A Method for Detecting DoS Attacks on Edge Servers Based on Runtime Verification
By using PPTL formulas and parallel runtime verification framework in the edge computing system, the dynamic execution status of edge servers is detected, and the problem of low DoS attack detection efficiency in the prior art is solved, and efficient and reliable DoS attack detection of edge servers is achieved.
Patent Information
- Application Number
- CN202110876832.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-07-31
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2041-07-31
AI Technical Summary
The prior art has low detection efficiency of DoS attacks in edge computing systems, and requires training models in advance, occupies large memory, making it difficult to achieve efficient detection on edge servers with limited computing resources.
The propositional projection timing logic (PPTL) formula is used to formally describe the expected behavior and DoS attack characteristics of edge servers. The dynamic execution trajectory of edge server programs is detected through the parallel runtime verification framework to determine whether they are being attacked by DoS.
It realizes efficient and reliable detection of DoS attacks on edge servers, makes full use of the idle computing and storage resources of edge servers, improves verification efficiency, timely discovers attacks, and ensures the normal operation of edge servers.
Smart Images

Figure CN113626813B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of program running verification, and particularly relates to a method for detecting DoS attacks on edge servers based on runtime verification. Background Art
[0002] At present, edge computing systems utilize the computing and storage resources of terminal devices and edge servers near the terminals to partially process data in advance, reduce the amount of data to be sent to the cloud data center, thereby reducing the network bandwidth usage, and enabling the system to immediately respond to data under lower data latency. However, the characteristics of edge servers pose new challenges. First, since edge servers are located at the edge of the network and closer to users, the heterogeneous access environment and diverse service requirements make edge servers face a more complex network environment. In addition, edge servers are often geographically distributed, making it difficult to achieve centralized device security protection, and each edge server is different, which brings more options for attackers. More seriously, due to the limitations of computing power and storage space, most edge servers only focus on the implementation of business logic and do not prevent and detect possible attacks. From the above analysis, although edge servers play an important role in the edge computing network, their vulnerable characteristics make them face severe attack threats.
[0003] Due to the limited computing and storage resources of edge servers, they are extremely easy to be exhausted. Therefore, among various attacks faced by edge computing systems, the denial-of-service (DoS) attack against edge servers is very widespread. In a DoS attack, malicious nodes send a large number of data packets to the attacked edge server or access the attacked edge server without limit, exhausting the resources of the running edge server and hindering the normal operation of the edge server. Since in the edge computing architecture, edge servers are used to implement partial processing of data and the transmission of data with cloud servers, once the communication link of the edge server is blocked or the resources are exhausted, the expected normal services will directly fail to be completed.
[0004] As an important means to ensure network security, intrusion detection can monitor network activities in real time, judge the device status, and timely detect DoS attacks suffered by the programs running on the device. At present, the commonly used existing methods in the industry include artificial intelligence methods such as pattern recognition and machine learning, as well as formal verification methods such as model checking and runtime verification, which can monitor and analyze the execution of real programs, check whether the running trajectory of the program meets the expectations, and have gradually been used in network intrusion detection. However, in the existing DoS attack detection methods for edge computing systems, most methods use pattern recognition or machine learning means. Although they can achieve good detection results, they need to train the model in advance and occupy a large amount of memory when performing real-time detection based on the trained model. Formal verification methods represented by model checking and runtime verification use temporal logic properties to identify the behavioral characteristics of network intrusion and do not require pre-training of the model. However, due to the need to construct theoretical models such as automata, the detection efficiency is often not high. Therefore, there is an urgent need for a new DoS attack detection method for edge servers to make up for the defects of the existing technologies.
[0005] Through the above analysis, the problems and defects existing in the prior art are as follows:
[0006] (1) The existing DoS attack detection methods for edge computing systems use pattern recognition or machine learning means, which require pre-training of the model and occupy a large amount of memory when performing real-time detection based on the trained model;
[0007] (2) In the existing formal verification methods represented by model checking and runtime verification, theoretical models such as automata need to be constructed, and the detection efficiency is not high.
[0008] The difficulty in solving the above problems and defects is that the large amount of program code running on the edge server contains complex logic and generates a large amount of program data. However, the computing resources of the edge server are limited, which increases the difficulty of accurately and efficiently detecting DoS attacks. How to make full use of the idle computing and storage resources of the edge server, improve the verification efficiency, and timely detect DoS attacks poses a great challenge.
[0009] The significance of solving the above problems and defects is that in view of the importance and vulnerability of the edge server in the edge computing system, as well as the universality of DoS attacks on the edge server and the severity of the threats, constructing a lightweight and efficient and accurate intrusion detection method can effectively ensure the normal running state of the edge server, enabling it to continuously respond to the service requests of terminal devices and complete the expected logical functions. Summary of the Invention
[0010] Aiming at the problems existing in the prior art, the present invention provides a method for detecting DoS attacks on edge servers based on runtime verification of programs.
[0011] The present invention is implemented as follows. A method for detecting DoS attacks on edge servers based on runtime verification, the method for detecting DoS attacks on edge servers based on runtime verification includes the following steps:
[0012] Step 1, formalize the expected behavior of the edge server using propositional projection temporal logic (PPTL) formulas, and provide the PPTL formulas corresponding to the expected behavior of the edge server for the (subsequent steps) runtime verification framework;
[0013] Step 2, formalize the DoS attack characteristics of the edge server using PPTL formulas, and provide the PPTL formulas corresponding to the DoS attack characteristics of the edge server for the (subsequent steps) runtime verification framework;
[0014] Step 3, instrument the running program of the edge server for the program variables and program functions involved in the PPTL formulas, and provide the necessary program running information for the (subsequent steps) runtime verification framework;
[0015] Step 4, for the dynamic execution trace of the edge server program, use a parallel runtime verification framework to detect the program running state, and determine whether the edge server is under DoS attack according to the detection result, providing an efficient and reliable DoS attack detection method for the edge server.
[0016] Further, in Step 1, formalize the expected behavior of the edge server given by the UML sequence diagram using PPTL formulas.
[0017] Further, in Step 2, formalize the DoS attack behaviors of Smurf, SYN Flood, and Land against the TCP / IP protocol family using PPTL formulas.
[0018] Further, in Step 3, for the program variables involved in the PPTL formulas, when the program variable is the left value of an assignment statement in the program, after the assignment statement, instrument the program to obtain the value of the program variable; for the program functions involved in the PPTL formulas, when the program function is called, after the call statement, instrument the program to assign the program variable with the same name as the program function to 1.
[0019] Further, in Step 4, for the dynamic execution trace of the edge server program, divide the execution trace into multiple slices; use multiple threads to simultaneously verify different slices of the execution trace to jointly complete the DoS attack detection.
[0020] Another object of the present invention is to provide a runtime verification-based edge server DoS attack detection system applying the runtime verification-based edge server DoS attack detection method, and the runtime verification-based edge server DoS attack detection system includes:
[0021] An expected behavior description module, configured to formally describe the expected behavior of the edge server in the form of a PPTL formula;
[0022] An attack feature description module, configured to formally describe the DoS attack features of the edge server in the form of a PPTL formula;
[0023] A program instrumentation module, configured to instrument the running program of the edge server for the program variables and program functions involved in the PPTL formula;
[0024] An attack detection module, configured to detect the running state of the program by using a parallel runtime verification framework for the dynamic execution trace of the edge server program, and determine whether the edge server is under a DoS attack according to the detection result.
[0025] Another object of the present invention is to provide a computer device, which includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the following steps:
[0026] Formally describe the expected behavior of the edge server in the form of a PPTL formula; formally describe the DoS attack features of the edge server in the form of a PPTL formula; instrument the running program of the edge server for the program variables and program functions involved in the PPTL formula; detect the running state of the program by using a parallel runtime verification framework for the dynamic execution trace of the edge server program, and determine whether the edge server is under a DoS attack according to the detection result.
[0027] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the processor performs the following steps:
[0028] Formally describe the expected behavior of the edge server in the form of a PPTL formula; formally describe the DoS attack features of the edge server in the form of a PPTL formula; instrument the running program of the edge server for the program variables and program functions involved in the PPTL formula; detect the running state of the program by using a parallel runtime verification framework for the dynamic execution trace of the edge server program, and determine whether the edge server is under a DoS attack according to the detection result.
[0029] Another object of the present invention is to provide an information data processing terminal for implementing the edge server DoS attack detection system based on runtime verification.
[0030] Another object of the present invention is to provide an application of the edge server DoS attack detection method based on runtime verification in the field of runtime verification of edge servers.
[0031] Combining all the above technical solutions, the advantages and positive effects of the present invention are as follows: The edge server DoS attack detection method based on runtime verification provided by the present invention uses PPTL formulas to formally describe the expected behavior of edge servers; uses PPTL formulas to formally describe the DoS attack characteristics of edge servers; for the program variables and program functions involved in the PPTL formulas, instrument the running programs of edge servers; for the dynamic execution traces of edge server programs, use a parallel runtime verification framework to detect the program running status, and determine whether the edge server is being DoS attacked according to the detection results. The present invention applies the runtime verification method to the DoS attack detection of edge servers in the edge computing system, enabling the dynamic execution status of edge servers to be verified in a timely manner, and effectively ensuring the reliability and security of edge servers.
[0032] The present invention uses PPTL formulas to formally describe the expected behavior and DoS attack characteristics of edge servers, and for the program variables and program functions involved in the PPTL formulas, instruments the running programs of edge servers, and then for the dynamic execution traces of edge server programs, uses a parallel runtime verification framework to detect the program running status, and determines whether the edge server is being DoS attacked according to the detection results. Among them, PPTL has a fully regular expressive ability and can be directly used to describe the interval-related and periodic repetition properties of different module calls on edge servers; in addition, based on the parallel runtime verification framework, the idle computing and storage resources of edge servers can be fully utilized to improve the verification efficiency and detect attacks in a timely manner. The application of the present invention is for the DoS attack detection of edge servers.
[0033] Since the present invention belongs to the field of program runtime verification, and the runtime verification method itself is based on rigorous mathematical reasoning, applying the program verification method of runtime verification to the DoS attack detection of edge servers enables each state of program execution to be reliably verified, effectively ensuring the security of edge servers. Brief Description of the Drawings
[0034] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the attached drawings required for use in the embodiments of the present invention. Obviously, the attached drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, other attached drawings can be obtained based on these attached drawings without creative efforts.
[0035] Figure 1 It is a flowchart of a method for detecting DoS attacks on edge servers based on runtime verification provided by an embodiment of the present invention.
[0036] Figure 2 It is a block diagram of the structure of a system for detecting DoS attacks on edge servers based on runtime verification provided by an embodiment of the present invention;
[0037] In the figure: 1. Expected behavior description module; 2. Attack feature description module; 3. Program instrumentation module; 4. Attack detection module.
[0038] Figure 3 It is a schematic diagram of LNFG corresponding to the PPTL formula provided by an embodiment of the present invention.
[0039] Figure 4 It is a schematic diagram of an intelligent parking system provided by an embodiment of the present invention.
[0040] Figure 5 It is a schematic diagram of using a UML sequence diagram to describe the expected behavior of an intelligent parking system provided by an embodiment of the present invention.
[0041] Figure 6 It is a block diagram of the structure for describing the DoS attack characteristics of edge servers provided by an embodiment of the present invention.
[0042] Figure 7 It is a block diagram of thread creation in a method for detecting DoS attacks on edge servers based on runtime verification provided by an embodiment of the present invention. Detailed implementation manners
[0043] In order to make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the following further details the present invention in combination with embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0044] Aiming at the problems existing in the prior art, the present invention provides a method for detecting DoS attacks on edge servers based on runtime verification. The following describes the present invention in detail with reference to the attached drawings.
[0045] As Figure 1 shown, a method for detecting DoS attacks on edge servers based on runtime verification provided by an embodiment of the present invention includes the following steps:
[0046] S101, Formalize the expected behavior of the edge server using the PPTL formula;
[0047] S102, Formalize the DoS attack characteristics of the edge server using the PPTL formula;
[0048] S103, Instrument the running program of the edge server for the program variables and program functions involved in the PPTL formula;
[0049] S104, For the dynamic execution trace of the edge server program, use a parallel runtime verification framework to detect the program running state, and determine whether the edge server is under a DoS attack according to the detection result.
[0050] As Figure 2 shown, a DoS attack detection system for edge servers based on runtime verification provided by an embodiment of the present invention includes:
[0051] An expected behavior description module 1, configured to formalize the expected behavior of the edge server using the PPTL formula;
[0052] An attack characteristic description module 2, configured to formalize the DoS attack characteristics of the edge server using the PPTL formula;
[0053] A program instrumentation module 3, configured to instrument the running program of the edge server for the program variables and program functions involved in the PPTL formula;
[0054] An attack detection module 4, configured to use a parallel runtime verification framework to detect the program running state for the dynamic execution trace of the edge server program, and determine whether the edge server is under a DoS attack according to the detection result.
[0055] It should be noted that PPTL has a fully regular expressive power and can be directly used to describe the interval-related and periodic repetition properties of different module calls on the edge server. The PPTL formula P is inductively defined as follows:
[0056]
[0057] where p is an atomic proposition, and P1,..., P m and P are PPTL formulas. Except that the definitions of the connective ∧ and the logical formulas true and false are the same as those in classical logic, the following are some temporal formulas derived from PPTL:
[0058]
[0059]
[0060] It should be noted that any PPTL formula can construct its corresponding labeled normal form graph (LNFG). Figure 3 The PPTL formula is given corresponding LNFG, where p and q are atomic propositions, each node in the graph represents a PPTL formula; each edge is a state formula; the additionally introduced proposition l k is used to identify whether a path is acceptable. For example, a finite path is an acceptable path; for the infinite path π2 = <1, true, (2, true) ω (, since means that the nodes with infinite loops have the same label l1, so this path is unacceptable.
[0061] The technical solution of the present invention will be further described below in conjunction with specific embodiments.
[0062] Such as Figure 4 taking the intelligent parking system shown as an example, a method for detecting edge server DoS attacks based on runtime verification provided by an embodiment of the present invention includes the following steps:
[0063] The first step is to formally describe the expected behavior of the edge server in the form of a PPTL formula.
[0064] It should be noted that as an important description method in the detailed design stage, the UML sequence diagram is used to describe the dynamic interaction relationship between different modules or functions within the same module, and focuses on reflecting the time sequence of function message passing and calls. Using the PPTL formula, the call relationship between functions expressed in the UML sequence diagram can be described.
[0065] In Figure 5 the behaviors of each module during the parking process of a vehicle from entering the parking lot are given using the UML sequence diagram, and are formally described using the PPTL formula Q1:
[0066] Q1 ≡ ◇(identifyEnter; vehicleReserved; sendSpace; sendStatus; returnStatus; identifyLeave; calculateFee; sendFee) +
[0067] It should be noted that the PPTL formula Q1 uses +The operator indicates that for different vehicle entry requests, the edge server will continuously repeat the execution of each function. Generally speaking, the meaning of the PPTL formula Q1 is that from a certain moment on, the edge server will cyclically execute the functions identifyEnter, vehicleReserved, sendSpace, sendStatus, returnStatus, identifyLeave, calculateFee, and sendFee.
[0068] Step 2: Describe the DoS attack characteristics using the PPTL formula.
[0069] It should be noted that since each DoS attack has different characteristics, the principle analysis of different DoS attacks can be carried out to obtain the action sequence of the attacked node when the attack occurs, and on this basis, establish the PPTL formula corresponding to different attacks. As Figure 6 shown, the description of the DoS attack characteristics of the edge server in the embodiment of the present invention includes:
[0070] Smurf attack description module 1:
[0071] It should be noted that the atomic proposition send of the PPTL formula Q2 means that the attacked edge server sends a data packet to the broadcast address of the subnet whose destination address is this subnet, and receive means that the attacked device receives a response data packet sent from a host in the subnet. The sub-formula (◇receive) of the PPTL formula Q2 + means that the receive behavior occurs continuously, that is, continuously receives data packets returned by other nodes. The meaning of the PPTL formula Q2 is that there exists a certain state, starting from this state, although the device does not send data packets, but can continuously receive data packets.
[0072] SYN Flood attack description module 2:
[0073] It should be noted that the atomic propositions receive.SYN, send.SYNACK, and receive.ACK of the PPTL formula Q3 respectively represent that the attacked edge server receives a SYN data packet, sends a SYN-ACK response data packet, and receives an ACK data packet. The sub-formula of the PPTL formula Q3, (receive.SYN; send.SYNACK), represents that the behaviors of receiving a SYN data packet and sending a SYN-ACK data packet occur one after another. The meaning of the PPTL formula Q3 is that there exists a certain state. Starting from this state, the edge server receives a SYN data packet and then sends a SYN-ACK data packet, but in all subsequent states, it does not receive an ACK data packet.
[0074] Land attack description module 3: Q4 ≡ ◇(receive.SYN → ◇(send.SYNACK; send.ACK) + )。
[0075] It should be noted that the atomic propositions receive.SYN, send.SYNACK, and send.ACK of the PPTL formula Q4 respectively represent that the attacked edge server receives a SYN data packet, sends a SYN-ACK response data packet, and sends an ACK data packet. The sub-formula (send.SYNACK; send.ACK) + of the PPTL formula Q4 represents that the behaviors of sending a SYN-ACK data packet and sending an ACK occur continuously. The meaning of the PPTL formula Q4 is that there exists a certain state. Starting from this state, the edge server receives a SYN data packet, and after that, continuously sends SYN-ACK data packets and ACK data packets.
[0076] In the third step, for the program variables and program functions involved in the PPTL formula, instrument the program running on the edge server.
[0077] It should be noted that for the program variables involved in the PPTL formula, when the program variable is the left value of an assignment statement in the program, after this assignment statement, instrument the program to obtain the value of the program variable. For example, the atomic proposition p in the PPTL formula is x = 2, where x is a program variable. Then whenever the program variable x is the left value of an assignment statement in the program, instrument the program to obtain the value of the program variable x.
[0078] It should be noted that for the program function involved in the PPTL formula, when the program function is called, after the call statement, program instrumentation is performed to assign the program variable with the same name as the program function to 1. For example, the atomic proposition q in the PPTL formula is f = 1, where f is a program function. Then, whenever the program function f is called, after the call statement, program instrumentation is performed to assign the program variable with the same name as the program function f to 1.
[0079] Fourthly, for the dynamic execution trace of the edge server program, a parallel runtime verification framework is adopted to detect the program running state, and according to the detection result, it is judged whether the edge server is under a DoS attack.
[0080] As Figure 7 shown, in the monitored edge server, it is assumed that there are n + 2 available threads, where the execution thread e is used for program running, the scheduling thread s is used for scheduling verification tasks and merging verification results, and the verification threads v i (1 ≤ i ≤ n) are used to verify different execution trace slices.
[0081] It should be noted that during the process of the execution thread e running the program, the generated state sequence is first divided into several slices by the scheduling thread s, where each slice contains m states. Then, the scheduling thread s sends the information of these slices to the verification threads v i (1 ≤ i ≤ n) to complete the corresponding verification tasks. Finally, the verification results of different slices are returned to the scheduling thread s, and it completes the aggregation of the verification results to obtain the final verification result. The parallel runtime verification method provided by the embodiment of the present invention includes the following steps:
[0082] (1) The execution thread e is used to run the program. During this process, the scheduling thread s and the verification threads v i (1 ≤ i ≤ n) run in parallel;
[0083] (2) Whenever the newly generated m states can form a new execution sequence slice sg to be verified k , the scheduling thread s adds the ordered pair (k; i) to the set L to save the relationship between sg k and the verification thread v i , where i = min(I), and I is the set storing the threads that have not performed verification tasks yet (the initial value of I = {1, 2,..., n});
[0084] (3) The scheduling thread s sends the information of the slice sg k to the verification thread v i , i is deleted from the set I, and k = k + 1;
[0085] (4) In the verification thread v iOnce it is called to verify the execution sequence slice sg in (1 ≤ i ≤ n), k it will be based on the slice sg k the values of program variables on each state in, explore the extensible paths on the corresponding LNFG G, and obtain the slice sg k the set A corresponding to the extensible paths in the LNFG k , and return (i, A k ) to the scheduling thread s;
[0086] (5) Whenever the scheduling thread s obtains the verification result (k, A i ) of the slice sg k from the verification thread v k , (k, A k ) is added to the map container. The key value of this map container is the subscript of the slice, and the value is the verification result of this slice;
[0087] (6) The scheduling thread s releases the relationship between the slice sg k and the thread v i by L = L - {(k; i)}, and adds i to the set I;
[0088] (7) The results stored in the map container are merged. If a path from the initial node to the ε node can be found in the LNFG, a counterexample path is found, that is, the current execution path of the program does not satisfy the property; if based on the existing results, it can be determined that there is no path from the initial node to the ε node in the LNFG, it means that the current execution path of the program satisfies the property; otherwise, the scheduling thread s will continue to wait for the verification results of more slices.
[0089] To illustrate the feasibility of a runtime verification-based edge server DoS attack detection method developed by the present invention, the DoS attack detection effect of the embodiment was further verified.
[0090] It should be noted that the violation of the PPTL formula Q1 means that the edge server cannot provide services normally. The establishment of the PPTL formula Q2 means that the Smurf attack in the DoS attack is detected. The establishment of the PPTL formula Q3 means that the SYN Flood attack in the DoS attack is detected. The establishment of the PPTL formula Q4 means that the Land attack in the DoS attack is detected. In the experiment, an Android mobile phone was used as the terminal, and 5 PC machines were used as edge servers, and Tencent Cloud provided cloud services.
[0091] It should be noted that the experiment was divided into three groups, and the runtime verification method was implemented using one, three, and five verification threads in the edge server respectively. The length of the execution trace slice for each verification included 1,000 program states. In each group of experiments, after adding a malicious node to the edge computing network, a Smurf attack in the DoS attack was carried out on the edge server. In order to prove the effectiveness of the proposed method and ensure the accuracy of the verification efficiency, the attack was repeated 10 times. Table 1 shows the detection results for the Smurf attack.
[0092] Table 1 Detection Results for the Smurf Attack
[0093]
[0094]
[0095] It should be noted that in Table 1, the first column is the PPTL formula to be verified; the second column represents the verification result given by the verification tool, that is, whether the program satisfies the corresponding PPTL formula. Q1 being "×" indicates that it is detected that the edge server does not provide services normally, Q2 being "√" indicates that the detected attack type is a Smurf attack, Q3 being "×" indicates that the detected attack type is not a SYN Flood attack, and Q4 being "×" indicates that the detected attack type is not a Land attack; the third to fifth columns give the time required for each verification of 1,000 states when using different numbers of verification threads in the edge server. By comparing the verification times given in the third to fifth columns, it can be found that when using three verification threads, the verification efficiency is the highest, while when using five verification threads, the verification efficiency will instead decrease. Generally speaking, in the case of using three verification threads, when the Smurf attack is carried out within 7 seconds, the proposed method for detecting DoS attacks on edge servers based on runtime verification of the present invention can detect the Smurf attack.
[0096] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented in whole or in part in the form of a computer program product, the computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more integrated available media. The available medium may be a magnetic medium (such as a floppy disk, a hard disk, or a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state disk (SSD)).
[0097] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be covered by the protection scope of the present invention.
Claims
1. A method for detecting DoS attacks on edge servers based on runtime verification, characterized in that The method for detecting DoS attacks on edge servers based on runtime verification includes the following steps: Step 1, formally describe the expected behavior of the edge server in the form of PPTL formulas; Step 2, formally describe the DoS attack characteristics of the edge server in the form of PPTL formulas; Step 3, instrument the running program of the edge server for the program variables and program functions involved in the PPTL formulas; Step 4, for the dynamic execution trace of the edge server program, use a parallel runtime verification framework to detect the program running state, and determine whether the edge server is under a DoS attack according to the detection results; The description of the DoS attack characteristics of the edge server includes: Smurf Attack Description Module 1: Note that the atomic proposition send of the PPTL formula Q2 means that the attacked edge server sends a data packet to the broadcast address of the subnet whose destination address is the subnet, and receive means that the attacked device receives a response data packet sent from a host in the subnet; the sub-formula (◇receive) of the PPTL formula Q2 + means that the receive behavior occurs continuously, that is, continuously receives data packets returned by other nodes; the meaning of the PPTL formula Q2 is that there exists a certain state. Starting from this state, although the device does not send data packets, it can continuously receive data packets; SYN Flood Attack Description Module 2: It should be noted that the atomic propositions receive.SYN, send.SYNACK, and receive.ACK in the PPTL formula Q3 respectively represent that the attacked edge server receives a SYN packet, sends a SYN-ACK response packet, and receives an ACK packet; the sub-formula of the PPTL formula Q3 uses (receive.SYN; send.SYNACK) to represent that the behaviors of receiving a SYN packet and sending a SYN-ACK packet occur successively; the meaning of the PPTL formula Q3 is that there exists a certain state, starting from this state, the edge server receives a SYN packet and then sends a SYN-ACK packet, but in all subsequent states, no ACK packet is received; Land attack description module 3: Q4 ≡ ◇(receive.SYN → ◇(send.SYNACK; send.ACK) + ) It should be noted that the atomic propositions receive.SYN, send.SYNACK, and send.ACK in the PPTL formula Q4 respectively represent that the attacked edge server receives a SYN data packet, sends a SYN-ACK response data packet, and sends an ACK data packet; the sub-formula (send.SYNACK; send.ACK) of the PPTL formula Q4 + represents that the actions of sending SYN-ACK data packets and sending ACKs occur continuously; the meaning of the PPTL formula Q4 is that there exists a certain state, starting from which the edge server receives a SYN data packet, and after that, continuously sends SYN-ACK data packets and ACK data packets.
2. The method for detecting DoS attacks on edge servers based on runtime verification according to claim 1, wherein, In Step 1, formally describe the expected behavior of the edge server given by the UML sequence diagram in the form of PPTL formulas.
3. The method for detecting DoS attacks on edge servers based on runtime verification according to claim 1, wherein In Step 2, formally describe the DoS attack behaviors of Smurf, SYN Flood, and Land against the TCP / IP protocol family in the form of PPTL formulas.
4. The method for detecting DoS attacks on edge servers based on runtime verification according to claim 1, characterized in that, In Step 3, for the program variables involved in the PPTL formulas, when the program variable is the left value of an assignment statement in the program, after this assignment statement, instrument the program to obtain the value of the program variable; for the program functions involved in the PPTL formulas, when the program function is called, after this call statement, instrument the program to assign the program variable with the same name as the program function to 1.
5. The method for detecting DoS attacks on edge servers based on runtime verification according to claim 1, wherein In Step 4, for the dynamic execution trace of the edge server program, divide the execution trace into multiple slices; use multiple threads to verify different slices of the execution trace simultaneously to jointly complete the DoS attack detection.
6. A runtime verification-based edge server DoS attack detection system for implementing the runtime verification-based edge server DoS attack detection method according to any one of claims 1 to 5, characterized in that, The system for detecting DoS attacks on edge servers based on runtime verification includes: An expected behavior description module for formally describing the expected behavior of the edge server in the form of PPTL formulas; An attack characteristic description module for formally describing the DoS attack characteristics of the edge server in the form of PPTL formulas; A program instrumentation module for instrumenting the running program of the edge server for the program variables and program functions involved in the PPTL formulas; An attack detection module for using a parallel runtime verification framework to detect the program running state for the dynamic execution trace of the edge server program, and determining whether the edge server is under a DoS attack according to the detection results.
7. A computer device, characterized in that, The computer device includes a memory and a processor. The memory stores a computer program. When the computer program is executed by the processor, the processor executes the method for detecting DoS attacks on edge servers based on runtime verification according to any one of claims 1 to 5, including the following steps: Formalize the expected behavior of the edge server in the form of PPTL formulas; Formalize the DoS attack characteristics of the edge server in the form of PPTL formulas; for the program variables and program functions involved in the PPTL formulas, instrument the program running on the edge server; for the dynamic execution trace of the edge server program, use a parallel runtime verification framework to detect the program running state, and determine whether the edge server is under a DoS attack according to the detection result.
8. A computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the processor executes the method for detecting DoS attacks on edge servers based on runtime verification according to any one of claims 1 to 5, including the following steps: Formalize the expected behavior of the edge server in the form of PPTL formulas; formalize the DoS attack characteristics of the edge server in the form of PPTL formulas; for the program variables and program functions involved in the PPTL formulas, instrument the program running on the edge server; for the dynamic execution trace of the edge server program, use a parallel runtime verification framework to detect the program running state, and determine whether the edge server is under a DoS attack according to the detection result.
9. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the system for detecting DoS attacks on edge servers based on runtime verification as described in claim 6.
10. Application of the method for detecting DoS attacks on edge servers based on runtime verification according to any one of claims 1 to 5 in the field of runtime verification of edge servers.
Citation Information
Patent Citations
Verification method and system during safe running of social network on the basis of source code instrumentation
CN107679400A
Modeling and verification method of neural network system based on MSVL
CN110443348A