Distributed denial of service attack defense method and device, electronic equipment and storage medium

By building a convex optimization model in the blockchain network monitoring system and selecting the optimal consensus node to defend against DDoS attacks, the problem of poor effectiveness of traditional defense methods is solved and more efficient network defense is achieved.

CN120342709APending Publication Date: 2025-07-18CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510524189.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The traditional distributed denial of service attack defense method has poor defense effect, especially when facing large DDoS attacks, increasing bandwidth and deploying firewalls cannot effectively block attack traffic.

Method used

By building a blockchain network monitoring system, the monitoring equipment obtains network performance indicators of each node, calculates the health and connection stability of the nodes, builds a convex optimization model to select the optimal consensus node, and uses smart contracts to update the consensus node to defend against DDoS attacks.

Benefits of technology

It improves consensus efficiency and target network resistance, significantly improves defense effect, and reduces the impact of DDoS attacks on network performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342709A_ABST
    Figure CN120342709A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed denial of service attack defense method and device, electronic equipment and a storage medium, and is used for solving the problem that a traditional distributed denial of service attack defense mode is poor in defense effect, and the method comprises the steps that monitoring equipment obtains a network performance index of each node in a block chain in a current time period; determining the health degree corresponding to each node according to the network performance index of each node; constructing an objective function of the probability that the nodes are selected as consensus nodes according to the health degree, the network delay and the bandwidth usage amount of the nodes; according to the health degree of each node, the network delay of each node and the bandwidth usage amount of each node, a preset optimization algorithm is adopted to solve an optimal solution of the target function, and the probability that each node is selected as a consensus node is obtained; and determining a target consensus node for the node of which the probability of being selected as the consensus node is greater than or equal to a preset probability threshold, and updating the consensus node in the block chain to the target consensus node through the smart contract in the next time period.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular, to a method, device, electronic device, and storage medium for defending against distributed denial of service attacks. Background Art

[0002] The number of Internet of Things (IoT) devices has been growing rapidly. When manufacturing these IoT devices, the main investment is usually concentrated on the functions of the devices themselves, while ignoring the network security attributes of the devices. In this way, hackers can easily use these easily controllable IoT devices as springboards or zombie hosts to further enrich their attack resources to achieve their attack goals. Taking the distributed denial of service (DDoS) attack as an example, hackers can simultaneously control a large number of zombie hosts through a master controller and use automated scripts to launch attacks on numerous potential target network systems in various networks including the IoT, thereby causing the attacked target system to be unable to provide normal business services. As Figure 1 shown, it is a schematic diagram of a typical DDoS attack, and the attacked target network system is an autonomous system (AS).

[0003] In traditional DDoS attack defense methods, one way is to increase bandwidth. Although expanding bandwidth can temporarily alleviate small DDoS attacks, it has a poor protection effect on large DDoS attacks. One way is to deploy a firewall or an intrusion detection system to monitor network traffic in real time, identify malicious traffic, and automatically block malicious traffic when necessary. However, this method cannot ensure that all DDoS attack traffic is blocked, and it has a poor defense effect on DDoS attacks that have entered the target network. Summary of the Invention

[0004] To solve the problem of poor defense effect of traditional distributed denial of service attack defense methods, embodiments of this application provide a method, device, electronic device, and storage medium for defending against distributed denial of service attacks.

[0005] In a first aspect, embodiments of this application provide a method for defending against distributed denial of service attacks, which is applied to a network monitoring system. The network monitoring system includes monitoring devices and a blockchain constructed by nodes of a target network. The method includes:

[0006] The monitoring device obtains network performance metrics of each node in the blockchain during the current time period. The network performance metrics at least include traffic load, network latency, and bandwidth usage;

[0007] Determine the respective health levels according to the network performance indicators of each node, where the health level characterizes the health degree of the node;

[0008] Construct an objective function for the probability that a node is selected as a consensus node based on the health level, network latency, and bandwidth usage of the node. The objective function is a convex optimization model for maximizing the health level of the selected consensus nodes and minimizing network latency and resource consumption;

[0009] According to the health level of each node, the network latency of each node, and the bandwidth usage of each node, use a preset optimization algorithm to solve the optimal solution of the objective function to obtain the probability that each node is selected as a consensus node;

[0010] Determine the target consensus nodes for the nodes whose probability of being selected as consensus nodes is greater than or equal to a preset probability threshold, and update the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period to defend against distributed denial-of-service attacks through the target consensus nodes.

[0011] In one implementation, the network performance indicator further includes a connection stability score, where the connection stability score characterizes the stability degree of the network connection of the node; and

[0012] For each node, determine the connection stability score of the node in the following manner:

[0013] Count the number of network connection interruptions between the node and other nodes in the current time period;

[0014] Determine the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and a preset maximum number of interruptions.

[0015] In one implementation, determining the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and a preset maximum number of interruptions specifically includes:

[0016] Calculate the connection stability score of the node through the following formula:

[0017]

[0018] where S i represents the connection stability score of the i-th node in the blockchain;

[0019] d i represents the number of network connection interruptions between the i-th node and other nodes;

[0020] D max represents the preset maximum number of interruptions.

[0021] In one embodiment, the healthiness corresponding to each node is determined according to the network performance metrics of each node, specifically including:

[0022] The healthiness of each node is calculated by the following formula:

[0023]

[0024] where H i represents the healthiness of the i-th node in the blockchain;

[0025] L i represents the network latency of the i-th node, and k1 represents the first weight of the network latency of the i-th node;

[0026] B i represents the bandwidth usage of the i-th node, and B i,max represents the maximum bandwidth of the i-th node, represents the bandwidth utilization rate of the i-th node, represents the remaining bandwidth utilization rate of the i-th node, and k2 represents the weight of the remaining bandwidth utilization rate of the i-th node;

[0027] U i represents the traffic load of the i-th node, and U i,max represents the maximum traffic load of the i-th node, represents the traffic load utilization rate of the i-th node, represents the remaining traffic load utilization rate of the i-th node, and k3 represents the weight of the remaining traffic load utilization rate of the i-th node;

[0028] S i represents the connection stability score of the i-th node, and k4 represents the weight of the connection stability score of the i-th node.

[0029] In one embodiment, an objective function for the probability that a node is selected as a consensus node is constructed according to the healthiness, network latency, and bandwidth usage of the node, specifically including:

[0030] The objective function is constructed as follows:

[0031]

[0032] And the constraint conditions are constructed as follows:

[0033]

[0034] where f(p i ) is the objective function;

[0035] N represents the number of nodes in the blockchain;

[0036] p i represents the probability that the i-th node is selected as a consensus node, p i ∈ [0, 1], i = 1, 2, …, N;

[0037] H i represents the health of the i-th node, and α represents the weight of the health of the i-th node;

[0038] L i represents the network latency of the i-th node, and β represents the second weight of the network latency of the i-th node;

[0039] B i represents the bandwidth usage of the i-th node, B i,max represents the maximum bandwidth of the i-th node, B i,max -B i represents the remaining bandwidth usage of the i-th node, and γ represents the weight of the remaining bandwidth usage of the i-th node;

[0040] ε(p i ) is a step function, and T represents the first probability threshold;

[0041] N min represents the minimum number of consensus nodes selected;

[0042] H T represents the health threshold;

[0043] B T represents the bandwidth threshold;

[0044] U i represents the traffic load of the i-th node, U max represents the maximum traffic load.

[0045] In one implementation, according to the health of each node, the network latency of each node, and the bandwidth usage of each node, a preset optimization algorithm is used to solve the optimal solution of the objective function, and the probability that each node is selected as a consensus node is obtained, specifically including:

[0046] The optimal solution of the objective function is solved by the following gradient descent method:

[0047]

[0048]

[0049] Among them, k represents the iteration round, and η is the iteration step size;

[0050] represents the probability that the i-th node is selected as a consensus node when the iteration round is k + 1; represents the probability that the i-th node is selected as a consensus node when the iteration round is k;

[0051] represents the gradient value of the probability that the i-th node is selected as a consensus node when the iteration round is k;

[0052] represents the probability matrix of the N nodes in the blockchain being selected as consensus nodes.

[0053] In a second aspect, an embodiment of the present application provides a distributed denial of service attack defense device, which is applied to a network monitoring system. The network monitoring system includes monitoring devices and a blockchain constructed by nodes of a target network. The device includes:

[0054] An acquisition module, configured to acquire network performance indicators of each node in the blockchain during the current time period. The network performance indicators at least include traffic load, network latency, and bandwidth usage;

[0055] A first determination module, configured to determine the corresponding health degree of each node according to the network performance indicators of each node. The health degree characterizes the health level of the node;

[0056] A construction module, configured to construct an objective function of the probability that a node is selected as a consensus node according to the health degree, network latency, and bandwidth usage of the node. The objective function is a convex optimization model for maximizing the health degree of the selected consensus nodes and minimizing network latency and resource consumption;

[0057] A calculation module, configured to solve the optimal solution of the objective function according to the health degree of each node, the network latency of each node, and the bandwidth usage of each node by using a preset optimization algorithm, and obtain the probability that each node is selected as a consensus node;

[0058] A second determination module, configured to determine nodes with the probability of being selected as consensus nodes greater than or equal to a preset probability threshold as target consensus nodes, and update the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period, so as to defend against distributed denial of service attacks through the target consensus nodes.

[0059] In one implementation, the network performance indicators further include a connection stability score, and the connection stability score characterizes the stability degree of the network connection of the node;

[0060] The obtaining module is further configured to determine the connection stability score of each node in the following manner: counting the number of network connection interruptions between the node and other nodes during the current time period; determining the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and a preset maximum number of interruptions.

[0061] In one implementation, the obtaining module is specifically configured to calculate the connection stability score of the node through the following formula:

[0062]

[0063] where S i represents the connection stability score of the i-th node in the blockchain;

[0064] d i represents the number of network connection interruptions between the i-th node and other nodes;

[0065] D max represents the preset maximum number of interruptions.

[0066] In one implementation, the first determination module is specifically configured to calculate the health of each node through the following formula:

[0067]

[0068] where H i represents the health of the i-th node in the blockchain;

[0069] L i represents the network latency of the i-th node, and k1 represents the first weight of the network latency of the i-th node;

[0070] B i represents the bandwidth usage of the i-th node, and B i,max represents the maximum bandwidth of the i-th node, represents the bandwidth usage rate of the i-th node, represents the remaining bandwidth usage rate of the i-th node, and k2 represents the weight of the remaining bandwidth usage rate of the i-th node;

[0071] U i represents the traffic load of the i-th node, and U i,max represents the maximum traffic load of the i-th node, represents the traffic load usage rate of the i-th node, represents the remaining traffic load usage rate of the i-th node, and k3 represents the weight of the remaining traffic load usage rate of the i-th node;

[0072] S i represents the connection stability score of the i-th node, and k4 represents the weight of the connection stability score of the i-th node.

[0073] In one implementation, the construction module is specifically configured to construct the objective function as follows:

[0074]

[0075] And construct the constraint conditions as follows:

[0076]

[0077] where f(p i ) is the objective function;

[0078] N represents the number of nodes in the blockchain;

[0079] p i represents the probability that the i-th node is selected as a consensus node, p i ∈[0, 1], i = 1, 2, …, N;

[0080] H i represents the health of the i-th node, and α represents the weight of the health of the i-th node;

[0081] L i represents the network latency of the i-th node, and β represents the second weight of the network latency of the i-th node;

[0082] B i represents the bandwidth usage of the i-th node, B i,max represents the maximum bandwidth of the i-th node, B i,max -B i represents the remaining bandwidth usage of the i-th node, and γ represents the weight of the remaining bandwidth usage of the i-th node;

[0083] ε(p i ) is a step function, and T represents the first probability threshold;

[0084] N min represents the minimum number of selected consensus nodes;

[0085] H T represents the health threshold;

[0086] B T represents the bandwidth threshold;

[0087] U irepresents the traffic load of the i-th node, U max represents the maximum traffic load.

[0088] In one embodiment, the computing module is specifically configured to solve the optimal solution of the objective function by the following gradient descent method:

[0089]

[0090]

[0091] where k represents the number of iteration rounds, and η is the iteration step size;

[0092] represents the probability that the i-th node is selected as a consensus node when the number of iteration rounds is k + 1; represents the probability that the i-th node is selected as a consensus node when the number of iteration rounds is k;

[0093] represents the gradient value of the probability that the i-th node is selected as a consensus node when the number of iteration rounds is k;

[0094] represents the probability matrix of the N nodes in the blockchain being selected as consensus nodes.

[0095] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the distributed denial of service attack defense method described in the present application is implemented.

[0096] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps in the distributed denial of service attack defense method described in the present application are implemented.

[0097] The beneficial effects of the present application are as follows:

[0098] The distributed denial of service attack defense method provided by the embodiments of the present application is applied to a network monitoring system. The network monitoring system includes monitoring devices and a blockchain constructed by nodes of a target network. The monitoring devices obtain the network performance indicators of each node in the blockchain during the current time period. The network performance indicators at least include traffic load, network latency, and bandwidth usage. Determine the respective corresponding health degrees according to the network performance indicators of each node. The health degree represents the health level of the node. Construct an objective function for the probability that a node is selected as a consensus node according to the health degree, network latency, and bandwidth usage of the node. The objective function is a convex optimization model for maximizing the health degree of the selected consensus node and minimizing network latency and resource consumption. Solve the optimal solution of the objective function by using a preset optimization algorithm according to the health degree of each node, the network latency of each node, and the bandwidth usage of each node, and obtain the probability that each node is selected as a consensus node. Determine the target consensus nodes for the nodes whose probability of being selected as consensus nodes is greater than or equal to a preset probability threshold, and update the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period, so as to defend against distributed denial of service attacks through the target consensus nodes. In the embodiments of the present application, the nodes in the target network are first constructed into a blockchain. The blockchain needs consensus nodes distributed everywhere to vote and make decisions during operation. In order to ensure the legitimacy and security of the consensus nodes participating in the vote when a distributed denial of service attack occurs, the present application models the selection of consensus nodes as a convex optimization problem to maximize the overall health degree of the selected consensus nodes and minimize network latency and resource consumption. Based on the constructed convex optimization model, the optimal set of consensus nodes is selected in real time according to the network performance indicators of each node in the current time period as the target consensus nodes in the next time period. Thus, the defense against distributed denial of service attacks is realized according to the updated target consensus nodes, avoiding attack nodes as consensus nodes to maximize network performance, minimizing the impact of distributed denial of service attacks on the target network, significantly improving the consensus efficiency and the anti-attack ability of the target network, and improving the defense effect.

[0099] Other features and advantages of the present application will be described in the following specification, and, in part, will become apparent from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained by the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0100] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:

[0101] Figure 1 It is a schematic diagram of a typical DDoS attack;

[0102] Figure 2 Schematic diagram of the application scenario of the distributed denial of service attack defense method provided by the embodiment of the present application;

[0103] Figure 3 Flow diagram of the distributed denial of service attack defense method provided by the embodiment of the present application;

[0104] Figure 4 Flow diagram of determining the connection stability score of a node provided by the embodiment of the present application;

[0105] Figure 5 Schematic diagram of the structure of the distributed denial of service attack defense device provided by the embodiment of the present application;

[0106] Figure 6 Schematic diagram of the structure of the electronic device provided by the embodiment of the present application. Specific embodiments

[0107] In order to solve the problem that the traditional distributed denial of service attack defense method has a poor defense effect, the embodiment of the present application provides a distributed denial of service attack defense method, device, electronic device and storage medium.

[0108] The following describes the preferred embodiments of the present application with reference to the accompanying drawings of the specification. It should be understood that the preferred embodiments described herein are only for the purpose of illustrating and explaining the present application, and are not used to limit the present application. And without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other.

[0109] In this article, it should be understood that among the technical terms involved in the present application:

[0110] 1. Internet of Things: "The Internet where everything is connected", which is an extension and expansion of the Internet, realizing the interconnection of people, machines, and things at any time and any place.

[0111] 2. DDoS attack: A distributed denial of service attack refers to multiple attackers at different locations simultaneously launching attacks on one or several targets, or one attacker controlling multiple machines located at different locations and using these machines to simultaneously attack the victim.

[0112] 3. Convex Optimization: It is a branch of mathematical optimization that focuses on a special class of optimization problems - where both the objective function and the constraints are convex. Such problems have received wide attention because they possess many desirable properties, such as the existence and uniqueness of the global optimal solution, as well as a variety of effective algorithms for solving these problems. Convex optimization is applied in many disciplinary fields, such as automatic control systems, signal processing, communication and networks, electronic circuit design, data analysis and modeling, statistics (optimal design), and the financial field, etc.

[0113] First, refer to Figure 2 , which is a schematic diagram of an application scenario of the distributed denial-of-service attack defense method provided by the embodiments of the present application. The network monitoring system includes a monitoring device 101 and a blockchain constructed by nodes of the target network 102. The monitoring device 101 includes a network monitoring and node status analysis module 1011, a convex optimization model construction module 1012, and a consensus phase update and smart contract trigger module 1013. The monitoring device 101 is connected to the target network 102 through a network. The monitoring device 101 can be, but is not limited to, a server. The target network 102 can be an autonomous domain or any other network to be monitored, such as an enterprise intranet, etc. The embodiments of the present application do not make any limitations in this regard. Each node included in the target network 102 may include devices such as routers, switches, Internet of Things devices, computers, and servers. Routers and switches are responsible for forwarding data traffic, and Internet of Things devices, computers, and servers can be responsible for processing and forwarding data traffic, etc. Among them, the data traffic may include service data traffic, attack traffic such as DDoS attack traffic. The service data can be, but is not limited to, including: Internet of Things service data, video service data, online transaction service data, social media service data, etc. The embodiments of the present application do not make any limitations in this regard. In the embodiments of the present application, the monitoring device 101 can preset the update time period T of the consensus nodes in the blockchain. update, for example, it can be set to update the consensus node set in the blockchain every 10 minutes. When a DDoS attack enters the target network 102, it is possible to avoid selecting the attacked node as a consensus node, select a consensus node set with the best overall quality, taking into account network latency and minimizing resource consumption to maximize network performance, minimize the impact of the DDoS attack on the target network 102, improve the consensus efficiency and the anti-attack ability of the target network 102, and enhance the defense effect. In the embodiment of the present application, the network monitoring and node status analysis module 1011 in the monitoring device 101 obtains the network performance indicators of each node in the blockchain during the current time period. The network performance indicators at least include traffic load, network latency, and bandwidth usage. The health degree corresponding to each node is determined according to the network performance indicator of each node. The health degree represents the health level of the node. The convex optimization model construction module 1012 constructs an objective function for the probability that a node is selected as a consensus node according to the health degree, network latency, and bandwidth usage of the node. The objective function is a convex optimization model for maximizing the health degree of the selected consensus node and minimizing network latency and resource consumption. According to the health degree of each node, the network latency of each node, and the bandwidth usage of each node, a preset optimization algorithm is used to solve the optimal solution of the objective function, and the probability that each node is selected as a consensus node is obtained. The nodes with the probability of being selected as a consensus node greater than or equal to the preset probability threshold are determined as the target consensus nodes. The consensus phase update and smart contract trigger module 1013 updates the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period to defend against distributed denial-of-service attacks through the target consensus nodes.

[0114] In the present application, the server can be an independent physical server or a cloud server that provides basic cloud computing services such as cloud servers, cloud databases, and cloud storage. The embodiments of the present application do not limit this.

[0115] Based on the above application scenarios, the following will refer to the attached Figures 3 - 4 More specifically, the exemplary embodiments of the present application will be described. It should be noted that the above application scenarios are only shown for the convenience of understanding the spirit and principle of the present application, and the embodiments of the present application are not limited by this. On the contrary, the embodiments of the present application can be applied to any applicable scenario.

[0116] Such as Figure 3 As shown, it is a schematic flowchart of the implementation process of the distributed denial-of-service attack defense method provided by the embodiment of the present application. The distributed denial-of-service attack defense method can be applied to the above network monitoring system and specifically includes the following steps:

[0117] S21. The monitoring device obtains the network performance indicators of each node in the blockchain during the current time period.

[0118] In specific implementation, the monitoring device pre-sets the update time period T of the consensus nodes in the blockchain update , so as to automatically update the consensus nodes of the next time period according to the set of consensus nodes updated in the previous time period.

[0119] In implementation, the monitoring device obtains the network performance metrics of each node in the current time period from the nodes in the blockchain. Each node can also actively report its own network performance metrics to the monitoring device. The network performance metrics at least include traffic load, network latency, and bandwidth usage, and also include a connection stability score, where the connection stability score represents the stability degree of the network connection of the node. The traffic load of the node is the total amount of data traffic processed by the node in the current world period (including the forwarded data traffic), and may also include other metrics that can measure network performance. This application embodiment does not limit this. When a general DDoS attack occurs, the traffic trend of the attacked nodes in the blockchain will be abnormal, and these abnormalities are reflected in aspects such as traffic load, network latency, bandwidth usage rate (or bandwidth usage), and connection stability. Therefore, in this application, the monitoring system can monitor these network performance metrics of each node in real time and measure the health status of each node based on these network performance metrics.

[0120] For each node, the connection stability score of the node can be determined according to the process as Figure 4 shown:

[0121] S31. Count the number of network connection interruptions between the node and other nodes in the current time period.

[0122] In specific implementation, the monitoring device monitors the number of interruptions of the network connection between each node and the other nodes it is connected to (or the number of times of communication failure and disconnection with other nodes). For each node, the monitoring device counts the number of network connection interruptions between this node and other nodes in the current time period.

[0123] S32. Determine the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and the preset maximum number of interruptions.

[0124] In specific implementation, the connection stability score of each node can be calculated through the following formula:

[0125]

[0126] where S i represents the connection stability score of the i-th node in the blockchain, i = 1, 2,..., N, and N represents the number of nodes in the blockchain;

[0127] d i represents the number of network connection interruptions between the i-th node and other nodes;

[0128] D max represents the preset maximum number of interruptions.

[0129] D max The value of D can be preset according to requirements.

[0130] S22. Determine the respective health levels according to the network performance indicators of each node.

[0131] In specific implementation, the monitoring device determines the respective health levels according to the network performance indicators of each node. The health level characterizes the health degree of the node, and quantifies the network performance indicators of the node into a comprehensive health score.

[0132] Specifically, the health level of each node can be calculated by the following formula:

[0133]

[0134] where H i represents the health level of the i-th node in the blockchain;

[0135] L i represents the network latency of the i-th node, and k1 represents the first weight of the network latency of the i-th node;

[0136] B i represents the bandwidth usage of the i-th node, and B i,max represents the maximum bandwidth of the i-th node, represents the bandwidth usage rate of the i-th node, represents the remaining bandwidth usage rate of the i-th node, and k2 represents the weight of the remaining bandwidth usage rate of the i-th node;

[0137] U i represents the traffic load of the i-th node, and U i,max represents the maximum traffic load of the i-th node, represents the traffic load usage rate of the i-th node, represents the remaining traffic load usage rate of the i-th node, and k3 represents the weight of the remaining traffic load usage rate of the i-th node;

[0138] S i represents the connection stability score of the i-th node, and k4 represents the weight of the connection stability score of the i-th node.

[0139] k1 + k2 + k3 + k4 = 1, and the values of k1, k2, k3, and k4 can be set according to the performance requirements of the service traffic. For services with high latency requirements such as video streams, the value of k1 can be set higher than k2, k3, and k4. For example, it can be set as k1 = 0.4, k2 = 0.2, k3 = 0.2, k4 = 0.2. The embodiments of the present application do not limit this.

[0140] S23. Construct an objective function for the probability that a node is selected as a consensus node based on the health, network latency, and bandwidth usage of the node. The objective function is a convex optimization model for maximizing the health of the selected consensus nodes and minimizing network latency and resource consumption.

[0141] Specifically, when constructing the objective function of the convex optimization model, it is considered to maximize the overall health of the selected target shared node set and minimize the network latency and resource consumption during the consensus process. Based on this, a convex optimization model for the probability that a node is selected as a consensus node is constructed using the three network performance metrics of the health, network latency, and bandwidth usage of the node, and the objective function is established as follows:

[0142]

[0143] And the following constraint conditions are constructed:

[0144]

[0145]

[0146] Among them, f(p i ) is the objective function;

[0147] N represents the number of nodes in the blockchain;

[0148] p i represents the probability that the i-th node is selected as a consensus node, p i ∈ [0, 1], i = 1, 2,..., N;

[0149] H i represents the health of the i-th node, and α represents the weight of the health of the i-th node;

[0150] L i represents the network latency of the i-th node, and β represents the second weight of the network latency of the i-th node;

[0151] B i represents the bandwidth usage of the i-th node, B i,max represents the maximum bandwidth of the i-th node, B i,max - B irepresents the remaining bandwidth usage of the i-th node, and γ represents the weight of the remaining bandwidth usage of the i-th node;

[0152] ε(p i ) is a step function, and T represents the first probability threshold;

[0153] N min represents the minimum number of consensus nodes selected;

[0154] H T represents the health threshold;

[0155] B T represents the bandwidth threshold;

[0156] U i represents the traffic load of the i-th node, and U max represents the maximum traffic load.

[0157] p i is a continuous variable. If it is set as a discrete variable that can only take values of 0 or 1, the convexity of the entire objective function cannot be guaranteed. α + β + γ = 1, and the values of α, β, and γ can be set according to actual needs. For example, α = 0.5, β = 0.3, and γ = 0.2 can be set. The embodiments of the present application do not make limitations on this. U max can be set according to actual needs as a constraint on the traffic load. The value of T can be set by itself. For example, it can be set to 0.5. The embodiments of the present application do not make limitations on this. N min The value of can be set according to the number of nodes in the target network. For example, Figure 2 in the application scenario where, there are 8 nodes in the target network, N min can be set to 3. The embodiments of the present application do not make limitations on this.

[0158] The physical meaning of the objective function is: preferentially select nodes with high health, reduce the negative impact of latency on the consensus process, and at the same time select stages with sufficient bandwidth to ensure communication efficiency and throughput. The constraint requires that the number of nodes participating in the consensus shall not be lower than the lower limit value N min , to ensure the security and fault tolerance of the blockchain network. The health H i is a comprehensive evaluation of the stability and historical performance of the node. Excluding nodes with a health lower than the health threshold H T can prevent nodes with poor performance or under DDoS attacks from being selected as target consensus nodes. The consensus process requires nodes to synchronize block and transaction data. Insufficient bandwidth will lead to communication delays or data loss, seriously affecting the consensus performance. Therefore, excluding nodes with a bandwidth usage higher than the bandwidth threshold B TLarge nodes can avoid bandwidth from becoming a communication bottleneck for nodes. At the same time, in order to prevent the situation of too many selected consensus nodes, it is also necessary to prevent nodes with too high load from being selected to avoid causing a decline in system performance.

[0159] S24. According to the health of each node, the network latency of each node, and the bandwidth usage of each node, use a preset optimization algorithm to solve the optimal solution of the objective function, and obtain the probability of each node being selected as a consensus node.

[0160] Specifically, the preset optimization algorithm can but is not limited to using the gradient descent method, and other algorithms that can solve the optimal solution of the objective function can also be used, such as the conjugate gradient method, the subgradient method, the stochastic approximation method, etc. The embodiments of the present application do not limit this. Only the gradient descent method is used as an example in the present application for illustration.

[0161] Specifically, the optimal solution of the objective function is gradually iteratively solved through the following gradient descent method:

[0162]

[0163] Perform the following gradient calculation:

[0164]

[0165] where k represents the iteration round, and η is the iteration step size;

[0166] represents the probability that the i-th node is selected as a consensus node in the (k + 1)-th iteration round;

[0167] p i (k) represents the probability that the i-th node is selected as a consensus node in the k-th iteration round;

[0168] represents the gradient value of the probability that the i-th node is selected as a consensus node in the k-th iteration round;

[0169] represents the probability matrix of N nodes in the blockchain being selected as consensus nodes.

[0170] The iteration round and the iteration step size (i.e., the iteration interval) can be set by oneself. For example, the iteration round can be set to 100 times, and the iteration step size can be set to 0.01 or 0.001. The embodiments of the present application do not limit this. When the gradient norm (i.e., the change amount between two iterations) is less than the set threshold, the iteration ends, and the p i value of each node is obtained, where the set threshold can be set to 0.01 or 0.02, and can also be set to other values. The embodiments of the present application do not limit this.

[0171] S25. Determine the target consensus nodes for the nodes whose probability of being selected as consensus nodes is greater than or equal to a preset probability threshold, and update the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period, so as to defend against distributed denial-of-service attacks through the target consensus nodes.

[0172] In specific implementation, the preset probability threshold can be set to be the same as the first probability threshold T, or can be set to be different from the first probability threshold T. The embodiments of the present application do not limit this. The monitoring device determines the nodes whose probability of being selected as consensus nodes is greater than or equal to the preset probability threshold as the target consensus nodes, and obtains a set of target consensus nodes.

[0173] In another implementation manner, it is also possible to select the first few nodes with the largest probabilities in descending order of the probabilities of being selected as consensus nodes as the target consensus nodes. The embodiments of the present application do not limit this.

[0174] Furthermore, in the next time period, the consensus nodes in the blockchain are automatically updated to the target consensus nodes in the set of target consensus nodes through a smart contract. The target consensus nodes organize the nodes in the target network to jointly defend against DDoS attacks according to the smart contract. Thus, the optimized consensus nodes can be quickly applied to the consensus process, and the response speed and transparency of the protection strategy can be enhanced.

[0175] In order to improve the defense effect, it is also possible to evaluate the performance difference between the newly adjusted set of target consensus nodes and the defense in the previous time period for feedback adjustment after the defense is completed. After the defense ends, according to the collected update information, perform an offline simulation test on the set of target consensus nodes in the previous and current cycles before and after the update, use the attack characteristics and traffic patterns of the most recent time to backtest its effect, and feedback-adjust the future defense mechanism based on the test results. Combining the defense effect feedback and attack pattern learning, dynamically optimize the detection parameters and node selection strategy to form a closed-loop optimization mechanism, and continuously improve the adaptability of the system to diverse attacks.

[0176] The following takes Figure 2 the application scenario of

[0177]

[0178] Assume that the maximum bandwidth value of each node is 120, the maximum load is 100, k1 = 0.4, k2 = 0.3, k3 = 0.2, k4 = 0.1. According to the healthiness calculation formula, the healthiness of nodes 1 to 8 is calculated as follows: H1 = 0.88, H2 = 0.752, H3 = 0.97, H4 = 0.635, H5 = 0.815, H6 = 0.692, H7 = 0.91, H8 = 0.543. Set α = 0.5, β = 0.3, γ = 0.2, and the objective function is:

[0179]

[0180] Set the constraint conditions. Set the first probability threshold T = 0.5, the minimum number N min = 3 of the selected consensus nodes, the healthiness threshold H T = 0.6, the bandwidth threshold B T = 80, the maximum traffic load U max = 300, and set the preset probability threshold to 0.8.

[0181] Using the gradient descent method for iterative solution, the probabilities of nodes 1 to 8 being selected as consensus nodes are: p1 = 0.82, p2 = 0.60, p3 = 0.91, p4 = 0.73, p5 = 0.68, p6 = 0.50, p7 = 0.88, p8 = 0.42. Among them, the nodes with the probability of being selected as consensus nodes greater than or equal to the preset probability threshold of 0.85 are: node 1, node 3, and node 7. Then select node 1, node 3, and node 7 as the target consensus nodes to obtain the target consensus node set. If the preset probability threshold is set to 0.7, then node 1, node 3, node 4, and node 7 can be selected as the target consensus nodes. In the next time period, update the consensus nodes in the blockchain to the target consensus nodes in the target consensus node set, and defend against DDoS attacks according to the target consensus nodes in the target consensus node set.

[0182] In the distributed denial of service attack defense method provided by the embodiment of the present application, a monitoring device obtains the network performance indicators of each node in the blockchain in the current time period, and the network performance indicators include at least traffic load, network delay and bandwidth usage; the corresponding health of each node is determined according to the network performance indicators of each node, and the health represents the health of the node; an objective function of the probability of a node being selected as a consensus node is constructed according to the health of the node, the network delay and the bandwidth usage, and the objective function is a convex optimization model for maximizing the health of the selected consensus node and minimizing network delay and resource consumption; according to the health of each node, the network delay of each node and the bandwidth usage of each node, a preset optimization algorithm is used to solve the optimal solution of the objective function to obtain the probability of each node being selected as a consensus node; the node whose probability of being selected as a consensus node is greater than or equal to the preset probability threshold is determined as a target consensus node, and the consensus node in the blockchain is updated to the target consensus node through a smart contract in the next time period, so as to defend against distributed denial of service attacks through the target consensus node. In an embodiment of the present application, the nodes in the target network are first constructed as a blockchain. During the operation of the blockchain, consensus nodes distributed in various places are required to vote and make decisions. In order to ensure the legitimacy and security of the consensus nodes selected to participate in the vote when a distributed denial of service attack occurs, the present application models the selection of consensus nodes as a convex optimization problem to maximize the overall health of the selected consensus nodes and minimize network latency and resource consumption. Based on the constructed convex optimization model, the optimal set of consensus nodes is selected in real time according to the network performance indicators of each node in the current time period as the target consensus node for the next time period. In this way, defense against distributed denial of service attacks is achieved based on the updated target consensus nodes, and attack nodes are avoided as consensus nodes to maximize network performance, thereby minimizing the impact of distributed denial of service attacks on the target network, significantly improving the consensus efficiency and the anti-attack capability of the target network, and improving the defense effect.

[0183] Based on the same inventive concept, an embodiment of the present application also provides a distributed denial of service attack defense device. Since the principle of solving the problem by the above-mentioned distributed denial of service attack defense device is similar to the above-mentioned distributed denial of service attack defense method, the implementation of the above-mentioned device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0184] like Figure 5 As shown, it is a schematic diagram of the structure of a distributed denial of service attack defense device provided in an embodiment of the present application. The distributed denial of service attack defense device is applied to a network monitoring system. The network monitoring system includes a monitoring device and a blockchain constructed by nodes of a target network. The device may include:

[0185] An acquisition module 41, configured to acquire network performance metrics of each node in the blockchain during the current time period, where the network performance metrics at least include traffic load, network latency, and bandwidth usage;

[0186] A first determination module 42, configured to determine the corresponding health degree for each node according to the network performance metrics of each node, where the health degree characterizes the health level of the node;

[0187] A construction module 43, configured to construct an objective function for the probability that a node is selected as a consensus node according to the health degree, network latency, and bandwidth usage of the node, where the objective function is a convex optimization model for maximizing the health degree of the selected consensus node and minimizing network latency and resource consumption;

[0188] A calculation module 44, configured to solve the optimal solution of the objective function according to the health degree of each node, the network latency of each node, and the bandwidth usage of each node by using a preset optimization algorithm, and obtain the probability that each node is selected as a consensus node;

[0189] A second determination module 45, configured to determine the target consensus nodes as the nodes whose probability of being selected as a consensus node is greater than or equal to a preset probability threshold, and update the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period, so as to defend against distributed denial-of-service attacks through the target consensus nodes.

[0190] In one implementation, the network performance metrics further include a connection stability score, where the connection stability score characterizes the stability degree of the network connection of the node;

[0191] The acquisition module 41 is further configured to, for each node, determine the connection stability score of the node in the following manner: count the number of network connection interruptions between the node and other nodes during the current time period; determine the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and a preset maximum number of interruptions.

[0192] In one implementation, the acquisition module 41 is specifically configured to calculate the connection stability score of the node through the following formula:

[0193]

[0194] where S i represents the connection stability score of the i-th node in the blockchain;

[0195] d i represents the number of network connection interruptions between the i-th node and other nodes;

[0196] Dmax represents the preset maximum number of interruptions.

[0197] In one implementation, the first determination module 42 is specifically configured to calculate the health of each node through the following formula:

[0198]

[0199] where H i represents the health of the i-th node in the blockchain;

[0200] L i represents the network latency of the i-th node, and k1 represents the first weight of the network latency of the i-th node;

[0201] B i represents the bandwidth usage of the i-th node, and B i,max represents the maximum bandwidth of the i-th node, represents the bandwidth utilization rate of the i-th node, represents the remaining bandwidth utilization rate of the i-th node, and k2 represents the weight of the remaining bandwidth utilization rate of the i-th node;

[0202] U i represents the traffic load of the i-th node, and U i,max represents the maximum traffic load of the i-th node, represents the traffic load utilization rate of the i-th node, represents the remaining traffic load utilization rate of the i-th node, and k3 represents the weight of the remaining traffic load utilization rate of the i-th node;

[0203] S i represents the connection stability score of the i-th node, and k4 represents the weight of the connection stability score of the i-th node.

[0204] In one implementation, the construction module 43 is specifically configured to construct the objective function as follows:

[0205]

[0206] And construct the constraint conditions as follows:

[0207]

[0208] where f(p i ) is the objective function;

[0209] N represents the number of nodes in the blockchain;

[0210] p iDenotes the probability that the \(i\)-th node is selected as a consensus node, \(p\) i \(\in[0,1]\), \(i = 1,2,\cdots,N\);

[0211] \(H\) i Denotes the health of the \(i\)-th node, and \(\alpha\) denotes the weight of the health of the \(i\)-th node;

[0212] \(L\) i Denotes the network latency of the \(i\)-th node, and \(\beta\) denotes the second weight of the network latency of the \(i\)-th node;

[0213] \(B\) i Denotes the bandwidth usage of the \(i\)-th node, \(B\) i,max Denotes the maximum bandwidth of the \(i\)-th node, \(B\) i,max \(-B\) i Denotes the remaining bandwidth usage of the \(i\)-th node, and \(\gamma\) denotes the weight of the remaining bandwidth usage of the \(i\)-th node;

[0214] \(\varepsilon(p\) i ) is a step function, and \(T\) denotes the first probability threshold;

[0215] \(N\) min Denotes the minimum number of consensus nodes selected;

[0216] \(H\) T Denotes the health threshold;

[0217] \(B\) T Denotes the bandwidth threshold;

[0218] \(U\) i Denotes the traffic load of the \(i\)-th node, \(U\) max Denotes the maximum traffic load.

[0219] In one implementation, the calculation module 44 is specifically configured to solve the optimal solution of the objective function by the following gradient descent method:

[0220]

[0221]

[0222] where \(k\) represents the iteration round, and \(\eta\) is the iteration step size;

[0223] Denotes the probability that the \(i\)-th node is selected as a consensus node when the iteration round is \(k + 1\); Denotes the probability that the \(i\)-th node is selected as a consensus node when the iteration round is \(k\);

[0224] The gradient value representing the probability that the $i$-th node is selected as a consensus node when the iteration round is $k$;

[0225] It represents the probability matrix that $N$ nodes in the blockchain are selected as consensus nodes.

[0226] Based on the same inventive concept, an embodiment of the present application further provides an electronic device 500. Referring to Figure 6 As shown, the electronic device 500 is used to implement the distributed denial-of-service attack defense method described in the above method embodiment. The electronic device 500 in this embodiment may include: a memory 501, a processor 502, and a computer program stored in the memory and executable on the processor, such as a distributed denial-of-service attack defense program. When the processor executes the computer program, the steps in the above various distributed denial-of-service attack defense method embodiments are implemented.

[0227] In the embodiment of the present application, the specific connection medium between the above memory 501 and the processor 502 is not limited. In the embodiment of the present application Figure 6 It is connected by a bus 503 between the memory 501 and the processor 502. The bus 503 is represented by a thick line in Figure 6 For the connection methods between other components, only a schematic illustration is made, and it is not to be construed as a limitation. The bus 503 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 6 In

[0228] It is only represented by a thick line, but it does not mean that there is only one bus or one type of bus. The memory 501 may be a volatile memory, such as a random-access memory (RAM); the memory 501 may also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), or the memory 501 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but not limited thereto. The memory 501 may be a combination of the above memories.

[0229] The processor 502 is used to implement the distributed denial-of-service attack defense method provided by the embodiment of the present application.

[0230] The embodiments of the present application also provide a computer-readable storage medium storing computer-executable instructions for the above-mentioned processor to execute, which include a program for the above-mentioned processor to execute.

[0231] In some possible implementation manners, various aspects of the distributed denial of service attack defense method provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on an electronic device, the program code is used to cause the electronic device to execute the steps in the distributed denial of service attack defense method according to various exemplary embodiments described above in this specification.

[0232] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a device, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0233] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (apparatuses), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of the flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0234] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device implements the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 or multiple blocks.

[0235] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable device provide for implementing in the processFigure 1 one or more processes and / or blocks Figure 1 steps of the functions specified in one or more blocks.

[0236] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the present application.

[0237] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A method for defending against distributed denial of service attacks, characterized in that Applied to a network monitoring system, the network monitoring system includes monitoring devices and a blockchain constructed by nodes of a target network. The method includes: The monitoring device obtains the network performance indicators of each node in the blockchain during the current time period. The network performance indicators at least include traffic load, network latency, and bandwidth usage; Determine the respective corresponding health degrees according to the network performance indicators of each node. The health degree characterizes the health level of the node; Construct an objective function for the probability that a node is selected as a consensus node based on the health degree, network latency, and bandwidth usage of the node. The objective function is a convex optimization model for maximizing the health degree of the selected consensus node and minimizing network latency and resource consumption; According to the health degree of each node, the network latency of each node, and the bandwidth usage of each node, use a preset optimization algorithm to solve the optimal solution of the objective function to obtain the probability that each node is selected as a consensus node; Determine the target consensus nodes for the nodes whose probability of being selected as consensus nodes is greater than or equal to a preset probability threshold, and update the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period to defend against distributed denial-of-service attacks through the target consensus nodes.

2. The method according to claim 1, characterized in that, The network performance indicator further includes a connection stability score, and the connection stability score characterizes the stability degree of the network connection of the node; and For each node, determine the connection stability score of the node in the following manner: Count the number of network connection interruptions between the node and other nodes during the current time period; Determine the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and a preset maximum number of interruptions.

3. The method according to claim 2, wherein Determine the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and a preset maximum number of interruptions, specifically including: Calculate the connection stability score of the node through the following formula: Among them, S i represents the connection stability score of the i-th node in the blockchain; d i represents the number of times of network connection interruption between the i-th node and other nodes; D max indicates the preset maximum number of interruptions.

4. The method according to claim 2, wherein Determine the respective corresponding health degrees according to the network performance indicators of each node, specifically including: Calculate the health degree of each node through the following formula: Among them, H i represents the health of the i-th node in the blockchain; L i represents the network latency of the i-th node, and k1 represents the first weight of the network latency of the i-th node; B i represents the bandwidth usage of the i-th node, B i,max represents the maximum bandwidth of the i-th node represents the bandwidth utilization rate of the i-th node represents the remaining bandwidth utilization rate of the i-th node, and k2 represents the weight of the remaining bandwidth utilization rate of the i-th node U i represents the traffic load of the i-th node, U i,max represents the maximum traffic load of the i-th node, represents the traffic load utilization rate of the i-th node, represents the remaining traffic load utilization rate of the i-th node, and k3 represents the weight of the remaining traffic load utilization rate of the i-th node; S i represents the connection stability score of the i-th node, and k4 represents the weight of the connection stability score of the i-th node.

5. The method according to any one of claims 2 to 4, characterized in that, Construct an objective function for the probability that a node is selected as a consensus node based on the health degree, network latency, and bandwidth usage of the node, specifically including: Construct the objective function as follows: And construct the constraint conditions as follows: H i ≥ H T B i ≤B T where f(p i ) is the objective function; N represents the number of nodes in the blockchain; p i represents the probability that the \(i\)-th node is selected as a consensus node, \(p\) i ∈[0, 1], \(i = 1, 2, \ldots, N\); H i represents the health of the i-th node, and α represents the weight of the health of the i-th node; L i represents the network latency of the i-th node, and β represents the second weight of the network latency of the i-th node; B i represents the bandwidth usage of the i-th node, B i,max represents the maximum bandwidth of the i-th node, B i,max -B i represents the remaining bandwidth usage of the i-th node, and γ represents the weight of the remaining bandwidth usage of the i-th node; ε(p i ) is a step function, and T represents the first probability threshold; N min represents the minimum number of selected consensus nodes; H T represents a health threshold; B T represents a bandwidth threshold; U i represents the traffic load of the i-th node, U max represents the maximum traffic load.

6. The method according to claim 5, wherein According to the health degree of each node, the network latency of each node, and the bandwidth usage of each node, use a preset optimization algorithm to solve the optimal solution of the objective function to obtain the probability that each node is selected as a consensus node, specifically including: Solve the optimal solution of the objective function through the following gradient descent method: Where k represents the number of iteration rounds, and η is the iteration step size; represents the probability that the \(i\)-th node is selected as a consensus node when the iteration round is \(k + 1\); represents the probability that the \(i\)-th node is selected as a consensus node when the iteration round is \(k\); The gradient value representing the probability that the $i$-th node is selected as a consensus node when the iteration round is $k$; A probability matrix indicating that N nodes in the blockchain are selected as consensus nodes.

7. A distributed denial of service attack defense device, characterized in that, Applied to a network monitoring system, the network monitoring system includes monitoring devices and a blockchain constructed by nodes of a target network. The device includes: An acquisition module for acquiring the network performance indicators of each node in the blockchain during the current time period. The network performance indicators at least include traffic load, network latency, and bandwidth usage; The first determination module is configured to determine the respective health levels corresponding to each node according to the network performance metrics of each node, where the health level represents the health degree of the node; The construction module is configured to construct an objective function for the probability that a node is selected as a consensus node according to the health level, network latency, and bandwidth usage of the node. The objective function is a convex optimization model for maximizing the health level of the selected consensus nodes and minimizing network latency and resource consumption; The calculation module is configured to solve the optimal solution of the objective function according to the health level of each node, the network latency of each node, and the bandwidth usage of each node by using a preset optimization algorithm, and obtain the probability that each node is selected as a consensus node; The second determination module is configured to determine the target consensus nodes as the nodes whose probability of being selected as a consensus node is greater than or equal to a preset probability threshold, and update the consensus nodes in the blockchain to the target consensus nodes through a smart contract in the next time period, so as to defend against distributed denial-of-service attacks through the target consensus nodes.

8. The device according to claim 7, characterized in that The network performance metrics further include a connection stability score, and the connection stability score represents the stability degree of the network connection of the node; The acquisition module is further configured to, for each node, determine the connection stability score of the node by the following method: counting the number of network connection interruptions between the node and other nodes in the current time period; Determine the connection stability score of the node according to the number of network connection interruptions between the node and other nodes and a preset maximum number of interruptions.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the distributed denial-of-service attack defense method according to any one of claims 1 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements the steps in the distributed denial-of-service attack defense method according to any one of claims 1 to 6.