Method, device and equipment for resource scheduling in defending against attack in multi-autonomous domain network
By locking decision variables in a multi-autonomous domain network, establishing objective functions and constraints, and using the block joint descent method to iteratively solve resource allocation, the problem of unreasonable resource scheduling during DDoS attacks in existing technologies is solved, achieving optimal resource allocation and effective network defense.
Patent Information
- Application Number
- CN202411312566.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-19
- Publication Date
- 2025-12-26
- Estimated Expiration
- 2044-09-19
AI Technical Summary
Existing technologies cannot achieve timely and reasonable resource scheduling when defending against DDoS attacks in multi-autonomous domain networks, thus failing to mitigate the impact of attacks to the greatest extent.
By locking decision variables, establishing objective functions and constraints, and using the block joint descent method to iteratively solve the resource allocation of each autonomous region, the resource allocation is ensured to minimize the impact of attacker resource consumption while satisfying the constraints.
This improves the targeting and feasibility of resource scheduling schemes for multi-autonomous domain networks (MAVs) in defending against DDoS attacks, enhances defense efficiency, and ensures network service availability.
Smart Images

Figure CN119210835B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a resource scheduling method, device and equipment for defending against attacks in a multi-autonomous domain network. BACKGROUND
[0002] With the development of the Internet of Things (IoT), there are more and more devices in the network that lack security mechanisms. Security vulnerabilities of these devices make them more likely to be controlled by hackers through malicious programs, thereby building a botnet and launching a Distributed Denial of Service (DDoS) attack. The history of DDoS attacks is long, but in recent years, as the hacking ability increases, the damage caused by DDoS attacks is also increasing. Many network scenarios such as the Internet of Things, space-based networks, and industrial Internet of Things have become hotspots of DDoS attacks. From an industry perspective, governments, medical care, finance, education, and cultural entertainment are all possible targets of hackers. DDoS attacks mainly achieve the effect of denial of service by exhausting the resources in the target network, which means that if the resources can be optimally scheduled in a timely and reasonable manner when an attack is encountered, the impact of DDoS attacks can be minimized.
[0003] Current measures to curb DDoS attacks often focus on sharing or transferring blacklisted addresses between different autonomous domains. When an autonomous domain is attacked, malicious IP addresses are discovered in a timely manner, and these malicious IP addresses are also intercepted in other autonomous domains. However, this scheme cannot achieve optimal scheduling of resources in a timely and reasonable manner. SUMMARY
[0004] The purpose of the present application is to provide a resource scheduling method, device and equipment for defending against attacks in a multi-autonomous domain network. To solve the problem that the existing scheme for defending against DDoS attacks cannot achieve optimal scheduling of resources in a timely and reasonable manner.
[0005] In a first aspect, an embodiment of the present application provides a resource scheduling method for defending against attacks in a multi-autonomous domain network, the method comprising:
[0006] When a DDoS attack is detected, the resources to be allocated in each autonomous domain are locked as decision variables;
[0007] The total sum of resources occupied by the attacker in each attacked autonomous domain is determined as the objective function;
[0008] The range of resources that can be allocated in each autonomous domain according to the total sum of resources in the multi-autonomous domain is determined as a constraint condition, and the resources to be allocated in each autonomous domain are determined not to exceed the corresponding resource range.
[0009] The decision variables of each autonomous domain are combined into blocks, and each block is solved iteratively by block joint descent method to minimize the objective function under the constraints;
[0010] At the end of the iteration, the decision variables in the blocks of each autonomous domain are used to allocate resources to the autonomous domain.
[0011] In some possible embodiments, the resources to be allocated to each autonomous domain in the network are locked as decision variables, including:
[0012] At least one of the bandwidth resources B i , the computing processing resources C i and the memory storage resources M i to be allocated to each autonomous domain in the network are locked as decision variables;
[0013] Wherein, i=1,2,…,n, n is the number of autonomous domains in the network, and i is the number of autonomous domains.
[0014] In some possible embodiments, the total of the resources occupied by the attacker to each attacked autonomous domain in the network is determined as the objective function, including:
[0015] The sum of the basic idle resource item and the attack information item is determined, and then the resource coupling item is subtracted to obtain the objective function;
[0016] Wherein, the basic idle resource item is the sum of the proportions of the total resources of the multi-autonomous domain to the resources remaining outside the service provided by the multi-autonomous domain in the network;
[0017] The attack information item is used to represent the resource consumption of the attacked autonomous domain according to the DDos attack launched by the attacker, and the coupling relationship of different resources of the attacked autonomous domain is determined;
[0018] The resource coupling item is used to represent the ability of other autonomous domains in the network to provide resource support to the attacked autonomous domain.
[0019] In some possible embodiments, the basic idle resource item is:
[0020]
[0021] Wherein, X(B1,C1,M1,…,B n ,C n ,M n ) is the basic idle resource item, B max is the total bandwidth resources of the multi-autonomous domain, C max is the total computing processing resources of the multi-autonomous domain, M max is the total memory storage resources of the multi-autonomous domain, and Bi.0 Bandwidth resource needed for maintaining basic network services for the ith autonomous domain, B i.0 Computing processing resource needed for maintaining basic network services for the ith autonomous domain, M i.0 Memory storage resource needed for maintaining basic network services for the ith autonomous domain.
[0022] In some possible embodiments, the attack information item is:
[0023]
[0024] where Y(B j ,C j ,M j ) is the attack information item, a is the first correction coefficient, V is the consumption of bandwidth resource of the jth attacked autonomous domain by the DDos attack launched by the attacker, R is the consumption of computing processing resource of the jth attacked autonomous domain by the DDos attack launched by the attacker, D is the consumption of memory storage resource of the jth attacked autonomous domain by the DDos attack launched by the attacker, s B is the adjustment factor of bandwidth resource, s C is the adjustment factor of computing processing resource, s M is the adjustment factor of memory storage resource.
[0025] In some possible embodiments, the resource coupling item is:
[0026]
[0027] where Z(B1,C1,M1,…,B n ,C n ,M n ) is the resource coupling item, β is the second correction coefficient, s B is the adjustment factor of bandwidth resource, s C is the adjustment factor of computing processing resource, s M is the adjustment factor of memory storage resource, B max is the total bandwidth resource of the multi-autonomous domain, C max is the total computing processing resource of the multi-autonomous domain, M max is the total memory storage resource of the multi-autonomous domain.
[0028] In some possible embodiments, the constraint condition comprises:
[0029] B i ≤B max -B i,0 , C i ≤C max -C i,0 , Mi ≤M max -M i,0 ;
[0030] B max is the total bandwidth resource of the multiple autonomous domains, C max is the total computing processing resource of the multiple autonomous domains, M max is the total memory storage resource of the multiple autonomous domains, B i.0 is the bandwidth resource required by the ith autonomous domain to maintain the basic network service, C i.0 is the computing processing resource required by the ith autonomous domain to maintain the basic network service, M i.0 is the memory storage resource required by the ith autonomous domain to maintain the basic network service.
[0031] In some possible embodiments, each block is solved iteratively by using the block coordinate descent method, including:
[0032] When triggering a new round of iteration, each block of each autonomous domain is optimized one by one, wherein the block of the current autonomous domain is optimized while the blocks of other autonomous domains are fixed;
[0033] When the current round of iteration ends, if the difference between the blocks of each autonomous domain in the last two rounds is less than a set threshold, or the number of iterations reaches a set number, or the objective function is less than a set target value, the iteration is stopped, otherwise a new round of iteration is triggered.
[0034] In a second aspect, the embodiments of the present application provide a resource scheduling device for defending against attacks in a multiple autonomous domain network, including:
[0035] A decision variable locking module is configured to lock the resources to be allocated to each autonomous domain in the network as decision variables when a DDoS attack is detected;
[0036] An objective function determining module is configured to determine the total resource occupation of each attacked autonomous domain in the network by an attacker as an objective function;
[0037] A constraint condition determining module is configured to determine, as a constraint condition, that the resources to be allocated to each autonomous domain do not exceed the corresponding resource range according to the resource range of each autonomous domain determined based on the total resources of the multiple autonomous domains;
[0038] A block solving module is configured to combine the decision variables of each autonomous domain into blocks, and solve each block iteratively by using the block coordinate descent method to minimize the objective function under the constraint condition;
[0039] A resource allocation module is configured to allocate resources to each autonomous domain according to the decision variables in the block of the autonomous domain when the iteration ends.
[0040] In a third aspect, another embodiment of the present application further provides a resource scheduling device for defending against DDoS attacks in a multi-autonomous domain network, comprising at least one processor; and a memory connected to the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform any of the resource scheduling methods for defending against DDoS attacks in a multi-autonomous domain network provided by the embodiments of the present application.
[0041] In a fourth aspect, another embodiment of the present application further provides a computer storage medium storing a computer program for causing a computer to execute any of the resource scheduling methods for defending against DDoS attacks in a multi-autonomous domain network provided by the embodiments of the present application.
[0042] The resource scheduling method, device and equipment for defending against DDoS attacks in a multi-autonomous domain network provided by the embodiments of the present application can improve the pertinence of the scheme by locking the variable factors that can be used for scheduling and distribution, improve the actual value of the scheme by establishing a target function to determine the mapping relationship between the real physical world and the theoretical model, further narrow the optimization range and improve the feasibility of the scheme by determining the maximum and minimum values of each resource that can be used for distribution according to the total sum of the resources of the multi-autonomous domain, and improve the overall defense efficiency of the defense party from the macro defense perspective by using the iterative solving optimization mechanism based on the block joint descent method to block the decision variables according to the autonomous domain, iteratively updating the decision variables of each block, and solving out the optimal resource combination that each autonomous domain should have when resisting attacks through multiple rounds of cyclic iteration.
[0043] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the following description, or can be learned by practice of the present application. The objects and other advantages of the present application can be realized and achieved by the structure particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF DRAWINGS
[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings needed to be used in the embodiments of the present application will be briefly introduced as follows. Obviously, the drawings introduced below are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without any creative effort on the basis of these drawings.
[0045] Figure 1 a schematic diagram of an application environment according to an embodiment of the present application;
[0046] Figure 2 a flowchart of a resource scheduling method for defending against DDoS attacks in a multi-autonomous domain network according to an embodiment of the present application;
[0047] Figure 3 a flowchart of an iterative solution optimization process based on a block joint descent method according to an embodiment of the present application;
[0048] Figure 4 a flowchart of a resource scheduling method when defending against a DDoS attack in a multi-autonomous domain network according to an embodiment of the present application;
[0049] Figure 5 a block diagram of a resource scheduling device when defending against a DDoS attack in a multi-autonomous domain network according to an embodiment of the present application;
[0050] Figure 6 a block diagram of a resource scheduling device when defending against a DDoS attack in a multi-autonomous domain network according to an embodiment of the present application. DETAILED DESCRIPTION
[0051] To further illustrate the technical solutions provided by the embodiments of the present application, the following will be described in detail in conjunction with the accompanying drawings and specific embodiments. Although the embodiments of the present application provide the following method operation steps as shown in the embodiments or the accompanying drawings, more or fewer operation steps can be included in the method based on conventional or non-creative labor. The execution order of the steps is not limited to the execution order provided by the embodiments of the present application in the logical sense. The method can be executed in sequence or in parallel when the actual processing process or the control device is executed according to the method order shown in the embodiments or the accompanying drawings.
[0052] The existing network space can often be divided into multiple autonomous systems (AS), and for an autonomous system, it can be further divided into network regions or sub-domains. When a hacker conducts a DDoS attack on a network target in an autonomous system, resources of other autonomous systems can be called to mitigate it, or distributed optimization can be performed through resource scheduling of multiple autonomous systems to achieve the purpose of stopping DDoS attacks to the maximum extent.
[0053] However, there is no solution in the related art to theoretically analyze and optimize the relevant network resources needed to defend against attacks. If the scenario can be established as a convex optimization problem, and the method of distributed optimization is used to iteratively optimize the coupled multiple key network resource variables, the actual physical scenario can be modeled, a convex function model can be constructed, and the block joint descent method can be used to solve it to obtain the optimal solution of the function under certain constraints, providing theoretical support for the joint resource scheduling and allocation strategy between multiple autonomous domains.
[0054] The application scenario of the resource scheduling method in the multi-autonomous domain network when defending against attacks provided by the embodiments of the present application is shown in Figure 1 As shown in the figure, the multi-autonomous domain network includes autonomous domain AS1, autonomous domain AS2, and autonomous domain AS3, an attacker initiates a DDoS attack against autonomous domain AS1, and the attacked autonomous domain AS1 produces resource consumption. In this network scenario, when the hacker sends DDoS attack traffic from autonomous domain AS1 into the entire network, the defender needs to timely adjust the resource allocation scheme for each autonomous domain to maintain the availability of the network, while preparing to implement other related security measures.
[0055] The technical terms involved in the embodiments of the present application are explained as follows:
[0056] IoT (Internet of Things): "Internet of everything", is the extension and expansion of the Internet network, realizing the interconnection and intercommunication of people, machines and things at any time and any place.
[0057] DDoS (Distributed denial of service): Distributed denial of service attack refers to that multiple attackers at different locations simultaneously attack one or several targets, or an attacker controls multiple machines at different locations and uses these machines to attack the victim at the same time.
[0058] Convex Optimization: Convex optimization is a subfield of mathematical optimization that studies the minimization of convex functions defined on convex sets. Convex optimization is applied in many disciplines, such as automatic control systems, signal processing, communication and network, electronic circuit design, data analysis and modeling, statistics (optimal design), and finance.
[0059] AS (Autonomous system): Autonomous domain refers to the combination of all IP networks and routers under the jurisdiction of one or more entities in the Internet, which jointly implement the same routing policy.
[0060] Block Coordinate Descent: Block Coordinate Descent is a method that groups problem variables into several "blocks" and iteratively optimizes each block. In each iteration, the variables of one or more blocks are optimized while the variables of other blocks are fixed. This method is particularly suitable for optimization problems with strong coupling between variables but tighter coupling within blocks.
[0061] The embodiment of the present application provides a resource scheduling method in a multi-autonomous domain network when defending against an attack, in order to fill the blank of lacking theoretical guidance in the joint resource scheduling of multiple autonomous domains when defending against a DDoS attack in the existing network. The embodiment of the present application is combined with a real network scenario, and a target function to be optimized is established by combining a convex optimization theory. Decision variables are locked by using attack characteristics and network resources. Constraint conditions are determined based on multiple limiting factors. The block joint descent method is used to decouple and iteratively solve the problem, so that the optimal allocation of resources of each autonomous domain is realized. Theoretical basis is provided for subsequent optimization and adjustment of the defense strategy and determination of the available resource range in each autonomous domain, the valuable resources in the network are protected, and the service availability of the user is ensured.
[0062] As shown in Figure 2 The resource scheduling method in a multi-autonomous domain network when defending against an attack provided by the embodiment of the present application comprises the following steps.
[0063] In step 201, when a DDoS attack is detected, the resources to be allocated to each autonomous domain in the network are locked as decision variables.
[0064] At present, in order to achieve the effect of denial of service, the existing DDoS attack can basically be considered as consuming the related resources of the autonomous domain in the network to achieve the effect of denial of service. Therefore, in the embodiment of the present application, the decision variables are locked by using attack information and main resource types, the related network resources which play a significant role in resisting attacks are determined, and the decision variables are set as the resources to be allocated to each autonomous domain. In the embodiment of the present application, the resources to be allocated to each autonomous domain are the resources allocated to each autonomous domain after the resource scheduling is performed, and the resources to be allocated are the resources determined from the available resources. The available resources do not include the resources required to maintain the basic network service of the autonomous domain.
[0065] In step 202, the sum of the resources occupied by the attacker to each attacked autonomous domain in the network is determined as a target function.
[0066] The resources in each autonomous domain can include at least one resource, and the resources are determined according to the resources required to provide network services. When the attacker launches a DDoS attack on the autonomous domain, the attacked autonomous domain will have corresponding resource consumption. In the embodiment of the present application, the sum of the resources occupied by the attacker to each attacked autonomous domain in the network is determined as a target function. If the sum of the resources occupied by the attacker to each attacked autonomous domain in the network is minimum, the effect of denial of service can be achieved.
[0067] In step 203, the range of the resources to be allocated to each autonomous domain is determined according to the sum of the resources of the multiple autonomous domains, and the resources to be allocated to each autonomous domain are determined as constraint conditions, which do not exceed the corresponding resource range.
[0068] The total sum of the resources of the multiple autonomous domains is the total sum of the resources available in the autonomous domain network, based on which the range of the allocable resources of each autonomous domain can be determined, and the constraint condition is that the to-be-allocated resources of each autonomous domain do not exceed the corresponding resource range.
[0069] In step 204, the decision variables of each autonomous domain are combined into blocks, and the block joint descent method is used to iteratively solve each block under the condition of satisfying the constraint condition and with the goal of minimizing the objective function.
[0070] When the resources of an autonomous domain include multiple items, the multiple decision variables of the autonomous domain are combined into blocks, and the block joint descent method is used to iteratively solve each block. When determining the values of the blocks after iteration, the constraint condition needs to be satisfied and the goal is to minimize the objective function. For specific iterative calculation methods, refer to the calculation methods of the block joint descent method in related technologies, which will not be described in detail in this embodiment.
[0071] In step 205, when the iteration is completed, the decision variables in the blocks of each autonomous domain are used to allocate resources to the autonomous domain.
[0072] According to the optimization solution of the decision variables in the blocks of each autonomous domain, the optimal resource allocation scheme of each sub-domain is determined, and the network resources of the sub-domain are deployed to resist DDoS attacks.
[0073] In this embodiment, the resources of each autonomous domain are locked as decision variables. Specifically, according to different types of main resources of each autonomous domain in the network and the influence and attack mode of DDoS attacks on the network, the variable factors that can be used for scheduling and allocation are locked to improve the pertinence of the scheme. A target function establishment method is proposed. According to the influence mode of DDoS attacks on the multiple autonomous domain network, a target function that maps the total sum of the resources occupied by the attackers in each attacked autonomous domain in the network is established to determine the mapping relationship between the real physical world and the theoretical model and improve the practical value of the scheme. A constraint condition determination method is proposed. According to the total sum of the resources of the multiple autonomous domains, the maximum and minimum values of each resource of the autonomous domain that can be deployed are determined to further narrow the optimization range and improve the feasibility of the scheme. An iterative optimization mechanism based on the block joint descent method is proposed. The decision variables are blocked according to the autonomous domain to which they belong, and then the decision variables of each block are iteratively updated. The optimal resource combination that each autonomous domain should have when resisting attacks is iteratively solved through multiple rounds of iteration, which improves the overall defense efficiency of the defense party from a macro defense perspective.
[0074] Based on this, in the existing multiple autonomous domain network scenario, the maximum resources owned or deployable by the defense party are combined with the attack information of the attacker to quickly calculate the most effective resource deployment scheme required to resist attacks, which provides a theoretical basis for the defense of each autonomous domain in the subsequent stage, protects the network resources, and ensures the service availability of users.
[0075] In some possible embodiments, the resources to be allocated to each autonomous domain in the network are locked as decision variables, including at least one of bandwidth resources B i , computing processing resources C i , and memory storage resources M i to be allocated to each autonomous domain in the network are locked as decision variables.
[0076] wherein i = 1, 2, …, n, n is the number of autonomous domains in the network, and i is the number of the autonomous domain.
[0077] The existing DDoS attack can basically be considered as the consumption of bandwidth resources, computing processing resources, and storage resources in the network by the attacker to achieve the effect of denial of service. Therefore, in the embodiments of the present application, the decision variables are set as the bandwidth resources, computing processing resources, and memory storage resources of each autonomous domain. The defender needs to allocate these resources to mitigate the network, and therefore the decision variables in the embodiments of the present application are set as the bandwidth resources B i , computing processing resources C i , and memory storage resources M i allocated to each autonomous domain when defending against the attack, wherein i = 1, 2, …, n, and n is the number of autonomous domains in the network.
[0078] After the decision variables are determined, the most critical step is to determine the objective function. According to the convex optimization theory, a multi-factor coupled objective function is established, and the size of each type of resource that should be allocated to different autonomous domains is obtained through the objective function. The attacker performs DDoS on several autonomous domains to consume their resources, and therefore the objective function is set as the total consumption of each type of resource of each attacked autonomous domain in the network by the attacker, denoted as G. In order to properly simplify the model while ensuring its practical significance, according to the resource consumption of the attacker as described above, the objective function in the embodiments of the present application is divided into three parts, namely a basic idle resource item, a resource coupling item, and an attack information item. The basic idle resource item is the sum of the proportion of the remaining resources of the multi-autonomous domain to the total resources of the multi-autonomous domain when providing services in the network; the attack information item is used to represent the resource consumption of the attacked autonomous domain according to the DDoS attack launched by the attacker, and to determine the coupling relationship of different resources of the attacked autonomous domain; and the resource coupling item is used to represent the ability of other autonomous domains in the network to provide resource support to the attacked autonomous domain. The sum of the basic idle resource item and the attack information item is subtracted by the resource coupling item to obtain the objective function.
[0079] The ultimate goal of the embodiments of the present application is to minimize the objective function G to minimize the influence of the resource occupation of the attacker through reasonable allocation of resources. The objective function G can be represented as:
[0080]
[0081] wherein X(B1,C1,M1,…,B n ,C n ,M n ) is a basic idle resource item, Y(B j ,C j ,M j ) is an attack information item, and Z(B1,C1,M1,…,B n ,C n ,M n ) is a resource coupling item.
[0082] In some possible embodiments, the basic idle resource item is:
[0083]
[0084] wherein B max is the total bandwidth resource of the multiple autonomous domains, C max is the total computing processing resource of the multiple autonomous domains, M max is the total memory storage resource of the multiple autonomous domains, B i.0 is the bandwidth resource required by the ith autonomous domain to maintain the basic network service, C i.0 is the computing processing resource required by the ith autonomous domain to maintain the basic network service, M i.0 is the memory storage resource required by the ith autonomous domain to maintain the basic network service, ω b is the proportion weight of the bandwidth resource in the degree of influence of the network service, ω c is the proportion weight of the computing processing resource in the degree of influence of the network service, and ω m is the proportion weight of the memory storage resource in the degree of influence of the network service. The above proportion weights are determined according to the network-related conditions, and the proportion weight of the network resource sensitive to the network service provision can be set to be larger, or the same value can be used. The basic idle resource item mainly represents the proportion sum of each resource remaining in each autonomous domain in addition to the service provision, and the sum of the proportions of the autonomous domains is obtained. The more unbalanced this part is, the larger the objective function is, indicating that the influence of the attacker on the network is greater, and vice versa.
[0085] In some possible embodiments, the attack information item is:
[0086]
[0087] Where α is the first correction coefficient, V is the bandwidth resource consumption of the attacked j-th autonomous system by the DDoS attack launched by the attacker, R is the computational processing resource consumption of the attacked j-th autonomous system by the DDoS attack launched by the attacker, D is the memory storage resource consumption of the attacked j-th autonomous system by the DDoS attack launched by the attacker, and s B As a factor for adjusting bandwidth resources, s C To calculate the adjustment factor for processing resources, s M This refers to the adjustment factor for memory storage resources. The adjustment factor can be set according to the impact of the resources; a larger adjustment factor is set for resources with a greater impact. The first correction coefficient mentioned above is a set parameter. The attack information item mainly represents the coupling relationship between different resources of the attacked autonomous system. For the j-th autonomous system being attacked, the fewer resources it has relative to the attacker's strength, the greater the impact of the attack, and the larger the objective function.
[0088] In some possible embodiments, the above resource coupling term is:
[0089]
[0090] Where Z(B1,C1,M1,…,B) n C n M n ) represents the resource coupling term, β is the second correction coefficient, and s B As a factor for adjusting bandwidth resources, s C To calculate the adjustment factor for processing resources, s M B is a factor for adjusting memory storage resources. max C represents the total bandwidth resources of multiple autonomous domains. max M represents the total computing resources required for multiple autonomous domains. max This represents the total memory storage resources of multiple autonomous systems. The second correction coefficient mentioned above is a set parameter. The functional relationship here expresses the resource support capability of other autonomous systems in the network relative to the attacked autonomous system. The larger this part is, the more reasonable the resource allocation is, and the smaller the corresponding objective function is.
[0091] In some possible embodiments, the above constraints include:
[0092] B i ≤B max -B i,0 C i ≤C max -C i,0 M i ≤M max -M i,0 ;
[0093] B maxC is the sum of bandwidth resources of the multiple autonomous domains max M is the sum of computing processing resources of the multiple autonomous domains max B is the sum of memory storage resources of the multiple autonomous domains i.0 C is the bandwidth resource required by the i-th autonomous domain to maintain basic network services i.0 M is the computing processing resource required by the i-th autonomous domain to maintain basic network services i.0 B is the memory storage resource required by the i-th autonomous domain to maintain basic network services. The maximum value of the resource to be allocated is limited by the above constraint conditions. The significance of these constraints is mainly to limit the resource scheduling range of each autonomous domain, i.e., not to exceed the maximum available amount of the whole network, so that the whole model is closer to the real situation, and the practical value of the optimized resource allocation scheme is increased.
[0094] In some possible embodiments, the block joint descent method is used to iteratively solve each block, including:
[0095] When triggering a new round of iteration, each block of each autonomous domain is optimized one by one, wherein the blocks of other autonomous domains are fixed when optimizing the block of the current autonomous domain;
[0096] When the current round of iteration ends, if the block difference of each autonomous domain in the last two rounds is less than a set threshold, or the number of iterations reaches a set number, or the objective function is less than a set target value, the iteration is stopped, otherwise a new round of iteration is triggered.
[0097] After the objective function, the decision variable and the constraint condition are determined, the block joint descent method can be used to solve the model. The block standard of the decision variable is determined in the embodiments of the present application. The bandwidth resource B i , the computing resource C i and the memory storage resource M iThe decision variables are divided into several blocks, and the number of blocks is the same as the number of autonomous domains. In addition, the initial values of the decision variables are set, for example, the resources are evenly distributed at the initial time. Then the whole process is divided into multiple iterations, and each iteration is performed on each block. When iterating on a block, multiple decision variables in the block are iterated simultaneously. In each iteration of a block, the variables of other blocks are fixed, and only the variables of the current block are optimized. When calculating the optimal solution of the decision variables of the current block by regarding the decision variables of other blocks as constants, the method of using the partial derivative of the objective function with respect to the variables of the current block to obtain the extreme point can be used. The specific calculation process can be referred to the related technical description, which will not be repeated here. After completing the iteration of all blocks in a round, the next iteration is started. Until the difference between the results of two consecutive iterations is less than a set threshold, that is, the change of all decision variables is less than the set threshold, the iteration is stopped. Or when other iteration stopping conditions are met, such as the number of iterations exceeds a set number or the objective function is less than a set target value, the iteration is stopped, and the final decision variables are output as the resource allocation scheme.
[0098] As shown in Figure 3 The iteration process for solving the convex optimization problem by using the block joint descent method mainly includes: setting the initial iteration values of the decision variables according to the constraint conditions; starting a new round of iteration, and updating each variable, i.e., the bandwidth resource B, the computing processing resource C, and the memory storage resource M, according to the above process; calculating the difference values of the decision variables B, C, and M of adjacent two rounds at the end of the round; if the difference values are all less than a set threshold, it is determined that the termination condition is met, and the optimal resource allocation scheme is output, otherwise the next round of iteration is triggered.
[0099] The following gives a specific example of the resource scheduling method provided by the embodiment of the application when defending against attacks in a multi-autonomous-domain network, as shown in Figure 4 The method mainly includes:
[0100] Step 401: The types of resources of each autonomous domain that can be called, such as bandwidth resources, computing processing resources, and memory storage resources, are determined, so as to lock the decision variables.
[0101] The subsequent optimization of the embodiment of the application is achieved by adjusting different types of resources of different autonomous domains, and finally the optimal defense effect is achieved. For example, there are 5 sub-autonomous domains in the network, and n=5.
[0102] Step 402: The objective function is established according to the convex optimization theory and the actual network environment. The objective function is the sum of the resource occupation of each attacked autonomous domain in the network by the attacker, and the minimum of the objective function represents the influence of reducing the attack degree of the attacker to the minimum;
[0103] The specific establishment of the objective function is described in the above embodiments, which will not be repeated here.
[0104] Step 403, determine the maximum value of all decision variables currently possessed in the network, thereby determining the constraint condition;
[0105] If the currently attacked autonomous domain is AS1, and the bandwidth resource available in the network is 10Tbps (10Tbits per second), the computing resource is 100000RPS (100000 requests per second), and the memory storage resource is 1TB. If a mixed DDoS attack is suffered at this time, with the intensity of 5000Gbps, 50000RPS, it will occupy 500GB of memory. And at the same time, each other autonomous domain has its own service task, in order to meet the service load in ordinary times, it needs to consume bandwidth resource 500Gbps, computing resource 5000RPS, and memory resource 5GB. Then the range of the available bandwidth resource B i , the available computing resource C i , and the available memory storage resource M i can be determined, i.e. the to-be-allocated bandwidth resource does not exceed the available bandwidth resource, the available bandwidth resource is the total bandwidth resource of the multiple autonomous domains minus the bandwidth resource required for maintaining the basic network service, the to-be-allocated computing resource does not exceed the available computing resource, the available computing resource is the total computing resource of the multiple autonomous domains minus the computing resource required for maintaining the basic network service, and the to-be-allocated memory storage resource does not exceed the available memory storage resource, the available memory storage resource is the total memory storage resource of the multiple autonomous domains minus the memory storage resource required for maintaining the basic network service.
[0106] Step 404, after the objective function, the decision variable, and the constraint condition are determined, the command center will start the calculation of the optimal allocation scheme of the network resource under the current attack according to the set program. The block descent method is used to solve the decision variable of different autonomous domains.
[0107] After setting the initial iteration starting value, the resource iteration solution for each autonomous domain is started. The starting value can be the result of the average allocation. And the iteration number t max is set to 500, or the difference between the allocation schemes of the two consecutive iterations is less than the threshold value such as tol B =10, tol C =20, tol C =5, then the iteration is stopped, and the B i , C i , and M i of each autonomous domain at this time are output, i.e. the optimal allocation scheme is obtained.
[0108] At step 405, according to the optimization solution, a resource optimal allocation scheme is determined to allocate network resources to each autonomous domain to resist DDoS attacks.
[0109] Based on the same inventive concept, the application further provides a resource scheduling device for resisting attacks in a multi-autonomous domain network, as shown in the accompanying drawings, comprising: Figure 5
[0110] A decision variable locking module 501 is configured to lock the resources to be allocated to each autonomous domain in the network as decision variables when a DDoS attack is detected;
[0111] A target function determining module 502 is configured to determine the total resource occupation of each attacked autonomous domain in the network by an attacker as a target function;
[0112] A constraint condition determining module 503 is configured to determine that the resources to be allocated to each autonomous domain do not exceed the corresponding resource range as a constraint condition according to the resource range of each autonomous domain determined by the total resources of the multi-autonomous domain;
[0113] A block solving module 504 is configured to combine the decision variables of each autonomous domain into blocks, and iteratively solve each block by using a block joint descent method to minimize the target function under the constraint condition;
[0114] A resource allocation module 505 is configured to allocate resources to each autonomous domain according to the decision variables in the block of each autonomous domain when the iteration ends.
[0115] In some possible embodiments, the resources to be allocated to each autonomous domain in the network are locked as decision variables, comprising:
[0116] At least one of the bandwidth resources B i , the computing processing resources C i and the memory storage resources M i to be allocated to each autonomous domain in the network is locked as a decision variable;
[0117] Wherein i=1, 2, …, n, n is the number of autonomous domains in the network, and i is the number of autonomous domains.
[0118] In some possible embodiments, the target function determining module determines the total resource occupation of each attacked autonomous domain in the network by an attacker as a target function, comprising:
[0119] Determining the sum of the basic idle resource item and the attack information item, and then subtracting the resource coupling item to obtain the target function;
[0120] Wherein, the basic idle resource item is the sum of the proportion of the resources remaining outside the service provided by the multi-autonomous domain in the total resources of the multi-autonomous domain;
[0121] The attack information item is used to represent resource consumption of the attacked autonomous domain according to the DDos attack launched by the attacker, and the coupling relationship of different resources of the determined attacked autonomous domain;
[0122] The resource coupling item is used to represent the ability of other autonomous domains in the network to provide resource support relative to the attacked autonomous domain.
[0123] In some possible embodiments, the basic idle resource item is:
[0124]
[0125] Wherein, X(B1, C1, M1, …, B n ,C n ,M n ) is the basic idle resource item, B max is the total bandwidth resource of the multi-autonomous domain, C max is the total computing processing resource of the multi-autonomous domain, M max is the total memory storage resource of the multi-autonomous domain, B i.0 is the bandwidth resource required by the i-th autonomous domain to maintain basic network services, C i.0 is the computing processing resource required by the i-th autonomous domain to maintain basic network services, and M i.0 is the memory storage resource required by the i-th autonomous domain to maintain basic network services.
[0126] In some possible embodiments, the attack information item is:
[0127]
[0128] Wherein, Y(B j ,C j ,M j ) is the attack information item, a is the first correction coefficient, V is the consumption of the bandwidth resource of the j-th attacked autonomous domain by the DDos attack launched by the attacker, R is the consumption of the computing processing resource of the j-th attacked autonomous domain by the DDos attack launched by the attacker, D is the consumption of the memory storage resource of the j-th attacked autonomous domain by the DDos attack launched by the attacker, s B is the adjustment factor of the bandwidth resource, s C is the adjustment factor of the computing processing resource, and s M is the adjustment factor of the memory storage resource.
[0129] In some possible embodiments, the resource coupling item is:
[0130]
[0131] wherein, Z(B1,C1,M1,…,B n , C n , M n ) is a resource coupling term, β is a second correction coefficient, s B is an adjustment factor of bandwidth resources, s C is an adjustment factor of computing processing resources, s M is an adjustment factor of memory storage resources, B max is a total of bandwidth resources of the multiple autonomous domains, C max is a total of computing processing resources of the multiple autonomous domains, M max is a total of memory storage resources of the multiple autonomous domains.
[0132] In some possible embodiments, the constraint conditions include:
[0133] B i ≤ B max i i,0 , C i ≤ C max i i,0 , M i ≤ M max i i,0 ;
[0134] B max is a total of bandwidth resources of the multiple autonomous domains, C max is a total of computing processing resources of the multiple autonomous domains, M max is a total of memory storage resources of the multiple autonomous domains, B i.0 is bandwidth resources required by the i-th autonomous domain to maintain basic network services, C i.0 is computing processing resources required by the i-th autonomous domain to maintain basic network services, M i.0 is memory storage resources required by the i-th autonomous domain to maintain basic network services.
[0135] In some possible embodiments, the block solving module iteratively solves each block by using a block joint descent method, including:
[0136] When triggering a new round of iteration, each block of each autonomous domain is optimized one by one, wherein the blocks of other autonomous domains are fixed when optimizing the block of the current autonomous domain;
[0137] When the current round of iteration ends, if the difference between the blocks of each autonomous domain in the last two rounds is less than a set threshold, or the number of iterations reaches a set number, or the objective function is less than a set target value, the iteration is stopped, otherwise a new round of iteration is triggered.
[0138] After introducing the resource scheduling method and device for defending DDoS attack in a multi-autonomous domain network according to the exemplary embodiments of the present application, next, the resource scheduling device for defending DDoS attack in a multi-autonomous domain network according to another exemplary embodiment of the present application is introduced.
[0139] Those skilled in the art can understand that various aspects of the present application can be implemented as a system, a method or a program product. Therefore, various aspects of the present application can be embodied as a whole hardware embodiment, a whole software embodiment (including firmware, microcode, etc.), or an embodiment combining hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" herein.
[0140] In some possible embodiments, the resource scheduling device for defending DDoS attack in a multi-autonomous domain network according to the present application can at least include at least one processor and at least one memory. The memory stores program codes, which, when executed by the processor, cause the processor to perform the steps of the resource scheduling method for defending DDoS attack in a multi-autonomous domain network according to various exemplary embodiments of the present application described above in the specification.
[0141] The resource scheduling device for defending DDoS attack in a multi-autonomous domain network according to this embodiment of the present application will be described below with reference to Figure 6 Figure 6 The displayed resource scheduling device for defending DDoS attack in a multi-autonomous domain network 160 is only an example, and should not bring any limitation to the functions and use range of the embodiments of the present application.
[0142] As shown in Figure 6 , the resource scheduling device for defending DDoS attack in a multi-autonomous domain network 160 is in the form of a general electronic device. The components of the resource scheduling device for defending DDoS attack in a multi-autonomous domain network 160 can include, but are not limited to, the above-mentioned at least one processor 161, the above-mentioned at least one memory 162, and a bus 163 connecting different system components, including the memory 162 and the processor 161.
[0143] The bus 163 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a processor or a local bus using any of the bus structures.
[0144] The memory 162 can include a readable medium in the form of a volatile memory, such as a random access memory (RAM) 1621 and / or a cache memory 1622, and can further include a read-only memory (ROM) 1623.
[0145] The memory 132 can also include a program / utility 1625 having a set (at least one) of program modules 1624, including but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which can include implementations of the network environment, alone or in combination.
[0146] The resource scheduling device for defending DDoS attack in multi-autonomous domain network 160 can also communicate with one or more external devices 164 (such as a keyboard, a pointing device, etc.), and can also communicate with one or more devices that enable a user to interact with the resource scheduling device for defending DDoS attack in multi-autonomous domain network 160, and / or any devices (such as a router, a modem, etc.) that enable the resource scheduling device for defending DDoS attack in multi-autonomous domain network 160 to communicate with one or more other electronic devices. Such communication can be via the input / output (I / O) interface 165. Also, the resource scheduling device for defending DDoS attack in multi-autonomous domain network 160 can communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via the network adapter 166. As shown, the network adapter 166 communicates with the other modules of the resource scheduling device for defending DDoS attack in multi-autonomous domain network 160 via the bus 163. It should be appreciated that although not shown, other hardware and / or software modules could be used in connection with the resource scheduling device for defending DDoS attack in multi-autonomous domain network 160, including but not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.
[0147] In some possible embodiments, various aspects of the method for resource scheduling for defending DDoS attack in multi-autonomous domain network provided by the present application can also be implemented as a program product in the form of a computer program or programs, which program or programs are used to cause a computer device to perform the steps of the method for resource scheduling for defending DDoS attack in multi-autonomous domain network according to various exemplary embodiments of the present application described above in the specification.
[0148] The program product of the embodiments of the present application for resource scheduling in defending DDoS attacks in a multi-autonomous domain network can employ any combination of one or more computer readable media or storage media. The computer readable media or storage media can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0149] The program product of the embodiments of the present application for resource scheduling in defending DDoS attacks in a multi-autonomous domain network can employ any combination of one or more computer readable media or storage media. The computer readable media or storage media can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0150] The computer readable signal medium can include a computer readable data signal embodied in a carrier wave, or a propagated signal, that establishes communication between a computing device and a remote computing device. Such a propagated signal can take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or acoustical waves including without limitation radio frequency signals, infrared signals, optical signals, or acoustical signals. The computer readable signal medium can be any computer readable medium that is not a computer readable storage medium and that can communicate with a computing device or a remote computing device, such as the Internet, wireless media, or any suitable combination of the foregoing.
[0151] While the preferred embodiments of the application have been described, additional variations and modifications can be made to the embodiments without departing from the spirit and scope of the application. Therefore, it should be understood that the appended claims are intended to cover all such modifications and variations as falling within the scope of the application. It is intended that each element recited in the claims covers all the equivalent elements or modifications of this element. It is intended that the disclosure and examples presented herein be considered as illustrative only, and that the scope of the application is to be indicated by the appended claims, with claim scope being interpreted without use of the learning effect doctrine.
[0152] Obviously, various modifications and changes can be made to the present application by those skilled in the art without departing from the spirit and scope of the present application. Thus, it is intended that the present application embrace all such modifications and changes and, accordingly, the application is not to be construed as limited to the embodiments described herein.
Claims
1. A resource scheduling method for defending against attacks in a multi-autonomous domain network, characterized in that, The method comprises: locking the resources to be allocated to each autonomous domain in the network as decision variables when a DDoS attack is detected; determining the total sum of the resources occupied by the attacker to each attacked autonomous domain in the network as a target function; determining the range of the resources to be allocated to each autonomous domain according to the total sum of the resources of the multiple autonomous domains, and determining that the resources to be allocated to each autonomous domain do not exceed the corresponding resource range as a constraint condition; combining the decision variables of each autonomous domain into blocks, and iteratively solving each block by using a block joint descent method under the condition that the constraint condition is met and the target function is minimized; allocating resources to each autonomous domain according to the decision variables in the block of the autonomous domain when the iteration ends; determining the total sum of the resources occupied by the attacker to each attacked autonomous domain in the network as a target function, comprising: summing the basic idle resource item and the attack information item, and then subtracting the resource coupling item to obtain the target function; wherein the basic idle resource item is the total sum of the proportions of the resources remaining outside the service provided by the multiple autonomous domains in the network to the total sum of the resources of the multiple autonomous domains; the attack information item is used to represent the coupling relationship of different resources of the attacked autonomous domain determined according to the resource consumption of the attacked autonomous domain caused by the DDoS attack launched by the attacker; the resource coupling item is used to represent the ability of other autonomous domains in the network to provide resource support relative to the attacked autonomous domain.
2. The method of claim 1, wherein, locking the resources to be allocated to each autonomous domain in the network as decision variables, comprising: at least one of bandwidth resources , computing processing resources and memory storage resources to be allocated to the autonomous domains of the network are locked as decision variables; wherein , is the number of autonomous domains in the network, i is the number of autonomous domain.
3. The method of claim 2, wherein, the basic idle resource item is: wherein, is a basic idle resource item, is a total bandwidth resource of the multiple autonomous domains, is a total computing processing resource of the multiple autonomous domains, is a total memory storage resource of the multiple autonomous domains, is a bandwidth resource required for the ith autonomous domain to maintain a basic network service, is a computing processing resource required for the ith autonomous domain to maintain a basic network service, is a memory storage resource required for the ith autonomous domain to maintain a basic network service.
4. The method of claim 2, wherein, the attack information item is: wherein, is an attack information item, is a first correction coefficient, V is the consumption of bandwidth resources of the jth attacked autonomous domain by the DDos attack launched by the attacker, R is the consumption of computing processing resources of the jth attacked autonomous domain by the DDos attack launched by the attacker, D is the consumption of memory storage resources of the jth attacked autonomous domain by the DDos attack launched by the attacker, is an adjustment factor of bandwidth resources, is an adjustment factor of computing processing resources, is an adjustment factor of memory storage resources.
5. The method of claim 2, wherein, the resource coupling item is: wherein, is a resource coupling item, is a second correction coefficient, is an adjustment factor for bandwidth resources, is an adjustment factor for computing processing resources, is an adjustment factor for memory storage resources, is a total of bandwidth resources for multiple autonomous domains, is a total of computing processing resources for multiple autonomous domains, is a total of memory storage resources for multiple autonomous domains.
6. The method of claim 2, wherein, the constraint condition comprises: 、 、 ; a sum of bandwidth resources for the multiple autonomous domains, a sum of computing processing resources for the multiple autonomous domains, a sum of memory storage resources for the multiple autonomous domains, a bandwidth resource required for the ith autonomous domain to maintain a basic network service, a computing processing resource required for the ith autonomous domain to maintain a basic network service, a memory storage resource required for the ith autonomous domain to maintain a basic network service.
7. The method of claim 1, wherein, iteratively solving each block by using a block joint descent method, comprising: when triggering a new round of iteration, optimizing each block of each autonomous domain one by one, wherein the optimization of the block of the current autonomous domain is fixed with the blocks of other autonomous domains unchanged; when the iteration of the current round ends, if the difference between the blocks of each autonomous domain in the last two rounds is less than a set threshold, or the number of iterations reaches a set number, or the target function is less than a set target value, stopping the iteration, otherwise triggering a new round of iteration.
8. A resource scheduling device for defending against attacks in a multi-autonomous domain network, characterized in that, comprising: a decision variable locking module configured to lock the resources to be allocated to each autonomous domain in the network as decision variables when a DDoS attack is detected; a target function determining module configured to determine the total sum of the resources occupied by the attacker to each attacked autonomous domain in the network as a target function; a constraint condition determining module configured to determine the range of the resources to be allocated to each autonomous domain according to the total sum of the resources of the multiple autonomous domains, and determine that the resources to be allocated to each autonomous domain do not exceed the corresponding resource range as a constraint condition; a block solving module configured to combine the decision variables of each autonomous domain into blocks, and iteratively solve each block by using a block joint descent method under the condition that the constraint condition is met and the target function is minimized; a resource allocation module configured to allocate resources to each autonomous domain according to the decision variables in the block of the autonomous domain when the iteration ends; determining the total sum of the resources occupied by the attacker to each attacked autonomous domain in the network as a target function, comprising: summing the basic idle resource item and the attack information item, and then subtracting the resource coupling item to obtain the target function; The basic idle resource item is the sum of the proportion of the total resources of the multi-autonomous domain to the total resources of the multi-autonomous domain which are left after providing services in the network. The attack information item is used to represent the resource consumption of the attacked autonomous domain according to the DDos attack launched by the attacker, and the coupling relationship of different resources of the attacked autonomous domain determined; The resource coupling item is used to represent the ability of other autonomous domains in the network to provide resource support relative to the attacked autonomous domain.
9. A resource scheduling device for defending against DDoS attacks in a multi-domain network, characterized in that, The computer storage medium stores a computer program, and the computer program is used to make a computer execute the method in any one of claims 1-7.
10. A computer storage medium, characterized in that, The computer storage medium stores a computer program, and the computer program is used to make a computer execute the method in any one of claims 1-7.
Citation Information
Patent Citations
Network defense resource optimal allocation method for advanced persistent threats
CN110365713A
DDoS attack detection method, device, equipment and computer program product
CN113542295A