Defense method based on edge computing DDoS attack
By building a two-layer game model, multi-stage dynamic interaction between attack and defense strategies in edge computing networks is achieved, and the problem of limited resources of edge nodes is solved, the response speed and resource utilization of edge networks are improved, local overload is avoided, and service quality is ensured.
Patent Information
- Application Number
- CN202510828156.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-06-20
AI Technical Summary
When facing DDoS attacks, edge computing networks have limited resources and traditional cloud computing defense methods cannot be directly applied, resulting in DDoS attacks that easily consume edge node resources. The existing defense solutions cannot meet real-time requirements, and the collaborative defense mechanism across edge nodes is incomplete.
A two-layer hybrid game model based on Stackelberg game main model and dynamic cooperative game sub-model is built. By allocating the initial rules of the attacker and the defender, a multi-stage dynamic interaction between attack solutions and defense solutions is achieved. The defender generates a traffic unloading strategy in real time, and uses dynamic priority rules to balance the cooperative node load and optimize traffic allocation.
It significantly improves the response speed and policy adaptability of edge networks in dynamic attack scenarios, improves resource utilization across the network, avoids local overload, and ensures stable service quality.
Smart Images

Figure CN120378218A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a defense method against DDoS attacks based on edge computing. Background Art
[0002] Edge computing significantly reduces service latency and improves real-time performance by sinking computing resources to edge nodes close to terminal devices. However, its distributed architecture and resource-constrained characteristics expose it to new security threats, especially edge distributed denial-of-service (DDoS) attacks. Such attacks coordinate a large number of Internet of Things (IoT) devices or botnets to exhaust the resources of edge servers with low-bandwidth but high-frequency legitimate requests, resulting in a decline in service quality or even service interruption.
[0003] DDoS defense in traditional cloud environments mainly relies on centralized resource redundancy, traffic cleaning centers, and rule-based black and white list mechanisms. However, these methods have significant drawbacks in the edge computing scenario: the physical size of edge servers is limited and they cannot scale resources massively like the cloud, redirecting traffic to the cloud for processing will violate the core goal of low latency in edge computing, and centralized defense is difficult to cover dispersed edge nodes, and dynamic attacks are difficult to detect in real time.
[0004] The problems of the prior art mainly involve two points: Firstly, existing dynamic defense schemes (such as resource competition models based on game theory) adjust resource allocation through optimization algorithms, but they have three limitations: when facing large-scale edge DDoS attacks, the collection and calculation of global information take too long to meet real-time requirements. Secondly, relying on a single control node is prone to single-point failures, and the cooperative defense mechanism across edge nodes is imperfect. Moreover, the dynamic defense resource allocation strategy based on machine learning will further exacerbate the resource tension of individual edge nodes.
[0005] The classical cooperative defense framework integrates multi-party resources, technologies, and strategies to establish a cross-organization and cross-domain security cooperation mechanism, realizing real-time monitoring, information sharing, and joint response to complex threats, thereby improving the overall defense efficiency. Cooperative defense relies on cross-ISP collaboration or pre-installed security devices, but in the edge scenario, it will face the lack of trust and incentive mechanisms. Edge nodes usually belong to a single operator and are not suitable for traditional cross-domain cooperation models. Heuristic algorithms lack theoretical performance guarantees, and frequent resource scheduling will introduce additional latency.
[0006] Therefore, there is an urgent need to develop a solution to solve the above problems. Summary of the Invention
[0007] The purpose of the present invention is to provide a defense method against DDoS attacks based on edge computing, which improves the problem that the resources of edge nodes are limited and the traditional cloud computing DDoS defense method cannot be directly applied to edge computing, resulting in the easy exhaustion of the resources of edge nodes by DDoS attacks.
[0008] A defense method against DDoS attacks based on edge computing provided by the present invention adopts the following technical solution: A defense method against DDoS attacks based on edge computing specifically includes the following steps: Set the attributes of edge nodes in the network environment; Initial attack and defense confrontation, the attacker obtains the initial attack rules, and the defender obtains the initial defense rules; Construct the first-layer Stackelberg game main model and define the utility functions of the attacker and the defender; Construct the second-layer dynamic cooperation game sub-model and define the participants, traffic types, and dynamic priority rules; Solve the initial defense solution of the dynamic cooperation game sub-model; Substitute the initial defense solution of the dynamic cooperation game sub-model into the Stackelberg game main model and reversely solve the attack solution of the Stackelberg game main model; Then substitute the attack solution of the Stackelberg game main model back into the dynamic cooperation game sub-model to obtain the defense solution of the dynamic cooperation model; Continuously and alternately update the attack solution and the defense solution. When the attack solution and the defense solution reach an equilibrium state, output the attack solution and the defense solution in the equilibrium state.
[0009] A defense method against DDoS attacks based on edge computing, based on the attributes of edge nodes in the network environment, allocates the initial attack rules for the attacker and the initial defense rules for the defender. Using the Stackelberg game main model and the dynamic cooperation game sub-model as the basis, a two-layer hybrid game model is constructed. Continuously and alternately update the attack solution and the defense solution, thereby achieving the multi-stage dynamic interaction between the attack solution and the defense solution. The defender generates a traffic offloading strategy in real time based on the attacker's strategy and adjusts the traffic allocation through iterative optimization, significantly improving the response speed and strategy adaptability of the edge network in dynamic attack scenarios. The dynamic priority rules are used to balance the load of cooperative nodes, ensuring the improvement of the overall network resource utilization rate and avoiding local overload.
[0010] Optionally, the setting of the attributes of edge nodes in the network environment is further expressed as: Define the edge network topology structure as an undirected graph G, where the undirected graph G contains the set N of edge host nodes in the network, the communication links E between nodes, and the weights , the weight is the number of hops between nodes, which is used for network topology modeling; Initialize the node attributes in the undirected graph G and configure the attack and defense parameters.
[0011] Optionally, in the initial attack and defense confrontation, the attacker obtains the initial attack rules, and the defender obtains the initial defense rules, which can be further expressed as: The attacker randomly selects a set of target nodes , and assigns initial attack parameters to each target node to generate initial attack rules; The defender, according to the node resource status and traffic load , adopts a dynamic priority allocation rule to allocate the overflow traffic according to the priority ratio and generates initial defense rules.
[0012] Optionally, when constructing the first-layer Stackelberg game master model, define the utility functions of the attacker and the defender, which can be further expressed as: Model the attack and defense confrontation. The attacker is the leader, aiming to maximize the overflow traffic revenue and minimize the attack cost; The defender is the follower, aiming to minimize the unprocessed overflow traffic and maximize the total processed traffic, and then construct the first-layer Stackelberg game master model; Define the utility function of the defender as , and define the utility function of the attacker as , and define the constraint conditions of the attacker's utility function .
[0013] Optionally, the constraint conditions for defining the attacker's utility function include that the sum of the attack traffic allocated to the nodes in the set is less than the total resources of the attacker; each allocated attack traffic should be greater than the sum of the remaining resources of the attacked node and the traffic assisted by the defense for forwarding.
[0014] Optionally, define the participants, traffic types, and dynamic priority rules, which can be further expressed as: Define the participants as the requesting node R and the collaborative node H, and define the traffic types as attack traffic, traffic, and overflow traffic; According to the multi-factor weighted correction mechanism, unify the real-time resource status, physical distance, and node capability elements of each node into the traffic allocation decision, and then define the dynamic priority rules; Based on load balancing, select the set of collaborative nodes and traffic allocation through policy constraints; Globally coordinate multi-node attacks.
[0015] Optionally, the policy constraint method includes a resource constraint condition and an overflow traffic integrity constraint condition; The resource constraint condition is that the traffic processed by the cooperation node is less than the remaining resources of the cooperation node itself; The overflow traffic integrity constraint condition is that the traffic allocated to all cooperation nodes is less than the total overflow traffic.
[0016] Optionally, the initial defense solution for solving the dynamic cooperative game sub-model is further expressed as: Use the greedy algorithm to perform greedy initialization on the set of cooperation nodes to generate an initial solution for traffic allocation; Combined with the mathematical programming method, use non-linear programming to adjust the traffic allocation through gradient information; Take the initial solution as the initial point, perform local optimization, and output the final initial defense solution.
[0017] Optionally, the reverse solution of the attack solution of the Stackelberg game main model includes building a solution framework for the Stackelberg game main model using backward induction; using genetic algorithms and integer programming algorithms for screening and optimization to obtain the attack solution of the Stackelberg game main model.
[0018] Optionally, the condition for the attack solution and the defense solution to reach an equilibrium state is that, based on the total resource constraint, the marginal attacker's attack benefit is equal to the marginal cost, and the defender ensures that the attacker cannot further reduce the defense utility through strategies.
[0019] The beneficial effects of the present invention are as follows: A defense method against DDoS attacks based on edge computing. Based on the attributes of edge nodes in the network environment, the initial attack rules of the attacker and the initial defense rules of the defender are allocated. Using the Stackelberg game main model and the dynamic cooperative game sub-model as the basis, a two-layer hybrid game model is constructed, and the attack solution and the defense solution are continuously updated alternately, thereby achieving multi-stage dynamic interaction between the attack solution and the defense solution. The defender generates a traffic offloading strategy in real time based on the attacker's strategy, and adjusts the traffic allocation through iterative optimization, significantly improving the response speed and strategy adaptability of the edge network in dynamic attack scenarios. The dynamic priority rule is used to balance the load of cooperation nodes, ensuring an increase in the utilization rate of the entire network's resources and avoiding local overload.
[0020] Through a double - layer hybrid game model, the present invention realizes multi - stage dynamic interaction between attack and defense strategies. The defender generates a traffic offloading scheme in real time based on the attacker's strategy, and adjusts resource allocation through iterative optimization, significantly improving the response speed and strategy adaptability of the edge network in dynamic attack scenarios. The dynamic priority allocation mechanism can preferentially allocate highly sensitive traffic to low - latency nodes and balance the loads of collaborative nodes. Combining traffic integrity constraints and resource upper - limit restrictions ensures an increase in the overall network resource utilization rate and avoids local overload.
[0021] The present invention uses a hybrid algorithm of greedy initialization and non - linear programming correction to quickly generate a feasible solution and then fine - tune the traffic allocation. This scheme approaches the global optimal solution within a millisecond - level response time, reduces the proportion of unprocessed overflow traffic, and strictly guarantees resource constraints and the priority of delay - sensitive tasks.
[0022] Based on the dynamic cooperative game among edge nodes, the present invention realizes decentralized traffic offloading and cross - node collaborative defense. Through the principle of proximity processing and the node - capacity matching mechanism, it reduces transmission latency, avoids the trust and scheduling costs of cross - domain collaboration, and at the same time improves the system's resistance to single - point failures. Strictly following traffic type marking and resource constraints, it preferentially allocates highly sensitive tasks to high - efficiency nodes, reducing the response latency of critical services. The traffic allocation strategy also ensures integrity, avoiding the problem of detection model failure caused by traffic splitting and ensuring stable service quality. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 is a schematic flow chart of the defense method for edge - computing - based DDoS attacks of the present invention; Figure 2 is a schematic flow chart of resource scheduling for both attackers and defenders in the defense method for edge - computing - based DDoS attacks of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meaning as understood by those of ordinary skill in the art to which the present invention pertains. The words such as "including" used herein mean that the elements or items appearing before this word cover the elements or items listed after this word and their equivalents, without excluding other elements or items.
[0025] As Figure 1As shown in the figure, a defense method against DDoS attacks based on edge computing specifically includes the following steps: S1. Set the attributes of edge nodes in the network environment; S2. Conduct initial attack and defense confrontation. The attacker obtains the initial attack rules, and the defender obtains the initial defense rules; S3. Construct the first-layer Stackelberg game main model and define the utility functions of the attacker and the defender; S4. Construct the second-layer dynamic cooperation game sub-model and define the participants, traffic types, and dynamic priority rules; S5. Solve the initial defense solution of the dynamic cooperation game sub-model; S6. Substitute the initial defense solution of the dynamic cooperation game sub-model into the Stackelberg game main model and reversely solve the attack solution of the Stackelberg game main model; S7. Then substitute the attack solution of the Stackelberg game main model back into the dynamic cooperation game sub-model to obtain the defense solution of the dynamic cooperation model; S8. Continuously and alternately update the attack solution and the defense solution. When the attack solution and the defense solution reach an equilibrium state, output the attack solution and the defense solution in the equilibrium state.
[0026] A defense method against DDoS attacks based on edge computing, based on the attributes of edge nodes in the network environment, allocates the initial attack rules for the attacker and the initial defense rules for the defender. With the Stackelberg game main model and the dynamic cooperation game sub-model as the basis, a two-layer hybrid game model is constructed. The attack solution and the defense solution are continuously and alternately updated, thereby achieving the multi-stage dynamic interaction between the attack solution and the defense solution. The defender generates a traffic offloading strategy in real time based on the attacker's strategy and adjusts the traffic allocation through iterative optimization, significantly improving the response speed and strategy adaptability of the edge network in dynamic attack scenarios. The dynamic priority rules are used to balance the load of cooperative nodes, ensuring the improvement of the overall network resource utilization rate and avoiding local overload.
[0027] Specifically, in some embodiments, the setting of the attributes of edge nodes in the network environment in step S1 is further expressed as: Define the edge network topology as an undirected graph G, which includes the set N of edge host nodes in the network, the communication links E between nodes, and the weights , and the weight is the number of hops between nodes for network topology modeling; Initialize the node attributes in the undirected graph G and configure the attack and defense parameters.
[0028] Further, through network topology modeling, it is used to define the edge network topology structure as an undirected graph G. The undirected graph G = (N, E). At the same time, the node attributes in the undirected graph G are initialized by defining parameters for each node i ∈ N. The defined parameters include the total computing resources of the node and the remaining resources initialized and dynamically updated as , the node capability weight and the traffic type label . Among them, the attack parameters are: the attack intensity , the attack cost coefficient (the unit cost of the attack traffic and the fixed cost of the attack node ), the attack resource upper limit . The defender parameters: the dynamic pricing coefficient , the resource consumption cost , the delay penalty coefficient γ.
[0029] Specifically, in some embodiments, in the initial attack and defense confrontation in step S2, the attacker obtains the initial attack rule, and the defender obtains the initial defense rule, which is further expressed as: The attacker randomly selects a target node set , and assigns initial attack parameters to each target node to generate an initial attack rule; The defender adopts a dynamic priority allocation rule according to the node resource status and the traffic load , and allocates the overflow traffic according to the priority ratio to generate an initial defense rule.
[0030] Further, step S2 may specifically include: S2.1. Generate the attacker's initial attack rule. The attacker randomly selects a target node set ∈ N, and assigns the attack intensity , the attack strategy .
[0031] S2.2. Generate the defender's initial defense rule. The defender triggers a dynamic priority allocation rule according to the resource status of the remaining idle nodes j other than the attack node i and the traffic load . The specific formula of the dynamic priority allocation rule is: , Furthermore, obtain the strategy for allocating the overflow traffic according to the priority ratio. The specific formula for allocating the overflow traffic is: , The above-obtained strategy for allocating the overflow traffic is also the defense strategy adopted by the defender.
[0032] Specifically, in some embodiments, in step S3, the first-layer Stackelberg game master model is constructed, and the utility functions of the attacker and the defender are defined, which are further expressed as: Model the attack and defense confrontation. The attacker is the leader, aiming to maximize the overflow traffic revenue and minimize the attack cost; The defender is the follower, aiming to minimize the unprocessed overflow traffic and maximize the total processed traffic, and then construct the first-layer Stackelberg game master model; Define the utility function of the defender as , and define the utility function of the attacker as , and define the constraint conditions of the attacker's utility function .
[0033] Furthermore, in some embodiments, as Figure 2 shown, step S3 can be expressed as constructing the first-layer Stackelberg game master model, defining the utility functions, constraint conditions and strategy spaces of the attacker and the defender, specifically including: S3.1. Model the attack and defense confrontation. Take the attacker as the leader, and select the set of attack target nodes and the attack intensity , to maximize the overflow traffic revenue and minimize the attack cost. The defender is the follower. When the current load of the node is greater than a certain security threshold (such as 80% of the total node resources), the second-layer cooperative game is triggered to allocate traffic, minimizing the unprocessed overflow traffic.
[0034] S3.2. Construct the defender model. The goal of the defender is to maximize the total processed traffic, minimize the response delay and solve the problem of load imbalance. By collaborating to avoid purchasing new resources, the entire edge network saves resource costs. Then the utility function of the defender can be defined as: , where the revenue term is: , where is a dynamic pricing coefficient, , k represents the resource tension sensitivity coefficient, represents the network-wide resource utilization rate. When the network-wide resource utilization rate is tight, the higher the weight of collaboration, that is, the higher the value of the node to assist in processing the overflow traffic at this time. represents the new resources that need to be purchased to process the overflow traffic. represents the strategy space, that is, the traffic forwarded from the overloaded node i to the collaborative node j.
[0035] Meanwhile, the resource consumption cost is: , where represents the remaining resources of the node, and the marginal cost of processing traffic increases as decreases. represents the marginal cost consumed when processing traffic, and is inversely proportional to the remaining resources of the node.
[0036] The delay penalty is: , The delay penalty represents the impact of the delay caused by forwarding traffic on the quality of service.
[0037] S3.3. Build an attacker model. The attacker consumes the resources of the target node, causing the legal traffic to overflow, thereby increasing the user response delay, while minimizing the attack cost. For the attacker, the attack strategy is to consider which edge nodes to attack, which can be one or more. However, no matter which scheme, if the attack effect is good, then the overflow traffic in these attacked nodes is mainly legal traffic, while more attack traffic is processed locally at the current attack node, occupying more node resources. Therefore, if there is a particularly large amount of legal traffic overflow, then the user's response delay is long, which can reflect the actual damage effect of the attack.
[0038] Design a delay loss to measure the attack benefit of the attacker, and calculate the net benefit of an attack strategy by subtracting the attack cost. This consideration is reasonable in the edge computing scenario because there are many services in edge services that are extremely sensitive to delay, such as some real-time critical services like autonomous driving and industrial control. The actual destructiveness of the attack can be reflected by increasing . The attacker's benefit mainly comes from the legal traffic that the attacked host fails to process, that is, the overflow legal traffic, which makes the user's response delay longer. Furthermore, the attacker's utility function can be defined as: , The attacker's utility function represents the reward obtained by the attacker when attacking the target node set selecting attack nodes and the attack intensity is . Among them, represents the penalty coefficient for the user delay caused by unit overflow legal traffic, represents the attack intensity of the attacker on node i, and its unit cost is , represents the number of attacked nodes, and the fixed cost of attacking each single node is , Represents the coordination cost of the attack. This cost is considered because when attacking a single node, the fixed costs may include one-time expenses such as target detection and deployment of attack tools, which do not vary with the attack traffic. Even if the intensity of the attack traffic is low, these costs still exist.
[0039] Moreover, based on this, the situation of attacking multiple edge nodes simultaneously can be considered. Then, the formula for the overflow traffic existing in node i that is not processed by the node itself and the defense strategy is obtained as: , Where, is the remaining resource of node i, that is, the remaining ability to process traffic at this time. is the overflow traffic existing in node i that is not processed by the node itself and the defense strategy, and is also equal to the attack traffic minus the traffic that can be processed by the node itself at this time and the traffic processed by the collaborative nodes .
[0040] Specifically, in some embodiments, the constraints for defining the attacker's utility function include that the sum of the attack traffic allocated to the nodes within the set is less than the total resources of the attacker; each allocated attack traffic should be greater than the sum of the remaining resources of the attacked node and the traffic assisted by the defense for forwarding.
[0041] Resource limitation constraint. For a given attack set, the nodes within this set also need to meet the constraint that the total attack resources are limited, represents the total resources of the attacker, that is: , Minimum attack traffic value constraint. Each allocated attack traffic should be greater than the sum of the remaining resources of the attacked node and the traffic that the defense can assist in forwarding. Otherwise, such a traffic allocation is an invalid allocation and cannot cause the node to generate overflow traffic, that is: , Through this constraint condition, it can be ensured that the attack will cause the node to generate overflow traffic .
[0042] Specifically, in some embodiments, the definition of the participants, traffic types, and dynamic priority rules in step S4 is further expressed as: Define the participants as the request node R and the collaborative node H, and define the traffic types as attack traffic, normal traffic, and overflow traffic; According to the multi-factor weighted correction mechanism, the real-time resource status, physical distance, and node ability factors of each node are unified into the traffic allocation decision, and then the dynamic priority rules are defined; Based on load balancing, the set of collaborative nodes and traffic distribution are selected through policy constraints; Globally coordinate multi-node attacks.
[0043] Furthermore, in some embodiments, Figure 2 As shown, step S4 can be expressed as: S4.1. Participants and traffic classification. In the edge network, when one or more nodes are short of resources due to DDoS attacks or traffic overload, the goals of traffic unloading, load balancing, and cost optimization are achieved through dynamic cooperative games. The participants in dynamic cooperation are divided into requesting nodes R (R N), indicating the attacked node with insufficient resources and needs to forward overflow traffic; the collaborative node H (H N\R), indicating nodes that are not attacked and meet resource and distance constraints, and can assist in processing traffic.
[0044] S4.2, build the basic idea framework of the game. Forwarding overflow traffic, but the total resources remain unchanged in this process, so the defense strategy can only forward as much overflow traffic as possible for processing. Therefore, when allocating traffic, three main points should be considered: real-time resource status. Only when the node has sufficient resources can it assist in defense. Letting nodes with fewer resources assist in defense will only put these nodes at risk of being attacked, and it is also to consider the balance of distribution. Physical distance considers the distance between the allocation node and the attacked node, from the number of hops. Obviously, the farther the node is, the lower the priority it is assigned, because the response delay is too long. Node capability, because the hardware equipment of each node is different, for example, some complex calculations can be accelerated by hardware, and these complex traffic can be responded to quickly. Because some complex traffic may be tasks with high delay sensitivity, such as unmanned driving traffic. Therefore, the stronger the capability, the priority should be given to processing these complex traffic. In fact, this is also a disguised consideration of the heterogeneity of nodes. Prioritize allocating high-load traffic to nodes with higher processing efficiency (such as GPU servers) to reduce resource consumption and delay.
[0045] S4.3, dynamic priority rules. Combined with the analysis of the above steps, in order to ensure the load balance of nodes during the allocation process, the dynamic priority rules for allocation are constructed based on the idea of Shapely value. The core is to unify the real-time resource status, physical distance and node capability elements of each node into the traffic allocation decision through multi-factor weighted correction. By dynamically adjusting the weight factor, the model can meet the requirements of efficiency, load balancing and real-time performance at the same time. The dynamic priority formula is: , The allocation rules are: , in, Represents the resource weight. The more remaining resources there are, the higher the allocated weight. Represents the distance weight, punishing nodes with a greater distance to reduce latency. Represents the capacity weight, measuring the supply capacity of node j. According to the above priorities, the defender can dynamically select nodes with higher priorities in real time. Once the cooperative nodes are selected, the defender also needs to design a reasonable traffic allocation mechanism to ensure that the load of each node does not exceed its processing capacity. At the same time, to avoid over-reliance on a few key nodes, try to ensure the load balance of cooperative nodes in the allocation of overflow traffic.
[0046] S4.4. Global coordination of multi-node attacks. If the resources of the cooperative nodes are insufficient, node conflicts need to be resolved, mainly allocated in the following order: to ensure the real-time performance of critical tasks, give priority to processing traffic with higher complexity; to reduce transmission latency, give priority to allocating traffic to cooperative nodes that are closer; to avoid node overload, give priority to allocating traffic to cooperative nodes with more abundant resources.
[0047] Furthermore, in some embodiments, the policy constraint method includes a resource constraint condition and an overflow traffic integrity constraint condition; The resource constraint condition is that the traffic processed by the cooperative node is less than the remaining resources of the cooperative node itself; The overflow traffic integrity constraint condition is that the traffic allocated to all cooperative nodes for processing is less than the total overflow traffic.
[0048] Specifically, the resource constraint condition is that the traffic processed by the cooperative node does not exceed its remaining resources. Since node j may receive traffic from multiple attacking nodes, the total consumed resources for processing them cannot exceed the remaining resources of the node itself at this time.
[0049] , The overflow traffic integrity constraint condition is that the overflow traffic needs to be allocated as much as possible, but it does not mean that all can be fully forwarded (especially when the resources in the entire network are insufficient). That is, the traffic allocated to all j nodes for processing cannot exceed the total overflow traffic 。
[0050] , Specifically, in some embodiments, the initial defense solution for solving the dynamic cooperative game sub-model in step S5 is further expressed as: Greedy initialize the set of cooperative nodes through the greedy algorithm to generate an initial solution for traffic allocation; Combined with the mathematical programming method, use nonlinear programming to adjust the traffic allocation through gradient information; Take the initial solution as the initial point, perform local optimization, and output the final initial defense solution.
[0051] Further, step S5 can be expressed as: S5.1. Greedy initialization. The attacked nodes cannot be used as cooperative nodes. Therefore, in the entire edge network, there are two types: one is the set of attacked nodes, and the other is the set of cooperative nodes. First, calculate the node priority in real time and allocate traffic according to the priority. Immediately update the remaining resources of the nodes after allocation to avoid overlimit. If the resources are insufficient, mark the unprocessed traffic and give an alarm. Allocate the overflow traffic to the cooperative nodes according to the priority ratio: , The purpose is to quickly generate an initial solution that satisfies the traffic integrity constraint, but the resource utilization and utility may not be fully optimized.
[0052] S5.2. Nonlinear programming correction. The role of mathematical correction is to adjust the traffic allocation through gradient information, direct more traffic to nodes with higher marginal utility, and improve the overall utility. Use the greedy solution as the initial point to construct a local optimization problem: , Use gradient ascent to quickly solve the fine-tuning amount , approaching the global optimal solution.
[0053] S5.3. Output the final initial defense solution, where .
[0054] Specifically, in some embodiments, the reverse solution of the attack solution of the Stackelberg game main model in step S6 includes: building a solution framework for the Stackelberg game main model using backward induction; using a genetic algorithm and an integer programming algorithm for screening and optimization to obtain the attack solution of the Stackelberg game main model.
[0055] Further, step S6 can be expressed as: S6.1. Backward induction framework. Based on the characteristics of the Stackelberg game, first solve the optimal response function of the defender, and then embed it into the optimization problem of the attacker. The optimal traffic allocation of the defender is obtained in the previous step, and the overflow traffic is obtained. The attacker selects and and to maximize its own utility , satisfying the total attack resource constraint.
[0056] S6.2. Mixed integer programming and heuristic algorithm. Since the attacked nodes The selection is a combinatorial optimization problem that requires combining integer programming and continuous optimization with a phased hybrid strategy.
[0057] S6.3. Attack node selection phase. Use a genetic algorithm to screen for high-value attack nodes, and use binary coding to represent whether a node is attacked. Calculate the net attack benefit through the overflow traffic Calculate the net attack benefit . The constraint handling for the attack is to use a penalty function to limit the total attack resources .
[0058] S6.4. Attack intensity allocation phase. For the selected , use convex optimization (such as gradient descent) to allocate the attack intensity to maximize . By initializing the attack strategy in the first stage (randomly or based on historical data), it will trigger the defender's response: trigger the greedy + mathematical correction algorithm to allocate traffic (defense strategy), and calculate . In this regard, the attacker needs to update: if the node selection is fixed, use the gradient method to optimize ; if adjustment is needed , trigger the genetic algorithm to re-select the attack nodes. Repeat until convergence or the maximum number of iterations is reached.
[0059] S6.5. Iterative alternating optimization. Approximate the equilibrium by alternately updating the strategies of the attacker and the defender. First, initialize the attack strategy and . In the second step, the defender solves and calculates . In the third step, the attacker fixes , and through optimization and adjustment and , if the total attack cost exceeds the benefit, reduce the number of attack nodes or the intensity; if the defender's coverage rate is high, preferentially attack the hub nodes or increase the proportion of high-complexity traffic. Repeat the second and third steps, and the attacker and the defender update their strategies at fixed time slots T until and converge.
[0060] Specifically, in some embodiments, the condition for the attack solution and the defense solution in step S8 to reach an equilibrium state is that, based on the total resource constraint, the marginal attacker's attack benefit is equal to the marginal cost, and the defender ensures that the attacker cannot further reduce the defense utility through the strategy.
[0061] Furthermore, step S8 can also be expressed as: the equilibrium state output of both the attacker and the defender makes the marginal attack benefit of the attacker equal to the marginal cost, and the defender ensures that the attacker cannot further reduce the defense utility by adjusting the strategy.
[0062] Specifically, step S8 may include: S8.1. Output of the balanced state between the attacker and the defender. In the Stackelberg game, the defender and the attacker continuously adjust their strategies. When both sides reach their respective optimal strategies, the optimal strategies of the attacker and the defender correspond to the Nash equilibrium. At this equilibrium point: Under the total resource constraint, the marginal attack benefit is equal to the marginal cost. The defender dynamically and preferentially allocates resources so that the attacker cannot further reduce the attack utility by adjusting its strategy. In this case, the defense system reaches a stable equilibrium state - the Nash equilibrium. The equilibrium solution satisfies , and at the same time, the set of attack nodes maximizes the overflow traffic of the defender. Maximize.
[0063] S8.2. Execution of the optimal strategy. According to the obtained optimal defense resource allocation strategy, the defender reasonably allocates the forwarding traffic and guides the edge network to reasonably process the attack traffic, and can achieve the best defense effect with the minimum resource consumption, communication delay, and economic cost of collaborative allocation.
[0064] A defense method against DDoS attacks based on edge computing. Based on the attributes of edge nodes in the network environment, the initial attack rules of the attacker and the initial defense rules of the defender are allocated. Using the Stackelberg game main model and the dynamic cooperation game sub-model as the basis, a two-layer hybrid game model is constructed, and the attack solution and the defense solution are continuously and alternately updated, thereby achieving the multi-stage dynamic interaction between the attack solution and the defense solution. The defender generates a traffic offloading strategy in real time based on the attacker's strategy, and adjusts the traffic allocation through iterative optimization, significantly improving the response speed and strategy adaptability of the edge network in dynamic attack scenarios. The dynamic priority rule is used to balance the load of collaborative nodes, ensuring the improvement of the overall network resource utilization rate and avoiding local overload.
[0065] The present invention realizes the multi-stage dynamic interaction between attack and defense strategies through a two-layer hybrid game model. The defender generates a traffic offloading plan in real time based on the attacker's strategy, and adjusts the resource allocation through iterative optimization, significantly improving the response speed and strategy adaptability of the edge network in dynamic attack scenarios. The dynamic priority allocation mechanism can preferentially allocate high-sensitive traffic to low-latency nodes and balance the load of collaborative nodes. Combining the traffic integrity constraint and the resource upper limit limit, it ensures the improvement of the overall network resource utilization rate and avoids local overload.
[0066] The present invention uses a hybrid algorithm of greedy initialization and nonlinear programming correction to quickly generate a feasible solution and then fine-tune the traffic allocation. This solution approaches the global optimal solution within a millisecond-level response time, reduces the proportion of unprocessed overflow traffic, and strictly guarantees the resource constraints and the priorities of delay-sensitive tasks.
[0067] Based on the dynamic cooperative game among edge nodes, the present invention realizes decentralized traffic offloading and cross-node collaborative defense. By following the principle of proximity processing and the node capacity matching mechanism, transmission delay is reduced, the trust and scheduling costs of cross-domain collaboration are avoided, and at the same time, the system's anti-single point of failure ability is improved. Strictly following the traffic type marking and resource constraints, high-sensitive tasks are preferentially allocated to high-efficiency nodes to reduce the response delay of critical services. The traffic allocation strategy synchronously ensures integrity, avoids the problem of detection model failure caused by traffic splitting, and ensures stable service quality.
[0068] Although the embodiments of the present invention have been described in detail above, it is obvious to those skilled in the art that various modifications and changes can be made to these embodiments. However, it should be understood that such modifications and changes are all within the scope and spirit of the present invention described in the claims. Moreover, the present invention described herein can have other embodiments and can be implemented or realized in various ways.
Claims
1. A defense method against DDoS attacks based on edge computing, characterized in that, Including: Setting the attributes of edge nodes in the network environment; Initial attack and defense confrontation, where the attacker obtains the initial attack rules and the defender obtains the initial defense rules; Constructing the first-layer Stackelberg game main model and defining the utility functions of the attacker and the defender; Constructing the second-layer dynamic cooperation game sub-model and defining the participants, traffic types, and dynamic priority rules; Solving the initial defense solution of the dynamic cooperation game sub-model; Substituting the initial defense solution of the dynamic cooperation game sub-model into the Stackelberg game main model and inversely solving the attack solution of the Stackelberg game main model; Then substituting the attack solution of the Stackelberg game main model back into the dynamic cooperation game sub-model to obtain the defense solution of the dynamic cooperation model; Continuously and alternately updating the attack solution and the defense solution, and when the attack solution and the defense solution reach an equilibrium state, outputting the attack solution and the defense solution in the equilibrium state.
2. A defense method against DDoS attacks based on edge computing according to claim 1, characterized in that, The setting of the attributes of edge nodes in the network environment is further expressed as: Define the edge network topology as an undirected graph G, which contains the set N of edge host nodes in the network, the communication links E between nodes, and weights , where the weights are the number of hops between nodes, used for network topology modeling; Initializing the node attributes in the undirected graph G and configuring the attack and defense parameters.
3. A defense method against DDoS attacks based on edge computing according to claim 1, characterized in that, The initial attack and defense confrontation, where the attacker obtains the initial attack rules and the defender obtains the initial defense rules, is further expressed as: The attacker randomly selects a set of target nodes and assigns initial attack parameters to each target node to generate initial attack rules; The defender, based on the node resource status and traffic load , adopts a dynamic priority allocation rule to allocate overflow traffic according to the priority ratio and generate an initial defense rule.
4. A defense method against DDoS attacks based on edge computing according to claim 1, characterized in that, The constructing of the first-layer Stackelberg game main model and defining the utility functions of the attacker and the defender is further expressed as: Modeling the attack and defense confrontation, with the attacker as the leader, aiming to maximize the overflow traffic revenue and minimize the attack cost; The defender as the follower, aiming to minimize the unprocessed overflow traffic and maximize the total processed traffic, and then constructing the first-layer Stackelberg game main model; Define the utility function of the defender as , and define the utility function of the attacker as , and define the constraint conditions of the attacker's utility function .
5. A defense method against DDoS attacks based on edge computing according to claim 4, characterized in that, The defined attacker utility function has the following constraints: the sum of the attack traffic allocated to the nodes within the set is less than the total resources of the attacker; each allocated attack traffic should be greater than the sum of the remaining resources of the attacked node and the traffic forwarded with defense assistance.
6. A defense method against DDoS attacks based on edge computing according to claim 1, characterized in that, The defining of the participants, traffic types, and dynamic priority rules is further expressed as: Defining the participants as the request node R and the cooperation node H, and defining the traffic types as attack traffic, normal traffic, and overflow traffic; According to the multi-factor weighted correction mechanism, unifying each node's real-time resource status, physical distance, and node capability elements into the traffic allocation decision, and then defining the dynamic priority rules; Based on load balancing, through the policy constraint method, selecting the cooperation node set and traffic allocation; Globally coordinating multi-node attacks.
7. A defense method against DDoS attacks based on edge computing according to claim 6, characterized in that, The policy constraint method includes resource constraint conditions and overflow traffic integrity constraint conditions; The resource constraint condition is that the traffic processed by the cooperation node is less than the remaining resources of the cooperation node itself; The overflow traffic integrity constraint condition is that the traffic allocated to all cooperation nodes for processing is less than the total overflow traffic.
8. A defense method against DDoS attacks based on edge computing according to claim 1, characterized in that The solving of the initial defense solution of the dynamic cooperation game sub-model is further expressed as: Greedy initializing the set of cooperation nodes through the greedy algorithm to generate the initial solution of traffic allocation; Combining the mathematical programming method, using nonlinear programming to adjust the traffic allocation through gradient information; Taking the initial solution as the initial point for local optimization and outputting the final initial defense solution.
9. A defense method against DDoS attacks based on edge computing according to claim 1, characterized in that The attack solution for reverse-solving the Stackelberg game master model includes building a solution framework for the Stackelberg game master model using backward induction; using a genetic algorithm and an integer programming algorithm for screening and optimization to obtain the attack solution for the Stackelberg game master model.
10. A defense method against DDoS attacks based on edge computing according to claim 1, characterized in that, The condition for the attack solution and the defense solution to reach an equilibrium state is that, under the total resource constraint, the marginal attacker's attack benefit equals the marginal cost, and the defender ensures that the attacker cannot further reduce the defense utility through strategies.
Citation Information
Patent Citations
Dynamic game method and device oriented to internet of things threat-defense resource allocation
CN109639729A
Edge intelligent moving target defense method based on Bayes-Stackelberg game
CN112115469A
Network game solving method based on greedy algorithm
CN119544523A
Method of optimizing coupling of computation offloading and resource allocation in mobile edge computing network based on hierarchical game
JP2025029581A