Methods, devices, electronic equipment, and storage media for detecting sweeping DDoS attacks.

By acquiring and analyzing the traffic feature set of IP addresses, calculating weights and performing clustering, the problem of detecting segment-based DDoS attacks has been solved, and effective identification and protection against segment-based DDoS attacks have been achieved.

CN121151116BActive Publication Date: 2026-05-26BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING VOLCANO ENGINE TECH CO LTD
Filing Date
2025-10-31
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Segment-based DDoS attacks are difficult to detect and protect against because attackers use technical tools to launch attacks on all IP addresses within a specific IP address segment, making detection and protection difficult. Furthermore, attackers frequently adjust attack parameters, making it difficult for detection rules to adapt continuously.

Method used

By obtaining the traffic feature set of each IP address, calculating the weight of the traffic features based on the historical traffic set, and clustering multiple IP addresses, the IP address network segments affected by the segment-scanning DDoS attack are determined by using the traffic feature set assigned with weights for clustering.

Benefits of technology

It effectively reduces false positives and false negatives in segment-based DDoS attacks, can adapt to various attack scenarios, and improves the accuracy and adaptability of detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121151116B_ABST
    Figure CN121151116B_ABST
Patent Text Reader

Abstract

A method, apparatus, electronic device, and storage medium for detecting segment-based DDoS attacks are disclosed. The detection method includes: for each IP address among multiple IP addresses, obtaining a first traffic feature set including N dimensions of traffic characteristics from a first traffic set with that IP address as the destination IP address within a first time period; calculating weights corresponding to the N dimensions of traffic characteristics based on historical traffic sets; assigning corresponding weights to the N dimensions of traffic characteristics of the IP address to obtain a second traffic feature set corresponding to that IP address; clustering the multiple IP addresses based on the multiple second traffic feature sets corresponding to the multiple IP addresses to obtain a clustering result; and determining, based on the clustering result, the IP address network segments within the IP address network segments where the multiple IP addresses are located that have been subjected to segment-based DDoS attacks. The method and apparatus provided in this disclosure can effectively detect segment-based DDoS attacks, reduce false positives and false negatives, thereby improving network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a method for detecting segment-based DDoS attacks, a device for detecting segment-based DDoS attacks, an electronic device, and a computer-readable storage medium. Background Technology

[0002] With the rapid development of information technology, the Internet has been deeply integrated into all aspects of social production and life. The widespread use of various network applications has greatly improved the efficiency of social production and life and expanded the boundaries of services.

[0003] However, with the rapid development of the internet, the threat of distributed denial-of-service (DDoS) attacks has become increasingly severe, posing a significant threat to the stable development of the internet. For example, the economic losses and damage to the reputation of products and services caused by DDoS attacks are increasingly becoming major challenges that all industries must face.

[0004] For example, the sweeping DDoS attack, which is one of the typical forms of network attack today, is characterized by launching a DDoS attack on all IP addresses within a certain continuous Internet Protocol Address (IP address) segment. This sweeping DDoS attack is difficult to defend against and has a wide range of impact. Summary of the Invention

[0005] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0006] At least one embodiment of this disclosure provides a method for detecting a segment-based DDoS attack, comprising: for each IP address among a plurality of IP addresses, obtaining a first traffic feature set of a first traffic set with the IP address as the destination IP address within a first time period, the first traffic feature set including N-dimensional traffic features, where N is a natural number greater than 1; calculating the weights corresponding to the N-dimensional traffic features based on historical traffic sets; assigning corresponding weights to the N-dimensional traffic features obtained for each IP address among the plurality of IP addresses, thereby obtaining a second traffic feature set corresponding to the IP address; clustering the plurality of IP addresses based on the plurality of second traffic feature sets corresponding to the plurality of IP addresses to obtain a clustering result; and determining, based on the clustering result, a first IP address network segment in the IP address network segment where the plurality of IP addresses are located that has been subjected to a segment-based DDoS attack.

[0007] At least another embodiment of this disclosure provides a detection device for a sweeping DDoS attack, comprising: a traffic feature acquisition module configured to acquire, for each of a plurality of IP addresses, a first traffic feature set of a first traffic set with the destination IP address as the first traffic set within a first time period, the first traffic feature set including N-dimensional traffic features, where N is a natural number greater than 1; a weight calculation module configured to calculate weights corresponding to the N-dimensional traffic features based on historical traffic sets; a weight assignment module configured to assign corresponding weights to the N-dimensional traffic features acquired for each of the plurality of IP addresses, thereby obtaining a second traffic feature set corresponding to the IP address; an address clustering module configured to cluster the plurality of IP addresses based on the plurality of second traffic feature sets corresponding to the plurality of IP addresses to obtain clustering results; and an attack network segment determination module configured to determine, based on the clustering results, a first IP address network segment in the IP address network segment where the plurality of IP addresses are located that has been subjected to a sweeping DDoS attack.

[0008] At least one further embodiment of this disclosure provides an electronic device, including: a processing device; and a storage device including one or more computer program instructions; wherein the one or more computer program instructions are executed by the processing device to perform the segment-scanning DDoS attack detection method provided in at least one embodiment of this disclosure.

[0009] At least one further embodiment of this disclosure provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, the method for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure is implemented.

[0010] At least one further embodiment of this disclosure provides a computer program product, including a computer program / instruction that, when executed on a computer, causes the computer to perform the segment-scanning DDoS attack detection method provided in at least one embodiment of this disclosure. Attached Figure Description

[0011] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0012] Figure 1 This illustration schematically shows an application scenario of the method and apparatus for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure;

[0013] Figure 2A flowchart illustrating at least one embodiment of the method for detecting segment-based DDoS attacks disclosed herein is shown schematically.

[0014] Figure 3 This illustration schematically demonstrates the principle of determining the weight value corresponding to each dimension according to at least one embodiment of the present disclosure;

[0015] Figure 4 The illustration shows a schematic diagram illustrating the principle of clustering multiple IP addresses according to at least one embodiment of the present disclosure;

[0016] Figure 5 This illustration schematically shows the principle of determining the first IP address network segment subjected to a segment-sweeping DDoS attack based on clustering results, according to at least one embodiment of the present disclosure.

[0017] Figure 6 This schematically illustrates a structural block diagram of a detection device for segment-based DDoS attacks according to at least one embodiment of the present disclosure; and

[0018] Figure 7 A schematic diagram of the structure of an electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation

[0019] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0020] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0021] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0022] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0023] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0024] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0025] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.

[0026] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization should be obtained from the relevant users. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.

[0027] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly inform the user that the requested operation will require obtaining and using the user's information, thereby enabling the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of the technical solution disclosed herein based on the prompt message.

[0028] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.

[0029] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.

[0030] With the rapid development of the internet, the types of attacks targeting the internet are increasing, and the threat to the internet is becoming more severe. Cybersecurity has become a major challenge threatening the stable development of the internet. Economic losses and damage to product and service reputation caused by cyberattacks are increasingly becoming problems that all industries must face. Segment scanning attacks are one of the typical forms of current cyberattacks. Their core characteristic is that attackers use technical tools to launch attacks on all IP addresses within a specific IP address segment, rather than targeting a single IP address. Taking a segment scanning DDoS attack as an example, attackers might control botnets distributed across the internet to launch a large number of malicious requests against a target server, causing the server to be unable to respond to normal business requests and resulting in a denial-of-service attack. Segment scanning DDoS attacks launch pulse attacks on multiple IP addresses in a short period of time. A key characteristic of segment scanning DDoS attacks is that the traffic targeting a single IP address is small, while the overall characteristics of the traffic targeting multiple IP addresses are similar. For example, the attack traffic targeting each IP address is only 1-10 Mbps, and the attack on a single IP address lasts only 3-10 seconds. For example, using the same protocol for traffic from multiple IP addresses, fixed traffic volumes, or even traffic from the same batch of intermediate servers.

[0031] For example, the essence of a segment-scanning DDoS attack is an attack strategy employed by attackers to bypass protection and expand the attack scope. It can ensure that an attack targeting a single IP address will not trigger an alert, while simultaneously attacking multiple IP addresses, causing network-wide service disruptions and posing significant challenges to detection and protection. Furthermore, attackers may frequently adjust attack parameters, such as sending traffic using mixed protocols, changing source IP addresses, or targeting random ports. This causes previously effective detection rules to quickly become ineffective, making it difficult for detection rules to continuously adapt to the attack scenario.

[0032] To at least partially address these technical problems, at least one embodiment of this disclosure provides a method for detecting segment-based DDoS attacks, comprising: for each IP address among a plurality of IP addresses, obtaining a first traffic feature set of a first traffic set with the IP address as the destination IP address within a first time period, the first traffic feature set including N-dimensional traffic features, where N is a natural number greater than 1; calculating weights corresponding to the N-dimensional traffic features based on historical traffic sets; for each IP address among the plurality of IP addresses, assigning corresponding weights to the N-dimensional traffic features obtained for that IP address to obtain a second traffic feature set corresponding to that IP address; clustering the plurality of IP addresses based on the plurality of second traffic feature sets corresponding to the plurality of IP addresses to obtain a clustering result; and based on the clustering result, determining a first IP address network segment in the IP address network segment where the plurality of IP addresses are located that has been subjected to a segment-based DDoS attack.

[0033] Based on the method for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides a device, electronic device, and computer-readable storage medium for detecting segment-based DDoS attacks.

[0034] The method for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure calculates the weights corresponding to N dimensions of traffic features based on historical traffic sets. This allows the calculated weights to reflect the ability of each dimension of traffic features to distinguish between attack traffic and non-attack traffic. Therefore, by clustering multiple IP addresses based on a weighted set of traffic features, IP addresses that are the destination IP addresses of attack traffic can be effectively clustered together. Thus, based on the clustering results, segment-based DDoS attacks can be effectively detected, reducing false positives and false negatives of segment-based DDoS attacks.

[0035] The embodiments and some examples of this disclosure will now be described in detail with reference to the accompanying drawings.

[0036] Figure 1 The illustration shows an application scenario of the method and apparatus for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure.

[0037] like Figure 1 As shown, the application scenario 100 of this embodiment involves an attacker server 110, multiple network segments 121-122, and an electronic device 130.

[0038] In at least one embodiment of this disclosure, the attacker server 110 may communicate with devices controlled by the attacked party, such as personal computers, servers, and Internet of Things devices (e.g., smart cameras, smart sockets), through a network. For example, the attacker may issue instructions to these controlled devices through the attacker server 110 to launch a segment-sweeping DDoS attack on one or at least two of the multiple network segments 121-122.

[0039] In at least one embodiment of this disclosure, the IP addresses included in each network segment can be assigned to at least two business objects, which may be one or at least two objects from different industries. These at least two business objects may include, for example, at least two electronic devices such as servers supporting the operation of online banking systems of financial institutions, transaction servers of e-commerce platforms, online game servers of game companies, or servers supporting the operation of any platform (e.g., content sharing platforms, short video platforms, etc.). For example, the format of the IP address range of network segment 121 may be XXX.XXX.XX / XX, and the format of the IP address range of network segment 122 may be YYY.YYY.YY / YY. The embodiments of this disclosure do not limit the specific values ​​of the IP address ranges of these network segments.

[0040] In at least one embodiment of this disclosure, a segment-scanning DDoS attack can target any one or a combination of at least two of the network layer, transport layer, and application layer in the Open Systems Interconnection Reference Model (OSI reference model). For example, it can primarily target the network layer and / or the transport layer. The embodiments of this disclosure do not limit this.

[0041] In at least one embodiment of this disclosure, the electronic device 130 may be, for example, a laptop computer, a desktop computer, or a server. The electronic device 130 may run a system capable of analyzing the traffic of each IP address and locating the network segment subjected to a segment-scanning DDoS attack, such as an anti-attack system.

[0042] In at least one embodiment of this disclosure, the electronic device 130 can acquire traffic characteristics of a traffic set with each IP address in multiple network segments as the destination IP address within a first time period. By analyzing the traffic characteristics, multiple IP addresses in multiple network segments are clustered. Based on the clustering results, the network segments in multiple network segments that have been subjected to a segment-sweeping DDoS attack are determined, so as to protect the network segments subjected to the segment-sweeping DDoS attack and reduce the impact of the segment-sweeping DDoS attack on services.

[0043] For example, the detection device for segment-based DDoS attacks provided in at least one embodiment of this disclosure can be implemented in software, hardware, firmware, or any combination thereof.

[0044] For example, the method for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure is applicable to electronic device 130. Electronic device 130 can load and execute the method for detecting segment-based DDoS attacks, and the embodiments of this disclosure do not limit this. For example, electronic device 130 may include a central processing unit (CPU), graphics processing unit (GPU), digital signal processor (DSP), neural network processing unit (NPU), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, storage units, etc. Electronic device 130 may also be equipped with an operating system, application programming interfaces (APIs) (e.g., OpenGL (Open Graphics Library), Metal, etc.). Electronic device 130 implements the method for detecting segment-based DDoS attacks provided in the embodiments of this disclosure by running code or instructions.

[0045] The following will combine Figures 2-5 The implementation principle of the method for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure will be described by way of example.

[0046] Figure 2 A flowchart illustrating a method for detecting a segment-based DDoS attack according to at least one embodiment of the present disclosure is shown.

[0047] like Figure 2 As shown, the method for detecting segment-based DDoS attacks according to embodiments of this disclosure may include steps S210 to S250. Steps S210 and S220 can be executed in any order, and this disclosure does not limit this.

[0048] Step S210: For each IP address among multiple IP addresses, obtain the first traffic feature set of the first traffic set with that IP address as the destination IP address within the first time period. The first traffic feature set includes traffic features of N dimensions.

[0049] Step S220: Calculate the weights corresponding to the traffic features of N dimensions based on the historical traffic set.

[0050] Step S230: For each of the multiple IP addresses, assign corresponding weights to the N dimensions of traffic features obtained for that IP address to obtain a second set of traffic features corresponding to that IP address.

[0051] Step S240: Based on multiple sets of second traffic features corresponding to multiple IP addresses, cluster the multiple IP addresses to obtain clustering results.

[0052] Step S250: Based on the clustering results, determine the first IP address network segment among the IP address network segments containing multiple IP addresses that has been subjected to a segment-sweeping DDoS attack.

[0053] In at least one embodiment of this disclosure, the multiple IP addresses can be all the IP addresses configured for network devices and servers in a data center, all the IP addresses configured for network devices and servers in a computer room, or all the IP addresses that need to be monitored according to actual needs. For example, it can be only all the IP addresses configured for servers. The embodiments of this disclosure do not limit this.

[0054] In at least one embodiment of this disclosure, the length of the first time period can be set according to actual needs. For example, the length of the first time period can be in the range of seconds or minutes. Specifically, the length of the first time period can be determined based on the duration of a sweeping DDoS attack or the detection cycle of a sweeping DDoS attack, etc. The embodiments of this disclosure do not limit this. For example, step S210 can, for each IP address, form a first traffic set by combining all traffic detected within the first time period that has that IP address as its destination IP address. For example, the first time period can be a time period with the current time as the end time and a predetermined length.

[0055] In at least one embodiment of this disclosure, the N dimensions of traffic features in the first traffic feature set can be obtained, for example, by statistically analyzing the packets in the first traffic set obtained for each IP address. N is any natural number greater than 1, and the value of N can be set according to actual needs; the embodiments of this disclosure do not limit this.

[0056] In at least one embodiment of this disclosure, the N-dimensional traffic characteristics may include, for example, ratio-type traffic characteristics, such as the percentage of each type of packet in the first traffic in a predetermined type, the percentage of packets with the first port as the source port in all packets, and the percentage of packets with the second port as the destination port in all packets.

[0057] For example, the predefined types may include one or more of the following types: TCP packet type, UDP packet type, SYN packet type, ACK packet type, RST / FIN packet type, UDP packet type hitting a UDP reflection port, TCP packet type whose TCP flags do not conform to predefined rules, and UDP packet type whose payload hits non-compliant features. When there are at least two predefined types, the N dimensions may include at least two dimensions corresponding to each of the at least two predefined types. For example, each predefined type corresponds to a dimension of traffic characteristics. For example, a TCP packet refers to a packet transmitted based on the Transmission Control Protocol (TCP), a UDP packet refers to a packet transmitted based on the User Datagram Protocol (UDP), a SYN packet is a packet with a synchronization sequence number (SYN) used to initiate a TCP connection, an ACK packet is an acknowledgment (ACK) packet used to confirm receipt of a TCP packet sent by the other party, an RST packet is a reset packet used to forcibly close an abnormal TCP connection, and a FIN packet is a finish packet used to actively request the normal closure of a TCP connection. Hitting a UDP reflection port means that the destination port of the UDP packet exactly matches a predefined list of "UDP reflection ports," which is one of the key characteristics for identifying DDoS attacks of the UDP reflection amplification attack type. Predefined rules may include, for example, that the TCP packet header contains six key flag bits: SYN, ACK, FIN, RST, PSH (Push), and URG (Urgency), each flag bit occupying 1 bit. Non-compliant features may be malicious features or other features set according to actual needs, and the embodiments disclosed herein do not limit this.

[0058] For example, all packets in the first traffic set can be counted by source port to determine the number of packets for each source port, and a predetermined number of source ports with the highest packet volume can be designated as the first port. For example, the first port includes source ports that are ranked at least before the first position based on packet volume. For example, the source ports with the highest, second highest, and third highest packet volume can be designated as the first port.

[0059] For example, all packets in the first traffic set can be counted by destination port to determine the number of packets at each destination port, and a predetermined number of destination ports with the highest packet volume can be designated as second ports. For example, the second ports include destination ports that are at least ranked before the second position based on packet volume. For example, the destination ports with the highest, second highest, and third highest packet volume can be designated as second ports. This second position may correspond to the same position as the aforementioned first position, or it may correspond to a different position; the embodiments of this disclosure do not limit this.

[0060] In at least one embodiment of this disclosure, the N-dimensional traffic characteristics may include, for example, non-ratio-type traffic characteristics. These non-ratio-type traffic characteristics may include, for example, at least one of the following: the average packet length of all packets in the first traffic set, the total number of packets in the first traffic set, the average time-to-live (TTL) of all packets in the first traffic set, and the variance of the packet length of all packets in the first traffic set. For example, the packet length refers to the total number of bytes in a single packet.

[0061] In at least one embodiment of this disclosure, the N-dimensional traffic characteristics obtained for each IP address can be as shown in Table 1 below. It is understood that the traffic characteristics included in the table below, along with the feature field names and meanings of each traffic characteristic, are merely examples to aid in understanding this disclosure, and the embodiments of this disclosure do not limit this understanding.

[0062] Table 1

[0063]

[0064]

[0065] In at least one embodiment of this disclosure, for example, the type, source IP address, destination IP address, source port, destination port, duration to life, packet length, TCP flags, and actual data portion following the UDP header can be determined by parsing each packet in the first traffic set. For instance, after obtaining the TCP flags, the combination of these flags can be compared with a specified compliant combination to determine if they match, thereby determining whether the TCP flag combination of the packet is compliant. After obtaining the actual data portion following the UDP header, this actual data portion can be compared with predefined non-compliant features. If the comparison determines that the actual data portion includes the predefined non-compliant features, the packet is determined to be a UDP packet whose payload matches the non-compliant features. It is understood that the principles for obtaining the various traffic features described above are merely examples to facilitate understanding of this disclosure, and the embodiments of this disclosure are not limited thereto.

[0066] In at least one embodiment of this disclosure, the historical traffic set may include, for example, all traffic collected before a first time period, or traffic collected within a predetermined time period before the first time period. For example, the historical traffic set includes both attack traffic and non-attack traffic, wherein the attack traffic may include, for example, the attack traffic of a sweeping DDoS attack. For example, the weight corresponding to the traffic characteristic of that dimension can be determined based on the correlation between the traffic characteristics of each dimension and the various types of historical traffic in the historical traffic set. For example, if the difference between non-attack traffic and attack traffic in the traffic characteristics of that dimension is large, a higher weight can be assigned to the traffic characteristics of that dimension; otherwise, a lower weight can be assigned.

[0067] In at least one embodiment of this disclosure, the weight corresponding to each dimension of traffic characteristics can, for example, characterize the ability of that dimension's traffic characteristics to distinguish between attack traffic and non-attack traffic. For instance, the weight corresponding to a traffic characteristic of a dimension can be positively correlated with its ability to distinguish between attack traffic and non-attack traffic; the stronger the distinguishing ability, the larger the corresponding weight. For example, traffic characteristics that appear only in sweeping DDoS attack traffic or only in non-attack traffic have a strong ability to distinguish between attack traffic and non-attack traffic, and therefore, larger weight values ​​can be assigned to these characteristics.

[0068] In at least one embodiment of this disclosure, step S230 may assign corresponding weights to the N traffic features obtained for each IP address. For example, for each of the N traffic features, the value of each traffic feature may be multiplied by its corresponding weight to obtain a traffic feature in the second set of traffic features. Alternatively, depending on actual needs, the value of each traffic feature may be multiplied by the square root, cube root, or a predetermined multiple of its corresponding weight to obtain a traffic feature in the second set of traffic features. It is understood that the above-described method of assigning corresponding weights to each traffic feature is merely an example to facilitate understanding of this disclosure, and the embodiments of this disclosure are not limited thereto.

[0069] In at least one embodiment of this disclosure, for non-ratio-type traffic features in the traffic feature set, the traffic features can be first normalized to obtain normalized traffic features. Then, weights are assigned to the normalized traffic features based on the weights corresponding to the traffic features. In this way, when clustering multiple IP addresses based on multiple second traffic feature sets, the dimensional differences between non-ratio-type traffic features and ratio-type traffic features can be eliminated, resulting in more accurate clustering results.

[0070] In at least one embodiment of this disclosure, the principle of normalization processing can be found in, for example, the following formula (1). This represents the value of the flow characteristic after normalization. This indicates the first of multiple first traffic feature sets obtained for multiple IP addresses. The values ​​of traffic features in a set of traffic features. and These represent the maximum and minimum values ​​of all traffic features in multiple first traffic feature sets, respectively. For example, the average TTL, average packet length, packet length variance, and total number of packets in the aforementioned table are non-ratio type traffic features. Taking the average TTL as an example, when normalizing the average TTL, and These represent the maximum and minimum average TTL values ​​for all values ​​in multiple first flow feature sets, respectively.

[0071] Formula (1)

[0072] In at least one embodiment of this disclosure, step S240 may, for example, determine the distances between multiple second traffic feature sets corresponding to multiple IP addresses, and cluster at least two IP addresses corresponding to at least two traffic feature sets whose distances to each other are all less than a predetermined distance into one class, thereby obtaining a clustering result. For example, the second traffic feature set corresponding to each IP address can be constructed into a feature vector, and the vector distance between multiple feature vectors corresponding to multiple IP addresses can be used as the distance between multiple second traffic feature sets. For example, Euclidean distance, Manhattan distance, etc., can be used to determine the vector distance between multiple feature vectors, and the embodiments of this disclosure are not limited thereto.

[0073] In at least one embodiment of this disclosure, the clustering result may include, for example, at least one address cluster group, each address cluster group including at least two IP addresses clustered into one class. This embodiment may first determine a first address cluster group containing a first number of IP addresses within the at least one address cluster group, and then identify the IP address network segment containing the IP addresses in the first address cluster group as the first IP address network segment suspected of being subjected to a segment-scanning DDoS attack. For example, the first number may be a value set according to actual needs; for example, the first number may be related to the number of IP addresses contained within a unit network segment, or it may be positively correlated with the number of IP addresses contained within a unit network segment. This is not limited in the embodiments of this disclosure.

[0074] In at least one embodiment of this disclosure, the unit network segment can be, for example, a / 26 network segment, or, depending on actual needs, a / 27 network segment, a / 24 network segment, etc., and the embodiments of this disclosure do not limit this.

[0075] The method for detecting segment-sweeping DDoS attacks provided in at least one embodiment of this disclosure calculates weights corresponding to N dimensions of traffic features based on historical traffic sets. This allows the calculated weights to reflect the ability of each dimension of traffic features to distinguish between attack and non-attack traffic. Therefore, by assigning corresponding weights to the N-dimensional traffic features obtained for each IP address, and clustering multiple IP addresses based on the weighted traffic feature sets, IP addresses that are the destination IP addresses of attack traffic can be effectively clustered together. Thus, based on the clustering results, segment-sweeping DDoS attacks can be effectively detected, reducing false positives and false negatives. Compared to technical solutions that use fixed weights and are only applicable to specific scenarios, unable to adapt to various segment-sweeping attack scenarios in the network, at least one embodiment of this disclosure introduces weights determined based on historical traffic sets, enabling the detection method provided in at least one embodiment of this disclosure to adapt to various segment-sweeping attack scenarios.

[0076] Figure 3 The illustration shows a schematic diagram illustrating the principle of determining the weight value corresponding to each dimension according to at least one embodiment of the present disclosure.

[0077] In at least one embodiment of this disclosure, the ability of a traffic feature of a given dimension to distinguish between attack traffic and non-attack traffic can be determined based on the distribution information of traffic features in each dimension and the mutual information between traffic types, and the weight of the traffic feature of that dimension can be determined based on the mutual information. Mutual information (MI) is used to measure the strength of the dependency between two random variables, describing the "information" contained in one random variable about another. Essentially, it reflects the degree to which observing one variable can reduce the uncertainty about another variable.

[0078] In at least one embodiment of this disclosure, the historical traffic set in step S220 may include multiple attack traffic subsets and multiple non-attack traffic subsets. For example, an exemplary implementation of step S220 may include the following steps: first, for each dimension, obtain first distribution information of the traffic characteristics of the multiple attack traffic subsets for that dimension and second distribution information of the traffic characteristics of the multiple non-attack traffic subsets for that dimension; then, determine the mutual information between the traffic characteristics and traffic types of that dimension based on the first and second distribution information; finally, determine the weight value corresponding to the traffic characteristics of that dimension based on the mutual information. The traffic types include non-attack types and attack types. Attack type traffic is attack traffic, and multiple attack traffic sets can constitute an attack traffic subset; non-attack type traffic is non-attack traffic, and multiple non-attack traffic sets can constitute a non-attack traffic subset.

[0079] In at least one embodiment of this disclosure, the same number of attack traffic subsets and non-attack traffic subsets can be obtained. Each attack traffic subset and each non-attack traffic subset corresponds to a network packet capture file. Each network packet capture file includes all attack-type packets transmitted on the network within a certain period of time, or includes all non-attack-type packets transmitted on the network within a certain period of time. The length of this period of time can be, for example, 1 second or other lengths set according to actual needs. The embodiments of this disclosure do not limit this.

[0080] In at least one embodiment of this disclosure, the traffic characteristics of each dimension can be treated as random variables X, and the traffic type as random variable Y, and the joint probability distribution between the two can be calculated. and their respective marginal probability distributions and Marginal probability distribution and Let X and Y represent the probability distributions of random variables X and Y respectively, describing the probabilistic relationships when focusing only on the values ​​of random variables X and Y. Joint probability distribution. It is used to describe the probability of random variables X and Y taking specific values ​​simultaneously.

[0081] In at least one embodiment of this disclosure, after obtaining the joint probability distribution Marginal probability distribution and Then, for example, the following formula (2) can be used to calculate the mutual information between the traffic characteristics and traffic types of each dimension. .

[0082] Formula (2)

[0083] In at least one embodiment of this disclosure, for ease of calculation, the values ​​of each dimension's traffic feature can be divided into multiple feature value intervals based on the distribution information of each dimension's traffic feature. Each feature value interval represents a value interval of the random variable X. Then, the mutual information between each feature value interval and the traffic type is calculated. Finally, the sum of the multiple mutual information between the multiple feature value intervals and the traffic type is taken as the mutual information between the traffic feature of each dimension and the traffic type.

[0084] In at least one embodiment of this disclosure, the number of both the attack traffic subset and the non-attack traffic subset is set to 10,000. The principle of determining the weight corresponding to the traffic feature is described in detail below, taking the percentage of UDP packets hitting the reflection port as an example. For example, the feature value of the percentage of UDP packets hitting the reflection port can be divided into three feature value intervals: [0, 33%), [33%, 66%), and [66%, 100%]. The distribution information of the percentage of UDP packets hitting the reflection port in the attack traffic subset and the non-attack traffic subset can be shown in Table 2 below. According to Table 2, the values ​​of random variable X include x1=[0, 33%), x2=[33%, 66%), and x3=[66%, 100%]. The values ​​of random variable Y include Y=0 and Y=1. The values ​​of the two can form six combinations, and the calculation principle and calculation results of the mutual information of each combination can be shown in Table 3 below. Summing the six calculation results in Table 3 yields the mutual information of 0.618 between the proportion of UDP packets that hit the reflection port based on traffic characteristics and the traffic type.

[0085] Table 2

[0086]

[0087] Table 3

[0088]

[0089]

[0090] It is understandable that, for traffic features other than the proportion of UDP packets that hit the reflection port, the principle of calculating the mutual information between the traffic feature and the traffic type is similar to the principle of calculating the mutual information between the proportion of UDP packets that hit the reflection port and the traffic type, and will not be elaborated here.

[0091] In at least one embodiment of this disclosure, after obtaining the mutual information between the traffic characteristics and traffic types of each dimension, the weight corresponding to the traffic characteristics of each dimension can be determined based on the positive correlation between the mutual information and the weight.

[0092] In at least one embodiment of this disclosure, a mapping relationship between the value range of mutual information and the weights can be pre-defined. For example... Figure 3As shown, after determining the mutual information 303 between the traffic features and traffic types in each dimension based on the distribution information 301 of the traffic features of the attack traffic subset in each dimension and the distribution information 302 of the traffic features of the non-attack traffic subset in each dimension, the value interval to which the mutual information 303 belongs among multiple value intervals 310 can be queried and determined as the first value interval 311. Then, based on the first value interval 311, the mapping relationship 320 is queried to determine the first weight that has a mapping relationship with the first value interval 311, which is used as the weight 304 corresponding to the traffic features in each dimension. By determining the weight based on the mapping relationship, rather than directly using the mutual information as the weight, the clustering scheme based on weights can be simplified, which is beneficial to improving the robustness of the detection method.

[0093] In at least one embodiment of this disclosure, for example, if the mutual information between the traffic feature and the traffic type in each dimension is less than or equal to 0.2, the weight corresponding to the traffic feature in each dimension may be determined to be 0.1; if the mutual information is greater than 0.2 and less than or equal to 0.7, the weight corresponding to the traffic feature in each dimension may be determined to be 0.3; and if the mutual information is greater than 0.7 and less than or equal to 1, the weight corresponding to the traffic feature in each dimension may be determined to be 0.7. It is understood that the above weight values ​​are merely examples to aid in understanding this disclosure, and the embodiments of this disclosure do not limit the scope of the disclosure.

[0094] In at least one embodiment of this disclosure, for example, sweeping DDoS attack events can be continuously detected. After determining the weight corresponding to the traffic characteristics of each dimension, for example, after detecting a first number of sweeping DDoS attacks, the distribution information of the traffic characteristics of each dimension of the attack traffic subset of the first number of sweeping DDoS attacks can be obtained, and the non-attack traffic subset can be re-obtained, and the distribution information of the traffic characteristics of each dimension of the re-obtained non-attack traffic subset can be obtained. Based on the obtained distribution information, the weight corresponding to the traffic characteristics of each dimension can be re-determined using the principle described in any of the above embodiments, so as to realize the continuous updating of the weights, so that the detection method provided by at least one embodiment of this disclosure can continuously evolve autonomously and adapt to more changing scenarios.

[0095] In at least one embodiment of this disclosure, the reacquired subset of non-attack traffic may be, for example, one or more subsets of traffic consisting of all non-attack traffic detected within a second time period, which may be, for example, a time period starting from the time when the weight was obtained and ending at the current time. Alternatively, the first time period may also be the time period between the time of the previous weight update and the current time.

[0096] Figure 4The illustration shows a schematic diagram of the principle of clustering multiple IP addresses according to at least one embodiment of the present disclosure.

[0097] In at least one embodiment of this disclosure, multiple IP addresses can be clustered based on the principle of "density" to improve robustness and the accuracy of identifying segment-based DDoS attacks without needing to set the number of clusters. This is because the number of segment-based DDoS attacks during the detection period is uncertain, and the characteristics of normal business traffic are often discrete; only the attack traffic of segment-based DDoS attacks exhibits clustering in terms of characteristic dimensions.

[0098] In at least one embodiment of this disclosure, when clustering multiple IP addresses to obtain clustering results, the neighborhood radius can be determined first based on multiple second traffic feature sets, and then the multiple IP addresses can be clustered based on the neighborhood radius to obtain clustering results.

[0099] In at least one embodiment of this disclosure, for example, the distances between multiple second flow feature sets can be calculated, and the average distance or median of all calculated distances can be used as a reference value for determining the neighborhood radius. For example, the product of the average distance or median and a predetermined coefficient can be used as the neighborhood radius. When calculating the distances between flow feature sets, each second flow feature set can be formed into a feature vector, and the vector distance between the two feature vectors formed by two flow feature sets can be used as the distance between the two flow feature sets.

[0100] In at least one embodiment of this disclosure, the neighborhood radius can be determined based on the deviation of traffic features obtained for multiple IP addresses from reference features. This embodiment improves the accuracy of the determined neighborhood radius and reduces clustering bias by introducing reference features to determine the neighborhood radius. For example, N reference features corresponding to N dimensions can be introduced.

[0101] In at least one embodiment of this disclosure, for each of the N dimensions, a weight corresponding to the flow feature of that dimension can be assigned to the reference feature corresponding to that dimension, resulting in a weighted reference feature corresponding to that dimension. The N weighted reference features corresponding to the N dimensions can constitute a reference feature set. Then, the deviation values ​​of multiple second flow feature sets relative to the reference feature set are determined, resulting in multiple deviation values. Finally, the neighborhood radius can be determined based on the multiple deviation values. By assigning weights to the reference features beforehand, the reference features and flow features can be made comparable when determining the deviation values.

[0102] For example, when determining the deviation value of each second flow feature set relative to the reference feature set, the deviation value between each flow feature in the second flow feature set and the corresponding reference feature in the reference feature set can be determined first, resulting in a total of N deviation values ​​for the second flow feature set. For example, the average of the N deviation values, the sum of the N deviation values, or the square root of the sum of the N deviation values ​​can be used as the deviation value of the second flow feature set relative to the reference feature set. It is understood that the above method of obtaining the deviation value of the second flow feature set relative to the reference feature set based on N deviation values ​​is only an example to facilitate understanding of this disclosure, and the embodiments of this disclosure are not limited in this respect. For example, after obtaining multiple deviation values ​​of multiple second flow feature sets relative to the reference feature set, the average or median of the multiple deviation values ​​can be used as the neighborhood radius. For example, the difference between the values ​​of two features, or the square of the difference, can be used as the deviation value between the two features, and the embodiments of this disclosure are not limited in this respect.

[0103] In at least one embodiment of this disclosure, for example, for each of N dimensions, a reference feature corresponding to that dimension can be determined based on all traffic features of that dimension obtained for multiple IP addresses, that is, based on multiple traffic features of that dimension in multiple first traffic feature sets corresponding to multiple IP addresses respectively. For example, the average or median of all traffic features obtained under that dimension can be used as the reference feature corresponding to that dimension.

[0104] In at least one embodiment of this disclosure, for example, for each of the N dimensions, a reference feature corresponding to that dimension can be determined based on the traffic characteristics of the non-attack traffic subset in the historical traffic set for that dimension. For example, the average or median of multiple traffic characteristics of multiple non-attack traffic subsets for that dimension can be used as the reference feature corresponding to that dimension. By determining the reference feature based on the traffic characteristics of multiple non-attack traffic subsets, attack traffic can be distinguished from non-attack traffic due to deviation from the reference feature, which helps to effectively improve the accuracy of the determined neighborhood radius.

[0105] In at least one embodiment of this disclosure, for the dimension containing a non-ratio type traffic feature among N dimensions, when determining the reference feature corresponding to that dimension, the feature determined based on traffic features from multiple non-attack traffic subsets can be used as the initial reference feature. Subsequently, the feature obtained after normalizing the initial reference feature is used as the reference feature. For example, the principle of normalization can be found in formula (1) described above, and will not be detailed here. By normalizing the reference feature of the dimension containing the non-ratio type traffic feature, the reference feature can be made comparable to the traffic features in the second traffic feature set, making the determined deviation value for each IP address more accurate, and thus improving the accuracy of the determined neighborhood radius.

[0106] In at least one embodiment of this disclosure, such as Figure 4 As shown, when clustering multiple IP addresses, for example, for each of the N dimensions, the reference feature 401 corresponding to that dimension can be assigned a weight 402 corresponding to the traffic feature of that dimension, resulting in a weighted reference feature 403 corresponding to that dimension. Then, for each IP address among the multiple IP addresses 410, the deviation value of the traffic feature 404 under each dimension in the second traffic feature set relative to the weighted reference feature 403 of each dimension is determined, resulting in a total of N deviation values. The square root of the sum of these N deviation values ​​is taken as the deviation value 405 corresponding to each IP address. Subsequently, the average value of the multiple deviation values ​​corresponding to the multiple IP addresses 410 can be determined, resulting in an average deviation value 406. Finally, the product between the average deviation value 406 and the adjustment coefficient 407 is determined to obtain the neighborhood radius 408.

[0107] In at least one embodiment of this disclosure, the adjustment coefficient, also known as the sensitivity coefficient, is used to control the tightness of clustering. For example, it can be determined based on the clustering of destination IP addresses of non-attack traffic. By setting this adjustment coefficient, the accuracy of the determined neighborhood radius can be further improved, the clustering effect enhanced, and the detection effectiveness of segment-based DDoS attacks improved.

[0108] In at least one embodiment of this disclosure, the core function of the adjustment coefficient is to add a "safety buffer" to the dispersion of non-attack traffic, ensuring that natural differences in non-attack traffic are not misjudged as clustering, while the similarity of attack traffic is covered. The value of the adjustment coefficient can be determined statistically, for example, to ensure that the overall deviation distance of non-attack traffic follows a normal distribution. For instance, the adjustment coefficient can be set to just cover the "extreme natural differences" of non-attack traffic, avoiding misjudging extreme values ​​of non-attack traffic as attack clustering. Alternatively, the value of the adjustment coefficient can be adjusted according to actual business conditions, thereby tightening or loosening the leniency and strictness of the detection model.

[0109] In at least one embodiment of this disclosure, the neighborhood radius can be determined, for example, using formula (3) as described below. .in, For adjustment coefficients, Let N be the total number of IP addresses, and N be the total number of dimensions. The weight value corresponding to the traffic feature in the k-th dimension out of m dimensions. This is the reference feature corresponding to the kth dimension out of m dimensions. This refers to the traffic feature of the k-th dimension obtained for the i-th IP address. For example, for non-ratio type traffic features, To normalize the flow characteristics, This is a normalized reference feature.

[0110] Formula (3)

[0111] In at least one embodiment of this disclosure, such as Figure 4 As shown, after obtaining the neighborhood radius 408, clustering algorithm 409 can be used to cluster multiple IP addresses to obtain clustering result 420. For example, clustering algorithm 409 may include density-based spatial clustering of applications with noise (DBSCAN) and other clustering algorithms that divide clusters based on the density distribution of data, or it may include any other clustering algorithm that needs to consider the neighborhood radius. The embodiments of this disclosure are not limited in this regard. For example, the DBSCAN algorithm is an unsupervised clustering algorithm. The core idea is to cluster samples with similar densities (e.g., IP addresses) into one class, and treat isolated sparse samples (e.g., IP addresses) as noise. It does not require specifying the number of clusters in advance, and is particularly suitable for identifying clusters of arbitrary shapes (e.g., attack clusters in a sweep attack where IP addresses are scattered but traffic characteristics are clustered).

[0112] The technical solution of at least one embodiment of this disclosure combines weights calculated based on historical traffic sets and uses the above formula (3) to determine the neighborhood radius. Compared with the technical solution that uses Euclidean distance to calculate the distance between samples and determines the neighborhood radius based on the distance, since the weights of traffic features of different dimensions are not fixed and consistent, some feature fields can be made more important, which can improve the detection effect. On the other hand, the technical solution that uses fixed and consistent weights has poor detection effect on attacks with deformed attack methods and cannot automatically adapt to the actual attack scenario.

[0113] Figure 5The illustration shows a schematic diagram of the principle of determining the first IP address network segment subjected to a segment-scanning DDoS attack based on clustering results, according to at least one embodiment of the present disclosure.

[0114] In at least one embodiment of this disclosure, steps S210 to S240 can be performed periodically. For example, a first set of traffic features for a first set of traffic destinations, collected within a first time period starting from the current time, can be periodically acquired. Based on the weights corresponding to the periodically acquired N dimensions of traffic features, multiple IP addresses are periodically clustered to obtain clustering results. When determining the first IP address network segment subjected to a sweeping DDoS attack based on the clustering results, multiple clustering results obtained from adjacent periods can be considered comprehensively. For example, the length of the second time period can be a relatively short length, such as 1 second, because the duration of a single sweeping DDoS attack is usually short.

[0115] In at least one embodiment of this disclosure, each clustering result may include, for example, at least one address cluster group. For instance, the first IP address network segment affected by a sweeping DDoS attack can be determined based on the spatiotemporal correlation between address cluster groups in multiple clustering results. For example, the spatiotemporal correlation may include correlations in time and / or in the virtual address space of the IP addresses. Determining the first IP address network segment by considering the spatiotemporal correlation between address cluster groups can improve the detection accuracy of sweeping DDoS attacks. This is because sweeping DDoS attacks are large-scale, short-term, and highly concentrated attacks targeting one or even multiple C network segments.

[0116] In at least one embodiment of this disclosure, if multiple address clusters are obtained within a short period of time, it indicates that the IP addresses within these multiple address clusters have been subjected to concurrent attacks within a short period of time, which is consistent with the characteristics of a segment-sweeping DDoS attack. If the IP addresses in the multiple address clusters obtained by clustering are located in the same or adjacent network segments, it indicates that the attack involves network segment aggregation, which is consistent with the characteristics of a segment-sweeping DDoS attack.

[0117] In at least one embodiment of this disclosure, in response to the fact that at least two address clusters with spatiotemporal correlation are included among the multiple address clusters included in the multiple clustering results, the IP address network segment where the at least two address clusters are located can be determined as the first IP address network segment that has been subjected to a segment-scanning DDoS attack.

[0118] In at least one embodiment of this disclosure, a spatiotemporal correlation can be determined when at least two address clusters have the same clustering time or an interval less than a predetermined interval. Alternatively, a spatiotemporal correlation can be determined when the IP addresses in at least two address clusters are located in the same or adjacent IP address network segments. Alternatively, a spatiotemporal correlation can also be determined when at least two address clusters have the same clustering time or an interval less than a predetermined interval, and the IP addresses in at least two address clusters are located in the same or adjacent IP address network segments.

[0119] In at least one embodiment of this disclosure, in response to at least two address clusters among a plurality of address clusters satisfying at least one of the following conditions, it can be determined that the at least two address clusters have a spatiotemporal correlation: the second IP address network segments of each of the at least two address clusters are located in the same or consecutive third address network segments; the clustering times of the at least two address clusters are within the same unit time period. For example, the network segment length of the second IP address network segment is less than the network segment length of the third IP address network segment. For example, the second IP address network segment can be a / 26 network segment, the third IP address network segment can be a C network segment, i.e., a / 24 network segment, and the unit time period can be, for example, 10 seconds, or any time period longer than the aforementioned second time period. It is understood that the specific selection of the above-mentioned second IP address network segment, third IP address network segment, and unit time period is only an example to facilitate understanding of this disclosure, and the embodiments of this disclosure do not limit this.

[0120] In at least one embodiment of this disclosure, after obtaining multiple clustering results, such as Figure 5 As shown, for example, multiple clustering results 501 can be used to first identify address clusters where the number of IP addresses included is greater than a first number, thus obtaining multiple suspected attack clusters 502. The first number can be determined, for example, based on the number of IP addresses included in the second IP address network segment. For example, the first number can be positively correlated with the number of IP addresses included in the second IP address network segment. Subsequently, based on the spatiotemporal correlation between the multiple suspected attack clusters 502, the first IP address network segment in the IP address network segment where the multiple suspected attack clusters are located can be identified as having been subjected to a segment-sweeping DDoS attack.

[0121] In at least one embodiment of this disclosure, it can be first determined whether the plurality of suspected attack clusters 502 include at least two address clusters with spatiotemporal correlation. If so, the IP address network segment where the at least two address clusters with correlation (e.g., the first address cluster 503, the second address cluster 504, and the third address cluster 505) are located is determined to be the first IP address network segment 506 that has been subjected to a segment-sweeping DDoS attack.

[0122] In at least one embodiment of this disclosure, if multiple suspected attack clusters include address clusters whose IP addresses reside in / 26 network segments within the same or consecutive C network segments, for example, if the / 26 network segments of the IP addresses in a suspected attack cluster include network segments 1.1.1.0 / 26 and 1.1.1.64 / 26 (these two network segments are in the same C network segment), or if the / 26 network segments of the IP addresses in a suspected attack cluster include network segments 1.1.1.0 / 26 and 1.1.2.0 / 26 (these two network segments are in consecutive C network segments), then this reflects the existence of network segment aggregation in the attack, which conforms to the characteristics of a segment-sweeping DDoS attack. Furthermore, if these address clusters are three or more address clusters that aggregate within 10 seconds, it can be determined that the C network segment containing these attack clusters suffered a segment-sweeping DDoS attack within 10 seconds.

[0123] This disclosure discloses at least one embodiment of a technical solution for determining the first IP address network segment subjected to a segment-based DDoS attack by combining the spatiotemporal correlation between address clusters. This solution realizes a two-stage attack determination process of micro-clustering and macro-correlation, which can effectively improve the detection accuracy and effectiveness of segment-based DDoS attacks.

[0124] In at least one embodiment of this disclosure, IP addresses in at least two address clusters with spatiotemporal correlation can also be identified as the IP addresses targeted by a segment-based DDoS attack. The segment-based DDoS attack detection method of at least one embodiment of this disclosure can not only locate the network segment targeted by the segment-based DDoS attack, but also locate the IP address targeted by the segment-based DDoS attack, facilitating rapid protection against segment-based DDoS attacks.

[0125] Based on the method for detecting segment-based DDoS attacks provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides a device for detecting segment-based DDoS attacks. The following will be combined with... Figure 6 An exemplary description is provided for the detection device of this segment-based DDoS attack.

[0126] Figure 6 The schematic diagram illustrates a structural block diagram of a detection device for segment-based DDoS attacks according to at least one embodiment of the present disclosure.

[0127] like Figure 6As shown, the segment-scanning DDoS attack detection device 600 of this embodiment includes a traffic feature acquisition module 610, a weight calculation module 620, a weight assignment module 630, an address clustering module 640, and an attack segment determination module 650. For example, these units or modules can be implemented by hardware (e.g., circuit) modules or software modules, as is the case in the following embodiments, and will not be repeated here. For example, these units or modules can be implemented by a central processing unit (CPU), a general-purpose graphics processing unit (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, along with corresponding computer instructions.

[0128] The traffic feature acquisition module 610 is configured to acquire a first traffic feature set for each IP address among multiple IP addresses, within a first time period, of a first set of traffic destined for that IP address. This first traffic feature set includes N dimensions of traffic features, where N is a natural number greater than 1. For example, the traffic feature acquisition module 610 can be configured to execute step S210 as described above; its specific implementation principle can be found in the relevant description of step S210, and will not be repeated here.

[0129] The weight calculation module 620 is configured to calculate the weights corresponding to the traffic features of N dimensions based on the historical traffic set. For example, the weight calculation module 620 can be configured to execute step S220 described above. The specific implementation principle can be referred to the relevant description of step S220, which will not be repeated here.

[0130] The weighting module 630 is configured to assign corresponding weights to the N dimensions of traffic features obtained for each of the multiple IP addresses, thereby obtaining a second set of traffic features corresponding to that IP address. For example, the weighting module 630 can be configured to execute step S230 described above; its specific implementation principle can be found in the relevant description of step S230, and will not be repeated here.

[0131] The address clustering module 640 is configured to cluster multiple IP addresses based on multiple second traffic feature sets corresponding to each IP address to obtain clustering results. For example, the address clustering module 640 can be configured to execute step S240 described above; its specific implementation principle can be found in the relevant description of step S240, and will not be repeated here.

[0132] The attack network segment determination module 650 is configured to determine, based on clustering results, the first IP address network segment among multiple IP address network segments that has been subjected to a segment-sweeping DDoS attack. For example, the attack network segment determination module 650 can be configured to execute step S250 described above; its specific implementation principle can be found in the relevant description of step S250, and will not be repeated here.

[0133] In at least one embodiment of this disclosure, the address clustering module 640 may include, for example, a neighborhood radius determination submodule and a clustering submodule. The neighborhood radius determination submodule is configured to determine the neighborhood radius based on multiple second traffic feature sets. The clustering submodule is configured to cluster multiple IP addresses based on the neighborhood radius to obtain a clustering result.

[0134] In at least one embodiment of this disclosure, the aforementioned neighborhood radius determination submodule may include, for example, a weighting unit, a deviation value determination unit, and a radius determination unit. The weighting unit is configured to assign a weight corresponding to the flow feature of each of the N dimensions to a reference feature corresponding to that dimension, thereby obtaining a weighted reference feature corresponding to that dimension. The deviation value determination unit is configured to determine the deviation value of each of the plurality of second flow feature sets relative to the reference feature set, thereby obtaining a plurality of deviation values. The reference feature set includes N weighted reference features obtained for the N dimensions. The radius determination unit is configured to determine the neighborhood radius based on the plurality of deviation values.

[0135] In at least one embodiment of this disclosure, the radius determination unit may include, for example, an average value determination subunit and a radius determination subunit. The average value determination subunit is configured to determine the average of multiple deviation values ​​to obtain an average deviation value. The radius determination subunit is configured to determine the product of the average deviation value and an adjustment coefficient to obtain a neighborhood radius. For example, the adjustment coefficient is determined based on the clustering of destination IP addresses of non-attack traffic.

[0136] In at least one embodiment of this disclosure, the above-mentioned detection device 600 for scanning DDoS attacks may further include, for example, a reference feature determination module, configured to determine a reference feature corresponding to each of the N dimensions based on multiple traffic features of that dimension in multiple first traffic feature sets corresponding to multiple IP addresses; or to determine a reference feature corresponding to each of the N dimensions based on the traffic features of that dimension in a non-attack traffic subset of a historical traffic set.

[0137] In at least one embodiment of this disclosure, the N-dimensional traffic features include at least one traffic feature of a non-ratio type. The aforementioned weighting module 630 may, for example, include a normalization submodule and an assignment submodule. The normalization submodule is configured to normalize each of the at least one traffic feature to obtain a normalized traffic feature. The assignment submodule is configured to assign weights to the normalized traffic feature based on the weights corresponding to that traffic feature.

[0138] In at least one embodiment of this disclosure, the historical traffic set includes multiple attack traffic subsets and multiple non-attack traffic subsets. The aforementioned weight calculation module 620 may, for example, include a distribution information acquisition submodule, a mutual information determination submodule, and a weight determination submodule. The distribution information acquisition submodule is configured to acquire, for each of the N dimensions, first distribution information of the traffic characteristics of the multiple attack traffic subsets in that dimension and second distribution information of the traffic characteristics of the multiple non-attack traffic subsets in that dimension. The mutual information determination submodule is configured to determine the mutual information between the traffic characteristics and traffic types of that dimension based on the first and second distribution information, wherein the traffic types include attack types and non-attack types. The weight determination submodule is configured to determine the weights corresponding to the traffic characteristics of that dimension based on the mutual information.

[0139] In at least one embodiment of this disclosure, the aforementioned weight determination submodule may include, for example, an interval determination unit and a weight value determination unit. The interval determination unit is configured to determine a first value interval to which the mutual information belongs among a plurality of value intervals. The weight determination unit is configured to determine that the weight corresponding to the traffic feature of this dimension is a first weight that has a mapping relationship with the first value interval.

[0140] In at least one embodiment of this disclosure, the aforementioned distribution information acquisition submodule may also be configured to: in response to detecting a first number of sweeping DDoS attacks after obtaining the weights corresponding to the traffic features of the N dimensions, acquire the attack traffic subset of the first number of sweeping DDoS attacks and the non-attack traffic subset detected within a second time period, so as to update the weights corresponding to the traffic features of the N dimensions. For example, the second time period starts at the time when the weights are obtained and ends at the current time.

[0141] In at least one embodiment of this disclosure, the traffic feature acquisition module 610 may be specifically configured to: periodically acquire a first traffic feature set of a first traffic set with the IP address as the destination IP address within a first time period starting from the current time, so as to periodically obtain clustering results. The attack network segment determination module 650 may include, for example, a cluster group determination submodule and a network segment determination submodule. The cluster group determination submodule is configured to determine multiple suspected attack clusters in multiple clustering results obtained in multiple adjacent periods, wherein the number of IP addresses included in the suspected attack clusters is greater than a first number. The network segment determination submodule is configured to determine, based on the spatiotemporal correlation between the multiple suspected attack clusters, the first IP address network segment in the IP address network segment where the multiple suspected attack clusters are located that has been subjected to a sweeping DDoS attack.

[0142] In at least one embodiment of this disclosure, the aforementioned network segment determination submodule may be specifically configured to determine, in response to at least two address clusters with spatiotemporal correlation among a plurality of suspected attack clusters, that the IP address network segment where the at least two address clusters are located is the first IP address network segment subjected to a segment-sweeping DDoS attack.

[0143] In at least one embodiment of this disclosure, the aforementioned network segment determination submodule may be further configured to: in response to the fact that at least two address clusters among a plurality of suspected attack clusters satisfy at least one of the following conditions, determine that at least two address clusters have a spatiotemporal correlation: the second IP address network segments in which each of the at least two address clusters is located are in the same or consecutive third IP address network segments; wherein, the network segment length of the second IP address network segment is less than the network segment length of the third IP address network segment; and the clustering time of the at least two address clusters is within the same unit time period.

[0144] In at least one embodiment of this disclosure, the N-dimensional traffic characteristics include at least one traffic characteristic of the ratio type and at least one traffic characteristic of the non-ratio type; the at least one traffic characteristic of the ratio type includes at least one of the following: the percentage of packets of each type in at least one type in all packets in the first traffic set; the percentage of packets with a first port as the source port in all packets; the percentage of packets with a second port as the destination port in all packets; wherein, the first port includes source ports that are at least ranked before a first position in terms of packet volume, and the second port includes destination ports that are at least ranked before a second position in terms of packet volume; the at least one traffic characteristic of the non-ratio type includes at least one of the following: the average packet length of all packets, the total packet volume of all packets, the average lifetime of all packets, and the variance of the packet length of all packets.

[0145] In at least one embodiment of this disclosure, the at least one type includes at least one of the following: TCP packet type, UDP packet type, SYN packet type, ACK packet type, RST / FIN packet type, UDP packet type that hits a UDP reflection port, TCP packet type whose TCP flag does not conform to a predetermined rule, and UDP packet type whose payload hits non-compliant features.

[0146] It should be noted that, for clarity and brevity, this disclosure does not provide all the constituent units of the segment-based DDoS attack detection device 600. To achieve the necessary functions of the segment-based DDoS attack detection device, those skilled in the art can provide and configure other constituent units (not shown) according to specific needs, and this disclosure does not impose any limitations on this.

[0147] At least one embodiment of this disclosure also provides an electronic device, including: a processing device; a storage device including one or more computer program modules; wherein the one or more computer program modules are stored in the storage device and configured to be executed by the processing device, and the one or more computer program modules are used to implement the method for detecting segment-based DDoS attacks provided in any embodiment of this disclosure.

[0148] For example, the processing device can be a processor, such as a central processing unit (CPU), digital signal processor (DSP), image processor (GPU), general-purpose graphics processor (GPGPU), or other form of processing unit with data processing capabilities and / or instruction execution capabilities. It can be a general-purpose processor or a dedicated processor, and can control other components in the electronic device to perform the desired functions.

[0149] For example, the storage device may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, which a processing device may execute to implement the functions (implemented by the processing device) in the embodiments of this disclosure and / or other desired functions, such as a method for detecting segment-based DDoS attacks. Various applications and various data may also be stored in the computer-readable storage medium, such as weights corresponding to N dimensions of traffic characteristics, reference characteristics, multiple value ranges of mutual information, compliance rules for TCP flags, a list of UDP reflection ports, and non-compliant characteristics of the payload.

[0150] The following is for reference. Figure 7 The diagram illustrates a structural schematic of an electronic device (e.g., a terminal device or a server) 700 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 7 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.

[0151] like Figure 7 As shown, the electronic device 700 may include a processing unit (e.g., a central processing unit, a graphics processor, etc.) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage device 708 into a random access memory (RAM) 703. The RAM 703 also stores various programs and data required for the operation of the electronic device 700. The processing unit 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0152] Typically, the following devices can be connected to I / O interface 705: input devices 706 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 707 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 708 including, for example, magnetic tapes, hard disks, etc.; and communication devices 709. Communication device 709 allows electronic device 700 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 7 An electronic device 700 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0153] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 709, or installed from storage device 708, or installed from ROM 702. When the computer program is executed by processing device 701, it performs the functions defined in the methods of embodiments of this disclosure.

[0154] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0155] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0156] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0157] The aforementioned computer-readable medium carries one or more programs. When the electronic device executes the aforementioned one or more programs, the electronic device causes the following: for each of the multiple IP addresses, to obtain a first set of traffic features for a first set of traffic destined for that IP address within a first time period, the first set of traffic features including N-dimensional traffic features, where N is a natural number greater than 1; to calculate the weights corresponding to the N-dimensional traffic features based on historical traffic sets; for each of the multiple IP addresses, to assign corresponding weights to the N-dimensional traffic features obtained for that IP address, thereby obtaining a second set of traffic features corresponding to that IP address; to cluster the multiple IP addresses based on the multiple second sets of traffic features corresponding to the multiple IP addresses, thereby obtaining a clustering result; and based on the clustering result, to determine a first IP address network segment in the IP address network segment where the multiple IP addresses are located that has been subjected to a sweeping DDoS attack.

[0158] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0159] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0160] The units or modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units or modules do not necessarily constitute a limitation on the unit or module itself.

[0161] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.

[0162] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0163] According to one or more embodiments of this disclosure, Example 1 provides a method for detecting segment-based DDoS attacks, including:

[0164] For each IP address among multiple IP addresses, obtain a first traffic feature set of a first traffic set with that IP address as the destination IP address within a first time period. The first traffic feature set includes traffic features of N dimensions, where N is a natural number greater than 1.

[0165] The weights corresponding to the N dimensions of traffic features are calculated based on the historical traffic set.

[0166] For each of the plurality of IP addresses, assign corresponding weights to the N dimensions of traffic features obtained for that IP address to obtain a second set of traffic features corresponding to that IP address;

[0167] Based on multiple sets of second traffic features corresponding to the multiple IP addresses respectively, clustering is performed on the multiple IP addresses to obtain clustering results; and

[0168] Based on the clustering results, the first IP address segment among the IP address segments containing the multiple IP addresses that has been subjected to a segment-sweeping DDoS attack is identified.

[0169] According to one or more embodiments of this disclosure, Example 2 provides the method described in Example 1 of clustering multiple IP addresses based on multiple sets of second traffic features corresponding to the multiple IP addresses to obtain clustering results, including:

[0170] Based on multiple sets of the second flow characteristics, the neighborhood radius is determined; and

[0171] The clustering result is obtained by clustering the multiple IP addresses based on the neighborhood radius.

[0172] According to one or more embodiments of this disclosure, Example 3 provides the method of determining the neighborhood radius based on a plurality of second traffic feature sets as described in Example 2, including:

[0173] For each of the N dimensions, the reference feature corresponding to that dimension is assigned the weight corresponding to the traffic feature of that dimension, thus obtaining the weighted reference feature corresponding to that dimension;

[0174] Determine the deviation values ​​of each of the multiple second traffic feature sets relative to a reference feature set, resulting in multiple deviation values. The reference feature set includes N weighted reference features obtained for the N dimensions; and

[0175] The neighborhood radius is determined based on the multiple deviation values.

[0176] According to one or more embodiments of this disclosure, Example 4 provides the method in Example 3 for determining the neighborhood radius based on the plurality of deviation values, including:

[0177] The average of the plurality of deviation values ​​is determined to obtain the average deviation value; and

[0178] The neighborhood radius is obtained by multiplying the average deviation value by the adjustment coefficient.

[0179] The adjustment coefficient is determined based on the aggregation of destination IP addresses of non-attack traffic.

[0180] According to one or more embodiments of this disclosure, Example 5 provides the detection method of Example 3 or Example 4, and further includes:

[0181] For each of the N dimensions, based on multiple traffic features of that dimension from multiple first traffic feature sets corresponding to the multiple IP addresses, a reference feature corresponding to that dimension is determined; or

[0182] For each of the N dimensions, a reference feature corresponding to that dimension is determined based on the traffic characteristics of the non-attack traffic subset in the historical traffic set.

[0183] According to one or more embodiments of this disclosure, Example Six provides that the N-dimensional traffic features in Example One include at least one traffic feature of a non-ratio type;

[0184] Here, corresponding weights are assigned to the N dimensions of traffic characteristics of this IP address, including:

[0185] For each of the at least one flow feature, the flow feature is normalized to obtain a normalized flow feature; and

[0186] Based on the weight corresponding to the traffic feature, a weight is assigned to the normalized traffic feature.

[0187] According to one or more embodiments of this disclosure, Example 7 provides that the historical traffic set of any of Examples 1 to 3 includes multiple attack traffic subsets and multiple non-attack traffic subsets.

[0188] The step of calculating the weights corresponding to the N dimensions of traffic features based on the historical traffic set includes:

[0189] For each of the N dimensions, obtain the first distribution information of the traffic characteristics of that dimension for the plurality of attack traffic subsets and the second distribution information of the traffic characteristics of that dimension for the plurality of non-attack traffic subsets;

[0190] Based on the first distribution information and the second distribution information, mutual information between traffic characteristics and traffic types in this dimension is determined, wherein the traffic types include attack types and non-attack types; and

[0191] The weights corresponding to the traffic characteristics of this dimension are determined based on the mutual information.

[0192] According to one or more embodiments of this disclosure, Example 8 provides the method in Example 7 for determining the weight value corresponding to the traffic feature of this dimension based on the mutual information, including:

[0193] Determine the first value interval to which the mutual information belongs among multiple value intervals; and

[0194] The weight corresponding to the traffic feature of this dimension is determined to be the first weight that has a mapping relationship with the first value interval.

[0195] According to one or more embodiments of this disclosure, Example 9 provides the detection method of Example 7, further comprising:

[0196] In response to detecting a first number of sweeping DDoS attacks after obtaining the weights corresponding to the traffic features of the N dimensions, the system obtains the attack traffic subset of the first number of sweeping DDoS attacks and the non-attack traffic subset detected within the second time period to update the weights corresponding to the traffic features of the N dimensions.

[0197] The second time period starts at the time when the weight is obtained and ends at the current time.

[0198] According to one or more embodiments of this disclosure, Example 10 provides a first traffic feature set for obtaining a first set of traffic destined for the IP address within a first time period, in any of Examples 1 to 3, including:

[0199] The first traffic feature set of the first traffic set with the IP address as the destination IP address within the first time period starting from the current time is periodically obtained to periodically obtain the clustering result;

[0200] The step of determining, based on the clustering results, the first IP address network segment among the IP address network segments containing the multiple IP addresses that has been subjected to a segment-sweeping DDoS attack includes:

[0201] Identify multiple suspected attack clusters from multiple clustering results obtained over multiple adjacent periods, wherein the number of IP addresses included in a suspected attack cluster is greater than the first number; and

[0202] Based on the spatiotemporal correlation between the multiple suspected attack clusters, the first IP address segment among the IP address segments where the multiple suspected attack clusters are located was identified as having been subjected to a segment-sweeping DDoS attack.

[0203] According to one or more embodiments of this disclosure, Example 11 provides the method described in Example 10 for determining the first IP address network segment in the IP address network segment where the multiple suspected attack clusters are located that has been subjected to a segment-sweeping DDoS attack based on the spatiotemporal correlation between the multiple suspected attack clusters, including:

[0204] In response to the fact that at least two address clusters with spatiotemporal correlation are included among the multiple suspected attack clusters, the IP address network segment where the at least two address clusters are located is determined to be the first IP address network segment that has been subjected to a segment-sweeping DDoS attack.

[0205] According to one or more embodiments of this disclosure, Example Twelve provides the detection method described in Example Eleven, further comprising:

[0206] The IP addresses included in the at least two address clusters are identified as the IP addresses targeted by a segment-based DDoS attack.

[0207] According to one or more embodiments of this disclosure, Example Thirteen provides the method described in Example Eleven for determining the first IP address network segment in the IP address network segment where the multiple suspected attack clusters are located that has been subjected to a segment-sweeping DDoS attack based on the spatiotemporal correlation between the multiple suspected attack clusters, and further includes:

[0208] In response to the fact that at least two address clusters among the plurality of suspected attack clusters satisfy at least one of the following conditions, it is determined that the at least two address clusters have a spatiotemporal correlation:

[0209] The second IP address network segments in which each of the at least two address clusters is located are in the same or consecutive third IP address network segments, wherein the network segment length of the second IP address network segment is less than the network segment length of the third IP address network segment;

[0210] The clustering times of the at least two address clusters are within the same unit time period.

[0211] According to one or more embodiments of this disclosure, Example Fourteen provides that the N-dimensional traffic features of any of Examples One to Three include at least one traffic feature of ratio type and at least one traffic feature of non-ratio type;

[0212] At least one of the following traffic characteristics of the ratio type includes: the percentage of packets of each type in at least one type out of all packets in the first traffic set; the percentage of packets with a first port as the source port out of all packets; the percentage of packets with a second port as the destination port out of all packets; wherein the first port includes source ports that are at least ranked before a first position in terms of packet volume, and the second port includes destination ports that are at least ranked before a second position in terms of packet volume;

[0213] At least one of the following traffic characteristics of the non-ratio type includes: the average packet length of all messages, the total number of messages, the average lifetime of all messages, and the variance of the packet length of all messages.

[0214] According to one or more embodiments of this disclosure, Example Fifteen provides that the at least one type mentioned in Example Fourteen includes at least one of the following: TCP packet type, UDP packet type, SYN packet type, ACK packet type, RST / FIN packet type, UDP packet type that hits a UDP reflection port, TCP packet type that the TCP flag does not conform to a predetermined rule, and UDP packet type that hits a non-compliant feature in the payload.

[0215] According to one or more embodiments of this disclosure, Example Sixteen provides a detection device for segment-based DDoS attacks, comprising:

[0216] The traffic feature acquisition module is configured to acquire a first traffic feature set for each IP address among multiple IP addresses, within a first time period, of a first traffic set with that IP address as the destination IP address. The first traffic feature set includes N dimensions of traffic features, where N is a natural number greater than 1.

[0217] The weight calculation module is configured to calculate the weights corresponding to the N dimensions of traffic features based on the historical traffic set.

[0218] The weighting module is configured to assign corresponding weights to the N dimensions of traffic features obtained for each of the plurality of IP addresses, thereby obtaining a second set of traffic features corresponding to that IP address.

[0219] The address clustering module is configured to cluster the multiple IP addresses based on multiple sets of second traffic features corresponding to the multiple IP addresses to obtain clustering results; and

[0220] The attack segment determination module is configured to determine, based on the clustering results, the first IP address segment among the IP address segments containing the multiple IP addresses that has been subjected to a segment-sweeping DDoS attack.

[0221] According to one or more embodiments of this disclosure, Example Seventeen provides an electronic device, including:

[0222] Processing device; and

[0223] Storage device, including one or more computer program instructions;

[0224] The one or more computer program instructions are executed by the processing device to perform the segment-scanning DDoS attack detection method provided in at least one embodiment of the present disclosure.

[0225] According to one or more embodiments of the present disclosure, Example 18 provides a computer-readable storage medium that non-temporarily stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the method for detecting segment-based DDoS attacks provided in at least one embodiment of the present disclosure.

[0226] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.

[0227] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.

[0228] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.

Claims

1. A method for detecting segment-based DDoS attacks, comprising: For each IP address among multiple IP addresses, obtain a first traffic feature set of a first traffic set with that IP address as the destination IP address within a first time period. The first traffic feature set includes traffic features of N dimensions, where N is a natural number greater than 1. The weights corresponding to the traffic features of the N dimensions are calculated based on the historical traffic set. For each of the N dimensions, the weight corresponding to the traffic feature of that dimension represents the ability of the traffic feature of that dimension to distinguish between attack type traffic and non-attack type traffic. For each of the plurality of IP addresses, assign corresponding weights to the N dimensions of traffic features obtained for that IP address to obtain a second set of traffic features corresponding to that IP address; Based on multiple sets of second traffic features corresponding to the multiple IP addresses respectively, clustering is performed on the multiple IP addresses to obtain clustering results; and Based on the clustering results, the first IP address segment among the IP address segments containing the multiple IP addresses that has been subjected to a segment-sweeping DDoS attack is identified.

2. The detection method according to claim 1, wherein, The step of clustering the multiple IP addresses based on multiple sets of second traffic features corresponding to the multiple IP addresses to obtain clustering results includes: Based on multiple sets of the second flow characteristics, the neighborhood radius is determined; and The clustering result is obtained by clustering the multiple IP addresses based on the neighborhood radius.

3. The detection method according to claim 2, wherein, The step of determining the neighborhood radius based on multiple sets of the second traffic features includes: For each of the N dimensions, the reference feature corresponding to that dimension is assigned the weight corresponding to the traffic feature of that dimension, thus obtaining the weighted reference feature corresponding to that dimension; Determine the deviation values ​​of each of the multiple second traffic feature sets relative to a reference feature set, resulting in multiple deviation values. The reference feature set includes N weighted reference features obtained for the N dimensions; and The neighborhood radius is determined based on the multiple deviation values.

4. The detection method according to claim 3, wherein, Determining the neighborhood radius based on the multiple deviation values ​​includes: The average of the plurality of deviation values ​​is determined to obtain the average deviation value; and The neighborhood radius is obtained by multiplying the average deviation value by the adjustment coefficient. The adjustment coefficient is determined based on the aggregation of destination IP addresses of non-attack traffic.

5. The detection method according to claim 3 or 4, further comprising: For each of the N dimensions, a reference feature corresponding to that dimension is determined based on multiple traffic features of that dimension in multiple first traffic feature sets corresponding to the multiple IP addresses respectively. or For each of the N dimensions, a reference feature corresponding to that dimension is determined based on the traffic characteristics of the non-attack traffic subset in the historical traffic set.

6. The detection method according to claim 1, wherein, The N-dimensional traffic features include at least one traffic feature of non-ratio type; Here, corresponding weights are assigned to the N dimensions of traffic characteristics of this IP address, including: For each of the at least one flow feature, the flow feature is normalized to obtain a normalized flow feature; and Based on the weight corresponding to the traffic feature, a weight is assigned to the normalized traffic feature.

7. The detection method according to any one of claims 1 to 3, wherein, The historical traffic set includes multiple attack traffic subsets and multiple non-attack traffic subsets. The step of calculating the weights corresponding to the N dimensions of traffic features based on the historical traffic set includes: For each of the N dimensions, obtain the first distribution information of the traffic characteristics of that dimension for the plurality of attack traffic subsets and the second distribution information of the traffic characteristics of that dimension for the plurality of non-attack traffic subsets; Based on the first distribution information and the second distribution information, mutual information between the traffic characteristics and traffic types of this dimension is determined, wherein the traffic types include the attack types and the non-attack types; and The weights corresponding to the traffic characteristics of this dimension are determined based on the mutual information.

8. The detection method according to claim 7, wherein, The step of determining the weight corresponding to the traffic feature of this dimension based on the mutual information includes: Determine the first value interval to which the mutual information belongs among multiple value intervals; and The weight corresponding to the traffic feature of this dimension is determined to be the first weight that has a mapping relationship with the first value interval.

9. The detection method according to claim 7, further comprising: In response to detecting a first number of sweeping DDoS attacks after obtaining the weights corresponding to the traffic features of the N dimensions, the system obtains the attack traffic subset of the first number of sweeping DDoS attacks and the non-attack traffic subset detected within the second time period to update the weights corresponding to the traffic features of the N dimensions. The second time period starts at the time when the weight is obtained and ends at the current time.

10. The detection method according to any one of claims 1 to 3, wherein, Obtain the first traffic feature set of the first traffic set with the destination IP address as the first time period, including: The first traffic feature set of the first traffic set with the IP address as the destination IP address within the first time period starting from the current time is periodically obtained to periodically obtain the clustering result; The step of determining, based on the clustering results, the first IP address network segment among the IP address network segments containing the multiple IP addresses that has been subjected to a segment-sweeping DDoS attack includes: Identify multiple suspected attack clusters from multiple clustering results obtained over multiple adjacent periods, wherein the number of IP addresses included in a suspected attack cluster is greater than the first number; and Based on the spatiotemporal correlation between the multiple suspected attack clusters, the first IP address segment in the IP address network segment where the multiple suspected attack clusters are located was identified as having been subjected to a segment-sweeping DDoS attack.

11. The detection method according to claim 10, wherein, The step of determining the first IP address network segment that has been subjected to a sweeping DDoS attack within the IP address network segment where the multiple suspected attack clusters are located, based on the spatiotemporal correlation between the multiple suspected attack clusters, includes: In response to the fact that at least two address clusters with spatiotemporal correlation are included among the multiple suspected attack clusters, the IP address network segment where the at least two address clusters are located is determined to be the first IP address network segment that has been subjected to a segment-sweeping DDoS attack.

12. The detection method according to claim 11, further comprising: The IP addresses included in the at least two address clusters are identified as the IP addresses targeted by a segment-based DDoS attack.

13. The detection method according to claim 11, wherein, The step of determining the first IP address segment in the IP address network segment where the multiple suspected attack clusters are located, which has been subjected to a sweeping DDoS attack, based on the spatiotemporal correlation between the multiple suspected attack clusters, further includes: In response to the fact that at least two address clusters among the plurality of suspected attack clusters satisfy at least one of the following conditions, it is determined that the at least two address clusters have a spatiotemporal correlation: The second IP address network segments in which each of the at least two address clusters is located are in the same or consecutive third IP address network segments, wherein the network segment length of the second IP address network segment is less than the network segment length of the third IP address network segment; The clustering times of the at least two address clusters are within the same unit time period.

14. The detection method according to any one of claims 1 to 3, wherein, The N-dimensional flow characteristics include at least one flow characteristic of the ratio type and at least one flow characteristic of the non-ratio type; At least one of the following traffic characteristics of the ratio type includes: the percentage of packets of each type in at least one type out of all packets in the first traffic set; the percentage of packets with the first port as the source port out of all packets; The percentage of all packets with the second port as the destination port; wherein the first port includes source ports that are at least ranked before the first position in terms of packet volume, and the second port includes destination ports that are at least ranked before the second position in terms of packet volume. At least one of the following traffic characteristics of the non-ratio type includes: the average packet length of all messages, the total number of messages, the average lifetime of all messages, and the variance of the packet length of all messages.

15. The detection method according to claim 14, wherein, The at least one type includes at least one of the following: TCP packet type, UDP packet type, SYN packet type, ACK packet type, RST / FIN packet type, UDP packet type that hits the UDP reflection port, TCP packet type whose TCP flag does not conform to the predetermined rules, and UDP packet type whose payload hits non-compliant features.

16. A detection device for segment-based DDoS attacks, comprising: The traffic feature acquisition module is configured to acquire a first traffic feature set for each IP address among multiple IP addresses, within a first time period, of a first traffic set with that IP address as the destination IP address. The first traffic feature set includes N dimensions of traffic features, where N is a natural number greater than 1. The weight calculation module is configured to calculate the weights corresponding to the traffic features of the N dimensions based on the historical traffic set. For each of the N dimensions, the weight corresponding to the traffic feature of that dimension represents the ability of the traffic feature of that dimension to distinguish between attack type traffic and non-attack type traffic. The weighting module is configured to assign corresponding weights to the N dimensions of traffic features obtained for each of the plurality of IP addresses, thereby obtaining a second set of traffic features corresponding to that IP address. The address clustering module is configured to cluster the multiple IP addresses based on multiple sets of second traffic features corresponding to the multiple IP addresses to obtain clustering results; and The attack segment determination module is configured to determine, based on the clustering results, the first IP address segment among the IP address segments containing the multiple IP addresses that has been subjected to a segment-sweeping DDoS attack.

17. An electronic device comprising: Processing device; as well as Storage device, including one or more computer program instructions; The one or more computer program instructions are executed by the processing device according to any one of claims 1 to 15.

18. A computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, The method described in any one of claims 1 to 15 is implemented when the computer-readable instructions are executed by a processor.

Citation Information

Patent Citations

  • Segment scanning attack detection method and device, equipment and storage medium

    CN117353950A

  • Sweep attack processing method and device and computer equipment

    CN120415870A