DDoS attack defense method and device, equipment and storage medium
Through cyberspace surveying and mapping and bearer network detection, DDoS attack information is analyzed and early warning is solved, and the existing technology cannot perceive DDoS reflective attacks in a timely manner, achieving efficient DDoS attack defense and traffic cleaning.
Patent Information
- Application Number
- CN202510301928.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-14
AI Technical Summary
The existing DDoS attack defense methods cannot sense the DDoS reflection attack and cleaning attack traffic received by the bearer network in time, resulting in system crash and paralysis.
By conducting cyberspace surveying and mapping of the Internet, the service asset information of the original open service is obtained, and the candidate open service is classified and stored and carried out bearer network detection to obtain the communication log set. Based on this information, DDoS attack analysis is carried out, attack information and attack information confidence are obtained, and attack warning is conducted based on the confidence threshold.
It realizes real-time monitoring of DDoS attack status around the world in seconds, shortens the DDoS attack perception time difference, improves the DDoS attack defense effect, and enhances the cleaning efficiency of the anti-DDoS traffic cleaning platform.
Smart Images

Figure CN119996051A_ABST
Abstract
Description
Background Art
[0002] Attackers launch DDoS attacks on their targets, causing the target's resources to be overloaded and unable to process legitimate users' requests normally. DDoS attacks have become one of the biggest threats to network security.
[0003] At present, DDoS attacks have four significant characteristics: First, ultra-large-scale attacks are extremely active, and T-level attacks occur frequently; second, compared with previous years, the frequency of attacks continues to increase. In order to evade defense, low-speed sweeping attacks have become the mainstream attack method, and hybrid attack methods are used to launch network attacks; third, the climbing speed of large-volume attacks has reached a new high, reaching T-level attacks in seconds, bringing huge impact to the targets of attack; fourth, the complexity of attacks continues to increase, and the threat of attacks has intensified.
[0004] Therefore, the following challenges arise when defending against DDoS attacks: First, as the complexity and intensity of DDoS attacks increase, existing DDoS attack defense methods are unable to timely detect DDoS reflection attacks on the bearer network; second, as the complexity of attack methods increases, existing DDoS attack defense methods are difficult to trace the attack link, and are unable to timely block the attack traffic received by the bearer network, causing the system to crash and become paralyzed, and unable to normally process requests from legitimate users. Summary of the invention
[0005] The embodiments of the present application provide a DDoS attack defense method, apparatus, device, and storage medium to solve the problem of being unable to timely perceive DDoS reflection attacks and clean attack traffic on a bearer network.
[0006] In a first aspect, an embodiment of the present application provides a DDoS attack defense method, including:
[0007] Conduct cyberspace mapping of the Internet to obtain service asset information of each original open service in the first period, and use the original open services associated with service asset information that hits specific service features as candidate open services;
[0008] Classify and store the service asset information of each candidate open service to obtain corresponding mapping details, and perform bearer network detection on the target open service that is still in the open service state in the second cycle to obtain the corresponding communication log set;
[0009] DDoS attack analysis is performed based on the mapping details and communication log sets of each target open service, the DDoS attack information and attack information confidence of each target open service are obtained, and attack warnings are issued based on DDoS attack information whose attack confidence is not less than the confidence threshold.
[0010] Optionally, perform cyberspace mapping of the Internet to obtain service asset information of each original open service in the first period, including:
[0011] Scan all ports and services on the Internet, identify the original open services that support public access in the first cycle, and obtain the service asset information of each original open service.
[0012] Optionally, the service asset information of each candidate open service is classified and stored to obtain corresponding mapping details, including:
[0013] According to the storage fields of service name, service type, service opening time, service distribution area and service label, the service information of each candidate open service is stored in detail, and the mapping details of each candidate open service under different storage fields are obtained.
[0014] Optionally, a bearer network detection is performed on the target open service that is still in the open service state during the second period to obtain a corresponding communication log set, including:
[0015] Obtain service asset information of target open services that are still in an open service state during the second cycle;
[0016] Based on the log storage location recorded in each service asset information, a communication log set generated when providing the corresponding target open service is obtained, and each communication log entry records the traffic transmission process between the target open service and the service request end.
[0017] Optionally, DDoS attack analysis is performed based on the mapping details of each target open service and each communication log set to obtain DDoS attack information and attack information confidence of each target open service, including:
[0018] To open services for each target, perform the following operations:
[0019] In the mapping details of a target open service, obtain the service opening time of the target open service;
[0020] In the communication log set of the target open service, obtain the communication log entries between the service opening time, and based on each communication log entry, count the number of response packets sent by the target open service to different service request ends;
[0021] Log analysis is performed on communication log entries whose sending quantity is not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the DDoS attack launched by the target open service on the corresponding service request end.
[0022] In a second aspect, the embodiment of the present application further provides a DDoS attack defense device, including:
[0023] A mapping unit is used to map the Internet network space, obtain the service asset information of each original open service in the first period, and use the original open services associated with the service asset information that hits the specific service feature as candidate open services;
[0024] The detection unit is used to classify and store the service asset information of each candidate open service, obtain corresponding mapping details, and perform bearer network detection on the target open service that is still in the open service state in the second period to obtain the corresponding communication log set;
[0025] The early warning unit is used to perform DDoS attack analysis based on the mapping details and communication log sets of each target open service, obtain the DDoS attack information and attack information confidence of each target open service, and issue an attack early warning based on the DDoS attack information whose attack confidence is not less than the confidence threshold.
[0026] Optionally, perform cyberspace mapping of the Internet to obtain service asset information of each original open service in the first period, including:
[0027] Scan all ports and services on the Internet, identify the original open services that support public access in the first cycle, and obtain the service asset information of each original open service.
[0028] Optionally, the service asset information of each candidate open service is classified and stored to obtain corresponding mapping details, including:
[0029] According to the storage fields of service name, service type, service opening time, service distribution area and service label, the service information of each candidate open service is stored in detail, and the mapping details of each candidate open service under different storage fields are obtained.
[0030] Optionally, a bearer network detection is performed on the target open service that is still in the open service state during the second period to obtain a corresponding communication log set, including:
[0031] Obtain service asset information of target open services that are still in an open service state during the second cycle;
[0032] Based on the log storage location recorded in each service asset information, a communication log set generated when providing the corresponding target open service is obtained, and each communication log entry records the traffic transmission process between the target open service and the service request end.
[0033] Optionally, DDoS attack analysis is performed based on the mapping details of each target open service and each communication log set to obtain DDoS attack information and attack information confidence of each target open service, including:
[0034] To open services for each target, perform the following operations:
[0035] In the mapping details of a target open service, obtain the service opening time of the target open service;
[0036] In the communication log set of the target open service, obtain the communication log entries between the service opening time, and based on each communication log entry, count the number of response packets sent by the target open service to different service request ends;
[0037] Log analysis is performed on communication log entries whose sending quantity is not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the DDoS attack launched by the target open service on the corresponding service request end.
[0038] In a third aspect, an embodiment of the present application further provides a computer device, comprising a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor executes the steps of any one of the above-mentioned DDoS attack defense methods.
[0039] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, which includes a program code. When the program product is run on a computer device, the program code is used to enable the computer device to execute the steps of any one of the above-mentioned DDoS attack defense methods.
[0040] In a fifth aspect, an embodiment of the present application further provides a computer program product, including computer instructions, wherein the computer instructions are executed by a processor to perform the steps of any of the above-mentioned DDoS attack defense methods.
[0041] The beneficial effects of this application are as follows:
[0042] The embodiments of the present application provide a DDoS attack defense method, apparatus, device and storage medium, the method comprising: performing cyberspace mapping on the Internet, obtaining service asset information of each original open service in a first period, and taking the original open service associated with the service asset information of a specific service as a candidate open service; classifying and storing the service asset information of each candidate open service to obtain corresponding mapping details, and performing bearer network detection on the target open service that is still in an open service state in a second period to obtain a corresponding communication log set; performing DDoS attack analysis based on the mapping details and communication log set of each target open service to obtain DDoS attack information and attack information confidence of each target open service, and performing attack warning based on DDoS attack information whose attack information confidence is not less than a confidence threshold.
[0043] This application links the bearer network, uses large model analysis technology, and coordinates the DDoS attack monitoring system and the anti-DDoS traffic cleaning platform to form a multi-dimensional coordinated three-dimensional monitoring, fully perceive the DDoS attack status, and achieve real-time monitoring of the DDoS attack status around the world in seconds, shortening the DDoS attack perception time difference as much as possible and improving the DDoS attack defense effect. The coordinated bearer network and traffic cleaning equipment can block the source of accurate attacks, form a highly automated traffic cleaning capability, strengthen the core capability of anti-DDoS traffic cleaning, and improve the cleaning efficiency of the anti-DDoS traffic cleaning platform.
[0044] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0046] Figure 1 A schematic diagram of the architecture of a multi-stage traffic monitoring and cleaning platform based on a bearer network provided in an embodiment of the present application;
[0047] Figure 2A A schematic diagram of a process for preventing an attacker from launching a DDoS attack on the Internet provided in an embodiment of the present application;
[0048] Figure 2B A logical diagram of the defense provided by the embodiment of the present application against DDoS attacks launched by attackers on the Internet;
[0049] Figure 2C A working diagram of a DDoS attack monitoring system provided in an embodiment of the present application;
[0050] Figure 2D A schematic diagram of the interface of the DDoS attack monitoring system provided in an embodiment of the present application;
[0051] Figure 3 A complete logical diagram of monitoring DDoS attacks provided in an embodiment of the present application;
[0052] Figure 4 A schematic diagram of the structure of a DDoS attack defense device provided in an embodiment of the present application;
[0053] Figure 5 A schematic diagram of the structure of a computer device provided in an embodiment of the present application;
[0054] Figure 6 Schematic diagram of the structure of a computing device in an embodiment of the present application. DETAILED DESCRIPTION
[0055] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the technical solution of the present application, rather than all of the embodiments. Based on the embodiments recorded in the application documents, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the technical solution of the present application.
[0056] Some of the terms used in the embodiments of the present application are explained below to facilitate understanding by those skilled in the art.
[0057] 1. DDoS attack: refers to multiple control terminals in different locations launching network attacks on one or several attack targets at the same time, or one control terminal controlling multiple controlled terminals in different locations and launching network attacks on one or several attack targets at the same time, causing the attack targets to be unable to provide normal services.
[0058] Among them, the control end refers to the machine used by the attacker, and the controlled end is a puppet machine controlled by remote instructions from the control end. The puppet machine is usually an infected computer and IoT device, and the target of the attack is usually the target server, service or network.
[0059] 2. T-level attack: refers to the control end launching a DDoS attack on the target with an ultra-high traffic of TB level per second (Tbps). The target may suffer system crash and paralysis due to the excessive load it bears in a short period of time.
[0060] 3. DDoS reflection attack: To enhance the effect of the attack, the control end forges the Internet Protocol Address (IP address) of the target, modifies the source IP address of the request to the IP address of the target, and sends requests to many reflection servers. These servers then send response packets of the request to the target, causing the target to receive much more data traffic than the actual request. As the target is overwhelmed by the large number of response packets, it is unable to provide services normally.
[0061] Reflection servers are usually servers widely distributed around the world and publicly accessible, such as Domain Name System (DNS) servers and Network Time Protocol (NTP) servers. These servers have large bandwidth and high response speed, allowing attackers to obtain a large amount of traffic from relatively few reflection servers. By using dozens or even hundreds of reflection servers to launch attacks on the target at the same time, the target is overloaded with requests, making the target's services unavailable.
[0062] 4. Zombie machine: refers to the machine that is remotely controlled by the control end during a DDoS attack and is used to initiate various malicious activities, including DDoS attacks and sending spam.
[0063] 5. Bearer network: It is located between the access network and the switch and is used to carry various business data. The main task of the bearer network is to provide stable, reliable and efficient data transmission services for various businesses. It can be the backbone network of the operator or the internal network of the enterprise.
[0064] 6. Internet Mapping: refers to the comprehensive scanning, analysis and visualization of resources, devices and services on the Internet to draw a detailed network structure map. This process helps to understand the global or regional network topology, identify potential security threats, evaluate the robustness and reliability of infrastructure, and provide data support for network security research.
[0065] The following is a brief introduction to the design concept of the embodiment of the present application:
[0066] Attackers launch DDoS attacks on their targets, causing the target's resources to be overloaded and unable to process legitimate users' requests normally. DDoS attacks have become one of the biggest threats to network security.
[0067] At present, DDoS attacks have four significant characteristics: First, ultra-large-scale attacks are extremely active, and T-level attacks occur frequently; second, compared with previous years, the frequency of attacks continues to increase. In order to evade defense, low-speed sweeping attacks have become the mainstream attack method, and hybrid attack methods are used to launch network attacks; third, the climbing speed of large-volume attacks has reached a new high, reaching T-level attacks in seconds, bringing huge impact to the targets of attack; fourth, the complexity of attacks continues to increase, and the threat of attacks has intensified.
[0068] Therefore, the following challenges arise when defending against DDoS attacks: First, as the complexity and intensity of DDoS attacks increase, existing DDoS attack defense methods are unable to timely detect DDoS reflection attacks on the bearer network; second, as the complexity of attack methods increases, existing DDoS attack defense methods are difficult to trace the attack link, and are unable to timely block the attack traffic received by the bearer network, causing the system to crash and become paralyzed, and unable to normally process requests from legitimate users.
[0069] In view of this, the embodiment of the present application provides a DDoS attack defense method, device, equipment and storage medium. The method includes: performing cyberspace mapping on the Internet, obtaining the service asset information of each original open service in the first period, and taking the original open service associated with the service asset information of the specific service as a candidate open service; classifying and storing the service asset information of each candidate open service, obtaining the corresponding mapping details, and performing bearer network detection on the target open service that is still in the open service state in the second period to obtain the corresponding communication log set; performing DDoS attack analysis based on the mapping details and communication log set of each target open service, obtaining the DDoS attack information and attack information confidence of each target open service, and performing attack warning based on the DDoS attack information whose attack information confidence is not less than the confidence threshold.
[0070] This application links the bearer network, uses large model analysis technology, and coordinates the DDoS attack monitoring system and the anti-DDoS traffic cleaning platform to form a multi-dimensional coordinated three-dimensional monitoring, fully perceive the DDoS attack status, and achieve real-time monitoring of the DDoS attack status around the world in seconds, shortening the DDoS attack perception time difference as much as possible and improving the DDoS attack defense effect. The coordinated bearer network and traffic cleaning equipment can block the source of accurate attacks, form a highly automated traffic cleaning capability, strengthen the core capability of anti-DDoS traffic cleaning, and improve the cleaning efficiency of the anti-DDoS traffic cleaning platform.
[0071] The preferred embodiments of the present application are described below in conjunction with the drawings in the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. In addition, the embodiments and features in the embodiments of the present application may be combined with each other if there is no conflict.
[0072] The DDoS attack defense method provided in the embodiment of the present application is applied to a multi-stage traffic monitoring and cleaning platform based on a bearer network, combined with Figure 1 The architecture diagram shown shows that the platform consists of a protocol space mapping module, a mapping asset storage module, a bearer network, a large model, a DDoS attack monitoring system and an anti-DDoS traffic cleaning platform.
[0073] The protocol space mapping module performs cyberspace mapping on the Internet and obtains service asset information of Internet open services. The mapping asset storage module is used to store the mapping details of Internet open services. The bearer network is used to detect and obtain the communication log set of Internet open services. The large model performs DDoS attack analysis based on the mapping details and communication log set of Internet open services to obtain DDoS attack information on the Internet. The bearer network is called to perform bearer network detection on the controlled end monitored by the simulation protocol of the DDoS attack monitoring system to obtain the corresponding communication log set. By analyzing the communication log set, the DDoS attack information monitored by the simulation protocol is obtained, and the DDoS attack information on the Internet is realized, which forms information complementarity with the information obtained by the simulation protocol monitoring.
[0074] The platform can achieve but is not limited to the following main core effects: (1) Each link of this application adopts automatic interface connection, and the integrated monitoring deployment is highly automated. There is no need for human intervention in the intermediate process. While reducing the cost of labor input, it can hunt the control terminals of various DDoS botnet families distributed around the world in real time; (2) Build a low-interaction monitoring network between the simulation protocol and the control terminal to grasp the attack targets, attack types, attack duration and other detailed information of the control terminals in various places in real time, realize accurate restoration of DDoS attack portraits, use large models to analyze the communication log sets associated with the service assets of Internet open services in real time, grasp DDoS attack information in real time, and then store the large model analysis results together with the DDoS attack portrait information and attack links in real time, fully perceive the DDoS attack status, and achieve real-time monitoring of the DDoS attack status around the world in seconds, minimizing the time spent on DDoS attacks. Shorten the time difference of DDoS attack perception and improve the DDoS attack defense effect; (3) Based on the real-time monitoring and acquisition of attack status information, combined with the network communication of the control end, grasp the distribution area and scale status of the controlled ends associated with the control ends in real time, and realize accurate tracing of DDoS attack links; (4) Grasp the DDoS attack information on the Internet in real time, and form information complementarity with the information obtained by simulation protocol monitoring; (5) Open up the connection between traffic cleaning equipment and DDoS attack monitoring system, anti-DDoS traffic cleaning platform, and bearer network, cooperate with the bearer network to do a good job in blocking the source of accurate attacks, curb the generation of DDoS attack traffic, and cooperate with traffic cleaning equipment to do a good job in accurate tracing and cleaning attack traffic, forming a highly automated traffic cleaning capability, strengthening the core capability of anti-DDoS traffic cleaning, and improving the cleaning efficiency of the anti-DDoS traffic cleaning platform.
[0075] like Figure 2A-2B As shown, the method provided in the embodiment of the present application is executed to defend against DDoS attacks launched by attackers on the Internet. The specific process is as follows:
[0076] S201: Mapping the Internet network space, obtaining service asset information of each original open service in the first period, and taking the original open services associated with the service asset information matching the specific service features as candidate open services.
[0077] In response to the request for surveying and mapping service assets triggered by the surveying and mapping asset storage module, the protocol space mapping module scans all ports and services on the Internet, identifies the original open services that support public access in the first period, and obtains the service asset information of each original open service. The service asset information includes but is not limited to: IP address, port number, version number, service type (such as DNS, NTP), open service characteristics, etc.
[0078] The protocol space mapping module screens the original open services obtained through mapping according to the pre-configured specific service features, and takes the original open services associated with the service asset information that hits the specific service features as candidate open services.
[0079] S202: Classify and store the service asset information of each candidate open service to obtain corresponding mapping details, and perform bearer network detection on the target open service that is still in the open service state in the second period to obtain the corresponding communication log set.
[0080] The surveying and mapping asset storage module stores the service information of each candidate open service in detail according to the storage fields of service name, service type, service opening time, service distribution area and service label, and obtains the surveying and mapping details of each candidate open service under different storage fields as shown in Table 1.
[0081] Table 1
[0082]
[0083] The surveying and mapping asset storage module obtains the service asset information of the target open service that is still in the open service state in the second cycle, and generates a request for detecting the service asset. In response to the request for detecting the service asset triggered by the surveying and mapping asset storage module, the bearer network detects the service asset information of the target open service that is still in the open service state in the second cycle in quasi-real time, obtains the communication log set generated when providing the corresponding target open service based on the log storage location recorded in each service asset information, and passes each communication log set to the large model for log integration analysis. Among them, each communication log entry records the traffic transmission process between the target open service and the service request end.
[0084] S203: Perform DDoS attack analysis based on the mapping details and communication log set of each target open service, obtain DDoS attack information and attack information confidence of each target open service, and issue an attack warning based on DDoS attack information whose attack confidence is not less than the confidence threshold.
[0085] The connection between the big model and the bearer network is established to form collaborative data collection and analysis, so that the big model can perform DDoS attack analysis based on the mapping details and communication log sets of each target open service. For each target open service, the following operations are performed respectively:
[0086] In the mapping details of a target open service, obtain the service opening time of the target open service;
[0087] In the communication log set of the target open service, the communication log entries between the service opening time are obtained, and based on each communication log entry, the number of response packets sent by the target open service to different service request terminals is counted;
[0088] Log analysis is performed on communication log entries whose sending quantity is not less than the response packet threshold to obtain the DDoS attack information and attack information confidence level of the DDoS attack launched by the target open service on the corresponding service request end.
[0089] In DDoS attacks, there are cases where open Internet services are used as reflection servers. These services can be abused by attackers to amplify attack traffic and reflect it to the target of attack, usually due to improper configuration or protocol characteristics. Therefore, the large model can combine the mapping details of Internet open services with the communication log set to analyze which Internet open services have launched DDoS attacks on the service request end, and grasp the distribution and scale status of the controlled ends associated with the control ends in real time, so as to accurately trace the DDoS attack link.
[0090] The connection between the big model and the DDoS attack monitoring system is established to form DDoS attack information storage and verification. The big model transmits the DDoS attack information to the DDoS attack monitoring system, and the system stores the DDoS attack information whose confidence level is not less than the confidence threshold, and re-verifies the DDoS attack information whose confidence level is less than the confidence threshold.
[0091] The same-source reflection logs generated in normalized DDoS attacks have attack information confidence levels greater than 100 after being analyzed by the big model. Therefore, when the attack information confidence level is greater than 80 and less than 100, the associated attack information is low-confidence attack information. The big model calls the bot identified by the DDoS attack monitoring system to verify again whether the low-confidence attack information is triggered by the bot.
[0092] The specific verification process is that the large model obtains the puppet machine identified by the DDoS attack monitoring system, and then calls the bearer network to query the communication log set of the puppet machine. By analyzing the communication log set, the detailed attack information of the puppet machine is obtained, and it is passed to the DDoS attack monitoring system as supplementary information for storage.
[0093] The connection between the anti-DDoS traffic cleaning platform and the DDoS attack monitoring system and the large model is established to form a three-dimensional DDoS attack monitoring and early warning system. The connection between the anti-DDoS traffic cleaning platform and the bearer network is established to form an automated attack traffic traction cleaning system and normal traffic injection system. The large model transmits the attack information to the anti-DDoS traffic cleaning platform for traffic cleaning, and blocks the Internet open services from sending response packets to the attack targets in the bearer network. The anti-DDoS traffic cleaning platform can perform fuzzy traffic cleaning to remove data packets with highly overlapping traffic content, and can also perform precise traffic cleaning to remove IP addresses identified as puppet machines and reflection servers.
[0094] Combination Figure 2C , the DDoS attack monitoring system performs the following operations to identify zombie machines on the Internet:
[0095] The collaborative automation between the DDoS attack monitoring system and the puppet machine protocol hijacking and the accuracy of the puppet machine protocol hijacking instruction parsing are established. The DDoS attack monitoring system responds to the monitoring instructions issued by the control node library, hijacks the communication between the control end and the controlled end, and realizes the simulation protocol monitoring function. Secondly, the control instructions issued by the control end are obtained and parsed, and the DDoS attack task status details of the control end and the IP address of the controlled end are grasped in real time. Based on the IP address of the controlled end, the corresponding simulation end is deployed, and the simulation end executes the control instructions, and the DDoS attack information generated by the simulation end simulating the DDoS attack is collected in real time, which is complementary to the collected DDoS attack task status details of the control end, and is stored in the warehouse. The DDoS attack monitoring system performs communication correlation monitoring on the control end in the attack state, and grasps the information and scale of the puppet machines associated with the control end for executing the DDoS attack in real time, and stores this information in the warehouse to achieve accurate tracing of the DDoS attack link.
[0096] exist Figure 2D The DDoS attack monitoring system shown in the figure displays the targets attacked by DDoS attacks within a period of time, the puppet machines that launched the DDoS attacks, as well as the specific attack information such as the number of puppet machines, peak value, attack method, threat source, etc., to accurately restore the DDoS attack portrait, fully perceive the DDoS attack status, accurately trace the DDoS attack link, and then realize accurate attack source blocking and curb the generation of DDoS attack traffic.
[0097] like Figure 3As shown in the figure, the attacker manipulated multiple botnet clusters through the control end, sent DDoS control instructions to multiple reflection servers in the cluster, and launched a DDoS attack on the DNS server. Big data analyzes DDoS attacks based on the mapping details and communication logs of each Internet open service, and feeds back the analysis results to the bearer network, cooperating with the bearer network to block the attack source accurately and curb the generation of DDoS attack traffic.
[0098] The DDoS attack monitoring system monitors DDoS attack behaviors and identifies the puppet machines that are controlled by the control end to execute attacks. Big data obtains the puppet machines identified by the DDoS attack monitoring system, and then calls the bearer network to query the communication log set of the puppet machine. By analyzing the communication log set, detailed attack information of the puppet machine is obtained and passed to the DDoS attack monitoring system as supplementary information for storage.
[0099] The connection between the bearer network and the anti-DDoS traffic cleaning platform is established to form automated attack traffic traction cleaning and normal traffic injection. The connection between the DDoS attack monitoring system and the anti-DDoS traffic cleaning platform is established to collect DDoS attack information generated by the simulated DDoS attack on the simulation end in real time, and to complement the information with the collected DDoS attack task status details on the control end, so as to fully perceive the DDoS attack status.
[0100] Based on the same inventive concept as the above method embodiment, the present application embodiment also provides a structural diagram of a DDoS attack defense device. Figure 4 As shown, the DDoS attack defense device 400 may include:
[0101] The mapping unit 401 is used to perform network space mapping on the Internet, obtain service asset information of each original open service in the first period, and use the original open services associated with the service asset information that hits the specific service feature as candidate open services;
[0102] The detection unit 402 is used to classify and store the service asset information of each candidate open service, obtain corresponding mapping details, and perform bearer network detection on the target open service that is still in the open service state in the second period to obtain the corresponding communication log set;
[0103] The early warning unit 403 is used to perform DDoS attack analysis based on the mapping details and communication log sets of each target open service, obtain the DDoS attack information and attack information confidence of each target open service, and issue an attack early warning based on the DDoS attack information whose attack confidence is not less than the confidence threshold.
[0104] Optionally, the surveying and mapping unit 401 is used to:
[0105] Scan all ports and services on the Internet, identify the original open services that support public access in the first cycle, and obtain the service asset information of each original open service.
[0106] Optionally, the detection unit 402 is used to:
[0107] According to the storage fields of service name, service type, service opening time, service distribution area and service label, the service information of each candidate open service is stored in detail, and the mapping details of each candidate open service under different storage fields are obtained.
[0108] Optionally, the detection unit 402 is used to:
[0109] Obtain service asset information of target open services that are still in an open service state during the second cycle;
[0110] Based on the log storage location recorded in each service asset information, a communication log set generated when providing the corresponding target open service is obtained, and each communication log entry records the traffic transmission process between the target open service and the service request end.
[0111] Optionally, the early warning unit 403 opens services for each target and performs the following operations respectively:
[0112] In the mapping details of a target open service, obtain the service opening time of the target open service;
[0113] In the communication log set of the target open service, obtain the communication log entries between the service opening time, and based on each communication log entry, count the number of response packets sent by the target open service to different service request ends;
[0114] Log analysis is performed on communication log entries whose sending quantity is not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the DDoS attack launched by the target open service on the corresponding service request end.
[0115] For the convenience of description, the above parts are divided into modules (or units) according to their functions and described separately. Of course, when implementing this application, the functions of each module (or unit) can be implemented in the same or multiple software or hardware.
[0116] After introducing the DDoS attack defense method and apparatus according to an exemplary embodiment of the present application, next, a computer device according to another exemplary embodiment of the present application is introduced.
[0117] Those skilled in the art will appreciate that various aspects of the present application may be implemented as a system, method or program product. Therefore, various aspects of the present application may be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or a combination of hardware and software, which may be collectively referred to as "circuit", "module" or "system" herein.
[0118] Based on the same inventive concept as the above method embodiment, the present application embodiment also provides a computer device, see Figure 5 As shown, the computer device 500 may include at least a processor 501 and a memory 502. The memory 502 stores program codes, and when the program codes are executed by the processor 501, the processor 501 executes the steps of any one of the above-mentioned DDoS attack defense methods.
[0119] In some possible implementations, the computing device according to the present application may include at least one processor and at least one memory. The memory stores program code, and when the program code is executed by the processor, the processor executes the steps of the DDoS attack defense method according to various exemplary implementations of the present application described above in this specification. For example, the processor may execute the following steps: Figure 2A Follow the steps shown in .
[0120] Refer to the following Figure 6 hereinafter, a computing device 600 according to this embodiment of the present application is described. Figure 6 The computing device 600 is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0121] like Figure 6 As shown, the computing device 600 is in the form of a general computing device. The components of the computing device 600 may include but are not limited to: at least one processing unit 601, at least one storage unit 602, and a bus 603 connecting different system components (including the storage unit 602 and the processing unit 601).
[0122] Bus 603 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a processor, or a local bus using any of a variety of bus architectures.
[0123] The storage unit 602 may include a readable medium in the form of a volatile memory, such as a random access memory (RAM) 6021 and / or a cache memory unit 6022 , and may further include a read-only memory (ROM) 6023 .
[0124] The storage unit 602 may also include a program / utility 6025 having a set (at least one) of program modules 6024, such program modules 6024 including but not limited to: an operating system, one or more application programs, other program modules, and program data, each of which or some combination may include an implementation of a network environment.
[0125] The computing device 600 may also communicate with one or more external devices 604 (e.g., keyboards, pointing devices, etc.), one or more devices that enable a user to interact with the computing device 600, and / or any device that enables the computing device 600 to communicate with one or more other computing devices (e.g., routers, modems, etc.). Such communication may be performed via an input / output (I / O) interface 605. In addition, the computing device 600 may also communicate with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) via a network adapter 606. As shown, the network adapter 606 communicates with other modules for the computing device 600 via a bus 603. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in conjunction with the computing device 600, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0126] Based on the same inventive concept as the above method embodiment, various aspects of the DDoS attack defense method provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to enable the computer device to execute the steps of the DDoS attack defense method according to various exemplary embodiments of the present application described above in this specification. For example, the computer device can execute the following steps: Figure 2A Follow the steps shown in .
[0127] The program product may use any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0128] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0129] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A DDoS attack defense method, characterized in that: include: Conduct cyberspace mapping of the Internet to obtain service asset information of each original open service in the first period, and use the original open services associated with service asset information that hits specific service features as candidate open services; Classify and store the service asset information of each candidate open service to obtain corresponding mapping details, and perform bearer network detection on the target open service that is still in the open service state in the second cycle to obtain the corresponding communication log set; DDoS attack analysis is performed based on the mapping details and communication log sets of each target open service, the DDoS attack information and attack information confidence of each target open service are obtained, and attack warnings are issued based on DDoS attack information whose attack confidence is not less than the confidence threshold.
2. The method according to claim 1, characterized in that Conduct cyberspace mapping of the Internet to obtain service asset information of each original open service in the first period, including: Scan all ports and services on the Internet, identify the original open services that support public access in the first cycle, and obtain the service asset information of each original open service.
3. The method according to claim 1, characterized in that The service asset information of each candidate open service is classified and stored to obtain the corresponding mapping details, including: According to the storage fields of service name, service type, service opening time, service distribution area and service label, the service information of each candidate open service is stored in detail, and the mapping details of each candidate open service under different storage fields are obtained.
4. The method according to claim 1, characterized in that Perform bearer network detection on the target open services that are still in the open service state during the second cycle, and obtain the corresponding communication log set, including: Obtain service asset information of target open services that are still in an open service state during the second period; Based on the log storage location recorded in each service asset information, a communication log set generated when providing the corresponding target open service is obtained, and each communication log entry records the traffic transmission process between the target open service and the service request end.
5. The method according to claim 1, characterized in that Based on the mapping details of each target open service and each communication log set, DDoS attack analysis is performed to obtain the DDoS attack information and attack information confidence of each target open service, including: To open services for each target, perform the following operations: In the mapping details of a target open service, obtain the service opening time of the target open service; In the communication log set of the target open service, obtain the communication log entries between the service opening time, and based on each communication log entry, count the number of response packets sent by the target open service to different service request ends; Log analysis is performed on communication log entries whose sending quantity is not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the DDoS attack launched by the target open service on the corresponding service request end.
6. A DDoS attack defense device, characterized in that: include: A mapping unit is used to map the Internet network space, obtain the service asset information of each original open service in the first period, and use the original open services associated with the service asset information that hits the specific service feature as candidate open services; The detection unit is used to classify and store the service asset information of each candidate open service, obtain corresponding mapping details, and perform bearer network detection on the target open service that is still in the open service state in the second period to obtain the corresponding communication log set; The early warning unit is used to perform DDoS attack analysis based on the mapping details and communication log sets of each target open service, obtain the DDoS attack information and attack information confidence of each target open service, and issue an attack early warning based on the DDoS attack information whose attack confidence is not less than the confidence threshold.
7. A computer device, characterized in that: It comprises a processor and a memory, wherein the memory stores program codes, and when the program codes are executed by the processor, the processor executes the steps of the method according to any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that: The method comprises a program code, and when the program code is run on a computer device, the program code is used to make the computer device execute the steps of the method according to any one of claims 1 to 5.
9. A computer program product, characterized in that The method comprises computer instructions, which implement the steps of the method according to any one of claims 1 to 5 when executed by a processor.
Citation Information
Patent Citations
Analytical method for security log based on Apriori algorithm
CN108255996A
DDoS reflection attack defense method, device and apparatus
CN110661763A
DDoS attack defense system and method based on dynamic transformation
CN111385235A
Protection method for providing distributed denial of attack
CN113037841A
Automatic detection method for intranet attack surface
CN114389848A
Cited By
DDoS attack object identification method, device and equipment based on security agent
CN121333662A