nodes belonging to the same tenant as the target node.
[0204] It's understandable that if the target node is abnormal, its associated nodes are generally also abnormal. For example, if a node communicating with the target node also uses a private protocol, then that node is likely abnormal. Similarly, nodes located in the same region as the target node (e.g., the same area or data center) are likely running similar services; therefore, if the target node is abnormal, nodes in the same region are also likely abnormal. Furthermore, nodes belonging to the same tenant as the target node (i.e., nodes rented by the same tenant) are also likely abnormal, as the target node's tenant is likely an illegal tenant.
[0205] Specifically, after performing functional tests on each transmission control function, the functional test results of each transmission control function can be obtained. Based on the functional test results, the transmission control functions that the target node has and the transmission control functions that the target node does not have can be determined. Therefore, based on the transmission control functions that the target node has and the transmission control functions that the target node does not have, it can be determined whether the target node uses a compliant public protocol for communication.
[0206] For example, if the target node has all the detected transmission control functions, it is determined that the target node is using the current communication protocol (i.e., a compliant public protocol) for communication; while if the target node does not have any of the detected transmission control functions, it is determined that the target node is not using a compliant public protocol for communication.
[0207] Then, the anomaly detection results of the target node can be determined based on whether the target node uses a compliant public protocol for communication.
[0208] For example, when the target node does not use a compliant public protocol for communication, the anomaly detection result is "abnormal," while when the target node uses a compliant public protocol for communication, the anomaly detection result is "normal."
[0209] In addition, the anomaly detection results of the target node and its associated nodes can be determined simultaneously through the functional detection results, realizing the anomaly detection of the target node and its associated nodes, and the detection efficiency is also high.
[0210] In some embodiments, step 014, "determining the anomaly detection results of the target node and its associated nodes based on the functional detection results," can be implemented through steps 0141 and 0142, as detailed below.
[0211] Step 0141: If the function detection results indicate that the number of transmission control functions that the target node has during communication is less than or equal to a preset number, the abnormal detection results of the target node and its associated nodes are determined to be abnormal, and the preset number is greater than or equal to 1.
[0212] If the number of transmission control functions that the target node possesses during communication is greater than the preset number, based on the functional detection results, the abnormal detection results of the target node and its associated nodes are determined to be normal.
[0213] Specifically, by statistically analyzing the functional detection results of each detected transmission control function, the number of transmission control functions possessed by the target node can be obtained. If the number of transmission control functions possessed by the target node is less than or equal to a preset number, it indicates that the target node does not possess most of the functions of the current communication protocol and is likely not using the current communication protocol for transmission. Therefore, the anomaly detection results of the target node and its associated nodes can be determined as abnormal. If the number of transmission control functions possessed by the target node is greater than the preset number, it indicates that the target node possesses most of the functions of the current communication protocol and is likely using the current communication protocol for transmission. Therefore, the anomaly detection results of the target node and its associated nodes can be determined as normal.
[0214] It's understandable that the preset quantity is an empirical value that can be determined based on actual needs; a larger preset quantity generally leads to higher detection accuracy. However, considering that functional testing may be affected by factors such as network fluctuations, target node failures, and client-side malfunctions, the results of some functional tests may not be accurate. Setting the preset quantity to the maximum value (i.e., the total number of transmission control functions being tested) could increase the probability of false positives. Therefore, the preset quantity can be smaller than but close to the total number of transmission control functions being tested, such as being determined based on 1 / 2, 2 / 3, or 3 / 4 of the total number, thereby minimizing false positives while ensuring the accuracy of abnormal node detection.
[0215] In some embodiments, the node anomaly detection method further includes:
[0216] Step 015: Perform consistency matching on the data formats of signaling packets and data packets to obtain a first matching result, which may include consistency or inconsistency.
[0217] Optionally, the target node's communication data includes signaling packets and data packets. When communicating with the client, the target node can establish a connection through signaling packets and then receive data packets sent by the client.
[0218] Optionally, the data format refers to the format of the TCP header (i.e., the packet header) and the TCP data portion (i.e., the packet body) of the TCP packet.
[0219] Since both TCP signaling packets and data packets use the TCP protocol format, their header and body data formats are consistent. That is, the fields contained in the header and body, as well as the number of bytes occupied by each field, are the same (except for the option field). The only difference between signaling packets and data packets is that the values of their fields may differ. For example, the values of fields related to establishing and closing connections (such as SYN, ACK, and FIN fields) may differ between signaling packets and data packets.
[0220] Optionally, if the data formats of the signaling packet and the data packet are the same (e.g., the data formats of the header of the signaling packet and the header of the data packet are the same, and the data formats of the body of the signaling packet and the body of the data packet are the same), the first matching result is consistent; if the data formats of the signaling packet and the data packet are different (e.g., the data formats of the header of the signaling packet and the header of the data packet are different, or the data formats of the body of the signaling packet and the body of the data packet are different), the first matching result is inconsistent.
[0221] Optionally, step 012, "perform functional detection on the target node to obtain detection data", can be implemented by step 0123, as explained below.
[0222] Step 0123: If the first matching result is consistent, perform functional testing on the target node to obtain detection data.
[0223] Specifically, if it is determined that the data formats of the signaling packets and data packets received by the target node are consistent, it indicates that the target node may be using a compliant public protocol. However, since private protocols can also disguise the data format to make the data formats of the signaling packets and data packets consistent, further judgment is required. At this time, functional testing can be performed on the target node to obtain test data, and then the test data can be analyzed to determine the functional test results, thereby conducting subsequent anomaly detection.
[0224] In some embodiments, the node anomaly detection method further includes:
[0225] Step 016: If the first matching result is inconsistent, perform byte order matching on the communication data received by the target node and the corresponding return packet data to obtain a second matching result, which may be the same or different.
[0226] Specifically, if the communication data and the corresponding return data have the same byte order range, the second matching result is "the same". If the communication data and the corresponding return data do not have the same byte order range, the second matching result is "different".
[0227] Specifically, if the data formats of the signaling packets and data packets received by the target node are inconsistent, it indicates that the target node is likely using a private protocol. However, to ensure detection accuracy, the design of the private protocol is relatively simple, and most fields (such as the fields in the packet header used to disguise the protocol format) have no actual function, so their values will not change. This will result in the data in the target node's received communication data and the corresponding return data having basically the same data within a certain byte order (i.e., byte sequence number) range (such as the packet header and part of the packet body).
[0228] Here, byte order can refer to the sorting of signaling packets and data packets in the byte stream of a TCP connection.
[0229] Therefore, byte order matching can be performed on the communication data received by the target node and the corresponding return packet data to obtain a second matching result. The matching process is as follows:
[0230] First, obtain the data within the first byte order range of the signaling packet and the data within the second byte order range of the data packet. The number of bytes in the first byte order range and the number of bytes in the second byte order range are the same to avoid similarity differences caused by different byte counts.
[0231] Optionally, the first byte order range generally includes the header of the signaling packet and at least part of the packet body, and the second byte order range generally includes the header of the data packet and at least part of the packet body.
[0232] The first byte order range may include multiple ranges. For each first byte order range of data in the signaling packet, a similarity calculation is performed between it and the data in each second byte order range in the data packet. This yields the similarity between any data in any first byte order range and any data in any second byte order range. If all similarities (e.g., all calculated similarities) are less than a preset similarity (e.g., 95%, 98%, 99%), it can be determined that there are no identical byte order ranges in the communication data and the corresponding return data, thus confirming that the second matching result is different. If any similarity is greater than the preset similarity, it can be determined that there are identical byte order ranges in the communication data and the corresponding return data, thus confirming that the second matching result is the same.
[0233] Step 017: Based on the second matching result, determine the anomaly detection results of the target node and its associated nodes.
[0234] Optionally, if the proportion of identical communication data in the total communication data is greater than a preset proportion in the second matching result, the anomaly detection result is determined to be abnormal; if the proportion of identical communication data in the total communication data is less than a preset proportion in the second matching result, the anomaly detection result is determined to be normal.
[0235] It is understandable that if the second matching result corresponding to any communication data is the same, it indicates that there is data confusion between the communication data and the corresponding return data (i.e., there is a range of data with the same byte order). When there are many communication data with data confusion, it indicates that the target node is likely using a private protocol. At this time, it can be determined that the anomaly detection result is that the target node is not abnormal.
[0236] Therefore, the proportion of communication data with identical second matching results in the total communication data is used to characterize the proportion of communication data with data confusion. If the proportion of communication data with identical second matching results (e.g., the proportion of identical data packets in the total number of data packets) is greater than a preset proportion (e.g., preset proportions are 60%, 70%, 80%, 90%, 95%, etc.), it indicates a large amount of communication data with data confusion, thus accurately determining the anomaly detection result as abnormal. Conversely, if the proportion of communication data with identical second matching results is less than the preset proportion, it indicates a small amount of communication data with data confusion, thus accurately determining the anomaly detection result as normal.
[0237] The higher the preset percentage setting, the more stringent the anomaly detection, which can improve the accuracy of the detected abnormal nodes.
[0238] Optionally, if the second matching result corresponding to any communication data is the same, the anomaly detection result is determined to be that the target node is abnormal. If the second matching results corresponding to each communication data are different, the anomaly detection result is determined to be that the target node is normal.
[0239] In some embodiments, the node anomaly detection method further includes:
[0240] Step 018: If the anomaly detection result is abnormal, the target node and its associated nodes are downgraded to increase the response time when the downgraded nodes communicate.
[0241] Specifically, if the anomaly detection result (such as the anomaly detection result determined by the function detection result of the function detection and the anomaly detection result determined by the first matching result and the second matching result) is abnormal, only the target node can be downgraded to prevent the abnormal target node from being used for illegal purposes.
[0242] Alternatively, if the anomaly detection result is abnormal, the target node and its associated nodes can be downgraded simultaneously to improve the processing efficiency of abnormal nodes and prevent abnormal target nodes and their associated nodes from being used for illegal purposes.
[0243] In some embodiments, the node anomaly detection method further includes: after a predetermined period of deweighting processing, if no feedback information related to the target node is received, then performing a first blocking process on the target node to prevent the target node from responding to the received communication data.
[0244] The reservation duration is an empirical value and can be set according to actual needs. For example, the reservation duration can be 1 hour or 1 day.
[0245] Optionally, the feedback information may be the appeals or complaints of the tenant to which the target node belongs.
[0246] Optionally, the first blocking process can be to prevent the abnormal target node from continuing to communicate, thereby preventing the abnormal target node from responding to the received communication data.
[0247] For cloud servers, the first blocking measure could be to stop allocating bandwidth, memory, or computing resources to the cloud server, or to disable the cloud server's communication functions, thus preventing the cloud server from communicating. For physical servers, the first blocking measure could be to limit the server's processor frequency, bandwidth, memory, etc., so that at least one of the processor frequency, bandwidth, and memory is essentially zero, making the server unable to operate normally or unable to communicate.
[0248] It's understandable that if the target node is abnormal, it indicates that its tenant is an unauthorized tenant. Unauthorized tenants generally don't file appeals or complaints. However, when a target node or its associated nodes are mistakenly identified as abnormal and demoted, impacting the normal business operations of legitimate tenants, those tenants will typically file appeals or complaints. Therefore, if no feedback is received from the target node after the predetermined demotion period, the target node will be subject to a first blocking action to prevent the abnormal target node from responding to received communication data.
[0249] Compared to detecting spoofed traffic through protocol formats, which has lower accuracy (e.g., typically 50% or 60%), the node anomaly detection method of this application achieves a detection accuracy rate of up to 90% (i.e., the ratio of the number of nodes verified as falsely blocked to the total number of blocked nodes) after verifying the feedback information of the blocked nodes following anomaly detection. This demonstrates a high detection accuracy rate.
[0250] Optionally, the current communication protocol includes at least one of connection-oriented and connectionless protocols.
[0251] Connection-oriented protocols are those that transmit data by establishing a connection, such as TCP. Connectionless protocols are those that transmit data without establishing a connection, such as UDP.
[0252] UDP is a connectionless transport layer protocol in computer networks, and it does not provide reliable data transmission.
[0253] Specifically, the protocol type used by the target node can be determined by the target node's communication data. If the target node's communication data contains signaling packets for establishing a connection, then the target node is using a connection-oriented protocol. If the target node's communication data does not contain signaling packets for establishing a connection and only contains data packets, then the target node is using a connectionless protocol.
[0254] In some embodiments, where the current communication protocol includes at least a connection protocol, detection data is obtained by performing functional detection on the target node.
[0255] Specifically, after determining the protocol type currently used by the target node, if the current communication protocol includes at least a connection protocol, further functional testing is required to perform subsequent anomaly detection, thereby reducing the privileges and blocking abnormal nodes through anomaly detection.
[0256] Optionally, after determining that the target node uses a connection-oriented protocol, the first matching result can be used to determine whether the data formats of the signaling packets and data packets of the target node are consistent. If the data formats are consistent, further functional testing can be performed to conduct subsequent anomaly detection.
[0257] In some embodiments, where the current communication protocol includes at least a connectionless protocol, a second blocking process is applied to the target node to prevent the target node from responding to the received communication data of the connectionless protocol.
[0258] To ensure the security of the target node, communication using connectionless and unreliable protocols such as UDP is generally prohibited. Therefore, if the target node uses at least one connectionless protocol (e.g., only connectionless protocols or both connectionless and connection-oriented protocols), a second blocking measure can be applied to the target node to prevent it from responding to received communication data using connectionless protocols.
[0259] Optionally, a second blocking process can be applied to the target node and its associated nodes for connectionless protocols to prevent the target node and its associated nodes from responding to the received communication data of the connectionless protocol.
[0260] Optionally, taking UDP as an example of a connectionless protocol, the second blocking process can be to modify the network address translation (NAT) type of the target node to NAT4, thereby preventing the target node from conducting UDP communication and preventing UDP from punching holes, thus completing the second blocking process.
[0261] NAT4 (Symmetric NAT) is a strict NAT type that restricts communication between internal and external addresses. Each time an internal address requests a specific external address, it may be bound to a new port number.
[0262] To facilitate understanding of the node anomaly detection method, the following section provides an overview of each step in the method. Please refer to [link / reference needed]. Figure 17 , Figure 17 This is a schematic diagram of the overall process of the node anomaly detection method provided in the embodiments of this application. The node anomaly detection method includes:
[0263] Step 021: Determine the current communication protocol of the target node based on its communication data;
[0264] If the current communication protocol includes at least a connection-oriented protocol, proceed to step 022; if the current communication protocol includes at least a connectionless protocol, proceed to step 028.
[0265] Step 022: Perform consistency matching on the data formats of signaling packets and data packets to obtain the first matching result;
[0266] If the first matching result is consistent, proceed to steps 023 and 024; if the first matching result is inconsistent, proceed to steps 025 and 026.
[0267] Step 023: Perform functional testing on the transmission control functions of each current communication protocol to obtain the functional testing results of each transmission control function;
[0268] Step 024: Based on the functional detection results of each transmission control function, determine the anomaly detection results of the target node and its associated nodes;
[0269] Step 025: Perform byte order matching on the communication data received by the target node and the corresponding return packet data to obtain the second matching result;
[0270] Step 026: Based on the second matching result, determine the anomaly detection results of the target node and its associated nodes;
[0271] Step 027: If the anomaly detection result is abnormal, perform a weight reduction and first-stage blocking on the target node and its associated nodes;
[0272] Step 028: Perform a second blocking process on the target node to prevent the target node from responding to the received connectionless protocol communication data.
[0273] For a detailed description of step 021, please refer to the description of step 011; for a detailed description of step 022, please refer to the description of step 015; for a detailed description of step 023, please refer to the descriptions of steps 01211 to 01213, 01221 and 01222, and 0131 to 0135; for a detailed description of step 024, please refer to the descriptions of steps 014, 0141 and 0142; for a detailed description of step 025, please refer to the description of step 016; for a detailed description of step 026, please refer to the description of step 017; for a detailed description of step 027, please refer to the description of step 018; and for a detailed description of step 028, please refer to the description of the embodiment of the second blocking process. For the sake of brevity, these details will not be repeated here.
[0274] Based on the method described in the above embodiments, this application also provides a detection device for performing the steps in the above-described node anomaly detection method. Please refer to... Figure 18 , Figure 18 This is a schematic diagram of the structure of the detection device 300 provided in an embodiment of this application. The detection device 300 includes an acquisition module 301, a detection module 302, an analysis module 303, and a determination module 304, wherein:
[0275] The acquisition module 301 is used to acquire the current communication protocol of the target node, which is determined based on the communication data of the target node;
[0276] The detection module 302 is used to perform functional detection on the target node to obtain detection data. The functional detection is used to detect at least one transmission control function of the current communication protocol. The detection data includes the communication data sent and received by the target node during the functional detection process.
[0277] The analysis module 303 is used to analyze and process the detection data to determine the functional detection results. The functional detection results include whether the target node has the detected transmission control function during communication.
[0278] The determination module 304 is used to determine the anomaly detection results of the target node and its associated nodes based on the functional detection results. The anomaly detection results include abnormal or normal.
[0279] It should be noted that the specific details of each module unit in the above-mentioned detection device 300 have been described in detail in the embodiments of the above-mentioned node anomaly detection method, and will not be repeated here.
[0280] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.
[0281] In some embodiments, the detection device in this application can be implemented in hardware, such as an electronic device or a component in an electronic device, such as an integrated circuit or a chip; the detection device can also be implemented in software, such as as an application installed in an electronic device.
[0282] In some embodiments, see Figure 19 , Figure 19This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device 400 includes a processor 401 and a memory 402. The memory 402 stores a computer program 403 that can run on the processor 401. When the processor 401 executes the program 403, it implements the various processes of the embodiments of the above-described node anomaly detection method and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0283] Please see Figure 20 , Figure 20 This is a schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application. The electronic device can be a terminal or a server. Exemplarily, the electronic device 500 includes a central processing unit (CPU) 501, a system memory 504 including random access memory (RAM) 502 and read-only memory (ROM) 503, and a system bus 505 connecting the system memory 504 and the central processing unit 501.
[0284] In some embodiments, the electronic device 500 may also include a basic input / output system 506 that helps transmit information between various devices within the computer, and a large-capacity storage device 507 for storing the operating system 513, the client 514, and other program modules 515.
[0285] In some embodiments, the basic input / output system 506 includes a display 508 for displaying information and an input device 509 for user input, such as a touch panel and other input devices. A touch panel is also called a touchscreen. A touch panel may include a touch detection device and a touch controller. Other input devices may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described further here.
[0286] Both the display 508 and the input device 509 are connected to the central processing unit 501 via an input / output controller 510 connected to the system bus 505. The basic input / output system 506 may also include the input / output controller 510 for receiving and processing input from touch panels, other input devices, etc. Similarly, the input / output system 506 also includes output devices such as displays, printers, or other types of output devices.
[0287] Mass storage device 507 is connected to central processing unit 501 via a mass storage controller (not shown) connected to system bus 505. Mass storage device 507 and its associated computer-readable media provide non-volatile storage for electronic device 500. That is, mass storage device 507 may include computer-readable media (not shown) such as hard disk or compact disc read-only memory (CD-ROM) drive.
[0288] Computer-readable media can include computer storage media and communication media. Computer storage media includes volatile and non-volatile, removable and non-removable media implemented using any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Computer storage media include RAM, ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other solid-state storage technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape cassettes, magnetic tape, disk storage, or other magnetic storage devices. Of course, those skilled in the art will recognize that computer storage media are not limited to the above-mentioned types. The system memory 504 and mass storage device 507 described above can be collectively referred to as memory.
[0289] According to various embodiments of this application, the electronic device 500 can also be connected to a remote computer on a network, such as the Internet. That is, the electronic device 500 can be connected to a network 517 via a network interface unit 516 connected to the system bus 505, or the network interface unit 516 can be used to connect to other types of networks or remote computer systems (not shown).
[0290] This application also provides a non-transitory computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described node anomaly detection method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0291] The processor can be the processor in the electronic device described in the above embodiments. The computer-readable storage medium can be a computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, etc.
[0292] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned node anomaly detection method. The processor may be a processor in the electronic device described in the above embodiments. When executed by the processor, the computer program implements the various processes of the embodiments of the aforementioned node anomaly detection method and achieves the same technical effects; therefore, to avoid repetition, further details are omitted here.
[0293] Although embodiments of this application have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of this application, the scope of which is defined by the claims and their equivalents.
Claims
1. A method for detecting node anomalies, characterized in that, include: Obtain the current communication protocol of the target node, wherein the current communication protocol is determined based on the communication data of the target node; The target node is subjected to functional testing to obtain testing data. The functional testing is used to detect at least one transmission control function of the current communication protocol. The testing data includes the communication data sent and received by the target node during the functional testing process. The detection data is analyzed and processed to determine the functional detection results, which include whether the target node has the detected transmission control function during communication. Based on the functional detection results, the anomaly detection results of the target node and its associated nodes are determined, and the anomaly detection results include abnormal or normal.
2. The node anomaly detection method according to claim 1, characterized in that, The process of performing functional detection on the target node to obtain detection data includes: The return packet data of the target node is controlled to obtain the detection data.
3. The node anomaly detection method according to claim 2, characterized in that, The transmission control function includes a timeout retransmission function, and the control of the return packet data of the target node to obtain the detection data includes: Control the target node to stop sending back packets of the received target communication data in order to obtain the detection data; The process of analyzing and processing the detection data to determine the functional detection results includes: If the target communication data is still not retransmitted in the detection data after a preset time period, it is determined that the target node does not have the timeout retransmission function during communication, and the preset time period is greater than the retransmission time threshold of the timeout retransmission function.
4. The node anomaly detection method according to claim 2, characterized in that, The transmission control function includes a packet loss retransmission function. Controlling the return packet data from the target node to obtain the detection data includes: When the target node receives the target communication data, it generates return packet data indicating that the target communication data has not been received and controls the target node to send a return packet based on the return packet data to obtain the detection data; The process of analyzing and processing the detection data to determine the functional detection results includes: If, after multiple packet retransmissions, the target communication data is still not retransmitted in the detection data, it is determined that the target node does not have the function of retransmitting lost packets during communication.
5. The node anomaly detection method according to claim 2, characterized in that, The transmission control function includes a congestion avoidance function, and the control of the return packet data of the target node to obtain the detection data includes: The return packets from the target node are downweighted to obtain the detection data. After downweighting, the response time of the target node to the received communication data increases. The process of analyzing and processing the detection data to determine the functional detection results includes: If, after the weighting process, the amount of data change in the communication data sent and received by the target node is less than a preset threshold, then it is determined that the target node does not have congestion avoidance function during communication.
6. The node anomaly detection method according to claim 1, characterized in that, The process of performing functional detection on the target node to obtain detection data includes: The communication data sent and received by the target node is acquired and used as the detection data.
7. The node anomaly detection method according to claim 6, characterized in that, The transmission control function includes a reliable connection function, and the step of acquiring the communication data sent and received by the target node as the detection data includes: The signaling packets of the target node are acquired as the detection data, and the signaling packets are used to establish or disconnect the connection. The process of analyzing and processing the detection data to determine the functional detection results includes: If the signaling packet does not meet the signaling packet requirements for reliable connection function, it is determined that the target node does not have reliable connection function during communication. The signaling packet requirements include at least one of the following: the number of signaling packets is a preset number and the field used for connection in the signaling packet is a preset value.
8. The node anomaly detection method according to claim 6, characterized in that, The transmission control function includes a slow start function, and the acquisition of communication data sent and received by the target node as the detection data includes: After establishing a connection with the target node, the data packets sent and received by the target node in multiple consecutive rounds are obtained as the detection data; The process of analyzing and processing the detection data to determine the functional detection results includes: If the trend of the number of data packets sent and received by the target node in multiple consecutive rounds does not conform to the preset trend, then it is determined that the target node does not have the slow start function during communication.
9. The node anomaly detection method according to claim 1, characterized in that, The step of determining the anomaly detection results of the target node and its associated nodes based on the functional detection results includes: If the number of transmission control functions that the target node has during communication, as indicated by the function detection results, is less than or equal to a preset number, then the abnormal detection results of the target node and its associated nodes are determined to be abnormal, and the preset number is greater than or equal to 1. If, based on the functional detection results, it is determined that the number of transmission control functions possessed by the target node during communication is greater than a preset number, then the anomaly detection results of the target node and its associated nodes are determined to be normal.
10. The node anomaly detection method according to any one of claims 1-9, characterized in that, The communication data of the target node includes signaling packets and data packets. The signaling packets are used to establish or disconnect a connection, and the data packets are used to transmit data. The method further includes: The data formats of the signaling packets and the data packets are matched for consistency to obtain a first matching result, wherein the first matching result includes consistency or inconsistency; The process of performing functional detection on the target node to obtain detection data includes: If the first matching result is consistent, the target node is subjected to functional detection to obtain detection data.
11. The node anomaly detection method according to claim 10, characterized in that, Also includes: If the first matching result is inconsistent, the byte order of the communication data received by the target node and the corresponding return packet data is matched to obtain a second matching result. The second matching result includes being the same or not the same. Specifically, if there is a byte order range with the same data in the communication data and the corresponding return packet data, the second matching result is the same. If there is no byte order range with the same data in the communication data and the corresponding return packet data, the second matching result is not the same. Based on the second matching result, the anomaly detection results of the target node and its associated nodes are determined.
12. The node anomaly detection method according to claim 11, characterized in that, The step of determining the anomaly detection result based on the second matching result includes: If the proportion of the communication data with the same second matching result in the total communication data is greater than a preset proportion, the anomaly detection result is determined to be abnormal. If the proportion of the communication data with the same second matching result in the total communication data is less than a preset proportion, the anomaly detection result is determined to be normal.
13. The node anomaly detection method according to any one of claims 1, 9, 11, and 12, characterized in that, Also includes: If the anomaly detection result is abnormal, the target node and its associated nodes are downgraded to increase the response time when the downgraded nodes communicate. The associated nodes of the target node include at least one of the following: nodes that communicate with the target node, nodes that are in the same area as the target node, and nodes that belong to the same tenant as the target node.
14. The node anomaly detection method according to claim 13, characterized in that, Also includes: If no feedback information related to the target node is received after a predetermined period of demotion processing, the target node and its associated nodes will be subject to a first blocking process to prevent the target node and its associated nodes from responding to the received communication data.
15. The node anomaly detection method according to claim 1, characterized in that, The current communication protocol type includes at least one of connection-oriented and connectionless protocols. The step of performing functional detection on the target node to obtain detection data includes: If the current communication protocol includes at least a connection protocol, detection data is obtained by performing functional detection on the target node.
16. The node anomaly detection method according to claim 15, characterized in that, Also includes: If the current communication protocol includes at least a connectionless protocol, a second blocking process is applied to the target node and its associated nodes to prevent the target node from responding to the received communication data of the connectionless protocol.
17. A detection device, characterized in that, include: The acquisition module is used to acquire the current communication protocol of the target node, wherein the current communication protocol is determined based on the communication data of the target node; The detection module is used to perform functional detection on the target node to obtain detection data. The functional detection is used to detect at least one transmission control function of the current communication protocol. The detection data includes the communication data sent and received by the target node during the functional detection process. An analysis module is used to analyze and process the detection data to determine the functional detection results, including whether the target node has the detected transmission control function during communication. The determination module is used to determine the anomaly detection results of the target node and its associated nodes based on the functional detection results, wherein the anomaly detection results include abnormal or normal.
18. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the node anomaly detection method as described in any one of claims 1-16.
19. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the node anomaly detection method as described in any one of claims 1-16.
20. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the node anomaly detection method as described in any one of claims 1-16.