RDMA traffic DDoS attack detection method and system in edge computing power network environment
By combining the PCC function module of the DPU network card and the GRU algorithm model at the edge computing node, RDMA traffic characteristics are extracted and time-series analysis is performed, solving the real-time and efficiency problems of RDMA traffic DDoS attack detection in high-performance computing environments, and achieving efficient attack detection and identification.
Patent Information
- Application Number
- CN202511213758.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-28
- Publication Date
- 2025-11-18
AI Technical Summary
In high-performance computing and data center environments, DDoS attack detection of RDMA traffic faces challenges in meeting real-time and efficiency requirements, especially in edge computing environments where resources are scarce and centralized detection equipment cannot effectively handle large-scale RDMA traffic.
By combining the PCC function module and GRU algorithm model of the DPU network card, lightweight detection of edge computing nodes is performed, RDMA traffic characteristic data is extracted and time-series analysis is performed, abnormal traffic is initially screened, and abnormal data is sent to the cloud for in-depth analysis.
It improves the efficiency of DDoS attack detection, reduces network traffic transmission and cloud server computing burden, and achieves efficient attack detection and identification.
Smart Images

Figure CN120979753A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure belongs to the technical field of network security, and particularly relates to a RDMA traffic DDoS attack detection method and system in an edge computing network environment. BACKGROUND
[0002] In modern network environments, distributed denial of service (DDoS) attacks have become an important problem in the field of network security. Traditional DDoS attack detection methods mainly rely on centralized gateway devices, which prevent attacks through a large amount of traffic analysis and filtering. However, with the increasing network traffic, especially in high-performance computing and data center environments, DDoS attack detection faces great challenges. In particular, in high-bandwidth and low-latency networks using RDMA (remote direct memory access) technology, traditional DDoS detection methods often fail to meet the real-time and efficiency requirements.
[0003] RDMA is a network protocol that allows direct access to remote computer memory, moving data in a buffer between two applications over a network, and is widely used in high-performance computing, big data analysis, and other scenarios. Due to its high bandwidth and low latency characteristics, RDMA network traffic is more intensive and complex than traditional network traffic. Traditional DDoS attack detection devices are mostly based on centralized gateways, which perform unified analysis of all network traffic. However, RDMA traffic has characteristics such as high throughput and multi-burst, and centralized detection gateways may have problems such as computing resource and bandwidth bottlenecks. In particular, in edge computing environments, data center resources are scarce, and centralized computing cannot effectively handle large-scale RDMA traffic detection and analysis.
[0004] Currently, DPU (Data Processing Unit) network cards with RDMA functionality have some computing power and traffic extraction modules, such as PCC (Programmable Congestion Control) functional modules. The PCC functional module was originally designed for congestion control, but due to its powerful traffic extraction capabilities, it can be used to extract feature information of network traffic and provide data support for DDoS attack detection. However, existing technologies have not fully utilized the PCC functional module for early detection of DDoS attacks, and lack effective solutions for lightweight computing on the edge side. SUMMARY
[0005] To solve the above problems, the present disclosure provides a RDMA traffic DDoS attack detection method and system in an edge computing environment, which realizes efficient RDMA traffic DDoS attack detection by combining the PCC function module in the DPU network card with the GRU (Gated Recurrent Unit, a modified recurrent neural network structure) algorithm model in the edge computing environment.
[0006] The present disclosure preferably implements the following embodiments: In a first aspect, the present disclosure provides a RDMA traffic DDoS attack detection method in an edge computing environment, comprising: extracting traffic feature data of the RDMA traffic by using the PCC function module in the DPU network card; transmitting the extracted traffic feature data to the edge computing node for preprocessing by the PCC function module; performing time series analysis on the preprocessed traffic feature data by using the GRU algorithm model in the DPU network card to determine whether the current RDMA traffic belongs to a normal mode; uploading the traffic feature data determined as abnormal to the cloud for deep analysis by the cloud server to accurately identify the attack type.
[0007] Further, determining whether the current RDMA traffic belongs to a normal mode, comprising: if the current RDMA traffic belongs to a normal mode, continue processing in the edge computing node.
[0008] Further, The method further comprises: the edge computing node takes protective measures according to the identification result of the cloud server.
[0009] Further, The DPU network card is arranged in the edge computing node.
[0010] Further, performing time series analysis on the preprocessed traffic feature data by using the GRU algorithm model in the DPU network card to determine whether the current RDMA traffic belongs to a normal mode, comprising: identifying and analyzing the long-term dependence relationship in the network traffic, determining whether the network traffic has abnormal fluctuations, predicting potential DDoS attacks, and then preliminarily screening the RDMA traffic.
[0011] In a second aspect, the embodiments of the present disclosure further provide a RDMA traffic DDoS attack detection system in an edge computing environment, comprising a traffic extraction module, a data preprocessing module, a time series analysis module, and a data uploading module. a traffic extraction module that monitors and analyzes RDMA traffic in real time by using the PCC function module and extracts traffic feature data of the RDMA traffic; a data preprocessing module configured to preprocess the traffic feature data; a time series analysis module configured to perform time series analysis on the preprocessed traffic feature data by using a GRU algorithm model to determine whether the current RDMA traffic belongs to a normal mode; a sending module configured to send the traffic feature data determined as abnormal to a cloud end for deep analysis.
[0012] Further, Further, the method further includes a report generation module configured to generate a DDoS attack detection report by a cloud end server and return the report to the edge computing node.
[0013] In a third aspect, the embodiments of the present disclosure further provide an electronic device including at least one processor and at least one memory electrically connected, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method for detecting DDoS attack of RDMA traffic in an edge computing network environment as described above.
[0014] In a fourth aspect, the embodiments of the present disclosure further provide a computer readable storage medium, wherein the computer readable storage medium stores a computer program, and the computer program is executed by a processor to implement the method for detecting DDoS attack of RDMA traffic in an edge computing network environment as described above.
[0015] In a fifth aspect, the embodiments of the present disclosure further provide a computer program product stored in at least one storage medium, and the computer program product includes a plurality of instructions for causing at least one computer device to perform the method for detecting DDoS attack of RDMA traffic in an edge computing network environment as described above.
[0016] The present disclosure extracts key features of RDMA traffic by using the PCC function module in the DPU network card, provides data support for DDoS attack detection, performs data analysis and prediction by using the GRU algorithm model, performs preliminary detection by the edge computing node, and sends traffic data to the cloud end for deep analysis and tracing when abnormality occurs.
[0017] Compared with the prior art, the present disclosure has the following advantages: The present disclosure uses a light-weight computing device with a PCC function module and a GRU algorithm model on the edge computing node side, reduces the burden of network traffic sending and cloud server centralized computing, and improves the efficiency of DDoS attack detection.
[0018] Other features and advantages of this disclosure will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the disclosure. The objects and other advantages of this disclosure may be realized and obtained by means of the structures pointed out in the description, claims and drawings. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 A schematic diagram of a single-machine internal architecture of a DPU network card according to an embodiment of the present disclosure is shown; Figure 2 A system architecture diagram of an edge computing network according to an embodiment of the present disclosure is shown; Figure 3 A schematic diagram of a DDoS attack detection process according to an embodiment of the present disclosure is shown; Figure 4 A schematic diagram of an electronic device structure according to an embodiment of the present disclosure is shown.
[0021] Figure 2 middle: DPU stands for DPU network interface card; QPC stands for Queue Pair Context, used to store QP-related attributes; CC-RX stands for register; Event_q stands for event q; Arm stands for ARM development platform; Host stands for host interface or device interface; eswitch stands for Embedded Switch; pkt stands for data packet. Detailed Implementation
[0022] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0023] Figure 1A schematic diagram of the internal architecture of a single DPU network interface card according to an embodiment of the present disclosure is shown. The single DPU network interface card includes: an embedded switch, an RDMA engine, an Arm development module, and a Host interface.
[0024] The RDMA engine enables the DPU network card to directly read and write memory by offloading data transfer protocols (such as InfiniBand or RoCE) through hardware, without requiring deep involvement of the remote computer's CPU.
[0025] The Arm development module is used to implement the PCC functional module and the GRU algorithm model.
[0026] The Host interface is used to connect the DPU network card to a host or computing device.
[0027] The PCC module extracts traffic characteristic data from RDMA traffic, such as traffic patterns, packet size, traffic rate, and latency, as input to the GRU algorithm model. The GRU algorithm model performs time-series prediction on the (preprocessed) traffic characteristic data, identifies and analyzes long-term dependencies in network traffic, determines whether there are abnormal fluctuations in network traffic, predicts potential DDoS attacks, and then performs preliminary screening of RDMA traffic.
[0028] Specifically, the GRU algorithm model can preliminarily determine whether traffic belongs to the normal mode by setting thresholds or classification methods, and determine whether abnormal data needs to be sent to the cloud.
[0029] This disclosure provides a method for detecting RDMA traffic DDoS attacks in an edge computing network environment, applicable to... Figure 2 The edge computing network system shown. Figure 2 The structure of a mid-edge computing network system includes: edge computing nodes, DPU network interface cards (DPUs) (not shown), and cloud servers. Multiple edge computing nodes constitute the system. Figure 2 Edge clusters in the middle, Figure 2 The centralized situational awareness and intrusion detection center is located on a cloud server.
[0030] Each edge computing node deployed at the network edge is equipped with the DPU network interface card described in the embodiments of this disclosure. The edge computing node utilizes the DPU network interface card to perform preliminary DDoS attack detection.
[0031] The cloud server receives initial detection data from edge computing nodes, and performs in-depth packet analysis and detailed attack analysis, especially when abnormal traffic is initially detected. The powerful computing capabilities of the cloud server can provide more sophisticated attack identification and protection strategies.
[0032] Corresponding to the aforementioned edge computing network system, the RDMA traffic DDoS attack detection method in the edge computing network environment of this disclosure embodiment relies on setting up a DPU network card with a PCC function module and a GRU algorithm module at the edge computing node. The PCC function module not only has RDMA traffic regulation function, but also can extract a large amount of RDMA traffic feature data, which can be used for DDoS attack detection.
[0033] See appendix Figure 3 The method for detecting RDMA traffic DDoS attacks in an edge computing network environment according to this disclosure includes: S1, RDMA traffic acquisition.
[0034] The PCC function module in the DPU network card is used to extract the traffic characteristic data of RDMA traffic.
[0035] Key traffic characteristic data may include, but is not limited to, some or all of the following data types: (1) QP (Queue Pair) Metric: Each network connection is represented by a QP, and the QP ID is an important identifier for different network connections. By analyzing the traffic of different QPs, abnormal connection patterns can be identified. According to the description in the IB protocol, a QP is a virtual interface between hardware and software; a QP consists of a transmit queue SQ and a receive queue RQ.
[0036] (2) SQ (Send Queue) and RQ (Receive Queue): The PCC function module monitors the status of the Send Queue and Receive Queue, detects abnormal queue lengths and queuing conditions, and reveals abnormal fluctuations in RDMA traffic.
[0037] (3) Packet size: The PCC function module extracts packet size information from RDMA traffic. By monitoring the size distribution of packets, abnormal packet size patterns commonly found in DDoS attacks can be detected.
[0038] (4) Latency: Latency is an important indicator for measuring the performance of RDMA traffic. The PCC function module provides real-time latency data. DDoS attack traffic may cause abnormal latency distribution. By monitoring latency changes, potential DDoS attacks can be identified.
[0039] (5) Throughput: The PCC functional module provides traffic throughput data, which reflects the data transmission rate of RDMA traffic. DDoS attacks usually cause drastic fluctuations in traffic throughput, and the PCC functional module can provide this fluctuation information for the GRU algorithm model to analyze.
[0040] (6) Packet loss rate: The PCC function module can monitor the packet loss rate. When there is a DDoS attack in the network connection, the packet loss rate will usually increase. The packet loss rate data can be used to further determine whether a DDoS attack is present.
[0041] (7) Error statistics: The PCC function module records errors in the data transmission of RDMA traffic (such as packet loss, retransmission, etc.). These statistics can reveal abnormal network conditions and are an important basis for judging whether there is a DDoS attack.
[0042] (8) Source and destination IP addresses: The location and direction of the specific malicious traffic are located by recording the original data packets.
[0043] The aforementioned traffic characteristics provide rich input for the GRU algorithm model, enabling it to perform accurate time-series analysis and DDoS attack detection.
[0044] S2, Preprocessing of traffic characteristic data.
[0045] The PCC module transmits the extracted traffic feature data to edge computing nodes for preprocessing such as denoising and normalization.
[0046] S3, GPU timing analysis.
[0047] The GRU algorithm model in the DPU network interface card is used to perform time-series analysis on the preprocessed traffic characteristic data to determine whether the current RDMA traffic belongs to the normal mode. If the GRU algorithm model detects an anomaly, it indicates a possible DDoS attack. If the current RDMA traffic belongs to the normal mode, processing continues at the edge computing node.
[0048] S4, uploaded to the cloud.
[0049] Traffic data deemed abnormal is sent to the cloud for in-depth analysis by the cloud server to accurately identify the attack type.
[0050] As a further preferred approach, edge computing nodes take protective measures (such as blocking the attack source IP and filtering malicious traffic) based on the identification results (decision response) of the cloud server.
[0051] Another preferred approach is that the cloud server also generates a DDoS attack detection report and returns it to the edge computing nodes to help further optimize the attack detection strategy.
[0052] Based on the above method, this disclosure also provides a DDoS attack detection system corresponding to the above attack detection method, including a traffic extraction module, a data preprocessing module, a time series analysis module, and a data uploading module.
[0053] The traffic extraction module uses the PCC function module to monitor and analyze RDMA traffic in real time, and extracts the traffic characteristic data of RDMA traffic. The data preprocessing module is used to preprocess traffic characteristic data; The timing analysis module uses the GRU algorithm model to perform timing analysis on the preprocessed traffic characteristic data to determine whether the current RDMA traffic belongs to the normal mode. The upload module is used to upload traffic feature data that is judged to be abnormal to the cloud for in-depth analysis.
[0054] As a preferred option, a report generation module is also included, which is used by the cloud server to generate DDoS attack detection reports and return them to the edge computing nodes to assist in further optimizing attack detection strategies.
[0055] Based on the same inventive concept as the above-disclosed content, this disclosure also provides an electronic device. For example... Figure 4 As shown, the electronic device of this disclosure embodiment includes at least one processor and at least one memory electrically connected to the processor. The memory is electrically connected to the processor, wherein the memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the RDMA traffic DDoS attack detection method in the edge computing network environment as described above.
[0056] It should be noted that the electrical connection between the above-mentioned units does not necessarily mean the connection between lines. The indirect connection method can be applied to the embodiments of this disclosure as long as it achieves the purpose of this disclosure.
[0057] Based on the same inventive concept, this disclosure also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the RDMA traffic DDoS attack detection method described above in an edge computing network environment.
[0058] Based on the same inventive concept, this disclosure also provides a computer program product, which is stored in at least one storage medium; the computer program product includes several instructions to cause at least one computer device to execute the RDMA traffic DDoS attack detection method in the edge computing network environment as described above.
[0059] Although the present disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.
Claims
1. A method for detecting RDMA traffic DDoS attacks in an edge computing network environment, characterized in that, The method includes, The PCC function module in the DPU network card is used to extract the traffic characteristic data of RDMA traffic; The PCC function module transmits the extracted traffic feature data to the edge computing node for preprocessing; The GRU algorithm model in the DPU network card is used to perform time-series analysis on the preprocessed traffic characteristic data to determine whether the current RDMA traffic belongs to the normal mode. Traffic data deemed abnormal is sent to the cloud for in-depth analysis by the cloud server to accurately identify the attack type.
2. The method according to claim 1, characterized in that, Determining whether the current RDMA traffic belongs to normal mode includes: If the current RDMA traffic is in normal mode, it will continue to be processed at the edge computing node.
3. The method according to claim 1 or 2, characterized in that, The DPU network interface card is installed within the edge computing node.
4. The method according to claim 1, characterized in that, The GRU algorithm model in the DPU network card is used to perform time-series analysis on the preprocessed traffic characteristic data to determine whether the current RDMA traffic belongs to the normal mode, including: Identify and analyze long-term dependencies in network traffic, determine whether there are abnormal fluctuations in network traffic, predict potential DDoS attacks, and then perform preliminary screening of RDMA traffic.
5. The method according to claim 1, 2, or 4, characterized in that, The method further includes: Edge computing nodes take protective measures based on the identification results from the cloud server.
6. A DDoS attack detection system for RDMA traffic in an edge computing network environment, characterized in that, The system includes a traffic extraction module, a data preprocessing module, a time series analysis module, and a data uploading module; The traffic extraction module uses the PCC function module to monitor and analyze RDMA traffic in real time, and extracts the traffic characteristic data of RDMA traffic. The data preprocessing module is used to preprocess traffic characteristic data; The timing analysis module uses the GRU algorithm model to perform timing analysis on the preprocessed traffic characteristic data to determine whether the current RDMA traffic belongs to the normal mode. The upload module is used to upload traffic feature data that is judged to be abnormal to the cloud for in-depth analysis.
7. The system according to claim 6, characterized in that, It also includes a report generation module, which is used by the cloud server to generate DDoS attack detection reports and return them to the edge computing nodes.
8. An electronic device, characterized in that, Includes at least one processor and at least one memory electrically connected; The memory stores instructions that can be executed by at least one of the processors, which are executed by at least one of the processors to enable the at least one of the processors to perform the RDMA traffic DDoS attack detection method in an edge computing network environment as described in any one of claims 1-5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program. When the computer program is executed by the processor, it implements the RDMA traffic DDoS attack detection method in the edge computing network environment as described in any one of claims 1-5.
10. A computer program product, characterized in that, The computer program product is stored in at least one storage medium; The computer program product includes several instructions to cause at least one electronic device to execute the RDMA traffic DDoS attack detection method in the edge computing network environment as described in any one of claims 1-5.
Citation Information
Patent Citations
Active security defense method based on network traffic time pattern and data volume analysis
CN119966731A
Distributed denial of service (DDOS) based artificial intelligence (AI) accelerated solution using a data processing unit (DPU)
US20250097260A1
Congestion control method and corresponding device
WO2025152402A1
Cited By
Automatic network diagnosis method, system, chip, network card and equipment based on DPU (Data Processing Unit)
CN121309333A
Method, system, chip, network card and device for automatic diagnosis of network based on DPU
CN121309333B