A network attack processing method, apparatus, device, medium and product

By acquiring and filtering the target load balancer source address field, combined with a multi-device whitelist, the problem of inaccurate attack source addresses in complex network environments is solved, enabling accurate location of attack sources and protection of normal traffic.

CN119276615BActive Publication Date: 2025-12-12AGRICULTURAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411657997.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-19
Publication Date
2025-12-12
Estimated Expiration
2044-11-19

AI Technical Summary

Technical Problem

In complex data center networks, existing technologies cannot accurately determine the true source address of network attacks, resulting in disruption to normal traffic.

Method used

By obtaining the target load balancer source address field and combining it with the whitelists of application load devices, intrusion prevention system devices, and security operation devices, the attack source address is filtered out to ensure accuracy.

Benefits of technology

In complex network environments, it can more accurately identify the source address of attacks, avoid mistakenly blocking normal traffic, and protect the security of the existing network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276615B_ABST
    Figure CN119276615B_ABST
Patent Text Reader

Abstract

A network attack processing method, device, equipment, medium and product are disclosed. The method comprises: when a network attack event sent by an intrusion prevention system device is received, a target load balancing source address field is obtained, wherein the target load balancing source address field is stored in a device corresponding to the network attack event; an initial address set corresponding to the target load balancing source address field is determined; the initial address set is filtered based on a target whitelist to obtain an attack source address, wherein the target whitelist comprises: an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in a security operation device, the whitelist stored in the intrusion prevention system device comprises: a translation address, and the whitelist stored in the security operation device comprises: an application system address running in the server and a content distribution network address.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] Embodiments of the present application relate to the technical field of computer, and particularly relate to a network attack processing method, device, equipment, medium and product. BACKGROUND

[0002] In the deployment scene of industry data center security solution, the intrusion prevention system device discovers attacks and traces evidence to report to the enterprise management platform, so that the user can further determine the security risk of the whole network and take necessary measures.

[0003] In the prior art, the strategy for collecting network attacks is: the intrusion prevention system device generates a security event (the security event includes: source address, destination address, protocol, protocol, port, attack type, attack name, level, URL, domain name and the like), transmits the security event to the management device through a specific format, and the enterprise network security personnel performs secondary security analysis and takes measures, and generates evaluation data.

[0004] However, in a complex data center networking, various network devices are often deployed in front of the intrusion prevention system device, thereby causing the source address not to be the real attack source address, and if the user blocks the above source address, the normal traffic will be affected. SUMMARY

[0005] Embodiments of the present application provide a network attack processing method, device, equipment, medium and product, which can more accurately determine the attack source address and ensure that the normal traffic of the existing network is not affected.

[0006] According to an aspect of the present application, a network attack processing method is provided, which is applied to a target system, the target system includes: a content distribution network, an application load device, an intrusion prevention system device, a server and a security operation device, the network attack processing method is executed by the security operation device, and the network attack processing method includes:

[0007] When receiving a network attack event sent by the intrusion prevention system device, a target load balancing source address field is acquired, wherein the target load balancing source address field is stored in a device corresponding to the network attack event;

[0008] An initial address set corresponding to the target load balancing source address field is determined;

[0009] The screening module is configured to screen the initial address set based on a target whitelist to obtain an attack source address, wherein the target whitelist comprises an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in the security operation device, the whitelist stored in the intrusion prevention system device comprises a translated address, and the whitelist stored in the security operation device comprises an application system address running in the server and the content distribution network address.

[0010] According to another aspect of the present application, a network attack processing apparatus is provided, which is configured in a security operation device in a target system, the target system comprising a content distribution network, an application load device, an intrusion prevention system device, a server, and the security operation device, the network attack processing apparatus comprising:

[0011] The obtaining module is configured to obtain a target load balancing source address field when a network attack event sent by the intrusion prevention system device is received, wherein the target load balancing source address field is stored in a device corresponding to the network attack event;

[0012] The determining module is configured to determine an initial address set corresponding to the target load balancing source address field;

[0013] The screening module is configured to screen the initial address set based on a target whitelist to obtain an attack source address, wherein the target whitelist comprises an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in the security operation device, the whitelist stored in the intrusion prevention system device comprises a translated address, and the whitelist stored in the security operation device comprises an application system address running in the server and the content distribution network address.

[0014] According to another aspect of the present application, an electronic device is provided, which comprises:

[0015] at least one processor; and

[0016] a memory connected to the at least one processor in communication; wherein

[0017] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the network attack processing method according to any one of the embodiments of the present application.

[0018] According to another aspect of the present application, a computer readable storage medium is provided, which stores computer instructions for enabling a processor to execute the network attack processing method according to any one of the embodiments of the present application when executed by the processor.

[0019] According to another aspect of the present application, there is provided a computer program product, which, when executed by a processor, implements the network attack processing method according to any of the embodiments of the present application.

[0020] The embodiment of the present application can obtain a target load balancing source address field and determine an initial address set corresponding to the target load balancing source address field when receiving a network attack event sent by the intrusion prevention system device; and filter the initial address set based on a target white list to obtain an attack source address. The attack source address can be determined more accurately in a complex network environment, and normal traffic in the existing network is not affected.

[0021] It should be understood that the content described in this part is not intended to identify key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiments. It should be understood that the following drawings only show some of the embodiments of the present application, and therefore should not be regarded as limiting the scope. For those skilled in the art, other related drawings can also be obtained without creative labor.

[0023] Figure 1 is a flow chart of a network attack processing method in the embodiment of the present application;

[0024] Figure 2 is a network diagram in the embodiment of the present application;

[0025] Figure 3 is a structural schematic diagram of a network attack processing device in the embodiment of the present application;

[0026] Figure 4 is a structural schematic diagram of an electronic device in the embodiment of the present application. DETAILED DESCRIPTION

[0027] In order to make the person skilled in the art better understand the present application, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.

[0028] It is to be understood that the terms "first", "second", and the like used in the description and the claims of the present application as well as the above-described drawings are used to distinguish similar objects, and are not necessarily used to describe a particular sequential or chronological order. It should be understood that the data thus used can be interchanged, where appropriate, so that the embodiments of the application described herein can be carried out in other than the order shown or described herein. Furthermore, the terms "comprise" and "have", and any variations thereof, are intended to cover non-exclusive inclusion, for example, processes, methods, systems, products, or devices that comprise a list of steps or units are not necessarily limited to those steps or units that are clearly listed, but can include other steps or units that are not clearly listed or inherent to such processes, methods, products, or devices.

[0029] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type of personal information involved in the present disclosure, the scope of use, the scene of use, etc. should be informed to the user and the authorization of the user should be obtained according to relevant laws and regulations.

[0030] Embodiment one

[0031] In the prior art, the following scheme is generally used for network attack processing:

[0032] Technical solution one: directly report the source address of the current traffic and the URL and other information in the attack flow for forensic analysis, and the IP disposed may be a CDN proxy IP. The disadvantage of this technology is that it cannot guarantee that it is a real attack source, it is easy to be mistaken, or the CDN IP cannot be blocked in the permanent whitelist.

[0033] Technical solution two: directly block based on the X-Forward-For field (XFF for short) of the current traffic as the attack source. The use of X-Forward-For is a factual standard and is widely used in proxy servers or load balancing services. In some scenarios, necessary information can be extracted through the XFF field in the traffic. The disadvantage of this technology is that in complex scenarios, the authenticity of XFF is not easy to determine. Once the error is reported, the platform side analysis is also disturbed, which will cause IP misblocking and affect normal users to handle Internet business.

[0034] In view of the above problems, the embodiment of the present application provides a network attack processing method. Figure 1 A flowchart of a network attack processing method provided by the embodiment of the present application, the embodiment can be applicable to the case of network attack processing, and the method can be executed by a network attack processing device in the embodiment of the present application. The device can be realized in the form of software and / or hardware, as shown in the figure, and the method specifically includes the following steps: Figure 1

[0035] ​S110, when receiving the network attack event sent by the intrusion prevention system device, obtaining a target load balancing source address field.

[0036] In this embodiment, the target load balancing source address field is stored in the device corresponding to the network attack event.

[0037] In this embodiment, the network attack processing method provided by the embodiment of the application is applied to a target system, and the target system includes a content delivery network, an application load device, an intrusion prevention system device, a server and a security operation device. The network attack processing method is executed by the security operation device. The content delivery network (CDN) is a layer of intelligent virtual network constructed by placing node servers at various places in the network on the basis of the existing Internet. The CDN can redirect the user's request to the service node closest to the user in real time according to the network traffic, the connection of each node, the load condition, the distance to the user and the response time and other comprehensive information. The application load device is used to ensure that the network load is balanced through load balancing technology. Load balancing (LB) technology refers to balancing and distributing the load (work task) to multiple operation units such as web servers, application servers and other main task servers for operation, so as to cooperatively complete the work task. The intrusion prevention system (IPS) can monitor the network data transmission behavior of the network or network device, and can immediately interrupt, adjust or isolate some abnormal or harmful network data transmission behavior. The security operation device (SOC) is used to detect network security events in real time, and solve problems as quickly and effectively as possible.

[0038] In this embodiment, when receiving the network attack event sent by the intrusion prevention system device, the target load balancing source address field can be obtained in the following way: when receiving the network attack event sent by the intrusion prevention system device, the target load balancing source address field corresponding to the grid attack event is obtained. When receiving the network attack event sent by the intrusion prevention system device, the target load balancing source address field can also be obtained in the following way: when receiving the network attack event sent by the intrusion prevention system device, the target session corresponding to the grid attack event is obtained; and the target load balancing source address field is determined according to the load balancing source address field stored in the device corresponding to the target session.

[0039] Optionally, the target load balancing source address field is obtained by:

[0040] The target session corresponding to the grid attack event is obtained.

[0041] In the embodiment, the target session corresponding to the grid attack event can be obtained by querying the log file according to the identification information carried by the grid attack event.

[0042] The target load balancing source address field is determined according to the load balancing source address field stored in the device corresponding to the target session.

[0043] In the embodiment, the target load balancing source address field can be determined by reading in reverse order from the last hop of the target session until the target load balancing source address field is obtained. The target load balancing source address field can also be determined by obtaining the load balancing source address field stored in the application load device corresponding to the target session.

[0044] It should be noted that a real source IP switch can be added. When the switch is on, if the real source IP address (i.e. the target load balancing source address field) cannot be extracted from the last hop of the target session, the real source IP address is read from the last hop of the target session in reverse order until the real source IP address is obtained. When the switch is off, the load balancing source address field stored in the application load device corresponding to the target session is obtained. If there is no real source IP address, the real source IP address is marked as empty. If the real source IP switch is not set, the real source IP switch is off by default.

[0045] Optionally, the target load balancing source address field is determined according to the load balancing source address field stored in the device corresponding to the target session, including:

[0046] The target load balancing source address field is read from the last hop of the target session in reverse order until the target load balancing source address field is obtained.

[0047] In the embodiment, the target load balancing source address field is read from the last hop of the target session. If the target load balancing source address field read by the last hop is empty, the target load balancing source address field is read in reverse order until the target load balancing source address field read is non-empty.

[0048] Optionally, the target load balancing source address field is determined according to the load balancing source address field stored in the device corresponding to the target session, including:

[0049] A reading variant mode is obtained.

[0050] In the embodiment, the read variant mode carries a load balancing source address field identifier. The read variant mode includes an X-Forwarded-For Only mode, a Cdn-Src-IP Only mode, an X-Real-IP Only mode, and a Tcp-Option Only mode. X-Forwarded-For, Cdn-Src-IP, X-Real-IP, and Tcp-Option are different variant forms of the load balancing source address field identifier.

[0051] The load balancing source address field identifier corresponding to the target load balancing source address field stored in the device corresponding to the target session is read.

[0052] In the embodiment, the read variant mode is added, for example, the X-Forwarded-For Only mode, the Cdn-Src-IP Only mode, the X-Real-IP Only mode, and the Tcp-Option Only mode. After the read variant mode is selected, the load balancing source address field is only extracted from the specified field, and other fields are no longer concerned, which simplifies the configuration. The read variant mode and the priority logic are in a parallel relationship, which is equivalent to five mutually exclusive extraction modes. If the read variant mode is not selected, the X-Forwarded-for Only mode is used by default.

[0053] S120, determining an initial address set corresponding to the target load balancing source address field.

[0054] In the embodiment, the manner of determining the initial address set corresponding to the target load balancing source address field can be: obtaining a preset address extraction quantity; extracting addresses in the target load balancing source address field according to the preset address extraction quantity; and generating an initial address set based on the extracted addresses of the preset address extraction quantity.

[0055] It should be noted that the target load balancing source address field can append records, so the function of extracting multiple addresses is added based on the extraction of the last address and the first address. The user can select the last N addresses, or the first N addresses, or all addresses, where N is a positive integer greater than 1.

[0056] In the embodiment, the manner of determining the initial address set corresponding to the target load balancing source address field can also be: obtaining an extraction rule, extracting addresses in the target load balancing source address field according to the extraction rule, and generating an initial address set based on the extracted addresses.

[0057] S130, screening the initial address set based on a target whitelist to obtain an attack source address.

[0058] In the embodiment, the target whitelist includes an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in the security operation device, the whitelist stored in the intrusion prevention system device includes a translation address, and the whitelist stored in the security operation device includes an application system address running in the server and a content distribution network address.

[0059] In the embodiment, the target whitelist is used to filter the initial address set to obtain the attack source address, and the filtering manner can be as follows: the initial address set is first filtered based on the application load device address and the translation address to obtain a filtered initial address set, and then the filtered initial address set is secondly filtered based on the application system address running in the server and the content distribution network address to obtain the attack source address. Optionally, determining the initial address set corresponding to the target load balancing source address field includes:

[0060] obtaining a preset address extraction quantity;

[0061] extracting addresses in the target load balancing source address field according to the preset address extraction quantity;

[0062] generating an initial address set according to the extracted addresses of the preset address extraction quantity.

[0063] In the embodiment, because the target load balancing source address field can be appended, the function of extracting multiple addresses is added on the basis of extracting the last address and the first address. The user can select to extract the last few addresses. For example, the target load balancing source address field can be as follows:

[0064] X-Forwarded-For: 110.100.122.132, 111.111.111.111, 113.113.113.111, 115.115.115.115, 1.1.1.1, 1.1.12.1, 12.12.12.2;

[0065] If the last two addresses are configured to be extracted, 1.1.12.1 and 12.12.12.2 are extracted. It should be noted that the extraction from the front and the extraction from the back are mutually exclusive, and the extraction of one and the extraction of multiple are mutually exclusive. The upper limit of the number of real source IP addresses that can be extracted is temporarily set to 10. If the address extraction quantity is not set, the first address in the target load balancing source address field is extracted by default.

[0066] Optionally, the target system further includes a network security device.

[0067] After the initial address set is filtered based on the whitelist to obtain the attack source address, the method further includes:

[0068] The attack source address is sent to the application load device or the network security device, so that the application load device or the network security device blocks the attack source address.

[0069] In the embodiment, the network security device can be a firewall. The firewall is mainly used to discover and handle security risks and data transmission problems in computer network operation in time. The handling measures include isolation and protection, and the firewall can record and detect each operation in computer network security, so as to ensure the security of computer network operation and the integrity of user data and information.

[0070] In the embodiment, the attack source address is sent to the application load device or the network security device, so that the application load device or the network security device blocks the attack source address. The way of sending the attack source address to the application load device or the network security device to block the attack source address can be that the attack source address is sent to the application load device to block the attack source address, or the attack source address is sent to the network security device to block the attack source address.

[0071] In the embodiment, the address set obtained is comprehensively judged and decided by deep tracing and combination of all network resources. The real attack source has no chance to initiate attack again, and the clean traffic is not affected by the misjudgment, so that the internal network security is effectively protected.

[0072] In a specific example, as shown in Figure 2 , the network security device is a firewall, the application load device is a load balancing device, and the network security device is connected to the application load device. Figure 2For a networking schematic diagram, the networking includes: a client GET1, a client GET2, a client GET3, a proxy device Proxy1, a proxy device Proxy2, an IPS, and a server. The client GET1, the client GET2, and the client GET3 need to access the server at least through the proxy device Proxy1, the proxy device Proxy2, and the IPS device. It should be noted that the proxy device Proxy1 and the proxy device Proxy2 include an internal distribution network, and each client and the first proxy device Proxy1 need to establish connections 1, 2, and 3, respectively. The flow from the Proxy1 to the server for each user is the same, and if a session is created from the Proxy1 to the Proxy2, from the Proxy2 to the IPS, and from the IPS to the server for each user, the pressure on the proxy, the IPS, and the server will be increased. Therefore, only one session 4, 5, and 6 is created from the Proxy1 to the Proxy2, from the Proxy2 to the IPS, and from the IPS to the server, the proxy device Proxy1 integrates and multiplexes the sessions for accessing the same server into one session 4, multiple requests in the same session, and the proxy device Proxy1 fills the source IP of the user into the X-Forwarded-For field. Because the X-Forwarded-for field is appendable, when the session 5 for the request from the Proxy2 to the IPS is sent, the proxy device Proxy2 appends the IP address of the proxy device Proxy1 after the IP address of the user. If an extreme case exists, a large number of X-forwarded-for fields may exist in the request message received by the IPS device for each request, or multiple IP addresses exist in the X-Forwarded-For field, and the last IP address is the IP address of the first proxy device Proxy1 in the above networking. For the requirement of tracing the source, the attack source address is reported to the security operation device. When the last IP address is reported, the extracted IP address is actually the IP address of the proxy device Proxy1. If the IP address is blocked, all the traffic is blocked. Therefore, under the premise of complex networking, the embodiment of the application extracts all the addresses as much as possible, for example, all the addresses in the X-forwarded-for field can be extracted. The security operation device has a complete set of network security events, and has an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in the security operation device. The addresses can be considered as not actively initiating attacks in the internal network, and are used as a target whitelist. The initial address set reported and the target whitelist are compared, and the addresses not in the target whitelist are determined as the attack source address. The security operation device can select to issue the attack source address to the firewall or the application load device for blocking.

[0073] The technical scheme of the embodiment can acquire a target load balancing source address field and determine an initial address set corresponding to the target load balancing source address field when a network attack event sent by the intrusion prevention system device is received, and can screen the initial address set based on a target white list to obtain an attack source address, so that the attack source address can be determined more accurately and normal traffic in the existing network is ensured not to be affected.

[0074] Embodiment Two

[0075] Figure 3 A structural schematic diagram of a network attack processing device provided by the embodiment of the application. The embodiment can be applied to the case of network attack processing. The device can be realized in the form of software and / or hardware, and can be integrated in any device providing network attack processing function, such as a server. Figure 3 As shown in the figure, the network attack processing device specifically comprises an acquisition module 310, a determination module 320 and a screening module 330.

[0076] The acquisition module is configured to acquire a target load balancing source address field when a network attack event sent by the intrusion prevention system device is received, wherein the target load balancing source address field is stored in a device corresponding to the network attack event.

[0077] The determination module is configured to determine an initial address set corresponding to the target load balancing source address field.

[0078] The screening module is configured to screen the initial address set based on a target white list to obtain an attack source address, wherein the target white list comprises an application load device address, a white list stored in the intrusion prevention system device and a white list stored in the security operation device, the white list stored in the intrusion prevention system device comprises a translation address, and the white list stored in the security operation device comprises an application system address running in the server and a content distribution network address.

[0079] The product can execute the method provided by any embodiment of the application, and has the corresponding function modules and beneficial effects of the execution method.

[0080] Embodiment Three

[0081] Figure 4A structural diagram of an electronic device 10 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular telephones, smartphones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not meant to limit implementations of the present application described and / or claimed in this document.

[0082] As shown, Figure 4 The electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., communicatively connected to the at least one processor 11, where the memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0083] Various components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, speakers, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.

[0084] The processor 11 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the network attack processing method.

[0085] In some embodiments, the network attack processing method can be implemented as a computer program tangibly embodied in a computer readable storage medium, e.g., storage unit 18. In some embodiments, parts or all of the computer program can be loaded and / or installed onto electronic device 10 via, e.g., ROM 12 and / or communication unit 19. When the computer program is loaded onto RAM 13 and executed by processor 11, one or more steps of the network attack processing method described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the network attack processing method by other means, e.g., with the aid of firmware.

[0086] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a programmable logic device (PLD), a computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0087] Computer programs used to implement the methods of the present application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the computer program, when executed by the processor of the machine, implements the functions / acts specified in the flowcharts and / or block diagrams. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, partially on a machine and partially on a remote machine or entirely on a remote machine or server.

[0088] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. A computer-readable storage medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of a machine-readable storage medium will include one or more lines of a program of instructions in a transitory signal, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0089] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0090] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0091] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. Servers can be cloud servers, also known as cloud computing servers or cloud hosts, which are a host product in the cloud computing service system to solve the defects of great management difficulty and weak business scalability in traditional physical hosts and VPS services.

[0092] It should be understood that the various forms of flow shown above can be reordered, additional steps added, or steps deleted. For example, the steps described in the present application can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions of the present application can be achieved, which are not limited herein.

[0093] The embodiment of the present application further provides a computer program product, comprising a computer program which, when executed by a processor, implements the network attack processing method according to any one of the embodiments of the present application.

[0094] The computer program product, in the implementation process, can be written in one or more programming languages or combinations thereof to implement computer program codes for performing the operations of the present application, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" language or similar programming languages. The program code can be executed entirely on a user computer, partially on a user computer, as an independent software package, partially on a user computer and partially on a remote computer, or entirely on a remote computer or server. In the case involving a remote computer, the remote computer can be connected to the user computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, through the Internet by using an Internet service provider).

[0095] The above detailed description does not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A network attack processing method characterized by comprising: The network attack processing method is applied to a target system, and the target system includes a content distribution network, an application load device, an intrusion prevention system device, a server, and a security operation device. The network attack processing method is executed by the security operation device, and the network attack processing method includes: When a network attack event sent by the intrusion prevention system device is received, a target load balancing source address field is obtained, wherein the target load balancing source address field is stored in a device corresponding to the network attack event; An initial address set corresponding to the target load balancing source address field is determined; The initial address set is filtered based on a target whitelist to obtain an attack source address, wherein the target whitelist includes an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in the security operation device. The whitelist stored in the intrusion prevention system device includes a translated address, and the whitelist stored in the security operation device includes an application system address running in the server and a content distribution network address; The target load balancing source address field is obtained, including: A target session corresponding to the network attack event is obtained; A target load balancing source address field is determined based on a load balancing source address field stored in a device corresponding to the target session; The initial address set corresponding to the target load balancing source address field is determined, including: A preset address extraction quantity is obtained; An address in the target load balancing source address field is extracted according to the preset address extraction quantity; An initial address set is generated based on the extracted address of the preset address extraction quantity.

2. The method of claim 1, wherein, The target system further includes a network security device; After the initial address set is filtered based on the whitelist to obtain the attack source address, the method further includes: The attack source address is sent to the application load device or the network security device, so that the application load device or the network security device blocks the attack source address.

3. The method of claim 1, wherein, The target load balancing source address field is determined based on the load balancing source address field stored in the device corresponding to the target session, including: Starting from the last hop of the target session, the target load balancing source address field is read in reverse order until the target load balancing source address field is obtained.

4. The method of claim 1, wherein, The target load balancing source address field is determined based on the load balancing source address field stored in the device corresponding to the target session, including: A reading variant mode is obtained, wherein the reading variant mode carries a load balancing source address field identifier; A target load balancing source address field corresponding to the load balancing source address field identifier stored in the device corresponding to the target session is read.

5. A cyberattack processing apparatus, characterized by comprising: The security operation device configured in the target system includes a content distribution network, an application load device, an intrusion prevention system device, a server, and a security operation device. The network attack processing device includes: An obtaining module is configured to obtain a target load balancing source address field when a network attack event sent by the intrusion prevention system device is received, wherein the target load balancing source address field is stored in a device corresponding to the network attack event; determining a target load balancing source address field corresponding to an initial address set; filtering the initial address set based on a target whitelist to obtain an attack source address, wherein the target whitelist includes an application load device address, a whitelist stored in the intrusion prevention system device, and a whitelist stored in the security operation device, the whitelist stored in the intrusion prevention system device includes a translated address, and the whitelist stored in the security operation device includes an application system address running in the server and a content distribution network address; the obtaining module is specifically configured to: obtain a target session corresponding to a network attack event; determine a target load balancing source address field according to a load balancing source address field stored in a device corresponding to the target session; the determining module is specifically configured to: obtain a preset address extraction quantity; extract addresses in the target load balancing source address field according to the preset address extraction quantity; and generate an initial address set according to the extracted addresses of the preset address extraction quantity.

6. An electronic device, comprising: The electronic device includes: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the network attack processing method in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, The computer readable storage medium stores computer instructions for causing the processor to execute the network attack processing method in any one of claims 1-4 when executed.

8. A computer program product, characterised in that, The computer program product includes a computer program that, when executed by the processor, implements the network attack processing method according to any one of claims 1-4.

Citation Information

Patent Citations

  • Method, system and device for identifying and blocking network attack source, and medium

    CN113726790A

  • Address banning method, device and system, storage medium and electronic equipment

    CN113949581A