Iptable-based traffic filtering control method and system
Patent Information
- Application Number
- CN202311425968.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-31
- Publication Date
- 2026-08-18
- Estimated Expiration
- 2043-10-31
AI Technical Summary
其中,流量攻击主要是在短时间内向用户端发送大量SYN包,使得用户端处于数据包接收极限状态,导致用户端发生死机等问题
Smart Images

Figure CN117560174B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet networks, and more particularly to a traffic filtering control method and system based on iptables. Background Technology
[0002] Once smartphones or laptops connect to the internet, they are inevitably vulnerable to attacks, including but not limited to Trojan virus attacks and DDoS attacks. DDoS attacks primarily involve sending a large number of SYN packets to the user's device within a short period, pushing it to its data packet reception limit and causing crashes or other problems. To prevent DDoS attacks, firewalls or protection software are typically installed on the user's device. However, these firewalls or protection software require regular updates to ensure effective and comprehensive blocking of DDoS attacks, increasing the cost of DDoS protection. Furthermore, they cannot quickly and accurately filter and control network traffic, nor can they reduce the load on the user's device receiving data from the network. Summary of the Invention
[0003] The purpose of this invention is to provide a traffic filtering control method and system based on iptables. Based on the data input attribute information of all input network links within the network from the user end, it sets up iptables proxies on all input network links, classifying them into corresponding security frameworks. Using the iptables proxies, it obtains the data flow status information of the input network links to determine whether abnormal data traffic events have occurred, and obtains the attribute information of the abnormal data packets from the input network links where abnormal data traffic events have occurred, thereby determining the components of the data packets that need to be blocked by traffic filtering. After filtering the input network links where abnormal data traffic events have occurred, based on the results of the filtering, it adjusts the working state of the input network links where abnormal data traffic events have occurred. This allows for accurate and comprehensive traffic control at the user end without the need for a firewall within the user end, reducing the data traffic reception load on the user end.
[0004] This invention is achieved through the following technical solution:
[0005] iptables-based traffic filtering control methods include:
[0006] Based on the network status information of the user terminal's current connection, all input network links of the user terminal within the network are determined; the input network links are identified to obtain the data input attribute information of the input network links, and based on the data input attribute information, corresponding iptables proxies are set for all input network links;
[0007] Based on the iptables proxy, the data flow status information of the input network link is obtained; the data flow status information is analyzed to determine whether an abnormal data traffic event has occurred in the input network link; the abnormal data flow component identification processing is performed on the input network link where an abnormal data traffic event has occurred to obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred.
[0008] Based on the abnormal data packet attribute information, traffic filtering is performed on the input network link where the data traffic anomaly event occurred; and based on the result of the traffic filtering, the working state of the input network link where the data traffic anomaly event occurred is adjusted.
[0009] Optionally, based on the network status information of the user terminal's current connection, all input network links within the network of the user terminal are determined; the input network links are identified to obtain data input attribute information of the input network links, and based on the data input attribute information, corresponding iptables proxies are set for all input network links, including:
[0010] Based on the network gateway address currently accessed by the user terminal, determine all network links currently connected to the user terminal; then, based on the uplink and downlink data transmission volumes of each network link, determine all input network links of the user terminal within the network.
[0011] The input network links are identified to obtain the data input speed information of the input network links. Based on the data input speed information, all input network links are divided into several input network link sets. Among them, the data input speeds of all input network links under each input network link set are within the same data input speed range, and the data input speed ranges corresponding to different input network link sets are different from each other.
[0012] Based on the data input speed range corresponding to each set of input network links, set up an iptables proxy with matching data processing speed for each set of input network links.
[0013] Optionally, based on the iptables proxy, the data flow status information of the input network link is obtained; the data flow status information is analyzed to determine whether an abnormal data traffic event has occurred on the input network link; abnormal data flow component identification processing is performed on the input network link where an abnormal data traffic event has occurred to obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred, including:
[0014] Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. The data stream samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link, which are used as the data stream status information of the input network link.
[0015] Based on the source address information and the transmission frequency information, it is determined whether a SYN packet traffic attack anomaly event has occurred on the input network link; SYN packet transmission time identification processing is performed on the input network link where a SYN packet traffic attack anomaly event has occurred to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event has occurred.
[0016] Optionally, based on the abnormal data packet attribute information, traffic filtering is performed on the input network link where the data traffic anomaly event occurred; and based on the result of the traffic filtering, the operating state of the input network link where the data traffic anomaly event occurred is adjusted, including:
[0017] Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly occurred, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly occurred; the average data traffic value after the SYN packet interception processing of the input network link where the SYN packet traffic attack anomaly occurred is obtained; if the average data traffic value is greater than or equal to a preset traffic threshold, then the transmission of data from the input network link where the SYN packet traffic attack anomaly occurred to the user terminal is stopped; otherwise, the current data transmission status of the input network link where the SYN packet traffic attack anomaly occurred to the user terminal remains unchanged.
[0018] An iptables-based traffic filtering control system includes:
[0019] The user-end network link identification module is used to determine all input network links of the user-end within the network based on the network status information currently connected to the user-end.
[0020] The iptables proxy setting module is used to identify the input network links, obtain the data input attribute information of the input network links, and set corresponding iptables proxies for all input network links based on the data input attribute information.
[0021] The data traffic anomaly event judgment module is used to obtain the data flow status information of the input network link based on the iptables proxy; analyze the data flow status information, and determine whether a data traffic anomaly event has occurred on the input network link;
[0022] The abnormal data packet identification module is used to identify the abnormal data stream components of the input network link where an abnormal data traffic event has occurred, and to obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred.
[0023] The traffic filtering module is used to filter the traffic of the input network link where the abnormal data packet attribute information has occurred.
[0024] The network link working status adjustment module is used to adjust the working status of the input network link where a data traffic abnormality event has occurred, based on the result of the traffic filtering.
[0025] Optionally, the user-end network link identification module is used to determine all input network links of the user-end within the network based on the network status information currently connected to the user-end, including:
[0026] Based on the network gateway address currently accessed by the user terminal, determine all network links currently connected to the user terminal; then, based on the uplink and downlink data transmission volumes of each network link, determine all input network links of the user terminal within the network.
[0027] The iptables proxy setting module is used to identify the input network links, obtain the data input attribute information of the input network links, and set corresponding iptables proxies for all input network links based on the data input attribute information, including:
[0028] The input network links are identified to obtain the data input speed information of the input network links. Based on the data input speed information, all input network links are divided into several input network link sets. Among them, the data input speeds of all input network links under each input network link set are within the same data input speed range, and the data input speed ranges corresponding to different input network link sets are different from each other.
[0029] Based on the data input speed range corresponding to each set of input network links, set up an iptables proxy with matching data processing speed for each set of input network links.
[0030] Optionally, the data traffic anomaly event judgment module is used to obtain data flow status information of the input network link based on the iptables proxy; analyze the data flow status information to determine whether a data traffic anomaly event has occurred on the input network link, including:
[0031] Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. The data stream samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link, which are used as the data stream status information of the input network link.
[0032] Based on the source address information and the transmission frequency information, determine whether a SYN packet traffic attack anomaly is currently occurring on the input network link;
[0033] The abnormal data packet identification module is used to perform abnormal data flow component identification processing on the input network link where an abnormal data traffic event has occurred, and obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred, including:
[0034] The SYN packet transmission time is processed on the input network link where the SYN packet traffic attack anomaly event occurs to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event occurs.
[0035] Optionally, the traffic filtering module is used to perform traffic filtering on the input network link where a data traffic anomaly event has occurred based on the abnormal data packet attribute information, including:
[0036] Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly event occurred, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly event occurred.
[0037] The network link operating status adjustment module is used to adjust the operating status of the input network link where a data traffic anomaly event has occurred based on the results of the traffic filtering, including:
[0038] The system obtains the average data traffic value after SYN packet interception processing on the input network link where the SYN packet traffic attack anomaly occurred. If the average data traffic value is greater than or equal to a preset traffic threshold, the system stops the input network link where the SYN packet traffic attack anomaly occurred from transmitting data to the user terminal; otherwise, the system maintains the current data transmission status of the input network link where the SYN packet traffic attack anomaly occurred to the user terminal.
[0039] Compared with the prior art, the present invention has the following beneficial effects:
[0040] The iptables-based traffic filtering control method and system provided in this application, based on the data input attribute information of all input network links within the user's network, sets up iptables proxies for all input network links, classifying the input network links into corresponding security frameworks. Using the iptables proxies, it obtains the data flow status information of the input network links to determine whether abnormal data traffic events have occurred, and obtains the attribute information of the abnormal data packets of the input network links where abnormal data traffic events have occurred, thereby determining the components of the data packets that need to be blocked by traffic filtering. After filtering the input network links where abnormal data traffic events have occurred, the working state of the input network links where abnormal data traffic events have occurred is adjusted based on the results of the traffic filtering. This allows for accurate and comprehensive traffic control at the user's end without the need to set up a firewall within the user's network, reducing the data traffic reception load at the user's end. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:
[0042] Figure 1 This is a flowchart illustrating the iptables-based traffic filtering control method provided by the present invention.
[0043] Figure 2 This is a schematic diagram of the iptables-based traffic filtering control system provided by the present invention. Detailed Implementation
[0044] To make the above-mentioned objectives, features, and advantages of this application more apparent and understandable, the specific embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of this application. Furthermore, it should be noted that, for ease of description, only the parts relevant to this application are shown in the accompanying drawings, not the entire structure. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this application.
[0045] The terms “comprising” and “having”, and any variations thereof, used in this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.
[0046] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0047] Please see Figure 1 As shown, an embodiment of this application provides a traffic filtering control method based on iptables, which includes:
[0048] Based on the network status information of the user terminal's current connection, determine all input network links of the user terminal within the network; identify the input network links to obtain the data input attribute information of the input network links, and set corresponding iptables proxies for all input network links based on the data input attribute information;
[0049] Based on the iptables proxy, the data flow status information of the input network link is obtained; the data flow status information is analyzed to determine whether an abnormal data traffic event has occurred in the input network link; the abnormal data flow component identification processing is performed on the input network link where an abnormal data traffic event has occurred to obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred.
[0050] Based on the attribute information of the abnormal data packet, traffic filtering is performed on the input network link where the data traffic anomaly event occurred; and based on the result of the traffic filtering, the working status of the input network link where the data traffic anomaly event occurred is adjusted.
[0051] The beneficial effects of the above embodiments are that the iptables-based traffic filtering control method sets up iptables proxies on all input network links within the network based on the data input attribute information of all input network links at the user end, classifying the input network links into corresponding security frameworks; using the iptables proxies, it obtains the data flow status information of the input network links to determine whether abnormal data traffic events have occurred on the input network links, and obtains the abnormal data packet attribute information of the input network links where abnormal data traffic events have occurred, thereby determining the data packet components that need to be blocked by traffic filtering on the input network links; after traffic filtering on the input network links where abnormal data traffic events have occurred, the working state of the input network links where abnormal data traffic events have occurred is adjusted based on the results of traffic filtering, enabling accurate and comprehensive traffic control at the user end without the need to set up a firewall inside the user end, reducing the data traffic receiving load of the user end.
[0052] In another embodiment, based on the network status information currently connected to the user terminal, all input network links within the network for the user terminal are determined; the input network links are identified to obtain their data input attribute information; and based on this data input attribute information, corresponding iptables proxies are set for all input network links, including:
[0053] Based on the network gateway address currently accessed by the user terminal, determine all network links currently connected to the user terminal; then, based on the uplink and downlink data transmission volumes of each of the network links, determine all input network links of the user terminal within the network.
[0054] The input network link is identified to obtain its data input speed information. Based on this data input speed information, all input network links are divided into several input network link sets. Among them, the data input speeds of all input network links under each input network link set are within the same data input speed range, and the data input speed ranges corresponding to different input network link sets are different from each other.
[0055] Based on the data input speed range corresponding to each set of input network links, set up an iptables proxy with matching data processing speed for each set of input network links.
[0056] The beneficial effects of the above embodiments are as follows: After a user terminal such as a smartphone or portable computer connects to the network, it forms network links with other terminals within the network. Based on the network gateway address currently accessed by the user terminal, all network links currently formed by the user terminal within the network are determined. Then, the uplink data transmission volume and downlink data transmission volume of each network link are obtained. If the uplink data transmission volume is less than a first preset data volume threshold and the downlink data transmission volume is greater than a second preset data volume threshold, then it is determined that the network link belongs to the user terminal's input network link (i.e., the network link receiving data from other terminals) within the network. Each input network link is then identified to obtain the average data input speed (i.e., data input speed information) of each input network link. Based on the average data input speed of each input network link, all input network links are divided into several input network link sets, such that the data input speed of all input network links under each input network link set is within the same data input speed range, and the data input speed ranges corresponding to different input network link sets are different from each other. Thus, all input network links are classified according to the speed of their average data input speed. In addition, based on the data input speed range corresponding to each input network link set, an iptables proxy with matching data processing speed is set for each input network link set, so that the set iptables proxy can perform fair and continuous traffic filtering and interception on all input network links under the corresponding input network link set.
[0057] In another embodiment, based on the iptables proxy, data flow status information of the input network link is obtained; the data flow status information is analyzed to determine whether an abnormal data traffic event has occurred on the input network link; abnormal data flow component identification processing is performed on the input network link where an abnormal data traffic event has occurred to obtain abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred, including:
[0058] Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. The data stream samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link, which are used as the data stream status information of the input network link.
[0059] Based on the source address information and the transmission frequency information, it is determined whether a SYN packet traffic attack anomaly event has occurred on the input network link; SYN packet transmission time identification processing is performed on the input network link where a SYN packet traffic attack anomaly event has occurred to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event has occurred.
[0060] The beneficial effects of the above embodiments are as follows: Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. These samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link. Combining this information with the source address information and transmission frequency information of all SYN packets transmitted in the input network link, it is determined whether the transmission frequency of SYN packets from the same source in the input network link exceeds a preset frequency threshold. If so, it is determined that a SYN packet traffic attack anomaly event has occurred on the input network link; otherwise, it is determined that no SYN packet traffic attack anomaly event has occurred on the input network link. This allows for accurate identification and determination of whether the input network link is under traffic attack. Furthermore, SYN packet transmission time identification processing is performed on the input network link where a SYN packet traffic attack anomaly event has occurred to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event has occurred. This facilitates subsequent targeted and accurate filtering and interception of SYN packets associated with traffic attacks in the input network link where the SYN packet traffic attack anomaly event has occurred.
[0061] In another embodiment, based on the abnormal data packet attribute information, traffic filtering is performed on the input network link where the data traffic anomaly event occurred; and based on the result of the traffic filtering, the operating state of the input network link where the data traffic anomaly event occurred is adjusted, including:
[0062] Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly occurred, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly occurred; the average data traffic value after the SYN packet interception processing of the input network link where the SYN packet traffic attack anomaly occurred is obtained. If the average data traffic value is greater than or equal to a preset traffic threshold, the data transmission from the input network link where the SYN packet traffic attack anomaly occurred to the user terminal is stopped; otherwise, the current data transmission status of the input network link where the SYN packet traffic attack anomaly occurred to the user terminal remains unchanged.
[0063] The beneficial effects of the above embodiments are as follows: Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly occurred. That is, targeted SYN packet interception processing is performed only on the input network link at a specific transmission time point, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly occurred and reducing the data reception load of the user terminal. Furthermore, the average data traffic value after SYN packet interception processing of the input network link where the SYN packet traffic attack anomaly occurred is obtained, and the average data traffic value is compared with a preset traffic threshold. This stops the input network link where the SYN packet traffic attack anomaly occurred from transmitting data to the user terminal, or keeps the current data transmission state of the input network link where the SYN packet traffic attack anomaly occurred unchanged, thereby ensuring normal data transmission of the input network link while avoiding traffic attacks.
[0064] Please see Figure 2 As shown, an embodiment of this application provides a traffic filtering control system based on iptables, including:
[0065] The user-end network link identification module is used to determine all input network links of the user-end within the network based on the network status information of the user-end's current connection.
[0066] The iptables proxy setting module is used to identify the input network link, obtain the data input attribute information of the input network link, and set the corresponding iptables proxy for all input network links based on the data input attribute information;
[0067] The data traffic anomaly event judgment module is used to obtain the data flow status information of the input network link based on the iptables proxy; analyze the data flow status information to determine whether a data traffic anomaly event has occurred on the input network link;
[0068] The abnormal data packet identification module is used to identify the abnormal data stream components of the input network link where an abnormal data traffic event has occurred, and to obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred.
[0069] The traffic filtering module is used to filter the traffic of the input network link where the abnormal data packet event occurred based on the attribute information of the abnormal data packet.
[0070] The network link working status adjustment module is used to adjust the working status of the input network link where the data traffic anomaly event has occurred based on the results of the traffic filtering.
[0071] The beneficial effects of the above embodiments are that the iptables-based traffic filtering control system sets up iptables proxies for all input network links within the network based on the data input attribute information of all input network links at the user end, classifying the input network links into corresponding security frameworks; using the iptables proxies, it obtains the data flow status information of the input network links to determine whether abnormal data traffic events have occurred, and obtains the abnormal data packet attribute information of the input network links where abnormal data traffic events have occurred, thereby determining the data packet components that need to be blocked by traffic filtering for the input network links; after traffic filtering of the input network links where abnormal data traffic events have occurred, the working state of the input network links where abnormal data traffic events have occurred is adjusted based on the results of traffic filtering, enabling accurate and comprehensive traffic control at the user end without the need to set up a firewall inside the user end, reducing the data traffic receiving load of the user end.
[0072] In another embodiment, the user terminal network link identification module is used to determine all input network links of the user terminal within the network based on the network status information currently connected to the user terminal, including:
[0073] Based on the network gateway address currently accessed by the user terminal, determine all network links currently connected to the user terminal; then, based on the uplink and downlink data transmission volumes of each of the network links, determine all input network links of the user terminal within the network.
[0074] This iptables proxy setting module is used to identify the input network link, obtain the data input attribute information of the input network link, and set corresponding iptables proxies for all input network links based on the data input attribute information, including:
[0075] The input network link is identified to obtain its data input speed information. Based on this data input speed information, all input network links are divided into several input network link sets. Among them, the data input speeds of all input network links under each input network link set are within the same data input speed range, and the data input speed ranges corresponding to different input network link sets are different from each other.
[0076] Based on the data input speed range corresponding to each set of input network links, set up an iptables proxy with matching data processing speed for each set of input network links.
[0077] The beneficial effects of the above embodiments are as follows: After a user terminal such as a smartphone or portable computer connects to the network, it forms network links with other terminals within the network. Based on the network gateway address currently accessed by the user terminal, all network links currently formed by the user terminal within the network are determined. Then, the uplink data transmission volume and downlink data transmission volume of each network link are obtained. If the uplink data transmission volume is less than a first preset data volume threshold and the downlink data transmission volume is greater than a second preset data volume threshold, then it is determined that the network link belongs to the user terminal's input network link (i.e., the network link receiving data from other terminals) within the network. Each input network link is then identified to obtain the average data input speed (i.e., data input speed information) of each input network link. Based on the average data input speed of each input network link, all input network links are divided into several input network link sets, such that the data input speed of all input network links under each input network link set is within the same data input speed range, and the data input speed ranges corresponding to different input network link sets are different from each other. Thus, all input network links are classified according to the speed of their average data input speed. In addition, based on the data input speed range corresponding to each input network link set, an iptables proxy with matching data processing speed is set for each input network link set, so that the set iptables proxy can perform fair and continuous traffic filtering and interception on all input network links under the corresponding input network link set.
[0078] In another embodiment, the data traffic anomaly event judgment module is used to obtain data flow status information of the input network link based on the iptables proxy; analyze the data flow status information to determine whether a data traffic anomaly event has occurred on the input network link, including:
[0079] Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. The data stream samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link, which are used as the data stream status information of the input network link.
[0080] Based on the source address information and the transmission frequency information, determine whether a SYN packet traffic attack anomaly is currently occurring on the input network link;
[0081] This abnormal data packet identification module is used to identify abnormal data stream components in the input network link where an abnormal data traffic event has occurred, and to obtain the attribute information of the abnormal data packets in the input network link where the abnormal data traffic event has occurred, including:
[0082] The SYN packet transmission time is processed on the input network link where the SYN packet traffic attack anomaly event occurs to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event occurs.
[0083] The beneficial effects of the above embodiments are as follows: Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. These samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link. Combining this information with the source address information and transmission frequency information of all SYN packets transmitted in the input network link, it is determined whether the transmission frequency of SYN packets from the same source in the input network link exceeds a preset frequency threshold. If so, it is determined that a SYN packet traffic attack anomaly event has occurred on the input network link; otherwise, it is determined that no SYN packet traffic attack anomaly event has occurred on the input network link. This allows for accurate identification and determination of whether the input network link is under traffic attack. Furthermore, SYN packet transmission time identification processing is performed on the input network link where a SYN packet traffic attack anomaly event has occurred to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event has occurred. This facilitates subsequent targeted and accurate filtering and interception of SYN packets associated with traffic attacks in the input network link where the SYN packet traffic attack anomaly event has occurred.
[0084] In another embodiment, the traffic filtering module is used to perform traffic filtering on the input network link where a data traffic anomaly event has occurred based on the abnormal data packet attribute information, including:
[0085] Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly event occurred, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly event occurred.
[0086] The network link operation status adjustment module is used to adjust the operation status of the input network link where the data traffic anomaly event occurred based on the traffic filtering results, including:
[0087] The system obtains the average data traffic value after SYN packet interception processing on the input network link where the SYN packet traffic attack anomaly occurred. If the average data traffic value is greater than or equal to a preset traffic threshold, the system stops the input network link where the SYN packet traffic attack anomaly occurred from transmitting data to the user terminal; otherwise, the system maintains the current data transmission status of the input network link where the SYN packet traffic attack anomaly occurred to the user terminal.
[0088] The beneficial effects of the above embodiments are as follows: Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly occurred. That is, targeted SYN packet interception processing is performed only on the input network link at a specific transmission time point, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly occurred and reducing the data reception load of the user terminal. Furthermore, the average data traffic value after SYN packet interception processing of the input network link where the SYN packet traffic attack anomaly occurred is obtained, and the average data traffic value is compared with a preset traffic threshold. This stops the input network link where the SYN packet traffic attack anomaly occurred from transmitting data to the user terminal, or keeps the current data transmission state of the input network link where the SYN packet traffic attack anomaly occurred unchanged, thereby ensuring normal data transmission of the input network link while avoiding traffic attacks.
[0089] In summary, this iptables-based traffic filtering control method and system uses the data input attribute information of all input network links within the user's network to set up iptables proxies on all input network links, classifying them into corresponding security frameworks. Utilizing the iptables proxies, it obtains the data flow status information of the input network links to determine whether abnormal data traffic events have occurred, and obtains the attribute information of abnormal data packets from the input network links experiencing abnormal data traffic events. This helps determine the components of data packets that need to be blocked by traffic filtering. After filtering the input network links experiencing abnormal data traffic events, the system adjusts the working state of these links based on the filtering results. This allows for accurate and comprehensive traffic control at the user's end without requiring a firewall, reducing the user's data traffic reception load.
[0090] The above is only one specific embodiment of the present invention, and any improvements made based on the concept of the present invention shall be considered within the scope of protection of the present invention.
Claims
1. A traffic filtering control method based on iptables, characterized in that, include: Based on the network status information of the user terminal's current connection, determine all input network links of the user terminal within the network; The process involves identifying the input network links to obtain their data input attribute information, and setting corresponding iptables proxies for all input network links based on this information. This includes: determining all network links currently connected to the user based on the network gateway address currently accessed by the user; determining all input network links within the network for the user based on the uplink and downlink data transmission volumes of each network link; identifying the data input speed information of each input network link, and dividing all input network links into several sets based on this speed information; wherein the data input speeds of all input network links within each set are within the same range, and the data input speed ranges for different sets are different; and setting an iptables proxy with a matching data processing speed for each set based on its corresponding data input speed range. Based on the iptables proxy, the data flow status information of the input network link is obtained; the data flow status information is analyzed to determine whether an abnormal data traffic event has occurred in the input network link; the abnormal data flow component identification processing is performed on the input network link where an abnormal data traffic event has occurred to obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred. Based on the abnormal data packet attribute information, traffic filtering is performed on the input network link where the data traffic anomaly event occurred; and based on the result of the traffic filtering, the working state of the input network link where the data traffic anomaly event occurred is adjusted.
2. The traffic filtering control method based on iptables as described in claim 1, characterized in that: Based on the iptables proxy, obtain the data flow status information of the input network link; analyze the data flow status information to determine whether an abnormal data traffic event has occurred on the input network link; The input network link where the data traffic anomaly event occurred is subjected to abnormal data flow component identification processing to obtain the abnormal data packet attribute information of the input network link where the data traffic anomaly event occurred, including: Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. The data stream samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link, which are used as the data stream status information of the input network link. Based on the source address information and the transmission frequency information, it is determined whether a SYN packet traffic attack anomaly event has occurred on the input network link; SYN packet transmission time identification processing is performed on the input network link where a SYN packet traffic attack anomaly event has occurred to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event has occurred.
3. The iptables-based traffic filtering control method as described in claim 2, characterized in that: Based on the abnormal data packet attribute information, traffic filtering is performed on the input network link where the data traffic anomaly event occurred; Based on the results of the traffic filtering, the operating status of the input network link where the data traffic anomaly event occurred is adjusted, including: Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly event occurred, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly event occurred. The system obtains the average data traffic value after SYN packet interception processing on the input network link where the SYN packet traffic attack anomaly occurred. If the average data traffic value is greater than or equal to a preset traffic threshold, the system stops the input network link where the SYN packet traffic attack anomaly occurred from transmitting data to the user terminal; otherwise, the system maintains the current data transmission status of the input network link where the SYN packet traffic attack anomaly occurred to the user terminal.
4. A traffic filtering control system based on iptables, characterized in that, include: The user-end network link identification module is used to determine all input network links of the user-end within the network based on the network status information currently connected to the user-end, including: determining all network links currently connected to the user-end based on the network gateway address currently accessed by the user-end; and then determining all input network links of the user-end within the network from all network links based on the uplink and downlink data transmission data volume of each of the network links. The iptables proxy setting module is used to identify the input network links, obtain the data input attribute information of the input network links, and set corresponding iptables proxies for all input network links based on the data input attribute information. This includes: identifying the input network links, obtaining the data input speed information of the input network links, and dividing all input network links into several input network link sets based on the data input speed information; wherein, the data input speeds of all input network links under each input network link set are within the same data input speed range, and the data input speed ranges corresponding to different input network link sets are different; and setting an iptables proxy with a matching data processing speed for each input network link set based on the data input speed range corresponding to each input network link set. The data traffic anomaly event judgment module is used to obtain the data flow status information of the input network link based on the iptables proxy; analyze the data flow status information, and determine whether a data traffic anomaly event has occurred on the input network link; The abnormal data packet identification module is used to identify the abnormal data stream components of the input network link where an abnormal data traffic event has occurred, and to obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred. The traffic filtering module is used to filter the traffic of the input network link where the abnormal data packet attribute information has occurred. The network link working status adjustment module is used to adjust the working status of the input network link where a data traffic abnormality event has occurred, based on the result of the traffic filtering.
5. The iptables-based traffic filtering control system as described in claim 4, characterized in that: The data traffic anomaly event judgment module is used to obtain the data flow status information of the input network link based on the iptables proxy; Analyzing the data stream status information to determine whether an abnormal data traffic event has occurred on the input network link includes: Based on the iptables proxy, data stream sampling processing is performed on the input network link to obtain data stream samples. The data stream samples are then analyzed to obtain the source address information and transmission frequency information of the SYN packets transmitted in the input network link, which are used as the data stream status information of the input network link. Based on the source address information and the transmission frequency information, determine whether a SYN packet traffic attack anomaly is currently occurring on the input network link; The abnormal data packet identification module is used to perform abnormal data flow component identification processing on the input network link where an abnormal data traffic event has occurred, and obtain the abnormal data packet attribute information of the input network link where the abnormal data traffic event has occurred, including: The SYN packet transmission time is processed on the input network link where the SYN packet traffic attack anomaly event occurs to obtain the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event occurs.
6. The iptables-based traffic filtering control system as described in claim 5, characterized in that: The traffic filtering module is used to filter traffic on the input network link where a data traffic anomaly event has occurred, based on the attribute information of the abnormal data packet, including: Based on the SYN packet transmission time information of the input network link where the SYN packet traffic attack anomaly event occurred, SYN packet interception processing is performed on the input network link where the SYN packet traffic attack anomaly event occurred, thereby reducing the SYN packet data traffic of the input network link where the SYN packet traffic attack anomaly event occurred. The network link operating status adjustment module is used to adjust the operating status of the input network link where a data traffic anomaly event has occurred based on the results of the traffic filtering, including: The system obtains the average data traffic value after SYN packet interception processing on the input network link where the SYN packet traffic attack anomaly occurred. If the average data traffic value is greater than or equal to a preset traffic threshold, the system stops the input network link where the SYN packet traffic attack anomaly occurred from transmitting data to the user terminal; otherwise, the system maintains the current data transmission status of the input network link where the SYN packet traffic attack anomaly occurred to the user terminal.
Citation Information
Patent Citations
Method for preventing flood attacks in desktop virtualization
CN104363230A