Attack handling method, apparatus, electronic device, medium, and product

By monitoring the performance indicators of metropolitan area network (MAN) devices and using machine learning to predict future utilization rates, the timing of DDoS attack response can be determined, and black hole routes or rate limiting policies can be generated. This solves the problem of ineffective handling of DDoS attack source addresses and improves network protection capabilities and device stability.

CN118827207BActive Publication Date: 2025-11-21CHINA MOBILE GROUP ZHEJIANG +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410987402.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-23
Publication Date
2025-11-21
Estimated Expiration
2044-07-23

AI Technical Summary

Technical Problem

Existing technologies are ineffective in addressing the source address of DDoS attacks, resulting in poor network attack protection capabilities.

Method used

By monitoring the performance metrics of metropolitan area network (MAN) devices, such as uplink port utilization, CPU utilization, and memory utilization, machine learning models are used to predict future utilization rates, determine the time points for numerical conversion of handling factors, and generate black hole routes or rate limiting policies based on the attacked Internet Protocol (IP) addresses to handle the attack.

Benefits of technology

It improved the ability to protect against network attacks, avoided frequent and unnecessary interventions, ensured the stable operation of equipment and services, and enhanced the stability of the metropolitan area network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827207B_ABST
    Figure CN118827207B_ABST
Patent Text Reader

Abstract

The application provides an attack handling method and device, electronic equipment, medium and product, and belongs to the technical field of Internet. The method comprises the following steps: determining that a distributed denial of service attack exists in a to-be-processed metropolitan area network, then determining a target metropolitan area network device that generates the distributed denial of service attack; determining a handling factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; if a value of the handling factor is a first target value, determining a predicted time point at which the value of the handling factor is earliest converted into a second target value; the first target value indicates that attack handling is not needed; the second target value indicates that attack handling is needed; if a time difference between the predicted time point and a current time point is less than a preset time threshold, performing attack handling on an attacked Internet Protocol address corresponding to the distributed denial of service attack. The application can improve the protection capability of network attacks.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, and particularly relates to an attack handling method and device, electronic equipment, medium and product. BACKGROUND

[0002] Distributed Denial of Service (DDoS) attack refers to that a large number of attackers distributed in different locations simultaneously attack one or more targets, or an attacker controls a large number of bot devices located in different locations and implements attacks by using the bot devices. Since the sending points of the attacks are distributed in different locations, the attacks are called distributed denial of service attacks.

[0003] Common DDoS attacks are divided into three types: traffic type, connection type and special protocol defect type. The three types of DDoS attacks exist in the metropolitan area network, and all cause different degrees of damage to the metropolitan area network. The connection type and special protocol defect type of DDoS attacks will cause the metropolitan area network devices to be paralyzed, mainly depending on the protection ability of the metropolitan area network devices and protocols themselves and the deployment of special security protection devices, and each device manufacturer also has its own protection means. In addition, the uplink bandwidth of the devices in the metropolitan area network is generally not large, and the traffic type of DDoS attack will cause congestion in the metropolitan area network, seriously affecting the business of the metropolitan area network, and even directly causing the device to be out of control.

[0004] The current handling of DDoS attacks is carried out on the DDoS attack source address, but due to the characteristics of the DDoS attack source address being scattered and changeable, the handling effect on the DDoS attack source address is poor, and the protection ability of the current network attack is low. SUMMARY

[0005] The present application provides an attack handling method and device, electronic equipment, medium and product, to solve the problem that the current handling effect on the DDoS attack source address is poor, and the protection ability of the current network attack is low, and to improve the protection ability of the network attack.

[0006] The application provides an attack handling method, which comprises the following steps: determining that a distributed denial of service attack exists in a metropolitan area network to be processed; determining a target metropolitan area network device of the distributed denial of service attack; determining a handling factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; determining a predicted time point at which a value of the handling factor is earliest converted into a second target value if the value of the handling factor is a first target value; the first target value represents that attack handling is not needed; the second target value represents that attack handling is needed; and performing attack handling on an attacked internet protocol address corresponding to the distributed denial of service attack if a time difference between the predicted time point and a current time point is less than a preset time threshold.

[0007] According to the attack handling method provided by the application, the step of determining the predicted time point at which the value of the handling factor is earliest converted into the second target value comprises the following steps: acquiring first time sequence information of historical uplink port utilization rate, second time sequence information of historical central processing unit utilization rate and third time sequence information of historical memory utilization rate of the target metropolitan area network device; determining first time sequence prediction information of future uplink port utilization rate, second time sequence prediction information of future central processing unit utilization rate and third time sequence prediction information of future memory utilization rate based on the first time sequence information, the second time sequence information and the third time sequence information; and determining the predicted time point at which the value of the handling factor is earliest converted into the second target value based on the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information.

[0008] According to the attack handling method provided by the application, the step of determining the predicted time point at which the value of the handling factor is earliest converted into the second target value based on the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information comprises the following steps: determining a first time point of uplink port utilization rate which is earliest greater than a preset utilization rate threshold in the first time sequence prediction information; determining a second time point of central processing unit utilization rate which is earliest greater than the preset utilization rate threshold in the second time sequence prediction information; determining a third time point of memory utilization rate which is earliest greater than the preset utilization rate threshold in the third time sequence prediction information; and determining the time point which is earliest in time among the first time point, the second time point and the third time point as the predicted time point at which the value of the handling factor is earliest converted into the second target value.

[0009] According to the attack processing method provided in the application, the first time sequence information, the second time sequence information and the third time sequence information are used to determine first time sequence prediction information of future uplink port utilization, second time sequence prediction information of future central processor utilization and third time sequence prediction information of future memory utilization, respectively, which includes: inputting the first time sequence information into a first time sequence prediction model to obtain the first time sequence prediction information of future uplink port utilization output by the first time sequence prediction model; the first time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample uplink port utilization; inputting the second time sequence information into a second time sequence prediction model to obtain the second time sequence prediction information of future central processor utilization output by the second time sequence prediction model; the second time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample central processor utilization; inputting the third time sequence information into a third time sequence prediction model to obtain the third time sequence prediction information of future memory utilization output by the third time sequence prediction model; the third time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample memory utilization.

[0010] According to the attack processing method provided in the application, the performance indicators include uplink port utilization, central processor utilization and memory utilization; and the processing factor of the target metropolitan area network device is determined based on the performance indicators of the target metropolitan area network device, which includes: if any one of the uplink port utilization, the central processor utilization and the memory utilization of the performance indicators of the target metropolitan area network device is greater than a preset utilization threshold, then the value of the processing factor of the target metropolitan area network device is determined as a second target value; and if the uplink port utilization, the central processor utilization and the memory utilization of the performance indicators of the target metropolitan area network device are all less than or equal to the preset utilization threshold, then the value of the processing factor of the target metropolitan area network device is determined as a first target value.

[0011] According to the attack processing method provided in the application, the attack processing based on the attacked Internet Protocol address corresponding to the distributed denial of service attack comprises: if the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a network device address, generating a black hole routing configuration based on the attacked Internet Protocol address and issuing the black hole routing configuration to a black hole router; the black hole router issuing a border gateway protocol black hole routing in the black hole routing configuration to all network devices in the to-be-processed metropolitan area network; if the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a service address, generating a rate limiting strategy configuration based on the attacked Internet Protocol address and issuing the rate limiting strategy configuration to a black hole router; and the black hole router issuing a border gateway protocol flow specification rate limiting routing strategy in the rate limiting strategy configuration to all network devices in the to-be-processed metropolitan area network.

[0012] According to the attack processing method provided in the application, after the processing factor of the target metropolitan area network device is determined, the attack processing based on the attacked Internet Protocol address corresponding to the distributed denial of service attack is further performed if the value of the processing factor is a first target value.

[0013] The application further provides an attack processing apparatus, comprising: a first determination module configured to determine that a distributed denial of service attack exists in a to-be-processed metropolitan area network, and determine a target metropolitan area network device that generates the distributed denial of service attack; a second determination module configured to determine a processing factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; a third determination module configured to determine a predicted time point at which the value of the processing factor is earliest converted to a second target value if the value of the processing factor is a first target value; the first target value indicates that attack processing is not needed; and the second target value indicates that attack processing is needed; and a processing module configured to perform attack processing based on an attacked Internet Protocol address corresponding to the distributed denial of service attack if the time difference between the predicted time point and a current time point is less than a preset time threshold.

[0014] The application further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the attack processing method according to any one of the above when executing the program.

[0015] The application further provides a medium, which is a non-transitory computer readable storage medium, and the medium stores a computer program, and the computer program is executable on a processor to implement the attack processing method according to any one of the above.

[0016] The application also provides a product, which is a computer program product comprising a computer program, wherein the computer program is executed by a processor to implement the attack handling method according to any one of the above.

[0017] The attack handling method, device, electronic equipment, medium and product provided by the application can determine the target metropolitan area network device subjected to the distributed denial of service attack, and then accurately determine the handling factor of the target metropolitan area network device based on the performance index of the target metropolitan area network device, so that when the value of the handling factor is the first target value indicating that attack handling is not needed, the prediction time point at which the value of the handling factor is converted into the second target value indicating that attack handling is needed can be further determined, so that when the time difference between the prediction time point and the current time point is less than the preset time threshold, attack handling can be accurately performed based on the attacked Internet Protocol address corresponding to the distributed denial of service attack. Since the handling factor is determined based on the performance index of the target metropolitan area network device subjected to the distributed denial of service attack, the protection capability against the distributed denial of service attack is enhanced. When the value of the handling factor is the first target value indicating that attack handling is not needed, the prediction time point at which the value of the handling factor is converted into the second target value indicating that attack handling is needed is determined, and attack handling is performed only when the time difference between the prediction time point and the current time point is less than the preset time threshold, so that the frequent distributed denial of service attack handling when the metropolitan area network device and the business connected thereto are not affected is avoided, and the risk faced by the metropolitan area network device is reduced. Attack handling is performed based on the attacked Internet Protocol address corresponding to the distributed denial of service attack, so that the stable operation of the device to which the attacked Internet Protocol address belongs and the normal use of other businesses connected to the device are ensured, and the stability of the metropolitan area network device and the connected business is improved, so that the protection capability against network attacks can be improved. BRIEF DESCRIPTION OF DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the application or the prior art, the following will briefly introduce the drawings needed in the embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the application, and those skilled in the art can also obtain other drawings according to these drawings without creative labor.

[0019] Figure 1 is a flowchart of the attack handling method provided by the application.

[0020] Figure 2 is a schematic diagram of the overall flow of the attack handling method provided by the application.

[0021] Figure 3is a structural schematic diagram of a DDoS attack automatic handling system of the present application.

[0022] Figure 4 is a structural schematic diagram of an electronic device provided by the present application. DETAILED DESCRIPTION

[0023] For the purpose of clarity, technical solutions in the present application will be described in detail below with reference to the drawings in the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0024] It should be noted that in the description of the present application, the terms "comprise", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "comprises a" does not exclude the presence of another identical element in the process, method, article or device comprising the element. The terms "upper", "lower" and the like indicate the orientation or positional relationship shown in the drawings, and are only used to facilitate the description of the present application and simplify the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application. Unless otherwise specified and limited, the terms "mount", "connect", "connect" should be understood broadly, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium, or it can be connected inside two elements. For those of ordinary skill in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.

[0025] The terms "first", "second", and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than that illustrated or described herein, and the objects distinguished by "first", "second", etc. are usually of a kind and do not limit the number of objects, for example, the first object can be one or more. In addition, "and / or" means at least one of the connected objects, and the character " / ", generally means that the front and rear associated objects are in a "or" relationship.

[0026] The application will be described below in conjunction with Figures 1-4 The attack handling method, device, electronic device, medium and product of the application are described.

[0027] Figure 1 is a flowchart of the attack handling method provided by the application, as Figure 1 shown, the method comprises the following steps 100 to 400.

[0028] Step 100, determining that there is a distributed denial of service attack in the to-be-processed metropolitan area network, and then determining the target metropolitan area network device of the distributed denial of service attack.

[0029] Step 200, determining the handling factor of the target metropolitan area network device based on the performance index of the target metropolitan area network device.

[0030] Step 300, if the value of the handling factor is a first target value, determining a predicted time point at which the value of the handling factor is earliest converted to a second target value; the first target value indicates that no attack handling is needed; and the second target value indicates that attack handling is needed.

[0031] Step 400, if the time difference between the predicted time point and the current time point is less than a preset time threshold, performing attack handling based on the attacked Internet Protocol address corresponding to the distributed denial of service attack.

[0032] It should be noted that the execution subject of the attack handling method provided by the embodiments of the application can be a server, a computer device, etc., such as a mobile phone, a tablet computer, a notebook computer, a palm computer, a vehicle-mounted electronic device, a wearable device, an Ultra-mobile Personal Computer (UMPC), a netbook, or a Personal Digital Assistant (PDA), etc.

[0033] The server or computer device of the application can be provided with or connected to an attack handling device (the attack handling device can also be referred to as a DDoS attack automatic handling system). In the application, the attack handling device can be controlled to execute the attack handling method of the application by controlling the attack handling device.

[0034] The application monitors whether a DDoS attack occurs in each metropolitan area network.

[0035] Specifically, for each metropolitan area network that needs to be monitored, the application can be defined as a to-be-processed metropolitan area network.

[0036] Further, it can be monitored whether a DDoS attack exists in the to-be-processed metropolitan area network.

[0037] When it is determined that a DDoS attack exists in the metropolitan area network to be processed, the application can identify the attacked Internet Protocol (IP) address (which can be referred to as the attacked Internet Protocol address hereinafter).

[0038] Further, the application can determine the metropolitan area network device of the attacked Internet Protocol address through a routing query, and define the metropolitan area network device as a target metropolitan area network device.

[0039] Further, the application can obtain performance indicators such as the utilization rate of the uplink port, the CPU utilization rate, and the memory utilization rate of the target metropolitan area network device.

[0040] Further, according to the performance indicators such as the utilization rate of the uplink port, the CPU utilization rate, and the memory utilization rate of the target metropolitan area network device, the disposal factor of the target metropolitan area network device is determined. Specifically, the disposal factor of the target metropolitan area network device can be determined to be at a current value. The value of the disposal factor in the application can be a first target value or a second target value, where the first target value indicates that no attack disposal is needed, and the second target value indicates that attack disposal is needed. In an embodiment, the first target value may, for example, be 0, and the second target value may, for example, be 1.

[0041] Further, if it is determined that the value of the disposal factor is the first target value, the prediction time point at which the value of the disposal factor of the target metropolitan area network device is converted to the second target value for the first time is determined through a machine learning algorithm. In an embodiment, the prediction time point at which the disposal factor of the target metropolitan area network device is “1” can be determined.

[0042] Further, the prediction time point and the current time point can be subjected to a difference operation to obtain a time difference between the prediction time point and the current time point.

[0043] Further, the time difference and a preset time threshold value set according to actual needs can be compared to determine the size relationship between the time difference and the preset time threshold value. In an embodiment, the preset time threshold value may, for example, be 10 minutes, 15 minutes, 20 minutes, etc.

[0044] Further, if it is determined that the time difference is less than the preset time threshold value, it can be determined that attack disposal is needed, and therefore, attack disposal can be performed on the attacked Internet Protocol address corresponding to the distributed denial of service attack.

[0045] Specifically, when attack disposal is performed on the attacked Internet Protocol address corresponding to the distributed denial of service attack, the processing logic is determined according to the type of the attacked Internet Protocol address.

[0046] The attack handling method provided by the embodiments of the present application can determine the target MAN device subjected to the distributed denial of service attack when it is determined that the distributed denial of service attack exists in the MAN to be processed, and then can accurately determine the handling factor of the target MAN device based on the performance index of the target MAN device. Thus, when the value of the handling factor is the first target value indicating that the attack handling is not needed, the prediction time point at which the value of the handling factor is converted to the second target value indicating that the attack handling is needed can be further determined, so that when the time difference between the prediction time point and the current time point is less than the preset time threshold, the attack handling can be accurately performed based on the attacked Internet Protocol address corresponding to the distributed denial of service attack. Since the handling factor is determined according to the performance index of the target MAN device subjected to the distributed denial of service attack, the protection capability against the distributed denial of service attack is enhanced. In addition, after the value of the handling factor is the first target value indicating that the attack handling is not needed, when the time difference between the prediction time point at which the value of the handling factor is converted to the second target value indicating that the attack handling is needed and the current time point is less than the preset time threshold, the attack handling is performed, so that the frequent attack handling of the distributed denial of service attack when the MAN device and the services hung thereunder are not affected is avoided, and the risk faced by the MAN device is reduced. Moreover, the attack handling is performed according to the attacked Internet Protocol address corresponding to the distributed denial of service attack, so that the stable operation of the device to which the attacked Internet Protocol address belongs and the normal use of other services hung thereunder are ensured, and the stability of the MAN device and the services hung thereunder is improved, thereby the protection capability against the network attack can be improved.

[0047] In one embodiment, the handling factor of the target MAN device is determined based on the performance index of the target MAN device, including: if any one of the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance index of the target MAN device is greater than a preset utilization rate threshold, the value of the handling factor of the target MAN device is determined as the second target value; and if the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance index of the target MAN device are all less than or equal to the preset utilization rate threshold, the value of the handling factor of the target MAN device is determined as the first target value.

[0048] In the application, when the performance index of the target metropolitan area network device is determined, the utilization rate of the uplink port, the utilization rate of the central processing unit and the utilization rate of the memory of the performance index of the target metropolitan area network device are compared with the utilization rate threshold set in advance according to the actual demand, so as to determine the size relationship between the utilization rate of the uplink port, the utilization rate of the central processing unit and the utilization rate of the memory and the preset utilization rate threshold. In the application, the preset utilization rate threshold can be 85%, 90%, 95% and the like.

[0049] It should be noted that the utilization rate of the uplink port, the utilization rate of the central processing unit and the utilization rate of the memory can be compared with the same preset utilization rate threshold, or the utilization rate of the uplink port, the utilization rate of the central processing unit and the utilization rate of the memory can be compared with different preset utilization rate thresholds set according to the actual demand.

[0050] Further, if it is determined through comparison that any one of the utilization rate of the uplink port, the utilization rate of the central processing unit and the utilization rate of the memory of the performance index of the target metropolitan area network device is greater than the preset utilization rate threshold, it can be determined that the value of the disposal factor of the target metropolitan area network device is the second target value.

[0051] If the utilization rate of the uplink port, the utilization rate of the central processing unit and the utilization rate of the memory of the performance index of the target metropolitan area network device are all less than or equal to the preset utilization rate threshold, it can be determined that the value of the disposal factor of the target metropolitan area network device is the first target value.

[0052] For example, in the application, the disposal factor can be defined as β=(x or y or z), wherein x is the utilization rate of the uplink port, y is the CPU utilization rate, and z is the memory utilization rate, wherein the values of β, x, y and z are all 0 or 1. When the utilization rate of the uplink port is >=90%, x=1, and when the utilization rate of the uplink port is <90%, x=0; when the CPU utilization rate is >=90%, y=1, and when the CPU utilization rate is <90%, y=0; when the memory utilization rate is >=90%, z=1, and when the memory utilization rate is <90%, z=0. When any one of x, y and z is 1, β=1.

[0053] In the application, the disposal factor of the metropolitan area network device is determined according to the utilization rate of the uplink port, the utilization rate of the central processing unit and the utilization rate of the memory and the like, which avoids the disposal deficiency of DDoS attack caused by a single index, and can enhance the protection ability of DDoS attack, thereby improving the protection ability of network attack.

[0054] In one embodiment, the determining of the predicted time point at which the value of the treatment factor is earliest converted to the second target value comprises: obtaining first time sequence information of historical uplink port utilization rate, second time sequence information of historical central processing unit utilization rate and third time sequence information of historical memory utilization rate of the target metropolitan area network device; determining first time sequence prediction information of future uplink port utilization rate, second time sequence prediction information of future central processing unit utilization rate and third time sequence prediction information of future memory utilization rate based on the first time sequence information, the second time sequence information and the third time sequence information; and determining the predicted time point at which the value of the treatment factor is earliest converted to the second target value based on the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information.

[0055] Further, the determining of the first time sequence prediction information of future uplink port utilization rate, the second time sequence prediction information of future central processing unit utilization rate and the third time sequence prediction information of future memory utilization rate based on the first time sequence information, the second time sequence information and the third time sequence information comprises: inputting the first time sequence information into a first time sequence prediction model to obtain the first time sequence prediction information of future uplink port utilization rate output by the first time sequence prediction model; the first time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample uplink port utilization rate; inputting the second time sequence information into a second time sequence prediction model to obtain the second time sequence prediction information of future central processing unit utilization rate output by the second time sequence prediction model; the second time sequence prediction model is obtained by training the preset time sequence prediction model based on time sequence information of sample central processing unit utilization rate; and inputting the third time sequence information into a third time sequence prediction model to obtain the third time sequence prediction information of future memory utilization rate output by the third time sequence prediction model; the third time sequence prediction model is obtained by training the preset time sequence prediction model based on time sequence information of sample memory utilization rate.

[0056] Further, the determining of the predicted time point at which the value of the treatment factor is earliest converted to the second target value based on the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information comprises: determining a first time point of uplink port utilization rate earliest greater than a preset utilization rate threshold in the first time sequence prediction information; determining a second time point of central processing unit utilization rate earliest greater than the preset utilization rate threshold in the second time sequence prediction information; determining a third time point of memory utilization rate earliest greater than the preset utilization rate threshold in the third time sequence prediction information; and determining the time point earliest in time among the first time point, the second time point and the third time point as the predicted time point at which the value of the treatment factor is earliest converted to the second target value.

[0057] The application can obtain first time sequence information of historical uplink port utilization, second time sequence information of historical central processor utilization and third time sequence information of historical memory utilization when determining the predicted time point at which the value of the treatment factor is earliest converted into the second target value. The first time sequence information can include time information and corresponding data information of the historical uplink port utilization, the second time sequence information can include time information and corresponding data information of the historical central processor utilization, and the third time sequence information can include time information and corresponding data information of the historical memory utilization.

[0058] Further, the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information of the future uplink port utilization, the future central processor utilization and the future memory utilization can be respectively determined based on the first time sequence information, the second time sequence information and the third time sequence information in combination with a machine learning algorithm. The first time sequence prediction information can include time information and corresponding data information of the future uplink port utilization, the second time sequence prediction information can include time information and corresponding data information of the future central processor utilization, and the third time sequence prediction information can include time information and corresponding data information of the future memory utilization.

[0059] Further, the predicted time point at which the value of the treatment factor is earliest converted into the second target value can be determined from the time information of the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information according to the comparison of the time information and the corresponding data information in the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information.

[0060] It should be noted that the application can obtain a time sequence prediction model preset according to actual needs, and the preset time sequence prediction model can be, for example, an autoregressive model, a moving average model, a seasonal model, a neural network model, a deep learning model, etc., which is not specifically limited in the application.

[0061] Further, the application can obtain sample data of a sample metropolitan area network device, and the sample data can include time sequence information of sample uplink port utilization, time sequence information of sample central processor utilization and time sequence information of sample memory utilization, etc.

[0062] Therefore, the application can train the preset time sequence prediction model based on the time sequence information of the sample uplink port utilization, and obtain a first time sequence prediction model after completing the training. The first time sequence prediction model can predict the time sequence information of the uplink port utilization in a corresponding future time period according to the input time sequence information of the uplink port utilization in a historical time period.

[0063] and the preset time series prediction model can be trained based on the time series information of the sample memory utilization rate, and after the training is completed, a third time series prediction model is obtained, and the third time series prediction model can predict the time series information of the memory utilization rate of the corresponding future period according to the input time series information of the memory utilization rate of the historical period.

[0064] and the preset time series prediction model can be trained based on the time series information of the sample memory utilization rate, and after the training is completed, a third time series prediction model is obtained, and the third time series prediction model can predict the time series information of the memory utilization rate of the corresponding future period according to the input time series information of the memory utilization rate of the historical period.

[0065] It should be noted that when training the first time series prediction model, the second time series prediction model and the third time series prediction model, in addition to the time series information of the corresponding utilization rate, the historical data of the corresponding utilization rate can also be added to learn the mode and trend of the time series.

[0066] Therefore, when determining the first time series prediction information of the future uplink port utilization rate, the second time series prediction information of the future central processor utilization rate and the third time series prediction information of the future memory utilization rate based on the first time series information, the second time series information and the third time series information, the first time series information can be input to the first time series prediction model to obtain the first time series prediction information of the future uplink port utilization rate output by the first time series prediction model.

[0067] The second time series information is input to the second time series prediction model to obtain the second time series prediction information of the future central processor utilization rate output by the second time series prediction model.

[0068] The third time series information is input to the third time series prediction model to obtain the third time series prediction information of the future memory utilization rate output by the third time series prediction model.

[0069] Further, when determining the predicted time point at which the value of the handling factor is converted to the second target value earliest based on the first time series prediction information, the second time series prediction information and the third time series prediction information, the first time point of the uplink port utilization rate in the first time series prediction information which is earliest greater than the preset utilization rate threshold can be determined.

[0070] and the second time point of the central processor utilization rate in the second time series prediction information which is earliest greater than the preset utilization rate threshold is determined.

[0071] and the third time point of the memory utilization rate in the third time series prediction information which is earliest greater than the preset utilization rate threshold is determined.

[0072] Further, the first time point, the second time point and the third time point are compared to determine the sequence of the first time point, the second time point and the third time point.

[0073] Further, after the comparison is completed, the time point with the earliest time among the first time point, the second time point and the third time point can be determined as the predicted time point of the earliest conversion of the value of the treatment factor to the second target value.

[0074] The application introduces a machine learning algorithm to predict the time point of the treatment factor 1, avoids frequent DDoS treatment when the metropolitan area network device and the business under it are not affected, reduces the risk faced by the metropolitan area network device, and thus can improve the protection capability of network attacks.

[0075] In one embodiment, the attack treatment based on the attacked Internet Protocol address corresponding to the distributed denial of service attack includes: if the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a network device address, generating a black hole routing configuration based on the attacked Internet Protocol address and issuing the black hole routing configuration to a black hole router; the black hole router issuing a border gateway protocol black hole route in the black hole routing configuration to all network devices in the metropolitan area network to be processed; if the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a business address, generating a rate limiting strategy configuration based on the attacked Internet Protocol address and issuing the rate limiting strategy configuration to the black hole router; the black hole router issuing a border gateway protocol flow specification rate limiting routing strategy in the rate limiting strategy configuration to all network devices in the metropolitan area network to be processed.

[0076] When the attack treatment based on the attacked Internet Protocol address corresponding to the distributed denial of service attack is performed, if it is determined that the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a network device address, a black hole routing configuration can be generated according to the attacked Internet Protocol address, and the black hole routing configuration is further issued to a black hole router.

[0077] The black hole router can issue a BGP black hole route in the black hole routing configuration to all network devices in the metropolitan area network to be processed through a BGP neighbor, and end the treatment.

[0078] It should be noted that the black hole routing configuration is used to instruct the network device how to process the traffic from the attacked target: that is, not to forward it to the normal target host, but to guide it to a non-existent "black hole" address (usually a specific / 32 address), so that the attack traffic cannot reach the target, and the "black hole" is realized. The BGP black hole route actually indicates the routing entry of the IP address of the attack target to the black hole address.

[0079] If it is determined that the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a service address, a rate limiting policy configuration can be generated according to the attacked Internet Protocol address and the rate limiting policy configuration is configured. In one embodiment, the application can also obtain the guaranteed bandwidth corresponding to the service of the attacked Internet Protocol address. Therefore, the rate limiting policy configuration can be generated according to the attacked Internet Protocol address and the guaranteed bandwidth. The guaranteed bandwidth generally refers to the minimum bandwidth guarantee agreed in the network service protocol, which is used to ensure the normal operation of the service.

[0080] Generating the rate limiting policy configuration according to the attacked Internet Protocol address and the guaranteed bandwidth can specifically be setting a traffic rate limiting rule to ensure that the attacked service can still maintain basic network service quality when it is subjected to a large flow attack.

[0081] More specifically, the rate limiting policy can be implemented based on the following aspects:

[0082] Traffic identification: determine which traffic belongs to the service.

[0083] Rate limiting parameters: set the rate limit of each traffic category, such as bandwidth limit or packet rate limit.

[0084] Dynamic adjustment: dynamically adjust the rate limiting policy according to the actual network load and attack situation to adapt to changing network conditions and attack types.

[0085] Further, the generated rate limiting policy configuration can be distributed to the black hole router.

[0086] The black hole router distributes the border gateway protocol flow specification rate limiting routing policy in the rate limiting policy configuration to all network devices in the metropolitan area network to be processed through the border gateway protocol flow specification (BGP Flow Specification, BGP Flowspc) neighbor, and ends the processing.

[0087] The application handles the DDoS attack based on the attacked IP address, ensures the stable operation of the device to which the attacked IP address belongs and the normal use of other services under the device, improves the stability of the metropolitan area network device and the services under the device, and thus the network attack protection capability can be improved.

[0088] In one embodiment, after determining the processing factor of the target metropolitan area network device, it further includes: if the value of the processing factor is a first target value, processing the attack based on the attacked Internet Protocol address corresponding to the distributed denial of service attack.

[0089] After determining the treatment factor of the target metropolitan area network device, if the value of the treatment factor is a first target value, the attacked Internet Protocol address corresponding to the distributed denial of service attack can be directly attacked and treated based on the distributed denial of service attack.

[0090] Specifically, if the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a network device address, a black hole routing configuration can be generated according to the attacked Internet Protocol address, and the black hole routing configuration is further issued to a black hole router.

[0091] The black hole router can issue the BGP black hole route in the black hole routing configuration to all network devices in the metropolitan area network to be processed through a border gateway protocol neighbor, and end the treatment.

[0092] If the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a service address, a rate limiting policy configuration can be generated according to the attacked Internet Protocol address and the rate limiting policy configuration is issued. In an embodiment, the application can also obtain the guaranteed bandwidth corresponding to the service of the attacked Internet Protocol address. Therefore, the rate limiting policy configuration can be generated according to the attacked Internet Protocol address and the guaranteed bandwidth. The guaranteed bandwidth generally refers to the minimum bandwidth guarantee agreed in the network service protocol, which is used to ensure the normal operation of the service.

[0093] Generating the rate limiting policy configuration according to the attacked Internet Protocol address and the guaranteed bandwidth can specifically be setting a traffic rate limiting rule to ensure that the attacked service can still maintain basic network service quality when suffering from a large flow attack.

[0094] Further, the generated rate limiting policy configuration can be issued to the black hole router.

[0095] The black hole router issues the border gateway protocol flow specification rate limiting route policy in the rate limiting policy configuration to all network devices in the metropolitan area network to be processed through a border gateway protocol flow specification neighbor, and ends the treatment.

[0096] The application treats the DDoS attack based on the attacked IP address, ensures the stable operation of the device to which the attacked IP address belongs and the normal use of other services under the device, improves the stability of the metropolitan area network device and the services under the device, and thus improves the protection capability of network attacks.

[0097] Figure 2 is the overall flow diagram of the attack treatment method provided by the application, Figure 3 is a structure diagram of the DDoS attack automatic treatment system of the application, such as Figure 2 and Figure 3As shown, in one embodiment, the DDoS attack automatic handling system of the present application can include a DDoS monitoring module, a device monitoring module, an address management module, a prediction module, an attack handling module and a black hole router, and the attack handling method can include the following steps:

[0098] Step one: the DDoS monitoring module monitors the occurrence of DDoS attack in the metropolitan area network, identifies the attacked destination IP address, and transmits the attacked IP address to the device monitoring module.

[0099] Step two: the device monitoring module determines the metropolitan area network device to which the attacked IP address belongs through a routing query method.

[0100] Step three: the device monitoring module respectively obtains the utilization rate indices x, y and z of the corresponding utilization rates of the network device uplink port, CPU utilization rate and memory utilization rate, and then judges the value of the handling factor β of the metropolitan area network device. If β is "0", the attacked IP address, the current network device uplink port utilization rate, CPU utilization rate and memory utilization rate are transmitted to the prediction module, and step four is continued; if β is "1", the attacked destination IP address is transmitted to the address management module, and step six is jumped to.

[0101] Step four: the prediction module uses a machine learning algorithm to predict the prediction time point of the handling factor β being "1" of the network device, and transmits the prediction time point to the attack handling module.

[0102] Step five: the attack handling module judges the time difference value λ (unit: minute) between the current time point and the prediction time point of β being "1". If λ>10 minutes, no handling is performed; if λ<=10 minutes, step six is continued.

[0103] Step six: the address management module identifies the type of the attacked IP address. If it is a network device address, the attacked IP address is transmitted to the attack handling module, and step seven is continued; if it is not a network device address, step eight is jumped to.

[0104] Step seven: the attack handling module generates a black hole routing configuration according to the attacked IP address, and issues it to the black hole router. The black hole router issues BGP black hole routing to all network devices in the network through BGP neighbors, and ends the handling.

[0105] Step eight: the address management module identifies the type of the attacked IP address. If it is a service address, the attacked IP address, the guaranteed bandwidth corresponding to the service, etc. are transmitted to the attack handling module, and step nine is continued; if it is not a service address, no handling is performed.

[0106] Step nine: the attack handling module generates a rate limiting policy configuration according to the attacked IP address and the service guarantee bandwidth, and delivers the configuration to the black hole router; the black hole router delivers a BGP flowspc rate limiting routing policy to all network devices in the network through a BGP Flowspc neighbor, and ends the handling.

[0107] The application can discover DDoS attacks in a metropolitan area network in a short time and handle them in time through automatic handling combined with machine learning, effectively avoids network congestion and service interruption, and guarantees the normal operation of the metropolitan area network.

[0108] The traditional DDoS attack defense method often needs a large amount of manual participation and monitoring, and the application reduces the need for manual intervention and reduces the operating cost through automatic handling. The network resource utilization rate can be improved through intelligent optimization based on historical data and real-time traffic, and the cost can be further saved. At the same time, the DDoS automatic handling system can be constructed by fully utilizing the existing function modules of the network, thereby saving investment.

[0109] By providing more efficient and intelligent network security protection services for customers, improving user experience in the DDoS attack scenario, and increasing user stickiness, more customers can be attracted and customer satisfaction can be improved.

[0110] The attack handling device provided by the application is described below, and the attack handling device described below can be correspondingly referred to the attack handling method described above.

[0111] Further, the application also provides an attack handling device.

[0112] The attack handling device can also include: a first determination module configured to determine that a distributed denial of service attack exists in a metropolitan area network to be processed, and determine a target metropolitan area network device of the distributed denial of service attack; a second determination module configured to determine a handling factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; a third determination module configured to determine a predicted time point at which a value of the handling factor is converted to a second target value earliest if the value of the handling factor is a first target value; the first target value indicates that attack handling is not needed; and the second target value indicates that attack handling is needed; and a handling module configured to perform attack handling based on an attacked Internet Protocol address corresponding to the distributed denial of service attack if a time difference between the predicted time point and a current time point is less than a preset time threshold.

[0113] In an embodiment, the second determining module is specifically configured to: if any one of the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance indicators of the target metropolitan area network device is greater than a preset utilization rate threshold, determine that the value of the handling factor of the target metropolitan area network device is a second target value; if all of the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance indicators of the target metropolitan area network device are less than or equal to the preset utilization rate threshold, determine that the value of the handling factor of the target metropolitan area network device is a first target value.

[0114] In an embodiment, the second determining module is further configured to: if the value of the handling factor is the first target value, perform attack handling on the attacked Internet Protocol address corresponding to the distributed denial of service attack.

[0115] In an embodiment, the third determining module is specifically configured to: acquire first time sequence information of historical uplink port utilization rate, second time sequence information of historical central processing unit utilization rate and third time sequence information of historical memory utilization rate of the target metropolitan area network device; based on the first time sequence information, the second time sequence information and the third time sequence information, respectively determine first time sequence prediction information of future uplink port utilization rate, second time sequence prediction information of future central processing unit utilization rate and third time sequence prediction information of future memory utilization rate; and based on the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information, determine a predicted time point at which the value of the handling factor is earliest converted to the second target value.

[0116] In an embodiment, the third determining module further includes a first determining unit, which is configured to: input the first time sequence information into a first time sequence prediction model to obtain first time sequence prediction information of future uplink port utilization rate output by the first time sequence prediction model; the first time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample uplink port utilization rate; input the second time sequence information into a second time sequence prediction model to obtain second time sequence prediction information of future central processing unit utilization rate output by the second time sequence prediction model; the second time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample central processing unit utilization rate; and input the third time sequence information into a third time sequence prediction model to obtain third time sequence prediction information of future memory utilization rate output by the third time sequence prediction model; the third time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample memory utilization rate.

[0117] In one embodiment, the third determining module further comprises a second determining unit, configured to: determine a first time point of an earliest uplink port utilization rate greater than a preset utilization rate threshold in the first time sequence prediction information; determine a second time point of an earliest central processing unit utilization rate greater than the preset utilization rate threshold in the second time sequence prediction information; determine a third time point of an earliest memory utilization rate greater than the preset utilization rate threshold in the third time sequence prediction information; and determine a time point with the earliest time among the first time point, the second time point and the third time point as a predicted time point at which the value of the treatment factor is earliest converted to the second target value.

[0118] In one embodiment, the treatment module is specifically configured to: if the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a network device address, generate a black hole routing configuration based on the attacked Internet Protocol address and issue the black hole routing configuration to a black hole router; the black hole router issues a border gateway protocol black hole route in the black hole routing configuration to all network devices in the to-be-processed metropolitan area network; if the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a service address, generate a rate limiting strategy configuration based on the attacked Internet Protocol address and issue the rate limiting strategy configuration to a black hole router; the black hole router issues a border gateway protocol flow specification rate limiting routing strategy in the rate limiting strategy configuration to all network devices in the to-be-processed metropolitan area network.

[0119] The attack treatment device provided by the embodiments of the present application can determine the target MAN equipment subjected to the distributed denial of service attack when it is determined that the distributed denial of service attack exists in the MAN to be processed, and then can accurately determine the treatment factor of the target MAN equipment based on the performance index of the target MAN equipment. Thus, when the value of the treatment factor is the first target value indicating that the attack treatment is not needed, the prediction time point at which the value of the treatment factor is converted into the second target value indicating that the attack treatment is needed can be further determined, so that when the time difference between the prediction time point and the current time point is less than the preset time threshold, the attack treatment can be accurately performed based on the attacked IP address corresponding to the distributed denial of service attack. Since the treatment factor is determined according to the performance index of the target MAN equipment subjected to the distributed denial of service attack, the protection capability against the distributed denial of service attack is enhanced. In addition, after the value of the treatment factor is the first target value indicating that the attack treatment is not needed, when the time difference between the prediction time point at which the value of the treatment factor is converted into the second target value indicating that the attack treatment is needed and the current time point is less than the preset time threshold, the attack treatment is performed, so that the frequent attack treatment of the distributed denial of service attack when the MAN equipment and the services hung thereunder are not affected is avoided, and the risk faced by the MAN equipment is reduced. Furthermore, the attack treatment is performed according to the attacked IP address corresponding to the distributed denial of service attack, so that the stable operation of the equipment to which the attacked IP address belongs and the normal use of other services hung thereunder are ensured, and the stability of the MAN equipment and the services hung thereunder is improved, so that the protection capability against the network attack can be improved.

[0120] Figure 4 An example of a schematic diagram of the physical structure of an electronic device is shown in FIG. 1. Figure 4As shown, the electronic device can include a processor 410, a communications interface 420, a memory 430, and a communications bus 440, wherein the processor 410, the communications interface 420, and the memory 430 complete mutual communication through the communications bus 440. The processor 410 can invoke a logical instruction in the memory 430 to execute an attack handling method, which includes: determining that a distributed denial of service attack exists in a to-be-handled metropolitan area network, then determining a target metropolitan area network device that occurs the distributed denial of service attack; determining a handling factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; if a value of the handling factor is a first target value, determining a predicted time point at which the value of the handling factor is earliest converted to a second target value; the first target value indicates that attack handling is not needed; the second target value indicates that attack handling is needed; and if a time difference between the predicted time point and a current time point is less than a preset time threshold, performing attack handling based on an attacked Internet Protocol address corresponding to the distributed denial of service attack.

[0121] In addition, the logical instruction in the memory 430 described above can be implemented in the form of a software functional unit and sold or used as an independent product, and can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the present application essentially or say the part that contributes to the prior art or part of the technical solutions can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the method described in various embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various program code storage media.

[0122] In another aspect, the present application also provides a computer program product, which comprises a computer program, the computer program being stored in a non-transitory computer readable storage medium, and the computer program being executable by a processor to cause a computer to execute the attack handling method provided by any of the above methods, the method comprising: determining that a distributed denial of service attack exists in a metropolitan area network to be processed, and then determining a target metropolitan area network device that generates the distributed denial of service attack; determining a handling factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; if a value of the handling factor is a first target value, determining a predicted time point at which the value of the handling factor is earliest converted to a second target value; the first target value indicating that attack handling is not needed; and the second target value indicating that attack handling is needed; and if a time difference between the predicted time point and a current time point is less than a preset time threshold, performing attack handling based on an attacked Internet Protocol address corresponding to the distributed denial of service attack.

[0123] In another aspect, the present application also provides a non-transitory computer readable storage medium, which stores a computer program, and the computer program is executable by a processor to implement the attack handling method provided by any of the above methods, the method comprising: determining that a distributed denial of service attack exists in a metropolitan area network to be processed, and then determining a target metropolitan area network device that generates the distributed denial of service attack; determining a handling factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; if a value of the handling factor is a first target value, determining a predicted time point at which the value of the handling factor is earliest converted to a second target value; the first target value indicating that attack handling is not needed; and the second target value indicating that attack handling is needed; and if a time difference between the predicted time point and a current time point is less than a preset time threshold, performing attack handling based on an attacked Internet Protocol address corresponding to the distributed denial of service attack.

[0124] The device embodiments described above are only schematic, wherein the units shown as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place or distributed on a plurality of network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment. Those skilled in the art can understand and implement without creative labor.

[0125] Those skilled in the art can clearly understand the implementation of the various embodiments by means of software and the necessary general hardware platform from the above description of the embodiments, and of course, the embodiments can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that contributes to the technical solutions can be embodied in the form of a software product. The computer software product can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the methods.

[0126] Finally, it should be noted that: the above examples are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing examples, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing examples, or make equivalent replacement for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. An attack handling method, characterized by, The method comprises: determining that a distributed denial of service attack exists in a metropolitan area network to be processed, determining a target metropolitan area network device of the distributed denial of service attack; determining a disposal factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; if a value of the disposal factor is a first target value, determining a prediction time point at which the value of the disposal factor is earliest converted to a second target value; the first target value indicates that attack disposal is not needed; and the second target value indicates that attack disposal is needed; if a time difference between the prediction time point and a current time point is less than a preset time threshold, performing attack disposal on an attacked internet protocol address corresponding to the distributed denial of service attack; the performance index comprises an uplink port utilization rate, a central processing unit utilization rate and a memory utilization rate; and the disposal factor of the target metropolitan area network device is determined based on the performance index of the target metropolitan area network device, comprising: if any one of the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance index of the target metropolitan area network device is greater than a preset utilization rate threshold, determining that the value of the disposal factor of the target metropolitan area network device is the second target value; if the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance index of the target metropolitan area network device are all less than or equal to the preset utilization rate threshold, determining that the value of the disposal factor of the target metropolitan area network device is the first target value.

2. The attack handling method of claim 1, wherein, The prediction time point at which the value of the disposal factor is earliest converted to the second target value comprises: obtaining first time sequence information of historical uplink port utilization rate, second time sequence information of historical central processing unit utilization rate and third time sequence information of historical memory utilization rate of the target metropolitan area network device; determining first time sequence prediction information of future uplink port utilization rate, second time sequence prediction information of future central processing unit utilization rate and third time sequence prediction information of future memory utilization rate based on the first time sequence information, the second time sequence information and the third time sequence information; determining the prediction time point at which the value of the disposal factor is earliest converted to the second target value based on the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information.

3. The attack handling method of claim 2, wherein, The prediction time point at which the value of the disposal factor is earliest converted to the second target value based on the first time sequence prediction information, the second time sequence prediction information and the third time sequence prediction information comprises: determining a first time point of the uplink port utilization rate in the first time sequence prediction information which is earliest greater than the preset utilization rate threshold; determining a second time point of the central processing unit utilization rate in the second time sequence prediction information which is earliest greater than the preset utilization rate threshold; determining a third time point of the memory utilization rate in the third time sequence prediction information which is earliest greater than the preset utilization rate threshold; determining the time point which is earliest in the first time point, the second time point and the third time point as the prediction time point at which the value of the disposal factor is earliest converted to the second target value.

4. The attack handling method of claim 2, wherein, The first time sequence information, the second time sequence information and the third time sequence information are used to determine first time sequence prediction information of future uplink port utilization, second time sequence prediction information of future central processor utilization and third time sequence prediction information of future memory utilization, respectively. The first time sequence information is input into a first time sequence prediction model to obtain first time sequence prediction information of future uplink port utilization output by the first time sequence prediction model; the first time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample uplink port utilization; The second time sequence information is input into a second time sequence prediction model to obtain second time sequence prediction information of future central processor utilization output by the second time sequence prediction model; the second time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample central processor utilization; The third time sequence information is input into a third time sequence prediction model to obtain third time sequence prediction information of future memory utilization output by the third time sequence prediction model; the third time sequence prediction model is obtained by training a preset time sequence prediction model based on time sequence information of sample memory utilization.

5. The attack handling method of claim 1, wherein, The attacked Internet Protocol address corresponding to the distributed denial of service attack is used to perform attack disposal, including: If the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a network device address, a black hole routing configuration is generated based on the attacked Internet Protocol address and the black hole routing configuration is issued to a black hole router; the black hole router issues a border gateway protocol black hole routing in the black hole routing configuration to all network devices in the to-be-processed metropolitan area network; If the type of the attacked Internet Protocol address corresponding to the distributed denial of service attack is a service address, a rate limiting strategy configuration is generated based on the attacked Internet Protocol address and the rate limiting strategy configuration is issued to a black hole router; the black hole router issues a border gateway protocol flow specification rate limiting routing strategy in the rate limiting strategy configuration to all network devices in the to-be-processed metropolitan area network.

6. The attack handling method of any of claims 1-5, wherein, After the disposal factor of the target metropolitan area network device is determined, further including: If the value of the disposal factor is a first target value, the attacked Internet Protocol address corresponding to the distributed denial of service attack is used to perform attack disposal.

7. An attack handling apparatus, characterized by, Including: A first determination module is configured to determine that a distributed denial of service attack exists in a to-be-processed metropolitan area network, and then determine a target metropolitan area network device where the distributed denial of service attack occurs; A second determination module is configured to determine a disposal factor of the target metropolitan area network device based on a performance index of the target metropolitan area network device; A third determination module is configured to determine a predicted time point at which the value of the disposal factor is converted into a second target value earliest if the value of the disposal factor is a first target value; the first target value indicates that attack disposal is not needed; and the second target value indicates that attack disposal is needed. The processing module is configured to perform attack disposal on the target Internet Protocol address corresponding to the distributed denial of service attack based on the attack type. The second determining module is specifically configured to determine the value of the disposal factor of the target metropolitan area network device as a second target value if any of the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance indicators of the target metropolitan area network device is greater than a preset utilization rate threshold; and determine the value of the disposal factor of the target metropolitan area network device as a first target value if all of the uplink port utilization rate, the central processing unit utilization rate and the memory utilization rate of the performance indicators of the target metropolitan area network device are less than or equal to the preset utilization rate threshold.

8. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the program to implement the attack disposal method according to any one of claims 1 to 6.

9. A medium, which is a non-transitory computer-readable storage medium, having stored thereon a computer program, characterized by, The computer program is executed by the processor to implement the attack disposal method according to any one of claims 1 to 6.

10. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the attack disposal method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Method and system for defending distributed denial of service (DDoS) attack

    CN105610851A

  • Network attack alarm threshold value configuration method and device, medium and computing device

    CN109194661A