A DDoS attack detection method and device based on multi-level traffic analysis
Through the DDoS attack detection method based on multi-level traffic analysis, the characteristics of network requests are collected and monitored in real time, the counters of multiple time windows are updated, and the potential attack requests are determined, which solves the concealment problem of HTTP CC attacks and effectively detects regular small traffic attacks.
Patent Information
- Application Number
- CN202411250561.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-06
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2044-09-06
AI Technical Summary
The prior art is difficult to effectively detect and defend against HTTP CC attacks. This kind of attack is concealed and difficult to identify through traditional firewalls and intrusion detection devices.
The DDoS attack detection method based on multi-level traffic analysis is adopted to collect network layer request characteristics in real time, update counters of multiple time windows at different levels, monitor the count values in the counter in real time, determine potential attack requests, and determine attack requests based on their proportion within the preset time range.
This method can more accurately capture the changing trend of abnormal traffic, identify continuous and low-intensity attacks, solve the problem of difficulty in detecting hidden attacks, and effectively detect regular small traffic attacks.
Smart Images

Figure CN119210802B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a DDoS attack detection method and device based on multi-level traffic analysis. Background Art
[0002] DDoS attack (Distributed Denial of Service Attack) is a common network attack method. The attacker controls a large number of network devices to send a large number of requests to the target server or network, causing the target server to be unable to process the requests of legitimate users and thus unable to provide normal services. The purpose of DDoS attack is to overload, crash or occupy the link bandwidth of the target server, affecting the access of normal users.
[0003] HTTP CC attack (HTTP Challenge Collapsar Attack), also known as HTTP flood attack, is a DDoS attack method targeting web applications. Its purpose is to exhaust server resources, so that normal users cannot access websites or applications. Since HTTP CC attack simulates the requests of normal users, it is highly concealed, making it more difficult to identify and defend against.
[0004] Attackers usually target specific pages or interfaces, or exploit vulnerabilities in websites, such as search functions, to generate a large number of complex queries and HTTP requests, such as GET or POST requests, to increase the load on the target website's Web server or backend application server. For example, using script attack tools to batch generate random client IPs, normal client Get access requests usually request sub-paths that carry resources, such as images, plug-ins, controls, etc., while abnormal access only requests the root path and only sends a small amount of data, but the server needs to return a large amount of data, thus forming an effect similar to an amplification attack. The traffic size and packet volume of these abnormal access requests are similar to those of normal requests, but the link traffic will be regularly bursty, and the attack is often carried out through scattered and irregular IP addresses, using small traffic to trigger intermittent, short-term bursts of covert attacks. Summary of the invention
[0005] In order to detect attack requests more accurately, an embodiment of the present invention provides a DDoS attack detection method and device based on multi-level traffic analysis.
[0006] In a first aspect, an embodiment of the present invention provides a DDoS attack detection method based on multi-level traffic analysis, which may include:
[0007] Collect network requests received by the system to be monitored in real time, and extract network layer request features of the network requests;
[0008] Based on the network layer request feature, the count values in the counters of the preset multiple different layers of time windows are updated;
[0009] Monitor in real time the count values corresponding to the counters of the plurality of different layers of time windows of each network layer request feature to determine potential attack requests;
[0010] Determine attack requests based on the proportion of potential attack requests in all network requests within a preset time range.
[0011] In one or some optional implementations of the embodiment of the present application, the counters of the multiple time windows at different levels are arranged according to the length of the time window;
[0012] The updating of the count values in the counters of the preset multiple time windows of different levels based on the network layer request feature includes:
[0013] Based on the network layer request feature, updating the count value of the corresponding network layer request feature in the first counter;
[0014] Whenever the window period of any preceding counter ends, the data in the preceding counter is accumulated into the succeeding counter, and the data in the preceding counter is reset.
[0015] In one or some optional implementations of the embodiments of the present application, further comprising:
[0016] Every time a preset time interval passes, the count value in the last counter is reduced based on a preset decay factor.
[0017] In one or some optional implementations of the embodiment of the present application, updating the count value of the corresponding network layer request feature in the first counter based on the network layer request feature includes:
[0018] Performing hash mapping on the network layer request feature to obtain a hash value corresponding to the network layer request feature;
[0019] The count value of the hash value in the first counter is updated.
[0020] In one or some optional implementations of the embodiment of the present application, determining the attack request according to the proportion of potential attack requests in all network requests within a preset time range includes:
[0021] Extracting application layer request features of the potential attack request and all network requests within a preset time range to obtain potential attack request features and multiple basic request features;
[0022] Recording the potential attack request feature into a preset potential attack feature counter;
[0023] Recording the basic request feature into a preset total request feature counter;
[0024] Calculate the proportion of the potential attack request feature in the basic request feature based on the count values in the potential attack feature counter and the total request feature counter;
[0025] When the proportion of the potential attack request feature in the basic request feature increases by more than a first preset threshold within a preset short time, marking the potential attack request corresponding to the potential attack request feature as a suspected attack request;
[0026] When the number of suspected attack requests with the same request characteristics exceeds a second preset threshold, the suspected attack requests are regarded as attack requests.
[0027] In one or some optional implementations of the embodiment of the present application, real-time monitoring of the count values corresponding to the counters of the multiple different layers of time windows of each network layer request feature to determine the potential attack request includes:
[0028] Monitor in real time the count value corresponding to each network layer request feature in each counter, and if the count value exceeds a preset threshold value corresponding to the counter, mark the network request corresponding to the network layer request feature as a suspicious request;
[0029] If a network request is marked as a suspicious request in multiple counters, the network request is regarded as a potential attack request.
[0030] In one or some optional implementations of the embodiment of the present application, after determining the attack request, the method further includes:
[0031] Performing cluster analysis on the determined multiple attack requests to obtain multiple attack request behavior features and forming an attack request behavior feature table;
[0032] Isolating the attack request;
[0033] If the request feature of the new network request received by the system to be monitored can match the attack request behavior feature table, the new network request is regarded as an attack request.
[0034] In a second aspect, an embodiment of the present invention provides a DDoS attack detection device based on multi-level traffic analysis, which may include:
[0035] A first extraction module, used for collecting network requests received by the system to be monitored in real time, and extracting network layer request features of the network requests;
[0036] A first updating module, configured to update count values in counters of a plurality of preset time windows at different levels based on the network layer request feature;
[0037] A first determination module is used to monitor in real time the count value corresponding to each network layer request feature in the counters of the multiple different layers of time windows to determine potential attack requests;
[0038] The second determination module is used to determine the attack request according to the proportion of the potential attack request in all network requests within a preset time range.
[0039] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program / instruction stored thereon, which, when executed by a processor, implements the DDoS attack detection method based on multi-level traffic analysis as described above.
[0040] In a fourth aspect, an embodiment of the present invention provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the DDoS attack detection method based on multi-level traffic analysis as described above.
[0041] In a fifth aspect, an embodiment of the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory, wherein when the processor executes the computer program, the DDoS attack detection method based on multi-level traffic analysis as described above is implemented.
[0042] The beneficial effects of the above technical solution provided by the embodiment of the present invention include at least:
[0043] The embodiment of the present invention provides a DDoS attack detection method based on multi-level traffic analysis, which collects network requests received in the system to be monitored in real time, extracts network layer request features of the network requests, and records the count values of all network layer request features through multiple time windows at different levels, thereby determining potential attack requests in the network requests, and then determining the attack requests according to the ratio of the potential attack requests to all network requests within a preset time range. Through multiple time windows at different levels, the method can more keenly capture the changing trend of abnormal traffic. For continuous, low-intensity attacks, the cumulative effect of the time window can be used to identify the abnormal behavior of the gradual accumulation of attack requests, rather than relying on the traffic peak at a single moment, and can effectively detect regular small-traffic attacks, solving the problem of difficult detection of covert attacks.
[0044] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.
[0045] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0047] Figure 1 A schematic diagram of the steps of a DDoS attack detection method based on multi-level traffic analysis provided by an embodiment of the present invention;
[0048] Figure 2 A schematic diagram of a process for detecting potential attack requests using a counter based on multiple time windows provided in an embodiment of the present invention;
[0049] Figure 3 A schematic diagram of the steps for enhancing user behavior analysis provided by an embodiment of the present invention;
[0050] Figure 4 A schematic diagram of clustering behavior analysis steps provided by an embodiment of the present invention;
[0051] Figure 5 A schematic diagram of the structure of a DDoS attack detection device based on multi-level traffic analysis provided in an embodiment of the present application. DETAILED DESCRIPTION
[0052] The exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.
[0053] The inventor found that in the prior art, HTTP CC attacks are often carried out through scattered and irregular IP addresses, and the link traffic presents a regular burst, triggering intermittent, short-term bursts of covert attacks with small traffic. This feature makes it difficult for existing firewalls and intrusion detection equipment to effectively detect and issue alarms, and traditional blocking methods based on IP blacklists are also difficult to deal with. Based on this, the inventor made the present invention after further research and development, providing a DDoS attack detection method and device based on multi-level traffic analysis.
[0054] Embodiment 1
[0055] In the first embodiment of the present invention, a DDoS attack detection method based on multi-level traffic analysis is provided. Figure 1 As shown, the method may include the following steps S101-S104:
[0056] S101: collecting network requests received by the system to be monitored in real time, and extracting network layer request features of the network requests;
[0057] S102: updating count values in counters of a plurality of preset time windows at different levels based on network layer request characteristics;
[0058] S103: monitor in real time the count values corresponding to the counters of each network layer request feature in multiple different layers of time windows to determine potential attack requests;
[0059] S104: Determine the attack request according to the proportion of the potential attack request in all network requests within a preset time range.
[0060] The embodiment of the present invention provides a DDoS attack detection method based on multi-level traffic analysis, which collects network requests received in the monitored system in real time, extracts network layer request features of the network requests, and records the count values of all network layer request features through multiple time windows at different levels, thereby determining potential attack requests in the network requests, and further determining the attack requests according to the ratio of the potential attack requests to all network requests within a preset time range. This method can more keenly capture the changing trend of abnormal traffic through multiple time windows at different levels. For continuous, low-intensity attacks, the cumulative effect of the time window can be used to identify the abnormal behavior of the gradual accumulation of attack requests, rather than relying on the traffic peak at a single moment. It can effectively detect regular small-traffic attacks and solve the problem of difficult detection of covert attacks.
[0061] In the above step S101, network requests received by the system to be monitored are collected in real time, and network layer request features of the network requests are extracted.
[0062] Specifically, the user may initiate a network request to the monitored system through a browser or application, generate a data packet corresponding to the network request, input the data packet into a DPI device (Deep Packet Inspection) to extract the network layer request features of the network request.
[0063] In a specific embodiment, the network layer request characteristics of the network request include the source IP, the request time interval and the request frequency, wherein the request time interval and the request frequency can be obtained through DPI equipment analysis.
[0064] In the embodiment of the present application, the network layer request characteristics of the network request are used for preliminary detection, and only part of the data in the data packet is used. Compared with the detection method of comprehensive data analysis, it can effectively save computing resources and processing time, and lay the foundation for the subsequent rapid screening of potential attack requests.
[0065] In the above step S102, the count values in the counters of the preset multiple time windows of different levels are updated based on the network layer request characteristics, and the counters of the multiple time windows of different levels are arranged from small to large according to the length of the time window. Specifically, the following steps S1021-S1022 are included:
[0066] S1021: Based on the network layer request feature, update the count value of the first counter corresponding to the network layer request feature.
[0067] Specifically, the network layer request feature is hash mapped to obtain the hash value corresponding to the network layer request feature, and then the hash value is retrieved in the first counter to determine whether the network layer request feature corresponding to the hash value appears repeatedly. If so, the count value of the hash value in the counter is increased by 1; if not, the hash value is added to the counter and the count value is set to 1.
[0068] S1022: Whenever the window period of any preceding counter ends, the data in the preceding counter is accumulated into the succeeding counter, and the data in the preceding counter is reset.
[0069] Specifically, whenever the window period of any preceding counter ends, the data in the preceding counter is accumulated in the succeeding counter. Specifically, it is retrieved whether there is the same hash value in the succeeding counter and the preceding counter. For the hash value already existing in the succeeding counter, the count value of the hash value is added and stored in the succeeding counter. For the hash value not existing in the succeeding counter, the hash value and the corresponding count value are added to the succeeding counter. Finally, the data in the preceding counter is cleared and reset.
[0070] Those skilled in the art may preset counters of multiple time windows at different levels according to the detailed description of the prior art, such as using a counting Bloom filter (CBF), which may not be specifically limited in the embodiments of the present application.
[0071] To facilitate technical personnel in this field to understand the present solution, the specific implementation process of the counter update method described in step S102 provided in the embodiment of the present application is illustrated below by way of example. Counters for three different levels of time windows are preset, namely ShortTermWindow CBF, MidTermWindow CBF and LongTermWindow CBF. The window periods of the three counters are 1 second, 1 minute and 5 minutes respectively.
[0072] In the process of real-time collection of network requests received by the monitored system, each time a new network request is received, the network layer request feature corresponding to the network request is hash mapped to obtain the corresponding hash value, and the count value in the ShortTermWindow CBF is updated. Whenever the window period of the ShortTermWindow CBF ends, that is, 1 second has passed since the last reset, the data in the ShortTermWindow CBF is accumulated in the MidTermWindow CBF, and the ShortTermWindow CBF is reset. Similarly, whenever the window period of the MidTermWindow CBF ends, that is, 1 minute has passed since the last reset, the data in the MidTermWindow CBF is accumulated in the LongTermWindow CBF, and the MidTermWindow CBF is reset.
[0073] In the embodiment of the present application, it should also be noted that the data in the last counter will not be cleared and reset to prevent some normal but frequent network requests from being mistakenly marked as suspicious requests. The count value in the last counter can be decayed every preset time interval, which can be achieved by setting a preset decay factor. Taking the above-mentioned setting of 3 counters as an example, the decayed count value in the last counter LongTermWindow CBF is calculated based on the following formula 1:
[0074] Count decay =Count*(decay_factor steps )Formula 1
[0075] In the formula, count decay is the count value after decay, count is the count value before decay, decay_factor is the preset decay factor, and steps is the number of times LongTermWindow CBF updates data after the last decay. The calculation method is shown in the following formula 2:
[0076]
[0077] Wherein, int represents rounding calculation, time_diff is the preset time interval, and window is the time interval for LongTermWindowCBF to update data, that is, the window period of the previous counter MidTermWindowCBF.
[0078] In a specific embodiment, the preset decay factor decay_factor is equal to 0.999, the preset time interval time_diff is equal to 150 seconds, and the time interval window for LongTermWindow CBF to update data is equal to 1 minute. According to Formula 2, steps can be calculated to be equal to 2, which means that LongTermWindow CBF has performed 2 data updates. If the count value of a hash value is 100, the decayed count value count corresponding to the hash value is decay =100*0.999 2 ≈99.8.
[0079] In the above step S103, the count values corresponding to each network layer request feature in the counters of multiple different layers of time windows are monitored in real time to determine potential attack requests.
[0080] Specifically, the count value corresponding to each network layer request feature in each counter may be monitored in real time, and if the count value exceeds a preset threshold corresponding to the counter, the network request corresponding to the network layer request feature is marked as a suspicious request. Furthermore, if a network request is marked as a suspicious request in multiple counters, the network request is regarded as a potential attack request.
[0081] In order to facilitate those skilled in the art to understand the present solution, the specific implementation process of the example corresponding to the above steps S101-S103 provided in the embodiment of the present application is described more clearly and completely below. Figure 2 As shown, starting from the top, the DPI device receives a data packet of a network request and extracts network layer request features in the data packet, corresponding to the above step S101.
[0082] In this example, the module composed of counters of three time windows is called TimeWindowStats module. The model includes three counters, namely ShortTermWindow CBF, MidTermWindow CBF and LongTermWindowCBF. For ShortTermWindow CBF, the corresponding count in ShortTermWindow CBF is updated based on the network layer request characteristics, and the count value in ShortTermWindow CBF is monitored. If it exceeds the corresponding preset threshold, the network request corresponding to the network layer request characteristics exceeding the preset threshold is marked as a suspicious request. For MidTermWindow CBF, every time the window period of ShortTermWindow ends, the data in ShortTermWindow CBF is accumulated into MidTermWindowCBF, ShortTermWindow CBF is reset, and the count value in MidTermWindow CBF is monitored. If it exceeds the corresponding preset threshold, the network request corresponding to the network layer request characteristics exceeding the preset threshold is marked as a suspicious request. Similarly, for LongTermWindow CBF, whenever the window period of MidTermWindowCBF ends, the data in MidTermWindow CBF is accumulated into LongTermWindow CBF, MidTermWindow CBF is reset, and the count value in LongTermWindow CBF is monitored. If it exceeds the corresponding preset threshold, the network request corresponding to the network layer request feature that exceeds the preset threshold is marked as a suspicious request.
[0083] Combined with the detection results of ShortTermWindow CBF, MidTermWindow CBF and LongTermWindowCBF, detect whether there is a network request marked as a suspicious request in the counters of multiple time windows. If so, mark the network request as a potential attack request. If not, continue monitoring.
[0084] In the embodiment of the present application, counters of different levels of time windows are set to capture the behavior of traffic on different time scales, so as to simultaneously monitor burst traffic in short time periods and continuous traffic attack patterns in long time periods. In this way, instantaneous traffic anomalies and their possible attack behaviors can be detected more accurately, and long-term accumulated attack patterns can also be identified, thereby providing more comprehensive network security protection. This multi-level monitoring strategy not only improves the detection capability of various attack types, but also optimizes resource utilization efficiency, which helps to respond to and handle potential network threats more quickly.
[0085] In the above step S104, the attack request is determined according to the proportion of the potential attack request in all network requests within the preset time range. Specifically, the following steps S1041-S1046 are included:
[0086] S1041: Extract application layer request features of potential attack requests and all network requests within a preset time range to obtain potential attack request features and multiple basic request features.
[0087] The preset time range is equal to the window period of the longest time window counter in step S102, such as 5 minutes. The application layer request characteristics include the number of requests of the IP address, the request type, the access path, and the request header.
[0088] S1042: Record the potential attack request feature into a preset potential attack feature counter.
[0089] S1043: Record the basic request feature into a preset total request feature counter.
[0090] S1044: Based on the count values in the potential attack feature counter and the total request feature counter, calculate the proportion of the potential attack request feature in the basic request feature.
[0091] S1045: When the proportion of the potential attack request feature in the basic request feature increases abnormally, that is, when the proportion increases by more than a first preset threshold within a preset short time, the potential attack request corresponding to the potential attack request feature is marked as a suspected attack request.
[0092] In a specific embodiment, when the proportion of a potential attack request feature in the basic request feature increases by more than 10% within 1 minute, the potential attack request corresponding to the potential attack request feature is marked as a suspected attack request, and the response to the network request with the same request feature as the suspected attack request is reduced.
[0093] S1046: When the number of suspected attack requests with the same request characteristics exceeds a second preset threshold, the suspected attack request is regarded as an attack request.
[0094] In order to facilitate those skilled in the art to understand the present solution, the specific implementation process of the above step S104 provided in the embodiment of the present application is described more clearly and completely below. Figure 3As shown, first, two counters are initialized, namely the potential attack request feature counter and the total request feature counter, and then the application layer request feature of the potential attack request determined in the above step S103 is loaded into the potential attack request feature counter. Similarly, the application layer request features of all network requests within the preset time range are loaded into the total request feature counter, corresponding to the above steps S1041-S1043. Next, monitor whether the proportion of potential attack request features in the total requests increases abnormally. If so, mark it as a suspected attack request and reduce the response to the same type of network requests. If not, continue monitoring, corresponding to the above steps S1044-S1045. Finally, monitor whether the number of suspected attack requests exceeds the threshold. If so, mark it as an attack request. If not, continue monitoring, corresponding to the above step S1046.
[0095] In the embodiment of the present application, the method further analyzes the potential attack request by strengthening the user behavior analysis through step S104, which effectively improves the detection efficiency. Two counters are initialized to respectively record the request characteristics of the potential attack request and all network requests within the preset time range, and monitor the proportion of each potential attack request characteristic in all network requests. When the proportion of a potential attack request characteristic increases abnormally, it is marked as a suspected attack request and the response priority is reduced. This mechanism avoids in-depth analysis of all request data and saves computing resources. At the same time, by setting a threshold to further judge the suspected attack request, the attack detection is more accurate.
[0096] In the embodiment of the present application, after the attack request is determined, cluster analysis can be performed on all the attack requests to facilitate rapid identification and isolation of the determined attack requests, which specifically includes the following steps S1047-S1049:
[0097] S1047: Perform cluster analysis on the determined multiple attack requests to obtain multiple attack request behavior features to form an attack request behavior feature table.
[0098] Specifically, it can be that a cluster analysis is performed on multiple determined attack requests, and based on the similarities of the attack requests, such as the same URL path, similar request headers, access frequency within the request time window, etc., the attack requests are clustered into multiple clusters, that is, multiple attack request behavior features, to form an attack request behavior feature table.
[0099] S1048: Isolate the attack request.
[0100] Specifically, for an identified attack request, isolation is implemented based on Advanced Filter, and CAPTCHA or other forms of challenge response tests are used to verify whether the request initiator is a human. If the verification is passed, the isolation of the attack request is cancelled and monitoring continues. If the verification is not passed, it is proved that the attack request is an automated attack request and isolation continues.
[0101] S1049: If the request feature of the new network request received by the to-be-monitored system can match the attack request behavior feature table, the new network request is regarded as an attack request.
[0102] In an embodiment of the present application, the attack request can be isolated by Advanced Filter (data screening tool). For the isolated request, the monitored system can use CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) or other forms of challenge response tests to verify whether the request initiator is a human user, so as to distinguish automated attack requests from requests generated by actual users.
[0103] In order to facilitate those skilled in the art to understand the present solution, the specific implementation process of the above steps S1047-S1048 provided in the embodiment of the present application is described more clearly and completely below. Figure 4 As shown, first, attack requests are classified into specific clusters based on similarity, attack request behavior characteristics are recorded, and the attack request behavior characteristic table Cluster Behavior Analysis Table is maintained, which corresponds to the above step S1047. Next, for the identified attack requests, isolation is implemented based on Advanced Filter, and CAPTCHA or other forms of challenge response tests are used to verify whether the request initiator is a human. If so, the isolation of the attack request is cancelled and monitoring continues. If not, it is proved that the attack request is an automated attack request and isolation continues, which corresponds to the above step S1048.
[0104] In the embodiment of the present application, the method performs clustering behavior analysis on the determined attack requests through steps S1047-S1049, identifies unified attack behaviors based on indicators such as the total number of clients, regional distribution, request size, and data packet volume during each peak, groups the attack requests, and classifies them into specific clusters based on the similarities of the requests, such as the same URL path, similar request headers, and access frequency within the request time window. This not only improves the accuracy and efficiency of identifying attack requests, but also ensures that the access experience of normal users is not affected, thereby enhancing the security and stability of the system.
[0105] Embodiment 2
[0106] Based on the same inventive concept, the embodiment of the present invention also provides a DDoS attack detection device based on multi-level traffic analysis, referring to Figure 5 As shown, the device comprises:
[0107] The first extraction module 101 is used to collect network requests received by the system to be monitored in real time and extract network layer request features of the network requests;
[0108] A first updating module 102, configured to update count values in counters of a plurality of preset time windows at different levels based on the network layer request feature;
[0109] The first determination module 103 is used to monitor in real time the count value corresponding to each network layer request feature in the counters of the multiple different layer time windows to determine potential attack requests;
[0110] The second determination module 104 is used to determine the attack request according to the proportion of the potential attack request in all network requests within a preset time range.
[0111] Embodiment 3
[0112] Based on the same inventive concept, an embodiment of the present invention further provides a computer-readable storage medium on which a computer program / instruction is stored. When the computer program / instruction is executed by a processor, the DDoS attack detection method based on multi-level traffic analysis as described in the above-mentioned embodiment 1 is implemented.
[0113] Embodiment 4
[0114] Based on the same inventive concept, an embodiment of the present invention further provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the DDoS attack detection method based on multi-level traffic analysis as described in the above-mentioned embodiment 1.
[0115] Embodiment 5
[0116] Based on the same inventive concept, an embodiment of the present invention further provides a computer device, including a memory, a processor, and a computer program stored in the memory. When the processor executes the computer program, the DDoS attack detection method based on multi-level traffic analysis as described in the above embodiment 1 is implemented.
[0117] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.
[0118] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0119] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0120] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0121] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A DDoS attack detection method based on multi-level traffic analysis, characterized in that: include: Collect network requests received by the system to be monitored in real time, and extract network layer request features of the network requests; Based on the network layer request feature, updating the count value of the corresponding network layer request feature in the first counter; Whenever a window period of any preceding counter ends, the data in the preceding counter is accumulated into the succeeding counter, and the data in the preceding counter is reset; Monitor in real time the count values corresponding to each network layer request feature in the counters of multiple time windows at different levels to determine potential attack requests; the counters of the multiple time windows at different levels are arranged according to the length of the time windows; Determine attack requests based on the proportion of potential attack requests in all network requests within a preset time range.
2. The method according to claim 1, characterized in that Also includes: Every time a preset time interval passes, the count value in the last counter is reduced based on a preset decay factor.
3. The method according to claim 1, characterized in that The updating of the count value of the corresponding network layer request feature in the first counter based on the network layer request feature includes: Hash mapping the network layer request feature to obtain a hash value corresponding to the network layer request feature; The count value of the hash value in the first counter is updated.
4. The method according to claim 1, characterized in that: Determining the attack request according to the proportion of the potential attack request in all network requests within a preset time range includes: Extracting application layer request features of the potential attack request and all network requests within a preset time range to obtain potential attack request features and multiple basic request features; Recording the potential attack request feature into a preset potential attack feature counter; Recording the basic request feature into a preset total request feature counter; Calculate the proportion of the potential attack request feature in the basic request feature based on the count values in the potential attack feature counter and the total request feature counter; When the proportion of the potential attack request feature in the basic request feature increases by more than a first preset threshold within a preset short time, marking the potential attack request corresponding to the potential attack request feature as a suspected attack request; When the number of suspected attack requests with the same request characteristics exceeds a second preset threshold, the suspected attack requests are regarded as attack requests.
5. The method according to claim 1, characterized in that The real-time monitoring of the count values corresponding to the counters of the multiple different layers of time windows of each network layer request feature to determine the potential attack request includes: Monitor in real time the count value corresponding to each network layer request feature in each counter, and if the count value exceeds a preset threshold value corresponding to the counter, mark the network request corresponding to the network layer request feature as a suspicious request; If a network request is marked as a suspicious request in multiple counters, the network request is regarded as a potential attack request.
6. The method according to claim 1, characterized in that After the attack request is determined, it also includes: Performing cluster analysis on the determined multiple attack requests to obtain multiple attack request behavior features and forming an attack request behavior feature table; Isolating the attack request; If the request feature of the new network request received by the system to be monitored can match the attack request behavior feature table, the new network request is regarded as an attack request.
7. A DDoS attack detection device based on multi-level traffic analysis, characterized in that: include: A first extraction module, used for collecting network requests received by the system to be monitored in real time, and extracting network layer request features of the network requests; A first updating module, configured to update a count value of a first counter corresponding to the network layer request feature based on the network layer request feature; Whenever a window period of any preceding counter ends, the data in the preceding counter is accumulated into the succeeding counter, and the data in the preceding counter is reset; The first determination module is used to monitor in real time the count values corresponding to each network layer request feature in the counters of multiple different layers of time windows to determine potential attack requests; the counters of the multiple different layers of time windows are arranged according to the length of the time windows; The second determination module is used to determine the attack request according to the proportion of the potential attack request in all network requests within a preset time range.
8. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instruction is executed by a processor, the DDoS attack detection method based on multi-level traffic analysis described in any one of claims 1 to 6 is implemented.
9. A computer device comprising a memory, a processor and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the DDoS attack detection method based on multi-level traffic analysis according to any one of claims 1 to 6.
Citation Information
Patent Citations
Attack detection device and attack detection method
JP2019126003A
Baselining techniques for detecting anomalous https traffic behavior
US20210194903A1