Network attack detection method and device, electronic equipment and storage medium
By collecting and monitoring network data packets in real time and detecting distributed denial of service attacks, the problem of the inability to detect in real time in the existing technology is solved, and effective guarantees for user account security are achieved.
Patent Information
- Application Number
- CN202411976255.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
AI Technical Summary
The existing technology cannot detect distributed denial of service attacks in real time, resulting in the inability to ensure the security of users' accounts and bring immeasurable losses to users.
By collecting the network data packets of the source host in real time, monitoring and statistics of the network data packets are carried out according to the network attack method, monitoring data within a unit of time is obtained, and monitoring data is detected based on these data.
Real-time detection and identification of distributed denial of service attacks is realized, effectively ensuring the security of users' accounts and avoiding immeasurable losses to users.
Smart Images

Figure CN119945744A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer network security technology, and in particular, to a network attack detection method, device, electronic device and storage medium. Background Art
[0002] With the rapid development of the Internet, network security issues have become increasingly prominent. DDoS (Distributed Denial of Service) attacks pose a serious threat to the availability of network services. Traditional network monitoring and security systems are often unable to effectively detect such network attacks in real time, resulting in the inability to protect user account security, causing immeasurable losses to users. Summary of the invention
[0003] In view of this, in order to solve the technical problem in the prior art that distributed denial of service attacks cannot be detected in real time, which makes it impossible to guarantee the security of user accounts and causes immeasurable losses to users, the embodiments of the present application provide a network attack detection method, device, electronic device and storage medium.
[0004] In a first aspect, an embodiment of the present application provides a network attack detection method, the method comprising:
[0005] Real-time collection of network data packets sent from the source host to the target host;
[0006] Performing monitoring data statistics on the network data packets according to the network attack mode to obtain monitoring data within a unit time; wherein the network attack mode is an attack means of a distributed denial of service attack;
[0007] Based on the monitoring data, it is detected whether there is a network attack on the target host by the network attack method.
[0008] Optionally, as in the aforementioned method, the monitoring data statistics of the network data packets are performed according to the network attack mode to obtain the monitoring data, including:
[0009] Obtaining the monitoring data type corresponding to the network attack mode;
[0010] Monitoring data statistics are performed on the network data packets based on the monitoring data type to obtain monitoring data within a unit time.
[0011] Optionally, as in the aforementioned method, obtaining the monitoring data type corresponding to the network attack mode includes:
[0012] Querying in a monitoring data type query table to obtain the monitoring data type corresponding to the network attack mode;
[0013] The corresponding relationship between the network attack mode and the monitoring data type stored in the monitoring data type query table includes:
[0014] When the network attack mode is a SYN Flood attack mode, the corresponding monitoring data type includes a SYN network data packet rate;
[0015] When the network attack mode is a UDP Flood attack mode, the corresponding monitoring data types include UDP network data packet ratio data and UDP network data packet average length;
[0016] When the network attack mode is an ICMP Flood attack mode, the corresponding monitoring data type includes ICMP network data packet flow;
[0017] When the network attack mode is an HTTP Flood attack mode, the corresponding monitoring data type includes HTTP network data packet rate.
[0018] Optionally, as in the aforementioned method, the performing monitoring data statistics on the network data packet based on the monitoring data type to obtain the monitoring data within a unit time includes:
[0019] Parsing the network data packet to obtain the data packet type and data packet length;
[0020] In the case where the monitored data type includes the SYN network data packet rate, the total number of first data packets of the SYN network data packets of the data packet type SYN in a unit time is counted, and the SYN network data packet rate is determined based on the total number of the first data packets, the unit time and the data packet length of each of the SYN network data packets; or
[0021] In the case where the monitored data types include UDP network data packet ratio data and UDP network data packet average length, the total number of second data packets of UDP network data packets whose data packet type is UDP and the total number of data packets of the network data packets are counted within the unit time, the UDP network data packet ratio data is determined based on the total number of the second data packets and the total number of data packets, and the UDP network data packet average length is determined based on the data packet length of each of the UDP network data packets; or
[0022] In the case where the monitored data type includes ICMP network data packet flow, counting the total number of third data packets of ICMP network data packets whose data packet type is ICMP within the unit time, and determining the ICMP network data packet flow based on the total number of third data packets and the data packet length of each of the ICMP network data packets; or
[0023] In the case where the monitored data type includes HTTP network data packet rate, the total number of fourth data packets of HTTP network data packets whose data packet type is HTTP is counted per unit time, and the HTTP network data packet rate is determined based on the total number of fourth data packets, the unit time and the data packet length of each of the HTTP network data packets.
[0024] Optionally, as in the aforementioned method, detecting whether there is a network attack on the target host by the network attack method based on the monitoring data includes:
[0025] Obtaining a preset data threshold corresponding to the network attack method;
[0026] Determining whether the monitoring data exceeds the preset data threshold;
[0027] In the case where it is determined that the monitoring data exceeds the preset data threshold, detecting the presence of a network attack on the target host by the network attack method;
[0028] When it is determined that the monitoring data does not exceed the preset data threshold, it is detected that there is no network attack on the target host by the network attack method.
[0029] Optionally, as in the aforementioned method, in the case where it is determined that the monitoring data exceeds the preset data threshold, detecting the existence of a network attack on the target host by the network attack method includes:
[0030] When the SYN network data packet rate exceeds a preset SYN network data packet rate threshold, detecting the existence of a network attack on the target host by the SYN Flood attack mode; or,
[0031] When the proportion of the UDP network data packets exceeds the preset data packet proportion threshold, and the average length of the UDP network data packets exceeds the preset average length threshold, it is detected that there is a network attack on the target host by the UDP Flood attack method; or,
[0032] When the ICMP network data packet flow exceeds a preset data packet flow threshold, detecting the existence of a network attack on the target host by the ICMP Flood attack mode; or,
[0033] When the HTTP network data packet rate exceeds a preset HTTP network data packet rate threshold, it is detected that there is a network attack on the target host using the HTTP Flood attack method.
[0034] Optionally, as in the aforementioned method, the method further comprises:
[0035] In the case of detecting that there is a network attack on the target host by the network attack method, generating alarm information, and generating a detection result based on the monitoring data;
[0036] The alarm information and the detection result are saved in a local log file, and the alarm information and the detection result are sent to a remote log server and / or an external log server.
[0037] In a second aspect, an embodiment of the present application provides a network attack detection device, the device comprising:
[0038] A collection module is used to collect network data packets sent from the source host to the target host in real time;
[0039] A statistics module, used to monitor the network data packets according to the network attack mode to obtain the monitoring data within a unit time; wherein the network attack mode is a distributed denial of service attack;
[0040] A detection module is used to detect whether there is a network attack on the target host in the network attack mode based on the monitoring data.
[0041] In a third aspect, an embodiment of the present application provides an electronic device, which includes: a processor and a memory, the processor is used to execute a program for network attack detection stored in the memory to implement the above-mentioned network attack detection method.
[0042] In a fourth aspect, an embodiment of the present application provides a storage medium, wherein the storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the above-mentioned network attack detection method.
[0043] In the embodiment of the present invention, real-time collection of network data packets sent by the source host to the target host is adopted; monitoring data statistics of the network data packets are performed according to the network attack mode to obtain monitoring data within a unit time; wherein the network attack mode is the attack means of a distributed denial of service attack; based on the monitoring data, it is detected whether there is a network attack on the target host by the network attack mode. Compared with the prior art, the present invention can obtain network data packets transmitted by the network in real time, and perform real-time statistics of the network data packets according to the network attack mode, so as to detect and identify various network attack modes of distributed denial of service attacks in real time through the statistical monitoring data, effectively protecting the user's account security and avoiding immeasurable losses to the user. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.
[0045] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0046] Figure 1 A flowchart of an embodiment of a network attack detection method provided in an embodiment of the present application;
[0047] Figure 2 A flowchart of another network attack detection method provided in an embodiment of the present application;
[0048] Figure 3 A flowchart of another network attack detection method provided in an embodiment of the present application;
[0049] Figure 4 A block diagram of an embodiment of a network attack detection device provided in an embodiment of the present application;
[0050] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0051] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0052] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0053] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0054] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology and application system that uses digital computers or machines controlled by digital computers to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.
[0055] The basic technologies of artificial intelligence generally include sensors, dedicated artificial intelligence chips, cloud computing, storage, big data processing technology, operation / interaction systems, mechatronics, etc. Artificial intelligence software technologies mainly include computer vision technology, robotics technology, biometrics technology, speech processing technology, natural language processing technology, and machine learning / deep learning.
[0056] It should be understood that the size of the serial numbers of the steps in the following embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0057] To facilitate understanding of the embodiments of the present application, further explanation will be given below with reference to specific embodiments in conjunction with the accompanying drawings. The embodiments do not constitute a limitation on the embodiments of the present application.
[0058] According to one aspect of the embodiments of the present application, a network attack detection method is provided. Figure 1 , Figure 1 A flowchart of an embodiment of a network attack detection method provided in an embodiment of the present application. Figure 1 The process shown may include the following steps:
[0059] Step 101, collecting network data packets sent from a source host to a target host in real time;
[0060] The above-mentioned network attack detection method can be implemented through a network attack detection system. During the specific implementation, the network attack detection system can be deployed in a bypass manner and connected to a network device (router or switch) to collect network data packets sent from the source host to the target host in real time. The specific network attack detection system can use standard network protocols and data formats, such as HTTP (Hypertext Transfer Protocol), JSON (JavaScript Object Notation), etc. to connect with the network device.
[0061] In actual application, since different source hosts may attack the same target host, in order to facilitate real-time detection of whether each source host is attacking the target host, in this embodiment, the network attack detection system collects and records network data packets sent by different source hosts to the same target host, so as to facilitate real-time detection of whether each source host is attacking the target host by analyzing the network data packets sent by different source hosts.
[0062] In actual application, the network attack detection system can collect network data packets from different source hosts for the same target host in real time based on the Sflow (Sampled Flow, network traffic control technology) data sampling method. Sflow is a high-performance traffic sampling technology that can provide sampling data of network traffic without adding additional load to network devices in the CDN (Content Delivery Network) node network. Sflow is an open standard widely supported by the industry. Most network devices and CDN infrastructure support the Sflow protocol. Therefore, it can be integrated into the network attack detection system without modifying the existing network architecture to sample a large number of network data packets, which greatly reduces the amount of data that needs to be processed and reduces the system's resource consumption.
[0063] The data sampling method may also adopt NetFlow (network flow) method, IPFIX (IP Flow Information Export, IP data flow information output) method, etc., and the collection method of network data packets is not limited here.
[0064] Step 102, monitoring data statistics of network data packets are performed according to the network attack mode to obtain monitoring data within a unit time;
[0065] The above network attack method is a means of attack of a distributed denial of service attack; since there are multiple means of attack of a distributed denial of service attack, i.e., network attack methods, in this embodiment, monitoring data statistics are performed on network data packets for each network attack method to obtain monitoring data within a unit time corresponding to each network attack method. The unit time may be per second, per minute, or per hour, which is not limited here; the monitoring data may be understood as data that can directly detect whether the source host has used the network attack method to carry out a network attack on the target host.
[0066] In actual application, due to the large number of network data packets, in order to improve the rate and security of data statistics, in this embodiment, engineering coroutine technologies such as object pools, pre-allocated buffers, and large buffer channels can be used to realize parallel processing of network data packet monitoring data statistics, and synchronization primitives and thread-safe data structures (such as sync.Map, sync.Mutex) are used to ensure the consistency and thread safety of data statistics; through efficient concurrent processing and optimization, the network attack detection system can analyze and count network data packets at the millisecond level to facilitate timely detection of network attacks.
[0067] Step 103: Detect whether there is a network attack on the target host in the form of a network attack based on the monitoring data.
[0068] In this embodiment, by using network data packets sent from different source hosts to the same target host, the monitoring data for each network attack method can be statistically compiled, and it can be detected in real time whether there are network attacks on the target host by network attack methods corresponding to the monitoring data for different source hosts. This network attack detection method can detect and identify various network attack methods of distributed denial of service attacks in real time, effectively protecting the user's account security and avoiding immeasurable losses to the user.
[0069] like Figure 2 As shown, as an optional implementation, as in the aforementioned method, step 102 performs monitoring data statistics on network data packets according to the network attack mode, and obtaining monitoring data within a unit time includes the following steps:
[0070] Step 201, obtaining monitoring data types corresponding to network attack methods;
[0071] Among them, the monitoring data type can be used to characterize which type of monitoring data corresponds to the network attack method. In specific implementation, since the monitoring data required for different network attack methods are different, in order to obtain the monitoring data corresponding to the network attack method, it is necessary to first obtain the monitoring data type corresponding to the network attack method, so as to obtain the monitoring data corresponding to the network attack method through the monitoring data type.
[0072] Specifically, the monitoring data type corresponding to the network attack method can be obtained by querying the monitoring data type query table. Since the monitoring data type query table stores the correspondence between the network attack method and the monitoring data type, the monitoring data type corresponding to the network attack method can be obtained by querying the monitoring data type query table.
[0073] In order to facilitate understanding of the correspondence between the network attack methods and the monitoring data types stored in the monitoring data type query table, as shown in Table 1, in this embodiment, representative attack methods in distributed denial of service attacks, including SYN (Synchronize Sequence Numbers) flood attack method, ICMP (Internet Control Message Protocol) flood attack method, UDP (User Datagram Protocol) flood attack method and HTTP Flood attack method, are used as examples for explanation.
[0074] Table 1
[0075]
[0076] It can be seen from Table 1 that when the network attack mode is SYN Flood attack mode, the corresponding monitoring data type includes SYN network data packet rate; when the network attack mode is UDP Flood attack mode, the corresponding monitoring data type includes UDP network data packet proportion data and UDP network data packet average length; when the network attack mode is ICMP Flood attack mode, the corresponding monitoring data type includes ICMP network data packet flow; when the network attack mode is HTTP Flood attack mode, the corresponding monitoring data type includes HTTP network data packet rate.
[0077] It should be noted that Table 1 only shows an example of the correspondence between network attack methods and monitoring data types. The specific correspondence between network attack methods and monitoring data types can be set according to actual needs and is not limited here.
[0078] Step 202: Perform monitoring data statistics on the network data packets based on the monitoring data type to obtain monitoring data within a unit time.
[0079] Continuing with the previous example, taking the network attack methods of SYN Flood attack method, UDP Flood attack method, ICMP Flood attack method, and HTTP Flood attack method as examples, it is explained that the statistical process of monitoring data corresponding to each network attack method can be achieved through steps A1 to A5:
[0080] Step A1, parsing the network data packet to obtain the data packet type and data packet length;
[0081] The data packet type can be understood as the communication protocol, port number and / or flag bit that can identify the type of network data packet; the data packet length refers to the amount of data contained in the network data packet. The above data packet type and data packet length are both included in the network data packet. Therefore, the data packet type and data packet length can be obtained by parsing Wang Liguo's data packet.
[0082] Step A2, when the monitored data type includes the SYN network data packet rate, counting the total number of first data packets of SYN network data packets of the data packet type SYN per unit time, and determining the SYN network data packet rate based on the total number of first data packets, the unit time and the data packet length of each SYN network data packet; or
[0083] For the SYN Flood attack method, the corresponding monitoring data type is the SYN network data packet rate. Then the monitoring data corresponding to the SYN Flood attack method is the SYN network data packet rate. In actual application, the SYN network data packet rate can be calculated by the total number of first data packets of SYN network data packets with a data packet type of SYN per unit time, the unit time and the data packet length of each SYN network data packet. Among them, the SYN network data packet rate calculation formula is: S1 = (total number of first data packets * sum of data packet lengths of each SYN network data packet) / unit time.
[0084] Step A3, when the monitored data types include UDP network data packet ratio data and UDP network data packet average length, count the total number of second data packets of UDP network data packets whose data packet type is UDP and the total number of network data packets within a unit time, determine the UDP network data packet ratio data based on the total number of second data packets and the total number of data packets, and determine the UDP network data packet average length based on the data packet length of each UDP network data packet; or,
[0085] For the UDP Flood attack method, the corresponding monitoring data types are the UDP network data packet ratio data and the average length of UDP network data packets. Then the monitoring data corresponding to the UDP Flood attack method are the UDP network data packet ratio data and the average length of UDP network data packets. In actual application, the UDP network data packet ratio data can be obtained by the ratio of the total number of second data packets of UDP network data packets per unit time to the total number of network data packets; the average length of UDP network data packets can be obtained by the average of the sum of the data packet lengths of each UDP network data packet.
[0086] Step A4, when the monitored data type includes ICMP network data packet flow, counting the total number of third data packets of ICMP network data packets whose data packet type is ICMP within a unit time, and determining the ICMP network data packet flow based on the total number of third data packets and the data packet length of each ICMP network data packet; or,
[0087] For the ICMP Flood attack method, the corresponding monitoring data type is ICMP network data packet traffic. Then the monitoring data corresponding to the ICMP Flood attack method is ICMP network data packet traffic. In actual application, the ICMP network data packet traffic can be obtained by multiplying the total number of the third data packets of ICMP network data packets with the data packet type of ICMP per unit time by the sum of the data packet lengths of each ICMP network data packet.
[0088] Step A5, when the monitored data type includes the HTTP network data packet rate, count the total number of fourth data packets of the HTTP network data packets whose data packet type is HTTP within a unit time, and determine the HTTP network data packet rate based on the total number of fourth data packets, the unit time and the data packet length of each HTTP network data packet.
[0089] For the HTTP Flood attack method, the corresponding monitoring data type is the HTTP network data packet rate. Then the monitoring data corresponding to the HTTP Flood attack method is the HTTP network data packet rate. In actual application, the HTTP network data packet rate can be calculated by the total number of fourth data packets of HTTP network data packets with the data packet type of HTTP per unit time, the unit time and the data packet length of each HTTP network data packet. Among them, the HTTP network data packet rate calculation formula is: S2 = (total number of fourth data packets * sum of the data packet lengths of each HTTP network data packet) / unit time.
[0090] Through the method in this embodiment, statistics of monitoring data corresponding to network attack methods can be achieved based on the types of monitoring data corresponding to different network attack methods, which facilitates the subsequent real-time detection of network attacks through the statistical monitoring data.
[0091] like Figure 3 As shown, as an optional implementation, as in the aforementioned method, the step 103 detects whether there is a network attack on the target host in a network attack manner based on the monitoring data, including the following steps:
[0092] Step 301, obtaining a preset data threshold corresponding to a network attack mode;
[0093] Among them, the preset data threshold can be understood as a pre-set data critical value for measuring whether there is a network attack.
[0094] Step 302, determining whether the monitoring data exceeds a preset data threshold;
[0095] Step 303, when it is determined that the monitoring data exceeds the preset data threshold, detecting the existence of a network attack on the target host in a network attack mode;
[0096] In actual application, since the monitoring data corresponding to different network attack methods are different, the preset data thresholds corresponding to different network attack methods are also different.
[0097] Continuing with the previous example, when the monitoring data is the SYN network data packet rate, the preset data threshold corresponding to the SYN Flood attack mode is the preset SYN network data packet rate threshold, that is, when the SYN network data packet rate exceeds the preset SYN network data packet rate threshold, a network attack on the target host using the SYN Flood attack mode is detected.
[0098] In one embodiment, when the monitoring data is the UDP network data packet proportion data and the UDP network data packet average length, the preset data thresholds corresponding to the UDP Flood attack mode are the preset data packet proportion threshold and the preset data packet average length threshold, that is, when the UDP network data packet proportion data exceeds the preset data packet proportion threshold, and the UDP network data packet average length exceeds the preset data packet average length threshold, it is detected that there is a network attack on the target host using the UDP Flood attack mode.
[0099] In another embodiment, in addition to using the UDP network data packet ratio data and the UDP network data packet average length monitoring data to detect whether there is a UDP Flood attack on the target host, the UDP network data packet ratio data and the packet length of each UDP network data packet can also be used to detect the network attack of the UDP Flood attack, that is, when the UDP network data packet ratio data exceeds the preset data packet ratio threshold, and the packet length of each UDP network data packet exceeds the preset data packet length threshold, it is detected that there is a UDP Flood attack on the target host. It can be seen that there may be different monitoring data to detect the same network attack method, which is not limited here.
[0100] When the monitored data is ICMP network data packet flow, the preset data threshold corresponding to the ICMP Flood attack mode is the preset data packet flow threshold, that is, when the ICMP network data packet flow exceeds the preset data packet flow threshold, a network attack on the target host using the ICMP Flood attack mode is detected.
[0101] When the monitoring data is the HTTP network data packet rate, the preset data threshold corresponding to the HTTP Flood attack mode is the preset HTTP network data packet rate threshold, that is, when the HTTP network data packet rate exceeds the preset HTTP network data packet rate threshold, it is detected that there is a network attack on the target host using the HTTP Flood attack mode.
[0102] Step 304 , when it is determined that the monitoring data does not exceed the preset data threshold, detect that there is no network attack on the target host in the form of a network attack.
[0103] However, when the monitoring data corresponding to each network attack method does not exceed the corresponding preset data threshold, it is deemed that there is no network attack on the target host by the source host using the network attack method, and the network attack detection needs to be continued.
[0104] The preset data threshold corresponding to the above network attack mode can be set according to actual needs through command line parameters or configuration files, and the detection of network attack mode can also be enabled or disabled through command line parameters or configuration files.
[0105] Through the method in this embodiment, various network attack methods of distributed denial of service attacks can be detected and identified in real time by comparing the statistical monitoring data with the preset data threshold, thereby effectively protecting the user's account security and avoiding immeasurable losses to the user.
[0106] In actual application, in order to meet different monitoring and integration requirements, when a network attack on the target host is detected, an alarm message is generated, and a detection result is generated based on the monitoring data; the alarm message and the detection result are saved in a local log file, and the alarm message and the detection result are sent to a remote log server and / or an external log server.
[0107] The above detection results are analysis reports including monitoring data, network attack methods, the attacked target host and the source host that initiated the attack; the above alarm information is prompt information that the target host is under network attack.
[0108] The detection results and alarm information are saved in the local log file of the network attack detection system to facilitate the subsequent provision of attack documents; the alarm information and detection results are sent to the remote log server, which can display the above alarm information and detection results on its configured user interface to facilitate technical personnel to discover network attacks in time and intercept their network attack methods according to the detection results; the alarm information and detection results are sent to the external log server of the third-party customer to remind the third-party customer to take corresponding measures (such as shutting down services and ceasing operations) to avoid unnecessary economic losses.
[0109] In specific implementation, the above-mentioned network attack detection method can not only be applied to the detection of various network attack methods of distributed denial of service attacks, but also to the detection of various network attacks such as port scanning attacks, email attacks, cross-site scripting attacks, etc. At this time, it is necessary to count the monitoring data corresponding to the network attack, and then realize real-time detection of network attacks by comparing the monitoring data with the preset data threshold corresponding to the network attack.
[0110] For ease of understanding, take the detection of port scanning attacks as an example. After collecting the network data packets sent by the source host to the target host, it is necessary to parse the network data packets to obtain the scanning port number, and count the total number of scanning port numbers that are not specific scanning port numbers (for example, 80, 443). This total number is the monitoring data corresponding to the port scanning attack. If the total number exceeds the preset total number threshold, it is considered that the source host has launched a port scanning attack on the target host.
[0111] Through the above analysis, different network attacks only correspond to different monitoring data and preset data thresholds, but the principle of network attack detection is the same, which is to detect the network attack launched by the source host to the target host in real time by comparing the statistical monitoring data with the preset data threshold. Therefore, the network attack detection method provided in this embodiment is applicable to the detection of all network attacks.
[0112] See also Figure 4 , is a block diagram of an embodiment of a network attack detection device provided in an embodiment of the present application. Figure 4 As shown, the device comprises:
[0113] The collection module 401 is used to collect network data packets sent from the source host to the target host in real time;
[0114] The statistics module 402 is used to monitor the network data packets according to the network attack mode to obtain the monitoring data within a unit time; wherein the network attack mode is a distributed denial of service attack;
[0115] The detection module 403 is used to detect whether there is a network attack on the target host in the form of a network attack based on the monitoring data.
[0116] Specifically, the specific process of each module in the device of the embodiment of the present invention realizing its function can be referred to the relevant description in the method embodiment, which will not be repeated here.
[0117] As an optional implementation, the above statistical module includes:
[0118] A monitoring data type acquisition module is used to obtain the monitoring data type corresponding to the network attack method;
[0119] The monitoring data statistics module is used to perform monitoring data statistics on network data packets based on the monitoring data type to obtain monitoring data within a unit time.
[0120] Specifically, the specific process of each module in the device of the embodiment of the present invention realizing its function can be referred to the relevant description in the method embodiment, which will not be repeated here.
[0121] As an optional implementation, the monitoring data type acquisition module includes:
[0122] A query acquisition module, used to query and acquire the monitoring data type corresponding to the network attack mode in the monitoring data type query table;
[0123] The corresponding relationship between the network attack mode and the monitoring data type stored in the monitoring data type query table includes:
[0124] When the network attack mode is SYN Flood attack mode, the corresponding monitoring data types include SYN network data packet rate;
[0125] When the network attack method is UDP Flood attack, the corresponding monitoring data types include UDP network data packet ratio data and UDP network data packet length;
[0126] When the network attack mode is ICMP Flood attack mode, the corresponding monitoring data type includes ICMP network data packet flow;
[0127] When the network attack mode is HTTP Flood attack mode, the corresponding monitoring data type includes HTTP network data packet rate.
[0128] Specifically, the specific process of each module in the device of the embodiment of the present invention realizing its function can be referred to the relevant description in the method embodiment, which will not be repeated here.
[0129] As an optional implementation, the monitoring data statistics module includes:
[0130] The parsing module is used to parse the network data packet to obtain the data packet type and data packet length;
[0131] A first statistical determination module is used to count the total number of first packets of SYN network packets whose packet type is SYN within a unit time when the monitored data type includes the SYN network packet rate, and determine the SYN network packet rate based on the total number of first packets, the unit time and the packet length of each SYN network packet; or
[0132] A second statistical determination module is used to count the total number of second packets of UDP network packets whose packet type is UDP and the total number of network packets within a unit time when the monitored data types include the proportion of UDP network packets and the average length of UDP network packets, determine the proportion of UDP network packets based on the total number of second packets and the total number of packets, and determine the average length of UDP network packets based on the packet length of each UDP network packet; or
[0133] A third statistical determination module is used to count the total number of third data packets of ICMP network data packets whose data packet type is ICMP within a unit time when the monitored data type includes ICMP network data packet flow, and determine the ICMP network data packet flow based on the total number of third data packets and the data packet length of each ICMP network data packet; or
[0134] The fourth statistical determination module is used to count the total number of fourth data packets of HTTP network data packets whose data packet type is HTTP per unit time when the monitored data type includes the HTTP network data packet rate, and determine the HTTP network data packet rate based on the total number of fourth data packets, the unit time and the data packet length of each HTTP network data packet.
[0135] Specifically, the specific process of each module in the device of the embodiment of the present invention realizing its function can be referred to the relevant description in the method embodiment, which will not be repeated here.
[0136] As an optional implementation, the detection module includes:
[0137] A threshold acquisition module is used to obtain a preset data threshold corresponding to a network attack method;
[0138] A determination module, used to determine whether the monitoring data exceeds a preset data threshold;
[0139] The first detection module is used to detect the existence of a network attack on the target host in a network attack mode when it is determined that the monitoring data exceeds a preset data threshold;
[0140] The second detection module is used to detect whether there is a network attack on the target host in the form of a network attack when it is determined that the monitoring data does not exceed a preset data threshold.
[0141] Specifically, the specific process of each module in the device of the embodiment of the present invention realizing its function can be referred to the relevant description in the method embodiment, which will not be repeated here.
[0142] As an optional implementation, the first detection module includes:
[0143] The third detection module is used to detect the existence of a network attack on the target host in the form of a SYN Flood attack when the SYN network data packet rate exceeds a preset SYN network data packet rate threshold; or
[0144] The fourth detection module is used to detect the existence of a network attack on the target host by a UDP Flood attack when the proportion of UDP network data packets exceeds a preset data packet proportion threshold and the average length of UDP network data packets exceeds a preset data packet length threshold; or
[0145] A fifth detection module is used to detect the existence of an ICMP Flood attack on a target host when the ICMP network data packet flow exceeds a preset data packet flow threshold; or,
[0146] The sixth detection module is used to detect the existence of a network attack on the target host in the form of HTTP Flood attack when the HTTP network data packet rate exceeds a preset HTTP network data packet rate threshold.
[0147] Specifically, the specific process of each module in the device of the embodiment of the present invention realizing its function can be referred to the relevant description in the method embodiment, which will not be repeated here.
[0148] As an optional implementation, the above device further includes:
[0149] A generation module, used to generate alarm information when a network attack on a target host is detected, and to generate detection results based on monitoring data;
[0150] The saving and sending module is used to save the alarm information and the detection result in the local log file, and send the alarm information and the detection result to the remote log server and / or the external log server.
[0151] Specifically, the specific process of each module in the device of the embodiment of the present invention realizing its function can be referred to the relevant description in the method embodiment, which will not be repeated here.
[0152] Figure 5A schematic diagram of the structure of an electronic device provided in an embodiment of the present application, Figure 5 The electronic device 1200 shown includes: at least one processor 1201, a memory 1202, at least one network interface 1204 and other user interfaces 1203. The various components in the electronic device 1200 are coupled together via a bus system 1205. It is understood that the bus system 1205 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 1205 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, the bus system 1205 is not described in detail. Figure 5 Various buses are labeled as bus system 1205.
[0153] The user interface 1203 may include a display, a keyboard, or a pointing device (eg, a mouse, a trackball, a touch pad, or a touch screen).
[0154] It can be understood that the memory 1202 in the embodiment of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus random access memory (DRRAM). The memory 1202 described herein is intended to include, but is not limited to, these and any other suitable types of memory.
[0155] In some embodiments, the memory 1202 stores the following elements, executable units or data structures, or a subset thereof, or an extended set thereof: an operating system 12021 and an application program 12022 .
[0156] Among them, the operating system 12021 includes various system programs, such as a framework layer, a core library layer, a driver layer, etc., which are used to implement various basic services and process hardware-based tasks. The application 12022 includes various application programs, such as a media player (Media Player), a browser (Browser), etc., which are used to implement various application services. The program for implementing the method of the embodiment of the present application can be included in the application 12022.
[0157] In the embodiment of the present application, by calling the program or instructions stored in the memory 1202, specifically, the program or instructions stored in the application 12022, the processor 1201 is used to execute the method steps provided by each method embodiment.
[0158] The method disclosed in the above embodiment of the present application can be applied to the processor 1201, or implemented by the processor 1201. The processor 1201 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 1201. The above processor 1201 can be a general processor, a digital signal processor (Digital Signal Processor, DSP), an application specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The methods, steps and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the embodiment of the present application can be directly embodied as a hardware decoding processor to execute, or the hardware and software units in the decoding processor can be executed. The software unit can be located in a mature storage medium in the field such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 1202, and the processor 1201 reads the information in the memory 1202 and completes the steps of the above method in combination with its hardware.
[0159] It is understood that the embodiments described herein may be implemented in hardware, software, firmware, middleware, microcode, or a combination thereof. For hardware implementation, the processing unit may be implemented in one or more application specific integrated circuits (ASIC), digital signal processors (DSP), digital signal processing devices (DSPDevice, DSPD), programmable logic devices (PLD), field programmable gate arrays (FPGA), general purpose processors, controllers, microcontrollers, microprocessors, other electronic units for performing the functions described in the present application, or a combination thereof.
[0160] For software implementation, the technology described herein can be implemented by a unit that performs the functions described herein. The software code can be stored in a memory and executed by a processor. The memory can be implemented in the processor or outside the processor.
[0161] The electronic device provided in this embodiment may be Figure 5 The electronic device shown in FIG. 1 may perform the following steps: Figure 1-3 All steps of the network attack detection method in Figure 1-3 For details, please refer to the technical effect of the network attack detection method shown in Figure 1-3 For the sake of brevity, the relevant description is not repeated here.
[0162] The embodiment of the present application also provides a storage medium (computer-readable storage medium). The storage medium here stores one or more programs. The storage medium may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a read-only memory, a flash memory, a hard disk or a solid-state drive; the memory may also include a combination of the above-mentioned types of memory.
[0163] When one or more programs in the storage medium can be executed by one or more processors, the above-mentioned network attack detection method can be implemented.
[0164] The processor is used to execute the network attack detection program stored in the memory to implement the steps of the network attack detection method.
[0165] The professionals should also be further aware that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented with electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0166] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0167] The specific implementation methods described above further illustrate the purpose, technical solutions and beneficial effects of the present application in detail. It should be understood that the above description is only the specific implementation method of the present application and is not intended to limit the scope of protection of the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application.
Claims
1. A network attack detection method, characterized in that: The method comprises: Real-time collection of network data packets sent from the source host to the target host; Performing monitoring data statistics on the network data packets according to the network attack mode to obtain monitoring data within a unit time; wherein the network attack mode is an attack means of a distributed denial of service attack; Based on the monitoring data, it is detected whether there is a network attack on the target host by the network attack method.
2. The method according to claim 1, characterized in that The monitoring data statistics of the network data packets are performed according to the network attack mode to obtain the monitoring data, including: Obtaining the monitoring data type corresponding to the network attack mode; Monitoring data statistics are performed on the network data packets based on the monitoring data type to obtain monitoring data within a unit time.
3. The method according to claim 2, characterized in that The monitoring data type corresponding to the network attack mode is obtained, including: Querying in a monitoring data type query table to obtain the monitoring data type corresponding to the network attack mode; The corresponding relationship between the network attack mode and the monitoring data type stored in the monitoring data type query table includes: When the network attack mode is a SYN Flood attack mode, the corresponding monitoring data type includes a SYN network data packet rate; When the network attack mode is a UDP Flood attack mode, the corresponding monitoring data types include UDP network data packet ratio data and UDP network data packet average length; When the network attack mode is an ICMP Flood attack mode, the corresponding monitoring data type includes ICMP network data packet flow; When the network attack mode is an HTTP Flood attack mode, the corresponding monitoring data type includes HTTP network data packet rate.
4. The method according to claim 3, characterized in that The monitoring data statistics of the network data packet based on the monitoring data type to obtain the monitoring data within a unit time include: Parsing the network data packet to obtain the data packet type and data packet length; In the case where the monitored data type includes the SYN network data packet rate, the total number of first data packets of the SYN network data packets of the data packet type SYN in a unit time is counted, and the SYN network data packet rate is determined based on the total number of the first data packets, the unit time and the data packet length of each of the SYN network data packets; or In the case where the monitored data types include UDP network data packet ratio data and UDP network data packet average length, the total number of second data packets of UDP network data packets whose data packet type is UDP and the total number of data packets of the network data packets are counted within the unit time, the UDP network data packet ratio data is determined based on the total number of the second data packets and the total number of data packets, and the UDP network data packet average length is determined based on the data packet length of each of the UDP network data packets; or In the case where the monitored data type includes ICMP network data packet flow, counting the total number of third data packets of ICMP network data packets whose data packet type is ICMP within the unit time, and determining the ICMP network data packet flow based on the total number of third data packets and the data packet length of each of the ICMP network data packets; or In the case where the monitored data type includes HTTP network data packet rate, the total number of fourth data packets of HTTP network data packets whose data packet type is HTTP is counted per unit time, and the HTTP network data packet rate is determined based on the total number of fourth data packets, the unit time and the data packet length of each of the HTTP network data packets.
5. The method according to claim 4, characterized in that The detecting, based on the monitoring data, whether there is a network attack on the target host by the network attack method comprises: Obtaining a preset data threshold corresponding to the network attack method; Determining whether the monitoring data exceeds the preset data threshold; In the case where it is determined that the monitoring data exceeds the preset data threshold, detecting the presence of a network attack on the target host by the network attack method; When it is determined that the monitoring data does not exceed the preset data threshold, it is detected that there is no network attack on the target host by the network attack method.
6. The method according to claim 5, characterized in that When it is determined that the monitoring data exceeds the preset data threshold, detecting the existence of a network attack on the target host by the network attack method includes: When the SYN network data packet rate exceeds a preset SYN network data packet rate threshold, detecting the existence of a network attack on the target host by the SYN Flood attack mode; or, When the proportion of the UDP network data packets exceeds the preset data packet proportion threshold, and the average length of the UDP network data packets exceeds the preset data packet length threshold, it is detected that there is a network attack on the target host by the UDP Flood attack method; or, When the ICMP network data packet flow exceeds a preset data packet flow threshold, detecting the existence of a network attack on the target host by the ICMP Flood attack method; or, When the HTTP network data packet rate exceeds a preset HTTP network data packet rate threshold, it is detected that there is a network attack on the target host using the HTTP Flood attack method.
7. The method according to claim 1, characterized in that The method further comprises: In the case of detecting that there is a network attack on the target host by the network attack method, generating alarm information, and generating a detection result based on the monitoring data; The alarm information and the detection result are saved in a local log file, and the alarm information and the detection result are sent to a remote log server and / or an external log server.
8. A network attack detection device, characterized in that: The device comprises: A collection module is used to collect network data packets sent from the source host to the target host in real time; A statistics module, used to monitor the network data packets according to the network attack mode to obtain the monitoring data within a unit time; wherein the network attack mode is a distributed denial of service attack; A detection module is used to detect whether there is a network attack on the target host in the network attack mode based on the monitoring data.
9. An electronic device, characterized in that: include: A processor and a memory, wherein the processor is used to execute a network attack detection program stored in the memory to implement the network attack detection method according to any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the network attack detection method according to any one of claims 1 to 7.