Business data processing method and device and electronic equipment

By establishing a second communication address between the network node and the service server and hiding the first communication address of the service server, the server's performance degradation and security problems during DDoS attacks are solved, and efficient and low-latency data processing is achieved.

CN120567433APending Publication Date: 2025-08-29NETEASE (HANGZHOU) NETWORK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510308508.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

In the face of DDoS and other attacks, the server is susceptible to a sharp increase in pressure, resulting in a decline in service capacity or paralysis. The existing protective measures are costly, delayed, and difficult to maintain.

Method used

By establishing a second communication address between the network node and the service server, hiding the first communication address of the service server, and processing service data through the network node, an attack is avoided to reach the server directly.

Benefits of technology

Maintain normal business processing efficiency and low latency when not attacked; when attacked, data is processed through network nodes to protect the server from attack, ensuring security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567433A_ABST
    Figure CN120567433A_ABST
Patent Text Reader

Abstract

The invention provides a service data processing method and device and electronic equipment, and the method comprises the steps: determining a second communication address in response to a service server entering an attacked state; wherein the attacked state is determined by the service server based on service data sent by the service client; sending the second communication address to the service client, so that the service client establishes a communication channel with the network node through the second communication address; and controlling the service server to hide the first communication address, receiving service data sent by the service client through the communication channel, and sending the service data to the service server, so that the service server processes the service data. According to the method, the service server can normally process the service data without being attacked, the delay is less, the service data is processed through the network node under the attack condition, the service server cannot be attacked, and the efficiency and the safety of service data processing are both considered.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and in particular to a business data processing method, device, and electronic device. Background Art

[0002] The primary architectural model for network services is the C (client) and S (server) architecture. C is typically the player's client, and S generally refers to the server program running on the server. Typically, the client connects to the server program via network protocols to enable data exchange between the client and server. However, some individuals actively use various technical means to attack servers for illicit purposes. Common attack methods include DDoS (Distributed Denial of Service). These attacks dramatically increase server pressure, impacting or even disrupting normal service. Without unprotected connections between the client and the application server, the application server will be left vulnerable to attack, resulting in a sharp decline in service capabilities or even complete paralysis.

[0003] In related technologies, a local firewall can be set up in the application server. This mode can filter the network traffic sent to the process to a certain extent and protect against network attacks with smaller traffic. However, when the traffic generated by the attack means is large and exceeds the processing limit of the server, the server will be overloaded and unable to provide stable services due to the high machine load. It is also possible to connect a protection device between the client and the application server, which has stronger protection. However, network protection equipment is generally provided by cloud providers and is relatively expensive; and the traffic must first pass through the network protection equipment, which increases the delay between the client and the server. This method does not distinguish between normal request traffic and abnormal traffic, and all traffic enters the protection device uniformly. It requires the deployment of a large number of protection and cleaning equipment, which increases the cost and difficulty of maintenance. Summary of the Invention

[0004] In view of this, an object of the present disclosure is to provide a business data processing method, device and electronic device to balance the efficiency and security of business data processing.

[0005] In a first aspect, an embodiment of the present disclosure provides a business data processing method, which is applied to a network node; the network node is communicatively connected to a business server; the business server is communicatively connected to a business client, and the communication connection includes a first communication address; the method includes: determining a second communication address in response to the business server entering an attacked state; wherein the attacked state is determined by the business server based on business data sent by the business client; sending the second communication address to the business client so that the business client establishes a communication channel with the network node through the second communication address; controlling the business server to hide the first communication address, and receiving business data sent by the business client through the communication channel, and sending the business data to the business server so that the business server processes the business data.

[0006] In a second aspect, an embodiment of the present disclosure provides another business data processing method, which is applied to a business server; the business server is communicatively connected to a network node; the business server is communicatively connected to a business client, and the communication connection includes a first communication address; the method includes: receiving business data sent by the business client, and determining whether it has entered an attacked state based on the business data; if it is determined that it has entered an attacked state, notifying the network node of the attacked state so that the network node determines a second communication address, sends the second communication address to the business client, and the business client establishes a communication channel with the network node through the second communication address, and sends business data to the network node through the communication channel; hiding the first communication address, and processing the business data sent by the network node.

[0007] In a third aspect, an embodiment of the present disclosure provides a business data processing device, which is arranged at a network node; the network node is communicatively connected to a business server; the business server is communicatively connected to a business client, and the communication connection includes a first communication address; the device includes: a second communication address determination module, which is used to determine a second communication address in response to the business server entering an attacked state; wherein the attacked state is determined by the business server based on business data sent by the business client; a second communication address sending module, which is used to send the second communication address to the business client, so that the business client establishes a communication channel with the network node through the second communication address; controls the business server to hide the first communication address, and receives business data sent by the business client through the communication channel, and sends the business data to the business server, so that the business server processes the business data.

[0008] In a fourth aspect, an embodiment of the present disclosure provides another business data processing device, which is arranged on a business server; the business server is communicatively connected to a network node; the business server is communicatively connected to a business client, and the communication connection includes a first communication address; the device includes: an attacked state determination module, which is used to receive business data sent by the business client, and determine whether to enter an attacked state based on the business data; an attacked state notification module, which is used to notify the network node of the attacked state if it is determined that the attacked state has entered, so that the network node determines a second communication address, sends the second communication address to the business client, and the business client establishes a communication channel with the network node through the second communication address, and sends business data to the network node through the communication channel; a data processing module, which is used to hide the first communication address and process the business data sent by the network node.

[0009] In a fifth aspect, an embodiment of the present invention provides an electronic device, including a processor and a memory, wherein the memory stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the above-mentioned business data processing method.

[0010] In a sixth aspect, an embodiment of the present invention provides a machine-readable storage medium, which stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to implement the above-mentioned business data processing method.

[0011] The embodiments of the present invention bring the following beneficial effects:

[0012] The aforementioned service data processing method, device, and electronic device determine a second communication address in response to a service server entering an attacked state. The attacked state is determined by the service server based on service data sent by a service client. The second communication address is sent to the service client, enabling the service client to establish a communication channel with a network node via the second communication address. The service server is controlled to conceal the first communication address, receive service data sent by the service client via the communication channel, and send the service data to the service server for processing. This method allows the service server to process service data normally with minimal delay when not under attack. In the event of an attack, service data is processed via the network node, protecting the service server from attack, while maintaining both efficiency and security in service data processing.

[0013] Other features and advantages of the present disclosure will be described in the following description, and in part will become apparent from the description, or understood by practicing the present disclosure. The objectives and other advantages of the present disclosure are realized and obtained by the structures particularly pointed out in the description, claims and drawings.

[0014] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the prior art, the drawings required for use in the specific embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without paying any creative work.

[0016] Figure 1 A flowchart of a business data processing method provided in an embodiment of the present disclosure;

[0017] Figure 2 A flowchart of another method for processing business data provided by an embodiment of the present disclosure;

[0018] Figure 3 A schematic diagram of a communication process between a business data processing device and a business client provided in an embodiment of the present disclosure;

[0019] Figure 4 A schematic diagram of the structure of a business data processing device provided in an embodiment of the present disclosure;

[0020] Figure 5 A schematic structural diagram of another business data processing device provided in an embodiment of the present disclosure;

[0021] Figure 6 A schematic structural diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0022] To make the purpose, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of them. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making any creative efforts shall fall within the scope of protection of the present disclosure.

[0023] Currently, the predominant network service architecture is client-server architecture. The client-server architecture typically refers to the user's client, while the server-server architecture typically refers to the server program running on the server. Typically, the client connects to the server program on the server via network protocols (UDP, TCP), enabling data exchange between the client and server. However, the internet is not a safe haven. Some individuals actively use various techniques to attack servers for illicit purposes. The most common attack method is Distributed Denial of Service (DDoS). These attacks dramatically increase server pressure, impacting or even disrupting normal service.

[0024] In related technologies, network protection is usually carried out through the following three methods:

[0025] 1. No protection. The client connects directly to the application server. This solution has no protection capabilities when attacked. During an attack, the service capacity will drop sharply. In mild cases, it will cause service delays. In severe cases, the server will crash or even be paralyzed and unable to provide services.

[0026] 2. Local firewall mode: Compared with mode 1, this mode adds a local firewall, which can filter the network traffic sent to the process to a certain extent and protect against network attacks with smaller traffic.

[0027] By using the server's own firewall, the traffic flowing into the process can be pre-filtered according to certain rules, which provides a certain degree of protection compared to Solution 1. When the traffic is large and exceeds the server's processing limit, the server will be overloaded and unable to provide stable services due to the excessive machine load.

[0028] 3. Connect protection equipment between the client and the application server. This solution has strong protection. The disadvantage is that network protection equipment is generally provided by cloud vendors and is expensive.

[0029] Solution 3, the industry's leading technical solution, employs passive defense, which involves adding a protection node at the front end of the application server. All traffic requesting services passes through the protection device before flowing into the application server. This model has the following drawbacks:

[0030] (1) Typically, network protection equipment is provided by cloud providers and charged based on traffic volume. When application services require large-scale deployment and have large traffic demands, the fees are often very expensive.

[0031] (2) Since the traffic must first pass through the network protection device, the delay between the client and the server is increased.

[0032] (3) This solution does not distinguish between normal request traffic and abnormal traffic, and all traffic enters the protection device uniformly. This requires the deployment of a large number of protection and cleaning equipment, increasing costs and maintenance difficulties.

[0033] Based on this, the embodiments of the present disclosure provide a business data processing method, device, and electronic device. This technology can be applied to scenarios where indoor effects need to be generated.

[0034] See also Figure 1 First, a business data processing method provided by an embodiment of the present invention is introduced. The method is applied to a network node; the network node is communicatively connected to a business server; the business server is communicatively connected to a business client, and the communication connection includes a first communication address. Communication between a server and a client usually requires an Internet Protocol (IP) address and a port number. The Internet Protocol address is used to identify a computer on the Internet, and each device connected to the network requires a unique IP address for communication; the port number is used to identify a process or application on the server. Therefore, the first communication address usually includes the Internet Protocol address of the business server, and may also include the communication port of the business server. The method includes the following steps:

[0035] Step S102 : In response to the service server entering an attacked state, determining a second communication address; wherein the attacked state is determined by the service server based on service data sent by the service client.

[0036] When a business server is attacked, network traffic passing through it typically surges. By monitoring the server's network traffic, you can identify unusual network activity, particularly large amounts of incoming and outgoing data, or unusual port and protocol usage, to determine whether the server is under attack.

[0037] If the service server determines it is under attack, it notifies the network node, which then provides a communication channel with the service client. The pre-defined network node can be one or more. Different network nodes are typically implemented using different devices, such as routers, switches, gateways, and servers, though this is not a limitation.

[0038] When there are multiple network nodes, a control node is usually set up among the multiple network nodes. When a service server is attacked, the control node can determine one or more nodes from the multiple network nodes and establish a communication parameter mapping relationship between the determined nodes and the service server.

[0039] Similar to the first communication address, the second communication address may also include communication parameters such as an Internet Protocol address and a communication port, which enable the network node to communicate with the service server. When the service client wants to access the service server, it can access the network node according to the second communication address.

[0040] Step S104: Send the second communication address to the service client, so that the service client establishes a communication channel with the network node through the second communication address.

[0041] To establish a communication channel between a service client and a network node, the network node typically receives a second communication address from the service client, or generates a corresponding communication parameter replacement instruction based on the correspondence between the second communication address and the first communication address, and then sends this instruction to the service client. After receiving this instruction, the service client can replace the service server's Internet communication address with the network node's Internet communication address and replace the service server's service port with the network node's port during communication, thereby sending service data to the network node.

[0042] Step S106 , controlling the service server to hide the first communication address, and receiving service data sent by the service client through the communication channel, and sending the service data to the service server so that the service server processes the service data.

[0043] After receiving service data, the network node can send it to the service server, which then processes the data through its running service system. The network node must communicate with the service server via a local area network (LAN) to reduce the server's vulnerability to attacks. After processing the service data, the service server sends the results to the network node, which then sends them to the service client, completing the service data processing process.

[0044] The aforementioned service data processing method determines a second communication address in response to a service server entering an attacked state. The attacked state is determined by the service server based on service data sent by a service client. The second communication address is sent to the service client, enabling the service client to establish a communication channel with a network node via the second communication address. The service server is controlled to conceal the first communication address, receives service data sent by the service client via the communication channel, and sends the service data to the service server for processing. This method allows the service server to process service data normally with minimal delay when not under attack. In the event of an attack, service data is processed via the network node, protecting the service server from attack, while maintaining both efficiency and security in service data processing.

[0045] The following embodiment provides a specific method for determining the second communication address in response to a service server entering an attacked state.

[0046] The aforementioned second communication address needs to include the Internet Protocol address of the network node and the port of the network node. The port of the network node is mapped to the port of the service application process running on the service server. In a specific implementation, the mapping relationship between the port of the network node and the port of the service application process on the service server can be pre-set. Alternatively, after the service server enters the attacked state, the network node can search for its own available ports and then establish a mapping relationship between the available ports and the ports of the service application process on the service server. The specific configuration can be based on needs and is not limited here.

[0047] In practical applications, network nodes may include control nodes and router nodes. There is typically one control node, and multiple router nodes. After being attacked, a service server may send a first notification message to the control node. The control node receives the first notification message from the service server; the first notification message indicates that the service server is under attack. After receiving this message, the control node typically sends a second notification message to the router node. After receiving the second notification message, the router node determines a second communication address based on the router's communication parameters.

[0048] When there are multiple router nodes, the control node needs to determine the first one or more router nodes from the multiple router nodes based on the load of each router node to take over the service server to receive service data sent by the service client. Then, the control node establishes a communication parameter mapping relationship between the service servers through the router nodes.

[0049] The following embodiment provides a specific method for sending a second communication address to a service client.

[0050] When the network nodes include a control node and a router node, after the router node determines the second communication address, it sends the second communication address to the control node. Furthermore, the control node sends the second communication address to the service client. After receiving the second communication address, the service client can switch to the communication channel corresponding to the second communication address using tunneling technology.

[0051] The following embodiment provides a specific method of receiving business data sent by a business client through a communication channel and sending the business data to a business server.

[0052] When a service server is attacked and network nodes are used to receive service data from service clients, the network nodes are often also vulnerable. A network security system, such as a firewall, can be pre-installed on the network nodes. After receiving service data from service clients, the network nodes can process the data through the network security system running on the network nodes to obtain processed service data. This data is typically filtered and cleaned to remove abnormal data. The processed data is then sent to the service server via the network node, which then processes the data.

[0053] For network security, the service server and the network nodes are usually connected via a local area network. The network nodes usually send service data to the service server via the local area network.

[0054] The embodiment of the present invention also provides another service data processing method. The method is applied to a service server; the service server is connected to a network node for communication; the service server is connected to a service client for communication, and the communication connection includes a first communication address. Figure 2 As shown, the method includes the following steps:

[0055] Step S202: Receive service data sent by the service client, and determine whether the system has entered an attacked state based on the service data.

[0056] Business servers typically run business systems. These systems can include gaming, communications, social networking, and more. Business clients can send business data to the business servers, which then process the data through their running business systems.

[0057] When a business server is attacked, its network traffic may show abnormalities. By monitoring the server's network traffic, for example, using a network traffic analysis tool like Wireshark, and looking for abnormal network activity, particularly large amounts of incoming and outgoing data, or unusual port and protocol usage, you can determine whether the business server is under attack.

[0058] After receiving business data, it can also monitor abnormal behaviors on the server, such as abnormal CPU usage, abnormal number of network connections, abnormal file activities, etc. These abnormal behaviors may be signs of an attack.

[0059] If a service server determines it is under attack, it must establish a communication parameter mapping relationship with a predefined network node. This predefined network node can be one or more. Different network nodes are typically implemented using different devices, such as routers, switches, gateways, and servers, though this is not a limitation.

[0060] Step S204: If it is determined that the attack state has been entered, the network node is notified of the attack state so that the network node determines a second communication address and sends the second communication address to the service client. The service client establishes a communication channel with the network node through the second communication address and sends service data to the network node through the communication channel.

[0061] Step S206: hide the first communication address and process the service data sent by the network node.

[0062] After determining the second communication address, the network node typically notifies the service server. The service server can then hide the first communication address to avoid network attacks. When the network node receives service data from the service client, it typically forwards it to the service server, which then processes the data through its own service system.

[0063] The aforementioned service data processing method receives service data sent by a service client and, based on the service data, determines whether it has entered an attacked state. If so, it notifies a network node of the attacked state, causing the network node to determine a second communication address and send the second communication address to the service client. The service client then establishes a communication channel with the network node via the second communication address and sends service data to the network node via the communication channel. The first communication address is then hidden, and the service data sent by the network node is processed. This method allows the service server to process service data normally with minimal delay when not under attack. In the event of an attack, service data is processed by the network node, protecting the service server from attack, while maintaining both efficiency and security in service data processing.

[0064] The following embodiment provides a specific method for processing business data.

[0065] To ensure greater security during the processing process, the service server typically needs to verify the legitimacy of the session between the service client and the network node. If verification succeeds, the service server processes the processed service data. If verification fails, the service server may refuse to process the service data, and the network node will then send a message to the service server indicating the processing failure.

[0066] The embodiment of the present invention also provides another business data processing method. Figure 1 The method shown is implemented based on

[0067] This method adopts an active defense approach. Under normal circumstances (i.e., when there is no attack), the application server (equivalent to the above-mentioned "business server") directly serves the client (consistent with the unprotected mode), without a front-end protection node, eliminating additional protection costs, and is economical. There is no front-end firewall setting, and the performance is also optimal. It also adopts active detection at the application layer, which is faster and more efficient than the industry's common platform detection solutions. When an attack is detected: abandon the industry's commonly used traffic cleaning solution, and let the application server enter the intranet mode, which is invisible to the public network. The attacker's traffic cannot reach the application server, so the attack is invalid, and the application server will not have performance problems, ensuring high-quality external services. At the same time, the client is notified to reconnect to the router node (also called "router") without feeling. In the specific implementation, the previous connection status is retained, and the data channel of the router node is switched to without feeling.

[0068] The structural framework of the business service system used in this method is as follows Figure 3 As shown, this method is specifically implemented in the following ways:

[0069] (1) An attack detection module is added to the application server to quickly detect whether the server is in an abnormal attack state. Specifically, the application server sets a reasonable threshold based on indicators such as connection packets, abnormal packets, disconnection packets, and the number of connection packets, combined with the current service status. When the indicator exceeds the threshold, it can be confirmed that the server is under attack.

[0070] (2) After the application server detects the attack, it immediately notifies the cluster's control node (controller) that it has been attacked.

[0071] (3) The control node notifies the router node and the attacked application server to establish an internal port mapping channel through the internal network.

[0072] After the control node notifies the router node of the information about the attacked server, the router node uses full NAT technology to establish a port mapping from the local port to the application process on the application server, cooperates with the firewall to allow normal connection packets to pass and filter out abnormal data packets, and returns the binding information to the control node.

[0073] (4) The control node notifies the service client to switch to the IP and port corresponding to the router node under high defense (equivalent to the above-mentioned "second communication address"). The client application layer switches to the new communication channel through tunneling technology. The client uses the new IP and port and connects to the application server through the router through tunneling technology at the application layer. The application server identifies and establishes a new data channel through the session between the client and the server. At the same time, security devices such as cleaning and filtering are added to the router to ensure the security and reliability of the router.

[0074] (5) The control node notifies the cloud service provider to delete the external IP address of the application server, or notifies the application server to remove the external IP address, that is, to set the Internet Protocol address of the application server to an inaccessible state, so that the external network cannot access this server. This method makes the attack traffic lose its target and discards the attack data packets at the routing level, so that the data packets cannot reach the application server, forming an effect similar to a routing black hole, protecting the stable operation of the application server.

[0075] (6) At this point, the client completes the data channel switching, the server becomes invisible to the outside world, and the attack is automatically resolved.

[0076] This method is implemented through a server attack detection module, router nodes, and control nodes. Under normal circumstances, the server directly connects to the client, with almost no performance or cost loss. When under attack, it automatically switches to protection mode, neutralizing traffic. This is more efficient and thorough than adding cleaning equipment, and is extremely low-cost to implement, with virtually no impact on users.

[0077] This method uses a low-latency direct connection service when the application server is not under attack, reducing network latency and avoiding the additional protection costs associated with passive protection. It also prevents normal traffic from passing through network protection and cleaning equipment, significantly reducing their utilization and unnecessary equipment and energy consumption. If the application server is under attack, it can quickly switch to protection mode, avoiding service degradation or interruptions caused by the attack.

[0078] For the above method embodiments, see Figure 4 A service data processing device is shown, which is arranged in a network node; the network node is in communication connection with a service server; the service server is in communication connection with a service client, and the communication connection includes a first communication address; the device includes:

[0079] A second communication address determination module 402 is configured to determine a second communication address in response to the service server entering an attacked state; wherein the attacked state is determined by the service server based on service data sent by the service client;

[0080] A second communication address sending module 404 is configured to send the second communication address to the service client, so that the service client establishes a communication channel with the network node through the second communication address;

[0081] The service data receiving module 406 is used to control the service server to hide the first communication address, receive service data sent by the service client through the communication channel, and send the service data to the service server so that the service server processes the service data.

[0082] The aforementioned service data processing device determines a second communication address in response to a service server entering an attacked state. The attacked state is determined by the service server based on service data sent by a service client. The second communication address is sent to the service client, enabling the service client to establish a communication channel with a network node via the second communication address. The service server is controlled to conceal the first communication address, receives service data sent by the service client via the communication channel, and sends the service data to the service server for processing. This method allows the service server to process service data normally with minimal delay when not under attack. In the event of an attack, service data is processed via the network node, protecting the service server from attack, while maintaining both efficiency and security in service data processing.

[0083] The second communication address includes an Internet Protocol address of the network node and a port of the network node; the port of the network node has a mapping relationship with the port of the service application process running on the service server.

[0084] The above-mentioned network node includes a control node and a router node; the second communication address determination module is also used to: receive a first notification message sent by the service server through the control node; the first notification message indicates that the service server is under attack; send a second notification message to the router node through the control node; and determine the second communication address through the router node based on the communication parameters of the router.

[0085] The second communication address sending module is further configured to: send the second communication address to the control node via the router node; and send the second communication address to the service client via the control node.

[0086] The above-mentioned network node runs a network security system; the steps of receiving business data sent by the business client through the communication channel and sending the business data to the business server include: receiving business data sent by the business client through the communication channel; filtering and processing the business data through the network security system; and sending the filtered business data to the business server.

[0087] The business data receiving module is further configured to send the business data to the business server via a preset local area network.

[0088] For the above method embodiment, the embodiment of the present invention also provides another service data processing device. The device is set in the service server; the service server is connected to the network node; the service server is connected to the service client, and the communication connection includes a first communication address. Figure 5 As shown, the device includes:

[0089] The attacked state determination module 502 is configured to receive service data sent by the service client and determine whether the system has entered the attacked state based on the service data;

[0090] The attacked state notification module 504 is configured to notify the network node of the attacked state if it is determined that the network node has entered the attacked state, so that the network node determines a second communication address and sends the second communication address to the service client. The service client establishes a communication channel with the network node through the second communication address and sends service data to the network node through the communication channel.

[0091] The data processing module 506 is configured to hide the first communication address and process the service data sent by the network node.

[0092] The aforementioned service data processing device receives service data sent by a service client and, based on the service data, determines whether it is under attack. If so, it notifies a network node of the attack, causing the network node to determine a second communication address and send the second communication address to the service client. The service client then establishes a communication channel with the network node via the second communication address and sends service data to the network node via the communication channel. The device also conceals the first communication address and processes the service data sent by the network node. This approach allows the service server to process service data normally with minimal latency when not under attack. In the event of an attack, service data is processed by the network node, protecting the service server from attack, while maintaining both efficiency and security in service data processing.

[0093] The above data processing module is also used to: verify the legitimacy of the session between the service client and the network node; if the verification is successful, process the service data.

[0094] This embodiment further provides an electronic device, including a processor and a memory, wherein the memory stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the above-mentioned service data processing method, for example:

[0095] In response to the business server entering an attacked state, a second communication address is determined; wherein the attacked state is determined by the business server based on business data sent by the business client; the second communication address is sent to the business client, so that the business client establishes a communication channel with the network node through the second communication address; the business server is controlled to hide the first communication address, and the business data sent by the business client is received through the communication channel, and the business data is sent to the business server, so that the business server processes the business data.

[0096] In the above method, when the business server is not attacked, it can process business data normally with less delay. When it is attacked, the business data is processed through the network node, so that the business server will not be attacked, taking into account the efficiency and security of business data processing.

[0097] Optionally, the second communication address includes an Internet Protocol address of the network node and a port of the network node; the port of the network node has a mapping relationship with the port of the service application process running on the service server.

[0098] Optionally, the above-mentioned network nodes include a control node and a router node; in response to the business server entering an attacked state, the step of determining the second communication address includes: receiving a first notification message sent by the business server through the control node; the first notification message indicates that the business server is under attack; sending a second notification message to the router node through the control node; and determining the second communication address through the router node based on the communication parameters of the router.

[0099] Optionally, the step of sending the second communication address to the service client includes: sending the second communication address to the control node through the router node; and sending the second communication address to the service client through the control node.

[0100] Optionally, the above-mentioned network node runs a network security system; the steps of receiving business data sent by the business client through the communication channel and sending the business data to the business server include: receiving business data sent by the business client through the communication channel; filtering and processing the business data through the network security system; and sending the filtered business data to the business server.

[0101] Optionally, the step of sending the business data to the business server includes: sending the business data to the business server via a preset local area network.

[0102] The processor executing the machine executable instructions may implement the above-mentioned another business data processing method, for example:

[0103] Receive business data sent by the business client, and determine whether it has entered an attacked state based on the business data; if it is determined that it has entered the attacked state, notify the network node of the attacked state, so that the network node determines a second communication address, sends the second communication address to the business client, and the business client establishes a communication channel with the network node through the second communication address, and sends business data to the network node through the communication channel; hide the first communication address, and process the business data sent by the network node.

[0104] In the above method, when the business server is not attacked, it can process business data normally with less delay. When it is attacked, the business data is processed through the network node, so that the business server will not be attacked, taking into account the efficiency and security of business data processing.

[0105] Optionally, in the above method, when the business server is not attacked, it can process business data normally with less delay. When attacked, the business data is processed through the network node, so that the business server will not be attacked, taking into account the efficiency and security of business data processing.

[0106] Optionally, the above step of processing the service data includes: verifying the legitimacy of the session between the service client and the network node; if the verification is successful, processing the service data.

[0107] See also Figure 6 As shown, the electronic device includes a processor 100 and a memory 101. The memory 101 stores machine-executable instructions that can be executed by the processor 100. The processor 100 executes the machine-executable instructions to implement the above-mentioned business data processing method.

[0108] Furthermore, Figure 6 The electronic device shown further includes a bus 102 and a communication interface 103 , and the processor 100 , the communication interface 103 and the memory 101 are connected via the bus 102 .

[0109] The memory 101 may include a high-speed random access memory (RAM), and may also include a non-volatile memory, such as at least one disk storage. The communication connection between the system network element and at least one other network element is achieved through at least one communication interface 103 (which may be wired or wireless), and the Internet, wide area network, local area network, metropolitan area network, etc. may be used. The bus 102 may be an ISA bus, a PCI bus, or an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 Only one bidirectional arrow is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0110] The processor 100 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by an integrated logic circuit of hardware in the processor 100 or by instructions in the form of software. The above-mentioned processor 100 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present disclosure can be implemented or executed. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The method disclosed in conjunction with the embodiments of the present disclosure can be directly embodied as a hardware decoding processor for execution, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium well-known in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in memory 101, and processor 100 reads information in memory 101 and, in conjunction with its hardware, implements the method of the aforementioned embodiment.

[0111] This embodiment further provides a machine-readable storage medium, which stores machine-executable instructions. When the machine-executable instructions are called and executed by a processor, the machine-executable instructions prompt the processor to implement the above-mentioned business data processing method.

[0112] The embodiments of the present disclosure provide a method, apparatus, and electronic device for processing business data, including a computer-readable storage medium storing program code. The program code includes instructions that can be used to execute a business data processing method described in the previous method embodiments, for example:

[0113] In response to the business server entering an attacked state, a second communication address is determined; wherein the attacked state is determined by the business server based on business data sent by the business client; the second communication address is sent to the business client, so that the business client establishes a communication channel with the network node through the second communication address; the business server is controlled to hide the first communication address, and the business data sent by the business client is received through the communication channel, and the business data is sent to the business server, so that the business server processes the business data.

[0114] In the above method, when the business server is not attacked, it can process business data normally with less delay. When it is attacked, the business data is processed through the network node, so that the business server will not be attacked, taking into account the efficiency and security of business data processing.

[0115] Optionally, the second communication address includes an Internet Protocol address of the network node and a port of the network node; the port of the network node has a mapping relationship with the port of the service application process running on the service server.

[0116] Optionally, the above-mentioned network nodes include a control node and a router node; in response to the business server entering an attacked state, the step of determining the second communication address includes: receiving a first notification message sent by the business server through the control node; the first notification message indicates that the business server is under attack; sending a second notification message to the router node through the control node; and determining the second communication address through the router node based on the communication parameters of the router.

[0117] Optionally, the step of sending the second communication address to the service client includes: sending the second communication address to the control node through the router node; and sending the second communication address to the service client through the control node.

[0118] Optionally, the above-mentioned network node runs a network security system; the steps of receiving business data sent by the business client through the communication channel and sending the business data to the business server include: receiving business data sent by the business client through the communication channel; filtering and processing the business data through the network security system; and sending the filtered business data to the business server.

[0119] Optionally, the step of sending the business data to the business server includes: sending the business data to the business server via a preset local area network.

[0120] The instructions included in the program code can also be used to execute another business data processing method described in the previous method embodiment, for example:

[0121] Receive business data sent by the business client, and determine whether it has entered an attacked state based on the business data; if it is determined that it has entered the attacked state, notify the network node of the attacked state, so that the network node determines a second communication address, sends the second communication address to the business client, and the business client establishes a communication channel with the network node through the second communication address, and sends business data to the network node through the communication channel; hide the first communication address, and process the business data sent by the network node.

[0122] In the above method, when the business server is not attacked, it can process business data normally with less delay. When it is attacked, the business data is processed through the network node, so that the business server will not be attacked, taking into account the efficiency and security of business data processing.

[0123] Optionally, the above step of processing the service data includes: verifying the legitimacy of the session between the service client and the network node; if the verification is successful, processing the service data.

[0124] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described systems and devices can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0125] In addition, in the description of the embodiments of the present disclosure, unless otherwise expressly specified or limited, the terms "installed," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to connections within two components. Those skilled in the art will understand the specific meanings of the above terms in the present disclosure based on the specific circumstances.

[0126] If the control function is implemented in the form of a software control function unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0127] In the description of this disclosure, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings and are intended solely to facilitate the description of this disclosure and simplify the description. They do not indicate or imply that the devices or components referred to must have a specific orientation, be constructed, or operate in a specific orientation. Therefore, they should not be construed as limitations on this disclosure. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0128] Finally, it should be noted that the above embodiments are only specific implementation methods of the present disclosure, which are used to illustrate the technical solutions of the present disclosure, rather than to limit them. The scope of protection of the present disclosure is not limited thereto. Although the present disclosure has been described in detail with reference to the above embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above embodiments within the technical scope disclosed in the present disclosure, or replace some of the technical features therein with equivalents. Such modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.

Claims

1. A business data processing method, characterized in that: The method is applied to a network node; The network node is in communication connection with the service server; the service server is in communication connection with the service client, and the communication connection includes a first communication address; the method includes: In response to the service server entering an attacked state, determining a second communication address; wherein the attacked state is determined by the service server based on the service data sent by the service client; Sending the second communication address to the service client, so that the service client establishes a communication channel with the network node through the second communication address; The service server is controlled to hide the first communication address, and receives service data sent by the service client through the communication channel, and sends the service data to the service server so that the service server processes the service data.

2. The method according to claim 1, characterized in that The second communication address includes the Internet Protocol address of the network node and the port of the network node; the port of the network node has a mapping relationship with the port of the business application process running on the business server.

3. The method according to claim 1, characterized in that The network nodes include control nodes and router nodes; In response to the service server entering an attacked state, the step of determining a second communication address includes: receiving, through the control node, a first notification message sent by the service server, wherein the first notification message indicates that the service server is under attack; Sending a second notification message to the router node through the control node; A second communication address is determined by the router node based on the communication parameters of the router.

4. The method according to claim 3, characterized in that The step of sending the second communication address to the service client includes: Sending the second communication address to the control node through the router node; The second communication address is sent to the service client through the control node.

5. The method according to claim 1, wherein The network node runs a network security system; The step of receiving the service data sent by the service client through the communication channel and sending the service data to the service server includes: receiving the service data sent by the service client through the communication channel; Filtering the business data through the network security system; The filtered business data is sent to the business server.

6. The method according to claim 1, characterized in that The step of sending the business data to the business server includes: The business data is sent to the business server via a preset local area network.

7. A business data processing method, characterized in that: The method is applied to a service server; the service server is communicatively connected with a network node; The service server is in communication connection with the service client, and the communication connection includes a first communication address; the method includes: receiving service data sent by the service client, and determining whether an attack state has been entered based on the service data; If it is determined that the network node has entered an attacked state, notifying the network node of the attacked state, so that the network node determines a second communication address, sends the second communication address to the service client, and the service client establishes a communication channel with the network node through the second communication address, and sends service data to the network node through the communication channel; The first communication address is hidden, and the service data sent by the network node is processed.

8. The method according to claim 7, characterized in that The step of processing the business data includes: Verifying the legitimacy of the session between the service client and the network node; If the verification is successful, the business data is processed.

9. A business data processing device, characterized in that: The device is set at a network node; the network node is in communication connection with a service server; the service server is in communication connection with a service client, and the communication connection includes a first communication address; the device includes: a second communication address determining module, configured to determine a second communication address in response to the service server entering an attacked state; wherein the attacked state is determined by the service server based on service data sent by the service client; a second communication address sending module, configured to send the second communication address to the service client, so that the service client establishes a communication channel with the network node through the second communication address; The service data receiving module is used to control the service server to hide the first communication address, receive the service data sent by the service client through the communication channel, and send the service data to the service server so that the service server processes the service data.

10. A business data processing device, characterized in that: The device is arranged on a service server; the service server is in communication connection with a network node; The service server is in communication connection with the service client, and the communication connection includes a first communication address; the device includes: An attacked state determination module, configured to receive service data sent by the service client and determine whether the system has entered an attacked state based on the service data; an attacked state notification module, configured to, if determining that the network node has entered an attacked state, notify the network node of the attacked state, so that the network node determines a second communication address, sends the second communication address to the service client, and the service client establishes a communication channel with the network node through the second communication address and sends service data to the network node through the communication channel; A data processing module is used to hide the first communication address and process the service data sent by the network node.

11. An electronic device, characterized in that: The system comprises a processor and a memory, wherein the memory stores machine-executable instructions that can be executed by the processor, and the processor executes the machine-executable instructions to implement the business data processing method according to any one of claims 1 to 8.

12. A machine-readable storage medium, characterized in that The machine-readable storage medium stores machine-executable instructions. When the machine-executable instructions are called and executed by the processor, the machine-executable instructions prompt the processor to implement the business data processing method according to any one of claims 1 to 8.