A method for evaluating the effectiveness of application-layer DDoS attack and defense

CN116455624BActive Publication Date: 2026-08-14BEIJING INST OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-07
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

但是,这些方法往往只能进行定性的分析,而无法获得准确的定量评估结果

Benefits of technology

[0015]1、本发明通过应用系统的各项指标数据计算应用层DDoS攻防行为效果,在计算攻防效果的过程中,不依赖于任何主观知识,只依据网络应用系统的客观指标数据;对资源指标数据和服务质量指标数据分别进行分析,以体现应用层DDoS攻防行为对资源利用状态和服务质量状态分别的作用效果,因此评估结果更加具体和全面。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116455624B_ABST
    Figure CN116455624B_ABST
Patent Text Reader

Abstract

This invention proposes an application-layer DDoS attack and defense effectiveness evaluation method. Based on the target application's computing, storage, and other resource indicators, as well as service quality indicators, it uses principal component analysis to reduce the dimensionality of the space composed of data indicators and extracts principal components to construct a resource state space and a service quality state space that reflect the effects of attack and defense behaviors. Furthermore, the state space is described as a differential manifold, and the Riemannian metric structure of the differential manifold is given. Finally, using the principles of differential geometry, the effects of attack and defense behaviors are quantitatively calculated, which can accurately evaluate the effectiveness of attack and defense systems and provide an effective reference for application-layer DDoS attack defense.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of application-layer DDoS attack and defense technology, and specifically to a method for evaluating the effectiveness of application-layer DDoS attack and defense. Background Technology

[0002] Current research on application-layer DDoS attacks mainly focuses on detection and defense systems for application-layer DDoS attacks, as well as corresponding methods for evaluating the effectiveness of attack and defense. For the detection and defense of application-layer DDoS attacks, this primarily involves using deep packet inspection (DPI) or CAPTCHA techniques to identify and block attack requests, thereby achieving the goal of resisting attacks. For evaluating the effectiveness of application-layer DDoS attacks, this mainly involves using data collected from application systems and establishing mathematical models to quantify the effectiveness of attack and defense actions.

[0003] Firstly, current research on application-layer DDoS attacks largely focuses on the detection and defense of attack behaviors, while research on evaluating the effectiveness of these defenses is relatively scarce. Existing methods mostly aim to propose application-layer DDoS attack detection and defense systems, utilizing statistical and probabilistic knowledge to establish behavioral models of normal or abnormal users, and using these models as the basis for detecting abnormal behavior within the system. If abnormal behavior is found, techniques such as IP isolation and rate limiting are used to defend against the attack. Although these defense systems can stop attacks to a certain extent and ensure the availability of application systems, there is still a lack of unified standards to compare the specific effectiveness of different defense systems in resisting attacks, as well as the resource and service quality overhead of these systems themselves.

[0004] Secondly, existing research on evaluating the effectiveness of application-layer DDoS attack and defense also has several shortcomings. First, existing technologies rely too heavily on subjective knowledge, leading to less objective evaluation results. For example, some methods utilize expert experience combined with techniques like the analytic hierarchy process (AHP) to evaluate attack and defense effectiveness. However, these methods often only provide qualitative analysis and cannot obtain accurate quantitative evaluation results. Second, existing technologies are based on invalid assumptions, rendering the evaluation results unreliable. For instance, some methods collect various indicator data from application systems, establish mathematical space models, and calculate the utility of attack and defense behaviors. When establishing these mathematical models, these methods assume that the indicators are mutually independent, thus considering them to constitute a Euclidean space. However, network application systems are often complex, and their indicator data exhibit significant correlations. Mathematically, these indicators are linearly correlated and therefore cannot be considered a basis of Euclidean space. Therefore, because these methods are based on invalid assumptions, their mathematical derivations are not rigorous enough, and the evaluation results lack reference value.

[0005] In summary, application-layer DDoS attackers send a large number of application requests, consuming the target server's computing and storage resources, causing service quality degradation and even application system crashes. Currently, there is some research on application-layer DDoS defense, which utilizes machine learning and other methods to detect attack behavior and defend against attacks by blocking attacking IP addresses or rate limiting. These defense strategies have varying degrees of effectiveness. Furthermore, defense strategies against application-layer attacks often require the use of deep packet inspection or CAPTCHA (a fully automated Turing test that distinguishes between computers and humans), which themselves can negatively impact application system resources and service quality to some extent. Therefore, it is necessary to evaluate the attack and defense effectiveness of application-layer DDoS attacks and different defense systems to select the optimal defense strategy, ensuring the availability of network applications and the service quality for legitimate users. Existing methods for evaluating the effectiveness of application-layer DDoS attacks and defenses are often subjective or based on invalid assumptions, leading to inaccurate evaluation results. Summary of the Invention

[0006] In view of this, the present invention proposes an application-layer DDoS attack and defense effectiveness evaluation method, which can accurately evaluate the effectiveness of attack and defense systems and provide an effective reference for the defense against application-layer DDoS attacks.

[0007] To achieve the above objectives, the technical solution of the present invention is as follows:

[0008] An application-layer DDoS attack and defense effectiveness evaluation method includes the following steps: First, simulate the attack and defense behavior of the target application system; during the simulation, collect indicator data of the target application system, including resource indicator data and service quality indicator data. The resource indicator data reflects the resource status of the application system, and the service quality indicator data reflects the service quality status of the application system; after obtaining the indicator data, use principal component analysis to process the resource indicator data and service quality indicator data respectively, and construct a resource state space and a service quality state space; finally, based on the principle of differential geometry, calculate the effect of the attack and defense behavior in the differential manifold. Specifically, according to the resource state space and service quality state space, calculate the effect of the attack behavior on the resource status and service quality status of the target application system respectively. Based on the effect of the attack behavior on the resource status and service quality status of the target application system respectively, compare the effect of a certain attack behavior with and without defense, calculate the defense effect of a certain defense strategy in resisting the specific attack behavior, and thus determine whether the defense is effective against the attack, which serves as the basis for selecting the best defense strategy.

[0009] When simulating the attack and defense behavior of the target application system, a target URL in the target application system is selected and input into the application layer DDoS attack simulation tool to carry out the attack. When evaluating the effect of a specific defense strategy on resisting a specific application layer DDoS attack, the attack behavior is first simulated separately, and then the defense strategy is applied while the attack behavior is in effect. The effect of the attack behavior is compared with and without defense, that is, the effect of the defense strategy.

[0010] The resource metrics data include four categories: computing metrics data, storage metrics data, disk metrics data, and process metrics data. The specific metrics for each category of resource metrics data can be expanded according to different application deployment methods and frameworks. The service quality metrics data include: latency, latency standard deviation, maximum latency, minimum latency, and error rate.

[0011] Specifically, for resource utilization index data and service quality index data, principal component analysis is used to process them respectively, resulting in two dimensionality-reduced spaces with orthogonal coordinate systems, representing the resource utilization state space and the service quality state space respectively. The dot product of two vectors is defined in the orthogonal coordinate system given by principal component analysis, thereby giving the Riemannian metric structure of the differential manifold. Finally, in the mathematical model of the differential manifold, the effects of offensive and defensive behaviors and the resulting movements are defined.

[0012] Specifically, the attack and defense behavior effect calculation method is used to calculate the effects of attack and defense behavior on the resource state space and the service quality state space, respectively. The effects of attack and defense behavior on the resource state and the service quality state are obtained. Based on the attack and defense effect evaluation, application administrators can analyze the effects of attack behavior on the application system and which defense strategies are more effective in resisting application layer DDoS attacks for a certain attack behavior.

[0013] Available application-layer DDoS attack simulation tools include Goldeneye, HULK, JMeter, and Slowhttptest; available application-layer DDoS defense strategies include rate limiting and other existing application-layer DDoS defense systems; available metrics data collection tools include JMeter and Prometheus.

[0014] Beneficial effects:

[0015] 1. This invention calculates the effectiveness of application-layer DDoS attack and defense behavior by using various indicator data of the application system. In the process of calculating the attack and defense effect, it does not rely on any subjective knowledge, but only on the objective indicator data of the network application system. Resource indicator data and service quality indicator data are analyzed separately to reflect the effects of application-layer DDoS attack and defense behavior on resource utilization status and service quality status respectively. Therefore, the evaluation results are more specific and comprehensive.

[0016] 2. This invention utilizes principal component analysis (PCA) to reduce the dimensionality of the collected indicator data, retaining the more important features while ignoring redundant features. This eliminates the correlations between indicator data, reducing computational complexity and improving evaluation efficiency. Simultaneously, the features after dimensionality reduction are independent of each other, eliminating assumptions in existing technologies and making the evaluation results more accurate. Furthermore, this invention uses PCA to obtain a new orthogonal coordinate system in the data space through orthogonal transformation, where the coordinate axes are pairwise independent. Based on the principles of differential geometry, the accurate effects of offensive and defensive behaviors in the application system are derived and calculated.

[0017] 3. This invention, based on various resource and service quality index data of network application systems, uses principal component analysis to process the data and construct a state space for application-layer DDoS attack and defense behavior. Through mathematical derivation, it is proven that the state space can be described as a differential manifold, and the Riemannian metric structure of the differential manifold is given. Based on the principles of differential geometry, the behavioral effects of attack and defense behaviors are calculated within the mathematical model of the differential manifold. The calculation results of this invention can accurately reflect the effectiveness of application-layer DDoS attacks and defenses, helping to select the optimal defense strategy.

[0018] 4. This invention first simulates normal user behavior and application-layer DDoS attack or defense behavior, and monitors the target network components in the application system, acquiring and recording resource utilization index data on the target components and service quality index data for normal users. For the resource utilization index data and service quality index data, principal component analysis is used to process them respectively, resulting in two dimensionality-reduced spaces with orthogonal coordinate systems, representing the resource utilization state space and the service quality state space. Since these spaces are real coordinate spaces and also vector spaces, they can be described as differential manifolds. The dot product of two vectors is defined within the orthogonal coordinate system given by principal component analysis, thus providing the Riemannian metric structure of the differential manifold. Finally, in the mathematical model of the differential manifold, the effects of attack and defense behaviors and the resulting movements are defined, and a method for calculating the effects of attack and defense behaviors is given. Attached Figure Description

[0019] Figure 1 This is a flowchart of the application layer DDoS attack and defense effectiveness evaluation method of the present invention. Detailed Implementation

[0020] The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0021] The terminology involved in this invention is explained as follows:

[0022] Application-layer DDoS: A DDoS (Distributed Denial of Service) attack refers to multiple attackers in different locations simultaneously launching attacks against one or more targets, or a single attacker controlling multiple machines in different locations and using these machines to simultaneously attack the victim. It achieves its goal of preventing the server from providing services to legitimate users by consuming server resources. Application-layer DDoS is a type of Layer 7 DDoS attack targeting the Open Systems Interconnection (OSI) model. Attackers send a large number of application requests, consuming the target server's computing, storage, and other resources, thus reducing the target's service efficiency or causing the application system to completely crash.

[0023] Principal Component Analysis (PCA): PCA is a statistical method that transforms a set of potentially correlated variables into a set of linearly uncorrelated variables through orthogonal transformations, known as principal components. Its main idea is to reconstruct k-dimensional features based on the original n-dimensional features. PCA calculates the covariance matrix of the data matrix and obtains the eigenvalues ​​and eigenvectors of the covariance matrix. It then selects the matrix composed of the eigenvectors corresponding to the k features with the largest eigenvalues. For the original space formed by the data, PCA sequentially finds a set of mutually orthogonal coordinate axes. The first coordinate axis is chosen from the direction of maximum variance in the original data, the second coordinate axis is chosen from the direction of maximum variance in a plane orthogonal to the first coordinate axis, and so on. Thus, PCA maps the original data to a smaller-dimensional space and provides an orthogonal coordinate system for the new space.

[0024] Differential manifolds: Differential manifolds are an important class of spaces in topology and geometry. A topological manifold is a Hausdorff, second countable, and locally Euclidean topological space. A differential manifold is a topological manifold with a differential structure. For a differential manifold, a Riemannian metric structure can be attached to it, which is a quadratic form on the tangent space of the manifold. Any differential manifold can be given a Riemannian metric structure, and geometric concepts such as distance and angle in the differential manifold can be defined by using this structure.

[0025] This invention, based on resource and service quality index data of network application systems, utilizes principal component analysis (PCA) to process the data and construct a state space for application-layer DDoS attack and defense behavior. Through mathematical derivation, it is proven that the state space can be described as a differential manifold, and the Riemannian metric structure of the differential manifold is given. Based on the principles of differential geometry, the behavioral effects of attack and defense behaviors are calculated within the mathematical model of the differential manifold. The calculation results of this invention can accurately reflect the effectiveness of application-layer DDoS attacks and defenses, helping to select the optimal defense strategy. The flowchart of the application-layer DDoS attack and defense effectiveness evaluation method proposed in this invention, based on PCA and differential geometry principles, is shown below. Figure 1 As shown, the implementation steps are as follows:

[0026] Step 1: Simulate the attack and defense behavior of the target application system. Available application-layer DDoS attack simulation tools include Goldeneye, HULK, JMeter, and Slowhttptest, while available application-layer DDoS defense strategies include rate limiting and other existing application-layer DDoS defense systems. Specifically, a target URL from the target application system is selected and input into the application-layer DDoS attack simulation tool to execute the attack. When evaluating the effectiveness of a specific defense strategy against a specific application-layer DDoS attack, the attack behavior is first simulated separately. Then, the defense strategy is applied while the attack behavior is in effect, and the change in the attack behavior with and without defense is compared, i.e., the effectiveness of the defense strategy.

[0027] Step 2: During the attack and defense simulation, indicator data is collected from the target application system. This indicator data includes two parts: resource indicator data and service quality indicator data. Specifically, the resource indicator data reflects the resource status of the application system and includes four categories: computation indicator data, storage indicator data, disk indicator data, and process indicator data. Depending on the application deployment method and framework, the specific indicators for each type of resource indicator data can be expanded. For example, when the application is deployed on a virtual machine, the resource indicator data may include virtual machine CPU-related indicators, virtual machine memory-related indicators, etc.; when the application is deployed on a container, the resource indicator data may include container CPU-related indicators, container interface data transmission and reception indicators, etc. The service quality indicator data reflects the service quality status of the application system and includes: latency, latency standard deviation, maximum latency, minimum latency, and error rate. For resource indicator data, tools such as Prometheus can be used to collect the indicators; for service quality indicator data, tools such as JMeter can be used to collect the indicators. The indicator data to be collected during the attack and defense simulation is shown in Table 1.

[0028] Table 1. Data Collection for Indicators

[0029]

[0030] Step 3: After obtaining the indicator data, principal component analysis is used to process the resource indicator data and service quality indicator data respectively, constructing the resource state space and service quality state space. Specifically:

[0031] Assume that the number of resource indicator data points obtained in step 2 is n, and the number of service quality indicator data points is m. Principal component analysis is performed on both the resource indicator data and the service quality indicator data. Based on the variance of each feature calculated by the algorithm, the data is dimensionality reduced. Assume that the dimensionality-reduced resource state is represented by U, which is described by i principal components; and the dimensionality-reduced service quality state is represented by Q, which is described by j principal components. Then U and Q can be represented as follows:

[0032] U = {u1, u2, ..., u} a ,…,u i}, a∈[1,i]

[0033] Q = {q1,q2,…,q} b ,…,q j}, b∈[1,j]

[0034] Among them, u a ,q b These are the resource status features and service quality features obtained after dimensionality reduction by principal component analysis, u a ,q b Since these features take values ​​in the real number field, U can be viewed as an i-dimensional real coordinate space, and Q can be viewed as a j-dimensional real coordinate space. Therefore, U is an i-dimensional vector space, and Q is a j-dimensional vector space. For a vector space U, any norm on U determines a topology, therefore U is an i-dimensional topological manifold. Similarly, for a vector space Q, any norm on Q determines a topology, therefore Q is a j-dimensional topological manifold. Each basis (B1,…,B...) of the vector space U... i A B:R isomorphism is defined. i →U, where:

[0035]

[0036] Since this mapping is a homeomorphism, therefore (U,B) -1 () is a coordinate chart. Assume... It is another basis of U, and If they are corresponding isomorphisms, then there exists an invertible matrix. Make This holds true for any 'a'. Then the transition mapping between the two coordinate axes is: in The following relationship must be satisfied:

[0037]

[0038] therefore, Therefore, x and The transition mapping between them is an invertible linear mapping, a differential homeomorphism. Therefore, any two coordinate cards are compatible. The set of all such coordinate cards defines a differential structure on the topological manifold U, thus U is an i-dimensional differential manifold. Similarly, it can be proven that Q is a j-dimensional differential manifold.

[0039] The features obtained from principal component analysis are independent of each other and form an orthogonal coordinate system. Due to the orthogonality between basis vectors, the dot product of two vectors can be defined as the second-order tensor field of the differential manifold, i.e., the Riemannian metric structure. Assume the Riemannian metric is composed of... This indicates that in coordinate system (m) a )Down, (According to Einstein's summation convention) can be expressed as:

[0040]

[0041] Where δ ac Kronecker notation. The symmetric product of a tensor α and itself is abbreviated as α0. 2 Then the Riemann metric can be written as:

[0042]

[0043] Therefore, for a point s on a differentiable manifold U, the tangent space T s For two vectors v and w in U, the Riemann metric is:

[0044]

[0045] Therefore, a Riemannian metric structure on the differential manifold U is defined, giving the resource state space of offensive and defensive actions, i.e., the Riemannian manifold U. Similarly, the service quality state space of offensive and defensive actions can be given, i.e., the Riemannian manifold Q. When offensive and defensive actions affect the target application, they change the target's resource index data and service quality index data, i.e., they change the feature values ​​in the resource state space and service quality state space, which is reflected as the movement of points on the Riemannian manifold.

[0046] Step 4: Based on the principles of differential geometry, calculate the effects of offensive and defensive actions within the differential manifold. Specifically:

[0047] Suppose that before a certain action is taken, the application system is at point P on a differentiable manifold M. After the action, the application system moves to point Q on the same manifold M. Connecting points P and Q with a geodesic yields a smooth parametric curve ρ(t) on the manifold M, called the action path. At any point on the action path ρ(t), the action causes an instantaneous movement along ρ(t). According to differential geometry, the movement of a point along the curve ρ(t) can be described as a parallel movement on a tangent vector field. For any point on the curve ρ(t), the instantaneous movement velocity can be described by the tangent vector at that point, while the instantaneous effect of the action at that point is described by the total derivative of the tangent vector field with respect to the curve parameter t. Simultaneously, the action causes an instantaneous movement along the curve ρ. For an i-dimensional differentiable manifold U, the instantaneous action is an i-dimensional vector, and the instantaneous movement is also an i-dimensional vector. Therefore, the differential element of the effect of the action at that point is the dot product of the instantaneous action vector and the instantaneous movement vector. The sum of the differential effects of all points on the entire curve ρ represents the effect of the action. Therefore, the attack effect produced by the simulated attack can be calculated.

[0048] Assume that without any defense strategy deployed, the effect of an attack A is E. A0 After deploying defense strategy D, the effect of attack A is E. A1 Then the defensive effect E of defense strategy D. D It can be represented as:

[0049] E D =E A0 -E A1

[0050] If E D If E is greater than or equal to 0, then defense strategy D can resist attack behavior A to a certain extent; if E D If the value is less than 0, then the deployment of defense strategy D cannot resist attack behavior A and has a negative impact.

[0051] By using the aforementioned methods for calculating the effects of attack and defense actions in both the resource state space and the service quality state space, we can obtain the effects of attack and defense actions on the resource state and the service quality state, respectively. Based on this attack and defense effect assessment, application administrators can analyze the impact of attacks on the application system and determine which defense strategies are more effective in resisting application-layer DDoS attacks, thus ensuring the availability of the application system.

[0052] Since the "effect" of a behavior is a concept of "function" or "energy," its quantification is related to the action itself and the changes that action produces on the object. Therefore, this invention utilizes the principles of differential geometry and, through mathematical derivation, provides a method for calculating the "effect," rather than simply describing the "effect" using state changes.

[0053] In summary, the above are merely preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for evaluating the effectiveness of application-layer DDoS attack and defense, characterized in that, The process includes the following steps: First, simulate the attack and defense behavior of the target application system. During the simulation, collect indicator data from the target application system. This data includes resource indicator data and service quality indicator data, whereby the resource indicator data reflects the resource status of the application system and the service quality indicator data reflects the service quality status. After obtaining the indicator data, use principal component analysis to process the resource indicator data and service quality indicator data respectively, constructing a resource state space and a service quality state space. Finally, based on the principles of differential geometry, calculate the effect of the attack and defense behavior in the differential manifold. Specifically, based on the resource state space and service quality state space, calculate the effect of the attack behavior on the resource status and service quality status of the target application system. By comparing the effect of a certain attack behavior with and without defense, calculate the defense effect of a certain defense strategy against the attack behavior, thereby determining whether the defense is effective against the attack and serving as the basis for selecting the best defense strategy. Due to the orthogonality between basis vectors, the dot product of two vectors is defined as the second-order tensor field of the differential manifold, i.e., the Riemannian metric structure. The Riemannian metric structure on the differential manifold U is defined, and the resource state space of the attack and defense behavior is given, i.e., the Riemannian manifold U. The service quality state space of the attack and defense behavior is given, i.e., the Riemannian manifold Q. It is assumed that before a certain behavior is performed, the application system state is at point P of the differential manifold M; after the behavior is performed, the application system state moves to point Q of the differential manifold M. Connecting points P and Q with geodesics yields a smooth parametric curve p(t) on manifold M, which is called the behavior path. At any point on the action path p(t), due to the action, an instantaneous movement along p(t) occurs at that point. For an i-dimensional differential manifold U, the instantaneous action is an i-dimensional vector, and the instantaneous movement is also an i-dimensional vector. Therefore, the differential element of the effect produced by the action at that point is the dot product of the instantaneous action vector and the instantaneous movement vector. The sum of the differential elements of the effects at all points on the entire curve p is the effect of the action.

2. The method as described in claim 1, characterized in that, When simulating the attack and defense behavior of the target application system, a target URL in the target application system is selected and entered into the application layer DDoS attack simulation tool to carry out the attack; When evaluating the effectiveness of a defense strategy in resisting a certain application-layer DDoS attack, the attack behavior is first simulated separately. Then, the defense strategy is applied while the attack behavior is in effect, and the effect of the attack behavior is compared with and without defense, i.e., the effectiveness of the defense strategy.

3. The method as described in claim 1, characterized in that, The resource metrics data includes four categories: computation metrics data, storage metrics data, disk metrics data, and process metrics data. The specific metrics for each category of resource metrics data can be expanded according to different application deployment methods and frameworks. The service quality metrics data includes: latency, latency standard deviation, maximum latency, minimum latency, and error rate.

4. The method as described in claim 3, characterized in that, For resource utilization index data and service quality index data, principal component analysis is used to process them respectively, resulting in two dimensionality-reduced spaces with orthogonal coordinate systems, representing the resource utilization state space and the service quality state space respectively. The dot product of two vectors is defined in the orthogonal coordinate system given by principal component analysis, thereby giving the Riemannian metric structure of the differential manifold. Finally, in the mathematical model of the differential manifold, the effects of offensive and defensive behaviors and the resulting movements are defined.

5. The method as described in claim 4, characterized in that, The effects of attack and defense behaviors are calculated in the resource state space and the service quality state space, respectively, using the attack and defense behavior effect on the resource state and the attack and defense behavior effect on the service quality state. Based on attack and defense effectiveness assessment, it helps application administrators analyze the effects of attack behaviors on application systems, and which defense strategies are more effective in resisting application-layer DDoS attacks against a particular attack behavior.

6. The method according to any one of claims 1-5, characterized in that, Available application-layer DDoS attack simulation tools include Goldeneye, HULK, JMeter, and Slowhttptest; available application-layer DDoS defense strategies include rate limiting and other existing application-layer DDoS defense systems; available metrics data collection tools include JMeter and Prometheus.