DDoS attack detection and verification system and method
By creating counting pulses in the interface module and setting statistics and interval periods, the shortcomings in the existing DDoS attack detection methods in terms of accuracy and reliability are solved, and the time synchronization between the UVM verification environment and the verification object is achieved, and the accuracy and reliability of detection are improved.
Patent Information
- Application Number
- CN202510325020.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-19
AI Technical Summary
The existing DDoS attack detection methods have shortcomings in terms of accuracy and reliability, and the verification environment relies on counting pulses, statistical periods and interval periods inside the verification object, resulting in uncertainty in the detection period.
It provides a detection and verification system and method for DDoS attacks. By creating count pulses in the interface module and setting statistics periods and interval periods based on count pulses, an independent UVM verification environment and verification object is constructed, time synchronization is realized and DDoS attack synchronization detection is performed.
It gets rid of the dependence of the verification environment on the internal counting pulses, statistics periods and interval periods of the verification object, improves the accuracy and reliability of detection, and ensures accurate message statistics and attack detection in each detection cycle.
Smart Images

Figure CN119835094B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a DDoS detection and verification system and method. Background Art
[0002] DDoS attacks, as a common means of network attack, can paralyze the target server or network resources in a short period of time, causing huge losses to enterprises and individuals. At present, in chip verification methodology, a variety of DDoS attack detection verification methods have been proposed, but these methods still have certain deficiencies in accuracy and reliability, and the verification environment needs to use the counting pulses, statistical cycles and interval cycles inside the verification object to achieve synchronous processing. Therefore, there is an urgent need for an effective DDoS attack detection and verification method that can accurately evaluate and verify the existing detection methods, get rid of the verification environment's dependence on the verification object, and improve the accuracy and reliability of detection. Summary of the invention
[0003] Based on this, it is necessary to provide a DDoS attack detection and verification system and method to address the above technical issues.
[0004] In a first aspect, the present application provides a DDoS attack detection and verification system, the DDoS attack detection and verification system comprising: an interface module, a UVM verification environment and a verification object;
[0005] The interface module is used to create a counting pulse, and set a statistical period and an interval period based on the counting pulse, wherein the counting pulse, pulse period and interval period are consistent with the counting pulse, pulse period and interval period inside the verification object;
[0006] The UVM verification environment is used to construct an excitation data stream including a first input data stream, a second input data stream, and a third input data stream, and to generate a first output data stream, a second output data stream, and a third output data stream based on the excitation data stream; and to perform DDoS attack synchronization detection processing based on a statistical period, an interval period, the first input data stream, and the first output data stream to obtain a first detection processing result;
[0007] The verification object is a DDoS functional module, and the UVM verification environment performs DDoS attack synchronization detection processing on the same stimulus data stream to obtain a second detection processing result;
[0008] The UVM verification environment compares the first detection processing result with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; and compares the counting pulses, statistical cycles, and interval cycles generated by the interface module with the counting pulses, statistical cycles, and interval cycles generated by the verification object to verify whether the timing is correct.
[0009] Optionally, the UVM verification environment includes: a reference module, a data driving module, a data acquisition module and a data comparison module;
[0010] The data-driven module is used to construct the stimulus data flow and drive the stimulus data flow to the reference module and the verification object;
[0011] The reference module is used to simulate the DDoS attack synchronization detection process of the verification object and perform the DDoS attack synchronization detection process with the verification object;
[0012] The data acquisition module acquires the data output by the verification object;
[0013] The data comparison module is used to compare the first detection processing result with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; and to compare the counting pulses, statistical cycles, interval cycles generated by the interface module with the counting pulses, statistical cycles, interval cycles generated by the verification object to verify whether the timing is correct.
[0014] In a second aspect, the present application provides a DDoS attack detection and verification method, the DDoS attack detection and verification method is performed based on the above-mentioned DDoS attack detection and verification system, and the DDoS attack detection and verification method includes the following steps:
[0015] Create counting pulses;
[0016] Setting a statistical period and an interval period based on the counting pulses;
[0017] Constructing an excitation data stream, the excitation data stream comprising a first input data stream, a second input data stream and a third input data stream, and generating a first output data stream, a second output data stream and a third output data stream based on the excitation data stream;
[0018] Perform DDoS attack synchronization detection processing based on the statistical period, the interval period, the first input data stream and the first output data stream;
[0019] The first detection processing result is compared with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; and the counting pulses, statistical cycles, interval cycles generated by the interface module and the counting pulses, statistical cycles, interval cycles generated by the verification object are compared in timing to verify whether the timing is correct.
[0020] Optionally, the creating a counting pulse comprises:
[0021] Pull down the configuration reset to clear the register working status;
[0022] Pull high to configure reset, the register starts to work, and at the same time starts to count the number of clock beats to obtain the counting pulse.
[0023] Optionally, the setting of the statistical period and the interval period based on the counting pulses includes:
[0024] Configure registers according to the time period of the statistical period and the interval period;
[0025] Counting the number of pulses;
[0026] When the number of count pulses is less than the configuration value of the statistical cycle register, the signal is high level, and the corresponding time is the statistical cycle;
[0027] When the number of counted pulses is equal to the configuration value of the statistical period register, starting from the next beat, the signal is at a low level, and the corresponding time is the interval period.
[0028] Optionally, a statistical cycle and an interval cycle constitute a detection cycle; the synchronous detection and processing of the DDoS attack based on the statistical cycle, the interval cycle, the first input data stream and the first output data stream includes:
[0029] For a process that needs to perform threshold detection in the DDoS attack detection process, when the first input data stream is at a high level and the first output data stream is at a low level, the UVM verification environment counts the messages that meet the DDoS attack detection. If the message count of the DDoS attack process exceeds the threshold value during the statistical period, all messages in the current detection period after the current moment are discarded, and the reason in the output result is modified to the reason of the current DDoS attack detection process. If the count does not exceed the threshold value, no processing is performed;
[0030] For the process that only needs message information comparison in the DDoS attack detection process, when the first input data stream is at a high level and the first output data stream is at a low level, the UVM verification environment processes the message that meets the DDoS attack detection. If the information of the message does not match the register configuration value within the statistical period, the message is discarded, and the reason in the output result is modified to the reason of the current DDoS attack detection process. The next message re-judges whether the information matches; if not, no processing is performed.
[0031] Optionally, after discarding all packets in the current detection period after the current time, the method further includes:
[0032] At the interval of the current detection cycle, the packet count is cleared and the overflow status of the DDoS attack detection process is set to 1. After the current moment, all packets in the current detection cycle do not need to be counted again. They are directly discarded according to the overflow of 1. The overflow status is reset to 0 at the beginning of the next detection cycle.
[0033] Optionally, if a packet meets the discarding criteria of multiple DDoS detection processes at the same time in a certain statistical period, the reason with the highest priority will be output according to the priority of the DDoS attack detection process.
[0034] Optionally, when the first input data stream is at a low level or the first output data stream is at a high level, and within a detection period, for a DDoS attack detection process that requires threshold detection, packets that meet the DDoS attack detection are counted, and if the packet count under the process exceeds the corresponding threshold, the overflow state of the process is set to 1; if the packet count of the process is less than or equal to the corresponding threshold, the overflow state under the process is set to 0, and different DDoS attack detection processes simultaneously process the overflow state under their respective processes.
[0035] The present application provides a detection and verification system and method for DDoS attacks, which creates a 1ms counting pulse in the interface module, constructs a statistical cycle and an interval cycle, and flexibly configures the system through registers; creates two independently running threads, one for DDoS attack detection and processing, and the other for updating the overflow state during DDoS attack detection. Through the above method, the verification environment is freed from the dependence on the internal counting pulse, statistical cycle and interval cycle of the verification object, and the independence of the verification environment is enhanced. At the same time, the correctness of the internal cycle and counting pulse of the verification object is also verified, which improves the completeness of the verification to a certain extent.
[0036] In order to make the above features and advantages of the invention more obvious and easy to understand, embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or related technologies, the drawings required for use in the embodiments or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0038] Figure 1 This is a structural block diagram of a DDoS attack detection and verification system provided in one embodiment of the present application.
[0039] Figure 2 This is a flowchart of a DDoS attack detection and verification method provided in another embodiment of the present application.
[0040] Figure 3 This is a flowchart of step S20 in the DDoS attack detection and verification method provided in another embodiment of the present application. DETAILED DESCRIPTION
[0041] In order to make the purpose and technical solution of the embodiment of the present invention clearer, the technical solution of the embodiment of the present invention will be clearly and completely described below in conjunction with the drawings of the embodiment of the present invention. Obviously, the described embodiment is a part of the embodiment of the present invention, not all of the embodiments. Based on the described embodiment of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0042] In one embodiment, see Figure 1 The present application provides a detection and verification system for DDoS attacks, which may include: an interface module 20, a UVM verification environment 10, and a verification object 30. The interface module 20 is used to create a counting pulse, and set a statistical period and an interval period based on the counting pulse, and the counting pulse, pulse period, and interval period are consistent with the timing of the counting pulse, pulse period, and interval period inside the verification object 30; the UVM verification environment 10 is used to construct an excitation data stream including a first input data stream Input_data_valid (input data valid bit), a second input data stream Input_data (input data), and a third input data stream Input_busy (input back pressure signal), and generate a first output data stream Ouput based on the excitation data stream _busy (output back pressure signal), the second output data stream Ouput_data_valid (input data valid bit) and the third output data stream Ouput_data (output data); and based on the statistical period, the interval period, the first input data stream Input_data_valid and the first output data stream Ouput_data_valid, DDoS attack synchronization detection processing is performed to obtain a first detection processing result; the verification object 30 is a DDoS functional module, and the UVM verification environment 10 performs DDoS attack synchronization detection processing on the same stimulus data stream to obtain a second detection processing result; the UVM verification environment 10 compares the first detection processing result with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object 30 is correct; and compares the counting pulses, statistical period, interval period generated by the interface module 20 with the counting pulses, statistical period, interval period generated by the verification object 30 in timing to verify whether the timing is correct.
[0043] As an example, the UVM verification environment 10 includes: a reference module 40, a data driving module 50, a data acquisition module 60 and a data comparison module 70. Among them, the data driving module 50 is used to construct an excitation data stream and drive the excitation data stream to the reference module 40 and the verification object 30; the data acquisition module 60 collects data output by the verification object 30; the reference module 40 is used to simulate the DDoS attack synchronization detection processing of the verification object 30, and perform DDoS attack synchronization detection processing with the verification object 30; the data comparison module 70 is used to compare the first detection processing result with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object 30 is correct; and the counting pulses, statistical cycles, and interval cycles generated by the interface module 20 are compared with the counting pulses, statistical cycles, and interval cycles generated by the verification object 30 to verify whether the timing is correct.
[0044] As an example, the code of the reference module 40 may be written in System_verilog. The reference module 40 includes a DDoS attack model, which may simulate the DDoS attack detection processing of the verification object 30 on the message.
[0045] As an example, the code of the verification object 30 can be written in Verilog, and the verification object 30 and the reference module 40 together receive the stimulus data sent by the data driving module 50 and perform DDoS attack detection processing.
[0046] As an example, the input of the verification object 30 may include: a first input data stream Input_data_valid, a second input data stream Input_data, and a third input data stream Input_busy; the output of the verification object 30 may include: a first output data stream Ouput_busy, a second output data stream Ouput_data_valid, and a third output data stream Ouput_data.
[0047] As an example, the DDoS attack detection process inside the verification object 30 may include DMAC attack detection, IP attack detection, ICMP attack detection, TCP attack detection, and the like.
[0048] As an example, the verification object 30 performs DDoS attack detection processing on the input message. If it meets the discarding criteria of one or more detection processes, it will be discarded and given a corresponding discarding reason. Otherwise, no processing will be performed.
[0049] As an example, for the process that needs to perform threshold detection in the DDoS attack detection process, such as ICMP threshold attack detection and TCP threshold attack detection. A corresponding counter, threshold and overflow state are set for each process that needs to perform threshold detection in the verification object 30, and the threshold can also be configured through a register. In the statistical period, when the first input data stream Input_data_valid is at a high level and the first output data stream Ouput_busy is at a low level, the UVM verification environment 10 and the verification object 30 simultaneously count the messages that meet the DDoS attack detection; specifically, if at a certain moment, the number of message counts exceeds the threshold, all messages after that moment in the complete detection cycle will be discarded, and at the same time, in the interval period, the message count will be cleared, the overflow of the process will be set to 1, and the reason in the output result will be the reason of the process. If the number of message counts is less than or equal to the threshold in the statistical period, all messages are sent normally in the statistical period and the interval period, the counter is cleared in the interval period, and the overflow of the process is set to 0. The above process is repeated in the next statistical period and interval period, and the overflow initial state is reset to 0.
[0050] As an example, for the DDoS attack detection process that only requires message information comparison, such as DMAC attack detection, IP attack detection, etc. When the first input data stream is at a high level and the first output data stream is at a low level, the UVM verification environment processes the message that meets the DDoS attack detection. If the information of the message does not match the register configuration value within the statistical period, the message is discarded, and the reason in the output result is modified to the reason of the current DDoS attack detection process. The next message re-judges whether the information matches; if not, no processing is performed.
[0051] In the above-mentioned DDoS attack detection and verification system, counting pulses are created through the interface module 20, and the statistical period and interval period are set based on the counting pulses; two identical excitation data streams are constructed through the data driving module 50, one is driven to the reference module 40, and the other is transmitted to the verification object 30 through the interface module; the reference module 40 receives the excitation data stream, and creates two independently running threads according to the driving signal, and performs DDoS attack synchronization detection processing based on the statistical period, interval period, the first input data stream Input_data_valid and the first output data stream Ouput_data_busy; the verification object will also perform DDoS attack detection processing after receiving the data; the data comparison module will verify the correctness of the detection processing and the timing correctness of the counting pulses, statistical period and interval period. Through the above-mentioned DDoS attack detection and verification system, the time synchronization between the UVM verification environment 10 and the verification object 30 is achieved, the UVM verification environment 10 is freed from the dependence on the internal counting pulses, statistical cycles and interval period signals of the verification object 30, and the uncertainty problem of the detection cycle is solved, so that accurate message statistics and attack detection can be performed in each detection cycle, thereby improving the reliability and effectiveness of DDoS attack detection.
[0052] In another embodiment, see Figure 2 The present application also provides a DDoS attack detection and verification method, which may include the following steps: S10~S50.
[0053] S10: Create counting pulses.
[0054] S20: Set the statistical period and interval period based on the counting pulses.
[0055] S30: constructing an excitation data stream, wherein the excitation data stream includes a first input data stream, a second input data stream, and a third input data stream, and generating a first output data stream, a second output data stream, and a third output data stream based on the excitation data stream.
[0056] S40: Perform DDoS attack synchronization detection processing based on the statistical period, the interval period, the first input data stream and the first output data stream.
[0057] S50: Compare the first detection processing result with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; and compare the counting pulses, statistical cycles, interval cycles generated by the interface module with the counting pulses, statistical cycles, interval cycles generated by the verification object to verify whether the timing is correct.
[0058] In the DDoS attack detection and verification method of the present application, by constructing a counting pulse, and on this basis constructing a statistical period and an interval period, the verification environment is freed from the dependence of the verification environment on the internal counting pulses, statistical periods and interval periods of the verification object, thereby enhancing the independence of the verification environment. At the same time, multi-threaded processing can effectively reduce false alarms and missed alarms, avoid the blocking or delay problems that may occur in a single process, and improve the accuracy of detection.
[0059] In step S10, refer to Figure 2 In step S10, a counting pulse is created.
[0060] As an example, a counting pulse is created in the interface module 20 , and the size of the counting pulse can be, but is not limited to, set to 1 ms.
[0061] As an example, the creation of the count pulse may include: pulling down the configuration reset to clear the register working state; pulling up the configuration reset, the register starts working, and starts counting the clock beats to obtain the count pulse. The time base frequency division value for generating the count pulse is determined according to the clock frequency, and a 1ms count pulse is generated every specific beat number.
[0062] For example, if the clock frequency is 1.2GHz, the time base division value of 1ms is 1199999, that is, after every 1199999 clock cycles, a counting pulse with a duration of 1ms will be generated. This precise time measurement method provides the basis for the accurate division of statistics and interval periods, so that the time period can be accurately controlled.
[0063] In step S20, refer to Figure 2 In step S20, a statistical period and an interval period are set based on the counting pulses.
[0064] As an example, see Figure 3 The setting of the statistical period and the interval period based on the counting pulses may include the following steps: S201~S204.
[0065] S201: configuring a register according to the time period of the statistical period and the interval period.
[0066] S202: Count the number of pulses.
[0067] S203: When the number of counted pulses is less than the configuration value of the statistical period register, the signal is high level, and the corresponding time is the statistical period.
[0068] S204: When the number of counted pulses is equal to the configuration value of the statistical period register, starting from the next beat, the signal is at a low level, and the corresponding time is the interval period.
[0069] As an example, the statistical cycle and the interval cycle are both in units of 1ms, including: according to the time cycle configuration registers of the statistical cycle and the interval cycle, the number of 1ms pulses is counted in a complete time cycle; when the number of 1ms counted pulses is less than the configuration value of the statistical cycle register, the statistical cycle signal inside the interface module 20 is high; when the number of 1ms counted pulses is equal to the configuration value of the statistical cycle register, starting from the next beat, the statistical cycle signal is low, entering the interval cycle, and continues until the next statistical cycle. In this way, the verification environment can get rid of its dependence on the internal counting pulses, statistical cycles and interval cycles of the verification object, solve the uncertainty problem of the detection cycle, and make it possible to perform accurate message statistics and attack detection in each detection cycle, thereby improving the reliability and effectiveness of DDoS attack detection.
[0070] As an example, one statistical cycle and one interval cycle constitute one detection cycle. The statistical cycle and the interval cycle can be configured through registers, and the lengths of the statistical cycle and the interval cycle can be adjusted according to actual needs to balance the accuracy of detection and the performance overhead of the system.
[0071] In step S30, refer to Figure 2 In step S30, an excitation data stream is constructed, wherein the excitation data stream includes a first input data stream, a second input data stream, and a third input data stream, and a first output data stream, a second output data stream, and a third output data stream are generated based on the excitation data stream.
[0072] As an example, the data driving module 50 may construct an excitation data stream, including: a first input data stream Input_data_valid, a second input data stream Input_data, and a third input data stream Input_busy.
[0073] As an example, a first output data stream Ouput_busy, a second output data stream Ouput_data_valid, and a third output data stream Ouput_data may be generated based on the excitation data stream.
[0074] As an example, the data stream can be driven to the reference module 40 and the verification object 30 to achieve synchronous processing of the two modules. It is possible to provide rich input data for the reference module 40 and the verification object 30, which helps to comprehensively test their performance and functions in different situations. The parameters and characteristics of the stimulus data stream can be flexibly adjusted as needed, which facilitates verification in different scenarios and improves the flexibility and scalability of verification.
[0075] In step S40, refer to Figure 2In step S40, DDoS attack synchronization detection processing is performed based on the statistical period, the interval period, the first input data stream Input_data_valid and the first output data stream Output_busy.
[0076] As an example, a fork_join statement is used to create two independently running threads in the reference module 40, including: DDoS attack detection processing and updating of overflow status during DDoS attack detection. The two threads are responsible for different tasks respectively, realizing parallel execution of tasks.
[0077] As an example, fork_join is a statement used in SystemVerilog to create parallel threads of execution.
[0078] As an example, the DDoS attack detection process includes: for the process that needs threshold detection in DDoS attack detection (such as TCP threshold attack detection, ICMP threshold attack detection, etc.), simulating the timing of the DDoS entry receiving the message, so as to process the same packet at the same time, according to the first input data stream Input_data_valid and the first output data stream Output_busy; when the first input data stream Input_data_valid is high (that is, the first input data stream Input_data_valid=1), and the first output data stream Output_busy is low (that is, the first output data stream Output_busy=0), the UVM verification environment 10 and the verification object 30 simultaneously count the messages that meet the DDoS attack detection. If the number of packets detected by the DDoS attack in the statistical period exceeds the threshold, all packets in the current detection period after the current time are discarded, the overflow status flag of the attack process is set to 1, and the corresponding discard flag is output. The reason in the output result is changed to the reason of the current DDoS attack detection process. In the interval period of the current detection period, the packet count is cleared. All packets in the current detection period after the current time do not need to be counted again. They are directly discarded according to the overflow of 1, and the reason in the output result is changed to the reason of the current DDoS attack detection process. The overflow status will be reset to 0 at the beginning of the next detection period. If the count does not exceed the threshold, no processing is performed.
[0079] As an example, for a process in the DDoS attack detection process that only requires message information comparison (such as DMAC attack detection, IP attack detection, etc.), when the first input data stream Input_data_valid is at a high level and the first output data stream Output_busy is at a low level, the UVM verification environment 10 processes the message that meets the DDoS attack detection, and compares the information of the message with the corresponding value of the register. If the information of the message does not match the register configuration value within the statistical period, the message is discarded, the discard label is directly output, and the reason in the output result is modified to the reason of the current DDoS attack detection process, otherwise it is forwarded normally, and the next message re-judges whether the information matches; otherwise, it is forwarded normally without processing.
[0080] As an example, after discarding all packets in the current detection cycle after the current moment, the following may also be included: in the interval period of the current detection cycle, the packet count is cleared to zero, and the overflow state of the DDoS attack detection process is set to 1. All packets in the current detection cycle after the current moment do not need to be counted again, and are directly discarded according to the overflow being 1. The overflow state is reset to 0 at the beginning of the next detection cycle.
[0081] As an example, there can be multiple DDoS detection processes, and they will be carried out simultaneously. Each process has its own detection process and discarding criteria. If a packet meets the discarding criteria of multiple DDoS detection processes at the same time in a certain statistical period, the reason with the highest priority will be output according to the priority of the DDoS attack detection process. The priority can be configured through the register.
[0082] As an example, the update of the overflow state during the DDoS attack detection process includes: when the first input data flow is at a low level (Input_data_valid=0) or the first output data flow is at a high level (Ouput_busy=1), and within the statistical period, for the DDoS attack detection process that requires threshold detection, the packets that meet the DDoS attack detection are counted. If the packet count under the process exceeds the corresponding threshold, the overflow state of the process is set to 1; if the packet count of the process is less than or equal to the corresponding threshold, the overflow state under the process is set to 0, and different DDoS attack detection processes simultaneously process the overflow state under their respective processes.
[0083] In step S50, refer to Figure 2In step S50, the first detection processing result is compared with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; and the counting pulses, statistical cycles, and interval cycles generated by the interface module are compared with the counting pulses, statistical cycles, and interval cycles generated by the verification object to verify whether the timing is correct.
[0084] As an example, the detection processing result of the reference model is compared with the detection processing result of the verification object 30 through the data comparison module 70 to verify whether the DDoS attack synchronization detection processing of the verification object 30 is correct.
[0085] As an example, the count pulses, statistical cycles, and interval cycles generated by the interface module 20 are compared with the count pulses, statistical cycles, and interval cycles generated by the verification object 30 to verify whether the timing is correct. This helps ensure that DDoS attack detection is performed on the correct time scale and improves the reliability of the detection results. The comparison process can discover potential errors or inconsistencies, thereby avoiding misjudgments or missed judgments caused by inaccurate time.
[0086] As an example, the 1ms counting pulse generated by the interface module 20 can be monitored, and the corresponding time-related signal or event can be observed in the verification object 30; check whether the two are synchronized on the time axis, that is, whether each 1ms counting pulse has a corresponding response or event in the verification object 30. The high and low state changes of the statistical cycle signal in the interface module 20 at different time points can be observed; check whether the time points of the start and end of the message counting in the interface module 20 correspond to the changes in the statistical cycle signal of the verification object 30; verify the message counting logic within the statistical cycle to ensure that the reference module 40 is consistent with the statistical cycle of the interface module for the number of messages that meet a certain DDoS attack detection. When the interface module 20 enters the interval period, it can be checked whether the message count reset operation within the interval period is correctly executed, and verify whether the length and time point of the interval period are consistent with the configuration of the interface module 20.
[0087] It should be understood that although Figure 1 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.
[0088] In the verification method of DDoS attack detection of the present application, by constructing a 1ms counting pulse, and setting a statistical cycle and an interval cycle based on the counting pulse, the time synchronization of the UVM verification environment 10 and the verification object 30 is realized; by constructing an excitation data stream, and driving it to the reference module 40 and the verification object 30, it is helpful to comprehensively test their performance and functions under different situations; receiving the excitation data stream, and creating two independently running threads according to the driving signal, it is helpful to find potential timing problems and data processing errors, and improve the accuracy and reliability of verification. Through the above method, the time synchronization of the UVM verification environment 10 and the verification object 30 is realized, and the dependence of the UVM verification environment 10 on the internal counting pulse, statistical cycle and interval cycle of the verification object 30 is eliminated, and the uncertainty problem of the detection cycle is solved, so that accurate message statistics and attack detection can be performed in each detection cycle, and the reliability and effectiveness of DDoS attack detection are improved, which helps to optimize the detection process, make the detection system run more efficiently, and improve the response speed to DDoS attacks.
[0089] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0090] Although the present invention has been disclosed as above by way of embodiments, it is not intended to limit the present invention. Any person having ordinary knowledge in the technical field may make some changes and modifications without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be determined by the scope of the attached patent application.
Claims
1. A DDoS attack detection and verification system, characterized in that: include: Interface module, UVM verification environment and verification object; The interface module is used to create a counting pulse, and set a statistical period and an interval period based on the counting pulse, wherein the counting pulse, pulse period and interval period are consistent with the counting pulse, pulse period and interval period inside the verification object; The UVM verification environment is used to construct an excitation data stream including a first input data stream, a second input data stream, and a third input data stream, and generate a first output data stream, a second output data stream, and a third output data stream based on the excitation data stream; and perform DDoS attack synchronization detection processing based on the statistical period, the interval period, the first input data stream, and the first output data stream to obtain a first detection processing result; The verification object is a DDoS functional module, and the UVM verification environment performs DDoS attack synchronization detection processing on the same excitation data stream to obtain a second detection processing result; The UVM verification environment compares the first detection processing result with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; The counting pulses, statistical cycles, and interval cycles generated by the interface module are compared with the counting pulses, statistical cycles, and interval cycles generated by the verification object to verify whether the timing is correct.
2. The DDoS attack detection and verification system according to claim 1, characterized in that: The UVM verification environment includes: a reference module, a data driving module, a data acquisition module and a data comparison module; The data driving module is used to construct the excitation data stream and drive the excitation data stream to the reference module and the verification object; The reference module is used to simulate the DDoS attack synchronization detection process of the verification object and perform the DDoS attack synchronization detection process with the verification object; The data acquisition module acquires data output by the verification object; The data comparison module is used to compare the first detection processing result with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; and to compare the counting pulses, statistical cycles, interval cycles generated by the interface module with the counting pulses, statistical cycles, interval cycles generated by the verification object to verify whether the timing is correct.
3. A DDoS attack detection and verification method, characterized in that: The DDoS attack detection and verification method is performed based on the DDoS attack detection and verification system according to claim 1 or 2, and the DDoS attack detection and verification method comprises the following steps: Create counting pulses; Setting a statistical period and an interval period based on the counting pulses; Constructing an excitation data stream, the excitation data stream comprising a first input data stream, a second input data stream and a third input data stream, and generating a first output data stream, a second output data stream and a third output data stream based on the excitation data stream; Perform DDoS attack synchronization detection processing based on the statistical period, the interval period, the first input data stream and the first output data stream; The first detection processing result is compared with the second detection processing result to verify whether the DDoS attack synchronization detection processing of the verification object is correct; and the counting pulses, statistical cycles, interval cycles generated by the interface module and the counting pulses, statistical cycles, interval cycles generated by the verification object are compared in timing to verify whether the timing is correct.
4. The DDoS attack detection and verification method according to claim 3, characterized in that: The creating of counting pulses comprises: Pull down the configuration reset to clear the register working status; Pull high to configure reset, the register starts to work, and at the same time starts to count the number of clock beats to obtain the counting pulse.
5. The DDoS attack detection and verification method according to claim 3, characterized in that: The setting of the statistical period and the interval period based on the counting pulses comprises: Configure registers according to the time period of the statistical period and the interval period; Count the number of pulses; When the number of count pulses is less than the configuration value of the statistical cycle register, the signal is high level, and the corresponding time is the statistical cycle; When the number of counted pulses is equal to the configuration value of the statistical period register, starting from the next beat, the signal is at a low level, and the corresponding time is the interval period.
6. The DDoS attack detection and verification method according to claim 3, characterized in that: A statistical cycle and an interval cycle constitute a detection cycle; the DDoS attack synchronization detection process based on the statistical cycle, the interval cycle, the first input data stream and the first output data stream includes: For a process that needs to perform threshold detection in the DDoS attack detection process, when the first input data stream is at a high level and the first output data stream is at a low level, the UVM verification environment counts the messages that meet the DDoS attack detection. If the message count of the DDoS attack process exceeds the threshold value during the statistical period, all messages in the current detection period after the current moment are discarded, and the reason in the output result is modified to the reason of the current DDoS attack detection process. If the count does not exceed the threshold value, no processing is performed; For the process that only needs message information comparison in the DDoS attack detection process, when the first input data stream is at a high level and the first output data stream is at a low level, the UVM verification environment processes the message that meets the DDoS attack detection. If the information of the message does not match the register configuration value within the statistical period, the message is discarded, and the reason in the output result is modified to the reason of the current DDoS attack detection process. The next message re-judges whether the information matches; if not, no processing is performed.
7. The DDoS attack detection and verification method according to claim 6, characterized in that: After discarding all packets in the current detection period after the current time, it also includes: At the interval of the current detection cycle, the packet count is cleared and the overflow status of the DDoS attack detection process is set to 1. After the current moment, all packets in the current detection cycle do not need to be counted again. They are directly discarded according to the overflow of 1. The overflow status is reset to 0 at the beginning of the next detection cycle.
8. The DDoS attack detection and verification method according to claim 6, characterized in that: If a packet meets the discarding criteria of multiple DDoS attack detection processes at the same time in a statistical period, the reason with the highest priority will be output based on the priority of the DDoS attack detection process.
9. The DDoS attack detection and verification method according to claim 6, characterized in that: Also includes: When the first input data stream is at a low level or the first output data stream is at a high level, and within the detection period, for the DDoS attack detection process that requires threshold detection, the packets that meet the DDoS attack detection are counted. If the packet count under the process exceeds the corresponding threshold, the overflow state of the process is set to 1; if the packet count of the process is less than or equal to the corresponding threshold, the overflow state under the process is set to 0, and different DDoS attack detection processes simultaneously process the overflow state under their respective processes.
Citation Information
Patent Citations
Distributed attack detection method and device based on custom field for use in switch chip
CN106534100A
Microcontroller- or microprocessor-based system with authorization verification for requests
EP4133768A1