Abnormal traffic monitoring method, model modeling method and device, and electronic equipment

CN116961964BActive Publication Date: 2026-09-15CHINA MOBILEHANGZHOUINFORMATION TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211222537.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-08
Publication Date
2026-09-15
Estimated Expiration
2042-10-08

AI Technical Summary

Technical Problem

[0002]异常流量攻击不仅降低网络性能、消耗网络资源,还可能会使企业面对经济损失甚至法律风险

Benefits of technology

[0012] In this embodiment, the abnormal traffic monitoring model is determined by the variance of the first rate and the second rate. This improves the learning efficiency and quality of the abnormal traffic monitoring model. The model is trained by gradually increasing the difficulty by progressively increasing the variance of the packet sending rates of attack traffic sent by attackers and legitimate traffic sent by normal users, thus blurring the difference between them. This achieves a more relaxed learning strategy and a gradual increase in difficulty, resolving the non-stationarity problem during model training.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116961964B_ABST
    Figure CN116961964B_ABST
Patent Text Reader

Abstract

The embodiment of the application discloses a modeling method of an abnormal traffic monitoring model, comprising: acquiring a traffic state sequence of a target software-defined network (SDN) switch in a target window time; the traffic state sequence at least includes one of the following traffics: attack traffic and legal traffic, wherein the attack traffic is used for sending an illegal request data packet to a target program; and the legal traffic is used for sending a legal request data packet to the target program; determining a first rate of sending data packets of the attack traffic and a second rate of sending data packets of the legal traffic; and determining an abnormal traffic monitoring model based on variances of the first rate and the second rate. The embodiment of the application also simultaneously provides an abnormal traffic monitoring method and device and an electronic device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of electronic equipment technology, and includes, but is not limited to, abnormal flow monitoring methods, modeling methods and devices, and electronic equipment. Background Technology

[0002] Anomaly traffic attacks not only degrade network performance and consume network resources, but can also expose businesses to economic losses and even legal risks. Therefore, there is an urgent need for a diagnostic monitoring model capable of efficiently identifying and analyzing anomaly traffic to ensure the healthy and secure operation of the network. Summary of the Invention

[0003] This application provides an abnormal traffic monitoring method, a modeling method and apparatus, and an electronic device.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] This application provides a modeling method for an abnormal traffic monitoring model. The method includes: acquiring a traffic state sequence of a target software-defined network (SDN) switch within a target window time; the traffic state sequence includes at least one type of traffic: attack traffic and legitimate traffic, wherein the attack traffic is used to send illegal request data packets to a target program; the legitimate traffic is used to send legitimate request data packets to the target program; determining a first rate at which the attack traffic sends data packets and a second rate at which the legitimate traffic sends data packets; and determining an abnormal traffic monitoring model based on the variance of the first rate and the second rate.

[0006] This application provides an abnormal traffic monitoring method, the method comprising: acquiring a traffic state sequence of an SDN switch and the bandwidth of a server connected to the SDN switch; determining the attack traffic at a target time based on the traffic state sequence using an abnormal traffic monitoring model, wherein the abnormal traffic monitoring model is a model determined by the variance between a first rate at which data packets are sent by the attack traffic and a second rate at which data packets are sent by the legitimate traffic; determining a rate-limiting bandwidth threshold based on the server bandwidth and the attack traffic at the target time; and determining the abnormal traffic based on the rate-limiting bandwidth threshold.

[0007] This application provides a modeling apparatus for an abnormal traffic monitoring model. The apparatus includes: an acquisition module, configured to acquire a traffic state sequence of a target software-defined network (SDN) switch within a target window time; the traffic state sequence includes at least one type of traffic: attack traffic and legitimate traffic, wherein the attack traffic is used to send illegal request data packets to a target program; and the legitimate traffic is used to send legitimate request data packets to the target program; and a determination module, configured to determine a first rate at which the attack traffic sends data packets and a second rate at which the legitimate traffic sends data packets; and to determine an abnormal traffic monitoring model based on the variance of the first rate and the second rate.

[0008] This application provides an abnormal traffic monitoring device, comprising: an acquisition module for acquiring a traffic state sequence of an SDN switch and the bandwidth of a server connected to the SDN switch; a determination module for determining, based on the traffic state sequence and using an abnormal traffic monitoring model, the attack traffic at a target time, wherein the abnormal traffic monitoring model is a model determined by the variance between a first rate at which data packets are sent via attack traffic and a second rate at which data packets are sent via legitimate traffic; determining a rate-limiting bandwidth threshold based on the server bandwidth and the attack traffic at the target time; and determining abnormal traffic based on the rate-limiting bandwidth threshold.

[0009] This application provides an electronic device, including a memory and a processor. The memory stores a computer program that can run on the processor, and the processor executes the program to implement the steps in the above-described method.

[0010] This application provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the steps in the above-described method.

[0011] The beneficial effects of the technical solutions provided in this application include at least the following:

[0012] In this embodiment, the abnormal traffic monitoring model is determined by the variance of the first rate and the second rate. This improves the learning efficiency and quality of the abnormal traffic monitoring model. The model is trained by gradually increasing the difficulty by progressively increasing the variance of the packet sending rates of attack traffic sent by attackers and legitimate traffic sent by normal users, thus blurring the difference between them. This achieves a more relaxed learning strategy and a gradual increase in difficulty, resolving the non-stationarity problem during model training. Attached Figure Description

[0013] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort, wherein:

[0014] Figure 1 This application provides a flowchart illustrating a method for modeling an abnormal traffic monitoring model.

[0015] Figure 2 This application provides a flowchart illustrating a method for modeling an abnormal traffic monitoring model.

[0016] Figure 3 This application provides a flowchart illustrating a method for modeling an abnormal traffic monitoring model.

[0017] Figure 4 A schematic diagram of an optional architecture for the execution system of the abnormal traffic monitoring modeling method provided in the embodiments of this application;

[0018] Figure 5 A schematic diagram of the composition structure of a modeling device for an abnormal traffic monitoring model provided in this application embodiment;

[0019] Figure 6A This application provides a flowchart illustrating a method for modeling an abnormal traffic monitoring model.

[0020] Figure 6B This application provides a flowchart illustrating a method for modeling an abnormal traffic monitoring model.

[0021] Figure 6C This application provides a flowchart illustrating a method for modeling an abnormal traffic monitoring model.

[0022] Figure 7 A schematic diagram of the composition structure of a modeling device for an abnormal traffic monitoring model provided in this application embodiment;

[0023] Figure 8 This is a schematic diagram of the composition structure of an abnormal flow monitoring device provided in an embodiment of this application;

[0024] Figure 9 This is a schematic diagram of the hardware entity of an electronic device provided in an embodiment of this application. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. The following embodiments are used to illustrate this application, but are not intended to limit the scope of this application. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0027] It should be noted that the terms "first, second, and third" used in the embodiments of this application are merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, and third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0028] It will be understood by those skilled in the art that, unless otherwise defined, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art to which the embodiments of this application pertain. It should also be understood that terms such as those defined in general dictionaries should be understood to have a meaning consistent with their meaning in the context of the prior art, and should not be interpreted in an idealized or overly formal sense unless specifically defined as herein.

[0029] To aid in understanding this application, the terms used in the embodiments of this application are explained below:

[0030] Software-defined networking (SDN) is a network management approach that supports dynamically programmable network configuration, improving network performance and management efficiency, and enabling network services to offer flexible customization capabilities similar to cloud computing. SDN decouples the forwarding plane from the control plane of network devices, with the controller responsible for managing network devices, orchestrating network services, and scheduling service traffic.

[0031] Flow Tables: OpenFlow switches rely on flow tables during actual data forwarding. A flow table is a set of policy entries used by the OpenFlow switch to forward data, instructing the switch how to handle traffic. All packets entering the switch are forwarded according to the flow table. The generation, maintenance, and distribution of the flow table itself are entirely handled by the controller.

[0032] Flow entries in the flow table: Each flow entry in the OpenFlow flow table consists of Match Fields, Instructions, and other parts. The most important parts of a flow entry are the Match Fields and the Instructions. When an OpenFlow switch receives a data packet, it parses the packet header and matches it with the Match Fields of the flow entry in the flow table. If a match is found, the Instruction is executed.

[0033] Flow table distribution methods: OpenFlow flow table distribution can be proactive or reactive. In proactive mode, the controller actively distributes the flow table information it has collected to the OpenFlow switch, which can then directly forward packets based on the flow tables. In reactive mode, when an OpenFlow switch receives a packet and fails to query the flow table, it sends a message to the controller, which then decides how to forward the packet and calculates and distributes the corresponding flow table. In reactive mode, the switch does not need to maintain all flow tables; it only retrieves and stores flow table records from the controller when actual traffic occurs. The corresponding flow tables can be deleted after the aging timer expires, saving switch storage space.

[0034] Meter tables can be used for rate limiting in SDN. The principle of rate limiting is to drop redundant packets. First, a forwarding flow table is created. For example, the switch has a flow table that states: traffic coming in from port 1 goes out from port 2, in_port=1, actions=output:2. Then, a meter table is created, whose function is to drop traffic exceeding 10Mbps, meter=1, type=drop, rate=10000. Finally, the flow table is modified to use the meter table. in_port=1, actions=meter:1, output:2. This means that traffic coming in from port 1 will be processed by the meter table before being forwarded from port 2, dropping traffic exceeding 10Mbps before forwarding it to port 2. In addition, OpenFlow switches mainly include the following components: flow tables, group tables, meter tables, ports (physical or virtual ports), and OpenFlow channels connected to external controllers. In OpenFlow version 1.3, the Meter table was introduced, which can implement simple QoS similar to bandwidth limiting. Its implementation principle is to match and process packets through a user-defined flow table. Meter entries are referenced by flow table entries, and the flow table entries that reference meter entries provide packet rate limiting functionality.

[0035] With the high-quality development of network technology and the explosive growth of various emerging business types, the scale of networks in related technologies is expanding daily, and network architecture is becoming increasingly complex. While network technology brings convenience, it also harbors significant security risks, such as website intrusion, distributed denial-of-service attacks, virus intrusion, and abnormal traffic. Among these, abnormal attacks are one of the most common and threatening attack methods on the Internet. Attackers may send a large number of illegal requests to the target program, exhausting server resources in a short period of time, or overloading the infrastructure, making resources unsustainable, and causing system crashes. As attack techniques and hacking skills continue to improve, launching abnormal traffic attacks is becoming increasingly easy. Due to factors such as business competition and retaliation, many payment systems, game servers, chat networks, and other service providers have been plagued by abnormal traffic attacks. Abnormal traffic attacks not only reduce network performance and consume network resources, but may also cause enterprises to face economic losses and even legal risks. Therefore, there is an urgent need for a diagnostic monitoring model that can efficiently identify and analyze abnormal traffic to ensure network security and achieve healthy network operation.

[0036] In related technologies, traditional defense methods and deep learning-based methods are used to address abnormal traffic attacks. However, the following problems exist: 1) Poor network adaptability: Traditional passive defense technologies cannot cope with unknown network security threats and cannot take effective defensive measures before the network and information system are attacked or suffer serious losses. Furthermore, some methods require modifications to routing devices / network protocols themselves, while others require support from network service providers. 2) Method limitations: With the development of SDN technology, some attack methods incorporate SDN characteristics, but these methods have high technical requirements or can only target specific attacks. 3) Non-stationarity and data dependence: In the process of applying machine learning technology to defend against abnormal traffic attacks, attack patterns constantly change with the introduction of new protocols and applications. Sudden and seasonal traffic fluctuations further exacerbate this situation. This non-stationarity problem hinders the application of machine learning in defense. In addition, due to the complexity of the network environment and its reliance on large amounts of labeled data, traditional machine learning methods cannot guarantee the accuracy and efficiency of abnormal traffic detection.

[0037] To address the aforementioned issues, this application provides a modeling method for an abnormal traffic monitoring model. Figure 1 This application provides a flowchart illustrating a modeling method for an abnormal traffic monitoring model, as shown in the following embodiment. Figure 1 As shown, the method includes at least the following steps:

[0038] Step S101: Obtain the traffic state sequence of the target software-defined network (SDN) switch within the target window time; the traffic state sequence includes at least one of the following traffic types: attack traffic and legitimate traffic, wherein the attack traffic is used to send illegal request data packets to the target program; the legitimate traffic is used to send legitimate request data packets to the target program;

[0039] Here, the window time refers to the set of traffic flows input to the model at different times during the training of an abnormal traffic monitoring model, and it is also the step size of the abnormal traffic monitoring model. Here, the traffic state sequence refers to the traffic flow at each time point within the window time.

[0040] Here, the attack traffic involves sending a large number of illegal requests to the target program, exhausting the server's resources or overloading its infrastructure within a short period, ultimately causing the server to crash, reducing network performance, and consuming network resources. Examples include distributed system attacks or worm viruses.

[0041] Here, the legitimate traffic can be a legitimate request sent to the target program. For example, a search request sent to a search engine, or a request to a video website to obtain video information.

[0042] Step S102: Determine the first rate at which the attack traffic sends data packets and the second rate at which the legitimate traffic sends data packets;

[0043] Here, determining the first rate may include: comparing the attack traffic data packets sent in the previous window time with the attack traffic data packets sent in the current window time and taking the difference to obtain the first rate of the attack traffic data packets sent in the target window time.

[0044] Here, determining the second rate may include: comparing the legitimate traffic transmission data packets of the previous window time with the legitimate traffic transmission data packets of the current window time and taking the difference to obtain the second rate of the legitimate traffic transmission data packets of the target window time.

[0045] Step S103: Determine the abnormal flow monitoring model based on the variance of the first rate and the second rate.

[0046] Here, the variance can be used to control the changes in the first and second rates. For example, when the variance increases, the first rate is greater than the second rate, or vice versa.

[0047] In this embodiment, the abnormal traffic monitoring model is determined by the variance of the first rate and the second rate. This improves the learning efficiency and quality of the abnormal traffic monitoring model. The model is trained by gradually increasing the difficulty by progressively increasing the variance of the packet sending rates of attack traffic sent by attackers and legitimate traffic sent by normal users, thus blurring the difference between them. This achieves a more relaxed learning strategy and a gradual increase in difficulty, resolving the non-stationarity problem during model training.

[0048] Figure 2 A flowchart illustrating a modeling method for an abnormal traffic monitoring model provided in this application embodiment is shown below. Figure 2 As shown, the method includes at least the following steps:

[0049] Step S201: Obtain the traffic state sequence of the target software-defined network (SDN) switch within the target window time; the traffic state sequence includes at least one type of traffic: attack traffic and legitimate traffic, wherein the attack traffic is used to send illegal request data packets to the target program; the legitimate traffic is used to send legitimate request data packets to the target program;

[0050] Step S202: Determine the first rate at which the attack traffic sends data packets and the second rate at which the legitimate traffic sends data packets;

[0051] Step S203: Obtain the decay parameter of the variance;

[0052] Here, the decay parameter s can be used to influence the slope of variance decay. When s < 0, the smaller the absolute value of s, the gentler the decay. When s > 0, the smaller s, the steeper the decay.

[0053] Step S204: Based on the decay parameters, determine the time when the target variance is reached and the variance at each time point within the target window.

[0054] Here, the target variance time can be the time t at which the variance stabilizes. e The variance at each moment within the target window time can be calculated using formulas (1) to (4):

[0055] σ=σ max ×(1-δ) Formula (1);

[0056]

[0057]

[0058]

[0059] Here, α is 1 at t = 0 and decreases continuously over time; β determines the time t at which the variance stabilizes. e ,α-β at t e The value is 0 at time t = 0. From t = 0 to t e Over time, δ decreases from 1 to 0, and the variance increases from 0 to σ. max And it has remained fixed ever since.

[0060] Step S205: Based on the target variance and the variance at each time step, determine the attack traffic and the legitimate traffic at each time step;

[0061] Here, based on the target variance and the variance at each time step, the first rate at which attack traffic sends data packets and the second rate at which legitimate traffic sends data packets at each time step can be determined. This allows the determination of the attack traffic and legitimate traffic at each time step.

[0062] Step S206: Determine an abnormal traffic monitoring model based on at least one of the attack traffic and the legitimate traffic.

[0063] In one possible implementation, step S206, determining an abnormal traffic monitoring model based on at least one of the attack traffic and the legitimate traffic, includes:

[0064] Step S2061: Determine a reward / penalty function based on at least one of the attack traffic and the legitimate traffic;

[0065] Here, the reward and punishment function is used to calculate the reward value for the mitigation strategy of mitigating attack traffic and adjust the training process of the abnormal traffic monitoring model.

[0066] In one possible implementation, the attack traffic refers to the attack traffic arriving at the target port of the SDN switch at each moment within the target window time; the legitimate traffic refers to the legitimate traffic arriving at the target port of the SDN switch at each moment within the target window time; step S2061, determining a reward / penalty function based on at least one of the attack traffic and the legitimate traffic, includes: acquiring the legitimate traffic and attack traffic passing through the SDN switch at each moment; determining a first objective function based on the legitimate traffic arriving at the target port of the SDN switch at each moment and the legitimate traffic passing through the SDN switch at each moment; determining a second objective function based on the attack traffic arriving at the target port of the SDN switch at each moment and the attack traffic passing through the SDN switch at each moment; and determining a reward / penalty function based on the first objective function and the second objective function.

[0067] For example, in order to increase legitimate traffic reaching the server while reducing attack traffic, a reward function is introduced. linear By linearly combining the two objective functions, we obtain:

[0068]

[0069]

[0070]

[0071] in, It arrives at the switch port at time t. i Legitimate traffic, It is through the switch port at time t. i Legitimate traffic, These are attack traffic destinations at the switch ports. It involves attack traffic, with the ultimate goal of maximizing the proportion of legitimate traffic to the switch within a window of time T, where T includes multiple time points t. b Let p be the first objective function, i.e., the percentage of legitimate traffic passing through the switch within the window time. a The second objective function is the percentage of attack traffic passing through the switch within the window time, Z. t For legitimate traffic, U s This is the traffic threshold.

[0072] For example, reducing the attack traffic reaching the server means reducing the proportion of attack traffic in the traffic state sequence, thereby improving the model training efficiency. Further optimization and harmonization of the two first and second objective functions yields the optimized reward and penalty function as follows:

[0073]

[0074]

[0075] Among them, pre b It represents the proportion of legitimate traffic to total traffic through the switch; total traffic is the sum of legitimate traffic and attack traffic.

[0076] For example, if server traffic exceeds a threshold, the reward / penalty function is set to a penalty of -1, while allowing as much legitimate traffic as possible to reach the victim server if the threshold is not exceeded.

[0077] Step S2062: Obtain the target iteration round number and mitigation strategy; the mitigation strategy is used to handle the attack traffic;

[0078] Step S2063, iterative execution: process the attack traffic based on the mitigation strategy; determine the reward value for each mitigation strategy based on the reward and punishment function; update the abnormal traffic monitoring model based on each reward value until the target number of iterations is reached, and obtain the abnormal traffic monitoring model.

[0079] Here, the abnormal traffic detection model can be a DQN (Deep Q-Learning) network. The model performs self-learning, and its output uses a softmax function for traffic mitigation. The reward value for the mitigation strategy is determined based on a reward-penalty function, adjusting the training process of the abnormal traffic detection model. For example, in the parameters of the DQN network, the target number of iterations is an episode, which includes multiple steps. Each step assigns a mitigation strategy to the attack traffic. By training the abnormal traffic detection model through episodes, an optimal mitigation strategy is obtained.

[0080] For example, the attack traffic and the legitimate traffic are stored in a state set S, the mitigation strategies for handling the attack traffic are stored in an action set A, the obtained optimal mitigation strategy is stored in an experience replay pool, and the DQN network is a Q network. The training process of the Q network can be as follows: the target number of iterations is episode, the state set is S, the action set is A, and the maximum size of the experience replay pool is n. Step 1: Initialize the experience pool Memory D, initialize the Q network, and randomly generate the weight matrix. Initialize the traffic state. Step 2: Iterate through episodes and determine whether all episodes have been trained. Here, an episode refers to completing mitigation strategies for all types of traffic. A step refers to assigning a mitigation strategy to the attack traffic. If completed, we will obtain an optimal mitigation strategy; otherwise, proceed to step 3. Step 3: Determine whether all steps of this episode have been completed. If completed, return to step 2; otherwise, proceed to step 4. Step 4: Execute actions and observe the reward value and the next traffic state. Step 5: Update the traffic state and update the Q network parameters according to the new reward value. This process is repeated until all episodes have been trained, resulting in a convergent Q-network that accurately reflects the actual situation.

[0081] In one possible implementation, step S201, obtaining the traffic state sequence of the target software-defined network (SDN) switch within the target window time, includes:

[0082] Step S2011: Obtain the access address of the SDN controller and the location information of the target SDN switch connected to the SDN controller;

[0083] Here, the access address of the SDN controller can be a MAC address, used by the SDN switch to transmit information with the SDN controller based on the MAC address. Here, the SDN controller can construct the network topology based on the location information of different SDN switches.

[0084] Step S2012: Determine request parameters based on the access address and the location information; wherein, the request parameters are used to access the SDN controller to obtain the traffic status sequence of the target SDN switch.

[0085] In one possible implementation, the SDN controller can provide a southbound or northbound interface for information transmission with switches or application layer modules. For example, the SDN controller can provide a northbound interface to access the controller's REST API by constructing different request parameters to obtain traffic status sequences from different switches.

[0086] In this embodiment, on the one hand, a reward / penalty function is determined based on the first objective function and the second objective function. This can address the issue of unstable deep learning performance caused by non-stationary problems. On the other hand, through iterative execution: processing the attack traffic based on the mitigation strategy; determining the reward value for each mitigation strategy based on the reward / penalty function; and updating the abnormal traffic monitoring model based on each reward value, until the target number of iterations is reached to obtain the abnormal traffic monitoring model, the labeling of attack traffic and legitimate traffic can be reduced, simplifying the model training process and improving the efficiency of model training.

[0087] Figure 3 This is a flowchart illustrating an abnormal traffic monitoring method provided in an embodiment of this application, as shown below. Figure 3 As shown, the method includes at least the following steps:

[0088] Step S301: Obtain the traffic status sequence of the SDN switch and the bandwidth of the server accessing the SDN switch;

[0089] Here, the server bandwidth can be denoted as Us.

[0090] Step S302: Based on the traffic state sequence, use the abnormal traffic monitoring model to determine the attack traffic at the target time, wherein the abnormal traffic monitoring model is a model determined by the variance between the first rate of sending data packets through attack traffic and the second rate of sending data packets through legitimate traffic.

[0091] For example, the set of attack traffic output by the abnormal traffic monitoring model at the target time is: The output values ​​are normalized using the softmax function and converted into a vector set of [0, 1] . Here, by normalizing the output, the output traffic can be made to approach 0 rather than equal to 0, eliminating the need to set a minimum bandwidth limit and simplifying the process of abnormal traffic monitoring.

[0092] Step S303: Determine the bandwidth threshold for rate limiting based on the server bandwidth and the attack traffic at the target time.

[0093] Step S304: Determine abnormal traffic based on the bandwidth threshold of the rate limit.

[0094] In one possible implementation, step S304, determining abnormal traffic based on the bandwidth threshold of the rate limit, includes:

[0095] Step S3041: Limit the SDN switch based on the displayed bandwidth threshold to obtain the traffic after limiting the speed. Step S3042: Determine abnormal traffic based on the traffic after limiting the speed and the abnormal traffic data feature database, wherein the abnormal traffic database includes at least the traffic data features of network attacks and network security.

[0096] For example, the product of the processed vector and the server bandwidth Us can be used as the bandwidth threshold of the flow limiting entry (Meter entry) in the action. If the traffic of the SDN switch corresponding to the flow entry exceeds the bandwidth of the corresponding Meter, the excess traffic exceeding the bandwidth threshold is discarded.

[0097] In the above embodiments, a bandwidth threshold for rate limiting is determined based on the server bandwidth and the attack traffic at the target time; abnormal traffic is then identified based on the bandwidth threshold for rate limiting. In this way, by using the bandwidth threshold for rate limiting, the probability of traffic exceeding the server bandwidth is reduced, thereby reducing the probability of traffic flooding.

[0098] This application provides a modeling method for an abnormal traffic monitoring model, the method being as follows: Figure 4 The architecture implementation shown is as follows: Figure 4 As shown, SDN switch 401 interacts with user 402, who includes an attacker, to request data from server 403 based on user 402's access request. During the interaction with server 403, agent 404 determines a reward or penalty value based on a reward / penalty function and feeds the reward or penalty value back to the switch, improving the switch's ability to handle attack traffic using mitigation strategies.

[0099] based on Figure 4 The architecture shown in this application provides a modeling apparatus for an abnormal traffic monitoring model. Figure 5 This is a schematic diagram of the composition structure of a modeling device for an abnormal traffic monitoring model provided in an embodiment of this application; as shown below. Figure 5 As shown, the device 500 includes an application layer, a control layer, and a data forwarding layer; it also includes a data plane and a control plane. The application layer is implemented using a configuration module 501, a data acquisition and preprocessing module 502, a reinforcement learning module 503, an abnormal traffic alarm module 504, and a policy distribution module 505.

[0100] The configuration module 501 is used to check the software versions used in the data plane and control plane to ensure that the network environment meets the required requirements, the configuration information is successfully distributed, and the system operation requirements are met. Figure 6A As shown, the configuration module is used to perform the following steps:

[0101] Step S601: Start network environment information detection;

[0102] Step S602: Obtain the network structure diagram and OpenFlow switch information;

[0103] Here, the network structure diagram is the topology information of the network, used to locate the position information of the switches connected to the network and extract the port information of the connected switches.

[0104] Step S603: Generate and distribute Meter table entries;

[0105] Here, the Meter table entries are distributed by calling the northbound REST API of the control plane to prepare for rate limiting of traffic.

[0106] Step S604: Generate and distribute Flow entries;

[0107] Here, after analyzing the switch information and the Meter table, the corresponding Flow table entries are automatically generated. The Flow table entries are then bound to the corresponding Meter table entries, and the Flow table entries are distributed by calling the northbound interface REST API of the control plane.

[0108] Step S605: Complete pre-configuration.

[0109] Here, if the network environment meets the requirements, the configuration process ends. Otherwise, continue to step S603.

[0110] The data acquisition and preprocessing module 502 is used to install OpenFlow protocol-related plugins to obtain the traffic information required by the system. This traffic information includes at least legitimate traffic and attack traffic. A corresponding OpenFlow protocol request message is generated, which is sent to the specified SDN data plane via the SDN controller. Then, traffic statistics information of the SDN data plane is obtained by calling the northbound REST API provided by the SDN controller. Figure 6B As shown, the data acquisition and preprocessing module 502 is used to perform the following steps:

[0111] Step S610: Read the initialization configuration information;

[0112] Here, the initialization configuration information includes: the access address of the SDN controller, the type and access address of the SDN controller REST API, the parameters required to request the SDN controller REST API and the returned results, and network topology information (mainly the access addresses of access switches and their positions in the network topology). To ensure that the time of each data request does not accumulate errors, a timer is added. The timer calculates a new start time before each data request, and sleeps after completing the data request and obtaining the corresponding data until the start time calculated at the beginning.

[0113] Step S620: Obtain flow table statistics (flow information / flow status sequence);

[0114] Here, different request parameters are constructed to access the REST API provided by the controller to obtain flow table statistics (traffic state sequences) of different switches, mainly including: flow table packet count (flow_packets), flow table byte count (flow_bytes), flow table live time (flow_seconds), flow table live time (flow_nanoSeconds), etc. Finally, the corresponding parameters are constructed by looping through to obtain the current network traffic statistics. Port traffic statistics are obtained by parsing the request and returning a single JSON file, mainly including the number of packets received by the port (inp_packets), the number of bytes received by the port (inp_bytes), the number of packets transmitted by the port (outp_packets), the number of bytes transmitted by the port (outp_bytes), etc. All the statistics are merged to form a feature set.

[0115] Step S630: Process traffic information to generate a feature set for a deep learning network (abnormal traffic monitoring model).

[0116] Here, when an abnormal traffic attack occurs, there is a correlation between the number of traffic packets passing through the switch port and flow table, the total number of bytes of data, and the time when these data changes. This system mainly focuses on changes in traffic information, so it obtains traffic changes through a statistical window time method. The specific steps are: comparing the traffic statistics of the above characteristics in the previous window time with the traffic statistics of the current window time and taking the difference to obtain the rate of change of traffic in the target window time. At the same time, the step size in the deep reinforcement learning model (abnormal traffic monitoring model) is set to be equal to the size of the target window time. Finally, the processed feature values ​​are used as the input feature set of the deep reinforcement learning model.

[0117] The reinforcement learning module 503 is used to take the feature set as input to the deep reinforcement learning module, optimize the output using the softmax function to achieve easing, and increase the proportion of legitimate traffic in the total network load of the target server through a custom reward and punishment function, thereby achieving adaptive adjustment of the model. The load includes legitimate traffic, attack traffic, and pending requests. The adjustment process is as follows: Figure 6C As shown:

[0118] Step S61: Determine the action (mitigation strategy) based on the state (traffic state sequence);

[0119] Step S62: Based on the reward and punishment function, determine the reward and punishment value of the mitigation strategy and update the network parameters.

[0120] Here, since the network parameters are updated iteratively each time, the network initialization needs to clear the network traffic information (traffic state sequence) and actions (mitigation strategies) left over from the previous training round.

[0121] The abnormal traffic alarm module 504 is used to compare the features output by the deep learning model through the softmax function with the abnormal traffic data feature library. If they match, the traffic is identified as abnormal, and alarm information is provided for the identified abnormal traffic and abnormal links. The abnormal traffic data feature library includes traffic data features related to network attacks and network security; the network attack behavior features include DDoS attacks and worm viruses, and support custom updates.

[0122] The policy distribution module 505 is used to obtain action information from the output of the deep reinforcement learning model, read parameter information of the SDN controller's northbound interface REST API from the configuration, and the sequence number of the SDN switch in the network topology. It constructs and compares the REST API parameters; if not updated, it performs an update operation; if the update fails, it retryes. This converts the actions output by the deep learning model into Meter table update operations. The policy is then distributed to the SDN data plane via the SDN controller. Based on the distributed rule information, the SDN data plane can drop or rate-limit malicious attack traffic.

[0123] In this embodiment, on the one hand, by leveraging the SDN controller's understanding and control of the global network, the required network traffic information can be statistically analyzed by strategically distributing flow tables to the SDN data plane without modifying the network's data plane or control plane. Feedback from the model's output reward value incentivizes the SDN data layer to rate-limit or drop attack traffic, achieving efficient attack traffic mitigation. At the application level, the system can interact with the SDN data plane via the OpenFlow protocol's northbound REST API provided by the SDN control plane, achieving better scalability and portability. On the other hand, an abnormal traffic alarm module dynamically updates the abnormal traffic database to detect the network in real time, providing real-time monitoring and alarm services for abnormal traffic requiring special attention, thus enhancing network security. Furthermore, by limiting bandwidth using the softmax function and proposing a reward / penalty function based on linear combination and considering efficiency, dynamic flow mitigation is implemented, exhibiting stronger robustness against unknown attack patterns. Moreover, the training process does not require a large amount of labeled dataset, resulting in a model with strong scalability and adaptability, and it does not require complex environments or highly skilled personnel, leading to a well-converged model.

[0124] Based on the foregoing embodiments, this application further provides a modeling device for an abnormal traffic monitoring model. The control device includes all the modules included, which can be implemented by a processor in an electronic device; of course, it can also be implemented by specific logic circuits. In the implementation process, the processor can be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.

[0125] Figure 7 This is a schematic diagram of the composition structure of a modeling device for an abnormal traffic monitoring model provided in an embodiment of this application, as shown below. Figure 7 As shown, the device 700 includes an acquisition module 701 and a determination module 702, wherein:

[0126] The acquisition module 701 is used to acquire the traffic state sequence of the target software-defined network (SDN) switch within the target window time; the traffic state sequence includes at least one of the following traffic types: attack traffic and legitimate traffic, wherein the attack traffic is used to send illegal request data packets to the target program; and the legitimate traffic is used to send legitimate request data packets to the target program.

[0127] The determination module 702 is used to determine the first rate at which the attack traffic sends data packets and the second rate at which the legitimate traffic sends data packets; and to determine an abnormal traffic monitoring model based on the variance of the first rate and the second rate.

[0128] In some possible embodiments, the determining module 702 is further configured to: obtain the decay parameter of the variance; determine the time when the target variance is reached and the variance at each time point within the target window based on the decay parameter; determine the attack traffic and the legitimate traffic at each time point based on the time of the target variance and the variance at each time point; and determine an abnormal traffic monitoring model based on at least one of the attack traffic and the legitimate traffic.

[0129] In some possible embodiments, the determining module 702 is further configured to: determine a reward / penalty function based on at least one of the attack traffic and the legitimate traffic; obtain a target iteration round number and a mitigation strategy; the mitigation strategy is used to handle the attack traffic; iteratively execute: handle the attack traffic based on the mitigation strategy; determine a reward value for each of the mitigation strategies based on the reward / penalty function; update the abnormal traffic monitoring model based on each of the reward values ​​until the target iteration round number is reached, thereby obtaining the abnormal traffic monitoring model.

[0130] In some possible embodiments, the attack traffic refers to the attack traffic arriving at the target port of the SDN switch at each moment within the target window time; the legitimate traffic refers to the legitimate traffic arriving at the target port of the SDN switch at each moment within the target window time; the determining module 702 is further configured to: acquire the legitimate traffic and attack traffic passing through the SDN switch at each moment; determine a first objective function based on the legitimate traffic arriving at the target port of the SDN switch at each moment and the legitimate traffic passing through the SDN switch at each moment; determine a second objective function based on the attack traffic arriving at the target port of the SDN switch at each moment and the attack traffic passing through the SDN switch at each moment; and determine a reward / penalty function based on the first objective function and the second objective function.

[0131] In some possible embodiments, the acquisition module 701 is further configured to: acquire the access address of the SDN controller and the location information of the target SDN switch connected to the SDN controller; determine request parameters based on the access address and the location information; wherein the request parameters are used to access the SDN controller to obtain the traffic status sequence of the target SDN switch.

[0132] Figure 8 This is a schematic diagram of the composition structure of an abnormal flow monitoring device provided in an embodiment of this application, as shown below. Figure 8As shown, the device 800 includes an acquisition module 801 and a determination module 802, wherein:

[0133] The acquisition module 801 is used to acquire the traffic status sequence of the SDN switch and the bandwidth of the server accessing the SDN switch;

[0134] The determination module 802 is used to determine the attack traffic at a target time based on the traffic state sequence and using an abnormal traffic monitoring model, wherein the abnormal traffic monitoring model is a model determined by the variance between a first rate at which data packets are sent through attack traffic and a second rate at which data packets are sent through legitimate traffic; determine a bandwidth threshold for rate limiting based on the server bandwidth and the attack traffic at the target time; and determine abnormal traffic based on the bandwidth threshold for rate limiting.

[0135] In some possible embodiments, the determining module 802 is further configured to: rate-limit the SDN switch based on the displayed bandwidth threshold to obtain the rate-limited traffic; and determine abnormal traffic based on the rate-limited traffic and an abnormal traffic data feature database, wherein the abnormal traffic database includes at least: traffic data features of network attacks and network security.

[0136] It should be noted that the descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0137] It should be noted that, in the embodiments of this application, if the above methods are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0138] Correspondingly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of any of the methods described in the above embodiments.

[0139] Correspondingly, in this embodiment of the application, a chip is also provided, the chip including programmable logic circuits and / or program instructions, which, when the chip is running, are used to implement the steps in any of the methods described in the above embodiments.

[0140] Correspondingly, in this embodiment of the application, a computer program product is also provided, which, when executed by the processor of an electronic device, is used to implement the steps in any of the methods described in the above embodiments.

[0141] Based on the same technical concept, this application provides an electronic device for implementing the method described in the above-described method embodiments. Figure 9 This is a hardware entity diagram of an electronic device provided in an embodiment of this application, such as... Figure 9 As shown, the electronic device 900 includes a memory 910 and a processor 920. The memory 910 stores a computer program that can run on the processor 920. When the processor 920 executes the program, it implements the steps in any of the methods described in the embodiments of this application.

[0142] The memory 910 is configured to store instructions and applications executable by the processor 920, and can also cache data to be processed or already processed by the processor 920 and various modules in the electronic device (e.g., image data, audio data, voice communication data and video communication data), which can be implemented by flash memory or random access memory (RAM).

[0143] When the processor 920 executes the program, it implements the steps of any of the methods described above. The processor 920 typically controls the overall operation of the electronic device 900.

[0144] The aforementioned processor can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), Controller, Microcontroller, and Microprocessor. It is understood that other electronic devices can also implement the functions of the aforementioned processor, and this application does not specifically limit the specific implementation.

[0145] The aforementioned computer storage media / memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM), etc.; or it can be various electronic devices that include one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.

[0146] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0147] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that in the various embodiments of this application, the sequence numbers of the above-described processes do not imply a sequential order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. The sequence numbers of the above-described embodiments are merely descriptive and do not represent the superiority or inferiority of the embodiments.

[0148] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0149] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0150] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units. They may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of the embodiments of this application, depending on actual needs.

[0151] In addition, each functional unit in the various embodiments of this application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0152] Alternatively, if the integrated units described above are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of this application, or the parts that contribute to related technologies, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause the device automatic test line to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROMs, magnetic disks, or optical disks.

[0153] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0154] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0155] The above description is merely an embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A modeling method for an abnormal traffic monitoring model, characterized in that, The method includes: Obtain the traffic state sequence of the target software-defined network (SDN) switch within the target window time; the traffic state sequence includes: attack traffic and legitimate traffic, wherein the attack traffic is used to send illegal request data packets to the target program; the legitimate traffic is used to send legitimate request data packets to the target program; Determine the first rate at which the attack traffic sends data packets and the second rate at which the legitimate traffic sends data packets; Obtain the decay parameter of the variance between the first rate and the second rate; Based on the decay parameters, determine the time when the target variance is reached and the variance at each time point within the target window. Based on the target variance time and the change process of the variance at each time from the initial time to the target variance time over time, the attack traffic and the legitimate traffic at each time are determined; An abnormal traffic monitoring model is determined based on at least one of the attack traffic and the legitimate traffic.

2. The method as described in claim 1, characterized in that, The process of determining the abnormal traffic monitoring model based on at least one of the attack traffic and the legitimate traffic includes: The reward / penalty function is determined based on at least one of the attack traffic and the legitimate traffic; Obtain the target iteration round number and mitigation strategy; the mitigation strategy is used to handle the attack traffic. Iterative execution: Process the attack traffic based on the mitigation strategy; determine the reward value for each mitigation strategy based on the reward and penalty function; update the abnormal traffic monitoring model based on each reward value until the target number of iterations is reached, thereby obtaining the abnormal traffic monitoring model.

3. The method as described in claim 2, characterized in that, The attack traffic refers to the attack traffic arriving at the target port of the SDN switch at each moment within the target window time; the legitimate traffic refers to the legitimate traffic arriving at the target port of the SDN switch at each moment within the target window time. The determination of the reward / penalty function based on at least one of the attack traffic and the legitimate traffic includes: Obtain the legitimate traffic and attack traffic passing through the SDN switch at each specific moment; The first objective function is determined based on the legitimate traffic arriving at the target port of the SDN switch at each time and the legitimate traffic passing through the SDN switch at each time. The second objective function is determined based on the attack traffic arriving at the target port of the SDN switch at each time and the attack traffic passing through the SDN switch at each time. Based on the first objective function and the second objective function, the reward and punishment function is determined.

4. The method according to any one of claims 1 to 3, characterized in that, The acquisition of the traffic state sequence of the target software-defined network (SDN) switch within the target window time includes: Obtain the access address of the SDN controller and the location information of the target SDN switch connected to the SDN controller; Based on the access address and the location information, request parameters are determined; wherein, the request parameters are used to access the SDN controller to obtain the traffic status sequence of the target SDN switch.

5. A method for monitoring abnormal flow, characterized in that, The method includes: Obtain the traffic status sequence of the SDN switch and the bandwidth of the server connected to the SDN switch; Based on the traffic state sequence, the attack traffic at the target time is determined using an abnormal traffic monitoring model, wherein the abnormal traffic monitoring model is modeled using the modeling method of the abnormal traffic monitoring model described in claim 1. Based on the server bandwidth and the attack traffic at the target time, determine the bandwidth threshold for rate limiting; The SDN switch is rate-limited based on the bandwidth threshold of the rate limit to obtain the rate-limited traffic. Based on the traffic flow after the rate limit and the abnormal traffic data feature library, abnormal traffic is determined, wherein the abnormal traffic data feature library includes at least: traffic data features of network attacks and network security.

6. A modeling device for an abnormal flow monitoring model, characterized in that, The device includes: The acquisition module is used to acquire the traffic status sequence of the target software-defined network (SDN) switch within the target window time; the traffic status sequence includes: attack traffic and legitimate traffic, wherein the attack traffic is used to send illegal request data packets to the target program; and the legitimate traffic is used to send legitimate request data packets to the target program. A determination module is configured to: determine a first rate at which the attack traffic sends data packets and a second rate at which the legitimate traffic sends data packets; obtain a decay parameter of the variance between the first rate and the second rate; based on the decay parameter, determine the time when the target variance is reached and the variance at each time point within the target window; based on the time of the target variance and the change process of the variance at each time point from the initial time to the target variance time point over time, determine the attack traffic and the legitimate traffic at each time point; and based on at least one of the attack traffic and the legitimate traffic, determine an abnormal traffic monitoring model.

7. An abnormal flow monitoring device, characterized in that, The device includes: The acquisition module is used to acquire the traffic status sequence of the SDN switch and the bandwidth of the server accessing the SDN switch; The determination module is used to determine the attack traffic at a target time based on the traffic state sequence and using an abnormal traffic monitoring model, wherein the abnormal traffic monitoring model is modeled using the modeling method of the abnormal traffic monitoring model described in claim 1; determine a bandwidth threshold for rate limiting based on the server bandwidth and the attack traffic at the target time; rate limit the SDN switch based on the bandwidth threshold for rate limiting to obtain the rate-limited traffic; and determine abnormal traffic based on the rate-limited traffic and an abnormal traffic data feature library, wherein the abnormal traffic data feature library includes at least: traffic data features of network attacks and network security.

8. An electronic device comprising a memory and a processor, the memory storing a computer program executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Sparse negative sample-oriented anomaly detection method, model construction method and device

    CN114443338A

  • Business data processing method and device, electronic equipment and storage medium

    CN115034400A