A method for deploying a DDoS defense strategy of a cloud-native system
By abstracting traditional DDoS protection functions into virtualized components and flexibly deploying them in cloud-native systems, the problem of on-demand deployment of DDoS protection strategies in cloud-native systems is solved, achieving low cost, high compatibility and flexibility, and adapting to user needs and changes in network environment.
Patent Information
- Application Number
- CN202411190527.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-28
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-08-28
AI Technical Summary
In cloud-native systems, existing technologies struggle to deploy anti-DDoS strategies at any time and place according to user needs, and are incompatible with the current network environment, resulting in high deployment costs and insufficient flexibility.
By abstracting traditional DDoS protection functions into virtualized components, the cloud-native system's control center analyzes user needs and network status to generate DDoS protection strategies, which are then flexibly deployed in the physical network in the form of containers. Combined with real-time monitoring and optimization, this enables on-demand deployment and compatibility.
It enables on-demand deployment of anti-DDoS policies in cloud-native systems, reducing deployment costs, improving flexibility and compatibility, and dynamically adjusting policies based on network conditions and attack predictions to ensure policy effectiveness.
Smart Images

Figure CN119210779B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and more particularly to a DDoS resistance strategy deployment method for a cloud native system. BACKGROUND
[0002] DDoS attack is one of the most important attack means in current network attacks, which evolved from DoS attack. The characteristic of DDoS attack is that it can quickly exhaust the resources of the target system through a large number of requests, resulting in the inability to provide normal services. This attack method may cause serious economic and reputation losses to enterprises, organizations or individuals.
[0003] With the popularity of the Internet and the increase of various device connections, the scale and frequency of DDoS attacks are also growing, bringing greater challenges to network security.
[0004] Cloud network convergence refers to the combination of cloud computing and communication network, which fully utilizes the advantages of cloud computer and network. Cloud computing can dynamically adjust resources according to demand, and network side realizes fast data transmission and wider coverage, with high flexibility and elasticity. Cloud network convergence develops super computing power to user end, realizes cloud edge convergence, realizes full network coverage through central cloud and edge cloud, and maximizes cloud network capability.
[0005] Cloud native aims to utilize cloud computing, containerization and microservices, etc. to build high flexibility and easy-to-manage application programs, and fully utilize the potential of cloud computing. Cloud native can deploy application programs according to demand, and application programs can be flexibly combined and linked for automatic management, realizing flexible deployment of network functions and improving response speed and efficiency of application programs.
[0006] Cloud network convergence provides flexible and sufficient basic conditions for various cloud native businesses. On the basis of cloud native, with the concept of software, traditional D is abstracted into ability, breaking through the constraints of existing network structure, realizing flexible combination and linkage of system functions, and possessing new features such as deployment, arrangement, expansion and update, etc. to solve the problems of rigid deployment and high cost of traditional hardware.
[0007] Flexible deployment refers to the deployment of services or applications at any time and any place according to user demand, configuration environment, etc. in computer system and network, and dynamic adjustment of services or applications according to actual situation, including adjustment of configuration parameters, change of deployment location, increase or decrease of resources, etc. so that services or applications can adapt to different environments and scenarios, including different hardware platforms, operating systems, network environments, etc.
[0008] The traditional anti-D method needs to deploy corresponding hardware devices and software functions in the physical network, resulting in that the traditional anti-D system lacks flexibility and elasticity, and further extends the problems of being unable to deploy on demand, anti-D strategies being difficult to be compatible with each other, and high deployment cost. At present, there is a technology that can abstract all anti-D functions into capabilities, which can break through the constraints of the existing network structure; however, how to deploy the anti-D strategy at any time and any place in the cloud native system according to the user demand, and be compatible with the current network environment is a problem to be solved. SUMMARY
[0009] In order to overcome the defects and deficiencies existing in the prior art, the application provides an anti-DDoS strategy deployment method of a cloud native system, and the application aims to, based on the existing anti-D strategy abstracted as a capability, deploy the anti-D strategy at any time and any place in the cloud native system according to the user demand, so as to reduce the deployment cost and make it compatible with the current network environment.
[0010] In order to solve the problems existing in the prior art, the application is realized by the following technical scheme.
[0011] The application provides an anti-DDoS strategy deployment method of a cloud native system, which comprises the following steps:
[0012] S1, a user of the cloud native system sends an anti-D strategy demand to a control center of the cloud native system, and the control center analyzes the anti-D strategy demand of the user; specifically,
[0013] The control center determines the key attributes of the user demand from the anti-D strategy demand of the user, and then evaluates the risk of the user demand;
[0014] S2, according to the analysis result of the anti-D strategy demand of the user in step S1, the control center generates an anti-D strategy, and the control center deploys the anti-D strategy to the cloud native system used by the user;
[0015] The anti-D strategy is realized by the control center through the analysis of the user demand, the perception of the current network state of the cloud native system, and the prediction of future attacks, abstracting the capabilities and combining the linkages in a set order to form a service chain and then deploying the service chain to the cloud native system;
[0016] The capability refers to a virtualized component abstracted from a traditional anti-D function; the traditional anti-D function is decoupled from the hardware, the network function is realized in a virtualized environment through network programming, a management and orchestration system is used to configure, manage and optimize the virtual network function, and the deployment is performed in any position of the physical network in the cloud native system in the form of a container.
[0017] Further preferably, the method further comprises a real-time monitoring step after the anti-DDoS strategy is deployed, that is, after the anti-DDoS strategy is deployed, the control center receives user feedback and usage of network capabilities in real time, uses detection algorithms to monitor whether the anti-DDoS strategy meets user expectations, and if the anti-DDoS strategy does not meet user expectations, the control center issues control instructions to optimize the deployed anti-DDoS strategy.
[0018] Still further preferably, the optimization of the deployed anti-DDoS strategy includes readjusting the deployment mode of the anti-DDoS strategy.
[0019] Still further preferably, the optimization of the deployed anti-DDoS strategy by the control center issuing control instructions includes any one or a combination of multiple of the following three trigger conditions:
[0020] The first trigger condition is a sudden hardware failure, network connection failure, and supposed adjustment in the physical network.
[0021] The second trigger condition is that the user demand and the anti-DDoS strategy do not meet user expectations due to deployment problems.
[0022] The third trigger condition is load balancing when multiple anti-DDoS strategies are deployed simultaneously.
[0023] Still further preferably, the load balancing specifically refers to maintaining the balance of computing, storage, and communication pressure in each location in the physical network through flexible scheduling when multiple anti-DDoS strategies are deployed simultaneously.
[0024] Still further preferably, the flexible scheduling specifically refers to that in the physical network, when the resources of a certain node or a certain link are exhausted and the resources of other nodes or links are sufficient, the capabilities of the nodes or links with exhausted resources are deployed to the nodes or links with sufficient resources.
[0025] Further preferably, in the S1 step, the control center determines the key attributes of user demand from the user's anti-DDoS strategy demand, and the key attributes include the user's demand for a certain specific capability, the user's demand for time determinism of anti-DDoS, or the user's demand for a certain specific resource.
[0026] Further preferably, in the S1 step, the risk assessment of user demand specifically refers to using a probability analysis method or an expert system risk assessment method to comprehensively assess the DDoS attack risk currently faced by the user, the attack type suffered by the user, and the potential attack source.
[0027] Further preferably, in the S2 step, after the anti-DDoS strategy is generated, the control center selects a suitable location in the physical network of the cloud native system for deployment and deploys each capability on the service chain in the form of a container.
[0028] Further preferably, the deployment position of the anti-D strategy is determined according to the key attributes of user demand and the actual situation of the physical network of the cloud native system, and the actual situation of the physical network of the cloud native system includes the resource occupation of each node or link or the link bandwidth.
[0029] Compared with the prior art, the beneficial technical effects brought by the present application are as follows:
[0030] 1. The present application can deploy anti-D strategies at any time and any place in the cloud native system according to user demand, and compared with the existing anti-D strategy deployment method, the present application reduces the deployment cost, and the anti-D strategy is generated in combination with the perception of the current network state of the cloud native system and the prediction of future attacks, so that the generated anti-D strategy can be compatible with the current network environment of the cloud native system.
[0031] 2. The present application abstracts the traditional anti-D function into a virtualized component to form various capabilities of anti-D, and then deploys the anti-D in the form of a container at any position of the physical network of the cloud native system, thereby solving the problem of high deployment cost of the anti-D strategy in the current network, and also solving the problem that the current network structure is fixed and the anti-D function depends on hardware devices, which is difficult to deploy flexibly. According to user demand, the perception of the current network state of the cloud native system and the prediction of future attacks, the present application combines the abstracted capabilities in a set order to form a service chain and deploys the service chain into the cloud native system, so as to realize the on-demand deployment of the anti-D strategy, solve the problem of rigid management and lack of flexibility of the current anti-D strategy, and through the flexible deployment of the anti-D strategy, the strategy can be flexibly scheduled. BRIEF DESCRIPTION OF DRAWINGS
[0032] Figure 1 It is a flowchart of the anti-DDoS strategy deployment method of the cloud native system of the present application. DETAILED DESCRIPTION
[0033] The technical solutions for achieving the purposes of the present application will be further described below through specific embodiments. It should be noted that the technical solutions claimed by the present application include but are not limited to the following embodiments.
[0034] Embodiment 1
[0035] As a preferred embodiment of the present application, referring to the drawings attached to the specification, Figure 1 the present embodiment discloses an anti-DDoS strategy deployment method for a cloud native system, which comprises the following steps:
[0036] S1, a user of the cloud native system sends an anti-D strategy demand to a control center, and the control center analyzes the anti-D strategy demand of the user; specifically,
[0037] The control center determines the key attributes of the user's demand from the user's anti-D strategy demand; and then performs risk assessment on the user's demand;
[0038] S2, according to the analysis result of the user's anti-D strategy demand, the control center generates an anti-D strategy, and deploys the anti-D strategy to the cloud native system used by the user;
[0039] The anti-D strategy is achieved by the control center through the analysis of the user's demand, the perception of the current network state of the cloud native system, and the prediction of future attacks, abstracting the capabilities and combining the linkage in a set order to form a service chain and then deploying it to the cloud native system.
[0040] The capability refers to a virtualized component abstracted from a traditional anti-D function; the traditional anti-D function is decoupled from the hardware, and the network function is realized in a virtualized environment through network programming, and a management and orchestration system (such as MANO, Management and Orchestration) is used to configure, manage and optimize the virtual network function, and the deployment is performed in any position of the physical network in the cloud native system in the form of a container.
[0041] In this embodiment, various anti-D functions are abstracted into various virtualized components to form various capabilities of anti-D, which are integrated in the capability pool of the control center, and then corresponding capabilities are extracted from the capability pool according to the analysis of the user's demand, the perception of the current network state of the cloud native system, and the prediction of future attacks, and the extracted capabilities are combined in a set order to form a service chain and then deployed to the cloud native system.
[0042] Embodiment 2
[0043] As another preferred embodiment of the present application, this embodiment is a further detailed supplement and elaboration of the technical solution of the present application based on the above-mentioned embodiment 1. In this embodiment, referring to the method shown in the accompanying drawings, Figure 1 As another preferred embodiment of the present application, this embodiment is a further detailed supplement and elaboration of the technical solution of the present application based on the above-mentioned embodiment 1. In this embodiment, referring to the method shown in the accompanying drawings,
[0044] Among them, the optimization of the deployed anti-D strategy includes re-adjusting the deployment mode of the anti-D strategy.
[0045] Further, the control center issues a control instruction to optimize the deployed anti-D strategy, which includes any one or a combination of multiple of the following three trigger conditions:
[0046] The first trigger condition is a sudden hardware failure, network connection failure and supposed adjustment in the physical network.
[0047] The second trigger condition is that the user demand and the anti-DDoS strategy do not achieve the expected effect due to deployment problems.
[0048] The third trigger condition is load balancing when multiple anti-DDoS strategies are deployed simultaneously.
[0049] The load balancing specifically refers to maintaining the balance of computing, storage and communication pressure in each position in the physical network through flexible scheduling when multiple anti-DDoS strategies are deployed simultaneously.
[0050] The flexible scheduling specifically refers to that when the resources of a certain node or link in the physical network are exhausted and the resources of other nodes or links are sufficient, the ability of the node or link with exhausted resources is deployed to the node or link with sufficient resources.
[0051] Embodiment 3
[0052] As another preferred embodiment of the present application, this embodiment is a further detailed supplement and elaboration of the technical solution of the present application on the basis of the above-mentioned embodiment 1 or embodiment 2. In this embodiment, in the S1 step, the control center determines the key attributes of the user demand from the user's anti-DDoS strategy demand, which includes the user's demand for a certain specific ability, the user's demand for time determinacy of anti-DDoS or the user's demand for a certain specific resource.
[0053] In the S1 step, the risk assessment of the user demand is specifically to comprehensively assess the DDoS attack risk currently faced by the user, the attack type suffered and the potential attack source by using the probability analysis method or the risk assessment method of the expert system.
[0054] In the S2 step, after generating the anti-DDoS strategy, the control center selects a suitable position in the physical network of the cloud native system for deployment, and deploys each ability on the service chain in the form of a container.
[0055] The deployment position of the anti-DDoS strategy is determined according to the key attributes of the user demand and the actual situation of the physical network of the cloud native system, and the actual situation of the physical network of the cloud native system includes the resource occupation of each node or link or the link bandwidth.
[0056] Embodiment 4
[0057] As another preferred embodiment of the present application, this embodiment is a further detailed supplement and elaboration of the technical solution of the present application on the basis of the above-mentioned embodiment 1, embodiment 2 or embodiment 3.
[0058] In the present embodiment, the anti-DDoS strategy is deployed in the cloud-native system, which needs to go through three stages, namely, user demand analysis stage, deployment location selection stage and real-time monitoring stage after deployment; the deployed anti-DDoS strategy also needs to have two functions, namely, flexible scheduling and load balancing.
[0059] According to the user demand analysis stage in the above three stages, when the user is subjected to DDoS attack, the control center of the cloud-native system perceives the user demand and analyzes the anti-DDoS strategy demand of the user, first of all, it is necessary to determine what the key attributes of the user demand are, such as whether the user needs a certain specific ability or whether there is a demand for anti-DDoS time determinacy; then the risk of the user's demand is evaluated, the DDoS attack risk faced by the user is evaluated according to the collected intelligence, including attack type and potential attack source, etc.
[0060] According to the deployment location selection stage in the above three stages, after analyzing the user demand, the control center in the cloud-native system will deploy the anti-DDoS strategy into the cloud-native system according to the user demand, wherein the anti-DDoS strategy is realized by a service chain formed by the combination of abstracted capabilities, the capability is a virtualized component abstracted from the traditional anti-DDoS function by means of software, specifically, the traditional anti-DDoS function is decoupled from the hardware, the network function is realized in the virtualized environment through network programming, and the management and orchestration system (such as MANO, Management and Orchestration) is used to configure, manage and optimize the virtual network function, for example, diversion function, cleaning function, detection function, etc., which can be deployed in various locations in the cloud-native system in the form of containers, the selection of deployment location is mainly based on the user demand and the actual situation in the network, and the appropriate location is selected in the physical network of the cloud-native system to deploy each capability on the service chain in the form of containers.
[0061] According to the real-time monitoring stage after deployment in the above three stages, mainly the anti-DDoS efficiency of the deployed anti-DDoS strategy is evaluated to determine whether it meets the user's expected requirements and feedback is given, if the anti-DDoS efficiency does not meet the user's demand, the control center will adjust the deployment mode of the anti-DDoS strategy through the automatic component according to the user demand and the actual network environment.
[0062] The deployed anti-DDoS strategy has the function of flexible scheduling, mainly referring to optimizing the deployed anti-DDoS strategy through automatic components, which includes three trigger conditions:
[0063] C1: sudden hardware failure, network connection failure and human adjustment in the physical network.
[0064] C2: user demand and anti-DDoS strategy do not meet the expectations due to deployment problems.
[0065] C3: Load balancing when multiple anti-DDoS strategies are deployed simultaneously.
[0066] The deployed anti-DDoS strategy has a load balancing function, mainly to keep the computing, storage and communication pressure of each position in the physical network balanced through flexible scheduling when multiple anti-DDoS strategies are deployed simultaneously.
[0067] Embodiment 5
[0068] As another preferred embodiment of the present application, this embodiment is a further detailed supplement and elaboration of the technical solution of the present application based on the above-mentioned embodiment 1, embodiment 2, embodiment 3 or embodiment 4.
[0069] In this embodiment, deploying an anti-DDoS strategy in a cloud-native system needs to go through three stages, namely user demand analysis using a cloud-native system, deployment position selection, and real-time monitoring after deployment, and the deployment strategy also needs to include two functions, namely flexible scheduling and load balancing.
[0070] In the user demand analysis stage, the user sends the anti-DDoS strategy demand to the control center, and the user's anti-DDoS strategy demand is analyzed. First, the control center determines the key attributes of the user's demand, such as the user's need for a certain specific capability, the user's demand for time determinacy of anti-DDoS, or the user's demand for a certain specific resource, etc. After determining the key attributes of the user's demand, the risk of the user's demand is evaluated using probability analysis, expert system, etc. Risk assessment methods are used to comprehensively evaluate the DDoS attack risk currently faced by the user, the type of attack suffered and the potential attack source, etc.
[0071] The anti-DDoS strategy is realized by the control center abstracting the capability, combining the linkage in a certain order to form a service chain, and deploying it to the cloud-native system after analyzing the user's demand, perceiving the current network state, and predicting future attacks. The capability is a virtualized component abstracted from traditional anti-DDoS functions. The traditional anti-DDoS function is decoupled from the hardware, and the network function is realized in a virtualized environment through network programming. The management and orchestration system (such as MANO, Management and Orchestration) is used to configure, manage and optimize the virtual network function, which can be deployed in any position of the physical network in the cloud-native system in the form of a container.
[0072] After forming the anti-DDoS strategy, the appropriate position in the physical network of the cloud-native system is selected for deployment, and each capability on the service chain is deployed in the form of a container. The selection of the deployment position is mainly determined according to the user's demand and the actual situation of the network, such as the user's demand for which aspect of the resource or time determinacy, the resource occupation of each node in the network, link bandwidth, etc.
[0073] The efficiency of the anti-D strategy is evaluated after the deployment of the anti-D strategy. According to user feedback and the use of network capabilities, a detection algorithm is used to detect whether the anti-D strategy meets the user's expectations. If the desired efficiency is not achieved, the control center will issue control instructions to readjust the deployment method.
[0074] The control center issues control instructions to optimize the deployed anti-D strategy, including any one or a combination of the following three trigger conditions:
[0075] The first trigger condition is a sudden hardware failure, network connection failure, and adjustment in the physical network.
[0076] The second trigger condition is that the user's demand and the anti-D strategy do not achieve the desired effect due to deployment problems.
[0077] The third trigger condition is load balancing when multiple anti-D strategies are deployed simultaneously.
[0078] The load balancing specifically refers to maintaining the balance of computing, storage, and communication pressure in each location in the physical network through flexible scheduling when multiple anti-D strategies are deployed simultaneously. The flexible scheduling specifically refers to that in the physical network, if the resources of a certain node or link are exhausted and the resources of other nodes or links are sufficient, the capabilities of the resource-exhausted node or link are deployed to the resource-sufficient node or link.
Claims
1. A method for deploying anti-DDoS strategies in a cloud-native system, characterized in that: The method comprises the following steps: S1. Users of the cloud-native system send anti-DDoS policy requirements to the control center of the cloud-native system. The control center analyzes the user's anti-DDoS policy requirements. Specifically, The control center identifies the key attributes of user requirements based on their anti-DDoS policy needs and then conducts a risk assessment on these requirements. Specifically, the risk assessment uses probabilistic analysis or expert system risk assessment methods to comprehensively assess the DDoS attack risks, attack types, and potential attack sources faced by users. S2. Based on the analysis of the user's anti-DDoS policy requirements in step S1, the control center generates an anti-DDoS policy and deploys it to the user's cloud-native system. The anti-DDoS strategy is implemented by the control center through analyzing user needs, perceiving the current network status of the cloud-native system, and predicting future attacks. The control center then abstracts capabilities and combines and links them in a set order to form a service chain, which is then deployed to the cloud-native system. This capability refers to virtualized components abstracted from traditional anti-DDoS functions. This decouples traditional anti-DDoS functions from hardware, implements network functions in a virtualized environment through network programming, and uses management and orchestration systems to configure, manage, and optimize virtual network functions. These functions are then deployed in containers anywhere on the physical network within a cloud-native system.
2. The anti-DDoS strategy deployment method for a cloud native system according to claim 1, characterized in that: The method also includes a real-time monitoring step after the anti-DDoS policy is deployed. That is, after the anti-DDoS policy is deployed, the control center receives user feedback and network capacity usage in real time, and uses a detection algorithm to monitor whether the anti-DDoS policy meets user expectations. If the expected effect is not achieved, the control center issues control instructions to optimize the deployed anti-DDoS policy.
3. The anti-DDoS strategy deployment method for a cloud native system according to claim 2, characterized in that: The optimization of the deployed anti-DDoS strategy includes readjusting the deployment method of the anti-DDoS strategy.
4. The anti-DDoS strategy deployment method for a cloud native system according to claim 2, characterized in that: The control center issues control instructions to optimize the deployed anti-DDoS policy, including any one or more combinations of the following three trigger conditions: The first trigger condition is a sudden hardware failure in the physical network, a network connection failure, or a network adjustment. The second trigger condition is that user needs and anti-DDoS strategies fail to achieve the expected results due to deployment issues; The third trigger condition is load balancing when multiple anti-DDoS strategies are deployed simultaneously.
5. The anti-DDoS strategy deployment method for a cloud native system according to claim 4, characterized in that: Load balancing specifically refers to maintaining balanced computing, storage, and communication pressures at each location in the physical network through flexible scheduling when multiple anti-DDoS strategies are deployed simultaneously.
6. The anti-DDoS strategy deployment method for a cloud native system according to claim 5, characterized in that: The flexible scheduling method specifically means that, in a physical network, if the resources of a certain node or a certain link are exhausted and the resources of other nodes or links are sufficient, the capacity of the node or link with exhausted resources is deployed to the node or link with sufficient resources.
7. The anti-DDoS policy deployment method for a cloud native system according to any one of claims 1 to 6, characterized in that: In step S1, the control center determines the key attributes of the user's requirements from the user's anti-DDoS policy requirements. The key attributes include the user's requirements for a specific capability, the user's requirements for time certainty in anti-DDoS, or the user's requirements for a specific resource.
8. The anti-DDoS policy deployment method for a cloud native system according to any one of claims 1 to 6, characterized in that: In step S2, after generating the anti-DDoS policy, the control center selects a suitable location in the physical network of the cloud-native system for deployment and deploys the various capabilities on the service chain in a containerized manner.
9. The anti-DDoS policy deployment method for a cloud native system according to any one of claims 1 to 6, characterized in that: The deployment location of the anti-DDoS policy is determined based on the key attributes of user needs and the actual physical network conditions of the cloud-native system. The actual physical network conditions of the cloud-native system include the resource usage or link bandwidth of each node or link.