An associated authentication defense method, device, electronic device and storage medium
Through the associated authentication defense method, different defense mechanisms and protocol atomic object strategies are associated, which solves the problem of poor defense performance caused by the independence of defense means in the existing technology, and achieves a more efficient and flexible overall defense effect.
Patent Information
- Application Number
- CN202111417521.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-26
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-11-26
AI Technical Summary
When defending against DDOS attacks, the defense methods are independent, resulting in poor defense performance and inability to effectively use a certain defense object as the basis for defense of other defense objects.
Through the association authentication defense method, different defense mechanisms in the horizontal dimension and different protocol atomic object strategies in the vertical dimension are associated to achieve a tighter and flexible overall defense. The specific steps include if the current message meets the static source reputation, the source authentication-free judgment and the source whitelist judgment are made; if the static source reputation is not met, the static purpose reputation judgment and dynamic reputation judgment are made to determine the correlation authentication or release.
Through association authentication, the efficiency of the overall defense system is improved, making the defense more tight and flexible, significantly improving the defense performance, and avoiding the disadvantages caused by the independence of traditional defense methods.
Smart Images

Figure CN114036492B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular, to an associated authentication and defense method, apparatus, electronic device, and storage medium. Background Art
[0002] In the attack against DDOS, it is usually determined whether the current packet is abnormal mainly based on the static characteristics and dynamic behavior of the data packet. When it is determined to be abnormal, some defense measures need to be taken to further determine whether it is an attack. The defense measures here include filter configuration rules, reputation mechanisms, source authentication in protocol objects, speed limiting, etc. Usually, these defense measures are relatively independent, which will have certain disadvantages: after a certain defense object is defended, it cannot be used as the defense basis for another defense object, and the defense performance is poor. Summary of the Invention
[0003] The purpose of the embodiments of the present application is to provide an associated authentication and defense method, apparatus, electronic device, and storage medium, which associates different defense mechanisms in the horizontal dimension and different protocol atomic object strategies in the vertical dimension, making the overall defense more compact and flexible, so that the overall defense system is more efficient, thereby solving the problem of poor defense performance of the existing methods.
[0004] The embodiments of the present application provide an associated authentication and defense method, and the method includes:
[0005] If the current message meets the static source reputation, source authentication exemption judgment and source whitelist judgment are sequentially performed to determine whether to perform associated authentication or release;
[0006] If the current message does not meet the static source reputation, static destination reputation judgment and dynamic reputation judgment are sequentially performed to determine whether to perform associated authentication or release.
[0007] In the above implementation process, different defense mechanisms in the horizontal dimension and different protocol atomic object strategies in the vertical dimension are associated to a certain extent, making the existing overall defense more compact and flexible, so that the overall defense system is more efficient.
[0008] Further, before the step of if the current message meets the static source reputation, source authentication exemption judgment and source whitelist judgment are sequentially performed, the method further includes:
[0009] Count the number of messages;
[0010] If the number of messages is greater than a preset detection threshold, perform associated authentication and defense.
[0011] In the above implementation process, by detecting the number of messages, an abnormal alarm is triggered for defense.
[0012] Further, if the current message meets the static source reputation, source authentication exemption judgment and source whitelist judgment are sequentially performed to determine whether to perform associated authentication or release, including:
[0013] If the current message is source authentication exempt, perform associated authentication;
[0014] If the current message is not source authentication exempt but is in the source whitelist, release it.
[0015] In the above implementation process, the network layer source IP of the current message is detected, the current message added to the whitelist is released, and associated authentication is performed on the current message that is source authentication exempt.
[0016] Further, if the current message does not meet the static source reputation, static destination reputation judgment and dynamic reputation judgment are sequentially performed to determine whether to perform associated authentication or release, including:
[0017] If the current message has static destination reputation, perform preset whitelist judgment to determine whether to release it;
[0018] If the current message does not have static destination reputation but has dynamic reputation, perform filter whitelist and policy whitelist judgments respectively;
[0019] If the current message does not have dynamic reputation, perform associated authentication.
[0020] In the above implementation process, the defense method for associated authentication based on multiple dimensions such as static reputation, dynamic reputation, policy configuration mechanism, and source authentication mechanism is more flexible than traditional defense means, making the existing overall network system more efficient.
[0021] Further, if the current message does not have static destination reputation but has dynamic reputation, perform filter whitelist and policy whitelist judgments respectively, including:
[0022] If the current message is in the filter whitelist, release it;
[0023] If the current message is in the policy whitelist, perform associated authentication.
[0024] In the above implementation process, the messages in the filter whitelist can be directly released. For the policy whitelist, it is necessary to verify whether the source is from the whitelist, so associated authentication is required.
[0025] Further, if the current message does not have dynamic reputation, perform associated authentication, including:
[0026] Perform rule configuration, policy configuration, and source authentication on the associated message of the current message.
[0027] In the above implementation process, a dynamic whitelist is established through associated authentication, and the dynamic whitelist is mainly generated through interactive source authentication of the defense object.
[0028] Further, the rule configuration and policy configuration for the associated messages of the current message include:
[0029] If the associated message is a normal source, add the associated message to the policy whitelist;
[0030] If the protocol atomic object of the associated message is a normal source, add the associated message to the dynamic whitelist, and the dynamic whitelist is generated through interactive source authentication of the defense object.
[0031] In the above implementation process, a dynamic whitelist is generated through interactive source authentication or filtering rules.
[0032] An embodiment of the present application further provides an associated authentication defense device, and the device includes:
[0033] A first judgment module, configured to, if the current message meets the static source reputation, sequentially perform source exemption authentication judgment and source whitelist judgment to determine whether to perform associated authentication or release;
[0034] A second judgment module, configured to, if the current message does not meet the static source reputation, sequentially perform static destination reputation judgment and dynamic reputation judgment to determine whether to perform associated authentication or release.
[0035] In the above implementation process, different defense mechanisms in the horizontal dimension and different protocol atomic object policies in the vertical dimension are associated to a certain extent, making the existing overall defense more compact and flexible, thereby making the overall defense system more efficient.
[0036] An embodiment of the present application further provides an electronic device, and the electronic device includes a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the associated authentication defense method described in any one of the above.
[0037] An embodiment of the present application further provides a readable storage medium, and computer program instructions are stored in the readable storage medium. When the computer program instructions are read and run by a processor, the associated authentication defense method described in any one of the above is executed. Description of the Drawings
[0038] To more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required to be used in the embodiments of the present application. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can also be obtained based on these drawings without creative efforts.
[0039] Figure 1 It is a flowchart of an associated authentication defense method provided by an embodiment of the present application;
[0040] Figure 2 It is a flowchart of traffic detection provided by an embodiment of the present application;
[0041] Figure 3 It is a flowchart of associated authentication defense provided by an embodiment of the present application;
[0042] Figure 4 It is a structural block diagram of an associated authentication defense device provided by an embodiment of the present application;
[0043] Figure 5 It is a structural block diagram of a denial-of-service resistance system provided by an embodiment of the present application;
[0044] Figure 6 It is a structural block diagram of another associated authentication defense device provided by an embodiment of the present application.
[0045] Icon:
[0046] 100 - First judgment module; 101 - Source free authentication judgment module; 102 - Source whitelist judgment module; 200 - Second judgment module; 210 - First whitelist judgment module; 220 - Second whitelist judgment module; 230 - Dynamic reputation judgment module; 300 - Defense module; 400 - Detection module; 500 - Statistics module. Detailed implementation manners
[0047] The following will describe the technical solutions in the embodiments of the present application in combination with the drawings in the embodiments of the present application.
[0048] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.
[0049] Please refer to Figure 1 , Figure 1 It is a flowchart of an associated authentication defense method provided by an embodiment of the present application. This method is applied to a denial-of-service resistance system.
[0050] When the original traffic arrives at the anti-DDoS system, traffic detection is first performed. As Figure 2 shown, it is the flowchart of traffic detection:
[0051] Step S111: Count the number of packets;
[0052] Step S112: If the number of packets is greater than the preset detection threshold, then perform associated authentication defense.
[0053] Compare the currently counted number of packets with the current detection threshold. If the statistical value is greater than the detection threshold, it indicates that an abnormal alarm has been triggered, and defense starts at this time.
[0054] Associated authentication can be classified into associated all authentication whitelists and associated application layer authentication whitelists according to granularity. Among them, the associated object of the associated all authentication whitelist is the whitelist authenticated by all defense mechanisms; the associated object of the associated application layer authentication whitelist is only the whitelist authenticated through application protocol interaction.
[0055] The associated entity can be a certain defense mechanism in the horizontal dimension and a certain specific atomic protocol object or configuration rule in the vertical dimension.
[0056] As Figure 3 shown, it is the flowchart of associated authentication defense. The method specifically includes the following steps:
[0057] Step S100: If the current packet meets the static source reputation, then perform source exemption authentication judgment and source whitelist judgment in sequence to determine whether to perform associated authentication or release;
[0058] This step can specifically include:
[0059] Step S101: If the current packet is source-exempt from authentication, then perform associated authentication;
[0060] Step S102: If the current packet is not source-exempt from authentication but is in the source whitelist, then release it.
[0061] For packets that are not in the source whitelist, i.e., source blacklist, they are directly discarded.
[0062] Step S200: If the current packet does not meet the static source reputation, then perform static destination reputation judgment and dynamic reputation judgment in sequence to determine whether to perform associated authentication or release.
[0063] This step can specifically include:
[0064] Step S210: If the current packet has static destination reputation, then perform preset whitelist judgment to determine whether to release it;
[0065] If it is a preset whitelist, it is directly allowed to pass; if it is a blacklist, it is discarded.
[0066] The preset whitelist here is a whitelist generated based on multiple methods, which is not limited here.
[0067] Step S220: If the current message is not a static destination reputation but a dynamic reputation, then perform judgment on the filter whitelist and the policy whitelist respectively;
[0068] This step may specifically include:
[0069] Step S221: If the current message is in the filter whitelist, it is allowed to pass;
[0070] Step S222: If the current message is in the policy whitelist, perform associated authentication.
[0071] Step S230: If the current message is not a dynamic reputation, perform associated authentication.
[0072] For the associated authentication, specifically:
[0073] Perform rule configuration, policy configuration, and source authentication on the associated message of the current message.
[0074] If the associated message is a normal source, add the associated message to the policy whitelist; if the protocol atomic object of the associated message is a normal source, add the associated message to the dynamic whitelist, and the dynamic whitelist is generated by the interactive source authentication of the defense object.
[0075] In the above defense process, it can be divided into: reputation mechanism, filter mechanism, policy configuration mechanism, and other defense mechanisms from the horizontal dimension according to each independent defense mechanism; from the vertical dimension, it is mainly divided into static reputation, dynamic reputation, different rule configurations, and different protocol atomic object configurations.
[0076] The associated authentication mode mainly includes two modes: associated all authentication whitelists and associated application layer authentication whitelists. Among them, the whitelist is divided into a static whitelist and a dynamic whitelist. The static whitelist is added with preset values manually, and the dynamic whitelist is generated through interactive source authentication or filtering rules.
[0077] The associated authentication mainly improves and processes some defense objects in the protocol atomic objects (such as IP, TCP), and the data messages processed by these defense objects usually do not appear independently, but can only appear after the previous message appears.
[0078] In the defense strategy for the protocol atomic object protocol_object, there are multiple defend_objects. Association authentication can be set for the defend_object, and the defend_object can be associated with the source whitelist.
[0079] When the source of the data packet matches the static whitelist or the filter whitelist in the horizontal dimension, it is directly allowed to pass, and at this time, it will not pass through the processing of the defend_object.
[0080] When the data packet is processed in the protocol atomic object in the policy configuration in the vertical dimension, if it is judged as a normal source after passing through the processing of the defend_object1 and is added to the dynamic whitelist, the dynamic whitelist here is mainly generated through the interactive source authentication of the defend_object1, and there is a valid period for this whitelist. During the valid period, when the subsequent data packets of this source pass through the defend_objdect2, since the association authentication has been configured at this time, then it can be directly considered that the data packet is legal and directly allowed to pass.
[0081] After a period of time, when the dynamic whitelist of a certain source expires, the data packets of the source will be directly discarded when passing through the processing of the defend_object2. This can directly avoid unnecessary subsequent processing and improve the processing efficiency of the data packet.
[0082] Judge whether the source IP of the current packet is added to the whitelist. Among them, the association authentication is mainly used to verify whether the associated packet is in the whitelist, the rule configuration can be used to set the policy whitelist to verify whether the associated packet comes from the whitelist; the policy configuration is used to generate the dynamic whitelist.
[0083] This multi-dimensional association authentication-based defense method can flexibly set the existing defense without causing mis-cleaning of the existing network system in the case of avoiding excessive interactive source authentication, making the overall defense more accurate. The defense method that performs association authentication based on multiple dimensions such as static reputation, dynamic reputation, policy configuration mechanism, and source authentication mechanism is more flexible than traditional defense means, making the existing overall network system more efficient.
[0084] In addition, this method improves the performance of the existing network system to a certain extent and avoids a certain degree of network bandwidth.
[0085] The embodiment of the present application also provides an association authentication defense device, as Figure 4 shown, which is the structural block diagram of the association authentication defense device. This device is applied to the anti-denial-of-service system, and this device corresponds to the defense module of the anti-denial-of-service system, asFigure 5 The structure block diagram of the anti-DDoS system is shown as follows, specifically including:
[0086] The detection module 400 is used to compare the currently counted number of packets with the current detection threshold. If the statistical value is greater than the detection threshold, it indicates that an abnormal alarm has been triggered. At this time, the defense module is notified to start defense.
[0087] The defense module 300 specifically includes:
[0088] The first judgment module 100 is used to, if the current packet meets the static source reputation, sequentially perform source authentication exemption judgment and source whitelist judgment to determine whether to perform associated authentication or release;
[0089] The second judgment module 200 is used to, if the current packet does not meet the static source reputation, sequentially perform static destination reputation judgment and dynamic reputation judgment to determine whether to perform associated authentication or release.
[0090] As Figure 6 shown, it is the structure block diagram of another associated authentication defense device. Among them, the first judgment module 100 includes:
[0091] The source authentication exemption judgment module 101 is used to, if the current packet is source authentication exempt, perform associated authentication;
[0092] The source whitelist judgment module 102 is used to, if the current packet is not source authentication exempt but is in the source whitelist, release it.
[0093] The second judgment module 200 includes:
[0094] The first whitelist judgment module 210 is used to, if the current packet has a static destination reputation, perform a preset whitelist judgment to determine whether to release it;
[0095] If it is in the preset whitelist, it is directly released; if it is in the blacklist, it is discarded.
[0096] The second whitelist judgment module 220 is used to, if the current packet does not have a static destination reputation but has a dynamic reputation, respectively perform filter whitelist and policy whitelist judgments;
[0097] For the specific judgment process, it has been described in the method embodiment and will not be elaborated here.
[0098] The dynamic reputation judgment module 230 is used to, if the current packet does not have a dynamic reputation, perform associated authentication.
[0099] For associated authentication, specifically:
[0100] Perform rule configuration, policy configuration, and source authentication on the associated packets of the current packet.
[0101] If the associated message is a normal source, add the associated message to the policy whitelist; if the protocol atomic object of the associated message is a normal source, add the associated message to the dynamic whitelist, where the dynamic whitelist is generated by the interactive source authentication of the defense object.
[0102] The statistics module 500 is used to mark the data packet messages entering the anti-denial-of-service system, and mark different messages according to different protocols or services, so as to uniformly count the number of messages of different protocol or service types. The subsequent detection module 400 can use this statistical value for comparison.
[0103] An embodiment of the present application also provides an electronic device, which includes a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the above-mentioned associated authentication defense method.
[0104] An embodiment of the present application also provides a readable storage medium, in which computer program instructions are stored. When the computer program instructions are read and run by a processor, the above-mentioned associated authentication defense method is executed.
[0105] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are only illustrative. For example, the flowcharts and block diagrams in the drawings show the possible architectures, functions, and operations of devices, methods, and computer program products according to multiple embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.
[0106] In addition, in each embodiment of the present application, the various functional modules may be integrated together to form an independent part, or each module may exist alone, or two or more modules may be integrated to form an independent part.
[0107] When the above-mentioned functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs.
[0108] The above are only the embodiments of this application and are not used to limit the protection scope of this application. For those skilled in the art, this application can have various changes and modifications. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this application shall be included in the protection scope of this application. It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0109] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by this application and should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0110] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
Claims
1. An associated authentication defense method, characterized in that, the method includes: If the current message meets the static source reputation, source authentication exemption judgment and source whitelist judgment are sequentially performed to determine whether to perform associated authentication or release. Specifically: If the current message is source authentication exemption, perform associated authentication; If the current message is not source authentication exemption but is in the source whitelist, release it; If the current message does not meet the static source reputation, static destination reputation judgment and dynamic reputation judgment are sequentially performed to determine whether to perform associated authentication or release. Specifically: If the current message is static destination reputation, perform preset whitelist judgment to determine whether to release it; If the current message is not static destination reputation but is dynamic reputation, perform filter whitelist and policy whitelist judgments respectively; If the current message is not dynamic reputation, perform associated authentication. Specifically: perform rule configuration, policy configuration, and source authentication on the associated message of the current message.
2. The associated authentication defense method according to claim 1, characterized in that, Before the step of if the current message meets the static source reputation, source authentication exemption judgment and source whitelist judgment are sequentially performed, the method further includes: Count the number of messages; If the number of messages is greater than the preset detection threshold, perform associated authentication defense.
3. The associated authentication defense method according to claim 1, characterized in that, The step of if the current message is not static destination reputation but is dynamic reputation, perform filter whitelist and policy whitelist judgments respectively, includes: If the current message is in the filter whitelist, release it; If the current message is in the policy whitelist, perform associated authentication.
4. The associated authentication defense method according to claim 1, characterized in that, The step of performing rule configuration and policy configuration on the associated message of the current message includes: If the associated message is a normal source, add the associated message to the policy whitelist; If the protocol atomic object of the associated message is a normal source, add the associated message to the dynamic whitelist, and the dynamic whitelist is generated by the interactive source authentication of the defense object.
5. An associated authentication defense device, characterized in that, the device includes: A first judgment module, used to if the current message meets the static source reputation, sequentially perform source authentication exemption judgment and source whitelist judgment to determine whether to perform associated authentication or release; A second judgment module, used to if the current message does not meet the static source reputation, sequentially perform static destination reputation judgment and dynamic reputation judgment to determine whether to perform associated authentication or release; The first judgment module includes: A source authentication exemption judgment module, used to if the current message is source authentication exemption, perform associated authentication; A source whitelist judgment module, used to if the current message is not source authentication exemption but is in the source whitelist, release it; The second judgment module includes: A first whitelist judgment module, used to if the current message is static destination reputation, perform preset whitelist judgment to determine whether to release it; A second whitelist judgment module, used to if the current message is not static destination reputation but is dynamic reputation, perform filter whitelist and policy whitelist judgments respectively; The dynamic reputation judgment module is used to perform associated authentication if the current message is not a dynamic reputation. Specifically: perform rule configuration, policy configuration, and source authentication on the associated messages of the current message.
6. An electronic device, characterized in that, the electronic device includes a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program so that the electronic device executes the associated authentication defense method according to any one of claims 1 to 4.
7. A readable storage medium, characterized in that, computer program instructions are stored in the readable storage medium, and when the computer program instructions are read and run by a processor, the associated authentication defense method according to any one of claims 1 to 4 is executed.
Citation Information
Patent Citations
Web application layer attack detection and defense method based on behavior feature matching and analysis
CN106790292A