A traffic protection method, device, apparatus and storage medium

By generating real-time and historical traffic models and dynamically adjusting protection strategies based on traffic analysis results, the problem of low protection efficiency of servers in traffic attacks is solved, achieving real-time and accurate protection effects.

CN119814364BActive Publication Date: 2025-11-11CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411773029.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-04
Publication Date
2025-11-11
Estimated Expiration
2044-12-04

AI Technical Summary

Technical Problem

In existing technologies, when servers are subjected to DDoS attacks, protection strategies cannot be comprehensively analyzed from the overall situation of the nodes, resulting in low protection efficiency and slow analysis time, which delays protection decisions.

Method used

By generating real-time and historical traffic models, traffic data is analyzed in real time and protection strategies are adjusted. Historical data is used to supplement and optimize the system, achieving dynamic protection.

Benefits of technology

It achieves real-time and precise protection against DDoS attacks, improves protection efficiency, and can continuously learn and adjust protection strategies, thereby enhancing the protection effect against DDoS attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814364B_ABST
    Figure CN119814364B_ABST
Patent Text Reader

Abstract

Embodiments of the present application relate to the technical field of data processing, in particular to a traffic protection method and device, equipment and storage medium, aiming to improve the traffic attack protection efficiency of a server. The method comprises: generating a corresponding real-time traffic model according to real-time traffic data in the server; obtaining index data corresponding to at least one protection module from the real-time traffic model; adjusting the protection strategy corresponding to at least one protection module through the index data, and executing the corresponding protection measures; generating a historical traffic model on the basis of the real-time traffic model according to historical traffic data in the server; obtaining a corresponding traffic analysis result according to the historical traffic model in the forwarding process of the real-time traffic data; adjusting the protection strategy corresponding to at least one protection module according to the traffic analysis result, and executing the corresponding protection measures.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network technology, and more specifically, to a traffic protection method, apparatus, device, and storage medium. Background Technology

[0002] Servers are prone to crashing when subjected to DDoS attacks, affecting their normal operation. Current technology involves pre-setting multiple protection modules within the server. When a DDoS attack occurs, the system directly analyzes the traffic logs and issues corresponding protection policies.

[0003] Existing technologies only consider protection strategies for individual nodes, failing to provide a comprehensive analysis of the overall situation of the nodes. Furthermore, the analysis process is slow, leading to delays in protection decisions and reduced protection efficiency. Summary of the Invention

[0004] This application provides a traffic protection method, apparatus, device, and storage medium, aiming to improve the efficiency of traffic attack protection for servers.

[0005] A first aspect of this application provides a traffic protection method, the method comprising:

[0006] Generate a corresponding real-time traffic model based on real-time traffic data from the server;

[0007] Obtain at least one indicator data corresponding to a protection module from the real-time traffic model;

[0008] Based on the aforementioned indicator data, the protection strategy corresponding to at least one of the protection modules is adjusted, and corresponding protection measures are implemented.

[0009] Based on the historical traffic data in the server, a historical traffic model is generated on the basis of the real-time traffic model.

[0010] During the forwarding of the real-time traffic data, the corresponding traffic analysis results are obtained based on the historical traffic model;

[0011] Based on the traffic analysis results, the protection strategy corresponding to at least one of the protection modules is adjusted, and the corresponding protection measures are implemented.

[0012] Optionally, before generating the corresponding real-time traffic model based on the real-time traffic data in the server, the method further includes:

[0013] Obtain traffic data from the server's traffic logs and attack logs;

[0014] The traffic data is classified according to its corresponding attributes to obtain the classified traffic data;

[0015] The categorized traffic data is stored in the server's memory according to the corresponding data metrics and asynchronously pushed to the database.

[0016] Optionally, generating a corresponding real-time traffic model based on real-time traffic data in the server includes:

[0017] Traffic data within a preset time period is extracted from the server's memory according to preset data indicators. The preset time period is a time period with a granularity of seconds, including the current time.

[0018] The traffic data is processed using preset data retrieval rules to obtain the real-time traffic model.

[0019] Optionally, adjusting the protection strategy corresponding to at least one of the protection modules using the indicator data includes: determining the protection module corresponding to the indicator data;

[0020] The indicator data is sent to the protection module;

[0021] Based on the aforementioned indicator data, the protection threshold corresponding to the protection module is adjusted, and the protection rules of the protection module are also adjusted.

[0022] Optionally, generating a historical traffic model based on the real-time traffic model using historical traffic data from the server includes:

[0023] Traffic data is extracted from the server's database at an hourly granularity based on preset data metrics.

[0024] The traffic data is processed according to preset data retrieval rules to obtain the processing result data;

[0025] The historical traffic model is obtained by supplementing the real-time traffic model with the processing result data.

[0026] Optionally, during the forwarding of the real-time traffic data, the corresponding traffic analysis results are obtained based on the historical traffic model, including:

[0027] Determine the time period corresponding to the real-time traffic data;

[0028] Obtain historical traffic data for the same time period within the historical time frame from the historical traffic model;

[0029] The historical traffic data and the real-time traffic data are analyzed to obtain the traffic analysis results.

[0030] Optionally, adjusting the protection strategy corresponding to at least one of the protection modules based on the traffic analysis results includes:

[0031] The traffic analysis results are then placed into the subscription message queue;

[0032] The traffic analysis results are sent from the subscription message queue to the corresponding protection module;

[0033] Based on the traffic analysis results, the module threshold of the protection module is adjusted, and the protection rules of the protection module are also adjusted.

[0034] A second aspect of this application provides a flow protection device, the device comprising:

[0035] The first traffic model generation module is used to generate a corresponding real-time traffic model based on the real-time traffic data in the server.

[0036] The indicator data acquisition module is used to acquire indicator data corresponding to at least one protection module from the real-time traffic model;

[0037] The first protection module is used to adjust the protection strategy corresponding to at least one of the protection modules based on the indicator data, and to execute the corresponding protection measures.

[0038] The second traffic model generation module is used to generate a historical traffic model based on the real-time traffic model according to the historical traffic data in the server.

[0039] The traffic analysis module is used to obtain corresponding traffic analysis results based on the historical traffic model during the forwarding of the real-time traffic data.

[0040] The second protection module is used to adjust the protection strategy corresponding to at least one of the protection modules based on the traffic analysis results, and to execute the corresponding protection measures.

[0041] Optionally, the device further includes:

[0042] The traffic data acquisition module is used to acquire traffic data from the server's traffic logs and attack logs;

[0043] The traffic data classification module is used to classify the traffic data according to corresponding attributes to obtain the classified traffic data;

[0044] The traffic data storage module is used to store the classified traffic data in the memory of the server according to the corresponding data indicators, and to push it to the database asynchronously.

[0045] Optionally, the first traffic model generation module includes:

[0046] The first data extraction submodule is used to extract traffic data within a preset time period from the memory of the server according to preset data indicators. The preset time period is a time period with a granularity of seconds, including the current time.

[0047] The first data processing submodule is used to process the traffic data according to preset data retrieval rules to obtain the real-time traffic model.

[0048] Optionally, the first protection module includes: a protection module determination submodule, used to determine the protection module corresponding to the indicator data;

[0049] The indicator data sending submodule is used to send the indicator data to the protection module;

[0050] The first protection submodule is used to adjust the protection threshold corresponding to the protection module and adjust the protection rules of the protection module based on the indicator data.

[0051] Optionally, the second flow model generation module includes:

[0052] The second data extraction submodule is used to extract traffic data from the database of the server, based on preset data indicators, with an hourly granularity.

[0053] The second data processing submodule is used to process the traffic data according to preset data retrieval rules to obtain the processing result data;

[0054] The second traffic model generation submodule is used to supplement the real-time traffic model with the processing result data to obtain the historical traffic model.

[0055] Optionally, the traffic analysis module includes:

[0056] The time period determination submodule is used to determine the time period corresponding to the real-time traffic data;

[0057] The historical traffic data acquisition submodule is used to acquire historical traffic data for the same time period within the historical time frame from the historical traffic model.

[0058] The analysis result acquisition submodule is used to analyze the historical traffic data and the real-time traffic data to obtain the traffic analysis results.

[0059] Optionally, the second protection module includes:

[0060] The result enqueueing submodule is used to put the traffic analysis results into the subscription message queue;

[0061] The result sending submodule is used to send the traffic analysis results from the subscribed message queue to the corresponding protection module;

[0062] The second protection submodule is used to adjust the module threshold of the protection module and the protection rules of the protection module based on the traffic analysis results.

[0063] A third aspect of this application provides a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps described in the first aspect of this application.

[0064] A fourth aspect of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the method described in the first aspect of this application.

[0065] The traffic protection method provided in this application generates a corresponding real-time traffic model based on real-time traffic data in the server; obtains indicator data corresponding to at least one protection module from the real-time traffic model; adjusts the protection strategy corresponding to at least one protection module based on the indicator data, and executes corresponding protection measures; generates a historical traffic model based on the real-time traffic model based on historical traffic data in the server; obtains corresponding traffic analysis results based on the historical traffic model during the forwarding process of the real-time traffic data; and adjusts the protection strategy corresponding to at least one protection module based on the traffic analysis results, and executes corresponding protection measures.

[0066] In this method, real-time traffic data is analyzed to generate a real-time traffic model. Based on the real-time traffic model, corresponding indicator data is determined. The protection module adjusts the protection strategy according to the indicator data and executes corresponding protection measures to achieve real-time traffic protection. At the same time, a historical traffic model is generated based on historical traffic data. Based on the analysis of historical traffic, the protection strategy of the protection module is further adjusted to better execute the corresponding protection measures. This achieves real-time and precise protection against traffic attacks. Furthermore, the method can continuously learn and adjust the protection strategy to improve the protection effect against traffic attacks. Attached Figure Description

[0067] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0068] Figure 1 This is a flowchart of a traffic protection method proposed in an embodiment of this application;

[0069] Figure 2 This is a schematic diagram of the overall protection process linked to the traffic model proposed in one embodiment of this application;

[0070] Figure 3 This is a flowchart of the dynamic adjustment process for node protection proposed in one embodiment of this application;

[0071] Figure 4 This is a schematic diagram of a flow protection device according to an embodiment of this application;

[0072] Figure 5 This is a schematic diagram of an electronic device according to an embodiment of this application. Detailed Implementation

[0073] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0074] refer to Figure 1 , Figure 1 This is a flowchart of a traffic protection method proposed in an embodiment of this application. Figure 1 As shown, the method includes the following steps:

[0075] S11: Generate a corresponding real-time traffic model based on the real-time traffic data in the server.

[0076] In this embodiment, real-time traffic data refers to traffic data within a time period relatively close to the current time. The real-time traffic model is generated by extracting data from the real-time traffic data using data extraction rules. These rules can be customized, such as mean, peak value, normal distribution, 95 rule, etc.

[0077] In this embodiment, to prevent DDoS (Distributed Denial of Service) attacks, a network attack method that sends a large number of requests to a target server, rendering it unable to process or refusing further service, thus paralyzing the server, a real-time traffic model is generated to analyze the traffic data, and then corresponding protection modules are used for protection, and the protection strategy is adjusted.

[0078] In this embodiment, during the normal operation of the server, real-time traffic data is first obtained from the server's database, and then data is extracted from the real-time traffic data according to preset data extraction rules to generate a real-time traffic model.

[0079] In this embodiment, the specific steps for generating a corresponding real-time traffic model based on real-time traffic data in the server include:

[0080] S11-1: Extract traffic data within a preset time period from the server's memory according to preset data indicators. The preset time period is a time period with a granularity of seconds, including the current time.

[0081] In this embodiment, the data metric is the attribute type in the traffic data, and the preset time period is a time period with a granularity of seconds, including the current time.

[0082] In this embodiment, traffic data within a preset time period is extracted from the server's memory according to preset data metrics. The data in the server is pre-classified and stored according to attributes. During extraction, the location of the data storage for the corresponding attribute is found, and the latest stored data in seconds is directly retrieved. Alternatively, data from the most recent few seconds can be extracted.

[0083] In this embodiment, data metrics include host IP, VIP, machine group, PPS packet rate, bps bandwidth, SYNCFLOOD, IP FLOOD, and other attack types and peak attributes. Host IP refers to the host's network address, VIP refers to the virtual address, machine group refers to the relevant machine components of the server, and PPS is a commonly used unit of network throughput (i.e., how many data packets are sent per second). Network performance is usually measured using throughput. bps is an abbreviation for bits per second, representing the number of bits transmitted per second. In computer science and network communication, bps is often used to describe data transmission rate. The unit of bps is "bits per second" (bit / s or bps), where "bit" is the basic unit of binary numbers, and "second" represents a unit of time. The higher the bps value, the faster the data transmission speed. SYN Flood attack is a common denial-of-service (DoS) attack method that sends a large number of forged TCP connection requests (SYN packets), causing the victim server's half-open connection queue to fill up rapidly, thus making it unable to process legitimate connection requests. This attack exploits the three-way handshake process in the TCP / IP protocol. The attacker sends a large number of SYN packets but does not respond to the server's SYN-ACK packets, causing the server to have to maintain a large number of half-open connections, eventually exhausting its resources. IP FLOOD is a network attack technique, commonly used in DDoS (Distributed Denial-of-Service) attacks. An IP FLOOD attack sends a large number of IP packets to the target server, causing the server resources to be exhausted, making it unable to handle normal network requests, thus affecting service availability.

[0084] S11-2: The traffic data is processed according to preset data acquisition rules to obtain the real-time traffic model.

[0085] In this embodiment, traffic data is processed using preset data retrieval rules to obtain corresponding indicator data. This indicator data is then statistically analyzed to obtain a real-time traffic model. After determining the data retrieval rules, these rules are applied to the traffic data to extract the required data. Based on this data, a corresponding real-time traffic model is generated, reflecting the characteristics of the traffic data within the current time period.

[0086] In this embodiment, different data are retrieved using different data retrieval rules. Multiple data retrieval rules can be used simultaneously to process the data. For example, using the 95 rule, the top 5% of the current traffic data can be removed, and the largest value in the remaining 95% can be taken as the target value. This approach is suitable for scenarios with large amounts of data.

[0087] In this embodiment, data is extracted directly from the server's memory, eliminating the need to extract it from the database. This ensures the timeliness of real-time traffic data analysis and facilitates rapid response to traffic attacks.

[0088] In another embodiment of this application, before generating the corresponding real-time traffic model based on the real-time traffic data in the server, the method further includes:

[0089] S21: Obtain traffic data from the server's traffic logs and attack logs.

[0090] In this embodiment, traffic logs refer to records of information related to data traffic in the network, including the data source, destination, transmission protocol, port number, etc. By analyzing traffic logs, network administrators can understand the data flow in the network, thereby enabling network monitoring, performance optimization, and user behavior analysis. Attack logs refer to records left by attackers during various attack behaviors in a network security attack. These records typically include information such as the attacker's IP address, attack time, attack method, and attack target. Attack logs are crucial for network security analysis, attribution, and defense.

[0091] In this embodiment, traffic data is obtained from the server's traffic logs. The traffic logs contain attributes such as host IP, VIP, machine group, PPS packet rate, and BPS bandwidth. The attack logs contain attack types such as SYNC FLOOD and IP FLOOD, as well as peak values. Traffic data is obtained from both the traffic logs and the attack logs. This traffic data includes the basic data recorded in the traffic logs and the attack data recorded in the attack logs.

[0092] S22: Classify the traffic data according to the corresponding attributes to obtain the classified traffic data.

[0093] In this embodiment, traffic data is classified according to corresponding attributes to obtain classified traffic data. The original traffic logs and traffic data aggregated from multiple machines are combined, and data is dynamically generated based on configurable rules, such as periodically extracting data from traffic logs and attack logs, to represent dimensions such as overall server node performance, single machine performance, single VIP performance, single protection group performance, and attack type classification.

[0094] S23: Store the categorized traffic data in the server's memory according to the corresponding data metrics, and push it to the database asynchronously.

[0095] In this embodiment, the categorized traffic data is stored in the server's memory according to the corresponding data metrics and is asynchronously pushed to the database.

[0096] S12: Obtain the indicator data corresponding to at least one protection module from the real-time traffic model.

[0097] In this embodiment, the indicator data refers to the values ​​of data indicators in the traffic model. The protection module is a module encapsulated as a program that takes protective measures against traffic attacks.

[0098] In this embodiment, at least one indicator data corresponding to a protection module is obtained from the real-time traffic model through a corresponding algorithm. The algorithm can determine whether the value of each data indicator in the real-time traffic model is in a normal state. When the value of the data indicator is in an abnormal state, the indicator data is extracted from the traffic model, and the protection module corresponding to the indicator data is determined.

[0099] For example, if the bps bandwidth value is too high, the metric data will be sent to the protection module corresponding to the network bandwidth.

[0100] S13: Based on the indicator data, adjust the protection strategy corresponding to at least one of the protection modules, and execute the corresponding protection measures.

[0101] In this embodiment, after obtaining the indicator data, the corresponding protection module executes the corresponding protection measures based on the indicator, and adjusts the protection strategy based on the indicator, such as adjusting the threshold set by the module or adjusting the protection rules of the module.

[0102] In this embodiment, the specific steps for adjusting the protection strategy corresponding to at least one of the protection modules using the indicator data include:

[0103] S13-1: Determine the protection module corresponding to the indicator data.

[0104] In this embodiment, each protection module corresponds to a different type of attack and requires different indicator data. The corresponding protection module is determined based on the type of indicator data.

[0105] For example, a metric data point is the current value of bandwidth in bps. The corresponding type is the bandwidth type, and the corresponding protection module is the protection module against bandwidth attacks.

[0106] S13-2: Send the indicator data to the protection module.

[0107] In this embodiment, after determining the type of indicator data, the indicator data is sent to the corresponding protection module.

[0108] S13-4: Based on the indicator data, adjust the protection threshold corresponding to the protection module, and adjust the protection rules of the protection module.

[0109] In this embodiment, the protection threshold is a critical value. When the value of a certain data indicator exceeds or falls below the critical value, the corresponding protection measures are triggered. The protection rule is the rule by which the protection module executes the protection measures.

[0110] In this embodiment, after obtaining indicator data from the real-time traffic model, the corresponding protection engine (a program deployed on the host to detect DDoS attacks and provide protection functions such as cleaning; the corresponding security configuration of the SOC needs to be hot-loaded after being distributed to the engine machine to take effect. The engine generates different logs according to different modules) is activated. For example, SYNC and IP protection modules. After obtaining the indicator data, the corresponding modules adjust the corresponding protection thresholds and the protection rules of the protection modules according to the obtained indicator data.

[0111] For example, if the obtained metrics are within the range specified by the protection threshold, but still appear in the attack log, it is necessary to appropriately narrow down the scope of the protection threshold. Regarding protection rules, new rules can be added to address the issues identified in the existing rules.

[0112] S14: Generate a historical traffic model based on the historical traffic data in the server and the real-time traffic model.

[0113] In this embodiment, historical traffic data refers to traffic data generated by the server over a long period of time. The historical traffic model is generated by supplementing the real-time traffic model with historical traffic data.

[0114] In this embodiment, the server's database stores historical traffic data. Based on preset indicators, traffic data is extracted at the hourly level, i.e., data from the past several hours is extracted, or at the daily level, i.e., data from the past several days is extracted. The granularity can be set by the user. The extracted data is analyzed according to the corresponding data retrieval rules to obtain the analysis results. Based on the analysis results, the real-time traffic model is supplemented to obtain the historical traffic model.

[0115] In this embodiment, the specific steps for generating a historical traffic model based on the real-time traffic model using historical traffic data from the server include:

[0116] S14-1: Extract traffic data from the server's database in hourly increments according to preset data metrics.

[0117] In this embodiment, traffic data is extracted from the server's historical database based on preset data indicators, such as overall node, single machine, single VIP, single protection group, etc., with hourly granularity, and then traffic data from the past several hours is extracted.

[0118] S14-2: The traffic data is processed according to the preset data retrieval rules to obtain the processing result data.

[0119] In this embodiment, traffic data is processed using preset data retrieval rules to obtain processed result data. The processed result data consists of multiple data indicator values ​​obtained by processing traffic data from the past few hours using the data retrieval rules.

[0120] S14-3: The real-time traffic model is supplemented with the processing result data to obtain the historical traffic model.

[0121] In this embodiment, the real-time traffic model is supplemented by the processed data, and then a historical traffic model for a long time period of the node is generated based on the real-time traffic model at the granularity of hours or days.

[0122] In this embodiment, the historical traffic model can be continuously improved as data in the database is added.

[0123] S15: During the forwarding of the real-time traffic data, the corresponding traffic analysis results are obtained based on the historical traffic model.

[0124] In this embodiment, the traffic analysis results characterize whether the performance of each preset indicator in the real-time traffic data during the current period conforms to the values ​​in the historical period.

[0125] In this embodiment, during the forwarding of real-time traffic data, the historical traffic model can be used to determine whether the value of each data indicator remains at a normal level and whether the trend of change conforms to historical patterns, thereby obtaining the corresponding traffic analysis results.

[0126] In this embodiment, the specific steps for obtaining the corresponding traffic analysis results based on the historical traffic model during the forwarding of the real-time traffic data include:

[0127] S15-1: Determine the time period corresponding to the real-time traffic data.

[0128] In this embodiment, the time period corresponding to the real-time traffic data being forwarded is first determined, that is, the current time period is determined.

[0129] S15-2: Obtain historical traffic data for the same time period within the historical time frame from the historical traffic model.

[0130] In this embodiment, after determining the current time period, historical traffic data for the same time period in the historical time period is obtained from the historical traffic model.

[0131] S15-3: Analyze the historical traffic data and the real-time traffic data to obtain the traffic analysis results.

[0132] In this embodiment, the historical traffic data and real-time traffic data are analyzed to determine the changes in the values ​​of data indicators in the real-time traffic data compared to the values ​​in the historical traffic data, whether the trend of change conforms to the traffic change pattern, and thus obtain the values ​​of data indicators that do not meet the preset threshold as the traffic analysis result.

[0133] In this embodiment, it supports the generation of long-term historical traffic models of nodes at hourly and daily granularities based on real-time traffic models, with dynamic configuration. The traffic models are continuously improved by self-learning over time. Combined with resource data such as node bandwidth, more detailed and accurate analysis results are generated during real-time traffic forwarding based on configuration rules such as the usual simultaneous period and single VIP peak value, so as to provide decision-making support for subsequent processes.

[0134] S16: Based on the traffic analysis results, adjust the protection strategy corresponding to at least one of the protection modules, and execute the corresponding protection measures.

[0135] In this embodiment, the traffic analysis results are sent to the corresponding protection modules. Each protection module executes corresponding protection measures based on the traffic analysis results and adjusts the protection strategy. The specific steps include:

[0136] S16-1: Place the traffic analysis results into the subscription message queue.

[0137] In this embodiment, the message queue is used to provide corresponding messages to each protection module. When a protection module subscribes to a message, the message subscribed to by the protection module is sent to the protection module.

[0138] In this embodiment, the traffic analysis results are placed in the subscription message queue so that the corresponding traffic analysis results are sent to the protection module for the subscription message.

[0139] S16-2: Send the traffic analysis results from the subscription message queue to the corresponding protection module.

[0140] In this embodiment, the traffic analysis results include the values ​​of various data indicators. The corresponding protection module for each data indicator is determined, and the corresponding data indicator is sent to the protection module.

[0141] S16-3: Based on the traffic analysis results, adjust the module threshold of the protection module and adjust the protection rules of the protection module.

[0142] In this embodiment, after receiving the traffic analysis results, the protection module adjusts its module threshold and protection rules. By adjusting the threshold and rules of the protection module based on the traffic analysis results generated by the historical traffic model, the protection threshold and protection strategy of the protection module can better conform to the traffic change pattern, thereby improving the protection effect and protection efficiency.

[0143] In this embodiment, the analysis results are written to the corresponding spring event message, and the protection module subscribing to the message processes them according to the configured rules. The subscribers mainly include the engine's self-adjusting thresholds for various attack types, rule self-creation logic, local engine traffic redirection or black hole logic on nodes, backbone network front-end traffic suppression logic, and remote center SOC (Security Operations Center: a management platform mainly used to manage security configurations, monitor and analyze various network attacks, and collect and aggregate security data reports) data reporting and decision-making linkage. Plug-in message subscription is supported, and each logical subscription module supports configuring data indicator filtering rules; logic implementation is triggered only when the rules are met, achieving smarter decision-making and more precise protection.

[0144] In this embodiment, it supports packaging Spring Boot projects into executable JAR files; writing Dockerfiles to package Docker images; and supporting horizontal scaling deployment of the traffic protection program on server nodes using Docker Compose or Kubernetes clusters.

[0145] refer to Figure 2 , Figure 2 This is a schematic diagram of the overall protection process linked to the traffic model proposed in an embodiment of this application, as shown below. Figure 2As shown, anti-DDoS machines consist of multiple devices that prevent DDoS attacks. On the server, traffic and attack logs are reported to the System-on-Card (SOC). The data is analyzed and aggregated according to various dimensions, such as machine IP, VIP, attack type, and policy group, to obtain second-level atomic data. This data is then used to build a real-time traffic model, make policy decisions, and send data metrics to the corresponding protection modules. This enables node-local engine protection linkage. The measures implemented include analyzing and learning the node's VIP traffic model, intelligent threshold adjustment and alarm protection, analyzing and learning the attack types and trends of the node, automatically adjusting the corresponding type of protection, analyzing and learning the node's single-machine model, and adjusting the single-machine protection policies of other machines on the node in conjunction with the model. A long-term node traffic model (historical traffic model) is then created for risk assessment, alarms, and intelligent adjustment of protection policies. The node traffic model and protection policies are reported to the remote SOC for analysis. The attack traffic models of multiple nodes are linked for data analysis and evaluation, and decisions are made to generate a global protection policy which is then distributed to each node. Furthermore, the backbone network is linked for IP blocking and other pre-emptive protection to prevent DDoS attacks.

[0146] refer to Figure 3 , Figure 3 This is a flowchart of the dynamic adjustment process for node protection proposed in one embodiment of this application, as follows: Figure 3 As shown, when creating the real-time traffic model, it analyzes the attack types and peak trends of attack traffic, extracts and generates atomic data indicators according to rules, processes the data indicators, and generates a real-time traffic model based on rules such as mean, normal distribution, and 95 distribution. This is then combined with historical traffic models over long time periods for analysis and data processing to form analysis results. Based on the analysis results, it pushes subscription messages (spring events) for intelligent decision-making and takes protective measures, including: automatically adjusting the threshold of attack type-based policies, automatically creating protection policies for traffic scrubbing (a network security service mainly used to protect government and enterprise customers of IDC (Internet Data Center) services from DDoS attacks. Traffic scrubbing services ensure the security of customers' network environment by monitoring, alerting, and protecting against these attacks). It also generates risk assessment reports, implements intra-node coordinated protection, coordinates with backbone networks and other front-end networks for IP blocking, and reports to remote SOCs for multi-node coordinated protection.

[0147] In the above embodiments of this application, dynamic configuration of atomic data indicators is supported to form a rich data foundation, offering advantages such as rapid configuration and flexible selection. On one hand, storing data in memory enables faster data acquisition, shortens analysis result acquisition time, reduces latency, and achieves more real-time analysis; on the other hand, asynchronous storage in the database allows for more convenient use when linking historical models and node data with the remote central SOC. Dynamically configurable rules can be used to select atomic data indicators, enabling faster and more flexible acquisition of multi-dimensional real-time traffic models. After obtaining data results from the real-time data model according to corresponding algorithms, the engine's SYNC, IP, and other attack type protection modules are linked to perform self-adjustment of protection policy thresholds and self-generation of protection rules, achieving intelligent adjustment and second-level protection at the first layer. It supports continuous learning and analysis based on configured rules to form long-term traffic historical models with hourly or daily granularity, and combines this with resource data such as node bandwidth to implement corresponding data analysis algorithms. During real-time traffic forwarding, more detailed and accurate analysis results are generated according to configured rules such as simultaneous time period, same group, and same VIP. After the analysis results are written to Spring Event messages, pluggable message subscription is supported, allowing for dynamic changes to logic processing modules at any time. This makes it more extensible, and each logic subscription module supports configuring data metric filtering rules. Logic implementation is only triggered when the rules are met, achieving smarter and more precise protection. The processing logic focuses on automatically adjusting thresholds and creating protection rules based on local attack traffic patterns on each node. This makes it more adaptable to the actual operating conditions of the nodes. It can also be extended with multi-node linkage, backbone network linkage, and other functions to continuously enrich protection decision-making measures and support flexible rule adjustments for more intelligent decision-making. Furthermore, it can package Spring Boot projects into executable JARs; create Docker images using Dockerfiles; and support horizontal scaling with Dockercompose or Kubernetes clusters to add the protection program to service nodes, improving the flexibility of protection. This effectively improves the protection efficiency against DDoS traffic attacks and ensures the stable operation of the server.

[0148] Based on the same inventive concept, one embodiment of this application provides a flow protection device. (Reference) Figure 4 , Figure 4 This is a schematic diagram of a flow protection device 400 according to an embodiment of this application. Figure 4 As shown, the device includes:

[0149] The first traffic model generation module 401 is used to generate a corresponding real-time traffic model based on the real-time traffic data in the server.

[0150] The indicator data acquisition module 402 is used to acquire indicator data corresponding to at least one protection module from the real-time traffic model;

[0151] The first protection module 403 is used to adjust the protection strategy corresponding to at least one of the protection modules based on the indicator data, and to execute the corresponding protection measures.

[0152] The second traffic model generation module 404 is used to generate a historical traffic model based on the real-time traffic model according to the historical traffic data in the server.

[0153] Traffic analysis module 405 is used to obtain corresponding traffic analysis results based on the historical traffic model during the forwarding process of the real-time traffic data;

[0154] The second protection module 406 is used to adjust the protection strategy corresponding to at least one of the protection modules based on the traffic analysis results, and to execute the corresponding protection measures.

[0155] Optionally, the device further includes:

[0156] The traffic data acquisition module is used to acquire traffic data from the server's traffic logs and attack logs;

[0157] The traffic data classification module is used to classify the traffic data according to corresponding attributes to obtain the classified traffic data;

[0158] The traffic data storage module is used to store the classified traffic data in the memory of the server according to the corresponding data indicators, and to push it to the database asynchronously.

[0159] Optionally, the first traffic model generation module includes:

[0160] The first data extraction submodule is used to extract traffic data within a preset time period from the memory of the server according to preset data indicators. The preset time period is a time period with a granularity of seconds, including the current time.

[0161] The first data processing submodule is used to process the traffic data according to preset data retrieval rules to obtain the real-time traffic model.

[0162] Optionally, the first protection module includes: a protection module determination submodule, used to determine the protection module corresponding to the indicator data;

[0163] The indicator data sending submodule is used to send the indicator data to the protection module;

[0164] The first protection submodule is used to adjust the protection threshold corresponding to the protection module and adjust the protection rules of the protection module based on the indicator data.

[0165] Optionally, the second flow model generation module includes:

[0166] The second data extraction submodule is used to extract traffic data from the database of the server, based on preset data indicators, with an hourly granularity.

[0167] The second data processing submodule is used to process the traffic data according to preset data retrieval rules to obtain the processing result data;

[0168] The second traffic model generation submodule is used to supplement the real-time traffic model with the processing result data to obtain the historical traffic model.

[0169] Optionally, the traffic analysis module includes:

[0170] The time period determination submodule is used to determine the time period corresponding to the real-time traffic data;

[0171] The historical traffic data acquisition submodule is used to acquire historical traffic data for the same time period within the historical time frame from the historical traffic model.

[0172] The analysis result acquisition submodule is used to analyze the historical traffic data and the real-time traffic data to obtain the traffic analysis results.

[0173] Optionally, the second protection module includes:

[0174] The result enqueueing submodule is used to put the traffic analysis results into the subscription message queue;

[0175] The result sending submodule is used to send the traffic analysis results from the subscribed message queue to the corresponding protection module;

[0176] The second protection submodule is used to adjust the module threshold of the protection module and the protection rules of the protection module based on the traffic analysis results.

[0177] Based on the same inventive concept, another embodiment of this application provides a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the traffic protection method as described in any of the above embodiments of this application.

[0178] Based on the same inventive concept, another embodiment of this application provides an electronic device. Figure 5 This is a schematic diagram of an electronic device 500 according to an embodiment of this application, including a memory 501, a processor 502, and a computer program stored in the memory and executable on the processor. When executed by the processor, the program implements the steps in the traffic protection method described in any of the above embodiments of this application.

[0179] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0180] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0181] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, or computer program products. Therefore, embodiments of this application can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of this application can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0182] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0183] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0184] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0185] Although preferred embodiments of the present application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.

[0186] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0187] The above provides a detailed description of the traffic protection method, apparatus, device, and storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A method for preventing traffic flow, characterized in that, The method includes: Generate a corresponding real-time traffic model based on real-time traffic data from the server; Obtain at least one indicator data corresponding to a protection module from the real-time traffic model; Based on the aforementioned indicator data, the protection strategy corresponding to at least one of the protection modules is adjusted, and corresponding protection measures are implemented, including: Determine the protection module corresponding to the indicator data; The indicator data is sent to the protection module; Based on the aforementioned indicator data, the protection threshold corresponding to the protection module is adjusted, and the protection rules of the protection module are also adjusted. Based on the historical traffic data in the server, a historical traffic model is generated on the basis of the real-time traffic model. During the forwarding of the real-time traffic data, the corresponding traffic analysis results are obtained based on the historical traffic model; Based on the traffic analysis results, the protection strategy adjusted using the indicator data is further adjusted, and corresponding protection measures are implemented, including: The traffic analysis results are then placed into the subscription message queue; The traffic analysis results are sent from the subscription message queue to the corresponding protection module; Based on the traffic analysis results, the module threshold of the protection module is dynamically adjusted, and corresponding protection rules are created or deleted for the protection module.

2. The flow protection method according to claim 1, characterized in that, Before generating the corresponding real-time traffic model based on the real-time traffic data in the server, the method further includes: Obtain traffic data from the server's traffic logs and attack logs; The traffic data is classified according to its corresponding attributes to obtain the classified traffic data; The categorized traffic data is stored in the server's memory according to the corresponding data metrics and asynchronously pushed to the database.

3. The flow protection method according to claim 1, characterized in that, The step of generating a corresponding real-time traffic model based on real-time traffic data from the server includes: Traffic data within a preset time period is extracted from the server's memory according to preset data indicators. The preset time period is a time period with a granularity of seconds, including the current time. The traffic data is processed using preset data retrieval rules to obtain the real-time traffic model.

4. The flow protection method according to claim 1, characterized in that, The step of generating a historical traffic model based on the real-time traffic model using historical traffic data from the server includes: Traffic data is extracted from the server's database at an hourly granularity based on preset data metrics. The traffic data is processed according to preset data retrieval rules to obtain the processing result data; The historical traffic model is obtained by supplementing the real-time traffic model with the processing result data.

5. The flow protection method according to claim 1, characterized in that, During the forwarding of the real-time traffic data, the corresponding traffic analysis results are obtained based on the historical traffic model, including: Determine the time period corresponding to the real-time traffic data; Obtain historical traffic data for the same time period within the historical time frame from the historical traffic model; The historical traffic data and the real-time traffic data are analyzed to obtain the traffic analysis results.

6. A flow protection device, characterized in that, The device includes: The first traffic model generation module is used to generate a corresponding real-time traffic model based on the real-time traffic data in the server. The indicator data acquisition module is used to acquire indicator data corresponding to at least one protection module from the real-time traffic model; The first protection module is used to adjust the protection strategy corresponding to at least one of the protection modules based on the indicator data, and to execute corresponding protection measures, including: Determine the protection module corresponding to the indicator data; The indicator data is sent to the protection module; Based on the aforementioned indicator data, the protection threshold corresponding to the protection module is adjusted, and the protection rules of the protection module are also adjusted. The second traffic model generation module is used to generate a historical traffic model based on the real-time traffic model according to the historical traffic data in the server. The traffic analysis module is used to obtain corresponding traffic analysis results based on the historical traffic model during the forwarding of the real-time traffic data. The second protection module is used to further adjust the protection strategy adjusted based on the traffic analysis results and the indicator data, and to execute corresponding protection measures, including: The traffic analysis results are then placed into the subscription message queue; The traffic analysis results are sent from the subscription message queue to the corresponding protection module; Based on the traffic analysis results, the module threshold of the protection module is dynamically adjusted, and corresponding protection rules are created or deleted for the protection module.

7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 5.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Generation method and device of hostile attack traffic and electronic equipment

    CN118611977A

  • DDoS log convergence method and system

    CN118827173A