A method and system for resisting DDoS attack based on intelligent migration

By establishing a threat database and an importance database, and dynamically migrating high-risk, low-value tenants, the impact of DDoS attacks on high-value customers in public cloud resource pools was resolved, thus achieving stability and business continuity protection for resource pools.

CN119051881BActive Publication Date: 2026-01-16CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410905646.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-08
Publication Date
2026-01-16
Estimated Expiration
2044-07-08

AI Technical Summary

Technical Problem

In a public cloud resource pool, when an individual tenant suffers a DDoS attack, it affects the stability of the entire resource pool and the business continuity of high-value customers. Existing technologies are insufficient to effectively defend against and isolate the risk.

Method used

Establish a tenant DDoS attack threat database and a business importance database. By calculating threat scores and business importance, dynamically migrate high-risk, low-value tenants to lower-level resource pools to avoid attacks affecting overall stability.

Benefits of technology

Effectively isolate the attack risks of high-value tenants, protect the stability of the resource pool and business continuity, and dynamically adjust resource allocation to cope with DDoS attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119051881B_ABST
    Figure CN119051881B_ABST
Patent Text Reader

Abstract

The application discloses a kind of anti- DDoS attack methods based on intelligent migration, comprising the following steps: S1: establishing tenant DDoS attack threat library;S2: tenant business importance database;S3: calculate tenant current latest possible suffer DDoS attack threat degree, and compare with threshold value;S4: obtain tenant current business importance label;A kind of anti- DDoS attack system based on intelligent migration, the system is applicable to any one of the above method, and system includes: ①: DDoS attack threat library;②: tenant business importance database;③: attack information record module;④: threat degree judging module;⑤: dynamic resource allocation module.The application can carry out resource pool migration to tenant business according to different tenant suffer ddos attack risk degree and tenant business importance, fundamentally avoid the collateral influence that high-value tenant is attacked with other users in same resource pool.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security and cloud security, and particularly relates to an anti-DDoS attack method and system based on intelligent migration. BACKGROUND

[0002] DDoS attack has become one of the biggest threats on the Internet due to its simplicity, low cost and difficulty to defend. Attackers challenge the defense success rate through multi-dimensional attacks, from network infrastructure to cloud business systems, and the threat is rising in all directions. The frequency, intensity and complexity of DDoS attacks in 2022 are increasing, especially bringing new challenges to the resource pool of cloud service providers. The customers served by cloud service providers involve thousands of industries, and the business situation is extremely complex. Different industries and users have different risks of potential DDoS attacks, and the risk of most businesses or hosts will also dynamically change. When individual tenants in the resource pool are subjected to large flow DDoS attacks, it may cause the entire resource pool outlet to be blocked, affecting the normal use of other tenants in the resource pool, and having a major impact on the service stability, security and brand image of cloud service providers.

[0003] Currently, tenants on public clouds can freely choose the resource pool to which they belong when purchasing public cloud resources, and thus various tenants and businesses are distributed in a single resource pool, so that all tenants and businesses share the risk of DDoS attacks. Most tenants are unwilling to purchase DDoS attack protection capabilities alone, resulting in a series of adverse problems such as affecting the business continuity of other high-value customers in the same resource pool when individual tenants in the resource pool are subjected to DDoS attacks. SUMMARY

[0004] This section is intended to summarize some aspects of the embodiments of the present application and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the abstract and title of the specification to avoid obscuring the purpose of this section, abstract and title, and such simplifications or omissions cannot be used to limit the scope of the present application.

[0005] In view of the above problems of the prior art anti-DDoS attack method and system based on intelligent migration, the present application is proposed.

[0006] Therefore, the purpose of the present application is to provide an anti-DDoS attack method and system based on intelligent migration, which is suitable for solving the problem of affecting the business continuity of other high-value customers in the same resource pool when individual tenants in the resource pool are subjected to DDoS attacks.

[0007] To solve the above technical problems, the present application provides the following technical scheme: an anti-DDoS attack method based on intelligent migration, comprising the following steps:

[0008] S1: Establish a tenant DDoS attack threat library;

[0009] S2: Tenant business importance database;

[0010] S3: Calculate the current latest possible DDoS attack threat degree of the tenant, and compare it with the threshold;

[0011] S4: Obtain the current business importance label of the tenant;

[0012] S5: Comprehensive analysis and judgment whether the tenant should be migrated to a lower level resource pool;

[0013] S6: Resource pool migration of the tenant business.

[0014] As a preferred scheme of the anti- DDoS attack method based on intelligent migration, in step S1, the DDoS attack situation and the threat degree of DDoS attack suffered by the single tenant resource are measured and recorded in detail, and the possibility of DDoS attack suffered by the user and the stability influence brought to the resource pool for this are positively correlated with the DDoS attack threat integral.

[0015] As a preferred scheme of the anti- DDoS attack method based on intelligent migration, the threat integral K is determined by the number M of IP addresses of the user attacked by DDoS, the number N of times of DDoS attack, the size F of the flow of each DDoS attack, the length T of the time distance from each DDoS attack to the current time and other factors, and the DDoS attack threat degree threshold Q is set.

[0016] As a preferred scheme of the anti- DDoS attack method based on intelligent migration, in step S2, according to the tenant resource consumption and the tenant industry attribute and other factors, the business importance V of the tenant is calculated.

[0017] As a preferred scheme of the anti- DDoS attack method based on intelligent migration, in step S3, when the tenant in a resource pool is attacked by DDoS, the DDoS attacked user ID corresponding to this attack, the resource pool ID to which the user belongs, the flow size of the DDoS attack and the time of the DDoS attack are recorded, and the number of IP addresses of the user attacked by DDoS and the number of times of DDoS attack are updated.

[0018] As a preferred scheme of the anti- DDoS attack method based on intelligent migration, in step S4, the current DDoS attack threat value K of the tenant is calculated, and compared with the threshold Q.

[0019] As a preferred scheme of the anti-DDoS attack method based on intelligent migration, the threat integral K is calculated according to the following formula:

[0020]

[0021] Wherein, F i and T i represent the size of the flow attacked by the i-th DDoS attack of the tenant and the time distance from the DDoS attack to the current time.

[0022] As a preferred scheme of the anti-DDoS attack method based on intelligent migration, in step S5, the current tenant service importance record value is obtained from the tenant service importance database, if the record value is "low", the tenant service is automatically migrated to the resource pool with the resource pool level "low" during the service low peak period, so as to avoid the influence of the DDoS attack on the entire resource pool due to the low service importance of the tenant.

[0023] An anti-DDoS attack system based on intelligent migration, the system is suitable for any one of the above methods, and the system comprises:

[0024] ①: DDoS attack threat library;

[0025] DDoS attack record sub-module: for recording the detailed information of each DDoS attack, including the user ID, resource pool ID, attack flow size and attack time;

[0026] Threat degree calculation sub-module: for calculating the DDoS attack threat integral K of each tenant, and measuring according to the number of user IPs, attack times, flow size and time distance factors;

[0027] ②: tenant service importance database; according to the tenant resource consumption, industry attribute and other factors, the service importance of the tenant is calculated and recorded;

[0028] ③: attack information recording module; for recording and updating the attack information of the tenant;

[0029] ④: threat degree judgment module; according to the threat integral K and the preset threshold Q, the DDoS attack threat degree of the current tenant is judged, and it is decided whether subsequent processing is needed;

[0030] ⑤: dynamic resource allocation module.

[0031] As a preferred scheme of the anti-DDoS attack system based on intelligent migration, the dynamic resource allocation module comprises:

[0032] A migration decision sub-module: according to the business importance of the tenant and the threat score K, it is decided whether to migrate the tenant to a different level of resource pool;

[0033] An automatic migration sub-module: during the business off-peak period, the tenant with low business importance and high threat score is automatically migrated to the "low" level resource pool to protect the stability of the overall resource pool.

[0034] The beneficial effects of the present application: the tenant business can be migrated according to the risk of ddos attack suffered by different tenants and the business importance of the tenant, which fundamentally avoids the collateral effects of high-value tenants being attacked by other users in the same resource pool, dynamically calculates the DDoS attack threat degree of the tenant, maintains the DDoS attack threat library, dynamically calculates the business importance of the tenant, maintains the tenant business importance database, and intelligently migrates the tenant business to the resource pool with a "low" level according to the DDoS attack threat degree of the tenant, so as to avoid the impact of the entire resource pool caused by the DDoS attack on the tenant with low business importance. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor. Among them:

[0036] Fig. 1 The anti- DDoS attack processing flowchart of the anti- DDoS attack method and system based on intelligent migration proposed by the present application;

[0037] Fig. 2 The influence threat score factor table of the anti- DDoS attack method and system based on intelligent migration proposed by the present application;

[0038] Fig. 3 The tenant business importance data table of the anti- DDoS attack method and system based on intelligent migration proposed by the present application. DETAILED DESCRIPTION

[0039] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the drawings.

[0040] In the following description, many specific details are set forth in order to provide a thorough understanding of the present application, but the present application can also be implemented in other ways different from those described herein, and those skilled in the art can make similar generalizations without departing from the connotation of the present application, therefore the present application is not limited to the specific embodiments disclosed below.

[0041] Second, the "one embodiment" or "an embodiment" referred to herein means a specific feature, structure, or characteristic under discussion. Each of the various embodiments presented in this specification are not necessarily all mutually exclusive alternatives from another. It should be understood that claims can be formulated to claim only those implementations in the specification that explicitly address the particular features under discussion.

[0042] Third, the present application is described in detail in conjunction with the schematic diagram. In the detailed description of the embodiments of the present application, the cross-sectional view of the device structure is partially enlarged without the general proportion for the convenience of description, and the schematic diagram is only an example, which should not limit the scope of protection of the present application. In addition, the three-dimensional spatial dimensions of length, width and depth should be included in actual production.

[0043] Embodiment

[0044] Reference Figs. 1-3 For an embodiment of the present application, an intelligent migration-based anti-DDoS attack method is provided, comprising the following steps:

[0045] S1: Establish a tenant DDoS attack threat library;

[0046] In step S1, the DDoS attack situation and the threat degree of the single-tenant resource suffered from DDoS attack are measured and recorded in detail. The possibility of user suffering from DDoS attack and the stability impact on the resource pool for this are positively correlated with the DDoS attack threat score. The threat score K is determined by the number of IP addresses M attacked by DDoS, the number of times N attacked by DDoS, the size of traffic F attacked by DDoS each time, the length T of the time distance from each time attacked by DDoS to the current time, and other factors. A DDoS attack threat degree threshold Q is set.

[0047] The calculation formula of the threat score K is as follows:

[0048]

[0049] Wherein, F i and T i represent the size of traffic attacked and the time distance from the DDoS attack to the current time when the tenant is attacked by DDoS for the i-th time.

[0050] S2: Tenant business importance database;

[0051] In step S2, the tenant business importance V is calculated according to the tenant resource consumption and tenant industry attributes and other factors.

[0052] S3: Calculate the latest possible DDoS attack threat degree of the tenant and compare it with the threshold.

[0053] In step S3, when a tenant in a resource pool suffers a DDoS attack, the DDoS attacked user ID, the resource pool ID, the amount of DDoS attack traffic, and the time of the DDoS attack are recorded. At the same time, the number of IPs attacked by the user ID and the number of DDoS attacks are updated in association.

[0054] S4: Obtain the current business importance tag of the tenant;

[0055] In step S4, the current DDoS attack threat value K of the tenant is calculated and compared with the threshold Q;

[0056] S5: Make a comprehensive assessment to determine whether the tenant should be migrated to a lower-level resource pool;

[0057] In step S5, the current tenant business importance record value is obtained from the tenant business importance database. If the record value is "low", the tenant business is automatically migrated to the resource pool with a resource pool level of "low" during the off-peak period to avoid the impact of DDoS attacks on the stability of the entire resource pool after the tenant with low business importance suffers a DDoS attack.

[0058] S6: Migrate the resource pool for tenant services.

[0059] A DDoS attack mitigation system based on intelligent migration, the system being applicable to any of the above methods, and the system comprising:

[0060] ①: DDoS attack threat database;

[0061] The DDoS attack logging submodule is used to record detailed information about each DDoS attack, including the attacking user ID, resource pool ID, attack traffic size, and attack time.

[0062] Threat Calculation Submodule: Used to calculate the DDoS attack threat score K for each tenant, based on factors such as the number of user IPs, number of attacks, traffic volume, and time distance.

[0063] ②: Tenant Business Importance Database; Calculates and records the business importance of tenants based on factors such as tenant resource consumption and industry attributes;

[0064] ③: Attack information recording module; used to record and update tenant's attack information;

[0065] ④ Threat Level Assessment Module: Based on the threat score K and the preset threshold Q, the module determines the DDoS attack threat level of the current tenant and decides whether further processing is required.

[0066] ⑤: Dynamic resource allocation module;

[0067] The dynamic resource allocation module comprises:

[0068] A migration decision sub-module decides whether to migrate the tenant to a resource pool of a different level according to the business importance of the tenant and the threat score K;

[0069] An automatic migration sub-module automatically migrates a tenant with low business importance and high threat score to a resource pool of a "low" level during a business off-peak period to protect the stability of the overall resource pool.

[0070] During use, the tenant business can be migrated according to the risk of ddos attack suffered by different tenants and the business importance of the tenant, fundamentally avoiding the collateral effects on high-value tenants caused by attacks on other users in the same resource pool, dynamically calculating the DDoS attack threat degree of the tenant, maintaining the DDoS attack threat library, dynamically calculating the business importance of the tenant, maintaining the tenant business importance database, intelligently migrating the tenant business to a resource pool of a "low" level according to the DDoS attack threat degree of the tenant, and avoiding the impact on the overall resource pool stability caused by DDoS attacks on tenants with low business importance.

[0071] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not limiting. Although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application can be modified or replaced by equivalents without departing from the spirit and scope of the present application, and they should be covered in the scope of the claims of the present application.

Claims

1. A method for anti-DDoS attack based on intelligent migration, characterized in that, The method comprises the following steps: S1: establishing a tenant DDoS attack threat library; S2: tenant business importance database; S3: calculating the current latest possible DDoS attack threat degree of the tenant and comparing it with a threshold value; S4: obtaining the current business importance label of the tenant; S5: comprehensively judging whether the tenant should be migrated to a resource pool with a lower level; S6: migrating the tenant business to a resource pool; In step S1, the DDoS attack situation and the threat degree of the DDoS attack suffered by the single-tenant resource are measured and recorded in detail, and the possibility of the user suffering from the DDoS attack and the stability impact on the resource pool for this are positively correlated with the DDoS attack threat integral K; In step S2, the tenant business importance V is calculated according to the tenant resource consumption and the tenant industry attribute factors. 2.The method of claim 1, wherein the method further comprises: The threat integral K is determined by the number M of IP addresses of the user attacked by DDoS, the number N of times of DDoS attack, the traffic size F of each DDoS attack, and the length T of the time distance from each DDoS attack to the current time, and a DDoS attack threat degree threshold value Q is set. 3.The method of claim 1, wherein the method further comprises: In step S3, when a tenant in a certain resource pool suffers from a DDoS attack, the DDoS attack user ID corresponding to this attack, the resource pool ID, the DDoS attack traffic size, and the DDoS attack time are recorded, and the number of IP addresses of the user attacked by DDoS and the number of times of DDoS attack are updated.

4. The method of claim 1, wherein the method is characterized by: In step S3, the current DDoS attack threat integral K of the tenant is calculated and compared with the threat degree threshold value Q.

5. The method of claim 1, wherein the method further comprises: The calculation formula of the threat integral K is as follows: wherein, and denotes the size of the traffic under attack and the time distance from the current time when the tenant is attacked by the i-th DDOS attack.

6. The method of claim 1, wherein the method further comprises: In step S5, the current tenant business importance record value is obtained from the tenant business importance database, if the record value is "low", the tenant business is automatically migrated to a resource pool with a "low" level in a business low peak period, so as to avoid the influence of the DDoS attack on the entire resource pool caused by the tenant with low business importance.

7. A system for anti-DDoS attack based on intelligent migration, characterized in that, The system is applicable to any one of the methods in claims 1-6, and the system comprises: ①: DDoS attack threat library; DDoS attack record submodule: used for recording the detailed information of each DDoS attack, including the user ID, resource pool ID, attack traffic size, and attack time; Threat degree calculation submodule: used for calculating the DDoS attack threat integral K of each tenant, and measuring according to the number of IP addresses of the user, the number of attacks, the traffic size, and the time distance factors; ②: tenant business importance database; the business importance of the tenant is calculated and recorded according to the tenant resource consumption, industry attribute, and other factors; ③: attack information recording module; used for recording and updating the attack information of the tenant; ④: threat degree judgment module; the current DDoS attack threat degree of the tenant is judged by comparing the threat integral K with the preset threshold value Q, and it is decided whether subsequent processing is needed; ⑤: dynamic resource allocation module. 8.The intelligent migration based anti-DDoS attack system of claim 7, wherein: The dynamic resource allocation module comprises: A migration decision submodule decides whether to migrate the tenant to a resource pool of a different level according to the business importance of the tenant and the threat score K; An automatic migration submodule automatically migrates a tenant with low business importance and a high threat score to a resource pool of a "low" level during a business off-peak period, so as to protect the stability of the overall resource pool.

Citation Information

Patent Citations

  • A method and system for adaptive on-demand resource allocation in a virtualized environment

    CN102279771A

  • System and method for implementing distributed denial of service (DDoS) based on cloud computing identification and management with short messages

    CN103188226A