DoS attack monitoring processing method and system in multi-agent network and storage medium

By monitoring the communication traffic characteristics of the multi-agent system in real time and dynamically adjusting the system parameters, the multi-agent system has solved the problem of low detection efficiency and slow response when facing DoS attacks, and the ability to quickly identify and effectively defend against DoS attacks is achieved.

CN120223382AInactive Publication Date: 2025-06-27GUANGDONG UNIV OF TECH

Patent Information

Application Number
CN202510342515.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

When facing DoS attacks, multi-agent systems have low detection efficiency, slow response, and high false alarm rate, and cannot effectively deal with the complexity and real-time requirements of distributed networks.

Method used

By monitoring the communication traffic characteristics in real time, extracting key feature data, determining whether the communication link is attacked by DoS, and dynamically adjusting the weight and controller gain of the communication link according to the attack strength.

Benefits of technology

It realizes rapid identification of DoS attacks, timely notify system administrators, and dynamically adjusts defense strategies according to the attack intensity, improving the system's real-time monitoring and defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223382A_ABST
    Figure CN120223382A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and particularly discloses a DoS attack monitoring processing method and system in a multi-agent network and a storage medium, and the monitoring processing method comprises the following steps: collecting data of communication flow characteristics, and extracting data of key communication flow characteristics as a basis for obtaining a collection value; comparing the acquisition value of the key communication flow characteristic with a preset normal threshold value of the corresponding communication flow characteristic, if the acquisition value exceeds the normal threshold value, judging that the communication link is possibly attacked by the DoS, and sending out an alarm notice; when the alarm notification is received, adjusting the weight of the communication link and adjusting the gain of the controller; and after adjustment, the system updates the control input and state of the intelligent agent. The system quickly identifies DoS attacks by monitoring communication flow characteristics in real time, and notifies a system administrator in time; meanwhile, the system dynamically adjusts the defense strategy according to the attack intensity, and has the advantages of real-time DoS attack monitoring, rapid alarm notification and dynamic adjustment of the defense strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a method, a system and a storage medium for monitoring and processing DoS attacks in a multi-agent network. Background Art

[0002] A multi-agent system consists of multiple autonomous agents that communicate and cooperate with each other through a network. Such systems have a wide range of applications in many fields such as industrial control, intelligent transportation, and military communication. However, multi-agent systems also face network security challenges, especially DoS attacks, where attackers send a large number of requests to exhaust system resources, resulting in the interruption of normal services. DoS attacks pose a serious threat to the normal operation of multi-agent systems. Such attacks may cause the interruption of communication between agents, affect the coordination and decision-making capabilities of the system, and may even lead to the paralysis of the entire system.

[0003] Existing DoS attack detection methods have limitations in multi-agent systems. These methods are usually designed for a single network environment and cannot effectively handle the complexity of distributed networks. In a multi-agent system, each agent may become a target of attack, and traditional centralized detection methods are difficult to detect and respond to attacks scattered on different agents in a timely manner.

[0004] In addition, existing technologies are difficult to detect and respond to attacks in real time. Multi-agent systems usually require quick reaction and decision-making, while traditional DoS attack detection methods often have a large detection delay. This delay may cause the attack to have caused serious damage before it is discovered, and cannot meet the real-time requirements of multi-agent systems.

[0005] Existing technologies also lack accurate quantification of DoS attack intensity and corresponding dynamic defense mechanisms. DoS attacks of different intensities have different impacts on the system, and different defense strategies need to be adopted. However, existing technologies usually adopt fixed defense measures and cannot dynamically adjust system parameters according to the attack intensity, resulting in poor defense effects.

[0006] Finally, existing DoS attack detection and defense methods often ignore the particularity of multi-agent systems. Agents in these systems need to maintain a certain degree of autonomy while coordinating with other agents. Existing technologies are difficult to strike a balance between protecting system security and maintaining agent autonomy, and may overly restrict the communication and decision-making capabilities of agents. Summary of the Invention

[0007] Aiming at the problems raised in the background art, the purpose of the present invention is to propose a method, a system and a storage medium for monitoring and processing DoS attacks in a multi-agent network, so as to solve the problems of low detection efficiency, slow response, and high false alarm rate in the face of DoS attacks in the existing multi-agent network.

[0008] To achieve this objective, the present invention adopts the following technical solutions:

[0009] A method for monitoring and processing DoS attacks in a multi-agent network, comprising the following steps:

[0010] S1. Collect data on communication traffic characteristics and extract the data of key communication traffic characteristics as the basis for obtaining the collected values;

[0011] S2. Compare the collected values of the key communication traffic characteristics with the preset normal thresholds of the corresponding communication traffic characteristics. If there is a collected value exceeding the normal threshold, it is determined that the communication link may be under a DoS attack, and an alarm notification is sent;

[0012] S3. When an alarm notification is received, adjust the weight of the communication link and adjust the controller gain;

[0013] S4. After the adjustment, the system updates the control input and state of the agent.

[0014] Preferably, in step S3, when a certain communication link is under a DoS attack, reduce the weight of this communication link, increase the weights of other normal communication links, and keep or increase the controller gain.

[0015] Preferably, in step S1, the key communication traffic characteristics extracted include packet size, packet frequency, transmission delay, and packet loss rate;

[0016] In step 3, it also includes judging the DoS attack intensity according to the data of the key communication traffic characteristics, wherein the DoS attack intensity is quantified by the comprehensive attack intensity, and the calculation formula of the comprehensive attack intensity is as follows:

[0017]

[0018] wherein, Δ represents the deviation between the collected value and the corresponding normal threshold;

[0019] w1, w2, w3, and w4 are the weight coefficients of packet size, packet frequency, transmission delay, and packet loss rate respectively, and satisfy w1 + w2 + w3 + w4 = 1;

[0020] When the comprehensive attack intensity < 0.5, it is a low-intensity attack; when the DoS attack intensity is a low-intensity attack, the weight of the attacked communication link is reduced by 10%, the weights of other normal communication links are increased by 5% on average, and the controller gain remains unchanged;

[0021] When 0.5 ≤ comprehensive attack intensity < 1, it is a medium-intensity attack; when the DoS attack intensity is a medium-intensity attack, the weight of the attacked communication link is reduced by 30%, the weights of other normal communication links are increased by 15% on average, and the controller gain is increased by 20%.

[0022] When the comprehensive attack intensity ≥ 1, it is a high-intensity attack; when the DoS attack intensity is a high-intensity attack, the weight of the attacked communication link is reduced by 50%, the weights of other normal communication links are increased by 25% on average, and the controller gain is increased by 50%.

[0023] Preferably, in step S1, it further includes statistically analyzing the data of key communication traffic characteristics and setting a normal threshold according to the statistical value of the corresponding key communication traffic characteristics, where the key communication traffic characteristics include any two or more of packet size, packet frequency, transmission delay, and packet loss rate.

[0024] Preferably, in step S2, when the collected value of any key communication traffic characteristic exceeds the set normal threshold, it is determined that the communication traffic characteristic is abnormal;

[0025] When two or more key communication traffic characteristics are abnormal, it is determined that the communication link is under a DoS attack;

[0026] Or, when a certain key communication traffic characteristic is abnormal three times in a row, it is determined that the communication link is under a DoS attack.

[0027] Preferably, in step S1, the data of communication traffic characteristics is collected in the following ways:

[0028] Use a network interface monitoring tool to monitor the network interfaces of each agent in real time to obtain communication traffic data;

[0029] Use a packet capture tool to capture the communication traffic characteristics passing through the agent network interface.

[0030] Preferably, in step S2, the system administrator is notified in any two or more of the following ways:

[0031] SMS method: Send an SMS alarm to the system administrator by integrating the SMS service API;

[0032] Email method: Use the SMTP protocol or integrate the email service API to send an alarm email to the system administrator, including attack characteristics and information on affected communication links;

[0033] Visual interface method: Display the alarm information in real time on the system management interface, and the alarm information includes the alarm level, attack characteristics, and / or affected communication links.

[0034] A monitoring and processing system for DoS attacks in a multi-agent network, comprising a monitoring module, an alarm module, and a processing module;

[0035] The monitoring module is used to collect data on the communication traffic characteristics in the multi-agent network, extract the data of the key communication traffic characteristics as the collected values, and determine whether the communication link is under a DoS attack by comparing the collected values with the set normal thresholds;

[0036] The alarm module is used to send an alarm notification when the monitoring module determines that the communication link is under a DoS attack;

[0037] The processing module is used to determine the DoS attack intensity based on the data of the key communication traffic characteristics, and dynamically adjust the weight of the communication link and the controller gain according to the DoS attack intensity.

[0038] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0039] Compared with the prior art, one of the above technical solutions has the following beneficial effects:

[0040] By real-time monitoring of the communication traffic characteristics, the system can quickly identify DoS attacks and notify the system administrator in a timely manner; at the same time, the system dynamically adjusts the defense strategy according to the attack intensity, and has the advantages of real-time monitoring of DoS attacks, quick alarm notification, and dynamic adjustment of the defense strategy. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] Figure 1 is the system architecture diagram of the present invention;

[0042] Figure 2 is the flowchart of the monitoring and processing method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the drawings are exemplary only for explaining the present invention and should not be construed as limiting the present invention.

[0044] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "upper", "lower", "front", "rear", "left", "right", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as limiting the present invention.

[0045] In addition, the terms "first", "second", and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first", "second", and "third" may explicitly or implicitly include one or more of such features.

[0046] It should be noted that, unless otherwise clearly specified and defined, the terms "installed", "connected", and "coupled" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0047] The following combines the attached Figures 1 to 2 and further illustrates the technical solutions of the present invention through specific embodiments.

[0048] A multi-agent system consists of multiple autonomous agents that communicate and cooperate with each other through a network. Such systems have a wide range of applications in many fields such as industrial control, intelligent transportation, and military communication. However, multi-agent systems face severe network security challenges, especially distributed denial-of-service (DoS) attacks. DoS attacks exhaust system resources by sending a large number of requests, resulting in the interruption of normal services. Existing DoS attack detection methods have obvious limitations in multi-agent systems, mainly reflected in the inability to effectively handle the complexity of distributed networks and the difficulty in real-time detecting and responding to attacks. These problems seriously affect the communication efficiency, cooperation ability, and overall performance of multi-agent systems, and reduce the reliability and stability of the systems.

[0049] Consider a linear multi-agent system, and the dynamic equation of each agent is as follows:

[0050]

[0051] where, x i (t) ∈ R n represents the state of agent i at time t, sat(u i (t)) represents the value of the control input u i (t) after being processed by the saturation function, u i (t) ∈ R m represents the control input of the system, A and B are known system matrices, and N is the total number of agents.

[0052] The expression of the saturation function is as follows:

[0053]

[0054] Among them, u max is the maximum value of the control input, and u min is the minimum value of the control input. The control input is restricted by a saturation function, which is more in line with the actual situation.

[0055] Based on the local information and neighbor information of the agents, the controller of each agent is designed. The control objective is to synchronize the states of all agents to a common value, that is:

[0056] lim t→∞ (x i (t)) - x j (t)) = 0

[0057] The designed distributed controller is:

[0058]

[0059] N i is the neighbor set of agent i, w ij is an element of the weighted adjacency matrix, x i represents the state of agent i, and x j represents the state of agent j. w ij represents the communication link weight between agent i and agent j. Agent i and agent j are any agents in the linear multi-agent system.

[0060] The communication topology model is as follows:

[0061] The communication topology between agents is represented by a directed graph, where N represents the set of nodes, representing the set of agents in the multi-agent network; B represents the set of edges connecting the nodes, that is, the communication links between agents; W is a weighted adjacency matrix used to represent the communication link weights between nodes.

[0062] If there is an edge b ij ∈B, it means that information can be propagated from node i to node j (b ij is equivalent to the connection edge between node i and node j), and the communication link weight w ij > 0; if not, then w ij = 0. It is assumed that the initial graph G contains a directed spanning tree to ensure the reachability and connectivity of the system.

[0063] The DoS attack model is as follows:

[0064] It is assumed that the DoS attack can attack any communication link, and the communication between the attacked communication links is interrupted, while the agents between other un-attacked communication links can communicate normally.

[0065] Suppose the communication topology in a multi-agent network is represented by a weighted adjacency matrix \(W\), where \(w\) ij represents the weight of the communication link from agent \(i\) to agent \(j\). During a DoS attack, the attacker can selectively attack certain specific links. Define an attack matrix \(A(t)\), where \(a\) ij (t) indicates whether the communication link \((i, j)\) is under attack at time \(t\):

[0066]

[0067] During a DoS attack, the change in the communication topology can be described by the weighted adjacency matrix. Define a dynamic communication topology matrix \(W(t)\) to represent the communication topology at time \(t\):

[0068] \(W(t)=W - A(t)\odot W\)

[0069] where \(\odot\) represents the Hadamard product (element-wise multiplication of two matrices). This means that if the communication link \((i, j)\) is under attack (i.e., \(a\) ij (t) = 1), then \(w\) ij (t) will be set to 0, indicating that the communication link is interrupted.

[0070] Considering a periodic DoS attack, define the DoS attack period as \(T\), and each attack period consists of an attack phase and a sleep phase. Define the attack pattern of the periodic DoS attack as:

[0071]

[0072] where \(A(t)\) is the attack matrix, \(T\) attack is the duration of the attack phase, and it satisfies \(0 < T\) attack < T\).

[0073] The values 0 or 1 of the elements \(a\) ij (t) of the attack matrix \(A(t)\) are used to indicate which links are not under attack or are under attack.

[0074] When \(A(t)=A\) attack , it means the system is under a DoS attack, and \(A\) attack represents the attack matrix of the system during the attack phase, where for some links \(a\) ij (t) = 1, indicating that these links are under attack during the attack phase.

[0075] When \(A(t)=0\), it represents the attack matrix of the system during the sleep phase, and at this time \(a\) ij (t) = 0 for all links, indicating that the system is not under a DoS attack.

[0076] Based on the above linear multi-agent system and model, as well as the method for monitoring and handling DoS attacks in the multi-agent network of the present invention, it is as follows:

[0077] S1. In the data collection stage, the system uses network interface monitoring tools (such as iftop, tcpdump) or packet capture tools (such as Wireshark, tcpdump) deployed on each agent to capture the data of the communication traffic characteristics of the local agent in real time, and extracts the data of the key communication traffic characteristics strongly related to DoS attacks (such as packet size, packet frequency, transmission delay, packet loss rate, etc.) as the collected values.

[0078] S2. The system monitors and compares the collected values of the data of the key communication traffic characteristics with the preset normal thresholds of the corresponding communication traffic characteristics. If there is a collected value exceeding the normal threshold, it is judged that the communication link may be under a DoS attack, and an alarm notification is sent. By monitoring the data of the communication traffic characteristics in real time, when the collected values of the key communication traffic characteristics such as packet frequency, packet size, transmission delay, or packet loss rate exceed the preset normal thresholds, it is determined that the communication traffic characteristic is abnormal, and it is judged that the communication link may be under a DoS attack. Specifically, the system can continuously compare the collected values of the communication traffic characteristics collected in real time with the preset normal thresholds. If a communication traffic characteristic exceeds the normal threshold, the system will mark this key communication traffic characteristic as abnormal. When a sufficient number of abnormal characteristics are detected, the system will judge that the current communication link may be under a DoS attack. Once the system judges that the communication link may be under a DoS attack, the alarm is immediately triggered, and notifications can be sent in multiple ways, including sending text messages or emails to the system administrator, and displaying the alarm information in real time on the system management interface. The alarm information usually contains detailed information such as attack characteristics and the affected communication link, so that the administrator can quickly understand the attack situation, ensure the real-time transmission of attack information, and shorten the response time.

[0079] S3. When receiving the alarm notification, the system first calculates the intensity of the DoS attack based on the data of the key communication traffic characteristics obtained by monitoring. The attack intensity is quantified by a comprehensive index, which takes into account the abnormal degrees of multiple key communication traffic characteristics. Based on the calculated attack intensity, the system dynamically adjusts the system parameters. The main adjustment strategies include reducing the weight of the attacked communication link, increasing the weight of other normal communication links, and adjusting the controller gain. This dynamic adjustment mechanism can effectively reduce the impact of the DoS attack on the overall performance of the system and ensure the communication efficiency and stability of the multi-agent network.

[0080] S4. After the adjustment is completed, the system updates the control input and status of the agent. Through the dynamically adjusted weighted adjacency matrix W(t) and gain K, the state synchronization of the agent is accelerated to ensure that the system can still quickly recover stability in the attack environment. Each agent autonomously adjusts its communication strategy based on the updated parameters to achieve the balance between distributed defense and global performance, and avoid the risk of single-point failure in centralized processing.

[0081] Further, in step S3, when a communication link is under a DoS attack, the weight of this communication link is reduced, and the weights of other normal communication links are increased, while maintaining or increasing the controller gain.

[0082] By dynamically adjusting the communication link weights and controller gain to cope with DoS attacks, the impact of the attacked link can be effectively reduced, while enhancing the overall stability and anti-interference ability of the system.

[0083] Specifically, when the system detects that a communication link is under a DoS attack, the following operations will be performed:

[0084] First, reduce the weight of the attacked communication link. This is because the attacked link may transmit a large amount of invalid or malicious data, and reducing its weight can reduce the impact of this data on the system. The reduction amplitude of the weight can be adjusted according to the attack intensity. For example, the reduction amplitude can be set to 10%, 20% or 50%.

[0085] Second, increase the weights of other normal communication links. By increasing the weights of the un-attacked links, the system can rely more on these normal links to transmit data and control information, thus maintaining the normal operation of the network. The increased amplitude can be evenly distributed, such as 5%, 15% or 25%.

[0086] Finally, maintain or increase the controller gain. The increase in the controller gain can improve the system's resistance to external interference, enabling the system to respond and correct the deviation caused by the DoS attack more quickly. The increased amplitude of the gain can be determined according to the attack intensity. For example, it can be increased by 0%, 20% or 50%.

[0087] The synergistic effect of these three steps can effectively mitigate the impact of DoS attacks. By reducing the weight of the attacked link, the system reduces its dependence on unreliable data; by increasing the weights of normal links, the system ensures the transmission of key information; by increasing the controller gain, the system improves its response speed and correction ability to attacks.

[0088] Even further, in step S1, the extracted key communication traffic characteristics include packet size, packet frequency, transmission delay, and packet loss rate;

[0089] In step 3, it also includes judging the DoS attack intensity according to the data of key communication traffic characteristics, where the DoS attack intensity is quantified by the comprehensive attack intensity, and the calculation formula of the comprehensive attack intensity is as follows:

[0090]

[0091] Among them, Δ represents the deviation between the collected value and the corresponding normal threshold;

[0092] w1, w2, w3 and w4 are the weight coefficients of the packet size, packet frequency, transmission delay and packet loss rate respectively, and satisfy w1 + w2 + w3 + w4 = 1;

[0093] When the comprehensive attack intensity < 0.5, it is a low-intensity attack; when the DoS attack intensity is a low-intensity attack, the weight of the attacked communication link is reduced by 10%, and the weights of other normal communication links are increased by 5% on average, and the controller gain remains unchanged;

[0094] When 0.5 ≤ comprehensive attack intensity < 1, it is a medium-intensity attack; when the DoS attack intensity is a medium-intensity attack, the weight of the attacked communication link is reduced by 30%, and the weights of other normal communication links are increased by 15% on average, and the controller gain is increased by 20%;

[0095] When the comprehensive attack intensity ≥ 1, it is a high-intensity attack; when the DoS attack intensity is a high-intensity attack, the weight of the attacked communication link is reduced by 50%, and the weights of other normal communication links are increased by 25% on average, and the controller gain is increased by 50%.

[0096] The method for the system to dynamically adjust the weights of communication links and the controller gain according to the DoS attack intensity includes: when it is monitored that a certain communication link is under a DoS attack, reduce the weight of this communication link, reduce the dependence on the communication link under the DoS attack, and increase the weights of other normal communication links to maintain the communication performance of the system; when the communication link between agents is under a DoS attack resulting in an increase in communication delay, appropriately increase the gain of the controller to accelerate the response speed of the system and maintain the stability of the system.

[0097] Specifically, assume that the initial controller gain is K = 1.0, w1 = 0.4, w2 = 0.2, w3 = 0.2, w4 = 0.2, the normal threshold of the packet size is 60 bytes, the normal threshold of the packet frequency is 50 per second, the normal threshold of the transmission delay is 8 milliseconds, and the normal threshold of the packet loss rate is 2%.

[0098] (1) At a certain moment, it is monitored that the packet size is 70 bytes, the packet frequency is 75 per second, the transmission delay is 10 milliseconds, and the packet loss rate is 2.5%. Substituting into the calculation formula of the comprehensive attack intensity, we get:

[0099]

[0100] Since the comprehensive attack intensity < 0.5, it is determined as a low-intensity attack. At this time, the system reduces the weight of the attacked communication link from 1.0 to 0.9, and increases the weights of other normal communication links from 1.0 to 1.05. The controller maintains the original gain and does not need to be adjusted.

[0101] (2) At a certain moment, it is monitored that the packet size is 80 bytes, the packet frequency is 90 packets / second, the transmission delay is 15 milliseconds, and the packet loss rate is 4%. Substituting into the calculation formula of the comprehensive attack intensity, we get:

[0102]

[0103] Since the comprehensive attack intensity ≥ 0.5 and < 1, it is determined as a medium-intensity attack. At this time, the system reduces the weight of the attacked communication link from 1.0 to 0.7, and increases the weights of other normal communication links from 1.0 to 1.15; the controller gain increases from 1.0 to 1.2 to compensate for the decrease in response speed caused by communication delay.

[0104] (3) At a certain moment, it is monitored that the packet size is 100 bytes, the packet frequency is 120 packets / second, the transmission delay is 25 milliseconds, and the packet loss rate is 8%. Substituting into the calculation formula of the comprehensive attack intensity, we get:

[0105]

[0106] Since the comprehensive attack intensity ≥ 1, it is determined as a high-intensity attack. At this time, the system reduces the weight of the attacked communication link from 1.0 to 0.5, and increases the weights of other normal communication links from 1.0 to 1.25; the controller gain increases from 1.0 to 1.5 to quickly offset the impact of high delay and packet loss on the system stability.

[0107] Through this dynamic adjustment, the system can effectively reduce the impact of DoS attacks on the entire multi-agent system while maintaining network connectivity. Compared with traditional methods, the solution of the present invention can more flexibly cope with attacks of different intensities, improving the robustness and adaptability of the system. On the one hand, by considering multiple communication traffic characteristics, it can more comprehensively reflect the situation of DoS attacks, reducing the possibility of misjudgment and missed judgment; on the other hand, using weight coefficients can adjust the importance of each characteristic according to the actual application scenario, making the system more adaptable to different network environments; in addition, by calculating the comprehensive attack intensity in real time, the system can quickly respond to changes in the network state and take corresponding adjustment measures in a timely manner; finally, it can also be conveniently extended to more communication traffic characteristics and adjust the division criteria of attack intensity according to needs. By dynamically reducing the weight of the attacked link, it reduces the occupancy of system resources by malicious traffic, while enhancing the communication priority of normal links to ensure that critical data transmission is not interrupted. The controller gain increases in stages with the attack intensity, accelerating the system's response speed to communication delays and packet losses, suppressing the performance degradation caused by attacks, and maintaining the stability of multi-agent collaboration.

[0108] For further explanation, the increase in the controller gain can affect the dynamic response of the system in the following way. The control input of the system is:

[0109]

[0110] where K is the controller gain, w ij is the weight of the communication link, x i and x j are the states of agent i and agent j respectively. By increasing the controller gain K, the control input u i (t) of the system will increase, thereby accelerating the response speed of the system and reducing the impact of communication delays on the system stability.

[0111] The gain adjustment of the controller can be described by the following mathematical model:

[0112] Assume that the gain matrix of the controller is K and the initial gain is K0. When a DoS attack is detected, according to the calculation result of the comprehensive attack intensity, the controller gain is adjusted to: K = K0 * (1 + ΔK). Where ΔK is the increase ratio of the gain, and the specific value depends on the comprehensive attack intensity. For low-intensity attacks, ΔK = 0; for medium-intensity attacks, ΔK = 0.2; for high-intensity attacks, ΔK = 0.5.

[0113] Suppose in a multi-agent system, the initial controller gain of the system \(K_0 = 1.0\). When a DoS attack is detected, according to the calculation result of the comprehensive attack intensity, if the comprehensive attack intensity is \(0.8\) (i.e., medium-intensity attack), the controller gain increases by \(20\%\), that is, \(\Delta K=0.2\), and the adjusted controller gain is \(K = 1.0\times(1 + 0.2)=1.2\).

[0114] In summary, the increase in the controller gain is based on the calculation result of the comprehensive attack intensity. The specific increase amplitude is as follows: for low-intensity attacks, the controller gain remains unchanged; for medium-intensity attacks, it increases by \(20\%\); for high-intensity attacks, it increases by \(50\%\). The adjustment of the controller gain is achieved through the mathematical model \(K = K_0\times(1+\Delta K)\), which depends on the comprehensive attack intensity. The increase in the controller gain can accelerate the system's response speed, offset the negative impact brought by communication delays, and thus maintain the stability of the system.

[0115] Furthermore, in step S1, it also includes statistically analyzing the data of the key communication traffic characteristics and setting normal thresholds according to the statistical values of the corresponding key communication traffic characteristics, where the key communication traffic characteristics include any two or more of the packet size, packet frequency, transmission delay, and packet loss rate.

[0116] In step S1, data collection is first carried out. The data of the communication traffic characteristics of the local agent in the wireless communication environment is collected. Specifically, by deploying a network traffic monitoring tool on each agent, the network traffic data passing through the agent can be captured and recorded in real time. These data may include information such as the size of the data packet, arrival time, source address, and destination address.

[0117] Secondly, key communication traffic characteristic data extraction is carried out. Key communication traffic characteristics such as the packet size, packet frequency, transmission delay, and packet loss rate are extracted from the collected communication traffic characteristics. For example, data analysis algorithms can be used to process the original traffic data, calculate the number of data packets per second (packet frequency), statistically analyze the average size of the data packets, calculate the time difference from the sending to the receiving of the data packets (transmission delay), and the proportion of data packets that are not successfully transmitted (packet loss rate).

[0118] Then, perform normal threshold setting. Set the normal threshold according to the statistical values of the normal key communication traffic characteristics among multiple agents. This step can be completed by observing and analyzing the communication traffic characteristics of the network in the normal operating state for a long time. For example, based on the data of historical normal communication traffic characteristics (such as the statistical results of one week or one month), the system calculates the average value and standard deviation of each communication traffic characteristic, and then sets the normal threshold to the range of the average value plus several standard deviations to set the normal threshold range of each communication traffic characteristic, so as to ensure that the communication link can tolerate short-term traffic fluctuations and accurately identify persistent anomalies. Further, the system can also dynamically adjust the normal threshold range by statistically learning the normal state of the network to adapt to the fluctuations of different network environments and service loads and reduce misjudgments caused by normal network fluctuations.

[0119] Further explanation, selecting the packet size, packet frequency, transmission delay, and packet loss rate as the key communication traffic characteristics is based on their sensitivity to attack behaviors and direct reflection of network performance, which can comprehensively capture the abnormal traffic patterns caused by attacks. Among them, for the packet size, in normal communication, the packet size usually has a diverse distribution (such as HTTP requests, video streams, etc.); but in a DoS attack, the attacker may use packets of a specific size to mask the target network, such as sending a large number of small packets (such as packets containing only the TCP SYN flag) to exhaust the target system resources, or sending packets of abnormal sizes (such as oversized or fragmented packets) to interfere with the processing logic of network devices, and these situations will cause the traffic to show a single or abnormal size distribution, which is easy to monitor. For the packet frequency, the core of a DoS attack is to send a large number of requests in a short time, causing the target system to be overloaded. For example, by sending UDP packets at a high frequency to exhaust the bandwidth or processing capacity or simulate a large number of legitimate requests, but the frequency far exceeds the normal user behavior, and the packet frequency is the most direct quantitative indicator, which can be quickly monitored and trigger an alarm. For the transmission delay, due to the saturation of the processing capacity of network devices (such as routers, switches) caused by a DoS attack, the queuing time of legitimate packets increases and the delay rises significantly. For the packet loss rate, when the attack traffic exceeds the processing capacity of the network device, buffer overflow causes legitimate packets to be discarded and the packet loss rate increases. The higher the packet loss rate, the more severely the network availability is damaged.

[0120] This monitoring method based on the analysis of multiple communication traffic characteristics has multiple advantages. First, it can monitor network traffic in real time and quickly detect abnormal situations. Second, a single characteristic may be interfered by normal fluctuations (such as short-term traffic peaks), but the simultaneous abnormality of multiple characteristics can improve the accuracy of attack determination. By analyzing multiple traffic characteristics, the detection accuracy can be improved, and the situations of false alarms and missed alarms can be reduced. Third, this method is applicable to distributed multi-agent network environments, and each agent can independently conduct monitoring, improving the overall security of the system. Finally, by setting reasonable normal thresholds, this method can adapt to different network environments and communication requirements, with good flexibility and scalability.

[0121] Further, in step S2, when the collected value of any key communication traffic characteristic exceeds the corresponding set normal threshold, it is determined that the communication traffic characteristic is abnormal;

[0122] When two or more key communication traffic characteristics are abnormal, it is determined that the communication link is under a DoS attack;

[0123] Or, when a certain key communication traffic characteristic is abnormal three times in a row, it is determined that the communication link is under a DoS attack.

[0124] "Two or more key communication traffic characteristics are abnormal" is equivalent to the multi-characteristic abnormality judgment. Specifically, if at the same time point, two or more key communication traffic characteristics exceed the normal threshold, the system will immediately determine it as a DoS attack. For example, when the packet frequency and transmission delay are abnormal at the same time, the attack judgment will be triggered.

[0125] "A certain key communication traffic characteristic is abnormal three times in a row" is equivalent to the single-characteristic continuous abnormality judgment. Specifically, if a certain characteristic exceeds the normal threshold in three consecutive samplings, the system will also determine it as a DoS attack. The "three times in a row" here can be adjusted according to the actual situation to balance the detection sensitivity and accuracy.

[0126] When any of the above conditions is met, the system will trigger an alarm and implement subsequent processing procedures. By setting multiple judgment conditions, the false alarm rate can be reduced, and at the same time, attack behaviors can be detected in a timely manner. Compared with the single-characteristic judgment, this monitoring method can, on the one hand, improve the accuracy and reduce misjudgments caused by normal phenomena such as network fluctuations; on the other hand, it can enhance the flexibility and can adjust the judgment conditions according to the actual application scenarios, such as adjusting the number of abnormal characteristics or the number of consecutive abnormal times. Through the joint judgment of multiple characteristics or continuous abnormality detection, false alarms caused by instantaneous interference (such as network congestion) are significantly reduced.

[0127] Further, in step S1, the data of communication traffic characteristics is collected in the following ways:

[0128] Use a network interface monitoring tool to monitor the network interfaces of each agent in real time and obtain communication traffic data;

[0129] Use a packet capture tool to capture the communication traffic characteristics passing through the agent's network interface.

[0130] Specifically, the "network interface monitoring tool" obtains communication traffic data by monitoring the network interfaces of each agent in real time. The network interface monitoring tool can continuously observe the network interface activities of the agent and record all data traffic passing through this interface. The advantage of this method is that it can comprehensively capture the network activities of the agent, including inbound traffic and outbound traffic, thus providing a complete overview of the communication traffic. The "packet capture tool" captures the communication traffic characteristics passing through the agent's network interface and analyzes the captured packets to extract key communication traffic characteristics such as packet size, packet frequency, transmission delay, and packet loss rate. The packet capture tool can deeply analyze the content and characteristics of network traffic and provide more detailed traffic information. Through the distributed deployment of monitoring tools, it is possible to cover the communication traffic of each node in the multi-agent network and ensure the comprehensiveness of data collection; capture traffic characteristics in real time and provide dynamic data support for subsequent analysis.

[0131] These two methods can be selected or used in combination according to the specific network environment and monitoring requirements. For example, when in-depth analysis of network traffic is required, the packet capture tool can be preferentially selected; while when a quick overview of the traffic is needed, the network interface monitoring tool can be used.

[0132] For example, in the Linux system, tools such as iftop and nethogs can be used to monitor the traffic data of network interfaces and obtain information such as packet size and packet frequency. Packet capture tools such as Wireshark and tcpdump can also be used to capture the packets passing through the agent's network interface. These tools can perform detailed analysis on the packets to obtain information such as the size of the packets, and thus calculate characteristics such as transmission delay and packet loss rate. For example, using tcpdump can capture the packets of a specified agent's network interface and calculate the transmission delay by analyzing the timestamps of the packets.

[0133] Furthermore, in step S2, notify the system administrator in any two or more of the following ways:

[0134] SMS method: Send an SMS alert to the system administrator by integrating the SMS service API;

[0135] Email method: Use the SMTP protocol or integrate the email service API to send an alert email to the system administrator, including attack characteristics and information about the affected communication links;

[0136] Visualization interface method: The alarm information is displayed in real time on the system management interface, and the alarm information includes the alarm level, attack characteristics, and / or affected communication links.

[0137] SMS notification is suitable for quick reminders in emergency situations; email notification can provide more detailed attack information for administrators to conduct in-depth analysis; visualization interface prompts help administrators monitor the system status in real time. By comprehensively using these alarm methods, the timeliness and effectiveness of alarms can be significantly improved.

[0138] Furthermore, when the monitoring module 100 detects a DoS attack, the alarm module 200 can simultaneously trigger the following operations: 1. Send a short alarm message to the preset administrator's mobile phone number through the SMS API, such as "DoS attack detected, please check the details in time". 2. Send a detailed alarm email using the SMTP protocol, and the email content includes the time when the attack occurred, the affected communication links, attack characteristics (such as abnormal packet size, frequency, etc.), and a preliminary impact assessment. 3. Pop up a highlighted alarm window on the system management interface to display the real-time status of the attack, including information such as attack intensity, duration, and affected network nodes.

[0139] Through this multi-level alarm mechanism, system administrators can select the most suitable response method according to different scenarios. For example, after receiving an SMS notification during non-working hours, the administrator can remotely log in to the system to view the detailed alarm email and monitor the attack status in real time through the visualization interface, so as to quickly formulate a response strategy.

[0140] Compared with the traditional single alarm method, the multi-channel alarm mechanism of this solution has the advantages of improving the reliability of alarms, enhancing the timeliness of alarms, adapting to different scenario requirements, and facilitating information tracking and analysis.

[0141] A monitoring and processing system for DoS attacks in a multi-agent network, including a monitoring module 100, an alarm module 200, and a processing module 300;

[0142] The monitoring module 100 is used to collect data on the communication traffic characteristics in the multi-agent network, extract the key communication traffic characteristic data as the collected value, and judge whether the communication link is under a DoS attack by comparing the collected value with the set normal threshold;

[0143] The alarm module 200 is used to send an alarm notification when the monitoring module 100 determines that the communication link is under a DoS attack;

[0144] The processing module 300 is used to determine the intensity of the DoS attack according to the data of the key communication traffic characteristics, and dynamically adjust the weight of the communication link and the controller gain according to the DoS attack intensity.

[0145] A multi-agent system consists of multiple autonomous agents that communicate and cooperate with each other through a network. Such systems have a wide range of applications in many fields such as industrial control, intelligent transportation, and military communication. However, multi-agent systems face severe network security challenges, especially distributed denial of service (DoS) attacks. DoS attacks deplete system resources by sending a large number of requests, resulting in the interruption of normal services. Existing DoS attack detection methods have obvious limitations in multi-agent systems, mainly reflected in the inability to effectively handle the complexity of distributed networks and the difficulty in real-time detecting and responding to attacks. These problems seriously affect the communication efficiency, cooperation ability, and overall performance of multi-agent systems, and reduce the reliability and stability of the systems.

[0146] The present invention proposes a monitoring and warning processing system for DoS attacks in a multi-agent network, including a monitoring module 100, a warning module 200, and a processing module 300. The monitoring module 100 is used to collect data on the communication traffic characteristics in the multi-agent network, extract and obtain data on several key communication traffic characteristics as several collected values, and determine whether the communication link is under a DoS attack by comparing the several collected values with the corresponding set normal thresholds respectively. The warning module 200 is used to send a warning notice when the monitoring module 100 determines that the communication link is under a DoS attack. The processing module 300 is used to determine the intensity of the DoS attack according to the key communication traffic characteristics, and dynamically adjust the weight of the communication link and the controller gain according to the DoS attack intensity.

[0147] Among them, the monitoring module 100 refers to a component used to collect the communication traffic characteristics in the multi-agent network and determine whether it is under a DoS attack, and can be specifically implemented by using a network traffic analysis tool or an embedded monitoring program. The warning module 200 refers to a component that sends a notice when a DoS attack is detected, and can be specifically implemented by means such as text messages, emails, or system interface prompts. The processing module 300 refers to a component that dynamically adjusts system parameters according to the attack intensity, and can be specifically implemented by using an adaptive algorithm to adjust the weight of the communication link and the controller gain.

[0148] The core innovation of the present invention lies in proposing a multi-agent network DoS attack defense system integrating monitoring, warning, and processing functions. This system can effectively maintain network performance by real-time monitoring communication traffic characteristics, quickly identifying DoS attacks, and dynamically adjusting system parameters according to the attack intensity. This integrated design significantly improves the response speed and defense effect of the system against DoS attacks.

[0149] The working principle of the present invention can be described in detail as follows:

[0150] The monitoring module 100 first continuously collects communication traffic characteristic data in the multi-agent network through a network interface monitoring tool or a packet capture tool. These communication traffic characteristic data include key metrics such as packet size, packet frequency, transmission delay, and packet loss rate. The collected data is then compared with a pre-set normal threshold. The normal threshold is set based on the statistical data of the system in the normal operating state.

[0151] When the collected values of certain key communication traffic characteristics exceed the normal threshold, the monitoring module 100 will determine that the communication link may be under a DoS attack. The specific determination criteria can be set as two or more characteristics being abnormal simultaneously, or a certain characteristic being abnormal three times in a row. This multi-dimensional determination criteria can effectively reduce the false alarm rate.

[0152] Once the monitoring module 100 determines that the communication link is under a DoS attack, the alarm module 200 is immediately triggered. The alarm module 200 can send notifications in various ways, including sending text messages or emails to the system administrator, and displaying alarm information in real-time on the system management interface. The alarm information usually contains detailed information such as attack characteristics and the affected communication link, so that the administrator can quickly understand the attack situation.

[0153] At the same time, the processing module 300 starts to work. The processing module 300 first calculates the intensity of the DoS attack based on the communication traffic characteristic data provided by the monitoring module 100. The attack intensity is quantified by a comprehensive index, which takes into account the abnormal degree of multiple communication traffic characteristics.

[0154] Based on the calculated attack intensity, the processing module 300 dynamically adjusts the system parameters. The main adjustment strategies include reducing the weight of the attacked communication link, increasing the weight of other normal communication links, and adjusting the controller gain. This dynamic adjustment mechanism can effectively reduce the impact of the DoS attack on the overall performance of the system and ensure the communication efficiency and stability of the multi-agent network.

[0155] Specifically, considering a multi-agent management application scenario, these agents communicate and exchange data in real-time through a wireless network. The monitoring module 100 is deployed on the controller of each agent to continuously monitor the communication traffic of its completion interface. Under normal circumstances, the packet size is 60 bytes, about 50 packets are processed per second, the transmission delay is 8 milliseconds, and the packet loss rate is 2%, and these values are set as the normal threshold.

[0156] When a controller of an intelligent agent is attacked by DoS, its data packet size may increase to 70 bytes, the data packet processing volume increases to 75 per second, the transmission delay rises to 9 milliseconds, and the packet loss rate increases to 2.5%. After the monitoring module 100 detects these anomalies, the alarm module 200 is immediately triggered.

[0157] The alarm module 200 then sends a text message and email notification to the system administrator, and displays the location of the attacked node and the attack characteristics on the management interface, so that the administrator can quickly locate the problem and take corresponding measures.

[0158] At the same time, the processing module 300 calculates that the current attack intensity is a high-intensity attack. According to the preset strategy, the processing module 300 reduces the weight of the attacked communication link, increases the weight of the communication links of other normal nodes on average, and increases the controller gain. These adjustments effectively reduce the impact of the attack on the entire multi-agent system network and ensure the normal operation of other links that are not attacked.

[0159] In this way, the present invention can quickly detect and respond to DoS attacks in a complex multi-agent network environment, effectively maintaining the overall performance and stability of the system.

[0160] A readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the DoS attack monitoring and processing method in the multi-agent network. The technical solution of the present invention, in essence or in other words, the part that contributes to the prior art, can be embodied in the form of a software product, and the computer-readable storage medium can be various types of storage devices, such as hard disks, solid-state drives, USB flash drives, memory cards, etc. Computer-executable instructions can be program codes written in various programming languages, such as C++, Java, Python, etc. These instructions are stored on a computer-readable storage medium and can be read and executed by a computer processor when they need to be executed.

[0161] The technical principle of the present invention is described above in conjunction with specific embodiments. These descriptions are only for explaining the principle of the present invention and cannot be interpreted as limiting the scope of protection of the present invention in any way. Based on the explanations herein, those skilled in the art can associate other specific implementations of the present invention without paying creative labor, and these methods will fall within the scope of protection of the present invention.

Claims

1. A DoS attack monitoring and processing method in a multi-agent network, characterized in that The following steps are involved: S1. Collect data on communication traffic characteristics, and extract data on key communication traffic characteristics as a basis for obtaining collection values; S2. Compare the collected values ​​of the key communication traffic characteristics with the preset normal thresholds of the corresponding communication traffic characteristics. If any collected value exceeds the normal threshold, it is determined that the communication link may be attacked by DoS, and an alarm notification is issued; S3. When receiving an alarm notification, adjusting the weight of the communication link and adjusting the controller gain; S4. After adjustment, the system updates the control input and state of the agent.

2. The method for monitoring and processing DoS attacks in a multi-agent network according to claim 1, characterized in that: In step S3, when a communication link is attacked by DoS, the weight of the communication link is reduced, the weights of other normal communication links are increased, and the controller gain is maintained or increased.

3. The method for monitoring and processing DoS attacks in a multi-agent network according to claim 2, characterized in that: In step S1, the key communication traffic features extracted include packet size, packet frequency, transmission delay, and packet loss rate; In step 3, it also includes determining the DoS attack intensity based on the data of the key communication traffic characteristics, wherein the DoS attack intensity is quantified by the comprehensive attack intensity, and the calculation formula of the comprehensive attack intensity is as follows: Where Δ represents the deviation of the collected value from the corresponding normal threshold; w1, w2, w3 and w4 are weight coefficients of packet size, packet frequency, transmission delay and packet loss rate, respectively, and satisfy w1+w2+w3+w4=1; When the comprehensive attack intensity is less than 0.5, it is a low-intensity attack; when the DoS attack intensity is a low-intensity attack, the weight of the attacked communication link is reduced by 10%, the weight of other normal communication links is increased by 5% on average, and the controller gain remains unchanged; When 0.5≤comprehensive attack intensity<1, it is a medium-intensity attack; when the DoS attack intensity is a medium-intensity attack, the weight of the attacked communication link is reduced by 30%, the weight of other normal communication links is increased by an average of 15%, and the controller gain is increased by 20%; When the comprehensive attack intensity is ≥1, it is a high-intensity attack; when the DoS attack intensity is a high-intensity attack, the weight of the attacked communication link is reduced by 50%, the weight of other normal communication links is increased by an average of 25%, and the controller gain is increased by 50%.

4. The method for monitoring and processing DoS attacks in a multi-agent network according to claim 1, characterized in that: In step S1, it also includes performing statistics based on the data of key communication traffic characteristics and setting a normal threshold value based on the statistical value of the corresponding key communication traffic characteristics, wherein the key communication traffic characteristics include any two or more of data packet size, data packet frequency, transmission delay and packet loss rate.

5. The method for monitoring and processing DoS attacks in a multi-agent network according to claim 4, characterized in that: In step S2, when the collected value of any key communication flow feature exceeds the corresponding set normal threshold, the communication flow feature is determined to be abnormal; When two or more key communication traffic characteristics are abnormal, it is determined that the communication link is under DoS attack; Or, when a key communication traffic feature is abnormal three times in a row, it is determined that the communication sprocket is under DoS attack.

6. The method for monitoring and processing DoS attacks in a multi-agent network according to claim 1, characterized in that: In step S1, data of communication traffic characteristics are collected in the following manner: Use network interface monitoring tools to monitor the network interface of each agent in real time and obtain communication traffic data; Use a packet capture tool to capture the characteristics of the communication traffic passing through the agent's network interface.

7. The method for monitoring and processing DoS attacks in a multi-agent network according to claim 1, characterized in that: In step S2, the system administrator is notified in any two or more of the following ways: SMS method: Send SMS alerts to system administrators by integrating SMS service API; Email method: Use SMTP protocol or integrated email service API to send warning emails to system administrators, including attack characteristics and affected communication link information; Visual interface mode: Alarm information is displayed in real time on the system management interface. The alarm information includes alarm level, attack characteristics and / or affected communication links.

8. A DoS attack monitoring and processing system in a multi-agent network, characterized in that: Including monitoring module, alarm module and processing module; The monitoring module is used to collect data on communication traffic characteristics in the multi-agent network, extract data on key communication traffic characteristics as collected values, and compare the collected values ​​with a set normal threshold to determine whether the communication link is under DoS attack; The alarm module is used to issue an alarm notification when the monitoring module determines that the communication link is under DoS attack; The processing module is used to determine the DoS attack intensity according to the data of the key communication traffic characteristics, and dynamically adjust the weight of the communication link and the controller gain according to the DoS attack intensity.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Low-speed DoS attack real-time response scheme based on flow coefficient

    CN114039780A

  • Network attack defense method and system for distributed new energy grid-connected system

    CN119341807A

  • SIP-DoS attack detection method, system and device based on traffic statistical characteristics and storage medium

    CN119382996A

Cited By

  • Safety control method, device and equipment of industrial network and medium

    CN120750650A