DDoS attack resistant flow dynamic cleaning method, system and device and medium

By monitoring and analyzing traffic data in real time and adjusting cleaning strategies dynamically, the adaptability of traffic cleaning methods to time fluctuations in DDoS attacks is solved, and the security and resource efficiency of the network are balanced.

CN120342747AInactive Publication Date: 2025-07-18SHENZHEN SHENZHOU TAIYUE INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510649837.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-20
Publication Date
2025-07-18
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the prior art, the traffic cleaning method of DDoS attacks relies on a fixed threshold or feature library and cannot effectively deal with the dynamic fluctuations of traffic in the time dimension, resulting in a normal request by mistake or failure to respond to concealed attacks in a time manner, which poses a network security risk.

Method used

By monitoring the traffic packet information in real time, analyzing the traffic data of the past preset days, updating the whitelist, subdividing the time units, calculating the abnormal risk index, dynamically adjusting the cleaning strategy, and performing traffic cleaning for different levels of abnormal risks.

Benefits of technology

Effectively resist DDoS attacks, ensure the normal operation of the network, avoid interference to normal services, and improve network resource utilization efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342747A_ABST
    Figure CN120342747A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of flow cleaning, and discloses a DDoS attack resistant flow dynamic cleaning method, system and device and a medium, and the method comprises the steps: S1, collecting flow packet information data in real time; s2, analyzing the traffic packet information data, and updating white list information data; s3, obtaining comparison flow packet value distribution information data of each time analysis unit and source IP distribution information data of a comparison source IP; s4, obtaining the distribution information data of the current traffic packet value and the distribution information data of the current source IP; s5, obtaining the current abnormal risk level of the key node; s6, performing corresponding flow cleaning processing on the key nodes according to the abnormal risk levels; corresponding processing measures are taken for different levels of abnormal risks, various network attacks can be effectively resisted, normal operation of the network is guaranteed, unnecessary interference to normal network services caused by excessive processing is avoided, and the utilization efficiency of network resources is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of traffic cleaning, and specifically relates to a method, system, device and medium for dynamically cleaning traffic against DDoS attacks. Background Art

[0002] A DDoS attack, also known as a distributed denial of service attack, is an attack in which an attacker controls multiple computers or devices and simultaneously sends a large amount of invalid or malicious traffic to a target server, network or service, causing the target system resources to be exhausted and unable to process legitimate user requests, thus making the service unavailable; due to its low attack technical threshold, rich attack resources and significant attack effect, DDoS attack is a relatively common network attack method, and anti-DDoS attack is to take a series of technologies and measures to defend against, mitigate or prevent DDoS attacks to ensure the availability and stability of network services.

[0003] Among them, traffic cleaning is a key link in anti-DDoS attacks. In the prior art, the system usually relies on preset thresholds (such as the number of requests per second, packet size, etc.) or feature libraries (such as known attack pattern signatures) to identify and filter malicious traffic, so as to achieve traffic cleaning and ensure the normal operation of network services.

[0004] However, the above technologies still have relatively large defects. For example, the preset thresholds or feature libraries in the above technologies often have relatively fixed characteristics and do not fully consider the dynamic fluctuation of traffic in the time dimension; for example, during the peak business period, the natural growth of legitimate traffic may trigger the cleaning threshold, resulting in the mis-killing of normal requests; while during the low valley period, the attacker may use the lower traffic base to launch a more concealed attack, and the cleaning system fails to respond in time because the preset threshold is not reached, thus making the network face security risks. Summary of the Invention

[0005] The purpose of the present invention is to provide a method, system, device and medium for dynamically cleaning traffic against DDoS attacks to solve the above technical problems.

[0006] The purpose of the present invention can be achieved by the following technical solutions: A method for dynamically cleaning traffic against DDoS attacks includes the following steps: S1: Real-time collect traffic packet information data through a monitoring module set at a key node; S2: Analyze the traffic packet information data of the key node in the past preset number of days through an analysis module, and update the whitelist information data; S3: Divide a day into several time analysis units through a time division module; and analyze the traffic packet information data of each time analysis unit within the past preset number of days for key nodes through an analysis module to obtain the comparison traffic packet value distribution information data of each traffic packet for each time analysis unit and the source IP distribution information data of the comparison source IP. S4: Analyze the real-time traffic packet information data of key nodes through an analysis module to obtain the current traffic packet value distribution information data and the distribution information data of the current source IP. S5: Analyze the current traffic packet value distribution information data, the distribution information data of the current source IP, the comparison traffic packet value distribution information data of the time analysis unit corresponding to the current time, and the source IP distribution information data of the comparison source IP through an analysis module to obtain the current abnormal risk index of the key node, and determine the abnormal risk level according to the abnormal risk index. S6: Perform corresponding traffic cleaning processing on the key node through a traffic cleaning module according to the current abnormal risk level of the key node.

[0007] As a further solution of the present invention: The traffic packet information data includes the source IP, the traffic packet value, and the source IP feedback status type; the source IP feedback status type includes the normal status and the abnormal status; the whitelist information data includes multiple legal IPs and the IP status types of each legal IP; the traffic packet value distribution information data includes multiple traffic packet value types and the ratio of each traffic packet value type to all traffic packet value types; the source IP distribution information data includes the source IP type and the ratio of each source IP type to all source IP types; the IP status type includes the high-quality status, the medium-quality status, and the low-quality status.

[0008] As a further solution of the present invention: The update process of the whitelist information data includes the following steps: S10: Compare the source IP of the traffic packet information data within the past preset number of days with the legal IPs in the whitelist information data updated last time to screen out the IPs to be analyzed. S20: Evenly divide the past preset number of days into several second time units, and analyze the traffic packet information data of each IP to be analyzed within each second time unit to obtain the legal judgment index of each IP to be analyzed. S30: Judge whether each IP to be analyzed is a legal IP according to the legal judgment index of each IP to be analyzed, and update the legal IPs in the whitelist information data. S40: Obtain the quality index of each legal IP according to the traffic packet information data of the legal IPs in the updated whitelist information data within the past preset number of days; and update the IP status type of each legal IP according to the quality index.

[0009] As a further solution of the present invention: In step S20, through the formula: ; Calculate the legal judgment index of any IP to be analyzed ; Wherein, Is the first judgment function. When , ; When , ; Is any IP to be analyzed; Is the number of source IP feedback status types that are in the normal state among the traffic packets sent by the IP to be analyzed in the past preset number of days; Is the number of traffic packets sent by the IP to be analyzed in the past preset number of days; Is the number of the second time unit; Is the number Of the weight coefficient of the second time unit; Is the number of source IP feedback status types that are in the normal state among the traffic packets sent by the IP to be analyzed in the second time unit numbered ; Is the number of traffic packets sent by the IP to be analyzed in the second time unit numbered ; Is the first weight coefficient; Is the second weight coefficient; Is the first preset comparison index; When , the IP to be analyzed is not a legal IP; When , the IP to be analyzed is a legal IP.

[0010] As a further solution of the present invention: In step S5, through the formula: ; Calculate the current abnormal risk index of the key node ; Wherein, Is the second judgment function. When , ; When , ; Is the traffic anomaly index; Is the source IP anomaly index; Is the traffic anomaly weight coefficient; Is the source IP anomaly weight coefficient; Is the number of traffic packet value types, ; Is the The influence weight coefficient of the traffic package value type; is the preset number of days in the past, ; is the th day in the preset number of days in the past, and in the time analysis unit corresponding to the current time, the ratio of the th traffic package value type to all traffic package value types; is the ratio of the current th traffic package value type to all traffic package value types; is the error adjustment coefficient of the th traffic package value type; is the preset traffic allowable error value; is the number of source IP types, ; is the influence weight coefficient of the th source IP type; is the th day in the preset number of days in the past, and in the time analysis unit corresponding to the current time, the ratio of the th source IP type to all source IP types; is the ratio of the current th source IP type to all source IP types; is the error adjustment coefficient of the th source IP type; is the preset source IP allowable error value; is the first preset constant; is the second preset constant.

[0011] As a further solution of the present invention: In step S5, the process of determining the abnormal risk level is: Compare the current abnormal risk index of the key node with the preset threshold ; When , the current abnormal risk level of this key node is risk-free; When , the current abnormal risk level of this key node is low risk; When , the current abnormal risk level of this key node is medium risk; When , the current abnormal risk level of this key node is high risk.

[0012] As a further solution of the present invention: In step S40, through the formula: ; Calculate the quality index of any legal IP ; Wherein, is any legal IP; is the traffic packet quantity quality index of the legal IP; is the traffic packet value quality index of the legal IP; is the th day's sent traffic packet quantity of the legal IP in the past preset number of days; is the preset sent traffic packet quantity; is the th day's average traffic packet value of the sent traffic packets of the legal IP in the past preset number of days; is the preset traffic packet value; is the first preset constant; is the second preset constant; is the first quality weight coefficient; is the second quality weight coefficient; is the first quality weight coefficient; is the second quality weight coefficient; The determination process of the IP status type of the legal IP is as follows: Compare the quality index of the legal IP with the preset quality comparison value ; When , the IP status type of the legal IP is the high-quality status; When , the IP status type of the legal IP is the medium-quality status; When , the IP status type of the legal IP is the low-quality status.

[0013] A traffic dynamic cleaning system against DDoS attacks, the system includes: A monitoring module, set on key nodes, for real-time collecting traffic packet information data; A time division module, for dividing a day into several time analysis units; An analysis module is used to analyze the traffic packet information data of key nodes for the past preset number of days, update the whitelist information data; then analyze the traffic packet information data of each time analysis unit within the past preset number of days of key nodes to obtain the control traffic packet value distribution information data of each traffic packet and each time analysis unit and the source IP distribution information data of the control source IP; then analyze the real-time traffic packet information data of key nodes to obtain the current traffic packet value distribution information data and the distribution information data of the current source IP; finally, analyze the current traffic packet value distribution information data, the distribution information data of the current source IP, and the control traffic packet value distribution information data and the source IP distribution information data of the control source IP corresponding to the current time analysis unit to obtain the current abnormal risk index of the key node, and determine the abnormal risk level according to the abnormal risk index; A traffic cleaning module is used to perform corresponding traffic cleaning processing on the key node according to the current abnormal risk level of the key node.

[0014] A traffic dynamic cleaning device against DDoS attacks includes a memory, a processor, and a computer program stored on the memory and used to run on the processor. When the processor executes the computer program, it implements the traffic dynamic cleaning method against DDoS attacks as described in any one of claims 1-7.

[0015] A traffic dynamic cleaning medium against DDoS attacks stores a computer program thereon. When the program is executed by a processor, it implements the traffic dynamic cleaning method against DDoS attacks as described in any one of claims 1-7.

[0016] Advantages of the present invention: (1) Through the analysis module of the present invention, the current traffic packet value distribution information data, the distribution information data of the current source IP, and the control traffic packet value distribution information data and the source IP distribution information data of the control source IP corresponding to the current time analysis unit are analyzed to obtain the current abnormal risk level of the key node; finally, through the traffic cleaning module, according to the current abnormal risk index of the key node and determining the abnormal risk level according to the abnormal risk index, corresponding traffic cleaning processing is performed on the key node, realizing corresponding processing measures for different levels of abnormal risks, which can not only effectively resist various network attacks, ensure the normal operation of the network, but also avoid unnecessary interference to normal network services caused by overprocessing, and improve the utilization efficiency of network resources. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The present invention will be further described below with reference to the accompanying drawings.

[0018] Figure 1 It is a method flow chart of an embodiment of the present invention; Figure 2System module framework diagram of an embodiment of the present invention. Detailed implementation manners

[0019] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0020] Embodiment 1 Please refer to Figure 1 As shown, in one embodiment, a traffic dynamic cleaning method against DDoS attacks is provided, including the following steps: S1: Real-time collect traffic packet information data through a monitoring module set at a key node; S2: Analyze the traffic packet information data of the key node in the past preset number of days through an analysis module, and update the whitelist information data; S3: Divide a day into several time analysis units through a time division module; and analyze the traffic packet information data of each time analysis unit of the key node in the past preset number of days through an analysis module to obtain the distribution information data of the comparison traffic packet values of each traffic packet for each time analysis unit and the source IP distribution information data of the comparison source IP; S4: Analyze the real-time traffic packet information data of the key node through an analysis module to obtain the current traffic packet value distribution information data and the distribution information data of the current source IP; S5: Analyze the current traffic packet value distribution information data, the distribution information data of the current source IP, the comparison traffic packet value distribution information data of the time analysis unit corresponding to the current time, and the source IP distribution information data of the comparison source IP through an analysis module to obtain the current abnormal risk index of the key node, and determine the abnormal risk level according to the abnormal risk index; S6: Perform corresponding traffic cleaning processing on the key node through a traffic cleaning module according to the current abnormal risk level of the key node; Through the above technical solution, in this embodiment, the monitoring module set at the key node first collects the traffic packet information data in real time; then the analysis module analyzes the traffic packet information data of the key node in the past preset number of days to obtain the whitelist information data; then the time division module divides a day into several time analysis units; the analysis module analyzes the traffic packet information data of each time analysis unit within the past preset number of days of the key node to obtain the comparison traffic packet value distribution information data of each traffic packet in each time analysis unit and the source IP distribution information data of the comparison source IP; since there are differences in the usage frequency, service type, etc. of the network in different time periods, and the traffic characteristics are also different, through this fine-grained analysis in the time dimension, the normal mode of network traffic can be described more carefully, providing a more accurate comparison basis for subsequent real-time traffic analysis, and further improving the sensitivity and pertinence of anomaly detection; then the analysis module analyzes the real-time traffic packet information data of the key node to obtain the current traffic packet value distribution information data and the distribution information data of the current source IP; then the analysis module analyzes the current traffic packet value distribution information data, the distribution information data of the current source IP, and the comparison traffic packet value distribution information data and the source IP distribution information data of the comparison source IP corresponding to the current time of the time analysis unit to obtain the current anomaly risk level of the key node; finally, the traffic cleaning module performs corresponding traffic cleaning processing on the key node according to the current anomaly risk index of the key node and determines the anomaly risk level according to the anomaly risk index, realizing corresponding treatment measures for different levels of anomaly risks, which can not only effectively resist various network attacks, ensure the normal operation of the network, but also avoid unnecessary interference to normal network services caused by over-treatment, and improve the utilization efficiency of network resources.

[0021] As an implementation manner of the present invention, the traffic packet information data includes a source IP, a traffic packet value, and a source IP feedback status type; the source IP feedback status type includes a normal status and an abnormal status; the whitelist information data includes a plurality of legal IPs and the IP status type of each legal IP; the traffic packet value distribution information data includes a plurality of traffic packet value types and the ratio of each traffic packet value type to all traffic packet value types; the source IP distribution information data includes a source IP type and the ratio of each source IP type to all source IP types; the IP status type includes a high-quality status, a medium-quality status, and a low-quality status.

[0022] It should be noted that the traffic packet value types can be classified according to the traffic packet size into small traffic packets, medium traffic packets, and large traffic packets; the source IP types can be divided into a first source IP (referring to the source IP of the first access), a second source IP (referring to a non-legal IP that has been accessed multiple times), and a legal IP; As an implementation manner of the present invention, the update process of the whitelist information data includes the following steps: S10: Compare the source IP of the traffic package information data within the preset number of days in the past with the legal IPs in the whitelist information data updated last time, and filter out the IPs to be analyzed; S20: Evenly divide the preset number of days in the past into several second time units, and analyze the traffic package information data of each IP to be analyzed within each second time unit to obtain the legal judgment index of each IP to be analyzed; S30: Judge whether each IP to be analyzed is a legal IP according to the legal judgment index of each IP to be analyzed, and update the legal IPs in the whitelist information data; S40: Obtain the quality index of each legal IP according to the traffic package information data of the legal IPs in the updated whitelist information data within the preset number of days in the past; and update the IP status type of each legal IP according to the quality index; Through the above technical solution, in this embodiment, first, by comparing the source IP of the traffic package information data within the preset number of days in the past with the legal IPs in the whitelist information data updated last time, the IPs to be analyzed are filtered out, which can accurately locate those IP addresses that may have changed or newly appeared; it effectively avoids the blind analysis of all IPs, greatly reduces the data processing volume, improves the analysis efficiency, and at the same time reduces the risk of misjudging and wrongly excluding normal IPs; then the preset number of days in the past is evenly divided into several second time units, and the traffic package information data of each IP to be analyzed within each second time unit (such as the source IP feedback status type, traffic package value, and service type, etc.) is analyzed to obtain the legal judgment index of each IP to be analyzed; through the legal judgment index, the legality of the IP to be analyzed can be more intuitively reflected, effectively improving the accuracy and reliability of the legal IP judgment and reducing the misjudgment rate; then judge whether each IP to be analyzed is a legal IP according to the legal judgment index of each IP to be analyzed, and update the legal IPs in the whitelist information data; realizing the dynamic update of the whitelist; finally, obtain the quality index of each legal IP according to the traffic package information data of the legal IPs in the updated whitelist information data within the preset number of days in the past, and update the IP status type of each legal IP according to the quality index; further refining the management of the whitelist. For legal IPs with a higher quality index, the strictness of traffic analysis can be appropriately relaxed to reduce unnecessary processing overhead; while for legal IPs with a lower quality index, monitoring and analysis can be strengthened to ensure the legality of their behaviors.

[0023] As an implementation manner of the present invention, in step S20, through the formula: ; Calculate the legal judgment index of any IP to be analyzed ; Wherein, is the first judgment function, when When ; when When ; is any IP to be analyzed; is the number of source IP feedback status types of normal status among the traffic packets sent by the IP to be analyzed in the past preset number of days; is the number of traffic packets sent by the IP to be analyzed in the past preset number of days; is the number of the second time unit; is the number of the weight coefficient of the second time unit; is the number of source IP feedback status types of normal status among the traffic packets sent by the IP to be analyzed in the second time unit numbered ; is the number of traffic packets sent by the IP to be analyzed in the second time unit numbered ; is the first weight coefficient; is the second weight coefficient; is the first preset comparison index; When the IP to be analyzed is not a legal IP; When the IP to be analyzed is a legal IP; Through the above technical solution, in this embodiment is the ratio of the number of source IP feedback status types of normal status among the traffic packets sent by the IP to be analyzed in the past preset number of days to the number of traffic packets sent by the IP to be analyzed in the past preset number of days; the larger the ratio of the source IP feedback status types of normal status among the traffic packets sent by the IP to be analyzed in the past preset number of days, the greater the legal probability index of the IP to be analyzed; conversely, the smaller the ratio of the source IP feedback status types of normal status among the traffic packets sent by the IP to be analyzed in the past preset number of days, the smaller the legal probability index of the IP to be analyzed; by numbering each second time unit in chronological order, the number of the second time unit farthest from the current time is 1; the number of the second time unit closest to the current time is J; the number ; the number of the weight coefficient of the second time unit satisfies and ; is the ratio of the number of source IP feedback status types of normal status among the traffic packets sent in the second time unit numbered to the number of traffic packets sent by the IP to be analyzed in the second time unit numbered ; in the number The ratio of the number of source IP feedback status types of traffic packets sent within the second time unit of to the number of traffic packets sent by the IP to be analyzed within the second time unit of is larger through the weight coefficient of the second time unit of to adjust the influence degree of each second time unit on the legal judgment index; The larger it is, the larger the legal probability index of the IP to be analyzed; conversely, the smaller it is, the smaller the legal probability index of the IP to be analyzed; is the legal probability index of the IP to be analyzed; in the formula , the first judgment function in refers to , which is used to judge whether the legal probability index of the IP to be analyzed is greater than the first preset comparison index; when , it indicates that the legal probability index of the IP to be analyzed is greater than the first preset comparison index, , and the IP to be analyzed is a legal IP; when , it indicates that the legal probability index of the IP to be analyzed is less than the first preset comparison index, , and the IP to be analyzed is not a legal IP; It should be noted that for the weight coefficient of the second time unit of , the first weight coefficient , the second weight coefficient , and the first preset comparison index are preset values obtained based on experience and will not be elaborated here.

[0024] As an implementation manner of the present invention, in step S5, through the formula: ; calculate the current abnormal risk index of the key node; wherein, is the second judgment function, when , ; when , ; is the traffic anomaly index; is the source IP anomaly index; is the traffic anomaly weight coefficient; is the source IP anomaly weight coefficient; is the number of traffic packet value types, ; is the The influence weight coefficient of the traffic package value type; is the preset number of days in the past, ; is the th day in the preset number of days in the past, and the ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time; is the ratio of the th traffic package value type to all traffic package value types at present; is the error adjustment coefficient of the th traffic package value type; is the preset traffic allowable error value; is the number of source IP types, ; is the th influence weight coefficient of the source IP type; is the th day in the preset number of days in the past, and the ratio of the th source IP type to all source IP types in the time analysis unit corresponding to the current time; is the ratio of the th source IP type to all source IP types at present; is the th error adjustment coefficient of the source IP type; is the preset source IP allowable error value; is the first preset constant; is the second preset constant; Through the above technical solution, in this embodiment is the first average ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the preset number of days in the past; is the absolute value of the difference between the ratio of the th traffic package value type to all traffic package value types at present and the first average ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the preset number of days in the past; is the th preset traffic allowable error value of the traffic package value type; is the standard deviation of the ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the preset number of days in the past; the standard deviation of the ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the preset number of days in the past The larger it is, the Error adjustment coefficient of a traffic package value type The larger the preset traffic allowable error value of the th traffic package value type; is the absolute value of the difference between the ratio of the current th traffic package value type to all traffic package value types and the first average ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the past preset number of days, and the preset traffic allowable error value of the th traffic package value type; in the formula the second judgment function in refers to , and is used to judge whether the absolute value of the difference between the ratio of the current th traffic package value type to all traffic package value types and the first average ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the past preset number of days exceeds the preset traffic allowable error value of the th traffic package value type; when , it means that the absolute value of the difference between the ratio of the current th traffic package value type to all traffic package value types and the first average ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the past preset number of days does not exceed the preset traffic allowable error value of the th traffic package value type; therefore, the current th traffic package value type has a very low risk of abnormality, ; when , it means that the absolute value of the difference between the ratio of the current th traffic package value type to all traffic package value types and the first average ratio of the th traffic package value type to all traffic package value types in the time analysis unit corresponding to the current time within the past preset number of days exceeds the preset traffic allowable error value of the th traffic package value type; therefore, the current th traffic package value type may have a relatively high risk of abnormality, and the larger the th traffic package value type, the greater the risk of abnormality; ; therefore, the abnormality risks of all traffic package value types are calculated through ; the greater the abnormality risks of all traffic package value types, the larger the traffic abnormality index , and the larger the current abnormality risk index of the key node; similarly, is the second average ratio of the type of source IP in the time analysis unit corresponding to the current time within the preset number of past days to all types of source IP; is the ratio of the current type of source IP to all types of source IP minus the absolute value of the difference between the second average ratio of the type of source IP in the time analysis unit corresponding to the current time within the preset number of past days to all types of source IP; is the preset source IP allowable error value of the type of source IP; is the standard deviation of the type of source IP in the time analysis unit corresponding to the current time within the preset number of past days to all types of source IP; the standard deviation of the type of source IP in the time analysis unit corresponding to the current time within the preset number of past days to all types of source IP The larger the error adjustment coefficient of the type of source IP, the larger the preset source IP allowable error value of the type of source IP; is the difference between the absolute value of the difference between the ratio of the current type of source IP to all types of source IP and the second average ratio of the type of source IP in the time analysis unit corresponding to the current time within the preset number of past days to all types of source IP and the preset source IP allowable error value of the type of source IP; in the formula , the second judgment function in refers to , and is used to judge whether the absolute value of the difference between the ratio of the current type of source IP to all types of source IP and the second average ratio of the type of source IP in the time analysis unit corresponding to the current time within the preset number of past days to all types of source IP exceeds the preset source IP allowable error value of the type of source IP; when , it indicates that the absolute value of the difference between the ratio of the current type of source IP to all types of source IP and the second average ratio of the type of source IP in the time analysis unit corresponding to the current time within the preset number of past days to all types of source IP does not exceed the preset source IP allowable error value of the type of source IP; therefore, the current type of source IP has a very low risk of abnormality, ; When occurs, it indicates that the absolute value of the difference between the ratio of the current th source IP type to all source IP types and the second average ratio of the th source IP type to all source IP types in the time analysis unit corresponding to the current time within the past preset number of days exceeds the preset source IP allowable error value of the th source IP type; Therefore, the current th source IP type may have a relatively high risk of abnormality, and the larger it is, the greater the risk of abnormality of the current th source IP type; ; Therefore, the abnormality risks of all source IP types are obtained through calculation; the greater the abnormality risks of all source IP types, the larger the source IP abnormality index , and the larger the current abnormality risk index of the key node; It should be noted that the traffic abnormality weight coefficient , the source IP abnormality weight coefficient , the influence weight coefficients of each traffic packet value type; the preset traffic allowable error value , the influence weight coefficients of each source IP type, the preset source IP allowable error value , the first preset constant and the second preset constant are preset values, obtained based on experience and not elaborated here.

[0025] As an implementation manner of the present invention, in step S5, the process of determining the abnormality risk level is as follows: Compare the current abnormality risk index of the key node with the preset threshold ; When occurs, the current abnormality risk level of this key node is risk-free; When occurs, the current abnormality risk level of this key node is low risk; When occurs, the current abnormality risk level of this key node is medium risk; When occurs, the current abnormality risk level of this key node is high risk; Through the above technical solution, in this embodiment, the current abnormality risk index of the key node is compared with the preset threshold ; When When the abnormal risk level of the critical node is risk-free at this time, the cleaning traffic module allows all source IPs to initiate access requests; when When the abnormal risk level of the critical node is low risk at this time, the cleaning traffic module will reject the access requests of source IPs that access for the first time and only allow source IPs with established access records to continue accessing; when When the abnormal risk level of the critical node is medium risk at this time, in this case, the cleaning traffic module only allows legal IPs to access to ensure the compliance and security of network access; when When the abnormal risk level of the critical node is high risk at this time, the cleaning traffic module only allows source IPs in a high-quality state to access, thereby minimizing the risk of network attacks and ensuring the stable operation of the critical node; It should be noted that the preset threshold is a preset value obtained based on experience and will not be elaborated here.

[0026] As an implementation manner of the present invention, in step S40, through the formula: ; Calculate the quality index ; where is any legal IP; is the quality index of the number of traffic packets of this legal IP; is the quality index of the traffic packet value of this legal IP; is the number of traffic packets sent on the th day in the past preset days of this legal IP; is the preset number of sent traffic packets; is the average traffic packet value of the traffic packets sent on the th day in the past preset days of this legal IP; is the preset traffic packet value; is the first preset constant; is the second preset constant; is the first quality weight coefficient; is the second quality weight coefficient; is the first quality weight coefficient; is the second quality weight coefficient; The process of determining the IP status type of this legal IP is as follows: Compare the quality index of this legal IP with the preset quality comparison value ; When , the IP status type of this legal IP is in a high-quality state; When the IP status type of the legal IP is the medium-quality status; When the IP status type of the legal IP is the low-quality status; Through the above technical solution, in this embodiment is the standard deviation of the number of traffic packets sent per day by the legal IP in the past preset number of days; the smaller the standard deviation of the number of traffic packets sent per day by the legal IP in the past preset number of days, the more stable the number of traffic packets sent by the legal IP per day in the past preset number of days, and the traffic packet quantity quality index is smaller, and the quality index of the legal IP is smaller, so the higher the quality of the legal IP; is the average number of traffic packets sent per day by the legal IP in the past preset number of days; is the absolute value of the difference between the average number of traffic packets sent per day by the legal IP in the past preset number of days and the preset number of traffic packets to be sent. The absolute value of the difference between the average number of traffic packets sent per day by the legal IP in the past preset number of days and the preset number of traffic packets to be sent is smaller, indicating that the number of traffic packets sent by the legal IP per day in the past preset number of days is closer to the preset number of traffic packets to be sent, indicating that the interaction frequency is relatively safe, and the traffic packet quantity quality index is smaller, and the quality index of the legal IP is smaller; so the higher the quality of the legal IP; Similarly, is the standard deviation of the average traffic packet value sent per day by the legal IP in the past preset number of days; the smaller the standard deviation of the average traffic packet value sent per day by the legal IP in the past preset number of days, the more stable the average traffic packet value sent by the legal IP per day in the past preset number of days, and the traffic packet value quality index is smaller, and the quality index of the legal IP is smaller, so the higher the quality of the legal IP; is the average value of the average traffic packet value sent per day by the legal IP in the past preset number of days; is the absolute value of the difference between the average value of the average traffic packet value sent per day by the legal IP in the past preset number of days and the preset traffic packet value. The absolute value of the difference between the average value of the average traffic packet value sent per day by the legal IP in the past preset number of days and the preset traffic packet value is smaller, indicating that the average value of the average traffic packet value sent per day by the legal IP in the past preset number of days is closer to the preset traffic packet value, indicating that the transmitted data is more secure, and the traffic packet value quality index is smaller, and the quality index of the legal IP The smaller it is; therefore, the higher the quality of the legal IP; the quality index of the legal IP is compared with a preset quality comparison value ; when , the IP status type of the legal IP is a high-quality status; when , the IP status type of the legal IP is a medium-quality status; when , the IP status type of the legal IP is a low-quality status; It should be noted that the preset quality comparison value , the first quality weight coefficient , the second quality weight coefficient , the first quality weight coefficient , the second quality weight coefficient , the first preset constant and the second preset constant are preset values, obtained based on experience and not elaborated here.

[0027] Please refer to Figure 2 shown, a traffic dynamic cleaning system for resisting DDoS attacks, the system includes: A monitoring module, arranged on key nodes, for real-time collecting traffic packet information data; A time division module, for dividing a day into several time analysis units; An analysis module, for analyzing the traffic packet information data of key nodes in the past preset number of days, updating the whitelist information data; then analyzing the traffic packet information data of each time analysis unit within the past preset number of days of key nodes, obtaining the distribution information data of the comparison traffic packet values of each traffic packet and each time analysis unit and the source IP distribution information data of the comparison source IP; then analyzing the real-time traffic packet information data of key nodes, obtaining the current traffic packet value distribution information data and the distribution information data of the current source IP; finally analyzing the current traffic packet value distribution information data, the distribution information data of the current source IP, and the comparison traffic packet value distribution information data and the source IP distribution information data of the comparison source IP corresponding to the current time analysis unit, obtaining the current abnormal risk index of the key node, and determining the abnormal risk level according to the abnormal risk index; A cleaning traffic module, for performing corresponding traffic cleaning processing on key nodes according to the current abnormal risk level of key nodes.

[0028] Embodiment 2 A traffic dynamic cleaning device for resisting DDoS attacks, including a memory, a processor, and a computer program stored on the memory and for running on the processor, and when the processor executes the computer program, it implements the traffic dynamic cleaning method for resisting DDoS attacks as in Embodiment 1.

[0029] Embodiment 3 A traffic dynamic cleaning medium for anti-DDoS attacks, on which a computer program is stored, characterized in that when the program is executed by a processor, it implements the traffic dynamic cleaning method for anti-DDoS attacks as described in Embodiment 1.

[0030] The above has described in detail one embodiment of the present invention, but the content described is only a preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made according to the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.

Claims

1. A traffic dynamic cleaning method against DDoS attacks, characterized in that, It includes the following steps: S1: Real-time collect traffic packet information data through the monitoring module set at the key node; S2: Analyze the traffic packet information data of the key node in the past preset number of days through the analysis module, and update the whitelist information data; S3: Divide a day into several time analysis units through the time division module; and analyze the traffic packet information data of each time analysis unit of the key node in the past preset number of days through the analysis module to obtain the comparison traffic packet value distribution information data of each traffic packet and each time analysis unit and the source IP distribution information data of the comparison source IP; S4: Analyze the real-time traffic packet information data of the key node through the analysis module to obtain the current traffic packet value distribution information data and the distribution information data of the current source IP; S5: Analyze the current traffic packet value distribution information data, the distribution information data of the current source IP, the comparison traffic packet value distribution information data of the time analysis unit corresponding to the current time, and the source IP distribution information data of the comparison source IP through the analysis module to obtain the current abnormal risk index of the key node, and determine the abnormal risk level according to the abnormal risk index; S6: Perform corresponding traffic cleaning processing on the key node through the traffic cleaning module according to the current abnormal risk level of the key node.

2. The traffic dynamic cleaning method for anti-DDoS attack according to claim 1, characterized in that, The traffic packet information data includes source IP, traffic packet value, and source IP feedback status type; the source IP feedback status type includes normal status and abnormal status; the whitelist information data includes multiple legal IPs and the IP status type of each legal IP; the traffic packet value distribution information data includes multiple traffic packet value types and the ratio of each traffic packet value type to all traffic packet value types; The source IP distribution information data includes source IP type and the ratio of each source IP type to all source IP types; the IP status type includes high-quality status, medium-quality status, and low-quality status.

3. The traffic dynamic cleaning method for anti-DDoS attack according to claim 2, characterized in that, The update process of the whitelist information data includes the following steps: S10: Compare the source IP of the traffic packet information data in the past preset number of days with the legal IPs in the whitelist information data updated last time to screen out the IPs to be analyzed; S20: Evenly divide the past preset number of days into several second time units, and analyze the traffic packet information data of each IP to be analyzed in each second time unit to obtain the legal judgment index of each IP to be analyzed; S30: Judge whether each IP to be analyzed is a legal IP according to the legal judgment index of each IP to be analyzed, and update the legal IPs in the whitelist information data; S40: Obtain the quality index of each legal IP according to the traffic packet information data of the legal IPs in the past preset number of days in the updated whitelist information data; and update the IP status type of each legal IP according to the quality index.

4. The traffic dynamic cleaning method for anti-DDoS attack according to claim 3, characterized in that In step S20, through the formula: ; Calculate the legal judgment index of any IP to be analyzed ; Among them, is the first judgment function. When , ; when , ; is any IP to be analyzed; is the number of source IP feedback status types that are in the normal state among the traffic packets sent by the IP to be analyzed in the past preset number of days; is the number of traffic packets sent by the IP to be analyzed in the past preset number of days; is the number of the second time unit; is the number of the weight coefficient of the second time unit; is the number of source IP feedback status types that are in the normal state among the traffic packets sent by the IP to be analyzed in the second time unit with the number ; is the number of traffic packets sent by the IP to be analyzed in the second time unit with the number ; is the first weight coefficient; is the second weight coefficient; is the first preset comparison index; When the IP to be analyzed is not a legal IP; When the IP to be analyzed is a legal IP.

5. The method for dynamically cleaning traffic against DDoS attacks according to claim 4, characterized in that In step S5, through the formula: ; Calculate the current abnormal risk index of the key node ; Among them, is the second judgment function. When , ; when , ; is the traffic anomaly index; is the source IP anomaly index; is the traffic anomaly weight coefficient; is the source IP anomaly weight coefficient; is the number of traffic packet value types, ; is the influence weight coefficient of the th traffic packet value type; is the preset number of past days, ; is the ratio of the th day of the preset past days in the current time corresponding time analysis unit to the th traffic packet value type among all traffic packet value types; is the ratio of the current th traffic packet value type to all traffic packet value types; is the error adjustment coefficient of the th traffic packet value type; is the preset traffic allowable error value; is the number of source IP types, ; is the influence weight coefficient of the th source IP type; is the ratio of the th day of the preset past days in the current time corresponding time analysis unit to the th source IP type among all source IP types; is the ratio of the current th source IP type to all source IP types; is the error adjustment coefficient of the th source IP type; is the preset source IP allowable error value; is the first preset constant; is the second preset constant.

6. The traffic dynamic cleaning method for anti-DDoS attack according to claim 5, characterized in that, In step S5, the process of determining the abnormal risk level is: Compare the current abnormal risk index of the key node with the preset threshold ; When the current abnormal risk level of this key node is risk-free; When the current abnormal risk level of this key node is a low risk; When the current abnormal risk level of this critical node is medium risk; When the current abnormal risk level of this key node is a high risk.

7. The traffic dynamic cleaning method for anti-DDoS attack according to claim 6, characterized in that In step S40, through the formula: ; Calculate the quality index of any legal IP address ; Among them, is any legal IP; is the traffic packet quantity quality index of this legal IP; is the traffic packet value quality index of this legal IP; is the number of traffic packets sent on the th day in the past preset number of days of this legal IP; is the preset number of traffic packets to be sent; is the average traffic packet value of the traffic packets sent on the th day in the past preset number of days of this legal IP; is the preset traffic packet value; is the first preset constant; is the second preset constant; is the first quality weight coefficient; is the second quality weight coefficient; is the first quality weight coefficient; is the second quality weight coefficient; The process of determining the IP status type of this legal IP is: Compare the quality index of the legal IP with a preset quality comparison value for comparison; When the IP status type of the legal IP is a high-quality status; When the IP status type of the legal IP is the medium quality status; When the IP status type of the legal IP is in a low-quality state.

8. A traffic dynamic cleaning system against DDoS attacks, applicable to the traffic dynamic cleaning method against DDoS attacks described in any one of claims 1-7, characterized in that, The system includes: A monitoring module, set at the key node, for real-time collecting traffic packet information data; A time division module for dividing a day into several time analysis units; An analysis module for analyzing the traffic packet information data of the past preset number of days of key nodes to update the whitelist information data; then analyzing the traffic packet information data of each time analysis unit within the past preset number of days of key nodes to obtain the comparison traffic packet value distribution information data of each traffic packet and each time analysis unit and the source IP distribution information data of the comparison source IP; then analyzing the real-time traffic packet information data of key nodes to obtain the current traffic packet value distribution information data and the distribution information data of the current source IP; finally, analyzing the current traffic packet value distribution information data, the distribution information data of the current source IP, and the comparison traffic packet value distribution information data and the source IP distribution information data of the comparison source IP corresponding to the current time of the time analysis unit to obtain the current abnormal risk index of the key node, and determining the abnormal risk level according to the abnormal risk index; A traffic cleaning module for performing corresponding traffic cleaning processing on the key node according to the current abnormal risk level of the key node.

9. A traffic dynamic cleaning device against DDoS attacks, comprising a memory, a processor, and a computer program stored in the memory and configured to run on the processor, characterized in that, When the processor executes the computer program, it implements the traffic dynamic cleaning method for resisting DDoS attacks according to any one of claims 1-7.

10. A traffic dynamic cleaning medium against DDoS attacks, on which a computer program is stored, characterized in that, When the program is executed by the processor, it implements the traffic dynamic cleaning method for resisting DDoS attacks according to any one of claims 1-7.