Method and device for detecting cache pollution attack of CDN (Content Delivery Network) and electronic equipment
By obtaining user requests in the CDN network and calculating the cumulative incremental times using the location encoding of the frequent item set and the target item set, the problem of the inability to fully detect cache pollution attacks in the prior art is solved, and comprehensive detection of cache pollution attacks and evaluation of the degree of persistence of abnormal states is achieved.
Patent Information
- Application Number
- CN202510749537.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2025-08-08
AI Technical Summary
The prior art cannot fully detect cache pollution attacks, especially in distinguishing the incremental or decreasing changes in attack states and identifying the persistence of abnormal states, and lacks the ability to analyze regional characteristics of users requesting traffic.
By obtaining user requests in the CDN network, identifying suspicious users, using the location encoding of the frequent item set and the target item set, calculating the cumulative incremental times, and identifying cache pollution attacks. The specific steps include generating the word embedding vector matrix, determining the reference and target vector matrix, analyzing the regional characteristics of the edge cache node, calculating the merged position encoding of the frequent item set and the target item set, and recording the cumulative incremental times to identify cache pollution information.
A comprehensive detection of cache pollution attacks is achieved, which can identify content controlled by malicious users and evaluate the persistence of abnormal states, improving the accuracy and targetedness of detection.
Smart Images

Figure CN120455131A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method for detecting cache pollution attacks in a CDN network, a device for detecting cache pollution attacks in a CDN network, a computer-readable storage medium, and an electronic device. Background Art
[0002] With the rapid development of the internet in recent years, services based on CDNs (Content Delivery Networks) have increased significantly. While providing efficient access, CDNs also face the risk of attack. Attackers exploit the structural characteristics of CDNs to launch targeted attacks. A typical attack method is cache poisoning. Cache poisoning attacks involve attackers injecting malicious content into CDN networks, reducing cache hit rates and thereby degrading CDN service performance. Because attackers can control the cache duration of malicious content, these attacks are stealthy, controllable, and persistent. Protection against cache poisoning attacks typically relies on the protection mechanisms of the CDN network itself or the content source. However, current protection mechanisms typically employ static policies, setting a threshold within the CDN network and triggering protection measures when the cache hit rate falls below this threshold. However, because attackers can dynamically adjust the cache duration of malicious content, these static policies fail to differentiate between attackers and legitimate users, easily leading to the inadvertent deletion of legitimate content. Even if a cache pollution attack is identified, it's impossible to distinguish whether the abnormal state change caused by the attack traffic is increasing or decreasing. Lacking a persistent feature for the abnormal state, this method can only determine the presence of an abnormal state based on a threshold, but cannot identify its persistence. Furthermore, existing technologies lack the ability to analyze the regional characteristics of user request traffic and lack the targeted detection capabilities for cache pollution attacks. Therefore, effectively detecting cache pollution attacks has become a pressing issue. Summary of the Invention
[0003] The main purpose of this application is to provide a method for detecting cache pollution attacks in a CDN network, a device for detecting cache pollution attacks in a CDN network, a computer-readable storage medium, and an electronic device, so as to at least solve the technical problem that the cache pollution attack detection technology in the prior art cannot comprehensively detect the attack status.
[0004] To achieve the above-mentioned purpose, according to one aspect of the present application, a method for detecting a cache pollution attack in a CDN network is provided, comprising: obtaining multiple user requests in the CDN network and determining suspicious users, wherein the user requests include at least: requested content information, content popularity, cache hit rate and edge cache node information; obtaining frequent item sets and target item sets of the user requests, wherein one user request corresponds to one frequent item set and multiple target item sets, and the target item set is used to characterize the level of the cache hit rate of the user request; calculating the position code of the frequent item set and multiple different target item sets after merging according to the time sequence of the multiple target item sets to obtain multiple merged position codes; determining the cumulative increment times of the position code of the user request based on the position code of the frequent item set and the multiple merged position codes, and when the cumulative increment times is greater than 0, determining that the user request is cache pollution information and determining that the CDN network is attacked.
[0005] Optionally, user requests of multiple users in the CDN network are obtained to determine suspicious users, including: generating a first word embedding vector matrix based on the content information of the request; determining a reference vector matrix based on the first word embedding vector matrix and a first weight matrix; generating a second word embedding vector matrix based on the edge cache node information; determining a target vector matrix based on the second word embedding vector matrix and the second weight matrix; determining a target feature matrix based on the reference vector matrix and the target vector matrix; judging whether the target feature matrix contains regional features, and if the target feature matrix does not contain the regional features, determining that the user is the suspicious user, and containing the regional features indicates that the target feature matrix has normal convertibility higher than a preset conversion possibility.
[0006] Optionally, obtaining the frequent itemsets and target itemsets requested by the user includes: determining the frequent itemsets according to the content popularity, the edge cache node information and the requested content information; and determining the target itemsets according to the frequent itemsets and the cache hit rate.
[0007] Optionally, the calculating the position codes of the frequent item set and the multiple different target item sets after merging according to the time sequence of the multiple target item sets to obtain multiple merged position codes includes: forming a target sequence with the frequent item set and the multiple target item sets, and determining the word segmentation codes of the frequent item set and the multiple target item sets according to the target sequence, the one-hot coding and the third weight matrix, wherein the first element of the target sequence is the frequent item set, and the subsequent elements are the multiple target item sets arranged according to the time sequence; determining the position codes of the frequent item set and the multiple target item sets according to the word segmentation codes and the position values of the word segmentation codes; merging the multiple target item sets with the frequent item sets according to the time sequence of the multiple target item sets to obtain merged position codes.
[0008] Optionally, determining the cumulative increasing number of the position code requested by the user based on the position code of the frequent item set and the multiple merged position codes includes: performing a first judgment and a second judgment in sequence to obtain the cumulative increasing number, wherein, if the judgment result of the first judgment indicates that the condition is satisfied, the cumulative increasing number of the merged position code is increased by 1; if the judgment result of the first judgment indicates that the condition is not satisfied, the cumulative increasing number of the merged position code is decreased by 1; if the judgment result of the second judgment indicates that the condition is satisfied, the cumulative increasing number of the merged position code is increased by 1; if the judgment result of the second judgment indicates that the condition is not satisfied, the cumulative increasing number of the merged position code is decreased by 1, wherein the first judgment is: determining whether the sum of the merged position codes of the first target item set and the frequent item set is greater than the position code of the frequent item set; and the second judgment is: determining whether the merged position code of the second target item set and the frequent item set is greater than the merged position code of the first target item set and the frequent item set.
[0009] Optionally, the detection method further includes: determining the target cache pollution information manipulated by the suspicious user based on the content popularity of the suspicious user and the edge cache node information of the current CDN network; determining a preset weight based on the cumulative number of increments of the position code of the target cache pollution information; and determining the content popularity of the target cache pollution information based at least on the preset weight.
[0010] Optionally, determining the content popularity of the target cache pollution information at least according to the preset weight includes: determining the adjusted content popularity of the target cache pollution information according to the preset weight and a first formula, where the first formula is: Wherein, P(ci) is the content popularity of the target cache pollution information after adjustment, P'(ci) is the original content popularity of the target cache pollution information, S n is the preset weight, n is the cumulative number of increments of the position encoding of the target cache pollution information, λ A is the regional characteristic value of user A, λ B is the regional characteristic value of user B.
[0011] To achieve the above objective, according to another aspect of the present application, a device for determining a cache pollution attack in a CDN network is provided, which is applied to the method for detecting a cache pollution attack in a CDN network. The device for determining a cache pollution attack in a CDN network includes: a first acquisition module, configured to acquire multiple user requests in the CDN network and determine suspicious users, wherein the user requests include at least requested content information, content popularity, cache hit rate, and edge cache node information; a second acquisition module, configured to acquire frequent itemsets and target itemsets of the user requests, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemsets are used to represent the cache hit rate level of the user request; a first determination module, configured to calculate, in chronological order of the multiple target itemsets, a position code of a merged frequent itemset and multiple different target itemsets to obtain multiple merged position codes; and a second determination module, configured to determine, based on the position code of the frequent itemset and the multiple merged position codes, a cumulative increment count of the position code of the user request. If the cumulative increment count is greater than 0, it is determined that the user request is cache pollution information and the CDN network is attacked.
[0012] According to another aspect of the present application, a computer-readable storage medium is provided, which includes a stored program, wherein when the program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method for detecting cache pollution attacks in the CDN network.
[0013] According to another aspect of the present application, an electronic device is provided, comprising: one or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include a method for detecting cache pollution attacks in the CDN network described above.
[0014] Applying the technical solution of the present application, first obtain multiple user requests in the CDN network and determine suspicious users, wherein the user request includes at least: requested content information, content popularity, cache hit rate, and edge cache node information; obtain the frequent item set and target item set of the user request, wherein one user request corresponds to one frequent item set and multiple target item sets, and the target item set is used to characterize the cache hit rate level of the user request; calculate the position code of the frequent item set after merging with multiple different target item sets according to the time sequence of the multiple target item sets, and obtain multiple merged position codes; determine the cumulative increment times of the position code of the user request based on the position code of the frequent item set and the multiple merged position codes, and if the cumulative increment times are greater than 0, determine that the user request is cache pollution information, and determine that the CDN network is attacked. The above method calculates the merged position codes of the frequent item set and the target item set according to the time sequence, and records the cumulative increment times n of the merged position codes of the frequent item set after merging with different target item sets. Content with an increment count greater than 0 is identified as content controlled by a malicious user. The increment count indicates the persistence of abnormal edge cache node conditions caused by cache pollution attacks, enabling comprehensive detection of cache pollution attacks on CDN networks. This addresses the technical issue of existing cache pollution attack detection technologies being unable to comprehensively detect attack conditions. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The drawings that constitute part of this application are used to provide a further understanding of this application. The illustrative embodiments of this application and their descriptions are used to explain this application and do not constitute an improper limitation on this application. In the drawings:
[0016] Figure 1 A hardware structure block diagram of a mobile terminal for performing a method for detecting cache pollution attacks in a CDN network provided in an embodiment of the present application is shown;
[0017] Figure 2 A schematic diagram of a process for detecting cache pollution attacks in a CDN network according to an embodiment of the present application is shown;
[0018] Figure 3 A schematic diagram of a reference vector matrix of user A's content access data on each edge cache node is shown;
[0019] Figure 4 A schematic diagram of a reference vector matrix of user B's content access data on each edge cache node is shown;
[0020] Figure 5 A schematic diagram of a reference vector matrix of user C's content access data on each edge cache node is shown;
[0021] Figure 6A schematic diagram showing the regional characteristics of user A's content access data regarding the attention value of each edge cache node;
[0022] Figure 7 A schematic diagram showing the regional characteristics of the attention value of user B's content access data on each edge cache node is shown;
[0023] Figure 8 A schematic diagram showing the regional characteristics of the attention value of user C's content access data on each edge cache node is shown;
[0024] Figure 9 A schematic diagram showing the regional characteristics of traffic on edge nodes measured by Box-Cox transformation parameters is shown;
[0025] Figure 10 A schematic diagram showing the content segments and edge node status information accessed by the first type of suspicious users A and B is shown;
[0026] Figure 11 A schematic diagram of the content segments and edge node status information accessed by the second type of suspicious users A and B is shown;
[0027] Figure 12 The figure shows the frequent item sets of suspect users A and B and the target item set (subset);
[0028] Figure 13 A schematic diagram showing the increasing number of position codes when different subsets of the frequent item set {3 files -> X -> content L} related to user A are merged;
[0029] Figure 14 A schematic diagram showing the increasing number of position codes when different subsets of the frequent item set {3-fold -> Y -> content M} related to user A are merged;
[0030] Figure 15 A schematic diagram showing the increasing number of position codes when different subsets of the frequent item set {8 files -> X -> content D} related to user B are merged;
[0031] Figure 16 A schematic diagram showing the increasing number of position codes when different subsets of the frequent item set {8-fold -> Y -> content C} related to user B are merged;
[0032] Figure 17 It shows a schematic diagram of the popularity control of access content by attacker A and normal user B;
[0033] Figure 18 A schematic structural diagram of a device for detecting cache pollution attacks in a CDN network provided according to an embodiment of the present application is shown.
[0034] The above drawings include the following reference numerals:
[0035] 102. Processor; 104. Memory; 106. Transmission device; 108. Input / output device. DETAILED DESCRIPTION
[0036] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0037] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0038] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0039] As described in the background, current protection mechanisms typically employ static strategies. These strategies set a threshold within the CDN network, triggering protection measures when the cache hit rate falls below it. However, because attackers dynamically adjust the cache duration of malicious content, this static strategy is ineffective in defending against cache pollution attacks. Even if a pollution attack is identified, it's impossible to distinguish whether the abnormal state changes caused by the attack traffic are incremental or decremental. Lacking a persistent feature for the abnormal state, the presence of an abnormal state can only be determined based on the threshold, without identifying its persistence. Therefore, effectively detecting cache pollution attacks has become a pressing issue.
[0040] For ease of description, some nouns or terms involved in the embodiments of the present application are explained below:
[0041] Cache pollution attacks: Attackers frequently request low-popularity malicious content to increase its hit rate in the target edge cache, forcing it to remain in the cache for a long time. Simultaneously, this type of attack can also reduce the cache hit rate of highly popular content requested by other legitimate users.
[0042] Traffic regionality: This refers to the regional characteristics of user traffic in the content distribution network with respect to edge cache nodes. Normally, content request traffic from normal users is concentrated on edge cache nodes in nearby areas, while attack traffic from cache pollution attackers spreads across edge cache nodes in multiple regions.
[0043] User behavior: This refers to the user's access behavior to content or edge cache nodes.
[0044] Frequent itemsets: It is a technique used in data mining to discover potential associations between variables in a data set. Frequent itemsets in a data set are filtered based on support. The filtering criterion is whether the association between the data set is greater than the minimum support.
[0045] Edge caching: Edge caching is a technology that caches data or services at edge nodes (such as base stations, CDN nodes, local servers, etc.) close to end users (or devices). It aims to reduce data transmission delays, improve response speeds, and reduce core network loads.
[0046] CDN (Content Delivery Networking) network: is a network architecture that optimizes content delivery efficiency through distributed node deployment and intelligent scheduling strategies.
[0047] Content sharding: Split large files (such as videos and software installation packages) into multiple small segments and store them in different edge nodes of the CDN.
[0048] Positional Encoding (PE): In the natural language self-attention mechanism, PE is used to reflect the order of text input. The same words arranged in different contexts will produce different semantics. PE can be further divided into absolute position encoding and relative position encoding. This application uses absolute position encoding, calculated as PE = position value + word segmentation code.
[0049] Cumulative increments of position codes: This application selects the frequent item sets of association rules between the user's access content fragment information and the edge cache nodes and content popularity information in the system, converts them into position codes, and calculates the cumulative increments of the position code values after the frequent item sets are merged with different subsets.
[0050] Cosine wave combination: In the natural language self-attention mechanism, cosine wave combination is a way to generate positional encoding. The implementation method of this application differs from existing methods in that the cosine angular rate ω is generated by using the machine code word segmentation encoding features of the resource pool code at both ends of the source and the destination, and the phase difference Ψ between each cosine wave in the cosine wave combination is generated by using the word segmentation encoding of the network performance loss data between the source and the destination. The two are combined to generate multiple cosine waves.
[0051] Positional value: During the positional encoding calculation process of the self-attention mechanism, each word's segmentation code corresponds to multiple cosine wave values, and the positional value is the combination of these cosine wave values. The more cosine waves in the cosine wave combination, the richer the combination of positional values and corresponding positional encodings.
[0052] Word segmentation encoding: A common method in natural language models that multiplies a word or phrase through one-hot encoding with the weight parameters of a neural network to obtain semantic features. It is the basis for the subsequent generation of word embedding vectors, position encoding, attention values, etc.
[0053] The technical solutions in the embodiments of the present application will be described clearly and completely below in conjunction with the drawings in the embodiments of the present application.
[0054] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 This is a hardware structure block diagram of a mobile terminal of a method for detecting cache pollution attacks in a CDN network according to an embodiment of the present application. Figure 1 As shown, the mobile terminal may include one or more ( Figure 1 Only one is shown) a processor 102 (the processor 102 may include but is not limited to a microprocessor MCU or a programmable logic device FPGA and other processing devices) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the mobile terminal. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0055] The memory 104 can be used to store computer programs, such as software programs and modules of application software, such as the computer program corresponding to the method for detecting cache pollution attacks in a CDN network in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, thereby implementing the above-mentioned method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some examples, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories can be connected to the mobile terminal via a network. Examples of the above-mentioned networks include but are not limited to the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof. The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned networks may include a wireless network provided by the mobile terminal's communication provider. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices via a base station to communicate with the Internet. In one example, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0056] In this embodiment, a method for detecting cache pollution attacks in a CDN network running on a mobile terminal, a computer terminal, or a similar computing device is provided. It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0057] Figure 2 Flowchart of a method for detecting cache pollution attacks in a CDN network according to an embodiment of the present application. Figure 2 As shown, the method includes the following steps:
[0058] Step S1: Obtain multiple user requests in the CDN network and identify suspicious users. The user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information;
[0059] Specifically, these parameters can reflect the regional characteristics of user requests, thereby identifying users suspected of cache pollution attacks and improving the accuracy and specificity of cache pollution attack detection. This improvement in detection accuracy is due to the ability to distinguish between the traffic patterns of legitimate users and attackers through statistical analysis. Specifically, legitimate user traffic requests exhibit regional characteristics, while attacker traffic requests are spread across multiple regions. This comparison helps accurately identify attack behavior.
[0060] Step S2, obtaining the frequent itemsets and target itemsets requested by the user, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemset is used to characterize the cache hit rate level of the user request;
[0061] Specifically, data mining is performed on collected user requests to identify combinations that frequently appear in request sequences, known as frequent itemsets, as well as subsets related to these frequent itemsets, known as target itemsets. These target itemsets reflect the level of cache hit rate changes and help further analyze the characteristics of cache pollution attacks.
[0062] Step S3, calculating the position codes of the merged frequent item sets and the multiple different target item sets according to the time sequence of the multiple target item sets to obtain multiple merged position codes.
[0063] Specifically, the frequent itemsets and the target itemset are merged in chronological order to obtain the merged position encoding (PE). This involves converting the content popularity and edge cache node information in the frequent itemsets and the target itemset into PE values, and then using the absolute position encoding calculation method, that is, PE = position value + word segmentation code, to generate the position code.
[0064] Step S4: Determine the cumulative increment times of the position codes requested by the user based on the position codes of the frequent itemsets and the multiple merged position codes. If the cumulative increment times are greater than 0, determine that the user request is cache pollution information and determine that the CDN network is attacked.
[0065] Specifically, the cumulative number of increments of the merged position encoding after the frequent item set and the target item set are merged is recorded as n. If n>0, the relevant user request is determined to be cache pollution information, which indicates that the attacker is affecting the cache hit rate through specific behavior patterns.
[0066] Through this embodiment, multiple user requests in the CDN network are first obtained to identify suspicious users. The user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information; frequent itemsets and target itemsets of the user requests are obtained, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemsets are used to characterize the cache hit rate level of the user request; the position codes of the frequent itemsets and multiple different target itemsets are calculated according to the time sequence of the multiple target itemsets to obtain multiple merged position codes; based on the position codes of the frequent itemsets and the multiple merged position codes, the cumulative increment times of the position codes of the user requests are determined. If the cumulative increment times are greater than 0, the user request is determined to be cache contamination information, and the CDN network is determined to be attacked. The above method calculates the merged position codes of the frequent itemsets and the target itemsets according to the time sequence, and records the cumulative increment times n of the merged position codes of the frequent itemsets and the different target itemsets. Content with an increment count greater than 0 is identified as content controlled by a malicious user. The increment count indicates the persistence of abnormal edge cache node conditions caused by cache pollution attacks, enabling comprehensive detection of cache pollution attacks on CDN networks. This addresses the technical issue of existing cache pollution attack detection technologies being unable to comprehensively detect attack conditions.
[0067] The existing technology identifies content whose popularity and edge cache node request rate change exceeds a threshold as content controlled by cache pollution attacks. This application identifies content whose popularity and edge cache node frequent item set subsets cause the parent set position code to increase more than 0 times as content controlled by attacks.
[0068] In some embodiments, step S1 obtains user requests from multiple users in the CDN network and identifies suspicious users, including:
[0069] Step S11: Generate a first word embedding vector matrix based on the requested content information; determine a reference vector matrix based on the first word embedding vector matrix and the first weight matrix; preprocess the content information requested by the user and convert it into a vector representation using word embedding technology, thereby converting the content information into a computable vector form to facilitate subsequent statistical analysis and machine learning applications. After obtaining the first word embedding vector matrix, it is converted into a reference vector matrix using the first weight matrix. This reference vector matrix reflects the global characteristics of the content requested by the user.
[0070] Step S12: Generate a second word embedding vector matrix based on the edge cache node information; determine a target vector matrix based on the second word embedding vector matrix and the second weight matrix; determine a target feature matrix based on the reference vector matrix and the target vector matrix; perform word embedding processing on the edge cache node information to obtain a vector representation (the second word embedding vector matrix), combine the second word embedding vector matrix with the second weight matrix, and calculate a target vector matrix to reflect the importance and contextual relationship of the edge cache node. Combine the reference vector matrix requested by the user and the target vector matrix of the edge cache node to generate a target feature matrix to further reveal regional characteristics.
[0071] Step S13, determine whether the target feature matrix contains regional features. When the target feature matrix (attention value combination) does not contain regional features, determine that the user is a suspicious user. The inclusion of regional features indicates that the target feature matrix has a normal convertibility that is higher than the preset conversion possibility. If the distribution of the target feature matrix is non-normal, it indicates that the target feature matrix has a lower normal convertibility, and the lower the normal convertibility, the lower the regional features of the above-mentioned user request, and the more suspicious the user's behavior is. Through the above steps, the distribution of the target feature matrix can be made into an importance feature index for identification. Content with regional features is normal content, and the rest of the content is identified as problematic content without regional features, and the user corresponding to the content is identified as a malicious user, thereby improving the ability to analyze the regional features of user requests and having the targeted detection capability of cache pollution attacks.
[0072] For example, the traffic monitoring device collects the content information of user A's request to the edge nodes S, B, H, X, and Y in the system, and obtains the Q parameters [1.63, 8.07] (reference vector matrix) of user A's access record by matrix multiplication between the shared Q parameter weight combination [1.07, 2.18; 2.09, 0.37] (first weight matrix) and the position code [3.91, -1.22] (first word embedding vector matrix) of user A's traffic data. User B obtains the Q parameters [2.56, 8.63] by matrix multiplication between the shared Q parameter weight combination and the position code [4.11, -0.88]. User C obtains the Q parameters [3.38, 1.95] by matrix multiplication between the position code [0.68, 1.27] and the shared Q parameter weight combination. The specific Q parameter calculation steps for users A, B, and C are as follows: Figures 3-5 The content shown in .
[0073] like Figures 6-8As shown, since the edge nodes in the system remain unchanged, the present application obtains a K value combination [0.42, 3.32] (target vector matrix) based on the matrix multiplication between the shared K parameter weight combination [0.55, 3.08; 0.19, -1.23] (second weight matrix) and the position code [0.91, -0.42] (second word embedding vector matrix) of the edge node S. Subsequently, the present application obtains a K value combination [0.29, 3.14] based on the matrix multiplication of the shared K parameter weight combination and the position code [0.76, -0.65] of the edge node B, obtains a K value combination [0.58, 2.61] based on the shared K parameter weight combination and the position code [0.96, 0.28] of the edge node H, and obtains a K value combination [0.56, 1.92] based on the matrix multiplication of the shared K parameter weight combination and the position code [0.84, 0.54] of the edge node X. Finally, this application obtains the K value combination [-0.11, 1.65] based on the matrix multiplication between the shared K parameter weight combination and the position encoding [0.14, -0.99] of the edge node Y.
[0074] like Figure 6 , this application multiplies the matrix of user A's Q parameter [1.63, 8.07] and the K value combination of each edge node S, B, H, X, Y by the transposed matrix K' [0.42; 3.32], [0.29; 3.14], [0.58; 2.61], [0.56; 1.92], [-0.11; 1.65] to obtain Q×K', that is, the user A's attention value combination for each edge node [27.483, 25.831, 22.038, 16.446, 13.129] (target feature matrix). Figure 7 , user B's Q parameter combination [2.56, 8.63] is multiplied by the transposed matrix K' of the K value combination of each edge node to obtain the attention value combination [29.74, 27.87, 24.04, 18.05, 13.95]. Figure 8 , the Q parameter combination of user C [3.38; 1.95] is multiplied by the transposed matrix K' of the K value combination of each edge node to obtain the attention value combination [7.90, 7.13, 7.07, 5.66, 2.84].
[0075] like Figure 9, this application then performs a Box-Cox transformation on user A's attention value combination, obtaining a transformation parameter λ value of 1.257. The corresponding transformation parameter λ value for user B's attention value combination is 1.399, and the transformation parameter λ value for user C is 2.567. Because the transformation parameter λ value is proportional to the normal transformability of the data, the normal transformation probability of the attention value combination of users A and B is only half that of user C. Therefore, the attention value distribution of users A and B is more uniform than that of user C, and their content request traffic is not regional. This application identifies them as suspicious users, while user C is a normal user.
[0076] In some embodiments, step S2 obtains the frequent item sets and target item sets requested by the user, including: determining the frequent item sets based on content popularity, edge cache node information, and requested content information; analyzing the combination of content popularity, edge cache node information, and requested content to identify frequently occurring combinations, focusing on abnormal request patterns, and laying the foundation for subsequent cache pollution attack identification. Determining the target item set based on the frequent item sets and cache hit rate. Determining the target item set based on changes in the frequent item sets and cache hit rate is used to quantify the impact of cache pollution attacks, refine the identification of cache pollution attacks, and further confirm the existence of attacks through changes in cache hit rates.
[0077] For example, the present application then identifies the impact of user A's content request across edge nodes on the cache hit rate of edge nodes. Figure 10 As shown in the figure, the content popularity (%) and content-related cache hit rate (%) in the system are converted into corresponding file numbers. Figure 11 Suspicious user A repeatedly requested low-popularity content L with a score of 28.71% and low-popularity content M with a score of 27.66% at edge nodes X and Y in chronological order. During this period, the content-related cache hit rate of the edge cache node increased from 6 to 7, which is consistent with the characteristics of cache pollution attackers occupying edge cache space by repeatedly requesting low-popularity content while increasing the cache hit rate.
[0078] This application analyzes the association rules of the content popularity, edge node information of the loaded content, and the requested content information in the content request initiated by the suspected user. Figure 12 From the 16 groups of 3 items related to user A and user B, select the frequent itemsets whose support is greater than the mean 0.06, that is, Figure 12As shown in the figure, {3rd file -> X -> content L}, {3rd file -> Y -> content M}, {8th file -> X -> content D}, and {8th file -> Y -> content C}. Among them, the target item set (subset) after the association cache hit rate of the frequent 3-item set {3rd file -> X -> content L} related to suspicious user A includes {6th file} and {7th file}, and the subset of the frequent 3-item set {3rd file -> Y -> content M} includes {6th file} and {7th file}.
[0079] In some embodiments, step S3 calculates the position codes of the merged frequent item sets and the multiple different target item sets according to the time sequence of the multiple target item sets to obtain multiple merged position codes, including:
[0080] Frequent item sets and multiple target item sets are combined into a target sequence. According to the target sequence, one-hot encoding and the third weight matrix, the word segmentation encoding of the frequent item sets and the multiple target item sets is determined, where the first element of the target sequence is the frequent item set, and the subsequent elements are multiple target item sets arranged in chronological order; for example, the target sequence is {frequent item set, target sequence 1, target sequence 2}, where the chronological order of target sequence 1 is before that of target sequence 2.
[0081] Based on the word segmentation codes and their positional values, the positional codes of the frequent itemsets and multiple target itemsets are determined. The target itemsets are then merged with the frequent itemsets in their chronological order to generate a merged positional code. The frequent itemsets and target itemsets use different one-hot encodings, combined with a third weight matrix to determine their respective word segmentation codes. This quantifies the semantic features of the sequence elements and facilitates further processing. By merging the positional codes, the ongoing impact of cache pollution attacks on cache status is assessed, ensuring the effectiveness of defense strategies.
[0082] In some embodiments, step S4 determines the cumulative increasing number of the position codes requested by the user based on the position codes of the frequent itemsets and the multiple merged position codes, including: performing a first judgment and a second judgment in sequence to obtain the cumulative increasing number, wherein, if the judgment result of the first judgment indicates that the condition is satisfied, the cumulative increasing number of the merged position codes is increased by 1, and if the judgment result of the first judgment indicates that the condition is not satisfied, the cumulative increasing number of the merged position codes is decreased by 1; if the judgment result of the second judgment indicates that the condition is satisfied, the cumulative increasing number of the merged position codes is increased by 1, and if the judgment result of the second judgment indicates that the condition is not satisfied, the cumulative increasing number of the merged position codes is decreased by 1, wherein the first judgment is: determining whether the sum of the merged position codes of the first target item set and the frequent item set is greater than the position code of the frequent item set; and the second judgment is: determining whether the merged position code of the second target item set and the frequent item set is greater than the merged position code of the first target item set and the frequent item set.
[0083] In the case of two target item sets, the first target item set and the second target item set are sequentially sorted in chronological order. First, the position code of the first target item set is added to the position code of the frequent itemset to obtain a first merged position code. The first merged position code is compared with the position code of the frequent itemset. If the first merged position code is greater than the position code of the frequent itemset, the cumulative increment count is increased by 1; if the first merged position code is less than the position code of the frequent itemset, the cumulative increment count is decreased by 1. Then, the position code of the second target item set is added to the position code of the frequent itemset to obtain a second merged position code. The second merged position code is compared with the position code of the frequent itemset. If the second merged position code is greater than the position code of the frequent itemset, the cumulative increment count is increased by 1; if the second merged position code is less than the position code of the frequent itemset, the cumulative increment count is decreased by 1. By calculating the cumulative increment count, continuous monitoring and identification of cache pollution attacks are ensured.
[0084] Example 1
[0085] This application then analyzes the cumulative increase in the position encoding when the frequent item sets related to user A are combined with different subsets, and extracts the persistence characteristics of the abnormal state caused by the cache pollution attack on the edge cache node. Figure 13 Taking the sequence of {3rd gear->X->content L} and its subsets {6th gear} and {7th gear} of suspicious user A as an example, first perform the position coding conversion of the first bit {3rd gear->X->content L}, and multiply the one-hot coding [1, 0, 0] with the universal third weight matrix [2.66; 1.91; 2.16] to obtain the word segmentation code 2.66, and then add it to the position value 0.9 to obtain the position code PE0=3.56. Then, the second bit of {6th gear}’s one-hot coding [0, 1, 0] is multiplied with the same third weight matrix to obtain the word segmentation code 1.91, and then added with the position value -0.88 to obtain PE1=1.03. Finally, the third bit of {7th gear}’s one-hot coding [0, 0, 1] is multiplied with the third weight matrix to obtain the word segmentation code 2.16, and then added with the position value 0.1 to obtain PE2=2.26. As Figure 14 , the combined position code PE3 of the subset {6-fold} and the frequent item set after merging is 4.59, and the combined position code PE4 of the subset {7-fold} after merging is 5.82. In chronological order, the position code PE0 of user A's frequent item set {3-fold -> X -> content L} combined with the position code PE1 of the first subset {6-fold} is greater than the position code PE0 of the frequent item set itself, so the cumulative increment number n = 1. Similarly, the position code PE0 of user A's frequent item set {3-fold -> X -> content L} combined with the position code PE2 of the second subset {7-fold} is greater than the position code PE3 of the frequent item set combined with the first subset {6-fold}, so the cumulative increment number n = 2.
[0086] like Figure 14 When another frequent item set of suspicious user A, {3-fold -> Y -> content M}, is sequenced with the subsets {6-fold} and {7-fold}, its own position code PE5 = 1.76, its subset {6-fold} receives a position code PE6 = 2.33, and the other subset {7-fold} receives a position code PE7 = 2.6. The position code PE8 of the combined subset {6-fold} and the frequent item set is 4.09, and the position code PE9 of the combined subset {7-fold} is 4.36. Therefore, the position code PE8 = 4.09 of the combined subset {6-fold} and the frequent item set is greater than the position code PE5 of the frequent item set itself, while the position code PE9 = 4.36 of the combined subset {7-fold} and the frequent item set is greater than the position code PE8 = 4.09 of the combined subset {6-fold} and the frequent item set. Therefore, both the subsets {6-fold} and {7-fold} have an incremental effect on the chronologically preceding position codes PE5 and PE8, resulting in a cumulative number of incremental increases n = 2. Since the cumulative increment times n brought by the frequent item set subset related to user A to the frequent item set are all > 0, attacker A's repeated request for content L from cache node X and content M from cache node Y constitutes a cache pollution attack.
[0087] Example 2
[0088] This embodiment, based on embodiment 1, identifies the impact of suspicious user B's content requests across edge nodes on the cache hit rate of edge nodes. Take the sequence of the frequent item set {8 files -> X -> content D} and its subsets {6 files} and {5 files} of suspicious user B as an example. Figure 15 In this embodiment, the first position code conversion of the first position {8 gear -> X -> content D} in the sequence is performed, and the word segmentation code 2.66 is obtained by multiplying the one-hot code [1, 0, 0] with the universal third weight matrix [2.66; 1.91; 2.16], and then adding it to the top position value 0.14 in another cosine wave combination to obtain the position code PE0'=2.8. Then, the second position {6 gear}'s one-hot code [0, 1, 0] is multiplied by the third weight matrix to obtain the word segmentation code 1.91, and then added to the middle position value -0.27 to obtain PE1'=1.64. Finally, the third position {5 gear}'s one-hot code [0, 0, 1] is multiplied by the weight matrix to obtain the word segmentation code 2.16, and then added to the bottom position value -0.84 to obtain PE2'=1.32. After the subset {6-level} is merged with the frequent item set, the position code PE3'=4.44 has an incremental effect on the PE0' of the frequent item set once. After the subset {5-level} is merged with the frequent item set, the position code PE4'=4.12 has an incremental effect of -1 compared to PE3'. Therefore, the cumulative number of incremental times n=1-1=0, and the hit rate of edge cache X has decreased during the process of user B requesting content.
[0089] like Figure 16 , after the sequence of another frequent item set {8-level -> Y -> content C} for suspicious user B and the subsets {6-level}, {5-level}, and {4-level} is formed, its one-hot code [1, 0, 0, 0] is multiplied by the corresponding third weight matrix [2.66; 1.91; 2.16; 1.76] to obtain the word segmentation code 2.66, which is then added to the top position value -0.34 in the next group of position values in the cosine wave combination to obtain the position code PE5' = 2.32. Then, the second position code of {6-level} [0, 1, 0, 0] is multiplied by the weight matrix to obtain the word segmentation code 1.91, which is then added to the second position value 0.87 to obtain PE6' = 2.78. The third position code of {5-level} [0, 0, 1, 0] is multiplied by the weight matrix to obtain the word segmentation code 2.16, which is then added to the position value -0.11 of the third position code to obtain PE7' = 2.05. The fourth position's one-hot encoding ([0, 0, 0, 1]) of {4th position} is multiplied by the weight matrix to obtain a word segmentation encoding of 1.76. This is then added to the position value of the fourth position encoding (0.29) to obtain PE8' = 2.05. The position encoding of the combined subset {6th position} and the frequent item set is PE9' = 5.1, which increases by 1 compared to PE5' of the frequent item set. The position encoding of the combined subset {5th position} and the frequent item set is PE10' = 4.37, which increases by -1 compared to the previous position encoding PE9' in the time series. The position encoding of the combined subset {4th position} and the frequent item set is PE11' = 4.37, which remains unchanged compared to PE10'. Therefore, the cumulative number of increments n = 1 - 1 + 0 = 0. During user B's content request, the hit rate of edge cache Y decreased.
[0090] Since the incremental cumulative times n brought by the frequent item set subset related to user B are all <= 0, user B's repeated request for content D from cache node X and content C from cache node Y are normal behaviors, and the edge cache hit rate has decreased due to the influence of attacker A.
[0091] in Figures 13 to 16 The colors of the waveforms in the diagram correspond to the position values. For example, the position value corresponding to the red waveform is the red number 0.9, the position value corresponding to the blue waveform is the blue number 0.1, and the position value corresponding to the yellow waveform is the yellow number 0.29.
[0092] Examples 1 and 2 compare the popularity of content related to users A and B with the number of position code increments during the merge of frequent item sets and subsets of edge cache nodes. Content with increments greater than 0 is identified as content controlled by an attack. This application can identify the persistence of abnormal edge cache node states caused by cache pollution attacks, covering more comprehensive attack characteristics.
[0093] Existing technologies stop updating the popularity of content corresponding to malicious interest packets identified by federated learning algorithms, and replace them with a cache strategy after natural decay. This application actively reduces the popularity of content by using the cumulative number of increments, support values, and weights composed of regional feature values of the association rule frequent item set subset, and logarithmic deviation values, and then replaces the controlled content with a cache strategy.
[0094] As the number of increments increases, the impact of frequent item sets on the degree of content contamination is further amplified. Therefore, if the judgment is still made based on the previously fixed weights, the contaminated information will be missed. The popularity of the content needs to be re-determined. In some embodiments, the detection method also includes: determining the target cache contamination information manipulated by the suspicious user based on the content popularity of the suspicious user and the edge cache node information of the current CDN network; determining the preset weight based on the cumulative number of increments of the position encoding of the target cache contamination information; and determining the content popularity of the target cache contamination information based on at least the preset weight. Through in-depth data analysis and dynamic weight adjustment, the detection accuracy and response speed of cache contamination attacks are greatly improved. The adjusted weights and deviation values are not fixed values. According to the polarization of the intrinsic attributes of attackers and normal users, the problem of accidental deletion will not occur, which effectively avoids misjudgment and missed judgment, and ensures the efficient operation of the CDN network and the user service experience.
[0095] In some embodiments, determining the content popularity of the target cache pollution information at least based on a preset weight includes: determining the adjusted content popularity of the target cache pollution information based on the preset weight and a first formula, where the first formula is: Among them, P(ci) is the content popularity of the target cache pollution information after adjustment, P'(ci) is the original content popularity of the target cache pollution information, S n is the preset weight, n is the cumulative number of increments of the location encoding of the target cache pollution information, λ A is the regional characteristic value of user A, λ B is the regional characteristic value of user B. By combining support, increment count, and weighted calculations based on user regional characteristics, content popularity can be dynamically updated, reducing the impact of attacked content without impacting legitimate content. Detailed traffic and cache status analysis distinguishes between legitimate business and malicious attacks, and by adjusting content popularity in real time, it prevents undue usage of edge caches, thereby maintaining the proper allocation of network resources and ensuring security.
[0096] Example 3
[0097] This embodiment adjusts the content popularity of users A and B based on the frequent item set features based on the first and second embodiments. This embodiment forms a weight based on the cumulative increment number n of the frequent item set position code brought by the subset of the frequent three-item set and the frequent item set support S to reduce the popularity of the content controlled by the attacker. The expression of the adjusted content popularity score is: like Figure 17 , ( Figure 17 The red area represents content related to attackers or suspicious users, while the green area represents content related to normal users. The support value S1 for {3rd tier -> X -> content L} related to attacker A is 0.0952. The positional encoding after merging with its subsets {6th tier} and {7th tier} has a cumulative increase of 2 times relative to the frequent item set, with n = 2. Furthermore, attacker A's regional eigenvalue λA = 1.256, while that of normal user B is λB = 1.399. Therefore, the adjusted popularity score for the frequent item related to content L is 28.71 × 0.095. 2 +log2(1.256 / 1.399)=0.2496-0.15=0.1091, almost zero.
[0098] Similarly, the support value S2 of {3-fold -> Y -> content M} is 0.0952, and the position code after merging with its subsets {6-fold} and {7-fold} has increased by 2 times relative to the frequent item set, n = 2. Combined with the regional characteristic values λA = 1.256 and λB = 1.399, the adjusted popularity score of the frequent item related content M = 27.66 × 0.0952 2 +log2(1.256 / 1.399)=0.2591-0.15=0.0996, which is almost zero. The system's caching strategy can replace content L in edge cache X and content M in edge cache Y with content of any popularity.
[0099] Another example Figure 17 , the support value S15 of the frequent item set {8-file -> X -> content D} related to normal user B is 0.0952, and the position code after merging with its subsets {6-file} and {5-file} has accumulated 0 increments relative to the frequent item set, n = 0. Therefore, combined with the regional characteristic values λA = 1.256 and λB = 1.399, the expression for the adjusted popularity score of the frequent item related to content D is 75.17 × 0.0952 0+log2(1.399 / 1.256)=75.17+0.156=75.326, where n is the number of position code increments, and the score remains unchanged. The support value S16 of the frequent item set {8-fold -> Y -> content C} associated with normal user B is 0.1429. The position code after merging with its subsets {6-fold}, {5-fold}, and {4-fold} has a cumulative increment of 0 times relative to the frequent item set, and n=0. Therefore, the adjusted popularity score of content C associated with the frequent item set is 72.19×0.1429. 0 +log2(1.399 / 1.256)=72.19+0.156=75.346, where n is the number of position code increments and the score remains unchanged. The system's caching strategy temporarily retains content D in edge cache X and content C in edge cache Y until a higher-scoring content is found.
[0100] In embodiment 3, the weight value used to adjust the content popularity includes the association rule support value of the user content request traffic across the edge cache nodes and the cumulative increment times of the position code when the frequent item set is merged into a subset.
[0101] The following introduces a device for determining a cache pollution attack on a CDN network provided in an embodiment of the present application.
[0102] Figure 18 Schematic diagram of a device for determining a cache pollution attack of a CDN network according to an embodiment of the present application. Figure 18 As shown, the device includes: a first acquisition module 10, used to obtain multiple user requests in the CDN network and determine suspicious users, where the user request includes at least: requested content information, content popularity, cache hit rate and edge cache node information; a second acquisition module 20, used to obtain frequent item sets and target item sets of the user request, wherein one user request corresponds to one frequent item set and multiple target item sets, and the target item set is used to characterize the level of cache hit rate of the user request; a first determination module 30, used to calculate the position code of the frequent item set and multiple different target item sets after merging according to the time sequence of the multiple target item sets to obtain multiple merged position codes; a second determination module 40, used to determine the cumulative increment times of the position code of the user request based on the position code of the frequent item set and the multiple merged position codes, and when the cumulative increment times is greater than 0, it is determined that the user request is cache pollution information and the CDN network is attacked.
[0103] Through this embodiment, a first acquisition module first acquires multiple user requests in the CDN network and identifies suspicious users. The user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information. A second acquisition module acquires frequent itemsets and target itemsets of the user requests, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemsets are used to characterize the cache hit rate level of the user request. The first determination module calculates the position codes of the frequent itemsets merged with multiple different target itemsets in chronological order to obtain multiple merged position codes. The second determination module determines the cumulative increment count of the position codes of the user requests based on the position codes of the frequent itemsets and the multiple merged position codes. If the cumulative increment count is greater than 0, the user request is determined to be cache contamination information, and the CDN network is determined to be under attack. The above method calculates the merged position codes of the frequent itemsets and target itemsets in chronological order, and records the cumulative increment count n of the merged position codes of the frequent itemsets merged with different target itemsets. Content with an increment count greater than 0 is identified as content controlled by a malicious user. The increment count indicates the persistence of abnormal edge cache node conditions caused by cache pollution attacks, enabling comprehensive detection of cache pollution attacks on CDN networks. This addresses the technical issue of existing cache pollution attack detection technologies being unable to comprehensively detect attack conditions.
[0104] An embodiment of the present application provides a computer-readable storage medium, which includes a stored program. When the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for detecting cache pollution attacks in the CDN network.
[0105] Specifically, the detection method for cache pollution attacks on CDN networks includes:
[0106] Step S1: Obtain multiple user requests in the CDN network and identify suspicious users. The user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information;
[0107] Step S2, obtaining the frequent itemsets and target itemsets requested by the user, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemset is used to characterize the cache hit rate level of the user request;
[0108] Step S3, calculating the position codes of the frequent item sets and the multiple different target item sets merged according to the time sequence of the multiple target item sets to obtain multiple merged position codes;
[0109] Step S4: Determine the cumulative increment times of the position codes requested by the user based on the position codes of the frequent itemsets and the multiple merged position codes. If the cumulative increment times are greater than 0, determine that the user request is cache pollution information and determine that the CDN network is attacked.
[0110] An embodiment of the present application provides an electronic device, comprising a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, at least the following steps are performed:
[0111] Methods for detecting cache pollution attacks on CDN networks include:
[0112] Step S1: Obtain multiple user requests in the CDN network and identify suspicious users. The user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information;
[0113] Step S2, obtaining the frequent itemsets and target itemsets requested by the user, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemset is used to characterize the cache hit rate level of the user request;
[0114] Step S3, calculating the position codes of the frequent item sets and the multiple different target item sets merged according to the time sequence of the multiple target item sets to obtain multiple merged position codes;
[0115] Step S4: Determine the cumulative increment times of the position codes requested by the user based on the position codes of the frequent itemsets and the multiple merged position codes. If the cumulative increment times are greater than 0, determine that the user request is cache pollution information and determine that the CDN network is attacked.
[0116] The electronic devices in this article can be servers, PCs, PADs, mobile phones, etc.
[0117] The present application also provides a computer program product, which, when executed on a data processing device, is adapted to execute a program for initializing at least the following method steps:
[0118] Methods for detecting cache pollution attacks on CDN networks include:
[0119] Step S1: Obtain multiple user requests in the CDN network and identify suspicious users. The user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information;
[0120] Step S2, obtaining the frequent itemsets and target itemsets requested by the user, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemset is used to characterize the cache hit rate level of the user request;
[0121] Step S3, calculating the position codes of the frequent item sets and the multiple different target item sets merged according to the time sequence of the multiple target item sets to obtain multiple merged position codes;
[0122] Step S4: Determine the cumulative increment times of the position codes requested by the user based on the position codes of the frequent itemsets and the multiple merged position codes. If the cumulative increment times are greater than 0, determine that the user request is cache pollution information and determine that the CDN network is attacked.
[0123] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices, they can be implemented using program code executable by the computing device, and thus, they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be performed in a different order than herein, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present application is not limited to any specific combination of hardware and software.
[0124] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0125] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0126] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0127] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0128] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0129] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0130] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0131] The method for detecting a cache pollution attack in a CDN network, the device for detecting a cache pollution attack in a CDN network, the computer-readable storage medium, and the electronic device described above in this application can achieve the following beneficial effects:
[0132] 1) A method for detecting cache pollution attacks in CDN networks calculates the merged position codes of frequent itemsets and target itemsets in chronological order and records the cumulative number of increments n of the merged position codes after merging the frequent itemsets with different target itemsets. Content with an increment count > 0 is identified as content controlled by a malicious user. The increment count can indicate the persistence of abnormal conditions at edge cache nodes caused by cache pollution attacks, enabling comprehensive detection of cache pollution attacks in CDN networks. This method addresses the technical problem in existing cache pollution attack detection techniques that cannot comprehensively detect attack conditions.
[0133] 2) Through in-depth data analysis and dynamic weight adjustment, the detection accuracy and response speed of cache pollution attacks are greatly improved. The adjusted weights and deviation values are not fixed values. They are polarized according to the intrinsic attributes of attackers and normal users, preventing accidental deletions. This effectively avoids misjudgments and missed judgments, ensuring the efficient operation of the CDN network and the user service experience.
[0134] 3) The detection method of the present application obtains the target feature matrix of the user request in the process of confirming the suspicious user, and determines whether the target feature matrix contains regional features. In this way, the target feature matrix can be distributed as an importance feature index for identification. The content with regional features is normal, and the rest of the content is identified as problematic content without regional features. The user corresponding to the content is identified as a malicious user, which improves the ability to analyze the regional features of user requests, so that the detection method of the present application has the targeted detection capability of cache pollution attacks.
[0135] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0136] The foregoing description is merely a preferred embodiment of the present application and is not intended to limit the present application. Persons skilled in the art will readily appreciate that various modifications and variations are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present application shall be included within the scope of protection of the present application.
Claims
1. A method for detecting cache pollution attacks in a CDN network, characterized in that: include: Obtain multiple user requests in the CDN network and identify suspicious users, wherein the user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information; Obtaining a frequent itemset and a target itemset of the user request, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemset is used to represent the level of the cache hit rate of the user request; Calculating the position codes of the frequent item set and the multiple different target item sets merged according to the time sequence of the multiple target item sets to obtain multiple merged position codes; The cumulative increment times of the position codes of the user requests are determined according to the position codes of the frequent itemsets and the multiple merged position codes. If the cumulative increment times are greater than 0, it is determined that the user request is cache pollution information and the CDN network is attacked.
2. The detection method according to claim 1, wherein Obtain user requests from multiple users in the CDN network and identify suspicious users, including: Generate a first word embedding vector matrix based on the content information of the request; Determine a reference vector matrix based on the first word embedding vector matrix and the first weight matrix; Generate a second word embedding vector matrix according to the edge cache node information; Determine a target vector matrix based on the second word embedding vector matrix and the second weight matrix; Determining a target feature matrix based on the reference vector matrix and the target vector matrix; Determine whether the target feature matrix includes regional features. If the target feature matrix does not include the regional features, determine that the user is the suspicious user. Including the regional features indicates that the target feature matrix has normal convertibility higher than a preset conversion possibility.
3. The detection method according to claim 1, wherein The obtaining of the frequent itemsets and target itemsets requested by the user includes: determining the frequent itemsets according to the content popularity, the edge cache node information, and the requested content information; The target itemset is determined according to the frequent itemset and the cache hit rate.
4. The detection method according to claim 1, wherein The step of calculating the position codes of the frequent item set and the multiple different target item sets merged according to the time sequence of the multiple target item sets to obtain multiple merged position codes includes: The frequent itemset and the multiple target itemsets are combined into a target sequence, and word segmentation codes of the frequent itemset and the multiple target itemsets are determined according to the target sequence, the one-hot encoding, and a third weight matrix, wherein the first element of the target sequence is the frequent itemset, and the subsequent elements are the multiple target itemsets arranged in the chronological order; Determining position codes of the frequent item sets and the plurality of target item sets according to the word segmentation codes and the position values of the word segmentation codes; According to the time sequence of the multiple target item sets, the multiple target item sets are merged with the frequent item set to obtain a merged position code.
5. The detection method according to claim 4, characterized in that The determining, based on the position code of the frequent item set and the plurality of merged position codes, the cumulative increasing times of the position code requested by the user includes: The first judgment and the second judgment are performed in sequence to obtain the cumulative number of increments, wherein, when the judgment result of the first judgment indicates that the condition is satisfied, the cumulative number of increments of the merged position code is determined to be plus 1, and when the judgment result of the first judgment indicates that the condition is not satisfied, the cumulative number of increments of the merged position code is determined to be minus 1; when the judgment result of the second judgment indicates that the condition is satisfied, the cumulative number of increments of the merged position code is determined to be plus 1, and when the judgment result of the second judgment indicates that the condition is not satisfied, the cumulative number of increments of the merged position code is determined to be minus 1. The first judgment is to judge whether the sum of the combined position codes of the first target item set and the frequent item set is greater than the position code of the frequent item set; the second judgment is to judge whether the combined position code of the second target item set and the frequent item set is greater than the combined position code of the first target item set and the frequent item set.
6. The detection method according to claim 1, characterized in that The detection method further comprises: Determining target cache pollution information manipulated by the suspicious user based on the content popularity of the suspicious user and the edge cache node information of the current CDN network; Determining a preset weight according to the cumulative number of increments of the position code of the target cache pollution information; The content popularity of the target cache pollution information is determined at least according to the preset weight.
7. The detection method according to claim 6, characterized in that The determining, at least according to the preset weight, the content popularity of the target cache pollution information includes: The adjusted content popularity of the target cache pollution information is determined according to the preset weight and a first formula, where the first formula is: Wherein, P(ci) is the content popularity of the target cache pollution information after adjustment, P'(ci) is the original content popularity of the target cache pollution information, S n is the preset weight, n is the cumulative number of increments of the position encoding of the target cache pollution information, λ A is the regional characteristic value of user A, λ B is the regional characteristic value of user B.
8. A device for determining cache pollution attacks in a CDN network, characterized in that: The method for detecting a cache pollution attack in a CDN network according to any one of claims 1 to 7, wherein the device for determining a cache pollution attack in the CDN network comprises: A first acquisition module is configured to acquire multiple user requests in the CDN network and determine suspicious users, wherein the user requests include at least: requested content information, content popularity, cache hit rate, and edge cache node information; A second acquisition module is configured to acquire a frequent itemset and a target itemset of the user request, wherein one user request corresponds to one frequent itemset and multiple target itemsets, and the target itemset is used to represent the cache hit rate level of the user request; A first determining module is configured to calculate, according to the time sequence of the plurality of target item sets, a position code after the frequent item set is merged with a plurality of different target item sets to obtain a plurality of merged position codes; The second determination module is used to determine the cumulative increasing number of the position code of the user request based on the position code of the frequent item set and the multiple merged position codes. When the cumulative increasing number is greater than 0, it is determined that the user request is cache pollution information and the CDN network is attacked.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored program, wherein when the program is executed, the device where the computer-readable storage medium is located is controlled to execute the method for detecting cache pollution attacks in a CDN network according to any one of claims 1 to 7.
10. An electronic device, characterized in that: include: One or more processors, a memory, and one or more programs, wherein the one or more programs are stored in the memory and configured to be executed by the one or more processors, and the one or more programs include a method for detecting a cache pollution attack in a CDN network according to any one of claims 1 to 7.