A method, device, electronic equipment and storage medium for scheduling attack traffic

By periodically iterating the division of communities in an autonomous system (AS) and limiting network traffic when abnormal traffic attacks are detected, the problem of traffic scheduling for DDoS attacks in AS is solved, enabling dynamic scheduling and adaptive management of network traffic, thereby improving network security and user service availability.

CN119172140BActive Publication Date: 2025-12-12CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411303297.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-18
Publication Date
2025-12-12
Estimated Expiration
2044-09-18

AI Technical Summary

Technical Problem

Network devices in autonomous systems are vulnerable to abnormal traffic attacks, especially distributed denial-of-service (DDoS) attacks, due to their low security performance. Existing technologies struggle to effectively manage network traffic to mitigate their impact.

Method used

During the normal operation of multiple nodes within an autonomous system network, network traffic information is periodically and iteratively divided to form multiple communities. When an abnormal traffic attack is detected, network traffic is restricted to the community where the target node is located. The community division is dynamically adjusted through the Leiden algorithm to optimize network traffic scheduling.

Benefits of technology

It effectively reduces the impact of abnormal traffic attacks on autonomous systems, enables dynamic scheduling and adaptive management of network traffic, and improves network security and user service availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119172140B_ABST
    Figure CN119172140B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, and in particular to a method and device for scheduling attack traffic, an electronic device and a storage medium. In the normal operation of multiple nodes in an autonomous domain network, the following setting operation is iteratively executed every first setting period: according to network traffic information transmitted between each two nodes with a current existing communication link, the multiple nodes are divided into multiple communities, each community includes at least one node, and each node is a device in the autonomous domain network; if it is determined that a target node in the autonomous domain network is subjected to abnormal traffic attack, the setting operation is performed to update the divided multiple communities to obtain newly divided multiple communities; a target community in which the target node is located is determined from the newly divided multiple communities, and network traffic of at least one node in the target community is limited. The application can effectively schedule network traffic when the autonomous domain network is subjected to attack, and reduce the influence of abnormal traffic attack on the autonomous domain network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a method and device for scheduling attack traffic, an electronic device and a storage medium. BACKGROUND

[0002] At present, network devices in an autonomous system (AS) network can be attacked by abnormal traffic of attackers due to low security performance. For example, Internet of Things (IoT) devices are weak in processing resources and memory resources, and manufacturers often focus on realizing the functions that the devices should have when manufacturing the IoT devices, and ignore the security properties of the devices, which makes the IoT devices vulnerable to abnormal traffic attacks.

[0003] The abnormal traffic attack is represented by a distributed denial of service (DDoS) attack, and attackers can easily control a large number of zombie hosts, use automated scripts, and launch attacks against many targets including IoT devices in the autonomous system network, so security protection measures against abnormal traffic attacks are imminent.

[0004] In related technologies, security protection measures against abnormal traffic attacks often focus on sharing and intercepting abnormal addresses, which are network addresses used to launch attacks, and cannot effectively schedule network traffic to reduce the impact of abnormal traffic attacks on the autonomous system network. SUMMARY

[0005] The embodiments of the present application provide a method and device for scheduling attack traffic, an electronic device and a storage medium, which are used to effectively schedule network traffic when the autonomous system network is attacked, so as to reduce the impact of abnormal traffic attacks on the autonomous system network.

[0006] In a first aspect, a method for scheduling attack traffic is provided, and the method comprises the following steps:

[0007] In the normal operation of the plurality of nodes in the autonomous system network, the following setting operation is iteratively executed every first setting period: according to the network traffic information transmitted between each two nodes having a communication link, the plurality of nodes are divided into a plurality of communities; each community includes at least one node, and each node is a device in the autonomous system network;

[0008] If it is determined that a target node in the autonomous system network is attacked by abnormal traffic, the setting operation is performed to update the plurality of divided communities, and a plurality of newly divided communities are obtained;

[0009] determining a target community in which the target node is located from the newly divided communities, and performing network traffic restriction on at least one node in the target community.

[0010] Optionally, the network traffic information comprises bandwidth occupancy, and the network traffic information transmitted between each two nodes having a communication link is obtained by:

[0011] detecting an amount of network data transmitted between each two nodes having a communication link in a set time period before the current time;

[0012] determining the bandwidth occupancy of the communication link between each two nodes according to the amount of network data transmitted between the two nodes and the maximum bandwidth of the communication link.

[0013] Optionally, the dividing the plurality of nodes into a plurality of communities according to the network traffic information transmitted between each two nodes having a communication link comprises:

[0014] determining a degree of each node according to the bandwidth occupancy of the communication link between each two nodes, the degree representing a sum of the bandwidth occupancy of the communication link between each node and other nodes;

[0015] obtaining a total bandwidth occupancy of all communication links between the plurality of nodes according to the bandwidth occupancy of the communication link between each two nodes;

[0016] dividing the plurality of nodes into a plurality of communities according to the bandwidth occupancy of the communication link between each two nodes, the degree of each node and the total bandwidth occupancy, and combining a set division method.

[0017] Optionally, the dividing the plurality of nodes into a plurality of communities according to the bandwidth occupancy of the communication link between each two nodes, the degree of each node and the total bandwidth occupancy, and combining a set division method comprises:

[0018] performing a set operation based on the bandwidth occupancy of the communication link between each two nodes, the degree of each node, the total bandwidth occupancy and an indicator function of each two nodes for the plurality of communities into which the plurality of nodes have been divided, to obtain a modularity, wherein the indicator function of two nodes is a first value when the two nodes are in the same community, and the indicator function of the two nodes is a second value when the two nodes are not in the same community, and the modularity represents a difference between a dense degree of connection within a community and a random connection;

[0019] repeatedly performing the following node moving operation until no node moving increases the modularity:

[0020] traversing each node, trying to move the node to a community where all the adjacent nodes are located, for each moving way, re-determining the modularity to obtain an updated modularity;

[0021] for each node, selecting a moving way from multiple moving ways which increases the updated modularity most, if the updated modularities corresponding to the multiple moving ways are not increased, abandoning to move the node.

[0022] Optionally, after the network traffic restriction on the at least one node in the target community, the method further comprises:

[0023] for the newly divided multiple communities, performing the setting operation iteratively every second setting period; wherein the second setting period is less than the first setting period.

[0024] if it is determined that the target community where the target node is located changes according to the newly divided multiple communities, performing the network traffic restriction on at least one node in the changed target community.

[0025] Optionally, the network traffic restriction on the at least one node in the target community comprises:

[0026] switching, according to a preset routing adjustment strategy, a routing path of the network traffic flowing through each node in the target community to a corresponding node in another community in the newly divided multiple communities.

[0027] Optionally, after the network traffic restriction on the at least one node in the target community, the method further comprises:

[0028] after processing the abnormal traffic attack on the target node, recovering the routing path of the at least one node in the target community and the routing path of the corresponding node in the other community according to a preset routing recovery strategy; and

[0029] recording attack information of the abnormal traffic attack on the target node; wherein the attack information comprises at least one of the following: node information of the target node, abnormal traffic information, attack type, attack duration, attack intensity.

[0030] In a second aspect, an embodiment of the present application provides a device for scheduling attack traffic, comprising:

[0031] The first dividing unit is configured to, in normal operation of a plurality of nodes in an autonomous domain network, perform the following setting operation iteratively every first setting period: dividing the plurality of nodes into a plurality of communities according to network traffic information transmitted between each two nodes having a communication link; wherein each community includes at least one node, and each node is a device in the autonomous domain network;

[0032] The second dividing unit is configured to, if it is determined that a target node in the autonomous domain network is subjected to abnormal traffic attack, perform the setting operation to update the plurality of divided communities to obtain a plurality of newly divided communities.

[0033] The scheduling unit is configured to determine a target community in which the target node is located from the plurality of newly divided communities, and perform network traffic limitation on at least one node in the target community.

[0034] Optionally, the network traffic information includes bandwidth occupancy, and the apparatus further includes a detection unit configured to:

[0035] detect an amount of network data transmitted between each two nodes having a communication link in the plurality of nodes within a set time length before the current time;

[0036] determine a bandwidth occupancy of the communication link between each two nodes according to the amount of network data transmitted between the two nodes and a maximum bandwidth of the communication link.

[0037] Optionally, the first dividing unit is specifically configured to:

[0038] determine a degree of each node according to the bandwidth occupancy of the communication link between each two nodes, the degree representing a sum of the bandwidth occupancies of the communication links between each node and other nodes;

[0039] obtain a total bandwidth occupancy of all communication links between the plurality of nodes according to the bandwidth occupancy of the communication link between each two nodes;

[0040] divide the plurality of nodes into a plurality of communities according to the bandwidth occupancy of the communication link between each two nodes, the degree of each node, and the total bandwidth occupancy, in combination with a set division method.

[0041] Optionally, when the plurality of nodes are divided into a plurality of communities according to the bandwidth occupancy of the communication link between each two nodes, the degree of each node, and the total bandwidth occupancy, in combination with a set division method, the first dividing unit is specifically configured to:

[0042] The modularity is obtained by performing a setting operation based on a bandwidth occupancy of a communication link between each two nodes, a degree of each node, the total bandwidth occupancy, and an indicator function of each two nodes; when the two nodes are in the same community, the indicator function of the two nodes is a first value, and when the two nodes are not in the same community, the indicator function of the two nodes is a second value, and the modularity represents a difference between a dense degree of connection within a community and a random connection;

[0043] The following node moving operation is repeatedly iteratively performed until no node moving increases the modularity:

[0044] Each node is traversed, and the node is attempted to be moved to a community in which all adjacent nodes are located, and for each moving manner, the modularity is re-determined to obtain an updated modularity;

[0045] For each node, a moving manner that increases the updated modularity most is selected from a plurality of moving manners, and if the updated modularity corresponding to the plurality of moving manners is not increased, the node is abandoned to be moved.

[0046] Optionally, the apparatus further comprises:

[0047] A third dividing unit is configured to perform the setting operation iteratively every second setting period for the newly divided plurality of communities; and the second setting period is less than the first setting period.

[0048] The scheduling unit is further configured to perform network flow limitation on at least one node in the changed target community if it is determined that the target community in which the target node is located changes according to the newly divided plurality of communities.

[0049] Optionally, the scheduling unit is specifically configured to:

[0050] According to a preset routing adjustment strategy, a routing path of network flow flowing through each node in the target community is switched to a corresponding node in another community in the newly divided plurality of communities.

[0051] Optionally, the apparatus further comprises:

[0052] A recovery unit is configured to, after processing the abnormal flow attack on the target node, perform recovery on a routing path of at least one node in the target community and a routing path of the corresponding node in the other community according to a preset routing recovery strategy.

[0053] A recording unit is configured to record attack information of an abnormal traffic attack on the target node; wherein the attack information comprises at least one of the following: node information of the target node, abnormal traffic information, attack type, attack duration, and attack intensity.

[0054] In a third aspect, an electronic device is provided, which includes a processor and a memory. The memory stores a computer program. When the computer program is executed by the processor, the processor performs the steps of any of the methods for scheduling attack traffic.

[0055] In a fourth aspect, a computer readable storage medium is provided, which includes a computer program. When the computer program is run on an electronic device, the computer program is configured to cause the electronic device to perform the steps of any of the methods for scheduling attack traffic.

[0056] In a fifth aspect, a computer program product is provided, which includes a computer program stored in a computer readable storage medium. When a processor of an electronic device reads the computer program from the computer readable storage medium, the processor executes the computer program, so that the electronic device performs the steps of any of the methods for scheduling attack traffic.

[0057] The above-mentioned solutions of the present application have at least the following beneficial effects:

[0058] The embodiments of the present application provide a method and apparatus for scheduling attack traffic, an electronic device and a storage medium. In the normal operation of a plurality of nodes in an autonomous domain network, the following operations are periodically and iteratively performed: dividing the plurality of nodes according to network traffic information transmitted between each two nodes having a communication link to obtain a plurality of communities; during the periodic and iterative performance of the above operations, if it is determined that a target node in the autonomous domain network is subjected to an abnormal traffic attack, the plurality of communities are re-divided immediately, even if the division time point has not been reached; a target community in which the target node is located is determined from the re-divided plurality of communities, and network traffic of at least one node in the target community is limited. In this way, the communication links between the nodes in the autonomous domain network are abstracted into an undirected graph, the plurality of nodes are dynamically and reasonably divided based on the network traffic information transmitted between the nodes, and then when the target node is subjected to an abnormal traffic attack, the network traffic of the community in which the target node is located is limited. Therefore, the embodiments of the present application can effectively schedule network traffic when the autonomous domain network is attacked, so as to reduce the influence of the abnormal traffic attack on the autonomous domain network.

[0059] Other features and advantages of the present application will be set forth in the description that follows, and in part will be apparent from the description, or can be learned by practice of the application. The purposes and other advantages of the present application will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings. BRIEF DESCRIPTION OF DRAWINGS

[0060] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and together with the description serve to explain the application. In the drawings:

[0061] Figure 1 A schematic diagram of a DDoS attack autonomous domain network in an embodiment of the present application;

[0062] Figure 2 A flow chart of a method for scheduling attack traffic in an embodiment of the present application;

[0063] Figure 3 A schematic diagram of bandwidth occupancy rate between nodes in an embodiment of the present application;

[0064] Figure 4 A schematic diagram of the overall logic of a method for scheduling attack traffic in an embodiment of the present application;

[0065] Figure 5 A schematic diagram of the overall logic of a method for scheduling attack traffic in an embodiment of the present application;

[0066] Figure 6 A schematic diagram of the overall logic of a method for scheduling attack traffic in an embodiment of the present application; DETAILED DESCRIPTION

[0067] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, rather than all the embodiments. Based on the embodiments described in the present application document, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0068] Some concepts involved in the embodiments of the present application will be introduced below.

[0069] DDoS (Distributed denial of service): Distributed denial of service attack refers to multiple attackers at different locations launching attacks on one or several targets at the same time, or an attacker controlling multiple machines at different locations and using these machines to attack the victim at the same time.

[0070] Autonomous domain: In the Internet, the combination of all Internet Protocol (IP) networks and routers under the jurisdiction of one or more entities that perform common routing policies on the Internet; where the entity can be an Internet service provider, an educational institution, a business, a government agency, etc.

[0071] Community detection algorithm: Community detection is a research field in graph theory, which aims to divide a network graph into multiple communities, so that nodes within the same community have more connections than nodes across communities.

[0072] Leiden algorithm: A community detection algorithm on large relationship networks. By calculating the relationship between nodes and edges in communities, the effectiveness of internal connections is ensured, and the separation of communities is achieved.

[0073] The design idea of the embodiments of the present application is briefly introduced as follows.

[0074] Currently, network devices in the autonomous domain network may be attacked by abnormal traffic due to low security performance. For example, Internet of Things devices are weak in terms of processing resources and memory resources, and manufacturers often focus on implementing the functions that the devices should have when manufacturing Internet of Things devices, ignoring the security properties of the devices, which makes the Internet of Things devices vulnerable to abnormal traffic attacks.

[0075] The above abnormal traffic attack is represented by a distributed denial of service (DDoS) attack, as shown in Figure 1 The attacker can easily control a large number of zombie hosts, use automated scripts, and launch attacks on many targets including Internet of Things devices within the autonomous domain network, so security measures against abnormal traffic attacks are imminent.

[0076] In the related art, the security protection measures against abnormal traffic attacks often focus on the sharing and interception of abnormal addresses, which are network addresses used to launch attacks. In terms of traffic scheduling, methods such as Border Gateway Protocol (BGP) route traction or Anycast are generally used. Anycast is a network technology that allows data packets to be sent to the nearest one of multiple destinations, but there are almost no adaptive dynamic adjustment traffic scheduling schemes. Therefore, when an autonomous domain network is attacked, network traffic cannot be effectively scheduled to reduce the impact of abnormal traffic attacks on the autonomous domain network.

[0077] Therefore, the embodiments of the present application provide a method and device for scheduling attack traffic, an electronic device and a storage medium. In the normal operation of the multiple nodes in the autonomous domain network, the following operations are periodically and iteratively performed: dividing the multiple nodes according to the network traffic information transmitted between each two nodes to obtain multiple communities; during the periodic and iterative performance of the above operations, if it is determined that a target node in the autonomous domain network is attacked by abnormal traffic, the multiple communities are divided again immediately to obtain newly divided multiple communities even if the division time point has not been reached; a target community in which the target node is located is determined from the newly divided multiple communities, and network traffic of at least one node in the target community is limited. In this way, the communication links between the nodes in the autonomous domain network are abstracted into an undirected graph, the multiple nodes are dynamically and reasonably divided based on the network traffic information transmitted between the nodes, and then when the target node is attacked by abnormal traffic, the network traffic of the community in which the target node is located is limited. Therefore, the embodiments of the present application can effectively schedule network traffic when the autonomous domain network is attacked to reduce the impact of abnormal traffic attacks on the autonomous domain network.

[0078] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application, and the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0079] Referring to Figure 2 As shown in FIG. 1, an implementation flowchart of a method for scheduling attack traffic is provided by the embodiments of the present application. The method can be performed by a network controller in an autonomous domain network. The network controller can be a device or a software platform for managing and controlling network devices (such as gateways, routers, etc.). That is, it can be a hardware device or software running on a server. The specific implementation process of the method includes the following S21-S23:

[0080] S21, in the normal operation of the plurality of nodes in the autonomous domain network, the following set operations are iteratively performed every first set period: according to the network traffic information transmitted between each two nodes of which a communication link currently exists, the plurality of nodes are divided into a plurality of communities, each community including at least one node, and each node being any device in the autonomous domain network.

[0081] Among them, the devices in the autonomous domain network include network devices such as routers, switches, and gateways, and also include terminal devices, servers, security devices, etc. Any device in the autonomous domain network is regarded as a node, and the nodes have communication links between them.

[0082] Considering that abnormal traffic attacks usually aim to paralyze the network by sending high-frequency burst attack traffic, according to the network traffic information transmitted between each two nodes of the plurality of nodes, the plurality of nodes are divided into a plurality of communities, and the network traffic information transmitted between each two nodes can reflect the tightness of the connection between the two nodes. Specifically, in order to reasonably divide the plurality of nodes into communities, a community detection algorithm such as the Leiden algorithm can be used to periodically and iteratively divide the plurality of nodes into communities, so that each node in each community has a high tightness.

[0083] In an optional implementation, the above network traffic information can include bandwidth occupancy, at which time the network traffic information transmitted between each two nodes of which a communication link currently exists can be obtained in the following way:

[0084] Detect the amount of network data transmitted between each two nodes of which a communication link exists in the plurality of nodes within a set time period before the current time; and determine the bandwidth occupancy of the communication link between each two nodes according to the amount of network data transmitted between each two nodes and the maximum bandwidth of the communication link.

[0085] Among them, the set time period can be set as needed. For two nodes of which a communication link exists, the amount of network data transmitted between the two nodes within the set time period divided by the maximum bandwidth of the communication link is equal to the bandwidth occupancy of the communication link between the two nodes, for example, as shown in the following formula (1):

[0086]

[0087] Among them, R ij is the amount of network data transmitted between node i and node j of which a communication link currently exists within the current first set period, and B ij is the maximum bandwidth of the communication link between node i and node j.

[0088] In the following example, the division process of the plurality of nodes is introduced taking the Leiden algorithm as an example of the community detection algorithm.

[0089] In an optional implementation, the process of dividing multiple nodes into multiple communities based on network traffic information transmitted between every two nodes with existing communication links in S21 may include the following steps A1-A3:

[0090] A1. Determine the degree of each node based on the bandwidth utilization of the communication link between every two nodes. The degree represents the sum of the bandwidth utilization of the communication links between each node and other nodes.

[0091] In this context, a node may have communication links with one or more other nodes. The degree of a node is equal to the sum of the bandwidth utilization rates of the communication links between that node and all other nodes. For example, for node R1, assuming that R1 has communication links with nodes R2 and R3, and the bandwidth utilization rate between R1 and R2 is 0.2, and the bandwidth utilization rate between R1 and R3 is 0.4, then the degree of node R1 is equal to 0.2 + 0.4 = 0.6. And so on, calculating the degree of each node.

[0092] A2. Based on the bandwidth utilization rate of the communication links between each pair of nodes, obtain the total bandwidth utilization rate of all communication links between multiple nodes.

[0093] This can be achieved by directly summing the bandwidth utilization of all communication links between multiple nodes to obtain the total bandwidth utilization of all communication links between multiple nodes. For example, such as... Figure 3 As shown, multiple nodes include: R1, R2, R3, R4, R5, and R6. The bandwidth occupancy rate between R1 and R2 is 0.2, between R1 and R3 is 0.4, between R2 and R4 is 0.5, between R3 and R4 is 0.8, between R3 and R5 is 0.1, between R5 and R6 is 0.1, and between R4 and R6 is 0.3. Therefore, the total bandwidth occupancy rate of all communication links = 0.2 + 0.4 + 0.5 + 0.8 + 0.1 + 0.1 + 0.3 = 2.4.

[0094] A3. Based on the bandwidth utilization of the communication link between every two nodes, the degree of each node, and the total bandwidth utilization, and combined with the set partitioning method, multiple nodes are divided into multiple communities.

[0095] Specifically, the partitioning method can be implemented based on the Leiden algorithm. The partitioning method is described below.

[0096] In an optional implementation, step A3 above may include the following steps a1-a2:

[0097] a1, for a plurality of communities divided for a plurality of nodes, based on bandwidth occupancy of a communication link between each two nodes, degree of each node, total bandwidth occupancy and an indicator function of each two nodes, a setting operation is performed to obtain a modularity; wherein the indicator function of two nodes is a first value when the two nodes are in the same community, and the indicator function of two nodes is a second value when the two nodes are not in the same community, and the modularity represents the difference between the dense degree of connection within the community and the random connection.

[0098] Wherein, when the plurality of nodes are divided for the first time, it can be assumed that each node is a separate community, i.e. the plurality of divided communities each contain one node.

[0099] The above setting operation can be set as needed, and the first value and the second value can also be set as needed, for example, the first value is 1 and the second value is 0. Exemplarily, the setting budget is shown in the following formula (2):

[0100]

[0101] Wherein, A ij represents the bandwidth occupancy of the communication link between any two nodes i and j, ki and kj represent the degrees of any two nodes i and j, and m represents the total bandwidth occupancy of all communication links between the plurality of nodes. δ(c i , c j ) is the indicator function of two nodes, which is 1 when the nodes i and j are in the same community, and 0 otherwise, Q represents the modularity, which is usually a value between -1 and 1, representing the difference between the dense degree of connection within the community and the random connection.

[0102] a2, repeat the following node moving operations a21-a22 iteratively until no node moving increases the modularity:

[0103] a21, traverse each node, try to move the node to the community where all adjacent nodes are located, for each moving way, re-determine the modularity to obtain an updated modularity.

[0104] Wherein, the adjacent nodes of each node refer to the nodes connected to the node, i.e. there is a communication link between each node and the adjacent node. For each node, when trying to move the node to the community where an adjacent node is located, the indicator function of the node and the adjacent node changes, and the modularity can be re-determined by using the above formula (2).

[0105] a22, for each node, select the moving way from a plurality of moving ways that increases the updated modularity the most, if the updated modularity corresponding to the plurality of moving ways is not increased, then give up moving the node.

[0106] In the embodiments of the present application, based on the Leiden algorithm, the bandwidth occupancy of the communication links between the multiple nodes in the autonomous domain network is considered, and the multiple nodes are reasonably divided, so that the connection density in each divided community is high.

[0107] S22, if it is determined that the target node in the autonomous domain network is attacked by abnormal traffic, performing a setting operation to update the multiple divided communities to obtain multiple newly divided communities.

[0108] Specifically, in the periodic iteration of the above setting operation, in each first setting period, it can be judged whether the autonomous domain network is attacked by abnormal traffic. If it is determined that the target node in the autonomous domain network is attacked by abnormal traffic, the above setting operation will be performed immediately regardless of whether the periodic execution time point is reached, so as to update the multiple divided communities according to the network traffic information transmitted between each two nodes in the current network.

[0109] S23, determining a target community in which the target node is located from the multiple newly divided communities, and limiting network traffic of at least one node in the target community.

[0110] Among them, the network traffic required to be transmitted by the at least one node in the target community can be transferred to the nodes in other communities, and the subsequent network traffic sent to the at least one node in the target community is limited, so as to realize network traffic redirection, isolation and flow limiting measures to reduce the impact of traffic attack.

[0111] It should be noted that the target node attacked by abnormal traffic can be one node or multiple nodes. When there are multiple nodes, network traffic limitation can be performed on the target communities corresponding to the multiple nodes respectively. Moreover, during the network traffic limitation of the at least one node in the target community, it can be detected that other nodes are also attacked by abnormal traffic, at which time the above S22-S23 can be repeatedly performed.

[0112] In an optional implementation, when limiting the network traffic of the at least one node in the target community, the routing path of the network traffic flowing through each node in the target community can be switched to the corresponding node in other communities in the multiple newly divided communities according to a preset routing adjustment strategy.

[0113] Among them, the preset routing adjustment strategy can be set according to actual conditions. For example, when the node R1 is attacked by abnormal traffic, the routing paths of R1 and the nodes R2 and R3 belonging to the same community as R1 will be switched, and can be switched to the nodes R4, R5 and R6 in another community.

[0114] In the embodiments of the present application, in the normal operation of the plurality of nodes in the autonomous domain network, the plurality of nodes are periodically divided according to the network traffic information transmitted between each two nodes, and a plurality of communities are obtained each time; when it is detected that the target node in the autonomous domain network is subjected to abnormal traffic attack, even if the division time point has not been reached, the plurality of communities are divided again immediately, and a plurality of newly divided communities are obtained; the target community in which the target node is located is determined from the plurality of newly divided communities, and the network traffic of at least one node in the target community is limited. In this way, the communication link between the nodes in the autonomous domain network is abstracted into an undirected graph, the plurality of nodes are dynamically and reasonably divided based on the network traffic information transmitted between the nodes, and then when the target node is subjected to abnormal traffic attack, the network traffic of the community in which the target node is located is limited. Therefore, the embodiments of the present application can effectively schedule the network traffic when the autonomous domain network is attacked, so as to reduce the influence of abnormal traffic attack on the autonomous domain network.

[0115] In some embodiments, after the network traffic of at least one node in the target community is limited, the set operation can be iteratively performed every second set period for the plurality of newly divided communities, and the second set period is less than the first set period; if it is determined that the target community in which the target node is located changes according to the plurality of newly divided communities, the network traffic of at least one node in the changed target community is limited.

[0116] In some embodiments, after the network traffic of at least one node in the target community is limited, the set operation can be iteratively performed every second set period for the plurality of newly divided communities, and the second set period is less than the first set period; if it is determined that the target community in which the target node is located changes according to the plurality of newly divided communities, the network traffic of at least one node in the changed target community is limited.

[0117] In some embodiments, after the network traffic of at least one node in the target community is limited, the set operation can be iteratively performed every second set period for the plurality of newly divided communities, and the second set period is less than the first set period; if it is determined that the target community in which the target node is located changes according to the plurality of newly divided communities, the network traffic of at least one node in the changed target community is limited.

[0118] In some embodiments, after the network traffic of at least one node in the target community is limited, the set operation can be iteratively performed every second set period for the plurality of newly divided communities, and the second set period is less than the first set period; if it is determined that the target community in which the target node is located changes according to the plurality of newly divided communities, the network traffic of at least one node in the changed target community is limited. In some embodiments, after the network traffic of at least one node in the target community is limited, the set operation can be iteratively performed every second set period for the plurality of newly divided communities, and the second set period is less than the first set period; if it is determined that the target community in which the target node is located changes according to the plurality of newly divided communities, the network traffic of at least one node in the changed target community is limited.

[0119] More specifically, when the initial state is the routing path at initialization, different time periods can correspond to different initial states. These different time periods can be different times of the day or different times within a set time period; there are no restrictions on this. After handling the abnormal traffic attack on the target node, the routing path of at least one node in the target community is restored to the initial state corresponding to the current time period. At the same time, the routing paths of other affected communities are also restored to their initial states.

[0120] Optionally, when the target community contains multiple nodes, the routing paths of the multiple nodes in the target community are restored sequentially according to their recovery priorities. The recovery priority of each node can be determined based on the node type or the type of business it performs. For example, if a node is a core node or performs a core business, it can be given a higher recovery priority to prioritize the restoration of the normal operation of the core node or the core business.

[0121] Furthermore, it can also record attack information of abnormal traffic attacks suffered by the target node; wherein, the attack information includes at least one of the following: node information of the target node, abnormal traffic information, attack type, attack duration, and attack intensity.

[0122] Specifically, abnormal traffic information can include the distribution characteristics of abnormal traffic. By recording the attack information of this abnormal traffic attack, we can analyze the attack patterns and characteristics, facilitating the improvement of pre-set defense strategies and thus reducing the impact of abnormal traffic attacks on the autonomous system network.

[0123] The following is combined Figure 4 The overall logic of the method for scheduling attack traffic according to embodiments of this application will be described by way of example.

[0124] like Figure 4 As shown, taking an abnormal traffic attack as a DDoS attack and using the Leiden algorithm for community partitioning as an example, the method for scheduling attack traffic in this embodiment of the application includes the following steps:

[0125] S401: Detect the network status of an autonomous system network.

[0126] Specifically, the system detects each communication link within the autonomous system network and periodically samples the network data volume on each communication link.

[0127] S402: Determine key values ​​based on network conditions to obtain the adjacency matrix.

[0128] Specifically, based on the network data volume and maximum bandwidth of each communication link, the bandwidth utilization rate of the communication link between each two nodes is calculated to obtain key values ​​and form an adjacency matrix.

[0129] wherein the adjacency matrix can be represented as A ij , A ij represents the bandwidth occupancy of the communication link between any two nodes i and j.

[0130] S403: iteratively performing the Leiden algorithm according to the set fixed period to update the community division in the autonomous domain network.

[0131] wherein the fixed period is the first set period in the above embodiment. The calculation formula of the Leiden algorithm is formula (2) in the above embodiment, i.e., based on the adjacency matrix A ij , the total bandwidth occupancy m of all communication links between the plurality of nodes, the degrees ki and kj of any two nodes i and j, and the indicator function δ(c i , c j ), the module degree Q is calculated.

[0132] Suppose the adjacency matrix A ij obtained by S402 is as follows:

[0133]

[0134] i.e., A 12 = A 21 = 0.2, A 13 = A 31 = 0.4, A 24 = A 42 = 0.5, A 34 = A 43 = 0.8, A 35 = A 53 = 0.1, A 56 = A 65 = 0.1, A 46 = A 64 = 0.3.

[0135] Based on this, the degree of each node can be obtained, as follows:

[0136] k1 = A 12 + A 13 = 0.2 + 0.4 = 0.6 (4)

[0137] k2 = A 21 + A 24 = 0.2 + 0.5 = 0.8 (5)

[0138] k3 = A 31 + A 34 + A 35 = 0.4 + 0.8 + 0.1 = 1.3 (6)

[0139] k4 = A 42 + A 43 + A 46 = 0.5 + 0.8 + 0.3 = 1.6 (7)

[0140] k5 = A 53 + A 56 = 0.1 + 0.1 = 0.2 (8)

[0141] k6 = A 64 + A 65 = 0.3 + 0.1 = 0.4 (9)

[0142] The total bandwidth occupancy rate m of all communication links between the plurality of nodes can be calculated by the following formula (10):

[0143]

[0144] In addition, the bandwidth occupancy rates of all communication links between the plurality of nodes can be directly summed to obtain m.

[0145] If it is the first time to perform community division on the plurality of nodes, δ(c i ,c j ) is 0 for any two nodes i and j. If the community division has been performed on the plurality of nodes, the specific value of δ(c i ,c j ) can be obtained according to the relationship between the communities where the two nodes i and j are located, that is, if the nodes i and j are in the same community, δ(c i ,c j ) is 1, otherwise, δ(c i ,c j ) is 0.

[0146] For each node, the node is tried to be moved to the community where all adjacent nodes are located, and then for each possible moving method thus generated, the Q value is recalculated, and the moving method that can increase the Q value the most is selected, and if no moving method can increase the Q value, the node is not moved. The above process is repeated until no moving method can increase the Q value.

[0147] S404: determining whether a DDoS attack occurs, if not, returning to S401, if yes, continuing to perform S405.

[0148] Specifically, the DDoS attack detection result is obtained from other functional units (such as a detection unit) to determine whether a DDoS attack occurs.

[0149] S405: immediately performing the Leiden algorithm to update the community division in the autonomous domain network.

[0150] S406: According to the updated community division result, the routing strategy of the autonomous domain network is adjusted.

[0151] Specifically, the target community under attack is determined, and the routing path of the network traffic flowing through each node in the target community is switched to the corresponding node in other communities according to the preset routing adjustment strategy.

[0152] Suppose the community division result is community A: R1, R2, community B: R3, R4, and community C: R5, R6, if R4 is currently under DDoS attack, the community B where node R4 is located is isolated from traffic. First, reduce the abnormal traffic flowing to R4, since R4 and R3 are in the same community, if community B is immediately isolated, it may cause network interruption, therefore, the abnormal traffic flowing to R4 is filtered and redirected to node R3 as much as possible, which can disperse abnormal traffic so that R4 is not overloaded. Then, the routing strategies of community A, community C, and community B are adjusted, and the network traffic passing through community B is transferred to community A and community C, and if network traffic must be sent to the community, it is preferentially sent through R3 rather than directly to R4.

[0153] S407: The routing strategy of the autonomous domain network is restored, and the attack information of this DDoS attack is recorded.

[0154] Among them, the routing path of each node in the target community and the routing path of the corresponding node in other communities can be restored according to the preset recovery strategy. The preset routing recovery strategy can be set according to specific circumstances, for example, the routing path of each node in the target community is restored to the initial state, and the routing path of other communities is also restored to the initial state. By recording the attack information of this DDoS attack, preparation can be made for subsequent attack defense strategy update.

[0155] The method for scheduling attack traffic provided by the embodiments of the present application can cope with abnormal traffic attacks (such as DDoS attacks) in the existing Internet, so that the defense party can dynamically, adaptively, and more finely schedule abnormal traffic and normal traffic. Specifically, by using the network traffic information detected by the embodiments of the present application, the community division result is periodically updated by using the Leiden algorithm, the target community under abnormal traffic attack is automatically redirected, isolated, and limited according to the updated community division result, the harm and influence of abnormal traffic attack are reduced, time is saved for subsequent defense, and the service availability of users is ensured; and after the autonomous domain network responds to the abnormal traffic attack in a timely manner, the routing is quickly recovered according to the preset routing recovery strategy, and the attack information is recorded in a timely manner, so as to prepare for subsequent attack defense strategy update, and improve the integrity and robustness of the present application.

[0156] Based on the same inventive concept, this application also provides a device for scheduling attack traffic. The principle of this device in solving the problem is similar to the method in the above embodiments. Therefore, the implementation of this device can refer to the implementation of the above method, and the repeated parts will not be described again.

[0157] like Figure 5 As shown, this is a schematic diagram of the structure of a device 500 for scheduling attack traffic, which may include:

[0158] The first partitioning unit 501 is used to iteratively execute the following setting operation every first set period during the normal operation of multiple nodes in the autonomous system network: divide the multiple nodes into multiple communities according to the network traffic information transmitted between every two nodes with existing communication links; wherein each community includes at least one node, and each node is any device in the autonomous system network.

[0159] The second partitioning unit 502 is used to perform a set operation to update the multiple partitioned communities and obtain the newly partitioned communities if it is determined that the target node in the autonomous system network is under abnormal traffic attack.

[0160] The scheduling unit 503 is used to determine the target community where the target node is located from the newly divided multiple communities, and to impose network traffic restrictions on at least one node in the target community.

[0161] Optionally, network traffic information includes bandwidth utilization, and the device also includes a detection unit for:

[0162] The amount of network data transmitted between any two nodes that have a communication link within a set time period prior to the current moment is detected.

[0163] The bandwidth utilization rate of the communication link between each pair of nodes is determined based on the amount of network data transmitted between each pair of nodes and the maximum bandwidth of the communication link.

[0164] Optionally, the first partitioning unit 501 is specifically used for:

[0165] The degree of each node is determined based on the bandwidth utilization of the communication link between every two nodes. The degree represents the sum of the bandwidth utilization of the communication links between each node and other nodes.

[0166] Based on the bandwidth utilization of the communication links between each pair of nodes, the total bandwidth utilization of all communication links between multiple nodes is obtained.

[0167] Based on the bandwidth utilization of the communication link between every two nodes, the degree of each node, and the total bandwidth utilization, and combined with the set partitioning method, multiple nodes are divided into multiple communities.

[0168] Optionally, the first division unit 501 is configured to divide the plurality of nodes into a plurality of communities according to the bandwidth occupancy of the communication link between each two nodes, the degree of each node, and the total bandwidth occupancy, in combination with a preset division method.

[0169] The modularity is obtained by performing a preset operation based on the bandwidth occupancy of the communication link between each two nodes, the degree of each node, the total bandwidth occupancy, and an indicator function of each two nodes, for the plurality of communities into which the plurality of nodes are divided; when the two nodes are in the same community, the indicator function of the two nodes is a first value, and when the two nodes are not in the same community, the indicator function of the two nodes is a second value, and the modularity represents the difference between the intensive degree of connection within the community and random connection.

[0170] The following node moving operation is repeatedly iteratively performed until no node moving increases the modularity:

[0171] Each node is traversed, and the node is attempted to be moved to the community in which all adjacent nodes are located, and for each moving manner, the modularity is re-determined to obtain an updated modularity.

[0172] For each node, a moving manner that increases the updated modularity the most is selected from a plurality of moving manners, and if the updated modularity corresponding to the plurality of moving manners is not increased, the node is abandoned.

[0173] Optionally, the apparatus further comprises:

[0174] The third division unit is configured to, for the newly divided plurality of communities, iteratively perform the preset operation every second preset period; and the second preset period is less than the first preset period.

[0175] The scheduling unit is further configured to, if it is determined that the target community in which the target node is located changes according to the newly divided plurality of communities, perform network flow restriction on at least one node in the changed target community.

[0176] Optionally, the scheduling unit 503 is configured to:

[0177] According to a preset routing adjustment strategy, the routing path of the network flow flowing through each node in the target community is switched to a corresponding node in another community in the newly divided plurality of communities.

[0178] Optionally, the apparatus further comprises:

[0179] The recovery unit is configured to, after processing the abnormal flow attack on the target node, perform recovery on the routing path of at least one node in the target community and the routing path of the corresponding node in the other community according to a preset routing recovery strategy.

[0180] A recording unit is configured to record attack information of an abnormal traffic attack on the target node, wherein the attack information comprises at least one of the following: node information of the target node, abnormal traffic information, attack type, attack duration, and attack intensity.

[0181] For the convenience of description, the above parts are divided into modules (or units) according to functions and are described respectively. Of course, the functions of the modules (or units) can be implemented in one or more software or hardware in the implementation of the present application.

[0182] After introducing the method and device for scheduling attack traffic according to the exemplary embodiments of the present application, next, an electronic device according to another exemplary embodiment of the present application is introduced.

[0183] Based on the same inventive concept as the above method embodiments, an electronic device is further provided in the embodiments of the present application. In an embodiment, the electronic device can be a server or a terminal device. In the embodiment, the structure of the electronic device can be as shown in Figure 6 The electronic device can include a memory 601, a communication module 603, and one or more processors 602.

[0184] The memory 601 is configured to store computer programs executed by the processor 602. The memory 601 can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system and programs required for running instant messaging functions, etc.; and the data storage area can store various instant messaging information and operation instruction sets, etc.

[0185] The memory 601 can be a volatile memory, such as a random-access memory (RAM); the memory 601 can also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD); or the memory 601 can be any other medium capable of carrying or storing desired computer programs in the form of instructions or data structures and capable of being accessed by a computer, but is not limited to this. The memory 601 can be a combination of the above memories.

[0186] The processor 602 can include one or more central processing units (CPUs) or digital processing units, etc. The processor 602 is configured to implement the above method for scheduling attack traffic when invoking the computer programs stored in the memory 601.

[0187] The communication module 603 is used to communicate with terminal devices and other servers.

[0188] This application embodiment does not limit the specific connection medium between the memory 601, communication module 603, and processor 602 described above. This application embodiment... Figure 6 The memory 601 and the processor 602 are connected via a bus 604, and the bus 604 is in Figure 6 The diagram uses thick lines to describe the connections between other components; these are for illustrative purposes only and should not be considered limiting. The 604 bus can be divided into address bus, data bus, control bus, etc. For ease of description, Figure 6 It is described using only a thick line, but does not indicate that there is only one bus or one type of bus.

[0189] This application provides a computer-readable storage medium storing a computer program. When the computer program is run on an electronic device, it causes the electronic device to execute the method for scheduling attack traffic described in the above embodiments, such as... Figure 2 As shown.

[0190] The computer-readable storage medium in the above embodiments can be any available medium or data storage device that can be accessed by the processor in the device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND FLASH), solid-state drives (SSDs), etc.

[0191] In some possible implementations, various aspects of the method for scheduling attack traffic provided in the embodiments of this application can also be implemented in the form of a program product, which includes a computer program. When the program product is run on an electronic device, the computer program causes the electronic device to perform the steps in the method for scheduling attack traffic according to the various exemplary embodiments of this application described above. For example, the electronic device can perform actions such as... Figure 2 The steps are shown in the figure.

[0192] The program product can employ any combination of one or more computer-readable media. The computer-readable media can be a computer-readable storage medium or a computer-readable signal medium. The computer-readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0193] The program product of the embodiments of the present application can employ a compact disc read-only memory (CD-ROM) and include a computer program and can be executed on an electronic device. However, the program product of the present application is not limited thereto, and in the present document, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with a command execution system, apparatus, or device.

[0194] The computer-readable signal medium can include a computer-readable storage medium that is configured to store and deliver a computer program, and a computer-readable transmission medium that is configured to carry a computer program. The computer-readable transmission medium can be any computer-readable medium that is not a storage medium and that can communicate, propagate or transport a program for use by or in connection with a command execution system, apparatus, or device.

[0195] The computer program contained in the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, and the like, or any suitable combination thereof.

[0196] The computer program for performing the operations of the present application can be written in any combination of one or more programming languages, including an object-oriented programming language such as Java, C++, and the like, and a conventional procedural programming language such as the "C" programming language or similar programming languages. The computer program can be executed entirely on the user's electronic device, partially on the user's electronic device, as a separate software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In the case of a remote electronic device, the remote electronic device can be connected to the user's electronic device through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external electronic device (for example, by connecting to the Internet using an Internet service provider).

[0197] It should be noted that while several units or sub-units of the apparatus are mentioned in the above detailed description, such division is merely exemplary and not mandatory. Indeed, according to an embodiment of the application, features and functionalities of two or more units described above can be embodied in one unit. Conversely, features and functionalities of one unit described above can be further divided into units embodied by several units.

[0198] Moreover, while operations of the methods of the present application are described in a particular order in the figures, this is not required or implied in any manner, nor is it required that all of the illustrated operations be performed to achieve desirable results. Additionally or alternatively, certain steps can be omitted, combined into fewer steps, and / or separated into additional steps.

[0199] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer program instructions.

[0200] The present application is described with reference to the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program commands. These computer program commands can be provided to a processor of a general purpose computer, a special purpose computer, an embedded processor or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products.

[0201] These computer program commands can also be stored in a computer- readable storage medium that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instructions which implement the functions specified in the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams of the methods, apparatus (systems) and computer program products.

[0202] These computer program instructions can also be loaded into computer or other programmable data processing devices, so that a series of operations steps are performed on the computer or other programmable devices to generate computer-implemented processes, so that the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in the flowchart Figure 1 one or more flows and / or blocks Figure 1 one or more blocks or steps of the functions specified in the flowchart

[0203] Although preferred embodiments of the application have been described, those skilled in the art will recognize that additional modifications and variations can be made thereto without departing from the spirit and scope of the application. It is therefore intended that the appended claims cover all such modifications and variations as fall within the scope of the application.

[0204] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore intended that the application be covered within the scope of the claims, and that the application be interpreted no more restrictively than is required by the patent laws and regulations.

Claims

1. A method of scheduling attack traffic, the method comprising: The method comprises the following steps: In the normal operation of a plurality of nodes in an autonomous domain network, the following setting operation is iteratively performed every first setting period: according to the network traffic information transmitted between each two nodes having a communication link, the plurality of nodes are divided into a plurality of communities, each community comprising at least one node, each node being a device in the autonomous domain network; If it is determined that a target node in the autonomous domain network is subjected to an abnormal traffic attack, the setting operation is performed to update the plurality of divided communities to obtain a plurality of newly divided communities; A target community in which the target node is located is determined from the plurality of newly divided communities, and network traffic of at least one node in the target community is limited; When the network traffic information comprises bandwidth occupancy, the setting operation comprises the following steps: For the plurality of communities in which the plurality of nodes are divided, a setting operation is performed based on the bandwidth occupancy of the communication link between each two nodes, the degree of each node, the total bandwidth occupancy of all communication links between the plurality of nodes, and an indicator function of each two nodes to obtain a modularity, wherein the degree represents the sum of the bandwidth occupancy of the communication link between each node and other nodes, the indicator function of two nodes is a first value when the two nodes are in the same community, and the indicator function of the two nodes is a second value when the two nodes are not in the same community, and the modularity represents the difference between the connection density in the community and the random connection; The following node movement operation is iteratively performed repeatedly until no node movement increases the modularity: Each node is traversed, and the node is attempted to be moved to the community in which all adjacent nodes are located, and for each movement mode, the modularity is re-determined to obtain an updated modularity; For each node, a movement mode that increases the updated modularity the most is selected from a plurality of movement modes, and if the updated modularity corresponding to the plurality of movement modes is not increased, the node is abandoned.

2. The method of claim 1, wherein, The bandwidth occupancy transmitted between each two nodes having a communication link at the current time is obtained by the following method: The network data amount transmitted between each two nodes having a communication link in the plurality of nodes within a set time period before the current time is detected; According to the network data amount transmitted between each two nodes and the maximum bandwidth of the communication link, the bandwidth occupancy of the communication link between each two nodes is determined.

3. The method of claim 1, wherein, After the network traffic of at least one node in the target community is limited, the following steps are further included: For the plurality of newly divided communities, the setting operation is iteratively performed every second setting period; wherein the second setting period is less than the first setting period; If it is determined that the target community in which the target node is located changes according to the plurality of newly divided communities, network traffic of at least one node in the changed target community is limited.

4. The method according to any one of claims 1 to 3, characterized in that, The network traffic of at least one node in the target community is limited by the following steps: According to a preset routing adjustment strategy, the routing path of the network traffic flowing through each node in the target community is switched to the corresponding node in other communities in the plurality of newly divided communities.

5. The method of claim 4, wherein, The network traffic restriction on the at least one node in the target community further comprises: After processing the abnormal traffic attack on the target node, the routing paths of the at least one node in the target community and the corresponding nodes in the other communities are recovered according to a preset routing recovery strategy; and Attack information of the abnormal traffic attack on the target node is recorded; wherein the attack information comprises at least one of the following: node information of the target node, abnormal traffic information, attack type, attack duration, and attack intensity.

6. An apparatus for scheduling attack traffic, the apparatus comprising: Comprise: The first division unit is configured to, in normal operation of a plurality of nodes in an autonomous domain network, perform the following setting operation iteratively every first set period: divide the plurality of nodes into a plurality of communities according to network traffic information transmitted between each two nodes that currently exist a communication link; wherein each community comprises at least one node, and each node is a device in the autonomous domain network; The second division unit is configured to, if it is determined that a target node in the autonomous domain network is subjected to an abnormal traffic attack, perform the setting operation to update the plurality of communities that have been divided, to obtain a plurality of newly divided communities; The scheduling unit is configured to determine a target community in which the target node is located from the plurality of newly divided communities, and perform network traffic restriction on at least one node in the target community; When the network traffic information comprises bandwidth occupancy, the setting operation comprises: For the plurality of communities in which the plurality of nodes have been divided, a setting operation is performed based on bandwidth occupancy of a communication link between each two nodes, a degree of each node, total bandwidth occupancy of all communication links between the plurality of nodes, and an indicator function of each two nodes, to obtain a modularity; wherein the degree represents a sum of bandwidth occupancies of communication links between each node and other nodes, the indicator function of two nodes is a first value when the two nodes are in the same community, and the indicator function of the two nodes is a second value when the two nodes are not in the same community, and the modularity represents a difference between a connection density in a community and random connection; The following node movement operation is iteratively performed repeatedly until no node movement increases the modularity: Each node is traversed, and the node is attempted to be moved to a community in which all adjacent nodes are located, and for each movement manner, the modularity is re-determined to obtain an updated modularity; For each node, a movement manner that increases the updated modularity most is selected from a plurality of movement manners, and if the updated modularity corresponding to the plurality of movement manners is not increased, the node is abandoned to be moved.

7. An electronic device, comprising: It comprises a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the method in any one of claims 1-5.

8. A computer-readable storage medium, characterized in that, It comprises a computer program, and when the computer program runs on an electronic device, the computer program is used to make the electronic device execute the steps of the method in any one of claims 1-5.

Citation Information

Patent Citations

  • Portrayal analysis method and device for honeypot attacker

    CN114398633A

  • Fast regional multiplexing method for multipoint asynchronous attack

    CN118074952A