DDoS attack defense methods, devices, equipment, and storage media

By combining cyberspace mapping and large-scale model analysis with communication log sets, and working in conjunction with a DDoS attack monitoring system and a traffic scrubbing platform, the problem of DDoS attack perception and tracing in existing technologies has been solved, achieving real-time monitoring and efficient scrubbing DDoS defense.

CN119996051BActive Publication Date: 2025-11-14CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510301928.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-11-14
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

Existing DDoS attack defense methods cannot detect DDoS reflection attacks on the bearer network in a timely manner, and it is difficult to trace the attack chain, leading to system crashes and paralysis, and the inability to process legitimate user requests normally.

Method used

By mapping the internet's cyberspace, acquiring service asset information, classifying and storing it, and conducting bearer network detection, and combining it with large-scale model analysis of communication log sets, we can achieve real-time monitoring and early warning of DDoS attack information. By coordinating the DDoS attack monitoring system and the anti-DDoS traffic scrubbing platform, we can form a multi-dimensional and collaborative monitoring and precise blocking system.

Benefits of technology

It achieves real-time monitoring of global DDoS attack status at the second level, shortens the perception time difference, improves the DDoS attack defense effect, strengthens the anti-DDoS traffic cleaning capability, accurately traces the attack link and blocks the attack source, and improves cleaning efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996051B_ABST
    Figure CN119996051B_ABST
Patent Text Reader

Abstract

This application relates to the field of network security technology, and provides a method, apparatus, device, and storage medium for defending against DDoS attacks. The method includes: linking the network to the DDoS protection network, using large-scale model analysis technology, and coordinating with a DDoS attack monitoring system and an anti-DDoS traffic scrubbing platform to form a multi-faceted, collaborative, three-dimensional monitoring system. This comprehensively perceives the DDoS attack status, achieving real-time monitoring of DDoS attacks worldwide within seconds, minimizing the time lag in DDoS attack detection, and improving the effectiveness of DDoS attack defense. The collaborative operation of the network and traffic scrubbing equipment ensures precise blocking of attack sources, forming a highly automated traffic scrubbing capability, strengthening the core capabilities of anti-DDoS traffic scrubbing, and improving the scrubbing efficiency of the anti-DDoS traffic scrubbing platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and provides a method, apparatus, device and storage medium for defending against DDoS attacks. Background Technology

[0002] Attackers launch DDoS attacks against their targets, causing resource overload and preventing the targets from processing legitimate user requests. DDoS attacks have become one of the biggest threats to network security.

[0003] Currently, DDoS attacks exhibit four significant characteristics: First, large-scale attacks are exceptionally active, with terabyte-level attacks occurring frequently; second, compared to previous years, the frequency of attacks continues to increase, and low-speed sweep attacks have become the mainstream attack method to evade defenses, employing hybrid attack techniques to launch network attacks; third, the ramp-up speed of large-volume attacks has reached new highs, achieving terabyte-level attacks within seconds, causing a huge impact on the targets; fourth, the complexity of attacks continues to increase, intensifying the attack threat.

[0004] Therefore, the following challenges arise when defending against DDoS attacks: First, as the complexity and intensity of DDoS attacks increase, existing DDoS attack defense methods cannot detect DDoS reflection attacks on the bearer network in a timely manner; Second, as the complexity of attack methods increases, existing DDoS attack defense methods struggle to trace the attack chain, thus failing to promptly block attack traffic received by the bearer network, leading to system crashes and paralysis, and the inability to properly process legitimate user requests. Summary of the Invention

[0005] This application provides a method, apparatus, device, and storage medium for defending against DDoS attacks, in order to solve the problem of not being able to detect DDoS reflection attacks and scrubbing attack traffic on the bearer network in a timely manner.

[0006] In a first aspect, embodiments of this application provide a method for defending against DDoS attacks, including:

[0007] The network space is mapped to obtain the service asset information of each original open service in the first period, and the original open services associated with the service asset information that hits specific service characteristics are used as candidate open services.

[0008] The service asset information of each candidate open service is classified and stored to obtain the corresponding mapping details. Additionally, the bearer network is detected for the target open services that are still in the open service state during the second cycle to obtain the corresponding communication log set.

[0009] DDoS attack analysis is performed based on the mapping details and communication log sets of each target open service to obtain DDoS attack information and attack information confidence level of each target open service, and attack warnings are issued based on DDoS attack information with an attack confidence level not less than the confidence level threshold.

[0010] Optionally, perform cyberspace mapping on the Internet to obtain service asset information for each original open service within the first period, including:

[0011] Scan all ports and services on the Internet, identify the original open services that support public access within the first period, and obtain the service asset information of each original open service.

[0012] Optionally, the service asset information of each candidate open service can be categorized and stored to obtain corresponding mapping details, including:

[0013] Based on the storage fields of service name, service type, service open duration, service distribution region, and service tag, the service information of each candidate open service is stored in detail to obtain the mapping details of each candidate open service under different storage fields.

[0014] Optionally, for target open services that are still in the open service state during the second cycle, bearer network detection is performed to obtain the corresponding communication log set, including:

[0015] Obtain service asset information for target open services that are still in an open service state during the second cycle;

[0016] Based on the log storage location recorded in the information of each service asset, the communication log set generated when providing the corresponding target open service is obtained. Each communication log entry records the traffic transmission process between the target open service and the service requesting end.

[0017] Optionally, DDoS attack analysis is performed based on the mapping details of each target open service and each communication log set to obtain DDoS attack information and attack information confidence levels for each target open service, including:

[0018] For each target service, perform the following operations respectively:

[0019] From the mapping details of a target open service, obtain the service open duration of the target open service;

[0020] In the communication log set of the target open service, obtain the communication log entries located between the service open durations, and based on each communication log entry, count the number of response packets sent by the target open service to different service requesters;

[0021] Log analysis is performed on communication log entries with a number of transmissions not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the target open service launching a DDoS attack against the corresponding service requesting end.

[0022] Secondly, embodiments of this application also provide a DDoS attack defense device, comprising:

[0023] The surveying and mapping unit is used to conduct cyberspace surveying and mapping of the Internet, obtain the service asset information of each original open service within the first period, and associate the original open services with service asset information that hits specific service characteristics as candidate open services.

[0024] The detection unit is used to classify and store the service asset information of each candidate open service to obtain the corresponding mapping details, and to perform bearer network detection on the target open service that is still in the open service state during the second cycle to obtain the corresponding communication log set.

[0025] The early warning unit is used to perform DDoS attack analysis based on the mapping details and communication log sets of each target open service, obtain DDoS attack information and attack information confidence level of each target open service, and issue attack warnings based on DDoS attack information with an attack confidence level not less than the confidence level threshold.

[0026] Optionally, perform cyberspace mapping on the Internet to obtain service asset information for each original open service within the first period, including:

[0027] Scan all ports and services on the Internet, identify the original open services that support public access within the first period, and obtain the service asset information of each original open service.

[0028] Optionally, the service asset information of each candidate open service can be categorized and stored to obtain corresponding mapping details, including:

[0029] Based on the storage fields of service name, service type, service open duration, service distribution region, and service tag, the service information of each candidate open service is stored in detail to obtain the mapping details of each candidate open service under different storage fields.

[0030] Optionally, for target open services that are still in the open service state during the second cycle, bearer network detection is performed to obtain the corresponding communication log set, including:

[0031] Obtain service asset information for target open services that are still in an open service state during the second cycle;

[0032] Based on the log storage location recorded in the information of each service asset, the communication log set generated when providing the corresponding target open service is obtained. Each communication log entry records the traffic transmission process between the target open service and the service requesting end.

[0033] Optionally, DDoS attack analysis is performed based on the mapping details of each target open service and each communication log set to obtain DDoS attack information and attack information confidence levels for each target open service, including:

[0034] For each target service, perform the following operations respectively:

[0035] From the mapping details of a target open service, obtain the service open duration of the target open service;

[0036] In the communication log set of the target open service, obtain the communication log entries located between the service open durations, and based on each communication log entry, count the number of response packets sent by the target open service to different service requesters;

[0037] Log analysis is performed on communication log entries with a number of transmissions not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the target open service launching a DDoS attack against the corresponding service requesting end.

[0038] Thirdly, embodiments of this application also provide a computer device, including a processor and a memory, wherein the memory stores program code, and when the program code is executed by the processor, the processor performs the steps of any of the above-described DDoS attack defense methods.

[0039] Fourthly, embodiments of this application also provide a computer-readable storage medium including program code, which, when the program product is run on a computer device, is used to cause the computer device to perform the steps of any of the above-described DDoS attack defense methods.

[0040] Fifthly, embodiments of this application also provide a computer program product, including computer instructions, which are executed by a processor to perform the steps of any of the above-described DDoS attack defense methods.

[0041] The beneficial effects of this application are as follows:

[0042] This application provides a method, apparatus, device, and storage medium for defending against DDoS attacks. The method includes: performing network space mapping on the Internet to obtain service asset information of each original open service within a first period, and identifying original open services associated with the service asset information of a specific service as candidate open services; classifying and storing the service asset information of each candidate open service to obtain corresponding mapping details; and performing bearer network detection on target open services that are still in the open service state within a second period to obtain corresponding communication log sets; performing DDoS attack analysis based on the mapping details and communication log sets of each target open service to obtain DDoS attack information and attack information confidence levels for each target open service, and issuing attack warnings based on DDoS attack information with attack information confidence levels not less than a confidence threshold.

[0043] This application integrates the bearer network, utilizes large-scale model analysis technology, and coordinates with the DDoS attack monitoring system and the anti-DDoS traffic scrubbing platform to form a multi-faceted, collaborative, three-dimensional monitoring system. This system comprehensively perceives the status of DDoS attacks, achieving real-time monitoring of DDoS attacks worldwide within seconds, minimizing the time lag in DDoS attack detection, and improving DDoS attack defense effectiveness. The coordinated operation of the bearer network and traffic scrubbing equipment ensures precise blocking of attack sources, forming a highly automated traffic scrubbing capability, strengthening the core capabilities of anti-DDoS traffic scrubbing, and improving the scrubbing efficiency of the anti-DDoS traffic scrubbing platform.

[0044] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description

[0045] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0046] Figure 1 A schematic diagram of the architecture of a multi-stage traffic monitoring and cleaning platform based on a bearer network provided in an embodiment of this application;

[0047] Figure 2A A schematic diagram illustrating the process of defending against DDoS attacks launched by attackers on the Internet, provided in an embodiment of this application;

[0048] Figure 2B A schematic diagram illustrating the logic for defending against DDoS attacks launched by attackers on the Internet, provided in an embodiment of this application.

[0049] Figure 2C This is a schematic diagram illustrating the operation of the DDoS attack monitoring system provided in the embodiments of this application;

[0050] Figure 2D This is a schematic diagram of the interface of the DDoS attack monitoring system provided in the embodiments of this application;

[0051] Figure 3 A complete logical diagram of monitoring DDoS attacks provided in the embodiments of this application;

[0052] Figure 4 A schematic diagram of a DDoS attack defense device provided in an embodiment of this application;

[0053] Figure 5 This is a schematic diagram of the composition structure of a computer device provided in the embodiments of this application;

[0054] Figure 6 This is a schematic diagram of the structure of a computing device in an embodiment of this application. Detailed Implementation

[0055] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this application. Obviously, the described embodiments are only some embodiments of the technical solutions of this application, and not all embodiments. Based on the embodiments recorded in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the technical solutions of this application.

[0056] The following explanations of some terms used in the embodiments of this application are provided to facilitate understanding by those skilled in the art.

[0057] 1. DDoS attack: refers to a network attack launched simultaneously by multiple control terminals in different locations against one or more targets, or by a control terminal controlling multiple controlled terminals in different locations to launch a network attack simultaneously against one or more targets, causing the targets to be unable to provide normal services.

[0058] In this context, the control end refers to the machine used by the attacker, while the controlled end is a bot machine remotely controlled by the control end. Bot machines are usually infected computers and IoT devices, and the targets of the attack are usually the target server, service, or network.

[0059] 2. T-level attack: This refers to a DDoS attack launched by the control end at an extremely high traffic rate of TB per second (Tbps). The target may experience system crash and paralysis due to the excessive load it bears in a short period of time.

[0060] 3. DDoS Reflection Attack: To enhance the attack effect, the control end forges the Internet Protocol Address (IP address) of the target, modifies the source IP address of the request to the IP address of the target, and sends the request to many reflection servers. These servers then send response packets to the target, causing the target to receive much more data traffic than the actual request. Due to being overwhelmed by a large number of response packets, the target is unable to provide normal services.

[0061] Reflection servers are typically widely distributed globally and publicly accessible, such as Domain Name System (DNS) servers and Network Time Protocol (NTP) servers. These servers have high bandwidth and fast response times, allowing attackers to obtain large amounts of traffic from a relatively small number of reflection servers. By using dozens or even hundreds of reflection servers to launch attacks simultaneously against the target, attackers can overload the target's requests, causing the target's service to become unavailable.

[0062] 4. Puppet machine: In a DDoS attack, this refers to a machine that is remotely controlled by the controlling end and used to launch various malicious activities, including DDoS attacks and sending spam.

[0063] 5. Backbone Network: Located between the access network and the switches, this network carries various service data. Its primary task is to provide stable, reliable, and efficient data transmission services for various services. It can be an operator's backbone network or an enterprise's internal network.

[0064] 6. Internet Mapping: This refers to the comprehensive scanning, analysis, and visualization of resources, devices, and services on the Internet to create detailed network structure maps. This process helps in understanding global or regional network topology, identifying potential security threats, assessing the robustness and reliability of infrastructure, and providing data support for cybersecurity research.

[0065] The design concept of the embodiments of this application is briefly introduced below:

[0066] Attackers launch DDoS attacks against their targets, causing resource overload and preventing the targets from processing legitimate user requests. DDoS attacks have become one of the biggest threats to network security.

[0067] Currently, DDoS attacks exhibit four significant characteristics: First, large-scale attacks are exceptionally active, with terabyte-level attacks occurring frequently; second, compared to previous years, the frequency of attacks continues to increase, and low-speed sweep attacks have become the mainstream attack method to evade defenses, employing hybrid attack techniques to launch network attacks; third, the ramp-up speed of large-volume attacks has reached new highs, achieving terabyte-level attacks within seconds, causing a huge impact on the targets; fourth, the complexity of attacks continues to increase, intensifying the attack threat.

[0068] Therefore, the following challenges arise when defending against DDoS attacks: First, as the complexity and intensity of DDoS attacks increase, existing DDoS attack defense methods cannot detect DDoS reflection attacks on the bearer network in a timely manner; Second, as the complexity of attack methods increases, existing DDoS attack defense methods struggle to trace the attack chain, thus failing to promptly block attack traffic received by the bearer network, leading to system crashes and paralysis, and the inability to properly process legitimate user requests.

[0069] In view of this, embodiments of this application provide a method, apparatus, device, and storage medium for defending against DDoS attacks. The method includes: performing cyberspace mapping on the Internet to obtain service asset information for each original open service within a first period, and identifying original open services associated with the service asset information of a specific service as candidate open services; classifying and storing the service asset information of each candidate open service to obtain corresponding mapping details; and performing bearer network detection on target open services still in an open service state within a second period to obtain corresponding communication log sets; performing DDoS attack analysis based on the mapping details and communication log sets of each target open service to obtain DDoS attack information and attack information confidence levels for each target open service, and issuing attack warnings based on DDoS attack information with attack information confidence levels not less than a confidence threshold.

[0070] This application integrates the bearer network, utilizes large-scale model analysis technology, and coordinates with the DDoS attack monitoring system and the anti-DDoS traffic scrubbing platform to form a multi-faceted, collaborative, three-dimensional monitoring system. This system comprehensively perceives the status of DDoS attacks, achieving real-time monitoring of DDoS attacks worldwide within seconds, minimizing the time lag in DDoS attack detection, and improving DDoS attack defense effectiveness. The coordinated operation of the bearer network and traffic scrubbing equipment ensures precise blocking of attack sources, forming a highly automated traffic scrubbing capability, strengthening the core capabilities of anti-DDoS traffic scrubbing, and improving the scrubbing efficiency of the anti-DDoS traffic scrubbing platform.

[0071] The preferred embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments and features in the embodiments of this application can be combined with each other without conflict.

[0072] The DDoS attack defense method provided in this application embodiment is applied to a multi-stage traffic monitoring and cleaning platform based on a bearer network, combined with Figure 1 The schematic diagram shown illustrates that the platform consists of a protocol space mapping module, a mapping asset storage module, a bearer network, a large model, a DDoS attack monitoring system, and an anti-DDoS traffic scrubbing platform.

[0073] The protocol space mapping module performs network space mapping on the Internet to obtain service asset information of open Internet services. The mapping asset storage module stores the mapping details of open Internet services. The bearer network is used to detect and obtain the communication log set of open Internet services. The large model performs DDoS attack analysis based on the mapping details and communication log set of open Internet services to obtain DDoS attack information in the Internet. It calls the bearer network to detect the controlled end detected by the simulation protocol of the DDoS attack monitoring system and obtain the corresponding communication log set. By analyzing the communication log set, it obtains the DDoS attack information monitored by the simulation protocol, realizing the DDoS attack information in the Internet and the information obtained by the simulation protocol monitoring to form information complementarity.

[0074] The platform can achieve, but is not limited to, the following main core effects: (1) Each link of this application adopts automatic interface connection, and the integrated monitoring deployment is highly automated. No manual intervention is required in the intermediate process. While reducing the cost of manual input, it can hunt down the control terminals of various DDoS botnet families distributed around the world in real time; (2) A low-interaction monitoring network between the simulation protocol and the control terminal is built to grasp the detailed information such as the attack targets, attack types, and attack duration of the control terminals in various places in real time, so as to accurately restore the DDoS attack profile. The large model is used to analyze the communication log set associated with the service assets of Internet open services in real time, and grasp the DDoS attack information in real time. Then, the analysis results of the large model and the DDoS attack profile information and attack links are put into the warehouse in real time to fully perceive the DDoS attack status, achieve the second-level real-time monitoring of the DDoS attack status around the world, and minimize the impact of the DDoS attack. (3) Based on real-time monitoring and acquisition of attack status information, combined with the network communication of the control terminal, the distribution area and scale status of the controlled terminals associated with the control terminals in various places are grasped in real time, so as to achieve accurate tracing of DDoS attack links; (4) Real-time grasp of DDoS attack information in the Internet, and information complementarity with the information obtained by simulation protocol monitoring; (5) Connect the traffic cleaning equipment with the DDoS attack monitoring system, the anti-DDoS traffic cleaning platform and the bearer network, coordinate with the bearer network to do a good job of accurate attack source blocking, curb the generation of DDoS attack traffic, coordinate with the traffic cleaning equipment to do a good job of accurate tracing and cleaning of attack traffic, form a highly automated traffic cleaning capability, strengthen the core capability of anti-DDoS traffic cleaning, and improve the cleaning efficiency of the anti-DDoS traffic cleaning platform.

[0075] like Figure 2A-2B As shown, the method provided in this application embodiment is used to defend against DDoS attacks launched by attackers on the Internet. The specific process is as follows:

[0076] S201: Conduct cyberspace mapping of the Internet, obtain service asset information of each original open service within the first period, and identify original open services associated with service asset information that matches specific service characteristics as candidate open services.

[0077] In response to a request for surveying service assets triggered by the surveying asset warehousing module, the protocol space surveying module scans all ports and services on the Internet, identifies the original open services that support public access within the first period, and obtains the service asset information for each original open service. Service asset information includes, but is not limited to: IP address, port number, version number, service type (such as DNS, NTP), and open service characteristics.

[0078] The protocol space mapping module filters the original open services obtained from the mapping based on pre-configured specific service characteristics, and selects the original open services associated with service asset information that match the specific service characteristics as candidate open services.

[0079] S202: Classify and store the service asset information of each candidate open service to obtain the corresponding mapping details, and perform bearer network detection on the target open service that is still in the open service state during the second cycle to obtain the corresponding communication log set.

[0080] The surveying asset storage module stores detailed service information for each candidate open service according to the storage fields of service name, service type, service open duration, service distribution area and service tag, resulting in the surveying details of each candidate open service under different storage fields as shown in Table 1.

[0081] Table 1

[0082]

[0083] The mapping asset storage module acquires service asset information of target open services that are still in an open service state within the second period and generates a request to detect service assets. In response to the service asset detection request triggered by the mapping asset storage module, the bearer network performs real-time detection of the service asset information of target open services that are still in an open service state within the second period. Based on the log storage location recorded in each service asset information, it retrieves the communication log sets generated when providing the corresponding target open service and passes each communication log set to the large model for log integration analysis. Each communication log entry records the traffic transmission process between the target open service and the service requesting end.

[0084] S203: Perform DDoS attack analysis based on the mapping details and communication log sets of each target open service, obtain DDoS attack information and attack information confidence level of each target open service, and issue attack warnings based on DDoS attack information with an attack confidence level not less than the confidence level threshold.

[0085] Establish a seamless connection between the large-scale model and the transport network to enable collaborative data collection and analysis. This allows the large-scale model to perform DDoS attack analysis based on the mapping details and communication log sets of each target open service. For each target open service, the following operations are performed:

[0086] From the mapping details of a target open service, obtain the service open duration of that target open service;

[0087] In the communication log set of the target open service, obtain the communication log entries located between the service open durations, and based on each communication log entry, count the number of response packets sent by the target open service to different service requesters;

[0088] Log analysis is performed on communication log entries with a number of transmissions not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the target open service launching a DDoS attack against the corresponding service requesting end.

[0089] In DDoS attacks, there are instances where open internet services are used as reflection servers. These services are often misconfigured or have protocol characteristics that allow attackers to abuse them, amplifying attack traffic and reflecting it back to the target. Therefore, large-scale models can combine detailed mapping of open internet services with communication log sets to analyze which open internet services have launched DDoS attacks to the service requesting end, and to monitor in real time the geographical distribution and scale of controlled endpoints associated with control endpoints in various locations, enabling precise tracing of DDoS attack chains.

[0090] Establish a connection between the large model and the DDoS attack monitoring system to form a DDoS attack information repository and verification. The large model transmits DDoS attack information to the DDoS attack monitoring system, which stores DDoS attack information with a confidence level not less than the confidence threshold and verifies DDoS attack information with a confidence level less than the confidence threshold.

[0091] In routine DDoS attacks, the same-origin reflection logs, analyzed by a large model, typically yield attack information with a confidence level greater than 100. Therefore, when the attack information confidence level is greater than 80 but less than 100, the associated attack information is considered low-confidence attack information. The large model then calls upon the botnet identified by the DDoS attack monitoring system to further verify whether the low-confidence attack information was triggered by a botnet.

[0092] The specific verification process is as follows: the large model obtains the botnet identified by the DDoS attack monitoring system, then calls the bearer network to query the communication log set of the botnet, and obtains detailed attack information of the botnet by analyzing the communication log set, and passes it as supplementary information to the DDoS attack monitoring system for storage.

[0093] The system establishes seamless connections between the anti-DDoS traffic scrubbing platform, the DDoS attack monitoring system, and the large-scale model, forming a comprehensive DDoS attack monitoring and early warning system. It also establishes connections between the anti-DDoS traffic scrubbing platform and the transport network, enabling automated attack traffic redirection and normal traffic reinjection. The large-scale model transmits attack information to the anti-DDoS traffic scrubbing platform for traffic scrubbing, while the transport network blocks open internet services from sending response packets to the attack target. The anti-DDoS traffic scrubbing platform can perform both fuzzy traffic scrubbing, removing highly overlapping data packets, and precise traffic scrubbing, removing IP addresses identified as botnets and reflection servers.

[0094] Combination Figure 2C The DDoS attack monitoring system performs the following operations to identify botnets on the internet:

[0095] This system achieves seamless collaboration and automation between the DDoS attack monitoring system and the hijacking of botnet protocols, ensuring accurate parsing of hijacking commands. The DDoS attack monitoring system responds to monitoring commands issued by the control node library, hijacking communication between the control end and the controlled end to achieve simulated protocol monitoring. Secondly, it acquires and parses control commands issued by the control end, gaining real-time insights into the DDoS attack task status details of the control end and the IP address of the controlled end. Based on the IP address of the controlled end, a corresponding emulator is deployed, executing control commands and collecting DDoS attack information generated by the simulated DDoS attack in real-time. This information complements the collected DDoS attack task status details from the control end and is then stored in a database. The DDoS attack monitoring system monitors the communication correlation of control ends in an attack state, gaining real-time insights into the botnet information and scale associated with the control end for executing DDoS attacks. This information is also stored in a database, enabling precise tracing of the DDoS attack chain.

[0096] exist Figure 2D The DDoS attack monitoring system shown displays the targets of DDoS attacks over a period of time, the botnets that launched the DDoS attacks, and specific attack information such as the number of botnets, peak values, attack methods, and threat sources. This enables accurate reconstruction of DDoS attack profiles, comprehensive awareness of DDoS attack status, precise tracing of DDoS attack chains, and ultimately, precise blocking of the attack source to curb the generation of DDoS attack traffic.

[0097] like Figure 3 As shown, attackers manipulate multiple botnet clusters through the control terminal, sending DDoS control commands to multiple reflection servers within the clusters to launch a DDoS attack against the DNS server. Big data analytics, based on the mapping details and communication log sets of various open internet services, performs DDoS attack analysis, feeding the analysis results back to the transport network, and collaborating with the transport network to accurately block the source of attacks and curb the generation of DDoS attack traffic.

[0098] The DDoS attack monitoring system monitors DDoS attack behavior and identifies botnets controlled by compromised endpoints to execute attacks. Big data is used to acquire the botnets identified by the DDoS attack monitoring system, and then the network is used to query the communication log sets of these botnets. By analyzing these communication log sets, detailed attack information about the botnets is obtained and transmitted as supplementary information to the DDoS attack monitoring system for storage.

[0099] Establish a seamless connection between the bearer network and the anti-DDoS traffic scrubbing platform to enable automated attack traffic diversion and normal traffic reinjection. Also establish a seamless connection between the DDoS attack monitoring system and the anti-DDoS traffic scrubbing platform to collect DDoS attack information generated by simulated DDoS attacks in real time. This information complements the DDoS attack task status details collected from the control terminal, providing a comprehensive understanding of the DDoS attack status.

[0100] Based on the same inventive concept as the above-described method embodiments, this application also provides a schematic diagram of the structure of a DDoS attack defense device. For example... Figure 4 As shown, the DDoS attack defense device 400 may include:

[0101] The mapping unit 401 is used to perform cyberspace mapping on the Internet, obtain service asset information of each original open service within the first period, and associate the original open services associated with service asset information that hits specific service characteristics as candidate open services.

[0102] The detection unit 402 is used to classify and store the service asset information of each candidate open service to obtain the corresponding mapping details, and to perform bearer network detection on the target open service that is still in the open service state during the second cycle to obtain the corresponding communication log set.

[0103] The early warning unit 403 is used to perform DDoS attack analysis based on the mapping details and communication log sets of each target open service, obtain DDoS attack information and attack information confidence level of each target open service, and issue attack early warning based on DDoS attack information with attack confidence level not less than the confidence level threshold.

[0104] Optionally, the mapping unit 401 is used for:

[0105] Scan all ports and services on the Internet, identify the original open services that support public access within the first period, and obtain the service asset information of each original open service.

[0106] Optionally, the detection unit 402 is used for:

[0107] Based on the storage fields of service name, service type, service open duration, service distribution region, and service tag, the service information of each candidate open service is stored in detail to obtain the mapping details of each candidate open service under different storage fields.

[0108] Optionally, the detection unit 402 is used for:

[0109] Obtain service asset information for target open services that are still in an open service state during the second cycle;

[0110] Based on the log storage location recorded in the information of each service asset, the communication log set generated when providing the corresponding target open service is obtained. Each communication log entry records the traffic transmission process between the target open service and the service requesting end.

[0111] Optionally, the early warning unit 403 provides services for each target and performs the following operations respectively:

[0112] From the mapping details of a target open service, obtain the service open duration of the target open service;

[0113] In the communication log set of the target open service, obtain the communication log entries located between the service open durations, and based on each communication log entry, count the number of response packets sent by the target open service to different service requesters;

[0114] Log analysis is performed on communication log entries with a number of transmissions not less than the response packet threshold to obtain DDoS attack information and attack information confidence level of the target open service launching a DDoS attack against the corresponding service requesting end.

[0115] For ease of description, the above sections are divided into modules (or units) according to their functions and described separately. Of course, in implementing this application, the functions of each module (or unit) can be implemented in one or more software or hardware components.

[0116] Having described the DDoS attack defense method and apparatus according to exemplary embodiments of this application, the following describes a computer device according to another exemplary embodiment of this application.

[0117] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."

[0118] Based on the same inventive concept as the above-described method embodiments, this application also provides a computer device, see below. Figure 5 As shown, the computer device 500 may include at least a processor 501 and a memory 502. The memory 502 stores program code, which, when executed by the processor 501, causes the processor 501 to perform the steps of any of the aforementioned DDoS attack defense methods.

[0119] In some possible implementations, the computing device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps in the DDoS attack defense methods according to the various exemplary embodiments of this application described above. For example, the processor may perform actions such as... Figure 2A The steps are shown in the figure.

[0120] The following reference Figure 6 To describe a computing device 600 according to this embodiment of the present application. Figure 6 The computing device 600 is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0121] like Figure 6 As shown, the computing device 600 is presented in the form of a general-purpose computing device. The components of the computing device 600 may include, but are not limited to: at least one processing unit 601, at least one storage unit 602, and a bus 603 connecting different system components (including storage unit 602 and processing unit 601).

[0122] Bus 603 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or local bus using any of the various bus structures.

[0123] Storage unit 602 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 6021 and / or cache storage unit 6022, and may further include read-only memory (ROM) 6023.

[0124] Storage unit 602 may also include a program / utility 6025 having a set (at least one) of program modules 6024, such program modules 6024 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.

[0125] The computing device 600 can also communicate with one or more external devices 604 (e.g., keyboard, pointing device, etc.), one or more devices that enable a user to interact with the computing device 600, and / or any device that enables the computing device 600 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 605. Furthermore, the computing device 600 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 606. As shown, network adapter 606 communicates with other modules used in the computing device 600 via bus 603. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with the computing device 600, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0126] Based on the same inventive concept as the above-described method embodiments, various aspects of the DDoS attack defense method provided in this application can also be implemented as a program product, which includes program code. When the program product is run on a computer device, the program code is used to cause the computer device to perform the steps in the DDoS attack defense method according to the various exemplary embodiments of this application described above. For example, the computer device can perform actions such as... Figure 2A The steps are shown in the figure.

[0127] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0128] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0129] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A method for defending against DDoS attacks, characterized in that, include: The network space is mapped to obtain the service asset information of each original open service in the first period, and the original open services associated with the service asset information that hits specific service characteristics are used as candidate open services. The service asset information of each candidate open service is classified and stored to obtain the corresponding mapping details. In addition, the service asset information of the target open service that is still in the open service state in the second period is obtained. Based on the log storage location recorded in each service asset information, the communication log set generated when providing the corresponding target open service is obtained. Each communication log entry records the traffic transmission process between the target open service and the service requesting end. For each target open service, the following operations are performed: In the mapping details of a target open service, obtain the service open duration of that target open service; in the communication log set of the target open service, obtain communication log entries located between the service open durations, and based on each communication log entry, count the number of response packets sent by the target open service to different service requesters; perform log analysis on communication log entries whose number of sent response packets is not less than a response packet count threshold to obtain DDoS attack information and attack information confidence level of the target open service launching a DDoS attack against the corresponding service requester; Attack warnings are issued based on DDoS attack information where the attack confidence level is not less than the confidence threshold.

2. The method as described in claim 1, characterized in that, Conduct cyberspace mapping of the Internet to obtain service asset information for each original open service within the first period, including: Scan all ports and services on the Internet, identify the original open services that support public access within the first period, and obtain the service asset information of each original open service.

3. The method as described in claim 1, characterized in that, The service asset information of each candidate open service is classified and stored to obtain the corresponding mapping details, including: Based on the storage fields of service name, service type, service open duration, service distribution region, and service tag, the service information of each candidate open service is stored in detail to obtain the mapping details of each candidate open service under different storage fields.

4. A DDoS attack defense device, characterized in that, include: The surveying and mapping unit is used to conduct cyberspace surveying and mapping of the Internet, obtain the service asset information of each original open service within the first period, and associate the original open services with service asset information that hits specific service characteristics as candidate open services. The detection unit is used to classify and store the service asset information of each candidate open service to obtain the corresponding mapping details, and to obtain the service asset information of the target open service that is still in the open service state in the second period. Based on the log storage location recorded in each service asset information, it obtains the communication log set generated when providing the corresponding target open service. Each communication log entry records the traffic transmission process between the target open service and the service requesting end. The early warning unit is used to perform the following operations for each target open service: obtain the service open duration of the target open service from the mapping details of the target open service; obtain communication log entries located between the service open durations from the communication log set of the target open service, and based on each communication log entry, count the number of response packets sent by the target open service to different service requesters; perform log analysis on communication log entries whose number of sent response packets is not less than a response packet number threshold to obtain DDoS attack information and attack information confidence level of the target open service launching a DDoS attack against the corresponding service requester; Attack warnings are issued based on DDoS attack information where the attack confidence level is not less than the confidence threshold.

5. A computer device, characterized in that, It includes a processor and a memory, wherein the memory stores program code that, when executed by the processor, causes the processor to perform the steps of the method according to any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that, It includes program code that, when run on a computer device, causes the computer device to perform the steps of the method according to any one of claims 1 to 3.

7. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Analytical method for security log based on Apriori algorithm

    CN108255996A

  • DDoS reflection attack defense method, device and apparatus

    CN110661763A