Method, device, storage medium and server for defending against cyber attacks
By using a multi-cloud collaborative management server to accurately locate the source of DDoS attacks and take action at the source network nodes, the problem of poor defense effectiveness in existing technologies is solved, achieving efficient and stable network security defense and reducing the impact on public networks.
Patent Information
- Application Number
- CN202511216417.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-28
- Publication Date
- 2026-01-06
- Estimated Expiration
- 2045-08-28
AI Technical Summary
Existing technologies are ineffective in defending against distributed denial-of-service (DDoS) attacks, especially when traffic peaks exceed the limits of local scrubbing equipment or outbound bandwidth. This leads to increased network latency, service interruptions, and configuration complexity, making it difficult to achieve efficient and stable network security defense.
The multi-cloud linkage management server receives attack information sent by the network security management device on the server side, accurately locates the network node of the attack source, generates handling instructions, and directly handles the attack at the virtual network layer of the source network node, including traffic blocking and cleaning, to avoid cross-network traffic diversion operations.
It enables immediate response at the source of attacks, reduces bandwidth consumption on public networks, shortens response cycles, enhances the initiative and effectiveness of defense, and ensures service stability and continuity.
Smart Images

Figure CN120729642B_ABST
Abstract
Description
Technical Field
[0001] The embodiments in this specification relate to the field of computer technology, and in particular to a method, apparatus, storage medium, and server for defending against network attacks. Background Technology
[0002] Distributed Denial-of-Service (DDoS) attacks, due to their massive traffic volume and dispersed attack sources, continue to pose a serious threat to online services and have become one of the core challenges urgently needing to be addressed in the current cybersecurity field. To combat this threat, the industry's commonly deployed technical approach mainly relies on implementing localized protection at the egress nodes of data centers or cloud resource pools. This protection system typically integrates mechanisms such as attack traffic detection, scrubbing and filtering, and routing black holes, aiming to identify and handle malicious traffic close to the protected target. However, when the peak attack traffic far exceeds the limits of local scrubbing equipment or egress bandwidth, its protective effectiveness will quickly fail. Furthermore, most existing solutions inevitably involve traffic scheduling and diversion operations during implementation, which may introduce network latency, increase configuration complexity, and pose potential risks of service interruption or instability during switching, severely hindering service continuity. Summary of the Invention
[0003] This specification provides a method, apparatus, storage medium, and server for defending against network attacks, which can solve the technical problem of poor defense against network attacks in related technologies.
[0004] Firstly, embodiments of this specification provide a method for defending against network attacks, the method comprising:
[0005] Receive attack information sent by the network security management device corresponding to the server. The attack information is the information collected by the network security management device corresponding to the server in response to the network attack events detected.
[0006] Based on the above attack information, the source network node corresponding to the above network attack event is identified, and a handling instruction for the above network attack event is generated.
[0007] The aforementioned handling instructions are sent to the network security management device corresponding to the aforementioned source network node, so that the network security management device corresponding to the aforementioned source network node can handle the aforementioned network attack event.
[0008] In one possible implementation, both the server and the source network node are deployed with their respective associated clients; receiving attack information sent by the network security management device corresponding to the server includes receiving attack information reported by the network security management device corresponding to the server through the associated first client; sending the handling instruction to the network security management device corresponding to the source network node includes sending the handling instruction to the second client associated with the source network node, so that the second client forwards the handling instruction to the network security management device corresponding to the source network node.
[0009] In one possible implementation, the attack information includes at least the source Internet Protocol address, destination Internet Protocol address, source network port, destination network port, and communication protocol corresponding to the network attack event.
[0010] In one possible implementation, determining the source network node corresponding to the network attack event based on the attack information includes: querying an address information database to see if a target network node corresponding to the source Internet Protocol address exists, based on the source Internet Protocol address in the attack information; if it exists, determining the target network node as the source network node corresponding to the network attack event; the address information database is used to store the correspondence between pre-deployed client identification information and Internet Protocol addresses in network nodes.
[0011] In one possible implementation, the source network node is either a cloud resource pool or a data center. When the source network node is a cloud resource pool, the network security management device corresponding to the source network node is a cloud management platform that is compatible with the cloud resource pool. When the source network node is a data center, the network security management device corresponding to the source network node is an attack handling system that is compatible with the data center.
[0012] In one possible implementation, the aforementioned network attack is a distributed denial-of-service attack.
[0013] Secondly, embodiments of this specification provide a network attack defense device, the device comprising:
[0014] The attack information receiving module is used to receive attack information sent by the network security management device corresponding to the server. The attack information is the information collected by the network security management device corresponding to the server in response to the network attack events detected.
[0015] The handling instruction issuance module is used to determine the source network node corresponding to the above network attack event based on the above attack information, and generate handling instructions for the above network attack event.
[0016] The attack incident handling module is used to send the aforementioned handling instructions to the network security management device corresponding to the aforementioned source network node, so that the network security management device corresponding to the aforementioned source network node can handle the aforementioned network attack incident.
[0017] Thirdly, embodiments of this specification provide a computer program product containing instructions that, when run on a computer or processor, cause the computer or processor to perform the steps of the method described above.
[0018] Fourthly, embodiments of this specification provide a computer storage medium storing a plurality of instructions adapted for loading by a processor and executing the steps of the method described above.
[0019] Fifthly, embodiments of this specification provide a server including a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being adapted to be loaded by the processor and to execute the steps of the method described above.
[0020] The beneficial effects of the technical solutions provided in some embodiments of this specification include at least the following:
[0021] This specification provides a method for defending against network attacks. It involves receiving attack information from a network security management device corresponding to a server. This attack information is collected by the server's network security management device in response to detected network attack events. Based on the attack information, the source network node corresponding to the network attack event is identified, and a handling instruction for the network attack event is generated. The handling instruction is sent to the network security management device corresponding to the source network node, enabling the source network node's network security management device to handle the network attack event. When the server encounters a network attack event, the corresponding network security management device collects attack-related information in real time and actively reports it. This real-time information transmission ensures that the attack event can be incorporated into the handling system immediately, laying the foundation for a rapid response. After receiving the attack information, the server can accurately locate the source network node that initiated the attack by analyzing the attack information. The accuracy of this source tracing directly determines the targeting of the attack handling, which helps improve the timeliness and accuracy of subsequent interception and processing operations. Once the source network node is identified, the server-generated handling instructions are directly sent to the network security management device corresponding to that node, prompting it to execute attack handling operations at the virtual network layer. This handling mechanism moves the defense operation node forward to the attack source itself, allowing attack traffic to be cleaned and eliminated before it leaves the source network node and enters the public internet, or even before it consumes public network routing resources. This mode of handling attack traffic at the attack source fundamentally cuts off the path for attack traffic to spread to the public network. It not only confines the impact of the attack to the source resource pool or data center, preventing unnecessary additional consumption of public network bandwidth resources and effectively alleviating the problems of public network routing congestion and bandwidth shortages, but also significantly shortens the response cycle, significantly improving the initiative and effectiveness of network security defense, and building a more efficient and stable security defense line for the server that is closer to the attack source. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 An exemplary system architecture diagram for a network attack defense method provided in the embodiments of this specification;
[0024] Figure 2 A flowchart illustrating a method for defending against network attacks provided in an embodiment of this specification;
[0025] Figure 3 A flowchart illustrating a method for defending against network attacks provided in an embodiment of this specification;
[0026] Figure 4 A schematic diagram of a multi-cloud deployment architecture for a network attack defense method provided in the embodiments of this specification;
[0027] Figure 5 A schematic diagram of the platform architecture for a network attack defense method provided in the embodiments of this specification;
[0028] Figure 6 A structural block diagram of a network attack defense device provided in the embodiments of this specification;
[0029] Figure 7 This is a schematic diagram of the structure of a server provided in an embodiment of this specification. Detailed Implementation
[0030] To make the features and advantages of the embodiments of this specification more apparent and understandable, the technical solutions of the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the embodiments of this specification.
[0031] In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with those in this specification. Rather, they are merely examples of apparatuses and methods consistent with some aspects of the embodiments in this specification as detailed in the appended claims. Furthermore, in the description of the embodiments in this specification, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; the word "and / or" in the text is merely a description of the relationship between related objects, indicating that three relationships can exist, for example, A and / or B can represent: A alone, A and B simultaneously, and B alone. Additionally, in the description of the embodiments in this specification, "multiple" refers to two or more.
[0032] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature.
[0033] Distributed Denial of Service (DDoS) refers to the use of multiple computers as an attack platform. Through remote connections, malicious programs launch DDoS attacks against one or more targets, consuming the target server's performance or network bandwidth, thus causing the server to be unable to provide normal service. Typically, attackers use an unauthorized account to install the DDoS master program on one computer and install proxy programs on multiple computers on the network. Within a set timeframe, the master program communicates with a large number of proxy programs. When the proxy programs receive instructions, they launch attacks against the target. The master program can even activate hundreds or thousands of proxy programs within seconds.
[0034] In the current field of network security protection, the defense technology system against DDoS attacks has formed a multi-stage collaborative architecture. The local protection mechanism at the data center and cloud resource pool egress constitutes the first line of defense, aiming to identify and handle malicious traffic close to the protected target. This mechanism achieves basic protection through real-time traffic monitoring, attack signature identification, and precise cleaning. When abnormal traffic is detected, the system automatically triggers filtering rules to remove malicious data packets. Simultaneously, for traffic exceeding the processing threshold, a routing black hole strategy is adopted, directing attack traffic to invalid addresses at the network routing level to avoid overloading core service nodes. When local protection resources face traffic saturation pressure, existing technical solutions typically employ traffic scheduling mechanisms to divert excess attack traffic to DDoS-simulated data centers with high-capacity cleaning capabilities for secondary processing. These data centers, relying on dedicated hardware and algorithm models, can handle large-scale traffic surges; however, due to limitations in physical deployment location and network topology, their response latency and protection efficiency still have room for optimization. In addition, in some scenarios, the protection functions provided by the operator will be invoked, including backbone network black hole and near-source cleaning services. Among them, near-source cleaning can intercept attack traffic before it spreads to the backbone network, and theoretically has a better protection effect.
[0035] However, near-source cleaning services have significant limitations in practical applications. On the one hand, this service requires substantial network routing resources and involves coordinated scheduling across network nodes, resulting in high operating costs and often placing a heavy financial burden on users. On the other hand, due to differences in network architecture among operators in various provinces and cities in my country, and the additional investment required for equipment deployment and system construction for near-source cleaning capabilities, the service coverage is uneven, making it difficult to achieve comprehensive DDoS attack response across the entire network. Another prominent problem with traditional protection solutions is the network distance between the cleaning nodes and the attack source. Existing technologies often deploy cleaning equipment at the metropolitan area network (MAN) level, while the actual attack source is often located at the edge of the MAN or in the access network. Attack traffic must travel a certain distance to reach the cleaning node, which not only increases the transit time but may also lead to reduced cleaning effectiveness due to differences in forwarding strategies at intermediate nodes. Furthermore, some traffic redirection operations may cause temporary service interruptions or path switching, posing a potential risk to sectors with extremely high service continuity requirements, such as finance and e-commerce.
[0036] Therefore, this specification provides a method for defending against network attacks to solve the aforementioned technical problem of poor defense effectiveness against network attacks.
[0037] Please see Figure 1 , Figure 1 This is an exemplary system architecture diagram of a network attack defense method provided in the embodiments of this specification.
[0038] like Figure 1 As shown, the system architecture may include a multi-cloud linkage management server 101, a network 102, and network node servers 103 housing network nodes such as servers of various cloud service providers, private cloud resource pools, hybrid cloud resource pools, and data centers. The network 102 serves as the medium for providing a communication link between the multi-cloud linkage management server 101 and the network node servers 103. The network 102 may include various types of wired or wireless communication links, such as wired communication links including fiber optic cables, twisted-pair cables, or coaxial cables, and wireless communication links including Bluetooth communication links, Wireless-Fidelity (Wi-Fi) communication links, or microwave communication links.
[0039] The multi-cloud linkage management server 101 can interact with the network node server 103 via network 102 to receive or send messages to the network node server 103. Alternatively, the multi-cloud linkage management server 101 can interact with the network node server 103 via network 102 to receive messages or data sent to the network node server 103 by other users. The multi-cloud linkage management server 101 and the network node server 103 can be hardware or software. When the multi-cloud linkage management server 101 and / or the network node server 103 are hardware, they can be implemented as a distributed server cluster composed of multiple servers, or as a single server or terminal device. When the multi-cloud linkage management server 101 and / or the network node server 103 are software, they can be implemented as multiple software programs or software modules (e.g., used to provide distributed services), or as a single software program or software module; no specific limitations are made here.
[0040] In this embodiment of the specification, the multi-cloud linkage management server 101 receives attack information sent by the network security management device corresponding to the network node server 103a where the server is located. The attack information is information collected by the network security management device corresponding to the server in response to a detected network attack event. Based on the attack information, the multi-cloud linkage management server 101 can further determine the source network node corresponding to the network attack event and generate a handling instruction for the network attack event. Then, the multi-cloud linkage management server 101 sends the handling instruction to the network security management device corresponding to the network node server 103b where the source network node is located, thereby enabling the network security management device to handle the network attack event.
[0041] It should be understood that Figure 1 The number of multi-cloud interconnected management servers, networks, and servers shown in the diagram is only illustrative. Depending on the implementation needs, there can be any number of servers, networks, and network node servers.
[0042] Please see Figure 2 , Figure 2 This is a flowchart illustrating a network attack defense method provided in an embodiment of this specification. The execution entity in this embodiment can be a server performing network attack defense, a processor within the server performing the network attack defense method, or a network attack defense service within the server performing the network attack defense method. For ease of description, the following example uses a processor within a server as the execution entity to illustrate the specific execution process of the network attack defense method.
[0043] like Figure 2 As shown, methods for defending against network attacks can include at least:
[0044] S202. Receive attack information sent by the network security management device corresponding to the server. The attack information is the information collected by the network security management device corresponding to the server in response to the network attack events detected.
[0045] Optionally, when the server provides services to users, it interacts with various cloud resource pools and data centers, resulting in a large amount of traffic. During these interactions, attackers can easily launch DDoS attacks against the server by controlling various cloud hosts, PCs, and IoT devices. This can attack the target services supported by the server, causing them to become unusable. Furthermore, the unnecessary consumption of computing resources by DDoS attacks can also affect the response efficiency of other services on the server. To address DDoS attacks promptly, a real-time monitoring and information collection system has been built using the corresponding network security management equipment on the server.
[0046] Specifically, a real-time monitoring and information collection perception system can be implemented in the following ways: Server-side network security management devices can deploy distributed software or hardware traffic probes at key locations such as network entry nodes, core switches, and server front-ends to monitor attack events. These probes are equipped with Deep Packet Inspection (DPI) and Flow Behavior Analysis (DFI) technologies, capable of parsing tens of thousands of data packets per second of network traffic. Specifically, Deep Packet Inspection (DPI) technology can overcome the limitation of traditional firewalls that only inspect IP packet headers, enabling in-depth analysis and feature matching of data packet payloads. This is achieved through a built-in attack signature library (such as known DDoS tool fingerprints, abnormal protocol formats, and specific attack strings) to identify malicious traffic at the application layer. It can accurately identify attack event characteristics such as abnormal request headers in HTTP Flood (a type of DDoS attack), specific request frequencies in Challenge Collapsar (a type of DDoS attack), or malformed query packets in DNS Query Flood (a type of DDoS attack). Flow Behavior Analysis (DFI) focuses more on analyzing the macroscopic behavioral characteristics of network flows. It establishes a baseline model of normal traffic by statistically analyzing metadata such as the five-tuple (source IP, destination IP, source port, destination port, protocol type), traffic size, packet rate, flow duration, and flow direction. Once abnormal behavior deviating from the baseline is detected, such as a surge in connections per second from a single IP or an abnormal spike in UDP traffic to a specific port, DFI can trigger an anomaly alert even if the packet content itself is encrypted or disguised.
[0047] Furthermore, when a server encounters a DDoS network attack, its associated network security management equipment not only issues an alarm for abnormal traffic, but also performs in-depth collection of characteristic parameters of the DDoS network attack, including but not limited to the characteristics of the attack traffic packets, initiation time, duration, target port, and preliminary traffic path identification. Specifically, through this precise perception system for abnormal traffic, when the monitoring system confirms a DDoS attack, the network security management equipment will start a deep collection program to construct a multi-dimensional attack feature profile. This includes at least: (1) Packet feature collection, that is, in addition to basic information such as source IP, destination IP, and port, it will also extract the TTL (time to live) value of the packets, IP fragmentation characteristics, abnormal combinations of TCP flag bits (such as uncommon SYN / ACK ratios, which are related to the handshake situation), payload length and distribution, etc. These features help to determine the type of attack tool, the attacker's technical situation, and whether IP spoofing exists. (2) Time-series behavioral characteristics collection, that is, accurately recording the attack initiation time, duration, and waveform of traffic intensity (whether it is pulsed, continuous flooding, or gradually increasing, etc.). For example, if the attack is recorded to have started at 02:00 UTC and lasted for 45 minutes, with a traffic peak every 5 minutes, it indicates that the attack may be controlled by an automated script or come from a botnet across time zones. (3) Target port and protocol analysis, that is, collecting and analyzing the target ports that the attack is concentrated on and the transport layer and application layer protocols used. This directly indicates the threatened service, which is convenient for targeted protection. (4) Preliminary traffic path identification, that is, by analyzing the IP geographic information of the data packets, the BGP (Border Gateway Protocol) Autonomous System Number (AS Number), and the entry router identification when entering the network, the source distribution and network path of the attack traffic are initially obtained. This multi-dimensional information collection mode provides rich data support for subsequent source location. Compared with the traditional solution that relies on a single traffic threshold to trigger defense, it can more accurately depict the whole picture of the attack event and lay a data foundation for subsequent handling decisions. After the network security management device on the server side collects the attack information, it transmits it to the multi-cloud linkage management server through an encrypted channel to ensure that the attack information is not tampered with or leaked during the transmission process, and to provide complete data support for subsequent location of the attack source and generation of handling instructions.
[0048] Furthermore, when the server encounters a DDoS attack, its corresponding network security management equipment activates a triple detection mechanism: First, it calculates the traffic baseline in real time based on a sliding window algorithm to dynamically identify abnormal fluctuations. Specifically, the system uses a sliding time window to calculate short-term dynamic baselines for key traffic indicators (such as bit rate in bps, network throughput in pps, and new connections per second in cps) in real time, with units of seconds or milliseconds. Any fluctuation deviating from the baseline by more than a preset adaptive threshold will trigger an initial anomaly alarm. This sliding window mechanism can effectively filter out normal peak service traffic (such as normal continuous high traffic during the release of popular content) and focus on sudden anomalies. Second, it uses protocol fingerprint analysis technology to deeply mine hidden attack characteristics in the TCP / IP protocol stack. Specifically, the system performs deep protocol stack analysis on abnormal traffic to check whether the protocol interaction process conforms to standards. For example, it checks whether the "three-way handshake" in the TCP connection establishment process is complete and whether there are a large number of asymmetric handshakes (SYN only without ACK), thereby identifying SYN Flood attacks; or it checks whether there is a normal request-response correspondence in the UDP stream to identify reflection attacks. Finally, machine learning models are used to predictively analyze the temporal changes and port distribution patterns of attack traffic. Specifically, the system uses historical attack data to train machine learning models (such as recurrent neural networks, RNNs) to predict traffic temporal changes, source IP distribution patterns, and port scanning patterns. This allows the model's inference and predictive capabilities to detect subtle, slow-moving early signs of DDoS attacks or predict their next move during attack evolution, providing a reliable reference for subsequent defense strategies. When identifying and analyzing DDoS attack events, a source tracing module can be specially designed to embed encrypted source tags, such as timestamped hash values, into data packet transmission, using blockchain technology to achieve an immutable record of the attack path. Establishing a multi-dimensional attack characteristic profile through a comprehensive monitoring system in network security management equipment not only facilitates rapid location of the attack source but also allows for prediction of attack evolution trends, providing a basis for dynamic defense strategy development.
[0049] In another feasible implementation, upon detecting an attack, a multi-dimensional analysis report can be automatically generated, including an attack topology map, risk level assessment, and comparisons with historical similar attack cases, greatly improving the response efficiency of security operations personnel. This function specifically relies on a data fusion, intelligent association, and automated report generation engine. Based on the collected multi-dimensional attack feature profiles, a graph visualization engine can automatically generate an intuitive attack topology map. The map clearly marks the attack flow path, key attack nodes (such as amplifiers and control terminals), and attacked assets. Different colors and sizes can be used to indicate their risk level and traffic proportion. Furthermore, a risk quantification model based on preset weights is used to quantitatively assess attack events. Assessment dimensions include, but are not limited to: attack scale: peak traffic (Gbps / Tbps), packet rate (Mpps); attack complexity: whether it is a multi-vector hybrid attack, whether protocol obfuscation or encryption technology is used; asset criticality: the importance of the attacked target business (such as core databases, external authentication services); source threat: whether the attack source IP has a relevant historical record, whether it belongs to a known attacker. Through model calculation, a quantitative risk level (such as "high risk," "medium risk," or "low risk") is finally output, providing a priority basis for resource scheduling. In addition, by using an attack case library and similarity matching algorithms, the system can automatically compare the current attack event with historical similar attack cases. When a new attack occurs, the system calculates the similarity between the collected attack characteristics and historical records in the case library, quickly identifying at least one most similar historical case. Various information related to the found historical cases (such as handling records, final results, and post-incident analysis conclusions) provides reliable reference for current decision-making. Based on the above analysis results, the report generation engine automatically summarizes and generates a structured, standardized report, which is then pushed to the corresponding security incident management node of the security operations personnel via a pre-built interface.
[0050] S204. Based on the attack information, determine the source network node corresponding to the network attack event and generate handling instructions for the network attack event.
[0051] Optionally, after receiving attack information, the multi-cloud linkage management server matches key characteristics of the attack traffic based on a pre-built dynamic network topology map and attack signature database. The dynamic network topology map is a real-time updated, global digital model of network assets and logical relationships built and maintained in the multi-cloud linkage management server. First, the server continuously collects and uploads network configuration information for each network node through clients deployed on each node. This information includes, but is not limited to, virtual LAN (VLAN) partitioning, subnet segments, routing table information, virtual switch flow table rules, and load balancer policies. The collected raw data is processed by a graph computing engine (such as a stream processing platform based on Apache Kafka) to construct a dynamic graph with network devices, IP addresses, and cloud instances as nodes, and network connections, routing relationships, and policy dependencies as edges. This graph is real-time; the online, offline, migration, or change of any node is synchronized to the multi-cloud linkage management server in real time through the client, ensuring consistency between the graph and the actual network state. During attack tracing, this topology map is the foundation for path reasoning and impact scope analysis. When a server receives an attacking IP address, it can immediately locate it in the graph to determine which source network node it belongs to. At the same time, based on the network relationships in the graph, the logical connection relationship between the IP and other assets in the network can be analyzed to predict the potential spread risk of the attack. The attack signature database is a knowledge base of attack behavior based on historical attack events. Its intelligent matching process focuses on comprehensive pattern recognition. The signature database can specifically include (1) fingerprint feature layer: storing specific payload fragments, protocol abnormal fields, packet timing intervals and other features of known DDoS attack tools. (2) behavioral pattern layer: storing macro attack patterns, such as the typical traffic size and protocol distribution of "SSDP reflection attack", the proportion of incomplete handshakes of "TCP SYN Flood", source IP forgery rules, etc. (3) threat intelligence layer: marking known malicious IPs, domain names, techniques and programs (TTPs), etc.
[0052] The source network node refers not only to the device that directly launches the attack, but also to the resource pool or data center where the hijacked nodes participate in the attack. During this process, the machine learning model on the multi-cloud linkage management server can update the attack signature database in real time. By learning from historical attack data, it continuously optimizes the accuracy of source location, effectively avoiding location errors caused by attackers using node masquerading or other methods.
[0053] Furthermore, while identifying the source network node corresponding to the network attack, the system also generates response instructions for the attack. These instructions inform the source network node about the attack and instruct it to perform actions such as traffic blocking and scrubbing to defend against it.
[0054] In one feasible implementation, the handling instructions can also be customized according to the specific circumstances of the attack event. For example, targeted instructions for resolving each type of attack event can be determined based on different attack types. For instance, for a SYN Flood attack, the instructions will include reset parameters for abnormal connection requests; for a UDP Flood attack, filtering rules based on packet content will be embedded; for coordinated attacks by distributed nodes, the instructions will also include identification and handling strategies for related nodes within the same attack cluster, ensuring that the handling operations can accurately target the core aspects of the attack.
[0055] S206. Send the handling instruction to the network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node can handle the network attack event.
[0056] Optionally, the handling instruction is sent directly to the network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node can handle the network attack event. This allows the attack handling to be completed in the virtual network layer of the source network node. The control entity of the virtual network layer (such as a virtual switch or virtual router) is not independent of the physical hardware in the Internet, but runs as a software process in the operating system kernel of the source network node.
[0057] Optionally, when transmitting disposal instructions, a targeted transmission mechanism based on dedicated management channels is employed to ensure that the instructions accurately reach the network security management equipment corresponding to the source network node. These dedicated channels differ from public data transmission links, possessing independent bandwidth resources and encrypted transmission capabilities. By encapsulating the instruction content with highly stable encryption algorithms and embedding dynamic checksums during transmission, the instructions can be effectively prevented from being illegally intercepted, tampered with, or forged. Highly stable encryption algorithms refer to those capable of maintaining high performance, high reliability, and high security in various environments (including high-load, high-latency, and resource-constrained network environments). These include, but are not limited to: transport layer security protocols (such as TLS 1.3) used to establish secure channels; key exchange algorithms used to securely negotiate shared keys between communicating parties; authentication algorithms used to verify the identity of the server (and client); symmetric encryption algorithms used for data encryption; and message authentication codes used for integrity verification and identity authentication. These algorithms collectively constitute the technical foundation for ensuring the confidentiality, integrity, and authenticity of the transmitted disposal instructions. Furthermore, the channel can also have a built-in node identity authentication mechanism. Before sending instructions, the server performs multiple verifications on the identity of the target network security management device, including matching the device's unique hardware code, access permission token, and real-time session key. Only devices that pass the full verification can receive and parse instructions. This design can eliminate the risk of instructions being sent by mistake or being tricked by malicious nodes, providing an underlying guarantee for the security of the handling operation.
[0058] Optionally, upon receiving a handling instruction, the network security management device corresponding to the source network node immediately initiates the instruction parsing and execution process. The network security management device first verifies the integrity of the instruction, quickly matching it to its locally pre-configured handling rule base by parsing the attack type identifier, handling strategy number, and parameter configuration information in the instruction header. In the initial system deployment phase, the locally pre-configured handling rule bases of each source network node are generally based on fundamental defense rule templates derived from professional experience. These templates cover standardized handling solutions for most known attack types. These template rules are pre-configured in the local rule bases of each network node, ensuring that all nodes possess basic defense capabilities. In addition, after each attack handling operation, the network security management device records the handling effect (such as cleaning success rate, false positive rate, and impact on normal business operations), feeding this data back to the multi-cloud linkage management server. The multi-cloud linkage management server uses machine learning algorithms (such as reinforcement learning) to train and optimize policy parameters. The optimized new policy is then dynamically distributed to each network security management device in the form of an update package, replacing the old policy, thereby achieving continuous optimization and self-adaptation of the rule base. Furthermore, to meet the unique needs of specific users, it also supports operations and maintenance personnel to customize defense rules for specific assets through the management interface. After compliance and security verification, these customized rules can also be distributed to the corresponding network security management devices and work in conjunction with standardized rules.
[0059] Furthermore, the local pre-built handling rule base will integrate a large number of policy entries, each containing several key fields: (1) Policy number: a globally unique policy identifier; (2) Attack type identifier; (3) Target object: target IP segment, target port, protocol type, virtual network identifier, etc.; (4) Handling action: defines specific operations, such as dropping, rate limiting, redirecting to the cleaning center, sending TCP reset packets, etc.; (5) Action parameters: provides detailed configuration for the action, such as the specific value of the rate limit (1000 pps), the cleaning template number, etc. In addition to the necessary fields required in the policy, priority can also be included to determine the execution order when multiple rules match; and the scope of effect to define which virtual switch, which physical host, or which cluster the rule takes effect on. For example, if the instruction targets a TCP reflection attack, the device will automatically retrieve the corresponding packet feature library and mark packets in the local traffic that match the attack features; if the instruction targets a botnet coordinated attack, the node isolation module will be activated to restrict network access for the internal botnet processes involved in the attack. This rule-based execution logic ensures both the standardization of handling operations and the flexibility to adjust based on dynamic parameters in the instructions. For example, threshold settings for attack traffic and interception durations can be updated in real time via instructions, avoiding the processing lag caused by rigid rules in traditional static defenses. At the specific attack handling execution level, network security management devices rely on the virtual network layer architecture of the source network nodes to achieve endogenous removal of attack traffic.
[0060] In one feasible implementation, the device filters or redirects tagged attack traffic at the data link layer by invoking the flow table manipulation interface of the virtual switch. The intercepted traffic is directly transferred to a local black hole port for destruction, without entering the physical network interface. For scenarios requiring restrictions on the attacker's source node's permissions, the device temporarily blocks the connection between the attacker's source node and the external network by modifying the virtual network's access control list (ACL). This blocking only applies at the virtual network level and does not affect the normal operation of service processes within the node. This mechanism changes the traditional defense model of cleaning at the public network backbone node or metropolitan area network level, moving the defense line forward to the source of attack traffic generation. Since the entire process is completed within the resource pool or data center of the source network node, relying on local computing and storage resources to clean attack traffic without relying on the cooperation of external network devices, the entire process from attack traffic generation to removal is in a closed environment. The entire cleaning process does not require adjustments to the public network's routing policies or cross-network traffic redirection operations, thus avoiding the occupation of public network routing and bandwidth resources by attack traffic and eliminating the service interruption risk caused by cross-network traffic redirection in traditional solutions. Furthermore, the handling operations at the virtual network layer rely on the local computing resources of the nodes, eliminating the need for external scrubbing equipment. This not only improves response speed but also reduces dependence on public network infrastructure. For scenarios with extremely high service availability requirements, such as finance and e-commerce, this traffic-free handling method significantly reduces interference with normal services during attack countermeasures, allowing service systems to maintain stable operation even when attacked. Additionally, because the handling commands act directly on the source network nodes, attack traffic is intercepted and scrubbed in its early stages, eliminating the time costs of cross-network transmission and multi-level node forwarding in traditional defenses. The response cycle from the detection of an attack to its final resolution is significantly shortened, enabling defenders to quickly contain its impact before the attack scales up. This rapid countermeasure capability significantly enhances the initiative and effectiveness of network security defense.
[0061] This specification provides a method for defending against network attacks. The method involves receiving attack information from a network security management device corresponding to a server. This attack information is collected by the network security management device in response to detected network attack events. Based on the attack information, the method identifies the source network node corresponding to the network attack event and generates a handling instruction for the event. The handling instruction is then sent to the network security management device corresponding to the source network node, enabling it to handle the attack. When a server encounters a network attack, the corresponding network security management device collects and proactively reports attack-related information in real time. This immediate information transmission ensures that the attack event is incorporated into the handling system immediately, laying the foundation for a rapid response. After receiving the attack information, the server can accurately locate the source network node initiating the attack by analyzing the information. This accuracy of source tracing directly determines the targeting of the attack handling, improving the timeliness and accuracy of subsequent interception and processing operations. Once the source network node is identified, the server-generated handling instructions are directly sent to the network security management device corresponding to that node, prompting it to execute attack handling operations at the virtual network layer. This handling mechanism moves the defense operation node forward to the attack source itself, allowing attack traffic to be cleaned and eliminated before it leaves the source network node and enters the public internet, or even before it consumes public network routing resources. This mode of handling attack traffic at the attack source fundamentally cuts off the path for attack traffic to spread to the public network. It not only confines the impact of the attack to the source resource pool or data center, preventing unnecessary additional consumption of public network bandwidth resources and effectively alleviating the problems of public network routing congestion and bandwidth shortages, but also significantly shortens the response cycle, significantly improving the initiative and effectiveness of network security defense, and building a more efficient and stable security defense line for the server that is closer to the attack source.
[0062] Please see Figure 3 , Figure 3 This is a flowchart illustrating a network attack defense method provided in an embodiment of this specification.
[0063] like Figure 3 As shown, methods for defending against network attacks can include at least:
[0064] S302, the server, and the source network node each have their own associated clients deployed; they receive attack information reported by the network security management device corresponding to the server through the associated first client.
[0065] Optionally, to establish an efficient and stable interactive channel between the multi-cloud linkage management server and various server terminals, cloud resource pools, and data centers, associated clients can be deployed on both the server terminals and the source network nodes. This deployment model is not simply a functional overlay, but rather lays the foundation for building a standardized link for attack information collection and transmission. As an intermediary layer connecting network security management devices and the multi-cloud linkage management server, the client undertakes the core functions of information preprocessing, protocol conversion, and secure transmission. Its existence makes the attack information reporting process more standardized and reliable.
[0066] Optionally, please refer to Figure 4 , Figure 4 This diagram illustrates a multi-cloud deployment architecture for a network attack defense method provided in an embodiment of this specification. Figure 4 As shown, for the server, its associated first client and corresponding network security management device form a close collaborative relationship. When the server suffers a network attack, the network security management device monitors and collects attack information related to the attack event (or the server can actively submit it to the network security management device). Then, the network security management device establishes real-time communication with the first client through a preset interface protocol to forward the attack information to the first client. After receiving the attack information, the first client can perform preliminary format standardization processing on this information. For example, it can convert unstructured logs output by devices from different vendors into unified structured data, ensuring that the subsequent server can parse it efficiently. Simultaneously, the first client has a built-in data caching and breakpoint resumption mechanism. In the event of network fluctuations or brief interruptions, it can temporarily store attack information and automatically retransmit it after the connection is restored, avoiding the loss of critical data and ensuring the integrity of information reporting. This client-device binding model makes the server's attack information collection process more environmentally adaptable, compatible with different brands and models of network security management devices, and lowers the compatibility threshold for system deployment.
[0067] Furthermore, the first client reports standard attack information to the multi-cloud collaborative management server. This reported information includes at least the core characteristic parameters of the attack event, which collectively form the key basis for the server to locate the attack source and formulate response strategies. Specifically, the source Internet Protocol address (source IP address) directly points to the network identifier of the network node initiating the attack, serving as fundamental information for tracing the attack's origin. The destination Internet Protocol address (destination IP address) clarifies the target of the attack, helping the multi-cloud collaborative management server distinguish between attack events encountered by different servers. The source and destination network port information further refines the transmission path characteristics of the attack traffic. The distribution pattern of the source ports reflects whether the attack originates from a specific type of application or a hijacked service, while the destination port is related to the specific service provided by the server, such as ports 80 and 443 commonly used in web services. This information helps the multi-cloud collaborative management server determine the type of service targeted by the attack and thus take more targeted response measures. In addition, the type of communication protocol included in the attack information provides important clues for identifying attack characteristics. Different types of DDoS attacks often correspond to specific network protocols, such as SYN Flood attacks based on TCP and reflection attacks based on UDP. By parsing the protocol type, the corresponding attack model can be quickly matched, improving the targeting of response commands. These parameters are not isolated but interconnected, forming a complete attack traffic profile. By analyzing the correlation between source IP and source port, the cluster of botnet nodes in a distributed attack can be identified; by matching destination IP and destination port, the specific service module under attack can be located; and by combining the communication protocol type, the attack techniques can be further pinpointed. This collaborative analysis of multi-dimensional information allows the server to have a more comprehensive understanding of the attack event, providing solid data support for accurately locating the source network node and generating response commands.
[0068] In one feasible implementation, the reporting process of these attack information by the first client also incorporates a multi-layered security mechanism. Before transmission, the information undergoes encryption by the client, using a session key negotiated with the server to prevent eavesdropping or tampering during public network transmission. Simultaneously, the reported information embeds the client's digital signature. Upon receiving the information, the multi-cloud linkage management server verifies the validity of the signature to confirm that the information originates from the legitimate first client, eliminating the risk of malicious nodes forging attack information and ensuring the authenticity, integrity, and confidentiality of the reported attack information. This provides a fundamental security guarantee for the reliable operation of the entire technical solution.
[0069] S304. Based on the source Internet Protocol address in the attack information, query the address information database to see if there is a target network node corresponding to the source Internet Protocol address; the address information database is used to store the correspondence between pre-deployed client identification information and Internet Protocol addresses in network nodes.
[0070] Optionally, please refer to Figure 5 , Figure 5 This is a schematic diagram of the platform architecture for a network attack defense method provided in an embodiment of this specification. Figure 5 As shown, the multi-cloud linkage management server can be equipped with a cloud brain to undertake information exchange, data sharing, and collaborative decision-making functions among artificial intelligence agents. It enables cross-platform and cross-system data interaction via the internet, supports real-time communication between virtual and physical artificial intelligence agents, and integrates intelligent algorithms and knowledge bases from different sources. Specifically, in the embodiments of this specification, the cloud brain on the multi-cloud linkage management server can locate the source network node of a network attack event based on the source Internet Protocol address (source IP) in the attack information reported by the first client. In this process, the address information database plays a core supporting role. The address information database not only includes a list of IP addresses but is also a systematically designed relational database. Its core function is to store the mapping relationship between pre-deployed client identification information and Internet Protocol addresses in network nodes. This mapping relationship is built upon the prior network topology analysis and client deployment. Each client deployed on a network node is assigned a unique identifier, which includes not only the client's hardware characteristics and its associated resource pool or data center information, but also its logical location within the virtual network layer. Simultaneously, the network node's Internet Protocol (IP) address (including periodic updates of static and dynamic IPs) is synchronized to the database in real time, forming a three-dimensional relational data structure of "client identifier - IP address - network node attribute." This structured design enables the address database to respond quickly to query requests, providing accurate data support for matching source IPs with source network nodes.
[0071] For further information, please refer to [link / reference]. Figure 5During the specific query process, the multi-cloud linkage management server initiates a targeted search of the address information database based on the source IP extracted from the attack information. Specifically, the search process leverages the database's built-in indexing mechanism for efficient matching. By hashing the source IP to generate a search key, it quickly locates the potentially corresponding client identifier entry. Then, by verifying the validity of the IP address under that entry (including whether it is within its validity period and whether it matches the node's current actual IP), it ultimately determines whether a corresponding target network node exists. In this process, the system introduces multiple verification mechanisms, such as checking whether the client corresponding to the source IP is in normal operating condition and whether the network node to which the client belongs possesses the network environment characteristics of the attack, to rule out cases where the IP address has been forged or stolen. For network nodes with dynamically allocated IP addresses, the address information database synchronizes IP change records with the client's real-time heartbeat mechanism to ensure the timeliness of the mapping relationship and avoid query deviations caused by dynamic IP adjustments. This efficient and accurate query mechanism enables the system to complete the matching of source IPs and target network nodes within milliseconds.
[0072] S306. If it exists, determine that the target network node is the source network node corresponding to the network attack event, and generate a handling instruction for the network attack event.
[0073] Optionally, when a target network node corresponding to the source IP is found in the address information database, the system can clearly identify the target network node as the source network node of the network attack. The core of this determination logic lies in the strong binding relationship between the client and the network node. Since the client is deployed inside the network node and directly associated with the node's network interface, the mapping relationship between its identification information and the node's IP address has undergone strict verification and filing in the early stage, possessing high reliability. Therefore, once a matching client identifier is found in the address information database for the source IP, the network node to which the client belongs can be identified as the origin of the attack. This determination method bypasses the complex process of relying on routing records in traditional IP source tracing, directly achieving source location based on pre-established trusted associations, significantly improving the accuracy and efficiency of location.
[0074] Furthermore, once the source network node is identified, the process of generating handling instructions can be initiated. These instructions can simply inform the source network node of the handling requirements for the network attack event, with the network security management device corresponding to the source network node determining the appropriate handling strategy and method. Alternatively, in a feasible implementation, the generation of handling instructions can also be closely integrated with other core parameters in the attack information (such as attack type, traffic characteristics, involved protocols and ports, etc.) to directly form a targeted handling strategy, which is then directly executed by the network security management device corresponding to the source network node. For example, if the attack information indicates a SYN Flood attack based on the TCP protocol, and the source network node corresponding to the source IP belongs to a virtual host within a resource pool, the handling instructions will include threshold adjustment parameters for the virtual host's TCP connection request queue, reset instructions for abnormal connections, and commands to investigate potential attack processes within the node. If the attack involves a cluster of nodes corresponding to multiple source IPs, the instructions will also include a coordinated handling strategy for related nodes within the cluster to ensure the overall containment of attack traffic. Simultaneously, the instructions embed the client identifier of the source network node and execution time parameters, ensuring that the corresponding network security management devices can accurately identify the target of the instructions and complete the disposal operation within the specified time. This disposal instruction, generated based on both source node attributes and attack characteristics, ensures the accuracy of the operation and provides a clear evaluation basis for subsequent disposal effect verification, thus achieving a seamless connection from attack location to disposal execution at the technical level. This design improves the efficiency and accuracy of attack tracing and provides a clear execution basis for subsequent source disposal, giving the entire defense system a significant advantage in accuracy and response speed.
[0075] It should be noted that during the process of locating the source network node based on the source Internet Protocol address, if a query fails, a pre-defined exception handling mechanism is activated. The core of this mechanism is to ensure the security and traceability of the operation, while also providing a basis for subsequent troubleshooting. A query failure typically means that no target network node corresponding to the source Internet Protocol address in the attack information was found in the address database, or that the location was terminated during the matching process due to incomplete information, verification failure, or other reasons. In this case, the system does not trigger the generation process of attack handling instructions to avoid misoperation caused by ambiguous or incorrect location. This design fundamentally eliminates the risk of sending handling instructions to non-attack source nodes, ensuring that the service operation of normal nodes in the network environment is not interfered with. After confirming that no attack handling instructions will be generated, the system will immediately feed back the query failure information to the first client that reported the attack information. This notification process is not a simple status update; it includes key details related to the query, such as the specific reason for the query failure (e.g., the source Internet Protocol address is not registered in the address information database, the association verification between the IP address and the client identifier fails, or the dynamic IP address is not synchronized in time), the query timestamp, and the system's suggested follow-up actions (e.g., resubmitting the attack information, checking the authenticity of the source IP). The notification is transmitted through an encrypted communication channel between the first client and the backend server, ensuring that the information is not tampered with or leaked during transmission. After receiving the notification, the first client synchronizes the relevant information to the corresponding network security management device on the server side, enabling the server to understand the progress of attack location in a timely manner and adjust its local defense strategy accordingly. For example, if the attack source is not clearly identified, local traffic scrubbing efforts can be temporarily strengthened to mitigate the impact of the attack. This two-way information exchange mechanism ensures that the entire defense system maintains coordination in the face of anomalies, avoiding defense delays caused by information gaps.
[0076] Furthermore, the multi-cloud integrated management server meticulously logs the entire process of query failures. The logs not only include basic event elements such as the time of the failure, the corresponding attack information number, and the source internet protocol address, but also cover specific status data for each stage of the query process, such as the retrieval path in the address database, the exception rules triggered during verification, and the current status of relevant entries in the database. These logs are stored in a structured format, including fields such as timestamp, operation node, event type, and detailed description. By employing blockchain or hash verification technology, they possess tamper-proof characteristics, ensuring that the log content maintains its originality and integrity at any subsequent point in time. The storage location and access permissions of the logs are strictly controlled, accessible only to system administrators or authorized auditors to meet network security compliance requirements. This logging mechanism provides technical personnel with complete clues to investigate the causes of query failures. The aggregated analysis of numerous query failure logs also helps the system identify potential risks. For example, frequently appearing unregistered source IPs may indicate the emergence of new attack methods, or there may be blind spots in the coverage of the address database. This data provides important evidence for iterative optimization of the system. In addition, log records provide irreplaceable evidence for post-incident auditing of cybersecurity incidents, ensuring that the operational process can be traced and the boundaries of responsibility can be clearly defined when a security incident occurs.
[0077] S308. Send the handling instruction to the second client associated with the source network node, so that the second client forwards the handling instruction to the network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node can handle the network attack event.
[0078] Alternatively, please continue reading Figure 4 The process of transmitting disposal instructions to the source network nodes is achieved through a hierarchical and highly adaptable transmission link formed by the second client associated with the source network nodes. This design ensures the accuracy of instruction transmission and provides adaptable execution interfaces for different types of source nodes. The second client, acting as an intermediary hub connecting the multi-cloud linkage management server and the security management devices of the source network nodes, is not simply an instruction forwarding carrier but undertakes a composite function of protocol adaptation, security verification, and status feedback. It has a pre-defined binding relationship with the source network nodes, based on the node's unique identifier and the client's authentication mechanism, ensuring that each disposal instruction is accurately routed to the client corresponding to the target node. Upon receiving a disposal instruction, the second client first verifies the integrity and legality of the instruction. By parsing the source node identifier, execution permission token, and other information embedded in the instruction, it confirms the reliability of the instruction's source and the compliance of the operation, preventing illegal or mis-sent instructions from interfering with the source nodes. Figure 4Taking Cloud Resource Pool 1 and Cloud Resource Pool 2 as the source network nodes, and Cloud Resource Pool 1 and Cloud Resource Pool 2 together corresponding to a network security management device as an example, this example is used for demonstration. In the traffic transmitted from Cloud Resource Pool 1 and Cloud Resource Pool 2 to the Internet, solid lines represent normal access traffic and dashed lines represent attack traffic. Dashed lines are used to indicate that after the source network nodes are cleaned, they can no longer flow to the public network route.
[0079] Furthermore, after verification, the second client forwards the handling command to the network security management device corresponding to the source network node. This forwarding process relies on a dedicated communication channel within the node, which employs a transmission protocol adapted to the node's network environment. For example, in highly virtualized environments, an SDN-based flow table interaction protocol is used, while in traditional network architectures, proprietary extension fields of the TCP / IP protocol are adapted to ensure the real-time performance and stability of the command transmission across different network environments. Simultaneously, the command content is re-encapsulated during forwarding, dynamically adjusting the data format according to the type of the source node, enabling the receiving device to directly parse and execute it, reducing latency caused by protocol conversion and supporting the timeliness of attack handling.
[0080] Furthermore, the type of the source network node determines the functional characteristics of its associated network security management equipment. This differentiated adaptation allows attack response operations to be deeply integrated with the node's network architecture. When the source network node is a cloud resource pool, the corresponding network security management equipment is the cloud management platform. As the core control hub of the cloud resource pool, this platform has the ability to globally schedule dynamic resources such as virtual hosts, containers, and network slices. After receiving the response instruction, the cloud management platform combines the attack characteristic parameters contained in the instruction and calls its own virtual network controller. By adjusting the flow table rules of the virtual switch, it implements traffic isolation for the virtual subnet where the attack source is located, or performs bandwidth limiting, port blocking, and other operations on the virtual instance that initiated the attack. Because the resources of the cloud resource pool have elastic scaling characteristics, the cloud management platform can also coordinate with the resource scheduling module to temporarily expand protection resources to cope with large-scale attack traffic, ensuring that the response operation can accurately target the attack source without affecting the operation of other normal services within the pool.
[0081] On the other hand, when the source network node is a data center, the corresponding network security management equipment is a dedicated attack handling system. This system typically consists of a hardware firewall, intrusion prevention equipment, and a centralized management platform, capable of handling large-scale physical machine traffic. Upon receiving a handling instruction, the system uses the centralized management platform to parse the attack type and source port information in the instruction, and coordinates with the underlying hardware devices to perform feature matching on the attack traffic. For known attack characteristics, it directly calls a preset signature database for packet filtering; for new attacks with unknown characteristics, it activates a behavior analysis engine to identify abnormal behavior and implement interception by establishing a normal traffic baseline. The data center's attack handling system also has deep adaptation capabilities to the internal network topology, and can adjust the forwarding policies of adjacent switches according to the source node location specified in the instruction, confining the attack traffic to an isolated area within the data center for cleaning, preventing it from spreading to the external network. Both the cloud management platform of the cloud resource pool and the attack handling system of the data center demonstrate a high degree of synergy with the source node's network architecture during the execution of attack handling. This node-type-adaptive handling mechanism allows command execution to fully utilize the node's own resources and control capabilities, ensuring both the accuracy of attack handling and avoiding compatibility issues arising from cross-platform operations. Simultaneously, the second client's forwarding link provides stable command transmission support throughout the entire process, forming a closed loop from command issuance to execution feedback. This ensures the backend server can monitor the handling progress in real time, providing a basis for subsequent strategy optimization. Thus, at the technical level, it achieves efficient end-to-end coordination in attack handling, from decision-making to execution.
[0082] It should be noted that the final handling result at the source network node is also transmitted back to the second client by its corresponding network security management device. The second client then transmits the result back to the multi-cloud linkage management server. The multi-cloud linkage management server records the result in its log and also reports the relevant information to the first client that reported the attack information, thus completing the closed-loop process of the entire attack handling process.
[0083] This specification provides a method for defending against network attacks. Because attack handling is completed at the source node, the response cycle from attack occurrence to handling execution is compressed to the stage before the attack traffic spreads. Compared to traditional methods where attack traffic is transmitted to remote cleaning nodes, the response efficiency is significantly improved, effectively curbing the expansion of the attack scale. Furthermore, by eliminating attack traffic at the source, bandwidth congestion caused by attack traffic entering the public network is avoided, ensuring efficient utilization of public network routing resources. This is particularly beneficial in large-scale DDoS attack scenarios, significantly reducing the load pressure on the public network. Simultaneously, since the handling process does not involve cross-network traffic diversion or routing adjustments, normal service traffic on the server side does not need to undergo path switching, ensuring service continuity. This has an irreplaceable advantage for scenarios with extremely high stability requirements, such as financial transactions and online services.
[0084] Please see Figure 6 , Figure 6 This is a structural block diagram of a network attack defense device provided in an embodiment of this specification. Figure 6 As shown, the network attack defense device 600 includes:
[0085] The attack information receiving module 610 is used to receive attack information sent by the network security management device corresponding to the server. The attack information is the information collected by the network security management device corresponding to the server in response to the network attack events detected.
[0086] The handling instruction issuing module 620 is used to determine the source network node corresponding to the network attack event based on the attack information, and generate handling instructions for the network attack event.
[0087] The attack incident handling module 630 is used to send handling instructions to the network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node can handle the network attack incident.
[0088] Optionally, both the server and the source network node are deployed with their own associated clients; the attack information receiving module 610 is also used to receive attack information reported by the network security management device corresponding to the server through the associated first client; the attack event handling module 630 is also used to send the handling instructions to the second client associated with the source network node, so that the second client forwards the handling instructions to the network security management device corresponding to the source network node.
[0089] Optionally, the attack information may include at least the source Internet Protocol address, destination Internet Protocol address, source network port, destination network port, and communication protocol corresponding to the network attack event.
[0090] Optionally, the handling instruction issuing module 620 is also used to query the address information database based on the source Internet Protocol address in the attack information to see if there is a target network node corresponding to the source Internet Protocol address; if there is, the target network node is determined to be the source network node corresponding to the network attack event; the address information database is used to store the correspondence between pre-deployed client identification information and Internet Protocol addresses in network nodes.
[0091] Optionally, the source network node can be a cloud resource pool or a data center. When the source network node is a cloud resource pool, the network security management device corresponding to the source network node is a cloud management platform that is compatible with the cloud resource pool. When the source network node is a data center, the network security management device corresponding to the source network node is an attack handling system that is compatible with the data center.
[0092] Optionally, the network attack event is a distributed denial-of-service attack event.
[0093] This specification provides a network attack defense device, comprising: an attack information receiving module for receiving attack information sent by a network security management device corresponding to the server, wherein the attack information is information collected by the network security management device in response to detected network attack events; a handling instruction issuing module for determining the source network node corresponding to the network attack event based on the attack information and generating a handling instruction for the network attack event; and an attack event handling module for sending the handling instruction to the network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node can handle the network attack event. When the server encounters a network attack event, the corresponding network security management device will collect attack-related information in real time and actively report it. This real-time information transmission ensures that the attack event can be included in the handling system as soon as possible, laying the foundation for subsequent rapid response. After receiving the attack information, the server can accurately locate the source network node that initiated the attack by parsing the attack information. The accuracy of this source tracing directly determines the targeting of the attack handling, which is conducive to improving the timeliness and accuracy of subsequent interception and processing operations. Once the source network node is identified, the server-generated handling instructions are directly sent to the network security management device corresponding to that node, prompting it to execute attack handling operations at the virtual network layer. This handling mechanism moves the defense operation node forward to the attack source itself, allowing attack traffic to be cleaned and eliminated before it leaves the source network node and enters the public internet, or even before it consumes public network routing resources. This mode of handling attack traffic at the attack source fundamentally cuts off the path for attack traffic to spread to the public network. It not only confines the impact of the attack to the source resource pool or data center, preventing unnecessary additional consumption of public network bandwidth resources and effectively alleviating the problems of public network routing congestion and bandwidth shortages, but also significantly shortens the response cycle, significantly improving the initiative and effectiveness of network security defense, and building a more efficient and stable security defense line for the server that is closer to the attack source.
[0094] This specification provides a computer program product containing instructions that, when run on a computer or processor, cause the computer or processor to perform the steps of any of the methods described above.
[0095] This specification also provides a computer storage medium that can store multiple instructions adapted for loading by a processor and executing the steps of any of the methods described in the above embodiments.
[0096] Please see Figure 7 , Figure 7 This is a schematic diagram of the structure of a server provided as an embodiment of this specification. Figure 7As shown, server 700 may include: at least one server processor 701, at least one network interface 704, user interface 703, memory 705, and at least one communication bus 702.
[0097] The communication bus 702 is used to enable communication between these components.
[0098] The user interface 703 may include a display screen and a camera. Optionally, the user interface 703 may also include a standard wired interface and a wireless interface.
[0099] The network interface 704 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface).
[0100] The server processor 701 may include one or more processing cores. The server processor 701 connects to various parts of the server 700 using various interfaces and lines, and performs various functions and processes data by running or executing instructions, programs, code sets, or instruction sets stored in memory 705, and by calling data stored in memory 705. Optionally, the server processor 701 may be implemented using at least one hardware form of Digital Signal Processing (DSP), Field-Programmable Gate Array (FPGA), or Programmable Logic Array (PLA). The server processor 701 may integrate one or a combination of several of the following: Central Processing Unit (CPU), Graphics Processing Unit (GPU), and modem. The CPU primarily handles the operating system, user interface, and applications; the GPU is responsible for rendering and drawing the content required for display; and the modem handles wireless communication. It is understood that the modem may also not be integrated into the server processor 701 and may be implemented as a separate chip.
[0101] The memory 705 may include random access memory (RAM) or read-only memory (ROM). Optionally, the memory 705 may include a non-transitory computer-readable storage medium. The memory 705 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 705 may include a program storage area and a data storage area, wherein the program storage area may store instructions for implementing an operating system, instructions for at least one function (such as touch function, sound playback function, image playback function, etc.), instructions for implementing the above-described method embodiments, etc.; the data storage area may store data involved in the above-described method embodiments, etc. Optionally, the memory 705 may also be at least one storage device located remotely from the aforementioned server processor 701. Figure 7 As shown, the memory 705, which serves as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a network attack defense program.
[0102] exist Figure 7 In the server 700 shown, the user interface 703 is mainly used to provide an input interface for users and to obtain user input data; while the server processor 701 can be used to call the network attack defense program stored in the memory 705 and specifically perform the following operations:
[0103] Receive attack information sent by the network security management device corresponding to the server. The attack information is the information collected by the network security management device corresponding to the server in response to the network attack events detected.
[0104] Based on the attack information, the source network node corresponding to the network attack event is identified, and handling instructions for the network attack event are generated.
[0105] The disposal instructions are sent to the network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node can handle the network attack event.
[0106] In some embodiments, both the server and the source network node are deployed with their respective associated clients. When the server processor 701 receives attack information sent by the network security management device corresponding to the server, it specifically performs the following steps: receiving attack information reported by the network security management device corresponding to the server through the associated first client. When the server processor 701 sends a handling instruction to the network security management device corresponding to the source network node, it specifically performs the following steps: sending the handling instruction to the second client associated with the source network node, so that the second client forwards the handling instruction to the network security management device corresponding to the source network node.
[0107] In some embodiments, the attack information includes at least the source Internet Protocol address, destination Internet Protocol address, source network port, destination network port, and communication protocol corresponding to the network attack event.
[0108] In some embodiments, when the server processor 701 determines the source network node corresponding to the network attack event based on attack information, it specifically performs the following steps: based on the source Internet Protocol address in the attack information, it queries the address information database to see if there is a target network node corresponding to the source Internet Protocol address; if there is, it determines that the target network node is the source network node corresponding to the network attack event; the address information database is used to store the correspondence between pre-deployed client identification information and Internet Protocol addresses in network nodes.
[0109] In some embodiments, the source network node is a cloud resource pool or a data center; when the source network node is a cloud resource pool, the network security management device corresponding to the source network node is a cloud management platform that is compatible with the cloud resource pool; when the source network node is a data center, the network security management device corresponding to the source network node is an attack handling system that is compatible with the data center.
[0110] In some embodiments, the network attack event is a distributed denial-of-service attack event.
[0111] In the several embodiments provided in this specification, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.
[0112] The modules described as separate components may or may not be physically separate. Similarly, the components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0113] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When these computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this specification are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in or transmitted through a computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The aforementioned available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., Digital Versatile Discs (DVDs)), or semiconductor media (e.g., Solid State Disks (SSDs)).
[0114] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification.
[0115] Furthermore, it should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in the embodiments of this specification are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, traffic and attack information involved in this specification were obtained under full authorization.
[0116] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0117] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0118] The above is a description of a network attack defense method, apparatus, storage medium, and server provided in the embodiments of this specification. For those skilled in the art, based on the ideas of the embodiments of this specification, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation on the embodiments of this specification.
Claims
1. A method for defending against a network attack, the method comprising: receiving attack information reported by a first client associated with a network security management device corresponding to a server, the attack information being information collected by the network security management device corresponding to the server for a monitored network attack event; determining a source network node corresponding to the network attack event based on the attack information, and generating a handling instruction for the network attack event; sending the handling instruction to a second client associated with the source network node, so that the second client forwards the handling instruction to a network security management device corresponding to the source network node, so that the network security management device corresponding to the source network node performs attack handling for the network attack event at a virtual network layer, the virtual network layer being in the form of a software process running in an operating system kernel of the source network node.
2. The method of claim 1, wherein the attack information at least includes a source Internet Protocol (IP) address, a destination IP address, a source network port, a destination network port, and a communication protocol corresponding to the network attack event.
3. The method of claim 2, wherein the determining of the source network node corresponding to the network attack event based on the attack information comprises: querying whether there is a target network node corresponding to the source IP address in an address information library based on the source IP address in the attack information; if there is, determining that the target network node is the source network node corresponding to the network attack event; the address information library is used to store a correspondence between pre-deployed client identification information and an IP address in a network node.
4. The method of claim 1, wherein the type of the source network node is a cloud resource pool or a data center; when the type of the source network node is the cloud resource pool, the network security management device corresponding to the source network node is a cloud management platform matched with the cloud resource pool; when the type of the source network node is the data center, the network security management device corresponding to the source network node is an attack handling system matched with the data center.
5. The method of claim 1, wherein the network attack event is a distributed denial of service attack event.
6. A device for defending against a network attack, the device comprising: an attack information receiving module configured to receive attack information reported by a first client associated with a network security management device corresponding to a server, the attack information being information collected by the network security management device corresponding to the server for a monitored network attack event; a handling instruction issuing module configured to determine a source network node corresponding to the network attack event based on the attack information, and generate a handling instruction for the network attack event. An attack event handling module is configured to send the handling instruction to a second client associated with the source network node, so that the second client forwards the handling instruction to a network security management device corresponding to the source network node, and the network security management device corresponding to the source network node performs attack handling on the network attack event at a virtual network layer, which is in the form of a software process running in an operating system kernel of the source network node.
7. A computer program product comprising instructions which, when the computer program product is executed on a computer or a processor, cause the computer or the processor to carry out the steps of the method according to any one of claims 1-5.
8. A computer storage medium storing a plurality of instructions adapted to be loaded and executed by a processor to perform the steps of the method according to any one of claims 1-5.
9. A server comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor implements the steps of the method according to any one of claims 1-5 when executing the computer program.
Citation Information
Patent Citations
IP address blocking processing method and device, electronic equipment and storage medium
CN116260618A
Network security active defense method and system for detecting abnormal network behaviors
CN119628910A