DDoS attack abnormal traffic checking method for network security service
By constructing multiple sequences and coefficients, combined with clustering analysis, the problem of insufficient or excessive threshold settings in the prior art when detecting abnormal traffic of DDoS attacks is solved, which improves the accuracy and sensitivity of detection and reduces the misjudgment rate.
Patent Information
- Application Number
- CN202510465574.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-15
AI Technical Summary
When detecting abnormal traffic of DDoS attacks, it is difficult for the prior art to adapt to complex network environments, resulting in insufficient or excessive threshold settings, affecting detection accuracy and misjudgment rate.
By crawling the source IP address, target IP address, packet length, network protocol and request response time of the data packet, a variety of sequences and coefficients are constructed, including packet length distribution sequence, request number sequence, network protocol proportional sequence, target IP proportional sequence, similarity coefficient, distribution coefficient, flood coefficient and abnormal response coefficient of the data packet, cluster analysis is carried out to troubleshoot the abnormal traffic of DDoS attacks.
It improves the accuracy and sensitivity of abnormal traffic detection of DDoS attacks, reduces the misjudgment rate, enhances the recognition ability of low-speed and slow attacks, and realizes high-sensitive and high-precision DDoS abnormal traffic inspection.
Smart Images

Figure CN119996086A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network measurement technology, and in particular to a method for troubleshooting abnormal traffic of DDoS attacks for network security services. Background Art
[0002] With the rapid development of the Internet and the deepening of digital transformation, network services have become an indispensable part of modern society, and network security threats have become increasingly severe. Among them, DDoS (distributed denial of service) attacks have become one of the most destructive forms of network attacks due to their efficiency and concealment. DDoS attacks use a large number of controlled botnet devices to send excessive requests to the target system, aiming to exhaust its computing resources or bandwidth, resulting in legitimate users being unable to obtain services. Therefore, how to accurately identify and effectively respond to abnormal traffic in DDoS attacks has become the key to ensuring network security services.
[0003] Although there are currently a variety of technical means for detecting abnormal traffic in DDoS attacks, there are still many challenges. In existing solutions, the characteristics of traffic data are often analyzed to determine whether there is abnormal DDoS attack traffic based on whether the change in data characteristics exceeds the threshold. However, this method of setting a fixed threshold is difficult to adapt to the increasingly complex network environment. When the threshold is set to a large value, the detection capability of DDoS attacks will be weak; when the threshold is set to a small value, the probability of misjudging flash events (FE) as DDoS attacks will increase, affecting the normal access of legitimate users; this method of setting thresholds only based on changes in traffic size is also difficult to detect slow and slow attacks. Summary of the invention
[0004] In order to solve the above technical problems, the present application provides a method for troubleshooting abnormal traffic of DDoS attacks for network security services to solve the existing problems.
[0005] The DDoS attack abnormal traffic troubleshooting method for network security services of this application adopts the following technical solutions: An embodiment of the present application provides a method for troubleshooting abnormal traffic of DDoS attacks for network security services, the method comprising the following steps: Capture data packets at each moment, obtain the source IP address, destination IP address, data packet length, network protocol and request response time of the data packet; construct a data packet length distribution sequence at each moment based on the length distribution of the data packets captured at each moment; Based on the number of data packets captured at each moment before each moment, as well as the proportion of various network protocols and target IP addresses of the data packets, the request number sequence, network protocol proportion sequence and target IP proportion sequence of each moment are constructed respectively; the similarity coefficient of the length of the data packet at each moment is calculated based on the similarity between the data packet length distribution sequence at each moment and other moments; based on the difference between the source IP addresses of different data packets at each moment, and the similarity between the source IP addresses of data packets at different moments, the distribution coefficient of the source IP address at each moment is constructed; Based on the trend changes of the similarity coefficient and the distribution coefficient at all moments before each moment, and the similarity between the request quantity sequence, the network protocol proportion sequence and the target IP proportion sequence at each moment, the flooding coefficient at each moment is constructed; Constructing a response time sequence at each moment based on the request response time of the data packets at all moments before each moment; acquiring normal data packets based on the request response time of each data packet, and constructing a normal data packet sequence at each moment; constructing an abnormal response coefficient at each moment based on the data changes in the first-order difference sequence of the request quantity sequence, the response time sequence, and the normal data packet sequence at each moment, combined with the flooding coefficient; Clustering is performed based on the flooding coefficient and the abnormal response coefficient, and abnormal traffic of DDoS attacks is checked based on the clustering result.
[0006] In one embodiment, the process of acquiring the data packet length distribution sequence at each moment is as follows: Each length interval is set according to the length of the data packet, the time interval between adjacent moments is obtained, the number of data packets in each length interval within each time interval is counted, and the sequence composed of the number of data packets in all the length intervals within each time interval is used as the data packet length distribution sequence at the corresponding moment.
[0007] In one embodiment, the process of obtaining the request quantity sequence, network protocol proportion sequence and target IP proportion sequence at each moment is as follows: The number of data packets captured at each moment is recorded as the first number; the sequence composed of the first numbers at the previous i moments is recorded as the request number sequence at the i-th moment; Among all the data packets captured at each moment, the number of data packets with the same network protocol is counted, the proportion of data packets of each network protocol is calculated, and the maximum value of the proportion of data packets of all network protocols at each moment is obtained, which is recorded as the first maximum value; the sequence composed of the first maximum values at the first i moments is recorded as the network protocol proportion sequence at the i-th moment; Based on the target IP addresses of all data packets captured at each moment, the target IP proportion sequence at each moment is obtained by adopting the same acquisition method as the network protocol proportion sequence.
[0008] In one embodiment, the expression of the similarity coefficient of the data packet length at each moment is: , where is the similarity coefficient of the packet length at the i-th moment, , are the packet length distribution sequences at the i-th and j-th moments, respectively. is the function for calculating the Euclidean distance, is the total number of data collection moments.
[0009] In one embodiment, the process of obtaining the distribution coefficient of the source IP address at each moment is as follows: The set of source IP addresses of all data packets captured at each moment is recorded as the source IP address set at each moment; the metric distance between the geographical longitude and latitude coordinates corresponding to any two elements in the source IP address set at each moment is calculated, recorded as the first distance; the average value of all the first distances in the source IP address set at the i-th moment is recorded as ; Calculate the intersection-and-combination ratio between the source IP address set at the ith moment and each moment thereafter, and record the average value of the intersection-and-combination ratio between the ith moment and all moments thereafter as ; The distribution coefficient of the source IP address at the i-th data collection time is recorded as , The expression is: .
[0010] In one embodiment, the process of obtaining the flooding coefficient at each moment is as follows: Record the sequence composed of similarity coefficients of the previous i moments as the similarity coefficient sequence of the i-th moment, use the similarity coefficient sequence as the input of the sequence decomposition algorithm, and output it as the trend sequence of the similarity coefficient sequence; perform straight line fitting on the trend sequence through a linear fitting algorithm, and record the output fitting straight line as the similarity coefficient straight line of the i-th moment; Based on the distribution coefficient of the previous i moments, the distribution coefficient line of the i-th moment is obtained in the same way as the similarity coefficient line; the flooding coefficient of the i-th moment is recorded as , The expression is: , where is the slope of the similarity coefficient line at the i-th moment, is the slope of the distribution coefficient line at the i-th moment, is the similarity between the request quantity sequence and the network protocol proportion sequence at the i-th moment, is the similarity between the sequence of request quantity and the sequence of target IP proportion at the i-th moment, It is an exponential function with the natural constant e as its base.
[0011] In one embodiment, the acquisition process of the response time series at each moment is: Calculate the average value of the request response time of all data packets captured at each moment; record the sequence consisting of the average values of the request response time at the previous i moments as the response time sequence at the i-th moment.
[0012] In one embodiment, the process of acquiring the normal data packet sequence at each moment is as follows: The mean of the request response time of all the collected data packets is used as the segmentation threshold, and the data packets whose request response time is less than the segmentation threshold are regarded as normal data packets. The number of normal data packets in the data packets captured at each moment is obtained; the sequence composed of the number of normal data packets at the first i moments is recorded as the normal data packet sequence at the i-th moment.
[0013] In one embodiment, the process of obtaining the abnormal response coefficient at each moment is as follows: The ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the request quantity sequence at the i-th moment is recorded as , the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the normal data packet sequence at the i-th moment is recorded as , the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the response time series at the i-th moment is recorded as ; The abnormal response coefficient at the i-th moment is recorded as , The expression is: , where is the flooding coefficient at the ith moment.
[0014] In one embodiment, the abnormal traffic investigation of DDoS attack based on the clustering result is specifically as follows: The flooding coefficient and the abnormal response coefficient at each moment are combined to obtain the feature vector at each moment, and the feature vectors at all moments are used as the input of the clustering algorithm and output as clusters; The mean flood coefficient and the mean abnormal response coefficient of all elements in each cluster are calculated, and the cluster with the smallest flood coefficient mean and the smallest abnormal response coefficient mean is taken as the normal cluster, and the time corresponding to each element in the normal cluster is taken as the time when there is no DDoS attack traffic anomaly, and the time corresponding to each element in the remaining clusters except the normal cluster is taken as the time when there is DDoS attack traffic anomaly; if there is no normal cluster, the time corresponding to each element of all clusters is the time when there is DDoS attack traffic anomaly.
[0015] This application has at least the following beneficial effects: The present application calculates the flood coefficient according to the correlation between the number of access requests and the network protocol distribution and the change in the target IP address distribution, combined with the data packet length corresponding to the access request and the source IP address distribution characteristics, which helps to improve the accuracy of flood attack detection and reduce the probability of misjudging FE events as DDoS attacks; then, according to the change trend of the request response time, the abnormal response coefficient is calculated, thereby improving the abnormal identification capability of slow and slow attacks; clustering is performed based on the flood coefficient and the abnormal response coefficient, and DDoS attack abnormal traffic is checked based on the clustering results, so that the judgment standard can be adaptively adjusted according to the actual traffic characteristics, and the changes in the network environment can be responded to in time, thereby enhancing the accuracy and sensitivity of abnormal traffic detection and differentiation, improving the accuracy of abnormal traffic detection of flood attacks, reducing the occurrence of misjudgment of FE events, and enhancing the identification capability of slow and slow attacks, thereby realizing high-sensitivity and high-precision DDoS abnormal traffic checking. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present application or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0017] Figure 1 A flowchart of the method for troubleshooting abnormal traffic of DDoS attacks for network security services provided by this application; Figure 2 Schematic diagram of the process of obtaining the data packet length distribution sequence at each moment. DETAILED DESCRIPTION
[0018] In order to further explain the technical means and effects adopted by the present application to achieve the predetermined invention purpose, the following is a detailed description of the DDoS attack abnormal traffic troubleshooting method for network security services proposed by the present application, its specific implementation method, structure, features and effects, in combination with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.
[0019] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs.
[0020] The specific scheme of the method for troubleshooting abnormal traffic of DDoS attacks for network security services provided by the present application is described in detail below with reference to the accompanying drawings.
[0021] An embodiment of the present application provides a method for troubleshooting abnormal traffic during DDoS attacks for network security services.
[0022] Specifically, the following DDoS attack abnormal traffic troubleshooting methods for network security services are provided. Figure 1 , the method comprises the following steps: Step S1, capture data packets at each moment, obtain the source IP address, destination IP address, data packet length, network protocol and request response time of the data packet; construct a data packet length distribution sequence at each moment based on the length distribution of the data packets captured at each moment.
[0023] By setting a timer, data is collected once every fixed time interval t, data packets are periodically captured, and the Wireshark tool is used to collect the data packets, so that the source IP address, target IP address, data packet length, network protocol, request timestamp and response timestamp in each data packet can be obtained. The difference between the request timestamp and the response timestamp of each data packet is used as the request response time of each data packet. Then the source IP address of each data packet is used as the input of MaxMind, and the output is the geographical longitude and latitude coordinates corresponding to each data packet. Among them, the use of the Wireshark tool and the MaxMind database is a well-known technology, and the specific process is not repeated here. The recommended value range of the time interval t is 30 seconds to 5 minutes. Preferably, the time interval t is set to 1 minute in the embodiment of the present application. As other embodiments of the present application, the implementer can set the time interval t according to the actual situation.
[0024] The data packets collected in each time interval are regarded as the data packets captured at the corresponding data collection moment.
[0025] In actual network traffic transmission, the commonly used data packet lengths are mostly concentrated in the following ranges: small data packets less than 128 bytes are used for control information transmission or lightweight message transmission; data packets from 128 bytes to 1024 bytes are commonly used for activities such as Web browsing and email transmission; data packets greater than 1024 bytes are often used for file downloads, video streaming and other content.
[0026] All data packets collected in each time interval are divided according to the length interval of each data packet. For example, when the length of the data packet is 126, the length interval of the data packet is an interval less than 128 bytes. The number of data packets in each length interval is counted to obtain the number of data packets in each length interval in each data collection time interval; the number of data packets in all length intervals in the same time interval is arranged in ascending order according to the corresponding length of the interval, and the composed sequence is used as the data packet length distribution sequence at the data collection moment corresponding to the time interval.
[0027] It should be noted that only one interval division method is provided in the embodiment of the present application. There are many existing interval division methods. The implementer may also use other interval division methods to divide the data packet. The present application does not make specific restrictions. The more detailed the interval division, the stronger the ability to troubleshoot abnormal data packet length.
[0028] Step S2, based on the number of data packets captured at each moment before each moment, and the proportion of various network protocols and target IP addresses of the data packets, respectively construct the request number sequence, network protocol proportion sequence and target IP proportion sequence at each moment; calculate the similarity coefficient of the data packet length at each moment based on the similarity between the data packet length distribution sequence at each moment and other moments; construct the distribution coefficient of the source IP address at each moment based on the difference between the source IP addresses of different data packets at each moment, and the similarity between the source IP addresses of data packets at different moments.
[0029] With the development of the Internet and digital transformation, various network attack methods emerge in an endless stream, and DDoS attacks, as one of the classic consumption attack methods, still pose a serious threat to network security. Traditional DDoS attack anomaly detection often determines whether there is DDoS attack traffic anomaly by analyzing whether the various characteristic changes in the traffic data exceed the set threshold. The setting of the threshold is a difficult point. In a complex network environment, when the threshold is set to a small value, it is difficult to deal with flash events (FE), resulting in a high probability of misjudgment, which affects the user experience of normal users; when the threshold is set to a large value, the ability of anomaly detection will be weakened, and it will also be difficult to detect slow and slow attacks. In other words, this method cannot take into account the detection of abnormal traffic and the distinction of abnormal traffic at the same time, resulting in a large number of misjudgments or missed judgments. Therefore, a method for troubleshooting abnormal traffic is needed, which can not only realize the detection of abnormal traffic, but also improve the accuracy of abnormal traffic distinction, enhance the ability to identify anomalies for DDoS attacks, FE events, and slow and slow attacks, and thus improve the accuracy and sensitivity of DDoS attack abnormal traffic troubleshooting.
[0030] As one of the most important attack methods in DDoS attacks, flooding attacks are mainly aimed at exhausting the memory or computing resources of the target network, so that it cannot process access requests from normal users. To achieve this goal, attackers usually control proxy machines scattered in different geographical locations through the main control machine to attack, establish a large number of sessions in a short period of time, and send requests to the target network at the same time. Therefore, in this case, a large number of data packets and access requests are often generated in a short period of time; secondly, the length of the generated data packets is also short, and the same network protocol is used to improve the efficiency of the attack; finally, since the proxy machines are often scattered in multiple geographical locations with large differences, the distribution of source IP addresses is wider and more dispersed, and attacking a target network at the same time will also cause the target IP address corresponding to the target network to be requested in large numbers in a short period of time. Under normal circumstances, the distribution of source IPs is relatively small, and the distribution of target IPs is relatively uniform; secondly, since the requirements of each access request are different, the length of the data packet and the network protocol used are also different.
[0031] On the other hand, the main purpose of DDoS attacks is to consume the target's resources (such as bandwidth, CPU, memory, etc.) so that legitimate users cannot obtain services. The resulting abnormal traffic changes are often not instantaneous, but require a certain duration to have a significant impact on the target system. Therefore, attackers often need to maintain high traffic or high request rates for a period of time to ensure that the target resources are fully exhausted. This results in a high similarity in the source IP address distribution and packet length within a period of time when a DDoS attack occurs.
[0032] (1) The number of data packets captured at each data collection moment is recorded as the first number; taking the i-th data collection moment as an example, starting from the data collection start moment, the sequence of the first numbers of the first i data collection moments in ascending time order is recorded as the request number sequence of the i-th data collection moment; wherein, in order to avoid affecting subsequent calculations, in the embodiment of the present application, the value of i is not 1 and , is the total number of data collection moments, that is, the i-th data collection moment is not the first and last data collection moment.
[0033] In the time interval corresponding to each data collection moment, the number of data packets with the same network protocol is counted, recorded as the second number, the ratio of the second number of each network protocol to the number of all data packets in the time interval is calculated, the data packet ratio of each network protocol is obtained, and the maximum value of the data packet ratio of all network protocols in the time interval is obtained, which is recorded as the first maximum value; taking the i-th data collection moment as an example, the sequence composed of the first maximum values corresponding to the first i data collection moments in ascending time order is recorded as the network protocol ratio sequence at the i-th data collection moment; Similarly, in the time interval corresponding to each data collection moment, the number of data packets with the same target IP address is counted, recorded as the third number, and the ratio of the third number of each target IP address to the number of all data packets in the time interval is calculated to obtain the proportion of each target IP address, and the maximum value of the proportion of all types of target IP addresses in each time interval is obtained, recorded as the second maximum value; the sequence composed of the second maximum values corresponding to the first i data collection moments in ascending time order is recorded as the target IP proportion sequence of the i-th data collection moment.
[0034] (2) Taking the i-th data collection moment as an example, the similarity between the data packet length distribution sequence at each moment and every other moment is analyzed. Based on the difference between the similarities in different time periods, the similarity coefficient of the data packet length at each data collection moment is calculated. The expression is: , where is the similarity coefficient of the data packet length at the i-th data collection moment, , are the data packet length distribution sequences at the i-th and j-th data collection moments, respectively. is the function for calculating the Euclidean distance, is the calculation sequence with sequence The Euclidean distance between is the total number of data collection moments.
[0035] When there is no DDoS attack, there is no regularity in the length of the data packets at each moment, so that the Euclidean distances before and after the i-th moment are large, and the corresponding similarity coefficient is small; when a DDoS attack occurs, there will be continuous attacks, and in order to ensure the attack efficiency, the length of the data packets is small, so after the DDoS attack occurs, there will be a certain similarity in the distribution of the length of the data packets at subsequent moments, so that the subsequent Euclidean distances are small, resulting in a large corresponding similarity coefficient.
[0036] (3) Record the set of source IP addresses of all data packets captured at each data collection moment as the source IP address set at that data collection moment; In the source IP address set at each data collection moment, the Euclidean distance between the geographic longitude and latitude coordinates corresponding to any two elements is calculated and recorded as the first distance, and the average value of all the first distances in the source IP address set is recorded as the first mean.
[0037] It should be noted that for the distance measurement between two geographic longitude and latitude coordinates, this application only provides a method for calculating the distance. There are many existing methods for measuring distance. Implementers can also use other distance measurement algorithms to calculate the distance between two geographic longitude and latitude coordinates. This application does not make specific restrictions.
[0038] Taking the i-th data collection moment as an example, the intersection-and-union ratio between the i-th data collection moment and the source IP address set of each subsequent data collection moment is calculated, and the average value of the intersection-and-union ratio between the i-th data collection moment and all subsequent data collection moments is recorded as the second mean. The calculation of the intersection-and-union ratio is a well-known technology, and the specific process is not repeated here.
[0039] Furthermore, according to the distribution of source IP addresses between each moment and the subsequent moment, the distribution coefficient of the source IP address at each data collection moment is calculated, and the expression is: , where is the distribution coefficient of the source IP address at the i-th data collection moment, is the first mean value of the source IP address set at the i-th data collection moment, is the second mean.
[0040] After a DDoS attack occurs, the distribution of source IP addresses of data packets collected in each time interval will be more dispersed, and have a high similarity with the distribution of source IP addresses at subsequent moments, so that the average distance and intersection-combination ratio between any two source IP addresses will be larger, so the distribution coefficient is larger.
[0041] Step S3, constructing the flooding coefficient at each moment based on the trend change of the similarity coefficient and the distribution coefficient at all moments before each moment, and the similarity between the request quantity sequence, network protocol proportion sequence and target IP proportion sequence at each moment.
[0042] Taking the i-th data collection moment as an example, the sequence of similarity coefficients of the first i data collection moments in ascending order of corresponding time is recorded as the similarity coefficient sequence of the i-th data collection moment, and the similarity coefficient sequence is used as the input of the STL (Seasonal and Trend decomposition using Loess) decomposition algorithm, and the output is the trend sequence of the similarity coefficient sequence; the trend sequence is linearly fitted by the least squares method, and the output fitting straight line is recorded as the similarity coefficient straight line of the i-th data collection moment. The STL decomposition algorithm and the least squares linear fitting are both well-known technologies, and the specific process will not be repeated.
[0043] It should be noted that, for the decomposition of trend terms of similarity coefficient sequences and the linear fitting of trend sequences, the present application only provides a sequence decomposition method and a linear fitting method. There are many existing sequence decomposition methods and linear fitting methods. Implementers may also use other sequence decomposition algorithms and linear fitting algorithms to obtain the trend terms of similarity coefficient sequences and to perform linear fitting on trend sequences respectively. The present application does not impose any specific restrictions.
[0044] Furthermore, based on the distribution coefficients at the previous i data collection moments, the distribution coefficient line at the i-th data collection moment is obtained by adopting the same acquisition method as the similarity coefficient line.
[0045] Furthermore, based on the above analysis, the flooding coefficient is calculated to measure the possibility of flooding attacks in DDoS attacks and reduce the probability of misjudging FE events as DDoS attacks.
[0046] , where is the flooding coefficient at the i-th data collection moment, is the slope of the similarity coefficient line at the i-th data collection moment, is the slope of the distribution coefficient line at the i-th data collection moment, is the Pearson correlation coefficient between the request quantity sequence and the network protocol proportion sequence at the i-th data collection moment, is the Pearson correlation coefficient between the request quantity sequence and the target IP ratio sequence at the i-th data collection moment, is an exponential function with the natural constant e as the base. The Pearson correlation coefficient is a well-known technology, and the specific process will not be repeated here.
[0047] It should be noted that for the calculation of the correlation between the request quantity sequence and the network protocol proportion sequence and the correlation between the request quantity sequence and the target IP proportion sequence, the present application only provides a similarity calculation method. There are many existing similarity calculation methods, and implementers may also use other similarity algorithms to calculate the correlation between the request quantity sequence and the network protocol proportion sequence and the correlation between the request quantity sequence and the target IP proportion sequence. The present application does not impose any specific restrictions.
[0048] When a DDoS attack occurs, the similarity coefficient of the packet length will increase as the attack occurs. Similarly, the distribution of the source IP address will also increase, and the similarity between subsequent moments will also increase. Therefore, the similarity coefficient line and the distribution coefficient line are both increasing lines. Secondly, a DDoS attack will cause an increase in the number of network requests for a target IP, and in order to ensure the efficiency of the attack, the same network protocol will be used for the attack. Therefore, the number of requests, the proportion of the target IP attacked, and the proportion of the network protocol used in the attack will all be large, and there is a positive correlation between the three. Therefore, when a DDoS flood attack occurs and causes traffic abnormalities, the flood coefficient is large.
[0049] Step S4, constructing a response time sequence at each moment based on the request response time of the data packets at all moments before each moment; obtaining normal data packets based on the request response time of each data packet, and constructing a normal data packet sequence at each moment; constructing an abnormal response coefficient at each moment based on the data changes in the first-order difference sequence of the request quantity sequence, the response time sequence and the normal data packet sequence at each moment, combined with the flooding coefficient.
[0050] The construction of flood coefficients helps to identify flood attacks in DDoS attacks, thereby enhancing the ability to identify flood attacks and reducing misjudgments of FE events. However, it is still difficult to detect slow and slow attacks in DDoS attacks. Slow and slow attacks are achieved by sending requests and maintaining long-term connections, thereby continuously occupying server resources and consuming server processing power. Conventional slow and slow attack detection is to detect the average response time. When the average response time exceeds the set threshold, it is determined that a slow and slow attack exists. However, this method can also lead to misjudgments, thus affecting the accuracy of detection.
[0051] In fact, in addition to the size of the average response time, the change trend of the average response time is also an important basis for measuring abnormal changes in traffic and determining whether there is a slow attack. When a slow attack occurs, the average response time of the access request will be longer; at the same time, due to the continuous occupation of resources, the number of access requests will show a decreasing trend, and the response time will show a gradually increasing trend; and because the number of access requests gradually decreases, the number of normal access requests will also decrease, so that the proportion of data packets corresponding to normal access requests will show a gradually decreasing trend. However, under normal circumstances, the changes in these characteristics do not have an obvious trend.
[0052] (1) The average value of the request response time of all data packets captured at each data collection moment is recorded as the third mean; the sequence of the third means of the first i data collection moments in ascending order of the corresponding time is recorded as the response time sequence of the i-th data collection moment.
[0053] The mean of the request response time of all the collected data packets is used as the segmentation threshold, and the data packets whose request response time is less than the segmentation threshold are obtained as normal data packets. The number of normal data packets in the data packets captured at each moment is obtained; the sequence composed of the number of normal data packets at the first i data collection moments in ascending time order is recorded as the normal data packet sequence at the i-th data collection moment.
[0054] (2) Furthermore, for each data collection moment, the first-order difference sequences of the request quantity sequence, response time sequence, and normal data packet sequence at that data collection moment are obtained respectively, and the ratio of the number of positive numbers to the number of negative numbers in each first-order difference sequence is calculated as the monotonicity measure of the original sequence corresponding to each first-order difference sequence.
[0055] Based on the above analysis, the abnormal response coefficient is calculated to measure the response of each access request and reduce the occurrence of missed low-speed and slow attacks.
[0056] , where is the abnormal response coefficient at the i-th data collection moment, is the flooding coefficient at the i-th data collection moment, , , are respectively the monotonicity measures of the request quantity sequence, normal data packet sequence and response time sequence at the i-th data collection moment.
[0057] When there is a slow and slow attack, in order to improve concealment, flood attacks are often not launched at the same time, so that the flood coefficient is small; at the same time, the response time will become longer and longer, showing an increasing trend; and the number of data packets and access requests corresponding to normal access requests will become fewer and fewer, showing a decreasing trend, so that the abnormal response coefficient is large. Under normal circumstances, although the flood coefficient is also small, other features do not show a trend change, so that the abnormal response coefficient is small. It should be noted that in some normal access, there may be a situation where the request response time is long, but in this case, it often does not lead to a trend change in other features, so the abnormal response coefficient is also small. The abnormal response coefficient helps to improve the detection accuracy of slow and slow attacks and reduce the occurrence of misjudgments.
[0058] Step S5, clustering is performed based on the flooding coefficient and the abnormal response coefficient, and abnormal traffic of DDoS attack is checked based on the clustering result.
[0059] At the beginning of the visit, the probability of DDoS attack is small, so Starting from the data collection moment, at each data collection moment, the flood coefficient and abnormal response coefficient of each data collection moment are calculated according to the method of steps S2-S4, and the flood coefficient and abnormal response coefficient of each data collection moment are combined to obtain the feature vector of each data collection moment. In order to avoid the calculation overhead when the probability of DDoS attack is relatively small in the early stage and to ensure the accuracy of the anomaly detection of DDoS attack in the later stage, the traffic trend change prediction is set The value range is between [100, 200]. Preferably, in the embodiment of the present application, The value of is set to 100. As other embodiments of the present application, the implementer can set it according to the actual situation. The value of .
[0060] The feature vectors of all data collection moments are used as the input of the K-means clustering algorithm, wherein, preferably, in the embodiment of the present application, the number of clusters is set to 3, and each cluster is output. The K-means clustering algorithm is a well-known technology, and the specific process is not repeated here. It should be noted that the number of clusters can be set according to the actual situation. The larger the number of clusters, the more detailed and sensitive the abnormal detection of traffic flow is. However, it should be noted that when the number of clusters is too large, the division of traffic flow changes is too detailed, which is of little significance for improving the accuracy and sensitivity of traffic anomaly detection. Therefore, the value range of the number of clusters is set to [3,10].
[0061] The mean of the flooding coefficient and the mean of the abnormal response coefficient of all elements in each cluster are calculated respectively. The cluster with the smallest values of both is the normal cluster. There is no DDoS attack traffic anomaly at the time corresponding to each element in this cluster. There is DDoS attack traffic anomaly at the time corresponding to each element in the remaining two clusters. If there is no normal cluster, all clusters are abnormal, that is, there is a large DDoS attack anomaly.
[0062] In this way, when checking for abnormal DDoS attack traffic, the abnormality judgment is no longer based on whether the size of each feature exceeds a fixed threshold. Instead, the accuracy and sensitivity of subsequent abnormal traffic detection are improved by analyzing whether the various feature changes corresponding to the traffic meet the characteristics of a flood attack or a slow and slow attack, based on the mutual influence between the features. At the same time, this method of detecting anomalies based on feature changes and the mutual influence between features avoids misjudging the traffic anomaly caused by FE events as the traffic anomaly caused by DDoS attacks, and also avoids misjudging slow and slow attacks, thereby improving the accuracy and sensitivity of DDoS attack abnormal traffic checking.
[0063] The schematic diagram of the acquisition process of the data packet length distribution sequence at each moment is as follows Figure 2 shown.
[0064] In summary, the embodiment of the present application calculates the flood coefficient according to the correlation between the number of access requests and the network protocol distribution and the change in the target IP address distribution, combined with the data packet length corresponding to the access request and the source IP address distribution characteristics, which helps to improve the accuracy of flood attack detection and reduce the probability of misjudging FE events as DDoS attacks; then, according to the changing trend of the request response time, the abnormal response coefficient is calculated, thereby improving the abnormal identification capability of slow and slow attacks; clustering is performed based on the flood coefficient and the abnormal response coefficient, and DDoS attack abnormal traffic is checked based on the clustering results, so that the judgment standard can be adaptively adjusted according to the actual traffic characteristics, and the changes in the network environment can be responded to in time, thereby enhancing the accuracy and sensitivity of abnormal traffic detection and differentiation, improving the accuracy of abnormal traffic detection of flood attacks, reducing the occurrence of misjudgment of FE events, and enhancing the identification capability of slow and slow attacks, thereby realizing high-sensitivity and high-precision DDoS abnormal traffic checking.
[0065] It should be noted that the above sequence of the embodiments of the present application is only for description and does not represent the advantages and disadvantages of the embodiments. The above describes specific embodiments of the present application. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0066] The various embodiments in the present application are described in a progressive manner, and the same or similar parts between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.
[0067] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Modifications to the technical solutions recorded in the aforementioned embodiments, or equivalent replacement of some of the technical features therein, do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A method for checking abnormal traffic of DDoS attacks for network security services, characterized in that: The method comprises the following steps: Capture data packets at each moment, obtain the source IP address, destination IP address, data packet length, network protocol and request response time of the data packet; construct a data packet length distribution sequence at each moment based on the length distribution of the data packets captured at each moment; Based on the number of data packets captured at each moment before each moment, as well as the proportion of various network protocols and target IP addresses of the data packets, the request number sequence, network protocol proportion sequence and target IP proportion sequence of each moment are constructed respectively; the similarity coefficient of the length of the data packet at each moment is calculated based on the similarity between the data packet length distribution sequence at each moment and other moments; based on the difference between the source IP addresses of different data packets at each moment, and the similarity between the source IP addresses of data packets at different moments, the distribution coefficient of the source IP address at each moment is constructed; Based on the trend changes of the similarity coefficient and the distribution coefficient at all moments before each moment, and the similarity between the request quantity sequence, the network protocol proportion sequence and the target IP proportion sequence at each moment, the flooding coefficient at each moment is constructed; Constructing a response time sequence at each moment based on the request response time of the data packets at all moments before each moment; acquiring normal data packets based on the request response time of each data packet, and constructing a normal data packet sequence at each moment; constructing an abnormal response coefficient at each moment based on the data changes in the first-order difference sequence of the request quantity sequence, the response time sequence, and the normal data packet sequence at each moment, combined with the flooding coefficient; Clustering is performed based on the flooding coefficient and the abnormal response coefficient, and abnormal traffic of DDoS attacks is checked based on the clustering result.
2. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the data packet length distribution sequence at each moment is as follows: Each length interval is set according to the length of the data packet, the time interval between adjacent moments is obtained, the number of data packets in each length interval within each time interval is counted, and the sequence composed of the number of data packets in all the length intervals within each time interval is used as the data packet length distribution sequence at the corresponding moment.
3. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the request quantity sequence, network protocol proportion sequence and target IP proportion sequence at each moment is as follows: The number of data packets captured at each moment is recorded as the first number; the sequence composed of the first numbers at the previous i moments is recorded as the request number sequence at the i-th moment; Among all the data packets captured at each moment, count the number of data packets with the same network protocol, calculate the data packet ratio of each network protocol, obtain the maximum value of the data packet ratio of all network protocols at each moment, and record it as the first maximum value; record the sequence composed of the first maximum values of the previous i moments as the network protocol ratio sequence at the i-th moment; Based on the target IP addresses of all data packets captured at each moment, the target IP proportion sequence at each moment is obtained by adopting the same acquisition method as the network protocol proportion sequence.
4. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The expression of the similarity coefficient of the data packet length at each moment is: , where is the similarity coefficient of the packet length at the i-th moment, , are the packet length distribution sequences at the i-th and j-th moments, respectively. is the function for calculating the Euclidean distance, is the total number of data collection moments.
5. The method for troubleshooting abnormal traffic of DDoS attacks for network security services according to claim 1, characterized in that: The process of obtaining the distribution coefficient of the source IP address at each moment is as follows: The set of source IP addresses of all data packets captured at each moment is recorded as the source IP address set at each moment; the metric distance between the geographical longitude and latitude coordinates corresponding to any two elements in the source IP address set at each moment is calculated, recorded as the first distance; the average value of all the first distances in the source IP address set at the i-th moment is recorded as ; Calculate the intersection-and-combination ratio between the source IP address set at the ith moment and each moment thereafter, and record the average value of the intersection-and-combination ratio between the ith moment and all moments thereafter as ; The distribution coefficient of the source IP address at the i-th data collection time is recorded as , The expression is: .
6. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The process of obtaining the flooding coefficient at each moment is as follows: Record the sequence composed of similarity coefficients of the previous i moments as the similarity coefficient sequence of the i-th moment, use the similarity coefficient sequence as the input of the sequence decomposition algorithm, and output it as the trend sequence of the similarity coefficient sequence; perform straight line fitting on the trend sequence through a linear fitting algorithm, and record the output fitting straight line as the similarity coefficient straight line of the i-th moment; Based on the distribution coefficient of the previous i moments, the distribution coefficient line of the i-th moment is obtained in the same way as the similarity coefficient line; the flooding coefficient of the i-th moment is recorded as , The expression is: , where is the slope of the similarity coefficient line at the i-th moment, is the slope of the distribution coefficient line at the i-th moment, is the similarity between the request quantity sequence and the network protocol proportion sequence at the i-th moment, is the similarity between the sequence of request quantity and the sequence of target IP proportion at the i-th moment, It is an exponential function with the natural constant e as its base.
7. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the response time series at each moment is: Calculate the average value of the request response time of all data packets captured at each moment; record the sequence consisting of the average values of the request response time at the previous i moments as the response time sequence at the i-th moment.
8. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the normal data packet sequence at each moment is as follows: The mean of the request response time of all the collected data packets is used as the segmentation threshold, and the data packets whose request response time is less than the segmentation threshold are regarded as normal data packets. The number of normal data packets in the data packets captured at each moment is obtained; the sequence composed of the number of normal data packets at the first i moments is recorded as the normal data packet sequence at the i-th moment.
9. The method for troubleshooting abnormal traffic of DDoS attacks for network security services according to claim 1, characterized in that: The process of obtaining the abnormal response coefficient at each moment is as follows: The ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the request quantity sequence at the i-th moment is recorded as , the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the normal data packet sequence at the i-th moment is recorded as , the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the response time series at the i-th moment is recorded as ; The abnormal response coefficient at the i-th moment is recorded as , The expression is: , where is the flooding coefficient at the ith moment.
10. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The abnormal traffic investigation of DDoS attack based on the clustering results is specifically as follows: The flooding coefficient and the abnormal response coefficient at each moment are combined to obtain the feature vector at each moment, and the feature vectors at all moments are used as the input of the clustering algorithm and output as clusters; The mean flood coefficient and the mean abnormal response coefficient of all elements in each cluster are calculated, and the cluster with the smallest flood coefficient mean and the smallest abnormal response coefficient mean is taken as the normal cluster, and the time corresponding to each element in the normal cluster is taken as the time when there is no DDoS attack traffic anomaly, and the time corresponding to each element in the remaining clusters except the normal cluster is taken as the time when there is DDoS attack traffic anomaly; if there is no normal cluster, the time corresponding to each element of all clusters is the time when there is DDoS attack traffic anomaly.
Citation Information
Patent Citations
Method for defending distributed denial of service attack of industrial network system
CN114531273A
SYN Flood attack detection and mitigation method based on GCBF
CN119094220A
Link flooding attack cross-layer cooperative defense method and system based on weighted ensemble learning
CN119341966A
Systems and methods for advanced core network controls
US20200021490A1