DDoS attack protection method and device
By using time-division window statistics to collect flow table traffic data in SDN networks, DDoS attacks can be identified and handled, thus solving the security problem of SDN network architecture under DDoS attacks, simplifying the networking process of smart home devices and improving gateway security.
Patent Information
- Application Number
- CN202511388064.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-25
- Publication Date
- 2025-11-18
AI Technical Summary
When facing DDoS attacks, SDN network architectures have low gateway security and are difficult to protect effectively.
By acquiring flow tables within a preset period, traffic data is divided into multiple time windows for statistical analysis. The statistical results are used to identify DDoS attacks and process the attack traffic, including redirection and dropping. The device networking is automatically completed using the identity information of each home device.
It simplifies the networking process for smart home devices, improves gateway security, reduces system overhead, and enhances the rational allocation and utilization efficiency of network resources.
Smart Images

Figure CN120979813A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and more specifically, to a method and apparatus for protecting against DDoS attacks. Background Technology
[0002] The converged gateway adopts an SDN (Software Defined Network) architecture that separates the data forwarding layer from the network control layer. General-purpose hardware is used to implement the functions of the data forwarding layer, while the network control layer is implemented in software, with communication between the two layers handled by software programs. DDoS (Distributed Denial of Service) attacks are one of the major threats currently facing the internet. Attackers control a large number of compromised machines to send illegal requests to a target host simultaneously, exhausting the target host's bandwidth or computing resources and preventing it from responding to legitimate requests. SDN network architectures, like traditional network architectures, will face the challenge of DDoS attacks. Summary of the Invention
[0003] This application provides a method and apparatus for protecting against DDoS attacks, thereby at least solving the technical problem in the related art where gateway security is low due to DDoS attacks on SDN network architecture.
[0004] According to one aspect of the embodiments of this application, a method for protecting against DDoS attacks is provided, comprising: acquiring flow tables according to a preset period; dividing the traffic data in the flow tables into traffic data of multiple time windows, and performing statistics on the traffic data in each time window to obtain statistical results; determining whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results; and, if the DDoS attack has occurred, processing the traffic corresponding to the DDoS attack.
[0005] Optionally, determining whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results includes: obtaining the number of traffic data with the destination address as the address to be detected within each time window from the statistical results; comparing the number of traffic data with the destination address as the address to be detected within each time window with a first threshold to obtain a comparison result; and determining whether the address to be detected is subjected to the DDoS attack based on the comparison result.
[0006] Optionally, determining whether the address to be detected is under DDoS attack based on the comparison result includes: identifying an abnormal time window as the time window in which the number of traffic data with the destination address of the address to be detected, as indicated by the comparison result, is greater than a first threshold; obtaining traffic data with the destination address of the address to be detected within multiple consecutive time windows after the abnormal time window from the statistical results; and determining that the address to be detected is under DDoS attack if the number of traffic data with the destination address of the address to be detected within the multiple consecutive time windows is greater than a second threshold.
[0007] Optionally, the traffic data within each time window is statistically analyzed to obtain statistical results, including: obtaining the destination address of the traffic data within each time window; if the destination address is in a preset hash table, changing the counter count of the destination address; if the destination address is not in the preset hash table, adding the destination address to the preset hash table; and determining the statistical results based on the counter count.
[0008] Optionally, the method further includes: if the number of traffic data whose destination address is the address to be detected, as indicated by the comparison result, is not greater than the first threshold, then determining that the address to be detected has not been subjected to the DDoS attack.
[0009] Optionally, the method further includes: if the number of traffic data with the destination address being the address to be detected within the consecutive multiple time windows is not greater than the second threshold, then determining that the address to be detected has not been subjected to the DDoS attack.
[0010] Optionally, the traffic corresponding to the DDoS attack is processed, including: redirecting the traffic data of the address to be detected to a new address; if the new address is detected to be under the DDoS attack, obtaining the source address of the traffic data corresponding to the DDoS attack; and discarding the traffic data whose source address is the source address of the traffic data corresponding to the DDoS attack.
[0011] According to another aspect of the embodiments of this application, a DDoS attack protection device is also provided, comprising: an acquisition module, configured to acquire flow tables according to a preset period; a statistics module, configured to divide the traffic data in the flow tables into traffic data of multiple time windows, and perform statistics on the traffic data in each time window to obtain a statistical result; a determination module, configured to determine whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical result; and a processing module, configured to process the traffic corresponding to the DDoS attack if it is determined that the DDoS attack has occurred.
[0012] According to another aspect of the embodiments of this application, a computer device is also provided, including: a memory and a processor, wherein the memory is used to store program instructions; the processor, connected to the memory, is used to execute the above-described method for protecting against DDoS attacks.
[0013] According to another aspect of the embodiments of this application, a computer program product is also provided, including computer instructions that, when executed by a processor, implement the above-described method for protecting against DDoS attacks.
[0014] In this embodiment, flow tables are acquired according to a preset period; the traffic data in the flow tables is divided into traffic data for multiple time windows, and the traffic data in each time window is statistically analyzed to obtain statistical results; based on the statistical results, it is determined whether a distributed denial-of-service (DDoS) attack has occurred; if a DDoS attack is determined to have occurred, the traffic corresponding to the DDoS attack is processed, and device networking is automatically completed using the identity information of each home device, thereby simplifying the smart home device networking process and solving the technical problem of low gateway security caused by DDoS attacks on SDN network architecture in related technologies. Attached Figure Description
[0015] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0016] Figure 1 This is a hardware structure block diagram of a computer terminal for implementing a DDoS attack protection method according to an embodiment of this application.
[0017] Figure 2 This is a flowchart of a DDoS attack protection method according to an embodiment of this application;
[0018] Figure 3 This is a schematic diagram of the structure of a DDoS attack protection system according to an embodiment of this application;
[0019] Figure 4 This is a flowchart of a DDoS attack protection method according to an embodiment of this application;
[0020] Figure 5 This is a flowchart illustrating the distribution of a DDoS attack handling strategy according to an embodiment of this application;
[0021] Figure 6 This is a structural diagram of a DDoS attack protection device according to an embodiment of this application. Detailed Implementation
[0022] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0023] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0024] The information collected in this application embodiment is information and data authorized by the user or fully authorized by all parties. The collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant regions, and necessary confidentiality measures have been taken. It does not violate public order and good morals, and provides corresponding operation entry points for users to choose to authorize or reject the automated decision results. If the user chooses to reject, the process will proceed to the expert decision-making process.
[0025] To address the problems existing in related technologies, this application provides a method for protecting against DDoS attacks, which can be implemented in... Figure 1 The computer terminal shown is explained below.
[0026] The DDoS attack protection method embodiments provided in this application can be executed on mobile terminals, computer terminals or similar computing devices. Figure 1 A hardware block diagram of a computer terminal for implementing a DDoS attack protection method is shown. Figure 1As shown, the computer terminal 10 may include one or more processors (shown as 102a, 102b, ..., 102n in the figure) (the processor may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission module 106 for communication functions connected via wired and / or wireless networks. In addition, it may also include: a display, a keyboard, a cursor control device, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, and a BUS bus. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0027] It should be noted that the aforementioned one or more processors and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be implemented wholly or partially as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be wholly or partially integrated into any other element in the computer terminal 10. As involved in the embodiments of this application, the data processing circuits serve as processor control (e.g., selection of a variable resistor termination path connected to an interface).
[0028] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the DDoS attack protection method in this embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the aforementioned DDoS attack protection method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0029] The transmission module 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission module 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission module 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0030] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10.
[0031] It should be noted here that, in some optional embodiments, the above... Figure 1 The computer terminal shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 1 This is only one instance of a specific particular instance, and is intended to illustrate the types of components that may exist in the aforementioned computer terminal.
[0032] In the above operating environment, this application provides an embodiment of a DDoS attack protection method. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0033] Figure 2 This is a flowchart of a DDoS attack protection method according to an embodiment of this application, such as... Figure 2 As shown, the method includes the following steps:
[0034] Step S202: Obtain the flow table according to a preset cycle;
[0035] In step S202, the flow table represents a concept in a Software Defined Networking (SDN) environment, closely related to the OpenFlow protocol (a network protocol). In an SDN architecture, the network control plane and data forwarding plane are separated, with data forwarding tasks typically performed by network switches. Flow tables exist within these switches to guide packet processing and forwarding. Each row in the flow table is a flow entry, containing key fields defining the flow (such as source / destination IP, port number, etc.) and corresponding actions (such as forwarding to a specific port, dropping, modifying the packet, etc.). When a packet arrives at the switch, it is matched against various flow entries in the flow table. If a matching entry is found, the packet is processed according to the action specified in that entry. These actions may include, but are not limited to, forwarding the packet to a specified physical port, dropping the packet, modifying certain fields of the packet (e.g., changing the TTL value), or reporting the existence of the flow to the SDN controller (through a secure channel).
[0036] It's important to further explain that a DDoS attack (Distributed Denial of Service attack) is a network attack method where attackers use multiple compromised computers (usually infected with malware, forming a so-called "botnet") to simultaneously send a large number of legitimate and illegitimate requests to a target server or network. The aim is to exhaust the target's network bandwidth, computing resources, or service responsiveness, thereby preventing legitimate users from accessing services or resources normally.
[0037] Step S204: Divide the flow data in the flow table into flow data of multiple time windows, and perform statistics on the flow data in each time window to obtain statistical results;
[0038] Step S206: Determine whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results.
[0039] Step S208: If it is determined that the DDoS attack has occurred, process the traffic corresponding to the DDoS attack.
[0040] Through steps S202 to S208 above, flow tables are obtained according to a preset period; the traffic data in the flow tables is divided into traffic data for multiple time windows, and the traffic data within each time window is statistically analyzed to obtain statistical results; based on the statistical results, it is determined whether a Distributed Denial-of-Service (DDoS) attack has occurred; if a DDoS attack is determined to have occurred, the traffic corresponding to the DDoS attack is processed, and device networking is automatically completed using the identity information of each home device, thereby simplifying the smart home device networking process and solving the technical problem of low gateway security due to DDoS attacks on SDN network architecture in related technologies. The following is a detailed explanation.
[0041] Figure 3 A schematic diagram of a gateway structure is shown, such as Figure 3 As shown, the gateway control plane includes a flow table collection module, a detection module, and a defense module. The flow table collection module is responsible for collecting and preprocessing flow table information. The controller periodically initiates flow table queries to the switch. The flow table collection module collects the flow table information obtained by the controller, sorts it by reception time, preprocesses the information to extract key information, and sends the processed flow table information to the detection module in window units for detection. The detection module is used to detect attacks. After receiving data from the flow table collection module, the detection module uses an optimized entropy algorithm to calculate the data to identify whether the traffic in that window is abnormal. After judging multiple consecutive windows, it finally determines whether an attack has occurred. If an attack has occurred, it sends an alarm to the defense module. The defense module is responsible for attack defense. After receiving an attack warning from the detection module, this module uses a redirection mechanism to protect the victim host, while continuing to monitor and count traffic originating from the original victim host's address. When the count exceeds a threshold, the traffic is determined to be attack traffic, and the corresponding policy is blocked.
[0042] In some embodiments of this application, the specific method for determining whether a Distributed Denial-of-Service (DDoS) attack has occurred based on the statistical results is as follows: obtain the number of traffic data with the destination address being the address to be detected within each time window from the statistical results; compare the number of traffic data with the destination address being the address to be detected within each time window with a first threshold to obtain a comparison result, and determine whether the address to be detected is subjected to the DDoS attack based on the comparison result.
[0043] The specific steps for determining whether the address to be detected is under DDoS attack based on the comparison results are as follows: The time window in which the number of traffic data destined for the address to be detected, as indicated by the comparison results, exceeds a first threshold, is identified as an abnormal time window; traffic data destined for the address to be detected within multiple consecutive time windows following the abnormal time window is obtained from the statistical results; if the number of traffic data destined for the address to be detected within the multiple consecutive time windows exceeds a second threshold, it is determined that the address to be detected is under DDoS attack.
[0044] If the number of traffic data whose destination address is the address to be detected, as indicated by the comparison result, is not greater than the first threshold, it is determined that the address to be detected has not been subjected to the DDoS attack.
[0045] If the number of traffic data destined for the address to be detected within the specified multiple consecutive time windows is not greater than the second threshold, it is determined that the address to be detected has not been subjected to the DDoS attack.
[0046] There are various ways to collect traffic data. This application provides a method for obtaining statistical results: obtaining the destination address of the traffic data within each time window; if the destination address is in a preset hash table, changing the counter count of the destination address; if the destination address is not in the preset hash table, adding the destination address to the preset hash table; and determining the statistical result based on the counter count.
[0047] After detecting a DDoS attack, the traffic corresponding to the DDoS attack is processed as follows: the traffic data of the address to be detected is redirected to a new address; if the new address is detected to be under DDoS attack, the source address of the traffic data corresponding to the DDoS attack is obtained; and the traffic data whose source address is the source address of the traffic data corresponding to the DDoS attack is discarded.
[0048] like Figure 3 As shown, the gateway also includes: the converged gateway forwarding plane 1 contains:
[0049] Flow table collection module 11: Responsible for collecting and preprocessing flow table information. The controller periodically initiates flow table queries to the switch. The flow table collection module collects the flow table information obtained by the controller, sorts it according to the receiving time, preprocesses the flow table information, extracts key information, and sends the processed flow table information to the DDoS detection module in window units for detection.
[0050] Flow table collection 111: This module mainly uses the OpenFlow protocol to collect flow tables.
[0051] Flow table preprocessing 112: During the matching process, if a packet matches an existing entry in the switch, the switch will execute the corresponding action. If the packet does not match any of the existing flow tables in the switch, it will be forwarded to the controller through a secure channel. Upon receiving the packet, the controller will determine the next action, such as generating a new flow table and pushing it to the switch. Simultaneously, as mentioned in the previous section, the controller will periodically initiate flow table queries to the switch, and the switch will respond with all of its own flow table entries.
[0052] Monitoring Module 12: After receiving flow table information sent in window units, the detection module calculates and compares it with a threshold to determine whether the traffic in that window is abnormal. Then, it uses multiple consecutive abnormal windows to determine if an attack has occurred.
[0053] Traffic Calculation 121: By comparing the calculated traffic value with a dynamically generated threshold, it is determined whether the traffic in the window is abnormal. If it is abnormal, the abnormal window counter is triggered.
[0054] Attack Detection 122: This module determines whether an attack has occurred by analyzing multiple consecutive windows.
[0055] Defense Module 13: Responsible for attack defense. Upon receiving an attack warning from the DDoS detection module, this module will employ a redirection mechanism to protect the victim host. Simultaneously, it will continue to monitor and count traffic originating from the original victim host's address. When the count exceeds a threshold, the traffic is determined to be attack traffic, and its corresponding policy will be blocked.
[0056] Traffic redirection 131: Service redirection is the process of transferring a service to a new IP address, port, or URL to continue providing the service.
[0057] Policy distribution 132: Responsible for policy control of identified attack traffic, and policy distribution to the forwarding plane.
[0058] Converged Gateway Forwarding Plane 2 includes:
[0059] Flow table generation module 21: Processes the flow table generation logic on the converged gateway to complete the access of broadband users to cloud services and cloud applications, and supports cloud service provisioning and user management (authentication, billing);
[0060] Policy execution module 22: Drops traffic according to the policy issued by the control plane.
[0061] To better explain the methods for detecting DDoS attacks, Figure 4 A flowchart illustrating a method for detecting DDoS attacks is shown, such as... Figure 4As shown, Step 31: Receive new traffic information and perform traffic analysis; Step 32: Parse the packet data DstIP (address to be detected) and determine if DstIP already exists in the hash table; Step 33: If DstIP does not exist, add a new record to the hash table; Step 34: If DstIP exists, update the record and increment counter 1 by 1; Step 35: Make a judgment based on the counter count value; Step 311: Set the counting threshold to N. When the count value is not equal to N, allow traffic; Step 36: When the count value is equal to N, perform traffic calculation; Step 37: When the cumulative traffic is lower than the threshold, reset the count to zero and allow traffic; Step 38: When the cumulative traffic is higher than the threshold, increment counter 2 by 1; Step 39: Make a judgment based on the counter 2 count value; Step 310: When the counter 2 count value is equal to the set value M, it is determined that this DstIP has an attack behavior.
[0062] After detecting a DDoS attack, the process of issuing handling policies is as follows: Figure 5 As shown, it includes:
[0063] Step 1: The detection module detects a DDoS attack. Step 2: Upon detecting the attack, the DDoS defense module immediately sends a policy request to the forwarding plane, requesting processing of the attack traffic. Step 3: After receiving the request, the control plane begins configuring specific defense policies. Step 4: The control plane pushes the configured policies as flow tables to network devices (such as switches) in the affected area, updating the flow table entries to achieve real-time traffic control. Step 5: Upon receiving the updated flow table instructions, the forwarding plane begins redirecting legitimate traffic from the target host D to a backup or new IP address D', ensuring uninterrupted service. Step 6: The attacker still launches attacks towards the original IP address D, but this attack traffic is identified by the network devices and processed according to the new flow table rules. Step 7: Host D responds to external requests with the new IP address D', restoring service to normal. Step 8: Legitimate user or service requests are successfully redirected to the new address D', ensuring smooth data communication. Step 9: Although attackers continue to launch attacks against the original IP address D, their traffic has been dropped or filtered by network devices according to updated flow table rules. Step 10: Continuous monitoring mechanisms keep counting the attack traffic from address D to assess attack strength and duration, and adjust policies as necessary. Step 11: If it is confirmed that the attack traffic needs to be continuously blocked, the defense module directly configures and executes policies on switches or related devices to localize defense measures and quickly respond to changes in the attack. Step 12: Switches or other network devices execute defense policies, such as dropping traffic from specific source IP addresses, ports, or protocols, to ensure network security and stable operation.
[0064] Specifically, steps 1 to 4 are the DDoS attack sending requests to the host; steps 5 to 8 are the redirected host responding to the DDoS attack with the new IP address D'; steps 9 to 10 are the DDoS attack not responding to the redirection message, but continuing to access the original IP D'; steps 11 and 12 show the actions of configuring and executing the policy.
[0065] It is understood that the DDoS attack protection method provided in this application embodiment can obtain the periodicity of flow table data in real time and perform attack judgment, regardless of the type of DDoS attack. It is not limited to converged gateways; control and transfer separation devices in traditional and new network architectures are all applicable to this method. By merging packets into flows, system overhead is reduced while improving detection accuracy. The DDoS attack protection method provided in this application embodiment, based on flow detection technology, groups data packets with the same header into one flow, using flow feature analysis instead of packet analysis, which greatly reduces computational overhead. The detection algorithm consists of two parts: one is to obtain detection information by detecting the flow header, and the other is to detect whether network traffic is normal by detecting traffic patterns. In DDoS attack detection, if there are a large number of ICMP, TCP, or UDP packets in the network, and the flow size is large, then an ICMP, TCP, or UDP attack can be considered to have occurred in the network. This method uses the flow size and the percentage of the number of packets to determine a threshold, which determines whether the number of packets and the flow size are large-scale. The threshold calculation takes into account network and link conditions, such as the number of flows and the number of unique IP addresses in the captured traffic.
[0066] To better understand the DDoS attack protection method proposed in the embodiments of this application, another DDoS attack protection method is also proposed in the embodiments of this application, including:
[0067] Step 1: Flow table collection and preprocessing:
[0068] Flow table collection: The controller periodically sends flow table query requests to the switches in the network to collect all flow table information.
[0069] Data sorting: The collected flow table information is sorted according to the order of receipt time.
[0070] Flow table preprocessing: Extract key fields from the flow table information, such as source IP, destination IP, transport protocol type, number of flows, etc., and send the processed flow table information to the DDoS detection module in the form of a time window.
[0071] Step 2: DDoS Detection:
[0072] Traffic Calculation: Receives preprocessed flow table information and calculates the total traffic and the traffic ratio of each type of flow within each time window.
[0073] Threshold comparison: The calculated traffic value is compared with the dynamically generated threshold to determine whether there is abnormal traffic.
[0074] Abnormal Window Count: If the traffic of a window is marked as abnormal, start the abnormal window counter.
[0075] Attack detection: Observe the abnormal counts of multiple consecutive windows. Once the count reaches a predetermined threshold, it is determined that a DDoS attack is in progress.
[0076] Step 3: DDoS defense response:
[0077] Traffic redirection: Once a DDoS attack is detected, the controller redirects the victim's traffic to a secure node or honeypot to mitigate the impact of the attack on the target.
[0078] Policy distribution: The controller generates corresponding defense policies based on the attack type and distributes the policies to the switches.
[0079] Enforcement Policy: After receiving the policy, the switch begins to execute operations such as dropping malicious traffic and limiting the rate to prevent the DDoS attack from continuing.
[0080] The specific steps for traffic analysis and attack detection are as follows: Step 1: The controller receives new traffic information. Step 2: Analyze the packet data, especially the destination IP (DstIP). Step 3: Check if the DstIP is already recorded in the hash table: If not, add it as a new record and initialize counter 1. If it is already recorded, update counter 1 for the corresponding record in the hash table. Determine if the value of counter 1 reaches the preset threshold N. If not, allow traffic to pass. If it does, enter the traffic calculation stage: calculate the cumulative traffic and compare it with the dynamic threshold. If it is below the threshold, reset the counter to zero and allow traffic to pass. If it is above the threshold, increment counter 2 by 1. Determine if the value of counter 2 reaches another preset threshold M. If it does, confirm that this DstIP has suffered a DDoS attack; if not, continue monitoring.
[0081] In real-world applications, once a DDoS attack is confirmed, the controller begins to formulate a defense strategy. When a host is attacked, it first attempts to respond with a new IP address, D'. The attacker ignores the redirect response and continues the attack on the original IP, D'. The controller configures the switch to create a policy to drop all malicious traffic directed to the original IP, D'. Enforcing the policy, the switch begins filtering malicious traffic, effectively protecting the target host from DDoS attacks.
[0082] By rapidly adjusting network flow table rules, real-time monitoring and defense against DDoS attacks were achieved. This not only improved network security but also reduced the system load of traditional defense methods, and enhanced the rational allocation and utilization efficiency of network resources.
[0083] For example: The network environment has deployed an SDN architecture, which includes a central controller and multiple network devices (such as switches). Step 1: Flow Table Collection and Preprocessing: The controller periodically (e.g., every 5 seconds) queries flow table information from all switches. The flow table collection module starts, collecting flow table data returned by all switches. This data includes information such as the number of packets and bytes passing through each flow. The collected information is sorted and preprocessed to extract key indicators, such as the number of flows and packets for each target IP. Then, it is passed to the DDoS detection module in fixed time windows (e.g., 1 minute). Step 2: DDoS Detection: The preprocessed flow table data is fed into the detection module. The number of packets and the percentage of flow size for each target IP address are calculated, and these indicators are compared with thresholds dynamically calculated based on network conditions. If the detected traffic pattern is considered abnormal, an abnormal window counter is triggered, and the abnormality is observed to persist within multiple consecutive time windows to ultimately confirm the attack behavior. Step 3: Attack Confirmation and Redirection: If large-scale abnormal traffic to the target IP is detected and continues to exceed the preset window number, such as 3 consecutive windows... The DDoS detection module sends an alert to the defense module, which simultaneously begins redirecting legitimate traffic from the target IP to another IP address. Legitimate traffic is successfully redirected to the new address, while attack traffic continues to target the IP and is marked as pending. Step Four: Policy Deployment and Execution: The DDoS defense module generates a traffic filtering policy for the target IP, requiring the controller to drop all illegitimate traffic (traffic exceeding the threshold). The controller pushes the policy in flow table form to all relevant switches, updating their forwarding rules. The switches begin executing the updated flow table rules, intercepting and dropping all suspicious packets. Simultaneously, the switches continue to monitor traffic flowing to the new address to ensure no new attacks occur. Step Five: Continuous Monitoring and Optimization: Even after the attack is initially mitigated, the system continues to monitor network traffic to ensure no new attack waves emerge or attackers find new attack points. Based on monitoring results, the defense module may adjust thresholds or policies to adapt to changing network conditions and attack trends.
[0084] Figure 6 A DDoS attack protection device is shown, which includes:
[0085] Module 60 is used to acquire flow tables according to a preset period;
[0086] The statistics module 62 divides the flow data in the flow table into multiple time windows, and performs statistics on the flow data in each time window to obtain statistical results.
[0087] The determination module 64 is used to determine whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results.
[0088] The processing module 66 is used to process the traffic corresponding to the DDoS attack when it is determined that the DDoS attack has occurred.
[0089] The aforementioned DDoS attack protection device employs the following methods: acquiring flow tables according to a preset period; dividing the traffic data in the flow tables into multiple time windows, and statistically analyzing the traffic data within each time window to obtain statistical results; determining whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results; and, if a DDoS attack is confirmed, processing the traffic corresponding to the DDoS attack, automatically completing device networking using the identity information of each home device. This simplifies the smart home device networking process and solves the technical problem of low gateway security caused by DDoS attacks on SDN network architectures in related technologies.
[0090] The determining module 64 includes a determining submodule, used to determine whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results, including: obtaining the number of traffic data with the destination address as the address to be detected within each time window from the statistical results; comparing the number of traffic data with the destination address as the address to be detected within each time window with a first threshold to obtain a comparison result, and determining whether the address to be detected is subjected to the DDoS attack based on the comparison result.
[0091] The determination submodule includes a determination unit, used to determine whether the address to be detected is under DDoS attack based on the comparison result, including: determining an abnormal time window as a time window in which the number of traffic data with the destination address of the address to be detected, as indicated by the comparison result, is greater than a first threshold; obtaining traffic data with the destination address of the address to be detected within multiple consecutive time windows after the abnormal time window from the statistical results; and determining that the address to be detected is under DDoS attack if the number of traffic data with the destination address of the address to be detected within the multiple consecutive time windows is greater than a second threshold.
[0092] The statistics module 62 includes a statistics submodule, which is used to perform statistics on traffic data in each time window and obtain statistical results, including: obtaining the destination address of the traffic data in each time window; changing the counter count of the destination address if the destination address is in a preset hash table; adding the destination address to the preset hash table if the destination address is not in the preset hash table; and determining the statistical results based on the counter count.
[0093] The determination module 64 further includes: a first detection submodule and a second detection submodule, wherein the first detection submodule is used to determine that the address to be detected has not been subjected to the DDoS attack if the number of traffic data whose destination address is the address to be detected as indicated by the comparison result is not greater than the first threshold.
[0094] The second detection submodule is used to determine that the address to be detected has not been subjected to the DDoS attack if the number of traffic data with the destination address as the address to be detected within the consecutive multiple time windows is not greater than the second threshold.
[0095] The processing module 66 includes a determination submodule, used to process the traffic corresponding to the DDoS attack, including: redirecting the traffic data of the address to be detected to a new address; if the new address is detected to be under the DDoS attack, obtaining the source address of the traffic data corresponding to the DDoS attack; and discarding the traffic data whose source address is the source address of the traffic data corresponding to the DDoS attack.
[0096] It should be noted that, Figure 6 The control device of the smart home audio playback system shown is used to perform Figure 2 The above-described methods for protecting against DDoS attacks also apply to the control device of this smart home audio playback system, and will not be repeated here.
[0097] This application also provides a computer device, including: a memory and a processor, wherein the memory is used to store program instructions; and the processor, connected to the memory, is used to execute the above-described DDoS attack protection method.
[0098] The method for protecting against DDoS attacks executed by the aforementioned computer devices employs the following steps: acquiring flow tables according to a preset period; dividing the traffic data in the flow tables into multiple time windows, and statistically analyzing the traffic data within each time window to obtain statistical results; determining whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results; and, if a DDoS attack is confirmed, processing the traffic corresponding to the DDoS attack, automatically completing device networking using the identity information of each home device. This simplifies the smart home device networking process and solves the technical problem of low gateway security caused by DDoS attacks on SDN network architectures in related technologies.
[0099] This application also provides a computer program product, including computer instructions that, when executed by a processor, implement the steps of the DDoS attack protection method in this application.
[0100] The DDoS attack protection method implemented by the above computer program adopts the following approach: acquiring flow tables according to a preset period; dividing the traffic data in the flow tables into traffic data of multiple time windows, and statistically analyzing the traffic data within each time window to obtain statistical results; determining whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results; and, if a DDoS attack is determined to have occurred, processing the traffic corresponding to the DDoS attack, and automatically completing device networking through the identity information of each home device, thereby simplifying the smart home device networking process and solving the technical problem of low gateway security caused by DDoS attacks on SDN network architecture in related technologies.
[0101] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0102] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0103] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0104] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0105] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0106] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0107] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method for protecting against DDoS attacks, characterized in that, include: Retrieve flow tables according to a preset cycle; The flow data in the flow table is divided into multiple time windows, and the flow data in each time window is statistically analyzed to obtain the statistical results. Determine whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results. If a DDoS attack is confirmed to have occurred, the traffic corresponding to the DDoS attack will be processed.
2. The method according to claim 1, characterized in that, Determining whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results includes: Obtain the number of traffic data with the destination address being the address to be detected within each time window from the statistical results; The number of traffic data with the destination address of the address to be detected within each time window is compared with a first threshold to obtain a comparison result, and the address to be detected is determined to be affected by the DDoS attack based on the comparison result.
3. The method according to claim 2, characterized in that, Determining whether the address to be detected is under DDoS attack based on the comparison results includes: The time window in which the number of traffic data whose destination address is the address to be detected, as indicated by the comparison results, is greater than the first threshold, is determined to be an abnormal time window. From the statistical results, obtain the traffic data whose destination address is the address to be detected within multiple consecutive time windows following the abnormal time window; If the number of traffic data destined for the address to be detected within a consecutive multiple time windows exceeds a second threshold, it is determined that the address to be detected is under DDoS attack.
4. The method according to claim 1, characterized in that, The traffic data within each time window was statistically analyzed to obtain the following results: Obtain the destination address of the traffic data within each time window; If the destination address is in a preset hash table, the counter for changing the destination address is updated. If the destination address is not in the preset hash table, add the destination address to the preset hash table; The statistical results are determined based on the number of times the counter is used.
5. The method according to claim 3, characterized in that, The method further includes: If the number of traffic data whose destination address is the address to be detected, as indicated by the comparison result, is not greater than the first threshold, it is determined that the address to be detected has not been subjected to the DDoS attack.
6. The method according to claim 3, characterized in that, The method further includes: If the number of traffic data destined for the address to be detected within the specified multiple consecutive time windows is not greater than the second threshold, it is determined that the address to be detected has not been subjected to the DDoS attack.
7. The method according to claim 1, characterized in that, Processing the traffic corresponding to the DDoS attack includes: Redirect the traffic data of the address to be detected to a new address; If the new address is detected to be under DDoS attack, obtain the source address of the traffic data corresponding to the DDoS attack; Discard traffic data whose source address is the same as the source address of the traffic data corresponding to the DDoS attack.
8. A DDoS attack protection device, characterized in that, include: The acquisition module is used to acquire flow tables according to a preset period. The statistics module divides the traffic data in the flow table into traffic data in multiple time windows, and performs statistics on the traffic data in each time window to obtain statistical results. The determination module is used to determine whether a distributed denial-of-service (DDoS) attack has occurred based on the statistical results. The processing module is used to process the traffic corresponding to the DDoS attack when it is determined that the DDoS attack has occurred.
9. A computer device, characterized in that, include: A memory and a processor, wherein the memory is used to store program instructions; The processor, connected to the memory, is used to execute the DDoS attack protection method according to any one of claims 1 to 7.
10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the DDoS attack protection method according to any one of claims 1 to 7.