A flow cleaning method, apparatus, electronic device and storage medium

By monitoring information from both the attack and cleaning sides, dynamically adjusting cleaning nodes, and rationally allocating cleaning traffic, the problem of excessive load on cleaning nodes was solved, achieving network stability and efficient defense under large-scale attacks.

CN119520068BActive Publication Date: 2025-11-14CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411629257.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-14
Publication Date
2025-11-14
Estimated Expiration
2044-11-14

AI Technical Summary

Technical Problem

During cyberattacks, the cleaning nodes are overloaded and unable to effectively handle the load, affecting the overall defense effect, especially during large-scale attacks, which impact network stability and reliability.

Method used

By monitoring attack information on the attack side and load information on the cleaning side, the cleaning nodes corresponding to the attack traffic are dynamically adjusted, and the cleaning traffic is reasonably allocated to achieve load balancing and optimized resource allocation.

Benefits of technology

Maintaining network stability and reliability during large-scale attacks, improving the efficiency and effectiveness of attack traffic processing and cleaning, and enhancing defense effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119520068B_ABST
    Figure CN119520068B_ABST
Patent Text Reader

Abstract

This application provides a traffic scrubbing method, apparatus, electronic device, and storage medium. The method includes: determining the attack type of any attack traffic based on attack information; determining the target load corresponding to any scrubbing node based on its current load; determining the attack traffic that needs adjustment and the corresponding new scrubbing node based on the attack type and target load; and sending information representing the attack traffic that needs adjustment and information representing the corresponding new scrubbing node to a corresponding border router, so that the border router sends the attack traffic that needs adjustment to the new scrubbing node. By rationally allocating scrubbing traffic, load balancing of scrubbing nodes is achieved, and overall scrubbing resources are optimized, thereby adapting to the constantly changing network environment, maintaining network stability and reliability during large-scale attacks, improving the efficiency and effectiveness of attack traffic processing and scrubbing, and enhancing defense effectiveness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to a traffic scrubbing method, apparatus, electronic device, and storage medium. Background Technology

[0002] With the development of the internet, network attacks occur frequently. For example, Distributed Denial of Service (DDoS) attacks consume enormous amounts of network resources, severely impacting normal network operation. Traffic scrubbing is an effective defense against network attacks.

[0003] In related technologies, attack traffic is cleaned by setting up one or more cleaning nodes to obtain cleaned traffic.

[0004] However, when the attack traffic is too large, the cleaning nodes may be unable to handle it effectively due to excessive load, affecting the overall defense effect. Summary of the Invention

[0005] This application provides a flow cleaning method, apparatus, electronic device, and storage medium to rationally allocate cleaning flow and improve defense effectiveness.

[0006] In a first aspect, embodiments of this application provide a first flow cleaning method, the method comprising:

[0007] Based on the attack information of any attack traffic, determine the attack type of the attack traffic; and based on the current load of any cleaning node, determine the target load corresponding to the cleaning node.

[0008] Based on the attack type and the target load, determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes;

[0009] The information representing the attack traffic that needs to be adjusted and the information representing the corresponding new scrubbing node are sent to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new scrubbing node.

[0010] The above solution monitors both the attack and cleaning sides, redirects attack traffic based on the attack type on the attack side and the target load on the cleaning side, dynamically adjusts the cleaning nodes corresponding to the attack traffic, and achieves load balancing of the cleaning nodes by reasonably allocating the cleaning traffic. The overall cleaning resources are optimized, thus adapting to the ever-changing network environment, maintaining network stability and reliability during large-scale attacks, improving the efficiency of attack traffic processing and cleaning effect, and enhancing the defense effect.

[0011] In some optional implementations, the attack type of the attack traffic is determined based on the attack information of any attack traffic, including:

[0012] Based on the traffic characteristics and traffic patterns in the attack information, the attack type of the attack traffic is determined.

[0013] In some optional implementations, the target load corresponding to the cleaning node is determined based on the current load of any cleaning node, including:

[0014] Based on the current load of the cleaning node, the traffic pattern and duration of the corresponding attack traffic, the target load corresponding to the cleaning node is determined.

[0015] In some optional implementations, based on the attack type and the target load, the attack traffic that needs to be adjusted and the corresponding new scrubbing nodes are determined, including:

[0016] For any cleaning node, the required load corresponding to the cleaning node is determined based on the attack type of the corresponding attack traffic.

[0017] Based on the required load, target load, and load limit of each cleaning node, the attack traffic that needs to be adjusted and the corresponding new cleaning node are determined.

[0018] In some optional implementations, based on the required load, target load, and load limit of each scrubbing node, the attack traffic that needs to be adjusted and the corresponding new scrubbing node are determined, including:

[0019] Based on the demand load, target load and load limit of each cleaning node, the first overloaded cleaning node and the second idle cleaning node are determined.

[0020] Select the attack traffic that needs to be adjusted from the first cleaning node, and determine the second cleaning node corresponding to each attack traffic that needs to be adjusted based on the first address information of the attack traffic that needs to be adjusted and the second address information of the second cleaning node.

[0021] In some optional implementations, information characterizing the attack traffic that needs adjustment and information characterizing the corresponding new scrubbing nodes are sent to the corresponding border router, including:

[0022] Configure the Border Gateway Protocol Flow Spec based on the attack traffic that needs to be adjusted and the corresponding new scrubbing nodes;

[0023] Send the BGP Flow Spec to the corresponding border router.

[0024] Secondly, embodiments of this application provide a first type of flow cleaning device, which includes:

[0025] The determination module is used to determine the attack type of any attack traffic based on the attack information of any attack traffic; and to determine the target load corresponding to any cleaning node based on the current load of any cleaning node.

[0026] The reconfiguration module is used to determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes based on the attack type and the target load.

[0027] The sending module is used to send information representing the attack traffic that needs to be adjusted and information representing the corresponding new cleaning node to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new cleaning node.

[0028] In some alternative implementations, the determining module is specifically used for:

[0029] Based on the traffic characteristics and traffic patterns in the attack information, the attack type of the attack traffic is determined.

[0030] In some alternative implementations, the determining module is specifically used for:

[0031] Based on the current load of the cleaning node, the traffic pattern and duration of the corresponding attack traffic, the target load corresponding to the cleaning node is determined.

[0032] In some optional implementations, the reconfiguration module is specifically used for:

[0033] For any cleaning node, the required load corresponding to the cleaning node is determined based on the attack type of the corresponding attack traffic.

[0034] Based on the required load, target load, and load limit of each cleaning node, the attack traffic that needs to be adjusted and the corresponding new cleaning node are determined.

[0035] In some optional implementations, the reconfiguration module is specifically used for:

[0036] Based on the demand load, target load and load limit of each cleaning node, the first overloaded cleaning node and the second idle cleaning node are determined.

[0037] Select the attack traffic that needs to be adjusted from the first cleaning node, and determine the second cleaning node corresponding to each attack traffic that needs to be adjusted based on the first address information of the attack traffic that needs to be adjusted and the second address information of the second cleaning node.

[0038] In some alternative implementations, the sending module is specifically used for:

[0039] Configure the BGP Flow Spec based on the attack traffic that needs to be adjusted and the corresponding new scrubbing nodes;

[0040] Send the BGP Flow Spec to the corresponding border router.

[0041] Thirdly, embodiments of this application provide an electronic device, including at least one processor and at least one memory, wherein the memory stores a computer program, and when the program is executed by the processor, the processor performs any of the traffic cleaning methods described in the first aspect above.

[0042] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program executable by a processor, which, when run on the processor, causes the processor to perform any of the flow cleaning methods described in the first aspect above. Attached Figure Description

[0043] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0044] Figure 1 A first system architecture diagram provided for embodiments of this application;

[0045] Figure 2 A second system architecture diagram provided for embodiments of this application;

[0046] Figure 3 A third system architecture diagram provided for embodiments of this application;

[0047] Figure 4 A schematic flowchart of the first flow cleaning method provided in the embodiments of this application;

[0048] Figure 5 A fourth system architecture diagram provided for embodiments of this application;

[0049] Figure 6 A schematic flowchart of the second flow cleaning method provided in the embodiments of this application;

[0050] Figure 7 A schematic flowchart illustrating the third flow cleaning method provided in this application embodiment;

[0051] Figure 8This is a schematic diagram of the flow cleaning device provided in the embodiments of this application;

[0052] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0053] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0054] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0055] In the description of this application, it should be noted that, unless otherwise expressly specified and limited, the term "connection" should be interpreted broadly. For example, it can refer to a direct connection, an indirect connection through an intermediate medium, or a connection within two devices. Those skilled in the art can understand the specific meaning of the above term in this application based on the specific circumstances.

[0056] With the development of the internet, network attacks occur frequently. For example, DDoS attacks consume enormous amounts of network resources, severely impacting normal network operation. Traffic scrubbing is an effective defense against network attacks.

[0057] In related technologies, attack traffic is cleaned by setting up one or more cleaning nodes to obtain cleaned traffic.

[0058] See Figure 1 As shown, the network architecture has a cleaning node. A single cleaning node may be overloaded due to processing capacity limitations, resulting in decreased cleaning efficiency or even service interruption.

[0059] See Figure 2 As shown, although the network architecture has multiple cleaning nodes, the attack traffic may come from different regions, making it impossible to effectively utilize the multiple cleaning nodes distributed in different regions. This results in some nodes having idle resources while others are overloaded.

[0060] When the attack traffic is too high, the cleaning nodes may not be able to handle the above methods effectively due to excessive load, affecting the overall defense effect.

[0061] In view of this, embodiments of this application propose a flow cleaning method, apparatus, electronic device, and storage medium to rationally allocate cleaning flow and improve the defense effect.

[0062] See Figure 3 The diagram shows the system architecture provided in this application, including a core router (RR), a border router (PE), and multiple scrubbing nodes (…). Figure 3 Taking two cleaning nodes as an example, more cleaning nodes can be set up in the implementation, along with an intrusion detection system (IDS) and electronic devices. Among them:

[0063] One or more core routers can be deployed in the network. Figure 3 Taking one as an example, the core router, as the backbone of the network, is responsible for the main data transmission and routing decisions; the core router is configured with Border Gateway Protocol (BGP) route reflector function, which is used to distribute routing information within the Autonomous System (AS).

[0064] Multiple border routers are deployed at the network edge, serving as the interface between the user network and the Internet Service Provider (ISP) network. Each PE router is configured with a BGP session to establish a connection with the core router and receive and distribute routing information.

[0065] Multiple geographically distributed scrubbing nodes are deployed in the network, each equipped with high-performance traffic scrubbing equipment. The scrubbing nodes are connected to the border router via a high-speed network to receive and return traffic. For example, the scrubbing equipment is configured with BGP Flow Spec functionality. In this embodiment, the scrubbing nodes report load information to electronic devices. Figure 3 Taking two cleaning nodes (cleaning node 1 and cleaning node 2) as an example, more cleaning nodes can be set up in the implementation.

[0066] IDS is used to monitor and identify attack traffic in real time and report it to electronic devices.

[0067] Electronic devices are used to monitor the security status of the entire network, including the load of cleaning nodes and attack traffic. Based on attack information of any attack traffic, the attack type of the attack traffic is determined; and based on the current load of any cleaning node, the target load corresponding to that cleaning node is determined; based on the attack type and the target load, the attack traffic that needs adjustment and the corresponding new cleaning node are determined; information representing the attack traffic that needs adjustment and information representing the corresponding new cleaning node are sent to the corresponding border router, so that the border router sends the attack traffic that needs adjustment to the new cleaning node.

[0068] The technical solution of this application and how it solves the above-mentioned technical problems will be described in detail below with reference to the accompanying drawings and specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0069] Figure 4 A schematic flowchart of the first flow cleaning method provided in the embodiments of this application is shown below. Figure 4 As shown, it includes the following steps:

[0070] Step S401: Based on the attack information of any attack traffic, determine the attack type of the attack traffic; and based on the current load of any cleaning node, determine the target load corresponding to the cleaning node.

[0071] In practice, multiple cleaning nodes are deployed in the network. If the cleaning nodes are allocated cleaning traffic in a fixed way, load imbalance may occur. Therefore, this embodiment monitors both the attack side and the cleaning side for subsequent dynamic adjustments.

[0072] Since the attack information of the attack traffic reflects the relevant characteristics of the attack traffic, the attack type of the attack traffic is determined based on the attack information, and the attack type represents the load demand. Since the current load of the cleaning node reflects whether the cleaning node is overloaded, but the traffic is dynamic, it may be frequently adjusted if it is directly based on the current load. Therefore, the target load of the cleaning node is determined based on the current load, and the target load reflects the subsequent load of the cleaning node to a certain extent.

[0073] Step S402: Based on the attack type and the target load, determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes.

[0074] As mentioned above, the attack type represents the load demand, and the target load reflects the subsequent load of the cleaning node to a certain extent. Therefore, by combining these two pieces of information from the attack side and the cleaning side, it is possible to reasonably determine the attack traffic that needs to be adjusted and the corresponding new cleaning node.

[0075] Step S403: Send the information representing the attack traffic that needs to be adjusted and the information representing the corresponding new cleaning node to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new cleaning node.

[0076] In practice, after determining the attack traffic that needs to be adjusted and the corresponding new cleaning nodes, the adjustment information is sent to the corresponding border router. Subsequently, the border router sends the adjusted attack traffic to the new cleaning nodes, thereby rationally allocating the cleaning traffic.

[0077] For example, corresponding to the above Figure 3 In the system shown, if attack traffic 2 is determined to be the attack traffic requiring adjustment, the corresponding new cleaning node is cleaning node 1. A first adjustment message needs to be sent to PE1, and a second adjustment message needs to be sent to PE2. PE2 stops sending attack traffic 2 to cleaning node 2 based on the second adjustment message, and PE1 sends attack traffic 2 to cleaning node 1 based on the first adjustment message. After traffic redistribution, please refer to [reference needed]. Figure 5 As shown.

[0078] The above solution monitors both the attack and cleaning sides, redirects attack traffic based on the attack type on the attack side and the target load on the cleaning side, dynamically adjusts the cleaning nodes corresponding to the attack traffic, and achieves load balancing of the cleaning nodes by reasonably allocating the cleaning traffic. The overall cleaning resources are optimized, thus adapting to the ever-changing network environment, maintaining network stability and reliability during large-scale attacks, improving the efficiency of attack traffic processing and cleaning effect, and enhancing the defense effect.

[0079] In some optional implementations, the above step S101, which determines the attack type of the attack traffic, can be achieved in, but is not limited to, the following ways:

[0080] Based on the traffic characteristics and traffic patterns in the attack information, the attack type of the attack traffic is determined.

[0081] As mentioned above, the attack information of attack traffic reflects the relevant characteristics of the attack traffic. Some of the attack information is related to the load (such as traffic characteristics and traffic patterns), while some is not related to the load (such as address information). Based on this, this embodiment determines the attack type of the attack traffic based on the load-related traffic characteristics and traffic patterns.

[0082] For example, the traffic characteristics are the attack peaks, and the traffic patterns are the types of attacks the attack traffic belongs to.

[0083] This embodiment does not limit the specific implementation method for determining the attack type of attack traffic. For example, a type recognition model can be trained based on the traffic characteristics, traffic patterns and attack types of sample traffic, and the attack type of attack traffic can be determined through the type recognition model.

[0084] In some optional implementations, step S101 above, which determines the target load, can be achieved in, but is not limited to, the following ways:

[0085] Based on the current load of the cleaning node, the traffic pattern and duration of the corresponding attack traffic, the target load corresponding to the cleaning node is determined.

[0086] As mentioned above, the current load of the cleaning node reflects whether the cleaning node is overloaded, but the traffic is dynamic, and it may be frequently adjusted if it is directly based on the current load;

[0087] The traffic pattern and duration of the attack traffic reflect its dynamic characteristics to a certain extent, such as whether it is about to end. Based on this, this embodiment determines the target load corresponding to the cleaning node based on three pieces of information: the current load of the cleaning node, the traffic pattern of the corresponding attack traffic, and the duration of the attack traffic.

[0088] This embodiment does not limit the specific implementation method for determining the attack type of the attack traffic. For example, a load identification model can be trained based on three pieces of information: the current load of the sample cleaning node, the traffic pattern of the corresponding attack traffic, and the duration. The target load corresponding to the cleaning node can then be determined through this load identification model. Alternatively, an adjustment factor can be determined based on the traffic pattern and duration of the attack traffic. The current load of the cleaning node can then be adjusted based on this adjustment factor to determine the target load corresponding to the cleaning node.

[0089] Figure 6 A schematic flowchart of the second flow cleaning method provided in the embodiments of this application is shown below. Figure 6 As shown, it includes the following steps:

[0090] Step S601: Based on the attack information of any attack traffic, determine the attack type of the attack traffic; and based on the current load of any cleaning node, determine the target load corresponding to the cleaning node.

[0091] The specific implementation of step S601 can be found in other embodiments, and will not be repeated here.

[0092] Step S602: For any cleaning node, determine the required load corresponding to the cleaning node based on the attack type of the corresponding attack traffic.

[0093] As mentioned above, the attack type characterizes the load requirement. Therefore, based on the attack type of the attack traffic, the load requirement of the attack traffic can be accurately determined; based on the attack type of all attack traffic corresponding to the cleaning node, the load requirement corresponding to the cleaning node can be accurately determined.

[0094] For example, a mapping relationship between attack types and demand load is established, and the demand load of each attack traffic is determined based on this mapping relationship; the demand load corresponding to the cleaning node is determined based on the sum of all demand loads corresponding to the cleaning node.

[0095] Step S603: Based on the required load, target load, and load limit of each cleaning node, determine the attack traffic that needs to be adjusted and the corresponding new cleaning node.

[0096] The demand load of a cleaning node reflects the load required to handle the corresponding attack traffic, while the target load reflects the existing load of the cleaning node. In addition, the cleaning equipment deployed on each cleaning node may be different, meaning that the load limit that can be achieved is also different, and the load limit will also affect the attack traffic that the cleaning node can handle.

[0097] Based on this, this embodiment can accurately determine which cleaning nodes need to be adjusted and which attack traffic needs to be adjusted by combining these three pieces of information.

[0098] Step S604: Send the information representing the attack traffic that needs to be adjusted and the information representing the corresponding new cleaning node to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new cleaning node.

[0099] The specific implementation of step S604 can be found in other embodiments, and will not be repeated here.

[0100] In some optional implementations, step S603 above can be implemented in, but is not limited to, the following ways:

[0101] Based on the demand load, target load and load limit of each cleaning node, the first overloaded cleaning node and the second idle cleaning node are determined.

[0102] Select the attack traffic that needs to be adjusted from the first cleaning node, and determine the second cleaning node corresponding to each attack traffic that needs to be adjusted based on the first address information of the attack traffic that needs to be adjusted and the second address information of the second cleaning node.

[0103] Since the cleaning equipment deployed at each cleaning node may differ, the cleaning capacity of each cleaning node is different, and the load limit that it can reach is also different. Therefore, the load limit will also affect the attack traffic that the cleaning node can handle.

[0104] Based on this, this embodiment combines the required load, target load, and load limit of the cleaning node to determine whether the cleaning node is overloaded, idle, or operating normally.

[0105] For example, a load recognition model is trained based on the demand load, target load, load limit, and load status (overload, idle, or normal operation) of the sample cleaning node. The demand load, target load, and load limit of the cleaning node are then input into the load recognition model to determine whether the cleaning node is overloaded, idle, or operating normally. Alternatively, load information is determined based on the demand load and target load, and the ratio of this load information to the load limit is determined. If the ratio is less than a first preset ratio, the cleaning node is determined to be idle; if the ratio is greater than or equal to the first preset ratio and less than or equal to a second preset ratio, the cleaning node is determined to be operating normally; if the ratio is greater than the second preset ratio, the cleaning node is determined to be overloaded.

[0106] Furthermore, for the overloaded first scrubbing node, it is necessary to select attack traffic that needs adjustment and migrate it to an idle second scrubbing node. Based on the attack traffic that needs adjustment and the address information of the second scrubbing node, the corresponding second scrubbing node can be determined more reasonably for each attack traffic that needs adjustment.

[0107] For example, the cleaning node closest to the address of the attack traffic that needs to be adjusted is selected from the second cleaning nodes. If the load of the cleaning node matches the attack traffic that needs to be adjusted (e.g., the difference between the load limit and the target load is greater than the required load of the attack traffic that needs to be adjusted), the cleaning node corresponding to the attack traffic that needs to be adjusted is selected.

[0108] Figure 7 A schematic flowchart of the third flow cleaning method provided in the embodiments of this application is shown below. Figure 7 As shown, it includes the following steps:

[0109] Step S701: Based on the attack information of any attack traffic, determine the attack type of the attack traffic; and based on the current load of any cleaning node, determine the target load corresponding to the cleaning node.

[0110] Step S702: Based on the attack type and the target load, determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes.

[0111] The specific implementation methods of steps S701 to S702 can be found in other embodiments, and will not be repeated here.

[0112] Step S703: Configure BGP FlowSpec based on the attack traffic that needs to be adjusted and the corresponding new cleaning nodes.

[0113] In this embodiment, BGP FlowSpec rules are generated based on the attack traffic that needs to be adjusted and the corresponding new cleaning nodes to guide traffic redirection.

[0114] Step S704: Send the BGP Flow Spec to the corresponding border router so that the border router sends the attack traffic that needs to be adjusted to the new cleaning node.

[0115] By pushing the generated BGP Flow Spec to PE routers in the network, timely updates and correct execution of rules are ensured.

[0116] In practice, all the cleaning nodes participating in dynamic load balancing are in normal working order. In some optional implementations, monitoring network components are deployed on electronic devices to quickly detect faults in the cleaning nodes, thereby ensuring high network availability.

[0117] In some optional implementations, the aforementioned electronic device also provides an interactive interface that displays information such as system status, configuration policies, management events, security reports, and logs. This facilitates auditing, compliance, and continuous security improvements by relevant personnel.

[0118] like Figure 8 As shown, this application embodiment provides a flow cleaning device 800, which includes:

[0119] The determination module 801 is used to determine the attack type of the attack traffic based on the attack information of any attack traffic; and to determine the target load corresponding to any cleaning node based on the current load of any cleaning node.

[0120] The reconfiguration module 802 is used to determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes based on the attack type and the target load.

[0121] The sending module 803 is used to send information representing the attack traffic that needs to be adjusted and information representing the corresponding new cleaning node to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new cleaning node.

[0122] In some optional implementations, the determining module 801 is specifically used for:

[0123] Based on the traffic characteristics and traffic patterns in the attack information, the attack type of the attack traffic is determined.

[0124] In some optional implementations, the determining module 801 is specifically used for:

[0125] Based on the current load of the cleaning node, the traffic pattern and duration of the corresponding attack traffic, the target load corresponding to the cleaning node is determined.

[0126] In some optional implementations, the reconfiguration module 802 is specifically used for:

[0127] For any cleaning node, the required load corresponding to the cleaning node is determined based on the attack type of the corresponding attack traffic.

[0128] Based on the required load, target load, and load limit of each cleaning node, the attack traffic that needs to be adjusted and the corresponding new cleaning node are determined.

[0129] In some optional implementations, the reconfiguration module 802 is specifically used for:

[0130] Based on the demand load, target load and load limit of each cleaning node, the first overloaded cleaning node and the second idle cleaning node are determined.

[0131] Select the attack traffic that needs to be adjusted from the first cleaning node, and determine the second cleaning node corresponding to each attack traffic that needs to be adjusted based on the first address information of the attack traffic that needs to be adjusted and the second address information of the second cleaning node.

[0132] In some optional implementations, the sending module 803 is specifically used for:

[0133] Configure the BGP Flow Spec based on the attack traffic that needs to be adjusted and the corresponding new scrubbing nodes;

[0134] Send the BGP Flow Spec to the corresponding border router.

[0135] Since this device is the same as the device in the method of this application embodiment, and the principle of the device in solving the problem is similar to that of the method, the implementation of the device can be referred to the implementation of the method, and the repeated parts will not be described again.

[0136] Based on the same technical concept, this application also provides an electronic device 900, such as... Figure 9 As shown, it includes at least one processor 901 and a memory 902 connected to at least one processor. In this embodiment, the specific connection medium between the processor 901 and the memory 902 is not limited. Figure 9Taking the connection between processor 901 and memory 902 via bus 903 as an example, the bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, Figure 9 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0137] The processor 901 is the control center of the electronic device, capable of connecting various parts of the device via various interfaces and lines. It performs data processing by running or executing instructions stored in the memory 902 and retrieving data stored in the memory 902. Optionally, the processor 901 may include one or more processing units. The processor 901 may integrate an application processor and a modem processor. The application processor primarily handles the operating system, user interface, and applications, while the modem processor primarily handles issuing instructions. It is understood that the modem processor may not be integrated into the processor 901. In some embodiments, the processor 901 and the memory 902 may be implemented on the same chip; in other embodiments, they may be implemented on separate chips.

[0138] The processor 901 can be a general-purpose processor, such as a CPU, digital signal processor, application-specific integrated circuit (ASIC), field-programmable gate array or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, capable of implementing or executing the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the flow cleaning method can be directly manifested as being executed by a hardware processor, or executed by a combination of hardware and software modules within the processor.

[0139] Memory 902, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. Memory 902 may include at least one type of storage medium, such as flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic storage, magnetic disk, optical disk, etc. Memory 902 can be any other medium capable of carrying or storing desired program code in the form of instructions or data structures that can be accessed by a computer, but is not limited thereto. In the embodiments of this application, memory 902 can also be a circuit or any other device capable of implementing storage functions for storing program instructions and / or data.

[0140] In this embodiment, the memory 902 stores a computer program, which, when executed by the processor 901, causes the processor 901 to perform the following:

[0141] Based on the attack information of any attack traffic, determine the attack type of the attack traffic; and based on the current load of any cleaning node, determine the target load corresponding to the cleaning node.

[0142] Based on the attack type and the target load, determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes;

[0143] The information representing the attack traffic that needs to be adjusted and the information representing the corresponding new scrubbing node are sent to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new scrubbing node.

[0144] In some optional implementations, processor 901 specifically performs:

[0145] Based on the traffic characteristics and traffic patterns in the attack information, the attack type of the attack traffic is determined.

[0146] In some optional implementations, processor 901 specifically performs:

[0147] Based on the current load of the cleaning node, the traffic pattern and duration of the corresponding attack traffic, the target load corresponding to the cleaning node is determined.

[0148] In some optional implementations, processor 901 specifically performs:

[0149] For any cleaning node, the required load corresponding to the cleaning node is determined based on the attack type of the corresponding attack traffic.

[0150] Based on the required load, target load, and load limit of each cleaning node, the attack traffic that needs to be adjusted and the corresponding new cleaning node are determined.

[0151] In some optional implementations, processor 901 specifically performs:

[0152] Based on the demand load, target load and load limit of each cleaning node, the first overloaded cleaning node and the second idle cleaning node are determined.

[0153] Select the attack traffic that needs to be adjusted from the first cleaning node, and determine the second cleaning node corresponding to each attack traffic that needs to be adjusted based on the first address information of the attack traffic that needs to be adjusted and the second address information of the second cleaning node.

[0154] In some optional implementations, processor 901 specifically performs:

[0155] Configure the BGP Flow Spec based on the attack traffic that needs to be adjusted and the corresponding new scrubbing nodes;

[0156] Send the BGP Flow Spec to the corresponding border router.

[0157] Since the electronic device is the same as the electronic device in the method of this application embodiment, and the principle of the electronic device in solving the problem is similar to that of the method, the implementation of the electronic device can refer to the implementation of the method, and the repeated parts will not be described again.

[0158] Based on the same technical concept, embodiments of this application also provide a computer-readable storage medium storing a computer program executable by a processor, which, when run on the processor, causes the processor to perform the steps of the above-described flow cleaning method.

[0159] In some alternative implementations, various aspects of the traffic scrubbing method provided in this application can also be implemented as a program product containing computer-executable instructions. When the program product is run on a computer device, the computer-executable instructions are used to cause the computer device to perform the steps of the traffic scrubbing method according to the various exemplary embodiments of this application described above.

[0160] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0161] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0162] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0163] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0164] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0165] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A flow cleaning method, characterized in that, Applied to electronic devices, the method includes: Based on the attack information of any attack traffic, determine the attack type of the attack traffic; and based on the current load of any cleaning node, determine the target load corresponding to the cleaning node; the target load represents the subsequent load of the cleaning node. Based on the attack type and the target load, determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes; The information representing the attack traffic that needs to be adjusted and the information representing the corresponding new scrubbing node are sent to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new scrubbing node. Based on the current load of any cleaning node, determine the target load corresponding to the cleaning node, including: Based on the current load of the cleaning node, the traffic pattern and duration of the corresponding attack traffic, the target load corresponding to the cleaning node is determined. Based on the attack type and the target load, determine the attack traffic that needs adjustment and the corresponding new scrubbing nodes, including: For any cleaning node, the required load corresponding to the cleaning node is determined based on the attack type of the corresponding attack traffic. Based on the required load, target load, and load limit of each cleaning node, determine the attack traffic that needs to be adjusted and the corresponding new cleaning node. Before determining the attack traffic to be adjusted and the corresponding new cleaning nodes based on the required load, target load, and load limit of each cleaning node, the following steps are also included: Determine whether the cleaning node is overloaded; wherein, whether the cleaning node is overloaded is obtained by the following method: Based on the demand load and the target load, load information is determined, and the ratio of the load information to the load limit is determined. If the ratio is greater than a second preset ratio, the cleaning node is determined to be overloaded.

2. The method as described in claim 1, characterized in that, Based on the attack information of any attack traffic, determine the attack type of the attack traffic, including: Based on the traffic characteristics and traffic patterns in the attack information, the attack type of the attack traffic is determined.

3. The method as described in claim 1, characterized in that, Based on the required load, target load, and load limit of each cleaning node, determine the attack traffic that needs adjustment and the corresponding new cleaning nodes, including: Based on the demand load, target load and load limit of each cleaning node, the first overloaded cleaning node and the second idle cleaning node are determined. Select the attack traffic that needs to be adjusted from the first cleaning node, and determine the second cleaning node corresponding to each attack traffic that needs to be adjusted based on the first address information of the attack traffic that needs to be adjusted and the second address information of the second cleaning node.

4. The method according to any one of claims 1 to 3, characterized in that, The information representing the attack traffic that needs to be adjusted, as well as the information representing the corresponding new cleaning node, is sent to the corresponding border router, including: Configure the BGP Flow Spec based on the attack traffic that needs to be adjusted and the corresponding new scrubbing nodes; Send the BGP Flow Spec to the corresponding border router.

5. A flow-rate cleaning device, characterized in that, The device includes: The determination module is used to determine the attack type of any attack traffic based on the attack information of any attack traffic; and to determine the target load corresponding to any cleaning node based on the current load of any cleaning node; the target load represents the subsequent load of the cleaning node. The reconfiguration module is used to determine the attack traffic that needs to be adjusted and the corresponding new cleaning nodes based on the attack type and the target load. The sending module is used to send information representing the attack traffic that needs to be adjusted and information representing the corresponding new cleaning node to the corresponding border router, so that the border router sends the attack traffic that needs to be adjusted to the new cleaning node. The module is specifically used for: Based on the current load of the cleaning node, the traffic pattern and duration of the corresponding attack traffic, the target load corresponding to the cleaning node is determined. The reconfiguration module is specifically used for: For any cleaning node, the required load corresponding to the cleaning node is determined based on the attack type of the corresponding attack traffic. Based on the required load, target load, and load limit of each cleaning node, determine the attack traffic that needs to be adjusted and the corresponding new cleaning node. Before determining the attack traffic to be adjusted and the corresponding new cleaning nodes based on the required load, target load, and load limit of each cleaning node, the reconfiguration module is further used for: Determine whether the cleaning node is overloaded; wherein, whether the cleaning node is overloaded is obtained by the following method: Based on the demand load and the target load, load information is determined, and the ratio of the load information to the load limit is determined. If the ratio is greater than a second preset ratio, the cleaning node is determined to be overloaded.

6. The apparatus as claimed in claim 5, characterized in that, The module is specifically used for: Based on the traffic characteristics and traffic patterns in the attack information, the attack type of the attack traffic is determined.

7. An electronic device, characterized in that, It includes at least one processor and at least one memory, wherein the memory stores a computer program that, when executed by the processor, causes the processor to perform the method as described in any one of claims 1 to 4.

8. A computer-readable storage medium, characterized in that, It stores a computer program executable by a computer, which, when run on the computer, causes the computer to perform the method as described in any one of claims 1 to 4.

Citation Information

Patent Citations

  • Traffic cleaning method and device, electronic equipment and storage medium

    CN117792690A