Virtual private cloud scanning behavior identification method, apparatus and device, and medium

By building scan records for ARP broadcast requests and updating the self-learning flow table, identifying the scanning behavior and its source in the virtual private cloud, it solves the network performance degradation and security threats caused by ARP broadcast flooding, and achieves efficient and accurate scanning behavior identification and protection.

CN120455056APending Publication Date: 2025-08-08CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510539421.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

In virtual private cloud (VPC) environments, ARP broadcast flooding causes network performance degradation and security threats, and prior art is difficult to effectively identify scanning behavior.

Method used

By constructing scan records for each ARP broadcast request, updating the self-learning flow table, determining whether a response message has been received, continuously updating unresponsive scan records, analyzing scan records to identify scan behavior and its source.

Benefits of technology

It realizes accurate tracking and identification of ARP broadcast requests, ensures the security and stability of the virtual private cloud, and protects the network through ban or speed limit measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455056A_ABST
    Figure CN120455056A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network communication, and discloses a scanning behavior identification method, device and equipment for a virtual private cloud and a medium, and the method comprises the steps: responding to a received ARP broadcast request, and constructing a scanning record based on the ARP broadcast request; updating a self-learning flow table based on the scanning record of the ARP broadcast request; judging whether a response message of the ARP broadcast request is received or not; under the condition that the response message is not received, responding to the continuously received ARP broadcast request, and updating a scanning record of the ARP broadcast request in the self-learning flow table; based on each scan record in the self-learning flow table, a scan behavior and a scan source thereof are identified. According to the method, the scanning record is constructed for the ARP broadcast request, the self-learning flow table is updated based on the scanning record, so that the flow table dynamically records and updates the broadcast condition in the network, the scanning behavior is efficiently and accurately identified by analyzing the scanning record in the flow table, and the security and stability of the virtual private cloud are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network communication technology, and in particular to a scanning behavior recognition method, device, equipment and medium for a virtual private cloud. Background Art

[0002] With the rapid development of cloud computing technology, Virtual Private Clouds (VPCs) within cloud networks have been widely adopted in various digital scenarios due to their security and customization. However, in the actual operation of VPCs, scanning behavior has gradually become a critical issue that seriously threatens network performance and security.

[0003] Scanning is essentially a malicious probing technique. Attackers attempt to detect existing devices, services, and potential vulnerabilities in the network by sending specific network packets, thereby preparing for subsequent attacks. In a VPC environment, some malicious attackers continuously send large numbers of ARP (Address Resolution Protocol) broadcast requests containing nonexistent target Internet Protocol (IP) addresses, causing explosive growth in ARP broadcast traffic and leading to ARP broadcast flooding.

[0004] ARP broadcast flooding not only causes OVS (Open vSwitch) bridges to stall or even crash due to processing a large number of invalid broadcast requests, resulting in packet loss, but also significantly consumes network bandwidth resources, significantly disrupting normal network communications within the VPC. In severe cases, it can affect the stability of the entire VPC network, impacting the reliability of cloud services and user experience. Therefore, identifying scanning behavior within the VPC is an urgent problem that needs to be solved. Summary of the Invention

[0005] In view of this, the present invention provides a method, apparatus, device and medium for identifying scanning behavior in a virtual private cloud (VPC) to solve the problem of identifying scanning behavior within a VPC.

[0006] In a first aspect, the present invention provides a method for identifying scanning behavior of a virtual private cloud, the method comprising:

[0007] In response to each received ARP broadcast request, construct a scan record of the ARP broadcast request based on the ARP broadcast request;

[0008] Update the self-learning flow table based on the scan records of ARP broadcast requests;

[0009] Determine whether a response message to the ARP broadcast request is received;

[0010] In the case where no response message to the ARP broadcast request is received, in response to the continuously received ARP broadcast request, updating the scanning record of the ARP broadcast request in the self-learning flow table;

[0011] Based on the scanning record of each ARP broadcast request in the self-learning flow table, the scanning behavior and its scanning source are identified.

[0012] The present invention realizes accurate tracking of ARP broadcast requests by constructing a scan record for each ARP broadcast request, and updates the self-learning flow table through the scan record, so that the self-learning flow table can dynamically record and update the ARP broadcast situation in the network, and checks whether the response message corresponding to the ARP broadcast request is received. For the ARP broadcast request that does not receive a response message, the present invention continues to receive the ARP broadcast request and continuously updates its scan record. By analyzing the scan records in the self-learning flow table, the scanning behavior and its scan source can be efficiently and accurately identified, thereby ensuring the security and stability of the virtual private cloud.

[0013] In an optional embodiment, in response to each received ARP broadcast request, a scan record of the ARP broadcast request is constructed based on the ARP broadcast request, including:

[0014] In response to each received ARP broadcast request, parse the ARP broadcast request to obtain the broadcast source address and the broadcast destination address;

[0015] Get the preset aging time and broadcast duration of ARP broadcast requests;

[0016] Determine the remaining aging time of the ARP broadcast request based on the preset aging time and the broadcast duration;

[0017] The broadcast source address, broadcast target address, preset aging time, remaining aging time, and broadcast duration of the ARP broadcast request are used as a scan record of the ARP broadcast request.

[0018] The present invention parses ARP broadcast requests and obtains the broadcast source address and target address, thereby clarifying the initiator and receiver of each ARP broadcast request, thereby accurately tracking its behavior, and at the same time obtaining the preset aging time, remaining aging time and broadcast duration of the ARP broadcast request, comprehensively and in detail recording the situation of the ARP broadcast request, and providing rich data support for subsequent scanning behavior identification.

[0019] In an optional implementation, updating the self-learning flow table based on the scan record of the ARP broadcast request includes:

[0020] If there is no scan record of the ARP broadcast request in the self-learning flow table, the scan record is stored in the self-learning flow table; or,

[0021] When there is a scan record of the ARP broadcast request in the self-learning flow table, the scan record of the ARP broadcast request in the self-learning flow table is updated.

[0022] The present invention stores the scan record of the current ARP broadcast request when there is no scan record in the self-learning flow table, and updates it when there is a scan record, thereby ensuring that the self-learning flow table can reflect the ARP broadcast situation in the network in real time.

[0023] In an optional implementation, updating the scan record of the ARP broadcast request in the self-learning flow table includes:

[0024] Reset the remaining aging time in the scan record to the preset aging time;

[0025] The time difference between the time when the ARP broadcast request is first sent and the current time is used as the broadcast duration in the scan record.

[0026] The present invention ensures that the scan record regains its valid life cycle in the flow table by resetting the remaining aging time in the scan record to the preset aging time, and by updating the broadcast duration of the ARP broadcast request, it can more accurately measure the existence time of the ARP broadcast request in the network, which helps to identify long-lasting broadcast requests.

[0027] In an optional implementation, after determining whether a response message to the ARP broadcast request is received, the method further includes:

[0028] When a response message to the ARP broadcast request is received, the scan record of the ARP broadcast request in the self-learning flow table is aged.

[0029] The present invention ensures that only scan records of incomplete or potentially abnormal ARP broadcast requests are retained in the self-learning flow table through an aging mechanism, so that more attention can be paid to monitoring and analyzing possible scanning behaviors, thereby improving recognition accuracy and efficiency.

[0030] In an optional embodiment, identifying the scanning behavior and its scanning source based on the scanning record of each ARP broadcast request in the self-learning flow table includes:

[0031] For each scanning record of ARP broadcast request in the self-learning flow table, when the broadcast duration in the scanning record is greater than the preset aging time, the ARP broadcast request corresponding to the scanning record is identified as a scanning behavior, and the broadcast source address in the scanning record is identified as the scanning source of the scanning behavior.

[0032] The present invention realizes accurate identification of scanning behavior by identifying it as scanning behavior and marking the broadcast source address as scanning source when the broadcast duration in the scanning record exceeds the preset aging time, indicating that the ARP broadcast request has existed in the network for too long and may have abnormal behavior.

[0033] In an optional embodiment, the method further includes:

[0034] For each scanning source of a scanning behavior, a blocking flow table or a rate-limiting flow table is sent to the scanning source.

[0035] The present invention can effectively prevent scanning behavior by taking timely blocking or speed limiting measures on the scanning source to protect the security of the virtual private cloud network.

[0036] In a second aspect, the present invention provides a scanning behavior recognition device for a virtual private cloud, the device comprising:

[0037] A construction module, configured to construct a scan record of the ARP broadcast request based on the ARP broadcast request in response to each received ARP broadcast request;

[0038] A first updating module is used to update the self-learning flow table based on the scanning record of the ARP broadcast request;

[0039] A judgment module is used to judge whether a response message of an ARP broadcast request is received;

[0040] A second updating module is configured to update the scanning record of the ARP broadcast request in the self-learning flow table in response to the continuously received ARP broadcast request when no response message to the ARP broadcast request is received;

[0041] The identification module is used to identify the scanning behavior and its scanning source based on the scanning record of each ARP broadcast request in the self-learning flow table.

[0042] In a third aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the scanning behavior identification method for a virtual private cloud according to the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0043] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the scanning behavior identification method for a virtual private cloud according to the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0045] Figure 1 is a flow chart of a scanning behavior identification method for a virtual private cloud according to an embodiment of the present invention;

[0046] Figure 2 is a flowchart of a scanning behavior identification method of another virtual private cloud according to an embodiment of the present invention;

[0047] Figure 3 is a structural block diagram of a scanning behavior recognition device for a virtual private cloud according to an embodiment of the present invention;

[0048] Figure 4 Schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0049] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.

[0050] In a VPC network, if the recipient that the initiator wants to access through an ARP broadcast request does not exist, the ARP broadcast request will continue to be sent, forming a malicious scanning behavior, and then causing ARP broadcast flooding. Therefore, how to identify scanning behavior within the VPC is an urgent problem to be solved. The present invention constructs a scanning record for each ARP broadcast request, and updates the self-learning flow table based on this, so that the self-learning flow table can dynamically record and update the ARP broadcast situation in the network, and checks whether the response message corresponding to the ARP broadcast request is received. For the ARP broadcast request that has not received a response message, the ARP broadcast request is continuously received and its scanning record is continuously updated. By analyzing the scanning records in the self-learning flow table, the scanning behavior can be efficiently and accurately identified.

[0051] According to an embodiment of the present invention, an embodiment of a method for identifying scanning behavior of a virtual private cloud is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0052] In this embodiment, a scanning behavior identification method for a virtual private cloud is provided, which can be used for a virtual switch, etc. Figure 1 FIG. 1 is a flow chart of a method for identifying scanning behavior of a virtual private cloud according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:

[0053] Step S101: In response to each received ARP broadcast request, a scan record of the ARP broadcast request is constructed based on the ARP broadcast request. Specifically, in a virtual private cloud environment, ARP scanning can disrupt normal network communications. To identify these scans, a scan record can be constructed for each received ARP broadcast request to facilitate subsequent analysis and judgment.

[0054] Step S102 updates the self-learning flow table based on the ARP broadcast request scan records. Specifically, the self-learning flow table records the broadcast status of ARP broadcast requests in the virtual private cloud and is a key data structure for identifying scanning behavior. By continuously updating it, it can reflect the latest status of ARP broadcast requests in the virtual private cloud in real time, providing accurate and timely data for subsequent identification of scanning behavior.

[0055] Step S103 determines whether a response message has been received to the ARP broadcast request. Specifically, a normal ARP broadcast request will receive a response message from the recipient within a short period of time. Since the recipient of the ARP broadcast request in the scanning behavior does not exist, the initiator often does not receive a response message. Therefore, by determining whether a response message has been received, it is possible to distinguish between normal ARP broadcast requests and potentially problematic ARP broadcast requests.

[0056] In step S104, if no response message is received to the ARP broadcast request, the scan record of the ARP broadcast request in the self-learning flow table is updated in response to the continuously received ARP broadcast requests. Specifically, if no response message is received to the ARP broadcast request, the initiator will continue to send ARP broadcast requests. Each time an ARP broadcast request is received, the scan record of the ARP broadcast request is updated to ensure that the scan record reflects the real-time status of the ARP broadcast request.

[0057] Step S105 identifies the scanning behavior and its source based on the scan records for each ARP broadcast request in the self-learning flow table. Specifically, the scan records in the self-learning flow table provide a comprehensive, real-time overview of the ARP broadcast request activity within the virtual private cloud (VPC). By thoroughly analyzing these scan records, scanning behavior can be accurately identified and its source determined, contributing to the security of the VPC.

[0058] The present invention realizes accurate tracking of ARP broadcast requests by constructing a scan record for each ARP broadcast request, and updates the self-learning flow table through the scan record, so that the self-learning flow table can dynamically record and update the ARP broadcast situation in the network, and checks whether the response message corresponding to the ARP broadcast request is received. For the ARP broadcast request that does not receive a response message, the present invention continues to receive the ARP broadcast request and continuously updates its scan record. By analyzing the scan records in the self-learning flow table, the scanning behavior and its scan source can be efficiently and accurately identified, thereby ensuring the security and stability of the virtual private cloud.

[0059] In this embodiment, a scanning behavior identification method for a virtual private cloud is provided, which can be used for the above-mentioned virtual switch, etc. Figure 2 FIG. 1 is a flow chart of another method for identifying scanning behavior of a virtual private cloud according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:

[0060] Step S201 : In response to each received ARP broadcast request, a scan record of the ARP broadcast request is constructed based on the ARP broadcast request.

[0061] Specifically, the above step S201 includes:

[0062] Step S2011: In response to each received ARP broadcast request, the ARP broadcast request is parsed to obtain the broadcast source address and broadcast destination address. Specifically, taking a virtual switch as an example, the virtual switch utilizes the OpenFlow Learn Action mechanism to parse the received ARP broadcast request to obtain the broadcast source address and broadcast destination address. The broadcast source address is the address of the initiator of the ARP broadcast request, and the broadcast destination address is the address of the recipient of the ARP broadcast request.

[0063] Step S2012: Obtain the preset aging time and broadcast duration of the ARP broadcast request. Specifically, the preset aging time is a value derived from extensive network practical experience and rigorous performance testing, and sets a standard for the normal duration of ARP broadcast requests in the VPC network. When the initiator sends an ARP broadcast request, the virtual switch records the sending timestamp. By calculating the difference between the current time and the sending timestamp, the duration of the ARP broadcast request in the VPC, i.e., the broadcast duration, can be obtained. For example, if the ARP broadcast request is sent at 10:00:00 and the current time is 10:01:00, then the broadcast duration is 1 minute.

[0064] Step S2013 determines the remaining aging time of the ARP broadcast request based on the preset aging time and the broadcast duration. Specifically, the remaining aging time is an important indicator of how long an ARP broadcast request can survive normally in the VPC network. For example, if the preset aging time of any ARP broadcast request is 3 minutes and the broadcast duration is 1 minute, the remaining aging time of the ARP broadcast request is 2 minutes.

[0065] In some optional implementations, for each ARP broadcast request, the preset aging time is a fixed value, and the broadcast duration and the remaining aging time change dynamically over time during their existence.

[0066] Step S2014: The source address, target address, preset aging time, remaining aging time, and duration of the ARP broadcast request are recorded as a scan record of the ARP broadcast request. Specifically, the scan record integrates various aspects of the ARP broadcast request information to provide data support for subsequent identification of the scanning behavior.

[0067] Step S202: Update the self-learning flow table based on the scan record of the ARP broadcast request.

[0068] Specifically, the above step S202 includes:

[0069] Step S2021, when there is no scan record of the ARP broadcast request in the self-learning flow table, the scan record is stored in the self-learning flow table. Specifically, when an ARP broadcast request is received for the first time, there is no scan record of the ARP broadcast request in the self-learning flow table, so it is necessary to store the scan record of the ARP broadcast request in the self-learning flow table to ensure that the self-learning flow table fully records the broadcast status of all ARP broadcast requests in the VPC network. Optionally, when determining whether there is a scan record of the ARP broadcast request in the self-learning flow table, other scan records that are consistent with the broadcast source address and broadcast target address of the ARP broadcast request can be queried from the self-learning flow table. If no scan record can be found, it is considered that there is no scan record of the ARP broadcast request in the self-learning flow table. If no scan record can be found, it is considered that there is a scan record of the ARP broadcast request in the self-learning flow table.

[0070] Alternatively, in step S2022, when there is a scan record of the ARP broadcast request in the self-learning flow table, the scan record of the ARP broadcast request in the self-learning flow table is updated.

[0071] In some optional implementations, the above step S2022 updates the scan record of the ARP broadcast request in the self-learning flow table, including:

[0072] In step a1, the remaining aging time in the scan record is reset to the preset aging time. Specifically, if a scan record for the ARP broadcast request already exists in the self-learning flow table, this indicates that the ARP broadcast request is not being sent for the first time. In the ARP protocol's operating mechanism, if an ARP broadcast request does not receive a response message, it will continue to be sent. Each time an ARP broadcast request is received, it can be regarded as a restart of the active state of the ARP broadcast request in the VPC network. Based on this, the remaining aging time in the scan record needs to be reset to the preset aging time. For example, if the preset aging time is 3 minutes and the original remaining aging time is 1 minute, it is reset to 3 minutes. By resetting the remaining aging time, the duration of the ARP broadcast request's continued activity in the network can be continuously monitored. If a normal ARP broadcast request repeatedly resets its remaining aging time before receiving a response message, and no response message is received for a long time, it is likely a scanning behavior, providing a key judgment basis for identifying scanning behavior.

[0073] In step a2, the time difference between the first ARP broadcast request and the current time is used as the broadcast duration in the scan record. Specifically, because ARP broadcast requests continue to be sent even if no response message is received, and each ARP broadcast request is sent consistently, the broadcast duration of the ARP broadcast request needs to be calculated from the first transmission to accurately reflect the cumulative length of time the ARP broadcast request has been in the network.

[0074] Step S203: Determine whether a response message to the ARP broadcast request is received. Figure 1 Step S103 of the illustrated embodiment will not be described in detail here.

[0075] In step S204, if no response message is received to the ARP broadcast request, the scanning record of the ARP broadcast request in the self-learning flow table is updated in response to the continuously received ARP broadcast request. Specifically, if no response message is received to the ARP broadcast request, the ARP broadcast request is continuously sent. Each time an ARP broadcast request is received, the scanning record of the ARP broadcast request is updated according to steps a1 and a2 above.

[0076] Step S205: When a response message to the ARP broadcast request is received, the scan record of the ARP broadcast request in the self-learning flow table is aged. Specifically, if a response message to the ARP broadcast request is received, it indicates that the recipient of the ARP broadcast request actually exists, the initiator and the recipient can communicate normally, and the ARP broadcast request has been completed. Therefore, the scan record of the broadcast request can be deleted from the self-learning flow table, so that only the scan records of unfinished or potentially abnormal ARP broadcast requests are retained in the self-learning flow table, so that more focus can be placed on monitoring and analyzing possible scanning behaviors, thereby improving recognition accuracy and efficiency.

[0077] Step S206 : Identify the scanning behavior and its scanning source based on the scanning record of each ARP broadcast request in the self-learning flow table.

[0078] Specifically, the above step S206 includes:

[0079] In step S2061, for each ARP broadcast request scan record in the self-learning flow table, if the broadcast duration in the scan record exceeds the preset aging time, the ARP broadcast request corresponding to the scan record is identified as a scanning behavior, and the broadcast source address in the scan record is identified as the scan source of the scanning behavior. Specifically, a periodic check is performed on each ARP broadcast request scan record in the self-learning flow table. During the check, if the broadcast duration of a scan record exceeds the preset aging time, it means that the ARP broadcast request corresponding to the scan record has existed in the VPC network for a period of time exceeding the normal range. Under normal circumstances, if an ARP broadcast request can receive a response, its existence time should be within the preset aging time. However, if an ARP broadcast request continues to exist without a response for a long time, the ARP broadcast request corresponding to the scan record is identified as a scanning behavior, and the broadcast source address in the scan record is determined as the scan source of the scanning behavior. By analyzing the scan records in the self-learning flow table, it is possible to accurately locate possible scanning behaviors and their initiators from a large number of ARP broadcast requests, providing a clear target for subsequent protective measures.

[0080] Step S207, for each scanning source of scanning behavior, a blocking flow table or a speed limiting flow table is sent to the scanning source. Specifically, for each identified scanning source of scanning behavior, control measures will be taken to prevent the scanning behavior from further endangering the VPC network. More specifically, the blocking flow table is used to prohibit the scanning source from sending ARP broadcast requests. When the scanning source located in the blocking flow table attempts to send an ARP broadcast request, the ARP broadcast request is intercepted and the discard policy is executed, thereby directly blocking the scanning behavior of the scanning source. The speed limiting flow table is used to limit the speed of the ARP broadcast request sent by the scanning source and reduce its consumption of network resources. By taking blocking or speed limiting measures on the scanning source in a timely manner, the scanning behavior can be effectively prevented to protect the security of the virtual private cloud network.

[0081] The present invention realizes accurate tracking of ARP broadcast requests by constructing a scan record for each ARP broadcast request, and updates the self-learning flow table through the scan record, so that the self-learning flow table can dynamically record and update the ARP broadcast situation in the network, and checks whether the response message corresponding to the ARP broadcast request is received. For the ARP broadcast request that does not receive a response message, the present invention continues to receive the ARP broadcast request and continuously updates its scan record. By analyzing the scan records in the self-learning flow table, the scanning behavior and its scan source can be efficiently and accurately identified, thereby ensuring the security and stability of the virtual private cloud.

[0082] In this embodiment, a scanning behavior recognition device for a virtual private cloud is also provided. The device is used to implement the above-mentioned embodiments and preferred implementations. The details that have been described will not be repeated here. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware, is also possible and contemplated.

[0083] This embodiment provides a scanning behavior recognition device for a virtual private cloud, such as Figure 3 As shown, including:

[0084] The construction module 301 is configured to construct a scan record of the ARP broadcast request in response to each received ARP broadcast request based on the ARP broadcast request.

[0085] The first updating module 302 is configured to update the self-learning flow table based on the scanning record of the ARP broadcast request.

[0086] The judging module 303 is configured to judge whether a response message to the ARP broadcast request is received.

[0087] The second updating module 304 is configured to update the scanning record of the ARP broadcast request in the self-learning flow table in response to continuously received ARP broadcast requests when no response message to the ARP broadcast request is received.

[0088] The identification module 305 is configured to identify the scanning behavior and its scanning source based on the scanning record of each ARP broadcast request in the self-learning flow table.

[0089] In some optional implementations, the building block 301 includes:

[0090] The parsing unit is used to respond to each received ARP broadcast request, parse the ARP broadcast request, and obtain the broadcast source address and the broadcast target address.

[0091] The obtaining unit is used to obtain the preset aging time and broadcast duration of the ARP broadcast request.

[0092] The first determining unit is configured to determine a remaining aging time of the ARP broadcast request based on a preset aging time and a broadcast duration.

[0093] The second determining unit is configured to use the broadcast source address, the broadcast target address, the preset aging time, the remaining aging time, and the broadcast duration of the ARP broadcast request as a scan record of the ARP broadcast request.

[0094] In some optional implementations, the first updating module 302 includes:

[0095] The storage unit is configured to store the scan record in the self-learning flow table when there is no scan record of the ARP broadcast request in the self-learning flow table.

[0096] Alternatively, the updating unit is configured to update the scanning record of the ARP broadcast request in the self-learning flow table when there is a scanning record of the ARP broadcast request in the self-learning flow table.

[0097] In some optional implementations, the updating unit includes:

[0098] The reset subunit is used to reset the remaining aging time in the scan record to the preset aging time.

[0099] The determination subunit is configured to use the time difference between the time when the ARP broadcast request is first sent and the current time as the broadcast duration in the scan record.

[0100] In some optional implementations, after determining module 303, the device further includes:

[0101] The aging module is used to age the scanning record of the ARP broadcast request in the self-learning flow table when a response message of the ARP broadcast request is received.

[0102] In some optional implementations, the identification module 305 includes:

[0103] An identification unit is used to identify the ARP broadcast request corresponding to the scanning record as a scanning behavior and the broadcast source address in the scanning record as the scanning source of the scanning behavior when the broadcast duration in the scanning record is greater than the preset aging time.

[0104] In some optional embodiments, the device further comprises:

[0105] The control module is used to send a blocking flow table or a rate-limiting flow table to the scanning source for each scanning behavior.

[0106] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0107] The scanning behavior recognition device of the virtual private cloud in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0108] The embodiment of the present invention also provides a computer device having the above Figure 3 The scanning behavior recognition device of the virtual private cloud is shown.

[0109] See also Figure 4 , Figure 4 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 4 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 4 A processor 10 is taken as an example.

[0110] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.

[0111] The memory 20 stores instructions that can be executed by at least one processor 10, so as to enable at least one processor 10 to execute the method shown in the above embodiment.

[0112] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0113] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0114] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0115] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.

[0116] A portion of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium that can be accessed by the computer.

[0117] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A method for identifying scanning behavior of a virtual private cloud, characterized in that: The method comprises: In response to each received ARP broadcast request, construct a scan record of the ARP broadcast request based on the ARP broadcast request; Based on the scan record of the ARP broadcast request, update the self-learning flow table; Determine whether a response message to the ARP broadcast request is received; In a case where no response message to the ARP broadcast request is received, in response to the ARP broadcast request continuously received, updating the scanning record of the ARP broadcast request in the self-learning flow table; Based on the scanning record of each ARP broadcast request in the self-learning flow table, the scanning behavior and the scanning source are identified.

2. The method according to claim 1, characterized in that The step of constructing a scan record of the ARP broadcast request based on the ARP broadcast request in response to each received ARP broadcast request includes: In response to each received ARP broadcast request, parsing the ARP broadcast request to obtain a broadcast source address and a broadcast destination address; Obtaining a preset aging time and broadcast duration of the ARP broadcast request; Determining a remaining aging time of the ARP broadcast request based on the preset aging time and the broadcast duration; The broadcast source address, broadcast target address, preset aging time, remaining aging time and broadcast duration of the ARP broadcast request are used as the scan record of the ARP broadcast request.

3. The method according to claim 2, characterized in that The updating of the self-learning flow table based on the scanning record of the ARP broadcast request includes: If there is no scan record of the ARP broadcast request in the self-learning flow table, storing the scan record in the self-learning flow table; or In a case where a scan record of the ARP broadcast request exists in the self-learning flow table, the scan record of the ARP broadcast request in the self-learning flow table is updated.

4. The method according to claim 3, characterized in that The updating of the scanning record of the ARP broadcast request in the self-learning flow table includes: Resetting the remaining aging time in the scan record to a preset aging time; The time difference between the time when the ARP broadcast request is first sent and the current time is used as the broadcast duration in the scan record.

5. The method according to claim 1, wherein After determining whether a response message to the ARP broadcast request is received, the method further includes: When a response message to the ARP broadcast request is received, the scanning record of the ARP broadcast request in the self-learning flow table is aged.

6. The method according to claim 2, characterized in that The scanning record based on each ARP broadcast request in the self-learning flow table, identifying the scanning behavior and its scanning source, includes: For each scanning record of the ARP broadcast request in the self-learning flow table, when the broadcast duration in the scanning record is greater than the preset aging time, the ARP broadcast request corresponding to the scanning record is identified as a scanning behavior, and the broadcast source address in the scanning record is identified as the scanning source of the scanning behavior.

7. The method according to claim 5, characterized in that The method further comprises: For each scanning source of a scanning behavior, a blocking flow table or a rate-limiting flow table is sent to the scanning source.

8. A scanning behavior recognition device for a virtual private cloud, characterized in that: The device comprises: a construction module, configured to construct, in response to each received ARP broadcast request, a scan record of the ARP broadcast request based on the ARP broadcast request; A first updating module is configured to update a self-learning flow table based on a scan record of the ARP broadcast request; A determination module, configured to determine whether a response message to the ARP broadcast request has been received; A second updating module is configured to update the scanning record of the ARP broadcast request in the self-learning flow table in response to the continuously received ARP broadcast request when no response message to the ARP broadcast request is received; The identification module is used to identify the scanning behavior and the scanning source based on the scanning record of each ARP broadcast request in the self-learning flow table.

9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the scanning behavior recognition method for a virtual private cloud according to any one of claims 1 to 7 by executing the computer instructions.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the scanning behavior recognition method for a virtual private cloud according to any one of claims 1 to 7.