A method and system for detecting DDoS attacks

CN116545699BActive Publication Date: 2025-12-16NANJING HEYI COMM EQUIP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310519637.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-09
Publication Date
2025-12-16
Estimated Expiration
2043-05-09

AI Technical Summary

Technical Problem

[0002]分布式拒绝服务攻击可以使很多的计算机在同一时间遭受到攻击,使攻击的目标无法正常使用,分布式拒绝服务攻击已经出现了很多次,导致很多的大型网站都出现了无法进行操作的情况,这样不仅仅会影响用户的正常使用,同时造成的经济损失也是非常巨大的;

Benefits of technology

[0029] Compared with the prior art, the application has the following advantages:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116545699B_ABST
    Figure CN116545699B_ABST
Patent Text Reader

Abstract

The application discloses a kind of DDoS attack detection method and system, computer field, a kind of DDoS attack detection method and system, including through the data receiving module on network packet is received and the data received is detected by the attack detection module;The attack detection module includes flow detection module and packet detection module detects packet and flow;If it is determined as DDoS attack mode, DDoS attack characteristics are collected, and data flow name is recorded and collected, form pre-attack database;Attack data packet is formed by the pre-attack database collected, then start reverse attack module to attack the ip address of attack according to circumstances, the ip address of host is simulated by the cloud virtual machine set in this scheme simultaneously let the ip address of host be modified, reach the effect of diverting attack, so that host has time to backup file or find attack source, avoid the loss of data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of computer DDoS attack, more particularly, to a DDoS attack detection method and system. BACKGROUND

[0002] Distributed denial of service attack can make many computers be attacked at the same time, so that the target of attack cannot be used normally. Distributed denial of service attack has occurred many times, resulting in many large websites cannot operate, which not only affects the normal use of users, but also causes huge economic losses.

[0003] In the computer network DDoS attack, the existing general method is to detect the data packet through flow monitoring or IP address query, and to intercept through the firewall after determining the attack. However, the firewall interception has a certain failure probability, and if the DDoS attack mode continuously attacks through the vulnerability, the host is easily attacked to cause certain security and property losses. At this time, the host generally backs up the file by the method of backing up the file and deleting the original file, but both the backup file and the deletion of the original file need time, and the existing technology cannot support the time. SUMMARY

[0004] 1. Technical problem to be solved

[0005] In view of the problems existing in the prior art, the purpose of the present application is to provide a DDoS attack detection method and system, which can realize that a DDoS attack detection method and system is set up to simulate the IP address of the host through the cloud virtual machine, and the IP address of the host is modified, so as to achieve the effect of transferring the attack. In this way, the host has time to back up the file or find the attack source, avoiding the loss of data.

[0006] 2. Technical scheme

[0007] In order to solve the above problems, the present application adopts the following technical scheme.

[0008] A DDoS attack detection system, comprising a host control module, the receiving end of the host control module is electrically connected with an attack detection module, the receiving end of the attack detection module is electrically connected with a data receiving module, the host control module is connected with an attack transfer module through a wireless network, the output end of the host control module is connected with a data backup module through an M.2 interface or a 5G, the host control module is built-in firewall module, the attack transfer module is a cloud virtual machine module.

[0009] A method for detecting DDoS attack, comprising the following steps: S1: receiving data packets on the network through the data receiving module and detecting the received data through the attack detection module;

[0010] S2: detecting through the attack detection module to determine whether the received data packets are DDoS attack mode, the attack detection module comprising a flow detection module and a packet detection module for detecting data packets and flow;

[0011] If it is determined to be a DDoS attack mode, the firewall module is started to intercept the attack;

[0012] If the time period detection is not determined to be a DDoS attack mode, the host is normally used, but the time detection module in the attack detection module is used for time monitoring, and if it is found that the data packets are sent at a certain rhythm and frequency in the monitoring time period, the ip address detection module in the attack detection module is started to detect the ip address of the data sending end;

[0013] If it is detected in the time period detection that the data packets are sent at a certain rhythm and frequency, and different ip addresses are used for simultaneous sending, it is determined to be a DDoS attack;

[0014] S3: starting the firewall module to adjust the data flow after determining the attack;

[0015] S4: after the attack transfer module is started, the ip address and MAC address of the host are simulated through the cloud virtual machine module, and the ip address, MAC address and time of the host are temporarily modified, so that the DDoS attack cannot search for the host and attacks the cloud virtual machine module instead;

[0016] S5: after the cloud virtual machine module is attacked, the feature collection module, flow collection module and reverse attack module built-in the cloud virtual machine module are started to collect the DDoS attack features, and the data flow name is recorded and collected to form a pre-attack database.

[0017] S6: forming an attack data packet through the collected pre-attack database, and then starting the reverse attack module to perform reverse attack on the ip address of the attack according to the situation.

[0018] Further, the data packet detection method comprises data packet name recording and data packet quantity recording, and a simple screening is performed on whether the data packet quantity is normal and whether the data packet name is repeated.

[0019] Further, the time detection method comprises: a total transmission time table and a single data packet time table, the start time and the end time of the single data packet and the total data packet are recorded, and the transmission time frequency of the single data packet is recorded.

[0020] Further, the flow detection method comprises: comparing the name and flow of the data in the data packet database with the attack data to determine whether it is an attack behavior.

[0021] The data packet database mode can be obtained from the network security database of the Tencent security manager, 360 security guard and the like network antivirus software.

[0022] Further, the data backup method comprises: cloud data backup and high-speed solid state disk backup.

[0023] Further, the cloud data backup comprises: data transmission through 5G or ten thousand megabit optical fiber;

[0024] Further, the high-speed solid state disk backup comprises: high-speed transmission through the M.2 interface and the PCI-E3.0x4 channel.

[0025] Further, the data flow regulation method comprises: limiting the transmitted data flow packet flow or interrupting the transmitted data flow packet, so as to prevent the attack data;

[0026] If the interception is successful, the attack data is cleared, and the attack IP address and the data packet data are recorded to form an interception log;

[0027] If the interception fails, the host control module is immediately started to control the attack transfer module, and the data in the host control module is simultaneously backed up.

[0028] 3. Advantage

[0029] Compared with the prior art, the application has the following advantages:

[0030] (1), the address of the host can be transferred through the cloud virtual machine, so that the attack data attacks the cloud virtual machine to provide time support for the reaction backup of the host, improve the security effect, and the reverse attack in the cloud virtual machine can attack the attack party, and the powerful computing power of the cloud computer can saturate the attack party, and the effect of attack instead of defense is achieved.

[0031] (2), the high-speed solid state disk is electrically connected and stored, which is convenient to take, the high-speed interface can quickly backup and save the backup time, the 5G can perform high-speed five wireless cloud backup, which is convenient and fast.

[0032] (3), this scheme is through the firewall control and adjustment of traffic, to block data attack effect, avoid attack again.

[0033] (4), this scheme through the connection between the system modules, can be in the preset attack is very strong and can not withstand when let attack diversion, give the main character backup file and delete file time, the last line of defense on the host. BRIEF DESCRIPTION OF DRAWINGS

[0034] Figure 1 for the overall structure of the system of the present application schematic diagram;

[0035] Figure 2 for the attack detection module of the present application running schematic diagram;

[0036] Figure 3 for the flow detection module of the present application running schematic diagram;

[0037] Figure 4 for the data packet detection module of the present application running schematic diagram;

[0038] Figure 5 for the time detection module of the present application running schematic diagram;

[0039] Figure 6 for the firewall module of the present application running schematic diagram;

[0040] Figure 7 for the attack transfer module of the present application running schematic diagram;

[0041] Mark the explanation of the figure:

[0042] 1, host control module;2, attack detection module;3, data receiving module;4, data backup module / 5, firewall module;6, attack transfer module. DETAILED DESCRIPTION

[0043] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application;Obviously, the described embodiments are only part of the embodiments of the present application, not all the embodiments;Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0044] Embodiment:

[0045] Please refer to Figure 1The system for detecting DDoS attack comprises a host control module 1, a receiving end of the host control module 1 is electrically connected with an attack detection module 2, a receiving end of the attack detection module 2 is electrically connected with a data receiving module 3, the host control module 1 is connected with an attack transfer module 6 through a wireless network, an output end of the host control module 1 is connected with a data backup module 4 through an M.2 interface or 5G, the host control module 1 is built-in with a firewall module 5, and the attack transfer module 6 is a cloud virtual machine module. Through the connection and cooperation between the system modules, the attack can be transferred when the preset attack is strong and cannot be resisted, the time for the host to back up files and delete files is provided, and the last safety device of the host is provided.

[0046] Specifically, when the system works, when data transmission is performed, the data packet on the network is transmitted to the host control module 1 through a wireless or wired mode, and is received through an interface of the data receiving module 3 in advance, the data receiving module 3 receives the information transmitted to the attack detection module 2 through a wire, the attack detection module 2 detects the data through a contained flow detection module and a data packet detection module in the first step, starts the firewall module 5 when the data is attack data, the firewall module 5 blocks the received data packet to avoid the data packet continuing to attack through the regulation and limitation or flow interruption of the data packet flow, if the first step detection is not attack, the ip address and time of the data packet are further monitored and detected through an ip address detection module and a time detection module, if different ips simultaneously send multiple same data packets, an alarm is performed, or the same data packets are sent at the same time frequency, an alarm is also performed, if not, no alarm is performed, when the firewall module 5 is detected and started, the attack is not reduced but increased, and when the attack cannot be recovered, the last safety device emergency plan is started, the attack transfer module 6 is started, the ip address, the Mac address, the user name and the use behavior of the host are simulated through the cloud virtual machine, and the corresponding configuration table of the host is modified, such as the time, the date, the ip address, the Mac address and the user name, so that the attacker shifts the attack direction, the host backs up the data in this time, and deletes the original data, at this time, the cloud virtual machine collects the data characteristics of the attack, collects the data flow information to form a counterattack database and starts AI learning, after the learning, the counterattack plan is performed, at this time, the attacker can be counterattacked according to the situation.

[0047] Please refer to Figures 2-6 The method for detecting DDoS attack comprises the following steps.

[0048] S2: After the attack detection module 2 detects to determine whether the received data packet is a DDoS attack mode, the attack detection module 2 includes a flow detection module and a data packet detection module to detect data packets and flows;

[0049] If it is determined to be a DDoS attack mode, the firewall module 5 is started to intercept the attack;

[0050] If the time period detection is not determined to be a DDoS attack mode, the host is normally used, but the time detection module in the attack detection module 2 is used for time monitoring, and if it is found that the data packet is sent at a certain rhythm and frequency during the monitoring time period, the ip address detection module in the attack detection module 2 is started to detect the ip address of the data sending end;

[0051] If it is detected in the time period detection that the data packet is sent at a certain rhythm and frequency, and different ip addresses are used for simultaneous sending, it is determined to be a DDoS attack;

[0052] S3: After determining the attack, the firewall module 5 is started to adjust the data flow, the flow is controlled and adjusted through the firewall, the effect of blocking data attack is achieved, and re-attack is avoided;

[0053] S4: After the attack transfer module 6 is started, the ip address and MAC address of the host are simulated through the cloud virtual machine module, and the ip address, MAC address and time of the host are temporarily modified, so that the DDoS attack cannot search for the host and attacks the cloud virtual machine module instead;

[0054] S5: After the cloud virtual machine module is attacked, the feature collection module, flow collection module and reverse attack module built-in the cloud virtual machine module are started to collect DDoS attack features, and the data flow name is recorded and collected to form a pre-attack database.

[0055] S6: Attack data packets are formed through the collected pre-attack database, and the reverse attack module is started to perform reverse attack on the ip address of the attack according to the situation.

[0056] Please refer to Figure 4 , the data packet detection method includes data packet name recording and data packet quantity recording, and a simple screening is performed on whether the data packet quantity is normal and whether the data packet name is repeated.

[0057] Please refer to Figure 5 , the time detection method includes a total transmission time table and a single data packet time table, the start time and end time of a single data packet and total data packets are recorded, and the transmission time frequency of a single data packet is recorded.

[0058] Please refer toFigure 3 The method for flow detection comprises: determining whether it is an attack behavior according to name and flow comparison of data in a data packet database with attack data; the data packet database mode can be obtained from a network security database of a network antivirus software such as Tencent security manager or 360 security guard.

[0059] Please refer to Figure 1 The method for data backup comprises: cloud data backup and high-speed solid state disk backup; the cloud data backup comprises: data transmission through 5G or 10G optical fiber; the high-speed solid state disk backup comprises: high-speed transmission through an M.2 interface and a PCI-E 3.0x4 channel; electrical connection storage through the high-speed solid state disk is convenient to take, and quick backup through the high-speed interface saves backup time, and high-speed five-wire cloud backup through the set 5G is convenient and fast.

[0060] Please refer to Figure 6 The method for data flow regulation comprises: limiting or cutting off the transmitted data flow packet flow, so as to stop the determined attack data; if the interception is successful, the attack data is cleared, and the attack IP address and data packet data are recorded to form an interception log; if the interception fails, the control attack transfer module 6 is started immediately through the host control module 1, and the data information in the host control module 1 is backed up at the same time; the address of the host can be transferred through the cloud virtual machine, so that the attack data attacks the cloud virtual machine to provide time support for the reaction backup of the host, improve the safety effect, and the reverse attack in the cloud virtual machine can attack the attack party, the powerful computing power of the cloud computer is used to saturate the attack party, and the effect of attack instead of defense is achieved.

[0061] The above is only a preferred specific embodiment of the present application; however, the protection scope of the present application is not limited thereto. Any skilled person in the art can make equivalent replacement or change according to the technical solution and the improvement concept of the present application within the technical range disclosed by the present application, which should be covered in the protection scope of the present application.

Claims

1. A method of DDoS attack detection, characterized by: The application relates to a system for detecting DDoS attacks, wherein the DDoS attack detection system comprises a host control module (1), the receiving end of the host control module (1) is electrically connected with an attack detection module (2), the receiving end of the attack detection module (2) is electrically connected with a data receiving module (3), the host control module (1) is connected with an attack transfer module (6) through a wireless network, the output end of the host control module (1) is connected with a data backup module (4) through an M.2 interface or a 5G, the host control module (1) is internally provided with a firewall module (5), and the attack transfer module (6) is a cloud virtual machine module. The execution of a DDoS attack detection method comprises the following steps: S1: receiving data packets on a network through the data receiving module (3) and detecting the received data through the attack detection module (2); S2: determining whether the received data packets are in a DDoS attack mode through the attack detection module (2), wherein the attack detection module (2) comprises a flow detection module and a data packet detection module for detecting data packets and flow; A time detection module in the attack detection module (2) performs time monitoring, and if it is found that data packets are sent at a certain rhythm and frequency in a monitoring time period, an ip address detection module in the attack detection module (2) is started to detect the ip address of a data sending end; If it is detected in the time period detection that data packets are sent at a certain rhythm and frequency and simultaneously sent by using different ip addresses, it is determined that the data packets are in a DDoS attack mode; if it is determined that the data packets are in a DDoS attack mode, the firewall module (5) is started to intercept the attack; S3: after determining the DDoS attack mode, the firewall module (5) is started to adjust data flow; the attack is intercepted, and the data flow adjustment method comprises limiting the sent data flow packets or cutting off the sent data flow packets, so that the determined attack data is prevented; If the interception is successful, the attack data is cleaned, and the attack ip address and data packet data are recorded to form an interception log; If the interception fails, the host control module (1) is immediately controlled to start the attack transfer module (6), and meanwhile, data materials in the host control module (1) are backed up; S4: after the attack transfer module (6) is started, the ip address and MAC address of the host are simulated through a cloud virtual machine module, and the ip address, MAC address and time of the host are temporarily modified, so that the DDoS attack cannot search for the host but attacks the cloud virtual machine module; S5: after the cloud virtual machine module is attacked, a feature collection module, a flow collection module and a reverse attack module built in the cloud virtual machine module are started to collect DDoS attack features and record and collect data flow names to form a pre-attack database. S6: Forming attack data packet through the collected pre-attack database, and then starting the reverse attack module to perform reverse attack on the ip address of the attack as appropriate.

2. The method of DDoS attack detection of claim 1, wherein: The detection module of the data packet detects whether the data packet quantity is normal and whether the data packet name is repeated based on the data packet name record and the data packet quantity record.

3. The method of DDoS attack detection of claim 1, wherein: The time detection module records the start time and end time of the single data packet and the total data packet based on the total transmission time table and the single data packet time table, and records the transmission time frequency of the single data packet.

4. The method of DDoS attack detection of claim 1, wherein: The flow detection module compares the name and flow of the data in the data packet database with the attack data to determine whether it is an attack behavior.

5. The method of DDoS attack detection of claim 4, wherein: The data packet database can be obtained from the network security database of Tencent Security Manager and 360 Security Guard network antivirus software.

6. The method of DDoS attack detection of claim 1, wherein: The data backup method includes cloud data backup and high-speed solid state disk backup.

7. The method of DDoS attack detection of claim 6, wherein: The cloud data backup includes data transmission through 5G or gigabit optical fiber; The high-speed solid state disk backup includes high-speed transmission through the M.2 interface with PCI-E3.0x4 channel.

Citation Information

Patent Citations

  • Network security protection method, device and storage medium

    CN107426242A