LFA passive defense method and device, electronic equipment and storage medium
By automatically identifying key nodes and network bottlenecks in the website to be defended, and using preset defense models to establish new nodes and links, the problem of time-consuming and labor-consuming manual establishment of backup links when defending LFA in the existing technology is solved, and the effect of rapid response and reducing the risk of network bottleneck attacks is achieved.
Patent Information
- Application Number
- CN202411927395.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-25
AI Technical Summary
The prior art has the problem of manual establishment of backup links or nodes when defending against link flood attacks (LFAs), and passive defense has lag and the defects of real-time detection and manual construction.
By obtaining the network topology and traffic information of the website to be defended, key nodes are determined based on graph central indicators, and inputting this information into a preset defense model, automatically identifying network bottlenecks and establishing new nodes and links to quickly resist attacks.
It realizes automatic identification of network bottlenecks and establishing new nodes and links after LFA occurs, quickly resisting attacks, reducing the risk of network bottlenecks being paralyzed after being attacked, and avoiding the time-consuming and labor costs of manual intervention.
Smart Images

Figure CN119945728A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of network attacks, and in particular to an LFA passive defense method, device, electronic device and storage medium. Background Art
[0002] Link-flooding attack (LFA) is a new type of distributed denial of service (DDoS) attack. Unlike traditional DDoS attacks, LFA targets network links rather than servers themselves. This attack attacks the main ingress and egress links of the server cluster, causing link congestion and making the server unable to respond to normal user requests. LFA is characterized by using low-rate traffic to attack, which is similar to the characteristics of legitimate traffic, making it difficult to defend against through traditional methods of detecting false addresses and specific signatures.
[0003] The topology of the network may cause data flows to be overly concentrated on certain nodes and links. These network bottlenecks are the main attack targets of LFA because once they are attacked, they may affect the normal transmission of a large number of data flows. In short, LFA attacks achieve their attack purposes by exploiting the weaknesses in the network topology, namely key links and nodes. Once these key points are attacked, they will become potential problem points for network transmission.
[0004] Related technologies for LFA defense are mainly divided into two types: passive defense and active defense. Among them, passive defense is to capture LFA and deal with the network bottlenecks that are blocked. The main method is to temporarily establish new links manually. For example, after the network is blocked, the link congestion caused by LFA can be alleviated by temporarily adding links; or suspicious links can be inferred through traffic information, and temporary links will be opened after the traffic reaches the threshold. These models are all innovations in link detection, and all have the defects of passive defense: they have a certain lag, and require real-time detection and manual construction; active defense is to hide, predict, and transfer network bottlenecks. First, find the network bottleneck, and then establish a virtual topology to hide the bottleneck and induce erroneous attacks. Its defect is that active defense is limited in the complexity of hiding the topology structure, and a few deployed nodes have become new network bottlenecks. Summary of the invention
[0005] The present application provides an LFA passive defense method, device, electronic device and storage medium to solve the problem of time-consuming and labor-intensive manual establishment of backup links or nodes to defend against LFA. The present application can automatically identify network bottlenecks and establish new nodes and links after an LFA attack through a preset defense model, introduce data streams into new nodes and links, quickly resist attacks, and reduce the risk of network bottlenecks being paralyzed after being attacked. The first aspect of the present application provides an LFA passive defense method, including the following steps:
[0006] Obtain the network topology and traffic information of the website to be defended;
[0007] Determine the graph centrality index of each node in the website to be defended according to the network topology structure, and determine the key nodes of the website to be defended according to the graph centrality index of each node;
[0008] The traffic information, network topology and key nodes of the website to be defended are input into a preset defense model, the network bottleneck in the key node is identified, and the first target defense action of the network bottleneck is determined, and passive defense is performed according to the first target defense action.
[0009] Optionally, in some embodiments, before the traffic information, the network topology and the key nodes are input into a preset defense model, the following steps are included:
[0010] Obtaining network topology and defense link information of at least one test website;
[0011] Conduct LFA simulation attacks on each test network to determine the network bottleneck of each test network, establish a state space based on the network topology of each test network and the network bottleneck of each test network, and establish an action space based on the defense link information of each test network;
[0012] The initial neural network model is trained according to the state space and the action space to obtain the preset defense model.
[0013] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain the preset defense model, the method further includes:
[0014] The preset defense model is updated using a preset reward function, wherein the preset reward function is:
[0015] R(D EO , D ET )=f obstacle (D EO )+f triplet (D EO , D ET )
[0016] Among them, D Eo is the resistance of the defense model before updating, D ET is the resistance of the updated defense model, f obstacle (D Eo ) is a redundant term, f triplet (D EO , DET ) is link-guided.
[0017] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain the preset defense model, the method further includes:
[0018] Simulate LFA to attack the network bottleneck of each test network, obtain a second target defense action using a preset defense model, and perform passive defense according to the second target defense action to obtain a resistance result;
[0019] Determining whether the preset defense model successfully resists according to the resistance result;
[0020] If the preset defense model fails to successfully resist, the network bottleneck of the test network is redetermined, and a new state space and a new action space are established, and the preset defense model is trained according to the new state space and the new action space until the preset defense model successfully resists.
[0021] Optionally, in some embodiments, the state space is:
[0022] S = {(f1, f2, ..., f n )};
[0023] Where S is the state space, f n Indicates status.
[0024] Optionally, in some embodiments, the action space is:
[0025] A={(a1,a2,...,a n )}
[0026] Among them, A is the action space, a n For action.
[0027] A second aspect of the present application provides an LFA passive defense device, including:
[0028] An acquisition module is used to obtain the network topology and traffic information of the website to be defended;
[0029] A determination module, used to determine the graph centrality index of each node in the website to be defended according to the network topology structure, and determine the key nodes of the website to be defended according to the graph centrality index of each node;
[0030] The defense module is used to input the traffic information, network topology and key nodes of the website to be defended into a preset defense model, identify the network bottleneck in the key node, determine the first target defense action of the network bottleneck, and perform passive defense according to the first target defense action.
[0031] Optionally, in some embodiments, before inputting the traffic information, the network topology and the key nodes into a preset defense model, the acquisition module includes:
[0032] An acquisition unit, used to acquire network topology and defense link information of at least one test website;
[0033] A testing unit, configured to launch LFA simulation attacks on each test network to determine the network bottleneck of each test network, establish a state space based on the network topology of each test network and the network bottleneck of each test network, and establish an action space based on the defense link information of each test network;
[0034] An establishing unit is used to train an initial neural network model according to the state space and the action space to obtain the preset defense model.
[0035] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain the preset defense model, the establishment module further includes:
[0036] An updating unit, configured to update the preset defense model using a preset reward function, wherein the preset reward function is:
[0037] R(D EO , D ET )=f obstacle (D EO )+f triplet (D EO , D ET )
[0038] Among them, D EO is the resistance of the defense model before updating, D ET is the resistance of the updated defense model, f obstacle (D EO ) is a redundant term, f triplet (D EO , D ET ) is link-guided.
[0039] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain the preset defense model, the establishing unit further includes:
[0040] A simulation subunit, used for simulating LFA to attack the network bottleneck of each test network, and obtaining a second target defense action by using a preset defense model, and performing passive defense according to the second target defense action to obtain a resistance result;
[0041] A judging subunit, used for judging whether the preset defense model successfully resists according to the resistance result;
[0042] The training subunit is used to redefine the network bottleneck of the test network and establish a new state space and a new action space when the preset defense model fails to successfully resist, and train the preset defense model according to the new state space and the new action space until the preset defense model successfully resists.
[0043] Optionally, in some embodiments, the state space is:
[0044] S = {(f1, f2, ..., f n )};
[0045] Where S is the state space, f n Indicates status.
[0046] Optionally, in some embodiments, the action space is:
[0047] A={(a1,a2,...,a n )}
[0048] Among them, A is the action space, a n For action.
[0049] The third aspect of the present application provides an electronic device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the LFA passive defense method as described in the above embodiment.
[0050] The fourth aspect of the present application provides a computer-readable storage medium on which a computer program is stored. The program is executed by a processor to implement the LFA passive defense method as described in the above embodiment.
[0051] Therefore, by obtaining the network topology and traffic information of the website to be defended, the graph centrality index of each node in the website to be defended is determined based on the network topology, so as to determine the key nodes of the website to be defended according to the graph centrality index of each node, and the traffic information, network topology and key nodes of the website to be defended are input into the preset defense model, the network bottleneck in the key node is identified, and the first target defense action of the network bottleneck is determined, and the first target defense action is executed for passive defense. Thus, the problem of manually establishing a backup link or node defense LFA is time-consuming and labor-intensive. The present application can automatically identify the network bottleneck and establish new nodes and links after LFA occurs through a preset defense model, introduce data flow into the new nodes and links, quickly resist attacks, and reduce the risk of network bottlenecks being paralyzed after being attacked.
[0052] Additional aspects and advantages of the present application will be given in part in the description below, and in part will become apparent from the description below, or will be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] The above and / or additional aspects and advantages of the present application will become apparent and easily understood from the following description of the embodiments in conjunction with the accompanying drawings, in which:
[0054] Figure 1 A flowchart of an LFA passive defense method provided according to an embodiment of the present application;
[0055] Figure 2 A schematic diagram of the principle of an LFA passive defense method provided according to an embodiment of the present application;
[0056] Figure 3 It is a block diagram of an LFA passive defense device provided according to an embodiment of the present application;
[0057] Figure 4 It is a schematic diagram of the structure of an electronic device provided according to an embodiment of the present application. DETAILED DESCRIPTION
[0058] Embodiments of the present application are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to be used to explain the present application, and should not be construed as limiting the present application.
[0059] The following describes the LFA passive defense method, device, electronic device and storage medium of the embodiment of the present application with reference to the accompanying drawings. In view of the time-consuming and labor-intensive problem of manually establishing a backup link or node defense LFA mentioned in the above background technology, the present application provides a LFA passive defense method, in which the network topology and traffic information of the website to be defended are obtained, and the graph centrality index of each node in the website to be defended is determined based on the network topology, so as to determine the key nodes of the website to be defended according to the graph centrality index of each node, and the traffic information, network topology and key nodes of the website to be defended are input into a preset defense model, the network bottleneck in the key node is identified, and the first target defense action of the network bottleneck is determined, and the first target defense action is executed for passive defense. Thus, the time-consuming and labor-intensive problem of manually establishing a backup link or node defense LFA is solved. The present application can automatically identify the network bottleneck and establish new nodes and links after LFA occurs through a preset defense model, introduce data flow into the new nodes and links, quickly resist attacks, and reduce the risk of network bottlenecks being paralyzed after being attacked.
[0060] Specifically, Figure 1 A flowchart of an LFA passive defense method provided in an embodiment of the present application.
[0061] like Figure 1 As shown, the LFA passive defense method includes the following steps:
[0062] In step S101, the network topology and traffic information of the website to be defended are obtained.
[0063] Specifically, the embodiments of the present application can obtain information about the website to be defended, including the network topology and traffic information of the website to be defended, so as to determine the number and location of alternative paths based on the network topology and traffic information, and allocate the optimal forwarding path for the data packet.
[0064] In step S102, the graph centrality index of each node in the website to be defended is determined according to the network topology structure, and the key nodes of the website to be defended are determined according to the graph centrality index of each node.
[0065] Among them, graph centrality is a concept used in social network analysis to measure the degree to which a node or a person in the network is close to the center of the entire network.
[0066] It is understandable that the embodiment of the present application can judge the importance of the central node (person) in the network by understanding the centrality of a node, so as to better understand the network structure and node behavior. Similar to social networks, network topology is also composed of nodes and edges, so the concept of graph centrality in social networks is also applicable to the analysis of the importance of nodes in network topology. The embodiment of the present application can sort the importance of nodes by analyzing the graph centrality indicators of different nodes in the network topology structure, and obtain important nodes, i.e., key nodes.
[0067] It is understandable that the embodiment of the present application can identify the key nodes in the network by analyzing the graph centrality index of each node in the website to be defended. The graph centrality index of these key nodes is high, indicating that they play an important role in the network. These key nodes are often potential network bottlenecks. In step S103, the traffic information, network topology and key nodes of the website to be defended are input into the preset defense model, the network bottleneck in the key node is identified, and the first target defense action of the network bottleneck is determined, and passive defense is performed according to the first target defense action.
[0068] Among them, the preset defense model is a neural network trained using deep reinforcement learning. The preset defense model can determine the network bottleneck in the key nodes based on the input data and determine the optimal defense action for the network bottleneck.
[0069] Specifically, by analyzing the network topology architecture and traffic data of the website to be defended, the embodiments of the present application can identify key nodes in the network. The graph centrality index of these nodes is relatively high, indicating that they play an important role in the network. These key nodes are often also potential network bottlenecks. This information is input into the preset defense model. After the preset defense model discovers the attack, it automatically identifies the network bottlenecks in the key nodes and establishes new nodes and links, introduces data flows into the new nodes and links, quickly resists attacks, and reduces the risk of network bottlenecks being paralyzed after being attacked.
[0070] Optionally, in some embodiments, before inputting traffic information, network topology and network bottleneck into a preset defense model, it includes: obtaining the network topology and defense link information of at least one test website; launching LFA simulation attacks on each test network to determine the network bottleneck of each test network, establishing a state space based on the network topology of each test website and the network bottleneck of each test network, and establishing an action space based on the defense link information of each test website; training the initial neural network model according to the state space and the action space to obtain a preset defense model.
[0071] It can be understood that the embodiments of the present application can establish a preset defense model to determine the defense action through the preset defense model, without the need to manually establish a new link, and the defense efficiency is high.
[0072] Specifically, the network topology structure and defense link information of at least one test website are obtained, wherein the defense link information is a known link artificially established to counter LFA attacks, and then the LFA attack on the test website is simulated to obtain the traffic information of the nodes and links, and the information is analyzed, and the network bottleneck is determined according to the graph centrality index. After that, the embodiment of the present application can arrange new links around these network bottlenecks. If an accurate judgment cannot be made, it may be due to the small amount of data. We can re-perform the LFA attack and make another judgment after increasing the amount of data.
[0073] Then, the embodiment of the present application regards the topological characteristics of the test network and the analyzed bottleneck information as states, and all states will form a state space. The state space S is expressed as:
[0074] S = {(f1, f2, ..., f n )}
[0075] Where n represents the number of input state parameters, f n Indicates specific status (such as topology information, etc.).
[0076] Analyze the known links artificially established to counter LFA attacks, obtain the link establishment methods, set all the establishment methods as action spaces, and the agent selects actions based on the generated classification probability vector. The action space A is represented as follows:
[0077] A={(a1,a2,...,a n )}
[0078] Where n represents the number of actions, a n Indicates a specific action.
[0079] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain a preset defense model, the method further includes: updating the preset defense model using a preset reward function, wherein the preset reward function is:
[0080] R(D EO , D ET )=f obstacle (D EO )+f triplet (D EO , D ET )
[0081] Among them, D EOis the resistance of the defense model before updating, D ET is the resistance of the updated defense model, f obstacle (D EO ) is a redundant term, f triplet (D EO , D ET ) is link-guided.
[0082] It is understandable that for a network bottleneck, the agent must not only quickly establish a new link, but also effectively avoid a large amount of waste caused by redundancy. Therefore, the reward function of the embodiment of the present application is divided into two parts:
[0083] Redundancy item: Redundancy items are established based on Gaussian distribution. The difference D in resistance between the resistance E after the new link is established and the resistance O before is calculated. EO , D EO The smaller the value, the higher the link redundancy, and the more penalty rewards will be obtained. The redundancy term is represented by the function f obstacle (D EO ) description, the formula is as follows:
[0084]
[0085] Link guidance term: In order to allow the agent to quickly establish new links while avoiding redundancy as much as possible, the formula for the link guidance term is as follows:
[0086] f triplet (D Eo , D ET )=[D EO 2 -D ET 2 -α] +
[0087] [·] + The symbol indicates that when the value in [] is greater than 0, the function value is output normally, otherwise the output is 0. ET It represents the relative difference between the current resistance E and the target resistance T, and α is D EO and D ET The value of α needs to be adjusted according to the actual working environment.
[0088] Considering the redundancy term and link guidance term, the designed reward function formula is as follows:
[0089] R(D EO , D ET )=f obstacle (D EO )+f triplet (D EO , D ET )
[0090] The agent takes action and selects actions from the action space to execute. The state of the environment will provide feedback on the actions taken by the agent based on the reward function. The agent's actions will also change the state space, resulting in state transfer.
[0091] After setting the above parameters, perform deep learning to train the initial neural network model. After the model is stable, attack the input network bottleneck. If it can resist, proceed to the next step. If it cannot resist, reset the state space to the initial state, adjust the reward function parameters appropriately, and perform deep learning again.
[0092] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain a preset defense model, it also includes: simulating LFA to attack the network bottleneck of each test network, and using the preset defense model to obtain a second target defense action, and performing passive defense according to the second target defense action to obtain a resistance result; judging whether the preset defense model successfully resists according to the resistance result; if the preset defense model fails to successfully resist, redetermining the network bottleneck of the test network, and establishing a new state space and a new action space, and training the preset defense model according to the new state space and the new action space until the preset defense model successfully resists.
[0093] Specifically, combined Figure 2 As shown, when the preset defense model is born from deep learning, the embodiment of the present application can repeat the LFA attack to observe whether it can resist the attack: if it can, it means that the model for the LFA attack has been established and perfected, and the next step can be carried out; if it cannot resist, it means that the judgment of the network bottleneck is wrong or not comprehensive enough, and the LFA attack will be re-performed to collect the traffic of each node and link of the network topology structure during the LFA attack, and combine the historical attack data to judge the network bottleneck again according to the graph centrality indicator.
[0094] It should be noted that the method used by the embodiment of the present application to detect whether the preset defense model is successfully resisted is to conduct a certain amount of user input before the attack, and conduct user input again after the attack. If the result obtained is basically unchanged, it means that the resistance is successful; if there is obvious user congestion, it means that the resistance has failed. Here, the selected LFA attacks are all historical attacks, and the network topology structure is the structure of the website that needs to be protected. Therefore, the link designed to resist LFA attacks has strong practical applicability.
[0095] Next, the embodiment of the present application will input more types of LFA attacks to see whether the model can resist them. If yes, the model will be put into practical application; if not, the LFA attack will be repeatedly and mechanically performed in the past to update the model.
[0096] In summary, the embodiment of the present application adopts the idea of passive defense. When the website is attacked, the embodiment of the present application can automatically identify the network bottleneck and establish new nodes and links to form a backup link through a preset defense model, and appropriately introduce the data flow into the backup link, reducing the risk of paralysis of the network bottleneck after being attacked to prevent accidents from affecting the normal operation of the website. Most of the related technologies are to manually establish backup links and nodes, which is time-consuming and labor-intensive. The embodiment of the present application can introduce deep reinforcement learning to train the neural network model to obtain a preset defense model. The preset defense model determines the number and location of the alternative paths according to the traffic conditions of the current topology, and allocates the optimal forwarding path for the data packet.
[0097] Therefore, the embodiments of the present application have the following beneficial effects:
[0098] (1) Low economic cost: The preset defense model can be used continuously after training is completed, saving costs.
[0099] (2) Low labor cost: Only known alternative paths need to be manually input for machine learning, and subsequent work can be completed by the preset defense model.
[0100] (3) All-day detection coverage: The machine learning model can run around the clock to resist attacks at any time.
[0101] According to the LFA passive defense method proposed in the embodiment of the present application, by obtaining the network topology and traffic information of the website to be defended, the graph centrality index of each node in the website to be defended is determined based on the network topology, so as to determine the key nodes of the website to be defended according to the graph centrality index of each node, and the traffic information, network topology and key nodes of the website to be defended are input into the preset defense model, the network bottleneck in the key node is identified, and the first target defense action of the network bottleneck is determined, and the first target defense action is executed for passive defense. Thus, the problem of manually establishing a backup link or node defense LFA is time-consuming and labor-intensive. The present application can automatically identify the network bottleneck and establish new nodes and links after LFA occurs through the preset defense model, introduce the data flow into the new node and link, quickly resist the attack, and reduce the risk of the network bottleneck being paralyzed after being attacked.
[0102] Next, the LFA passive defense device proposed according to the embodiment of the present application is described with reference to the accompanying drawings.
[0103] Figure 3 Schematic diagram of the LFA passive defense device according to an embodiment of the present application.
[0104] like Figure 3 As shown, the LFA passive defense device 10 includes: an acquisition module 100 , a determination module 200 and a defense module 300 .
[0105] The acquisition module 100 is used to acquire the network topology and flow information of the website to be defended.
[0106] The determination module 200 is used to determine the graph centrality index of each node in the website to be defended according to the network topology structure, and determine the key nodes of the website to be defended according to the graph centrality index of each node.
[0107] The defense module 300 is used to input the traffic information, network topology and key nodes of the website to be defended into a preset defense model, identify the network bottleneck in the key node, determine the first target defense action of the network bottleneck, and perform passive defense according to the first target defense action.
[0108] Optionally, in some embodiments, before the traffic information, network topology and key nodes are input into a preset defense model, the acquisition module 100 includes: an acquisition unit, a test unit and a building unit.
[0109] The acquisition unit is used to acquire the network topology and defense link information of at least one test website.
[0110] The test unit is used to launch LFA simulation attacks on each test network to determine the network bottleneck of each test network, establish a state space based on the network topology structure of each test website and the network bottleneck of each test network, and establish an action space based on the defense link information of each test website.
[0111] A unit is established to train an initial neural network model according to a state space and an action space to obtain a preset defense model.
[0112] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain a preset defense model, the module 300 is established to further include: an updating unit.
[0113] The updating unit is used to update the preset defense model using a preset reward function, wherein the preset reward function is:
[0114] R(D EO , D ET ) = f obstacle (D EO )+f triplet (D EO , D ET )
[0115] Among them, D EO is the resistance of the defense model before updating, D ET is the resistance of the updated defense model, f obstacle (D EO ) is a redundant term, f triplet (D EO , D ET ) is link-guided.
[0116] Optionally, in some embodiments, after the initial neural network model is trained according to the state space and the action space to obtain a preset defense model, the establishment unit also includes: a simulation subunit, a judgment subunit and a training subunit.
[0117] Among them, the simulation subunit is used to simulate LFA to attack the network bottleneck of each test network, and use the preset defense model to obtain the second target defense action, and perform passive defense according to the second target defense action to obtain the resistance result.
[0118] The judgment subunit is used to judge whether the preset defense model successfully resists according to the resistance result.
[0119] The training subunit is used to redefine the network bottleneck of the test network and establish a new state space and a new action space when the preset defense model fails to successfully resist, and train the preset defense model according to the new state space and the new action space until the preset defense model successfully resists.
[0120] Optionally, in some embodiments, the state space is:
[0121] S = {(f1, f2, ..., f n )};
[0122] Where S is the state space, f n Indicates status.
[0123] Optionally, in some embodiments, the action space is:
[0124] A={(a1,a2,...,a n )}
[0125] Among them, A is the action space, a n For action.
[0126] It should be noted that the aforementioned explanation of the LFA passive defense method embodiment is also applicable to the LFA passive defense device of this embodiment, and will not be repeated here.
[0127] According to the LFA passive defense device proposed in the embodiment of the present application, by obtaining the network topology and traffic information of the website to be defended, the graph centrality index of each node in the website to be defended is determined based on the network topology, so as to determine the key nodes of the website to be defended according to the graph centrality index of each node, and the traffic information, network topology and key nodes of the website to be defended are input into the preset defense model, the network bottleneck in the key node is identified, and the first target defense action of the network bottleneck is determined, and the first target defense action is executed for passive defense. Thus, the problem of manually establishing a backup link or node defense LFA is time-consuming and labor-intensive. The present application can automatically identify the network bottleneck and establish new nodes and links after LFA occurs through the preset defense model, introduce data flow into the new nodes and links, quickly resist attacks, and reduce the risk of network bottlenecks being paralyzed after being attacked.
[0128] Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device may include:
[0129] Memory 401 , processor 402 , and a computer program stored in the memory 401 and executable on the processor 402 .
[0130] When the processor 402 executes the program, the LFA passive defense method provided in the above embodiment is implemented.
[0131] Furthermore, the electronic device further comprises:
[0132] The communication interface 403 is used for communication between the memory 401 and the processor 402 .
[0133] The memory 401 is used to store computer programs that can be executed on the processor 402 .
[0134] The memory 401 may include a high-speed RAM (Random Access Memory) memory, and may also include a non-volatile memory, such as at least one disk memory.
[0135] If the memory 401, the processor 402 and the communication interface 403 are implemented independently, the communication interface 403, the memory 401 and the processor 402 can be connected to each other through a bus and communicate with each other. The bus can be an ISA (Industry Standard Architecture) bus, a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 4 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0136] Optionally, in a specific implementation, if the memory 401, the processor 402 and the communication interface 403 are integrated on a chip, the memory 401, the processor 402 and the communication interface 403 can communicate with each other through an internal interface.
[0137] The processor 402 may be a CPU (Central Processing Unit), or an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits configured to implement the embodiments of the present application.
[0138] An embodiment of the present application also provides a computer-readable storage medium having a computer program stored thereon, which implements the above-mentioned LFA passive defense method when executed by a processor.
[0139] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms are not necessarily directed to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or N embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0140] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of this application, "N" means at least two, such as two, three, etc., unless otherwise clearly and specifically defined.
[0141] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, fragment or portion of code comprising one or more executable instructions for implementing the steps of a custom logical function or process, and the scope of the preferred embodiments of the present application includes alternative implementations in which functions may not be performed in the order shown or discussed, including performing functions in a substantially simultaneous manner or in reverse order depending on the functions involved, which should be understood by technicians in the technical field to which the embodiments of the present application belong.
[0142] It should be understood that the various parts of the present application can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiment, the N steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array, a field programmable gate array, etc.
[0143] A person skilled in the art may understand that all or part of the steps in the method for implementing the above-mentioned embodiment may be completed by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, which, when executed, includes one or a combination of the steps of the method embodiment.
[0144] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in the field can change, modify, replace and modify the above embodiments within the scope of the present application.
Claims
1. A LFA passive defense method, characterized in that: The following steps are involved: Obtain the network topology and traffic information of the website to be defended; Determine the graph centrality index of each node in the website to be defended according to the network topology structure, and determine the key nodes of the website to be defended according to the graph centrality index of each node; input the traffic information, network topology structure and key nodes of the website to be defended into a preset defense model, identify the network bottleneck in the key node, determine the first target defense action of the network bottleneck, and perform passive defense according to the first target defense action.
2. The method according to claim 1, characterized in that Before inputting the traffic information, the network topology and the key nodes into the preset defense model, it includes: Obtaining network topology and defense link information of at least one test website; Launch LFA simulation attacks on each test network respectively, determine the network bottleneck of each test network, establish a state space based on the network topology of each test network and the network bottleneck of each test network, and establish an action space based on the defense link information of each test network; The initial neural network model is trained according to the state space and the action space to obtain the preset defense model.
3. The method according to claim 2, characterized in that After the initial neural network model is trained according to the state space and the action space to obtain the preset defense model, the method further includes: The preset defense model is updated using a preset reward function, wherein the preset reward function is: R(D Eo ,D ET )=f obstacle (D Eo )+f triplet (D TO ,D ET ) Among them, D EO is the resistance of the defense model before updating, D ET To update the resistance of the defense model, f obstacle (D EO ) is a redundant term, f triplet (D EO ,D ET ) is link-guided.
4. The method according to claim 2, characterized in that: After the initial neural network model is trained according to the state space and the action space to obtain the preset defense model, the method further includes: Simulate LFA to attack the network bottleneck of each test network, obtain a second target defense action using a preset defense model, and perform passive defense according to the second target defense action to obtain a resistance result; Determining whether the preset defense model successfully resists according to the resistance result; If the preset defense model fails to successfully resist, the network bottleneck of the test network is redetermined, and a new state space and a new action space are established, and the preset defense model is trained according to the new state space and the new action space until the preset defense model successfully resists.
5. The method according to claim 2, characterized in that: The state space is: S={(f1,f2,…,f n )}; Where S is the state space, f n Indicates status.
6. The method according to claim 2, characterized in that The action space is: <h2 style=";text-align:left;direction:ltr">A = {(a1,a2,…,a<h2 style=";text-align:left;direction:ltr"> n <h2 style=";text-align:left;direction:ltr"> )} Among them, A is the action space, a n For action.
7. An LFA passive defense device, characterized in that: include: An acquisition module is used to obtain the network topology and traffic information of the website to be defended; A determination module, used to determine the graph centrality index of each node in the website to be defended according to the network topology structure, and determine the key nodes of the website to be defended according to the graph centrality index of each node; The defense module is used to input the traffic information, network topology and key nodes of the website to be defended into a preset defense model, identify the network bottleneck in the key node, determine the first target defense action of the network bottleneck, and perform passive defense according to the first target defense action.
8. The device according to claim 7, characterized in that Before inputting the traffic information, the network topology and the key nodes into the preset defense model, the acquisition module includes: An acquisition unit, used to acquire network topology and defense link information of at least one test website; A testing unit, configured to launch LFA simulation attacks on each test network to determine the network bottleneck of each test network, establish a state space based on the network topology of each test network and the network bottleneck of each test network, and establish an action space based on the defense link information of each test network; An establishing unit is used to train an initial neural network model according to the state space and the action space to obtain the preset defense model.
9. An electronic device, characterized in that: include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the LFA passive defense method according to any one of claims 1 to 6.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: The program is executed by a processor to implement the LFA passive defense method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Safety protection method and terminal based on active power distribution network MEC system
CN114880696A
Industrial control network automatic defense decision-making method oriented to partially unknown security state
CN116582330A
Network space intelligent game decision-making method and system
CN117196040A
Defense method and device for network environment, equipment, medium and program product
CN119071087A
Synchronous adaptive link flooding attack defense method for multi-dimensional identification heterogeneous network
CN119172130A