A network traffic cleaning method, device, equipment and medium

By acquiring and analyzing traffic data in the traffic scrubbing method, and dynamically adjusting the scrubbing task to match the protection rules, the problem of the single scrubbing strategy in the existing technology is solved, and more efficient network traffic scrubbing and adaptive capabilities are achieved.

CN116366278BActive Publication Date: 2025-12-12CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211662876.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-23
Publication Date
2025-12-12
Estimated Expiration
2042-12-23

AI Technical Summary

Technical Problem

Existing traffic scrubbing methods can only perform scrubbing when a threshold is reached, and cannot dynamically change the strategy, resulting in insufficient adaptability.

Method used

By acquiring a set of traffic data within a specified time period, determining the target traffic data based on the bit rate and monitoring time of the traffic data, and matching it with a set of protection rules, the cleaning task is dynamically adjusted to achieve cleaning upgrade operations.

Benefits of technology

It improves the adaptability and efficiency of traffic scrubbing, and can dynamically adjust the scrubbing strategy according to traffic changes, thereby enhancing the flexibility and effectiveness of network protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116366278B_ABST
    Figure CN116366278B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a network traffic cleaning method, device, equipment and medium, the method comprising: obtaining a traffic data set in a set time period; determining target traffic data from the traffic data set based on the code rate and monitoring time of each traffic data; determining a protection rule set matched with the target traffic data; performing a cleaning upgrade operation on a cleaning task corresponding to to-be-processed traffic data based on the relationship between the code rate of the to-be-processed traffic data and the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set, to obtain an upgraded cleaning task; and performing a cleaning operation on the to-be-processed traffic data based on the upgraded cleaning task by using a protection rule corresponding to the to-be-processed traffic data. The present disclosure can dynamically perform a cleaning upgrade operation on a cleaning task, thereby improving the adaptive ability of cleaning.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of network management, and in particular to a network traffic cleaning method, device, equipment and medium. BACKGROUND

[0002] Traffic cleaning is a technology for detecting and controlling abnormal traffic existing in a network, and has excellent processing effect on DDos (Distributed Denial of Service) attacks existing in the network. The principle of realizing cleaning is that, after discovering network attack behavior, the BGP (Border Gateway Protocol) route announcement is used to route and forward attack traffic, the traffic is led to a cleaning device for attack traffic filtering, and then the filtered legal traffic is injected back into the network to avoid the failure caused by DDos attacks.

[0003] However, the cleaning protection strategy in the above traffic cleaning method can only be cleaned when the threshold is reached, the method is single, and the cleaning strategy cannot be dynamically changed. SUMMARY

[0004] The present disclosure provides a network traffic cleaning method, device, equipment and medium, which can realize dynamic cleaning upgrade operation of cleaning tasks and improve the self-adaptive ability of cleaning.

[0005] According to a first aspect of an embodiment of the present disclosure, a network traffic cleaning method is provided, which comprises:

[0006] Obtaining a traffic data set in a set time period, wherein the traffic data set comprises a plurality of traffic data, each traffic data comprises a code rate and a monitoring time, the code rate represents the code rate of transmitting the traffic data, and the monitoring time represents the time when the traffic data is monitored;

[0007] Determining target traffic data from the traffic data set based on the code rate and the monitoring time of each traffic data;

[0008] Determining a protection rule set matched with the target traffic data;

[0009] Performing cleaning upgrade operation on a cleaning task corresponding to the to-be-processed traffic data based on the relationship between the code rate of the to-be-processed traffic data and the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set, to obtain an upgraded cleaning task;

[0010] Performing cleaning operation on the to-be-processed traffic data by using a protection rule corresponding to the to-be-processed traffic data based on the upgraded cleaning task.

[0011] In a possible implementation, the target traffic data is determined from the traffic data set based on the code rate and the monitoring time of each traffic data, comprising:

[0012] For each traffic data, a change value of the traffic data is determined based on the code rate and the monitoring time of the traffic data and the code rate and the monitoring time of adjacent traffic data;

[0013] A change difference value corresponding to the traffic data is obtained based on a difference between the change value of the adjacent traffic data and the change value of the traffic data;

[0014] The target traffic data is determined from the traffic data set based on a relationship between each change difference value in a change difference value set and a set value, wherein the change difference value set comprises the change difference value corresponding to each traffic data.

[0015] In a possible implementation, the change value of the kth traffic data is determined by the following formula: k

[0016]

[0017] wherein x k+1 is the monitoring time of the k+1th traffic data, x k is the monitoring time of the kth traffic data, y k+1 is the code rate of the k+1th traffic data, y k is the code rate of the kth traffic data.

[0018] In a possible implementation, the target traffic data is determined from the traffic data set based on a relationship between each change difference value in a change difference value set and a set value, comprising:

[0019] If each change difference value in the change difference value set is greater than the set value, the traffic data with a code rate greater than or equal to a set threshold is taken as the target traffic data;

[0020] If each change difference value in the change difference value set is equal to the set value, a traffic data is randomly selected from the traffic data set as the target traffic data;

[0021] If each change difference value in the change difference value set is less than the set value, the traffic data with the smallest monitoring time in the traffic data set is taken as the target traffic data;

[0022] ​If the set of change difference values includes a change difference value greater than the set value and a change difference value less than the set value, the flow data corresponding to the change difference value of the set value is taken as the target flow data, and / or the flow data adjacent to the flow data corresponding to the change difference value of the set value is taken as the target flow data.

[0023] In a possible implementation, the determining the set of protection rules matched with the target flow data comprises:

[0024] determining an initial set of protection rules, wherein the initial set of protection rules includes the protection rules matched with the target flow data;

[0025] eliminating the protection rules with the protection object being the user in the initial set of protection rules to obtain the set of protection rules.

[0026] In a possible implementation, the performing the cleaning upgrade operation on the cleaning task corresponding to the to-be-processed flow data based on the relationship between the code rate of the to-be-processed flow data and the code rate of the target flow data and the diversion type of each protection rule in the set of protection rules to obtain the upgraded cleaning task comprises:

[0027] If the code rate of the to-be-processed flow data is greater than the code rate of the target flow data, and the diversion type of each protection rule in the set of protection rules is the first diversion type, it is determined that the cleaning direction in the cleaning task and the cleaning direction in each protection rule, and / or the reinjection direction in the cleaning task and the reinjection direction in each protection rule, exist differences, and the cleaning upgrade operation is performed on the cleaning direction and / or the reinjection direction in the cleaning task that exist differences to obtain the upgraded cleaning task.

[0028] In a possible implementation, before the performing the cleaning upgrade operation on the cleaning task, the method further comprises:

[0029] determining that the code rate of the to-be-processed flow data is greater than the code rate of the target flow data, and the diversion type of each protection rule in the set of protection rules is not the second diversion type.

[0030] In a possible implementation, the method further comprises:

[0031] If the code rate of the to-be-processed flow data is less than or equal to the code rate of the target flow data, or the code rate of the to-be-processed flow data is greater than the code rate of the target flow data, and the diversion type of each protection rule in the set of protection rules is the second diversion type, the cleaning upgrade operation is prohibited on the cleaning task; and

[0032] Based on the cleaning task, the to-be-processed traffic data is cleaned by using a protection rule corresponding to the to-be-processed traffic data.

[0033] According to a second aspect of the embodiments of the present disclosure, a network traffic cleaning device is provided, which comprises:

[0034] An acquisition module is configured to acquire a traffic data set in a set time period, wherein the traffic data set comprises a plurality of traffic data, each traffic data comprising a code rate and a monitoring time, the code rate representing a code rate of transmitting the traffic data, and the monitoring time representing a time of monitoring the traffic data;

[0035] A first determination module is configured to determine target traffic data from the traffic data set based on the code rate and the monitoring time of each traffic data;

[0036] A second determination module is configured to determine a protection rule set matched with the target traffic data;

[0037] An upgrading module is configured to perform cleaning upgrading operation on a cleaning task corresponding to to-be-processed traffic data based on a relationship between a code rate of the to-be-processed traffic data and a code rate of the target traffic data, and a diversion type of each protection rule in the protection rule set, to obtain an upgraded cleaning task;

[0038] A first cleaning module is configured to perform cleaning operation on the to-be-processed traffic data by using a protection rule corresponding to the to-be-processed traffic data based on the upgraded cleaning task.

[0039] In a possible implementation, the first determination module is configured to:

[0040] For each traffic data, determine a change value of the traffic data based on the code rate and the monitoring time of the traffic data and the code rate and the detection time of adjacent traffic data;

[0041] Obtain a change difference value corresponding to the traffic data based on a difference value between the change value of the adjacent traffic data and the change value of the traffic data;

[0042] Determine target traffic data from the traffic data set based on a relationship between each change difference value in a change difference value set and a set value, wherein the change difference value set comprises the change difference value corresponding to each traffic data.

[0043] In a possible implementation, the first determination module is configured to determine the change value Δr k of the kth traffic data by the following formula: k :

[0044]

[0045] wherein x k+1 is the monitoring time of the k+1th traffic data, x k is the monitoring time of the kth traffic data, y k+1 is the code rate of the k+1th traffic data, y k is the code rate of the kth traffic data.

[0046] In a possible implementation, the first determining module is configured to:

[0047] if each of the change difference values in the change difference value set is greater than the set value, taking the traffic data with a code rate greater than or equal to a set threshold as the target traffic data;

[0048] if each of the change difference values in the change difference value set is equal to the set value, randomly selecting a traffic data from the traffic data set as the target traffic data;

[0049] if each of the change difference values in the change difference value set is less than the set value, taking the traffic data with the smallest monitoring time in the traffic data set as the target traffic data;

[0050] if the change difference value set includes a change difference value greater than the set value and a change difference value less than the set value, taking the traffic data corresponding to the change difference value equal to the set value and / or the traffic data adjacent to the traffic data corresponding to the change difference value equal to the set value as the target traffic data.

[0051] In a possible implementation, the second determining module is configured to:

[0052] determining an initial protection rule set, wherein the initial protection rule set includes a protection rule matched with the target traffic data;

[0053] eliminating the protection rule with a user as a protection object in the initial protection rule set to obtain a protection rule set.

[0054] In a possible implementation, the upgrading module is configured to:

[0055] if the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is a first diversion type, determining that there is a difference between the cleaning direction in the cleaning task and the cleaning direction in each protection rule and / or between the reinjection direction in the cleaning task and the reinjection direction in each protection rule, and performing a cleaning upgrade operation on the cleaning direction and / or the reinjection direction with the difference in the cleaning task to obtain an upgraded cleaning task.

[0056] In a possible implementation, before the cleaning upgrade operation is performed on the cleaning task, the upgrade module is further configured to:

[0057] determine that the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is a non-second diversion type.

[0058] In a possible implementation, the apparatus further includes:

[0059] a judgment module configured to, if the code rate of the to-be-processed traffic data is less than or equal to the code rate of the target traffic data, or the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data and the diversion type of each protection rule in the protection rule set is a second diversion type, prohibit the cleaning upgrade operation from being performed on the cleaning task; and

[0060] a second cleaning module configured to perform a cleaning operation on the to-be-processed traffic data based on the cleaning task and the protection rule corresponding to the to-be-processed traffic data.

[0061] According to a third aspect of the embodiments of the present disclosure, an electronic device is provided, including a processor, a memory for storing processor-executable instructions, wherein the processor implements the steps of the network traffic cleaning method by running the executable instructions.

[0062] According to a fourth aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided, which stores computer instructions, and the instructions are executed by a processor to implement the steps of the network traffic cleaning method.

[0063] The technical solutions provided by the embodiments of the present disclosure at least bring the following beneficial effects:

[0064] The present disclosure determines the target traffic data based on the traffic data set in a time period, and performs a cleaning upgrade operation on the cleaning task corresponding to the to-be-processed traffic data based on the relationship between the code rate of the to-be-processed traffic data and the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set, to obtain the upgraded cleaning task, thereby realizing dynamic cleaning upgrade operation on the cleaning task and improving the self-adaptation ability of cleaning. Furthermore, the present disclosure performs a cleaning operation on the to-be-processed traffic data based on the upgraded cleaning task and the protection rule corresponding to the to-be-processed traffic data, thereby improving the cleaning efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0065] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the drawings needed to be used in the embodiments description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0066] Figure 1 is an application scenario diagram according to an example embodiment;

[0067] Figure 2 is a flowchart of a network traffic cleaning method according to an example embodiment;

[0068] Figure 3 is a structural diagram of a network traffic cleaning system according to an example embodiment;

[0069] Figure 4 is a specific flowchart of a network traffic cleaning method according to an example embodiment;

[0070] Figure 5 is a specific flowchart of determining target traffic data according to an example embodiment;

[0071] Figure 6 is a schematic diagram of three protection rules according to an example embodiment;

[0072] Figure 7 is a schematic diagram of a cleaning operation on to-be-processed traffic data according to an example embodiment;

[0073] Figure 8 is a schematic diagram of selecting a network type combination according to an example embodiment;

[0074] Figure 9 is a schematic diagram of a network traffic cleaning device according to an example embodiment;

[0075] Figure 10 is an electronic device schematic diagram of a network traffic cleaning method according to an example embodiment;

[0076] Figure 11 is a program product schematic diagram of a network traffic cleaning method according to an example embodiment. DETAILED DESCRIPTION

[0077] In order to make the purposes, technical solutions and advantages of the present disclosure clearer, the present disclosure will be further described in detail below with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by a person of ordinary skill in the art without creative work belong to the protection scope of the present disclosure.

[0078] Some words appearing in the text are explained as follows:

[0079] 1. In the embodiments of the present disclosure, the term "and / or" describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after it.

[0080] 2. The terms "first", "second", and the like in the description, claims, and above-described drawings of the present disclosure are used to distinguish similar objects, and do not necessarily indicate a specific order or chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented in an order other than that illustrated or described herein.

[0081] The application scenarios described in the embodiments of the present disclosure are used to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. A person of ordinary skill in the art can know that, as new application scenarios appear, the technical solutions provided by the embodiments of the present disclosure are also applicable to similar technical problems. In the description of the present disclosure, unless otherwise specified, the meaning of "multiple" is two or more.

[0082] Traffic cleaning is a technology for detecting and controlling abnormal traffic existing in a network, and has excellent processing effect on DDos attack existing in the network. The principle of realizing cleaning is that, after discovering network attack behavior, the attack traffic is routed and forwarded by using BGP route announcement, the traffic is led to a cleaning device for attack traffic filtering, and then the filtered legal traffic is injected back to the network, so as to avoid the failure caused by DDos attack.

[0083] However, the cleaning protection strategy in the above traffic cleaning method can only be cleaned when the threshold is reached, the mode is single, and the cleaning strategy cannot be dynamically changed.

[0084] Therefore, in order to solve the above problems, the present disclosure provides a network traffic cleaning method, device, equipment and medium, which realizes dynamic cleaning upgrade operation of the cleaning task, and improves the self-adaptive ability of cleaning.

[0085] Firstly,Figure 1 which is a schematic diagram of an application scenario of an embodiment of the present disclosure, comprising a collector 10 and a server 11. The collector 10 is configured to collect traffic data, and the server 11 is configured to perform a cleaning operation on the traffic data collected by the collector 10.

[0086] In the embodiment of the present disclosure, the server 11 obtains a traffic data set collected by the collector 10 within a set time period, wherein the traffic data set comprises a plurality of traffic data, each traffic data comprising a code rate and a monitoring time, the code rate representing a code rate of transmitting the traffic data, and the monitoring time representing a time when the traffic data is monitored; based on the code rate and the monitoring time of each traffic data, a target traffic data is determined from the traffic data set; a protection rule set matching the target traffic data is determined; based on a relationship between a code rate of to-be-processed traffic data and a code rate of the target traffic data, and a diversion type of each protection rule in the protection rule set, a cleaning upgrade operation is performed on a cleaning task corresponding to the to-be-processed traffic data to obtain an upgraded cleaning task; based on the upgraded cleaning task, a protection rule corresponding to the to-be-processed traffic data is used to perform a cleaning operation on the to-be-processed traffic data.

[0087] In the embodiment of the present disclosure, a network traffic cleaning method is provided, and based on the same concept, the present disclosure further provides a network traffic cleaning device, an electronic device, and a computer readable storage medium.

[0088] In some embodiments, a network traffic cleaning method provided by the present disclosure is described below through specific embodiments, as shown in Figure 2 , comprising:

[0089] Step 201, obtaining a traffic data set within a set time period;

[0090] The traffic data set comprises a plurality of traffic data, each traffic data comprising a code rate and a monitoring time, the code rate representing a code rate of transmitting the traffic data, and the monitoring time representing a time when the traffic data is monitored;

[0091] The set time period can be set by itself according to actual conditions, which is not limited here.

[0092] Each traffic data comprises a code rate (trafficBps) and a monitoring time (time), and further comprises a monitoring address (ip), a user code (customerCode), an alarm number (alrmId), etc.

[0093] The traffic data set within the set time period is pushed by a valley security device.

[0094] Step 202, determining target traffic data from the traffic data set based on the code rate and monitoring time of each traffic data;

[0095] Step 203, determining a set of protection rules matched with the target traffic data;

[0096] Based on the ip, customerCode and trafficBps in the target traffic data, the set of protection rules matched with the target traffic data is obtained by matching with the user-defined protection rules.

[0097] Step 204, performing cleaning upgrade operation on the cleaning task corresponding to the to-be-processed traffic data based on the relationship between the code rate of the to-be-processed traffic data and the code rate of the target traffic data, and the diversion type of each protection rule in the set of protection rules, to obtain an upgraded cleaning task;

[0098] If the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the set of protection rules is the first diversion type, then the cleaning upgrade operation is performed on the cleaning task corresponding to the to-be-processed traffic data, to obtain an upgraded cleaning task.

[0099] The above first diversion type is 163 network.

[0100] Step 205, performing cleaning operation on the to-be-processed traffic data based on the upgraded cleaning task by using the protection rule corresponding to the to-be-processed traffic data.

[0101] The present disclosure determines target traffic data by setting a set of traffic data within a time period, and performs cleaning upgrade operation on the cleaning task corresponding to the to-be-processed traffic data based on the relationship between the code rate of the to-be-processed traffic data and the code rate of the target traffic data, and the diversion type of each protection rule in the set of protection rules, to obtain an upgraded cleaning task, thereby realizing dynamic cleaning upgrade operation on the cleaning task and improving the self-adaptive ability of cleaning. Moreover, the present disclosure performs cleaning operation on the to-be-processed traffic data based on the upgraded cleaning task by using the protection rule corresponding to the to-be-processed traffic data, thereby improving the cleaning efficiency.

[0102] Before introducing the network traffic cleaning method in the present disclosure, the structure of the network traffic cleaning system in the present disclosure is first described, as shown in Figure 3 The network traffic cleaning system of the present disclosure includes a security device, a protection object configuration module, a cleaning task upgrade module and a cleaning module.

[0103] Among them, the Gu'an equipment is used to provide the protection object configuration module with a set of flow data within a set time period, and to provide the cleaning task upgrade module with the flow data to be processed.

[0104] The protection target configuration module is used to acquire a set of traffic data within a set time period. The set of traffic data includes multiple traffic data entries, each of which includes a bitrate and a monitoring time. The bitrate represents the bitrate at which the traffic data is transmitted, and the monitoring time represents the time when the traffic data is detected. Based on the bitrate and monitoring time of each traffic data entry, the target traffic data is determined from the set of traffic data.

[0105] The cleaning task upgrade module is used to determine the set of protection rules that match the target traffic data; based on the relationship between the bitrate of the traffic data to be processed and the bitrate of the target traffic data, and the traffic redirection type of each protection rule in the set of protection rules, the cleaning task corresponding to the traffic data to be processed is upgraded to obtain the upgraded cleaning task.

[0106] The cleaning module is used to perform cleaning operations on the traffic data to be processed based on the upgraded cleaning task and using the protection rules corresponding to the traffic data to be processed.

[0107] The following is a detailed explanation of the specific process of the network traffic cleaning method provided in this disclosure, such as... Figure 4 As shown, it includes:

[0108] Step 401: Obtain the traffic data set within the specified time period;

[0109] For example, if the time period is set to (T1, T2), then the traffic data set within (T1, T2) is {D1, D2, ..., D...} n}, where D k Let k be the kth traffic data, where the value of k ranges from [1, n].

[0110] Step 402: Based on the bitrate and monitoring time of each traffic data, determine the target traffic data from the traffic data set;

[0111] The specific process of determining the target traffic data from the traffic data set based on the bitrate and monitoring time of each traffic data point is as follows: Figure 5 As shown, it includes:

[0112] Step 501: For each data stream, determine the change value of the data stream based on the bitrate and monitoring time of the data stream and the bitrate and detection time of adjacent data streams;

[0113] The change value Δr of the kth flow data can be determined using the following formula.k :

[0114]

[0115] wherein, x k+1 is the monitoring time of the k+1th flow data, x k is the monitoring time of the kth flow data, y k+1 is the code rate of the k+1th flow data, y k is the code rate of the kth flow data.

[0116] Step 502, obtaining a change difference value corresponding to the flow data based on the difference between the change value of the adjacent flow data and the change value of the flow data;

[0117] The change difference value h k of the kth flow data can be determined by the following formula:

[0118] h k = Δr k+1 - Δr k ;

[0119] wherein, Δr k is the change value of the kth flow data, and Δr k+1 is the change value of the k+1th flow data.

[0120] Step 503, determining a target flow data from the flow data set based on the relationship between each change difference value in a change difference value set and a set value, wherein the change difference value set includes the change difference value corresponding to each flow data.

[0121] The change difference value set can be represented as Q ∈ {h k = (Δr k+1 - Δr k ), wherein 1≤k≤n.

[0122] The set value can be 0.

[0123] The determination of the target flow data from the flow data set based on the relationship between each change difference value in the change difference value set and the set value can include the following four cases:

[0124] In the first case, if each change difference value in the change difference value set is greater than the set value, the flow data with a code rate greater than or equal to a set threshold is taken as the target flow data.

[0125] The set threshold can be set according to actual conditions, which is not limited here.

[0126] Specifically, if all the variation differences in the set of variation differences Q are greater than 0, the flow data set is {D1, D2, ..., D...} n}, then traffic data D with a bitrate greater than or equal to the set threshold will be... k If multiple traffic data points have a bitrate equal to the set threshold, one traffic data point can be randomly selected as the target traffic data. If multiple traffic data points have a bitrate greater than the set threshold, the traffic data point with the highest bitrate can be selected as the target traffic data.

[0127] In the second case, if all the variation differences in the set of variation differences are equal to the set value, then a flow data is randomly selected from the set of flow data as the target flow data.

[0128] Specifically, if all the variation differences in the set of variation differences Q are equal to 0, the flow data set is {D1, D2, ..., D...} n Then, a traffic data point D is randomly selected from the traffic data set. k As target traffic data.

[0129] In the third case, if all the variation differences in the set of variation differences are less than the set value, then the traffic data with the shortest monitoring time in the set of traffic data will be taken as the target traffic data.

[0130] Specifically, if all the variation differences in the set of variation differences Q are less than 0, the flow data set is {D1, D2, ..., D...} n If the monitoring time is shortest, the traffic data D1 will be used as the target traffic data.

[0131] In the fourth case, if the set of variation differences includes variation differences greater than the set value and less than the set value, then the traffic data with variation differences equal to the set value is taken as the target traffic data, and / or the traffic data adjacent to the traffic data with variation differences equal to the set value is taken as the target traffic data.

[0132] Specifically, if the set of variation differences Q includes variation differences that are greater than 0 and less than 0, the flow data set is {D1, D2, ..., D...} n}, then the flow data D corresponding to a change difference of 0. k As the target traffic data, and / or the traffic data D adjacent to the traffic data with a change difference of 0. k As target traffic data.

[0133] Step 403: Determine the set of protection rules that match the target traffic data;

[0134] Before step 403, according to alarmId in target traffic data D k , query alarm information pushed by the cloud security device to determine whether the current alarm is ongoing, if the alarm stops, the subsequent step operation is not executed, if the alarm is ongoing, the subsequent step operation is continued.

[0135] The original protection can only be directed to a single IP (Internet Protocol) address or a single IP address segment, and cannot solve the problem of simultaneous cleaning of multiple IP segments under an Internet large customer. In the present disclosure, the protection object can be set to a user level or an IP segment level, and the protection object has the following priority: the IP protection level is higher than the user level. The protection of the IP refers to the cleaning of the traffic in the IP segment, and the protection of the user level refers to the cleaning of all the recorded cleaning IP segments under the user. The present disclosure can increase the configuration scene of cleaning and meet the different scene needs of users.

[0136] As shown in Figure 6 , three protection rules are displayed, for example, the third protection rule is an IP traffic alarm, and the code rate is greater than or equal to 555 Gbps (GigaBits Per Second). The protection object in the protection rule can be an IP or a customer.

[0137] The following method is used to determine a protection rule set matched with the target traffic data:

[0138] An initial protection rule set is determined, wherein the initial protection rule set includes protection rules matched with the target traffic data;

[0139] Protection rules with a user as the protection object in the initial protection rule set are removed to obtain a protection rule set.

[0140] Specifically, based on target traffic data D k , each protection rule matched with the target traffic data D k is determined, a protection rule set T c ={(cn2,defendAction{1,2...n}),(163,defendAction{1,2...n})} is constructed according to the diversion types of the protection rules.

[0141] Wherein, the specific calculation process of defendAction{1,2...n} is as follows:

[0142] Based on target traffic data D kThe IP, customerCode and trafficBps of the target traffic data are matched with the user-defined protection rules to obtain an initial protection rule set defendActionOrigin{1,2...n} including multiple protection rules matched with the target traffic data;

[0143] The principle of IP priority is introduced, that is, if each protection rule in the initial protection rule set has both a user and an IP segment as protection objects, the protection rule having the user as the protection object is removed, and a protection rule set defendAction{1,2...n} is obtained.

[0144] The target traffic data D k is used to query whether there is a cleaning task in progress, and for an existing cleaning task, the tasks are classified according to the diversion type, which can be a cn2 (China Telecom Next Carrier Network) network type and a 163 network type. When the diversion type is the cn2 network type and the 163 network type, a cleaning task set R c ={(cn2, cleanTask{1,2...n}),(163, cleanTask{1,2...n})} is constructed. The diversion type can include other network types in addition to the cn2 network type and the 163 network type, which is not limited here.

[0145] Based on the protection rule set T c and the cleaning task set R c , the protection rule set is processed. If the cleaning task set R c has cleaning tasks of the cn2 network type and the 163 network type, the processed protection rule set U c ={} c If the cleaning task set R c has cleaning tasks of the 163 network type, the processed protection rule set U c ={(cn2, defendAction{1,2...n})} c If the cleaning task set R c has cleaning tasks of the cn2 network type, the processed protection rule set U c ={(163, defendAction{1,2...n})}

[0146] If the cleaning task set R c is empty, the processed protection rule set U c ={(cn2, defendAction{1,2...n}),(163, defendAction{1,2...n})}.

[0147] Step 404, determine whether the first code rate is less than or equal to the second code rate, if yes, execute steps 405-406, otherwise execute step 407;

[0148] The first code rate is the code rate of the to-be-processed traffic data, and the second code rate is the code rate of the target traffic data. The to-be-processed traffic data is pushed by the valley security device.

[0149] Step 405, prohibit cleaning upgrade operation on the cleaning task corresponding to the to-be-processed traffic data;

[0150] Step 406, based on the cleaning task, using the protection rule corresponding to the to-be-processed traffic data to clean the to-be-processed traffic data;

[0151] The cleaning operation process of the to-be-processed traffic data is shown in Figure 7 If the network type is 163 network type, determine whether to start the cleaning, if yes, perform the cleaning operation. Otherwise, determine whether the routing back annotation set is empty, if yes, perform the backbone network cleaning, otherwise, perform the reverse routing back annotation. If the network type is cn2 network type, directly perform the backbone network cleaning. The specific process of the cleaning operation is a prior art, which will not be described in detail here.

[0152] Step 407, determine whether the diversion type of each protection rule in the protection rule set is the first diversion type, if yes, execute steps 408-409, otherwise, execute steps 410-411;

[0153] Different diversion sets can be selected through various network types and diversion directions to reduce the load of network cleaning devices in different sets. As shown in Figure 8 The user can select different network type combinations, such as cn2 network type and 163 network type. Each network type diversion direction set contains multiple cleaning devices. When the user selects the cn2 network type, the determination of the diversion direction is involved. When the user selects the 163 network type, the determination of the diversion direction, the province direction, the back annotation configuration and other parameters is involved.

[0154] The present disclosure supports that the user can freely select different cleaning devices and back annotation routing devices to disperse the cleaning device pressure and reduce the cleaning pressure.

[0155] The first diversion type is 163 network type.

[0156] Step 408, perform cleaning upgrade operation on the cleaning task corresponding to the to-be-processed traffic data to obtain an upgraded cleaning task;

[0157] The cleaning task corresponding to the to-be-processed traffic data is a cleaning task that has not been executed yet. That is, the cleaning task being executed cannot be subjected to the cleaning upgrade operation.

[0158] The specific process of performing the cleaning upgrade operation on the cleaning task corresponding to the to-be-processed traffic data to obtain an upgraded cleaning task is as follows:

[0159] It is determined that the cleaning direction in the cleaning task and the cleaning direction in each protection rule are different, and the cleaning upgrade operation is performed on the cleaning direction that is different in the cleaning task to obtain an upgraded cleaning task; or

[0160] It is determined that the back-annotation direction in the cleaning task and the back-annotation direction in each protection rule are different, and the cleaning upgrade operation is performed on the back-annotation direction that is different in the cleaning task to obtain an upgraded cleaning task; or

[0161] It is determined that the cleaning direction in the cleaning task and the cleaning direction in each protection rule, and the back-annotation direction in the cleaning task and the back-annotation direction in each protection rule are different, and the cleaning upgrade operation is performed on the cleaning direction and the back-annotation direction that are different in the cleaning task to obtain an upgraded cleaning task.

[0162] At step 409, based on the upgraded cleaning task, the protection rule corresponding to the to-be-processed traffic data is used to perform the cleaning operation on the to-be-processed traffic data.

[0163] The specific process of performing the cleaning operation on the to-be-processed traffic data based on the configuration parameter in the upgraded cleaning task and using the protection rule corresponding to the to-be-processed traffic data is the same as that of step 406, and will not be described in detail here.

[0164] At step 410, the cleaning upgrade operation is prohibited on the cleaning task corresponding to the to-be-processed traffic data.

[0165] If the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is a non-second diversion type, the cleaning upgrade operation is prohibited on the cleaning task.

[0166] If the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is a second diversion type.

[0167] The second diversion type is a cn2 network type.

[0168] At step 411, based on the cleaning task, the protection rule corresponding to the to-be-processed traffic data is used to perform the cleaning operation on the to-be-processed traffic data.

[0169] The specific process and steps of performing the cleaning operation on the to-be-processed traffic data by using the protection rule corresponding to the to-be-processed traffic data based on the configuration parameter in the cleaning task are the same as those in step 406, and details are not described herein.

[0170] In some embodiments, based on the same inventive concept, the present disclosure also provides a network traffic cleaning device. Since the device is the device in the method of the present disclosure, and the principle of solving problems of the device is similar to that of the method, the implementation of the device can be referred to the implementation of the method, and details are not described herein.

[0171] As shown in Figure 9 The above device includes the following modules:

[0172] The acquisition module 901 is configured to acquire a traffic data set in a set time period, where the traffic data set includes a plurality of traffic data, each piece of traffic data includes a code rate and a monitoring time, the code rate represents a code rate of transmitting the traffic data, and the monitoring time represents a time of monitoring the traffic data.

[0173] The first determination module 902 is configured to determine target traffic data from the traffic data set based on the code rate and the monitoring time of each piece of traffic data.

[0174] The second determination module 903 is configured to determine a protection rule set matched with the target traffic data.

[0175] The upgrade module 904 is configured to perform a cleaning upgrade operation on a cleaning task corresponding to to-be-processed traffic data based on a relationship between a code rate of the to-be-processed traffic data and a code rate of the target traffic data and a diversion type of each protection rule in the protection rule set, to obtain an upgraded cleaning task.

[0176] The first cleaning module 905 is configured to perform a cleaning operation on the to-be-processed traffic data by using a protection rule corresponding to the to-be-processed traffic data based on the upgraded cleaning task.

[0177] As an optional implementation, the first determination module 902 is configured to:

[0178] For each piece of traffic data, determine a change value of the traffic data based on the code rate and the monitoring time of the traffic data and the code rate and the detection time of adjacent traffic data.

[0179] Obtain a change difference value corresponding to the traffic data based on a difference value between the change value of the adjacent traffic data and the change value of the traffic data.

[0180] determine the target traffic data from the set of traffic data based on a relationship between each change difference in the set of change differences and a set value, wherein the set of change differences comprises change differences corresponding to each traffic data.

[0181] As an optional implementation, the first determining module 902 is configured to determine the change value of the kth traffic data by the following formula: k :

[0182]

[0183] wherein x k+1 is the monitoring time of the k+1th traffic data, x k is the monitoring time of the kth traffic data, y k+1 is the code rate of the k+1th traffic data, and y k is the code rate of the kth traffic data.

[0184] As an optional implementation, the first determining module 902 is configured to:

[0185] if each change difference in the set of change differences is greater than the set value, the traffic data with a code rate greater than or equal to a set threshold is determined as the target traffic data;

[0186] if each change difference in the set of change differences is equal to the set value, a traffic data is randomly selected from the set of traffic data as the target traffic data;

[0187] if each change difference in the set of change differences is less than the set value, the traffic data with the smallest monitoring time in the set of traffic data is determined as the target traffic data;

[0188] if the set of change differences comprises change differences greater than the set value and change differences less than the set value, the traffic data corresponding to the set value is determined as the target traffic data, and / or the traffic data adjacent to the traffic data corresponding to the set value is determined as the target traffic data.

[0189] As an optional implementation, the second determining module 903 is configured to:

[0190] determine an initial protection rule set, wherein the initial protection rule set comprises protection rules matched with the target traffic data;

[0191] remove protection rules with a user as a protection object in the initial protection rule set to obtain a protection rule set.

[0192] As an optional implementation, the upgrading module 904 is configured to:

[0193] If the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is the first diversion type, it is determined that there is a difference between the cleaning direction in the cleaning task and the cleaning direction in each protection rule, and / or between the back-feeding direction in the cleaning task and the back-feeding direction in each protection rule, and a cleaning upgrade operation is performed on the cleaning direction and / or the back-feeding direction in the cleaning task that has the difference, to obtain an upgraded cleaning task.

[0194] As an optional implementation, before the cleaning upgrade operation is performed on the cleaning task, the upgrade module 904 is further configured to:

[0195] determine that the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is not the second diversion type.

[0196] As an optional implementation, the apparatus further includes:

[0197] a judgment module configured to, if the code rate of the to-be-processed traffic data is less than or equal to the code rate of the target traffic data, or the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data and the diversion type of each protection rule in the protection rule set is the second diversion type, prohibit performing a cleaning upgrade operation on the cleaning task; and

[0198] a second cleaning module configured to perform a cleaning operation on the to-be-processed traffic data based on the cleaning task and using the protection rule corresponding to the to-be-processed traffic data.

[0199] In some embodiments, based on the same inventive concept, the present disclosure also provides a network traffic cleaning device, which can implement the network traffic cleaning function discussed above. Please refer to Figure 10 The device includes a processor 101 and a memory 102, wherein the memory 102 is configured to store program instructions.

[0200] The processor 101 invokes the program instructions stored in the memory, and implements the following functions by running the program instructions:

[0201] acquire a traffic data set in a set time period, wherein the traffic data set includes a plurality of traffic data, each traffic data includes a code rate and a monitoring time, the code rate represents the code rate of transmitting the traffic data, and the monitoring time represents the time when the traffic data is monitored;

[0202] determine a target traffic data from the traffic data set based on the code rate and the monitoring time of each traffic data.

[0203] determining a protection rule set matched with the target traffic data;

[0204] performing a cleaning upgrade operation on a cleaning task corresponding to the to-be-processed traffic data based on a relationship between a code rate of the to-be-processed traffic data and a code rate of the target traffic data, and a diversion type of each protection rule in the protection rule set, to obtain an upgraded cleaning task;

[0205] performing a cleaning operation on the to-be-processed traffic data by using a protection rule corresponding to the to-be-processed traffic data based on the upgraded cleaning task.

[0206] As an optional implementation, the determining of the target traffic data from the traffic data set based on the code rate and the monitoring time of each traffic data comprises:

[0207] determining, for each traffic data, a change value of the traffic data based on a code rate and a monitoring time of the traffic data and a code rate and a monitoring time of an adjacent traffic data;

[0208] obtaining a change difference value corresponding to the traffic data based on a difference between the change value of the adjacent traffic data and the change value of the traffic data;

[0209] determining the target traffic data from the traffic data set based on a relationship between each change difference value in a change difference value set and a set value, wherein the change difference value set comprises the change difference value corresponding to each traffic data.

[0210] As an optional implementation, the change value of the kth traffic data is determined by the following formula: k :

[0211]

[0212] wherein x k+1 is the monitoring time of the k+1th traffic data, x k is the monitoring time of the kth traffic data, y k+1 is the code rate of the k+1th traffic data, y k is the code rate of the kth traffic data.

[0213] As an optional implementation, the determining of the target traffic data from the traffic data set based on the relationship between each change difference value in the change difference value set and the set value comprises:

[0214] if each change difference value in the change difference value set is greater than the set value, the traffic data with a code rate greater than or equal to a set threshold is taken as the target traffic data;

[0215] If each of the change difference values in the change difference value set is equal to the set value, randomly selecting a traffic data from the traffic data set as the target traffic data;

[0216] If each of the change difference values in the change difference value set is less than the set value, selecting the traffic data with the smallest monitoring time in the traffic data set as the target traffic data;

[0217] If the change difference value set includes change difference values greater than the set value and less than the set value, selecting the traffic data with the change difference value as the set value as the target traffic data, and / or the traffic data adjacent to the traffic data with the change difference value as the set value as the target traffic data.

[0218] As an optional implementation, the determining the protection rule set matched with the target traffic data comprises:

[0219] Determining an initial protection rule set, wherein the initial protection rule set includes protection rules matched with the target traffic data;

[0220] Eliminating protection rules with a protection object as a user in the initial protection rule set to obtain the protection rule set.

[0221] As an optional implementation, the performing cleaning upgrade operation on the cleaning task corresponding to the to-be-processed traffic data based on the relationship between the code rate of the to-be-processed traffic data and the code rate of the target traffic data and the diversion type of each protection rule in the protection rule set to obtain an upgraded cleaning task comprises:

[0222] If the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data and the diversion type of each protection rule in the protection rule set is a first diversion type, determining that there is a difference between the cleaning direction in the cleaning task and the cleaning direction in each of the protection rules, and / or between the reinjection direction in the cleaning task and the reinjection direction in each of the protection rules, and performing cleaning upgrade operation on the cleaning direction and / or the reinjection direction with the difference in the cleaning task to obtain the upgraded cleaning task.

[0223] As an optional implementation, before the performing cleaning upgrade operation on the cleaning task, the processor is further configured to perform:

[0224] Determining that the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data and the diversion type of each protection rule in the protection rule set is not a second diversion type.

[0225] As an optional implementation, the processor is further configured to perform:

[0226] If the code rate of the to-be-processed traffic data is less than or equal to the code rate of the target traffic data, or the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is the second diversion type, the cleaning upgrade operation is prohibited on the cleaning task; and

[0227] Based on the cleaning task, the to-be-processed traffic data is cleaned by using the protection rule corresponding to the to-be-processed traffic data.

[0228] In some possible implementation manners, various aspects of the present disclosure can also be implemented in the form of a program product, such as a computer program product 110 shown in the figure, which includes computer program codes. When the computer program codes are run on a computer, the computer is caused to perform the network traffic cleaning method as discussed in any of the preceding embodiments. Since the principle of solving problems by the computer program product is similar to that of the network traffic cleaning method, the implementation of the computer program product can be referred to the implementation of the method, and the repeated parts will not be described herein. Figure 11 The computer program product 110 includes computer program codes. When the computer program codes are run on a computer, the computer is caused to perform the network traffic cleaning method as discussed in any of the preceding embodiments. Since the principle of solving problems by the computer program product is similar to that of the network traffic cleaning method, the implementation of the computer program product can be referred to the implementation of the method, and the repeated parts will not be described herein.

[0229] Those skilled in the art should understand that the embodiments of the present disclosure can be provided in the form of a method, a system, or a computer program product. Therefore, the present disclosure can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage, etc.) containing computer-usable program codes.

[0230] The present disclosure is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus produce a device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1 The functions specified in one or more flows and / or blocks Figure 1 The functions specified in one or more flows and / or blocks

[0231] These computer program instructions can also be stored in a computer-readable memory capable of guiding a computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in the flowcharts and / or block diagrams. Figure 1one or more processes and / or blocks Figure 1 the function specified in the one or more blocks or blocks.

[0232] These computer program instructions can also be loaded into computer or other programmable data processing devices, so that a series of operation steps are performed on the computer or other programmable data processing devices to generate computer-implemented processes, so that the instructions executed on the computer or other programmable data processing devices provide processes for implementing the flow Figure 1 one or more processes and / or blocks Figure 1 the function specified in the one or more blocks or blocks.

[0233] Other embodiments of the disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the disclosure disclosed herein. It is intended that the specification and examples be considered as exemplary only, with the true scope and spirit of the disclosure being indicated by the following claims.

[0234] It should be understood that the present disclosure is not limited to the precise structures as herein described and illustrated in the drawings, and that various modifications and changes can be made without departing from its scope. The scope of the present disclosure is limited only by the claims that follow.

Claims

1. A network traffic cleaning method characterized by, The method comprises: acquiring a flow data set in a set time period, wherein the flow data set comprises a plurality of flow data, each flow data comprising a code rate and a monitoring time, the code rate representing a code rate of transmitting the flow data, and the monitoring time representing a time of monitoring the flow data; for each flow data, determining a change value of the flow data based on the code rate and the monitoring time of the flow data and the code rate and the monitoring time of adjacent flow data, obtaining a change difference value corresponding to the flow data based on a difference value between the change value of the adjacent flow data and the change value of the flow data, and determining a target flow data from the flow data set based on a relationship between each change difference value in a change difference value set and a set value, wherein the change difference value set comprises the change difference value corresponding to each flow data; determining a protection rule set matched with the target flow data; performing a cleaning upgrade operation on a cleaning task corresponding to a to-be-processed flow data based on a relationship between a code rate of the to-be-processed flow data and a code rate of the target flow data and a diversion type of each protection rule in the protection rule set, to obtain an upgraded cleaning task, wherein the diversion type of each protection rule is a network type included in the protection rule; performing a cleaning operation on the to-be-processed flow data by using a protection rule corresponding to the to-be-processed flow data based on the upgraded cleaning task.

2. The method of claim 1, wherein, The change value of the kth flow data is determined by the following formula : ; wherein, is the monitoring time of the k+1th flow data, is the monitoring time of the kth flow data, is the code rate of the k+1th flow data, is the code rate of the kth flow data.

3. The method of claim 1, wherein, The determining of the target flow data from the flow data set based on the relationship between each change difference value in the change difference value set and the set value comprises: if each change difference value in the change difference value set is greater than the set value, taking flow data with a code rate greater than or equal to a set threshold as the target flow data; if each change difference value in the change difference value set is equal to the set value, randomly selecting a flow data from the flow data set as the target flow data; if each change difference value in the change difference value set is less than the set value, taking flow data with a minimum monitoring time in the flow data set as the target flow data; if the change difference value set comprises a change difference value greater than the set value and a change difference value less than the set value, taking flow data corresponding to the change difference value as the set value as the target flow data, and / or taking flow data adjacent to the flow data corresponding to the change difference value as the set value as the target flow data.

4. The method of claim 1, wherein, The determining of the protection rule set matched with the target flow data comprises: determining an initial protection rule set, wherein the initial protection rule set comprises protection rules matched with the target flow data; eliminating protection rules with a user as a protection object in the initial protection rule set to obtain the protection rule set.

5. The method of claim 1, wherein, The performing of the cleaning upgrade operation on the cleaning task corresponding to the to-be-processed flow data based on the relationship between the code rate of the to-be-processed flow data and the code rate of the target flow data and the diversion type of each protection rule in the protection rule set to obtain the upgraded cleaning task comprises: If the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is the first diversion type, it is determined that there is a difference between the cleaning direction in the cleaning task and the cleaning direction in each protection rule, and / or between the back-feeding direction in the cleaning task and the back-feeding direction in each protection rule, and a cleaning upgrade operation is performed on the cleaning direction and / or the back-feeding direction in the cleaning task that has the difference, to obtain an upgraded cleaning task.

6. The method according to any one of claims 1 to 5, characterized in that, Before the cleaning upgrade operation is performed on the cleaning task, the method further includes: It is determined that the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is not the second diversion type.

7. The method of claim 6, wherein, The method further includes: If the code rate of the to-be-processed traffic data is less than or equal to the code rate of the target traffic data, or the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is the second diversion type, the cleaning upgrade operation is prohibited on the cleaning task; and Based on the cleaning task, a protection rule corresponding to the to-be-processed traffic data is used to perform a cleaning operation on the to-be-processed traffic data.

8. A network traffic cleaning device, characterized by The apparatus includes: An acquisition module is configured to acquire a traffic data set in a set time period, where the traffic data set includes a plurality of traffic data, each piece of traffic data includes a code rate and a monitoring time, the code rate represents a code rate at which the traffic data is transmitted, and the monitoring time represents a time at which the traffic data is monitored; A first determination module is configured to, for each piece of traffic data, determine a change value of the traffic data based on the code rate and the monitoring time of the traffic data and the code rate and the monitoring time of adjacent traffic data, obtain a change difference value corresponding to the traffic data based on a difference between the change value of the adjacent traffic data and the change value of the traffic data, and determine a target traffic data from the traffic data set based on a relationship between each change difference value in a change difference value set and a set value, where the change difference value set includes the change difference value corresponding to each piece of traffic data; A second determination module is configured to determine a protection rule set matched with the target traffic data; An upgrade module is configured to perform a cleaning upgrade operation on a cleaning task corresponding to to-be-processed traffic data based on a relationship between the code rate of the to-be-processed traffic data and the code rate of the target traffic data and a diversion type of each protection rule in the protection rule set, to obtain an upgraded cleaning task, where the diversion type of each protection rule is a network type included in the protection rule; A first cleaning module is configured to perform a cleaning operation on the to-be-processed traffic data based on the upgraded cleaning task and a protection rule corresponding to the to-be-processed traffic data.

9. The apparatus of claim 8, wherein, The first determining module is configured to determine the change value of the kth piece of traffic data according to the following formula : ; wherein, is the monitoring time of the k+1th flow data, is the monitoring time of the kth flow data, is the code rate of the k+1th flow data, is the code rate of the kth flow data.

10. The apparatus of claim 8, wherein, The first determination module is configured to: If each change difference value in the change difference value set is greater than the set value, a piece of traffic data with a code rate greater than or equal to a set threshold is taken as the target traffic data. if each of the change difference values in the change difference value set is equal to the set value, randomly selecting a traffic data from the traffic data set as the target traffic data; if each of the change difference values in the change difference value set is less than the set value, selecting a traffic data with the smallest monitoring time from the traffic data set as the target traffic data; if the change difference value set includes a change difference value greater than the set value and a change difference value less than the set value, selecting a traffic data corresponding to the change difference value as the set value as the target traffic data, and / or selecting a traffic data adjacent to the traffic data corresponding to the change difference value as the set value as the target traffic data.

11. The apparatus of claim 8, wherein, The second determining module is configured to: determine an initial protection rule set, wherein the initial protection rule set includes a protection rule matched with the target traffic data; remove a protection rule with a user as a protection object from the initial protection rule set to obtain a protection rule set.

12. The apparatus of claim 8, wherein, The upgrading module is configured to: if a code rate of the to-be-processed traffic data is greater than a code rate of the target traffic data, and a diversion type of each protection rule in the protection rule set is a first diversion type, determine that a cleaning direction in the cleaning task and a cleaning direction in each protection rule, and / or a back-feeding direction in the cleaning task and a back-feeding direction in each protection rule exist differences, and perform a cleaning upgrading operation on the cleaning direction and / or the back-feeding direction in the cleaning task with the differences to obtain an upgraded cleaning task.

13. The apparatus of any of claims 8-12, wherein, Before the cleaning upgrading operation is performed on the cleaning task, the upgrading module is further configured to: determine that the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is a non-second diversion type.

14. The apparatus of claim 13, wherein, The apparatus further includes: a judging module configured to, if the code rate of the to-be-processed traffic data is less than or equal to the code rate of the target traffic data, or the code rate of the to-be-processed traffic data is greater than the code rate of the target traffic data, and the diversion type of each protection rule in the protection rule set is a second diversion type, prohibit the cleaning upgrading operation on the cleaning task; and a second cleaning module configured to perform a cleaning operation on the to-be-processed traffic data based on the cleaning task by using a protection rule corresponding to the to-be-processed traffic data.

15. An electronic device, comprising: include: a processor; a memory for storing processor-executable instructions; wherein the processor implements the steps of the method of any one of claims 1 to 7 by running the executable instructions.

16. A computer readable and writeable storage medium having stored thereon computer instructions which, if executed by a computer, cause the computer to perform the method of any one of claims 1 to 15. The instructions are executed by the processor to implement the steps of the method of any one of claims 1 to 7. The instructions are executed by the processor to implement the steps of the method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Attack detection method and device, computer equipment and storage medium

    CN110166418A

  • DDoS attack protection method, device and equipment and computer storage medium

    CN115412310A