Service attack processing method and device, computer device and storage medium thereof
By performing risk detection and threat intelligence assessment on DNS query request traffic data, the threat level of the problematic access source is determined, and appropriate processing rules are selected. This solves the problem of resource waste caused by DNS denial-of-service attacks in existing technologies, and realizes the rational allocation and diversified processing of resources.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- INDUSTRIAL AND COMMERCIAL BANK OF CHINA
- Filing Date
- 2022-09-21
- Publication Date
- 2026-04-21
AI Technical Summary
Existing methods for blocking denial-of-service attacks on DNS query requests lack flexibility, leading to wasted resources.
By performing threat detection on the traffic data to be detected, the source of the problem access is identified, and based on the threat intelligence and processing rules of the problem access source, the target processing rules are determined and the appropriate processing method is selected.
It enables the selection of different processing rules based on the different threat intelligence of the problem access source, and reasonably allocates blocking resources to avoid resource waste.
Smart Images

Figure CN115567270B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of artificial intelligence technology, and in particular to a service attack processing method, apparatus, computer device and its storage medium. Background Technology
[0002] With the development of internet technology, enterprise internet security has received increasing attention. In order to prevent enterprises from being attacked by problematic access sources, it is often necessary to conduct service attack detection on enterprises to ensure their internet security.
[0003] In existing technologies, traffic data is subjected to danger detection. Once a problematic access source is identified among the sources sending the traffic data, the problematic access source is blocked.
[0004] However, existing blocking methods lack flexibility, resulting in wasted resources when blocking problematic access sources. Summary of the Invention
[0005] Therefore, it is necessary to provide a service attack handling method, apparatus, computer equipment, and storage medium to address the aforementioned technical problems.
[0006] Firstly, this application provides a method for handling service attacks. The method includes:
[0007] Based on pre-set detection standards, perform hazard detection on the traffic data to be detected;
[0008] If the danger detection of the traffic data to be detected fails, the problematic access source of the traffic data to be detected is determined;
[0009] Based on the threat intelligence and processing rules of the problematic access source, a target processing rule is determined, and the problematic access source is processed according to the target processing rule.
[0010] In one embodiment, the processing rule may include a pre-set high-risk threshold, and the determination of the target processing rule based on the threat intelligence and processing rules of the problematic access source includes:
[0011] Based on the high-risk threshold, the threat intelligence of the problematic access source is assessed to determine its threat level.
[0012] Based on the threat level, the target processing rule is determined in the processing rules.
[0013] In one embodiment, the step of assessing the threat intelligence of the problematic access source and determining the threat level of the problematic access source includes:
[0014] Determine whether the threat intelligence from the source of the problem meets the preset high-risk conditions;
[0015] If the threat intelligence of the problem access source meets the high-risk condition, the threat level of the problem access source is determined to be high-risk;
[0016] If the threat intelligence of the problematic access source does not meet the high-risk condition, the threat level of the problematic access source is determined to be non-high-risk.
[0017] In one embodiment, the threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions, and the threat intelligence satisfies at least one of the preset high-risk conditions:
[0018] The frequency of the query requests from the problem access source is greater than or equal to a pre-set request threshold;
[0019] The frequency of queries made by the problem access source to a single domain name is greater than or equal to a pre-set query threshold.
[0020] The average frequency of the problem accessing the source session is greater than or equal to a pre-set average threshold.
[0021] In one embodiment, the threat intelligence does not meet the high-risk condition including at least one of the following:
[0022] The frequency of the query requests from the source of the problem is less than the request threshold;
[0023] The frequency of queries made by the problematic access source for a single domain name is less than the query threshold;
[0024] The average frequency of the problem accessing the source session is less than the average threshold.
[0025] In one embodiment, the method further includes:
[0026] Determine the historical access records of the traffic data to be detected;
[0027] Determine the purpose of accessing the traffic data to be detected;
[0028] Based on the historical access records and the access purpose, the traffic data to be detected is subject to focused detection.
[0029] If the traffic data to be detected is data of concern, then the step of processing the problematic access source according to the target processing rules is executed.
[0030] In one embodiment,
[0031] Secondly, this application also provides a service attack processing apparatus. The apparatus includes:
[0032] The detection module is used to perform hazard detection on the traffic data to be detected based on pre-set detection standards.
[0033] The determination module is used to determine the problematic access source of the traffic data to be detected if the danger detection of the traffic data to be detected fails.
[0034] The processing module is used to determine target processing rules based on the threat intelligence of the problematic access source, and process the problematic access source according to the target processing rules.
[0035] Thirdly, this application also provides a computer device. The computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement the service attack processing method as described in any of the embodiments of the first aspect above.
[0036] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, implements the service attack processing method as described in any embodiment of the first aspect above.
[0037] Fifthly, this application also provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the service attack processing method as described in any of the embodiments of the first aspect above.
[0038] According to the technical solution of this application, by performing danger detection on the detected traffic data, the source of the problematic access can be identified, providing a data foundation for subsequently determining the target processing rules. By determining the target processing rules, it is ensured that the processing rules for the problematic access source can be determined based on the threat intelligence of the problematic access source. This enables the selection of different processing rules based on different threat intelligence of the problematic access source, thereby improving the diversity of service attack handling and achieving reasonable allocation of blocking resources, preventing resource waste during service blocking attacks. Attached Figure Description
[0039] Figure 1 This is an application environment diagram of a service attack handling method in one embodiment;
[0040] Figure 2 A flowchart illustrating a service attack handling method provided in this application embodiment;
[0041] Figure 3 A flowchart illustrating another service attack handling method provided in this application embodiment;
[0042] Figure 4 A flowchart illustrating another service attack handling method provided in this application embodiment;
[0043] Figure 5 A flowchart illustrating another service attack handling method provided in this application embodiment;
[0044] Figure 6 A structural block diagram of a service attack processing device provided in an embodiment of this application;
[0045] Figure 7 A structural block diagram of another service attack processing apparatus provided in the embodiments of this application;
[0046] Figure 8 A structural block diagram of another service attack processing apparatus provided in the embodiments of this application;
[0047] Figure 9 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0048] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0049] It should be understood that the specific embodiments described herein are merely illustrative of this application and are not intended to limit this application. In the description of this application, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in a suitable manner in any one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0050] With the development of Internet technology, the Internet security of enterprises has received increasing attention. Currently, enterprises often suffer from denial-of-service attacks based on DNS (Domain Name System) query requests. The attack form of denial-of-service attacks is to launch a large number of requests frequently in a short period of time based on normal DNS query channels, thereby paralyzing the enterprise's DNS service and preventing it from working normally.
[0051] Existing technologies typically involve performing threat detection on traffic data. Once a problematic access source is identified among the sources sending the traffic data, it is blocked to ensure the security of the enterprise's internet. However, the aforementioned methods for blocking problematic access sources lack flexibility, making it impossible to select the appropriate blocking method based on the threat intelligence of the problematic access source. This results in a waste of blocking resources when blocking problematic access sources.
[0052] The service attack handling method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, in one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows. Figure 1 As shown, the computer device includes a processor, memory, and a network interface connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The database stores data acquired for service attack processing. The network interface communicates with external terminals via a network connection. When executed by the processor, the computer program implements a service attack processing method.
[0053] This application discloses a service attack handling method, apparatus, computer device, and storage medium. Based on detection standards, the method performs threat detection on the traffic to be detected, identifying traffic data that fails the threat detection; it then identifies the problematic access source of the traffic data to be detected, and processes the problematic access source based on threat intelligence and target processing rules.
[0054] Figure 2 A flowchart of a service attack handling method provided in an embodiment of this application is shown below. Figure 2 As shown, the service attack handling method may include the following steps:
[0055] Step 201: Based on the pre-set detection standards, perform hazard detection on the traffic data to be detected.
[0056] It should be noted that the detection standard is used to perform hazard detection on the traffic to be detected, thereby determining the problematic access source. If the hazard detection of the traffic data to be detected fails, it means that the access source corresponding to the traffic data to be detected is a problematic access source. If the hazard detection of the traffic data to be detected passes, it means that the access source corresponding to the traffic data to be detected is a normal access source.
[0057] To further clarify, the detection criteria may include, but are not limited to: determining whether the frequency of query requests corresponding to the traffic data to be detected exceeds the first query criterion; determining whether the frequency of queries for a single domain name in the traffic data to be detected exceeds the second query criterion; and determining whether the session frequency of the traffic data to be detected exceeds the session criterion.
[0058] Among them, the first query standard, the second query standard, and the session standard are all standard thresholds set according to the actual situation. If the frequency of query requests for the traffic data to be tested exceeds the first query standard, it means that the traffic data to be tested has failed the test. If the frequency of queries for a single domain name in the traffic data to be tested exceeds the second query standard, it means that the traffic data to be tested has failed the test. If the session frequency of the traffic data to be tested exceeds the session standard, it means that the traffic data to be tested has failed the test.
[0059] In one embodiment of this application, if any one of the detection criteria for the traffic data to be detected fails during the hazard detection process, then the hazard detection of the traffic data to be detected is determined to have failed. Specifically, when it is necessary to perform hazard detection on the traffic data to be detected, the frequency of query requests, the frequency of queries against a single domain name, and the session frequency of the traffic data to be detected are detected respectively. If, based on the detection results, it is determined that the frequency of queries against a single domain name in the traffic data to be detected exceeds the second query criterion, then the detection of the traffic data to be detected is deemed to have failed.
[0060] In one embodiment of this application, if any two detection criteria of the traffic data to be detected fail during the hazard detection process, then the hazard detection of the traffic data to be detected is determined to have failed. Specifically, when it is necessary to perform hazard detection on the traffic data to be detected, the frequency of query requests, the frequency of queries against a single domain name, and the session frequency of the traffic data to be detected are detected separately. If the detection results determine that only the session frequency of the traffic data to be detected exceeds the session standard, then the detection of the traffic data to be detected is considered to have passed.
[0061] It should be noted that historical attack records can be used to determine whether the access source of the traffic data to be tested is a problematic access source. Specifically, when it is necessary to perform security detection on the traffic data to be tested, the list of problematic access sources that have previously launched attacks is determined based on historical attack records. The access source of the traffic data to be tested is then determined, and it is determined whether the access source of the traffic data to be tested appears in the list of problematic access sources. If the access source of the traffic data to be tested appears in the list of problematic access sources, it means that the access source of the traffic data to be tested is a problematic access source; if the access source of the traffic data to be tested does not appear in the list of problematic access sources, it means that the access source of the traffic data to be tested is a normal access source.
[0062] Step 202: If the danger detection of the traffic data to be detected fails, the problematic access source of the traffic data to be detected is determined.
[0063] It should be noted that if the security check of the traffic data to be tested fails, it means that the traffic data to be tested has a potential attack risk. Therefore, the access source corresponding to the traffic data to be tested is the problematic access source.
[0064] Step 203: Determine the target processing rules based on the threat intelligence and processing rules of the problematic access source, and process the problematic access source according to the target processing rules.
[0065] Threat intelligence on problematic access sources is information used to demonstrate the harm caused by service attacks from those sources. Different threat intelligence levels indicate different levels of potential attack harm from problematic access sources. A high threat intelligence level indicates that the problematic access source can cause greater attack harm; a low threat intelligence level indicates that the problematic access source can cause less attack harm.
[0066] To further explain, target processing rules refer to the different processing rules adopted for different levels of threat intelligence. The higher the threat intelligence level of the problematic access source, the more resources are required for the target processing rules adopted; similarly, the lower the threat intelligence level of the problematic access source, the less resources are required for the target processing rules adopted. By adopting different target processing rules for different threat intelligence of the problematic access source, the reasonable allocation of blocking resources can be achieved.
[0067] In one embodiment of this application, the threat level corresponding to the problematic access source is determined based on the threat intelligence of the problematic access source, and different target processing rules are determined based on the non-compliance threat level, thereby completing the processing operation on the problematic access source according to the target processing rules.
[0068] According to the service attack handling method of this application, the source of the problem access is determined by performing danger detection on the detected traffic data, which provides a data basis for determining the target handling rules. By determining the target handling rules, it is ensured that the handling rules for the problem access source can be determined based on the threat intelligence of the problem access source. This enables the selection of different handling rules according to different threat intelligence of the problem access source, thereby improving the diversity of service attack handling and realizing the rational allocation of blocking resources, preventing the waste of resources when blocking service attacks.
[0069] It should be noted that the processing rules may include pre-set high-risk thresholds. These thresholds can be used to assess the threat intelligence of the problematic access source, thereby determining the target processing rules. Optionally, such as... Figure 3 As shown, Figure 3A flowchart illustrating another service attack handling method provided in this application embodiment. Specifically, determining the target handling rules may include the following steps:
[0070] Step 301: Based on the high-risk threshold, assess the threat intelligence of the problematic access source to determine its threat level.
[0071] In one embodiment of this application, it is determined whether the threat intelligence of the problematic access source meets the preset high-risk conditions; if the threat intelligence of the problematic access source meets the high-risk conditions, the threat level of the problematic access source is determined to be high-risk; if the threat intelligence of the problematic access source does not meet the high-risk conditions, the threat level of the problematic access source is determined to be non-high-risk.
[0072] It should be noted that threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions. By determining the relationship between the frequency of query requests, the frequency of queries, and the average frequency of sessions and the request threshold, query threshold, and average threshold, respectively, the threat level of the problematic access source can be determined.
[0073] To further clarify, threat intelligence meeting the preset high-risk conditions includes at least one of the following: the frequency of query requests from the problematic access source is greater than or equal to a preset request threshold; the frequency of queries from the problematic access source to a single domain name is greater than or equal to a preset query threshold; the average frequency of sessions from the problematic access source is greater than or equal to a preset average threshold.
[0074] To further clarify, threat intelligence does not meet the high-risk criteria if at least one of the following conditions is met: the frequency of query requests from the problematic access source is less than the request threshold; the frequency of queries from the problematic access source against a single domain name is less than the query threshold; or the average frequency of sessions from the problematic access source is less than the average threshold.
[0075] In one embodiment of this application, the frequency of query requests corresponding to the problematic access source is determined to be 8 times per second, the frequency of a single domain name being queried is 35 times per second, and the average frequency of a session is 400 times per minute, based on threat intelligence. The preset request threshold, query threshold, and average threshold are 10 times per second, 40 times per second, and 300 times per minute, respectively. When it is necessary to determine the threat level of the problematic access source, if the frequency of query requests corresponding to the problematic access source is less than the request threshold, the frequency of a single domain name being queried is less than the query threshold, but the average frequency of the problematic access source session is greater than the average threshold, then the threat level of the problematic access source can be determined to be high-risk.
[0076] In one embodiment of this application, the frequency of query requests corresponding to the problematic access source is determined to be 8 times per second, the frequency of a single domain name being queried is 35 times per second, and the average frequency of a session is 2500 times per minute, based on threat intelligence. The preset request threshold, query threshold, and average threshold are 10 times per second, 40 times per second, and 300 times per minute, respectively. When it is necessary to determine the threat level of the problematic access source, if the frequency of query requests corresponding to the problematic access source is less than the request threshold, the frequency of a single domain name being queried is less than the query threshold, and the average frequency of the problematic access source session is less than the average threshold, then the threat level of the problematic access source can be determined to be non-high-risk.
[0077] Step 302: Based on the threat level, determine the target handling rules in the handling rules.
[0078] In one embodiment of this application, if the threat level of the problematic access source is high, then a target processing rule for processing the high-risk problematic access source is determined in the processing rules based on the high-risk threat level. The target processing rule for processing the high-risk problematic access source can be blocking or banning. Specifically, when the threat level of the problematic access source is determined to be high, the traffic data of the problematic access source can be blocked, and the problematic access source can be banned.
[0079] In one embodiment of this application, if the threat level of the problematic access source is non-high-risk, then a target processing rule for processing the non-high-risk problematic access source is determined in the processing rules based on the non-high-risk threat level. The target processing rule for processing the non-high-risk problematic access source can implement DNS (Domain Name System) request black hole operation. Specifically, when it is determined that the threat level of the problematic access source is non-high-risk, the problematic access source request is received, but no response action is taken. The problematic access source request is redirected to the black hole route to avoid exposing information and prevent attacks from the problematic access source.
[0080] According to the service attack handling method of this application, the threat level of the problematic access source is determined by assessing the threat intelligence, which ensures that the target handling rules matching the problematic access source can be selected according to the threat level. This achieves reasonable allocation of blocking resources and ensures that the waste of blocking resources is reduced while effectively handling the problematic access source. By determining the target handling rules through the threat level, the target handling rules can be determined according to different threat levels of the problematic access source, thereby improving the diversity of handling service attacks.
[0081] It should be noted that the data of interest can be determined by the purpose of access and historical access records, and then the target processing rules corresponding to the data of interest can be selected, such as... Figure 4 As shown, Figure 4A flowchart illustrating another service attack handling method provided in this application embodiment. Specifically, the service attack handling method may further include the following steps:
[0082] Step 401: Determine the historical access records of the traffic data to be detected.
[0083] It should be noted that by determining the historical access records of the traffic data to be tested, all access records of the traffic data to be tested are obtained, and then it is determined whether the traffic data to be tested has been accessed multiple times. If it is determined from the historical access records that the traffic data to be tested has been accessed multiple times, then the traffic data to be tested is considered to have an attack risk. If it is determined from the historical access records that the traffic data to be tested is accessed for the first time, then the traffic data to be tested is considered not to have an attack risk.
[0084] Step 402: Determine the access purpose of the traffic data to be detected.
[0085] It should be noted that by determining the access purpose of the traffic data to be detected, it is determined whether the access purpose of the traffic data to be detected is confidential data, and thus whether the traffic data to be detected is at risk of attack. Specifically, if the access purpose of the traffic data to be detected is confidential data, then the traffic data to be detected is considered to have an attack risk; if the access purpose of the traffic data to be detected is non-confidential data, then the traffic data to be detected is considered not to have an attack risk.
[0086] Confidential data refers to data that is not disclosed to the public within an enterprise. Furthermore, the definition of confidential data can be added to or deleted based on actual circumstances. In other words, confidential data can be selected based on the specific situation.
[0087] In one embodiment of this application, confidential data needs to be detected before determining the access purpose of the traffic data to be detected, and the confidential data at the current moment needs to be determined to ensure that no mistakes are made when determining whether the traffic data to be detected has an attack risk based on the access purpose.
[0088] Step 403: Based on historical access records and access purposes, conduct focused detection on the traffic data to be detected.
[0089] It should be noted that when monitoring traffic data, the system checks whether there are multiple access records in the historical access history of the traffic data. If there are multiple access records, the traffic data is identified as data under monitoring. If there are no multiple access records, the system determines whether the traffic data accesses confidential data based on the purpose of the access. If the purpose of the access is confidential data, the traffic data is identified as data under monitoring. If the purpose of the access is not confidential data, the traffic data is not identified as data under monitoring.
[0090] Step 404: If the traffic data to be detected is data of concern, then execute the step of processing the problematic access source according to the target processing rules.
[0091] It should be noted that if the traffic data to be detected is data of interest, then the traffic data to be detected will be redirected to a honeypot. Specifically, the data of interest will be redirected to the honeypot system to observe the subsequent actions and behaviors of the data of interest in the honeypot system, thereby obtaining behavioral data of the data of interest. Based on the behavioral data of the data of interest, data support will be provided for subsequent optimization of the attack strategy of the defense service.
[0092] Honeypot attacks are essentially a technique to deceive data of interest. By deploying decoy hosts, network services, or information, the data of interest is induced to attack them. This allows for the capture and analysis of the attack behavior, understanding the tools and methods used by the data of interest, and inferring the attack intent and motives. This enables the defender to clearly understand the security threats they face and to enhance the security protection capabilities of the actual system through technical and management means.
[0093] According to the service attack handling method of this application, by determining the historical access records and access purpose of the traffic data to be detected, the detection of the traffic data to be detected is realized. This ensures that the data of interest in the traffic data to be detected can be identified, thereby realizing the processing of the data of interest. It also realizes the selection of different target processing rules for processing according to different situations of the traffic data to be detected, thereby improving the diversity of service attack handling.
[0094] In one embodiment of this application, such as Figure 5 As shown, Figure 5 A flowchart illustrating another service attack handling method provided in this application embodiment, when it is necessary to process the traffic data to be detected:
[0095] Step 501: Based on the pre-set detection standards, perform hazard detection on the traffic data to be detected.
[0096] Step 502: If the danger detection of the traffic data to be detected fails, then the problematic access source of the traffic data to be detected is determined.
[0097] Step 503: Based on the high-risk threshold, assess the threat intelligence of the problematic access source to determine its threat level.
[0098] Step 504: Based on the threat level, determine the target handling rules in the handling rules.
[0099] According to the service attack handling method of this application, the source of the problem access is determined by performing danger detection on the detected traffic data, which provides a data basis for determining the target handling rules. By determining the target handling rules, it is ensured that the handling rules for the problem access source can be determined based on the threat intelligence of the problem access source. This enables the selection of different handling rules according to different threat intelligence of the problem access source, thereby improving the diversity of service attack handling and realizing the rational allocation of blocking resources, preventing the waste of resources when blocking service attacks.
[0100] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0101] Based on the same inventive concept, this application also provides a service attack processing apparatus for implementing the service attack processing method described above. The solution provided by this apparatus is similar to the implementation scheme described in the above method; therefore, the specific limitations in one or more service attack processing apparatus embodiments provided below can be found in the limitations of the service attack processing method described above, and will not be repeated here.
[0102] In one embodiment, such as Figure 6 As shown, Figure 6 This application provides a structural block diagram of a service attack processing device, which includes: a first detection module 610, a first determination module 620, and a processing module 630, wherein:
[0103] The first detection module 610 is used to perform hazard detection on the traffic data to be detected based on pre-set detection standards.
[0104] The first determination module 620 is used to determine the problematic access source of the traffic data to be detected if the danger detection of the traffic data to be detected fails.
[0105] The processing module 630 is used to determine the target processing rules based on the threat intelligence and processing rules of the problematic access source, and to process the problematic access source according to the target processing rules.
[0106] According to the service attack processing device of this application, the source of the problem access is determined by performing danger detection on the detected traffic data, which provides a data basis for the subsequent determination of target processing rules. By determining the target processing rules, it is ensured that the processing rules for the problem access source can be determined based on the threat intelligence of the problem access source. Different processing rules can be selected according to different threat intelligence of the problem access source, thereby improving the diversity of service attack processing and realizing the rational allocation of blocking resources, preventing the waste of resources when blocking service attacks.
[0107] In one embodiment, such as Figure 7 As shown, Figure 7 This is a structural block diagram of another service attack processing device provided in this application embodiment. A service attack processing device is provided, and it should be noted that the processing rules may include a pre-set high-risk threshold. The processing module 730 in this service attack processing device includes: an evaluation unit 731 and a determination unit 732, wherein:
[0108] The evaluation unit 731 is used to evaluate the threat intelligence of the problematic access source based on the high-risk threshold and determine the threat level of the problematic access source.
[0109] In one embodiment of this application, it is determined whether the threat intelligence of the problematic access source meets the preset high-risk conditions; if the threat intelligence of the problematic access source meets the high-risk conditions, the threat level of the problematic access source is determined to be high-risk; if the threat intelligence of the problematic access source does not meet the high-risk conditions, the problematic access source is determined to be non-high-risk.
[0110] It should be noted that threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions. Threat intelligence that meets the preset high-risk conditions includes at least one of the following: the frequency of query requests from the problematic access source is greater than or equal to a preset request threshold; the frequency of queries from the problematic access source to a single domain name is greater than or equal to a preset query threshold; and the average frequency of sessions from the problematic access source is greater than or equal to a preset average threshold.
[0111] To further clarify, threat intelligence does not meet the high-risk criteria if at least one of the following conditions is met: the frequency of query requests from the problematic access source is less than the request threshold; the frequency of queries from the problematic access source against a single domain name is less than the query threshold; or the average frequency of sessions from the problematic access source is less than the average threshold.
[0112] The determination unit 732 is used to determine the target processing rules in the processing rules based on the threat level.
[0113] in, Figure 7 710, 720 and Figure 6 The 610 and 620 have the same function and structure.
[0114] According to the service attack processing device of this application, by assessing the threat intelligence, the threat level of the problematic access source is determined, ensuring that the target processing rule matching the problematic access source can be selected according to the threat level, realizing the rational allocation of blocking resources, and ensuring that the waste of blocking resources is reduced while effectively processing the problematic access source; by determining the target processing rule through the threat level, the target processing rule can be determined according to the different threat levels of the problematic access source, thereby improving the diversity of service attack processing.
[0115] In one embodiment, such as Figure 8 As shown, Figure 8 This is a structural block diagram of another service attack processing device provided in an embodiment of this application. The device further includes: a second determining module 840, a third determining module 850, a second detecting module 860, and an execution module 870, wherein:
[0116] The second determination module 840 is used to determine the historical access records of the traffic data to be detected.
[0117] The third determination module 850 is used to determine the access purpose of the traffic data to be detected.
[0118] The second detection module 860 is used to perform focused detection on the traffic data to be detected based on historical access records and access purposes.
[0119] The execution module 870 is used to perform steps to process the problematic access source according to the target processing rules if the traffic data to be detected is data of concern.
[0120] in, Figure 8 Medium 810-830 and Figure 7 The 710-730 series have the same functions and structure.
[0121] According to the service attack processing device of this application, by determining the historical access records and access purpose of the traffic data to be detected, the device can detect the traffic data to be detected with interest, ensuring that the data of interest in the traffic data to be detected can be identified, thereby realizing the processing of the data of interest. It also realizes the selection of different target processing rules for processing according to different situations of the traffic data to be detected, thereby improving the diversity of service attack processing.
[0122] Each module in the aforementioned service attack processing device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can invoke and execute the operations corresponding to each module.
[0123] In one embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 9 As shown. The computer device includes a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, NFC (Near Field Communication), or other technologies. When executed by the processor, the computer program implements a service attack handling method. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad mounted on the computer device casing, or an external keyboard, touchpad, or mouse.
[0124] Those skilled in the art will understand that Figure 9 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0125] In one embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0126] Based on pre-set detection standards, perform hazard detection on the traffic data to be detected;
[0127] If the danger detection of the traffic data to be tested fails, the problematic access source of the traffic data to be tested is determined;
[0128] Based on threat intelligence and processing rules from the problematic access source, target processing rules are determined, and the problematic access source is processed according to the target processing rules.
[0129] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0130] The handling rules may include pre-defined high-risk thresholds. Target handling rules are determined based on threat intelligence and handling rules from the problematic access source, including:
[0131] Based on high-risk thresholds, the threat intelligence of problematic access sources is assessed to determine the threat level of the problematic access sources.
[0132] Based on the threat level, target handling rules are determined in the handling rules.
[0133] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0134] Determine whether the threat intelligence of the problematic access source meets the preset high-risk conditions;
[0135] If the threat intelligence of the problematic access source meets the high-risk criteria, the threat level of the problematic access source is determined to be high-risk.
[0136] If the threat intelligence of the problematic access source does not meet the high-risk criteria, the problematic access source is determined to be non-high-risk.
[0137] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0138] Threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions. Threat intelligence that meets the preset high-risk criteria includes at least one of the following:
[0139] The frequency of query requests from the problem access source is greater than or equal to a pre-set request threshold;
[0140] The problem access source queries a single domain name at a frequency greater than or equal to a pre-set query threshold;
[0141] The average frequency of the problem access source session is greater than or equal to a pre-set average threshold.
[0142] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0143] Threat intelligence does not meet the high-risk criteria if at least one of the following is true:
[0144] The frequency of query requests to the problem access source is less than the request threshold;
[0145] The frequency of queries targeting a single domain for the problematic access source is less than the query threshold;
[0146] The average frequency of accessing the source session for the problem is less than the average threshold.
[0147] In one embodiment, the processor, when executing a computer program, also performs the following steps:
[0148] Determine the historical access records of the traffic data to be detected;
[0149] Determine the purpose of accessing the traffic data to be monitored;
[0150] Based on historical access records and access purposes, the traffic data to be detected is monitored.
[0151] If the traffic data to be detected is data of concern, then the steps to process the problematic access source according to the target processing rules will be executed.
[0152] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor:
[0153] Based on pre-set detection standards, perform hazard detection on the traffic data to be detected;
[0154] If the danger detection of the traffic data to be tested fails, the problematic access source of the traffic data to be tested is determined;
[0155] Based on threat intelligence and processing rules from the problematic access source, target processing rules are determined, and the problematic access source is processed according to the target processing rules.
[0156] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0157] The handling rules may include pre-defined high-risk thresholds. Target handling rules are determined based on threat intelligence and handling rules from the problematic access source, including:
[0158] Based on high-risk thresholds, the threat intelligence of problematic access sources is assessed to determine the threat level of the problematic access sources.
[0159] Based on the threat level, target handling rules are determined in the handling rules.
[0160] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0161] Determine whether the threat intelligence of the problematic access source meets the preset high-risk conditions;
[0162] If the threat intelligence of the problematic access source meets the high-risk criteria, the threat level of the problematic access source is determined to be high-risk.
[0163] If the threat intelligence of the problematic access source does not meet the high-risk criteria, the problematic access source is determined to be non-high-risk.
[0164] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0165] Threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions. Threat intelligence that meets the preset high-risk criteria includes at least one of the following:
[0166] The frequency of query requests from the problem access source is greater than or equal to a pre-set request threshold;
[0167] The problem access source queries a single domain name at a frequency greater than or equal to a pre-set query threshold;
[0168] The average frequency of the problem access source session is greater than or equal to a pre-set average threshold.
[0169] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0170] Threat intelligence does not meet the high-risk criteria if at least one of the following is true:
[0171] The frequency of query requests to the problem access source is less than the request threshold;
[0172] The frequency of queries targeting a single domain for the problematic access source is less than the query threshold;
[0173] The average frequency of accessing the source session for the problem is less than the average threshold.
[0174] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0175] Determine the historical access records of the traffic data to be detected;
[0176] Determine the purpose of accessing the traffic data to be monitored;
[0177] Based on historical access records and access purposes, the traffic data to be detected is monitored.
[0178] If the traffic data to be detected is data of concern, then the steps to process the problematic access source according to the target processing rules will be executed.
[0179] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, performs the following steps:
[0180] Based on pre-set detection standards, perform hazard detection on the traffic data to be detected;
[0181] If the danger detection of the traffic data to be tested fails, the problematic access source of the traffic data to be tested is determined;
[0182] Based on threat intelligence and processing rules from the problematic access source, target processing rules are determined, and the problematic access source is processed according to the target processing rules.
[0183] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0184] The handling rules may include pre-defined high-risk thresholds. Target handling rules are determined based on threat intelligence and handling rules from the problematic access source, including:
[0185] Based on high-risk thresholds, the threat intelligence of problematic access sources is assessed to determine the threat level of the problematic access sources.
[0186] Based on the threat level, target handling rules are determined in the handling rules.
[0187] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0188] Determine whether the threat intelligence of the problematic access source meets the preset high-risk conditions;
[0189] If the threat intelligence of the problematic access source meets the high-risk criteria, the threat level of the problematic access source is determined to be high-risk.
[0190] If the threat intelligence of the problematic access source does not meet the high-risk criteria, the problematic access source is determined to be non-high-risk.
[0191] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0192] Threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions. Threat intelligence that meets the preset high-risk criteria includes at least one of the following:
[0193] The frequency of query requests from the problem access source is greater than or equal to a pre-set request threshold;
[0194] The problem access source queries a single domain name at a frequency greater than or equal to a pre-set query threshold;
[0195] The average frequency of the problem access source session is greater than or equal to a pre-set average threshold.
[0196] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0197] Threat intelligence does not meet the high-risk criteria if at least one of the following is true:
[0198] The frequency of query requests to the problem access source is less than the request threshold;
[0199] The frequency of queries targeting a single domain for the problematic access source is less than the query threshold;
[0200] The average frequency of accessing the source session for the problem is less than the average threshold.
[0201] In one embodiment, when the computer program is executed by a processor, it further performs the following steps:
[0202] Determine the historical access records of the traffic data to be detected;
[0203] Determine the purpose of accessing the traffic data to be monitored;
[0204] Based on historical access records and access purposes, the traffic data to be detected is monitored.
[0205] If the traffic data to be detected is data of concern, then the steps to process the problematic access source according to the target processing rules will be executed.
[0206] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0207] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0208] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0209] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for handling service attacks, the method being applied at the Domain Name System (DNS) level, characterized in that, The method includes: Based on pre-set detection standards, the traffic data to be detected is subjected to danger detection, and the traffic data to be detected is real-time network traffic data based on Domain Name System (DNS) query requests; If the danger detection of the traffic data to be detected fails, the problematic access source of the traffic data to be detected is determined; Based on the threat intelligence and processing rules of the problematic access source, a target processing rule is determined, and the problematic access source is processed according to the target processing rule; The processing rules may include pre-set high-risk thresholds. The process of determining target processing rules based on threat intelligence and processing rules related to the problematic access source, and processing the problematic access source according to the target processing rules, includes: Based on the high-risk threshold, the threat intelligence of the problematic access source is assessed to determine the threat level of the problematic access source. The threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions. If the threat level is high, the source of access to the problem will be blocked. If the threat level is non-high-risk, then based on the non-high-risk threat level, a target processing rule for handling non-high-risk problem access sources is determined in the processing rules. The target processing rule for handling non-high-risk problem access sources is to implement a Domain Name System (DNS) request black hole operation. The DNS request black hole operation is used to redirect the DNS query requests of the problem access source to the black hole route without responding.
2. The method according to claim 1, characterized in that, The step of assessing the threat intelligence of the problematic access source and determining the threat level of the problematic access source includes: Determine whether the threat intelligence from the source of the problem meets the preset high-risk conditions; If the threat intelligence of the problem access source meets the high-risk condition, the threat level of the problem access source is determined to be high-risk; If the threat intelligence of the problematic access source does not meet the high-risk condition, the problematic access source is determined to be non-high-risk.
3. The method according to claim 2, characterized in that, The threat intelligence meets at least one of the preset high-risk conditions: The frequency of the query requests from the problem access source is greater than or equal to a pre-set request threshold; The frequency of queries made by the problem access source to a single domain name is greater than or equal to a pre-set query threshold. The average frequency of the problem accessing the source session is greater than or equal to a pre-set average threshold.
4. The method according to claim 3, characterized in that, The threat intelligence does not meet the high-risk criteria, including at least one of the following: The frequency of the query requests from the source of the problem is less than the request threshold; The frequency of queries made by the problematic access source for a single domain name is less than the query threshold; The average frequency of the problem accessing the source session is less than the average threshold.
5. A service attack handling device, the device being applied at the Domain Name System (DNS) layer, characterized in that, The device includes: The detection module is used to perform danger detection on the traffic data to be detected based on a pre-set detection standard. The traffic data to be detected is real-time network traffic data based on Domain Name System (DNS) query requests. The determination module is used to determine the problematic access source of the traffic data to be detected if the danger detection of the traffic data to be detected fails. The processing module is used to determine the target processing rule based on the threat intelligence and processing rules of the problematic access source, and process the problematic access source according to the target processing rule; The processing rules may include a pre-set high-risk threshold, and the processing module is specifically used for: Based on the high-risk threshold, the threat intelligence of the problematic access source is assessed to determine the threat level of the problematic access source. The threat intelligence includes at least one of the frequency of query requests, the frequency of queries, and the average frequency of sessions. If the threat level is high, the source of access to the problem will be blocked. If the threat level is non-high-risk, then based on the non-high-risk threat level, a target processing rule for handling non-high-risk problem access sources is determined in the processing rules. The target processing rule for handling non-high-risk problem access sources is to implement a Domain Name System (DNS) request black hole operation. The DNS request black hole operation is used to redirect the DNS query requests of the problem access source to the black hole route without responding.
6. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Anti-crawler method and device, equipment and storage medium
CN110020512A
Data monitoring processing method and device, computer equipment and storage medium
CN110602046A
Detection and protection method and system for application layer DDOS attack based on IP credibility
CN112491869A
Method and device for automatically banning IP (Internet Protocol) aiming at network attack
CN114598525A