Anti-attack method and system for path computation protocol initialization message and communication equipment
By safely authenticating the label exchange path information in the path computing protocol initialization message and adding attack identifiers when the authentication fails, the problem of the path computing protocol initialization message is solved, and effective protection of service traffic is achieved.
Patent Information
- Application Number
- CN202510297870.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-10
AI Technical Summary
In the prior art, the problem of whether the initialization packet of the path computing protocol is attacked has not been effectively solved, and there is a risk that the service traffic will be interrupted.
The initialization packets are initialized by the receiving server, and the tag exchange path information is parsed and securely authenticated. If the authentication fails, a path calculation error message is generated, an attack identifier is added to the message, and sent to the server to identify whether the message has been attacked.
Effectively identify and prevent path computing protocol initialization packets from being attacked, and avoid the risk of service traffic being interrupted.
Smart Images

Figure CN120128385A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technologies, and particularly to a method, system, and communication device for preventing attacks on path computation protocol initialization messages. Background Art
[0002] PCEP (Path Computation Element Communication Protocol) is a network communication protocol used for communication between a PCE (Path Computation Element) and a PCC (Path Computation Client), including path requests, path responses, path updates, etc. Among them, the PCE is the server side, and the PCC is the client side. PCInitiate (PCEP initialization message), that is, the path computation protocol initialization message, is used for the PCE to actively initiate the establishment of an LSP (Label Switching Path). It is actively sent by the PCE to the PCC, and a PCC creates an LSP. The LSP is a path for carrying service traffic and is used to forward service traffic.
[0003] However, in the prior art, whether the path computation protocol initialization message is attacked is not considered, and there is a risk of service traffic interruption. Summary of the Invention
[0004] Based on this, it is necessary to provide a method, system, and communication device for preventing attacks on path computation protocol initialization messages that can accurately identify whether the path computation protocol initialization message is attacked, thereby effectively preventing the risk of service traffic interruption caused by an attack on the path computation protocol initialization message for the above technical problems.
[0005] In a first aspect, this application provides a method for preventing attacks on path computation protocol initialization messages, including:
[0006] Receiving a path computation protocol initialization message sent by a server side, and parsing label switching path information from the path computation protocol initialization message;
[0007] Performing security authentication on the label switching path information;
[0008] In the case where the security authentication of the label switching path information fails, generating a path computation error message according to the authentication failure information, adding an attack identifier to the path computation error message, and sending the path computation error message to the server side so that the server side can determine whether the path computation protocol initialization message is attacked by identifying the attack identifier in the path computation error message.
[0009] In one embodiment, the security authentication of the label switching path information includes:
[0010] Comparing the label switching path information with the switching path authentication file;
[0011] When there is path information in the switching path authentication file that matches the label switching path information, it is determined that the security authentication of the label switching path information is successful;
[0012] When there is no path information in the switching path authentication file that matches the label switching path information, it is determined that the security authentication of the label switching path information fails.
[0013] In one embodiment, adding an attack identifier to the path calculation error message includes:
[0014] Determining the error object in the path calculation error message;
[0015] Setting the error type field and the error value field in the error object to a first attack identifier and a second attack identifier respectively.
[0016] In one embodiment, parsing the label switching path information from the path calculation protocol initialization message includes:
[0017] According to the path calculation protocol specification information, performing message parsing on the path calculation protocol initialization message in a preset parsing order to obtain the label switching path information.
[0018] In one embodiment, the method further includes:
[0019] When the security authentication of the label switching path information is successful, sending the label switching path information to a network device so that the network device creates a label switching path according to the label switching path information.
[0020] In a second aspect, the present application further provides an anti-attack system for a path calculation protocol initialization message, including:
[0021] A server for sending a path calculation protocol initialization message to a client;
[0022] A client for receiving the path calculation protocol initialization message sent by the server, parsing the label switching path information from the path calculation protocol initialization message; performing security authentication on the label switching path information; when the security authentication of the label switching path information fails, generating a path calculation error message according to the authentication failure information, adding an attack identifier to the path calculation error message, and sending the path calculation error message to the server;
[0023] A server, configured to receive a path calculation error message, identify whether an attack flag is added to the path calculation error message, and determine that the path calculation protocol initialization message is attacked when the attack flag is added to the path calculation error message.
[0024] In a third aspect, the present application further provides a communication device, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0025] Receive a path calculation protocol initialization message sent by the server, and parse label switching path information from the path calculation protocol initialization message;
[0026] Perform security authentication on the label switching path information;
[0027] When the security authentication of the label switching path information fails, generate a path calculation error message according to the authentication failure information, add an attack flag to the path calculation error message, and send the path calculation error message to the server, so that the server can determine whether the path calculation protocol initialization message is attacked by identifying the attack flag in the path calculation error message.
[0028] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0029] Receive a path calculation protocol initialization message sent by the server, and parse label switching path information from the path calculation protocol initialization message;
[0030] Perform security authentication on the label switching path information;
[0031] When the security authentication of the label switching path information fails, generate a path calculation error message according to the authentication failure information, add an attack flag to the path calculation error message, and send the path calculation error message to the server, so that the server can determine whether the path calculation protocol initialization message is attacked by identifying the attack flag in the path calculation error message.
[0032] In a fifth aspect, the present application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the following steps are implemented:
[0033] Receive a path calculation protocol initialization message sent by the server, and parse label switching path information from the path calculation protocol initialization message;
[0034] Perform security authentication on the label switching path information;
[0035] In the case of a failure in the security authentication of the label switched path information, a path calculation error message is generated according to the authentication failure information, an attack identifier is added to the path calculation error message, and the path calculation error message is sent to the server, so that the server can determine whether the path calculation protocol initialization message is attacked by identifying the attack identifier in the path calculation error message.
[0036] The above method, system, and communication device for preventing attacks on the path calculation protocol initialization message parse the label switched path information in the path calculation protocol initialization message sent by the server, perform security authentication on the label switched path information, and in the case of authentication failure, generate a path calculation error message according to the authentication failure information, add an attack identifier to the path calculation error message, and send the path calculation error message to the server, so that the server can determine whether the path calculation protocol initialization message is attacked by identifying the attack identifier in the path calculation error message. By performing security authentication on the label switched path information, adding an attack identifier, and reporting anomalies, the server can identify that the path calculation protocol initialization message is attacked based on the attack identifier, so as to adopt countermeasures, thereby effectively preventing the risk of service traffic interruption caused by an attack on the path calculation protocol initialization message. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for the description of the embodiments or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0038] Figure 1 FIG. is an application environment diagram of the method for preventing attacks on the path calculation protocol initialization message in an embodiment;
[0039] Figure 2 FIG. is a flowchart of the method for preventing attacks on the path calculation protocol initialization message in an embodiment;
[0040] Figure 3 FIG. is a schematic diagram of the label switched path information in an embodiment;
[0041] Figure 4 FIG. is a schematic diagram of the white list LSP information in an embodiment;
[0042] Figure 5 FIG. is a flowchart of adding an attack identifier to the path calculation error message in an embodiment;
[0043] Figure 6 FIG. is a schematic diagram of the format of the Error Object in an embodiment;
[0044] Figure 7 It is a structural block diagram of an anti - attack system for path calculation protocol initialization messages in an embodiment;
[0045] Figure 8 It is an internal structure diagram of a communication device in an embodiment. Detailed implementation manners
[0046] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0047] The anti - attack method for path calculation protocol initialization messages provided by the embodiments of the present application can be applied to an application environment as Figure 1 shown. Among them, the client 102 communicates with the server 104 through a network. The client 102 receives the path calculation protocol initialization message sent by the server 104, parses the label - switched path information from the path calculation protocol initialization message; performs security authentication on the label - switched path information; in the case where the security authentication of the label - switched path information fails, generates a path calculation error message according to the authentication failure information, adds an attack identifier to the path calculation error message, and sends the path calculation error message to the server 104, so that the server 104 can determine whether the path calculation protocol initialization message is attacked by identifying the attack identifier in the path calculation error message. Among them, the client 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and Internet of Things devices. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.
[0048] In an exemplary embodiment, as Figure 2 shown, an anti - attack method for path calculation protocol initialization messages is provided. Taking the method applied to the Figure 1 client as an example, the method includes the following steps 202 to 206. Among them:
[0049] Step 202: Receive the path calculation protocol initialization message sent by the server, and parse the label - switched path information from the path calculation protocol initialization message.
[0050] Among them, the path calculation protocol initialization message refers to the PCEP initialization message, that is, PCInitiate. The path calculation protocol initialization message is used for the PCE to actively initiate the establishment of an LSP to the PCC. The label - switched path information refers to the information related to creating a label - switched path. The label - switched path refers to the path carrying service traffic.
[0051] Optionally, after receiving the path calculation protocol initialization message sent by the server, the client parses the label switched path information from the path calculation protocol initialization message. The label switched path information is used to create a label switched path. The label switched path information specifies the forwarding method of service traffic from the ingress label switched router to the egress label switched router and is used to forward service traffic. A label switched router refers to a path node through which the label switched path passes. The label switched path information includes a label sequence composed of multiple labels. The labels are used to assign to service traffic, and each label corresponds to a label switched router. When forwarding service traffic according to the label switched path, between the ingress label switched router and the egress label switched router, the service traffic is forwarded through label switching between the labels.
[0052] Step 204: Perform security authentication on the label switched path information.
[0053] Among them, the switched path authentication file refers to the path information of the label switched path that is allowed to be established.
[0054] Optionally, obtain a pre-generated switched path authentication file, and perform security authentication on the label switched path information according to the switched path authentication file. Exemplarily, the switched path authentication file is the whitelist LSP information. Security authentication refers to identifying whether there is path information in the switched path authentication file that is consistent with the label switched path information. If it exists, the security authentication of the label switched path information is successful. If it does not exist, the security authentication of the label switched path information fails.
[0055] Step 206: In the case where the security authentication of the label switched path information fails, generate a path calculation error message according to the authentication failure information, add an attack identifier to the path calculation error message, and send the path calculation error message to the server so that the server can determine whether the path calculation protocol initialization message has been attacked by identifying the attack identifier in the path calculation error message.
[0056] Among them, the path calculation error message refers to the PCErr (Path Computation Error) message, which is an error reporting message in the PCEP protocol. The attack identifier is used to identify that the path calculation protocol initialization message has been attacked.
[0057] Optionally, in the case of failure of the label switched path information security authentication, obtain the authentication failure information. The authentication failure information may include an error type and an error value, and the error value refers to the specific reason for the error. Generate a path computation error message according to the authentication failure information and the message structure of the path computation error message. Since the label switched path information security authentication fails, it indicates that the path computation protocol initialization message has been attacked. Therefore, add an attack identifier to the path computation error message, and feedback the path computation error message with the added attack identifier to the server to notify the server that the path computation protocol initialization message has been attacked.
[0058] After receiving the path computation error message, the server also needs to confirm again whether the path computation protocol initialization message has been attacked to avoid the client sending an incorrect path computation error message. Specifically, the server parses the path computation error message to identify whether there is an attack identifier in the path computation error message. If there is an attack identifier, it is confirmed that the path computation protocol initialization message has been attacked. Then the server will adopt corresponding attack response strategies to avoid the risk of service traffic interruption caused by the attack on the path computation protocol initialization message.
[0059] Further, the method further includes: in the case of successful label switched path information security authentication, send the label switched path information to the network device. The network device creates a label switched path according to the label switched path information. The label switched path is used to forward service traffic. For example, the network device may be a router supporting MPLS (Multiprotocol Label Switching) or SR (Segment Routing) technology.
[0060] Exemplarily, the label switched path information may be as Figure 3 shown. Among them, the label switched path information includes four labels: 16002, 16003, 16004, and 16005. The four labels respectively correspond to the ingress label switched router, the first label switched router, the second label switched router, and the third label switched router. The egress label switched router is used to strip the label 16005 carried by the service traffic data packet. After creating the label switched path according to the label switched path information, the service traffic data packet can be forwarded according to the label switched path. The service traffic data packet refers to the encapsulated data packet of the service traffic.
[0061] When the service traffic data packet enters the label switching path, the ingress label switching router assigns a label 16002 to the service traffic data packet, and forwards the service traffic data packet carrying the label 16002 to the first label switching router. The first label switching router looks up the next-hop label 16003 and exchanges the label. At this time, the label carried by the service traffic data packet is changed from 16002 to 16003, and the service traffic data packet carrying the label 16003 is forwarded to the second label switching router. The second label switching router looks up the next-hop label 16004 and exchanges the label. At this time, the label carried by the service traffic data packet is changed from 16003 to 16004, and the service traffic data packet carrying the label 16004 is forwarded to the third label switching router. The third label switching router looks up the next-hop label 16005 and exchanges the label. At this time, the label carried by the service traffic data packet is changed from 16004 to 16005, and the service traffic data packet carrying the label 16005 is forwarded to the egress label switching router. The egress label switching router strips the label 16005 carried by the service traffic data packet and forwards it to the destination IP address in the original IP forwarding manner, completing the forwarding of the service traffic data packet.
[0062] In the above anti-attack method for the path computation protocol initialization message, by parsing the label switching path information in the path computation protocol initialization message sent by the server, performing security authentication on the label switching path information, in the case of authentication failure, generating a path computation error message according to the authentication failure information, adding an attack identifier to the path computation error message, and sending the path computation error message to the server, so that the server can determine whether the path computation protocol initialization message is attacked by identifying the attack identifier in the path computation error message. Through performing security authentication on the label switching path information, adding an attack identifier and reporting anomalies, the server can identify that the path computation protocol initialization message is attacked based on the attack identifier, so as to adopt countermeasures, thereby effectively preventing the risk of service traffic interruption caused by the attack on the path computation protocol initialization message.
[0063] In an exemplary embodiment, in step 202, parsing the label switching path information from the path computation protocol initialization message includes: according to the path computation protocol specification information, performing message parsing on the path computation protocol initialization message in a preset parsing order to obtain the label switching path information.
[0064] Optionally, when parsing the path computation protocol initialization message, the main basis is the path computation protocol specification information. The path computation protocol specification information refers to the specification information of PCEP. According to the path computation protocol specification information, the path computation protocol initialization message is gradually parsed in a preset parsing order to obtain the label switching path information. Among them, the preset parsing order can be the order of the message header, the message body, and the key fields.
[0065] In this embodiment, by calculating protocol specification information according to a path and parsing a path calculation protocol initialization message in a preset parsing order, label switched path information can be accurately and quickly parsed out.
[0066] In an exemplary embodiment, step 204, the security authentication of the label switched path information includes: comparing the label switched path information with a switched path authentication file; determining that the security authentication of the label switched path information is successful when there is path information in the switched path authentication file that matches the label switched path information; and determining that the security authentication of the label switched path information fails when there is no path information in the switched path authentication file that matches the label switched path information.
[0067] Compare the label switched path information with the switched path authentication file. If there is path information in the switched path authentication file that matches the label switched path information, the authentication is successful. If there is no path information in the switched path authentication file that matches the label switched path information, the authentication fails.
[0068] Exemplarily, the switched path authentication file is whitelist LSP information, and the whitelist LSP information is as Figure 4 shown. The whitelist LSP information includes 4 pieces of LSP information. Compare the label switched path information with each piece of LSP information in the whitelist LSP information.
[0069] In this embodiment, by comparing the label switched path information with the switched path authentication file to perform security authentication on the label switched path information, the security of the label switched path information can be enhanced to identify whether a path calculation protocol initialization message has been attacked.
[0070] In an exemplary embodiment, as Figure 5 shown, in step 206, adding an attack identifier to the path calculation error message includes steps 502 to 504. Among them:
[0071] Step 502, determine an error object in the path calculation error message.
[0072] Step 504, set the error type field and the error value field in the error object to a first attack identifier and a second attack identifier, respectively.
[0073] The path calculation error message includes a standard PCEP header and an Error Object. The standard PCEP header includes information such as the PCEP version, message type, message length, etc. The Error Object includes an error type and an error value, which are used to represent the category and specific reason of the error respectively. Set the error type field in the Error Object to the first attack identifier, and set the error value field to the second attack identifier.
[0074] Exemplarily, the format of the Error Object in the path calculation error message is as Figure 6 shown. Among them, Reserved represents a reserved field for implementing extended functions. Flags represents a flag field for indicating the characteristics of the Error Object. Error-Type is the error type field for representing the category of the error. Error-Value is the error value field for representing the specific reason of the error. Optional TLVs are optional TLV (Type-Length-Value) fields for representing additional error information and can be used to provide more detailed context data. Set the Error-Type field and the Error-value field in the ERROR object to FE and EF respectively to add attack identifiers in the path calculation error message.
[0075] In this embodiment, by adding special values to the error type field and the error value field in the path calculation error message, the server can accurately identify whether the path calculation protocol initialization message is attacked through the special values, so as to adopt countermeasures, effectively preventing the risk of service traffic interruption in the case of the path calculation protocol initialization message being attacked.
[0076] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are displayed in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least some of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0077] Based on the same inventive concept, an embodiment of the present application further provides an anti-attack device for a path calculation protocol initialization message for implementing the anti-attack method of the path calculation protocol initialization message involved above. The implementation solution provided by this device to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the anti-attack device for the path calculation protocol initialization message provided below can refer to the limitations on the anti-attack method of the path calculation protocol initialization message in the above text, and will not be repeated here.
[0078] In an exemplary embodiment, as Figure 7 shown, an anti-attack system for a path calculation protocol initialization message is provided, including: a server 702 and a client 704, where:
[0079] The server 702 is configured to send a path calculation protocol initialization message to the client 704.
[0080] The client 704 is configured to receive the path calculation protocol initialization message sent by the server 702, parse out label switched path information from the path calculation protocol initialization message; perform security authentication on the label switched path information; in the case where the security authentication of the label switched path information fails, generate a path calculation error message according to the authentication failure information, add an attack identifier to the path calculation error message, and send the path calculation error message to the server 702.
[0081] The server 702 is configured to receive the path calculation error message, identify whether an attack identifier is added to the path calculation error message, and in the case where an attack identifier is added to the path calculation error message, determine that the path calculation protocol initialization message is attacked.
[0082] Optionally, continuing to refer to Figure 7 , the client 704 includes a parsing module, an authentication module, and an exception reporting module. The parsing module receives the path calculation protocol initialization message sent by the server 702, parses out label switched path information from the path calculation protocol initialization message, and sends the label switched path information to the authentication module. The authentication module performs security authentication on the label switched path information, and in the case where the security authentication of the label switched path information fails, sends the authentication failure information to the exception reporting module. The exception reporting module receives the authentication failure information, generates a path calculation error message according to the authentication failure information, adds an attack identifier to the path calculation error message, and sends the path calculation error message to the server 702.
[0083] In an exemplary embodiment, the exception reporting module is further configured to determine an error object in the path calculation error message; set the error type field and the error value field in the error object to a first attack identifier and a second attack identifier, respectively.
[0084] In an exemplary embodiment, the authentication module is further configured to compare the label switched path information with the switched path authentication file; in the case where there is path information in the switched path authentication file that matches the label switched path information, it is determined that the security authentication of the label switched path information is successful; in the case where there is no path information in the switched path authentication file that matches the label switched path information, it is determined that the security authentication of the label switched path information fails.
[0085] In an exemplary embodiment, the parsing module is further configured to parse the path computation protocol initialization message according to the path computation protocol specification information in a preset parsing order to obtain the label switched path information.
[0086] In an exemplary embodiment, the authentication module is further configured to, in the case where the security authentication of the label switched path information is successful, send the label switched path information to the network device so that the network device creates a label switched path according to the label switched path information.
[0087] Each module in the above anti-attack device for the path computation protocol initialization message can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory in the computer device in software form so that the processor can call and execute the operations corresponding to the above respective modules.
[0088] In an exemplary embodiment, a communication device is provided. The communication device can be a terminal, and its internal structure diagram can be as Figure 8As shown in the figure. The communication device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the communication device is used to provide computing and control capabilities. The memory of the communication device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the communication device is used to exchange information between the processor and external devices. The communication interface of the communication device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a method for preventing attacks on path calculation protocol initialization messages. The display unit of the communication device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the communication device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the communication device, or an external keyboard, touchpad, or mouse, etc.
[0089] Those skilled in the art can understand that Figure 8 the structure shown in the figure is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the communication device to which the solution of this application is applied. The specific communication device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0090] In one embodiment, a communication device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0091] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0092] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0093] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0094] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0095] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0096] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A method for preventing attacks on path computation protocol initialization messages, characterized in that: The method comprises: Receiving a path computation protocol initialization message sent by the server, and parsing label switching path information from the path computation protocol initialization message; Performing security authentication on the label switching path information; In the case where the label switching path information security authentication fails, a path calculation error message is generated according to the authentication failure information, an attack identifier is added to the path calculation error message, and the path calculation error message is sent to the server, so that the server determines whether the path calculation protocol initialization message is attacked by identifying the attack identifier in the path calculation error message.
2. The method according to claim 1, characterized in that The performing security authentication on the label switching path information includes: Comparing the label switching path information with the switching path authentication file; In the case where there is path information in the switching path authentication file that is consistent with the label switching path information, determining that the label switching path information security authentication is successful; When there is no path information in the switching path authentication file that is consistent with the label switching path information, it is determined that the label switching path information security authentication fails.
3. The method according to claim 1, characterized in that The adding an attack identifier to the path calculation error message includes: Determining an error object in the path calculation error message; The error type field and the error value field in the error object are respectively set to the first attack identifier and the second attack identifier.
4. The method according to claim 1, characterized in that: The step of parsing the label switching path information from the path computation protocol initialization message comprises: According to the path computation protocol specification information, the path computation protocol initialization message is parsed in a preset parsing order to obtain label switching path information.
5. The method according to claim 1, characterized in that The method further comprises: When the security authentication of the label switched path information is successful, the label switched path information is sent to a network device, so that the network device creates a label switched path according to the label switched path information.
6. A path computation protocol initialization message anti-attack system, characterized in that: The system comprises: The server is used to send the path calculation protocol initialization message to the client; The client is used to receive a path computation protocol initialization message sent by a server, parse the label switching path information from the path computation protocol initialization message, perform security authentication on the label switching path information, generate a path computation error message according to the authentication failure information when the security authentication of the label switching path information fails, add an attack identifier to the path computation error message, and send the path computation error message to the server; The server is used to receive the path calculation error message, identify whether an attack identifier is added to the path calculation error message, and determine that the path calculation protocol initialization message is attacked when the attack identifier is added to the path calculation error message.
7. The system according to claim 6, characterized in that The client is further configured to determine an error object in the path calculation error message; and set an error type field and an error value field in the error object to a first attack identifier and a second attack identifier, respectively.
8. A communication device, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 5 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.