Attack protection method, device, electronic device and storage medium
By using VPP and DPDK plug-in loading software to perform DDoS protection detection in the server user space, the problems of high costs and insufficient coverage in the existing technology are solved, and efficient DDoS protection is achieved.
Patent Information
- Application Number
- CN202110849679.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-07-27
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2041-07-27
AI Technical Summary
The existing DDoS protection solutions are costly to deploy at the network level, insufficient coverage, difficult to effectively protect small cloud servers and edge computing centers, and it is difficult for customers to deploy proprietary protection equipment in other people's cloud service network environments.
Receive access data in the server's user space, and implement attack protection detection through plug-in loading software such as VPP and DPDK, bypass the kernel protocol stack, improve detection performance and determine the target access source.
It reduces the cost of DDoS protection, improves detection performance, and enhances the operability of protection. It is suitable for various cloud computing environments.
Smart Images

Figure CN115694853B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network technology, and in particular to an attack protection method, device, electronic device and storage medium. Background Art
[0002] A denial-of-service (DoS) attack is a network attack in which an attacker attempts to render a computer or network resource unavailable to its intended users by temporarily or indefinitely disrupting service to hosts connected to the network. A DoS attack is typically implemented by flooding the target host or resource with unnecessary requests, overloading the system and preventing some or all legitimate requests from being fulfilled.
[0003] Distributed denial-of-service (DDoS) attacks, in which attack traffic originates from various sources, are often mitigated by existing DDoS protection solutions that typically attach dedicated anti-DDoS protection devices to intermediate network devices, such as core switches. This means that dedicated hardware is attached to the core switch to provide protection.
[0004] However, this protection scheme has several limitations:
[0005] First, it is not easy to operate because the network architecture is invasive. The customer who needs to perform network layer protection and the server provider who provides the cloud service network are usually two different parties. It is difficult for customers to deploy such a set of network layer protection equipment in someone else's cloud service network environment.
[0006] The second problem is insufficient coverage. For some smaller cloud servers, virtual hosts, or edge computing centers, these types of servers are difficult to cover. This is because the cost of deploying this type of network-layer DDoS protection equipment is huge, and deploying it in these scenarios is not worth the cost. Summary of the Invention
[0007] To address the problems of the prior art, embodiments of the present invention provide an attack protection method, device, electronic device, and storage medium. The technical solution is as follows:
[0008] In a first aspect, an attack protection method is provided, the method comprising:
[0009] receiving at least one access data based on the original interface; the original interface is located in the user space of the server;
[0010] Performing attack protection detection on at least one access data in the user space to obtain a protection detection result;
[0011] A target access source is determined from access sources corresponding to at least one access data according to the protection detection result.
[0012] In a second aspect, an attack protection device is provided, the device comprising:
[0013] A data receiving unit, configured to receive at least one access data based on an original interface; the original interface is located in a user space of the server;
[0014] a protection detection unit, configured to perform attack protection detection on at least one access data in a user space and obtain a protection detection result;
[0015] The access source determination unit is used to determine a target access source from the access sources corresponding to at least one access data according to the protection detection result.
[0016] In a third aspect, a computer-readable storage medium is provided, in which at least one instruction or at least one program is stored, and the at least one instruction or at least one program is loaded and executed by a processor to implement the attack protection method as described in the first aspect above.
[0017] In a fourth aspect, a computer program product or computer program is provided, comprising computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the attack protection method provided in the first aspect.
[0018] An embodiment of the present invention receives at least one access data based on an original interface located in the user space of a server. In the user space, attack protection detection is performed on the at least one access data to obtain a protection detection result. Based on the protection detection result, a target access source is determined from the access sources corresponding to the at least one access data. This method differs from directly implementing attack protection detection on access data by attaching hardware. Instead, attack protection detection is performed on the at least one access data in the user space of the server, increasing its operability and reducing costs. Furthermore, because it operates in user space, it significantly improves the performance of attack protection detection processing on access data. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0020] Figure 1 is a schematic diagram of an implementation environment provided by an embodiment of the present invention;
[0021] Figure 2 is a schematic diagram of an implementation environment provided by an embodiment of the present invention;
[0022] Figure 3 This is a flow chart of an attack protection method provided by an embodiment of the present invention;
[0023] Figure 4 This is a schematic diagram of a process for performing attack protection detection provided by an embodiment of the present invention;
[0024] Figure 5 This is a flow chart of attack protection detection provided by an embodiment of the present invention.
[0025] Figure 6 This is a structural block diagram of an attack protection device provided by an embodiment of the present invention;
[0026] Figure 7 This is a hardware structure block diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way are interchangeable where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0029] See also Figure 1 , which shows a schematic diagram of an implementation environment provided by an embodiment of the present invention, the implementation environment is a traditional server network architecture, which may include a server 10 and an access source 11. Figure 1As shown, the server 10 may include a service processing device 101 for processing service requests from an access source 11. Optionally, when the service processing device 101 is located in the server 10, the service processing device may be considered a service processing module in the server 10. The access source 11 may be a gateway device, such as a router or switch. One side of the access source 11 may be connected to the server 10, and the other side may be connected to a client.
[0030] Optionally, the server 10 may further include an original interface 102 connecting the service processing device 101 and the access source 11 . The server 10 receives a service request from the access source 11 based on the original interface 102 and sends the service request to the service processing device 101 through the original interface 102 .
[0031] The original interface runs in the kernel space of the server and is a virtual interface in kernel state. Specifically, the server 10 may be a public cloud server, which has a virtual network card driver in its kernel space. The public cloud server can identify the original interface through the virtual network card driver, receive data packets (service requests) based on the original interface in the kernel space, and send the service requests to the service processing device. When the service processing device determines feedback data based on the service request, the server 10 can feed the feedback data back to the access source 11 through the original interface.
[0032] However, when this traditional server network architecture encounters a denial-of-service (DoS) attack or a distributed denial-of-service (DDoS) attack, the attacker can temporarily or indefinitely disrupt the services of hosts connected to the network, making the server unavailable to its intended users.
[0033] In the embodiments of the present application, a denial-of-service (DoS) attack refers to an attacker's attempt to stop the victim (e.g., a target server) from providing services. Consuming network bandwidth is only a small part of a DoS attack. Any attack that can cause trouble to the victim, such as suspending certain services on the victim's computer or even crashing the target host, is considered a DoS attack.
[0034] In the embodiments of the present application, a distributed denial-of-service attack (DDoS) is a type of attack that is derived from traditional DoS attacks. Single DoS attacks are generally carried out in a one-on-one manner. When the target host has low CPU speed, limited memory, or low network bandwidth, the DoS attack is most effective. However, with the development of computer and network technology, such as the rapid growth of computer processing power and memory, as well as the emergence of gigabit-class networks, DoS attacks have become more difficult to carry out. For example, an attacker can send 3,000 attack packets per second, but the target host (the target server) and its network bandwidth can only process 10,000 attack packets per second. In this case, the attack will have little significant effect. At this point, a distributed denial-of-service (DDoS) attack comes into being. Compared to a single DoS attack, which uses one attacker to target one target, a distributed denial-of-service (DDoS) attack provides different attackers, such as using larger-scale attack software to attack the target host, making the attack effect on the current target host equally significant.
[0035] There are many methods for performing DoS and DDoS attacks, and SYNFLOOD flood attacks are a common one. SYNFLOOD exploits a flaw in the Transmission Control Protocol (TCP) to send a large number of forged TCP connection requests, causing the target host to exhaust its resources (CPU saturation or insufficient memory).
[0036] The SYN Flood attack process is called the three-way handshake in the TCP protocol, and the SYN Flood denial of service attack is achieved through the three-way handshake. Generally speaking, the steps of the three-way handshake under normal circumstances are as follows:
[0037] The visitor sends a TCP packet containing the SYN flag to the server. SYN (Synchronize) indicates the port used by the client and the initial sequence number of the TCP connection. This is when the visitor and the server establish the first handshake.
[0038] After receiving the visitor's SYN message, the server will return a SYN+ACK message, indicating that the visitor's request is accepted. At the same time, the TCP sequence number is increased by one. The ACK (Acknowledgment) is the confirmation information, so that the visitor and the server establish a second handshake.
[0039] The visitor also returns an acknowledgment message ACK to the server, and the TCP sequence number is also increased by one. At this point, a TCP connection is completed and the three-way handshake is completed.
[0040] However, when the three-way handshake of a TCP connection is established between an attacker and a victim, suppose a visitor sends a SYN packet to the server and then suddenly crashes or goes offline. After sending a SYN+ACK reply packet, the server will not receive the visitor's ACK packet (the third handshake cannot be completed). In this case, the server will generally retry (send SYN+ACK to the visitor again) and wait for a period of time before abandoning the incomplete connection. The length of this period is called the SYN timeout, and it is generally on the order of minutes (approximately 30 seconds to 2 minutes). A visitor's anomaly causing a server thread to wait for a minute is not a big problem, but if a malicious attacker simulates this situation in large quantities (forging IP addresses), the server will consume a lot of resources to maintain a very large list of half-connected connections. Even simply storing and iterating can consume a lot of CPU time and memory, not to mention the need to constantly retry SYN+ACK for the IP addresses in this list. In fact, if the server's TCP / IP stack is not powerful enough, the final result is often a stack overflow and crash. Even if the server's system is powerful enough, the server will be busy processing the attacker's forged TCP connection requests and will have no time to pay attention to the client's normal requests (after all, the client's normal request ratio is very small). At this time, from the perspective of a normal client, the server has lost response. This situation is called: the server side has been attacked by a SYN Flood, that is, a SYN flood attack.
[0041] Based on this, the embodiment of the present application provides a server network architecture that can perform attack protection to protect against distributed denial of service attacks DDoS. Figure 2 , which shows a schematic diagram of an implementation environment provided by an embodiment of the present invention, the implementation environment may include a server 20 and an access source 21. Figure 2As shown, the server 20 may include a service processing device 201 for processing service requests from an access source 21. Optionally, when the service processing device 201 is located in the server 20, the service processing device 201 may be considered as a service processing module in the server 20. The access source 21 may be a gateway device, such as a router, a switch, etc., and one side of the access source 21 may be connected to the server 20, and the other side may be connected to the client ( Figure 2 not shown in the figure).
[0042] The server 20 may further include a switching module 202, which may be generated based on plug-in loading software provided in the server 20. The switching module 202 may include an attack protection module 204, which may be generated by loading a protection plug-in using the plug-in loading software. The running attack protection module 204 may perform protection attack detection on at least one access data in user space to obtain a protection detection result.
[0043] Optionally, the server 20 may further include an original interface 203 connecting the switching module 202 and the access source 21. The original interface 203 is a plug-in loading software that loads a preset takeover plug-in, so that the preset takeover plug-in can access the original interface (such as Figure 1 The original interface in the kernel state shown in FIG. 1 is taken over to obtain the original interface in the user space at the current time.
[0044] Optionally, the server 20 may further include a virtual interface 205 connecting the service processing device 201 and the switching module. The virtual interface 205 is created by plug-in loading software after startup and is located in the kernel space.
[0045] Specifically, the server 20 may receive at least one access data based on an original interface, where the original interface is located in the user space of the server, and perform attack protection detection on the at least one access data in the user space to obtain a protection detection result. Finally, the server may determine a target access source from the access sources corresponding to the at least one access data based on the protection detection result.
[0046] In some possible embodiments, Figure 2 The server 10 and Figure 2The server 20 shown can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, as well as big data and artificial intelligence platforms. The present invention does not impose any restrictions on this.
[0047] In the embodiments of this application, cloud computing is a computing model that distributes computing tasks across a resource pool consisting of a large number of computers, enabling various application systems to obtain computing power, storage space, and information services as needed. The network that provides resources is called the "cloud." The resources in the "cloud" appear to users to be infinitely scalable and can be accessed at any time, used on demand, expanded at any time, and paid for on a per-use basis. As a provider of cloud computing infrastructure capabilities, a cloud computing resource pool (referred to as a cloud platform, generally referred to as an IaaS (Infrastructure as a Service) platform) will be established. Various types of virtual resources will be deployed in the resource pool for external customers to choose from. The cloud computing resource pool mainly includes: computing devices (virtualized machines, including operating systems), storage devices, and network devices. According to logical functional division, the PaaS (Platform as a Service) layer can be deployed on the IaaS (Infrastructure as a Service) layer, and the SaaS (Software as a Service) layer can be deployed on the PaaS layer. SaaS can also be deployed directly on IaaS. PaaS is a platform for software operation, such as databases and web containers. SaaS is a variety of business software, such as web portals and SMS mass senders. Generally speaking, SaaS and PaaS are upper layers relative to IaaS.
[0048] In the embodiments of the present application, cloud storage is a new concept extended and developed from the concept of cloud computing. A distributed cloud storage system (hereinafter referred to as the storage system) refers to a storage system that uses cluster applications, grid technology, and distributed storage file systems to bring together a large number of different types of storage devices (storage devices are also called storage nodes) in the network through application software or application interfaces to work together and provide external data storage and business access functions.
[0049] Currently, storage systems utilize a method for creating logical volumes. When creating a logical volume, physical storage space is allocated for each logical volume. This physical storage space may consist of disks on a specific storage device or several storage devices. When a client stores data on a logical volume, it stores the data on a file system. The file system divides the data into multiple parts, each of which is an object. An object contains not only the data but also additional information such as the data identifier (ID) of the data entity. The file system writes each object to the physical storage space of the logical volume and records the storage location information of each object. Therefore, when a client requests access to data, the file system can provide access to the data based on the storage location information of each object.
[0050] The storage system allocates physical storage space to logical volumes by pre-dividing the physical storage space into stripes based on the estimated capacity of the objects to be stored in the logical volume (this estimate often has a large margin relative to the actual capacity of the objects to be stored) and the Redundant Array of Independent Disks (RAID) groupings. A logical volume can be understood as a stripe, thereby allocating physical storage space to the logical volume.
[0051] In the embodiments of the present application, cloud servers may include public clouds and private clouds, wherein a public cloud generally refers to a cloud provided by a third-party provider for users to use. A public cloud is generally available through the Internet and may be free or low-cost. The core attribute of a public cloud is shared resource services. There are many instances of this type of cloud that can provide services throughout today's open public networks. A private cloud is a cloud infrastructure and software and hardware resources created within a firewall so that various departments within an organization or enterprise can share resources within the data center. In addition to hardware resources, creating a private cloud generally also includes cloud equipment (IaaS, Infrastructure as a Service) software.
[0052] Private cloud computing also encompasses three layers: cloud hardware, cloud platform, and cloud services. The difference is that the cloud hardware is the user's own personal computer or server, rather than the cloud computing vendor's data center. Cloud computing vendors build data centers to provide public cloud services to millions of users, requiring tens or even millions of servers. Private cloud computing, for individuals, only serves friends and family, while for businesses, only serves their employees, customers, and suppliers. Therefore, an individual or business's own personal computer or server is sufficient for providing cloud services.
[0053] See also Figure 3 , Figure 3The figure shows a flow chart of an attack protection method provided by an embodiment of the present invention, which can be applied to Figure 2 The system shown. It should be noted that this specification provides method operation steps as described in the embodiments or flow charts, but more or fewer operation steps may be included based on conventional or non-creative work. The order of steps listed in the embodiments is only one way of executing the steps among many steps, and does not represent the only execution order. When the actual system or product is executed, it can be executed in sequence or in parallel according to the method shown in the embodiments or the drawings (for example, in a parallel processor or multi-threaded processing environment). Specifically, Figure 3 As shown, the method may include:
[0054] In step S301 , at least one access data is received based on an original interface; the original interface is located in a user space of a server.
[0055] In the embodiment of the present application, the server may receive at least one access data based on an original interface section located in a user space of the server, and the at least one access data may be sent by at least one access source.
[0056] Optionally, the above-mentioned server may be a cloud server, which may also be referred to as a cloud virtual machine (Cloud Virtual Machine, CVM).
[0057] Cloud servers can be implemented in the form of blockchains. Blockchain is a novel application model that integrates distributed data storage, peer-to-peer transmission, consensus mechanisms, encryption algorithms, and other computer technologies. Blockchain is essentially a decentralized database, a series of data blocks linked using cryptographic methods. Each block contains information about a batch of online transactions, used to verify the validity of the information (to prevent counterfeiting) and generate the next block. Blockchain can include the underlying blockchain platform, the platform product and service layer, and the application service layer.
[0058] The underlying blockchain platform can include processing modules such as user management, basic services, smart contracts, and operation monitoring. Among them, the user management module is responsible for the identity information management of all blockchain participants, including maintaining public and private key generation (account management), key management, and maintaining the corresponding relationship between the user's real identity and the blockchain address (authority management), etc., and under authorization, it supervises and audits the transactions of certain real identities and provides risk control rule configuration (risk control audit); the basic service module is deployed on all blockchain node devices to verify the validity of business requests, and records the valid requests to the storage after consensus is reached. For a new business request, the basic service first adapts the interface to parse and authenticate the request (interface adaptation), and then encrypts the business information through the consensus algorithm (consensus management). The smart contract module is responsible for the registration, issuance, triggering and execution of contracts. Developers can define the contract logic in a programming language and publish it to the blockchain (contract registration). According to the logic of the contract terms, the contract logic is triggered by calling keys or other events to trigger execution. The contract logic is completed, and the contract upgrade and cancellation functions are also provided. The operation monitoring module is mainly responsible for the deployment, configuration modification, contract setting, cloud adaptation and real-time status visualization output of the product during the product release process, such as alarms, network status monitoring, and node equipment health status monitoring.
[0059] The platform's product service layer provides the basic capabilities and implementation framework for typical applications. Developers can build on these basic capabilities, overlay business features, and complete the blockchain implementation of business logic. The application service layer provides application services based on blockchain solutions for business participants to use.
[0060] In an implementation method of obtaining the original interface located in the user space, before receiving at least one access data based on the original interface, the server can start the plug-in loading software set in the server, and the plug-in loading software includes a preset takeover plug-in. After the plug-in loading software is started, the server can use the started plug-in loading software to load the preset takeover plug-in, and based on the preset takeover plug-in, perform a historical time of the original interface located in the kernel space (such as Figure 1 The original interface in the kernel state shown in FIG) is taken over to obtain the original interface in the user space at the current time (such as Figure 2 The original interface in user mode is shown).
[0061] Optionally, the historical time may be the time when the preset takeover plug-in is not loaded, and the current time may be the time when the preset takeover plug-in is loaded.
[0062] Optionally, the above-mentioned plug-in loading software can be Vector Packet Processing (VPP) software. In the embodiment of the present application, the VPP software is a fast, scalable 2-4 layer multi-platform network protocol stack that can run in multiple Linux user spaces. In terms of application, the capabilities of the VPP software are continuously enhanced through the extensive use of plug-ins. Among them, the Data Plane Development Kit (DPDK) is a good example. The DPDK plug-in provides some important features and drivers for VPP.
[0063] Optionally, the aforementioned preset takeover plug-in may be a preset interface takeover plug-in, and the preset interface takeover plug-in may be implemented through a data platform development kit DPDK plug-in.
[0064] In an optional embodiment, when the plug-in loading software is the Vector Packet Processing Framework (VPP) software and the preset takeover plug-in is the DPDK plug-in, the server can start the VPP software set in the server. After the VPP software is started, a VPP virtual switch (i.e. Figure 2 The switching module shown in the figure). Subsequently, the server can use the plug-in loading software after startup to load the DPDK plug-in, and use the polling mode corresponding to the DPDK plug-in to drive the network card in the takeover server (such as the cloud server CVM). In this way, a network card named GigabitEthernet can appear in the server, where the interface corresponding to the network card can be the original interface in the user space. In other words, the server uses the DPDK plug-in to load the original interface in the kernel space at the historical time (such as Figure 1 The original interface in kernel mode shown in the figure is taken over and becomes the original interface in user space at the current time (such as Figure 2 Optionally, the driver may be a virtualio-interface driver.
[0065] Optionally, the above-mentioned plug-in loading software is the vector packet processing framework VPP software, and the preset takeover plug-in is a DPDK plug-in, which is only an optional implementation method. Other software with the same function can be used in this application.
[0066] In the embodiments of the present application, the DPDK plug-in is a data plane development tool set provided by the network, which provides library functions and driver support for efficient user space data packet processing under the Intel (Intel architecture, IA) processor architecture. In layman's terms, it is a software library used to accelerate packet data processing.
[0067] Unlike Linux systems, which are designed for general purpose, the DPDK plug-in focuses on high-performance packet processing in network applications. Specifically, DPDK applications run in user space (user mode), utilizing its own data plane library to send and receive packets, bypassing the packet processing of the Linux kernel protocol stack (kernel mode). This bypass of the kernel protocol stack (kernel mode) allows the entire solution to run in user space during attack protection and detection, significantly improving data processing performance.
[0068] In step S303, attack protection detection is performed on at least one access data in the user space to obtain a protection detection result.
[0069] In an embodiment of the present application, the server can perform attack protection detection on at least one access data in the user space to obtain a protection detection result. Figure 4 FIG2 is a flow chart of attack protection detection according to an embodiment of the present invention, including:
[0070] In step S3031, the protection plug-in is loaded using the plug-in loading software.
[0071] In the embodiment of the present application, when the plug-in loading software is VPP software, after the VPP software is started, a VPP virtual switch (that is, Figure 2 The server can then load the protection plug-in using the plug-in loading software after startup.
[0072] In step S3033, attack protection detection is performed on at least one access data in the user space based on the running protection plug-in to obtain a protection detection result.
[0073] As mentioned above, the DPDK application runs in user space (user mode) and uses its own data plane library to send and receive data packets, bypassing the Linux kernel protocol stack (kernel mode)'s data packet processing process. Therefore, the server's attack protection detection process for at least one access data based on the protection plug-in runs in user space.
[0074] In an embodiment of the present application, the server can perform attack protection detection on at least one access data in the user space based on the running protection plug-in. Figure 5 FIG2 is a flow chart of attack protection detection according to an embodiment of the present invention, including:
[0075] In step S501, an interception node is generated based on the running protection plug-in, and the interception node is located in the user space.
[0076] Optionally, the above-mentioned interception node may be a SYN COOKIE, based on which the server may obtain the SYN COOKIE located in the user space based on the running protection plug-in.
[0077] In step S503, at least one access data is received by using an interception node; each access data in the at least one access data includes an access source identifier.
[0078] Optionally, the access data may be a SYN message based on the TCP protocol, the UDP protocol or the IP protocol. The present application will illustrate the embodiment in conjunction with a SYN Flood attack, and thus will be described using the three-way handshake in the TCP protocol.
[0079] The server may use SYN COOKIE to receive at least one access data, wherein the at least one access data may include a SYN message sent by a normal access source or a SYN message sent by an abnormal access source (attacker). Each access data may include an access source identifier.
[0080] In step S505, first confirmation information is sent to the access source based on the interception node; the access source is the access source corresponding to the access source identifier included in each access data.
[0081] The server can determine each access source based on the access source identifier included in each access data, and use SYNCOOKIE to send a first confirmation message to the access source. In this case, the connection state can be called semi-connected. The first confirmation message can be a returned SYN+ACK message.
[0082] As mentioned above, the access source corresponding to at least one access data can be a legitimate access source or an unauthorized access source (an attacker). Therefore, after the server uses a SYN cookie to send the first confirmation message to the unauthorized access source, it may not receive the second confirmation message (i.e., the ACK message) from the unauthorized access source. If the server does not receive the second confirmation message (for example, it is lost in the link), it will retransmit the first confirmation message after a timeout. If it still does not receive the first confirmation message after multiple timeouts and retransmissions, the server will reclaim the resources and close the semi-connection, as if the access data (SYN message) sent by the unauthorized access source had never arrived.
[0083] In step S507, a protection detection result is obtained according to second determination information fed back by the access source; the second determination information is determined based on the first determination information.
[0084] Optionally, the server can obtain the protection detection result based on the second determination information fed back by the access source, that is, the server determines that only the access source that receives the second determination information (including the access source received when the first determination information is sent for the first time and the access source received by retransmitting the first determination information) passes the attack protection detection.
[0085] In step S305, a target access source is determined from access sources corresponding to at least one access data according to the protection detection result.
[0086] Optionally, the server may determine the target access data from the at least one access data according to the second determination information, and determine the access source corresponding to the target access data as the target access source.
[0087] Optionally, the second determination information may carry identification information of the access source, and the server may determine the target access source from the corresponding access source in at least one access data according to the identification information of the access source carried in the second determination information.
[0088] Among the access sources corresponding to at least one access data, after removing the target access source, the remaining access sources can be considered as attack access sources.
[0089] Optionally, the server may add the identification information of the target access source to a whitelist, add the identification information of the attack access source to a blacklist, and delete the access data transmitted by the attack access source.
[0090] In an embodiment of the present application, the server can use the plug-in loading software after startup to create a virtual interface, and the virtual interface is located in the kernel space. The identification information of the virtual interface is the same as the identification information of the original interface located in the kernel space at a historical time.
[0091] Optionally, the server can be based on Figure 1 The virtual interface is created based on the identification information of the original interface shown in FIG.
[0092] In some possible embodiments, the identification information of the original interface may be a media access control address (MAC), or an Internet Protocol address (IP), or of course, a character string of other information that can be used to identify the original interface.
[0093] Specifically, the virtual interface that the server can create can be a tap type interface. The MAC address of the virtual interface and Figure 1 The MAC address of the original interface is the same as that of the tap interface. The optional type of the original interface is veth, which has the same effect as the tap type.
[0094] In some optional specific embodiments, in order to ensure Figure 2 The connections between the original interface, virtual interface, and switch module (VPP virtual switch) are shown. The server can create a bridge domain in the switch module and connect the bridge domain to the original interface and virtual interface respectively. In actual application, this process is similar to plugging two network cables into a switch.
[0095] Continuing with the above content, which has already been discussed, the server can add the identification information of the target access source to a whitelist, add the identification information of the attacking access source to a blacklist, and delete the access data transmitted by the attacking access source. After this, the SYN cookie can send a reset message to the target access source. This reset message is used to simply disconnect the current connection with the SYN cookie and re-initiate the three-way handshake connection. When the target access source again sends access data, i.e., a SYN packet, the SYN cookie extracts the identification information of the access source carried in the SYN packet. If it finds that the identification information is on the whitelist, the SYN cookie forwards the access data, i.e., the SYN packet, to the server, allowing the server to establish a connection with the target access source through the three-way handshake, preparing to subsequently receive service requests from the target access source. Optionally, the service request can be a type of request sent by the target access source, and other types of requests can also be received from the target access source. For other types of requests, the service request will be used as an example for explanation here, and other requests can be processed according to actual circumstances.
[0096] In an optional embodiment, after the server determines a target access source from at least one access source corresponding to the access data based on the protection detection results, that is, after cleaning the access data, the server further includes: if a service request is received from the target access source based on the original interface, the server sends the service request to the service processing device based on the virtual interface located in the kernel space. In addition, if feedback data is received from the service processing device based on the virtual interface, and the feedback data is determined based on the service request, the server may feed back the feedback data to the target access source based on the original interface.
[0097] In this way, through the above implementation plan, the first process of performing attack protection detection on access data in user space and obtaining the target access source is completed. In addition, the second process of transmitting business requests and feedback data generated based on business requests through the original interface located in the user space and the virtual interface located in the kernel space is also completed.
[0098] In the embodiment of the present application, before the above steps S301-S305, Figure 2 Following the system framework shown, the following steps are also included:
[0099] Assume that the target server provides web query services to the outside world. When the first access data from the client passes through the access source (gateway device) and wants to be sent to the target server, the gateway device does not know which server among the multiple servers is the target server. Therefore, the gateway device needs a corresponding ARP forwarding table to correctly send the access data to the target server.
[0100] Here is a detailed description of the process by which the access source (gateway device) learns the cloud server MAC address and writes it into the arp table. First, the gateway device caches the access data (user request) and sends an arp broadcast (arp with the target mac as the full f) request to each interface. After the cloud server connected to the gateway device receives the arp request, if it determines that the target IP is its own IP, that is, the target server is itself, it can send an arp response message. Other cloud servers do not respond to the broadcast because they determine that the target IP is not their own IP. After receiving the arp response, the gateway writes the mac address of the target IP into the arp table, and then sends the access data to the target server. Subsequent access requests or business requests can be forwarded directly.
[0101] In the above scenario, the server-side VPP virtual switch (or, in other words, a VPP virtual switch with an attack protection module) performs similar actions as a gateway device. When the VPP virtual switch receives an ARP broadcast packet from the original interface, it queries the local FIB forwarding table (a gateway typically performs Layer 3 forwarding, forwarding based on the ARP table. Here, the VPP virtual switch is used as a Layer 2 forwarding device, which forwards based on the FIB table. FIB entries contain MAC addresses and corresponding interface numbers). Finding no corresponding entry, it initiates a flood (flooding is a Layer 2 concept, unlike ARP broadcasts. The VPP virtual switch is unaware of the Layer 3 protocol and, therefore, will not modify the destination MAC address of the received packet to all f and then send it to all interfaces other than the one it received the packet from. In this case, the VPP virtual switch modifies the destination MAC address of the received ARP packet to all f and then sends it to the second interface). When a virtual interface receives a flooded ARP packet, the kernel protocol stack can send the ARP response packet out of the virtual interface because the virtual interface is managed by the Linux kernel driver. The VPP virtual switch learns the MAC address corresponding to the virtual interface and writes it to the FIB table. It then sends the ARP response packet to the gateway device via the original interface. Subsequently, VPP can directly forward the packet without flooding.
[0102] In this embodiment of the present application, upon receiving an access request from a gateway device, the VPP virtual switch corresponding to the VPP software executes security protection logic, discards malicious access data, and forwards normal service traffic (including normal access data and service data) to the virtual interface. The virtual interface is unaware of malicious traffic and only needs to respond to normal traffic.
[0103] Related technologies also include a host-layer DDoS protection solution based on the eXpress Data Path (XDP). XDP refers to the high-performance eBPF-based data path incorporated into the Linux kernel since version 4.8. This solution uses XDP to inject DDoS protection code into the Linux kernel. This code performs packet inspection and protection after the network interface card receives the packet, then passes normal traffic to the Linux kernel protocol stack.
[0104] However, this approach has three main disadvantages:
[0105] First, this method requires specific kernel support. Only Linux kernels later than version 4.8 support running XDP programs. Therefore, many lower-version kernels cannot use this solution. Therefore, version compatibility issues may cause problems in the application and promotion of this method.
[0106] Second, the Linux kernel imposes numerous restrictions on XDP, limiting its capabilities. Specifically, while VPP software running in user space can freely request resources there, XDP runs in kernel space. Because kernel space has stricter security requirements than user space, the Linux kernel imposes numerous restrictions on XDP, including restrictions on resource allocation. This ultimately limits the functionality of XDP-based host-layer DDoS protection solutions.
[0107] Third, there are performance issues. Packet reception in the Linux kernel generates interruptions, which significantly reduce data plane processing efficiency. Specifically, in addition to processing the XDP-based host-layer DDoS protection solution, the Linux kernel also runs other processes, each requiring kernel resources to handle. Therefore, when processing the DDoS protection solution, these processes are interrupted and then restored, ultimately reducing data plane processing efficiency.
[0108] This application uses VPP software to start the DPDK plug-in, which runs in user space (user state) and uses its own data plane library to send and receive data packets, bypassing the Linux kernel protocol stack (kernel state) to process data packets. Precisely because it bypasses the kernel protocol stack (kernel state), by bypassing the kernel protocol network stack, the entire solution can run in user space during attack protection detection and processing, thereby significantly improving data processing performance.
[0109] Some related technologies allow for adding a load balancing machine to the business server, while deploying DDoS protection software on a proxy server to forward cleaned traffic to the business server. However, due to the unique nature of their network architecture, many cloud service providers do not offer this type of network architecture, requiring customers to build their own proxy servers, which is extremely costly. Furthermore, such proxy servers can only forward traffic within a small Layer 2 network and cannot forward traffic across regions, resulting in low network utilization.
[0110] Some related technologies employ dedicated DDoS protection devices attached to intermediate network devices, such as core switches, to divert attack traffic to the protection devices and then inject the cleaned traffic back into the core switches. However, because the customer seeking network-layer protection and the cloud service provider are typically separate entities, deploying such network-layer protection devices within a different cloud service network environment is difficult.
[0111] In summary, the embodiment of the present application utilizes VPP software, which replaces the above-mentioned hardware devices. It does not require special network support and has no kernel restrictions. It can avoid interruptions to kernel processes through attack protection detection in user space, and therefore has the best performance. Secondly, VPP software can run directly on a physical host or cloud host, without intrusion into the business and without business perception, making it more suitable for different application scenarios and conducive to promotion. Furthermore, DPDK software and PMD drivers support most types of network cards and virtual network cards, and VPP software is a software that does not rely on kernel version or operating system version, so this solution can run on most cloud servers.
[0112] Optionally, the embodiments of the present application can be applied to DDoS security protection scenarios such as cloud security services, host security protection, edge computing, and overseas games. When using third-party cloud servers and it is impossible to deploy proprietary DDoS protection equipment, this solution can be used to implement host-layer DDoS protection. In addition, in some edge computing scenarios, due to the large number and dispersion of business servers, the cost of deploying proprietary DDoS protection equipment is too high, so this solution can also be used for host-layer DDoS protection.
[0113] See also Figure 6 , which shows a schematic diagram of the structure of an attack protection device provided by an embodiment of the present invention. The device has the function of implementing the attack protection method in the above method embodiment. The function can be implemented by hardware or by hardware executing corresponding software. Figure 6 As shown, the device may include:
[0114] The data receiving unit 601 is configured to receive at least one access data based on an original interface; the original interface is located in the user space of the server;
[0115] a protection detection unit 602, configured to perform attack protection detection on at least one access data in a user space and obtain a protection detection result;
[0116] The access source determining unit 603 is configured to determine a target access source from the access sources corresponding to at least one access data according to the protection detection result.
[0117] As a possible implementation, the device further includes:
[0118] A startup unit, used to start the plug-in loading software;
[0119] A loading unit, configured to load a preset takeover plug-in by using the plug-in loading software after startup;
[0120] A takeover unit, configured to take over the original interface in the kernel space at a historical time based on a preset takeover plug-in, and obtain the original interface in the user space at a current time;
[0121] The historical time is the time when the preset takeover plug-in is not loaded, and the current time is the time when the preset takeover plug-in is loaded.
[0122] As a possible implementation, the protection detection unit is used to:
[0123] Use the plug-in loading software to load the protection plug-in;
[0124] An attack protection detection is performed on at least one access data in a user space based on the running protection plug-in to obtain a protection detection result.
[0125] As a possible implementation, the protection detection unit is used to:
[0126] Generate an interception node based on the running protection plug-in; the interception node is located in the user space;
[0127] receiving at least one access data using an interception node; each access data in the at least one access data includes an access source identifier;
[0128] Sending first determination information to the access source based on the interception node; the access source is the access source corresponding to the access source identifier included in each access data;
[0129] The protection detection result is obtained according to the second determination information fed back by the access source; the second determination information is determined based on the first determination information.
[0130] As a possible implementation, the protection detection unit is used to:
[0131] determining target access data from at least one access data according to the second determination information;
[0132] An access source corresponding to the target access data is determined as the target access source.
[0133] As a possible implementation, the device further includes:
[0134] A creation unit is used to create a virtual interface using the plug-in loading software after startup; the virtual interface is located in the kernel space;
[0135] The identification information of the virtual interface is the same as the identification information of the original interface in the kernel space at the historical time.
[0136] As a possible implementation, the device further includes:
[0137] The data transmission unit is configured to send the service request to the service processing device based on the virtual interface in the kernel space when receiving the service request sent by the target access source based on the original interface.
[0138] As a possible implementation, the device further includes:
[0139] The data feedback unit receives feedback data sent by the service processing device based on the virtual interface; the feedback data is determined based on the service request; and the feedback data is fed back to the target access source based on the original interface.
[0140] It should be noted that the apparatus provided in the above embodiments, when implementing its functions, is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus and method embodiments provided in the above embodiments are based on the same concept. The specific implementation process is detailed in the method embodiment and will not be repeated here.
[0141] An embodiment of the present invention provides an electronic device, which includes a processor and a memory, wherein the memory stores at least one instruction or at least one program, and the at least one instruction or the at least one program is loaded and executed by the processor to implement the attack protection method provided in the above method embodiment.
[0142] The memory can be used to store software programs and modules. The processor executes various functional applications and attack protection by running the software programs and modules stored in the memory. The memory can mainly include a program storage area and a data storage area. The program storage area can store the operating system, application programs required for the functions, etc.; the data storage area can store data created based on the use of the device, etc. In addition, the memory can include high-speed random access memory and non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory can also include a memory controller to provide the processor with access to the memory.
[0143] The method embodiments provided by the embodiments of the present invention may be executed in a computer terminal, a server or a similar computing device. Figure 7 This is a hardware structure diagram of an electronic device running an attack protection method provided by an embodiment of the present invention, such as Figure 7 As shown, the internal structure of the electronic device may include but is not limited to: a processor, a network interface and a memory. The processor, network interface and memory in the electronic device may be connected via a bus or other means. Figure 7 The bus connection is taken as an example.
[0144] Among them, the processor (or CPU (Central Processing Unit)) is the computing core and control core of the electronic device. The network interface may optionally include a standard wired interface, a wireless interface (such as WI-FI, a mobile communication interface, etc.). Memory is a memory device in an electronic device for storing programs and data. It is understandable that the memory here can be a high-speed RAM storage device or a non-volatile memory device (non-volatile memory), such as at least one disk storage device; optionally, it can also be at least one storage device located away from the aforementioned processor. The memory provides a storage space, which stores the operating system of the electronic device, which may include but is not limited to: Windows system (an operating system), Linux (an operating system), Android (Android, a mobile operating system) system, IOS (a mobile operating system) system, etc., and the present invention is not limited to this; and, in the storage space, one or more instructions suitable for being loaded and executed by the processor are also stored. These instructions can be one or more computer programs (including program codes). In the embodiment of this specification, the processor loads and executes one or more instructions stored in the memory to implement the attack protection method provided in the above method embodiment.
[0145] An embodiment of the present invention also provides a computer-readable storage medium, which can be set in an electronic device to store at least one instruction or at least one program related to implementing an attack protection method. The at least one instruction or the at least one program is loaded and executed by the processor to implement the attack protection method provided by the above method embodiment.
[0146] Embodiments of the present invention further provide a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the attack protection methods provided in the various optional implementations described above.
[0147] Optionally, in this embodiment, the above-mentioned storage medium may include but is not limited to: a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and other media that can store program codes.
[0148] It should be noted that the order in which the embodiments of the present invention are described above is for illustrative purposes only and does not represent the superiority or inferiority of the embodiments. The above description is of specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0149] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences from other embodiments. In particular, the device embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0150] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.
[0151] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. An attack protection method, characterized in that: The method comprises: receiving at least one access data based on an original interface located in a user space of a server; the at least one access data is received by the user space bypassing a kernel space of the server; Performing attack protection detection on the at least one access data in the user space to obtain a protection detection result; determining a target access source from the access sources corresponding to the at least one access data according to the protection detection result; Based on the original interface located in the user space and the virtual interface located in the kernel space, data interaction is performed between the target access source and the business processing device in the kernel space; the virtual interface is created based on the original interface located in the kernel space at a historical time.
2. The attack protection method according to claim 1, characterized in that: Before receiving at least one access data based on the original interface in the user space of the server, the method further includes: Start the plug-in loading software; Using the plug-in loading software after startup to load the preset takeover plug-in; Taking over the original interface located in the kernel space at the historical time based on the preset takeover plug-in, and obtaining the original interface located in the user space at the current time; The historical time is the time when the preset takeover plug-in is not loaded, and the current time is the time when the preset takeover plug-in is loaded.
3. The attack protection method according to claim 2, characterized in that: The performing attack protection detection on the at least one access data in the user space to obtain a protection detection result includes: Loading the protection plug-in using the plug-in loading software; An attack protection detection is performed on the at least one access data in the user space based on the running protection plug-in to obtain a protection detection result.
4. The attack protection method according to claim 3, characterized in that: The performing attack protection detection on the at least one access data in the user space based on the running protection plug-in to obtain a protection detection result includes: Generate an interception node based on the running protection plug-in; the interception node is located in the user space; Utilizing the interception node to receive the at least one access data; each access data in the at least one access data includes an access source identifier; Sending first determination information to the access source based on the interception node; the access source is the access source corresponding to the access source identifier included in each access data; The protection detection result is obtained according to second determination information fed back by the access source; the second determination information is determined based on the first determination information.
5. The attack protection method according to claim 4, characterized in that: The determining, according to the protection detection result, a target access source from the access sources corresponding to the at least one access data, includes: determining target access data from the at least one access data according to the second determination information; An access source corresponding to the target access data is determined as the target access source.
6. The attack protection method according to claim 2, characterized in that: The method further comprises: The virtual interface is created by using the plug-in loading software after startup; the identification information of the virtual interface is the same as the identification information of the original interface located in the kernel space at the historical time.
7. The attack protection method according to claim 6, characterized in that: After determining the target access source from the access source corresponding to the at least one access data according to the protection detection result, the method further includes: If a service request sent by the target access source is received based on the original interface, the service request is sent to the service processing device based on the virtual interface located in the kernel space.
8. The attack protection method according to claim 7, characterized in that: After sending the service request to the service processing device based on the virtual interface in the kernel space, the method further includes: receiving feedback data sent by the service processing device based on the virtual interface; the feedback data is determined based on the service request; The feedback data is fed back to the target access source based on the original interface.
9. An attack protection device, characterized in that: The device comprises: A data receiving unit, configured to receive at least one access data based on an original interface located in a user space of a server; the at least one access data is received by the user space bypassing a kernel space of the server; a protection detection unit, configured to perform attack protection detection on the at least one access data in the user space to obtain a protection detection result; an access source determining unit, configured to determine a target access source from the access sources corresponding to the at least one access data according to the protection detection result; A data transmission unit is used to perform data interaction between the target access source and the business processing device in the kernel space based on the original interface located in the user space and the virtual interface located in the kernel space; the virtual interface is created based on the original interface located in the kernel space at a historical time.
10. The attack protection device according to claim 9, characterized in that: The device further comprises: A startup unit, used to start the plug-in loading software; A loading unit, configured to load a preset takeover plug-in using the plug-in loading software after startup; a takeover unit, configured to take over the original interface located in the kernel space at the historical time based on the preset takeover plug-in, and obtain the original interface located in the user space at the current time; The historical time is the time when the preset takeover plug-in is not loaded, and the current time is the time when the preset takeover plug-in is loaded.
11. The attack protection device according to claim 10, characterized in that: The protection detection unit is further used for: Loading the protection plug-in using the plug-in loading software; An attack protection detection is performed on the at least one access data in the user space based on the running protection plug-in to obtain a protection detection result.
12. The attack protection device according to claim 11, characterized in that: The protection detection unit is further used for: Generate an interception node based on the running protection plug-in; the interception node is located in the user space; Utilizing the interception node to receive the at least one access data; each access data in the at least one access data includes an access source identifier; Sending first determination information to the access source based on the interception node; the access source is the access source corresponding to the access source identifier included in each access data; The protection detection result is obtained according to second determination information fed back by the access source; the second determination information is determined based on the first determination information.
13. The attack protection device according to claim 12, characterized in that: The protection detection unit is further used for: determining target access data from the at least one access data according to the second determination information; An access source corresponding to the target access data is determined as the target access source.
14. The attack protection device according to claim 10, characterized in that: The device further comprises: The creation unit is configured to create the virtual interface by using the plug-in loading software after startup; the identification information of the virtual interface is the same as the identification information of the original interface located in the kernel space at the historical time.
15. The attack protection device according to claim 14, characterized in that: The data transmission unit is further configured to: If a service request sent by the target access source is received based on the original interface, the service request is sent to the service processing device based on the virtual interface located in the kernel space.
16. The attack protection device according to claim 15, characterized in that: The data transmission unit is further configured to: Feedback data sent by the service processing device is received based on the virtual interface; the feedback data is determined based on the service request; and the feedback data is fed back to the target access source based on the original interface.
17. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores at least one instruction or at least one program, and the at least one instruction or the at least one program is loaded and executed by the processor to implement the attack protection method according to any one of claims 1 to 8.
18. A computer-readable storage medium, wherein at least one instruction or at least one program is stored in the computer-readable storage medium, wherein the at least one instruction or the at least one program is loaded and executed by a processor to implement the attack protection method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Method of preventing syn flood and router equipment
CN101163041A
Cluster type virtualization data forwarding method, device and system based on VPP
CN112905305A
Data center architecture that supports attack detection and mitigation
US20160036838A1