DDoS attack defense method, device and equipment based on multi-layer filtering and medium
By employing a multi-layered filtering method, combining traffic detection, packet capture analysis, machine learning, and communication protocol verification, abnormal traffic is identified and blocked. This method distinguishes between network traffic, real user traffic, and attack traffic, and blocks abnormal traffic. Combined with specific implementation examples, it solves the technical problem of difficulty in identification in existing technologies, providing a new technical approach that addresses the performance limitations and low detection accuracy of traditional DDoS defense methods, achieving effective defense against DDoS attacks.
Patent Information
- Application Number
- CN202510582160.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2045-05-07
AI Technical Summary
Traditional DDoS defense methods are limited in performance and have low detection accuracy when facing modern complex attacks. They are unable to identify attack traffic that mimics normal user behavior, and their defense strategies are slow to update, making it difficult to effectively protect network security.
By employing a multi-layered filtering approach, through traffic detection, packet capture analysis, machine learning, and communication protocol verification, abnormal traffic is identified and blocked, distinguishing between genuine user traffic and attack traffic. This multi-layered filtering and management approach enhances network attack filtering capabilities.
It achieves effective defense against DDoS attacks, improves network security and performance, reduces false alarms, and enhances the ability to respond to complex attacks.
Smart Images

Figure CN120200843B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, device, and medium for DDoS attack defense based on multi-layer filtering. Background Technology
[0002] Denial-of-service (DoS) attacks are a type of cyberattack that has become increasingly prevalent in recent years. They are widely used in various business competitions and hacker attacks. Attacks can cause network outbound bandwidth congestion or server system resource exhaustion, making it impossible to provide services to the outside world normally. In some cases, DoS attacks are just a cover for attackers to hide other attack methods such as penetration testing and APT attacks.
[0003] Traditional DDoS defense methods have several shortcomings when facing modern, complex attacks. First, traditional devices such as firewalls and intrusion detection systems are limited in performance when handling large-scale traffic, making it difficult to cope with attacks whose peak traffic is increasing year by year. Second, these devices mainly rely on local information for detection, which is limited by the stealth and dispersion of DDoS attacks, resulting in low detection accuracy. Furthermore, traditional defense methods often struggle to identify and block attack traffic that mimics normal user behavior, such as application-layer attacks, because these attack traffic patterns are similar to normal traffic. Finally, as attack methods continue to evolve, traditional devices are slow to update their defense strategies and adapt to new attack types. These shortcomings significantly reduce the effectiveness of traditional DDoS defense methods against increasingly complex and diverse attacks, making it difficult to effectively protect network security.
[0004] The above-mentioned shortcomings are worth improving. Summary of the Invention
[0005] This invention provides a DDoS attack defense method, device, equipment, and medium based on multi-layer filtering, the main purpose of which is to improve the filtering capability in response to network attacks.
[0006] To achieve the above objectives, this invention provides a DDoS attack defense method based on multi-layer filtering, comprising:
[0007] The original network traffic is detected by a preset traffic detection device, problematic network traffic is obtained from the original network traffic, and problematic packets in the problematic network traffic are filtered to obtain filtered network traffic.
[0008] By using packet capture analysis to obtain the traffic characteristics of the filtered network traffic, network traffic characteristics are obtained, and static matching filtering is performed on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic.
[0009] The statically filtered network traffic is monitored to identify abnormal attack patterns in the statically filtered network traffic, obtain suspected attack source addresses, and match and verify the suspected attack source addresses to obtain verification results. Based on the verification results, false source defense is blocked to obtain source control network traffic.
[0010] The client behavior characteristics and verification mechanisms in the source control network traffic are obtained, and the real user and attack traffic in the source control network traffic are distinguished based on the client behavior characteristics and verification mechanisms to obtain the distinguished network traffic;
[0011] Based on a preset communication protocol, the differentiated network traffic is subjected to customized analysis and filtering mechanism analysis to identify and block malicious traffic, thereby obtaining customized filtered network traffic.
[0012] By checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain the session filtered network traffic.
[0013] The network traffic behavior characteristics of the session filtering network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
[0014] Optionally, filtering problematic packets from the problematic network traffic to obtain filtered network traffic includes:
[0015] Based on the preset RFC standard, the legality of packets in the problematic network traffic is checked, and vulnerable packets that exploit protocol vulnerabilities are identified.
[0016] By analyzing the characteristics of packets in the problematic network traffic, identification features are obtained, and these identification features are matched with known attack features to obtain specific problematic packets with specific attack features;
[0017] Based on the vulnerability-related packets and specific problematic packets, corresponding filtering rules are set to obtain packet filtering rules. Then, the problematic network traffic is filtered according to the packet filtering rules to obtain filtered network traffic.
[0018] Optionally, the step of performing static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic includes:
[0019] Based on the network traffic characteristics, static filtering rules are set to obtain the feature-based static filtering rules;
[0020] Obtain network traffic data packets from the filtered network traffic, match the network traffic data packets with the feature static filtering rules, and check whether the network traffic data packets meet the matching conditions of the feature static filtering rules;
[0021] When the network traffic data packet meets the matching conditions of the feature static filtering rule, the network traffic data packet that meets the conditions is filtered to obtain static filtered network traffic, wherein the filtering operation includes discarding and logging.
[0022] Optionally, filtering the problematic network traffic according to the packet filtering rules to obtain filtered network traffic includes:
[0023] The pre-constructed binary convolutional neural network and one-dimensional convolutional neural network are adjusted according to the message filtering rules to obtain the adjusted binary convolutional network model and the adjusted one-dimensional convolutional network model.
[0024] The adjusted binary convolutional network model is used to perform traffic situation awareness on the problem network traffic, and the traffic situation awareness results are obtained.
[0025] Based on the traffic situation awareness results, the detected network traffic is subjected to feature extraction and binary classification using the adjusted one-dimensional convolutional network model to obtain problem features and binary classification results. Based on the problem features and binary classification, the problem network traffic is filtered to obtain filtered network traffic.
[0026] Optionally, the step of monitoring the statically filtered network traffic, identifying abnormal attack patterns in the statically filtered network traffic, and obtaining suspected attack source addresses includes:
[0027] Based on preset historical traffic data, a network traffic model is established using machine learning algorithms to obtain the historical network traffic model.
[0028] Traffic prediction is performed using the historical network traffic model to obtain the predicted traffic.
[0029] The predicted traffic is compared with the static filtering network traffic to identify abnormal traffic;
[0030] Extract features from the abnormal traffic and analyze the features to obtain abnormal attack pattern traffic;
[0031] Obtain the relevant source IP address of the traffic from the abnormal attack pattern to obtain the suspected attack source address.
[0032] Optionally, the step of matching and verifying the suspected attack source address to obtain a verification result, and then performing false source defense blocking based on the verification result to obtain source control network traffic, includes:
[0033] The data packet of the suspected attack source address is obtained, the suspected attack data packet is obtained, and the suspected attack source address is checked with a preset source address verification technology to see if the suspected attack source address matches the source interface of the suspected attack data packet, and the verification result is obtained.
[0034] Based on the verification results, traffic originating from the alleged attack source address is blocked, and preset firewall rules or DDoS defense devices are used to block the traffic, thereby verifying the false source address.
[0035] The falsified source address is added to the blacklist to obtain the address update blacklist. The packets of the falsified source address are automatically blocked through the address update blacklist to obtain source control network traffic.
[0036] Optionally, the customized analysis and filtering mechanism analysis of the differentiated network traffic based on a preset communication protocol to identify and block malicious traffic, resulting in customized filtered network traffic, includes:
[0037] By setting characteristic parameters for the preset communication protocol, a traffic communication protocol is obtained;
[0038] Extract the relevant features of the traffic communication protocol to obtain the traffic communication protocol features, and analyze whether the distinguishing network traffic conforms to the traffic communication protocol features;
[0039] When the distinguishing network traffic does not conform to the characteristics of the traffic communication protocol, a malicious traffic filtering rule is constructed based on the traffic communication protocol.
[0040] Based on the malicious traffic filtering rules, the malicious traffic in the differentiated network traffic is automatically blocked and processed using preset automated tools to obtain customized filtered network traffic.
[0041] To address the aforementioned problems, the present invention also provides a DDoS attack defense device based on multi-layer filtering, the device comprising:
[0042] The traffic filtering module is used to detect the original network traffic through a preset traffic detection device, obtain problematic network traffic from the original network traffic, and filter problematic packets in the problematic network traffic to obtain filtered network traffic.
[0043] By using packet capture analysis to obtain the traffic characteristics of the filtered network traffic, network traffic characteristics are obtained, and static matching filtering is performed on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic.
[0044] The defense and blocking module is used to monitor the static filtering network traffic, identify abnormal attack patterns in the static filtering network traffic, obtain suspected attack source addresses, match and verify the suspected attack source addresses, obtain verification results, and perform false source defense and blocking based on the verification results to obtain source control network traffic.
[0045] A customized filtering module is used to obtain client behavior characteristics and verification mechanisms in the source control network traffic, and to distinguish real user traffic and attack traffic in the source control network traffic based on the client behavior characteristics and verification mechanisms, thereby obtaining differentiated network traffic;
[0046] Based on a preset communication protocol, the differentiated network traffic is subjected to customized analysis and filtering mechanism analysis to identify and block malicious traffic, thereby obtaining customized filtered network traffic.
[0047] The traffic management module is used to identify and block malicious TCP connections by checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection to obtain the session filtered network traffic.
[0048] The network traffic behavior characteristics of the session filtering network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
[0049] To address the above problems, the present invention also provides an electronic device, the electronic device comprising:
[0050] At least one processor; and,
[0051] A memory communicatively connected to the at least one processor; wherein,
[0052] The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the multi-layer filtering-based DDoS attack defense method as described above.
[0053] To address the aforementioned problems, the present invention also provides a computer-readable storage medium, comprising a data storage area and a program storage area, wherein the data storage area stores created data and the program storage area stores a computer program; wherein, when the computer program is executed by a processor, it implements the multi-layer filtering-based DDoS attack defense method described above.
[0054] This invention employs a pre-set detection device to detect raw network traffic, extract problematic network traffic from it, and filter out problematic packets within this traffic to obtain filtered network traffic, achieving initial network traffic filtering. Packet capture analysis is then used to obtain the traffic characteristics of the filtered network traffic, and static matching filtering is performed based on these characteristics to obtain static filtered network traffic, achieving network traffic filtering based on traffic characteristics. The static filtered network traffic is monitored to identify abnormal attack patterns, obtain suspected attack source addresses, and verify these addresses to obtain verification results. Based on these verification results, false source defense and blocking are implemented to achieve source control. The method involves several steps: acquiring client behavior characteristics and verification mechanisms from the source control network traffic; distinguishing between genuine user and attack traffic based on these characteristics and mechanisms to obtain differentiated network traffic; performing customized analysis and filtering mechanisms on the differentiated network traffic according to a preset communication protocol to identify and block malicious traffic, resulting in customized filtered network traffic for malicious traffic filtering; checking whether packets in the customized filtered network traffic match established session states, and combining new connection rates and abnormal session detection to identify and block malicious TCP connections, resulting in session filtered network traffic; detecting and analyzing the network traffic behavior characteristics of the session filtered network traffic, and implementing preset traffic management measures to obtain standard network traffic. Therefore, the multi-layered filtering-based DDoS attack defense method, device, electronic device, and computer-readable storage medium proposed in this invention, through a combination of multiple filtering methods and continuous advancement, achieves effective DDoS attack defense and enhances the filtering capability against network attacks. Attached Figure Description
[0055] Figure 1 This is a flowchart illustrating a DDoS attack defense method based on multi-layer filtering, provided in an embodiment of the present invention.
[0056] Figure 2 A schematic diagram of a DDoS attack defense device based on multi-layer filtering provided in an embodiment of the present invention;
[0057] Figure 3 This is a schematic diagram of the internal structure of an electronic device that implements a multi-layer filtering-based DDoS attack defense method according to an embodiment of the present invention.
[0058] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0059] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0060] This application provides a DDoS attack defense method based on multi-layer filtering. The executing entity of the multi-layer filtering DDoS attack defense method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. The server can be a standalone server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms. In other words, the multi-layer filtering DDoS attack defense method can be executed by software or hardware installed on remote devices or server-side devices, and the software can be a blockchain platform. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster.
[0061] Reference Figure 1 The diagram shown is a flowchart illustrating a DDoS attack defense method based on multi-layer filtering according to an embodiment of the present invention. In this embodiment, the DDoS attack defense method based on multi-layer filtering includes the following steps S1-S7:
[0062] S1. The original network traffic is detected by a preset traffic detection device, the problematic network traffic is obtained from the original network traffic, and the problematic packets in the problematic network traffic are filtered to obtain the filtered network traffic.
[0063] Understandably, the problematic packets refer to problematic packets that exploit protocol stack vulnerabilities and problematic packets that employ special attacks. By filtering out problematic packets that exploit protocol stack vulnerabilities and problematic packets that employ special attacks, network security is effectively improved, network congestion is reduced, network performance is enhanced, and data protection is strengthened, laying the foundation for subsequent security measures.
[0064] In this embodiment of the invention, the raw network traffic refers to all data packet streams received directly from the network interface without any processing. These data packets may originate from various sources on the Internet, including legitimate user requests, normal communication data, and potentially malicious traffic, such as attack packets. Raw network traffic contains all the details of network communication, such as source IP address, destination IP address, port number, protocol type, etc., and has not undergone any form of security inspection or filtering before reaching the network security device.
[0065] Furthermore, the aforementioned protocol stack vulnerability refers to a security flaw or programming error existing in the network communication protocol stack. A protocol stack is a collection of components that implement network communication protocols. These components operate at different layers according to the OSI model or TCP / IP model, responsible for tasks such as data encapsulation, transmission, routing, and decapsulation. Protocol stack vulnerabilities can occur at any layer, from the physical layer to the application layer.
[0066] The protocol stack vulnerabilities mentioned include, but are not limited to, buffer overflows, insufficient input validation, state management defects, protocol implementation errors, configuration errors, encryption and authentication defects, etc.
[0067] It should be understood that filtering problematic packets from the problematic network traffic to obtain filtered network traffic includes:
[0068] Based on the preset RFC standard, the legality of packets in the problematic network traffic is checked, and vulnerable packets that exploit protocol vulnerabilities are identified.
[0069] By analyzing the characteristics of packets in the problematic network traffic, identification features are obtained, and these identification features are matched with known attack features to obtain specific problematic packets with specific attack features;
[0070] Based on the vulnerability-related packets and specific problematic packets, corresponding filtering rules are set to obtain packet filtering rules. Then, the problematic network traffic is filtered according to the packet filtering rules to obtain filtered network traffic.
[0071] In this embodiment of the invention, the vulnerability issue message refers to a network message with an incorrect or abnormal format. By sending such messages to the target system, attackers can cause the target system to malfunction, crash, or exhibit abnormal behavior when processing the vulnerability issue message. Vulnerability issue messages may be carefully crafted, containing fields or data that violate network protocol regulations or exceed normal processing limits, causing the target system to be unable to respond correctly during parsing or processing. These specific issue messages do not possess direct destructive behavior; attackers send them to probe the network structure, preparing for a subsequent real attack. Such attacks may include oversized ICMP message attacks, which typically use excessively long ICMP messages to attack the target system. Some systems, upon receiving oversized ICMP messages, may experience system crashes or restarts due to improper handling.
[0072] Furthermore, the traffic detection device refers to an abnormal traffic detection device (DETECTOR). The traffic detection device supports two DDoS attack detection methods: Deep Flow Detection (DFI) and Deep Packet Inspection (DPI). It detects traffic in the network in real time. When the traffic detection device detects abnormal traffic, it will trigger an alarm according to the alarm settings and quickly and automatically redirect the abnormal traffic to a preset cache device.
[0073] Further, the step of filtering the problematic network traffic according to the packet filtering rules to obtain filtered network traffic includes:
[0074] The pre-constructed binary convolutional neural network and one-dimensional convolutional neural network are adjusted according to the message filtering rules to obtain the adjusted binary convolutional network model and the adjusted one-dimensional convolutional network model.
[0075] The adjusted binary convolutional network model is used to perform traffic situation awareness on the problem network traffic, and the traffic situation awareness results are obtained.
[0076] Based on the traffic situation awareness results, the detected network traffic is subjected to feature extraction and binary classification using the adjusted one-dimensional convolutional network model to obtain problem features and binary classification results. Based on the problem features and binary classification, the problem network traffic is filtered to obtain filtered network traffic.
[0077] Among them, the one-dimensional convolutional neural network is responsible for the deep detection stage, extracting features and performing binary classification tasks.
[0078] Among them, binary convolutional neural networks refer to a lightweight convolutional neural network used in the detection phase of DDoS attack defense. It mainly monitors whether DDoS attacks occur in the network, senses changes in traffic patterns, and indirectly determines whether there are DDoS attacks in the network. It can achieve efficient monitoring and rapid alarm of network traffic while ensuring a certain accuracy rate.
[0079] Among them, situational awareness results refer to the quantitative assessment results on traffic behavior patterns, potential threat levels, or abnormal characteristics output after analyzing the traffic of the problematic network through an adjusted binary convolutional neural network (BCNN).
[0080] S2. Use packet capture analysis to obtain the traffic characteristics of the filtered network traffic, obtain network traffic characteristics, and perform static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic.
[0081] Understandably, by using packet capture analysis to obtain the traffic characteristics of filtered network traffic and performing static matching filtering based on these characteristics, malicious traffic can be effectively identified and blocked, network security can be improved, network performance can be optimized, false alarms can be reduced, and accurate data support can be provided for network monitoring and security analysis.
[0082] In this embodiment of the invention, the network traffic filtering features refer to various identifiable and analyzable attributes or patterns in the filtered network traffic. These features can be used to distinguish different types of traffic, identify normal traffic from abnormal traffic, or detect specific network behaviors and potential security threats.
[0083] The filtered traffic characteristics can be defined based on various parameters and standards, such as traffic statistics characteristics, protocol characteristics, port characteristics, IP address characteristics, and behavioral characteristics.
[0084] In this embodiment of the invention, the static matching filter examines network traffic based on predetermined rules to determine whether a data packet in the network traffic matches a rule in the rule table, and decides whether to allow the data packet to pass accordingly.
[0085] Further, the step of performing static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic includes:
[0086] Based on the network traffic characteristics, static filtering rules are set to obtain the feature-based static filtering rules;
[0087] Obtain network traffic data packets from the filtered network traffic, match the network traffic data packets with the feature static filtering rules, and check whether the network traffic data packets meet the matching conditions of the feature static filtering rules;
[0088] When the network traffic data packet meets the matching conditions of the feature static filtering rule, the network traffic data packet that meets the conditions is filtered to obtain static filtered network traffic, wherein the filtering operation includes discarding and logging.
[0089] In another embodiment of the present invention, when the network traffic data packet meets the matching conditions of the feature static filtering rule, the network traffic data packet can be directly used as statically filtered network traffic and enter the next processing step for filtering.
[0090] Furthermore, the step of obtaining network traffic characteristics by using packet capture analysis includes:
[0091] Obtain a preset packet capture tool and configure the network interface to be monitored for the packet capture tool to obtain a configured packet capture tool;
[0092] The packet capture tool is configured to capture data packets in the filtered network traffic, and the traffic characteristics in the data packets are extracted to obtain network traffic characteristics, wherein the traffic characteristics include protocol type, data packet size and transmission rate.
[0093] In this embodiment of the invention, the packet capture tool refers to a software or hardware tool that is pre-selected and prepared for capturing network data packets in a network monitoring and analysis scenario, such as software packet capture tools like Wireshark, Tcpdump, and Fiddler, as well as hardware packet capture tools like network probes and protocol analyzers.
[0094] S3. Monitor the statically filtered network traffic, identify abnormal attack patterns in the statically filtered network traffic, obtain suspected attack source addresses, and perform matching verification on the suspected attack source addresses to obtain verification results. Based on the verification results, perform false source defense blocking to obtain source control network traffic.
[0095] Understandably, by monitoring statically filtered network traffic, abnormal attack patterns can be identified, thereby determining the suspected attack source addresses. Verification of these addresses yields verification results, which are then used to implement decoy source defense and blocking measures, ultimately controlling network traffic originating from the source. This effectively improves network security, reduces attacks initiated from decoy sources such as SYN Flood, SYN-ACK Flood, and ACK Flood, while also enhancing the monitoring and control capabilities for abnormal behavior from genuine sources.
[0096] In this embodiment of the invention, the abnormal attack mode refers to those network attack patterns that do not conform to the characteristics of normal network behavior. The abnormal network attack deviates from the normal baseline of network entities and their behavior, and specifically includes, but is not limited to, the following denial-of-service attacks, injection attacks, man-in-the-middle attacks, malware attacks, and phishing attacks.
[0097] Denial-of-service attacks refer to sending a large number of requests, making the service unable to respond to the needs of legitimate users, thus causing service interruption; injection attacks refer to attackers injecting malicious code to control or steal data, such as SQL injection and cross-site scripting attacks.
[0098] In this embodiment of the invention, monitoring the statically filtered network traffic, identifying abnormal attack patterns in the statically filtered network traffic, and obtaining suspected attack source addresses includes:
[0099] Based on preset historical traffic data, a network traffic model is established using machine learning algorithms to obtain the historical network traffic model.
[0100] Traffic prediction is performed using the historical network traffic model to obtain the predicted traffic.
[0101] The predicted traffic is compared with the static filtering network traffic to identify abnormal traffic;
[0102] Extract features from the abnormal traffic and analyze the features to obtain abnormal attack pattern traffic;
[0103] Obtain the relevant source IP address of the traffic from the abnormal attack pattern to obtain the suspected attack source address.
[0104] The historical network traffic model represents the normal behavior pattern of the network.
[0105] Further, the process of matching and verifying the suspected attack source address to obtain a verification result, and then blocking the false source based on the verification result to obtain the source control network traffic, includes:
[0106] The data packet of the suspected attack source address is obtained, the suspected attack data packet is obtained, and the suspected attack source address is checked with a preset source address verification technology to see if the suspected attack source address matches the source interface of the suspected attack data packet, and the verification result is obtained.
[0107] Based on the verification results, traffic originating from the alleged attack source address is blocked, and preset firewall rules or DDoS defense devices are used to block the traffic, thereby verifying the false source address.
[0108] The falsified source address is added to the blacklist to obtain the address update blacklist. The packets of the falsified source address are automatically blocked through the address update blacklist to obtain source control network traffic.
[0109] If the suspected attack source address does not match the source interface in the verification results of the matching results, it may be a fake source address.
[0110] Furthermore, after ensuring that the packets verifying the fake source address in subsequent traffic are automatically blocked, it is also necessary to continuously monitor network traffic and optimize the source address verification and blocking strategies to adapt to new attack patterns and changes in the network environment.
[0111] S4. Obtain the client behavior characteristics and verification mechanism in the source control network traffic, and distinguish between real user and attack traffic in the source control network traffic based on the client behavior characteristics and verification mechanism to obtain the distinguished network traffic.
[0112] In this embodiment of the invention, the client behavior characteristics refer to the behavior patterns and security features of terminal devices in the power monitoring system in terms of access, authentication, security checks, configuration compliance, risk control, and data collection and monitoring. These characteristics together ensure the security, stability, and efficiency of the power monitoring system.
[0113] Furthermore, the verification mechanism refers to technical means used in the field of network security to confirm that users, devices, or services can be correctly identified and authorized when accessing a system. By verifying the source, controlling the identity and permissions of network traffic topics, and controlling their access and operation in the network system, unauthorized access and data leakage can be prevented.
[0114] The verification mechanism typically includes three steps: identity authentication, authorization, and auditing, to ensure that the system only allows legitimate users to access and operate.
[0115] Furthermore, the term "real users" refers to legitimate users who normally use network services and resources. These users typically possess valid accounts and permissions, and their behavior conforms to normal business logic and usage patterns. The term "attack traffic" refers to network traffic initiated by malicious actors, aimed at disrupting, stealing, or interfering with normal network services. Attack traffic may include various types of network attacks, such as distributed denial-of-service attacks, SQL injection, cross-site scripting attacks, and malware propagation.
[0116] S5. Based on the preset communication protocol, perform customized analysis and filtering mechanism analysis on the differentiated network traffic to identify and block malicious traffic, and obtain customized filtered network traffic.
[0117] Understandably, by using preset communication protocols to perform customized analysis and filtering of network traffic, malicious traffic can be effectively identified and blocked, thereby enhancing network security protection, ensuring the smooth transmission of legitimate traffic, and improving network performance and data security.
[0118] In this embodiment of the invention, the communication protocol refers to a series of rules and standards used in network communication to ensure the security, integrity and reliability of data transmission, including but not limited to: SSL / TLS protocol, IPSec protocol, WPA / WPA2 / WPA3 protocol, DNS protocol.
[0119] The SSL / TLS protocol is used to establish a secure connection between the client and the server to ensure the confidentiality, integrity and authentication of data; the IPSec protocol is used to protect data transmission at the network layer and provides authentication, encryption and data integrity protection.
[0120] In this embodiment of the invention, the filtering mechanism refers to a network security technology capable of analyzing and filtering network traffic according to preset communication protocol standards. This mechanism uses specific algorithms and rules to identify normal traffic conforming to the protocol and potentially malicious traffic, and then takes action such as allowing, denying, or rerouting the traffic to protect the network from attacks.
[0121] Furthermore, the customized analysis and filtering mechanism analysis of the differentiated network traffic based on the preset communication protocol, identifying and blocking malicious traffic, and obtaining customized filtered network traffic includes:
[0122] By setting characteristic parameters for the preset communication protocol, a traffic communication protocol is obtained;
[0123] Extract the relevant features of the traffic communication protocol to obtain the traffic communication protocol features, and analyze whether the distinguishing network traffic conforms to the traffic communication protocol features;
[0124] When the distinguishing network traffic does not conform to the characteristics of the traffic communication protocol, a malicious traffic filtering rule is constructed based on the traffic communication protocol.
[0125] Based on the malicious traffic filtering rules, the malicious traffic in the differentiated network traffic is automatically blocked and processed using preset automated tools to obtain customized filtered network traffic.
[0126] Furthermore, after automatically blocking and processing malicious traffic in the differentiated network traffic according to the malicious traffic filtering rules using preset automated tools to obtain customized filtered network traffic, the method further includes:
[0127] Data Analysis and Feedback: Regularly evaluate traffic analysis results, collect feedback information, and understand the effectiveness and misjudgment of the filtering mechanism; Rule Updates: Continuously update and optimize communication protocol rules and filtering rules based on evaluation results and changes in the network environment to improve the accuracy of malicious traffic identification and the adaptability of the filtering mechanism analysis; Model Training and Optimization: For traffic analysis methods that use machine learning models, regularly train and optimize the models, introduce new traffic data and attack characteristics, and improve the model's identification capabilities.
[0128] S6. By checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain the session filtered network traffic.
[0129] Understandably, by checking whether packets in the customized filtered network traffic match pre-built session states, malicious TCP connections disguised as normal can be effectively identified and blocked, thereby improving network security and the ability to resist DDoS attacks.
[0130] In this embodiment of the invention, the session state in a computer network refers to the current state information of a session established between two or more communication entities. This state information is typically used to track and manage ongoing network communication sessions, ensuring the orderly transmission and correct processing of data.
[0131] Furthermore, the newly established connection rate refers to the number or frequency of newly established TCP connections in the network within a specific time interval. It is an important indicator for measuring network connection activity and is usually measured in Connections Per Second (CPS). Abnormal session monitoring refers to a technique that identifies sessions that do not conform to normal network activity patterns by analyzing various characteristics and behaviors of TCP sessions. It not only focuses on information from individual data packets but also considers multiple factors from the perspective of the entire session to determine whether the session is abnormal.
[0132] In this embodiment of the invention, the malicious TCP connection refers to a TCP (Transmission Control Protocol) session designed to exploit, disrupt, or interfere with normal services. These connections are typically initiated by attackers and include spoofed sessions, abnormal traffic patterns, scanning, and probing.
[0133] S7. Detect and analyze the network traffic behavior characteristics of the session filtering network traffic, and implement preset traffic management measures to obtain standard network traffic.
[0134] Understandably, by detecting and analyzing the behavioral characteristics of network traffic with fewer sessions and implementing pre-defined traffic management measures, the network environment can be effectively purified, ensuring that only normal traffic that meets security and compliance standards is allowed to be transmitted, thereby improving the security, stability, and efficiency of the network.
[0135] In this embodiment of the invention, the traffic management measures refer to a series of strategies and techniques used to identify, control, and optimize network traffic to ensure network security and stable operation. Specific measures include, but are not limited to, threshold adjustment methods, feature association analysis methods, knowledge base-based methods, machine learning methods, and behavior-based anomaly detection methods.
[0136] This invention employs a pre-set detection device to detect raw network traffic, extract problematic network traffic from it, and filter out problematic packets within this traffic to obtain filtered network traffic, achieving initial network traffic filtering. Packet capture analysis is then used to obtain the traffic characteristics of the filtered network traffic, and static matching filtering is performed based on these characteristics to obtain static filtered network traffic, achieving network traffic filtering based on traffic characteristics. The static filtered network traffic is monitored to identify abnormal attack patterns, obtain suspected attack source addresses, and verify these addresses to obtain verification results. Based on these verification results, false source defense and blocking are implemented to achieve source control. The method involves several steps: acquiring client behavior characteristics and verification mechanisms from the source control network traffic; distinguishing between genuine user and attack traffic based on these characteristics and mechanisms to obtain differentiated network traffic; performing customized analysis and filtering mechanisms on the differentiated network traffic according to a preset communication protocol to identify and block malicious traffic, resulting in customized filtered network traffic for malicious traffic filtering; checking whether packets in the customized filtered network traffic match established session states, and combining new connection rates and abnormal session detection to identify and block malicious TCP connections, resulting in session filtered network traffic; detecting and analyzing the network traffic behavior characteristics of the session filtered network traffic, and implementing preset traffic management measures to obtain standard network traffic. Therefore, the multi-layered filtering-based DDoS attack defense method, device, electronic device, and computer-readable storage medium proposed in this invention, through a combination of multiple filtering methods and continuous advancement, achieves effective DDoS attack defense and enhances the filtering capability against network attacks.
[0137] like Figure 2 The diagram shown is a schematic of the modules of the DDoS attack defense device based on multi-layer filtering according to the present invention.
[0138] The multi-layer filtering-based DDoS attack defense device 100 of this invention can be installed in electronic devices. Depending on the functions implemented, the multi-layer filtering-based DDoS attack defense device may include a traffic filtering module 101, a defense blocking module 102, a customized filtering module 103, and a traffic management module 104. The module described in this invention can also be called a unit, referring to a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, stored in the memory of the electronic device.
[0139] In this embodiment, the functions of each module / unit are as follows:
[0140] The traffic filtering module 101 is used to detect the original network traffic through a preset traffic detection device, obtain the problematic network traffic from the original network traffic, and filter the problematic packets in the problematic network traffic to obtain the filtered network traffic.
[0141] By using packet capture analysis to obtain the traffic characteristics of the filtered network traffic, network traffic characteristics are obtained, and static matching filtering is performed on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic.
[0142] The defense blocking module 102 is used to monitor the static filtering network traffic, identify abnormal attack patterns in the static filtering network traffic, obtain suspected attack source addresses, match and verify the suspected attack source addresses, obtain verification results, and perform false source defense blocking based on the verification results to obtain source control network traffic.
[0143] The customized filtering module 103 is used to obtain client behavior characteristics and verification mechanisms in the source control network traffic, and to distinguish real user traffic and attack traffic in the source control network traffic based on the client behavior characteristics and verification mechanisms, thereby obtaining differentiated network traffic;
[0144] Based on a preset communication protocol, the differentiated network traffic is subjected to customized analysis and filtering mechanism analysis to identify and block malicious traffic, thereby obtaining customized filtered network traffic.
[0145] The traffic management module 104 is used to identify and block malicious TCP connections by checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection to obtain the session filtered network traffic.
[0146] The network traffic behavior characteristics of the session filtering network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
[0147] In detail, the modules in the multi-layer filtering-based DDoS attack defense device 100 described in this embodiment of the invention employ the same methods as described above. Figure 1 The method used is the same as the multi-layer filtering-based DDoS attack defense method and can produce the same technical effect, so it will not be described in detail here.
[0148] like Figure 3 The diagram shown is a structural schematic of an electronic device that implements the DDoS attack defense method based on multi-layer filtering according to the present invention.
[0149] The electronic device may include a processor 10, a memory 11, a communication bus 12, and a communication interface 13. It may also include a computer program stored in the memory 11 and capable of running on the processor 10, such as a DDoS attack defense program based on multi-layer filtering.
[0150] In some embodiments, the processor 10 may be composed of integrated circuits, such as a single packaged integrated circuit or multiple integrated circuits with the same or different functions, including combinations of one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and various control chips. The processor 10 is the control unit of the electronic device, connecting various components of the entire electronic device through various interfaces and lines. It executes programs or modules stored in the memory 11 (e.g., executing DDoS attack defense programs based on multi-layer filtering) and calls data stored in the memory 11 to perform various functions of the electronic device and process data.
[0151] The memory 11 includes at least one type of readable storage medium, including flash memory, portable hard drive, multimedia card, card-type memory (e.g., SD or DX memory), magnetic memory, disk, optical disk, etc. In some embodiments, the memory 11 can be an internal storage unit of an electronic device, such as a portable hard drive. In other embodiments, the memory 11 can be an external storage device of the electronic device, such as a plug-in portable hard drive, Smart Media Card (SMC), Secure Digital (SD) card, Flash Card, etc. Furthermore, the memory 11 can include both internal and external storage units of the electronic device. The memory 11 can be used not only to store application software and various types of data installed on the electronic device, such as the code of a multi-layered filtering DDoS attack defense program, but also to temporarily store data that has been output or will be output.
[0152] The communication bus 12 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into an address bus, a data bus, a control bus, etc. The bus is configured to enable communication between the memory 11 and at least one processor 10, etc.
[0153] The communication interface 13 is used for communication between the aforementioned electronic device and other devices, including a network interface and a user interface. Optionally, the network interface may include a wired interface and / or a wireless interface (such as a Wi-Fi interface, Bluetooth interface, etc.), typically used to establish communication connections between the electronic device and other electronic devices. The user interface may be a display, an input unit (such as a keyboard), or optionally, a standard wired or wireless interface. Optionally, in some embodiments, the display may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen, etc. The display may also be appropriately referred to as a screen or display unit, used to display information processed in the electronic device and to display a visual user interface.
[0154] Figure 3 Only electronic devices with components are shown; it will be understood by those skilled in the art that... Figure 3 The structure shown does not constitute a limitation on the electronic device and may include fewer or more components than shown, or combine certain components, or have different component arrangements.
[0155] For example, although not shown, the electronic device may also include a power supply (such as a battery) to power the various components. Preferably, the power supply can be logically connected to the at least one processor 10 through a power management device, thereby enabling functions such as charging management, discharging management, and power consumption management. The power supply may also include one or more DC or AC power supplies, recharging devices, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components. The electronic device may also include various sensors, Bluetooth modules, Wi-Fi modules, etc., which will not be described in detail here.
[0156] It should be understood that the embodiments described are for illustrative purposes only and are not limited to this structure in the scope of the patent application.
[0157] The DDoS attack defense program based on multi-layer filtering stored in the memory 11 of the electronic device is a combination of multiple computer programs. When run in the processor 10, it can achieve the following:
[0158] The original network traffic is detected by a preset traffic detection device, problematic network traffic is obtained from the original network traffic, and problematic packets in the problematic network traffic are filtered to obtain filtered network traffic.
[0159] By using packet capture analysis to obtain the traffic characteristics of the filtered network traffic, network traffic characteristics are obtained, and static matching filtering is performed on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic.
[0160] The statically filtered network traffic is monitored to identify abnormal attack patterns in the statically filtered network traffic, obtain suspected attack source addresses, and match and verify the suspected attack source addresses to obtain verification results. Based on the verification results, false source defense is blocked to obtain source control network traffic.
[0161] The client behavior characteristics and verification mechanisms in the source control network traffic are obtained, and the real user and attack traffic in the source control network traffic are distinguished based on the client behavior characteristics and verification mechanisms to obtain the distinguished network traffic;
[0162] Based on a preset communication protocol, the differentiated network traffic is subjected to customized analysis and filtering mechanism analysis to identify and block malicious traffic, thereby obtaining customized filtered network traffic.
[0163] By checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain the session filtered network traffic.
[0164] The network traffic behavior characteristics of the session filtering network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
[0165] Specifically, the processor 10's implementation method of the above-mentioned computer program can be found in [reference needed]. Figure 1 The descriptions of the relevant steps in the corresponding embodiments are not repeated here.
[0166] Furthermore, if the modules / units integrated into the electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium. The computer-readable storage medium can be volatile or non-volatile. For example, the computer-readable medium may include: any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, or a read-only memory (ROM).
[0167] The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor of an electronic device, can perform the following:
[0168] The original network traffic is detected by a preset traffic detection device, problematic network traffic is obtained from the original network traffic, and problematic packets in the problematic network traffic are filtered to obtain filtered network traffic.
[0169] By using packet capture analysis to obtain the traffic characteristics of the filtered network traffic, network traffic characteristics are obtained, and static matching filtering is performed on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic.
[0170] The statically filtered network traffic is monitored to identify abnormal attack patterns in the statically filtered network traffic, obtain suspected attack source addresses, and match and verify the suspected attack source addresses to obtain verification results. Based on the verification results, false source defense is blocked to obtain source control network traffic.
[0171] The client behavior characteristics and verification mechanisms in the source control network traffic are obtained, and the real user and attack traffic in the source control network traffic are distinguished based on the client behavior characteristics and verification mechanisms to obtain the distinguished network traffic;
[0172] Based on a preset communication protocol, the differentiated network traffic is subjected to customized analysis and filtering mechanism analysis to identify and block malicious traffic, thereby obtaining customized filtered network traffic.
[0173] By checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain the session filtered network traffic.
[0174] The network traffic behavior characteristics of the session filtering network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
[0175] In the several embodiments provided by this invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.
[0176] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0177] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.
[0178] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0179] Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description. Thus, all variations falling within the meaning and scope of equivalents of the claims are intended to be embraced within the invention. No appended diagram markings in the claims should be construed as limiting the scope of the claims.
[0180] The blockchain referred to in this invention is a novel application model of computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, and encryption algorithms. Essentially, a blockchain is a decentralized database, a chain of data blocks linked together using cryptographic methods. Each data block contains information about a batch of network transactions, used to verify the validity of the information (anti-counterfeiting) and generate the next block. A blockchain can include an underlying blockchain platform, a platform product service layer, and an application service layer.
[0181] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence (AI) refers to the theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0182] Furthermore, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices recited in a system claim may also be implemented by a single unit or device through software or hardware. The term "second class" is used to indicate names and does not indicate any specific order.
[0183] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A DDoS attack defense method based on multi-layer filtering, characterized in that, The method includes: The original network traffic is detected by a preset traffic detection device, problematic network traffic is obtained from the original network traffic, and problematic packets in the problematic network traffic are filtered to obtain filtered network traffic. By using packet capture analysis to obtain the traffic characteristics of the filtered network traffic, network traffic characteristics are obtained, and static matching filtering is performed on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic. The statically filtered network traffic is monitored to identify abnormal attack patterns in the statically filtered network traffic, obtain suspected attack source addresses, and match and verify the suspected attack source addresses to obtain verification results. Based on the verification results, false source defense is blocked to obtain source control network traffic. The client behavior characteristics and verification mechanisms in the source control network traffic are obtained, and the real user and attack traffic in the source control network traffic are distinguished based on the client behavior characteristics and verification mechanisms to obtain the distinguished network traffic; Based on a preset communication protocol, the differentiated network traffic is subjected to customized analysis and filtering mechanism analysis to identify and block malicious traffic, thereby obtaining customized filtered network traffic. By checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection, malicious TCP connections are identified and blocked to obtain the session filtered network traffic. The network traffic behavior characteristics of the session filtering network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
2. The DDoS attack defense method based on multi-layer filtering as described in claim 1, characterized in that, The process of filtering problematic packets from the problematic network traffic to obtain filtered network traffic includes: Based on the preset RFC standard, the legality of packets in the problematic network traffic is checked, and vulnerable packets that exploit protocol vulnerabilities are identified. By analyzing the characteristics of packets in the problematic network traffic, identification features are obtained, and these identification features are matched with known attack features to obtain specific problematic packets with specific attack features; Based on the vulnerability-related packets and specific problematic packets, corresponding filtering rules are set to obtain packet filtering rules. Then, the problematic network traffic is filtered according to the packet filtering rules to obtain filtered network traffic.
3. The DDoS attack defense method based on multi-layer filtering as described in claim 1, characterized in that, The step of performing static matching filtering on the filtered network traffic based on the network traffic characteristics to obtain statically filtered network traffic includes: Based on the network traffic characteristics, static filtering rules are set to obtain the feature-based static filtering rules; Obtain network traffic data packets from the filtered network traffic, match the network traffic data packets with the feature static filtering rules, and check whether the network traffic data packets meet the matching conditions of the feature static filtering rules; When the network traffic data packet meets the matching conditions of the feature static filtering rule, the network traffic data packet that meets the conditions is filtered to obtain static filtered network traffic, wherein the filtering operation includes discarding and logging.
4. The DDoS attack defense method based on multi-layer filtering as described in claim 2, characterized in that, The step of filtering the problematic network traffic according to the packet filtering rules to obtain filtered network traffic includes: The pre-constructed binary convolutional neural network and one-dimensional convolutional neural network are adjusted according to the message filtering rules to obtain the adjusted binary convolutional network model and the adjusted one-dimensional convolutional network model. The adjusted binary convolutional network model is used to perform traffic situation awareness on the problem network traffic, and the traffic situation awareness results are obtained. Based on the traffic situation awareness results, the problem network traffic is subjected to feature extraction and binary classification using the adjusted one-dimensional convolutional network model to obtain problem features and binary classification results. Based on the problem features and binary classification, the problem network traffic is filtered to obtain filtered network traffic.
5. The DDoS attack defense method based on multi-layer filtering as described in claim 1, characterized in that, The monitoring of the statically filtered network traffic, identifying abnormal attack patterns in the statically filtered network traffic, and obtaining suspected attack source addresses include: Based on preset historical traffic data, a network traffic model is established using machine learning algorithms to obtain the historical network traffic model. Traffic prediction is performed using the historical network traffic model to obtain the predicted traffic. The predicted traffic is compared with the static filtering network traffic to identify abnormal traffic; Extract features from the abnormal traffic and analyze the features to obtain abnormal attack pattern traffic; Obtain the relevant source IP address of the traffic from the abnormal attack pattern to obtain the suspected attack source address.
6. The DDoS attack defense method based on multi-layer filtering as described in claim 1, characterized in that, The process of matching and verifying the suspected attack source address to obtain the verification result, and then blocking the false source based on the verification result to obtain the source control network traffic includes: The data packet of the suspected attack source address is obtained, the suspected attack data packet is obtained, and the suspected attack source address is checked with a preset source address verification technology to see if the suspected attack source address matches the source interface of the suspected attack data packet, and the verification result is obtained. Based on the verification results, traffic originating from the suspected attack source address is blocked, and traffic is blocked using preset firewall rules or DDoS defense devices to verify the false source address. The falsified source address is added to the blacklist to obtain the address update blacklist. The packets of the falsified source address are automatically blocked through the address update blacklist to obtain source control network traffic.
7. The DDoS attack defense method based on multi-layer filtering as described in any one of claims 1 to 6, characterized in that, The customized analysis and filtering mechanism analysis of the differentiated network traffic based on the preset communication protocol identifies and blocks malicious traffic, resulting in customized filtered network traffic, including: By setting characteristic parameters for the preset communication protocol, a traffic communication protocol is obtained; Extract the relevant features of the traffic communication protocol to obtain the traffic communication protocol features, and analyze whether the distinguishing network traffic conforms to the traffic communication protocol features; When the distinguishing network traffic does not conform to the characteristics of the traffic communication protocol, a malicious traffic filtering rule is constructed based on the traffic communication protocol. Based on the malicious traffic filtering rules, the malicious traffic in the differentiated network traffic is automatically blocked and processed using preset automated tools to obtain customized filtered network traffic.
8. A DDoS attack defense device based on multi-layer filtering, characterized in that, The device includes: The traffic filtering module is used to detect the original network traffic through a preset traffic detection device, obtain problematic network traffic from the original network traffic, and filter problematic packets in the problematic network traffic to obtain filtered network traffic. By using packet capture analysis to obtain the traffic characteristics of the filtered network traffic, network traffic characteristics are obtained, and static matching filtering is performed on the filtered network traffic based on the network traffic characteristics to obtain static filtered network traffic. The defense and blocking module is used to monitor the static filtering network traffic, identify abnormal attack patterns in the static filtering network traffic, obtain suspected attack source addresses, match and verify the suspected attack source addresses, obtain verification results, and perform false source defense and blocking based on the verification results to obtain source control network traffic. A customized filtering module is used to obtain client behavior characteristics and verification mechanisms in the source control network traffic, and to distinguish real user traffic and attack traffic in the source control network traffic based on the client behavior characteristics and verification mechanisms, thereby obtaining differentiated network traffic; Based on a preset communication protocol, the differentiated network traffic is subjected to customized analysis and filtering mechanism analysis to identify and block malicious traffic, thereby obtaining customized filtered network traffic. The traffic management module is used to identify and block malicious TCP connections by checking whether the packets in the customized filtered network traffic match the pre-built session state, and combining the preset new connection rate and abnormal session detection to obtain the session filtered network traffic. The network traffic behavior characteristics of the session filtering network traffic are detected and analyzed, and preset traffic management measures are implemented to obtain standard network traffic.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the DDoS attack defense method based on multi-layer filtering as described in any one of claims 1 to 7.
10. A computer-readable storage medium, comprising a data storage area and a program storage area, wherein the data storage area stores created data and the program storage area stores a computer program; wherein, When the computer program is executed by the processor, it implements the DDoS attack defense method based on multi-layer filtering as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Malicious traffic identification method and device, electronic equipment and storage medium
CN112054992A
Detection method for defending ddos traffic attack
CN113630394A