Method for Detecting Abnormal Traffic of DDoS Attacks for Network Security Services

By constructing a variety of traffic feature sequences, calculating flood coefficients and abnormal response coefficients, combined with clustering analysis, the shortcomings of the existing technology in detecting abnormal traffic of DDoS attacks are solved, and high-precision and high-sensitivity DDoS abnormal traffic inspection are achieved.

CN119996086BActive Publication Date: 2025-06-13SHAANXI SIAN INFORMATION NETWORK SECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510465574.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-06-13
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

When detecting abnormal traffic of DDoS attacks, it is difficult for the prior art to adapt to complex network environments, resulting in insufficient detection capabilities or high misjudgment rates, and it is especially difficult to detect low-speed and slow attacks.

Method used

By crawling the source IP address, target IP address, packet length, network protocol and request response time of the data packet, the packet length distribution sequence, the number of requests, the proportion of network protocols and the proportion of target IPs, the flood coefficient and abnormal response coefficient are calculated, and clustered to troubleshoot the abnormal traffic of the DDoS attack.

Benefits of technology

It improves the accuracy and sensitivity of abnormal traffic detection of DDoS attacks, reduces the misjudgment rate, enhances the recognition ability of low-speed and slow attacks, and realizes high-sensitive and high-precision DDoS abnormal traffic inspection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996086B_ABST
    Figure CN119996086B_ABST
Patent Text Reader

Abstract

This application relates to the field of network measurement technology, and specifically relates to a method for detecting abnormal traffic of DDoS attacks for network security services. The method includes: calculating a flooding coefficient according to the correlation between the number of access requests, the network protocol distribution, and the change in the target IP address distribution, and combining the packet length corresponding to the access request and the source IP address distribution characteristics; calculating an abnormal response coefficient according to the change trend of the request response time and combining the flooding coefficient; performing clustering based on the flooding coefficient and the abnormal response coefficient, and performing detection of abnormal traffic of DDoS attacks based on the clustering result, which enhances the accuracy and sensitivity of abnormal traffic detection and differentiation, improves the accuracy of detecting abnormal traffic of flooding attacks, reduces the occurrence of misjudgment of FE events, and enhances the ability to identify low-speed and slow attacks, thereby realizing high-sensitivity and high-precision detection of DDoS abnormal traffic.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network measurement technology, and specifically to a method for detecting abnormal traffic in DDoS attacks for network security services. Background Art

[0002] With the rapid development of the Internet and the deepening of digital transformation, network services have become an indispensable part of modern society, and network security threats have become increasingly severe. Among them, DDoS (Distributed Denial of Service) attacks have become one of the most destructive network attack forms due to their high efficiency and concealment. DDoS attacks send an excessive amount of requests to the target system by using a large number of controlled botnet devices, aiming to exhaust its computing resources or bandwidth, resulting in legitimate users being unable to obtain services. Therefore, how to accurately identify and effectively respond to abnormal traffic in DDoS attacks has become the key to ensuring network security services.

[0003] Although there are currently various technical means for detecting abnormal traffic in DDoS attacks, many challenges still remain. In existing solutions, it is often to analyze the characteristics of traffic data and determine whether there is abnormal DDoS attack traffic based on whether the change in data characteristics exceeds a threshold. However, this way of setting a fixed threshold is difficult to adapt to the increasingly complex network environment. When the threshold is set large, the detection ability for DDoS attacks will be weak; when the threshold is set small, the probability of misjudging flash events (FE) as DDoS attacks will increase, affecting the normal access of legitimate users; this way of setting the threshold only based on the change in traffic size is also difficult to detect low-speed slow attacks. Summary of the Invention

[0004] To solve the above technical problems, this application provides a method for detecting abnormal traffic in DDoS attacks for network security services to solve existing problems.

[0005] The method for detecting abnormal traffic in DDoS attacks for network security services of this application adopts the following technical solutions:

[0006] An embodiment of this application provides a method for detecting abnormal traffic in DDoS attacks for network security services, and this method includes the following steps:

[0007] Capture data packets at each moment, obtain the source IP address, target IP address, data packet length, network protocol, and request response time of the data packets; construct a data packet length distribution sequence for each moment based on the length distribution of the data packets captured at each moment;

[0008] Based on the number of data packets captured at each moment before each moment, as well as the proportion of various network protocols and target IP addresses of the data packets, construct the request quantity sequence, network protocol proportion sequence, and target IP proportion sequence for each moment respectively; calculate the similarity coefficient of the data packet length for each moment based on the similarity between the data packet length distribution sequences of each moment and other moments; construct the distribution coefficient of the source IP address for each moment based on the differences between the source IP addresses of different data packets at each moment and the similarity between the source IP addresses of the data packets at different moments;

[0009] Based on the trend changes of the similarity coefficient and the distribution coefficient at all moments before each moment, as well as the similarity between the request quantity sequence, network protocol proportion sequence, and target IP proportion sequence at each moment, construct the flooding coefficient for each moment;

[0010] Construct the response time sequence for each moment based on the request response time of the data packets at all moments before each moment; obtain the normal data packets based on the request response time of each data packet, and construct the normal data packet sequence for each moment; based on the data changes in the first-order difference sequences of the request quantity sequence, response time sequence, and normal data packet sequence at each moment, and in combination with the flooding coefficient, construct the abnormal response coefficient for each moment;

[0011] Perform clustering based on the flooding coefficient and the abnormal response coefficient, and conduct a DDoS attack abnormal traffic investigation based on the clustering results.

[0012] In one embodiment, the process of obtaining the data packet length distribution sequence for each moment is as follows:

[0013] Set each length interval according to the data packet length, obtain the time interval between adjacent moments, count the number of data packets in each length interval within each time interval, and use the sequence composed of the number of data packets in all the length intervals within each time interval as the data packet length distribution sequence corresponding to the moment.

[0014] In one embodiment, the process of obtaining the request quantity sequence, network protocol proportion sequence, and target IP proportion sequence for each moment is as follows:

[0015] Record the number of data packets captured at each moment as the first quantity; record the sequence composed of the first quantity at the first i moments as the request quantity sequence at the i-th moment;

[0016] Among all the data packets captured at each moment, count the number of data packets with the same network protocol, calculate the proportion of the data packets of each network protocol, obtain the maximum value of the proportion of the data packets of all network protocols at each moment, and record it as the first maximum value; record the sequence composed of the first maximum value at the first i moments as the network protocol proportion sequence at the i-th moment;

[0017] Based on the destination IP addresses of all the data packets captured at each moment, and adopting the same acquisition method as that of the network protocol ratio sequence, the destination IP ratio sequence at each moment is obtained.

[0018] In one embodiment, the expression of the similarity coefficient of the data packet lengths at each moment is:

[0019] , where is the similarity coefficient of the data packet length at the i-th moment, , are respectively the data packet length distribution sequences at the i-th and j-th moments, is the function for calculating the Euclidean distance, is the total number of data acquisition moments.

[0020] In one embodiment, the process for obtaining the distribution coefficient of the source IP address at each moment is as follows:

[0021] Denote the set composed of the source IP addresses of all the data packets captured at each moment as the source IP address set at each moment; calculate the metric distance between the geographical longitude and latitude coordinates corresponding to any two elements in the source IP address set at each moment, and denote it as the first distance; denote the average value of all the first distances in the source IP address set at the i-th moment as ;

[0022] Calculate the intersection-union ratio between the source IP address set at the i-th moment and the source IP address sets at each subsequent moment, and denote the average value of the intersection-union ratios between the i-th moment and all subsequent moments as ;

[0023] Denote the distribution coefficient of the source IP address at the i-th data acquisition moment as , The expression of is:

[0024] In one embodiment, the process for obtaining the flooding coefficient at each moment is as follows:

[0025] Denote the sequence composed of the similarity coefficients of the first i moments as the similarity coefficient sequence at the i-th moment, use the similarity coefficient sequence as the input of the sequence decomposition algorithm, and the output is the trend sequence of the similarity coefficient sequence; perform linear fitting on the trend sequence through the linear fitting algorithm, and denote the output fitting straight line as the similarity coefficient straight line at the i-th moment;

[0026] Based on the distribution coefficients of the first i moments, adopt the same acquisition method as that of the similarity coefficient straight line to obtain the distribution coefficient straight line at the i-th moment; denote the flooding coefficient at the i-th moment as , The expression of

[0027] is: is the slope of the similarity coefficient line at the i-th moment, is the slope of the distribution coefficient line at the i-th moment, is the similarity between the request quantity sequence and the network protocol proportion sequence at the i-th moment, is the similarity between the request quantity sequence and the target IP proportion sequence at the i-th moment, is the exponential function with the natural constant e as the base.

[0028] In one embodiment, the process of obtaining the response time sequence at each moment is as follows:

[0029] Calculate the average value of the request response times of all the data packets captured at each moment; Denote the sequence composed of the average values of the request response times at the previous i moments as the response time sequence at the i-th moment.

[0030] In one embodiment, the process of obtaining the normal data packet sequence at each moment is as follows:

[0031] Take the average value of the request response times of all the collected data packets as the segmentation threshold, regard the data packets with request response times less than the segmentation threshold as normal data packets, and obtain the number of normal data packets in the data packets captured at each moment; Denote the sequence composed of the number of normal data packets at the previous i moments as the normal data packet sequence at the i-th moment.

[0032] In one embodiment, the process of obtaining the abnormal response coefficient at each moment is as follows:

[0033] Denote the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the request quantity sequence at the i-th moment as Denote the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the normal data packet sequence at the i-th moment as Denote the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the response time sequence at the i-th moment as ; Denote the abnormal response coefficient at the i-th moment as , The expression of is: is the flooding coefficient at the i-th moment.

[0034] In one embodiment, the DDoS attack abnormal traffic troubleshooting based on the clustering result is specifically as follows:

[0035] Combine the flooding coefficient and the abnormal response coefficient at each moment to obtain the feature vector at each moment, and use the feature vectors at all moments as the input of the clustering algorithm, with the output being each clustering cluster;

[0036] Calculate the average value of the flooding coefficients and the average value of the abnormal response coefficients of all elements in each clustering cluster. Take the clustering cluster with the minimum of both the average value of the flooding coefficients and the average value of the abnormal response coefficients as the normal clustering cluster. Take the moments corresponding to the elements in the normal clustering cluster as the moments when there is no abnormal DDoS attack traffic. Take the moments corresponding to the elements in the remaining clustering clusters except the normal clustering cluster as the moments when there is abnormal DDoS attack traffic; if there is no such normal clustering cluster, then the moments corresponding to the elements in all clustering clusters are the moments when there is abnormal DDoS attack traffic.

[0037] The present application has at least the following beneficial effects:

[0038] Based on the correlation between the number of access requests, the network protocol distribution, and the change in the target IP address distribution, combined with the packet length corresponding to the access request and the source IP address distribution characteristics, the present application calculates the flooding coefficient, which helps to improve the accuracy of flood attack detection and reduce the probability of misjudging FE events as DDoS attacks; then, according to the change trend of the request response time, the abnormal response coefficient is calculated, improving the abnormal recognition ability for low-speed and slow attacks; clustering is performed based on the flooding coefficient and the abnormal response coefficient, and DDoS attack abnormal traffic is investigated based on the clustering result, so that the judgment criteria can be adaptively adjusted according to the actual traffic characteristics, timely respond to the changes in the network environment, enhance the accuracy and sensitivity of abnormal traffic detection and differentiation, improve the accuracy of flood attack abnormal traffic detection, reduce the occurrence of misjudgment of FE events, and enhance the recognition ability for low-speed and slow attacks, thus realizing high-sensitivity and high-precision DDoS abnormal traffic investigation. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] To more clearly illustrate the technical solutions and advantages in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0040] Figure 1 It is a flowchart of the method for investigating DDoS attack abnormal traffic for network security services provided by the present application;

[0041] Figure 2 It is a schematic diagram of the acquisition process of the packet length distribution sequence at each moment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0042] In order to further elaborate on the technical means and effects adopted by this application to achieve the intended invention purpose, the following will, in conjunction with the accompanying drawings and preferred embodiments, elaborate in detail on the specific implementation manner, structure, features and effects of the DDoS attack abnormal traffic detection method for network security services proposed according to this application. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs.

[0044] The following will specifically describe the specific solution of the DDoS attack abnormal traffic detection method for network security services provided by this application in conjunction with the accompanying drawings.

[0045] A DDoS attack abnormal traffic detection method for network security services provided by an embodiment of this application.

[0046] Specifically, the following DDoS attack abnormal traffic detection method for network security services is provided. Please refer to Figure 1 , and this method includes the following steps:

[0047] Step S1, capture data packets at each moment, obtain the source IP address, destination IP address, data packet length, network protocol and request response time of the data packets; construct a data packet length distribution sequence at each moment based on the length distribution of the data packets captured at each moment.

[0048] By setting a timer, data is collected once every fixed time interval t, data packets are captured periodically, and the Wireshark tool is used to collect the data packets, so that the source IP address, destination IP address, data packet length, network protocol, request timestamp and response timestamp in each data packet can be obtained. The difference between the request timestamp and the response timestamp of each data packet is used as the request response time of each data packet. Then, the source IP address of each data packet is used as the input of MaxMind, and the output is the geographical longitude and latitude coordinates corresponding to each data packet. The use of the Wireshark tool and the MaxMind database is a well-known technology, and the specific process will not be elaborated here. The recommended value range of the time interval t is 30 seconds to 5 minutes. Preferably, in the embodiment of this application, the time interval t is set to 1 minute. As other embodiments of this application, the implementer can set the time interval t according to the actual situation.

[0049] The data packets collected within each time interval are used as the data packets captured at the corresponding data collection moment.

[0050] In actual network traffic transmission, the lengths of commonly used data packets mostly concentrate in the following intervals: small data packets with a length less than 128 bytes, which are used for control information transmission or lightweight message transmission; data packets with a length from 128 bytes to 1024 bytes, which are commonly used in activities such as Web browsing and email transmission; data packets with a length greater than 1024 bytes, which are commonly used for content such as file downloads and video streaming.

[0051] For all the data packets collected within each time interval, divide the data packets according to the length interval where each data packet's length is located. For example, when the length of the data packet is 126, the length interval where the data packet is located is the interval less than 128 bytes. Count the number of data packets in each length interval, so as to obtain the number of data packets in each length interval within each data collection time interval; arrange the number of data packets in all length intervals within the same time interval in ascending order according to the corresponding length of the interval, and the formed sequence is used as the data packet length distribution sequence at the data collection moment corresponding to this time interval.

[0052] It should be noted that only one interval division method is provided in the embodiments of this application. There are many existing interval division methods, and implementers can also use other interval division methods to divide the data packets. This application does not make specific restrictions. The more detailed the interval division is, the stronger the ability to detect abnormal data packet lengths will be.

[0053] Step S2: Based on the number of data packets captured at each moment before each moment, as well as the proportion of various network protocols and target IP addresses of the data packets, construct a request number sequence, a network protocol proportion sequence, and a target IP proportion sequence for each moment respectively; calculate the similarity coefficient of the data packet lengths at each moment based on the similarity between the data packet length distribution sequences at each moment and those at other moments; construct a distribution coefficient of the source IP addresses at each moment based on the differences between the source IP addresses of different data packets at each moment and the similarity of the source IP addresses of the data packets at different moments.

[0054] With the development of the Internet and digital transformation, various network attack methods emerge in an endless stream. As one of the classic consumption attack methods, DDoS attacks still pose a serious threat to network security. Traditional DDoS attack anomaly detection often judges whether there is abnormal DDoS attack traffic by analyzing whether various feature changes in traffic data exceed the set threshold. The setting of the threshold is a difficult point. In a complex network environment, when the threshold is set too small, it is difficult to cope with flash events (FE), resulting in a relatively high misjudgment probability and affecting the usage experience of normal users. When the threshold is set too large, the anomaly detection ability will be weakened, and it is also difficult to detect slow and low-speed attacks. That is to say, this method cannot take into account both the detection of abnormal traffic and the differentiation of abnormal traffic, resulting in a relatively large number of misjudgments or missed judgments. Therefore, an abnormal traffic investigation method is needed, which can not only detect abnormal traffic, but also improve the accuracy of abnormal traffic differentiation, enhance the abnormal recognition ability for DDoS attacks, FE events, and slow and low-speed attacks, and then improve the accuracy and sensitivity of DDoS attack abnormal traffic investigation.

[0055] As one of the main attack methods in DDoS attacks, the main purpose of flooding attacks is to exhaust the memory or computing resources of the target network, so that it cannot process access requests from normal users. To achieve this goal, attackers usually control proxy machines scattered in different geographical locations through a master control machine to launch attacks, establish a large number of sessions in a short time, and send requests to the target network at the same time. Therefore, in this case, a large number of data packets and access requests are often generated in a short time. Secondly, the length of the generated data packets is also short, and the same network protocol is used to improve the attack efficiency. Finally, since the proxy machines are often scattered in multiple geographical locations with large differences, the distribution of source IP addresses is wider and more dispersed. At the same time, attacking a target network will also cause the target IP address corresponding to the target network to be requested a large number of times in a short time. Under normal circumstances, the distribution range of source IPs is relatively small, and the distribution of target IPs is also relatively uniform. Secondly, due to the different requirements of each access request, the length of the data packets and the network protocols used are also different.

[0056] On the other hand, the main purpose of DDoS attacks is to consume the resources of the target (such as bandwidth, CPU, memory, etc.), so that legitimate users cannot obtain services. Therefore, the resulting abnormal traffic changes are often not instantaneous, but require a certain duration to have a significant impact on the target system. So attackers often need to maintain a high traffic or high request rate for a period of time to ensure that the target resources are fully exhausted. This leads to a high similarity in the characteristics such as the distribution of source IP addresses and the length of data packets within a certain period of time when a DDoS attack occurs.

[0057] (1) Denote the number of data packets captured at each data collection moment as the first quantity; taking the \(i\) -th data collection moment as an example, starting from the data collection start moment, the sequence formed by arranging the first quantities of the first \(i\) data collection moments in ascending order of time is denoted as the request quantity sequence at the \(i\) -th data collection moment; among them, to avoid affecting subsequent calculations, in the embodiments of the present application, the value of \(i\) is not 1 and , is the total number of data collection moments, that is, the \(i\) -th data collection moment is not the first and the last data collection moments.

[0058] Within the time interval corresponding to each data collection moment, count the number of data packets with the same network protocol, denoted as the second quantity, calculate the ratio of the second quantity of each network protocol to the number of all data packets within this time interval, obtain the packet proportion of each network protocol, and obtain the maximum value of the packet proportions of all network protocols within this time interval, denoted as the first maximum value; taking the \(i\) -th data collection moment as an example, the sequence formed by arranging the first maximum values corresponding to the first \(i\) data collection moments in ascending order of time is denoted as the network protocol proportion sequence at the \(i\) -th data collection moment;

[0059] Similarly, within the time interval corresponding to each data collection moment, count the number of data packets with the same target IP address, denoted as the third quantity, calculate the ratio of the third quantity of each target IP address to the number of all data packets within this time interval, obtain the proportion of each target IP address, and obtain the maximum value of the proportions of all target IP addresses within each time interval, denoted as the second maximum value; the sequence formed by arranging the second maximum values corresponding to the first \(i\) data collection moments in ascending order of time is denoted as the target IP proportion sequence at the \(i\) -th data collection moment.

[0060] (2) Taking the \(i\) -th data collection moment as an example, analyze the similarity between the packet length distribution sequences at each moment and those at each other moment, and calculate the similarity coefficient of the packet lengths at each data collection moment based on the differences between the similarities in different time periods. The expression is:

[0061] , where in the formula, is the similarity coefficient of the packet lengths at the \(i\) -th data collection moment, , are respectively the packet length distribution sequences at the \(i\) -th and \(j\) -th data collection moments, is the function for calculating the Euclidean distance, is to calculate the between the sequence and the sequence is the total number of data collection moments.

[0062] When there is no DDoS attack, the lengths of data packets at each moment are irregular, resulting in relatively large Euclidean distances before and after the i-th moment, and thus relatively small similarity coefficients. When a DDoS attack occurs, there will be a continuous attack, and to ensure the attack efficiency, the lengths of data packets are relatively small. Therefore, after a DDoS attack occurs, there is a certain similarity in the distribution of data packet lengths at subsequent moments, resulting in relatively small Euclidean distances and relatively large corresponding similarity coefficients.

[0063] (3) Denote the set composed of the source IP addresses of all data packets captured at each data collection moment as the source IP address set at that data collection moment;

[0064] In the source IP address set at each data collection moment, calculate the Euclidean distance between the geographical longitude and latitude coordinates corresponding to any two elements, denoted as the first distance, and denote the average value of all the first distances in the source IP address set as the first mean value.

[0065] It should be noted that for the distance measurement between two geographical longitude and latitude coordinates, this application only provides a method for calculating the distance. There are many existing methods for measuring distances, and implementers can also use other distance measurement algorithms to calculate the distance between two geographical longitude and latitude coordinates. This application does not make specific restrictions.

[0066] Taking the i-th data collection moment as an example, calculate the intersection-union ratio between the source IP address set at the i-th data collection moment and the source IP address sets at each subsequent data collection moment, and denote the average value of the intersection-union ratios between the source IP address set at the i-th data collection moment and all subsequent data collection moments as the second mean value. Among them, the calculation of the intersection-union ratio is a well-known technology, and the specific process will not be elaborated here.

[0067] Further, according to the distribution of source IP addresses between each moment and subsequent moments, calculate the distribution coefficient of the source IP addresses at each data collection moment. The expression is:

[0068] , where in the formula, is the distribution coefficient of the source IP addresses at the i-th data collection moment, is the first mean value of the source IP address set at the i-th data collection moment, is the second mean value.

[0069] After a DDoS attack occurs, the distribution of the source IP addresses of the data packets collected within each time interval will be relatively dispersed, and has a high similarity with the distribution of the source IP addresses at subsequent moments, resulting in relatively large average distances and intersection-union ratios between any two source IP addresses, so the distribution coefficient is relatively large.

[0070] Step S3: Based on the trend changes of the similarity coefficients and the distribution coefficients at all previous moments, as well as the similarities among the request quantity sequences, network protocol proportion sequences, and target IP proportion sequences at each moment, construct the flood coefficients at each moment.

[0071] Taking the i-th data collection moment as an example, denote the sequence formed by arranging the similarity coefficients at the previous i data collection moments in ascending order of corresponding time as the similarity coefficient sequence at the i-th data collection moment. Use this similarity coefficient sequence as the input of the STL (Seasonal and Trend decomposition using Loess) decomposition algorithm, and the output is the trend sequence of this similarity coefficient sequence. Fit the trend sequence by the least squares method, and the output fitted straight line is denoted as the similarity coefficient straight line at the i-th data collection moment. Both the STL decomposition algorithm and the least squares method straight line fitting are well-known technologies, and the specific processes will not be elaborated here.

[0072] It should be noted that for the trend term decomposition of the similarity coefficient sequence and the linear fitting of the trend sequence, this application only provides a sequence decomposition method and a linear fitting method. There are many existing sequence decomposition methods and linear fitting methods, and implementers can also use other sequence decomposition algorithms and linear fitting algorithms to respectively obtain the trend terms of the similarity coefficient sequence and perform linear fitting on the trend sequence. This application does not make specific restrictions.

[0073] Furthermore, based on the distribution coefficients at the previous i data collection moments, use the same acquisition method as the similarity coefficient straight line to obtain the distribution coefficient straight line at the i-th data collection moment.

[0074] Furthermore, based on the above analysis, calculate the flood coefficient, which is used to measure the possibility of flood attacks occurring in DDoS attacks and reduce the probability of misjudging FE events as DDoS attacks.

[0075] , where is the flood coefficient at the i-th data collection moment, is the slope of the similarity coefficient straight line at the i-th data collection moment, is the slope of the distribution coefficient straight line at the i-th data collection moment, is the Pearson correlation coefficient between the request quantity sequence and the network protocol proportion sequence at the i-th data collection moment, is the Pearson correlation coefficient between the request quantity sequence and the target IP proportion sequence at the i-th data collection moment, is the exponential function with the natural constant e as the base. Among them, the Pearson correlation coefficient is a well-known technology, and the specific process will not be elaborated here.

[0076] It should be noted that for the calculation of the correlation between the request quantity sequence and the network protocol ratio sequence and the correlation between the request quantity sequence and the target IP ratio sequence, this application only provides a similarity calculation method. There are many existing similarity calculation methods, and implementers can also use other similarity algorithms to calculate the correlation between the request quantity sequence and the network protocol ratio sequence and the correlation between the request quantity sequence and the target IP ratio sequence. This application does not make specific restrictions.

[0077] During a DDoS attack, the similarity coefficient of the packet length will increase as the attack occurs. Similarly, the distribution of the source IP addresses will also increase, and the similarity with subsequent moments will also be higher. Therefore, both the similarity coefficient line and the distribution coefficient line are increasing lines. Secondly, a DDoS attack will cause an increase in the number of network requests for a target IP, and in order to ensure the attack efficiency, the same network protocol will be used for the attack. Therefore, the request quantity, the ratio of the attacked target IP, and the ratio of the network protocol used for the attack will all be relatively large, and there is a positive correlation among the three. Therefore, when a DDoS flood attack causes traffic anomalies, the flood coefficient is relatively large.

[0078] Step S4: Based on the request response times of the packets at all previous moments, construct the response time sequence for each moment; based on the request response times of each packet, obtain the normal packets and construct the normal packet sequence for each moment; based on the data changes in the first-order difference sequences of the request quantity sequence, response time sequence, and normal packet sequence at each moment, and in combination with the flood coefficient, construct the abnormal response coefficient for each moment.

[0079] The construction of the flood coefficient helps to identify the flood attack in a DDoS attack, thereby enhancing the ability to identify the flood attack and reducing the misjudgment of FE events. However, it is still difficult to detect the slow and low-speed attacks in a DDoS attack. Slow and low-speed attacks achieve the purpose of continuously occupying server resources and consuming server processing capabilities by sending requests and maintaining long-term connections. Conventional slow and low-speed attack detection is to detect the average response duration. When the average response duration exceeds the set threshold, it is determined that there is a slow and low-speed attack. However, this method will also cause misjudgment, thus affecting the accuracy of detection.

[0080] In fact, in addition to the magnitude of the average response time, the trend of the average response time is also an important basis for measuring abnormal traffic changes and determining whether there is a slowloris attack. During a slowloris attack, the average response time of access requests will be relatively large. At the same time, due to the continuous resource occupation, the number of access requests will show a decreasing trend, and the response time will show a gradually increasing trend. Moreover, since the number of access requests is gradually decreasing, the number of normal access requests will also become fewer and fewer, resulting in a gradually decreasing trend in the proportion of data packets corresponding to normal access requests. However, under normal circumstances, the changes in these characteristics do not have an obvious trend.

[0081] (1) Denote the average value of the request response times of all data packets captured at each data collection moment as the third mean value; denote the sequence formed by arranging the third mean values of the first i data collection moments in ascending order of the corresponding time as the response time sequence at the i-th data collection moment.

[0082] Take the mean value of the request response times of all collected data packets as the segmentation threshold, obtain the data packets with request response times less than the segmentation threshold as normal data packets, and obtain the number of normal data packets in the data packets captured at each moment; denote the sequence formed by arranging the number of normal data packets of the first i data collection moments in ascending order of time as the normal data packet sequence at the i-th data collection moment.

[0083] (2) Further, for each data collection moment, respectively obtain the first-order difference sequences of the request number sequence, response time sequence, and normal data packet sequence at this data collection moment, and calculate the ratio of the number of positive numbers to the number of negative numbers in each first-order difference sequence as the monotonicity measure of the original sequence corresponding to each first-order difference sequence.

[0084] Based on the above analysis, calculate the abnormal response coefficient to measure the response situation of each access request and reduce the occurrence of missed judgments of slowloris attacks.

[0085] , where is the abnormal response coefficient at the i-th data collection moment, is the flooding coefficient at the i-th data collection moment, 、 、 are the monotonicity measures of the request number sequence, normal data packet sequence, and response time sequence at the i-th data collection moment, respectively.

[0086] When there is a low-speed slow attack, in order to improve concealment, a flood attack is often not launched simultaneously, resulting in a small flood coefficient; at the same time, the response time will become longer and longer, showing an increasing trend; while the number of data packets and access requests corresponding to normal access requests will become fewer and fewer, showing a decreasing trend, resulting in a large abnormal response coefficient. Under normal circumstances, although the flood coefficient is also small, other features will not show a trend change, resulting in a small abnormal response coefficient. It should be noted that in some normal accesses, there may be a situation where the request response time is long, but in this case, it usually does not lead to a trend change in other features, so the abnormal response coefficient is also small. The abnormal response coefficient helps to improve the detection accuracy of low-speed slow attacks and reduce the occurrence of misjudgment situations.

[0087] Step S5: Cluster based on the flood coefficient and the abnormal response coefficient, and conduct a DDoS attack abnormal traffic investigation based on the clustering result.

[0088] At the beginning of the access, the probability of a DDoS attack is small. Therefore, starting from the th data collection moment, at each data collection moment, calculate the flood coefficient and the abnormal response coefficient in the manner of steps S2 - S4 respectively, and combine the flood coefficient and the abnormal response coefficient at each data collection moment to obtain the feature vector at each data collection moment. Among them, in order to avoid the computational overhead when the probability of a DDoS attack is small in the early stage and ensure the accuracy of the prediction of the DDoS attack abnormal detection and the traffic trend change in the later stage, it is set that the value range is between [100, 200]. Preferably, in the embodiment of the present application, the value of is set to 100. As other embodiments of the present application, the implementer can set the value of according to the actual situation.

[0089] Take the feature vectors at all data collection moments as the input of the K-means clustering algorithm. Among them, preferably, in the embodiment of the present application, the number of clustering clusters is set to 3, and each clustering cluster is output. Among them, the K-means clustering algorithm is a well-known technology, and the specific process will not be elaborated. It should be noted that the number of clustering clusters can be set according to the actual situation. The larger the value of the number of clustering clusters, the more detailed and sensitive the abnormal detection of the traffic is. However, it should be noted that when the value of the number of clustering clusters is too large, the division of the traffic change is too detailed, and the significance of improving the accuracy and sensitivity of the traffic abnormal detection is small. Therefore, the value range of the number of clustering clusters is set to [3, 10].

[0090] Calculate the mean of the flooding coefficients and the mean of the abnormal response coefficients for all elements in each cluster respectively. The cluster with the smallest values for both is the normal cluster, and there is no abnormal DDoS attack traffic at the moments corresponding to the elements in this cluster. There is abnormal DDoS attack traffic at the moments corresponding to the elements in the remaining two clusters. If there is no normal cluster, then all clusters are abnormal, indicating a significant DDoS attack anomaly.

[0091] In this way, when troubleshooting abnormal DDoS attack traffic, instead of making abnormal judgments based on whether the magnitudes of various features exceed a fixed threshold, it analyzes whether the changes in various features corresponding to the traffic conform to the characteristics of flooding attacks or slow-speed attacks, and based on the mutual influence between the features, thereby improving the accuracy and sensitivity of subsequent abnormal traffic detection. At the same time, this method of detecting abnormalities based on feature changes and the mutual influence between features avoids misjudging traffic abnormalities caused by FE events as those caused by DDoS attacks, and also avoids misjudging slow-speed attacks, thus improving the accuracy and sensitivity of DDoS attack abnormal traffic troubleshooting.

[0092] The schematic diagram of the acquisition process of the packet length distribution sequence at each moment is as Figure 2 shown.

[0093] In summary, the embodiment of the present application calculates the flooding coefficient based on the correlation between the number of access requests, the network protocol distribution, and the change in the target IP address distribution, combined with the packet length and source IP address distribution characteristics corresponding to the access requests, which helps to improve the accuracy of detecting flooding attacks and reduce the probability of misjudging FE events as DDoS attacks. Then, according to the change trend of the request response time, the abnormal response coefficient is calculated, improving the ability to identify abnormalities in slow-speed attacks. Clustering is performed based on the flooding coefficient and the abnormal response coefficient, and DDoS attack abnormal traffic troubleshooting is carried out based on the clustering results. Thus, it can adaptively adjust the judgment criteria according to the actual traffic characteristics, respond in a timely manner to changes in the network environment, enhance the accuracy and sensitivity of abnormal traffic detection and differentiation, improve the accuracy of detecting abnormal flooding attack traffic, reduce the occurrence of misjudgment of FE events, and enhance the ability to identify slow-speed attacks, thereby achieving high-sensitivity and high-precision DDoS abnormal traffic troubleshooting.

[0094] It should be noted that: the above sequence of embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above specific embodiments of the present application have been described. Additionally, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be beneficial.

[0095] Each embodiment in the present application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments.

[0096] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Modifying the technical solutions recorded in the foregoing embodiments, or equivalently replacing some of the technical features, does not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of each embodiment of the present application, and should all be included within the protection scope of the present application.

Claims

1. A method for checking abnormal traffic of DDoS attacks for network security services, characterized in that: The method comprises the following steps: Capture data packets at each moment, obtain the source IP address, destination IP address, data packet length, network protocol and request response time of the data packet; construct a data packet length distribution sequence at each moment based on the length distribution of the data packets captured at each moment; Based on the number of data packets captured at each moment before each moment, as well as the proportion of various network protocols and target IP addresses of the data packets, the request number sequence, network protocol proportion sequence and target IP proportion sequence of each moment are constructed respectively; the similarity coefficient of the length of the data packet at each moment is calculated based on the similarity between the data packet length distribution sequence at each moment and other moments; based on the difference between the source IP addresses of different data packets at each moment, and the similarity between the source IP addresses of data packets at different moments, the distribution coefficient of the source IP address at each moment is constructed; Based on the trend changes of the similarity coefficient and the distribution coefficient at all moments before each moment, and the similarity between the request quantity sequence, the network protocol proportion sequence and the target IP proportion sequence at each moment, the flooding coefficient at each moment is constructed; Constructing a response time sequence at each moment based on the request response time of the data packets at all moments before each moment; acquiring normal data packets based on the request response time of each data packet, and constructing a normal data packet sequence at each moment; constructing an abnormal response coefficient at each moment based on the data changes in the first-order difference sequence of the request quantity sequence, the response time sequence, and the normal data packet sequence at each moment, combined with the flooding coefficient; Clustering is performed based on the flooding coefficient and the abnormal response coefficient, and abnormal traffic of DDoS attacks is checked based on the clustering result.

2. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the data packet length distribution sequence at each moment is as follows: Each length interval is set according to the length of the data packet, the time interval between adjacent moments is obtained, the number of data packets in each length interval within each time interval is counted, and the sequence composed of the number of data packets in all the length intervals within each time interval is used as the data packet length distribution sequence at the corresponding moment.

3. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the request quantity sequence, network protocol proportion sequence and target IP proportion sequence at each moment is as follows: The number of data packets captured at each moment is recorded as the first number; the sequence composed of the first numbers at the previous i moments is recorded as the request number sequence at the i-th moment; Among all the data packets captured at each moment, count the number of data packets with the same network protocol, calculate the data packet ratio of each network protocol, obtain the maximum value of the data packet ratio of all network protocols at each moment, and record it as the first maximum value; record the sequence composed of the first maximum values ​​of the previous i moments as the network protocol ratio sequence at the i-th moment; Based on the target IP addresses of all data packets captured at each moment, the target IP proportion sequence at each moment is obtained by adopting the same acquisition method as the network protocol proportion sequence.

4. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The expression of the similarity coefficient of the data packet length at each moment is: , where is the similarity coefficient of the packet length at the i-th moment, , are the packet length distribution sequences at the i-th and j-th moments, respectively. is the function for calculating the Euclidean distance, is the total number of data collection moments.

5. The method for troubleshooting abnormal traffic of DDoS attacks for network security services according to claim 1, characterized in that: The process of obtaining the distribution coefficient of the source IP address at each moment is as follows: The set of source IP addresses of all data packets captured at each moment is recorded as the source IP address set at each moment; the metric distance between the geographical longitude and latitude coordinates corresponding to any two elements in the source IP address set at each moment is calculated, recorded as the first distance; the average value of all the first distances in the source IP address set at the i-th moment is recorded as ; Calculate the intersection-and-combination ratio between the source IP address set at the ith moment and each moment thereafter, and record the average value of the intersection-and-combination ratio between the ith moment and all moments thereafter as ; The distribution coefficient of the source IP address at the i-th data collection time is recorded as , The expression is: .

6. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The process of obtaining the flooding coefficient at each moment is as follows: Record the sequence composed of similarity coefficients of the previous i moments as the similarity coefficient sequence of the i-th moment, use the similarity coefficient sequence as the input of the sequence decomposition algorithm, and output it as the trend sequence of the similarity coefficient sequence; perform straight line fitting on the trend sequence through a linear fitting algorithm, and record the output fitting straight line as the similarity coefficient straight line of the i-th moment; Based on the distribution coefficient of the previous i moments, the distribution coefficient line of the i-th moment is obtained in the same way as the similarity coefficient line; the flooding coefficient of the i-th moment is recorded as , The expression is: , where is the slope of the similarity coefficient line at the i-th moment, is the slope of the distribution coefficient line at the i-th moment, is the similarity between the request quantity sequence and the network protocol proportion sequence at the i-th moment, is the similarity between the sequence of request quantity and the sequence of target IP proportion at the i-th moment, It is an exponential function with the natural constant e as its base.

7. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the response time series at each moment is: Calculate the average value of the request response time of all data packets captured at each moment; record the sequence consisting of the average values ​​of the request response time at the previous i moments as the response time sequence at the i-th moment.

8. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The acquisition process of the normal data packet sequence at each moment is as follows: The mean of the request response time of all the collected data packets is used as the segmentation threshold, and the data packets whose request response time is less than the segmentation threshold are regarded as normal data packets. The number of normal data packets in the data packets captured at each moment is obtained; the sequence composed of the number of normal data packets at the first i moments is recorded as the normal data packet sequence at the i-th moment.

9. The method for troubleshooting abnormal traffic of DDoS attacks for network security services according to claim 1, characterized in that: The process of obtaining the abnormal response coefficient at each moment is as follows: The ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the request quantity sequence at the i-th moment is recorded as , the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the normal data packet sequence at the i-th moment is recorded as , the ratio of the number of positive numbers to the number of negative numbers in the first-order difference sequence of the response time series at the i-th moment is recorded as ; The abnormal response coefficient at the i-th moment is recorded as , The expression is: , where is the flooding coefficient at the ith moment.

10. The method for checking abnormal traffic of DDoS attack for network security service according to claim 1, characterized in that: The abnormal traffic investigation of DDoS attack based on the clustering results is specifically as follows: The flooding coefficient and the abnormal response coefficient at each moment are combined to obtain the feature vector at each moment, and the feature vectors at all moments are used as the input of the clustering algorithm and output as clusters; The mean flood coefficient and the mean abnormal response coefficient of all elements in each cluster are calculated, and the cluster with the smallest flood coefficient mean and the smallest abnormal response coefficient mean is taken as the normal cluster, and the time corresponding to each element in the normal cluster is taken as the time when there is no DDoS attack traffic anomaly, and the time corresponding to each element in the remaining clusters except the normal cluster is taken as the time when there is DDoS attack traffic anomaly; if there is no normal cluster, the time corresponding to each element of all clusters is the time when there is DDoS attack traffic anomaly.

Citation Information

Patent Citations

  • Method for defending distributed denial of service attack of industrial network system

    CN114531273A

  • SYN Flood attack detection and mitigation method based on GCBF

    CN119094220A