Malicious host detection methods, devices, equipment and media

By statistically analyzing access address changes and congestion events in network transmission links and combining them with historical trust levels to identify malicious hosts, the problem of inaccurate malicious host identification in existing technologies is solved, enabling accurate identification and punishment of malicious hosts.

CN120675813BActive Publication Date: 2025-10-28PENG CHENG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511121747.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-12
Publication Date
2025-10-28
Estimated Expiration
2045-08-12

AI Technical Summary

Technical Problem

Existing technologies struggle to accurately identify and block malicious hosts on network transmission links, leading to network congestion and making it impossible to completely block attacks from malicious hosts.

Method used

By acquiring access address change events and congestion events within the current time window, the number of congestion participations, access address changes, and consecutive participations of each target host are counted. The initial trust level is calculated, and combined with the historical trust level, a target decision model is used to identify malicious hosts.

Benefits of technology

It improves the accuracy of malicious host identification, enables long-term punishment of malicious hosts, and blocks their attacks on network transmission links.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675813B_ABST
    Figure CN120675813B_ABST
Patent Text Reader

Abstract

The present application discloses a malicious host detection method, apparatus, device, and medium. Based on multiple access address change events and multiple congestion events within a current time window, the method calculates the initial trust of each target host identifier within the current time window by counting the number of congestion participations, access address change times, and consecutive participation times of each target host identifier. The method also obtains the historical trust corresponding to each target host identifier in the historical time window and calculates the target trust of each target host identifier based on the initial trust and the corresponding historical trust. The method also obtains a current state data set and inputs the state data set into a target decision model to obtain a target trust threshold. The method then identifies malicious hosts based on the target trust threshold and the target trust of each target host identifier. This improves the accuracy of identifying malicious hosts and blocks attacks on network transmission links by malicious hosts.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular to a method, apparatus, device and medium for detecting malicious hosts. Background Technology

[0002] In computing network systems, the expansion of service types and target users has led to a wider distribution and a larger number of computing nodes. Consequently, the number of network transmission links involved in computing network services has also increased, raising the risk of malicious attacks on these links. For example, attackers may compromise multiple authenticated hosts within the network and coordinate attacks on transmission links to maliciously consume network bandwidth resources, causing congestion on previously normal network transmission links. This results in users being unable to access the computing services provided by the computing network system. Therefore, it is necessary to identify malicious hosts causing network transmission link congestion.

[0003] Related technologies identify malicious hosts by monitoring malicious traffic. However, this method relies on mining the relevant characteristics of malicious traffic. In transmission link attacks, benign and malicious traffic are similar, making it difficult for this method to mine the differences in traffic characteristics between benign and malicious traffic. Therefore, it is difficult to distinguish between benign and malicious traffic, thus reducing the accuracy of identifying malicious hosts. As a result, this method can only temporarily alleviate network transmission link congestion and cannot completely block malicious host attacks. Summary of the Invention

[0004] This application provides a method, apparatus, device, and medium for detecting malicious hosts, which can improve the accuracy of identifying malicious hosts and block malicious hosts from attacking network transmission links.

[0005] In a first aspect, an embodiment of this application provides a method for detecting malicious hosts, comprising:

[0006] Retrieve multiple access address change events and multiple congestion events within the current time window. Each access address change event contains the target host identifier for the changed access address, and each congestion event contains the target host identifier for the network link congestion.

[0007] Based on the multiple access address change events and the multiple congestion events, the number of congestion participations, access address changes, and consecutive participations for each target host identifier are counted.

[0008] Based on the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier within the current time window, calculate the initial trust level of each target host identifier within the current time window.

[0009] Obtain the historical trust score of each target host identifier within a historical time window, and calculate the target trust score of each target host identifier based on the initial trust score and the corresponding historical trust score.

[0010] Obtain the current state dataset and input the state dataset into the target decision model to obtain the target trust threshold;

[0011] Malicious host identifiers are identified based on the target trust threshold and the target trust level of each target host identifier.

[0012] Secondly, an embodiment of this application provides a malicious host detection device, comprising:

[0013] The acquisition unit is used to acquire multiple access address change events and multiple congestion events within the current time window. Each access address change event contains the target host identifier of the changed access address, and each congestion event contains the target host identifier of the network link congestion.

[0014] The statistics unit is used to count the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier based on the multiple access address change events and the multiple congestion events.

[0015] The first calculation unit is used to calculate the initial trust level of each target host identifier in the current time window based on the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier in the current time window.

[0016] The second calculation unit is used to obtain the historical trust level of each target host identifier in the historical time window, and to calculate the target trust level of each target host identifier based on the initial trust level and the corresponding historical trust level.

[0017] The input unit is used to acquire the current state dataset, input the state dataset into the target decision model, and obtain the target trust threshold.

[0018] The identification unit is used to identify malicious host identifiers based on the target trust threshold and the target trust level of each target host identifier.

[0019] In some embodiments, the first computing unit is further configured to:

[0020] Based on the number of congestion participations for each target host identifier within the current time window, a direct participation score is determined for each target host identifier.

[0021] Calculate the continuous participation score based on the number of consecutive participations for each target host identifier within the current time window;

[0022] Calculate the address change score based on the number of access address changes for each target host identifier within the current time window;

[0023] The direct participation score, the continuous participation score, and the address change score are weighted and calculated to obtain the initial trust level of each target host identifier within the current time window.

[0024] In some embodiments, the first computing unit is further configured to:

[0025] Determine the first evidence weighting factor for the direct participation in the scoring association, the second evidence weighting factor for the continuous participation in the scoring association, and the third evidence weighting factor for the address change scoring association;

[0026] Wherein, the sum of the first evidence weight factor, the second evidence weight factor, and the third evidence weight factor is 1;

[0027] The direct participation score, the continuous participation score, and the address change score are weighted according to the first evidence weighting factor, the second evidence weighting factor, and the third evidence weighting factor to obtain the initial trust level of each target host identifier within the current time window.

[0028] In some implementations, there are multiple historical time windows, and the second calculation unit is further configured to:

[0029] Determine the current trust weight factor corresponding to the current time window and the historical trust weight factor corresponding to each historical time window. The historical trust weight factor decreases exponentially as the distance between the corresponding historical time window and the current time window increases.

[0030] Based on the current trust weight factor and each historical trust weight factor, the initial trust level of each target host identifier and the corresponding multiple historical trust levels are weighted and summed to obtain the target total trust score corresponding to each target host identifier.

[0031] The total trust weight coefficient is determined by combining the current trust weight factor and each historical trust weight factor, and the target trust level of each target host identifier is determined based on the ratio between the target total trust score of each target host identifier and the total trust weight coefficient.

[0032] In some embodiments, the identification unit is further configured to:

[0033] The target trust level of each target host identifier is compared with the target trust threshold to obtain the comparison result;

[0034] Based on the comparison results, the target host identifier whose target trust level is less than the target trust level threshold is identified as a malicious host identifier.

[0035] In some embodiments, the malicious host detection device further includes a penalty control unit, used for:

[0036] The number of consecutive penalties for each malicious host identifier within multiple historical time windows is determined, and the corresponding penalty parameters are determined based on the difference between the number of historical time windows and the number of consecutive penalties.

[0037] Determine the target trust ratio between the target trust level and the target trust level threshold for each malicious host identifier, and determine the target trust loss ratio for each malicious host identifier based on the target trust ratio.

[0038] The traffic rate limit ratio for each malicious host identifier is obtained by raising the corresponding penalty parameter to the power of the target trust loss ratio.

[0039] The traffic rate limit percentage for each malicious host identifier is sent to each network device so that each network device limits the traffic rate of each malicious host identifier according to the traffic rate limit percentage for each malicious host identifier.

[0040] In some embodiments, the malicious host detection device further includes a training unit for:

[0041] The sample target trust level of each sample host identifier, the average trust level among multiple sample host identifiers, the historical trust level threshold of the sample, the number of malicious hosts, the rate of change of the number of sample congestion events, and the average traffic rate limit ratio of the multiple sample host identifiers, as well as the benign host identifier and the malicious host identifier among the multiple sample host identifiers.

[0042] A sample status dataset is constructed based on the sample average trust level, the sample historical trust level threshold, the sample number of malicious hosts, the sample congestion event frequency change rate, and the sample average traffic rate limit ratio. The first number of samples of benign host identifiers and the second number of samples of malicious host identifiers are determined among the multiple sample host identifiers.

[0043] The sample state dataset is input into a preset decision model to obtain a predicted trust threshold, and the predicted malicious host identifier is identified based on the predicted trust threshold and the sample target trust of each sample host identifier.

[0044] By combining the predicted malicious host identifier, the sample benign host identifier, and the sample malicious host identifier, a balance score of detection precision and recall for the sample malicious host identifier is determined, as well as the misclassification rate for misidentifying the sample benign host identifier as the predicted malicious host identifier.

[0045] Based on each predicted malicious host identifier and the sample target trust level of each sample host identifier, the predicted average traffic rate limit ratio is determined.

[0046] Determine the target difference between the balance score and the misjudgment rate and the predicted average flow rate limit ratio, and construct a reward function based on the target difference as a variable. The reward function takes maximizing the target difference as its optimization objective.

[0047] By combining the output value of the reward function and adjusting the model parameters of the preset decision model according to the optimization objective, the target decision model is obtained.

[0048] Furthermore, this application also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the aforementioned malicious host detection method.

[0049] Furthermore, embodiments of this application also provide a computer-readable storage medium storing a plurality of instructions adapted for loading by a processor to execute the aforementioned malicious host detection method.

[0050] This application embodiment acquires multiple access address change events and multiple congestion events within the current time window. Each access address change event includes the target host identifier that changed the access address, and each congestion event includes the target host identifier that participated in network link congestion. Based on the multiple access address change events and multiple congestion events, the number of congestion participations, access address changes, and consecutive participations of each target host identifier are counted. Based on the number of congestion participations, access address changes, and consecutive participations of each target host identifier within the current time window, the initial trust level of each target host identifier within the current time window is calculated. The historical trust level of each target host identifier in a historical time window is acquired, and the target trust level of each target host identifier is calculated based on the initial trust level and the corresponding historical trust level. The current state dataset is acquired and input into the target decision model to obtain the target trust level threshold. Based on the target trust level threshold and the target trust level of each target host identifier, malicious host identifiers are identified.

[0051] As shown above, we can first obtain multiple access address change events and multiple congestion events within the current time window. Each access address change event contains the target host identifier for the changed access address, and each congestion event contains the target host identifier for participating in network link congestion. Then, based on the multiple access address change events and multiple congestion events, we can count the number of congestion participations, access address changes, and consecutive participations for each target host identifier. In this way, we can construct multi-dimensional evidence data as the basis for calculating the trust level of the target host identifier. Then, based on the multi-dimensional evidence data, we can calculate the initial trust level of each target host identifier within the current time window and set the initial trust level of each target host identifier as... The initial trust level is combined with its historical trust level within a historical time window to calculate the target trust level of each target host identifier within the current time window. In this way, the current target trust level is calculated by combining the historical trust level within the historical time window and the initial trust level of the current time window. This avoids the phenomenon that malicious hosts are mistakenly identified as benign hosts because they participate in network link congestion less frequently within the current time window. Furthermore, the current state dataset is obtained and input into the target decision model to determine the target trust level threshold for the current time window. Finally, the target trust level of each target host identifier and the target trust level threshold are combined to identify the malicious host identifier. Therefore, compared to related technologies that identify malicious hosts through malicious traffic characteristics, which have relatively low accuracy, this application directly calculates the initial trust level based on the host trust level mechanism. It calculates the initial trust level through multiple dimensions, including the number of times each target host identifier participates in congestion, the number of times it changes its access address, and the number of times it continuously participates in congestion, corresponding to network link congestion data. This eliminates the need to detect malicious hosts by mining malicious traffic characteristics. Furthermore, it combines the trust level situation of historical time windows to calculate the final target trust level of each target host identifier, making the calculation of the trust level of each host more accurate. This allows for long-term punishment of malicious hosts and subsequent blocking of attacks on network transmission links by malicious hosts, thereby improving the accuracy of malicious host identification. Attached Figure Description

[0052] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 This is a schematic diagram of a malicious host detection system provided in an embodiment of this application.

[0054] Figure 2 This is a diagram illustrating the architecture of a malicious host detection system provided in an embodiment of this application.

[0055] Figure 3 This is a flowchart illustrating the steps of the malicious host detection method provided in the embodiments of this application;

[0056] Figure 4 An example diagram illustrating a scenario for updating host trust based on a sliding window, provided in an embodiment of this application;

[0057] Figure 5 This is a schematic diagram of the malicious host detection device provided in the embodiments of this application;

[0058] Figure 6 This is a schematic diagram of the network device provided in the embodiments of this application;

[0059] Figure 7 This is a schematic diagram of the server structure provided in an embodiment of this application. Detailed Implementation

[0060] To enable those skilled in the art to better understand the solutions of this application, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0061] It is understood that in the specific implementation of this application, network link congestion data, target host identifier, access address, number of times of congestion participation, number of times of access address change, number of consecutive participations, historical trust level, initial trust level, target trust level, and malicious host identifier are involved. When the above embodiments of this application are applied to specific products or technologies, permission or consent from the target is required, and the collection, use and processing of related data must comply with relevant laws, regulations and standards.

[0062] Furthermore, when this application embodiment needs to obtain relevant data, it will obtain separate permission or separate consent for relevant data such as network link congestion data, target host identifier, access address, number of congestion participations, number of access address changes, number of consecutive participations, historical trust level, initial trust level, target trust level, and malicious host identifier through pop-up windows or redirection to a confirmation page. After clearly obtaining separate permission or separate consent for relevant data such as network link congestion data, target host identifier, access address, number of congestion participations, number of access address changes, number of consecutive participations, historical trust level, initial trust level, target trust level, and malicious host identifier, it will then obtain the necessary data for this application embodiment to operate normally.

[0063] It should be noted that while some processes described in the specification, claims, and accompanying drawings contain multiple steps that appear in a specific order, it should be clearly understood that these steps may not be performed in the order they appear herein, or may be performed in parallel. The step numbers are merely used to distinguish different steps and do not represent any particular order of execution. Furthermore, descriptions such as "first," "second," or "objective" in this document are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0064] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0065] This application provides a method, apparatus, device, and medium for detecting malicious hosts. Specifically, the malicious host detection method of this application can be implemented in a computer device, which can be a server or a network device. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms. The network device can be a network switch, router, firewall, bridge, hub, gateway, VPN server, wireless access point (WAP), modem, etc., but is not limited to these.

[0066] This application provides a malicious host detection method that, based on multiple access address change events and multiple congestion events within the current time window, counts the number of congestion participations, access address changes, and consecutive participations for each target host identifier. This allows for the construction of multi-dimensional evidence data as the foundation for calculating the trust level of the target host identifier. The method calculates the initial trust level for each target host identifier within the current time window and combines this with the historical trust level within historical time windows and the initial trust level of the current time window to calculate the current target trust level. This avoids the phenomenon where a malicious host is mistakenly identified as a benign host due to a low number of network link congestion participations within the current time window. Furthermore, the method acquires the current state dataset and inputs it into a target decision model to determine the target trust level threshold for the current time window. Finally, by combining the target trust level of each target host identifier with the target trust threshold, the malicious host identifier is identified. Therefore, based on the host trust mechanism, the initial trust level is calculated using multiple dimensions for each target host identifier corresponding to network link congestion data, including the number of times it participated in congestion, the number of times it changed its access address, and the number of times it participated in congestion consecutively. This eliminates the need to detect malicious hosts by mining malicious traffic characteristics. Furthermore, by combining the trust level data from historical time windows, the final target trust level for each target host identifier is calculated, making the trust level calculation for each host more accurate. This allows for long-term punishment of malicious hosts and subsequent blocking of attacks on network transmission links by malicious hosts. Please refer to the specific embodiments below for details.

[0067] It should be noted that this malicious host detection method can be performed jointly by network devices and servers.

[0068] For example, taking a method for detecting malicious hosts jointly performed by network devices and servers as an example, see [link to relevant documentation]. Figure 1 This is a schematic diagram of a malicious host detection system provided in an embodiment of this application. The system includes multiple network devices 110 and a server 120.

[0069] The network device 110 can include two types: edge network devices and intermediate network devices, depending on the actual scenario. For example, when a network device is used to access a local target host, it can act as an edge network device. When it is one of the points of passage in the network transmission link, it can act as an intermediate network device. In addition, the network device can also directly act as a fixed type of role according to its transmission function. For example, some network devices always act as access layer network devices, while some network devices always act as intermediate network devices in the network transmission link. This is not limited here.

[0070] It should be noted that network device 110 can be installed with target applications, and can run corresponding application services through these applications. When acting as an edge network device at the access layer, network device 110 can detect whether the access address of the target host within a target time period has changed compared to its previous historical access address. If a change is detected, an access address change event is generated and sent to server 120. When acting as an intermediate network device in a network transmission link, the network device can detect the length of the data transmission queue and the transmission time. If the length of the data transmission queue is too long or the transmission delay is too long, it is determined that the current network transmission link is congested, the target hosts involved in the network link congestion are identified, a congestion event is generated, and the congestion event is sent to server 120. Server 120 can be a single service node, a distributed system composed of multiple service nodes, or a service node within a distributed system.

[0071] The server 120 executes the malicious host detection method in the following steps: Specifically, it acquires multiple access address change events and multiple congestion events within the current time window. Each access address change event includes the identifier of the target host whose access address has changed, and each congestion event includes the identifier of the target host involved in network link congestion. Based on these events, it counts the number of congestion participations, access address changes, and consecutive participations for each target host identifier. Based on these data, it calculates the initial trust level of each target host identifier within the current time window. It acquires the historical trust level of each target host identifier within a historical time window and calculates the target trust level based on the initial and historical trust levels. It acquires the current state dataset, inputs it into the target decision model, and obtains the target trust level threshold. Finally, it identifies the malicious host identifier based on the target trust level threshold and the target trust level of each target host identifier. Afterwards, server 120 can return the malicious host identifier to network device 110 for punishment, so that network device 110 can limit the traffic rate of the malicious host and reduce the traffic of the malicious host. No specific restrictions are imposed here.

[0072] Figure 2 This is a diagram of the malicious host detection system architecture provided in the embodiments of this application. For ease of understanding of the above embodiments, it is combined with... Figure 2 The architecture of the malicious host detection system is introduced below:

[0073] The malicious host detection system consists of a host, access layer, core network, computing center, and server in its architecture.

[0074] Among them, the host is a host that has been authenticated through the network. Attackers mainly infiltrate the host to control it to send low-speed traffic to the network transmission link, thereby maliciously occupying bandwidth and causing network transmission link congestion.

[0075] The access layer refers to the outermost layer of the network that hosts access, directly facing the hosts. It can be understood as edge network devices, representing the first layer network devices that directly face the hosts. The access layer can contain multiple first layer network devices.

[0076] The core network refers to the network transmission link system based on network devices (such as switches).

[0077] Among them, the computing power center refers to the computing power service center, which can provide computing power support for the business services of any host or terminal device.

[0078] Here, "server" refers to the server used to detect malicious hosts, namely server 120 mentioned above.

[0079] Specifically, attackers compromise hosts and control them to send low-speed traffic, causing congestion events on critical network links in the core network's transmission system. Upon detecting each congestion event, network devices upload network link congestion data, including the target host identifier, access address, and changed destination address, to server 120 to update the observed variables. Server 120 constructs multi-dimensional trust evidence based on the received network link congestion data (i.e., observed variables). This trust evidence includes direct participation evidence (number of times congestion occurred), behavioral consistency evidence (number of consecutive participations), and direct change evidence (number of times access addresses changed). Then, based on this multi-dimensional trust evidence, it calculates the initial trust level of each target host within the current time window. This initial trust level is then weighted and calculated by combining the initial trust levels of each target host across multiple historical time windows within the sliding window to obtain the host trust, i.e., the target trust level of each target host.

[0080] Furthermore, a dynamic target trust threshold can be generated based on deep reinforcement learning algorithms. Specifically, a state dataset can be constructed, including the average trust level, the historical trust threshold of the previous historical time window, the rate of change of the number of congestion events, the number of malicious hosts in the previous historical time window, and the overall average penalty of the previous historical time window. This dataset is then used as input for deep reinforcement learning to obtain the action, i.e., the target trust threshold.

[0081] Finally, malicious hosts are identified by comparing the target trust level of each target host with the target trust level threshold. Figure 2As shown, if the target trust level of hosts H1 and H4 is lower than the target trust level threshold, then hosts H1 and H4 are determined to be malicious hosts. Finally, malicious hosts H1 and H4 are punished by limiting their traffic rate at the access layer.

[0082] Therefore, multiple access address change events and multiple congestion events within the current time window can be obtained first. Each access address change event contains the target host identifier for the changed access address, and each congestion event contains the target host identifier for participating in network link congestion. Then, based on the multiple access address change events and multiple congestion events, the number of congestion participations, access address changes, and consecutive participations for each target host identifier can be counted. In this way, multi-dimensional evidence data can be constructed as the basic data for calculating the trust level of the target host identifier. Then, based on the multi-dimensional evidence data, the initial trust level of each target host identifier within the current time window can be calculated, and the initial trust level of each target host identifier can be set. The trust level is combined with its historical trust level within a historical time window to calculate the target trust level of each target host identifier within the current time window. In this way, the current target trust level is calculated by combining the historical trust level within the historical time window with the initial trust level of the current time window. This avoids the phenomenon that malicious hosts are mistakenly identified as benign hosts because they participate in network link congestion less frequently within the current time window. Furthermore, the current state dataset is obtained and input into the target decision model to determine the target trust level threshold for the current time window. Finally, the target trust level of each target host identifier and the target trust level threshold are combined to identify the malicious host identifier. Therefore, compared to related technologies that identify malicious hosts through malicious traffic characteristics, which have relatively low accuracy, this application directly calculates the initial trust level based on the host trust level mechanism. It calculates the initial trust level through multiple dimensions, including the number of times each target host identifier participates in congestion, the number of times it changes its access address, and the number of times it continuously participates in congestion, corresponding to network link congestion data. This eliminates the need to detect malicious hosts by mining malicious traffic characteristics. Furthermore, it combines the trust level situation of historical time windows to calculate the final target trust level of each target host identifier, making the calculation of the trust level of each host more accurate. This allows for long-term punishment of malicious hosts and subsequent blocking of attacks on network transmission links by malicious hosts, thereby improving the accuracy of malicious host identification.

[0083] For ease of understanding, each step of the malicious host detection method will be described in detail below. It should be noted that the order of the following embodiments is not intended to limit the preferred order of the embodiments.

[0084] See Figure 3 , Figure 3This is a flowchart illustrating the steps of a malicious host detection method provided in an embodiment of this application. In this embodiment, the malicious host detection method can be executed by a computer device, such as a server. The specific process is as follows:

[0085] 101. Obtain multiple access address change events and multiple congestion events within the current time window.

[0086] In computing network systems, the expansion of service types and target users has led to a wider distribution and a larger number of computing nodes. Consequently, the number of network transmission links involved in computing network services has also increased, raising the risk of malicious attacks on these links. For example, attackers may compromise multiple authenticated hosts within the network and coordinate attacks on transmission links to maliciously consume network bandwidth resources, causing congestion on previously normal network transmission links. This results in users being unable to access the computing services provided by the computing network system. Therefore, it is necessary to identify malicious hosts causing network transmission link congestion.

[0087] Related technologies typically identify malicious hosts by monitoring malicious traffic. However, this method relies on mining the characteristics of malicious traffic. In transmission link attacks, benign and malicious traffic are similar, making it difficult for this method to discover the differences in traffic characteristics between benign and malicious traffic. Therefore, it is difficult to distinguish between benign and malicious traffic, thus reducing the accuracy of identifying malicious hosts. Consequently, this method can only temporarily alleviate network transmission link congestion and cannot completely block malicious host attacks.

[0088] It's important to note that attackers typically employ link flooding attacks when targeting network transmission links. Link flooding is a typical dynamic and covert attack that involves continuously selecting critical network links (i.e., specific network transmission links). This means choosing different critical links each time, constantly switching between them, and controlling different malicious hosts to initiate low-speed traffic to congest each critical link, thus achieving the attack objective. For example, in a malicious host attack scenario, the attacker controls some low-security terminals (i.e., hosts, acting as malicious hosts) in the network to send low-speed traffic to surrounding servers serving the computing center. Since the route from the hosts to the surrounding servers passes through the critical network links, the traffic sent by the attacker through the malicious hosts aggregates on the critical network links, causing congestion.

[0089] To address the above issues, this application embodiment uses the target host identifiers involved in network link congestion corresponding to each congestion event within the current time window and the target host identifiers with changed access addresses corresponding to each access address change event. It statistically analyzes the number of congestion participations, access address changes, and consecutive participations for each target host identifier. This allows for the construction of multi-dimensional evidence data as the foundation for calculating the trust level of the target host identifier. The initial trust level for each target host identifier within the current time window is calculated, and the current target trust level is calculated by combining the historical trust level within historical time windows with the initial trust level of the current time window. This avoids the phenomenon where malicious hosts are misjudged as benign hosts due to a low number of network link congestion participations within the current time window. Furthermore, the current state dataset is obtained and input into the target decision model to determine the target trust level threshold for the current time window. Finally, by combining the target trust level of each target host identifier with the target trust threshold, the malicious host identifier is identified. Therefore, based on the host trust mechanism, the initial trust level is calculated by considering multiple dimensions such as the number of times each target host identifier participates in congestion, the number of times it changes its access address, and the number of times it continuously participates in congestion within the current time window. This eliminates the need to detect malicious hosts by mining malicious traffic characteristics. Furthermore, by combining the trust level data from historical time windows, the final target trust level of each target host identifier is calculated, making the trust level calculation of each host more accurate. This allows for long-term punishment of malicious hosts and subsequent blocking of attacks on network transmission links by malicious hosts.

[0090] Specifically, in order to identify malicious hosts with low security and controlled by attackers from multiple authenticated hosts, this application embodiment obtains multiple access address change events and multiple congestion events within the current time window. This allows for subsequent identification of malicious hosts based on a host trust mechanism. For example, the target host identifier involved in network link congestion corresponding to each congestion event within the current time window and the target host identifier of the changed access address corresponding to each access address change event can be combined to construct multi-dimensional host trust evidence for each target host. This allows for the calculation of the trust level of each target host, thereby identifying malicious hosts based on the trust level.

[0091] The time window can represent the number of attack events. It limits the number of attack events, meaning the size of each time window represents the number of attack events it can accommodate. For example, assuming a time window is based on 10 attack events, then 10 attack events accumulated since the end of the previous historical time window constitute a time window. Based on the 10 or more access address change events corresponding to the 10 attack events within this time window, the host participation information regarding the number of access address changes within the time window is statistically analyzed. It should be noted that an attack event refers to an event where the network device detects that a target host has changed its access address; that is, one or more attacks occur at a given moment. It should be noted that each attack event can be uploaded to the server by the first network device directly connected to the target host, while a congestion event can be uploaded to the server by one of the intermediate network devices forming the network transmission link. Each attack event does not necessarily cause a congestion event in the network transmission link. In order to associate the congestion event with the time window, when the number of attack events in the current time window reaches the event length defined by the current time window, the first time information of the first attack event in the current time window and the second time information of the last attack event in the current time window can be determined. The first time information and the second event information are combined to determine the target time range corresponding to the current time window, and a mapping relationship is established between the congestion events received within the target time range and the current time window, so as to construct multi-dimensional host trust evidence by combining multiple attack events in the current time window and the congestion events mapped by the current time window.

[0092] In addition, the time window can also be a window used to limit a time range. For example, the time window is 1 minute long and can specifically correspond to a time range, such as the time range from xx:00 to xx:01. Through this time window, attack events and congestion events uploaded by each network device within the corresponding time range are collected and statistically analyzed, so as to combine one or more attack events and one or more congestion events within the current time window to construct multi-dimensional host trust evidence.

[0093] It should be noted that each access address change event is uploaded by one of the network devices in the network link system, and each congestion event is uploaded by one of the network devices in the network link system. These network devices can be switches, routers, firewalls, bridges, hubs, gateways, VPN servers, wireless access points (WAPs), modems, etc., and are not limited here.

[0094] In some implementations, step 101 may include: acquiring multiple event information uploaded by multiple network devices, the multiple event information including multiple access address change events and multiple congestion events; and determining multiple target event information within the current time window based on the multiple event information.

[0095] Each access address change event and each congestion event can be understood as host participation information. Each access address change event contains the target host identifier for the changed access address, and each congestion event contains the target host identifier for the network link congestion. In addition, the access time information for each target host identifier can be recorded. Furthermore, this access time information can be specified down to the time "xx year xx month xx day xx hour xx minute xx second".

[0096] The target host identifier can be a unique identifier of the target host, an Internet Protocol address (IP), or a physical address of the target host (such as world coordinates, latitude and longitude, street address, etc.). There are no restrictions here. It is used to identify the identity of the target host and distinguish it from different hosts.

[0097] It's important to note that a congestion event represents a single instance of congestion on a network transmission link. Specifically, during data transmission, network devices can manage the traffic data of each host using data transmission queues to ensure a sequential transmission order and fairness. Based on this, the network device can monitor the length of the data transmission queue in real time—that is, the number of data items waiting to be transmitted—and the transmission latency of each data item in the queue. When the length of the data transmission queue exceeds a preset threshold or the transmission latency exceeds a preset threshold, the network transmission link corresponding to the network device is determined to be congested. At this point, the identifiers and access times of the target hosts causing the congestion are obtained to generate a congestion event. Therefore, a congestion event is triggered based on the length of the data transmission queue and the transmission latency of the network device.

[0098] It should be noted that network devices can detect whether the access address of each target host within the target time period has changed relative to the previous historical access address. If a change is detected, the device obtains the target host identifier that changed the access address within the target time period (e.g., 10 seconds) and generates an access address change event. Therefore, each access address change event is generated based on the target host identifier that participated in the change of access address within the target time period.

[0099] In addition, network devices can also directly send the access address of each target host identifier within the target time period to the server. The server detects whether the access address of each target host within the target time period has changed compared to the previous historical access address. If a change is detected, the server obtains the target host identifier whose access address has changed within the target time period and generates an access address change event. Specifically, the server determines the access timing relationship of multiple access addresses corresponding to each target host identifier according to the reception time order among them. For each target host identifier, the server compares any two adjacent access addresses according to the access timing relationship, obtains the comparison result, and determines the number of access address changes corresponding to each target host identifier based on the comparison result. This access address can be the address of the service that the target host wants to access when causing network transmission link congestion; for example, the access address can specifically be the Internet Protocol (IP) address of the service.

[0100] By using the above methods, multiple access address change events and multiple congestion events within the current time window can be obtained. This allows for the subsequent combination of multiple access address change events and multiple congestion events within a specific time window to construct multi-dimensional host trust evidence data, calculate the trust level of each target host, and thus identify malicious hosts based on the host trust level mechanism.

[0101] 102. Based on multiple access address change events and multiple congestion events, count the number of congestion participations, access address changes, and consecutive participations for each target host identifier.

[0102] In this embodiment, after obtaining multiple access address change events and multiple congestion events within the current time window, multi-dimensional host trust evidence is constructed by combining the target host identifiers involved in network link congestion corresponding to each congestion event and the target host identifiers of changed access addresses corresponding to each access address change event, using the current time window as a unit. For example, the number of congestion participations, access address changes, and consecutive participations of each target host identifier are counted. In this way, multi-dimensional host trust evidence representing host participation in network transmission link congestion is obtained, so that the initial trust level corresponding to each target host identifier can be calculated based on the multi-dimensional host trust evidence. Thus, malicious hosts can be identified without mining the traffic characteristics of each host, improving the accuracy of subsequent identification of malicious hosts.

[0103] The congestion participation count can be the number of times a target host participates in multiple congestion events within the current time window. For example, if a target host requests access to the corresponding service address through the corresponding network transmission link during a congestion event, it is considered to have participated in the congestion event, and the congestion participation count for that target host is incremented by 1. If the target host does not have an access request during the congestion event, it is considered not to have participated in the congestion event, and the congestion non-participation count for that target host is incremented by 1. Since the current time window includes the target number of congestion events, if a target host accesses the corresponding service address through the corresponding network transmission link during a congestion event, the congestion participation count is incremented by 1. Therefore, the congestion participation count for each target host is calculated based on multiple congestion events.

[0104] It should be noted that in a link flooding attack, the attacker controls the host to launch attacks on different critical network links in a rolling manner. Although the attacker selects one network transmission link to attack each congestion event, and this network transmission link involves some benign hosts, the number of congestion events participated in by benign hosts is relatively small compared to that of malicious hosts. Therefore, the number of congestion events participated in can be used as one of the trust evidences for assessing the trustworthiness of a host.

[0105] The access address change count can be the number of times the target host changes its access address in multiple access address change events within the current time window. An access address change can be understood as the destination address of the target host's current access service differing from its previous historical destination address. For example, if the target host accessed service destination address A in the previous access address change event and accessed service destination address B in the current access address change event, this indicates an access address change, and the access address change count is incremented by 1. Since the current time window contains the target number of access address change events, if the access address of a target host in the current access address change event differs from the access address in the previous access address change event, the access address change count is incremented by 1. Thus, the access address change count for each target host identifier is counted based on multiple access address change events within the current time window.

[0106] It's important to note that in link flooding attacks, attackers control hosts to launch attacks on different critical network links in a rolling fashion. Therefore, it's generally necessary to control the hosts to frequently change the destination address of the target server to ensure the attack traffic reaches the desired network transmission link. Unlike malicious hosts, benign hosts, to ensure the continuity of business flow, generally do not easily change the destination server they are accessing. Therefore, if a target host frequently changes its destination address when sending traffic, it is likely a malicious host. Based on this, the number of times the access address changes is used as one piece of trust evidence to assess the trustworthiness of a host.

[0107] The consecutive participation count can be the number of times the target host participates in congestion events consecutively within the current time window. For example, assuming a time window consists of 10 congestion events, and a target host participates consecutively in congestion events from the 1st to the 4th, and consecutively in congestion events from the 6th to the 8th, then the consecutive participation count is 2, the length of the first consecutive participation is 4 congestion events, and the length of the second consecutive participation is 3 congestion events.

[0108] It should be noted that attackers can only control a limited number of hosts, and some hosts may be reused as malicious hosts to launch low-traffic attacks on network transmission links. Therefore, if a target host participates in congestion events more frequently, it is likely a malicious host. Thus, the number of consecutive participations serves as one piece of trust evidence in assessing a host's trustworthiness. Each congestion event corresponds to the identifier of the target host participating in network link congestion, and each access address change event corresponds to the identifier of the target host whose access address has changed.

[0109] In some implementations, multidimensional trust evidence is constructed for multiple access address change events and multiple congestion events within the current time window. For example, statistics are performed based on the target host identifiers involved in network link congestion included in each congestion event within the current time window, and the target host identifiers whose access addresses have changed for each access address change event. Specifically, firstly, based on the target host identifiers involved in network link congestion included in each congestion event, the number of times each target host identifier participates in congestion is counted; simultaneously, based on the target host identifiers involved in network link congestion included in each congestion event within the current time window, the number of consecutive participations of each target host identifier in congestion events within the current time window is counted; furthermore, based on the target host identifiers whose access addresses have changed for each access address change event within the current time window, the number of access address changes for each target host identifier within the current time window is counted. In this way, multidimensional host trust evidence is constructed based on the host participation information within the current time window to assess the trust level of the target host, so that the initial trust level of the target host can be calculated subsequently based on the multidimensional host trust evidence.

[0110] By combining the target host identifiers involved in network link congestion for each congestion event within the current time window with the target host identifiers of changed access addresses for each access address change event, multi-dimensional host trust evidence can be constructed. For example, the number of congestion participations, access address changes, and consecutive participations for each target host identifier can be counted. In this way, multi-dimensional host trust evidence representing host participation in network transmission link congestion can be obtained. This allows for the subsequent calculation of the initial trust level corresponding to each target host identifier based on the multi-dimensional host trust evidence. As a result, malicious hosts can be identified without mining the traffic characteristics of each host, thus improving the accuracy of subsequent malicious host identification.

[0111] 103. Based on the number of congestion participations, access address changes, and consecutive participations of each target host identifier within the current time window, calculate the initial trust level of each target host identifier within the current time window.

[0112] In this embodiment, after constructing the three-dimensional host trust evidence—congestion participation count, access address change count, and consecutive participation count—for each target host identifier, the initial trust level of each target host identifier within the current time window can be calculated by combining these three metrics. Specifically, a direct participation score can be calculated based on the congestion participation count, a consecutive participation score can be calculated based on the consecutive participation count, and an address change score can be calculated based on the access address change count. Then, the initial trust level of each target host is determined by combining the direct participation score, consecutive participation score, and address change score. In this way, the initial trust level corresponding to each target host identifier is calculated using the constructed multi-dimensional host trust evidence, enabling subsequent malicious host identification based on trust levels. This eliminates the need to mine the traffic characteristics of each host to identify malicious hosts, improving the accuracy of subsequent malicious host identification.

[0113] The initial trust level can reflect the host trust value of the corresponding target host within the current time window. It is determined based on the target host's participation in congestion events within the current time window. For example, it can be determined by comprehensively considering the number of times the target host participates in congestion events, the number of times it changes its access address, and the number of consecutive participations within the current time window. In other words, the trust level of the target host is evaluated based on its participation in congestion events within the current time window. This initial trust level can be understood as a trust value indicating that the corresponding target host belongs to the benign host category.

[0114] In some implementations, a direct participation score can be calculated based on the number of congestion participations for each target host identifier, a continuous participation score can be calculated based on the number of consecutive participations for each target host identifier, and an address change score can be calculated based on the number of access address changes for each target host identifier. The direct participation score, continuous participation score, and address change score are then weighted to obtain the initial trust level for each target host identifier within the current time window. For example, step 103 may include:

[0115] (103.1) Determine the direct participation score for each target host identifier based on the number of congestion participations for each target host identifier within the current time window;

[0116] (103.2) Calculate the continuous participation score based on the number of consecutive participations for each target host identifier within the current time window;

[0117] (103.3) Calculate the address change score based on the number of access address changes for each target host identifier within the current time window;

[0118] (103.4) The direct participation score, continuous participation score and address change score are weighted and calculated to obtain the initial trust level of each target host identifier in the current time window.

[0119] The direct participation score can be a sub-trust score representing the number of times a target host identifier participates in congestion events within the current time window. The more times a target host participates in congestion events within the current time window, the lower the direct participation score, the higher the probability of being judged as a malicious host, and the lower the likelihood of being trusted. For example, a Beta distribution is used to calculate the number of direct participations of a target host in congestion events, and the direct participation score is used as one of the direct participation pieces of evidence in the multi-dimensional host trust evidence. Since it is impossible to confirm whether a host is malicious at the initial moment, a uniform distribution is used as the initial distribution of the direct participation evidence. The calculation process for the direct participation score of each target host identifier within the current time window is as follows:

[0120]

[0121] in, Indicates the corresponding target host In the current time window Direct participation in scoring, Represents the target host The number of times the user does not participate in congestion events within the current time window. Represents the host The number of times a participant participates in a congestion event within the current time window, i.e., the number of times a participant participates in congestion.

[0122] The continuous participation score can be a sub-trust score representing the number of consecutive participations of a target host identifier in congestion events within the current time window. The more consecutive participations a target host makes in congestion events within the current time window, the lower its continuous participation score, the greater the probability of it being judged as a malicious host, and the lower its trustworthiness. For example, the calculation process for the continuous participation score of each target host identifier within the current time window is as follows:

[0123]

[0124] in, Indicates the corresponding target host In the current time window Continuous participation in rating within the period, Indicates the target host The number of consecutive sequences of events that participate in congestion events within the current time window, i.e., the number of consecutive participations. Indicates the target host The length of a continuous sequence of congestion events within the current time window, i.e., how many consecutive congestion events are participated in without interruption.

[0125] The address change score can be a sub-trust score representing the number of times the corresponding target host identifier has changed its address in response to the access address change event within the current time window. If a target host changes its access address more times within the current time window, the address change score will be smaller, the probability of being judged as a malicious host will be greater, and the possibility of being trusted will be smaller, that is, the trust level of the target host will be relatively low.

[0126] The statistics for the number of access address changes for each target host identifier within the current time window are as follows:

[0127]

[0128] in, Indicates the corresponding target host The number of times the access address has changed within the current time window. This indicates the number of access address change events contained within the current time window. It can be a two-dimensional array. Indicates the first The target host under the next access address change event Whether the user participated in the current access address change event. If the user participated, the value is 1; otherwise, the value is 0.

[0129] Furthermore, the calculation method for this address change score is as follows:

[0130]

[0131] in, Indicates the corresponding target host In the current time window Internal address change rating, Indicates the corresponding target host Number of times the access address has changed within the current time window.

[0132] Finally, a weighted calculation can be performed on the scoring of direct participation, continuous participation, and address change, to obtain the initial trust level of each target host identifier within the current time window. In this way, the initial trust level corresponding to each target host identifier is calculated using the constructed multi-dimensional host trust evidence, enabling subsequent malicious host identification based on trust levels. This eliminates the need to mine the traffic characteristics of each host to identify malicious hosts, improving the accuracy of subsequent malicious host identification.

[0133] In some implementations, different evidence weighting factors can be assigned to direct participation scoring, continuous participation scoring, and address change scoring respectively, and the direct participation scoring, continuous participation scoring, and address change scoring can be weighted according to the different evidence weighting factors to obtain the initial trust level of each target host identifier in the current time window. For example, step (103.4) may include: determining a first evidence weighting factor associated with direct participation scoring, a second evidence weighting factor associated with continuous participation scoring, and a third evidence weighting factor associated with address change scoring; wherein the sum of the first evidence weighting factor, the second evidence weighting factor, and the third evidence weighting factor is 1; and weighting the direct participation scoring, continuous participation scoring, and address change scoring according to the first evidence weighting factor, the second evidence weighting factor, and the third evidence weighting factor to obtain the initial trust level of each target host identifier in the current time window.

[0134] The first evidence weighting factor is used to measure the importance of the direct participation score in the process of identifying malicious hosts. The larger the first evidence weighting factor, the greater the weight of the direct participation score in calculating the initial trust level of the corresponding target host identifier. This indicates that the number of times the congestion event is involved should be given more consideration as evidence of host trust in the process of identifying malicious hosts.

[0135] The second evidence weighting factor is used to measure the importance of the continuous participation score in the process of identifying malicious hosts. The larger the second evidence weighting factor, the greater the weight of the continuous participation score in calculating the initial trust level of the corresponding target host identifier. This indicates that the number of consecutive participations in congestion events, as evidence of host trust, needs to be given more consideration in the process of identifying malicious hosts.

[0136] The third evidence weighting factor is used to measure the importance of address change score in the process of identifying malicious hosts. The larger the third evidence weighting factor, the greater the weight of address change score in calculating the initial trust level of the corresponding target host identifier. This indicates that the number of access address changes during congestion events, as evidence of host trust, needs to be given more consideration in the process of identifying malicious hosts.

[0137] Specifically, first, determine the weighting factors for the first piece of evidence directly involved in the scoring association, the second piece of evidence for continuous involvement in the scoring association, and the third piece of evidence for address change scoring association. For example, firstly, if more emphasis is placed on the number of times a host directly participates in congestion events when identifying malicious hosts, the weighting factor for the first piece of evidence can be increased. If it is necessary to balance the behavior of short-term involvement in congestion events with the behavior of long-term congestion events, the weighting factor for the first piece of evidence can be set to a corresponding value to ensure that the impact of the number of direct involvements is moderate. Secondly, if malicious hosts tend to repeatedly participate in attacks during link flooding attacks, the weighting factor for the second piece of evidence can be increased to make the continuous involvement behavior have a greater impact on trust. Thirdly, if attacks rely on frequently changing access destinations to hide their identities, the weighting factor for the third piece of evidence can be increased to highlight the role of address change scoring. Following the above methods, the weighting factors for the first, second, and third pieces of evidence are set respectively, and the sum of the weighting factors for the first, second, and third pieces of evidence is made equal to 1. This ensures that the subsequent weighted calculation of multi-dimensional scoring is standardized, interpretable, and practical. Furthermore, the direct participation score is multiplied by the first evidence weighting factor to obtain the first sub-score; the continuous participation score is multiplied by the second evidence weighting factor to obtain the second sub-score; and the address change score is multiplied by the third evidence weighting factor to obtain the third sub-score. The first, second, and third sub-scores are then added together to obtain the initial trust level for each target host identifier within the current time window. In this way, the initial trust level corresponding to each target host identifier is calculated using the constructed multi-dimensional host trust evidence, enabling subsequent malicious host identification based on trust levels. This eliminates the need to mine the traffic characteristics of each host to identify malicious hosts, improving the accuracy of subsequent malicious host identification.

[0138] For example, combining direct participation scoring, continuous participation scoring, and address change scoring, a weighted approach is used to calculate the initial trust level of each target host within the current time window. The calculation process for the initial trust level of each target host within the current time window is as follows:

[0139]

[0140] in, Indicates the corresponding target host In the current time window Initial level of trust within, This represents the first evidence weighting factor. This represents the weighting factor for the second piece of evidence. This represents the third evidence weighting factor. Thus, the initial trust level of each target host within the current time window is obtained.

[0141] By combining the congestion participation count, access address change count, and consecutive participation count of each target host identifier within the current time window, the initial trust level of each target host identifier within the current time window can be calculated. This allows for the calculation of the initial trust level corresponding to each target host identifier based on the constructed multi-dimensional host trust evidence, enabling subsequent malicious host identification based on trust levels. In this way, malicious hosts can be identified without mining the traffic characteristics of each host, improving the accuracy of subsequent malicious host identification.

[0142] 104. Obtain the historical trust level of each target host identifier within the historical time window, and calculate the target trust level of each target host identifier based on its initial trust level and corresponding historical trust level.

[0143] In this embodiment, since the initial trust level is only used to evaluate the participation of each target host in congestion events within the current time window, if the participation of a malicious host in congestion events within the current time window is considered only to identify the malicious host, it may lead to the original malicious host being mistakenly identified as a benign host. This increases the risk of the malicious host launching another large-scale attack on the network transmission link, which is detrimental to the security and stability of the subsequent network transmission link. Therefore, after obtaining the initial trust level corresponding to each target host identifier, the historical trust level corresponding to each target host identifier in a historical time window can be obtained. By combining the initial trust level and the corresponding historical trust level of each target host identifier, the target trust level of each target host identifier can be calculated. In this way, the final target trust level of each target host is determined by combining the initial trust level of each target host in the current time window and the historical trust level of each target host in the historical time window. This avoids the phenomenon that a malicious host may be mistakenly identified as a benign host because it reduces the number of times it participates in congestion events in the current time window. This improves the accuracy of subsequent identification of malicious hosts and avoids the risk of malicious hosts launching another large-scale attack on the network transmission link, thereby enhancing the security and stability of the subsequent network transmission link.

[0144] The historical time window can be a historical time window preceding the current time window. Specifically, it can be a target historical time window within a sliding window preceding the current time window. The sliding window can accommodate multiple target historical time windows, and the initial trust level of each target host identifier is then weighted and calculated based on its corresponding historical trust levels across multiple historical time windows within the sliding window. For a further explanation of the historical time window, please refer to the previous description of the "current time window," which will not be repeated here.

[0145] Here, the historical trust level can be the historical target trust level of the corresponding target host within the corresponding historical time window, i.e., the final trust level. Each historical time window corresponds to one historical trust level, which is calculated by combining the historical initial trust level calculated based on the congestion event participation information of the corresponding historical time window with the historical trust level of the earlier historical time window. For example, starting from the current time window, the historical time window closest to and adjacent to the current time window is defined as the first historical time window. Then, the second historical event window, the third historical time window, the fourth historical time window, and so on are defined. After calculating the historical initial trust level of each target host identifier based on the historical host participation information within the first historical time window, the historical trust level of each target host identifier within the first historical time window can be calculated by combining the historical trust level of the target host identifier within the second historical event window, the historical trust level of the target host identifier within the third historical time window, the historical trust level of the target host identifier within the fourth historical time window, and the historical initial trust level. It should be noted that the calculation methods for the historical trust scores of the second historical event window, the third historical time window, and the fourth historical time window can refer to the calculation process of the historical trust score of each target host identifier within the first historical time window, and will not be listed here.

[0146] In this embodiment, since the malicious host used in each congestion event may be different, some malicious hosts may participate less in congestion events within certain time windows, leading to an increased trust assessment and misclassification as benign hosts. Therefore, to avoid blindly increasing host trust, a sliding window mechanism is introduced, considering historical assessment data, and a trust weight for historical time windows is designed. This weight is combined with the weight of the current event window to calculate the initial trust level and corresponding historical trust level for each target host identifier, thus obtaining the target trust level for each target host identifier. This improves the accuracy of malicious host identification.

[0147] In some implementations, the current trust weight factor corresponding to the current time window and the historical trust weight factor corresponding to each historical time window can be determined separately. The initial trust score of each target host identifier is then weighted and calculated by combining the current trust weight factor and each historical trust weight factor, yielding the target trust score for each target host identifier. For example, if there are multiple historical time windows, step 104, "calculating the target trust score for each target host identifier based on its initial trust score and corresponding historical trust score," can include: determining the current trust weight factor corresponding to the current time window and the historical trust weight factor corresponding to each historical time window, wherein the historical trust weight factor decreases exponentially as the distance between the corresponding historical time window and the current time window increases; weighting and summing the initial trust score of each target host identifier with the corresponding multiple historical trust scores according to the current trust weight factor and each historical trust weight factor, yielding the target total trust score for each target host identifier; determining the total trust weight coefficient by combining the current trust weight factor and each historical trust weight factor; and determining the target trust score for each target host identifier based on the ratio between the target total trust score and the total trust weight coefficient.

[0148] The current trust weight factor can be used to perform a weighted calculation with the target trust level of the corresponding target host identifier to participate in the calculation of the target trust level of each target host within the current time window. A larger current trust weight factor indicates greater emphasis on the initial trust level represented by each target host within the current time window. It should be noted that the current time window corresponds to the latest congestion event behavior data for each target host. Since the current behavior best reflects the real-time state of the target host, the current time window can be assigned the highest trust weight factor.

[0149] The historical trust weighting factor can be a weighting factor for a specific historical time window. It is used to perform a weighted calculation with the historical trust score of the corresponding target host within that historical time window to participate in the calculation of the target trust score of each target host within the current time window. It should be noted that, starting from the current time window, the historical trust weighting factor of each historical time window decreases exponentially with the distance from the window. This makes the "historical trust score" of the more distant historical time window have a smaller impact on the calculation of the "target trust score" of the current time window, which is consistent with the logic of "recent behavior is more critical".

[0150] Specifically, to determine the current trust weight factor corresponding to the current time window, the current trust weight factor can be set to 1. The calculation process for the historical trust weight factor corresponding to each historical time window is as follows:

[0151]

[0152] in, Indicates the corresponding target host The i-th historical time window within the sliding window Historical trust weighting factor within, This indicates the historical time window within the sliding window that precedes the current time window. Indicates the current time window. Represents the history time window within the sliding window. The host's historical trust level, Indicates the first [number]th ... Historical trust threshold under a historical time window This indicates the recovery parameters. It's important to note that... On the one hand, if within a historical time window If the historical trust level of a host is lower than the corresponding historical trust threshold, the recovery parameter is... , making the first The historical trust weighting factor is relatively large in the first historical time window to avoid blindly increasing the final target trust level of the host; on the other hand, if in the first historical time window... If the historical trust score of a host within a given historical time window is higher than the corresponding historical trust threshold, the recovery parameter is... , making the first The historical trust weighting factor for each historical time window is normal.

[0153] Furthermore, after determining the current trust weight factor corresponding to the current time window and the historical trust weight factor corresponding to each historical time window, the initial trust score of each target host identifier is weighted and summed with its corresponding multiple historical trust scores according to the current trust weight factor and each historical trust weight factor, to obtain the target total trust score for each target host identifier. Finally, the current trust weight factor and each historical trust weight factor are added together to obtain the total trust weight coefficient, and the target total trust score of each target host identifier is divided by the total trust weight coefficient to obtain the target trust score for each target host identifier. For example, the calculation process for the target trust score of each target host identifier within the current time window is as follows:

[0154]

[0155] in, Indicates the corresponding target host The i-th historical time window within the sliding window Internal target trust level This represents the size of the sliding window, i.e., the number of historical time windows it contains. This represents the i-th historical time window within the sliding window. Represents a historical time window Historical trust weighting factor Represents a historical time window Historical trust level of the host. The target host corresponding to the current time window The initial level of trust.

[0156] Figure 4 This is an example diagram illustrating a scenario where host trust is updated based on a sliding window, as provided in an embodiment of this application. (Combined with...) Figure 4 The following describes a scenario where a sliding window is used to change the host trust level:

[0157] Within the current time window, multiple network devices simultaneously report M destination address changes, indicating that M destination address change events occurred within the current time window. Multiple network devices upload N congestion events, indicating that n network transmission link congestion events occurred within the current time window. Each congestion event contains the identifier of the target host involved in the network link congestion, and each access address change event contains the identifier of the target host whose access address changed. For example, taking the first congestion event as an example, it includes a sequence of target host identifiers involved in the congestion event, i.e. Figure 4 For example, the "IE1" in the context of the first access address change event includes a sequence of the target host identifier for the changed access address. Figure 4 In the context of "CE1", "IE1" indicates that host 2 (IP2) and host 4 (IP4) participated in the first congestion event, and "CE1" indicates that host 2 (IP2) participated in a change of the access destination address. It should be noted that network devices can also directly upload the access address of each host to the server, allowing the server to determine whether an access address change event has occurred for each host based on its access address. Based on the above data, multi-dimensional trust evidence is constructed for host 1, host 2, host 3, ..., host n, namely, the number of congestion participations, the number of consecutive participations, and the number of access address changes, to calculate the initial trust level of each host.

[0158] Furthermore, by using a sliding window, four historical time windows preceding the current time window are selected, namely Ti, Ti-1, Ti-2, and Ti-3, and the historical trust level of each host in each historical time window is determined. Finally, for each host, a weighted calculation is performed by combining the weight factor corresponding to each historical time window with the corresponding historical trust level to obtain the final target trust level of each host in the current time window.

[0159] By combining the initial trust level of each target host identifier within the current time window with its historical trust level within historical time windows, the final target trust level of each target host identifier can be determined. This avoids the phenomenon of a malicious host being mistakenly identified as a benign host due to a reduction in the number of congestion events it participates in within the current time window. This improves the accuracy of subsequent identification of malicious hosts, thereby avoiding the risk of malicious hosts launching another large-scale attack on network transmission links and enhancing the security and stability of subsequent network transmission links.

[0160] 105. Obtain the current state dataset, input the state dataset into the target decision model, and obtain the target trust threshold.

[0161] In this embodiment, after obtaining the target trust level corresponding to each target host identifier within the current time window, a reinforcement learning algorithm can be used to calculate the current target trust level threshold in order to identify malicious hosts. This target trust level threshold is used to compare and identify malicious hosts. Thus, a host trust level mechanism is subsequently implemented to identify malicious hosts based on the magnitude of the target trust level of each target host identifier within the current time window, improving the accuracy of subsequent malicious host identification.

[0162] The target trust threshold is used to identify malicious hosts within the current time window. Specifically, it is compared with the target trust score of the corresponding target host identifier to identify malicious hosts. It should be noted that different time windows correspond to different trust thresholds, and each historical time window has a corresponding historical trust threshold.

[0163] The current state dataset can be state data describing the characteristics of the current network environment and the participation behavior characteristics of target hosts within the current time window. It may include the average trust level of all target hosts within the current time window. The historical target trust threshold of the previous historical time window Number of malicious hosts detected in the previous historical time window The degree of change in congestion events within the current time window compared to the previous time window. and the average penalty level of all target hosts within the previous time window. .

[0164] Specifically, the process of obtaining the current state dataset is as follows: First, calculate the average trust level based on the target trust level of each target host identifier. ;

[0165] Get the number of historical congestion events within the previous historical time window. And get the number of current congestion events within the current time window. Determine the ratio between the number of historical congestion events and the number of current congestion events, and subtract a constant value of 1 to obtain the degree of change. Specifically, it is expressed as follows:

[0166]

[0167] Next, the penalty level for each target host is determined. This penalty level can be understood as the percentage of traffic rate limit imposed on the malicious host. The specific calculation process is as follows:

[0168]

[0169] in, Indicates the first The target host in the current time window The degree of punishment. It is the target trust threshold within the current time window. This represents the size of the sliding window, i.e., the number of historical time windows it contains. Represents the first The number of consecutive penalties a target host is subjected to within the sliding window. Indicates the first The target hosts in the current time window The target level of trust.

[0170] The average penalty level for multiple target hosts The calculation process is as follows:

[0171]

[0172] in, This represents the average penalty level across multiple target hosts within the current window. This represents the total number of target hosts, i.e., the number of historical time windows included. Indicates the first The target hosts in the current time window The degree of punishment.

[0173] Based on the above method for calculating the average penalty level, determine the average penalty level for all target hosts within the previous time window. .

[0174] Next, directly obtain the historical target trust threshold of the previous historical time window. and the number of malicious hosts detected in the previous historical time window. .

[0175] Finally, based on the average trust level of all target hosts within the current time window... Historical target trust threshold of the previous historical time window Number of malicious hosts detected in the previous historical time window The degree of change in congestion events within the current time window compared to the previous time window. and the average penalty level of all target hosts within the previous time window. Construct the current state dataset, represented as follows:

[0176]

[0177] It should be noted that the state dataset can be time-sensitive, and can be obtained through " "" represents the time step of the state dataset. Assuming the current time step is 3, then The state dataset is represented as .

[0178] In this embodiment of the application, after obtaining the current state dataset, the current state dataset is input into the trained target decision model so that the target decision model outputs a target trust threshold based on the current state dataset, which is used to compare and identify malicious hosts.

[0179] The trained target decision model is primarily trained by maximizing the reward value corresponding to the reward function after the preset decision model outputs a predicted trust threshold based on the sample state dataset. The reward value is maximized when the target difference between the balance score, the misclassification rate, and the predicted average penalty is maximized. The reward function is constructed based on the balance score, the misclassification rate, and the predicted average penalty. The balance score and misclassification rate are determined by comparing the predicted trust threshold with the target trust of each sample host identifier to detect predicted malicious and benign host identifiers, and then combining this with the sample benign and malicious host identifiers from the sample host identifiers. The predicted average penalty (i.e., the predicted traffic rate limit ratio) is determined based on the ratio of the difference between the predicted trust threshold and the target trust of each sample host identifier.

[0180] To facilitate understanding, the training process of the objective decision-making model is described below:

[0181] The system obtains the target trust level of each sample host identifier, the average trust level among multiple sample host identifiers, the historical trust level threshold, the number of malicious hosts, the rate of change of the number of congestion events, the average traffic rate limit ratio corresponding to multiple sample host identifiers, and the benign and malicious host identifiers among multiple sample host identifiers. A sample state dataset is constructed based on the average trust level, historical trust level threshold, number of malicious hosts, rate of change of the number of congestion events, and average traffic rate limit ratio. This sample state dataset is input into a pre-defined decision model to obtain the predicted trust level threshold. Based on the predicted trust level threshold and the target trust level of each sample host identifier, the predicted malicious hosts are identified. The system identifies host identifiers; combines predicted malicious host identifiers, sample benign host identifiers, and sample malicious host identifiers to determine a balance score for the detection precision and recall rate for sample malicious host identifiers, as well as a misclassification rate for misclassifying sample benign host identifiers as predicted malicious host identifiers; based on the sample target trust level for each predicted malicious host identifier and each sample host identifier, it determines the predicted average traffic rate limit ratio; it determines the target difference between the balance score, the misclassification rate, and the predicted average traffic rate limit ratio, and constructs a reward function based on the target difference, with the reward function aiming to maximize the target difference; combining the output value of the reward function, it adjusts the model parameters of the preset decision model according to the optimization target to obtain the target decision model.

[0182] Specifically, the sample target trust score for each sample host identifier is obtained, and the average sample trust score among multiple sample host identifiers is calculated based on the multiple sample target trust scores corresponding to multiple sample host identifiers. And obtain the historical trust threshold of the sample. Number of malicious hosts in the sample Rate of change in the number of sample congestion events And the average traffic rate limit ratio corresponding to multiple sample host identifiers. Based on the above state data, a sample state dataset is constructed, which is represented as follows: .

[0183] Then, the sample state dataset is input into a preset decision model to obtain a prediction confidence threshold. This prediction confidence threshold can be understood as actions falling within the range [0, 1], represented as... .

[0184] Then, the target trust level of each sample host identifier is compared with the predicted trust level threshold to identify predicted malicious host identifiers and predicted benign host identifiers, so as to determine the penalty level corresponding to each sample host identifier, that is, the predicted traffic rate limit ratio corresponding to each sample host identifier. The calculation process of the predicted traffic rate limit ratio corresponding to each sample host identifier is as follows:

[0185]

[0186] Furthermore, by combining the predicted traffic rate limiting ratio corresponding to each sample host identifier, the predicted average traffic rate limiting ratio is calculated. The calculation process for the predicted average traffic rate limiting ratio is as follows:

[0187]

[0188] Next, based on the predicted trust threshold and the target trust of each sample host identifier, predicted malicious host identifiers and predicted benign host identifiers are identified, and the first number of predicted benign hosts and the second number of predicted malicious hosts are calculated. The predicted malicious host identifiers, predicted benign host identifiers, sample benign host identifiers, and sample malicious host identifiers are compared to count the number of correctly detected predicted malicious host identifiers. The number of false detections that misclassify benign host identifiers as predicted malicious host identifiers. And the number of missed detections of malicious host identifiers in the samples. Furthermore, a balance score between precision and recall for detecting malicious host identifiers in the samples was determined. For example, the F1-Score is used to measure the precision and recall of detection against malicious host identifiers in a sample. The specific calculation process is as follows:

[0189]

[0190] In addition, determine the misclassification rate of misidentifying benign host identifiers as predicted malicious host identifiers. The specific calculation process is as follows:

[0191]

[0192] Where U represents the total number of all sample host identifiers, i.e., the total number of sample hosts, and Z represents the total number of all sample malicious host identifiers, i.e., the total number of sample malicious hosts.

[0193] Furthermore, a target difference is determined between the balance score and the misjudgment rate, and the predicted average flow rate limit ratio. This target difference is denoted as "". Therefore, a reward function can be constructed based on the target difference as a variable.

[0194] It should be noted that an accurate predicted trust threshold can effectively detect malicious hosts and prevent network congestion events, thus reducing the frequency of congestion events. Therefore, it is necessary to determine the number of congestion events within the next time window. It should be compared to the number of congestion events in the previous time window. To say "less" is expressed as " ".

[0195] Based on the above, a constrained optimization problem is constructed to train a pre-defined decision model. This constrained optimization problem is expressed as follows:

[0196] , , .

[0197] To facilitate understanding, the above constrained optimization problem is transformed into a reward function. The rate of change in the number of congestion events between consecutive time windows can be expressed as "". Furthermore, this can be combined with the prediction of the number of malicious host identifiers. Relative to the number of malicious host identifiers in the sample The proportion Therefore, by combining the target difference, the rate of change in the number of congestion events between the preceding and following time windows, and the ratio between the predicted malicious host identifier and the sample malicious host identifier, a reward function is constructed. It is expressed as follows:

[0198]

[0199] It should be noted that the optimization objective of the reward function is to improve the accuracy of identifying malicious host identifiers in samples, while reducing the misclassification rate of benign host identifiers as predicted malicious host identifiers, and reducing the number of congestion events and the average traffic rate limit ratio (i.e., average penalty level). In other words, maximizing the objective difference between the balanced score and the misclassification rate and the predicted average penalty level is the optimization objective, and the reward value corresponding to the reward function reaches its maximum value when the objective difference between the balanced score and the misclassification rate and the predicted average penalty level is maximized.

[0200] Finally, based on the output value of the reward function and the optimization objective, the model parameters of the preset decision model are adjusted until the output value of the reward function reaches its maximum value. Then, training is stopped, and the trained target decision model is obtained.

[0201] By combining the above methods with reinforcement learning algorithms, the current target trust threshold can be calculated. This threshold can then be used to identify malicious hosts. In this way, a host trust mechanism can be implemented to identify malicious hosts based on the target trust level of each target host identifier within the current time window, thereby improving the accuracy of subsequent malicious host identification.

[0202] 106. Identify malicious host identifiers based on the target trust threshold and the target trust level of each target host identifier.

[0203] In the embodiments of this application, after obtaining the target trust threshold, the malicious host identifier can be identified from multiple target host identifiers by combining the target trust threshold and the target trust level of each target host identifier. In this way, a host trust mechanism is implemented to identify malicious hosts according to the target trust level of each target host identifier in the current time window, thereby improving the accuracy of malicious host identification and enabling accurate punishment of malicious hosts in the future. This prevents malicious hosts from launching further traffic attacks on the network transmission link, thereby reducing the occurrence of subsequent network transmission link congestion events and improving the security and stability of the network transmission link.

[0204] The malicious host identifier is one of multiple target host identifiers. It should be noted that one or more malicious host identifiers can be identified from multiple target host identifiers by using the target trust threshold. The specific number depends on the actual situation and is not limited here.

[0205] In some implementations, the target trust level of each target host identifier can be compared with a target trust level threshold to identify malicious host identifiers whose target trust level is less than the target trust level threshold. For example, step 106 may include: comparing the target trust level of each target host identifier with a target trust level threshold to obtain a comparison result; and based on the comparison result, identifying target host identifiers whose target trust level is less than the target trust level threshold as malicious host identifiers.

[0206] Specifically, after obtaining the target trust threshold corresponding to the current time window, the target trust score of each target host identifier within the current time window is compared with the target trust threshold to obtain the comparison result. Further, based on the comparison result, malicious and benign host identifiers are determined among the multiple target host identifiers. On the one hand, if the comparison result shows that the target trust score is greater than or equal to the target trust threshold, the corresponding target host identifier is identified as a benign host identifier; on the other hand, if the comparison result shows that the target trust score is less than the target trust threshold, the corresponding target host identifier is identified as a malicious host identifier. In this way, malicious host identifiers are identified by comparing the target trust score of each target host identifier with the target trust threshold. This achieves the goal of identifying malicious hosts based on the host trust mechanism, according to the magnitude of the target trust score of each target host identifier within the current time window, thus improving the accuracy of subsequent malicious host identification.

[0207] In some implementations, for example, step 106 may include: comparing the target trust level of each target host identifier with the target trust level threshold to obtain a comparison result, and obtaining each historical comparison result corresponding to each historical time window within the sliding window, and combining the current comparison result and each historical comparison result to identify the malicious host identifier from multiple target host identifiers.

[0208] Specifically, the target trust level of each target host identifier is compared with the target trust level threshold to obtain the current comparison result; each historical comparison result corresponding to each historical time window within the sliding window is obtained, and each historical comparison result contains the magnitude relationship between the historical trust level of multiple target host identifiers and the corresponding historical trust level threshold within the corresponding historical time window; when a set of candidate host identifiers with target trust levels less than the target trust level threshold is determined from multiple target host identifiers based on the comparison results, a set of historical candidate host identifiers with historical trust levels less than the historical trust level threshold is determined based on each comparison result, and the intersection information between the candidate host identifier set and multiple candidate host identifier sets is determined, and the target host identifiers in the intersection information are identified as malicious identifiers. Therefore, target host identifiers with a target trust level less than the target trust level threshold within the current time window are identified as malicious host identifiers to be confirmed. Furthermore, for each malicious host identifier to be confirmed, the relationship between its historical trust level and the corresponding historical trust level threshold within each historical time window included in the sliding window is queried. If a target host identifier has a target trust level lower than the target trust level threshold within the current time window, and its historical trust level is lower than the corresponding historical trust level threshold for multiple consecutive historical time windows within the sliding window, then the target host identifier with a trust level continuously lower than the trust level threshold is identified as a malicious host identifier. This can improve the accuracy of malicious host identification, reduce the risk of misidentifying benign hosts as malicious hosts, and enable accurate punishment of malicious hosts in the future, which is beneficial to maintaining the security and stability of network links.

[0209] In this embodiment of the application, after identifying the malicious host, in order to prevent the malicious host from launching further traffic attacks on the network transmission link, it is necessary to accurately punish the malicious host, such as limiting the network transmission rate and traffic of the malicious host. In this way, the occurrence of subsequent network transmission link congestion events is reduced, and the security and stability of the network transmission link are improved.

[0210] In some implementations, the traffic rate limiting ratio for each malicious host identifier can be determined based on the trust difference ratio between the target trust level and the target trust level threshold for each malicious host identifier. For example, after step 106, the method may further include: determining the number of consecutive penalties for each malicious host identifier in multiple historical time windows, and determining the corresponding penalty parameter based on the difference between the number of historical time windows and the number of consecutive penalties; determining the target trust ratio between the target trust level and the target trust level threshold for each malicious host identifier, and determining the target trust loss ratio for each malicious host identifier based on the target trust loss ratio; raising the corresponding penalty parameter to the power of the target trust loss ratio for each malicious host identifier to obtain the traffic rate limiting ratio for each malicious host identifier; and sending the traffic rate limiting ratio for each malicious host identifier to each network device so that each network device limits the traffic rate of each malicious host identifier according to the traffic rate limiting ratio for each malicious host identifier.

[0211] The consecutive penalty count refers to the number of times the corresponding malicious host was penalized (network transmission rate was limited) in multiple historical time windows.

[0212] The number of historical time windows can be the length of the sliding time window, that is, the number of historical time windows contained in the sliding time window.

[0213] For example, the traffic rate limit percentage for each malicious host identifier. The calculation process is as follows:

[0214]

[0215] Here, Indicates the first The target hosts in the current time window The degree of punishment, i.e., the percentage of traffic rate limit. It is the target trust threshold within the current time window. This represents the size of the sliding window, i.e., the number of historical time windows it contains. Represents the first The number of times a target host is consecutively penalized within a sliding window. Indicates the first The target host in the current time window The target level of trust.

[0216] Subsequently, the traffic rate limit ratio for each malicious host identifier is sent to each network device, so that each network device can limit the traffic rate of each malicious host identifier according to the traffic rate limit ratio for each malicious host identifier. For example, the network transmission rate and traffic of the malicious host can be limited. In this way, the occurrence of subsequent network transmission link congestion events is reduced, and the security and stability of the network transmission link are improved.

[0217] In some implementations, after determining the traffic rate limit for each malicious host identifier, in order to prevent malicious hosts from hijacking or tampering with the traffic rate limit, the traffic rate limit for each malicious host identifier can be encrypted using blockchain technology and uploaded to the blockchain, so that it can be shared with each network device through the blockchain. The local service node (server) is one of the service nodes in the blockchain system. For example, the step "sending the traffic rate limit ratio for each malicious host identifier to each network device" may include: obtaining the target node's private key from the public-private key pair of the local node (server); signing the traffic rate limit ratio for each malicious host identifier based on the target node's private key to obtain the target hash value for the traffic rate limit ratio for each malicious host identifier; then, packaging the traffic rate limit ratio for each malicious host identifier and each target hash value to generate a target block; broadcasting the target block to other service nodes within the blockchain system for consensus verification to obtain a consensus verification result; when the consensus verification result is successful, adding the target block to the blockchain so that each network device can obtain the traffic rate limit ratio for each malicious host identifier from the target block on the blockchain, and limit the traffic rate of each malicious host identifier according to the traffic rate limit ratio for each malicious host identifier. This not only prevents malicious hosts from hijacking and tampering with the traffic rate limit ratio, but also avoids the possibility of a single server (e.g., the server itself being compromised by an attacker) deliberately protecting a malicious host, such as by forging a "traffic rate limit ratio" to try to reduce the malicious host's impact on traffic rate. Therefore, blockchain technology can effectively eliminate the above problems, reduce the occurrence of subsequent network transmission link congestion events, and improve the security and stability of network transmission links.

[0218] By combining the target trust threshold and the target trust level of each target host identifier, malicious host identifiers can be identified from multiple target host identifiers. In this way, a host trust level mechanism is implemented to identify malicious hosts according to the target trust level of each target host identifier in the current time window, thereby improving the accuracy of malicious host identification. Furthermore, malicious hosts can be accurately punished to prevent them from launching further traffic attacks on the network transmission link. This reduces the occurrence of subsequent network transmission link congestion events and improves the security and stability of the network transmission link.

[0219] As described above, the malicious host detection method of this application embodiment obtains multiple access address change events and multiple congestion events within the current time window. Each access address change event includes the target host identifier that changed the access address, and each congestion event includes the target host identifier that participated in network link congestion. Based on the multiple access address change events and multiple congestion events, the number of congestion participations, access address changes, and consecutive participations of each target host identifier are counted. Based on the number of congestion participations, access address changes, and consecutive participations of each target host identifier within the current time window, the initial trust level of each target host identifier within the current time window is calculated. The historical trust level of each target host identifier in a historical time window is obtained, and the target trust level of each target host identifier is calculated based on the initial trust level and the corresponding historical trust level. The current state dataset is obtained, and the state dataset is input into the target decision model to obtain the target trust level threshold. Based on the target trust level threshold and the target trust level of each target host identifier, the malicious host identifier is identified.

[0220] Based on this, we can first obtain multiple access address change events and multiple congestion events within the current time window. Each access address change event contains the target host identifier that changed the access address, and each congestion event contains the target host identifier that participated in network link congestion. Then, based on the multiple access address change events and multiple congestion events, we can count the number of congestion participations, access address changes, and consecutive participations for each target host identifier. In this way, we can construct multidimensional evidence data as the basis for calculating the trust level of the target host identifier. Then, based on the multidimensional evidence data, we can calculate the initial trust level of each target host identifier within the current time window and set the initial trust level of each target host identifier as follows: The initial trust level is combined with its historical trust level within a historical time window to calculate the target trust level of each target host identifier within the current time window. In this way, the current target trust level is calculated by combining the historical trust level within the historical time window and the initial trust level of the current time window. This avoids the phenomenon that malicious hosts are mistakenly identified as benign hosts because they participate in network link congestion less frequently within the current time window. Furthermore, the current state dataset is obtained and input into the target decision model to determine the target trust level threshold for the current time window. Finally, the target trust level of each target host identifier and the target trust level threshold are combined to identify the malicious host identifier. Therefore, compared to related technologies that identify malicious hosts through malicious traffic characteristics, which have relatively low accuracy, this application directly uses a host trust mechanism to calculate the initial trust level based on multiple dimensions such as the number of times each target host identifier participates in congestion, the number of times it changes its access address, and the number of times it continuously participates in congestion within the current time window. This eliminates the need to detect malicious hosts by mining malicious traffic characteristics. Furthermore, it combines the trust level data from historical time windows to calculate the final target trust level for each target host identifier, making the calculation of the trust level for each host more accurate. This allows for long-term punishment of malicious hosts and subsequent blocking of attacks on network transmission links by malicious hosts, thereby improving the accuracy of malicious host identification.

[0221] For details on the implementation of each of the above steps, please refer to the previous examples, which will not be repeated here.

[0222] To facilitate better implementation of the malicious host detection method provided in this application, this application also provides a malicious host detection device based on the above-described malicious host detection method. The meanings of the terms used are the same as in the malicious host detection method described above, and specific implementation details can be found in the descriptions within the method embodiments.

[0223] Please see Figure 5 , Figure 5This is a schematic diagram of the structure of a malicious host detection device provided in an embodiment of this application. The malicious host detection device is integrated into the computer equipment of this application. The malicious host detection device may include an acquisition unit 401, a statistics unit 402, a first calculation unit 403, a second calculation unit 404, an input unit 405, and an identification unit 406.

[0224] The acquisition unit 401 is used to acquire multiple access address change events and multiple congestion events within the current time window. Each access address change event contains the target host identifier of the changed access address, and each congestion event contains the target host identifier of the network link congestion.

[0225] The statistics unit 402 is used to count the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier based on the multiple access address change events and the multiple congestion events.

[0226] The first calculation unit 403 is used to calculate the initial trust level of each target host identifier in the current time window based on the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier in the current time window.

[0227] The second calculation unit 404 is used to obtain the historical trust level of each target host identifier in the historical time window, and calculate the target trust level of each target host identifier based on the initial trust level and the corresponding historical trust level of each target host identifier.

[0228] Input unit 405 is used to acquire the current state dataset, input the state dataset into the target decision model, and obtain the target trust threshold.

[0229] The identification unit 406 is used to identify malicious host identifiers based on the target trust threshold and the target trust level of each target host identifier.

[0230] In some embodiments, the first computing unit 403 is further configured to:

[0231] Based on the number of congestion participations for each target host identifier within the current time window, determine the direct participation score for each target host identifier; calculate the continuous participation score based on the number of consecutive participations for each target host identifier within the current time window; calculate the address change score based on the number of access address changes for each target host identifier within the current time window; and perform a weighted calculation on the direct participation score, continuous participation score, and address change score to obtain the initial trust level for each target host identifier within the current time window.

[0232] In some embodiments, the first computing unit 403 is further configured to:

[0233] The first evidence weighting factor for direct participation in scoring association, the second evidence weighting factor for continuous participation in scoring association, and the third evidence weighting factor for address change scoring association are determined; wherein the sum of the first evidence weighting factor, the second evidence weighting factor, and the third evidence weighting factor is 1; according to the first evidence weighting factor, the second evidence weighting factor, and the third evidence weighting factor, the scoring of direct participation, continuous participation, and address change are weighted and calculated to obtain the initial trust level of each target host identifier in the current time window.

[0234] In some implementations, there are multiple historical time windows, and the second calculation unit 404 is also used for:

[0235] Determine the current trust weight factor corresponding to the current time window and the historical trust weight factor corresponding to each historical time window. The historical trust weight factor decreases exponentially as the distance between the corresponding historical time window and the current time window increases. Based on the current trust weight factor and each historical trust weight factor, the initial trust level of each target host identifier is weighted and summed with the corresponding multiple historical trust levels to obtain the target total trust score for each target host identifier. Combine the current trust weight factor and each historical trust factor to determine the total trust weight coefficient, and determine the target trust level of each target host identifier based on the ratio between the target total trust score and the total trust weight coefficient.

[0236] In some embodiments, the identification unit 406 is further configured to:

[0237] The target trust level of each target host identifier is compared with the target trust level threshold to obtain the comparison result; based on the comparison result, the target host identifier with a target trust level less than the target trust level threshold is identified as a malicious host identifier.

[0238] In some implementations, the malicious host detection device further includes a penalty control unit, used for:

[0239] The process involves determining the number of consecutive penalties for each malicious host identifier across multiple historical time windows, and determining the corresponding penalty parameters based on the difference between the number of historical time windows and the number of consecutive penalties; determining the target trust ratio between the target trust level and the target trust level threshold for each malicious host identifier, and determining the target trust loss ratio for each malicious host identifier based on the target trust loss ratio; raising the corresponding penalty parameter to the power of the target trust loss ratio for each malicious host identifier to obtain the traffic rate limiting ratio for each malicious host identifier; and sending the traffic rate limiting ratio for each malicious host identifier to each network device so that each network device limits the traffic rate of each malicious host identifier according to the traffic rate limiting ratio for each malicious host identifier.

[0240] In some implementations, the malicious host detection device further includes a training unit for:

[0241] The system obtains the target trust level of each sample host identifier, the average trust level among multiple sample host identifiers, the historical trust level threshold, the number of malicious hosts, the rate of change of the number of congestion events, and the average traffic rate limit ratio corresponding to multiple sample host identifiers. It also identifies benign and malicious host identifiers among the multiple sample host identifiers. Based on the average trust level, historical trust level threshold, number of malicious hosts, rate of change of the number of congestion events, and average traffic rate limit ratio, a sample state dataset is constructed. The system also determines the first number of benign host identifiers and the second number of malicious host identifiers among the multiple sample host identifiers. The sample state dataset is input into a pre-defined decision model to obtain the predicted trust level threshold. Finally, the system uses the predicted trust level threshold... The system identifies predicted malicious host identifiers based on the target trust level of each sample host identifier. Combining the predicted malicious host identifier, the sample benign host identifier, and the sample malicious host identifier, it determines a balance score between the detection precision and recall for the sample malicious host identifier, as well as the misclassification rate for misclassifying a sample benign host identifier as a predicted malicious host identifier. Based on each predicted malicious host identifier and the sample target trust level of each sample host identifier, it determines the predicted average traffic rate limit ratio. It then determines the target difference between the balance score, the misclassification rate, and the predicted average traffic rate limit ratio, constructs a reward function using this target difference as a variable, and optimizes the reward function by maximizing the target difference. Finally, based on the output value of the reward function and according to the optimization target, it adjusts the model parameters of the preset decision model to obtain the target decision model.

[0242] As described above, in this embodiment, multiple access address change events and multiple congestion events within the current time window can be obtained first. Each access address change event includes the target host identifier that changed the access address, and each congestion event includes the target host identifier that participated in network link congestion. Then, based on the multiple access address change events and multiple congestion events, the number of congestion participations, access address changes, and consecutive participations of each target host identifier are counted. In this way, multi-dimensional evidence data can be constructed as the basic data for calculating the trust level of the target host identifier. Then, based on the multi-dimensional evidence data, the initial trust level of each target host identifier within the current time window is calculated, and each target host identifier is assigned a trust level. The initial trust level of a host identifier is combined with its historical trust level within a historical time window to calculate the target trust level of each target host identifier within the current time window. In this way, the current target trust level is calculated by combining the historical trust level within the historical time window and the initial trust level of the current time window. This avoids the phenomenon that malicious hosts are mistakenly identified as benign hosts because they participate in network link congestion less frequently within the current time window. Furthermore, the current state dataset is obtained and input into the target decision model to determine the target trust level threshold for the current time window. Finally, the target trust level of each target host identifier and the target trust level threshold are combined to identify the malicious host identifier. Therefore, compared to related technologies that identify malicious hosts through malicious traffic characteristics, which have relatively low accuracy, this application directly uses a host trust mechanism to calculate the initial trust level based on multiple dimensions such as the number of times each target host identifier participates in congestion, the number of times it changes its access address, and the number of times it continuously participates in congestion within the current time window. This eliminates the need to detect malicious hosts by mining malicious traffic characteristics. Furthermore, it combines the trust level data from historical time windows to calculate the final target trust level for each target host identifier, making the calculation of the trust level for each host more accurate. This allows for long-term punishment of malicious hosts and subsequent blocking of attacks on network transmission links by malicious hosts, thereby improving the accuracy of malicious host identification.

[0243] The specific implementation of each of the above units can be found in the previous embodiments, and will not be repeated here.

[0244] Figure 6To implement a portion of the structural block diagram of the network device 110 according to an embodiment of this disclosure, the network device 110 includes components such as: a radio frequency (RF) circuit 510, a memory 515, an input unit 530, a display unit 540, a sensor 550, an audio circuit 560, a wireless fidelity (WiFi) module 570, a processor 580, and a power supply 590. Those skilled in the art will understand that the structure of the network device 110 shown in the figures does not constitute a limitation on a mobile phone or computer, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0245] The RF circuit 510 can be used to receive and transmit signals during information transmission or calls. In particular, it receives downlink information from the base station and processes it with the processor 580; in addition, it transmits uplink data to the base station.

[0246] The memory 515 can be used to store software programs and modules. The processor 580 executes various functional applications and data processing of the terminal by running the software programs and modules stored in the memory 515.

[0247] The input unit 530 can be used to receive input numeric or character information, and to generate key signal inputs related to the terminal's settings and function control. Specifically, the input unit 530 may include a touch panel 531 and other input devices 532.

[0248] The display unit 540 can be used to display input or provided information, as well as various menus of the terminal. The display unit 540 may include a display panel 541.

[0249] Audio circuit 560, speaker 561, and microphone 562 provide an audio interface.

[0250] In this embodiment, the processor 580 included in the network device 110 can execute the malicious host detection method of the previous embodiment.

[0251] The network device 110 in this disclosure includes, but is not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle terminals, and aircraft. This invention can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, and assisted driving.

[0252] Figure 7This is a partial structural block diagram of a server 120 implementing an embodiment of the present disclosure. The server 120 can vary significantly due to different configurations or performance characteristics, and may include one or more central processing units (CPUs) 622 (e.g., one or more processors) and memory 632, and one or more storage media 620 (e.g., one or more mass storage devices) for storing application programs 642 or data 644. The memory 632 and storage media 620 may be temporary or persistent storage. The program stored in the storage media 620 may include one or more modules (not shown in the diagram), each module including a series of instruction operations on the server 120. Furthermore, the CPU 622 may be configured to communicate with the storage media 620 and execute the series of instruction operations in the storage media 620 on the server 120.

[0253] Server 120 may also include one or more power supplies 626, one or more wired or wireless network interfaces 650, one or more input / output interfaces 658, and / or one or more operating systems 641, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0254] The central processing unit 622 in server 120 can be used to execute the malicious host detection method of the present disclosure embodiments.

[0255] This disclosure also provides a computer-readable storage medium for storing program code for executing the malicious host detection methods of the foregoing embodiments.

[0256] This disclosure also provides a computer program product comprising a computer program. A processor of a computer device reads and executes the computer program, causing the computer device to perform the malicious host detection method described above.

[0257] Furthermore, the terms “comprising” and “including”, and any variations thereof, are intended to cover non-exclusive inclusion, such that a process, method, apparatus, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are expressly listed, but may include other steps or units that are not expressly listed or that are inherent to such process, method, product or device.

[0258] It should be understood that in this disclosure, "at least one item" means one or more, and "more than one" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0259] It should be understood that in the description of the embodiments of this disclosure, "multiple" means two or more, "greater than", "less than", "exceeding" etc. are understood to exclude the number itself, and "above", "below", "within" etc. are understood to include the number itself.

[0260] In the several embodiments provided in this disclosure, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between apparatuses or units, and may be electrical, mechanical, or other forms.

[0261] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0262] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0263] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0264] It should also be understood that the various implementation methods provided in this disclosure can be combined arbitrarily to achieve different technical effects.

[0265] In the embodiments of this application, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.

[0266] The above is a detailed description of the embodiments of this disclosure. However, this disclosure is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this disclosure. All such equivalent modifications or substitutions are included within the scope defined by the claims of this disclosure.

Claims

1. A method for detecting malicious hosts, characterized in that, include: Retrieve multiple access address change events and multiple congestion events within the current time window. Each access address change event contains the target host identifier for the changed access address, and each congestion event contains the target host identifier for the network link congestion. Based on the multiple access address change events and the multiple congestion events, the number of congestion participations, access address changes, and consecutive participations for each target host identifier are counted. Based on the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier within the current time window, calculate the initial trust level of each target host identifier within the current time window. Obtain the historical trust score of each target host identifier within a historical time window, and calculate the target trust score of each target host identifier based on the initial trust score and the corresponding historical trust score. Obtain the current state dataset and input the state dataset into the target decision model to obtain the target trust threshold; Malicious host identifiers are identified based on the target trust threshold and the target trust level of each target host identifier.

2. The malicious host detection method according to claim 1, characterized in that, The calculation of the initial trust level of each target host identifier within the current time window, based on the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier within the current time window, includes: Based on the number of congestion participations for each target host identifier within the current time window, a direct participation score is determined for each target host identifier. Calculate the continuous participation score based on the number of consecutive participations for each target host identifier within the current time window; Calculate the address change score based on the number of access address changes for each target host identifier within the current time window; The direct participation score, the continuous participation score, and the address change score are weighted and calculated to obtain the initial trust level of each target host identifier within the current time window.

3. The malicious host detection method according to claim 2, characterized in that, The weighted calculation of the direct participation score, the continuous participation score, and the address change score to obtain the initial trust level of each target host identifier within the current time window includes: Determine the first evidence weighting factor for the direct participation in the scoring association, the second evidence weighting factor for the continuous participation in the scoring association, and the third evidence weighting factor for the address change scoring association; Wherein, the sum of the first evidence weight factor, the second evidence weight factor, and the third evidence weight factor is 1; The direct participation score, the continuous participation score, and the address change score are weighted according to the first evidence weighting factor, the second evidence weighting factor, and the third evidence weighting factor to obtain the initial trust level of each target host identifier within the current time window.

4. The malicious host detection method according to any one of claims 1 to 3, characterized in that, The historical time windows are multiple, and the calculation of the target trust score for each target host identifier based on the initial trust score and the corresponding historical trust score includes: Determine the current trust weight factor corresponding to the current time window and the historical trust weight factor corresponding to each historical time window. The historical trust weight factor decreases exponentially as the distance between the corresponding historical time window and the current time window increases. Based on the current trust weight factor and each historical trust weight factor, the initial trust level of each target host identifier and the corresponding multiple historical trust levels are weighted and summed to obtain the target total trust score corresponding to each target host identifier. The total trust weight coefficient is determined by combining the current trust weight factor and each historical trust weight factor, and the target trust level of each target host identifier is determined based on the ratio between the target total trust score of each target host identifier and the total trust weight coefficient.

5. The malicious host detection method according to claim 1, characterized in that, The step of identifying malicious host identifiers based on the target trust threshold and the target trust level of each target host identifier includes: The target trust level of each target host identifier is compared with the target trust threshold to obtain the comparison result; Based on the comparison results, the target host identifier whose target trust level is less than the target trust level threshold is identified as a malicious host identifier.

6. The malicious host detection method according to claim 1 or 5, characterized in that, After identifying the malicious host identifier based on the target trust threshold and the target trust level of each target host identifier, the method further includes: The number of consecutive penalties for each malicious host identifier within multiple historical time windows is determined, and the corresponding penalty parameters are determined based on the difference between the number of historical time windows and the number of consecutive penalties. Determine the target trust ratio between the target trust level and the target trust level threshold for each malicious host identifier, and determine the target trust loss ratio for each malicious host identifier based on the target trust ratio. The traffic rate limit ratio for each malicious host identifier is obtained by raising the corresponding penalty parameter to the power of the target trust loss ratio. The traffic rate limit percentage for each malicious host identifier is sent to each network device so that each network device limits the traffic rate of each malicious host identifier according to the traffic rate limit percentage for each malicious host identifier.

7. The malicious host detection method according to claim 1, characterized in that, Before inputting the state dataset into the target decision model to obtain the target trust threshold, the method further includes: The sample target trust level of each sample host identifier, the average trust level among multiple sample host identifiers, the historical trust level threshold of the sample, the number of malicious hosts, the rate of change of the number of sample congestion events, and the average traffic rate limit ratio of the multiple sample host identifiers, as well as the benign host identifier and the malicious host identifier among the multiple sample host identifiers. A sample status dataset is constructed based on the sample average trust level, the sample historical trust level threshold, the sample number of malicious hosts, the sample congestion event frequency change rate, and the sample average traffic rate limit ratio. The first number of samples of benign host identifiers and the second number of samples of malicious host identifiers are determined among the multiple sample host identifiers. The sample state dataset is input into a preset decision model to obtain a predicted trust threshold, and the predicted malicious host identifier is identified based on the predicted trust threshold and the sample target trust of each sample host identifier. By combining the predicted malicious host identifier, the sample benign host identifier, and the sample malicious host identifier, a balance score of detection precision and recall for the sample malicious host identifier is determined, as well as the misclassification rate for misidentifying the sample benign host identifier as the predicted malicious host identifier. Based on each predicted malicious host identifier and the sample target trust level of each sample host identifier, the predicted average traffic rate limit ratio is determined. Determine the target difference between the balance score and the misjudgment rate and the predicted average flow rate limit ratio, and construct a reward function based on the target difference as a variable. The reward function takes maximizing the target difference as its optimization objective. By combining the output value of the reward function and adjusting the model parameters of the preset decision model according to the optimization objective, the target decision model is obtained.

8. A malicious host detection device, characterized in that, include: The acquisition unit is used to acquire multiple access address change events and multiple congestion events within the current time window. Each access address change event contains the target host identifier of the changed access address, and each congestion event contains the target host identifier of the network link congestion. The statistics unit is used to count the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier based on the multiple access address change events and the multiple congestion events. The first calculation unit is used to calculate the initial trust level of each target host identifier in the current time window based on the number of congestion participations, the number of access address changes, and the number of consecutive participations for each target host identifier in the current time window. The second calculation unit is used to obtain the historical trust level of each target host identifier in the historical time window, and to calculate the target trust level of each target host identifier based on the initial trust level and the corresponding historical trust level. The input unit is used to acquire the current state dataset, input the state dataset into the target decision model, and obtain the target trust threshold. The identification unit is used to identify malicious host identifiers based on the target trust threshold and the target trust level of each target host identifier.

9. A computer device, characterized in that, The computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the malicious host detection method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a plurality of instructions adapted for loading by a processor to execute the malicious host detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Malicious account identification method and device, storage medium and electronic equipment

    CN115345620A

  • Internet protocol address identification method and device, computer equipment and storage medium

    CN118250095A