A method, device, equipment and storage medium for preventing attacks

By receiving HTTP requests from the client and checking the request header length and window size, and rejecting requests that exceed the threshold, the defense problem of the HTTP2 protocol when facing the application layer denial of service attack is solved, and effective protection of server resources is achieved.

CN114491517BActive Publication Date: 2025-06-06AGRICULTURAL BANK OF CHINA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202210101280.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-27
Publication Date
2025-06-06
Estimated Expiration
2042-01-27

AI Technical Summary

Technical Problem

When facing complex application layer denial of service attacks, the current HTTP2 protocol is difficult to effectively prevent attacks, resulting in exhaustion of server resources and unable to serve legitimate users normally.

Method used

By receiving the HTTP request sent by the client, the request header length and client window size are determined. If the request header length is greater than or equal to the set threshold and the window size is less than the threshold, the HTTP request is rejected, thereby preventing a denial of service attack.

Benefits of technology

It effectively prevents the application layer denial of service attack, ensures the security of server resources, and ensures that normal users can access the server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491517B_ABST
    Figure CN114491517B_ABST
Patent Text Reader

Abstract

The present invention discloses a method, device, equipment and storage medium for preventing attacks. The method comprises: receiving an HTTP request sent by a client; determining the length of the HTTP request header according to the HTTP request; obtaining the window size of the client; if the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, rejecting the HTTP request. Through the technical solution of the present invention, "denial of service attacks" can be prevented, so that normal users can access the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of computer technology, and in particular to an attack prevention method, device, equipment and storage medium. Background Art

[0002] Web services are the most widely used services on the Internet, and the Hypertext Transfer Protocol (HTTP), the basis of Web services, has been constantly developing. With the rapid development of the Internet, the current main versions of the protocol, HTTP / 1.1 and the design of HTTPS protocol serially obtaining resources, can no longer meet the response speed and protocol performance requirements of users and developers. In 2015, the new version of HTTP, HTTP2, has been standardized by RFC and gradually adopted by major websites and browsers. By introducing many new features, the HTTP2 protocol is mainly used to improve the performance of Web communications. The HTTP2 protocol introduces new features such as binary framing, multiplexing, header compression, data flow priority, application layer flow control, and server push. It not only solves the performance-affecting problems such as header blocking in HTTP / 1.1, but also the introduction of some new features can further improve the performance of Web communications. However, the new features of the HTTP2 protocol are often accompanied by new potential security threats. Since the current HTTP2 protocol has been adopted by most mainstream browsers and tens of thousands of websites, the new HTTP2 protocol may have a destructive impact on end users and website servers.

[0003] Denial of Service (DoS) attacks can deny legitimate users access to website resources. They are one of the most destructive attack methods on the current Internet. The main targets are relatively large sites, such as commercial companies, search engines, and government websites. DoS attacks were originally basically targeted at network layer denial of service attacks, using protocols such as TCP, UDP, and ICMP to exhaust the network resources of the target site (including bandwidth, sockets, etc.), thereby achieving the purpose of denying its site services. However, network layer DoS attacks have been studied for many years, and there are relatively mature defense solutions in both industry and academia. Therefore, in order to circumvent these defense solutions, attackers began to design and use more complex application layer denial of service attacks (Application-Level DoS), because this type of attack is more covert and the attack cost is relatively low. Specifically, application layer DoS attacks exhaust all server resources (including not only network resources, but also CPU, memory, I / O bandwidth and other machine resources) through application layer request connections, thereby interfering with or completely denying normal users from accessing the target server. In order to enable normal users to access the target server, how to prevent "denial of service attacks" has become an urgent problem to be solved. Summary of the invention

[0004] The embodiments of the present invention provide an attack prevention method, device, equipment and storage medium, which can prevent "denial of service attacks" and enable normal users to access a server.

[0005] In a first aspect, an embodiment of the present invention provides a method for preventing attacks, including:

[0006] Receive HTTP requests sent by clients;

[0007] Determine the length of the HTTP request header according to the HTTP request;

[0008] Obtaining the window size of the client;

[0009] If the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is smaller than a window size threshold, the HTTP request is rejected.

[0010] Furthermore, it also includes:

[0011] If the length of the HTTP request header is less than the length threshold, and the window size of the client is greater than or equal to the window size threshold, determining a response result according to the HTTP request;

[0012] The response result is sent to the client.

[0013] Further, if the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, rejecting the HTTP request includes:

[0014] Determine the HTTP request header structure parameters according to the HTTP request;

[0015] If the HTTP request header structure parameters include a start frame and at least two connection frames, the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, the HTTP request is rejected.

[0016] Furthermore, receiving the HTTP request sent by the client includes:

[0017] Receive HTTP requests sent by clients based on the HTTP2 protocol.

[0018] Furthermore, before receiving the HTTP request sent by the client, it also includes:

[0019] A transport layer connection is established with the client based on the TCP protocol and the TLS protocol.

[0020] Furthermore, before receiving the HTTP request sent by the client, it also includes:

[0021] Receiving a magic frame and a setting frame sent by the client;

[0022] The window size is sent to the client according to the setting frame, so that the client sends an HTTP request according to the window size.

[0023] In a second aspect, an embodiment of the present invention further provides a device for preventing attacks, the device comprising:

[0024] The receiving module is used to receive the HTTP request sent by the client;

[0025] A first determining module, used to determine the length of the HTTP request header according to the HTTP request;

[0026] An acquisition module, used to acquire the window size of the client;

[0027] The rejection module is used to reject the HTTP request if the length of the HTTP request header is greater than or equal to a length threshold and the window size of the client is less than a window size threshold.

[0028] Furthermore, it also includes:

[0029] A second determination module, configured to determine a response result according to the HTTP request if the length of the HTTP request header is less than a length threshold and the window size of the client is greater than or equal to a window size threshold;

[0030] A sending module is used to send the response result to the client.

[0031] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, any method described in the embodiments of the present invention is implemented.

[0032] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any method described in the embodiments of the present invention.

[0033] The embodiment of the present invention receives an HTTP request sent by a client; determines the length of the HTTP request header according to the HTTP request; obtains the window size of the client; and rejects the HTTP request if the length of the HTTP request header is greater than or equal to a length threshold and the window size of the client is less than a window size threshold, thereby preventing a "denial of service attack" and allowing normal users to access the server. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for use in the embodiments are briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without creative work.

[0035] Figure 1 is a flow chart of a method for preventing attacks in an embodiment of the present invention;

[0036] Figure 2 is a schematic structural diagram of a device for preventing attacks in an embodiment of the present invention;

[0037] Figure 3 is a schematic structural diagram of an electronic device in an embodiment of the present invention;

[0038] Figure 4 It is a schematic diagram of the structure of a computer-readable storage medium containing a computer program in an embodiment of the present invention. DETAILED DESCRIPTION

[0039] The present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the present invention, rather than to limit the present invention. It should also be noted that, for ease of description, only the parts related to the present invention, rather than all structures, are shown in the accompanying drawings. In addition, the embodiments of the present invention and the features in the embodiments may be combined with each other without conflict.

[0040] It should be mentioned before discussing exemplary embodiments in more detail that some exemplary embodiments are described as processes or methods depicted as flow charts. Although the flow charts describe various operations (or steps) as sequential processes, many operations therein can be implemented in parallel, concurrently or simultaneously. In addition, the order of various operations can be rearranged. The process can be terminated when its operation is completed, but can also have additional steps not included in the accompanying drawings. The process can correspond to methods, functions, procedures, subroutines, subprograms, etc. In addition, the embodiments in the present invention and the features in the embodiments can be combined with each other without conflict.

[0041] The term “including” and its variations used in the present invention are open inclusions, that is, “including but not limited to.” The term “based on” means “based at least in part on.” The term “one embodiment” means “at least one embodiment.”

[0042] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings. At the same time, in the description of the present invention, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0043] Figure 1 A flowchart of a method for preventing attacks provided by an embodiment of the present invention. This embodiment can be applied to the situation of preventing "denial of service attacks". The method can be executed by the device for preventing attacks in the embodiment of the present invention. The device can be implemented in software and / or hardware. Figure 1 As shown, the method specifically comprises the following steps:

[0044] S110, receiving an HTTP request sent by a client.

[0045] The HTTP request may be an HTTP request sent by the client based on the HTTP2 protocol.

[0046] Specifically, a transport layer connection is established with the client based on the TCP protocol and the TLS protocol, and before the HTTP2 protocol is formally initiated, a magic frame is first sent as a connection preamble. Then, a setting frame for the entire connection is sent, in which the negotiation parameters are set.

[0047] In a specific example, a three-way handshake of TCP (Transmission Control Protocol) and a handshake of TLS (Transport Layer Security) are performed. Before the HTTP2 protocol is formally initiated, a Magic frame is first sent as a connection preface. Then, a SETTINGS frame for the entire connection is sent in Stream 0. In the SETTINGS frame, the client's window size is determined by setting the negotiated parameters.

[0048] S120: Determine the length of the HTTP request header according to the HTTP request.

[0049] The length of the HTTP request header refers to: the length of a field in the HTTP header, for example, the User-Agent field in the HTTP header.

[0050] Specifically, the method of determining the length of the HTTP request header according to the HTTP request may be: pre-acquiring the fields in the header of the HTTP request, and then acquiring the total length of the fields in the header of the HTTP request.

[0051] S130: Obtain the window size of the client.

[0052] Specifically, the client window size may be acquired by: determining the client window size based on a setting frame sent by the client and feedback information of the server with respect to the setting frame.

[0053] S140: If the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is smaller than a window size threshold, reject the HTTP request.

[0054] The length threshold is a preset threshold, which is not limited in the embodiment of the present invention.

[0055] The window size threshold is a preset window size threshold. It should be noted that if the window size is too small, it is easy to cause an increase in the size of the frame sent by the client.

[0056] It should be noted that if the HTTP2 connection is maintained without being terminated, limiting the attacker's receiving window size as much as possible and increasing the frame size sent by the attacker as much as possible are typical characteristics of a denial of service attack.

[0057] Specifically, if the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is smaller than a window size threshold, the method for rejecting the HTTP request may be: determining the HTTP request header structure parameters according to the HTTP request; if the HTTP request header structure parameters include a start frame and at least two connection frames, the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is smaller than a window size threshold, rejecting the HTTP request.

[0058] In a specific example, in order to solve the problem that the header field in the HTTP request may be too long, the HTTP2 protocol introduces the CONTINUATION frame, which is used as the continuation of the Header header, and a HEADERS header frame can be followed by multiple CONTINUATION frames. Denial of service attack In order to further increase the processing pressure of the target server, a new application layer denial of service attack on the HTTP2 protocol constructs an overlong header field, so that multiple CONTINUATION frames can be sent in one HTTP request, which not only increases the processing time of the target server, but also increases the amount of data it processes. Therefore, when it is detected that the HTTP request header structure parameters include a start frame and at least two connection frames, it means that a denial of service attack is likely to occur.

[0059] Optionally, also include:

[0060] If the length of the HTTP request header is less than the length threshold, and the window size of the client is greater than or equal to the window size threshold, determining a response result according to the HTTP request;

[0061] The response result is sent to the client.

[0062] Specifically, if the length of the HTTP request header is less than the length threshold, and the window size of the client is greater than or equal to the window size threshold, the method for determining the response result according to the HTTP request may be: determining the HTTP request header structure parameters according to the HTTP request; if the HTTP request header structure parameters include a start frame and at least two connection frames, the length of the HTTP request header is less than the length threshold, and the window size of the client is greater than or equal to the window size threshold, determining the response result according to the HTTP request.

[0063] Optionally, if the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, rejecting the HTTP request includes:

[0064] Determine the HTTP request header structure parameters according to the HTTP request;

[0065] If the HTTP request header structure parameters include a start frame and at least two connection frames, the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, the HTTP request is rejected.

[0066] Among them, the HTTP request header structure parameters are the frames included in the HTTP request header. For example, it may be that since the request finally sent by the client in a denial of service attack is in the form of a HEADERS frame and multiple CONTINUATION frames at the stream layer, therefore, if it is determined according to the HTTP request that the HTTP request header structure parameters include a start frame and at least two connection frames, then the HTTP request may have a denial of service attack.

[0067] In a specific example, since the denial of service attack includes the following steps: performing TCP three-way handshake and TLS handshake, before formally initiating the HTTP2 protocol, first send a Magic frame as a connection preface. Then, send a SETTINGS frame for the entire connection in Stream0, in which the negotiated parameters are set to limit the attacker's receiving end window size, and greatly increase the size of the frame sent by the attacker, initiate an application layer HTTP resource request in stream 1, and construct an HTTP request with a very long header through the User-Agent and other fields in the HTTP header, so that the final request is sent to the server in the form of a HEADERS frame and multiple CONTINUATION frames at the stream layer, and then repeatedly initiate HTTP requests in Stream3, 5, ..., (2*n+1) and other odd-numbered streams, and the specific initiation method is shown in the above steps. In order to prevent "denial of service attacks", the embodiments of the present invention need to judge the HTTP request header structure parameters, the length of the HTTP request header and the client's window size. If the HTTP request header structure parameters include a start frame and at least two connection frames, the length of the HTTP request header is greater than or equal to a length threshold, and the client's window size is less than a window size threshold, the HTTP request is rejected.

[0068] Optionally, receiving an HTTP request sent by a client includes:

[0069] Receive HTTP requests sent by clients based on the HTTP2 protocol.

[0070] Specifically, HTTP2 has a multiplexing mechanism. Different from the HTTP / 1.1 protocol, in which one TCP connection can only initiate one HTTP request for application layer resources, HTTP2 introduces a multiplexing mechanism, which allows multiple HTTP requests to be initiated on a single TCP connection, namely, HTTP Stream. The new application layer denial of service attack against the HTTP2 protocol in the embodiment of the present invention utilizes the multiplexing mechanism in the HTTP2 protocol, and increases the number of malicious HTTP requests initiated by the original application layer DoS attack while keeping the number of TCP connections in use unchanged, thereby deepening the impact of the attack on the server.

[0071] Optionally, before receiving the HTTP request sent by the client, it also includes:

[0072] A transport layer connection is established with the client based on the TCP protocol and the TLS protocol.

[0073] Specifically, based on the TCP protocol and the TLS protocol, a TCP three-way handshake and a TLS handshake are performed with the client.

[0074] Optionally, before receiving the HTTP request sent by the client, it also includes:

[0075] Receiving a magic frame and a setting frame sent by the client;

[0076] The window size is sent to the client according to the setting frame, so that the client sends an HTTP request according to the window size.

[0077] The magic frame may be a Magic frame, and the setting frame may be a SETTINGS frame.

[0078] Specifically, the HTTP2 protocol introduces a flow control mechanism at the application layer, which uses SETTINGS and WINDOW_UPDATE frames to implement flow control. In order to exhaust server resources, the strategy used by the denial of service attack is to limit the attacker's receiving end window size as much as possible while maintaining the HTTP2 connection without being terminated, and to increase the size of the frame sent by the attacker as much as possible.

[0079] The denial of service attack exploits the SETTINGS_MAX_CONCURRENT_STREAMS, SETTINGS_INITIAL_WINDOW_SIZE, SETTINGS_MAX_FRAME_SIZE parameters in the SETTINGS frame, and the Window Size Increment field in the WINDOWS_UPDATE frame to consume as much server resources as possible.

[0080] In a specific example, the denial of service attack provided by the embodiment of the present invention includes the following steps:

[0081] (1) According to the requirements of the communication process of the application layer HTTP2 protocol, the TCP three-way handshake and TLS handshake are performed, and the application layer protocol negotiation extension in the TLS handshake process is negotiated to use the "h2" protocol at the application layer, that is, negotiate to use the HTTP2 protocol;

[0082] (2) Before formally initiating the HTTP2 protocol, a Magic frame is first sent as a connection preface. Then, a SETTINGS frame for the entire connection is sent in Stream0. In this SETTINGS frame, the negotiated parameters are set to limit the attacker's receiving end window size and greatly increase the frame size sent by the attacker;

[0083] (3) Initiate an application layer HTTP resource request in stream1, and construct an HTTP request with a very long header using fields such as User-Agent in the HTTP header, so that the final request is sent in the form of a HEADERS frame and multiple CONTINUATION frames at the stream layer;

[0084] (4) Then, in Stream 3, 5, ..., (2*n+1) and other odd-numbered streams, HTTP requests are repeatedly initiated. The specific initiation method is the same as step (3);

[0085] (5) To prevent the target server from rejecting the HTTP request of the stream due to timeout, a WINDOW_UPDATE frame is sent in stream 0 and the window size is increased using the Window Size Increment field;

[0086] (6) Because all the above steps are initiated in one TCP connection, the multiplexing mechanism of HTTP2 communication is utilized to use more TCP connections to repeat the above steps (1) to (5) to initiate HTTP requests.

[0087] The following prevention methods are proposed for the above-mentioned "denial of service attack":

[0088] A transport layer connection is established with the client based on the TCP protocol and the TLS protocol, and a magic frame and a setting frame sent by the client are received; a window size is sent to the client according to the setting frame, so that the client sends an HTTP request according to the window size. The server receives the HTTP request sent by the client, determines the length of the HTTP request header according to the HTTP request, obtains the window size of the client; if the length of the HTTP request header is greater than or equal to the length threshold, and the window size of the client is less than the window size threshold, the HTTP request is rejected.

[0089] The technical solution of this embodiment is to receive an HTTP request sent by a client; determine the length of the HTTP request header according to the HTTP request; obtain the window size of the client; if the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, reject the HTTP request, thereby preventing a "denial of service attack" and allowing normal users to access the server.

[0090] Figure 2 This is a schematic diagram of the structure of a device for preventing attacks provided by an embodiment of the present invention. This embodiment is applicable to the case of preventing attacks. The device can be implemented in software and / or hardware. The device can be integrated in any device that provides the function of preventing attacks, such as Figure 2 As shown, the device for preventing attacks specifically includes: a receiving module 210 , a first determining module 220 , an acquiring module 230 and a rejecting module 240 .

[0091] Wherein, the receiving module is used to receive the HTTP request sent by the client;

[0092] A first determining module, used to determine the length of the HTTP request header according to the HTTP request;

[0093] An acquisition module, used to acquire the window size of the client;

[0094] The rejection module is used to reject the HTTP request if the length of the HTTP request header is greater than or equal to a length threshold and the window size of the client is less than a window size threshold.

[0095] Optionally, also include:

[0096] A second determination module, configured to determine a response result according to the HTTP request if the length of the HTTP request header is less than a length threshold and the window size of the client is greater than or equal to a window size threshold;

[0097] A sending module is used to send the response result to the client.

[0098] The above-mentioned product can execute the method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0099] The technical solution of this embodiment is to receive an HTTP request sent by a client; determine the length of the HTTP request header according to the HTTP request; obtain the window size of the client; if the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, reject the HTTP request, thereby preventing a "denial of service attack" and allowing normal users to access the server.

[0100] Figure 3 A schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. Figure 3 A block diagram of an electronic device 312 suitable for implementing embodiments of the present invention is shown. Figure 3 The electronic device 312 shown is only an example and should not limit the functions and scope of use of the embodiments of the present invention. The device 312 is a typical computing device for trajectory fitting functions.

[0101] like Figure 3 As shown, the electronic device 312 is in the form of a general purpose computing device. The components of the electronic device 312 may include, but are not limited to: one or more processors 316, a storage device 328, and a bus 318 connecting different system components (including the storage device 328 and the processor 316).

[0102] Bus 318 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, an accelerated graphics port, a processor or a local bus using any of a variety of bus architectures. For example, these architectures include but are not limited to Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MCA) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus and Peripheral Component Interconnect (PCI) bus.

[0103] The electronic device 312 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by the electronic device 312, including volatile and non-volatile media, removable and non-removable media.

[0104] The storage device 328 may include computer system readable media in the form of volatile memory, such as random access memory (RAM) 330 and / or cache memory 332. The electronic device 312 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 334 may be used to read and write non-removable, non-volatile magnetic media ( Figure 3 not shown, usually called a "hard drive"). Although Figure 3 Not shown in the figure, a disk drive for reading and writing a removable non-volatile disk (e.g., a "floppy disk"), and an optical disk drive for reading and writing a removable non-volatile optical disk (e.g., a read-only optical disk (Compact Disc-Read Only Memory, CD-ROM), a digital video disk (Digital Video Disc-Read Only Memory, DVD-ROM) or other optical media) may be provided. In these cases, each drive may be connected to the bus 318 via one or more data medium interfaces. The storage device 328 may include at least one program product having a set (e.g., at least one) of program modules that are configured to perform the functions of the various embodiments of the present invention.

[0105] A program 336 having a set (at least one) of program modules 326 may be stored, for example, in a storage device 328, such program modules 326 including, but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment. The program modules 326 generally perform the functions and / or methods of the embodiments described herein.

[0106] The electronic device 312 may also communicate with one or more external devices 314 (e.g., keyboard, pointing device, camera, display 324, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 312, and / or communicate with any device that enables the electronic device 312 to communicate with one or more other computing devices (e.g., network card, modem, etc.). Such communication may be performed through an input / output (I / O) interface 322. In addition, the electronic device 312 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN) and / or a public network, such as the Internet) through a network adapter 320. As shown, the network adapter 320 communicates with other modules of the electronic device 312 through a bus 318. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 312, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, disk arrays (Redundant Arrays of Independent Disks, RAID) systems, tape drives, and data backup storage systems.

[0107] The processor 316 executes various functional applications and data processing by running the programs stored in the storage device 328, such as implementing the method for preventing attacks provided by the above-mentioned embodiment of the present invention.

[0108] Receive HTTP requests sent by clients;

[0109] Determine the length of the HTTP request header according to the HTTP request;

[0110] Obtaining the window size of the client;

[0111] If the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is smaller than a window size threshold, the HTTP request is rejected.

[0112] Figure 4 Schematic diagram of the structure of a computer-readable storage medium containing a computer program in an embodiment of the present invention. The embodiment of the present invention provides a computer-readable storage medium 61 on which a computer program 610 is stored. When the program is executed by one or more processors, the method for preventing attacks provided in all the embodiments of the present invention is implemented:

[0113] Receive HTTP requests sent by clients;

[0114] Determine the length of the HTTP request header according to the HTTP request;

[0115] Obtaining the window size of the client;

[0116] If the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is smaller than a window size threshold, the HTTP request is rejected.

[0117] Any combination of one or more computer-readable media can be used. Computer-readable media can be computer-readable signal media or computer-readable storage media or any combination of the above two. Computer-readable storage media can be, for example, but not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this document, computer-readable storage media can be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device.

[0118] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0119] The program code embodied on the computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0120] In some embodiments, the client and the server may communicate using any currently known or future developed network protocol such as HTTP (Hyper Text Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0121] The computer-readable medium may be included in the electronic device, or may exist independently without being installed in the electronic device.

[0122] Computer program code for performing the operation of the present invention may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0123] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0124] The units involved in the embodiments described in the present disclosure may be implemented by software or hardware, wherein the name of a unit does not, in some cases, limit the unit itself.

[0125] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.

[0126] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0127] Note that the above are only preferred embodiments of the present invention and the technical principles used. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in more detail through the above embodiments, the present invention is not limited to the above embodiments, and may include more other equivalent embodiments without departing from the concept of the present invention, and the scope of the present invention is determined by the scope of the appended claims.

Claims

1. A method to prevent attacks, It is characterized in that include: Receive HTTP requests sent by clients; Determine the length of the HTTP request header according to the HTTP request; The length of the HTTP request header is the length of the field in the HTTP header; Obtaining the window size of the client; If the length of the HTTP request header is greater than or equal to the length threshold, and the window size of the client is less than the window size threshold, rejecting the HTTP request; If the length of the HTTP request header is greater than or equal to the length threshold, and the window size of the client is less than the window size threshold, rejecting the HTTP request includes: Determine the HTTP request header structure parameters according to the HTTP request; If the HTTP request header structure parameters include a start frame and at least two connection frames, the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, the HTTP request is rejected.

2. The method according to claim 1, It is characterized in that Also includes: If the length of the HTTP request header is less than the length threshold, and the window size of the client is greater than or equal to the window size threshold, determining a response result according to the HTTP request; The response result is sent to the client.

3. The method according to claim 1, It is characterized in that Receiving HTTP requests sent by clients includes: Receive HTTP requests sent by clients based on the HTTP2 protocol.

4. The method according to claim 1, It is characterized in that Before receiving the HTTP request sent by the client, it also includes: A transport layer connection is established with the client based on the TCP protocol and the TLS protocol.

5. The method according to claim 1, It is characterized in that Before receiving the HTTP request sent by the client, it also includes: Receiving a magic frame and a setting frame sent by the client; The window size is sent to the client according to the setting frame, so that the client sends an HTTP request according to the window size.

6. A device for preventing attack, It is characterized in that include: The receiving module is used to receive the HTTP request sent by the client; A first determining module, used to determine the length of the HTTP request header according to the HTTP request; The length of the HTTP request header is the length of the field in the HTTP header; An acquisition module, used to acquire the window size of the client; a rejection module, configured to reject the HTTP request if the length of the HTTP request header is greater than or equal to a length threshold and the window size of the client is less than a window size threshold; If the length of the HTTP request header is greater than or equal to the length threshold, and the window size of the client is less than the window size threshold, rejecting the HTTP request includes: Determine the HTTP request header structure parameters according to the HTTP request; If the HTTP request header structure parameters include a start frame and at least two connection frames, the length of the HTTP request header is greater than or equal to a length threshold, and the window size of the client is less than a window size threshold, the HTTP request is rejected.

7. The device according to claim 6, It is characterized in that Also includes: A second determination module, configured to determine a response result according to the HTTP request if the length of the HTTP request header is less than a length threshold and the window size of the client is greater than or equal to a window size threshold; A sending module is used to send the response result to the client.

8. An electronic device, It is characterized in that include: one or more processors; A memory for storing one or more programs; When the one or more programs are executed by the one or more processors, the processors are enabled to implement the method according to any one of claims 1 to 5.

9. A computer-readable storage medium containing a computer program, wherein the computer program is stored on the medium. It is characterized in that When the program is executed by one or more processors, the method according to any one of claims 1 to 5 is implemented.

Citation Information

Patent Citations

  • Attack detection device, attack detection method, and attack detection program

    CN106471778A

  • DDOS attack detection and defense method and device, terminal equipment and storage medium

    CN111181932A

  • Systems and methods for aggressive window probing

    US20110131654A1