DDoS attack monitoring method and system for industrial network equipment

CN119520171BActive Publication Date: 2025-05-09BEIJING TIANDIHEXING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510089581.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-09
Estimated Expiration
2045-01-21

Smart Images

  • Figure CN119520171B_ABST
    Figure CN119520171B_ABST
Patent Text Reader

Abstract

The present invention discloses a DDoS attack monitoring method and system for industrial network equipment, and relates to the field of data processing technology. The method comprises: obtaining a first flow curve of each edge engineering server in an engineering logistics network, wherein the first flow curve includes flow sub-curves of multiple time periods; determining the normal time period of each edge engineering server respectively according to each first flow curve; determining the server association index between each edge engineering server according to the number of access users of each edge engineering server in the normal time period and the distance between each edge engineering server; determining the abnormal index of each access user according to the server association index between each edge engineering server; determining the access user whose abnormal index is greater than a preset abnormal threshold as a malicious user who initiates a DDoS attack. The present invention can accurately identify malicious users who initiate DDoS attacks and improve the accuracy of identifying DDoS attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular to a DDoS attack monitoring method and system for industrial network equipment. Background Art

[0002] During operation, engineering logistics networks may be attacked by malicious users. The most common attack method includes Distributed Denial of Service (DDoS) attacks.

[0003] In the existing methods, when detecting the engineering logistics network under DDoS attack from malicious users, a threshold is usually set for the traffic in the network based on the characteristic that DDoS attack will cause a sudden increase in network traffic within a certain period of time, so as to determine whether the engineering logistics network in the corresponding state is under DDoS attack.

[0004] However, when a road section is interrupted due to bad weather, maintenance, etc., it will also cause a sudden increase in traffic on its adjacent sections during a certain period of time. As a result, the existing methods have low accuracy in identifying DDoS attacks. Summary of the invention

[0005] The embodiments of the present invention provide a DDoS attack monitoring method and system for industrial network equipment, which can accurately identify malicious users who initiate DDoS attacks and improve the accuracy of identifying DDoS attacks.

[0006] A first aspect of an embodiment of the present invention provides a DDoS attack monitoring method for industrial network devices, comprising:

[0007] Acquire a first flow curve of each edge engineering server in the engineering logistics network, wherein the first flow curve includes flow sub-curves in multiple time periods;

[0008] Determine the normal time period of each edge engineering server according to each first traffic curve;

[0009] Determine the server correlation index between the edge engineering servers according to the number of access users of each edge engineering server in a normal time period and the distance between the edge engineering servers;

[0010] Determine the abnormal index of each access user based on the server correlation index between each edge engineering server;

[0011] Access users whose anomaly index is greater than the preset anomaly threshold are identified as malicious users who initiate DDoS attacks.

[0012] A second aspect of an embodiment of the present invention provides a DDoS attack monitoring system for industrial network devices, including:

[0013] A curve acquisition module, used to acquire a first flow curve of each edge engineering server in the engineering logistics network, wherein the first flow curve includes flow sub-curves of multiple time periods;

[0014] A time period determination module, used to determine the normal time period of each edge engineering server according to each first traffic curve;

[0015] An association determination module, used to determine the server association index between each edge engineering server according to the number of access users of each edge engineering server in a normal time period and the distance between each edge engineering server;

[0016] An abnormality determination module, used to determine the abnormality index of each access user according to the server association index between each edge engineering server;

[0017] The user determination module is used to determine the access user whose abnormal index is greater than a preset abnormal threshold as a malicious user who initiates a DDoS attack.

[0018] In the DDoS attack monitoring method for industrial network equipment provided by an embodiment of the present invention, the normal time period of each edge engineering server is screened out according to the first flow curve of each edge engineering server in the engineering logistics network. Then, according to the number of access users of each edge engineering server in the normal time period and the distance between each edge engineering server, the server association index between each edge engineering server is determined. Then, according to the server association index between each edge engineering server, the abnormal index of each access user is determined, and the malicious user who initiates the DDoS attack is screened out according to the abnormal index. In this way, the present invention evaluates the abnormal index of the access user by comprehensively considering the server association index between each edge engineering server. It can avoid the interference caused by the sudden increase in traffic in the adjacent section during a certain period of time when a certain section is interrupted due to bad weather, overhaul and maintenance, etc. Thereby, the malicious user who initiates the DDoS attack can be accurately identified, and the accuracy of identifying the DDoS attack can be improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0020] Figure 1A flowchart of a first DDoS attack monitoring method for industrial network devices provided by an embodiment of the present invention;

[0021] Figure 2 A network topology diagram of an edge engineering server provided by an embodiment of the present invention;

[0022] Figure 3 A flow chart of a second DDoS attack monitoring method for industrial network devices provided by an embodiment of the present invention;

[0023] Figure 4 A schematic diagram of path transfer when an edge engineering server is damaged provided by an embodiment of the present invention;

[0024] Figure 5 A schematic diagram of a flow chart of a third DDoS attack monitoring method for industrial network devices provided by an embodiment of the present invention;

[0025] Figure 6 A flowchart of a fourth DDoS attack monitoring method for industrial network devices provided by an embodiment of the present invention;

[0026] Figure 7 A schematic diagram of the structure of a DDoS attack monitoring system for industrial network devices provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0027] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following is a detailed description of a DDoS attack monitoring method and system for industrial network equipment proposed by the present invention, its specific implementation method, structure, features and effects, in combination with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.

[0028] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

[0029] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of the present invention are in compliance with the relevant provisions of laws and regulations.

[0030] It should be noted that in the embodiments of the present invention, certain software, components, models and other existing solutions in the industry may be mentioned, which should be regarded as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of the present invention, but it does not mean that the applicant has or will necessarily use the solution.

[0031] In the existing methods, when detecting the engineering logistics network under DDoS attacks by malicious users, a threshold is usually set for the network traffic based on the characteristic that DDoS attacks will cause a sudden increase in network traffic within a certain period of time, so as to determine whether the engineering logistics network in the corresponding state is under DDoS attacks. However, when a section of road is interrupted due to bad weather, maintenance, etc., it will also cause a sudden increase in traffic in its adjacent sections within a certain period of time. As a result, the existing methods have low accuracy in identifying DDoS attacks.

[0032] The object of the present invention is to provide a DDoS attack monitoring method and system for industrial network equipment. In the DDoS attack monitoring method for industrial network equipment provided by the embodiment of the present invention, the normal time period of each edge engineering server is screened out according to the first flow curve of each edge engineering server in the engineering logistics network. Then, according to the number of access users of each edge engineering server in the normal time period and the distance between each edge engineering server, the server association index between each edge engineering server is determined. Then, according to the server association index between each edge engineering server, the abnormal index of each access user is determined, and the malicious user who initiates the DDoS attack is screened out according to the abnormal index. In this way, the present invention evaluates the abnormal index of the access user by comprehensively considering the server association index between each edge engineering server. It can avoid the interference caused by the sudden increase in traffic in the adjacent section during a certain period of time when a certain section is interrupted due to bad weather, overhaul and maintenance, etc. Thereby, the malicious user who initiates the DDoS attack can be accurately identified, and the accuracy of identifying the DDoS attack can be improved.

[0033] The following describes specific embodiments of the DDoS attack monitoring method and system for industrial network devices provided by the embodiments of the present invention.

[0034] The following first introduces a DDoS attack monitoring method for industrial network devices provided by an embodiment of the present invention.

[0035] Figure 1 A flow chart of a DDoS attack monitoring method for industrial network devices is provided. The DDoS attack monitoring method for industrial network devices can be applied to a server. The DDoS attack monitoring method for industrial network devices can include the following S101 to S105.

[0036] S101, obtaining a first flow curve of each edge engineering server in an engineering logistics network, where the first flow curve includes flow sub-curves in multiple time periods.

[0037] In this embodiment, the first flow curve is used to characterize the flow change of the edge engineering server in each time period within a preset time period. The first flow curve includes multiple flow sub-curves, each flow sub-curve corresponds to a time period.

[0038] Each flow sub-curve represents the flow change in the time period, and the length of the time period corresponding to each flow sub-curve can be the same or different. For example, the first flow curve can include a flow sub-curve with a time period of 1 day, or a flow sub-curve with a time period of 1 hour.

[0039] As an example, the server collects the traffic data of each edge engineering server within a preset time period through a network monitoring tool or a log system. Then, the collected traffic data is divided according to a preset time period (for example, every day, every hour, etc.) to obtain traffic sub-curves for multiple time periods. Finally, the traffic sub-curves are aggregated to form a first traffic curve corresponding to each edge engineering server.

[0040] S102: Determine a normal time period of each edge engineering server according to each first traffic curve.

[0041] In this embodiment, as an example, the server sets a slope threshold according to the traffic characteristics, wherein the slope threshold can be dynamically adjusted according to factors such as historical data.

[0042] Then, the first traffic curve of each edge engineering server is analyzed to identify the traffic change pattern of each edge engineering server, such as peak period, trough period, etc., and the slope of each traffic sub-curve in the first traffic curve is calculated.

[0043] Finally, the curve slope of each traffic sub-curve is compared with the slope threshold. When the curve slope of the traffic sub-curve is less than the slope threshold, it means that there is no sudden increase in traffic on the edge engineering server at this time, that is, the time period corresponding to the traffic sub-curve is a normal time period.

[0044] S103, determining a server association index between the edge engineering servers according to the number of access users of each edge engineering server in a normal time period and the distance between the edge engineering servers.

[0045] In this embodiment, the server association index is used to characterize the similarity or association between two edge engineering servers and access users.

[0046] As an example, the server counts the number of users accessing each edge engineering server during a normal time period; at the same time, the distance between each edge engineering server is calculated using a geographic information system (GIS) or a network topology map.

[0047] like Figure 2 As shown, a network topology diagram of an edge engineering server is provided. Among them, A1, A2, A3, A4, A5 and A6 are all edge engineering servers, and S1, S2, S3, S4, S5, S6 and S7 are all paths between edge engineering servers, that is, the distance between edge engineering servers. For example, S1 is the path between edge engineering server A1 and edge engineering server A2, that is, the distance between edge engineering server A1 and edge engineering server A2.

[0048] Then, combining the number of access users and distance information, a suitable algorithm (such as weighted summation, cluster analysis, etc.) is used to calculate the correlation index between each edge engineering server. Specifically, the closer the number of access users between two edge engineering servers in a normal time period, the greater the server correlation index; the smaller the distance between two edge engineering servers, the greater the server correlation index.

[0049] S104: Determine the abnormality index of each access user according to the server association index between the edge engineering servers.

[0050] In this embodiment, the abnormality index is used to characterize the suspicious degree of the behavior of the accessing user. The larger the abnormality index is, the greater the possibility that the accessing user is a malicious user who initiates a DDoS attack.

[0051] As an example, the server analyzes the behavior characteristics of each access user on different edge engineering servers, such as access frequency, access duration, access path, etc. According to the behavior characteristics of the access user on different edge engineering servers and the server correlation index between the edge engineering servers accessed by the access user, an abnormality index is set for each access user.

[0052] Specifically, if the server correlation index between the edge engineering servers accessed by the visiting user is high, it means that the access behavior of the visiting user at this time conforms to the normal rules. That is, it conforms to the normal phenomenon that when a certain section of the road is interrupted due to bad weather, maintenance, etc., the user chooses to go to the adjacent section with strong correlation. Therefore, the smaller the corresponding abnormal index is at this time.

[0053] If the server correlation index between the edge engineering servers accessed by the accessing user is low, it means that the access behavior of the accessing user does not conform to the normal rules. That is, there is no correlation between the edge engineering servers with high access frequency, which may be a DDoS attack launched by malicious irregularity. At this time, the larger the corresponding abnormal index.

[0054] S105, determining the access user whose abnormality index is greater than the preset abnormality threshold as a malicious user who initiates the DDoS attack.

[0055] In this embodiment, the server sets a reasonable preset abnormal threshold according to business requirements and security policies, and marks access users whose abnormal index is greater than the preset abnormal threshold as malicious users, who may be the source of DDoS attacks.

[0056] Furthermore, necessary security measures can be taken against identified malicious users, such as blocking IP addresses, restricting access rights, etc., to prevent DDoS attacks from continuing to occur.

[0057] In the DDoS attack monitoring method for industrial network equipment provided in this embodiment, the normal time period of each edge engineering server is screened out according to the first flow curve of each edge engineering server in the engineering logistics network. Then, according to the number of access users of each edge engineering server in the normal time period and the distance between each edge engineering server, the server association index between each edge engineering server is determined. Then, according to the server association index between each edge engineering server, the abnormal index of each access user is determined, and the malicious user who initiates the DDoS attack is screened out according to the abnormal index. In this way, the present invention evaluates the abnormal index of the access user by comprehensively considering the server association index between each edge engineering server. It can avoid the interference caused by the sudden increase in traffic in the adjacent section during a certain period of time when a certain section is interrupted due to bad weather, overhaul and maintenance, etc. Thereby, the malicious user who initiates the DDoS attack can be accurately identified, and the accuracy of identifying the DDoS attack can be improved.

[0058] As an optional embodiment, S101 may specifically include:

[0059] Monitor each edge engineering server in the engineering logistics network and obtain the traffic of each edge engineering server at each time;

[0060] Based on the traffic of each edge engineering server at each time, construct a second traffic curve for each edge engineering server;

[0061] Each second flow curve is segmented from the flow extreme point, and each segmented curve is determined as a flow sub-curve to constitute the first flow curve of each edge engineering server.

[0062] In this embodiment, the second traffic curve is used to characterize the overall traffic change of the edge engineering server within a preset time period, that is, the second traffic curve belongs to the overall traffic change curve that is not split into multiple traffic sub-curves.

[0063] As an example, the server first deploys traffic monitoring tools on each edge engineering server to capture network traffic data in real time. Set an appropriate data collection frequency, such as recording traffic data once per second or every minute, and store the collected traffic data in a central database or distributed storage system for subsequent processing and analysis.

[0064] Then, the traffic data corresponding to each edge engineering server is arranged in chronological order to construct a time series; and a chart library (such as Matplotlib, ECharts, etc.) is used to draw the time series data into a second traffic curve, and each edge engineering server corresponds to a second traffic curve.

[0065] Finally, use the target algorithm (such as peak detection algorithm, moving average method, etc.) to detect the flow extreme points (including peaks and valleys) in each second flow curve. And according to the detected flow extreme points, divide the second flow curve into multiple flow sub-curves, each flow sub-curve from one flow extreme point to the next flow extreme point. All the flow sub-curves corresponding to the edge engineering server are combined to form the first flow curve of the edge engineering server.

[0066] Through this embodiment, the second flow curve is segmented from the flow extreme point to obtain multiple flow sub-curves. In this way, each flow sub-curve can fully reflect the change trend of the flow in a stage, so that the normal time period of each edge engineering server can be accurately analyzed according to the change trend of the flow, thereby improving the recognition accuracy of the normal time period of the edge engineering server.

[0067] As an optional embodiment, Figure 3 As shown, S102 may specifically include the following S301 to S303:

[0068] S301, obtaining each flow sub-curve in a target first flow curve, where the target first flow curve is any one of the first flow curves;

[0069] S302, determining the abnormal possibility of the time period corresponding to each flow sub-curve according to the flow at each moment in each flow sub-curve;

[0070] S303: Determine each time period in which the abnormal possibility is less than or equal to the preset possibility threshold as a normal time period of the edge engineering server corresponding to the target first traffic curve.

[0071] In this embodiment, the abnormal possibility is used to characterize the probability that the time period corresponding to the traffic sub-curve belongs to the abnormal time period. The greater the abnormal possibility, the greater the probability that the time period corresponding to the traffic sub-curve belongs to the abnormal time period.

[0072] The preset possibility threshold is used to determine whether the time period corresponding to the traffic sub-curve belongs to an abnormal time period. If the abnormal possibility is less than or equal to the preset possibility threshold, it means that the time period corresponding to the traffic sub-curve does not belong to an abnormal time period.

[0073] As an example, the server retrieves the target first traffic curve from the database or obtains it through a network request, and then for each traffic sub-curve in the target first traffic curve, calculates the corresponding curve slope according to the traffic at each moment in the traffic sub-curve, and sets the corresponding abnormality possibility according to the curve slope.

[0074] Then, the abnormal possibility of the time period corresponding to each traffic sub-curve in the target first traffic curve is traversed, and the time period corresponding to each traffic sub-curve whose abnormal possibility is less than or equal to the preset possibility threshold is determined as the normal time period of the edge engineering server corresponding to the target first traffic curve.

[0075] The above operations are performed respectively for the first traffic curve of each edge engineering server, so that the normal time period of each edge engineering server can be obtained.

[0076] Through this embodiment, the abnormal possibility of the time period corresponding to the traffic sub-curve is determined according to the traffic at each moment in the traffic sub-curve. And each time period with an abnormal possibility less than or equal to a preset possibility threshold is determined as a normal time period of the edge engineering server. In this way, by calculating the abnormal possibility of the time period corresponding to the traffic sub-curve, the normal time period of the edge engineering server can be accurately screened out, thereby improving the accuracy of identifying DDoS attacks.

[0077] As an optional embodiment, S302 may specifically include:

[0078] Obtaining a first average flow of a target flow sub-curve and a second average flow of each first reference flow sub-curve, wherein the first reference flow sub-curve is a flow sub-curve of the remaining edge engineering servers in the engineering logistics network, except for the target edge engineering server corresponding to the target flow sub-curve, within a time period corresponding to the target flow sub-curve;

[0079] Determine the first reference flow sub-curve of each edge engineering server whose distance to the target edge engineering server is less than a preset distance threshold as the second reference flow sub-curve;

[0080] The absolute value of the difference between the average value of the second average flow of each second reference flow sub-curve and the first average flow is multiplied by the first average flow to obtain a first calculation result;

[0081] The first calculation result is divided by the maximum value of each second average flow rate to obtain the abnormal possibility of the time period corresponding to the target flow sub-curve.

[0082] In this embodiment, the first average flow is used to characterize the average flow obtained by averaging the flow at each moment in the target flow sub-curve, and the second average flow is used to characterize the average flow obtained by averaging the flow at each moment in the first reference flow sub-curve.

[0083] The first reference flow sub-curve is used to characterize the flow sub-curves of the edge engineering servers in the engineering logistics network, except for the target edge engineering server corresponding to the target flow sub-curve, in the time period corresponding to the target flow sub-curve; the second reference flow sub-curve is used to characterize the flow sub-curves of the edge engineering servers whose distance from the target edge engineering server is less than a preset distance threshold in the time period corresponding to the target flow sub-curve. The preset distance threshold is equal to the average of the distances between the edge engineering servers in the engineering logistics network.

[0084] like Figure 4 As shown, a schematic diagram of path transfer when the edge engineering server is damaged is provided. When the edge engineering server A3 is damaged, the path S2 will be interrupted. At this time, the logistics vehicles that originally need to pass through the path S2 will be transferred to the path S1 and the path S3, so that the traffic of the edge engineering server A2 and the edge engineering server A4 will increase suddenly.

[0085] Based on this, the abnormal possibility of the time period corresponding to the target flow sub-curve can be determined by the following formula 1:

[0086] Formula 1

[0087] In formula 1, It is used to characterize the abnormal possibility of the i-th edge engineering server in the j-th time period. The first average flow rate of the flow sub-curve used to characterize the i-th edge engineering server in the j-th time period, The average value of the second average flow of each second reference flow sub-curve corresponding to the flow sub-curve of the i-th edge engineering server in the j-th time period, Used to characterize the maximum value of the second average flows of each first reference flow sub-curve in the j-th time period in the engineering logistics network.

[0088] in, The larger the value is, the greater the traffic difference between the target edge engineering server and each edge engineering server within the preset distance threshold in the jth time period is, and the greater the possibility that the target edge engineering server is abnormal in the jth time period is; The larger the value is, the greater the traffic difference between the target edge engineering server and each edge engineering server in the engineering logistics network in the jth time period, and the greater the possibility of abnormality of the target edge engineering server in the jth time period.

[0089] Through this embodiment, the abnormal possibility of the time period corresponding to each traffic sub-curve is determined according to the traffic at each time in each traffic sub-curve. In this way, by quantifying the abnormal possibility of the time period corresponding to the traffic sub-curve, the normal time period of the edge engineering server can be accurately screened, thereby improving the accuracy of identifying DDoS attacks.

[0090] As an optional embodiment, Figure 5 As shown, S103 may specifically include the following S501 to S503:

[0091] S501, calculating the local correlation degree between the first edge engineering server and the second edge engineering server in each normal time period based on the number of first visiting users of the first edge engineering server in each normal time period, the number of second visiting users of the second edge engineering server in each normal time period, and the distance between the first edge engineering server and the second edge engineering server;

[0092] S502, calculating the average value of each local correlation degree to obtain the overall correlation degree between the first edge engineering server and the second edge engineering server;

[0093] S503: After dividing the overall correlation degree by the maximum value of each local correlation degree, an activation function operation is performed to obtain a server correlation index between the first edge engineering server and the second edge engineering server.

[0094] In this embodiment, the first number of access users is used to characterize the number of access users of the first edge engineering server in each normal time period, and the second number of access users is used to characterize the number of access users of the second edge engineering server in each normal time period. The first edge engineering server and the second edge engineering server are any two different edge engineering servers among the edge engineering servers.

[0095] The local correlation degree is used to characterize the local correlation degree between the first edge engineering server and the second edge engineering server in a normal time period, and the overall correlation degree is used to characterize the total correlation degree between the first edge engineering server and the second edge engineering server in each normal time period.

[0096] As an example, the server first obtains the number of first access users of the first edge engineering server in each normal time period and the number of second access users of the second edge engineering server in each normal time period. And uses correlation analysis (such as Pearson correlation coefficient, Spearman rank correlation coefficient, etc.) to calculate the correlation of the number of access users of the two servers in the same normal time period. And the distance between the first edge engineering server and the second edge engineering server is used as an adjustment factor to adjust the correlation of the number of access users of the two servers in the same normal time period, thereby obtaining the local correlation degree between the first edge engineering server and the second edge engineering server.

[0097] Then, the average value of the local correlation degrees of all normal time periods is calculated to obtain the overall correlation degree between the first edge engineering server and the second edge engineering server. Finally, the overall correlation degree is divided by the maximum value of each local correlation degree, and then the activation function is operated to obtain the server correlation index between the first edge engineering server and the second edge engineering server.

[0098] Through this embodiment, based on the number of users accessing each edge engineering server in a normal time period and the distance between each edge engineering server, the server association index between each edge engineering server can be accurately calculated. This helps to determine the abnormal index of each access user based on the server association index. Malicious users who initiate DDoS attacks can be accurately identified, improving the accuracy of identifying DDoS attacks.

[0099] As an optional embodiment, S501 may specifically include:

[0100] For each normal time period, perform the following steps respectively:

[0101] Obtaining the number of overlapping visiting users between the first number of visiting users and the second number of visiting users;

[0102] Multiplying the first number of access users, the second number of access users, and the distance between the first edge engineering server and the second edge engineering server to obtain a second calculation result;

[0103] The number of overlapping access users is divided by the second calculation result to obtain the local correlation degree between the first edge engineering server and the second edge engineering server.

[0104] In this embodiment, the number of overlapping access users is used to represent the number of access users who have accessed both the first edge engineering server and the second edge engineering server.

[0105] As an example, the local correlation degree between the first edge engineering server and the second edge engineering server may be specifically determined by the following formula 2:

[0106] Formula 2

[0107] In formula 2, Used to characterize the relationship between the i-th edge engineering server and the The local correlation degree of the edge engineering server in the jth normal time period, Used to characterize the relationship between the i-th edge engineering server and the The number of overlapping access users of an edge engineering server in the jth normal time period, To characterize the The number of users accessing the edge engineering server in the jth normal time period, It is used to characterize the number of users accessing the i-th edge engineering server in the j-th normal time period. To characterize the relationship between the i-th edge engineering server and the The distance between the edge engineering servers.

[0108] in, The larger the value, the more frequent the visits to the i-th edge engineering server and the i-th edge engineering server in a short time. The more users of the edge engineering server, the more The greater the degree of association between the edge engineering servers; The smaller the value, the closer the i-th edge engineering server is to the i-th edge engineering server. The smaller the distance between the edge engineering servers, the closer the distance between the i-th edge engineering server and the The greater the degree of association between the edge engineering servers.

[0109] Through this embodiment, according to the number of first access users of the first edge engineering server in each normal time period, the number of second access users of the second edge engineering server in each normal time period, and the distance between the first edge engineering server and the second edge engineering server, the local correlation degree between the first edge engineering server and the second edge engineering server in each normal time period can be accurately calculated. In this way, it is helpful to accurately evaluate the server correlation index between each edge engineering server and improve the accuracy of identifying DDoS attacks.

[0110] As an optional embodiment, S104 may specifically include:

[0111] Obtain the number of visits to the engineering logistics network by the target access user in the current access cycle, as well as each edge engineering server visited by the target access user;

[0112] Based on the number of visits and the server correlation index between the edge engineering servers visited by the target visit user, the abnormal index of the target visit user is determined.

[0113] In this embodiment, one access cycle corresponds to one first flow curve, and the current access cycle corresponds to the first flow curve at the current moment.

[0114] The number of visits is used to represent the total number of visits made by the target access user to the edge engineering server.

[0115] As an example, the abnormal index of the target access user can be determined by the following formula 3:

[0116] Formula 3

[0117] In formula 3, The abnormal index used to characterize the mth access user The number used to represent the z-1th visit of the mth user. The edge engineering server and the zth access The server correlation index between edge engineering servers, It is used to represent the number of visits of the mth visiting user in the current visiting cycle. The mean value of the abnormal possibility of the edge engineering server corresponding to each access behavior of the m-th access user in the corresponding time period is used to characterize the abnormal possibility. Specifically, for the edge engineering servers corresponding to each access behavior of the m-th access user, the abnormal possibility is calculated by the above formula 1 respectively, and then the mean value is processed to obtain the result. It is used to characterize the historical access frequency of the m-th access user. Specifically, it can be obtained by dividing the total duration of the last access cycle of the m-th access user by the number of visits in the last access cycle.

[0118] in, The larger the value is, the less the access behavior of the m-th access user in the current access cycle conforms to the normal rules, and the larger the abnormal index of the m-th access user is.

[0119] Through this embodiment, the target access user's abnormal index is accurately evaluated based on the number of visits to the engineering logistics network by the target access user in the current access cycle and the target access user's access server. In this way, the malicious user who launched the DDoS attack can be accurately identified based on the abnormal index, thereby improving the accuracy of identifying the DDoS attack.

[0120] As an optional embodiment, Figure 6 As shown, after S105, the DDoS attack monitoring method for industrial network devices may further include the following S601 to S603:

[0121] S601, determining the access priority of the target normal access user to each candidate server according to the abnormal possibility of each candidate server at the current moment and the server association index between each candidate server and the current access server of the target normal access user, the candidate server is used to represent the edge engineering server that the target normal access user can access at the next moment;

[0122] S602, determining the pheromone concentration of the access path corresponding to each candidate server according to the access priority of the target normal access user to each candidate server;

[0123] S603: Based on the pheromone concentration of each access path, determine the optimal access path for the target normal access user through an ant colony algorithm.

[0124] In this embodiment, the server first selects candidate servers that the target normal access user can access at the next moment based on the current access server of the target normal access user. For each candidate server, an access priority is comprehensively calculated based on its abnormal possibility at the current moment and its server association index with the current access server of the target normal access user.

[0125] Specifically, a weighted average method can be used to assign different weights to the abnormal possibility and the server association index, and the final access priority can be calculated based on the weights. The lower the abnormal possibility, the higher the access priority; the higher the server association index, the higher the access priority.

[0126] Then, according to the access priority of the target normal access user to each candidate server, the pheromone concentration of the access path corresponding to each candidate server is determined by the following formula 4:

[0127] Formula 4

[0128] In formula 4, Used to represent the candidate server corresponding to the mth access user at the current tth time The pheromone concentration of the corresponding access path, It is used to represent the candidate server of the mth access user at the end of the last access behavior (i.e., the z-1th access behavior). The historical pheromone concentration of the corresponding access path, Used to represent the mth access user's access to the candidate server at the current tth moment. The access priority.

[0129] Finally, create a certain number of virtual ants, each of which represents an explorer of a possible access path. Set the parameters of the ant colony algorithm, such as the number of ants, the number of iterations, etc. Each ant selects the next candidate server to be accessed according to the corresponding probability based on the pheromone concentration of each current access path. During the traversal process, the ant will update the pheromone concentration based on the path it has traveled, taking into account the volatilization and enhancement of pheromones. In this way, the above process is repeated until the preset number of iterations is reached or the preset stop condition is met. After the iteration is completed, the recorded optimal access path (that is, the path with the highest pheromone concentration) is output as the optimal access path for the target normal access user at the next moment.

[0130] Through this embodiment, the abnormal possibility of candidate servers and the server association index are comprehensively considered, and the intelligent search capability of the ant colony algorithm is used to determine an optimal access path for the target normal access users. In this way, the mobile path of the access users can be planned, thereby allocating the network load and reducing the interference of DDoS attacks on the normal operation of the engineering logistics network.

[0131] As an optional embodiment, S601 may specifically include:

[0132] Calculate the average value of the abnormal probability of the target candidate server in each time period to obtain the average value of the abnormal probability;

[0133] After multiplying the mean value of the abnormal possibility by the server association index between the target candidate server and the currently accessed server, the result is divided by the abnormal possibility of the target candidate server at the current moment to obtain the access priority of the target normal access user to the target candidate server.

[0134] In this embodiment, the access priority of the target normal access user to the target candidate server can be specifically determined by the following formula 5:

[0135] Formula 5

[0136] In formula 5, Used to represent the mth access user's access to the candidate server at the current tth moment. The access priority of Used to characterize candidate servers The average probability of abnormality in each time period, It is used to characterize the server association index between the edge engineering server i currently accessed by the mth access user and the candidate server x. Used to characterize candidate servers The probability of anomaly in the j-th time period at the current time t.

[0137] in, The larger the value, the more likely the candidate server is to The lower the access traffic in the current period, the more likely the target normal access users are to access the candidate server. The higher the access priority.

[0138] Through this embodiment, according to the abnormal possibility of each candidate server at the current moment, and the server association index between each candidate server and the current access server of the target normal access user, the access priority of the target normal access user to each candidate server can be accurately determined. In this way, the mobile path of the access user can be planned according to the access priority, thereby allocating the network load and reducing the interference of DDoS attacks on the normal operation of the engineering logistics network.

[0139] Based on the DDoS attack monitoring method for industrial network devices. Accordingly, the present invention also provides a specific embodiment of a DDoS attack monitoring system for industrial network devices.

[0140] Figure 7 A structural schematic diagram of a DDoS attack monitoring system for industrial network devices provided in an embodiment of the present application is shown. The DDoS attack monitoring system 700 for industrial network devices may include a curve acquisition module 710, a time period determination module 720, an association determination module 730, an anomaly determination module 740 and a user determination module 750.

[0141] The curve acquisition module 710 is used to acquire a first flow curve of each edge engineering server in the engineering logistics network, wherein the first flow curve includes flow sub-curves of multiple time periods;

[0142] A time period determination module 720, configured to determine a normal time period of each edge engineering server according to each first traffic curve;

[0143] The association determination module 730 is used to determine the server association index between the edge engineering servers according to the number of access users of each edge engineering server in a normal time period and the distance between the edge engineering servers;

[0144] The abnormality determination module 740 is used to determine the abnormality index of each access user according to the server association index between each edge engineering server;

[0145] The user determination module 750 is used to determine an access user whose abnormality index is greater than a preset abnormality threshold as a malicious user who initiates a DDoS attack.

[0146] In the DDoS attack monitoring system for industrial network equipment provided by the embodiment of the present invention, the normal time period of each edge engineering server is screened out according to the first flow curve of each edge engineering server in the engineering logistics network. Then, according to the number of access users of each edge engineering server in the normal time period and the distance between each edge engineering server, the server association index between each edge engineering server is determined. Then, according to the server association index between each edge engineering server, the abnormal index of each access user is determined, and the malicious user who initiates the DDoS attack is screened out according to the abnormal index. In this way, the present invention evaluates the abnormal index of the access user by comprehensively considering the server association index between each edge engineering server. It can avoid the interference caused by the sudden increase in traffic in the adjacent section during a certain period of time when a certain section is interrupted due to bad weather, overhaul and maintenance, etc. Therefore, the malicious user who initiates the DDoS attack can be accurately identified, and the accuracy of identifying the DDoS attack can be improved.

[0147] It should be clear that the present invention is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present invention.

[0148] It should also be noted that the exemplary embodiments mentioned in the present invention describe some methods or systems based on a series of steps or devices. However, the present invention is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiments, or in a different order from the embodiments, or several steps can be performed simultaneously.

[0149] The above is only a specific implementation of the present invention. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process of the system, module and unit described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here. It should be understood that the protection scope of the present invention is not limited to this. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed by the present invention, and these modifications or replacements should be covered within the protection scope of the present invention.

Claims

1. A DDoS attack monitoring method for industrial network equipment, characterized in that: The method comprises: Acquire a first flow curve of each edge engineering server in the engineering logistics network, wherein the first flow curve includes flow sub-curves of multiple time periods; Determining the normal time period of each edge engineering server according to each of the first traffic curves; Determine the server association index between the edge engineering servers according to the number of access users of each edge engineering server in a normal time period and the distance between the edge engineering servers; the distance is represented as the path between the edge engineering servers in the network topology node; Determining an abnormality index of each access user according to a server association index between each of the edge engineering servers; Determine the access user whose abnormal index is greater than the preset abnormal threshold as a malicious user who initiates the DDoS attack; Determining the server association index between the edge engineering servers according to the number of access users of the edge engineering servers in a normal time period and the distance between the edge engineering servers includes: Calculate the local association degree between the first edge engineering server and the second edge engineering server in each normal time period based on the number of first visiting users of the first edge engineering server in each normal time period, the number of second visiting users of the second edge engineering server in each normal time period, and the distance between the first edge engineering server and the second edge engineering server; Calculating an average value of each of the local correlation degrees to obtain an overall correlation degree between the first edge engineering server and the second edge engineering server; After dividing the overall correlation degree by the maximum value of each of the local correlation degrees, an activation function operation is performed to obtain a server correlation index between the first edge engineering server and the second edge engineering server; The calculating the local correlation degree between the first edge engineering server and the second edge engineering server in each normal time period based on the number of first visiting users of the first edge engineering server in each normal time period, the number of second visiting users of the second edge engineering server in each normal time period, and the distance between the first edge engineering server and the second edge engineering server includes: For each normal time period, perform the following steps respectively: Obtaining the number of overlapping visiting users between the first number of visiting users and the second number of visiting users; Multiplying the first number of access users, the second number of access users, and the distance between the first edge engineering server and the second edge engineering server to obtain a second calculation result; Dividing the number of overlapping access users by the second calculation result to obtain a local correlation degree between the first edge engineering server and the second edge engineering server; Determining the abnormality index of each access user according to the server association index between the edge engineering servers includes: Obtaining the number of visits to the engineering logistics network by the target access user in the current access cycle, and each of the edge engineering servers accessed by the target access user; Based on the number of visits and the server association indexes between the edge engineering servers visited by the target visiting user, an abnormality index of the target visiting user is determined.

2. The DDoS attack monitoring method for industrial network equipment according to claim 1 is characterized in that: The obtaining of the first flow curve of each edge engineering server in the engineering logistics network includes: Monitor each edge engineering server in the engineering logistics network to obtain the flow of each edge engineering server at each time; Based on the traffic of each edge engineering server at each time, respectively construct a second traffic curve of each edge engineering server; Each of the second flow curves is segmented from the flow extreme value point, and each segmented curve is determined as a flow sub-curve to constitute the first flow curve of each edge engineering server.

3. The DDoS attack monitoring method for industrial network equipment according to claim 1 is characterized in that: The determining the normal time period of each edge engineering server according to each of the first traffic curves includes: Acquire each flow sub-curve in a target first flow curve, wherein the target first flow curve is any one of the first flow curves; According to the flow at each moment in each flow sub-curve, respectively determine the abnormal possibility of the time period corresponding to each flow sub-curve; Each of the time periods in which the abnormal possibility is less than or equal to a preset possibility threshold is determined as a normal time period of the edge engineering server corresponding to the target first traffic curve.

4. The DDoS attack monitoring method for industrial network equipment according to claim 3 is characterized in that: The determining, according to the flow at each moment in each flow sub-curve, respectively the abnormal possibility of the time period corresponding to each flow sub-curve, comprises: Obtaining a first average flow of a target flow sub-curve and a second average flow of each first reference flow sub-curve, wherein the first reference flow sub-curve is a flow sub-curve of the edge engineering servers in the engineering logistics network, except for the target edge engineering server corresponding to the target flow sub-curve, within a time period corresponding to the target flow sub-curve; Determine the first reference flow sub-curve of each edge engineering server whose distance to the target edge engineering server is less than a preset distance threshold as a second reference flow sub-curve; multiplying the absolute value of the difference between the average value of the second average flow of each of the second reference flow sub-curves and the first average flow by the first average flow to obtain a first calculation result; The first calculation result is divided by the maximum value of each of the second average flow rates to obtain the abnormal possibility of the time period corresponding to the target flow sub-curve.

5. The DDoS attack monitoring method for industrial network equipment according to any one of claims 1 to 4, characterized in that: After determining that the access user whose abnormality index is greater than the preset abnormality threshold is a malicious user who initiates the DDoS attack, the method further includes: According to the abnormal possibility of each candidate server at the current moment and the server association index between each candidate server and the current access server of the target normal access user, the access priority of the target normal access user to each candidate server is determined, and the candidate server is used to represent the edge engineering server that the target normal access user can access at the next moment; Determining the pheromone concentration of the access path corresponding to each candidate server according to the access priority of the target normal access user to each candidate server; Based on the pheromone concentration of each access path, the optimal access path of the target normal access user is determined by an ant colony algorithm.

6. The DDoS attack monitoring method for industrial network equipment according to claim 5 is characterized in that: The step of determining the access priority of the target normal access user to each candidate server according to the abnormal possibility of each candidate server at the current moment and the server association index between each candidate server and the current access server of the target normal access user comprises: Calculate the average value of the abnormal probability of the target candidate server in each time period to obtain the average value of the abnormal probability; The access priority of the target normal access user to the target candidate server is obtained by multiplying the average abnormal possibility by the server association index between the target candidate server and the currently accessed server and dividing the result by the abnormal possibility of the target candidate server at the current moment.

7. A DDoS attack monitoring system for industrial network equipment, characterized in that: The system comprises: A curve acquisition module, used to acquire a first flow curve of each edge engineering server in the engineering logistics network, wherein the first flow curve includes flow sub-curves of multiple time periods; A time period determination module, used to determine the normal time period of each edge engineering server according to each of the first traffic curves; The association determination module is used to determine the server association index between each edge engineering server according to the number of access users of each edge engineering server in a normal time period and the distance between each edge engineering server, including: Calculate the local association degree between the first edge engineering server and the second edge engineering server in each normal time period based on the number of first visiting users of the first edge engineering server in each normal time period, the number of second visiting users of the second edge engineering server in each normal time period, and the distance between the first edge engineering server and the second edge engineering server; Calculating an average value of each of the local correlation degrees to obtain an overall correlation degree between the first edge engineering server and the second edge engineering server; After dividing the overall correlation degree by the maximum value of each of the local correlation degrees, an activation function operation is performed to obtain a server correlation index between the first edge engineering server and the second edge engineering server; The calculating the local correlation degree between the first edge engineering server and the second edge engineering server in each normal time period based on the number of first visiting users of the first edge engineering server in each normal time period, the number of second visiting users of the second edge engineering server in each normal time period, and the distance between the first edge engineering server and the second edge engineering server includes: For each normal time period, perform the following steps respectively: Obtaining the number of overlapping visiting users between the first number of visiting users and the second number of visiting users; Multiplying the first number of access users, the second number of access users, and the distance between the first edge engineering server and the second edge engineering server to obtain a second calculation result; Dividing the number of overlapping access users by the second calculation result to obtain a local correlation degree between the first edge engineering server and the second edge engineering server; The distance is represented as the path between edge engineering servers in the network topology node; The abnormality determination module is used to determine the abnormality index of each access user according to the server association index between the edge engineering servers, including: Obtaining the number of visits to the engineering logistics network by the target access user in the current access cycle, and each of the edge engineering servers accessed by the target access user; Determine the abnormal index of the target access user based on the number of accesses and the server association index between the edge engineering servers accessed by the target access user The user determination module is used to determine the access user whose abnormality index is greater than a preset abnormality threshold as a malicious user who initiates a DDoS attack.

Citation Information

Patent Citations

  • Method and system for monitoring DDOS (distributed denial of service) attacks in small flow

    CN102821081A

  • Intelligent control system and method based on big data

    CN114844703A