A message processing method, apparatus, device, and machine-readable storage medium
By checking the cookie information in the IP option field in the network device, filtering out unauthenticated or illegal packets, the impact of DDoS attacks on the CPU of the security device is solved, and the stability and processing capabilities of the device are improved.
Patent Information
- Application Number
- CN202210874079.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-25
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2042-07-25
AI Technical Summary
DDoS attacks cause CPU impact on security equipment, affecting normal service processing, and the existing technology is difficult to effectively filter unauthorized or illegal messages, resulting in device stability and load problems.
After receiving the message to be forwarded, the network device checks whether the IP option field carries legitimate cookie information, and only sends packets with legitimate cookie information to the CPU of the security device to filter out unauthorized or illegal packets.
It improves the stability of security equipment, reduces the burst shocks and load of the CPU, and avoids the impact on normal business.
Smart Images

Figure CN115442070B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technologies, and in particular, to a method, apparatus, device, and machine-readable storage medium for message processing. Background Art
[0002] A DDoS (Distributed Denial of Service) attack is a type of attack behavior that utilizes hosts or servers distributed across the Internet, aiming to temporarily or permanently paralyze the network service capabilities of a target.
[0003] A UDP flood attack refers to an attacker sending a large number of UDP messages to a specific target within a short period of time, occupying the bandwidth of the target host and causing the target host to be unable to handle normal services.
[0004] DDoS attacks usually manifest as message floods from different sources. These malicious messages will occupy the network resources of the attack target, causing network congestion and increasing the burden on its processor, thereby preventing normal user requests from being effectively responded to.
[0005] The distributed nature of DDoS attacks gives them a larger attack traffic and stronger concealment than traditional DoS (Denial of Service) attacks. Therefore, detecting and preventing DDoS attacks will be more difficult.
[0006] Currently, the security services of security devices need to be sent to the CPU for processing. Illegal IP messages will impact the CPU of the security device and affect normal services. Summary of the Invention
[0007] In view of this, the present disclosure provides a method, apparatus, electronic device, and machine-readable storage medium for message processing to improve the problem that the CPU of the above-mentioned security device is impacted and normal services are affected.
[0008] Specific technical solutions are as follows:
[0009] The present disclosure provides a method for message processing, which is applied to a network device. The method includes: receiving a message to be forwarded sent by a client device; checking whether the IP option field of the message to be forwarded has cookie information, and extracting the cookie information of the message to be forwarded whose IP option field has cookie information; checking the legality of the extracted cookie information, and forwarding the message to be forwarded with legal cookie information to the CPU of the security device; discarding the message whose IP option field does not have cookie information, and discarding the message whose cookie information in the IP option field is illegal.
[0010] As a technical solution, the cookie information is generated by the security management device in response to a request from the client device, and is sent to the network device and the client device, and is filled by the client device into the IP option field of the packet to be forwarded.
[0011] The present disclosure also provides a packet processing method, which is applied to a client device. The method includes: requesting and obtaining cookie information from a security management device; filling the cookie information in the IP Option field of the packet to be forwarded; sending the packet to be forwarded to a network device; the network device is configured to receive the packet to be forwarded sent by the client device, and forward the packet to be forwarded to the CPU of the security device after checking that the cookie information in the IP option field is legal.
[0012] As a technical solution, the cookie information is generated by the security device in response to a request from the client device and is sent to the network device and the client device.
[0013] The present disclosure also provides a packet processing apparatus, which is applied to a network device. The apparatus includes: a receiving module, configured to receive the packet to be forwarded sent by the client device; an inspection module, configured to check whether the IP option field of the packet to be forwarded has cookie information, and extract the cookie information of the packet to be forwarded whose IP option field has cookie information; a processing module, configured to check the legality of the extracted cookie information, and forward the packet to be forwarded with legal cookie information to the CPU of the security device; a discard module, configured to discard the packet whose IP option field does not have cookie information, and discard the packet whose cookie information in the IP option field is illegal.
[0014] As a technical solution, the cookie information is generated by the security management device in response to a request from the client device, and is sent to the network device and the client device, and is filled by the client device into the IP option field of the packet to be forwarded.
[0015] The present disclosure also provides a packet processing apparatus, which is applied to a client device. The apparatus includes: a request module, configured to request and obtain cookie information from a security management device; a filling module, configured to fill the cookie information in the IPOption field of the packet to be forwarded; a sending module, configured to send the packet to be forwarded to a network device; the network device is configured to receive the packet to be forwarded sent by the client device, and forward the packet to be forwarded to the CPU of the security device after checking that the cookie information in the IP option field is legal.
[0016] As a technical solution, the cookie information is generated by the security device in response to a request from the client device and sent to the network device and the client device.
[0017] The present disclosure also provides an electronic device, including a processor and a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the foregoing message processing method.
[0018] The present disclosure also provides a machine-readable storage medium. The machine-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by the processor, the machine-executable instructions cause the processor to implement the foregoing message processing method.
[0019] The above technical solutions provided by the present disclosure at least bring the following beneficial effects:
[0020] After a network device such as a switch receives a message to be forwarded, it first checks whether the IP option field carries legal cookie information, and then sends the message to be forwarded with legal cookie information only to the CPU of the security device, thereby filtering out a large part of unauthenticated or illegal messages, reducing various attacks, miscellaneous packets, or messages sent to the CPU of the security device for processing due to routing configuration errors, etc., improving the stability of the security device, reducing the sudden impact and load on the CPU of the security device, and avoiding affecting other services. Description of the Drawings
[0021] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following will briefly introduce the drawings required for describing the embodiments of the present disclosure or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present disclosure. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings of the embodiments of the present disclosure.
[0022] Figure 1 is a flowchart of the message processing method in an embodiment of the present disclosure;
[0023] Figure 2 is a flowchart of the message processing method in an embodiment of the present disclosure;
[0024] Figure 3 is a structural diagram of the message processing device in an embodiment of the present disclosure;
[0025] Figure 4 is a structural diagram of the message processing device in an embodiment of the present disclosure;
[0026] Figure 5 It is a hardware structure diagram of an electronic device in an embodiment of the present disclosure. Specific embodiments
[0027] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments and do not limit the present disclosure. The singular forms "a", "the", and "said" used in the present disclosure and the claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to any or all possible combinations of one or more of the associated listed items.
[0028] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present disclosure to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present disclosure, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "when" or "while" or "in response to a determination".
[0029] Most flood attack detections are based on source IP or destination IP threshold detections. Flood attack prevention based on source IP statistics: This method monitors the packet rate from a certain IP address. When the rate continuously reaches or exceeds the specified trigger threshold, it is considered that a server has been attacked. The device then enters the attack prevention state and starts corresponding prevention measures according to the configuration (outputting an alarm log or discarding subsequent packets). Thereafter, when the device monitors that the packet rate from this IP address is lower than the recovery threshold, it is considered that the attack has ended. The device resumes from the attack prevention state to the attack detection state and stops executing the prevention measures. Flood attack prevention based on destination IP statistics: This method monitors the rate of sending packets to a certain server. When the rate continuously reaches or exceeds the specified trigger threshold, it is considered that the server has been attacked. The device then enters the attack prevention state and starts corresponding prevention measures according to the configuration (outputting an alarm log, discarding subsequent packets, or performing client verification). Thereafter, when the device monitors that the rate of sending packets to this server is lower than the recovery threshold, it is considered that the attack has ended. The device resumes from the attack prevention state to the attack detection state and stops executing the prevention measures.
[0030] The DDOS attack interception is detected based on a threshold or according to the fingerprint of the packet. Whether it is identified based on a threshold or a fingerprint, the packet will be sent to the CPU, consuming CPU resources. This protects the server by consuming the resources of the front-end security device of the server. However, when the DDOS attack is very large or the DDOS attack is completely random and cannot be identified based on traditional thresholds or fingerprints, it will cause the front-end security device of the server to crash, making it difficult for the internal server to provide services externally. The security policies, ACLs, and DDOS interception services of the security device generally need to be sent to the CPU for processing. When the device receives a large number of packets that need to be processed by other devices, the CPU of the device will be busy processing these services, affecting normal service processing.
[0031] In view of this, the present disclosure provides a packet processing method, apparatus, electronic device, and machine-readable storage medium to improve the problem that the CPU of the above-mentioned security device is impacted and affects normal services.
[0032] Specifically, the technical solution is as follows.
[0033] In one implementation, the present disclosure provides a packet processing method applied to a network device. The method includes: receiving a packet to be forwarded sent by a client device; checking whether the IP option field of the packet to be forwarded has cookie information, and extracting the cookie information of the packet to be forwarded whose IP option field has cookie information; checking the legality of the extracted cookie information, and forwarding the packet to be forwarded with legal cookie information to the CPU of the security device; discarding the packet whose IP option field does not have cookie information, and discarding the packet whose cookie information in the IP option field is illegal.
[0034] Specifically, as Figure 1 , it includes the following steps:
[0035] Step S11, receiving a packet to be forwarded sent by a client device;
[0036] Step S12, checking whether the IP option field of the packet to be forwarded has cookie information, and extracting the cookie information of the packet to be forwarded whose IP option field has cookie information;
[0037] Step S13, checking the legality of the extracted cookie information, and forwarding the packet to be forwarded with legal cookie information to the CPU of the security device;
[0038] Step S14: discarding the message with no cookie information in the IP option field and discarding the message with illegal cookie information in the IP option field.
[0039] After receiving a packet to be forwarded, a network device such as a switch first checks whether the IP option field carries valid cookie information. It then sends only the packets with valid cookie information to the CPU of the security device. This filters out a large portion of unauthenticated or illegal packets, reducing the number of packets sent to the CPU for processing due to various attacks, miscellaneous packets, or routing errors. This improves the stability of the security device, reduces sudden impacts and load on the CPU, and avoids affecting other services.
[0040] In one embodiment, the cookie information is generated by the security management device in response to a request from the client device, sent to the network device and the client device, and filled into the IP option field of the message to be forwarded by the client device.
[0041] In one embodiment, the present disclosure also provides a message processing method, which is applied to a client device, and the method includes: requesting and obtaining cookie information from a security management device; filling in the cookie information in the IP Option field of the message to be forwarded; sending the message to be forwarded to a network device; the network device is used to receive the message to be forwarded sent by the client device, and after checking that the cookie information in the IP option field is legal, forward the message to be forwarded to the CPU of the security device.
[0042] Specifically, if Figure 2 , including the following steps:
[0043] Step S21, requesting and obtaining cookie information from the security management device;
[0044] Step S22, filling the cookie information in the IP Option field of the message to be forwarded;
[0045] Step S23: Send the message to be forwarded to the network device.
[0046] After a network device such as a switch receives a packet to be forwarded, it first checks whether the IP option field carries legal cookie information, and then sends the packet to be forwarded with legal cookie information to the CPU of the security device, thereby filtering out a large number of unauthenticated or illegal packets, reducing various attacks, miscellaneous packets, or packets sent to the CPU of the security device for processing due to reasons such as incorrect routing configuration, improving the stability of the security device, reducing the sudden impact and load on the CPU of the security device, and avoiding affecting other services.
[0047] In one embodiment, the cookie information is generated by the security device in response to a request from the client device and sent to the network device and the client device.
[0048] In one embodiment, a client software is installed on the PC side. When the PC initiates a connection to the server, it first obtains a cookie from the security authentication center and fills the cookie into the IP Option field. When the security device FW on the server side receives a packet, it first uses the switching chip to extract the IP option field and compare the cookie of the security authentication center to verify the legality of the packet. If the cookies are consistent, the packet is allowed to be sent to the CPU for other services; if they are inconsistent, the packet is discarded.
[0049] In one embodiment, the present disclosure also provides a packet processing device, such as Figure 3 , which is applied to a network device. The device includes: a receiving module 31 for receiving a packet to be forwarded sent by a client device; an inspection module 32 for checking whether the IP option field of the packet to be forwarded has cookie information and extracting the cookie information of the packet to be forwarded whose IP option field has cookie information; a processing module 33 for checking the legality of the extracted cookie information and forwarding the packet to be forwarded with legal cookie information to the CPU of the security device; and a discard module 34 for discarding a packet whose IP option field does not have cookie information and discarding a packet whose cookie information in the IP option field is illegal.
[0050] In one embodiment, the cookie information is generated by the security management device in response to a request from the client device, sent to the network device and the client device, and filled into the IP option field of the packet to be forwarded by the client device.
[0051] In one embodiment, the present disclosure also provides a packet processing device, such as Figure 4, applied to a client device, the apparatus includes: a request module 41, configured to request and obtain cookie information from a security management device; a filling module 42, configured to fill the cookie information in the IP Option field of the packet to be forwarded; a sending module 43, configured to send the packet to be forwarded to a network device; the network device is configured to receive the packet to be forwarded sent by the client device, and after checking that the cookie information in the IP option field is legal, forward the packet to be forwarded to the CPU of the security device.
[0052] In one embodiment, the cookie information is generated by the security device in response to a request from the client device and sent to the network device and the client device.
[0053] The device embodiments are the same as or similar to the corresponding method embodiments, and will not be elaborated herein.
[0054] In one embodiment, the present disclosure provides an electronic device, including a processor and a machine-readable storage medium, the machine-readable storage medium stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the foregoing packet processing method. From a hardware perspective, the schematic diagram of the hardware architecture can be seen Figure 5 as shown.
[0055] In one embodiment, the present disclosure provides a machine-readable storage medium, the machine-readable storage medium stores machine-executable instructions, and when the machine-executable instructions are called and executed by a processor, the machine-executable instructions cause the processor to implement the foregoing packet processing method.
[0056] Here, the machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be: RAM (Radom Access Memory, random access memory), volatile memory, non-volatile memory, flash memory, storage drive (such as a hard disk drive), solid state drive, any type of storage disk (such as an optical disk, DVD, etc.), or a similar storage medium, or a combination thereof.
[0057] The systems, apparatuses, modules or units described in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, and the specific form of the computer can be a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver device, a game console, a tablet computer, a wearable device, or a combination of any several of these devices.
[0058] For the convenience of description, when describing the above device, various units are described separately according to their functions. Of course, when implementing the present disclosure, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0059] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, a system, or a computer program product. Therefore, the present disclosure can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0060] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, as well as the combination of processes and / or blocks in the flowchart and / or block diagram. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0061] Moreover, these computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0062] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0063] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, a system, or a computer program product. Therefore, the present disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (which may include, but are not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0064] The above are only the embodiments of the present disclosure and are not intended to limit the present disclosure. For those skilled in the art, various changes and modifications can be made to the present disclosure. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present disclosure should be included within the scope of the claims of the present disclosure.
Claims
1. A message processing method, characterized in that, Applied to a network device, the method includes: Receiving a packet to be forwarded sent by a client device; Checking whether the IP option field of the packet to be forwarded has cookie information, and extracting the cookie information of the packet to be forwarded whose IP option field has cookie information; Checking the legality of the extracted cookie information, and forwarding the packet to be forwarded with legal cookie information to the CPU of the security device; Discarding the packet whose IP option field does not have cookie information, and discarding the packet whose cookie information in the IP option field is illegal.
2. The method according to claim 1, wherein The cookie information is generated by the security management device in response to a request from the client device, and is sent to the network device and the client device, and is filled by the client device into the IP option field of the packet to be forwarded.
3. A message processing method, characterized in that, Applied to a client device, the method includes: Requesting and obtaining cookie information from the security management device; Filling the cookie information in the IP Option field of the packet to be forwarded; Sending the packet to be forwarded to the network device; The network device is used to receive the packet to be forwarded sent by the client device, and after checking that the cookie information in the IP option field is legal, forward the packet to be forwarded to the CPU of the security device.
4. The method according to claim 3, characterized in that, The cookie information is generated by the security device in response to a request from the client device and sent to the network device and the client device.
5. A message processing device, characterized in that, Applied to a network device, the apparatus includes: A receiving module, configured to receive a packet to be forwarded sent by a client device; An inspection module, configured to check whether the IP option field of the packet to be forwarded has cookie information, and extract the cookie information of the packet to be forwarded whose IP option field has cookie information; A processing module, configured to check the legality of the extracted cookie information, and forward the packet to be forwarded with legal cookie information to the CPU of the security device; A discard module, configured to discard the packet whose IP option field does not have cookie information, and discard the packet whose cookie information in the IP option field is illegal.
6. The device according to claim 5, wherein The cookie information is generated by the security management device in response to a request from the client device, and is sent to the network device and the client device, and is filled by the client device into the IP option field of the packet to be forwarded.
7. A message processing device, characterized in that, Applied to a client device, the apparatus includes: A request module, configured to request and obtain cookie information from the security management device; A filling module, configured to fill the cookie information in the IP Option field of the packet to be forwarded; A sending module, configured to send the packet to be forwarded to the network device; The network device is used to receive the packet to be forwarded sent by the client device, and after checking that the cookie information in the IP option field is legal, forward the packet to be forwarded to the CPU of the security device.
8. The device according to claim 7, characterized in that, The cookie information is generated by the security device in response to a request from the client device and sent to the network device and the client device.
9. An electronic device, characterized in that, Comprising: A processor and a machine-readable storage medium, the machine-readable storage medium storing machine-executable instructions that can be executed by the processor, and the processor executing the machine-executable instructions to implement the method according to any one of claims 1-4.
10. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores machine-executable instructions, and when the machine-executable instructions are called and executed by a processor, the machine-executable instructions cause the processor to implement the method according to any one of claims 1-4.
Citation Information
Patent Citations
Network attack detection method, device, equipment and storage medium
CN113746786A
Systems and methods for protecting against denial of service attacks
US20100031315A1