Distributed denial of service attack detection method and device, equipment and storage medium

By collecting and analyzing the information of the control node, intercepting and parsing its communication instructions with the puppet host, and generating attack detection results, the complexity and real-time problems of DDoS attack detection are solved, and comprehensive and efficient detection of DDoS attacks is achieved.

CN120074941APending Publication Date: 2025-05-30CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510301307.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

How to comprehensively detect distributed denial of service attacks (DDoS) to reduce the risk of DDoS attacks, taking into account the complexity of DDoS attacks and the continued growing threat.

Method used

By collecting node information of active control nodes in the network, intercepting communication instructions between the control nodes and the puppet hosts in the botnet, and analyzing the communication instructions, obtaining attack task information and host information of the puppet hosts, and finally performing aggregation analysis to generate attack detection results.

Benefits of technology

It realizes comprehensive detection of DDoS attacks, can perceive and analyze attack situations in real time, and reduces the risk and impact of DDoS attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074941A_ABST
    Figure CN120074941A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a method, a device and equipment for detecting a distributed denial of service (DDoS) attack and a storage medium, which are used for comprehensively detecting the DDoS attack so as to reduce the risk of the DDoS attack. The method comprises the steps that node information of a plurality of control nodes in an active state in a network is collected, each control node is used for controlling a botnet attacked by a distributed denial of service (DDoS), and the node information comprises address information and communication protocol information; for each control node, based on the node information of the control node, intercepting a communication instruction between the control node and a puppet host in the botnet, analyzing the communication instruction, obtaining corresponding attack task information, and obtaining host information of each puppet host controlled by the control node; and performing aggregation analysis on the node information of the plurality of control nodes, the corresponding attack task information and the host information of the associated puppet hosts to generate an attack detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular, to a method, apparatus, device, and storage medium for detecting distributed denial of service attacks. Background Art

[0002] A distributed denial of service (DDoS) attack is a form of network attack whose purpose is to overwhelm a target server or network resource with a large number of requests, thereby causing legitimate users to be unable to access the service.

[0003] Currently, DDoS attacks have become one of the greatest threats to network security, mainly presenting four significant characteristics: First, ultra-large-scale attacks are extremely active, and T-level attacks frequently occur; Second, the attack frequency continues to show an increasing trend; Third, the climbing speed of large-traffic attacks reaches a new high, reaching T-level attacks in seconds; Fourth, the attack complexity continues to increase, and the attack threat intensifies.

[0004] Therefore, how to comprehensively detect DDoS attacks to reduce the risk of DDoS attacks is a problem that needs to be solved. Summary of the Invention

[0005] The present application provides a method, apparatus, device, and storage medium for detecting distributed denial of service attacks, which are used to comprehensively detect DDoS attacks to reduce the risk of DDoS attacks.

[0006] In a first aspect, an embodiment of the present application provides a method for detecting distributed denial of service attacks, including:

[0007] Collect node information of multiple active control nodes in the network. Each of the control nodes is used to control a botnet for distributed denial of service (DDoS) attacks, and the node information includes address information and communication protocol information;

[0008] For each of the control nodes, based on the node information of the control node, intercept communication instructions between the control node and puppet hosts in the botnet, and parse the communication instructions to obtain corresponding attack task information and obtain host information of each puppet host controlled by the control node;

[0009] Aggregate and analyze the node information of multiple control nodes, the corresponding attack task information, and the host information of associated puppet hosts to generate an attack detection result.

[0010] In a possible implementation manner, the collecting node information of multiple active control nodes in the network includes one or more of the following operation steps:

[0011] According to the communication characteristics of the botnet, network detection is performed in the target network to extract the communication information between the corresponding control node and the corresponding puppet host, and the node information of the corresponding control node is obtained according to the communication information;

[0012] Obtain the node information of the corresponding control node from the open source clue source;

[0013] Obtain the information of the trojan storage site, and according to the information of the trojan storage site, collect the trojan sample data in real time from the corresponding trojan storage site, and based on the collected trojan sample data, extract the node information of the corresponding control node; wherein, the information of the trojan storage site is obtained through at least one of the open source clue source and the honeypot cluster network.

[0014] In a possible implementation manner, the performing network detection in the target network according to the communication characteristics of the botnet to extract the communication information between the corresponding control node and the corresponding puppet host, and obtaining the node information of the corresponding control node according to the communication information includes one or both of the following operation steps:

[0015] Detect the network traffic of the target network according to the communication traffic characteristics of the botnet to extract the communication traffic between the corresponding control node and the corresponding puppet host, and obtain the node information of the corresponding control node according to the communication traffic;

[0016] Scan and detect the target network according to the communication protocol characteristics of the botnet to extract the communication protocol information between the corresponding control node and the corresponding puppet host, and perform simulated communication with the corresponding control node according to the extracted communication protocol information to obtain the node information of the corresponding control node.

[0017] In a possible implementation manner, the extracting the node information of the corresponding control node based on the collected trojan sample data includes:

[0018] When the decryption of the trojan sample in the collected trojan sample data is successful, the node information of the corresponding control node is extracted;

[0019] When the decryption of the trojan sample in the collected trojan sample data fails, perform dynamic analysis on the trojan sample with decryption failure through a sandbox to extract the node information of the corresponding control node.

[0020] In a possible implementation manner, the intercepting the communication instruction between the control node and the puppet host in the botnet based on the node information of the control node and parsing the communication instruction to obtain the corresponding attack task information includes:

[0021] Intercept a first communication instruction between the control node and a puppet host with a castration trojan function based on the node information of the control node. If the decryption of the first communication instruction is successful, obtain first attack task information. If the decryption of the first communication instruction fails, decrypt the first communication instruction through the puppet host with the castration trojan function to obtain the first attack task information;

[0022] Intercept a second communication instruction between the control node and a puppet host without a castration trojan function based on the node information of the control node. After the decryption of the second communication instruction is successful, obtain second attack task information.

[0023] In a possible implementation manner, the parsing of the communication instruction to obtain corresponding attack task information includes:

[0024] Parse the communication instruction to obtain initial attack task information and address information of a reflection server;

[0025] Based on the address information of the reflection server, obtain reflected amplification attack task information from the reflection server;

[0026] Based on the initial attack task information and the amplification attack task information, obtain the attack task information.

[0027] In a possible implementation manner, after generating the attack detection result, it further includes:

[0028] Display the attack detection result in an attack detection interface, where the attack detection result includes one or more of the following information:

[0029] Distribution status of multiple control nodes;

[0030] Attack link status of multiple control nodes with the puppet host, reflection server, and attack target;

[0031] Attack portraits of multiple control nodes, where the attack portraits include one or more of attack target, attack type, attack time, and attack duration;

[0032] Distribution status of the puppet hosts associated with multiple control nodes.

[0033] In a second aspect, an embodiment of the present application provides a detection device for distributed denial of service attacks, including:

[0034] An acquisition module for acquiring node information of multiple active control nodes in a network. Each control node is used to control a botnet for distributed denial of service (DDoS) attacks, and the node information includes address information and communication protocol information;

[0035] An interception module, for each of the control nodes, based on the node information of the control node, intercept the communication instructions between the control node and the puppet hosts in the botnet, and parse the communication instructions to obtain corresponding attack task information, and obtain the host information of each of the puppet hosts controlled by the control node;

[0036] A generation module, for aggregating and analyzing the node information of multiple control nodes, the corresponding attack task information, and the host information of the associated puppet hosts to generate an attack detection result.

[0037] In a possible implementation manner, the acquisition module is specifically used to perform one or more of the following operation steps:

[0038] Perform network detection in the target network according to the communication characteristics of the botnet to extract the communication information between the corresponding control node and the corresponding puppet host, and obtain the node information of the corresponding control node according to the communication information;

[0039] Obtain the node information of the corresponding control node from an open source clue source;

[0040] Obtain trojan storage site information, and according to the trojan storage site information, collect trojan sample data from the corresponding trojan storage site in real time, and based on the collected trojan sample data, extract the node information of the corresponding control node; wherein, the trojan storage site information is obtained through at least one of the open source clue source and the honeypot cluster network.

[0041] In a possible implementation manner, when performing network detection in the target network according to the communication characteristics of the botnet to extract the communication information between the corresponding control node and the corresponding puppet host, and obtaining the node information of the corresponding control node according to the communication information, the acquisition module is specifically used to perform one or two of the following operation steps:

[0042] Detect the network traffic of the target network according to the communication traffic characteristics of the botnet to extract the communication traffic between the corresponding control node and the corresponding puppet host, and obtain the node information of the corresponding control node according to the communication traffic;

[0043] Scan and detect the target network according to the communication protocol characteristics of the botnet to extract the communication protocol information between the corresponding control node and the corresponding puppet host, and perform simulation communication with the corresponding control node according to the extracted communication protocol information to obtain the node information of the corresponding control node.

[0044] In a possible implementation, when extracting the node information of the corresponding control node based on the collected Trojan sample data, the collection module is specifically configured to:

[0045] When the decryption of the Trojan sample in the collected Trojan sample data is successful, the node information of the corresponding control node is extracted;

[0046] When the decryption of the Trojan sample in the collected Trojan sample data fails, the Trojan sample with decryption failure is dynamically analyzed through a sandbox, and the node information of the corresponding control node is extracted.

[0047] In a possible implementation, when parsing the communication instruction to obtain the corresponding attack task information, the interception module is specifically configured to:

[0048] Parse the communication instruction to obtain the initial attack task information and the address information of the reflection server;

[0049] Based on the address information of the reflection server, obtain the reflected amplification attack task information from the reflection server;

[0050] Based on the initial attack task information and the amplification attack task information, obtain the attack task information.

[0051] In a possible implementation, the interception module is specifically configured to:

[0052] Based on the node information of the control node, intercept the first communication instruction between the control node and the puppet host with the Trojan function castrated. If the decryption of the first communication instruction is successful, obtain the first attack task information. If the decryption of the first communication instruction fails, the puppet host with the Trojan function castrated decrypts the first communication instruction to obtain the first attack task information;

[0053] Based on the node information of the control node, intercept the second communication instruction between the control node and the puppet host without the Trojan function castrated. After the decryption of the second communication instruction is successful, obtain the second attack task information.

[0054] In a possible implementation, the device further includes a display module, which is used to:

[0055] Display the attack detection result in the attack detection interface, and the attack detection result includes one or more of the following information:

[0056] The distribution status of multiple control nodes;

[0057] The attack link status of multiple control nodes with the puppet host, the reflection server, and the attack target;

[0058] Attack portraits of multiple said control nodes, where the attack portrait includes one or more of an attack target, an attack type, an attack time, and an attack duration;

[0059] The distribution status of the puppet hosts associated with multiple said control nodes.

[0060] In a third aspect, an embodiment of the present application provides an electronic device, which includes a processor and a memory. Among them, the memory stores a computer program. When the computer program is executed by the processor, the processor is caused to execute the steps of any of the methods in the first aspect.

[0061] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which includes a computer program. When the computer program runs on a communication device, the computer program is used to cause the communication device to execute the steps of any of the methods in the first aspect.

[0062] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, where the computer program is stored in a computer-readable storage medium; when a processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, causing the electronic device to execute the steps of any of the methods in the first aspect.

[0063] The present application has at least the following beneficial effects:

[0064] In the embodiment of the present application, first, node information of multiple control nodes in an active state in the network is collected; then, based on the node information of each control node, communication instructions between the control node and the puppet hosts in the botnet are intercepted, and the communication instructions are parsed to obtain corresponding attack task information and host information of each puppet host controlled by the control node; finally, the node information of each control node, the corresponding attack task information, and the host information of the associated puppet hosts are aggregated and analyzed to generate an attack detection result, so as to comprehensively detect DDoS attacks and reduce the risk of DDoS attacks.

[0065] Other features and advantages of the present application will be described in the subsequent specification, and part of them will become obvious from the specification or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0066] The accompanying drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0067] Figure 1 is a flowchart of a method for detecting distributed denial of service attacks provided by an embodiment of the present application;

[0068] Figure 2 is a schematic structural diagram of a control node acquisition system provided by an embodiment of the present application;

[0069] Figure 3 is a schematic structural diagram of an attack detection system provided by an embodiment of the present application;

[0070] Figure 4 is a schematic diagram of an attack detection interface provided by an embodiment of the present application;

[0071] Figure 5 is a schematic structural diagram of a device for detecting distributed denial of service attacks provided by an embodiment of the present application;

[0072] Figure 6 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0073] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will clearly and completely describe the technical solutions of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the technical solutions of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments recorded in this application document without creative efforts belong to the scope protected by the technical solutions of the present application.

[0074] The following introduces some concepts involved in the embodiments of the present application.

[0075] Botnet: It refers to a network that can be controlled one-to-many formed between a control node and infected zombie host computers by infecting a large number of hosts with zombie program viruses through one or more propagation means.

[0076] Control node: A server that issues various types of control commands to zombie hosts.

[0077] Zombie host: Commonly known as a "zombie host" or "bot", it refers to a computer that is infected with malicious software after accessing the target network and is controlled by a control node. It can execute DDoS attacks at any time according to the instructions issued by the control node.

[0078] Trojan storage site: A malicious website or server used to store and distribute Trojan programs. These sites are typically maintained by cybercriminals to facilitate the spread of Trojan viruses to target systems.

[0079] Honeypot: A cybersecurity resource whose main purpose is to attract and detect potential attackers. Honeypots are typically designed to appear as valuable network targets, but in reality, they do not host any actual business functions or data. A honeypot can be a server, network service, file system, or any other form of computing resource.

[0080] Open-source clue source: Refers to publicly available information resources related to DDoS attacks.

[0081] Reflection server: In a DDoS attack, the attacker takes advantage of the specific service or protocol characteristics of a reflection server. By sending packets with forged source addresses to the reflection server, the reflection server responds and amplifies the network traffic, reflecting a large number of packets back to the target server. This type of attack is usually referred to as a "reflection attack" or "amplification attack".

[0082] Puppet host with Trojan functions disabled: Usually refers to a computer infected with malicious software (such as a Trojan) sent by a controlled node, but whose malicious functions have been removed. It can still communicate with the control node but will not perform attack operations.

[0083] The terms "first" and "second" in the specification and claims of this application are used to distinguish different objects, not to describe a specific order. In addition, the term "including" and any of its variations are intended to cover non-exclusive protection. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may optionally also include steps or units not listed, or may optionally also include other steps or units inherent to these processes, methods, products, or devices. "Multiple" in this application can mean at least two, for example, it can be two, three, or more, and the embodiments of this application do not make any limitations.

[0084] Currently, DDoS attacks have become one of the greatest threats to network security, mainly presenting four significant characteristics: First, ultra-large-scale attacks are extremely active, and T-level attacks frequently occur; Second, the attack frequency continues to show an increasing trend; Third, the climbing speed of large-traffic attacks reaches a new high, reaching T-level attacks in seconds; Fourth, the attack complexity continues to increase, and the attack threat intensifies.

[0085] In view of this, in order to comprehensively detect DDoS attacks and reduce the risk of DDoS attacks, the embodiments of the present application provide a method, apparatus, device, and storage medium for detecting distributed denial of service attacks. First, node information of multiple active control nodes in the network is collected; then, based on the node information of each control node, communication instructions between the control node and the puppet hosts in the botnet are intercepted, and the communication instructions are parsed to obtain corresponding attack task information and host information of each puppet host controlled by the control node; finally, the node information of each control node, the corresponding attack task information, and the host information of the associated puppet hosts are aggregated and analyzed to generate an attack detection result, so as to comprehensively detect DDoS attacks and reduce the risk of DDoS attacks.

[0086] The preferred embodiments of the present application will be described below with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present application, and are not used to limit the present application. And without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0087] The method for detecting distributed denial of service attacks in the embodiments of the present application can be executed by a detection device for distributed denial of service attacks. The detection device can be any device, equipment, platform, or cluster of devices with computing capabilities. The embodiments of the present application do not make specific limitations on the specific implementation device of the detection device, and appropriate computing devices can be selected according to needs.

[0088] Refer to Figure 1 As shown, a method for detecting distributed denial of service attacks provided by the embodiments of the present application includes the following S11-S13:

[0089] S11. Collect node information of multiple active control nodes in the network. Each control node is used to control a botnet for distributed denial of service (DDoS) attacks. The node information includes address information and communication protocol information.

[0090] Among them, one or more operation methods can be used to collect the node information of the control node, including but not limited to communication traffic detection, communication protocol scanning, protocol hijacking active low-interaction detection, honeypot, open source clue source, etc., to collect the node information of active control nodes in real time. The collected node information of multiple control nodes is uniformly saved to the control node library.

[0091] In some embodiments, collecting node information of multiple active control nodes in the network includes one or more of the following operation methods:

[0092] The first operation mode is to perform network detection in the target network according to the communication characteristics of the botnet, extract the communication information between the corresponding control node and the corresponding puppet host, and obtain the node information of the corresponding control node based on the communication information.

[0093] Among them, the communication characteristics of the DDoS attack botnet include communication traffic characteristics and communication protocol characteristics, etc. According to the communication traffic characteristics, the communication traffic between the control node and the corresponding puppet host can be detected in the target network (such as the Internet), and then the node information of the active control node can be extracted; according to the communication protocol characteristics, the target network can be scanned and probed, and protocol simulation interaction can be performed to obtain the node information of the active control node.

[0094] In a possible implementation manner, the above first operation mode may include one or both of the following methods:

[0095] Method 1: Detect the network traffic of the target network according to the communication traffic characteristics of the botnet, extract the communication traffic between the corresponding control node and the corresponding puppet host, and obtain the node information of the corresponding control node based on the communication traffic.

[0096] Among them, the communication traffic characteristics of the DDoS attack botnet usually include: specific communication protocol, specific port, specific command format, large traffic burst, multi-source target network protocol (Internet Protocol, IP) address, similar packet characteristics, long duration, uneven traffic distribution, etc.

[0097] Specifically, all communication traffic entering and leaving the target network can be detected at key positions (such as border routers, firewalls) of the target network through network traffic detection tools. Then, according to the communication traffic characteristics of the botnet, the data packets that meet the communication traffic characteristics are screened out from all the detected communication traffic, and then the communication traffic between the control node and the puppet host is extracted. Further, the communication traffic between the control node and the puppet host is analyzed by a data analysis tool, and relevant information of the control node, such as communication address (such as IP address, port number), communication protocol information, etc., is extracted from the communication traffic, so as to obtain the node information of the latest active control node.

[0098] Method 2: Scan and probe the target network according to the communication protocol characteristics of the botnet, extract the communication protocol information between the corresponding control node and the corresponding puppet host, and perform simulation communication with the corresponding control node based on the extracted communication protocol information to obtain the node information of the corresponding control node.

[0099] Among them, the communication protocol features of the botnet can include the communication protocol used, ports, encryption methods, command formats, command types, authentication methods, etc. Specifically, by using a network scanning tool to comprehensively scan the target network, the scanning scope can be defined: determine the IP address range and port list to be scanned, record the response situation of each IP address and port, identify possible control nodes, and then conduct protocol simulation interactions with these control nodes, simulate the behavior of the puppet host, send simulation requests to these control nodes, and obtain the response information of the simulation interaction, including the response content, timestamp, etc. By analyzing the response data of the simulation interaction, confirm which are the real control nodes, so as to obtain the node information of the active control nodes, including IP addresses, port numbers, communication protocol information, etc.

[0100] The second operation method is to obtain the node information of the corresponding control nodes from open-source clue sources.

[0101] Among them, the open-source clue sources include Internet clue sources and commercial clue sources, etc. Using this open-source clue source as a third-party source, obtain the node information of the active control nodes.

[0102] The third operation method is to obtain the information of the trojan storage site, and based on the information of the trojan storage site, collect the trojan sample data in real time from the corresponding trojan storage site, and based on the collected trojan sample data, extract the node information of the corresponding control nodes; among them, the information of the trojan storage site is obtained through at least one of the open-source clue sources and the honeypot cluster network.

[0103] On the one hand, one or more pieces of information about the trojan storage site can be obtained from the above-mentioned open-source clue sources.

[0104] On the other hand, a honeypot cluster network can be deployed in the Internet to collect information of one or more Trojan storage sites in the honeypot cluster network in real time. Specifically, multiple honeypots are deployed in different geographical locations or subnets to form a honeypot cluster network. The honeypots can provide only limited service simulations with low resource consumption. Ports and services are set to make them look like real servers, simulating common vulnerabilities and services to attract the attention of attackers. For example, the information of Trojan storage sites can be collected in the following ways: 1. Detect file upload behavior. By detecting the file upload behavior in the honeypot cluster network, identify and save the uploaded malicious software samples, analyze the content of the malicious software samples, and extract information such as the Command and Control (C&C) server address and download link therein. 2. External link parsing. By analyzing the network traffic in the honeypot cluster network, identify the HTTP / HTTPS requests pointing to external sites, extract the Uniform Resource Locator (URL) in these requests, and further parse the content of the URL to find possible information of Trojan storage sites. It should be noted that the above collection methods are only exemplary, and the embodiments of the present application do not limit the collection methods of Trojan sample data.

[0105] After obtaining the information of one or more Trojan storage sites, the latest Trojan sample data can be collected in real time from the corresponding Trojan storage sites according to the Trojan storage site information. Specifically, the Trojan sample data can be automatically downloaded from the Trojan storage site through an automated script, including the files in the target URL; it is also possible to simulate a normal browser to access the Trojan storage site to download the Trojan sample data; or the Trojan sample data can be downloaded from the Trojan storage site through a command-line tool. The embodiments of the present application do not limit the collection methods of Trojan sample data.

[0106] In a possible implementation manner, the Trojan sample data may include multiple Trojan samples. When extracting the node information of the corresponding control node based on the collected Trojan sample data, the collected Trojan sample data can be first subjected to static decryption processing. When the decryption of the Trojan samples in the Trojan sample data is successful, the node information of the corresponding control node can be extracted from the Trojan samples; when the decryption of the Trojan samples fails, the Trojan samples with decryption failure can be dynamically analyzed through a sandbox to extract the node information of the corresponding control node.

[0107] Specifically, a pre-set static decryption model can be used to perform static decryption on the Trojan sample. The static decryption model can attempt to perform static decryption on the Trojan sample using a set decryption method, and there is no limitation on the set decryption method. When the decryption of the Trojan sample is successful, the node information of the control node can be extracted; for the Trojan sample with decryption failure, dynamic analysis is performed through a sandbox. Specifically, by running the Trojan sample in the sandbox, the behavior of the Trojan sample can be captured, including the communication traffic with the control node, so as to extract the node information of the control node.

[0108] In the embodiment of the present application, the node information of the control node can be comprehensively collected through various operation methods, so as to ensure that DDoS attacks can be comprehensively detected subsequently.

[0109] S12. For each control node, based on the node information of the control node, intercept the communication instructions between the control node and the puppet hosts in the botnet, and parse the communication instructions to obtain the corresponding attack task information, and obtain the host information of each puppet host controlled by the control node.

[0110] Among them, for each control node, based on the address information and communication protocol information of the control node, an interception measure is deployed to intercept the communication traffic that conforms to the address information and the communication protocol information of the control node. Specifically, for the communication traffic entering and leaving the target network, check the content of the data packets therein, identify and intercept the suspicious communication traffic, and then identify the communication instructions between the control node and the puppet hosts in the botnet from these communication traffic. Further, parse the communication instructions to obtain the corresponding attack task information, which may specifically include the details of the DDoS attack task, such as the attack target, attack time, attack duration, attack type, etc.

[0111] By intercepting the communication instructions between the control node and each puppet host, the host information of each puppet host controlled by the control node can also be determined, including information such as IP address and port.

[0112] In a possible implementation manner, parsing the communication instructions in S12 above to obtain the corresponding attack task information may specifically further include: parsing the communication instructions to obtain the initial attack task information and the address information of the reflection server; based on the address information of the reflection server, obtaining the reflected amplification attack task information from the reflection server; and obtaining the attack task information based on the initial attack task information and the amplification attack task information.

[0113] Among them, the reflection server can be a Memory Caching System (Memcache) server, a Domain Name System (DNS) server, a Network Time Protocol (NTP) server, etc.

[0114] When the control node initiates a DDoS attack, it can send an attack instruction (i.e., the above communication instruction) to the puppet host, and carry the above initial attack task information and the address information of the used reflection server in the attack instruction, so as to instruct the puppet host to send a packet with a forged source address to the corresponding reflection server when launching an attack on the attack target (such as the target server), causing the reflection server to respond and amplify the network traffic, and reflecting a large number of packets back to the attack target. Therefore, when analyzing the communication instruction sent by the control node to obtain the corresponding attack task information, the address information of the used reflection server may also be obtained.

[0115] An embodiment of the present application can deploy an emulated reflection server, which has an amplification function but does not execute attacks. The reflection server in the communication instruction sent by the control node can be a real reflection server (which can execute attacks) or an emulated reflection server.

[0116] Further, based on the address information of the reflection server, obtain the amplified attack task information reflected from the reflection server, specifically including the details of the amplified DDoS attack task, such as the attack target, attack time, attack duration, attack type, etc.

[0117] In an embodiment of the present application, the amplified attack task information can be collected from the reflection server to complement the above initial attack task information and obtain more comprehensive attack task information.

[0118] In a possible implementation manner, based on the node information of the control node, intercept the communication instruction between the control node and the puppet host in the botnet, and parse the communication instruction to obtain the corresponding attack task information, which may include the following two cases:

[0119] The first case is to intercept the first communication instruction between the control node and the puppet host with the trojan horse function disabled based on the node information of the control node. If the decryption of the first communication instruction is successful, the first attack task information is obtained. If the decryption of the first communication instruction fails, the first communication instruction is decrypted by the puppet host with the trojan horse function disabled to obtain the first attack task information.

[0120] Among them, a set decryption method can be adopted to attempt to decrypt the above first communication instruction. If the decryption of the first communication instruction fails, the first communication instruction can be sent to a puppet host with the Trojan horse function disabled. Although this puppet host will not initiate an attack, it retains the ability to communicate with the control node. Therefore, this puppet host can decrypt the first communication instruction. The obtained first attack task information can be used as the corresponding attack task information mentioned above.

[0121] In the second case, based on the node information of the control node, intercept the second communication instruction between the control node and the puppet host without the Trojan horse function disabled. After successfully decrypting the second communication instruction, obtain the second attack task information.

[0122] Among them, a set decryption method can be adopted to attempt to decrypt the above first communication instruction. After successful decryption, the second attack task information can be obtained, and this second attack task information can be used as the corresponding attack task information mentioned above.

[0123] In the embodiments of the present application, based on the node information of the control node, on the one hand, intercept the first communication instruction between the control node and the puppet host with the Trojan horse function disabled to obtain the first attack task information; on the other hand, intercept the second communication instruction between the control node and the puppet host without the Trojan horse function disabled to obtain the second attack task information, so as to ensure that the corresponding attack task information can be obtained.

[0124] S13. Aggregate and analyze the node information of multiple control nodes, the corresponding attack task information, and the host information of each associated puppet host to generate an attack detection result.

[0125] Among them, by aggregating and analyzing the node information of multiple control nodes in real time, the distribution status of control nodes in each region can be determined; by aggregating and analyzing the attack task information of multiple control nodes in real time, the attack profile of each control node can be determined, including the attack target, attack type, attack time, attack duration, etc.; by aggregating and analyzing the attack targets of multiple control nodes and the host information of each associated puppet host in real time, the attack link status between multiple control nodes, puppet hosts, and attack targets can be determined. In addition, a reflection server can also be included in the attack link, so as to comprehensively perceive the DDoS attack status.

[0126] In the embodiments of the present application, first, node information of multiple control nodes in an active state in the network is collected; then, based on the node information of each control node, communication instructions between the control node and the puppet hosts in the botnet are intercepted, and the communication instructions are parsed to obtain corresponding attack task information and host information of each puppet host controlled by the control node; finally, the node information of each control node, the corresponding attack task information, and the host information of the associated puppet hosts are aggregated and analyzed to generate an attack detection result, so as to comprehensively detect DDoS attacks and reduce the DDoS attack risk.

[0127] In some embodiments, after generating the attack detection result, the attack detection result can also be displayed in the attack detection interface, and the attack detection result can include one or more of the following information:

[0128] The distribution status of multiple control nodes;

[0129] The attack link status of multiple control nodes with puppet hosts, reflection servers, and attack targets;

[0130] The attack portraits of multiple control nodes, where the attack portraits include one or more of the attack target, attack type, attack time, and attack duration;

[0131] The distribution status of the puppet hosts associated with multiple control nodes.

[0132] Among them, the distribution status of multiple control nodes can include the distribution location, the number or proportion of different distribution locations, the involved botnet families, etc. A botnet family refers to a group of botnets with similar characteristics and using the same or similar malware. These botnets are usually developed and maintained by the same or the same group of attackers and share similar infrastructures (such as servers), communication protocols, attack methods, and technical characteristics. The distribution status of puppet hosts can also include the distribution location, the number or proportion of different distribution locations, etc.

[0133] It can be understood that each control node can be associated with multiple puppet hosts, multiple reflection servers, and multiple attack targets, so that multiple attack links between each control node and the puppet hosts, reflection servers, and attack targets can be obtained.

[0134] It should be noted that the embodiments of the present application can execute the above S11-S13 at regular intervals to obtain the latest attack detection result.

[0135] Next, in combination with Figure 2 and Figure 3 the overall system architecture of the detection method for implementing distributed denial-of-service attacks in the embodiments of the present application is introduced.

[0136] The overall system architecture of the embodiments of this application includes a control node acquisition system, a DDoS attack detection system, and a DDoS attack situation platform.

[0137] As Figure 2 shown, it is a schematic diagram of the working process of the control node acquisition system, which specifically includes:

[0138] 1. Protocol space mapping:

[0139] (1) Traffic detection: Utilize the communication traffic characteristics of the DDoS botnet to conduct network traffic detection and collection, extract the real-time communication traffic between the control node and the puppet host, and perform parsing of the control node puppet host information to obtain the node information of the latest active control node;

[0140] (2) Active scanning: Utilize the communication protocol characteristics between the control node and the puppet host to conduct active scanning and detection across the network, and perform protocol simulation interaction to obtain the node information of the accurate active control node;

[0141] 2. Open-source clue source: Unify and standardize the aggregation of Internet open-source and commercial clue sources as the information source of the third-party control node, and obtain the node information of the active control node and the information of the Trojan storage site;

[0142] 3. Honeypot cluster network collection: Deploy a simulated honeypot cluster network to collect the vulnerability attack details and Trojan storage site information in real time when the botnet spreads in the honeypot cluster network;

[0143] 4. Sample collection: Obtain the information of the Trojan storage site through the honeypot cluster network and the open-source clue source, and collect the latest Trojan sample data of the Trojan site in real time.

[0144] 5. Static configuration decryption: Perform fast automated static configuration decryption on the collected Trojan sample data, extract the node information of the control node, and transfer the Trojan samples with decryption failures to the sandbox for dynamic analysis;

[0145] 6. Dynamic sandbox analysis: Conduct dynamic network analysis and detection on the Trojan samples with failed static configuration decryption, and extract the node information of the control node;

[0146] 7. Control node information warehousing: Uniformly warehouse the node information of the control node obtained through protocol space mapping, open-source clue source, static configuration decryption, and dynamic sandbox analysis to prepare for later attack detection.

[0147] As Figure 3 shown, it is a schematic diagram of the working process of the overall system architecture, which includes the working process of the DDoS attack detection system:

[0148] 1. Issue detection instructions: Issue the node information and detection instructions of the control node from the control node library to the DDoS attack detection system;

[0149] 2. Simulated protocol detection: After receiving the DDoS attack detection system instructions, the DDoS attack detection system starts to intercept the communication instructions between the puppet host with the function of intercepting and castrating Trojans and the control node, forming a simulated protocol detection function;

[0150] 3. Intercept the instructions received by the puppet host: Intercept the communication instructions between the puppet host and the control node, and parse the communication instructions to timely master the initial attack task information of the control node and obtain the IP information of the specific reflection server node used when executing the attack;

[0151] 4. Simulate amplification reflection servers: Deploy simulated reflection servers such as MemCache, DNS, and NTP, and timely collect the amplified attack task information of the reflection, which complements the above initial attack task information;

[0152] 5. Parse the attack task information and store it in the database: Uniformly store the parsed initial attack task information and amplified attack task information in the warehouse;

[0153] 6. Parse the puppet host information and store it in the database: Detect the puppet hosts associated with the control nodes in the attack state, timely master the host information of the puppet hosts that execute the attack under the association of the control nodes, and uniformly store them in the warehouse.

[0154] Finally, aggregate and analyze the node information of each control node, the corresponding attack task information, and the host information of each associated puppet host to generate an attack detection result, and visualize it on the DDoS attack situation platform.

[0155] In the embodiments of the present application, the automated connection of multiple links under the control node acquisition system is achieved, the cost of manual intervention and manual operation is reduced, and the operation efficiency of the acquisition system is improved; the automatic interaction connection between the control node acquisition system and the DDoS detection system is achieved. The coordination automation between the DDoS detection system and the puppet host protocol hijacking and the accuracy of the puppet host protocol hijacking instruction parsing are achieved. The connection between the DDoS attack detection system and the DDoS attack detection situation platform is achieved.

[0156] Furthermore, timely aggregate and analyze the node information of the control node, and perform visual analysis; timely aggregate and analyze the DDoS attack portrait, and perform accurate traceability and visualization; timely aggregate and analyze the attack link status of the control node, puppet host, attack object, and reflection server, and perform visualization, so as to comprehensively perceive the DDoS attack state.

[0157] Exemplarily, such as Figure 4As shown in the figure, the global DDoS attack situation platform can achieve but is not limited to the following main effects:

[0158] 1. Hunt in real time for the control nodes of each DDoS botnet family distributed around the world;

[0159] 2. In real time, master the detailed information such as the attack targets, types, times, and durations of the control nodes in each region, accurately restore the attack portraits of multiple control nodes, and comprehensively perceive the DDoS attack status;

[0160] 3. In real time, master the distribution and scale status of the puppet hosts associated with the control nodes in each region, and accurately trace the DDoS attack link;

[0161] 4. It can cooperate with traffic cleaning devices to accurately trace the attack source and clean the attack traffic.

[0162] The detection method of distributed denial of service attack in the embodiments of the present application has at least the following advantages:

[0163] In the embodiments of the present application, by collecting the active control nodes of the DDoS botnet, the attack task information can be obtained by means of communication protocol hijacking, avoiding the consumption of a large amount of hardware resources by the large model algorithm to calculate and analyze the single DDoS attack status, and the two methods can form a complementary effect.

[0164] In the embodiments of the present application, the automatic interfaces of each system are connected, the detection process is highly automated, and no manual intervention is required in the middle process, reducing the labor input cost; it does not require a large system resource configuration for detection, and only needs to parse the instruction protocol to achieve the integrated detection effect, and the deployment and detection cost is relatively low.

[0165] In the embodiments of the present application, the global DDoS attack status can be detected in real time only in seconds, minimizing the DDoS attack perception time difference and improving the DDoS attack defense effect; in the case of real-time detection of the DDoS botnet executing an attack, quickly and accurately restore the DDoS attack portrait and accurately trace the DDoS attack link.

[0166] The embodiments of the present application are applicable to building a global DDoS attack detection system, including: timely perceiving DDoS attack events against domestic assets, accurately tracing the attack source, and quickly restoring the attack link; empowering and landing in the anti-DDoS attack traffic cleaning system, providing real-time and accurate DDoS attack clue information to guide the traffic cleaning system to accurately block; quickly reviewing and evaluating the risk situation and attack activity portrait status in major DDoS attack events, and achieving the purpose of high-precision joint defense and control.

[0167] Based on the same inventive concept, an embodiment of the present application further provides a detection device for distributed denial of service attacks. The principle of the device to solve the problem is similar to that of the detection method for distributed denial of service attacks in the above embodiment. Therefore, the implementation of the device can refer to the implementation of the above method, and the repeated parts will not be elaborated again.

[0168] Refer to Figure 5 As shown, a detection device 500 for distributed denial of service attacks provided by an embodiment of the present application includes:

[0169] A collection module 501, configured to collect node information of multiple active control nodes in the network. Each control node is used to control a botnet for distributed denial of service (DDoS) attacks. The node information includes address information and communication protocol information;

[0170] An interception module 502, configured to, for each control node, based on the node information of the control node, intercept communication instructions between the control node and the puppet hosts in the botnet, and parse the communication instructions to obtain corresponding attack task information, and obtain host information of each puppet host controlled by the control node;

[0171] A generation module 503, configured to perform aggregation analysis on the node information of multiple control nodes, corresponding attack task information, and host information of associated puppet hosts to generate an attack detection result.

[0172] In a possible implementation manner, the collection module 501 is specifically configured to perform one or more of the following operation steps:

[0173] According to the communication characteristics of the botnet, perform network detection in the target network to extract communication information between the corresponding control node and the corresponding puppet host, and obtain the node information of the corresponding control node according to the communication information;

[0174] Obtain the node information of the corresponding control node from an open-source clue source;

[0175] Obtain trojan repository site information, and according to the trojan repository site information, collect trojan sample data from the corresponding trojan repository in real time, and based on the collected trojan sample data, extract the node information of the corresponding control node; wherein, the trojan repository site information is obtained through at least one of an open-source clue source and a honeypot cluster network.

[0176] In a possible implementation manner, when performing network detection in the target network according to the communication characteristics of the botnet to extract communication information between the corresponding control node and the corresponding puppet host, and obtaining the node information of the corresponding control node according to the communication information, the collection module 501 is specifically configured to perform one or two of the following operation steps:

[0177] Detect the network traffic of the target network according to the communication traffic characteristics of the botnet, so as to extract the communication traffic between the corresponding control node and the corresponding zombie host, and obtain the node information of the corresponding control node according to the communication traffic;

[0178] Scan and detect the target network according to the communication protocol characteristics of the botnet, so as to extract the communication protocol information between the corresponding control node and the corresponding zombie host, and perform simulated communication with the corresponding control node according to the extracted communication protocol information to obtain the node information of the corresponding control node;

[0179] In a possible implementation manner, when extracting the node information of the corresponding control node based on the collected Trojan sample data, the acquisition module 501 is specifically used for:

[0180] When the decryption of the Trojan sample in the collected Trojan sample data is successful, the node information of the corresponding control node is extracted;

[0181] When the decryption of the Trojan sample in the collected Trojan sample data fails, perform dynamic analysis on the Trojan sample with decryption failure through a sandbox, and extract the node information of the corresponding control node.

[0182] In a possible implementation manner, when parsing the communication instruction to obtain the corresponding attack task information, the interception module 502 is specifically used for:

[0183] Parse the communication instruction to obtain the initial attack task information and the address information of the reflection server;

[0184] Based on the address information of the reflection server, obtain the reflected amplification attack task information from the reflection server;

[0185] Based on the initial attack task information and the amplification attack task information, obtain the attack task information.

[0186] In a possible implementation manner, the interception module 502 is specifically used for:

[0187] Based on the node information of the control node, intercept the first communication instruction between the control node and the zombie host with the Trojan function disabled. If the decryption of the first communication instruction is successful, obtain the first attack task information. If the decryption of the first communication instruction fails, the zombie host with the Trojan function disabled decrypts the first communication instruction to obtain the first attack task information;

[0188] Based on the node information of the control node, intercept the second communication instruction between the control node and the zombie host with the Trojan function not disabled. After the decryption of the second communication instruction is successful, obtain the second attack task information.

[0189] In a possible implementation, the device further includes a display module, configured to:

[0190] display the attack detection result in an attack detection interface, where the attack detection result includes one or more of the following information:

[0191] the distribution status of multiple control nodes;

[0192] the attack link status of multiple control nodes with the puppet host, the reflection server, and the attack target;

[0193] the attack portraits of multiple control nodes, where the attack portraits include one or more of the attack target, the attack type, the attack time, and the attack duration;

[0194] the distribution status of the puppet hosts associated with multiple control nodes.

[0195] For the convenience of description, the above parts are divided into respective modules (or units) according to functions and described separately. Of course, when implementing this application, the functions of the respective modules (or units) can be implemented in the same or multiple software or hardware.

[0196] After introducing the detection method and device for distributed denial of service attacks in the exemplary embodiments of this application, next, an electronic device according to another exemplary embodiment of this application will be introduced.

[0197] Based on the same inventive concept as the above method embodiment, an electronic device is also provided in the embodiment of this application. In this embodiment, the structure of the electronic device may be as Figure 6 shown, including a memory 601, a communication module 603, and one or more processors 602.

[0198] The memory 601 is used to store the computer program executed by the processor 602. The memory 601 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system and programs required to run the instant messaging function, etc.; the data storage area may store various instant messaging information and operation instruction sets, etc.

[0199] The memory 601 can be a volatile memory, such as a random-access memory (RAM); the memory 601 can also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or the memory 601 is any other medium that can be used to carry or store a desired computer program in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 601 can be a combination of the above memories.

[0200] The processor 602 can include one or more central processing units (CPUs) or be a digital processing unit, etc. The processor 602 is used to implement the above-described method for detecting distributed denial-of-service attacks when calling the computer program stored in the memory 601.

[0201] The communication module 603 is used to communicate with other electronic devices.

[0202] In the embodiments of the present application, the specific connection medium between the above-mentioned memory 601, communication module 603, and processor 602 is not limited. In the embodiments of the present application Figure 6 it is described that the memory 601 and the processor 602 are connected through a bus 604. The bus 604 is described by a thick line in Figure 6 The connection manners between other components are only for illustrative purposes and are not to be construed as limiting. The bus 604 can be divided into an address bus, a data bus, a control bus, etc. For ease of description, Figure 6 only a thick line is used to describe it in

[0203] The embodiments of the present application provide a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program runs on an electronic device, the computer program is used to cause the electronic device to execute the method for detecting distributed denial-of-service attacks in the above embodiments, as Figure 5 shown.

[0204] The computer-readable storage medium in the above embodiments may be any available medium or data storage device accessible by the processor in the device, including but not limited to magnetic memories such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), etc., optical memories such as CDs, DVDs, BDs, HVDs, etc., and semiconductor memories such as ROMs, EPROMs, EEPROMs, non-volatile memories (NAND FLASH), solid state drives (SSD), etc.

[0205] In some possible implementation manners, aspects of the method for scheduling attack traffic provided in the embodiments of the present application may also be implemented in the form of a computer program product, which includes a computer program. When the program product runs on an electronic device, the computer program is used to cause the electronic device to execute the steps in the method for detecting distributed denial of service attacks according to various exemplary embodiments of the present application described above in this specification. For example, the electronic device may execute the steps as Figure 1 shown in.

[0206] The computer program product may adopt any combination of one or more readable media. The readable media may be a readable signal medium or a readable storage medium. The readable storage medium may, for example, be but is not limited to an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0207] The computer program product of the embodiments of the present application may adopt a portable compact disk read-only memory (CD-ROM) and include a computer program, and may run on a communication device. However, the program product of the present application is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with a command execution system, apparatus, or device.

[0208] The readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a readable computer program. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with a command execution system, apparatus, or device.

[0209] A computer program embodied on a readable medium can be transmitted with any appropriate medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0210] A computer program for performing the operations of the present application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The computer program can be executed entirely on the user communication device, partially on the user communication device, executed as a stand-alone software package, partially on the user communication device and partially on a remote communication device, or entirely on a remote communication device or server. In the case of a remote communication device, the remote communication device can be connected to the user communication device through any type of network including a local area network (LAN) or a wide area network (WAN), or, can be connected to an external communication device (e.g., by connecting through the Internet using an Internet service provider).

[0211] It should be noted that although several units or subunits of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0212] In addition, although the operations of the method of the present application are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution.

[0213] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable computer programs.

[0214] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present application.

[0215] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.

Claims

1. A method for detecting a distributed denial of service attack, characterized in that: include: Collecting node information of multiple active control nodes in the network, each of which is used to control a botnet that attacks a distributed denial of service (DDoS), wherein the node information includes address information and communication protocol information; For each of the control nodes, based on the node information of the control node, the communication instructions between the control node and the puppet host in the botnet are intercepted, and the communication instructions are parsed to obtain the corresponding attack task information, and the host information of each of the puppet hosts controlled by the control node is obtained; The node information of the plurality of control nodes, the corresponding attack task information, and the host information of the associated puppet hosts are aggregated and analyzed to generate an attack detection result.

2. The method according to claim 1, characterized in that The step of collecting node information of multiple active control nodes in the network includes one or more of the following operation steps: According to the communication characteristics of the botnet, network detection is performed in the target network to extract communication information between the corresponding control node and the corresponding puppet host, and node information of the corresponding control node is obtained according to the communication information; Obtain node information of corresponding control nodes from open source clue sources; Obtain Trojan storage site information, and based on the Trojan storage site information, collect Trojan sample data in real time from the corresponding Trojan storage site, and extract node information of the corresponding control node based on the collected Trojan sample data; wherein the Trojan storage site information is obtained through at least one of the open source clue source and the honeypot cluster network.

3. The method according to claim 2, characterized in that The method of performing network detection in the target network according to the communication characteristics of the botnet to extract communication information between the corresponding control node and the corresponding puppet host, and obtaining node information of the corresponding control node according to the communication information, includes one or both of the following operation steps: According to the communication traffic characteristics of the botnet, the network traffic of the target network is detected to extract the communication traffic between the corresponding control node and the corresponding puppet host, and the node information of the corresponding control node is obtained according to the communication traffic; According to the communication protocol characteristics of the botnet, the target network is scanned and detected to extract the communication protocol information between the corresponding control node and the corresponding puppet host, and simulated communication is performed with the corresponding control node according to the extracted communication protocol information to obtain the node information of the corresponding control node.

4. The method according to claim 3, characterized in that The step of extracting node information of corresponding control nodes based on the collected Trojan sample data includes: When the Trojan horse sample in the collected Trojan horse sample data is decrypted successfully, the node information of the corresponding control node is extracted; When decryption of a Trojan horse sample in the collected Trojan horse sample data fails, the Trojan horse sample that fails to be decrypted is dynamically analyzed through a sandbox to extract node information of a corresponding control node.

5. The method according to claim 1, characterized in that Parse the communication instruction to obtain corresponding attack task information, including: Parsing the communication instruction to obtain initial attack task information and address information of the reflection server; Based on the address information of the reflection server, obtaining reflected amplification attack task information from the reflection server; The attack task information is obtained based on the initial attack task information and the amplified attack task information.

6. The method according to any one of claims 1 to 5, characterized in that: The method of intercepting the communication instructions between the control node and the puppet host in the botnet based on the node information of the control node, and parsing the communication instructions to obtain corresponding attack task information includes: Based on the node information of the control node, intercept the first communication instruction between the control node and the puppet host with the Trojan function castrated, if the first communication instruction is decrypted successfully, obtain the first attack task information, if the first communication instruction is decrypted unsuccessfully, decrypt the first communication instruction through the puppet host with the Trojan function castrated to obtain the first attack task information; Based on the node information of the control node, the second communication instruction between the control node and the puppet host that has not been castrated of the Trojan horse function is intercepted, and when the second communication instruction is successfully decrypted, the second attack task information is obtained.

7. The method according to any one of claims 1 to 5, characterized in that: After generating the attack detection result, the method further includes: The attack detection result is displayed in the attack detection interface, and the attack detection result includes one or more of the following information: a distribution status of a plurality of the control nodes; The attack link status of the plurality of control nodes and the puppet host, the reflection server, and the attack target; attack profiles of the plurality of control nodes, the attack profiles including one or more of attack targets, attack types, attack times, and attack durations; The distribution status of the puppet hosts associated with multiple control nodes.

8. A distributed denial of service attack detection device, characterized in that: include: A collection module, used to collect node information of multiple active control nodes in the network, each of which is used to control a botnet that attacks a distributed denial of service (DDoS), and the node information includes address information and communication protocol information; An interception module is used for intercepting the communication instructions between the control node and the puppet host in the botnet for each control node based on the node information of the control node, and parsing the communication instructions to obtain corresponding attack task information and host information of each puppet host controlled by the control node; The generating module is used to aggregate and analyze the node information of the plurality of control nodes, the corresponding attack task information, and the host information of the associated puppet hosts to generate an attack detection result.

9. An electronic device, characterized in that: It comprises a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of any one of the methods of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: It comprises a computer program. When the computer program is run on a communication device, the computer program is used to make the communication device execute the steps of any one of the methods of claims 1 to 7.

11. A computer program product, characterized in that The method comprises a computer program stored in a computer-readable storage medium; when a processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, so that the electronic device executes the steps of any one of the methods described in claims 1 to 7.

Citation Information

Cited By

  • DDoS attack object identification method, device and equipment based on security agent

    CN121333662A