Regional-level network layer congestion type identification method, device, network and storage medium
By evenly deploying probe triplets across the Internet and using ping and traceroute probes to obtain connectivity and path information, the problem of detecting and identifying regional network layer blocking types is solved, and efficient blocking type identification is achieved.
Patent Information
- Application Number
- CN202510071777.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-01-16
AI Technical Summary
Existing technologies find it difficult to effectively detect and identify regional-level network layer blocking types, especially new network threats such as regional-level network layer distributed denial of service attacks, regional-level route hijacking, regional-level IP blocking, and regional-level route withdrawal.
By evenly deploying probe triplets across the Internet, using ping and traceroute probes to obtain connectivity information and network path information, combined with preset conditions, the regional network layer blocking type is determined, including DDoS attacks, route hijacking, route withdrawal, and IP blocking.
It achieves timely detection and identification of regional-level network layer blocking types, improving the accuracy and efficiency of identification.
Smart Images

Figure CN119966693B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of Internet security technology, and in particular to a method, device, network, and storage medium for identifying regional network layer blocking types. Background Art
[0002] The Internet connects several autonomous systems (ASs), also known as autonomous domains (ADs). These ASs are a larger network or group of networks, such as ISPs (Internet service providers), enterprise networks, and university networks. These ASs can form large-scale network systems at national, continental, and other regional levels.
[0003] In recent years, a new type of cyber threat has emerged on the Internet: regional-level network-layer blocking. Imagine region A (the attacker) conducting large-scale regional-level network-layer blocking on region V (the victim). These attacks include regional-level network-layer distributed denial of service (DDoS) attacks, regional-level route hijacking, regional-level IP blocking, and regional-level route revocation.
[0004] The above-mentioned regional network layer blocking behavior will affect the normal use of the Internet, so an effective detection and identification method is urgently needed. Summary of the Invention
[0005] The present disclosure provides a method, device, network and storage medium for identifying regional network layer congestion types to solve the above technical problems.
[0006] According to a first aspect of the present disclosure, a method for identifying a regional network layer congestion type is provided, the method comprising:
[0007] Obtaining the detection results of each probe triplet; the probe triplet includes the initiating blocking area, the blocked area, and other areas; the detection results include connectivity information and network path information between each pair of probes within each probe triplet; the detection results of each probe triplet are obtained by performing ping detection between each pair of probes in the probe triplet at a first preset period to obtain connectivity information between the two areas, and performing traceroute detection between each pair of probes in the probe triplet at a second preset period to obtain network path information between the two areas;
[0008] determining whether regional network layer congestion occurs according to the connectivity information, and obtaining a network layer congestion result;
[0009] When it is determined that the network layer congestion result is the regional network layer congestion, the congestion type of the regional network layer congestion is determined according to the connectivity information and the network path information.
[0010] Optionally, determining whether regional network layer congestion occurs according to the connectivity information to obtain a network layer congestion result includes:
[0011] Determine the number of first target triplets according to the connectivity information, where the first target triplets refer to probe triplets in which the blocked area is unreachable from the blocking area and the blocking area is reachable from other areas;
[0012] When it is determined that the first target number is greater than or equal to a first preset number threshold, determining that a network layer congestion result of regional-level network layer congestion occurs;
[0013] When it is determined that the first target number is less than a first preset number threshold, it is determined that a network layer congestion result indicating that no regional-level network layer congestion occurs is obtained.
[0014] Optionally, determining a congestion type of regional network layer congestion according to the connectivity information and the network path information includes:
[0015] Obtaining the number of second target triplets that meet a preset condition to obtain a second target number; the preset condition is that, in the connectivity information, a probability of a reply packet of a ping probe from the blocked area to the blocking-initiating area is greater than zero and less than or equal to a preset probability threshold;
[0016] When it is determined that the second target quantity is greater than or equal to a second preset quantity threshold, the regional-level network layer congestion type is determined to be a regional-level DDoS attack type.
[0017] Optionally, determining a congestion type of regional network layer congestion according to the connectivity information and the network path information includes:
[0018] Obtaining the number of third target triplets that meet a preset condition to obtain a third target number; the preset condition is that, in the network path information, the path similarity of autonomous domain paths from other areas to the blocked area in the current detection cycle and the previous detection cycle is less than or equal to a first preset degree threshold;
[0019] When it is determined that the third target quantity is greater than or equal to a third preset quantity threshold, the regional-level network layer blocking type is determined to be a regional-level route hijacking type.
[0020] Optionally, determining a congestion type of regional network layer congestion according to the connectivity information and the network path information includes:
[0021] Obtaining the number of fourth target triples that meet a preset condition to obtain a fourth target number; the preset condition is that, in the network path information, the path similarity of the autonomous domain path from the blocked area to the blocking-initiating area in the current detection cycle and the previous detection cycle is less than or equal to a second preset degree threshold;
[0022] When it is determined that the fourth target number is greater than or equal to a fourth preset number threshold, the blocking type of the regional network layer blocking is determined to be a regional route withdrawal type.
[0023] Optionally, determining a congestion type of regional network layer congestion according to the connectivity information and the network path information includes:
[0024] Obtaining the number of fifth target triples that meet a preset condition to obtain a fifth target number; the preset condition is that, in the network path information, from the blocked area to the blocking-initiating area, the autonomous domain path in the current control cycle is included in the autonomous domain path in the previous control cycle, and the autonomous domains shared by the autonomous domain paths in the current control cycle and the previous control cycle do not belong to the blocking-initiating area, and all autonomous domains in the autonomous domain path in the previous control cycle, except the shared autonomous domains, belong to the blocking-initiating area;
[0025] When it is determined that the fifth target number is greater than or equal to a fifth preset number threshold, the blocking type of the regional-level network layer blocking is determined to be a regional-level IP blocking type.
[0026] Optionally, the probe triples are evenly deployed in the Internet, and the method further includes a step of evenly deploying the probe triples in the Internet, including:
[0027] Obtaining repeated paths of newly added probe triples and each historical probe triplet; the historical probe triplet refers to a probe triplet that has been deployed on the Internet;
[0028] Obtaining similarities between the newly added probe triplet and each historical probe triplet according to the repeated path;
[0029] When it is determined that the similarities between the newly added probe triplet and each historical probe triplet are less than or equal to a preset similarity threshold, it is determined that the newly added probe triplet and each historical probe triplet are evenly deployed.
[0030] According to a second aspect of the present disclosure, a device for identifying a regional network layer blocking type is provided, the device comprising:
[0031] A detection result acquisition module is used to obtain the detection results of each probe triplet; the probe triplet includes the initiating blocking area, the blocked area, and other areas; the detection results include connectivity information and network path information between each pair of probes within each probe triplet; the detection results of each probe triplet are obtained by performing ping detection between each pair of probes within the probe triplet at a first preset period to obtain connectivity information between the two areas, and performing traceroute detection between each pair of probes within the probe triplet at a second preset period to obtain network path information between the two areas;
[0032] a blocking result obtaining module, configured to determine whether regional network layer blocking occurs based on the connectivity information, and obtain a network layer blocking result;
[0033] The congestion type acquisition module is used to determine the congestion type of the regional network layer congestion according to the connectivity information and the network path information when it is determined that the network layer congestion result is the regional network layer congestion.
[0034] Optionally, the detection results of each probe triplet are obtained by performing ping detection between each probe in the probe triplet at a first preset period to obtain connectivity information between the two areas, and performing traceroute detection between each probe in the probe triplet at a second preset period to obtain network path information between the two areas.
[0035] Optionally, the blocking result acquisition module includes:
[0036] a target quantity determination submodule, configured to determine the number of first target triplets according to the connectivity information, wherein the first target triplets refer to probe triplets in which the blocked area is unreachable from the blocking area and the blocking area is reachable from other areas;
[0037] A first determining submodule is configured to determine a network layer congestion result of regional network layer congestion when it is determined that the first target number is greater than or equal to a first preset number threshold;
[0038] The second determining submodule is configured to determine, when it is determined that the first target quantity is less than a first preset quantity threshold, a network layer congestion result indicating that no regional network layer congestion occurs.
[0039] Optionally, the blocking type acquisition module includes:
[0040] A second target quantity acquisition submodule is configured to acquire the number of second target triplets that meet a preset condition, thereby obtaining the second target quantity; the preset condition being that, in the connectivity information, the probability of a reply packet of a ping probe from the blocked area to the blocking area is greater than zero and less than or equal to a preset probability threshold;
[0041] The DDoS attack type determination submodule is configured to determine that the regional-level network layer blocking type is a regional-level DDoS attack type when it is determined that the second target quantity is greater than or equal to a second preset quantity threshold.
[0042] Optionally, the blocking type acquisition module includes:
[0043] an autonomous domain path similarity acquisition submodule, configured to acquire the number of third target triplets that meet a preset condition, thereby obtaining a third target number; the preset condition being that the path similarity of autonomous domain paths from other areas to the blocked area in the network path information in the current detection cycle and the previous detection cycle is less than or equal to a first preset degree threshold;
[0044] The routing hijacking type determination submodule is configured to determine that the regional-level network layer blocking type is a regional-level routing hijacking type when it is determined that the third target number is greater than or equal to a third preset number threshold.
[0045] Optionally, the blocking type acquisition module includes:
[0046] a path similarity acquisition submodule, configured to acquire the number of fourth target triples that meet a preset condition, thereby obtaining a fourth target number; wherein the preset condition is that the path similarity of the autonomous domain path from the blocked area to the blocking-initiating area in the network path information within the current detection cycle and the previous detection cycle is less than or equal to a second preset degree threshold;
[0047] The route withdrawal type acquisition submodule is configured to determine that the blocking type of the regional network layer blocking is a regional route withdrawal type when it is determined that the fourth target number is greater than or equal to a fourth preset number threshold.
[0048] Optionally, the blocking type acquisition module includes:
[0049] a fifth target quantity acquisition submodule, configured to acquire the number of fifth target triplets that meet a preset condition, thereby obtaining the fifth target quantity; the preset condition being that, in the network path information, from the blocked area to the blocking-initiating area, the autonomous domain path in the current control cycle is included in the autonomous domain path in the previous control cycle, and the autonomous domains shared by the autonomous domain paths in the current control cycle and the previous control cycle do not belong to the blocking-initiating area, and all autonomous domains in the autonomous domain path in the previous control cycle, except for the shared autonomous domains, belong to the blocking-initiating area;
[0050] The IP blocking type determining submodule is used to determine that the blocking type of the regional-level network layer blocking is the regional-level IP blocking type when it is determined that the fifth target number is greater than or equal to a fifth preset number threshold.
[0051] Optionally, the probe triples are uniformly deployed in the Internet, and the apparatus further includes a triple deployment module, wherein the triple deployment module is configured to uniformly deploy the probe triples in the Internet, and the triple deployment module includes:
[0052] A repeated path acquisition submodule is used to obtain repeated paths between the newly added probe triples and each historical probe triple; the historical probe triples refer to probe triples that have been deployed on the Internet;
[0053] A router path similarity acquisition submodule, configured to acquire similarities between the newly added probe triplet and each historical probe triplet according to the repeated path;
[0054] The triplet deployment submodule is configured to determine that the new probe triplet and each historical probe triplet are evenly deployed when it is determined that the average similarity between the new probe triplet and each historical probe triplet is less than or equal to a preset similarity threshold.
[0055] According to a third aspect of the present disclosure, there is provided a regional level network layer blocking type identification network, comprising: a probe triplet, a processor, and a memory distributedly deployed on the Internet;
[0056] Each probe triplet is used to obtain the detection results of each probe triplet; the probe triplet includes the initiating blocking area, the blocked area and other areas; the detection results include the connectivity information and network path information between the two probes in each probe triplet;
[0057] The memory is used to store a computer program executable by the processor;
[0058] The processor is configured to execute the computer program in the memory to implement the method as described in any one of the first aspects.
[0059] According to a fourth aspect of the present disclosure, a non-transitory computer-readable storage medium is provided, which, when an executable computer program in the storage medium is executed by a processor, can implement the method described in any one of the first aspects.
[0060] The technical solutions provided by the embodiments of the present disclosure may have the following beneficial effects:
[0061] The solution provided by the present disclosure first obtains the detection results of each probe triple; the probe triple includes the initiating blocking area (attacker), the blocked area (victim) and other areas (others); the detection result includes the connectivity information and network path information between the two probes in each group of probe triples; then, based on the connectivity information, it is determined whether regional network layer blocking occurs to obtain the network layer blocking result; thereafter, when it is determined that the network layer blocking result is the occurrence of regional network layer blocking, the blocking type of the regional network layer blocking is determined based on the connectivity information and network path information. In this way, the present disclosure can determine the blocking type when network layer blocking occurs at the regional network layer by setting the probe triple, thereby achieving the effect of timely detection and identification of network layer blocking at the regional network layer.
[0062] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 This is a flowchart of a method for identifying regional network layer congestion types according to an embodiment of the present disclosure.
[0064] Figures 2 to 5 They are respectively flowcharts of an embodiment of the present disclosure for determining whether network congestion is a regional-level DDoS attack type, a regional-level route hijacking type, a regional-level route withdrawal type, and a regional-level IP congestion type.
[0065] Figure 6 This is a block diagram of a regional-level network layer congestion type identification device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0066] Exemplary embodiments will be described in detail herein, examples of which are illustrated in the accompanying drawings. In the following description, when referring to the drawings, like numbers in different figures represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present disclosure. Rather, they are merely examples of devices consistent with certain aspects of the present disclosure, as detailed in the appended claims.
[0067] To address the aforementioned technical issues, embodiments of the present disclosure provide a method, apparatus, network, and storage medium for identifying regional network-layer congestion types. The method can be applied to a regional network-layer congestion type identification network, which includes a probe triplet deployed on the Internet and a controller capable of communicating with the probe triplet over the network.
[0068] The concept of this regional-level network layer congestion type identification method is to deploy probe triplets in a distributed manner on the data plane of the Internet to detect the Internet's network connectivity and network topology changes; then determine whether large-scale network layer congestion has occurred based on the network connectivity and network topology changes; and identify the congestion type when regional-level network layer congestion occurs, thereby achieving the effect of detecting and identifying the congestion type.
[0069] It should be noted that the above probe triplet Can be evenly deployed on the Internet. and Refers to terminals whose IP addresses belong to the blocked area (victim), the blocking area (attacker), and other areas (others) and can access the Internet. In this example, other areas This is for the purpose of comparing and verifying the blocked area and the area that initiated the blocking.
[0070] In one example, the three probes of each probe triplet and is a pairwise combination, such as and combination, and Combination and and Combination. Each group of probes (or each pair of probes) performs ping detection between each other at a first preset period T1 to detect connectivity information of the local network within the Internet, that is, the local network is connected or the data packet is reachable. In addition, each group of probes performs traceroute detection, i.e., path tracing, between each other at a second preset period T2 to obtain detection results, i.e., network path information between the two areas; the detection results are saved to detect changes in local network topology information.
[0071] In one example, ping(x,y) is the result of a ping probe from probe x to probe y, indicating connectivity between the two areas. This connectivity information ranges from 0 to 1 and represents the ratio of the number of received reply packets to the total number of sent packets. IP_route(x,y) is the result of a traceroute probe from probe x to probe y. This value represents an IP-level path, and the corresponding autonomous system (AS)-level path is denoted as AS_route(x,y).
[0072] In one example, the deployment of probe triplets must meet the following requirements: the paths detected by the Traceroute probes of each probe triplet do not overlap with each other, such as the similarity of the paths between any two probe triplets is less than or equal to a preset similarity threshold, thereby avoiding information redundancy affecting the accuracy of the detection algorithm. The preset similarity threshold has a value range of [0.1, 0.2], which can be adjusted according to the specific scenario. In one example, the preset similarity threshold is 0.2, that is, the uniform deployment requirement is met when the similarity of the overlapping paths between any two triplets is less than or equal to 0.2.
[0073] The present disclosure provides a method for identifying regional network layer congestion types, see Figure 1 , including steps 11 to 13.
[0074] In step 11, the detection results of each probe triple are obtained; the probe triple includes the initiating blocking area (attacker), the blocked area (victim) and other areas (others); the detection results include the connectivity information and network path information between each pair of probes in each probe triple.
[0075] In this step, probe triplets can be pre-deployed evenly across the internet. Any two probe triplets can perform detections at a preset interval, obtaining detection results. Each probe triplet can then send the detection results to the controller. The controller can then obtain the detection results of each probe triplet.
[0076] In step 12, it is determined whether regional network layer congestion occurs according to the connectivity information, and a network layer congestion result is obtained.
[0077] In this step, the controller can determine the first target number of the first target triplet based on the connectivity information. The first target triplet refers to a probe triplet in which the blocked area is in an unreachable state with the blocking area initiating the blocking, and the other areas are in a reachable state with the blocking area initiating the blocking. In this step, the first target triplet is defined as a partially unreachable state, that is, the first target triplet is in a partially unreachable state. and Ping detection is unreachable, and and It is reachable between.
[0078] In this step, reachability between two probes means that if ping(x,y)≥θ0, it is determined that probe x is reachable to probe y, otherwise it is unreachable. Wherein, θ0 is a preset ratio threshold, and the value range of the preset ratio threshold is [0.8, 1). Under normal network conditions, the value of the preset ratio threshold is less than or equal to 1. In other words, when the probe triplet is partially unreachable, there is Remember S i Indicates that the i-th probe triplet is in a partially unreachable state. The value range {1,0} represents "partially unreachable state" and normal state respectively.
[0079] In this step, the controller can compare the first target number of first target triplets with a preset number threshold. Since network failures often occur on the Internet, these network failures may cause probe triplets to be partially unreachable. However, ordinary network failures only occur in a local area of the Internet and do not cause widespread network unreachability. Therefore, the specific value of the first preset number threshold M1 should be greater than the maximum value that can be reached by ordinary network failures, for example, N / 4 <= M1 <= 3N / 4, where N represents the number of probe triplets.
[0080] Among them, ordinary network failure refers to a state in which the network cannot provide normal services or reduces the service quality due to sudden hardware and / or software problems under normal network operation. It is different from the network failure caused by regional network layer congestion in the disclosed solution.
[0081] In this step, when it is determined that the first target quantity is greater than or equal to the first preset quantity threshold, When the first target number is less than the preset number threshold, the controller can determine that no regional network layer congestion has occurred, and jump to step 11.
[0082] In step 13, when it is determined that the network layer congestion result is the regional network layer congestion, the congestion type of the regional network layer congestion is determined according to the connectivity information and the network path information.
[0083] In this step, when the network layer blocking result is determined to be regional-level network layer blocking, the controller may determine the blocking type of the regional-level network layer blocking based on the connectivity information and the network path information. The blocking types of the regional-level network layer blocking may include regional-level DDoS attack type, regional-level route hijacking type, regional-level route revocation type, and regional-level IP blocking type.
[0084] Considering that the network congestion is a DDoS (Distributed Denial of Service) attack type, area A launches a distributed denial of service attack on the export link or border router of area V, causing the traffic at the export of area V to show a high packet loss rate, that is, the probe within the probe triplet arrive The path has a higher packet loss rate, but it is not completely disconnected.
[0085] In one example, the controller can determine the blocking type of the regional network layer blocking according to the connectivity information and the network path information, including: the controller can obtain the connectivity information of each group of probe triples from arrive The probability of a reply packet for a ping probe. The controller can then compare the reply packet probability with a preset probability threshold θ1, where the preset probability threshold θ1 has a value range of (0, 0.3], which is a positive value close to 0. When it is determined that the reply packet probability is greater than zero and less than or equal to the preset probability threshold θ1, the controller can determine that the local network corresponding to the group of probe triplets has been attacked by a DDoS attack; when it is determined that the number of probe triplets that meet this condition, that is, the second target number, is greater than or equal to the second preset number threshold M2, the regional-level network layer blocking type is determined to be a regional-level DDoS attack type. Wherein, N / 2<=M2, N represents the number of probe triplets.
[0086] See also Figure 2 In the case of regional DDoS attacks, To the probe The packet loss rate of the path is high, but it is not completely disconnected, such as the reachable path 21 and the high packet loss rate path 22. The value of is close to 0 but not equal to 0, such as 0.12. With θ1 = 0.2, when , it is determined that the local network corresponding to the probe triplet is under DDoS attack.
[0087] In this example, the reply packet probability of the probe triplet and the preset probability threshold are set to determine whether a DDoS attack type has occurred, which can improve the accuracy of identifying the type.
[0088] Considering that the network congestion is a regional routing hijacking type, region A hijacks most or even all of the IP prefixes in region V and directly discards the hijacked data packets, or in other words, the probe within the probe triplet To the probe The traceroute path of the current control cycle shows obvious differences compared with the historical path. Similarity(x,y) is defined as the difference between the AS_route(x,y) obtained by the traceroute detection in the current control cycle and the AS_route(x,y) obtained by the traceroute detection in the previous control cycle. ′ Path similarity compared with (x,y) It is considered that routing hijacking has occurred in the local network corresponding to the triplet. The first preset degree threshold μ1 reflects the degree of change in the AS granularity path during routing hijacking.
[0089] It should be noted that when tracing a path, an IP address is returned. Each IP address belongs to an autonomous area. In this step, the IP address is replaced with the AS area. For example, if IP1 to IP5 are returned, where IP1 and IP2 belong to AS1 and IP3 to IP5 belong to AS2, the AS-granular path is [AS1, AS2].
[0090] In one example, the controller can determine each probe triplet from the network path information. arrive The path similarity of the autonomous domain path in the current detection cycle and the previous detection cycle. When it is determined that the above path similarity is less than or equal to the first preset degree threshold μ1, the controller can determine that the local network corresponding to the group of probe triplets has been route hijacked; when the number of probe triplets that meet this condition, that is, the third target number, is greater than or equal to the third preset number threshold M3, the regional network layer blocking type is determined to be the regional route hijacking type. Wherein, N / 4<=M3, N represents the number of probe triplets.
[0091] See also Figure 3 In the case of regional routing hijacking, the probe arrive The traceroute path shows obvious differences compared with the historical path, such as the original path 31 and the new path 32. The value is close to 0, such as 0.2. When the first preset degree threshold μ1=0.25, it is determined that the local network corresponding to the group of probe triples has been subjected to routing hijacking.
[0092] In this way, in this example, by obtaining the similarity of the paths from other areas to the blocked area in the current detection cycle and the previous detection cycle, whether the route hijacking type occurs can be determined, which can improve the accuracy of the identification type.
[0093] Considering the case of regional route withdrawal, area A announces to area V the withdrawal of all routes to area A, and / or announces the withdrawal of all routes to area V. In the case of regional route withdrawal, the probe triplet from the probe arrive The traceroute path of shows obvious differences compared with the historical path, i.e. The second preset threshold μ2 reflects the degree of change in the AS granularity path in the case of route withdrawal. In one example, the controller can determine the number of probe triples from each group based on the network path information. arrive The controller determines the path similarity between the autonomous domain paths in the current detection cycle and the previous detection cycle. When it is determined that the path similarity is less than or equal to the second preset degree threshold μ2, the controller can determine that the local network corresponding to the group of probe triplets has been routed out. When the number of probe triplets that meet this condition, i.e., the fourth target number, is greater than or equal to the fourth preset number threshold M4, the regional network layer congestion type is determined to be the regional route withdrawal type. Where N / 4 <= M4, N represents the number of probe triplets.
[0094] See also Figure 4 In the case of regional route withdrawal, the probe To the probe The traceroute path of the original path 41, the new path 42 and the reachable link 43 show obvious differences compared with the historical path. The value of is close to 0, such as 0.15. When the second preset degree threshold μ2=0.2, it is determined that the local network corresponding to the reorganized probe triplet has been subjected to routing withdrawal.
[0095] In this way, in this example, whether the route withdrawal type occurs is determined by obtaining the path similarity from the blocked area to the blocking-initiating area in the current detection cycle and the previous detection cycle, which can improve the accuracy of identifying the type.
[0096] Considering that the network blocking is regional IP blocking type, area A filters the data packets whose source IP and / or destination IP belong to area V, and other routers and links on the Internet are in normal working state, or in other words, the probe triplet is sent from the probe arrive The traceroute path of A is cut off at the border router of area A, that is, AS_route(x,y)∈AS_route ′ (x,y), and appears in AS_route(x,y)∩AS_route ′ The AS in (x,y) does not belong to area A, AS_route ′ All other ASs in (x,y) belong to area A.
[0097] In one example, the controller can obtain the number of fifth target triplets that meet the preset conditions and obtain the fifth target number. The preset condition is that in the network path information, from area V to area A, the autonomous domain path in the current control cycle is included in the autonomous domain path in the previous control cycle, and the autonomous domains shared by the autonomous domain paths of the current control cycle and the previous control cycle do not belong to the initiating blocking area, and all autonomous domains except the shared autonomous domains in the autonomous domain path of the previous control cycle belong to the initiating blocking area. The controller can compare the fifth target number with the fifth preset number threshold M5, where the fifth preset number threshold M5 can be set according to the specific scenario. When it is determined that the fifth target number is greater than or equal to the fifth preset number threshold M5, the controller can determine that the blocking type of the regional-level network layer blocking is the regional-level IP blocking type. Wherein, N / 2<=M5, N represents the number of probe triplets.
[0098] See also Figure 5 In the case of regional IP blocking, arrive The traceroute path is cut off at the border router of area A. In one example, all AS_routes (x, y) detected by the current traceroute are the AS_routes detected in the previous control cycle. ′ A subset of (x,y) that appears in AS_route(x,y)∩AS_route ′ The AS in (x,y) does not belong to area A, AS_route ′ If all other ASs in (x, y) belong to area A, then it is determined that the probe triplet is blocked by the IP.
[0099] In this way, in this example, whether the IP blocking type is determined by judging whether truncation occurs at the border router can improve the accuracy of the identification type.
[0100] Thus, the present disclosure can determine the type of congestion when network layer congestion occurs at the regional network layer by setting the probe triplet, thereby achieving the effect of timely detection and identification of network layer congestion at the regional network layer.
[0101] Based on the method for identifying a regional network layer congestion type provided in the embodiment of the present disclosure, the embodiment of the present disclosure also provides a device for identifying a regional network layer congestion type, see Figure 6 , the device comprises:
[0102] The detection result acquisition module 61 is used to obtain the detection results of each probe triple; the probe triple includes the blocking initiating area, the blocked area and other areas; the detection results include the connectivity information and network path information between the two probes in each probe triple;
[0103] The blocking result acquisition module 62 is used to determine whether regional network layer blocking occurs according to the connectivity information, and obtain a network layer blocking result;
[0104] The congestion type acquisition module 63 is configured to determine the congestion type of the regional-level network layer congestion according to the connectivity information and the network path information when determining that the network layer congestion result is the regional-level network layer congestion.
[0105] In some possible examples, the detection results of each probe triplet are obtained by performing ping detection between each probe in the probe triplet at a first preset period to obtain connectivity information between the two areas, and performing traceroute detection between each probe in the probe triplet at a second preset period to obtain network path information between the two areas.
[0106] In some possible examples, the blocking result acquisition module includes:
[0107] a target quantity determination submodule, configured to determine the number of first target triplets according to the connectivity information, wherein the first target triplets refer to probe triplets in which the blocked area is unreachable from the blocking area and the blocking area is reachable from other areas;
[0108] A first determining submodule is configured to determine a network layer congestion result of regional network layer congestion when it is determined that the first target number is greater than or equal to a first preset number threshold;
[0109] The second determining submodule is configured to determine, when it is determined that the first target quantity is less than a first preset quantity threshold, a network layer congestion result indicating that no regional network layer congestion occurs.
[0110] In some possible examples, the blocking type acquisition module includes:
[0111] A second target quantity acquisition submodule is configured to acquire the number of second target triplets that meet a preset condition, thereby obtaining the second target quantity; the preset condition being that, in the connectivity information, the probability of a reply packet of a ping probe from the blocked area to the blocking area is greater than zero and less than or equal to a preset probability threshold;
[0112] The DDoS attack type determination submodule is configured to determine that the regional-level network layer blocking type is a regional-level DDoS attack type when it is determined that the second target quantity is greater than or equal to a second preset quantity threshold.
[0113] In some possible examples, the blocking type acquisition module includes:
[0114] an autonomous domain path similarity acquisition submodule, configured to acquire the number of third target triplets that meet a preset condition, thereby obtaining a third target number; the preset condition being that the path similarity of autonomous domain paths from other areas to the blocked area in the network path information in the current detection cycle and the previous detection cycle is less than or equal to a first preset degree threshold;
[0115] The routing hijacking type determination submodule is configured to determine that the regional-level network layer blocking type is a regional-level routing hijacking type when it is determined that the third target number is greater than or equal to a third preset number threshold.
[0116] In some possible examples, the blocking type acquisition module includes:
[0117] a path similarity acquisition submodule, configured to acquire the number of fourth target triples that meet a preset condition, thereby obtaining a fourth target number; wherein the preset condition is that the path similarity of the autonomous domain path from the blocked area to the blocking-initiating area in the network path information within the current detection cycle and the previous detection cycle is less than or equal to a second preset degree threshold;
[0118] The route withdrawal type acquisition submodule is configured to determine that the blocking type of the regional network layer blocking is a regional route withdrawal type when it is determined that the fourth target number is greater than or equal to a fourth preset number threshold.
[0119] In some possible examples, the blocking type acquisition module includes:
[0120] a fifth target quantity acquisition submodule, configured to acquire the number of fifth target triplets that meet a preset condition, thereby obtaining the fifth target quantity; the preset condition being that, in the network path information, from the blocked area to the blocking-initiating area, the autonomous domain path in the current control cycle is included in the autonomous domain path in the previous control cycle, and the autonomous domains shared by the autonomous domain paths in the current control cycle and the previous control cycle do not belong to the blocking-initiating area, and all autonomous domains in the autonomous domain path in the previous control cycle, except for the shared autonomous domains, belong to the blocking-initiating area;
[0121] The IP blocking type determining submodule is used to determine that the blocking type of the regional-level network layer blocking is the regional-level IP blocking type when it is determined that the fifth target number is greater than or equal to a fifth preset number threshold.
[0122] In some possible examples, the probe triplets are uniformly deployed in the Internet.
[0123] In some possible examples, the apparatus further includes a triplet deployment module, wherein the triplet deployment module is configured to uniformly deploy probe triples within the Internet. The triplet deployment module includes:
[0124] A repeated path acquisition submodule is used to obtain repeated paths between the newly added probe triples and each historical probe triple; the historical probe triples refer to probe triples that have been deployed on the Internet;
[0125] A router path similarity acquisition submodule, configured to acquire similarities between the newly added probe triplet and each historical probe triplet according to the repeated path;
[0126] The triplet deployment submodule is configured to determine that the new probe triplet and each historical probe triplet are evenly deployed when it is determined that the average similarity between the new probe triplet and each historical probe triplet is less than or equal to a preset similarity threshold.
[0127] It should be noted that the solution of the device embodiment of the present disclosure has been described in the method embodiment of the regional network layer blocking type identification method. Please refer to the contents of the above embodiments for details and will not be repeated here.
[0128] In some possible embodiments, a regional-level network layer congestion type identification network is provided, comprising: a probe triplet distributedly deployed on the Internet, a processor, and a memory;
[0129] Each probe triplet is used to obtain the detection results of each probe triplet; the probe triplet includes the initiating blocking area, the blocked area and other areas; the detection results include the connectivity information and network path information between the two probes in each probe triplet;
[0130] The memory is used to store a computer program executable by the processor;
[0131] The processor is configured to execute the computer program in the memory to implement the above method.
[0132] In some possible examples, a non-transitory computer-readable storage medium is provided, which, when an executable computer program in the storage medium is executed by a processor, can implement the regional-level network layer blocking type identification method as described above.
[0133] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the disclosure herein. This disclosure is intended to cover any variations, uses, or adaptations that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.
[0134] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. A method for identifying regional network layer congestion types, characterized in that: The method comprises: Obtaining the detection results of each probe triplet; the probe triplet includes the initiating blocking area, the blocked area, and other areas; the detection results include connectivity information and network path information between each pair of probes within each probe triplet; the detection results of each probe triplet are obtained by performing ping detection between each pair of probes in the probe triplet at a first preset period to obtain connectivity information between the two areas, and performing traceroute detection between each pair of probes in the probe triplet at a second preset period to obtain network path information between the two areas; determining whether regional network layer congestion occurs according to the connectivity information, and obtaining a network layer congestion result; When it is determined that the network layer congestion result is the regional network layer congestion, the congestion type of the regional network layer congestion is determined according to the connectivity information and the network path information.
2. The method according to claim 1, characterized in that Determining whether regional network layer congestion occurs according to the connectivity information, and obtaining a network layer congestion result, including: Determining a first target number of first target triples according to the connectivity information, where the first target triples refer to probe triplets in which the blocked area is unreachable from the blocking area and the blocking area is reachable from other areas; When it is determined that the first target number is greater than or equal to a first preset number threshold, determining that a network layer congestion result of regional-level network layer congestion occurs; When it is determined that the first target number is less than a first preset number threshold, it is determined that a network layer congestion result indicating that no regional-level network layer congestion occurs is obtained.
3. The method according to claim 1, characterized in that Determining a blocking type of a regional network layer blocking according to the connectivity information and the network path information includes: Obtaining the number of second target triplets that meet a preset condition to obtain a second target number; the preset condition is that, in the connectivity information, a probability of a reply packet of a ping probe from the blocked area to the blocking-initiating area is greater than zero and less than or equal to a preset probability threshold; When it is determined that the second target quantity is greater than or equal to a second preset quantity threshold, the regional-level network layer congestion type is determined to be a regional-level DDoS attack type.
4. The method according to claim 1, wherein Determining a blocking type of a regional network layer blocking according to the connectivity information and the network path information includes: Obtaining the number of third target triplets that meet a preset condition to obtain a third target number; the preset condition is that, in the network path information, the path similarity of autonomous domain paths from other areas to the blocked area in the current detection cycle and the previous detection cycle is less than or equal to a first preset degree threshold; When it is determined that the third target quantity is greater than or equal to a third preset quantity threshold, the regional-level network layer blocking type is determined to be a regional-level route hijacking type.
5. The method according to claim 1, wherein Determining a blocking type of a regional network layer blocking according to the connectivity information and the network path information includes: Obtaining the number of fourth target triples that meet a preset condition to obtain a fourth target number; the preset condition is that, in the network path information, the path similarity of the autonomous domain path from the blocked area to the blocking-initiating area in the current detection cycle and the previous detection cycle is less than or equal to a second preset degree threshold; When it is determined that the fourth target number is greater than or equal to a fourth preset number threshold, the blocking type of the regional network layer blocking is determined to be a regional route withdrawal type.
6. The method according to claim 1, wherein Determining a blocking type of a regional network layer blocking according to the connectivity information and the network path information includes: Obtaining the number of fifth target triples that meet a preset condition to obtain a fifth target number; the preset condition is that, in the network path information, from the blocked area to the blocking-initiating area, the autonomous domain path in the current control cycle is included in the autonomous domain path in the previous control cycle, and the autonomous domains shared by the autonomous domain paths in the current control cycle and the previous control cycle do not belong to the blocking-initiating area, and all autonomous domains in the autonomous domain path in the previous control cycle, except the shared autonomous domains, belong to the blocking-initiating area; When it is determined that the fifth target number is greater than or equal to a fifth preset number threshold, the blocking type of the regional-level network layer blocking is determined to be a regional-level IP blocking type.
7. The method according to claim 1, characterized in that The probe triples are evenly deployed in the Internet. The method further includes the step of evenly deploying the probe triples in the Internet, including: Obtaining repeated paths of newly added probe triples and each historical probe triplet; the historical probe triplet refers to a probe triplet that has been deployed on the Internet; Obtaining similarities between the newly added probe triplet and each historical probe triplet according to the repeated path; When it is determined that the similarities between the newly added probe triplet and each historical probe triplet are less than or equal to a preset similarity threshold, it is determined that the newly added probe triplet and each historical probe triplet are evenly deployed.
8. A regional network layer blocking type identification device, characterized in that: The device comprises: A detection result acquisition module is used to obtain the detection results of each probe triplet; the probe triplet includes the initiating blocking area, the blocked area, and other areas; the detection results include connectivity information and network path information between each pair of probes within each probe triplet; the detection results of each probe triplet are obtained by performing ping detection between each pair of probes within the probe triplet at a first preset period to obtain connectivity information between the two areas, and performing traceroute detection between each pair of probes within the probe triplet at a second preset period to obtain network path information between the two areas; a blocking result obtaining module, configured to determine whether regional network layer blocking occurs based on the connectivity information, and obtain a network layer blocking result; The congestion type acquisition module is used to determine the congestion type of the regional network layer congestion according to the connectivity information and the network path information when it is determined that the network layer congestion result is the regional network layer congestion.
9. A regional level network layer blocking type identification network, characterized in that: include: Probe triples, processors, and memories distributed across the Internet; Each probe triplet is used to obtain the detection results of each probe triplet; the probe triplet includes the initiating blocking area (attacker), the blocked area (victim) and other areas (others); the detection results include connectivity information and network path information between any two probes within each probe triplet; the detection results of each probe triplet are obtained by performing ping detection between any two probes within the probe triplet at a first preset period to obtain connectivity information between the two areas, and performing traceroute detection between any two probes within the probe triplet at a second preset period to obtain network path information between the two areas; The memory is used to store a computer program executable by the processor; the processor is used to execute the computer program in the memory to implement the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium, characterized in that When the executable computer program in the storage medium is executed by a processor, the method according to any one of claims 1 to 7 can be implemented.