A method and device for analyzing feature information

By analyzing the five-tuple information and characteristic values of data packets in units of sessions, combined with the IPFIX protocol extension indicators, the problem of incomplete network session analysis in the existing technology is solved, and effective detection of network session attacks is achieved.

CN111835708BActive Publication Date: 2025-07-08HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202010460439.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2014-12-30
Publication Date
2025-07-08
Estimated Expiration
2034-12-30

Smart Images

  • Figure CN111835708B_ABST
    Figure CN111835708B_ABST
Patent Text Reader

Abstract

The embodiment of the present invention provides a method and device for analyzing characteristic information in a groundbreaking manner, which obtains multiple data packets in a session to be analyzed; extracts a characteristic value of a preset session characteristic from each of the data packets; and obtains the session characteristic information of the session to be analyzed by counting the characteristic value. In the embodiment of the present invention, the session is used as the basic analysis unit to achieve an overall analysis of the session, and obtains session characteristic information that can fully reflect the session. The embodiment of the present invention also provides a method and system for detecting network attacks based on the session characteristic information of the session to be analyzed obtained within a preset time interval, which solves the problem in the prior art that the characteristic information of the data stream cannot detect session attacks in the network, and achieves effective detection of session attacks in the network, thereby improving the completeness of network attack detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and in particular, to a method and device for analyzing characteristic information. Background Art

[0002] Currently, data transmission in the Internet is generally described by data streams. A data stream refers to a sequence of data packets that are read once in a specified order. The five-tuple information of multiple data packets belonging to the same data stream is the same, and the five-tuple information includes the source Internet Protocol (IP) address, the destination IP address, the source port number, the destination port number, and the transport layer protocol number.

[0003] By analyzing the information carried by the data packet sequence in a data stream, the characteristic information of the data stream can be obtained. By comprehensively analyzing the characteristic information of multiple data streams, the operating status of data transmission in the network can be understood. For example: by analyzing the duration of data streams in the network, the network data transmission speed can be understood; by analyzing the packet length of data streams in the network, network traffic billing can be performed; by analyzing information such as the IP addresses of data streams in the network, network security detection can be performed.

[0004] It can be seen that those skilled in the art use data streams as the basic analysis unit when analyzing the network operating status, but only partial network operating status can be analyzed based on the characteristic information of data streams. Summary of the Invention

[0005] Embodiments of the present invention provide a method and device for analyzing characteristic information, which use sessions as the basic analysis unit to obtain session characteristic information, and solve the problem that only partial network operating status can be analyzed based on the characteristic information of data streams.

[0006] A first aspect of an embodiment of the present invention provides a method for analyzing characteristic information, the method including:

[0007] Obtaining multiple data packets in a session to be analyzed;

[0008] Extracting the characteristic values of preset session characteristics from each of the data packets;

[0009] Statistically analyzing the characteristic values to obtain the session characteristic information of the session to be analyzed.

[0010] In a first possible implementation manner of the first aspect of the embodiment of the present invention, before extracting the characteristic values of preset session characteristics from each of the data packets, it includes:

[0011] Obtaining the session characteristic metrics configured in the IP Flow Information Export (IPFIX) protocol as the preset session characteristics.

[0012] Combined with the first possible implementation manner of the first aspect of the embodiments of the present invention, in the second possible implementation manner, the method further includes:

[0013] Output the feature information of the session to be analyzed in the standard format of the IPFIX protocol.

[0014] Combined with the first aspect to the second possible implementation manner of the first aspect of the embodiments of the present invention, in the third possible implementation manner, the obtaining of multiple data packets in the session to be analyzed includes:

[0015] Obtain the five-tuple information of each data packet respectively from all the received data packets;

[0016] Based on the five-tuple information of each data packet, obtain multiple data packets of the session to be analyzed from all the received data packets.

[0017] Combined with the first aspect to the second possible implementation manner of the first aspect of the embodiments of the present invention, in the fourth possible implementation manner, before obtaining multiple data packets in the session to be analyzed, it further includes:

[0018] Perform session sampling on all the received data packets to obtain data packets of multiple sampled sessions;

[0019] The obtaining of multiple data packets in the session to be analyzed includes:

[0020] Obtain multiple data packets of the session to be analyzed from the data packets of the multiple sampled sessions.

[0021] Combined with the fourth possible implementation manner of the first aspect of the embodiments of the present invention, in the fifth possible implementation manner, the obtaining of the data packets of the session to be analyzed from the data packets of the multiple sampled sessions includes:

[0022] Obtain the five-tuple information of each data packet respectively from the data packets of the multiple sessions;

[0023] Based on the five-tuple information of each data packet, obtain the data packets of the session to be analyzed from the data packets of the multiple sessions.

[0024] Combined with the fourth possible implementation manner of the first aspect of the embodiments of the present invention, in the sixth possible implementation manner, the performing of session sampling on all the received data packets includes:

[0025] Parse the five-tuple information of each received data packet;

[0026] Calculate the positive hash value and the reverse hash value of the received data packet by using the quintuple information. The positive hash value is the hash value calculated by using the quintuple information of the received data packet as the input. The reverse hash value is the hash value calculated by using, as the input, the quintuple information of the received data packet with the source IP address and the destination IP address swapped and the source port number and the destination port number swapped.

[0027] Calculate a first remainder obtained by dividing the positive hash value by a preset sampling parameter in a preset session sampling template, and calculate a second remainder obtained by dividing the reverse hash value by the preset sampling parameter in the session sampling template. The preset sampling parameter is the denominator of the sampling ratio in the session sampling template.

[0028] Determine whether the first remainder or the second remainder is the preset sampling remainder in the session sampling template.

[0029] When the first remainder or the second remainder is the preset sampling remainder in the session sampling template, sample the received data packet.

[0030] A second aspect of the embodiments of the present invention provides a network attack detection method, and the method includes:

[0031] Analyze the session feature information of all sessions to be analyzed obtained within a preset time interval. The session feature information is analyzed by using the method described in the first aspect to the sixth possible implementation manner of the first aspect of the embodiments of the present invention.

[0032] Detect a network session attack within the preset time interval according to the session feature information.

[0033] In the first possible implementation manner of the second aspect of the embodiments of the present invention, the detecting a network session attack within the preset time interval according to the session feature information includes:

[0034] According to the session feature information, count a first proportion of incomplete sessions among all sessions to be analyzed obtained within the preset time interval.

[0035] Determine whether the first proportion exceeds a first preset threshold.

[0036] When the first proportion of incomplete sessions exceeds the first preset threshold, identify a network session attack within the preset time interval.

[0037] Combined with the first possible implementation manner of the second aspect of the embodiments of the present invention, in the second possible implementation manner,

[0038] The session feature information includes the number of uplink data packets and the number of downlink data packets.

[0039] The incomplete session is a session to be analyzed where the number of uplink data packets is greater than 1 and the number of downlink data packets is 0.

[0040] Combined with the first possible implementation manner of the second aspect of the embodiments of the present invention, in the third possible implementation manner,

[0041] The session feature information includes Transmission Control Protocol (TCP) flag bits;

[0042] The incomplete session is a session to be analyzed with incomplete TCP flag bits.

[0043] In the fourth possible implementation manner of the second aspect of the embodiments of the present invention,

[0044] The session feature information includes the number of echo packets and the number of echo reply packets in Internet Control Message Protocol (ICMP) sessions;

[0045] The detecting of network session attacks within the preset time interval according to the session feature information includes:

[0046] Statistically calculate a second ratio of echo packets to echo reply packets in the obtained ICMP sessions within the preset time interval according to the session feature information;

[0047] Determine whether the second ratio is within a preset numerical range;

[0048] When the second ratio is not within the preset numerical range, identify the ICMP session attack within the preset time interval.

[0049] In the fifth possible implementation manner of the second aspect of the embodiments of the present invention, the detecting of network session attacks within the preset time interval according to the session feature information includes:

[0050] Statistically calculate the number of denial-of-service sessions within the preset time interval according to the session feature information, where the denial-of-service session is the session to be analyzed that contains Hypertext Transfer Protocol (HTTP) error code information in the session feature information;

[0051] Determine whether the number of denial-of-service sessions exceeds a second preset threshold;

[0052] When the number of denial-of-service sessions exceeds the second preset threshold, identify the CC session attack within the preset event interval.

[0053] In the sixth possible implementation manner of the embodiments of the present invention, the detecting of network session attacks within the preset time interval according to the session feature information includes:

[0054] Determine whether the session feature information of each of the to-be-analyzed sessions collected within the preset time interval includes session fragmentation exception information, where the session fragmentation exception information includes any one or more of incomplete fragmentation, overlapping fragmentation, and incorrect fragmentation flag bits;

[0055] When the session feature information of the to-be-analyzed session includes session fragmentation exception information, identify the to-be-analyzed session as a fragmentation attack session within the preset time interval.

[0056] Combined with the second aspect to the sixth possible implementation manner of the second aspect of the present invention, in the seventh possible implementation manner, the method further includes:

[0057] When a network session attack within the preset time interval is detected, generate an attack event according to the session feature information of the to-be-analyzed session;

[0058] Generate an attack suppression strategy according to the attack event.

[0059] Combined with the seventh possible implementation manner of the second aspect of the present invention, in the eighth possible implementation manner, the method further includes:

[0060] Identify the attack source device, attack service, and attacked device according to the attack event.

[0061] Combined with the second aspect to the eighth possible implementation manner of the second aspect of the present invention, in the ninth possible implementation manner, the session feature information adopts the standard output format of the IPFIX protocol.

[0062] The third aspect of the embodiments of the present invention provides a feature information analysis device, and the device includes:

[0063] A first acquisition unit, configured to acquire multiple data packets in the to-be-analyzed session;

[0064] An extraction unit, configured to extract the feature values of preset session features from each of the data packets;

[0065] A statistics unit, configured to count the feature values to obtain the session feature information of the to-be-analyzed session.

[0066] In the first possible implementation manner of the third aspect of the embodiments of the present invention, the device further includes:

[0067] A second acquisition unit, configured to acquire the session features configured in the IPFIX protocol as preset features.

[0068] Combined with the first possible implementation manner of the third aspect of the embodiments of the present invention, in the second possible implementation manner, the device further includes:

[0069] An output unit, configured to output the feature information of the session to be analyzed in the standard format of the IPFIX protocol.

[0070] Combined with the third aspect to the second possible implementation manner of the third aspect of the embodiments of the present invention, in the third possible implementation manner, the first obtaining unit includes:

[0071] A first obtaining subunit, configured to respectively obtain the five-tuple information of each data packet from all received data packets;

[0072] A second obtaining subunit, configured to obtain the data packets of the session to be analyzed from all received data packets based on the five-tuple information of each data packet.

[0073] Combined with the third aspect to the second possible implementation manner of the third aspect of the embodiments of the present invention, in the fourth possible implementation manner, the apparatus further includes:

[0074] A sampling unit, configured to perform session sampling on all received data packets to obtain data packets of multiple sampled sessions;

[0075] The first obtaining unit is specifically configured to obtain multiple data packets of the session to be analyzed from the data packets of the multiple sampled sessions.

[0076] Combined with the fourth possible implementation manner of the embodiments of the present invention, in the fifth possible implementation manner, the first obtaining unit includes:

[0077] A third obtaining subunit, configured to respectively obtain the five-tuple information of each data packet from the data packets of the multiple sampled sessions;

[0078] A fourth obtaining subunit, configured to obtain the data packets of the session to be analyzed from the data packets of the multiple sampled sessions based on the five-tuple information of each data packet.

[0079] Combined with the fourth possible implementation manner of the embodiments of the present invention, in the sixth possible implementation manner, the sampling unit includes:

[0080] A parsing subunit, configured to parse the five-tuple information of each received data packet;

[0081] A first calculating subunit, configured to calculate a positive hash value and a reverse hash value of the received data packet by using the five-tuple information, where the positive hash value is a hash value calculated by using the five-tuple information of the received data packet as an input, and the reverse hash value is a hash value calculated by using, after swapping the source IP address and the destination IP address, and swapping the source port number and the destination port number in the five-tuple information of the received data packet, as an input;

[0082] A second calculation subunit, configured to calculate a first remainder obtained by dividing the positive hash value by a preset sampling parameter in a preset session sampling template, and calculate a second remainder obtained by dividing the negative hash value by the preset sampling parameter in the session sampling template, where the preset sampling parameter is the denominator of a sampling ratio in the session sampling template;

[0083] A judgment subunit, configured to judge whether the first remainder or the second remainder is a preset sampling remainder in the session sampling template;

[0084] A sampling subunit, configured to sample the received data packet when the first remainder or the second remainder is the preset sampling remainder in the session sampling template.

[0085] A fourth aspect of an embodiment of the present invention provides a network attack detection system, where the system includes:

[0086] The feature information analysis device described in the third aspect to the sixth possible implementation manners of the third aspect of the embodiment of the present invention, configured to analyze session feature information of all sessions to be analyzed obtained within a preset time interval;

[0087] A detection device, configured to detect a network session attack within the preset time interval according to the session feature information.

[0088] In a first possible implementation manner of the fourth aspect of the embodiment of the present invention, the detection device includes:

[0089] A first statistics unit, configured to count a first ratio of incomplete sessions in all sessions to be analyzed obtained within the preset time interval according to the session feature information;

[0090] A first judgment unit, configured to judge whether the first ratio exceeds a first preset threshold;

[0091] A first identification unit, configured to identify a network session attack within the preset time interval when the first ratio of incomplete sessions exceeds the first preset threshold.

[0092] Combined with the first possible implementation manner of the fourth aspect of the embodiment of the present invention, in a second possible implementation manner, the session feature information includes the number of bytes of an uplink data packet and the number of bytes of a downlink data packet;

[0093] The incomplete session is a session to be analyzed in which the number of uplink data packets is greater than 1 and the number of downlink data packets is 0.

[0094] Combined with the first possible implementation manner of the fourth aspect of the embodiments of the present invention, in the third possible implementation manner, the session feature information includes Transmission Control Protocol (TCP) flag bits; the incomplete session is the session to be analyzed with incomplete TCP flag bits.

[0095] In the fourth possible implementation manner of the fourth aspect of the embodiments of the present invention, the session feature information includes the number of echo requests and the number of echo replies in Internet Control Message Protocol (ICMP) sessions;

[0096] The detection device includes:

[0097] A second statistical unit, configured to count a second ratio of echo requests and echo replies in the acquired ICMP sessions within a preset time interval according to the session feature information;

[0098] A second determination unit, configured to determine whether the second ratio is within a preset numerical range;

[0099] A second identification unit, configured to identify an ICMP session attack within the preset time interval when the second ratio is not within the preset numerical range.

[0100] In the fifth possible implementation manner of the embodiments of the present invention, the detection device includes:

[0101] A third statistical unit, configured to count the number of denial-of-service sessions within the preset time interval according to the session feature information, where the denial-of-service session is the session to be analyzed whose session feature information includes HyperText Transfer Protocol (HTTP) error code information;

[0102] A third determination unit, configured to determine whether the number of denial-of-service sessions exceeds a second preset threshold;

[0103] A third identification unit, configured to identify a CC session attack within the preset event interval when the number of denial-of-service sessions exceeds the second preset threshold.

[0104] In the sixth possible implementation manner of the embodiments of the present invention, the detection device includes:

[0105] A fourth determination unit, configured to determine whether the session feature information of each session to be analyzed collected within the preset time interval includes session fragmentation anomaly information, where the session fragmentation anomaly information includes any one or more of incomplete fragmentation, overlapping fragmentation, and incorrect fragmentation flag bits;

[0106] A fourth identification unit, configured to identify the session to be analyzed as a fragmentation attack session within the preset time interval when the session feature information of the session to be analyzed includes session fragmentation anomaly information.

[0107] In combination with the third aspect to the sixth possible implementation manner of the third aspect of the embodiment of the present invention, in a seventh possible implementation manner, the system further includes:

[0108] The defense device is used to generate an attack event according to the session feature information of the session to be analyzed when a network session attack is detected within the preset time interval; and generate an attack suppression strategy according to the attack event.

[0109] In conjunction with the seventh possible implementation manner of the third aspect of the embodiment of the present invention, in an eighth possible implementation manner, the system further includes:

[0110] The attack identification device is used to identify the attack source device, the attack service and the attacked device according to the attack event.

[0111] In combination with the third aspect to the eighth possible implementation manner of the third aspect of the embodiment of the present invention, in a ninth possible implementation manner, the session feature information adopts a standard output format of the IPFIX protocol.

[0112] It can be seen from the above technical solution that the present invention has the following beneficial effects:

[0113] The embodiment of the present invention provides a method and device for analyzing characteristic information in a groundbreaking manner, which obtains multiple data packets in a session to be analyzed; extracts a characteristic value of a preset session characteristic from each of the data packets; and obtains session characteristic information of the session to be analyzed by counting the characteristic values. In the embodiment of the present invention, the session is taken as the basic analysis unit, and an overall analysis of the session is achieved to obtain session characteristic information that can fully reflect the session.

[0114] The embodiments of the present invention also provide a network attack detection method and system, which detects network session attacks within a preset time interval based on session feature information of the session to be analyzed obtained within the preset time interval, solves the problem in the prior art that session attacks in the network cannot be detected based on feature information of the data stream, realizes effective detection of session attacks in the network, and improves the completeness of network attack detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0115] Figure 1 A flow chart of a feature information analysis method provided by an embodiment of the present invention;

[0116] Figure 2 A schematic diagram of the IPFIX protocol message format provided by an embodiment of the present invention;

[0117] Figure 3 A flow chart of a network attack detection method provided by an embodiment of the present invention;

[0118] Figure 4A schematic diagram of the structure of a feature information analysis device provided by an embodiment of the present invention;

[0119] Figure 5 A schematic diagram of the network attack detection system structure provided by an embodiment of the present invention;

[0120] Figure 6 A schematic diagram of the hardware structure of a feature information analysis device provided in an embodiment of the present invention;

[0121] Figure 7 A schematic diagram of the hardware structure of a network attack detection system provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0122] In the prior art, when analyzing the operation status of a network, the data stream is mainly used as the basic unit to obtain multiple data streams transmitted in the network, and the characteristic information of the obtained multiple data streams is comprehensively analyzed to obtain the operation status of the network. The analysis based on the data stream cannot analyze the connection probability of the network, cannot detect session attacks on the network, and cannot analyze abnormal sessions on the network.

[0123] In order to solve the above technical problems, the embodiments of the present invention provide a method and device for analyzing session characteristic information in a pioneering manner, taking the session as the basic analysis unit, and providing important data information for realizing a comprehensive analysis of the operation status of the network, especially a comprehensive analysis of session attacks in the network.

[0124] To make the objectives, technical solutions and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are described in detail below with reference to the accompanying drawings.

[0125] Figure 1 A flow chart of a feature information analysis method provided by an embodiment of the present invention, the method comprising:

[0126] S101: Acquire multiple data packets in a session to be analyzed.

[0127] In a network application, a session refers to the communication interaction between two network devices within a specific non - interrupted operation time. A session can be established between a first network device and a second network device, so as to transmit multiple data packets between the first network device and the second device. The five - tuple information of multiple data packets of the same session has the following characteristics: the source IP address of multiple data packets of the same session is the IP address of the first network device or the IP address of the second network device, the destination IP address of multiple data packets of the same session is the IP address of the first network device or the IP address of the second network device, the source port number of multiple data packets of the same session is the port number of the first network device or the port number of the second network device, the destination port number of multiple data packets of the same session is the port number of the first network device or the port number of the second network device, and the transport layer protocol numbers used by multiple data packets of the same session are the same.

[0128] That is to say, the five-tuple information of the data packet sent from the first network device to the second network device is (the IP address of the first network device, the port number of the first network device, the IP address of the second network device, the port number of the second network device, the transport layer protocol number). That is, the source IP address of the data packet sent from the first network device to the second network device is the IP address of the first network device, the source port number of the data packet sent from the first network device to the second network device is the port number of the first network device, the destination IP address of the data packet sent from the first network device to the second network device is the IP address of the second network device, the destination port number of the data packet sent from the first network device to the second network device is the port number of the second network device, and the transport layer protocol number of the data packet sent from the first network device to the second network device is the number of the transport layer protocol used to transmit these data packets between the first network device and the second network device. The five-tuple information of the data packet sent from the second network device to the first network device is (the IP address of the second network device, the port number of the second network device, the IP address of the first network device, the port number of the first network device, the transport layer protocol number). That is, the source IP address of the data packet sent from the second network device to the first network device is the IP address of the second network device, the source port number of the data packet sent from the second network device to the first network device is the port number of the second network device, the destination IP address of the data packet sent from the second network device to the first network device is the IP address of the first network device, the destination port number of the data packet sent from the second network device to the first network device is the port number of the first network device, and the transport layer protocol number of the data packet sent from the second network device to the first network device is the number of the transport layer protocol used to transmit these data packets between the first network device and the second network device. The transport layer protocol numbers carried in the data packet sent from the first network device to the second network device and the data packet sent from the second network device to the first network device are the same.

[0129] In the embodiments of the present invention, there are at least the following two possible implementation manners for obtaining multiple data packets in the session to be analyzed:

[0130] In the first possible implementation manner, the five-tuple information of each data packet is respectively obtained from all the received data packets; based on the five-tuple information of each data packet, multiple data packets of the session to be analyzed are obtained from all the received data packets.

[0131] For all received data packets, parse the five-tuple information of each data packet, group all the received data packets based on the five-tuple information, divide the multiple data packets sent from the first network device to the second network device and the multiple data packets sent from the second network device to the first network device into one group, and multiple data packets in each group belong to the same session, and finally obtain multiple sessions. Each session refers to the communication between two network devices. In practical applications, at least one of the obtained sessions can be selected as the session to be analyzed for analysis to obtain the session feature information of the session to be analyzed.

[0132] When obtaining multiple data packets of the session to be analyzed, for a session to be analyzed, the two communication parties of this session are the first network device and the second network device. When a data packet uses the IP address of the first network device as the source IP address, the IP address of the second network device as the destination IP address, the port number of the first network device as the source port number, and the port number of the second network device as the destination port number, this data packet belongs to the session to be analyzed. Based on the five-tuple information of the received data packets, the data packets of the session to be analyzed can be obtained.

[0133] In the second possible implementation manner,

[0134] Perform session sampling on all the received data packets to obtain data packets of multiple sampled sessions;

[0135] The obtaining of multiple data packets in the session to be analyzed includes:

[0136] Obtain multiple data packets of the session to be analyzed from the data packets of the multiple sampled sessions.

[0137] Generally, the number of received data packets is very large. Usually, sampling analysis is performed on all the received data packets. Since the embodiment of the present invention provides a session feature information analysis method, therefore, session sampling is performed on all the received data packets to ensure that all the data packets belonging to the sampled sessions among all the received data packets can be sampled, so as to realize the analysis of session-based feature information.

[0138] Similar to the first possible implementation manner, the obtaining of the data packets of the session to be analyzed from the data packets of the multiple sampled sessions includes:

[0139] Respectively obtain the five-tuple information of each data packet from the data packets of the multiple sessions;

[0140] Based on the five-tuple information of each data packet, obtain the data packets of the session to be analyzed from the data packets of the multiple sessions.

[0141] In the first possible implementation manner, the data packets of the session to be analyzed are obtained from all received data packets. In the second possible implementation manner, the data packets of the session to be analyzed are obtained from the data packets of the multiple sampled sessions.

[0142] For all sampled data packets, parse the five-tuple information of each sampled data packet, group all sampled data packets based on the five-tuple information, divide multiple data packets sent from the first network device to the second network device and multiple data packets sent from the second network device to the first network device into one group. Multiple data packets in each group belong to the same session, and each session refers to the communication between two network devices. In practical applications, at least one of the obtained sampled sessions can be selected as the session to be analyzed for analysis to obtain the session feature information of the session to be analyzed.

[0143] In one embodiment, to ensure that all data packets belonging to the sampled session can be sampled, the session sampling of all received data packets includes:

[0144] Parse the five-tuple information of each received data packet;

[0145] Calculate the positive hash value and the reverse hash value of the received data packet using the five-tuple information. The positive hash value is the hash value calculated with the five-tuple information of the received data packet as the input, and the reverse hash value is the hash value calculated with the source IP address and the destination IP address in the five-tuple information of the received data packet swapped and the source port number and the destination port number swapped as the input.

[0146] Calculate the first remainder obtained by dividing the positive hash value by the preset sampling parameter in the preset session sampling template, and calculate the second remainder obtained by dividing the reverse hash value by the preset sampling parameter in the session sampling template. The preset sampling parameter is the denominator of the sampling ratio in the session sampling template.

[0147] Judge whether the first remainder or the second remainder is the preset sampling remainder in the session sampling template;

[0148] When the first remainder or the second remainder is the preset sampling remainder in the session sampling template, sample the received data packet.

[0149] Parse each received data packet to obtain the five-tuple information of the received data packet. Arrange the source IP address, destination IP address, source port number, destination port number, and transport layer protocol number in a preset order to form a string, which is an input value of the hash function, and calculate the positive hash value; swap the positions of the source IP address and the destination IP address, and swap the positions of the source port number and the destination port number, while keeping the position of the transport layer protocol number unchanged, and arrange to get another string to form another input of the hash function, and calculate the negative hash value. Obtain the sampling ratio m / n in the preset session sampling template, calculate the first remainder of the positive hash value divided by the denominator m of the sampling ratio, and calculate the second remainder of the negative hash value divided by the denominator m of the sampling ratio. Determine whether the first remainder or the second remainder is the sampling remainder in the session sampling template. When the first remainder or the second remainder is the sampling remainder, sample the data packet. Among them, the preset session sampling template includes the sampling ratio m / n and m sampling remainders. The sampling ratio determines the proportion of the data packets collected from a large number of received data packets, and the sampling remainder determines sampling based on the session.

[0150] For example: If the sampling ratio in the session sampling template is 3 / 1000, then the denominator of the sampling ratio is 1000. Calculate the first remainder obtained by dividing the positive hash value by 1000, and calculate the second remainder obtained by dividing the negative hash value by 1000. Then the value ranges of the first remainder and the second remainder are from 0 to 999. When the sampling ratio is 3 / 1000, select three numbers from 0 to 999 as the sampling remainders in the session sampling template. Suppose three numbers 5, 386, and 857 are selected as the sampling remainders. Then when the first remainder is the sampling remainder or the second remainder is preset as the sampling remainder, sample the data packet. Of course, more than 3 numbers can also be selected as the sampling remainders.

[0151] It can be understood that multiple data packets sent from the first network device to the second network device and multiple data packets sent from the second network device to the first network device are divided into a group. The multiple data packets in each group belong to the same session, and each session refers to the communication between two network devices. For different data packets in the same session, calculating the hash value based on the five-tuple information can obtain the same set of hash values, and thus the same set of remainders can be calculated. That is, it is possible to extract all the data packets in a session.

[0152] For example: If the positive hash value calculated from the five-tuple information of the data packets in a session is A, the negative hash value is B, the first remainder obtained by dividing by the denominator of the sampling ratio is C, and the second remainder is D. Then the hash values calculated from the five-tuple information of other data packets in this session are also A and B. It's just that for some data packets, the positive hash value is A and the negative hash value is B, while for some other data packets, the positive hash value is B and the negative hash value is A, and the remainders obtained by dividing by the denominator of the sampling ratio are also C and D. When C or D is the sampling remainder in the preset session sampling template, sample this data packet, and thus other data packets in this session will also be sampled; when both C and D are not the sampling remainders in the preset session sampling template, this data packet will not be sampled, and thus other data packets in this session will not be sampled either.

[0153] Since the distribution of the five-tuple information of data packets is very uneven in different regions, several bits that are evenly distributed in different regions can be separately selected from the five-tuple information to form the input string of the hash function, so as to achieve uniform session sampling as much as possible. For example: Select the string composed of M consecutive bits of the IP address, the string composed of N consecutive bits of the port number, and the string composed of P consecutive bits of the transport layer protocol number from the five-tuple information, and obtain a string of M + N + P bits as the input string of the hash function, where M, N, and P are integers greater than 0. In practical applications, the CRC16 hash function can be selected to calculate the hash value.

[0154] S102: Extract the feature values of the preset session features from each of the said data packets.

[0155] Analyze the multiple data packets of the session to be analyzed and extract the feature values of the preset session features. Extract the feature values of the preset session features from each data packet in a session. By analyzing the feature values of the preset session features extracted from all data packets, the session feature information of the preset session features of this session can be obtained. When analyzing the session feature analysis of the preset session features of a session, it is necessary to use the feature values of the preset session features extracted from all data packets in this session as the analysis basis, and take the feature values of the preset session features carried in all data packets in the session as a whole. Analyzing only the feature values of the preset session features carried in a part of the data packets in a session cannot obtain the session feature information of the preset session features of this session.

[0156] For example, the preset session features may include one or more of the following: the number of uplink data packets of the session, the number of downlink data packets of the session, the number of Transmission Control Protocol (TCP) session flag bits for each session, the reason for session termination, the maximum data packet length, the minimum data packet length, the uplink message transmission speed of the session, the downlink message transmission speed, the number of echo requests and echo response messages in an Internet Control Message Protocol (ICMP) session, etc. It should be noted here that in addition to the preset session features illustrated above, there are many other preset session features with the session as the basic analysis unit. The preset session features may be session feature indicators selected from the session feature indicators extended from the IPFIX protocol according to actual needs, or features set by users according to actual needs, which will not be elaborated here.

[0157] In one embodiment, before extracting the feature value of the preset session feature from each of the data packets, it includes:

[0158] Obtaining the session feature indicators configured in the IPFIX protocol for IP data stream information output as the preset session features.

[0159] The preset session features are the session features configured in the IP Flow Information Export (IPFIX) protocol. IPFIX is a standard protocol for flow information measurement in the network published by the Internet Engineering Task Force (IETF). The IPFIX protocol provides an output standard for data stream feature information, and the original IPFIX protocol metrics are used to describe data streams. In the embodiments of the present invention, in order to output session characteristic information using the IPFIX protocol, the metrics in the original IPFIX protocol are extended by adding multiple session feature indicators for describing sessions. The session features to be counted are configured as preset session features in the IPFIX protocol. When extending the session feature indicators of the IPFIX protocol, the session feature indicators mainly extended for analyzing the following session states are: session server delay, session anomaly, session incompleteness, Hypertext Transfer Protocol (HTTP) session error, etc.

[0160] As shown in Table 1, an example is given for the multiple session feature indicators extended in the IPFIX protocol for describing sessions:

[0161] Table 1. Session Feature Indicators Extended in the IPFIX Protocol

[0162]

[0163]

[0164] Table 1 only gives examples of the extended session feature metrics in several IPFIX protocols. Other session feature metrics for describing sessions can also be extended in the IPFIX protocol according to actual needs. The session feature metrics can be selected as the preset session features, which will not be elaborated one by one here.

[0165] In addition to the several session feature metrics extended in the IPFIX protocol shown in Table 1, there are also session feature metrics in the original IPFIX protocol that can be used to describe sessions. As shown in Table 2.

[0166] Table 2. Original session feature metrics in the IPFIX protocol

[0167]

[0168]

[0169] Table 1 only gives examples of the original session feature metrics in several IPFIX protocols. Other session feature metrics for describing sessions in the original IPFIX protocol can also be analyzed according to actual needs, which will not be elaborated one by one here.

[0170] According to the preset session features, each data packet in the session to be analyzed is parsed respectively, and the feature values of the preset session features are extracted from the information carried by each data packet. For example: when the preset session features are the number of bytes in the session's uplink and downlink, the number of bytes of each data packet in the session to be analyzed is extracted; when the preset session feature is the number of TCP session flag bits, the TCP flag bits carried in the data packets in the session to be analyzed are extracted. Extracting the feature values of other preset session features from each data packet in the session to be analyzed is similar to the above examples and is specifically executed according to the actual situation, which will not be elaborated one by one here.

[0171] When extracting the feature values of the preset session features from each of the data packets, according to the number of preset session features, when extracting the feature values from each data packet in the session to be analyzed, it is possible to extract only the feature values of one preset session feature, or to extract the feature values of multiple preset session features simultaneously, which is not specifically limited here.

[0172] S103: Statistically analyze the feature values to obtain the session feature information of the session to be analyzed.

[0173] After extracting the feature values of the preset session features from each data packet in the session to be analyzed, statistically analyze the feature values, and the session feature information of the preset session feature of the session to be analyzed can be obtained.

[0174] For example: when the preset session feature is the number of bytes in the uplink and downlink of the session, sum the number of bytes of each uplink data packet to obtain the uplink byte count, and sum the number of bytes of each downlink data packet to obtain the downlink byte count; when the preset session feature is the number of TCP session flag bits, count each type of TCP session identifier extracted from the data packets respectively to obtain the number of each type of TCP session identifier. In addition, the preset session feature can also be the number of uplink data packets and downlink data packets of the session. Count the number of uplink data packets and downlink data packets of the session to be analyzed according to the source IP address and the destination IP address respectively; the preset session feature can also be the number of TCP flag bits, and count the number of each type of TCP flag bit according to the flag bits carried by the data packets.

[0175] It should be noted here that in addition to the above examples, it is also possible to count the feature values of other preset session features to obtain the session feature information of other preset session features, which will not be elaborated here one by one.

[0176] In one embodiment, before extracting the feature value of the preset session feature from each of the data packets, it includes: obtaining the session feature metrics configured in the IPFIX protocol for the IP data stream information output as the preset session feature.

[0177] That is, when the preset session feature is the session feature configured in the IPFIX protocol, the method further includes:

[0178] Output the feature information of the session to be analyzed in the standard format of the IPFIX protocol.

[0179] The IPFIX protocol defines the standard output format of the session feature information, which is convenient for technicians to extract and view the session feature information. In the embodiments of the present invention, the Cisco Netflow Version 9 version is used as an example, and other versions of the standard output format can also be used, which will not be elaborated here one by one. Figure 2 This is a schematic diagram of the IPFIX protocol message format for the embodiments of the present invention; Table 3 shows one of the output templates of the data standard output format Netflow V 9 version of the IPFIX protocol.

[0180] Table 3. Output Template of the Data Standard Output Format Netflow V9 Version of the IPFIX Protocol

[0181]

[0182]

[0183] When outputting session feature information, you can also use the standard output format of other versions of the IPFIX protocol, or you can use other output templates in Cisco Netflow Version 9. You can choose according to the actual situation. This will not be described in detail here.

[0184] It can be seen from the above content that the embodiments of the present invention have the following beneficial effects:

[0185] The embodiment of the present invention provides a method for analyzing characteristic information in a creative way, which obtains multiple data packets in a session to be analyzed; extracts a characteristic value of a preset session characteristic from each of the data packets; and obtains the session characteristic information of the session to be analyzed by counting the characteristic values. In the embodiment of the present invention, the session is taken as the basic analysis unit, and an overall analysis of the session is realized to obtain the session characteristic information that can fully reflect the session.

[0186] Figure 3 A flow chart of a network attack detection method provided by an embodiment of the present invention, the method comprising:

[0187] S301: Analyze session feature information of all to-be-analyzed sessions acquired within a preset time interval.

[0188] The session feature information is used Figure 1 The characteristic information analysis method provided by the embodiment of the present invention is obtained by analysis, referring to Figure 1 The specific description of the characteristic information analysis method shown will not be repeated here.

[0189] S302: Detecting a network session attack within the preset time interval according to the session feature information.

[0190] S301 acquires the session feature information of all the sessions to be analyzed obtained within the preset time interval. By comprehensively analyzing the session feature information of all the sessions to be analyzed, it is possible to detect whether there is a network session attack within the preset time interval. It is understandable that different types of network session attacks can be detected by analyzing different session feature information.

[0191] There are at least four possible implementations of detecting the network session attack within the preset time interval according to the session feature information. These four possible implementations are described one by one below.

[0192] In a first possible implementation manner, detecting the network session attack within the preset time interval according to the session feature information includes:

[0193] Counting a first proportion of incomplete sessions among all the to-be-analyzed sessions acquired within the preset time interval according to the session characteristic information;

[0194] Determine whether the first ratio exceeds a first preset threshold;

[0195] When the first ratio of incomplete sessions exceeds the first preset threshold, identify a network session attack within the preset time interval.

[0196] Count the number of incomplete sessions based on the session feature information. When there are a large number of incomplete sessions within the preset time interval, it indicates that a network session attack has occurred within this preset time interval. Among them, the first preset threshold can be set according to the actual situation. For example, the first preset threshold can be set to 60%. When the incomplete sessions exceed 60% within the first preset time interval, it indicates that a network session attack has occurred. At this time, the attack type, attack source device, attack target device, etc. of the network session attack can be analyzed based on the session feature information.

[0197] In a first possible implementation manner, according to the types of session feature information of the session to be analyzed obtained, the definition of an incomplete session is different, and the identified session attack types are also different.

[0198] Scenario 1, the session feature information includes the number of uplink data packets and the number of downlink data packets;

[0199] The incomplete session is a session to be analyzed where the number of uplink data packets is greater than 1 and the number of downlink data packets is 0.

[0200] When there are a large number of incomplete sessions with only uplink data packets and no downlink data packets within the preset time interval, it is very likely that a DNS session attack has occurred within this preset time interval.

[0201] Scenario 2, the session feature information includes Transmission Control Protocol (TCP) flag bits;

[0202] The incomplete session is a session to be analyzed with incomplete TCP flag bits.

[0203] When there are a large number of sessions to be analyzed with incomplete TCP flag bits within the preset time interval, it is very likely that a TCP Flood session attack has occurred within this preset time interval.

[0204] In addition to the above two implementation scenarios, there are other session feature information that can also describe incomplete sessions. The types of session attacks received are analyzed based on the session feature information, which will not be elaborated here.

[0205] In a second possible implementation manner, the session feature information includes the number of echo packets and the number of echo reply packets in Internet Control Message Protocol (ICMP) sessions;

[0206] Detecting the network session attack within the preset time interval according to the session feature information includes:

[0207] Counting a second ratio of echo packets and echo reply packets in the obtained ICMP sessions within the preset time interval according to the session feature information;

[0208] Determining whether the second ratio is within a preset numerical range;

[0209] When the second ratio is not within the preset numerical range, identifying an ICMP protocol session attack within the preset time interval.

[0210] For an Internet Control Message Protocol (ICMP) session, the echo packets and echo reply packets in the session should theoretically be the same. For every echo packet, there should be an echo reply packet. In actual applications, the ratio of echo packets and echo reply packets in an ICMP session should be approximately 1, that is, the preset numerical range can be set to 0.8 - 1.2. Of course, the preset numerical range can also be set to other ranges as long as the number of echo packets and echo reply packets in the ICMP session does not differ much.

[0211] When the second ratio of echo packets and echo reply packets exceeds the preset numerical range, it means that the number of echo packets far exceeds the number of echo reply packets, or the number of echo reply packets far exceeds the number of echo packets. Identify that there is an ICMP network attack in the network within the preset time interval.

[0212] A third possible implementation method, detecting the network session attack within the preset time interval according to the session feature information includes:

[0213] Counting the number of denial-of-service sessions within the preset time interval according to the session feature information, where the denial-of-service session is the session to be analyzed whose session feature information contains HTTP error code information;

[0214] Determining whether the number of denial-of-service sessions exceeds a second preset threshold;

[0215] When the number of denial-of-service sessions exceeds the second preset threshold, identifying a CC session attack within the preset event interval.

[0216] When the session to be analyzed contains HTTP error code information, the session to be analyzed is an HTTP denial-of-service session. According to the session feature Application Error Code, count the number of HTTP denial-of-service sessions. When a large number of denial-of-service sessions occur within a preset time interval, identify that there may be a CC (Challenge Collapsar) session attack in the network.

[0217] The fourth possible implementation manner, where detecting a network session attack within the preset time interval according to the session feature information includes:

[0218] Determine whether the session feature information of each session to be analyzed collected within the preset time interval contains any one or more of the following situations: session fragmentation anomaly information, where the session fragmentation anomaly information includes incomplete fragmentation, overlapping fragmentation, and incorrect fragmentation flag bits;

[0219] When the session feature information of the session to be analyzed contains session fragmentation anomaly information, identify the session to be analyzed as a fragmentation attack session within the preset time interval.

[0220] When the session feature information of the session to be analyzed contains fragmentation anomaly information, the session to be analyzed is a fragmentation anomaly session. When a large number of fragmentation anomaly sessions occur within a preset time interval, identify that there may be a fragmentation attack in the network.

[0221] The fragmentation anomaly information includes:

[0222] Fragment Incomplete, incomplete fragmentation, that is, a certain fragment is missing in the session;

[0223] Fragment Offset Error, overlapping fragmentation, that is, there is overlapping data information between the previous fragment and the next fragment;

[0224] Fragment Flag Error, incorrect flag bit, that is, the flag bits in different fragments are both set to 1.

[0225] In addition, the fragmentation anomaly information also includes: the first fragment is too short, that is, the first fragment is less than 1400 bytes; the fragment is too long, that is, the fragment carrying the fragment identifier exceeds 1500 bytes. There may be other fragmentation anomaly information, which will not be elaborated here one by one.

[0226] Detect network session attacks within the preset time interval according to the session feature information. Besides the above four possible implementation manners, the reasons for session termination can also be counted. If a large number of session terminations occur within the preset time interval, it is recognized that there may be a network session attack. The maximum packet length and the minimum packet length can also be counted. When the maximum packet length and the minimum packet length of a large number of sessions to be analyzed are basically the same, it is recognized that there may be a network session attack. Or the uplink data transmission rate and the downlink data transmission rate of the sessions to be analyzed are counted to assist in identifying network session attacks.

[0227] Optionally, the session feature information in the embodiments of the present invention can be output in the standard output format in the IPFIX protocol. It should be noted here that there are many types of session feature information, which will not be listed one by one here. Different types of session feature information can identify different types of network session attacks.

[0228] In one embodiment, the method further includes:

[0229] When a network session attack within the preset time interval is detected, generate an attack event according to the session feature information of the session to be analyzed;

[0230] Generate an attack suppression strategy according to the attack event.

[0231] When a network session attack is recognized, an attack event can be generated according to the session feature information. By analyzing the attack event, an attack suppression strategy can be generated, and information such as the attack source device, the attacked service, and the attacked device can also be identified.

[0232] Next, an Figure 3 application scenario of the network attack detection method provided by the embodiments of the present invention shown is illustrated by way of example.

[0233] Application scenario 1, attack detection in a Software Defined Network (SDN):

[0234] Switches in the SDN network: Based on session sampling for all received data packets to obtain data packets of multiple sampled sessions; obtain multiple data packets of the session to be analyzed from the data packets of the multiple sampled sessions; extract the feature values of preset session features from each of the data packets; count the feature values to obtain the session feature information of the session to be analyzed, and output the session feature information to the attack detection device in the SDN network in the standard format in the IPFIX protocol.

[0235] Attack detection device in the SDN network: Analyze the session feature information of all sessions to be analyzed obtained within a preset time interval, detect network session attacks within the preset time interval according to the session feature information, and generate an attack event when a network session attack is identified, and send it to the SDN network controller.

[0236] SDN network controller: Generate an attack suppression policy according to the received attack event, and send it to the switches in the SND network to suppress session attacks in the SDN network.

[0237] Application scenario two:

[0238] Receive session feature information output in the standard format of the IPFIX protocol in large quantities;

[0239] Use a distributed device to statistically analyze a large amount of session feature information using the CUSUM algorithm;

[0240] Analyze the statistical results to detect session attacks.

[0241] When statistically analyzing the session feature information, it is possible to statistically analyze network concurrent sessions, session server latency, session connection rate, and abnormal sessions. When detecting session attacks, it is also possible to identify information such as the original attack device, attack proxy device, attack service type, and attacked device. It should be noted here that when statistically analyzing a large amount of session feature information, other statistical algorithms can also be used, which will not be elaborated here.

[0242] As can be seen from the above, the embodiments of the present invention also have the following beneficial effects:

[0243] The embodiments of the present invention also provide a network attack detection method and system, which detect network session attacks within a preset time interval according to the session feature information of sessions to be analyzed obtained within the preset time interval, solve the problem that session attacks in the network cannot be detected based on the feature information of data streams in the prior art, realize the effective detection of session attacks in the network, and improve the completeness of network attack detection.

[0244] Figure 4 It is a schematic structural diagram of a feature information analysis device provided by an embodiment of the present invention. The device includes:

[0245] The first acquisition unit 401 is used to acquire multiple data packets in the session to be analyzed.

[0246] In one embodiment, the first acquisition unit 401 includes:

[0247] The first acquisition subunit is used to respectively acquire the five-tuple information of each data packet from all received data packets;

[0248] A second obtaining subunit, configured to obtain the data packets of the session to be analyzed from all the received data packets based on the five-tuple information of each data packet.

[0249] In another embodiment, the apparatus further includes:

[0250] A sampling unit, configured to sample all the received data packets based on sessions to obtain data packets of multiple sampled sessions;

[0251] Then the first obtaining unit 401 is specifically configured to obtain multiple data packets of the session to be analyzed from the data packets of the multiple sampled sessions.

[0252] The first obtaining unit 401 includes:

[0253] A third obtaining subunit, configured to respectively obtain the five-tuple information of each data packet from the data packets of the multiple sampled sessions;

[0254] A fourth obtaining subunit, configured to obtain the data packets of the session to be analyzed from the data packets of the multiple sampled sessions based on the five-tuple information of each data packet.

[0255] The sampling unit includes:

[0256] A parsing subunit, configured to parse the five-tuple information of each received data packet;

[0257] A first calculating subunit, configured to calculate a positive hash value and a reverse hash value of the received data packet by using the five-tuple information, where the positive hash value is a hash value calculated by using the five-tuple information of the received data packet as an input, and the reverse hash value is a hash value calculated by using, after swapping the source IP address and the destination IP address and swapping the source port number and the destination port number in the five-tuple information of the received data packet, the swapped five-tuple information as an input;

[0258] A second calculating subunit, configured to calculate a first remainder obtained by dividing the positive hash value by a preset sampling parameter in a preset session sampling template, and calculate a second remainder obtained by dividing the reverse hash value by the preset sampling parameter in the session sampling template, where the preset sampling parameter is the denominator of the sampling ratio in the session sampling template;

[0259] A judging subunit, configured to judge whether the first remainder or the second remainder is a preset sampling remainder in the session sampling template;

[0260] A sampling subunit, configured to sample the received data packet when the first remainder or the second remainder is the preset sampling remainder in the session sampling template.

[0261] An extraction unit 402, configured to extract the eigenvalue of a preset session feature from each of the data packets.

[0262] A statistical unit 403, configured to obtain session feature information of the session to be analyzed by statistically analyzing the eigenvalues.

[0263] In a specific embodiment, the apparatus further includes:

[0264] A second acquisition unit, configured to acquire the session features configured in the IPFIX protocol as preset features.

[0265] In a specific embodiment, the apparatus further includes:

[0266] An output unit, configured to output the feature information of the session to be analyzed in a standard format of the IPFIX protocol.

[0267] Figure 4 The shown feature information analysis apparatus is Figure 1 the apparatus corresponding to the shown feature information analysis method. For the description in the Figure 1 feature analysis method, it will not be elaborated here.

[0268] Figure 5 The following is a schematic structural diagram of a network attack detection system provided by an embodiment of the present invention. The system includes:

[0269] Figure 4 The shown feature analysis apparatus 501, configured to analyze the session feature information of all sessions to be analyzed acquired within a preset time interval.

[0270] A detection apparatus 502, configured to detect network session attacks within the preset time interval according to the session feature information.

[0271] A first possible structure of the detection apparatus 502 includes:

[0272] A first statistical unit, configured to statistically analyze the first ratio of incomplete sessions among all sessions to be analyzed acquired within the preset time interval according to the session feature information;

[0273] A first judgment unit, configured to judge whether the first ratio exceeds a first preset threshold;

[0274] A first recognition unit, configured to recognize network session attacks within the preset time interval when the first ratio of incomplete sessions exceeds the first preset threshold.

[0275] In the first possible structure, scenario one:

[0276] The session feature information includes the number of bytes of the uplink packet and the number of bytes of the downlink packet;

[0277] The incomplete session is a session to be analyzed where the number of the uplink data packets is greater than 1 and the number of the downlink data packets is 0.

[0278] In the first possible structure, scenario two:

[0279] The session feature information includes Transmission Control Protocol (TCP) flag bits;

[0280] The incomplete session is a session to be analyzed with incomplete TCP flag bits.

[0281] The second possible structure of the detection device 502 includes:

[0282] The session feature information includes the number of echo packets and the number of echo reply packets in the Internet Control Message Protocol (ICMP) session;

[0283] A second statistical unit, configured to statistically calculate a second ratio of the echo packets and the echo reply packets in the obtained ICMP sessions within a preset time interval according to the session feature information;

[0284] A second judgment unit, configured to judge whether the second ratio is within a preset numerical range;

[0285] A second identification unit, configured to identify an ICMP session attack within the preset time interval when the second ratio is not within the preset numerical range.

[0286] The third possible structure of the detection device 502 includes:

[0287] A third statistical unit, configured to statistically calculate the number of denial-of-service sessions within the preset time interval according to the session feature information, where the denial-of-service session is the session to be analyzed that contains Hypertext Transfer Protocol (HTTP) error code information in the session feature information;

[0288] A third judgment unit, configured to judge whether the number of the denial-of-service sessions exceeds a second preset threshold;

[0289] A third identification unit, configured to identify a CC session attack within the preset event interval when the number of the denial-of-service sessions exceeds the second preset threshold.

[0290] The fourth possible structure of the detection device 502 includes:

[0291] A fourth determination unit, configured to determine whether the session feature information of each of the to-be-analyzed sessions collected within the preset time interval includes session fragmentation exception information, where the session fragmentation exception information includes any one or more of incomplete fragmentation, overlapping fragmentation, and incorrect fragmentation flag bits;

[0292] A fourth recognition unit, configured to, when the session feature information of the to-be-analyzed session includes session fragmentation exception information, recognize the to-be-analyzed session as a fragmentation attack session within the preset time interval.

[0293] In one embodiment, the system further includes:

[0294] A defense device, configured to, when detecting a network session attack within the preset time interval, generate an attack event according to the session feature information of the to-be-analyzed session; and generate an attack suppression policy according to the attack event.

[0295] The system further includes:

[0296] An attack recognition device, configured to identify an attack source device, an attacked service, and an attacked device according to the attack event.

[0297] In practical applications, the session feature information adopts the standard output format of the IPFIX protocol.

[0298] Figure 5 The shown network attack detection system is a system corresponding to Figure 2 the shown network attack detection method. Refer to Figure 2 the description in the network attack detection method described above, which will not be elaborated here.

[0299] Refer to Figure 6 , Figure 6 which is a schematic hardware structure diagram of a feature information analysis device provided by an embodiment of the present invention. The feature information analysis device includes a memory 601 and a processor 602 connected to the memory 601. The memory 601 is used to store a set of program instructions, and the processor 602 is used to call the program instructions stored in the memory 601 to perform the following operations:

[0300] Obtain multiple data packets in the to-be-analyzed session;

[0301] Extract the feature values of preset session features from each of the data packets;

[0302] Statistically analyze the feature values to obtain the session feature information of the to-be-analyzed session;

[0303] Optionally, before extracting the feature values of preset session features from each of the data packets, it includes:

[0304] Obtain the session characteristic metrics configured in the IP data flow information output IPFIX protocol as the preset session characteristics;

[0305] Optionally, it further includes:

[0306] Output the characteristic information of the session to be analyzed in the standard format of the IPFIX protocol;

[0307] Optionally,

[0308] The obtaining of multiple data packets in the session to be analyzed includes:

[0309] Respectively obtain the five-tuple information of each data packet from all the received data packets;

[0310] Based on the five-tuple information of each data packet, obtain multiple data packets of the session to be analyzed from all the received data packets;

[0311] Optionally, before obtaining multiple data packets in the session to be analyzed, it further includes:

[0312] Perform session sampling on all the received data packets to obtain data packets of multiple sampled sessions;

[0313] The obtaining of multiple data packets in the session to be analyzed includes:

[0314] Obtain multiple data packets of the session to be analyzed from the data packets of the multiple sampled sessions;

[0315] Optionally, the obtaining of the data packets of the session to be analyzed from the data packets of the multiple sampled sessions includes:

[0316] Respectively obtain the five-tuple information of each data packet from the data packets of the multiple sessions;

[0317] Based on the five-tuple information of each data packet, obtain the data packets of the session to be analyzed from the data packets of the multiple sessions;

[0318] Optionally, the performing of session sampling on all the received data packets includes:

[0319] Parse the five-tuple information of each of the received data packets;

[0320] Calculate the positive hash value and the reverse hash value of the received data packet by using the quintuple information. The positive hash value is a hash value calculated by using the quintuple information of the received data packet as input. The reverse hash value is a hash value calculated by using, as input, the quintuple information of the received data packet with the source IP address and the destination IP address swapped and the source port number and the destination port number swapped.

[0321] Calculate a first remainder obtained by dividing the positive hash value by a preset sampling parameter in a preset session sampling template, and calculate a second remainder obtained by dividing the reverse hash value by the preset sampling parameter in the session sampling template. The preset sampling parameter is the denominator of the sampling ratio in the session sampling template.

[0322] Determine whether the first remainder or the second remainder is a preset sampling remainder in the session sampling template.

[0323] When the first remainder or the second remainder is the preset sampling remainder in the session sampling template, sample the received data packet.

[0324] Refer to Figure 7 , Figure 7 FIG. is a schematic diagram of the hardware structure of the network attack detection system provided by an embodiment of the present invention. The network attack detection system is located in a network, and the network further includes a plurality of routers. Adjacent routers among the plurality of routers are connected by a link with a certain bandwidth. The plurality of routers form a network topology through the link. The network attack detection system includes a memory 701 and a processor 702 connected to the memory 701. The memory 701 is used to store a set of program instructions, and the processor 702 is used to call the program instructions stored in the memory 701 to perform the following operations:

[0325] Analyze the session feature information of all sessions to be analyzed obtained within a preset time interval.

[0326] Detect network session attacks within the preset time interval according to the session feature information.

[0327] Optionally, the detecting network session attacks within the preset time interval according to the session feature information includes:

[0328] Statistically analyze a first ratio of incomplete sessions among all sessions to be analyzed obtained within the preset time interval according to the session feature information.

[0329] Determine whether the first ratio exceeds a first preset threshold.

[0330] When the first ratio of incomplete sessions exceeds the first preset threshold, identify network session attacks within the preset time interval.

[0331] Among them, the session feature information includes the number of uplink data packets and the number of downlink data packets;

[0332] The incomplete session is a session to be analyzed where the number of uplink data packets is greater than 1 and the number of downlink data packets is 0;

[0333] Among them, the session feature information includes the Transmission Control Protocol (TCP) flag bits;

[0334] The incomplete session is a session to be analyzed with incomplete TCP flag bits;

[0335] Optionally, the session feature information includes the number of echo packets and the number of echoreply packets in an Internet Control Message Protocol (ICMP) session;

[0336] The detecting of network session attacks within the preset time interval according to the session feature information includes:

[0337] Statistically calculating a second ratio of echo packets to echoreply packets in the obtained ICMP sessions within the preset time interval according to the session feature information;

[0338] Judging whether the second ratio is within a preset numerical range;

[0339] When the second ratio is not within the preset numerical range, identifying the ICMP session attack within the preset time interval;

[0340] Optionally, the detecting of network session attacks within the preset time interval according to the session feature information includes:

[0341] Statistically calculating the number of denial-of-service sessions within the preset time interval, where the denial-of-service session is a session to be analyzed whose session feature information contains Hypertext Transfer Protocol (HTTP) error code information;

[0342] Judging whether the number of denial-of-service sessions exceeds a second preset threshold;

[0343] When the number of denial-of-service sessions exceeds the second preset threshold, identifying the CC session attack within the preset event interval;

[0344] Optionally, the detecting of network session attacks within the preset time interval according to the session feature information includes:

[0345] Judging whether the session feature information of each session to be analyzed collected within the preset time interval contains session fragmentation anomaly information, where the session fragmentation anomaly information includes incomplete fragmentation,

[0346] Any one or more of sharding overlap and sharding flag bit errors;

[0347] When the session feature information of the session to be analyzed contains session sharding exception information, identify the session to be analyzed as a sharding attack session within the preset time interval;

[0348] Optionally, the method further includes:

[0349] When a network session attack within the preset time interval is detected, generate an attack event according to the session feature information of the session to be analyzed;

[0350] Generate an attack suppression strategy according to the attack event;

[0351] Optionally, the method further includes:

[0352] Identify the attack source device, attack service, and attacked device according to the attack event.

[0353] Wherein, the session feature information adopts the standard output format of the IPFIX protocol.

[0354] It should be noted here that in the embodiments of the present invention, the processor may be a central processing unit (CPU), the memory may be an internal memory of the random access memory (RAM) type, and the processor and the memory may be integrated into one or more independent circuits or hardware, such as: an application specific integrated circuit (ASIC).

[0355] In the embodiments of the present invention, the "first" of the first host device and the first interface is only used for name identification and does not represent the first in order. The same rule applies to "second" and "third".

[0356] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium can be at least one of the following media: read-only memory (ROM), RAM, magnetic disk, or optical disk, etc., which can store program codes.

[0357] It should be noted that the embodiments in this specification are all described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for the device and system embodiments, since they are basically similar to the method embodiments, they are described relatively simply, and reference can be made to the corresponding parts of the method embodiments for the relevant content. The device and system embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0358] The above is only the preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. It should be pointed out that for those of ordinary skill in the art in this technical field, several improvements and refinements can be made without departing from the principle of the present invention, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A detection method for network session attacks, characterized in that, The method includes: Taking a session as the basic analysis unit to obtain session feature information of each session to be analyzed. Here, a session refers to the communication interaction established between two network devices within a specific uninterrupted operation time. During the specific operation time, all the packets exchanged between the two network devices belong to the session. The session feature information of the session to be analyzed is obtained based on the feature values of the preset session features extracted from all the packets in the session to be analyzed; Detecting network session attacks within the preset time interval according to the session feature information of all the sessions to be analyzed obtained within the preset time interval. Here, all the sessions to be analyzed include at least one session to be analyzed, and different session feature information corresponds to detecting different types of network session attacks.

2. The method according to claim 1, wherein Before obtaining the session feature information of each session to be analyzed, the method further includes: Obtaining multiple packets included in each session to be analyzed.

3. The method according to claim 2, wherein The obtaining of the multiple packets included in each session to be analyzed includes: Respectively obtaining the five-tuple information of each packet from all the received packets; Based on the five-tuple information of each packet, obtaining the multiple packets included in each session to be analyzed from all the received packets.

4. The method according to claim 2, wherein The obtaining of the multiple packets included in each session to be analyzed includes: Based on session sampling for all the received packets, obtaining all the sampled packets of all the sampled sessions; Obtaining the multiple packets included in each session to be analyzed from all the sampled packets of all the sampled sessions.

5. The method according to claim 4, wherein The obtaining of the multiple packets included in each session to be analyzed from all the sampled packets of all the sampled sessions includes: Respectively obtaining the five-tuple information of each sampled packet from all the sampled packets; Based on the five-tuple information of each sampled packet, obtaining the multiple packets included in each session to be analyzed from all the sampled packets.

6. The method according to claim 4, characterized in that, Based on session sampling for all the received packets includes: Parsing the five-tuple information of each received packet; Calculating the positive hash value and the reverse hash value of the received packet by using the five-tuple information. The positive hash value is the hash value calculated with the five-tuple information of the received packet as the input, and the reverse hash value is the hash value calculated with the source IP address and the destination IP address in the five-tuple information of the received packet swapped, and the source port number and the destination port number swapped as the input; Calculating the first remainder obtained by dividing the positive hash value by the preset sampling parameter in the preset session sampling template, and calculating the second remainder obtained by dividing the reverse hash value by the preset sampling parameter in the session sampling template. The preset sampling parameter is the denominator of the sampling ratio in the session sampling template; Judging whether the first remainder or the second remainder is the preset sampling remainder in the session sampling template; When the first remainder or the second remainder is the preset sampling remainder in the session sampling template, sampling the received packet.

7. The method according to any one of claims 1-6, characterized in that, The session feature information includes any one or more of the following: The number of upstream messages and the number of downstream messages; The number of upstream bytes and the number of downstream bytes; The session termination is caused by an exception in the protocol state machine; The number of Transmission Control Protocol (TCP) flag bits; The number of echo messages and the number of echo reply messages in an Internet Control Message Protocol (ICMP) session; The number of denial-of-service sessions; Session fragmentation exception information; Message length; Or Session termination.

8. The method according to any one of claims 1 to 6, characterized in that, Output the session feature information of each session to be analyzed in the standard format of the IPFIX protocol using Internet Protocol (IP) data stream information.

9. The method according to any one of claims 1-6, characterized in that, The detecting of network session attacks within a preset time interval according to the session feature information of each session to be analyzed includes: Counting the first proportion of incomplete sessions among all sessions to be analyzed obtained within the preset time interval; In response to the first proportion exceeding a first preset threshold, identifying that there is a network session attack within the preset time interval.

10. The method according to any one of claims 1-6, characterized in that The detecting of network session attacks within a preset time interval includes: Counting the second proportion of echo messages and echo reply messages among all sessions to be analyzed obtained within the preset time interval; When the second proportion is not within a preset numerical range, identifying that there is a network session attack within the preset time interval.

11. The method according to any one of claims 1-6, characterized in that, The detecting of network session attacks within a preset time interval includes: Counting the number of denial-of-service sessions among all sessions to be analyzed obtained within the preset time interval, where the denial-of-service session is a session whose session feature information includes HTTP error code information; When the number of denial-of-service sessions exceeds a second preset threshold, identifying that there is a network session attack within the preset time interval.

12. The method according to any one of claims 1-6, characterized in that, The detecting of network session attacks within a preset time interval includes: In response to detecting multiple fragmented abnormal sessions within the preset time interval, identifying that there is a network session attack within the preset time interval.

13. The method according to claim 12, wherein When the session feature information of a session to be analyzed includes fragmentation exception information, then the session to be analyzed is a fragmented abnormal session.

14. The method according to claim 13, wherein The fragmentation exception information includes any one or more of the following: Fragmentation incomplete; Fragmentation overlap; Fragmentation flag bit error; The length of the first fragment is less than or equal to a first preset length; or The length of the fragment is greater than or equal to a second preset length.

15. The method according to any one of claims 1-6, characterized in that, The method further includes: When detecting a network session attack within the preset time interval, generating an attack event according to the session feature information of each session to be analyzed; Generating an attack suppression strategy according to the attack event.

16. The method according to claim 15, characterized in that, The method further includes: Identifying the attacking source device, the attacked service, or the attacked device according to the attack event.

17. A method for obtaining session feature information, characterized in that, The method includes: Taking a session as the basic analysis unit, obtaining multiple messages included in each session to be analyzed, where a session refers to the communication interaction established between two network devices within a non-interrupted specific operation time, and all messages exchanged between the two network devices within the specific operation time belong to the session; Based on all the packets included in each session to be analyzed, session feature information of each session to be analyzed is obtained. Different session feature information corresponds to detecting different types of network session attacks. The session feature information of the session to be analyzed is obtained based on the feature values of preset session features extracted from all the packets in the session to be analyzed.

18. The method according to claim 17, wherein The obtaining of multiple packets included in each session to be analyzed includes: Respectively obtain the five-tuple information of each packet from all the received packets; Based on the five-tuple information of each packet, obtain the multiple packets included in each session to be analyzed from all the received packets.

19. The method according to claim 17, characterized in that, The obtaining of multiple packets included in each session to be analyzed includes: For all the received packets, based on session sampling, obtain all the sampled packets of all the sampled sessions; From all the sampled packets of all the sampled sessions, obtain the multiple packets included in each session to be analyzed.

20. The method according to claim 19, wherein The obtaining of the multiple packets included in each session to be analyzed from all the sampled packets of all the sampled sessions includes: Respectively obtain the five-tuple information of each sampled packet from all the sampled packets; Based on the five-tuple information of each sampled packet, obtain the multiple packets included in each session to be analyzed from all the sampled packets.

21. The method according to claim 19, wherein For all the received packets, based on session sampling, includes: Parse the five-tuple information of each received packet; Calculate the positive hash value and the reverse hash value of the received data packet by using the five-tuple information. The positive hash value is the hash value calculated with the five-tuple information of the received data packet as the input, and the reverse hash value is the hash value calculated with the source IP address and the destination IP address in the five-tuple information of the received data packet swapped, and the source port number and the destination port number swapped as the input; Calculate the first remainder obtained by dividing the positive hash value by the preset sampling parameter in the preset session sampling template, and calculate the second remainder obtained by dividing the reverse hash value by the preset sampling parameter in the session sampling template. The preset sampling parameter is the denominator of the sampling ratio in the session sampling template; Judge whether the first remainder or the second remainder is the preset sampling remainder in the session sampling template; When the first remainder or the second remainder is the preset sampling remainder in the session sampling template, sample the received data packet.

22. The method according to any one of claims 17 - 21, characterized in that, The session feature information includes any one or more of the following: The number of upstream data packets and the number of downstream data packets; The number of upstream bytes and the number of downstream bytes; Session termination caused by abnormal protocol state machine; The number of Transmission Control Protocol (TCP) flag bits; The number of echo packets and the number of echo reply packets in the Internet Control Message Protocol (ICMP) session; The number of denial-of-service sessions; Session fragmentation exception information; Packet length; Or Session termination.

23. The method according to any one of claims 17-21, characterized in that, Output the session feature information of each session to be analyzed in the standard format of the IP Flow Information Export (IPFIX) protocol using the Internet Protocol (IP) data stream information.

24. A network attack detection device, characterized in that, The device includes: A memory, and a processor connected to the memory, the memory being configured to store a set of program instructions, and the processor being configured to invoke the program instructions stored in the memory such that the network attack detection device executes the method according to any one of claims 1-16.

25. A feature information analysis device, characterized in that, The device comprises: A memory, and a processor connected to the memory, the memory being configured to store a set of program instructions, and the processor being configured to invoke the program instructions stored in the memory such that the feature information analysis device executes the method according to any one of claims 17-23.

26. A network system, characterized in that, The system comprises: a first network device, a second network device, and the network attack detection device according to claim 24.

27. A network system, characterized in that, The system comprises: a first network device, a second network device, and the feature information analysis device according to claim 25.

28. A network system, characterized in that, Comprising the network attack detection device according to claim 24 and the feature information analysis device according to claim 25.

29. A computer-readable storage medium includes computer instructions, characterized in that, When the computer instructions are run on a computer, the computer is caused to execute the method according to any one of claims 1-23.

Citation Information

Patent Citations

  • Session attack detection system and method

    CN101047509A

  • Method and device for identifying attack

    CN102882894A

  • Method and system for data flow sampling

    CN1909554A

  • Transmission control protocol flooding attack prevention method and apparatus

    US20120117646A1