A method and device for detecting and defending DDoS quantitatively based on the lanchester equation
By extending the Lanchester equation, introducing cyberspace-specific combat power factors, and setting early warning thresholds, the problem of insufficient description of traditional equations in DDoS attack and defense simulations is solved, enabling real-time quantitative assessment and dynamic defense of DDoS attacks, and improving defense effectiveness and resource utilization.
Patent Information
- Application Number
- CN202211365456.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-02
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2042-11-02
AI Technical Summary
Traditional Lanchester equations lack spatial degrees of freedom when simulating DDoS attack and defense processes in cyberspace, resulting in an overly idealized description of the impact and interference of the adversarial process and a lack of effective quantification methods.
The Lanchester equation is extended and improved by introducing specific factors affecting the combat capabilities of network defenders and attackers, such as CPU performance, memory performance, and network bandwidth. The Lanchester equation is used to simulate the attrition process of both DDoS attackers and defenders, and an early warning threshold is set to implement dynamic defense strategies based on the amount of attrition.
It enables real-time quantitative assessment and dynamic defense against DDoS attacks, improving the resource utilization and defense effectiveness of the protection system, ensuring normal system operation and avoiding resource waste.
Smart Images

Figure CN115766133B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of security detection and protection of network attacks, more particularly, to a DDoS quantitative detection and defense method and device based on Lanchester equation. BACKGROUND
[0002] There are many attack modes of denial of service attack (DoS), the most basic DoS attack is to use reasonable service request to occupy too many service resources, so that the legitimate user cannot get the response of the service. Distributed denial of service attack (DDoS) is a distributed, collaborative and large-scale denial of service attack mode, which is generated on the basis of traditional DoS attack with the popularity of high-speed and widely connected network. The attack strategy focuses on sending a large number of network packets to the victim host through many "zombie hosts" (hosts that have been attacked by intruders or can be indirectly used), so as to cause network congestion or server resource exhaustion and cause denial of service. According to the result caused by DDoS attack, DDoS attack can be divided into resource exhaustion type and bandwidth exhaustion type, and the essence of both is the loss of service efficiency of target host (network), so that it cannot handle the legitimate request of normal user.
[0003] For the defense of DDoS, the current main means include: using high-performance network equipment, upgrading host server hardware, installing system patch in time, installing system firewall, closing unnecessary services, controlling IP address connection number and other means, but these means are often some normal or static defense methods, lack of quantitative description of attack intensity, and mechanism of using different coping strategies according to the change of our defense efficiency. The real-time quantitative description of the influence of attack and defense on their respective efficiency, the description of efficiency change, the current DDoS defense system still lacks effective means.
[0004] In 1914, the famous British operations researcher Lanchester analyzed historical wars. Based on the comparison of ancient cold weapon wars, modern hot weapon wars and modern wars, and under the premise of simplifying assumptions (such as ignoring psychological factors and other unquantifiable factors), he quantified various elements of the two parties in the war and established a series of differential equations describing the relationship between the number of forces of the two parties and time, i.e. Lanchester equation, which opened up a way for us to study armed conflicts and wars by combining quantitative and qualitative research. After World War II, many military experts and scholars kept pace with the times and conducted research on some special battles according to the actual situation of modern conflicts and wars. Based on the original Lanchester equation, they continuously developed and innovated and established a series of new battle models, called Lanchester-type equations, which include guerrilla war models, information war models, etc. and provide an important tool for studying conflicts and wars in the new era. Subsequently, many scholars have expanded the application field of Lanchester equation and transplanted it to different fields to describe the loss of the two parties.
[0005] The traditional Lanchester equation is suitable for simulating the loss of forces of the two parties in the war. The equation introduces a set of coupled ordinary differential equations as the loss model in modern war. The basic idea is that the loss rate of the forces of one party is proportional to the number of the forces of the other party. Based on this idea, in the network space confrontation simulation system, the loss model of the two opposing parties is represented by the following linear equation, i.e.
[0006]
[0007] where P(t) and A(t) represent the forces (represented by numbers) of the red army (network defense party) and the blue army (network attack party) at time t; a A and a P represent the loss coefficients of one unit of combat forces of one party resulting in casualties of the other party, where a A is the Lanchester loss coefficient of the defense party in the case of being attacked; a P is the Lanchester loss coefficient of the attacker when attacking the defender; u(t) and v(t) represent the given reinforcement functions of the defense party and the attack party, respectively.
[0008] As can be seen from equations (1) and (2), the equation form is too simple, lacks spatial freedom to simulate modern war, and idealizes the influence and interference of multiple factors on the confrontation process in the DDoS attack and defense process in network space. Therefore, the patent expands the influence factors a A and a PThe expansion is carried out, and in addition to the consideration of the time domain in the traditional Lanchester model, the key influencing factors of each combat unit model of the attack and defense sides in the network space are considered. The number of the red side (network DDoS defense side) army is mapped into the number of servers (including virtual servers) corresponding to the defense side in the network space, and the factors influencing the combat effectiveness thereof include: CPU performance, memory performance, network bandwidth, network connection number, concurrent processing capacity, etc. The number of the blue side (network DDoS attack side) army is mapped into the number of IP addresses that can be obtained through sensors in the network space, and the factors influencing the combat effectiveness thereof include: the number of concurrent connections obtained by the sensors and the number of data packets sent per unit time, etc. Therefore, the traditional DDoS quantification method of the Lanchester equation needs to be improved. SUMMARY
[0009] The application provides a DDoS quantification detection and defense method and device of a Lanchester equation, and solves the problem that the traditional Lanchester equation form is too simple, lacks spatial freedom to simulate modern war, and idealizes the influence and interference of multiple factors on the confrontation process in the DDoS attack and defense process in the network space.
[0010] To solve the above problems, on the one hand, the application provides a DDoS quantification detection and defense method of a Lanchester equation, comprising:
[0011] setting parameters of the Lanchester equation;
[0012] simulating a loss process of the DDoS attack and defense sides according to the Lanchester equation;
[0013] judging whether the loss amount of the loss process exceeds a preset threshold value and executing a preset decision mechanism according to the judgment result.
[0014] The setting of the parameters of the Lanchester equation comprises:
[0015] setting the Lanchester loss demotion function of the network defense side as P[p1, p2, p3, p4, t]; wherein p1 is the CPU performance of the own side, the weight is p2 is the memory performance of the own side, the weight is p3 is the network performance of the own side, the weight is p4 is the equipment failure of the own side, the weight is ω p4 ;
[0016] setting the Lanchester loss demotion function of the network attack side as A[a1, a2, t]; wherein a1 is the concurrent connection number attack performance, the weight is a2 is the data packet sending attack performance per unit time, the weight is The simulating of the loss process of the DDoS attack and defense sides according to the Lanchester equation comprises:
[0017] Initialize the strength of both sides: the strength of the network defense side is P0 at the beginning of the network attack; the strength of the network attack side is A0 at the beginning of the network attack;
[0018] Start the simulation of the loss process of both sides of the DDoS attack and defense, the strength of the network defense side satisfies
[0019] P ′ = -aA, the strength of the network attack side satisfies A' = -pP; wherein a is the Lanchester loss coefficient of the network defense side, and p is the Lanchester loss coefficient of the network attack side;
[0020] Simplify into a non-coupled form: the strength of the network defense side satisfies P ″ = apP, the strength of the network attack side satisfies A ″ = paA;
[0021] Therefore, the fighting force functions of both the network defense side and the network attack side satisfy: Z" = paZ, the geometric mean of the fighting force of a single soldier is k = sqrt(ap), and the solution of Z" = paZ is Z = Z(0)exp(-kt), wherein Z(0) is the initial value of the strength;
[0022] Therefore, the Lanchester loss demobilization functions of the network defense side and the network attack side are respectively P(t) = P0exp(-kt) and A(t) = A0exp(-kt).
[0023] The method further includes:
[0024] Setting the preset threshold value;
[0025] Determining whether the loss amount of the loss process of both sides of the DDoS attack and defense exceeds the preset threshold value;
[0026] When the loss amount of the network defense side does not exceed the preset threshold value, continuing the current defense strategy;
[0027] When the loss amount of the network defense side exceeds the preset threshold value, replacing the defense means according to a preset strategy.
[0028] In one aspect, a device for DDoS quantitative detection and defense based on Lanchester equation is provided, and the device includes:
[0029] A setting module configured to set parameters of the Lanchester equation;
[0030] A simulation module configured to simulate the loss process of both sides of the DDoS attack and defense according to the Lanchester equation;
[0031] The execution module is configured to determine whether the loss amount of the loss process exceeds a preset threshold value and execute a preset decision mechanism according to a determination result.
[0032] The setting module comprises:
[0033] The defense setting submodule is configured to set the Lanchester loss demobilization function of the network defense as P[p1, p2, p3, p4, t], wherein p1 is the CPU performance of the own side, and the weight is
[0034] P[p1, p2, p3, p4, t]; wherein, p1 is the CPU performance of the own side, and the weight is p2 is the memory performance of the own side, and the weight is p3 is the network performance of the own side, and the weight is p4 is the device failure of the own side, and the weight is The attack setting submodule is configured to set the Lanchester loss demobilization function of the network attack as A[a1, a2, t]; wherein a1 is the concurrent connection number attack performance, and the weight is a2 is the data packet sending attack performance per unit time, and the weight is
[0035] The simulation module comprises:
[0036] The initialization submodule is configured to initialize the strength of the attack and defense sides: the strength of the network defense at the beginning of the network attack is P0; and the strength of the network attack at the beginning of the network attack is A0.
[0037] The loss simulation submodule is configured to start the loss process simulation of the DDoS attack and defense sides, wherein the strength of the network defense satisfies P ′ =-aA, and the strength of the network attack satisfies A'= -pP; wherein a is the Lanchester loss coefficient of the network defense, and p is the Lanchester loss coefficient of the network attack.
[0038] The simplification submodule is configured to simplify into a non-coupling form: the strength of the network defense satisfies
[0039] P ″ =apP, and the strength of the network attack satisfies A ″ =paA.
[0040] The calculation submodule is configured to calculate the geometric mean of the individual combat effectiveness as k=sqrt(ap).
[0041] The acquisition submodule is configured to acquire the Lanchester loss demobilization functions of the network defense and the network attack respectively: P(t)=P0exp(-kt), and A(t)=A0exp(-kt).
[0042] The execution module comprises:
[0043] A threshold setting submodule is configured to set the preset threshold value.
[0044] A judgment submodule is configured to judge whether the loss amount of the loss process of the DDoS attack and defense parties exceeds the preset threshold value.
[0045] A strategy execution submodule is configured to continue the current defense strategy when the loss amount of the network defense party does not exceed the preset threshold value, and replace the defense means according to the preset strategy when the loss amount of the network defense party exceeds the preset threshold value.
[0046] In one aspect, a computer readable storage medium is provided, and the storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the above-described DDoS quantitative detection and defense method of the Lanchester equation.
[0047] The present application has the following beneficial effects: the Lanchester loss equation theory is used for reference, the equation is extended and improved, and is applied to the network space environment to quantitatively evaluate the efficiency loss of the DDoS attack and defense parties; the threshold-based security strategy automatic response measure is used, the real-time loss of the attack and defense parties is calculated by using the Lanchester equation, the preset security strategy is automatically processed when the loss value reaches the preset warning threshold value, the dynamic automatic response based on the attack intensity and the on-demand protection requirement are realized, the resource utilization rate of the protection system is more reasonable and efficient under the premise of meeting the protection requirement. BRIEF DESCRIPTION OF DRAWINGS
[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without any creative effort.
[0049] Figure 1 is a flowchart of a DDoS quantitative detection and defense method of the Lanchester equation provided by an embodiment of the present application;
[0050] Figure 2 is a structural schematic diagram of a DDoS quantitative detection and defense system of the Lanchester equation provided by an embodiment of the present application. DETAILED DESCRIPTION
[0051] The technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort are within the protection scope of the present application.
[0052] In the description of the present application, it should be understood that the terms "center", "longitudinal", "lateral", "length", "width", "thickness", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the purpose of facilitating the description of the present application and simplifying the description, and do not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. In addition, the terms "first", "second" are only for the purpose of description, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more features. In the description of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly specified.
[0053] In the present application, the word "exemplary" is used to mean "serving as an example, instance, or illustration." Any implementation described as "exemplary" in the present application is not necessarily to be construed as preferred or advantageous over other implementations. The following description is presented to enable any person skilled in the art to make and use the application. In the following description, for purposes of explanation, specific details are set forth. It will be apparent to those skilled in the art that the present application can be practiced without the specific details presented. In other instances, well-known structures and processes are not elaborated in order not to obscure the description of the present application with unnecessary detail. Thus, the present application is not intended to be limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features presented herein.
[0054] The traditional Lanchester equation is extended and improved in the case, is transplanted to network security space, is used for the loss of the effectiveness of the attack and defense of both sides in DDoS attack is quantitatively described, the loss warning threshold is set, different coping strategies are adopted in different stages of attack, the normal operation of the attacked system is ensured, and unnecessary resource consumption is avoided. The method and system can be applied to the field of DDoS security detection and protection, the degree of system attack is quickly evaluated through real-time loss calculation, and corresponding strategies are adopted, a good balance effect between security and economy is achieved, and has wide application prospect. That is, the Lanchester equation is extended and improved, applied to the field of network space security, used for quantitatively describing the loss of attack and defense of both sides in DDoS attack, according to the set warning loss threshold, the defense system can take real-time measures (such as expansion, diversion, connection number limitation and calling of special protection components) according to the customized strategy, thereby improving the effective evaluation and quantitative support for realizing adaptive dynamic defense against DDoS.
[0055] Reference Figure 1 , Figure 1 It is a flow chart of a Lanchester equation DDoS quantitative detection and defense method provided by an embodiment of the application, and the Lanchester equation DDoS quantitative detection and defense method comprises steps S1-S3:
[0056] S1, setting the parameters of the Lanchester equation; step S1 comprises steps S11-S12:
[0057] S11, setting the Lanchester demobilization function of the network defense side as P[p1, p2, p3, p4, t]; wherein p1 is the CPU effectiveness of the own side, the weight is p2 is the memory effectiveness of the own side, the weight is p3 is the network effectiveness of the own side, the weight is p4 is the device failure of the own side, the weight is
[0058] In the embodiment, the loss function of the red side (the network defense side) is extended to P[p1, p2, p3, p4, t]. The function has five parameters, in addition to the consideration of the time domain in the traditional Lanchester equation model, the key related factors of each combat unit model of the network space defense side are considered. Among them, p1 is the CPU effectiveness of the own side (determined by CPU frequency and kernel number), the weight is p2 is the memory effectiveness of the own side (determined by memory size and memory frequency), the weight is p3 is the network effectiveness of the own side (determined by network bandwidth, support concurrent connection number and other factors), the weight is P4 is the failure rate of the defender's equipment (which can be obtained from the average failure rate statistics disclosed by such equipment), and the weight is That is, the number of servers (forces) of the defender (the own side) and the combat effectiveness factors (CPU performance, memory performance, network bandwidth, network connection number, concurrent processing ability, etc.) are obtained, and the failure rate of the own side equipment is estimated according to the average failure rate of the industry equipment.
[0059] S12, set the Lanchester equation demobilization function of the network attack side as A[a1, a2, t]; wherein a1 is the concurrent connection number attack performance, and the weight is a2 is the data packet attack performance per unit time, and the weight is
[0060] In this embodiment, the loss function of the blue side (network attack side) is extended to A[a1, a2, t]. This function has three parameters. In addition to the consideration of the time domain in the traditional Lanchester model, the key factors of each combat unit model of the network space attack side can be obtained through various sensors. Among them, a1 is the concurrent connection number attack performance (determined by the connection request received by the sensor), and the weight is a2 is the data packet attack performance per unit time (determined by the data packet request received by the sensor), and the weight is
[0061] For the sake of simplicity, in this model, the defender only considers the above four factors and the time domain, and the attacker only considers the above two factors and the time domain. According to the different types of network DDoS attacks, the specific parameter domain can be customized as needed in the loss function. Since the reinforcement functions of both sides are given functions, this effect is ignored in this improved equation.
[0062] S2, simulate the loss of the DDoS attack and defense sides according to the Lanchester equation; step S2 includes steps S21-S26:
[0063] S21, initialize the forces of the attack and defense sides: the network defense side has a force P0 at the beginning of the network attack; the network attack side has a force A0 at the beginning of the network attack.
[0064] In this embodiment, the forces of the attack and defense sides are initialized as follows:
[0065] The red side (network defense side) has a force (obtained by the own side information collector) at the beginning of the network attack:
[0066] P(0)=P0 (3)
[0067] The blue side (network attack side) has a force (obtained by the set sensor) at the beginning of the network attack:
[0068] A(0)=A0 (4)
[0069] S22, start the DDoS attack and defense both sides of the loss simulation, the network defense force to meet P ′ = -aA, the network attack force to meet A' = -pP; wherein, a is the network defense force of Lanchester loss coefficient, p is the network attack force of Lanchester loss coefficient, P is the loss function of the red side (network defense force) is extended to P[p1, p2, p3, p4, t], A is the Lanchester equation of the network attack force of the demobilization function is A[a1, a2, t].
[0070] In this embodiment, after the start of the confrontation, both sides of the loss function meets the Lanchester equation 1 order coupled differential equations, according to the writing habit of differential equation, the following equation in the independent variable) is omitted:
[0071] P ′ = -aA, A' = -pP (5)
[0072] At a certain time, the network defense force (red army) combat demobilization and DDoS attack force (blue army) force and its single combat force is proportional; DDoS attack force (blue army) combat demobilization and network defense force (red army) force and its single combat force is proportional.
[0073] S23, simplified as a non coupled form: the network defense force to meet P ″ = apP, the network attack force to meet A ″ = paA.
[0074] In this embodiment, (5) formula is simplified as a non coupled form, obtained:
[0075] P ″ = apP, A ″ = paA (6)
[0076] Wherein, a is the network defense force of Lanchester loss coefficient, p is the network attack force of Lanchester loss coefficient, so ap = pa, that is: the network defense force and the network attack force of both sides of the combat function meets the same 2 order differential equation: Z'' = paZ (9)
[0077] For the DDoS attack and defense both sides of the loss model, equation (9) shows that the combat power of both sides will be exponentially decayed.
[0078] The solution of equation (9) can be expressed as:
[0079] Z = Z(0)exp(-kt) (10), wherein, Z(0) is the initial value of the force.
[0080] S24, the geometric mean of single combat is: k = sqrt(ap).
[0081] In this embodiment, the geometric mean of the fighting power of the red and blue sides is:
[0082] k = sqrt(ap) (7)
[0083] S25, respectively, obtain the Lanchester attrition function of the network defense side and the network attack side: P(t) = P0exp(-kt) and A(t) = A0exp(-kt).
[0084] P0exp(-kt), A(t) = A0exp(-kt).
[0085] In this embodiment, the attrition functions of the red and blue sides are respectively:
[0086] P(t) = P0exp(-kt),
[0087] A(t) = A0exp(-kt) (8)
[0088] With the passage of time, the forces (effectiveness) of both the attack and defense sides are consumed, and the consumption rate is affected by various key related factors (effectiveness loss function).
[0089] When an attack occurs, the IP address number (force) of the attack side (enemy) performing the attack and the attack strength information (number of concurrent connections, number of data packets sent per unit time) are obtained through sensors deployed in the attacked system. According to the obtained information of the enemy and me, a quantitative loss evaluation model is generated using the Lanchester equation evaluation method designed in this patent.
[0090] S3, determine whether the loss exceeds the preset threshold and execute the preset decision mechanism according to the determination result. Step S3 includes steps S31-S33:
[0091] S31, set the preset threshold.
[0092] In this embodiment, an effectiveness warning threshold (threshold level) is introduced. The warning threshold level for DDoS attack is set in advance, which can be set as a single threshold or multiple level thresholds (such as warning level, danger level, emergency level, etc.) according to the actual application scene, and the corresponding coping strategies of each level are set, such as: taking expansion, increasing servers and diversion, etc. Enhance the technical means of the effectiveness of the own side, or call the corresponding linkage protection components to take the technical means of limiting the IP address of the attack side, limiting the connection number of the opponent, etc. to restore the effectiveness loss rate of the opponent to an acceptable level.
[0093] S32, determine whether the loss of the DDoS attack and defense sides exceeds the preset threshold.
[0094] S33, when the network defense party's loss does not exceed the preset threshold, continuing the current defense strategy; when the network defense party's loss exceeds the preset threshold, replacing the defense means according to the preset strategy. In the embodiment, when the defense party's efficiency loss (force loss) does not exceed the corresponding threshold, the current defense strategy is continued, and when the loss reaches the corresponding threshold, appropriate defense means such as expansion, diversion, limiting the opponent's IP and the like are adopted according to the preset strategy to restore the system efficiency loss rate (force casualty rate) to an acceptable level.
[0095] In the whole attack duration, the model generated in step S2 is used to evaluate the efficiency loss of the own party (the defense party) in real time, if the loss does not reach the preset warning threshold, the current strategy is maintained, if the loss exceeds the warning threshold, corresponding defense measures are taken according to the strategy set in step S31 to restore the efficiency loss rate of the own party to an acceptable level, and the force and combat power information of the own party is updated.
[0096] The DDoS quantification, detection and defense method of the Lanchester equation can be realized by a DDoS quantification, detection and defense system of the Lanchester equation, see Figure 2 , Figure 2 is a structural schematic diagram of a DDoS quantification, detection and defense system of the Lanchester equation provided by an embodiment of the application, and the DDoS quantification, detection and defense system of the Lanchester equation comprises:
[0097] 1. Attack information sensor: responsible for receiving attack intensity information of the attack party, such as the number of data packets sent by the enemy in a unit of time, the number of required concurrent connections and the like, which are attack intensity information indexes that can be obtained.
[0098] 2. Defense party (own party) information collector: responsible for collecting the energy efficiency information of the defense party system, including force information (the number of servers) and combat power information (energy efficiency information such as CPU efficiency, memory efficiency, network bandwidth, network connection number and concurrent processing capacity).
[0099] 3. Energy efficiency loss calculation module based on the Lanchester equation: according to the information obtained by components 1 and 2, the loss quantification model based on the Lanchester equation designed in the patent is constructed, and the real-time loss of both parties is calculated.
[0100] 4. Energy efficiency loss monitoring system (threshold value): the real-time loss of the own force (energy efficiency) is obtained by component 3, and the corresponding threshold level is set according to the actual application (in a simple application scenario, a single threshold can be designed)
[0101] 5. Strategy library: according to the threshold level of component 4, the corresponding defense strategy is preset, such as expansion, diversion, increasing servers, limiting the attack party's IP and the like.
[0102] 6. Linked Protection and Response Module: Performs specific protection and response measures based on the strategy established in Component 5. The Lanchester Equation DDoS quantification, detection, and defense device provided in this case includes:
[0103] The settings module is used to set the parameters of the Lanchester equations;
[0104] The simulation module is used to simulate the attrition process of both sides in a DDoS attack and defense based on the Lanchester equation.
[0105] The execution module is used to determine whether the amount of loss in the loss process exceeds a preset threshold and to execute a preset decision mechanism based on the determination result.
[0106] The settings module includes:
[0107] The defense settings submodule is used to configure the Lanchester attrition reduction function of the network defense.
[0108] P[p1,p2,p3,p4,t]; where p1 represents the CPU performance of the user, with a weight of t. p2 represents the team's memory performance, with a weight of [value missing]. p3 represents the network performance of our own team, with a weight of [value missing]. p4 represents a fault in our own equipment, with a weight of ω. p4 The attacker settings submodule is used to set the Lanchester attrition reduction function of the network attacker as A[a1,a2,t]; where a1 is the concurrent connection attack effectiveness, and the weight is... a2 represents the attack effectiveness of sending data packets per unit time, with a weight of [value missing].
[0109] The simulation module includes:
[0110] The initialization submodule is used to initialize the forces of both the attacking and defending sides: the network defender's forces are P0 at the start of the network attack; the network attacker's forces are A0 at the start of the network attack.
[0111] The attrition simulation submodule is used to simulate the attrition process of both the attacker and defender in a DDoS attack, where the strength of the network defender satisfies P. ′ =-aA, where the attacking force of the network attacker satisfies A′=-pP; where a is the Lanchester attrition coefficient of the network defender and p is the Lanchester attrition coefficient of the attacking force.
[0112] Simplified submodule, used to simplify to a decoupled form: the force of the network defender satisfies P ″ =apP, the attacking force of the network attacker satisfies A ″ =paA;
[0113] The computing sub-module is configured to calculate a geometric mean of the individual combat power as k=sqrt(ap).
[0114] The obtaining sub-module is configured to obtain a Lanchester loss reduction function of the network defense side and the network attack side respectively as P(t)=P0exp(-kt) and A(t)=A0exp(-kt).
[0115] The execution module comprises:
[0116] The threshold setting sub-module is configured to set the preset threshold value.
[0117] The judgment sub-module is configured to judge whether the loss amount of the loss process of the DDoS attack and defense sides exceeds the preset threshold value.
[0118] The strategy execution sub-module is configured to continue the current defense strategy when the loss amount of the network defense side does not exceed the preset threshold value, and replace the defense means according to the preset strategy when the loss amount of the network defense side exceeds the preset threshold value.
[0119] Those skilled in the art can understand that all or part of the steps of the various methods of the above embodiments can be completed by instructions, or by related hardware controlled by the instructions, which can be stored in a computer readable storage medium and loaded and executed by a processor. Therefore, the embodiments of the present application provide a storage medium, which stores a plurality of instructions, the instructions can be loaded by a processor to execute the steps in any of the DDoS quantitative detection and defense methods of the Lanchester equation provided by the embodiments of the present application.
[0120] The storage medium can include a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0121] Since the instructions stored in the storage medium can execute the steps in any of the DDoS quantitative detection and defense methods of the Lanchester equation provided by the embodiments of the present application, the beneficial effects of any of the DDoS quantitative detection and defense methods of the Lanchester equation provided by the embodiments of the present application can be achieved, which are described in detail in the above embodiments and will not be repeated here.
[0122] The above only describes the preferred embodiments of the present application and should not be used to limit the present application. Any modification, equivalent replacement and improvement made within the spirit and principle of the present application should be included in the protection scope of the present application.
Claims
1. A DDoS quantification detection and defense method of the Lanchester equation, characterized in that, The method comprises the following steps: setting parameters of a Lanchester equation; simulating a loss process of DDoS attack and defense sides according to the Lanchester equation; judging whether the loss amount of the loss process exceeds a preset threshold value and executing a preset decision mechanism according to a judgment result; the setting parameters of the Lanchester equation comprises: The Lanchester attrition function of the network defense party is set as P[p1, p2, p3, p4, t]; wherein p1 is the CPU performance of the own side, the weight is p2 is the memory performance of the own side, the weight is p3 is the network performance of the own side, the weight is p4 is the equipment failure of the own side, the weight is The Lanchester attrition function of the network attack party is set as A[a1, a2, t]; wherein a1 is the attack performance of the number of concurrent connections, the weight is a2 is the attack performance of the data packet sent per unit time, the weight is the simulating the loss process of the DDoS attack and defense sides according to the Lanchester equation comprises: initializing forces of the attack and defense sides: the force of the network defense side is P0 at the beginning of the network attack; the force of the network attack side is A0 at the beginning of the network attack; starting the loss process simulation of the DDoS attack and defense sides, the force of the network defense side satisfies P' = -aA, the force of the network attack side satisfies A' = -pP; wherein, a is a Lanchester loss coefficient of the network defense side, and p is a Lanchester loss coefficient of the network attack side; simplifying into a non-coupling form: the force of the network defense side satisfies P'' = apP, and the force of the network attack side satisfies A'' = paA; therefore, functions of fighting forces of the network defense side and the network attack side satisfy Z'' = paZ, a geometric mean of single soldier fighting force is k = sqrt(ap); and a solution of Z'' = paZ is: Z = Z(0)exp(-kt), wherein Z(0) is an initial value of the force; therefore, Lanchester loss reduction functions of the network defense side and the network attack side are respectively P(t) = P0exp(-kt) and A(t) = A0exp(-kt); the judging whether the loss amount of the loss process exceeds the preset threshold value and executing the preset decision mechanism according to the judgment result comprises: setting the preset threshold value; judging whether the loss amount of the loss process of the DDoS attack and defense sides exceeds the preset threshold value; when the loss amount of the network defense side does not exceed the preset threshold value, continuing a current defense strategy; when the loss amount of the network defense side exceeds the preset threshold value, replacing a defense means according to a preset strategy.
2. A device for DDoS quantitative detection and defense of the Lanchester equation, characterized in that, The method comprises the following steps: a setting module is configured to set parameters of a Lanchester equation; a simulation module is configured to simulate a loss process of DDoS attack and defense sides according to the Lanchester equation; an execution module is configured to judge whether the loss amount of the loss process exceeds a preset threshold value and execute a preset decision mechanism according to a judgment result; the setting module comprises: The defense party setting submodule is configured to set the Lanchester attrition function of the network defense party as P[p1, p2, p3, p4, t]; wherein p1 is the CPU performance of the own side, the weight is p2 is the memory performance of the own side, the weight is p3 is the network performance of the own side, the weight is p4 is the device fault of the own side, the weight is The attack party setting submodule is configured to set the Lanchester attrition function of the network attack party as A[a1, a2, t]; wherein a1 is the attack performance of the number of concurrent connections, the weight is a2 is the attack performance of the data packet sent per unit time, the weight is The simulation module comprises: an initialization sub-module is configured to initialize forces of the attack and defense sides: the force of the network defense side is P0 at the beginning of the network attack; the force of the network attack side is A0 at the beginning of the network attack; a loss simulation sub-module is configured to start the loss process simulation of the DDoS attack and defense sides, the force of the network defense side satisfies P' = -aA, the force of the network attack side satisfies A' = -pP; wherein, a is a Lanchester loss coefficient of the network defense side, and p is a Lanchester loss coefficient of the network attack side; a simplification sub-module is configured to simplify into a non-coupling form: the force of the network defense side satisfies P'' = apP, and the force of the network attack side satisfies A'' = paA; a calculation sub-module is configured to calculate a geometric mean of single soldier fighting force as k = sqrt(ap); An acquisition sub-module is configured to acquire a Lanchester attrition reduction function of a network defense party and a network attack party respectively: P(t) = P0exp(-kt), A(t) = A0exp(-kt); The execution module comprises: A threshold setting sub-module is configured to set the preset threshold value; A judgment sub-module is configured to judge whether the loss of the loss process of the DDoS attack and defense parties exceeds the preset threshold value; A strategy execution sub-module is configured to continue the current defense strategy when the loss of the network defense party does not exceed the preset threshold value, and replace the defense means according to a preset strategy when the loss of the network defense party exceeds the preset threshold value.
3. A computer-readable storage medium, characterized in that, The storage medium has a plurality of instructions stored therein, and the instructions are suitable for being loaded by the processor to execute the DDoS quantitative detection and defense method of the Lanchester equation.