Bitcoin P2P (Peer-to-Peer) network defense strategy generation method and device, equipment and storage medium

By interacting with the Bitcoin P2P network to obtain information and analyze and generate defense strategies, the security threat problem of the Bitcoin P2P network is solved, active defense and timely response are achieved, and the security and availability of the network are improved.

CN120474806APending Publication Date: 2025-08-12XIAN JIAOTONG LIVERPOOL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510746632.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

Bitcoin P2P networks face security threats such as solar eclipse attacks, network partition attacks, witch attacks and denial of service attacks. The existing defense methods mainly rely on passive detection, making it difficult to prevent and mitigate security threats in a timely manner.

Method used

By interacting with the target nodes in the Bitcoin P2P network, the interaction log, other peer node address information and the latest block header information are obtained, and the large language model is used to analyze this information to generate defense strategies to achieve active detection and timely response.

Benefits of technology

It realizes active defense of the Bitcoin P2P network, which can timely prevent and mitigate security threats and improve the security and availability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474806A_ABST
    Figure CN120474806A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of block chains, in particular to a Bitcoin P2P network defense strategy generation method and device, equipment and a storage medium, and the method comprises the steps: carrying out the interaction with a target node in a Bitcoin P2P network, and obtaining an interaction log, the address information of other peer nodes provided by the target node, and the latest block header information; determining a node address anomaly judgment result based on the other peer node address information, and determining a block header anomaly judgment result based on the latest block header information; generating a Bitcoin P2P network defense strategy based on the interaction log, the node address abnormity judgment result and the block head abnormity judgment result; according to the invention, the Bitcoin P2P network can conveniently and timely prevent and relieve security threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of blockchain technology, and in particular to a method, apparatus, device, and storage medium for generating a Bitcoin P2P network defense strategy. Background Art

[0002] The Bitcoin P2P network consists of multiple permissionless nodes that communicate through the Bitcoin protocol to verify, propagate, and record transactions. As the Bitcoin P2P network ecosystem continues to expand, it faces increasing security threats, such as eclipse attacks, which hijack all peer connections of a target node, preventing it from receiving authentic information from the network, leading to transaction manipulation and double-spending attacks. Partitioning attacks, which manipulate network routing to fragment the topology of the Bitcoin P2P network, preventing some nodes from syncing with the latest block information. Sybil attacks, which create multiple fake identities to undermine the trust mechanism of the Bitcoin P2P network. Furthermore, attackers can exploit the Bitcoin P2P network's peer connection strategy to conduct connection manipulation attacks (ConMan attacks) or launch denial-of-service attacks (DoS attacks) through resource exhaustion strategies. These various attack methods not only threaten the availability of the Bitcoin P2P network but can also lead to serious consequences such as transaction tampering and privacy leaks.

[0003] To address these various security threats, the Bitcoin Core development team has introduced several defense mechanisms. For example, improved peer selection and connection management methods are used to mitigate eclipse attacks. Furthermore, the Bitcoin P2P network has introduced a penalty mechanism to detect and punish malicious nodes.

[0004] However, the current defense measures of the Bitcoin P2P network mainly rely on passive detection and response to attacks. This method detects attacks only after they occur, making it difficult to prevent and mitigate security threats in a timely manner. Summary of the Invention

[0005] In order to facilitate the timely prevention and mitigation of security threats in the Bitcoin P2P network, the present application provides a Bitcoin P2P network defense strategy generation method, apparatus, device, and storage medium.

[0006] In a first aspect, the present application provides a method for generating a Bitcoin P2P network defense strategy, comprising:

[0007] Interact with the target node in the Bitcoin P2P network to obtain the interaction log, the address information of other peer nodes provided by the target node, and the latest block header information;

[0008] Determine a node address anomaly judgment result based on the other peer node address information, and determine a block header anomaly judgment result based on the latest block header information;

[0009] A Bitcoin P2P network defense strategy is generated based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0010] In a second aspect, the present application provides a Bitcoin P2P network defense strategy generation device, comprising:

[0011] A lightweight node is used to interact with a target node in the Bitcoin P2P network to obtain interaction logs, address information of other peer nodes provided by the target node, and the latest block header information;

[0012] A detection engine, configured to determine a node address anomaly determination result based on the other peer node address information, and a block header anomaly determination result based on the latest block header information;

[0013] The anomaly analyzer generates a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0014] In a third aspect, the present application provides a computer device, which includes a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps in the above method when executing the computer program.

[0015] In a fourth aspect, the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the steps in the above-mentioned method when executed by a processor.

[0016] In a fifth aspect, the present application further provides a computer program product, which includes a computer program that implements the steps of any of the above method embodiments when executed by a processor.

[0017] The above-mentioned Bitcoin P2P network defense strategy generation method, device, equipment and storage medium interact with the target node in the Bitcoin P2P network to obtain the interaction log, the address information of other peer nodes provided by the target node and the latest block header information; determine the node address anomaly judgment result based on the other peer node address information, and determine the block header anomaly judgment result based on the latest block header information; generate the Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result and the block header anomaly judgment result; through the above implementation, the interaction log, other peer node address information and the latest block header information can be obtained by actively interacting with the target node in the Bitcoin P2P network. Peer node address information and the latest block header information, the interaction log records events where the target node has abnormal behavior, and by analyzing the address information of other peer nodes and the latest block header information, the data anomalies contained therein can be determined. Finally, by analyzing the abnormal behavior events and the analyzed data anomalies in the interaction log, a Bitcoin P2P network defense strategy can be generated; this application actively interacts with the target node in the Bitcoin P2P network, thereby realizing active detection in the defense process, and immediately generating a corresponding Bitcoin P2P network defense strategy when an anomaly is detected, so as to facilitate the Bitcoin P2P network to prevent and mitigate security threats in a timely manner.

[0018] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 A flowchart of a method for generating a Bitcoin P2P network defense strategy provided in an embodiment of the present application;

[0021] Figure 2 This is a structural diagram of a Bitcoin P2P network defense strategy generation device provided in an embodiment of the present application;

[0022] Figure 3 This is a schematic diagram of the structure of another Bitcoin P2P network defense strategy generation device provided in an embodiment of the present application;

[0023] Figure 4A schematic diagram of the structure of a computer device provided in an embodiment of the present application;

[0024] Figure 5 This is a diagram of the internal structure of a computer-readable storage medium provided in an embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solutions and advantages of the present disclosure more clearly understood, the present disclosure is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present disclosure and are not intended to limit the present disclosure.

[0026] It should be noted that the terms "first," "second," and the like in the specification and claims herein and in the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," as well as any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or device comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to these processes, methods, products, or devices.

[0027] In this document, the term "and / or" simply describes a relationship between related objects, indicating that three possible relationships exist. For example, "A and / or B" could mean: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates an "or" relationship between the related objects.

[0028] Example 1

[0029] Figure 1 This is a flowchart of a method for generating a Bitcoin P2P network defense strategy provided in Example 1 of this application, refer to Figure 1 The method may be performed by a device for performing the method, and the device may be implemented by software and / or hardware. The method includes:

[0030] S110: interact with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information.

[0031] Among them, the Bitcoin P2P network is a decentralized distributed network composed of numerous nodes (computers). These nodes are interconnected and communicated through specific protocols and technologies, and jointly maintain an unalterable distributed ledger; in other embodiments, the Bitcoin P2P network can also be other networks based on P2P protocols, which are not specifically limited.

[0032] In order to achieve active defense of the Bitcoin P2P network, this application adopts a method of actively interacting with each node in the Bitcoin P2P network; in order to achieve active interaction with the Bitcoin P2P network, this embodiment provides a lightweight honeypot, which includes a lightweight node. The lightweight node is used to disguise itself as a node in the Bitcoin P2P network and actively interact with nodes in the Bitcoin P2P network. The node with which the lightweight node actively interacts in the Bitcoin P2P network is recorded as a target node, and there are generally multiple target nodes.

[0033] Taking one of the target nodes as an example, the lightweight node interacts with the target node, that is, the lightweight node actively sends a message to the target node, and the target node sends a corresponding reply message to the lightweight node. Exemplarily, the lightweight node first determines an online node in the Bitcoin P2P network through a preset website and uses it as the target node. Taking one of the target nodes as an example, the lightweight node actively sends an ICMP ECHO message to the target node. In response to receiving an ICMP REPLY message corresponding to the ICMP ECHO message, it is determined that the target node is currently online, which also indicates that it is currently possible to actively interact with the target node. In order to interact with the target node, it is necessary to first establish a TCP connection with the target node at the network layer. If the TCP connection is not successfully established, a reconnection is performed. The upper limit of the number of reconnections ranges from 3 to 10 times, and the upper limit of the number of reconnections is not specifically limited.

[0034] In response to the successful establishment of a TCP connection with the target node, the next step is to try to establish a session (Application Layer Session) with the target node at the application layer. The process of establishing a session is: the lightweight node first sends a VERSION message to the target node, and the target node then sends a VERSION message and a VERACK message to the lightweight node in turn, and then the lightweight node sends a VERACK message to the lightweight node, thereby establishing a session. It should be noted that during the process of establishing a session, if the target node does not respond to the message sent by the lightweight node, the target node will resend the message every 5 seconds, and the upper limit of the number of resending messages is 3-5 times, and the upper limit of the number of resending messages is not specifically limited; if the upper limit of the number of resending messages is reached and the target node still does not respond, the abnormal event will be recorded in the preset log. It should be noted that the log will record all events that occur during the interaction between the lightweight node and the target node, such as the time when the lightweight node sends or receives a message, the type of message sent or received, the content of the message sent or received, etc., and the log will be recorded as an interaction log.

[0035] In response to the successful establishment of the session, the target node further sends a node address acquisition message GETADDR to the lightweight node. The node address acquisition message GETADDR is used to obtain the addresses of other nodes in the Bitcoin P2P network. Under normal circumstances, the lightweight node will reply with a node address message ADDR corresponding to the node address acquisition message GETADDR, and record the node address message ADDR replied by each target node as the address information of other peer nodes. If the lightweight node does not receive a node address message ADDR replied by the target node after sending the node address acquisition message GETADDR, it will send a node address acquisition message GETADDR to the target node once every 10 seconds, starting from the first sending of the node address acquisition message GETADDR. If the target node fails to successfully reply to the node address message ADDR within 120 seconds, the preset log will record the abnormal event.

[0036] In response to the target node successfully replying to the node address message ADDR within the above 120s, the lightweight node continues to send a block header acquisition message GETHEADERS to the target node. Under normal circumstances, the lightweight node will reply with a block header message HEADERS corresponding to the block header acquisition message GETHEADERS, and the block header message HEADERS replied by each target node will be recorded as the latest block header information; if the lightweight node does not reply with a block header message HEADERS corresponding to the block header acquisition message GETHEADERS, the lightweight node will send a block header acquisition message GETHEADERS to the target node once every 10s, starting from the first sending of the node address acquisition message GETADDR. If the target node does not reply with a block header message HEADERS corresponding to the block header acquisition message GETHEADERS within 120s, the preset log will record the abnormal event.

[0037] It should be noted that during the interaction between the lightweight node and the target node, if the target node does not respond to the message sent by the lightweight node in accordance with the protocol format, the event is considered an abnormal event and will also be recorded in the interaction log.

[0038] S120: Determine a node address abnormality judgment result based on the other peer node address information, and determine a block header abnormality judgment result based on the latest block header information.

[0039] Among them, after obtaining the address information of other peer nodes and the latest block header information through the above steps, it is necessary to perform statistical analysis on the address information of other peer nodes and the latest block header information to determine whether there is any abnormality in the conversion between the address information of other peer nodes and the latest block header information; and the result of the statistical analysis of the address information of other peer nodes is recorded as the node address abnormality judgment result, and the result of the statistical analysis of the latest block header information is also recorded as the block header abnormality judgment result.

[0040] S130. Generate a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0041] Among them, by analyzing the interaction logs, node address anomaly judgment results, and block header anomaly judgment results obtained through the above steps, it is possible to infer the deep-seated reasons behind the anomalies in the Bitcoin P2P network, and after knowing the deep-seated reasons, a corresponding Bitcoin P2P network defense strategy is formulated; in this embodiment, a large language model (LLM) is specifically used to process the interaction logs, node address anomaly judgment results, and block header anomaly judgment results, first determining the deep-seated reasons behind the anomalies in the Bitcoin P2P network, and further generating a corresponding Bitcoin P2P network defense strategy based on the deep-seated reasons.

[0042] It should be noted that this embodiment obtains the interaction log, the address information of other peer nodes provided by the target node and the latest block header information by interacting with the target node in the Bitcoin P2P network; determines the node address anomaly judgment result based on the address information of other peer nodes, and determines the block header anomaly judgment result based on the latest block header information; generates the Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result and the block header anomaly judgment result; through the above implementation, the interaction log, the address information of other peer nodes and the latest block header information can be obtained by actively interacting with the target node in the Bitcoin P2P network. The latest block header information and the interaction log record the event of abnormal behavior of the target node. By analyzing the address information of other peer nodes and the latest block header information, the data anomalies contained therein can be determined. Finally, by analyzing the abnormal behavior events in the interaction log and the analyzed data anomalies, a Bitcoin P2P network defense strategy can be generated. This application actively interacts with the target node in the Bitcoin P2P network, thereby realizing active detection in the defense process and immediately generating a corresponding Bitcoin P2P network defense strategy when an anomaly is detected, so that the Bitcoin P2P network can prevent and mitigate security threats in a timely manner.

[0043] Example 2

[0044] A second embodiment of the present application provides a method for generating a Bitcoin P2P network defense strategy. This method optimizes the "determining a node address anomaly judgment result based on the other peer node address information" in the first embodiment. It should be noted that for portions not described in detail in this embodiment, reference may be made to the descriptions of other embodiments. This method includes:

[0045] S210: interact with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information.

[0046] It should be noted that the address information of other peer nodes includes a reference timestamp and at least one record, wherein the record includes an IP address, a port, and a connection timestamp.

[0047] Among them, if the target node is connected to other nodes in the Bitcoin P2P network, the target node can obtain the IP addresses of other nodes; the lightweight node can obtain the IP addresses of other nodes sent by each target node by interacting with each target node, and the set of IP addresses of other nodes sent by each target node obtained by the lightweight node, the port and connection timestamp corresponding to each IP address, and the reference timestamp set for the set are collectively referred to as other peer node address information; taking one of the IP addresses as an example, the IP address and its corresponding port and connection timestamp are recorded as a record, and one other peer node address information includes at least one record, wherein the IP address is the IP of the corresponding node, the port is the port number corresponding to the IP of the node, and the connection timestamp is the time when the target node connects to the node corresponding to the IP address.

[0048] S221. Determine abnormality ratio information based on the record in the other peer node address information and the reference timestamp.

[0049] Among them, the other peer node address information contains multiple records, each record contains three dimensions of information, namely the IP address, port and connection timestamp mentioned above; it should be noted that, if the record is judged from each of the three dimensions, there may be anomalies in the record, and the proportion of records with anomalies judged from different dimensions in the other peer node address information is recorded as anomaly proportion information, which is used as a factor in the subsequent analysis of the cause of anomalies in the Bitcoin P2P network.

[0050] S222: Determine a node address information abnormality judgment result based on the record in the other peer node address information.

[0051] Among them, taking a record in the address information of other peer nodes as an example, the record contains information of three dimensions: IP address, port and connection timestamp. In this embodiment, if the information of one dimension is judged to be abnormal, it means that the record is abnormal, otherwise, it means that the corresponding record is normal; and the result of the abnormal judgment of each record in each other peer node address information is recorded as the node address information abnormality judgment result, and the node address information abnormality judgment result is also used as a factor in the subsequent analysis of the cause of the abnormality in the Bitcoin P2P network.

[0052] S223. Determine a distribution judgment result based on the record in the other peer node address information.

[0053] Among them, by counting the records in the address information of all other peer nodes, the distribution of each record in different dimensions can be obtained. Furthermore, by synchronously performing anomaly judgment on the distribution in different dimensions, it can be determined whether the distribution in different dimensions is abnormal, and the results of the anomaly judgment in different dimensions are recorded as the distribution judgment results.

[0054] S224. Determine a node address abnormality judgment result based on the abnormality proportion information, the node address information abnormality judgment result, and the distribution judgment result.

[0055] Among them, the node address anomaly judgment result includes: anomaly ratio information, node address information anomaly judgment result and distribution judgment result.

[0056] S225. Determine a block header abnormality judgment result based on the latest block header information.

[0057] S230: Generate a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0058] Example 3

[0059] A method for generating a Bitcoin P2P network defense strategy is provided in Example 3 of the present application. This method optimizes the "determining abnormality ratio information based on the records in the other peer node address information and the reference timestamp" in Example 2. It should be noted that for portions not described in detail in this embodiment, reference may be made to the descriptions in other embodiments. This method includes:

[0060] S310: interact with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information.

[0061] The other peer node address information includes at least one record and a reference timestamp, wherein the record includes an IP address, a port, and a connection timestamp.

[0062] S321A: Determine the proportion of abnormal IP addresses based on the IP addresses in the other peer node address information and the preset reserved IP addresses.

[0063] Among them, the IP addresses included in the address information of other peer nodes may belong to some specific IPs, and the specific IPs are recorded as preset reserved IPs. In this embodiment, the preset reserved IPs include IPv4 reserved addresses and IPv6 reserved addresses, among which the IPv4 reserved addresses include: 10.0.0.0 / 8-private network, 172.16.0.0 / 12-private network, 192.168.0.0 / 16-private network, 127.0.0.0 / 8-loopback address, 169.254.0.0 / 16-link local address, 0.0.0.0 / 8-current network, 240.0.0.0 / 4-reserved address; the IPv6 reserved addresses include: :: / 128-unspecified address, ::1 / 128-loopback address, fe80:: / 10-link local address, fc00:: / 7-unique local address (ULA), fec0:: / 10-site local address.

[0064] Taking a record in the address information of other peer nodes as an example, determine the IP address in the record, and then determine whether the IP address belongs to the above-mentioned preset reserved IP. If so, the record is determined to be an abnormal record; determine the abnormal record in the address information of other peer nodes in the above manner, and then calculate the proportion of the abnormal record in the address information of other peer nodes, and record the proportion as the abnormal IP proportion.

[0065] S321B: Determine a proportion of abnormal timestamps based on the connectivity timestamp and the reference timestamp in the other peer node address information.

[0066] Among them, each record has a corresponding connectivity timestamp. If the connectivity timestamp differs greatly from the benchmark timestamp in time, it means that the corresponding record is abnormal. In order to determine whether the connectivity timestamp differs greatly from the benchmark timestamp in time, this embodiment establishes a timestamp range based on the benchmark timestamp. The lower limit of the timestamp range is the benchmark timestamp -94694400s, and the upper limit of the timestamp range is the benchmark timestamp +600s. Taking a record as an example, the connectivity timestamp in the record is determined, and then it is determined whether the connectivity timestamp is within the timestamp range. If not, it is determined that the corresponding record is abnormal, and the abnormal record is recorded as an abnormal record. According to the above method, each record in the address information of other peer nodes is judged, so as to determine all abnormal records in the address information of other peer nodes as an abnormal record group. Further, the proportion of records in the abnormal record group in all records in the address information of other peer nodes is calculated, and the proportion is recorded as the abnormal timestamp proportion.

[0067] S321C: Determine a proportion of abnormal ports based on the ports in the other peer node address information and preset ports.

[0068] Among them, each record has a one-to-one matching port, and the preset port in this embodiment is a specific service port or a port with a port number of 0; it should be noted that if the port corresponding to the record belongs to the preset port, the port is determined to be an abnormal port; the abnormal port in the address information of other peer nodes can be determined by the above method, and then the proportion of the abnormal port in all ports in the address information of other peer nodes is calculated, and the proportion is recorded as the abnormal port proportion.

[0069] S321D. Determine abnormality proportion information based on the abnormal IP proportion, the abnormal timestamp proportion, and the abnormal port proportion.

[0070] Among them, the abnormal proportion information includes the abnormal IP proportion, abnormal timestamp proportion and abnormal port proportion.

[0071] S322: Determine a node address information abnormality judgment result based on the record in the other peer node address information.

[0072] S323. Determine a distribution judgment result based on the record in the other peer node address information.

[0073] S324: Determine a node address abnormality judgment result based on the abnormality proportion information, the node address information abnormality judgment result, and the distribution judgment result.

[0074] S325. Determine a block header abnormality judgment result based on the latest block header information.

[0075] S330: Generate a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0076] Example 4

[0077] A fourth embodiment of the present application provides a method for generating a Bitcoin P2P network defense strategy. This method optimizes the "determining a node address information anomaly judgment result based on the record in the other peer node address information" in the second embodiment. It should be noted that for parts not described in detail in this embodiment, reference may be made to the descriptions of other embodiments. This method includes:

[0078] S410: interact with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information.

[0079] The other peer node address information includes at least one IP address and a reference timestamp, and the IP address includes an IP address, a port, and a connection timestamp.

[0080] S421. Determine abnormality ratio information based on the record in the other peer node address information and the reference timestamp.

[0081] S422A: Determine a first abnormality judgment result of the IP address, a second abnormality judgment result of the port, and a third abnormality judgment result of the connectivity timestamp in the record.

[0082] Among them, taking a record in the address information of other peer nodes as an example, the record includes: IP address, port and connection timestamp; to determine whether the record is an abnormal record, it is necessary to determine whether the IP address is the reserved IP address mentioned in step S321A. If so, the record is determined to be abnormal; otherwise, the record is determined to be normal, and the result of the above-mentioned abnormal judgment on the record is recorded as the first abnormal judgment result; in addition, it is also necessary to determine whether the port is the preset port mentioned in step S321C. If so, the port is determined to be abnormal; otherwise, the port is determined to be normal; and the result of the above-mentioned abnormal judgment on the port is recorded as the second abnormal judgment result; in addition, it is also necessary to determine whether the connection timestamp is in the timestamp range mentioned in step S321B. If so, the connection timestamp is determined to be normal; otherwise, the connection timestamp is determined to be abnormal, and the result of the above-mentioned abnormal judgment on the connection timestamp is recorded as the third abnormal judgment result.

[0083] S422B: Determine an abnormality record based on the first abnormality judgment result, the second abnormality judgment result, and the third abnormality judgment result.

[0084] Among them, in response to one of the first abnormal judgment result, the second abnormal judgment result and the third abnormal judgment result being abnormal, the records corresponding to the first abnormal judgment result, the second abnormal judgment result and the third abnormal judgment result are determined as abnormal records.

[0085] For example, taking a record as an example, if the first abnormality judgment result of the record is that the IP address is abnormal, the second abnormality judgment result is that the port is normal, and the third abnormality judgment result is that the connectivity timestamp is normal, then the record is determined to be an abnormal record.

[0086] S422C. Determine a node address information abnormality judgment result based on the abnormal record, the address information of other peer nodes, and a preset abnormal IP ratio threshold.

[0087] Among them, through steps S422A-S422B, the abnormal records in the address information of other peer nodes can be determined, and then the proportion of abnormal records in the address information of other peer nodes can be calculated to obtain the abnormal IP proportion; in this embodiment, in order to judge whether the abnormal IP proportion is too high, an abnormal IP proportion threshold is preset. Exemplarily, the abnormal IP proportion threshold is 30%. If the abnormal IP proportion exceeds the abnormal IP proportion threshold, the corresponding other peer node address information is judged to be abnormal. Otherwise, the corresponding other peer node address information is judged to be normal, and the result of the above-mentioned abnormal judgment on the address information of other peer nodes is recorded as the node address information abnormality judgment result.

[0088] S423: Determine a distribution judgment result based on the record in the other peer node address information.

[0089] S424. Determine a node address abnormality judgment result based on the abnormality proportion information, the node address information abnormality judgment result, and the distribution judgment result.

[0090] S425. Determine a block header abnormality judgment result based on the latest block header information.

[0091] S430: Generate a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0092] Example 5

[0093] A fifth embodiment of the present application provides a method for generating a Bitcoin P2P network defense strategy. This method optimizes the "determining a distribution judgment result based on the records in the address information of the other peer nodes" in the second embodiment. It should be noted that for parts not described in detail in this embodiment, reference may be made to the descriptions of other embodiments. This method includes:

[0094] S510: interact with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information.

[0095] The other peer node address information includes at least one record and a reference timestamp, and the record includes an IP address, a port, and a connection timestamp.

[0096] S521. Determine abnormality ratio information based on the record in the other peer node address information and the reference timestamp.

[0097] S522: Determine a node address information abnormality judgment result based on the record in the other peer node address information.

[0098] S523A. Based on the records in the other peer node address information, determine the distribution of IP addresses within a single network segment given by multiple target nodes, the distribution of IP addresses and IP+Port tuples within each network segment given by a single target node, and the distribution of all IP+Port tuples of a single IP address.

[0099] Among them, for all other peer node address information, all other peer node address information contains multiple IP addresses, each IP address has its own network segment, in order to determine the distribution judgment result based on the IP addresses in all other peer node address information, it is necessary to first determine the network segments corresponding to each IP address in all other peer node address information, taking one of the network segments as an example, first determine the number of types of IP addresses in the network segment, the number of types is used to characterize the number of different IP addresses in the network segment, and then calculate the number of occurrences of each IP address in the network segment, and further, according to the occurrence of each IP address, The number of times each IP address appears can be used to determine the probability of occurrence of each IP address. For example, taking one of the IP addresses as an example, the number of times this IP address appears in the corresponding network segment is calculated, and then the ratio of this number of occurrences to the number of occurrences of all IP addresses in the network segment is calculated, and the ratio is used as the probability of occurrence of this IP address. In this way, the probability of occurrence corresponding to each IP address in the network segment can be calculated. Furthermore, the information entropy value corresponding to the network segment can be calculated through the probability of occurrence corresponding to each IP address and the information entropy calculation formula, and the information entropy value is used as the IP address distribution in a single network segment given by multiple target nodes in the network segment.

[0100] In addition, for the address information of another peer node, it is also necessary to determine the network segment described by each IP address corresponding to the address information of the other peer node. Taking one of the network segments as an example, first determine the number of types of IP addresses in the network segment. The number of types is used to characterize the number of different IP addresses in the network segment, and then calculate the number of occurrences of each IP address in the network segment. Further, the occurrence probability of each IP address can be determined based on the number of occurrences of each IP address. For example, taking one of the IP addresses as an example, calculate the number of occurrences of this type of IP address in the corresponding network segment, and then calculate the ratio of the number of occurrences to the number of all IP addresses in the network segment, and use the ratio as the occurrence probability of this type of IP address; through the above method, the occurrence probability corresponding to each IP address in the network segment can be calculated; further, through the occurrence probability corresponding to each IP address and the information entropy calculation formula, the information entropy value corresponding to the network segment can be calculated, and the information entropy value is used as the distribution of IP addresses and IP+Port tuples in each network segment given by a single target node of the network segment.

[0101] In addition, for each IP address in all other peer node address information, it is also necessary to determine the number of port types corresponding to each IP address. This number of types is used to characterize the number of port types that appear after the same IP address. In addition, it is necessary to calculate the number of times each port appears after the same IP address, and then calculate the ratio of this number to the number of all ports that appear after the same node, and use this ratio as the probability of occurrence of this type of port; calculate the probability of occurrence of various ports after the same IP address in the above manner, and then calculate the information entropy value corresponding to the same IP address based on the probability of occurrence of various ports after the same IP address and the information entropy calculation formula, and use this information entropy value as the distribution of all IP+Port tuples of a single IP address of the same IP address.

[0102] S523B. Determine a distribution judgment result based on the IP address distribution within a single network segment given by multiple target nodes, the distribution of IP addresses and IP+Port tuples within each network segment given by a single target node, and the distribution of all IP+Port tuples of a single IP address.

[0103] Among them, in order to judge whether the distribution of IP addresses in a single network segment given by multiple target nodes, the distribution of IP addresses and IP+Port tuples in each network segment given by a single target node, and the distribution of all IP+Port tuples of a single IP address are abnormal, this embodiment sets a first entropy threshold for the distribution of IP addresses in a single network segment given by multiple target nodes, a second entropy threshold for the distribution of IP addresses and IP+Port tuples in each network segment given by a single target node, and a third entropy threshold for the distribution of all IP+Port tuples of a single IP address; if the distribution of IP addresses in a single network segment given by multiple target nodes is less than the first entropy threshold, it is determined that the distribution of IP addresses in a single network segment given by multiple target nodes is abnormal; otherwise, it is determined that the distribution of IP addresses in a single network segment given by multiple target nodes is normal; if the distribution of IP addresses in each network segment given by a single target node is less than the first entropy threshold, it is determined that the distribution of IP addresses in a single network segment given by multiple target nodes is abnormal; otherwise, it is determined that the distribution of IP addresses in a single network segment given by multiple target nodes is normal; If the distribution of IP addresses and IP+Port tuples is less than the second entropy threshold, the distribution of IP addresses and IP+Port tuples in each network segment given by a single target node is judged to be abnormal; otherwise, the distribution of IP addresses and IP+Port tuples in each network segment given by a single target node is judged to be normal; if the distribution of all IP+Port tuples of a single IP address is less than the third entropy threshold, the distribution of all IP+Port tuples of a single IP address is judged to be abnormal; otherwise, the distribution of all IP+Port tuples of a single IP address is judged to be normal; and the results of the above-mentioned abnormality judgments on the distribution of IP addresses in a single network segment given by multiple target nodes, the distribution of IP addresses and IP+Port tuples in each network segment given by a single target node, and the distribution of all IP+Port tuples of a single IP address are collectively referred to as distribution judgment results.

[0104] S524 : Determine a node address abnormality judgment result based on the abnormality proportion information, the node address information abnormality judgment result, and the distribution judgment result.

[0105] S525: Determine a block header abnormality judgment result based on the latest block header information.

[0106] S530: Generate a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0107] Example 6

[0108] A method for generating a Bitcoin P2P network defense strategy is provided in Example 6 of the present application. This method optimizes the "determining a block header anomaly judgment result based on the latest block header information" in Example 1. It should be noted that for portions not described in detail in this embodiment, reference may be made to the descriptions of other embodiments. This method includes:

[0109] S610: interact with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information.

[0110] S621. Determine a node address abnormality judgment result based on the other peer node address information.

[0111] S622. Determine the target blockchain height based on the latest block header information.

[0112] Among them, the latest block header information obtained by the lightweight node includes the blockchain height corresponding to the Bitcoin P2P network, and the blockchain height is recorded as the target blockchain height H1.

[0113] S623. Determine a block header anomaly judgment result based on the target blockchain height and the latest blockchain height obtained.

[0114] Among them, this embodiment can obtain the current latest blockchain height of the Bitcoin P2P network by calling the API, and record the current latest blockchain height as the latest blockchain height H2. By comparing the target blockchain height H1 with the latest blockchain height H2, it can be determined whether the corresponding latest block header information obtained is abnormal. In this implementation, if it is determined that the target blockchain height H1 is less than the latest blockchain height H2, the latest block header information obtained is determined to be abnormal; otherwise, the latest block header information obtained is determined to be normal; and the result of the above-mentioned abnormality judgment on the latest block header information is recorded as the block header abnormality judgment result.

[0115] S630: Generate a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0116] Example 7

[0117] A method for generating a Bitcoin P2P network defense strategy is provided in Example 7 of the present application. This method optimizes the method of "interacting with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information" in Example 1. It should be noted that for parts not described in detail in this embodiment, reference may be made to the descriptions of other embodiments. This method includes:

[0118] S711. Interact with the target node in the Bitcoin P2P network to obtain interaction events, other peer node address information, and the latest block header information.

[0119] S712: Obtain a full interaction log based on the interaction event.

[0120] Among them, in this embodiment, the lightweight node actively interacts with each target node in the Bitcoin P2P network. During the interaction process, each interaction event that occurs during the interaction process will be recorded in the log, thereby obtaining a full interaction log, and the format of the full interaction log is json format; among them, during the interaction process, the node address message ADDR returned by each target node obtained by the lightweight node is also the address information of other peer nodes, and the block header message HEADERS returned by each target node obtained by the lightweight node is also the latest block header information.

[0121] S713: In response to the interaction event being an abnormal event, obtain an abnormal interaction log based on the abnormal type of the interaction event.

[0122] Among them, some abnormal events may occur in the process of lightweight nodes interacting with target nodes, such as the one mentioned in Example 1: "If the lightweight node does not receive the node address message ADDR replied by the target node after sending the node address acquisition message GETADDR, it will send a node address acquisition message GETADDR to the target node once every 10 seconds, and start timing from the first sending of the node address acquisition message GETADDR. If the target node fails to successfully reply to the node address message ADDR within 120 seconds, the preset log will record the abnormal event"; the above-mentioned abnormal events correspond to different abnormal types in this embodiment. There are 4 types of abnormalities in this embodiment: the first is failure to reply to the message, such as the target node fails to reply to the node address message ADDR for more than 120 seconds; the second is failure to reply to the message in time, such as the target node replies to the node address message ADDR for nearly 120 seconds; the third is failure to reply to the message in the protocol format, and the fourth is abnormal reply content; the four abnormal types can be used to divide the interaction events into four logs, and each log is recorded as an abnormal interaction log. It should be noted that the format of the abnormal interaction log is json format.

[0123] S714. Obtain an interaction log based on the full interaction log and the abnormal interaction log.

[0124] Among them, the interaction log includes the full interaction log and each abnormal interaction log. The interaction log is used as a factor in the subsequent analysis of the cause of abnormalities in the Bitcoin P2P network.

[0125] It should be noted that the lightweight honeypot provided in this embodiment also includes a data storage device, which is used to store the above-mentioned interaction logs or other data generated during the interaction process.

[0126] S720: Determine a node address anomaly judgment result based on the other peer node address information, and determine a block header anomaly judgment result based on the latest block header information.

[0127] S730: Generate a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0128] Example 8

[0129] A method for generating a Bitcoin P2P network defense strategy is provided in Example 8 of the present application. This method optimizes the method of "interacting with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information" in Example 2. It should be noted that for parts not described in detail in this embodiment, reference may be made to the descriptions of other embodiments. This method includes:

[0130] S810: Interact with a target node in the Bitcoin P2P network to obtain an interaction log, address information of other peer nodes provided by the target node, and the latest block header information.

[0131] S821. Determine abnormality ratio information based on the record in the other peer node address information and the reference timestamp.

[0132] S822. Determine a node address information abnormality judgment result based on the record in the other peer node address information.

[0133] S823. Determine a distribution judgment result based on the record in the other peer node address information.

[0134] S824. Determine a node address abnormality judgment result based on the abnormality proportion information, the node address information abnormality judgment result, and the distribution judgment result.

[0135] S825. Determine a block header abnormality judgment result based on the latest block header information.

[0136] S831. Generate a single-target node defense strategy based on the interaction log, the abnormality ratio information in the node address abnormality judgment result and the node address information abnormality judgment result, and the block header abnormality judgment result.

[0137] Among them, in order to understand the deep-seated reasons behind the anomalies in the Bitcoin P2P network and formulate corresponding Bitcoin P2P network defense strategies after knowing the deep-seated reasons, this embodiment presets a large language model (LLM); the large language model (LLM) is used to process the interaction logs, the abnormal proportion information in the node address abnormality judgment results and the node address information abnormality judgment results, as well as the block header abnormality judgment results input therein, and output a single-target node defense strategy. The single-target node defense strategy is a defense strategy for a single target node in the Bitcoin P2P network.

[0138] S832. Generate a global node defense strategy based on the distribution judgment result in the node address abnormality judgment result;

[0139] The large language model (LLM) preset in this embodiment is also used to process the distribution judgment results input therein and input the global node defense strategy, which is a defense strategy for all target nodes in the Bitcoin P2P network.

[0140] S833. Determine a Bitcoin P2P network defense strategy based on the single-target node defense strategy and the global node defense strategy.

[0141] Among them, the Bitcoin P2P network defense strategy includes single-target node defense strategy and global node defense strategy.

[0142] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0143] Embodiment 9

[0144] Based on the same inventive concept, this embodiment also provides a Bitcoin P2P network defense strategy generation device for implementing the aforementioned Bitcoin P2P network defense strategy generation method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations of one or more Bitcoin P2P network defense strategy generation device embodiments provided below can be found in the above-mentioned limitations of the Bitcoin P2P network defense strategy generation method and will not be repeated here.

[0145] In this embodiment, Figure 2 As shown, a Bitcoin P2P network defense strategy generation device is provided, comprising:

[0146] A lightweight node is used to interact with a target node in the Bitcoin P2P network to obtain interaction logs, address information of other peer nodes provided by the target node, and the latest block header information;

[0147] A detection engine, configured to determine a node address anomaly determination result based on the other peer node address information, and a block header anomaly determination result based on the latest block header information;

[0148] The anomaly analyzer generates a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0149] Each module in the aforementioned Bitcoin P2P network defense strategy generation device can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in hardware form, or can be stored in a computer device's memory in software form, so that the processor can call and execute the corresponding operations of each module.

[0150] It should be noted that this embodiment obtains the interaction log, the address information of other peer nodes provided by the target node and the latest block header information by interacting with the target node in the Bitcoin P2P network; determines the node address anomaly judgment result based on the address information of other peer nodes, and determines the block header anomaly judgment result based on the latest block header information; generates the Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result and the block header anomaly judgment result; through the above implementation, the interaction log, the address information of other peer nodes and the latest block header information can be obtained by actively interacting with the target node in the Bitcoin P2P network. The latest block header information and the interaction log record the event of abnormal behavior of the target node. By analyzing the address information of other peer nodes and the latest block header information, the data anomalies contained therein can be determined. Finally, by analyzing the abnormal behavior events in the interaction log and the analyzed data anomalies, a Bitcoin P2P network defense strategy can be generated. This application actively interacts with the target node in the Bitcoin P2P network, thereby realizing active detection in the defense process and immediately generating a corresponding Bitcoin P2P network defense strategy when an anomaly is detected, so that the Bitcoin P2P network can prevent and mitigate security threats in a timely manner.

[0151] In another embodiment, Figure 3 As shown, a Bitcoin P2P network defense strategy generation device is provided, comprising:

[0152] A lightweight node is used to interact with a target node in the Bitcoin P2P network to obtain interaction logs, address information of other peer nodes provided by the target node, and the latest block header information;

[0153] A detection engine, configured to determine a node address anomaly determination result based on the other peer node address information, and a block header anomaly determination result based on the latest block header information;

[0154] Data storage, used to store interaction logs or other data generated during the interaction process;

[0155] The anomaly analyzer generates a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

[0156] It should be noted that the Bitcoin P2P network defense strategy generation device provided in this embodiment can also be called a lightweight honeypot.

[0157] Example 10

[0158] In this embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When executed by the processor, the computer program implements a method for generating a Bitcoin P2P network defense strategy.

[0159] Those skilled in the art will understand that Figure 4 The structure shown in the figure is merely a block diagram of a portion of the structure related to the solution of the present disclosure, and does not constitute a limitation on the computer device to which the solution of the present disclosure is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0160] Example 11

[0161] In this embodiment, a computer readable storage medium is provided. Figure 5 As shown, a computer program is stored thereon, and when the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0162] Example 12

[0163] In this embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0164] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties.

[0165] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in the present disclosure may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this disclosure may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in each embodiment provided in this disclosure may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, etc.

[0166] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0167] The above-described embodiments merely represent several implementation methods of the present disclosure. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present disclosure. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present disclosure, all of which fall within the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure shall be determined by the appended claims.

Claims

1. A method for generating a Bitcoin P2P network defense strategy, characterized in that: include: Interact with the target node in the Bitcoin P2P network to obtain the interaction log, the address information of other peer nodes provided by the target node, and the latest block header information; Determine a node address anomaly judgment result based on the other peer node address information, and determine a block header anomaly judgment result based on the latest block header information; A Bitcoin P2P network defense strategy is generated based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

2. The method according to claim 1, characterized in that The other peer node address information includes a reference timestamp and at least one record, wherein the record includes an IP address, a port, and a connection timestamp; The determining of the node address abnormality judgment result based on the other peer node address information includes: Determining abnormality ratio information based on the record in the other peer node address information and the reference timestamp; Determining a node address information abnormality judgment result based on the record in the other peer node address information; Determining a distribution judgment result based on the record in the other peer node address information; The node address abnormality judgment result is determined based on the abnormality proportion information, the node address information abnormality judgment result and the distribution judgment result.

3. The method according to claim 2, characterized in that The determining of abnormality ratio information based on the record in the other peer node address information and the reference timestamp includes: Determine the proportion of abnormal IP addresses based on the IP addresses in the other peer node address information and the preset reserved IP addresses; Determining a proportion of abnormal timestamps based on the connectivity timestamp and the reference timestamp in the other peer node address information; Determine a proportion of abnormal ports based on the ports and preset ports in the address information of the other peer nodes; Based on the abnormal IP ratio, the abnormal timestamp ratio, and the abnormal port ratio, abnormal ratio information is determined.

4. The method according to claim 2, characterized in that The determining, based on the record in the other peer node address information, a result of determining that the node address information is abnormal, includes: Determine a first abnormality judgment result of the IP address, a second abnormality judgment result of the port, and a third abnormality judgment result of the connectivity timestamp in the record; Determining an abnormality record based on the first abnormality judgment result, the second abnormality judgment result, and the third abnormality judgment result; Based on the abnormal record, the address information of other peer nodes and a preset abnormal IP ratio threshold, a node address information abnormality judgment result is determined.

5. The method according to claim 2, characterized in that The determining of the distribution judgment result based on the record in the address information of the other peer nodes includes: Based on the records in the other peer node address information, determine the distribution of IP addresses within a single network segment given by multiple target nodes, the distribution of IP addresses and IP+Port tuples within each network segment given by a single target node, and the distribution of all IP+Port tuples of a single IP address; The distribution judgment result is determined based on the distribution of IP addresses in a single network segment given by multiple target nodes, the distribution of IP addresses and IP+Port tuples in each network segment given by a single target node, and the distribution of all IP+Port tuples of a single IP address.

6. The method according to claim 1, characterized in that The determining of a block header abnormality judgment result based on the latest block header information includes: Determining a target blockchain height based on the latest block header information; Based on the target blockchain height and the latest blockchain height obtained, a block header anomaly judgment result is determined.

7. The method according to claim 1, characterized in that The interaction with the target node in the Bitcoin P2P network obtains the interaction log, the address information of other peer nodes provided by the target node, and the latest block header information, including: Interact with the target node in the Bitcoin P2P network to obtain interaction events, other peer node address information, and the latest block header information; Obtaining a full interaction log based on the interaction event; In response to the interaction event being an abnormal event, obtaining an abnormal interaction log based on the abnormal type of the interaction event; An interaction log is obtained based on the full interaction log and the abnormal interaction log.

8. The method according to claim 2, characterized in that The generating of a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result includes: Generate a single-target node defense strategy based on the interaction log, the abnormality ratio information in the node address abnormality judgment result and the node address information abnormality judgment result, and the block header abnormality judgment result; Generate a global node defense strategy based on the distribution judgment result in the node address anomaly judgment result; Based on the single-target node defense strategy and the global node defense strategy, a Bitcoin P2P network defense strategy is determined.

9. A Bitcoin P2P network defense strategy generation device, characterized in that: The device comprises: A lightweight node is used to interact with a target node in the Bitcoin P2P network to obtain interaction logs, address information of other peer nodes provided by the target node, and the latest block header information; A detection engine, configured to determine a node address anomaly determination result based on the other peer node address information, and a block header anomaly determination result based on the latest block header information; The anomaly analyzer generates a Bitcoin P2P network defense strategy based on the interaction log, the node address anomaly judgment result, and the block header anomaly judgment result.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.