Collaborative mitigation architecture and method against DDoS attacks
By extracting feature fingerprints and generating global mitigation strategies in a multi-layered network space, and utilizing the cooperative instruction API to transmit strategies, the shortcomings of existing defense architectures in the face of new and complex DDoS attacks are solved, achieving stronger defense capabilities and a flexible network security solution.
Patent Information
- Application Number
- CN202411934116.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2044-12-25
AI Technical Summary
Existing collaborative defense architectures are insufficient in defending against new and complex network attacks with high intensity and strong adversarial characteristics, especially security threats against the QUIC protocol, segment scanning attacks, and anthropomorphic attacks, which are difficult to effectively resist.
A collaborative mitigation architecture for DDoS attacks is adopted. The feature extraction module extracts feature fingerprints of multi-level network space, and the mitigation strategy generation module generates a global mitigation strategy based on the constructed DDoS attack mitigation strategy knowledge graph. The strategy distribution module coordinates the instruction API to transmit the mitigation strategy to each level of network space, thereby realizing global traffic scheduling and handling.
It improves the defense capabilities against new and complex network attacks with high intensity and strong adversarial characteristics, enhances the defense effect against DDoS attacks, and adapts to complex and ever-changing network attack environments.
Smart Images

Figure CN119814426B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to an anti-DDoS attack cooperative mitigation architecture and method. BACKGROUND
[0002] With the development of the network, Distributed Denial of Service (DDoS) attacks have become a normal threat in the field of network security, and frequent attacks are launched against various websites, servers and infrastructures. The current situation of DDoS attacks presents characteristics such as high frequency, large scale and diversification of means, which brings great challenges to network security. At present, the enterprise end-side attack defense strategy cannot solve the upstream link congestion; however, the operator has the advantage of link pipeline, but due to the difficulty of coordination of different levels of network demand, the difficulty of balancing detection costs and other factors, the detection and disposal precision is not enough, and the detection ability of new attack types is weak. Simply relying on single-sided defense technology has been difficult to effectively resist emerging complex DDoS attack patterns. Therefore, it is urgent to explore a usable cooperative defense architecture.
[0003] The existing cooperative defense architecture mainly opens an interface to the end side from the network side. When the end side encounters a large flow attack that threatens the network bandwidth, cloud cleaning or cleaning alliance can be triggered to protect enterprise business and network bandwidth. Among them, the cleaning alliance manages and schedules DDoS cleaning resources in the alliance to provide powerful DDoS near-source cloud cleaning services for users, and can also solve the network congestion problem of the upstream pipeline to protect the upstream bandwidth.
[0004] However, the existing cooperative defense method can solve the link congestion problem when a large flow attack occurs, but it still lacks the ability to defend against new complex network attacks with high intensity and strong confrontation characteristics, such as the security threat of Quick User Datagram Protocol Internet Connections (QUIC) protocol, segment scanning attacks, and anthropomorphic attacks. SUMMARY
[0005] The present application provides an anti-DDoS attack cooperative mitigation architecture and method to solve the technical problem of insufficient defense capability against new complex network attacks with high intensity and strong confrontation characteristics.
[0006] In a first aspect, the present application provides an anti-DDoS attack cooperative mitigation architecture, comprising:
[0007] The feature extraction module is configured to, in response to detecting a distributed denial of service (DDoS) attack, extract a target traffic fingerprint of a corresponding hierarchical network space based on a feature fingerprint corresponding to each hierarchical network space in a multi-level network space, and transmit the target traffic fingerprint to the mitigation strategy generation module, wherein the multi-level network space includes an access network, an intra-domain network, and an inter-domain network.
[0008] The mitigation strategy generation module is configured to, in response to receiving the target traffic fingerprint, construct a global DDoS attack mitigation strategy based on a constructed DDoS attack mitigation strategy knowledge graph, and transmit the global DDoS attack mitigation strategy to the strategy distribution module, wherein the DDoS attack mitigation strategy knowledge graph reflects a correspondence between the feature fingerprint, the attack type, and the DDoS attack mitigation strategy.
[0009] The strategy distribution module is configured to transmit the DDoS attack mitigation strategy to the corresponding hierarchical network space through a cooperative instruction API based on the global DDoS attack mitigation strategy.
[0010] Optionally, in the above DDoS attack cooperative mitigation architecture, the mitigation strategy generation module is specifically configured to:
[0011] The mitigation strategy generation module is configured to search for the global DDoS attack mitigation strategy corresponding to the target traffic fingerprint in the constructed DDoS attack mitigation strategy knowledge graph through a link association search technology.
[0012] Optionally, in the above DDoS attack cooperative mitigation architecture, the mitigation strategy generation module further includes:
[0013] The cooperative control module is configured to collect and analyze traffic data information of the hierarchical network space to evaluate an anti-DDoS attack effect of executing the DDoS attack mitigation strategy in the corresponding hierarchical network space, and update the DDoS attack mitigation strategy knowledge graph and / or the feature fingerprint of the corresponding hierarchical network space according to the anti-DDoS attack effect.
[0014] Optionally, in the above DDoS attack cooperative mitigation architecture, the cooperative control module is specifically configured to:
[0015] The cooperative control module is configured to analyze the traffic data information of the hierarchical network space to obtain a traffic curve of the hierarchical network space after executing the DDoS attack mitigation strategy, wherein the traffic curve reflects the anti-DDoS attack effect.
[0016] The cooperative control module is configured to update the DDoS attack mitigation strategy knowledge graph according to the anti-DDoS attack effect, including: if the traffic curve contains traffic greater than a traffic threshold, deleting, in the DDoS attack mitigation strategy knowledge graph, a correspondence between the DDoS attack mitigation strategy executed in the corresponding hierarchical network space and the target traffic fingerprint of the corresponding hierarchical network space.
[0017] Optionally, in the above anti-DDoS attack collaborative mitigation architecture, the feature extraction module is further used to:
[0018] Obtain historical traffic in hierarchical network space, which includes normal traffic and multiple attack traffic;
[0019] Obtain the attack type corresponding to each attack flow in multiple attack flows;
[0020] Determine the contribution of the eigenvalue corresponding to each target feature to each attack type. The target features are determined through feature engineering techniques; the contribution is determined using a preset random forest model.
[0021] According to the corresponding contribution of each target feature, the feature fingerprint corresponding to the hierarchical network space is determined.
[0022] Optionally, in the above anti-DDoS attack collaborative mitigation architecture, the mitigation strategy generation module is further used to:
[0023] Obtaining the first relationship between the characteristic fingerprints of different layers of network space and the attack type, and the second relationship between the attack type and the anti-DDoS attack mitigation strategy of different layers of network space;
[0024] Based on the first and second relationships, an initial anti-DDoS attack mitigation strategy knowledge graph is constructed;
[0025] Based on the initial anti-DDoS attack mitigation strategy knowledge graph, the third relationship between the feature fingerprint and the anti-DDoS attack mitigation strategy is determined through knowledge reasoning;
[0026] According to the third relationship, the initial anti-DDoS attack mitigation strategy knowledge graph is optimized to obtain the anti-DDoS attack mitigation strategy knowledge graph.
[0027] In a second aspect, the present application provides a collaborative mitigation method for anti-DDoS attacks, including:
[0028] In response to detecting a distributed denial of service (DDoS) attack, the feature extraction module extracts a target traffic fingerprint of each layer of the network space based on a feature fingerprint corresponding to each layer of the multi-layer network space, and transmits the target traffic fingerprint to the mitigation strategy generation module. The multi-layer network space includes an access network, an intra-domain network, and an inter-domain network.
[0029] The mitigation strategy generation module responds to receiving the target traffic fingerprint and, based on the established anti-DDoS attack mitigation strategy knowledge graph, constructs a global anti-DDoS attack mitigation strategy according to the target traffic fingerprint and transmits the global anti-DDoS attack mitigation strategy to the strategy distribution module. The anti-DDoS attack mitigation strategy knowledge graph reflects the correspondence between feature fingerprints, attack types, and anti-DDoS attack mitigation strategies.
[0030] The policy distribution module transmits the anti-DDoS attack mitigation policy to the corresponding hierarchical network space through the cooperative instruction API based on the global anti-DDoS attack mitigation policy.
[0031] Optionally, the method as above, based on the constructed anti-DDoS attack mitigation policy knowledge graph, constructs a global anti-DDoS attack mitigation policy according to the target traffic fingerprint, comprising:
[0032] Through the link association search technology, the global anti-DDoS attack mitigation policy corresponding to the traffic fingerprint is searched in the constructed anti-DDoS attack mitigation policy knowledge graph.
[0033] Optionally, the method as above further comprises:
[0034] The cooperative control module collects and analyzes the traffic data information of the hierarchical network space to evaluate the anti-DDoS attack effect of executing the anti-DDoS attack mitigation policy on the corresponding hierarchical network space, and updates the anti-DDoS attack mitigation policy knowledge graph and / or the feature fingerprint of the corresponding hierarchical network space according to the anti-DDoS attack effect.
[0035] In a third aspect, the present application provides an anti-DDoS attack cooperative mitigation device, comprising:
[0036] The first transmission module is configured to extract a target traffic fingerprint of the corresponding hierarchical network space based on the feature fingerprint corresponding to each hierarchical network space in the multi-level network space respectively in response to the detection of the distributed denial of service (DDoS) attack by the feature extraction module, and transmit the target traffic fingerprint to the mitigation policy generation module, wherein the multi-level network space comprises an access network, an intra-domain network and an inter-domain network;
[0037] The second transmission module is configured to construct a global anti-DDoS attack mitigation policy according to the target traffic fingerprint based on the constructed anti-DDoS attack mitigation policy knowledge graph in response to the reception of the target traffic fingerprint by the mitigation policy generation module, and transmit the global anti-DDoS attack mitigation policy to the policy distribution module, wherein the anti-DDoS attack mitigation policy knowledge graph reflects the correspondence among the feature fingerprint, the attack type and the anti-DDoS attack mitigation policy;
[0038] The third transmission module is configured to transmit the anti-DDoS attack mitigation policy to the corresponding hierarchical network space through the cooperative instruction API based on the global anti-DDoS attack mitigation policy by the policy distribution module.
[0039] In a third aspect, the present application provides an electronic device, comprising: a memory, a processor;
[0040] The memory stores computer execution instructions;
[0041] The processor executes the computer-executed instructions stored in the memory, so that the processor executes the first aspect and / or various possible implementation manners of the first aspect.
[0042] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, and the computer-readable storage medium stores computer-executed instructions. When the computer-executed instructions are executed by a processor, the computer-executed instructions are used to implement the first aspect and / or various possible implementation manners of the first aspect.
[0043] In a fifth aspect, an embodiment of the present application provides a computer program product, and the computer program product includes a computer program. When the computer program is executed by a processor, the computer program implements the first aspect and / or various possible implementation manners of the first aspect.
[0044] The anti-DDoS attack cooperative mitigation architecture and method provided by the present application include a feature extraction module, a mitigation strategy generation module, and a strategy distribution module. In response to detecting a distributed denial of service (DDoS) attack, the feature extraction module extracts a target traffic fingerprint of a corresponding hierarchical network space based on a feature fingerprint corresponding to each hierarchical network space in a multi-level network space, and transmits the target traffic fingerprint to the mitigation strategy generation module. The multi-level network space includes an access network, an intra-domain network, and an inter-domain network. By extracting the target traffic fingerprint of the corresponding hierarchical network space according to the feature fingerprints of the multiple hierarchical network spaces, the multi-layer traffic features can be utilized. The mitigation strategy generation module, in response to receiving the target traffic fingerprint, constructs a global anti-DDoS attack mitigation strategy based on a constructed anti-DDoS attack mitigation strategy knowledge graph according to the target traffic fingerprint, and transmits the global anti-DDoS attack mitigation strategy to the strategy distribution module. The anti-DDoS attack mitigation strategy knowledge graph reflects the correspondence between the feature fingerprint, the attack type, and the anti-DDoS attack mitigation strategy. By determining the global anti-DDoS attack mitigation strategy according to the target traffic fingerprint, the multi-layer traffic features can be utilized, thereby generating a multi-layer DDoS attack mitigation strategy, so as to better defend against DDoa attacks. The strategy distribution module, based on the global anti-DDoS attack mitigation strategy, transmits the anti-DDoS attack mitigation strategy to the corresponding hierarchical network space through a cooperative instruction API. Transmitting the anti-DDoS attack mitigation strategy to the corresponding hierarchical network space enables the hierarchical network spaces to defend against DDoa attacks in all directions, thereby improving the defense effect. BRIEF DESCRIPTION OF DRAWINGS
[0045] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the application.
[0046] Figure 1 FIG. 1 is a structural schematic diagram of an anti-DDoS attack cooperative architecture provided by an embodiment of the present application.
[0047] Figure 2 A structural schematic diagram of an anti-DDoS attack mitigation strategy knowledge graph provided for an embodiment of the present application;
[0048] Figure 3 A multi-layer network space schematic diagram provided for the present application;
[0049] Figure 4 A flowchart of an anti-DDoS attack collaborative mitigation method provided for an embodiment of the present application;
[0050] Figure 5 A flowchart of another anti-DDoS attack collaborative mitigation method provided for an embodiment of the present application;
[0051] Figure 6 A structural schematic diagram of an anti-DDoS attack collaborative mitigation device provided for an embodiment of the present application;
[0052] Figure 7 An electronic device structural schematic diagram provided for an embodiment of the present application.
[0053] Through the above-mentioned drawings, the specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application by any means, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0054] The exemplary embodiments will be described in detail herein with reference to the attached drawings. In the following description, the same numbers are used to indicate the same or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not meant to represent all implementations consistent with the present application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the present application as detailed in the appended claims.
[0055] At present, with the development of the network, DDoS attacks have become a normal threat in the field of network security, and frequent attacks are launched against various websites, servers and infrastructure. The current situation of DDoS attacks presents the characteristics of high frequency, large scale and diversified means, which brings great challenges to network security. At present, the enterprise end attack defense strategy cannot solve the upstream link congestion; however, the operators have the advantage of link pipeline, but due to the difficulty of coordination of different levels of network demand, the difficulty of balancing detection cost and other factors, the detection and disposal are not fine enough, and the detection ability of new attack is weak. Simply relying on unilateral defense technology has been difficult to effectively resist the emerging complex DDoS attack mode. It is urgent to explore a usable collaborative defense architecture.
[0056] The application provides an anti-DDoS attack cooperative mitigation architecture and method. Through cooperation between modules, a feature extraction module is arranged to extract feature fingerprints of different hierarchical network spaces, a mitigation strategy generation module is arranged to determine a global anti-DDoS attack mitigation strategy according to fingerprint features of corresponding hierarchical spaces and an anti-DDoS attack mitigation strategy knowledge graph, the global anti-DDoS attack mitigation strategy can defend against traffic attacks of different hierarchical network spaces, and finally a strategy distribution module is arranged, and through a cooperative instruction API, the anti-DDoS attack mitigation strategy can be accurately and timely transmitted to the corresponding hierarchical network space, so that through the three modules of the feature extraction module, the mitigation strategy generation module and the strategy distribution module, the traffic features (i.e. feature fingerprints) of each network space can be effectively utilized to realize global vision traffic scheduling and disposal, thereby enhancing the defense effect of DDoS attacks.
[0057] The technical solutions of the application and how the technical solutions of the application solve the above technical problems will be described in detail below with specific examples. The following specific examples can be combined with each other, and the same or similar concepts or processes can not be described again in some examples. The embodiments of the application will be described below with reference to the drawings.
[0058] Figure 1 A structure diagram of an anti-DDoS attack cooperative mitigation architecture provided by an embodiment of the application is shown in the figure. The execution subject can be software implementation and / or hardware implementation, such as Figure 1 As shown, it includes:
[0059] The feature extraction module is configured to, in response to detecting a distributed denial of service (DDoS) attack, extract target traffic fingerprints of corresponding hierarchical network spaces based on feature fingerprints corresponding to each hierarchical network space in the multi-level network space, and transmit the target traffic fingerprints to the mitigation strategy generation module. The multi-level network space includes an access network, an intra-domain network, and an inter-domain network.
[0060] The distributed denial of service (DDoS) attack is a malicious attempt to flood a target server, service, or network with a large amount of network traffic to make it unable to function normally. DDoS attacks usually involve the coordinated work of multiple computer systems, which are usually part of a "botnet" infected by malicious software and controlled remotely by an attacker.
[0061] The access network represents an edge network or node, such as an enterprise network, a cloud vendor, etc. The intra-domain network represents a network with the same jurisdiction, such as a backbone network, a metropolitan area network, etc. The inter-domain network represents a network boundary and an interconnection area with other networks, such as an operator interconnection layer.
[0062] Feature fingerprint: for traffic features, including packet size, transmission time interval, protocol type, traffic pattern, etc.
[0063] The target traffic fingerprint of different levels of network space is different, and the target traffic fingerprint includes high-level features, middle-level features and low-level features. Specifically, the inter-domain network corresponds to the high-level features, the intra-domain network corresponds to the middle-level features, and the access network corresponds to the low-level features. The high-level features are shown in Table 1, the middle-level features are shown in Table 2, and the low-level features are shown in Table 3.
[0064] Table 1
[0065]
[0066] Table 2
[0067]
[0068]
[0069] Table 3
[0070]
[0071] Through the traffic fingerprint technology, a distributed denial of service (DDoS) attack is detected, and then the high-level features corresponding to the inter-domain network, the middle-level features corresponding to the intra-domain network, and the low-level features corresponding to the access network in the traffic attack are identified. Then, the high-level features, the low-level features, and the middle-level features are sent to the mitigation strategy generation module.
[0072] The mitigation strategy generation module is configured to respond to receiving the target traffic fingerprint, construct a global anti-DDoS attack mitigation strategy based on the constructed anti-DDoS attack mitigation strategy knowledge graph according to the target traffic fingerprint, and transmit the global anti-DDoS attack mitigation strategy to the strategy distribution module. The anti-DDoS attack mitigation strategy knowledge graph reflects the correspondence between the feature fingerprint, the attack type and the anti-DDoS attack mitigation strategy.
[0073] Wherein, Figure 2A structural schematic diagram of an anti-DDoS attack mitigation strategy knowledge graph provided in an embodiment of the present application, wherein SYN Flood represents an attack type, (SYN flood) is a common denial of service (Denial of Service, DoS) attack, especially an attack on the transmission control protocol (TCP (Transmission Control Protocol, Transmission Control Protocol)). Its purpose is to consume the resources of the server so that it cannot handle legitimate requests. The source authentication strategy and the abnormal session check are anti-DDoS attack mitigation strategies. The source authentication strategy refers to verifying the authenticity of the access source according to the syn (synchronize) packet, and the cleaning device replies a reset packet to clean the abnormal traffic. The abnormal session check refers to checking the number of sent packets or connections within a certain period of time. If it exceeds a certain frequency, it is determined to be abnormal, and the corresponding traffic is cleaned. The feature fingerprint is the traffic size feature, the time distribution feature, the network boundary feature, the routing path feature, and the packet feature. The traffic size feature and the time distribution feature belong to high-level features, the network boundary feature and the routing path feature belong to middle-level features, and the packet feature belongs to low-level features. The attack type, the feature fingerprint, and the anti-DDoS attack mitigation strategy are connected through edges.
[0074] Upon receiving the target traffic fingerprint (including high-level features (i.e., traffic size features and time distribution features), middle-level features (network boundary features and routing path features), and low-level features (i.e., packet features)), based on the constructed anti-DDoS attack mitigation strategy knowledge graph, the attack type is determined to be SYN Flood, and then the global anti-DDoS attack mitigation strategy is determined to be the source authentication strategy and the abnormal session check. Then, the global anti-DDoS attack mitigation strategy is transmitted to the strategy distribution module.
[0075] In the embodiment of the present application, based on the constructed anti-DDoS attack mitigation strategy knowledge graph, the mitigation strategy generation module is specifically configured to:
[0076] By link association search technology, the global anti-DDoS attack mitigation strategy corresponding to the target traffic fingerprint is searched in the constructed anti-DDoS attack mitigation strategy knowledge graph.
[0077] Among them, the link key search technology usually involves identifying and analyzing key links or nodes in the network to ensure the reliability, performance and security of the network. This technology is of great significance in network design, optimization and troubleshooting.
[0078] After receiving the target traffic fingerprint, the link correlation search technology is activated to retrieve the corresponding mitigation strategies at different layers. The target traffic fingerprint corresponding to the traffic characteristics is determined. In this application, the link correlation search technology is used to add the mitigation strategies at different layers to the anti-DDoS attack mitigation strategy knowledge graph. By combining the target traffic fingerprint and the anti-DDoS attack mitigation strategy knowledge graph, the anti-DDoS attack mitigation strategy can be determined.
[0079] Specifically, Figure 3 A multi-layer network space schematic diagram provided for this application, such as Figure 3 As shown, the inter-domain network is at a high position, the intra-domain network is at a middle position, and the access network is at a low position.
[0080] The inter-domain network is at a high level, and a high-level mitigation strategy is executed at a high level. The high-level mitigation strategy includes: ACL (Access Control List, access control list), traffic scheduling, etc.
[0081] The intra-domain network is at the median level, where median mitigation strategies are implemented. These strategies include UDP (User Datagram Protocol) rate limiting and UDF FLOOD defense strategies. FLOOD usually refers to a denial of service (DoS) attack, in which an attacker floods the target system or network with a large number of requests, preventing it from providing normal services.
[0082] The access network is at a low level, and a low-level mitigation strategy is implemented at a low level. The low-level mitigation strategy includes: more application layer defense strategies based on the middle level, such as CNAME (Canonical Name) source authentication strategy, HTTP (Hypertext Transfer Protocol) defense strategy, etc.
[0083] The high, medium, and low levels represent attack types. The attack traffic size corresponding to each layer ranges from terabytes (TB) to gigabytes (GB) to megabytes (MB), depending on network bandwidth. The low level can obtain corresponding packet information and can handle application-layer attacks, as well as persona attacks and segment sweep attacks. Large-scale persona attacks or segment sweep attacks are difficult to detect at the high and medium levels, while the low level can be detected but cannot be defended against due to limited defense capabilities. Therefore, based on the target traffic fingerprints of the high, medium, and low levels, anti-DDoS attack mitigation policies are issued at each level, providing refined layer-by-layer response.
[0084] The advantage of this setting is that it can mitigate attacks at all levels through anti-DDoS attack mitigation strategies, thereby improving defense effectiveness.
[0085] a policy distribution module configured to transmit the anti-DDoS attack mitigation policy to the corresponding hierarchical network space through a collaborative command API based on the global anti-DDoS attack mitigation policy.
[0086] The collaborative command API generally refers to an interface that allows multiple systems, applications or services to operate in collaboration.
[0087] Through the collaborative command API, a fast and stable communication channel can be established between high, medium and low levels (i.e., different network levels or management levels). Through this channel, the system can quickly distribute the anti-DDoS attack mitigation policy to the relevant nodes at each level and instruct them to perform the corresponding defense operations according to the anti-DDoS attack mitigation policy requirements.
[0088] The anti-DDoS attack collaborative mitigation architecture provided by the embodiments of the present application can extract the target traffic fingerprint of the corresponding hierarchical network space according to the feature fingerprint corresponding to each hierarchical network space in the multi-level network space through the feature extraction module, generate a global anti-DDoS attack mitigation policy based on the constructed anti-DDoS attack mitigation policy knowledge graph according to the target traffic fingerprint of the corresponding hierarchical network space through the mitigation policy generation module, and transmit the anti-DDoS attack mitigation policy to the corresponding hierarchical network space through the collaborative command API through the policy distribution module. Therefore, the defense capability can be improved for new complex network attacks with high intensity and strong confrontation characteristics.
[0089] In the above embodiments of the present application, the following are further included:
[0090] a collaborative control module configured to collect and analyze traffic data information of the hierarchical network space to evaluate the anti-DDoS attack effect of executing the anti-DDoS attack mitigation policy in the corresponding hierarchical network space, and update the anti-DDoS attack mitigation policy knowledge graph and / or the feature fingerprint of the corresponding hierarchical network space according to the anti-DDoS attack effect.
[0091] The traffic data information refers to the traffic change before and after executing the anti-DDoS attack mitigation policy.
[0092] The anti-DDoS attack effect of executing the anti-DDoS attack mitigation policy in the corresponding hierarchical network space is evaluated through the traffic change before and after executing the anti-DDoS attack mitigation policy, and the feature fingerprint of the corresponding hierarchical network space in the anti-DDoS attack mitigation policy knowledge graph or / and the anti-DDoS attack mitigation policy is updated according to the anti-DDoS attack effect.
[0093] The advantage of such an arrangement is that the cooperative control module can provide a comprehensive and flexible DDoS attack mitigation solution by combining real-time monitoring, dynamic policy adjustment, and knowledge updating, adapting to complex and changing network attack environments.
[0094] In the above embodiments of the present application, the cooperative control module is specifically used for:
[0095] analyzing traffic data information of the hierarchical network space to obtain a traffic curve of the hierarchical network space after executing the DDoS attack mitigation strategy, the traffic curve reflecting the DDoS attack mitigation effect;
[0096] updating the DDoS attack mitigation strategy knowledge graph according to the DDoS attack mitigation effect, including: if the traffic curve contains traffic greater than a traffic threshold, deleting the corresponding relationship between the DDoS attack mitigation strategy executed by the corresponding hierarchical network space and the target traffic fingerprint of the corresponding hierarchical network space in the DDoS attack mitigation strategy knowledge graph.
[0097] The corresponding relationship is a connection line in the DDoS attack mitigation strategy knowledge graph, for example, a connection line between the traffic size feature and the SYN Flood. Figure 2
[0098] According to the traffic data information of the hierarchical network space, the traffic curve of the hierarchical network space is obtained, and the traffic curve represents that when a DDoS attack comes, the traffic will be higher than the normal traffic condition, causing the system to be unable to use, and then the DDoS attack mitigation strategy is executed. If the traffic of the hierarchical network space decreases to below the threshold value of the preset value after the execution of the DDoS attack mitigation strategy of the hierarchical network space is completed, it is proved that the DDoS attack mitigation strategy of the hierarchical network space has a certain effect. Otherwise, the DDoS attack mitigation strategy of the hierarchical network space is not effective, and the corresponding relationship between the DDoS attack mitigation strategy executed by the corresponding hierarchical network space and the target traffic fingerprint of the corresponding hierarchical network space in the DDoS attack mitigation strategy knowledge graph is deleted.
[0099] The advantage of such an arrangement is that through detailed analysis of the traffic data, the system can generate a traffic curve reflecting the traffic changes after implementing the DDoS strategy. This curve can help identify the effectiveness of the strategy, such as whether it has successfully reduced attack traffic, and dynamic updates ensure that the knowledge graph always reflects the latest attack patterns and protection measures.
[0100] In the above embodiments of the present application, the feature extraction module is further used for:
[0101] obtaining historical traffic of the hierarchical network space, the historical traffic including normal traffic and multiple attack traffics;
[0102] obtaining an attack type corresponding to each attack traffic in the multiple attack traffics, respectively;
[0103] determining a contribution degree of each target feature corresponding to a feature value to each attack type, the target feature being determined through a feature engineering technique; the contribution degree being determined through a preset random forest model;
[0104] determining a feature fingerprint corresponding to the hierarchical network space according to the contribution degree corresponding to each target feature respectively.
[0105] The contribution degree represents importance, that is, those feature values in the target feature can more determine the judgment of the attack type.
[0106] The method for obtaining the preset random forest model is: constructing a relatively comprehensive combination feature set, training the model using an initial random forest classifier to obtain the importance of each feature, selecting appropriate proportions of important features according to the importance of the features, reducing the feature dimension, and retraining the initial random forest model using the selected important features, thereby obtaining the preset random forest model.
[0107] Feature engineering is a key step in data science and machine learning, involving extracting, selecting and transforming features from raw data to improve the performance and predictive ability of the model.
[0108] By obtaining the historical traffic of the hierarchical network space, the attack type of the attack traffic is manually labeled. Then the attack traffic and the normal traffic are clustered, the attack type of clustering is constantly adjusted, and the contribution degree of different features to the attack type is calculated. The contribution degrees are sorted and processed, and the features with larger contribution degrees are selected as the feature fingerprints corresponding to the hierarchical network space. Clustering is an unsupervised learning method in data mining and machine learning, which aims to divide a set of data objects into multiple groups or clusters, so that the objects in the same cluster are more similar in some sense, while the objects in different clusters are relatively dissimilar. Clustering analysis is widely used in various fields such as marketing, image processing, bioinformatics and social network analysis.
[0109] The advantage of such setting is that by analyzing historical traffic data and obtaining the attack type corresponding to each attack traffic, the system can more accurately identify and classify different attacks. This provides a basis for subsequent defense strategies. The contribution degree of each target feature to different attack types is evaluated through a preset random forest model. The feature importance evaluation of the random forest model can reveal which features are most important in distinguishing normal traffic and attack traffic.
[0110] In the above embodiments of the present application, the mitigation strategy generation module is further configured to:
[0111] obtain a first relationship between the feature fingerprints of different hierarchical network spaces and the attack types, and a second relationship between the attack types and the anti-DDoS attack mitigation strategies of different hierarchical network spaces;
[0112] According to the first relationship and the second relationship, an initial DDoS attack resistance mitigation strategy knowledge graph is constructed;
[0113] Based on the initial DDoS attack resistance mitigation strategy knowledge graph, a third relationship between the feature fingerprint and the DDoS attack resistance mitigation strategy is determined through knowledge reasoning;
[0114] According to the third relationship, the initial DDoS attack resistance mitigation strategy knowledge graph is optimized to obtain a DDoS attack resistance mitigation strategy knowledge graph.
[0115] Among them, the knowledge reasoning method is an important field in artificial intelligence and computer science, which involves deriving new information or conclusions from known information. Knowledge reasoning method is widely used in expert systems, natural language processing, semantic web and intelligent decision support system and other fields.
[0116] The first relationship between the feature fingerprint and the attack type of the existing different level network space, the second relationship between the attack type and the DDoS attack resistance mitigation strategy of the different level network space, and the initial DDoS attack resistance mitigation strategy knowledge graph are constructed, and more third relationships between the feature fingerprint and the DDoS attack resistance mitigation strategy are found through the knowledge reasoning method. The initial DDoS attack resistance mitigation strategy knowledge graph is updated through the third relationship to obtain a DDoS attack resistance mitigation strategy knowledge graph.
[0117] The advantage of such setting is that by combining knowledge graph and knowledge reasoning technology, an intelligent and dynamic solution is provided for DDoS attack resistance, which can effectively improve the overall ability of network security protection.
[0118] The anti-DDoS attack collaborative mitigation architecture provided by the embodiment of the application comprises a feature extraction module, a mitigation strategy generation module and a strategy distribution module. The feature extraction module is configured to extract target traffic fingerprints of corresponding level network spaces according to feature fingerprints corresponding to each level network space in a multi-level network space. The mitigation strategy generation module is configured to generate a global DDoS attack resistance mitigation strategy based on an already constructed DDoS attack resistance mitigation strategy knowledge graph according to the target traffic fingerprints of the corresponding level network spaces. The strategy distribution module is configured to transmit the DDoS attack resistance mitigation strategy to the corresponding level network spaces through a collaborative instruction API. Therefore, the anti-DDoS attack collaborative mitigation architecture can improve the defense capability against new complex network attacks with high intensity and strong confrontation characteristics.
[0119] Figure 4 A flowchart of an anti-DDoS attack collaborative mitigation method provided by the embodiment of the application is shown in FIG. 1. Figure 4 As shown in FIG. 1, the method comprises:
[0120] S401、the feature extraction module responds to detection of a distributed denial of service (DDoS) attack, extracts a target traffic fingerprint corresponding to each hierarchical network space in a multi-level network space based on a feature fingerprint corresponding to each hierarchical network space, and transmits the target traffic fingerprint to a mitigation strategy generation module, the multi-level network space including an access network, an intra-domain network, and an inter-domain network;
[0121] S402、the mitigation strategy generation module responds to receiving the target traffic fingerprint, constructs a global anti-DDoS attack mitigation strategy based on an anti-DDoS attack mitigation strategy knowledge graph that has been constructed, and transmits the global anti-DDoS attack mitigation strategy to a strategy distribution module, the anti-DDoS attack mitigation strategy knowledge graph reflecting a correspondence between a feature fingerprint, an attack type, and an anti-DDoS attack mitigation strategy.
[0122] In the embodiments of the present application, the global anti-DDoS attack mitigation strategy corresponding to the target traffic fingerprint is searched for in the anti-DDoS attack mitigation strategy knowledge graph that has been constructed through a link association search technique.
[0123] In the embodiments of the present application, the global anti-DDoS attack mitigation strategy corresponding to the target traffic fingerprint is searched for in the anti-DDoS attack mitigation strategy knowledge graph that has been constructed through a link association search technique.
[0124] S403、the strategy distribution module transmits the anti-DDoS attack mitigation strategy to the corresponding hierarchical network space through a cooperative instruction API based on the global anti-DDoS attack mitigation strategy.
[0125] In the above embodiments of the present application, it also includes:
[0126] The cooperative control module collects and analyzes traffic data information of the hierarchical network space to evaluate the anti-DDoS attack effect of executing the anti-DDoS attack mitigation strategy on the corresponding hierarchical network space, and updates the anti-DDoS attack mitigation strategy knowledge graph and / or the feature fingerprint of the corresponding hierarchical network space according to the anti-DDoS attack effect.
[0127] The anti-DDoS attack cooperative mitigation method provided by the embodiments of the present application can extract a target traffic fingerprint of a corresponding hierarchical network space from a feature fingerprint corresponding to each hierarchical network space in a multi-level network space through a feature extraction module, generate a global anti-DDoS attack mitigation strategy based on an anti-DDoS attack mitigation strategy knowledge graph that has been constructed from the target traffic fingerprint of the corresponding hierarchical network space through a mitigation strategy generation module, and transmit the anti-DDoS attack mitigation strategy to the corresponding hierarchical network space through a strategy distribution module through a cooperative instruction API, thereby improving the defense capability against new complex network attacks with high intensity and strong counter characteristics.
[0128] Figure 5 Another flowchart of the anti-DDoS attack collaborative mitigation method provided by the embodiment of the present application is shown in the figure. As shown in the figure, the method comprises the following steps. Figure 5
[0129] When the network is attacked, the traffic fingerprints of the attack traffic are accurately extracted from the traffic of each domain. After the extraction is completed, the system transmits the traffic fingerprints to the multi-layer policy generation module facing the multi-layer network space. The traffic fingerprints of the attack traffic include high-level traffic fingerprint features, median traffic fingerprint features and low-level traffic fingerprint features.
[0130] When the traffic fingerprints from each domain are received, the multi-layer mitigation policy generation module starts the link association search technology. The corresponding mitigation strategies of different layers are searched. Through the mitigation strategy knowledge graph, the corresponding mitigation strategy is searched when the feature vector of the network space is received, wherein the features, attack categories and mitigation strategies in the mitigation strategy knowledge graph are connected as entities through edges. When we receive the feature vector of the network space, the corresponding mitigation strategy is searched, and the mitigation strategy includes the median mitigation strategy, the low-level mitigation strategy and the high-level mitigation strategy. The high-level corresponds to the high-level mitigation strategy, which specifically includes traffic scheduling and traffic cleaning. The median corresponds to the median mitigation strategy, which specifically includes intelligent filtering and traffic cleaning. The low-level corresponds to the low-level mitigation strategy, which specifically corresponds to traffic black hole and traffic cleaning.
[0131] The multi-layer mitigation strategy can establish a fast and stable communication channel between the high, median and low levels (i.e. different network levels or management levels) through the collaborative instruction API (i.e. the collaborative interface in the Figure 4 Through this channel, the system can quickly distribute the mitigation strategies to the relevant nodes of each level and instruct them to perform the corresponding defense operations according to the strategy requirements.
[0132] The evaluation module in the collaborative control center collects and analyzes the traffic logs to evaluate the actual effectiveness of the layered strategies. Specifically, if the traffic logs represent that the attack traffic does not reach below the threshold after the strategy is executed, the knowledge update module in the collaborative control center automatically and dynamically removes the corresponding relationship (including the corresponding mitigation strategy and the fingerprint of the attack traffic) in the knowledge graph, and allows the user to manually update the knowledge graph to ensure the effectiveness and accuracy of the strategy.
[0133] The anti-DDoS attack collaborative mitigation method provided by the embodiment of the present application can cover the full life cycle of the traffic end to end through the traffic fingerprints of the multi-layer network space, extract the feature fingerprints conforming to the network traffic characteristics of the current domain network from the multi-dimensional and multi-layer network domains of the access network, the intra-domain and the inter-domain, and improve the fine degree of network traffic detection. The method makes up for the single feature problem of the traditional detection scheme; searches the targeted mitigation strategies of each layer based on the link search technology of the knowledge graph; and fully utilizes the defense means of each layer for full-view defense.
[0134] Figure 6 A structural example diagram of the anti-DDoS attack cooperative mitigation device provided in the embodiments of the present application is shown in the figure. Figure 6 As shown in the figure, the anti-DDoS attack cooperative mitigation device 60 comprises a first transmission module 601, a second transmission module 602, and a third transmission module 603. Wherein:
[0135] The first transmission module 601 is configured to, in response to the feature extraction module detecting a distributed denial of service (DDoS) attack, extract a target traffic fingerprint of a corresponding hierarchical network space based on a feature fingerprint corresponding to each hierarchical network space in a multi-level network space, and transmit the target traffic fingerprint to a mitigation strategy generation module, wherein the multi-level network space comprises an access network, an intra-domain network, and an inter-domain network.
[0136] The second transmission module 602 is configured to, in response to the mitigation strategy generation module receiving the target traffic fingerprint, construct a global anti-DDoS attack mitigation strategy based on an anti-DDoS attack mitigation strategy knowledge graph that has been constructed, and transmit the global anti-DDoS attack mitigation strategy to a strategy distribution module, wherein the anti-DDoS attack mitigation strategy knowledge graph reflects a corresponding relationship among a feature fingerprint, an attack type, and an anti-DDoS attack mitigation strategy.
[0137] The third transmission module 603 is configured to, based on the global anti-DDoS attack mitigation strategy, transmit the anti-DDoS attack mitigation strategy to a corresponding hierarchical network space through a cooperative instruction API.
[0138] In the embodiments of the present application, the second transmission module 602 is specifically configured to:
[0139] Search for the global anti-DDoS attack mitigation strategy corresponding to the target traffic fingerprint in the anti-DDoS attack mitigation strategy knowledge graph that has been constructed through a link association search technology.
[0140] In the embodiments of the present application, the second transmission module 602 is further specifically configured to:
[0141] The cooperative control module collects and analyzes traffic data information of the hierarchical network space to evaluate the anti-DDoS attack effect of executing the anti-DDoS attack mitigation strategy on the corresponding hierarchical network space, and updates the anti-DDoS attack mitigation strategy knowledge graph and / or the feature fingerprint of the corresponding hierarchical network space according to the anti-DDoS attack effect.
[0142] The device provided in the embodiments of the present application can execute the technical solutions shown in the above method embodiments, and the implementation principles and beneficial effects are similar, which will not be described in detail here.
[0143] It should be noted that the division of the various modules of the above apparatus is only a logical functional division, and all or part of them can be integrated into one physical entity or physically separated in actual implementation. These modules can all be implemented in the form of software invoked by a processing element; all in the form of hardware; or some modules are implemented in the form of software invoked by a processing element, and some modules are implemented in the form of hardware. For example, the processing module can be a separately established processing element, or can be integrated in a chip of the above apparatus, in addition, it can also be stored in the form of program code in the memory of the above apparatus, and the function of the above processing module is invoked and executed by a processing element of the above apparatus. The implementation of other modules is similar. In addition, all or part of these modules can be integrated together or independently implemented. The processing element here can be an integrated circuit with signal processing capability. In the implementation process, each step of the above method or each module can be completed by the integrated logic circuit of hardware or the instruction of software in the processing element.
[0144] For example, the above modules can be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), etc. For another example, when a certain module above is implemented in the form of program code invoked by a processing element, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can invoke program code. For another example, these modules can be integrated together to implement in the form of system on a chip (SOC).
[0145] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions according to the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (for example, coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (for example, infrared, wireless, microwave, etc.) mode. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, etc. containing one or more available media sets. The available media can be a magnetic medium (for example, floppy disk, hard disk, magnetic tape), an optical medium (for example, digital versatile disc (Digital Video Disc, DVD)) or a semiconductor medium (for example, solid state disk (solid state disk, SSD)) and the like.
[0146] Figure 7 The structure schematic diagram of the electronic device provided by the embodiments of the present application is shown in the figure. As shown in the figure, the electronic device 70 includes: Figure 7
[0147] The electronic device 70 can include a processor 701 with one or more processing cores, a memory 702 with one or more computer readable storage media, a communication component 703 and the like. Among them, the processor 701, the memory 702 and the communication component 703 are connected through the bus 704.
[0148] In the specific implementation process, the at least one processor 701 executes the computer execution instructions stored in the memory 702, so that the at least one processor 701 executes the above anti-DDoS attack cooperative mitigation method.
[0149] The specific implementation process of the processor 701 can refer to the above method embodiments, which have similar implementation principles and technical effects, and will not be described here in detail.
[0150] In the above Figure 7 In the illustrated embodiment, it should be understood that the processor can be a central processing unit (CPU), but can also be other general purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), and so on. The general purpose processor can be a microprocessor or the processor can be any conventional processor. The steps of the disclosed method can be directly embodied as hardware processor execution, or a combination of hardware and software modules in the processor.
[0151] The memory can include random access memory (RAM), and can also include non-volatile memory (NVM), such as at least one disk memory.
[0152] The bus can be an industry standard architecture (ISA) bus, a peripheral component (PCI) bus, or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus in the drawings of the present application does not limit to only one bus or one type of bus.
[0153] In some embodiments, a computer program product is also provided, which includes a computer program or instructions, which, when executed by a processor, implements the steps of any of the above-described DDoS attack cooperative mitigation methods.
[0154] The specific implementation of each of the above operations can refer to the previous embodiments, which will not be repeated here.
[0155] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by relevant hardware controlled by the instructions, which can be stored in a computer readable storage medium and loaded and executed by a processor.
[0156] To this end, the embodiments of the present application provide a computer readable storage medium, which stores a plurality of instructions, which can be loaded by a processor to execute the steps of any of the DDoS attack cooperative mitigation methods provided by the embodiments of the present application.
[0157] The storage medium can include a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0158] According to an aspect of the present application, there is provided a computer program product or computer program comprising computer instructions stored in a computer readable storage medium.
[0159] Since the instructions stored in the storage medium can execute the steps of any of the DDoS attack resistant collaborative mitigation methods provided by the embodiments of the present application, the beneficial effects of any of the DDoS attack resistant collaborative mitigation methods provided by the embodiments of the present application can be achieved. Details are described in the foregoing embodiments, which will not be repeated here.
[0160] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. It is intended that the specification and examples be considered as exemplary only, with the true scope and spirit of the application being indicated by the following claims.
[0161] It should be understood that the application is not limited to the precise construction that has been described above and shown in the accompanying drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application is limited only by the appended claims.
Claims
1. A collaborative mitigation architecture against DDoS attacks, characterized in that: include: Feature extraction module, mitigation strategy generation module and strategy distribution module, where: The feature extraction module is configured to, in response to detecting a distributed denial of service (DDoS) attack, extract a target traffic fingerprint of each hierarchical network space in the multi-level network space based on a feature fingerprint corresponding to each hierarchical network space, and transmit the target traffic fingerprint to the mitigation strategy generation module, wherein the multi-level network space includes an access network, an intra-domain network, and an inter-domain network; The mitigation strategy generation module is configured to, in response to receiving the target traffic fingerprint, construct a global anti-DDoS attack mitigation strategy based on the constructed anti-DDoS attack mitigation strategy knowledge graph according to the target traffic fingerprint, and transmit the global anti-DDoS attack mitigation strategy to the strategy distribution module, wherein the anti-DDoS attack mitigation strategy knowledge graph reflects the correspondence between feature fingerprints, attack types, and anti-DDoS attack mitigation strategies; The policy distribution module is used to transmit the anti-DDoS attack mitigation strategy to the corresponding layer network space through the collaborative instruction API based on the global anti-DDoS attack mitigation strategy.
2. The anti-DDoS attack collaborative mitigation architecture according to claim 1, characterized in that: The mitigation strategy generation module is specifically used to: Through the link correlation search technology, the global anti-DDoS attack mitigation strategy corresponding to the target traffic fingerprint is searched in the constructed anti-DDoS attack mitigation strategy knowledge graph.
3. The anti-DDoS attack collaborative mitigation architecture according to claim 1 or 2, characterized in that: Also includes: A collaborative control module is used to collect and analyze traffic data information of the hierarchical network space to evaluate the anti-DDoS attack effect of the anti-DDoS attack mitigation strategy executed in the corresponding hierarchical network space, and update the anti-DDoS attack mitigation strategy knowledge graph and / or the feature fingerprint of the corresponding hierarchical network space according to the anti-DDoS attack effect.
4. The anti-DDoS attack collaborative mitigation architecture according to claim 3, characterized in that: The collaborative control module is specifically used to: Analyze traffic data information of the hierarchical network space to obtain a traffic curve after the hierarchical network space implements the anti-DDoS attack mitigation strategy, wherein the traffic curve reflects the anti-DDoS attack effect; The updating of the anti-DDoS attack mitigation strategy knowledge graph according to the anti-DDoS attack effect includes: if the traffic curve contains traffic greater than a traffic threshold, deleting the correspondence between the anti-DDoS attack mitigation strategy executed in the corresponding hierarchical network space and the target traffic fingerprint of the corresponding hierarchical network space in the anti-DDoS attack mitigation strategy knowledge graph.
5. The anti-DDoS attack collaborative mitigation architecture according to claim 1 or 2, characterized in that: The feature extraction module is also used to: Obtaining historical traffic of a hierarchical network space, where the historical traffic includes normal traffic and multiple attack traffic; Obtaining an attack type corresponding to each attack flow in the plurality of attack flows; Determining the contribution of the characteristic value corresponding to each target feature to each attack type, wherein the target feature is determined through feature engineering technology; the contribution is determined through a preset random forest model; According to the contribution degree corresponding to each target feature, a feature fingerprint corresponding to the hierarchical network space is determined.
6. The anti-DDoS attack collaborative mitigation architecture according to claim 1 or 2, characterized in that: The mitigation strategy generation module is further configured to: Obtaining the first relationship between the characteristic fingerprints of different layers of network space and the attack type, and the second relationship between the attack type and the anti-DDoS attack mitigation strategy of different layers of network space; Constructing an initial anti-DDoS attack mitigation strategy knowledge graph based on the first relationship and the second relationship; Based on the initial anti-DDoS attack mitigation strategy knowledge graph, determining a third relationship between the feature fingerprint and the anti-DDoS attack mitigation strategy through knowledge reasoning; According to the third relationship, the initial anti-DDoS attack mitigation strategy knowledge graph is optimized to obtain the anti-DDoS attack mitigation strategy knowledge graph.
7. A collaborative mitigation method against DDoS attacks, characterized in that: Applied to the anti-DDoS attack collaborative mitigation architecture according to any one of claims 1 to 6, the anti-DDoS attack collaborative mitigation method includes: In response to detecting a distributed denial of service (DDoS) attack, the feature extraction module extracts a target traffic fingerprint of each layer of network space in the multi-layer network space based on a feature fingerprint corresponding to each layer of network space, and transmits the target traffic fingerprint to the mitigation strategy generation module. The multi-layer network space includes an access network, an intra-domain network, and an inter-domain network. In response to receiving the target traffic fingerprint, the mitigation strategy generation module constructs a global anti-DDoS attack mitigation strategy based on the constructed anti-DDoS attack mitigation strategy knowledge graph according to the target traffic fingerprint, and transmits the global anti-DDoS attack mitigation strategy to the strategy distribution module, wherein the anti-DDoS attack mitigation strategy knowledge graph reflects the correspondence between feature fingerprints, attack types and anti-DDoS attack mitigation strategies; The policy distribution module transmits the anti-DDoS attack mitigation strategy to the corresponding level network space through the collaborative instruction API based on the global anti-DDoS attack mitigation strategy.
8. The anti-DDoS attack collaborative mitigation method according to claim 7, characterized in that: The method of constructing a global anti-DDoS attack mitigation strategy based on the constructed anti-DDoS attack mitigation strategy knowledge graph and the target traffic fingerprint includes: Through the link correlation search technology, the global anti-DDoS attack mitigation strategy corresponding to the target traffic fingerprint is searched in the constructed anti-DDoS attack mitigation strategy knowledge graph.
9. The anti-DDoS attack collaborative mitigation method according to claim 7 or 8, characterized in that: Also includes: The collaborative control module collects and analyzes traffic data information of the hierarchical network space to evaluate the anti-DDoS attack effect of the anti-DDoS attack mitigation strategy executed in the corresponding hierarchical network space, and updates the anti-DDoS attack mitigation strategy knowledge graph and / or the feature fingerprint of the corresponding hierarchical network space according to the anti-DDoS attack effect.
10. An electronic device, characterized in that: include: Memory, processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory, so that the processor performs the method according to any one of claims 7 to 9.
11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed, are used to implement the method according to any one of claims 7 to 9.
12. A computer program product comprising a computer program, characterized in that When the computer program is executed, the method according to any one of claims 7 to 9 is implemented.
Citation Information
Patent Citations
Method for detecting and alleviating DDoS attack of industrial SDN network
CN108289104A
Method for mitigating DDoS attack, programmable switch and SDN controller
CN112995238A