Content delivery network (CDN) controller and method for minimizing impact of one or more rate limiters
By generating traffic and attack histograms through the CDN controller, calculating the attack differentiation factor, and dynamically adjusting the rate limiter, the problem of traditional rate limiters having a large impact on legitimate traffic and a high false alarm rate when defending against DDoS attacks is solved, achieving a more efficient balance between user experience and security.
Patent Information
- Application Number
- CN202380098110.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-15
- Publication Date
- 2025-12-26
AI Technical Summary
Existing traffic enforcement technologies present challenges in balancing security and availability, leading to a decline in user experience, especially when defending against DDoS attacks. Traditional rate limiters have a significant impact on legitimate traffic and a high false alarm rate.
By employing a Content Delivery Network (CDN) controller, which generates traffic and attack histograms and calculates the Attack Differentiation Factor (ADF), the rate limiter is dynamically adjusted to distinguish between legitimate and malicious traffic, thereby reducing the impact on legitimate users.
It improves the ability to resist zero-day and sophisticated attacks, reduces false positive rates, ensures the availability of legitimate traffic, enhances user experience, and provides a more effective way to mitigate DDoS attacks.
Smart Images

Figure CN121220002A_ABST
Abstract
Description
Technical Field
[0001] This invention generally relates to network security, and more specifically, to a Content Delivery Network (CDN) controller and a method for minimizing the impact of one or more rate limiters. Background Technology
[0002] Many traditional traffic enforcement techniques, such as rate limiting, traffic shaping, or packet filtering, can negatively impact user experience. Therefore, balancing security and availability in the context of traffic enforcement is a challenge.
[0003] Packet loss filters are designed to prevent certain packets from reaching their destinations, but they can also cause legitimate session interruptions and retransmissions, leading to a poor user experience. To minimize the impact, filters must be carefully tuned and set with appropriate thresholds. Network administrators must monitor the impact on user experience and make adjustments as needed.
[0004] The purpose of these technologies is to limit or prioritize network traffic based on specific criteria such as source Internet Protocol (IP) address, packet type, or date and time to prevent various threats, such as distributed denial-of-service (DDoS) attacks, malware infections, or unauthorized access.
[0005] These technologies can also lead to slower page load times, increased latency, or other types of disruption, thus degrading the user experience. This can frustrate users, cause lost revenue, or reduce productivity, ultimately undermining the overall effectiveness of the network or system. In today's digital environment, balancing security and availability is particularly challenging, as users expect fast, reliable, and seamless access to information and services. To remain competitive, organizations must find ways to protect their networks and systems from threats while simultaneously providing a good user experience.
[0006] A more granular, context-aware approach to traffic enforcement is introduced, taking into account user behavior, device type, and other factors. For example, administrators can use machine learning techniques to identify patterns of behavior indicating malicious intent and restrict only traffic matching these patterns, rather than simply rate-limiting all traffic originating from a specific Internet Protocol (IP) address. This approach is necessary because many traditional traffic enforcement techniques, such as rate limiting or traffic shaping, negatively impact user experience by slowing page load times or otherwise interfering with legitimate traffic. By estimating the impact on user experience, network administrators can make informed decisions about which enforcement techniques to use and how to configure them.
[0007] Combining multiple traffic enforcement mechanisms helps to effectively defend against various threats while minimizing negative impacts on user experience. This principle is necessary because no single traffic enforcement technology is perfect; different technologies may be better suited to different types of threats. By combining multiple technologies in an optimized manner, network administrators can provide better threat protection without compromising user experience. The traffic enforcement combination is adjusted based on network or system feedback. This approach is necessary because traffic patterns and threats can change over time, and static configurations are not necessarily optimal in all situations. By automatically adjusting the combination structure based on feedback, network administrators can ensure that the system is both secure and available.
[0008] Therefore, it is necessary to address the aforementioned technical issues / drawbacks in balancing security and availability in the context of traffic execution. Summary of the Invention
[0009] One object of the present invention is to provide a Content Distribution Network (CDN) controller for minimizing the impact of one or more rate limiters, and a method in the CDN controller for minimizing the impact of one or more rate limiters while avoiding one or more disadvantages of prior art methods.
[0010] This objective is achieved through the features of the independent claim. Other implementations are apparent in the dependent claims, the specification, and the drawings.
[0011] The present invention provides a Content Distribution Network (CDN) controller for minimizing the impact of one or more rate limiters, and a method for minimizing the impact of one or more rate limiters in the CDN controller.
[0012] According to a first aspect, a Content Distribution Network (CDN) controller is provided. The CDN controller is used to minimize the impact of one or more rate limiters. The CDN controller is used to receive a first plurality of data packets. Each data packet includes one or more packet features. The CDN controller is used to generate a traffic histogram for the packet features based on the first plurality of data packets. The histogram of the packet features is based on matching the packet features with multiple conditions, each condition corresponding to a bin in the traffic histogram. The traffic histogram represents a benign traffic quota (BQ). The CDN controller is used to determine that an attack is in progress. The CDN controller is used to receive a second plurality of data packets. The CDN controller is used to determine the effect of the rate limiter on the packet features by: (a) generating an attack histogram for the packet features based on the second plurality of data packets, and (b) determining an Attack Differentiating Factor (ADF) for each bin in the attack histogram according to the following formula: ADF(f, i) = AQ(f, i) / BQ(f, i), where f represents the packet feature and i represents the histogram value bin. The attack histogram represents the attack traffic quota (AQ). The attack differentiating factor (ADF) represents the effect of the rate limiter.
[0013] The aforementioned CDN controller provides more accurate filtering technology. It minimizes the impact on legitimate users and reduces false positives. By ensuring effective attack mitigation without affecting the availability of legitimate traffic, it improves user experience. A system implemented using this CDN controller enhances resilience against zero-day and sophisticated attacks, is relatively simple, requires no extensive training, is suitable for dynamically changing traffic patterns, and features a relatively compact decision engine and real-time efficiency. The CDN controller is easy to detect, making it easy to assess the system's ability to handle adversarial traffic. It can also be applied to cloud infrastructure. This CDN controller provides a more effective and user-friendly way to mitigate Distributed Denial of Service (DDoS) attacks.
[0014] The aforementioned CDN controller improves the reliability of content distribution. By distributing content across multiple servers and geographical locations, the CDN controller ensures content availability even in the event of server failures or network outages. The CDN controller is easily scalable to handle increasing traffic, enabling organizations to meet surging demand without performance issues. By handling requests for cacheable content, the CDN controller reduces the load on origin servers, thereby improving server performance and mitigating the risk of server overload during peak traffic periods. The CDN controller provides enhanced security for content distribution by offering Distributed Denial of Service (DDoS) protection, Secure Socket Layer (SSL) encryption, and other security features.
[0015] Optionally, the CDN controller is further configured to determine the Attack Differentiating Factor (ADF) according to the following formula: ADF(f, i)=AQ(f, i) / Max(BQ(f, i); MinBQ(f, i)), where MinBQ(f, i) is the set minimum value of the interval i corresponding to feature f in the traffic before the attack.
[0016] The Attack Differentiating Factor (ADF) is used to distinguish between legitimate traffic and malicious traffic during an attack. By minimizing the Attack Differentiating Factor (ADF), the timing of an attack can be identified, and the rate limiter can be adjusted accordingly.
[0017] Optionally, the CDN controller is also configured to set MinBQ to the default minimum value.
[0018] Optionally, the CDN controller is further configured to select rate limiters to be combined from a plurality of interval-specific rate limiters. Each rate limiter is associated with one or more intervals in a histogram of suitable features. The CDN controller is configured to determine the Attack Differentiating Factor (ADF) for the one or more packet features. The CDN controller is configured to select the rate limiter to be executed as the rate limiter associated with the interval of the packet feature having the highest Attack Differentiating Factor (ADF).
[0019] Optionally, the CDN controller is further configured to determine packet characteristics where the Attack Differentiating Factor (ADF) exceeds a threshold before selecting the rate limiter to be executed.
[0020] Optionally, the controller is also configured to determine that the ADF exceeds a threshold using the Kolmogorov-Smirnov Test.
[0021] Optionally, the CDN controller is further configured to determine, before selecting the rate limiter to be executed, that there are no packet features whose Attack Differentiating Factor (ADF) exceeds a threshold, and in response, not select the rate limiter to be executed.
[0022] Rate limiters reduce the impact of attacks on legitimate traffic, ensuring network continuity. They provide fast response times, enabling organizations to detect and mitigate attacks in real time. Rate limiters offer several advantages to organizations facing network attacks. They can withstand large-scale attacks, preventing excessive traffic from causing denial-of-service.
[0023] Optionally, the CDN controller is further configured to determine whether to select another rate limiter to be executed by: (a) determining the amount of traffic to be removed (RMV), wherein the amount of traffic to be removed is determined to be traffic exceeding an attack threshold, and (b) determining that the amount of traffic to be removed (RMV) is greater than 0, and in response, selecting another rate limiter based on the Attack Differentiating Factor (ADF) determined for the packet characteristics. The amount of traffic to be removed is determined to be traffic exceeding an attack threshold.
[0024] Optionally, the CDN controller is further configured to determine that the attack is still ongoing and respond accordingly. The CDN controller is configured to receive a second plurality of additional data packets and determine a second attack histogram based on the second plurality of additional data packets and the Attack Differentiating Factor (ADF) of the packet characteristics.
[0025] Optionally, the CDN controller is also configured to determine that the attack is still ongoing at certain intervals. The intervals may be 45 seconds, 60 seconds, 75 seconds, 90 seconds, 105 seconds, 120 seconds, 135 seconds, 150 seconds, 165 seconds, or 180 seconds, or any range in between.
[0026] Optionally, the CDN controller is further configured to determine the traffic volume (RMV) to be removed as RMV=FF×SUM(AQ(f, i)), where FF is a feedback factor and is determined as FFj=1–RMVj–1 / RMVj–2, FF0=FF1=1.
[0027] Optionally, the packet characteristics include the number of packets, the number of open connections, the packet size, the packet header size, the payload size, the protocol type, the destination port, the source port, the fragment number, the time to live (TTL), the Transmission Control Protocol (TCP) flag, the sequence counter, or the Internet Protocol (IP) identifier.
[0028] According to a second aspect, a method is provided for minimizing the impact of one or more rate limiters in a Content Distribution Network (CDN) controller. The method includes: receiving a first plurality of data packets, wherein each data packet includes one or more packet features. The method includes: generating a traffic histogram for the packet features based on the first plurality of data packets. The histogram of the packet features is based on matching the packet features with a plurality of conditions, each condition corresponding to an interval in the traffic histogram. The traffic histogram represents a benign traffic quota (BQ). The method includes: determining that an attack is in progress. The method includes: receiving a second plurality of data packets. The method includes: determining the effect of the rate limiter on the packet features by generating an attack histogram for the packet features based on the second plurality of data packets. The attack histogram represents an attack traffic quota (AQ). The method includes determining an Attack Differentiating Factor (ADF) for each interval of the attack histogram according to the following formula: ADF(f, i) = AQ(f, i) / BQ(f, i), where f represents the packet feature and i represents the histogram value interval. The Attack Differentiating Factor (ADF) represents the effect of the rate limiter.
[0029] This approach offers more accurate filtering technology. It minimizes the impact on legitimate users and reduces false positives. It improves user experience by effectively mitigating attacks without affecting the availability of legitimate traffic. This approach enhances the system's resilience against zero-day and sophisticated attacks, and is relatively simple, requiring no extensive training, suitable for dynamically changing traffic patterns, and features a relatively compact decision engine and real-time efficiency. This approach is easy to detect, allowing for easy evaluation of the system's ability to handle adversarial traffic. This approach provides a more effective and user-friendly way to mitigate Distributed Denial of Service (DDoS) attacks.
[0030] Optionally, the method includes: selecting rate limiters to be combined from a plurality of interval-specific rate limiters. Each rate limiter is associated with one or more intervals in a histogram of suitable features. The method includes: determining the Attack Differentiating Factor (ADF) for the one or more packet features. The method includes: selecting the rate limiter to be executed as the rate limiter associated with the interval of the packet feature having the highest Attack Differentiating Factor (ADF).
[0031] According to a third aspect, a computer program product including program instructions is provided. When executed by one or more processors in a Content Distribution Network (CDN) controller system, the program instructions are used to perform the second aspect.
[0032] The aforementioned computer program products offer more accurate filtering technology. They minimize the impact on legitimate users and reduce false positives. By ensuring effective attack mitigation without affecting the availability of legitimate traffic, they improve user experience. They enhance the system's resilience against zero-day and sophisticated attacks, are relatively simple, require no extensive training, are suitable for dynamically changing traffic patterns, and feature a relatively compact decision engine and real-time efficiency. They are easy to detect, allowing for easy assessment of the system's ability to handle adversarial traffic. Finally, they provide a more effective and user-friendly way to mitigate Distributed Denial of Service (DDoS) attacks.
[0033] This invention solves the technical problem in the prior art, which is to minimize the impact of UX and provide a feedback-based real-time combinatorial rebalancing method.
[0034] Therefore, unlike existing technologies, a CDN controller and method for minimizing the impact of one or more rate limiters enable more accurate filtering to improve the overall user experience while minimizing the occurrence of truly negative events that are often unavoidable in rate limiters. The aforementioned CDN controller and method enhance the system's resilience against zero-day and sophisticated attacks, making it more secure and robust. The CDN controller and method are relatively simple, require no extensive training, are suitable for dynamically changing traffic patterns, and feature a relatively compact decision engine and real-time efficiency, making them a highly attractive option for organizations seeking to defend against Distributed Denial of Service (DDoS) attacks while maintaining optimal user experience and system performance. Enhancing DDoS attack mitigation offers several benefits, significantly improving the user experience by minimizing the impact of malicious traffic on key performance indicators (KPIs) such as response time and service interruption through more accurate filtering. By using more advanced systems to more accurately distinguish between legitimate and malicious traffic, the inevitable negative events in rate limiters can be reduced. CDN controllers can rapidly adapt to detect and mitigate new types of attacks, thus enhancing their resilience against zero-day and sophisticated attacks. Relatively simple and requiring no extensive training, CDN controllers are adaptable to dynamically changing traffic patterns, feature a relatively compact decision engine and real-time efficiency, offering significant advantages over state-of-the-art tools. This provides organizations seeking to protect their systems and users from cyberattacks with a low-cost and easy-to-use solution. By achieving these advantages, mitigating Distributed Denial of Service (DDoS) attacks provides enterprises and organizations with a reliable and efficient way to protect their infrastructure and users from cyber threats.
[0035] These and other aspects of the invention will be apparent from one or more implementations described below. Attached Figure Description
[0036] The implementation of the present invention will now be described by way of example only, with reference to the accompanying drawings, in which:
[0037] Figure 1 This is a block diagram of a Content Distribution Network (CDN) controller provided in one implementation of the present invention;
[0038] Figures 2A to 2D This is an exemplary graphical view of a histogram-formatted package feature provided in one implementation of the present invention;
[0039] Figures 3A to 3D This is an exemplary graphical view of packet features provided by one implementation of the present invention for generating rate limiting rules in a histogram format that minimizes the risk of loss.
[0040] Figure 3E This is one implementation of the present invention. Figures 3A to 3D An exemplary table view of the Attack Differentiating Factor (ADF) values of packet features in the data;
[0041] Figure 4 This is a flowchart of a process that minimizes the impact of one or more rate limiters, provided by one implementation of the present invention;
[0042] Figure 5A and Figure 5B This is a flowchart illustrating a method for minimizing the impact of one or more rate limiters in a Content Distribution Network (CDN) controller, as provided in one implementation of the present invention.
[0043] Figure 6 It is a diagram of a computer system (e.g., a Content Distribution Network (CDN) controller) that can implement various architectures and functions of various prior implementations. Detailed Implementation
[0044] Various implementations of the present invention provide a content distribution network (CDN) controller for minimizing the impact of one or more rate limiters, and a method for minimizing the impact of one or more rate limiters in a content distribution network (CDN) controller.
[0045] To enable those skilled in the art to more easily understand the present invention, the following implementation of the present invention is described with reference to the accompanying drawings.
[0046] In the description of the invention, the claims, and the accompanying drawings, the terms "first," "second," "third," and "fourth" (if any) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that these terms are interchangeable where appropriate, and therefore, the embodiments of the invention described herein can be implemented in orders other than those described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to the explicitly listed steps or units, but may include other steps or units not explicitly listed or inherent to the aforementioned process, method, product, or apparatus.
[0047] Figure 1 This is a block diagram of a Content Distribution Network (CDN) controller 102 provided in one implementation of the present invention. The CDN controller 102 is used to minimize the impact of one or more rate limiters. The CDN controller 102 is used to receive a first plurality of data packets 104A to 104N. Each data packet includes one or more packet features. The CDN controller 102 is used to generate a traffic histogram 108 for the packet features based on the first plurality of data packets 104A to 104N. The traffic histogram 108 of the packet features is based on matching multiple conditions, each condition corresponding to an interval (bin) in the traffic histogram 108. The traffic histogram 108 represents a benign traffic quota (BQ). The CDN controller 102 is used to determine that an attack is in progress. The CDN controller 102 is used to receive a second plurality of data packets 106A to 106N. CDN controller 102 determines the effect of the rate limiter on packet characteristics by: (a) generating an attack histogram 110 for packet characteristics based on a second plurality of data packets, and (b) determining an attack differentiating factor (ADF) for each interval in the attack histogram 110 according to the following formula: ADF(f, i) = AQ(f, i) / BQ(f, i), where f represents the packet characteristic and i represents the histogram value interval. The attack histogram 110 represents the attack traffic quota (AQ). The attack differentiating factor (ADF) represents the effect of the rate limiter.
[0048] CDN Controller 102 provides more accurate filtering technology. It minimizes the impact on legitimate users and reduces false positives. CDN Controller 102 improves user experience by effectively mitigating attacks without affecting the availability of legitimate traffic. A system implemented using CDN Controller 102 enhances resilience against zero-day and sophisticated attacks, is relatively simple, requires no extensive training, is suitable for dynamically changing traffic patterns, and features a relatively compact decision engine and real-time efficiency. CDN Controller 102 is easy to detect, making it easy to assess the system's ability to handle adversarial traffic. CDN Controller 102 can also be applied to cloud infrastructure. CDN Controller 102 provides a more effective and user-friendly way to mitigate Distributed Denial of Service (DDoS) attacks.
[0049] CDN Controller 102 enhances the reliability of content distribution. By distributing content across multiple servers and geographic locations, CDN Controller 102 ensures content availability even in the event of server failures or network outages. CDN Controller 102 is easily scalable to handle increasing traffic, enabling organizations to meet surging demand without performance issues. By handling requests for cacheable content, CDN Controller 102 reduces the load on origin servers, thereby improving server performance and mitigating the risk of server overload during peak traffic periods. CDN Controller 102 provides enhanced security for content distribution by offering Distributed Denial of Service (DDoS) protection, Secure Socket Layer (SSL) encryption, and other security features.
[0050] Optionally, the CDN controller 102 is used to determine the Attack Differentiating Factor (ADF) according to the following formula: ADF(f, i)=AQ(f, i) / Max(BQ(f, i); MinBQ(f, i)), where MinBQ(f, i) is the set minimum value of the interval i corresponding to feature f in the traffic before the attack.
[0051] The Attack Differentiating Factor (ADF) is used to distinguish between legitimate traffic and malicious traffic during an attack. By minimizing the Attack Differentiating Factor (ADF), the timing of an attack can be identified, and the rate limiter can be adjusted accordingly.
[0052] Optionally, the CDN controller 102 is used to set MinBQ to the default minimum value.
[0053] Optionally, the CDN controller 102 is used to select rate limiters to be combined from a plurality of interval-specific rate limiters. Each rate limiter is associated with one or more intervals in a histogram of suitable features. The CDN controller 102 is used to determine an Attack Differentiating Factor (ADF) for one or more packet features. The CDN controller 102 is used to select the rate limiter to be executed as the rate limiter associated with the interval of the packet feature having the highest Attack Differentiating Factor (ADF).
[0054] Optionally, the CDN controller 102 is further configured to identify packet characteristics where the Attack Differentiating Factor (ADF) exceeds a threshold before selecting a rate limiter to be executed. Optionally, the CDN controller 102 is further configured to determine if the ADF exceeds the threshold using a Kolmogorov-Smirnov test. Optionally, the Kolmogorov-Smirnov test defines the maximum possible difference between the threshold and the current value, but considers this maximum difference to be insignificant (not exceeding normal parameter deviation).
[0055] Optionally, the CDN controller 102 is also configured to determine, before selecting a rate limiter to be executed, that there are no packet characteristics whose Attack Differentiating Factor (ADF) exceeds a threshold, and in response, not select a rate limiter to be executed.
[0056] Rate limiters reduce the impact of attacks on legitimate traffic, ensuring network continuity. They provide fast response times, enabling organizations to detect and mitigate attacks in real time. Rate limiters offer several advantages to organizations facing network attacks. They can withstand large-scale attacks, preventing excessive traffic from causing denial-of-service.
[0057] Optionally, the CDN controller 102 is further configured to determine whether to select another rate limiter to be executed by: (a) determining the amount of traffic to be removed (RMV), and (b) determining that the amount of traffic to be removed (RMV) is greater than 0, and in response, selecting another rate limiter based on the Attack Differentiating Factor (ADF) determined for packet characteristics. The amount of traffic to be removed is determined to be the amount of traffic exceeding the attack threshold.
[0058] Optionally, the CDN controller 102 is also configured to determine that the attack is still ongoing and to respond accordingly. The CDN controller 102 is configured to receive additional second plurality of data packets and to determine a second attack histogram based on the additional second plurality of data packets and the attack differentiating factor (ADF) of the packet characteristics.
[0059] Optionally, the CDN controller 102 is also used to determine if an attack is still ongoing at certain intervals. These intervals can be 45 seconds, 60 seconds, 75 seconds, 90 seconds, 105 seconds, 120 seconds, 135 seconds, 150 seconds, 165 seconds, or 180 seconds, or any range in between.
[0060] Optionally, the CDN controller 102 is further configured to determine the amount of traffic to be removed (RMV) as RMV=FF×SUM(AQ(f,i)), where FF is a feedback factor and is determined as FFj=1–RMVj–1 / RMVj–2, FF0=FF1=1.
[0061] Optionally, packet characteristics include the number of packets, the number of open connections, packet size, packet header size, payload size, protocol type, destination port, source port, fragment number, time to live (TTL), Transmission Control Protocol (TCP) flag, sequence counter, or Internet Protocol (IP) identifier.
[0062] Figures 2A to 2DThis is an exemplary graphical view of packet features in histogram format provided in one implementation of the present invention. Packet features include the number of packets, the number of open connections, packet size, header size, payload size, protocol type, destination port, source port, fragment number, Time to Live (TTL), Transmission Control Protocol (TCP) flag, sequence counter, or Internet Protocol (IP) identifier. Packet features are represented as a histogram, with the X-axis representing values and the Y-axis representing the corresponding percentages. Optionally, packet features are used to create histograms for anomaly detection and generation of optimal rate limiting rules. Packet features include one or more graphical views of at least one of packet size 202A, Transmission Control Protocol (TCP) flag 202B, Time to Live (TTL) 202C, and source port 202D. Optionally, packet characteristics include one or more graphical representations of Internet Protocol (IP) header size, payload size, L4 header size, L4 payload size, protocol type, destination port, source port, geographic location, fragment number, sequence number, or Internet Protocol (IP) Identity (ID). Under a Distributed Denial of Service (DDoS) attack, the histogram may show signs of distributed disruption. These signs may include interval values larger than expected. Histograms with distributed disruptions can be selected to evaluate the impact on user experience (UX) and generation rate limiting rules.
[0063] Figures 3A to 3DThis is an exemplary graphical view of packet features in a histogram format provided by one implementation of the present invention for generating rate-limiting rules to a minimum. The graphical view of histogram 302 includes adversarial traffic and benign traffic. Histogram 302 includes one or more packet features and one or more intervals, namely V1 to V5. The Attack Differentiating Factor (ADF) is calculated for all intervals in histogram 302 according to the following formula: ADF(f,i)=AQ(f, i) / Max(BQ(f, i); MinBQ(f, i)), where MinBQ(f, i) is the set minimum value of interval i corresponding to feature f in the traffic before the attack. Optionally, f represents the feature identifier, i represents the interval number in histogram 302 related to f, AQ represents the quota of adversarial traffic in the total incoming traffic, and BQ represents the quota of benign traffic in the total incoming traffic. MinBQ can be the smallest possible value greater than 0 in a suitable interval, measured as an integer in the range of 1 to 10,000 packets or bytes.
[0064] Histogram 302 includes the interval 304, or V4, with the highest Attack Differentiating Factor (ADF). This means that rate limiting using the specific condition F=V4 can maximally suppress adversarial traffic with minimal impact on benign traffic, thus minimizing disruption to user experience (UX). The selected intervals in the histogram can be sorted by their Attack Differentiating Factor (ADF).
[0065] like Figure 3B , Figure 3C and Figure 3D As shown in the graphical view, the top-ranked intervals can be used to create Rate Limiting Rule (RLM) rule 308 for the traffic volume (RMV) 306 to be removed, to remove excessive traffic, and to restore the filtered traffic to the normal range below the threshold. Rate Limiting Rule (RLM) rules 308 can overlap, but overall, the traffic volume (RMV) 306 to be removed created by all Rate Limiting Rule (RLM) rules 308 may be less than the absolute sum. A feedback-based self-optimizing rule combination feedback factor (FF) approach helps address the overlap problem of Rate Limiting Rule (RLM) rules 308. FF is calculated as FF = 1 – most recent RMV / previous RMV.
[0066] Figure 3E This is one implementation of the present invention. Figures 3A to 3D An exemplary table view 310 shows the Attack Differentiating Factor (ADF) values of packet characteristics. Table view 310 includes multiple buckets, namely the ranges from V1 to V5, and corresponding values associated with benign traffic quotas (BQ), attack traffic quotas (AQ), and Attack Differentiating Factor (ADF).
[0067] Dropping valid packets through rate-limiting filters can negatively impact user experience (UX). Attack vectors (i.e., Transmission Control Protocol (TCP) packet flooding) are identified as excessive traffic generated by appropriate types of packets, and rules for dropping packets are generated. Attack vectors can reduce unnecessary excessive traffic. For example, if 70% of TCP traffic is dropped, then 7 out of 10 packets with a TCP value in the protocol type field are dropped. This results in most of the dropped packets being adversarial packets, whereas statistically, the dropped packets represent benign traffic. TCP sessions with packet loss become sluggish due to additional retransmissions or terminate when multiple packets in the same session cannot be exchanged. Because benign traffic represents the lowest percentage, the probability of dropping benign packets in the selection is lower than in the alternative, minimizing the UX impact and providing a method for selective packet dropping. In traffic with appropriate characteristics (including TCP packets, packets of size 76, packets destined for port 1213, etc.), the ratio between attack quotas and benign quotas is called the Attack Differentiating Factor (ADF). The ADF is used to create drop rules that rank appropriate packet characteristics based on the highest-ranking intervals. In the highest-ranking intervals, dropping packets in interval 4 (V4) statistically results in only a 2% loss of valid packets. Statistically, dropping packets associated with interval 2 (V2) results in a 20% loss of valid packets, negatively impacting UX. Optionally, interval 2 (V2) can be used when a single filtering rule and interval 4 (V4) cannot clear the flooded portion of the traffic.
[0068] Figure 4This is a flowchart illustrating a process for minimizing the impact of one or more rate limiters, provided by one implementation of the present invention. A first set of first plurality of data packets is received in a system implemented using a Content Distribution Network (CDN) controller. Optionally, each data packet includes one or more packet characteristics. Optionally, a traffic histogram is created for the packet characteristics based on the first set of first plurality of data packets. In step 402, it is determined that an attack is in progress. The in progress attack may be a Distributed Denial of Service (DDoS) attack. Optionally, a DDoS attack is detected by a significant decrease in one or more Quality of Service (QoS) Key Performance Indicators (KPIs) (including response time or service interruption). Optionally, technical measurements (including Packet Per Second (PPS) and Bit Per Second (BPS), Central Processing Unit (CPU) percentage, and the number of Transmission Control Protocol (TCP) connections) can identify a DDoS attack. In step 404, when an attack is identified, the Distributed Denial of Service (DDoS) metric is evaluated. In step 406, based on the DDoS metric evaluation results, it is determined whether the Key Performance Indicator (KPI) is within the limit. If the KPI is within the limit, the histogram is refreshed in step 408. The packet feature histogram matches multiple conditions based on packet features, each condition corresponding to an interval in the histogram. The traffic histogram represents the benign traffic quota (BQ). All traffic histograms can be run simultaneously, using pre-recorded traffic snapshots at various depths. In step 410, the reference template is updated, and then steps 406, 408, and 410 are repeated until the KPI limit is exceeded.
[0069] In step 412, the Attack Differentiating Factor (ADF) is calculated for each interval in the histogram according to the following formula: ADF(f, i) = AQ(f, i) / BQ(f, i). f represents the packet feature, and i represents the histogram value interval. Optionally, the Attack Differentiating Factor (ADF) represents the effect of the rate limiter. In step 414, the intervals in the histogram are sorted according to the Attack Differentiating Factor (ADF) in the user experience (UX) rate. In step 416, the amount of traffic to be removed (RMV) is determined to determine whether the amount of traffic to be removed (RMV) reaches 0. When the amount of traffic to be removed (RMV) is greater than 0, in step 418, a Rate Limiting Rule (RLM) is added to the top-ranked interval in the histogram. Optionally, a rate limiter is determined for packet features based on the ADF until the amount of traffic to be removed (RMV) is 0. The Removable Traffic Volume (RMV) is determined as the traffic volume exceeding the attack threshold. Rate limiters can be based on the histogram range with the highest ranking and lowest UX invasiveness. Optionally, if applying the "highest ranking" rate limiter fails to restore the QoS KPIs to normal, the system can add more Rate Limiting Rules (RLMs) until the desired Removable Traffic Volume (RMV) target is reached. When the Removable Traffic Volume (RMV) reaches 0, an ongoing attack is re-identified in step 420. An ongoing attack can be identified when the KPIs are outside the limits. In a DDoS attack, the histogram may be continuously evaluated to switch to the most efficient histogram as the attack changes or a new histogram emerges. In step 422, all applied rate limiters are removed.
[0070] Figure 5A and Figure 5BThis is a flowchart illustrating a method for minimizing the impact of one or more rate limiters in a Content Delivery Network (CDN) controller, according to one implementation of the present invention. In step 502, a first plurality of data packets are received. Each data packet includes one or more packet features. In step 504, a traffic histogram is generated for the packet features based on the first plurality of data packets. The histogram of the packet features matches multiple conditions based on the packet features, each condition corresponding to an interval in the traffic histogram. The traffic histogram represents a benign traffic quota (BQ). In step 506, an ongoing attack is identified. In step 508, a second plurality of data packets are received. In step 510, the effect of the rate limiter on the packet characteristics is determined by: (a) generating an attack histogram for the packet characteristics based on the second plurality of data packets, and (b) determining an Attack Differentiating Factor (ADF) for each interval in the attack histogram according to the following formula: ADF(f, i) = AQ(f, i) / BQ(f, i), where f represents the packet characteristics and i represents the histogram value interval. The attack histogram represents the attack traffic quota (AQ). The Attack Differentiating Factor (ADF) represents the effect of the rate limiter.
[0071] This approach offers more accurate filtering technology. It minimizes the impact on legitimate users and reduces false positives. It improves user experience by effectively mitigating attacks without affecting the availability of legitimate traffic. This approach enhances the system's resilience against zero-day and sophisticated attacks, and is relatively simple, requiring no extensive training, suitable for dynamically changing traffic patterns, and features a relatively compact decision engine and real-time efficiency. This approach is easy to detect, allowing for easy assessment of the system's ability to handle adversarial traffic. This approach provides a more effective and user-friendly way to mitigate DDoS attacks.
[0072] Optionally, the above method includes: selecting rate limiters to be combined from a plurality of interval-specific rate limiters. Each rate limiter is associated with one or more intervals in a histogram of suitable features. The above method includes: determining the Attack Differentiating Factor (ADF) for the one or more packet features. The above method includes: selecting the rate limiter to be executed as the rate limiter associated with the interval of the packet feature having the highest Attack Differentiating Factor (ADF).
[0073] In one implementation, a computer program product including program instructions is provided. When executed by one or more processors in a Content Distribution Network (CDN) controller system, the program instructions are used to perform the methods described above.
[0074] Figure 6 This is an illustration of a computer system (e.g., a database management system) capable of implementing various architectures and functions of various prior implementations. As shown, computer system 600 includes at least one processor 604 connected to bus 602. Computer system 600 can be implemented using any suitable protocol, such as Peripheral Component Interconnect (PCI), PCI Express, Accelerated Graphics Port (AGP), Hyper Transport, or any other bus or one or more point-to-point communication protocols. Computer system 600 also includes memory 606.
[0075] The control logic (software) and data are stored in memory 606, which may be random-access memory (RAM). In this invention, a single semiconductor platform can refer to a single, individual semiconductor-based integrated circuit or chip. It should be noted that the term "single semiconductor platform" can also refer to multi-chip modules with enhanced connectivity (these multi-chip modules simulate on-chip modules with enhanced connectivity, and these on-chip modules simulate on-chip operations), representing a significant improvement compared to implementations using traditional central processing units (CPUs) and buses. Of course, various modules can also be installed individually or combined on different semiconductor platforms according to user needs.
[0076] Computer system 600 also includes auxiliary storage 610. Auxiliary storage 610 includes hard disk drives and removable storage drives, such as floppy disk drives, magnetic tape drives, optical disk drives, digital versatile disk (DVD) drives, recording devices, and universal serial bus (USB) flash memory. The removable storage drives drive reading from and / or writing to the removable storage unit in a known manner.
[0077] Computer programs or computer control logic algorithms may be stored in at least one of the memory 606 and the auxiliary memory 610. When executed, these computer programs enable the computer system 600 to perform the various functions described above. The memory 606, the auxiliary memory 610, and any other storage are possible examples of computer-readable media.
[0078] In one implementation, the architecture and functionality described in the preceding figures can be implemented within the context of processor 604, a graphics processor coupled to communication interface 612, an integrated circuit (not shown) capable of simultaneously possessing at least some of the functions of processor 604 and graphics processor, a chipset (i.e., a set of integrated circuits designed to function and be sold as units performing related functions, etc.).
[0079] Furthermore, the architectures and functions described in the preceding diagrams can also be implemented in the context of general-purpose computer systems, circuit board systems, game console systems dedicated to entertainment, and special-purpose systems. For example, computer system 600 can be a desktop computer, laptop computer, server, workstation, game console, or embedded system.
[0080] In addition, the computer system 600 can also be various other devices, including but not limited to personal digital assistant (PDA) devices, mobile phone devices, smartphones, televisions, etc. Furthermore, the computer system 600 can be coupled to a network (e.g., telecommunications networks, local area networks (LANs), wireless networks, wide area networks (WANs) such as the Internet, peer-to-peer networks, cable networks, etc.) to communicate via I / O interface 608.
[0081] It should be understood that the component arrangements shown in the described figures are exemplary, and other arrangements may exist. It should also be understood that the various system components (and elements) defined by the claims, described below, and shown in the various block diagrams represent components in some systems configured according to the subject matter disclosed herein. For example, one or more of these system components (and elements) may be implemented wholly or partially by at least some of the components illustrated in the arrangements shown in the described figures.
[0082] In addition, while at least one of these components is implemented at least partially as an electronic hardware component and thus constitutes a machine, the other components may be implemented in software, which, when included in the execution environment, constitutes a machine, hardware, or a combination of software and hardware.
[0083] While the invention and its advantages have been described in detail, it should be understood that various changes, substitutions and alterations may be made herein without departing from the scope and spirit of the invention as defined by the appended claims.
Claims
1. A Content Delivery Network (CDN) controller (102) for minimizing the impact of one or more rate limiters, characterized in that, The CDN controller (102) is used for: Receive the first plurality of data packets (104A to 104N), wherein each data packet includes one or more packet features; A traffic histogram (108) is generated for the packet features based on the first plurality of data packets (104A to 104N), wherein the traffic histogram (108) of the packet features is based on matching multiple conditions with the packet features, each condition corresponding to an interval in the traffic histogram (108), and the traffic histogram (108) represents a benign traffic quota (BQ). An ongoing attack has been confirmed; Receive a second set of multiple data packets (106A to 106N). The effect of the rate limiter on packet characteristics is determined in the following ways: An attack histogram (110) is generated for the packet characteristics based on the second plurality of data packets, wherein the attack histogram (110) represents the attack traffic quota (AQ). The Attack Differentiating Factor (ADF) is determined for each interval in the attack histogram (110) according to the following formula: ADF(f, i)=AQ(f, i) / BQ(f, i), Where f represents the packet feature. i represents the range of values for the histogram. The ADF represents the effect of the rate limiter.
2. The CDN controller (102) according to claim 1, characterized in that, The CDN controller (102) is also used to determine the ADF according to the following formula: ADF(f, i)=AQ(f, i) / Max(BQ(f, i); MinBQ(f, i)), where MinBQ(f, i) is the set minimum value of the interval i corresponding to feature f in the traffic before the attack.
3. The CDN controller (102) according to claim 2, characterized in that, The CDN controller (102) is also used to set MinBQ to the default minimum value.
4. The CDN controller (102) according to any one of the preceding claims, characterized in that, The CDN controller (102) is further configured to select rate limiters to be combined from a plurality of interval-specific rate limiters, wherein each rate limiter is associated with one or more intervals in a histogram of suitable features, and the controller is further configured to: The ADF is determined for the one or more package features. The rate limiter to be executed is selected as the rate limiter associated with the interval of the packet feature with the highest ADF.
5. The CDN controller (102) according to claim 4, characterized in that, The CDN controller (102) is also configured to determine, before selecting the rate limiter to be executed, that there are packet features where the ADF exceeds a threshold.
6. The CDN controller according to claim 5, characterized in that, The controller is also used to determine if the ADF exceeds a threshold using the Kolmogorov-Smirnov Test.
7. The CDN controller (102) according to claim 5 or 6, characterized in that, The CDN controller (102) is also configured to determine, before selecting the rate limiter to be executed, that there are no packet features with ADF exceeding a threshold, and in response, not select the rate limiter to be executed.
8. The CDN controller (102) according to claim 4, 5 or 6, characterized in that, The CDN controller (102) is also used to determine whether to select another rate limiter to be executed in the following manner: Determine the amount of traffic to be removed (RMV) (306), wherein the amount of traffic to be removed is determined to be the amount of traffic exceeding the attack threshold; The RMV (306) is determined to be greater than 0, and in response, another rate limiter is selected based on the ADF determined for the packet characteristics.
9. The CDN controller (102) according to any one of claims 4 to 8, characterized in that, The CDN controller (102) is also configured to: determine that the attack is still ongoing, and in response, receive additional second plurality of data packets; and determine a second attack histogram based on the additional second plurality of data packets and the ADF of the packet characteristics.
10. The CDN controller (102) according to claim 9, characterized in that, The CDN controller (102) is also used to determine that the attack is still ongoing at certain intervals.
11. The CDN controller (102) according to claim 10, characterized in that, The interval is 45 seconds, 60 seconds, 75 seconds, 90 seconds, 105 seconds, 120 seconds, 135 seconds, 150 seconds, 165 seconds, or 180 seconds, or any range in between.
12. The CDN controller (102) according to any one of claims 4 to 11, characterized in that, The CDN controller (102) is further configured to determine the RMV (306) as RMV = FF × SUM(AQ(f, i)), where FF is a feedback factor and is determined to be FF. j =1–RMV j–1 / RMV j–2 , FF0=FF1=1.
13. The CDN controller (102) according to any one of the preceding claims, characterized in that, The packet characteristics include the number of packets, the number of open connections, packet size, packet header size, payload size, protocol type, destination port, source port, fragment number, time to live (TTL), Transmission Control Protocol (TCP) flag, sequence counter, or Internet Protocol (IP) identifier.
14. A method for minimizing the impact of one or more rate limiters in a Content Distribution Network (CDN) controller (102), characterized in that, The method includes: Receive the first plurality of data packets (104A to 104N), wherein each data packet includes one or more packet features; A traffic histogram (108) is generated for the packet features based on the first plurality of data packets (104A to 104N), wherein the traffic histogram (108) of the packet features is based on matching multiple conditions with the packet features, each condition corresponding to an interval in the traffic histogram (108), and the traffic histogram (108) represents a benign traffic quota (BQ). An attack is confirmed to be in progress; Receive a second set of multiple data packets (106A to 106N). The effect of the rate limiter on packet characteristics is determined in the following ways: An attack histogram (110) is generated for the packet characteristics based on the second plurality of data packets, wherein the attack histogram (110) represents the attack traffic quota (AQ). The Attack Differentiating Factor (ADF) is determined for each interval in the attack histogram (110) according to the following formula: ADF(f, i)=AQ(f, i) / BQ(f, i), Where f represents the packet feature. i represents the range of values for the histogram. The ADF represents the effect of the rate limiter.
15. The method according to claim 14, characterized in that, The method is further configured to select rate limiters to be combined from a plurality of interval-specific rate limiters, wherein each rate limiter is associated with one or more intervals in a histogram of suitable features, and the method further comprises: The ADF is determined for the one or more package features; The rate limiter to be executed is selected as the rate limiter associated with the interval of the packet feature with the highest ADF.
16. A computer program product comprising program instructions, characterized in that, When executed by one or more processors in the CDN system, the program instructions are used to perform the method according to claim 14 or 15.
Citation Information
Patent Citations
Detection method and system for low-rate DDoS attack
CN113206859A
Method and system for detecting and mitigating https flood attacks
US20200412750A1