An abnormal IP detection method, apparatus, detection equipment, and storage medium
By recording the IP information and IDC relationship of terminal devices in a preset storage space and using business packets to detect abnormal IP addresses, the problem of detecting abnormal IPs that prevent pinging devices is solved, thus ensuring the stability of the data center network.
Patent Information
- Application Number
- CN202411041349.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-31
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-07-31
AI Technical Summary
Existing technologies cannot effectively detect abnormal IP addresses of terminal devices that have been configured to block ping tests, leading to reduced stability of the data center network architecture.
By recording the IP information of terminal devices and their corresponding Internet Data Centers (IDCs) in a preset storage space, and utilizing the matching relationship between IP addresses in business packets and switch IDCs, the system can detect whether the IP address to be detected is abnormal.
Even in scenarios where ping is disabled, it can effectively detect whether the IP address of the terminal device is abnormal, thus improving the stability of the data center network.
Smart Images

Figure CN118740509B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of computer technology, and in particular to an abnormal IP detection method, apparatus, detection equipment, and storage medium. Background Technology
[0002] In the field of computer technology, network addresses defined by IP (Internet Protocol) can be called IP resources. Technicians can distribute IP resources from a DCN (Data Center Network) to various terminal devices within the DCN, that is, assign IP addresses to each terminal device in the DCN. Abnormal IP addresses can lead to various situations. For example, technicians assign IP address 1 to terminal device 1 and IP address 2 to terminal device 2. If a malicious user modifies the IP address of terminal device 1 to address 2, both terminal device 1 and terminal device 2 will then have the same IP address. Subsequently, when other terminal devices in the DCN need to send messages to address 2, both terminal device 1 and terminal device 2 may receive the message, meaning that terminal devices that do not need to receive the message may also receive it, causing abnormal interactions between terminal devices within the DCN. This leads to a decrease in the stability of the DCN's network architecture. Therefore, detecting abnormal IP addresses is crucial.
[0003] In related technologies, abnormal IPs can be detected through periodic ping tests (Packet Internet Groper). Specifically, the detection device in the DCN sends detection packets to the IP address. Based on whether a data packet of the same length as the detection packet is received within a specified time period, the device determines whether it is connected to the IP address. If the detection device is not connected to the IP address, the IP address can be considered abnormal.
[0004] However, to reduce the risk of malicious ping attacks on terminal devices, technicians often configure these devices to disable ping testing, meaning they will not receive detection packets. Therefore, it is impossible to detect whether the IP addresses of these disabled terminal devices are abnormal through ping testing. Thus, a method is needed to detect abnormal IP addresses on terminal devices configured to disable ping testing. Summary of the Invention
[0005] The purpose of this invention is to provide an abnormal IP detection method, apparatus, detection device, and storage medium to detect abnormal IPs on terminal devices that have been configured to block ping tests. The specific technical solution is as follows:
[0006] In a first aspect of this invention, an abnormal IP address detection method is provided. The method includes: when a service packet to be detected is received, obtaining the IP address to be detected carried in the service packet; if no IP information matching the IP address to be detected is found in the IP information recorded in a preset storage space, determining that the IP address to be detected is an abnormal IP address; wherein, the preset storage space is used to record IP information allocated to each terminal device; for each IP information, the preset storage space also records the Internet Data Center (IDC) corresponding to the IP information; the switch used to forward packets of the terminal device to which the IP information belongs belongs to the IDC corresponding to the IP information; if IP information matching the IP address to be detected exists in the preset storage space, and the IDC to which the first switch used to forward packets of the terminal device to which the IP address to be detected belongs is different from the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space, determining that the IP address to be detected is an abnormal IP address.
[0007] Optionally, the preset storage space is a cache space, and the information recorded in the cache space is obtained by caching the information recorded in the IP resource library.
[0008] Optionally, the information recorded in the IP resource database is cached to obtain the information recorded in the cache space, including: when a preset update cycle is reached, updating the IP information recorded in the preset storage space and the IDC corresponding to each IP information recorded in the IP resource database based on all IP information recorded in the IP resource database and the IDC corresponding to each IP information recorded in the IP resource database; or, when an update to the IP information recorded in the IP resource database is detected, updating the IP information recorded in the preset storage space based on the updated IP information in the IP resource database, and when an update to the IDC corresponding to the IP information recorded in the IP resource database is detected, updating the IDC recorded in the preset storage space based on the updated IDC in the IP resource database.
[0009] Optionally, the method further includes: if no IP information matching the IP address to be detected is recorded in the preset storage space, displaying an indication that the IP address to be detected is an abnormal IP address, including the IP address to be detected and a detection result indicating that no IP information matching the IP address to be detected is recorded in the preset storage space; if the IDC to which the first switch belongs is different from the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space, displaying an indication that the IP address to be detected is an abnormal IP address, including the IP address to be detected, the IDC to which the first switch belongs, and the detection result of the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space; if the IP address to be detected is not an abnormal IP address, displaying an indication that the IP address to be detected is a normal IP address, including the IP address to be detected and the detection result of the IDC to which the first switch belongs.
[0010] Optionally, the method further includes: if a corrected IP address and the IDC corresponding to the corrected IP address are received, recording the corrected IP address and the IDC corresponding to the corrected IP address in the preset storage space; wherein the switch used to forward packets of the terminal device to which the corrected IP address belongs belongs to the IDC corresponding to the corrected IP address; if correction information for IP information matching the IP address to be detected is received, updating the information recorded in the preset storage space using the correction information; wherein the correction information includes at least one of the following: corrected IP information for IP information matching the IP address to be detected, the IDC corresponding to the corrected IP information; and the switch used to forward packets of the terminal device to which the corrected IP information belongs belongs to the IDC corresponding to the corrected IP information.
[0011] Optionally, the IP information recorded in the preset storage space includes at least one of the following: the IP address to be matched, and the IP network segment to be matched; before determining that the IP address to be detected is an abnormal IP address if there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space, the method further includes: if there is neither an IP address identical to the IP address to be detected nor an IP network segment identical to the network segment to which the IP address to be detected belongs in the preset storage space, determining that there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space; if there is an IP address identical to the IP address to be detected in the preset storage space, determining that the IP address identical to the IP address to be detected is: the IP information matching the IP address to be detected in the preset storage space; if there is an IP network segment identical to the network segment to which the IP address to be detected belongs in the preset storage space, determining that the IP network segment identical to the network segment to which the IP address to be detected belongs is: the IP information matching the IP address to be detected in the preset storage space.
[0012] Optionally, the IP address to be detected includes a source IP address and / or a destination IP address; the IDC to which the first switch belongs is determined based on the following method: if the IP address to be detected is a source IP address, the source switch address carried in the service packet is determined, and the IDC corresponding to the source switch address is found from the pre-recorded correspondence between switch addresses and IDCs, which is taken as the IDC to which the first switch belongs; if the IP address to be detected is the destination IP address, the destination switch address carried in the service packet is determined, and the IDC corresponding to the destination switch address is found from the pre-recorded correspondence between switch addresses and IDCs, which is taken as the IDC to which the first switch belongs.
[0013] Optionally, determining the IP address to be detected as an abnormal IP address if no matching IP information exists in the IP information recorded in the preset storage space includes: obtaining a preset whitelist; wherein the preset whitelist records preset attribute values for specified attributes of service packets; the specified attributes include at least one of the following: the network protocol type of the service packet, the service type of the service packet, and the IDC to which the switch used to forward the service packet belongs; obtaining the attribute value of the service packet to be detected for the specified attribute, as the attribute value to be detected; if the attribute value to be detected has the same attribute value as the preset attribute value, determining the IP address to be detected as a normal IP, and recording the IP address to be detected and the IDC to which the first switch belongs in the preset storage space accordingly; if the attribute value to be detected does not have the same attribute value as the preset attribute value, and if no matching IP information exists in the IP information recorded in the preset storage space, determining the IP address to be detected as an abnormal IP address.
[0014] In a second aspect of the invention, an abnormal IP detection device is also provided, the device comprising:
[0015] The acquisition module is used to acquire the IP address to be detected carried in the service message when a service message to be detected is received.
[0016] The first detection module is used to determine that the IP address to be detected is an abnormal IP address if there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space; wherein, the preset storage space is used to record the IP information allocated to each terminal device; for each IP information, the preset storage space also records the Internet Data Center (IDC) corresponding to the IP information; the switch used to forward the packets of the terminal device to which the IP information belongs belongs to the IDC corresponding to the IP information;
[0017] The second detection module is used to determine that the IP address to be detected is an abnormal IP address if there is IP information in the preset storage space that matches the IP address to be detected, and the IDC of the first switch used to forward the packets of the terminal device to which the IP address to be detected belongs is different from the IDC corresponding to the IP information in the preset storage space that matches the IP address to be detected.
[0018] Optionally, the preset storage space is a cache space, and the information recorded in the cache space is obtained by caching the information recorded in the IP resource library.
[0019] Optionally, the information recorded in the IP resource database is cached to obtain the information recorded in the cache space, including: when a preset update cycle is reached, updating the IP information recorded in the preset storage space and the IDC corresponding to each IP information recorded in the IP resource database based on all IP information recorded in the IP resource database and the IDC corresponding to each IP information recorded in the IP resource database; or, when an update to the IP information recorded in the IP resource database is detected, updating the IP information recorded in the preset storage space based on the updated IP information in the IP resource database, and when an update to the IDC corresponding to the IP information recorded in the IP resource database is detected, updating the IDC recorded in the preset storage space based on the updated IDC in the IP resource database.
[0020] Optionally, the device further includes: a first display module, configured to display an indication that the IP address to be detected is an abnormal IP address if no IP information matching the IP address to be detected is recorded in the preset storage space, and including the IP address to be detected, and a detection result indicating that no IP information matching the IP address to be detected is recorded in the preset storage space; a second display module, configured to display an indication that the IP address to be detected is an abnormal IP address if the IDC to which the first switch belongs is different from the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space, and including the IP address to be detected, the IDC to which the first switch belongs, and the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space; and a third display module, configured to display an indication that the IP address to be detected is a normal IP address if the IP address to be detected is not an abnormal IP address, and including the IP address to be detected and the IDC to which the first switch belongs.
[0021] Optionally, the device further includes:
[0022] The correction module is used to record the correction IP address and the corresponding IDC in the preset storage space if it receives a correction IP address for the IP address to be detected and the IDC corresponding to the correction IP address; wherein the switch used to forward the packets of the terminal device to which the correction IP address belongs belongs to the IDC corresponding to the correction IP address.
[0023] The correction module is used to update the information recorded in the preset storage space using the correction information if it receives correction information for IP information matching the IP address to be detected; wherein the correction information includes at least one of the following: corrected IP information for IP information matching the IP address to be detected, the IDC corresponding to the corrected IP information; and the switch used to forward packets of the terminal device to which the corrected IP information belongs belongs to the IDC corresponding to the corrected IP information.
[0024] Optionally, the IP information recorded in the preset storage space includes at least one of the following: the IP address to be matched, and the IP network segment to be matched;
[0025] The device further includes:
[0026] The first determining module is configured to, before the first detection module determines that the IP address to be detected is an abnormal IP address by executing the following steps: if there is neither an IP address identical to the IP address to be detected nor an IP network segment identical to the network segment to which the IP address to be detected belongs in the preset storage space, then the first detection module determines that there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space.
[0027] The second determining module is used to determine, when there is an IP address in the preset storage space that is the same as the IP address to be detected, that the IP address that is the same as the IP address to be detected is: the IP information in the preset storage space that matches the IP address to be detected;
[0028] The third determining module is used to determine, when there is an IP network segment in the preset storage space that is the same as the network segment to which the IP address to be detected belongs, as: IP information in the preset storage space that matches the IP address to be detected.
[0029] Optionally, the IP address to be detected includes the source IP address and / or the destination IP address;
[0030] The IDC to which the first switch belongs is determined in the following way: if the IP address to be detected is the source IP address, the source switch address carried in the service packet is determined, and the IDC corresponding to the source switch address is found from the pre-recorded correspondence between switch addresses and IDCs, which is taken as the IDC to which the first switch belongs; if the IP address to be detected is the destination IP address, the destination switch address carried in the service packet is determined, and the IDC corresponding to the destination switch address is found from the pre-recorded correspondence between switch addresses and IDCs, which is taken as the IDC to which the first switch belongs.
[0031] Optionally, the first detection module is specifically configured to: obtain a preset whitelist; wherein the preset whitelist records preset attribute values for specified attributes of service packets; the specified attributes include at least one of the following: the network protocol type of the service packet, the service type of the service packet, and the IDC to which the switch used to forward the service packet belongs; obtain the attribute value of the service packet to be detected for the specified attribute, as the attribute value to be detected; if the attribute value to be detected has the same attribute value as the preset attribute value, determine that the IP address to be detected is a normal IP, and record the IP address to be detected and the IDC to which the first switch belongs in the preset storage space accordingly; if the attribute value to be detected does not have the same attribute value as the preset attribute value, and if the IP information recorded in the preset storage space does not contain IP information matching the IP address to be detected, determine that the IP address to be detected is an abnormal IP address.
[0032] In a third aspect of the present invention, a detection device is provided, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus; the memory is used to store computer programs; and the processor, when executing the program stored in the memory, implements the abnormal IP detection method steps described in any of the first aspects above.
[0033] In a fourth aspect of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored therein, and when the computer program is executed by a processor, it implements any of the above-described abnormal IP detection methods.
[0034] In a fifth aspect of the invention, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute any of the abnormal IP detection methods described above.
[0035] This invention provides an abnormal IP address detection method. When a service packet to be detected is received, the method obtains the IP address to be detected carried in the service packet. If no IP information matching the IP address to be detected is found in the IP information recorded in a preset storage space, the IP address to be detected is determined to be an abnormal IP address. The preset storage space is used to record IP information allocated to each terminal device. For each IP information, the preset storage space also records the Internet Data Center (IDC) corresponding to the IP information. The switch used to forward packets of the terminal device to which the IP information belongs belongs to the IDC corresponding to the IP information. If an IP information matching the IP address to be detected exists in the preset storage space, and the IDC to which the first switch used to forward packets of the terminal device to which the IP address to be detected belongs is different from the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space, the IP address to be detected is determined to be an abnormal IP address.
[0036] Based on the above processing, the preset storage space records IP information pre-assigned to each terminal device, as well as the corresponding IDC for each IP information. If the preset storage space does not contain IP information matching the IP address to be detected carried in the service packet, meaning the IP address to be detected may not be the IP information pre-assigned to the terminal device, then the IP address to be detected is abnormal, and therefore can be determined to be an abnormal IP address. If the preset storage space contains IP information matching the IP address to be detected, but the IDC of the first switch used to forward the service packet is different from the IDC corresponding to the IP information matching the IP address recorded in the preset storage space, meaning the IDC corresponding to the IP address to be detected is not the IDC pre-assigned for that IP information, then the IP address to be detected is also abnormal, and therefore can also be determined to be an abnormal IP address. In other words, by matching the IP information recorded in the preset storage space with the IDC corresponding to each IP information, it is possible to detect whether the IP address to be detected is an abnormal IP address. Furthermore, since this invention is for detecting abnormal IPs in business packets, even in scenarios where ping is disabled, as long as there is interaction between terminal devices, the IP address of the terminal device can be detected as an abnormal IP based on the solution of this invention. That is, abnormal IP detection can be achieved even in scenarios where ping is disabled. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below.
[0038] Figure 1 A schematic diagram of a DCN provided in an embodiment of the present invention;
[0039] Figure 2 This is a first flowchart of an abnormal IP detection method provided in an embodiment of the present invention;
[0040] Figure 3 This is a second flowchart of the abnormal IP detection method provided in the embodiments of the present invention;
[0041] Figure 4 This is a schematic diagram of an abnormal IP detection method provided in an embodiment of the present invention;
[0042] Figure 5 A structural diagram of an abnormal IP detection device provided in an embodiment of the present invention;
[0043] Figure 6 This is a structural diagram of a detection device provided in an embodiment of the present invention. Detailed Implementation
[0044] The technical solutions of the present invention will now be described with reference to the accompanying drawings in the embodiments of the present invention.
[0045] In related technologies, abnormal IPs can be detected through periodic ping tests. However, for terminal devices that have ping tests disabled, it is impossible to detect whether their IP addresses are abnormal using ping tests alone. Therefore, a method is needed to detect abnormal IPs on terminal devices that have been disabled for ping tests.
[0046] To address the aforementioned issues, this invention provides an abnormal IP detection method applied to a detection device within an NTA (Network Traffic Analysis System), such as a vflow-agent (virtual traffic proxy) cluster. The detection device can be located within a DCN (Distributed Traffic Network), and the NTA manages network traffic within the DCN. The DCN also includes terminal devices and switches for forwarding packets from these terminal devices; for example, the terminal devices can be servers for processing service requests. When abnormal IP detection of a terminal device is required, the detection device can obtain service packets from the switches within the DCN that forward packets from the terminal device. Then, following the abnormal IP detection method provided by this invention, it detects whether the IP address of the terminal device is an abnormal IP address based on the service packets. Since this invention performs abnormal IP detection on service packets, even in scenarios where ping is disabled, as long as there is interaction between terminal devices, the method can be used to detect whether the IP address of the terminal device is an abnormal IP address; that is, abnormal IP detection can be achieved even in scenarios where ping is disabled.
[0047] For example, see Figure 1 , Figure 1This is a schematic diagram of a DCN provided in an embodiment of the present invention. Taking a terminal device 101 in the DCN needing to send a message to a terminal device 102 as an example, terminal device 101 belongs to IDC (Internet Data Center) 103, and switch 104 belonging to IDC 103 is used to forward the message from terminal device 101; terminal device 102 belongs to IDC 105, and switch 106 belonging to IDC 105 is used to forward the message from terminal device 102. Terminal device 101 first sends a message to switch 104, and switch 104 forwards the received message to switch 106. Switch 106 forwards the message received from switch 104 to terminal device 102, thus the message from terminal device 101 is also sent to terminal device 102. To improve the stability of the DCN network architecture, the detection device can perform abnormal IP detection on the IP addresses of terminal devices 101 and 102 based on the messages obtained from switch 1.
[0048] See also Figure 2 , Figure 2 This is a first flowchart of an abnormal IP detection method provided by an embodiment of the present invention. The method may include the following steps:
[0049] S201: When a service message to be tested is received, obtain the IP address to be tested carried in the service message.
[0050] S202: If there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space, the IP address to be detected is determined to be an abnormal IP address.
[0051] The preset storage space is used to record the IP information allocated to each terminal device; for each IP information, the preset storage space also records the Internet Data Center (IDC) corresponding to that IP information; the switch used to forward the packets of the terminal device to which the IP information belongs belongs to the IDC corresponding to that IP information.
[0052] S203: If there is IP information in the preset storage space that matches the IP address to be detected, and the IDC of the first switch used to forward the packets of the terminal device to which the IP address to be detected belongs is different from the IDC corresponding to the IP information in the preset storage space that matches the IP address to be detected, then the IP address to be detected is determined to be an abnormal IP address.
[0053] Based on the above processing, the preset storage space records IP information pre-assigned to each terminal device, as well as the corresponding IDC for each IP information. If the preset storage space does not contain IP information matching the IP address to be detected carried in the service packet, meaning the IP address to be detected may not be the IP information pre-assigned to the terminal device, then the IP address to be detected is abnormal, and therefore can be determined to be an abnormal IP address. If the preset storage space contains IP information matching the IP address to be detected, but the IDC of the first switch used to forward the service packet is different from the IDC corresponding to the IP information matching the IP address recorded in the preset storage space, meaning the IDC corresponding to the IP address to be detected is not the IDC pre-assigned for that IP information, then the IP address to be detected is also abnormal, and therefore can also be determined to be an abnormal IP address. In other words, by matching the IP information recorded in the preset storage space with the IDC corresponding to each IP information, it is possible to detect whether the IP address to be detected is an abnormal IP address. Furthermore, since this invention is for detecting abnormal IPs in business packets, even in scenarios where ping is disabled, as long as there is interaction between terminal devices, the IP address of the terminal device can be detected as an abnormal IP based on the solution of this invention. That is, abnormal IP detection can be achieved even in scenarios where ping is disabled.
[0054] Regarding step S201, a DCN may include multiple IDCs, and each IDC includes terminal devices and switches. A switch in an IDC can forward packets for the terminal devices within that IDC.
[0055] The switch ports are configured with traffic sampling protocol types and reporting addresses for sampled packets. When sampling packets transmitted through the switch from its ports, sampling must be performed according to the traffic sampling protocol type configured on that port, and then the sampled packets are reported to the reporting address configured on that port. For example, a designated device in the DCN can sample the service packets to be detected according to the sampling method specified by the traffic sampling protocol type, and then report the sampled service packets to be detected to the QLB (iQiYi Load Balance). Subsequently, the QLB sends the service packets to be detected to the detection device. The traffic sampling protocol type can be SFlow (Sampled Flow), NetFlow, etc., and the traffic sampling protocol type configured on the switch ports can be determined based on the switch manufacturer, switch model, and switch version.
[0056] For each received packet, the detection device can perform abnormal IP detection on the IP address carried in the packet based on the scheme provided by this invention. This embodiment of the invention uses abnormal IP detection based on the service packet to be detected as an example for illustration. The service packet to be detected can be a service packet sent by any terminal device in the DCN. For ease of description, the following description will use the example of a first terminal device sending a service packet to be detected to a second terminal device.
[0057] The service message to be tested is a message encapsulated according to a specified format, such as a UDP (User Datagram Protocol) message. It can be understood that the service message to be tested may encapsulate the source IP address of the first terminal device, the source switch address of the first switch used to forward the message from the first terminal device, the destination IP address of the second terminal device, the destination switch address of the second switch used to forward the message from the second terminal device, and the service type of the service message to be tested. The switch address can be the switch's MAC (Media Access Control Address) or IP address, etc.
[0058] After acquiring the service packet to be tested, the detection equipment can parse the packet according to the decapsulation method corresponding to its encapsulation format to obtain information such as the source IP address, destination IP address, source switch address, destination switch address, and service type carried in the packet. For example, the detection equipment can parse the traffic 5-tuple of the packet to obtain the IP address carried in the packet.
[0059] Regarding step S202, the preset storage space records multiple IP information entries and the corresponding IDC for each IP information entry. Technicians can manually record the IP information assigned to each terminal device in the preset storage space. For each IP information entry, the IDC to which the switch used to forward packets from the terminal device to which that IP information belongs can also be recorded; that is, the IDC corresponding to that IP information can be recorded, such as the name of the IDC corresponding to that IP information. Subsequently, when performing abnormal IP detection based on the information recorded in the preset storage space, the information recorded in the preset storage space can be updated based on the detection results. For specific update methods, please refer to the detailed description in the following embodiments.
[0060] In this embodiment of the invention, after obtaining the IP address to be detected, the detection device can search for IP information (hereinafter referred to as the hit IP information) that matches the IP address to be detected in the information currently recorded in the preset storage space, and then perform abnormal IP detection on the IP address to be detected based on the search results.
[0061] Since the IP information recorded in the preset storage space is the IP information assigned to each terminal device, if no matching IP information is found in the preset storage space, it means that the IP address to be detected may not be the IP information pre-assigned to the terminal device, and the IP address to be detected is abnormal. Therefore, the detection device can determine that the IP address to be detected is an abnormal IP address.
[0062] Regarding step S203, if a matching IP address is found in the IP information recorded in the preset storage space, it indicates that the IP address to be detected is an IP address pre-assigned to the terminal device. Furthermore, the detection device can continue to detect the terminal device to which the IP address to be detected belongs, to determine whether the IP address of the first terminal device has been modified. Specifically, after parsing the switch address carried in the service packet, the detection device can determine the switch with the same address, i.e., determine the first switch used to forward packets to the terminal device to which the IP address to be detected belongs. Then, the detection device can check whether the IDC to which the first switch belongs (hereinafter referred to as the first IDC) is the same as the IDC corresponding to the matching IP address recorded in the preset storage space (hereinafter referred to as the second IDC), i.e., check whether the IDC to which the switch forwarding the service packet carrying the IP address to be detected belongs is the same as the preset IDC to which the switch used to forward packets to the terminal device to which the IP address to be detected belongs.
[0063] If the first IDC and the second IDC are the same, it means that the switch forwarding the service packet carrying the IP address to be detected belongs to the same IDC as the preset switch used to forward packets of the terminal device to which the IP address to be detected belongs. That is, the IDC corresponding to the IP address to be detected is the IDC pre-allocated for that IP address. Therefore, the detection device can determine that the IP address to be detected is a normal IP address and that the IP address of the first terminal device has not been changed.
[0064] If the first IDC and the second IDC are different, it means that the switch forwarding the service packet carrying the IP address to be detected is not in the same IDC as the preset switch used to forward packets from the terminal device to which the IP address to be detected belongs. In other words, the IDC corresponding to the IP address to be detected is not the IDC pre-assigned for that IP address. This means the IP address to be detected may have been modified, or the information recorded in the preset storage space may be incorrect. Therefore, the detection device can determine the IP address to be detected as an abnormal IP address.
[0065] For example, if the technician assigns IP address 1 to terminal device 1 and IP address 2 to terminal device 2, then switch 1, belonging to IDC1, is used to forward packets from terminal device 1, and switch 2, belonging to IDC2, is used to forward packets from terminal device 2.
[0066] If the information recorded in the preset storage space is correct (i.e., the preset storage space records address 1 corresponding to IDC1 and address 2 corresponding to IDC2), and a malicious user modifies the IP address of terminal device 1 to address 2, then when the detection device performs abnormal IP detection on the IP address of terminal device 1, it can determine that there is IP information in the preset storage space that matches the IP address to be detected (i.e., "address 2"). Then, the detection device detects that the IDC1 to which the first switch belongs is different from the "IDC2" corresponding to "address 2" recorded in the preset storage space. Therefore, the detection device can determine that the IP address to be detected is an abnormal IP address.
[0067] If the information recorded in the preset storage space is incorrect, such as the preset storage space recording that address 1 corresponds to IDC2 and address 2 corresponds to IDC1, when the detection device performs abnormal IP detection on the IP address of terminal device 1, it can determine that there is IP information in the preset storage space that matches the IP address to be detected (i.e., "address 1"). Then, the detection device detects that IDC1, to which the first switch belongs, is different from "IDC2" corresponding to "address 1" recorded in the preset storage space. Therefore, the detection device can determine that the IP address to be detected is an abnormal IP address. Subsequently, based on the abnormal IP address, the matching IP addresses corresponding to the abnormal IP addresses recorded in the preset storage space can be corrected.
[0068] In some embodiments, the IP address to be detected includes the source IP address and / or the destination IP address.
[0069] The IDC to which the first switch belongs was determined based on the following method:
[0070] If the IP address to be detected is the source IP address, determine the source switch address carried in the service message, and find the IDC corresponding to the source switch address from the pre-recorded correspondence between switch addresses and IDCs, and use it as the IDC to which the first switch belongs; if the IP address to be detected is the destination IP address, determine the destination switch address carried in the service message, and find the IDC corresponding to the destination switch address from the pre-recorded correspondence between switch addresses and IDCs, and use it as the IDC to which the first switch belongs.
[0071] Understandably, after parsing the IP address and switch address from the service message to be tested, the testing device can distinguish whether the IP address is the source IP address of the first terminal device or the destination IP address of the second terminal device based on the identifier of the IP address; and the testing device can also distinguish whether the switch address is the source switch address or the destination switch address based on the identifier of the switch address.
[0072] Furthermore, technicians can pre-record the mapping between switch addresses and data centers (IDCs), and verify the information recorded in this mapping. If the recorded information is incorrect, it can be corrected until the accurate mapping between switch addresses and IDCs is obtained. Then, the detection equipment can obtain the mapping between switch addresses and IDCs, and according to this mapping, find the IDC corresponding to the switch address that matches the IP address to be detected.
[0073] When the IP address to be detected is a source IP address, the detection device can determine the source switch address and search for the corresponding IDC from a pre-recorded mapping between switch addresses and IDCs. The found IDC is then designated as the IDC of the first switch, meaning it finds the IDC of the terminal device that actually sends the service packet. When the IP address to be detected is a destination IP address, the detection device can determine the destination switch address and search for the corresponding IDC from a pre-recorded mapping between switch addresses and IDCs. The found IDC is then designated as the IDC of the first switch, meaning it finds the IDC of the terminal device that needs to receive the service packet. Subsequently, by checking whether the found IDC is the same as the IDC corresponding to the IP address to be detected recorded in the preset storage space, it can determine whether the IDC corresponding to the IP address to be detected is the IDC pre-assigned for this IP information, i.e., whether the IP address to be detected is an abnormal IP address.
[0074] Furthermore, it is understandable that when the IP address to be detected is both a source IP address and a destination IP address, i.e., when abnormal IP detection is required for both the source IP address and the destination IP address, the detection device can determine the IDC corresponding to each of the two IP addresses by determining the IDC to which the first switch belongs, and then perform abnormal detection on each IP address based on the corresponding IDC.
[0075] Based on the above processing, the detection device can perform abnormal IP detection on both the source IP address and the destination IP address carried in the business message. That is, it can perform abnormal IP detection on two IP addresses through one business message, without having to obtain multiple business messages, which can improve the efficiency of abnormal IP detection.
[0076] In some embodiments, when distributing DCN IP resources, technicians can distribute IP addresses to terminal devices or IP network segments to the cloud. Subsequently, the cloud can continue to distribute its own IP network segment resources to other clouds or terminal devices. Therefore, the IP information recorded in the preset storage space may include at least one of the following: IP addresses to be matched and IP network segments to be matched.
[0077] Accordingly, before step S203, the method may further include the following steps: if there is neither an IP address identical to the IP address to be detected nor an IP network segment identical to the network segment to which the IP address to be detected belongs in the preset storage space, determine that there is no IP information matching the IP address to be detected among the IP information recorded in the preset storage space; if there is an IP address identical to the IP address to be detected in the preset storage space, determine that the IP address identical to the IP address to be detected is: the IP information matching the IP address to be detected in the preset storage space; if there is an IP network segment identical to the network segment to which the IP address to be detected belongs in the preset storage space, determine that the IP network segment identical to the network segment to which the IP address to be detected belongs is: the IP information matching the IP address to be detected in the preset storage space.
[0078] If the preset storage space includes the IP address to be matched, after obtaining the IP address to be detected, the detection device can search for an IP address that matches the IP address to be detected in the preset storage space (hereinafter referred to as the matched IP address). If a matched IP address is found, it means that there is IP information in the preset storage space that matches the IP address to be detected. If no matched IP address is found, it means that there is no IP information in the preset storage space that matches the IP address to be detected.
[0079] If the preset storage space includes the IP network segment to be matched, after obtaining the IP address to be detected, the detection device can search the preset storage space for an IP network segment that matches the IP network segment to which the IP address to be detected belongs (hereinafter referred to as the matched IP network segment). If a matched IP network segment is found, that is, IP information matching the IP address to be detected exists in the preset storage space, the first terminal device may be a terminal device in the cloud of DCN. If no matched IP network segment is found, that is, IP information matching the IP address to be detected does not exist in the preset storage space.
[0080] If the preset storage space includes both the IP address to be matched and the IP network segment to be matched, after obtaining the IP address to be detected, the detection device can first search for a matching IP address in the preset storage space. If no matching IP address is found, it will then search for a matching IP network segment in the preset storage space. If neither a matching IP address nor a matching IP network segment is found, it is determined that there is no IP information in the IP information recorded in the preset storage space that matches the IP address to be detected.
[0081] Based on the above processing, the preset storage space can store IP addresses assigned to terminal devices and IP network segments assigned to the cloud. Even if the cloud continues to allocate IP network segments to terminal devices or other cloud environments, the preset storage space can be used to comprehensively and uniformly manage the IP resources of the DCN. Subsequently, the cloud environment to which the IP address belongs can be determined based on the network segment to which the IP address belongs, thereby improving the effectiveness and accuracy of the management of the DCN's IP resources.
[0082] In some embodiments, the method may further include the following steps: if there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space, display an indication that the IP address to be detected is an abnormal IP address, including the IP address to be detected and a detection result indicating that there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space; if the IDC to which the first switch belongs is different from the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space, display an indication that the IP address to be detected is an abnormal IP address, including the IP address to be detected, the IDC to which the first switch belongs, and the detection result of the IDC corresponding to the IP information matching the IP address to be detected recorded in the preset storage space; if the IP address to be detected is not an abnormal IP address, display an indication that the IP address to be detected is a normal IP address, including the IP address to be detected and the detection result of the IDC to which the first switch belongs.
[0083] After obtaining the detection result of whether the IP address to be detected is an abnormal IP address, the detection equipment can display the detection result on the display module. Technicians can then process the result accordingly. For example, if the IP address to be detected is an abnormal IP address, technical means can be used to identify and correct the erroneous information. If the IP address to be detected is a normal IP address, technicians can also perform statistical analysis on each normal IP address, such as counting the number of normal IP addresses corresponding to each data center. Furthermore, to facilitate the processing of the detection results by technicians, abnormal IP addresses and normal IP addresses can be displayed in different ways.
[0084] In some embodiments, the method may further include the following steps:
[0085] If a corrected IP address and the corresponding IDC are received for the IP address to be detected, the corrected IP address and the corresponding IDC are recorded in the preset storage space.
[0086] Among them, the switch used to forward packets from the terminal device to which the correction IP address belongs belongs to the IDC corresponding to the correction IP address.
[0087] If correction information is received for IP information that matches the IP address to be detected, the information recorded in the preset storage space is updated using the correction information.
[0088] The correction information includes at least one of the following: corrected IP information for IP information matching the IP address to be detected, the IDC corresponding to the corrected IP information; and the switch used to forward packets from the terminal device to which the corrected IP information belongs to the IDC corresponding to the corrected IP information.
[0089] When the IP address to be detected is an abnormal IP address, technicians can use technical means to determine the error based on the displayed abnormal IP address and related detection results, and then correct the error.
[0090] It is understandable that when the IP address to be detected is an abnormal IP address, it may be that the IP address to be detected has been modified, or it may be that there is an error in the information recorded in the preset storage space.
[0091] When the detection equipment receives the corrected IP address for the IP address to be detected, along with the corresponding IDC (Internet Data Center) for that corrected IP address, it means that technicians have determined through technical means that the IP address to be detected has been modified and have identified the original IP address (i.e., the corrected IP address). At this point, the detection equipment can record the corrected IP address and its corresponding IDC in a preset storage space to update the information recorded in the preset storage space.
[0092] When the detection device receives correction information for IP information matching the IP address to be detected (i.e., the hit IP information in the aforementioned embodiment), it means that the technician has determined through technical means that the information recorded in the preset storage space is incorrect, and has determined the actual information corresponding to the hit IP information. It is understood that the information recorded in the preset storage space may contain errors in either the IP information itself or the IDC corresponding to the IP information. Therefore, the correction information may include corrected IP information for the hit IP information, and / or the IDC corresponding to the corrected IP information. When the hit IP information is correct, but the corresponding IDC is incorrect, the corrected IP information is the hit IP information, and correspondingly, the IDC corresponding to the corrected IP information is: the IDC of the switch used by the technician to forward the packets of the terminal device to which the hit IP information belongs.
[0093] Based on the above processing, the detection device can display the detection results obtained by detecting abnormal IPs of the IP address to be detected. If correction information for the IP address to be detected is received subsequently, the abnormal IP address can be tracked and corrected. If correction information for the hit IP information is received, the information stored in the preset storage space can be corrected.
[0094] In some embodiments, due to the large amount of information traffic within a DCN in actual application scenarios, such as potentially reaching TB (terabytes), the detection device may acquire multiple service packets, naturally requiring the detection of abnormal IP addresses for multiple terminal devices. To improve the efficiency of abnormal IP detection, the preset storage space can be a cache space, and the information recorded in the cache space is obtained by caching information recorded in the IP resource database. For example, the preset storage space can be Redis. ( Remote Dictionary Server (RDS) database; the IP resource database can be a DB (Database), and information can be searched in the DB using ES (Elastic Search).
[0095] In some embodiments, caching information recorded in the IP resource library to obtain information recorded in the cache space may include the following steps: when a preset update cycle is reached, updating the IP information recorded in the preset storage space and the IDC corresponding to each IP information recorded in the IP resource library based on all IP information recorded in the IP resource library and the IDC corresponding to each IP information recorded in the IP resource library; or, when an update is detected in the IP information recorded in the IP resource library, updating the IP information recorded in the preset storage space based on the updated IP information in the IP resource library, and when an update is detected in the IDC corresponding to the IP information recorded in the IP resource library, updating the IDC recorded in the preset storage space based on the updated IDC in the IP resource library.
[0096] Since the data volume recorded in the IP resource database is typically hundreds of megabytes (MB), caching such a large amount of information would consume considerable time. Therefore, to improve the stability of abnormal IP detection, the detection device can update the information recorded in the preset storage space only when a preset update cycle is reached. For example, upon reaching the preset update cycle, the detection device can first delete all information recorded in the preset storage space, and then cache all information recorded in the IP resource database to the preset storage space. Alternatively, the detection device can also, upon reaching the preset update cycle, detect the differences between the information recorded in the IP resource database and the information recorded in the preset storage space, and then update the cached information in the preset storage space according to these differences.
[0097] To improve the accuracy of abnormal IP detection, the detection device can update the IP information recorded in a preset storage space based on the updated IP information when the information recorded in the IP resource database is updated. This means the information recorded in the IP resource database is loaded and modified in real time. For example, when the information recorded in the IP resource database is updated, a message indicating the updated information can be added to a preset message queue. After detecting the addition of a message to the message queue, the detection device can subscribe to and process the message, thus updating the IP information recorded in the preset storage space with the updated IP information. The preset message queue can be a Kafka message queue, RocketMQ (RocketMessage Queue), etc. The process of updating the information recorded in the IP resource database can also be called IP asset management.
[0098] In some embodiments, Figure 2 Based on this, see Figure 3 Step S202 may include the following steps:
[0099] S2021: Get the preset whitelist.
[0100] The preset whitelist contains preset attribute values for specified attributes of service packets; the specified attributes include at least one of the following: the network protocol type of the service packet, the service type of the service packet, and the IDC to which the switch used to forward the service packet belongs.
[0101] S2022: Obtain the attribute value of the service message to be detected for the specified attribute, and use it as the attribute value to be detected.
[0102] S2023: If the attribute value to be detected is the same as the preset attribute value, determine that the IP address to be detected is a normal IP, and record the IP address to be detected and the IDC to which the first switch belongs in the preset storage space.
[0103] S2024: If the attribute value to be detected does not have the same attribute value as the preset attribute value, and if the IP information recorded in the preset storage space does not have IP information that matches the IP address to be detected, the IP address to be detected is determined to be an abnormal IP address.
[0104] In real-world applications, switches forward not only service packets but also other types of packets. For example, when technicians assign IP addresses to terminal devices but haven't stored these IP addresses and related information in the pre-defined storage space, to improve DCN security, they can first perform ping tests on these IP addresses, i.e., forward detection packets to these IP addresses through the switch. The detection device may then obtain these detection packets from the switch and treat them as service packets for anomaly IP detection. Since these IP addresses haven't been stored in the pre-defined storage space yet, they will inevitably be detected as anomaly IP addresses, requiring significant time from technicians for processing, thus reducing the effectiveness of subsequent handling of anomaly IP addresses.
[0105] Therefore, to avoid the aforementioned problems, a preset whitelist can be set up, recording preset attribute values for specified attributes of business packets, according to specific scenarios. For example, if technicians are performing ping tests on terminal devices in a specified data center, the specified attribute can be the data center to which the switch used to forward business packets belongs; if technicians are testing terminal devices that transmit packets using a new network protocol type, the specified attribute can be the network protocol type of the business packet, such as a preset attribute value of HTTP (Hypertext Transfer Protocol). It is understood that the preset whitelist can record multiple types of specified attributes, and a single specified attribute can have multiple preset attribute values; this invention does not limit this.
[0106] Furthermore, the detection device can obtain the target attribute value of the service packet to be detected for the specified attribute recorded in the preset whitelist, and determine whether there is an attribute value in the preset attribute values that is the same as the target attribute value. If there is an attribute value in the preset attribute values that is the same as the target attribute value, it can be indicated that the service packet to be detected is a packet that meets the preset whitelist conditions. Therefore, the detection device can directly determine that the IP address to be detected is a normal IP address, that is, it will not continue to perform abnormal IP detection on the IP address to be detected based on the information recorded in the preset storage space. Correspondingly, the IP address to be detected and the IDC to which the first switch belongs can also be recorded in the preset storage space.
[0107] If there is no attribute value in the preset attribute values that is the same as the attribute value to be detected, it can be indicated that the service message to be detected is not a message that meets the preset whitelist conditions. Subsequently, abnormal IP detection can be performed on the IP address to be detected based on the information recorded in the preset storage space.
[0108] Based on the above processing, by setting a preset whitelist, interference from business packets that do not require abnormal IP detection can be eliminated, thereby improving the effectiveness of subsequent processing of abnormal IP addresses.
[0109] In some embodiments, see Figure 4 , Figure 4 This is a schematic diagram of an abnormal IP detection method provided in an embodiment of the present invention.
[0110] Figure 4 In the schematic diagram shown, IDC1 and IDC2 communicate with terminal devices in IDC1 and IDC2 through their respective switches. When sampling packets transmitted by the switch belonging to IDC1, the traffic sampling protocol type used is Sflow; when sampling packets transmitted by the switch belonging to IDC2, the traffic sampling protocol type used is NetFlow.
[0111] NTA is used for network traffic analysis and classifies traffic according to attributes such as service type, IDC, and carrier. During network traffic analysis, a designated device in the DCN samples the network flows forwarded by the switch according to the traffic sampling protocol type, and then inputs the sampled network flows to the load balancer QLB. The QLB then sends the sampled network flows to the traffic collector vflow-agent in the data processing and analysis unit; that is, the detection device in the aforementioned embodiment acquires the service packets to be detected.
[0112] vflow-agent can parse the five-tuple of the received network flow to obtain information such as the IP address and traffic sampling protocol type carried in the network flow.
[0113] Furthermore, the IP resource packaging module can pull relevant data on IP network segments and IP addresses from the IDC asset management platform and the IP allocation platform, package and compress it, and push it to vflow-agent. For example, the IDC asset management platform can push data packets to vflow-agent based on Kafka. vflow-agent can load data packets according to changes in the data packets, that is, obtain each IP asset in the IP asset library (i.e., the IP resource library in the aforementioned embodiment). The IP network segments pulled from the IDC asset management platform are the IP network segments to be matched in the aforementioned embodiment; the IP addresses pulled from the IP allocation platform are the IP addresses to be matched in the aforementioned embodiment. vflow-agent can load data packets according to changes in the data packets, that is, update the information in the preset storage space in the aforementioned embodiment. The preset storage space records the full IP asset cache and the full IP network segment cache.
[0114] vflow-agent can compare and tag the parsed traffic quintuples with each IP asset. Specifically, in the aforementioned embodiment, it determines whether IP information matching the IP address to be detected exists in the preset storage space. If such IP information exists in the preset storage space, it determines whether the IDC to which the first switch belongs is the same as the IDC corresponding to the IP information matching the IP address recorded in the preset storage space. The corresponding detection result can be obtained based on the determination result.
[0115] Then, the data tagged by vflow-agent can be processed sequentially through a Kafka message queue and processed by Flink to obtain the final detection result. Based on Elasticsearch, the relevant information is recorded in the database. Furthermore, the detection result can be displayed on a dashboard, and the IP asset database can be updated subsequently based on APIs (Application Programming Interfaces) or reports. That is, in the aforementioned embodiment, upon receiving a corrected IP address and its corresponding IDC, the corrected IP address and its corresponding IDC are recorded in a preset storage space; upon receiving correction information, the information recorded in the preset storage space is updated based on the correction information.
[0116] Based on the above processing, the preset storage space records IP information pre-assigned to each terminal device, as well as the corresponding IDC for each IP information. If the preset storage space does not contain IP information matching the IP address to be detected carried in the service packet, meaning the IP address to be detected may not be the IP information pre-assigned to the terminal device, then the IP address to be detected is abnormal, and therefore can be determined to be an abnormal IP address. If the preset storage space contains IP information matching the IP address to be detected, but the IDC of the first switch used to forward the service packet is different from the IDC corresponding to the IP information matching the IP address recorded in the preset storage space, meaning the IDC corresponding to the IP address to be detected is not the IDC pre-assigned for that IP information, then the IP address to be detected is also abnormal, and therefore can also be determined to be an abnormal IP address. In other words, by matching the IP information recorded in the preset storage space with the IDC corresponding to each IP information, it is possible to detect whether the IP address to be detected is an abnormal IP address. Furthermore, since this invention is for detecting abnormal IPs in business packets, even in scenarios where ping is disabled, as long as there is interaction between terminal devices, the IP address of the terminal device can be detected as an abnormal IP based on the solution of this invention. That is, abnormal IP detection can be achieved even in scenarios where ping is disabled.
[0117] Furthermore, compared to the periodic ping test method in the existing technology, which can be bypassed by malicious users simply by not starting the terminal device with the modified IP address when the ping test period arrives, this invention can detect the abnormal IP of the terminal device with the modified IP address as long as the malicious user starts and uses it, thus solving the problem of being evaded by periodic ping tests.
[0118] Furthermore, since this invention allows for updating the information recorded in the IP resource database, it solves the problem of incomplete manual data entry or errors in related attribute entry in IP asset management. Moreover, because this invention provides unified management of IP addresses and IP network segments in the IP resource database, subsequent abnormal IP detection based on the database and subsequent updates to the database can identify and correct IPs not recorded in the NTA (Network Address Translation) for multi-cloud and hybrid cloud architectures, and can monitor and detect illegally used IPs in real time.
[0119] Furthermore, since this invention uses vflow-agent to compare and tag each IP asset based on the parsed traffic quintuple, there is no need for subsequent Flink calculations for comparison and tagging. This reduces the computational burden on Flink, enables rapid comparison and tagging, and thus improves the efficiency of abnormal IP detection.
[0120] When applied in real-world scenarios, this invention has uncovered and resolved thousands of IP addresses that were missed in the NTA's IP assets and were already in use. It has also detected and calibrated tens of thousands of IP addresses with erroneous records, and detected multiple instances of potential illegal use and allocation of IP addresses. This has greatly improved the stability of DCN and the accuracy of IP asset management.
[0121] Based on the same inventive concept as the above-described abnormal IP detection method, this embodiment of the invention also provides an abnormal IP detection device. See [link to related document]. Figure 5 , Figure 5 A structural diagram of an abnormal IP detection device provided in an embodiment of the present invention is shown. The device includes:
[0122] The acquisition module 501 is used to acquire the IP address to be detected carried in the service message when a service message to be detected is received.
[0123] The first detection module 502 is used to determine that the IP address to be detected is an abnormal IP address if there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space; wherein, the preset storage space is used to record the IP information allocated to each terminal device; for each IP information, the preset storage space also records the Internet Data Center (IDC) corresponding to the IP information; the switch used to forward the packets of the terminal device to which the IP information belongs belongs to the IDC corresponding to the IP information;
[0124] The second detection module 503 is used to determine that the IP address to be detected is an abnormal IP address if there is IP information in the preset storage space that matches the IP address to be detected, and the IDC of the first switch used to forward the packets of the terminal device to which the IP address to be detected belongs is different from the IDC corresponding to the IP information in the preset storage space that matches the IP address to be detected.
[0125] Optionally, the preset storage space is a cache space, and the information recorded in the cache space is obtained by caching the information recorded in the IP resource library.
[0126] Optionally, the information recorded in the IP resource database is cached to obtain the information recorded in the cache space, including: when a preset update cycle is reached, updating the IP information recorded in the preset storage space and the IDC corresponding to each IP information recorded in the IP resource database based on all IP information recorded in the IP resource database and the IDC corresponding to each IP information recorded in the IP resource database; or, when an update to the IP information recorded in the IP resource database is detected, updating the IP information recorded in the preset storage space based on the updated IP information in the IP resource database, and when an update to the IDC corresponding to the IP information recorded in the IP resource database is detected, updating the IDC recorded in the preset storage space based on the updated IDC in the IP resource database.
[0127] Optionally, the device further includes:
[0128] The first display module is used to display an indication that the IP address to be detected is an abnormal IP address if there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space, and includes the IP address to be detected, as well as a detection result indicating that there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space.
[0129] The second display module is used to display an indication that the IP address to be detected is an abnormal IP address if the IDC to which the first switch belongs is different from the IDC corresponding to the IP information that matches the IP address to be detected recorded in the preset storage space. The display module includes the IP address to be detected, the IDC to which the first switch belongs, and the detection result of the IDC corresponding to the IP information that matches the IP address to be detected recorded in the preset storage space.
[0130] The third display module is used to display an indication that the IP address to be detected is a normal IP address if the IP address to be detected is not an abnormal IP address, and includes the IP address to be detected and the detection result of the IDC to which the first switch belongs.
[0131] Optionally, the device further includes:
[0132] The correction module is used to record the correction IP address and the corresponding IDC in the preset storage space if it receives a correction IP address for the IP address to be detected and the IDC corresponding to the correction IP address; wherein the switch used to forward the packets of the terminal device to which the correction IP address belongs belongs to the IDC corresponding to the correction IP address.
[0133] The correction module is used to update the information recorded in the preset storage space using the correction information if it receives correction information for IP information matching the IP address to be detected; wherein the correction information includes at least one of the following: corrected IP information for IP information matching the IP address to be detected, the IDC corresponding to the corrected IP information; and the switch used to forward packets of the terminal device to which the corrected IP information belongs belongs to the IDC corresponding to the corrected IP information.
[0134] Optionally, the IP information recorded in the preset storage space includes at least one of the following: the IP address to be matched, and the IP network segment to be matched;
[0135] The device further includes:
[0136] The first determining module is configured to, before the first detection module 502 determines that the IP address to be detected is an abnormal IP address by executing the following steps: if there is neither an IP address identical to the IP address to be detected nor an IP network segment identical to the network segment to which the IP address to be detected belongs in the preset storage space, then the first detection module 502 determines that there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space.
[0137] The second determining module is used to determine, when there is an IP address in the preset storage space that is the same as the IP address to be detected, that the IP address that is the same as the IP address to be detected is: the IP information in the preset storage space that matches the IP address to be detected;
[0138] The third determining module is used to determine, when there is an IP network segment in the preset storage space that is the same as the network segment to which the IP address to be detected belongs, as: IP information in the preset storage space that matches the IP address to be detected.
[0139] Optionally, the IP address to be detected includes the source IP address and / or the destination IP address;
[0140] The IDC to which the first switch belongs is determined in the following way: if the IP address to be detected is the source IP address, the source switch address carried in the service packet is determined, and the IDC corresponding to the source switch address is found from the pre-recorded correspondence between switch addresses and IDCs, which is taken as the IDC to which the first switch belongs; if the IP address to be detected is the destination IP address, the destination switch address carried in the service packet is determined, and the IDC corresponding to the destination switch address is found from the pre-recorded correspondence between switch addresses and IDCs, which is taken as the IDC to which the first switch belongs.
[0141] Optionally, the first detection module 502 is specifically used for: obtaining a preset whitelist; wherein the preset whitelist records preset attribute values for specified attributes of service packets; the specified attributes include at least one of the following: the network protocol type of the service packet, the service type of the service packet, and the IDC to which the switch used to forward the service packet belongs; obtaining the attribute value of the service packet to be detected for the specified attribute, as the attribute value to be detected; if the attribute value to be detected has the same attribute value as the preset attribute value, determining that the IP address to be detected is a normal IP, and recording the IP address to be detected and the IDC to which the first switch belongs in the preset storage space accordingly; if the attribute value to be detected does not have the same attribute value as the preset attribute value, and if the IP information recorded in the preset storage space does not contain IP information matching the IP address to be detected, determining that the IP address to be detected is an abnormal IP address.
[0142] Based on the abnormal IP detection device provided in this embodiment of the invention, a preset storage space records IP information pre-allocated to each terminal device, and the corresponding IDC for each IP information. When no IP information matching the IP address to be detected carried in the service packet exists in the preset storage space, meaning the IP address to be detected may not be the IP information pre-allocated to the terminal device, the IP address to be detected is abnormal, and therefore, it can be determined that the IP address to be detected is an abnormal IP address. When IP information matching the IP address to be detected exists in the preset storage space, but the IDC of the first switch used to forward the service packet is different from the IDC corresponding to the IP information matching the IP address recorded in the preset storage space, meaning the IDC corresponding to the IP address to be detected is not the IDC pre-allocated for that IP information, the IP address to be detected is also abnormal, and therefore, it can also be determined that the IP address to be detected is an abnormal IP address. In other words, by matching the IP information recorded in the preset storage space with the IDC corresponding to each IP information, it is possible to detect whether the IP address to be detected is an abnormal IP address. Furthermore, since this invention is for detecting abnormal IPs in business packets, even in scenarios where ping is disabled, as long as there is interaction between terminal devices, the IP address of the terminal device can be detected as an abnormal IP based on the solution of this invention. That is, abnormal IP detection can be achieved even in scenarios where ping is disabled.
[0143] This invention also provides a detection device, such as... Figure 6 As shown, it includes a processor 601, a communication interface 602, a memory 603, and a communication bus 604, wherein the processor 601, the communication interface 602, and the memory 603 communicate with each other through the communication bus 604.
[0144] Memory 603 is used to store computer programs;
[0145] When the processor 601 executes the program stored in the memory 603, it implements any of the abnormal IP detection methods described in the foregoing embodiments.
[0146] The communication bus mentioned in the aforementioned testing equipment can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not indicate that there is only one bus or one type of bus.
[0147] The communication interface is used for communication between the aforementioned detection equipment and other devices.
[0148] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0149] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0150] In another embodiment of the present invention, a computer-readable storage medium is also provided, wherein a computer program is stored therein, and when the computer program is executed by a processor, it implements any of the abnormal IP detection methods described in the above embodiments.
[0151] In another embodiment of the present invention, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute any of the abnormal IP detection methods described in the above embodiments.
[0152] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present invention are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid state disk (SSD)).
[0153] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.
[0154] The various embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, testing equipment, computer-readable storage media, and computer program products are basically similar to the method embodiments, and therefore the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0155] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention are included within the scope of protection of the present invention.
Claims
1. An abnormal IP detection method, characterized in that, The method includes: When a service message to be detected is received, the IP address to be detected carried in the service message is obtained; If no IP information matching the IP address to be detected is found in the IP information recorded in the preset storage space, the IP address to be detected is determined to be an abnormal IP address; wherein, the preset storage space is used to record the IP information allocated to each terminal device; for each IP information, the preset storage space also records the Internet Data Center (IDC) corresponding to the IP information; the switch used to forward the packets of the terminal device to which the IP information belongs belongs to the IDC corresponding to the IP information; If the preset storage space contains IP information that matches the IP address to be detected, and the IDC of the first switch used to forward the packets of the terminal device to which the IP address to be detected belongs is different from the IDC corresponding to the IP information that matches the IP address to be detected recorded in the preset storage space, then the IP address to be detected is determined to be an abnormal IP address.
2. The method according to claim 1, characterized in that, The preset storage space is a cache space, and the information recorded in the cache space is obtained by caching the information recorded in the IP resource library.
3. The method according to claim 2, characterized in that, The information recorded in the IP resource database is cached to obtain the information recorded in the cache space, including: When the preset update cycle is reached, the IP information recorded in the preset storage space and the IDC corresponding to each IP information recorded in the preset storage space are updated based on all IP information recorded in the IP resource library and the IDC corresponding to each IP information recorded in the preset storage space. or, When an update to the IP information recorded in the IP resource database is detected, the IP information recorded in the preset storage space is updated based on the updated IP information in the IP resource database. And when an update to the IDC corresponding to the IP information recorded in the IP resource database is detected, the IDC recorded in the preset storage space is updated based on the updated IDC in the IP resource database.
4. The method according to claim 1, characterized in that, The method further includes: If there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space, the display indicates that the IP address to be detected is an abnormal IP address, and includes the IP address to be detected, as well as the detection result indicating that there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space; If the IDC to which the first switch belongs is different from the IDC corresponding to the IP information that matches the IP address to be detected recorded in the preset storage space, the display indicates that the IP address to be detected is an abnormal IP address, and includes the detection results of the IP address to be detected, the IDC to which the first switch belongs, and the IDC corresponding to the IP information that matches the IP address to be detected recorded in the preset storage space. If the IP address to be detected is not an abnormal IP address, the system displays an indication that the IP address to be detected is a normal IP address, including the IP address to be detected and the detection result of the IDC to which the first switch belongs.
5. The method according to claim 1, characterized in that, The method further includes: If a corrected IP address and the corresponding IDC for the IP address to be detected are received, the corrected IP address and the corresponding IDC are recorded in the preset storage space; wherein, the switch used to forward the packets of the terminal device to which the corrected IP address belongs belongs to the IDC corresponding to the corrected IP address; If correction information is received for IP information matching the IP address to be detected, the information recorded in the preset storage space is updated using the correction information; wherein, the correction information includes at least one of the following: corrected IP information for IP information matching the IP address to be detected, the IDC corresponding to the corrected IP information; the switch used to forward packets of the terminal device to which the corrected IP information belongs belongs to the IDC corresponding to the corrected IP information.
6. The method according to claim 1, characterized in that, The IP information recorded in the preset storage space includes at least one of the following: the IP address to be matched, and the IP network segment to be matched; Before determining that the IP address to be detected is an abnormal IP address if no matching IP information is found in the IP information recorded in the preset storage space, the method further includes: If there is neither an IP address identical to the IP address to be detected nor an IP network segment identical to the network segment to which the IP address to be detected belongs in the preset storage space, it is determined that there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space. If an IP address identical to the IP address to be detected exists in the preset storage space, the IP address identical to the IP address to be detected is determined to be: the IP information in the preset storage space that matches the IP address to be detected; If an IP network segment exists in the preset storage space that is the same as the network segment to which the IP address to be detected belongs, the IP network segment that is the same as the network segment to which the IP address to be detected belongs is determined to be: the IP information in the preset storage space that matches the IP address to be detected.
7. The method according to claim 1, characterized in that, The IP address to be detected includes the source IP address and / or the destination IP address; The data center to which the first switch belongs is determined based on the following method: If the IP address to be detected is the source IP address, determine the source switch address carried in the service packet, and find the IDC corresponding to the source switch address from the pre-recorded correspondence between switch addresses and IDCs, and use it as the IDC to which the first switch belongs. If the IP address to be detected is the destination IP address, determine the destination switch address carried in the service message, and find the IDC corresponding to the destination switch address from the pre-recorded correspondence between switch addresses and IDCs, and use it as the IDC to which the first switch belongs.
8. The method according to claim 1, characterized in that, If no IP information matching the IP address to be detected is found in the IP information recorded in the preset storage space, the step of determining the IP address to be detected as an abnormal IP address includes: Obtain a preset whitelist; wherein the preset whitelist records preset attribute values for specified attributes of service packets; the specified attributes include at least one of the following: the network protocol type of the service packet, the service type of the service packet, and the IDC to which the switch used to forward the service packet belongs; Obtain the attribute value of the service message to be detected for the specified attribute, and use it as the attribute value to be detected; If the attribute value to be detected has the same attribute value as the preset attribute value, the IP address to be detected is determined to be a normal IP, and the IP address to be detected and the IDC to which the first switch belongs are recorded in the preset storage space accordingly; If the attribute value to be detected does not have the same attribute value as the preset attribute values, and if the IP information recorded in the preset storage space does not contain IP information that matches the IP address to be detected, then the IP address to be detected is determined to be an abnormal IP address.
9. An abnormal IP detection device, characterized in that, The device includes: The acquisition module is used to acquire the IP address to be detected carried in the service message when a service message to be detected is received. The first detection module is used to determine that the IP address to be detected is an abnormal IP address if there is no IP information matching the IP address to be detected in the IP information recorded in the preset storage space; wherein, the preset storage space is used to record the IP information allocated to each terminal device; for each IP information, the preset storage space also records the Internet Data Center (IDC) corresponding to the IP information; the switch used to forward the packets of the terminal device to which the IP information belongs belongs to the IDC corresponding to the IP information; The second detection module is used to determine that the IP address to be detected is an abnormal IP address if there is IP information in the preset storage space that matches the IP address to be detected, and the IDC of the first switch used to forward the packets of the terminal device to which the IP address to be detected belongs is different from the IDC corresponding to the IP information in the preset storage space that matches the IP address to be detected.
10. A testing device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, when executing a program stored in memory, implements the steps of the method described in any one of claims 1-8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method described in any one of claims 1-8.
Citation Information
Patent Citations
Sweep attack detection method and device, medium and electronic equipment
CN114338120A
Blocking processing method and device for malicious IP address, equipment and storage medium
CN115174243A