Resource Abnormal Allocation Detection Method, Device, Computer Equipment and Storage Medium
By obtaining resource allocation data, determining relevant tables and matching target lookup tables, and detecting based on data association relationships and non-conflict conditions, the problem of incomplete and inaccurate resource abnormal allocation detection in the prior art is solved, and a more comprehensive and accurate resource abnormal allocation detection is achieved.
Patent Information
- Application Number
- CN202411334503.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2044-09-23
AI Technical Summary
The prior art has problems of incomplete and inaccurate detection in resource anomaly allocation detection, especially in resource conflict detection across publishing points.
By obtaining the resource allocation data to be tested, determining its corresponding resource certificate table and route origin authorization table, multiple conflict detection items are determined, and the target lookup table is matched based on these tables, determining the set to be detected based on the data association relationship, and excluding data that meets the conditions through non-conflict conditions to obtain resource exception allocation detection results.
It improves the comprehensiveness and accuracy of resource anomaly allocation detection, can detect across release points, eliminate potential resource conflict missed detection problems, and improves detection accuracy through precise matching and conditional exclusion.
Smart Images

Figure CN119276555B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of routing security technology, and in particular, to a method, device, computer device, and storage medium for detecting abnormal resource allocation. Background Art
[0002] RPKI (Resource Public Key Infrastructure) is a security framework based on Public Key Infrastructure (PKI), aiming to enhance the security of the Internet routing system. RPKI provides a trusted verification mechanism for the allocation and authorization of Internet Protocol (IP) address blocks and Autonomous System (AS) numbers through digital certificates, thereby preventing security issues such as route hijacking, spoofing, and prefix hijacking.
[0003] Due to malicious or misoperations of the certification authority, there may be a risk of abnormal resource allocation during the resource allocation process. For example, the same resource may be wrongly allocated to multiple lower-level institutions by the upper-level institution, resulting in security issues such as route hijacking and prefix hijacking. At this time, it is necessary to detect the resources to ensure the uniqueness and legality of resource allocation.
[0004] In related technologies, resource certificates can be detected within the same publishing point. Specifically, it can be determined whether there is a conflict by simply comparing the information between certificates. However, only comparing the resource certificates within a single publishing point may lead to missed detection of abnormal allocations, and at the same time, potential conflicts between resources across publishing points may not be accurately detected, thus resulting in abnormal allocation problems. In summary, the resource abnormal allocation detection method in related technologies has problems of incomplete and inaccurate detection. Summary of the Invention
[0005] The main purpose of the embodiments of this application is to propose a method, device, computer device, and storage medium for detecting abnormal resource allocation, which can improve the comprehensiveness and accuracy of detecting abnormal resource allocation.
[0006] To achieve the above object, the first aspect of the embodiments of this application proposes a method for detecting abnormal resource allocation, and the method includes:
[0007] Obtain the resource allocation data to be measured, and determine the resource certificate table and routing origin authorization table corresponding to the resource allocation data to be measured;
[0008] Determine multiple conflict detection items for detecting the to-be-tested resource allocation data, and match a target lookup table for each conflict detection item according to the resource certificate table and the routing origin authorization table;
[0009] Based on the data association relationship corresponding to the conflict detection item, determine a first set to be detected corresponding to the conflict detection item from the target lookup table, and a second set to be detected having the data association relationship with at least one first to-be-tested resource sub-data in the first set to be detected;
[0010] Determine the non-conflict condition for each first to-be-tested resource sub-data in the first set to be detected and the second to-be-tested resource sub-data in the second set to be detected, exclude the first to-be-tested resource sub-data that meets the non-conflict condition and the corresponding second to-be-tested resource sub-data, and determine the remaining target to-be-tested resource sub-data after exclusion as the conflict detection result of the corresponding conflict detection item;
[0011] Based on the multiple conflict detection results corresponding to the multiple conflict detection items, obtain the resource abnormal allocation detection result of the to-be-tested resource allocation data.
[0012] Correspondingly, a second aspect of the embodiments of the present application proposes a resource abnormal allocation detection device, and the device includes:
[0013] A first acquisition module, configured to acquire to-be-tested resource allocation data, and determine a resource certificate table and a routing origin authorization table corresponding to the to-be-tested resource allocation data;
[0014] A matching module, configured to determine multiple conflict detection items for detecting the to-be-tested resource allocation data, and match a target lookup table for each conflict detection item according to the resource certificate table and the routing origin authorization table;
[0015] A determination module, configured to determine a first set to be detected corresponding to the conflict detection item from the target lookup table based on the data association relationship corresponding to the conflict detection item, and a second set to be detected having the data association relationship with at least one first to-be-tested resource sub-data in the first set to be detected;
[0016] An exclusion module, configured to determine the non-conflict condition for each first to-be-tested resource sub-data in the first set to be detected and the second to-be-tested resource sub-data in the second set to be detected, exclude the first to-be-tested resource sub-data that meets the non-conflict condition and the corresponding second to-be-tested resource sub-data, and determine the remaining target to-be-tested resource sub-data after exclusion as the conflict detection result of the corresponding conflict detection item;
[0017] A second acquisition module, configured to obtain a resource abnormal allocation detection result of the to-be-tested resource allocation data based on multiple conflict detection results corresponding to the multiple conflict detection items.
[0018] In some embodiments, the matching module is further configured to:
[0019] For a conflict detection scenario of detecting the to-be-tested resource allocation data between the upper and lower levels of a certificate chain, determine an illegal allocation conflict detection item and an illegal authorization conflict detection item as conflict detection items;
[0020] For a conflict detection scenario of detecting the to-be-tested resource allocation data between certificate chains, determine a conflict detection item between sub-certificates, a conflict detection item between a sub-certificate and a route origin authorization, and a conflict detection item between route origin authorizations as conflict detection items.
[0021] In some embodiments, the conflict detection item is an illegal allocation conflict detection item; the target lookup table matched by the illegal allocation conflict detection item is a resource certificate table; the exclusion module is further configured to:
[0022] For each first to-be-tested resource sub-data in the first set to be detected, match an Internet Protocol (IP) address prefix with at least one second to-be-tested resource sub-data having a data association relationship with the corresponding data in the second set to be detected, to obtain a first matching result; wherein, the first to-be-tested resource sub-data is the IP address prefix corresponding to a sub-certificate, and the second to-be-tested resource sub-data is the IP address prefix of the parent certificate corresponding to the sub-certificate;
[0023] When the first matching result indicates that a target first to-be-tested resource sub-data having a data association relationship with the first to-be-tested resource sub-data meets an inclusion relationship, determine that the first to-be-tested resource sub-data and the target first to-be-tested resource sub-data meet a non-conflict condition;
[0024] In the first set to be detected, exclude the first to-be-tested resource sub-data and the target first to-be-tested resource sub-data that meet the non-conflict condition, and determine, according to the remaining first to-be-tested resource sub-data after exclusion and the second to-be-tested resource sub-data having a data association relationship with the remaining first to-be-tested resource sub-data, target to-be-tested resource sub-data;
[0025] Determine the target to-be-tested resource sub-data as a conflict detection result of the illegal allocation conflict detection item of the to-be-tested resource allocation data for the IP address prefix.
[0026] In some embodiments, the conflict detection item is an illegal allocation conflict detection item; the target lookup table matched by the illegal allocation conflict detection item is a resource certificate table; the exclusion module is further configured to:
[0027] For each first resource sub - data to be detected in the first set to be detected, match the autonomous system number of the first resource sub - data to be detected with at least one second resource sub - data having a corresponding data association relationship in the second set to be detected, to obtain a second matching result; wherein, the first resource sub - data to be detected is the autonomous system number corresponding to the sub - certificate, and the second resource sub - data to be detected is the autonomous system number of the parent certificate corresponding to the sub - certificate;
[0028] When the second matching result indicates that there is a target second resource sub - data having a corresponding data association relationship with the first resource sub - data to be detected that meets the inclusion relationship, determine that the first resource sub - data to be detected and the target second resource sub - data meet the non - conflict condition;
[0029] In the first set to be detected, exclude the first resource sub - data to be detected and the target second resource sub - data that meet the non - conflict condition, and determine the remaining first resource sub - data in the first set to be detected and the second resource sub - data having a data association relationship with the remaining first resource sub - data to be detected as the target resource sub - data to be detected;
[0030] Determine the target resource sub - data to be detected as the conflict detection result of the illegal allocation conflict detection item of the resource allocation data to be detected for the autonomous system number.
[0031] In some embodiments, the conflict detection item is an illegal authorization conflict detection item; the target lookup tables matched by the illegal authorization conflict detection item are a resource certificate table and a routing origin authorization table; the exclusion module is further configured to:
[0032] For each first resource sub - data to be detected in the first set to be detected, match the Internet protocol address prefix of the first resource sub - data to be detected with at least one second resource sub - data having a corresponding data association relationship in the second set to be detected, to obtain a third matching result; wherein, the first resource sub - data to be detected is the first authorized Internet protocol address prefix corresponding to the autonomous system, and the second resource sub - data to be detected is the Internet protocol address prefix of the parent certificate corresponding to the autonomous system;
[0033] When the third matching result indicates that there is a target third resource sub - data having a corresponding data association relationship with the first resource sub - data to be detected that meets the inclusion relationship, determine that the first resource sub - data to be detected and the target third resource sub - data meet the non - conflict condition;
[0034] In the first set of resources to be detected, exclude the first resource sub-data to be measured and the target third resource sub-data to be measured that meet the non-conflict condition, and determine the target resource sub-data to be measured based on the remaining first resource sub-data to be measured after exclusion and the second resource sub-data to be measured that has a data association relationship with the remaining first resource sub-data to be measured;
[0035] Determine the target resource sub-data to be measured as the conflict detection result of the resource allocation data to be measured in the illegal authorization conflict detection item.
[0036] In some embodiments, the conflict detection item is an inter-sub-certificate conflict detection item; the target lookup table matched by the inter-sub-certificate conflict detection item is a resource certificate radix tree generated based on the resource certificate table; the exclusion module is further configured to:
[0037] For each first resource sub-data to be measured in the first set of resources to be detected, match the unified resource identifier of the first resource sub-data to be measured with at least one second resource sub-data to be measured corresponding to the data association relationship in the second set of resources to be detected, and obtain a fourth matching result; wherein, the first resource sub-data to be measured is the first Internet protocol address prefix corresponding to the first sub-certificate, and the second resource sub-data to be measured is a second Internet protocol address prefix that has an inclusion relationship with the first Internet protocol address prefix of the first sub-certificate in the resource certificate radix tree;
[0038] When the fourth matching result indicates that the unified resource identifier of the target fourth resource sub-data to be measured is equal to the unified resource identifier of the first resource sub-data to be measured, determine that the first resource sub-data to be measured and the target fourth resource sub-data to be measured meet the non-conflict condition; or, when the fourth matching result indicates that the unified resource identifier of the target fourth resource sub-data to be measured is equal to the unified resource identifier of the upper-level certificate of the first resource sub-data to be measured, determine that the first resource sub-data to be measured and the target fourth resource sub-data to be measured meet the non-conflict condition;
[0039] Exclude the target fourth resource sub-data to be measured that meets the non-conflict condition with the first resource sub-data to be measured, and determine the remaining second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured after exclusion as the target resource sub-data to be measured;
[0040] Use the target resource sub-data to be measured as the first sub-conflict detection result of the first resource sub-data to be measured, and determine the conflict detection result of the resource allocation data to be measured in the inter-sub-certificate conflict detection item for the multiple first sub-conflict detection results corresponding to the multiple first resource sub-data to be measured in the first set of resources to be detected.
[0041] In some embodiments, the conflict detection item is a sub-certificate and route origin authorization conflict detection item; the target lookup table matching the sub-certificate and route origin authorization conflict detection item is a resource certificate radix tree generated based on the resource certificate table; the exclusion module is further configured to:
[0042] For each first resource sub-data to be detected in the first set to be detected, match the unified resource identifier with at least one second resource sub-data having a corresponding data association relationship with the first resource sub-data in the second set to be detected, to obtain a fifth matching result; wherein, the first resource sub-data to be detected is a second authorized Internet protocol address prefix corresponding to an autonomous system, and the second resource sub-data to be detected is a third Internet protocol address prefix having an inclusion relationship with the second authorized Internet protocol address prefix in the resource certificate radix tree;
[0043] When the fifth matching result indicates that the unified resource identifier of the target fifth resource sub-data to be detected is equal to the unified resource identifier of the upper-layer certificate of the first resource sub-data to be detected, determine that the first resource sub-data to be detected and the target fifth resource sub-data to be detected meet the non-conflict condition;
[0044] Exclude the target fifth resource sub-data that meets the non-conflict condition with the first resource sub-data to be detected, and determine the remaining second resource sub-data having a data association relationship with the first resource sub-data to be detected after exclusion as the target resource sub-data to be detected;
[0045] Use the target resource sub-data to be detected as the second sub-conflict detection result of the first resource sub-data to be detected, and determine the conflict detection result of the resource allocation data to be detected in the sub-certificate and route origin authorization conflict detection item for the multiple second sub-conflict detection results corresponding to the multiple first resource sub-data to be detected in the first set to be detected.
[0046] In some embodiments, the conflict detection item is a conflict detection item between route origin authorizations; the target lookup table matching the conflict detection item between route origin authorizations is a route origin authorization radix tree generated based on the route origin authorization table; the exclusion module is further configured to:
[0047] For each first resource sub-data to be detected in the first set to be detected, match the uniform resource identifier of the first resource sub-data to be detected with at least one second resource sub-data to be detected having a data association relationship with the corresponding data in the second set to be detected, to obtain a sixth matching result; wherein, the first resource sub-data to be detected is a third authorized Internet protocol address prefix corresponding to an autonomous system, and the second resource sub-data to be detected is a fourth authorized Internet protocol address prefix having an inclusion relationship with the third authorized Internet protocol address prefix in the routing origin authorization radix tree;
[0048] When the sixth matching result indicates that the uniform resource identifier of the target sixth resource sub-data to be detected is equal to the uniform resource identifier of the first resource sub-data to be detected, determine that the first resource sub-data to be detected and the target sixth resource sub-data to be detected satisfy the non-conflict condition;
[0049] Exclude the target sixth resource sub-data to be detected that satisfies the non-conflict condition with the first resource sub-data to be detected;
[0050] Obtain the first autonomous system number of the remaining second resource sub-data to be detected that has a data association relationship with the first resource sub-data to be detected after exclusion, and the second autonomous system number of the first resource sub-data to be detected;
[0051] When one of the first autonomous system number and the second autonomous system number is zero, determine the authorized Internet protocol address prefixes corresponding to the first autonomous system number and the second autonomous system number respectively as the target resource sub-data to be detected;
[0052] Use the target resource sub-data to be detected as the third sub-conflict detection result of the first resource sub-data to be detected, and for the multiple third sub-conflict detection results corresponding to the multiple first resource sub-data to be detected in the first set to be detected, determine the conflict detection result of the resource allocation data in the routing origin authorization conflict detection item.
[0053] Correspondingly, a third aspect of the embodiments of the present application proposes a computer device, the computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, it implements the resource abnormal allocation detection method according to any one of the embodiments of the first aspect of the present application.
[0054] Correspondingly, a fourth aspect of the embodiments of the present application proposes a computer-readable storage medium, the storage medium stores a computer program, and when the computer program is executed by a processor, it implements the resource abnormal allocation detection method according to any one of the embodiments of the first aspect of the present application.
[0055] In an embodiment of the present application, by obtaining the resource allocation data to be measured, the resource certificate table and the route origin authorization table corresponding to the resource allocation data to be measured are determined; multiple conflict detection items for detecting the resource allocation data to be measured are determined, and a target lookup table is matched for each conflict detection item according to the resource certificate table and the route origin authorization table; based on the data association relationship corresponding to the conflict detection item, a first set to be detected corresponding to the conflict detection item is determined from the target lookup table, and a second set to be detected having a data association relationship with at least one first sub-data of the resource to be measured in the first set to be detected; the non-conflict condition between each first sub-data of the resource to be measured in the first set to be detected and the second sub-data of the resource to be measured in the second set to be detected is determined, the first sub-data of the resource to be measured that meets the non-conflict condition and the corresponding second sub-data of the resource to be measured are excluded, and the remaining target sub-data of the resource to be measured after the exclusion is determined as the conflict detection result corresponding to the conflict detection item; based on the multiple conflict detection results corresponding to the multiple conflict detection items, a resource abnormal allocation detection result of the resource allocation data to be measured is obtained. In this way, it is possible to perform corresponding detection on the resource allocation data to be measured in different conflict detection items, not only being able to detect across publishing points to eliminate potential missed detections of resource conflicts, but also improving the detection accuracy through precise matching and condition exclusion, thus significantly enhancing the comprehensiveness and accuracy of resource abnormal allocation detection. Description of the Drawings
[0056] Figure 1 is a schematic diagram of the architecture of the resource abnormal allocation detection system provided by an embodiment of the present application;
[0057] Figure 2 is a flowchart of the resource abnormal allocation detection method provided by an embodiment of the present application;
[0058] Figure 3 is a flowchart of the detection of illegal allocation conflict items provided by an embodiment of the present application;
[0059] Figure 4 is a flowchart of the detection of illegal authorization conflict items provided by an embodiment of the present application;
[0060] Figure 5 is a flowchart of the construction of the resource certificate radix tree provided by an embodiment of the present application;
[0061] Figure 6 is a flowchart of the detection of conflict items between sub-certificates provided by an embodiment of the present application;
[0062] Figure 7 is a flowchart of the detection of conflict items between a sub-certificate and a route origin authorization provided by an embodiment of the present application;
[0063] Figure 8 is a flowchart of the detection of conflict items between route origin authorizations provided by an embodiment of the present application;
[0064] Figure 9 It is a sample diagram of the RCR file format provided by an embodiment of the present application;
[0065] Figure 10 It is a schematic diagram of the functional modules of the resource abnormal allocation detection device provided by an embodiment of the present application;
[0066] Figure 11 It is a schematic diagram of the hardware structure of the computer device provided by an embodiment of the present application. Detailed implementation manners
[0067] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0068] It should be noted that although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order from the module division in the device or the order in the flowchart. Terms such as "first" and "second" in the specification, claims and the above-mentioned drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence.
[0069] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0070] RPKI (Resource Public Key Infrastructure) is a security framework based on the Public Key Infrastructure (PKI), aiming to enhance the security of the Internet routing system. RPKI provides a trusted verification mechanism for the allocation and authorization of Internet Protocol (IP) address blocks and Autonomous System (AS) numbers through digital certificates, thereby preventing security problems such as route hijacking, spoofing, and prefix hijacking.
[0071] Due to malicious operations or misoperations of the certification authority, there may be a risk of abnormal resource allocation during the resource allocation process. For example, the same resource may be wrongly allocated to multiple lower-level institutions by the upper-level institution, resulting in security problems such as route hijacking and prefix hijacking. At this time, it is necessary to detect the resources to ensure the uniqueness and legality of resource allocation.
[0072] In the related art, resource certificates can be detected within the same publishing point. Specifically, whether a conflict occurs can be determined by simply comparing the information between certificates. However, only comparing resource certificates within a single publishing point may lead to missed detection of abnormal allocations. At the same time, potential conflicts between resources across publishing points may not be accurately detected, thus resulting in abnormal allocation problems. In summary, the resource abnormal allocation detection method in the related art has problems of incomplete and inaccurate detection.
[0073] Based on this, the embodiments of the present application provide a resource abnormal allocation detection method, device, computer device, and storage medium, which can improve the comprehensiveness and accuracy of resource abnormal allocation detection.
[0074] The resource abnormal allocation detection method, device, computer device, and storage medium provided by the embodiments of the present application are specifically described through the following embodiments. First, the resource abnormal allocation detection system in the embodiments of the present application is described.
[0075] Please refer to Figure 1 , in some embodiments, the embodiments of the present application provide a resource abnormal allocation detection system.
[0076] Specifically, the resource abnormal allocation detection system can interact with relying parties in the RPKI system, obtain valid data objects in the RPKI from the relying parties through a data collection module, and finally upload the SLURM file responsible for local control to the relying party server for risk defense after a series of analysis and processing. The system consists of a data collection module, a data preprocessing module, resource abnormal allocation detection, a resource abnormal allocation detection result output module, an alarm and emergency defense module, and visualization and a user interface.
[0077] Among them, the data acquisition module is responsible for obtaining valid RPKI data from the relying party, extracting the contents of the certificate file, route origin authorization file, manifest file, and certificate revocation list file, and storing them in the local database or local file. Taking the local database as an example, the Certificate Entity Record Store (CERS) table, that is, the resource certificate table, is used to store the relevant information of the RPKI resource certificate. The relevant information of the RPKI resource certificate is extracted from the valid RPKI data obtained from the relying party and stored in the local database or local file. The resource certificate table may include the certificate serial number, subject key identifier (SKI), authority key identifier (AKI), certificate issuance time (NotBefore), expiration time (NotAfter), certificate file URI (Uniform Resource Identifier, URI), URI for issuing the certificate (Authority Information Access, AIA), IP resources included in the certificate, autonomous system number (Autonomous System Number, ASN) resources included in the certificate, and other contents.
[0078] Furthermore, the route origin authorization table can be used to store the relevant information of the ROA file in the RPKI data, that is, the ROA table. For example, the certificate serial number, subject key identifier, authority key identifier, certificate issuance time and expiration time, certificate file URI, Internet Protocol address prefix corresponding to the ROA file, autonomous system number and autonomous domain number (Autonomous System, AS) corresponding to the ROA file, etc. The storage fields of the route origin authorization table are similar to those of the resource certificate table and will not be listed one by one here.
[0079] Exemplarily, the Manifest File (MFTS) table is used to store RPKI manifest file information. The stored fields need to additionally add information such as the file list in the manifest compared to resource certificates. The Certificate Revocation List (CRLS) table is used to store information related to certificate revocation list files. Since the RPKI repository is continuously updated, the information of local resource certificate files, ROA files, certificate manifest files, and certificate revocation list files also needs to be continuously updated. The CERS table, ROAS table, MFTS table, and CRLS table can all use the file URI as the primary key to uniquely identify a file. If the URI corresponding to the file does not exist in the data table, a new record is added. If the URI corresponding to the file already exists in the data table, other fields are directly updated.
[0080] The data preprocessing module is responsible for scanning the CERS table, ROAS table, MFTS table, and CRLS table corresponding to certificate files, route origin authorization files, manifest files, and certificate revocation files, filtering out expired file records and detecting invalid file records to ensure data accuracy and consistency.
[0081] Exemplarily, the resource abnormal allocation detection module of the present application adopts an improved RPKI abnormal conflict detection algorithm, which includes two parts. One is to detect illegal allocation and illegal authorization problems between certificates and between certificates and route origin authorization at the upper and lower levels of the certificate chain, and record the corresponding problem information in the database table. The other is to detect duplicate allocation and overlapping allocation problems of Internet protocol address prefixes and autonomous domain resources between certificates, and duplicate allocation and overlapping allocation problems of Internet protocol address prefixes between certificates and route origin authorization and between route origin authorizations, and record the corresponding problem information in the database table.
[0082] Furthermore, the resource abnormal allocation detection result output module can be used to store and query the resource abnormal allocation detection results, convert the conflict detection result information corresponding to each conflict detection item, and uniformly output it as a JSON file in the general RPKI conflict detection file format proposed by the present application, and upload it to a third-party agency or dependent software for further analysis.
[0083] Further, the alarm and emergency defense module is responsible for obtaining information about both parties in the conflict based on third-party data, such as the CAIDA dataset, WHOIS database, etc. It notifies relevant network operators or administrators of the detected conflict by sending emails or other means. In addition, it can generate local policies for the routing origin authorization data threatened by the conflict and upload them to the dependent party in the form of a Localized Routing Anomaly Management (SLURM) file to do a good job in emergency defense.
[0084] Further, the visualization and user interface can be used to display the current RPKI conflict status, conflict distribution and trends, and allow users to query the conflict situation of specific Internet protocol address prefixes or ASNs.
[0085] The resource abnormal allocation detection method in the embodiments of this application can be illustrated by the following embodiments.
[0086] It should be noted that in each specific implementation manner of this application, when it comes to relevant processing that needs to be based on data related to the user's identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first. Moreover, the collection, use, and processing of these data will comply with relevant laws, regulations, and standards. In addition, when the embodiments of this application need to obtain the user's sensitive personal information, the user's separate permission or separate consent will be obtained through methods such as pop-up windows or jumping to a confirmation page. After clearly obtaining the user's separate permission or separate consent, the necessary user-related data for the embodiments of this application to operate normally will be obtained.
[0087] In the embodiments of this application, it will be described from the dimension of the resource abnormal allocation detection device, which can be specifically integrated in a computer device. See Figure 2 , Figure 2 is the step flowchart of the resource abnormal allocation detection method provided by the embodiments of this application. In the embodiments of this application, taking the resource abnormal allocation detection device being specifically integrated in a terminal or a server as an example, when the processor on the terminal or the server executes the program instructions corresponding to the resource abnormal allocation detection method, the specific process is as follows:
[0088] Step 101, obtain the resource allocation data to be measured, and determine the resource certificate table and routing origin authorization table corresponding to the resource allocation data to be measured.
[0089] In some embodiments, in order to comprehensively cover possible abnormal situations of the resource allocation data to be tested, a resource certificate table and a route origin authorization table corresponding to the resource allocation data to be tested can be determined, so as to facilitate subsequent detection of various types of conflict detection items for the resource allocation data to be tested based on the resource certificate table and the route origin authorization table.
[0090] Among them, the resource allocation data to be tested can be valid RPKI data obtained from a dependent party. The resource allocation data to be tested includes, but is not limited to, Resource Certificate (RC), Route Origin Authorization (ROA), Manifest File (MFTS), Certificate Revocation List (CRLS), and so on.
[0091] Among them, the resource certificate table can be a Certificate Entity Record Store (CERS) table, which is used to store relevant information of RPKI resource certificates. The relevant information of RPKI resource certificates is extracted from the valid RPKI data obtained from the dependent party and stored in a local database or a local file. The resource certificate table can include the certificate serial number, Subject Key Identifier (SKI), Authority Key Identifier (AKI), certificate issuance time (NotBefore), expiration time (NotAfter), certificate file URI (Uniform Resource Identifier, URI), URI for issuing the certificate (Authority Information Access, AIA), IP resources included in the certificate, autonomous system number (Autonomous System Number, ASN) resources included in the certificate, and other contents.
[0092] Among them, the routing origin authorization table can be used to store relevant information of the ROA file in the RPKI data, that is, the ROA table, such as the certificate serial number of the ROA file, the certificate subject public key identifier, the issuer key identifier, the certificate issuance time and expiration time, the certificate file URI, the Internet protocol address prefix corresponding to the ROA file, the autonomous system number and autonomous domain number (Autonomous System, AS) corresponding to the ROA file, etc. The storage fields of the routing origin authorization table are similar to those of the resource certificate table and will not be listed one by one here.
[0093] By obtaining and determining these data tables, an accurate data basis can be provided for subsequent resource exception conflict detection, ensuring the comprehensiveness and accuracy of the detection process.
[0094] Exemplarily, after obtaining the resource allocation data to be tested, the resource certificate, routing origin authorization file, manifest file, and certificate revocation list file content can be extracted and stored in a local database or local file. Since the RPKI data is constantly updated, the above files are updated accordingly.
[0095] Furthermore, the resource certificate, routing origin authorization file, manifest file, and certificate revocation list file can all use the file URI as the primary key to uniquely identify a file. If the URI corresponding to the file does not exist in the corresponding data table, a new record is added. If the URI corresponding to the file already exists in the corresponding data table, other fields are directly updated.
[0096] Exemplarily, expired file records can be filtered regularly or in real time and invalid file records can be detected to ensure data accuracy and consistency.
[0097] Through the resource certificate table and routing origin authorization table corresponding to the resource allocation data to be tested, the process of resource tracking and management can be simplified, which is conducive to improving the speed and accuracy of resource abnormal allocation detection.
[0098] Step 102, determine multiple conflict detection items for detecting the resource allocation data to be tested, and match a target lookup table for each conflict detection item according to the resource certificate table and the routing origin authorization table.
[0099] In some embodiments, to ensure that the detection process is both comprehensive and accurate, multiple conflict detection items for detecting the resource allocation data to be tested can be determined, and a target lookup table can be matched for the conflict detection items to ensure that the detection process covers as many potential abnormal situations as possible and improve the pertinence of detecting the conflict detection items.
[0100] Among them, the conflict detection items can be detection metrics for detecting resource allocation data. Each conflict detection item needs to match at least one target lookup table for specific detection operations. The target lookup tables include, but are not limited to, the resource certificate table, the resource certificate radix tree generated based on the resource certificate table, the route origin authorization table, and the route origin authorization radix tree generated based on the route origin authorization table.
[0101] Among them, the target lookup table can be a data table for assisting in the specific implementation of the conflict detection items. The target lookup table contains the necessary information to enable the system to perform conflict detection quickly and accurately.
[0102] In some embodiments, the conflict detection items can include the illegal allocation conflict detection item and the illegal authorization conflict detection item between the upper and lower levels of the certificate chain as conflict detection items, as well as the sub-certificate conflict detection item between certificate chains, the sub-certificate and route origin authorization conflict detection item, and the route origin authorization conflict detection item between route origin authorizations as conflict detection items. The conflict detection items can also include the certificate revocation status detection item, the certificate lifecycle detection item, and so on.
[0103] Specifically, different conflict detection items can correspond to different target lookup tables to improve the efficiency and accuracy of resource abnormal allocation detection. For example, the illegal allocation conflict detection item mainly focuses on the relationship between the upper and lower levels of the certificate chain, so the target lookup table it matches is the resource certificate table. The target lookup table matched by the illegal authorization conflict detection item is the resource certificate table and the route origin authorization table. The target lookup table matched by the sub-certificate conflict detection item between certificate chains is the resource certificate radix tree generated based on the resource certificate table, and so on. The details of the target lookup tables corresponding to specific conflict detection items will be elaborated below and will not be repeated here.
[0104] By defining multiple conflict detection items and matching the most suitable target lookup table for each detection item, it is beneficial to improve the efficiency and accuracy of resource abnormal allocation detection.
[0105] In some embodiments, in order to improve the efficiency and accuracy of resource abnormal allocation detection, specific conflict detection items can be defined for different conflict detection scenarios, and a suitable target lookup table can be matched for each detection item to ensure that potential conflicts or abnormal situations can be accurately and comprehensively detected in different levels and different types of resource allocations. For example, "determining multiple conflict detection items for detecting the resource allocation data to be tested" in step 102 can include:
[0106] (102.1) For the conflict detection scenario of detecting the resource allocation data to be tested between the upper and lower levels of the certificate chain, determining the illegal allocation conflict detection item and the illegal authorization conflict detection item as conflict detection items;
[0107] (102.2) For the conflict detection scenario of detecting data allocation for the resource under test among certificate chains, determine the conflict detection items among sub-certificates, the conflict detection items between sub-certificates and route origin authorization, and the conflict detection items between route origin authorizations as conflict detection items.
[0108] Among them, the upper and lower levels of the certificate chain can be the relationship between the upper-level CA and the lower-level CA in the same Certification Authority (CA) hierarchical structure. In the relationship between the upper and lower levels of the certificate chain, the upper-level CA is responsible for issuing certificates to the lower-level CA, including resource certificates and End Entity (EE) certificates, for resource allocation and authorization. In the upper and lower levels of the certificate chain, each layer of CA has a series of resources (such as Internet Protocol address prefixes and AS numbers) that it is authorized to manage, and their relationship is reflected through the certificate chain. The upper-level CA should only issue resource certificates that it has the right to manage and allocate to the lower-level CA.
[0109] Among them, the illegal allocation conflict detection item can be to detect whether the upper-level certificate issuing authority in the certificate chain has allocated Internet Protocol address prefixes or autonomous domain resources that do not belong to itself to the lower-level certificate issuing authority. For example, CA1 allocates the IP resource 193.30.12.0 / 22 that does not belong to itself to the lower-level CA2, or allocates the autonomous domain resource 696 that does not belong to itself to the lower-level CA3.
[0110] Among them, the illegal authorization conflict detection item can be to detect whether the upper-level CA has authorized Internet Protocol address prefixes that do not belong to itself to a certain autonomous system. For example, CA1 authorizes the Internet Protocol address prefix 193.30.12.0 / 22 that does not belong to itself to AS65001.
[0111] Among them, the certificate chains can be the relationship between different certificate chains, that is, the relationship between different certificate issuing authorities, that is, different independent certificate chains. There may be situations of resource overlap or conflict among certificate chains. For example, different CAs may authorize the same Internet Protocol address prefix or autonomous system number, resulting in contradictions in resource allocation.
[0112] Among them, the conflict detection item among sub-certificates can be to detect whether there are problems of duplicate allocation or overlapping allocation of Internet Protocol address prefixes or autonomous domain resources among sub-certificates of different certificate chains. For example, CA1 duplicates the allocation of the Internet Protocol address prefix 192.0.2.128 / 26 to the lower-level CA2 and the lower-level CA3, or allocates the overlapping Internet Protocol address prefixes 192.0.2.128 / 26 and 192.0.131 / 26 to the lower-level CA2 and the lower-level CA3 respectively.
[0113] Among them, the conflict detection item between the sub-certificate and the route origin authorization can be to detect whether there is a problem of duplicate allocation (or authorization) or overlapping allocation (or authorization) of Internet protocol address prefixes between the sub-certificate and the route origin authorization. For example, CA1 allocates the Internet protocol address prefix 192.0.2.128 / 26 to the subordinate CA2 and authorizes it to be used by AS65001 at the same time; or allocates the Internet protocol address prefix 192.0.2.128 / 26 to the subordinate CA2 and authorizes the Internet protocol address prefix 192.0.131 / 26 that overlaps with this Internet protocol address prefix to be used by AS65001.
[0114] Among them, the conflict detection item between route origin authorizations is that the conflict detection item can be to detect whether there is a problem of duplicate authorization or overlapping authorization of Internet protocol address prefixes between different route origin authorization files. For example, CA1 authorizes the Internet protocol address prefix 192.0.2.128 / 26 to be used by AS65001 and authorizes it to AS0 as a reserved resource at the same time; or authorizes the Internet protocol address prefix 192.0.2.128 / 26 to be used by AS65001 and authorizes the Internet protocol address prefix 192.0.131 / 26 that overlaps with this Internet protocol address prefix to AS0 as a reserved resource.
[0115] Specifically, since between the upper and lower levels of the certificate chain, the upper-level CA should only issue to the lower-level CA the resources that it has the right to manage and allocate by itself. Otherwise, it will lead to problems of illegal allocation or illegal authorization. Therefore, in the conflict detection scenario of detecting the resource allocation data between the upper and lower levels of the certificate chain, the illegal allocation conflict detection item and the illegal authorization conflict detection item can be determined as the conflict detection items. Through these two conflict detection items, it can be effectively identified whether the upper-level CA allocates or authorizes resources that do not belong to itself to the lower-level CA, thus ensuring the legality of resource allocation.
[0116] In the conflict detection scenario of detecting the resource allocation data between certificate chains, since there may be resource overlap or duplicate allocation between different certificate chains, the conflict detection items between sub-certificates, the conflict detection item between the sub-certificate and the route origin authorization, and the conflict detection item between route origin authorizations can be determined as the conflict detection items to detect whether there is duplicate or overlapping allocation of resources between sub-certificates, conflicts between the sub-certificate and the route origin authorization, and conflicts between different route origin authorizations between different certificate chains, thus preventing routing errors or other security problems caused by resource conflicts.
[0117] By configuring corresponding conflict detection items for different detection scenarios, potential problems in resource allocation can be discovered and solved targeted, preventing duplicate or illegal use of resources, ensuring the legality and consistency of resource allocation and use, and thus guaranteeing the security and stability of Internet communication.
[0118] Step 103: Based on the data association relationships corresponding to the conflict detection items, determine, from the target lookup table, a first set to be detected corresponding to the conflict detection items, and a second set to be detected that has a data association relationship with at least one first resource sub-data to be detected in the first set to be detected.
[0119] In some embodiments, to ensure that when performing resource abnormal allocation detection, the resource sub-data that needs to be detected can be accurately identified, a first set to be detected corresponding to the conflict detection items and a second set to be detected that has a data association relationship with at least one first resource sub-data to be detected in the first set to be detected can be determined from the target lookup table, so as to quickly and accurately locate the target to be detected and improve the efficiency and accuracy of detection.
[0120] Among them, the data association relationship can be a way or rule for determining the mutual association between resource sub-data in different conflict detection scenarios. Different conflict detection items can correspond to different data association relationships, so as to quickly find the resource sub-data to be detected corresponding to the conflict detection items, which is beneficial to quickly complete the detection task.
[0121] Among them, the first set to be detected can be a set of resources that need to be detected and are screened from the target lookup table according to the requirements of the conflict detection items. Each element in the first set to be detected is a resource sub-data to be detected, and the first resource sub-data to be detected corresponding to different conflict detection items is also different.
[0122] Among them, the first resource sub-data to be detected can be a specific resource unit to be detected selected from the first set to be detected. The first resource sub-data to be detected can be an Internet Protocol address prefix corresponding to a sub-certificate, an autonomous system number, or other attribute values related to detection. For example, when detecting an illegal allocation conflict, the first resource sub-data to be detected can be the Internet Protocol address prefix corresponding to the sub-certificate.
[0123] Among them, the second set to be detected can be a set of resources that has a data association relationship with at least one first resource sub-data to be detected in the first set to be detected. The data association relationship between each element in the second set to be detected and the first resource to be detected in the first set to be detected can be an inclusion relationship based on the Internet Protocol address prefix or other logical relationships.
[0124] Specifically, the data association relationship can be an inclusion relationship, a matching relationship, or other logical relationships based on attributes such as Internet Protocol address prefixes, autonomous system numbers, or uniform resource identifiers. For example, in the illegal allocation conflict detection item, for the resource illegal allocation detection item of the Internet Protocol address prefix, the data association relationship can be that the URI of the parent certificate is equal to the Authority Information Access (AIA) field of the child certificate. For the illegal authorization conflict detection item, the data association relationship can be that the URI of the child certificate is equal to the Authority Information Access (AIA) field of the routing origin authorization file. Other data association relationships are not elaborated here one by one.
[0125] Through the above method, it can be ensured that when detecting abnormal resource allocation, the target to be detected can be quickly and accurately located, thereby improving the efficiency and accuracy of the detection.
[0126] Step 104: Determine the non-conflict conditions for each first resource sub-data to be detected in the first set to be detected and the second resource sub-data to be detected in the second set to be detected. Exclude the first resource sub-data to be detected and the corresponding second resource sub-data that meet the non-conflict conditions, and determine the remaining target resource sub-data to be detected after exclusion as the conflict detection result of the corresponding conflict detection item.
[0127] In some embodiments, to improve the efficiency and accuracy of the detection, the non-conflict conditions for the first resource sub-data to be detected and the second resource sub-data to be detected can be determined, and the non-conflicting data can be quickly excluded, rather than determining the conflicting data one by one through the conflict conditions, so as to significantly reduce the amount of data that needs to be further analyzed.
[0128] Among them, the second resource sub-data to be detected can be resource sub-data that has a data association relationship with at least one first resource sub-data to be detected in the first set to be detected. The second resource sub-data to be detected can be selected from the target lookup table for further checking whether there is a potential conflict between the second resource sub-data to be detected and the first resource sub-data to be detected in the corresponding conflict detection item. For example, in the illegal allocation conflict detection item, the second resource sub-data to be detected can be the Internet Protocol address prefix corresponding to the parent certificate.
[0129] Among them, the non-conflict condition can be a specific relationship satisfied between the first resource sub-data to be detected and the second resource sub-data, so that there is no conflict between the two. For example, when detecting the illegal allocation conflict between the upper and lower levels of the certificate chain, if the Internet Protocol address prefix of the child certificate is included in the Internet Protocol address prefix of its parent certificate, it is considered that there is no conflict between these two resource sub-data.
[0130] Among them, the target resource sub-data to be measured can be the resource sub-data to be measured that does not meet the non-conflict condition remaining after excluding the first set to be detected and the second set to be detected according to the non-conflict condition. When detecting different conflict detection items, the finally determined target resource sub-data to be measured is also different, and it is specifically selected according to the actual situation.
[0131] Among them, the conflict detection result can be the target resource sub-data to be measured remaining after excluding all the first resource sub-data to be measured and the corresponding second resource sub-data to be measured that meet the non-conflict condition.
[0132] Exemplarily, the conflict detection result can include specific conflict resources (such as specific Internet Protocol address prefixes, autonomous system numbers, etc.), conflict types (such as illegal allocation, illegal authorization, conflict between sub-certificates, conflict between sub-certificate and route origin authorization, conflict between route origin authorizations, etc.), and information about both parties in the conflict (providing detailed information about both parties in the conflict, such as certificate URIs, ROA file identifiers, etc.).
[0133] In some embodiments, for all conflict detection items, each first resource sub-data to be measured in the first set to be detected corresponding to the conflict detection item can correspond to one or more second resource sub-data to be measured in the second set to be detected.
[0134] Exemplarily, for the detection scenario of the upper and lower levels of the certificate chain, if the conflict detection item to be detected is the illegal allocation conflict detection item, then, according to the data association relationship, that is, the URI of the parent certificate is equal to the authoritative information access point field of the sub-certificate (P_CERS.URI = C_CERS.AIA), which means that the sub-certificate is issued by the specified parent certificate. For example, it can be determined that the first set to be detected includes CER1: 192.0.2.0 / 24, CER2: 192.0.2.128 / 25; based on the data association relationship, it is determined that the second set to be detected includes P_CER1: 192.0.2.0 / 23, P_CER2: 192.0.3.0 / 23, 192.0.3.0 / 22. At this time, it can be determined that the non-conflict condition is that the Internet Protocol address prefix of the sub-certificate is included in the Internet Protocol address prefix of its parent certificate, so as to determine that there is no illegal allocation conflict detection between the first resource sub-data to be measured and the second resource sub-data to be measured, that is, the upper-level CA of the certificate chain does not allocate Internet Protocol addresses that do not belong to itself to the lower-level CA.
[0135] Furthermore, exclusion can be performed according to the non-conflict condition. For example, when checking and excluding the non-conflict data CER1 (192.0.2.0 / 24), the Internet Protocol address prefix of the parent certificate P_CER1 is 192.0.2.0 / 23, 192.0.2.0 / 24 192.0.2.0 / 23 meets the non - conflict condition, and this pair of data is excluded. It can be understood that for each first resource sub - data to be tested, through the above - mentioned method, it can be compared with the second resource sub - data with a data association relationship to determine whether the two meet the non - conflict condition. After comparing the first resource sub - data to be tested with all the second resource sub - data with a data association relationship, the first resource sub - data that does not meet the non - conflict condition and the second resource sub - data with the corresponding data association relationship can be used as the conflict detection result of the first resource sub - data under the corresponding conflict detection item.
[0136] By using the non - conflict condition to quickly exclude data, it avoids the inefficient method of checking whether each pair of resource sub - data conflicts one by one, thus greatly improving the processing speed. This method is not only applicable to the detection of a single publishing point, but also can be used for cross - multiple - publishing - point detection, eliminating the potential problem of missed detection of resource conflicts and enabling efficient detection of abnormal resource allocation.
[0137] In some embodiments, in order to comprehensively, quickly, and accurately determine the final conflict detection result, non - conflict data can be excluded by defining and applying non - conflict conditions, so as to accurately determine the conflict detection result of the resource allocation data to be tested under this conflict detection item. For example, when the conflict detection item is an illegal allocation conflict detection item, and the corresponding target lookup table is a resource certificate table, then step 104's "excluding the first resource sub - data to be tested and the corresponding second resource sub - data that meet the non - conflict condition, and determining the remaining target resource sub - data after exclusion as the conflict detection result of the corresponding conflict detection item" can include:
[0138] (104.a1) For each first resource sub - data to be tested in the first set to be tested, match the Internet Protocol address prefix of the first resource sub - data to be tested with at least one second resource sub - data with the corresponding data association relationship in the second set to be tested, and obtain a first matching result; wherein, the first resource sub - data to be tested is the Internet Protocol address prefix corresponding to the sub - certificate, and the second resource sub - data to be tested is the Internet Protocol address prefix corresponding to the parent certificate of the sub - certificate;
[0139] (104.a2) When the first matching result indicates that there is an inclusion relationship between the first resource sub - data to be tested and the target first resource sub - data with the corresponding data association relationship, determine that the first resource sub - data to be tested and the target first resource sub - data meet the non - conflict condition;
[0140] (104.a3) In the first set of resources to be detected, exclude the first resource sub-data to be measured and the target first resource sub-data to be measured that meet the non-conflict condition, and determine the target resource sub-data to be measured based on the remaining first resource sub-data to be measured after exclusion and the second resource sub-data to be measured that has a data association relationship with the remaining first resource sub-data to be measured;
[0141] (104.a4) Determine the target resource sub-data to be measured as the conflict detection result of the conflict detection item for the illegal allocation conflict of the Internet Protocol address prefix in the resource allocation data to be measured.
[0142] Among them, the first matching result can be the result obtained by matching the first resource sub-data to be measured (the Internet Protocol address prefix of the sub-certificate) with all the second resource sub-data to be measured (the Internet Protocol address prefix of the parent-certificate) that has a data association relationship in the illegal allocation conflict detection item. The first matching result is used to characterize whether the first resource sub-data to be measured and the second resource sub-data to be measured conform to the inclusion relationship. For example, the first matching result can be that the first resource sub-data A conforms to the inclusion relationship with the second resource sub-data B, or the first resource sub-data C does not conform to the inclusion relationship with the second resource sub-data D, etc. Exemplarily, the inclusion relationship of the Internet Protocol address prefix can be repetition or partial overlap between the Internet Protocol address prefixes.
[0143] Among them, the Internet Protocol address prefix can be the prefix used to identify the Internet Protocol address in the Internet. It is usually represented as an IP address plus a slash and a number, such as 192.0.2.0 / 24.
[0144] Among them, the non-conflict condition can be that the first resource sub-data to be measured and the second resource sub-data to be measured satisfy the inclusion relationship of the Internet Protocol address prefix, so that there is no conflict between them. When the conflict detection item is the illegal allocation conflict detection item for the Internet Protocol address prefix, the non-conflict condition can be that the Internet Protocol address prefix of the sub-certificate is included in the Internet Protocol address prefix of its parent-certificate.
[0145] Among them, the target first resource sub-data to be measured can be the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured and meets the non-conflict condition during the matching process. When the conflict detection item is the illegal allocation conflict detection item for the Internet Protocol address prefix, the target first resource sub-data to be measured is the Internet Protocol address prefix of the parent-certificate, and there is an inclusion relationship between this prefix and the Internet Protocol address prefix of the sub-certificate.
[0146] Among them, the target resource sub-data to be measured can be the remaining first resource sub-data to be measured that do not meet the non-conflict condition after excluding the first resource sub-data to be measured that meet the non-conflict condition, and the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured.
[0147] It can be understood that when the superior CA in the certificate chain assigns an Internet protocol address prefix that does not belong to itself to the subordinate CA, an illegal assignment conflict will occur. Exemplarily, CA1 assigns the Internet protocol address prefix 193.30.12.0 / 22 that does not belong to itself to the subordinate CA2, and this process belongs to the illegal assignment of the Internet protocol address prefix.
[0148] Exemplarily, when the conflict detection item is an illegal assignment conflict detection item for the Internet protocol address prefix, the corresponding target lookup table that can be matched is the resource certificate table. According to the resource certificate table, the first set A to be detected corresponding to the first resource sub-data to be measured is determined, and the second set B to be detected corresponding to the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured is determined. Then, each first resource sub-data a1 in the first set to be detected is matched with the second resource sub-data with the corresponding data association relationship in the second set to be detected to obtain the first matching result. And according to the matching result, the target first resource sub-data to be measured that meets the non-conflict condition with the first resource sub-data to be measured is excluded. So far, the remaining first resource sub-data to be measured that do not meet the non-conflict condition in the first set to be detected, and the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured are used as the target resource sub-data to be measured, and the target resource sub-data to be measured is determined as the conflict detection result of the illegal assignment conflict detection item of the resource allocation data to be measured for the Internet protocol address prefix.
[0149] Furthermore, for each first resource sub-data to be measured, it is matched with all the second resource sub-data with the corresponding data association relationship in the second set to be detected. As long as there is at least one second resource sub-data that meets the non-conflict condition with this first resource sub-data to be measured, then this first resource sub-data to be measured is legal, and the matching of this first resource sub-data to be measured can be stopped, and the matching of the next resource sub-data to be measured in the first set to be detected can be started; conversely, if the first resource sub-data to be measured does not meet the non-conflict condition with all the second resource sub-data with the corresponding data association relationship, it indicates that this first resource sub-data to be measured is illegal, and this illegal first resource sub-data to be measured and the second resource sub-data with the corresponding data association relationship are determined as the target resource sub-data to be measured.
[0150] Please refer to Figure 3, exemplarily, all sub-certificates can be filtered out by looking up the resource certificate table (i.e., records where CERS.AIA is not empty), and the Internet Protocol address prefixes of these sub-certificates can be used as the first set of resources to be detected. For example, the first set of resources to be detected may include CER1: 192.0.2.0 / 24; CER2: 192.0.2.128 / 25; CER3: 192.0.3.0 / 24; CER4: 192.0.3.128 / 25.
[0151] Furthermore, based on the illegal allocation conflict detection items corresponding to the Internet Protocol addresses, the data association relationship between the first sub-data of the resource to be detected and the second sub-data of the resource to be detected can be determined. Specifically, the URI of the parent certificate is equal to the authoritative information access point field of the sub-certificate (i.e., P_CERS.URI = C_CERS.AIA). And based on this data association relationship, the second sub-data of the resource to be detected corresponding to each first sub-data of the resource to be detected can be determined, thereby obtaining the second set of resources to be detected. For example, the second set of resources to be detected may be P_CER1: 192.0.2.0 / 23; P_CER2: 192.0.3.0 / 23.
[0152] Furthermore, for each first sub-data of the resource to be detected (the Internet Protocol address prefix of the sub-certificate) in the first set of resources to be detected, it can be matched with the second sub-data of the resource to be detected (the Internet Protocol address prefix of the parent certificate) corresponding to the data association relationship in the second set of resources to be detected, obtaining the first matching result. For example, if the first sub-data of the resource to be detected is 192.0.2.0 / 24, in the second set of resources to be detected, the second sub-data of the resource to be detected having a data association relationship with it is 192.0.2.0 / 24. Since 192.0.2.0 / 24 contains 192.0.2.0 / 24, this indicates that the superior CA corresponding to 192.0.2.0 / 24 has not allocated an Internet Protocol address prefix that does not belong to itself to the subordinate CA, and 192.0.2.0 / 24 and 192.0.2.0 / 24 meet the non-conflict condition. Then it shows that the first sub-data of the resource to be detected, 192.0.2.0 / 24, is legal, and the matching of the first sub-data of the resource to be detected, 192.0.2.0 / 24, in the second set of resources to be detected can be stopped, and other first sub-data of the resource to be detected in the first set of resources to be detected can be selected to continue the matching with the second set of resources to be detected.
[0153] Further, if the first resource sub-data to be tested is 192.0.2.0 / 23, and in the second set to be tested, the second resource sub-data to be tested that has a data association relationship with it is 172.81.3.0 / 23. Since 172.81.3.0 / 23 does not contain 192.0.2.0 / 23, this indicates that the superior CA corresponding to 192.0.2.0 / 23 has assigned an Internet Protocol address prefix that does not belong to itself to the subordinate CA, and 192.0.2.0 / 23 and 172.81.3.0 / 23 do not meet the non-conflict condition.
[0154] Specifically, when all the first resource sub-data to be tested in the first set to be tested have been detected, the first resource sub-data that does not meet the non-conflict condition and the second resource sub-data that has a data association relationship with the first resource sub-data can be determined as the target resource sub-data to be tested, and the target resource sub-data to be tested is used as the conflict detection result of the illegal allocation conflict detection item corresponding to the resource allocation data to be tested in the Internet Protocol address prefix.
[0155] Further, an illegal allocation conflict detection table corresponding to the Internet Protocol address prefix can be set up, and the sub-certificate and parent-certificate information that does not meet the non-conflict condition can be recorded in the illegal allocation conflict table corresponding to the Internet Protocol address prefix. Exemplarily, the illegal allocation conflict detection table can record information such as the Internet Protocol address prefix declared in the conflicting parent certificate, the Internet Protocol address prefix declared in the sub-certificate, the parent-certificate URI, the sub-certificate URI, the illegally allocated Internet Protocol address prefix, etc.
[0156] Through the above method, the logic of resource abnormal allocation detection can be simplified to facilitate quickly and accurately determining the conflict detection result of the illegal allocation conflict detection item in the detection scenario of the Internet Protocol address prefix.
[0157] In some embodiments, in order to comprehensively, quickly, and accurately determine the final conflict detection result, non-conflict conditions can be defined and applied to exclude non-conflicting data, thereby accurately determining the conflict detection result of the resource allocation data to be tested under this conflict detection item. For example, when the conflict detection item is an illegal allocation conflict detection item, the corresponding target lookup table is the resource certificate table. At this time, the "excluding the first resource sub-data to be tested that meets the non-conflict condition and the corresponding second resource sub-data to be tested, and determining the remaining target resource sub-data to be tested after the exclusion as the conflict detection result of the corresponding conflict detection item" in step 104 can further include:
[0158] (104.b1) For each first resource sub - data to be detected in the first set to be detected, match the autonomous system number of the first resource sub - data to be detected with at least one second resource sub - data to be detected having a data association relationship with the corresponding data in the second set to be detected, and obtain a second matching result; wherein, the first resource sub - data to be detected is the autonomous system number corresponding to the sub - certificate, and the second resource sub - data to be detected is the autonomous system number of the parent certificate corresponding to the sub - certificate;
[0159] (104.b2) When the second matching result indicates that there is a target second resource sub - data with a data association relationship with the first resource sub - data to be detected that meets the inclusion relationship, determine that the first resource sub - data to be detected and the target second resource sub - data satisfy the non - conflict condition;
[0160] (104.b3) In the first set to be detected, exclude the first resource sub - data to be detected and the target second resource sub - data that satisfy the non - conflict condition, and determine the remaining first resource sub - data to be detected and the second resource sub - data to be detected having a data association relationship with the remaining first resource sub - data to be detected as the target resource sub - data to be detected;
[0161] (104.b4) Determine the target resource sub - data to be detected as the conflict detection result of the illegal allocation conflict detection item of the resource to be allocated data for the autonomous system number.
[0162] Among them, the autonomous system number can be a number that uniquely identifies an autonomous system in the Internet. An autonomous system refers to a group of routers controlled by a management entity, and these routers use the same routing policy.
[0163] Among them, the second matching result can be the result obtained by matching the first resource sub - data to be detected (the autonomous system number corresponding to the sub - certificate) with all second resource sub - data to be detected (the autonomous system number of the parent certificate) having a data association relationship in the illegal allocation conflict detection item. The second matching result is used to indicate whether the first resource sub - data to be detected and the second resource sub - data to be detected meet the inclusion relationship. For example, if the autonomous system number of the sub - certificate is included in the autonomous system number of its parent certificate, the second matching result is "meets the inclusion relationship".
[0164] Among them, the target second resource sub - data can be the second resource sub - data that has a data association relationship with the first resource sub - data to be detected and meets the non - conflict condition during the matching process. When the conflict detection item is the illegal allocation conflict detection item for the autonomous system number, the target second resource sub - data can be the autonomous system number of the parent certificate, and there is an inclusion relationship between this number and the autonomous system number of the sub - certificate.
[0165] Among them, the non-conflict condition may refer to the inclusion relationship of the autonomous system number between the first resource sub-data to be measured and the second resource sub-data to be measured, so that there is no conflict between the two. When the conflict detection item is an illegal allocation conflict detection item for the autonomous system number, the non-conflict condition may be that the autonomous system number of the sub-certificate is included in the autonomous system number of its parent certificate.
[0166] Among them, the target resource sub-data to be measured may be the remaining first resource sub-data to be measured that do not meet the non-conflict condition after excluding the first resource sub-data to be measured that meet the non-conflict condition, and the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured.
[0167] It can be understood that when the superior CA in the certificate chain assigns an autonomous system number that does not belong to itself to the subordinate CA, an illegal allocation conflict will occur. Exemplarily, CA1 assigns the autonomous system number 265677 that does not belong to itself to the subordinate CA2, and this process belongs to the illegal allocation of the autonomous system number.
[0168] Exemplarily, when the conflict detection item is an illegal allocation conflict detection item for the autonomous system number, the corresponding target lookup table that can be matched is the resource certificate table. According to the resource certificate table, the first set C to be detected corresponding to the first resource sub-data to be measured, and the second set D to be detected corresponding to the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured are determined. Then, each first resource sub-data to be measured in the first set to be detected is matched with the second resource sub-data to be measured corresponding to the data association relationship in the second set to be detected to obtain a second matching result. And according to the matching result, the first resource sub-data to be measured in the first set to be detected that meets the non-conflict condition with the target second resource sub-data to be measured is excluded. After traversing all the first resource sub-data to be measured in the first set to be detected, the first resource sub-data to be measured that does not meet the non-conflict condition and the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured can be used as the target resource sub-data to be measured, and the target resource sub-data to be measured is determined as the conflict detection result of the illegal allocation conflict detection item of the resource allocation data to be measured for the autonomous system number.
[0169] Further, for each first resource sub-data to be tested, match all the second resource sub-data with corresponding data association relationships in the second set to be detected. As long as there is at least one second resource sub-data that satisfies the non-conflict condition with the first resource sub-data, then the first resource sub-data is legal, and the matching of the first resource sub-data can be stopped, and the matching of the next resource sub-data to be tested in the first set to be detected can be started; conversely, if the first resource sub-data does not satisfy the non-conflict condition with all the second resource sub-data with corresponding data association relationships, it indicates that the first resource sub-data is illegal, and the illegal first resource sub-data and the second resource sub-data with corresponding data association relationships are determined as the target resource sub-data to be tested.
[0170] Exemplarily, by looking up the resource certificate table, all sub-certificates (i.e., records with non-empty CERS.AIA) can be screened out, and the autonomous system numbers of these sub-certificates are used as the first set to be detected. For example, the first set to be detected may include CER1: 65001; CER2: 65002; CER3: 63256; CER4: 69532.
[0171] Further, the data association relationship between the first resource sub-data to be tested and the second resource sub-data to be tested can be determined according to the illegal allocation conflict detection items corresponding to the autonomous system numbers. Specifically, it can be that the URI of the parent certificate is equal to the authoritative information access point field of the sub-certificate (i.e., P_CERS.URI = C_CERS.AIA). And based on this data association relationship, the second resource sub-data corresponding to each first resource sub-data to be tested is determined, so as to obtain the second set to be detected. For example, the second set to be detected may be P_CER1: 66380; P_CER2: 69532, etc.
[0172] Further, for each first resource sub-data (the autonomous system number of the sub-certificate) in the first set to be detected, it can be matched with the second resource sub-data (the autonomous system number of the parent certificate) with corresponding data association relationships in the second set to be detected to obtain the second matching result. For example, if the first resource sub-data to be tested is 69532, in the second set to be detected, the second resource sub-data with a data association relationship with it is 69532. Since 69532 contains 69532, it indicates that the superior CA corresponding to 69532 has not assigned an autonomous system number that does not belong to itself to the subordinate CA, and 69532 and 69532 satisfy the non-conflict condition. At this time, it can be confirmed that the first resource sub-data 69532 is a legally allocated autonomous system number, and the matching of the first resource sub-data 69532 is stopped, and the matching of the remaining first resource sub-data in the first set to be detected is continued.
[0173] Further, if the first resource sub-data to be tested is 66380, and in the second set to be tested, the second resource sub-data having a data association relationship with it is 63201. Since 63201 does not contain 66380, this indicates that the superior CA corresponding to 66380 assigns an autonomous system number that does not belong to itself to the subordinate CA, and 66380 and 63201 do not meet the non-conflict condition.
[0174] Specifically, after matching all the first resource sub-data to be tested in the first set to be tested, the first resource sub-data that meets the non-conflict condition can be excluded, and the remaining first resource sub-data that does not meet the non-conflict condition and the second resource sub-data with the corresponding data association relationship are determined as the target resource sub-data to be tested, and the target resource sub-data to be tested is determined as the conflict detection result of the illegal allocation conflict detection item of the resource allocation data to be tested for the autonomous system number.
[0175] Further, an illegal allocation conflict detection table corresponding to the autonomous system number (or autonomous domain resource) can be set, and the sub-certificate and parent-certificate information that does not meet the non-conflict condition is recorded in the illegal allocation conflict table corresponding to the autonomous system number. Exemplarily, the illegal allocation conflict detection table can record information such as the autonomous system number corresponding to the conflicting parent certificate, the autonomous system number corresponding to the sub-certificate, the parent-certificate URI, the sub-certificate URI, the illegally allocated autonomous system number, etc.
[0176] Through the above method, the logic of resource abnormal allocation detection can be simplified to facilitate quickly and accurately determining the conflict detection result of the illegal allocation conflict detection item in the detection scenario of the autonomous system number.
[0177] In some embodiments, in order to comprehensively, quickly, and accurately determine the final conflict detection result, non-conflicting data can be excluded by defining and applying non-conflict conditions to accurately determine the conflict detection result of the resource allocation data to be tested under this conflict detection item. For example, when the conflict detection item is an illegal authorization conflict detection item, the corresponding target lookup tables for matching are the resource certificate table and the route origin authorization table. At this time, the "excluding the first resource sub-data to be tested that meets the non-conflict condition and the corresponding second resource sub-data to be tested, and determining the remaining target resource sub-data to be tested after exclusion as the conflict detection result of the corresponding conflict detection item" in step 104 can further include:
[0178] (104.c1) For each first resource sub-data to be detected in the first set to be detected, match the first resource sub-data to be detected with at least one second resource sub-data of the corresponding data association relationship in the second set to be detected for the Internet Protocol address prefix, and obtain a third matching result; wherein, the first resource sub-data to be detected is the first authorized Internet Protocol address prefix corresponding to the autonomous system, and the second resource sub-data to be detected is the Internet Protocol address prefix of the parent certificate corresponding to the autonomous system;
[0179] (104.c2) When the third matching result indicates that there is a target third resource sub-data of the corresponding data association relationship with the first resource sub-data to be detected that meets the inclusion relationship, determine that the first resource sub-data to be detected and the target third resource sub-data meet the non-conflict condition;
[0180] (104.c3) In the first set to be detected, exclude the first resource sub-data to be detected and the target third resource sub-data that meet the non-conflict condition, and determine the remaining first resource sub-data to be detected and the second resource sub-data that have a data association relationship with the remaining first resource sub-data to be detected as the target resource sub-data to be detected;
[0181] (104.c4) Determine the target resource sub-data to be detected as the conflict detection result of the resource allocation data to be detected in the illegal authorization conflict detection item.
[0182] Among them, the third matching result can be the result obtained by matching the first resource sub-data to be detected (the first authorized Internet Protocol address prefix corresponding to the autonomous system) with the second resource sub-data to be detected (the Internet Protocol address prefix corresponding to the parent certificate) in the illegal authorization conflict detection item. The third matching result is used to indicate whether the first resource sub-data to be detected and the second resource sub-data meet the inclusion relationship. For example, if the first authorized Internet Protocol address prefix 192.0.2.0 / 24 is included in the Internet Protocol address prefix 192.0.2.0 / 24 of its parent certificate, the third matching result is "meets the inclusion relationship".
[0183] Among them, the first authorized Internet Protocol address prefix can be the first Internet Protocol address prefix authorized for use by the autonomous system. The first authorized Internet Protocol address prefix can be extracted from the Route Origin Authorization (ROA) table, while the Internet Protocol address prefix corresponding to its corresponding parent certificate is extracted from the resource certificate table.
[0184] Among them, the data association relationship can be a way or rule for determining the mutual association between the first resource sub-data to be tested (sub-certificate) and the second resource sub-data to be tested (parent certificate) in the illegal authorization conflict detection item. In the illegal authorization conflict detection item, the data association relationship is established by the equality of the URI of the parent certificate (CERS.URI) and the authoritative information access point field of the routing origin authorization file (ROAS.AIA), that is, CERS.URI = ROAS.AIA, which means that the Internet protocol address prefix of the autonomous system is authorized by the specified parent certificate, and the authorized Internet protocol address prefix of the autonomous system should be within the Internet protocol address prefix range of the parent certificate.
[0185] Among them, the non-conflict condition can be that the inclusion relationship of the Internet protocol address prefix is satisfied between the first resource sub-data to be tested and the second resource sub-data to be tested, so that there is no conflict between them. When the conflict detection item is an illegal authorization conflict detection item, the non-conflict condition can be that the first authorized Internet protocol address prefix is included in the Internet protocol address prefix of its parent certificate.
[0186] Among them, the target third resource sub-data to be tested can be the second resource sub-data to be tested that has a data association relationship with the first resource sub-data to be tested and satisfies the non-conflict condition during the matching process.
[0187] Among them, the target resource sub-data to be tested can be the remaining first resource sub-data to be tested that does not satisfy the non-conflict condition after excluding the first resource sub-data to be tested that satisfies the non-conflict condition, and the second resource sub-data to be tested that has a data association relationship with the first resource sub-data to be tested.
[0188] Specifically, the illegal authorization conflict can be that the superior CA authorizes the Internet protocol address prefix that does not belong to itself to other autonomous systems. Exemplarily, CA1 authorizes the Internet protocol address prefix 193.30.12.0 / 22 that does not belong to itself to AS65001, and this process belongs to illegal authorization.
[0189] Exemplarily, when the conflict detection item is an illegal authorization conflict detection item, the corresponding target lookup tables that can be matched are the resource certificate table and the route origin authorization table. First, according to the route origin authorization table, the first set to be detected E corresponding to the first resource sub-data to be tested can be determined, and according to the resource certificate table, the second set to be detected F corresponding to the second resource sub-data to be tested that has a data association relationship with the first resource sub-data to be tested can be determined. Then, each first resource sub-data in the first set to be detected E is matched with the second resource sub-data corresponding to the data association relationship in the second set to be detected F to obtain a third matching result. And according to the matching result, the first resource sub-data to be tested that meets the non-conflict condition and the second resource sub-data to be tested that has a data association relationship with the first resource sub-data to be tested are excluded. After traversing each first resource sub-data in the first set to be detected, the remaining first resource sub-data to be tested after exclusion and the second resource sub-data to be tested that has a data association relationship with the first resource sub-data to be tested can be determined as the target resource sub-data to be tested, and the target resource sub-data to be tested is determined as the conflict detection result of the resource allocation data to be tested in the illegal authorization conflict detection item.
[0190] Further, for each first resource sub-data to be tested, it is matched with all the second resource sub-data corresponding to the data association relationship in the second set to be detected. As long as there is at least one second resource sub-data that meets the non-conflict condition with the first resource sub-data to be tested, then the first resource sub-data to be tested is legal, and the matching of the first resource sub-data to be tested can be stopped, and the matching of the next resource sub-data to be tested in the first set to be detected can be started; otherwise, if the first resource sub-data to be tested does not meet the non-conflict condition with all the second resource sub-data corresponding to the data association relationship, it indicates that the first resource sub-data to be tested is illegal, and the illegal first resource sub-data to be tested and the second resource sub-data to be tested corresponding to the data association relationship are determined as the target resource sub-data to be tested.
[0191] Please refer to Figure 4 , exemplarily, all autonomous systems can be screened out by looking up the route origin authorization table (i.e., records where ROAS.AIA is not empty), and the Internet Protocol address prefixes of these autonomous systems are used as the first set to be detected. For example, the first set to be detected may include ROA1: 192.0.2.0 / 24; ROA2: 192.0.2.128 / 25; ROA3: 192.0.3.0 / 24; ROA4: 192.0.3.128 / 25.
[0192] Further, the data association relationship between the first resource sub-data to be tested and the second resource sub-data to be tested can be determined according to the illegal authorization conflict detection item. Specifically, it can be established by the equality of the URI of the parent certificate (CERS.URI) and the authoritative information access point field of the routing origin authorization file (ROAS.AIA), that is, CERS.URI = ROAS.AIA. And based on this data association relationship, the second resource sub-data corresponding to each first resource sub-data to be tested in the resource certificate set is determined, so as to obtain the second set to be detected. For example, the second set to be detected can be P_CER1: 192.0.2.0 / 23; P_CER2: 192.0.3.0 / 23.
[0193] Further, for each first resource sub-data (the first authorized Internet protocol address prefix) in the first set to be detected, it can be matched with the second resource sub-data (the Internet protocol address prefix of the parent certificate corresponding to the autonomous system) with the corresponding data association relationship in the second set to be detected to obtain the third matching result. For example, if the first resource sub-data to be tested is 192.0.2.0 / 24, in the second set to be detected, the second resource sub-data with the data association relationship with it is 192.0.2.0 / 24. Since 192.0.2.0 / 24 contains 192.0.2.0 / 24, this indicates that the superior CA corresponding to 192.0.2.0 / 24 has not authorized the Internet protocol address prefix that does not belong to itself to the subordinate autonomous system, and 192.0.2.0 / 24 and 192.0.2.0 / 24 meet the non-conflict condition, and the first resource sub-data 192.0.2.0 / 24 is legal, and the matching of the first resource sub-data to be tested can be stopped, and the matching of the remaining first resource sub-data to be tested in the first set to be detected can be continued.
[0194] Further, if the first resource sub-data to be tested is 192.0.2.0 / 23, in the second set to be detected, the second resource sub-data with the data association relationship with it is 172.81.3.0 / 23. Since 172.81.3.0 / 23 does not contain 192.0.2.0 / 23, this indicates that the superior CA corresponding to 192.0.2.0 / 23 has authorized the Internet protocol address prefix that does not belong to itself to the subordinate autonomous system, and 192.0.2.0 / 23 and 172.81.3.0 / 23 do not meet the non-conflict condition.
[0195] Specifically, after all the first resource sub-data to be tested in the first set to be tested are matched, the first resource sub-data that meet the non-conflict condition can be excluded, and the remaining first resource sub-data that do not meet the non-conflict condition and the second resource sub-data corresponding to the data association relationship are determined as the target resource sub-data to be tested. The target resource sub-data to be tested is determined as the conflict detection result of the illegal authorization conflict detection item corresponding to the resource allocation data to be tested.
[0196] Furthermore, an illegal authorization conflict detection table can be set up, and the autonomous systems and parent certificate information that do not meet the non-conflict condition are recorded in the illegal authorization conflict detection table. Exemplarily, the illegal authorization conflict detection table can record the URI of the autonomous system where the conflict occurs, the URI of the parent certificate, the Internet protocol address prefix declared in the parent certificate, the first authorized Internet protocol address prefix of the autonomous system, the autonomous system number, and so on.
[0197] Through the above method, the logic of resource abnormal allocation detection can be simplified, so as to quickly and accurately determine the conflict detection result for the illegal authorization conflict detection item.
[0198] In some embodiments, in order to comprehensively, quickly, and accurately determine the final conflict detection result, non-conflict conditions can be defined and applied to exclude non-conflicting data, so as to accurately determine the conflict detection result of the resource allocation data to be tested under this conflict detection item. For example, when the conflict detection item is an inter-sub-certificate conflict detection item, the target lookup table matched by the inter-sub-certificate conflict detection item is a resource certificate radix tree generated based on the resource certificate table. At this time, "excluding the first resource sub-data to be tested that meet the non-conflict condition and the corresponding second resource sub-data to be tested, and determining the remaining target resource sub-data to be tested after exclusion as the conflict detection result of the corresponding conflict detection item" in step 104 can further include:
[0199] (104.d1) For each first resource sub-data to be tested in the first set to be tested, match the unified resource identifier of the first resource sub-data to be tested with at least one second resource sub-data to be tested corresponding to the data association relationship in the second set to be tested, and obtain a fourth matching result; wherein, the first resource sub-data to be tested is the first Internet protocol address prefix corresponding to the first sub-certificate, and the second resource sub-data to be tested is the second Internet protocol address prefix that has an inclusion relationship with the first Internet protocol address prefix of the first sub-certificate in the resource certificate radix tree;
[0200] (104.d2) When the fourth matching result indicates that the uniform resource identifier of the target fourth resource sub-data to be measured is equal to the uniform resource identifier of the first resource sub-data to be measured, it is determined that the first resource sub-data to be measured and the target fourth resource sub-data to be measured meet the non-conflict condition; or, when the fourth matching result indicates that the uniform resource identifier of the target fourth resource sub-data to be measured is equal to the uniform resource identifier of the upper-level certificate of the first resource sub-data to be measured, it is determined that the first resource sub-data to be measured and the target fourth resource sub-data to be measured meet the non-conflict condition;
[0201] (104.d3) Exclude the target fourth resource sub-data to be measured that meets the non-conflict condition with the first resource sub-data to be measured, and determine the second resource sub-data to be measured that remains after the exclusion and has a data association relationship with the first resource sub-data to be measured as the target resource sub-data to be measured;
[0202] (104.d4) Use the target resource sub-data to be measured as the first sub-conflict detection result of the first resource sub-data to be measured, and determine the conflict detection result of the resource allocation data in the sub-certificate conflict detection item for the multiple first sub-conflict detection results corresponding to the multiple first resource sub-data to be measured in the first set to be detected.
[0203] Among them, the resource certificate radix tree can be a radix tree data structure based on classless inter-domain routing, used to efficiently store and query the Internet Protocol address prefixes and their related information in the resource certificate table.
[0204] Among them, the uniform resource identifier can be a URI, used to uniquely identify resources on the Internet.
[0205] Among them, the fourth matching result can be the result obtained by matching the uniform resource identifiers of the first resource sub-data to be measured (the first Internet Protocol address prefix corresponding to the first sub-certificate) and the second resource sub-data to be measured (the second Internet Protocol address prefix in the resource certificate radix tree that has an inclusion relationship with the first Internet Protocol address prefix of the first sub-certificate) in the sub-certificate conflict detection item.
[0206] Among them, the first sub-certificate can be all valid certificates in the resource certificate table corresponding to the resource allocation data to be measured except for the five major trust anchor certificates.
[0207] Among them, the target fourth resource sub-data to be measured can be the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured and meets the non-conflict condition during the matching process.
[0208] Among them, the non-conflict condition can be that the URI of the second resource sub-data to be measured is equal to the URI of the first sub-certificate of the first resource sub-data to be measured, or the URI of the second resource sub-data to be measured is equal to the URI of the upper-level certificate of the first sub-certificate.
[0209] Among them, the first sub-conflict detection result may be the remaining second to-be-tested resource sub-data after excluding all first to-be-tested resource sub-data and corresponding second to-be-tested resource sub-data that meet the non-conflict conditions.
[0210] Please refer to Figure 5 , in some embodiments, the construction process of the resource certificate radix tree of the present application is introduced. First, an empty resource certificate radix tree can be created, and all valid certificate records except the five major trust anchor certificates are obtained from the resource certificate table (since the Internet protocol address resources corresponding to the five major trust anchor certificates are 0.0.0.0 / 0 and :: / 0, which include all Internet protocol address prefixes and do not belong to the scope of anomaly detection). The address resources (IP Resources), URIs, AIAs, etc. of each resource certificate are obtained. Further, the Internet protocol address prefix of each resource certificate record is extracted, and it is checked whether the current Internet protocol address prefix already exists in the resource certificate radix tree. If not, a new Internet protocol address prefix node is inserted, and an empty object list is created for this node. Information such as URIs and AIAs associated with the Internet protocol address prefix is added to the object list. If it exists, the new URIs, AIAs, etc. are added to the object list of the existing Internet protocol address prefix node. The next resource certificate record is continued to be processed until all records are processed. By establishing the resource certificate radix tree, it is convenient to perform conflict detection quickly and accurately in the follow-up. Especially when dealing with a large amount of data with common Internet protocol address prefixes, the detection efficiency can be greatly improved. Further, when constructing the resource certificate radix tree and inserting nodes, it can be constructed according to the Internet protocol address prefix. For example, the Internet protocol address prefixes with the same or similar Internet protocol address prefixes are placed within the same node range to further accelerate the detection efficiency.
[0211] Specifically, the conflict between sub-certificates refers to the problem of duplicate allocation or overlapping allocation of Internet protocol address prefixes or autonomous domain resources between certificates. For example, in the duplicate allocation between sub-certificates, CA1 duplicates the Internet protocol address prefix 192.0.2.128 / 26 to the subordinate CA2 and subordinate CA3. This process belongs to the duplicate allocation of IP prefix resources between sub-certificates. Exemplarily, in the overlapping allocation between sub-certificates, CA1 allocates the overlapping Internet protocol address prefixes 192.0.2.128 / 26 and 192.0.131 / 26 to the subordinate CA2 and subordinate CA3 respectively. This process belongs to the overlapping allocation of Internet protocol address prefixes between sub-certificates. The duplicate allocation and overlapping allocation of autonomous domain resources between sub-certificates also belong to the conflict between sub-certificates, and the conflict logic is similar to the above description and will not be elaborated here.
[0212] Please refer toFigure 6 Exemplarily, when the conflict detection item is for conflict detection between sub-certificates, the corresponding target lookup table that can be matched is a resource certificate radix tree generated based on the resource certificate table. And according to the resource certificate table, all valid certificates except the five major trust anchor certificates are determined as the first sub-certificates, and address information such as the Internet Protocol address prefix, URI, AIA, etc. of each first sub-certificate are obtained.
[0213] Furthermore, the first Internet Protocol address prefix corresponding to the first sub-certificate can be used as the first sub-data of the resource to be tested, so as to obtain a first set to be detected corresponding to multiple first sub-data of the resource to be tested. Furthermore, by traversing each first sub-data of the resource to be tested in the resource certificate radix tree, a second set to be detected corresponding to the second sub-data of the resource to be tested that has a data association relationship with the first sub-data of the resource to be tested (there is a duplicate or overlapping part between the Internet Protocol address prefixes of the first sub-data of the resource to be tested and the second sub-data of the resource to be tested) can be determined. Furthermore, based on the resource certificate radix tree, an object list of the second resource to be tested can be obtained to obtain information such as the URI and AIA of the second sub-data of the resource to be tested.
[0214] Furthermore, according to the non-conflict conditions for conflicts between sub-certificates, each first sub-data of the resource to be tested and multiple second sub-data of the resource to be tested with corresponding data association relationships can be screened to determine the target fourth sub-data of the resource to be tested that satisfies the non-conflict relationship with the first sub-data of the resource to be tested, and the remaining second sub-data of the resource to be tested is used as the first sub-conflict detection result corresponding to the first sub-data of the resource to be tested. For example, for the first sub-data of the resource to be tested 192.0.128.0 / 24, the corresponding second sub-data of the resource to be tested are 192.0.128.0 / 24, 192.0.128.0 / 23, and 192.0.128.0 / 20. At this time, the URI 1 corresponding to the first sub-data of the resource to be tested, and the URI2, URI3, and URI4 corresponding to the second sub-data of the resource to be tested can be obtained.
[0215] Furthermore, when URI2 = URI 1, it indicates that the second sub-data of the resource to be tested 192.0.128.0 / 24 is the first sub-data of the resource 192.0.128.0 / 24 itself, satisfying the non-conflict condition; when URI3 is the URI of the upper-layer certificate of URI 1, then this second sub-data of the resource to be tested also satisfies the non-conflict condition with the first sub-data of the resource to be tested. And when URI4 is neither equal to URI 1 nor equal to the URI of the upper-layer certificate of URI 1, then this second sub-data of the resource to be tested does not satisfy the non-conflict condition with the first sub-data of the resource to be tested, and 192.0.128.0 / 20 is used as the first sub-conflict detection result of the first sub-data of the resource to be tested 192.0.128.0 / 24.
[0216] Further, when all the first resource sub - data to be detected in the first set to be detected are detected, all the first sub - conflict detection results corresponding to all the first resource sub - data to be detected are used as the conflict detection results of the conflict detection item of the resource allocation data to be detected among sub - certificates.
[0217] It can be understood that the conflict detection item among sub - certificates also includes duplicate allocation and overlapping allocation of autonomous domain resources among sub - certificates. The detection process is similar to the above - mentioned scheme and will not be elaborated here.
[0218] In some embodiments, a conflict detection table among sub - certificates can be established, and after the detection is completed, the conflicting certificate information can be saved into the sub - certificate conflict table. For example, the certificate information can include the Internet Protocol address prefix where the conflict among sub - certificates occurs, the URIs, AIAs, etc. of the conflicting sub - certificates.
[0219] By constructing a resource certificate radix tree, a large number of Internet Protocol address prefixes and their related information can be systematically stored and managed, optimizing memory usage and improving the query efficiency for conflicts among sub - certificates.
[0220] In some embodiments, in order to comprehensively, quickly, and accurately determine the final conflict detection result, non - conflict conditions can be defined and applied to exclude non - conflicting data, so as to accurately determine the conflict detection result of the resource allocation data to be detected under this conflict detection item. For example, when the conflict detection item is the conflict detection item between a sub - certificate and a routing origin authorization, the target lookup table matched by the conflict detection item between the sub - certificate and the routing origin authorization is a resource certificate radix tree generated based on the resource certificate table. At this time, the "excluding the first resource sub - data to be detected and the corresponding second resource sub - data that meet the non - conflict conditions, and determining the remaining target resource sub - data to be detected after the exclusion as the conflict detection result of the corresponding conflict detection item" in step 104 can further include:
[0221] (104.e1) For each first resource sub - data to be detected in the first set to be detected, match the unified resource identifiers of at least one second resource sub - data with the corresponding data association relationship in the second set to be detected, and obtain a fifth matching result; wherein, the first resource sub - data to be detected is the second authorized Internet Protocol address prefix corresponding to the autonomous system, and the second resource sub - data to be detected is the third Internet Protocol address prefix that has an inclusion relationship with the second authorized Internet Protocol address prefix in the resource certificate radix tree;
[0222] (104.e2) When the fifth matching result indicates that the unified resource identifier of the target fifth resource sub - data is equal to the unified resource identifier of the upper - layer certificate of the first resource sub - data to be detected, determine that the first resource sub - data to be detected and the target fifth resource sub - data meet the non - conflict conditions;
[0223] (104.e3) Exclude the target fifth sub-data to be measured that meets the non-conflict condition with the first sub-data to be measured, and determine the second sub-data to be measured that remains after the exclusion and has a data association relationship with the first sub-data to be measured as the target sub-data to be measured;
[0224] (104.e4) Use the target sub-data to be measured as the second sub-conflict detection result of the first sub-data to be measured, and determine the conflict detection result of the sub-certificate and the routing origin authorization conflict detection item for the multiple second sub-conflict detection results corresponding to the multiple first sub-data to be measured in the first set to be detected.
[0225] Among them, the fifth matching result can be the result obtained by performing a uniform resource identifier match between the first sub-data to be measured (i.e., the second authorized Internet protocol address prefix corresponding to the autonomous system) and at least one second sub-data to be measured in the second set to be detected (i.e., the third Internet protocol address prefix that has an inclusion relationship with the second authorized Internet protocol address prefix in the resource certificate radix tree) in the sub-certificate and the routing origin authorization conflict detection item.
[0226] Among them, the second authorized Internet protocol address prefix can be the Internet protocol address prefix specified in the routing origin authorization file and legally declared by the autonomous system. The second authorized Internet protocol address prefix is the IP address range authorized for use by the autonomous system.
[0227] Among them, the third Internet protocol address prefix can be the Internet protocol address prefix existing in the resource certificate radix tree, and these prefixes have an inclusion relationship with the second authorized Internet protocol address prefix. In other words, the third Internet protocol address prefix is the Internet protocol address prefix defined in the resource certificate, and may have an overlap or inclusion relationship with the Internet protocol address prefix in the autonomous system.
[0228] Among them, the target fifth sub-data to be measured can be the second sub-data to be measured that meets the non-conflict condition in the fifth matching result. Specifically, if the uniform resource identifier (URI) of the second sub-data to be measured is equal to the uniform resource identifier (AIA) of the upper-layer certificate of the first sub-data to be measured, then this second sub-data to be measured is considered the target fifth sub-data to be measured.
[0229] Among them, the non-conflict condition can be that in the sub-certificate and the routing origin authorization conflict detection item, when the uniform resource identifier (URI) of the second sub-data to be measured is equal to the uniform resource identifier (AIA) of the upper-layer certificate of the first sub-data to be measured, it is considered that there is no conflict between the two.
[0230] Among them, the data association relationship can be whether the Internet protocol address between the first resource to be tested sub-data (the second authorized Internet protocol address prefix) and the second resource to be tested sub-data (the third Internet protocol address prefix) in the resource certificate radix tree is included (duplicated or overlapped).
[0231] Among them, the second sub-conflict detection result can be the remaining second resource to be tested sub-data after excluding all target fifth resource to be tested sub-data that meet the non-conflict conditions.
[0232] Specifically, the conflict between the sub-certificate and the route origin authorization refers to the problem of duplicate allocation (or authorization) and overlapping allocation (or authorization) of Internet protocol address prefixes between the sub-certificate and the route origin authorization (ROA). Exemplarily, in the duplicate allocation (or authorization) between the sub-certificate and the route origin authorization (AS≠0), CA1 allocates the Internet protocol address prefix 192.0.2.128 / 26 to the subordinate CA2 and authorizes it to be used by AS65001 at the same time. This process belongs to the problem of duplicate allocation (or authorization) of Internet protocol address prefixes between the sub-certificate and the route origin authorization (AS≠0); Exemplarily, in the overlapping allocation (or authorization) between the sub-certificate and the route origin authorization (AS≠0), CA1 allocates the Internet protocol address prefix 192.0.2.128 / 26 to the subordinate CA2 and authorizes the overlapping Internet protocol address prefix 192.0.131 / 26 to AS65001 at the same time. This process belongs to the problem of overlapping allocation (or authorization) of IP address resources between the sub-certificate and the route origin authorization (AS≠0). The above situations all belong to the conflict problem between the sub-certificate and the route origin authorization.
[0233] Exemplarily, in the duplicate allocation (or authorization) between the sub-certificate and the route origin authorization (AS=0), CA1 allocates the Internet protocol address prefix 192.0.2.128 / 26 to the subordinate CA2 and authorizes it to the autonomous system AS0 as a reserved resource at the same time. This process belongs to the problem of duplicate allocation (or authorization) of Internet protocol address prefixes between the sub-certificate and the route origin authorization (AS=0); Exemplarily, in the overlapping allocation (or authorization) between the sub-certificate and the route origin authorization (AS=0), CA1 allocates the Internet protocol address prefix 192.0.2.128 / 26 to the subordinate CA2 and authorizes the overlapping Internet protocol address prefix 192.0.131 / 26 to AS0 as a reserved resource at the same time. This process belongs to the problem of overlapping allocation (or authorization) of Internet protocol address prefixes between the sub-certificate and the route origin authorization (AS=0). The above situations all belong to the conflict problem between the sub-certificate and the route origin authorization.
[0234] Please refer to Figure 7, Exemplarily, the following gives an example of the detection process for the conflict detection item between the sub-certificate and the routing origin authorization. Exemplarily, when the conflict detection item is for the conflict detection item between the sub-certificate and the routing origin authorization, the corresponding target lookup table that can be matched is the resource certificate radix tree generated according to the resource certificate table. And according to the routing origin authorization table, determine multiple second authorized Internet protocol address prefixes corresponding to the autonomous system, and use them as the first to-be-tested resource sub-data to obtain a first to-be-detected set composed of multiple first to-be-tested resource sub-data. Further, information such as the URI, AIA, and autonomous system number of each first to-be-tested resource sub-data can be obtained.
[0235] Further, by traversing each first to-be-tested resource sub-data in the resource certificate radix tree, a second to-be-detected set corresponding to the second to-be-tested resource sub-data having a data association relationship (there is a duplicate or overlapping part in the Internet protocol address prefix between the first to-be-tested resource sub-data and the second to-be-tested resource sub-data) with the first to-be-tested resource sub-data can be determined. Further, based on the resource certificate radix tree, an object list of the second to-be-tested resource can be obtained to obtain information such as the URI and AIA of the second to-be-tested resource sub-data.
[0236] Further, according to the non-conflict condition of the conflict between the sub-certificate and the routing origin authorization, each first to-be-tested resource sub-data and multiple second to-be-tested resource sub-data with corresponding data association relationships can be screened to determine the target fifth to-be-tested resource sub-data that satisfies the non-conflict relationship with the first to-be-tested resource sub-data, and the remaining second to-be-tested resource sub-data is used as the second sub-conflict detection result corresponding to the first to-be-tested resource sub-data.
[0237] For example, for the first to-be-tested resource sub-data 192.0.128.0 / 24, its corresponding second to-be-tested resource sub-data are 192.0.128.0 / 24, 192.0.128.0 / 23, and 192.0.128.0 / 20. At this time, the URI 1 corresponding to the first to-be-tested resource sub-data, and the URI2, URI3, and URI4 corresponding to the second to-be-tested resource sub-data can be obtained.
[0238] Further, when URI2 and URI3 are the URIs of the upper-layer certificate of URI 1, the second to-be-tested resource sub-data and the first to-be-tested resource sub-data satisfy the non-conflict condition. And when URI4 is not equal to the URI of the upper-layer certificate of URI 1, then the second to-be-tested resource sub-data and the first to-be-tested resource sub-data do not satisfy the non-conflict condition, and the two conflict. Take 192.0.128.0 / 20 as the second sub-conflict detection result of the first to-be-tested resource sub-data 192.0.128.0 / 24.
[0239] Further, when all the first resource sub-data to be detected in the first set to be detected are detected, all the second sub-conflict detection results corresponding to all the first resource sub-data to be detected are used as the conflict detection results of the resource allocation data to be detected in the conflict detection item between the sub-certificate and the route origin authorization.
[0240] In some embodiments, a conflict table between the sub-certificate and the route origin authorization may be established, and after the detection is completed, information such as the conflicting IP address prefix, the URI of the autonomous system where the conflict occurs, the URI of the sub-certificate corresponding to the conflicting IP address prefix, and the conflicting autonomous system number is saved to the conflict table between the sub-certificate and the route origin authorization.
[0241] By constructing a resource certificate radix tree and performing efficient conflict detection between the sub-certificate and the route origin authorization, the efficiency, comprehensiveness, and accuracy of resource abnormal allocation detection are improved, providing a solid technical guarantee for the reasonable allocation and use of network resources.
[0242] In some embodiments, in order to comprehensively, quickly, and accurately determine the final conflict detection result, non-conflict conditions can be defined and applied to exclude non-conflicting data, so as to accurately determine the conflict detection result of the resource allocation data to be detected finally under this conflict detection item. For example, when the conflict detection item is the conflict detection item between route origin authorizations, the target lookup table matched by the conflict detection item between route origin authorizations is a route origin authorization radix tree generated based on the route origin authorization table. At this time, the step of "excluding the first resource sub-data to be detected and the corresponding second resource sub-data to be detected that meet the non-conflict conditions, and determining the remaining target resource sub-data to be detected after the exclusion as the conflict detection result corresponding to the conflict detection item" in step 104 may further include:
[0243] (104.f1) For each first resource sub-data to be detected in the first set to be detected, match the unified resource identifiers of at least one second resource sub-data in the second set to be detected with the corresponding data association relationship of the first resource sub-data to be detected, and obtain a sixth matching result; wherein, the first resource sub-data to be detected is the third authorized IP address prefix corresponding to the autonomous system, and the second resource sub-data to be detected is the fourth authorized IP address prefix that has an inclusion relationship with the third authorized IP address prefix in the route origin authorization radix tree;
[0244] (104.f2) When the sixth matching result indicates that the unified resource identifier of the target sixth resource sub-data is equal to the unified resource identifier of the first resource sub-data to be detected, determine that the first resource sub-data to be detected and the target sixth resource sub-data meet the non-conflict conditions;
[0245] (104.f3) Exclude the target sixth resource sub-data that meets the non-conflict conditions with the first resource sub-data to be detected;
[0246] (104.f4) Obtain the first autonomous system number of the second to-be-tested resource sub-data that remains after exclusion and has a data association relationship with the first to-be-tested resource sub-data, and the second autonomous system number of the first to-be-tested resource sub-data;
[0247] (104.f5) When one of the first autonomous system number and the second autonomous system number is zero, determine the authorized Internet protocol address prefixes corresponding to the first autonomous system number and the second autonomous system number respectively as the target to-be-tested resource sub-data;
[0248] (104.f6) Take the target to-be-tested resource sub-data as the third sub-conflict detection result of the first to-be-tested resource sub-data, and for the multiple third sub-conflict detection results corresponding to the multiple first to-be-tested resource sub-data in the first to-be-detected set, determine the conflict detection result of the to-be-tested resource allocation data in the routing origin authorization conflict detection item.
[0249] Among them, the routing origin authorization radix tree can be a radix tree data structure based on classless inter-domain routing, which is used to efficiently store and query the autonomous system number information, Internet protocol address prefixes and their related information in the routing origin authorization table.
[0250] Among them, the sixth matching result can be the result obtained by performing a uniform resource identifier (URI) match between the first to-be-tested resource sub-data (i.e., the third authorized Internet protocol address prefix corresponding to the autonomous system) and at least one second to-be-tested resource sub-data in the second to-be-detected set (i.e., the fourth authorized Internet protocol address prefix that has an inclusion relationship with the third authorized Internet protocol address prefix in the routing origin authorization radix tree) in the routing origin authorization conflict detection item.
[0251] Among them, the third authorized Internet protocol address prefix can be the Internet protocol address prefix specified in the routing origin authorization file (ROA) of each autonomous system (AS) in the routing origin authorization table and legally announced by the autonomous system. The third authorized Internet protocol address prefix is the IP address range authorized for use by the autonomous system.
[0252] Among them, the fourth authorized Internet protocol address prefix can refer to the Internet protocol address prefix that exists in the routing origin authorization radix tree and is defined in the routing origin authorization.
[0253] Among them, the target sixth to-be-tested resource sub-data can be the second to-be-tested resource sub-data that meets the non-conflict condition in the sixth matching result. Specifically, if the uniform resource identifier (URI) of the second to-be-tested resource sub-data is equal to the uniform resource identifier (URI) of the first to-be-tested resource sub-data, then the second to-be-tested resource sub-data is considered as the target sixth to-be-tested resource sub-data.
[0254] Among them, the non - conflict condition can be that in the conflict detection item of the routing origin authorization, when the Uniform Resource Identifier (URI) of the second resource sub - data to be measured is equal to the Uniform Resource Identifier (URI) of the first resource sub - data to be measured, it indicates that there is no conflict between the two.
[0255] Among them, the first autonomous system number can be the number of the autonomous system associated in the second resource sub - data to be measured, which is defined in the routing origin authorization table and represents the autonomous system that owns the fourth authorized Internet Protocol address prefix.
[0256] Among them, the second autonomous system number can be the number of the autonomous system associated in the first resource sub - data to be measured, representing the autonomous system that owns the third authorized Internet Protocol address prefix.
[0257] Among them, the third sub - conflict detection result can be the remaining second resource sub - data to be measured after excluding all target sixth resource sub - data to be measured that meet the non - conflict condition.
[0258] In some embodiments, the construction process of the routing origin authorization radix tree is introduced. Exemplarily, first, an empty routing origin authorization radix tree can be created, and all valid routing origin authorization records are queried from the resource allocation data to be measured. Information such as the Internet Protocol address prefix, URI, AIA, and autonomous system number (ASN) of each routing origin authorization record is obtained.
[0259] Furthermore, it can be checked whether the current Internet Protocol address prefix already exists in the routing origin authorization radix tree. If not, a new Internet Protocol address prefix node is inserted, and an empty object list is created for this node. Information such as the URI, AIA, and autonomous system number associated with the Internet Protocol address prefix is added to the object list. If it exists, the new URI, AIA, and autonomous system number and other information are updated to the object list of the existing Internet Protocol address prefix node. The next routing origin authorization is continued to be processed until all records are processed, and the routing origin authorization radix tree is obtained. By constructing the routing origin authorization radix tree, it not only helps to achieve a comprehensive detection of the resource allocation data to be measured, but also can improve the efficiency and accuracy of the detection.
[0260] Specifically, the conflict between the routing origin authorization (AS = 0) and the routing origin authorization (AS ≠ 0) refers to the problem of duplicate authorization and overlapping authorization of IP prefix resources between the routing origin authorization (AS = 0) and the routing origin authorization (AS ≠ 0). Exemplarily, in the duplicate authorization between the routing origin authorization (AS = 0) and the routing origin authorization (AS ≠ 0), CA1 authorizes the Internet protocol address prefix 192.0.2.128 / 26 to both AS65001 for use and AS0 as a reserved resource. This process belongs to the problem of duplicate authorization of Internet protocol address prefixes between the routing origin authorization (AS = 0) and the routing origin authorization (AS ≠ 0); CA1 authorizes the Internet protocol address prefix 192.0.2.128 / 26 to both AS65001 for use and authorizes the prefix 192.0.131 / 26 that overlaps with this prefix to AS0 as a reserved resource. This process belongs to the problem of overlapping authorization of Internet protocol address prefixes between the routing origin authorization (AS = 0) and the routing origin authorization (AS ≠ 0). By detecting the conflicts between routing origin authorizations, the reasonable allocation and use of network resources can be ensured.
[0261] Please refer to Figure 8 , and the following will introduce the detection process of the conflict detection items between routing origin authorizations in combination with Figure 8 . Exemplarily, based on all valid records of the routing origin authorization table corresponding to the resource allocation data to be tested, the third authorized Internet protocol address prefix (the first sub-data of the resource to be tested) and the corresponding first set to be detected can be determined. Further, information such as the URI, AIA, and autonomous system number of each first sub-data of the resource to be tested can be obtained.
[0262] Further, based on the first sub-data of the resource to be tested, traversal can be performed in the routing origin authorization radix tree to determine the second sub-data of the resource to be tested that has a data association relationship with it, that is, the fourth authorized Internet protocol address prefix that has an inclusion relationship with the first sub-data of the resource to be tested in the routing origin authorization radix tree, and the second set to be detected can be determined based on the multiple second sub-data of the resource to be tested corresponding to the multiple first sub-data of the resource to be tested. Further, information such as the URI, AIA, and autonomous system number of each second sub-data of the resource to be tested in the second set to be detected can be obtained to facilitate subsequent conflict detection.
[0263] Further, the URIs of the first resource sub-data to be measured and the second resource sub-data to be measured that has a data association relationship with the first resource sub-data to be measured can be obtained, and the URIs of the two are matched to obtain a sixth matching result. For example, the URI corresponding to the first resource sub-data to be measured 192.0.2.0 / 24 is URI 1, and the URI corresponding to the second resource sub-data to be measured 192.0.2.0 / 24 is URI2, and URI 1 = URI2. Therefore, when the URIs of the two are equal, it indicates that the certificate corresponding to the second resource sub-data to be measured is the certificate corresponding to the first resource sub-data to be measured, and the two satisfy the non-conflict condition.
[0264] Further, the URI corresponding to the first resource sub-data to be measured 192.0.2.0 / 24 is URI 1, and the URI corresponding to the second resource sub-data to be measured 192.0.2.0 / 22 is URI3. URI 1 and URI3 are not equal, and the two do not satisfy the non-conflict condition. At this time, it is necessary to further determine whether the autonomous system number 1 (ASN1) corresponding to the first resource sub-data to be measured and the autonomous system number 2 (ASN2) corresponding to the second resource sub-data to be measured both contain the situations of ASN = 0 and ASN ≠ 0. If so, it indicates that there is a conflict between routing authorizations.
[0265] Further, when all the second resource sub-data to be measured corresponding to the first resource sub-data to be measured are detected, the second resource sub-data to be measured that conflicts with the first resource sub-data to be measured can be used as the third sub-conflict detection result of the first resource sub-data to be measured. After all the first resource sub-data to be measured in the first set to be detected are detected, all the third sub-conflict detection results corresponding to all the first resource sub-data to be measured can be used as the conflict detection result of the resource allocation data to be measured in the routing authorization conflict detection item.
[0266] Exemplarily, a routing origin authorization conflict table can be set, and information such as the Internet protocol address prefix, autonomous system number, URI, etc. that cause conflicts can be stored in the routing origin authorization conflict table for subsequent viewing.
[0267] Step 105, based on the multiple conflict detection results corresponding to the multiple conflict detection items, obtain the resource abnormal allocation detection result of the resource allocation data to be measured.
[0268] In some embodiments, in order to comprehensively and systematically identify and solve various potential problems in network resource allocation, the multiple sub-graph detection results of the multiple conflict detection items for detecting the resource allocation data to be measured can be summarized to obtain the resource abnormal allocation detection result of the resource allocation data to be measured, so as to ensure the consistency, legality and security of resource allocation.
[0269] Among them, the detection result of abnormal resource allocation can be the overall detection result of the resource allocation data to be measured obtained by summarizing multiple conflict detection items (such as illegal allocation detection items, illegal authorization detection items, conflict detection items between sub-certificates, conflict detection items between sub-certificates and route origin authorization, conflict detection items between route origin authorizations, etc.).
[0270] Furthermore, a detection report can be generated based on the detection result of abnormal resource allocation and notified to relevant network operators or administrators in the form of sending emails. In addition, local policies can be generated for the data related to route origin authorization threatened by conflicts and uploaded to the dependent party to facilitate emergency defense work.
[0271] Furthermore, the generated detection report can be an RPKI conflict detection report. Since currently major operators and Internet service providers select different RPKI abnormal conflict detection algorithms on the dependent party side according to actual needs, it is difficult to form a unified standard for the abnormal conflict detection model and algorithm, resulting in a decline in the quality of RPKI detection data. Therefore, this application specifies a unified output standard for the detection result of abnormal resource allocation to facilitate the adaptation and popularization of the output results of RPKI abnormal data detection tools of each manufacturer, and further promote the improvement of RPKI data quality. Specifically, this application designs a general RPKI conflict detection file format (RPKI Conflict Detection Report, RCR). The RCR file is described using a JSON file, and the JSON format follows IETF RFC 8259.
[0272] For the RCR file sample, as Figure 9 shown. The specific meanings of the stored data involved in Figure 9 will be explained below.
[0273] rcrVersion represents the RCR file version number.
[0274] publisher represents the publisher of the RCR file.
[0275] conflictList corresponds to a list structure for storing the RPKI conflicts detected by the detection tool, and each element in the list represents a conflict record.
[0276] conflictType represents the conflict type.
[0277] The defined range of the conflict type: 0x01 - 0xff.
[0278] At present, five types of RPKI conflicts have been defined for the improved RPKI anomaly conflict detection model proposed for the present invention, supporting the extension of subsequent conflict types.
[0279] 0x01: Illegal assignment.
[0280] 0x02: Illegal authorization.
[0281] 0x03: Conflict between sub-certificates.
[0282] 0x04: Conflict between sub-certificate and ROA.
[0283] 0x05: Conflict between ROA (ASN = 0) and ROA (ASN ≠ 0).
[0284] conf l ictPrefix represents the conflict prefix list.
[0285] conf l ictASNs represents the conflict autonomous system list.
[0286] conf l ictRCLi st represents the list of resource certificates (RCs) involved in the conflict. Each element in the list represents a resource certificate information, where ur i represents the URI of the resource certificate, aia represents the URI that issues the resource certificate, ipResources represents the IP prefix resource corresponding to the resource certificate, asResources represents the autonomous system resource corresponding to the resource certificate, notBefore represents the effective time of the certificate, notAfter represents the expiration time of the certificate, and comment represents the description field, including information such as the CA operating agency.
[0287] conf l ictROALi st represents the list of ROAs involved in the conflict. Each element in the list represents a ROA information, where ur i represents the URI of the ROA, aia represents the URI that issues the ROA, ipResources represents the IP prefix resource corresponding to the ROA, asResources represents the autonomous system resource corresponding to the ROA, asn represents the autonomous system number of the ROA, notBefore represents the effective time of the ROA, notAfter represents the expiration time of the ROA, and comment represents the description field, including information such as the ROA operating agency.
[0288] d i scoveryTime represents the discovery time of the conflict.
[0289] affectedRCLi st represents the list of resource certificates that may be affected by the conflict. Each element in the list represents an affected resource certificate information, and its format definition is the same as that of the elements in conf l ictRCLi st.
[0290] The affectedROA list represents a list of ROAs that may be affected by conflicts. Each element in the list represents the information of an ROA file affected by the conflict, and its format definition is the same as that of the elements in the conflictROA list.
[0291] In the embodiment of the present application, by obtaining the resource allocation data to be measured, and determining the resource certificate table and the route origin authorization table corresponding to the resource allocation data to be measured; determining a plurality of conflict detection items for detecting the resource allocation data to be measured, and respectively matching a target lookup table for each conflict detection item according to the resource certificate table and the route origin authorization table; based on the data association relationship corresponding to the conflict detection item, determining a first set of data to be detected corresponding to the conflict detection item from the target lookup table, and a second set of data to be detected having a data association relationship with at least one first sub-data of the resource to be measured in the first set of data to be detected; determining the non-conflict condition between each first sub-data of the resource to be measured in the first set of data to be detected and the second sub-data of the resource to be measured in the second set of data to be detected, excluding the first sub-data of the resource to be measured that meets the non-conflict condition and the corresponding second sub-data of the resource to be measured, and determining the remaining target sub-data of the resource to be measured after the exclusion as the conflict detection result corresponding to the conflict detection item; based on the plurality of conflict detection results corresponding to the plurality of conflict detection items, obtaining the resource abnormal allocation detection result of the resource allocation data to be measured. In this way, it is possible to perform corresponding detection on the resource allocation data to be measured in different conflict detection items, which can not only detect across distribution points, eliminate potential missed detections of resource conflicts, but also improve the detection accuracy through precise matching and condition exclusion, thus significantly improving the comprehensiveness and accuracy of the resource abnormal allocation detection.
[0292] Please refer to Figure 10 , the embodiment of the present application further provides a resource abnormal allocation detection device, which can implement the above resource abnormal allocation detection method. The resource abnormal allocation detection device includes:
[0293] The first acquisition module 101 is used to acquire the resource allocation data to be measured, and determine the resource certificate table and the route origin authorization table corresponding to the resource allocation data to be measured;
[0294] The matching module 102 is used to determine a plurality of conflict detection items for detecting the resource allocation data to be measured, and respectively match a target lookup table for each conflict detection item according to the resource certificate table and the route origin authorization table;
[0295] The determination module 103 is used to determine, based on the data association relationship corresponding to the conflict detection item, a first set of data to be detected corresponding to the conflict detection item from the target lookup table, and a second set of data to be detected having a data association relationship with at least one first sub-data of the resource to be measured in the first set of data to be detected;
[0296] An exclusion module 104 is configured to determine a non - conflict condition between each first resource sub - data to be detected in the first set to be detected and the second resource sub - data to be detected in the second set to be detected, exclude the first resource sub - data to be detected and the corresponding second resource sub - data that meet the non - conflict condition, and determine the remaining target resource sub - data to be detected after exclusion as the conflict detection result of the corresponding conflict detection item;
[0297] A second acquisition module 105 is configured to obtain a resource abnormal allocation detection result of the resource allocation data to be detected based on the multiple conflict detection results corresponding to the multiple conflict detection items.
[0298] The specific implementation manner of this resource abnormal allocation detection device is basically the same as the specific embodiments of the above - mentioned resource abnormal allocation detection method, and will not be elaborated here. On the premise of meeting the requirements of the embodiments of the present application, other functional modules can be set in the resource abnormal allocation detection device to implement the resource abnormal allocation detection method in the above - mentioned embodiments.
[0299] Embodiments of the present application also provide a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the above - mentioned resource abnormal allocation detection method. This computer device can be any intelligent terminal including a tablet computer, an in - vehicle computer, etc.
[0300] Please refer to Figure 11 , Figure 11 , which schematically shows the hardware structure of a computer device in another embodiment. The computer device includes:
[0301] A processor 111, which can be implemented in ways such as a general - purpose CPU (Central Processing Unit), a microprocessor, an application - specific integrated circuit (ASIC), or one or more integrated circuits, and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;
[0302] A memory 112, which can be implemented in forms such as a read - only memory (ROM), a static storage device, a dynamic storage device, or a random - access memory (RAM). The memory 112 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 112, and the processor 111 is called to execute the resource abnormal allocation detection method of the embodiments of the present application;
[0303] An input / output interface 113 for implementing information input and output;
[0304] A communication interface 114 for implementing communication interaction between this device and other devices, which can achieve communication through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WI FI, Bluetooth, etc.);
[0305] A bus 115 for transmitting information between various components of the device (such as the processor 111, the memory 112, the input / output interface 113, and the communication interface 114);
[0306] Among them, the processor 111, the memory 112, the input / output interface 113, and the communication interface 114 achieve communication connections with each other inside the device through the bus 115.
[0307] The embodiment of the present application also provides a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned resource abnormal allocation detection method.
[0308] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0309] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art can know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are also applicable to similar technical problems.
[0310] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.
[0311] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0312] Those of ordinary skill in the art will understand that all or some of the steps in the methods disclosed above, and the functional modules / units in systems and devices, can be implemented as software, firmware, hardware, or a suitable combination thereof.
[0313] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances, so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.
[0314] It should be understood that in this application, "at least one (item)" and "several" mean one or more, and "multiple" means two or more. "And / or" is used to describe the association relationship of associated objects and indicates that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally means that the associated objects before and after are in an "or" relationship. "At least one (item) of the following" or a similar expression means any combination of these items, including any combination of single items (items) or plural items (items). For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.
[0315] In the several embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are only illustrative. For example, the above-mentioned unit division is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in an electrical, mechanical, or other form.
[0316] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0317] In addition, each functional unit in various embodiments of the present application may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0318] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0319] The preferred embodiments of the embodiments of the present application have been described above with reference to the accompanying drawings, but this does not limit the scope of the rights of the embodiments of the present application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of the present application shall be within the scope of the rights of the embodiments of the present application.
Claims
1. A method for detecting abnormal resource allocation, characterized in that: The method comprises: Acquire resource allocation data to be tested, and determine a resource certificate table and a routing origin authorization table corresponding to the resource allocation data to be tested; Determine a plurality of conflict detection items for detecting the resource allocation data to be tested, and match a target lookup table for each conflict detection item according to the resource certificate table and the routing origin authorization table; Based on the data association relationship corresponding to the conflict detection item, determine from the target lookup table a first set to be detected corresponding to the conflict detection item, and a second set to be detected having the data association relationship with at least one first resource sub-data to be detected in the first set to be detected; Determine a non-conflict condition between each first resource sub-data to be tested in the first set to be tested and the second resource sub-data to be tested in the second set to be tested, exclude the first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition, and determine the remaining target resource sub-data to be tested after exclusion as the conflict detection result of the corresponding conflict detection item; Based on the multiple conflict detection results corresponding to the multiple conflict detection items, a resource abnormal allocation detection result of the resource allocation data to be tested is obtained.
2. The resource abnormal allocation detection method according to claim 1, characterized in that: The determining of a plurality of conflict detection items for detecting the resource allocation data to be tested includes: For a conflict detection scenario in which the resource allocation data to be tested is detected between upper and lower levels of a certificate chain, determining an illegal allocation conflict detection item and an illegal authorization conflict detection item as conflict detection items; For the conflict detection scenario of detecting the resource allocation data to be tested between certificate chains, conflict detection items between sub-certificates, conflict detection items between sub-certificates and routing origin authorizations, and conflict detection items between routing origin authorizations are determined as conflict detection items.
3. The resource abnormal allocation detection method according to claim 2, characterized in that: The conflict detection item is an illegal allocation conflict detection item; the target lookup table matched by the illegal allocation conflict detection item is a resource certificate table; The step of excluding the first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition, and determining the remaining target resource sub-data to be tested after the exclusion as the conflict detection result of the corresponding conflict detection item includes: For each first resource sub-data to be tested in the first set to be tested, the first resource sub-data to be tested is matched with at least one second resource sub-data to be tested in the corresponding data association relationship in the second set to be tested by an Internet Protocol address prefix to obtain a first matching result; wherein the first resource sub-data to be tested is the Internet Protocol address prefix corresponding to the child certificate, and the second resource sub-data to be tested is the Internet Protocol address prefix of the parent certificate corresponding to the child certificate; When the first matching result indicates that the target first resource sub-data to be tested having an association relationship with the first resource sub-data to be tested and the corresponding data meets the inclusion relationship, it is determined that the first resource sub-data to be tested and the target first resource sub-data to be tested meet the non-conflict condition; In the first to-be-tested set, the first to-be-tested resource sub-data and the target first to-be-tested resource sub-data that meet the non-conflict condition are excluded, and the target to-be-tested resource sub-data are determined according to the remaining first to-be-tested resource sub-data after the exclusion and the second to-be-tested resource sub-data having a data association relationship with the remaining first to-be-tested resource sub-data; The target resource sub-data to be tested is determined as a conflict detection result of the resource allocation data to be tested for an illegal allocation conflict detection item of an Internet Protocol address prefix.
4. The resource abnormal allocation detection method according to claim 2, characterized in that: The conflict detection item is an illegal allocation conflict detection item; the target lookup table matched by the illegal allocation conflict detection item is a resource certificate table; The first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition are excluded, and the remaining target resource sub-data to be tested is determined as the conflict detection result of the corresponding conflict detection item after the exclusion, and further includes: For each first resource sub-data to be tested in the first set to be tested, the first resource sub-data to be tested is matched with at least one second resource sub-data to be tested in the corresponding data association relationship in the second set to be tested in terms of the autonomous system number to obtain a second matching result; wherein the first resource sub-data to be tested is the autonomous system number corresponding to the sub-certificate, and the second resource sub-data to be tested is the autonomous system number of the parent certificate corresponding to the sub-certificate; When the second matching result indicates that the target second resource sub-data to be tested that has an association relationship between the first resource sub-data to be tested and the corresponding data meets the inclusion relationship, it is determined that the first resource sub-data to be tested and the target second resource sub-data to be tested meet the non-conflict condition; In the first to-be-tested set, the first to-be-tested resource sub-data and the target second to-be-tested resource sub-data that meet the non-conflict condition are excluded, and the target to-be-tested resource sub-data are determined according to the remaining first to-be-tested resource sub-data after the exclusion and the second to-be-tested resource sub-data having a data association relationship with the remaining first to-be-tested resource sub-data; The target resource sub-data to be tested is determined as a conflict detection result of the resource allocation data to be tested for an illegal allocation conflict detection item of an autonomous system number.
5. The resource abnormal allocation detection method according to claim 2, characterized in that: The conflict detection item is an illegal authorization conflict detection item; the target lookup table matched by the illegal authorization conflict detection item is a resource certificate table and a routing origin authorization table; The first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition are excluded, and the remaining target resource sub-data to be tested is determined as the conflict detection result of the corresponding conflict detection item after the exclusion, and further includes: For each first resource sub-data to be tested in the first set to be tested, the first resource sub-data to be tested is matched with at least one second resource sub-data to be tested in the corresponding data association relationship in the second set to be tested in terms of the Internet Protocol address prefix to obtain a third matching result; wherein the first resource sub-data to be tested is the first authorized Internet Protocol address prefix corresponding to the autonomous system, and the second resource sub-data to be tested is the Internet Protocol address prefix of the parent certificate corresponding to the autonomous system; When the third matching result indicates that the target third resource sub-data to be tested that has an association relationship between the first resource sub-data to be tested and the corresponding data meets the inclusion relationship, it is determined that the first resource sub-data to be tested and the target third resource sub-data to be tested meet the non-conflict condition; In the first to-be-tested set, the first to-be-tested resource sub-data and the target third to-be-tested resource sub-data that meet the non-conflict condition are excluded, and the target to-be-tested resource sub-data are determined as the target to-be-tested resource sub-data according to the remaining first to-be-tested resource sub-data after the exclusion and the second to-be-tested resource sub-data having a data association relationship with the remaining first to-be-tested resource sub-data; The target resource sub-data to be tested is determined as the conflict detection result of the resource allocation data to be tested in the illegal authorization conflict detection item.
6. The resource abnormal allocation detection method according to claim 2, characterized in that: The conflict detection item is a conflict detection item between sub-certificates; the target lookup table for matching the conflict detection item between sub-certificates is a resource certificate cardinality tree generated based on the resource certificate table; The first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition are excluded, and the remaining target resource sub-data to be tested is determined as the conflict detection result of the corresponding conflict detection item after the exclusion, and further includes: For each first resource sub-data to be tested in the first set to be tested, the first resource sub-data to be tested is matched with at least one second resource sub-data to be tested in the corresponding data association relationship in the second set to be tested by a uniform resource identifier to obtain a fourth matching result; wherein the first resource sub-data to be tested is a first Internet Protocol address prefix corresponding to the first sub-certificate, and the second resource sub-data to be tested is a second Internet Protocol address prefix that has an inclusion relationship with the first Internet Protocol address prefix of the first sub-certificate in the resource certificate radix tree; When the fourth matching result indicates that the uniform resource identifier of the target fourth resource sub-data to be tested is equal to the uniform resource identifier of the first resource sub-data to be tested, it is determined that the first resource sub-data to be tested and the target fourth resource sub-data to be tested meet the non-conflict condition; or, when the fourth matching result indicates that the uniform resource identifier of the target fourth resource sub-data to be tested is equal to the uniform resource identifier of the upper-layer certificate of the first resource sub-data to be tested, it is determined that the first resource sub-data to be tested and the target fourth resource sub-data to be tested meet the non-conflict condition; Excluding the target fourth resource sub-data to be tested that meets the non-conflicting condition with the first resource sub-data to be tested, and determining the remaining second resource sub-data to be tested that has a data association relationship with the first resource sub-data to be tested as the target resource sub-data to be tested after the exclusion; The target resource sub-data to be tested is used as the first sub-conflict detection result of the first resource sub-data to be tested, and the conflict detection result of the conflict detection item between the sub-certificates of the resource allocation data to be tested is determined according to the multiple first sub-conflict detection results corresponding to the multiple first resource sub-data to be tested in the first set to be detected.
7. The resource abnormal allocation detection method according to claim 2, characterized in that: The conflict detection item is a sub-certificate and routing origin authorization conflict detection item; the target lookup table matching the sub-certificate and routing origin authorization conflict detection item is a resource certificate cardinality tree generated based on the resource certificate table; The first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition are excluded, and the remaining target resource sub-data to be tested is determined as the conflict detection result of the corresponding conflict detection item after the exclusion, and further includes: For each first resource sub-data to be tested in the first set to be tested, the first resource sub-data to be tested is matched with at least one second resource sub-data to be tested in the corresponding data association relationship in the second set to be tested by a uniform resource identifier to obtain a fifth matching result; wherein the first resource sub-data to be tested is a second authorized Internet Protocol address prefix corresponding to the autonomous system, and the second resource sub-data to be tested is a third Internet Protocol address prefix in the resource certificate radix tree that has an inclusion relationship with the second authorized Internet Protocol address prefix; When the fifth matching result indicates that there is a uniform resource identifier of the target fifth resource sub-data to be tested that is equal to the uniform resource identifier of the upper layer certificate of the first resource sub-data to be tested, determining that the first resource sub-data to be tested and the target fifth resource sub-data to be tested meet a non-conflict condition; Excluding the target fifth resource sub-data to be tested that meets the non-conflicting condition with the first resource sub-data to be tested, and determining the remaining second resource sub-data to be tested that has a data association relationship with the first resource sub-data to be tested as the target resource sub-data to be tested after the exclusion; The target resource sub-data to be tested is used as the second sub-conflict detection result of the first resource sub-data to be tested, and based on the multiple second sub-conflict detection results corresponding to the multiple first resource sub-data to be tested in the first set to be detected, the conflict detection result of the resource allocation data to be tested in the sub-certificate and routing origin authorization conflict detection item is determined.
8. The resource abnormal allocation detection method according to claim 2, characterized in that: The conflict detection item is a conflict detection item between routing origin authorizations; the target lookup table matched by the conflict detection item between routing origin authorizations is a routing origin authorization radix tree generated based on the routing origin authorization table; The first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition are excluded, and the remaining target resource sub-data to be tested is determined as the conflict detection result of the corresponding conflict detection item after the exclusion, and further includes: For each first resource sub-data to be tested in the first set to be tested, the first resource sub-data to be tested is matched with at least one second resource sub-data to be tested in the corresponding data association relationship in the second set to be tested by a uniform resource identifier to obtain a sixth matching result; wherein the first resource sub-data to be tested is a third authorized Internet Protocol address prefix corresponding to the autonomous system, and the second resource sub-data to be tested is a fourth authorized Internet Protocol address prefix in the routing origin authorization radix tree that has an inclusion relationship with the third authorized Internet Protocol address prefix; When the sixth matching result indicates that there is a uniform resource identifier of a target sixth resource sub-data to be tested that is equal to the uniform resource identifier of the first resource sub-data to be tested, determining that the first resource sub-data to be tested and the target sixth resource sub-data to be tested meet a non-conflict condition; Excluding the target sixth resource sub-data to be tested that meets the non-conflict condition with the first resource sub-data to be tested; Acquire the first autonomous system number of the second resource sub-data to be tested that is data-associated with the first resource sub-data to be tested and the second autonomous system number of the first resource sub-data to be tested; When one of the first autonomous system number and the second autonomous system number is zero, determining the authorized Internet Protocol address prefixes corresponding to the first autonomous system number and the second autonomous system number respectively as the target resource sub-data to be tested; The target resource sub-data to be tested is used as the third sub-conflict detection result of the first resource sub-data to be tested, and based on the multiple third sub-conflict detection results corresponding to the multiple first resource sub-data to be tested in the first set to be detected, the conflict detection result of the conflict detection item of the resource allocation data to be tested between the routing origin authorizations is determined.
9. A resource abnormal allocation detection device, characterized in that: The device comprises: A first acquisition module is used to acquire the resource allocation data to be tested, and determine the resource certificate table and the routing origin authorization table corresponding to the resource allocation data to be tested; A matching module, used to determine a plurality of conflict detection items for detecting the resource allocation data to be tested, and to match a target lookup table for each conflict detection item according to the resource certificate table and the routing origin authorization table; A determination module, configured to determine, from the target lookup table, a first set to be detected corresponding to the conflict detection item and a second set to be detected having the data association relationship with at least one first resource sub-data to be detected in the first set to be detected, based on the data association relationship corresponding to the conflict detection item; An exclusion module is used to determine a non-conflict condition between each first resource sub-data to be tested in the first set to be detected and the second resource sub-data to be tested in the second set to be detected, exclude the first resource sub-data to be tested and the corresponding second resource sub-data to be tested that meet the non-conflict condition, and determine the remaining target resource sub-data to be tested after exclusion as the conflict detection result of the corresponding conflict detection item; The second acquisition module is used to obtain the resource abnormal allocation detection result of the resource allocation data to be tested based on the multiple conflict detection results corresponding to the multiple conflict detection items.
10. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and the processor implements the resource abnormal allocation detection method according to any one of claims 1 to 8 when executing the computer program.
11. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the method for detecting abnormal resource allocation according to any one of claims 1 to 8 is implemented.
Citation Information
Patent Citations
Certificate transaction alarm method of resource public key infrastructure based on block chain
CN111031010A
Medical text conflict detection method, electronic equipment and storage medium
CN116050381A