Distributed denial of service attack defense method and device and electronic equipment

By obtaining network characteristic data to calculate the attack impact and link reliability, building the objective function and solving the exception probability, it realizes accurate and flexible defense against DDoS attacks, isolates abnormal links, and improves the network system's anti-attack ability and traffic transmission efficiency.

CN120378205APending Publication Date: 2025-07-25CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510724516.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the DDoS attack defense strategy does not control network nodes accurately and flexible enough, resulting in the inability to effectively block malicious traffic and poor defense effect.

Method used

By obtaining network characteristic data, calculating the attack impact and link reliability, building the objective function and using gradient descent algorithm to solve it, determining the probability of exceptions, and executing a traffic isolation strategy to isolate the abnormal links to achieve optimal routing adjustment.

Benefits of technology

It improves the accuracy and flexibility of DDoS attack defense, avoids interference from normal nodes, and improves the network system's attack resistance and traffic transmission efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378205A_ABST
    Figure CN120378205A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed denial of service attack defense method and device and electronic equipment, relates to the technical field of network security, and is used for solving the problems that a control strategy for each network node is not accurate enough and low in flexibility during DDoS attack defense, and the method comprises the steps: obtaining network feature data in a preset time period; determining the attack influence degree and the link reliability between the two network nodes according to the network feature data; constructing a target function based on the attack influence degree, the link reliability, the traffic load and the data transmission time; solving the objective function according to the network feature data between every two network nodes to obtain the abnormal probability that each network node is an abnormal link; and based on each abnormal probability, executing a distributed denial of service attack defense strategy, through the above method, effectively calculating an optimal routing adjustment strategy, preventing normal network nodes from being interfered by attacked network nodes, and effectively isolating the attacked network nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a distributed denial of service attack defense method, device and electronic device. Background Art

[0002] The number of Internet of Things (IoT) devices is growing rapidly. When manufacturing these IoT devices, manufacturers usually focus their main investment on the functions of the IoT devices themselves, while ignoring the network security properties of IoT devices, which makes it easy for hackers to use these controlled IoT devices as springboards or zombie hosts to further enrich their attack resources to achieve their own attack goals. Taking the distributed denial of service (DDoS) attack as an example, hackers can control a large number of zombie hosts at the same time through the main control side, and use automated scripts to attack many potential target network systems in various networks including the Internet of Things, so that the attacked target network system cannot provide normal business services. Figure 1 FIG. 1 is a typical schematic diagram of a DDoS attack, in which the target network system being attacked is an autonomous system (AS).

[0003] In the related art, in order to achieve DDoS attack defense, each network node in the AS is usually grouped to form a variety of grouping schemes. When encountering a DDoS attack, a fixed strategy is used to disconnect the network nodes of some groups to achieve DDoS attack defense. However, this method is not flexible enough and the defense strategy is not precise enough. There may still be controlled nodes in the network nodes that have not been disconnected to launch DDoS attacks, so that all malicious traffic cannot be blocked, resulting in poor DDoS attack defense effect. Summary of the invention

[0004] The embodiments of the present application provide a distributed denial of service attack defense method, device and electronic device to solve the problem that the control strategy for each network node is not accurate enough and has low flexibility when performing DDoS attack defense in related technologies. It can effectively calculate the optimal routing adjustment strategy, block malicious traffic, and prevent DDoS attacks.

[0005] In a first aspect, the present application provides a distributed denial of service attack defense method, the method is applied to a network monitoring system, the network monitoring system includes a monitoring device and an autonomous domain composed of various network nodes, the method includes:

[0006] Obtain network feature data within a preset time period. The network feature data at least includes: the traffic rate between two network nodes, the average traffic rate, the proportion of traffic transmitted by different types of network protocols, the traffic load, the traffic change rate, and the data transmission time;

[0007] Determine the attack impact degree and link reliability between two network nodes according to the network feature data. The attack impact degree represents the degree of influence when the two network nodes are attacked, and the link reliability represents the degree of network fluctuation between the two network nodes;

[0008] Construct an objective function based on the attack impact degree, link reliability, traffic load, and data transmission time. Among them, the objective function is used for the convex optimization model that minimizes network latency;

[0009] Solve the objective function according to the network feature data between every two network nodes to obtain the anomaly probability that each network node link is an abnormal link;

[0010] Execute the distributed denial-of-service attack defense strategy based on each anomaly probability.

[0011] Based on the objective function, from the perspective of the degree of network node being attacked and network latency, it can accurately calculate the network nodes that may be under DDoS currently, and then implement a traffic isolation strategy for these network nodes to avoid interference to other normal nodes, improving the accuracy and flexibility of DDoS attack defense

[0012] In an alternative implementation manner, constructing the objective function based on the attack impact degree, link reliability, traffic load, and data transmission time includes:

[0013] The objective function is as follows:

[0014]

[0015] And construct the following constraint conditions:

[0016]

[0017] Among them, minf(x) represents the objective function;

[0018] λ1, λ2, λ3, λ4 represent correction factors, which are preset parameters;

[0019] D ij represents the data transmission time;

[0020] L ij represents the traffic load;

[0021] I attack represents the attack impact degree;

[0022] S ij represents the link reliability;

[0023] X ij represents the exception probability;

[0024] T represents a preset probability threshold;

[0025] U min represents the threshold of the number of links between two directly connected network nodes in the autonomous region;

[0026] E represents the set of all network nodes in the autonomous region.

[0027] In an alternative embodiment, according to the network feature data between every two network nodes, solving the objective function to obtain the exception probability that each network node link is an abnormal link includes:

[0028] Using the following gradient descent algorithm to solve the optimal solution of the objective function:

[0029]

[0030] where k represents the iteration round;

[0031] η represents the iteration step size;

[0032] X ij (k+1) represents the exception probability that the network node link between the i-th network node and the j-th network node is an abnormal link when the iteration round is k + 1;

[0033] X ij (k) represents the exception probability that the network node link between the i-th network node and the j-th network node is an abnormal link when the iteration round is k;

[0034] represents the gradient norm when the iteration round is k;

[0035] represents the gradient norm.

[0036] In an alternative embodiment, the attack impact degree is calculated by the following formula:

[0037] I attack (i, j) = αI rate (i, j) + βI protocal (i, j)

[0038] where,

[0039]

[0040] I attack (i, j) represents the attack impact degree; α represents I rate (i, j) corresponding weight parameter; β represents I protocal (i, j) corresponding weight parameter;

[0041] I rate (i, j) is used to determine whether a sudden abnormality occurs in the network node link between the i-th network node and the j-th network node;

[0042] I protocal (i, j) represents the proportion of common attack protocols in the network node link between the i-th network node and the j-th network node;

[0043] ΔR ij (t) represents the traffic change rate;

[0044] δ R represents a preset traffic change rate threshold;

[0045] P k,i,j (t) represents the proportion of traffic transmitted by different types of network protocols.

[0046] In an alternative embodiment, the link reliability can be calculated by the following formula:

[0047] S ij =1 - |ΔR ij (t)|

[0048] where S ij represents the link reliability;

[0049] ΔR ij (t) represents the traffic change rate.

[0050] In an alternative embodiment, based on each anomaly probability, a distributed denial-of-service attack defense strategy is executed, including:

[0051] Compare each anomaly probability with a preset anomaly probability threshold, and screen out each target network node link corresponding to the anomaly probability greater than the anomaly probability threshold;

[0052] Execute a traffic isolation strategy for each target network node link.

[0053] In a second aspect, the present application provides a distributed denial-of-service attack defense device, which is applied to a network monitoring system. The network monitoring system includes monitoring devices and an autonomous domain composed of each network node. The device includes:

[0054] An acquisition module, configured to acquire network feature data within a preset time period, where the network feature data at least includes: the traffic rate between two network nodes, the average traffic rate, the proportion of traffic transmitted using different types of network protocols, the traffic load, the traffic change rate, and the data transmission time;

[0055] A determination module, configured to determine the attack impact degree and the link reliability between two network nodes according to the network feature data, where the attack impact degree represents the degree of influence when the two network nodes are attacked, and the link reliability represents the degree of network fluctuation between the two network nodes;

[0056] A processing module, configured to construct an objective function based on the attack impact degree, the link reliability, the traffic load, and the data transmission time, where the objective function is used for a convex optimization model that minimizes network latency;

[0057] A calculation module, configured to solve the objective function according to the network feature data between every two network nodes, and obtain the abnormal probability that each network node link is an abnormal link

[0058] A defense module, configured to execute a distributed denial of service attack defense strategy based on each abnormal probability.

[0059] In an optional implementation manner, when constructing the objective function based on the attack impact degree, the link reliability, the traffic load, and the data transmission time, the processing module is specifically configured to construct the following objective function:

[0060]

[0061] And construct the following constraint conditions:

[0062]

[0063]

[0064] Where, minf(x) represents the objective function;

[0065] λ1, λ2, λ3, λ4 represent correction factors, which are preset parameters;

[0066] D ij Represents the data transmission time;

[0067] L ij Represents the traffic load;

[0068] I attack Represents the attack impact degree;

[0069] S ij Represents the link reliability;

[0070] Xij represents the abnormal probability;

[0071] T represents a preset probability threshold;

[0072] U min represents the threshold of the number of links between two directly connected network nodes in the autonomous domain;

[0073] E represents the set of all network nodes in the autonomous domain.

[0074] Through the above objective function, the abnormal probability of each network node link can be solved, so as to facilitate traffic isolation for network node links with abnormal probability greater than the preset threshold, and avoid interference to other normal network nodes.

[0075] In an alternative embodiment, when solving the objective function according to the network feature data between every two network nodes to obtain the abnormal probability that each network node link is an abnormal link, the calculation module specifically uses the gradient descent algorithm to solve the optimal solution of the objective function:

[0076]

[0077] where k represents the number of iteration rounds;

[0078] η represents the iteration step size;

[0079] X ij (k+1) represents the abnormal probability that the network node link between the i-th network node and the j-th network node is an abnormal link when the iteration round is k + 1;

[0080] X ij (k) represents the abnormal probability that the network node link between the i-th network node and the j-th network node is an abnormal link when the iteration round is k;

[0081] represents the gradient norm when the iteration round is k;

[0082] represents the gradient norm.

[0083] In an alternative embodiment, the calculation module calculates the attack influence degree through the following formula:

[0084] I attack (i, j) = αI rate (i, j) + βI protocal (i, j)

[0085] where

[0086]

[0087] I attack (i, j) represents the attack impact degree; α represents I rate (i, j) corresponding weight parameter; β represents I protocal (i, j) corresponding weight parameter;

[0088] I rate (i, j) is used to determine whether a sudden anomaly occurs in the network node link between the i-th network node and the j-th network node;

[0089] I protocal (i, j) represents the proportion of common attack protocols in the network node link between the i-th network node and the j-th network node;

[0090] ΔR ij (t) represents the traffic change rate;

[0091] δ R represents a preset traffic change rate threshold;

[0092] P k,i,j (t) represents the proportion of traffic transmitted by different types of network protocols.

[0093] In an alternative embodiment, the calculation module calculates the link reliability through the following formula:

[0094] S ij = 1 - |ΔR ij (t)|

[0095] where S ij represents the link reliability;

[0096] ΔR ij (t) represents the traffic change rate.

[0097] In an alternative embodiment, when implementing the distributed denial of service attack defense strategy based on each anomaly probability, the defense module is specifically configured to:

[0098] Compare each anomaly probability with a preset anomaly probability threshold, and filter out each target network node link corresponding to an anomaly probability greater than the anomaly probability threshold;

[0099] Execute a traffic isolation strategy for each target network node link.

[0100] In a third aspect, the present application provides an electronic device, which includes a processor and a memory. Among them, the memory stores program code, and when the program code is executed by the processor, the processor is caused to execute the steps of the distributed denial of service attack defense method described in the first aspect above.

[0101] In a fourth aspect, the present application provides a computer-readable storage medium, which includes program code. When the program code runs on an electronic device, the program code is used to cause the electronic device to execute the steps of the distributed denial of service attack defense method described in the first aspect above.

[0102] In a fifth aspect, the present application provides a computer program product. When the computer program product is called by a computer, the computer is caused to execute the steps of the distributed denial of service attack defense method as described in the first aspect.

[0103] In addition, other features and advantages of the present application will be described in the subsequent specification, and some of them will become obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0104] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts. In the drawings:

[0105] Figure 1 It is a schematic diagram of a DDoS attack scenario in the prior art;

[0106] Figure 2 It is a schematic diagram of an application scenario of a distributed denial of service attack defense method provided by an embodiment of the present application;

[0107] Figure 3 It is a schematic diagram of the implementation process of a distributed denial of service attack defense method provided by an embodiment of the present application;

[0108] Figure 4 It is a schematic diagram of the structure of a distributed denial of service attack defense device provided by an embodiment of the present application;

[0109] Figure 5 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0110] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of the technical solutions of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments recorded in this application document without creative efforts belong to the scope protected by the technical solutions of this application.

[0111] It should be noted that in the description of this application, "a plurality of" is understood as "at least two". "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B may represent: A is directly connected to B and A is connected to B through C. In addition, in the description of this application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying an order.

[0112] In addition, in the technical solutions of this application, the collection, dissemination, use, etc. of data all comply with the requirements of relevant national laws and regulations.

[0113] The design concept of the embodiments of this application is briefly introduced below:

[0114] The number of IoT devices has been growing rapidly. When manufacturing these IoT devices, each manufacturer usually focuses the main investment on the functions of the IoT devices themselves, while ignoring the network security attributes of the IoT devices. As a result, hackers can easily use these controlled IoT devices as springboards or botnets to further enrich their attack resources to achieve their attack goals. Taking the DDoS attack as an example, hackers can simultaneously control a large number of zombie hosts through the master control side and use automated scripts to launch attacks on many potential target network systems in various networks including the Internet of Things, resulting in the target network systems under attack being unable to provide normal business services. In related technologies, to achieve DDoS attack defense, the network nodes in the AS are usually grouped to form various grouping schemes. When a DDoS attack occurs, a fixed strategy is adopted to disconnect the network nodes in some of the groups to achieve DDoS attack defense. However, this method is not flexible enough, the defense strategy is not precise enough, and there may still be controlled nodes among the network nodes that are not disconnected, which can launch DDoS attacks, resulting in the inability to block all malicious traffic and poor DDoS attack defense effects.

[0115] In view of this, the present application provides a method for defending against distributed denial of service (DDoS) attacks, aiming to improve the flexibility and accuracy of DDoS attack defense. The method includes: First, obtaining network feature data within a preset time period; then, determining the attack impact degree and link reliability between two network nodes based on the network feature data; further constructing an objective function based on the attack impact degree, link reliability, traffic load, and data transmission time; secondly, solving the objective function according to the network feature data between each two network nodes to obtain the abnormal probability of each network node being an abnormal link; finally, executing a DDoS attack defense strategy based on each abnormal probability. Through the above method, based on the objective function, it is possible to accurately calculate the network nodes that may be currently under DDoS attack from the perspective of the degree of network node being attacked and network latency, and then implement a traffic isolation strategy for these network nodes to avoid interference to other normal nodes, thereby improving the accuracy and flexibility of DDoS attack defense.

[0116] Further, referring to Figure 2 As shown, it is a schematic diagram of an application scenario provided by an embodiment of the present application. In this application scenario, the network monitoring system 1 includes a monitoring device 11 and an autonomous domain 12 composed of various network nodes. The monitoring device includes a network traffic monitoring and analysis module 111, a dynamic routing optimization module 112, and an attack traffic isolation and redirection module 113. The monitoring device 11 is connected to the autonomous domain 12 through cellular mobile communication technology. Among them, the cellular mobile communication technology, for example, includes the fifth-generation mobile communication (5G) technology; it can also be connected through short-range wireless communication methods. The short-range wireless communication methods, for example, include Wireless Fidelity (Wi-Fi). Of course, it can also be communicatively connected through other means. Each network node included in the autonomous domain 12 can be: routers, switches, Internet of Things devices, servers, and other devices. In an embodiment of the present application, the monitoring device 11 can preset a defense strategy update time period, for example, perform a defense strategy update every ten minutes. When a DDoS attack enters the autonomous domain, the monitoring device accurately identifies the network nodes under attack, so that the network nodes under attack can be isolated in a timely manner, thereby improving the anti-attack ability of the autonomous domain, avoiding interference to other normal nodes from the attacked nodes, and minimizing the impact of the DDoS attack.

[0117] The following describes the method for defending against distributed denial of service attacks provided by an exemplary embodiment of the present application with reference to the accompanying drawings.

[0118] Referring to Figure 3As shown in the figure, it is a schematic diagram of the implementation process of a distributed denial of service attack defense method provided by an embodiment of the present application. The specific implementation process of this method is as follows:

[0119] S1: Obtain network feature data within a preset time period.

[0120] In the embodiment of the present application, the monitoring system can obtain network feature data within a preset time period. For example, obtain network feature data in the time period from 10:00 to 11:00.

[0121] Specifically, when the monitoring system obtains network feature data within a preset time period, it can at least obtain the traffic rate, average traffic rate, proportion of traffic transmitted by different types of network protocols, traffic load, traffic change rate, and data transmission time between two network nodes.

[0122] In the face of DDoS attack threats, compared with other types of network attacks, the characteristics of most DDoS attacks are relatively obvious. These malicious traffic can cause congestion in the links between target network nodes or paralyze specific servers, and the network feature data can significantly reflect the abnormal traffic situation in the autonomous domain. Therefore, in the embodiment of the present application, the monitoring system can monitor the network feature data of each network node in the autonomous domain in real time, and judge whether each network node in the autonomous domain is under DDoS attack according to these network feature data.

[0123] Furthermore, in the embodiment of the present application, the traffic rate can represent the speed (actual amount of data transmitted) of data transmission between network node i and network node j within a preset time period. The traffic rate between every two network nodes can be specifically calculated by the following formula:

[0124]

[0125] Where R ij (t) represents the traffic rate between two network nodes;

[0126] R total (i, j, t) represents the total number of bytes of data transmitted between two network nodes within time period t;

[0127] Δt represents the length of the time window.

[0128] The average traffic rate can represent the average speed of data transmission between network node i and network node j within a preset time period. The average traffic rate between every two network nodes can be specifically calculated by the following formula:

[0129]

[0130] Where, Represents the average traffic rate between two network nodes;

[0131] t - k represents a certain moment before the current time window;

[0132] W represents the time window.

[0133] The proportion of traffic transmitted by different types of network protocols characterizes the proportion of traffic transmitted by different types of network protocols in the total traffic. Specifically, it can be calculated by the following formula:

[0134]

[0135] Among them, P k,i,j (t) represents the proportion of traffic transmitted by different types of network protocols;

[0136] N k,i,j (t) represents the number of data packets of the k-th protocol in the traffic occurring between network node i and network node j within the preset time period t;

[0137] ∑ protocal N k,i,j (t) represents the total number of data packets within the preset time period t.

[0138] The traffic load characterizes the data transmission pressure borne within the preset time period, defined as the ratio of the traffic rate to the link capacity, and the link capacity can be directly measured by the monitoring system. Then, the traffic load can be calculated by the following formula:

[0139]

[0140] Among them, L ij (t) represents the traffic load;

[0141] R ij (t) represents the traffic rate;

[0142] C ij Represents the link capacity.

[0143] The traffic change rate characterizes the degree of change in the traffic between network node i and network node j within the preset time period. Specifically, the traffic change rate can be calculated by the following formula:

[0144]

[0145] Among them, ΔR ij (t) represents the traffic change rate;

[0146] R ij (t) represents the traffic rate;

[0147] represents the average flow rate.

[0148] In addition, the monitoring system also detects the data transmission time D ij , D ij represents the transmission time of data on the network node link from network node i to network node j.

[0149] Through the above various calculation formulas, the network characteristic parameters in the embodiments of the present application can be obtained. Through the network characteristic parameters, it is beneficial to determine the traffic conditions of current network nodes, so as to identify attack traffic and normal traffic.

[0150] S2: Determine the attack impact degree and link reliability between two network nodes according to the network characteristic data.

[0151] In the embodiments of the present application, it is also necessary to determine the attack impact degree and link reliability between two network nodes. Specifically, the attack impact degree characterizes the degree of influence when two network nodes are attacked, and the link reliability characterizes the degree of network fluctuation between two network nodes.

[0152] In an alternative embodiment, the attack impact degree can be calculated by the following formula:

[0153] I attack (i, j) = αI rate (i, j) + βI protocal (i, j)

[0154] wherein, I attack (i, j) represents the attack impact degree, α represents the weight parameter corresponding to I rate (i, j); β represents the weight parameter corresponding to I protocal (i, j);

[0155] I rate (i, j) is used to determine whether a sudden abnormality occurs in the network node link between the i-th network node and the j-th network node;

[0156] I protocal (i, j) represents the proportion of common attack protocols in the network node link between the i-th network node and the j-th network node.

[0157] Furthermore, in the embodiments of the present application, I rate (i, j) can be calculated by the following formula:

[0158]

[0159] wherein, ΔR ij (t) represents the flow rate change rate;

[0160] δ R represents a preset traffic change threshold; if the traffic change rate exceeds δ R , it is considered that there is an abnormal situation in the traffic between two network nodes.

[0161] Furthermore, in the embodiments of the present application, I protocal (i, j) can be calculated by the following formula:

[0162]

[0163] where P k,i,j (t) represents the proportion of traffic transmitted by different types of network protocols.

[0164] Through the above method according to the network characteristic data, the attack impact degree and the link reliability can be accurately calculated. The attack impact degree and the link reliability can reflect the abnormal situation of the traffic between network nodes. The attack impact degree can be used to identify the degree of influence of a DDoS attack between two network nodes, while the link reliability can reflect the severity of the link fluctuation between two network nodes. The larger the fluctuation value, the lower the link reliability. At this time, the possibility of a DDoS attack between network nodes is also higher.

[0165] S3: Construct an objective function based on the attack impact degree, link reliability, traffic load, and data transmission time.

[0166] In the embodiments of the present application, when constructing the objective function of the convex optimization model, the network delay can be minimized and the attack impact degree and link reliability of network nodes can be maximized. Therefore, from the two perspectives of the degree of being attacked and network delay, the attack impact degree, link reliability, traffic load, and data transmission time can be used to construct the objective function corresponding to the convex optimization model in which the link of each network node is an abnormal link.

[0167] Specifically, in the embodiments of the present application, the objective function is as follows:

[0168]

[0169] Then, the constraint conditions are constructed as:

[0170]

[0171] where minf(x) represents the objective function;

[0172] λ1, λ2, λ3, λ4 represent correction factors, which are preset parameters;

[0173] D ij represents the data transmission time;

[0174] L ij represents the traffic load;

[0175] I attack represents the attack impact degree;

[0176] S ij represents the link reliability;

[0177] X ij represents the anomaly probability;

[0178] T represents the preset probability threshold;

[0179] U min represents the threshold of the number of links between two directly connected network nodes in the autonomous domain;

[0180] E represents the set of all network nodes in the autonomous domain.

[0181] When setting the constraint conditions, it is also necessary to consider that the number of links between two directly connected network nodes reaches a certain threshold U min , the threshold U min can be selected according to the actual application scenario to ensure the connectivity and availability of the network, and to avoid that when isolating the network nodes under DDoS attack later, there are not enough network nodes available, which increases the load of the remaining network nodes in the autonomous domain and reduces the stability of the autonomous domain.

[0182] When setting the objective function, based on the attack impact degree and the link reliability, when solving the network nodes that may be under DDoS attack, network nodes with higher attack impact degree and link reliability are preferentially selected. Moreover, considering the traffic load and the data transmission time, when the network nodes under DDoS attack process service data, their own load is definitely too high. Based on the traffic load and the data transmission time, network nodes with higher load in the preset time period can be screened out as candidate abnormal network nodes, so as to more accurately screen the network nodes under DDoS attack from multiple dimensions of parameters.

[0183] S4: According to the network feature data between every two network nodes, solve the objective function to obtain the anomaly probability that the link of each network node is an abnormal link.

[0184] In the embodiments of the present application, the gradient descent algorithm can be used to solve the objective function, and other algorithms can also be used to solve the objective function, such as the stochastic approximation method, etc. The embodiments of the present application do not make specific limitations here.

[0185] In an optional implementation manner, the following gradient descent algorithm can be used to solve the optimal solution of the objective function:

[0186]

[0187] Among them, k represents the number of iteration rounds;

[0188] η represents the iteration step size;

[0189] X ij (k+1) represents the abnormal probability that the network node link between the i-th network node and the j-th network node is an abnormal link when the iteration round is k + 1;

[0190] X ij (k) represents the abnormal probability that the network node link between the i-th network node and the j-th network node is an abnormal link when the iteration round is k;

[0191] represents the gradient norm when the iteration round is k;

[0192] represents the gradient norm.

[0193] In the embodiments of the present application, the iteration step size and the number of iteration rounds can be set according to specific application scenarios to set the iteration interval. For example, the iteration step size is set to 0.1 and the number of iteration rounds is set to 50. When the gradient norm is less than the preset threshold, it indicates that the iteration ends. When the iteration ends, the abnormal probability X of each network node link being an abnormal link is obtained ij .

[0194] S5: Based on each abnormal probability, execute a distributed denial-of-service attack defense strategy.

[0195] In an alternative embodiment, for each network node in the autonomous domain, by solving the objective function, the abnormal probability that the network node link corresponding to each pair of network nodes is an abnormal link can be obtained.

[0196] Then, compare the abnormal probability corresponding to each network node link with the preset abnormal probability threshold. Thus, each target network node link with an abnormal probability greater than the abnormal probability threshold can be screened out. In the embodiments of the present application, the preset abnormal probability threshold can be selected according to the actual application scenario. For example, it is set to 0.6. The embodiments of the present application do not make specific limitations here.

[0197] Exemplarily, for instance, currently there is a network node link 1 corresponding to network node 1 and network node 2, and its corresponding abnormal probability is 0.4. There is also a network node link 2 corresponding to network node 3 and network node 4, and its corresponding abnormal probability is 0.7. Then, if the abnormal probability of network node link 2 is greater than the preset abnormal probability threshold, network node link 2 is screened as the target network node link. Further, a traffic isolation policy is executed on the target network node link, so that the routing relationship between the target network node links is disconnected, while other normal network node links can still establish routing relationships normally and process and forward network traffic, thereby achieving the isolation of abnormal network nodes and preventing normal nodes from receiving DDoS attacks again.

[0198] Furthermore, after each execution of the distributed denial-of-service attack defense policy, the monitoring system can collect the updated routing information and compare and analyze the defense effects under different defense policies. The performance of each defense policy is backtested through offline testing, and the routing optimization policy is further adjusted based on the backtest results to ensure that it can automatically adapt and optimize the routing path in future attacks or traffic fluctuations, continuously improving the defense effectiveness and accuracy against DDoS attacks.

[0199] Exemplarily, taking a specific example below to illustrate the technical solution of the embodiment of the present application:

[0200] First, as shown in Table 1, it is the network feature data obtained by the monitoring system for monitoring 8 network nodes in the autonomous domain.

[0201] Table 1

[0202]

[0203] Furthermore, the correction factors λ1, λ2, λ3, and λ4 in the objective function are set to 0.909, 0.2, 0.66, and 0.61 respectively.

[0204] Then, the network feature parameters in Table 1 can be substituted into the objective function and the constraint conditions are set:

[0205]

[0206] The gradient descent method described above is used for iterative solution to obtain the corresponding abnormal probability of each initial network node link. For example, as shown in Table 2:

[0207] Table 2

[0208]

[0209]

[0210] Then, when the preset abnormal probability is 0.5, if the abnormal probabilities corresponding to the initial network node links 1-2, 2-4, 1-3, 4-5, 4-7, and 6-8 are greater than the preset abnormal probability threshold, the traffic isolation strategy can be executed for these initial network node links to achieve DDoS attack defense.

[0211] Through the distributed denial of service attack defense method provided by the embodiments of the present application, based on network characteristic parameters such as traffic rate, average traffic rate, proportion of traffic transmitted by different types of network protocols, traffic load, traffic change rate, and data transmission time, the network nodes that may currently be under DDoS attack can be obtained by solving the objective function. It can determine whether a network node has been attacked by DDoS from the impact and load conditions of the network node under attack, so as to dynamically adjust the routing path according to the status of each network node, effectively avoid normal network nodes from being interfered by the attacked nodes, and can also implement the traffic balancing strategy to effectively avoid network nodes with performance bottlenecks, further improving the anti-attack ability and traffic transmission efficiency of each network node in the autonomous domain.

[0212] Further, based on the same technical concept, the embodiments of the present application provide a distributed denial of service attack defense device, and the distributed denial of service attack defense device is used to implement the above method flow of the embodiments of the present application. Refer to Figure 4 As shown, the device includes: an acquisition module 401, a determination module 402, a processing module 403, a calculation module 404, and a defense module 405, where

[0213] The acquisition module 401 is configured to acquire network characteristic data within a preset time period, and the network characteristic data at least includes: traffic rate between two network nodes, average traffic rate, proportion of traffic transmitted by different types of network protocols, traffic load, traffic change rate, and data transmission time;

[0214] The determination module 402 is configured to determine the attack impact degree and link reliability between the two network nodes according to the network characteristic data, where the attack impact degree represents the impact degree when the two network nodes are attacked, and the link reliability represents the degree of network fluctuation between the two network nodes;

[0215] The processing module 403 is configured to construct an objective function based on the attack impact degree, link reliability, traffic load, and data transmission time, where the objective function is used for a convex optimization model that minimizes network latency;

[0216] The calculation module 404 is configured to solve the objective function according to the network characteristic data between every two network nodes to obtain the abnormal probability that each network node link is an abnormal link

[0217] The defense module 405 is used to execute a distributed denial of service attack defense strategy based on each of the abnormal probabilities.

[0218] In an alternative embodiment, when constructing the objective function based on the attack impact degree, link reliability, traffic load, and data transmission time, the processing module 403 is specifically configured to construct the following objective function:

[0219]

[0220] And construct the following constraint conditions:

[0221]

[0222] Where, minf(x) represents the objective function;

[0223] λ1, λ2, λ3, λ4 represent correction factors, which are preset parameters;

[0224] D ij Represents the data transmission time;

[0225] L ij Represents the traffic load;

[0226] I attack Represents the attack impact degree;

[0227] S ij Represents the link reliability;

[0228] X ij Represents the abnormal probability;

[0229] T represents a preset probability threshold;

[0230] U min Represents the threshold of the number of links between two directly connected network nodes in the autonomous domain;

[0231] E represents the set of all network nodes in the autonomous domain.

[0232] In an alternative embodiment, when solving the objective function according to the network feature data between every two network nodes to obtain the abnormal probability that each network node link is an abnormal link, the calculation module 404 specifically uses the gradient descent algorithm to solve the optimal solution of the objective function:

[0233]

[0234] Where, k represents the number of iteration rounds;

[0235] η represents the iteration step size;

[0236] X ij(k+1) Denotes the anomaly probability that the network node link between the \(i\)-th network node and the \(j\)-th network node is an abnormal link when the iteration round is \(k + 1\);

[0237] X ij (k) Denotes the anomaly probability that the network node link between the \(i\)-th network node and the \(j\)-th network node is an abnormal link when the iteration round is \(k\);

[0238] Denotes the gradient norm when the iteration round is \(k\);

[0239] Denotes the gradient norm.

[0240] In an alternative embodiment, the calculation module 404 calculates the attack impact degree through the following formula:

[0241] I attack (i, j) = αI rate (i, j) + βI protocal (i, j)

[0242] Where

[0243]

[0244] I attack (i, j) denotes the attack impact degree; α denotes the weight parameter corresponding to I rate (i, j); β denotes the weight parameter corresponding to I protocal (i, j);

[0245] I rate (i, j) is used to determine whether a sudden anomaly occurs in the network node link between the \(i\)-th network node and the \(j\)-th network node;

[0246] I protocal (i, j) represents the proportion of common attack protocols in the network node link between the \(i\)-th network node and the \(j\)-th network node;

[0247] ΔR ij (t) represents the traffic change rate;

[0248] δ R Denotes the preset traffic change rate threshold;

[0249] P k,i,j (t) represents the proportion of traffic transmitted by different types of network protocols.

[0250] In an alternative embodiment, the calculation module 404 calculates the link reliability through the following formula:

[0251] S ij = 1 - |ΔR ij (t)|

[0252] Wherein, S ij represents the link reliability;

[0253] ΔR ij (t) represents the traffic change rate.

[0254] In an alternative embodiment, when executing the distributed denial of service attack defense strategy based on each anomaly probability, the defense module 405 is specifically configured to:

[0255] Compare each anomaly probability with a preset anomaly probability threshold, and filter out each target network node link corresponding to an anomaly probability greater than the anomaly probability threshold;

[0256] Execute a traffic isolation strategy for each target network node link.

[0257] Based on the same technical concept, an embodiment of the present application further provides an electronic device, which can implement the distributed denial of service attack defense method flow provided in the above embodiments of the present application. In one embodiment, the electronic device can be a server, or a terminal device or other electronic devices. Refer to Figure 5 as shown, the electronic device may include:

[0258] At least one processor 501, and a memory 502 connected to at least one processor 501. In the embodiments of the present application, the specific connection medium between the processor 501 and the memory 502 is not limited. Figure 5 In, it is taken as an example that the processor 501 and the memory 502 are connected through a bus 500. The bus 500 is Figure 5 shown by a thick line in, and the connection manners between other components are only for illustrative purposes and are not limited thereto. The bus 500 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 5 it is only shown by a thick line in, but it does not mean that there is only one bus or one type of bus. Alternatively, the processor 501 can also be called a controller, and the name is not limited.

[0259] In the embodiments of the present application, the memory 502 stores instructions executable by at least one processor 501. By executing the instructions stored in the memory 502, at least one processor 501 can execute a distributed denial of service attack defense method described above. The processor 501 can implement Figure 4 the functions of each module in the device shown in.

[0260] Among them, the processor 501 is the control center of the device. It can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 502 and calling the data stored in the memory 502, various functions of the device and data processing are performed, thereby monitoring the device as a whole.

[0261] In a possible design, the processor 501 may include one or more processing units. The processor 501 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 501 either. In some embodiments, the processor 501 and the memory 502 may be implemented on the same chip. In some embodiments, they may also be separately implemented on independent chips.

[0262] The processor 501 may be a general-purpose processor, such as a CPU, a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, which can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of a distributed denial of service attack defense method disclosed in combination with the embodiments of the present application can be directly embodied as being completed by a hardware processor, or being completed by a combination of hardware and software modules in the processor.

[0263] The memory 502, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 502 can include at least one type of storage medium. For example, it can include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disk, and so on. The memory 502 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 502 in the embodiments of the present application can also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.

[0264] By programming the processor 501, the code corresponding to the distributed denial of service attack defense method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute Figure 3 the steps of a distributed denial of service attack defense method of the illustrated embodiment. How to program the processor 501 is a well-known technology to those skilled in the art and will not be elaborated here.

[0265] Based on the same inventive concept, the embodiments of the present application also provide a storage medium storing computer instructions, which, when run on a computer, cause the computer to execute a distributed denial of service attack defense method discussed above.

[0266] In some possible implementation manners, the present application also provides that various aspects of a distributed denial of service attack defense method can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps of a distributed denial of service attack defense method according to various exemplary embodiments of the present application described above in this specification.

[0267] It should be noted that although several units or subunits of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0268] In addition, although the operations of the method of the present application are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.

[0269] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0270] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a server, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0271] Program code for performing the operations of the present application can be written using any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, executed as an independent software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0272] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are executed on the computer or other programmable apparatus to produce a computer-implemented process, thereby providing instructions for implementing the steps specified in one process or a plurality of processes and / or blocks Figure 1 in one block or a plurality of blocks Figure 1 the functions specified in one block or a plurality of blocks.

[0273] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.

Claims

1. A method for defending against distributed denial of service attacks, characterized in that, Applied to a network monitoring system, the network monitoring system includes monitoring devices and an autonomous domain composed of various network nodes, and the method includes: Obtain network feature data within a preset time period, where the network feature data at least includes: the traffic rate between two network nodes, the average traffic rate, the proportion of traffic transmitted using different types of network protocols, the traffic load, the traffic change rate, and the data transmission time; Determine the attack impact degree and the link reliability between the two network nodes according to the network feature data, where the attack impact degree represents the degree of impact when the two network nodes are attacked, and the link reliability represents the degree of network fluctuation between the two network nodes; Construct an objective function based on the attack impact degree, the link reliability, the traffic load, and the data transmission time, where the objective function is used for a convex optimization model that minimizes network latency; Solve the objective function according to the network feature data between every two network nodes to obtain the abnormal probability that each network node link is an abnormal link; Execute a distributed denial-of-service attack defense strategy based on each of the abnormal probabilities.

2. The method according to claim 1, wherein The constructing an objective function based on the attack impact degree, the link reliability, the traffic load, and the data transmission time includes: The objective function is as follows: And construct the following constraint conditions: Where minf(x) represents the objective function; λ1, λ2, λ3, λ4 represent correction factors, which are preset parameters; D ij represents the data transmission time; L ij represents the said traffic load; I attack indicates the degree of impact of the said attack; S ij indicates the reliability of the link; X ij represents the abnormal probability; T represents a preset probability threshold; U min represents the threshold of the number of links between two directly connected network nodes in the autonomous domain; E represents the set of all network nodes in the autonomous domain.

3. The method according to claim 1, characterized in that The solving the objective function according to the network feature data between every two network nodes to obtain the abnormal probability that each network node link is an abnormal link includes: Use the following gradient descent algorithm to solve the optimal solution of the objective function: Where k represents the number of iteration rounds; η represents the iteration step size; X ij (k+1) represents the abnormal probability that the network node link between the $i$-th network node and the $j$-th network node is an abnormal link when the iteration round is $k + 1$; X ij (k) represents the abnormal probability that the network node link between the i-th network node and the j-th network node is an abnormal link when the iteration round is k; Denote the gradient norm at the k-th iteration round; Indicates the gradient norm.

4. The method according to claim 1, characterized in that, The attack impact degree is calculated by the following formula: I attack (i, j) = αI rate (i, j) + βI protocal (i, j) Among them, I attack (i, j) represents the attack impact degree; α represents I rate (i, j) corresponding weight parameter; β represents I protocal (i, j) corresponding weight parameter; I rate (i, j) is used to determine whether a burst anomaly occurs in the network node link between the i-th network node and the j-th network node; I protocal (i, j) represents the proportion of common attack protocols in the network node link between the i-th network node and the j-th network node; ΔR ij (t) represents the flow rate change rate; δ R represents a preset flow rate change rate threshold value; P k,i,j (t) represents the proportion of traffic transmitted by different types of network protocols.

5. The method according to claim 1, wherein The link reliability can be calculated by the following formula: S ij = 1 - |ΔR ij (t)| Among them, S ij represents the reliability of the link; ΔR ij (t) represents the flow rate change rate mentioned above.

6. The method according to claim 1, characterized in that, The executing a distributed denial-of-service attack defense strategy based on each of the abnormal probabilities includes: Compare each of the abnormal probabilities with a preset abnormal probability threshold, and filter out each target network node link corresponding to the abnormal probability greater than the abnormal probability threshold; Execute a traffic isolation strategy on each of the target network node links.

7. A distributed denial of service attack defense device, characterized in that Applied to a network monitoring system, the network monitoring system includes monitoring devices and an autonomous domain composed of various network nodes, and the device includes: An acquisition module, configured to acquire network feature data within a preset time period, where the network feature data at least includes: the traffic rate between two network nodes, the average traffic rate, the proportion of traffic transmitted using different types of network protocols, the traffic load, the traffic change rate, and the data transmission time; A determination module, configured to determine the attack impact degree and the link reliability between the two network nodes according to the network feature data, where the attack impact degree represents the degree of impact when the two network nodes are attacked, and the link reliability represents the degree of network fluctuation between the two network nodes; A processing module, configured to construct an objective function based on the attack impact degree, the link reliability, the traffic load, and the data transmission time, where the objective function is used for a convex optimization model that minimizes network latency; A calculation module, configured to solve the objective function according to the network feature data between every two network nodes, and obtain the abnormal probability that each network node link is an abnormal link A defense module, configured to execute a distributed denial of service attack defense strategy based on each of the abnormal probabilities.

8. The device according to claim 7, characterized in that, When constructing the objective function based on the attack impact degree, the link reliability, the traffic load, and the data transmission time, the processing module is specifically configured to construct the following objective function: And construct the following constraint conditions: Where, minf(x) represents the objective function; λ1, λ2, λ3, and λ4 represent correction factors, which are preset parameters; D ij represents the data transmission time; L ij represents the said traffic load; I attack indicating the attack impact degree; S ij represents the reliability of the said link; X ij represents the abnormal probability; T represents a preset probability threshold; U min represents the threshold of the number of links between two directly connected network nodes in the autonomous domain; E represents the set of all network nodes in the autonomous domain.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method described in any one of claims 1-6 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the method described in any one of claims 1-6 is implemented.