A method, device, equipment and medium for early warning

By calculating the traffic share and communication frequency of the network topology, detecting the traffic pressure value and betweenness centrality of the links, and generating alarm information, this solves the problem that existing technologies cannot effectively detect LFA attacks, and achieves efficient and accurate detection of LFA attacks and network security protection.

CN119602988BActive Publication Date: 2025-11-14CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411471967.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-21
Publication Date
2025-11-14
Estimated Expiration
2044-10-21

AI Technical Summary

Technical Problem

Existing technologies cannot effectively detect Link Flooding (LFA) attacks, resulting in a lack of network security guarantees.

Method used

By obtaining the traffic share and communication frequency of the network topology, the traffic pressure value and betweenness centrality of the links are calculated. The abnormal changes in the betweenness centrality calculation results are used to analyze potential LFA attack threats and generate alarm information.

Benefits of technology

It achieves efficient and accurate detection of LFA attacks, reduces the impact of malicious attacks on the network, and ensures the availability of services for users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119602988B_ABST
    Figure CN119602988B_ABST
Patent Text Reader

Abstract

This application relates to the field of network security technology, and in particular to an early warning method, apparatus, device, and medium. In embodiments of this application, an electronic device method is used to collect traffic data and topological connectivity of a target network topology, optimize existing BC algorithms to calculate the betweenness centrality of the target links, analyze potential LFA attack threats based on abnormal changes in the betweenness centrality calculation results of the target links, adjust network configurations to reduce the impact of malicious attacks for confirmed LFA attacks, and ensure service availability for users.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity technology, and in particular to an early warning method, device, equipment, and medium. Background Technology

[0002] With the development of IoT technology, attacks on IoT devices are also increasing. Besides traditional Distributed Denial of Service (DDoS) attacks, a new type of attack called Link Flooding Attack (LFA) is constantly threatening network security. Unlike traditional attack methods, LFA attacks target the bandwidth resources of links on the backbone network. Sometimes attackers divide their botnets into two parts, then control these botnets to communicate with each other on the other side of the link, sending and receiving large amounts of data. In this way, a large number of network packets pass through the targeted attack link on the backbone network, causing network congestion and latency.

[0003] Since LFA targets links rather than nodes, traditional attack detection methods cannot effectively detect LFA, thus failing to guarantee network security. Summary of the Invention

[0004] This application provides an early warning method, apparatus, device, and medium to address the problem that existing methods cannot effectively detect LFA, thus failing to guarantee network security.

[0005] In a first aspect, embodiments of this application provide an early warning method, the method comprising:

[0006] Obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency, and the preset weight value of each link in the target network topology;

[0007] Based on the traffic pressure value of each link, determine the total traffic pressure value corresponding to each short path in the target network topology; based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed, determine the target betweenness centrality corresponding to the target link in the current period.

[0008] If the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, an alarm message indicating that the target link has been attacked is generated.

[0009] Secondly, embodiments of this application also provide an early warning device, the device comprising:

[0010] The processing module is used to obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency, and the preset weight value of each link in the target network topology; determine the total traffic pressure value of each short path in the target network topology based on the traffic pressure value of each link; and determine the target betweenness centrality of the target link in the current period based on the total traffic pressure value of each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed.

[0011] The early warning module is used to generate an alarm message indicating that the target link has been attacked if the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold.

[0012] Thirdly, embodiments of this application also provide an electronic device, which includes at least a processor and a memory, wherein the processor is used to execute a computer program stored in the memory to implement the steps of any of the above-described warning methods.

[0013] Fourthly, embodiments of this application also provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the warning methods described above.

[0014] In this embodiment, the electronic device acquires the traffic percentage and network communication frequency of the target network topology in the current period; based on the traffic percentage, the network communication frequency, and the preset weight value corresponding to each link in the target network topology, it determines the traffic pressure value of each link in the current period; based on the traffic pressure value of each link, it determines the total traffic pressure value corresponding to each short path in the target network topology; based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed, it determines the target betweenness centrality corresponding to the target link in the current period; if the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, an alarm message indicating that the target link has been attacked is generated. In this embodiment, the electronic device collects traffic data and topology connection relationships of the target network topology, optimizes the existing BC algorithm to realize the betweenness centrality evaluation calculation of the target link, analyzes potential LFA attack threats based on abnormal changes in the betweenness centrality calculation results of the target link, adjusts network configuration to reduce the impact of malicious attacks for confirmed LFA attacks, and ensures the service availability of users. Attached Figure Description

[0015] To more clearly illustrate the technical solutions of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0016] Figure 1 A typical LFA attack diagram is provided for related technologies;

[0017] Figure 2 A schematic diagram of an early warning process provided in an embodiment of this application;

[0018] Figure 3 This is a schematic diagram of the target network topology provided in the embodiments of this application;

[0019] Figure 4 This is a flowchart illustrating the early warning process provided in an embodiment of this application.

[0020] Figure 5 This is a schematic diagram of the structure of an early warning device provided in an embodiment of this application;

[0021] Figure 6 This is a schematic diagram of an electronic device structure provided in an embodiment of this application. Detailed Implementation

[0022] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0023] The development of the Internet of Things (IoT) has been remarkable in recent years. Currently, the number of IoT devices worldwide has exceeded 20 billion and is still growing rapidly. These massive numbers of devices are relatively weak in terms of processing and memory resources. Furthermore, due to limitations in size and cost, manufacturers often focus more on the functionality of the devices themselves, neglecting security. This makes them vulnerable to hacking, allowing malicious programs to control these easily manipulated IoT devices and use them as botnets to launch DDoS attacks. Automated scripts can then be used to launch attacks against numerous targets across the network, including IoT devices. Therefore, security measures against DDoS attacks are urgently needed.

[0024] Besides traditional flooding DDoS attacks, the novel Link Flooding (LFA) attack is also threatening network security. Unlike traditional attack methods, LFA attacks target not the resources of servers acting as internet endpoints, but rather the bandwidth resources of links on the backbone network. Sometimes attackers divide their botnets into two parts, then control these botnets to communicate with every other botnet on the other side of the link, sending and receiving large amounts of data. This causes a large number of network packets to pass through the targeted attack link on the backbone network, resulting in network congestion and latency. Betweenness Centrality (BC) is a traditional method in graph theory that calculates the centrality of nodes to help network administrators identify critical nodes. However, researchers also point out that LFA attacks target links rather than nodes, therefore traditional BC cannot effectively detect LFA.

[0025] Figure 1 A typical LFA attack diagram is provided for related technologies, such as this Figure 1 As shown, an LFA attack blocks legitimate browsing transmissions by congesting one or more core target links, thus achieving a denial-of-service effect.

[0026] Based on this, in order to improve the efficiency and accuracy of early warning and realize early warning of FLA attacks, this application provides an early warning method, device, equipment and medium.

[0027] In this embodiment, the traffic percentage and network communication frequency of the target network topology in the current period are obtained; based on the traffic percentage, the network communication frequency, and the preset weight value corresponding to each link in the target network topology, the traffic pressure value of each link in the current period is determined; based on the traffic pressure value of each link, the total traffic pressure value corresponding to each short path in the target network topology is determined; based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed, the target betweenness centrality corresponding to the target link in the current period is determined; if the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, an alarm message indicating that the target link has been attacked is generated.

[0028] Figure 2 A schematic diagram of an early warning process provided in this application embodiment, the process including:

[0029] S201: Obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency and the preset weight value of each link in the target network topology.

[0030] An early warning method provided in this application is applied to an electronic device, which may be a PC or a server.

[0031] This application proposes a method for detecting link flooding attacks based on optimized link betweenness centrality, addressing the prevalence of DDoS attacks on the Internet and the lack of effective methods and theoretical guidance for detecting its new variant, LFA attack. This application collects and monitors network traffic data and topology connections based on graph theory algorithms, optimizes the existing BC algorithm to achieve incremental updates and link betweenness centrality assessment calculations, analyzes potential LFA attack threats based on abnormal changes in the betweenness centrality calculation results, and adjusts network configurations for confirmed LFA attacks to reduce the impact of malicious attacks and ensure service availability for users.

[0032] Furthermore, this application proposes a network monitoring and dynamic graph maintenance method that monitors the traffic data of communication links between nodes in real time, collects and calculates key topology data, and improves the real-time performance of subsequent analysis of the solution.

[0033] Specifically, the electronic device monitors the traffic in the target network topology to determine the traffic value and network communication frequency of the target network topology in the current period. Based on this traffic value and the pre-saved maximum supported communication bandwidth of the target network topology, it determines the traffic share of the target network topology in the current period. In other words, the electronic device determines the ratio of the traffic value to the maximum supported communication bandwidth and sets this ratio as the traffic share of the target network topology in the current period.

[0034] The current period refers to the time from the last detection of the target link to the current time.

[0035] After determining the traffic share and network communication frequency, the electronic device can determine the traffic pressure value of each link in the current period based on the traffic share, the network communication frequency, and the weight value corresponding to each link in the preset target network topology. Thus, it can determine whether it is under LFA attack based on the traffic pressure value.

[0036] S202: Based on the traffic pressure value of each link, determine the total traffic pressure value corresponding to each short path in the target network topology; based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed, determine the target betweenness centrality corresponding to the target link in the current period.

[0037] In practical applications, LFA attacks primarily exhaust bandwidth by sending long data packets or high-density traffic. Therefore, it is necessary to periodically statistically analyze the absolute traffic volume on each link. Furthermore, tools such as Sflow or Netflow are needed to periodically sample data packets, monitoring the network at a finer granular level and obtaining raw information about link status, providing a data foundation for subsequent functional modules. In addition, relevant methods and mechanisms are required for dynamic graph maintenance. Electronic devices can construct a connection relationship matrix between nodes to abstract the network topology, and automatically update this matrix using traffic monitoring tools or network discovery tools to maintain the latest connectivity of the network topology.

[0038] Based on this, in this embodiment, the electronic device determines the betweenness centrality of the target link to be detected based on traffic characteristics and connectivity, thereby optimizing the betweenness centrality. The traffic characteristics refer to the traffic pressure value of each link in the current period determined by the electronic device.

[0039] Betweenness centrality is one of the metrics for network topological centrality based on shortest paths. It primarily reflects a node's ability to act as a "bridge" or "mediator" in the network topology, that is, how frequently it acts as the shortest path between other nodes in the network topology.

[0040] Specifically, the electronic device determines the total traffic pressure value corresponding to each short path in the target network topology based on the traffic pressure value of each link, and determines the target betweenness centrality corresponding to the target link in the current period based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed.

[0041] In this embodiment, when determining the shortest path in a target network topology, the electronic device can construct a connection matrix based on the nodes and links in the target network topology, and determine the shortest path according to the connection matrix. Each row and column of the connection matrix corresponds to a node. If a link exists between two nodes, the value at the intersection of their row and column is 1; if no link exists between two nodes, the value at the intersection of their row and column is 0.

[0042] S203: If the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, an alarm message indicating that the target link has been attacked is generated.

[0043] In this embodiment of the application, the electronic device stores other betweenness centralities from the previous period in advance. The electronic device can determine whether the target link has been attacked based on the target betweenness centrality and the other betweenness centralities in the current period.

[0044] Specifically, if the electronic device determines that the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, it indicates that the traffic of the target link has surged in the current period. The electronic device determines that the target link has been attacked and generates and pushes an alarm message that the target link has been attacked.

[0045] In this embodiment of the application, the electronic device method collects traffic data and topological connection relationships of the target network topology, optimizes the existing BC algorithm to realize the betweenness centrality evaluation calculation of the target link, analyzes potential LFA attack threats based on abnormal changes in the betweenness centrality calculation results of the target link, and adjusts the network configuration to reduce the impact of malicious attacks for confirmed LFA attacks, thereby ensuring the service availability of users.

[0046] Example 2:

[0047] To improve the efficiency and accuracy of early warning and achieve early warning of FLA attacks, based on the above embodiments, in this embodiment, determining the traffic pressure value of each link in the current period according to the traffic proportion, the network communication frequency, and the preset weight value corresponding to each link in the target network topology includes:

[0048] For each link, a first parameter value is determined based on the traffic share, a second parameter value is determined based on the weight value corresponding to the link, and a third parameter value is determined based on the network communication frequency; the sum of the first parameter value, the second parameter value, and the third parameter value is determined as the traffic pressure value corresponding to the link.

[0049] In this embodiment, when determining the traffic pressure value corresponding to each link, the electronic device determines a first parameter based on the traffic proportion, a second parameter based on the weight value corresponding to the link, and a third parameter based on the network communication frequency. The electronic device then determines the traffic pressure value corresponding to that link by summing the first, second, and third parameter values.

[0050] Specifically, electronic devices can use the following formula to determine the traffic pressure value corresponding to each link:

[0051]

[0052] Where w(s,t) represents the traffic pressure value of the link connecting node s and node t, T represents the traffic value of the current period, and B max This indicates the maximum communication bandwidth supported by the target network topology. represents the traffic percentage, F represents the network communication frequency of the current period, Essential(s,t) represents the weight value corresponding to the link, and α, β and γ are preset normalization coefficients.

[0053] It should be noted that, in this embodiment of the application, the weight value corresponding to the link can be determined based on the function Essential, which defines the criticality of traffic services from node s to node t. This needs to be determined manually in advance by the administrator. F is the network communication frequency in the current period, and its logarithm is taken to obtain a more accurate evaluation result.

[0054] Example 3:

[0055] To improve the efficiency and accuracy of early warning and achieve early warning of FLA attacks, based on the above embodiments, in this embodiment, determining the total traffic pressure value corresponding to each shortest path in the target network topology based on the traffic pressure value of each link includes:

[0056] For each shortest path, determine each candidate link contained in the shortest path, and determine the candidate traffic pressure value corresponding to each candidate link; the sum of the candidate traffic pressure values ​​corresponding to each candidate link is determined as the total traffic pressure value of the shortest path.

[0057] In this embodiment of the application, the electronic device can determine the total traffic pressure value of the shortest path as the sum of the traffic pressure values ​​of the links contained in each shortest path.

[0058] Specifically, for each shortest path, the electronic device determines each candidate link included in that shortest path and determines the candidate traffic pressure value corresponding to each candidate link. The electronic device then determines the total traffic pressure value of the shortest path by summing the candidate traffic pressure values ​​corresponding to each candidate link.

[0059] Figure 3 This is a schematic diagram of the target network topology provided in the embodiments of this application, as shown below. Figure 3 As shown, the target network topology contains six nodes: Node1, Node2, Node3, Node4, Node5, and Node6. The traffic pressure value of link 1 connecting Node1 and Node2 is 1.5, the traffic pressure value of link 2 connecting Node3 and Node2 is 0.8, the traffic pressure value of link 3 connecting Node5 and Node2 is 2.5, the traffic pressure value of link 4 connecting Node4 and Node5 is 2.0, and the traffic pressure value of link 5 connecting Node5 and Node6 is 1.2.

[0060] Based on this, the electronic device can determine that the total traffic pressure value of the shortest path Node1-Node2-Node5-Node6 is 5.2, the total traffic pressure value of the shortest path Node1-Node2-Node5-Node4 is 6, the total traffic pressure value of the shortest path Node3-Node2-Node5 is 3.3, and the total traffic pressure value of the shortest path Node1-Node2-Node5 is 4.

[0061] Example 4:

[0062] To improve the efficiency and accuracy of early warning and achieve early warning of FLA attacks, based on the above embodiments, in this embodiment, determining the target betweenness centrality of the target link in the current period according to the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed includes:

[0063] For every two nodes, determine each candidate shortest path corresponding to those two nodes; based on the total traffic pressure value corresponding to each candidate shortest path, determine the node traffic pressure value between the two nodes; based on the number of sub-paths of each candidate shortest path and the target number of sub-paths of the candidate shortest path containing the target link; determine a first ratio between the target number of sub-paths and the number of sub-paths, and determine the product of the first ratio and the node traffic pressure value, and determine the product as the sub-between centrality;

[0064] The sum of the values ​​of each sub-between centrality is determined as the target betweenness centrality.

[0065] In this embodiment of the application, the electronic device determines the target betweenness centrality of the target link based on the total traffic pressure value corresponding to each shortest path, the number of shortest paths, and the number of targets that pass through the target link.

[0066] Specifically, for every two nodes in the target network topology, the electronics and devices determine each candidate shortest path corresponding to those two nodes; based on the total traffic pressure value corresponding to each candidate shortest path, they determine the node traffic pressure value between the two nodes; based on the number of sub-paths of each candidate shortest path and the target number of sub-paths containing the target link; they determine a first ratio of the target number of sub-paths to the total number of sub-paths, and determine the product of the first ratio and the node traffic pressure value, using this product as the sub-between centrality. The electronics and devices then determine the target betweenness centrality by summing the sub-between centralities in the target network topology.

[0067] The electronic device can use the following formula to determine the target betweenness centrality of the target link:

[0068]

[0069] Among them, C B (e) represents the objective betweenness centrality, W(s,t) represents the node flow pressure between node s and node t, and σ st σ represents the number of sub-paths of each candidate shortest path between node s and node t. st (e) represents the number of target sub-paths of the candidate shortest path containing the target link in each candidate shortest path between node s and node t. Indicates the first ratio. This indicates sub-between centrality.

[0070] It should be noted that in the embodiments of this application, W(s,t) is a comprehensive evaluation of the traffic on the path from node s to node t, including but not limited to the proportion of traffic to the maximum bandwidth of the link communication, service importance, communication frequency, etc.

[0071] To improve the efficiency and accuracy of early warning and achieve early warning of FLA attacks, based on the above embodiments, in this embodiment, determining the node traffic pressure value between two nodes according to the total traffic pressure value corresponding to each candidate shortest path includes:

[0072] Determine the mean of the total flow pressure value corresponding to each candidate shortest path;

[0073] The average value is determined as the node flow pressure value between the two nodes.

[0074] In this embodiment, there may be one or more candidate shortest paths between two nodes. If there is one candidate shortest path between the two nodes, the electronic device determines the total traffic pressure value corresponding to the candidate shortest path as the node traffic pressure value between the two nodes. If there are multiple candidate shortest paths between the two nodes, the electronic device determines the average of the total traffic pressure values ​​corresponding to each candidate shortest path and determines the average value as the node traffic pressure value between the two nodes.

[0075] Example 5:

[0076] To improve the efficiency and accuracy of early warning and achieve early warning of FLA attacks, based on the above embodiments, in this embodiment, if the difference between the target betweenness centrality and other betweenness centralities in the previous period does not exceed a preset threshold, the method further includes:

[0077] For each pair of nodes, obtain the historical number of historical shortest paths for each of the two nodes in the saved target network topology of the previous period, and the historical number of historical target paths containing the target link; determine a first ratio between the number of target paths containing the target link corresponding to the two nodes and the number of candidate shortest paths corresponding to the two nodes, and determine a second ratio between the historical number of target paths and the historical number of paths; determine the difference between the first ratio and the second ratio, and multiply the difference by the node traffic pressure value corresponding to the two nodes to determine the incremental sub-betweenness centrality corresponding to the two nodes;

[0078] The sum of the incremental betweenness centralities of every two child nodes is determined as the incremental betweenness centrality of the target link.

[0079] If the incremental betweenness centrality exceeds a preset incremental threshold, an alarm message indicating that the target link has been attacked is generated.

[0080] In related applications, attacks can also be launched against the target link by adding the shortest path that includes the target link, thereby consuming its bandwidth. Based on this, in this embodiment, the electronic device can also provide early warnings by detecting changes in the shortest path in the target network topology.

[0081] In this embodiment, the electronic device determines the incremental sub-betweenness centrality of every two nodes based on the shortest path of the current cycle and the historical shortest path of the previous cycle, thereby determining the incremental betweenness centrality of the target link, and then determining whether the target link has been attacked based on the incremental betweenness centrality and a preset incremental threshold.

[0082] Specifically, for each pair of nodes, the electronic device obtains the historical number of historical shortest paths for each of the two nodes in the target network topology of the previous period, as well as the historical number of historical target paths containing the target link; determines a first ratio between the number of target paths containing the target link for the two nodes and the number of candidate shortest paths for the two nodes, and determines a second ratio between the number of historical target paths and the number of historical paths; determines the difference between the first ratio and the second ratio, and determines the incremental sub-betweenness centrality of the two nodes by multiplying the difference by the node traffic pressure value corresponding to the two nodes.

[0083] The electronic device determines the incremental betweenness centrality of the target link by summing the incremental betweenness centralities of every two child nodes; if the incremental betweenness centrality exceeds a preset incremental threshold, the electronic device generates an alarm message indicating that the target link has been attacked.

[0084] The electronic device can determine the incremental betweenness centrality of the target link based on the following formula:

[0085]

[0086] Where, ΔC B (e) represents incremental betweenness centrality, and W(s,t) represents the node flow pressure value between node s and node t. This represents the number of sub-paths for each candidate shortest path between node s and node t. This represents the number of target sub-paths of the candidate shortest path containing the target link in each candidate shortest path between node s and node t. This represents the number of historical sub-paths for each historical candidate shortest path between node s and node t. This represents the number of historical target sub-paths included in each historical candidate shortest path between node s and node t. Indicates the first ratio. This represents the second ratio. This indicates the increment sub-between centrality.

[0087] In this embodiment of the application, if the network topology changes, then ΔC B (e) is not 0, which will affect the original C. B (e) k Update it. Furthermore, even if the network topology remains unchanged, W(s,t) will still be affected by real-time changes in traffic, reflecting traffic fluctuations.

[0088] Based on the above embodiments, in the embodiments of this application, if the flow rate does not change, the target betweenness centrality of the current period can also be expressed as: C B (e) k+1 =C B (e) k +ΔC B (e), where C B (e) k+1 C represents the target betweenness centrality of the current period. B (e) k Denotes other betweenness centralities in the previous period, ΔC B (e) denotes incremental betweenness centrality.

[0089] Example 6:

[0090] To improve the efficiency and accuracy of early warning and achieve early warning of FLA attacks, based on the above embodiments, the method in this application embodiment further includes:

[0091] Based on the preset routing configuration information, the target link is switched to the preset backup link.

[0092] In this embodiment of the application, after the electronic device generates an alarm message that the target link has been attacked, in order to ensure network security, the electronic device will switch the target link to a preset backup link according to the preset routing configuration information.

[0093] In this embodiment, when the betweenness centrality of a target link changes significantly before and after a certain period update, the electronic device determines that the target link is abnormal. A threshold can be introduced to evaluate the difference in change. The threshold is obtained by training through accumulating normal fluctuations and normal link switching over multiple periods during normal network testing. This enables automatic assessment of the importance of a link and its likelihood of becoming an attack target, improving detection accuracy. Once an anomaly is detected, the electronic device generates a real-time alert, providing detailed information about the threatened or important link, including the magnitude of the abnormal fluctuation, the types of services that may be affected, and the specific degree of traffic change.

[0094] To address detected LFA attacks, the network links need to be adjusted based on the analysis results. Firstly, when the primary link is attacked or fails, the system should automatically switch to a predefined backup link. Secondly, firewall policies need to be adjusted according to the analyzed attack information to filter attack traffic in the network. Furthermore, during normal operation, this module also needs to periodically allocate and check backup links, update firewall policies, and set up necessary blocking rules.

[0095] To make the method of this application clearer, the steps for detecting link flooding attacks using the optimized link betweenness centrality method are described in detail. Figure 3 Taking the target network topology and traffic pressure distribution as an example, an embodiment is as follows:

[0096] Step 101:

[0097] Monitor the traffic status of each link within the target network topology to obtain the connectivity relationships between nodes. For example, the connectivity matrix might look like this:

[0098]

[0099] Step 102:

[0100] Calculate the number of shortest paths between any two nodes based on the maximum bandwidth of each link. Also calculate the number of shortest paths through a given link. The numbers shown in the diagram represent the traffic pressure value w(s,t) of the link between two adjacent nodes. The total traffic pressure value W(s,t) between non-connected nodes can be obtained by adding them together. For example, the shortest path from Node1 to Node3 is: Node1-Node2-Node3 (total traffic pressure value: 2.3), and the shortest path from Node3 to Node1 is: Node3-Node2-Node1 (total traffic pressure value: 2.3).

[0101] Step 103:

[0102] Substitute each w(s,t) into the optimized betweenness centrality calculation method. Taking the target link Node2-Node5 as an example, all paths arriving at or originating from Node2 and Node5 will pass through this target link, including: Node1 to Node4, Node1 to Node6, Node3 to Node6, and Node3 to Node4. The sums of traffic pressure for these four shortest paths are 6.0, 5.2, 5.3, and 4.5, respectively. Based on this, the target betweenness centrality of the target link can be determined:

[0103] C B (Node2-Node5)

[0104] =W(Node1,Node4)+W(Node1,Node6)+W(Node3,Node4)

[0105] +W(Node3,Node6) = 21

[0106] This is a specific example of all link evaluations. In actual use, each link is calculated periodically, but apart from the first calculation, subsequent calculations are lightweight incremental calculations performed in response to changes.

[0107] Step 104:

[0108] If an attacker launches an LFA attack targeting Node2-Node5 of the target link at this time, the target link will undergo significant changes, such as C. B (Node2-Node5) is further increased, for example, by 10. The maximum threshold for normal fluctuations is 5. Therefore, it can be determined that an LFA attack has occurred, and a real-time alarm is generated, indicating the specific link that encountered the LFA attack, as well as the specific composition of the link W(s,t) at this time.

[0109] Step 105:

[0110] Select the corresponding backup disaster recovery link for the link that has suffered an LFA attack, and switch a portion of the traffic to it to alleviate and distribute the traffic pressure. Simultaneously, implement corresponding firewall policies and blocking rules based on the information in W(s,t) and the information from periodic traffic packet sampling.

[0111] Figure 4 This is a schematic diagram of the early warning process provided in the embodiments of this application, as shown below. Figure 4 As shown, the process includes:

[0112] Step S401: Monitor the traffic status of each link in the network and obtain the connection relationship between nodes.

[0113] Step S404: Calculate the total number of shortest paths between any two nodes, and calculate the number of shortest paths passing through each link.

[0114] Step S403: Calculate w(s,t) for each shortest path and substitute it into the formula to calculate the betweenness centrality C. B .

[0115] Step S404: Evaluate the results and fluctuation magnitude, compare the results for anomalies, and if no LFA attack has occurred, return to step S401.

[0116] Step S405: If an LFA attack occurs, automatically switch to a predefined backup link based on the attacked link's number. Simultaneously, adjust firewall policies accordingly to filter attack traffic from the network.

[0117] This application proposes a method for detecting link flooding attacks based on optimized link betweenness centrality. To address the rampant DDoS attacks on the current Internet and the lack of effective methods and theoretical guidance for detecting its new variant, LFA (Link Flooding Attack), this application collects and monitors network traffic data and topology connections based on graph theory algorithms. It optimizes the existing BC (Browser-Browser) algorithm to achieve incremental updates and link betweenness centrality assessment calculations. Based on abnormal changes in the betweenness centrality calculation results, it analyzes potential LFA attack threats. For confirmed LFA attacks, it adjusts network configurations to reduce the impact of malicious attacks and ensure service availability for users.

[0118] This application proposes a network monitoring and dynamic graph maintenance method, which monitors the traffic data of communication links between nodes in real time, collects and calculates key topology data, and improves the real-time performance of subsequent analysis. It also proposes a dynamic link betweenness centrality calculation method, optimizing and improving the traditional node betweenness centrality calculation method to accurately assess key communication links in the network and support incremental updates, providing data support and lightweight attributes for identifying potential attack targets. Furthermore, it proposes a link threat analysis and alarm method, which automatically assesses the importance of links and their likelihood of becoming attack targets based on the betweenness centrality calculation results, improving the detection accuracy of the solution. Finally, it proposes a network adaptive adjustment method, which responds promptly when the network is confirmed to be under an LFA attack, adjusting routing configurations according to pre-prepared plans and activating backup communication links, improving the integrity and robustness of the solution.

[0119] Based on this, the embodiments of this application can quickly and accurately detect LFA attacks in existing Internet scenarios, according to the network topology and traffic characteristics of the defense location, and adjust the routing configuration according to the LFA attack, thereby reducing the effect of the LFA attack while ensuring the availability of user services.

[0120] Compared with the prior art, the embodiments of this application have the following advantages:

[0121] 1. This application provides a network monitoring and dynamic graph maintenance method, which can monitor the traffic data of communication links between nodes in real time, collect and calculate key topology data, and improve the real-time performance of subsequent analysis of the solution.

[0122] 2. The embodiments of this application provide a dynamic link betweenness centrality calculation method, which can optimize and improve the traditional node betweenness centrality calculation method, enabling it to accurately evaluate key communication links in the network and support incremental updates, providing data support and lightweight attributes for identifying potential attack targets;

[0123] 3. The embodiments of this application provide a link threat analysis and alarm method, which can automatically assess the importance of the link and the possibility of it becoming an attack target based on the calculation results of betweenness centrality, thereby improving the detection accuracy of the solution;

[0124] 4. The embodiments of this application provide a network adaptive adjustment method, which can respond in a timely manner when the network is confirmed to be encountering an LFA attack, adjust the routing configuration according to the pre-prepared plan, activate the backup communication link, and improve the integrity and robustness of the solution.

[0125] Example 7:

[0126] Based on the above embodiments, Figure 5 This application provides a schematic diagram of a warning device structure, which includes:

[0127] Processing module 501 is used to obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency, and the preset weight value of each link in the target network topology; determine the total traffic pressure value of each short path in the target network topology based on the traffic pressure value of each link; and determine the target betweenness centrality of the target link in the current period based on the total traffic pressure value of each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed.

[0128] The early warning module 502 is used to generate an alarm message indicating that the target link has been attacked if the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold.

[0129] In one possible implementation, the processing module 501 is specifically used to determine a first parameter value based on the traffic ratio, a second parameter value based on the weight value corresponding to the link, and a third parameter value based on the network communication frequency for each link; and to determine the sum of the first parameter value, the second parameter value, and the third parameter value as the traffic pressure value corresponding to the link.

[0130] In one possible implementation, the processing module 501 is specifically configured to, for each shortest path, determine each candidate link contained in the shortest path, and determine the candidate traffic pressure value corresponding to each candidate link; and determine the sum of the candidate traffic pressure values ​​corresponding to each candidate link as the total traffic pressure value of the shortest path.

[0131] In one possible implementation, the processing module 501 is specifically configured to: determine each candidate shortest path corresponding to each pair of nodes; determine the node traffic pressure value between the two nodes based on the total traffic pressure value corresponding to each candidate shortest path; determine the target number of sub-paths and the target number of sub-paths containing the target link based on the number of sub-paths of each candidate shortest path; determine a first ratio between the target number of sub-paths and the number of sub-paths, and determine the product of the first ratio and the node traffic pressure value, and determine the product as the sub-betweenness centrality; and determine the sum of each sub-betweenness centrality as the target betweenness centrality.

[0132] In one possible implementation, the processing module 501 is specifically used to determine the average value of the total flow pressure value corresponding to each candidate shortest path; and to determine the average value as the node flow pressure value between the two nodes.

[0133] In one possible implementation, the processing module 501 is further configured to: if the difference between the target betweenness centrality and other betweenness centralities of the previous period does not exceed a preset threshold, then for each pair of nodes, obtain the historical number of historical shortest paths for each pair of nodes in the saved target network topology of the previous period, and the historical number of historical target shortest paths containing the target link; determine a first ratio between the number of target shortest paths containing the target link corresponding to the two nodes and the number of candidate shortest paths corresponding to the two nodes, and determine a second ratio between the historical number of target shortest paths and the historical number of shortest paths; determine the difference between the first ratio and the second ratio, and determine the incremental betweenness centrality corresponding to the two nodes by multiplying the difference by the node traffic pressure value corresponding to the two nodes; and determine the sum of the incremental betweenness centralities corresponding to each pair of nodes as the incremental betweenness centrality of the target link.

[0134] The early warning module 502 is also used to generate an alarm message indicating that the target link has been attacked if the incremental betweenness centrality exceeds a preset incremental threshold.

[0135] In one possible implementation, the processing module 501 is further configured to switch the target link to a preset backup link according to preset routing configuration information.

[0136] Example 8:

[0137] Based on the above embodiments, this application also provides an electronic device. Figure 6 This application provides a schematic diagram of an electronic device structure, such as... Figure 6 As shown, it includes: processor 601, communication interface 602, memory 603 and communication bus 604, wherein processor 601, communication interface 602 and memory 603 communicate with each other through communication bus 604.

[0138] The memory 603 stores a computer program, which, when executed by the processor 601, causes the processor 601 to perform the following steps:

[0139] Obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency, and the preset weight value of each link in the target network topology;

[0140] Based on the traffic pressure value of each link, determine the total traffic pressure value corresponding to each short path in the target network topology; based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed, determine the target betweenness centrality corresponding to the target link in the current period.

[0141] If the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, an alarm message indicating that the target link has been attacked is generated.

[0142] In one possible implementation, determining the traffic pressure value of each link in the current period based on the traffic share, the network communication frequency, and the preset weight value corresponding to each link in the target network topology includes:

[0143] For each link, a first parameter value is determined based on the traffic share, a second parameter value is determined based on the weight value corresponding to the link, and a third parameter value is determined based on the network communication frequency; the sum of the first parameter value, the second parameter value, and the third parameter value is determined as the traffic pressure value corresponding to the link.

[0144] In one possible implementation, determining the total traffic pressure value corresponding to each shortest path in the target network topology based on the traffic pressure value of each link includes:

[0145] For each shortest path, determine each candidate link contained in the shortest path, and determine the candidate traffic pressure value corresponding to each candidate link; the sum of the candidate traffic pressure values ​​corresponding to each candidate link is determined as the total traffic pressure value of the shortest path.

[0146] In one possible implementation, determining the target betweenness centrality of the target link in the current period based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed includes:

[0147] For every two nodes, determine each candidate shortest path corresponding to those two nodes; based on the total traffic pressure value corresponding to each candidate shortest path, determine the node traffic pressure value between the two nodes; based on the number of sub-paths of each candidate shortest path and the target number of sub-paths of the candidate shortest path containing the target link; determine a first ratio between the target number of sub-paths and the number of sub-paths, and determine the product of the first ratio and the node traffic pressure value, and determine the product as the sub-between centrality;

[0148] The sum of the values ​​of each sub-between centrality is determined as the target betweenness centrality.

[0149] In one possible implementation, determining the node traffic pressure value between the two nodes based on the total traffic pressure value corresponding to each candidate shortest path includes:

[0150] Determine the mean of the total flow pressure value corresponding to each candidate shortest path;

[0151] The average value is determined as the node flow pressure value between the two nodes.

[0152] In one possible implementation, if the difference between the target betweenness centrality and other betweenness centralities in the previous period does not exceed a preset threshold, the method further includes:

[0153] For each pair of nodes, obtain the historical number of historical shortest paths for each of the two nodes in the saved target network topology of the previous period, and the historical number of historical target paths containing the target link; determine a first ratio between the number of target paths containing the target link corresponding to the two nodes and the number of candidate shortest paths corresponding to the two nodes, and determine a second ratio between the historical number of target paths and the historical number of paths; determine the difference between the first ratio and the second ratio, and multiply the difference by the node traffic pressure value corresponding to the two nodes to determine the incremental sub-betweenness centrality corresponding to the two nodes;

[0154] The sum of the incremental betweenness centralities of every two child nodes is determined as the incremental betweenness centrality of the target link.

[0155] If the incremental betweenness centrality exceeds a preset incremental threshold, an alarm message indicating that the target link has been attacked is generated.

[0156] In one possible implementation, the method further includes:

[0157] Based on the preset routing configuration information, the target link is switched to the preset backup link.

[0158] Since the principle of the above-mentioned electronic device in solving the problem is similar to that of the early warning method, the implementation of the above-mentioned electronic device can be found in the embodiments of the method, and repeated parts will not be described again.

[0159] The communication bus mentioned in the above-mentioned electronic device can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used in the figure, but this does not indicate that there is only one bus or one type of bus. Communication interface 602 is used for communication between the above-mentioned electronic device and other devices. The memory can include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory can also be at least one storage device located remotely from the aforementioned processor.

[0160] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0161] Example 9:

[0162] Based on the above embodiments, this invention also provides a computer-readable storage medium storing a computer program executable by a processor. When the program is run on the processor, it causes the processor to perform the following steps:

[0163] Obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency, and the preset weight value of each link in the target network topology;

[0164] Based on the traffic pressure value of each link, determine the total traffic pressure value corresponding to each short path in the target network topology; based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed, determine the target betweenness centrality corresponding to the target link in the current period.

[0165] If the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, an alarm message indicating that the target link has been attacked is generated.

[0166] In one possible implementation, determining the traffic pressure value of each link in the current period based on the traffic share, the network communication frequency, and the preset weight value corresponding to each link in the target network topology includes:

[0167] For each link, a first parameter value is determined based on the traffic share, a second parameter value is determined based on the weight value corresponding to the link, and a third parameter value is determined based on the network communication frequency; the sum of the first parameter value, the second parameter value, and the third parameter value is determined as the traffic pressure value corresponding to the link.

[0168] In one possible implementation, determining the total traffic pressure value corresponding to each shortest path in the target network topology based on the traffic pressure value of each link includes:

[0169] For each shortest path, determine each candidate link contained in the shortest path, and determine the candidate traffic pressure value corresponding to each candidate link; the sum of the candidate traffic pressure values ​​corresponding to each candidate link is determined as the total traffic pressure value of the shortest path.

[0170] In one possible implementation, determining the target betweenness centrality of the target link in the current period based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed includes:

[0171] For every two nodes, determine each candidate shortest path corresponding to those two nodes; based on the total traffic pressure value corresponding to each candidate shortest path, determine the node traffic pressure value between the two nodes; based on the number of sub-paths of each candidate shortest path and the target number of sub-paths of the candidate shortest path containing the target link; determine a first ratio between the target number of sub-paths and the number of sub-paths, and determine the product of the first ratio and the node traffic pressure value, and determine the product as the sub-between centrality;

[0172] The sum of the values ​​of each sub-between centrality is determined as the target betweenness centrality.

[0173] In one possible implementation, determining the node traffic pressure value between the two nodes based on the total traffic pressure value corresponding to each candidate shortest path includes:

[0174] Determine the mean of the total flow pressure value corresponding to each candidate shortest path;

[0175] The average value is determined as the node flow pressure value between the two nodes.

[0176] In one possible implementation, if the difference between the target betweenness centrality and other betweenness centralities in the previous period does not exceed a preset threshold, the method further includes:

[0177] For each pair of nodes, obtain the historical number of historical shortest paths for each of the two nodes in the saved target network topology of the previous period, and the historical number of historical target paths containing the target link; determine a first ratio between the number of target paths containing the target link corresponding to the two nodes and the number of candidate shortest paths corresponding to the two nodes, and determine a second ratio between the historical number of target paths and the historical number of paths; determine the difference between the first ratio and the second ratio, and multiply the difference by the node traffic pressure value corresponding to the two nodes to determine the incremental sub-betweenness centrality corresponding to the two nodes;

[0178] The sum of the incremental betweenness centralities of every two child nodes is determined as the incremental betweenness centrality of the target link.

[0179] If the incremental betweenness centrality exceeds a preset incremental threshold, an alarm message indicating that the target link has been attacked is generated.

[0180] In one possible implementation, the method further includes:

[0181] Based on the preset routing configuration information, the target link is switched to the preset backup link.

[0182] Since the principles behind the problem-solving and early warning methods of the aforementioned computer program products are similar, the implementation of the aforementioned computer program products can be found in the implementation of the methods, and the repetitive parts will not be repeated.

[0183] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0184] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0185] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0186] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0187] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. An early warning method, characterized in that, The method includes: Obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency, and the preset weight value of each link in the target network topology; Based on the traffic pressure value of each link, determine the total traffic pressure value corresponding to each shortest path in the target network topology; based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed, determine the target betweenness centrality corresponding to the target link in the current period. If the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold, an alarm message indicating that the target link has been attacked is generated. The step of determining the target betweenness centrality of the target link in the current period based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed includes: For every two nodes, determine each candidate shortest path corresponding to those two nodes; based on the total traffic pressure value corresponding to each candidate shortest path, determine the node traffic pressure value between the two nodes; based on the number of sub-paths of each candidate shortest path and the target number of sub-paths of the candidate shortest path containing the target link; determine a first ratio between the target number of sub-paths and the number of sub-paths, and determine the product of the first ratio and the node traffic pressure value, and determine the product as the sub-between centrality; The sum of the values ​​of each sub-between centrality is determined as the target betweenness centrality.

2. The method according to claim 1, characterized in that, The step of determining the traffic pressure value of each link in the current period based on the traffic proportion, the network communication frequency, and the preset weight value corresponding to each link in the target network topology includes: For each link, a first parameter value is determined based on the traffic share, a second parameter value is determined based on the weight value corresponding to the link, and a third parameter value is determined based on the network communication frequency; the sum of the first parameter value, the second parameter value, and the third parameter value is determined as the traffic pressure value corresponding to the link.

3. The method according to claim 1, characterized in that, The step of determining the total traffic pressure value corresponding to each shortest path in the target network topology based on the traffic pressure value of each link includes: For each shortest path, determine each candidate link contained in the shortest path, and determine the candidate traffic pressure value corresponding to each candidate link; the sum of the candidate traffic pressure values ​​corresponding to each candidate link is determined as the total traffic pressure value of the shortest path.

4. The method according to claim 1, characterized in that, The step of determining the node traffic pressure value between the two nodes based on the total traffic pressure value corresponding to each candidate shortest path includes: Determine the mean of the total flow pressure value corresponding to each candidate shortest path; The average value is determined as the node flow pressure value between the two nodes.

5. The method according to claim 1, characterized in that, If the difference between the target betweenness centrality and other betweenness centralities in the previous period does not exceed a preset threshold, the method further includes: For each pair of nodes, obtain the historical number of historical shortest paths for each of the two nodes in the saved target network topology of the previous period, and the historical number of historical target paths containing the target link; determine a first ratio between the number of target paths containing the target link corresponding to the two nodes and the number of candidate shortest paths corresponding to the two nodes, and determine a second ratio between the historical number of target paths and the historical number of paths; determine the difference between the first ratio and the second ratio, and multiply the difference by the node traffic pressure value corresponding to the two nodes to determine the incremental sub-betweenness centrality corresponding to the two nodes; The sum of the incremental betweenness centralities of every two child nodes is determined as the incremental betweenness centrality of the target link. If the incremental betweenness centrality exceeds a preset incremental threshold, an alarm message indicating that the target link has been attacked is generated.

6. The method according to claim 1 or 5, characterized in that, The method further includes: Based on the preset routing configuration information, the target link is switched to the preset backup link.

7. An early warning device, characterized in that, The device includes: The processing module is used to obtain the traffic percentage and network communication frequency of the target network topology in the current period; determine the traffic pressure value of each link in the current period based on the traffic percentage, the network communication frequency, and the preset weight value of each link in the target network topology; determine the total traffic pressure value corresponding to each shortest path in the target network topology based on the traffic pressure value of each link; and determine the target betweenness centrality of the target link in the current period based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed. The early warning module is used to generate an alarm message that the target link is under attack if the difference between the target betweenness centrality and other betweenness centralities in the previous period exceeds a preset threshold. The step of determining the target betweenness centrality of the target link in the current period based on the total traffic pressure value corresponding to each shortest path, the number of each shortest path, and the target number of shortest paths passing through the target link to be processed includes: For every two nodes, determine each candidate shortest path corresponding to those two nodes; based on the total traffic pressure value corresponding to each candidate shortest path, determine the node traffic pressure value between the two nodes; based on the number of sub-paths of each candidate shortest path and the target number of sub-paths of the candidate shortest path containing the target link; determine a first ratio between the target number of sub-paths and the number of sub-paths, and determine the product of the first ratio and the node traffic pressure value, and determine the product as the sub-between centrality; The sum of the values ​​of each sub-between centrality is determined as the target betweenness centrality.

8. An electronic device, characterized in that, The electronic device includes at least a processor and a memory, wherein the processor is used to implement the steps of the early warning method as described in any one of claims 1-6 when executing a computer program stored in the memory.

9. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the steps of the early warning method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Network path selection method and device, equipment and storage medium

    CN114298431A

  • Network path analysis system and method for network security anomaly detection

    CN116232774A