Method and apparatus for alerting of network attack anomaly traffic

By nesting and configuring IP detection ranges within the detection devices and matching them according to priority, the problem of device performance degradation during DDoS attacks involving multiple detection devices was solved. This enabled rapid and accurate reporting of abnormal IP traffic alarms, improving the efficiency of network security management.

CN115664820BActive Publication Date: 2026-05-29HANGZHOU DPTECH TECH

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU DPTECH TECH
Filing Date
2022-10-26
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, when multiple detection devices are used to detect DDoS attacks, it is difficult to make efficient and reasonable use of the detection device's capabilities, resulting in a decline in device performance. This is especially true when deep packet inspection is required to handle large traffic volumes, and it is difficult to quickly and accurately report abnormal IP traffic alarm information.

Method used

By nesting and configuring IP detection ranges in the detection device, the target IP detection ranges are matched one by one according to priority, and warning information of abnormal network attack traffic is generated. The abnormal traffic management platform dynamically allocates the priority of the detection IP segments, prioritizes matching high-priority IP segments, and reports alarm information after successful matching.

Benefits of technology

It enables the rational and efficient use of the detection capabilities of the detection equipment, quickly and accurately reports abnormal IP traffic alarm information, reduces the performance burden on the equipment, and facilitates the maintenance work of network operation and maintenance personnel.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664820B_ABST
    Figure CN115664820B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a network attack abnormal traffic warning method, device, electronic equipment and computer readable medium. The method comprises: detecting the IP address of the abnormal traffic when the detection equipment detects the network attack abnormal traffic; extracting a plurality of preset IP detection intervals; extracting the target IP detection interval one by one based on the priority corresponding to the IP detection interval; matching the IP address and the target IP detection interval; and generating the warning information of the network attack abnormal traffic based on the IP address after the matching is successful. The network attack abnormal traffic warning method, device, electronic equipment and computer readable medium disclosed in the present application can reasonably and efficiently utilize the detection capability of the detection equipment, quickly and accurately report the abnormal IP traffic alarm information to the management platform, and facilitate the maintenance work of the network operation and maintenance personnel.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of computer information processing, and more specifically, to a method, apparatus, electronic device, and computer-readable medium for alerting abnormal network attack traffic. Background Technology

[0002] With the rapid development of the internet, cyberattacks occur frequently, and the methods are constantly evolving. Distributed Denial-of-Service (DDoS) attacks are one of the most destructive attack methods in the internet environment. How to detect such attacks has become a hot research topic in the internet security community. Many traffic monitoring devices are configured with monitoring IP ranges to monitor the network in real time. However, in different application scenarios, traffic monitoring devices may prioritize certain IPs over others. Therefore, it is increasingly important to utilize these monitoring IPs efficiently and effectively to combat DDoS attacks in different application scenarios and better protect customer network security.

[0003] In existing technologies, DDoS detection can be performed using multiple detection devices or multiple monitoring devices. With multiple detection devices, all devices simultaneously protect the same IP segment and detect abnormal IP traffic within that segment. With multiple monitoring devices, each device protects different IP segments and detects abnormal IP traffic within its own protected segment.

[0004] Multiple detection devices protect the same or different IP ranges. When a DDoS attack occurs, the detection devices will detect abnormal traffic attacks on these IPs based on the user-configured detection IPs. To prevent attack traffic from entering the customer's normal network, we configure the detection devices with a large IP range covering a wide range of IP addresses. However, continuously and simultaneously detecting a large number of IPs can easily degrade the performance of the detection devices. This is especially true for deep packet inspection; while it allows for accurate traffic analysis and relatively complete statistical data, the demands on the equipment are extremely high when the traffic volume to be detected is very large.

[0005] Therefore, there is a need for new methods, devices, electronic equipment, and computer-readable media for alerting abnormal traffic during network attacks.

[0006] The information disclosed in the background section is only intended to enhance the understanding of the background of this application, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0007] In view of this, this application provides a method, device, electronic device, and computer-readable medium for alerting abnormal network attack traffic, which can reasonably and efficiently utilize the detection capabilities of detection equipment to quickly and accurately report abnormal IP traffic alarm information to the management platform, making it more convenient for network operation and maintenance personnel to carry out maintenance work.

[0008] Other features and advantages of this application will become apparent from the following detailed description, or may be learned in part from practice of this application.

[0009] According to one aspect of this application, a method for alerting abnormal network attack traffic is proposed. The method includes: when a detection device detects abnormal network attack traffic, extracting the IP address of the abnormal traffic; extracting multiple preset IP detection intervals; extracting target IP detection intervals one by one based on the priority corresponding to the IP detection intervals; matching the IP address with the target IP detection interval; and generating alert information for abnormal network attack traffic based on the IP address after successful matching.

[0010] In one exemplary embodiment of this application, the method further includes: the abnormal traffic management platform distributes multiple IP detection ranges and their corresponding priorities to multiple detection devices.

[0011] In one exemplary embodiment of this application, the abnormal traffic management platform distributes multiple IP detection intervals and their corresponding priorities to multiple detection devices, including: generating multiple parent intervals according to business requirements; generating sub-intervals through a portion of the IP detection intervals in the parent intervals; generating the multiple IP detection intervals through the multiple parent intervals and their corresponding sub-intervals; and distributing the multiple IP detection intervals and their corresponding priorities to the multiple detection devices.

[0012] In one exemplary embodiment of this application, generating a sub-interval by means of a portion of the IP detection intervals in the parent interval includes: analyzing the historical network attack abnormal traffic of the parent interval to determine the core interval; and extracting the core intervals from the parent interval to generate the sub-interval.

[0013] In one exemplary embodiment of this application, generating a sub-interval through a portion of the IP detection interval in the parent interval further includes: setting a high priority for the sub-interval; and setting a low priority for the parent interval.

[0014] In one exemplary embodiment of this application, the distribution of the plurality of IP detection intervals and their corresponding priorities to the plurality of detection devices includes: treating the parent interval and its corresponding child interval among the plurality of IP detection intervals as a set of intervals; and distributing each set of intervals among the plurality of intervals as a whole to the detection devices.

[0015] In one exemplary embodiment of this application, when the detection device detects abnormal network attack traffic, it extracts the IP address of the abnormal traffic, including: the detection device performs real-time detection of DDoS attacks; and when the real-time acquired abnormal network attack traffic exceeds a traffic threshold, it extracts the IP address of the abnormal traffic.

[0016] In one exemplary embodiment of this application, the detection device performs real-time detection of DDoS attacks, including: the detection device performs real-time deep packet inspection on the current traffic; and / or the detection device performs traffic statistical analysis on the current traffic.

[0017] In one exemplary embodiment of this application, the target IP detection interval is extracted one by one based on the priority corresponding to the IP detection interval, including: extracting sub-intervals based on the priority corresponding to the IP detection interval; when the sub-interval matching fails, the parent interval corresponding to the sub-interval is extracted for matching.

[0018] According to one aspect of this application, a warning device for abnormal network attack traffic is proposed. The device includes: a detection module for extracting the IP address of the abnormal network attack traffic when the detection device detects abnormal network attack traffic; an interval module for extracting multiple preset IP detection intervals; an extraction module for extracting target IP detection intervals one by one based on the priority corresponding to the IP detection intervals; a matching module for matching the IP address with the target IP detection interval; and a warning module for generating warning information for abnormal network attack traffic based on the IP address after successful matching.

[0019] According to one aspect of this application, an electronic device is provided, comprising: one or more processors; a storage device for storing one or more programs; and, when the one or more programs are executed by the one or more processors, causing the one or more processors to implement the method as described above.

[0020] According to one aspect of this application, a computer-readable medium is provided having a computer program stored thereon that, when executed by a processor, implements the method described above.

[0021] According to the network attack abnormal traffic warning method, device, electronic device, and computer-readable medium of this application, when a detection device detects network attack abnormal traffic, it extracts the IP address of the abnormal traffic; extracts multiple preset IP detection intervals; extracts target IP detection intervals one by one based on the priority of the corresponding IP detection intervals; matches the IP address and the target IP detection interval; and generates network attack abnormal traffic warning information based on the IP address after successful matching. This method can reasonably and efficiently utilize the detection capabilities of the detection device, quickly and accurately report abnormal IP traffic alarm information to the management platform, and make the maintenance work of network operation and maintenance personnel more convenient.

[0022] It should be understood that the above general description and the following detailed description are merely exemplary and do not limit this application. Attached Figure Description

[0023] The above and other objects, features, and advantages of this application will become more apparent from the detailed description of exemplary embodiments with reference to the accompanying drawings. The drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.

[0024] Figure 1 This is a block diagram illustrating an application scenario of a method and apparatus for alerting abnormal network attack traffic according to an exemplary embodiment.

[0025] Figure 2 This is a flowchart illustrating a method for alerting abnormal network attack traffic according to an exemplary embodiment.

[0026] Figure 3 This is a schematic diagram illustrating a method for alerting abnormal network attack traffic according to another exemplary embodiment.

[0027] Figure 4 This is a flowchart illustrating a method for alerting abnormal network attack traffic according to another exemplary embodiment.

[0028] Figure 5 This is a block diagram illustrating an alarm device for abnormal network attack traffic according to an exemplary embodiment.

[0029] Figure 6 This is a block diagram illustrating an electronic device according to an exemplary embodiment.

[0030] Figure 7 This is a block diagram illustrating a computer-readable medium according to an exemplary embodiment. Detailed Implementation

[0031] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, they are provided so that this application will be thorough and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. The same reference numerals in the drawings denote the same or similar parts, and therefore repeated descriptions of them will be omitted.

[0032] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. Numerous specific details are provided in the following description to give a thorough understanding of embodiments of this application. However, those skilled in the art will recognize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, apparatuses, steps, etc., can be employed. In other instances, well-known methods, apparatuses, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this application.

[0033] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.

[0034] The flowcharts shown in the accompanying drawings are merely illustrative and do not necessarily include all content and operations / steps, nor do they necessarily have to be performed in the described order. For example, some operations / steps can be broken down, while others can be combined or partially combined; therefore, the actual execution order may change depending on the specific circumstances.

[0035] It should be understood that although the terms first, second, third, etc., may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Therefore, the first component discussed below may be referred to as the second component without departing from the teachings of this application. As used herein, the term "and / or" includes all combinations of any one and more of the associated listed items.

[0036] Those skilled in the art will understand that the accompanying drawings are merely schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing this application, and therefore cannot be used to limit the scope of protection of this application.

[0037] The technical abbreviations used in this application are explained as follows:

[0038] DDoS attack: Distributed Denial of Service (DDoS) attack refers to an attack launched simultaneously by multiple attackers located in different locations against one or more targets, or an attacker controlling multiple machines located in different locations and using these machines to launch attacks against the victim simultaneously. Because the attack originates from different places, this type of attack is called a distributed denial-of-service attack, and there can be multiple attackers involved.

[0039] Traffic detection device: A device that performs real-time detection of DDoS attack traffic according to certain rules and periodically reports traffic logs. When abnormal traffic is detected, it will promptly send an abnormal traffic alarm log.

[0040] Figure 1 This is a block diagram illustrating an application scenario of a method and apparatus for alerting abnormal network attack traffic according to an exemplary embodiment.

[0041] like Figure 1 As shown, system architecture 10 may include terminal devices 101, 102, and 103, network 104, and traffic detection devices 105, servers 106, 107, and 108. Network 104 serves as the medium for providing communication links between terminal devices 101, 102, and 103 and traffic detection device 105, between traffic detection device 105 and servers 106, 107, and 108, and between terminal devices 101, 102, and 103 and servers 106, 107, and 108. Network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0042] Users can use terminal devices 101, 102, and 103 to interact with servers 106, 107, and 108 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, and social media platform software.

[0043] Terminal devices 101, 102, and 103 can be various electronic devices with displays and web browsing capabilities, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0044] Servers 106, 107, and 108 can be servers providing various services, such as backend management servers supporting shopping websites browsed by users using terminal devices 101, 102, and 103. The backend management server can analyze and process received data such as product information query requests, and then feed the processing results back to terminal devices 101, 102, and 103.

[0045] Traffic detection device 105 can detect the data traffic accessing servers 106, 107, and 108, and generate warning information when abnormal network attack traffic is detected.

[0046] The traffic detection device 105 may, for example, extract the IP address of the abnormal traffic when it detects abnormal traffic from a network attack; the traffic detection device 105 may, for example, extract multiple preset IP detection ranges; the traffic detection device 105 may, for example, extract target IP detection ranges one by one based on the priority corresponding to the IP detection ranges; the traffic detection device 105 may, for example, match the IP address with the target IP detection range; and the traffic detection device 105 may, for example, generate a warning message for abnormal traffic from a network attack based on the IP address after a successful match.

[0047] The traffic detection device 105 can be a physical network device, or it can be composed of multiple servers, for example. It should be noted that the network attack abnormal traffic warning method provided in this application embodiment can be executed by the traffic detection device 105. Correspondingly, the network attack abnormal traffic warning device can be set in the traffic detection device 105.

[0048] Figure 2 This is a flowchart illustrating an exemplary method for alerting abnormal network attack traffic. The method 20 for alerting abnormal network attack traffic includes at least steps S202 to S210.

[0049] like Figure 2 As shown in S202, when the detection device detects abnormal network attack traffic, it extracts the IP address of the abnormal traffic. For example, the detection device performs real-time detection of DDoS attacks; when the real-time acquired abnormal network attack traffic exceeds a traffic threshold, it extracts the IP address of the abnormal traffic.

[0050] More specifically, the detection equipment can perform real-time deep packet inspection on the current traffic; it can also perform traffic statistical analysis on the current traffic. When a DDoS attack occurs, the detection equipment aggregates user traffic information and performs real-time deep packet inspection or traffic statistical analysis on the traffic according to set thresholds.

[0051] Traffic detection devices detect attack traffic according to certain detection standards. They can perform deep packet inspection (DPI) on real traffic to provide the most accurate analysis and relatively complete statistical data. However, this places excessive demands on device performance when detecting very large volumes of traffic. Alternatively, traffic statistics can be performed by receiving flow information such as NetFlow / NetStream / nFlow. This method is well-suited for large-scale traffic analysis, but the statistical data is coarse and information is delayed. Different monitoring methods can be selected for different IP addresses based on business needs; this application is not limited to this.

[0052] In S204, multiple preset IP detection ranges are extracted. The abnormal traffic management platform can pre-distribute multiple IP detection ranges and their corresponding priorities to the detection devices.

[0053] In S206, the target IP detection intervals are extracted one by one based on the priority corresponding to the IP detection intervals.

[0054] In step S208, the IP address is matched with the target IP detection interval. Sub-intervals are extracted based on the priority corresponding to the IP detection interval; if a sub-interval match fails, the parent interval corresponding to the sub-interval is extracted for matching.

[0055] Once abnormal traffic is detected, the IP address carrying the abnormal traffic will be detected and matched with the IP segment with the highest priority number on the device according to the priority number of the detected IP segment. If the abnormal IP address is not matched with an IP address in the highest priority IP segment, the next level of IP segment will be selected according to the priority of the IP segment, and so on.

[0056] It's worth noting that for traffic detection device A, the IP ranges sent to it can include sub-ranges b1, b2, and c1, and parent ranges B, C, and D. To facilitate processing by the detection device, it can first detect the IPs in sub-ranges b1 and b2. If no abnormal IPs are found in sub-ranges b1 and b2, then sub-range c1 is detected. If no abnormal IPs are found in sub-range c1, then parent range B is detected, followed by parent range C, and finally parent range D. When detecting parent ranges B and C, sub-ranges b1, b2, and c1 can be skipped.

[0057] In step S210, after a successful match, an alert message for abnormal network attack traffic is generated based on the IP address. If the abnormal IP matches an IP in a certain priority IP range, the traffic detection device will send an abnormal IP traffic alarm message to the abnormal traffic management platform, which will then acquire and display the abnormal IP traffic rate information in real time.

[0058] The traffic detection device implements a nested configuration of detection IPs and assigns anomaly detection hit priorities to these IP ranges. This allows the detection device to actively and dynamically call the nested IP ranges. Based on the nesting relationship of the detection IPs, the device first matches IPs carrying abnormal traffic against the highest priority IP range. If a match is found, an abnormal traffic alarm is reported to the traffic management platform. If an IP carrying abnormal traffic does not match an IP in a high-priority IP range, the device actively matches IPs in a low-priority IP range. If a match is found, an abnormal traffic alarm is reported.

[0059] According to the network attack abnormal traffic warning method of this application, when the detection device detects network attack abnormal traffic, it extracts the IP address of the abnormal traffic; extracts multiple preset IP detection intervals; extracts target IP detection intervals one by one based on the priority of the IP detection intervals; matches the IP address and the target IP detection interval; and generates network attack abnormal traffic warning information based on the IP address after successful matching. This method can reasonably and efficiently utilize the detection capabilities of the detection device, quickly and accurately report abnormal IP traffic alarm information to the management platform, and make the maintenance work of network operation and maintenance personnel more convenient.

[0060] It should be clearly understood that this application describes how specific examples are formed and used, but the principles of this application are not limited to any details of these examples. Rather, based on the teachings of the disclosure of this application, these principles can be applied to many other embodiments.

[0061] Figure 3 This is a schematic diagram illustrating a method for alerting abnormal network attack traffic according to another exemplary embodiment. Multiple traffic detection devices can be managed using an abnormal traffic management platform, which distributes nested configuration detection IPs to the detection devices. In practical applications, the traffic detection devices obtain real-time traffic data from a router for detection.

[0062] Nested configuration for detecting IPs means allowing multiple IP ranges or IP masks with a nested relationship to be configured on the abnormal traffic management platform and traffic detection device, as shown in the attachment. Figure 3 As shown, these large and small IP segments form a nested configuration. The large IP segment can be called the parent segment of the small IP segment, or simply the parent segment. The small IP segment is the child segment of the large IP segment, or simply the child segment. The abnormal traffic management platform sends the nested IP segments to the designated detection devices by calling the device's interface. After receiving the nested detection IPs from the platform, the detection device assigns anomaly detection priority to these IP segments, i.e., smaller IP segments are given higher priority, and larger IP segments are given lower priority. The priority relationship of each IP segment can also be determined by the user during configuration.

[0063] In a practical application scenario, if the IP range that the user wants to detect changes frequently, the user can configure the detection IPs nested in the traffic detection device, and the device will automatically change the detection IP range. This can make full use of the device's detection capabilities to achieve accurate traffic identification, and also achieve the goal of flexibly configuring the detection IPs.

[0064] According to the network attack abnormal traffic alert method of this application, in the case of multiple detection devices, the nested configuration of detection IP segments is distributed to the detection devices through the detection device management platform. The detection devices dynamically and reasonably call the detection IP segments, matching DDoS attacks with more IPs to larger detection IP segments and DDoS attacks with fewer IPs to smaller detection IP segments. This achieves reasonable and efficient use of the detection capabilities of the detection devices, and quickly and accurately reports abnormal IP traffic alarm information to the management platform, making it more convenient for network operation and maintenance personnel to perform maintenance work.

[0065] Figure 4 This is a flowchart illustrating a method for alerting abnormal network attack traffic according to another exemplary embodiment. Figure 4 The process 40 shown is a detailed description of "the abnormal traffic management platform distributes multiple IP detection ranges and their corresponding priorities to multiple detection devices".

[0066] like Figure 4 As shown, in S402, multiple parent intervals are generated according to business requirements.

[0067] In S404, sub-intervals are generated by detecting a portion of the IP addresses within the parent interval. Historical network attack anomaly traffic within the parent interval can be analyzed to identify core intervals; these core intervals are then extracted from the parent interval to generate the sub-intervals.

[0068] In S406, the multiple IP detection intervals are generated by the multiple parent intervals and their corresponding child intervals.

[0069] Nested configuration of detection IPs can be implemented on the abnormal traffic management platform and detection devices, and can be displayed in layers. The abnormal traffic management platform sends nested configured IPs to the detection devices, and the detection devices change from calling a single detection IP segment to actively calling the nested configured IP segments.

[0070] In step S408, the plurality of IP detection intervals and their corresponding priorities are sent to the plurality of detection devices. The parent interval and its corresponding child interval in the plurality of IP detection intervals are treated as a set of intervals; each set of intervals in the plurality of intervals is sent as a whole to the detection devices.

[0071] The detection device will first select the high-priority detection IP segment to report abnormal traffic alarm information based on the nesting relationship and priority of the detected IP segments. If no IP in the high-priority detection IP segment is found, it will actively try to match IP in the low-priority IP segment. If a match is found, abnormal traffic alarm information will be reported.

[0072] The abnormal traffic management system implements nested IP configuration for detection. The management system calls an interface to send detection IPs to the traffic detection devices. After receiving abnormal traffic alarm information from the detection devices, the management platform will also prioritize displaying abnormal IP traffic rate information from IPs within the corresponding priority IP ranges based on the priority relationship of the nested IPs.

[0073] According to the network attack abnormal traffic alert method of this application, in the case of multiple detection devices, the detection IPs are nested and distributed to the devices through the detection device management platform, allowing the detection IPs to have an inclusion relationship. When the detection device detects abnormal DDoS attack traffic, it will prioritize matching the IP carrying the abnormal traffic to a smaller detection IP range. If an IP in that range is matched, an alarm log is generated and sent to the management platform. If no smaller IP range is matched, it will automatically switch to matching a larger detection IP range. If a match is found, an alarm log is generated and sent to the management platform. This method makes reasonable and efficient use of the detection capabilities of the detection devices and facilitates the maintenance work of technical personnel.

[0074] Those skilled in the art will understand that all or part of the steps of the above embodiments are implemented as a computer program executed by a CPU. When the computer program is executed by the CPU, it performs the functions defined by the method provided in this application. The program can be stored in a computer-readable storage medium, such as a read-only memory, a magnetic disk, or an optical disk.

[0075] Furthermore, it should be noted that the above figures are merely illustrative representations of the processes included in the method according to exemplary embodiments of this application, and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0076] The following are embodiments of the apparatus described in this application, which can be used to execute the embodiments of the method described in this application. For details not disclosed in the apparatus embodiments of this application, please refer to the embodiments of the method described in this application.

[0077] Figure 5 This is a block diagram illustrating an alarm device for abnormal network attack traffic according to an exemplary embodiment. Figure 5 As shown, the network attack abnormal traffic warning device 50 includes: detection module 502, interval module 504, extraction module 506, matching module 508, and warning module 510. The network attack abnormal traffic warning device 50 may also include: platform module 512.

[0078] The detection module 502 is used to extract the IP address of abnormal network attack traffic when the detection device detects abnormal network attack traffic; the detection module 502 is also used to detect DDoS attacks in real time; when the abnormal network attack traffic obtained in real time exceeds the traffic threshold, the IP address of the abnormal traffic is extracted.

[0079] The interval module 504 is used to extract multiple preset IP detection intervals;

[0080] Extraction module 506 is used to extract target IP detection intervals one by one based on the priority corresponding to the IP detection intervals;

[0081] The matching module 508 is used to match the IP address with the target IP detection range; the matching module 508 is also used to extract sub-ranges based on the priority corresponding to the IP detection range; when the sub-range matching fails, the parent range corresponding to the sub-range is extracted for matching.

[0082] The warning module 510 is used to generate warning information about abnormal network attack traffic based on the IP address after a successful match.

[0083] Platform module 512 is used to distribute multiple IP detection ranges and their corresponding priorities to multiple detection devices. Platform module 512 is also used to generate multiple parent ranges according to business requirements; generate child ranges from some IP detection ranges in the parent ranges; generate the multiple IP detection ranges from the multiple parent ranges and their corresponding child ranges; and distribute the multiple IP detection ranges and their corresponding priorities to the multiple detection devices.

[0084] The network attack abnormal traffic warning device of this application extracts the IP address of the abnormal traffic when the detection device detects network attack abnormal traffic; extracts multiple preset IP detection intervals; extracts target IP detection intervals one by one based on the priority of the IP detection intervals; matches the IP address with the target IP detection interval; and generates network attack abnormal traffic warning information based on the IP address after successful matching. This method can reasonably and efficiently utilize the detection capabilities of the detection device, quickly and accurately report abnormal IP traffic alarm information to the management platform, and make the maintenance work of network operation and maintenance personnel more convenient.

[0085] Figure 6 This is a block diagram illustrating an electronic device according to an exemplary embodiment.

[0086] The following reference Figure 6 To describe an electronic device 600 according to this embodiment of the present application. Figure 6 The electronic device 600 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0087] like Figure 6 As shown, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include, but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different system components (including storage unit 620 and processing unit 610), a display unit 640, etc.

[0088] The storage unit stores program code that can be executed by the processing unit 610, causing the processing unit 610 to perform the steps described in this specification according to various exemplary embodiments of this application. For example, the processing unit 610 can perform actions such as... Figure 2 , Figure 4 The steps are shown in the figure.

[0089] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access memory unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only memory unit (ROM) 6203.

[0090] The storage unit 620 may also include a program / utility 6204 having a set (at least one) program module 6205, such program module 6205 including but not limited to: an operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0091] Bus 630 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.

[0092] Electronic device 600 can also communicate with one or more external devices 600' (e.g., keyboard, pointing device, Bluetooth device, etc.), enabling users to communicate with devices that interact with electronic device 600, and / or any device that allows electronic device 600 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 650. Furthermore, electronic device 600 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 660. Network adapter 660 can communicate with other modules of electronic device 600 via bus 630. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0093] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software, or by combining software with necessary hardware. Therefore, as... Figure 7 As shown, the technical solution according to the embodiments of this application can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, mobile hard drive, etc.) or on a network, and includes several instructions to cause a computing device (such as a personal computer, server, or network device, etc.) to execute the above-described method according to the embodiments of this application.

[0094] The software product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections with one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0095] Overall,

[0096] In the case of multiple detection devices, a nested configuration of detection IPs is used to distribute them to the devices through a detection device management platform, allowing the detection IPs to have an inclusion relationship. When a detection device detects abnormal DDoS attack traffic, it will prioritize matching the IP carrying the abnormal traffic against smaller detection IP ranges. If a match is found with an IP in that range, an alarm log is generated and sent to the management platform. If no smaller IP range is matched, it automatically switches to matching larger detection IP ranges. If a match is found, an alarm log is generated and sent to the management platform. This method makes reasonable and efficient use of the detection capabilities of the detection devices and facilitates maintenance work for technical personnel. Therefore, this disclosure utilizes an abnormal traffic management platform to manage multiple traffic detection devices, and then distributes nested configuration of detection IPs to the detection devices through the management platform. Nested configuration of detection IPs means that multiple IP ranges or IP masks with an inclusion relationship are allowed to be configured on the abnormal traffic management platform and the traffic detection devices. These large and small IP ranges form a nested configuration relationship. We can call the large IP range the parent node of the small IP range, or simply the parent node. The small IP range is the child node of the large IP range, or simply the child node. The abnormal traffic management platform sends nested IP ranges to designated detection devices by calling the device's interface. Upon receiving the nested IPs from the platform, the detection device assigns anomaly detection priorities to these IP ranges, with smaller IP ranges receiving higher priority and larger IP ranges receiving lower priority. The priority relationship for each IP range can also be determined by the user during configuration. Traffic detection devices detect attack traffic according to certain detection standards. They can perform DPI (Deep Packet Inspection) to analyze real traffic for the most accurate and comprehensive statistical data. However, this places high demands on device performance when detecting very large volumes of traffic. Alternatively, they can receive flow information such as NetFlow / NetStream / nFlow for traffic statistical analysis. This method is well-suited for large-scale traffic statistics, but the statistical data is coarse and information is delayed. When a DDoS attack occurs, the detection device aggregates user traffic information and performs real-time deep packet inspection or traffic statistical analysis based on set thresholds. Upon detecting abnormal traffic, the traffic detection device will prioritize matching the IP address carrying the abnormal traffic to the highest priority IP segment on the device, based on the priority number of the detected IP segment. If the abnormal IP address does not match an IP address in the highest priority IP segment, the next highest priority IP segment will be considered, and so on. If the abnormal IP address matches an IP address in a certain priority IP segment, the traffic detection device will send an abnormal IP traffic alarm message to the abnormal traffic management platform. The abnormal traffic management platform will then obtain and display the abnormal IP traffic rate information in real time.In a certain network application scenario, if the IP range to be detected changes frequently, the user can configure nested detection IPs on the traffic detection device. The device will then automatically change the detection IP range, thus fully utilizing the device's detection capabilities for accurate traffic identification and achieving flexible configuration of detection IPs. This disclosure, in the case of multiple detection devices, uses a detection device management platform to distribute nested detection IP ranges to the detection devices. The detection devices dynamically and rationally allocate these IP ranges, matching DDoS attacks with more IPs to larger detection IP ranges and DDoS attacks with fewer IPs to smaller detection IP ranges. This achieves efficient and rational utilization of the detection device's capabilities, quickly and accurately reporting abnormal IP traffic alarms to the management platform, and facilitating network maintenance personnel's work.

[0097] The computer-readable storage medium may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. The readable storage medium may also be any readable medium other than a readable storage medium, capable of transmitting, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0098] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's computing device, partially on the user's device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0099] The aforementioned computer-readable medium carries one or more programs. When the one or more programs are executed by the device, the computer-readable medium performs the following functions: when the detection device detects abnormal network attack traffic, it extracts the IP address of the abnormal traffic; extracts multiple preset IP detection intervals; extracts target IP detection intervals one by one based on the priority corresponding to the IP detection intervals; matches the IP address with the target IP detection interval; and after a successful match, generates a warning message for abnormal network attack traffic based on the IP address.

[0100] Those skilled in the art will understand that the above modules can be distributed in the device as described in the embodiments, or they can be modified accordingly and placed in one or more devices that are unique to this embodiment. The modules in the above embodiments can be combined into one module, or they can be further divided into multiple sub-modules.

[0101] Through the description of the above embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, mobile terminal, or network device, etc.) to execute the methods according to the embodiments of this application.

[0102] Exemplary embodiments of this application have been specifically shown and described above. It should be understood that this application is not limited to the detailed structures, arrangements, or implementation methods described herein; rather, this application is intended to cover various modifications and equivalent arrangements contained within the spirit and scope of the appended claims.

Claims

1. A method for alerting abnormal network attack traffic, characterized in that, include: When the detection equipment detects abnormal network attack traffic, it extracts the IP address of the abnormal traffic. Extract multiple preset IP detection ranges; Target IP detection intervals are extracted one by one based on the priority corresponding to the IP detection intervals. Match the IP address with the target IP detection range; Upon successful matching, an alert message regarding abnormal network attack traffic is generated based on the IP address; The abnormal traffic management platform distributes multiple IP detection ranges and their corresponding priorities to multiple detection devices, including: Generate multiple parent ranges based on business requirements; Generating sub-intervals by detecting a portion of the IP addresses in the parent interval includes: analyzing historical network attack anomaly traffic in the parent interval to determine the core interval; extracting the core interval from the parent interval to generate the sub-interval; setting a high priority for the sub-interval; and setting a low priority for the parent interval. The multiple IP detection intervals are generated by the multiple parent intervals and their corresponding child intervals; The multiple IP detection ranges and their corresponding priorities are distributed to the multiple detection devices.

2. The method as described in claim 1, characterized in that, Distributing the multiple IP detection ranges and their corresponding priorities to the multiple detection devices includes: The parent interval and its corresponding child interval in multiple IP detection intervals are combined into a set of intervals; Each set of multiple intervals is sent to the detection device as a whole.

3. The method as described in claim 1, characterized in that, When the detection equipment detects abnormal network attack traffic, it extracts the IP addresses of the abnormal traffic, including: The detection equipment performs real-time detection of DDoS attacks; When the abnormal network attack traffic acquired in real time exceeds the traffic threshold, the IP address of the abnormal traffic is extracted.

4. The method as described in claim 3, characterized in that, The detection equipment performs real-time detection of DDoS attacks, including: The detection equipment performs real-time deep packet inspection on the current traffic; and / or The detection equipment performs flow statistics analysis on the current flow rate.

5. The method as described in claim 1, characterized in that, Based on the priority corresponding to the IP detection interval, the target IP detection interval is extracted one by one, including: Sub-intervals are extracted based on the priority corresponding to the IP detection interval; If a sub-interval match fails, the parent interval corresponding to the sub-interval is extracted for matching.

6. A warning device for abnormal network attack traffic, characterized in that, include: The detection module is used to extract the IP address of abnormal traffic when the detection device detects abnormal traffic from network attacks. The interval module is used to extract multiple preset IP detection intervals; The extraction module is used to extract target IP detection intervals one by one based on the priority corresponding to the IP detection intervals; The matching module is used to match the IP address with the target IP detection range; The alert module is used to generate alert information about abnormal network attack traffic based on the IP address after a successful match; An abnormal traffic management platform distributes multiple IP detection ranges and their corresponding priorities to multiple detection devices. This includes: generating multiple parent ranges based on business needs; generating sub-ranges from a portion of the IP detection ranges within the parent ranges; generating the multiple IP detection ranges from the parent ranges and their corresponding sub-ranges; and distributing the multiple IP detection ranges and their corresponding priorities to the multiple detection devices. Specifically, generating sub-ranges from a portion of the IP detection ranges within the parent ranges includes: analyzing historical network attack abnormal traffic from the parent ranges to determine core ranges; extracting the core ranges from the parent ranges to generate the sub-ranges; assigning high priority to the sub-ranges; and assigning low priority to the parent ranges.