Defense system and method for network attack and electronic equipment

By monitoring the resource usage of QUIC connections, dynamically control the defense module, and using the QUIC re-establishment mechanism to verify the source address, the problem of QUIC Initial Flood attack is solved, and efficient defense and low-latency cyber attack defense is achieved.

CN120602113APending Publication Date: 2025-09-05ALIBABA (SHENZHEN) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510528365.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2025-04-23
Filing Date
2025-04-24
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The existing defense scheme cannot effectively defend against QUIC Initial Flood attacks, resulting in exhaustion of server resources and having a significant impact on normal connections.

Method used

The resource monitoring module monitors key indicators, dynamically enables or disables the statistical and matching modules and address verification modules, uses the QUIC protocol re-establishment mechanism to verify the authenticity of the source address of the connection request, and combines the feedback aggregation module to output the attack source address.

Benefits of technology

Effectively defend against QUIC Initial Flood attacks, reduce the impact on normal connection latency, and improve the server's defense capabilities and resource utilization efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602113A_ABST
    Figure CN120602113A_ABST
Patent Text Reader

Abstract

The invention discloses a defense system and method for network attacks and electronic equipment. The system comprises a resource monitoring module, a statistics and matching module and an address verification module. The resource monitoring module is used for starting or closing the functions of the statistics and matching module and / or the address verification module according to the key index data and the corresponding threshold value of the protected equipment; the statistics and matching module is used for identifying whether the first connection establishment request of which the token verification fails is attack traffic or not according to a preset source address rule; and the address verification module is used for sending a reconnection establishment notification containing the token to the source address of the first connection establishment request identified as the attack traffic, and identifying the source address corresponding to the first connection establishment request as an attack source address if the second initial signaling message is not received and the number of token verification failures in the statistical period exceeds a threshold value. By adopting the system, the QUIC-based semi-open connection attack can be efficiently defended.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on April 23, 2025, with application number 202510519372.3 and invention name “Defense system, method and electronic device against network attacks”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The present application relates to the field of network security technology, and in particular to a defense system, method, electronic device, and storage medium against network attacks. Background Art

[0003] The QUIC (Quick UDP Internet Connections) protocol is an improved Internet transmission protocol based on UDP (User Datagram Protocol). It is a transport layer protocol for connecting computers through the Internet. With the increasing number of applications of the QUIC protocol, network attack patterns based on the QUIC protocol have gradually emerged. Among them, the QUIC-based half-open connection attack (i.e., the QUIC Initial Flood attack) is a common type of QUIC network attack, which is essentially a DDOS network attack. Attackers can use attack tools to correctly construct and encrypt QUIC Initial messages, and send a large number of such Initial messages to the target server, which may cause the server's memory resources, network connection resources, computing resources and other resources to be exhausted and attacked by DDOS.

[0004] Therefore, how to provide an effective defense solution for half-open connection attacks based on the QUIC protocol is a technical problem that needs to be solved.

[0005] The above information disclosed in the background technology section is only used to enhance the understanding of the background of this application.

[0006] It may therefore include information that does not form the prior art already known to a person of ordinary skill in the art. Summary of the Invention

[0007] The defense system and method against network attacks provided in the embodiments of the present application can effectively defend against QUIC-based half-open connection attacks.

[0008] In a first aspect, an embodiment of the present application provides a defense system against network attacks, comprising: a resource monitoring module, a statistics and matching module, and an address verification module; wherein the resource monitoring module is used to obtain key indicator data of a protected device, and enable or disable the functions of the statistics and matching module and / or the address verification module according to whether the key indicator data is higher than the threshold of the corresponding indicator; wherein the key indicator data is indicator data characterizing resource usage; the statistics and matching module is used to, when in an enabled state, identify whether a first connection request in which a token verification fails is attack traffic according to a preset source address rule, and pass the first connection request identified as attack traffic to the address verification module; the first connection request is a first initial signaling message for establishing a QUIC connection between the protected device and the source address of the first connection request; the address verification module is used to, when in an enabled state, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic, and for a reconnection notification to which no response is received and the number of token verification failures exceeds the threshold within a statistical period, identify the source address of the corresponding first connection request as an attack source address.

[0009] Optionally, the system also includes: a feedback aggregation module; the feedback aggregation module is used to obtain the attack source address identified by the address verification module, aggregate the attack source address into an attack source network segment, and output the attack source network segment so that the attack source network segment is added to the configuration of the preset source address rule.

[0010] Optionally, the function of enabling or disabling the statistics and matching module and / or the address verification module according to whether the key indicator data is higher than the threshold of the corresponding indicator includes: when the key indicator data is not higher than the first threshold of the corresponding indicator, disabling the statistics and matching module and the address verification module; and / or, when the key indicator data is higher than the first threshold of the corresponding indicator and not higher than the second threshold of the corresponding indicator, enabling the statistics and matching module and the address verification module; and / or, when the key indicator data is higher than the second threshold of the corresponding indicator, disabling the statistics and matching module and enabling the address verification module; the address verification module is specifically configured to, when the key indicator data is higher than the second threshold of the corresponding indicator, send a reconnection notification containing a token to the source address of each first connection request in which token verification fails, and for a reconnection notification of a second initial signaling message for which no response is received and the number of token verification failures within a statistical period exceeds a threshold, identify the source address of the first connection request corresponding to the reconnection notification as an attack source address; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator; wherein the key indicator data includes the total number of QUIC connections and / or the rate of new QUIC connections.

[0011] Optionally, the resource monitoring module is specifically used to: control the first enabling switch and the second enabling switch to be enabled or disabled according to whether the key indicator data is higher than the threshold value of the corresponding indicator, so as to dynamically enable or disable the functions of the statistics and matching module and the address verification module; the statistics and matching module is specifically used to enter the enabled state when the first enabling switch is in the enabled state; and enter the disabled state when the second enabling switch is in the enabled state; the address verification module is specifically used to: when the first enabling switch is in the enabled state, send a message to the address identified as an attack by the statistics and matching module. A reconnection notification containing a token is sent to the source address of the first connection request of the traffic, and for the reconnection notification of the second initial signaling message to which no response is received, the source address of the corresponding first connection request is identified as the attack source address; when the second enabling switch is enabled, a reconnection notification containing a token is sent to the source address of each first connection request in which token verification fails, and for the reconnection notification of the second initial signaling message to which no response is received and the number of token verification failures within a statistical period exceeds a threshold, the source address of the first connection request corresponding to the reconnection notification is identified as the attack source address.

[0012] Optionally, controlling the first enabling switch and the second enabling switch to be in an enabled state or a disabled state according to whether the key indicator data is higher than the threshold of the corresponding indicator includes: when the key indicator data is not higher than the first threshold of the corresponding indicator, setting both the second enabling switch and the first enabling switch to a disabled state; and / or, when the key indicator data is higher than the first threshold of the corresponding indicator and not higher than the second threshold of the corresponding indicator, setting the second enabling switch to a disabled state and setting the first enabling switch to an enabled state; and / or, when the key indicator data is higher than the second threshold of the corresponding indicator, setting the second enabling switch to an enabled state and setting the first enabling switch to a disabled state; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator.

[0013] Optionally, the preset source address rule includes a source IP threshold rule and / or a source IP blacklist; the identification of whether the first connection request that fails the token verification according to the preset source address rule is attack traffic includes: counting the source addresses of the first connection request that fails the token verification, if the statistical number of connection requests that fail the token verification with the same source address exceeds the threshold included in the source IP threshold rule, identifying the first connection request as attack traffic; and / or matching the source IP of the first connection request that fails the token verification with the IP address and / or IP address segment in the source IP blacklist, if they match, identifying the first connection request as attack traffic.

[0014] Optionally, the first initial signaling message does not contain token information, or the first initial signaling message contains illegal token information or the token information has expired; the second initial signaling message contains token information; the statistics and matching module is specifically used to: when in an enabled state, determine whether the first initial signaling message contains legal token information; if not, identify whether the received first connection request is attack traffic according to a preset source address rule; the address verification module is specifically used to: when in an enabled state, determine whether the first initial signaling message contains legal token information; if not, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic.

[0015] In the second aspect, the present application also provides a defense method against network attacks, including: obtaining key indicator data of a protected device, and controlling a first enabling switch to an enabled state or a disabled state according to whether the key indicator data is higher than a threshold of a corresponding indicator; wherein the key indicator data is indicator data characterizing resource usage; when the first enabling switch is in the enabled state, identifying whether the first connection request in which the token verification fails is attack traffic according to a preset source address rule; the first connection request is a first initial signaling message for establishing a QUIC connection between the protected device and the source address of the first connection request; when the first enabling switch is in the enabled state, sending a reconnection notification containing a token to the source address of the first connection request identified as attack traffic, and for the reconnection notification of the second initial signaling message to which no response is received and the number of token verification failures exceeds the threshold within the statistical period, identifying the corresponding source address of the first connection request as an attack source address.

[0016] Optionally, the method further includes: aggregating the identified attack source addresses into attack source network segments, and outputting the attack source network segments so that the attack source network segments are added to the configuration of the preset source address rule.

[0017] Optionally, it also includes: controlling the second enabling switch to be in an enabled state or a disabled state according to whether the key indicator data is higher than the threshold of the corresponding indicator; when the second enabling switch is in the enabled state, sending a reconnection notification containing a token to the source address of each first connection request in which token verification fails, and for the reconnection notification of the second initial signaling message to which no response is received and the number of token verification failures exceeds a threshold within a statistical period, identifying the source address of the first connection request corresponding to the reconnection notification as an attack source address.

[0018] Optionally, controlling the second enabling switch to be in an enabled state or a disabled state based on whether the key indicator data is higher than the threshold of the corresponding indicator includes: when the key indicator data is not higher than the first threshold of the corresponding indicator, setting both the second enabling switch and the first enabling switch to a disabled state; and / or, when the key indicator data is higher than the first threshold of the corresponding indicator and not higher than the second threshold of the corresponding indicator, setting the second enabling switch to a disabled state, and setting the first enabling switch to an enabled state; and / or, when the key indicator data is higher than the second threshold of the corresponding indicator, setting the second enabling switch to an enabled state, and setting the first enabling switch to a disabled state; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator; wherein the key indicator data includes the total number of QUIC connections and / or the rate of new QUIC connections.

[0019] Optionally, the preset source address rule includes a source IP threshold rule and / or a source IP blacklist; the identification of whether the first connection request that fails the token verification according to the preset source address rule is attack traffic includes: counting the source addresses of the first connection request that fails the token verification, if the statistical number of connection requests that fail the token verification with the same source address exceeds the threshold included in the source IP threshold rule, identifying the first connection request as attack traffic; and / or matching the source IP of the first connection request that fails the token verification with the IP address and / or IP address segment in the source IP blacklist, if they match, identifying the first connection request as attack traffic.

[0020] Optionally, the first initial signaling message does not contain token information, or the first initial signaling message contains illegal token information or the token information has expired; the second initial signaling message contains token information; the method further includes: determining whether the first initial signaling message contains legal token information; if not, executing: when the first enabling switch is in the enabled state, identifying whether the received first connection request is attack traffic according to a preset source address rule, and sending a reconnection notification containing a token to the source address of the first connection request identified as attack traffic.

[0021] In a third aspect, the present application also provides an electronic device comprising: a processor, a memory, and computer program instructions stored on the memory and executable on the processor; when the processor executes the computer program instructions, the method as described in any one of the second aspects is implemented.

[0022] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, they are used to implement any one of the methods in the second aspect.

[0023] Compared with the prior art, the present application has the following advantages:

[0024] A defense system against network attacks provided by an embodiment of the present application includes: a resource monitoring module, a statistics and matching module, and an address verification module; the resource monitoring module is used to obtain key indicator data of a protected device, and enable or disable the functions of the statistics and matching module and / or the address verification module according to whether the key indicator data is higher than the threshold of the corresponding indicator; wherein the key indicator data is indicator data characterizing resource usage; the statistics and matching module is used to, when in an enabled state, identify whether a first connection request received is attack traffic according to a preset source address rule, and pass the first connection request identified as attack traffic to the address verification module; the first connection request is a first initial signaling message for establishing a QUIC connection between the protected device and the source address of the first connection request; the address verification module is used to, when in an enabled state, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic, and identify the source address of the corresponding first connection request as the attack source address for the reconnection notification of the second initial signaling message to which no response is received.

[0025] In the above system, key indicators are monitored through the resource monitoring module, and the statistics and matching module and the address verification module are dynamically enabled or disabled according to the key indicator data and the threshold of the corresponding indicator; after the statistics and matching module is enabled, the attack traffic can be identified, and after the address verification module is enabled, the source address of the connection request can be verified through the reconnection mechanism to determine whether it is a real source address or an attack source address, thereby providing attack defense capabilities. Furthermore, the above system also includes a feedback aggregation module, which outputs the address verification result of the address verification module as the configuration basis of the source address rule of the statistics and matching module, thereby further serving as the basis for identifying the current attack traffic. Therefore, the above system can effectively defend against QUIC Initial Flood (i.e., half-open connection) attacks, while greatly reducing the impact on normal connection requests. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 This is a schematic diagram of an application scenario of the defense system against network attacks provided by this application;

[0027] Figure 2 This is a logical framework diagram of a defense system against network attacks provided in the first embodiment of the present application;

[0028] Figure 3 This is the QUIC protocol reconnection mechanism handshake interaction process provided by the first embodiment of this application;

[0029] Figure 4This is a processing flow chart of a defense method against network attacks provided in the second embodiment of the present application;

[0030] Figure 5 This is a schematic diagram of a defense device against network attacks provided in the third embodiment of the present application;

[0031] Figure 6 It is a schematic diagram of an electronic device provided in this application. DETAILED DESCRIPTION

[0032] The following description sets forth many specific details to facilitate a thorough understanding of the present application. However, the present application can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the scope of the present application. Therefore, the present application is not limited to the specific implementations disclosed below.

[0033] The embodiments of the present application provide a defense system, method, device, electronic device, and storage medium against network attacks, which are described in the following embodiments.

[0034] To facilitate understanding, an application scenario of the defense system against network attacks is first given.

[0035] The defense system against network attacks using QUIC as an example will be explained. QUIC (Quick UDP Internet Connections) is a low-latency internet transport protocol. Built on UDP, QUIC avoids the TCP three-way handshake and slow start processes, thereby reducing connection establishment time and achieving lower latency. QUIC supports fast connection migration. When a user's network environment changes, such as switching from Wi-Fi to mobile data, QUIC can quickly restore the connection, minimizing downtime. QUIC allows multiple data streams to be transmitted simultaneously over the same connection, avoiding the head-of-line blocking problem inherent in TCP. This means that even if one data stream experiences packet loss, other data streams remain unaffected, improving overall transmission efficiency. Multiplexing also allows servers to manage connections more efficiently, reducing resource consumption. QUIC implements encryption at the transport layer, providing enhanced security. Using modern encryption algorithms and key exchange mechanisms, QUIC protects data from unauthorized access or tampering during transmission. This encryption also makes it difficult for intermediary network devices (such as routers and firewalls) to perform application-layer inspection of QUIC traffic, enhancing the privacy of network communications. Furthermore, the QUIC protocol is flexible and can be easily extended and customized. Developers can add new functionality and features to meet specific application requirements without impacting the existing protocol implementation. For example, QUIC performance can be optimized by adding new encryption algorithms, compression algorithms, or flow control mechanisms. Consequently, QUIC implementations are increasing. For example, HTTP / 3 communication over QUIC is becoming increasingly widespread. However, with the widespread use of HTTP / 3, various network attacks targeting QUIC are on the rise.

[0036] The half-open connection attack (QUIC Initial Flood) against the QUIC protocol is a common QUIC network attack. The establishment of a QUIC connection is initiated by the client sending a QUIC connection request message (Initial message). Although the Initial message is transmitted encrypted, its encryption algorithm and key are public. Attackers can use attack tools to correctly construct and encrypt the Initial message and send the attack message to the server. When the server receives the Initial message, it will open a QUIC connection for the client. Since the handshake is not completed for this connection, it is called a half-open connection. Since the attack message is a real Initial message, the server needs to consume more performance to decrypt, process and respond to it. Therefore, this attack method consumes more processing performance of the server. When the attacker sends a large number of Initial messages to the server, it may cause the server's memory, network connection, computing and other resources to be exhausted and DDOS. The so-called DDOS refers to a distributed denial of service (DDoS) attack, which means that the attacker uses client / server technology to launch a DDoS attack on one or more target servers through multiple client computers acting as attack devices.

[0037] Existing defenses against network flooding attacks similar to the QUIC Initial Flood (e.g., the TCP transport protocol's SYN Flood attack) typically employ methods such as SYN proxy mechanisms, first-packet drop, and whitelisting. These methods rely on verifying the legitimacy of the source client. For example, a SYN proxy mechanism can be deployed on a network communication link (e.g., a switch). When a client sends a TCP SYN packet to establish a connection with the server, the SYN proxy mechanism successfully establishes a connection with the client and then establishes a TCP connection with the server. The key is that the SYN proxy on the network link first verifies that the client is authentic before allowing the client to establish a true TCP connection with the server. For another example, after a SYN Flood attack is identified, first-packet drop and whitelisting mechanisms are employed to defend against SYN Flood attacks. However, SYN proxy mechanisms are typically deployed on Layer 4 network devices (e.g., switches and load balancers). The QUIC protocol's connection request message carries information related to the SSL handshake. Layer 4 network devices lack relevant certificate information, making them unable to establish connections on behalf of the QUIC server. Furthermore, Layer 4 network devices lack the performance to support the encryption and decryption costs of QUIC messages. Therefore, the syn proxy mechanism is not suitable for defending against QUIC half-open connection attacks. The first-packet drop and whitelist mechanism discards the syn packets from the first connection between the attacking client (bot) and the legitimate client, using TCP's reconnection mechanism to ensure that the clients establishing the connection are legitimate. However, if the first-packet drop mechanism is used in a QUIC link, it will cause significant delays in client connection establishment, significantly impacting the access experience of legitimate clients.

[0038] The defense system against network attacks proposed in the embodiments of the present application provides a defense solution for QUIC half-open connection DDOS attacks, and uses the QUIC protocol's reconnection (Retry Packet) mechanism to verify the authenticity of the source client to defend against QUIC Initial Flood attacks; at the same time, through the dynamic control of the thresholds of key indicators, the defense module is called to identify attack traffic and reconnect the mechanism, so as to reduce the impact of the reconnection mechanism on the normal client connection delay.

[0039] Please refer to Figure 1The figure shows an application scenario of the defense system against network attacks, including: a network attack defense system 101, a protected device 102, a bot 103, and a client 104, wherein the network attack defense system includes a resource monitoring module 101-1, a statistics and matching module 101-2, an address verification module 101-3, and a feedback aggregation module 101-4. In the figure, the network attack defense system is deployed on the access layer device before the protected device. The access layer device may include but is not limited to a QUIC gateway, other QUIC-enabled access servers, etc. Each protected device may include a server, a web server, etc., which may refer to a physical server or software that provides server functions such as a server container, a microserver, etc. The client can be any legitimate user device, such as a computer, a laptop, a mobile phone, a server, a smart terminal, a handheld terminal, a wearable device, etc., which can send QUIC-based traffic to the protected device. A bot refers to an attack device controlled by an attacker, that is, an attack end. The attacking end may include computers, mobile phones, servers, smart terminals, wearable devices, etc., which can construct and encrypt Initial messages and send a large number of such forged connection requests to the protected device, implement half-open connection attacks, and cause server congestion or even paralysis to achieve the attack effect. The client and / or the puppet machine sends a connection request based on the QUIC protocol. The resource monitoring module in the network attack defense system sends an enable / disable instruction to the defense module (specifically the statistics and matching module, the address verification module) according to the thresholds corresponding to key indicator data such as the total number of QUIC connections and / or the QUIC new connection rate, thereby dynamically controlling the enabling / disabling of the defense module function. Among them, the connection request is the initial connection message sent by the client device to the protected device to request the establishment of a QUIC connection, especially the Initial message for the initial connection. For a key indicator, the first threshold of the indicator is lower than the second threshold of the corresponding indicator; when the key indicator data exceeds the first threshold of the corresponding indicator and does not exceed the second threshold of the corresponding indicator, an enable instruction is sent to the statistics and matching module, so that the connection request received by the network attack defense system enters the statistics and matching module for attack traffic identification, and the connection request identified as attack traffic is verified by the address verification module through the re-establishment mechanism to verify the authenticity / legitimacy of the client source IP; when the key indicator data exceeds the second threshold of the corresponding indicator, the statistics and matching module is disabled, and an enable instruction is sent to the address verification module so that all connection requests received by the network attack defense system are verified by the address verification module through the re-establishment mechanism to verify the authenticity / legitimacy of the client source IP; when the key indicator data does not exceed the first threshold of the corresponding indicator, a disable instruction is sent to the statistics and matching module and the address verification module.Traffic from legitimate source IP addresses identified by the address verification module is passed to the protected device. The attack source IP addresses identified by the address verification module are aggregated into attack source network segments (i.e., IP address segments suspected of being attack sources) by the feedback aggregation module and output to the source IP rule configuration. This segment serves as a source IP blacklist and is provided to the statistics and matching module as a basis for identifying attack traffic. While the address verification method of the reconnection mechanism verifies the legitimacy of the source IP address, it also introduces latency, increasing the RTT performance metric. RTT (Round-Trip Time) refers to the round-trip time (RTT). In computer networks, this performance metric represents the total delay from the start of data transmission to the receipt of an acknowledgment from the receiver. The receiver sends an acknowledgment immediately after receiving the data. By dynamically enabling and disabling the functions of various defense modules based on high and low thresholds, the validity of the source IP address of the connection request can be verified while addressing the increased RTT to a certain extent, minimizing the impact on legitimate clients establishing QUIC connections.

[0040] It is understandable that the above scenarios are exemplary scenarios, which are only used to help understand the method and do not constitute a specific limitation on the system and / or method.

[0041] Figure 2 The logical framework diagram of the defense system against network attacks provided by the first embodiment of this application is as follows: Figure 2 The system will be described. Figure 2 The defense system against network attacks shown includes: a resource monitoring module 201 , a statistics and matching module 202 , and an address verification module 203 .

[0042] The resource monitoring module 201 is used to obtain key indicator data of the protected device, and enable or disable the functions of the statistics and matching module and / or the address verification module based on whether the key indicator data is higher than the threshold of the corresponding indicator; wherein the key indicator data is indicator data that characterizes resource usage.

[0043] The goal of the QUIC Initial Flood attack is to exhaust the computing resources, memory resources, and network connection resources of the protected device. In this embodiment, the role of the resource monitoring module is to monitor the usage of resources of the protected device (such as a server), and when the usage rate of server-related resources exceeds the threshold, call other defense modules to start working; when the usage rate of server-related resources is below the threshold, disable the functions of other defense modules. That is, in this case, even if there is Initial Flood attack traffic on the network, the server is at a safe water level and does not affect the normal provision of services, so no defense action is performed. Each defense module includes a statistics and matching module and an address verification module.

[0044] Specifically, the key indicators monitored by the resource detection module are resource usage indicators, including: the total number of QUIC connections of the protected device and / or the rate of new connection. Among them, the total number of QUIC connections determines to a certain extent the degree of consumption of the connection resources and memory resources of the protected device. Therefore, it can reflect the usage of the memory resources and network connection resources of the protected device. The new connection rate (create connection per second, CPS) reflects the usage of the computing resources of the protected device. In the process of establishing a QUIC connection between the client and the protected device, the protected device will consume computing resources for encryption, decryption and other calculations. Therefore, the connection rate indicator data can reflect the consumption of computing resources.

[0045] In this embodiment, the control of opening or closing each defense module is based on whether the key indicator data is higher than the threshold of the corresponding indicator. For example, if any one of the two key indicators mentioned above exceeds the threshold, each defense module is enabled. Furthermore, a multi-level threshold can be set for the key indicator as a judgment standard for opening each defense module, and the multi-level threshold includes: a low threshold and a high threshold. This makes it easy to implement address verification only for suspected attack traffic when the indicator data exceeds the low threshold but does not exceed the high threshold; when the resource usage indicator exceeds the high threshold, all traffic addresses are verified. In an actual environment, when the low threshold is exceeded, as long as the rules for identifying attack traffic are valid, the Initial Flood attack in most scenarios can be defended, thereby avoiding the system from entering a state that exceeds the high threshold; when the address verification of the suspected attack traffic takes effect, the key indicators related to resource usage return to below the low threshold, and then the defense modules can no longer be called. If the defense effect of identifying attack traffic is poor, it may cause the key indicators to exceed the high threshold. In this case, address verification is performed on all QUIC connection requests. After the address verification of all QUIC connection requests continues for a period of time, the load of the protected device will decrease because the Initial Flood attack traffic can no longer establish a connection with the protected device, and the state of exceeding the low threshold but falling below the high threshold will be re-entered. In this case, address verification can be stopped for all QUIC connection requests, and only address verification can be performed on suspected attack traffic.

[0046] Specifically, the first threshold of the key indicator is a low threshold, and the second threshold is a high threshold. When the key indicator exceeds the low threshold but does not exceed the high threshold, the statistics and matching module can be enabled to identify attack traffic and the address verification module's address verification mechanism can be enabled to defend against attack traffic. If the key indicator further exceeds the high threshold, the statistics and matching module function can be disabled, and the address verification module function can be enabled to perform address verification on the first connection request that fails token verification to defend against QUIC Initial Flood attacks. Specifically, the resource monitoring module enables or disables the functions of the statistics and matching module and / or the address verification module according to whether the key indicator data is higher than the threshold of the corresponding indicator, including: when the key indicator data is not higher than the first threshold of the corresponding indicator, disabling the statistics and matching module and the address verification module; and / or, when the key indicator data is higher than the first threshold of the corresponding indicator and not higher than the second threshold of the corresponding indicator, enabling the statistics and matching module and the address verification module; and / or, when the key indicator data is higher than the second threshold of the corresponding indicator, disabling the statistics and matching module and enabling the address verification module; the address verification module is specifically configured to, when the key indicator data is higher than the second threshold of the corresponding indicator, send a reconnection notification containing a token to the source address of each first connection request in which token verification fails, and for a reconnection notification of a second initial signaling message for which no response is received and the number of token verification failures within a statistical period exceeds a threshold, identify the source address of the first connection request corresponding to the reconnection notification as an attack source address; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator; wherein the key indicator data includes the total number of QUIC connections and / or the rate of new QUIC connections.

[0047] During implementation, different enable switches can be designed respectively, with the first enable switch corresponding to the low threshold and the second enable switch corresponding to the high threshold. The resource monitoring module is specifically used to: control the first enable switch and the second enable switch to be enabled or disabled according to whether the key indicator data is higher than the threshold of the corresponding indicator, so as to dynamically enable or disable the functions of the statistics and matching module and the address verification module; wherein, the statistics and matching module is specifically used to enter the enabled state when the first enable switch is in the enabled state; and enter the disabled state when the second enable switch is in the enabled state; correspondingly, the address verification module is specifically used to: when the first enable switch is in the enabled state, send a signal to the address that is identified as the statistics and matching module. A reconnection notification containing a token is sent to the source address of the first connection request of the attack traffic, and for the reconnection notification of the second initial signaling message that does not receive a response, the source address of the corresponding first connection request is identified as the attack source address; when the second enabling switch is in the enabled state, a reconnection notification containing a token is sent to the source address of each first connection request that fails token verification, and for the reconnection notification of the second initial signaling message that does not receive a response and the number of token verification failures within the statistical period exceeds a threshold, the source address of the first connection request corresponding to the reconnection notification is identified as the attack source address. Wherein, according to whether the key indicator data is higher than the threshold of the corresponding indicator, the first enabling switch and the second enabling switch are controlled to be enabled or disabled, including: when the key indicator data is higher than the first threshold of the corresponding indicator, the first enabling switch is set to the enabled state; and / or, when the key indicator data is not higher than the first threshold of the corresponding indicator, the first enabling switch is set to the disabled state. Wherein, the controlling of the first enabling switch and the second enabling switch to be enabled or disabled according to whether the key indicator data is higher than the threshold value of the corresponding indicator includes: when the key indicator data is not higher than the first threshold value of the corresponding indicator, setting the second enabling switch and the first enabling switch to disabled state; and / or, when the key indicator data is higher than the first threshold value of the corresponding indicator and not higher than the second threshold value of the corresponding indicator, setting the second enabling switch to disabled state and setting the first enabling switch to enabled state; and / or, when the key indicator data is higher than the second threshold value of the corresponding indicator, setting the second enabling switch to enabled state and setting the first enabling switch to disabled state; wherein the second threshold value of the key indicator is greater than the first threshold value of the corresponding indicator. Wherein, the key indicator monitored by the resource monitoring module can be a global indicator of the protected device, that is, the global total number of QUIC connections and / or the rate of new QUIC connections.

[0048] The statistics and matching module 202 is used to, when in an enabled state, identify whether the first connection request that fails token verification is attack traffic according to a preset source address rule, and pass the first connection request identified as attack traffic to the address verification module; the first connection request is the first initial signaling message used to establish a QUIC connection between the protected device and the source address of the first connection request.

[0049] Specifically, the statistics and matching module is mainly used to identify attack traffic. It is enabled when the resource monitoring module determines that the indicator data of the key indicator (such as resource utilization rate) exceeds the first threshold of the corresponding indicator. After being enabled, the function is to count and match the client source address (ie, source IP) of the QUIC connection request, thereby identifying the attack traffic. Among them, the attack traffic is the traffic that fails the token verification, that is, the traffic that passes the token verification is regarded as legal traffic, and address verification is not required for legal traffic, while address verification is performed for attack traffic. The basis for identifying attack traffic is the preset source address rule. Among them, the first connection request is the initial connection message sent by the client, specifically the initial connection message based on the QUIC protocol, which contains the basic information and parameters required to establish a QUIC connection. Specifically, the preset source address rule includes a source IP threshold rule and / or a source IP blacklist, and the source IP blacklist includes a preset IP address and / or a preset IP address segment; the identification of whether the first connection request that fails the token verification is attack traffic based on the preset source address rule includes: counting the source addresses of the first connection request that fails the token verification, if the statistical number of connection requests that fail the token verification with the same source address exceeds the threshold included in the source IP threshold rule, then the first connection request is identified as attack traffic; and / or, matching the source IP of the first connection request that fails the token verification with the IP address and / or IP address segment in the source IP blacklist, if they match, then the first connection request is identified as attack traffic. The attack traffic is further address-verified by the address verification module. In actual applications, when a client initiates a connection request, it can carry a token (such as the token issued by the server during the last successful connection). If the token is valid, it will not be identified as attack traffic. Therefore, the source address of the first connection request that fails token verification is counted to determine whether the number of connection requests with the same source address that fail token verification exceeds the threshold contained in the source IP threshold rule. Token verification failure includes the following two situations: one is that the first connection request does not contain token information; the other is that the token information is included but the token information is illegal or has expired.

[0050] Among them, the source IP threshold rule refers to the threshold for initiating a new QUIC connection within a statistical period for the client source IP that requests to establish a QUIC connection. The threshold is the upper limit of the number of connection requests initiated by a single IP within a time period. Connection requests initiated by source IPs that exceed the threshold are identified as attack traffic. The statistical period can be set to the QUIC semi-connection timeout period; the larger the threshold for new QUIC connections of the source IP, the greater the probability of missed identification of true attack traffic; the smaller the threshold, the greater the probability of misidentification of normal traffic as attack traffic. Therefore, it is necessary to flexibly configure the threshold according to the form and characteristics of the upper-layer content carried by the QUIC protocol.

[0051] The source IP blacklist includes preset IP addresses and / or preset IP address segments. The source IP blacklist can be aggregated based on the attack source addresses identified by the address verification module. It contains source IPs that have attacked in the past period of time. When the client source IP of a newly received first connection request is within the blacklist range, it is considered to match the preset source address rule and the first connection request is identified as attack traffic.

[0052] During implementation, for the first connection request received to establish a new QUIC connection, if it meets any of the above-mentioned source IP blacklist and source IP threshold rules after the statistics and matching module is enabled, it will be identified as attack traffic, and the address verification module will be called to verify the authenticity of the client source IP.

[0053] The address verification module 203 is used to, when in an enabled state, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic, and for the reconnection notification of the second initial signaling message to which no response is received, identify the source address of the corresponding first connection request as the attack source address.

[0054] Specifically, the address verification module includes an address verification mechanism. The address verification mechanism uses the reestablishment connection to verify the source IP address. For the first connection request Initial message of the first establishment, a reestablishment notification, namely a Retry Packet (reestablishment message), is sent to the source IP address corresponding to the Initial message, thereby verifying the authenticity of the source client IP address. Figure 3The figure schematically shows the interactive process of the reconnection mechanism, including: S301, the first initial signaling message Initial[0]: CRYPTO[CH]. S302, the reconnection notification Retry message carries Token. S303, the second initial signaling message Initial[1], carries Token: CRYPTO[CH]. S304, the initial signaling message Initial[0] responds ACK[1], and the handshake message HandShake[0]. That is, after the server receives the initial connection message Initial from the client, it sends a Retry+Token message to notify the client to re-initiate the connection. After receiving the notification, the client parses the Token field in the notification, and then reconstructs the Initial message with the Token field based on the connection identifier passed by the server and initiates the connection. The so-called connection identifier (Server Connection ID, SCID) is generated by the server and is used to uniquely identify a connection.

[0055] In this embodiment, after the statistics and matching module and the address verification module are enabled, they identify and / or verify the address of the first connection request, and do not match and verify the reconnection request of the client based on the reconnection notification feedback. That is, these two defense modules do not act on the Initial message with Token. The legitimacy of the Initial message with Token is determined by the server as the protected device when parsing the message. The server can determine whether the Initial message with Token is legal by the timeliness of the DCID (DestinationConnection ID) and Token fields in the message. Specifically, the first initial signaling message does not contain token information, or the first initial signaling message contains illegal token information or the token information has expired; the second initial signaling message contains token information; the statistics and matching module is specifically used to: when in an enabled state, determine whether the first initial signaling message contains legal token information; if not, identify whether the received first connection request is attack traffic according to a preset source address rule; the address verification module is specifically used to: when in an enabled state, determine whether the first initial signaling message contains legal token information; if not, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic.

[0056] The following describes the defense implementation principles of the address verification module in different network attack scenarios.

[0057] One network attack scenario is that the attacker forges the source IP address to launch an attack. The client launching the attack cannot receive the reconnection notification message (Retry+Token message, that is, the Retry message carrying the Token), and therefore cannot establish a QUIC connection with the server as the protected device by sending the Initial message carrying the Token (that is, the second initial signaling message). Therefore, the attacker cannot achieve the goal of consuming a large amount of server resources.

[0058] A network attack scenario involves an attacker using a large number of botnet machines to send a large number of pre-constructed Initial messages directly to the server. This scenario can be divided into two cases:

[0059] Scenario 1: The attacker does not process the Retry+Token message sent by the server, so the attacker cannot establish a connection with the server. This is similar to the scenario of forging the source IP address. In this case, the attacker cannot consume a large amount of server resources.

[0060] In the second scenario, the attacker is capable of processing Retry+Token messages. Therefore, the server returns a large number of Initial+Token messages, similar to the number of pre-constructed Initial messages sent by the attacker. This causes the attacker to consume a large amount of resources for decoding and decryption calculations. Constructing new Initial+Token messages also consumes a large amount of encryption and encoding calculations, effectively bouncing back on itself. In other words, establishing a connection with the server consumes similar resources as a normal client-server connection, making the attack uneconomical.

[0061] Therefore, the address verification module can effectively defend against Initial Flood attacks. Considering that the reconnection mechanism causes the first connection request of the client entering the reconnection process to increase an RTT (Round-Trip Time), the network delay for the normal client to establish a QUIC connection increases, affecting the user experience. In this embodiment, the statistics and matching module first identifies the attack traffic and distinguishes the attack traffic from the normal traffic. The address verification module then further performs address verification only on the identified attack traffic. This can minimize the impact of address verification on the establishment of normal client connections.

[0062] Specifically, the address verification module is also used to record the address verification results, including: after initiating a reconnection notification (Retry+Token) to the client IP, recording the client source IP that did not initiate the Initial message with Token to reconnect in accordance with the protocol specification, identifying the client source IP as the attack source address that initiated the Initial Flood attack, and the attack source address is further integrated into an IP segment by the feedback aggregation module.

[0063] The system further includes a feedback aggregation module 204 configured to obtain the attack source addresses identified by the address verification module, aggregate the attack source addresses into attack source network segments, and output the attack source network segments so that the attack source network segments are added to the configuration of the preset source address rule.

[0064] Specifically, the feedback aggregation module aggregates the client source IP addresses that fail the address verification based on the results of the address verification module, and generates an attack source network segment blacklist rule, which is output to the configuration of the above-mentioned source IP blacklist, so that the statistics and matching module uses the attack source network segment blacklist to identify whether the first connection request received subsequently is attack traffic.

[0065] In a real-world environment, a normal client establishing a QUIC connection with a protected device consumes computing, storage, and network connection resources similar to those consumed by the server. Therefore, attackers launching QUIC Initial Flood attacks, in order to consume a large amount of server resources at a low cost, often pre-construct Initial messages and then send a large number of them to the protected device in a short period of time, causing resource exhaustion and a denial of service (DDOS). Specific attack methods include: First, the attacker uses a bot under their control to directly send a large number of pre-constructed Initial messages to the server. In this case, the source IP addresses of the attack traffic are highly clustered. Second, to avoid source IP clustering, the attacker forges source IP addresses on the bot under their control and sends a large number of pre-constructed Initial messages to the server. In this case, due to carrier network restrictions, the forged source IP addresses may be clustered. Therefore, a feedback aggregation module can be used to aggregate the network segments of the identified attack source addresses. The resulting attack source network segments serve as at least a partial configuration for the source IP blacklist in the aforementioned preset source address rules. This allows the statistics and matching module to accelerate the search speed of IP addresses in the blacklist when matching the source IP of the first connection request against the source IP blacklist. During implementation, the module can aggregate the source IP addresses that failed the client address authenticity verification within the aggregation period based on the address verification results recorded by the address verification module, and use the IP address segment obtained as the attack source segment. It is understandable that a single source IP without segment aggregation can also be understood as an attack source segment that only contains this IP.

[0066] Specifically, the feedback aggregation module outputs an attack source network segment blacklist, which can be used as a component of the source IP blacklist in the above-mentioned preset source address rules, and is used by the statistics and matching module as a basis for identifying attack traffic. The attack source network segment blacklist can be set with an effective period, and the configuration of its effective period can be set according to the characteristics of the corresponding aggregated address segment. Since the QUIC Initial Flood attack generally has a large number of connection requests and lasts for a period of time, the aggregation period of the feedback aggregation module can be set to be shorter, and the rules for network segment aggregation can be flexibly configured according to actual needs. For example, when it is counted that more than a certain number (such as more than half) of the connection requests for the IP addresses of a certain network segment are all attack traffic, the entire network segment is added to the attack source network segment blacklist output by the feedback aggregation module, and the effective period of the attack source network segment blacklist can be configured for a longer period of time, for example, the effective period is configured to be several QUIC half-connection timeout periods.

[0067] In this embodiment, the defense system dynamically activates each defense module through key indicator monitoring. Specifically, each defense module is dynamically invoked based on high and low thresholds. When each defense module is activated, the attack traffic is statistically analyzed and identified by the matching module. The identified attack traffic is then verified by the address verification module, thereby defending against QUIC half-open connection attacks. This significantly reduces the impact of address verification on network latency caused by normal connection requests. Furthermore, the results of the address verification module can be used as the basis for identifying attack traffic, effectively defending against QUIC initial flood attacks.

[0068] It should be noted that, unless there is any conflict, the features given in this embodiment and other embodiments of the present application can be combined with each other.

[0069] So far, the system provided by this embodiment has been explained. The system monitors key indicators through a resource monitoring module, and dynamically enables or disables the statistics and matching module and the address verification module based on the key indicator data and the threshold value of the corresponding indicator; after the statistics and matching module is enabled, the attack traffic can be identified, and after the address verification module is enabled, the source address of the connection request can be verified through the reconnection mechanism to see whether it is a real source address or an attack source address, thereby providing attack defense capabilities. Furthermore, the above-mentioned system also includes a feedback aggregation module, which outputs the address verification result of the address verification module as the configuration basis of the source address rule of the statistics and matching module, thereby further serving as the basis for identifying the current attack traffic. Therefore, the above-mentioned system can effectively defend against half-open connection attacks, while greatly reducing the impact on normal connection requests.

[0070] Based on the above embodiment, the second embodiment of the present application provides a method for defending against network attacks. In this embodiment, the method is described by taking the QUIC network attack as an example. Figure 4 The method is described in detail. For the relevant parts, please refer to the description of the above system embodiment. Figure 4 The defense method against network attacks shown in the figure includes: steps S401 to S403.

[0071] Step S401: Acquire key indicator data of a protected device, and control a first enabling switch to be enabled or disabled based on whether the key indicator data is higher than a threshold value of a corresponding indicator; wherein the key indicator data is indicator data representing resource usage;

[0072] Step S402: When the first enabling switch is in an enabled state, identifying whether a first connection request that fails token verification is attack traffic according to a preset source address rule; the first connection request is a first initial signaling message for establishing a QUIC connection between the protected device and the source address of the first connection request;

[0073] Step S403, when the first enabling switch is in the enabled state, a reconnection notification containing a token is sent to the source address of the first connection request identified as attack traffic, and for the reconnection notification of the second initial signaling message that does not receive a response and the number of token verification failures exceeds the threshold within the statistical period, the source address of the corresponding first connection request is identified as the attack source address.

[0074] The defense method provided in this embodiment defends against QUIC half-open connection attacks through the address verification mechanism of re-establishing the connection. In addition, considering that the address verification is performed using the Retry Packet (i.e., re-establishing) mechanism for each connection request, the normal connection request of the client will increase the network delay by one RTT. Furthermore, by monitoring the key indicators related to resource usage, defense functions such as attack traffic identification and address verification mechanism are dynamically enabled or disabled according to whether the key indicator data exceeds the threshold.

[0075] Specifically, multiple thresholds can be set: for example, two thresholds, a low threshold and a high threshold, can be set as conditions for determining whether the attack traffic identification and / or address verification mechanism is enabled. If the key indicator data is not higher than the low threshold, the defense function will not be enabled; if it is between the low threshold and the high threshold, the attack traffic identification will be enabled and only the detected attack traffic will be subjected to address verification to achieve defense; if it is higher than the high threshold, all received first connection requests will be subjected to address verification, and the attack traffic identification function can be turned off. Among them, the first threshold is a low threshold, and the second threshold is a high threshold; the method further includes: controlling the second enabling switch to be enabled or disabled according to whether the key indicator data is higher than the threshold of the corresponding indicator; when the second enabling switch is in the enabled state, a reconnection notification containing a token is sent to the source address of each first connection request that fails token verification, and for the reconnection notification of the second initial signaling message that has not received a response and for which the number of token verification failures exceeds the threshold within the statistical period, the source address of the first connection request corresponding to the reconnection notification is identified as the attack source address. Among them, controlling the second enabling switch to be in an enabled state or a disabled state according to whether the key indicator data is higher than the threshold of the corresponding indicator includes: when the key indicator data is not higher than the first threshold of the corresponding indicator, setting both the second enabling switch and the first enabling switch to a disabled state; and / or, when the key indicator data is higher than the first threshold of the corresponding indicator and not higher than the second threshold of the corresponding indicator, setting the second enabling switch to a disabled state and setting the first enabling switch to an enabled state; and / or, when the key indicator data is higher than the second threshold of the corresponding indicator, setting the second enabling switch to an enabled state and setting the first enabling switch to a disabled state; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator; wherein the key indicator data includes the total number of QUIC connections and / or the rate of new QUIC connections.

[0076] Specifically, attack traffic can be identified according to the preset source address rules. Attack traffic can be detected by source IP statistics based on the source IP threshold rules, or by matching source IP to blacklist based on the source IP blacklist. The two methods can be combined. The corresponding preset source address rules include source IP threshold rules and / or source IP blacklists; the identification of whether the first connection request that fails token verification according to the preset source address rules is attack traffic includes: counting the source addresses of the first connection request that fails token verification, if the statistical number of connection requests that fail token verification for the same source address exceeds the threshold contained in the source IP threshold rules, then the first connection request is identified as attack traffic; and / or, matching the source IP of the first connection request that fails token verification with the IP address and / or IP address segment in the source IP blacklist, if they match, then the first connection request is identified as attack traffic. For example, detecting attack traffic by source IP statistics based on the source IP threshold rules can be specifically as follows: counting the number of connection requests per unit time for a single IP, and if it exceeds the threshold, then the first connection request from the IP is identified as attack traffic. Furthermore, it also includes: aggregating the identified attack source addresses into attack source network segments, and outputting the attack source network segments so that the attack source network segments are added to the configuration of the preset source address rules, specifically, added to the source IP blacklist configuration of the source address rules. During implementation: based on the verification result feedback of the address verification mechanism over a period of time (i.e., the aggregation period), establish an attack source network segment blacklist of suspected attack traffic as at least part of the rule of the source IP blacklist; when the source IP of the newly received first connection request hits the IP address segment blacklist included in the source IP blacklist, it is identified as attack traffic for further address verification. In contrast, the whitelist mechanism for non-attack traffic will still perform address verification on normal connection requests that are not in the whitelist when no attack occurs, while the blacklist for attack traffic only requires address verification of attack traffic in the case of occasional attacks. Because attacks are occasional, and there are no attacks in most scenarios, the blacklist mechanism for attack traffic is preferred.

[0077] In this embodiment, attack traffic identification is performed on the first connection request message for the initial connection establishment, and the first connection request and the second initial signaling message in response to the reconnection notification can be distinguished by whether the message contains token information. Specifically, the first initial signaling message does not contain token information, or the first initial signaling message contains illegal token information or the token information has expired; the second initial signaling message contains token information; the method further includes: determining whether the first initial signaling message contains legal token information; if not, executing: when the first enabling switch is in the enabled state, identifying whether the received first connection request is attack traffic according to the preset source address rule, and sending a reconnection notification containing the token to the source address of the first connection request identified as attack traffic.

[0078] It should be noted that, unless there is a conflict, the features given in this embodiment and other embodiments of the present application can be combined with each other, and steps S401 and S402 or similar terms do not limit the steps to being performed in sequence.

[0079] So far, the method provided in this embodiment has been explained. The method defends against QUIC half-open connection attacks through the address verification mechanism of re-establishing the connection, and dynamically enables or disables defense functions such as attack traffic identification and address verification mechanism based on whether key indicator data exceeds the threshold. This can greatly reduce the impact of address verification on network delays caused by normal connection requests.

[0080] Corresponding to the second embodiment, the third embodiment of the present application also provides a defense device against network attacks. For the relevant parts, please refer to the description of the corresponding method embodiment. Figure 5 ,The defense devices against network attacks shown in the figure include:

[0081] The resource monitoring unit 501 is configured to obtain key indicator data of the protected device and control the first enabling switch to be enabled or disabled based on whether the key indicator data is higher than a threshold value of a corresponding indicator; wherein the key indicator data is indicator data representing resource usage;

[0082] An attack traffic detection unit 502 is configured to, when the first enabling switch is in an enabled state, identify, according to a preset source address rule, whether a first connection establishment request that fails token verification is attack traffic; the first connection establishment request is a first initial signaling message for establishing a QUIC connection between the protected device and the source address of the first connection establishment request;

[0083] The address verification unit 503 is used to send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic when the first enabling switch is in the enabled state, and for the reconnection notification of the second initial signaling message to which no response is received and the number of token verification failures exceeds a threshold within a statistical period, identify the source address of the corresponding first connection request as an attack source address.

[0084] Optionally, the device further includes a feedback aggregation unit, which is used to aggregate the identified attack source addresses into attack source network segments, and output the attack source network segments so that the attack source network segments are added to the configuration of the preset source address rules.

[0085] Optionally, the resource monitoring unit 501 is further used to: control the second enabling switch to be in an enabled state or a disabled state according to whether the key indicator data is higher than the threshold of the corresponding indicator; the address verification unit 503 is further used to: when the second enabling switch is in an enabled state, send a reconnection notification containing a token to the source address of each first connection request in which token verification fails, and for the reconnection notification of the second initial signaling message that does not receive a response and the number of token verification failures exceeds a threshold within a statistical period, identify the source address of the first connection request corresponding to the reconnection notification as an attack source address.

[0086] Optionally, the resource monitoring unit is specifically used to: when the key indicator data is not higher than the first threshold of the corresponding indicator, set the second enable switch and the first enable switch to a disabled state; and / or, when the key indicator data is higher than the first threshold of the corresponding indicator and not higher than the second threshold of the corresponding indicator, set the second enable switch to a disabled state, and set the first enable switch to an enabled state; and / or, when the key indicator data is higher than the second threshold of the corresponding indicator, set the second enable switch to an enabled state, and set the first enable switch to a disabled state; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator; wherein the key indicator data includes the total number of QUIC connections and / or the QUIC new connection rate.

[0087] Optionally, the attack traffic detection unit 502 is specifically used to: the preset source address rules, including source IP threshold rules and / or source IP blacklist; count the source addresses of the first connection request that fails the token verification, if the statistical number of connection requests that fail the token verification with the same source address exceeds the threshold included in the source IP threshold rule, then identify the first connection request as attack traffic; and / or, match the source IP of the first connection request that fails the token verification with the IP address and / or IP address segment in the source IP blacklist, if they match, then identify the first connection request as attack traffic.

[0088] Optionally, the first initial signaling message does not contain token information, or the first initial signaling message contains illegal token information or the token information has expired; the second initial signaling message contains token information; the attack traffic detection unit 502 is specifically used to: determine whether the first initial signaling message contains legal token information; if not, execute: when the first enabling switch is in the enabled state, identify whether the received first connection request is attack traffic according to a preset source address rule; the address verification unit 503 is specifically used to: determine whether the first initial signaling message contains token information; if not, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic.

[0089] Based on the above embodiment, one embodiment of the present application provides an electronic device. For the relevant parts, please refer to the corresponding description of the above embodiment. Figure 6 Schematic diagram of an electronic device, the electronic device shown in the figure includes: a memory, and a processor; the memory is used to store a computer program, and after the computer program is run by the processor, the method provided in the embodiment of the present application is executed.

[0090] Based on the above embodiments, one embodiment of the present application provides a computer storage medium. For relevant parts, please refer to the corresponding description of the above embodiments. The schematic diagram of the computer storage medium is similar to the schematic diagram of an electronic device, and the memory in the figure can be understood as the storage medium. The computer storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method provided in the embodiment of the present application.

[0091] In a typical configuration, an electronic device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM), and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0092] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0093] Although the present application is disclosed as above with the preferred embodiments, it is not intended to limit the present application. Any person skilled in the art may make possible changes and modifications without departing from the spirit and scope of the present application. Therefore, the scope of protection of the present application shall be based on the scope defined by the claims of the present application.

Claims

1. A defense system against network attacks, characterized in that: include: Resource monitoring module, statistics and matching module and address verification module; among them, The resource monitoring module is configured to obtain key indicator data of the protected device and enable or disable the functions of the statistics and matching module and / or the address verification module based on whether the key indicator data is higher than a threshold value of the corresponding indicator; wherein the key indicator data is indicator data representing resource usage; The statistics and matching module is used to, when in an enabled state, identify whether the first connection request that fails token verification is attack traffic according to a preset source address rule, and pass the first connection request identified as attack traffic to the address verification module; the first connection request is a first initial signaling message for establishing a QUIC connection between the protected device and the source address of the first connection request; The address verification module is used to, when in an enabled state, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic, and for the reconnection notification for which no response is received and the number of token verification failures exceeds a threshold within a statistical period, identify the source address of the corresponding first connection request as the attack source address.

2. The system according to claim 1, wherein: The system further includes: a feedback aggregation module; The feedback aggregation module is used to obtain the attack source address identified by the address verification module, aggregate the attack source address into an attack source network segment, and output the attack source network segment so that the attack source network segment is added to the configuration of the preset source address rule.

3. The system according to claim 1, wherein: The enabling or disabling of the functions of the statistics and matching module and / or the address verification module according to whether the key indicator data is higher than the threshold of the corresponding indicator includes: When the key indicator data is not higher than the first threshold value of the corresponding indicator, shutting down the statistics and matching module and the address verification module; and / or, When the key indicator data is higher than the first threshold value of the corresponding indicator and not higher than the second threshold value of the corresponding indicator, the statistics and matching module and the address verification module are enabled; and / or, When the key indicator data is higher than the second threshold value of the corresponding indicator, the statistics and matching module is closed and the address verification module is enabled; the address verification module is specifically used to send a reconnection notification containing a token to the source address of each first connection request in which token verification fails when the key indicator data is higher than the second threshold value of the corresponding indicator, and for the reconnection notification of the second initial signaling message to which no response is received and the number of token verification failures within the statistical period exceeds the threshold, identify the source address of the first connection request corresponding to the reconnection notification as the attack source address; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator; Among them, the key indicator data includes the total number of QUIC connections and / or the rate of new QUIC connections.

4. The system according to claim 1, wherein: The resource monitoring module is specifically configured to: control the first enabling switch and the second enabling switch to be enabled or disabled according to whether the key indicator data is higher than the threshold of the corresponding indicator, so as to dynamically enable or disable the functions of the statistics and matching module and the address verification module; The statistics and matching module is specifically configured to enter an enabled state when the first enabling switch is in an enabled state; and enter a disabled state when the second enabling switch is in an enabled state; The address verification module is specifically used to: when the first enabling switch is in the enabled state, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic by the statistics and matching module, and for the reconnection notification of the second initial signaling message that has not received a response, identify the source address of the corresponding first connection request as the attack source address; when the second enabling switch is in the enabled state, send a reconnection notification containing a token to the source address of each first connection request that fails token verification, and for the reconnection notification of the second initial signaling message that has not received a response and the number of token verification failures within the statistical period exceeds a threshold, identify the source address of the first connection request corresponding to the reconnection notification as the attack source address.

5. The system according to claim 4, characterized in that The controlling the first enabling switch and the second enabling switch to be in an enabled state or a disabled state according to whether the key indicator data is higher than a threshold value of a corresponding indicator includes: When the key indicator data is not higher than a first threshold value of the corresponding indicator, setting both the second enabling switch and the first enabling switch to a disabled state; and / or, When the key indicator data is higher than a first threshold value of the corresponding indicator and not higher than a second threshold value of the corresponding indicator, setting the second enabling switch to a disabled state and setting the first enabling switch to an enabled state; and / or, When the key indicator data is higher than a second threshold value of the corresponding indicator, setting the second enabling switch to an enabled state and setting the first enabling switch to a disabled state; The second threshold of the key indicator is greater than the first threshold of the corresponding indicator.

6. The system according to claim 1, wherein: The preset source address rules include source IP threshold rules and / or source IP blacklist; The step of identifying whether the first connection establishment request that fails token verification is attack traffic according to a preset source address rule includes: Counting the source addresses of the first connection requests that fail the token verification, if the statistical number of connection requests with the same source address that fail the token verification exceeds the threshold included in the source IP threshold rule, identifying the first connection request as attack traffic; and / or, The source IP of the first connection request that fails the token verification is matched with the IP addresses and / or IP address segments in the source IP blacklist. If a match occurs, the first connection request is identified as attack traffic.

7. The system according to claim 1, wherein: The first initial signaling message does not include token information, or the first initial signaling message includes illegal token information or the token information has expired; the second initial signaling message includes token information; The statistics and matching module is specifically used to: When in the enabled state, determining whether the first initial signaling message contains legal token information; if not, identifying whether the received first connection establishment request is attack traffic according to a preset source address rule; The address verification module is specifically used to: When in the enabled state, determine whether the first initial signaling message contains legal token information; if not, send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic.

8. A method for defending against network attacks, characterized in that: include: Acquire key indicator data of the protected device, and control the first enabling switch to an enabled state or a disabled state according to whether the key indicator data is higher than a threshold value of a corresponding indicator; wherein the key indicator data is indicator data representing resource usage; When the first enabling switch is in an enabled state, identifying whether the first connection request that fails token verification is attack traffic according to a preset source address rule; the first connection request is a first initial signaling message for establishing a QUIC connection between the protected device and the source address of the first connection request; When the first enabling switch is in the enabled state, a reconnection notification containing a token is sent to the source address of the first connection request identified as attack traffic. For the reconnection notification of the second initial signaling message to which no response is received and the number of token verification failures exceeds a threshold within a statistical period, the source address of the corresponding first connection request is identified as the attack source address.

9. The method according to claim 8, characterized in that Also includes: The identified attack source addresses are aggregated into attack source network segments, and the attack source network segments are output, so that the attack source network segments are added to the configuration of the preset source address rule.

10. The method according to claim 8, characterized in that Also includes: Controlling the second enabling switch to an enabled state or a disabled state according to whether the key indicator data is higher than a threshold value of the corresponding indicator; When the second enabling switch is in the enabled state, a reconnection notification containing a token is sent to the source address of each first connection request that fails token verification. For the reconnection notification of the second initial signaling message that does not receive a response and the number of token verification failures exceeds a threshold within a statistical period, the source address of the first connection request corresponding to the reconnection notification is identified as the attack source address.

11. The method according to claim 10, characterized in that The controlling the second enabling switch to be in an enabled state or a disabled state according to whether the key indicator data is higher than a threshold value of a corresponding indicator includes: When the key indicator data is not higher than a first threshold value of the corresponding indicator, setting both the second enabling switch and the first enabling switch to a disabled state; and / or, When the key indicator data is higher than a first threshold value of the corresponding indicator and not higher than a second threshold value of the corresponding indicator, setting the second enabling switch to a disabled state and setting the first enabling switch to an enabled state; and / or, When the key indicator data is higher than a second threshold value of the corresponding indicator, setting the second enabling switch to an enabled state and setting the first enabling switch to a disabled state; wherein the second threshold of the key indicator is greater than the first threshold of the corresponding indicator; Among them, the key indicator data includes the total number of QUIC connections and / or the rate of new QUIC connections.

12. The method according to claim 8, characterized in that The preset source address rules include source IP threshold rules and / or source IP blacklist; The step of identifying whether the first connection establishment request that fails token verification is attack traffic according to a preset source address rule includes: Counting the source addresses of the first connection requests that fail the token verification, if the statistical number of connection requests with the same source address that fail the token verification exceeds the threshold included in the source IP threshold rule, identifying the first connection request as attack traffic; and / or, The source IP of the first connection request that fails the token verification is matched with the IP addresses and / or IP address segments in the source IP blacklist. If a match occurs, the first connection request is identified as attack traffic.

13. The method according to claim 8, characterized in that The first initial signaling message does not include token information, or the first initial signaling message includes illegal token information or the token information has expired; The second initial signaling message includes token information; The method further comprises: Determining whether the first initial signaling message includes legal token information; If not, execute: when the first enabling switch is in the enabled state, identify whether the received first connection request is attack traffic according to the preset source address rule, and send a reconnection notification containing a token to the source address of the first connection request identified as attack traffic.

14. An electronic device, characterized in that: include: A memory and a processor; the memory is used to store a computer program, and after the computer program is run by the processor, the method according to any one of claims 8 to 13 is executed.

15. A computer storage medium, characterized in that Computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of claims 8 to 13.