A cloud-native anti-DDoS defense method
By software-encapsulating the functions of the anti-DDoS system and forming a service chain on the cloud server, the flexibility and response speed issues of traditional anti-DDoS systems are solved, enabling efficient and flexible anti-DDoS policy management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- UNIV OF ELECTRONICS SCI & TECH OF CHINA
- Filing Date
- 2024-08-28
- Publication Date
- 2026-04-10
AI Technical Summary
In existing technologies, traditional anti-DDoS devices and strategies lack flexibility and resilience, making it difficult to automate and coordinate responses, resulting in high deployment costs, slow response speeds, and low anti-DDoS efficiency.
The functions of the anti-DDoS system are software-defined as capabilities, forming a coverage network, and then connected and deployed on cloud servers in the form of service chains to achieve policy automation.
It improves the response speed and efficiency of anti-DDoS strategies, and has high flexibility and elasticity, enabling flexible deployment and management of anti-DDoS strategies according to user needs.
Smart Images

Figure CN119210784B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a cloud-native anti-DDoS defense method. BACKGROUND
[0002] DDoS attack is a distributed denial of service attack. DDoS attack is one of the most important attack means in current network attacks. Attackers manipulate multiple devices in the network to send a large number of illegal request packets to the target host, so that the target host resources are exhausted and unable to respond to normal user requests, thereby achieving the attack purpose. Common DDoS attack methods include flood attack and reflection amplification attack. Cloud network integration refers to the combination of cloud computing and communication network, which fully utilizes the advantages of cloud computing and network. Cloud computing can dynamically adjust resources according to demand, and network realizes fast data transmission and wider coverage, with high flexibility and elasticity. Cloud network integration develops supercomputing power to the user end, realizes cloud edge integration, realizes full network coverage through central cloud and edge cloud, and maximizes cloud network capability.
[0003] Cloud native aims to utilize cloud computing, containerization and microservice technology to build high flexibility and easy-to-manage application programs, and fully utilize the potential of cloud computing. Cloud native can deploy application programs according to demand, and application programs can be flexibly combined and linked, automatically managed, and network functions flexibly deployed, to improve the response speed and efficiency of application programs. Cloud network integration provides flexible and sufficient basic conditions for various cloud native businesses. On the basis of cloud native, with the help of software concept, the constraints of existing network structure are broken through, and flexible combination and linkage of system functions are realized.
[0004] Traditionally, DDoS attack mitigation requires deploying anti-DDoS devices and strategies in the physical network. However, the current anti-DDoS solution based on hardware devices lacks flexibility and elasticity of system structure, anti-DDoS devices are difficult to deploy flexibly, anti-DDoS strategies are fragmented, and do not have the ability of automatic collaborative response, resulting in high cost of anti-DDoS system device deployment in the existing network and slow response speed of anti-DDoS strategy.
[0005] The Chinese patent document with the publication number CN114640610A and the publication date of June 17, 2022 discloses a cloud-native service governance method, device and storage medium, which comprises the following steps: receiving service information of a service provider, and generating a registration list based on the service information, a cloud-native microservice platform is used to realize service registration and service discovery; in response to a service invocation request sent by a service consumer, a service list is searched according to the registration list, a service invocation connection between the service consumer and a target service provider in the service list is created, so as to realize fast remote service invocation of the target service provider by the service consumer; local native executable codes of the service provider and the service consumer are constructed, and the local native executable codes are deployed and run on the cloud-native microservice platform, so as to realize fast dynamic elastic scaling of the cloud-native microservice platform, improve resource utilization, and save cost.
[0006] The cloud-native service governance method, device and storage medium disclosed in the patent document reduce three-party dependence and middleware deployment through cloud-native service registration and discovery, use an existing service discovery mode, and reduce the deployment of other service discovery components. However, there are still problems of slow response speed of the anti-DDoS strategy and low anti-DDoS efficiency. SUMMARY
[0007] In order to overcome the defects of the prior art, the present application provides a cloud-native anti-DDoS defense method, which can realize automatic anti-DDoS strategy, improve the response speed of the anti-DDoS strategy and the anti-DDoS efficiency.
[0008] The present application is realized by the following technical solutions:
[0009] A cloud-native anti-DDoS defense method, characterized in that it comprises the following steps:
[0010] S1, software, the functions of the anti-DDoS system are softwareized into capabilities to form a cover network;
[0011] S2, strategy automation, the capabilities are connected in the form of a service chain;
[0012] S3, service chain validation, the corresponding order of execution of each capability is specified through the service chain;
[0013] S4, capability deployment, the capabilities existing in the service chain are deployed on the cloud server of the underlying network to form an anti-DDoS strategy.
[0014] In the step S1, the functions of the anti-DDoS system are softwareized into capabilities, which means that the functions of the underlying network and the hardware devices in the anti-DDoS system are extracted and abstracted into capabilities.
[0015] The capabilities are all deployed in the cloud server in the underlying network.
[0016] The capability includes a traffic-based detection cleaning capability and an IP-based source address management capability.
[0017] The traffic-based detection cleaning capability includes a diversion capability, a detection capability, a cleaning capability and a back-feeding capability.
[0018] The traffic-based detection cleaning capability is used for detecting data traffic in a cloud native system, removing DDoS attack data flow and back-feeding the cleaned traffic in the cloud native system.
[0019] The IP-based source address management capability includes a source address verification capability, a source address detection capability and a black / white list capability.
[0020] The IP-based source address management capability is used for managing the source address of data in a cloud native system and controlling the source address of DDoS attack.
[0021] The capability further includes an intelligence sharing capability.
[0022] The intelligence sharing capability is used for intelligence sharing in a cloud native system.
[0023] The capability of the application refers to a virtualized component abstracted from a traditional anti-DDoS function, which decouples the traditional anti-DDoS function from hardware, realizes network function in a virtualized environment through network programming, uses a management and orchestration system to configure, manage and optimize the virtual network function, and deploys the function in any position of a physical network in a cloud native system in the form of a container.
[0024] The anti-DDoS strategy of the application is realized by abstracting the capability and combining the capability in a set order to form a service chain after the control center analyzes user demand, perceives the current network state of the cloud native system and predicts future attacks, and then deploying the service chain to the cloud native system.
[0025] The anti-DDoS of the application refers to an anti-D.
[0026] The beneficial effects of the application mainly include the following aspects:
[0027] 1、The application, S1, software, software the function of the anti-DDoS system into a capability, form a cover network; S2, strategy automation, the capability is connected in the form of a service chain; S3, service chain takes effect, the corresponding order of each capability execution is specified through the service chain; S4, capability deployment, the capability existing in the service chain is deployed on the cloud server of the underlying network to form an anti-DDoS strategy, compared with the prior art, the anti-DDoS strategy automation can be realized, the anti-DDoS strategy response speed and anti-DDoS efficiency are improved.
[0028] 2、The application abstracts the hardware function of resisting DDoS in the traditional network into software capacity and organizes it systematically, deploys it to the cloud according to the user's needs, forms the overlay network of the anti- DDoS system, and combines and links the capacity on the overlay network in the form of service chain to realize the automatic anti- DDoS strategy, which has high flexibility and elasticity.
[0029] 3、The application abstracts the anti- DDoS system function into various capacities, which are independent of the hardware facilities, and deploys them to the cloud in the form of software to realize the cloud- born anti- DDoS system structure.
[0030] 4、The abstracted capacity in the cloud- born system can form a micro- service chain in sequence and combine into an anti- DDoS strategy, which has automatic capacity.
[0031] 5、The application abstracts the hardware function in the traditional network into various capacities, forms an overlay network, and automatically formulates an anti- DDoS attack strategy according to the user's needs, which is concentrated in a controllable range, and the capacity in the overlay network is combined into an anti- DDoS attack strategy in the form of service chain according to the user's needs through strategy automation, all the capacities in the cloud- born anti- DDoS attack are deployed on the cloud server in the underlying network, which has higher flexibility and expansibility.
[0032] 6、The application can better manage and deploy the distributed anti- DDoS strategy by abstracting the hardware function in the traditional network into various capacities. BRIEF DESCRIPTION OF DRAWINGS
[0033] The application will be further specifically explained in combination with the drawings and specific embodiments in the specification:
[0034] Figure 1 It is a cloud- born deployment schematic diagram in the application;
[0035] Figure 2 It is a strategy automation process schematic diagram in the application. DETAILED DESCRIPTION
[0036] Embodiment 1
[0037] Referring to Figure 1 and Figure 2 A cloud- born anti- DDoS defense method, comprising the following steps:
[0038] S1, software, software the function of anti- DDoS system into capacity, form an overlay network;
[0039] S2, strategy automation, the capacity is connected in the form of service chain;
[0040] S3, service chain validation, the corresponding order of each capability execution is specified through the service chain;
[0041] S4, capability deployment, the capabilities existing in the service chain are deployed on the cloud server of the underlying network to form the anti-DDoS strategy.
[0042] The capability in the application refers to a virtualized component abstracted from a traditional anti-DDoS function, which decouples the traditional anti-DDoS function from hardware, implements network functions in a virtualized environment through network programming, uses a management and orchestration system to configure, manage and optimize virtual network functions, and deploys in a container manner at any position of a physical network in a cloud native system.
[0043] The anti-DDoS strategy in the application is realized by the control center after abstracting the capabilities and combining them in a set order to form a service chain according to the analysis of user demand, the perception of the current network state of the cloud native system and the prediction of future attacks, and then deploying the service chain to the cloud native system.
[0044] The embodiment is the most basic implementation, S1, software, the functions of the anti-DDoS system are software into capabilities to form a coverage network; S2, strategy automation, the capabilities are connected in the form of a service chain; S3, service chain validation, the corresponding order of each capability execution is specified through the service chain; S4, capability deployment, the capabilities existing in the service chain are deployed on the cloud server of the underlying network to form the anti-DDoS strategy, compared with the prior art, the anti-DDoS strategy automation can be realized, and the anti-DDoS strategy response speed and anti-DDoS efficiency are improved.
[0045] Embodiment 2
[0046] Referring to Figure 1 and Figure 2 A cloud native anti-DDoS defense method, comprising the following steps:
[0047] S1, software, the functions of the anti-DDoS system are software into capabilities to form a coverage network;
[0048] S2, strategy automation, the capabilities are connected in the form of a service chain;
[0049] S3, service chain validation, the corresponding order of each capability execution is specified through the service chain;
[0050] S4, capability deployment, the capabilities existing in the service chain are deployed on the cloud server of the underlying network to form the anti-DDoS strategy.
[0051] The capability according to the application refers to a virtualization component abstracted from a traditional anti-DDoS function, decoupling the traditional anti-DDoS function from hardware, implementing network functions in a virtualized environment through network programming, using a management and orchestration system to configure, manage and optimize virtual network functions, and deploying in a container manner at any position of a physical network in a cloud-native system.
[0052] The anti-DDoS strategy according to the application is realized by abstracting the capability and combining the linkage in a set order to form a service chain and then deploying and arranging to the cloud-native system after the control center analyzes user demand, perceives the current network state of the cloud-native system and predicts future attacks.
[0053] In the step S1, the softwareization of the function of the anti-DDoS system into the capability refers to extracting and abstracting the function of the underlying network function and the hardware device in the anti-DDoS system into the capability.
[0054] The embodiment is a preferred embodiment, which abstracts the hardware function of the anti-DDoS in the traditional network into a software capability and systematically organizes it, deploys it to the cloud according to user demand, forms a coverage network of the anti-DDoS system, combines and links the capabilities on the coverage network in the form of a service chain, realizes the automation of the anti-DDoS strategy, and has high flexibility and elasticity.
[0055] Embodiment 3
[0056] Referring to Figure 1 and Figure 2 A cloud-native anti-DDoS defense method comprises the following steps:
[0057] S1, softwareization, softwareizing the function of the anti-DDoS system into a capability to form a coverage network;
[0058] S2, strategy automation, concatenating the capabilities in the form of a service chain;
[0059] S3, service chain validation, specifying the corresponding order of execution of each capability through the service chain;
[0060] S4, capability deployment, deploying the capabilities existing in the service chain on the cloud server of the underlying network to form an anti-DDoS strategy.
[0061] The capability according to the application refers to a virtualization component abstracted from a traditional anti-DDoS function, decoupling the traditional anti-DDoS function from hardware, implementing network functions in a virtualized environment through network programming, using a management and orchestration system to configure, manage and optimize virtual network functions, and deploying in a container manner at any position of a physical network in a cloud-native system.
[0062] The anti-DDoS strategy is realized by the control center after analyzing the user demand, perceiving the current network state of the cloud native system, and predicting future attacks, abstracting the capability, combining the linkage in a set order to form a service chain, and deploying the service chain to the cloud native system.
[0063] In the step S1, the function software of the anti-DDoS system is abstracted as a capability, which means that the functions of the underlying network and the hardware devices in the anti-DDoS system are extracted and abstracted as a capability.
[0064] The capability is deployed in the cloud server in the underlying network.
[0065] The capability includes a traffic-based detection and cleaning capability and an IP-based source address management capability.
[0066] In this embodiment, the functions of the anti-DDoS system are abstracted as a plurality of capabilities, which are decoupled from the hardware facilities and deployed to the cloud in the form of software, so that the cloud native anti-DDoS system structure is realized.
[0067] Embodiment 4
[0068] Referring to Figure 1 and Figure 2 A cloud native anti-DDoS defense method includes the following steps:
[0069] S1, software, software of anti-DDoS system function is abstracted as a capability, and a covering network is formed;
[0070] S2, strategy automation, the capability is connected in the form of a service chain;
[0071] S3, service chain validation, the corresponding order of each capability execution is specified through the service chain;
[0072] S4, capability deployment, the capability existing in the service chain is deployed on the cloud server of the underlying network to form an anti-DDoS strategy.
[0073] The capability is a virtualized component abstracted from the traditional anti-DDoS function, which decouples the traditional anti-DDoS function from the hardware, realizes the network function in the virtualized environment through network programming, uses a management and arrangement system to configure, manage and optimize the virtual network function, and deploys the capability in the form of a container at any position of the physical network in the cloud native system.
[0074] The anti-DDoS strategy is realized by the control center after analyzing the user demand, perceiving the current network state of the cloud native system, and predicting future attacks, abstracting the capability, combining the linkage in a set order to form a service chain, and deploying the service chain to the cloud native system.
[0075] In the step S1, the function of the anti-DDoS system is softwareized into capabilities, which means that the functions of the underlying network and the hardware devices in the anti-DDoS system are extracted and abstracted into capabilities.
[0076] The capabilities are deployed in the cloud server in the underlying network.
[0077] The capabilities include a traffic-based detection and cleaning capability and an IP-based source address management capability.
[0078] The traffic-based detection and cleaning capability includes a diversion capability, a detection capability, a cleaning capability and a back-feeding capability.
[0079] The traffic-based detection and cleaning capability is used to detect the data traffic in the cloud-native system, remove the DDoS attack data flow, and back-feed the cleaned traffic into the cloud-native system.
[0080] In this embodiment, the abstracted capabilities in the cloud-native system can form a micro-service chain in sequence, and are combined into an anti-DDoS strategy, and have an automatic capability.
[0081] Embodiment 5
[0082] Referring to Figure 1 and Figure 2 A cloud-native anti-DDoS defense method includes the following steps:
[0083] S1, softwareization, softwareize the functions of the anti-DDoS system into capabilities to form a cover network;
[0084] S2, strategy automation, string the capabilities in the form of a service chain;
[0085] S3, service chain validation, specify the corresponding sequence of each capability execution through the service chain;
[0086] S4, capability deployment, deploy the capabilities existing in the service chain on the cloud server of the underlying network to form an anti-DDoS strategy.
[0087] The capability in the present application refers to a virtualized component abstracted from a traditional anti-DDoS function, which decouples the traditional anti-DDoS function from the hardware, realizes the network function in a virtualized environment through network programming, uses a management and orchestration system to configure, manage and optimize the virtual network function, and deploys the function in a container in any position of the physical network in the cloud-native system.
[0088] The anti-DDoS strategy is realized by the control center after analyzing the user demand, perceiving the current network state of the cloud native system, and predicting the future attack, abstracting the capability, combining the linkage in a set order to form a service chain, and deploying the service chain to the cloud native system.
[0089] In the step S1, the software function of the anti-DDoS system is softwareized as a capability, which means that the functions of the underlying network and the hardware devices in the anti-DDoS system are extracted and abstracted as a capability.
[0090] The capability is deployed in the cloud server in the underlying network.
[0091] The capability includes a flow-based detection and cleaning capability and an IP-based source address management capability.
[0092] The flow-based detection and cleaning capability includes a diversion capability, a detection capability, a cleaning capability, and a back-feeding capability.
[0093] The flow-based detection and cleaning capability is used to detect the data flow in the cloud native system, remove the DDoS attack data flow, and back-feed the cleaned flow into the cloud native system.
[0094] The IP-based source address management capability includes a source address verification capability, a source address detection capability, and a black and white list capability.
[0095] The IP-based source address management capability is used to manage the source address of the data in the cloud native system and control the source address of the DDoS attack.
[0096] In this embodiment, the hardware functions in the traditional network are abstracted as multiple capabilities to form a coverage network, the anti-DDoS attack strategy is automatically formulated according to the user demand, the anti-DDoS attack strategy is concentrated in a controllable range, and the capability in the coverage network is combined in the form of a service chain according to the order to form an anti-DDoS attack strategy through strategy automation. All capabilities in the cloud native anti-DDoS attack are deployed in the cloud server in the underlying network, which has higher flexibility and expansibility.
[0097] Embodiment 6
[0098] Referring to Figure 1 and Figure 2 A cloud native anti-DDoS defense method includes the following steps:
[0099] S1, softwareization, softwareize the functions of the anti-DDoS system as a capability to form a coverage network;
[0100] S2, strategy automation, string the capability in the form of a service chain;
[0101] S3, service chain is activated, and a corresponding order of each capability execution is defined by the service chain;
[0102] S4, capability deployment, deploying the capabilities existing in the service chain on the cloud server of the underlying network to form an anti-DDoS strategy.
[0103] The capability in the application refers to a virtualized component abstracted from a traditional anti-DDoS function, which decouples the traditional anti-DDoS function from hardware, implements network functions in a virtualized environment through network programming, uses a management and orchestration system to configure, manage and optimize virtual network functions, and deploys in a container manner at any position of a physical network in a cloud native system.
[0104] The anti-DDoS strategy in the application is achieved by abstracting the capabilities and combining them in a set order to form a service chain after the control center analyzes user demand, perceives the current network state of the cloud native system and predicts future attacks, and then deploying the service chain to the cloud native system.
[0105] In the step S1, the function of the anti-DDoS system is softwareized into a capability, which refers to extracting and abstracting the functions of the underlying network and hardware devices in the anti-DDoS system into a capability.
[0106] The capability is deployed in a cloud server in the underlying network.
[0107] The capability includes a traffic-based detection and cleaning capability and an IP-based source address management capability.
[0108] The traffic-based detection and cleaning capability includes a diversion capability, a detection capability, a cleaning capability and a back-feeding capability.
[0109] The traffic-based detection and cleaning capability is used to detect data traffic in the cloud native system, eliminate DDoS attack data streams, and back-feed the cleaned traffic into the cloud native system.
[0110] The IP-based source address management capability includes a source address verification capability, a source address detection capability and a black and white list capability.
[0111] The IP-based source address management capability is used to manage the source addresses of data in the cloud native system and control the source addresses of DDoS attacks.
[0112] The capability also includes an intelligence sharing capability.
[0113] The intelligence sharing capability is used for intelligence sharing in the cloud native system.
[0114] The embodiment is the best mode, and by abstracting hardware functions in a traditional network into various capabilities, distributed DDoS resistance strategies can be better managed and deployed.
[0115] The basic principle of the application is as follows:
[0116] Cloud native: all abstracted capabilities are separated from the hardware devices to which they belong and are deployed in a software form on a cloud server, and the DDoS resistance strategy no longer depends on the hardware device, and has higher scalability and flexibility.
[0117] Strategy automation: the abstracted capabilities can be sequentially formed into a micro-service chain and combined into a DDoS resistance strategy.
[0118] Flexible deployment: all abstracted capabilities in the cloud native are deployed to the cloud, and can be flexibly deployed according to user needs.
[0119] The capability refers to a virtualized component abstracted from a traditional DDoS resistance function, which decouples the traditional DDoS resistance function from the hardware, implements network functions in a virtualized environment through network programming, uses a management and orchestration system such as MANO to configure, manage and optimize the virtual network function, and deploys in a container manner at any position of a physical network in a cloud native system.
[0120] MANO refers to a unified framework for managing various virtual network functions and a basic network virtualization architecture, and is used for service orchestration and device management.
Claims
1. A cloud-native anti-DDoS defense method, characterized in that, Comprise the following steps: S1, software, the function software of anti-DDoS system into the ability, form a cover network; S2, strategy automation, the ability is connected in the form of service chain; S3, service chain takes effect, through the service chain, the corresponding order of each ability execution is stipulated; S4, ability deployment, the ability existing in the service chain is deployed on the cloud server of the underlying network, and the anti-DDoS strategy is formed; In the step S1, the function software of anti-DDoS system into the ability refers to the function of the underlying network and hardware equipment in anti-DDoS system is extracted and abstracted into the ability; The ability is deployed in the cloud server in the underlying network; The ability includes the detection and cleaning ability based on traffic and the source address management ability based on IP.
2. The cloud-native anti-DDoS defense method of claim 1, wherein: The detection and cleaning ability based on traffic includes the ability of diversion, detection, cleaning and back injection.
3. The cloud-native anti-DDoS defense method of claim 2, wherein: The detection and cleaning ability based on traffic is used for detecting the data flow in the cloud native system, eliminating the DDoS attack data flow, and back injecting the cleaned flow into the cloud native system.
4. The cloud-native anti-DDoS defense method of claim 1, wherein: The source address management ability based on IP includes the source address verification ability, the source address detection ability and the black and white list ability.
5. The cloud-native anti-DDoS defense method of claim 4, wherein: The source address management ability based on IP is used for managing the source address of data in the cloud native system and controlling the source address of DDoS attack.
6. The cloud-native anti-DDoS defense method of claim 1, wherein: The ability also includes intelligence sharing ability.
7. The cloud-native anti-DDoS defense method of claim 6, wherein: The intelligence sharing ability is used for intelligence sharing in the cloud native system.
Citation Information
Patent Citations
Service governance method and device based on cloud native, and storage medium
CN114640610A
Software-defined NFV-based security service chain arrangement and deployment method and system
CN114024747A