A DDoS resistance function abstraction method suitable for cloud native system
By abstracting anti-DDoS functionality into two types of capabilities and building a capability pool, and utilizing the policy automation components of cloud-native systems to achieve flexible combination and linkage of functions, the problem of rigid deployment of traditional anti-DDoS systems is solved, and the system's flexibility and response speed are improved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- UNIV OF ELECTRONICS SCI & TECH OF CHINA
- Filing Date
- 2024-08-28
- Publication Date
- 2026-04-10
AI Technical Summary
In existing technologies, anti-DDoS systems lack deployment flexibility, cannot achieve flexible combination and linkage of functions, and traditional hardware deployment results in high costs and rigidity.
The anti-DDoS function is abstracted into two types of capabilities: traffic-based detection and cleaning capabilities and IP-based source address management capabilities. First and second capability pools are constructed and uniformly controlled by the policy automation component of the cloud-native system. The capability configuration is dynamically adjusted according to user needs and network traffic characteristics to achieve flexible combination and linkage of functions.
It enables flexible combination and linkage of anti-DDoS system functions, enhances the system's deployment flexibility and adaptability, and improves response speed and resource utilization efficiency.
Smart Images

Figure CN119210785B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to an anti-DDoS function abstraction method suitable for a cloud native system. BACKGROUND
[0002] DDoS attack, which stands for Distributed Denial of Service attack, is one of the most important attack methods in current network attacks. The characteristic of DDoS attack is that it can quickly exhaust the resources of the target system through a large number of requests, resulting in the inability of the target system to provide normal services. With the popularity of the Internet and the increase of the connection of various devices, the scale and frequency of DDoS attacks are also growing, bringing greater challenges to network security.
[0003] Cloud network convergence refers to the combination of cloud computing and communication network, which fully utilizes the advantages of cloud computing and network. Cloud computing can dynamically adjust resources according to demand, and network realizes fast data transmission and wider coverage, with high flexibility and elasticity. Cloud network convergence develops super computing power to the user end, realizes cloud edge convergence, and realizes full network coverage through central cloud and edge cloud, and maximizes the cloud network capability. Cloud native aims to utilize cloud computing, containerization and microservice technology to build highly flexible and easy-to-manage applications, and fully utilize the potential of cloud computing. Cloud native can deploy applications according to demand, and applications can be flexibly combined and linked, automatically managed, and network functions can be flexibly deployed to improve the response speed and efficiency of applications. Cloud network convergence provides flexible and sufficient basic conditions for various cloud native businesses. On the basis of cloud native, with the concept of software, traditional anti-DDoS is abstracted into capability, breaking through the constraints of existing network structure, realizing flexible combination and linkage of system functions, and having the characteristics of deployment, arrangement, expansion and update, solving the problem of rigid deployment and high cost of traditional hardware.
[0004] A method and device for preventing DDoS attacks based on node cleaning are disclosed in Chinese patent document CN117375942A, published on January 9, 2024. The method comprises: monitoring the network traffic information of the protected server, and analyzing the network traffic information to obtain network abnormal traffic. When the size of the network abnormal traffic exceeds the corresponding defense threshold of the protected server, a preset traffic cleaning node set is obtained, the network abnormal traffic is attracted to the traffic cleaning node set, and the network abnormal traffic is cleaned by a preset traffic cleaning method to obtain a network traffic cleaning result. The network traffic cleaning result includes first target network abnormal traffic and first normal access traffic. According to the preset traffic back-feeding route, the first normal access traffic is back-fed to the protected server.
[0005] The patent document discloses a method and device for preventing DDoS attacks based on node cleaning, which can prevent DDoS attacks. However, the anti-DDoS system has poor deployment flexibility, and cannot realize flexible combination and linkage of anti-DDoS system functions. SUMMARY
[0006] In order to overcome the defects of the prior art, the present application provides an anti-DDoS function abstraction method suitable for a cloud native system, which abstracts the anti-DDoS function as a capability in a coverage network, and uniformly deploys in the coverage network, which has flexible deployment and can realize flexible combination and linkage of anti-DDoS system functions.
[0007] The present application is realized by the following technical solutions:
[0008] An anti-DDoS function abstraction method suitable for a cloud native system, characterized in that it comprises the following steps:
[0009] a. Abstracting the anti-DDoS function into two types of capabilities;
[0010] b. Constructing a first capability pool and a second capability pool according to the classification of the capabilities;
[0011] c. The cloud native system automatically generates rules according to user requirements, and dynamically adjusts the capability configuration according to network traffic characteristics, attack patterns and system security requirements.
[0012] In step a, the two types of capabilities refer to detection and cleaning capabilities based on traffic and source address management capabilities based on IP.
[0013] The detection and cleaning capabilities based on traffic include diversion, detection, cleaning and back-feeding.
[0014] The detection and cleaning capabilities based on traffic are used to detect the data traffic in the cloud native system, eliminate DDoS attack data streams, and back-feeding the cleaned traffic to the cloud native system.
[0015] The source address management capabilities based on IP include source address verification, source address detection, black and white list and trusted source collection.
[0016] The source address management capabilities based on IP are used to manage the source addresses of data in the cloud native system and control the source addresses of DDoS attacks.
[0017] In step b, the first capability pool and the second capability pool are both controlled by a policy automation component of the cloud native system.
[0018] The unified control of the policy automation component refers to that when the user demand occurs, the policy automation component selects corresponding capabilities from the first capability pool and the second capability pool according to the policy, combines and links each capability, and deploys the capability in the cloud native system.
[0019] Any capability in the first capability pool and the second capability pool is independent of each other and is used for independent deployment, allocation, orchestration, expansion and update.
[0020] The detection and cleaning capability based on traffic is located in the first capability pool, and the IP-based source address management capability is located in the second capability pool.
[0021] The capability of the application refers to a virtualized component abstracted from a traditional DDoS resistance function, which decouples the traditional DDoS resistance function from hardware, implements network functions in a virtualized environment through network programming, uses a management and orchestration system to configure, manage and optimize virtual network functions, and deploys in a container manner at any position of a physical network in a cloud native system.
[0022] The policy of the application is realized by the control center after abstracting the capability and combining and linking in a set order to form a service chain according to the analysis of user demand, the perception of the current network state of the cloud native system and the prediction of future attacks, and then deploying to the cloud native system.
[0023] The beneficial effects of the application mainly include the following aspects:
[0024] 1、The application, a, abstracts the DDoS resistance function into two types of capabilities; b, constructs the first capability pool and the second capability pool according to the classification of the capabilities; c, the cloud native system automatically generates rules according to user demand, and dynamically adjusts the capability configuration according to network traffic characteristics, attack patterns and system security requirements, compared with the prior art, the DDoS resistance function is abstracted into a capability in the overlay network, and the DDoS resistance function is flexibly combined and linked in the overlay network.
[0025] 2、The application, the two types of capabilities can be seamlessly migrated and deployed in the cloud native system, and the flexibility of the DDoS attack resistance strategy is enhanced.
[0026] 3、The application, in view of the problem that the current network DDoS resistance strategy is difficult to combine and automatically execute, the capability pool is constructed, the policy automation component of the cloud native system is uniformly controlled, and the DDoS resistance strategy automation can be realized.
[0027] 4、The application, using a cloud server, abstracts the DDoS resistance function in the existing physical network into a capability in the overlay network, each capability can be independently deployed, allocated, orchestrated, expanded and updated, and the deployment is more flexible.
[0028] 5、The cloud native system automatically generates a set of rules according to user requirements, dynamically adjusts the configuration and scale of the capability abstraction according to network traffic characteristics, attack patterns and system security requirements, and realizes the adaptive capability against DDoS attacks. BRIEF DESCRIPTION OF DRAWINGS
[0029] The application will be further described below in conjunction with the accompanying drawings and specific embodiments:
[0030] Figure 1 A functional abstraction diagram in the application;
[0031] Figure 2 A diagram showing the combination of capabilities in the capability pool serving the application. DETAILED DESCRIPTION
[0032] Embodiment 1
[0033] Reference Figure 1 A DDoS-resistant functional abstraction method suitable for a cloud native system, comprising the following steps:
[0034] a. Abstracting the DDoS-resistant function into two types of capabilities;
[0035] b. Constructing a first capability pool and a second capability pool according to the classification of the capabilities;
[0036] c. The cloud native system automatically generates rules according to user requirements, and dynamically adjusts the capability configuration according to network traffic characteristics, attack patterns and system security requirements.
[0037] The capability refers to a virtualized component abstracted from the traditional DDoS-resistant function, which decouples the traditional DDoS-resistant function from the hardware, realizes network functions in a virtualized environment through network programming, uses a management and orchestration system such as MANO to configure, manage and optimize virtual network functions, and deploys them in any location of the physical network in the cloud native system in the form of containers.
[0038] MANO refers to a unified framework for managing various virtual network functions and basic network virtualization architecture, which is used for service orchestration and device management.
[0039] This embodiment is the most basic implementation, a. Abstracting the DDoS-resistant function into two types of capabilities; b. Constructing a first capability pool and a second capability pool according to the classification of the capabilities; c. The cloud native system automatically generates rules according to user requirements, and dynamically adjusts the capability configuration according to network traffic characteristics, attack patterns and system security requirements. Compared with the prior art, the DDoS-resistant function is abstracted into a capability in the overlay network, and is deployed uniformly in the overlay network, which is flexible and can realize flexible combination and linkage of the DDoS-resistant system function.
[0040] Embodiment 2
[0041] Referring to Figure 1 A DDoS resistance function abstraction method suitable for a cloud native system, comprising the following steps:
[0042] a. Abstracting the DDoS resistance function into two types of capabilities;
[0043] b. Constructing a first capability pool and a second capability pool according to the classification of the capabilities;
[0044] c. The cloud native system automatically generates rules according to user requirements, and dynamically adjusts the capability configuration according to network traffic characteristics, attack patterns and system security requirements.
[0045] In the step a, the two types of capabilities refer to traffic-based detection and cleaning capabilities and IP-based source address management capabilities.
[0046] The traffic-based detection and cleaning capabilities include diversion, detection, cleaning and back-feeding.
[0047] The traffic-based detection and cleaning capabilities are used to detect data traffic in the cloud native system, eliminate DDoS attack data streams, and back-feeding the cleaned traffic into the cloud native system.
[0048] The capability refers to a virtualized component abstracted from a traditional DDoS resistance function, which decouples the traditional DDoS resistance function from the hardware, implements network functions in a virtualized environment through network programming, uses a management and orchestration system such as MANO to configure, manage and optimize virtual network functions, and deploys in a container manner at any location of the physical network in the cloud native system.
[0049] MANO refers to a unified framework for managing various virtual network functions and basic network virtualization architecture, which is used for service orchestration and device management.
[0050] This embodiment is a preferred implementation, and the two types of capabilities can be seamlessly migrated and deployed in the cloud native system, enhancing the flexibility of the DDoS attack resistance strategy.
[0051] Embodiment 3
[0052] Referring to Figure 1 A DDoS resistance function abstraction method suitable for a cloud native system, comprising the following steps:
[0053] a. Abstracting the DDoS resistance function into two types of capabilities;
[0054] b. Constructing a first capability pool and a second capability pool according to the classification of the capabilities;
[0055] c、Cloud-Native system automatically generates rules by user demand, and dynamically adjusts the ability configuration according to network traffic characteristics, attack patterns and system security requirements.
[0056] In step a, the two types of capabilities refer to traffic-based detection and cleaning capabilities and IP-based source address management capabilities.
[0057] The traffic-based detection and cleaning capabilities include diversion, detection, cleaning and back-feeding.
[0058] The traffic-based detection and cleaning capabilities are used to detect data traffic in the Cloud-Native system, eliminate DDoS attack data streams, and back-feeding the cleaned traffic into the Cloud-Native system.
[0059] The IP-based source address management capabilities include source address verification, source address detection, black and white list and trusted source collection.
[0060] The IP-based source address management capabilities are used to manage the source address of data in the Cloud-Native system and control the source address of DDoS attacks.
[0061] The capabilities refer to virtualized components abstracted from traditional DDoS resistance functions, decoupling traditional DDoS resistance functions from hardware, implementing network functions in a virtualized environment through network programming, using management and orchestration systems such as MANO to configure, manage and optimize virtual network functions, and deploying in a container manner in any location of the physical network in the Cloud-Native system.
[0062] MANO refers to a unified framework for managing various virtual network functions and basic network virtualization architecture, used for service orchestration and device management.
[0063] This embodiment is another preferred embodiment, which aims to solve the problem that DDoS resistance strategies in current networks are difficult to combine and automatically execute. By constructing a capability pool, the strategy automation component of the Cloud-Native system can uniformly control and achieve DDoS resistance strategy automation.
[0064] Embodiment 4
[0065] Referring to Figure 1 A DDoS resistance function abstraction method suitable for a Cloud-Native system includes the following steps:
[0066] a. Abstract the DDoS resistance function into two types of capabilities;
[0067] b. Construct a first capability pool and a second capability pool according to the classification of capabilities;
[0068] c. The cloud-native system automatically generates rules based on user requirements, and dynamically adjusts the capability configuration based on network traffic characteristics, attack patterns and system security requirements.
[0069] In step a, the two types of capabilities refer to traffic-based detection and cleaning capabilities and IP-based source address management capabilities.
[0070] The traffic-based detection and cleaning capabilities include diversion, detection, cleaning and back-feeding.
[0071] The traffic-based detection and cleaning capabilities are used to detect data traffic in the cloud-native system, eliminate DDoS attack data streams, and back-feed the cleaned traffic into the cloud-native system.
[0072] The IP-based source address management capabilities include source address verification, source address detection, black and white lists and trusted source collection.
[0073] The IP-based source address management capabilities are used to manage the source addresses of data in the cloud-native system and control the source addresses of DDoS attacks.
[0074] In step b, the first capability pool and the second capability pool are both controlled by the policy automation component of the cloud-native system.
[0075] The policy automation component controls specifically refers to when user requirements appear, the policy automation component selects corresponding capabilities from the first capability pool and the second capability pool according to the policy, combines and links each capability, and deploys the capabilities in the cloud-native system.
[0076] The capabilities refer to virtualized components abstracted from traditional DDoS resistance functions, decoupling traditional DDoS resistance functions from hardware, implementing network functions in a virtualized environment through network programming, using management and orchestration systems such as MANO to configure, manage and optimize virtual network functions, and deploying in any location of the physical network in the cloud-native system in the form of containers.
[0077] MANO refers to a unified framework for managing each virtual network function and the underlying network virtualization architecture, used for business orchestration and device management.
[0078] This embodiment is another preferred embodiment, which uses a cloud server to abstract the DDoS resistance functions in the existing physical network into capabilities in the overlay network, and each capability can be independently deployed, allocated, orchestrated, extended and updated, making the deployment more flexible.
[0079] Embodiment 5
[0080] Referring to Figure 1 and Figure 2The application discloses an anti-DDoS function abstraction method suitable for a cloud native system, and comprises the following steps:
[0081] a. abstracting anti-DDoS functions into two types of capabilities;
[0082] b. constructing a first capability pool and a second capability pool according to the classification of the capabilities;
[0083] c. automatically generating rules by the cloud native system according to user demands, and dynamically adjusting capability configurations according to network traffic characteristics, attack modes and system security demands.
[0084] In the step a, the two types of capabilities refer to traffic-based detection and cleaning capabilities and IP-based source address management capabilities.
[0085] The traffic-based detection and cleaning capabilities comprise diversion, detection, cleaning and back-feeding.
[0086] The traffic-based detection and cleaning capabilities are used for detecting data traffic in the cloud native system, removing DDoS attack data streams and back-feeding the cleaned traffic into the cloud native system.
[0087] The IP-based source address management capabilities comprise source address verification, source address detection, black and white list and trusted source collection.
[0088] The IP-based source address management capabilities are used for managing the source addresses of data in the cloud native system and controlling the source addresses of DDoS attacks.
[0089] In the step b, the first capability pool and the second capability pool are both controlled uniformly by a strategy automation component of the cloud native system.
[0090] The uniform control of the strategy automation component specifically refers to that when user demands appear, the strategy automation component selects corresponding capabilities from the first capability pool and the second capability pool according to a strategy, combines and links each capability, and deploys the capabilities in the cloud native system.
[0091] Any capability in the first capability pool and the second capability pool is independent of each other and is used for independent deployment, allocation, arrangement, expansion and update.
[0092] The traffic-based detection and cleaning capabilities are located in the first capability pool, and the IP-based source address management capabilities are located in the second capability pool.
[0093] The capability refers to a virtualization component abstracted from a traditional anti-DDoS function, decoupling the traditional anti-DDoS function from hardware, implementing network functions in a virtualized environment through network programming, using a management and orchestration system such as MANO to configure, manage and optimize virtual network functions, and deploying in a container manner at any location of a physical network in a cloud-native system.
[0094] MANO refers to a unified framework for managing various virtual network functions and a basic network virtualization architecture, for service orchestration and device management.
[0095] The embodiment is the best mode of implementation, and the cloud-native system automatically generates a set of rules according to user requirements, and dynamically adjusts the configuration and scale of capability abstraction according to network traffic characteristics, attack patterns and system security requirements, to realize adaptive capability against DDoS attacks.
[0096] The basic principle of the application is as follows:
[0097] The traditional anti-DDoS function is abstracted into a capability by means of softwareization, to realize flexible service deployment and rapid dynamic response, including building a capability pool to support on-demand allocation and scheduling of capabilities, and using capability abstraction strategies to dynamically adjust resources according to traffic characteristics and attack patterns, thereby improving the overall response speed and resource utilization efficiency of the cloud-native system.
[0098] Abstracting the function into a capability by means of softwareization specifically refers to extracting the security function, collection function, diversion function and back-feeding function attached to the hardware or software environment by means of softwareization, so that the function is separated from its original hardware or software environment, and is transformed into a capability that can be deployed, arranged, expanded and updated, and can be deployed at any location in the cloud-native system. Flexible service deployment is specifically embodied in that the abstracted capability can be deployed at any location in the cloud-native system and adapted to the components in the cloud-native system; rapid dynamic response is specifically embodied in that the abstracted capability can be deployed, arranged, expanded and updated according to user requirements.
[0099] The capability pool is a set composed of multiple abstracted capabilities, each capability in the capability pool is independent of each other, and each capability can be independently deployed, allocated, arranged, expanded and updated; the capability pool is automatically controlled by the strategy automation of the cloud native system, when the user demand appears, the strategy automation selects the corresponding capability from the capability pool according to the generated strategy, combines and links each capability, and deploys the capability in the cloud native system to meet the user demand in the form of a service chain. The capability abstraction strategy is specifically embodied in that the system automatically generates a set of rules according to the user demand, the rules dynamically adjust the configuration and scale of the capability abstraction according to the network traffic characteristics, attack mode and system security demand, and realize the self-adaptive capability of the DDoS attack; the capability abstraction strategy allows the capability to be seamlessly migrated and deployed in the cloud native system, and enhances the flexibility of the anti-DDoS attack strategy.
[0100] The flow-based detection and cleaning capability constructs a capability pool, the capabilities in the capability pool include diversion, detection, cleaning and back-feeding. The strategy automation selects the anti-DDoS strategy composed of capabilities from the capability pool, which is used to detect the data flow in the cloud native system, remove the DDoS attack data flow, and back-feed the cleaned flow to the cloud native system.
[0101] The IP-based source address management capability constructs a capability pool, the capabilities in the capability pool include source address verification, source address detection, black and white list and trusted source collection. The strategy automation selects the anti-DDoS strategy composed of capabilities from the capability pool, which is used to manage the source address of the data in the cloud native system, and control the source address of the DDoS attack.
Claims
1. An anti-DDoS function abstraction method suitable for a cloud-native system, characterized in that, The method comprises the following steps: a. Abstracting the anti-DDoS function into two types of capabilities; b. Constructing a first capability pool and a second capability pool according to the classification of the capabilities; c. The cloud-native system automatically generates rules according to user requirements, and dynamically adjusts the capability configuration according to network traffic characteristics, attack patterns and system security requirements; In step a, the two types of capabilities refer to traffic-based detection and cleaning capabilities and IP-based source address management capabilities; Any capability in the first capability pool and the second capability pool is independent of each other and is used for independent deployment, deployment, arrangement, expansion and update; The traffic-based detection and cleaning capabilities are located in the first capability pool, and the IP-based source address management capabilities are located in the second capability pool; The capability pool is automatically controlled by the strategy automation of the cloud-native system. When user requirements appear, the strategy automation selects corresponding capabilities from the capability pool according to the generated strategy, combines and links each capability, and deploys the capabilities in the cloud-native system in the form of a service chain to meet user requirements. 2.The DDoS defense function abstraction method for cloud-native system of claim 1, wherein: The traffic-based detection and cleaning capabilities include diversion, detection, cleaning and back-feeding. 3.The DDoS defense function abstraction method for cloud-native system of claim 1, wherein: The traffic-based detection and cleaning capabilities are used to detect data traffic in the cloud-native system, remove DDoS attack data streams, and back-feeding the cleaned traffic to the cloud-native system. 4.The DDoS defense function abstraction method for cloud-native system of claim 1, wherein: The IP-based source address management capabilities include source address verification, source address detection, black and white list and trusted source collection. 5.The DDoS defense function abstraction method for cloud-native system of claim 4, wherein: The IP-based source address management capabilities are used to manage the source address of data in the cloud-native system and control the source address of DDoS attacks. 6.The DDoS defense function abstraction method for cloud-native system of claim 1, wherein: In step b, the first capability pool and the second capability pool are both controlled by the strategy automation component of the cloud-native system.
7. The method of claim 6, wherein the method is applied to a cloud-native system. The strategy automation component unified control specifically refers to when user requirements appear, the strategy automation component selects corresponding capabilities from the first capability pool and the second capability pool according to the strategy, combines and links each capability, and deploys the capabilities in the cloud-native system.
Citation Information
Patent Citations
Method and device for preventing DDoS attack based on node cleaning
CN117375942A