DDoS attack defense method and device based on multi-layer filtering, equipment and medium
Through multi-layer filtering technology, network traffic is detected and analyzed, DDoS attacks are identified and blocked, and the problems of traditional defense methods are limited in performance and low detection accuracy when facing complex attacks are solved, achieving more efficient network security protection.
Patent Information
- Application Number
- CN202510582160.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-05-07
AI Technical Summary
Traditional DDoS defense methods have problems such as limited performance, low detection accuracy, difficulty in identifying and intercepting attack traffic that mimics normal user behavior, and slow response to update defense strategies when facing modern complex attacks.
The DDoS attack defense method based on multi-layer filtering is adopted to detect and filter the original network traffic through preset traffic detection devices, and the traffic characteristics are obtained by packet capture analysis for static matching filtering, monitoring abnormal attack patterns, distinguishing real users and attack traffic, and customizing analysis and filtering based on communication protocols, combining session status and abnormal session detection to identify and block malicious traffic.
It improves the filtering ability to deal with network attacks, effectively identify and block complex DDoS attacks, improves network security and performance, and reduces false alarms and attack risks.
Smart Images

Figure CN120200843A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a DDoS attack defense method, device, equipment and medium based on multi-layer filtering. Background Art
[0002] Denial of service attack is a kind of network attack means that has become increasingly fierce in recent years, and widely exists in various commercial competitions and hacker attacks. The attack will cause the network egress bandwidth of the target server to be congested or the server system resources to be exhausted, and it cannot provide services to the outside normally. Even more, the denial of service attack is just a means to deceive people, and the attacker will use this to hide other attack means such as penetration and APT.
[0003] Traditional DDoS defense means have many defects when facing modern complex attacks. First of all, traditional devices such as firewalls and intrusion detection systems are limited in performance when dealing with large-scale traffic, and it is difficult to cope with attacks with increasing traffic peaks year by year. Secondly, these devices mainly rely on local information for detection, and due to the concealment and dispersion of DDoS attacks, the detection accuracy is not high. In addition, traditional defense means often have difficulty in identifying and intercepting attack traffic that imitates the behavior of normal users, such as application layer attacks, because these attack traffic is similar to the characteristics of normal traffic. Finally, with the continuous evolution of attack means, traditional devices are slow in updating defense strategies and adapting to new types of attacks. These defects greatly reduce the effectiveness of traditional DDoS defense means when facing increasingly complex and diverse attacks, and it is difficult to effectively protect network security.
[0004] The above defects are worthy of improvement. Summary of the Invention
[0005] The present invention provides a DDoS attack defense method, device, equipment and medium based on multi-layer filtering, and its main purpose is to improve the filtering ability to cope with network attacks.
[0006] To achieve the above purpose, a DDoS attack defense method based on multi-layer filtering provided by the present invention includes: Detect the original network traffic through a preset traffic detection device, obtain the problem network traffic from the original network traffic, and filter the problem packets in the problem network traffic to obtain filtered network traffic; Use packet capture analysis to obtain the traffic characteristics of the filtered network traffic, obtain network traffic characteristics, and perform static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic; Monitor the static filtered network traffic, identify abnormal attack patterns in the static filtered network traffic, obtain suspected attack source addresses, perform matching verification on the suspected attack source addresses to obtain verification results, and perform false source defense blocking based on the verification results to obtain source-controlled network traffic; Obtain the client behavior characteristics and verification mechanisms in the source-controlled network traffic, and distinguish real users and attack traffic in the source-controlled network traffic based on the client behavior characteristics and verification mechanisms to obtain differentiated network traffic; Based on a preset communication protocol, perform customized analysis and filtering mechanism analysis on the differentiated network traffic, identify and block malicious traffic to obtain customized screened network traffic; By checking whether the packets in the customized screened network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection, identify and block malicious TCP connections to obtain session-screened network traffic; Detect and analyze the network traffic behavior characteristics of the session-screened network traffic, and implement preset traffic management measures to obtain standard network traffic.
[0007] Optionally, filtering the problem packets in the problem network traffic to obtain filtered network traffic includes: Perform a legality check on the packets in the problem network traffic based on a preset RFC standard, and identify vulnerability problem packets that utilize protocol vulnerabilities from them; By analyzing the characteristics of the packets in the problem network traffic, obtain identification characteristics, and match the identification characteristics with known attack characteristics to obtain specific problem packets with specific attack characteristics; Set corresponding filtering rules based on the vulnerability problem packets and specific problem packets to obtain packet filtering rules, and filter the problem network traffic according to the packet filtering rules to obtain filtered network traffic.
[0008] Optionally, the static matching filtering of the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic includes: Set static filtering rules according to the network traffic characteristics to obtain characteristic static filtering rules; Obtain the network traffic data packets in the filtered network traffic, and match the network traffic data packets with the characteristic static filtering rules to check whether the network traffic data packets meet the matching conditions of the characteristic static filtering rules; When the network traffic data packets meet the matching conditions of the characteristic static filtering rules, filter the network traffic data packets that meet the conditions to obtain static filtered network traffic, where the filtering operations include discarding and logging.
[0009] Optionally, filtering the problematic network traffic according to the packet filtering rule to obtain filtered network traffic includes: Adjusting a pre-constructed binary convolutional neural network and a one-dimensional convolutional neural network according to the packet filtering rule to obtain an adjusted binary convolutional network model and an adjusted one-dimensional convolutional network model; Using the adjusted binary convolutional network model to perform traffic situation awareness on the problematic network traffic to obtain a traffic situation awareness result; Based on the traffic situation awareness result, using the adjusted one-dimensional convolutional network model to perform feature extraction and binary classification on the detected network traffic to obtain problem features and a binary classification result, and filtering the problematic network traffic based on the problem features and the binary classification to obtain filtered network traffic.
[0010] Optionally, monitoring the statically filtered network traffic to identify an abnormal attack pattern in the statically filtered network traffic to obtain a suspected attack source address includes: Based on preset historical traffic data, establishing a network traffic model using a machine learning algorithm to obtain a historical network traffic model; Performing traffic prediction through the historical network traffic model to obtain predicted traffic; Comparing the predicted traffic with the statically filtered network traffic to identify abnormal traffic; Extracting features in the abnormal traffic and analyzing the features in the abnormal traffic to obtain abnormal attack pattern traffic; Obtaining the relevant source IP address of the abnormal attack pattern traffic to obtain a suspected attack source address.
[0011] Optionally, performing matching verification on the suspected attack source address to obtain a verification result, and performing false source defense blocking according to the verification result to obtain source-controlled network traffic includes: Obtaining a data packet of the suspected attack source address to obtain a suspected attack data packet, and using a preset source address verification technology to check whether the suspected attack source address matches the source interface of the suspected attack data packet to obtain a verification result; Blocking the traffic initiated by the suspected attack source address according to the verification result, and using a preset firewall rule or DDoS defense device to perform traffic blocking to obtain a verified false source address; Adding the verified false source address to a blacklist to obtain an updated address blacklist, and automatically blocking the packets of the verified false source address through the updated address blacklist to obtain source-controlled network traffic.
[0012] Optionally, performing customized analysis and filtering mechanism analysis on the differentiated network traffic based on a preset communication protocol, identifying and blocking malicious traffic, to obtain customized screened network traffic, including: Setting characteristic parameters for the preset communication protocol to obtain a traffic communication protocol; Extracting relevant characteristics of the traffic communication protocol to obtain traffic communication protocol characteristics, and analyzing whether the differentiated network traffic conforms to the traffic communication protocol characteristics; When the differentiated network traffic does not conform to the traffic communication protocol characteristics, constructing a malicious traffic filtering rule based on the traffic communication protocol; According to the malicious traffic filtering rule, automatically blocking and processing malicious traffic in the differentiated network traffic by using a preset automated tool to obtain customized screened network traffic.
[0013] To solve the above problems, the present invention further provides a DDoS attack defense device based on multi-layer filtering. The device includes: A traffic filtering module, configured to detect original network traffic through a preset traffic detection device, obtain problem network traffic from the original network traffic, and filter problem packets in the problem network traffic to obtain filtered network traffic; Obtaining traffic characteristics of the filtered network traffic by using packet capture analysis to obtain network traffic characteristics, and performing static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic; A defense blocking module, configured to monitor the statically filtered network traffic, identify abnormal attack patterns in the statically filtered network traffic to obtain a suspected attack source address, perform matching verification on the suspected attack source address to obtain a verification result, and perform false source defense blocking according to the verification result to obtain source-controlled network traffic; A customized screening module, configured to obtain client behavior characteristics and verification mechanisms in the source-controlled network traffic, and distinguish real users and attack traffic in the source-controlled network traffic according to the client behavior characteristics and verification mechanisms to obtain differentiated network traffic; Performing customized analysis and filtering mechanism analysis on the differentiated network traffic based on a preset communication protocol, identifying and blocking malicious traffic, to obtain customized screened network traffic; A traffic management module, configured to identify and block malicious TCP connections by checking whether packets in the customized screened network traffic match a pre-constructed session state, and combining a preset new connection rate and abnormal session detection to obtain session-screened network traffic; Detecting and analyzing network traffic behavior characteristics of the session-screened network traffic, and implementing preset traffic management measures to obtain standard network traffic.
[0014] To solve the above problems, the present invention further provides an electronic device, which includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the DDoS attack defense method based on multi-layer filtering as described above.
[0015] To solve the above problems, the present invention further provides a computer-readable storage medium, including a storage data area and a storage program area. The storage data area stores created data, and the storage program area stores a computer program; wherein, when the computer program is executed by a processor, it implements the DDoS attack defense method based on multi-layer filtering as described above.
[0016] In the embodiment of the present invention, the original network traffic is detected by a preset detection device, the problem network traffic is obtained from the original network traffic, and the problem packets in the problem network traffic are filtered to obtain filtered network traffic, realizing the primary filtering of network traffic; the traffic characteristics of the filtered network traffic are obtained by packet capture analysis to obtain network traffic characteristics, and the filtered network traffic is statically matched and filtered based on the network traffic characteristics to obtain statically filtered network traffic, realizing the filtering of network traffic based on traffic characteristics; the statically filtered network traffic is monitored to identify abnormal attack patterns in the statically filtered network traffic to obtain suspected attack source addresses, and the suspected attack source addresses are verified to obtain verification results, and false source defense blocking is performed according to the verification results to obtain source-controlled network traffic; the client behavior characteristics and verification mechanisms in the source-controlled network traffic are obtained, and the real users and attack traffic in the source-controlled network traffic are distinguished according to the client behavior characteristics and verification mechanisms to obtain distinguished network traffic; customized analysis and filtering mechanism analysis are performed on the distinguished network traffic based on a preset communication protocol to identify and block malicious traffic to obtain customized screened network traffic, realizing the filtering of malicious traffic; by checking whether the packets in the customized screened network traffic match the established session state, and combining the new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain session-screened network traffic; the session-screened network traffic is detected and analyzed for network traffic behavior characteristics, and preset traffic management measures are implemented to obtain standard network traffic. Therefore, the DDoS attack defense method, device, electronic device and computer-readable storage medium proposed by the present invention realize the effective defense of DDoS attacks and improve the filtering ability to cope with network attacks through the combination of various filtering means and continuous progression. Description of the Drawings
[0017] Figure 1 A schematic flowchart of a DDoS attack defense method based on multi - layer filtering provided by an embodiment of the present invention; Figure 2 A schematic diagram of modules of a DDoS attack defense device based on multi - layer filtering provided by an embodiment of the present invention; Figure 3 A schematic internal structure diagram of an electronic device for implementing a DDoS attack defense method based on multi - layer filtering provided by an embodiment of the present invention.
[0018] The realization, functional features and advantages of the object of the present invention will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners
[0019] It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0020] An embodiment of the present application provides a DDoS attack defense method based on multi - layer filtering. The execution subject of the DDoS attack defense method based on multi - layer filtering includes, but is not limited to, at least one of electronic devices such as a server, a terminal, etc. that can be configured to execute the method provided by the embodiment of the present application. Among them, the server can be an independent server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms. In other words, the DDoS attack defense method based on multi - layer filtering can be executed by software or hardware installed on a remote device or a server device, and the software can be a blockchain platform. The server includes, but is not limited to: a single server, a server cluster, a cloud server, or a cloud server cluster, etc.
[0021] Refer to Figure 1 As shown, it is a schematic flowchart of a DDoS attack defense method based on multi - layer filtering provided by an embodiment of the present invention. In this embodiment, the DDoS attack defense method based on multi - layer filtering includes the following steps S1 - S7: S1. Detect the original network traffic through a preset traffic detection device, obtain the problem network traffic from the original network traffic, and filter the problem packets in the problem network traffic to obtain filtered network traffic.
[0022] It is understandable that the problem packets refer to the problem packets exploiting protocol stack vulnerabilities and the problem packets of special attacks. By filtering out the problem packets of exploiting protocol stack vulnerabilities and special attacks, the network security is effectively improved, network congestion is reduced, network performance is enhanced, and data protection is strengthened, laying a foundation for subsequent security protection measures.
[0023] In the embodiments of the present invention, the original network traffic refers to all unprocessed packet flows directly received from network interfaces. These packets may come from different sources on the Internet, including legitimate user requests, normal communication data, and possible malicious traffic such as attack packets. The original network traffic contains all details of network communication, such as source IP address, destination IP address, port number, protocol type, etc., and has not undergone any form of security inspection or filtering before reaching the network security device.
[0024] Furthermore, the protocol stack vulnerability refers to a security flaw or programming error existing in the network communication protocol stack. The protocol stack refers to the set of components implementing network communication protocols. The protocol stacks work according to different layers of the OSI model or the TCP / IP model, and are responsible for tasks such as data encapsulation, transmission, routing, and decapsulation. Protocol stack vulnerabilities may occur at any layer, from the physical layer to the application layer.
[0025] Among them, the protocol stack vulnerabilities include but are not limited to buffer overflows, insufficient input validation, state management flaws, protocol implementation errors, configuration errors, encryption and authentication flaws, etc.
[0026] It should be understood that filtering the problem packets in the problem network traffic to obtain the filtered network traffic includes: Performing a legality check on the packets in the problem network traffic based on a preset RFC standard, and identifying the vulnerability problem packets exploiting protocol vulnerabilities therefrom; Obtaining an identification feature by analyzing the features of the packets in the problem network traffic, and matching the identification feature with known attack features to obtain specific problem packets with specific attack features; Setting corresponding filtering rules based on the vulnerability problem packets and the specific problem packets to obtain packet filtering rules, and filtering the problem network traffic according to the packet filtering rules to obtain the filtered network traffic.
[0027] In the embodiments of the present invention, the vulnerability problem message refers to a network message with incorrect format or abnormality. An attacker can send a network message with incorrect format or abnormality to the target system, causing the target system to make mistakes, crash, or generate abnormal behaviors when processing the vulnerability problem message. The vulnerability problem message may be carefully constructed, containing fields or data that violate network protocol regulations or exceed the normal processing range, resulting in the target system being unable to respond correctly when parsing or processing. The specific problem message does not have direct destructive behavior. The attacker probes the network structure by sending the specific problem message to prepare for subsequent sending of real attacks. Such attacks may include attacks with oversized ICMP messages, usually using ICMP messages with oversized lengths to attack the target system. When some systems receive oversized ICMP messages, due to improper processing, the system may crash or restart.
[0028] Further, the traffic detection device refers to an abnormal traffic detection device (DETECTOR). The traffic detection device supports two DDoS attack detection methods, namely deep flow inspection DFI and deep packet inspection DPI, to detect the traffic in the network in real time. When the traffic detection device discovers abnormal traffic, it will trigger an alarm according to the alarm settings and quickly and automatically divert the abnormal traffic to a preset cache device.
[0029] Further, filtering the problem network traffic according to the packet filtering rule to obtain filtered network traffic includes: Adjusting the pre-constructed binary convolutional neural network and one-dimensional convolutional neural network according to the packet filtering rule to obtain an adjusted binary convolutional network model and an adjusted one-dimensional convolutional network model; Using the adjusted binary convolutional network model to perform traffic situation awareness on the problem network traffic to obtain a traffic situation awareness result; Based on the traffic situation awareness result, using the adjusted one-dimensional convolutional network model to perform feature extraction and binary classification on the detected network traffic to obtain problem features and a binary classification result, and filtering the problem network traffic based on the problem features and binary classification to obtain filtered network traffic.
[0030] Among them, the one-dimensional convolutional neural network is responsible for the tasks in the deep detection stage, extracting features and performing binary classification tasks.
[0031] Among them, the binary convolutional neural network refers to a lightweight convolutional neural network, which is used in the detection stage of DDoS attack defense. It mainly monitors whether a DDoS attack occurs in the network, perceives changes in the traffic situation, and indirectly judges whether there is a DDoS attack in the network. It can achieve efficient monitoring and rapid alarm of network traffic while ensuring a certain accurate recognition rate.
[0032] Among them, the situation awareness result refers to the quantitative evaluation result of the traffic behavior pattern, potential threat level, or abnormal feature output after analyzing the problem network traffic through the adjusted binary convolutional neural network (BCNN).
[0033] S2. Obtain the traffic characteristics of the filtered network traffic through packet capture analysis to obtain network traffic characteristics, and perform static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic.
[0034] It can be understood that obtaining the traffic characteristics of the filtered network traffic through packet capture analysis and performing static matching filtering based on these characteristics can effectively identify and block malicious traffic, improve network security, optimize network performance, reduce false alarms, and provide accurate data support for network monitoring and security analysis.
[0035] In the embodiment of the present invention, the filtered network traffic characteristics refer to various identifiable and analyzable attributes or patterns in the filtered network traffic, which can be used to distinguish different types of traffic, identify normal traffic and abnormal traffic, or detect specific network behaviors and potential security threats.
[0036] Among them, the filtered traffic characteristics can be defined based on a variety of different parameters and criteria, such as traffic statistical characteristics, protocol characteristics, port characteristics, IP address characteristics, behavior characteristics, etc.
[0037] In the embodiment of the present invention, the static matching filtering examines the network traffic based on a predetermined rule to determine whether the data packet in the network traffic matches a certain rule in the rule table, and decides whether to allow the data packet to pass accordingly.
[0038] Further, the performing static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic includes: Set static filtering rules according to the network traffic characteristics to obtain feature static filtering rules; Obtain the network traffic data packets in the filtered network traffic, and match the network traffic data packets with the feature static filtering rules to check whether the network traffic data packets meet the matching conditions of the feature static filtering rules; When the network traffic data packets meet the matching conditions of the feature static filtering rules, filter the network traffic data packets that meet the conditions to obtain statically filtered network traffic, where the filtering operation includes discarding and logging.
[0039] In another embodiment of the present invention, when the network traffic packet meets the matching condition of the characteristic static filtering rule, the network traffic packet can be directly used as the static filtering network traffic and enter the next processing step for filtering.
[0040] Further, the obtaining of the traffic characteristics of the filtered network traffic by using packet capture analysis to obtain network traffic characteristics includes: Obtain a preset packet capture tool and configure the network interface to be monitored for the packet capture tool to obtain a configured packet capture tool; Obtain the data packets in the filtered network traffic through the configured packet capture tool, and extract the traffic characteristics in the data packets to obtain network traffic characteristics, where the traffic characteristics include protocol type, packet size, and transmission rate.
[0041] In the embodiment of the present invention, the packet capture tool refers to a software or hardware tool that is pre-selected and prepared for capturing network data packets in the network monitoring and analysis scenario, such as software packet capture tools such as Wireshark, Tcpdump, Fiddler, etc., and hardware packet capture tools such as network probes and protocol analyzers.
[0042] S3. Monitor the static filtering network traffic, identify the abnormal attack patterns in the static filtering network traffic to obtain a suspected attack source address, perform matching verification on the suspected attack source address to obtain a verification result, and perform false source defense blocking according to the verification result to obtain source-controlled network traffic.
[0043] It can be understood that by monitoring the static filtering network traffic, abnormal attack patterns are identified, thereby determining the suspected attack source address. Through the verification of these addresses, a verification result can be obtained, and false source defense blocking measures can be performed accordingly, and finally source-controlled network traffic is obtained. Effectively improves the security of the network, reduces attacks initiated by false sources, such as SYN Flood, SYN-ACK Flood, ACK Flood, etc., and also enhances the monitoring and control capabilities of abnormal behaviors of real sources.
[0044] In the embodiment of the present invention, the abnormal attack pattern refers to those patterns in network attacks that do not conform to the normal network behavior characteristics. The abnormal network attack deviates from the normal baseline of network entities and their behaviors, and specifically includes, but is not limited to, the following denial-of-service attacks, injection attacks, man-in-the-middle attacks, malware attacks, and phishing attacks.
[0045] Among them, the denial-of-service attack refers to sending a large number of requests, making the service unable to respond to the needs of legitimate users, resulting in service interruption; the injection attack refers to the attacker injecting malicious code to control or steal data, such as SQL injection, cross-site scripting attacks, etc.
[0046] In the embodiments of the present invention, the monitoring of the static filtered network traffic, identifying abnormal attack patterns in the static filtered network traffic, and obtaining a suspected attack source address includes: Based on preset historical traffic data, using a machine learning algorithm to establish a network traffic model to obtain a historical network traffic model; Performing traffic prediction through the historical network traffic model to obtain predicted traffic; Comparing the predicted traffic with the static filtered network traffic to identify abnormal traffic; Extracting the features in the abnormal traffic and analyzing the features in the abnormal traffic to obtain abnormal attack pattern traffic; Obtaining the relevant source IP address of the abnormal attack pattern traffic to obtain a suspected attack source address.
[0047] Among them, the historical network traffic model represents the normal behavior pattern of the network.
[0048] Further, the matching verification of the suspected attack source address is performed to obtain a verification result, and according to the verification result, false source defense blocking is performed to obtain source-controlled network traffic, including: Obtaining the data packet of the suspected attack source address to obtain a suspected attack data packet, and using a preset source address verification technology to check whether the suspected attack source address matches the source interface of the suspected attack data packet to obtain a verification result; Blocking the traffic initiated by the suspected attack source address according to the verification result, and using a preset firewall rule or DDoS defense device to block the traffic to obtain a verified false source address; Adding the verified false source address to the blacklist to obtain an updated address blacklist, and automatically blocking the packets of the verified false source address through the updated address blacklist to obtain source-controlled network traffic.
[0049] Among them, if the suspected attack source address does not match the source interface in the matching result of the verification result, it may be a false source address.
[0050] Further, after ensuring that the packets of the verified false source address are automatically blocked in subsequent traffic, it is also necessary to continuously monitor the network traffic and optimize the source address verification and blocking strategies to adapt to new attack patterns and network environment changes.
[0051] S4. Obtaining the client behavior characteristics and verification mechanism in the source-controlled network traffic, and distinguishing the real users and attack traffic in the source-controlled network traffic according to the client behavior characteristics and verification mechanism to obtain distinguished network traffic.
[0052] In the embodiments of the present invention, the client behavior characteristics refer to the behavior patterns and security features of terminal devices in a power monitoring system in aspects such as access, authentication, security inspection, configuration compliance, risk control, and data collection and monitoring. These characteristics jointly ensure the security, stability, and efficiency of the power monitoring system.
[0053] Furthermore, the verification mechanism refers to the technical means in the field of network security used to confirm that users, devices, or services can be correctly identified and authorized when accessing the system. By verifying the identity and permissions of the source to control the network traffic topic and its access and operations in the network system, unauthorized access and data leakage can be prevented.
[0054] Among them, the verification mechanism generally includes three links: identity authentication, authorization, and auditing, ensuring that the system only allows legitimate users to access and operate.
[0055] Furthermore, the real users refer to legitimate users who normally use network services and resources. These users usually have valid accounts and permissions, and their behaviors conform to normal business logics and usage patterns. The attack traffic refers to the network traffic initiated by malicious actors and aimed at damaging, stealing, or interfering with normal network services. Attack traffic may include various types of network attacks, such as distributed denial-of-service attacks, SQL injection, cross-site scripting attacks, malware propagation, etc.
[0056] S5. Perform customized analysis and filtering mechanism analysis on the differentiated network traffic based on a preset communication protocol, identify and block malicious traffic, and obtain customized screened network traffic.
[0057] It can be understood that by performing customized analysis and filtering on network traffic through a preset communication protocol, malicious traffic can be effectively identified and blocked, thereby enhancing network security protection, ensuring the smooth transmission of legitimate traffic, and improving network performance and data security.
[0058] In the embodiments of the present invention, the communication protocol refers to a series of rules and standards used to ensure the security, integrity, and reliability of data transmission in network communication, including but not limited to: SSL / TLS protocol, IPSec protocol, WPA / WPA2 / WPA3 protocol, DNS protocol.
[0059] Among them, the SSL / TLS protocol is used to establish a secure connection between the client and the server side to ensure data confidentiality, integrity, and authentication; the IPSec protocol is used to protect data transmission at the network layer and provide authentication, encryption, and data integrity protection.
[0060] In the embodiments of the present invention, the filtering mechanism refers to a network security technology that can analyze and screen network traffic according to preset communication protocol standards. This mechanism uses specific algorithms and rules to identify normal traffic that conforms to the protocol and potential malicious traffic, and then takes actions such as allowing, denying, or rerouting the traffic to protect the network from attacks.
[0061] Further, the customized analysis and filtering mechanism analysis of the differentiated network traffic based on the preset communication protocol, identifying and blocking malicious traffic, to obtain customized screened network traffic, includes: By setting characteristic parameters for the preset communication protocol, a traffic communication protocol is obtained; Extract relevant characteristics of the traffic communication protocol to obtain traffic communication protocol characteristics, and analyze whether the differentiated network traffic conforms to the traffic communication protocol characteristics; When the differentiated network traffic does not conform to the traffic communication protocol characteristics, a malicious traffic filtering rule is constructed based on the traffic communication protocol; According to the malicious traffic filtering rule, use a preset automated tool to automatically block and process the malicious traffic in the differentiated network traffic to obtain customized screened network traffic.
[0062] Further, after obtaining the customized screened network traffic by automatically blocking and processing the malicious traffic in the differentiated network traffic according to the malicious traffic filtering rule using a preset automated tool, the method further includes: Data analysis and feedback: Regularly evaluate the traffic analysis results, collect feedback information, and understand the effectiveness and misjudgment situation of the filtering mechanism; Rule update: Continuously update and optimize the communication protocol rules and filtering rules according to the evaluation results and changes in the network environment to improve the accuracy of malicious traffic identification and the adaptability of the filtering mechanism analysis; Model training and optimization: For traffic analysis methods using machine learning models, regularly train and optimize the model, introduce new traffic data and attack characteristics, and enhance the model's identification ability.
[0063] S6. By checking whether the packets in the customized screened network traffic match the pre-constructed session state, and combining the preset new connection rate and abnormal session detection, identify and block malicious TCP connections to obtain session-screened network traffic.
[0064] It can be understood that by checking whether the packets in the customized screened network traffic match the pre-constructed session state, malicious TCP connections disguised as normal can be effectively identified and blocked, thereby improving the security of the network and the ability to resist DDoS attacks.
[0065] In the embodiments of the present invention, the session state in a computer network refers to the current state information of a session established between two or more communication entities. This state information is typically used to track and manage ongoing network communication sessions, ensuring the orderly transmission and correct processing of data.
[0066] Further, the new connection rate refers to the number or frequency of newly established TCP connections in a network within a specific time interval, which is an important indicator for measuring network connection activities and is usually measured in terms of the number of connections established per second (ConnectionsPer Second, CPS). The abnormal session monitoring refers to a technique that identifies sessions that do not conform to normal network activity patterns by analyzing various characteristics and behaviors of TCP sessions. It not only focuses on the information of individual data packets but also considers multiple factors from the perspective of the entire session to determine whether a session is abnormal.
[0067] In the embodiments of the present invention, malicious TCP connections refer to those TCP (Transmission Control Protocol) sessions that are intended to exploit, damage, or interfere with normal services. These connections are usually initiated by attackers and include disguised sessions, abnormal traffic patterns, scanning, and probing, etc.
[0068] S7. Detect and analyze the behavior characteristics of the network traffic of the session screening, and implement preset traffic management measures to obtain standard network traffic.
[0069] It can be understood that by detecting and analyzing the behavior characteristics of the session less-selected network traffic and implementing preset traffic management measures, the network environment can be effectively purified to ensure that only normal traffic that meets security and compliance standards is allowed to be transmitted, thereby improving the security, stability, and efficiency of the network.
[0070] In the embodiments of the present invention, the traffic management measures refer to a series of strategies and technologies for identifying, controlling, and optimizing network traffic to ensure the secure and stable operation of the network. Specific measures include, but are not limited to, threshold adjustment method, feature correlation analysis method, knowledge base-based method, application of machine learning method, behavior-based anomaly detection method.
[0071] In an embodiment of the present invention, the original network traffic is detected by a preset detection device, problem network traffic is obtained from the original network traffic, and problem packets in the problem network traffic are filtered to obtain filtered network traffic, thereby realizing the initial filtering of network traffic; the traffic characteristics of the filtered network traffic are obtained by packet capture analysis to obtain network traffic characteristics, and the filtered network traffic is statically matched and filtered based on the network traffic characteristics to obtain statically filtered network traffic, thereby realizing network traffic filtering based on traffic characteristics; the statically filtered network traffic is monitored to identify abnormal attack patterns in the statically filtered network traffic to obtain suspected attack source addresses, and the suspected attack source addresses are verified to obtain verification results, and false source defense blocking is performed according to the verification results to obtain source-controlled network traffic; the client behavior characteristics and verification mechanisms in the source-controlled network traffic are obtained, and the real users and attack traffic in the source-controlled network traffic are distinguished according to the client behavior characteristics and verification mechanisms to obtain distinguished network traffic; customized analysis and filtering mechanism analysis are performed on the distinguished network traffic based on a preset communication protocol to identify and block malicious traffic to obtain customized screened network traffic, thereby realizing the filtering of malicious traffic; by checking whether the packets in the customized screened network traffic match the established session state and combining the new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain session-screened network traffic; the traffic behavior characteristics of the session-screened network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic. Therefore, the DDoS attack defense method, device, electronic device, and computer-readable storage medium based on multi-layer filtering proposed by the present invention realize the effective defense of DDoS attacks and improve the filtering ability to cope with network attacks through the combination of various filtering means and continuous progression.
[0072] As Figure 2 shown, it is a module schematic diagram of the DDoS attack defense device based on multi-layer filtering of the present invention.
[0073] The DDoS attack defense device 100 based on multi-layer filtering of the present invention can be installed in an electronic device. According to the functions achieved, the DDoS attack defense device based on multi-layer filtering may include a traffic filtering module 101, a defense blocking module 102, a customized screening module 103, and a traffic management module 104. The modules of the present invention may also be referred to as units, which refer to a series of computer program segments that can be executed by a processor of an electronic device and can complete fixed functions, and are stored in the memory of the electronic device.
[0074] In this embodiment, the functions of each module / unit are as follows: The traffic filtering module 101 is used to detect the original network traffic through a preset traffic detection device, obtain problem network traffic from the original network traffic, and filter the problem packets in the problem network traffic to obtain filtered network traffic; Use packet capture analysis to obtain the traffic characteristics of the filtered network traffic, obtain network traffic characteristics, and perform static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic; The defense blocking module 102 is used to monitor the statically filtered network traffic, identify abnormal attack patterns in the statically filtered network traffic, obtain suspected attack source addresses, perform matching verification on the suspected attack source addresses to obtain a verification result, and perform false source defense blocking according to the verification result to obtain source-controlled network traffic; The customized screening module 103 is used to obtain the client behavior characteristics and verification mechanisms in the source-controlled network traffic, and distinguish real users and attack traffic in the source-controlled network traffic according to the client behavior characteristics and verification mechanisms to obtain differentiated network traffic; Based on a preset communication protocol, perform customized analysis and filtering mechanism analysis on the differentiated network traffic, identify and block malicious traffic, and obtain customized screened network traffic; The traffic management module 104 is used to identify and block malicious TCP connections by checking whether the packets in the customized screened network traffic match a pre-constructed session state, and combining a preset new connection rate and abnormal session detection to obtain session-screened network traffic; Detect and analyze the network traffic behavior characteristics of the session-screened network traffic, and implement preset traffic management measures to obtain standard network traffic.
[0075] Specifically, each module in the DDoS attack defense device 100 based on multi-layer filtering described in the embodiments of the present invention adopts the same technical means as those Figure 1 described in the above-mentioned DDoS attack defense method based on multi-layer filtering, and can produce the same technical effects, which will not be elaborated here.
[0076] As Figure 3 shown, it is a schematic structural diagram of an electronic device for implementing the DDoS attack defense method based on multi-layer filtering of the present invention.
[0077] The electronic device may include a processor 10, a memory 11, a communication bus 12, and a communication interface 13, and may also include a computer program stored in the memory 11 and executable on the processor 10, such as a DDoS attack defense program based on multi-layer filtering.
[0078] Among them, in some embodiments, the processor 10 may be composed of an integrated circuit. For example, it may be composed of a single packaged integrated circuit, or may be composed of multiple integrated circuits with the same or different functions, including one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and combinations of various control chips, etc. The processor 10 is the control core (Control Unit) of the electronic device, connecting various components of the entire electronic device through various interfaces and circuits. By running or executing programs or modules stored in the memory 11 (such as executing a DDoS attack defense program based on multi-layer filtering, etc.), and calling data stored in the memory 11, it performs various functions of the electronic device and processes data.
[0079] The memory 11 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, mobile hard disks, multimedia cards, card-type memories (such as SD or DX memories, etc.), magnetic memories, magnetic disks, optical disks, etc. In some embodiments, the memory 11 may be an internal storage unit of the electronic device, such as the mobile hard disk of the electronic device. In some other embodiments, the memory 11 may also be an external storage device of the electronic device, such as a plug-in mobile hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the electronic device. Further, the memory 11 may also include both an internal storage unit and an external storage device of the electronic device. The memory 11 can not only be used to store application software installed on the electronic device and various types of data, such as the code of a DDoS attack defense program based on multi-layer filtering, etc., but can also be used to temporarily store data that has been output or will be output.
[0080] The communication bus 12 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. This bus can be divided into an address bus, a data bus, a control bus, etc. The bus is set to realize the connection and communication between the memory 11 and at least one processor 10, etc.
[0081] The communication interface 13 is used for communication between the above-mentioned electronic device and other devices, including a network interface and a user interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a WI-FI interface, a Bluetooth interface, etc.), which is generally used to establish a communication connection between this electronic device and other electronic devices. The user interface may be a display, an input unit (such as a keyboard), and optionally, the user interface may also be a standard wired interface or a wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch liquid crystal display, and an OLED (Organic Light-Emitting Diode) toucher, etc. Among them, the display may also be appropriately referred to as a display screen or a display unit, which is used to display the information processed in the electronic device and to display a visual user interface.
[0082] Figure 3 Only the electronic device with components is shown. Those skilled in the art can understand that Figure 3 The shown structure does not constitute a limitation on the electronic device, and it may include fewer or more components than shown, or combine certain components, or have different component arrangements.
[0083] For example, although not shown, the electronic device may further include a power source (such as a battery) for supplying power to each component. Preferably, the power source may be logically connected to the at least one processor 10 through a power management device, so as to implement functions such as charge management, discharge management, and power consumption management through the power management device. The power source may also include any components such as one or more DC or AC power sources, a recharge device, a power failure detection circuit, a power converter or an inverter, and a power status indicator. The electronic device may also include various sensors, a Bluetooth module, a Wi-Fi module, etc., which will not be elaborated here.
[0084] It should be understood that the above embodiments are only for illustration purposes and are not limited by this structure in the scope of the patent application.
[0085] The DDoS attack defense program based on multi-layer filtering stored in the memory 11 in the electronic device is a combination of multiple computer programs. When running in the processor 10, it can achieve: Detect the original network traffic through a preset traffic detection device, obtain the problem network traffic from the original network traffic, and filter the problem packets in the problem network traffic to obtain filtered network traffic; Use packet capture analysis to obtain the traffic characteristics of the filtered network traffic, obtain network traffic characteristics, and perform static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic; Monitor the static filtered network traffic, identify abnormal attack patterns in the static filtered network traffic to obtain suspected attack source addresses, perform matching verification on the suspected attack source addresses to obtain a verification result, and perform false source defense blocking according to the verification result to obtain source-controlled network traffic; Obtain the client behavior characteristics and verification mechanism in the source-controlled network traffic, and distinguish real users and attack traffic in the source-controlled network traffic according to the client behavior characteristics and verification mechanism to obtain differentiated network traffic; Based on a preset communication protocol, perform customized analysis and filtering mechanism analysis on the differentiated network traffic, identify and block malicious traffic to obtain customized screened network traffic; By checking whether the packets in the customized screened network traffic match a pre-constructed session state, and combining a preset new connection rate and abnormal session detection, identify and block malicious TCP connections to obtain session-screened network traffic; Detect and analyze the network traffic behavior characteristics of the session-screened network traffic, and implement preset traffic management measures to obtain standard network traffic.
[0086] Specifically, for the specific implementation method of the above computer program by the processor 10, reference can be made to Figure 1 the description of the relevant steps in the corresponding embodiment, which will not be elaborated here.
[0087] Furthermore, if the modules / units integrated in the electronic device are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium. The computer-readable storage medium can be volatile or non-volatile. For example, the computer-readable medium can include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard disk, a magnetic disk, an optical disc, a computer memory, a read-only memory (ROM, Read-Only Memory).
[0088] The present invention also provides a computer-readable storage medium. The readable storage medium stores a computer program, and when the computer program is executed by a processor of an electronic device, it can implement: Detect the original network traffic through a preset traffic detection device, obtain problem network traffic from the original network traffic, and filter the problem packets in the problem network traffic to obtain filtered network traffic; Use packet capture analysis to obtain the traffic characteristics of the filtered network traffic to obtain network traffic characteristics, and perform static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic; Monitor the static filtered network traffic, identify abnormal attack patterns in the static filtered network traffic to obtain suspected attack source addresses, perform matching verification on the suspected attack source addresses to obtain verification results, and perform false source defense blocking according to the verification results to obtain source-controlled network traffic; Obtain the client behavior characteristics and verification mechanisms in the source-controlled network traffic, and distinguish real users and attack traffic in the source-controlled network traffic according to the client behavior characteristics and verification mechanisms to obtain differentiated network traffic; Based on a preset communication protocol, perform customized analysis and filtering mechanism analysis on the differentiated network traffic, identify and block malicious traffic to obtain customized screened network traffic; By checking whether the packets in the customized screened network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection, identify and block malicious TCP connections to obtain session-screened network traffic; Detect and analyze the network traffic behavior characteristics of the session-screened network traffic, and implement preset traffic management measures to obtain standard network traffic.
[0089] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation.
[0090] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0091] In addition, the functional modules in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware, or in the form of hardware plus software functional modules.
[0092] For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and can be implemented in other specific forms without departing from the spirit or basic characteristics of the present invention.
[0093] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be encompassed by the present invention. Any associated drawing reference signs in the claims should not be construed as limiting the claims involved.
[0094] The blockchain referred to in the present invention is a new application mode of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanism, and encryption algorithm. Blockchain, in essence, is a decentralized database, a string of data blocks generated by using cryptographic methods. Each data block contains information about a batch of network transactions, which is used to verify the validity of the information (anti-counterfeiting) and generate the next block. The blockchain can include a blockchain underlying platform, a platform product service layer, an application service layer, etc.
[0095] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Among them, artificial intelligence (AI) is a theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use the knowledge to obtain the best results.
[0096] In addition, it is obvious that the term "including" does not exclude other units or steps, and the singular does not exclude the plural. The multiple units or devices stated in the system claims can also be implemented by one unit or device through software or hardware. Words such as "second" are used to denote names and do not indicate any particular order.
[0097] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not restrictive. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A DDoS attack defense method based on multi-layer filtering, characterized in that: The method comprises: Detecting the original network traffic through a preset traffic detection device, obtaining the problematic network traffic from the original network traffic, and filtering the problematic messages in the problematic network traffic to obtain the filtered network traffic; The flow characteristics of the filtered network flow are obtained by using packet capture analysis to obtain network flow characteristics, and static matching filtering is performed on the filtered network flow based on the network flow characteristics to obtain static filtered network flow; Monitor the static filtering network traffic, identify abnormal attack patterns in the static filtering network traffic, obtain suspected attack source addresses, perform matching verification on the suspected attack source addresses, obtain verification results, perform false source defense blocking according to the verification results, and obtain source control network traffic; Acquire client behavior characteristics and verification mechanisms in the source control network traffic, and distinguish real user and attack traffic in the source control network traffic according to the client behavior characteristics and verification mechanisms to obtain differentiated network traffic; Based on a preset communication protocol, a customized analysis and filtering mechanism analysis is performed on the differentiated network traffic to identify and block malicious traffic and obtain customized filtered network traffic; By checking whether the message in the customized filtering network traffic matches the pre-built session state, and combining the preset new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain session filtering network traffic; The session screening network traffic is detected and the network traffic behavior characteristics are analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
2. The DDoS attack defense method based on multi-layer filtering as claimed in claim 1, characterized in that: The filtering of the problematic messages in the problematic network traffic to obtain the filtered network traffic includes: Performing a legitimacy check on the messages in the problematic network traffic based on a preset RFC standard, and identifying problematic messages that exploit protocol vulnerabilities; By analyzing the features of the messages in the problematic network traffic, an identification feature is obtained, and the identification feature is matched with a known attack feature to obtain a specific problematic message with a specific attack feature; Corresponding filtering rules are set based on the vulnerability problem messages and the specific problem messages to obtain message filtering rules, and the problem network traffic is filtered according to the message filtering rules to obtain filtered network traffic.
3. The DDoS attack defense method based on multi-layer filtering as claimed in claim 1, characterized in that: The static matching filtering of the filtered network traffic based on the network traffic characteristics to obtain the static filtered network traffic includes: Setting static filtering rules according to the network traffic characteristics to obtain characteristic static filtering rules; Acquire a network traffic data packet in the filtered network traffic, and match the network traffic data packet with the characteristic static filtering rule to check whether the network traffic data packet meets the matching condition of the characteristic static filtering rule; When the network traffic data packet meets the matching condition of the characteristic static filtering rule, the network traffic data packet meeting the condition is filtered to obtain static filtered network traffic, wherein the filtering operation includes discarding and logging.
4. The DDoS attack defense method based on multi-layer filtering as claimed in claim 1, characterized in that: The filtering of the problematic network traffic according to the message filtering rule to obtain filtered network traffic includes: Adjusting the pre-constructed binary convolutional neural network and the one-dimensional convolutional neural network according to the message filtering rule to obtain an adjusted binary convolutional network model and an adjusted one-dimensional convolutional network model; Using the adjusted binary convolutional network model to perform traffic situation awareness on the problematic network traffic, and obtain a traffic situation awareness result; Based on the traffic situation awareness results, the adjusted one-dimensional convolutional network model is used to perform feature extraction and binary classification on the detected network traffic to obtain problem features and binary classification results, and the problem network traffic is filtered based on the problem features and binary classification to obtain filtered network traffic.
5. The DDoS attack defense method based on multi-layer filtering as claimed in claim 1, characterized in that: The monitoring of the static filtering network traffic, identifying abnormal attack patterns in the static filtering network traffic, and obtaining suspected attack source addresses includes: Based on the preset historical traffic data, a network traffic model is established using a machine learning algorithm to obtain a historical network traffic model; Performing traffic prediction using the historical network traffic model to obtain predicted traffic; Comparing the predicted traffic with the statically filtered network traffic to identify abnormal traffic; Extracting features from the abnormal traffic, and analyzing the features from the abnormal traffic to obtain abnormal attack pattern traffic; Obtain the relevant source IP address of the abnormal attack pattern traffic to obtain the suspected attack source address.
6. The DDoS attack defense method based on multi-layer filtering as claimed in claim 1, characterized in that: The matching verification of the suspected attack source address to obtain a verification result, and performing false source defense blocking according to the verification result to obtain source control network traffic includes: Acquire the data packet of the suspected attack source address to obtain the suspected attack data packet, and use the preset source address verification technology to check whether the suspected attack source address matches the source interface of the suspected attack data packet to obtain a verification result; According to the verification result, the traffic initiated by the attack source address is blocked, and the traffic is blocked using a preset firewall rule or DDoS defense device to obtain a verified false source address; The verified false source address is added to a blacklist to obtain an address update blacklist, and the message of the verified false source address is automatically blocked by the address update blacklist to obtain source control network traffic.
7. The DDoS attack defense method based on multi-layer filtering according to any one of claims 1 to 6, characterized in that: The customized analysis and filtering mechanism analysis of the differentiated network traffic based on the preset communication protocol, identifying and blocking malicious traffic, and obtaining customized filtered network traffic, includes: By setting characteristic parameters for the preset communication protocol, a flow communication protocol is obtained; Extracting relevant features of the traffic communication protocol to obtain traffic communication protocol features, and analyzing whether the differentiated network traffic conforms to the traffic communication protocol features; When the differentiated network traffic does not conform to the traffic communication protocol characteristics, constructing a malicious traffic filtering rule based on the traffic communication protocol; According to the malicious traffic filtering rules, a preset automation tool is used to automatically block and process the malicious traffic in the differentiated network traffic to obtain customized filtered network traffic.
8. A DDoS attack defense device based on multi-layer filtering, characterized in that: The device comprises: A traffic filtering module is used to detect the original network traffic through a preset traffic detection device, obtain the problematic network traffic from the original network traffic, and filter the problematic messages in the problematic network traffic to obtain filtered network traffic; The flow characteristics of the filtered network flow are obtained by using packet capture analysis to obtain network flow characteristics, and static matching filtering is performed on the filtered network flow based on the network flow characteristics to obtain static filtered network flow; A defense blocking module is used to monitor the static filtering network traffic, identify abnormal attack patterns in the static filtering network traffic, obtain suspected attack source addresses, and perform matching verification on the suspected attack source addresses to obtain verification results, and perform false source defense blocking according to the verification results to obtain source control network traffic; A customized screening module is used to obtain client behavior characteristics and verification mechanisms in the source control network traffic, and distinguish between real users and attack traffic in the source control network traffic according to the client behavior characteristics and verification mechanisms to obtain differentiated network traffic; Based on a preset communication protocol, a customized analysis and filtering mechanism analysis is performed on the differentiated network traffic to identify and block malicious traffic and obtain customized filtered network traffic; A traffic management module, used to identify and block malicious TCP connections by checking whether the messages in the customized filtering network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection to obtain the session filtering network traffic; The session screening network traffic is detected and the network traffic behavior characteristics are analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the DDoS attack defense method based on multi-layer filtering as described in any one of claims 1 to 7.
10. A computer-readable storage medium, comprising a data storage area and a program storage area, wherein the data storage area stores created data and the program storage area stores a computer program; wherein: When the computer program is executed by a processor, the DDoS attack defense method based on multi-layer filtering as claimed in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Service attack flow cleaning control method and device, server and storage medium
CN111131199A
Malicious traffic identification method and device, electronic equipment and storage medium
CN112054992A
Detection method for defending ddos traffic attack
CN113630394A
Malicious traffic cleaning method and device, electronic equipment and storage medium
CN116346499A
Application service refusal attack defense method, system and its program
JP2006060599A