Information center network cache pollution attack defense system and method based on grey Markov model, and storage medium
Through the method based on the gray Markov model, the content popularity is predicted and the discrete coefficient of the request path are analyzed, and cache pollution attacks are screened and defended against cache pollution attacks, which solves the impact of cache pollution attacks on the network performance of the information center and achieves efficient and accurate defense effects.
Patent Information
- Application Number
- CN202510160801.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-13
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-02-13
AI Technical Summary
Cache pollution attacks have a serious impact on the content distribution efficiency of the information center network, resulting in frequent user access misses and degradation of network performance.
Using a method based on the gray Markov model, malicious content is screened by predicting content popularity, analyzing the discrete coefficients of requests on different paths, and responding to data packets to screen malicious content to achieve the defense of cache pollution attacks.
Effectively defend against cache pollution attacks, avoid accidentally damaging normal content, improve cache hit rate, reduce the number of hops in response packets, and improve network performance.
Smart Images

Figure CN120074895A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to an information-centric network cache pollution attack defense system, method and storage medium based on a grey Markov model. Background Art
[0002] As a targeted network attack means, cache pollution attack is designed to occupy the built-in cache space in an Information-Centric Network (ICN) and reduce its content distribution efficiency. In the information-centric network architecture, the cache plays a key role in accelerating content delivery and reducing the server load. However, this attack strategy poses a severe challenge to the operation efficiency of the information center. Attackers inject a large number of low-popularity contents into the network, maliciously occupying the limited cache resources in the network, causing normal popular contents to be replaced, resulting in frequent misses in user access, a serious decline in network performance, and a significant reduction in content distribution efficiency.
[0003] In order to achieve timely and efficient defense against cache pollution attacks in ICN, the present invention proposes an information-centric network cache pollution attack defense method based on a grey Markov model, which uses the predicted popularity of cache pollution attack contents, the dispersion coefficient of requests on different paths, and the number of hops of response data packets to screen malicious contents, so as to achieve timely and efficient defense.
[0004] There are differences in the behavioral characteristics between normal content and attack content. The differences between them can be utilized to screen attack content, thereby achieving timely and efficient defense against cache pollution attacks. DDCPC [Yao L, Fan Z, Deng J, et al. Detection and defense of cache pollution attacks using clustering in named data networks [J]. IEEE Transactions on Dependable and Secure Computing, 2018, 17(6): 1310 - 1321.] classifies content into popular and non - popular categories using a clustering algorithm based on the popularity of router content and the average time interval between requests. In multiple time slices, if the increment of the popular category is greater than the threshold, it is determined that a cache pollution attack is detected. For attack content, only the corresponding interest packets are forwarded without caching them, thus effectively defending against cache pollution attacks. FLAGP [Yao L, Zeng Y, Wang X, et al. Detection and defense of cache pollution based on popularity prediction in named data networking [J]. IEEE Transactions on Dependable and Secure Computing, 2020, 18(6): 2848 - 2860.] analyzes relevant parameters such as the request frequency of each content. By analyzing the data in consecutive time slices, this scheme can predict the predicted popularity of a content in future time slices. If the difference between the true popularity of the content and the predicted value exceeds a preset threshold, it is listed as suspicious content. Once a content is evaluated as suspicious in multiple time slices, it is determined that it has suffered a cache pollution attack. For the detected attack content, this scheme actively controls the growth of its popularity, thereby limiting its impact on the cache. The present invention is based on a grey Markov model and uses the predicted popularity value, the discrete coefficient on different paths, and the hop count of response data packets to screen malicious content, achieving defense against cache pollution attacks. Summary of the Invention
[0005] The purpose of the present invention is to provide a defense system, method, and storage medium for cache pollution attacks in an information - centric network based on a grey Markov model.
[0006] The purpose of the present invention is achieved through the following technical solutions:
[0007] A defense method for cache pollution attacks in an information - centric network based on a grey Markov model, the specific steps are as follows:
[0008] Step 1: Processing of blacklist content; When users in the information center network exchange information through interest packets and data packets, each router in the network performs defense optimization according to the detection method specified by the network administrator, forming a blacklist to process the content without caching; In addition, each router suspends updating the popularity of suspicious content according to its own blacklist in the current time slice and randomly discards requests for suspicious content;
[0009] Step 2: Obtaining parameters; modifying the table structure, interest packet field, and data packet field in the router of the information center network to record the content popularity, the path of the interest packet, and the number of hops returned by the data packet respectively;
[0010] Step 3: Screening the blacklist content: Using the parameters obtained in step 2, screen the content in the blacklist processed in step 1, and remove the misjudged content from the blacklist in a timely manner.
[0011] Furthermore, the step 1 is specifically as follows:
[0012] Step 1.1: Pause updating the popularity of suspicious content; when a data packet in the network passes through a router, if the content matches the router blacklist, suspend updating its content popularity to prevent the router cache from being deceived by the attack content, thereby avoiding the attack content from receiving inappropriate priority;
[0013] Step 1.2: Process content requests and responses; when a request for blacklisted content passes through a router, the router discards the request with probability p, while ensuring that normal user requests can be responded to, limiting cache pollution attacks to the router at this level to prevent them from spreading upstream; only forwarding but not caching responses to blacklisted content to prevent attack content from occupying limited cache space.
[0014] Furthermore, the router randomly discards suspicious interests with probability p and does not cache attack content. It uses the current time of program execution as a random seed and then generates a random number in the range of [0,1]. If the random number falls within the range of [0,p], the interest packet is discarded; if the random number falls within the range of [p,1], the interest packet is forwarded.
[0015] Furthermore, the step 2 is specifically as follows:
[0016] Step 2.1: Record content popularity. After receiving the interest packet, the router records the number of requests for each content to calculate the content popularity. The content popularity in the built-in cache is used as the screening criterion, and the popularity of suspicious content is used to predict its subsequent popularity. The popularity prediction of suspicious content uses the gray Markov model to predict the popularity of suspicious content. Make predictions, Among them, GMM is the Grey Markov Model, p k-j (c i ) is the popularity of content c i in the j-th past time slice;
[0017] Step 2.2: Modify the fields in the requested interest packet to record the path passed by the interest packet; when the router receives the interest packet, maintain a hash table that records the correspondence between the recorded path and the request times; when normal content screening needs to be performed according to the coefficient of variation, calculate the mean mean(c i ) and standard deviation SD(c i ) of the requests for content c i ) on different paths:
[0018]
[0019] Among them, path cnt represents the number of paths for requesting content c i , and Num k (c i ) represents the number of requests for content c i from path k; furthermore, calculate the coefficient of variation of the content requests on different paths:
[0020]
[0021] Among them, t is a constant greater than 0;
[0022] Step 2.3: When the data packet corresponding to the interest packet request is passed back through the router, the router modifies the fields in the data packet to record the number of hops of the data packet from the data hit point.
[0023] Furthermore, the specific steps of step 3 are as follows:
[0024] Step 3.1: Continuously monitor the three parameters of the content popularity, interest packet path, and data packet hop count of the content in the router's built-in cache and the content in the blacklist;
[0025] Step 3.2: Use the content popularity, interest packet path, and data packet hop count metrics of the content in the built-in cache as dynamic thresholds to screen the content in the blacklist, and timely remove the normal content from the blacklist to achieve dynamic update of the blacklist content;
[0026] Step 3.3: At the beginning of the next time slice, receive the result of the cache pollution detection method specified by the network manager and process the cache content newly added to the CS (Content Store) cache table in the current time slice. If there is no cache pollution attack in the current time slice, these contents will not be processed; if there is a cache pollution attack in the previous time slice, the cache content newly added to the CS in the current time slice will be added to the temporary blacklist for continuous monitoring.
[0027] An information - centric network cache pollution attack defense system based on a grey Markov model, including a blacklist management device, a transmission packet processing device, and a content monitoring and screening device;
[0028] The blacklist management device updates the content insertion time and adds new content to the blacklist according to the content update time and whether an attack is detected within the time slice;
[0029] The transmission packet processing device is responsible for processing the interest packets and data packets reaching the router according to the temporary blacklist, including pausing the update of the popularity of suspicious content, randomly discarding a part of the requests for suspicious content with a given probability, and prohibiting caching of suspicious content;
[0030] The content monitoring and screening device is responsible for continuously monitoring the content in the temporary blacklist. First, it uses the grey Markov model to predict the popularity, and then uses the predicted value of content popularity, the dispersion coefficient of content requests on different paths, and the hop count of response data packets to remove normal popular content from the temporary blacklist and put it back into the cache to reduce the impact on normal users.
[0031] A computer - readable storage medium, on which computer programs / instructions are stored. When the computer programs / instructions are executed by a processor, the steps of an information - centric network cache pollution attack defense method based on a grey Markov model are implemented.
[0032] A computer program product, including computer programs / instructions. When the computer programs / instructions are executed by a processor, the steps of an information - centric network cache pollution attack defense method based on a grey Markov model are implemented.
[0033] The beneficial effects of the present invention are as follows:
[0034] The present invention can use the blacklist to defend against attack content in a timely manner, and then screen the content in the blacklist to remove normal content from the blacklist, thus improving the problems of lagging defense and easy misjudgment of normal content in the existing methods, and further realizing timely and efficient defense. Description of the Drawings
[0035] Figure 1 It is a schematic diagram of the system of the present invention;
[0036] Figure 2 This is the flowchart for updating the insertion time in the present invention;
[0037] Figure 3 This is the flowchart for updating the blacklist in the present invention;
[0038] Figure 4 It is the cache hit rate of normal content for the XC topology;
[0039] Figure 5 It is the cache hit rate of normal content for the DFN topology;
[0040] Figure 6 It is the average number of hops of normal content under the XC topology, θ = 0.7;
[0041] Figure 7 It is the average number of hops of normal content under the DFN, θ = 0.7;
[0042] Figure 8 It is the average number of hops under different attack intensities for the XC topology;
[0043] Figure 9 It is the average number of hops under different attack intensities for the DFN topology. Detailed implementation manners
[0044] The following further describes the present invention with reference to the accompanying drawings.
[0045] A method for defending against cache pollution attacks in an information - centric network based on a grey Markov model in the present invention specifically comprises the following steps:
[0046] Step 1: Processing of blacklist content; When users in the information - centric network exchange information through interest packets and data packets, each router in the network performs defense optimization according to the detection method specified by the network administrator, forms a blacklist to perform non - caching processing on the content; In addition, each router pauses updating the popularity of suspicious content according to the blacklist of its current time slice and randomly discards requests for suspicious content;
[0047] Step 2: Obtaining of parameters; The table structure, interest - packet fields, and data - packet fields in the routers of the information - centric network are transformed to record the content popularity, the path passed by the interest packet, and the number of hops returned by the data packet respectively;
[0048] Step 3: Screening of blacklist content; Using the parameters obtained in Step 2, screen the content in the blacklist processed in Step 1, and promptly remove the misjudged content from the blacklist.
[0049] Figure 1 This is the system schematic diagram of the present invention. Specifically:
[0050] The present invention proposes a cache pollution defense method based on the grey Markov model, aiming to achieve efficient and accurate defense, avoid misjudgment or popularity changes from hurting normal content, and thus minimize the impact on normal users while achieving good defense effects. The defense framework mainly consists of three modules, namely the blacklist management module, the transport packet processing module, and the blacklist content monitoring and screening module.
[0051] The blacklist management module is responsible for the management of the blacklist, needs to maintain the time when the content is inserted into the cache, and remove the suspicious content from the cache and add it to the blacklist when a cache pollution attack occurs. To implement this module, an attribute "insert timestamp" needs to be added to the content cache CS to record the time when the content enters the cache, and the timestamp adopts the form of Unix timestamp.
[0052] The transformed CS is shown in Table 1.
[0053] Table 1 Transformed CS
[0054]
[0055] The transport packet processing module is responsible for processing the interest packets and data packets reaching the router according to the temporary blacklist, including pausing the update of the popularity of suspicious content, randomly discarding some requests for suspicious content with a given probability, and prohibiting caching of suspicious content.
[0056] When receiving an interest packet, this module first extracts the content name information therein and queries the temporary blacklist to determine whether the content name exists. If the content name is in the blacklist, the module will suspend updating the popularity statistics information of this content. This is because the content in the temporary blacklist is suspected cache pollution content, and its request volume cannot truly reflect the user's demand. Suspending the update of its popularity can prevent these contents from obtaining improper priorities in subsequent decisions. In addition to suspending the update of popularity information, this module will also randomly discard some requests for blacklisted content with a certain probability p. To protect the cache, there are usually two ways to handle suspected content using the blacklist. One way is to only forward the interest packets of pollution attack content but not cache its content. This approach has a certain effect on protecting the cache, but forwarding the interest packets will spread the cache pollution attack to the upstream routers, and a large number of requests and responses will bring huge pressure to the bandwidth. Another way is to directly discard the interest packets requesting suspected content, which will cause the requests of normal users for this content to not be responded to. Normal users request non-popular content less frequently, but they will also request it occasionally. This module adopts the method of randomly discarding suspected interests with probability p and not caching the attack content, ensuring that the attack content does not enter the cache, while limiting the attack scope below the local router, avoiding affecting the upstream routers, and also reducing the impact on normal users. The algorithm for discarding interest packets with probability p is implemented as Algorithm 2. The current time of program operation is used as the random seed, and then a random number in the range [0, 1] is generated. If the random number falls within the range [0, p], the interest packet is discarded; if the random number falls within the range [p, 1], the interest packet is forwarded.
[0057]
[0058] When the router receives the returned data packet, this module will check whether the content name corresponding to this interest packet is in the blacklist. If the content is in the blacklist, the data packet will be directly discarded from caching to ensure that the cache only contains popular content requested by normal users.
[0059] In the transmission packet processing module, the query and processing of the temporary blacklist need to be executed online. Therefore, it is required to implement an efficient query algorithm and data structure to ensure the minimum impact on the router forwarding performance. In the present invention, the temporary blacklist is implemented using a prefix tree. A prefix tree, also known as a dictionary tree or Trie tree, is a tree structure used for quickly retrieving strings. It maximizes the utilization of space by sharing common prefixes. The path from the root node to a non-leaf node represents a prefix of a string, and the path from the root node to a leaf node represents a complete string. The hierarchical naming mechanism in ICN makes a large number of contents have the same prefix, so it is very suitable for storage using a prefix tree. The time complexity of the insertion, search, and deletion operations of the prefix tree is all O(m), where m is the length of the content name, which means that the efficiency of the operation is independent of the amount of data stored in the tree and only related to the length of the string being operated on. In terms of space complexity, in the worst case, all strings have no common prefix, and the space complexity is O(n*m) at this time. However, in fact, in ICN, the contents produced by the same producer and different chunks of the same content share prefixes, and the worst case hardly occurs.
[0060] The blacklist content monitoring and screening module is responsible for continuously monitoring the contents in the temporary blacklist. First, it uses the grey Markov model to predict the popularity, and then uses the content popularity prediction value, the dispersion coefficient of the content request on different paths, and the hop count of the response packet to move the normal popular content out of the temporary blacklist and put it back into the cache to reduce the impact on normal users.
[0061] When screening normal popular contents, the contents with high popularity and low dispersion coefficient are put back into the cache as normal popular contents, the contents with low popularity and low dispersion coefficient are removed from the blacklist as non-popular contents, the contents with low popularity and high dispersion coefficient but few packet hops are removed from the blacklist as normal contents, and other contents remain in the blacklist as attack contents. The high and low of the content popularity and dispersion coefficient and the number of hops are determined using dynamic thresholds, and the threshold takes the median of the corresponding parameters in CS. Compared with static thresholds, using the popularity median in CS can adapt to scenarios with different traffic sizes. Since the popularity, dispersion coefficient, and hop count of each content in CS are not in order, an efficient algorithm is needed to find the median of the content dispersion coefficient in CS. The solution of the present invention uses the quickselect algorithm, which can find the median in O(n) time and the space complexity is only O(1). The process is shown in Algorithm 2. The overall screening process is shown in Algorithm 3.
[0062] Through the determination of the above three parameters, the truly popular contents are taken out of the temporary blacklist and put back into the cache, avoiding the impact on normal users when defending against cache pollution.
[0063]
[0064]
[0065]
[0066] Content popularity is an important factor for the proposed scheme to screen normal popular content. Therefore, a cache replacement policy based on content popularity (CCP) is adopted.
[53] , This cache replacement policy periodically counts the popularity of content and makes cache replacement decisions based on the dynamic popularity, preferentially caching content with high popularity. To implement CCP, first, outside the CS, PIT, and FIB, a content popularity table CPT (Content Popularity Table) is added. This data table is used to record the content popularity. Within a time slice, when the router receives an interest packet, it checks whether the corresponding content name exists in the CPT and updates the popularity of the corresponding content. The popularity is counted for the data within a time slice. Therefore, at the end of a time slice, the popularity table is cleared, and a new count starts at the beginning of the next time slice. The process of updating the insertion time of content into the cache is as Figure 4 shown. When a data packet arrives, first query the content popularity in the CPT, and then decide whether to cache this content according to CCP. If this content should be cached according to CCP, update the insertion time of this content to the current time.
[0067] Figure 2 is the flowchart for updating the insertion time in the present invention. Specifically:
[0068] Content popularity is an important factor for the proposed scheme to screen normal popular content. Therefore, the present invention adopts a cache replacement policy based on content popularity (CCP). This cache replacement policy periodically counts the popularity of content and makes cache replacement decisions based on the dynamic popularity, preferentially caching content with high popularity. To implement CCP, first, outside the CS, PIT, and FIB, a content popularity table CPT (Content Popularity Table) is added. This data table is used to record the content popularity. Within a time slice, when the router receives an interest packet, it checks whether the corresponding content name exists in the CPT and updates the popularity of the corresponding content. The popularity is counted for the data within a time slice. Therefore, at the end of a time slice, the popularity table is cleared, and a new count starts at the beginning of the next time slice. The process of updating the insertion time of content into the cache is as Figure 2 shown. When a data packet arrives, first query the content popularity in the CPT, and then decide whether to cache this content according to CCP. If this content should be cached according to CCP, update the insertion time of this content to the current time.
[0069] Figure 3 is the flowchart for updating the blacklist in the present invention. Specifically:
[0070] When the blacklist management module receives a signal of cache pollution attack, it will immediately activate the defense strategy. The attacker sends a large number of interest packets to increase the popularity of the attack content, thus occupying the cache space. Therefore, the content that enters the cache during a cache pollution attack is regarded as suspicious content, and this content is added to the temporary blacklist to prevent it from entering the cache. Subsequently, the screening mechanism is relied on to filter out normal popular content.
[0071] The experimental example scenario of the present invention is described in detail below. Combining the advantages of the present invention, the implementation results are analyzed.
[0072] The present invention runs on the ndnSIM simulation platform. To cooperate with the proposed defense method of the present invention, the cache replacement policy selects the cache replacement algorithm based on content popularity (CCP). When the cache space is full, the content with the lowest popularity is replaced out of the cache. Comparative experiments are respectively carried out on the XC topology and the DFN topology in this section. Each group of experiments lasts for 600 s. Only normal user requests for content in the first 300 s, and the attacker starts to launch an attack at the 300 s. The cache hit rate of normal content and the number of hops of the response data packet of normal content are used as performance evaluation indicators. Table 2 shows the specific parameters of the simulation configuration.
[0073] Table 2 ndnSIM simulation experiment parameters
[0074]
[0075]
[0076] The purpose of the cache pollution attack is to use unpopular content to occupy the cache, which ultimately leads to a decrease in the cache hit rate of normal user requests and an increase in the average number of hops of the response. The cache pollution defense scheme based on the grey Markov model proposed by the present invention is compared with the defense scheme based on clustering and the defense scheme based on popularity prediction. The cache hit rate of normal content and the average number of hops of the response data packet, which can best reflect the effect of the cache pollution attack, are selected for comparison.
[0077] (1) Cache hit rate of normal content
[0078] The cache hit rate reflects the probability that a user request can be satisfied by the cache. The lower the cache hit rate, the more the cache is occupied by the attack content. One of the goals of the cache pollution attack defense scheme is to increase the cache hit rate of the content. The calculation of the cache hit rate is as follows:
[0079]
[0080] Among them, Hit r(t) represents the number of times that the normal interest packet r hits the cache within time t, and R represents the total number of normal interest packets within time t.
[0081] Figure 4 and Figure 5 shows the comparison of the normal content cache hit rates under different attack intensities in the XC topology and the DFN topology. Four levels of attack intensities, namely 0.1, 0.3, 0.5, and 0.7, are selected in the two topology diagrams, covering low-rate attacks and high-rate attacks. It can be seen from the figure that as the attack intensity increases, the cache hit rate of normal content under the same method decreases. This is because the more non-popular content the attacker requests, the more cache space is occupied, and finally, when the content requests of normal users arrive, they cannot hit the cache. The cache pollution defense method can alleviate the impact caused by the attack, but it is difficult to completely eliminate the impact. Under different attack intensities in XC and DFN, compared with DDCPC and FLAGP, the proposed GMM-based cache pollution defense method of the present invention has achieved higher cache hit rates. This is because in DDCPC, blacklisting is used for defense, and all content included in the blacklist cannot be cached. In this scheme, the content that changes from non-popular to popular in the time slice suffering from cache pollution attack will enter the blacklist, and there is no subsequent monitoring of the content in the blacklist, which will cause misjudgment of normal content; FLAGP uses the method of controlling the growth of the popularity of suspicious content for defense. This method reduces the popularity of suspicious content, but there is no continuous monitoring of suspicious content. This scheme realizes efficient defense based on early detection, does not cache suspicious content and randomly discards some requests according to probability. After implementing the defense behavior, it continuously monitors the content in the temporary blacklist, reducing the impact on the cache hit rate of normal content caused by misjudgment or the change of content from non-popular to popular.
[0082] (2) The hop count of the response packet
[0083] The hop count of the response packet is also one of the important indicators to measure the effect of the cache pollution attack defense method. It reflects the distance between the cache of the content requested by the user and the user. The larger the hop count, the farther the cache location of the content requested by the user is from the user, and the longer it takes for the user to obtain the response, and the in-network cache is not effectively utilized. The hop count of the response packet is calculated as follows:
[0084]
[0085] where hop r (t) represents the hop count that the normal content r passes from the cache hit point to the consumer, and R represents the total number of requests within time t.
[0086] Figure 6 and Figure 7The normal content packet hop counts on the XC topology and the DFN topology are respectively shown, with the attack intensity θ being 0.7. The hop count data between the 200th second and the 400th second is intercepted in the figure. Only normal user requests for content exist before the 300th second, and the attack is launched at the 300th second. It can be seen from the figure that the response hop count of the normal content rises rapidly after the attack is launched. The defense method proposed by the present invention is activated before the 310th second, putting the suspicious content into the temporary blacklist to prevent the attack content from entering the cache. Since DDCPC and FLAGP require the accumulation of time slices, and FLAGP also requires the superposition and judgment of multiple detection results to carry out defense, it takes longer to implement the defense measures, resulting in a defense lag.
[0087] Figure 8 and Figure 9 The comparison of the average hop counts at different attack intensities under the XC and DFN topologies is respectively shown. It can be seen from the figure that the defense method proposed by the present invention achieves a lower hop count. This is because in the continuous detection of the suspicious content after the defense is implemented, the method of the present invention will use the popularity prediction value, the dispersion coefficient of the content request on different paths, and the hop count of the response packet to remove the normal popular content from the blacklist and put it back into the cache to meet the needs of normal users, while DDCPC and FLAGP adopt a one-size-fits-all blacklist mode and lack continuous monitoring of the content.
[0088] The present invention compares the cache pollution attack defense effects of GMM, DDCPC, and FLAGP through simulation experiments. The experimental results show that the defense method proposed by the present invention has better performance under different attack intensities and different topological structures. DDCPC defends against cache pollution by broadcasting blacklists, without continuous monitoring of the blacklist content. Moreover, the blacklist generation method determines that when there are both attack content and normal content with increasing popularity in the same time slice, the normal popular content will also enter the blacklist and cannot be cached, affecting the caching of normal content. FLAGP also defends using blacklists. During the process of generating blacklists, content needs to be determined as suspicious in multiple time slices before it can enter the blacklist, which results in a lag in defense. In addition, this scheme defends by controlling the popularity of suspicious content and also lacks long-term monitoring of suspicious content. The cache pollution defense method based on GMM proposed by the present invention implements defense measures immediately upon receiving the detection results, avoiding cache pollution content in the router. At the same time, it suspends the popularity update of suspicious content to prevent the router from being "deceived" by the false increase in the popularity of attack content. It randomly discards requests for suspicious content, limiting the cache pollution attack below the local router. In subsequent time slices, this scheme continuously monitors suspicious content using the predicted values of the popularity of trusted content, the dispersion coefficient of content requests on different paths, and the hop count of response packets, and puts the truly popular content back into the cache, reducing the impact on normal content and obtaining a higher cache hit rate and a smaller hop count of response packets.
[0089] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for defending against cache pollution attacks in information center networks based on a grey Markov model, characterized in that: The specific steps are as follows: Step 1: Processing of blacklist content; When users in the information center network exchange information through interest packets and data packets, each router in the network performs defense optimization according to the detection method specified by the network administrator, forming a blacklist to process the content without caching; In addition, each router suspends updating the popularity of suspicious content according to its own blacklist in the current time slice and randomly discards requests for suspicious content; Step 2: Obtaining parameters; modifying the table structure, interest packet field, and data packet field in the router of the information center network to record the content popularity, the path of the interest packet, and the number of hops returned by the data packet respectively; Step 3: Screening the blacklist content: Using the parameters obtained in step 2, screen the content in the blacklist processed in step 1, and remove the misjudged content from the blacklist in a timely manner.
2. The information center network cache pollution attack defense method based on the grey Markov model according to claim 1 is characterized by: The step 1 is specifically as follows: Step 1.1: Pause updating the popularity of suspicious content; when a data packet in the network passes through a router, if the content matches the router blacklist, suspend updating its content popularity to prevent the router cache from being deceived by the attack content, thereby avoiding the attack content from receiving inappropriate priority; Step 1.2: Process content requests and responses; when a request for blacklisted content passes through a router, the router discards the request with probability p, ensuring that normal user requests can be responded to while limiting cache pollution attacks to the router at this level to prevent them from spreading upstream; Only forward but do not cache responses to blacklisted content to prevent attack content from occupying limited cache space.
3. The information center network cache pollution attack defense method based on the grey Markov model according to claim 2 is characterized by: The router randomly discards suspicious interests with probability p and does not cache attack content. It uses the current time of the program running as a random seed and then generates a random number in the range of [0,1]. If the random number falls within the range of [0,p], the interest packet is discarded; if the random number falls within the range of [p,1], the interest packet is forwarded.
4. The information center network cache pollution attack defense method based on the grey Markov model according to claim 1 is characterized by: The step 2 is specifically as follows: Step 2.1: Record content popularity. After receiving the interest packet, the router records the number of requests for each content to calculate the content popularity. The content popularity in the built-in cache is used as the screening criterion, and the popularity of suspicious content is used to predict its subsequent popularity. The popularity prediction of suspicious content uses the gray Markov model to predict the popularity of suspicious content. Make predictions, Among them, GMM is a grey Markov model, p k-j (c i ) is the content c in the jth time slice in the past i popularity; Step 2.2: Modify the fields in the request interest packet and record the path that the interest packet has passed through; when the router receives the interest packet, it maintains a hash table that records the corresponding relationship between the path and the number of requests; When normal content screening is required based on the discrete coefficient, calculate the content c i Request the mean value mean(c i ) and standard deviation SD(c i ): Among them, path cnt Indicates the request content c i The number of paths, Num k (c i ) represents the content c from path k i The number of requests; Then calculate the discrete coefficient of content requests on different paths: Wherein, t is a constant greater than 0; Step 2.3: When the data packet corresponding to the interest packet request is transmitted back through the router, the router modifies the field in the data packet and records the number of hops from the data packet to the data hit point.
5. The information center network cache pollution attack defense method based on the grey Markov model according to claim 1 is characterized by: The step 3 is specifically as follows: Step 3.1: Continuously monitor the content popularity, interest packet path, and data packet hop count of the content in the router's built-in cache and the content in the blacklist; Step 3.2: The content popularity, interest packet path, and data packet hop count of the content in the built-in cache are used as dynamic thresholds to filter the content in the blacklist, remove the normal content from the blacklist in time, and realize dynamic update of the blacklist content; Step 3.3: At the beginning of the next time slice, the result of the cache pollution detection method specified by the network administrator is received to process the newly added cache content in the CS cache table in the current time slice. If there is no cache pollution attack in the current time slice, these contents will not be processed; if there is a cache pollution attack in the previous time slice, the newly added cache content in the CS in the current time slice will be added to the temporary blacklist for continuous monitoring.
6. The information center network cache pollution attack defense system based on the grey Markov model according to any one of claims 1 to 5, characterized in that: It includes a blacklist management device, a transmission packet processing device, and a content monitoring and screening device; The blacklist management device completes the update of the content insertion time, and adds new content to the blacklist according to the content update time and whether an attack is detected within the time slice; The transmission packet processing device is responsible for processing the interest packets and data packets reaching the router according to the temporary blacklist, including suspending the update of the popularity of suspicious content, randomly discarding some requests for suspicious content according to a given probability, and prohibiting the caching of suspicious content; The content monitoring and screening device is responsible for continuously monitoring the content in the temporary blacklist. First, the popularity is predicted using a grey Markov model. Then, the normal popular content is removed from the temporary blacklist and put back into the cache using the content popularity prediction value, the discrete coefficient of the content request on different paths, and the number of hops of the response data packet, thereby reducing the impact on normal users.
7. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instructions are executed by a processor, the steps of the method described in claims 1-5 are implemented.
8. A computer program product, comprising a computer program / instructions, which, when executed by a processor, implement the steps of the method according to claims 1-5.
Citation Information
Patent Citations
Cache pollution attack detection method based on cooperation mode under vehicle-mounted content center network
CN110535875A
Multi-attribute collaborative caching method for information center network cache privacy protection
CN111625565A
Device and method for detecting cache attack
KR1020140118070A