Network Attack Protection Method, Device, Equipment, Storage Medium and Program Product
By implementing a network attack protection method in load balancing equipment, using the protection policy configuration file to quickly identify abnormal traffic and perform protection processing, the problem of poor timeliness of network attack protection in the existing technology is solved, and efficient and comprehensive protection of network attacks inside and outside the cloud platform is achieved.
Patent Information
- Application Number
- CN202510157818.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-02-13
AI Technical Summary
The current technology has poor timeliness in the protection of network attacks on cloud platforms, mainly due to the large delay in detecting traffic by anti-attack devices, which leads to the inability to respond to network attacks quickly.
Implement a network attack protection method in a load balancing device. By obtaining the current operating characteristics of the load balancing device, if the target attack operation characteristics are met, abnormal traffic will be determined in the received traffic and the protection process will be performed. This method uses the protection policy profile of the load balancing device to quickly identify and deal with abnormal traffic.
By implementing this method on load balancing devices, it is possible to quickly identify and respond to network attacks, reduce detection delays, improve the timeliness of network attack protection, and provide comprehensive and effective protection for network attacks from inside and outside the cloud platform.
Smart Images

Figure CN119652664B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing, and in particular, to a method, apparatus, device, storage medium, and program product for network attack protection. Background Art
[0002] In the Internet, cloud platforms may be subject to network attacks, so network attack protection is required.
[0003] In the related art, anti-attack devices are usually set at the entrance of the cloud platform, and the anti-attack devices detect and filter the traffic from outside the cloud platform to achieve network attack protection. However, in the above method, all the traffic entering and leaving the cloud platform must be detected and filtered by the anti-attack device, and the detection delay of the anti-attack device for the traffic is large, resulting in poor timeliness of network attack protection. Summary of the Invention
[0004] Multiple aspects of this application provide a method, apparatus, device, storage medium, and program product for network attack protection to solve the problem of poor timeliness of network attack protection.
[0005] In a first aspect, an embodiment of this application provides a method for network attack protection, which is applied to a load balancing device. The method includes:
[0006] Obtain the current operating characteristics of the load balancing device;
[0007] If the current operating characteristics conform to the target attack operating characteristics, determine current abnormal traffic in at least one current traffic received by the load balancing device, and perform protection processing on the current abnormal traffic. The target attack operating characteristics are any one of at least one attack operating characteristic in at least one attack scenario.
[0008] In a possible implementation manner, a protection policy configuration file is included in the load balancing device. Determining current abnormal traffic in at least one current traffic received by the load balancing device includes:
[0009] In the at least one attack scenario, determine the target attack scenario corresponding to the target attack operating characteristics;
[0010] Determine the target abnormal traffic characteristics in the protection policy configuration file for the target attack scenario;
[0011] According to the target abnormal traffic characteristics, determine the current abnormal traffic in the at least one current traffic.
[0012] In a possible implementation manner, performing protection processing on the current abnormal traffic includes:
[0013] Determining a target protection strategy corresponding to the target abnormal traffic feature in the protection strategy configuration file;
[0014] According to the target protection strategy, protection processing is performed on the current abnormal traffic.
[0015] In a possible implementation, the method further includes:
[0016] If the current running feature does not match any attack running feature, determining whether there is an enabled protection strategy in the protection strategy configuration file;
[0017] If it exists, the enabled protection strategy is deleted, and load balancing is performed on the at least one current flow;
[0018] If not, load balancing is performed on the at least one current flow.
[0019] In a possible implementation, the method further includes:
[0020] In the protection strategy configuration file, determining a protection switch state, wherein the protection switch state is used to indicate whether protection is turned on;
[0021] When the protection switch state is in the on state, at least one attack operation feature of the load balancing device in at least one attack scenario is obtained.
[0022] In a possible implementation, the method further includes:
[0023] When the protection switch state is in the closed state, load balancing processing is performed on the at least one current flow.
[0024] In a possible implementation, the method further includes:
[0025] After determining the current abnormal traffic, recording the five-tuple information of the current abnormal traffic in the abnormal traffic log; and / or,
[0026] After the current operation characteristics are restored to normal operation characteristics, the target protection strategy is released and a protection log is generated, wherein the protection log is used to record information on the protection processing performed on the current abnormal traffic.
[0027] In a possible implementation, obtaining the current operating characteristics of the load balancing device includes:
[0028] Obtaining operation information of the load balancing device within a preset time period before the current moment;
[0029] According to the operation information, current operation characteristics of the load balancing device are determined.
[0030] In a possible implementation, the at least one current traffic includes internal traffic of the cloud platform and external traffic of the cloud platform.
[0031] In a second aspect, an embodiment of the present application provides a network attack protection system, which is set in a load balancing device, and the system is used to execute the method described in any item of the first aspect.
[0032] In a third aspect, an embodiment of the present application provides a cloud platform, which includes a management and control device and at least one load balancing device, wherein,
[0033] The management and control device is used to configure a protection policy configuration file for the load balancing device;
[0034] The load balancing device is provided with the network attack protection system as described in the second aspect.
[0035] In a fourth aspect, an embodiment of the present application provides a network attack protection device, which is applied to a load balancing device, and the device includes: a first acquisition module and a protection module, wherein,
[0036] The first acquisition module is used to acquire the current operation characteristics of the load balancing device;
[0037] The protection module is used to, if the current operation characteristics conform to the target attack operation characteristics, determine current abnormal traffic in at least one current traffic received by the load balancing device, and perform protection processing on the current abnormal traffic, where the target attack operation characteristics are any one of at least one attack operation characteristics in at least one attack scenario.
[0038] In a possible implementation, the load balancing device includes a protection policy configuration file; the protection module is specifically used for:
[0039] In the at least one attack scenario, determine the target attack scenario corresponding to the target attack operation characteristics;
[0040] Determine the target abnormal traffic characteristics in the protection policy configuration file under the target attack scenario;
[0041] According to the target abnormal traffic characteristics, determine the current abnormal traffic in the at least one current traffic.
[0042] In a possible implementation, the protection module is specifically used for:
[0043] Determine the target protection policy corresponding to the target abnormal traffic characteristics in the protection policy configuration file;
[0044] According to the target protection strategy, protection processing is performed on the current abnormal traffic.
[0045] In a possible implementation, the device further includes: a determination module, a deletion module and a load balancing module, wherein:
[0046] The determination module is used to determine whether there is an enabled protection strategy in the protection strategy configuration file if the current operation feature does not meet any attack operation feature;
[0047] The deletion module is used to delete the enabled protection strategy if it exists;
[0048] The load balancing module is used to perform load balancing processing on the at least one current flow;
[0049] The load balancing module is also used to, if it does not exist, perform load balancing processing on the at least one current flow.
[0050] In a possible implementation manner, the device further includes a second acquisition module, where the second acquisition module is configured to:
[0051] In the protection strategy configuration file, determining a protection switch state, wherein the protection switch state is used to indicate whether protection is turned on;
[0052] When the protection switch state is in the on state, at least one attack operation feature of the load balancing device in at least one attack scenario is obtained.
[0053] In a possible implementation, the load balancing module is further used to:
[0054] When the protection switch state is in the closed state, load balancing processing is performed on the at least one current flow.
[0055] In a possible implementation, the device further includes: a recording module, a releasing module and a generating module, wherein:
[0056] The recording module is used to, after determining the current abnormal traffic, record the five-tuple information of the current abnormal traffic in the abnormal traffic log; and / or,
[0057] The release module is used to release the target protection strategy after the current operation characteristics are restored to normal operation characteristics;
[0058] The generation module is used to generate a protection log, and the protection log is used to record information on the protection processing performed on the current abnormal traffic.
[0059] In a possible implementation manner, the first acquisition module is specifically configured to:
[0060] Obtain the operation information of the load balancing device within a preset duration before the current moment;
[0061] Determine the current operation characteristics of the load balancing device according to the operation information.
[0062] In a possible implementation manner, the at least one current traffic includes internal traffic of the cloud platform and external traffic of the cloud platform.
[0063] In a fifth aspect, an embodiment of the present application provides a load balancing device, including: a memory and a processor;
[0064] The memory stores computer execution instructions;
[0065] The processor executes the computer execution instructions stored in the memory, so that the processor executes the method according to any one of the first aspects.
[0066] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer execution instructions are stored, and when the computer execution instructions are executed by a processor, they are used to implement the method according to any one of the first aspects.
[0067] In a seventh aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the method according to any one of the first aspects.
[0068] An embodiment of the present application provides a network attack prevention method, device, equipment, storage medium and program product. The load balancing device can obtain the current operation characteristics. If the current operation characteristics conform to the target attack operation characteristics, the load balancing device can determine the current abnormal traffic in at least one received current traffic and perform protection processing on the current abnormal traffic. Since the load balancing device is usually set at a key node within the cloud platform, closer to each server within the cloud platform, and the traffic both inside and outside the cloud platform needs to pass through the load balancing device, when the cloud platform is under a network attack, the load balancing device can quickly determine the current abnormal traffic in at least one received current traffic and perform protection processing on the current abnormal traffic. Compared with the anti-attack device set at the entrance of the cloud platform, the current abnormal traffic can be detected without long-distance transmission, greatly reducing the detection delay and improving the timeliness of network attack prevention. Description of the Drawings
[0069] The drawings here are incorporated into the description and form a part of this description, showing embodiments consistent with the present application and used together with the description to explain the principles of the present application.
[0070] Figure 1 A schematic diagram of an application scenario provided for an exemplary embodiment of the present application;
[0071] Figure 2 A schematic flowchart of a network attack protection method provided for an exemplary embodiment of the present application;
[0072] Figure 3 A schematic flowchart of another network attack protection method provided for an exemplary embodiment of the present application;
[0073] Figure 4 A schematic diagram of a protection processing procedure provided for an exemplary embodiment of the present application;
[0074] Figure 5 A schematic diagram of a network attack protection system provided for an exemplary embodiment of the present application;
[0075] Figure 6 A schematic diagram of the architecture of a cloud platform provided for an exemplary embodiment of the present application;
[0076] Figure 7 A schematic diagram of the structure of a network attack protection device provided for an exemplary embodiment of the present application;
[0077] Figure 8 A schematic diagram of the structure of another network attack protection device provided for an exemplary embodiment of the present application;
[0078] Figure 9 A schematic diagram of the structure of a load balancing device provided for an exemplary embodiment of the present application.
[0079] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Embodiments
[0080] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards, and corresponding operation entrances are provided for users to select authorization or rejection.
[0081] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments of this application and the corresponding drawings. Apparently, the described embodiments are only a part rather than all of the embodiments of this application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0082] Next, in conjunction with Figure 1 , the application scenarios of this application will be described.
[0083] Figure 1 FIG. is a schematic diagram of an application scenario provided for an exemplary embodiment of this application. Please refer to Figure 1 , the cloud platform may include multiple application servers and a load balancing device. The load balancing device can be used to perform load balancing processing on traffic. The multiple application servers can be used to run applications. For example, the multiple application servers can be Application Server 1, Application Server 2, Application Server 3,..., Application Server N respectively, where N is an integer greater than or equal to 1.
[0084] An anti-attack device can be set at the entrance of the cloud platform. The anti-attack device can receive traffic F1 and traffic F2 from outside the cloud platform. The anti-attack device can detect and filter traffic F1 and traffic F2 respectively.
[0085] If the anti-attack device detects that traffic F1 is normal traffic, it can forward traffic F1 to the load balancing device normally, and then the load balancing device performs load balancing processing on traffic F1 and forwards traffic F1 to Application Server 1 and Application Server 2; if the anti-attack device detects that traffic F2 is abnormal traffic, it can block traffic F2 to achieve network attack protection.
[0086] In the related art, usually an anti-attack device is set at the entrance of the cloud platform, and the traffic from outside the cloud platform is detected and filtered by the anti-attack device to achieve network attack protection. However, in the above method, all the traffic entering and leaving the cloud platform must pass through the anti-attack device for detection and filtering, and the detection delay of the anti-attack device for traffic is large, resulting in poor protection timeliness.
[0087] To solve the above problems, an embodiment of the present application provides a network attack protection method, which is applied to a load balancing device. The load balancing device can obtain the current operation characteristics. If the current operation characteristics meet the target attack operation characteristics, the load balancing device can determine the current abnormal traffic in at least one current traffic received, and perform protection processing on the current abnormal traffic. Since the load balancing device is usually set at a key node in the cloud platform, it is closer to each server in the cloud platform, and the traffic in and outside the cloud platform must pass through the load balancing device. Therefore, when the cloud platform is attacked by a network, the load balancing device can quickly determine the current abnormal traffic in at least one current traffic received, and perform protection processing on the current abnormal traffic. Compared with the anti-attack device set at the entrance of the cloud platform, the current abnormal traffic can be detected without long-distance transmission, which greatly reduces the detection delay and improves the timeliness of network attack protection.
[0088] The technical solutions shown in the present application are described in detail below through specific embodiments. It should be noted that the following embodiments can exist independently or in combination with each other, and the same or similar contents will not be described repeatedly in different embodiments.
[0089] The execution subject of the embodiment of the present application may be a load balancing device, or a network attack protection device or a network attack protection system set in the load balancing device. The network attack protection device or the network attack protection system may be implemented by software, or by a combination of software and hardware. The network attack protection device may be a processor in the load balancing device. For ease of understanding, the following description is made by taking the execution subject as a load balancing device as an example.
[0090] Figure 2 A flowchart of a network attack protection method provided by an exemplary embodiment of the present application. Figure 2 , the method may include:
[0091] S201. Obtain current operating characteristics of the load balancing device.
[0092] A cloud platform is usually equipped with at least one load balancing device. The load balancing device can be used to load balance traffic, that is, it can evenly distribute traffic to different application servers (or application service instances), thereby achieving load balancing for application servers and ensuring the continuity and reliability of application services.
[0093] Optionally, the current operation feature may be characterized by at least one of the following statistical values: central processing unit (CPU) utilization, bandwidth throughput, bandwidth utilization, memory utilization, etc. Optionally, the statistical value may be an average value, a maximum value, etc.
[0094] For example, the current operating characteristics of the load balancing device can be obtained as: the average CPU utilization rate is 96%.
[0095] S202. If the current operating characteristics match the target attack operating characteristics, determine the current abnormal traffic among at least one current traffic received by the load balancing device, and perform protection processing on the current abnormal traffic.
[0096] The target attack operating characteristics can be any one of at least one attack operating characteristic in at least one attack scenario.
[0097] Optionally, a protection policy configuration file can be stored in the load balancing device.
[0098] The protection policy configuration file can include at least one attack operating characteristic in at least one attack scenario. For any one attack scenario, there can be one attack operating characteristic corresponding to this attack scenario.
[0099] For example, the protection policy configuration file can include attack operating characteristics in 3 attack scenarios, as shown in Table 1 for example:
[0100] Table 1
[0101]
[0102] Optionally, at least one current traffic can include internal traffic within the cloud platform and external traffic outside the cloud platform. The internal traffic within the cloud platform can be the interaction traffic among various application servers in the cloud platform. The external traffic outside the cloud platform can be the traffic sent from external servers outside the cloud platform to the cloud platform. The cloud platform is the platform where the load balancing device is located.
[0103] The current abnormal traffic can be internal traffic within the cloud platform or external traffic outside the cloud platform.
[0104] Optionally, the load balancing device can match the current operating characteristics with at least one attack operating characteristic to determine the target attack operating characteristics that the current operating characteristics match.
[0105] For example, if the load balancing device obtains 3 attack operating characteristics in 3 attack scenarios as shown in Table 1, and if the current operating characteristics are: the average CPU utilization rate is 96%, then the load balancing device can determine that the current operating characteristics match attack operating characteristic 2, that is, the target attack operating characteristics are attack operating characteristic 2.
[0106] If there are no target attack operating characteristics that the current operating characteristics match, it means that the load balancing device has not been attacked. The load balancing device can perform load balancing processing on the received current traffic.
[0107] If there is a target attack running feature that the current running feature conforms to, it indicates that the load balancing device is under attack by abnormal traffic. The load balancing device can determine the current abnormal traffic in at least one current traffic received and perform protection processing on the current abnormal traffic.
[0108] Optionally, the current abnormal traffic can be determined in at least one current traffic received by the load balancing device in the following manner: in at least one attack scenario, determine the target attack scenario corresponding to the target attack running feature; determine the target abnormal traffic feature in the protection policy configuration file for the target attack scenario; and determine the current abnormal traffic in at least one current traffic according to the target abnormal traffic feature.
[0109] The target attack scenario can be the attack scenario corresponding to the target attack running feature. For example, if the target attack running feature is the attack running feature 2 shown in Table 1, the target attack scenario is the attack scenario 2 corresponding to the attack running feature 2.
[0110] Optionally, the abnormal traffic feature can be characterized by at least one of the following statistical values: CPU utilization rate, bandwidth utilization rate, bandwidth throughput, etc. occupied by the abnormal traffic in the load balancing device. Optionally, the statistical value can be an average value, a maximum value, etc.
[0111] The target abnormal traffic feature refers to the abnormal traffic feature in the target attack scenario.
[0112] Optionally, the protection policy configuration file can also include abnormal traffic features in at least one attack scenario.
[0113] For example, based on Table 1, the protection policy configuration file can also include abnormal traffic features in 3 attack scenarios, as shown in Table 2 for example:
[0114] Table 2
[0115]
[0116] For example, if the load balancing device determines that the target attack scenario is attack scenario 2, the load balancing device can determine in the protection policy configuration file that the target abnormal traffic feature is the abnormal traffic feature 2 in attack scenario 2 (i.e., the average CPU utilization rate is higher than 90%). If the load balancing device receives 2 current traffics, namely traffic F1 and traffic F2, and the average CPU utilization rate occupied by traffic F1 in the load balancing device is 91%, and the average CPU utilization rate occupied by traffic F2 in the load balancing device is 5%, since the average CPU utilization rate of 91% occupied by traffic F1 in the load balancing device conforms to the target abnormal traffic feature, the load balancing device can determine that traffic F1 is the current abnormal traffic. The load balancing device can perform protection processing on traffic F1.
[0117] In the technical solution of the present application, since the load balancing device may include a protection policy configuration file, and the protection policy configuration file includes at least one attack scenario, as well as the attack operation characteristics and abnormal traffic characteristics corresponding to each attack scenario, the load balancing device can quickly determine the current abnormal traffic in at least one current traffic based on the protection policy configuration file, improving the efficiency of determining the current abnormal traffic, and further improving the efficiency of protecting and processing the current abnormal traffic.
[0118] In an embodiment of the present application, the load balancing device may obtain the current operation characteristics. If the current operation characteristics conform to the target attack operation characteristics, the load balancing device may determine the current abnormal traffic in at least one current traffic received, and perform protection processing on the current abnormal traffic. Since the load balancing device is usually set at a key node within the cloud platform, closer to each server within the cloud platform, and the traffic both inside and outside the cloud platform needs to pass through the load balancing device, when the cloud platform is under a network attack, the load balancing device can quickly determine the current abnormal traffic in at least one current traffic received, and perform protection processing on the current abnormal traffic. Compared with the anti-attack device set at the entrance of the cloud platform, the current abnormal traffic can be detected without long-distance transmission, greatly reducing the detection delay and improving the timeliness of network attack protection; and since the load balancing device can receive external traffic and internal traffic of the cloud platform, network attack protection through the load balancing device can effectively protect against network attacks from both inside and outside the cloud platform, improving the comprehensiveness and reliability of protection compared with the prior art where the anti-attack device can only protect against attacks from outside the cloud platform.
[0119] Next, based on the Figure 2 illustrated embodiment, in combination with Figure 3 , the above network attack protection method will be described in detail.
[0120] Figure 3 It is a schematic flowchart of another network attack protection method provided by an exemplary embodiment of the present application. Please refer to Figure 3 , the method may include:
[0121] S301. In the protection policy configuration file, determine whether the protection switch status is the on state.
[0122] Optionally, the protection policy configuration file may further include the protection switch status. The protection switch status may be used to indicate whether to enable protection.
[0123] The protection switch status may be the on state or the off state. Optionally, the on state may be represented by "1", and the off state may be represented by "0".
[0124] If the protection switch status is the on state, it indicates that the protection has been enabled and protection processing is required, then S302 can be executed; if the protection switch status is the off state, it indicates that the protection has not been enabled, then S309 can be executed.
[0125] For example, the load balancing device can determine that the protection switch status is the on state in the protection policy configuration file.
[0126] S302. Obtain at least one attack operation characteristic of the load balancing device under at least one attack scenario.
[0127] For example, the load balancing device can obtain three attack operation characteristics under three attack scenarios shown in Table 1 in the protection policy configuration file.
[0128] S303. Obtain the current operation characteristic of the load balancing device.
[0129] Optionally, the current operation characteristic of the load balancing device can be obtained in the following manner: obtain the operation information of the load balancing device within a preset duration before the current moment; determine the current operation characteristic of the load balancing device according to the operation information.
[0130] Optionally, the preset duration can be preset manually. For example, the preset duration can be 5 minutes before the current moment.
[0131] Optionally, the operation information can include at least one of the following: CPU utilization rate, bandwidth throughput, bandwidth utilization rate, memory utilization rate, etc.
[0132] The load balancing device can obtain the operation information within a preset duration before the current moment and perform statistical processing on the operation information to obtain the current operation characteristic.
[0133] For example, if the preset duration is 5 minutes and the operation information obtained by the load balancing device within 5 minutes before the current moment is 5 CPU utilization rates, which are: 96%, 95%, 94%, 97%, 98%, if the current operation characteristic is characterized by the average CPU utilization rate, then the load balancing device can determine the current operation characteristic as: the average CPU utilization rate is 96% according to the 5 CPU utilization rates.
[0134] S304. Determine whether the current operation characteristic conforms to the target operation characteristic among at least one attack operation characteristic.
[0135] The target operation characteristic can be any one of at least one attack operation characteristic.
[0136] If so, it indicates that the load balancing device has been attacked, and S305 - S306 can be executed; if not, it indicates that the current running characteristics do not conform to any attack running characteristics and the load balancing device has not been attacked, and S307 - S309 can be executed.
[0137] S305. Determine the current abnormal traffic in at least one current traffic received by the load balancing device.
[0138] If the current running characteristics conform to the target attack running characteristics, the load balancing device can determine the target abnormal traffic characteristics in the target attack scenario in the protection policy configuration file, and determine the current abnormal traffic in at least one current traffic according to the target abnormal traffic characteristics.
[0139] For example, if the load balancing device determines that the target attack scenario is attack scenario 2, the load balancing device can determine in the protection policy configuration file that the target abnormal traffic characteristic is the abnormal traffic characteristic 2 in attack scenario 2 (i.e., the average CPU utilization rate is higher than 90%). If the load balancing device receives 2 current traffics, namely traffic F1 and traffic F2, and the average CPU utilization rate of traffic F1 in the load balancing device is 91%, and the average CPU utilization rate of traffic F2 in the load balancing device is 5%, since the average CPU utilization rate of traffic F1 in the load balancing device, which is 91%, conforms to the target abnormal traffic characteristic, the load balancing device can determine that traffic F1 is the current abnormal traffic.
[0140] Optionally, after the load balancing device determines the current abnormal traffic, it can also record the five - tuple information of the current abnormal traffic in the abnormal traffic log. Among them, the five - tuple information can include the source Internet Protocol (IP) address, source port number, destination IP address, destination port number, and transport layer protocol.
[0141] For example, the load balancing device can determine that the five - tuple information of traffic F1 includes: the source IP address is IP address 1, the source port number is 001, the destination IP address is IP address 2, the destination port number is 002, and the transport layer protocol is Transmission Control Protocol (TCP). The load balancing device can record the five - tuple information of this traffic F1 in the abnormal traffic log.
[0142] S306. Perform protection processing on the current abnormal traffic.
[0143] Optionally, the current abnormal traffic can be protected in the following way: determine the target protection policy corresponding to the target abnormal traffic characteristic in the protection policy configuration file; perform protection processing on the current abnormal traffic according to the target protection policy.
[0144] Optionally, the protection strategy configuration file may also include protection strategies corresponding to each abnormal traffic feature. For example, based on Table 2, the protection strategy configuration file may also include three protection strategies corresponding to three abnormal traffic features, as shown in Table 3:
[0145] Table 3
[0146]
[0147] Optionally, the load balancing device can set the state flag corresponding to the target protection policy to an open flag (for example, the open flag can be represented by "1") in the protection policy configuration file, indicating that the target protection policy is executed. The load balancing device can perform protection processing on the current abnormal traffic according to the target protection policy.
[0148] Optionally, the protection processing may include at least one of the following: rate limiting processing and packet loss processing.
[0149] Optionally, the specific implementation of the rate limiting process or packet loss process can be implemented by related existing technologies, which will not be described in detail here. For example, the rate limiting process or packet loss process can be performed by using the Extended Berkeley Packet Filter (eBPF) technology.
[0150] It should be emphasized that in the technical solution of the present application, the abnormal traffic is speed-limited or packet-dropped by using relevant existing technologies, without the need for additional hardware or software, thus achieving lightweight, strong versatility and wide applicability.
[0151] Optionally, after the load balancing device performs protection processing on the current abnormal traffic, S303 to S306 may be executed again until the current operation characteristics are restored to normal operation characteristics (ie, the current operation characteristics do not meet any attack operation characteristics).
[0152] Optionally, the normal operation feature may be preset manually. The protection strategy configuration file may include the normal operation feature.
[0153] Optionally, after the current operation characteristics are restored to normal operation characteristics, the load balancing device can release the target protection policy and generate a protection log. The protection log can be used to record information on the protection processing of the current abnormal traffic.
[0154] Optionally, the load balancing device may reset the state flag corresponding to the target protection policy to a closed flag (for example, the closed flag may be represented by "0") in the protection policy configuration file, indicating that the target protection policy is released and will not be executed.
[0155] Next, combineFigure 4 , describes the process of protecting abnormal traffic.
[0156] Figure 4 A schematic diagram of a protection process provided by an exemplary embodiment of the present application. Figure 4 ,When the load balancing device receives traffic F1 and traffic F2, the current operating characteristics of the load balancing device under normal conditions are: the average CPU utilization is 50%.
[0157] If the flow F1 suddenly increases and meets the abnormal flow feature 2, the load balancing device determines that the current abnormal flow is flow F1. When flow F1 attacks the load balancing device, since flow F1 occupies a large amount of CPU resources of the load balancing device, the average CPU utilization of the load balancing device increases to 96%, causing the load balancing device to be unable to process flow F2 normally, and it is necessary to protect flow F1.
[0158] If the protection policy configuration file is as shown in Table 3, the load balancing device can determine the target protection policy as protection policy 2 in the protection policy configuration file (i.e., limit the rate of abnormal traffic until the average CPU utilization rate drops below 50%). In the protection state, the load balancing device can limit the rate of traffic F1 according to protection policy 2, so that the average CPU utilization rate drops from 96% to below 50% until it returns to normal.
[0159] After returning to normal, the load balancing device can cancel the rate limit processing for traffic F1, that is, release the protection strategy 2. In normal state, the average CPU utilization of the load balancing device can be restored to 50%, that is, the current operation characteristics are restored to normal operation characteristics. Normal operation characteristics are that the average CPU utilization is 50%.
[0160] The load balancing device can also generate a protection log: protection strategy 2 is enabled from 15:00 to 16:00, and the rate of traffic F1 is limited, reducing the average CPU utilization from 96% to 50%.
[0161] Optionally, in the technical solution of the present application, the load balancing device can also send abnormal traffic logs and protection logs to the external monitoring system. After the external monitoring system obtains the abnormal traffic logs and protection logs, it can perform statistical aggregation processing on the abnormal traffic logs and protection logs and present them to the operation and maintenance personnel to facilitate the operation and maintenance personnel to make decisions or interventions.
[0162] S307: Determine whether there is an enabled protection policy in the protection policy configuration file.
[0163] If the current running feature does not match any of the attack running features, it means that the load balancing device is not under attack, that is, there is no current abnormal traffic in at least one current traffic flow.
[0164] The load balancing device can determine whether there is an enabled protection policy in the protection policy configuration file. If there is, S308~S309 can be executed; if not, S309 can be executed.
[0165] S308. Delete the enabled protection policy in the protection policy configuration file.
[0166] Since the current running feature does not match any of the attack running features, it indicates that the load balancing device is not under attack, so there is no need to enable the protection policy. Therefore, if the load balancing device determines that there is an enabled protection policy in the protection policy configuration file, the enabled protection policy can be deleted.
[0167] For example, if the load balancing device determines that it is not under attack and the protection policy configuration file is as shown in Table 3, if Protection Policy 1 is in the enabled state, the load balancing device can delete Protection Policy 1 in the protection policy configuration file.
[0168] It should be noted that when the load balancing device is not under attack, deleting the enabled protection policy in the protection policy configuration file can avoid continuously accumulating historical protection policies, achieve lightweight, and reduce the resources occupied by the protection policy configuration file in the load balancing device.
[0169] Optionally, after step S308 is executed, step S309 can be executed.
[0170] S309. Perform load balancing processing on at least one current traffic flow.
[0171] Optionally, when the protection switch is in the off state, it means that no protection processing is required, so the load balancing device can perform load balancing processing on at least one received current traffic flow; or, when the current running feature does not match any of the attack running features, it means that the load balancing device is not under attack, that is, there is no current abnormal traffic in at least one current traffic flow, so the load balancing device can perform load balancing processing on at least one received current traffic flow.
[0172] Load balancing processing means that the load balancing device forwards at least one current traffic flow according to the load balancing policy.
[0173] It should be noted that in Figure 3 The various processing steps (S301~S309) shown in the embodiments do not constitute a specific limitation on the network attack protection process. In other embodiments of the present application, the network attack protection process may include more than Figure 3The embodiments may include more or fewer steps. For example, the network attack protection process may include: Figure 3 Some steps in the embodiment, or, Figure 3 Some steps in the embodiments may be replaced by steps having the same functions, or Figure 3 Some steps in the embodiments may be split into multiple steps, etc.
[0174] In an embodiment of the present application, the load balancing device can determine whether the protection switch state is in the on state in the protection policy configuration file. If the protection switch state is in the off state, the load balancing device can directly perform load balancing processing on at least one current flow; if the protection switch state is in the on state, the load balancing device can obtain at least one attack operation feature in at least one attack scenario, and obtain the current operation feature. The load balancing device can determine whether the current operation feature meets the target operation feature in at least one attack operation feature. If the current operation feature meets the target operation feature, the current abnormal flow can be determined in at least one current flow received, and the current abnormal flow can be protected. If the current operation feature does not meet any attack operation feature, the load balancing device can determine whether there is an enabled protection policy in the protection policy configuration file. If so, the enabled protection policy can be deleted in the protection policy configuration file, and then load balancing processing can be performed on at least one current flow; if not, load balancing processing can be directly performed on at least one current flow. Since the load balancing device is usually set at a key node in the cloud platform, it is closer to the servers in the cloud platform, and the traffic inside and outside the cloud platform must pass through the load balancing device. Therefore, when the cloud platform is attacked by a network attack, the load balancing device can quickly determine the current abnormal traffic in at least one current traffic received, and perform protection processing on the current abnormal traffic. Compared with the anti-attack device set at the entrance of the cloud platform, the current abnormal traffic can be detected without long-distance transmission, which greatly reduces the detection delay and improves the timeliness of network attack protection; and since the load balancing device can receive both external and internal traffic of the cloud platform, network attack protection is performed through the load balancing device, which can effectively protect against network attacks from inside and outside the cloud platform. Compared with the prior art in which the anti-attack device can only protect against attacks from outside the cloud platform, the comprehensiveness and reliability of the protection are improved; and compared with the prior art that requires special anti-attack equipment, the present application does not require additional anti-attack equipment, and achieves the effect of efficient network attack protection at low cost.
[0175] Optionally, a network attack protection system may be provided in the load balancing device to execute the network attack protection method shown in any of the above embodiments.
[0176] Next, combine Figure 5, a network attack protection system is described.
[0177] Figure 5 A schematic diagram of a network attack protection system provided by an exemplary embodiment of the present application. Figure 5 The network attack protection system 50 may include a policy management component 51, a monitoring component 52, an attack tracing component 53 and a protection component 54.
[0178] The policy management component 51 can be used to manage the protection policy configuration files.
[0179] The monitoring component 52 can be used to obtain the operation information of the load balancing device within a preset time period before the current moment, and determine the current operation characteristics of the load balancing device based on the operation information; the monitoring component 52 can also be used to obtain at least one attack operation characteristic of the load balancing device in at least one attack scenario, and determine whether the current operation characteristic meets the target attack operation characteristic, and the target attack operation characteristic is any one of the at least one attack operation characteristic.
[0180] The attack tracing component 53 can be used to determine the current abnormal traffic in at least one current traffic received by the load balancing device when the current operation characteristics meet the target attack operation characteristics. Optionally, the attack tracing component 53 can also determine the five-tuple information of the current abnormal traffic and record the five-tuple information of the current abnormal traffic in the abnormal traffic log.
[0181] The protection component 54 can be used to perform protection processing on the current abnormal traffic.
[0182] Optionally, the protection component 54 can also be used to release the target protection policy and generate a protection log after the current operating characteristics are restored to normal operating characteristics. The protection log can be used to record information on the protection processing of the current abnormal traffic.
[0183] In the embodiment of the present application, the network attack protection system is set in the load balancing device. The load balancing device can quickly determine the current abnormal traffic through the network attack protection system, and perform protection processing on the current abnormal traffic, which greatly reduces the detection delay and improves the timeliness of network attack protection; and because the load balancing device can receive the external traffic of the cloud platform and the internal traffic of the cloud platform, the network attack protection through the load balancing device can effectively protect against network attacks from inside and outside the cloud platform. Compared with the existing technology that the anti-attack device can only protect against attacks from outside the cloud platform, the comprehensiveness and reliability of the protection are improved.
[0184] Next, combine Figure 6 , describe the cloud platform described in any of the above embodiments.
[0185] Figure 6 A schematic diagram of the architecture of a cloud platform provided by an exemplary embodiment of the present application. Please refer to Figure 6 , the cloud platform may include a management and control device, at least one load balancing device, and at least one application server.
[0186] For example, the at least one load balancing device may be a load balancing device 1, ……, a load balancing device M respectively, where M is an integer greater than or equal to 1; the at least one application server may be an application server 1, an application server 2, an application server 3, ……, an application server N respectively, where N is an integer greater than or equal to 1.
[0187] The management and control device may periodically send a protection policy configuration file to the at least one load balancing device to configure the protection policy configuration file for the at least one load balancing device. The protection policy configuration file may be stored in the at least one load balancing device.
[0188] For any one load balancing device, a network attack protection system may be provided in the load balancing device to perform protection processing on the current abnormal traffic in at least one current traffic received. The load balancing device may further include a load balancing component, and the load balancing component may be used to perform load balancing processing on normal traffic, that is, evenly distribute the normal traffic to different application servers.
[0189] In the embodiment of the present application, the cloud platform may include a management and control device and at least one load balancing device. The load balancing device may include a network attack protection system and a load balancing component. In the cloud platform, the load balancing device may quickly determine the current abnormal traffic through the network attack protection system and perform protection processing on the current abnormal traffic, greatly reducing the detection delay and improving the timeliness of network attack protection; and since the load balancing device can receive external traffic and internal traffic of the cloud platform, network attack protection through the load balancing device can effectively protect network attacks from both inside and outside the cloud platform, improving the comprehensiveness and reliability of protection compared with the prior art in which the anti-attack device can only protect against attacks from outside the cloud platform.
[0190] Figure 7 A schematic diagram of the structure of a network attack protection device provided by an exemplary embodiment of the present application. Please refer to Figure 7 , the network attack protection device 70 is applied to the load balancing device, and the network attack protection device 70 includes: a first acquisition module 71 and a protection module 72, where
[0191] The first acquisition module 71 is used to acquire the current operation characteristics of the load balancing device;
[0192] The protection module 72 is configured to, if the current running feature conforms to the target attack running feature, determine current abnormal traffic in at least one current traffic received by the load balancing device, and perform protection processing on the current abnormal traffic, where the target attack running feature is any one of at least one attack running feature in at least one attack scenario.
[0193] The network attack protection device provided by the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be elaborated here.
[0194] In a possible implementation manner, a protection policy configuration file is included in the load balancing device; specifically, the protection module 72 is configured to:
[0195] In the at least one attack scenario, determine the target attack scenario corresponding to the target attack running feature;
[0196] Determine the target abnormal traffic feature in the target attack scenario in the protection policy configuration file;
[0197] According to the target abnormal traffic feature, determine the current abnormal traffic in the at least one current traffic.
[0198] In a possible implementation manner, the protection module 72 is specifically configured to:
[0199] Determine the target protection policy corresponding to the target abnormal traffic feature in the protection policy configuration file;
[0200] According to the target protection policy, perform protection processing on the current abnormal traffic.
[0201] The network attack protection device provided by the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be elaborated here.
[0202] Figure 8 It is a structural schematic diagram of another network attack protection device provided for an exemplary embodiment of the present application. Please refer to Figure 8 , in Figure 7 Based on the shown embodiment, the network attack protection device 70 may further include: a determination module 73, a deletion module 74, and a load balancing module 75, where
[0203] The determination module 73 is configured to, if the current running feature does not conform to any attack running feature, determine whether there is an enabled protection policy in the protection policy configuration file;
[0204] The deletion module 74 is configured to, if there is, delete the enabled protection policy;
[0205] The load balancing module 75 is used to perform load balancing processing on the at least one current flow;
[0206] The load balancing module 75 is further configured to perform load balancing processing on the at least one current flow if the at least one current flow does not exist.
[0207] The network attack protection device provided in the embodiment of the present application can execute the technical solution shown in the above method embodiment, and its implementation principle and beneficial effects are similar, which will not be repeated here.
[0208] In a possible implementation manner, the network attack protection device 70 may further include a second acquisition module 76, and the second acquisition module 76 is used to:
[0209] In the protection strategy configuration file, determining a protection switch state, wherein the protection switch state is used to indicate whether protection is turned on;
[0210] When the protection switch state is in the on state, at least one attack operation feature of the load balancing device in at least one attack scenario is obtained.
[0211] In a possible implementation manner, the load balancing module 75 is further configured to:
[0212] When the protection switch state is in the closed state, load balancing processing is performed on the at least one current flow.
[0213] In a possible implementation manner, the device further includes: a recording module 77, a releasing module 78 and a generating module 79, wherein:
[0214] The recording module 77 is used to, after determining the current abnormal traffic, record the five-tuple information of the current abnormal traffic in the abnormal traffic log; and / or,
[0215] The release module 78 is used to release the target protection strategy after the current operation characteristics are restored to normal operation characteristics;
[0216] The generating module 79 is used to generate a protection log, and the protection log is used to record information on the protection processing performed on the current abnormal traffic.
[0217] In a possible implementation manner, the first acquisition module 71 is specifically configured to:
[0218] Obtaining operation information of the load balancing device within a preset time period before the current moment;
[0219] According to the operation information, current operation characteristics of the load balancing device are determined.
[0220] In a possible implementation, the at least one current traffic includes internal traffic of the cloud platform and external traffic of the cloud platform.
[0221] The network attack protection device provided by the embodiments of the present application can execute the technical solutions shown in the above method embodiments, and the implementation principles and beneficial effects are similar, which will not be elaborated here.
[0222] Figure 9 The following is a schematic structural diagram of a load balancing device provided for an exemplary embodiment of the present application. Please refer to Figure 9 , the load balancing device 90 may include a processor 91 and a memory 92. Exemplarily, the processor 91 and the memory 92 are interconnected with each other through a bus 93.
[0223] The memory 92 stores computer execution instructions;
[0224] The processor 91 executes the computer execution instructions stored in the memory 92, so that the processor 91 executes the method as shown in the above method embodiment.
[0225] Correspondingly, the embodiments of the present application provide a computer-readable storage medium, in which computer execution instructions are stored, and when the computer execution instructions are executed by a processor, they are used to implement the method described in the above method embodiment.
[0226] Correspondingly, the embodiments of the present application may also provide a computer program product, including a computer program, which when executed by a processor, can implement the method shown in the above method embodiment.
[0227] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0228] The present invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each flow and / or block of the flowchart illustrations and / or block diagrams, and combinations of flows and / or blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions executed by the processor of the computer or other programmable data processing apparatus create means for implementing the functions specified in the flowchart Figure 1 for one or more of the flows and / or blocks Figure 1 and / or boxes.
[0229] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means that implement the functions specified in the flowchart Figure 1 for one or more of the flows and / or blocks Figure 1 and / or boxes.
[0230] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart Figure 1 for one or more of the flows and / or blocks Figure 1 and / or boxes.
[0231] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0232] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
[0233] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined in this article, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0234] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0235] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A network attack protection method, characterized in that: Applied to a load balancing device, the method comprises: Obtaining the operation information of the load balancing device within a preset time period before the current moment; performing statistics on the operation information to determine the current operation characteristics of the load balancing device; the operation characteristics include: average CPU utilization and average bandwidth utilization; If the current operation characteristic meets the target attack operation characteristic, the target abnormal traffic characteristic is determined based on the mapping relationship between the target attack operation characteristic and the abnormal traffic characteristic in the protection strategy configuration file, and the current abnormal traffic that meets the current target abnormal traffic characteristic condition is determined in at least one current traffic received by the load balancing device, and protection processing is performed on the current abnormal traffic. The target attack operation characteristic is any one of at least one attack operation characteristic under at least one attack scenario; the at least one received traffic includes internal traffic and external traffic of the cloud platform where the load balancing device is located, and the internal traffic is the interaction traffic between application servers in the cloud platform.
2. The method according to claim 1, characterized in that The load balancing device includes a protection strategy configuration file; determining a current abnormal flow that meets a current target abnormal flow characteristic condition in at least one current flow received by the load balancing device, including: In the at least one attack scenario, determining a target attack scenario corresponding to the target attack operation feature; Determining target abnormal traffic characteristics under a target attack scenario in the protection strategy configuration file; According to the target abnormal flow characteristic, a current abnormal flow satisfying the current target abnormal flow characteristic condition is determined in the at least one current flow.
3. The method according to claim 2, characterized in that Performing protection processing on the current abnormal traffic includes: Determining a target protection strategy corresponding to the target abnormal traffic feature in the protection strategy configuration file; According to the target protection strategy, protection processing is performed on the current abnormal traffic.
4. The method according to claim 2 or 3, characterized in that: The method further comprises: If the current running feature does not match any attack running feature, determining whether there is an enabled protection strategy in the protection strategy configuration file; If it exists, the enabled protection strategy is deleted, and load balancing is performed on the at least one current flow; If not, load balancing is performed on the at least one current flow.
5. The method according to claim 2 or 3, characterized in that: The method further comprises: In the protection strategy configuration file, determining a protection switch state, wherein the protection switch state is used to indicate whether protection is turned on; When the protection switch state is in the on state, at least one attack operation feature of the load balancing device in the at least one attack scenario is obtained.
6. The method according to claim 5, characterized in that The method further comprises: When the protection switch state is in the closed state, load balancing processing is performed on the at least one current flow.
7. The method according to claim 3, characterized in that The method further comprises: After determining the current abnormal traffic, recording the five-tuple information of the current abnormal traffic in the abnormal traffic log; and / or, After the current operation characteristics are restored to normal operation characteristics, the target protection strategy is released and a protection log is generated, wherein the protection log is used to record information on the protection processing performed on the current abnormal traffic.
8. A network attack protection system, characterized in that: The system is arranged in a load balancing device, and the system is used to execute the method according to any one of claims 1 to 7.
9. A cloud platform, characterized in that: The cloud platform includes a control device and at least one load balancing device, wherein: The control device is used to configure a protection policy configuration file to the load balancing device; The load balancing device is provided with the network attack protection system as claimed in claim 8.
10. A network attack protection device, characterized in that: Applied to a load balancing device, the device comprises: a first acquisition module and a protection module, wherein: The first acquisition module is used to obtain the operation information of the load balancing device within a preset time period before the current moment; to collect statistics on the operation information to determine the current operation characteristics of the load balancing device; the operation characteristics include: average CPU utilization and average bandwidth utilization; The protection module is used to, if the current operation characteristic meets the target attack operation characteristic, determine the target abnormal traffic characteristic based on the mapping relationship between the target attack operation characteristic and the abnormal traffic characteristic in the protection policy configuration file, determine the current abnormal traffic that meets the current target abnormal traffic characteristic condition in at least one current traffic received by the load balancing device, and perform protection processing on the current abnormal traffic, the target attack operation characteristic is any one of at least one attack operation characteristic under at least one attack scenario; the at least one received traffic includes internal traffic and external traffic of the cloud platform where the load balancing device is located, and the internal traffic is the interaction traffic between application servers in the cloud platform.
11. A load balancing device, characterized in that: include: at least one processor; as well as a memory communicatively coupled to the at least one processor; The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the load balancing device executes the method described in any one of claims 1 to 7.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and when the processor executes the computer-executable instructions, the method according to any one of claims 1 to 7 is implemented.
13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Load balancing device and load balancing and defending method
CN103139246A
Data processing method and device and storage medium
CN112333130A