SDoS defense method

Through the initialization time parameters and blacklist mechanism, SDoS attack blocks are identified and isolated, and combined with the Markov chain model to calculate the income of honest nodes, the problem of SDoS attacks in the blockchain network is solved, and effective defense against SDoS attacks and the improvement of honest node benefits are achieved.

CN120301677APending Publication Date: 2025-07-11GUANGZHOU UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510568231.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

There is a lack of mitigation or defense technology for denial of service attacks (SDoS) based on selfish work, resulting in overloading or paralyzing blockchain network resources and affecting legitimate user access.

Method used

By initializing the time parameters and blacklisting mechanism, blocks that meet the characteristics of attack behavior are identified and isolated. Honest nodes use the blacklisting mechanism to filter blocks and work after non-blacklisting blocks. Combining the Markov chain model, the income and income of honest nodes are calculated, and the work difficulty is dynamically adjusted to resist SDoS attacks.

Benefits of technology

Effectively defend against SDoS attacks, ensure that honest nodes expand blocks on the longest legal chain, deprive attackers of their profits, reduce attackers' income, increase the work income of honest nodes, and restore the normal state of the blockchain network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301677A_ABST
    Figure CN120301677A_ABST
Patent Text Reader

Abstract

The invention provides an SDoS defense method, and relates to the technical field of block chains, the SDoS defense method comprises the following steps: according to behavior characteristics of an SDoS attack, honesty nodes adopt a defense strategy to judge blocks conforming to the behavior characteristics of the attack and descendant blocks thereof through a blacklist mechanism and add the blocks and the descendant blocks into a blacklist, the honesty nodes use the blacklist mechanism to screen the blocks, and then the blocks and the descendant blocks of the blocks are added into the blacklist; the black list block works behind the non-black list block; and under the condition that a plurality of longest chains without blacklist blocks exist, the honest node adopting the defense strategy selects to work after receiving the chain of the complete block at the earliest. According to the method, based on an incentive mechanism, the attacker is enabled to actively stop attacking by reducing income of the attacker, more nodes are enabled to actively work, and the SDoS attack can be effectively relieved and defended.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of blockchain, and in particular, to a method for defending against SDoS. Background Art

[0002] Denial-of-Service attack: A network attack method aimed at overloading or paralyzing the target computer resources, thereby preventing users from accessing relevant network services or resources. Attackers usually send a large number of requests or data packets to the target system, causing the messages to exceed the system's processing capacity, and ultimately resulting in the system being unable to respond to legitimate user requests.

[0003] Blockchain Denial-of-Service attack: Different from the traditional Denial-of-Service attack method, the blockchain Denial-of-Service attack utilizes the incentive mechanism of the proof-of-work blockchain. The blockchain Denial-of-Service attack deliberately creates a fork by only publishing the block header, increasing the probability of some or even all honest nodes (hereinafter referred to as nodes for short) encountering forks and the probability of failing to compete for the longest legitimate chain, thereby reducing the expected revenue of the nodes. When the expected revenue of the nodes is negative, the nodes will actively choose to stop working, ultimately achieving the purpose of denying service to the blockchain.

[0004] Selfish-Mining-based Denial-of-Service attack (SDoS): SDoS targets the proof-of-work token blockchain system. SDoS can be regarded as a combination of selfish mining and blockchain Denial-of-Service attack. SDoS simultaneously wastes the node computing power by temporarily hiding blocks and only publishing block headers. The same as SM, their purpose is to obtain more block rewards.

[0005] Currently, there is no mitigation or defense technology against the Selfish-Mining-based Denial-of-Service attack (SDoS) in the existing technology.

[0006] Therefore, it is urgent to develop a solution to solve the above problems. Summary of the Invention

[0007] The purpose of the present invention is to provide a method for defending against SDoS.

[0008] A method for defending against SDoS provided by the present invention adopts the following technical solution:

[0009] A method for defending against SDoS, characterized in that it specifically includes the following steps:

[0010] Initialize the time parameter to 0 and initialize the blacklist, enter the block header receiving and listening state, and sense the generation of new blocks in the network;

[0011] When receiving the block header information, record the time parameter of the received block as t1, which is used to represent the time when the block header is received, and mark the block as N';

[0012] When a complete block is received, mark the complete block as N and check the value of t1;

[0013] When the heights of N and N′ are the same but the hash values are different, record the time parameter of the received complete block N as t2, which is used to represent the time of receiving the competing block for the block header, and continue to monitor other blocks;

[0014] When the heights of N and N′ are the same and the hash values are the same, then N is the complete block corresponding to N′, and record the time parameter of the received complete block N as t3, which is used to represent the time of receiving the complete block corresponding to the block header;

[0015] Determine the attack behavior based on the relationship between the time parameters t1, t2, and t3, and isolate the attacker's block according to the blacklist mechanism.

[0016] An SDoS defense method. According to the behavioral characteristics of SDoS attacks, honest nodes adopt a defense strategy to determine and add the blocks that conform to the attack behavior characteristics and their descendant blocks to the blacklist through the blacklist mechanism. Honest nodes use the blacklist mechanism to screen blocks and work after non-blacklist blocks. When there are multiple longest chains without blacklist blocks, the honest nodes adopting the defense strategy choose to work after the chain where the complete block is received earliest.

[0017] Optionally, the SDoS defense method further includes:

[0018] Calculate the probability that an honest block is added to the blacklist, and construct a Markov chain representing the system state transition and transition probability;

[0019] Calculate the working difficulty after defense, and calculate the income and benefits of honest nodes according to the state probability.

[0020] Optionally, the calculation of the probability that an honest block is added to the blacklist includes calculating the probability that an honest block is added to the blacklist through the proportion of malicious nodes in the total computing power of the blockchain network, the proportion of honest nodes in the total computing power of the system, the block header appearance probability and time, and the system block generation time, as well as the attack strategy. According to the fact that the time probability of finding a block follows an exponential distribution, calculate the honest node P i The formula for the probability that the found block is added to the blacklist is:

[0021]

[0022] where p h is the probability that an honest node publishes the block header first, λ is the speed parameter of finding a block during the working process, θ is the average block header existence time, α i is the proportion of the honest node P i in the total computing power of the entire network, αD(v) is the proportion of honest computing power in the current network, α A is the proportion of malicious computing power in the network is the probability that the block found by honest node P is added to the blacklist when the ratio of honest node's computing power is α D(v) and the ratio of honest node's computing power is α i is the probability that the block found by honest node P is added to the blacklist is the probability that the block found by honest node P is added to the blacklist when the ratio of honest node's computing power is 1 - α A and the ratio of honest node's computing power is 1 - α i is the probability that the block found by honest node P is added to the blacklist

[0023] Optionally, constructing the Markov chain representing the system state transition and transition probability includes, according to the probability that an honest block is added to the blacklist, distinguishing different system states by the number of blocks led by malicious nodes, constructing the Markov chain representing the system state transition and transition probability, and depicting the dynamic movement process of the system between different states through the Markov chain; the system states are divided into normal working state, system fork state and malicious attack state, and there are internal logical connections between the various system states

[0024] Optionally, calculating the working difficulty after defense includes calculating the expected ratio of blockchain computing power after defense, calculating the block generation rate of honest blocks after defense, and calculating the working difficulty after defense according to the block generation rate of honest blocks after defense

[0025] Optionally, calculating the income and profit of honest nodes according to the state probability includes, according to the state probability and the probability that an honest block is added to the blacklist, calculating the working income of honest node P i selecting a defense strategy, calculating the working profit of honest nodes after defense, and calculating the profit of honest nodes choosing an avoidance strategy after defense

[0026] Optionally, when receiving a complete block, marking the complete block as N and checking the value of t1 includes, when honest node P i receives a complete block, marking the complete block as N and checking the value of t1, associating the block header with the complete block through the time parameter t1, and identifying the time dimension of the attack behavior; if t1 > 0, the block header has been received, if t1 ≤ 0, the block header has not been received or all corresponding complete blocks have been received

[0027] Optionally, determining the attack behavior through the relationship between the time parameters t1, t2 and t3, and isolating the attacker's block according to the blacklist mechanism includes, by comparing the magnitude relationship of the time parameters t1, t2 and t3 and sorting them, identifying the attack behavior; if t1 < t2 < t3, the complete block is published after the competing block appears; honest node P iAdd the complete block N to the blacklist, reset the time parameters t1, t2, and t3, and receive the next round of blocks.

[0028] Optionally, the complete block consists of a block header and a block body. The block header contains the block height and the hash value of the parent block. The block body contains specific transaction information. The block height is the distance from this block to the first block, and the parent block is the block at the previous height. If the parent block of the complete block N exists in the blacklist, then the complete block N and all its descendant blocks are determined by the blacklist mechanism as attacker blocks and added to the blacklist.

[0029] Optionally, during the work selection phase, work is only carried out after the non-blacklist blocks determined by the blacklist mechanism.

[0030] The beneficial effects of the present invention are as follows: A SDoS defense method. According to the behavioral characteristics of SDoS attacks, honest nodes adopt a defense strategy to determine and add the blocks that conform to the attack behavioral characteristics and their descendant blocks to the blacklist through the blacklist mechanism. Honest nodes use the blacklist mechanism to screen blocks and work after non-blacklist blocks. When there are multiple longest chains without blacklist blocks, the honest nodes adopting the defense strategy choose to work after the chain that receives the complete block earliest. When all the blocks mined during an SDoS attacker's attack are added to the blacklist by the defense strategy, and the computing power of the defense strategy nodes is greater than that of the attacker, the chain supported by the defense strategy nodes will eventually become the longest chain. If the attacker does not adjust the attack strategy, then the attacker's income will be 0, achieving an effective defense against SDoS. If the attacker chooses to optimize the attack and publishes the complete block corresponding to the block header before others are expected to mine a block, since the average block generation time of the defense strategy nodes is less than the attacker's average block generation time, the attacker should immediately publish the corresponding complete block after publishing the block, and then the system is equivalent to returning to the normal state, where everyone publishes the block immediately after mining it, and the SDoS attack has no effect. Description of the Drawings

[0031] Figure 1 is a flowchart of a SDoS defense method provided by the present invention. Detailed Embodiment

[0032] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings understood by those of ordinary skill in the art in the field to which the present invention belongs. The words such as "including" used herein are intended to mean that the elements or items appearing before this word cover the elements or items listed after this word and their equivalents, without excluding other elements or items.

[0033] An embodiment of the present invention provides an SDoS defense method, which specifically includes the following steps:

[0034] Initialize the time parameter to 0 and initialize the blacklist, enter the block header receiving and listening state, and sense the generation of new blocks in the network;

[0035] When receiving the block header information, record the time parameter of the received block as t1, which is used to represent the time when the block header is received, and mark the block as N';

[0036] When receiving the complete block, mark the complete block as N and check the value of t1;

[0037] When the heights of N and N' are the same but the hash values are different, record the time parameter of the received complete block N as t2, which is used to represent the time when the competing block for the block header is received, and continue to listen for other blocks;

[0038] When the heights of N and N' are the same and the hash values are the same, then N is the complete block corresponding to N', and record the time parameter of the received complete block N as t3, which is used to represent the time when the complete block corresponding to the block header is received;

[0039] Determine the attack behavior based on the relationship among the time parameters t1, t2, and t3, and isolate the attacker's block according to the blacklist mechanism.

[0040] An SDoS defense method. According to the behavioral characteristics of SDoS attacks, honest nodes adopt a defense strategy to determine and add the blocks that conform to the attack behavioral characteristics and their descendant blocks to the blacklist through the blacklist mechanism. Honest nodes use the blacklist mechanism to screen blocks and work after non-blacklist blocks. When there are multiple longest chains without blacklist blocks, the honest nodes adopting the defense strategy choose to work after the chain where the complete block is received earliest.

[0041] Specifically, in some embodiments, the SDoS defense method starts with initializing key parameters, covering multiple aspects such as block reception, competing block identification, time recording, blacklist management, and chain selection. By dynamically monitoring the network status and attack characteristics, it ensures that honest nodes always extend blocks on the longest legitimate chain, ultimately depriving attackers of their benefits.

[0042] Further, in some embodiments, the time parameter of the block header is initialized to 0 and the blacklist is initialized, entering the block header reception monitoring state to sense the generation of new blocks in the network, specifically including:

[0043] Honest nodes first need to initialize key parameters locally, including time parameters t1, t2, and t3, as well as the blacklist. The blacklist is used to record the hash values of blocks determined to be attacker blocks to ensure that subsequent block extensions are not based on these blocks during the subsequent work process. The complete block consists of a block header and a block body. The block header contains the block height and the hash value of the parent block, and the block body contains specific transaction information. A legitimate block needs to meet conditions such as the hash value being less than the difficulty target, the hash value of the parent block matching, and the transaction information being legal. The longest legitimate chain is defined as the longest chain containing all legitimate blocks, and the main chain is this chain. The attacker's private chain may be different from the main chain due to the delayed release of blocks, and competing blocks refer to blocks with the same height but different hashes that compete for the qualification to enter the longest legitimate chain.

[0044] After an honest node starts the defense strategy, it first enters the block header reception monitoring state. Once a block header is received, the reception time is immediately recorded into t1, and the block is marked as N' (including height and hash) to facilitate subsequent tracking of the reception of its complete block. This step ensures that the node can timely sense the generation of new blocks in the network and provides a basis for subsequent processing of competing blocks.

[0045] Further, in some embodiments, the SDoS defense method further includes:

[0046] Calculating the probability that an honest block is added to the blacklist and constructing a Markov chain representing the system state transformation and transformation probability;

[0047] Calculating the working difficulty after defense and calculating the income and benefits of honest nodes based on the state probability.

[0048] Specifically, in some embodiments, calculating the probability of an honest block being added to a blacklist is the starting point. In a blockchain network, there are a variety of factors that may affect the inclusion of honest blocks in the main chain, and interference from malicious nodes is one of them. Malicious nodes may initiate some improper behaviors, such as fork attacks, denial of service attacks, etc., for their own interests, such as to monopolize work income or conduct specific attacks. These behaviors may cause the system to deviate when judging the validity of blocks, and then cause the blocks mined by honest nodes to be mistakenly added to the blacklist. It is usually necessary to comprehensively consider these factors that may cause problems and comprehensively evaluate the probability of honest blocks being added to the blacklist. Through these analyses, the probability of honest blocks being added to the blacklist can be quantified more accurately, providing basic data for subsequent analysis.

[0049] Specifically, in some embodiments, the honest node P i The situation where the found block is added to the blacklist is as follows. i The block is mined and the block header is published first, followed by the block body. During the block transmission process, another honest node P j Mining blocks and publishing them, P i The block is then received. The situation can be transformed into, P i P j The probability of mining a block at an earlier time θ and publishing the block header first.

[0050] use and They represent the honest work computing power ratios respectively D(v) , 1-α A When P i The probability of the block found being added to the blacklist is expressed as θ, and p is used to represent the average block header existence time. h Indicates the probability of publishing the block header first. 0≤p h ≤100%, worst case p h =100%( is the average block time of the blockchain system).

[0051] The probability of calculating the honest block being added to the blacklist includes calculating the probability of the honest block being added to the blacklist through the proportion of malicious nodes in the blockchain network to the total computing power of the system, the proportion of honest nodes to the total computing power of the system, the probability and time of block header appearance, the system block generation time and the attack strategy, and calculating the honest node P according to the time probability of finding the block following the exponential distribution. i The probability formula for the found block to be added to the blacklist is:

[0052]

[0053]

[0054] Among them, p h is the probability that an honest node publishes a block header first, λ is the speed parameter for finding blocks during the operation of the entire system, θ is the average block header existence time under normal circumstances, and α i is the proportion of the honest node P i in the entire network computing power, and α D(v) is the proportion of honest working computing power in the current network, and α A is the proportion of malicious computing power in the network. is when the ratio of honest node working computing power is α D(v) and the probability that the block found by the honest node P i is added to the blacklist. is when the ratio of honest node working computing power is 1 - α A and the probability that the block found by the honest node P i is added to the blacklist.

[0055] Use and to represent the probabilities that the blocks found by P D(v) when the ratios of honest working computing power are α A , 1 - α i respectively, are not added to the blacklist. The specific formula is as follows:

[0056]

[0057] After obtaining the probability that an honest block is added to the blacklist through the above formula, a Markov chain representing the system state transition and transition probability is established. A Markov chain is a powerful mathematical tool that can well describe the transition process of the system between different states. In the blockchain working system, the system state can be defined in various situations.

[0058] The construction of the Markov chain representing the system state transformation and transformation probability includes differentiating different system states according to the number of blocks led by malicious nodes based on the probability that an honest block is added to the blacklist, constructing a Markov chain representing the system state transformation and transformation probability, and depicting the dynamic movement process of the system between different states through the Markov chain; the system state is divided into a normal working state, a system fork state, and a state of being under malicious attack, and there are internal logical connections between the various system states.

[0059] The calculation of the working difficulty after defense includes calculating the expected ratio of blockchain working computing power after defense, calculating the block generation rate of honest blocks after defense, and calculating the working difficulty after defense according to the block generation rate of honest blocks after defense.

[0060] The state transition probability reflects the possibility of the system transitioning from one state to another. Taking the operation of honest nodes as an example, when the system is in a normal operating state, there is a certain probability that it will suddenly be attacked by malicious nodes and thus transition to the state of being maliciously attacked; while in the state of being maliciously attacked, there is also a certain probability that honest nodes will mine a block and confront malicious nodes, thus transitioning to the state of system forking. By constructing such a Markov chain model, the dynamic change relationship between system states and the probability law followed by this change can be clearly depicted. This not only helps to deeply understand the operating mechanism of the system in a complex environment but also provides a theoretical framework for subsequent calculation of system state probabilities.

[0061] The calculation of the income and benefits of honest nodes according to the state probability includes calculating the honest node P after defense according to the state probability and the probability that the honest block is added to the blacklist. i Select the working income of the defense strategy, calculate the working benefits of honest nodes after defense, and calculate the benefits of honest nodes choosing the avoidance strategy after defense.

[0062] Specifically, in some embodiments, use respectively represent the state probabilities of the system under different strategies. Among them, {0, 1, 2, 3,..., n} represents the system state, and the specific data represents the number of blocks in the local private chain of malicious nodes leading the defense strategy support chain. 0 represents the normal state, and 0' represents the system forking state where the defense strategy support chain and the private chain of malicious nodes are both the longest legal chains. v represents the specific strategy selected by honest nodes, v = {D, E}, where D represents the defense strategy and E represents the avoidance strategy, that is, it only operates in the normal state and the system forking state. According to the Markov chain of SDoS after defense, the formula for establishing the state probability equation group is:

[0063]

[0064] Solving the above equations, the formula for the state probability equation group can be obtained as:

[0065]

[0066] The solution of the probabilities of each system state is usually described by some of the above linear equations. These equations are constructed based on the state transition probabilities and the normalization condition of probabilities. Specifically, for each system state, the probability at the next moment is equal to the sum of the products of the probabilities of all other states that can possibly transfer to this state at the current moment and the corresponding transition probabilities. At the same time, since the sum of the probabilities of all system states must be equal to 1, this provides us with another constraint condition. By transforming these relationships into mathematical equations, a system of equations containing the probabilities of all system states can be obtained. Solving this system of equations can yield the probabilities of each state of the system in the steady state. These state probabilities are key parameters for subsequent calculations of income and revenue. They reflect the frequencies of the system in different states, and thus determine the working opportunities and revenue possibilities of honest nodes in different situations.

[0067] After calculating the probabilities of the system states, calculate the difficulty of work after defense. In a blockchain network, the difficulty of work is a dynamically adjusted parameter, which directly affects the probability of a node mining a new block. When the system is under malicious attack or a defense strategy is adopted, factors such as the overall computing power distribution and block propagation speed in the network may change, resulting in an adjustment of the difficulty of work. If the defense strategy effectively isolates the computing power of some malicious nodes, the effective computing power in the network will change, and the system will adjust the difficulty of work according to a certain algorithm to maintain the average time interval for generating new blocks. It is necessary to comprehensively consider the impact of the defense strategy on aspects such as network computing power and block propagation efficiency, and combine the rules for adjusting the difficulty of work in the blockchain protocol to accurately calculate the difficulty of work after defense. This parameter is crucial for accurately evaluating the income and revenue of honest nodes subsequently, directly determining the difficulty of honest nodes mining new blocks after the implementation of the defense strategy, and thus affecting their work revenue.

[0068] In some embodiments, calculating the difficulty of work after defense specifically includes:

[0069] Calculate the ratio of the computing power of the blockchain after defense to the expected value α * as:

[0070]

[0071] Calculate the block generation rate of honest blocks after defense as:

[0072]

[0073] Calculate the difficulty of work λ of the blockchain after defense as:

[0074]

[0075] where λ o is the difficulty of work under normal circumstances.

[0076] After obtaining the system state probability and the work difficulty after defense, calculate the income and profit according to the state probability and the probability that the honest block is added to the blacklist. The income of an honest node mainly comes from the reward obtained by successfully mining a new block and the block finally being on the longest legal chain, while the profit is the net value after subtracting the work cost from the income. When calculating the income, combine the system state probability calculated previously and the probability that the honest block is added to the blacklist. In different system states, the probability of an honest node mining a new block and obtaining income is different. When the system is in a normal working state, the work difficulty is relatively stable, and all blocks are on the longest legal chain. The honest node mines a new block with a certain probability and obtains the corresponding reward; while when the system is under a malicious attack or the honest block is added to the blacklist, the block probability is not on the longest legal chain, and the income will also decrease accordingly. By multiplying the work income in each state by the corresponding system state probability and summing them up, the expected income of the honest node after the implementation of the defense strategy can be obtained. At the same time, the work cost needs to be considered, including the purchase and maintenance costs of hardware devices, power consumption costs, etc. Subtract the work cost from the expected income to obtain the expected profit of the honest node. This step organically combines the analysis results of the previous links and quantitatively evaluates the impact of the defense strategy from an economic perspective.

[0077] In some embodiments, calculating the income and profit of an honest node according to the state probability specifically includes:

[0078] Calculate the honest node P after defense i Select the work income of the defense strategy For:

[0079]

[0080] Calculate the honest node P after defense i Work profit For:

[0081]

[0082] Calculate the honest node P after defense i Select the avoidance side rate profit For:

[0083]

[0084] The above calculation of income and revenue generally involves comparing the revenue of honest nodes after adopting a defense strategy with the revenue of continuously working before the defense under different parameters. To comprehensively evaluate the advantages and disadvantages of the defense strategy, a series of representative parameter combinations need to be selected, and the revenue of honest nodes after adopting the defense strategy and the revenue of continuously working before the defense are calculated respectively under these parameters. By comparing the revenues in these two cases, the economic effects of the defense strategy in different environments can be clearly seen. If the defense strategy can enable honest nodes to obtain higher revenues under most parameter combinations, it indicates that the defense strategy has good economic feasibility and effectiveness; conversely, if the defense strategy leads to a decrease in revenue in most cases, then the strategy needs to be reexamined and optimized. This step provides an important decision-making basis for whether honest nodes adopt the defense strategy in actual operations, and helps to make a choice that is more beneficial to their own interests in the complex blockchain network environment.

[0085] Specifically, in some embodiments, the income before and after the defense is compared through experiments. Before the defense, the honest nodes {continuously work, adopt the avoidance strategy}, and after the defense, the honest nodes choose {the defense strategy, work only when the attacker has no advantage}, and the avoidance strategy is to work only when the attacker has no advantage.

[0086] In the worst case ( p h = 100%), the experimental comparison of the income of honest node P i after adopting the defense strategy and the income of continuously working before the defense under the same parameters is carried out. In most cases, the income of honest node P i after adopting the defense strategy is greater than the income of continuously working before the defense. Only when the computing power ratio of the attacker α A is very low (less than 0.05) and the computing power ratio of other nodes adopting the defense strategy is very high, the situation of low income will occur. Since the threshold computing power ratio for the attacker to increase income by launching an SDoS attack is 19.6%, and the attacker will not launch an attack when it is lower than this threshold, it can be considered that in general, the income of honest node P i after adopting the defense strategy is greater than the income of continuously working before the defense. Further explanation is that the honest nodes that continuously worked before the defense will all choose the defense strategy for higher revenue.

[0087] Due to the different costs of different honest nodes P i , the profit factor at this time is used as the key profit factor If the profit w when not under attack i satisfies It is proved that the revenue of honest node P i after adopting the defense strategy is greater than the revenue of the avoidance strategy (note that w i> 1, otherwise, even under normal circumstances, honest node P i will not choose to work).

[0088] Through experiments, it is found that in most cases, for example, when α i = 0.05 and α i = 0.2, only in some areas will the benefit ratio be lower than 1. Since the threshold computing power ratio for an attacker to increase revenue by launching an SDoS attack is 19.6%, the attacker will not launch an attack when it is lower than this threshold. Therefore, it can be considered that in general, the benefit of adopting a defense strategy after defense is higher. Further explanation, when the computing power of the defense strategy is greater than that of the attacker, after defense, honest nodes that do not choose the defense strategy will also choose the defense strategy for higher benefits, and ultimately all honest nodes will choose the defense strategy.

[0089] According to the above analysis, after being attacked by an SDoS attack, before defense, honest nodes choose {always work, avoidance strategy} according to the level of benefits. Since the benefit of the defense strategy is higher than always working, after defense, honest nodes choose {defense strategy, avoidance strategy} according to the level of benefits. And because the benefit of the defense strategy after defense is higher than the avoidance strategy, it will ultimately evolve into all honest nodes choosing the defense strategy.

[0090] In summary, when the computing power of the defense strategy is greater than that of the attacker, the defense method proposed by the present invention can not only make the income of the attacker from continuing the attack lower than the income from giving up the attack, thus forcing the attacker to give up the attack, but also, in most cases, improve the income of nodes that always work, and moreover, encourage all honest nodes to choose the defense strategy and reduce the harm of the attack.

[0091] When receiving a complete block, marking the complete block as N and checking the value of t1 includes that when honest node P i receives a complete block, marking the complete block as N and checking the value of t1, associating the block header with the complete block through the time parameter t1 to identify the time dimension of the attack behavior; if t1 > 0, the block header has been received, if t1 ≤ 0, the block header has not been received or all corresponding complete blocks have been received.

[0092] Determining the attack behavior through the relationship between the time parameters t1, t2, and t3, and isolating the attacker's block according to the blacklist mechanism includes comparing the magnitude relationship of the time parameters t1, t2, and t3 and sorting them to identify the attack behavior; if t1 < t2 < t3, the complete block was published after the competing block appeared; honest node P i adds the complete block N to the blacklist, resets the time parameters t1, t2, and t3, and receives the next round of blocks.

[0093] The complete block consists of a block header and a block body. The block header contains the block height and the hash value of the parent block. The block body contains specific transaction information. The block height is the distance from this block to the first block, and the parent block is the block at the previous height. If the parent block of the complete block N exists in the blacklist, then the complete block N and all its descendant blocks are determined by the blacklist mechanism as attacker blocks and added to the blacklist.

[0094] When in the work selection phase, work is only carried out after the non-blacklist blocks determined by the blacklist mechanism.

[0095] Specifically, in some embodiments, as Figure 1 shown, the step process of an SDoS defense method can be summarized as:

[0096] Starting from the start node, first perform initialization operations, including initializing time variables t1, t2, t3 and initializing the blacklist. Next, the process enters a judgment link to check whether a block header is received. If the block header is not received, the process loops and waits here; if the block header is received, record the local reception time t1 and mark the corresponding block as N'.

[0097] Subsequently, the process continues to judge whether a complete block is received. If the complete block is not received, the process returns to the previous step and continues to wait; if the complete block is received, mark the corresponding block as N. Then, the process checks whether t1 is greater than 0. If t1 is greater than 0, further judge whether the heights of N and N' are the same. If the heights are different or t1 is not greater than 0 and the parent block of N is in the blacklist, the process adds N to the blacklist, resets t1, t2, t3, and then returns to re-judge whether a block header is received.

[0098] If t1 is greater than 0 and the heights of N and N' are the same, the process continues to judge whether the hash values of N and N' are different. If the hash values are different, record the reception time t2 of N, and the process returns to re-judge whether a complete block is received; if the hash values are the same, record the reception time t3 of N. After that, the process checks whether t1 is less than t2 and whether t2 is less than t3. If this condition is not satisfied, the process returns to re-judge whether a block header is received; if the condition is satisfied, add N to the blacklist, reset t1, t2, t3, and then return to re-judge whether a block header is received.

[0099] The entire process is in continuous loop, performing a series of judgments and processing on the received blockchain data. The ultimate goal is to find the longest and earliest received non-blacklist chain for work operations.

[0100] An SDoS defense method. According to the behavioral characteristics of SDoS attacks, honest nodes adopt defense strategies to determine the blocks that conform to the attack behavioral characteristics and their descendant blocks through the blacklist mechanism and add them to the blacklist. Honest nodes use the blacklist mechanism to filter blocks and work after non-blacklist blocks. When there are multiple longest chains without blacklist blocks, the honest nodes adopting the defense strategy choose to work after the chain that receives the complete block earliest.

[0101] The defense strategy proposed by the present invention is based on an incentive mechanism. By reducing the attacker's income, the attacker is made to actively stop the attack, and the harm of SDoS attacks can be reduced, enabling more nodes to work actively. In most cases, the income of honest nodes that keep working will be increased. Considering the income of honest nodes' defense, there is no need to defend at all costs or even with negative income, making it easier to promote the defense strategy among honest nodes.

[0102] The present invention also provides a defense strategy for SDoS attacks to honest nodes. After a sufficient number of honest nodes actively defend, if the attacker continues to attack, it will instead reduce its income, so the attacker will actively choose to stop the attack.

[0103] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention described in the claims. Moreover, the present invention described herein can have other embodiments and can be implemented or realized in various ways.

Claims

1. A method for SDoS defense, characterized in that, Including: Initialize the time parameter to 0 and initialize the blacklist, enter the block header receiving and listening state, and sense the generation of new blocks in the network; When receiving the block header information, record the time parameter of the received block as t1, which is used to represent the time of receiving the block header, and mark the block as N'; When receiving a complete block, mark the complete block as N and check the value of t1; When the heights of N and N' are the same but the hash values are different, record the time parameter of the received complete block N as t2, which is used to represent the time of receiving the competing block for the block header, and continue to listen for other blocks; When the heights of N and N' are the same and the hash values are the same, then N is the complete block corresponding to N', and record the time parameter of the received complete block N as t3, which is used to represent the time of receiving the complete block corresponding to the block header; Judge the attack behavior through the relationship of the time parameters t1, t2, and t3, and isolate the attacker's block according to the blacklist mechanism.

2. The SDoS defense method according to claim 1, wherein The SDoS defense method further includes: Calculate the probability that an honest block is added to the blacklist, and construct a Markov chain representing the system state transition and transition probability; Calculate the work difficulty after defense, and calculate the income and profit of honest nodes according to the state probability.

3. The SDoS defense method according to claim 2, wherein Calculating the probability that an honest block is added to the blacklist includes calculating the probability that an honest block is added to the blacklist based on the proportion of malicious nodes in the blockchain network to the total computing power of the system, the proportion of honest nodes to the total computing power of the system, the probability and time of block header appearance, the block generation time of the system, and the attack strategy. According to the fact that the time probability of finding a block follows an exponential distribution, calculate the probability of honest node P i The formula for the probability that the found block is added to the blacklist is: Among them, p h is the probability that an honest node publishes a block header first, λ is the speed parameter for finding a block during the operation, θ is the average block header existence time, α i is the proportion of the honest node P i in the entire network computing power, α D(v) is the proportion of the honest computing power in the current network, α A is the proportion of malicious computing power in the network, is the probability that the block found by the honest node with the honest computing power ratio of α D(v) is added to the blacklist when the honest node P i finds it, is the probability that the block found by the honest node with the honest computing power ratio of 1 - α A is added to the blacklist when the honest node P i finds it.

4. The SDoS defense method according to claim 2, characterized in that, The construction of the Markov chain representing the system state transition and transition probability includes, according to the probability that an honest block is added to the blacklist, distinguishing different system states through the number of blocks led by malicious nodes, constructing a Markov chain representing the system state transition and transition probability, and depicting the dynamic movement process of the system between different states through the Markov chain; the system states are divided into normal working state, system fork state, and malicious attack state, and there are internal logical connections between the various system states.

5. The SDoS defense method according to claim 2, wherein The calculation of the work difficulty after defense includes calculating the ratio of the blockchain work computing power after defense to the expectation, calculating the block generation rate of honest blocks after defense, and calculating the work difficulty after defense according to the block generation rate of honest blocks after defense.

6. The SDoS defense method according to claim 2, wherein Calculating the income and benefits of honest nodes based on state probabilities includes calculating the honest node P after defense according to the state probability and the probability that the honest block is added to the blacklist. i Selecting the working income of the defense strategy, calculating the working benefits of the honest node after defense, and calculating the benefits of the honest node choosing the avoidance strategy after defense.

7. The SDoS defense method according to claim 1, characterized in that, When a complete block is received, mark the complete block as N, and the check of the value of t1 includes that when the honest node P i When a complete block is received, mark the complete block as N, and check the value of t1. Associate the block header with the complete block through the time parameter t1 to identify the time dimension of the attack behavior; if t1 > 0, the block header has been received, and if t1 ≤ 0, the block header has not been received or all corresponding complete blocks have been received.

8. An SDoS defense method according to claim 1, characterized in that, Determining an attack behavior based on the relationship between the time parameters t1, t2, and t3, and isolating the attacker's block according to the blacklist mechanism includes identifying the attack behavior by comparing the magnitude relationship of the time parameters t1, t2, and t3 and sorting them; if t1 < t2 < t3, the complete block is published after the competing block appears; honest node P i Add the complete block N to the blacklist, reset the time parameters t1, t2, and t3, and receive the next round of blocks.

9. The SDoS defense method according to claim 1, characterized in that The complete block consists of a block header and a block body. The block header contains the block height and the hash value of the parent block. The block body contains specific transaction information; the block height is the distance from this block to the first block, and the parent block is the block at the previous height; if the parent block of the complete block N exists in the blacklist, then the complete block N and all its descendant blocks are determined by the blacklist mechanism to be attacker blocks and added to the blacklist.

10. A method for SDoS defense according to claim 9, characterized in that, When in the work selection stage, work only after the non-blacklist blocks determined by the blacklist mechanism.