DDoS attack detection method, device, equipment, storage medium and program product

By combining autoencoder networks and Siamese networks, an abnormal traffic data set is identified and its similarity is calculated. This solves the problems of accuracy and false alarm rate in existing DDoS attack detection technologies, and enables efficient detection and timely response to DDoS attacks.

CN118972150BActive Publication Date: 2025-11-21CHINA MOBILE GROUP ZHEJIANG +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411247596.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2025-11-21
Estimated Expiration
2044-09-06

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately detect DDoS attacks, resulting in a high false alarm rate and an inability to promptly identify network attacks, thus impacting network and system security and stability.

Method used

A two-step detection approach is adopted. First, the traffic data groups are encoded and reconstructed through an autoencoder network to identify abnormal data groups. Then, a twin network is used to calculate the similarity between traffic data to determine whether a DDoS attack exists.

Benefits of technology

It improves the accuracy of DDoS attack detection, reduces the false alarm rate, and can detect potential network attacks in real time and accurately, protecting the security and stability of networks and systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118972150B_ABST
    Figure CN118972150B_ABST
Patent Text Reader

Abstract

The application discloses a DDoS attack detection method, device, equipment, storage medium and program product. The DDoS attack detection method comprises the following steps: encoding and reconstructing a plurality of first traffic data groups in a first time period before a current time point by a first detection model to obtain a reconstructed traffic data group of each first traffic data group, each first traffic data group comprising a plurality of first traffic data, each first traffic data corresponding to a time unit, and the source address and the destination address of the first traffic data belonging to the same first traffic data group being the same; determining an abnormal target first traffic data group from the plurality of first traffic data groups based on each first traffic data group and the reconstructed traffic data group thereof; determining the similarity between two first traffic data in the target first traffic data group based on a second detection model; and determining whether DDoS attack exists in each first traffic data in the target first traffic data group based on the similarity between the two first traffic data.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a DDoS attack detection method and device, equipment, a storage medium and a program product. BACKGROUND

[0002] DDoS (Distributed Denial of Service, distributed denial of service) attack is a network attack form that prevents users from normally accessing target services by consuming target resources, and is the main threat in current network attacks. DDoS attack mainly uses multiple computers to illegally occupy Internet resources, resulting in that users cannot get network response, which causes great threat to the Internet and Internet services.

[0003] With the continuous development of network technology, network security problems have become a prominent problem in the whole human society. How to accurately detect DDoS attacks has become a hot research direction. SUMMARY

[0004] The purpose of the embodiments of the present application is to provide a DDoS attack detection method, device, equipment, storage medium and program product, which can detect DDoS attacks in real time and accurately, and reduce the false positive rate.

[0005] In order to achieve the above purpose, the embodiments of the present application adopt the following technical solutions:

[0006] In a first aspect, the embodiments of the present application provide a DDoS attack detection method, comprising:

[0007] encoding and reconstructing a plurality of first traffic data groups in a first time period before a current time point by using a first detection model to obtain a reconstructed traffic data group of each first traffic data group, each first traffic data group comprising a plurality of first traffic data, each first traffic data corresponding to a time unit, and the source address and the destination address of the first traffic data belonging to the same first traffic data group being the same;

[0008] determining an abnormal target first traffic data group from the plurality of first traffic data groups based on each first traffic data group and the reconstructed traffic data group of each first traffic data group;

[0009] determining the similarity between two first traffic data in the target first traffic data group based on a second detection model;

[0010] determining whether DDoS attack exists in each first traffic data in the target first traffic data group based on the similarity between the two first traffic data.

[0011] In a second aspect, the embodiments of the present application provide a DDoS attack detection device, comprising:

[0012] a reconstruction unit, configured to encode and reconstruct, by a first detection model, a plurality of first traffic data groups in a first time period before a current time point, to obtain a reconstructed traffic data group of each first traffic data group, each first traffic data group comprising a plurality of first traffic data, each first traffic data corresponding to a time unit, and the source address and the destination address of the first traffic data belonging to a same first traffic data group being the same;

[0013] a first detection unit, configured to determine, based on each first traffic data group and the reconstructed traffic data group of each first traffic data group, a target first traffic data group with anomaly from the plurality of first traffic data groups;

[0014] a comparison unit, configured to determine, based on a second detection model, a similarity between two first traffic data in the target first traffic data group;

[0015] a second detection unit, configured to determine, based on the similarity between the two first traffic data, whether each first traffic data in the target first traffic data group is subjected to a DDoS attack.

[0016] In a third aspect, an embodiment of the present application provides an electronic device, comprising:

[0017] a processor;

[0018] a memory for storing instructions executable by the processor;

[0019] The processor is configured to execute the instructions to implement the DDoS attack detection method according to the first aspect.

[0020] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, when instructions in the storage medium are executed by a processor of an electronic device, the electronic device can execute the DDoS attack detection method according to the first aspect.

[0021] In a fifth aspect, an embodiment of the present application provides a computer program product, the computer program product comprising a non-transitory computer-readable storage medium storing a computer program, the computer program being operable to cause a computer to perform some or all of the steps of the DDoS attack detection method according to the first aspect.

[0022] The above at least one technical solution adopted by the embodiments of the present application can achieve the following beneficial effects:

[0023] The two-step detection mode is adopted, the traffic data collected in the first period before the current time point is divided into a plurality of first traffic data groups according to source addresses and destination addresses, two-step anomaly detection is performed by using the plurality of first traffic data groups, a target first traffic data group with an anomaly is detected first, and first traffic data with a DDoS attack in the target first traffic data group is further detected, the time sequence period correlation between the traffic data can be fully utilized, the accuracy of DDoS attack detection is improved, the false positive rate is reduced, the DDoS attack can be accurately detected in real time, potential network attack behaviors can be discovered and responded to in time, and therefore the safety and stability of the network and the system can be effectively protected. On this basis, for detection of the target first traffic data group with an anomaly, it is considered that the abnormal traffic data group is difficult to be effectively reconstructed by using a machine learning model, which leads to a large difference between the abnormal traffic data group and the reconstructed traffic data group thereof, based on this, the first detection model is used to code and reconstruct each first traffic data group to obtain a corresponding reconstructed traffic data group, and then the difference between the first traffic data group and the reconstructed traffic data group thereof can be used to quickly and accurately determine whether the first traffic data group is abnormal. In addition, for detection of the traffic data with a DDoS attack in the target first traffic data group, it is considered that there is a large difference between the DDoS attack traffic data and the normal traffic data, if the similarity between a first traffic data in the target first traffic data group and most of the remaining first traffic data is low, it can be determined that the first traffic data has a DDoS attack. BRIEF DESCRIPTION OF DRAWINGS

[0024] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application, and do not limit the application in any way. In the drawings:

[0025] Figure 1 A schematic diagram of an implementation environment to which a DDoS attack detection method provided by an embodiment of the application is applicable;

[0026] Figure 2 A schematic diagram of a traffic data collection process provided by an embodiment of the application;

[0027] Figure 3 A flowchart of a DDoS attack detection method provided by an embodiment of the application;

[0028] Figure 4 A structural schematic diagram of a first detection model provided by an embodiment of the application;

[0029] Figure 5 A flowchart of a training method of a first detection model provided by an embodiment of the application

[0030] Figure 6 A structural diagram of a second detection model provided for an embodiment of the present application is shown in FIG. 1B.

[0031] Figure 7 A flow diagram of a training method of a second detection model provided for an embodiment of the present application is shown in FIG. 2B.

[0032] Figure 8 A flow diagram of a determination method of a similarity threshold provided for an embodiment of the present application is shown in FIG. 3B.

[0033] Figure 9 A structural diagram of a DDoS attack detection apparatus provided for an embodiment of the present application is shown in FIG. 4B.

[0034] Figure 10 A structural diagram of an electronic device provided for an embodiment of the present application is shown in FIG. 5B. DETAILED DESCRIPTION

[0035] In order to make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described below in detail with reference to the embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0036] The terms "first", "second", and the like in the specification and claims are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here. In addition, "and / or" in the specification and claims means at least one of the connected objects, and the character " / " generally means that the front and rear associated objects are in an "or" relationship.

[0037] It should be understood that the DDoS attack detection method provided by the embodiments of the present application can be executed by an electronic device. The so-called electronic device here can include terminal devices such as smart phones, tablet computers, notebook computers, desktop computers, smart voice interaction devices, smart home appliances, smart watches, vehicle-mounted terminals, aircraft, etc.; or the electronic device can also include servers such as independent physical servers, and can also be a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0038] The technical solutions provided by the embodiments of the present application will be described in detail below with reference to the drawings.

[0039] To facilitate the understanding of the technical solutions provided by the embodiments of the present application, first, the implementation environment to which the technical solutions provided by the embodiments of the present application are applicable is described. Figure 1 The implementation environment to which the technical solutions provided by the embodiments of the present application are applicable is described. It should be understood that the technical solutions provided by the embodiments of the present application are applicable to Figure 1 The implementation environment shown in the figure is only an exemplary description and should not be understood as a limitation on the implementation environment to which the technical solutions are applicable.

[0040] As Figure 1 shown, an implementation environment to which the technical solutions provided by the embodiments of the present application are applicable includes a plurality of virtual machines deployed in a cloud computing platform, and a detection system for detecting whether each virtual machine is subjected to a DDoS attack. The detection system includes a DDoS protection module, a data module, and an AI module.

[0041] The DDoS protection module has an anomaly detection function and an attack detection function. The anomaly detection function is used to pre-detect the access traffic data of each virtual machine to obtain abnormal traffic data suspected of existing a DDoS attack. The attack detection function is used to further detect the abnormal traffic data to obtain the DDoS attack traffic of each virtual machine.

[0042] The data module is the data basis for DDoS attack detection, and has a traffic data collection function and a traffic data storage function. The traffic data collection function is used to collect the access traffic data of each virtual machine, and the access traffic data carries a corresponding timestamp. The traffic data storage function is used to store the access traffic data collected by the traffic data collection function, and provides data support for the AI module and the DDoS protection module.

[0043] The AI (Artificial Intelligence) module has a data preprocessing function, a first detection model training function, and a second detection model training function. The data preprocessing function is used to preprocess the access traffic data collected by the data module, group and count the access traffic data according to the source address and the destination address, to obtain a plurality of traffic data groups. Each traffic data group includes a plurality of traffic data, and each traffic data corresponds to a time unit. The traffic data in the same traffic data group has the same source address and destination address. The first detection model training function is used to train a first detection model using a plurality of traffic data groups in a historical period. The first detection model is used to implement the anomaly pre-detection function of the DDoS protection module. The second detection model training function is used to train a second detection model using a plurality of traffic data groups in a historical period. The second detection model is used to implement the attack detection function of the DDoS protection module.

[0044] In one implementation manner, as Figure 2As shown, the data module adopts a centralized master-slave structure to collect access traffic data of each virtual machine. Exemplarily, the data module includes a plurality of agent plug-ins, and one agent plug-in responsible for collecting traffic data is deployed on each virtual machine, which collects traffic data of the virtual machine at a fixed frequency. The data module further includes a central detection server as a data receiving and summarizing end for receiving and storing the traffic data collected by each agent plug-in. The agent plug-in samples data sent by the virtual machine from the virtual switch, organizes traffic statistical data for the virtual machine, counts the number of data packets based on the destination address, and encapsulates the virtual machine information into a UDP (User Datagram Protocol) data packet to send to the central detection server for further processing. This way, the latest data of each virtual machine can be obtained in time, and the real-time performance is relatively high. In actual application, the collection frequency of the agent plug-in can be set according to actual needs, for example, 1 second, and the present embodiment does not limit this. The source address and the destination address can be IP (Internet Protocol Address) addresses.

[0045] The AI module starts the data preprocessing function, groups the UDP data packets according to the <source address, destination address> two-tuple, constructs a traffic sequence, and then constructs a sample traffic data group for anomaly detection based on the temporary list data of the stored traffic value sequence and the sliding window.

[0046] Exemplarily, according to the <source address, destination address> two-tuple, the UDP data packets with the same two-tuple are gathered together to obtain a plurality of groups of UDP data packets. For each two-tuple, a time interval t is selected to analyze the traffic of the UDP data packets, and the traffic in each time interval is counted to obtain the traffic sequence of the two-tuple. wherein, Ci represents the traffic of the Ci-th two-tuple in the first time interval, Ci represents the traffic of the Ci-th two-tuple in the second time interval, Ci represents the traffic of the Ci-th two-tuple in the n-th time interval. It can be seen that the traffic sequence of each two-tuple reflects the change of the traffic of the two-tuple over time. The time interval t can be set according to actual needs.

[0047] Based on the above method, the AI module can periodically obtain a traffic data group in a specified period before the current time point, denoted as: wherein, Ci represents the traffic of the Ci-th two-tuple in the first time interval, ia flow data group, each row of the flow data group is a flow data, corresponding to a time unit (such as a day), which contains the flow of m time windows (such as 60 minutes) within the time unit. Specifically, represents the flow of the first time window within the first time unit, represents the flow of the mth time window within the first time unit, represents the flow of the first time window within the nth time unit, represents the flow of the nth time window within the nth time unit. It should be noted that in actual applications, the elements in each flow data group can be normalized.

[0048] Further, the AI module can train the first detection model and the second detection model based on the flow data groups of the historical period respectively. In the anomaly detection process, the DDoS protection module can use the first detection model and the second detection model to detect whether each virtual machine is attacked by DDoS based on the real-time flow data group of each virtual machine.

[0049] It should be noted that in actual applications, the above detection system can be deployed in an electronic device, and each module in the above detection system can be implemented by a chip in the electronic device.

[0050] Please refer to Figure 3 , a flowchart of a DDoS attack detection method provided by an embodiment of the present application, the method comprising the following steps:

[0051] S302, encoding and reconstructing the plurality of first flow data groups within the first period before the current time point by the first detection model to obtain the reconstructed flow data group of each first flow data group.

[0052] Each first flow data group includes a plurality of first flow data, and each first flow data corresponds to a time unit. The source address and the destination address of the first flow data belonging to the same first flow data group are the same. Among them, the time unit refers to a paragraph or interval in time, which can be of any length, depending on the actual application or demand. As an example, the length of the time unit is a day, in which case each first flow data group includes the first flow data of each day within the first period, and each first flow data includes the flow of a plurality of time windows within the day. The time window refers to a smaller time unit than the time unit, such as a time window with a length of 60 minutes. Thus, the first flow data of each day can reflect the change of flow over time within the day.

[0053] The first detection model has the functions of encoding and reconstruction. The first detection model can have various appropriate structures, which are not limited by the embodiments of the present application. Exemplarily, as shown inFigure 4 As shown, the first detection model adopts a self-encoding network structure, which includes an encoder and a decoder. The encoder is used to encode high-dimensional input into low-dimensional hidden variables, forcing the neural network to learn the most informative features; the decoder restores the hidden variables to the original dimension, i.e., reconstructs the high-dimensional input. In the above S302, for each first traffic data group, the first traffic data group is input into the first detection model, the first traffic data group is encoded and converted into low-dimensional hidden variables by the encoder, and then the decoder reconstructs the hidden variables to obtain the reconstructed traffic data group of the first traffic data group.

[0054] In the embodiments of the present application, the first detection model can be obtained in various appropriate ways. In one implementation, an existing self-encoding network is used as the first detection model.

[0055] In another implementation, the first detection model is obtained by training based on a plurality of second traffic data groups in a second time period before the current time point. Each second traffic data group includes a plurality of second traffic data, each second traffic data corresponding to a time unit, and the source address and the destination address of the second traffic data belonging to the same second traffic data group are the same. The second time period is before the first time period and the length of the second time period is equal to the length of the first time period. For example, the first time period is 7 days before the current time point, and the second time period is 7 days before the first time period. The acquisition method of the plurality of second traffic data groups is similar to the acquisition method of the first traffic data group, which will not be described again.

[0056] Specifically, the inventive concept for training the first detection model is: by using a plurality of normal traffic data groups to train the model, the model can learn the time sequence period correlation between the traffic data in the traffic data group and can reconstruct the input of the model; then using the model to reconstruct the unknown traffic data group at the future time, and then according to the difference between the traffic data groups before and after the reconstruction, distinguishing the abnormal traffic data group and the normal traffic data group.

[0057] Based on the above inventive concept, as shown in the following embodiments: Figure 5 The first detection model is obtained by training in the following way:

[0058] Step A1, obtaining a plurality of normal second traffic data groups in a second time period before the current time point.

[0059] Step A2, encoding and reconstructing each second traffic data group by a self-encoding network to obtain a reconstructed traffic data group of each second traffic data group.

[0060] Exemplarily, the auto-encoding network comprises an encoder and a decoder. For each second traffic data group, the second traffic data group is input into the auto-encoding network, the second traffic data group is converted into a low-dimensional hidden variable by the encoder, and then the second traffic data group is reconstructed based on the hidden variable by the decoder to obtain a reconstructed traffic data group of the second traffic data group.

[0061] Step A3, based on the error between each second traffic data group and the reconstructed traffic data group of each second traffic data group, the parameters of the auto-encoding network are adjusted to obtain the first detection model.

[0062] Exemplarily, for each second traffic data group, the mean square error between the second traffic data group and the reconstructed traffic data group thereof is calculated as the error therebetween, i.e., as shown in the following formula (1); then, the errors between all second traffic data groups and the reconstructed traffic data groups thereof are summed to obtain the loss of the auto-encoding network; further, the parameters of the auto-encoding network are continuously adjusted by minimizing the loss.

[0063]

[0064] wherein, Loss1 represents the error between the second traffic data group and the reconstructed traffic data group thereof.

[0065] It is worth noting that the above steps A1-A3 are only a training process of the auto-encoding network. In actual application, the auto-encoding network can be trained multiple times until the training stop condition is met, and the auto-encoding network after the last training is taken as the first detection network. The training stop condition can be set according to actual needs, for example, the loss of the auto-encoding network converges, or the number of training times reaches a number threshold, or the accuracy and recall rate of the auto-encoding network meet the preset requirements, etc., which are not limited by the embodiments of the present application.

[0066] Through the above training method, the auto-encoding network can learn the time series periodicity from each second traffic data group, extract the most informative features for reconstruction, so that the first detection model obtained can effectively capture abnormal patterns in the subsequent anomaly detection process.

[0067] ​Furthermore, since the above method considers that most traffic is normal traffic, far exceeding the amount of DDoS attack traffic, and since the labels for each traffic instance in supervised training often contain noise, this extremely small amount of DDoS attack traffic can be ignored. Therefore, all second traffic data sets within the second time period before the current time point can be considered as normal second traffic data sets. This allows for the acquisition of a large amount of labeled data without the need for additional labeling, resulting in the aforementioned multiple second traffic data sets – an unsupervised training method. Compared to supervised training that labels each traffic data set as normal / abnormal, this method avoids the problem of the model favoring more common normal patterns and ignoring abnormal patterns, thus improving the detection accuracy of the first detection model. Moreover, it eliminates the need for sample balancing operations, achieving the same ideal detection accuracy.

[0068] S304, based on each first traffic data group and the reconstructed traffic data group of each first traffic data group, determine the abnormal target first traffic data group from multiple first traffic data groups.

[0069] Since the first detection model is based on the error between the normal second traffic data set and its reconstructed traffic data set, it cannot effectively reproduce abnormal patterns, meaning it cannot reconstruct abnormal traffic data sets. This results in a significant difference between the abnormal traffic data set and the traffic data set obtained after reconstruction using the first detection model. Therefore, by calculating the difference between the first traffic data set and its reconstructed traffic data set, it can be determined whether the first traffic data set is abnormal.

[0070] In one embodiment, S304 includes the following steps:

[0071] S341, determine the error between each first traffic data group and the reconstructed traffic data group of each first traffic data group.

[0072] For example, for each first traffic data group, the mean square error between the first traffic data group and its reconstructed traffic data group is calculated as the error between the two, as shown in the above formula (1).

[0073] S342, from multiple first traffic data groups, obtain the first traffic data group whose error with the corresponding reconstructed traffic data group is greater than the error threshold, and determine it as the abnormal target first traffic data group.

[0074] For each first traffic data group, if the error between the first traffic data group and its reconstructed traffic data group is greater than the error threshold, it is determined that the difference between the two is large, and then it is determined that the first traffic data group is an abnormal target first traffic data group; if the error between the first traffic data group and its reconstructed traffic data group is less than or equal to the error threshold, it is determined that the difference between the two is small, and then it is determined that the first traffic data group is a normal first traffic data group.

[0075] It can be understood that the error between the first traffic data group and its reconstructed traffic data group can intuitively and accurately quantify the difference between the two, and the error is used to determine whether the first traffic data group is abnormal, which is simple and efficient.

[0076] In the above embodiment, the error threshold can be set according to actual needs, and the present application embodiment does not limit this. As an example, the error threshold can be set according to expert experience.

[0077] As another example, the error threshold can also be obtained after obtaining the first detection model, by reconstructing the plurality of second traffic data groups known to be normal using the first detection model, and by statistically analyzing the reconstruction results.

[0078] Specifically, by encoding and reconstructing the plurality of second traffic data groups known to be normal using the first detection model, a reconstructed traffic data group of each second traffic data group is obtained, and the error between each second traffic data group and its reconstructed traffic data group is calculated; then, by statistically analyzing the errors between all normal second traffic data groups and their reconstructed traffic data groups, such as visualizing statistics by histogram or density map, the mean and standard deviation of the errors are obtained; finally, based on the 3sigma principle, the error threshold is determined, that is: error threshold = mean error ± 3 x standard deviation.

[0079] It can be understood that the error threshold determined by the above is an adaptive threshold, which can change with the change of historical traffic data, and can more accurately distinguish abnormal traffic data groups and normal traffic data groups.

[0080] In another embodiment, the S304 includes the following steps: for each first traffic data group, determining the similarity between the first traffic data group and its reconstructed traffic data group; if the similarity is less than the similarity threshold, it is determined that the first traffic data group is an abnormal target first traffic data group. In order to distinguish from the similarity threshold used in the second anomaly detection, the similarity threshold here is also called the first similarity threshold.

[0081] The similarity between two traffic data sets can be obtained by using various similarity calculation methods commonly used in the art, such as Euclidean distance, dynamic time warping (DTW), cosine similarity, etc., and the embodiments of the present application are not limited in this regard.

[0082] The embodiments of the present application show part of the implementation of S304 described above. Of course, it should be understood that S304 described above can also be implemented in other ways, and the embodiments of the present application are not limited in this regard. It is worth noting that S304 described above is a preliminary anomaly detection of the first traffic data set, which is used to detect whether there is suspected DDoS attack traffic in the first traffic data set.

[0083] S306, determining the similarity between each pair of first traffic data in the target first traffic data set based on a second detection model.

[0084] The second detection model has a comparison function. As an example, the second detection model is obtained based on training of a first sample pair and a second sample pair, wherein the first sample pair includes two third traffic data belonging to the same third traffic data set, and the second sample pair includes two third traffic data belonging to different third traffic data sets.

[0085] The second detection model can have various appropriate structures, and the embodiments of the present application are not limited in this regard. Exemplarily, as shown in Figure 6 The second detection model adopts a Siamese network structure, which includes a subnetwork 1 and a subnetwork 2 that are identical, and these subnetworks share the same weights and parameters. These subnetworks can process different types of input data, such as numerical data, image data or sequence data. The paired input data are input into the two subnetworks at the same time, and since the subnetwork structures are the same and the weights are shared, they can process the input data similarly and extract features to obtain corresponding feature vectors, and then the similarity between the two subnetwork outputs is calculated, that is, the similarity between the paired input data is obtained.

[0086] In S206 described above, one first traffic data is input into subnetwork 1 for processing and feature extraction to obtain a feature vector 1 of the first traffic data; another first traffic data is input into subnetwork 2 for similar processing and feature extraction to obtain a feature vector 2 of the first traffic data; then, the feature vector 1 and the feature vector 2 are compared, and the similarity between the two is calculated, which is the similarity between the two input first traffic data.

[0087] In the embodiments of the present application, the second detection model can be obtained in various appropriate manners. In an implementation, an existing twin network is adopted as the second detection model.

[0088] In another implementation, the second detection model is obtained by training based on a plurality of third traffic data groups in a third time period before the current time point. Each third traffic data group includes a plurality of third traffic data, each of which corresponds to a time unit, and the source address and the destination address of the third traffic data belonging to the same third traffic data group are the same. The third time period is before the first time period, and the length of the third time period is equal to that of the first time period. It should be noted that the third time period herein can be the same as the second time period, or can be different from the second time period, such as a time period before the second time period. The manner of obtaining the plurality of third traffic data groups is similar to that of obtaining the first traffic data groups, and will not be described herein.

[0089] Specifically, the inventive concept for training the second detection model is to reduce the similarity between two traffic data belonging to the same category and increase the similarity between two traffic data belonging to different categories, and then calculate the similarity of the traffic data in the abnormal traffic data group by the model, and distinguish the traffic data existing DDoS attack and the normal traffic data according to the similarity between each traffic data and the remaining traffic data.

[0090] Based on the above inventive concept, as shown in Figure 7 The second detection model is obtained by the following manner:

[0091] Step B1, obtaining a plurality of third traffic data groups in a third time period before the current time point.

[0092] Step B2, combining the third traffic data in the plurality of third traffic data groups in pairs to obtain a first sample pair and a second sample pair.

[0093] Among them, the third traffic data in the first sample pair belongs to the same third traffic data group, and the third traffic data in the second sample pair belongs to different third traffic data groups.

[0094] Exemplarily, for each third traffic data group, two third traffic data are selected from the third traffic data group, and after adding a small amount of noise in the two third traffic data respectively, the two third traffic data are combined to obtain a first sample pair. In actual application, the number of first sample pairs is plural.

[0095] For each third traffic data group, one third traffic data is selected from the third traffic data group, and one third traffic data is selected from another third traffic data group, and the two third traffic data are combined after adding a small noise to each of the two third traffic data, to obtain a second sample pair. In actual application, the number of first sample pairs is multiple.

[0096] Step B3, determining the similarity of the first sample pair and the similarity of the second sample pair by the Siamese network.

[0097] Exemplarily, the Siamese network includes a sub-network 1 and a sub-network 3. One third traffic data in the first sample pair is input into the sub-network 1 for processing and feature extraction, to obtain a feature vector of the third traffic data; another third traffic data in the first sample pair is input into the sub-network 2 for processing and feature extraction, to obtain a feature vector of the third traffic data; then, the Euclidean distance between the two feature vectors is calculated, to obtain the similarity of the first sample pair.

[0098] The second sample pair is input into the Siamese network for similar processing, to obtain the similarity of the second sample pair.

[0099] Step B4, adjusting the parameters of the Siamese network based on the similarity of the first sample pair and the similarity of the second sample pair, to obtain a second detection model.

[0100] Exemplarily, based on the similarity of the first sample pair and the similarity of the second sample pair, the loss of the Siamese network is calculated, as shown in the following formula (2); then, by taking minimizing the loss as a target, the parameters of the Siamese network, including the parameters of the sub-network 1 and the parameters of the sub-network 2, are adjusted by a back propagation algorithm.

[0101]

[0102] Wherein, Loss2 represents the loss of the Siamese network; N represents the sum of the number of the first sample pairs and the number of the second sample pairs; Y represents a weight, Y=1 if it is the first sample pair, and Y=0 if it is the second sample pair; E w represents the similarity of the first sample pair or the second sample pair, and m represents a set similarity threshold value. In the embodiments of the present application, the L2 norm is selected as a measurement function, and m can be obtained based on historical data statistics.

[0103] It should be noted that the above steps B1-B4 are only a training process of the twin network. In actual application, the auto-encoding network can be trained multiple times until a training stop condition is met, and the twin network after the last training is taken as the second detection network. The training stop condition can be set according to actual needs, for example, loss convergence of the twin network, or the number of training times reaches a threshold, or the accuracy and recall rate of the twin network meet a preset requirement, and the embodiments of the present application do not limit this.

[0104] It can be understood that, since the traffic data in the same traffic data group usually belongs to the same category, and the traffic data in different traffic data groups usually belongs to different categories, the parameters of the twin network are adjusted by the above training method to minimize the distance between sample pairs composed of the same traffic data and maximize the distance between sample pairs composed of the same traffic data, that is, to reduce the similarity of sample pairs belonging to the same category and increase the similarity of sample pairs belonging to different categories. The second detection network obtained in this way can accurately calculate the similarity between any two traffic data, thereby accurately detecting DDoS attack traffic.

[0105] In addition, the above method does not need to label each third traffic data as abnormal or normal in advance, and is an unsupervised training method. Compared with the supervised training method of labeling each traffic data as normal / abnormal, this method can avoid the problem of model biasing to recognize more common normal patterns and ignoring abnormal patterns, which helps to improve the detection accuracy of the second detection model, and also does not need to perform sample balancing operation, and can also achieve ideal detection accuracy.

[0106] S308, determining whether each first traffic data in the target first traffic data group exists DDoS attack based on the similarity between each pair of first traffic data.

[0107] Since the difference between the traffic data with DDoS attack and the normal traffic data is large, if the similarity between a first traffic data in the target first traffic data group and most of the remaining first traffic data is low, it can be determined that the first traffic data exists DDoS attack.

[0108] Specifically, in an embodiment, the above S208 includes the following steps: for each first traffic data in the target first traffic data group, determining the average of the similarity between the first traffic data and the remaining first traffic data; if the average is less than a similarity threshold, it is determined that the first traffic data exists DDoS attack. Of course, if the average is greater than or equal to the similarity threshold, it is determined that the first traffic data is normal traffic data.

[0109] It can be understood that the mean of the similarity between each first traffic data and the rest of the first traffic data can accurately reflect the difference between each first traffic data and the rest of the first traffic data. If the mean of the similarity between a certain first traffic data and the rest of the first traffic data is low, it can be determined that the difference between the first traffic data and most of the first traffic data is large. Conversely, it can be determined that the difference between the first traffic data and most of the first traffic data is small. Therefore, based on the mean of the similarity between each first traffic data and the rest of the first traffic data, the first traffic data with DDoS attack can be quickly and accurately identified from the target first traffic data group.

[0110] In another embodiment, S208 includes the following steps: for each first traffic data, determining the number of the rest of the first traffic data with similarity greater than the similarity threshold, and if the number is greater than the number threshold, determining that the first traffic data is normal traffic; otherwise, determining that the first traffic data has DDoS attack.

[0111] The embodiments of the present application show part of the implementation of S208 described above. Of course, S208 described above can also be implemented by other ways, and the embodiments of the present application do not limit this.

[0112] It is worth noting that in the above various embodiments, in order to distinguish from the similarity threshold used in the anomaly pre-detection described above, the similarity threshold here can also be called the second similarity threshold.

[0113] In the above various embodiments, the similarity threshold can actually need to be set, and the embodiments of the present application do not limit this. As an example, the similarity threshold can be set according to expert experience.

[0114] As another example, the similarity threshold can also be calculated by using the second detection model to calculate the similarity between two third traffic data in the above plurality of third traffic data groups after obtaining the second detection model, and obtaining by statistical analysis of the similarity calculation result.

[0115] Specifically, as shown in Figure 8 After step B4, the similarity threshold is determined by the following way:

[0116] Step C1, encoding and reconstructing each third traffic data group by the first detection model to obtain the reconstructed traffic data group of each third traffic data group.

[0117] Exemplarily, the first detection model comprises an encoder and a decoder. For each third traffic data group, the third traffic data group is input into the first detection model, the third traffic data group is converted into a low-dimensional latent variable by the encoder, and the latent variable is reconstructed by the decoder to obtain a reconstructed traffic data group of the third traffic data group.

[0118] In step C2, based on errors between each third traffic data group and a reconstructed traffic data group of each third traffic data group, an abnormal target third traffic data group is determined from the plurality of third traffic data groups.

[0119] The specific implementation of step C2 is similar to that of step C1, and will not be described herein again. Figure 3 The specific implementation of S304 in the illustrated embodiment is similar to that of S302, and will not be described herein again.

[0120] In step C3, third traffic data in the target third traffic data group and third traffic data in the remaining third traffic data groups are combined to obtain a plurality of third sample pairs and a similarity label of each third sample pair.

[0121] Exemplarily, for each third traffic data in the target third traffic data group, the third traffic data is paired with one third traffic data in the remaining third traffic data groups to obtain a third sample pair. That is, one third traffic data in the third sample pair is from the target third traffic data group and is suspected to be DDoS attack traffic data, and the other third traffic data is from the remaining third traffic data groups and is normal traffic data.

[0122] For each third sample pair, the similarity label of the third sample pair is used to indicate whether the third sample pair is similar, and specifically can indicate whether the third sample pair contains normal traffic data and DDoS attack traffic data.

[0123] The similarity label of the third sample pair can be obtained in various appropriate manners, and embodiments of the present application do not limit this. As an example, the similarity label of the third sample pair can be obtained according to manual labeling. For example, the third sample pair is sent to a labeling platform, and a labeling personnel labels to obtain.

[0124] As another example, the plurality of third traffic data groups contain a part of known normal third traffic data groups. If one third traffic data in the third sample pair belongs to the normal third traffic data group, and the other third traffic data belongs to other third traffic data groups, a similarity label indicating similarity is labeled for the third sample pair. If the third traffic data in the third sample pair all belong to the normal third traffic data groups, a similarity label indicating dissimilarity is labeled for the third sample pair.

[0125] Step C4, determining the similarity of each third sample pair by the second detection model.

[0126] Exemplarily, the second detection model comprises a sub-network 1 and a sub-network 2. For each third sample pair, one of the third traffic data in the third sample pair is input into the sub-network 1 for processing and feature extraction, obtaining a corresponding feature vector; the other of the third traffic data in the third sample pair is input into the sub-network 2 for similar processing and feature extraction, obtaining a corresponding feature vector; then, the Euclidean distance between the two feature vectors is calculated to obtain the similarity of the third sample pair.

[0127] Step C5, determining the similarity threshold based on the similarity of each third sample pair and the similarity label of each third sample pair.

[0128] As an example, the similarity label can be determined as the mean of the similarity of the similar third sample pairs, and the similarity label can be determined as the mean of the similarity of the dissimilar third sample pairs, and then the two means are integrated to determine the similarity threshold.

[0129] For example, the mean of the similarity of the similar third sample pairs is 0.7, and the mean of the similarity of the dissimilar third sample pairs is 0.4, and a value between the two, such as 0.6, can be taken as the similarity threshold.

[0130] As another example, in order to enable the similarity threshold to be used to more accurately distinguish normal traffic data and traffic data with DDoS attack, an initial similarity threshold can be set, and from the above plurality of third sample pairs, target third sample pairs with a similarity less than the similarity threshold and a similarity label of dissimilar are selected, the target third sample pairs are third sample pairs whose detection results by the initial similarity threshold are consistent with the similarity label, that is, third sample pairs that can be accurately detected by the initial similarity threshold; then, according to the ratio between the number of target third sample pairs and the number of all third sample pairs with a similarity label of dissimilar, the detection accuracy of the initial similarity threshold is obtained; if the detection accuracy does not reach the expected detection accuracy (such as 90%), the initial similarity threshold is adjusted, and the above steps are repeated until the detection accuracy reaches the expected detection accuracy, and the similarity threshold at this time is taken as the final similarity threshold for DDoS attack traffic detection.

[0131] It can be understood that the similarity threshold determined by the above is an adaptive threshold, which can change with the change of historical traffic data, and can more accurately realize the distinction between real-time DDoS attack traffic data and normal traffic data.

[0132] Optionally, after S308, after the first traffic data existing DDoS attack is determined from the target first traffic data group, a warning information is also output, and the warning information can include the source address and the destination address of the first traffic data existing DDoS attack, so as to locate the DDoS attack. The warning information can also include the timestamp information of the first traffic data existing DDoS attack, so as to locate the period of time suffering from the DDoS attack.

[0133] The DDoS traffic detection method provided by one or more embodiments of the present application adopts a two-step detection manner, divides the traffic data collected in a first time period before the current time point into a plurality of first traffic data groups according to source addresses and destination addresses, and performs two-step anomaly detection by using the plurality of first traffic data groups. The target first traffic data group existing anomaly is detected first, and the first traffic data existing DDoS attack in the target first traffic data group is further detected. The time sequence period correlation between the traffic data can be fully utilized, the accuracy of DDoS attack detection is improved, the false positive rate is reduced, the DDoS attack can be accurately detected in real time, the potential network attack behavior can be discovered and responded to in time, and thus the safety and stability of the network and system can be effectively protected. On this basis, for the detection of the target first traffic data group existing anomaly, it is considered that the abnormal traffic data group is difficult to be effectively reconstructed by using the machine learning model, which leads to a large difference between the abnormal traffic data group and the reconstructed traffic data group thereof. Based on this, the first detection model is used to code and reconstruct each first traffic data group to obtain the corresponding reconstructed traffic data group. Then, the difference between the first traffic data group and the reconstructed traffic data group thereof can be used to quickly and accurately determine whether the first traffic data group is abnormal. In addition, for the detection of the traffic data existing DDoS attack in the target first traffic data group, it is considered that the difference between the DDoS attack traffic data and the normal traffic data is large. If the similarity between a certain first traffic data in the target first traffic data group and the remaining most first traffic data is low, it can be determined that the first traffic data exists DDoS attack.

[0134] The above describes specific embodiments of the present specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in an order different than the order in the embodiments and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous or necessary.

[0135] Based on the same inventive concept, the present application also provides a DDoS attack detection device. Please refer to Figure 9FIG. 1 is a schematic diagram of a DDoS attack detection device according to an embodiment of the present application. In a software implementation, the DDoS attack detection device 100 includes a reconstruction unit 110, a first detection unit 120, a comparison unit 130, and a second detection unit 140.

[0136] The reconstruction unit 110 is configured to encode and reconstruct, by using a first detection model, a plurality of first traffic data groups in a first time period before a current time point, to obtain a reconstructed traffic data group of each first traffic data group, each first traffic data group including a plurality of first traffic data, each first traffic data corresponding to a time unit, and the source address and the destination address of the first traffic data belonging to the same first traffic data group being the same.

[0137] The first detection unit 120 is configured to determine, based on each first traffic data group and the reconstructed traffic data group of each first traffic data group, a target first traffic data group from the plurality of first traffic data groups.

[0138] The comparison unit 130 is configured to determine, based on a second detection model, a similarity between two first traffic data in the target first traffic data group.

[0139] The second detection unit 140 is configured to determine, based on the similarity between the two first traffic data, whether each first traffic data in the target first traffic data group is subjected to a DDoS attack.

[0140] In another embodiment, the first detection unit is configured to:

[0141] determine an error between each first traffic data group and the reconstructed traffic data group of each first traffic data group;

[0142] obtain, from the plurality of first traffic data groups, a first traffic data group having an error greater than an error threshold with the corresponding reconstructed traffic data group, and determine the first traffic data group as the target first traffic data group.

[0143] In another embodiment, the second detection unit is configured to:

[0144] for each first traffic data in the target first traffic data group, determine a mean value of the similarity between the first traffic data and the remaining first traffic data;

[0145] if the mean value is less than a similarity threshold, determine that the first traffic data is subjected to a DDoS attack.

[0146] In another embodiment, the first detection model is obtained by training in the following manner:

[0147] a plurality of second traffic data groups in a second time period before the current time point, each second traffic data group comprising a plurality of second traffic data, each second traffic data corresponding to a time unit, and the source address and the destination address of the second traffic data belonging to the same second traffic data group being the same;

[0148] encoding and reconstructing each second traffic data group through a self-encoding network to obtain a reconstructed traffic data group of each second traffic data group;

[0149] adjusting parameters of the self-encoding network based on errors between each second traffic data group and the reconstructed traffic data group of each second traffic data group, to obtain a first detection model.

[0150] In another embodiment, the second detection model is obtained by training in the following manner:

[0151] a plurality of third traffic data groups in a third time period before the current time point, each third traffic data group comprising a plurality of third traffic data, each third traffic data corresponding to a time unit, and the source address and the destination address of the third traffic data belonging to the same third traffic data group being the same;

[0152] combining the third traffic data in the plurality of third traffic data groups in pairs to obtain a first sample pair and a second sample pair, the third traffic data in the first sample pair belonging to the same third traffic data group, and the third traffic data in the second sample pair belonging to different third traffic data groups, and determining the similarity of the first sample pair and the similarity of the second sample pair through a twin network;

[0153] adjusting parameters of the twin network based on the similarity of the first sample pair and the similarity of the second sample pair, to obtain a second detection model.

[0154] In another embodiment, the reconstruction unit is further configured to encode and reconstruct each third traffic data group through the first detection model to obtain a reconstructed traffic data group of each third traffic data group;

[0155] The first detection unit is further configured to determine an abnormal target third traffic data group from the plurality of third traffic data groups based on errors between each third traffic data group and the reconstructed traffic data group of each third traffic data group;

[0156] The comparison unit is further configured to combine the third traffic data in the target third traffic data group with the third traffic data in the remaining third traffic data groups to obtain a plurality of third sample pairs and a similarity label of each third sample pair, and determine the similarity of each third sample pair through the second detection model;

[0157] The DDoS attack detection apparatus further includes:

[0158] A determination unit configured to determine a similarity threshold based on the similarity of each third sample pair and the similarity label of each third sample pair.

[0159] Obviously, the DDoS attack detection apparatus 900 provided by the embodiments of the present application can be used as the execution subject of the DDoS attack detection method shown in Figure 3 , and thus can realize the functions of the DDoS attack detection method shown in Figure 3 . Since the principles are the same, they will not be repeated here.

[0160] Figure 10 is a structural schematic diagram of an electronic device according to an embodiment of the present application. Please refer to Figure 10 , at the hardware level, the electronic device includes a processor, and optionally further includes an internal bus, a network interface, and a memory. The memory can include a memory such as a random-access memory (RAM), and can also include a non-volatile memory such as at least one disk memory. Of course, the electronic device can also include other hardware required by the business.

[0161] The processor, the network interface, and the memory can be connected to each other through the internal bus, which can be an industry standard architecture (ISA) bus, a peripheral component interconnect (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, and a control bus. For ease of representation, Figure 10 , only one bidirectional arrow is used, but it does not mean that there is only one bus or only one type of bus.

[0162] The memory is used to store programs. Specifically, the program can include program code, and the program code includes computer operation instructions. The memory can include a memory and a non-volatile memory, and provides instructions and data to the processor.

[0163] The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs, and forms a DDoS attack detection apparatus at the logical level. The processor executes the program stored in the memory, and is specifically used to perform the following operations:

[0164] The first detection model encodes and reconstructs multiple first traffic data groups within the first time period before the current time point to obtain a reconstructed traffic data group for each first traffic data group. Each first traffic data group includes multiple first traffic data, and each first traffic data corresponds to a time unit. The source address and destination address of the first traffic data belonging to the same first traffic data group are the same.

[0165] Based on each first traffic data group and the reconstructed traffic data group of each first traffic data group, an abnormal target first traffic data group is determined from the plurality of first traffic data groups;

[0166] Based on the second detection model, the similarity between pairs of first traffic data in the target first traffic data group is determined;

[0167] Based on the similarity between each pair of first traffic data, it is determined whether each first traffic data in the target first traffic data group is subject to a DDoS attack.

[0168] The above is as stated in this application. Figure 3 The method executed by the DDoS attack detection device disclosed in the illustrated embodiment can be applied to a processor or implemented by a processor. The processor may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by integrated logic circuits in the processor's hardware or by instructions in software form. The processor can be a general-purpose processor, including a Central Processing Unit (CPU), a Network Processor (NP), etc.; it can also be a Digital Signal Processor (DSP), an Application Specific Integrated Circuit (ASIC), a Field-Programmable Gate Array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of this application can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can reside in a mature storage medium in the field, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, or registers. This storage medium is located in memory, and the processor reads information from the memory and, in conjunction with its hardware, completes the steps of the above method.

[0169] The electronic device can also execute the method shown in Figure 3 and realize the function of the DDoS attack detection device in the embodiment shown in Figures 3 to 6 The embodiments of the present application will not be described here.

[0170] Of course, in addition to the software implementation, the electronic device of the present application does not exclude other implementation manners, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0171] The embodiments of the present application also propose a computer readable storage medium storing one or more programs, the one or more programs including instructions that, when executed by a portable electronic device including a plurality of application programs, can cause the portable electronic device to execute the method shown in Figure 3 and specifically used to perform the following operations:

[0172] Encode and reconstruct the plurality of first traffic data groups in the first time period before the current time point by the first detection model to obtain a reconstructed traffic data group of each first traffic data group, each first traffic data group including a plurality of first traffic data, each first traffic data corresponding to a time unit, and the source address and the destination address of the first traffic data belonging to the same first traffic data group being the same;

[0173] Based on each first traffic data group and the reconstructed traffic data group of each first traffic data group, determine an abnormal target first traffic data group from the plurality of first traffic data groups;

[0174] Based on the second detection model, determine the similarity between each pair of first traffic data in the target first traffic data group;

[0175] Based on the similarity between each pair of first traffic data, determine whether DDoS attack exists in each first traffic data in the target first traffic data group.

[0176] The embodiments of the present application also provide a computer program product, which includes a non-transitory computer readable storage medium storing a computer program, the computer program being operable to cause a computer to execute part or all of the steps of the DDoS attack detection method provided by the embodiments of the present application.

[0177] In summary, the above only describes the preferred embodiments of the present application, and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0178] The systems, apparatuses, modules, or units in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0179] Computer readable media includes permanent and non-permanent, removable and non-removable media, which can be implemented by any method or technology to store information. The information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read only memory (ROM), electrically erasable programmable read only memory (EEPROM), flash memory or other memory technology, compact disc read only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. According to the definition herein, computer readable media does not include transitory media such as modulated data signals and carriers.

[0180] It should also be noted that the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, so that processes, methods, articles or devices including a series of elements not only include those elements, but also include other elements not explicitly listed or inherent to such processes, methods, articles or devices. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or device including the element.

[0181] The embodiments in the specification are described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, the system embodiments are described simply because they are basically similar to the method embodiments, and the relevant parts can be referred to the description of the method embodiments. The embodiments in the specification are described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the difference from other embodiments. In particular, the system embodiments are described simply because they are basically similar to the method embodiments, and the relevant parts can be referred to the description of the method embodiments.

Claims

1. A DDoS attack detection method, characterized in that, include: The first detection model encodes and reconstructs multiple first traffic data groups within the first time period before the current time point to obtain a reconstructed traffic data group for each first traffic data group. Each first traffic data group includes multiple first traffic data, and each first traffic data corresponds to a time unit. The source address and destination address of the first traffic data belonging to the same first traffic data group are the same. Based on each first traffic data group and the reconstructed traffic data group of each first traffic data group, an abnormal target first traffic data group is determined from the plurality of first traffic data groups; Based on the second detection model, the similarity between pairs of first traffic data in the target first traffic data group is determined; Based on the similarity between each pair of first traffic data, it is determined whether each first traffic data in the target first traffic data group is subject to a DDoS attack.

2. The method according to claim 1, characterized in that, The step of determining the abnormal target first traffic data group from the plurality of first traffic data groups based on each first traffic data group and the reconstructed traffic data group of each first traffic data group includes: Determine the error between each first traffic data group and the reconstructed traffic data group of each first traffic data group; The first traffic data group whose error with the corresponding reconstructed traffic data group is greater than the error threshold is selected from the plurality of first traffic data groups and identified as the abnormal target first traffic data group.

3. The method according to claim 1, characterized in that, The step of determining whether each first traffic data in the target first traffic data group is subject to a DDoS attack based on the similarity between each pair of first traffic data includes: For each first traffic data in the target first traffic data group, determine the average similarity between the first traffic data and the other first traffic data; If the mean value is less than the similarity threshold, then it is determined that the first traffic data is subject to a DDoS attack.

4. The method according to any one of claims 1 to 3, characterized in that, The first detection model was trained in the following way: Get multiple second traffic data groups within the second time period before the current time point. Each second traffic data group includes multiple second traffic data, and each second traffic data corresponds to a time unit. The source address and destination address of the second traffic data belonging to the same second traffic data group are the same. Each second traffic data group is encoded and reconstructed using an autoencoder network to obtain a reconstructed traffic data group for each second traffic data group. Based on the error between each second flow data group and the reconstructed flow data group of each second flow data group, the parameters of the autoencoder network are adjusted to obtain the first detection model.

5. The method according to any one of claims 1 to 3, characterized in that, The second detection model was trained in the following way: Get multiple third traffic data groups within the third time period before the current time point. Each third traffic data group includes multiple third traffic data. Each third traffic data corresponds to a time unit. The source address and destination address of the third traffic data belonging to the same third traffic data group are the same. The third traffic data in the plurality of third traffic data groups are combined in pairs to obtain a first sample pair and a second sample pair. The similarity between the first sample pair and the second sample pair is determined by a Siamese network. The third traffic data in the first sample pair belong to the same third traffic data group, and the third traffic data in the second sample pair belong to different third traffic data groups. Based on the similarity between the first sample pair and the second sample pair, the parameters of the Siamese network are adjusted to obtain a second detection model.

6. The method according to claim 5, characterized in that, After adjusting the parameters of the Siamese network based on the similarity of the first sample pair and the similarity of the second sample pair to obtain the second detection model, the method further includes: The first detection model is used to encode and reconstruct each third traffic data group to obtain the reconstructed traffic data group of each third traffic data group. Based on the error between each third traffic data group and the reconstructed traffic data group of each third traffic data group, an abnormal target third traffic data group is determined from the plurality of third traffic data groups; The third traffic data in the target third traffic data group and the third traffic data in other third traffic data groups are combined to obtain multiple third sample pairs and similar labels for each third sample pair, and the similarity of each third sample pair is determined by the second detection model. A similarity threshold is determined based on the similarity of each third sample pair and the similarity label of each third sample pair.

7. A DDoS attack detection device, characterized in that, include: The reconstruction unit is used to encode and reconstruct multiple first traffic data groups within a first time period before the current time point through the first detection model, so as to obtain a reconstructed traffic data group for each first traffic data group. Each first traffic data group includes multiple first traffic data, each first traffic data corresponds to a time unit, and the source address and destination address of the first traffic data belonging to the same first traffic data group are the same. The first detection unit is used to determine the abnormal target first traffic data group from the plurality of first traffic data groups based on each first traffic data group and the reconstructed traffic data group of each first traffic data group. The comparison unit is used to determine the similarity between pairs of first traffic data in the target first traffic data group based on the second detection model; The second detection unit is used to determine whether each first traffic data in the target first traffic data group is subject to a DDoS attack based on the similarity between the pairs of first traffic data.

8. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the DDoS attack detection method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by the processor of the electronic device, the electronic device is able to perform the DDoS attack detection method as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, The computer program product includes a non-transitory computer-readable storage medium storing a computer program operable to cause a computer to perform some or all of the steps in the DDoS attack detection method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • DDoS attack detection method and system in software defined industrial internet

    CN114760087A

  • Network abnormal traffic classification method and device, equipment and storage medium

    CN117786570A