Ldos attack flow accurate positioning method for saving control bandwidth in software defined network
Patent Information
- Application Number
- CN202310235799.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-13
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2043-03-13
AI Technical Summary
[0005]有鉴于此,本申请旨在提出一种软件定义网络中节省控制带宽的LDoS攻击流精准定位方法、装置、设备及介质,以解决在软件定义网络中定位LDoS攻击流比较困难的问题,能够从大量的数据流中精准定位LDoS攻击流且节省控制宽带,使网路防御更加安全有效
[0016]由此,通过将获取到的数据流集合划分为多个数据流子集,匹配每个数据流子集对应的定位规则,基于每个数据流子集对应的定位规则,获取目标吞吐量序列,并根据目标吞吐量序列计算每个定位规则的指标值,筛选出指标值高于预设阈值的至少一个目标定位规则,并将至少一个目标定位规则对应的数据流子集作为新的数据流集合,直至新的数据流集合内的数据流数量为1个,得到LDoS攻击流。由此,解决了在软件定义网络中定位LDoS攻击流比较困难的问题,能够从大量的数据流中精准定位LDoS攻击流且节省控制宽带,使网路防御更加安全有效。
Smart Images

Figure CN116418563B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method for accurately locating LDoS attack flows in software-defined networks while saving control bandwidth. Background Technology
[0002] Software-Defined Networking (SDN) is a centralized network architecture. SDN separates the data plane and control plane, placing control logic on a central controller. SDN switches rely on flow table rules to process data packets. These rules can forward packets from a specified port or guide packets to match other flow table rules within the switch. SDN control flow uses the TCP (Transmission Control Protocol) to transmit data. LDoS (Low-rate Denial of Service) attacks exploit TCP's timeout and retransmission mechanism to send periodic, high-speed bursts of attacks, significantly reducing the throughput of normal user TCP flows. While achieving the effect of a denial-of-service attack, LDoS attacks have a low average rate, require fewer resources, and are highly stealthy. LDoS attacks can threaten not only ordinary user data flows but also potentially damage SDN control flows.
[0003] In related technologies, schemes that locate attack flows by periodically analyzing the throughput sequences of all flows in SDN require uploading traffic information of all data flows to the controller for analysis. However, the bandwidth of the SDN control channel is limited. When there are a large number of data flows in the data plane, this detection method will consume a lot of control bandwidth, and in extreme cases, it may even indirectly cause a denial-of-service attack on the control channel. Another scheme checks for traffic bursts at the switch port to detect LDoS attacks. However, this scheme can only detect the existence of LDoS attacks, but cannot accurately locate the LDoS attack flow from massive data flows.
[0004] In summary, the relevant technologies have the problem of not being able to accurately locate LDoS attack flows in SDN while saving control bandwidth, which urgently needs to be solved. Summary of the Invention
[0005] In view of this, this application aims to propose a method, apparatus, device and medium for accurately locating LDoS attack flows in software-defined networks while saving control bandwidth, so as to solve the problem that it is difficult to locate LDoS attack flows in software-defined networks. It can accurately locate LDoS attack flows from a large amount of data flow and save control bandwidth, making network defense more secure and effective.
[0006] The first aspect of this application provides a method for accurately locating LDoS attack flows in a software-defined network while saving control bandwidth, comprising the following steps: Obtain a set of data streams, divide the set of data streams into multiple subsets of data streams, and match the positioning rules corresponding to each subset of data streams; Based on the positioning rules corresponding to each data stream subset, a target throughput sequence is obtained, and the index value of each positioning rule is calculated based on the target throughput sequence; and At least one target location rule with an index value higher than a preset threshold is selected, and the data stream subset corresponding to the at least one target location rule is used as a new data stream set until the number of data streams in the new data stream set is 1, thus obtaining the LDoS attack stream.
[0007] Furthermore, in some embodiments, calculating the metric value for each positioning rule based on the target throughput sequence includes: Based on a preset traffic intensity standardization formula, the index value of each positioning rule is calculated according to the target throughput sequence, wherein the preset traffic intensity standardization formula is: ; in, Let be the flow intensity of the data stream at time t. , where n is an integer and X is a flow sequence.
[0008] Further, in some embodiments, the step of using a subset of data streams corresponding to the at least one target location rule as a new data stream set, until the number of data streams in the new data stream set is 1, to obtain the LDoS attack stream, includes: Each subset of data streams corresponding to a target location rule is treated as a new set of data streams until the number of data streams in any new set of data streams is 1. Then, the data streams in any new set of data streams are treated as the LDoS attack streams.
[0009] Furthermore, in some embodiments, the data stream error within the plurality of data stream subsets is less than a preset threshold.
[0010] A second aspect of this application provides an LDoS attack flow precision location device in a software-defined network that saves control bandwidth, comprising: The acquisition module is used to acquire a data stream set, divide the data stream set into multiple data stream subsets, and match the positioning rules corresponding to each data stream subset; The calculation module is used to obtain a target throughput sequence based on the positioning rules corresponding to each data stream subset, and to calculate the index value of each positioning rule based on the target throughput sequence; and The positioning module is used to filter out at least one target positioning rule whose indicator value is higher than a preset threshold, and take the data stream subset corresponding to the at least one target positioning rule as a new data stream set until the number of data streams in the new data stream set is 1, thus obtaining the LDoS attack stream.
[0011] Furthermore, in some embodiments, the computing module includes: A calculation unit is used to calculate the index value of each positioning rule based on a preset traffic intensity standardization formula and the target throughput sequence, wherein the preset traffic intensity standardization formula is: ; in, Let be the flow intensity of the data stream at time t. , X is an integer, and X is a flow sequence.
[0012] Furthermore, in some embodiments, the positioning module includes: The positioning unit is used to treat each subset of data streams corresponding to a target positioning rule as a new set of data streams until the number of data streams in any new set of data streams is 1, and then treat the data streams in any new set of data streams as the LDoS attack streams.
[0013] Furthermore, in some embodiments, the data stream error within the plurality of data stream subsets is less than a preset threshold.
[0014] A third aspect of this application provides an electronic device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method for accurately locating LDoS attack flows in a software-defined network that saves control bandwidth as described in the above embodiments.
[0015] A fourth aspect of this application provides a computer-readable storage medium having a computer program stored thereon, which is executed by a processor to implement a method for accurately locating LDoS attack flows in a software-defined network that saves control bandwidth, as described in the above embodiments.
[0016] Therefore, by dividing the acquired data stream set into multiple data stream subsets, matching the location rules corresponding to each data stream subset, obtaining the target throughput sequence based on the location rules corresponding to each data stream subset, and calculating the index value of each location rule according to the target throughput sequence, at least one target location rule with an index value higher than a preset threshold is selected, and the data stream subset corresponding to at least one target location rule is used as a new data stream set, until the number of data streams in the new data stream set is 1, thus obtaining the LDoS attack stream. This solves the problem of the difficulty in locating LDoS attack streams in software-defined networks, enabling accurate location of LDoS attack streams from a large number of data streams while saving control bandwidth, making network defense more secure and effective.
[0017] Additional aspects and advantages of this application will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this application. Attached Figure Description
[0018] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings: Figure 1 A flowchart illustrating a method for accurately locating LDoS attack streams in a software-defined network that saves control bandwidth, according to an embodiment of this application. Figure 2 This is a schematic diagram of a positioning method according to an embodiment of this application; Figure 3 This is a schematic diagram of an LDoS attack flow precision location device in a software-defined network that saves control bandwidth according to an embodiment of this application. Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0019] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other.
[0020] The present application will now be described in detail with reference to the accompanying drawings and embodiments.
[0021] Figure 1 This is a flowchart of a method for accurately locating LDoS attack flows in a software-defined network that saves control bandwidth, according to an embodiment of this application.
[0022] like Figure 1 As shown, the method for accurately locating LDoS attack flows in a software-defined network that saves control bandwidth according to an embodiment of this application includes the following steps: Step S101: Obtain the data stream set, divide the data stream set into multiple data stream subsets, and match the positioning rule corresponding to each data stream subset.
[0023] In this context, a data stream is an ordered sequence of bytes with a start and an end point. A data stream set refers to a collection of sequentially sent packets with the same attributes that pass through the same network within a certain period of time. An LDoS attack stream may exist within a particular data stream set. SDN separates the data platform and control platform, using switches for data stream forwarding. The switches rely on flow table rules to process data packets. Flow table rules are used to match and forward data packets through a forwarding table. This application sets two flow table sets for flow table rules in the switch: a location table and a forwarding table. After passing through the location table, the data stream is forwarded from the port to the switch according to the forwarding rules in the forwarding table. The location table contains the location rules of this embodiment, which are used to match data streams before the forwarding table and to collect information on all data streams.
[0024] Understandably, the number of data streams in a network environment is extremely large, while the bandwidth of the SDN control channel is limited, making it impossible to support uploading statistical information for all data streams for location. Therefore, this application, without changing the SDN framework, uses a divide-and-conquer approach, treating all data streams as a set and dividing this set into multiple data stream subsets, which can then be processed subsequently. Furthermore, considering that flow table rules can guide data streams to match other flow table rules and can statistically analyze matched packets, this application leverages the characteristics of SDN flow table rules to establish location flow table rules for statistical analysis of multiple streams.
[0025] Specifically, the SDN controller generates location rules in the location table to match each subset of data flows. For example, given a set of data flows S containing an LDoS attack flow, this method uses m location rules to divide the data flow set S into m subsets of similar size, and each location rule matches one subset. Thus, this application uses the divide-and-conquer approach to divide a large number of data flows in the network into multiple subsets, processing the data flows in an efficient and bandwidth-controlled manner.
[0026] In actual implementation, to save control bandwidth, the positioning rules in the positioning table match multiple flow tables each time, as shown in Table 1. Table 1 is the control bandwidth table for locating LDoS attack flows required in this application embodiment. The polling interval of the controller is set to a uniform 50 milliseconds. After a limited number of experiments, it has been proven that, compared with the solutions in the aforementioned related technologies, the control bandwidth required for locating LDoS attack flows in this application can analyze more data flows than the method of directly analyzing all data flows under the same bandwidth. The bandwidth required for analyzing 1000 data flows in this application is much less than that required for directly analyzing all data flows. Therefore, it can be seen that this application, through the divide-and-conquer algorithm, can use a small amount of bandwidth in the process of locating LDoS attack flows, avoiding the situation in related technologies where the consumption of a large amount of control bandwidth may lead to denial of service of the control channel.
[0027] Table 1
[0028] Step S102: Based on the positioning rules corresponding to each data stream subset, obtain the target throughput sequence, and calculate the index value of each positioning rule according to the target throughput sequence.
[0029] Throughput refers to the number of data packets that pass through per unit time without packet loss. The throughput of normal traffic is relatively stable, while LDoS attacks have periodic high-speed traffic. Therefore, based on the high-speed burst characteristics of LDoS attacks, this application defines the index value of the location rule to represent the maximum change in the intensity of standardized traffic. Furthermore, the index value of LDoS attack flow is much higher than that of normal traffic.
[0030] Specifically, the SDN network controller obtains the throughput sequence of at least one data stream subset by periodically querying the positioning rules, and calculates the indicator value of each positioning rule based on the throughput sequence, thus obtaining the indicator value of each data stream subset.
[0031] Furthermore, in some embodiments, the metric value for each positioning rule is calculated based on the target throughput sequence, including: Based on a preset traffic intensity standardization formula, the index value of each location rule is calculated according to the target throughput sequence. The preset traffic intensity standardization formula is as follows: ; in, Let X be the data flow intensity at time t, when the flow sequence is X. , .
[0032] Step S103: Filter out at least one target location rule whose index value is higher than a preset threshold, and take the data stream subset corresponding to at least one target location rule as a new data stream set until the number of data streams in the new data stream set is 1, thus obtaining the LDoS attack stream.
[0033] In this embodiment, a preset threshold is defined. After standardizing the traffic intensity of the target data stream subset, the calculated index value of the target positioning rule is compared with the preset threshold. If the index value of the target positioning rule exceeds the preset threshold, it is determined that the data stream subset corresponding to the target positioning rule contains an LDoS attack stream. In other words, as long as the positioning rule matches a data stream subset containing an LDoS attack stream, the corresponding index value will be higher than the index value of the normal stream set. Thus, this application can accurately locate the LDoS attack stream. Furthermore, there are many ways to set the preset threshold in this embodiment. The preset threshold can be a threshold pre-set by those skilled in the art, a threshold obtained through a limited number of experiments, or a threshold obtained through a limited number of computer simulations; no specific limitation is made here.
[0034] Optionally, in some embodiments, at least one subset of data streams corresponding to a target location rule is used as a new set of data streams until the number of data streams in the new set is 1, resulting in an LDoS attack stream, including: Each subset of data streams corresponding to a target location rule is treated as a new set of data streams until the number of data streams in any new set of data streams is 1. Then, the data streams in any new set of data streams are treated as LDoS attack streams.
[0035] Specifically, this application provides an LDoS attack flow localization algorithm in SDN, which uses a divide-and-conquer iterative approach to locate LDoS attack flows from a large number of data flows. Since the subset of data flows corresponding to the selected target definition rules may contain LDoS attack flows, this application can then modify the matching domain of the localization rule and divide this subset into multiple smaller subsets. That is, the subset of data flows corresponding to the target localization rule is used as a new set of data flows, and then the steps of S102 are repeated to calculate the index value of each localization rule in the new set of data flows. The index value is compared with a preset threshold to obtain another new set of data flows. The above steps are repeated until the number of data flows in a certain subset is 1, then the flow in that subset is determined to be an LDoS attack flow.
[0036] In actual implementation, this application retrieved information on the recall and precision of the method for identifying LDoS attack flows, resulting in the metrics shown in Table 2. Table 2 is a table of the recall and precision of identifying LDoS attack flows in this application's embodiments. With the polling interval of the controller uniformly set to 50 milliseconds, limited experiments have demonstrated that the recall rate of this application for identifying LDoS attack flows is 94.57%, while the precision rate is as high as 99.58%. Therefore, this application, through a divide-and-conquer iterative algorithm, can accurately locate LDoS attack flows in an SDN environment while using a small amount of bandwidth.
[0037] Table 2
[0038] The following is combined with Figure 2 This illustration demonstrates the process of divide-and-conquer iteratively processing a data stream set in an SDN environment using the LDoS attack stream precise localization method of this application embodiment. Figure 2 As shown, 256 data streams pass through the switch. These 256 data streams are considered as a single data stream set, and their source IP addresses belong to subnet 12.12.11.0 / 24. Among them, the stream with source IP address 12.12.11.193 is the LDoS attack stream. Four location rules are used to iteratively locate the LDoS attack stream. The specific implementation method is as follows: In the first round, this application divides the data stream set into four data stream subsets, i.e., into four subnets: 12.12.11.0 / 26, 12.12.11.64 / 26, 12.12.11.128 / 26, and 12.12.11.192 / 26. Four location rules are used to collect aggregated statistical information for each data stream subset. The controller generates location rules in the location table to match each subset. The controller obtains the throughput sequence of each data stream subset and calculates the index values of the four location rules. Comparing these index values, if the index value of the location rule corresponding to subnet 12.12.11.192 / 26 is higher than a preset threshold, then the LDoS attack stream is determined to belong to subnet 12.12.11.192 / 26.
[0039] In the second round, the location rules were modified to match the four subnets of 12.12.11.192 / 26. The index values of these four location rules were calculated and compared with the preset threshold. If it was confirmed that the index value of the location rule corresponding to subnet 12.12.11.192 / 28 was higher than the preset threshold, then it was determined that subnet 12.12.11.192 / 28 contained an LDoS attack flow.
[0040] In the third round, the location rules are used to match the four subnets of 12.12.11.192 / 28. At this point, the subnet containing the LDoS attack flow is confirmed to be 12.12.11.192 / 30.
[0041] Finally, in the fourth round, the source IP address of the LDoS attack flow was confirmed to be 12.12.11.193 in subnet 12.12.11.192 / 30.
[0042] Therefore, this application utilizes the characteristics of SDN flow table rules to establish location flow table rules to count data from multiple flows. In each iteration, the application divides all data flows in a data flow set into multiple data flow subsets, and uses a special flow table to count the throughput of each data flow subset and calculate the index value. Then, the data flow subset with an index higher than a preset threshold is selected for the next iteration. After multiple iterations, when there is only one data flow in a certain flow set, that flow is the LDoS attack flow.
[0043] Optionally, in some embodiments, the data stream error within multiple data stream subsets is less than a preset threshold.
[0044] It is understandable that when this application divides the data stream set into multiple data stream subsets, the imbalance of network data traffic will cause certain errors between data streams within the data stream subsets. Therefore, this application has a preset threshold for data stream error. There are many ways to set this threshold, which are not specifically limited here. The threshold can be a threshold preset by those skilled in the art, a threshold obtained through a limited number of experiments, or a threshold obtained through a limited number of calculations and simulations.
[0045] The method for accurately locating LDoS attack flows in software-defined networks (SDNs) according to embodiments of this application saves control bandwidth. It divides the acquired data flow set into multiple data flow subsets, matches the location rules corresponding to each data flow subset, obtains a target throughput sequence based on the location rules for each data flow subset, calculates the index value for each location rule based on the target throughput sequence, filters out at least one target location rule whose index value is higher than a preset threshold, and uses the data flow subset corresponding to at least one target location rule as a new data flow set until the number of data flows in the new data flow set is 1, thus obtaining the LDoS attack flow. This solves the problem of difficulty in locating LDoS attack flows in SDNs, enabling accurate location of LDoS attack flows from a large number of data flows while saving control bandwidth, making network defense more secure and effective.
[0046] Next, referring to the accompanying drawings, a precise LDoS attack flow location device for saving control bandwidth in software-defined networks, according to an embodiment of this application, is described.
[0047] Figure 3 This is a schematic diagram of an LDoS attack flow precision location device in a software-defined network that saves control bandwidth, according to an embodiment of this application.
[0048] like Figure 3 As shown, the LDoS attack flow precise location device 10 in the software-defined network that saves control bandwidth includes: an acquisition module 100, a calculation module 200, and a location module 300.
[0049] The acquisition module 100 is used to acquire a data stream set, divide the data stream set into multiple data stream subsets, and match the positioning rule corresponding to each data stream subset; the calculation module 200 is used to acquire a target throughput sequence based on the positioning rule corresponding to each data stream subset, and calculate the indicator value of each positioning rule according to the target throughput sequence; the positioning module 300 is used to filter out at least one target positioning rule with an indicator value higher than a preset threshold, and take the data stream subset corresponding to at least one target positioning rule as a new data stream set, until the number of data streams in the new data stream set is 1, thus obtaining the LDoS attack stream.
[0050] Furthermore, in some embodiments, the computing module 200 includes: The calculation unit is used to calculate the index value of each positioning rule based on a preset traffic intensity standardization formula and the target throughput sequence. The preset traffic intensity standardization formula is as follows: ; in, Let be the flow intensity of the data stream at time t. , , X is an integer, and X is a flow sequence.
[0051] Furthermore, in some embodiments, the positioning module 300 includes: The positioning unit is used to treat each subset of data streams corresponding to a target positioning rule as a new set of data streams until the number of data streams in any new set of data streams is 1, at which point the data streams in any new set of data streams are taken as LDoS attack streams.
[0052] Furthermore, in some embodiments, the data stream error within multiple data stream subsets is less than a preset threshold.
[0053] It should be noted that the foregoing explanation of the LDoS attack flow precise location method embodiment for saving control bandwidth in software-defined networks also applies to the LDoS attack flow precise location device for saving control bandwidth in software-defined networks in this embodiment, and will not be repeated here.
[0054] The method for accurately locating LDoS attack flows in software-defined networks (SDNs) according to embodiments of this application saves control bandwidth. It divides the acquired data flow set into multiple data flow subsets, matches the location rules corresponding to each data flow subset, obtains a target throughput sequence based on the location rules for each data flow subset, calculates the index value for each location rule based on the target throughput sequence, filters out at least one target location rule whose index value is higher than a preset threshold, and uses the data flow subset corresponding to at least one target location rule as a new data flow set until the number of data flows in the new data flow set is 1, thus obtaining the LDoS attack flow. This solves the problem of difficulty in locating LDoS attack flows in SDNs, enabling accurate location of LDoS attack flows from a large number of data flows while saving control bandwidth, making network defense more secure and effective.
[0055] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device may include: The memory 401, the processor 402, and the computer program stored on the memory 401 and capable of running on the processor 402.
[0056] When the processor 402 executes the program, it implements the method for accurately locating LDoS attack flows in software-defined networks that saves control bandwidth, as provided in the above embodiments.
[0057] Furthermore, electronic devices also include: Communication interface 403 is used for communication between memory 401 and processor 402.
[0058] The memory 401 is used to store computer programs that can run on the processor 402.
[0059] The memory 401 may include high-speed RAM (Random Access Memory) memory, and may also include non-volatile memory, such as at least one disk storage.
[0060] If the memory 401, processor 402, and communication interface 403 are implemented independently, then the communication interface 403, memory 401, and processor 402 can be interconnected via a bus to complete communication between them. The bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 4 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0061] Optionally, in a specific implementation, if the memory 401, processor 402, and communication interface 403 are integrated on a single chip, then the memory 401, processor 402, and communication interface 403 can communicate with each other through an internal interface.
[0062] Processor 402 may be a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of this application.
[0063] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for accurately locating LDoS attack flows in a software-defined network while saving control bandwidth.
[0064] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0065] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise explicitly specified.
[0066] Any process or method described in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more N executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of this application includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as should be understood by those skilled in the art to which embodiments of this application pertain.
[0067] It should be understood that the various parts of this application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, the N steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (FPGAs), field-programmable gate arrays (FPGAs), etc.
[0068] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.
[0069] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.
Claims
1. A method for accurately locating LDoS attack flows in a software-defined network while saving control bandwidth, characterized in that, Includes the following steps: Obtain a set of data streams, divide the set of data streams into multiple subsets of data streams, and match the positioning rules corresponding to each subset of data streams; Based on the positioning rules corresponding to each data stream subset, a target throughput sequence is obtained, and the index value of each positioning rule is calculated based on the target throughput sequence. as well as At least one target location rule with an indicator value higher than a preset threshold is selected, and the data stream subset corresponding to the at least one target location rule is used as a new data stream set until the number of data streams in the new data stream set is 1, thus obtaining the LDoS attack stream. The step of calculating the index value for each positioning rule based on the target throughput sequence includes: Based on a preset traffic intensity standardization formula, the index value of each positioning rule is calculated according to the target throughput sequence, wherein the preset traffic intensity standardization formula is: ; in, Let be the flow intensity of the data stream at time t. X is an integer, and X is a flow sequence.
2. The method according to claim 1, characterized in that, The step of taking a subset of data streams corresponding to the at least one target location rule as a new data stream set, until the number of data streams in the new data stream set is 1, to obtain the LDoS attack stream, includes: Each subset of data streams corresponding to a target location rule is treated as a new set of data streams until the number of data streams in any new set of data streams is 1. Then, the data streams in any new set of data streams are treated as the LDoS attack streams.
3. The method according to claim 1, characterized in that, The data stream error within the plurality of data stream subsets is less than a preset threshold.
4. A device for precise location of LDoS attack flows in software-defined networks that saves control bandwidth, characterized in that, include: The acquisition module is used to acquire a data stream set, divide the data stream set into multiple data stream subsets, and match the positioning rules corresponding to each data stream subset; The calculation module is used to obtain the target throughput sequence based on the positioning rule corresponding to each data stream subset, and calculate the index value of each positioning rule according to the target throughput sequence. as well as The positioning module is used to filter out at least one target positioning rule whose indicator value is higher than a preset threshold, and take the data stream subset corresponding to the at least one target positioning rule as a new data stream set until the number of data streams in the new data stream set is 1, thus obtaining the LDoS attack stream. The computing module includes: A calculation unit is used to calculate the index value of each positioning rule based on a preset traffic intensity standardization formula and the target throughput sequence, wherein the preset traffic intensity standardization formula is: ; in, Let be the flow intensity of the data stream at time t. X is an integer, and X is a flow sequence.
5. The apparatus according to claim 4, characterized in that, The positioning module includes: The positioning unit is used to treat each subset of data streams corresponding to a target positioning rule as a new set of data streams until the number of data streams in any new set of data streams is 1, and then treat the data streams in any new set of data streams as the LDoS attack streams.
6. The apparatus according to claim 4, characterized in that, The data stream error within the plurality of data stream subsets is less than a preset threshold.
7. An electronic device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the program to implement a method for precise location of LDoS attack flows in a software-defined network that saves control bandwidth as described in any one of claims 1-3.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, The program is executed by the processor to implement the method for precise location of LDoS attack flows in a software-defined network that saves control bandwidth as described in any one of claims 1-3.
Citation Information
Patent Citations
A LDoS attack detection method in SDN environment
CN109040131A
LDoS attack detection method based on integrated wavelet transform in SDN environment
CN112637202A