Method and device for defending DDoS attack, electronic equipment and storage medium

By building an undirected graph model and dimensionality reduction analysis, we identify and sort key nodes, solving the problem of identifying key nodes in DDoS attacks and improving the effectiveness of defense.

CN120200812APending Publication Date: 2025-06-24CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510371278.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

When defending against DDoS attacks, how to accurately identify key nodes is a technical difficulty, and it is difficult for existing technology to effectively identify and intercept malicious traffic.

Method used

By building an undirected graph model, the communication description data between nodes is obtained, communication features are generated, dimensionality reduction processing is performed, local traffic characteristics are analyzed, key nodes matching DDoS attacks are filtered, and defense resources are adjusted according to the sorting results.

Benefits of technology

It realizes the relatively accurate identification of key nodes that match local traffic characteristics with DDoS attacks, and improves the effectiveness of DDoS defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200812A_ABST
    Figure CN120200812A_ABST
Patent Text Reader

Abstract

The invention discloses a method and device for defending DDoS attacks, electronic equipment and a storage medium, and belongs to the technical field of network security, in the method, communication description data between nodes in an undirected graph is obtained, the undirected graph is established based on a topological link relation of a network, communication features of the nodes are generated according to the communication description data between the nodes, and the communication features are stored in the undirected graph; the method comprises the following steps of: performing dimension reduction processing on communication characteristics of each node, then analyzing local flow characteristics of each node according to the communication characteristics of each node after dimension reduction, screening key nodes of which the local flow characteristics are matched with the local flow characteristics when the DDoS attack occurs from each node, sorting the key nodes, and further adjusting defense resources according to a sorting result. And therefore, DDoS attacks can be defended. Therefore, the key node of which the local flow feature is matched with the local flow feature when the DDoS attack occurs can be accurately found out and defended, so that the effectiveness of DDoS defense can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technologies, and in particular, to a method, apparatus, electronic device, and storage medium for defending against DDoS attacks. Background Art

[0002] In the field of network security technologies, a distributed denial of service (DDoS) attack is a common network attack.

[0003] A DDoS attack usually paralyzes a network or a key node quickly within a short time through a large number of requests or flooding attack traffic. In addition, an attacker will deliberately attack a node with relatively scarce processing resources or a link with weak bandwidth resources. These attacks include, in addition to traditional User Datagram Protocol (UDP) attacks and Synchronize (SYN) attacks, reflection amplification attacks, slow attacks, and link flooding attacks that have emerged more widely in recent years. Even though there are various types of attacks, ultimately, the purpose of denying service is achieved by exhausting resources or bandwidth.

[0004] For DDoS attacks, intercepting malicious traffic at key nodes such as border nodes and weakly defended nodes is the most effective control method. However, in the actual defense process, how to accurately identify key nodes is a technical difficulty. Summary of the Invention

[0005] Embodiments of the present application provide a method, apparatus, electronic device, and storage medium for defending against DDoS attacks, so as to provide a method for effectively defending against DDoS attacks.

[0006] In a first aspect, embodiments of the present application provide a method for defending against DDoS attacks, including:

[0007] Obtaining communication description data between each pair of nodes in an undirected graph, where the undirected graph is established based on the topological link relationship of a network;

[0008] Generating communication characteristics of each node according to the communication description data between each pair of nodes;

[0009] Performing dimensionality reduction processing on the communication characteristics of each node;

[0010] Analyzing the local traffic characteristics of each node according to the communication characteristics of each node after dimensionality reduction;

[0011] Screening key nodes from each node whose local traffic characteristics match the local traffic characteristics during a distributed denial of service (DDoS) attack, and sorting the key nodes;

[0012] Adjust the defense resources according to the sorting result to defend against DDoS attacks.

[0013] In some embodiments, dimensionality reduction processing is performed on the communication characteristics of each node, including:

[0014] Perform dimensionality reduction processing on the communication characteristics of each node through the locally linear embedding (LLE) algorithm.

[0015] In some embodiments, performing dimensionality reduction processing on the communication characteristics of each node through the locally linear embedding (LLE) algorithm includes:

[0016] Use the communication characteristics of the neighbor nodes of each node to perform linear fitting on the communication characteristics of the node to determine the fitting parameters of the neighbor nodes for the node, where the neighbor nodes refer to the nodes whose communication characteristics are similar to the communication characteristics of the node;

[0017] Perform dimensionality reduction on the communication characteristics of each node according to the rule that the fitting parameters of the neighbor nodes for the corresponding nodes after dimensionality reduction remain unchanged.

[0018] In some embodiments, according to the communication characteristics of each node after dimensionality reduction, analyze the local traffic characteristics of each node, including:

[0019] For each node, determine the distance between the communication characteristics of the node and the communication characteristics of each neighbor node of the node after dimensionality reduction;

[0020] Determine the average value of the distances between the communication characteristics of the node and the communication characteristics of each neighbor node after dimensionality reduction as the local traffic characteristic of the node.

[0021] In some embodiments, screening key nodes from each node whose local traffic characteristics match the local traffic characteristics during a DDoS attack includes:

[0022] Determine the nodes in which the corresponding average distance is greater than a preset value as the key nodes, where the preset value is determined according to the average distance corresponding to the node where a DDoS attack occurs.

[0023] In some embodiments, the topological link relationship of the network includes the topological link relationship between Internet of Things devices.

[0024] In a second aspect, an embodiment of the present application provides a device for defending against DDoS attacks, including:

[0025] An acquisition module, configured to acquire communication description data between each node in an undirected graph, where the undirected graph is established based on the topological link relationship of the network;

[0026] A generation module, configured to generate communication characteristics of each node according to the communication description data between the nodes;

[0027] A dimensionality reduction module, configured to perform dimensionality reduction processing on the communication characteristics of each node;

[0028] An analysis module, configured to analyze the local traffic characteristics of each node according to the communication characteristics of each node after dimensionality reduction;

[0029] A screening module, configured to screen key nodes whose local traffic characteristics match the local traffic characteristics during a distributed denial of service (DDoS) attack from each node, and sort the key nodes;

[0030] An adjustment module, configured to adjust defense resources according to the sorting result to defend against DDoS attacks.

[0031] In a third aspect, an embodiment of the present application provides an electronic device, including: at least one processor, and a memory communicatively connected to the at least one processor, where:

[0032] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute any of the above methods for defending against DDoS attacks.

[0033] In a fourth aspect, an embodiment of the present application provides a storage medium, when the computer program in the storage medium is executed by a processor of an electronic device, the electronic device can execute any of the above methods for defending against DDoS attacks.

[0034] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements any of the above methods for defending against DDoS attacks.

[0035] In the embodiments of the present application, communication description data between each node in an undirected graph is obtained. The undirected graph is established based on the topological link relationship of a network. According to the communication description data between each node, communication characteristics of each node are generated, and dimensionality reduction processing is performed on the communication characteristics of each node. Then, according to the communication characteristics of each node after dimensionality reduction, the local traffic characteristics of each node are analyzed, key nodes whose local traffic characteristics match the local traffic characteristics during a DDoS attack are screened from each node, the key nodes are sorted, and further, defense resources are adjusted according to the sorting result to defend against DDoS attacks. In this way, key nodes whose local traffic characteristics match the local traffic characteristics during a DDoS attack can be found and defended more accurately, so the effectiveness of DDoS defense can be improved. Description of the Drawings

[0036] The accompanying drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0037] Figure 1 It is a schematic diagram of a DDoS attack provided by an embodiment of the present application;

[0038] Figure 2 It is a flowchart of a method for defending against DDoS attacks provided by an embodiment of the present application;

[0039] Figure 3 It is a schematic diagram of a network topology provided by an embodiment of the present application;

[0040] Figure 4 It is a schematic structural diagram of a device for defending against DDoS attacks provided by an embodiment of the present application;

[0041] Figure 5 It is a schematic hardware structure diagram of an electronic device for implementing a method for defending against DDoS attacks provided by an embodiment of the present application. Detailed implementation manners

[0042] In order to provide a method for effectively defending against DDoS attacks, embodiments of the present application provide a method, a device, an electronic device, and a storage medium for defending against DDoS attacks.

[0043] The following describes the preferred embodiments of the present application with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application and are not used to limit the present application. And, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0044] In recent years, with the continuous popularization of the fifth-generation mobile communication technology and the rapid development of the Internet of Things (IoT), more and more IoT devices have emerged in people's lives. Due to various limitations such as resources, volume, and energy consumption, these IoT devices generally have difficulty obtaining effective security protection.

[0045] See Figure 1 , Figure 1 , which is a schematic diagram of a DDoS attack provided by an embodiment of the present application. For attackers, IoT devices are extremely vulnerable to being remotely implanted with malicious programs and then controlled, becoming a botnet for launching attacks. Moreover, in addition to the damage to the IoT devices themselves, what is even more terrifying is that attackers manipulate these IoT devices to attack some servers. Therefore, security protection measures and mitigation measures against DDoS attacks are extremely urgent.

[0046] Generally, DDoS attacks paralyze the network or key nodes quickly in a short period of time through a large number of requests or flooding attack traffic. In addition, attackers will intentionally attack nodes with relatively scarce processing resources or links with weak bandwidth resources. In addition to traditional UDP attacks and SYN attacks, these attacks also include reflection amplification attacks, slow attacks, and link flooding attacks that have appeared more widely in recent years. Even though there are many types of attacks, in the final analysis, they all achieve the purpose of denial of service by exhausting resources or bandwidth.

[0047] The most effective control method for DDoS attacks is to intercept malicious traffic at key nodes such as border nodes and weakly defended nodes. If a defense mechanism can be set up at key nodes, DDoS attacks can be effectively mitigated. Therefore, it is very important to identify key nodes.

[0048] To this end, the embodiment of the present application uses graph theory to model the network scenario to obtain an undirected graph, obtains the high-dimensional communication characteristics of each node in the network through the undirected graph, reduces the dimension of the high-dimensional communication characteristics of each node, and searches for nodes with abnormal local traffic characteristics from the low-dimensional communication characteristics after dimensionality reduction, that is, key nodes that match the local traffic characteristics when a DDoS attack occurs. These nodes are the most effective interception positions, and deploying defense strategies at these nodes can better defend against DDoS attacks.

[0049] See also Figure 2 , Figure 2 A flowchart of a method for defending against DDoS attacks provided in an embodiment of the present application, the method comprising the following steps.

[0050] In step 201, communication description data between nodes in an undirected graph is obtained, and the undirected graph is established based on the topological link relationship of the network.

[0051] The nodes in the undirected graph represent devices in the network, and the edges in the undirected graph represent links between two devices. The communication description data between any two nodes is used to characterize the link status of the corresponding link, such as bandwidth, delay, packet loss rate, traffic burst rate, etc.

[0052] Furthermore, the devices in the network may or may not include IoT devices. When IoT devices are included, the topological link relationship of the network may include the topological link relationship between IoT devices.

[0053] In step 202, the communication characteristics of each node are generated according to the communication description data between each node.

[0054] For example, combine the communication description data between each node and other nodes to obtain the communication characteristics of this node. It should be noted that when this node is not directly connected to a certain other node, the corresponding communication description data cannot be obtained. When generating the communication characteristics, the corresponding position can be set to a preset value such as 0, or it can be left blank.

[0055] In step 203, perform dimensionality reduction processing on the communication characteristics of each node.

[0056] In some embodiments, the Principal Component Analysis (PCA) algorithm can be used to perform dimensionality reduction processing on the communication characteristics of each node.

[0057] In some embodiments, the Locally Linear Embedding (LLE) algorithm can be used to perform dimensionality reduction processing on the communication characteristics of each node.

[0058] Specifically, for each node, according to the communication characteristics of this node, select nodes with similar communication characteristics to it (such as a preset number of nodes with the most similar communication characteristics) from each node as neighbor nodes. Then, use the communication characteristics of each neighbor node to perform linear fitting on the communication characteristics of this node to determine the fitting parameters of each neighbor node for this node (because when a DDoS attack occurs, the traffic of the attacked node comes from its adjacent nodes, and the traffic between the attacked node and the neighbor nodes shows a linear superposition relationship). Furthermore, according to the rule that the fitting parameters of each neighbor node for the corresponding node remain unchanged (that is, the fitting relationship between the node and the adjacent node is retained), perform dimensionality reduction on the communication characteristics of each node.

[0059] Since the LLE algorithm has the characteristic of retaining local features, after performing dimensionality reduction on the communication characteristics of each node through the LLE algorithm, the nodes under DDoS attack will be more prominent (which conforms to the locality characteristic of DDoS attacks), and it is easier to analyze the key nodes that conform to the characteristics of DDoS attacks.

[0060] In step 204, analyze the local traffic characteristics of each node according to the communication characteristics of each node after dimensionality reduction.

[0061] In some embodiments, for each node, the distance between the communication characteristics of this node and each neighbor node after dimensionality reduction can be determined, and then the average value of the distances between the communication characteristics of this node and each neighbor node after dimensionality reduction is determined as the local traffic characteristic of this node.

[0062] In step 205, screen out the key nodes whose local traffic characteristics match the local traffic characteristics during DDoS attacks from each node, and sort the key nodes.

[0063] For example, nodes with the average distance corresponding to each node greater than a preset value are determined as key nodes, and the preset value is determined based on the average distance corresponding to the nodes where DDoS attacks occur. For example, the preset value is a preset multiple of the average distance corresponding to the nodes where DDoS attacks occur, such as 0.8, 1.1, etc. Then, the key nodes can be sorted according to the average distance. For example, the key nodes are sorted in descending order of the average distance.

[0064] In step 206, the defense resources are adjusted according to the sorting result to defend against DDoS attacks.

[0065] Among them, the defense resources are such as high-performance firewalls, traffic cleaning devices, load balancers, etc.

[0066] Taking the example of sorting the key nodes in descending order of the average distance, the defense resources can be allocated in the order from front to back according to the sorting to ensure that the limited defense resources can be used on the nodes that most need them, thereby improving the overall defense effect.

[0067] In the embodiments of the present application, graph theory is first used to model the network to obtain an undirected graph, and then the high-dimensional communication characteristics of each node are obtained through the undirected graph. Subsequently, the LLE algorithm is used to perform dimensionality reduction processing on the communication characteristics of each node to obtain the low-dimensional communication characteristics of each node that are helpful for discriminating DDoS attacks. With the help of the low-dimensional communication characteristics of each node, the key nodes for defense are determined from each node, and the key nodes are sorted. According to the sorting result, the corresponding defense strategy is executed at the key nodes to defend against DDoS attacks.

[0068] The above process will be introduced in detail below.

[0069] I. Undirected graph construction and data collection.

[0070] First, the topological link relationship of the network is abstracted into an undirected graph. Devices in the network, such as servers, routers, Internet of Things devices, etc., are represented as nodes in the graph, and the communication behaviors between nodes are represented as weighted edges. The weights of the edges can be defined based on parameters such as bandwidth, delay, packet loss rate, etc.

[0071] Then, network monitoring tools such as NetFlow and sFlow can be used for communication data collection to obtain the communication description data between each node in real time. Based on the communication description data between each node, the communication characteristics of each node in multiple dimensions are generated, where each dimension represents a communication characteristic, such as bandwidth, number of connections, delay, etc.

[0072] Assume that there are N nodes in the network, and each node collects M-dimensional features. Then, for node i, the M-dimensional features on the connection links with all nodes are recorded to obtain an N×M-dimensional matrix, denoted as Xi , where node i is not connected to itself by a link, and the elements in the corresponding column of X i are 0.

[0073]

[0074] where X i represents the high-dimensional communication feature of the i-th node, and F(*,*), L(*,*), P(*,*) represent information in different dimensions.

[0075] II. Dimensionality reduction by LLE algorithm.

[0076] The key idea of the LLE algorithm is to preserve the local neighborhood features in the high-dimensional space and embed these local features into a low-dimensional space, ensuring that the data after dimensionality reduction still reflects the local features of the original network. This is very suitable for analyzing DDoS attacks because DDoS attacks usually involve sudden increases in local traffic. If only the single attacked node is focused on, the traffic features of some surrounding neighbor nodes will be ignored and lost.

[0077] In specific implementation, k neighbor nodes can be selected for the i-th node according to the high-dimensional communication features of the nodes (such as traffic, delay, bandwidth, etc.) to construct the neighborhood set N(i). Neighbor selection can effectively reflect the local interaction relationship between nodes.

[0078] Then, calculate the linear reconstruction weight W ij between the i-th node and its neighbor node j. This weight represents the contribution of node j to reconstructing node i. Through these weights, the LLE algorithm attempts to approximate the i-th node by a linear combination of neighbor nodes, thereby capturing the local features in the high-dimensional space. Therefore, the optimal W ij can be obtained first in the high-dimensional space. For example, the optimal W ij is obtained through the following formula:

[0079] minimize∑ i (X i -∑ j∈N(i) W ij X j ) 2 ,

[0080] where X i represents the high-dimensional communication feature of the i-th node, X j represents the high-dimensional communication feature of the j-th neighbor node, and N(i) represents the neighborhood set of the i-th node.

[0081] The feature Y i of node i in the low-dimensional space and the feature Y jThe relationship between them still preserves the local features in the high-dimensional space. That is to say, the optimization goal is to minimize the reconstruction error of the nodes in the low-dimensional space, so as to ensure that the local features of the network can be preserved after dimensionality reduction. Therefore, the following new optimization function is constructed, where W ij is a known quantity, and what needs to be optimized is Y i and Y j :

[0082] minimize ∑ i (Y i - ∑ j∈N(i) W ij Y j ) 2 ;

[0083] where Y i is the communication feature of node i in the low-dimensional space, and Y j is the communication feature of its j-th neighbor node in the low-dimensional space.

[0084] During the dimensionality reduction process, W ij is retained in the low-dimensional space to ensure the integrity of the local features. Since DDoS attacks usually cause a sudden increase in local traffic, this can amplify these abnormal changes and provide support for subsequent anomaly detection. This means that the attacking nodes and the affected links will be more prominent after dimensionality reduction. By this method of dimensionality reduction, the characteristics of DDoS attacks can be clearly shown. For example, nodes with abnormal traffic will be more prominent in the low-dimensional space, and these nodes may be the targets of attacks or the concentration points of attack traffic. The attack paths are manifested as some high-weight links in the dimensionality reduction graph, and these links may be the main propagation paths of attack traffic.

[0085] III. Key Node Identification and Priority Ranking.

[0086] Based on the communication features of each node after dimensionality reduction, use the local traffic anomaly index formula to identify the areas where traffic anomalies are concentrated, so as to provide effective defense points and interception strategies for DDoS attack defense.

[0087] For example, calculate the local traffic feature of the i-th node according to the following formula:

[0088]

[0089] where |N(i)| represents the number of neighbor nodes of the i-th node. ||Y i - Y j || represents the distance between node i and its j-th neighbor node in the low-dimensional space. The larger the distance, the greater the feature deviation between a certain node i and its j-th neighbor node, which also means that there are more traffic anomalies between node i and its j-th neighbor, and it may be a hot spot area for DDoS attacks.

[0090] Then, nodes with local traffic characteristics greater than a preset value can be determined as key nodes, where the preset value is determined based on the local traffic characteristics of the nodes where DDoS attacks occur, and the key nodes can be sorted in descending order of local traffic characteristics, and the sorting result is the interception priority list.

[0091] IV. Dynamic Defense Strategy and Interception.

[0092] Combined with the aforementioned generated interception priority list, defense resources are effectively allocated to flexibly respond to sudden traffic increases and changes in attack paths.

[0093] By continuously monitoring traffic changes on nodes and links, potential attack behaviors (such as sudden traffic increases, connection anomalies, etc.) are detected. Once an attack is detected, the interception mechanism is immediately activated to prevent the further spread of attack traffic. In addition, when the attack mode changes (such as the attacker switching paths or changing the attack intensity), the defense strategy can also be automatically adjusted to reallocate resources.

[0094] The above process will be introduced below in combination with specific examples.

[0095] See Figure 3 , Figure 3 which is a schematic diagram of a network topology provided by an embodiment of the present application, including a total of 7 nodes A to G. Among them, node A is connected to nodes B and C, node D is connected to nodes B, C, E, and F, and node G is connected to nodes E and F.

[0096] Specifically, DDoS defense can be carried out according to the following steps.

[0097] Step 1: Periodically obtain communication description data between each pair of nodes in the undirected graph.

[0098] Among them, the undirected graph is established based on the network topology. Each node represents two devices in the network, and the communication description data between any two nodes, such as bandwidth, latency, packet loss rate, and traffic burst rate, is used to characterize the link state between the corresponding two devices.

[0099] Assume that the communication description data obtained between each pair of nodes is shown in Table 1.

[0100] Table 1

[0101] Link Bandwidth (Mbps) Latency (ms) Packet Loss Rate (%) Traffic Burst Rate (%) A - B 60 8 0.02 5 A - C 40 12 0.01 3 B - D 80 10 0.03 4 C - D 30 20 0.02 6 D - E 100 15 0.01 2 D - F 50 10 0.02 7 E - G 70 18 0.03 4 F - G 60 22 0.02 5

[0102] Step 2: Generate high-dimensional communication characteristics for each node based on the communication description data between each pair of nodes.

[0103] Among them, each node can generate an N×M-dimensional feature matrix (i.e., high-dimensional communication characteristics).

[0104] For example, the feature matrix of node A is as follows:

[0105]

[0106] Among them, other nodes such as nodes D, E, F, and G are not directly connected to A, and the elements in the corresponding columns of the feature matrix are 0.

[0107] Step 3: Select a preset number of neighbor nodes for each node.

[0108] Assume that the number of neighbors is 2, and the neighbor nodes of node A are nodes B and C, the neighbor nodes of node B are nodes A and D, the neighbor nodes of node D are nodes B and C, the neighbor nodes of node E are nodes D and G, and the adjacent nodes of node F are nodes D and G.

[0109] Step 4: Calculate the linear fitting weights of neighbor nodes for a node according to the high-dimensional communication features between each node and its neighbor nodes.

[0110] Step 5: Substitute the obtained weight coefficients into the optimization objective function in the low-dimensional space to reduce the dimensionality of the high-dimensional communication features of each node.

[0111] Assume that the communication features of each node after dimensionality reduction are: A(1.0, 1.2), B(0.8, 1.0), C(1.2, 1.4), D(0.5, 0.8), E(0.3, 0.6), F(0.6, 1.0), G(0.7, 1.1).

[0112] This means that the communication features containing multi-dimensional traffic information are reduced to abstract points on a plane coordinate system that only contain two-dimensional information of the horizontal and vertical coordinates, and the local traffic features can be calculated through these points.

[0113] Step 6: Identify and sort key nodes.

[0114] Calculate the local traffic feature of the i-th node according to the following formula:

[0115]

[0116] Among them, |N(i)| represents the number of neighbor nodes of the i-th node, Y i represents the communication feature of the i-th node after dimensionality reduction, and Y j represents the communication feature of the j-th neighbor node of the i-th node after dimensionality reduction.

[0117] If D(i) is greater than the preset value, the i-th node can be determined as a key node. After that, the key nodes can also be sorted in descending order of the local traffic feature to obtain an interception priority list.

[0118] For example, after dimensionality reduction, node D shows that it is located at the center of the low-dimensional space and has a relatively large local traffic feature, indicating that it is not only a traffic concentration point but also plays a key role in the global network structure. Additionally, after dimensionality reduction, due to its relatively large local traffic feature, node E also shows its importance in carrying a large amount of traffic. That is, nodes D and E are key nodes. Assume the sorting is {node D, node E}

[0119] Step 7, adjust the defense strategy.

[0120] According to the sorting {node D, node E}, preferentially deploy defense resources at node D. In the case of remaining defense resources, then deploy defense resources at node E, thereby effectively intercepting DDoS attacks.

[0121] In the embodiment of the present application, based on graph theory, the connection relationship of network nodes and the network traffic situation are modeled. High-dimensional traffic data in the network is obtained through the modeling result. With the help of the LLC algorithm in traditional manifold learning, the high-dimensional traffic data in the network is reduced to low-dimensional traffic data. The traffic features related to DDoS attacks are analyzed emphatically, and then key nodes are calculated based on local traffic density. A strategy for targeted interception and control of malicious traffic is carried out at these key nodes, thereby providing targeted defense objectives and interception strategies for the defense side, reducing the impact of DDoS attacks on the network, and ensuring the service availability of users.

[0122] Based on the same technical concept, the embodiment of the present application also provides a device for defending against DDoS attacks. The principle of the device for defending against DDoS attacks to solve problems is similar to the above method for defending against DDoS attacks. Therefore, the implementation of the device for defending against DDoS attacks can refer to the implementation of the method for defending against DDoS attacks, and the repeated parts will not be elaborated.

[0123] Figure 4 FIG. is a schematic structural diagram of a device for defending against DDoS attacks provided by an embodiment of the present application, including:

[0124] An acquisition module 401, configured to acquire communication description data between each node in an undirected graph, where the undirected graph is established based on the topological link relationship of the network;

[0125] A generation module 402, configured to generate communication characteristics of each node according to the communication description data between each node;

[0126] A dimensionality reduction module 403, configured to perform dimensionality reduction processing on the communication characteristics of each node;

[0127] An analysis module 404, configured to analyze the local traffic characteristics of each node according to the communication characteristics of each node after dimensionality reduction;

[0128] A screening module 405, configured to screen key nodes whose local traffic characteristics match the local traffic characteristics during a distributed denial of service (DDoS) attack from each node, and sort the key nodes;

[0129] An adjustment module 406, configured to adjust defense resources according to the sorting result to defend against DDoS attacks.

[0130] In some embodiments, the dimensionality reduction module 403 is specifically configured to:

[0131] Perform dimensionality reduction processing on the communication characteristics of each node through a locally linear embedding (LLE) algorithm.

[0132] In some embodiments, the dimensionality reduction module 403 is specifically configured to:

[0133] Use the communication characteristics of the neighbor nodes of each node to perform linear fitting on the communication characteristics of the node to determine the fitting parameters of the neighbor nodes for the node, where the neighbor nodes refer to the nodes whose communication characteristics are similar to the communication characteristics of the node;

[0134] Perform dimensionality reduction on the communication characteristics of each node according to the rule that the fitting parameters of the neighbor nodes for the corresponding nodes after dimensionality reduction remain unchanged.

[0135] In some embodiments, the analysis module 404 is specifically configured to:

[0136] For each node, determine the distance between the communication characteristics of the node after dimensionality reduction and the communication characteristics of each neighbor node of the node;

[0137] Determine the average value of the distances between the communication characteristics of the node after dimensionality reduction and the communication characteristics of each neighbor node as the local traffic characteristic of the node.

[0138] In some embodiments, the screening module 405 is specifically configured to:

[0139] Determine the nodes in which the corresponding average value of the distances is greater than a preset value as the key nodes, where the preset value is determined according to the average value of the distances corresponding to the nodes during a DDoS attack.

[0140] In some embodiments, the topological link relationship of the network includes the topological link relationship between Internet of Things devices.

[0141] In the embodiments of the present application, the division of modules is illustrative, merely a logical function division. In actual implementation, there may be other division methods. Additionally, in each embodiment of the present application, each functional module may be integrated in a processor, may exist independently physically, or two or more modules may be integrated in one module. The coupling between each module may be realized through some interfaces, and these interfaces are usually electrical communication interfaces, but mechanical interfaces or other forms of interfaces are not excluded. Therefore, the modules described as separate components may or may not be physically separated, and may be located in one place or distributed to different positions of the same or different devices. The above integrated modules may be implemented in the form of hardware or in the form of software functional modules.

[0142] After introducing the method and apparatus for defending against DDoS attacks in the exemplary embodiments of the present application, next, an electronic device according to another exemplary embodiment of the present application will be introduced.

[0143] Next, refer to Figure 5 to describe the electronic device 130 implemented according to this embodiment of the present application. Figure 5 The shown electronic device 130 is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.

[0144] As Figure 5 shown, the electronic device 130 is presented in the form of a general electronic device. The components of the electronic device 130 may include but are not limited to: the above at least one processor 131, the above at least one memory 132, and a bus 133 connecting different system components (including the memory 132 and the processor 131).

[0145] The bus 133 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a processor, or a local bus using any bus structure in a variety of bus structures.

[0146] The memory 132 may include a readable medium in the form of volatile memory, such as a random access memory (RAM) 1321 and / or a cache memory 1322, and may further include a read-only memory (ROM) 1323.

[0147] The memory 132 may further include a program / utilities 1325 having a set (at least one) of program modules 1324. Such program modules 1324 include but are not limited to: an operating system, one or more application programs, other program modules, and program data. The implementation of a network environment may be included in each or some combination of these examples.

[0148] The electronic device 130 may also communicate with one or more external devices 134 (such as a keyboard, a pointing device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 130, and / or communicate with any device that enables the electronic device 130 to communicate with one or more other electronic devices (such as a router, a modem, etc.). Such communication may be carried out through the input / output (I / O) interface 135. Moreover, the electronic device 130 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 136. As shown in the figure, the network adapter 136 communicates with other modules for the electronic device 130 through the bus 133. It should be understood that, although not shown in the figure, other hardware and / or software modules may be used in combination with the electronic device 130, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0149] In an exemplary embodiment, the electronic device of the present application may at least include at least one processor, and a memory communicatively connected to the at least one processor, wherein the memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor can execute the steps of any method for defending against DDoS attacks provided by the embodiments of the present application.

[0150] In an exemplary embodiment, a storage medium is also provided. When the computer program in the storage medium is executed by the processor of the electronic device, the electronic device can execute the above method for defending against DDoS attacks. Optionally, the storage medium may be a non-transitory computer-readable storage medium. For example, the non-transitory computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0151] In an exemplary embodiment, a computer program product is also provided. When the computer program product is executed by the electronic device, the electronic device can implement any exemplary method provided by the present application.

[0152] It should be noted that although several modules or sub-modules of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more modules described above may be embodied in one module. Conversely, the features and functions of one module described above may be further divided and embodied by multiple modules.

[0153] In addition, although the operations of the method of the present application are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the shown operations must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.

[0154] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0155] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn of the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application.

[0156] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application also includes these changes and modifications.

Claims

1. A method for defending against DDoS attacks, characterized in that: include: Acquire communication description data between nodes in an undirected graph, wherein the undirected graph is established based on a topological link relationship of a network; Generate communication characteristics of each node according to the communication description data between the nodes; Performing dimensionality reduction processing on the communication characteristics of each node; Analyze the local traffic characteristics of each node according to the communication characteristics of each node after dimensionality reduction; Selecting key nodes whose local traffic characteristics match the local traffic characteristics when a distributed denial of service (DDoS) attack occurs from each node, and sorting the key nodes; Adjust defense resources based on the sorting results to defend against DDoS attacks.

2. The method according to claim 1, characterized in that Performing dimensionality reduction processing on the communication characteristics of each node, including: The communication characteristics of each node are subjected to dimension reduction processing by means of a local linear embedding (LLE) algorithm.

3. The method according to claim 2, characterized in that The communication characteristics of each node are subjected to dimension reduction processing by using a local linear embedding (LLE) algorithm, including: Performing linear fitting on the communication characteristics of each node using the communication characteristics of the neighboring nodes of the node to determine fitting parameters of the neighboring nodes for the node, wherein the neighboring nodes refer to nodes having communication characteristics similar to the communication characteristics of the node; According to the rule that the fitting parameters of the neighbor nodes to the corresponding nodes remain unchanged after dimensionality reduction, the communication characteristics of each node are reduced in dimension.

4. The method according to any one of claims 1 to 3, characterized in that: According to the communication characteristics of each node after dimensionality reduction, the local traffic characteristics of each node are analyzed, including: For each node, determining the distance between the node and each neighboring node of the node after dimension reduction; The average value of the distances between the node and the communication features of each neighboring node after dimension reduction is determined as the local traffic feature of the node.

5. The method according to claim 4, characterized in that Select key nodes from each node whose local traffic characteristics match the local traffic characteristics when a DDoS attack occurs, including: A node whose corresponding average distance value among all nodes is greater than a preset value is determined as the key node, and the preset value is determined according to the average distance value corresponding to the node where the DDoS attack occurs.

6. The method according to claim 1, characterized in that The topological link relationship of the network includes the topological link relationship between Internet of Things devices.

7. A device for defending against DDoS attacks, characterized in that: include: An acquisition module, used to acquire communication description data between nodes in an undirected graph, wherein the undirected graph is established based on a topological link relationship of a network; A generating module, used for generating the communication characteristics of each node according to the communication description data between the nodes; A dimension reduction module, used for performing dimension reduction processing on the communication characteristics of each node; An analysis module, used to analyze the local traffic characteristics of each node according to the communication characteristics of each node after dimensionality reduction; A screening module is used to screen key nodes whose local traffic characteristics match the local traffic characteristics when a distributed denial of service DDoS attack occurs from each node, and sort the key nodes; The adjustment module is used to adjust the defense resources according to the sorting results to defend against DDoS attacks.

8. An electronic device, characterized in that: include: at least one processor, and a memory communicatively connected to the at least one processor, wherein: The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can perform the method according to any one of claims 1 to 6.

9. A storage medium, characterized in that: When the computer program in the storage medium is executed by a processor of an electronic device, the electronic device can execute the method according to any one of claims 1 to 6.

10. A computer program product, characterized in that The method comprises a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.