Attack network identification method and device, server, and storage medium

By obtaining the characteristic information of the IP address of the DDoS attack source, the cluster of attack source IP addresses can be identified and its participation in the attack can be determined. This solves the problem that existing technologies cannot prevent botnets from attacking again, and achieves effective protection against DDoS attacks.

CN116707912BActive Publication Date: 2026-08-25CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310685151.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-09
Publication Date
2026-08-25
Estimated Expiration
2043-06-09

AI Technical Summary

Technical Problem

Current technologies can only block the IP addresses of the attack sources involved in the attack, and cannot fundamentally prevent an attack network from launching another attack using other botnets.

Method used

By obtaining the source IP address of the DDoS attack, its characteristic information is obtained, the cluster of source IP addresses is identified, and it is determined whether the IP addresses in the cluster are involved in the attack. If they are involved, they are marked and an alarm is output, thus discovering the botnet associated with the control terminal IP address.

Benefits of technology

It can identify and mark the control terminal IP address that initiates the attack and its associated botnet, thereby fundamentally avoiding botnet attacks and achieving effective protection against DDoS attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116707912B_ABST
    Figure CN116707912B_ABST
Patent Text Reader

Abstract

The application provides an attack network identification method and device, a server and a storage medium. The method comprises the following steps: obtaining an attack source Internet protocol (IP) address of any known distributed denial of service (DDoS) attack, obtaining characteristic information corresponding to the attack source IP address according to the attack source IP address, determining an attack source IP address cluster according to the characteristic information corresponding to the attack source IP address, judging whether the IP addresses in the attack source IP address cluster participate in the attack, and if any IP address in the attack source IP address cluster is determined to participate in the attack, marking the IP address and outputting an alarm prompt. The application processes the characteristic information of the known attack source IP, can not only determine the IP address of the control end that initiates the attack, but also find the attack source IP address cluster that is associated with the IP address of the control end, and avoids the attack of the puppet machine.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, server, and storage medium for identifying network attacks. Background Technology

[0002] Distributed Denial of Service (DDoS) attacks can forge a large number of data packets and send them to a target network device in a short period of time. This causes the target network device to receive a large number of data packet requests in a short period of time, thereby preventing it from providing normal network services. Therefore, how to identify and detect DDoS attacks on target network devices in a timely and effective manner is an urgent technical problem that needs to be solved.

[0003] In existing technologies, the discovery of large-scale DDoS attack networks mainly relies on traffic analysis during the launch of DDoS attacks to identify attack networks composed of Internet Protocol (IP) addresses involved in the attack. When determining a DDoS attack network, it is mainly done by analyzing past DDoS attacks, extracting relevant attack source IP addresses and attack characteristics, and clustering the attack source IP addresses and attack methods to include attack source IP addresses with the same characteristics into the same attack network. The analysis and determination are mainly based on the attack source IP addresses and attack methods involved in the DDoS attack.

[0004] However, current technology can only block the IP addresses of the attack sources involved in the attack, and these attackers may just be some botnets, so it cannot fundamentally prevent an attack network from launching another attack using other botnets. Summary of the Invention

[0005] This invention provides an attack network identification method, device, server, and storage medium to solve the problem that existing technologies can only block the IP addresses of the attack sources involved in the attack, and cannot fundamentally prevent an attack network from launching another attack using other botnets.

[0006] In a first aspect, embodiments of the present invention provide a method for identifying attack networks, including:

[0007] Obtain the Internet Protocol (IP) address of the source of any known Distributed Denial-of-Service (DDoS) attack.

[0008] Based on the attack source IP address, obtain the characteristic information corresponding to the attack source IP address;

[0009] Based on the characteristic information corresponding to the attack source IP addresses, the attack source IP address cluster is determined;

[0010] Determine whether any IP addresses in the attack source IP address cluster are involved in the attack;

[0011] If any IP address in the attack source IP address cluster is determined to be involved in the attack, then that IP address will be marked and an alarm will be output.

[0012] In one possible design, the feature information includes the control terminal IP address, the control terminal domain name, the target IP address, and the target domain name. Determining the attack source IP address cluster based on the feature information corresponding to the attack source IP address includes: obtaining a first controlled IP address corresponding to the control terminal IP address; obtaining a second and third controlled IP address corresponding to the control terminal domain name; obtaining first traffic information of the target IP address during the target time period based on the target IP address; obtaining second traffic information of the target domain name during the target time period, and third traffic information of the subdomains of the target domain name during the target time period based on the target domain name; obtaining abnormal attack source IP addresses with abnormal traffic during the same time period but not detected by the DDoS protection system based on the first, second, and third traffic information; and determining the first controlled IP address, second controlled IP address, third IP address, and abnormal attack source IP address as the attack source IP address cluster.

[0013] In one possible design, obtaining the first controlled IP address corresponding to the control terminal IP address based on the control terminal IP address includes: performing NetFlow traffic feature processing based on the obtained control terminal IP address to obtain the first controlled IP address corresponding to the control terminal IP address.

[0014] In one possible design, obtaining the second controlled IP address and the third controlled IP address corresponding to the control domain name includes: performing domain name feature processing on the obtained control domain name to obtain an attack domain name with the same domain name features and a subdomain of the attack domain name; performing NetFlow traffic feature processing on the obtained attack domain name and subdomain to obtain the second controlled IP address corresponding to the attack domain name and subdomain; and performing NetFlow traffic feature processing on the obtained control domain name to obtain the third controlled IP address corresponding to the control domain name.

[0015] In one possible design, obtaining the first traffic information of the target IP address during the target time period based on the target IP address includes: performing NetFlow traffic feature processing on the obtained target IP address to obtain the first traffic information of the target IP address during the target time period.

[0016] In one possible design, obtaining the second traffic information related to the target domain name during the target time period and the third traffic information of the subdomains of the target domain name during the target time period based on the target domain name includes: performing NetFlow traffic feature processing on the obtained target domain name to obtain the second traffic information of the target domain name during the target time period; performing domain name feature processing on the obtained target domain name to obtain the subdomains of the target domain name; and performing NetFlow traffic feature processing on the obtained subdomains to obtain the third traffic information of the subdomains during the target time period.

[0017] In one possible design, obtaining the abnormal attack source IP address that is not detected by the DDoS protection system during the same period based on the first traffic information, the second traffic information, and the third traffic information includes: performing clustering and statistical processing based on the source IP address as the dimension to obtain the abnormal attack source IP address that is not detected by the DDoS protection system during the target period based on the first traffic information, the second traffic information, and the third traffic information.

[0018] In one possible design, determining whether an IP address in the attack source IP address cluster participated in the attack includes: obtaining historical information of the attack source IP address cluster; and performing historical NetFlow traffic feature processing on the historical information to determine whether each IP address in the attack source IP address cluster has participated in the attack.

[0019] In one possible design, obtaining the feature information corresponding to the attack source IP address based on the attack source IP address includes: performing NetFlow traffic feature processing based on the known attack source IP to obtain the feature information corresponding to the attack source IP address; wherein the feature information includes at least one of the following: control terminal IP address, control terminal domain name, attack target IP address, and attack target domain name.

[0020] In a second aspect, embodiments of the present invention provide an attack network identification device, comprising:

[0021] The acquisition module is used to obtain the Internet Protocol IP address of the attack source for any known Distributed Denial-of-Service (DDoS) attack.

[0022] The feature processing module is used to obtain feature information corresponding to the attack source IP address based on the attack source IP address;

[0023] The cluster processing module is used to determine the cluster of attack source IP addresses based on the characteristic information corresponding to the attack source IP addresses.

[0024] The judgment module is used to determine whether the IP addresses in the attack source IP address cluster are involved in the attack;

[0025] The output module is used to mark any IP address in the attack source IP address cluster and output an alarm message if it is determined that any IP address is involved in the attack.

[0026] Thirdly, the present invention provides a server, comprising: at least one processor and a memory;

[0027] The memory stores computer-executed instructions;

[0028] The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform the attack network identification method as described in the first aspect and various possible designs of the first aspect.

[0029] Fourthly, embodiments of the present invention provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the method described in the first aspect and various possible designs of the first aspect.

[0030] The attack network identification method, device, server, and storage medium provided by this invention obtain the attack source IP address of the DDoS attack through the server and obtain the characteristic information corresponding to the attack source IP address. Based on the characteristic information, the attack source IP address cluster is determined. Then, it is determined whether the IP addresses in the attack source IP address cluster are involved in the attack. If any IP address is involved in the attack, the IP address is marked and an alarm is output. In this way, not only can the IP address of the control terminal that initiated the attack be determined, but also the attack source IP address cluster associated with the control terminal IP address can be discovered. Furthermore, botnets associated with the control terminal IP address are found in the attack source IP address cluster, thereby fundamentally avoiding attacks by botnets. Attached Figure Description

[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1 This is a flowchart illustrating an attack network identification method according to an embodiment of the present invention.

[0033] Figure 2 A flowchart illustrating an attack network identification method provided in another embodiment of the present invention;

[0034] Figure 3 This is a schematic diagram of the attack network identification device provided in an embodiment of the present invention;

[0035] Figure 4 This is a schematic diagram of the hardware structure of a server provided in an embodiment of the present invention. Detailed Implementation

[0036] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0037] Example 1

[0038] Figure 1 This is a flowchart illustrating an attack network identification method according to an embodiment of the present invention. The executing entity in this embodiment can be a server or other computer devices; no particular limitation is made here. Figure 1 As shown, the method includes:

[0039] S101: Obtain the Internet Protocol IP address of the source of any known Distributed Denial-of-Service (DDoS) attack.

[0040] Specifically, the attack source IP address is obtained in two ways: from known datasets and from the server's identification results.

[0041] S102: Obtain the characteristic information corresponding to the attack source IP address based on the attack source IP address.

[0042] Specifically, NetFlow traffic feature processing is performed based on the known attack source IP to obtain the feature information corresponding to the attack source IP address.

[0043] Specifically, NetFlow traffic feature processing can involve obtaining multiple packet information corresponding to the attack source IP, and extracting at least one of the following fields from these multiple packet information as feature information corresponding to the attack source IP address: control terminal IP address, control terminal domain name, attack target IP address, and attack target domain name.

[0044] S103: Determine the cluster of attack source IP addresses based on the characteristic information corresponding to the attack source IP addresses.

[0045] The characteristic information includes the control terminal IP address, control terminal domain name, target IP address, and target domain name.

[0046] Specifically, S103 includes Sa to Sf:

[0047] Sa: Based on the control terminal IP address, obtain the first controlled IP address corresponding to the control terminal IP address.

[0048] Specifically, NetFlow traffic feature processing is performed based on the obtained control terminal IP address to obtain the corresponding first controlled IP address.

[0049] Specifically, NetFlow traffic feature processing can be performed by acquiring multiple packets sent or received by the control terminal's IP address, and extracting the following fields from each packet: source IP address, destination IP address, source port number, destination port number, IP protocol number, service type, Transmission Control Protocol (TCP) flag, number of bytes, and interface number; and extracting the corresponding destination IP address from multiple packets as the first controlled IP.

[0050] Sb: Based on the control domain name, obtain the second and third controlled IP addresses corresponding to the control domain name.

[0051] Specifically, the system obtains the domain name, associated parent domain name, or subdomain name associated with the control domain name to obtain the attack domain name and subdomain name with the same domain name characteristics; it performs NetFlow traffic feature processing on the attack domain name and subdomain name to obtain the second controlled IP address corresponding to the attack domain name and subdomain name; it performs NetFlow traffic feature processing on the control domain name to obtain the third controlled IP address corresponding to the control domain name.

[0052] Specifically, NetFlow traffic feature processing of the attack domain and subdomains can be performed by obtaining multiple packets sent or received by the attack domain and subdomains, and extracting the corresponding destination IP address from the multiple packets as the second controlled IP.

[0053] Specifically, NetFlow traffic feature processing of the control domain name can be performed by obtaining multiple packets sent or received by the control domain name, and extracting the corresponding destination IP address from the multiple packets as the third controlled IP. The multiple packets include the following fields: source IP address, destination IP address, source port number, destination port number, IP protocol number, service type, TCP flag, number of bytes, and interface number.

[0054] Sc: Based on the target IP address, obtain the first traffic information of the target IP address during the target time period.

[0055] Specifically, NetFlow traffic feature processing is performed based on the obtained target IP address to obtain the first traffic information of the target IP address during the target time period.

[0056] Specifically, NetFlow traffic feature processing can involve acquiring multiple packets sent and received by the target IP address within a preset time period, and using these multiple packets within the preset time period as the first traffic information.

[0057] Sd: Based on the target domain name, obtain the second traffic information of the target domain name during the target time period, and the third traffic information of the subdomains of the target domain name during the target time period.

[0058] Specifically, NetFlow traffic feature processing is performed on the obtained target domain name to obtain the second traffic information of the target domain name during the target time period; the domain name, associated parent domain name or subdomain name associated with the target domain name is obtained to obtain the subdomain name of the attack domain name with the same domain name feature; NetFlow traffic feature processing is performed on the obtained subdomain name to obtain the third traffic information of the subdomain name during the target time period.

[0059] Specifically, NetFlow traffic feature processing of the target domain name can be performed by obtaining multiple packets sent and received by the target domain name within a preset time period, and using these multiple packets within the preset time period as secondary traffic information.

[0060] Specifically, NetFlow traffic feature processing of the target subdomain can be performed by obtaining multiple packets sent and received by the target subdomain within a preset time period, and using these multiple packets within the preset time period as third-party traffic information.

[0061] Se: Based on the first traffic information, the second traffic information, and the third traffic information, obtain the IP addresses of abnormal attack sources that were not detected by the DDoS protection system during the same period of traffic anomalies.

[0062] Specifically, based on the first, second, and third traffic information, clustering and statistical processing are performed using the source IP address as the dimension to obtain the abnormal attack source IP addresses that were not detected by the DDoS protection system during the same period of abnormal traffic.

[0063] Sf: Identify the first controlled IP address, the second controlled IP address, the third IP address, and the abnormal attack source IP address as the attack source IP address cluster.

[0064] S104: Determine whether any IP addresses in the attack source IP address cluster are involved in the attack.

[0065] Specifically, you can query each IP address in the attack source IP address cluster to see if there is a record of attack behavior; if there is, it is determined that the IP address participated in the attack; if not, it is determined that the IP address did not participate in the attack.

[0066] S105: If it is determined that any IP address in the attack source IP address cluster is involved in the attack, then mark that IP address and output an alarm message.

[0067] Specifically, the output alarm notification could be sent to the terminal of any marked IP address so that the maintenance personnel can view it; or it could be sent to a large screen to display all marked IP addresses so as to notify all maintenance personnel.

[0068] As described above, the process involves several steps. First, the server retrieves the IP addresses of the DDoS attack sources and their corresponding characteristic information. Based on this information, the attack source IP address cluster is identified. Then, it determines whether any IP address in the cluster is involved in the attack. If any IP address is involved, it is marked and an alarm is triggered. This process not only identifies the IP address of the control server initiating the attack but also discovers the attack source IP address cluster associated with the control server's IP address. Consequently, botnets associated with the control server's IP address are found within the attack source IP address cluster, thus fundamentally preventing attacks from botnets.

[0069] Example 2

[0070] Figure 2 This is a flowchart illustrating an attack network identification method according to another embodiment of the present invention. In this embodiment of the present invention, in Figure 1 Based on the provided embodiments, the method includes:

[0071] S201: Obtain the Internet Protocol IP address of the source of any known DDoS attack.

[0072] S202: Based on the attack source IP address, obtain the characteristic information corresponding to the attack source IP address.

[0073] S203: Determine the cluster of attack source IP addresses based on the characteristic information corresponding to the attack source IP addresses.

[0074] In this embodiment, the description of steps S201-S203 is the same as that of steps S101-S103 above. For a detailed description, please refer to the relevant content, which will not be repeated here.

[0075] S204: Obtain historical information about the attack source IP address cluster.

[0076] The server pre-stores behavior logs for each IP address, which record details of each IP address launching a network attack.

[0077] Among them, the historical information of the attack source IP address cluster includes the behavior logs of each IP address.

[0078] S205: Perform historical NetFlow traffic feature processing on historical information to determine whether each IP address in the attack source IP address cluster has participated in the attack.

[0079] Specifically, historical NetFlow traffic feature processing of the historical information of the attack source IP address cluster can be performed by checking whether there are records of network attack events in the behavior logs of each IP address in the attack source IP address cluster, thereby determining whether each IP address in the attack source IP address cluster has participated in the attack. If there are records of network attack events, it is determined that the IP address participated in the attack; if there are no records of network attack events, it is determined that the IP address did not participate in the attack.

[0080] S206: If it is determined that any IP address in the attack source IP address cluster is involved in the attack, then mark that IP address and output an alarm message.

[0081] In this embodiment, the description of step S206 is the same as that of step S105 above. For a detailed description, please refer to the relevant content, which will not be repeated here.

[0082] S207: Use any of the marked IP addresses as new input and repeat step S201.

[0083] As described above, by acquiring historical information about the attack source IP address clusters and processing this information using historical NetFlow traffic characteristics, it is possible to more accurately determine whether each IP address in the attack source IP address cluster has participated in the attack. Furthermore, after obtaining the IP addresses involved in the attack, these IP addresses are used as new inputs to iteratively execute the IP network attack identification steps. This continuously expands the search scope, discovering more attack source IP address clusters associated with the control terminal's IP addresses, and further preventing network attacks.

[0084] Figure 3 This is a schematic diagram of the attack network identification device provided in an embodiment of the present invention. Figure 3 As shown, the attack network identification device 30 includes: an acquisition module 301, a feature processing module 302, a cluster processing module 303, a judgment module 304, and an output module 305.

[0085] The acquisition module 301 is used to acquire the Internet Protocol IP address of the attack source of any known Distributed Denial-of-Service (DDoS) attack.

[0086] The feature processing module 302 is used to obtain feature information corresponding to the attack source IP address based on the attack source IP address;

[0087] The cluster processing module 303 is used to determine the cluster of attack source IP addresses based on the characteristic information corresponding to the attack source IP addresses.

[0088] The judgment module 304 is used to determine whether the IP addresses in the attack source IP address cluster are involved in the attack;

[0089] The output module 305 is used to mark any IP address in the attack source IP address cluster and output an alarm prompt if it is determined that any IP address in the cluster is involved in the attack.

[0090] In one possible design, the feature information includes the control terminal IP address, the control terminal domain name, the attack target IP address, and the attack target domain name; the cluster processing module 303 includes:

[0091] The first IP address processing unit 3031 is used to obtain the first controlled IP address corresponding to the control terminal IP address based on the control terminal IP address;

[0092] The second IP address processing unit 3032 is used to obtain the second controlled IP address corresponding to the control terminal domain name based on the control terminal domain name;

[0093] The third IP address processing unit 3033 is used to obtain the third controlled IP address corresponding to the control terminal domain name based on the control terminal domain name;

[0094] The first traffic information processing unit 3034 is used to obtain the first traffic information of the target IP address in the target time period based on the target IP address.

[0095] The second traffic information processing unit 3035 is used to obtain the second traffic information of the target domain name during the target time period based on the target domain name.

[0096] The third traffic information processing unit 3036 is used to obtain the third traffic information of the subdomains of the target domain during the target time period based on the target domain.

[0097] The abnormal attack source IP address processing unit 3037 is used to obtain the abnormal attack source IP address that is not detected by the DDoS protection system during the same period based on the first traffic information, the second traffic information and the third traffic information.

[0098] IP address cluster processing unit 3038 is used to identify the first controlled IP address, the second controlled IP address, the third IP address and the abnormal attack source IP address as an attack source IP address cluster.

[0099] In one possible design, the first IP address processing unit 3031 is specifically used to: perform NetFlow traffic feature processing based on the obtained control terminal IP address to obtain the first controlled IP address corresponding to the control terminal IP address.

[0100] In one possible design, the second IP address processing unit 3032 is specifically used for: performing domain name feature processing based on the obtained control domain name to obtain an attack domain name with the same domain name features and a subdomain of the attack domain name; and performing NetFlow traffic feature processing based on the obtained attack domain name and subdomain to obtain a second controlled IP address corresponding to the domain name and subdomain.

[0101] In one possible design, the third IP address processing unit 3033 is specifically used to: perform NetFlow traffic feature processing based on the obtained control domain name to obtain the third controlled IP address corresponding to the aforementioned control domain name.

[0102] In one possible design, the first traffic information processing unit 3034 is specifically used to: perform NetFlow traffic feature processing based on the obtained attack target IP address to obtain the first traffic information of the attack target IP address in the target time period.

[0103] In one possible design, the second traffic information processing unit 3035 is specifically used to: perform NetFlow traffic feature processing based on the obtained attack target domain name to obtain the second traffic information of the attack target domain name in the target time period.

[0104] In one possible design, the third traffic information processing unit 3036 is specifically used to: perform domain name feature processing based on the obtained target domain name to obtain the subdomain of the target domain name; and perform NetFlow traffic feature processing based on the obtained subdomain to obtain the third traffic information of the subdomain during the target time period.

[0105] In one possible design, the abnormal attack source IP address processing unit 3037 is specifically used to: perform clustering and statistical processing based on the first traffic information, the second traffic information, and the third traffic information, with the source IP address as the dimension, to obtain the abnormal attack source IP address that is abnormal in traffic during the target time period but has not been detected by the DDoS protection system.

[0106] In one possible design, the determination module 304 includes:

[0107] The acquisition unit 3041 is used to acquire historical information of the attack source IP address cluster, wherein the historical information of the attack source IP address cluster is the behavior log of each IP address.

[0108] The judgment unit 3042 is used to perform historical NetFlow traffic feature processing on the historical information to determine whether each IP address in the attack source IP address cluster has participated in the attack.

[0109] In one possible design, the feature processing module 302 is specifically used to: perform NetFlow traffic feature processing based on the known attack source IP to obtain feature information corresponding to the attack source IP address; the feature information includes at least one of the following: control terminal IP address, control terminal domain name, attack target IP address, and attack target domain name.

[0110] In one possible design, the attack network identification device 30 further includes:

[0111] The loop module 306 is used to repeatedly execute the IP network attack identification steps, taking any of the marked IP addresses as new inputs.

[0112] The apparatus provided in this embodiment can be used to execute the technical solutions of the above method embodiments. Its implementation principle and technical effects are similar, and will not be described again here.

[0113] Figure 4 This is a schematic diagram of the hardware structure of a server provided in an embodiment of the present invention. Figure 4 As shown, the server 40 in this embodiment includes: a processor 401 and a memory 402; wherein

[0114] Memory 402 is used to store instructions executed by the computer;

[0115] Processor 401 is configured to execute computer execution instructions stored in memory to implement the various steps performed by the server in the above embodiments. For details, please refer to the relevant descriptions in the foregoing method embodiments.

[0116] Alternatively, the memory 402 can be either standalone or integrated with the processor 401.

[0117] When the memory 402 is set up independently, the server also includes a bus 403 for connecting the memory 402 and the processor 401.

[0118] This invention also provides a computer storage medium storing computer execution instructions. When a processor executes the computer execution instructions, the attack network identification method described above is implemented.

[0119] This invention also provides a computer program product, including a computer program that, when executed by a processor, implements the attack network identification method described above.

[0120] In the several embodiments provided by this invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or modules, and may be electrical, mechanical, or other forms.

[0121] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to implement the solution of this embodiment according to actual needs.

[0122] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit. The unit composed of the above modules can be implemented in hardware or in the form of hardware plus software functional units.

[0123] The integrated modules implemented as software functional modules described above can be stored in a computer-readable storage medium. These software functional modules, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of this application.

[0124] It should be understood that the aforementioned processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0125] The memory may include high-speed RAM, and may also include non-volatile storage (NVM), such as at least one disk storage device, and may also be a USB flash drive, external hard drive, read-only memory, disk or optical disc, etc.

[0126] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0127] The aforementioned storage medium can be implemented from any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium can be any available medium accessible to general-purpose or special-purpose computers.

[0128] An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Alternatively, the storage medium can be an integral part of the processor. Both the processor and the storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and storage medium can exist as discrete components in an electronic device or host device.

[0129] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0130] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for identifying attack networks, characterized in that, Applied to servers, including: Obtain the Internet Protocol (IP) address of the source of any known Distributed Denial-of-Service (DDoS) attack. Based on the attack source IP address, obtain the characteristic information corresponding to the attack source IP address; Based on the characteristic information corresponding to the attack source IP addresses, the attack source IP address cluster is determined; Determine whether any IP addresses in the attack source IP address cluster are involved in the attack; If it is determined that any IP address in the attack source IP address cluster is involved in the attack, then the IP address is marked and an alarm is output. The characteristic information includes the control terminal IP address, the control terminal domain name, the attack target IP address, and the attack target domain name; Accordingly, determining the cluster of attack source IP addresses based on the characteristic information corresponding to the attack source IP addresses includes: Based on the control terminal IP address, the first controlled IP address corresponding to the control terminal IP address is obtained; Based on the control terminal domain name, the second controlled IP address and the third controlled IP address corresponding to the control terminal domain name are obtained; Based on the target IP address, the first traffic information of the target IP address during the target time period is obtained; Based on the target domain name, the second traffic information of the target domain name during the target time period and the third traffic information of the subdomains of the target domain name during the target time period are obtained. Based on the first traffic information, the second traffic information, and the third traffic information, the abnormal attack source IP addresses that were not detected by the DDoS protection system during the same period were obtained. The first controlled IP address, the second controlled IP address, the third controlled IP address, and the abnormal attack source IP address are identified as the attack source IP address cluster.

2. The method according to claim 1, characterized in that, The step of obtaining the first controlled IP address corresponding to the control terminal IP address based on the control terminal IP address includes: Based on the obtained control terminal IP address, perform NetFlow traffic feature processing to obtain the first controlled IP address corresponding to the control terminal IP address.

3. The method according to claim 1, characterized in that, The step of obtaining the second controlled IP address and the third controlled IP address corresponding to the control terminal domain name includes: Based on the obtained control domain name, domain name feature processing is performed to obtain attack domain names with the same domain name features and subdomains of the attack domain names; NetFlow traffic feature processing is performed on the obtained attack domain name and subdomain to obtain the second controlled IP address corresponding to the attack domain name and subdomain. Based on the obtained control domain name, NetFlow traffic feature processing is performed to obtain the third controlled IP address corresponding to the control domain name.

4. The method according to claim 1, characterized in that, The step of obtaining the first traffic information of the target IP address during the target time period based on the target IP address includes: NetFlow traffic feature processing is performed on the obtained target IP address to obtain the first traffic information of the target IP address in the target time period.

5. The method according to claim 1, characterized in that, The step of obtaining second traffic information related to the target domain name during the target time period and third traffic information of the subdomains of the target domain name during the target time period based on the target domain name includes: Based on the obtained target domain name, perform NetFlow traffic feature processing to obtain the second traffic information of the target domain name in the target time period; Based on the obtained target domain name, domain name feature processing is performed to obtain the subdomains of the target domain name; NetFlow traffic feature processing is performed on the obtained subdomains to obtain the third traffic information of the subdomains in the target time period.

6. The method according to claim 1, characterized in that, The process of obtaining the abnormal attack source IP addresses that were not detected by the DDoS protection system during the same period based on the first traffic information, the second traffic information, and the third traffic information includes: Based on the first, second, and third traffic information, clustering and statistical processing are performed using the source IP address as the dimension to obtain the abnormal attack source IP addresses that were not detected by the DDoS protection system during the target time period.

7. The method according to any one of claims 1 to 6, characterized in that, The step of determining whether the IP addresses in the attack source IP address cluster participated in the attack includes: Obtain historical information about the cluster of attack source IP addresses; The historical information is processed using historical NetFlow traffic characteristics to determine whether each IP address in the attack source IP address cluster has participated in the attack.

8. The method according to any one of claims 1 to 6, characterized in that, The step of obtaining the characteristic information corresponding to the attack source IP address based on the attack source IP address includes: NetFlow traffic feature processing is performed based on the known attack source IP to obtain the feature information corresponding to the attack source IP address; The feature information includes at least one of the following: control terminal IP address, control terminal domain name, target IP address, and target domain name.

9. An attack network identification device, characterized in that, Applied to servers, including: The acquisition module is used to obtain the Internet Protocol IP address of the attack source for any known Distributed Denial-of-Service (DDoS) attack. The feature processing module is used to obtain feature information corresponding to the attack source IP address based on the attack source IP address; The cluster processing module is used to determine the cluster of attack source IP addresses based on the characteristic information corresponding to the attack source IP addresses. The judgment module is used to determine whether the IP addresses in the attack source IP address cluster are involved in the attack; The output module is used to mark any IP address in the attack source IP address cluster and output an alarm message if it is determined that any IP address in the cluster is involved in the attack. The characteristic information includes the control terminal IP address, the control terminal domain name, the attack target IP address, and the attack target domain name; the cluster processing module is used for: Based on the control terminal IP address, the first controlled IP address corresponding to the control terminal IP address is obtained; Based on the control terminal domain name, the second controlled IP address and the third controlled IP address corresponding to the control terminal domain name are obtained; Based on the target IP address, the first traffic information of the target IP address during the target time period is obtained; Based on the target domain name, the second traffic information of the target domain name during the target time period and the third traffic information of the subdomains of the target domain name during the target time period are obtained. Based on the first traffic information, the second traffic information, and the third traffic information, the abnormal attack source IP addresses that were not detected by the DDoS protection system during the same period were obtained. The first controlled IP address, the second controlled IP address, the third controlled IP address, and the abnormal attack source IP address are identified as the attack source IP address cluster.

10. A server, characterized in that, include: At least one processor and memory; The memory stores computer-executed instructions; The at least one processor executes computer execution instructions stored in the memory, causing the at least one processor to perform the attack network identification method as described in any one of claims 1 to 8.

11. A computer storage medium, characterized in that, The computer storage medium stores computer execution instructions, and when the processor executes the computer execution instructions, it implements the attack network identification method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Network security detection method and device

    CN104579819A

  • Method for identifying and judging DDoS attack gang behaviors

    CN112822194A