Network Attack Information Processing Method, Apparatus, Electronic Device, and Storage Medium

By dynamically adjusting the configuration and resources of the target system and combining with the blockchain network, the problem of insufficient detection of DNS attacks is solved, and the protection efficiency and service data transmission speed are improved.

CN115314231BActive Publication Date: 2025-07-25TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110496008.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-05-07
Publication Date
2025-07-25
Estimated Expiration
2041-05-07

AI Technical Summary

Technical Problem

The prior art cannot effectively detect DNS attacks in the face of randomly changing domain names, resulting in overloading or paralysis of the DNS server, affecting the normal processing of user business data.

Method used

By obtaining the configuration information of the target system, dynamically adjusting the scheduling resources and configuration storage, saving attack events and triggering corresponding defense strategies, processing based on parsing records, and using blockchain network storage and consensus mechanisms to achieve flexible defense strategy triggering.

Benefits of technology

It improves the efficiency of network attack protection, reduces protection delay, and ensures the normal transmission speed of user service data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115314231B_ABST
    Figure CN115314231B_ABST
Patent Text Reader

Abstract

The present invention provides a method for processing network attack information, including: saving attack events in corresponding message queues and changing the scheduling resources and configuration storage information of the target system; when the attack events or the changes in the configuration storage information trigger the scheduling conditions of the target system, polling and reading corresponding scheduling messages, and determining the parsing records that need to be changed based on the scheduling messages; triggering the defense strategy of the target system based on the parsing records that need to be changed, and processing the attack events through the triggered defense strategy. The present invention also provides a device for processing network attack information, an electronic device, and a storage medium. The present invention can flexibly adjust the scheduling resources and configuration storage information of the target system, trigger the defense strategy of the target system, process the attack events through the triggered defense strategy, improve the efficiency of protecting against network attacks, reduce the latency of protecting against network attacks, and ensure the transmission speed of normal business data processing of users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technology of network attack information processing, and particularly to a method, device, system, equipment and storage medium for network attack information processing. Background Art

[0002] In the related art, DNS (Domain Name System) consists of a resolver and a domain name server. The domain name server stores the domain names and corresponding IP addresses of all hosts in the network and has the function of converting domain names into IP addresses. Among them, a domain name must correspond to an IP address, while an IP address does not necessarily have a domain name. On the Internet, domain names and IP addresses correspond one by one. Although domain names are convenient for people to remember, machines only recognize IP addresses. The conversion work between the two is called domain name resolution, and domain name resolution needs to be completed by a dedicated domain name resolution system. DNS is a system for domain name resolution. By setting fixed protected domain names and protection thresholds to detect DNS attack behaviors. For example, the number of domain names matching the protected domain name within a detection period is counted, and this number is compared with the protection threshold. When the threshold is exceeded, it can be determined that a DNS attack has occurred. However, when an attacker uses randomly changing domain names for DNS attacks, since the preset protected domain names are fixed, the number of detected DNS request packets may not trigger the set protection threshold, resulting in the inability to detect DNS attack behaviors, causing the DNS server to be overloaded or even paralyzed. Summary of the Invention

[0003] In view of this, embodiments of the present invention provide a method, device, electronic equipment and storage medium for network attack information processing, which can flexibly adjust the scheduling resources and configured storage information of the target system, trigger the defense strategy of the target system based on the parsing records that need to be changed, process the attack event through the triggered defense strategy, improve the efficiency of protecting against network attacks, reduce the latency of protecting against network attacks, and ensure the transmission speed of normal business data processing of users.

[0004] The technical solution of the embodiments of the present invention is implemented as follows:

[0005] Embodiments of the present invention provide a method for network attack information processing, including:

[0006] Obtain the configuration information of the target system, and dynamically adjust the configuration information of the target system according to the usage environment of the target system;

[0007] Obtain an attack event, save the attack event in a corresponding message queue, and send it to the processing component of the target system through the message queue;

[0008] In response to the attack event obtained by the processing component, change the scheduling resources and configuration storage information of the target system;

[0009] When the attack event or the change in the configuration storage information triggers the scheduling condition of the target system, poll and read the corresponding scheduling messages, and based on the scheduling messages, determine the parsing records that need to be changed;

[0010] Based on the parsing records that need to be changed, trigger the defense strategy of the target system, and process the attack event through the triggered defense strategy.

[0011] An embodiment of the present invention further provides a network attack information processing device, including:

[0012] An information transmission module, configured to obtain the configuration information of the target system, and dynamically adjust the configuration information of the target system according to the usage environment of the target system;

[0013] An information processing module, configured to obtain an attack event, save the attack event in a corresponding message queue, and send it to the processing component of the target system through the message queue;

[0014] The information processing module is configured to, in response to the attack event obtained by the processing component, change the scheduling resources and configuration storage information of the target system;

[0015] The information processing module is configured to, when the attack event or the change in the configuration storage information triggers the scheduling condition of the target system, poll and read the corresponding scheduling messages, and based on the scheduling messages, determine the parsing records that need to be changed;

[0016] The information processing module is configured to, based on the parsing records that need to be changed, trigger the defense strategy of the target system to implement processing of the attack event through the triggered defense strategy.

[0017] In the above solution,

[0018] The information processing module is configured to send the target system configuration information, the attack event, and the attack event processing record to the blockchain network, so that

[0019] The nodes of the blockchain network fill the target system configuration information, the attack event, and the attack event processing record into a new block, and when consensus is reached on the new block, append the new block to the tail of the blockchain.

[0020] An embodiment of the present invention further provides an electronic device, the electronic device includes:

[0021] A memory, configured to store executable instructions;

[0022] A processor, when running the executable instructions stored in the memory, implements the aforementioned network attack information processing method.

[0023] An embodiment of the present invention also provides a computer-readable storage medium storing executable instructions, which, when executed by a processor, implement the aforementioned network attack information processing method.

[0024] The embodiments of the present invention have the following beneficial effects:

[0025] In the present invention, by obtaining the configuration information of the target system, dynamically adjusting the configuration information of the target system according to the usage environment of the target system; obtaining attack events and saving the attack events in a corresponding message queue, and sending the attack events to the processing component of the target system through the message queue; in response to the attack events obtained by the processing component, changing the scheduling resources and configuration storage information of the target system; when the attack events or the changes in the configuration storage information trigger the scheduling conditions of the target system, polling and reading the corresponding scheduling messages, and determining the parsing records that need to be changed based on the scheduling messages; based on the parsing records that need to be changed, triggering the defense strategy of the target system, and processing the attack events through the triggered defense strategy. Thus, it is possible to flexibly adjust the scheduling resources and configuration storage information of the target system, trigger the defense strategy of the target system based on the parsing records that need to be changed, process the attack events through the triggered defense strategy, improve the efficiency of protecting against network attacks, reduce the latency of protecting against network attacks, and ensure the transmission speed of normal business data processing of users. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is a schematic diagram of the usage environment of the network attack information processing method provided by an embodiment of the present invention;

[0027] Figure 2 is a schematic diagram of the composition structure of the network attack information processing device provided by an embodiment of the present invention;

[0028] Figure 3 is a schematic diagram of the configuration effect of the target system in an embodiment of the present invention;

[0029] Figure 4 is an alternative flowchart of the network attack information processing method provided by an embodiment of the present invention;

[0030] Figure 5 is a schematic diagram of the configuration process of the target system in an embodiment of the present invention;

[0031] Figure 6 is a schematic diagram of the configuration process of the target system in an embodiment of the present invention;

[0032] Figure 7 It is a schematic diagram of the configuration process of the target system in the embodiments of the present invention;

[0033] Figure 8 It is a schematic diagram of the configuration process of the target system in the embodiments of the present invention;

[0034] Figure 9 It is a schematic diagram of the network attack information processing process of the target system in the embodiments of the present invention;

[0035] Figure 10 It is a schematic diagram of the architecture of the target object determination device 100 provided in the embodiments of the present invention;

[0036] Figure 11 It is a schematic diagram of the structure of the blockchain in the blockchain network 200 provided in the embodiments of the present invention;

[0037] Figure 12 It is a schematic diagram of the functional architecture of the blockchain network 200 provided in the embodiments of the present invention;

[0038] Figure 13 It is an optional schematic diagram of the network attack information processing process of the network attack information processing method provided in the embodiments of the present application;

[0039] Figure 14 It is an optional flowchart of the network attack information processing method provided in the embodiments of the present application. Detailed implementation manners

[0040] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be construed as limiting the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0041] In the following description, "some embodiments" are involved, which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0042] Before further elaborating on the embodiments of the present invention, the nouns and terms involved in the embodiments of the present invention are described. The nouns and terms involved in the embodiments of the present invention are applicable to the following explanations.

[0043] 1) Target system technology. Target system technology is essentially a technology for deceiving attackers. By deploying decoy hosts, network services or information, it induces attackers to launch attacks on them, thereby enabling the capture and analysis of attack behaviors, understanding the tools and methods used by attackers, inferring attack intentions and motives, enabling the defense side to clearly understand the security threats they face, and enhancing the security protection capabilities of the actual system through technical and management means.

[0044] 2) Terminals, including but not limited to: ordinary terminals, dedicated terminals, where the ordinary terminals maintain long connections and / or short connections with the sending channel, and the dedicated terminals maintain long connections with the sending channel.

[0045] 3) Client, the carrier for implementing specific functions in a terminal. For example, a mobile client (APP) is the carrier for specific functions in a mobile terminal, such as performing the function of online live broadcast or playing online videos.

[0046] 4) In response to, used to represent the conditions or states on which the executed operations depend. When the dependent conditions or states are met, the one or more operations to be executed can be real-time or can have a set delay; without special instructions, there is no restriction on the execution order of the multiple operations to be executed.

[0047] 5) Operating environment, the engine for interpreting and executing code. For example, for the operating environment of a small program, it can be JavaScript Core on the iOS platform or X5 JS Core on the Android platform.

[0048] 6) CNAME, a record in the domain name system, used to map one domain name (the same name) to another domain name (the real name). When the domain name resolution server encounters a CNAME record, it will start a new query with the mapped target.

[0049] 7) DDoS (Denial of Service) attack, a network attack method whose purpose is to exhaust the network or system resources of the target computer, causing the service to be temporarily interrupted or stopped, resulting in its normal users being unable to access. That is, distributed denial of service means that the attacker controls a large number of zombie hosts in a botnet to send a large amount of data to the attack target, exhausting the system resources of the attack target and causing it to be unable to respond to normal service requests.

[0050] 8) Redis database: An open-source, network-supported, memory-based, optionally persistent key-value pair storage database written in ANSI C.

[0051] 9) Blockchain (Block chain), an encrypted, chain-like storage structure formed by blocks (Blocks) of transactions.

[0052] For example, the header of each block can include the hash values of all transactions in the block and also the hash values of all transactions in the previous block, so as to prevent the tampering and forgery of transactions in the block based on the hash values. After the newly generated transactions are filled into the block and consensus is reached among the nodes in the blockchain network, they will be appended to the end of the blockchain to form a chain-like growth.

[0053] 10) Blockchain Network, a set of a series of nodes that incorporate new blocks into the blockchain through consensus.

[0054] In the traditional attack defense process, the CNAME is provided to the customer for parsing the business traffic access, and the cloud assets or cloud native protection are configured to link with the high-defense IP rules. When it is detected that the cloud assets or cloud native protection products are under attack or exceed the maximum protection capacity of the cloud native, the DNS resolution record is modified to direct the traffic to a high-defense IP with stronger protection capabilities for cleaning and protection.

[0055] However, this way of processing attack information is only limited to the protection of products in the cloud server, and the scheduling logic is simple. When the traffic is directed to the high-defense IP, the customer's business may have cross-operator transmission, resulting in increased latency, affecting the processing effect of network attack information and the user experience.

[0056] Figure 1 For the usage scenario schematic diagram of the network attack information processing method provided by the embodiments of the present invention, see Figure 1 , different corresponding clients capable of performing different functions are set on the terminals (including terminal 10-1 and terminal 10-2). Among them, the corresponding clients are that the terminals (including terminal 10-1 and terminal 10-2) obtain different information from the corresponding servers 200 through the network 300 for processing. The server 200 can receive network attack information from different terminals. The terminals are connected to the server 200 through the network 300. The network 300 can be a wide area network or a local area network, or a combination of the two, and uses a wireless link to implement data transmission. Since the terminals may be under network attack during the process of information interaction with the network, a target system can be deployed to trigger the target system defense strategy, and the attack event is processed through the triggered defense strategy to ensure the data security in the server 200 and ensure the normal communication between the terminal 10-1 and terminal 10-2 and the server 200.

[0057] Specifically, the target system provided by this application can be provided through a paid product for anti-DDoS attacks launched by the cloud server network for all users, and supports the execution of the network attack information processing method provided by this application at any source station location. The switching bandwidth of the adapted use environment can reach 900Gbps, that is, it provides a 900Gbps BGP line protection function, which can easily and effectively respond to DDoS attacks and CC (Challenge Collapsar) attacks to ensure stable and normal business. When the website is in a cloud server network, the network attack information processing method provided by this application can be used to trigger the target system defense strategy when games, Internet, finance and other businesses are attacked by large-volume DDoS attacks, and the attacked events are processed through the triggered defense strategy to protect the normal operation of games, Internet, finance and other businesses. Among them, users configure high-defense IP to divert attack traffic to the high-defense IP for cleaning, ensuring the stability and availability of source station services. The high-defense IP of the Border Gateway Protocol BGP (Border Gateway Protocol) can use the public network proxy access method, and support TCP, UDP, HTTP, HTTPS and HTTP2 protocols at the same time, so as to cover various business usage scenarios such as finance, e-commerce, and games through the network attack information processing method provided in this application.

[0058] As an example, the server 200 is used to deploy a network attack information processing device to implement the network attack information processing method provided by the present invention, so as to obtain the configuration information of the target system and dynamically adjust the configuration information of the target system according to the use environment of the target system; obtain the attack event, and save the attack event in the corresponding message queue, and send it to the processing component of the target system through the message queue; in response to the attack event obtained by the processing component, change the scheduling resources and configuration storage information of the target system; when the attack event or the change of the configuration storage information triggers the scheduling condition of the target system, poll and read the corresponding scheduling message, and determine the parsing record that needs to be changed based on the scheduling message; based on the parsing record that needs to be changed, trigger the target system defense strategy, and process the attack event through the triggered defense strategy.

[0059] The structure of the network attack information processing device of the embodiment of the present invention is described in detail below. The network attack information processing device can be implemented in various forms, such as a dedicated terminal with a network attack information processing device processing function, or a server or server group provided with a network attack information processing device processing function, such as a target system deployed in a target system, such as the preceding sequence Figure 1 Server 200 in. Figure 2The figure is a schematic structural diagram of a network attack information processing device provided by an embodiment of the present invention. It can be understood that Figure 2 only the exemplary structure of the network attack information processing device is shown, rather than all structures, and partial or all structures shown can be implemented as needed. Figure 2

[0060] The network attack information processing device provided by an embodiment of the present invention includes: at least one processor 201, a memory 202, a user interface 203, and at least one network interface 204. Each component in the network attack information processing device is coupled together through a bus system 205. It can be understood that the bus system 205 is used to realize the connection and communication between these components. In addition to a data bus, the bus system 205 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, Figure 2 all kinds of buses are labeled as the bus system 205 in

[0061] Among them, the user interface 203 may include a display, a keyboard, a mouse, a trackball, a click wheel, a button, a touchpad, or a touch screen, etc.

[0062] It can be understood that the memory 202 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. The memory 202 in the embodiment of the present invention is capable of storing data to support the operation of a terminal (such as 10-1). Examples of these data include: any computer programs for operating on the terminal (such as 10-1), such as an operating system and application programs. Among them, the operating system includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., for implementing various basic services and processing hardware-based tasks. The application programs may include various application programs.

[0063] In some embodiments, the network attack information processing device provided by an embodiment of the present invention can be implemented in a combination of software and hardware. As an example, the network attack information processing device provided by an embodiment of the present invention may be a processor in the form of a hardware decoding processor, which is programmed to execute the network attack information processing method provided by an embodiment of the present invention. For example, a processor in the form of a hardware decoding processor may employ one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.​

[0064] As an example of the implementation of the network attack information processing device provided by the embodiments of the present invention by combining software and hardware, the network attack information processing device provided by the embodiments of the present invention can be directly embodied as a software module combination executed by the processor 201. The software module can be located in the storage medium, and the storage medium is located in the memory 202. The processor 201 reads the executable instructions included in the software module in the memory 202 and combines the necessary hardware (for example, including the processor 201 and other components connected to the bus 205) to complete the network attack information processing method provided by the embodiments of the present invention.

[0065] As an example, the processor 201 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor can be a microprocessor or any conventional processor, etc.

[0066] As an example of the implementation of the network attack information processing device provided by the embodiments of the present invention by hardware, the device provided by the embodiments of the present invention can be directly implemented by using the processor 201 in the form of a hardware decoding processor. For example, it is executed and implemented by one or more application-specific integrated circuits (ASIC, Application Specific Integrated Circuit), DSP, programmable logic device (PLD, Programmable Logic Device), complex programmable logic device (CPLD, Complex Programmable Logic Device), field programmable gate array (FPGA, Field-Programmable Gate Array) or other electronic components to implement the network attack information processing method provided by the embodiments of the present invention.

[0067] The memory 202 in the embodiments of the present invention is used to store various types of data to support the operation of the network attack information processing device. Examples of these data include: any executable instructions for operating on the network attack information processing device, such as executable instructions. The program for implementing the network attack information processing method of the embodiments of the present invention can be included in the executable instructions.

[0068] In some other embodiments, the network attack information processing device provided by the embodiments of the present invention can be implemented in software. Figure 2The network attack information processing device stored in the memory 202 is shown, which can be software in the form of programs and plug-ins, and includes a series of modules. As an example of a program stored in the memory 202, a network attack information processing device can be included, and the network attack information processing device includes the following software modules: information transmission module 2081 and information processing module 2082. When the software modules in the network attack information processing device are read into the RAM by the processor 201 and executed, the network attack information processing method provided by the embodiment of the present invention will be implemented, wherein the functions of each software module in the network attack information processing device include:

[0069] The information transmission module 2081 is used to obtain the configuration information of the target system and dynamically adjust the configuration information of the target system according to the use environment of the target system.

[0070] The information processing module 2082 is used to obtain attack events, store the attack events in corresponding message queues, and send them to the processing components of the target system through the message queues.

[0071] The information processing module 2082 is used to modify the scheduling resources and configuration storage information of the target system in response to the attack event obtained by the processing component.

[0072] The information processing module 2082 is used to poll and read corresponding scheduling messages when the attack event or the change of configuration storage information triggers the scheduling condition of the target system, and determine the parsing record that needs to be changed based on the scheduling message.

[0073] The information processing module 2082 is used to trigger the target system defense strategy based on the parsing record that needs to be modified, so as to process the attack event through the triggered defense strategy. Figure 2 The network attack information processing device shown in the figure illustrates the network attack information processing method provided by the embodiment of the present invention, in which, reference is made to Figure 3 , Figure 3 This is a schematic diagram of the configuration effect of the target system in the embodiment of the present invention. When the user's cloud assets (such as data in the cloud server or virtual assets such as game equipment) or server group are attacked by large traffic, DNS can be used to schedule to resources with greater protection capabilities, and the optimal line resolution path can be calculated at the same time; or the cloud API scheduling interface can be used to control DNS resolution records and other scenarios, trigger the target system defense strategy, and process the attack event through the triggered defense strategy. Before executing the network attack information processing method provided by this application, the user can Figure 3The interface shown is used to configure scheduling rules, control the parsing switch, and set the DNS ttl value, etc. Among them, TTL (Time-To-Live) is the retention time of a domain name resolution record in the DNS server. When DNS servers around the world receive a resolution request, they will send a resolution request to the NS server (authoritative domain name server) specified by the domain name to obtain the resolution record; after obtaining this record, the record will be saved in the DNS server (recursive domain name server) for a period of time. During this period, if a resolution request for this domain name is received again, the DNS server will no longer send a request to the DNS server, but directly return the record just obtained; and the time this record is retained on the DNS server is the TTL value. In this process, there are two types of domain name DNS. One is the authoritative domain name server. For example, the servers of domain name registrars are all authoritative domain name servers, and the TTL value can only be modified on the authoritative server. The other type of domain name resolution server is the caching DNS server. For example, the DNS servers set by ISPs for Internet access everywhere. Its main function is to cache the domain name resolution results locally for convenient user queries. Through Figure 3 the configuration process shown, the corresponding naming specification (CANME), the corresponding parsing status, the associated IP can be set for the application environment of the target system, and the scheduling mode (different priorities) can be configured.

[0074] After the scheduling rules are configured, refer to Figure 4 , Figure 4 which is an optional process schematic diagram of the network attack information processing method provided by the embodiment of the present invention. It can be understood that Figure 4 the steps shown can be executed by various electronic devices running the network attack information processing device. For example, it can be a server or a server group that can deploy the target system. The server or server group that deploys the target system can execute various types of tasks. For example, it can be a server group for various games. Figure 4 The processing shown specifically includes the following steps:

[0075] Step 401: The network attack information processing device obtains the configuration information of the target system and dynamically adjusts the configuration information of the target system according to the usage environment of the target system.

[0076] Among them, in the process of executing the network attack information processing method provided by this application through the target system, in order to avoid the server from being attacked by the network, the target system can be deployed in the server or server group. Specifically, the corresponding firmware configuration information can be determined according to the usage environment of the target system; according to the firmware configuration information, the matching target system image can be obtained from the target system image cloud server, where the target system image supports the target system structures of different organizational architectures; and different types of target system images are stored in the cloud server. Further, a container is created in the target system, and the target system supporting different organizational architectures is created through the container, so that the attack events on the target system can be captured through the deployed target system, where the attack event refers to the attack behavior initiated by the attacker through the Internet, and one attack behavior corresponds to one attack event.

[0077] Reference Figure 5 , Figure 5 FIG. is a schematic diagram of the configuration process of the target system in the embodiment of the present invention. In the dynamic adjustment of the target system configuration information, when creating a scheduling process, the corresponding resolution record of the target system can be determined; according to the usage environment of the target system, scheduling rule configuration processing is performed on the resolution record domain name corresponding to the resolution record, and the name parameter and survival time parameter of the target system are dynamically adjusted; according to the usage environment of the target system, the scheduling priority corresponding to the resolution record is dynamically adjusted. As Figure 5 shown, the user can first create a scheduling process to generate a user-exclusive CNAME resource. On the home page of this function, all the scheduling resources created by the user are displayed, and information such as the resolution status of the CNAME, the associated IP resources, and the modification time of the operation are also displayed. Then, for the generated CNAME domain name, scheduling rules are configured to modify attribute information such as the name and ttl. High-defense resource IPs and non-high-defense resource IPs under this user can be added to the associated IP resources of the scheduling. The linked high-defense resources cover two product forms: high-defense packages and high-defense IPs. In the non-high-defense resources, the user can customize the input of the IP to be associated and the relevant line attributes. All can be added to the scheduling resource pool of this CNAME.

[0078] Continue to refer to Figure 6 , Figure 6 FIG. is a schematic diagram of the configuration process of the target system in the embodiment of the present invention. After adding all the required scheduling resources, the scheduling priority can be customized. The default priority of the IP initially added to the scheduling resource pool is 100 (taking the priority from 1 to 100 as an example, the smaller the value, the higher the priority). The user can modify the value of the priority to determine the scheduling priority, and at the same time, the user can also manually control whether the IP in the resource pool participates in the resolution scheduling. At the same time, in Figure 6During the configuration of the target system shown in the figure, select the corresponding resource type. Taking high-defense resources as an example, the configured high-defense packages may include the following: 1) Single-IP high-defense package, which provides protection for a server or load balancer corresponding to the target system; 2) Multi-IP high-defense package, also known as shared high-defense package, which can protect multiple servers or load balancers corresponding to the target system. When serving servers of different business types, Figure 6 The configured high-defense IP targets the service server (when the service becomes unavailable after being attacked by a large-volume DDoS attack, the traffic that originally directly accessed the user site will be diverted to the target system BGP high-defense IP protection cluster first, and then the secure business traffic will be returned to the user site after attack cleaning and filtering, thereby ensuring the stability and reliability of the user site.

[0079] refer to Figure 7 , Figure 7 It is a schematic diagram of the configuration process of the target system in an embodiment of the present invention. When the configuration information of the target system is dynamically adjusted, the domain name of the business system corresponding to the target system is adjusted to the resolution record domain name; the configuration completion prompt information is presented to the user through the target system. Specifically, after configuring the scheduling rules, the customer needs to resolve the domain name of the business to the scheduling CNAME domain name. When the IP resources in the scheduling pool are attacked by large traffic, the back-end scheduler will calculate the optimal resolution solution based on the priority configured by the user and the IP line attributes in the resource pool to ensure the stable operation of the customer's business.

[0080] refer to Figure 8 , Figure 8 This is a schematic diagram of the configuration process of the target system in the embodiment of the present invention. Since different business servers have different protection requirements at different business stages, different businesses may be attacked differently at different stages of their life cycle. Taking the processing of network attack information of chess and card games as an example, in the early stage of the launch of a new game, it may be frequently attacked by attacks. Because in the first launch stage of a new game, if it is frequently attacked continuously, the retention rate of game users will be very low, causing great economic losses to the game operator. Therefore, it can be achieved through Figure 8 As shown in the figure, a large number of high-defense resources are configured. For example, a new game can use BGP high-defense IP or BGP high-defense package to cover all public network services. When an attack occurs, the black hole state can be quickly released by increasing the number of protection resources to restore business access. After the new game has been put into operation for a period of time, the binding of high-defense resources can be untied to reduce the cost of using high-defense resources, making the processing of network attack information more flexible.

[0081] Step 402: Acquire an attack event, save the attack event in a corresponding message queue, and send the attack event to a processing component of the target system through the message queue.

[0082] Among them, an attack event can be obtained, and the attack event is sorted through the message queue according to the trigger time of the attack event; according to the type of the target system, the message format of the attack event in the message queue is adjusted to enable the target system to identify the attack event. Since there are various types of attack events, by adjusting the message format of the attack events, rapid processing of the attack events can be achieved, so as to achieve the purpose of accurately identifying the attack events. After the format adjustment is completed, a processing component identifier matching the attack event is determined; according to the processing component identifier, the attack event with the adjusted message format is sent to the processing component of the target system through the message queue, so as to avoid affecting the triggering of the target system's defense strategy due to the message format of the attack event.

[0083] Step 403: The network attack information processing device changes the scheduling resources and configuration storage information of the target system in response to the attack event obtained by the processing component.

[0084] See Figure 9 , Figure 9 FIG. is a schematic diagram of the network attack information processing process of the target system in an embodiment of the present invention. In some embodiments of the present invention, changing the scheduling resources and configuration storage information of the target system in response to the attack event obtained by the processing component can be achieved in the following manner:

[0085] In response to the attack event obtained by the processing component, trigger the intermediate component of the target system; through the database component in the intermediate component, change the scheduling resources of the target system, and through the key-value pair storage database component in the intermediate component, delete or modify the parsing records and time-to-live parameters of the target system. Among them, the scheduling resources and configuration storage and modification include function configurations such as domain name CNAME creation and deletion, TTL value modification, and scheduling resource addition and deletion. The intermediate component mainly includes databases Mysql and Redis. The database mainly stores user-related scheduling configurations, and Redis mainly uses its queue function to decouple the two modules of the function interface and the scheduling logic. When it is determined at the function interface that the scheduling logic update needs to be triggered, Redis will be connected and a scheduling message will be sent to it. When the attack event or the change of the configuration storage information triggers the scheduling condition of the target system, the scheduling logic component of the target system obtains the information in the key-value pair storage database queue through a multi-threaded polling method; when obtaining the scheduling message in the key-value pair storage database queue through a multi-threaded polling method, determine the parsing record that needs to be changed; based on the parsing record that needs to be changed, obtain the corresponding scheduling configuration information; based on the scheduling configuration information, determine the A record of the target parsing to be output. Among them, the attack event or the configuration change triggers the scheduling. The DNS scheduling logic module starts a multi-threaded method to poll and read the Redis queue message. When the scheduling message is read, calculations are performed through an internal algorithm (combining line priority, configuration priority, and enable / disable status). The CNAME that needs to be updated is read through the Redis queue, and the relevant scheduling configuration is retrieved from Mysql. First, calculations are performed according to the configuration priority, and the parsing A resource group is output according to the logic (0 to 100, the lower the number, the higher the priority). According to the line attributes of the IPs in the A resource group, a secondary sorting calculation is performed according to the priority of "Telecom > Unicom > Mobile > Overseas" to output the A record of the target parsing. At the same time, to ensure the effectiveness of DNS parsing, when performing line parsing on resources such as Telecom, Unicom, and Mobile, for the DNS parsing DE1A record, two types of A records (default, corresponding to the parsing line attribute) will be generated for a single IP resource.

[0086] In some embodiments of the present invention, the line attributes of the IP in the resource group of the A record can also be sorted according to the priority information carried in the scheduling configuration information; when the line of the IP in the resource group of the A record is a single IP line, at least two types of A records are generated at the same time. Among them, for cloud network products, the DNSPod cloud API can be called for resolution, and the A record that was last resolved and effective in the Mysql configuration can be pulled for incremental comparison, and the A record that needs to be changed can be calculated and output. At the same time, the cloud resolution API is used to support CNAME resolution A addition, deletion, modification, and query functions to actually modify the CNAME resolution record. Furthermore, when the attack ends or the unblocking operation is performed through the cloud API in the console, the platform attack protection system will be linked to generate a corresponding attack or blocking message. After receiving the message, the scheduling system updates the internal attack flag, and then recalculates the best resolution record based on the existing available resources and priority configuration based on step four, and resolves and takes effect by calling the DNS Pod API.

[0087] Step 404: When the attack event or the change of the configuration storage information triggers the scheduling condition of the target system, the network attack information processing device polls and reads the corresponding scheduling message, and determines the parsing record that needs to be changed based on the scheduling message.

[0088] Step 405: The network attack information processing device triggers the target system defense strategy based on the parsing record that needs to be modified, and processes the attack event through the triggered defense strategy.

[0089] In some embodiments of the present invention, Figure 9 As shown, the diversion location corresponding to the attack event can be determined based on the parsing record that needs to be changed; the attack event is diverted according to the diversion location corresponding to the attack event, so as to achieve high-defense cleaning of the attack event through the resources of the diversion location. Therefore, in the process of high-defense cleaning, the user can flexibly adjust the cleaning threshold according to the attack situation, quickly respond to different types of DDoS attacks, and fully match different users with different business types, so that the network attack information processing method provided in this application can be applicable to more business scenarios.

[0090] In some embodiments of the present invention, when a user of a target system migrates or reconfigures the system, the information stored in the blockchain network can be obtained through the blockchain network service, so as to quickly configure the target system and the network attack information processing device. Among them, the target system configuration information, attack events, and attack event processing records can be sent to the blockchain network, so that the nodes of the blockchain network fill the target system configuration information, attack events, and attack event processing records into a new block, and when consensus is reached on the new block, the new block is appended to the end of the blockchain.

[0091] Among them, the embodiments of the present invention can be implemented in combination with cloud technology. Cloud technology refers to a hosting technology that unifies a series of resources such as hardware, software, and networks within a wide area network or a local area network to achieve data computing, storage, processing, and sharing. It can also be understood as the general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model. The background services of the technical network system require a large amount of computing and storage resources, such as video websites, picture websites, and more portal websites. Therefore, cloud technology needs to be supported by cloud computing.

[0092] It should be noted that cloud computing is a computing model that distributes computing tasks on a resource pool composed of a large number of computing devices, enabling various application systems to obtain computing power, storage space, and information services as needed. The network that provides resources is called the "cloud". The resources in the "cloud" seem to be infinitely expandable to users, and can be obtained at any time, used on demand, expanded at any time, and paid according to usage. As a basic capability provider of cloud computing, a cloud computing resource pool platform will be established, abbreviated as a cloud platform, generally referred to as Infrastructure as a Service (IaaS). Various types of virtual resources are deployed in the resource pool for external customers to choose from. The cloud computing resource pool mainly includes: computing devices (which can be virtual machines, including operating systems), storage devices, and network devices.

[0093] Combined with the foregoing Figure 1 As shown, the data processing method provided by the embodiments of the present invention can be implemented through corresponding cloud devices. For example: terminals (including terminal 10-1 and terminal 10-2) are connected to the server 200 located in the cloud through the network 300. The network 300 can be a wide area network or a local area network, or a combination of the two. It is worth noting that the server 200 can be a physical device or a virtualized device.

[0094] In some embodiments of the present invention, when receiving a data synchronization request from other nodes in the blockchain network, the permission of the other nodes may be verified in response to the data synchronization request; when the permission of the other nodes passes the verification, data synchronization is controlled between the current node and the other nodes, so that the other nodes can obtain target system configuration information, attack events, and attack event handling records.

[0095] In some embodiments of the present invention, in response to a query request, the query request may also be parsed to obtain a corresponding object identifier; according to the object identifier, permission information in a target block in the blockchain network is obtained; the matching degree between the permission information and the object identifier is verified; when the permission information matches the object identifier, corresponding target system configuration information, attack events, and attack event handling records are obtained in the blockchain network; in response to the query instruction, the obtained corresponding target system configuration information, attack events, and attack event handling records are pushed to the corresponding client.

[0096] See Figure 10 , Figure 10 is a schematic architecture diagram of a target object determination device 100 provided by an embodiment of the present invention, including a blockchain network 200 (exemplarily showing consensus nodes 210-1, 210-2, and 210-3), an authentication center 300, a business entity 400, and a business entity 500, which will be described separately below.

[0097] The type of the blockchain network 200 is flexible and diverse. For example, it can be any one of a public chain, a private chain, or a consortium chain. Taking the public chain as an example, the electronic devices of any business entity, such as user terminals and servers, can access the blockchain network 200 without authorization; taking the consortium chain as an example, after obtaining authorization, the electronic devices (such as terminals / servers) under the business entity can access the blockchain network 200, and at this time, they become client nodes in the blockchain network 200.

[0098] In some embodiments, the client node can only be an observer of the blockchain network 200, that is, it provides functions to support business entities to initiate transactions (for example, for storing data on the chain or querying data on the chain). For the functions of the consensus nodes 210 of the blockchain network 200, such as sorting functions, consensus services, and ledger functions, the client node can be default or selectively (for example, depending on the specific business requirements of the business entity) implemented. Thus, the data and business processing logic of the business entity can be migrated to the blockchain network 200 to the greatest extent, and the credibility and traceability of the data and business processing process can be achieved through the blockchain network 200.

[0099] The consensus nodes in the blockchain network 200 receive transactions submitted by client nodes (e.g., the client node 410 belonging to the business entity 400 and the client node 510 belonging to the business entity 500 shown in Figure 10 such as the business entities 400 and 500 shown in Figure 10 ) from different business entities, execute the transactions to update or query the ledger, and various intermediate or final results of the executed transactions can be returned to be displayed in the client nodes of the business entities.

[0100] For example, the client nodes 410 / 510 can subscribe to events of interest in the blockchain network 200, such as transactions occurring in a specific organization / channel in the blockchain network 200. The consensus node 210 pushes corresponding transaction notifications to the client nodes 410 / 510, thereby triggering the corresponding business logic in the client nodes 410 / 510.

[0101] Taking the access of multiple business entities to the blockchain network to manage the determination result of the target object as an example, the exemplary application of the blockchain network is described below.

[0102] Refer to Figure 7 . Among the multiple business entities involved in the management process, for example, the business entity 400 can be a target object determination device based on artificial intelligence, and the business entity 500 can be a display system with a target object determination function. They obtain their respective digital certificates from the certification center 300. The digital certificate includes the public key of the business entity and the digital signature signed by the certification center 300 for the public key and identity information of the business entity. It is used to be attached to the transaction together with the digital signature of the business entity for the transaction and sent to the blockchain network, so that the blockchain network can extract the digital certificate and signature from the transaction, verify the reliability of the message (i.e., whether it has been tampered with) and the identity information of the business entity sending the message. The blockchain network will perform verification based on the identity, such as whether it has the permission to initiate the transaction. The client running on the electronic device (such as a terminal or a server) under the business entity can request to access the blockchain network 200 and become a client node.

[0103] The client node 410 of the service entity 400 is used to obtain the configuration information of the target system, dynamically adjust the configuration information of the target system according to the usage environment of the target system; obtain attack events, save the attack events in the corresponding message queue, and send them to the processing component of the target system through the message queue; in response to the attack events obtained by the processing component, change the scheduling resources and configuration storage information of the target system; when the attack events or the changes in the configuration storage information trigger the scheduling conditions of the target system, poll and read the corresponding scheduling messages, and based on the scheduling messages, determine the parsing records that need to be changed; based on the parsing records that need to be changed, trigger the defense strategy of the target system, and process the attack events through the triggered defense strategy to achieve obtaining corresponding attack events through different types of target systems; send the target system configuration information, attack events, and attack event processing records to the blockchain network 200.

[0104] Among them, to send the target system configuration information, attack events, and attack event processing records to the blockchain network 200, the business logic can be pre-set in the client node 410. When the corresponding target object determination result is formed, the client node 410 automatically sends the target system configuration information, attack events, and attack event processing records to the blockchain network 200. It can also be that the business personnel of the service entity 400 log in to the client node 410, manually package the target system configuration information, attack events, and attack event processing records, and send them to the blockchain network 200. When sending, the client node 410 generates a transaction corresponding to the update operation according to the target system configuration information, attack events, and attack event processing records. The transaction specifies the smart contract that needs to be called to implement the update operation and the parameters passed to the smart contract. The transaction also carries the digital certificate of the client node 410 and the signed digital signature (for example, encrypted using the private key in the digital certificate of the client node 410 to obtain the digest of the transaction), and broadcasts the transaction to the consensus node 210 in the blockchain network 200.

[0105] When the consensus node 210 in the blockchain network 200 receives the transaction, it verifies the digital certificate and digital signature carried by the transaction. After successful verification, according to the identity of the service entity 400 carried in the transaction, it confirms whether the service entity 400 has the transaction permission. Any verification judgment in the digital signature and permission verification will result in the failure of the transaction. After successful verification, the signing node 210 signs its own digital signature (for example, encrypted using the private key of the node 210-1 to obtain the digest of the transaction), and continues to broadcast in the blockchain network 200.

[0106] After the consensus node 210 in the blockchain network 200 receives a transaction with successful verification, it fills the transaction into a new block and broadcasts it. When the consensus node 210 in the blockchain network 200 broadcasts a new block, it conducts a consensus process on the new block. If the consensus is successful, it appends the new block to the tail of the blockchain stored by itself, updates the state database according to the result of the transaction, and executes the transaction in the new block: for a transaction that submits an update of the target system configuration information, attack event, and attack event handling record, a key-value pair including the target system configuration information, attack event, and attack event handling record is added to the state database.

[0107] The business personnel of the business entity 500 log in to the client node 510, input the target object determination result or the target object query request. The client node 510 generates a transaction corresponding to the update operation / query operation according to the target object determination result or the target object query request, specifies the smart contract to be called to implement the update operation / query operation and the parameters passed to the smart contract in the transaction. The transaction also carries the digital certificate of the client node 510 and the signed digital signature (for example, encrypted using the private key in the digital certificate of the client node 510 for the digest of the transaction), and broadcasts the transaction to the consensus node 210 in the blockchain network 200.

[0108] After receiving the transaction, the consensus node 210 in the blockchain network 200 verifies the transaction, fills the block, and reaches a consensus. Then it appends the filled new block to the tail of the blockchain stored by itself, updates the state database according to the result of the transaction, and executes the transaction in the new block: for a transaction that submits an update of a certain target system configuration information, attack event, and attack event handling record, it updates the key-value pair corresponding to the target object determination result in the state database according to the manual recognition result; for a transaction that submits a query of a certain target object determination result, it queries the key-value pair corresponding to the target object determination result from the state database and returns the transaction result.

[0109] It should be noted that Figure 7 exemplarily shows the process of directly uploading the target system configuration information, attack event, and attack event handling record to the chain. However, in some other embodiments, for the case where the data volume of the target object determination result is large, the client node 410 can upload the hash of the target object determination result and the corresponding hash of the target object determination result in pairs to the chain, and store the original target object determination result and the corresponding target object determination result in a distributed file system or database. After the client node 510 obtains the target object determination result and the corresponding target object determination result from the distributed file system or database, it can perform verification in combination with the corresponding hash in the blockchain network 200, thereby reducing the workload of the chain-upload operation.

[0110] For an example of a blockchain, see Figure 11 , Figure 11 which is a schematic structural diagram of a blockchain in the blockchain network 200 provided by an embodiment of the present invention. The header of each block may include the hash value of all transactions in the block and also the hash value of all transactions in the previous block. After the records of newly generated transactions are filled into the block and consensus is reached among the nodes in the blockchain network, they will be appended to the tail of the blockchain to form a chain-like growth. The chain-like structure based on the hash value between blocks ensures the anti-tampering and anti-forgery of the transactions in the block.

[0111] The following describes the exemplary functional architecture of the blockchain network provided by an embodiment of the present invention. See Figure 12 , Figure 12 which is a schematic diagram of the functional architecture of the blockchain network 200 provided by an embodiment of the present invention, including an application layer 201, a consensus layer 202, a network layer 203, a data layer 204, and a resource layer 205, which will be described separately below.

[0112] The resource layer 205 encapsulates the computing resources, storage resources, and communication resources for implementing each node 210 in the blockchain network 200.

[0113] The data layer 204 encapsulates various data structures for implementing the ledger, including a blockchain implemented by files in a file system, a key-value state database, and an existence proof (e.g., a hash tree of transactions in a block).

[0114] The network layer 203 encapsulates functions of a peer-to-peer (P2P) network protocol, a data dissemination mechanism, a data verification mechanism, an access authentication mechanism, and business entity identity management.

[0115] Among them, the P2P network protocol realizes communication between nodes 210 in the blockchain network 200. The data dissemination mechanism ensures the dissemination of transactions in the blockchain network 200. The data verification mechanism is used to realize the reliability of data transmitted between nodes 210 based on cryptographic methods (e.g., digital certificates, digital signatures, public / private key pairs). The access authentication mechanism is used to authenticate the identity of a business entity joining the blockchain network 200 according to the actual business scenario and grant the business entity the permission to access the blockchain network 200 when the authentication is passed. The business entity identity management is used to store the identities of business entities allowed to access the blockchain network 200 and their permissions (e.g., the types of transactions that can be initiated).

[0116] The consensus layer 202 encapsulates the mechanism for nodes 210 in the blockchain network 200 to reach consensus on blocks (i.e., the consensus mechanism), and functions of transaction management and ledger management. The consensus mechanism includes consensus algorithms such as POS, POW, and DPOS, and supports the pluggability of consensus algorithms.

[0117] Transaction management is used to verify the digital signatures carried in the transactions received by node 210, verify the identity information of the business entity, and determine whether it has the permission to conduct transactions based on the identity information (reading relevant information from the business entity identity management); for business entities authorized to access the blockchain network 200, they all have digital certificates issued by the certification authority. The business entity uses the private key in its own digital certificate to sign the submitted transaction, thereby declaring its legal identity.

[0118] Ledger management is used to maintain the blockchain and the state database. For the blocks that reach a consensus, append them to the end of the blockchain; execute the transactions in the blocks that reach a consensus. When the transaction includes an update operation, update the key-value pairs in the state database. When the transaction includes a query operation, query the key-value pairs in the state database and return the query results to the client node of the business entity. Support various dimensions of query operations on the state database, including: querying blocks according to the block vector number (such as the hash value of the transaction); querying blocks according to the block hash value; querying blocks according to the transaction vector number; querying transactions according to the transaction vector number; querying the account data of the business entity according to the account (vector number) of the business entity; querying the blockchain in the channel according to the channel name.

[0119] The application layer 201 encapsulates various services that the blockchain network can implement, including transaction traceability, evidence storage, and verification, etc.

[0120] Next, taking the processing of the DDoS attack received by the game server as an example, the network attack information processing method provided by this application will be further described. Refer to Figure 13 , Figure 13 FIG. is an optional schematic diagram of a network attack information processing process for the network attack information processing method provided by an embodiment of this application. Among them, the scheduling system receives the Http Api / Redis queue and the attack blocking message. The scheduling system uses the Http function interface and the message queue reading module, and executes the following steps by using the middleware (Mysql / Redis):

[0121] Step 1301: Read the Redis message queue and read the relevant database configuration according to the message structure.

[0122] Among them, when processing the DDoS attack received by the game server, the type information of the DDoS attack includes but is not limited to types such as ICMP flood attack, UDP flood attack, and SYN flood attack. Those skilled in the art should understand that the above attack-related information and its acquisition methods are only examples. Other existing or future possible attack-related information or its acquisition methods, if applicable to the present invention, should also be included within the protection scope of the present invention and are hereby incorporated by reference.

[0123] Step 1302: Calculate the prioritized A record group according to the configured priority.

[0124] Among them, the A (Address) record is used to specify the IP address record corresponding to the hostname (or domain name). Users can point the website server under this domain name to their own web server. At the same time, the second-level domain name of the domain name can also be set. The domain name server (DNS, Domain Name System) resolves the A record and can automatically translate the domain name address into an IP address. In this process, the domain name service is an Internet tool that runs the domain name system. The server that executes the domain name service is called a DNS server, and the DNS server is used to answer the queries of the domain name service.

[0125] Step 1303: Perform a secondary calculation process on the prioritized A record group according to the line priority of the resource.

[0126] Among them, according to the line attributes in the target system environment, a secondary sorting calculation can be performed according to the priority of "Telecom > Unicom > Mobile > Overseas" to output the A record of the target resolution. At the same time, to ensure the effectiveness of DNS resolution, when performing line resolution on resources such as Telecom, Unicom, and Mobile, for the DNS resolution DE1A record, two types of A records (default, corresponding to the resolved line attributes) will be generated for a single IP resource.

[0127] Step 1304: Compare the A record after the secondary calculation process with the current A record to determine the incremental output of the changed A record.

[0128] Among them, the A record data will be different according to the lines configured by the user, that is, the user can select different lines to correspond to different A record data. By determining the incremental output of the changed A record, the accuracy and comprehensiveness of the A record can be ensured.

[0129] Step 1305: DNS Pod registers the application programming interface API.

[0130] Among them, data is transmitted through the API service port of the control node of DNS to the network and the workload unit. When executing the network attack information processing method provided in this application, the application programming interface API can be used to deploy internal services such as the network and the workload. The data transmission format is a yaml file to adapt to the usage environment of the target system.

[0131] Step 1306: Add, delete, modify, and query the A record.

[0132] For board games, the attack situation is relatively complex, with a large volume of attack traffic, diverse types, rapid changes, more professional attackers, and a potentially long attack cycle, which can even last for months or over a year in some cases. Therefore, a set of solutions to handle complex situations is required. Through the network attack information processing method provided in this application, targeted change protection strategies can be implemented to achieve the purpose of effective protection.

[0133] Among them, referring to Figure 14 , Figure 14 which is an optional flowchart of the network attack information processing method provided by an embodiment of this application. It is possible to plan whether a game requires independent protection resources according to the game type and whether its own competitive environment is healthy, group different players within the game, and whether different business modules require independent protection; otherwise, multiple services can share protection resources; it is also possible to select the region and line of the protection resources according to the latency requirements. Different services within a game may also have different latency requirements. Specifically, the following steps are included:

[0134] Step 1401: Obtain the high-defense IP resources of the cloud server network and configure the corresponding forwarding rules and scheduling rules.

[0135] Among them, the scheduling rule configures the local IP to be added with the first priority and the obtained high-defense IP resources to be added with the second priority, and the customer business domain name is resolved to the CNAME generated by the scheduling.

[0136] For users of different levels, ordinary users can enjoy 2Gbps protection, and paying users can enjoy 10Gbps protection. When the external network IP of the CVM in the cloud is attacked and exceeds the DDoS basic protection value, IP blocking is triggered, and the blocking duration can be configured to 2 hours. In the case of large traffic attacks, the blocking duration is 24 - 72 hours. In addition to the DDoS basic protection, according to different usage scenarios with reference to Table 1, the cloud server network also launches three different target system defense strategies, namely BGP high-defense packages, BGP high-defense IPs, and chess and card shields, which can meet the needs of users to resist large traffic DDoS attacks.

[0137] Table 1

[0138]

[0139] Step 1402: Obtain the corresponding backhaul IP network segment of the high-defense IP through the cloud server network API and add the local network to the whitelist.

[0140] Thus, it is possible to prevent the service from being accidentally killed due to internal network security rules. At the same time, by configuring the cloud upload bandwidth threshold and cloud download bandwidth threshold locally, different network environments can be adapted, making the attack information processing method provided in this application more flexible.

[0141] Step 1403: When it is detected that the traffic exceeds the cloud upload bandwidth threshold, intelligent scheduling is operated by calling the cloud server network API to turn off the first-priority resolution. At this time, the second-priority A record becomes effective, and the traffic is redirected to the cloud server network high-defense IP for cleaning and protection; at the same time, the in-and-out traffic of the high-defense IP is obtained through the cloud API to generate a data report.

[0142] Among them, when the attack event is a DDoS attack, according to the usage environment of the target system, the original network access traffic corresponding to the target system in the network access traffic is forwarded to obtain the traffic to be cleaned; according to the attack-related information of the DDoS attack, the traffic to be cleaned is cleaned to obtain the clean access traffic corresponding to the original access traffic; the clean access traffic is forwarded to the target system to access the target service in the target system. Specifically, the attack-related information of the DDoS attack may include: the traffic information of the DDoS attack, the status information of the DDoS attack, the type information of the DDoS attack, and the traffic to be cleaned is cleaned, such as retaining the normal data packets in the original access traffic, discarding the data packets that conform to the DDoS attack characteristics in the original access traffic, forwarding the data packets that conform to the DDoS attack characteristics in the traffic to be cleaned to the attack data packet database, and resetting the access links that conform to the DDoS attack characteristics in the traffic to be cleaned to obtain the clean access traffic corresponding to the traffic to be cleaned.

[0143] Step 1404: When it is detected that the incoming traffic is less than the cloud download bandwidth threshold, the cloud server network API is called at this time to enable the first-priority resolution of intelligent scheduling, and the corresponding CNAME is modified to resolve the A record, and the traffic is redirected back to the game server network.

[0144] Beneficial technical effects:

[0145] The present invention obtains the configuration information of a target system, dynamically adjusts the configuration information of the target system according to the usage environment of the target system; obtains attack events, saves the attack events in a corresponding message queue, and sends them to a processing component of the target system through the message queue; in response to the attack events obtained by the processing component, changes the scheduling resources and configuration storage information of the target system; when the attack events or the changes in the configuration storage information trigger the scheduling conditions of the target system, polls and reads corresponding scheduling messages, and determines the parsing records to be changed based on the scheduling messages; based on the parsing records to be changed, triggers the defense strategy of the target system, and processes the attack events through the triggered defense strategy. Thus, it is possible to flexibly adjust the scheduling resources and configuration storage information of the target system, trigger the defense strategy of the target system based on the parsing records to be changed, process the attack events through the triggered defense strategy, improve the efficiency of protecting against network attacks, reduce the latency of protecting against network attacks, and ensure the transmission speed of normal business data processing of users.

[0146] As described above, the above are only embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for processing network attack information, characterized in that The method includes: Obtain the configuration information of the target system, and dynamically adjust the configuration information of the target system according to the usage environment of the target system; Obtain attack events, save the attack events in a corresponding message queue, and send them to the processing component of the target system through the message queue; In response to the attack events obtained by the processing component, change the scheduling resources and configuration storage information of the target system; When the attack events or changes in the configuration storage information trigger the scheduling conditions of the target system, poll and read the corresponding scheduling messages, and based on the scheduling messages, determine the parsing records that need to be changed; Based on the parsing records that need to be changed, obtain the corresponding scheduling configuration information; Based on the priority information carried in the scheduling configuration information, output the resource group of the A record; According to the sorting of the line attributes of the IPs within the resource group, perform a secondary sorting calculation to output the A record of the target parsing; Based on the A record, trigger the defense strategy of the target system, and process the attack events through the triggered defense strategy.

2. The method according to claim 1, wherein The obtaining of the configuration information of the target system and the dynamic adjustment of the configuration information of the target system according to the usage environment of the target system include: Create a scheduling process and determine the corresponding parsing records of the target system; According to the usage environment of the target system, perform scheduling rule configuration processing on the parsing record domain names corresponding to the parsing records, and dynamically adjust the name parameters and survival time parameters of the target system; According to the usage environment of the target system, dynamically adjust the scheduling priority corresponding to the parsing records.

3. The method according to claim 2, characterized in that The method further includes: After the dynamic adjustment of the configuration information of the target system is completed, adjust the domain name of the business system corresponding to the target system to the parsing record domain name; Present a configuration completion prompt message to the user through the target system, so as to display the configuration progress of the target system through the configuration completion prompt message.

4. The method according to claim 1, wherein The obtaining of the attack events, saving the attack events in a corresponding message queue, and sending them to the processing component of the target system through the message queue include: Obtain attack events, and sort the attack events through the message queue according to the trigger time of the attack events; According to the type of the target system, adjust the message format of the attack events in the message queue to enable the target system to identify the attack events; Determine the processing component identifier that matches the attack events; According to the processing component identifier, send the attack events with adjusted message format to the processing component of the target system through the message queue.

5. The method according to claim 1, wherein The responding to the attack events obtained by the processing component and changing the scheduling resources and configuration storage information of the target system includes: In response to the attack events obtained by the processing component, trigger the intermediate component of the target system; Through the database component in the intermediate component, change the scheduling resources of the target system; Delete or modify the parsing records and time-to-live parameters of the target system through the key-value pair storage database component in the intermediate component.

6. The method according to claim 1, characterized in that, When the attack event or the change of the configuration storage information triggers the scheduling condition of the target system, poll and read the corresponding scheduling messages, and based on the scheduling messages, determine the parsing records to be changed, including: When the attack event or the change of the configuration storage information triggers the scheduling condition of the target system, the scheduling logic component of the target system obtains the information in the key-value pair storage database queue through a multi-threaded polling method; When obtaining the scheduling messages in the key-value pair storage database queue through a multi-threaded polling method, determine the parsing records to be changed based on the scheduling messages.

7. The method according to claim 6, characterized in that, The method further includes: When the line of the IP in the resource group of the A record is a single IP line, generate at least two types of A records simultaneously.

8. The method according to claim 1, wherein Based on the A record, trigger the defense strategy of the target system, and process the attack event through the triggered defense strategy, including: Based on the A record, determine the drainage location corresponding to the attack event; According to the drainage location corresponding to the attack event, perform drainage processing on the attack event to achieve high-defense cleaning of the attack event through the resources at the drainage location.

9. The method according to claim 8, wherein The method further includes: When the attack event is a DDoS attack, according to the usage environment of the target system, forward the original access traffic corresponding to the target system in the network access traffic to obtain the access traffic to be cleaned; According to the attack-related information of the DDoS attack, perform traffic cleaning processing on the access traffic to be cleaned to obtain the clean access traffic corresponding to the original access traffic; Forward the clean access traffic to the target system to access the target service in the target system.

10. The method according to claim 1, characterized in that, The method further includes: When different types of target systems obtain corresponding attack events, based on the attack events, capture the records of the access services of the attack events; Based on the records of the access services of the attack events, obtain and parse the network data packets carried by the attack events; Based on the network data packets, determine and monitor the connection behavior of the target system after the attack event invades the target system.

11. The method according to claim 1, characterized in that, The method further includes: According to the usage environment of the target system, determine the corresponding firmware configuration information; According to the firmware configuration information, obtain the matching target system image from the target system image cloud server, where the target system image supports the target system structures of different organizational architectures; Create a container in the target system, and create a target system that supports different organizational architectures through the container to achieve capturing the attack events on the target system through the deployed target system.

12. The method according to any one of claims 1-11, characterized in that The method further includes: Send the target system configuration information, attack events, and attack event processing records to the blockchain network, so that The nodes of the blockchain network fill the target system configuration information, attack events, and attack event processing records into a new block, and when reaching a consensus on the new block, append the new block to the tail of the blockchain.

13. An information processing device for network attacks, characterized in that, The device includes: An information transmission module, configured to obtain configuration information of a target system and dynamically adjust the configuration information of the target system according to the usage environment of the target system; An information processing module, configured to obtain an attack event, save the attack event in a corresponding message queue, and send the attack event to a processing component of the target system through the message queue; The information processing module is configured to change the scheduling resources and configuration storage information of the target system in response to the attack event obtained by the processing component; The information processing module is configured to, when the attack event or the change in the configuration storage information triggers the scheduling condition of the target system, poll and read corresponding scheduling messages, and determine the parsing record to be changed based on the scheduling messages; The information processing module is configured to obtain corresponding scheduling configuration information based on the parsing record to be changed; output a resource group of A records according to the priority information carried in the scheduling configuration information; perform secondary sorting calculation according to the sorting of the line attributes of the IPs in the resource group, and output the A record of the target parsing; The information processing module is configured to trigger a defense strategy of the target system based on the A record, so as to process the attack event through the triggered defense strategy.

14. An electronic device, characterized in that, The electronic device includes: A memory, configured to store executable instructions; A processor, configured to implement the network attack information processing method according to any one of claims 1 to 12 when running the executable instructions stored in the memory.

15. A computer-readable storage medium stores executable instructions, characterized in that, The executable instructions, when executed by the processor, implement the network attack information processing method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • DDoS attack defense system and method based on dynamic transformation

    CN111385235A