Data processing method and device, equipment and medium

By analyzing the server's business logs for CC attacks, segmenting and evaluating them, and formulating personalized protection strategies, we resolved the protection vulnerabilities caused by unified frequency control values ​​and improved the protection effect of network attacks.

CN120834935APending Publication Date: 2025-10-24TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410499255.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-20
Publication Date
2025-10-24

AI Technical Summary

Technical Problem

In the existing technology, the protection method against CC attacks uses a unified frequency control value, which causes the attack traffic to pass through the protection and directly reach the source station, resulting in poor protection effect.

Method used

By analyzing the service protection logs and prompt logs reported by the protection devices obtained from the server, the attack and non-attack traffic logs are divided, the attack level of illegal network addresses is evaluated, and differentiated protection strategies are formulated.

Benefits of technology

It achieves refined and hierarchical protection against illegal network addresses, improves the protection effect of network attacks, reduces the amount of frequency control pass-through, and protects the stability of business servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120834935A_ABST
    Figure CN120834935A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method and device, equipment and a medium. The method comprises the steps that an aggregation access log is determined based on a service protection log, and attack time data used for log division is determined based on a service prompt log; dividing the aggregation access log into an attack type traffic log and a non-attack type traffic log based on the attack time data; based on the attack type traffic log and the non-attack type traffic log, determining an attacked target business server in the business servers and a target access device which initiates an illegal access request to the target business server in the access device, and obtaining illegal access data associated with the target business server and the target access device; performing attack degree evaluation on the illegal network address according to the illegal access data to obtain the attack degree of the illegal network address for the target access domain name; the attack degree is used for determining a protection strategy for the illegal network address. By adopting the method and the device, the protection effect on network attacks can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a data processing method and device, equipment and medium. BACKGROUND

[0002] CC attack (Challenge Collapsar) is a denial of service (DoS) / distributed denial of service (DDoS) attack method for web services. Attackers simulate a large number of normal user access requests to make the business server of the deployed website continuously generate high load, thereby affecting the stable operation of the website.

[0003] In the scenario where normal users and attackers simultaneously access the business of the attacked website, the widely used protection method is to formulate a unified frequency control value according to the access frequency of normal users, that is, for each IP (Internet Protocol) address, only a certain amount of access requests are allowed to pass in a fixed time window, so as to alleviate the pressure of the website caused by medium and high frequency CC attacks. However, the inventors have found in practice that when a non-discriminatory frequency control value is formulated for all IP addresses, a certain amount of attack traffic will pass through the protection and directly reach the source station (i.e., the business server), thereby resulting in poor protection effect on network attacks. SUMMARY

[0004] The embodiments of the present application provide a data processing method, device, equipment and medium, which can improve the protection effect on network attacks.

[0005] The embodiments of the present application provide a data processing method, device, equipment and medium, which can improve the protection effect on network attacks.

[0006] Obtaining the business protection log and the business prompt log reported by the protection device, determining the aggregated access log associated with the access device and the business server based on the business protection log, and determining the attack time data used for log division based on the business prompt log; the access request sent by the access device to the business server carries the access domain name of the business server and the network address of the access device;

[0007] Dividing the aggregated access log into attack type traffic log and non-attack type traffic log based on the attack time data;

[0008] Based on attack traffic logs and non-attack traffic logs, the target business server under attack is determined among the business servers, as well as the target access device that initiates an illegal access request to the target business server among the access devices, and illegal access data associated with the target business server and the target access device is obtained; the illegal access request carries the target access domain name of the target business server and the illegal network address of the target access device;

[0009] The attack degree of illegal network addresses is evaluated based on illegal access data to obtain the attack degree of illegal network addresses against target access domain names; the attack degree is used to determine the protection strategy for illegal network addresses.

[0010] In one aspect, an embodiment of the present application provides a data processing method, which is executed by a protection device and includes:

[0011] Send business protection logs and business prompt logs to the analysis server; business protection logs are used to determine the aggregated access logs associated with the access device and the business server; business prompt logs are used to determine the attack time data used for log division; the access request sent by the access device to the business server carries the access domain name of the business server and the network address of the access device; the attack time data is used to divide the aggregated access logs into attack traffic logs and non-attack traffic logs; attack traffic logs and non-attack traffic logs are used to determine the target business server that is attacked in the business server, and the target access device that initiates an illegal access request to the target business server in the access device, and obtain illegal access data associated with the target business server and the target access device; the illegal access request carries the target access domain name of the target business server and the illegal network address of the target access device; the analysis server is used to evaluate the attack degree of the illegal network address based on the illegal access data, obtain the attack degree of the illegal network address against the target access domain name, and send the attack degree to the protection device;

[0012] Receive and analyze the attack severity sent by the server, and determine the protection strategy for illegal network addresses based on the attack severity.

[0013] On the one hand, an embodiment of the present application provides a data processing device, which runs on an analysis server and includes:

[0014] A log processing module is used to obtain the service protection logs and service prompt logs reported by the protection device, determine the aggregated access logs associated with the access device and the service server based on the service protection logs, and determine the attack time data used for log segmentation based on the service prompt logs; the access request sent by the access device to the service server carries the access domain name of the service server and the network address of the access device;

[0015] A log partitioning module, used to partition aggregated access logs into attack traffic logs and non-attack traffic logs based on attack time data;

[0016] A data acquisition module is used to determine, based on attack traffic logs and non-attack traffic logs, a target business server under attack among business servers, and a target access device among access devices that initiates an illegal access request to the target business server, and obtain illegal access data associated with the target business server and the target access device; the illegal access request carries the target access domain name of the target business server and the illegal network address of the target access device;

[0017] The attack assessment module is used to evaluate the attack degree of illegal network addresses based on illegal access data to obtain the attack degree of illegal network addresses against target access domain names; the attack degree is used to determine the protection strategy for illegal network addresses.

[0018] In one embodiment, the log processing module is further configured to perform the following operations:

[0019] Perform log preprocessing on the service protection log to obtain aggregated access logs associated with access devices and service servers;

[0020] Based on the business prompt log, continuous attack detection data in the time dimension is obtained, and the attack detection data is preprocessed to obtain attack time data for log segmentation.

[0021] In one embodiment, the log processing module is further configured to perform the following operations:

[0022] Perform data cleanup on abnormal log data in business protection logs to obtain standard log data;

[0023] Based on the first type of log fields, a data aggregation operation is performed on the standard log data to obtain an aggregated access log associated with the access device and the service server.

[0024] Business notification logs include traffic surge notification logs and illegal address access notification logs;

[0025] In one embodiment, the log processing module is further configured to perform the following operations:

[0026] Continuous processing is performed on the traffic surge prompt log and the illegal address access prompt log to obtain first attack detection data corresponding to the traffic surge prompt log and second attack detection data corresponding to the illegal address access prompt log, and the first attack detection data and the second attack detection data are used as attack detection data that are continuous in the time dimension; continuous processing refers to data processing of the log data obtained within the detection time interval; the time dimension refers to the time within the detection time interval;

[0027] The first attack detection data and the second attack detection data in the attack detection data are preprocessed to obtain attack time data used for log division.

[0028] In an implementation, the log processing module is further configured to perform the following operation:

[0029] The first detection time interval configured for the traffic surge prompt log is obtained, and log data in the traffic surge prompt log located in the first detection time interval is processed to obtain first attack detection data corresponding to the traffic surge prompt log;

[0030] The second detection time interval configured for the illegal address access prompt log is obtained, and log data in the illegal address access prompt log located in the second detection time interval is processed to obtain second attack detection data corresponding to the illegal address access prompt log.

[0031] In an implementation, the log processing module is further configured to perform the following operation:

[0032] The first attack time interval associated with the first attack detection data and the second attack time interval associated with the second attack detection data are obtained, and the first attack detection data and the second attack detection data are processed based on the first attack time interval and the second attack time interval to obtain aggregated detection data; the confidence included in the aggregated detection data is determined by the first confidence corresponding to the first attack detection data and the second confidence corresponding to the second attack detection data;

[0033] Data with a confidence greater than an attack confidence threshold is obtained from the aggregated detection data, and the obtained data is taken as first-class attack time data;

[0034] Data with a confidence less than or equal to the attack confidence threshold is obtained from the aggregated detection data, and data in the aggregated detection data satisfying an attack screening condition is taken as second-class attack time data when the obtained data satisfies the attack screening condition;

[0035] The first-class attack time data and the second-class attack time data are taken as attack time data used for log division.

[0036] In an implementation, the log division module is further configured to perform the following operation:

[0037] Log data in the aggregated access log hitting the attack time data is taken as initial attack log data, and the initial attack log data is processed based on a second log field to obtain attack-class traffic log;

[0038] The log data in the poly access log which does not hit the attack time data is taken as initial business log data, and the initial business log data is subjected to a data aggregation operation based on the third type of log field, to obtain non-attack type flow log.

[0039] In an implementation, the data acquisition module is further configured to perform the following operation:

[0040] The access domain name contained in the attack type flow log is taken as a target access domain name, the server indicated by the target access domain name is taken as a target business server in the business server which is attacked, and the legitimate access condition corresponding to the target access domain name is determined based on the log data associated with the target access domain name in the non-attack type flow log.

[0041] The log data which does not conform to the legitimate access condition is obtained from the attack type flow log as initial illegal data.

[0042] When the trusted network address associated with the target access domain name is determined based on the legitimate access condition, the illegal network address is obtained from the network address contained in the initial illegal data based on the trusted network address, and the device indicated by the illegal network address is taken as a target access device in the access device which initiates an illegal access request to the target business server; the trusted network address is used to indicate the device in the access device which is trusted by the target business server.

[0043] The data associated with the illegal network address obtained from the initial illegal data is taken as illegal access data associated with the target business server and the target access device.

[0044] In an implementation, the data acquisition module is further configured to perform the following operation:

[0045] The log data associated with the target access domain name in the non-attack type flow log is subjected to volatility analysis, to obtain a volatility analysis result for the target access domain name, and the first analysis data source is obtained from the non-attack type flow log based on the volatility analysis result.

[0046] The log data associated with the target access domain name in the non-attack type flow log is subjected to access frequency analysis, to obtain a high-frequency access range for the target access domain name, and the log data in the non-attack type flow log whose access frequency is in the high-frequency access range is taken as the second analysis data source.

[0047] The legitimate access condition corresponding to the target access domain name is determined based on the first analysis data source and the second analysis data source.

[0048] In an implementation, the data acquisition module is further configured to perform the following operation:

[0049] If the fluctuation analysis result indicates that the access traffic to the target access domain name is smooth, log data located in the first type of attack time interval is obtained from the non-attack type traffic log as the first analysis data source;

[0050] If the fluctuation analysis result indicates that the access traffic to the target access domain name fluctuates, log data located in the second type of attack time interval is obtained from the non-attack type traffic log as the first analysis data source; the range corresponding to the second type of attack time interval is greater than the range corresponding to the first type of attack time interval.

[0051] In an implementation, the data acquisition module is further configured to perform the following operation:

[0052] Obtain log data that does not meet the legal access condition from the attack type traffic log as initial illegal data, including:

[0053] In the attack type traffic log, find network addresses with a number of access requests greater than a threshold of a number of legal requests or network addresses with an access request rate greater than a threshold of a legal request rate in an attack time interval associated with the target access domain name, and take the found network addresses as preliminary illegal network addresses, and take log data associated with the preliminary illegal network addresses as log data that does not meet the legal access condition;

[0054] Obtain log data that does not meet the legal access condition from the attack type traffic log, and take the obtained log data as initial illegal data.

[0055] The network addresses contained in the initial illegal data are preliminary illegal network addresses;

[0056] In an implementation, the data acquisition module is further configured to perform the following operation:

[0057] Obtain network addresses that meet the legal access condition from the attack type traffic log, and add the obtained network addresses to trusted network addresses associated with the target access domain name;

[0058] Take network addresses obtained after removing the trusted network addresses from the preliminary illegal network addresses as illegal network addresses; the illegal network addresses are network addresses other than the trusted network addresses in the preliminary illegal network addresses.

[0059] In an implementation, the attack evaluation module is further configured to perform the following operation:

[0060] Determine historical attack dimension information associated with the illegal network addresses according to the illegal access data, perform attack degree evaluation on the illegal network addresses based on the historical attack dimension information, and obtain an attack degree of the illegal network addresses to the target access domain name; the historical attack dimension information is used to represent multi-dimensional characteristics of the illegal network addresses in historical attacks.

[0061] In an implementation, the attack evaluation module is further configured to perform the following operations:

[0062] When the data validity period for the illegal network address configuration is obtained, access reputation data for sending to the protection device is constructed based on the illegal network address, the attack degree, and the data validity period; the data validity period is determined by the data minimum validity period and the data maximum validity period; the protection device is configured to, when detecting the illegal network address hitting the access reputation data within the data validity period, determine the protection policy for the illegal network address based on the attack degree in the access reputation data.

[0063] In an implementation, the apparatus further comprises:

[0064] The interception analysis module is configured to obtain service access association data associated with the access device and the service server, and perform interception analysis on the illegal network address based on the service access association data; when an abnormal interception network address is analyzed in the illegal network address, the abnormal interception network address is added to the trusted network address associated with the target access domain name; the abnormal interception network address is used to indicate a device in the target access device that has a legal access right; and the trusted network address is used to identify a device in the access device that is trusted by the target service server.

[0065] The embodiment of the present application provides a data processing apparatus, which runs on a protection device and comprises:

[0066] The log sending module is configured to send the service protection log and the service prompt log to the analysis server; the service protection log is used to determine the aggregated access log associated with the access device and the service server; and the service prompt log is used to determine the attack time data used for log division; the access request sent by the access device to the service server carries the access domain name of the service server and the network address of the access device; the attack time data is used to divide the aggregated access log into attack type traffic log and non-attack type traffic log; the attack type traffic log and the non-attack type traffic log are used to determine the target service server attacked in the service server and the target access device initiating an illegal access request to the target service server in the access device, and obtain the illegal access data associated with the target service server and the target access device; the illegal access request carries the target access domain name of the target service server and the illegal network address of the target access device; the analysis server is configured to evaluate the attack degree of the illegal network address for the target access domain name according to the illegal access data, and send the attack degree to the protection device;

[0067] The policy determination module is configured to receive the attack degree sent by the analysis server, and determine the protection policy for the illegal network address based on the attack degree.

[0068] In an implementation, the policy determining module is further configured to perform the following operations:

[0069] If the attack degree is within the first attack range, a first type of protection policy is configured; the first type of protection policy is used to intercept all illegal access requests initiated by the target access device to the target service server;

[0070] If the attack degree is within the second attack range, an execution frequency control value for the illegal network address is obtained according to the attack degree, and a second type of protection policy is configured based on the execution frequency control value; the second type of protection policy is used to intercept illegal access requests initiated by the target access device to the target service server, which exceed the execution frequency control value;

[0071] The first type of protection policy or the second type of protection policy is used as the protection policy for the target access device.

[0072] An embodiment of the present application provides a computer device, which comprises a processor and a memory.

[0073] The processor is connected with the memory, and the memory is configured to store a computer program, and the computer program is configured to be executed by the processor, so that the computer device executes the method provided by the embodiment of the present application.

[0074] An embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program is adapted to be loaded and executed by a processor, so that a computer device with the processor executes the method provided by the embodiment of the present application.

[0075] An embodiment of the present application provides a computer program product (or a computer program), which comprises computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions, so that the computer device executes the method provided by the embodiment of the present application.

[0076] In the embodiment of the present application, the analysis server can obtain the service protection log and the service prompt log reported by the protection device, determine the aggregated access log associated with the access device and the service server based on the service protection log, and determine the attack time data for log division based on the service prompt log; wherein the access request sent by the access device to the service server carries the access domain name of the service server and the network address of the access device; further, the aggregated access log can be divided into attack type traffic log and non-attack type traffic log based on the attack time data; based on the attack type traffic log and the non-attack type traffic log, the target service server attacked in the service server and the target access device initiating illegal access request to the target service server in the access device can be determined, and the illegal access data associated with the target service server and the target access device can be obtained; wherein the illegal access request carries the target access domain name of the target service server and the illegal network address of the target access device; further, the attack degree of the illegal network address against the target access domain name can be obtained by performing attack degree evaluation on the illegal network address according to the illegal access data; the attack degree here can be used to determine the protection strategy for the illegal network address. As can be seen, the embodiment of the present application plays a key role in protecting network attacks (such as CC attacks), and by combining the service protection log and the service prompt log for analysis, the legal access and illegal access can be accurately distinguished from the attack type traffic log, and the attack degree of the illegal network address can be evaluated according to the illegal access data, and different attack degrees can be obtained to formulate different protection strategies, which is equivalent to continuously accumulating and fine-grading the illegal network address (such as illegal IP address) so as to formulate differentiated protection strategies for different illegal network addresses, rather than formulating a unified frequency control value without difference, so that the illegal network address can have high speed limiting capability when the network attack comes, thereby improving the protection effect of the network attack. BRIEF DESCRIPTION OF DRAWINGS

[0077] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0078] Figure 1 is a system architecture schematic diagram provided by the embodiment of the present application;

[0079] Figure 2 is a data interaction scene schematic diagram provided by the embodiment of the present application;

[0080] Figure 3is a flow diagram of a data processing method provided by an embodiment of the present application Figure 1 ;

[0081] Figure 4 is a flow diagram of a data processing method provided by an embodiment of the present application Figure 2 ;

[0082] Figure 5a is a schematic diagram of a unified threshold protection logic provided by an embodiment of the present application

[0083] Figure 5b is a schematic diagram of a protection logic under access reputation data provided by an embodiment of the present application

[0084] Figure 6 is a schematic diagram of an intelligent protection method and system based on access reputation data provided by an embodiment of the present application

[0085] Figure 7 is a structural schematic diagram of a data processing apparatus provided by an embodiment of the present application Figure 1 ;

[0086] Figure 8 is a structural schematic diagram of a data processing apparatus provided by an embodiment of the present application Figure 2 ;

[0087] Figure 9 is a structural schematic diagram of a computer device provided by an embodiment of the present application

[0088] Figure 10 is a structural schematic diagram of a data processing system provided by an embodiment of the present application DETAILED DESCRIPTION

[0089] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0090] Please refer to Figure 1 , Figure 1 is a schematic diagram of a system architecture provided by an embodiment of the present application. As shown in Figure 1 , the system architecture can include an access device cluster and a business server cluster. The access device cluster can include one or more access devices, and the number of access devices in the access device cluster will not be limited here, such as Figure 1As shown, the plurality of access devices in the access device cluster can specifically include: access device 200a, access device 200b, access device 200c, …, access device 200n, where the access device refers to a device for network service access, and there can be a communication connection between different access devices, for example, there is a communication connection between access device 200a and access device 200b. The service server cluster can include one or more service servers, which will not be limited to the number of service servers in the service server cluster, for example Figure 1 As shown, the plurality of service servers in the service server cluster can specifically include: service server 100a, service server 100b, …, service server 100m, where the service server refers to a server that provides specific service services (such as various website services).

[0091] Any access device in the access device cluster can have a communication connection with any service server in the service server cluster, so that each access device in the access device cluster can interact with the service server through the communication connection, for example, there is a communication connection between access device 200a and service server 100a, any access device (such as access device 200a) can initiate an access request to the service server (such as service server 100a) through the corresponding communication connection to obtain the service provided by the service server. Wherein, the above communication connection is not limited to the connection mode, which can be directly or indirectly connected through wired communication mode, or directly or indirectly connected through wireless communication mode, or through other ways, which will not be limited by the present application.

[0092] Wherein, the access device in the above access device cluster can be a terminal device, a server, a routing device, and various forms of devices, and the specific form of the access device will not be limited by the embodiments of the present application. The terminal device here can be a smart phone, a tablet computer, a notebook computer, a desktop computer, a palm computer, a mobile internet device (MID), a wearable device (such as a smart watch, a smart helmet, smart glasses, etc.), a smart computer, a smart home appliance, a smart car, and the like. Wherein, the access device and the service server can be directly or indirectly connected through wired or wireless mode, which will not be limited by the embodiments of the present application.

[0093] The service server in the service server cluster can be a standalone physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and basic cloud computing services such as big data and artificial intelligence platforms. One access device can be connected to one or more service servers, and each service server can interact with the access device connected thereto.

[0094] It should be understood that each access device in the access device cluster shown in Figure 1 The client can be installed on each access device, and when the client runs in each access device, it can interact with the service server in the service server cluster shown in Figure 1 The client can be an entertainment client (for example, a game client), a social client, an instant messaging client, a multimedia client (for example, a video client), a shopping client, an information client, a tool client, a browser, or an application program with network access function. The client can be a standalone client or an embedded sub-client integrated in a certain client (such as a video client), which is not limited herein. Taking access to a website as an example, assuming that the service server 100a is a set of one or more servers (such as data processing servers, data storage servers, etc.) for deploying a website, each access device can transmit data with the service server 100a through the installed client, for example, a certain client (such as a browser) running on the access device 200a can send an access request to the service server 100a, and the service server 100a is mainly responsible for processing business logic and data according to the access request sent by the client. When the service server 100a normally responds to the access request, the client can return the service resource requested by the client, wherein the service resource can include but is not limited to text, image, video, audio, etc. The type of service resource is not limited herein.

[0095] It can be understood that with the increasing complexity of network environment, the service server is vulnerable to various network attacks. Taking a CC attack as an example, usually, an attacker will use a large number of real source IP addresses to send a large number of access requests to the service server, which is several times the normal access, in order to cause network congestion or server resource exhaustion, so as to cause the service server to refuse to provide services for normal users, and cause abnormal response such as timeout and response delay. The present application relates to the field of passive defense of network security, in order to effectively defend against network attacks, as shown inFigure 1 The system architecture shown can also include a protection device 300a and an analysis server 300b. Among them, the protection device 300a refers to a device for defending network attacks (such as CC attacks), which is mainly responsible for performing corresponding rate limiting operations on the illegal access behavior of the access device (i.e. the target access device) initiating the attack in the aforementioned access device cluster, so as to protect the business server from network attacks. The protection device is a set of devices deployed before the business service, which can integrate software and hardware. In actual application, one or more protection devices can be deployed according to business needs to form a protection device cluster (or attack processing cluster), thereby maintaining network security. The specific form and number of the protection device 300a will not be limited in the embodiments of the present application. Among them, the analysis server 300b refers to a server corresponding to the protection device 300a for back-end analysis, which is mainly responsible for attack detection analysis and attack degree evaluation, and pushes the attack degree obtained by evaluation to the protection device 300a to assist the protection device 300a to discover and block network attacks in time. The analysis server 300b can be a separate physical server, or a server cluster (which can be called an analysis server cluster or a back-end computing cluster) or a distributed system composed of multiple physical servers, or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDNs, and big data and artificial intelligence platforms. The specific form and number of the analysis server 300b will not be limited in the embodiments of the present application. Among them, the protection device 300a and the analysis server 300b can be directly or indirectly connected through wired or wireless means to facilitate data interaction between the two, which will not be limited in the embodiments of the present application.

[0096] It can be understood that the present application provides a network attack detection and protection method and system, which can effectively defend against attacks (such as CC attacks) on the top application layer of the network protocol proposed by the International Organization for Standardization (ISO). For the convenience of subsequent understanding and explanation, some concepts related to the present application are explained here:

[0097] (1) Network address: an identifier that any networked device has, referred to as a network address. The network address of an access device can be used to find the access device. For example, the network address of an access device 200a connected to a network (such as the Internet or a local network) can be an IP address, which is a unique address that can be used to identify a device on the Internet or a local network. In addition to an IP address, the network address can also be a Media Access Control (MAC) address (also referred to as a local area network address) or other forms of addresses, which are not limited in this application. It can be understood that at different times, the same network address can indicate the same access device or different access devices, that is, the network address of the access device can change.

[0098] For ease of distinction, the network address used by an attacker (also referred to as an illegal business object) when attacking a designated service server can be referred to as an illegal network address in the subsequent embodiments of this application. The access device indicated by the illegal network address can be referred to as a target access device, which is used to initiate an abnormal access request to the designated service server.

[0099] Similarly, the network address used by a normal user (also referred to as a legal business object) when normally accessing a service server can be referred to as a legal network address. The access device indicated by the legal network address can initiate a normal access request to the designated service server.

[0100] In some cases, different normal users can also share the same egress IP address (referred to as an egress network address). The egress IP address refers to the IP address used when connecting to the public Internet from a local network. The IP address is allocated by an Internet Service Provider (ISP) and can be used to identify the source of network traffic. If the Network Address Translation (NAT) technology is used, address translation will be performed inside the NAT device, so that multiple access devices can share the same public IP address (i.e., the egress IP address). Therefore, the egress IP address can be different from the IP address inside the local network. For example, in an office network, a school, a supermarket, or a public WIFI environment, different access devices can use the same egress IP address. In this application, the network address of an access device can be a unique IP address of the access device inside the local network, a unique IP address of the access device in the Internet, or a shared egress IP address, or other forms of addresses (such as a MAC address), which are not limited in this application.

[0101] (2) Access domain name: refers to the domain name (Domain Name) of the service server, which can be simply understood as the name of the service server. Actually, the service server itself also has its own IP address (which can be called service network address). The access domain name is an alias of the service network address. The access domain name is composed of several English letters and is divided into several parts by “.”. The access domain name is more convenient to remember than the IP address. The access domain name and the service network address are mapped to each other through the domain name system (Domain Name System, DNS). When the access domain name is used to access the service server, the access domain name can be resolved into the service network address, and then the corresponding service server on the Internet or the local network can be found according to the service network address for access.

[0102] In order to distinguish, the subsequent embodiments of the present application can refer to the service server attacked by the illegal service object as a target service server, and the access domain name of the target service server can be referred to as a target access domain name. In the attack time period, the target access device indicated by the illegal network address will send a large number of illegal access requests to the target service server. In addition, the target access device can also send illegal access requests to other service servers except the target service server. If the service server is not successfully attacked, the situation does not have harmfulness to the object to be protected (i.e. the target service server), and therefore, the attack degree of the illegal network address does not need to be evaluated through the access data related to the other service servers.

[0103] It should be noted that the access device indicated by the legal network address can also request to access the target service server and send a legal access request to the target service server.

[0104] (3) Access request: a request sent by the access device to the service server, which can also be referred to as a request, and can be used to access the service provided by the service server. The access request in the present application can include a legal access request and an illegal access request. The legal access request refers to a normal or legal request, which can be used for normal business access to indicate the service server to return the corresponding business resource. The illegal access request is the opposite, which refers to an abnormal / abnormal or illegal request, and has an attack. The illegal service object can cause the server resource to be exhausted, and even crash.

[0105] (4) Resource address: used to identify the location of the requested business resource. The resource address can be a uniform resource locator (Uniform Resource Locator, URL), which can indicate the specific location and access method of the business resource on the Internet or the local network.

[0106] Based on this, Figure 1As shown, any access device in the access device cluster can send an access request to the protection device 300a, and the protection device 300a can send the access request to the analysis server 300b. The analysis server 300b can obtain access reputation data (also referred to as IP reputation data, which is network address-based security big data, and can include illegal network addresses, attack levels, data validity periods, etc.) based on the access request. The protection device 300a can determine, based on the access reputation data, whether the network address of the access request is an illegal network address. If the network address is an illegal network address, the protection device 300a can determine, based on the attack level of the illegal network address, a personalized protection policy for the illegal network address, and execute strict rate limiting on the access request from the illegal network address. If the network address is a legal network address, the protection device 300a can send the access request to the corresponding service server in the service server cluster.

[0107] Specifically, in combination with the above description of the access device cluster, the service server cluster, and the analysis server, the protection device 300a can perform the following operations. Figure 1The service servers 100a, 100b, …, 100m can be servers that provide different service services to service objects (which can be users such as individuals, enterprises, institutions, organizations, etc., including the aforementioned illegal service objects and legal service objects), i.e., the service objects can access the service servers (such as the service servers 100a, 100b, …, 100m) through relevant access devices (such as the access devices 200a, 200b, 200c, …, 200n) at any time to obtain corresponding services. Based on this, the analysis server 300b can obtain the service protection log and the service prompt log reported by the protection device 300a. The service protection log herein can also be referred to as a service access log, which is an access log file used by the protection device to record the access behavior (which can include normal access behavior and abnormal access behavior) of the access device to the service server in the daily protection process. For example, the access domain name of the relevant service server, the network address of the access device, the requested resource address, the access time, etc. can be recorded. The service prompt log is a detection log used by the protection device to record the abnormal access behavior (such as an attack) of the access device to the service server, or other possible abnormal and sudden access behavior, and to remind in the daily protection process. For example, the access domain name of the relevant service server, the network address of the access device, the attack time interval, etc. can be recorded. Therefore, based on the service protection log, the aggregated access log associated with the access device and the service server can be determined, and based on the service prompt log, the attack time data used for log division can be determined. The attack time data herein refers to data about suspected attack time, which is used to record the time interval that can be attacked. The access request sent by the access device to the service server carries the access domain name of the service server and the network address of the access device. For example, the access domain name of the service server 100a is domain name A1, the access domain name of the service server 100b is domain name A2, the access domain name of the service server 100m is domain name A3, the network address of the access device 200a is network address B1, the network address of the access device 200b is network address B2, the network address of the access device 200c is network address B3, and the network address of the access device 200n is network address B4.

[0108] Further, the analysis server 300b can divide the aggregated access log into attack type traffic log and non-attack type traffic log based on the foregoing attack time data; the attack type traffic log herein refers to traffic log about suspected network attack (such as suspected CC attack), which is used to record access requests (which can be illegal access requests) that can be abnormal access; the non-attack type traffic log refers to traffic log about non-network attack, which is used to record access requests (i.e. legal access requests) of normal access; further, based on the attack type traffic log and the non-attack type traffic log, the target service server in the service server that is attacked and the target access device in the access device that initiates illegal access requests to the target service server can be determined, and illegal access data associated with the target service server and the target access device can be obtained; the illegal access data herein refers to access data about abnormal access, which can be used to record high-trust illegal access requests; wherein the illegal access request carries the target access domain name of the target service server and the illegal network address of the target access device. For example, assuming that the service server 100a is the target service server and the access device 200a is the target access device, then the domain name A1 is the target access domain name and the network address B1 is the illegal network address. Further, the analysis server 300b can perform attack degree evaluation on the illegal network address (such as the network address B1) according to the illegal access data, to obtain the attack degree of the illegal network address against the target access domain name (such as the domain name A1); wherein the attack degree herein refers to the attack strength of the target access device (such as the access device 200a) against the target service server (such as the service server 100a), which can be used to determine the protection strategy against the illegal network address, and the subsequent protection device 300a can effectively defend against network attacks based on the protection strategy.

[0109] As can be seen, the embodiments of the present application can accurately distinguish between legal access and illegal access from the attack type traffic log by combining the service protection log and the service prompt log, and further can perform attack degree evaluation on the illegal network address according to the illegal access data, and different attack degrees obtained can formulate different protection strategies, which is equivalent to continuously accumulating and fine-grading the illegal network address, so as to formulate differentiated protection strategies for different illegal network addresses, rather than formulating a unified frequency control value without distinction, so that higher speed limiting capability can be achieved for illegal network addresses when network attacks occur, thereby improving the protection effect against network attacks.

[0110] It should be noted that the analysis server or the protection device in the embodiments of the present application can display a prompt interface or a pop-up window when obtaining the service protection log and the service prompt log (which involves data such as an accessed domain name, a network address, a regional location where an access device is located, an access time, and a feature associated with an access request). The prompt interface or the pop-up window is used to prompt that the service object is currently collecting data such as the service protection log and the service prompt log. Only after obtaining a confirmation operation of the service object on the prompt interface or the pop-up window, the related steps of data acquisition are started, otherwise the process is ended.

[0111] It can be understood that in the specific embodiments of the present application, the data related to the service protection log and the service prompt log and the like are involved. When the embodiments of the present application are applied to specific products or technologies, the permission or consent of the service object is required, and the collection, use and processing of the related data need to comply with the relevant regulations and standards of the relevant region.

[0112] For ease of understanding, further see Figure 2 , Figure 2 is a data interaction scene schematic diagram provided by an embodiment of the present application. The scene can be realized by the protection device 20a and the analysis server 20b. As shown in Figure 2 , the embodiments of the present application involve the interaction between a plurality of access devices and a plurality of service servers. The plurality of access devices can specifically include access device 21a, access device 21b and access device 21c. These access devices can be devices belonging to the same enterprise or institution, such as devices used by internal users of enterprise A. The embodiments of the present application do not limit the form of these access devices. The plurality of service servers can specifically include service server 22a, service server 22b and service server 22c. Any access device can request to access any service server, so as to perform data interaction.

[0113] Any access device can be identified by a corresponding network address, for example, the network address of access device 21a is network address D1, the network address of access device 21b is network address D2, and the network address of access device 21c is network address D3. Any service server can be identified by a corresponding access domain name, for example, the access domain name of service server 22a is domain name E1, the access domain name of service server 22b is domain name E2, and the access domain name of service server 22c is domain name E3. In order to realize data interaction, the access request sent by any access device to any service server carries the access domain name of the service server and the network address of the access device, for example, the access request sent by access device 21a to service server 22a can carry the corresponding domain name E1 and network address D1, which are respectively used to indicate the destination and source of the access request.

[0114] It can be understood that, among the above-mentioned multiple access devices, there can be a device (i.e., a target access device) that is utilized by an illegal service object to initiate a network attack (such as a CC attack), and accordingly, among the above-mentioned multiple service servers, there can be a server (i.e., a target service server) that is attacked by the target access device. In order to achieve intelligent protection and maintain service stability, the embodiments of the present application can analyze the target service server existing in the above-mentioned multiple service servers and the target access device existing in the multiple access devices in combination with relevant logs. As shown in Figure 2 The protection device 20a can send the service protection log 23a and the service prompt log 23b to the analysis server 20b, and the sending manner of the logs is not limited herein, for example, the protection device 20a can report the logs to the analysis server 20b at a regular time interval. The service protection log 23a and the service prompt log 23b are internal data of enterprise A, which can support the analysis server 20b to analyze them.

[0115] After obtaining the service protection log 23a and the service prompt log 23b reported by the protection device 20a, the analysis server 20b can determine, based on the service protection log 23a, an aggregated access log 23c associated with the aforementioned access devices (i.e., the access device 21a, the access device 21b, and the access device 21c) and service servers (i.e., the service server 22a, the service server 22b, and the service server 22c), that is, the aggregated access log 23c can be used to aggregate information related to access requests sent by the access devices to the service servers, and is a general description of the access requests sent by the access devices to the service servers. In addition, the analysis server 20b can determine, based on the service prompt log 23b, attack time data 23d for log division, which is data for representing suspected attack time analyzed from the service prompt log 23b.

[0116] Further, as shown in Figure 2 The analysis server 20b can divide the aggregated access log 23c into attack type traffic log 23e and non-attack type traffic log 23f based on the attack time data 23d, wherein, since the attack time data 23d describes suspected attack time, the result of log division based on the attack time data 23d is not very accurate, for example, log data in the aggregated access log 23c that hits the attack time data 23d can be used to determine the attack type traffic log 23e, which can be used to record access requests that may belong to illegal access requests, that is, the attack type traffic log 23e may contain information that belongs to legal access requests; log data in the aggregated access log 23c that does not hit the attack time data 23d can be used to determine the non-attack type traffic log 23f, which can be used to record legal access requests.

[0117] Further, based on the attack-type traffic log 23e and the non-attack-type traffic log 23f, the target service server in the plurality of service servers that is attacked and the target access device in the plurality of access devices that initiates the illegal access request to the target service server can be determined. For ease of understanding, it is assumed that only the access device 21a in the plurality of access devices is utilized by the illegal service object to send a large number of illegal access requests to the service server 22b, and then, taking the access device 21a and the service server 22b as an example, it can be known through analysis of the attack-type traffic log 23e and the non-attack-type traffic log 23f that the service server 22b can be the target service server, the access device 21a can be the target access device, the domain name E2 of the service server 22b can be the target access domain name of the target service server, the network address D1 of the access device 21a can be the illegal network address of the target access device, and the illegal access request sent by the access device 21a to the service server 22b carries the domain name E2 and the network address D1. Then, based on the attack-type traffic log 23e and the non-attack-type traffic log 23f, the analysis server 20b can obtain the illegal access data 23g associated with the target access device (such as the access device 21a) and the target service server (such as the service server 22b), and the illegal access data 23g can include relevant statistical information of the illegal access request sent by the access device 21a to the service server 22b in the historical attack, such as an attack time interval of the illegal access request initiated by the access device 21a to the service server 22b, a total number of the illegal access request sent, a number of the illegal access request intercepted, and the like.

[0118] Further, as Figure 2As shown, the analysis server 20b can perform attack degree evaluation on the illegal network address (such as network address D1) according to the illegal access data 23g, and obtain an attack degree 23h of the illegal network address against the target access domain name (such as access domain name E2), which can be used to determine a protection policy against the illegal network address (such as network address D1). For example, the analysis server 20b can send the attack degree 23h to the protection device 20a, so that the protection device 20a can determine the protection policy 23i against the network address D1 based on the attack degree 23h, so that when the access device (such as access device 21a) indicated by the network address D1 sends an illegal access request to the service server 22b, the protection device 20a can perform corresponding interception according to the protection policy 23i, thereby effectively reducing the frequency control transmission amount. Alternatively, the analysis server 20b can determine the protection policy 23i against the network address D1 based on the attack degree 23h, and then send the protection policy 23i to the protection device 20a to start protection. The present application does not limit the method of determining the protection policy. It should be noted that the network address of the access device may change over time, such as different users using the same access device, so the network address corresponding to the access device may be different. Therefore, the present application focuses on analyzing the illegal network address, and the protection policy is also for the illegal network address, that is, the access device indicated by the illegal network address can be considered as an abnormal access device, but the device indicated at different times may be different (that is, the target access device may change), and the protection device does not need to focus on the access device itself, but only needs to clean up illegal access requests from the illegal network address based on the protection policy.

[0119] It can be understood that for other access devices and service servers, in the case of network attacks, the protection policy can also be determined through a similar process, in which different attack degrees can determine different protection policies. For example, the target access device with a higher attack degree indicates that it has stronger attackability, and the corresponding protection policy will be more stringent. The target access device with a lower attack degree indicates that it has weaker attackability, and the corresponding protection policy will be more relaxed. That is, the protection policy can be adjusted in a timely manner according to the current attack degree, thereby enhancing the effectiveness and adaptability of the protection policy, and improving the reliability of the service.

[0120] As can be seen, the present application can formulate different protection policies according to different attack degrees, that is, different protection policies are formulated for different illegal network addresses, rather than a unified frequency control value without distinction. In this way, when a network attack occurs, it can achieve a higher speed limiting capability for illegal network addresses, thereby improving the protection effect of network attacks.

[0121] The specific implementation manner that the attack degree corresponding to the illegal network address is evaluated according to the illegal access data can be seen from the following Figures 3-6 The description in the corresponding embodiment.

[0122] Further, please refer to Figure 3 , Figure 3 is a flow diagram of a data processing method provided by the embodiment of the application Figure 1 . As shown in Figure 3 , the method can be executed by an analysis server, for example, the analysis server can be the analysis server 300b exemplified in the corresponding embodiment of the application Figure 1 . The method can specifically include the following steps S101-S104.

[0123] Step S101, obtaining the service protection log and the service prompt log reported by the protection device, determining the aggregated access log associated with the access device and the service server based on the service protection log, and determining the attack time data used for log division based on the service prompt log;

[0124] It can be understood that in a network attack, an illegal business object often uses the same bot IP (i.e., an illegal network address) to launch multiple attack behaviors, and the bot IP basically has no normal access behavior in normal times, so by analyzing the related logs (i.e., business protection logs and business prompt logs), normal access and abnormal access can be distinguished from historical attacks. Optionally, subsequent comprehensive judgment and analysis can also be considered in combination with other external information. Based on this, the analysis server can obtain the business protection logs and the business prompt logs reported by the protection device, and then can determine the aggregated access logs associated with the access device and the business server based on the business protection logs, and determine the attack time data for log division based on the business prompt logs, wherein the access request sent by the access device to the business server carries the access domain name of the business server and the network address of the access device. In the embodiments of the present application, the number of business servers can be one or more, and the number of business servers is not limited here, one business server corresponds to one or more access domain names; the number of access devices can be one or more, and the number of access devices is not limited here, one access device can correspond to one network address, and the form of the network address is not limited here. When the network address includes an egress network address (i.e., an egress IP address), one egress network address can correspond to one or more access devices, and a non-egress network address (i.e., a unique IP address inside the Internet or local network) corresponds to one access device.

[0125] The business protection log can be used to record the access request (which can include normal access request and abnormal access request) sent by the access device to the business server, and can include various protection logs, traffic logs, etc., which can be recorded and reported by the protection device. For example, in the scenario of protecting against CC attacks, the business protection log can specifically include CC protection logs (also referred to as first type of business protection log), BOT (abbreviation of Robot) protection logs (also referred to as second type of business protection log), Web Application Firewall (WAF) protection logs (also referred to as third type of business protection log), etc. These logs are obtained based on different protection features, such as CC protection logs based on CC protection features, mainly recorded when protecting against CC attacks, BOT protection logs based on BOT protection features, mainly recorded when protecting against anthropomorphic computer programs that perform data crawling, illegal transactions, etc., and WAF protection logs based on WAF protection features, mainly recorded when protecting against Web requests or responses (such as vulnerability attacks).

[0126] The service prompt log can be used to record illegal access requests or other possible abnormal access requests, and corresponding prompts can be performed, which can include various prompt logs, detection logs, etc. For example, in the scenario of protecting against CC attacks, the service prompt log can specifically include a CC traffic surge prompt log, a CC illegal IP access prompt log, etc.

[0127] The process of determining the aggregated access log based on the service protection log and determining the attack time data based on the service prompt log can be as follows: log preprocessing is performed on the service protection log, and the aggregated access log associated with the access device and the service server can be obtained. The aggregated access log can also be referred to as an aggregated log, which is mainly obtained by aggregating the entire log through specific fields (such as fields for indicating access domain names, network addresses, access times, etc.), and can contain log data associated with legal access requests and illegal access requests. In addition, attack detection data that is continuous in the time dimension can be obtained based on the service prompt log, and data preprocessing is performed on the attack detection data to obtain attack time data for log division. The attack time data is actually suspected attack time data, which can be used to indicate the possible attack time interval (which can be represented by the possible attack start time and attack end time) detected by the service prompt log. In the scenario of protecting against CC attacks, the attack time data can also be referred to as CC suspected attack time data. Therefore, the aggregated access log can be divided into attack class traffic log (i.e., suspected attack traffic log) and non-attack class traffic log (i.e., normal traffic log) based on the attack time data.

[0128] The specific process of log preprocessing of the service protection log to obtain the aggregated access log can be: performing a data cleaning operation on abnormal log data in the service protection log to obtain standard log data. It can be understood that the abnormal log data refers to abnormal data in the service protection log that does not meet the expected or log-related standards due to abnormal situations that can occur in the network environment, hardware environment, and program running, such as log misplacement, IP address error, unknown fields, etc. The abnormal log data that can occur in the service protection log is filtered, and the log data that meets the requirements (i.e., the data cleaning operation) is retained, i.e., the standard log data, which meets the log-related standards. Further, the standard log data can be aggregated based on the first type of log field to obtain aggregated access logs associated with the access device and the service server. It can be understood that due to the high concurrency of some network attacks (such as CC attacks), the standard log data is aggregated through specific fields of the log (i.e., the aforementioned first type of log field, such as fields for indicating access domain name, network address, access time, statistical time interval, etc.) to obtain aggregated access logs. The advantage of this is that it can effectively reduce the computational burden of subsequent steps and improve computational efficiency to some extent. For example, taking a CC attack as an example, the same illegal access request can be sent many times within a configured statistical time interval (i.e., a statistical time interval, such as one second of statistics or one minute of statistics, etc.), and there are many related log data. However, many features of these requests are consistent, so the log data related to these multiple requests can be aggregated into one within the statistical time interval (such as aggregating log data related to access requests from the same network address and to the same access domain name into one log data within a minute set), thereby saving computational resources.

[0129] It can be understood that when the standard log data is aggregated, different aggregations can be selected according to different address ranges, thereby obtaining aggregated access logs based on different characteristic dimensions. Optionally, different network addresses (such as IP addresses) can be selected as the dimension for aggregation, and the aggregated access logs obtained at this time can be referred to as the first type of aggregated access logs. Optionally, different geographical locations to which the network addresses belong can also be selected as the dimension for aggregation, and the aggregated access logs obtained at this time can be referred to as the second type of aggregated access logs. The two types of aggregation methods are described below.

[0130] Optionally, in the case of selecting to aggregate in the dimension of different network addresses, the first type of log field can specifically include a first network address field, a first access time field, a first access domain name field, and a first statistical time field. The first network address field can be used to indicate the network address of the access device. The first access time field can be used to indicate the access time of the access device initiating an access request to the service server, which can be represented by a timestamp or a time interval, such as the aforementioned access device 21a accessing the service server 22a at 8:27 on March 1. The first access domain name field can be used to indicate the access domain name of the service server. The first statistical time field can be used to indicate the first statistical time interval configured for the first type of aggregated access log. The specific value of the first statistical time interval is not limited by the embodiments of the present application and can be configured according to actual needs, such as being configured as one minute, indicating that the statistics is performed once a minute. Based on this, the standard log data can be subjected to a data aggregation operation based on the first network address field, the first access time field, the first access domain name field, and the first statistical time field, thereby obtaining the first type of aggregated access log associated with the access device and the service server.

[0131] For example, assuming that the aforementioned access device 21a sends 30 access requests to the service server 22a at 8:27:01 on March 1, 20 access requests to the service server 22a at 8:27:30 on March 1, and 50 access requests to the service server 22a at 8:27:45 on March 1, the protection device can report the service protection log F1 recording the 100 access requests to the analysis server. It can be understood that each of the 100 access requests has a corresponding log data in the service protection log F1, and actually many features of the 100 access requests are consistent, that is, many contents of the 100 log data are repetitive. For example, assuming that the statistical time interval configured at this time is one minute (i.e., the aforementioned first statistical time interval), in the case of one-minute statistics, it can be found that the network addresses carried in the 100 access requests are all the network address (i.e., the network address D1) of the access device 21a, indicating that they come from the same network address, the access domain names carried in the 100 access requests are all the access domain name (i.e., the domain name E1) of the service server 22a, indicating that they go to the same access domain name, and the access times corresponding to the 100 access requests are very close, all between 8:27:00-8:28:00 on March 1. Therefore, the 100 log data can be aggregated into one in the statistical time interval. At this time, a network address field (i.e., the aforementioned first network address field) can be used to indicate the network address D1, an access time field (i.e., the aforementioned first access time field) can be used to indicate the access time as 8:27:00-8:28:00 on March 1, an access domain name field (i.e., the aforementioned first access domain name field) can be used to indicate the domain name E1, and a statistical time field (i.e., the aforementioned first statistical time field) can be used to indicate the statistical time interval as one minute. In this way, the log data can be greatly simplified to save computing resources.

[0132] In addition, in the case of selecting different network addresses as the dimension for aggregation, different characteristic dimensions of the related access requests can be counted when performing the data aggregation operation on the standard log data, including but not limited to one or more of the following: the number of source ports, the number of client identifiers, the number of source identifiers, the number of identity signatures, the number of resource types, the number of compression types, the number of fingerprint marks, the number of cache marks, and one or more of the HTTP request characteristics, and rich characteristic statistics are conducive to subsequent attack degree evaluation from multiple dimensions to improve the effectiveness and adaptability of the protection strategy. For example, in the above example, the access device 21a sends 100 access requests to the service server 22a, and when the related log data is aggregated, the number of source ports and the number of client identifiers of the 100 access requests can be counted. In addition, the number of requests in different statistical dimensions (which can be referred to as the first type of request number) and the request rate (which can be referred to as the first type of request rate) can also be counted. Subsequently, other characteristics can also be counted, and the embodiments of the present application do not limit the same; these characteristics can be indicated by corresponding fields in the first type of aggregated access log.

[0133] wherein the number of source ports refers to the number of source ports. The source port refers to the port configured by the application client running on the access device to initiate an access request to the service server within the first statistical time interval; the specific type and running mode of the application client are not limited herein; the source port can be selected from the available port number range by the operating system of the access device, for example, it can be randomly selected. The source port is equivalent to an identity in the network, because different ports can be equivalent to different business objects.

[0134] Wherein, the number of client identifiers refers to the number of client identifiers. The client identifier can be used to indicate configuration information associated with the application client carried in the access request initiated by the access device to the service server in the first statistical time interval. The client identifier can be specifically indicated by a user agent field (i.e., User Agent, UA), and in the scenario where the application client is a browser, the UA can also be referred to as a browser identifier or a browser business card. The UA is a specific field sent to the service server when the application client (such as a browser) accesses the service server, and can be used to represent information related to the user identifier. The UA is part of the HTTP protocol and belongs to the components of the HTTP request header field. It is a special string that enables the service server to identify the operating system and version, central processing unit (CPU) type, browser and version, browser rendering engine, browser language, browser plug-in, and other information (i.e., configuration information associated with the application client) used by the application client. That is, the service server can generally determine the software and hardware environment used by the service object based on the UA, and then take different content strategies. These content strategies were usually used to solve compatibility problems in the early era of the Internet.

[0135] Wherein, the number of request source identifiers refers to the number of request source identifiers. The request source identifier can be used to indicate source information carried in the access request initiated by the application client to the service server in the first statistical time interval. The request source identifier can be specifically indicated by a page source field (i.e., Referer). The Referer is part of the HTTP request header field and can be used to identify the source page of the request. It provides referral information to tell the service server which page the current request is linked from, such as a www.bbb.com link in www.aaa.com. When the www.bbb.com is clicked, the header information can have source information: Referer = http: / / www.aaa.com. The Referer plays an important role in web development and network analysis. By understanding the source of the request, developers can perform statistical analysis, find traffic sources, and make appropriate processing based on this information.

[0136] Wherein, the identity signature quantity here refers to the quantity of identity signature information. The identity signature information refers to signature information used for identifying the application client in the first statistical time interval. The identity signature information here can be specifically a JA3-based identity signature. JA3 is a method for creating a client fingerprint based on a Secure Socket Layer (SSL) / Transport Layer Security (TLS) protocol. The corresponding identity signature information can be generated based on information such as an SSL / TLS version, a browser extension list, and a Cipher Suites quantity. The identity signature information is easy to generate on any platform and can be shared for dangerous prompt information. Therefore, if a website uses the JA3 algorithm, it can be approximately considered that the JA3 identity signature information is consistent in the same type of access within a period of time.

[0137] Wherein, the resource type quantity here refers to the quantity of requested resource types. The requested resource type refers to a resource type indicated by an access request initiated by the application client and acquired by the business server in the first statistical time interval. The resource type here can be specifically indicated by a request resource type field (i.e., ACCEPT). ACCEPT is part of an HTTP request header field, is a related mark of a business object, and can be used to inform the application client of a desired resource type or to parse and identify a resource type. In addition, Content-Type is used to represent a resource type actually sent by the business server (which can be referred to as a response resource type). The resource type here is represented by MIME types. According to different request contexts, the set Accept will change accordingly. The business server can select the most suitable type based on a content negotiation mechanism, set Content-Type, and return to the application client. The resource type requested by the application client to acquire can include but is not limited to any one or more of a text type, a picture type, a video type, an audio type, and a script file type.

[0138] The number of compression types refers to the number of request compression types. The request compression type refers to a compression type indicated by the application client to the service server through an access request initiated by the application client in the first statistical time interval. The compression type can be indicated by the request compression type field (i.e., ACCEPT-ENCODING), which is part of the HTTP request header field, is a language mark of a service object, and can be used to inform the application client of the content encoding method (usually a compression algorithm, i.e., a compression type) that the application client can understand. The service server can select a content encoding method proposed by the application client based on a content negotiation mechanism, set Content-Encoding, and return it to the application client. That is, ACCEPT-ENCODING can indicate whether the service resource of the current request expects compression when responding. Generally, a browser adds it to the request header by default when accessing a web page, which can reduce the amount of network transmission data and save network bandwidth.

[0139] The number of fingerprint marks refers to the number of fingerprint marks. The fingerprint mark refers to fingerprint information used to identify the application client in the first statistical time interval. The fingerprint mark can be indicated by the fingerprint mark field (i.e., tls_CIPHER). tls_CIPHER can be referred to as a TLS fingerprint. It is a feature of the application client sending ClientHello in the TLS handshake. Specifically, it can include a list of encryption suites supported by the application client and the arrangement order, a TLS version supported by the application client, a compression method, a list of TLS extensions and the arrangement order, and the like.

[0140] The number of cache marks refers to the number of cache marks. The cache mark refers to a cache instruction carried in an access request initiated by the application client to the service server in the first statistical time interval. The cache mark can be indicated by the cache mark field (i.e., Cache-Control). Cache-Control is a general message header field used in HTTP requests and responses. It is used to implement a cache mechanism by specifying a cache instruction. The cache instruction is one-way, which means that the instruction set in the request is not necessarily included in the response.

[0141] The first type of request quantity can include a first pass request quantity, a first interception request quantity, and a first request total quantity. The first pass request quantity refers to the number of access requests (denoted as C1) initiated by the access device (e.g., the access device 21a) to the service server (e.g., the service server 22a) and passed by the protection device (e.g., the protection device 20a) within the first statistical time interval. The first interception request quantity refers to the number of access requests (denoted as C2) initiated by the access device (e.g., the access device 21a) to the service server (e.g., the service server 22a) and intercepted by the protection device (e.g., the protection device 20a) within the first statistical time interval. The first request total quantity refers to the total number of access requests (denoted as C3) initiated by the access device (e.g., the access device 21a) to the service server (e.g., the service server 22a) within the first statistical time interval. It can be understood that the sum of the first pass request quantity and the first interception request quantity is equal to the first request total quantity, i.e., C1+C2=C3. For example, among the 100 access requests sent by the access device 21a to the service server 22a, 90 access requests are passed, and the remaining 10 access requests are intercepted.

[0142] The first type of request rate can include a first feature request rate and a first average request rate. The first feature request rate refers to the rate of access requests associated with a certain HTTP request feature initiated by the access device to the service server within the first statistical time interval, which can be represented by the average value of the topn feature request rate, such as the top1 feature request rate (also referred to as the first type of feature request rate), the top5 feature request rate (also referred to as the second type of feature request rate), the top20 feature request rate (also referred to as the third type of feature request rate), and the like. For example, in the foregoing example, taking the number of source ports as an example, for the 100 access requests sent by the access device 21a to the service server 22a, the top1 feature request rate can be the rate corresponding to the port with the highest request on the access device 21a, the top5 feature request rate can be the average rate corresponding to the five ports with the highest request on the access device 21a, and the top20 feature request rate can be the average rate corresponding to the 20 ports with the highest request on the access device 21a. The purpose of analyzing these topn feature request rates is to analyze the features that do not conform to normal access behavior, which is helpful for further determining illegal network addresses. The first average request rate refers to the average rate of access requests initiated by the access device to the service server within the first statistical time interval, such as the average rate of the 100 access requests sent by the access device 21a to the service server 22a. By comparing and analyzing the first feature request rate and the first average request rate, the difference between the access traffic under a certain feature dimension can be determined.

[0143] For ease of understanding, please refer to Table 1, which exemplarily shows the format of the first type of aggregated access log.

[0144] Table 1

[0145]

[0146] In Table 1, ReqTime is the first access time field, Host is the first access domain name field, Src_IP is the first network address field, Time_Intrval is the first statistical time field, Cnt_Trans is the first pass request quantity field, indicating the first pass request quantity, Cnt_Drop is the first intercept request quantity field, indicating the first intercept request quantity, X is the characteristic dimension field, indicating the characteristic dimension, Cnt is the first request total number field, indicating the first request total number, topn_Avg_Speed is the first characteristic request rate field, indicating the first characteristic request rate, and optionally, topn_Avg_Speed can include one or more of top1_Avg_Speed (top1 characteristic request rate), top5_Avg_Speed (top5 characteristic request rate), and top20_Avg_Speed (top20 characteristic request rate), and Avg_Speed is the first average request rate field, indicating the first average request rate.

[0147] X can include the following characteristic dimensions: SrcPort_Cnt, UA_Cnt, REFER_Cnt, JA3_Cnt, ACCEPT_Cnt, ACCEPT_ENCODING_Cnt, TLS_Cnt, and CacheControl_Cnt, wherein SrcPort_Cnt is the source port quantity field, indicating the number of independent source ports, UA_Cnt is the client identifier quantity field, indicating the number of independent UAs, REFER_Cnt is the source identifier quantity field, indicating the number of independent Referers, JA3_Cnt is the identity signature quantity field, indicating the number of independent JA3s, ACCEPT_Cnt is the resource type quantity field, indicating the number of independent ACCEPTs, ACCEPT_ENCODING_Cnt is the compression type quantity field, indicating the number of independent Accept-Encodins, TLS_Cnt is the fingerprint flag quantity field, indicating the number of independent tls_ciphers, and CacheControl_Cnt is the cache flag quantity field, indicating the number of independent Cache-Controls.

[0148] Optionally, in the case of selecting the different regional locations where the network addresses belong to as the dimension for aggregation, the first type of log field can specifically include a regional distribution field, a second access time field, a second access domain name field, and a second statistical time field. The regional distribution field can be used to indicate the regional location (i.e., geographical location information) of the access device, for example, if the access device 21a and the access device 21b are both located in a region W, the regional distribution field can indicate the region W. The second access time field can be used to indicate the access time of the access device located in the aforementioned regional location to initiate an access request to the service server, which can be represented by a timestamp or a time interval, for example, the access device 21a and the access device 21b located in the region W both access the service server 22a at 8:10 on March 1st. The second access domain name field can be used to indicate the access domain name of the service server, for example, the access domain name of the aforementioned service server 22a is domain name E1. The second statistical time field can be used to indicate the second statistical time interval configured for the second type of aggregated access log. The specific value of the second statistical time interval is not limited by the embodiments of the present application and can be configured according to actual needs, for example, it can be configured as one minute, indicating that it is counted once a minute. Based on this, the standard log data can be subjected to a data aggregation operation based on the regional distribution field, the second access time field, the second access domain name field, and the second statistical time field, thereby obtaining the second type of aggregated access log associated with the access device and the service server.

[0149] For example, assuming that the aforementioned access device 21a located in the region W sends 30 access requests to the service server 22a at 8:10:01 on March 1, and the access device 21b located in the same region W sends 20 access requests to the service server 22a at 8:10:20 on March 1, the protection device can report the service protection log F2 recording the 50 access requests to the analysis server. It can be understood that each of the 50 access requests has a corresponding log data in the service protection log F2, and actually many features of the 50 access requests are consistent, that is, many contents of the 50 log data are repetitive. For example, assuming that the configured statistical time interval is one minute (i.e., the aforementioned second statistical time interval), in the case of one-minute statistics, it can be found that the network addresses carried in the 50 access requests all correspond to the same geographical location (i.e., the region W), indicating that they come from the same region, the access domain names carried in the 50 access requests are all the access domain name of the service server 22a (i.e., the domain name E1), indicating that they are sent to the same access domain name, and the access times corresponding to the 50 access requests are very close, all between 8:10:00-8:11:00 on March 1, and therefore the 50 log data can be aggregated into one in the statistical time interval. At this time, the region W can be indicated by a geographical distribution field, the access time of 8:10:00-8:11:00 on March 1 can be indicated by an access time field (i.e., the aforementioned second access time field), the domain name E1 can be indicated by an access domain name field (i.e., the aforementioned second access domain name field), and the statistical time interval of one minute can be indicated by a statistical time field (i.e., the aforementioned second statistical time field), so that the log data can be greatly simplified to save computing resources.

[0150] In addition, in the case of selecting different geographical locations to which network addresses belong as the dimension for aggregation, the number of related access requests (which can be referred to as a second type of request number), the request rate (which can be referred to as a second type of request rate), and the like can be counted when the standard log data is subjected to the data aggregation operation. Other features can also be counted, which are not limited by the embodiments of the present application; these features can be indicated by corresponding fields in the second type of aggregated access log.

[0151] It can be understood that the features counted by the second type of aggregated access log will contain log data corresponding to all relevant access devices in a certain region, and the features counted by the first type of aggregated access log contain log data corresponding to an access device indicated by a network address. Since the network address (such as an IP address) and the geographical location (such as GEOIP) are strongly bound, the second type of aggregated access log will not count the relevant features with the network address as the dimension (that is, it does not contain the aforementioned HTTP request features). It can be understood that it is a special collection of the geographical attribute in the IP attribute. Any network address uniquely corresponds to a geographical location. The embodiments of the present application can support the use of lists, databases, and other forms to store the mapping relationship between network addresses and geographical locations. When needed, the geographical location to network address conversion can be realized based on the stored mapping relationship to obtain data related to a specific network address.

[0152] In the formula, the second type of request quantity can specifically include a second pass request quantity, a second intercepted request quantity, and a second request total quantity. The second pass request quantity refers to the number of access requests (which can be represented by C4) initiated by the access device (such as the access device 21a and the access device 21b) to the service server (such as the service server 22a) and passed by the protection device (such as the protection device 20a) in the second statistical time interval. The second intercepted request quantity refers to the number of access requests (which can be represented by C5) initiated by the access device (such as the access device 21a and the access device 21b) to the service server (such as the service server 22a) and intercepted by the protection device (such as the protection device 20a) in the second statistical time interval. The second request total quantity field refers to the total number of access requests (which can be represented by C6) initiated by the access device (such as the access device 21a and the access device 21b) to the service server (such as the service server 22a) in the second statistical time interval. It can be understood that the sum of the second pass request quantity and the second intercepted request quantity is equal to the second request total quantity, that is, C4+C5=C6. For example, of the 50 access requests sent by the access device 21a and the access device 21b to the service server 22a, 45 access requests are passed, and the remaining 5 access requests are intercepted.

[0153] The second type of request rate can include a second feature request rate and a second average request rate. The second feature request rate refers to the average rate of access requests initiated by access devices in target geographical locations to the service server within the second statistical time interval. The target geographical locations refer to the top N geographical locations with the most requests, where N is a positive integer. The specific value of N is not limited and can be selected according to actual conditions. That is, the average value of the request rate of the top n feature (i.e., the aforementioned N geographical locations) can also be used to represent it, such as the top 1 feature request rate (also referred to as the fourth type of feature request rate), the top 5 feature request rate (also referred to as the fifth type of feature request rate), the top 20 feature request rate (also referred to as the sixth type of feature request rate), etc. The top 1 feature request rate can be the rate corresponding to the top one geographical location (such as the aforementioned area W, i.e., the aforementioned N = 1), the top 5 feature request rate can be the average rate corresponding to the top 5 geographical locations (i.e., the aforementioned N = 5), and the top 20 feature request rate can be the average rate corresponding to the top 20 geographical locations (i.e., the aforementioned N = 20). The analysis of these top n feature request rates can analyze features that do not conform to normal access behavior, which can help to further determine illegal network addresses. The second average request rate refers to the average rate of access requests initiated by access devices in specified geographical locations to the service server within the second statistical time interval. For example, in the aforementioned example, the average rate of 50 access requests sent by the access device 21a and the access device 21b in the area W to the service server 22a. The comparison and analysis of the second feature request rate and the second average request rate can help to determine the difference between access traffic under specific feature dimensions.

[0154] For ease of understanding, please refer to Table 2, which exemplarily shows the format of the second type of aggregated access log.

[0155] Table 2

[0156]

[0157]

[0158] In Table 2, ReqTime is the aforementioned second access time field, Host is the aforementioned second access domain name field, GEOIP is the aforementioned geographical distribution field, Time_Intrval is the aforementioned second statistical time field, Cnt_Trans is the second released request quantity field, used to indicate the aforementioned second released request quantity, Cnt_Drop is the second intercepted request quantity field, used to indicate the aforementioned second intercepted request quantity, Cnt is the second total request quantity field, used to indicate the aforementioned second total request quantity, topn_Avg_Speed is the second characteristic request rate field, used to indicate the aforementioned second characteristic request rate, which can involve statistics on the number of GEOIPs, Avg_Speed is the second average request rate field, used to indicate the aforementioned second average request rate.

[0159] In addition, it can be understood that for different types of service protection logs, aggregation can be performed based on different characteristic dimensions, such as for a CC protection log, the characteristic dimension field can be used to indicate the relevant statistical value of the CC characteristic (also referred to as the first type of request characteristic); for a BOT protection log, the characteristic dimension field can be used to indicate the relevant statistical value of the BOT characteristic (also referred to as the second type of request characteristic); for a WAF protection log, the characteristic dimension field can be used to indicate the relevant statistical value of the WAF characteristic (also referred to as the third type of request characteristic), which can be seen from the above description of the characteristic dimension, and specific characteristics will not be listed one by one here.

[0160] In an implementation, the service prompt log can include multiple types of prompt logs, such as a traffic surge prompt log and an illegal address access prompt log, and can also include other prompt logs, which are not limited; wherein the traffic surge prompt log can be used to record traffic surge related access requests, which can be a CC traffic surge prompt log in particular; the illegal address access prompt log can be used to record illegal access requests from known inventory of illegal network addresses (such as illegal IP addresses), which can be a CC illegal IP access prompt log in particular; then based on the service prompt log, attack detection data that is continuous in the time dimension is obtained, and the specific process of attack time data is that: the traffic surge prompt log and the illegal address access prompt log are processed continuously, the first attack detection data corresponding to the traffic surge prompt log and the second attack detection data corresponding to the illegal address access prompt log can be obtained, and the first attack detection data and the second attack detection data are taken as attack detection data that is continuous in the time dimension; wherein the continuous processing here refers to data processing on the log data obtained in the detection time interval, which can be set according to needs; the time dimension refers to the time in the detection time interval; further, the first attack detection data and the second attack detection data in the attack detection data can be preprocessed, so as to obtain attack time data used for log division.

[0161] It can be understood that the traffic surge prompt log and the illegal address access prompt log are both detection logs of a specified time granularity, and the time granularity here can be set according to actual conditions to ensure the accuracy of detection, for example, it can be set to 10 seconds, and there is no limitation on this. For example, there is a detection at 5:04:10 on a certain day, and there is another detection at 5:04:20, and the data detected by the two detections is discrete and discontinuous in the time dimension, but in fact continuous data is needed in the case of detecting attacks, so the two discrete detection logs need to be processed to obtain continuous first attack detection data and second attack detection data in the time dimension, and there cannot be a blank in the undetected intermediate period (such as 5:04:10-5:04:20). The specific process of continuously processing the traffic surge prompt log and the illegal address access prompt log can be: obtaining a first detection time interval configured for the traffic surge prompt log, and performing merging processing on log data in the traffic surge prompt log located in the first detection time interval, so that the first attack detection data corresponding to the traffic surge prompt log can be obtained. The first detection time interval here can be determined by prepositioning a first time length (represented by time length t1, such as 300 seconds) before the attack start time detected by the traffic surge prompt log and postpositioning a second time length (represented by time length t2, such as 300 seconds), and the specific values of the first time length and the second time length are not limited here and can be set according to actual conditions; the log data located in the first detection time interval is merged and processed, which can be understood as that the log data located in the first detection time interval has a certain continuity in the time dimension (including log data detected at multiple times), so these log data can be merged to obtain the first attack detection data. Similarly, a second detection time interval configured for the illegal address access prompt log is obtained, and merging processing is performed on log data in the illegal address access prompt log located in the second detection time interval, so that the second attack detection data corresponding to the illegal address access prompt log can be obtained; the second detection time interval here can be determined by prepositioning a third time length (represented by time length t3, such as 300 seconds) before the attack start time detected by the illegal address access prompt log and postpositioning a fourth time length (represented by time length t4, such as 300 seconds), and the specific values of the third time length and the fourth time length are not limited here and can be set according to actual conditions; the log data located in the second detection time interval is merged and processed, which can be understood as that the log data located in the second detection time interval has a certain continuity in the time dimension (including log data detected at multiple times), so these log data can be merged to obtain the second attack detection data.

[0162] The first attack detection data can be used to indicate information related to traffic surge, and can specifically include a third access domain name field, a second network address field, a first attack time field, and a first confidence field. The third access domain name field can be used to indicate an access domain name of a first service server in which traffic surge exists. Traffic surge refers to a sudden increase in access traffic at a certain time or time period compared to normal access traffic. For example, a service server normally has a traffic of 500 qps (query per second), but suddenly has a traffic of 10 wqps one day, which is a traffic surge. The second network address field can be used to indicate a network address of a first access device that initiates an access request to the first service server in which traffic surge exists. The first attack time field can be used to indicate a first attack time interval associated with the first service server and the first access device, which is determined by a first attack start time and a first attack end time. Within the first attack time interval, the first access device can initiate an attack on the first service server or normal service access. The first confidence field can be used to indicate a first confidence of the first access device initiating an attack on the first service server within the first attack time interval. In other words, the first confidence can be used to represent the possibility of an access request sent by the first access device to the first service server being an illegal access request, and can be used to determine whether related data needs to be included in an attack prompt as subsequent attack time data.

[0163] The second attack detection data can be used to indicate information related to illegal access, and can specifically include a fourth access domain name field, a third network address field, a second attack time field, and a second confidence level field. The fourth access domain name field can be used to indicate the access domain name of the second service server that is attacked in the service server. The third network address field can be used to indicate the network address of the second access device that initiates an illegal access request to the second service server in the access device. The network address of the second access device can be understood as a known inventory of illegal network addresses, such as illegal IP addresses in an existing address blacklist. The second attack time field can be used to indicate a second attack time interval associated with the second service server and the second access device, which is determined by a second attack start time and a second attack end time. Within the second attack time interval, the second access device initiates an attack on the second service server. The second confidence level field can be used to indicate the second confidence level of the second access device initiating an attack on the second service server within the second attack time interval. In other words, the second confidence level can be used to represent the possibility of the access request sent by the second access device to the second service server being an illegal access request, and can be used to determine whether to include relevant data in the attack prompt as subsequent attack time data.

[0164] For ease of understanding, please refer to Table 3, which exemplarily shows the format of attack detection data, which is applicable to the first attack detection data and the second attack detection data.

[0165] Table 3

[0166]

[0167] In Table 3, Host can represent the third access domain name field / the fourth access domain name field, Src_IP can represent the second network address field / the third network address field, Attack_Start_Time can represent the first attack start time / the second attack start time, Attack_End_Time can represent the first attack end time / the second attack end time, and Score can represent the first confidence level field / the second confidence level field.

[0168] It can be understood that the above Tables 1, 2 and 3 show the format of data standardization. The advantage of standardization is that different log data can be processed and connected, and after connection, they can be analyzed and processed together, which is beneficial to improving the data processing efficiency of subsequent steps.

[0169] It can be understood that the traffic surge prompt log only focuses on the scene of coping with traffic surge, but there may be traffic surge in non-attack scenes (such as cut-in scenes), for example, before the new game is put on line, the traffic of the relevant business server may be very small, but on the day when the new game is put on line, the traffic will be very large, which is actually a normal situation, but it is difficult to distinguish this situation from abnormal traffic surge in the traffic surge prompt log; the illegal address access prompt log is for the scene of a large number of access devices identified by known illegal network addresses, which has a higher probability of illegal access, but there will be some problems of inaccurate identification of non-stored illegal network addresses, if only one kind of log is used alone, there will be respective defects and inadaptation, therefore, the two kinds of logs need to be aggregated for complementation, so as to improve the accuracy of illegal access detection. That is to say, the traffic surge prompt log is easy to misjudge for the cut-in scene, and the illegal address access prompt log is not good for the newly added illegal network address, so the attack detection data corresponding to the two prompt logs needs to be aggregated to obtain the attack time data.

[0170] Based on this, the specific process of data preprocessing of the first attack detection data and the second attack detection data to obtain attack time data can be: obtaining a first attack time interval associated with the first attack detection data and a second attack time interval associated with the second attack detection data, based on the first attack time interval and the second attack time interval, the first attack detection data and the second attack detection data are aggregated to obtain aggregated detection data; wherein the similar attack time intervals of the two logs can be combined, and the data therein can be aggregated based on the same field, for example, assuming that the attack time interval Q1 contained in the first attack time interval is determined by the attack start time ST1 (belonging to the first attack start time) and the attack end time ET1 (belonging to the first attack end time), the attack time interval Q2 contained in the second attack time interval is determined by the attack start time ST2 (belonging to the second attack start time) and the attack end time ET2 (belonging to the second attack end time), when the time difference between the attack start time ST1 and the attack start time ST2 is less than the set time difference threshold, and the time difference between the attack end time ET1 and the attack end time ET2 is less than the set time difference threshold, it can be determined that the attack time interval Q1 and the attack time interval Q2 are similar attack time intervals, at this time, the two similar attack time intervals can be combined (to obtain a new attack time interval, which can be called an aggregated attack time interval), that is, the first attack detection data located in the attack time interval Q1 and the second attack detection data located in the attack time interval Q2 are aggregated based on the field to obtain the aggregated detection data. The confidence included in the aggregated detection data is determined by the first confidence corresponding to the first attack detection data and the second confidence corresponding to the second attack detection data, and the specific calculation method can be designed as required, for example, the first confidence (such as 0.1) and the second confidence (such as 0.5) can be weighted and averaged, and the weighted average confidence (such as 0.3) can be used as the confidence in the aggregated detection data.Further, for the inconsistent places of the two logs, the relevant confidence (such as the aforementioned weighted average confidence) can be used for judgment; wherein, the data with the confidence greater than the attack confidence threshold can be obtained from the aggregated detection data, and the obtained data is taken as the first type of attack time data; the specific value of the attack confidence threshold is not limited here, and can be set as needed, such as 0.7; for the high confidence prompt, such as the data (including the corresponding network address) with the confidence greater than 0.7, is included in the attack prompt; in addition, the data with the confidence less than or equal to the attack confidence threshold can be obtained from the aggregated detection data, and when the obtained data meets the attack screening condition, the data meeting the attack screening condition in the aggregated detection data is taken as the second type of attack time data; the attack screening condition herein refers to the rule for screening the attack time data, which can be configured according to the actual situation, and the specific content of the attack screening condition is not limited here; for example, for the low confidence prompt, such as the data with the confidence less than 0.7, is not included in the attack prompt, but it can be found that it belongs to illegal attack through the attack screening condition (or manual review), and at this time, the data meeting the attack screening condition in the aggregated detection data is taken as the second type of attack time data. In addition, the business prompt rule related to the business prompt log (that is, the rule for indicating how the business prompt log processes data and prompts) can be updated accordingly, such as adjusting the attack confidence threshold, or adjusting the confidence judgment method of the traffic surge prompt log and the illegal address access prompt log respectively. Finally, the first type of attack time data and the second type of attack time data can be taken as attack time data for log division, and the attack time data is suspected attack time data, and the attack time interval indicated by the attack time data is not necessarily real and accurate, and there is a certain confidence. The specific format of the attack time data can be referred to in the above table 3, and will not be described here. The attack time interval indicated by the attack time data is determined by the aforementioned aggregated attack time interval.

[0171] As known from the above, the embodiments of the present application combine the similar attack time intervals of the two logs, for the inconsistent places, the weighted average confidence can be used for judgment, for the confidence greater than the attack confidence threshold (such as 0.7), is included in the attack prompt, and for the low confidence prompt, the attack screening condition or manual review can be used to screen and update the prompt rule, and finally form the suspected attack time data.

[0172] Step S102, dividing the aggregated access log into attack type traffic log and non-attack type traffic log based on attack time data;

[0173] It can be understood that after the attack time data and the aggregated access log are obtained through the above step S101, in order to analyze the information related to the illegal access request, the analysis server can divide the aggregated access log into attack type traffic log and non-attack type traffic log based on the attack time data, that is, the aggregated access log is layered by the suspected attack time data, and the initial attack log data and the initial business log data of suspected abnormal access obtained after layering are aggregated respectively to obtain the attack type traffic log and the non-attack type traffic log.

[0174] Specifically, the analysis server can take the log data in the aggregated access log that hits the attack time data as initial attack log data, and can perform a data aggregation operation on the initial attack log data based on the second type log field to obtain the attack type traffic log. The log data that hits the attack time data refers to log data in the aggregated access log whose access time is located in the suspected attack time interval indicated by the attack time data, which may be log data related to illegal access requests, and is taken as initial attack log data, that is, the initial attack log data is log data recording suspected abnormal traffic or suspected attack traffic log data. Based on a specific field (i.e., the second type log field, such as a field for indicating access domain name, network address, attack time interval, etc.) to aggregate the initial attack log data, a standardized attack type traffic log can be obtained. The attack type traffic log here can be used to record suspected attack access traffic, so the access requests contained therein may be illegal access requests or legal access requests.

[0175] The second type log field can specifically include a fifth access domain name field, a fourth network address field, and a third attack time field. The fifth access domain name field can be used to indicate the access domain name of the target business server in the business server that is attacked. The fourth network address field can be used to indicate the network address of the third access device in the access device that accesses the target business server abnormally, that is, the third access device may initiate an attack on the target business server, so the third access device will include the target access device that initiates an illegal access request to the target business server. The third attack time field can be used to indicate a suspected third attack time interval associated with the target business server and the third access device, which is determined by a third attack start time and a third attack end time. Within the third attack time interval, the third access device may initiate an attack on the target business server. Based on this, the initial attack log data can be aggregated based on the fifth access domain name field, the fourth network address field, and the third attack time field, so as to obtain the attack type traffic log.

[0176] For example, assuming that the current detected suspected attack time interval (i.e., the aforementioned third attack time interval) is 10:05-10:10 on March 2, the aforementioned service server 22a is attacked in the attack time interval, and it is detected that the access device 21a sends 20 access requests to the service server 22a in the attack time interval, it can be suspected that the 20 access requests sent by the access device 21a to the service server 22a may belong to illegal access requests. Based on this, the initial attack log data F3 obtained at present contains log data corresponding to each of the 20 access requests, and it can be found that the access domain name and network address carried in the 20 access requests are the same, so the log data corresponding to the 20 access requests can be aggregated in the attack time interval. At this time, the domain name E1 of the service server 22a can be indicated by an access domain name field (i.e., the aforementioned fifth access domain name field), the network address D1 of the access device 21a can be indicated by a network address field (i.e., the aforementioned fourth network address field), and the suspected attack time interval 10:05-10:10 on March 2 can be indicated by an attack time field (i.e., the aforementioned third attack time field).

[0177] In addition, when performing the data aggregation operation on the initial attack log data, the number of related access requests in different statistical dimensions (which can be referred to as a third type of request quantity) and other characteristics can be counted. Subsequently, other characteristics can also be counted, and the embodiments of the present application do not limit this. These characteristics will be indicated by corresponding fields in the attack type traffic log. The third type of request quantity here can specifically include a third request total number and a third intercepted request quantity. The third request total number refers to the total number of access requests initiated by the third access device (such as the aforementioned access device 21a) to the target service server (such as the aforementioned service server 22a) in the third attack time interval. The third intercepted request quantity refers to the number of access requests initiated by the third access device (such as the aforementioned access device 21a) to the target service server (such as the aforementioned service server 22a) and intercepted by the protection device (such as the aforementioned protection device 20a) in the third attack time interval. For example, in the aforementioned example, the access device 21a sent a total of 20 access requests to the service server 22a from 10:05 to 10:10 on March 2, of which 10 access requests were intercepted.

[0178] For ease of understanding, please refer to Table 4, which exemplarily shows the format of the attack type traffic log.

[0179] Table 4

[0180] Attribute Meaning Attribute Meaning Host Access domain name Attack_Start_Time Attack start time Src_IP Source IP address Attack_End_Time Attack end time Cnt Total number of requests Drop_Cnt Number of intercepted attack requests

[0181] In Table 4, Host is the aforementioned fifth access domain name field, Src_IP is the aforementioned fourth network address field, Attack_Start_Time and Attack_End_Time belong to the aforementioned third attack time field, Attack_Start_Time is used to indicate the aforementioned third attack start time, Attack_End_Time is used to indicate the aforementioned third attack end time, Cnt is the third request total number field, which is used to indicate the aforementioned third request total number, and Drop_Cnt is the third intercepted request quantity field, which is used to indicate the aforementioned third intercepted request quantity.

[0182] In addition, the analysis server can take log data in which the attack time data is not hit in the aggregated access log as initial service log data, and can perform a data aggregation operation on the initial service log data based on the third type of log field to obtain non-attack type traffic log; wherein the log data in which the attack time data is not hit refers to log data in which the access time in the aggregated access log is located outside the suspected attack time interval indicated by the attack time data, and is log data related to a legal access request, and is taken as initial service log data, that is, the initial service log data is log data recording normal traffic (i.e., normal traffic log data); based on a specific field (i.e., the third type of log field, such as a field used to indicate the number of access domain names, network addresses, access dates, etc.) to aggregate the initial service log data, that is, to obtain standardized non-attack type traffic log, and the non-attack type traffic log here can be used to record normal access traffic, and therefore the access requests contained therein belong to legal access requests.

[0183] The third type of log field can specifically include an access domain name quantity field, a fifth network address field, and a third access time field; the access domain name quantity field can be used to indicate the number of access domain names of the third service server in the service server that is normally accessed, and it can be understood that the third service server that is normally accessed can also be attacked at the same time (i.e., the third service server can include a target service server), and no limitation is made in this regard; the fifth network address field can be used to indicate the network address of the fourth access device that normally accesses the third service server in the access device, that is, the access request initiated by the fourth access device to the third service server belongs to a legal access request; and the third access time field can be used to indicate the access date of the fourth access device to the third service server to initiate a legal access request. Based on this, the initial service log data can be subjected to a data aggregation operation based on the access domain name quantity field, the fifth network address field, and the third access time field, thereby obtaining the non-attack type traffic log.

[0184] For example, in combination with Figure 2, assuming that the service servers subjected to normal access include the service server 22a and the service server 22b, and on March 2, the access device 21a sends 10 legitimate access requests to the service server 22a and 15 legitimate access requests to the service server 22b. Based on this, the initial service log data F4 currently obtained contains log data corresponding to each of the 25 legitimate access requests, and it can be found that the access domain names carried in the 25 legitimate access requests are different, but the network addresses are the same, and they are all sent on March 2, indicating that the access device 21a can normally access multiple service servers, and therefore the log data corresponding to the 25 legitimate access requests can be aggregated. At this time, the number of domain names normally accessed by the access device 21a (which is 2 at this time) can be indicated by the access domain name number field, the network address D1 of the access device 21a can be indicated by one network address field, and the access date of the access device 21a normally accessing the two service servers is March 2, which can be indicated by one access time field.

[0185] In addition, when performing the data aggregation operation on the initial service log data, the number of related access requests under different statistical dimensions (which can be referred to as the fourth request quantity) and other characteristics can be counted. Subsequently, other characteristics can also be counted, and embodiments of the present application do not limit this; these characteristics will be indicated by corresponding fields in the non-attack type traffic log. The fourth request quantity specifically can include a fourth request total number, a fourth intercepted request quantity, and an intercepted domain name number; the fourth request total number refers to the total number of legitimate access requests initiated by the fourth access device to the third service server within the access date; the fourth intercepted request quantity refers to the number of legitimate access requests initiated by the fourth access device to the third service server and intercepted by the protection device within the non-attack time interval of the access date; the non-attack time interval here refers to other time except the attack time interval in the access date; the intercepted domain name number refers to the number of intercepted domain names counted within the non-attack time interval; the intercepted domain name here is used to indicate the server determined in the third service server that intercepts the legitimate access request of the fourth access device by the protection device. For example, in the foregoing example, the access device 21a sends 10 legitimate access requests to the service server 22a and 15 legitimate access requests to the service server 22b on March 2, and the total number of requests (i.e., the fourth request total number) counted is 25. Assuming that the non-attack time interval is 10:00-23:00 on March 2, the protection device 20a intercepts two of the 25 access requests within the non-attack time interval, and the access domain names carried in the two intercepted access requests are both the domain name E2 of the service server 22b. At this time, the number of intercepted requests in the non-attack time (i.e., the fourth intercepted request quantity) is 2, and the number of intercepted domain names in the non-attack time (i.e., the intercepted domain name number) is 1.

[0186] It is understandable that a normal user can visit many websites. During the non-attack time period, if a website requires the user to enter a verification code, the web page loads slowly or cannot be displayed, or times out, it is equivalent to intercepting the user's legitimate access request. Based on this, the number of intercepted requests during the non-attack time period can be counted (through the aforementioned fourth number of intercepted requests); during the non-attack time period, if the user visits a large number of domain names, but is only intercepted when accessing a website indicated by a certain access domain name, it means that this may be an occasional behavior, but if it is found that the user is intercepted when accessing websites indicated by a large number of access domain names, it means that the user is very suspicious and may be on the blacklist of many websites. Based on this, the number of intercepted domain names during the non-attack time period can be counted (through the aforementioned number of intercepted domain names); by counting the number of intercepted requests during the non-attack time period and the number of intercepted domain names during the non-attack time period, it is helpful to characterize normal traffic, thereby improving the accuracy of distinguishing between legitimate access and illegal access.

[0187] For easier understanding, see Table 5, which illustrates the format of non-attack traffic logs.

[0188] Table 5

[0189]

[0190] In Table 5, Host_Num is the aforementioned access domain name quantity field, Date is the aforementioned third access time field, Src_IP is the aforementioned fifth network address field, Cnt is the fourth request total number field, used to indicate the aforementioned fourth request total number, Drop_Cnt is the fourth intercepted request quantity field, used to indicate the aforementioned fourth intercepted request quantity, and Drop_Host_Num is the intercepted domain name quantity field, used to indicate the aforementioned intercepted domain name quantity.

[0191] Step S103: Based on the attack traffic log and the non-attack traffic log, determine the target business server under attack among the business servers, and the target access device that initiates an illegal access request to the target business server among the access devices, and obtain illegal access data associated with the target business server and the target access device;

[0192] It is understood that the analysis server can determine the target business server under attack among the business servers, and the target access device that initiated the illegal access request to the target business server among the access devices, based on the attack traffic logs and non-attack traffic logs, and obtain illegal access data associated with the target business server and the target access device. The illegal access data here refers to data associated with the illegal access request. The illegal access request carries the target access domain name of the target business server and the illegal network address of the target access device.

[0193] As can be known from the foregoing, the attack-type traffic log can contain data associated with both illegal access requests and legal access requests, and therefore it is necessary to separate, from the attack-type traffic log, log data associated only with illegal access requests as illegal access data about highly trusted illegal network addresses, for subsequent attack degree evaluation, using the non-attack-type traffic log.

[0194] Specifically, the analysis server can take the access domain name contained in the attack-class traffic log as a target access domain name (i.e., an attacked domain name), take the server indicated by the target access domain name as a target service server of the service server that is attacked, and further determine a legitimate access condition corresponding to the target access domain name based on log data associated with the target access domain name in the non-attack-class traffic log. The legitimate access condition refers to relevant information used to depict the historical normal access frequency of the target access domain name, which can be obtained by comparing abnormal access data and normal access data, that is, the normal access data of the target service server when it is not attacked (i.e., the log data associated with the target access domain name in the non-attack-class traffic log) can be used to describe the normal traffic pattern (i.e., the legitimate access condition) thereof, so that the log data about normal access (i.e., the log data associated with the legitimate access request) contained in the attack-class traffic log can be filtered out, and the log data about abnormal access (i.e., the log data associated with the illegal access request) remaining after the data is removed is the log data about abnormal access. Based on this, log data that does not meet the above legitimate access condition can be obtained from the attack-class traffic log as initial illegal data, which is equivalent to extracting log data that does not meet normal access from the attack-class traffic log as the obtained data about suspected abnormal access (i.e., initial illegal data), and the data format is consistent with the format of the attack-class traffic log. For specific formats, refer to Table 4 above. Further, when determining the trusted network address associated with the target access domain name based on the legitimate access condition, the illegal network address can be obtained from the network address contained in the initial illegal data based on the trusted network address. At this time, the illegal network address obtained is highly trusted, and therefore the device indicated by the illegal network address can be taken as a target access device that initiates an illegal access request to the target service server among the access devices. The trusted network address is used to indicate a device in the access device that is trusted by the target service server, which is equivalent to an address white list (such as containing whitelisted IP addresses) configured for the target service server, that is, the access device indicated by the trusted network address can be considered as a legitimate access request when sending an access request to the target service server, and the protection device can directly pass it. Further, the data associated with the illegal network address obtained from the initial illegal data can be taken as illegal access data associated with the target service server and the target access device, that is, the data associated with the trusted network address is data about normal access (such as whitelisted IP data), and therefore, after removing this part of data from the initial illegal data about suspected abnormal access, the illegal access data about abnormal access can be obtained.

[0195] The specific process of determining the legal access condition corresponding to the target access domain name based on the log data associated with the target access domain name in the non-attack type traffic log can be: performing fluctuation analysis on the log data associated with the target access domain name in the non-attack type traffic log to obtain a fluctuation analysis result for the target access domain name, and obtaining a first analysis data source from the non-attack type traffic log based on the fluctuation analysis result. The purpose of the fluctuation analysis is to determine whether the access traffic for the target access domain name fluctuates by analyzing the historical access data of the attacked domain name, that is, the access traffic for the target access domain name is stable or fluctuates, which will affect the selection of the first analysis data source. At the same time, the log data associated with the target access domain name in the non-attack type traffic log can be analyzed for access frequency to obtain a high-frequency access range for the target access domain name, and the log data in the non-attack type traffic log with an access frequency in the high-frequency access range is taken as a second analysis data source. The purpose of the access frequency analysis is to obtain the data of the domain name in a specified access frequency range in the IP level dimension by analyzing the historical access data of the attacked domain name. The specific range of the high-frequency access range is not limited, and can be set according to actual needs, for example, P95 to P9995, for example, the access frequencies of different IP addresses for the target access domain name are sorted from small to large, and the data with an access frequency ranking from 95% to 99.95% is taken as the second analysis data source. It can be understood that the analysis data source (including the first analysis data source and the second analysis data source) in the embodiment of the application is obtained from the non-attack type traffic log, that is, the historical normal access data and experience are combined to analyze and select different analysis data sources, which will affect the final evaluation of the attack degree. Further, the legal access condition corresponding to the target access domain name can be determined based on the first analysis data source and the second analysis data source, that is, the historical access data of the attacked domain name (i.e., the target access domain name) can be analyzed to determine the legal access condition corresponding to the domain name. The specific content of the legal access condition is not limited in the embodiment of the application, and can be represented by certain threshold or range.

[0196] Optionally, in the absence of historical access data, the legal access condition can be set according to experience.

[0197] In the method, the first analysis data source can be obtained from the non-attack traffic log based on the fluctuation analysis result. For example, if the fluctuation analysis result indicates that the access traffic to the target access domain name is stable, the log data in the first attack time interval can be obtained from the non-attack traffic log as the first analysis data source. The specific range of the first attack time interval is not limited herein. For example, the traffic data in the time period before and after the attack can be taken as the analysis data source. For example, if it is detected that the service server 22a indicated by the domain name E1 is attacked from 2:00 to 3:00, the historical normal access data in the time period before and after 2:00-3:00 can be taken as the analysis data source. Alternatively, if the fluctuation analysis result indicates that the access traffic to the target access domain name fluctuates, the log data in the second attack time interval can be obtained from the non-attack traffic log as the first analysis data source. The range of the second attack time interval is greater than that of the first attack time interval. The specific range of the second attack time interval is not limited herein. For example, the historical H-day data in the attack time period can be taken as the first analysis data source. The attack time period refers to the attack time interval indicated by the attack traffic log. H is a positive integer, and the value of H is not limited herein. For example, H can be set to 7, indicating that the historical 7-day data in the attack time period can be taken as the first analysis data source. For example, if it is detected that the service server 22a indicated by the domain name E1 is attacked from 2:00 to 3:00, the historical normal access data in the time period of 2:00-3:00 in the previous 7 days can be taken as the analysis data source.

[0198] It can be understood that the traffic pattern of the target access domain name under the historical normal access can be described by the first analysis data source.

[0199] Among them, fluctuation analysis rules can be set as needed, and volatility analysis can be performed based on the fluctuation analysis rules. The specific content of the fluctuation analysis rules is not limited here. For example, a corresponding request volume interval can be set according to experience or historical normal access to indicate the range of normal request quantities for the target access domain name within a unit time. Based on the access traffic indicated by the log data associated with the target access domain name in the non-attack traffic log, the number of multiple domain name requests for the target access domain name can be determined. Each domain name request number corresponds to a detection time period, and the duration corresponding to different detection time periods is equal to the unit time. Further, when the number of multiple domain name requests is within the aforementioned request volume interval, it can be determined that the access traffic for the target access domain name is stable. Optionally, when the number of some domain name requests among the multiple domain name requests is outside the aforementioned request volume interval, it can be determined that the access traffic for the target access domain name fluctuates. Therefore, the result when the access traffic for the target access domain name is stable or the result when the access traffic for the target access domain name fluctuates can be used as the volatility analysis result for the target access domain name. For example, taking the aforementioned domain name E1 as an example, assuming that its request volume interval is set to 100-110 access requests within one hour, if based on the relevant log data, the number of domain name requests in the detection time period of 1:00-2:00 is 100, the number of domain name requests in the detection time period of 9:00-10:00 is 105, the number of domain name requests in the detection time period of 16:00-17:00 is 110, and the number of domain name requests in the detection time period of 22:00-23:00 is 10. If the number of domain name requests during the detection period of 1:00-2:00 is 10, the number of domain name requests during the detection period of 9:00-10:00 is 105, the number of domain name requests during the detection period of 16:00-17:00 is 200, and the number of domain name requests during the detection period of 22:00-23:00 is 50, it can be determined that the access traffic to domain name E1 fluctuates.

[0200] In an implementation, the legal access condition can specifically include a legal access request quantity threshold (denoted as Y1) and a legal access request rate threshold (denoted as Y2) corresponding to the target access domain name, which are determined by the first analysis data source and the second analysis data source and are condition values required to be satisfied according to historical attack evaluation to determine whether an IP address is an attack IP. The legal access request quantity threshold can be used to indicate the maximum request quantity for the target access domain name in a historical normal access situation, and the legal access request rate threshold can be used to indicate the maximum request rate for the target access domain name in the historical normal access situation, that is, when the request quantity of an IP address for the target access domain name in an attack time is greater than Y1 or the request rate is greater than Y2, the IP address can belong to a non-legal network address.

[0201] Based on this, the process of obtaining initial illegal data from the attack-type traffic log can be: in the attack-type traffic log, searching for a network address with an access request quantity greater than the legal request quantity threshold or a network address with an access request rate greater than the legal request rate threshold in an attack time interval associated with the target access domain name, taking the searched network address as a preliminary screening illegal network address, and taking log data associated with the preliminary screening illegal network address as log data that does not meet the legal access condition. The preliminary screening illegal network address here refers to a network address suspected of being used for abnormal access, which can contain both illegal network addresses and legal network addresses. Further, the log data that does not meet the legal access condition can be obtained from the attack-type traffic log, and the obtained log data can be taken as initial illegal data. The initial illegal data here refers to data about suspected abnormal access. As can be seen, the embodiments of the present application can filter out access data of IP addresses that do not meet the legal access condition through domain name and IP level dimensions, and obtain suspected abnormal access data (i.e., initial illegal data) after statistical processing.

[0202] Among them, the network address contained in the above-mentioned initial illegal data is the initial screening of illegal network addresses. Based on this, the network address that meets the legal access conditions can be obtained from the attack traffic log, and the obtained network address can be added to the trusted network address associated with the target access domain name. At this time, the trusted network address includes the network address that meets the legal access conditions determined based on log analysis (i.e., the whitelist IP address that needs to be dynamically generated), and the original trusted network address obtained from the outside (i.e., the static whitelist IP address); that is, a whitelist (i.e., address whitelist) can be obtained from the outside, which contains a known amount of trusted network addresses. Then, the network address that meets the legal access conditions obtained from the attack traffic log can be added to the whitelist, which is equivalent to merging the data related to the network address that meets the legal access conditions with the external dynamic and static whitelist IP data into the whitelist IP data. Further, the network address obtained after removing the trusted network address from the initial screening of illegal network addresses can be used as an illegal network address; the illegal network address is the network address other than the trusted network address in the initial screening of illegal network addresses. It can be understood that the illegal network address obtained at this time is a highly trusted network address used for abnormal access.

[0203] Step S104: evaluating the attack degree of the illegal network address based on the illegal access data to obtain the attack degree of the illegal network address on the target access domain name.

[0204] As you can understand, after acquiring illegal access data, the analysis server can use this data to assess the attack severity of the illegal network address, thereby determining the attack severity of the illegal network address against the target domain name. This attack severity is used to determine the protection strategy for illegal network addresses. In other words, illegal IP addresses used for irregular access can be evaluated across multiple dimensions based on illegal access data. Subsequently, based on the current attack situation, IP addresses with a certain attack severity can be pushed to protection devices, which can then implement strict interception based on the IP attack severity.

[0205] It can be understood that the embodiments of the present application can characterize the attack level of illegal network addresses based on illegal access data, that is, the analysis server can perform a multi-dimensional evaluation of illegal network addresses based on illegal access data, and obtain the attack level of illegal network addresses against target access domain names, and then send the attack level to the protection device, which determines the protection strategy based on the attack level; wherein the protection strategy can be used to intercept illegal access requests initiated by the target access device to the target business server, that is, when the protection device protects the target business service, it can intercept illegal access requests originating from illegal network addresses.

[0206] Specifically, the historical attack dimension information associated with the illegal network address can be determined according to the illegal access data, and the attack degree of the illegal network address is evaluated based on the historical attack dimension information, and the attack degree of the illegal network address to the target access domain name can be obtained. The attack degree evaluation rule or formula can be set for attack degree evaluation, and the specific evaluation rule is not limited here. The historical attack dimension information can be used to represent the multi-dimensional characteristics of the illegal network address in the historical attack, which can include but is not limited to the number of attacks, the number of attack requests (i.e. the number of illegal access requests), the attack request frequency (i.e. the frequency of sending illegal access requests), IP attributes, attack frequency magnitude (including request number frequency magnitude and request rate frequency magnitude), historical attack date, etc. The IP attribute can include regional attribute (i.e. the regional location corresponding to the IP address), HTTP request characteristics, operator attribute (civilian or commercial), etc. The attack degree can be indicated by attack score, attack level, etc. The specific form of the attack degree is not limited in the embodiment of the application.

[0207] It should be noted that there can be multiple different aggregated access logs aggregated based on different feature dimensions, and in the foregoing steps S101-S103, different aggregated access logs can be processed separately to obtain different illegal access data, but in step S104, different illegal access data needs to be combined and weighted to evaluate the attack degree after multi-dimensional evaluation, so the evaluation process involves multi-dimensional characteristics in the historical attack, which can improve the evaluation accuracy and adaptability of the attack degree. For example, assume that the aggregated access log G1 based on the number of client identifiers, the aggregated access log G2 based on the number of source ports, and the aggregated access log G3 based on the regional location are aggregated, and the aggregated access log G1, the aggregated access log G2 and the aggregated access log G3 are processed by the above steps, the illegal access data H1, the illegal access data H2 and the illegal access data H3 can be obtained, and the attack degree of the illegal network address can be evaluated based on the illegal access data H1, the illegal access data H2 and the illegal access data H3, such as weighted average or simple average, to obtain the corresponding attack degree.

[0208] In addition, the embodiment of the present application can also construct access reputation data (i.e. IP reputation data) based on the obtained attack degree, and push the access reputation data to the protection device. Specifically, when the data validity period configured for the illegal network address is obtained, the access reputation data for sending to the protection device can be constructed based on the illegal network address, the attack degree, and the data validity period; wherein the data validity period is determined by the data minimum validity period and the data maximum validity period; the protection device is configured to determine the protection policy for the illegal network address based on the attack degree in the access reputation data when the illegal network address hitting the access reputation data is detected within the data validity period. Optionally, the analysis server can also determine the protection policy for the illegal network address based on the attack degree, and the specific process can be referred to the subsequent description of the protection policy. Figure 4 Step S202 in the corresponding embodiment.

[0209] In the embodiment of the present application, the above-mentioned access reputation data can specifically include a sixth network address field, a validity period field, and an attack degree field; wherein the sixth network address field can be used to indicate the illegal network address; the validity period field can be used to indicate the data validity period configured for the illegal network address, within which the illegal network address and its attack degree are valid; the data validity period is determined by the data minimum validity period and the data maximum validity period; the attack degree field can be used to indicate the attack degree. It can be understood that since the network address can not be used by the same user for a long time, it is necessary to configure the corresponding data validity period for the illegal network address to avoid abnormal interception due to long-term validity when different users use it, for example, the IP address of a home bandwidth can be configured with a data validity period of 1 day; the specific value of the data validity period in the embodiment of the present application is not limited, for example, it can be determined according to the attack degree, the higher the attack degree of the IP address, the longer the corresponding data validity period can be set, and it can also be set according to actual needs.

[0210] For ease of understanding, please refer to Table 6, which exemplarily shows the format of the access reputation data.

[0211] Table 6

[0212] Attribute Meaning Attribute Meaning Src_IP Source IP address Start_Date Data minimum validity period Score Attack score (-1-1000) End_Date Data maximum validity period

[0213] In Table 6, Src_IP represents the aforementioned sixth network address field, Score represents the aforementioned attack degree field, for example, attack score can be used for representation, the value range can be between -1 and 1000, the smaller the value, the higher the attack degree, Start_Date represents the aforementioned data minimum validity period, and End_Date represents the aforementioned data maximum validity period.

[0214] It can be understood that the embodiment of the application also provides a negative feedback mechanism, which can compare and analyze the overlapping part of the historical normal data and the abnormal data. When it is found that the attack time interception is higher and the normal time interception is lower, it is probably a protection misjudgment problem at the attack time. At this time, the IP address in this part can be added to the white IP data, and the IP address that appears a lot at the attack time and does not appear or appears a little at the normal time can be added to the black IP data. Then, the IP address that needs to be whitelisted can be removed from the black IP data to obtain the final IP reputation data.

[0215] Specifically, it is assumed that the non-attack type traffic log and the attack type traffic log both contain data associated with a first target network address, and the access device indicated by the first target network address can send an access request to a target service server; the first target network address can be determined based on the non-attack type traffic log to correspond to a first target interception request quantity, and the first target network address can be determined based on the attack type traffic log to correspond to a second target interception request quantity. The first target interception request quantity refers to the number of access requests carrying the first target network address and the target access domain name intercepted by the protection device in the non-attack time interval, and the second target interception request quantity refers to the number of access requests carrying the first target network address and the target access domain name intercepted by the protection device in the attack time interval. When the first target interception request quantity is less than a first interception threshold, and the second target interception request quantity is greater than a second interception threshold, it indicates that the first target network address is intercepted at the attack time and the normal time interception is lower, which may be caused by the protection device in the face of attack using various protection means. Therefore, the first target network address can be added to the trusted network address associated with the target access domain name, i.e., the first target network address is whitelisted, and the subsequent protection device will no longer intercept the access request from the first target network address. The first interception threshold is less than the second interception threshold, and the specific value of the first interception threshold and the second interception threshold is not limited in the embodiment of the application. For example, it can be set according to actual demand or experience.

[0216] Further, assuming that the attack-type traffic log contains data associated with a second target network address, the access device indicated by the second target network address can send an access request to the target service server; the first target request quantity corresponding to the second target network address can be determined based on the attack-type traffic log, and the second target request quantity corresponding to the second target network address can be determined based on the non-attack-type traffic log, where the first target request quantity refers to the number of access requests carrying the second target network address and the target access domain name within the attack time interval, and the first target request quantity is a positive integer; the second target request quantity refers to the number of access requests carrying the second target network address and the target access domain name within the non-attack time interval, and the second target request quantity is an integer and can be equal to zero; when the first target request quantity is greater than the first request threshold and the second target request quantity is less than the second request threshold, it indicates that the second target network address appears in large quantities in the attack time and does not appear or appears in small quantities in the normal time, and the second target network address can be added to the preliminary screening illegal network address associated with the target access domain name, i.e., the second target network address is blacklisted, and subsequently, by removing trusted network addresses from the preliminary screening illegal network addresses, high-trust illegal network addresses can be obtained, which can be used to construct access reputation data. Wherein the first request threshold is greater than the second request threshold, and the specific values of the first request threshold and the second request threshold are not limited in the embodiments of the present application, which can be set according to actual needs or experience.

[0217] In addition, the application can also support the analysis server to perform abnormal interception analysis, specifically, business access association data associated with the access device and the business server can be acquired, and the illegal network address is intercepted and analyzed based on the business access association data; when it is analyzed that the illegal network address includes an abnormal interception network address, the abnormal interception network address is added to the trusted network address associated with the target access domain name; wherein the abnormal interception network address here is used to indicate the device with legal access permission in the target access device, and the trusted network address is used to identify the device trusted by the target business server in the access device. That is, the device indicated by the abnormal interception network address has legal access permission and can actually normally access the business server, that is, it is separated from the illegal identity represented by the illegal network address, but the legal access request sent by it is still intercepted by the protection device, so it needs to be whitelisted. In this way, the protection device timely adjusts the protection strategy and will no longer intercept the access request from the abnormal interception network address, improving the reliability of the business service. Wherein, the business access association data can include but is not limited to access reputation data, externally acquired danger prompt information, historical interception water level and other data sources; the specific content of the access reputation data can be referred to in Table 6 above, which will not be described here. The danger prompt information is the information commonly used to prompt danger in the field of network security, which is usually provided by external professional merchants and can be used to indicate abnormal network addresses and access domain names. The historical interception water level refers to the interception water level of the access domain name learned from the historical interception of the access domain name, which can be used to indicate the number of intercepted requests of the access domain name to different network addresses. For example, it is statistically found that during a certain period of time, when the network address D1 accesses the domain name E1, 100 access requests are intercepted within 1 minute, so it can be used as the historical interception water level.

[0218] Wherein, the business access association data can be used to monitor the real-time access of the network, find suspected abnormal interception, automatically analyze and start the IP whitelisting system as needed, add the detected IP address that has separated from the illegal identity (i.e. abnormal interception network address) to the external dynamic and static whitelisted IP data (i.e. trusted network address), and perform calculation and pushing at regular intervals. Wherein, a streaming computing platform can be used to build a task to monitor and calculate the access of the illegal network address in real time, analyze the IP address hitting the illegal IP library (i.e. address blacklist), and when IP reputation interception occurs, the data of the IP address in the danger prompt information can be queried. When the result of the danger prompt information is inconsistent with the illegal IP address, the historical access and request access to other domain names of the IP address are calculated; in addition, when the illegal IP address has normal access benefits, it can be added to the whitelisted IP library (i.e. address whitelist) to avoid restrictions on the IP address (i.e. abnormal interception network address) used by the non-illegal business object, thereby avoiding the occurrence of abnormal interception.

[0219] Based on this, assuming that the illegal network address includes a third target network address, taking the third target network address as an example, the specific process of intercepting and analyzing the illegal network address based on the service access association data can be: obtaining the attack degree corresponding to the third target network address from the access reputation data, when the attack degree is in the reputation interception range, it indicates that the reputation interception is generated for the third target network address, and then the target danger prompt information associated with the third target network address can be obtained from the danger prompt information; when the target danger prompt information indicates that the third target network address does not belong to the illegal network address, the number of domain name interceptions of the domain names that intercept the access requests from the third target network address in the remaining access domain names can be determined based on the historical interception level, and when the number of domain name interceptions is less than the domain name interception threshold, it can be determined that the access device indicated by the third target network address has legal access authority, and the third target network address can be taken as an abnormal interception network address. The reputation interception range is a numerical range used to determine whether IP reputation interception is generated, for example, assuming that the value range of the attack degree is -1-1000, the reputation interception range can be set to 1-1000, that is, when the attack degree is 1-1000, the frequency control value needs to be calculated and executed based on the attack degree, that is, IP reputation interception is generated, at this time, the data associated with the IP address in the danger prompt information needs to be queried as the target danger prompt information, and when the attack degree is less than 0, it can be considered as extremely abnormal and directly intercepted. It can be understood that the third target network address can be used to access many domain names, including the above target access domain names and the remaining access domain names, the remaining access domain names herein refer to the access domain names of the servers in the above service servers except the target service server, the number of the remaining access domain names is K (K is a positive integer), the access of the third target network address to the K remaining access domain names can be counted, if it is counted that J (J is a positive integer less than or equal to K) access domain names in the K remaining access domain names all intercept the access requests from the third target network address, then the number of domain name interceptions is J; when J is less than the domain name interception threshold, it indicates that the access device indicated by the third target network address has normal access to most service servers, therefore, the third target network address can be dynamically whitelisted, and the specific value of the domain name interception threshold is not limited here, which can be set according to needs.

[0220] From the above, the embodiment of the application can accurately distinguish normal access and abnormal access from the historical attack traffic log by combining historical business log analysis, and then can evaluate the attack degree of illegal network address according to illegal access data, which is equivalent to continuously accumulating and fine-grading illegal IP addresses, so as to formulate differentiated protection strategies for different illegal IP addresses, rather than formulating a unified frequency control value. In this way, when future attacks come, it can achieve higher speed limiting capability for illegal IP addresses, thereby improving the protection effect of network attacks. At the same time, the embodiment of the application provides a network attack defense method based on IP reputation, which models historical illegal access behavior through traffic layering and traffic form comparison technology, analyzes illegal IP addresses from it, and completes the description of the attack degree of illegal IP addresses according to the data related to historical illegal access behavior (i.e. illegal access data). In this way, in the case of multiple attacks on the business server, the frequency control transmission amount can be greatly reduced from the second attack. In addition, the embodiment of the application correlates the historical access of the website (i.e. business server) and the user traffic characteristics for correlation analysis, effectively solves the modeling of abnormal interception detection of a small amount of traffic in a cloud service environment (i.e. the protection system is deployed in the cloud), thereby truly reflecting the effectiveness of different defense strategies, and can be adjusted in time, improving the reliability of business services.

[0221] Further, please refer to Figure 4 , Figure 4 is a flow diagram of a data processing method provided by the embodiment of the application Figure 2 . As shown in Figure 4 , the method can be executed by a protection device, for example, the protection device can be the protection device 300a exemplified in the above Figure 1 corresponding embodiment. The method can specifically include the following steps S201-S202.

[0222] Step S201, sending a business protection log and a business prompt log to an analysis server;

[0223] It can be understood that the protection device can send the service protection log and the service prompt log to the analysis server, and the sending manner can be periodic sending or real-time sending, and the embodiments of the present application do not limit this. Wherein, the service protection log is used to determine the aggregated access log associated with the access device and the service server; the service prompt log is used to determine the attack time data for log division; the access request sent by the access device to the service server carries the access domain name of the service server and the network address of the access device; the attack time data is used to divide the aggregated access log into attack type traffic log and non-attack type traffic log; the attack type traffic log and the non-attack type traffic log are used to determine the target service server attacked in the service server, and the target access device initiating illegal access request to the target service server in the access device, and obtain the illegal access data associated with the target service server and the target access device; the illegal access request carries the target access domain name of the target service server and the illegal network address of the target access device; the analysis server is used to evaluate the attack degree of the illegal network address according to the illegal access data, obtain the attack degree of the illegal network address to the target access domain name, and send the attack degree to the protection device. The specific processing process of the analysis server side can be referred to the above Figure 3 corresponding embodiments, which will not be repeated here.

[0224] Step S202, receiving the attack degree sent by the analysis server, and determining the protection strategy for the illegal network address based on the attack degree.

[0225] It can be understood that the protection device can determine the protection strategy for the illegal network address based on the attack degree sent by the analysis server after receiving the attack degree, wherein the protection strategy can be used to intercept the illegal access request initiated by the target access device to the target service server.

[0226] Specifically, if the attack degree is in the first attack range, a first type of protection policy can be configured; the first type of protection policy can be used to intercept all illegal access requests initiated by the target access device to the target service server, and the specific range of the first attack range is not limited; if the attack degree is in the second attack range, an execution frequency control value for the illegal network address can be obtained according to the attack degree, and then a second type of protection policy can be configured based on the execution frequency control value; the second type of protection policy can be used to intercept illegal access requests initiated by the target access device to the target service server that exceed the execution frequency control value, that is, only a number of access requests below the execution frequency control value are allowed to pass through the protection device to the target service server in a fixed time window, for example, assuming that the execution frequency control value is 10 qps, it means that only 10 access requests are allowed to pass through the protection device to the target service server in one second; the specific range of the second attack range is not limited; the first type of protection policy or the second type of protection policy is used as the protection policy.

[0227] It can be understood that the protection device can strictly limit the frequency of the illegal network address accessing the aforementioned access reputation data according to the attack degree thereof, taking the attack score as an example, assuming that the value range of the attack score is an integer between -1 and 1000, and the smaller the value is, the higher the attack degree is; when the attack score is less than 0, it means that the attack degree is in the first attack range, and the interception operation (i.e., the first type of protection policy is configured) can be directly performed at this time. Alternatively, when the attack score is between 1 and 1000, it means that the attack degree is in the second attack range, and the frequency limiting formula that can be used at this time is as follows:

[0228] C_R=C*Score / 1000

[0229] Wherein, C_R is the actual execution frequency control value (i.e., the aforementioned execution frequency control value) of the protection device for the illegal network address of the hit address blacklist of the target access domain name, C is the predetermined frequency control value (i.e., the initial frequency control value) for the illegal network address, and Score is the attack score of the illegal network address for the target access domain name. The protection device can perform an interception operation (i.e., configure the second type of protection policy) according to C_R.

[0230] For ease of understanding, please refer to Figure 5a , Figure 5a is a unified threshold protection logic diagram provided by an embodiment of the present application. It can be understood that in actual attacks, the ratio of attack traffic (i.e., abnormal access traffic) to normal service traffic (i.e., normal access traffic) is often hundreds of times or even tens of thousands of times. For example, Figure 5aAs shown in the scenario without the protection method provided by the embodiments of the present application, in order to serve normal users, a unified threshold is set as a frequency control value for speed limiting, and at the attack moment, assuming that 5wqps of the 100wqps of traffic is normal service traffic and the remaining 95wqps of traffic is abnormal attack traffic, after the unified threshold speed limiting, there are still 80wqps of traffic reaching the service server for providing service, so it can be seen that a lot of attack traffic penetrates through the protection and directly reaches the source station, and at this time, the protection effect is very poor.

[0231] Further, please refer to Figure 5b , Figure 5b is a protection logic diagram provided by the embodiments of the present application under the access credit data. As shown in Figure 5b , in the scenario of using the protection method provided by the embodiments of the present application, facing 100wqps at the attack moment, 95wqps of attack traffic from illegal network addresses can be strictly speed limited (such as 85wqps of attack traffic is intercepted), and 5wqps of service traffic from legal network addresses can be normally speed limited (such as allowing all of the 5wqps of service traffic to reach the service server without interception), compared with Figure 5a , through this layered protection, the protection effect can be significantly improved, and the pressure on the backend can be reduced.

[0232] As known from the above, the embodiments of the present application can formulate differentiated protection strategies for different illegal network addresses, instead of formulating a unified frequency control value, so that the protection effect on network attacks can be improved. Meanwhile, the intelligent protection system based on access credit data proposed by the embodiments of the present application plays an important role in the CC defense system: the embodiments of the present application can effectively improve the protection and cleaning rate of a new access customer (i.e. a service server) under a cloud service environment when the service server is attacked, solve the problem of poor protection effect when the service server is migrated to the cloud protection platform without manual customization of protection strategies under the attack situation; and the embodiments of the present application can also improve the protection and cleaning rate of a historical service server under a cloud service environment when the service server is attacked, effectively improve the protection capability of the service server after the first attack in the scenario of the historical service server being attacked by the same botnet multiple times, and avoid the situation that the service server is damaged by the attacker through changing methods.

[0233] Further, please refer to Figure 6 , Figure 6 is a schematic diagram of an intelligent protection method and system based on access credit data provided by the embodiments of the present application. As shown in Figure 6 , the system mainly includes a protection device and an analysis server (not shown in the figure) and can be applied to protection against CC attacks or other similar network attacks; wherein the protection device can be the above Figure 2The analysis server can be the security device 20a exemplified in the corresponding embodiment. The analysis server can be the analysis server 20b exemplified in the corresponding embodiment. The method can specifically include the following steps: Figure 2 The analysis server can be the security device 20a exemplified in the corresponding embodiment. The analysis server can be the analysis server 20b exemplified in the corresponding embodiment. The method can specifically include the following steps:

[0234] Step S1: The analysis server can collect the access log file reported by the security device (i.e., the business security log described above) and perform preprocessing operations on the access log file to obtain the preprocessed access log (i.e., the aggregated access log described above). This step can be performed by a data preprocessing module in the analysis server. The specific implementation of this step can be referred to the related description of step S101 in the corresponding embodiment described above. Figure 3 The specific implementation of this step can be referred to the related description of step S101 in the corresponding embodiment described above.

[0235] Step S2: The analysis server can obtain attack detection data (including the first attack detection data and the second attack detection data described above) from the business prompt log and perform preprocessing operations to obtain suspected attack time data. This step can be performed by an attack time processing module in the analysis server. The specific implementation of this step can be referred to the related description of step S101 in the corresponding embodiment described above. Figure 3 The specific implementation of this step can be referred to the related description of step S101 in the corresponding embodiment described above.

[0236] Step S3: The analysis server can use the suspected attack time data obtained in step S2 to perform layering on the preprocessed access log (i.e., the aggregated access log) obtained in step S1, and the layered log is normal flow log (i.e., the non-attack flow log described above) and suspected abnormal flow log (i.e., the attack flow log). This step can be performed by a flow layering module in the analysis server. The specific implementation of this step can be referred to the related description of step S102 in the corresponding embodiment described above. Figure 3 The specific implementation of this step can be referred to the related description of step S102 in the corresponding embodiment described above.

[0237] Step S4: The analysis server can evaluate the condition value that needs to be met to determine whether an IP address is a illegal IP address according to the related access data of the historical attacked domain name (i.e., the log data associated with the target access domain name in the non-attack flow log described above): the request amount in the attack time is greater than Y1 (i.e., the legal request amount threshold in the legal access condition described above) or the request rate is greater than Y2 (i.e., the legal request rate threshold in the legal access condition described above). This step can be performed by an attack flow determination standard module in the analysis server.

[0238] Subsequently, the access data of the IP meeting the above conditions is filtered out in the domain name and IP level, and after statistical processing, the suspected abnormal access data (i.e., the initial illegal data described above) is obtained.

[0239] Step S5: The analysis server can use the suspected abnormal access data to compare with the normal traffic log, analyze the related information conforming to the historical normal access frequency (i.e. the aforementioned legal access condition), and after processing, merge the external dynamic and static whitelisted IP data into the whitelisted IP data, remove the whitelisted IP data from the suspected abnormal access data, and obtain the abnormal access data information (i.e. the aforementioned illegal access data); the whitelisted IP here is the aforementioned trusted network address for normal access, which can form a whitelisted IP library (i.e. the aforementioned address whitelist); this step can be performed by an address layering module in the analysis server;

[0240] The specific implementation of steps S4 and S5 can be referred to the above Figure 3 The related description of step S103 in the corresponding embodiment will not be repeated here.

[0241] Step S6: The analysis server can score the illegal IP address (i.e. the aforementioned illegal network address) through multiple dimensions according to the illegal access data, and push the IP with a certain attack level to the protection device according to the attack status. The protection device can strictly intercept according to the IP attack level. This step can be performed by an illegal address scoring module in the analysis server. The specific implementation of this step can be referred to the above Figure 3 The related description of step S104 in the corresponding embodiment will not be repeated here.

[0242] Step S7: The analysis server can use multiple data sources such as danger prompt information, IP reputation data (i.e. the aforementioned access reputation data), and historical interception level to monitor the real-time access of the network, find suspected abnormal interception, automatically analyze and start the IP whitelisting system according to the need, and add the IP address (i.e. the aforementioned abnormal interception network address) that has left the attack identity to the external dynamic and static whitelisted IP data (i.e. the trusted network address) for calculation and pushing at regular intervals. This step can be performed by an intelligent interception judgment module in the analysis server. The specific implementation of this step can be referred to the above Figure 3 The related description of step S104 in the corresponding embodiment will not be repeated here.

[0243] Among them, each module involved in the embodiments of the application can be understood as each component in the analysis server. Different modules can be distributed on different or same analysis servers, and the same module can also be distributed on different analysis servers. The deployment manner of the modules is not limited in the embodiments of the application.

[0244] Therefore, the embodiment of the application plays a key role in protecting the high-frequency CC attack, and through comprehensive judgment of the service protection log, the service prompt log, external prompt information and the like, accurate distinction between normal access and abnormal access can be realized from historical attacks, and through continuous accumulation and fine classification of illegal IP addresses, the illegal IP addresses have high speed limiting capability when future attacks come, and the protection effect of the CC attack is effectively improved.

[0245] Please refer to Figure 7 , Figure 7 is a structure schematic diagram of a data processing device provided by the embodiment of the application Figure 1 . As shown in Figure 7 , the data processing device 1 can be applied to an analysis server, for example, the analysis server can be the analysis server 20b in the embodiment corresponding to the above Figure 2 . It should be understood that the data processing device 1 can be a computer program (including program code) running in the analysis server, for example, the data processing device 1 can be an application software; the data processing device 1 can be used to execute the corresponding steps in the data processing method provided by the embodiment of the application. As shown in Figure 7 , the data processing device 1 can include a log processing module 11, a log division module 12, a data acquisition module 13, and an attack evaluation module 14.

[0246] The log processing module 11 is configured to acquire the service protection log and the service prompt log reported by the protection device, determine the aggregated access log associated with the access device and the service server based on the service protection log, and determine the attack time data used for log division based on the service prompt log; the access request sent by the access device to the service server carries the access domain name of the service server and the network address of the access device.

[0247] The log division module 12 is configured to divide the aggregated access log into attack type traffic log and non-attack type traffic log based on the attack time data.

[0248] The data acquisition module 13 is configured to determine the target service server attacked in the service server and the target access device initiating illegal access request to the target service server in the access device based on the attack type traffic log and the non-attack type traffic log, and obtain the illegal access data associated with the target service server and the target access device; the illegal access request carries the target access domain name of the target service server and the illegal network address of the target access device.

[0249] The attack evaluation module 14 is configured to evaluate the attack degree of the illegal network address according to the illegal access data, and obtain the attack degree of the illegal network address to the target access domain name; the attack degree is used to determine the protection strategy for the illegal network address.

[0250] In an implementation, the log processing module 11 is further configured to perform the following operations:

[0251] log preprocessing is performed on the service protection logs to obtain aggregated access logs associated with the access devices and the service servers;

[0252] attack detection data that is continuous in the time dimension is obtained based on the service prompt logs, and data preprocessing is performed on the attack detection data to obtain attack time data used for log division.

[0253] In an implementation, the log processing module 11 is further configured to perform the following operations:

[0254] data cleaning is performed on the abnormal log data in the service protection logs to obtain standard log data;

[0255] data aggregation is performed on the standard log data based on the first type of log field to obtain aggregated access logs associated with the access devices and the service servers.

[0256] The service prompt logs include traffic surge prompt logs and illegal address access prompt logs;

[0257] In an implementation, the log processing module 11 is further configured to perform the following operations:

[0258] continuous processing is performed on the traffic surge prompt logs and the illegal address access prompt logs to obtain first attack detection data corresponding to the traffic surge prompt logs and second attack detection data corresponding to the illegal address access prompt logs, and the first attack detection data and the second attack detection data are taken as attack detection data that is continuous in the time dimension; the continuous processing refers to data processing performed on log data obtained within a detection time interval; the time dimension refers to time within the detection time interval;

[0259] data preprocessing is performed on the first attack detection data and the second attack detection data in the attack detection data to obtain attack time data used for log division.

[0260] In an implementation, the log processing module 11 is further configured to perform the following operations:

[0261] a first detection time interval configured for the traffic surge prompt logs is obtained, and log data in the traffic surge prompt logs that is within the first detection time interval is merged to obtain first attack detection data corresponding to the traffic surge prompt logs;

[0262] The second detection time interval configured for the illegal address access prompt log is obtained, log data in the illegal address access prompt log located in the second detection time interval is merged, and second attack detection data corresponding to the illegal address access prompt log is obtained.

[0263] In an implementation, the log processing module 11 is further configured to perform the following operations:

[0264] The first attack time interval associated with the first attack detection data and the second attack time interval associated with the second attack detection data are obtained, the first attack detection data and the second attack detection data are subjected to data aggregation processing based on the first attack time interval and the second attack time interval, and aggregated detection data is obtained; the confidence included in the aggregated detection data is determined by the first confidence corresponding to the first attack detection data and the second confidence corresponding to the second attack detection data;

[0265] Data with a confidence greater than the attack confidence threshold is obtained from the aggregated detection data, and the obtained data is taken as first-class attack time data;

[0266] Data with a confidence less than or equal to the attack confidence threshold is obtained from the aggregated detection data, and when the obtained data satisfies the attack screening condition, data in the aggregated detection data that satisfies the attack screening condition is taken as second-class attack time data;

[0267] The first-class attack time data and the second-class attack time data are taken as attack time data used for log division.

[0268] In an implementation, the log division module 12 is further configured to perform the following operations:

[0269] Log data in the aggregated access log that hits the attack time data is taken as initial attack log data, the initial attack log data is subjected to a data aggregation operation based on the second-class log field, and attack-class traffic log is obtained;

[0270] Log data in the aggregated access log that does not hit the attack time data is taken as initial service log data, the initial service log data is subjected to a data aggregation operation based on the third-class log field, and non-attack-class traffic log is obtained.

[0271] In an implementation, the data acquisition module 13 is further configured to perform the following operations:

[0272] An access domain name included in the attack-class traffic log is taken as a target access domain name, a server indicated by the target access domain name is taken as a target service server in the service server that is attacked, and a legitimate access condition corresponding to the target access domain name is determined based on log data associated with the target access domain name in the non-attack-class traffic log;

[0273] obtain log data that does not meet the legal access condition from the attack-type traffic log as initial illegal data;

[0274] In a case where a trusted network address associated with the target access domain name is determined based on the legal access condition, the illegal network address is obtained from the network addresses contained in the initial illegal data based on the trusted network address, and a device indicated by the illegal network address is taken as a target access device that initiates an illegal access request to the target service server among the access devices; the trusted network address is used to indicate a device trusted by the target service server among the access devices.

[0275] Data associated with the illegal network address obtained from the initial illegal data is taken as illegal access data associated with the target service server and the target access device.

[0276] In an embodiment, the data obtaining module 13 is further configured to perform the following operations:

[0277] fluctuation analysis is performed on log data associated with the target access domain name in the non-attack-type traffic log to obtain fluctuation analysis results for the target access domain name, and first analysis data sources are obtained from the non-attack-type traffic log based on the fluctuation analysis results;

[0278] access frequency analysis is performed on log data associated with the target access domain name in the non-attack-type traffic log to obtain a high-frequency access range for the target access domain name, and log data in the non-attack-type traffic log with an access frequency in the high-frequency access range is taken as second analysis data sources;

[0279] The legal access condition corresponding to the target access domain name is determined based on the first analysis data sources and the second analysis data sources.

[0280] In an embodiment, the data obtaining module 13 is further configured to perform the following operations:

[0281] If the fluctuation analysis results indicate that the access traffic for the target access domain name is stable, log data in the non-attack-type traffic log in the first type of attack time interval is obtained as the first analysis data sources;

[0282] If the fluctuation analysis results indicate that the access traffic for the target access domain name fluctuates, log data in the non-attack-type traffic log in the second type of attack time interval is obtained as the first analysis data sources; the range corresponding to the second type of attack time interval is greater than the range corresponding to the first type of attack time interval.

[0283] In an embodiment, the data obtaining module 13 is further configured to perform the following operations:

[0284] The log data that does not meet the legal access condition is obtained from the attack-type traffic log as initial illegal data, including:

[0285] In the attack-type traffic log, a network address with a number of access requests greater than a threshold of a number of legal requests or a network address with an access request rate greater than a threshold of a legal request rate in an attack time interval associated with the target access domain name is found, the found network address is taken as a preliminary screening illegal network address, and log data associated with the preliminary screening illegal network address is taken as log data that does not meet the legal access condition.

[0286] The log data that does not meet the legal access condition is obtained from the attack-type traffic log, and the obtained log data is taken as initial illegal data.

[0287] The network address contained in the initial illegal data is a preliminary screening illegal network address.

[0288] In an implementation, the data obtaining module 13 is further configured to perform the following operation:

[0289] The network address that meets the legal access condition is obtained from the attack-type traffic log, and the obtained network address is added to the trusted network address associated with the target access domain name.

[0290] The network address obtained after the trusted network address is removed from the preliminary screening illegal network address is taken as an illegal network address; the illegal network address is a network address other than the trusted network address in the preliminary screening illegal network address.

[0291] In an implementation, the attack evaluating module 14 is further configured to perform the following operation:

[0292] The historical attack dimension information associated with the illegal network address is determined according to the illegal access data, the attack degree of the illegal network address against the target access domain name is obtained by performing attack degree evaluation on the illegal network address based on the historical attack dimension information; the historical attack dimension information is used to represent multi-dimensional characteristics of the illegal network address in historical attacks.

[0293] In an implementation, the attack evaluating module 14 is further configured to perform the following operation:

[0294] When the data validity period configured for the illegal network address is obtained, the access reputation data used for sending to the protection device is constructed based on the illegal network address, the attack degree, and the data validity period; the data validity period is determined by a data minimum validity period and a data maximum validity period; when the protection device detects the illegal network address that hits the access reputation data within the data validity period, the protection strategy for the illegal network address is determined based on the attack degree in the access reputation data.

[0295] In an implementation, the apparatus further comprises:

[0296] The intercept analysis module 15 is configured to acquire service access association data associated with the access device and the service server, perform intercept analysis on the illegal network address based on the service access association data, and add an abnormal intercept network address to the trusted network address associated with the target access domain name when the abnormal intercept network address is analyzed from the illegal network address; the abnormal intercept network address is used to indicate a device in the target access device that has legitimate access authority; and the trusted network address is used to identify a device in the access device that is trusted by the target service server.

[0297] The specific function implementation manners of the log processing module 11, the log division module 12, the data acquisition module 13, the attack evaluation module 14, and the intercept analysis module 15 can refer to the descriptions of the corresponding embodiments of the log processing module 11, the log division module 12, the data acquisition module 13, the attack evaluation module 14, and the intercept analysis module 15 in the foregoing Figure 3 The descriptions of steps S101-S104 in the corresponding embodiments will not be repeated here. It should be understood that the beneficial effects obtained by using the same method will not be repeated.

[0298] Please refer to Figure 8 , Figure 8 is a structure schematic diagram of a data processing apparatus provided by an embodiment of the present application Figure 2 . As shown in Figure 8 , the data processing apparatus 2 can be applied to a protection device, for example, the protection device can be the protection device 20a in the corresponding embodiments of the foregoing Figure 2 . It should be understood that the data processing apparatus 2 can be a computer program (including program code) running in the protection device, for example, the data processing apparatus 2 can be an application software; the data processing apparatus 2 can be used to execute the corresponding steps in the data processing method provided by the embodiments of the present application. As shown in Figure 8 , the data processing apparatus 2 can include a log sending module 21 and a policy determination module 22.

[0299] The log sending module 21 is configured to send a service protection log and a service prompt log to an analysis server; the service protection log is used to determine an aggregated access log associated with an access device and a service server; the service prompt log is used to determine attack time data used for log division; an access request sent by the access device to the service server carries an access domain name of the service server and a network address of the access device; the attack time data is used to divide the aggregated access log into attack type traffic log and non-attack type traffic log; the attack type traffic log and the non-attack type traffic log are used to determine a target service server attacked in the service server and a target access device initiating an illegal access request to the target service server in the access device, and obtain illegal access data associated with the target service server and the target access device; the illegal access request carries a target access domain name of the target service server and an illegal network address of the target access device; the analysis server is configured to perform attack degree evaluation on the illegal network address according to the illegal access data, obtain an attack degree of the illegal network address to the target access domain name, and send the attack degree to the protection device.

[0300] The policy determination module 22 is configured to receive the attack degree sent by the analysis server, and determine a protection policy for the illegal network address based on the attack degree.

[0301] In an embodiment, the policy determination module 22 is further configured to perform the following operations:

[0302] If the attack degree is within a first attack range, a first type of protection policy is configured; the first type of protection policy is used to intercept all illegal access requests initiated by the target access device to the target service server;

[0303] If the attack degree is within a second attack range, an execution frequency control value for the illegal network address is obtained according to the attack degree, and a second type of protection policy is configured based on the execution frequency control value; the second type of protection policy is used to intercept illegal access requests initiated by the target access device to the target service server and exceeding the execution frequency control value;

[0304] The first type of protection policy or the second type of protection policy is used as the protection policy for the target access device.

[0305] The specific function implementation of the log sending module 21 and the policy determination module 22 can be referred to the description of steps S201-S202 in the above-mentioned Figure 4 embodiments, which will not be repeated here. It should be understood that the beneficial effects obtained by using the same method will not be repeated.

[0306] Please refer to Figure 9 , Figure 9 is a structural schematic diagram of a computer device provided by an embodiment of the present application. As shown inFigure 9 As shown in the figure, the computer device 1000 can include a processor 1001, a network interface 1004 and a memory 1005, in addition, the computer device 1000 can also include a user interface 1003 and at least one communication bus 1002. The communication bus 1002 is used to realize the connection communication between the components. The optional user interface 1003 can include a standard wired interface, a wireless interface. The network interface 1004 can optionally include a standard wired interface, a wireless interface (such as a WI-FI interface). The memory 1005 can be a high-speed RAM memory, or a non-volatile memory, for example, at least one disk memory. The memory 1005 can also be at least one storage device located away from the aforementioned processor 1001. For example Figure 9 As shown in the figure, the memory 1005 as a computer readable storage medium can include an operating system, a network communication module, a user interface module and a computer program.

[0307] In the computer device 1000 as shown in the figure, the network interface 1004 can provide network communication function; while the user interface 1003 is mainly used to provide an interface for user input; and the processor 1001 can be used to call the computer program stored in the memory 1005 to execute the foregoing Figure 9 、 Figure 3 、 Figure 4 The description of the data processing method in any of the corresponding embodiments will not be repeated here. In addition, the description of the beneficial effects of using the same method will also not be repeated.

[0308] In addition, it needs to be pointed out here that the present application also provides a computer readable storage medium, and the computer readable storage medium stores the computer program executed by the data processing device 1 and the data processing device 2 mentioned above, and the computer program includes computer instructions, when the processor executes the computer instructions, the foregoing Figure 3 、 Figure 4 The description of the data processing method in any of the corresponding embodiments will not be repeated here. In addition, the description of the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the computer readable storage medium embodiments involved in the present application, please refer to the description of the method embodiments of the present application.

[0309] The computer readable storage medium can be an internal storage unit of the data processing apparatus or the computer device, for example, a hard disk or a memory of the computer device. The computer readable storage medium can also be an external storage device of the computer device, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, and the like. Further, the computer readable storage medium can include both the internal storage unit and the external storage device of the computer device. The computer readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer readable storage medium can also be used to temporarily store data that has been output or will be output.

[0310] In addition, it should be noted that the embodiments of the present application also provide a computer program product (or computer program) including computer instructions stored in a computer readable storage medium. The processor of the computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to enable the computer device to perform the method of any of the preceding Figure 3 、 Figure 4 embodiments. In addition, the beneficial effects of using the same method will not be described again. For technical details not disclosed in the embodiments of the computer program product (or computer program) of the present application, please refer to the description of the method embodiments of the present application.

[0311] Further, please refer to Figure 10 , Figure 10 is a structural schematic diagram of a data processing system provided by the embodiments of the present application. As shown in Figure 10 , the data processing system 3 can include an analysis server 1a and a protection device 2a. In the scenario of protecting against CC attacks, the data processing system 3 can also be used as an IP reputation-based CC intelligent protection system. The analysis server 1a can be the analysis server described in the embodiments of the preceding Figure 2 , which will not be described again. The protection device 2a can be the protection device described in the embodiments of the preceding Figure 2 , which will not be described again. In addition, the beneficial effects of using the same method will not be described again. For technical details not disclosed in the embodiments of the data processing system of the present application, please refer to the description of the method embodiments of the present application.

[0312] The terms "first", "second", etc. in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not intended to describe a particular order. In addition, the term "comprising" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or equipment including a series of steps or units is not limited to the listed steps or modules, but can optionally include steps or modules not listed, or can optionally include other steps or units inherent to the process, method, device, product or equipment.

[0313] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined target, and can be implemented entirely or partially by using software, hardware (such as a processing circuit or a memory) or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of an integral module or unit that includes the functions of the module or unit.

[0314] Those of ordinary skill in the art can be aware that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software or a combination thereof. In order to clearly illustrate the interchangeability of hardware and software, each example has been described in the above description in terms of its general functionality. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0315] It should be noted that for each of the above method embodiments, in order to simply describe, it is expressed as a combination of a series of actions, but those skilled in the art should know that the present application is not limited by the order of the described actions, because according to the present application, some steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.

[0316] The steps in the method of the embodiments of the present application can be adjusted in order, combined and deleted according to actual needs.

[0317] The modules in the device of the embodiments of the present application can be combined, divided and deleted according to actual needs.

[0318] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program. The computer program can be stored in a computer readable storage medium. When the program is executed, the processes of the above-mentioned embodiments of the methods can be included. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM), a random access memory (RAM), or the like.

[0319] The above disclosure is only the preferred embodiment of the present application, and of course cannot limit the scope of the right of the present application, so the equivalent changes made according to the claims of the present application still belong to the scope covered by the present application.

Claims

1. A data processing method, characterized by, The method is performed by an analysis server and comprises: obtaining service protection logs and service prompt logs reported by a protection device, determining aggregated access logs associated with access devices and service servers based on the service protection logs, and determining attack time data for log division based on the service prompt logs; the access requests sent by the access devices to the service servers carry access domain names of the service servers and network addresses of the access devices; dividing the aggregated access logs into attack-type traffic logs and non-attack-type traffic logs based on the attack time data; based on the attack-type traffic logs and the non-attack-type traffic logs, determining target service servers of the service servers that are attacked and target access devices of the access devices that initiate illegal access requests to the target service servers, and obtaining illegal access data associated with the target service servers and the target access devices; the illegal access requests carry target access domain names of the target service servers and illegal network addresses of the target access devices; performing attack degree evaluation on the illegal network addresses according to the illegal access data, and obtaining attack degrees of the illegal network addresses against the target access domain names; the attack degrees are used to determine protection strategies for the illegal network addresses.

2. The method of claim 1, wherein, The method comprises: performing log preprocessing on the service protection logs to obtain aggregated access logs associated with access devices and service servers; based on the service prompt logs, obtaining attack detection data that is continuous in the time dimension, and performing data preprocessing on the attack detection data to obtain attack time data for log division.

3. The method of claim 2, wherein, The method comprises: performing data cleaning operations on abnormal log data in the service protection logs to obtain standard log data; based on first-type log fields, performing data aggregation operations on the standard log data to obtain aggregated access logs associated with access devices and service servers.

4. The method of claim 2, wherein, The service prompt logs comprise traffic surge prompt logs and illegal address access prompt logs. The method comprises: The traffic surge prompt log and the illegal address access prompt log are continuously processed to obtain first attack detection data corresponding to the traffic surge prompt log and second attack detection data corresponding to the illegal address access prompt log, and the first attack detection data and the second attack detection data are taken as attack detection data continuous in a time dimension; the continuous processing refers to data processing on log data obtained in a detection time interval; the time dimension refers to time in the detection time interval; The first attack detection data and the second attack detection data in the attack detection data are preprocessed to obtain attack time data for log division.

5. The method of claim 4, wherein, The continuous processing of the traffic surge prompt log and the illegal address access prompt log to obtain the first attack detection data corresponding to the traffic surge prompt log and the second attack detection data corresponding to the illegal address access prompt log comprises: A first detection time interval configured for the traffic surge prompt log is obtained, and log data in the traffic surge prompt log located in the first detection time interval is processed to obtain the first attack detection data corresponding to the traffic surge prompt log; A second detection time interval configured for the illegal address access prompt log is obtained, and log data in the illegal address access prompt log located in the second detection time interval is processed to obtain the second attack detection data corresponding to the illegal address access prompt log.

6. The method of claim 4, wherein, The data preprocessing of the first attack detection data and the second attack detection data in the attack detection data to obtain attack time data for log division comprises: A first attack time interval associated with the first attack detection data and a second attack time interval associated with the second attack detection data are obtained, and the first attack detection data and the second attack detection data are processed based on the first attack time interval and the second attack time interval to obtain aggregated detection data; the confidence included in the aggregated detection data is determined by a first confidence corresponding to the first attack detection data and a second confidence corresponding to the second attack detection data; Data with a confidence greater than an attack confidence threshold is obtained from the aggregated detection data, and the obtained data is taken as first-class attack time data; Data with a confidence less than or equal to the attack confidence threshold is obtained from the aggregated detection data, and when the obtained data meets an attack screening condition, data in the aggregated detection data that meets the attack screening condition is taken as second-class attack time data; The first-class attack time data and the second-class attack time data are taken as attack time data for log division.

7. The method of claim 1, wherein, The division of the aggregated access log into attack-class traffic logs and non-attack-class traffic logs based on the attack time data comprises: The log data in the aggregated access log that hits the attack time data is taken as initial attack log data, data aggregation is performed on the initial attack log data based on a second type of log field, and attack type traffic log is obtained; The log data in the aggregated access log that does not hit the attack time data is taken as initial service log data, data aggregation is performed on the initial service log data based on a third type of log field, and non-attack type traffic log is obtained.

8. The method of claim 1, wherein, The target service server in the service server that is attacked and the target access device in the access device that initiates an illegal access request to the target service server are determined based on the attack type traffic log and the non-attack type traffic log, and illegal access data associated with the target service server and the target access device is obtained, including: The access domain name contained in the attack type traffic log is taken as a target access domain name, the server indicated by the target access domain name is taken as the target service server in the service server that is attacked, and a legal access condition corresponding to the target access domain name is determined based on the log data associated with the target access domain name in the non-attack type traffic log; Log data that does not meet the legal access condition is obtained from the attack type traffic log as initial illegal data; When a trusted network address associated with the target access domain name is determined based on the legal access condition, an illegal network address is obtained from the network addresses contained in the initial illegal data based on the trusted network address, and the device indicated by the illegal network address is taken as the target access device in the access device that initiates an illegal access request to the target service server; the trusted network address is used to indicate a device in the access device that is trusted by the target service server; Data associated with the illegal network address obtained from the initial illegal data is taken as illegal access data associated with the target service server and the target access device.

9. The method of claim 8, wherein, The legal access condition corresponding to the target access domain name is determined based on the log data associated with the target access domain name in the non-attack type traffic log, including: Fluctuation analysis is performed on the log data associated with the target access domain name in the non-attack type traffic log, fluctuation analysis results for the target access domain name are obtained, and a first analysis data source is obtained from the non-attack type traffic log based on the fluctuation analysis results; Access frequency analysis is performed on the log data associated with the target access domain name in the non-attack type traffic log, a high-frequency access range for the target access domain name is obtained, and log data in the non-attack type traffic log whose access frequency is in the high-frequency access range is taken as a second analysis data source; The legal access condition corresponding to the target access domain name is determined based on the first analysis data source and the second analysis data source.

10. The method of claim 9, wherein, The first analysis data source is obtained from the non-attack type traffic log based on the fluctuation analysis results, including: If the fluctuation analysis result indicates that the access traffic to the target access domain name is smooth, log data located in the first type of attack time interval is obtained from the non-attack type traffic log as a first analysis data source; If the fluctuation analysis result indicates that the access traffic to the target access domain name fluctuates, log data located in the second type of attack time interval is obtained from the non-attack type traffic log as a first analysis data source; the range corresponding to the second type of attack time interval is greater than the range corresponding to the first type of attack time interval.

11. The method of claim 8, wherein, The legal access condition includes a legal request quantity threshold and a legal request rate threshold corresponding to the target access domain name; The obtaining of log data that does not meet the legal access condition from the attack type traffic log as initial illegal data includes: In the attack type traffic log, network addresses with access request quantity greater than the legal request quantity threshold or network addresses with access request rate greater than the legal request rate threshold in the attack time interval associated with the target access domain name are searched, the searched network addresses are taken as screened illegal network addresses, and log data associated with the screened illegal network addresses are taken as log data that does not meet the legal access condition; The log data that does not meet the legal access condition is obtained from the attack type traffic log, and the obtained log data is taken as initial illegal data.

12. The method of claim 8, wherein, The network addresses contained in the initial illegal data are screened illegal network addresses; In the determination of trusted network addresses associated with the target access domain name based on the legal access condition, the trusted network addresses are used to obtain illegal network addresses from the network addresses contained in the initial illegal data, including: Network addresses meeting the legal access condition are obtained from the attack type traffic log, and the obtained network addresses are added to the trusted network addresses associated with the target access domain name; Network addresses obtained after the trusted network addresses are removed from the screened illegal network addresses are taken as illegal network addresses; the illegal network addresses are network addresses other than the trusted network addresses in the screened illegal network addresses.

13. The method of claim 1, wherein, The attack degree evaluation of the illegal network addresses according to the illegal access data includes: The historical attack dimension information associated with the illegal network addresses is determined according to the illegal access data, the attack degree of the illegal network addresses to the target access domain name is evaluated based on the historical attack dimension information; the historical attack dimension information is used to represent the multidimensional characteristics of the illegal network addresses in historical attacks.

14. A data processing method, characterized by, The method is executed by a protection device, including: sending a service protection log and a service prompt log to an analysis server; the service protection log is used to determine an aggregated access log associated with an access device and a service server; the service prompt log is used to determine attack time data used for log division; an access request sent by the access device to the service server carries an access domain name of the service server and a network address of the access device; the attack time data is used to divide the aggregated access log into attack type traffic logs and non-attack type traffic logs; the attack type traffic logs and the non-attack type traffic logs are used to determine a target service server attacked in the service server and a target access device initiating an illegal access request to the target service server in the access device, and obtain illegal access data associated with the target service server and the target access device; the illegal access request carries a target access domain name of the target service server and an illegal network address of the target access device; the analysis server is used to evaluate an attack degree of the illegal network address against the target access domain name according to the illegal access data, and send the attack degree to the protection device; receiving the attack degree sent by the analysis server, and determining a protection strategy for the illegal network address based on the attack degree.

15. The method of claim 14, wherein, The determination of the protection strategy for the illegal network address based on the attack degree comprises: if the attack degree is within a first attack range, a first type of protection strategy is configured; the first type of protection strategy is used to intercept all illegal access requests initiated by the target access device to the target service server; if the attack degree is within a second attack range, an execution frequency control value for the illegal network address is obtained according to the attack degree, and a second type of protection strategy is configured based on the execution frequency control value; the second type of protection strategy is used to intercept illegal access requests initiated by the target access device to the target service server and exceeding the execution frequency control value; the first type of protection strategy or the second type of protection strategy is used as a protection strategy for the target access device.

16. A data processing apparatus, characterized by The device runs on an analysis server, and the device comprises: a log processing module configured to obtain a service protection log and a service prompt log reported by a protection device, determine an aggregated access log associated with an access device and a service server based on the service protection log, and determine attack time data used for log division based on the service prompt log; an access request sent by the access device to the service server carries an access domain name of the service server and a network address of the access device; a log division module configured to divide the aggregated access log into attack type traffic logs and non-attack type traffic logs based on the attack time data. The data acquisition module is configured to determine a target service server under attack in the service server and a target access device initiating an illegal access request to the target service server in the access device based on the attack type traffic log and the non-attack type traffic log, and obtain illegal access data associated with the target service server and the target access device; the illegal access request carries a target access domain name of the target service server and an illegal network address of the target access device; The attack evaluation module is configured to evaluate an attack degree of the illegal network address with respect to the target access domain name according to the illegal access data, and obtain an attack degree of the illegal network address with respect to the target access domain name; and the attack degree is used to determine a protection strategy for the illegal network address.

17. A data processing apparatus, characterized by The device runs on a protection device, and the device comprises: The log sending module is configured to send a service protection log and a service prompt log to an analysis server; the service protection log is used to determine an aggregated access log associated with an access device and a service server; the service prompt log is used to determine attack time data used for log division; an access request sent by the access device to the service server carries an access domain name of the service server and a network address of the access device; the attack time data is used to divide the aggregated access log into an attack type traffic log and a non-attack type traffic log; the attack type traffic log and the non-attack type traffic log are used to determine a target service server under attack in the service server and a target access device initiating an illegal access request to the target service server in the access device, and obtain illegal access data associated with the target service server and the target access device; the illegal access request carries a target access domain name of the target service server and an illegal network address of the target access device; the analysis server is used to evaluate an attack degree of the illegal network address with respect to the target access domain name according to the illegal access data, and send the attack degree to the protection device; The policy determination module is configured to receive the attack degree sent by the analysis server, and determine a protection strategy for the illegal network address based on the attack degree.

18. A computer device, comprising: It comprises: A processor and a memory; The processor is connected with the memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program to enable a computer device to execute the method in any one of claims 1-15.

19. A computer-readable storage medium, characterized in that, A computer program is stored in a computer readable storage medium, and the computer program is adapted to be loaded and executed by a processor to enable a computer device with the processor to execute the method in any one of claims 1-15.

20. A computer program product, characterised in that, A computer program product comprises computer instructions stored in a computer readable storage medium, and the computer instructions are adapted to be read and executed by a processor to enable a computer device with the processor to execute the method in any one of claims 1-15.