A DDoS resistance intelligence sharing method suitable for cloud native system
By adopting direct and indirect sharing methods in the cloud-native system, combined with the interconnection and intelligence sharing capabilities of the control center, the problem of untimely intelligence sharing caused by the isolation of anti-DDoS devices in the cloud-native system was solved, realizing efficient intelligence transmission and feedback, and enhancing the system's anti-DDoS capability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- UNIV OF ELECTRONICS SCI & TECH OF CHINA
- Filing Date
- 2024-08-28
- Publication Date
- 2026-04-10
AI Technical Summary
In cloud-native systems, anti-DDoS devices are often isolated from each other, resulting in untimely and inefficient intelligence sharing, making it difficult to effectively respond to DDoS attacks.
Intelligence sharing is conducted in cloud-native systems using both direct and indirect sharing methods. Through the service chain connection and intelligence sharing capabilities controlled by the control center, intelligence format conversion, data analysis, and decryption/encryption operations are performed, and an intelligence sampling, feature extraction, analysis, and feedback mechanism is established.
It enables timely and effective intelligence sharing in cloud-native systems, improves the efficiency and real-time nature of intelligence sharing, solves the problem of untimely intelligence sharing caused by isolated devices, and enhances the system's anti-DDoS capability.
Smart Images

Figure CN119210781B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to an anti-DDoS intelligence sharing method suitable for a cloud native system. BACKGROUND
[0002] DDoS attack, namely distributed denial of service attack, is one of the most important attack means in current network attacks, and is characterized in that the DDoS attack can rapidly exhaust the resources of a target system through a large number of requests, so that the target system cannot normally provide services. This attack method can cause economic losses and reputation damage to enterprises, organizations or individuals. With the popularity of the Internet and the increase in the connection of various devices, the scale and frequency of DDoS attacks are also increasing, bringing greater challenges to network security.
[0003] Cloud network convergence refers to the combination of cloud computing and communication network, which fully utilizes the respective advantages of cloud computing and network. Cloud computing can dynamically adjust resources according to demand, and network realizes fast data transmission and wider coverage, with high flexibility and elasticity. Cloud network convergence develops super computing power to the user end, realizes cloud edge convergence, realizes full network coverage through central cloud and edge cloud, and maximizes the cloud network capability. Cloud native aims to utilize cloud computing, containerization and microservice technology to build high-flexibility and easy-to-manage application programs, and fully utilize the potential of cloud computing. Cloud native can deploy application programs according to demand, and application programs can be flexibly combined and linked, automatically managed, and network functions flexibly deployed, to improve the response speed and efficiency of application programs.
[0004] Cloud network convergence provides flexible and sufficient basic conditions for various cloud native businesses. On the basis of cloud native, with the help of software concept, the constraints of existing network structure are broken through, flexible combination and linkage of system functions are realized, and the characteristics of deployment, arrangement, expansion and updating are possessed, to solve the problems of rigid deployment and high cost of traditional hardware.
[0005] Intelligence sharing refers to sharing attack information to other components in the system when the system is attacked, such as the source of the attack, the specific technology and method details used by the attacker, the operation process and behavior pattern of the attacker. Through intelligence sharing, each component of the system can more quickly identify and respond to threats in the network, prevent future attacks, improve the collaboration ability between components, and reduce the loss of attacks.
[0006] Anti-DDoS intelligence sharing requires anti-DDoS devices in the system to interlink and communicate through internal interconnection, but due to the current network solidification, anti-DDoS devices are deployed in isolation in the network, anti-DDoS strategies are fragmented, and the problems of untimely intelligence sharing and difficult intelligence sharing are extended.
[0007] The Chinese patent document with publication number CN117914596A and publication date of April 19, 2024 discloses an anti-DDOS attack defense method, system and storage medium, characterized in that the system comprises a cross-network joint defense platform and a plurality of operator corresponding end-side DDoS attack monitoring processing nodes and anti-DDoS defense platforms. The end-side DDoS attack monitoring processing node is deployed in an Internet data center and / or a public cloud.
[0008] The end-side DDoS attack monitoring processing node is configured to defend against attack traffic when the attack traffic value of the network is less than or equal to the node processing limit, and report attack information corresponding to the attack traffic to the anti-DDoS defense platform corresponding to the end-side DDoS attack monitoring processing node and the cross-network joint defense platform when the attack traffic value is greater than the node processing limit.
[0009] The anti-DDoS defense platform is configured to issue a traffic cleaning instruction to a cleaning device based on the attack information to clean the attack traffic after receiving the attack information.
[0010] The cross-network joint defense platform is configured to share the attack information with the anti-DDoS defense platforms corresponding to the plurality of operators to defend against the attack traffic represented by the attack information in advance.
[0011] The anti-DDOS attack defense method, system and storage medium disclosed in the patent document can defend against attack traffic and report attack information corresponding to attack traffic to the anti-DDoS defense platform corresponding to the DDoS attack monitoring processing node and the cross-network joint defense platform when the attack traffic value is greater than the node processing limit. The anti-DDoS defense platform can issue a traffic cleaning instruction to a cleaning device based on the attack information to clean the attack traffic after receiving the attack information, thereby improving the defense effect. However, there are still problems of untimely intelligence sharing and low intelligence sharing efficiency. SUMMARY
[0012] To overcome the above-mentioned defects of the prior art, the present application provides an anti-DDoS intelligence sharing method suitable for a cloud native system. The present application is based on a cloud native system and realizes anti-DDoS intelligence sharing in the cloud native system, which can timely share intelligence and improve the efficiency of intelligence sharing.
[0013] The present application is realized by the following technical solutions:
[0014] An anti-DDoS intelligence sharing method suitable for a cloud native system, characterized by comprising the following steps:
[0015] a. Direct sharing and indirect sharing are used for intelligence sharing in the cloud-native system;
[0016] b. Direct sharing, intelligence information is transmitted through the service chain connected in series between each capability;
[0017] c. Indirect sharing, under the control of the control center of the cloud-native system, intelligence sharing is carried out through intelligence sharing capabilities.
[0018] In step b, direct sharing specifically refers to the intelligence sharing between each capability or service chain in the cloud-native system through the first-in-line connection method. When the demander of the capability or service chain demands intelligence from the provider of another capability or service chain, the demand is sent to the control center. The control center connects the intelligence-providing capability or service chain before the demander according to the demand to form a new service chain.
[0019] When the control center performs the connection operation, it performs intelligence format conversion, intelligence data analysis, and decryption and encryption operations.
[0020] Before the capability or service chain provider provides intelligence, it performs encryption operation, and the capability or service chain demander performs decryption operation before receiving intelligence.
[0021] In step c, indirect sharing includes intelligence sampling, intelligence feature extraction, intelligence analysis, intelligence sharing and intelligence feedback.
[0022] The intelligence sampling specifically refers to the control center sampling the output intelligence of the capabilities or service chains already deployed in the current cloud-native system for subsequent intelligence feature extraction.
[0023] The intelligence feature extraction specifically refers to the control center extracting features from the sampled intelligence through algorithms to evaluate the performance of the output intelligence of each capability or service chain and classify them.
[0024] The intelligence analysis specifically refers to the control center evaluating the performance of each capability or service chain and classifying the intelligence according to the sampled data, which is used as the basis for optimal intelligence sharing allocation.
[0025] The intelligence sharing specifically refers to the control center perceiving the demand for intelligence of each capability or service chain in the cloud-native system. When it perceives that any capability or service chain demands intelligence, it selects the optimal intelligence capability or service chain provider according to the evaluation results and classification results, and sends the intelligence to the intelligence demander.
[0026] The intelligence feedback specifically refers to the capability or service chain in the cloud-native system feeding back the intelligence sharing and usage to the control center after receiving the shared intelligence, including evaluating the intelligence quality, sharing efficiency and utilization rate of the intelligence.
[0027] The capability of the application refers to a virtualization component abstracted from a traditional anti-DDoS function, decoupling the traditional anti-DDoS function from hardware, implementing network functions in a virtualized environment through network programming, using a management and orchestration system to configure, manage and optimize virtual network functions, and deploying in a container manner at any location of a physical network in a cloud-native system.
[0028] The beneficial effects of the application mainly manifest in the following aspects:
[0029] 1、The application, a, intelligence sharing is carried out by direct sharing and indirect sharing in a cloud-native system; b, intelligence information is transmitted through a service chain connected between various capabilities by direct sharing; c, intelligence sharing is carried out by intelligence sharing capabilities under the control of a control center in the cloud-native system, compared with the prior art, based on the cloud-native system, DDoS intelligence sharing is realized in the cloud-native system, intelligence sharing can be carried out in time, and the efficiency of intelligence sharing is improved.
[0030] 2、The application, direct sharing and indirect sharing are used for intelligence sharing, which can solve the problems that DDoS devices in the current network are isolated from each other, attack intelligence sharing is not timely and difficult to share, and has good applicability.
[0031] 3、The application, the control center carries out intelligence format conversion, intelligence data analysis and decryption and encryption operations when carrying out the series operation, which can ensure the unity of intelligence in the transmission process.
[0032] 4、In step c, the indirect sharing includes intelligence sampling, intelligence feature extraction, intelligence analysis, intelligence sharing and intelligence feedback, through the five stages, the cloud-native system can share DDoS intelligence more conveniently, and through the feedback mechanism, the intelligence sharing process is continuously optimized.
[0033] 5、The application, for the problem that DDoS threat intelligence is difficult to share in the current network, DDoS threat intelligence sharing is realized in the cloud-native system, so that intelligence sharing is easier to realize.
[0034] 6、The application, for the problem that DDoS threat intelligence sharing is not timely in the current network, a DDoS threat intelligence sharing mechanism is established in the cloud-native system, which can share intelligence faster and improve real-time performance.
[0035] 7、The application, for the problem that DDoS threat intelligence processing feedback is not timely in the current network, a DDoS intelligence feedback mechanism is established in the cloud-native system, which can timely feedback according to the effect of intelligence sharing. BRIEF DESCRIPTION OF DRAWINGS
[0036] The application will be further described in conjunction with the accompanying drawings and specific embodiments.
[0037] Figure 1 The flow chart of the application. DETAILED DESCRIPTION
[0038] Embodiment 1
[0039] Referring to Figure 1 A DDoS resistance intelligence sharing method suitable for a cloud native system, comprising the following steps:
[0040] a. Direct sharing and indirect sharing are adopted in the cloud native system for intelligence sharing;
[0041] b. Direct sharing: intelligence information is transmitted through a service chain connected in series between each capability;
[0042] c. Indirect sharing: intelligence sharing is performed through intelligence sharing capabilities under the control of the control center of the cloud native system.
[0043] This embodiment is the most basic implementation. a. Direct sharing and indirect sharing are adopted in the cloud native system for intelligence sharing; b. Direct sharing: intelligence information is transmitted through a service chain connected in series between each capability; c. Indirect sharing: intelligence sharing is performed through intelligence sharing capabilities under the control of the control center of the cloud native system. Compared with the prior art, the DDoS resistance intelligence sharing is realized in the cloud native system, which can timely perform intelligence sharing and improve the efficiency of intelligence sharing.
[0044] Embodiment 2
[0045] Referring to Figure 1 A DDoS resistance intelligence sharing method suitable for a cloud native system, comprising the following steps:
[0046] a. Direct sharing and indirect sharing are adopted in the cloud native system for intelligence sharing;
[0047] b. Direct sharing: intelligence information is transmitted through a service chain connected in series between each capability;
[0048] c. Indirect sharing: intelligence sharing is performed through intelligence sharing capabilities under the control of the control center of the cloud native system.
[0049] Preferably, in step b, the direct sharing specifically refers to that each capability or service chain in the cloud native system performs intelligence sharing through a first-in series mode. When a capability or service chain demander demands intelligence of another capability or service chain provider, the demand is sent to the control center. The control center connects the intelligence providing capability or service chain before the demander according to the demand to form a new service chain.
[0050] The embodiment is a preferred embodiment, which uses direct sharing and indirect sharing to share information, can solve the problem that anti-DDoS devices in the current network are isolated from each other, attack information sharing is not timely and difficult to share, and has good applicability.
[0051] Embodiment 3
[0052] Referring to Figure 1 An anti-DDoS information sharing method suitable for a cloud native system, comprising the following steps:
[0053] a. Direct sharing and indirect sharing are used in the cloud native system to share information;
[0054] b. Direct sharing, information is transmitted through a service chain connected in series between each capability;
[0055] c. Indirect sharing, under the control of the control center of the cloud native system, information is shared through the information sharing capability.
[0056] In the step b, the direct sharing specifically refers to that each capability or service chain in the cloud native system shares information through a first-in series mode. When a capability or service chain demander needs information provided by another capability or service chain provider, the demand is sent to the control center. The control center connects the capability or service chain providing information before the demander according to the demand to form a new service chain.
[0057] The control center performs information format conversion, information data analysis, and decryption and encryption operations when performing the series operation.
[0058] The capability or service chain provider performs encryption operation before providing information, and the capability or service chain demander performs decryption operation before receiving information.
[0059] In the step c, the indirect sharing includes information sampling, information feature extraction, information analysis, information sharing, and information feedback.
[0060] The embodiment is another preferred embodiment, the control center performs information format conversion, information data analysis, and decryption and encryption operations when performing the series operation, which can ensure the unity of information in the transmission process.
[0061] In the step c, the indirect sharing includes information sampling, information feature extraction, information analysis, information sharing, and information feedback. Through the five stages, the cloud native system can more conveniently share anti-DDoS information, and through the feedback mechanism, the information sharing process is continuously optimized.
[0062] Embodiment 4
[0063] Referring toFigure 1 A DDoS threat intelligence sharing method suitable for a cloud native system, comprising the following steps:
[0064] a. Direct sharing and indirect sharing are adopted in the cloud native system for intelligence sharing;
[0065] b. Direct sharing, intelligence information is transmitted through a service chain connected in series between various capabilities;
[0066] c. Indirect sharing, intelligence sharing is carried out through intelligence sharing capabilities under the control of the control center of the cloud native system.
[0067] In step b, direct sharing specifically refers to intelligence sharing between various capabilities or service chains in the cloud native system through first-in-line connection. When a capability or service chain demander needs intelligence from another capability or service chain provider, the demand is sent to the control center. The control center connects the intelligence-providing capability or service chain before the demander according to the demand to form a new service chain.
[0068] The control center performs intelligence format conversion, intelligence data analysis, and decryption and encryption operations when performing the connection operation.
[0069] The capability or service chain provider performs encryption operation before providing intelligence, and the capability or service chain demander performs decryption operation before receiving intelligence.
[0070] Further preferably, in step c, indirect sharing includes intelligence sampling, intelligence feature extraction, intelligence analysis, intelligence sharing, and intelligence feedback.
[0071] The intelligence sampling specifically refers to the control center sampling the output intelligence of the capabilities or service chains already deployed in the current cloud native system for subsequent intelligence feature extraction.
[0072] The intelligence feature extraction specifically refers to the control center extracting features from the sampled intelligence through algorithms to evaluate and classify the output intelligence of various capabilities or service chains.
[0073] This embodiment is another preferred embodiment. For the problem that DDoS threat intelligence is difficult to share due to the isolation of DDoS device deployment in the current network, DDoS threat intelligence sharing is realized in the cloud native system, making intelligence sharing easier to implement.
[0074] Embodiment 5
[0075] See Figure 1 A DDoS threat intelligence sharing method suitable for a cloud native system, comprising the following steps:
[0076] a. Direct sharing and indirect sharing are used for intelligence sharing in the cloud native system;
[0077] b. Direct sharing, intelligence information is transmitted through the service chain connected in series between each capability;
[0078] c. Indirect sharing, intelligence sharing is carried out through intelligence sharing capabilities under the control of the control center of the cloud native system.
[0079] In step b, direct sharing specifically refers to intelligence sharing between each capability or service chain in the cloud native system through the first-in-line connection method. When a capability or service chain demander needs intelligence from another capability or service chain provider, the demand is sent to the control center. The control center connects the intelligence-providing capability or service chain before the demander according to the demand to form a new service chain.
[0080] The control center performs intelligence format conversion, intelligence data analysis, and decryption and encryption operations when performing the connection operation.
[0081] The capability or service chain provider performs encryption operation before providing intelligence, and the capability or service chain demander performs decryption operation before receiving intelligence.
[0082] In step c, indirect sharing includes intelligence sampling, intelligence feature extraction, intelligence analysis, intelligence sharing, and intelligence feedback.
[0083] Intelligence sampling specifically refers to the control center sampling the output intelligence of the capabilities or service chains already deployed in the current cloud native system for subsequent intelligence feature extraction.
[0084] Intelligence feature extraction specifically refers to the control center extracting features from the sampled intelligence through algorithms to evaluate the performance of the output intelligence of each capability or service chain and classify them.
[0085] Intelligence analysis specifically refers to the control center evaluating the performance of each capability or service chain and classifying intelligence based on the sampled data, which serves as the basis for optimal intelligence sharing allocation.
[0086] Intelligence sharing specifically refers to the control center perceiving the demand for intelligence of each capability or service chain in the cloud native system. When it perceives that any capability or service chain needs intelligence, it selects the optimal intelligence capability or service chain provider according to the evaluation results and classification results, and sends the intelligence to the intelligence demander.
[0087] This embodiment is another preferred implementation. To solve the problem of untimely DDoS threat intelligence sharing in the current network, a DDoS threat intelligence sharing mechanism is established in the cloud native system, which can share intelligence faster and improve real-time performance.
[0088] Embodiment 6
[0089] Referring to Figure 1 A DDoS resistance intelligence sharing method for a cloud native system, comprising the following steps:
[0090] a. Direct sharing and indirect sharing are adopted in the cloud native system for intelligence sharing;
[0091] b. Direct sharing, intelligence information is transmitted through a service chain connected in series between various capabilities;
[0092] c. Indirect sharing, intelligence sharing is performed by intelligence sharing capabilities under the control of the control center of the cloud native system.
[0093] In the step b, direct sharing specifically refers to intelligence sharing between various capabilities or service chains in the cloud native system through a first-in series connection method. When a capability or service chain demander needs intelligence provided by another capability or service chain provider, the demand is sent to the control center. The control center connects the intelligence providing capability or service chain before the demander according to the demand to form a new service chain.
[0094] The control center performs intelligence format conversion, intelligence data analysis, and decryption and encryption operations when performing the series connection operation.
[0095] The capability or service chain provider performs encryption operation before providing intelligence, and the capability or service chain demander performs decryption operation before receiving intelligence.
[0096] In the step c, indirect sharing includes intelligence sampling, intelligence feature extraction, intelligence analysis, intelligence sharing, and intelligence feedback.
[0097] The intelligence sampling specifically refers to the control center sampling the output intelligence of the capabilities or service chains already deployed in the current cloud native system for subsequent intelligence feature extraction.
[0098] The intelligence feature extraction specifically refers to the control center extracting features from the sampled intelligence through an algorithm for performance evaluation and classification of the output intelligence of various capabilities or service chains.
[0099] The intelligence analysis specifically refers to the control center performing performance evaluation and intelligence classification of various capabilities or service chains according to the sampled data as a basis for optimal intelligence sharing distribution.
[0100] Further preferably, the intelligence sharing specifically refers to the control center perceiving the demand for intelligence of various capabilities or service chains in the cloud native system. When any capability or service chain demands intelligence, the optimal intelligence capability or service chain provider is selected according to the evaluation results and classification results, and the intelligence is sent to the intelligence demander.
[0101] The intelligence feedback specifically refers to that the capability or service chain in the cloud native system feeds back the intelligence sharing and use condition to the control center after receiving the shared intelligence, including evaluating intelligence quality, sharing efficiency and utilization rate of intelligence.
[0102] The embodiment is the best mode of implementation, and the DDoS intelligence feedback mechanism is established in the cloud native system to solve the problem of untimely feedback of DDoS threat intelligence processing in the current network, and the effect of intelligence sharing can be fed back in time.
[0103] The basic principle of the application is as follows:
[0104] The intelligence sharing in the cloud native system includes direct sharing and indirect sharing. The direct sharing of intelligence refers to that the capabilities or service chains in the cloud native system share intelligence through the first-in-line mode. The indirect sharing refers to that intelligence sharing is performed by the intelligence sharing capability under the control of the control center of the cloud native system, including five stages of intelligence sampling, intelligence feature extraction, intelligence analysis, intelligence sharing and intelligence feedback. The five stages of indirect sharing can make the cloud native system more convenient to share DDoS intelligence, and the feedback mechanism can continuously optimize the intelligence sharing process, so that the intelligence sharing can be performed in time and the efficiency of intelligence sharing can be improved.
[0105] The capability refers to a virtualized component abstracted from a traditional DDoS defense function, which decouples the traditional DDoS defense function from hardware, realizes network function in a virtualized environment through network programming, uses a management and orchestration system such as MANO to configure, manage and optimize virtual network function, and deploys in any position of the physical network in the cloud native system in the form of a container.
[0106] MANO refers to a unified framework for managing each virtual network function and a basic network virtualization architecture, which is used for service orchestration and device management.
Claims
1. A method for sharing anti-DDoS intelligence suitable for cloud-native systems, characterized in that, Includes the following steps: In the field of cybersecurity technology, a. Use direct and indirect sharing for intelligence sharing in cloud-native systems; b. Direct sharing: Intelligence information is transmitted through a service chain that connects various capabilities; c. Indirect sharing: Under the control of the cloud-native system's control center, intelligence is shared through intelligence sharing capabilities. In step b, direct sharing specifically refers to the sharing of intelligence between various capabilities or service chains in the cloud-native system through a first-to-last connection. When a capability or service chain requester needs intelligence from another capability or service chain provider, the request is sent to the control center. The control center, based on the request, connects the capability or service chain providing the intelligence before the requester to form a new service chain. In step c, indirect sharing includes intelligence sampling, intelligence feature extraction, intelligence analysis, intelligence sharing, and intelligence feedback. The capability refers to a virtualization component abstracted from traditional DDoS protection functions, which decouples traditional DDoS protection functions from hardware, implements network functions in a virtualized environment through network programming, uses a management and orchestration system to configure, manage and optimize virtual network functions, and can be deployed in any location of the physical network in a cloud-native system in the form of containers.
2. The anti-DDoS intelligence sharing method applicable to cloud-native systems according to claim 1, characterized in that: When performing serial operations, the control center performs intelligence format conversion, intelligence data analysis, and decryption and re-encryption operations.
3. The anti-DDoS intelligence sharing method applicable to cloud-native systems according to claim 2, characterized in that: Before providing intelligence, the capability or service chain provider performs an encryption operation, and the capability or service chain requester performs a decryption operation before receiving the intelligence.
4. The anti-DDoS intelligence sharing method for cloud-native systems according to claim 3, characterized in that: The intelligence sampling specifically refers to the control center sampling the output intelligence of the capabilities or service chains already deployed in the current cloud-native system for subsequent intelligence feature extraction.
5. A method for sharing anti-DDoS intelligence suitable for cloud-native systems according to claim 4, characterized in that: The aforementioned intelligence feature extraction specifically refers to the control center extracting features based on the sampled intelligence using algorithms, which are then used to evaluate and classify the output intelligence of various capabilities or service chains.
6. A method for sharing anti-DDoS intelligence suitable for cloud-native systems according to claim 5, characterized in that: The intelligence analysis specifically refers to the control center conducting performance evaluations and intelligence classifications of various capabilities or service chains based on sampled data, which serves as the basis for allocating optimal intelligence sharing.
7. A method for sharing anti-DDoS intelligence applicable to cloud-native systems according to claim 3, characterized in that: Specifically, the intelligence sharing refers to the control center sensing the intelligence needs of various capabilities or service chains in the cloud-native system. When any capability or service chain needs intelligence, the control center selects the optimal intelligence capability or service chain provider based on the evaluation and classification results, and sends the intelligence to the intelligence requester.
8. A method for sharing anti-DDoS intelligence applicable to cloud-native systems according to claim 6, characterized in that: The intelligence feedback specifically refers to the process by which capabilities or service chains in a cloud-native system, after receiving shared intelligence, report the sharing and usage of the intelligence to the control center, including evaluating intelligence quality, sharing efficiency, and intelligence utilization.
Citation Information
Patent Citations
Defense method and system for resisting DDOS attack and storage medium
CN117914596A
Micro-service effective containerization deployment method of intelligent factory based on resource sharing
CN115052033A
Cross-service data sharing method and system
CN115145649A