Flow filtering method and device based on CC attack characteristics

By performing feature extraction and Laplace feature mapping and dimensionality reduction on historical HTTP request traffic samples, combining deep punishment generation adversarial networks and multi-layer game models, dynamically adjusting defense strategies, solving the problems of staticity and high false alarm rates of existing CC attack defense measures, and achieving more efficient CC attack identification and resource utilization.

CN120358098AActive Publication Date: 2025-07-22SHAOGUAN COLLEGE

Patent Information

Application Number
CN202510847206.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-07-22
Estimated Expiration
2045-06-24

AI Technical Summary

Technical Problem

The existing CC attack defense measures are based on static rules, making it difficult to effectively identify complex and changeable CC attacks, resulting in high false positive rates and waste of resources, and the inability to dynamically adjust the defense strategy.

Method used

By performing feature extraction and Laplace feature mapping and dimensionality reduction on historical HTTP request traffic samples, CC attack feature parameters are constructed, and attack risk assessment is performed using deep punishment generation adversarial networks, and defense strategies are dynamically adjusted in combination with multi-layer game models to realize hierarchical filtering.

Benefits of technology

It improves the accuracy and flexibility of CC attack identification, optimizes resource utilization efficiency, and reduces the impact on normal users, especially in low-frequency CC attacks and hybrid Flash Crowd traffic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358098A_ABST
    Figure CN120358098A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of traffic filtering, and discloses a CC attack feature-based traffic filtering method and device. The method comprises the following steps: performing feature extraction and Laplacian feature mapping dimensionality reduction on a historical HTTP request traffic sample to obtain a dimensionality-reduced feature vector set; cC attack feature analysis is carried out based on the dimension reduction feature vector set, and a CC attack feature parameter set is obtained; performing attack risk assessment on the real-time HTTP request to be filtered based on the CC attack feature parameter set to obtain an attack possibility score; performing time-varying parameter defense analysis based on the attack possibility score to obtain an adaptive defense rule set; and performing hierarchical filtering processing on the real-time HTTP request to be filtered according to the self-adaptive defense rule set to obtain filtered security traffic. According to the method, the defense parameters can be dynamically adjusted according to the attack situation, compared with a static defense rule, the method is more flexible and adaptive, and the resource utilization efficiency can be optimized while safety is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of traffic filtering, and particularly to a traffic filtering method and device based on CC attack characteristics. Background Art

[0002] With the popularization of Internet applications and the rapid development of network services, the CC (Challenge Collapsar) attack, as a DDoS attack method with strong concealment and low bandwidth consumption, poses a serious threat to various network services. The CC attack simulates normal user behaviors and sends a large number of seemingly legitimate HTTP requests in a low-frequency and distributed manner, consuming server-side resources and causing normal users to be unable to access the target website or service. Existing defense measures mainly filter based on static rules or simple statistical features, such as request frequency limits, IP blacklists, access frequency threshold controls, etc. However, when facing complex and changeable attack behaviors, the detection accuracy of these methods is relatively low, and it is easy to misjudge normal user traffic. Especially when dealing with the FlashCrowd (sudden high traffic) scenario, the false alarm rate is high and it is difficult to distinguish malicious traffic from high-concurrency normal access.

[0003] With the upgrading of attackers' technologies, new CC attack variants emerge in an endless stream, such as low-frequency CC attacks, hybrid CC attacks, and distributed CC attacks. These attacks evade detection by adjusting the request frequency, changing request parameters, or mixing legitimate requests. Existing defense methods based on statistical features lack in-depth analysis of the correlation relationships between HTTP requests and cannot effectively capture the temporal correlation patterns and behavioral characteristics in attack traffic. Traditional defense systems usually adopt static defense rules and cannot adaptively adjust defense strategies according to changes in attack intensity, resulting in waste of resources due to over-defense or security risks due to insufficient defense. Summary of the Invention

[0004] The present invention provides a traffic filtering method and device based on CC attack characteristics. The present invention can dynamically adjust defense parameters according to the attack situation, is more flexible and adaptable than static defense rules, and can optimize resource utilization efficiency while ensuring security.

[0005] In a first aspect, the present invention provides a traffic filtering method based on CC attack characteristics. The traffic filtering method based on CC attack characteristics includes: Performing feature extraction and Laplacian feature mapping dimensionality reduction on historical HTTP request traffic samples to obtain a set of dimensionality-reduced feature vectors; Performing CC attack feature analysis based on the set of dimensionality-reduced feature vectors to obtain a set of CC attack feature parameters; Performing an attack risk assessment on real-time HTTP requests to be filtered based on the set of CC attack feature parameters to obtain an attack possibility score; Perform time-varying parameter defense analysis based on the attack possibility score to obtain an adaptive defense rule set; Perform hierarchical filtering on the real-time HTTP request to be filtered according to the adaptive defense rule set to obtain filtered secure traffic.

[0006] In a second aspect, the present invention provides a traffic filtering device based on CC attack characteristics. The traffic filtering device based on CC attack characteristics includes: A mapping and dimensionality reduction module, configured to perform feature extraction and Laplacian feature mapping dimensionality reduction on historical HTTP request traffic samples to obtain a set of dimensionality-reduced feature vectors; A feature analysis module, configured to perform CC attack feature analysis based on the set of dimensionality-reduced feature vectors to obtain a set of CC attack feature parameters; A risk assessment module, configured to perform attack risk assessment on the real-time HTTP request to be filtered based on the set of CC attack feature parameters to obtain an attack possibility score; A defense analysis module, configured to perform time-varying parameter defense analysis based on the attack possibility score to obtain an adaptive defense rule set; A hierarchical filtering module, configured to perform hierarchical filtering on the real-time HTTP request to be filtered according to the adaptive defense rule set to obtain filtered secure traffic.

[0007] In the technical solution provided by the present invention, through multi-dimensional extraction and fusion of temporal features, session behavior features, and content features from historical HTTP request traffic samples, the present invention constructs a comprehensive set of HTTP request feature vectors. Compared with traditional methods based on only single or a small number of statistical features, it can more comprehensively depict the feature patterns of HTTP requests. The present invention introduces Laplacian eigenmaps to perform dimensionality reduction on the set of HTTP request feature vectors, converting the original high-dimensional discrete features into a continuous feature space, effectively preserving the topological relationship and similarity structure among HTTP requests, not only reducing the computational complexity but also enhancing the expressive power of features, enabling the system to better capture the temporal correlation patterns in CC attacks. The present invention uses a deep penalty generative adversarial network for CC attack feature analysis. Through the adversarial learning of the generator and discriminator, it automatically learns the feature patterns of CC attacks and has stronger feature learning ability compared with traditional machine learning methods. At the same time, the introduced attention mechanism can automatically focus on the key features for distinguishing CC attacks, improving the interpretability and accuracy of the model. The denoising penalty constraint introduced by the present invention constrains the gradient norm of the discriminator near the real data, making the output of the model remain stable when the input changes slightly, significantly enhancing the adaptability of the model to HTTP request mutations and effectively dealing with the behavior of attackers to avoid detection by changing request parameters, adjusting request frequencies, etc. The multi-layer game model constructed by the present invention regards CC attack defense as a dynamic game process between attackers and defenders. By solving the optimal control equation, it obtains the optimal defense strategy, can dynamically adjust the defense parameters according to the attack situation, and is more flexible and adaptable than static defense rules, and can optimize the resource utilization efficiency while ensuring security. The hierarchical filtering processing mechanism implemented by the present invention processes requests at different levels according to the attack possibility score. Combining various defense means such as JavaScript challenge verification, CAPTCHA verification, and dynamic resource allocation, it can adopt differential defense strategies for requests with different risk levels, minimizing the impact on normal users while ensuring system security, especially having significant advantages in dealing with low-frequency CC attacks and mixed Flash Crowd traffic environments. Brief Description of the Drawings

[0008] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0009] Figure 1 It is a schematic diagram of an embodiment of the traffic filtering method based on CC attack features in the embodiments of the present invention; Figure 2This is a schematic diagram of an embodiment of the traffic filtering device based on CC attack characteristics in the embodiments of the present invention. Detailed implementation manners

[0010] The embodiments of the present invention provide a traffic filtering method and device based on CC attack characteristics. Terms such as "first", "second", "third", "fourth", etc. (if any) in the specification, claims and above-mentioned drawings of the present invention are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments described herein can be implemented in an order different from that illustrated or described herein. In addition, the term "comprising" or "having" and any variation thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment comprising a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.

[0011] For ease of understanding, the following describes the specific process of the embodiments of the present invention. Please refer to Figure 1 , an embodiment of the traffic filtering method based on CC attack characteristics in the embodiments of the present invention includes: Step S101, perform feature extraction and Laplacian eigenmap dimensionality reduction on historical HTTP request traffic samples to obtain a set of dimensionality-reduced feature vectors; It can be understood that the execution subject of the present invention can be a traffic filtering device based on CC attack characteristics, or a terminal or a server. Specifically, it is not limited here. The embodiments of the present invention are described by taking the server as the execution subject as an example.

[0012] Specifically, perform preliminary data cleaning and format unification on historical HTTP request traffic samples, and normalize missing values, outliers, and polysemous formats in the original request fields through predefined rules to construct a preprocessed HTTP request record set with a unified structure and consistent time series. Based on this standardized request record set, divide the request sequence into time windows according to the request timestamp, and extract time series behavior characteristics highly related to CC attacks within each time window, such as the fluctuation of request frequency per unit time, the mean and variance of request intervals, the position and distribution density of peak frequencies, etc., to form an HTTP request time series feature set describing the burstiness and periodicity of requests. To detect attack signs based on the user behavior chain, classify and aggregate all preprocessed request records according to their session identifiers to construct a logically continuous set of HTTP sessions, and extract session behavior characteristics that can measure their interaction behavior patterns in each session, including session duration, the number of requests within a single session, URL path repeatability, resource request type distribution entropy, and session stability, etc., to obtain a session behavior feature set that can reflect the stability and suspiciousness of user behavior. At the same time, to capture the content perturbation strategies adopted by attackers to construct malicious traffic, parse the field content of the preprocessed HTTP request records, and extract information such as the path depth and character entropy of the request URL, the complexity of the User-Agent field and Referer field, the number of hierarchical levels of the Cookie field structure, and the nesting level and mutation degree of request parameters, etc., to construct an HTTP content feature set for measuring content abnormality. The features in the above three dimensions, namely the HTTP request time series feature set, the session behavior feature set, and the HTTP content feature set, are vectorized, aligned in the dimension space, and then spliced and fused to form a unified structured set of HTTP request feature vectors, covering the potential manifestation patterns of CC attacks at the time, behavior, and content levels. Based on the set of HTTP request feature vectors, introduce a graph structure method to model the relationships between feature vectors. By constructing a similarity weight matrix and a node degree matrix between request samples, obtain the Laplacian matrix, and solve its eigenvalue equation to obtain low-dimensional embedding vectors, so that the original high-dimensional set of HTTP request feature vectors is projected into a continuous low-dimensional space with good geometric structure preservation, generating a set of dimensionality-reduced feature vectors.

[0013] In this embodiment, using the HTTP request feature vector set as the input, a graph relationship reflecting the association structure between samples is constructed by measuring the feature similarity between each pair of HTTP requests. The similarity is calculated by comparing the relative proximity of each request in multiple dimensions such as access frequency, time interval, request path, parameter complexity, session behavior, etc. The similarity relationships between all samples are aggregated into a weight matrix, which represents the connection strength between each pair of requests. According to this weight matrix, the total connection strength of each request node is calculated to form a degree diagonal matrix, thereby depicting the distribution density structure of HTTP requests in the overall feature space. Based on these two types of matrices, a Laplacian matrix representing the entire request graph structure is constructed. This matrix reflects the local adjacency relationship and global distribution trend between samples. Its construction process does not change the original data content of the requests but effectively retains the structural connections between them. Feature analysis processing is performed on the Laplacian matrix, that is, its structural attributes are decomposed to obtain a feature data set reflecting the internal change patterns of the request set. These data sets reflect the main change directions between samples. To compress the feature space dimension and improve the subsequent model processing efficiency, the most representative principal component part is selected from these feature data, that is, a set of feature dimensions that can retain the distribution relationship between data to the greatest extent is selected. These dimensions represent the directions that can best reflect the structural differences of attack behaviors. The initial HTTP request feature vector set is mapped into the new feature space formed by these representative dimensions, thereby completing the dimensionality reduction transformation of the features and obtaining a dimensionality reduction feature vector set. In the new feature space, each request data is expressed in a lower-dimensional form but still retains its key structural attributes and potential attack features, enabling the entire data set to have sufficient discrimination ability while reducing complexity.

[0014] Step S102: Perform CC attack feature analysis based on the dimensionality reduction feature vector set to obtain a CC attack feature parameter set; Specifically, the set of HTTP request feature vectors after dimensionality reduction is input into the input layer of the deep penalty generative adversarial network model for feature loading. By initializing the connection weights between the input nodes and the dimensionality reduction vectors, each low-dimensional feature vector is accurately mapped into an initial representation form that can be processed by the network, obtaining the initial network features reflecting the actual HTTP request structure. The initial network features are input into the generator module of the deep penalty generative adversarial network. This module adopts a multi-layer fully connected neural network structure and introduces non-linear activation functions such as the ReLU or tanh function, enabling the generator to perform high-dimensional feature mapping and non-linear transformation on the initial features, generating intermediate mapping features that capture the differential expression of real requests and forged requests at the feature level in the latent space. The intermediate mapping features are input into the discriminator module in the deep penalty generative adversarial network for feature classification learning. The discriminator is also a multi-layer fully connected structure, and its core function is to map the input features into probability responses of attack and non-attack. Through reinforcement learning of the distribution differences of sample features, a feature response map is output, which reflects the contribution degree of each input dimension to the classification decision result. To improve the model's ability to identify key features of CC attacks, an attention mechanism layer is embedded in the network structure. This layer calculates the global and local importance scores for each dimension of the feature response map by constructing an attention weight matrix, obtaining the final feature weight distribution, thereby highlighting the discriminant main features in the attack behavior. At the same time, to enhance the model's stability in the face of request mutation and feature perturbation, a denoising penalty mechanism based on the input gradient is introduced. This mechanism constrains the gradient norm of the discriminator output with respect to the input features, calculates the gradient regularization term and combines it with the feature weight distribution to generate a feature expression with enhanced robustness. Feature dimensions with weights significantly higher than the set threshold are selected from the robustness-enhanced features, and the corresponding boundary values are combined to form a set of CC attack feature parameters, which includes parameters such as the upper limit of the attack request frequency, the request path entropy threshold, the session duration range, and the User-Agent structure complexity limit.

[0015] In this embodiment, the structure of the discriminator in the deep penalty generative adversarial network is trained for scalability, so that it can not only effectively distinguish input features, but also quantify the response sensitivity of each feature dimension. During the training process, a gradient calculation operation is performed on each set of input features, that is, the degree of change in the discriminator output when a small perturbation occurs in the current input is calculated, thereby constructing a feature gradient matrix. Each column in this matrix represents the influence intensity of the change in one feature dimension on the output result. The norm of the feature gradient matrix is calculated to calculate the magnitude of the change corresponding to each feature dimension, which is used to reflect the dependence degree of the model on the input of each dimension. To improve the adaptability of the model to traffic variability, a traffic state analysis mechanism is introduced, that is, the quantization index of traffic variability is determined according to the fluctuation degree of traffic features in the current period. Based on this index, the constraint strength in the penalty mechanism is dynamically adjusted, so that the model can enhance the discriminative ability for key features when the attack features change significantly, and maintain a stable response when the normal traffic fluctuates slightly. After the above analysis, the calculated feature sensitivity information is fused with the existing feature weight distribution to form a comprehensive penalty term, which is added to the training objective, so that the model automatically suppresses the excessive dependence on unstable features during the optimization process, and at the same time enhances the robust learning of core features. After the optimization is completed, a set of features output by the model exhibit higher stability and discrimination, that is, features with enhanced robustness. Among these features, only a part repeatedly shows high weights and significant influences in multiple rounds of training and perturbation tests. Therefore, a weight threshold is set, and features exceeding this threshold are selected from all dimensions. For the selected high-weight features, the numerical range shown in the training set is further statistically analyzed, and the upper and lower limits with higher occurrence frequencies are extracted as the behavior boundaries of this dimension. A CC attack feature parameter set is formed, which includes specific feature indexes and corresponding weight sizes, as well as the upper and lower limits that repeatedly appear in historical attack data.

[0016] Step S103: Based on the CC attack feature parameter set, perform an attack risk assessment on the real-time HTTP request to be filtered, and obtain an attack possibility score; Specifically, perform structured feature extraction operations on each real-time HTTP request to be filtered, that is, extract dimension information such as request frequency, parameter complexity, path structure, number of header fields, and source IP distribution characteristics from the request to form a preliminary real-time HTTP request feature vector. Perform Laplace mapping processing on the real-time HTTP request feature vector and project it into the low-dimensional space used by the discriminant model to obtain a dimensionality-reduced real-time feature vector, enabling it to be aligned and compared with the set of learned attack feature parameters in the same feature scale and structure. To achieve an effective association between real-time features and the extracted CC attack feature parameters, construct a feature similarity evaluation model based on the aforementioned set of CC attack feature parameters. This model includes several core modules, including a key feature dimension recognizer, a feature boundary interval discriminator, and a multi-scale similarity measurement engine, whose role is to quickly determine the proximity of a real-time request to existing attack samples in the core attack feature dimension and output a comprehensive feature matching score. When the real-time features exceed the upper or lower limit range of known attack features in several key dimensions, or show a high degree of overlap with attack features in multiple dimensions, the similarity score will be significantly increased to reflect its potential risk. To improve the contextual accuracy of attack recognition, based solely on the feature matching score, introduce the behavior information of the session to which the request belongs as a supplementary reference, including indicators such as the request frequency change trend, session duration, path repeatability, and parameter structure volatility of the session, to assist in judging the request background from the user behavior level. Input the feature matching score and session behavior features into the comprehensive risk assessment module, and integrate them into the final attack likelihood score through methods such as weight fusion, rule strengthening, and statistical analysis.

[0017] Extract the index information of all key feature dimensions from the CC attack feature parameter set to construct a key feature dimension index set, which indicates which of the reduced features play a decisive role in attack behavior recognition. Match the reduced feature vector corresponding to the real-time HTTP request to be evaluated with this index set, extract the feature values of all specified dimensions from the original reduced vector, and construct a real-time key feature vector, which only retains the core feature information with the highest correlation with the CC attack and excludes the interference of secondary or invalid dimensions on the scoring result. Based on the above real-time key feature vector and the threshold and weight information in the CC attack feature parameter set, construct a feature similarity evaluation model, which is used to quantify the matching degree between the current request and the attack pattern in each key dimension. In the model design, the relationship between the feature value of each dimension and its corresponding upper and lower boundaries is introduced into the boundary determination function for measurement. If the value of this dimension falls within the upper and lower boundary intervals, it is considered that its matching degree is good, and the function output is 1; if the value exceeds the boundary, it gradually decays to the lowest acceptable threshold in a linear or non-linear manner according to the degree of its deviation from the boundary, and the output is a value close to 0 or even negative, which is used to represent the negative incentive degree of this feature dimension to abnormal behavior. At the same time, to reflect the influence of each dimension in the entire attack feature recognition, introduce the feature weight of each dimension provided in the attack feature parameter set, which is used to weight the boundary matching results of each dimension in the final scoring stage. In the execution of the matching calculation stage, substitute each feature value of the real-time key feature vector into the feature similarity evaluation model one by one, calculate the boundary matching results of all dimensions, then multiply these results with the corresponding feature weights one by one to form a weighted score vector, and finally sum up all the weighted scores and map the final score to a unified score interval through normalization operation to form a feature matching score. The higher this score, the closer the feature performance of the real-time request is to the feature pattern of historical CC attack behaviors, and vice versa, it represents that its behavior deviates from the attack features.

[0018] Step S104, perform time-varying parameter defense analysis based on the attack possibility score to obtain an adaptive defense rule set; Specifically, an attack situation vector reflecting the current network security situation is established. This vector is constructed based on the attack possibility scores collected within a continuous time window and includes three core elements: attack intensity, attack mutation degree, and attack distribution characteristics. Among them, the attack intensity represents the proportion of high-risk requests per unit time, the attack mutation degree reflects the dynamic drift degree of attack behaviors in the feature space, and the attack distribution characteristics depict the diffusion range of malicious requests across different sessions, source IPs, or paths. This situation vector can provide a multi-dimensional description of attack trends, complexity, and concentration, serving as the basic input information for constructing dynamic defense strategies. To model the behavioral relationship between attacks and defenses, a multi-player game model is constructed based on this attack situation vector, with three main participating roles defined, namely CC attackers, defense controllers, and resource schedulers. Among them, the attacker attempts to expand the attack impact and reduce costs, the defense controller is responsible for formulating countermeasures to minimize resource losses and misjudgment costs, and the resource scheduler achieves the optimal balance between security and service performance under the premise of limited system resources. Based on this game structure, optimization objective functions are defined for each participant. For example, the goal of the attacker is to maximize the request passing rate and minimize the challenge cost, the defender focuses on reducing the false alarm rate, shortening the response time, and controlling the risk of service interruption, while the resource scheduler weighs the fairness of the processing queue and the allocation efficiency of security resources. After clearly defining their respective game goals, the attack situation vector is introduced into the game model as a dynamic input affecting the decision variables of all parties, and a set of parameter update rules associated with time changes is constructed. These rules guide the system to automatically adjust the frequency, threshold, and execution resources of the defense response when the attack intensity increases or the behavior mutation intensifies. On this basis, the optimal control equation is introduced to mathematically solve these update rules and optimize the strategies. Through iterative calculations and strategy simulations, a set of defense strategy combinations with the best defense effect, optimal resource usage, and minimum response delay under the current situation is obtained. Finally, a set of optimal defense strategies is obtained. This strategy set includes the complexity and triggering mechanism of JS challenge verification, as well as the suspiciousness threshold used for session behavior analysis and the dynamic allocation ratio of system resources such as processors, bandwidth, and buffer areas. To enable this strategy set to be executed in a refined manner according to different levels of attack risks, it is subjected to a structured hierarchical combination process. Multiple defense levels are divided according to the interval of attack possibility scores, and a corresponding set of strategy combinations is bound under each level. For example, a low score corresponds to lightweight verification and resource retention, a medium score triggers behavior analysis and delay regulation, and a high score initiates strong challenge verification in cooperation with resource restrictions. Finally, an adaptive defense rule set is obtained.

[0019] Step S105: Perform hierarchical filtering on the real-time HTTP requests to be filtered according to the adaptive defense rule set to obtain the filtered secure traffic.

[0020] Specifically, according to the attack possibility score, each real-time HTTP request to be filtered is classified into different defense levels. Combining the corresponding relationship between the multi-level scoring intervals and defense strategies preset in the adaptive defense rule set, the requests are marked with different security risk levels, forming HTTP requests with defense level identifiers. These identifiers are used to trigger defense processes with different intensities and strategies in subsequent stages. For requests with scores exceeding the first threshold in the marking, that is, the traffic that is initially identified as having a certain risk but has not reached the rejection standard, the system performs JavaScript challenge verification on them. The specific method includes embedding specific JS execution logic to test whether the client has the normal browser parsing and response capabilities, and generating a JavaScript verification result based on its execution result. This result is used to further determine whether the request behavior conforms to the legal interaction mode. When the request score not only exceeds the first threshold but also fails the JavaScript challenge verification, that is, it exhibits obvious automated or scripted characteristics, then CAPTCHA graphic verification code verification is performed on it. This process guides the user to perform graphic recognition or interactive click operations to confirm that they are real human users, and finally obtains the verification response result. The determination of the verification result is not only used to determine whether the current request passes or not, but also, together with the JavaScript challenge result, is used to update the IP reputation library mechanism of the system. The system dynamically adjusts the reputation score of a certain source IP according to its verification performance over a period of time. If it frequently fails the verification, its reputation will be lowered. On the contrary, if it has been performing normally for a long time, the reputation score will gradually recover. The updated IP reputation library will be fed back to the adaptive defense rule set in real time, enabling the defense rules to always make policy decisions based on the latest credibility data during dynamic execution, forming a self-learning and self-adjusting defense closed-loop. At the same time, according to the risk level and verification status of each request with a level mark, combined with the current node resource load situation, a fine-grained processor resource, memory buffer, and network bandwidth allocation strategy is executed. In the resource scheduling engine, a lower priority is set for high-risk requests and their occupancy is restricted, while requests that pass the verification or have a lower score are given normal or weighted resource guarantees, so as to effectively suppress the consumption of potential attack resources while ensuring the system performance. Combining the resource scheduling results and the output of the verification process, one of the three response strategies is executed for each request to be processed: if the score is low or all verifications have been passed, it is allowed to pass normally; if the score is medium and some verifications fail, it enters the response delay mechanism, and the response is delayed through exponential backoff or queuing; if the score is extremely high and all verifications fail, the request processing is directly rejected, thus outputting the final filtered secure traffic.

[0021] In an embodiment of the present invention, the present invention constructs a comprehensive set of HTTP request feature vectors by performing multi-dimensional extraction and fusion of temporal features, session behavior features, and content features on historical HTTP request traffic samples. Compared with traditional methods that only rely on single or a small number of statistical features, it can more comprehensively characterize the feature patterns of HTTP requests. The present invention introduces Laplacian eigenmaps to perform dimensionality reduction on the set of HTTP request feature vectors, converting the original high-dimensional discrete features into a continuous feature space, effectively preserving the topological relationship and similarity structure between HTTP requests, not only reducing the computational complexity, but also enhancing the expressive power of the features, enabling the system to better capture the temporal correlation patterns in CC attacks. The present invention uses a deep penalty generative adversarial network for CC attack feature analysis. Through the adversarial learning of the generator and discriminator, it automatically learns the feature patterns of CC attacks, and has stronger feature learning ability compared with traditional machine learning methods; at the same time, the introduced attention mechanism can automatically focus on the key features for distinguishing CC attacks, improving the interpretability and accuracy of the model. The denoising penalty constraint introduced in the present invention constrains the gradient norm of the discriminator near the real data, making the output of the model stable when the input changes slightly, significantly enhancing the adaptability of the model to HTTP request mutations, and effectively coping with the behavior of attackers to avoid detection by changing request parameters, adjusting request frequencies, etc. The multi-layer game model constructed in the present invention regards CC attack defense as a dynamic game process between attackers and defenders, and obtains the optimal defense strategy by solving the optimal control equation, which can dynamically adjust the defense parameters according to the attack situation, and is more flexible and adaptable than static defense rules, and can optimize the resource utilization efficiency while ensuring security. The hierarchical filtering processing mechanism implemented in the present invention processes requests at different levels according to the attack possibility score, and combines various defense means such as JavaScript challenge verification, CAPTCHA verification, and dynamic resource allocation, and can adopt differential defense strategies for requests with different risk levels, minimizing the impact on normal users while ensuring the security of the system, especially having significant advantages in dealing with low-frequency CC attacks and mixed Flash Crowd traffic environments.

[0022] In a specific embodiment, the process of executing step S101 may specifically include the following steps: Perform data preprocessing on the historical HTTP request traffic samples to obtain a preprocessed set of HTTP request records; Extract temporal features from the preprocessed set of HTTP request records to obtain a set of HTTP request temporal features; Group the preprocessed set of HTTP request records by session ID to obtain a set of HTTP sessions; Extract session behavior features from the set of HTTP sessions to obtain a set of session behavior features; Extract content features from the preprocessed HTTP request record set to obtain the HTTP content feature set; Merge the HTTP request time series feature set, session behavior feature set, and HTTP content feature set to obtain the HTTP request feature vector set; Perform Laplacian eigenmap dimensionality reduction on the HTTP request feature vector set to obtain the dimensionality-reduced feature vector set.

[0023] Specifically, data preprocessing is performed on historical HTTP request traffic samples to unify field formats, timestamp standards, character encodings, and missing value filling strategies. At the same time, meaningless fields, empty requests, duplicate records, and illegal character interference items are removed to form a preprocessed HTTP request record set with a clean data format, clear fields, and a complete timeline, and ensure that this data set has basic field information such as accurate request time, session ID, URL path, request parameters, request headers, source IP, etc. On this basis, time series analysis operations are performed on each request record. All request records are sorted by timestamp, and the analysis interval is divided in units of a sliding time window or a fixed period to extract a series of time series features describing the request time behavior, including request frequency per unit time, mean, standard deviation, maximum and minimum values of request intervals, request peak positions, request density, burst degree, etc. Dimensions, and identify abnormal dense request segments through time distribution functions and probability histogram modeling methods to form a metric expression of each request in the time dimension, thereby constructing an HTTP request time series feature set. The preprocessed request records are grouped according to their session identification fields. All requests with the same session ID or the same source IP and consecutive request intervals lower than the set threshold are regarded as the same user behavior chain, constituting a logically meaningful HTTP session set. Based on the session-level data structure, session behavior features containing complete behavior information are extracted, including the total number of requests in a single session, the repetition rate of request paths, the diversity of URL paths within a session, the duration of a single session, request density distribution, the number of resource access types, session stability change indicators, etc. Through these session behavior features, patterns of potential attackers simulating normal user access behaviors are revealed, such as probing behaviors with low-frequency requests but continuous existence, high-density brushing behaviors with periodic bursts, or probing behaviors with a single path but continuously varying parameters, thereby constituting a session behavior feature set with attack behavior directivity. Content features are extracted from the preprocessed HTTP request record set, including the hierarchical structure depth of the URL path, path string entropy value, the number and variability of parameter names and parameter values, the number of request header fields, the nested level and number of fields in the Cookie structure, the complexity of the User-Agent string, the path jump length of the Referer, content encoding mark anomalies, and other content-related indicators. Through the analysis of the content structure and semantic layer, request types containing highly disguised, parameter-polluted, or feature-obscured behaviors are effectively identified, and the semantic recognition ability of content features can be further enhanced by combining a regular template library and keyword black-and-white list strategies, so that the content feature set becomes an important analysis support covering the concealed expression of attack requests.Unify the encoding and alignment of the HTTP request timing feature set, session behavior feature set, and HTTP content feature set in the feature dimension space. Merge them into a unified HTTP request feature vector set through the feature vector splicing method. Each vector in this set completely expresses the time behavior, context structure, and content complexity of the request. Introduce the Laplacian eigenmap method to perform dimensionality reduction on this high-dimensional feature set. This method constructs a similarity graph between HTTP request features, treats all request samples as nodes in the graph, calculates the similarity between samples using a Gaussian kernel or Euclidean distance function to construct weighted edges, thereby forming a weight matrix, and constructs a Laplacian matrix in combination with the node connectivity. With the help of its graph structure information, maintain the local geometric relationship between features. Under this graph structure, perform the feature mapping operation, that is, project the original high-dimensional feature vector set into a group of low-dimensional spaces by solving the eigenvectors of the Laplacian matrix, while maintaining the similarity relationship of the original data in the graph structure, so that the dimensionality-reduced feature vectors not only compress redundant information but also retain the discriminant structure and distribution characteristics of attack behaviors, forming a dimensionality-reduced feature vector set for subsequent CC attack recognition, feature adversarial training, and policy optimization analysis.

[0024] In a specific embodiment, the process of performing the Laplacian eigenmap dimensionality reduction on the HTTP request feature vector set to obtain the dimensionality-reduced feature vector set may specifically include the following steps: Calculate the HTTP request similarity based on the HTTP request feature vector set to obtain a weight matrix; Perform a metric calculation on the weight matrix to obtain a degree diagonal matrix; Perform matrix operations according to the degree diagonal matrix and the weight matrix to obtain a Laplacian matrix; Perform eigen-decomposition calculation on the Laplacian matrix to obtain an eigenvalue set and an eigenvector set; Sort and filter the eigenvector set according to the eigenvalue set to obtain a subset of principal eigenvectors; Project the HTTP request feature vector set into the feature space composed of the subset of principal eigenvectors to obtain a dimensionality-reduced feature vector set.

[0025] Specifically, HTTP request similarity calculation is performed based on the HTTP request feature vector set. A similarity function between samples is constructed. Commonly used functions include the Gaussian radial basis function, cosine similarity function, or Manhattan distance function. Through function operations, the numerical relationship between each pair of requests is obtained, and a symmetric similarity weight matrix is formed. Each element in this matrix represents the similarity degree between the corresponding two HTTP requests. The larger the value, the more similar they are at the feature level. In practical applications, to improve the sparsity of the weight matrix and reduce the computational complexity, a local adjacency mechanism is introduced. Only the similarity between each request and several nearest samples in its feature space is calculated, and other positions are set to zero values, thereby constructing a weight matrix that has practical discriminative ability and is sparse and efficient. The metric structure of the weight matrix is supplemented, that is, the connection strength of each request node is calculated. This step is completed by constructing a degree diagonal matrix. This matrix is a diagonal matrix, and each diagonal element represents the sum of all connection edge weights of the corresponding request in the weight matrix, representing its total connection strength with other requests in the similarity graph. This degree diagonal matrix and the previously constructed weight matrix are jointly used to generate the Laplacian matrix in the graph structure. This matrix represents the overall transformation form of the entire request feature graph in the graph structure space. By subtracting the weight matrix from the degree diagonal matrix, the Laplacian matrix is obtained, which reflects the difference in the connection relationship between the local and the whole of the nodes in the graph structure and has mathematical properties such as symmetry and positive semi-definiteness, making it suitable for feature embedding and dimensionality reduction modeling. The Laplacian matrix is subjected to eigenvalue decomposition, that is, the eigenvalue set and eigenvector set of this matrix are solved. By decomposition, the smoothest feature transformation direction in the graph is identified, that is, the principal component direction in the graph structure. All eigenvalues are sorted by size. The smallest eigenvalue corresponds to the direction in the sample structure where the change is the slowest and the local consistency is the strongest, and the corresponding eigenvector will form the basis of the embedding space. To achieve effective dimensionality reduction, according to the preset dimensionality reduction target dimension or through spectral gap analysis, the first several eigenvectors corresponding to the optimal eigenvalues are selected to construct a subset of principal eigenvectors. The original HTTP request feature vector set is projected into the low-dimensional space formed by this subset of eigenvectors. Through feature coordinate transformation, each request vector in the high-dimensional space is re-expressed in the low-dimensional principal component space, and a dimensionality-reduced feature expression matrix is formed.

[0026] In a specific embodiment, the process of executing step S102 may specifically include the following steps: Input the dimensionality-reduced feature vector set into the input layer of the deep penalty generative adversarial network for feature loading to obtain the initial network features; Perform a non-linear transformation on the initial network features through the generator in the deep penalty generative adversarial network to obtain intermediate mapping features; Input the intermediate mapping features into the discriminator in the deep penalty generative adversarial network for CC attack feature learning to obtain a feature response map; Calculate the feature importance of the feature response map through the attention mechanism layer in the deep penalty generative adversarial network to obtain the feature weight distribution; Calculate the denoising penalty constraint based on the feature weight distribution and gradient information to obtain the robustness-enhanced features, and extract the feature dimensions and their boundary values whose weights exceed the threshold from the robustness-enhanced features to obtain the CC attack feature parameter set.

[0027] Specifically, the dimensionality-reduced feature vector set of HTTP requests is input into the input loading layer of the deep penalty generative adversarial network. This loading layer is connected to the input layer of the generator network and is a linear transformation layer that performs preliminary scale mapping and embedding encoding on the input features to make them meet the calculation format and dimensionality requirements of subsequent neural network layers, and the output is the initial network features. The initial network features are input into the generator. The generator network consists of multiple fully connected layers, specifically set as a four-layer structure. The first layer is the input embedding layer, the second and third layers are hidden layers, and the fourth layer is the output layer. ReLU is used as the non-linear activation function between layers, and the Tanh function is used in the output layer to limit the range of generated feature values. The input of the generator can include both actual dimensionality-reduced features and random noise can be introduced during training to improve the generalization ability of the generator. The generator performs a non-linear mapping transformation on the input features and outputs intermediate mapping features. This intermediate feature vector is essentially a form of expression in the latent feature space, capturing deep features that are not explicitly encoded in the original request but are meaningful for model discrimination. The intermediate mapping features are input into the discriminator module in the deep penalty generative adversarial network. The discriminator consists of a four-layer fully connected neural network. The first layer is the input perception layer, the second and third layers are discriminator hidden layers, and the fourth layer is the probability output layer. The Sigmoid function is used to output the attack possibility prediction value, and the training objective is to distinguish between real features and generated features. In this discrimination process, the deep penalty generative adversarial network introduces the concept of a feature response map, that is, when each batch of training samples passes through the discriminator, the responses generated by each feature dimension in the activation of hidden layer neurons are recorded, thereby generating a response map reflecting the influence degree of each feature on the final classification output, providing input for feature interpretability and importance analysis. To achieve the goals of feature selection and feature compression, the deep penalty generative adversarial network embeds an attention mechanism layer in the discriminator structure. This layer is set after the second or third hidden layer of the discriminator, and weights are learned for the importance of each dimension in the feature response map by constructing a weight matrix. After normalization using the Softmax function, the weight value of each dimension feature is output. The training process of the attention mechanism layer is synchronized with the main network of the discriminator. Its goal is to maximize the discrimination accuracy while focusing the model's attention on the feature dimensions that can best distinguish CC attacks from normal requests, thereby generating a feature weight distribution. The higher the weight value, the greater the decision-making contribution of that dimension in attack discrimination. To improve the model's adaptability to variant attacks in actual scenarios, the deep penalty generative adversarial network introduces a denoising penalty mechanism to optimize the model's robustness through the stability of the discriminator gradient response.In each round of training, a small perturbation is applied to the input features, the gradient of the discriminator output with respect to the input is calculated, and then a constraint is imposed on the gradient norm to form a denoising penalty term. This term is added as an additional loss to the main loss function. The optimization objective is to slow down the large fluctuations in the output under perturbations, so as to maintain the stability of the output discrimination when facing mutation attack strategies such as malicious request parameter randomization and path obfuscation. After completing the above training process, the deep penalty generative adversarial network model has the ability to respond to the features of different types of HTTP requests. In the deployment stage, the trained discriminator and attention layer are directly used to infer and evaluate the newly input request features, and generate corresponding feature response maps and weight distributions. On this basis, the attention weights are screened, a preset threshold is set, and the dimensions with weights greater than this threshold are extracted from all feature dimensions and marked as key attack discrimination features. Combining the value range of this feature dimension in the corresponding training samples, the maximum value, minimum value, or upper and lower percentile boundary values are extracted, thus forming a CC attack feature parameter set. Each record in this set contains the feature dimension number, feature name, feature weight value, feature upper limit value, and feature lower limit value.

[0028] In a specific embodiment, the process of performing the step of calculating the denoising penalty constraint based on the feature weight distribution and gradient information to obtain the robustness-enhanced features, and extracting the feature dimensions and their boundary values with weights exceeding the threshold from the robustness-enhanced features to obtain the CC attack feature parameter set may specifically include the following steps: Calculate the gradient of the discriminator in the deep penalty generative adversarial network to obtain a feature gradient matrix, and calculate the norm of the feature gradient matrix to obtain a gradient norm value; Dynamically adjust the penalty coefficient according to the gradient norm value and the current traffic mutation degree index to obtain an adaptive penalty coefficient; Calculate the denoising penalty term based on the adaptive penalty coefficient and the feature weight distribution to obtain a constrained model loss function. The constrained model loss function includes the adversarial loss and the denoising penalty term; Optimize and train the discriminator using the constrained model loss function to output the robustness-enhanced features; Screen the feature dimensions with weight values greater than the preset threshold from the robustness-enhanced features and extract their boundary values to obtain the CC attack feature parameter set. The CC attack feature parameter set includes the feature dimension index, feature weight value, feature upper limit value, and feature lower limit value.

[0029] Specifically, a deep penalty generative adversarial network system consisting of a generator and a discriminator is constructed. The discriminator not only undertakes the adversarial task of identifying real and forged features but also needs to have the ability to control the stability of the gradient response to input perturbations. The structure of this network should consist of an input feature loading layer, a generator module, a discriminator module, an attention mechanism module, and a denoising penalty term calculation module, and the organic connection between modules is achieved through a standard deep learning framework. In the core stage of model training, gradient calculation operations are performed on the discriminator, that is, after the input feature vector is dimensionally reduced, the partial derivatives of the discriminator output result with respect to the input features are solved dimension by dimension to obtain a feature gradient matrix. This matrix records the sensitivity of the discriminator's response to each dimension of the input features. The larger the value, the stronger the influence of the feature on the model output, and at the same time, it also indicates that the feature is more vulnerable to input perturbations. After the feature gradient matrix is calculated, it is normalized, and the gradient L2 norm of each row (i.e., each sample) in each feature dimension is calculated to obtain the overall gradient response strength of each sample, which is then summarized into a set of stability quantization indicators called gradient norm values. In order to enable the discriminator to dynamically adapt to input perturbations and data changes, considering the changing trend of the current network traffic environment, a traffic variability index is introduced as a regulatory factor. This index is calculated based on the statistical change range or standard deviation of the request feature vectors in the sliding window to measure the fluctuation amplitude of the HTTP request structure in a short period. Combining this index with the previously calculated gradient norm values, the denoising penalty intensity in the current round of training is dynamically adjusted according to a preset functional relationship to obtain a penalty control amount that automatically changes with the training stage and traffic state, that is, an adaptive penalty coefficient. This coefficient will directly affect the weight of the penalty term in the model loss function and has the effect of automatically adjusting the sensitivity of the model to input perturbations. Based on the adaptive penalty coefficient, the gradient intensity of the discriminant output with respect to the input is weighted by combining the feature weight distribution in the discriminator to form a denoising penalty term. The denoising penalty term is superimposed on the original adversarial loss function to form a new constraint model loss function with structural regularization ability. This loss function not only retains the discriminator's classification ability for real and generated data but also introduces the ability to constrain the local gradient behavior of the model, thereby enhancing its invariance to small perturbations and the ability to identify unknown variant attacks. This composite loss function is used in the backpropagation and gradient optimization process and will automatically adjust the network weight structure, enabling the discriminator to not only have discriminative accuracy in the training set but also maintain strong generalization robustness in the test set and real network environment. After several rounds of optimized training, the feature response output by the discriminator will enhance the adversarial perturbation ability, which is called the robustness-enhanced feature.These features will carry the expression form for the discriminator to stably learn under multiple rounds of perturbations. On this basis, the feature weight distribution output by the embedded attention mechanism is sorted and analyzed, and a stable threshold within the system is set. All feature dimensions with weight values higher than this threshold are screened out, and these features are identified as the key inputs of the discriminant model. At the same time, in the training set, the value range of each key feature dimension in the attack and normal samples is traced back, and the minimum and maximum values of this dimension, or the upper and lower quartile values are selected as the value boundaries of this dimension, so as to construct a complete CC attack feature parameter set including feature dimension index, feature weight value, feature upper limit value and lower limit value. When this parameter set is applied to the network security defense scenario, its structure can be used as the basis for determining rule-based defense strategies. The input is the HTTP request features extracted in real time, and the output is whether the request meets the attack performance determination conditions of a certain feature dimension, and a hierarchical risk assessment system can be formed in combination with the scoring model; in the model integration scenario, this parameter set is also shared with other deep models for improving the discriminant weighting mechanism in the multi-model fusion strategy; at the same time, in the cloud platform deployment or edge gateway system, this set is cached as a feature rule table for accelerating fast matching and pre-judgment in low-resource environments and improving the response efficiency of the overall defense system.

[0030] In a specific embodiment, the process of executing step S103 may specifically include the following steps: Extract features from the real-time HTTP request to be filtered to obtain a real-time HTTP request feature vector, and perform Laplace mapping processing on the real-time HTTP request feature vector to obtain a dimension-reduced real-time feature vector; Construct a feature similarity evaluation model based on the CC attack feature parameter set, and input the dimension-reduced real-time feature vector into the feature similarity evaluation model for feature matching calculation to obtain a feature matching score; Perform comprehensive risk assessment based on the feature matching score and the session behavior information of the real-time HTTP request to be filtered to obtain an attack possibility score.

[0031] Specifically, a traffic processing framework for real-time request analysis is established. This framework can capture HTTP request packets at the network entry layer and quickly decode their content structure to perform structured processing on the request data at the first time. Keywords in the request content, such as URL path, parameter string, request header field, Cookie field, User-Agent identifier, Referer field, source IP address, and request timestamp, etc., will be uniformly extracted and mapped into a structure with numerical and vector processing capabilities. Subsequently, the above information is transformed into the original feature vector that can be input into the artificial intelligence model through preprocessing operations such as standardization and normalization, forming a real-time HTTP request feature vector. To maintain consistency with the feature space in the training stage, Laplace mapping processing is performed on the real-time feature vector. Based on the existing Laplace projection subspace, the input vector is projected using its eigenvector transformation matrix to ensure that the mapped result has the same dimensionality reduction scale and semantic space as the training samples. In the modeling process, Laplace eigenmap constructs a weight matrix, degree matrix, and Laplace matrix based on the similarity graph between historical HTTP requests, and extracts its principal component directions through eigenvalue decomposition to construct a projection matrix. When deployed, this matrix is cached in the online system to support low-latency computing. After the real-time request is input, the original vector is quickly transformed into a dimensionality-reduced real-time feature vector through a set of linear transformations, thereby reducing the computational complexity during model inference and enhancing the expression ability for the structure of non-linear attack behaviors. After completing dimensionality reduction, this is used as input to call a pre-constructed feature similarity evaluation model. This model is instantiated according to the set of CC attack feature parameters generated in the offline stage. Its structure includes a key feature dimension index table, the corresponding feature weight list, the upper and lower boundary values of each feature dimension, and a set of interpretability matching functions. The evaluation model extracts a subset of key dimensions from the real-time feature vector and calls the boundary matching function to calculate the boundary membership degree of each feature dimension, that is, to judge whether the feature value falls within the boundary interval of the attack sample. If it is within the boundary, a full score match is given; if it exceeds the boundary, a penalty score is given according to the distance beyond the boundary. The matching scores of all dimensions are then weighted and summed through the corresponding weight factors and normalized to obtain the feature matching score, which directly quantifies the similarity degree of the current request with typical attack samples in the high-dimensional feature distribution. The behavioral feature information of the session where the request is located is introduced to construct a complete risk assessment input set. Session clustering is performed on the current request. According to the relationship between the source IP, User-Agent, and time window of the request, the session entity to which it belongs is delimited, and behavioral statistical features are extracted from this session, including dimensions such as session life cycle length, request frequency fluctuation range, path repetition rate, resource request type change rate, parameter structure mutation times, etc. These behavioral features, combined with the feature matching score, are jointly used as input to the comprehensive risk assessment module.This module is usually implemented as a lightweight scoring network or decision tree model in the system architecture. Its structure includes an input layer, a feature normalization layer, a weighted rule base layer, and an output scoring function module. The model fuses and evaluates the feature matching score and the session behavior score through weighted addition or a multi-layer perception mechanism, and outputs an attack possibility score between 0 and 1. The closer the score is to 1, the higher the attack risk.

[0032] In a specific embodiment, the process of performing the steps of constructing a feature similarity evaluation model based on the CC attack feature parameter set and inputting the dimension-reduced real-time feature vector into the feature similarity evaluation model for feature matching calculation to obtain the feature matching score may specifically include the following steps: Extract the feature dimension indexes from the CC attack feature parameter set to obtain a set of key feature dimension indexes, and extract the feature values of the corresponding dimensions from the dimension-reduced real-time feature vector according to the set of key feature dimension indexes to obtain a real-time key feature vector; Construct a feature similarity evaluation model , where x is the real-time key feature vector, i represents the index, w i is the feature weight value of the corresponding dimension in the CC attack feature parameter set, B i (x i ) is a boundary determination function, n is the dimension number of the set of key feature dimension indexes, and the boundary determination function B i (x i ) is defined as B i (x i ) = 1 when x i falls between the feature upper limit value and the feature lower limit value, otherwise B i (x i ) decreases to a value between 0 and -1 according to the distance from the boundary, and S(x) represents the feature matching score; Substitute each dimension value xi of the real-time key feature vector into the feature similarity evaluation model to obtain the boundary matching results of all dimensions, and perform weighted summation and normalization processing on the boundary matching results of all dimensions to obtain the feature matching score.

[0033] Specifically, during the operation of the system, the pre-constructed CC attack feature parameter set is stored in the cache or database in a structured table form. Each parameter record includes four fields: feature dimension index, feature weight value, feature upper limit value, and feature lower limit value. This parameter set is generated by the attention weight output and boundary extraction module obtained from training in the deep penalty generative adversarial network, and has high discriminability and low redundancy. When it is necessary to perform a matching judgment on a certain real-time HTTP request, all feature dimension indexes are extracted from this parameter set to form a key feature dimension index set. This set is an integer vector that identifies the feature numbers that need to participate in the matching evaluation from the complete dimensionality-reduced feature space. The dimensionality-reduced feature vector is obtained from the input real-time HTTP request. This vector is a set of low-dimensional vectors formed after dimensionality reduction by the Laplace mapping module before. According to the key feature dimension index set, the corresponding feature values are extracted from this dimensionality-reduced vector according to the indexes to form a new vector structure, that is, the real-time key feature vector. To ensure processing efficiency, this extraction operation is completed through sparse matrix mapping or index selection tensors, avoiding the time overhead brought by loop structures. A feature similarity evaluation model is constructed. This model is a structured matching model with interpretability and adjustability. It is not a black-box discriminator in the form of a deep neural network, but a scoring function for rule expression. Its core structure consists of the following parts: The input is the real-time key feature vector x, and its dimension is n; the internal structure includes a set of boundary determination functions B i (x i ). Each B i performs piecewise scoring according to whether the value x i of the i-th feature falls between the upper and lower boundaries. If x i is within the predefined boundary interval, then B i (x i ) = 1, indicating that this feature fully conforms to the attack feature performance; if x i exceeds the boundary, then linear attenuation is performed according to the distance by which it exceeds the upper and lower limits, so that the output value of B i (x i ) drops from 0 to -1, representing that this feature is outside the security boundary and has a certain degree of deviation. Its attenuation amplitude is defined as a linear or exponential function according to the maximum deviation ratio. The boundary determination result of each dimension will be weighted with the feature weight of this dimension, indicating the influence degree of this feature in the overall scoring. In the scoring execution stage, the model executes the boundary determination function B i (x i ) for each dimension i to obtain the matching result, and combines the result with the weight Multiply them to form a weighted matching score. After summing up the weighted matching scores of all dimensions, divide the sum by the sum of all feature weights for normalization to obtain the final feature matching score S(x), whose value ranges from -1 to 1. The closer the value is to 1, the more highly the current request fits the attack pattern in multiple key feature dimensions. The closer it is to 0 or negative, the more its behavior deviates from the feature distribution range of the attack samples, thus providing a quantitative basis for the subsequent risk assessment system.

[0034] In a specific embodiment, the process of executing step S104 may specifically include the following steps: Construct an attack situation vector based on the attack possibility score. The attack situation vector includes the attack intensity, attack variability, and attack distribution characteristics within the current time window; Construct a set of game participants based on the attack situation vector. The set of game participants includes CC attackers, defense controllers, and resource schedulers; Define a game optimization objective according to the set of game participants, and perform time-varying parameter analysis based on the attack situation vector and the game optimization objective to obtain a parameter dynamic update rule; Optimize the parameter dynamic update rule by solving the optimal control equation to obtain an optimal defense strategy set. The optimal defense strategy set includes the JavaScript challenge verification intensity, session behavior analysis threshold, and resource allocation ratio; Perform hierarchical combination on the optimal defense strategy set to obtain an adaptive defense rule set. The adaptive defense rule set includes multiple defense levels, and each defense level corresponds to a different attack possibility score interval and a corresponding combination of defense measures.

[0035] Specifically, an attack situation vector describing the current attack state is constructed with the attack possibility score as the input. The attack possibility score is output by the upstream deep discriminant network, feature matching model or hybrid decision engine, representing the attack risk degree of a single HTTP request. By setting a sliding time window with a fixed length, all the scoring results within the current time window are statistically analyzed to construct a multi-dimensional vector reflecting the overall security situation. Among them, the attack intensity is measured by the proportion of requests with scores higher than a certain high-risk threshold. The attack variability is calculated by the standard deviation, entropy value or dispersion coefficient of the fluctuation range of key features in high-scoring requests. The attack distribution characteristics are modeled based on the discreteness of the IP sources, path distributions, user agent or session dimensions of high-scoring requests, and clustering entropy, frequency dispersion coefficient and other measurement methods are used to comprehensively evaluate whether the attack shows a centralized outbreak or a distributed scatter camouflage. Taking the attack situation vector as the input, mathematical representations of three types of game participants are constructed, namely CC attackers, defense controllers and resource schedulers. As potential adversaries, the strategies of CC attackers include attack operations such as request frequency adjustment, behavior obfuscation, feature perturbation, IP switching, etc. The goal is to bypass defense detection, maintain a high passing rate and consume the resources of the target server as much as possible. The defense controller represents the response execution core of the security module, and its strategies include the selection of verification means (such as whether to enable JS challenges), the adjustment of analysis granularity (such as session determination threshold), the risk response frequency, etc. The resource scheduler is responsible for resource balance control at the system level, and its strategies include CPU allocation, memory cache adjustment, bandwidth limitation and request queuing strategies. Its optimization goal is to maintain the service ability and stability of the system under the premise of effective defense. After clarifying the roles of the game participants, a multi-objective optimization function is constructed based on their strategy spaces and the attack situation vector to form the optimization objective expression of the game problem. The objective function of the CC attacker is defined as "maximizing the request passing rate minus the attack cost". The objective function of the defense controller is defined as "a weighted combination of maximizing the attack detection accuracy and minimizing the false alarm rate". The objective function of the resource scheduler is expressed as "maximizing the resource load balance degree and minimizing the system processing delay". To achieve dynamic adaptation, the attack situation vector is input into the game modeling tool, combined with the game objective function, and time-varying parameter analysis is performed. By calculating indicators such as risk weight fluctuation, attack mode transfer rate, response effect feedback, etc., dynamic adjustment rules for control variables are generated, that is, a set of adjustment models responsive to changes in the attack situation are established for each dimension of the strategy parameters (such as verification intensity, analysis threshold, resource quota), such as linear regression functions, exponential response models, state machine switching strategies or LSTM sequence prediction models. The optimal control equation is introduced to jointly optimize the above adjustment models. The inputs of the equation include: the current attack situation vector, the output value of the previous round of strategy, the strategy change cost function and the system resource constraint conditions. The optimization goal is to maximize the attack interception rate and minimize the verification cost under the constraints of minimizing service interruption and minimizing resource overrun.The optimal control solution is implemented using dynamic programming, the Lagrange multiplier method, the Bellman equation, or reinforcement learning methods, such as the Q-learning or DDPG algorithms, to form a step-by-step approximation process of the policy space in continuous time. Finally, the system outputs a set of verified optimal control policy results, namely the optimal defense policy set, which at least includes three types of core variables: the JavaScript challenge verification intensity (such as whether it is enabled, the enabled ratio, the complexity of the challenge script), the session behavior analysis threshold (such as the lower limit of the suspiciousness score), and the resource allocation ratio (such as the maximum allowed bandwidth for high-risk requests, the proportion of CPU cores, etc.). To improve the application flexibility and scalability of the policy system, the above optimal defense policy set is structurally reorganized to form a standardized hierarchical control table structure and construct an adaptive defense rule set. This rule set maps each scoring interval to a policy combination through setting multiple attack possibility scoring intervals. Each interval is defined as a defense level, and the higher the level, the stronger the policy strength and the more significant the resource intervention. Each record in the rule set consists of a scoring interval, a trigger condition, a verification policy, a resource regulation plan, and a recovery mechanism, and policy iteration is achieved through timed updates, policy evaluations, or manual adjustments by the administrator.

[0036] In a specific embodiment, the process of executing step S105 may specifically include the following steps: According to the attack possibility score of the real-time HTTP request to be filtered, perform a defense level division on the real-time HTTP request to be filtered to obtain an HTTP request with a level mark; Perform JavaScript challenge verification on the requests in the HTTP request with a level mark whose score exceeds the first threshold to obtain a JavaScript verification result; Perform CAPTCHA verification on the requests in the HTTP request with a level mark whose score exceeds the second threshold and whose JavaScript verification result fails to pass to obtain a verification response result, where the second threshold is greater than the first threshold; Update the reputation score of the request source IP based on the JavaScript verification result and the verification response result to obtain an updated IP reputation database, and feedback the updated IP reputation database to the adaptive defense rule set for rule update; Perform dynamic allocation of processor resources, memory buffers, and network bandwidth on the HTTP request with a level mark to obtain a resource scheduling result; Perform pass, delayed response, or rejection processing on the real-time HTTP request to be filtered according to the resource scheduling result and the verification passed status to obtain filtered secure traffic.

[0037] Specifically, a hierarchical decision-making module driven by real-time scoring is established. This module takes the attack possibility score as input, which is obtained by an artificial intelligence recognition model through reasoning on the feature vectors of HTTP requests and session behavior data. The output value ranges from 0 to 1, representing the probability that the request is a CC attack. The system sets two scoring thresholds: the first threshold is used to identify mildly suspicious requests, and the second threshold, which is higher than the first threshold, is used to identify severely high-risk requests. Each request is classified into multiple defense levels according to the score value, such as low risk (score < the first threshold), medium risk (between the two thresholds), and high risk (score > the second threshold), and a defense level mark is attached to the request object to form a set of HTTP requests with level marks. JavaScript challenge verification is performed on all requests with medium and high risk marks (i.e., scores exceeding the first threshold). This verification is implemented by dynamically injecting JavaScript scripts on the server side. After receiving the response, the client parses and correctly executes the script, such as constructing specific cookies, submitting signature verification parameters, or performing mathematical logic tasks. The system will collect the results returned by the client and compare them with the original logic to determine whether the client has the ability to parse and execute in the browser. This process does not rely on manual interaction, is transparent to normal users, and has a certain interception ability for simulation tools and script programs. Those who pass the verification will obtain a "verification successful" mark, while those who fail the verification or do not respond will be recorded as "JS verification failed". For requests with scores exceeding the second threshold and failing the JavaScript verification, a higher-level human-machine verification mechanism - CAPTCHA verification is performed. This verification mechanism requires the client to display interactive interfaces such as image recognition, character input, and drag-and-drop puzzles, and the user needs to complete the verification task through real operations. The system records whether the verification is successful according to the returned results, generates a verification response record, and retains the session context information to avoid repeated verification. The entire verification process must have timeout control, exception return handling, and verification status synchronization mechanisms to ensure the stable performance of the system in the face of large-scale verification traffic. To implement a dynamic reputation feedback and policy self-learning mechanism, a reputation scoring mechanism for the request source IP is established. After each verification ends, the IP reputation score is updated according to the verification results. If a certain IP continuously passes the verification, its reputation value will increase; conversely, if it fails multiple times, the reputation value will decrease. The reputation calculation model uses the exponential smoothing method or a score backtracking update method with a memory window to maintain the sensitivity and anti-mutation ability of the response. The updated IP reputation information is stored in the IP reputation database, which should adopt a high-concurrency key-value storage structure (such as Redis or an in-memory database), and is synchronized to the adaptive defense rule set in real time through a feedback interface for adjusting the initial score of subsequent requests, verification threshold adjustment, and policy level recommendations. For example, IPs with a higher reputation can be temporarily exempted from verification; IPs with an extremely low reputation can be added to the blacklist in advance.In terms of policy response, a resource-aware scheduling mechanism is introduced. Based on the HTTP requests with level tags, combined with the current system load status and resource pool capacity, dynamic allocation of processor resources, memory buffers, and network bandwidth for requests is performed. The scheduling policy uses a resource allocation model based on a priority queue or adopts a dynamic weight allocation method to preferentially allocate resources to requests that pass verification or have low risk, while performing bandwidth limitation, buffer contraction, or queuing delay processing on medium- and high-risk requests. In high-load situations, an elastic degradation strategy is used to delay the processing of high-risk requests to ensure the continuity of the core business of the system. Combining the comprehensive resource scheduling results and verification status, the final processing method for each HTTP request to be filtered is determined. If the resources are sufficient and the verification passes, it is directly released and enters the business logic layer; if the verification fails but the system resources are still available, it enters the delayed response queue for exponential backoff queuing processing; if the verification fails and the resources are tight, or the IP reputation is extremely low, a rejection response is directly returned, or it is redirected to a closed logic processing module such as an error page or a sandbox environment. This multi-path response mechanism constitutes the final secure traffic screening output process, ensuring that the system can dynamically adapt in the event of a high-risk traffic outbreak and achieving the triple goals of traffic quality filtering, precise resource allocation, and service availability guarantee.

[0038] The above described the traffic filtering method based on CC attack characteristics in the embodiments of the present invention. Next, the traffic filtering device based on CC attack characteristics in the embodiments of the present invention will be described. Please refer to Figure 2 One embodiment of the traffic filtering device based on CC attack characteristics in the embodiments of the present invention includes: A mapping and dimensionality reduction module 201, configured to perform feature extraction and Laplacian feature mapping and dimensionality reduction on historical HTTP request traffic samples to obtain a set of dimensionality-reduced feature vectors; A feature analysis module 202, configured to perform CC attack feature analysis based on the set of dimensionality-reduced feature vectors to obtain a set of CC attack feature parameters; A risk assessment module 203, configured to perform attack risk assessment on real-time HTTP requests to be filtered based on the set of CC attack feature parameters to obtain an attack possibility score; A defense analysis module 204, configured to perform time-varying parameter defense analysis based on the attack possibility score to obtain an adaptive defense rule set; A hierarchical filtering module 205, configured to perform hierarchical filtering processing on real-time HTTP requests to be filtered according to the adaptive defense rule set to obtain filtered secure traffic.

[0039] Through the collaborative cooperation of the above-mentioned various components, the present invention constructs a comprehensive set of HTTP request feature vectors by performing multi-dimensional extraction and fusion of temporal features, session behavior features, and content features on historical HTTP request traffic samples. Compared with traditional methods that only rely on single or a small number of statistical features, it can more comprehensively depict the feature patterns of HTTP requests. The present invention introduces Laplacian eigenmaps to reduce the dimensionality of the HTTP request feature vector set, converting the original high-dimensional discrete features into a continuous feature space, effectively retaining the topological relationship and similarity structure between HTTP requests. This not only reduces the computational complexity but also enhances the expressive power of the features, enabling the system to better capture the temporal correlation patterns in CC attacks. The present invention uses a deep penalty generative adversarial network for CC attack feature analysis. Through the adversarial learning of the generator and discriminator, it automatically learns the feature patterns of CC attacks and has stronger feature learning ability compared with traditional machine learning methods. At the same time, the introduced attention mechanism can automatically focus on the key features for distinguishing CC attacks, improving the interpretability and accuracy of the model. The denoising penalty constraint introduced in the present invention makes the model output stable when the input changes slightly by constraining the gradient norm of the discriminator near the real data, significantly enhancing the model's adaptability to HTTP request mutations and effectively dealing with the behavior of attackers evading detection by changing request parameters, adjusting request frequencies, etc. The multi-layer game model constructed in the present invention regards CC attack defense as a dynamic game process between attackers and defenders. By solving the optimal control equation, it obtains the optimal defense strategy, which can dynamically adjust the defense parameters according to the attack situation and is more flexible and adaptable than static defense rules, capable of optimizing resource utilization efficiency while ensuring security. The hierarchical filtering processing mechanism implemented in the present invention processes requests at different levels according to the attack possibility score. Combining multiple defense means such as JavaScript challenge verification, CAPTCHA verification, and dynamic resource allocation, it can adopt differential defense strategies for requests with different risk levels, minimizing the impact on normal users while ensuring system security, especially having significant advantages in dealing with low-frequency CC attacks and mixed Flash Crowd traffic environments.

[0040] Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the above-described devices, apparatuses, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0041] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a traffic filtering device based on CC attack characteristics (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0042] As described above, the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of various embodiments of the present invention.

Claims

1. A traffic filtering method based on CC attack characteristics, characterized in that, Including: Performing feature extraction and Laplacian eigenmap dimensionality reduction on historical HTTP request traffic samples to obtain a set of dimensionality-reduced feature vectors; Performing CC attack feature analysis based on the set of dimensionality-reduced feature vectors to obtain a set of CC attack feature parameters; Performing attack risk assessment on the real-time HTTP requests to be filtered based on the set of CC attack feature parameters to obtain an attack possibility score; Performing time-varying parameter defense analysis based on the attack possibility score to obtain an adaptive defense rule set; Performing hierarchical filtering processing on the real-time HTTP requests to be filtered according to the adaptive defense rule set to obtain filtered secure traffic.

2. The traffic filtering method based on CC attack characteristics according to claim 1, wherein The performing feature extraction and Laplacian eigenmap dimensionality reduction on historical HTTP request traffic samples to obtain a set of dimensionality-reduced feature vectors includes: Performing data preprocessing on historical HTTP request traffic samples to obtain a preprocessed set of HTTP request records; Extracting temporal features from the preprocessed set of HTTP request records to obtain a set of HTTP request temporal features; Grouping the preprocessed set of HTTP request records by session ID to obtain a set of HTTP sessions; Extracting session behavior features from the set of HTTP sessions to obtain a set of session behavior features; Extracting content features from the preprocessed set of HTTP request records to obtain a set of HTTP content features; Merging the set of HTTP request temporal features, the set of session behavior features, and the set of HTTP content features to obtain a set of HTTP request feature vectors; Performing Laplacian eigenmap dimensionality reduction on the set of HTTP request feature vectors to obtain a set of dimensionality-reduced feature vectors.

3. The traffic filtering method based on CC attack characteristics according to claim 2, characterized in that, The performing Laplacian eigenmap dimensionality reduction on the set of HTTP request feature vectors to obtain a set of dimensionality-reduced feature vectors includes: Calculating HTTP request similarity based on the set of HTTP request feature vectors to obtain a weight matrix; Performing metric calculation on the weight matrix to obtain a degree diagonal matrix; Performing matrix operations according to the degree diagonal matrix and the weight matrix to obtain a Laplacian matrix; Performing eigen-decomposition calculation on the Laplacian matrix to obtain a set of eigenvalues and a set of eigenvectors; Sorting and screening the set of eigenvectors according to the set of eigenvalues to obtain a subset of principal eigenvectors; Projecting the set of HTTP request feature vectors into the feature space constituted by the subset of principal eigenvectors to obtain a set of dimensionality-reduced feature vectors.

4. The traffic filtering method based on CC attack characteristics according to claim 1, wherein The performing CC attack feature analysis based on the set of dimensionality-reduced feature vectors to obtain a set of CC attack feature parameters includes: Inputting the set of dimensionality-reduced feature vectors into the input layer of a deep penalty generative adversarial network for feature loading to obtain initial network features; Performing non-linear transformation on the initial network features through the generator in the deep penalty generative adversarial network to obtain intermediate mapping features; Inputting the intermediate mapping features into the discriminator in the deep penalty generative adversarial network for CC attack feature learning to obtain a feature response map; Calculating feature importance on the feature response map through the attention mechanism layer in the deep penalty generative adversarial network to obtain a feature weight distribution; Calculate the denoising penalty constraint based on the feature weight distribution and gradient information to obtain robustness-enhanced features, and extract the feature dimensions and their boundary values with weights exceeding the threshold from the robustness-enhanced features to obtain the CC attack feature parameter set.

5. The traffic filtering method based on CC attack characteristics according to claim 4, wherein The calculating the denoising penalty constraint based on the feature weight distribution and gradient information to obtain robustness-enhanced features, and extracting the feature dimensions and their boundary values with weights exceeding the threshold from the robustness-enhanced features to obtain the CC attack feature parameter set includes: Calculate the gradient of the discriminator in the deep penalty generative adversarial network to obtain the feature gradient matrix, and calculate the norm of the feature gradient matrix to obtain the gradient norm value; Dynamically adjust the penalty coefficient according to the gradient norm value and the current traffic variability index to obtain the adaptive penalty coefficient; Calculate the denoising penalty term based on the adaptive penalty coefficient and the feature weight distribution to obtain the constrained model loss function, and the constrained model loss function includes the adversarial loss and the denoising penalty term; Optimize and train the discriminator using the constrained model loss function to output robustness-enhanced features; Screen the feature dimensions with weight values greater than the preset threshold from the robustness-enhanced features and extract their boundary values to obtain the CC attack feature parameter set, and the CC attack feature parameter set includes the feature dimension index, the feature weight value, the feature upper limit value, and the feature lower limit value.

6. The traffic filtering method based on CC attack characteristics according to claim 1, wherein The performing attack risk assessment on the real-time HTTP request to be filtered based on the CC attack feature parameter set to obtain the attack possibility score includes: Extract features from the real-time HTTP request to be filtered to obtain the real-time HTTP request feature vector, and perform Laplace mapping processing on the real-time HTTP request feature vector to obtain the reduced-dimensional real-time feature vector; Construct a feature similarity evaluation model based on the CC attack feature parameter set, and input the reduced-dimensional real-time feature vector into the feature similarity evaluation model to perform feature matching calculation to obtain the feature matching score; Perform comprehensive risk assessment based on the feature matching score and the session behavior information of the real-time HTTP request to be filtered to obtain the attack possibility score.

7. The traffic filtering method based on CC attack characteristics according to claim 6, characterized in that, The constructing a feature similarity evaluation model based on the CC attack feature parameter set, and inputting the reduced-dimensional real-time feature vector into the feature similarity evaluation model to perform feature matching calculation to obtain the feature matching score includes: Extract the feature dimension indexes in the CC attack feature parameter set to obtain the key feature dimension index set, and extract the feature values of the corresponding dimensions from the reduced-dimensional real-time feature vector according to the key feature dimension index set to obtain the real-time key feature vector; Construct a feature similarity evaluation model , where x is the real-time key feature vector, i represents the index, and w i is the feature weight value corresponding to the dimension in the CC attack feature parameter set, B i (x i ) is the boundary determination function, n is the dimension number of the key feature dimension index set, and the boundary determination function B i (x i ) is defined as B i (x i ) = 1 when x i falls between the feature upper limit value and the feature lower limit value, otherwise B i (x i ) decreases from 0 to -1 according to the distance from the boundary, and S(x) represents the feature matching score; Substitute each dimension value xi of the real-time key feature vector into the feature similarity evaluation model to obtain the boundary matching results of each dimension, and perform weighted summation normalization processing on the boundary matching results of all dimensions to obtain the feature matching score.

8. The traffic filtering method based on CC attack characteristics according to claim 1, wherein The performing time-varying parameter defense analysis based on the attack possibility score to obtain the adaptive defense rule set includes: Construct an attack situation vector based on the attack possibility score, where the attack situation vector includes the attack intensity, attack mutation degree, and attack distribution characteristics within the current time window; Construct a set of game participants based on the attack situation vector, where the set of game participants includes CC attackers, defense controllers, and resource schedulers; Define a game optimization goal according to the set of game participants, and perform time-varying parameter analysis based on the attack situation vector and the game optimization goal to obtain a parameter dynamic update rule; Optimize the parameter dynamic update rule by solving the optimal control equation to obtain an optimal defense strategy set, where the optimal defense strategy set includes the JavaScript challenge verification intensity, session behavior analysis threshold, and resource allocation ratio; Perform hierarchical combination on the optimal defense strategy set to obtain an adaptive defense rule set, where the adaptive defense rule set includes multiple defense levels, and each defense level corresponds to a different attack possibility score interval and a corresponding combination of defense measures.

9. The traffic filtering method based on CC attack characteristics according to claim 1, characterized in that Performing hierarchical filtering processing on the to-be-filtered real-time HTTP request according to the adaptive defense rule set to obtain filtered secure traffic, including: According to the attack possibility score of the to-be-filtered real-time HTTP request, perform defense level division on the to-be-filtered real-time HTTP request to obtain an HTTP request with a level mark; Perform JavaScript challenge verification on the requests in the HTTP request with a level mark whose score exceeds the first threshold to obtain a JavaScript verification result; Perform CAPTCHA verification on the requests in the HTTP request with a level mark whose score exceeds the second threshold and the JavaScript verification result fails to pass to obtain a verification response result, where the second threshold is greater than the first threshold; Update the reputation score of the request source IP based on the JavaScript verification result and the verification response result to obtain an updated IP reputation library, and feedback the updated IP reputation library to the adaptive defense rule set for rule update; Perform dynamic allocation of processor resources, memory buffers, and network bandwidth on the HTTP request with a level mark to obtain a resource scheduling result; Perform pass, delayed response, or rejection processing on the to-be-filtered real-time HTTP request according to the resource scheduling result and the verification passed status to obtain filtered secure traffic.

10. A traffic filtering device based on CC attack characteristics, characterized in that, For implementing the traffic filtering method based on CC attack characteristics as described in any one of claims 1-9, the traffic filtering device based on CC attack characteristics includes: A mapping and dimensionality reduction module for performing feature extraction and Laplacian feature mapping dimensionality reduction on historical HTTP request traffic samples to obtain a set of dimensionality-reduced feature vectors; A feature analysis module for performing CC attack feature analysis based on the set of dimensionality-reduced feature vectors to obtain a set of CC attack feature parameters; A risk assessment module for performing attack risk assessment on the to-be-filtered real-time HTTP request based on the set of CC attack feature parameters to obtain an attack possibility score; A defense analysis module, configured to perform time-varying parameter defense analysis based on the attack possibility score to obtain an adaptive defense rule set; A hierarchical filtering module, configured to perform hierarchical filtering processing on the to-be-filtered real-time HTTP requests according to the adaptive defense rule set to obtain filtered secure traffic.

Citation Information

Patent Citations

  • Industrial internet intrusion detection method based on Gaussian process

    CN114124517A

  • CC attack detection method and CC attack detection device

    CN114499917A

  • CC attack defense method and system based on time and space

    CN119210750A

  • Network attack risk mapping assessment method and system

    CN119583198A

  • Artificial intelligence enhanced distributed denial of service attack defense method and system

    CN119865343A

Cited By

  • Flow data cleaning method and system

    CN120710798A

  • A traffic data cleaning method and system

    CN120710798B

  • Quantum attack method and system for detecting continuous variable quantum key distribution

    CN121261890A

  • Cloud security multi-level depth defense system construction method and system

    CN121396667A

  • Active defense method and system based on large model

    CN121396685A