Cyclic amplification attack processing method, device, equipment, medium and product

By acquiring and analyzing the CDN origin path field, combined with CAA servers and ICP origin servers, the problem of monitoring and handling CDN loop amplification attacks was solved, and the safe and stable operation of the CDN system was achieved.

CN121509064APending Publication Date: 2026-02-10CHINA MOBILE COMM GRP CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511853171.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-10
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

In existing technologies, the CDN object back-to-origin process may lead to loop amplification attacks, causing CDN system paralysis. Existing back-to-origin inspection methods have limited monitoring scope and cannot accurately locate and effectively handle loop amplification attacks.

Method used

By obtaining the first origin path field, we can monitor the loop amplification attack on the CDN object, determine the handling method using the ICP origin station, monitor and accurately locate the loop amplification attack node in real time, and use the CAA server and ICP origin station for early warning and handling.

Benefits of technology

It enables precise location and effective handling of CDN loop amplification attacks, ensuring the safe and stable operation of CDN business systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509064A_ABST
    Figure CN121509064A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and provides a circular amplification attack processing method, device, equipment, medium and product, the method is applied to a first agent center, and the method comprises the following steps: obtaining a first back source path field; based on the judgment result of the first back source path field, determining a monitoring result of a cyclic amplification attack for a content distribution network CDN object; under the condition that the cyclic amplification attack of the CDN object is monitored, early warning information corresponding to the cyclic amplification attack of the CDN object is sent to an internet content provider ICP source station through a cyclic amplification attack CAA server; and based on the first processing mode sent by the ICP source station, processing the cyclic amplification attack of the CDN object. According to the method, the accurate positioning of the nodes of the CDN cyclic amplification attack is improved, the effectiveness of solving the CDN cyclic amplification attack problem is improved, and the safe and stable operation of a CDN service system is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and in particular to a method, apparatus, device, medium, and product for dealing with cyclic amplification attacks. Background Technology

[0002] China Mobile's Content Delivery Network (CDN) is a content delivery network built by China Mobile to improve the user experience for end users. This network comprises a dispatch center, a content center, and edge nodes, providing content distribution for Internet Content Providers (ICPs) such as e-commerce, video, and games. Edge nodes provide content services to end users; content resources not available at edge nodes are routed back to the content center, and vice versa. However, the CDN's origin-fetching process can be vulnerable to loopback attacks, potentially causing the CDN system to crash.

[0003] Currently, common methods for checking origin servers in the CDN industry include checking during the origin server configuration phase and monitoring the origin server status. However, these methods have limited monitoring scope, making it impossible to accurately locate the nodes involved in CDN loop amplification attacks and effectively handle such attacks. Summary of the Invention

[0004] This application provides a method, apparatus, device, medium, and product for handling cycle amplification attacks, addressing the shortcomings of existing technologies where limited monitoring range leads to inaccurate location of CDN cycle amplification attack nodes and ineffective handling of such attacks. It achieves real-time monitoring of origin access based on a first origin path field, and accurately detects the presence of a CDN object cycle amplification attack by checking if the first origin path field contains the name of the first CDN object corresponding to the first proxy center. This improves the accuracy of locating attack nodes. Then, a first handling method is determined using the ICP origin server, and the CDN cycle amplification attack is effectively handled according to this method, improving the effectiveness of resolving CDN cycle amplification attack problems and ensuring the safe and stable operation of the CDN business system.

[0005] In a first aspect, embodiments of this application provide a method for dealing with loop amplification attacks, applied to a first proxy center, comprising the following steps: Obtain the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. Based on the judgment result of the first origin path field, the monitoring result of the loop amplification attack against the content delivery network CDN object is determined. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. Upon detecting a cyclic amplification attack on the CDN object, the cyclic amplification attack CAA server sends the warning information corresponding to the cyclic amplification attack on the CDN object to the Internet Content Provider (ICP) origin server; the ICP origin server is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information. Based on the first processing method sent by the ICP origin station, the cyclic amplification attack on the CDN object is handled.

[0006] In one embodiment, determining the monitoring result of a loop amplification attack against a Content Delivery Network (CDN) object based on the judgment result of the first origin path field includes: if the judgment result is that the name of the first CDN object does not exist in the first origin path field, determining that there is no loop amplification attack between the CDN objects; if the judgment result is that the name of the first CDN object exists in the first origin path field, determining the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears.

[0007] In one embodiment, determining the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears includes: if the name of the first CDN object appears twice and there is a name of a second CDN object between the two positions where the name of the first CDN object appears twice, determining the monitoring result as the existence of a loop amplification attack between the CDN objects; if the name of the first CDN object appears once and the position where the name of the first CDN object appears is at the end of the first origin path field, determining the monitoring result based on the first device name corresponding to the first proxy center.

[0008] In one embodiment, determining the monitoring result based on the first device name corresponding to the first proxy center includes: if the first device name exists in the first origin field, determining that the monitoring result indicates the presence of a loop amplification attack within the CDN object; if the first device name does not exist in the first origin field, determining that the monitoring result indicates the absence of a loop amplification attack within the CDN object.

[0009] In one embodiment, obtaining the first origin path field includes: receiving an origin request sent by a second proxy center; if no origin resource exists in the first device corresponding to the first proxy center, checking whether the first origin path field exists in the origin request; if the first origin path field does not exist in the origin request, adding the name of the first CDN object and the name corresponding to the first proxy center to the header of the origin request to obtain the first origin path field; if the first origin path field exists in the origin request, obtaining the first origin path field.

[0010] In one embodiment, the first handling method includes a first origin domain name and a first origin domain name Internet Protocol address (IPA). The handling of a loop amplification attack on the CDN object based on the first handling method sent by the ICP origin server includes: when the first origin domain name is the same as the original origin domain name but the first origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address, sending a first origin domain name resolution request to the scheduling center corresponding to the first proxy center; the scheduling center is used to resolve the first origin domain name based on the first origin domain name resolution request to obtain the resolved origin domain name Internet Protocol address; receiving the resolved origin domain name Internet Protocol address sent by the scheduling center; and handling the loop amplification attack on the CDN object based on the resolved origin domain name Internet Protocol address.

[0011] In one embodiment, handling a loop amplification attack on the CDN object based on the resolved origin domain name Internet Protocol address includes: comparing the first origin domain name Internet Protocol address with the resolved origin domain name Internet Protocol address to obtain a first comparison result; handling the loop amplification attack on the CDN object if the first comparison result is consistent with the resolved origin domain name Internet Protocol address; and handling the loop amplification attack on the CDN object based on a second handling method if the first comparison result is inconsistent with the resolved origin domain name Internet Protocol address. The second handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0012] In one embodiment, the first handling method includes a second origin domain name and a second origin domain name Internet Protocol address. The handling of the cyclic amplification attack on the CDN object based on the first handling method sent by the ICP origin station includes: receiving a third origin domain name sent by the CDN object's management center when the second origin domain name is different from the original origin domain name and the second origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address; and handling the cyclic amplification attack on the CDN object based on the third origin domain name.

[0013] In one embodiment, handling the loop amplification attack on the CDN object based on the third origin domain includes: comparing the second origin domain with the third origin domain to obtain a second comparison result; handling the loop amplification attack on the CDN object if the second comparison result shows that the second origin domain and the third origin domain are the same; and handling the loop amplification attack on the CDN object based on a third handling method if the second comparison result shows that the second origin domain and the third origin domain are different. The third handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0014] Secondly, embodiments of this application provide a method for dealing with cyclic amplification attacks, utilizing an ICP source server, including: The system receives a warning message from the first proxy center regarding a loop amplification attack on a CDN object. The loop amplification attack on the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the loop amplification attack on the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path by which the terminal performs content return to the origin. Based on the aforementioned warning information, a first method for handling cyclic amplification attacks on the CDN object is determined. The first handling method is sent to the first proxy center, which is used to handle the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station.

[0015] In one embodiment, the early warning information includes the distribution domain name, the origin domain name, the origin path, and CDN object node information. Determining the first handling method for a cyclic amplification attack on the CDN object based on the early warning information includes: determining a cyclic amplification attack handling model in the ICP origin server; the cyclic amplification attack handling model in the ICP origin server includes multiple handling methods; and selecting the first handling method from the multiple handling methods based on the distribution domain name, the origin domain name, the origin path, and the CDN object node information.

[0016] Thirdly, embodiments of this application also provide a device for dealing with cyclic amplification attacks, comprising: The first acquisition module is used to acquire the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. The monitoring module is used to determine the monitoring result of a loop amplification attack against a content delivery network (CDN) object based on the judgment result of the first origin path field. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first sending module is used to send the warning information corresponding to the cyclic amplification attack of the CDN object to the ICP origin station through the cyclic amplification attack CAA server when the cyclic amplification attack of the CDN object is detected; the ICP origin station is used to determine the first handling method of the cyclic amplification attack of the CDN object based on the warning information. The processing module is used to process the cyclic amplification attack on the CDN object based on the first processing method sent by the ICP origin station.

[0017] Fourthly, embodiments of this application also provide a device for dealing with cyclic amplification attacks, comprising: The first receiving module is used to receive the warning information corresponding to the cyclic amplification attack of the CDN object sent by the first proxy center. The cyclic amplification attack of the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field and by monitoring the cyclic amplification attack of the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path of the terminal to perform content origin. The determination module is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information; The second sending module is used to send the first processing method to the first proxy center, and the first proxy center is used to process the cyclic amplification attack of the CDN object based on the first processing method sent by the ICP origin station.

[0018] Fifthly, embodiments of this application also provide a proxy center device, including a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: Obtain the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. Based on the judgment result of the first origin path field, the monitoring result of the loop amplification attack against the content delivery network CDN object is determined. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. Upon detecting a cyclic amplification attack on the CDN object, the cyclic amplification attack CAA server sends the warning information corresponding to the cyclic amplification attack on the CDN object to the Internet Content Provider (ICP) origin server; the ICP origin server is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information. Based on the first processing method sent by the ICP origin station, the cyclic amplification attack on the CDN object is handled.

[0019] Sixthly, embodiments of this application also provide an ICP source station device, including: a memory, a transceiver, and a processor; A memory for storing computer programs; a transceiver for sending and receiving data under the control of the processor; and a processor for reading the computer programs from the memory and performing the following operations: The system receives a warning message from the first proxy center regarding a loop amplification attack on a CDN object. The loop amplification attack on the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the loop amplification attack on the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path by which the terminal performs content return to the origin. Based on the aforementioned warning information, a first method for handling cyclic amplification attacks on the CDN object is determined. The first handling method is sent to the first proxy center, which is used to handle the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station.

[0020] In a seventh aspect, embodiments of this application also provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method for handling cyclic amplification attacks as described in the first or second aspect above.

[0021] Eighthly, embodiments of this application also provide a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for handling cyclic amplification attacks as described in the first or second aspect above.

[0022] Ninthly, embodiments of this application also provide a computer program product comprising a computer program that, when executed by a processor, implements the method for handling loop amplification attacks as described in the first or second aspect above.

[0023] The method, apparatus, equipment, medium, and product for handling loop amplification attacks provided in this application involve a first proxy center acquiring a first origin path field. This first origin path field represents the path by which a terminal retrieves content from the origin. Based on the judgment result of the first origin path field, a monitoring result for a loop amplification attack targeting a Content Delivery Network (CDN) object is determined. The judgment result represents whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. If a loop amplification attack is detected on the CDN object, a loop amplification attack CAA server sends a warning message corresponding to the loop amplification attack on the CDN object to the Internet Content Provider (ICP) origin station. The ICP origin station determines a first handling method for the loop amplification attack on the CDN object based on the warning message. Based on the first handling method sent by the ICP origin station, the loop amplification attack on the CDN object is handled. In this way, by monitoring the origin status in real time based on the first origin path field, and by checking whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field, it is possible to accurately detect whether there is a CDN object loop amplification attack, which improves the accuracy of locating the nodes of the CDN loop amplification attack. Then, the first handling method is determined by using the ICP origin station. Based on the first handling method, the CDN loop amplification attack is effectively handled, which improves the effectiveness of solving the CDN loop amplification attack problem and ensures the safe and stable operation of the CDN business system. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a schematic diagram illustrating the process of CDN returning to the ICP origin server using existing technology.

[0026] Figure 2 This is a schematic diagram illustrating the process of CDN accessing the origin from other CDN objects using existing technologies.

[0027] Figure 3 This is a schematic diagram of the structure of a single-content loop amplification attack provided by existing technology.

[0028] Figure 4 This is a schematic diagram of the structure of a loop amplification attack using three CDN objects and two content centers provided by existing technology.

[0029] Figure 5 This is one of the flowcharts illustrating the method for dealing with loop amplification attacks provided in this application.

[0030] Figure 6 This is a diagram illustrating the relationship between the CAA server, CAA agent center, and piping center provided in this application.

[0031] Figure 7 This is the second flowchart illustrating the method for dealing with loop amplification attacks provided in this application.

[0032] Figure 8 This is a schematic diagram of the cyclic amplification attack handling model provided in this application.

[0033] Figure 9 This is a schematic diagram of the origin path structure for all CDN objects provided in this application.

[0034] Figure 10 This is a schematic diagram of the device for dealing with the first cyclic amplification attack provided in this application.

[0035] Figure 11 This is a schematic diagram of the device for dealing with the second cycle amplification attack provided in this application.

[0036] Figure 12 This is a schematic diagram of the structure of the agent center device according to an embodiment of this application.

[0037] Figure 13 This is a schematic diagram of the structure of the ICP source station equipment provided in the embodiments of this application.

[0038] Figure 14 This is a schematic diagram of the structure of the electronic device provided in this application. Detailed Implementation

[0039] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0040] Figure 1 This is a schematic diagram illustrating the process relationship between CDN and ICP origin server provided by existing technology, such as... Figure 1 As shown, it includes user equipment 110, local domain name server (DNS) 120, origin server 130, and first CDN object 140, wherein the first CDN object 140 includes first scheduling center 141, first content center 142, first edge node 143, second edge node 144 and third edge node 145. The specific origin-following process includes: the user device initiates a Domain Name Server (DNS) resolution service to the local domain name server to obtain content from the origin server; if the LDNS does not have a corresponding DNS resolution result, it initiates a resolution request to the origin server; the origin server, based on the LDNS information, sends back the resolution result from the scheduling center of the corresponding first CDN object; the LDNS saves the corresponding resolution result, following the Time To Live (TTL), and sends the result back to the user device; the user device initiates a request to the scheduling center of the first CDN object, which selects the optimal service resource based on information such as the ordinary user's Internet Protocol Address (IP) address (e.g., if it is determined that the user belongs to province X, the corresponding request is scheduled to the edge node of the first CDN object in province X); the user device initiates a content request to the first edge node of the corresponding first CDN object; if the first edge node of the first CDN object does not have the corresponding content, it obtains it from the first content center; if the first content center does not have the content, it obtains it from the origin server; after the origin server obtains the content, the content center and the edge node cache the corresponding content, and the edge node of the corresponding first CDN object sends the corresponding content to the user device.

[0041] Large ICPs often choose multiple CDN providers during CDN distribution due to considerations such as bidding and quality. When the origin server is processing origin requests from a given CDN provider, it will not direct these requests to its own actual origin server due to cost considerations; instead, it will often direct them to other CDN providers.

[0042] Figure 2 This is a schematic diagram illustrating the process of CDN accessing the origin server from other CDN objects using existing technologies, such as... Figure 2As shown, it includes: user equipment 110, local domain name server (DNS) 120, origin server 130, first CDN object 140 and second CDN object 150, wherein the second CDN object 150 includes fourth edge node 151, fifth edge node 152, sixth edge node 153, second content center 154 and second scheduling center 155. The specific origin pull process includes: the user device initiates a DNS resolution service to the LDNS to retrieve content from the origin server; the LDNS finds that it does not have a corresponding DNS resolution result and initiates a resolution request to the origin server; the origin server, based on the LDNS information, sends back the corresponding resolution result from the first dispatch center; the LDNS saves the corresponding resolution result (following the TTL time) and sends the result back to the user device; the user device initiates a request to the first dispatch center, which selects the optimal service resource based on the user device's Internet Protocol address and other information (e.g., if it determines that the user device belongs to province X, it will dispatch the corresponding request to the edge node of the first CDN object in province X); the user device initiates a content request to the corresponding first edge node; if the first edge node does not have the corresponding content, it retrieves it from the first content center; if the first content center does not have the content, it retrieves it from the fourth edge node of the second CDN object according to its configuration; if the fourth edge node does not have the content, it will directly retrieve it from the second content center; if the second content center does not have the content, and the second content center's origin pull configuration uses the origin server's Internet Protocol address, it will retrieve the content resource from the origin server.

[0043] In the above-mentioned back-to-origin process, if the second content center is not the origin server IP address, but the first edge node in the first CDN object, a loop phenomenon will occur.

[0044] Figure 3 This is a schematic diagram of the structure of a single-content loop amplification attack provided by existing technology, such as... Figure 3 As shown, a loop appears from edge node 1 of CDN object 1 to the content center of CDN object 1, then to edge node 1 of CDN object 2, then to the content center of CDN object 2, and back to edge node 1 of CDN object 1. This not only prevents the terminal from obtaining content, but also creates a request amplification attack between the four devices of CDN object 1 and CDN object 2. Invalid requests occupy the resources of the four servers and cannot be released for a long time. In essence, this causes a loop amplification attack between some servers of CDN objects.

[0045] Figure 4 This is a schematic diagram of the structure of a loop amplification attack using three CDN objects and two content centers provided by existing technology, such as... Figure 4As shown, the system includes a user device, CDN object 1, CDN object 2, and CDN object 3. Each CDN object contains two edge nodes and two content centers. The three CDN objects form a loop storm as follows: User terminal -> Edge node 1 of CDN object 1 -> Content center 1 of CDN object 1 -> Edge node 2 of CDN object 2 -> Content center 2 of CDN object 2 -> Edge node 1 of CDN object 3 -> Content center 1 of CDN object 3 -> Edge node 2 of CDN object 1 -> Content center 2 of CDN object 1 -> Edge node 1 of CDN object 2 -> Content center 1 of CDN object 2 -> Edge node 2 of CDN object 3 -> Content center 2 of CDN object 3 -> Edge node 1 of CDN object 1.

[0046] Currently, common methods for checking origin servers in the CDN industry include checking during the origin server configuration phase and monitoring the origin server status. However, these methods have limited monitoring scope, making it impossible to accurately locate the nodes involved in CDN loop amplification attacks and effectively handle such attacks.

[0047] In addition, existing technologies have the following problems: monitoring and verification are only performed during the initial configuration, which does not conform to the actual situation of real-time adjustment in the CDN industry; the location and handling time is long and the effect is poor; and it lacks the advantages of the CDN industry in network-wide linkage.

[0048] To address the aforementioned problems, this application provides a method for handling loop amplification attacks. It monitors the origin server status in real time based on the first origin path field and accurately detects the presence of a loop amplification attack on a CDN object by checking if the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. This improves the precision of locating nodes involved in CDN loop amplification attacks. Then, it uses the ICP origin server to determine a first handling method. Based on this method, the CDN loop amplification attack is effectively handled, improving the effectiveness of resolving CDN loop amplification attack problems and ensuring the safe and stable operation of the CDN business system.

[0049] The following is combined with Figures 5-9 This application describes a method for dealing with cyclic amplification attacks. The subject executing this method can be an electronic device or a method for dealing with cyclic amplification attacks installed in the electronic device. The device for dealing with cyclic amplification attacks can be implemented by software, hardware, or a combination of both.

[0050] Figure 5 This is one of the flowcharts illustrating the method for dealing with loop amplification attacks provided in this application, such as... Figure 5 As shown, applied to the first agent center, the method includes the following: Step 101: Obtain the first source path field.

[0051] The first origin path field is used to characterize the path through which the terminal retrieves content from the origin.

[0052] Here, the first origin path field includes the name of the CDN object through which the terminal's origin request passes and the name of the node in the CDN object. For each node passed, the name of that node is added to the origin path field.

[0053] Optionally, the first origin path field can be obtained by adding the device name corresponding to the first proxy center, or it can be obtained directly from other proxy centers.

[0054] Here, the first proxy center also becomes the Cycle Amplified AttacksAggent (CAA Aggent). For example, obtaining the first origin path field includes: receiving an origin request sent by a second proxy center; if there is no origin resource in the first device corresponding to the first proxy center, checking whether the first origin path field exists in the origin request; if the first origin path field does not exist in the origin request, adding the name of the first CDN object and the name corresponding to the first proxy center to the header of the origin request to obtain the first origin path field; if the first origin path field exists in the origin request, obtaining the first origin path field.

[0055] In another example, when origin-back resources exist in the first device, origin-back services are provided to the upstream network element.

[0056] Here, the origin request can be an HTTP request, with the name of the first CDN object and the first proxy center added to the HTTP request header.

[0057] It should be noted that the first device corresponding to the first proxy center can be an edge node or content center in the CDN object. Each edge node and content center in the CDN object has its own proxy center.

[0058] In this embodiment, when the first origin path field does not exist, the name of the first CDN object and the name corresponding to the first proxy center are added to the header of the origin request to obtain the first origin path field. When the first origin path field exists, the first origin path field is obtained, providing important origin data for subsequent loop amplification attack monitoring.

[0059] Step 102: Based on the judgment result of the first origin path field, determine the monitoring result of the loop amplification attack against the Content Delivery Network (CDN) object.

[0060] The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field.

[0061] Specifically, the system monitors for loop amplification attacks on CDN objects by checking whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field.

[0062] Optionally, the monitoring results will differ depending on the number of times the name of the first CDN object appears.

[0063] Optionally, a loop amplification attack on CDN objects can include a loop amplification attack between CDN objects or a loop amplification attack within a CDN object.

[0064] In Example 1, the loop amplification attack includes a loop amplification attack between CDN objects. Determining the monitoring result of a loop amplification attack against a Content Delivery Network (CDN) object based on the judgment result of the first origin path field includes: if the judgment result is that the name of the first CDN object does not exist in the first origin path field, determining that the monitoring result is that there is no loop amplification attack between the CDN objects; if the judgment result is that the name of the first CDN object exists in the first origin path field, determining the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears.

[0065] If the name of the first CDN object is not found in the first origin path field, it means that the origin path does not pass through the first CDN object, and therefore, there is no loop amplification attack. If the name of the first CDN object is found in the first origin path field, there may or may not be a loop amplification attack. It is necessary to monitor whether a loop amplification attack of the CDN object exists based on the number of times and position of the name of the first CDN object.

[0066] It should be noted that in the event of a loop amplification attack where no CDN object exists, the name of the first device is added to the first origin path field, and an origin request and origin path field are sent to the next origin node. Here, the next origin node is pre-distributed by the ICP.

[0067] In this embodiment of the application, when the name of the first CDN object exists in the first origin path field, it is determined that there is no loop amplification attack between CDN objects. When the name of the first CDN object exists, loop amplification attacks are further monitored based on the number of times and location of the first CDN object, which improves the accuracy of monitoring and enables real-time monitoring and rapid handling. Starting from the origin process, any abnormality is detected and immediately intervened to avoid serious risks and hidden dangers caused by loop amplification attacks between CDN objects.

[0068] Furthermore, determining the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears includes: if the name of the first CDN object appears twice and the position of the two occurrences of the name of the first CDN object is between the names of a second CDN object, the monitoring result is determined to be a loop amplification attack between the CDN objects; if the name of the first CDN object appears once and the position of the name of the first CDN object is at the end of the first origin path field, the monitoring result is determined based on the name of the first device corresponding to the first proxy center.

[0069] If the first CDN object name appears twice, and there is another CDN object name sandwiched between these two appearances, it indicates that a CDN object loop amplification attack has already occurred.

[0070] It should be noted that when a circular amplification attack is detected between CDN objects, the circular amplification attack needs to be reported to the ICP origin server so that the ICP origin server can issue a handling method to resolve the circular amplification attack between CDN objects.

[0071] If the first CDN object name appears only once, then the first CDN object must be on the last CDN node in the origin path field. The first proxy center CAA agent needs to check whether there is a loop problem in the origin return within this CDN.

[0072] In this embodiment of the application, the loop amplification attack is further monitored based on the number of times and location of the first CDN object, so as to achieve accurate monitoring and analysis of the loop amplification attack nature of CDN itself and CDN objects.

[0073] Furthermore, determining the monitoring result based on the first device name corresponding to the first proxy center includes: if the first device name exists in the first origin field, determining that the monitoring result indicates the presence of a loop amplification attack within the CDN object; if the first device name does not exist in the first origin field, determining that the monitoring result indicates the absence of a loop amplification attack within the CDN object.

[0074] If the first device name is present in the first origin path field, it means that the origin process passes through the first device and there are no origin resources in the first device. Repeated attacks to the first device will cause a loop amplification attack inside the CDN object. Otherwise, there is no loop amplification attack inside the CDN object.

[0075] It should be noted that when a loop amplification attack exists within the CDN object, it needs to be reported to the ICP origin server to obtain the handling method issued by the ICP origin server to resolve the loop amplification attack within the CDN object. When a loop amplification attack does not exist within the CDN object, the first device name is added to the first origin path field, and an origin request and origin path field are sent to the next origin point.

[0076] In this embodiment of the application, the device name is used to further monitor the cyclic amplification attack inside the CDN object, so as to achieve accurate monitoring and analysis of the cyclic amplification attack nature of the CDN itself and between CDN objects.

[0077] Step 103: If a loop amplification attack is detected on the CDN object, the loop amplification attack CAA server sends the warning information corresponding to the loop amplification attack on the CDN object to the Internet Content Provider (ICP) origin server.

[0078] The ICP origin station is used to determine the first response method for cyclic amplification attacks on the CDN object based on the early warning information.

[0079] Here, the warning information can include the distribution domain name, origin domain name, origin path, and CDN object node information.

[0080] It should be noted that the initial origin path is pre-distributed by the ICP, and the CDN object obtains content according to the pre-distribution rules. In the event of a loop amplification attack, the ICP needs to update the origin path.

[0081] Here, the first approach is to update the origin path. The method for updating the origin path can be to keep the origin domain name unchanged or to change the origin domain name.

[0082] Here, the ICP source station sends the information to the first agent center after determining the first handling method.

[0083] In this embodiment of the invention, by recording and analyzing the back-to-origin path in detail, the discovered loop amplification attacks can be quickly alerted within the CDN and ICP.

[0084] In another embodiment, the ICP source station may also send the first processing method to the previous node of the first agent center.

[0085] It should be noted that the Cycle Amplified Attacks (CAA) server interacts with each ICP origin server through an interface to complete the transmission, review, and recording of cycle amplified attack alerts between CDN objects, and assists in receiving, forwarding, and verifying the handling methods of the ICP origin server.

[0086] It should be noted that a CDN object contains only one CAA server and multiple CAA proxy centers. The CAA server has the following functions: (1) Record the activity status of all CAA agents under its jurisdiction. If the ICP origin station formulates a method to resolve the loop amplification attack between CDN objects based on the alarms provided by the corresponding CDN objects, it needs to find the CAA server of the corresponding CDN object, provide the corresponding handling plan and the corresponding CAA agent information to the CAA server, and the CAA server needs to determine the handling method based on the activity status according to the global information table of the corresponding CAA agent. If the corresponding CAA agent is alive, the CAA server can transfer the relevant handling information to the CAA agent. If the corresponding CAA agent is in an abnormal state, the CAA server needs to report the situation to the ICP origin station, and the ICP origin station will formulate a new handling plan and issue it for targeted execution. The internal CAA agent status information table of CDN is shown in Table 1 below: Table 1 CDN Internal CAA Agent Status Information Table Serial Number CDN object name CAA server corresponding IP CAA agent name CAA agent corresponding IP Status (Online / Offline / Abnormal) 1 XXX 1.1.1.1 XXX-NODE-11 3.3.3.3 Online 2 XXX 1.1.1.1 XXX-NODE-12 3.3.8.9 Offline 3 XXX 1.1.1.2 XXX-NODE-13 3.3.9.6 abnormal (2) The alarms uploaded by the CAA agent are forwarded to the corresponding ICP origin server. Because the CDN serves multiple ICPs, it is necessary to send the CDN loop amplification attack generated by the specified distribution domain back to the designated ICP origin server in accordance with the agreement. From the perspective of business security and data volume, the ICP origin server only accepts the alarms uploaded by the CAA server and does not directly accept the alarms of the CAA agents in each CDN.

[0087] (3) The handling method of the ICP origin station is passed down to the corresponding CAA agent. After the ICP origin station selects the handling method, it will select the corresponding CDN CAA server (which may be the CAA server of the alarm or the CAA server of the previous CDN object in the back-to-origin path).

[0088] (4) According to the handling method issued by the ICP origin site, the CAA server starts the CDN mechanism. If the handling method is to keep the origin domain name unchanged and change the origin IP, the CDN server will directly update the cache of the origin domain name resolution result of the relevant scheduling center to the corresponding origin IP; if the handling method is to change the origin domain name, when the origin site issues the handling instruction, it updates the corresponding origin domain name and origin IP, the CAA server updates the origin domain name of the corresponding domain name in the configuration management center, and the origin domain name is immediately distributed to the CDN nodes (edge ​​nodes, content center) according to the CDN mechanism.

[0089] (5) Record the alarm status of all CDN cyclic amplification attacks within this CDN. The alarm status table of all CDN cyclic amplification attacks within this CDN is shown in Table 2 below: Table 2. Alarm Status of All CDN Cyclic Amplification Attacks Serial Number CDN loop amplification attack number CDN object name CAAserver corresponding IP CAAagent Name CAAagent corresponding IP Origin path Reporting time ICP Name ICP handling methods (changing the origin IP / changing the origin domain) Specific operations Status of processing (Completed / Processing / Failed) Time to complete disposal 1 20240813-001 XXX 1.1.1.1 XXX-NODE-11 3.3.3.3 CDN Object 1 - NOD1, CDN Object 2 - Edge Node NOD2 - Content Center NOD3, CDN Object 3 - Edge Node NOD4 - Content Center NOD5 ICP1 Change origin IP 6.6.6.6 Finish 2 20240813-002 XXX 1.1.1.1 XXX-NODE-12 3.3.8.9 XX ICP1 Change origin domain huiyuan.xxx.com Processing 3 20240813-003 XXX 1.1.1.2 XXX-NODE-13 3.3.9.6 XX ICP2 Change origin IP 6.7.7.7 fail The CAA server can provide CDN operators with excellent analytical assistance by monitoring the status of all cyclic amplification attack alerts within the CDN, and can also present the overall situation in a visual way through its interface with the network management system.

[0090] In this embodiment, the CAA server employs a hot standby mechanism. Large CDN objects are organized into multiple CAA servers based on regions, etc. Each CAA server oversees its own CAA agents (from a management perspective, a CAA agent can only belong to one CAA server). The specific CAA server corresponding to a CAA agent is determined by the distribution management center. The CAA server maintains a backup of the status information of all its managed CAA agents within the CDN distribution management center. If the distribution management center detects an anomaly in a CAA server, in addition to alerting the CDN system administrator, it will select a normal CAA server to take over the work of the CAA agents under the jurisdiction of the abnormal CAA server. At this time, the distribution management center issues instructions to all CAA agents under the jurisdiction of the abnormal CAA server, requiring them to immediately change their CAA server configuration to the new CAA server.

[0091] Step 104: Based on the first processing method sent by the ICP origin station, handle the cyclic amplification attack on the CDN object.

[0092] Here, based on the first handling method, handling a loop amplification attack on a CDN object is essentially about changing the origin path and making origin requests according to the new origin path to resolve the loop amplification attack.

[0093] In another embodiment, after the agent center monitors and completes the handling, it feeds back the relevant handling results to the Cyclic Amplification Attack Server (CAA server). The CAA server verifies the results and feeds them back to the ICP source station, thus realizing closed-loop management of CAA agent's discovery of cyclic amplification attack alarms.

[0094] It should be noted that for CDN objects cooperating with CDN origin servers, on the edge nodes and content centers that distribute the ICP content, the corresponding CAA agent function is an integral part of its own CDN, based on the existing CDN distribution mechanism. This CAA agent works with the CAA server to monitor and handle loop amplification attacks between CDN objects. Once each CDN object edge node or content center goes online, the CAA agent will be started immediately. The CAA agent's functionality must cover all monitoring, recording, and triggering / handling requirements for loop amplification attacks on CDN objects within the domains distributed by this node. Specifically, it monitors all CDN object loop amplification attacks for all domains distributed by this CDN node, records relevant origin path information, and interacts with the corresponding CAA server (including reporting alerts and issuing handling instructions).

[0095] It should be noted that a CAA agent has the following functions: (1) CAA agent reports to CAA server. In order to realize the reporting and processing between CAA agent and ICP source station CAA server, CAA agent needs to report to the corresponding CAA server to realize a one-to-many correspondence between each CAA agent and CAA server. Among them, each CAA agent reports to CAA server in several situations: CAA agent's first report, CAA agent's periodic sending of liveness instructions, and CAA agent's corresponding device going offline due to maintenance or other reasons, which requires reporting to CAA server.

[0096] (2) The CAA agent itself performs CDN object cyclic amplification attack monitoring. The CAA agent monitors in real time whether a cyclic amplification attack occurs, and immediately issues an alarm when it is detected.

[0097] (3) CAA agent reports alarms. Alarm information includes the corresponding distribution domain, origin domain, origin path, CDN node information, etc. After receiving the alarm, the CAA server will generate a unified alarm number and pass the number down to the corresponding CAA agent to ensure that CDN content responds to alarms in a unified manner.

[0098] (4) CAA agent receives handling instructions. After receiving the handling instructions from the CAA server, the CAA agent strictly follows the CDN mechanism. After the CDN scheduling center and distribution management center issue normal origin return instructions, the CAA agent immediately compares the received handling instructions with the instructions. If the two instructions are inconsistent, the CAA agent will report 4XX or 5XX errors level by level according to the CDN agreement and send an abnormal handling application to the CAA server to request re-issuance. After the CAA agent completes the handling, it will send a handling completion instruction to the CAA server, and the corresponding alarm handling will be completed.

[0099] In another embodiment of this application, the CAA agent has a self-checking error reporting mechanism. The server corresponding to the CAA agent has a self-checking mechanism that monitors the running status of the CAA agent in the daemon process. If the following abnormalities are found, they are handled immediately: (1) If the CAA agent process disappears, it will be restarted.

[0100] (2) If the device fails to start N times in a row (which can be configured globally, such as 3 times with an interval of 1 minute), the device will send an alert to the CAA server.

[0101] (3) The CAA server notifies the scheduling center to stop the node service and notifies the distribution center that the node is in an abnormal state and changes the CAAagent status to abnormal.

[0102] Once the CAA agent has completed the process, it will report to the corresponding CAA server according to the online procedure.

[0103] Figure 6 This is a diagram illustrating the relationship between the CAA server, CAA agent center, and piping center provided in this application, as follows: Figure 6As shown, this includes the CDN management center, CAA server 1, CAA server 2, CAA agent centers (agents) at CDN edge nodes, and CAA agents at the CDN content center. Specifically, the CDN management center centrally directs which CAA agent should be associated with which CAA server. CAA server1 and CAA server2 communicate with the CDN management center regarding the status of their respective CAA agents. The CDN management center manages all CAA servers and CAA agents within its CDN. When a CAA agent starts up or goes online for the first time, it reports to the corresponding CAA server according to the management center's configuration. Afterward, it periodically reports its liveness status using heartbeat messages. The corresponding server for each CAA agent also performs status checks. If it detects an abnormal CAA agent that it cannot quickly resolve itself, it sends a message to the CDN management center and the scheduling center, initiating a handling mechanism. Each CAA server periodically publishes liveness heartbeat information to the management center. If the CDN management center does not receive heartbeat information from the corresponding CAA server within the specified time, it notifies all CAA agents under that CAA server to relocate to a new CAA server.

[0104] In this embodiment, the origin status is monitored in real time based on the first origin path field, and the existence of the name of the first CDN object corresponding to the first proxy center can be accurately detected by checking whether the first origin path field contains the name of the first CDN object. This improves the accuracy of locating the nodes of the CDN cyclic amplification attack. Then, the first handling method is determined using the ICP origin station. Based on the first handling method, the CDN cyclic amplification attack is effectively handled, improving the effectiveness of solving the CDN cyclic amplification attack problem and ensuring the safe and stable operation of the CDN business system.

[0105] Furthermore, the first handling method includes a first origin domain name and a first origin domain name Internet Protocol address (IPA). The handling of a loop amplification attack on the CDN object based on the first handling method sent by the ICP origin station includes: when the first origin domain name is the same as the original origin domain name but the first origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address, sending a first origin domain name resolution request to the scheduling center corresponding to the first proxy center; the scheduling center is used to resolve the first origin domain name based on the first origin domain name resolution request to obtain the resolved origin domain name Internet Protocol address; receiving the resolved origin domain name Internet Protocol address sent by the scheduling center; and handling the loop amplification attack on the CDN object based on the resolved origin domain name Internet Protocol address.

[0106] Here, the original origin domain is the origin domain that was first distributed by the ICP origin site.

[0107] Here, the scheduling center is the scheduling center in the first CDN object.

[0108] When the first origin domain name is the same as the original origin domain name but the origin domain name IP address is different, it means that the ICP's handling method is to keep the origin domain name unchanged, and the ICP origin site itself changes the origin IP address resolution result. Here, the origin IP address resolution result is obtained after resolving the origin domain name.

[0109] The ICP sends the first origin domain name and its IP address to the first proxy center via the CAA server. The first proxy center then requests the first origin domain name resolution from the corresponding scheduling center. The scheduling center resolves the first origin domain name and obtains the resolved origin domain name IP address. After receiving the resolved origin domain name IP address, the first proxy center handles the loop amplification attack on the CDN object.

[0110] Optionally, the first proxy center may directly handle the loop amplification attack based on the resolved origin domain IP address; or it may re-handle the loop amplification attack by having the ICP origin server reissue a new handling method through the CAA server if the resolved origin domain IP address fails to handle the loop amplification attack.

[0111] In this embodiment of the application, when the handling method issued by the ICP origin station is to keep the origin domain name unchanged, the path update operation is performed to handle the loop amplification attack. Moreover, the handling method is flexible and diverse, which maximizes the protection of the ICP's purpose of controlling the origin traffic and also ensures the normal origin traffic between CDN partners.

[0112] Furthermore, the step of handling the loop amplification attack on the CDN object based on the resolved origin domain name Internet Protocol address includes: comparing the first origin domain name Internet Protocol address with the resolved origin domain name Internet Protocol address to obtain a first comparison result; handling the loop amplification attack on the CDN object if the first comparison result is consistent with the resolved origin domain name Internet Protocol address; and handling the loop amplification attack on the CDN object based on a second handling method if the first comparison result is inconsistent with the resolved origin domain name Internet Protocol address. The second handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0113] It should be noted that when the first origin domain's Internet Protocol address matches the resolved origin domain's Internet Protocol address, the next origin point of the first device is changed according to the first origin domain's Internet Protocol address, and the origin process continues.

[0114] Here, the abnormal information refers to the discrepancy between the Internet Protocol address of the first origin domain and the Internet Protocol address of the resolved origin domain.

[0115] When the first origin domain's Internet Protocol address (IPA address) is inconsistent with the resolved origin domain's IPA address, the CAA server reports this to the ICP origin server, causing the ICP origin server to issue a second handling method. Based on the second handling method, the loop amplification attack is dealt with.

[0116] In this embodiment of the application, by comparing the first origin domain Internet Protocol address issued by the ICP origin station with the resolved origin domain Internet Protocol address, the accuracy and efficiency of handling loop amplification attacks are improved.

[0117] Furthermore, the first handling method includes a second origin domain name and a second origin domain name Internet Protocol address. The handling of the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station includes: receiving a third origin domain name sent by the CDN object's management center when the second origin domain name is different from the original origin domain name and the second origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address; and handling the cyclic amplification attack of the CDN object based on the third origin domain name.

[0118] When the second origin domain name is different from the original origin domain name and the IP address of the second origin domain name is different from the original origin domain name, it means that the ICP's handling method is to change the origin domain name, let the first CDN object scheduling center refresh the origin result, and use the CDN object's configuration center to send the corresponding updated origin domain name, i.e., the third origin domain name, to the corresponding CDN edge node and content center. The first proxy center handles the loop amplification attack based on the third origin domain name.

[0119] Optionally, the first proxy center may handle the loop amplification attack directly based on the third origin domain, or it may not be able to handle the loop amplification attack based on the third origin domain and need to obtain the handling method from the ICP origin station again to handle the loop amplification attack.

[0120] In this embodiment of the application, when the handling method issued by the ICP origin station is to change the origin domain name, the update path operation is performed to handle the loop amplification attack. Moreover, the handling method is flexible and diverse, which maximizes the protection of the ICP's purpose of controlling the origin traffic and also ensures the normal origin access method between CDN vendors.

[0121] Furthermore, the step of handling the loop amplification attack on the CDN object based on the third origin domain includes: comparing the second origin domain with the third origin domain to obtain a second comparison result; handling the loop amplification attack on the CDN object if the second comparison result shows that the second origin domain and the third origin domain are the same; and handling the loop amplification attack on the CDN object based on a third handling method if the second comparison result shows that the second origin domain and the third origin domain are different. The third handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0122] It should be noted that if the second origin domain name is the same as the third origin domain name, the next origin point of the first device is changed according to the second origin domain name, and the origin process continues.

[0123] Here, the abnormal information refers to the inconsistency between the second and third origin domains.

[0124] When the second and third origin domains are inconsistent, the CAA server reports the issue to the ICP origin server, causing the ICP origin server to issue the second handling method. According to the second handling method, the loop amplification attack is handled.

[0125] In this embodiment of the application, by comparing the origin domain name issued by the ICP origin station with the origin domain name of the CDN object's management center, the accuracy and efficiency of handling loop amplification attacks are improved.

[0126] Figure 7 This is the second flowchart illustrating the method for handling loop amplification attacks provided in this application, as shown below. Figure 7 As shown, the method using an ICP source station includes the following: Step 201: Receive the warning information corresponding to the cyclic amplification attack of the CDN object sent by the first proxy center.

[0127] The CDN object loop amplification attack is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the content delivery network CDN object loop amplification attack. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path of the terminal to perform content origin.

[0128] Step 202: Based on the warning information, determine the first handling method for the cyclic amplification attack on the CDN object.

[0129] Here, the warning information includes the distribution domain, origin domain, origin path, and CDN object node information. Furthermore, the early warning information includes the distribution domain name, origin domain name, origin path, and CDN object node information. Determining the first handling method for a loop amplification attack on the CDN object based on the early warning information includes: determining a loop amplification attack handling model in the ICP origin server; the loop amplification attack handling model in the ICP origin server includes multiple handling methods; and selecting the first handling method from the multiple handling methods based on the distribution domain name, the origin domain name, the origin path, and the CDN object node information.

[0130] Here, the loop amplification attack handling model refers to the source path for resolving loop attack prevention.

[0131] For example, Figure 8 This is a schematic diagram of the cyclic amplification attack handling model provided in this application, as shown below. Figure 8 As shown, the ICP origin server distributes content to different origin points through distribution domain name 1 and distribution domain name 2. For example, distribution domain name 1 distributes content to CDN object 1 and CDN object 2, and distribution domain name 2 distributes content to CDN object 1, CDN object 2, CDN object 3, and the origin server. If there is no content at the origin point, the IP address of the upstream node is obtained through the origin domain name, and content is requested from the upstream node. For example, in distribution domain name 1, CDN object 1 requests content from the origin IP a or an agreed-upon IP address accessible from the origin via origin domain name a (ICP origin server), and CDN object 2 requests content from the origin IP via origin domain name b. Content is retrieved from the origin IP (ICP origin server) or the origin IP (CDN object 1) or an agreed-upon IP that can be accessed from the origin. In distribution domain 2, CDN object 1 retrieves content from the origin IP (CDN object 2) via the origin domain c or an agreed-upon IP that can be accessed from the origin. CDN object 2 retrieves content from the origin IP (CDN object 1) via the origin domain d or an agreed-upon IP (CDN object 1). CDN object 3 retrieves content from the origin IP (CDN object 2) via the origin domain e or an agreed-upon IP that can be accessed from the origin. The origin server retrieves content from the origin IP (ICP origin server) or an agreed-upon IP that can be accessed from the origin.

[0132] In another example of this application, the ICP origin server, based on the CDN object loop amplification attack warning information uploaded by the corresponding CAA server, prioritizes selecting a CDN object with a direct origin selection option from the CDN objects not involved in the origin path of the distribution domain. The origin of the upstream CDN of the CDN loop amplification attack is then directed to the newly selected CDN object. The origin of the newly selected CDN object is reduced by utilizing its own distribution mechanism (ideally, the corresponding domain name within the CDN has already cached content on all devices).

[0133] If, within a fixed timeframe (the timeframe can be set), the ICP origin server receives another alarm for a similar loop amplification attack (with at least two identical CDN objects), it immediately selects the local CDN involved in the loop amplification attack to execute the attack back to the origin server itself. Simultaneously, based on the size of the CDN object, it selects a smaller-scale CDN object and executes its origin domain name resolution IP on the ICP origin server. If the ICP detects that the origin domain name has not experienced another inter-CDN loop amplification attack for an extended period, and the origin traffic increases, it will readjust the origin domain names among the CDN objects to reduce the origin traffic of the ICP origin server.

[0134] The process of constructing a cyclic amplification attack handling model includes: (1) ICP origin site stores all distribution domain name corresponding information group: ICP origin site stores all distribution domain names Q={q1,q2,q3,...,qi}, where each qi represents the full back-to-origin information corresponding to a distribution domain name (i.e., distribution domain name, ICP name, back-to-origin domain name and back-to-origin IP information, etc.).

[0135] (2) CDN loop amplification attack alarm information reported by each CDN object: The CDN loop amplification attack alarm information reported by each CDN object is R={r1,r2,r3,...,r m}, where each r m This represents information about specific CDN loop amplification attacks reported by the corresponding CDN object.

[0136] (3) CDN Cyclic Amplification Attack Alarm Information Occurring Within a Fixed Time Period: The CDN cyclic amplification attack historical alarm information stored within a fixed time period reported by the CDN object is T={t1,t2,t3,...,tn}, where each tn represents the historical CDN cyclic amplification attack information of the corresponding CDN object within a fixed time period. The alarms in T automatically disappear after the fixed time period.

[0137] To address CDN loop amplification attacks, the process of an ICP automatically distributing a solution algorithm for CDN loop amplification attacks includes: (1) The alarm is first detected within a fixed time period.

[0138] a) Selectable origin domain and IP information group corresponding to each CDN loop amplification attack alert: W=R∩Q={domain name corresponding to each alert, specific path of loop attack, CDN name involved in loop attack, all origin domains and IP addresses of ICP under this domain}, where W represents the current loop amplification attack, R represents the alert information, Q represents all origin domains and IP addresses of ICP under this domain, and ∩ represents the intersection; if T∩W is empty, it means that the alert has been discovered for the first time, and subsequent operations are performed.

[0139] b) The specific path of the loop attack in W is matrix A, and matrix A is as follows (1): (1) In W, the ICP under this domain name has multiple origin domain names and IP address information as shown in the following formula (2): (2) c) The available origin domains are BB∩A. Select a smaller CDN from among them, and then select an accessible IP from among them.

[0140] d) Select the last node of the second-to-last CDN object (set as d) from A, and adopt the corresponding replacement origin method according to the ICP and the corresponding CDN object d agreement.

[0141] If the method of replacing the origin IP is adopted (the origin domain name of the original CDN object d is still used).

[0142] Alternatively, the origin domain name can be replaced (as agreed, the origin domain name and specific available origin IP of the corresponding CDN object d are replaced).

[0143] (2) The alarm is detected a second time within a fixed time period: a) Each CDN loop amplification attack alarm corresponds to a selectable origin domain name and IP information group: W=R∩Q={each alarm corresponds to the domain name, the specific path of the loop attack, the CDN name involved in the loop attack, all origin domain names and IP addresses of the ICP under this domain name}; if T∩W is not empty, it means that the alarm has been detected for the second time, and subsequent operations should be performed.

[0144] b) The specific path of the loop attack in W is matrix A.

[0145] c) In accordance with the agreement between the ICP and the corresponding CDN object d, the origin IP is sent directly to the last network element of the last CDN object in A for fast origin return.

[0146] (3) After the processing is completed, the corresponding alarm will automatically enter T.

[0147] In this embodiment of the invention, through automatic detection within the CDN and interaction between the ICP and the CAA server in the CDN, the domain name distributed by the ICP is ensured to be analyzed and processed in a coordinated manner among all CDN objects. The processing methods are flexible and diverse, maximizing the protection of the ICP's purpose of controlling the origin traffic and ensuring the normal origin traffic between CDN objects.

[0148] Step 203: Send the first processing method to the first agent center.

[0149] The first proxy center is used to handle the cyclic amplification attack on the CDN object based on the first handling method sent by the ICP origin station.

[0150] By monitoring the origin server status in real time based on the first origin path field, and by checking whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field, it is possible to accurately detect whether a CDN object loop amplification attack exists. This improves the accuracy of locating nodes involved in CDN loop amplification attacks. Then, the first handling method is determined using the ICP origin server. Based on the first handling method, the CDN loop amplification attack is effectively handled, improving the effectiveness of solving the CDN loop amplification attack problem and ensuring the safe and stable operation of the CDN business system.

[0151] The following example, using a direct loop amplification attack on three CDN objects, illustrates the process for monitoring and handling loop amplification attacks.

[0152] Figure 9 This is a schematic diagram of the origin path structure for all CDN objects provided in this application, such as... Figure 9 As shown, the terminal requests relevant content from the CDN object 1 CAA proxy center. CDN object 1 does not have the corresponding content and a backhaul to the origin server is required. According to the agreement between CDN object 1 and the ICP origin server, the backhaul is performed from the edge node of CDN object 2. During the backhaul process, CDN object 1 adds a backhaul path field to the HTTP Request Headers, which contains the name and node identifier of CDN object 1. The identifier can be added according to the ICP origin server's requirements, following the field names and sizes defined by the ICP. Subsequent CDN objects can only add this field later; the content preceding this field cannot be deleted. For example, if this is the first backhaul request for CDN object 1, the backhaul path field records the CDN object 1 identifier and the backhaul node name. In this case, the backhaul path is: CDN object 1-NODX.

[0153] The edge node of CDN object 2 found no relevant resources, so it initiated a back-to-origin request to the content center of CDN object 2 according to the CDN object 2 origin return rules. Before initiating the back-to-origin request to the content center of CDN object 2, the CAA agent of the edge node of CDN object 2 must first perform a CDN object loop attack check, that is, check whether there is a back-to-origin path field. If there is no back-to-origin path field, the CAA agent adds the corresponding information (i.e., CDN object 2 + corresponding edge node name) and sends a back-to-origin request to the next back-to-origin node according to the back-to-origin domain name; if there is a back-to-origin path field, the CAA agent first checks all CDN names in the back-to-origin path field.

[0154] Specifically, if the name of CDN object 2 is not found in the origin path field, it means that CDN object 2 and the previous CDN object have not yet formed a loop amplification attack. The origin request is still sent to the content center of CDN object 2. At the same time, the CAA agent adds the corresponding information (i.e., CDN object 2 + corresponding edge node name).

[0155] Upon discovering the name CDN object 2, the CAA agent checks the frequency and positional relationships of its appearance. Based on these relationships, it monitors for loop amplification attacks. Specifically, if the name CDN object 2 appears twice, and another CDN object name appears between these two occurrences, it indicates a loop amplification attack between CDN objects (e.g., CDN objects x-NOD1, NOD2; CDN object 2-NOD3, NOD4; CDN object 1; CDN object 2-NOD5). If the name CDN object 2 appears only once, it must be on the last CDN node in the origin path field. The CAA agent then checks for loop issues within the CDN's origin process. If the origin path field contains an edge node for CDN object 2, it indicates a problem with the origin logic within CDN object 2. Otherwise, the CAA agent appends the name of the current node (i.e., the edge node of CDN object 2) to the last node name in the origin path field and initiates an origin request to the content center of CDN object 2. The origin path at this time is: CDN object 1 - NODX, CDN object 2 - edge node NOD2.

[0156] Then, the content center of CDN object 2 finds that it does not have the relevant resources, so according to the origin return rules of CDN object 2, it initiates an origin return request to CDN object 1. The CAA agent of the corresponding device adds the content center node name to the origin return path in the origin return request header.

[0157] The origin pull path at this point is: CDN object 1 - NODX, CDN object 2 - edge node NOD2 - content center NOD3. Based on the previous situation, CDN object 1 will find that it does not have the required origin pull content. When the CAA agent of CDN object 1 checks, it discovers CDN object 1 in the origin pull path, indicating a loop amplification attack. Therefore, the CAA agent of the corresponding device immediately stops the origin pull operation and alerts the CDN system administrator of CDN object 1. The CDN system administrator must simultaneously coordinate with the ICP to resolve the origin pull issue.

[0158] When a circular amplification attack is detected, the CAA agent on CDN object 1 submits an alert to the ICP origin server of the corresponding domain name through the agreed interface via the CAA server of CDN object 1. The alert information includes the distribution domain name, the origin domain name, the origin path, and abnormal errors.

[0159] After receiving the corresponding alarm, the ICP origin station locates the origin path node and immediately cooperates in handling the CDN object loop amplification attack. According to the CDN scheduling mechanism, there are two handling methods: (1) The ICP origin station, according to the origin path, makes the upper-level origin node change the origin path again; (2) The ICP origin station, according to the origin path, makes the current origin node change the origin path again.

[0160] Next, the ICP origin server initiates a change of origin path operation to the CAA server of CDN object 2. In this process, the ICP origin server notifies the corresponding CAA server of CDN object 2 to clarify the solution for resolving the inter-CDN object loop amplification attack. The CAA server issues corresponding instructions to the corresponding CAA agent of CDN object 2. After the corresponding operation is completed, the CAA agent of CDN object 2 is instructed to re-initiate the origin path through the interface.

[0161] There are two ways to change the origin path of an ICP origin server: (1) In order to keep the origin domain name unchanged, after the ICP origin site changes the origin IP address resolution result, the CAA agent of the CDN object 2 content center re-initiates the origin domain name resolution request, and the CDN object 2 content center re-initiates the origin domain name resolution request to the corresponding scheduling center to obtain the new origin domain name IP address.

[0162] (2) One method is to change the origin domain name of the ICP origin site and then let the CDN object 2 scheduling center refresh the origin result.

[0163] After the corresponding CAA agent completes the monitoring of the new origin domain and origin return result, it will feed back the relevant processing results to the CAA server. The CAA server will verify the results and then feed them back to the ICP origin server, thus realizing the closed-loop management of CAA agent's discovery of loop amplification attack alarms and restarting the origin return process.

[0164] During the CDN origin pull process, the origin pull path is continuously recorded, and it is determined whether there are loop amplification attacks caused by origin pulls between CDN objects.

[0165] With the cooperation of the ICP origin server and CAA agent, CDN object 1 performs a back-to-origin operation at the edge node on CDN object 3. The back-to-origin path at this time is: CDN object 1 - NODX, CDN object 2 - edge node NOD2 - content center NOD3, CDN object 3 - edge node NOD4.

[0166] If the edge nodes on CDN object 3 have no content, the origin pull operation will be performed from the content center of CDN object 3. The origin pull path at this point is: CDN object 1 - NODX, CDN object 2 - edge node NOD2 - content center NOD3, CDN object 3 - edge node NOD4 - content center NOD5.

[0167] The content center on CDN object 3 has no content, so according to the origin domain rules, the origin pull operation is performed at the edge node of CDN object 2. The CAA agent of the edge node of CDN object 2 detects a loop amplification attack, stops the origin pull operation, and alerts the CDN system administrator of CDN object 2. The corresponding CDN system administrator should also coordinate with the ICP to resolve the origin pull issue.

[0168] The CAA agent on the edge node of CDN object 2 submits an alert to the corresponding CAA server according to the agreed interface. The CAA server submits the alert information to the corresponding ICP origin server according to the ICP affiliation of the corresponding domain name. The alert information includes information such as the distribution domain name, the origin domain name, the origin path, and abnormal errors.

[0169] After receiving the corresponding alarm, the ICP origin server locates the origin path node and immediately cooperates in handling the CDN object loop amplification attack.

[0170] The ICP origin server initiates an operation to change the origin path to the CDN object 2CAAserver. The origin domain name remains unchanged, and the resolution result of the origin domain name is updated to the origin server.

[0171] This solution involves keeping the origin domain unchanged, having the ICP origin server change the origin domain resolution result to this site, and then notifying the CAA server of the corresponding CDN object 2. The CAA server then passes this information to the corresponding CAA agent to resolve the CDN object loop amplification attack.

[0172] The CAA agent of the CDN object 2 edge node re-initiates the origin resolution request, and the CDN object 2 edge node re-enters the origin domain name resolution request from the corresponding scheduling center to obtain the new origin domain name IP address.

[0173] After the CAA agent of the corresponding CDN object 2 edge node completes the new origin check, it will feed back the relevant handling results to the CAA server. After verification by the CAA server, it will feed back to the ICP origin station, thus realizing the closed-loop management of this CDN object inter-circular amplification attack alarm handling.

[0174] CDN object 2 edge node successfully retrieved the relevant content resources by going back to the ICP origin server.

[0175] According to the corresponding CDN origin pull business process, in the reverse order of CDN object 1-NODX, CDN object 2-edge node NOD2-content center NOD3, CDN object 3-edge node NOD4-content center NOD5, the relevant content is sequentially pulled to the content center of CDN object 3, the edge node of CDN object 3, the content center of CDN object 2, the edge node of CDN object 2, and the origin pull of CDN object 1, and then CDN object 1 feeds back the corresponding content to the user terminal.

[0176] The apparatus for dealing with cyclic amplification attacks provided in this application will be described below. The apparatus for dealing with cyclic amplification attacks described below can be referred to in correspondence with the method for dealing with cyclic amplification attacks described above.

[0177] Figure 10 This is a schematic diagram of the structure of the device for dealing with the first cyclic amplification attack provided in this application, as shown below. Figure 10 As shown, the first cycle amplification attack disposal device 300 includes: The first acquisition module 310 is used to acquire the first origin path field; the first origin path field is used to characterize the path through which the terminal performs content return. The monitoring module 320 is used to determine the monitoring result of a loop amplification attack against a content delivery network (CDN) object based on the judgment result of the first origin path field. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first sending module 330 is used to send the warning information corresponding to the cyclic amplification attack of the CDN object to the ICP origin station through the cyclic amplification attack CAA server when the cyclic amplification attack of the CDN object is detected; the ICP origin station is used to determine the first handling method of the cyclic amplification attack of the CDN object based on the warning information. The processing module 340 is used to process the cyclic amplification attack of the CDN object based on the first processing method sent by the ICP origin station.

[0178] In one embodiment, the monitoring module 320 is specifically configured to: determine that there is no loop amplification attack between the CDN objects when the judgment result is that the name of the first CDN object does not exist in the first origin path field; and determine the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears when the judgment result is that the name of the first CDN object exists in the first origin path field.

[0179] In one embodiment, the monitoring module 320 is further configured to: determine that a loop amplification attack exists between the CDN objects when the name of the first CDN object appears twice and the name of a second CDN object exists between the two occurrences of the name of the first CDN object; and determine the monitoring result based on the first device name corresponding to the first proxy center when the name of the first CDN object appears once and the occurrence of the name of the first CDN object is at the end of the first origin path field.

[0180] In one embodiment, the monitoring module 320 is further configured to: determine that a loop amplification attack exists within the CDN object if the first device name exists in the first origin field; and determine that a loop amplification attack does not exist within the CDN object if the first device name does not exist in the first origin field.

[0181] In one embodiment, the first acquisition module 310 is specifically configured to: receive a back-to-origin request sent by the second proxy center; if there is no back-to-origin resource in the first device corresponding to the first proxy center, check whether the first back-to-origin path field exists in the back-to-origin request; if the first back-to-origin path field does not exist in the back-to-origin request, add the name of the first CDN object and the name corresponding to the first proxy center to the header of the back-to-origin request to obtain the first back-to-origin path field; if the first back-to-origin path field exists in the back-to-origin request, acquire the first back-to-origin path field.

[0182] In one embodiment, the first handling method includes a first origin domain name and a first origin domain name Internet Protocol address (IPA). The handling module 340 is specifically used for: sending a first origin domain name resolution request to the scheduling center corresponding to the first proxy center when the first origin domain name is the same as the original origin domain name and the first origin domain name IPA is different from the original origin domain name IPA; the scheduling center is used to resolve the first origin domain name based on the first origin domain name resolution request to obtain the resolved origin domain name IPA; receiving the resolved origin domain name IPA sent by the scheduling center; and handling the loop amplification attack of the CDN object based on the resolved origin domain name IPA.

[0183] In one embodiment, the processing module 340 is further configured to: compare the first origin domain name Internet Protocol address with the resolved origin domain name Internet Protocol address to obtain a first comparison result; if the first comparison result shows that the first origin domain name Internet Protocol address and the resolved origin domain name Internet Protocol address are consistent, process the cyclic amplification attack of the CDN object; if the first comparison result shows that the first origin domain name Internet Protocol address and the resolved origin domain name Internet Protocol address are inconsistent, process the cyclic amplification attack of the CDN object based on a second processing method; the second processing method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0184] In one embodiment, the first processing method includes a second origin domain name and a second origin domain name Internet Protocol address. The processing module 340 is further specifically used to: receive a third origin domain name sent by the CDN object's management center when the second origin domain name is different from the original origin domain name and the second origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address; and process the CDN object's cyclic amplification attack based on the third origin domain name.

[0185] In one embodiment, the handling module 340 is further specifically configured to: compare the second origin domain name with the third origin domain name to obtain a second comparison result; if the second comparison result shows that the second origin domain name and the third origin domain name are the same, handle the loop amplification attack of the CDN object; if the second comparison result shows that the second origin domain name and the third origin domain name are inconsistent, handle the loop amplification attack of the CDN object based on a third handling method; the third handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0186] Figure 11This is a schematic diagram of the structure of the device for dealing with the second cycle amplification attack provided in this application, as shown below. Figure 11 As shown, the second cycle amplification attack disposal device 400 includes: The first receiving module 410 is used to receive the warning information corresponding to the cyclic amplification attack of the CDN object sent by the first proxy center. The cyclic amplification attack of the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field and by monitoring the cyclic amplification attack of the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path of the terminal to perform content origin. The determination module 420 is used to determine the first handling method for the cyclic amplification attack of the CDN object based on the warning information; The second sending module 430 is used to send the first processing method to the first proxy center, and the first proxy center is used to process the cyclic amplification attack of the CDN object based on the first processing method sent by the ICP origin station.

[0187] In one embodiment, the warning information includes the distribution domain name, the origin domain name, the origin path, and CDN object node information. The determination module 420 is specifically used to: determine the loop amplification attack handling model in the ICP origin station; the loop amplification attack handling model in the ICP origin station includes multiple handling methods; and select the first handling method from the multiple handling methods based on the distribution domain name, the origin domain name, the origin path, and the CDN object node information.

[0188] Figure 12 This is a schematic diagram of the structure of the agent center device according to an embodiment of this application, with reference to... Figure 12 This application embodiment also provides a proxy center device, which may include: a memory 1210, a transceiver 1220 and a processor 1230; Memory 1210 is used to store computer programs; transceiver 1220 is used to send and receive data under the control of processor 1230; processor 1230 is used to read the computer program in memory 1210 and perform the following operations: Obtain the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. Based on the judgment result of the first origin path field, the monitoring result of the loop amplification attack against the content delivery network CDN object is determined. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. Upon detecting a cyclic amplification attack on the CDN object, the cyclic amplification attack CAA server sends the warning information corresponding to the cyclic amplification attack on the CDN object to the Internet Content Provider (ICP) origin server; the ICP origin server is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information. Based on the first processing method sent by the ICP origin station, the cyclic amplification attack on the CDN object is handled.

[0189] Among them, Figure 12 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1230 and memory represented by memory 1210 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1220 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. For different user equipment, user interface 1240 can also be an interface capable of connecting external or internal devices as needed.

[0190] The processor 1230 is responsible for managing the bus architecture and general processing, and the memory 1210 can store the data used by the processor 1230 when performing operations.

[0191] The processor 1230 executes any of the methods described in the embodiments of this application by calling a computer program stored in the memory 1210, according to the obtained executable instructions. The processor and the memory may also be physically separated.

[0192] Optionally, the processor 1230 is also used to perform the following operations: The loop amplification attack includes loop amplification attacks between CDN objects. Determining the monitoring result of a loop amplification attack against a Content Delivery Network (CDN) object based on the judgment result of the first origin path field includes: if the judgment result is that the name of the first CDN object does not exist in the first origin path field, determining that the monitoring result is that there is no loop amplification attack between the CDN objects; if the judgment result is that the name of the first CDN object exists in the first origin path field, determining the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears.

[0193] The loop amplification attack also includes loop amplification attacks within CDN objects. Determining the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears includes: if the name of the first CDN object appears twice and the name of a second CDN object exists between the two positions where the name of the first CDN object appears twice, the monitoring result is determined to be a loop amplification attack between the CDN objects; if the name of the first CDN object appears once and the position where the name of the first CDN object appears is at the end of the first origin path field, the monitoring result is determined based on the first device name corresponding to the first proxy center.

[0194] The step of determining the monitoring result based on the first device name corresponding to the first proxy center includes: if the first device name exists in the first origin field, determining that the monitoring result indicates the presence of a loop amplification attack within the CDN object; if the first device name does not exist in the first origin field, determining that the monitoring result indicates the absence of a loop amplification attack within the CDN object.

[0195] The step of obtaining the first origin path field includes: receiving an origin request sent by the second proxy center; if there is no origin resource in the first device corresponding to the first proxy center, checking whether the first origin path field exists in the origin request; if the first origin path field does not exist in the origin request, adding the name of the first CDN object and the name corresponding to the first proxy center to the header of the origin request to obtain the first origin path field; if the first origin path field exists in the origin request, obtaining the first origin path field.

[0196] The first handling method includes a first origin domain name and a first origin domain name Internet Protocol address (IPA). The handling of a loop amplification attack on the CDN object based on the first handling method sent by the ICP origin server includes: when the first origin domain name is the same as the original origin domain name but the first origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address, sending a first origin domain name resolution request to the scheduling center corresponding to the first proxy center; the scheduling center is used to resolve the first origin domain name based on the first origin domain name resolution request to obtain the resolved origin domain name Internet Protocol address; receiving the resolved origin domain name Internet Protocol address sent by the scheduling center; and handling the loop amplification attack on the CDN object based on the resolved origin domain name Internet Protocol address. The method for handling cyclic amplification attacks on the CDN object based on the resolved origin domain name Internet Protocol address includes: comparing the first origin domain name Internet Protocol address with the resolved origin domain name Internet Protocol address to obtain a first comparison result; handling the cyclic amplification attack on the CDN object if the first comparison result shows that the first origin domain name Internet Protocol address and the resolved origin domain name Internet Protocol address are the same; and handling the cyclic amplification attack on the CDN object based on a second handling method if the first comparison result shows that the first origin domain name Internet Protocol address and the resolved origin domain name Internet Protocol address are different. The second handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0197] The first handling method includes a second origin domain name and a second origin domain name Internet Protocol address. The handling of the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station includes: receiving a third origin domain name sent by the CDN object's management center when the second origin domain name is different from the original origin domain name and the second origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address; and handling the cyclic amplification attack of the CDN object based on the third origin domain name.

[0198] The method for handling a loop amplification attack on the CDN object based on the third origin domain includes: comparing the second origin domain with the third origin domain to obtain a second comparison result; handling the loop amplification attack on the CDN object if the second comparison result shows that the second origin domain and the third origin domain are the same; and handling the loop amplification attack on the CDN object based on a third handling method if the second comparison result shows that the second origin domain and the third origin domain are different. The third handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

[0199] Figure 13 This is a schematic diagram of the structure of the ICP source station equipment provided in the embodiments of this application, with reference to... Figure 13 This application also provides an ICP source station device, which may include: a memory 1310, a transceiver 1320 and a processor 1330; Memory 1310 is used to store computer programs; transceiver 1320 is used to send and receive data under the control of processor 1330; processor 1330 is used to read the computer program in memory 1310 and perform the following operations: The system receives a warning message from the first proxy center regarding a loop amplification attack on a CDN object. The loop amplification attack on the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the loop amplification attack on the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path by which the terminal performs content return to the origin. Based on the aforementioned warning information, a first method for handling cyclic amplification attacks on the CDN object is determined. The first handling method is sent to the first proxy center, which is used to handle the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station.

[0200] Among them, Figure 13 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 1330) and memory (memory 1310). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. A bus interface provides an interface. Transceiver 1320 may be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium. Processor 1330 is responsible for managing the bus architecture and general processing, and memory 1310 may store data used by processor 1330 during operation.

[0201] Optionally, the processor 1330 is also used to perform the following operations: The early warning information includes the distribution domain name, origin domain name, origin path, and CDN object node information. Based on the early warning information, determining the first handling method for a loop amplification attack on the CDN object includes: A cyclic amplification attack handling model is determined for the ICP source station; the cyclic amplification attack handling model for the ICP source station includes multiple handling methods; Based on the distribution domain name, the origin domain name, the origin path, and the CDN object node information, the first processing method is selected from the multiple processing methods.

[0202] Figure 14 This is a schematic diagram of the structure of the electronic device provided in this application, such as... Figure 14 As shown, the electronic device may include: a processor 1410, a communications interface 1420, a memory 1430, and a communication bus 1440, wherein the processor 1410, the communications interface 1420, and the memory 1430 communicate with each other via the communication bus 1440. The processor 1410 can call logical instructions in the memory 1430 to execute steps of a method for handling cyclic amplification attacks, such as: Obtain the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. Based on the judgment result of the first origin path field, the monitoring result of the loop amplification attack against the content delivery network CDN object is determined. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. Upon detecting a cyclic amplification attack on the CDN object, the cyclic amplification attack CAA server sends the warning information corresponding to the cyclic amplification attack on the CDN object to the Internet Content Provider (ICP) origin server; the ICP origin server is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information. Based on the first processing method sent by the ICP origin station, handle the cyclic amplification attack of the CDN object; or, The system receives a warning message from the first proxy center regarding a loop amplification attack on a CDN object. The loop amplification attack on the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the loop amplification attack on the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path by which the terminal performs content return to the origin. Based on the aforementioned warning information, a first method for handling cyclic amplification attacks on the CDN object is determined. The first handling method is sent to the first proxy center, which is used to handle the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station.

[0203] Furthermore, the logical instructions in the aforementioned memory 1430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0204] On the other hand, this application also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer is able to perform the steps of the methods for handling cyclic amplification attacks provided by the above-described methods, such as including: Obtain the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. Based on the judgment result of the first origin path field, the monitoring result of the loop amplification attack against the content delivery network CDN object is determined. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. Upon detecting a cyclic amplification attack on the CDN object, the cyclic amplification attack CAA server sends the warning information corresponding to the cyclic amplification attack on the CDN object to the Internet Content Provider (ICP) origin server; the ICP origin server is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information. Based on the first processing method sent by the ICP origin station, handle the cyclic amplification attack of the CDN object; or, The system receives a warning message from the first proxy center regarding a loop amplification attack on a CDN object. The loop amplification attack on the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the loop amplification attack on the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path by which the terminal performs content return to the origin. Based on the aforementioned warning information, a first method for handling cyclic amplification attacks on the CDN object is determined. The first handling method is sent to the first proxy center, which is used to handle the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station.

[0205] Furthermore, this application also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements steps for performing the methods for handling cyclic amplification attacks provided by the aforementioned methods, including, for example: Obtain the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. Based on the judgment result of the first origin path field, the monitoring result of the loop amplification attack against the content delivery network CDN object is determined. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. Upon detecting a cyclic amplification attack on the CDN object, the cyclic amplification attack CAA server sends the warning information corresponding to the cyclic amplification attack on the CDN object to the Internet Content Provider (ICP) origin server; the ICP origin server is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information. Based on the first processing method sent by the ICP origin station, handle the cyclic amplification attack of the CDN object; or, The system receives a warning message from the first proxy center regarding a loop amplification attack on a CDN object. The loop amplification attack on the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the loop amplification attack on the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path by which the terminal performs content return to the origin. Based on the aforementioned warning information, a first method for handling cyclic amplification attacks on the CDN object is determined. The first handling method is sent to the first proxy center, which is used to handle the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station.

[0206] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0207] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0208] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.

Claims

1. A method for dealing with cyclic amplification attacks, characterized in that, Applied to the first agent center, including: Obtain the first origin path field; the first origin path field is used to characterize the path through which the terminal retrieves content from the origin. Based on the judgment result of the first origin path field, the monitoring result of the loop amplification attack against the content delivery network CDN object is determined. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. Upon detecting a cyclic amplification attack on the CDN object, the cyclic amplification attack CAA server sends the warning information corresponding to the cyclic amplification attack on the CDN object to the Internet Content Provider (ICP) origin server; the ICP origin server is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information. Based on the first processing method sent by the ICP origin station, the cyclic amplification attack on the CDN object is handled.

2. The method for dealing with cyclic amplification attacks according to claim 1, characterized in that, The determination of the monitoring results of a loop amplification attack against a Content Delivery Network (CDN) object based on the judgment result of the first origin path field includes: If the judgment result is that the name of the first CDN object does not exist in the first origin path field, it is determined that the monitoring result is that there is no loop amplification attack between the CDN objects; If the judgment result indicates that the name of the first CDN object exists in the first origin path field, the monitoring result is determined based on the number of times the name of the first CDN object appears and the location where the name of the first CDN object appears.

3. The method for dealing with cyclic amplification attacks according to claim 2, characterized in that, The determination of the monitoring result based on the number of times the name of the first CDN object appears and the position where the name of the first CDN object appears includes: If the name of the first CDN object appears twice and the name of the second CDN object exists between the two occurrences of the name of the first CDN object, the monitoring result is determined to be a loop amplification attack between the CDN objects. If the name of the first CDN object appears once and the position of the name of the first CDN object is at the end of the first origin path field, the monitoring result is determined based on the first device name corresponding to the first proxy center.

4. The method for dealing with cyclic amplification attacks according to claim 3, characterized in that, The step of determining the monitoring result based on the first device name corresponding to the first agent center includes: If the first device name is present in the first origin field, the monitoring result is determined to be a loop amplification attack inside the CDN object; If the first device name is not found in the first origin field, the monitoring result is determined to be that there is no loop amplification attack inside the CDN object.

5. The treatment method according to any one of claims 1 to 4, characterized in that, The process of obtaining the first origin path field includes: Receive origin requests sent by the second proxy center; If there is no origin resource in the first device corresponding to the first proxy center, check whether the first origin path field exists in the origin request; If the first origin path field is not present in the origin request, the name of the first CDN object and the name corresponding to the first proxy center are added to the header of the origin request to obtain the first origin path field. If the first origin path field exists in the origin request, obtain the first origin path field.

6. The method for dealing with cyclic amplification attacks according to any one of claims 1 to 4, characterized in that, The first handling method includes the first origin domain name and the first origin domain name Internet Protocol address. The handling of the cyclic amplification attack on the CDN object based on the first handling method sent by the ICP origin server includes: If the first origin domain name is the same as the original origin domain name but the first origin domain name Internet Protocol address is different from the original origin domain name Internet Protocol address, a first origin domain name resolution request is sent to the scheduling center corresponding to the first proxy center; the scheduling center is used to resolve the first origin domain name based on the first origin domain name resolution request to obtain the resolved origin domain name Internet Protocol address. Receive the resolved origin domain name Internet Protocol address sent by the scheduling center; Based on the resolved origin domain name Internet Protocol address, handle the loop amplification attack on the CDN object.

7. The method for dealing with cyclic amplification attacks according to claim 6, characterized in that, The handling of loop amplification attacks on the CDN object based on the resolved origin domain Internet Protocol address includes: The first origin domain name Internet Protocol address is compared with the resolved origin domain name Internet Protocol address to obtain a first comparison result; If the first comparison result shows that the first origin domain name Internet Protocol address is consistent with the resolved origin domain name Internet Protocol address, then handle the loop amplification attack of the CDN object. If the first comparison result shows that the first origin domain name Internet Protocol address is inconsistent with the resolved origin domain name Internet Protocol address, the CDN object is dealt with based on the second handling method; the second handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

8. The method for dealing with cyclic amplification attacks according to any one of claims 1 to 4, characterized in that, The first handling method includes a second origin domain name and a second origin domain name Internet Protocol address. The handling of cyclic amplification attacks on the CDN object based on the first handling method sent by the ICP origin server includes: In the case where the second origin domain name is different from the original origin domain name and the Internet Protocol address of the second origin domain name is different from the Internet Protocol address of the original origin domain name, the third origin domain name sent by the CDN object's management center is received. Based on the third origin domain, handle the loop amplification attack on the CDN object.

9. The method for dealing with cyclic amplification attacks according to claim 8, characterized in that, The handling of loop amplification attacks on the CDN object based on the third origin domain includes: The second origin domain name is compared with the third origin domain name to obtain a second comparison result; If the second comparison result shows that the second origin domain name is the same as the third origin domain name, then handle the loop amplification attack on the CDN object. If the second comparison result shows that the second origin domain name and the third origin domain name are inconsistent, the CDN object is dealt with based on the third handling method to handle the loop amplification attack; the third handling method is obtained by the CAA server feeding back abnormal information to the ICP origin station.

10. A method for dealing with cyclic amplification attacks, characterized in that, The application of ICP source station is characterized by: The system receives a warning message from the first proxy center regarding a loop amplification attack on a CDN object. The loop amplification attack on the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field, which monitors the loop amplification attack on the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path by which the terminal performs content return to the origin. Based on the aforementioned warning information, a first method for handling cyclic amplification attacks on the CDN object is determined. The first handling method is sent to the first proxy center, which is used to handle the cyclic amplification attack of the CDN object based on the first handling method sent by the ICP origin station.

11. The method for dealing with cyclic amplification attacks according to claim 10, characterized in that, The early warning information includes the distribution domain name, origin domain name, origin path, and CDN object node information. Based on the early warning information, determining the first handling method for a loop amplification attack on the CDN object includes: A cyclic amplification attack handling model is determined for the ICP source station; the cyclic amplification attack handling model for the ICP source station includes multiple handling methods; Based on the distribution domain name, the origin domain name, the origin path, and the CDN object node information, the first processing method is selected from the multiple processing methods.

12. A device for dealing with cyclic amplification attacks, characterized in that, include: The first acquisition module is used to acquire the first source path field; The first origin path field is used to characterize the path through which the terminal retrieves content from the origin. The monitoring module is used to determine the monitoring result of a loop amplification attack against a content delivery network (CDN) object based on the judgment result of the first origin path field. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first sending module is used to send the warning information corresponding to the cyclic amplification attack of the CDN object to the ICP origin station through the cyclic amplification attack CAA server when the cyclic amplification attack of the CDN object is detected. The ICP origin station is used to determine the first handling method for the cyclic amplification attack of the CDN object based on the early warning information; The processing module is used to process the cyclic amplification attack on the CDN object based on the first processing method sent by the ICP origin station.

13. A device for dealing with cyclic amplification attacks, characterized in that, include: The first receiving module is used to receive the warning information corresponding to the cyclic amplification attack of the CDN object sent by the first proxy center. The cyclic amplification attack of the CDN object is obtained by the first proxy center based on the judgment result of the first origin path field and by monitoring the cyclic amplification attack of the content delivery network CDN object. The judgment result is used to indicate whether the name of the first CDN object corresponding to the first proxy center exists in the first origin path field. The first origin path field is used to indicate the path of the terminal to perform content origin. The determination module is used to determine the first handling method for the cyclic amplification attack on the CDN object based on the warning information; The second sending module is used to send the first processing method to the first proxy center, and the first proxy center is used to process the cyclic amplification attack of the CDN object based on the first processing method sent by the ICP origin station.

14. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the method for handling cyclic amplification attacks as described in any one of claims 1 to 9 or 10-11.

15. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the method for handling cyclic amplification attacks as described in any one of claims 1 to 9 or 10-11.

16. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the method for handling cyclic amplification attacks as described in any one of claims 1 to 9 or 10-11.

Citation Information

Patent Citations

  • Content looping detection processing method and device and computer readable storage medium

    CN111404761A

  • Loop detection method and device

    CN117176640A

  • Live broadcast source returning method and device

    CN117768662A

  • Source return test method, computer equipment and storage medium

    CN121012767A

  • Method of request routing re-direction with loop detection and prevention

    US20140156822A1