Network Information Security Maintenance System Based on Big Data
By obtaining and analyzing the IP addresses and other information of UDP data packets, filtering out attack nodes and making corresponding adjustments, the threat of UDP flood attacks to the server is solved, and the server's credibility and operational efficiency is improved.
Patent Information
- Application Number
- CN202411019411.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-29
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-07-29
AI Technical Summary
When handling UDP flood attacks, existing network information security maintenance systems cannot effectively distinguish between normal UDP packets and attack UDP packets, resulting in reduced server trustworthiness and inability to dynamically adjust UDP packets in time and dynamically when business volume changes, resulting in reduced server data processing performance.
The server data information acquisition module obtains the access IP address and other information of the UDP data packets, and uses the network attack analysis module and the attack node analysis module to filter out the attack nodes. The UDP data regulation and analysis module adjusts the UDP traffic rate and buffer space, and the server maintenance and processing module adjusts and deletes the attack data packets accordingly.
It improves the credibility of the server, reduces the threat of UDP flood attacks, ensures the normal operation of the server and efficient processing of data, and reduces the problem of performance degradation.
Smart Images

Figure CN118748620B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network information security, and particularly to a network information security maintenance system based on big data. Background Art
[0002] With the development of the Internet, the amount of network data has increased significantly. However, the traditional network information security maintenance system has performance bottlenecks when dealing with a large amount of data, resulting in increasingly prominent network security problems, thus reducing the security of network information. Big data analysis has characteristics such as high speed and the ability to process a large amount of data. Therefore, it is necessary to research a network security information maintenance system based on big data to ensure the security of network information.
[0003] The prior art, such as the invention patent application with the publication number of CN117478349A, discloses a network information security maintenance system based on big data. The system includes: obtaining the information source of network information through an information collection module; obtaining an information source index according to the level of the information source and the account credit degree; obtaining an information quality index according to the level of information quality; obtaining a security index according to the information source index and the information quality index; when the security index belongs to the error security index interval, marking the corresponding network information as dangerous information; and a security alarm module deleting the network information marked as dangerous information and reducing the account credit degree of the corresponding uploading user, improving the security and greenness of the network environment.
[0004] The prior art, such as the invention patent application with the publication number of CN115001877B, discloses a big data-based information security operation and maintenance management system and method. The system includes: marking the collection time of operation status data and network attack data; converting each index data in the operation status data of different node devices into an operation trend curve that changes with time; extracting the trend feature data of the operation trend curve; and generating a trend alarm information containing abnormal trend feature data. This application quickly locates the faulty node device, evaluates the severity of the node device failure, and performs security maintenance on the node device to improve the system security.
[0005] As can be seen from the above solution, in the current network information security maintenance system, on the one hand, there is a lack of due attention to the comprehensive analysis of UDP flood attacks through historical data, IP addresses and other information. UDP flood attacks will forge the source IP address and send a large number of UDP data packets to attack the server, resulting in the server being unable to be used normally. Among these large numbers of UDP data packets, there are often some normal UDP data packets. If there is no comprehensive analysis of UDP flood attacks, it is easy to have the problem that normal UDP data packets cannot be served normally by the server, thus reducing the credibility of the server. On the other hand, there is a lack of attention to the trend analysis of UDP data volume and adjusting the relevant data of UDP data packets accordingly. When the business volume of the server increases or decreases, if the relevant data of UDP data packets are not adjusted dynamically in time, it is easy to cause the problem of reduced performance of the server in processing data, thus reducing the operating efficiency of the server. Summary of the Invention
[0006] The purpose of the present invention is to provide a network information security maintenance system based on big data, which solves the problems existing in the background technology.
[0007] To solve the above technical problems, the present invention adopts the following technical solutions: The present invention provides a network information security maintenance system based on big data, including: a server data information acquisition module, which is used to acquire the access IP address, storage occupancy value, and octal code of the message content of each user datagram protocol data packet of each node to which the server belongs at the current monitoring time point, and record the user datagram protocol data packet as a UDP data packet.
[0008] A network attack analysis module, which is used to analyze the sending regions of each UDP data packet of each node to which the server belongs, and screen each attack node and each regular node to which the server belongs.
[0009] An attack node analysis module, which is used to analyze the UDP traffic rate adjustment value of each sending region of each attack node to which the server belongs, and screen each allowed UDP data packet and each rejected UDP data packet of each attack node to which the server belongs.
[0010] A UDP data adjustment analysis module, which is used to analyze the UDP buffer space adjustment value of each node to which the server belongs, and calculate the UDP data packet length adjustment value of each node to which the server belongs.
[0011] The server maintenance processing module is used to send the UDP traffic rate adjustment values of each sending region of each attack node to which the server belongs, the UDP buffer space adjustment values of each node, and the UDP packet length adjustment values to the server processing terminal, and perform corresponding adjustments, delete each rejected UDP packet of each attack node to which the server belongs, and send each attack node to which the server belongs to the person in charge of network security maintenance.
[0012] Preferably, the method for analyzing the sending regions of each UDP packet of each node to which the server belongs is as follows: by using the IP address location query tool carried, and based on the access IP address of each UDP packet of each node to which the server belongs, the sending regions of each UDP packet of each node to which the server belongs are obtained.
[0013] Preferably, the method for screening each attack node and each normal node to which the server belongs is as follows: based on the sending regions of each UDP packet of each node to which the server belongs, each UDP packet of each sending region of each node to which the server belongs is mapped.
[0014] Analyze the threat coefficient β of abnormal data volume in each sending region of each node to which the server belongs xn , where x represents the number of each node, x = 1, 2,..., y, y is a positive integer greater than 2, n represents the number of each sending region, n = 1, 2,..., m, and m is a positive integer greater than 2.
[0015] Analyze the anomaly coefficient δ of the sending regions of each node to which the server belongs x .
[0016] Calculate the UDP attack threat coefficient of each node to which the server belongs
[0017] Obtain the UDP attack threat coefficient threshold from the local database, compare the UDP attack threat coefficient of each node to which the server belongs with the UDP attack threat coefficient threshold. If the UDP attack threat coefficient of a certain node to which the server belongs is greater than the UDP attack threat coefficient threshold, then mark this node as an attack node; otherwise, mark this node as a normal node, so as to screen each attack node and each normal node to which the server belongs.
[0018] Preferably, the method for specifically analyzing the threat coefficient of abnormal data volume in each sending region of each node to which the server belongs is as follows: obtain the received quantity a of suitable UDP packets in each sending region of each node to which the server belongs from the local database xn and the sending quantity b of UDP packets at each historical monitoring time point xni , where i represents the number of each historical monitoring time point, i = 1, 2,..., j, and j is a positive integer greater than 2.
[0019] Based on each UDP packet in each sending area of each node to which the server belongs, count the total number c of UDP packets in each sending area of each node to which the server belongs. xn .
[0020] Calculate the threat coefficient of abnormal data volume for each sending area of each node to which the server belongs. Where e represents the natural constant and j represents the number of historical monitoring time points.
[0021] Preferably, for analyzing the abnormal coefficient of the sending area of each node to which the server belongs, the specific analysis method is: obtain each historical receiving area of each node to which the server belongs from the local database.
[0022] Perform a consistency comparison between each sending area of each node to which the server belongs and each historical receiving area. If a certain sending area of a certain node to which the server belongs is inconsistent with all historical receiving areas, then mark this sending area as the target area, thereby screening each target area of each node to which the server belongs, and counting the number d of target areas of each node to which the server belongs. x .
[0023] Count the number f of sending areas of each node to which the server belongs, and calculate the abnormal coefficient of the sending area of each node to which the server belongs. x , calculate the abnormal coefficient of the sending area of each node to which the server belongs.
[0024] Preferably, for analyzing the UDP traffic rate adjustment value of each sending area of each attacking node to which the server belongs, the specific analysis method is: based on the threat coefficient of abnormal data volume of each sending area of each node to which the server belongs, extract the threat coefficient of abnormal data volume of each sending area of each attacking node to which the server belongs.
[0025] Obtain the UDP traffic rate adjustment value corresponding to each threat coefficient interval of abnormal data volume from the local database, and map to obtain the UDP traffic rate adjustment value of each sending area of each attacking node to which the server belongs.
[0026] Obtain the current UDP traffic rate of each sending area of each attacking node to which the server belongs from the local database, and add the UDP traffic rate adjustment value of each sending area of each attacking node to which the server belongs, thereby calculating the UDP traffic rate adjustment value of each sending area of each attacking node to which the server belongs.
[0027] Preferably, for screening each allowed UDP packet and each rejected UDP packet of each attacking node to which the server belongs, the specific screening method is: obtain each suitable octal code of the message content from the local database.
[0028] According to the octal codes of the message contents of each UDP packet of each node to which the server belongs, extract the octal codes of the message contents of each UDP packet of each attacking node to which the server belongs, and compare them with the octal codes of each appropriate message content. If the octal code of the message content of a certain UDP packet of a certain attacking node to which the server belongs is the same as the octal code of a certain appropriate message content, then mark this UDP packet as an analyzed UDP packet, so as to screen out each analyzed UDP packet of each attacking node to which the server belongs, and mark the remaining UDP packets of each attacking node to which the server belongs as UDP packets refused to be analyzed, so as to obtain each UDP packet refused to be analyzed of each attacking node to which the server belongs.
[0029] According to the storage occupancy values of each UDP packet of each node to which the server belongs, extract the storage occupancy value g of each analyzed UDP packet of each attacking node to which the server belongs rt and the storage occupancy value h of each UDP packet refused to be analyzed ru , where r represents the number of each attacking node, r = 1, 2,..., s, s is a positive integer greater than 2, t represents the number of each analyzed UDP packet, t = 1, 2,..., v, v is a positive integer greater than 2, and u represents the number of each refused UDP packet, u = 1, 2,..., w, w is a positive integer greater than 2.
[0030] Obtain the appropriate storage occupancy value A from the local database, and calculate the storage occupancy variation coefficient of each analyzed UDP packet of each attacking node to which the server belongs where w represents the number of refused UDP packets.
[0031] Analyze each allowed UDP packet and each refused UDP packet in each analyzed UDP packet of each attacking node to which the server belongs.
[0032] Mark each UDP packet refused to be analyzed of each attacking node to which the server belongs as each refused UDP packet.
[0033] Summarize each allowed UDP packet and each refused UDP packet of each attacking node to which the server belongs.
[0034] Preferably, for the analysis of the UDP buffer space adjustment value of each node to which the server belongs, the specific analysis method is: obtain the received quantity of UDP packets of each node to which the server belongs at each historical monitoring time point from the local database, and extract the received quantity F of UDP packets of each attacking node to which the server belongs at each historical monitoring time point ri , and extract the received quantity L of UDP packets of each normal node to which the server belongs at each historical monitoring time point pi, where p represents the numbers of each regular node, p = 1, 2,..., q, q is a positive integer greater than 2, and the number of received UDP packets G of each attack node to which the extraction server belongs at the last historical monitoring time point is extracted. r , and the number of received UDP packets H of each regular node to which the server belongs at the last historical monitoring time point is extracted. p .
[0035] Based on the UDP packets of each node to which the server belongs, the UDP packets of each regular node to which the server belongs are extracted, and the number E of UDP packets of each regular node to which the server belongs is counted. p .
[0036] Based on the allowed UDP packets of each attack node to which the server belongs, the number D of allowed UDP packets of each attack node to which the server belongs is counted. r .
[0037] Calculate the historical received data fluctuation tuning parameter values of each node to which the server belongs, and extract the historical received data fluctuation tuning parameter values B of each attack node to which the server belongs. r and the historical received data fluctuation tuning parameter values C of each regular node. p .
[0038] Calculate the data quantity evaluation coefficients of each attack node to which the server belongs.
[0039]
[0040] Calculate the data quantity evaluation coefficients of each regular node to which the server belongs.
[0041]
[0042] Obtain the UDP buffer space adjustment values corresponding to each data quantity evaluation coefficient interval from the local database, map to obtain the UDP buffer space adjustment values of each attack node to which the server belongs and the UDP buffer space adjustment values of each regular node, and summarize to obtain the UDP buffer space adjustment values of each node to which the server belongs.
[0043] Preferably, for the calculation of the historical received data fluctuation tuning parameter values of each node to which the server belongs, the specific calculation method is: based on the number k of received UDP packets of each node to which the server belongs at each historical monitoring time point. xi , calculate the historical received data fluctuation coefficients of each node to which the server belongs.
[0044]
[0045] Obtain the historical received data fluctuation tuning values corresponding to each historical received data fluctuation coefficient interval from the local database, and map to obtain the historical received data fluctuation tuning values of each node to which the server belongs.
[0046] Preferably, the specific calculation method for calculating the UDP packet length adjustment value of each node to which the computing server belongs is: obtain the UDP packet length adjustment value corresponding to each data quantity evaluation coefficient interval from the local database, map to obtain the UDP packet length adjustment value of each attack node and each normal node to which the server belongs, and summarize to obtain the UDP packet length adjustment value of each node to which the server belongs.
[0047] The beneficial effects of the present invention are as follows: (1) The server data information acquisition module of the present invention facilitates subsequent analysis by acquiring the data information of each node to which the server belongs.
[0048] (2) The network attack analysis module of the present invention comprehensively analyzes a large amount of historical data and existing data, and intelligently screens out each attack node and each normal node to which the server belongs, thereby facilitating subsequent analysis.
[0049] (3) The attack node analysis module of the present invention screens out normal UDP packets in each attack node to which the server belongs. On the one hand, it reduces the situation where normal UDP packets are denied service together because they are from the same region as the UDP data used for attacks, improving the credibility of the server. On the other hand, it limits the UDP traffic rate of each sending region of each attack node to which the server belongs, reducing the threat of UDP flood attacks.
[0050] (4) The UDP data adjustment analysis module of the present invention performs trend analysis on the UDP data volume, thereby analyzing the relevant adjustment values of UDP packets, facilitating subsequent processing.
[0051] (5) The server maintenance processing module of the present invention deletes each rejected UDP packet in a timely manner and performs relevant adjustments on each attack node to which the server belongs, thereby reducing the threat of UDP flood attacks to the server, improving the security of the server, and dynamically adjusting the relevant data of UDP packets in a timely manner. By releasing or increasing relevant data in a timely manner, it ensures the normal operation of the server, reduces the incidence of performance degradation problems in the server's data processing, and improves the operating efficiency of the server. Description of the Drawings
[0052] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0053] Figure 1 It is a schematic diagram of the system modules of the present invention. Detailed implementation manners
[0054] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0055] Refer to Figure 1 As shown, the present invention provides a network information security maintenance system based on big data, including: a server data information acquisition module, a network attack analysis module, an attack node analysis module, a UDP data adjustment analysis module, a server maintenance processing module, and a local database.
[0056] It should be noted that the server data information acquisition module is connected to the network attack analysis module, the network attack analysis module is connected to the attack node analysis module, the attack node analysis module is connected to the UDP data adjustment analysis module, the UDP data adjustment analysis module is connected to the server maintenance processing module, and the local database is connected to the network attack analysis module, the attack node analysis module, and the UDP data adjustment analysis module.
[0057] It should also be noted that the local database is used to store the UDP attack threat coefficient threshold, the appropriate UDP packet reception quantity for each sending area of each node to which the server belongs, the UDP packet sending quantity at each historical monitoring time point, each historical receiving area of each node to which the server belongs, the UDP traffic rate adjustment value corresponding to each abnormal data volume threat coefficient interval, the current UDP traffic rate of each sending area of each attack node to which the server belongs, each appropriate message content octal code, the appropriate storage occupancy value, the storage occupancy mutation coefficient threshold, the UDP packet reception quantity of each node to which the server belongs at each historical monitoring time point, the UDP buffer space adjustment value corresponding to each data quantity evaluation coefficient interval, the historical received data fluctuation adjustment parameter value corresponding to each historical received data fluctuation coefficient interval, and the UDP packet length adjustment value corresponding to each data quantity evaluation coefficient interval.
[0058] The server data information acquisition module is used to acquire the access IP address, storage occupancy value, and octal code of the message content of each User Datagram Protocol (UDP) packet of each node to which the server belongs at the current monitoring time point, and record the User Datagram Protocol packet as a UDP packet.
[0059] In a specific embodiment, the method for acquiring the access IP address, length, storage occupancy value, and octal code of the message content of each UDP packet of each node to which the server belongs at the current monitoring time point is as follows: Through the control platform of each node to which the server belongs, acquire the access IP address, length, storage occupancy value, and octal code of the message content of each UDP packet of each node to which the server belongs at the current monitoring time point.
[0060] The server data information acquisition module of the present invention facilitates subsequent analysis by acquiring the data information of each node to which the server belongs.
[0061] The network attack analysis module is used to analyze the sending regions of each UDP packet of each node to which the server belongs, and screen each attack node and each normal node to which the server belongs.
[0062] In a specific embodiment of the present invention, the method for analyzing the sending regions of each UDP packet of each node to which the server belongs is as follows: Through the IP address location query tool carried, and based on the access IP address of each UDP packet of each node to which the server belongs, acquire the sending regions of each UDP packet of each node to which the server belongs.
[0063] It should be noted that the existing IP address location query tools are relatively mature, and through the existing IP address location query tools, the sending regions of each UDP packet of each node to which the server belongs can be acquired.
[0064] In a specific embodiment of the present invention, the method for screening each attack node and each normal node to which the server belongs is as follows: Based on the sending regions of each UDP packet of each node to which the server belongs, map to obtain each UDP packet of each sending region of each node to which the server belongs.
[0065] Analyze the threat coefficient β of the abnormal data volume of each sending region of each node to which the server belongs xn , where x represents the number of each node, x = 1, 2,..., y, y is a positive integer greater than 2, n represents the number of each sending region, n = 1, 2,..., m, and m is a positive integer greater than 2.
[0066] Analyze the anomaly coefficient δ of the sending regions of each node to which the server belongs x .
[0067] Calculate the UDP attack threat coefficients of each node to which the computing server belongs
[0068] Obtain the UDP attack threat coefficient threshold from the local database, compare the UDP attack threat coefficients of each node to which the server belongs with the UDP attack threat coefficient threshold. If the UDP attack threat coefficient of a certain node to which the server belongs is greater than the UDP attack threat coefficient threshold, mark this node as an attack node; otherwise, mark this node as a normal node, so as to screen each attack node and each normal node to which the server belongs.
[0069] In a specific embodiment of the present invention, for analyzing the threat coefficients of abnormal data volumes in each sending area of each node to which the server belongs, the specific analysis method is: obtain the received quantity a of appropriate UDP data packets in each sending area of each node to which the server belongs from the local database xn and the sent quantity b of UDP data packets at each historical monitoring time point xni , where i represents the number of each historical monitoring time point, i = 1, 2,..., j, and j is a positive integer greater than 2.
[0070] Based on each UDP data packet in each sending area of each node to which the server belongs, count the total quantity c of UDP data packets in each sending area of each node to which the server belongs xn .
[0071] Calculate the threat coefficients of abnormal data volumes in each sending area of each node to which the server belongs where e represents the natural constant and j represents the number of historical monitoring time points.
[0072] In a specific embodiment of the present invention, for analyzing the abnormal coefficient of the sending area of each node to which the server belongs, the specific analysis method is: obtain each historical receiving area of each node to which the server belongs from the local database.
[0073] Perform a consistency comparison between each sending area of each node to which the server belongs and each historical receiving area. If a certain sending area of a certain node to which the server belongs is inconsistent with each historical receiving area, mark this sending area as a target area, so as to screen each target area of each node to which the server belongs, and count the quantity d of target areas of each node to which the server belongs x .
[0074] Count the quantity f of sending areas of each node to which the server belongs x , and calculate the abnormal coefficient of the sending area of each node to which the server belongs
[0075] The network attack analysis module of the present invention conducts comprehensive analysis through a large amount of historical data and existing data, and intelligently screens out each attack node and each regular node to which the server belongs, thereby facilitating subsequent analysis.
[0076] The attack node analysis module is used to analyze the UDP traffic rate adjustment values of each sending region of each attack node to which the server belongs, and screen out each allowed UDP packet and each rejected UDP packet of each attack node to which the server belongs.
[0077] In a specific embodiment of the present invention, for the analysis of the UDP traffic rate adjustment values of each sending region of each attack node to which the server belongs, the specific analysis method is as follows: According to the threat coefficient of abnormal data volume of each sending region of each node to which the server belongs, extract the threat coefficient of abnormal data volume of each sending region of each attack node to which the server belongs.
[0078] Obtain the UDP traffic rate adjustment values corresponding to each threat coefficient interval of abnormal data volume from the local database, and map to obtain the UDP traffic rate adjustment values of each sending region of each attack node to which the server belongs.
[0079] Obtain the current UDP traffic rate of each sending region of each attack node to which the server belongs from the local database, and add the UDP traffic rate adjustment value of each sending region of each attack node to which the server belongs, so as to calculate the UDP traffic rate adjustment value of each sending region of each attack node to which the server belongs.
[0080] In a specific embodiment of the present invention, for the screening of each allowed UDP packet and each rejected UDP packet of each attack node to which the server belongs, the specific screening method is as follows: Obtain the octal code of each appropriate message content from the local database.
[0081] According to the octal code of the message content of each UDP packet of each node to which the server belongs, extract the octal code of the message content of each UDP packet of each attack node to which the server belongs, and compare it with the octal code of each appropriate message content. If the octal code of the message content of a certain UDP packet of a certain attack node to which the server belongs is consistent with the octal code of a certain appropriate message content, mark this UDP packet as an analyzed UDP packet, so as to screen out each analyzed UDP packet of each attack node to which the server belongs, and mark the remaining UDP packets of each attack node to which the server belongs as rejected analyzed UDP packets, so as to obtain each rejected analyzed UDP packet of each attack node to which the server belongs.
[0082] According to the storage occupancy value of each UDP packet of each node to which the server belongs, extract the storage occupancy value g of each analyzed UDP packet of each attack node to which the server belongs rt and the storage occupancy value h of each rejected analyzed UDP packet ru, where r represents the numbers of each attack node, r = 1, 2, ..., s, s is a positive integer greater than 2, t represents the numbers of each analyzed UDP packet, t = 1, 2, ..., v, v is a positive integer greater than 2, and u represents the numbers of each rejected UDP packet, u = 1, 2, ..., w, w is a positive integer greater than 2.
[0083] Obtain the appropriate storage occupancy value A from the local database, and calculate the storage occupancy mutation coefficient of each analyzed UDP packet of each attack node to which the server belongs Where w represents the number of rejected UDP packets.
[0084] Analyze each allowed UDP packet and each rejected UDP packet in each analyzed UDP packet of each attack node to which the server belongs.
[0085] Mark each rejected analyzed UDP packet of each attack node to which the server belongs as each rejected UDP packet.
[0086] Summarize each allowed UDP packet and each rejected UDP packet of each attack node to which the server belongs.
[0087] In a specific embodiment, for each allowed UDP packet and each rejected UDP packet in each analyzed UDP packet of each attack node to which the server belongs, the specific analysis method is as follows: Obtain the storage occupancy mutation coefficient threshold from the local database, compare the storage occupancy mutation coefficient of each analyzed UDP packet of each attack node to which the server belongs with the storage occupancy mutation coefficient threshold. If the storage occupancy mutation coefficient of a certain analyzed UDP packet of a certain attack node to which the server belongs is greater than the storage occupancy mutation coefficient threshold, then mark this analyzed UDP packet as a rejected UDP packet; otherwise, mark this analyzed UDP packet as an allowed UDP packet, so as to screen each allowed UDP packet and each rejected UDP packet in each analyzed UDP packet of each attack node to which the server belongs.
[0088] The attack node analysis module of the present invention, by screening the normal UDP packets of each attack node to which the server belongs, on the one hand, reduces the situation where normal UDP packets are rejected together because they are from the same region as the UDP data used for attacks, improving the credibility of the server. On the other hand, it limits the UDP traffic rate of each sending region of each attack node to which the server belongs, reducing the threat of UDP flood attacks.
[0089] The UDP data adjustment analysis module is used to analyze the UDP buffer space adjustment value of each node to which the server belongs, and calculate the UDP packet length adjustment value of each node to which the server belongs.
[0090] In a specific embodiment of the present invention, the method for specifically analyzing the UDP buffer space adjustment value of each node to which the analysis server belongs is as follows: Obtain the number of received UDP packets of each node to which the server belongs at each historical monitoring time point from the local database, and extract the number of received UDP packets F of each attack node to which the server belongs at each historical monitoring time point ri and extract the number of received UDP packets L of each normal node to which the server belongs at each historical monitoring time point pi , where p represents the number of each normal node, p = 1, 2,..., q, q is a positive integer greater than 2, extract the number of received UDP packets G of each attack node to which the server belongs at the last historical monitoring time point r and extract the number of received UDP packets H of each normal node to which the server belongs at the last historical monitoring time point p .
[0091] Extract the UDP packets of each normal node to which the server belongs based on the UDP packets of each node to which the server belongs, and count the number E of UDP packets of each normal node to which the server belongs p .
[0092] Count the number D of allowed UDP packets of each attack node to which the server belongs based on the allowed UDP packets of each attack node to which the server belongs r .
[0093] Calculate the historical received data fluctuation tuning parameter value of each node to which the server belongs, and extract the historical received data fluctuation tuning parameter value B of each attack node to which the server belongs r and the historical received data fluctuation tuning parameter value C of each normal node to which the server belongs p .
[0094] Calculate the data quantity evaluation coefficient of each attack node to which the server belongs
[0095]
[0096] Calculate the data quantity evaluation coefficient of each normal node to which the server belongs
[0097]
[0098] Obtain the UDP buffer space adjustment value corresponding to each data quantity evaluation coefficient interval from the local database, map to obtain the UDP buffer space adjustment value of each attack node to which the server belongs and the UDP buffer space adjustment value of each normal node to which the server belongs, and summarize to obtain the UDP buffer space adjustment value of each node to which the server belongs.
[0099] It should be noted that the data quantity evaluation coefficient is positively correlated with the UDP buffer space adjustment value. The larger the data quantity evaluation coefficient, the larger the UDP buffer space adjustment value, and the data quantity evaluation coefficient can be negative. In this case, the UDP buffer space adjustment value is negative, which is used to reduce the use of the UDP buffer space.
[0100] In a specific embodiment of the present invention, the historical received data fluctuation tuning value of each node to which the computing server belongs is calculated as follows: based on the received quantity k of UDP data packets of each node to which the server belongs at each historical monitoring time point xi , calculate the historical received data fluctuation coefficient of each node to which the server belongs
[0101]
[0102] Obtain the historical received data fluctuation tuning value corresponding to each historical received data fluctuation coefficient interval from the local database, and map to obtain the historical received data fluctuation tuning value of each node to which the server belongs.
[0103] In a specific embodiment of the present invention, the UDP data packet length adjustment value of each node to which the computing server belongs is calculated as follows: obtain the UDP data packet length adjustment value corresponding to each data quantity evaluation coefficient interval from the local database, map to obtain the UDP data packet length adjustment value of each attacking node and each normal node to which the server belongs, and summarize to obtain the UDP data packet length adjustment value of each node to which the server belongs.
[0104] It should be noted that the data quantity evaluation coefficient is negatively correlated with the UDP data packet length adjustment value. The larger the data quantity evaluation coefficient, the smaller the UDP data packet length adjustment value. When the data quantity evaluation coefficient is positive, the UDP data packet length adjustment value is negative, which is used to reduce the UDP data packet length.
[0105] The UDP data adjustment analysis module of the present invention performs trend analysis on the UDP data volume, thereby analyzing the relevant adjustment values of UDP data packets, which is convenient for subsequent processing.
[0106] The server maintenance processing module is used to send the UDP traffic rate adjustment value of each sending area of each attacking node to which the server belongs, the UDP buffer space adjustment value and the UDP data packet length adjustment value of each node to the server processing terminal, and perform corresponding adjustments, delete each rejected UDP data packet of each attacking node to which the server belongs, and send each attacking node to which the server belongs to the network security maintenance person in charge.
[0107] The server maintenance processing module of the present invention reduces the threat of UDP flood attacks to the server by promptly deleting each rejected UDP data packet and performing relevant adjustments on each attack node to which the server belongs, thereby improving the security of the server. It also promptly and dynamically adjusts the relevant data of UDP data packets, ensures the normal operation of the server by promptly releasing or increasing relevant data, reduces the incidence of problems with the performance degradation of the server in processing data, and improves the operating efficiency of the server.
[0108] The above content is only an example and illustration of the concept of the present invention. Those skilled in the art of the present technology can make various modifications, supplements, or use similar methods for substitution to the specific embodiments described, as long as they do not deviate from the concept of the invention or exceed the scope defined by the present invention, they should fall within the protection scope of the present invention.
Claims
1. A network information security maintenance system based on big data, characterized in that, Including: A server data information acquisition module, which is used to acquire the access IP addresses, storage occupancy values, and octal codes of the message contents of each User Datagram Protocol (UDP) packet of each node to which the server belongs at the current monitoring time point, and record the User Datagram Protocol packets as UDP packets; A network attack analysis module, which is used to analyze the sending regions of each UDP packet of each node to which the server belongs, and screen each attack node and each normal node to which the server belongs; An attack node analysis module, which is used to analyze the UDP traffic rate adjustment values of each sending region of each attack node to which the server belongs, and screen each allowed UDP packet and each rejected UDP packet of each attack node to which the server belongs; For screening each allowed UDP packet and each rejected UDP packet of each attack node to which the server belongs, the specific screening method is as follows: Obtain each appropriate octal code of the message content from the local database; According to the octal codes of the message contents of each UDP packet of each node to which the server belongs, extract the octal codes of the message contents of each UDP packet of each attack node to which the server belongs, and compare them with each appropriate octal code of the message content. If the octal code of the message content of a certain UDP packet of a certain attack node to which the server belongs is consistent with a certain appropriate octal code of the message content, mark this UDP packet as an analyzed UDP packet, so as to screen each analyzed UDP packet of each attack node to which the server belongs, and mark the remaining UDP packets of each attack node to which the server belongs as rejected analyzed UDP packets, so as to obtain each rejected analyzed UDP packet of each attack node to which the server belongs; Extract the storage occupancy values g of each analyzed UDP packet of each attack node to which the server belongs according to the storage occupancy values of each UDP packet of each node to which the server belongs rt and the storage occupancy values h of each rejected analyzed UDP packet ru , where r represents the numbers of each attack node, r = 1, 2,..., s, s is a positive integer greater than 2, t represents the numbers of each analyzed UDP packet, t = 1, 2,..., v, v is a positive integer greater than 2, and u represents the numbers of each rejected UDP packet, u = 1, 2,..., w, w is a positive integer greater than 2; Obtain the appropriate storage occupancy value A from the local database, and calculate the storage occupancy mutation coefficient of each analyzed UDP packet of each attack node to which the server belongs where w represents the number of rejected UDP packets; Analyze each allowed UDP packet and each rejected UDP packet in each analyzed UDP packet of each attack node to which the server belongs; Mark each rejected analyzed UDP packet of each attack node to which the server belongs as each rejected UDP packet; Summarize each allowed UDP packet and each rejected UDP packet of each attack node to which the server belongs; A UDP data adjustment analysis module, which is used to analyze the UDP buffer space adjustment value of each node to which the server belongs, and calculate the UDP packet length adjustment value of each node to which the server belongs; For analyzing the UDP buffer space adjustment value of each node to which the server belongs, the specific analysis method is as follows: Obtain the received quantity of UDP packets of each node to which the server belongs at each historical monitoring time point from the local database, and extract the received quantity F of UDP packets of each attack node to which the server belongs at each historical monitoring time point ri , and extract the received quantity L of UDP packets of each normal node to which the server belongs at each historical monitoring time point pi , where p represents the number of each normal node, p = 1, 2,..., q, q is a positive integer greater than 2, and extract the received quantity G of UDP packets of each attack node to which the server belongs at the last historical monitoring time point r , and extract the received quantity H of UDP packets of each normal node to which the server belongs at the last historical monitoring time point p ; Extract the UDP packets of each regular node to which the server belongs based on the UDP packets of each node to which the server belongs, and count the number E of UDP packets of each regular node to which the server belongs p ; According to each allowed UDP packet of each attack node to which the server belongs, count the number D of allowed UDP packets of each attack node to which the server belongs r ; Calculate the historical received data fluctuation tuning parameter values of each node to which the computing server belongs, and extract the historical received data fluctuation tuning parameter values B of each attack node to which the server belongs r and the historical received data fluctuation tuning parameter values C of each normal node p ; Calculate the data quantity evaluation coefficient of each attack node to which the computing server belongs Calculate the data quantity evaluation coefficient of each regular node to which the computing server belongs Obtain the UDP buffer space adjustment values corresponding to each data quantity evaluation coefficient interval from the local database, map to obtain the UDP buffer space adjustment values of each attack node to which the server belongs and the UDP buffer space adjustment values of each normal node, and summarize to obtain the UDP buffer space adjustment values of each node to which the server belongs; A server maintenance and processing module, which is used to send the UDP traffic rate adjustment values of each sending region of each attack node to which the server belongs, the UDP buffer space adjustment values of each node, and the UDP packet length adjustment values to the server processing terminal, and perform corresponding adjustments, delete each rejected UDP packet of each attack node to which the server belongs, and send each attack node to which the server belongs to the person in charge of network security maintenance.
2. The network information security maintenance system based on big data according to claim 1, characterized in that For analyzing the sending regions of each UDP packet of each node to which the server belongs, the specific method is as follows: By means of the IP address location query tool carried, and based on the access IP addresses of each UDP data packet of each node to which the server belongs, the sending regions of each UDP data packet of each node to which the server belongs are obtained.
3. The network information security maintenance system based on big data according to claim 1, characterized in that, Screening each attack node and each regular node to which the server belongs, the specific screening method is as follows: Based on the sending regions of each UDP data packet of each node to which the server belongs, map to obtain each UDP data packet of each sending region of each node to which the server belongs; Analyze the threat coefficient β of the abnormal data volume in each sending area of each node to which the analysis server belongs xn , where x represents the number of each node, x = 1, 2,..., y, y is a positive integer greater than 2, n represents the number of each sending area, n = 1, 2,..., m, and m is a positive integer greater than 2; Analyze the abnormal coefficient δ of the sending regions of each node to which the analysis server belongs x ; Calculate the UDP attack threat coefficients of each node to which the computing server belongs Obtain the UDP attack threat coefficient threshold from the local database, compare the UDP attack threat coefficient of each node to which the server belongs with the UDP attack threat coefficient threshold. If the UDP attack threat coefficient of a certain node to which the server belongs is greater than the UDP attack threat coefficient threshold, then mark this node as an attack node; otherwise, mark this node as a regular node, thereby screening each attack node and each regular node to which the server belongs.
4. The network information security maintenance system based on big data according to claim 3, characterized in that Analyzing the threat coefficient of the abnormal data volume of each sending region of each node to which the server belongs, the specific analysis method is as follows: Obtain the appropriate received quantity a of UDP data packets for each sending area of each node to which the server belongs from the local database xn and the sent quantity b of UDP data packets at each historical monitoring time point xni , where i represents the number of each historical monitoring time point, i = 1, 2,..., j, and j is a positive integer greater than 2; Based on each UDP packet in each sending region of each node to which the server belongs, count the total number c of UDP packets in each sending region of each node to which the server belongs xn ; Calculate the threat coefficient of abnormal data volume for each sending region of each node to which the computing server belongs Where e represents the natural constant and j represents the number of historical monitoring time points.
5. The network information security maintenance system based on big data according to claim 3, characterized in that, Analyzing the abnormal coefficient of the sending regions of each node to which the server belongs, the specific analysis method is as follows: Obtain the historical receiving regions of each node to which the server belongs from the local database; Compare the sending regions of each node to which the server belongs with each historical receiving region. If a certain sending region of a certain node to which the server belongs is inconsistent with all historical receiving regions, then mark this sending region as the target region, so as to screen the target regions of each node to which the server belongs, and count the number d of the target regions of each node to which the server belongs x ; Count the number f of sending regions of each node to which the statistical server belongs x , and calculate the anomaly coefficient of the sending regions of each node to which the computing server belongs 6. The network information security maintenance system based on big data according to claim 4, wherein, Analyzing the UDP traffic rate adjustment value of each sending region of each attack node to which the server belongs, the specific analysis method is as follows: Based on the threat coefficient of the abnormal data volume of each sending region of each node to which the server belongs, extract the threat coefficient of the abnormal data volume of each sending region of each attack node to which the server belongs; Obtain the UDP traffic rate adjustment value corresponding to each abnormal data volume threat coefficient interval from the local database, and map to obtain the UDP traffic rate adjustment value of each sending region of each attack node to which the server belongs; Obtain the current UDP traffic rate of each sending region of each attack node to which the server belongs from the local database, and add the UDP traffic rate adjustment value of each sending region of each attack node to which the server belongs, thereby calculating the UDP traffic rate adjustment value of each sending region of each attack node to which the server belongs.
7. The network information security maintenance system based on big data according to claim 1, characterized in that, Calculating the historical received data fluctuation tuning parameter value of each node to which the server belongs, the specific calculation method is as follows: According to the number k of received UDP packets at each historical monitoring time point of each node to which the server belongs xi , calculate the historical reception data fluctuation coefficient of each node to which the server belongs Obtain the historical received data fluctuation tuning parameter value corresponding to each historical received data fluctuation coefficient interval from the local database, and map to obtain the historical received data fluctuation tuning parameter value of each node to which the server belongs.
8. The network information security maintenance system based on big data according to claim 7, characterized in that Calculating the UDP data packet length adjustment value of each node to which the server belongs, the specific calculation method is as follows: Obtain the UDP data packet length adjustment value corresponding to each data quantity evaluation coefficient interval from the local database, map to obtain the UDP data packet length adjustment value of each attack node and each regular node to which the server belongs, and summarize to obtain the UDP data packet length adjustment value of each node to which the server belongs.
Citation Information
Patent Citations
A Big Data-Based Information Security Operation and Maintenance Management System and Method
CN115001877B
Network information security maintenance system based on big data
CN117478349A
Network security situation diagnosis method and system based on multi-node relevance
CN118316728A