Network attack positioning method and device, and storage medium

By analyzing the router information table in the communication system, the source router of the attack can be identified and directed for location, thus solving the problem of difficult identification of DDoS attack traffic and achieving accurate location of the attacking host.

CN116599738BActive Publication Date: 2025-12-05CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310611192.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-26
Publication Date
2025-12-05
Estimated Expiration
2043-05-26

AI Technical Summary

Technical Problem

Existing technologies struggle to effectively distinguish between legitimate data packets and DDoS attack traffic, making it difficult for hosts to pinpoint the source of a network attack.

Method used

By receiving and analyzing information tables in the routers of the communication system, routers that forward more than a threshold of target data packets are identified as attack sources, and indication information is sent to the target routers for location.

Benefits of technology

It enables precise location of the host launching the network attack, solving the problem of identifying DDoS attack traffic.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116599738B_ABST
    Figure CN116599738B_ABST
Patent Text Reader

Abstract

The application provides a network attack positioning method and device and a storage medium, relates to the technical field of communication, and can position a host initiating a network attack. The method comprises the following steps: receiving a first information table from a second router; the first information table comprises the routing identifier of at least one third router and the IP address of a target data packet; the first terminal is a terminal with a resource utilization rate greater than a first preset threshold value and an access quantity greater than a second preset threshold value; determining that the third router in the first information table forwarding the target data packet in a quantity greater than a third preset threshold value is a target router; and sending first indication information to the target router; the first indication information is used for instructing the target router to position a second terminal attacking the first terminal; and the second terminal is a terminal connected with the target router.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of communication technology, and in particular to a network attack positioning method and device and storage medium. BACKGROUND

[0002] At present, a distributed denial of service (DDOS) attack is launched on other hosts by constructing data packets identical to those of legitimate users. This makes it impossible for a host to determine whether the received traffic is hot spot traffic or attack traffic when detecting that the resource utilization and access volume of the host exceed a certain threshold. As a result, it is difficult for the host to locate the attack traffic when the host is subjected to a network attack. Therefore, how to locate the host initiating the network attack becomes a technical problem to be solved. SUMMARY

[0003] The present application provides a network attack positioning method, device and storage medium, which can locate the host initiating the network attack.

[0004] To achieve the above object, the present application adopts the following technical solutions:

[0005] In a first aspect, a network attack positioning method is provided, which is applied to a first router in a communication system. The communication system includes the first router, a second router and a third router. The first router is any router in the communication system. The second router is a router connected to a first terminal to be positioned for a network attack. The third router is a router forwarding a target data packet. The destination Internet Protocol (IP) address of the target data packet is the IP address of the first terminal. The method includes: receiving a first information table from the second router; the first information table includes the routing identifier of at least one third router and the IP address of the target data packet; the destination IP address of the target data packet is the IP address of the first terminal; the first terminal is a terminal with a resource utilization greater than a first preset threshold and an access volume greater than a second preset threshold; determining that the third router forwarding the target data packet in the first information table and having a quantity greater than a third preset threshold is a target router; sending first indication information to the target router; the first indication information is used to instruct the target router to locate a second terminal attacking the first terminal; and the second terminal is a terminal connected to the target router.

[0006] With the first aspect above, in a possible implementation, the third router whose quantity of the target data packets is greater than the third preset threshold in the first information table is determined as the target router, including: receiving second indication information from the second router, the second indication information being indication information generated by the second router when resource utilization of the first terminal is greater than a fourth preset threshold and access quantity is greater than a fifth preset threshold; and determining, in response to the second indication information, the target router whose quantity of the target data packets is greater than the third preset threshold from the first information table.

[0007] In a second aspect, a network attack positioning method is provided, applied to a second router in a communication system, the communication system including a first router, the second router and a third router, the first router being any router in the communication system, the second router being a router connected with a first terminal to be positioned for network attack, and the third router being a router forwarding target data packets, the target data packets having a destination IP address being an IP address of the first terminal; the method including: receiving third indication information sent by the first terminal; the third indication information being used to represent that resource utilization of the first terminal is greater than a first preset threshold and access quantity is greater than a second preset threshold; generating a first information table in response to the third indication information; the first information table including: routing identification of at least one third router and IP address of the target data packets; and sending the first information table to at least one first router.

[0008] With the second aspect above, in a possible implementation, after the first information table is sent to at least one first router, the method further includes: receiving fourth indication information sent by the first terminal; the fourth indication information being indication information generated by the first terminal when resource utilization of the first terminal is greater than a fourth preset threshold and access quantity is greater than a fifth preset threshold; and sending second indication information to at least one first router in response to the fourth indication information. The second indication information is used to instruct the first router to position the target router.

[0009] In a third aspect, a network attack positioning method is provided, which is applied to a target router. The target router is a third router that forwards a number of target data packets greater than a third preset threshold. The third router is a router in a communication system. The communication system includes a first router, a second router, and the third router. The first router is any router in the communication system. The second router is a router connected to a first terminal to be positioned for a network attack. The third router is a router that forwards target data packets. The target data packets have a destination IP address of the IP address of the first terminal. The method includes receiving first indication information sent by the first router. The first indication information is used to instruct the target router to position a second terminal that attacks the first terminal. The second terminal is a terminal connected to the target router. In response to the first indication information, an access control list (ACL) is generated. The ACL is used to control the forwarding of target data packets sent by the second terminal. The forwarding of the target data packets sent by the second terminal is controlled according to the ACL.

[0010] In a fourth aspect, a network attack positioning apparatus is provided, which is applied to a first router in a communication system. The communication system includes the first router, a second router, and a third router. The first router is any router in the communication system. The second router is a router connected to a first terminal to be positioned for a network attack. The third router is a router that forwards target data packets. The target data packets have a destination IP address of the IP address of the first terminal. The apparatus includes a processing unit and a communication unit. The communication unit is configured to receive a first information table from the second router. The first information table includes the routing identifier of at least one third router and the IP address of the target data packets. The first terminal is a terminal with a resource utilization rate greater than a first preset threshold and an access quantity greater than a second preset threshold. The processing unit is configured to determine that the third router that forwards the target data packets in the first information table and has a number greater than a third preset threshold is a target router. The communication unit is further configured to send first indication information to the target router. The first indication information is used to instruct the target router to position a second terminal that attacks the first terminal. The second terminal is a terminal connected to the target router.

[0011] In combination with the fourth aspect described above, in a possible implementation, the processing unit is further configured to instruct the communication unit to receive second indication information from the second router. The second indication information is indication information generated by the second router when the resource utilization rate of the first terminal is greater than a fourth preset threshold and the access quantity is greater than a fifth preset threshold. In response to the second indication information, the target router that forwards the target data packets and has a number greater than the third preset threshold is determined from the first information table.

[0012] In a fifth aspect, a network attack positioning apparatus is provided, which is applied to a second router in a communication system, the communication system comprising the second router, a first router and a third router, the first router being any router in the communication system, the second router being a router connected with a first terminal to be positioned in a network attack, and the third router being a router forwarding a target data packet, the target data packet having a destination IP address being an IP address of the first terminal; the apparatus comprising: a processing unit and a communication unit; the communication unit is configured to receive third indication information sent by the first terminal; the first terminal being a terminal with a resource utilization rate greater than a first preset threshold and an access quantity greater than a second preset threshold; the third indication information being used to indicate that the resource utilization rate of the first terminal is greater than the first preset threshold and the access quantity is greater than the second preset threshold; the processing unit is configured to generate a first information table in response to the third indication information; the first information table comprising: a routing identifier of at least one third router and an IP address of the target data packet; and the communication unit is further configured to send the first information table to at least one first router.

[0013] In combination with the fifth aspect, in a possible implementation manner, the processing unit is further configured to: instruct the communication unit to receive fourth indication information sent by the first terminal; the fourth indication information being indication information generated when the resource utilization rate of the first terminal is greater than a fourth preset threshold and the access quantity is greater than a fifth preset threshold; and in response to the fourth indication information, instruct the communication unit to send second indication information to at least one first router; the second indication information being used to instruct the first router to position the target router.

[0014] In a sixth aspect, a network attack positioning apparatus is provided, which is applied to a target router, the target router being a third router forwarding a target data packet in a communication system, the third router being a router in the communication system; the communication system comprising the third router, a first router and a second router, the first router being any router in the communication system, the second router being a router connected with a first terminal to be positioned in a network attack, and the third router being a router forwarding a target data packet, the target data packet having a destination IP address being an IP address of the first terminal; the apparatus comprising: a processing unit and a communication unit; the communication unit is configured to receive first indication information sent by the first router; the first indication information being used to instruct the target router to position a second terminal attacking the first terminal; the second terminal being a terminal connected with the target router; the processing unit is configured to generate an access control list (ACL) in response to the first indication information; the access control list (ACL) being used to control forwarding of a target data packet sent by the second terminal; and the processing unit is further configured to control forwarding of the target data packet sent by the second terminal according to the access control list (ACL).

[0015] In a seventh aspect, the present application provides a network attack positioning apparatus, comprising: a processor and a memory; wherein the memory is configured to store computer-executable instructions, and when the network attack positioning apparatus is running, the processor executes the computer-executable instructions stored in the memory, so that the network attack positioning apparatus performs the network attack positioning method described in the first aspect and any possible implementation manner of the first aspect.

[0016] In an eighth aspect, the present application provides a network attack positioning apparatus, comprising: a processor and a memory; wherein the memory is configured to store computer-executable instructions, and when the network attack positioning apparatus is running, the processor executes the computer-executable instructions stored in the memory, so that the network attack positioning apparatus performs the network attack positioning method described in the second aspect and any possible implementation manner of the second aspect.

[0017] In a ninth aspect, the present application provides a network attack positioning apparatus, comprising: a processor and a memory; wherein the memory is configured to store computer-executable instructions, and when the network attack positioning apparatus is running, the processor executes the computer-executable instructions stored in the memory, so that the network attack positioning apparatus performs the network attack positioning method described in the third aspect and any possible implementation manner of the third aspect.

[0018] In a tenth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, and when the instructions in the computer-readable storage medium are executed by a processor of a network attack positioning apparatus, the network attack positioning apparatus can perform the network attack positioning method described in the first aspect and any possible implementation manner of the first aspect.

[0019] In an eleventh aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, and when the instructions in the computer-readable storage medium are executed by a processor of a network attack positioning apparatus, the network attack positioning apparatus can perform the network attack positioning method described in the second aspect and any possible implementation manner of the second aspect.

[0020] In a twelfth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores instructions, and when the instructions in the computer-readable storage medium are executed by a processor of a network attack positioning apparatus, the network attack positioning apparatus can perform the network attack positioning method described in the third aspect and any possible implementation manner of the third aspect.

[0021] In a thirteenth aspect, the present application provides a computer program product comprising instructions which, when the computer program product is executed on a network attack positioning apparatus, cause the network attack positioning apparatus to carry out the network attack positioning method as described in the first aspect and any possible implementation manner of the first aspect.

[0022] In a fourteenth aspect, the present application provides a computer program product comprising instructions which, when the computer program product is executed on a network attack positioning apparatus, cause the network attack positioning apparatus to carry out the network attack positioning method as described in the second aspect and any possible implementation manner of the second aspect.

[0023] In a fifteenth aspect, the present application provides a computer program product comprising instructions which, when the computer program product is executed on a network attack positioning apparatus, cause the network attack positioning apparatus to carry out the network attack positioning method as described in the third aspect and any possible implementation manner of the third aspect.

[0024] In a sixteenth aspect, the present application provides a chip, which comprises a processor and a communication interface, the communication interface and the processor are coupled, and the processor is configured to execute a computer program or instructions to implement the network attack positioning method as described in the first aspect and any possible implementation manner of the first aspect.

[0025] In a seventeenth aspect, the present application provides a chip, which comprises a processor and a communication interface, the communication interface and the processor are coupled, and the processor is configured to execute a computer program or instructions to implement the network attack positioning method as described in the second aspect and any possible implementation manner of the second aspect.

[0026] In an eighteenth aspect, the present application provides a chip, which comprises a processor and a communication interface, the communication interface and the processor are coupled, and the processor is configured to execute a computer program or instructions to implement the network attack positioning method as described in the third aspect and any possible implementation manner of the third aspect.

[0027] Specifically, the chip provided in the embodiments of the present application further comprises a memory for storing the computer program or instructions.

[0028] In the present application, the name of the network attack positioning apparatus does not constitute a limitation on the device or functional module itself, and in actual implementation, these devices or functional modules can appear with other names. As long as the functions of each device or functional module are similar to those of the present application, they belong to the scope of the claims of the present application and equivalent technologies.

[0029] These aspects or other aspects of the present application will be more apparent in the following description.

[0030] The technical solutions provided by the present application at least have the following beneficial effects:

[0031] The application provides a network attack positioning method applied to a network attack positioning device in a communication system. The communication system comprises a first router, a second router and a third router, the first router is any router in the communication system, the second router is a router connected with a first terminal to be positioned in a network attack, and the third router is a router forwarding a target data packet, and a destination IP address of the target data packet is an IP address of the first terminal. The network attack positioning method is that the first router receives a first information table sent by the second router, and records information of the target data packet with the destination address being the first terminal according to the first information table. The first router determines whether the third router forwarding the target data packet with the number of the target data packet being greater than a third preset threshold value is a target router forwarding an attack packet in the first information table according to the first information table. The first router sends first indication information to the target router, and instructs the target router to position a second terminal sending the attack packet. In this way, the network attack positioning device determines the target router forwarding the attack packet according to the information of the target data packet in the first information table. Further, the target router positions the terminal sending the attack packet according to the received indication information, so that the technical problem of positioning a host machine sending a network attack is solved. BRIEF DESCRIPTION OF DRAWINGS

[0032] Figure 1 A communication system schematic diagram provided by the embodiment of the application;

[0033] Figure 2 A hardware structure schematic diagram of the network attack positioning device provided by the embodiment of the application;

[0034] Figure 3 A flowchart of the network attack positioning method provided by the embodiment of the application;

[0035] Figure 4 Another flowchart of the network attack positioning method provided by the embodiment of the application;

[0036] Figure 5 Another flowchart of the network attack positioning method provided by the embodiment of the application;

[0037] Figure 6 Another flowchart of the network attack positioning method provided by the embodiment of the application;

[0038] Figure 7 A structure schematic diagram of the network attack positioning device applied to the first router in the communication system provided by the embodiment of the application;

[0039] Figure 8A structural diagram of a network attack positioning apparatus applied to a second router in a communication system is provided in the embodiments of the present application.

[0040] Figure 9 A structural diagram of a network attack positioning apparatus applied to a target router in a communication system is provided in the embodiments of the present application. DETAILED DESCRIPTION

[0041] The network attack positioning method, apparatus and storage medium provided in the embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0042] The term "and / or" in the present document is merely used to describe an association relationship of associated objects, and indicates that three relationships can exist, for example, A and / or B can represent three cases of existence of A alone, existence of A and B simultaneously, and existence of B alone.

[0043] The terms "first" and "second" and the like in the description of the present application and the accompanying drawings are used to distinguish different objects or different processing of the same object, and are not used to describe a specific order of the objects.

[0044] In addition, the terms "comprising" and "having" and any variations thereof in the description of the present application are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can optionally further include other steps or units not listed, or can optionally further include other steps or units inherent to the process, method, product or device.

[0045] It should be noted that in the embodiments of the present application, the words "exemplary" or "for example" are used to mean serving as an example, instance, or illustration. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or advantageous than other embodiments or design schemes. Rather, the use of the words "exemplary" or "for example" is intended to present the relevant concept in a specific manner.

[0046] In the related art, a DDOS attack is launched by constructing a large number of IP addresses and attack messages, using a host or remotely logging into a host of another person to attack a target host. The target host under attack cannot reply to all the received data messages because the target host receives a large number of data messages in a short time, and the resource utilization of the target host exceeds a threshold. This makes the target host under attack unable to provide services to the public. Since the attack messages constructed by the DDOS attack are the same as the legal data messages, the target host under attack and the firewall connected to the target host cannot effectively distinguish the attack messages from the legal data messages. When the target host is attacked, the devices such as the egress gateway, the egress router, and the firewall deployed by the target host cannot effectively clean the data traffic received by the target host.

[0047] Currently, when a host detects that the resource utilization and the access amount of the host exceed a certain threshold, since the DDOS attack launches an attack on other hosts by constructing data messages that are the same as the data messages sent by legal users, the host under attack cannot determine whether the received data messages are hot spot traffic or attack traffic, and thus it is difficult for the host under attack to locate the attack traffic when the host under attack is attacked.

[0048] Therefore, how to locate the host that launches a network attack becomes a technical problem to be solved.

[0049] In order to locate the host that launches a network attack, the present application provides a network attack locating method applied to a network attack locating device in a communication system. The communication system includes a first router, a second router, and a third router. The first router is any router in the communication system. The second router is a router connected to a first terminal to be located for a network attack. The third router is a router forwarding a target data message. The destination IP address of the target data message is the IP address of the first terminal. The network attack locating method is that the first router receives a first information table sent by the second router, and records information of the target data message with the destination address being the first terminal according to the first information table. The first router determines, through the first information table, whether there is a third router forwarding a target data message with the number of forwarded target data messages being greater than a third preset threshold in the first information table, and the third router is a target router forwarding an attack message. The first router sends first indication information to the target router, and instructs the target router to locate a second terminal sending the attack message. In this way, the network attack locating device determines the target router forwarding the attack message through the information of the target data message in the first information table. Further, the target router locates the terminal launching the attack message according to the received indication information. Thus, the technical problem of locating the host launching a network attack is solved.

[0050] The network attack locating method can be applied to, for example,Figure 1 In the communication system shown, the following is combined Figure 1 The communication system 10 provided in the embodiments of this application will be described in detail. For example... Figure 1 As shown, the communication system 10 includes: a first terminal 101, a routing device 102, and a second terminal 103. The routing device 102 includes: a second router 1021, a first router 1022, a first router 1023, a third router 1024, a first router 1025, and a first router 1026. It should be noted that the first terminal is the terminal being attacked; the second terminal is the terminal initiating the attack; the first router is any router in the communication system; the second router is the router connected to the first terminal to be located in the network attack; the third router is the router forwarding the target data packets; and the destination IP address of the target data packets is the IP address of the first terminal. The first router receives a first information table sent from the second router and records information about target data packets with the destination address of the first terminal according to the first information table. The first router uses the first information table to determine whether there exists a third router in the first information table whose number of forwarded target data packets exceeds a third preset threshold, thus being the target router forwarding the attack packets. The first router sends a first indication message to the target router, instructing the target router to locate the second terminal that sent the attack packets. In this way, the network attack location device determines the target router forwarding the attack packet by analyzing the information in the target data packet in the first information table. Furthermore, the target router locates the terminal that initiated the attack packet based on the received indication information. This solves the technical problem of locating the host that initiated the network attack.

[0051] This application also provides a network attack locating device, which can be applied to... Figure 1 The communication system shown includes a first router, a second router, and a third router. The first router, the second router, and the third router implement the functions required for network attack localization, such as... Figure 2 The diagram shows the basic hardware structure for locating network attacks provided in an embodiment of this application.

[0052] like Figure 2 As shown, the network attack location device 200 includes at least one processor 201, a communication line 202, and at least one communication interface 204, and may also include a memory 203. The processor 201, memory 203, and communication interface 204 can be connected via the communication line 202.

[0053] The processor 201 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to perform the operations of the embodiments of the present application, such as one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0054] The communication line 202 can include a path for transmitting information between the components described above.

[0055] The communication interface 204, which is configured to communicate with other devices or communication networks, can use any transceiver device, such as an Ethernet, a radio access network (RAN), a wireless local area network (WLAN), and the like.

[0056] The memory 203 can be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disk storage, a magnetic disk storage or other magnetic storage devices, or any other medium capable of storing desired program code in the form of instructions or data structures and that can be accessed by a computer, but is not limited thereto.

[0057] In one possible design, the memory 203 can exist independently of the processor 201, meaning the memory 203 can be an external memory of the processor 201. In this case, the memory 203 can be connected to the processor 201 via the communication line 202 to store execution instructions or application code, and its execution is controlled by the processor 201 to implement the space measurement determination method provided in the following embodiments of this application. In another possible design, the memory 203 can also be integrated with the processor 201, meaning the memory 203 can be an internal memory of the processor 201. For example, the memory 203 can be a cache, which can be used to temporarily store some data and instruction information.

[0058] As one possible implementation, processor 201 may include one or more CPUs, for example Figure 2 CPU0 and CPU1 in the example. Alternatively, the network attack location device 200 may include multiple processors, such as CPU0 and CPU1. Figure 2 The processors 201 and 207 are included. Alternatively, the network attack location device 200 may also include an output device 205 and an input device 206.

[0059] Through the above description of the implementation methods, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the network node can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, modules, and network nodes described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0060] The network attack location method provided in this application embodiment can be applied to, for example, Figure 1 In the communication system shown, such as Figure 3 As shown, the network attack location method provided in this application embodiment can be implemented through the following steps 301 to 303.

[0061] Step 301: The second router sends the first information table to the first router. Correspondingly, the first router receives the first information table from the second router.

[0062] The first information table includes: the routing identifier of at least one third router and the IP address of the target data packet; the destination IP address of the target data packet is the IP address of the first terminal; the third router is the router that forwards the target data packet; the first terminal is a terminal whose resource utilization rate is greater than a first preset threshold and whose access quantity is greater than a second preset threshold; and the second router is the router connected to the first terminal.

[0063] In a possible implementation, the second router sends the first information table to the at least one first router by broadcasting a message. Correspondingly, the first router in the communication system saves the first information table after receiving the first information table. When the first router detects a target data message with the first terminal as the destination address, the first router extracts relevant data of the target data message and stores the extracted relevant data in the first information table.

[0064] An example, as shown in Table 1, the first information table can refer to, but is not limited to, the following storage format:

[0065] Table 1

[0066]

[0067]

[0068] It should be noted that, as shown in Table 1, the first router can accurately locate the router forwarding the attack data message by Table 1.

[0069] Optionally, as shown in Table 2, the storage format of the first information table can also refer to the following storage format.

[0070] Table 2

[0071]

[0072] Specifically, the information extracted by the first router from the target data message is as follows: the IP address of the first terminal is 123*.1*.1*.3, the source IP address of the target data message is 192*.12*.13*.1, the source MAC address of the target data message is 51*:8a*:5h*:55*:dg*:6j*, the terminal identifier sending the target data message is A, the router identifier forwarding the target data message is Router-A, and the IP address of the identifier of the router forwarding the target data message is 193*.1*.2*.6*.

[0073] Further, the format of the target data message extracted by the first router and stored in the first information table can refer to Table 3 as follows:

[0074] Table 3

[0075]

[0076] It should be noted that when the second router sends the first information table to the first router in the communication system by broadcasting, the destination address of the broadcast can be set as 255*.255*.255*.255*. In addition, after receiving the first information table, the first router still broadcasts the first information table to other routers connected to the first router by broadcasting. It should be noted that, in order to prevent the first information table from being circulated, the router only forwards the first information table from ports other than the receiving port when broadcasting the first information table.

[0077] In step 302, the first router determines that the third router whose number of forwarded target data packets is greater than the third preset threshold is the target router in the first information table.

[0078] In a possible implementation, when the terminal detects that the resource utilization and the access amount of the terminal exceed a certain preset threshold, the first router determines, according to the forwarding record of the target data packet in the saved first information table, whether there is a router whose number of forwarded target data packets is greater than a third preset threshold in the first information table. The third preset threshold can be set as 70%. If there is no router whose number of forwarded target data packets is greater than the third preset threshold, the first router determines that the reason why the resource utilization and the access amount of the terminal exceed the certain preset threshold is caused by the hotspot traffic of the access terminal. If there is a router whose number of forwarded target data packets is greater than the third preset threshold, the first router determines that the router whose number of forwarded target data packets is greater than the third preset threshold is the target router.

[0079] In step 303, the first router sends first indication information to the target router. Correspondingly, the target router receives the first indication information sent by the first router.

[0080] The first indication information is used to instruct the target router to locate the second terminal that attacks the first terminal, and the second terminal is a terminal connected to the target router.

[0081] In a possible implementation, the first router sends the first indication information to the target router whose number of forwarded target data packets is greater than the third preset threshold, to instruct the target router to locate the second terminal that attacks the first terminal. Correspondingly, after receiving the first indication information sent by the first router, the target router locates the second terminal that attacks the first terminal according to the first indication information.

[0082] In an example, the first indication information sent by the first terminal to the target router includes, but is not limited to, the source IP address, the source Media Access Control (MAC) address of the second terminal, and the identifier of the second terminal, and the like. Correspondingly, after receiving the first indication information, the target router records the source IP address, the source MAC address of each data packet forwarded in real time, and the identifier of the terminal sending the data packet according to the second terminal included in the first indication information. Further, the target router accurately locates the second terminal attacking the first terminal according to the recorded information of the data packet.

[0083] The above scheme at least has the following beneficial effects: the first router receives the first information table sent by the second router, and records the information of the target data packet with the destination address of the first terminal according to the first information table. The first router determines whether there is a third router forwarding a number of target data packets greater than a third preset threshold in the first information table as a target router forwarding attack packets. The first router sends first indication information to the target router, instructing the target router to locate the second terminal sending the attack packets. In this way, the network attack locating device determines the target router forwarding the attack packets according to the information of the target data packet in the first information table. Further, the target router locates the terminal initiating the attack packets according to the received indication information. Thus, the technical problem of locating the host initiating the network attack is solved.

[0084] In combination Figure 3 As Figure 4 shown, the above step 301 further includes steps 401-402 before the step 301.

[0085] Step 401, the first terminal sends third indication information to the second router. Correspondingly, the second router receives the third indication information sent by the first terminal.

[0086] The third indication information is used to represent that the resource utilization rate of the first terminal is greater than a first preset threshold, and the access quantity is greater than a second preset threshold.

[0087] In a possible implementation, when the first terminal detects that the resource utilization rate is greater than a first preset threshold "N1" and the access quantity is greater than a second preset threshold "H1", the first terminal sends third indication information to the second router, instructing the second router to generate a first information table, and instructing the second router to share the first information table to any first router in the communication system. Correspondingly, after receiving the third indication information sent by the first terminal, the second router generates the first information table according to the instruction of the second router, and shares the first information table to any first router in the communication system.

[0088] In an example, the resource utilization of the first terminal is a sum of a first parameter value, a second parameter value, a third parameter value, and a fourth parameter value; the first parameter value is a product of the CPU utilization and a first coefficient; the second parameter value is a product of the memory occupancy and a second coefficient; the third parameter value is a product of the port flow occupancy and a third coefficient; and the fourth parameter is a product of the target resource and a fourth coefficient.

[0089] Specifically, the resource utilization of the first terminal is denoted as M, and satisfies the following formula:

[0090] M = a*A + b*B + c*C + x*X Formula 1

[0091] wherein A represents the CPU utilization; B represents the memory occupancy; C represents the port flow occupancy; X represents optional other resources; a, b, c, and x represent the weights of A, B, C, and X respectively.

[0092] It should be noted that the value ranges of A, B, C, and X are [0 1]; the value ranges of a, b, c, and x are [1 4], and are integers. The values of a, b, c, and x are set by human beings, and can be the same. The values of A, B, C, and X are determined by detection results.

[0093] In step 402, the second router generates the first information table in response to the third indication information.

[0094] The first information table includes the routing identifier of the at least one third router and the IP address of the target data packet.

[0095] In a possible implementation, the second router generates the first information table with the destination address being the first terminal in response to the third indication information sent by the first terminal. The first information table includes but is not limited to the source IP address and the source MAC address of the target data packet with the destination address being the first terminal, the terminal identifier sending the target data packet, the identifier of the router forwarding the target data packet, and the IP address of the identifier of the router forwarding the target data packet.

[0096] The above scheme has at least the following beneficial effects: when the resource utilization of the first terminal is greater than the first preset threshold and the access volume is greater than the second preset threshold, the first terminal sends third indication information to the second router connected thereto, instructing the second router to generate the first information table. After receiving and generating the first information table, the second router forwards the first information table to at least one first router. The first router is any router in the communication system. In this way, when the first terminal detects that the resource utilization and the access volume are greater than the first threshold, the first terminal instructs the router connected thereto to generate the first information table, so that the network attack positioning device can accurately locate the second terminal attacking the first terminal.

[0097] In combination Figure 3 As shown in Figure 5 The step 302 can also be implemented by the following steps 501-503.

[0098] In step 501, the first terminal sends fourth indication information to the second router. Correspondingly, the second router receives the fourth indication information sent by the first terminal.

[0099] The fourth indication information is indication information generated when the resource utilization of the first terminal is greater than a fourth preset threshold and the access volume is greater than a fifth preset threshold.

[0100] In a possible implementation, when the first terminal detects that the resource utilization M of the first terminal is greater than a fourth preset threshold "N2" and the access volume H is greater than a fifth preset threshold "H2", the first terminal sends fourth indication information to the second terminal, instructing the second router to determine whether the attack traffic is received by the first terminal. Correspondingly, the second router receives the fourth indication information sent by the first terminal and performs the following step 502.

[0101] An example is shown in Figure 1 When the first terminal detects that the resource utilization M is greater than N2 and the access volume H is greater than H2, the first terminal sends fourth indication information to the routing device 1021 connected thereto to determine whether the received traffic is hotspot traffic or attack traffic.

[0102] In step 502, the second router sends second indication information to at least one first router in response to the fourth indication information. Correspondingly, the first router receives the second indication information sent by the second router.

[0103] The second indication information is indication information generated by the second router when the resource utilization of the first terminal is greater than the fourth preset threshold and the access volume is greater than the fifth preset threshold, and is used to instruct the first router to locate the target router.

[0104] In one possible implementation, in response to the fourth indication information, the second router broadcasts a second indication information to at least one first router to confirm whether the first terminal is receiving hotspot traffic or attack traffic. Correspondingly, the first router receives the second indication information from the second router. The first router determines whether the first terminal is receiving hotspot traffic or attack traffic based on the received second indication information. If the first terminal is receiving attack traffic, the first router locates the target router forwarding the attack traffic.

[0105] Step 503: The first router responds to the second indication information and determines from the first information table the target router whose number of forwarded target data packets is greater than the third preset threshold.

[0106] In one possible implementation, in response to the second indication information, the first router determines that the traffic received by the first terminal is attack traffic. Then, the first router determines from the first information table that the router whose number of forwarded target data packets exceeds a third preset threshold "P" is the target router for forwarding the attack traffic. The third preset threshold can be set according to actual conditions.

[0107] The above scheme brings at least the following beneficial effects: When the resource utilization of the first terminal exceeds a fourth preset threshold and the access volume exceeds a fifth preset threshold, the first terminal sends a fourth indication message to the second router. In response to the fourth indication message, the second router sends a second indication message to at least one first router. Based on the received second indication message, the first router uses a first information table to determine whether the traffic received by the first terminal is attack traffic or hotspot traffic. If it is attack traffic, the first router, in response to the second indication message, determines from the first information table the target router whose number of forwarded target data packets exceeds a third preset threshold. Thus, when the first terminal detects that its resource utilization exceeds the fourth preset threshold and its access volume exceeds the fifth preset threshold, the first terminal instructs its connected routers to generate a first information table to accurately locate the router forwarding the attack traffic, thereby locating the second terminal attacking the first terminal.

[0108] Combination Figure 3 ,like Figure 6 As shown, the steps 601-602 are included after step 303.

[0109] Step 601: In response to the first indication information, the target router generates an Access Control List (ACL). The ACL is used to control the forwarding of target data packets sent by the second terminal.

[0110] In a possible implementation, the third router, which is a forwarding target of the target data packet exceeding a third preset threshold, locates the second terminal attacking the first terminal in response to the first indication information sent by the first router, and generates an access control list (ACL) according to information such as the source IP address, the destination IP address, the MAC address, and the terminal identifier of the second terminal contained in the first indication information.

[0111] In step 602, the target router controls forwarding of the target data packet sent by the second terminal according to the access control list (ACL).

[0112] In a possible implementation, the third router controls the attack packet sent by the second terminal attacking the first terminal according to the generated access control list (ACL).

[0113] The above scheme at least has the following beneficial effects: the third router locates the second terminal attacking the first terminal according to the first indication information, and generates an access rule table to control the second terminal to continue sending the attack packet to the first terminal. In this way, the attack packet initiated by the target terminal will not be forwarded by the network attack locating apparatus through the access control rule set by the ACL, and the target terminal is further flow blocked.

[0114] The functions of the network attack locating apparatus and each device of the network attack locating apparatus, and the interaction between the devices are described in detail above.

[0115] It can be seen that the technical scheme provided by the embodiments of the present application is mainly introduced from the perspective of the method. In order to realize the above functions, it contains the corresponding hardware structure and / or software module for executing each function. Those skilled in the art should easily realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed in the present application can be realized in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed by hardware or computer software driven hardware depends on the specific application and design constraints of the technical scheme. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0116] The embodiments of the present application can divide the network attack locating apparatus into functional modules according to the above method examples. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing module. The above integrated module can be realized in the form of hardware or software functional module. Optionally, the division of the modules in the embodiments of the present application is illustrative, and is only a logical functional division. When actually implemented, there can be another division manner.

[0117] The embodiments of the present application can divide the functional modules of the network attack positioning device according to the above method examples. For example, each functional module can be divided according to each function, or two or more functions can be integrated in one processing module. The above integrated module can be realized in the form of hardware or in the form of a software functional module. Optionally, the division of the modules in the embodiments of the present application is illustrative, and is only a logical functional division. In actual implementation, another division mode can be used.

[0118] The embodiments of the present application provide a network attack positioning device for performing the method required to be performed by the routers (including the first router, the second router and the third router) in the above communication system. The network attack positioning device can be the router involved in the present application, or a module in the router, or a chip in the router, or other device for performing the network attack positioning method, which is not limited in the present application.

[0119] As shown in Figure 7 FIG. 1 is a structural schematic diagram of a network attack positioning device applied to a first router in a communication system according to an embodiment of the present application. The network attack positioning device comprises a processing unit 701 and a communication unit 702.

[0120] The communication unit 702 is configured to receive a first information table from a second router. The first information table comprises a routing identifier of at least one third router and an IP address of a target data packet. The destination IP address of the target data packet is an IP address of a first terminal. The first terminal is a terminal with a resource utilization rate greater than a first preset threshold value and an access quantity greater than a second preset threshold value. The processing unit 701 is configured to determine that the third router with a quantity of forwarding the target data packet greater than a third preset threshold value in the first information table is a target router. The communication unit 702 is further configured to send first indication information to the target router. The first indication information is used to instruct the target router to locate a second terminal attacking the first terminal. The second terminal is a terminal connected with the target router.

[0121] Optionally, the processing unit 701 is further configured to instruct the communication unit 702 to receive second indication information from the second router. The second indication information is indication information generated by the second router when the resource utilization rate of the first terminal is greater than a fourth preset threshold value and the access quantity is greater than a fifth preset threshold value. In response to the second indication information, the target router with the quantity of forwarding the target data packet greater than the third preset threshold value is determined from the first information table.

[0122] As shown in Figure 8The diagram shown is a schematic representation of a network attack location device applied in a second router of a communication system according to an embodiment of this application. The network attack location device includes a processing unit 801 and a communication unit 802.

[0123] The communication unit 802 is used to receive third indication information sent by the first terminal; the third indication information is used to indicate that the resource utilization rate of the first terminal is greater than a first preset threshold and the number of accesses is greater than a second preset threshold; the processing unit 801 is used to generate a first information table in response to the third indication information; the first information table includes: the routing identifier of at least one third router and the IP address of the target data packet; the communication unit 802 is also used to send the first information table to at least one first router.

[0124] Optionally, the processing unit 801 is further configured to: instruct the communication unit 802 to receive fourth indication information sent by the first terminal; the fourth indication information is indication information generated when the resource utilization rate of the first terminal is greater than a fourth preset threshold and the access volume is greater than a fifth preset threshold; in response to the fourth indication information, instruct the communication unit 802 to send second indication information to at least one first router. The second indication information is used to instruct the first router to locate the target router.

[0125] like Figure 9 The diagram shown is a schematic representation of a network attack location device applied in a target router of a communication system, according to an embodiment of this application. The network attack location device includes a processing unit 901 and a communication unit 902.

[0126] The communication unit 902 is used to receive first indication information sent by the first router; the first indication information is used to instruct the target router to locate the second terminal attacking the first terminal; the second terminal is a terminal connected to the target router; the processing unit 901 is used to generate a control access rule (ACL) in response to the first indication information, the ACL control access rule is used to control the forwarding of target data packets sent by the second terminal; the processing unit 901 is also used to control the forwarding of target data packets sent by the second terminal according to the ACL control access rule.

[0127] This application provides a network attack location device for executing the method required by any device in the aforementioned network attack location system. This network attack location device may be the network attack location device described in this application, or a module within a network attack location device; it may also be a chip within a network attack location device, or other devices for executing network attack location methods; this application does not limit the specific device used.

[0128] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores instructions. When a computer executes the instructions, the computer executes each step in the method flow shown in the above method embodiment.

[0129] The embodiment of the present application provides a computer program product containing instructions, which, when executed on a computer, cause the computer to perform the network attack positioning method in the above method embodiment.

[0130] The embodiment of the present application provides a chip, which includes a processor and a communication interface. The communication interface is coupled with the processor. The processor is configured to execute a computer program or instructions to implement the network attack positioning method in the above method embodiment.

[0131] The computer readable storage medium may, for example, be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any combination thereof. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a register, a hard disk, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any other suitable combination of the foregoing, or any other suitable tangible computer readable storage medium. An exemplary storage medium is coupled to the processor such that the processor can read information from, and write information to, the storage medium. Of course, the storage medium can be a component of the processor. Suitable processors include, by way of example, both general and special purpose microprocessors. The processor can also include other processing circuitry, such as a custom circuit, an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or the like. Suitable memory includes, by way of example, both volatile and non-volatile memory, including, by way of example, read-only memory (ROM), random access memory (RAM), and the like. The memory can also include other forms of storage, including, for example, without limitation, a hard disk, a solid state drive, a flash drive, a magnetic disk, a tape drive, a cassette, an optical drive, and the like.

[0132] Since the device, the equipment, the computer readable storage medium, and the computer program product in the embodiment of the present application can be applied to the above method, the technical effects that can be obtained are also referable to the above method embodiment, and the embodiment of the present application will not be described herein again.

[0133] The above merely provides the specific implementation of the present application, but the protection scope of the present application is not limited to this. Any change or replacement within the technical scope disclosed by the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A network attack localization method, characterized in that, The application is applied to a first router of a communication system, the communication system comprising the first router, a second router and a third router, the first router being any router in the communication system, the second router being a router connected with a first terminal to be positioned for network attack, and the third router being a router forwarding a target data packet, the target data packet having a destination Internet Protocol (IP) address being an IP address of the first terminal, and the method comprising: receiving a first information table from the second router, the first information table comprising: routing identifiers of at least one third router and an IP address of the target data packet, the first terminal being a terminal having a resource utilization rate greater than a first preset threshold and an access quantity greater than a second preset threshold; receiving second indication information from the second router, the second indication information being indication information generated by the second router when the resource utilization rate of the first terminal is greater than a fourth preset threshold and the access quantity is greater than a fifth preset threshold; in response to the second indication information, determining, from the first information table, that a third router forwarding the target data packet in a quantity greater than a third preset threshold is a target router; sending first indication information to the target router, the first indication information being used to instruct the target router to position a second terminal attacking the first terminal, the second terminal being a terminal connected with the target router.

2. A network attack positioning method, characterized by, The application is applied to a second router of a communication system, the communication system comprising a first router, the second router and a third router, the first router being any router in the communication system; the second router being a router connected with a first terminal to be positioned for network attack, and the third router being a router forwarding a target data packet, the target data packet having a destination IP address being an IP address of the first terminal, and the method comprising: receiving third indication information sent by the first terminal, the third indication information being used to represent that the resource utilization rate of the first terminal is greater than a first preset threshold and the access quantity is greater than a second preset threshold; in response to the third indication information, generating a first information table, the first information table comprising: routing identifiers of at least one third router and an IP address of the target data packet; sending the first information table to at least one first router; receiving fourth indication information sent by the first terminal, the fourth indication information being indication information generated when the resource utilization rate of the first terminal is greater than a fourth preset threshold and the access quantity is greater than a fifth preset threshold; in response to the fourth indication information, sending second indication information to the at least one first router, the second indication information being used to instruct the first router to position a target router.

3. A network attack localization method, characterized in that, The application is applied to a target router, the target router is a third router whose number of forwarding target data packets is greater than a third preset threshold, the third router is a router in a communication system, the communication system comprises a first router, a second router and the third router, and the first router is any router in the communication system; The second router is a router connected with a first terminal to be positioned for a network attack, the second router is configured to receive fourth indication information sent by the first terminal, and in response to the fourth indication information, send second indication information to at least one first router, wherein the fourth indication information is indication information generated when resource utilization of the first terminal is greater than a fourth preset threshold and access volume is greater than a fifth preset threshold, and the second indication information is used to instruct the first router to position the target router; the third router is a router forwarding target data packets, and a destination IP address of the target data packets is an IP address of the first terminal, and the method comprises: Receiving first indication information sent by the first router; the first indication information is used to instruct the target router to position a second terminal attacking the first terminal; and the second terminal is a terminal connected with the target router; In response to the first indication information, generating an access control list (ACL), the access control list (ACL) is used to control forwarding of the target data packets sent by the second terminal; According to the access control list (ACL), the forwarding of the target data packets sent by the second terminal is controlled.

4. A cyber attack positioning apparatus, characterized by, The application is applied to a first router in a communication system, the communication system comprises the first router, a second router and a third router, the first router is any router in the communication system; the second router is a router connected with a first terminal to be positioned for a network attack, and the third router is a router forwarding target data packets, and a destination IP address of the target data packets is an IP address of the first terminal, and the device comprises a processing unit and a communication unit; The communication unit is configured to receive a first information table from the second router; the first information table comprises a routing identifier of at least one third router and an IP address of the target data packets; the destination IP address of the target data packets is an IP address of the first terminal; and the first terminal is a terminal whose resource utilization is greater than a first preset threshold and access volume is greater than a second preset threshold; The processing unit is configured to instruct the communication unit to receive second indication information from the second router, the second indication information is indication information generated by the second router when resource utilization of the first terminal is greater than a fourth preset threshold and access volume is greater than a fifth preset threshold; The processing unit is further configured to determine, in response to the second indication information, a third router whose number of forwarding the target data packets is greater than a third preset threshold as a target router from the first information table. The communication unit is further configured to send first indication information to the target router, and the first indication information is used to instruct the target router to locate a second terminal that attacks the first terminal, and the second terminal is a terminal connected to the target router.

5. A cyber attack positioning apparatus, characterized by, The second router is a router connected to a first terminal to be located for a network attack, and the third router is a router forwarding a target data packet, and the target data packet has a destination IP address of an IP address of the first terminal. The communication unit is configured to receive third indication information sent by the first terminal, and the third indication information is used to represent that resource utilization of the first terminal is greater than a first preset threshold value and an access quantity is greater than a second preset threshold value. The processing unit is configured to generate a first information table in response to the third indication information, and the first information table includes routing identifiers of at least one third router and an IP address of a target data packet. The communication unit is further configured to send the first information table to the at least one first router. The processing unit is further configured to: The communication unit is configured to receive fourth indication information sent by the first terminal, and the fourth indication information is generated when resource utilization of the first terminal is greater than a fourth preset threshold value and an access quantity is greater than a fifth preset threshold value. The communication unit is configured to send second indication information to at least one first router in response to the fourth indication information, and the second indication information is used to instruct the first router to locate a target router. The target router is a third router forwarding a target data packet, and the number of the target data packet is greater than a third preset threshold value, and the third router is a router in a communication system.

6. A cyber attack positioning apparatus, characterized by, The second router is a router connected to a first terminal to be located for a network attack, and the second router is configured to receive fourth indication information sent by the first terminal and send second indication information to at least one first router in response to the fourth indication information, wherein the fourth indication information is generated when resource utilization of the first terminal is greater than a fourth preset threshold value and an access quantity is greater than a fifth preset threshold value, and the second indication information is used to instruct the first router to locate the target router, and the third router is a router forwarding a target data packet, and the target data packet has a destination IP address of an IP address of the first terminal. ​ The communication unit is configured to receive first indication information sent by the first router, wherein the first indication information is used to indicate that the target router locates a second terminal that attacks the first terminal, and the second terminal is a terminal connected to the target router. The processing unit is configured to generate an access control list (ACL) in response to the first indication information, wherein the ACL is used to control the forwarding of the target data packet sent by the second terminal. The processing unit is further configured to control the forwarding of the target data packet sent by the second terminal according to the ACL.

7. A cyber attack positioning apparatus, characterized by, The computer program product comprises: a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is configured to run computer programs or instructions to implement the network attack locating method according to any one of claims 1-3.

8. A computer-readable storage medium having stored therein instructions, the computer-readable storage medium comprising: When a computer executes the instructions, the computer executes the network attack locating method according to any one of claims 1-3.

Citation Information

Patent Citations

  • Attack prevention processing method and device

    CN106131046A

  • Method, device and system for preventing and controlling network attack

    CN107135187A