DDoS attack object identification method and device based on security agent, equipment
By using a security agent-based approach, large models and knowledge bases are employed to analyze attack information of sweeping DDoS attacks, accurately locate and isolate attack targets, and solve the problem of difficulty in identifying sweeping DDoS attack targets in existing technologies, thereby improving network security and business stability.
Patent Information
- Application Number
- CN202511430287.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-09-30
AI Technical Summary
Existing technologies are insufficient to effectively identify and isolate specific target business objects in a sweeping DDoS attack, resulting in a wide-ranging impact of network attacks and an inability to effectively protect non-target business objects.
By adopting a security intelligent agent-based approach, attack information of sweeping DDoS attacks is obtained, and analysis using large models and knowledge bases is used to identify the target business objects and implement corresponding isolation measures.
Quickly and accurately identify the targets of sweeping DDoS attacks, reduce the network impact on non-target business objects, improve network security and business stability, and enhance user experience.
Smart Images

Figure CN121333662B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to a method for identifying DDoS attack targets based on a security agent, a device for identifying DDoS attack targets based on a security agent, an electronic device, and a computer-readable storage medium. Background Technology
[0002] With the rapid development of information technology, the Internet has been deeply integrated into all aspects of social production and life. The widespread use of various network applications has greatly improved the efficiency of social production and life and expanded the boundaries of services.
[0003] However, with the rapid development of the internet, the threat of distributed denial-of-service (DDoS) attacks has become increasingly severe, posing a significant threat to the stable development of the internet. For example, the economic losses and damage to the reputation of products and services caused by DDoS attacks are increasingly becoming major problems that all industries must face.
[0004] For example, a typical form of current network attack is the segment-sweeping DDoS attack, which is characterized by launching a DDoS attack on all IP addresses within a contiguous Internet Protocol (IP) address segment. This type of attack is difficult to defend against and has a wide impact. Summary of the Invention
[0005] This summary section is provided to briefly introduce the concepts, which will be described in detail in the detailed description section below. This summary section is not intended to identify key or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0006] At least one embodiment of this disclosure provides a DDoS attack target identification method based on a security agent, comprising: in response to detecting a segment-scanning DDoS attack targeting a first IP address network segment, acquiring first attack information of the segment-scanning DDoS attack, wherein IP addresses in the first IP address network segment are assigned to at least two service objects, and the first attack information includes at least the first IP address network segment; and inputting the first attack information into a security agent to acquire the first service object targeted by the segment-scanning DDoS attack among the at least two service objects determined by the security agent, wherein the security agent acquires security risk association information related to the first IP address network segment based on the first attack information, and determines the first service object based on the security risk association information related to the first IP address network segment.
[0007] At least another embodiment of this disclosure provides a DDoS attack target identification device based on a security agent, comprising: an attack information acquisition module configured to acquire first attack information of a sweeping DDoS attack in response to detecting a sweeping DDoS attack targeting a first IP address network segment, wherein IP addresses in the first IP address network segment are assigned to at least two service objects, and the first attack information includes at least the first IP address network segment; and an object determination module configured to input the first attack information into the security agent, acquire the first service object targeted by the sweeping DDoS attack from among the at least two service objects determined by the security agent, wherein the security agent acquires security risk association information related to the first IP address network segment based on the first attack information, and determines the first service object based on the security risk association information related to the first IP address network segment.
[0008] At least one further embodiment of this disclosure provides an electronic device, including: a processing device; and a storage device including one or more computer program instructions; wherein the one or more computer program instructions are executed by the processing device to perform the DDoS attack target identification method based on a security intelligent agent provided in at least one embodiment of this disclosure.
[0009] At least one further embodiment of this disclosure provides a computer-readable storage medium that non-temporarily stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the DDoS attack target identification method based on a secure intelligent agent provided in at least one embodiment of this disclosure.
[0010] At least one further embodiment of this disclosure provides a computer program product, including a computer program / instruction that, when run on a computer, causes the computer to execute the DDoS attack target identification method based on a security intelligent agent provided in at least one embodiment of this disclosure. Attached Figure Description
[0011] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.
[0012] Figure 1 This illustration schematically depicts an application scenario of the DDoS attack target identification method and apparatus based on a security intelligent agent provided in at least one embodiment of this disclosure;
[0013] Figure 2 The schematic diagram illustrates a flowchart of a DDoS attack target identification method based on a security intelligent agent provided in at least one embodiment of the present disclosure;
[0014] Figure 3 This illustration schematically shows a principle diagram of determining the first business object targeted by a segment-based DDoS attack in at least one embodiment of the present disclosure;
[0015] Figure 4 This illustration schematically shows a principle diagram of determining the first business object targeted by a segment-based DDoS attack in at least another embodiment of this disclosure;
[0016] Figure 5 This illustration schematically shows a principle diagram of determining the first business object targeted by a segment-based DDoS attack in at least one embodiment of the present disclosure;
[0017] Figure 6 The schematic diagram illustrates the implementation principle of the DDoS attack target identification method based on security intelligent agents provided in at least one embodiment of the present disclosure;
[0018] Figure 7 This schematically illustrates a structural block diagram of a DDoS attack target identification device based on a security intelligent agent, according to at least one embodiment of the present disclosure; and
[0019] Figure 8 A schematic diagram of the structure of an electronic device suitable for implementing embodiments of the present disclosure is shown. Detailed Implementation
[0020] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0021] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.
[0022] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.
[0023] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0024] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0025] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0026] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition, use, storage or deletion of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0027] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, relevant users should be informed of the type, scope of use, and usage scenarios of the information involved in this disclosure through appropriate means in accordance with relevant laws and regulations, and authorization should be obtained from the relevant users. Among them, relevant users may include any type of rights holder, such as individuals, enterprises, and groups.
[0028] For example, in response to receiving an active request from a user, a prompt message is sent to the relevant user to clearly inform the user that the requested operation will require obtaining and using the user's information, thereby enabling the relevant user to choose whether to provide information to the software or hardware such as the electronic device, application, server, or storage medium that performs the operation of the technical solution disclosed herein based on the prompt message.
[0029] As an optional but non-restrictive implementation, in response to a user's active request, a prompt message can be sent to the user, such as a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide information to the electronic device.
[0030] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0031] With the rapid development of the internet, the types of attacks targeting the internet are increasing, and the threat to the internet is becoming more and more serious. Network security has become a major challenge threatening the stable development of the internet. Economic losses and damage to product and service reputation caused by cyberattacks are increasingly becoming problems that all industries must face. Segment scanning attacks are one of the typical forms of current cyberattacks. Their core characteristic is that attackers use technical tools to launch attacks on all IP addresses within a specific IP address segment, rather than targeting a single IP address. Taking a segment scanning DDoS attack as an example, attackers might control botnets distributed across the internet to launch a large number of malicious requests against a target server, causing the server to be unable to respond to normal business requests and resulting in a denial-of-service attack. Segment scanning DDoS attacks launch pulse attacks on multiple IP addresses in a short period of time. Although the attack traffic to each IP address is small, the total traffic is large, easily clogging public network lines. This places extremely high demands on the bandwidth capacity and detection timeliness of the defenders. Furthermore, large-scale, segment-based DDoS attacks can cause network congestion in the data center, and all users in the data center will face the risk of packet loss, increased latency, or even network outages. The failure radius is at least at the Availability Zone (AZ) level.
[0032] For example, in scenarios such as cloud services and Internet Data Centers (IDCs), IP addresses within a network segment are typically randomly assigned to different users. When a segment-sweeping DDoS attack occurs, all IP addresses within the segment are usually subjected to attacks of similar magnitude. This makes it difficult for cloud service providers and IDC providers to determine which of the all business objects associated with that IP address segment (e.g., all business objects assigned IP addresses within that segment) is the attacker's target. They are unable to protect the services of other business objects associated with the same network segment from the target by isolating the IP address assigned to the target, strengthening the protection of the IP address associated with the target, or even removing the target from the network. Instead, they can only passively defend.
[0033] To at least partially solve the aforementioned technical problems, at least one embodiment of this disclosure provides a DDoS attack target identification method based on a security agent, comprising: in response to detecting a segment-scanning DDoS attack targeting a first IP address network segment, obtaining first attack information of the segment-scanning DDoS attack, for example, IP addresses in the first IP address network segment are assigned to at least two service objects, and the first attack information includes at least the first IP address network segment; inputting the first attack information into a security agent, and obtaining the first service object targeted by the segment-scanning DDoS attack among the at least two service objects determined by the security agent.
[0034] Based on the DDoS attack target identification method based on security intelligent agents provided in at least one embodiment of the present disclosure, at least one embodiment of the present disclosure also provides a DDoS attack target identification device based on security intelligent agents, an electronic device, and a computer-readable storage medium.
[0035] The DDoS attack target identification method based on a security agent provided in at least one embodiment of this disclosure relies on the security agent's ability to quickly determine the business object targeted by the sweeping DDoS attack based on the attack information of the sweeping DDoS attack. This allows for effective protection of the business objects associated with the first IP address segment, excluding the business object targeted by the sweeping DDoS attack, from network attacks by isolating the business object from the IP address allocated to that business object, or by other measures. This improves network security, enhances the stability of other business objects' services, and improves user experience.
[0036] The embodiments and some examples of this disclosure will now be described in detail with reference to the accompanying drawings.
[0037] Figure 1 The illustration shows an application scenario of the DDoS attack target identification method and apparatus based on a security intelligent agent provided in at least one embodiment of the present disclosure.
[0038] like Figure 1 As shown, the application scenario 100 of this embodiment involves an attacker server 110, a target network segment 120, and an electronic device 130.
[0039] In at least one embodiment of this disclosure, the attacker server 110 may communicate with devices controlled by the attacked party, such as personal computers, servers, and Internet of Things devices (e.g., smart cameras, smart sockets), through a network. For example, the attacker may issue instructions to these controlled devices through the attacker server 110 to launch a segment-sweeping DDoS attack on the target network segment 120 using these controlled devices.
[0040] In at least one embodiment of this disclosure, the IP addresses included in the target network segment 120 may be assigned to at least two business objects. These at least two business objects may be one or at least two objects from different industries. They may include, for example, at least two electronic devices such as servers supporting the operation of online banking systems of financial institutions, transaction servers of e-commerce platforms, online game servers of game companies, or servers supporting the operation of any platform (e.g., content sharing platforms, short video platforms, etc.). For example, the format of the IP address range of the target network segment 120 may be XXX.XXX.XX / XX. The embodiments of this disclosure do not limit the specific values of the IP address range of the target network segment.
[0041] In at least one embodiment of this disclosure, a segment-scanning DDoS attack can target any one or a combination of at least two of the network layer, transport layer, and application layer in the Open Systems Interconnection Reference Model (OSI reference model). For example, it can primarily target the network layer and / or the transport layer. The embodiments of this disclosure do not limit this.
[0042] In at least one embodiment of this disclosure, the electronic device 130 may be, for example, a laptop computer, a desktop computer, or a server. The electronic device 130 may run a system capable of analyzing attack information and locating the business object targeted by the attack, such as an anti-attack system.
[0043] In at least one embodiment of this disclosure, an electronic device 130 may be equipped with a server, which may include a security agent for analyzing attack information and locating system calls targeting the business object being attacked. For example, the system capable of analyzing attack information and locating the business object being attacked, and the security agent, may be deployed on the same server or on different servers deployed within the electronic device 130; this disclosure does not limit the scope of the embodiments.
[0044] In at least one embodiment of this disclosure, the security agent is an agent based on a large model. For example, it can be an artificial intelligence system that integrates planning, memory, and tool recall capabilities on top of a large model, enabling it to autonomously think, decompose tasks, utilize external resources, and continuously optimize the execution process to complete complex tasks. The large model mentioned in this disclosure may include, for example, any one or a combination of at least two of the following: a large language model, a large visual model, a large audio model, and a multimodal large model.
[0045] In at least one embodiment of this disclosure, a large model refers to an artificial intelligence model based on a deep learning architecture, with an ultra-large-scale parameter scale and massive data training foundation, capable of capturing complex patterns and generalizing to multi-domain tasks. Its core feature is that through the exponential growth of the number of parameters (usually reaching billions to trillions) and learning from massive and diverse data, it breaks through the capability boundaries of traditional models and achieves the leap from "adapting to specific tasks" to "general task processing".
[0046] In at least one embodiment of this disclosure, an intelligent agent is a core concept in the field of artificial intelligence, referring to an entity capable of perceiving the environment, making autonomous decisions, and performing actions to achieve a specific goal; it can be software or hardware. Intelligent agents typically possess fundamental characteristics such as autonomy, responsiveness, initiative, sociality, and evolutionary capacity.
[0047] For example, the DDoS attack target identification method based on a security intelligent agent provided in at least one embodiment of this disclosure can be implemented in software, hardware, firmware, or any combination thereof.
[0048] For example, the DDoS attack target identification method based on a secure intelligent agent provided in at least one embodiment of this disclosure is applicable to an electronic device 130. The electronic device 130 can load and execute the DDoS attack target identification method based on a secure intelligent agent, and the embodiments of this disclosure do not limit this. For example, the electronic device 130 may include a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a neural network processing unit (NPU), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, storage units, etc. The electronic device 130 may also be equipped with an operating system, application programming interfaces (APIs) (e.g., OpenGL (Open Graphics Library), Metal, etc.), etc. The electronic device 130 implements the DDoS attack target identification method based on a secure intelligent agent provided in the embodiments of this disclosure by running code or instructions.
[0049] The following will combine Figures 2-6 The present disclosure provides a detailed description of at least one embodiment of a DDoS attack target identification method based on a security intelligent agent.
[0050] Figure 2 The illustration shows a flowchart of a DDoS attack target identification method based on a security intelligent agent provided in at least one embodiment of the present disclosure.
[0051] like Figure 2As shown, the DDoS attack target identification method 200 based on security intelligent agents in this embodiment may include steps S210 to S220.
[0052] Step S210: In response to detecting a segment-sweeping DDoS attack targeting the first IP address network segment, obtain the first attack information of the segment-sweeping DDoS attack.
[0053] Step S220: Input the first attack information into the security agent and obtain the first business object targeted by the sweeping DDoS attack from at least two business objects determined by the security agent.
[0054] In at least one embodiment of this disclosure, IP addresses in the first IP address segment can be assigned to at least two service objects, and each service object can be assigned one or more IP addresses. For example, the first IP address segment can be any IP address segment subject to a DDoS attack, and this disclosure does not limit this. For example, a service object can refer to a user, and the IP address assigned to the service object can be understood as an IP address assigned to the electronic device used by the user. Alternatively, a service object can refer to an electronic device (server), and a user can use one or more electronic devices.
[0055] In at least one embodiment of this disclosure, the first attack information of a segment-based DDoS attack may include, for example, at least a first IP address network segment. For example, the first attack information may also include at least one of the following: peak traffic for each IP address in the first IP address network segment, attack protocol, and attack start time information. For example, the IP address segment of the first IP address network segment can be obtained by analyzing firewall logs; the peak traffic for each IP address within the first IP address network segment can be obtained using IPS traffic monitoring tools; the attack protocol can be obtained by parsing the "protocol type" field of the attack event in the firewall's attack logs; or the attack logs can be sorted in ascending order by timestamp, and the earliest recorded time of the attack log can be used as the attack start time. It is understood that the above methods of obtaining the information in the first attack information are merely examples to facilitate understanding of this disclosure, and the embodiments of this disclosure do not limit this approach.
[0056] In at least one embodiment of this disclosure, a security agent can be invoked based on first attack information. The first business object targeted by the sweeping DDoS attack can be determined from at least two business objects based on information fed back by the security agent. For example, the first attack information can be input into the security agent, and information fed back by the security agent can be obtained, which characterizes the first business object targeted by the sweeping DDoS attack. For example, after inputting the first attack information into the security agent, the security agent can first determine a prompt word to be input into the large model that forms the basis of the security agent, based on the first attack information and a prompt word template. Then, the prompt word is input into the large model to obtain information generated by the large model. For example, the security agent can analyze the information generated by the large model to determine the first business object targeted by the sweeping DDoS attack from at least two business objects, and use the identification information of the first business object as feedback information.
[0057] In at least one embodiment of this disclosure, the security agent may, for example, invoke a knowledge base based on the Model Context Protocol (MCP). For instance, the knowledge base stores documents detailing the specific implementation principles of determining the target business object of a sweeping DDoS attack based on attack information. The security agent may retrieve this document by invoking the knowledge base and input it along with prompts into the large model, enabling the large model to determine the first business object targeted by the sweeping DDoS attack based on the principles described in the document. For example, the Model Context Protocol is an open standard protocol used to unify the communication methods between the large model and external data sources and tools.
[0058] In at least one embodiment of this disclosure, the prompt word template can be, for example, the template shown below. The first IP address network segment in the first attack information can be substituted into the prompt word template to obtain the prompt word for the input large model (the following XX or similar expressions are used as general substitutes):
[0059] Please strictly adhere to the "Segment-Based DDoS Attack Target Identification Method.docx" and use 'XXXX network segment' as the reference.
[0060] Taking a sweeping DDoS attack as a scenario, the complete solution involves data analysis and target inference.
[0061] process:
[0062] Data Acquisition: Lists the specific content of contextual data, including information on the current sweeping DDoS attack.
[0063] It must include key data about business objects in the document (such as 90 attacks against the transport layer (L4), etc.).
[0064] 15 attacks on the Domain Name System (DNS).
[0065] Data analysis: Calculate the correlation between each business object and a sweeping DDoS attack;
[0066] Target inference: Based on the correlation between each business object and a segment-based DDoS attack, determine the segment-based attack.
[0067] DDoS attacks target specific business entities;
[0068] Requirements: All content must originate from the document, without adding any information outside the document, and without using vague expressions.
[0069] (e.g., “a certain data” needs to be replaced with the specific value in the document).
[0070] It is understood that the above prompt word template is only an example to facilitate understanding of this disclosure, and the embodiments of this disclosure are not limited thereto.
[0071] In at least one embodiment of this disclosure, the security agent may, for example, obtain the correspondence between each IP address in the first IP address segment and at least two business objects by calling a knowledge base or other data interface. This correspondence may indicate which IP addresses in the first IP address segment are assigned to which business object. The security agent may provide this correspondence and prompt words to a large model, enabling the large model to determine the first business object targeted by a segment-based DDoS attack based on the input information.
[0072] The DDoS attack target identification method based on a security agent provided in at least one embodiment of this disclosure relies on the security agent's ability to quickly locate the business object targeted by a segment-based DDoS attack. By isolating the business object targeted by the segment-based DDoS attack from its assigned IP address or other measures, the business of other business objects in the business objects associated with the first IP address network segment, excluding the first business object, can be effectively protected from network attacks. This is beneficial for improving network security and the business stability of other business objects, and for improving user experience.
[0073] The DDoS attack target identification method based on security intelligent agents provided in at least one embodiment of this disclosure has a wider range of applicable scenarios and higher efficiency in identifying attack targets compared to the technical solution of using a binary search method to determine the attack target of a segment-sweeping DDoS attack. For example, the implementation principle of the technical solution of using a binary search method to determine the attack target of a segment-sweeping DDoS attack is as follows: the service objects associated with a network segment are divided into two groups, the IP addresses allocated to each group of service objects are migrated to a new network segment, and the IP addresses allocated to different groups of service objects are migrated to two different new network segments. Then, it is observed which new network segment is attacked, and the service objects associated with the attacked new network segment are divided into two groups again. Based on a similar principle, the IP addresses allocated to the two groups of service objects obtained after this re-division are migrated to two different new network segments, and it is continued to observe which of the two new network segments is attacked until the attack target is located. The binary search method used to identify the target of a segment-based DDoS attack is only applicable to platforms that use domain names for access, such as Content Delivery Networks (CDNs). This allows for the migration of IP addresses to new network segments by modifying the service domain names. Furthermore, this binary search method requires multiple attacks to pinpoint the target, significantly disrupting the normal operation of at least some other services within the network segment besides the attacked service, thus failing to effectively guarantee network security.
[0074] The DDoS attack target identification method based on security intelligent agents provided in at least one embodiment of this disclosure, compared with the technical solution of using static rules to filter the attack targets of sweeping DDoS attacks, can locate the attack targets of sweeping DDoS attacks when the attack traffic of sweeping DDoS attacks is evenly distributed among all IP addresses in a first IP address network segment. For example, the static rules used in the technical solution of using static rules to filter the attack targets of sweeping DDoS attacks may include rules such as "the business object whose attack traffic of the assigned IP address accounts for a proportion exceeding a threshold of all attack traffic is the attack business object", etc., and the embodiments of this disclosure do not limit this.
[0075] Figure 3 The illustration shows a schematic diagram of the principle of determining the first business object targeted by a segmented DDoS attack in at least one embodiment of the present disclosure.
[0076] In at least one embodiment of this disclosure, such as Figure 3As shown, an exemplary implementation of the aforementioned step S220 can be as follows: inputting the first attack information 310 into the security agent 320 to obtain the inference information 330 generated by the security agent 320. Based on this inference information 330, the first business object targeted by the sweeping DDoS attack among at least two business objects can be determined.
[0077] In at least one embodiment of this disclosure, such as Figure 3 As shown, the reasoning information 330 may include a reasoning result 331 and a reasoning basis 332. For example, the reasoning result 331 represents the first business object targeted by the sweeping DDoS attack, and the reasoning basis 332 represents an explanatory description of the first business object being the target of the sweeping DDoS attack.
[0078] In at least one embodiment of this disclosure, the prompt word in the "target inference" part of the aforementioned prompt word template may also be: based on the correlation between each business object and the sweeping DDoS attack, determine the business object targeted by the sweeping DDoS attack and explain the reasons, so that the information generated by the large model includes the reasoning result and the reasoning basis.
[0079] At least one embodiment of this disclosure obtains reasoning information, including reasoning results and reasoning basis, output by a security intelligent agent. This information can be displayed to network security operations personnel, facilitating their assessment of the reliability and rationality of the reasoning results. Based on the assessment results, the personnel can then implement measures such as isolating the first business object from its assigned IP address. This effectively avoids situations where inaccurate reasoning results prevent accurate location of the target of a sweeping DDoS attack, thus hindering effective protection against such attacks.
[0080] Figure 4 The illustration shows a schematic diagram of the principle for determining the first business object targeted by a segmented DDoS attack in at least another embodiment of the present disclosure.
[0081] In at least one embodiment of this disclosure, when determining the first business target of a segment-based DDoS attack, the security agent can first obtain security risk association information related to the first IP address network segment based on the first attack information. Then, the security agent determines the business target of the segment-based DDoS attack based on this security risk association information, thereby improving the accuracy and reasonableness of the determined business target. For example, security operations personnel can pre-set the information included in the security risk association information based on experience.
[0082] In at least one embodiment of this disclosure, such as Figure 4As shown, after providing the first attack information 401 to the security agent 410, the security agent 410 can, for example, use at least a portion of the information in the first attack information 401 as query conditions to query the knowledge base 420 through the model context protocol to obtain security risk association information 402 related to the first IP address network segment. For example, the knowledge base 420 may store a large amount of information related to network attacks, such as attack logs, IP address information allocated to each business object, the business operated by each business object, the mapping relationship between the business and the industry, and industry dynamic information of various industries, or a combination of at least two of these types of information. It is understood that the above method of obtaining security risk association information 402 is only an example to facilitate understanding of this disclosure, and the embodiments of this disclosure are not limited thereto.
[0083] In at least one embodiment of this disclosure, the first attack information 401 includes an attack start time. When acquiring security risk association information, the security agent 410 may, for example, first determine the time range for the security risk association information based on the first attack information 401. The security agent 410 then acquires security risk association information related to the first IP address network segment based on this time range. By determining the time range based on the first attack information, the collection time of the acquired security risk association information can be constrained. For example, only security risk association information collected within the most recent predetermined time period can be acquired, thereby improving the effectiveness of the acquired security risk association information and the accuracy of identifying the business targets of the segment-scanning DDoS attack. This is because network attacks are highly time-sensitive, and analyzing only the security risk association information collected within the most recent predetermined time period is more meaningful.
[0084] In at least one embodiment of this disclosure, the time range can be used as a constraint on the collection time of the acquired security risk association information. For example, the time range can end at the attack start time and begin at a time interval predetermined from the end time interval. The acquired security risk association information is information whose collection time falls within this time range.
[0085] In at least one embodiment of this disclosure, after obtaining security risk association information, the security agent can, for example, input the security risk association information and the prompt words determined using the aforementioned at least one embodiment into a large model, and the large model outputs inference information 403. Based on the inference information 403, the first business object targeted by the sweeping DDoS attack among at least two business objects can be determined.
[0086] In at least one embodiment of this disclosure, the acquired security risk association information may include, for example, security risk association information corresponding to each of the at least two business objects, i.e., the security risk association information may be acquired on a per-business-object basis. For example, when a security agent determines the first business object targeted by a sweeping DDoS attack, it may first determine the degree of association between each business object and the sweeping DDoS attack based on the security risk association information corresponding to each of the at least two business objects, thus obtaining at least two degrees of association. Subsequently, the security agent may determine the first business object targeted by the sweeping attack among the at least two business objects based on the at least two degrees of association between the at least two business objects and the sweeping DDoS attack. By acquiring the security risk association information corresponding to each business object, the association between each business object and the sweeping DDoS attack can be analyzed separately, which is beneficial for accurately identifying the attacking business object of the sweeping DDoS attack.
[0087] In at least one embodiment of this disclosure, the security risk association information corresponding to each business object may include, for example, the number of times the IP address assigned to each business object has been attacked. The more times it has been attacked, the higher the probability that each business object is a target of a sweeping DDoS attack, and the higher the correlation between each business object and the sweeping DDoS attack.
[0088] In at least one embodiment of this disclosure, the security agent can first determine the security risk level of each business object based on security risk association information, and then determine the correlation between each business object and a sweeping DDoS attack based on the security risk level. For example, the security risk level of each business object is positively correlated with the correlation between each business object and a sweeping DDoS attack. For example, the security risk association information corresponding to each business object may include the security risk level of each business object. Alternatively, the security risk association information corresponding to each business object may include information characterizing the factors that determine the security risk level, such as the number of times the IP address allocated to each business object has been attacked, the allocation duration of the IP address allocated to each business object in the first IP address network segment, the number of IP addresses, and network security dynamic information of the industry to which the business operated by each business object belongs.
[0089] In at least one embodiment of this disclosure, the security agent may, for example, use the business object corresponding to the highest correlation among at least two correlation degrees as the first business object targeted by a sweeping DDoS attack, or it may use the business object corresponding to a correlation degree exceeding a correlation degree threshold among at least two correlation degrees as the first business object targeted by a sweeping DDoS attack. For example, depending on actual needs, the first business object may be one business object or two or more business objects, and the embodiments of this disclosure do not limit this.
[0090] In at least one embodiment of this disclosure, the acquired security risk association information may include attack information on historical attacks against each business object. Given a defined time range, the security agent may, for example, acquire second attack information on historical attacks against each of at least two business objects, based on the time range. For instance, the information dimension of the acquired security risk association information may include the dimension of historical attacks against each business object; the security risk association information under this dimension is the attack information on historical attacks against each business object.
[0091] In at least one embodiment of this disclosure, the second attack information for historical attacks against each business object may include, for example, one or a combination of at least two of the following: the time of occurrence of the historical attack, the IP address assigned to the business object targeted by the historical attack, and the traffic volume of the historical attack.
[0092] In at least one embodiment of this disclosure, historical attacks against each service object may include, for example, transport layer attacks (also known as L4 attacks) launched against each service object. For instance, the occurrence times of the acquired L4 attacks fall within a defined time range. Since attackers, in order to disrupt the availability of the services of the attacked service object, often launch single-IP attacks against all service IP modules of the service object's services, in addition to launching sweeping DDoS attacks, the attack information on historical transport layer attacks acquired in at least one embodiment of this disclosure helps to determine the target of sweeping DDoS attacks. For example, for at least two service objects, the number of L4 attacks launched against each service object within a defined time range (e.g., the past 7 days) can be obtained, resulting in at least two attack counts corresponding to each of the at least two service objects.
[0093] In at least one embodiment of this disclosure, historical attacks against each business object may include, for example, application-layer attacks (also known as L7 attacks) launched against each business object. For instance, the occurrence times of the acquired L7 attacks fall within a defined timeframe. Since attackers frequently launch L7 attacks to target the services of business objects, the characteristics of L7 attacks dictate that attackers are highly likely to carry service domain names. However, requests carrying service domain names are usually directly intercepted by the service provider, failing to achieve a significant attack effect. Therefore, attackers typically launch other types of attacks (e.g., sweeping DDoS attacks) after launching an L7 attack. Thus, the attack information on historical application-layer attacks acquired in at least one embodiment of this disclosure helps in identifying the targets of sweeping DDoS attacks. For example, for at least two business objects, the number of L7 attacks launched against each business object within a defined timeframe (e.g., the last 7 days) can be obtained, yielding at least two attack counts corresponding to each of the at least two business objects.
[0094] In at least one embodiment of this disclosure, historical attacks against each business object may include, for example, query flood attacks launched against the domain name resolution system used by each business object. For instance, the occurrence time of the obtained query flood attacks falls within a defined time range. To disrupt the availability of the target business of a business object, attackers, in addition to directly attacking the business object (e.g., a server), often launch query flood attacks against the domain name resolution system server (also known as a DNS server) that provides resolution services for the business, forcing the DNS server provider to block the domain name allocated to the business object, ultimately affecting access to the domain name allocated to the business object. Therefore, the attack information on query flood attacks launched against the domain name resolution system used by each business object obtained in at least one embodiment of this disclosure helps in identifying the target of a sweeping DDoS attack. For example, for at least two business objects, query flooding attacks occurring within a defined time frame (e.g., within the last 7 days) can be extracted from historical query flooding attacks suffered by the local DNS server and authoritative DNS server. The domain names targeted by these query flooding attacks can be extracted from the attack information of these extracted attacks. These extracted domain names are then compared with the domain names assigned to each business object to determine the number of times the domain names assigned to each business object appear in the extracted domain names. This yields second attack information regarding historical attacks against each business object. For instance, in this embodiment, the historical attacks against each business object include a first query flooding attack launched against the domain name resolution system, where the attacking domain names include those associated with each business object.
[0095] In at least one embodiment of this disclosure, the dimensions of historical attacks against each business object may include, for example, at least two dimensions corresponding to at least two attack types. These at least two attack types may include at least two of the aforementioned attacks targeting the transport layer, attacks targeting the application layer, and first query flooding attacks launched against the domain name resolution system. The attack domain name in the first query flooding attack includes a domain name associated with each business object (which can also be understood as a domain name assigned to each business object). For example, each of the aforementioned historical attacks corresponds to one attack type. For example, an example of obtaining second attack information on historical attacks against each business object based on a time range can be achieved by obtaining the number of historical attacks of the attack type corresponding to each of the at least two dimensions based on the time range, thus obtaining at least two attack counts corresponding to each of the at least two dimensions, i.e., obtaining at least two attack counts for each business object. By obtaining attack information on historical attacks in at least two dimensions as security risk association information for each business object, it is convenient to perform multi-dimensional data association analysis for each business object, which helps improve the accuracy of the business objects targeted by the sweeping DDoS attack determined based on the security risk association information.
[0096] In at least one embodiment of this disclosure, the acquired security risk association information may include address information of IP addresses located in a first IP address network segment allocated to each business object within a defined time range. Given a defined time range, the security agent may, for example, acquire the address information of the IP addresses allocated to each of at least two business objects within the first IP address network segment based on the time range. For instance, the information dimension of the acquired security risk association information may include the address information dimension, where the security risk association information under this address information dimension is the address information of the IP addresses allocated to each business object within the first IP address network segment.
[0097] In at least one embodiment of this disclosure, the address information may include, for example, the number of IP addresses and the allocation time of the IP addresses. For instance, it is common for a business entity to migrate its operations to a new network segment because its business relies on servers in a particular data center and is frequently attacked. This migration may introduce a sweeping DDoS attack to the new network segment. Therefore, the address information can be obtained, for example, by acquiring the number of IP addresses within the first IP address network segment allocated to each electronic device used by the business entity within a given timeframe (e.g., the last 7 days), or by acquiring the allocation time of the IP addresses within the first IP address network segment allocated to each business entity within the given timeframe. For example, the more IP addresses within the first IP address network segment allocated to a business entity and / or the closer the allocation time of the allocated IP addresses is to the time of a sweeping DDoS attack, the greater the likelihood that the business entity is targeted by a sweeping DDoS attack. Therefore, the address information obtained in at least one embodiment of this disclosure, under the dimension of address information, helps to determine the attack target of a sweeping DDoS attack and improves the accuracy of identifying the business object targeted by the sweeping DDoS attack.
[0098] In at least one embodiment of this disclosure, the information dimension of the acquired security risk association information may include the dimension of business attribute attacks corresponding to each business object, and the acquired security risk association information may include historical attack information of business attribute attacks corresponding to each business object within a defined time range. When the time range is determined, the security agent may, for example, acquire historical attack information of business attribute attacks corresponding to each of at least two business objects based on the time range. For example, business attribute attacks corresponding to each business object may include at least one of the following: attacks targeting the industry to which the business operated by each business object belongs, and attacks targeting the business form to which the business operated by each business object belongs. For example, attacks on the industry and business form to which the business operated by the business object belong are essentially attacks on the "business foundation" of the business object, which are typically referred to as "business attribute attacks" or "business form foundation attacks" in risk analysis and other scenarios. Both of these expressions accurately cover the two dimensions of "industry" and "business form," and clearly point to the impact on the core business logic of the business object.
[0099] In at least one embodiment of this disclosure, the historical attack information of business attribute attacks may include, for example, attack information of business attribute attacks that occurred within a defined time range (e.g., the last 7 days), and may include at least one of the following: attack time, attack scale, industry of the attack, and business form of the attack. For example, large-scale mutual attacks often occur due to malicious competition, industry changes, etc. If a large-scale attack occurs in the industry or business form to which a certain business entity operates, and / or the time of the large-scale attack in the industry or business form to which a certain business entity operates is close to the time of a sweeping DDoS attack, then the certain business entity is more likely to be the target of the sweeping DDoS attack. Therefore, the historical attack information of business attribute attacks corresponding to each business entity obtained in at least one embodiment of this disclosure helps to determine the target of a sweeping DDoS attack, and improves the accuracy of determining the business entity targeted by the sweeping DDoS attack.
[0100] In at least one embodiment of this disclosure, the information dimensions of the security risk association information obtained corresponding to each business object may include one or at least two information dimensions mentioned in the above embodiments. It is understood that the number and type of information dimensions of the security risk association information can be set according to actual needs, and the embodiments of this disclosure do not limit this.
[0101] Figure 5 The illustration shows a schematic diagram of the principle for determining the first business object targeted by a segmented DDoS attack in at least another embodiment of the present disclosure.
[0102] In at least one embodiment of this disclosure, a knowledge graph can be constructed based on historical attacks to establish associations between historical attacks and various types of entities (e.g., industries, business models, business objects, IP addresses, etc.). For example, the entities represented by nodes in the knowledge graph may include a certain type or instance of attack, malicious competition / changes in an industry, IP addresses, business objects, attack time information, etc. An edge between two nodes represents the association between the two entities represented by those two nodes. When the security agent obtains security risk association information, it can first query the knowledge graph based on historical attacks (i.e., the knowledge graph constructed based on historical attacks) based on the first attack information to determine the information dimensions of the security risk association information. Then, based on the information dimensions and the first attack information, it obtains security risk association information related to the first IP address network segment. In this way, the information dimensions of security risk association information related to the sweeping DDoS attack can be determined based on the knowledge graph, which helps to improve the accuracy and effectiveness of the obtained security risk association information and improve the accuracy and efficiency of determining the business objects targeted by the sweeping DDoS attack.
[0103] In at least one embodiment of this disclosure, such as Figure 5 As shown, after providing the first attack information 501 to the security agent 510, the security agent 510 can, for example, first query the knowledge graph 530 based on the first attack information 501 to determine the information dimension 503. The security agent then retrieves security risk association information 502 related to the first IP address network segment from the knowledge base 520 based on the information dimension 503 and the first attack information 501. The security agent 510 then determines the first business object targeted by the segment-scanning DDoS attack based on the security risk association information 502. For example, the security agent 510 can input the retrieved security risk association information 502 and the prompt words determined using at least one of the aforementioned embodiments into a large model, which outputs inference information 504. Based on this inference information 504, the first business object targeted by the segment-scanning DDoS attack among at least two business objects can be determined.
[0104] In at least one embodiment of this disclosure, a triple constituting a knowledge graph can be represented, for example, as [sweeping DDoS attack, often accompanied by L4 attack targeting a single IP address]. This triple can be based on the knowledge that "in order to disrupt the availability of a target service, attackers will not only use sweeping DDoS attacks, but also launch attacks on a single IP address among all IP addresses involved in the target service. The associated historical L4 attack records can help determine the target." By querying this triple in the knowledge graph, it can be determined that the historical L4 attack data can be used as a basis for determining the business object targeted by the sweeping DDoS attack, so as to help the security agent associate the frequency of L4 attacks recently suffered by the business object with the current sweeping DDoS attack. Thus, it can be determined that the dimensions of the obtained security risk association information include the L4 attack dimension, and the obtained security risk association information includes the number of attacks that occurred within a certain time range in the L4 attacks launched against each business object.
[0105] In at least one embodiment of this disclosure, the knowledge graph 530 can be queried using the attack type of a sweeping DDoS attack included in a single attack information as a query condition. For example, a node representing the attack type of the sweeping DDoS attack in the knowledge graph can be used as the starting node, and nodes of a predetermined number of layers can be diffused outwards. The information dimension of the security risk association information can be determined based on the entities represented by the diffused nodes. For example, if the entities represented by the diffused nodes include L7 attacks, then the determined information dimension includes the dimension corresponding to the L7 attack type. It is understood that the specific implementation method of querying the knowledge graph to determine the information dimension described above is only an example to facilitate understanding of this disclosure, and the embodiments of this disclosure are not limited thereto.
[0106] For example, in at least one embodiment of this disclosure, the security agent can determine the time range for security risk association information based on the first attack information, and then use the time range and the determined information dimension 503 as query conditions to query the knowledge base 520, thereby obtaining security risk association information 502 under the information dimension 503 within the time range. By comprehensively considering the time range and information dimension, the accuracy and effectiveness of the obtained security risk association information can be further improved, which is conducive to further improving the accuracy and efficiency of identifying attack targets.
[0107] In at least one embodiment of this disclosure, the determined information dimension 503 may include, for example, one dimension or a combination of at least two of the following: a dimension of historical attacks against each business object, a dimension of address information, and a dimension of business attribute attacks corresponding to each business object. The dimension of historical attacks against each business object may include, for example, one dimension or a combination of at least two of the following: an L4 attack dimension, an L7 attack dimension, and a dimension of DNS query flooding attacks.
[0108] In at least one embodiment of this disclosure, when information dimension 503 includes at least two information dimensions, the security agent can, for each business object, retrieve information from the knowledge base within each of the at least two information dimensions based on a defined time range, as associated sub-information for each information dimension. This results in the acquisition of associated sub-information for at least two information dimensions for each business object, which constitutes security risk association information corresponding to each business object. For example, for the dimension of historical attacks against each business object, the acquired associated sub-information includes second attack information related to historical attacks against that business object. For the dimension of address information, the acquired associated sub-information includes address information of the IP address allocated to each business object within the first IP address network segment. For the dimension of business attribute attacks corresponding to each business object, the acquired associated sub-information includes historical attack information related to business attribute attacks corresponding to that business object. In at least one embodiment of this disclosure, when the dimensions of historical attacks against each business object include at least two dimensions corresponding to at least two attack types, the associated sub-information corresponding to each business object can be obtained on a unit of each of the at least two dimensions. In this way, at least two associated sub-information corresponding to at least two dimensions are obtained (for example, an information group composed of multiple pieces of information).
[0109] In at least one embodiment of this disclosure, when the information dimension includes at least two dimensions, the security risk association information corresponding to each business object includes association sub-information of at least two dimensions. When determining the association degree between each business object and a sweeping DDoS attack, the security agent can, for example, determine a association degree between each business object and the sweeping DDoS attack based on the association sub-information of each dimension corresponding to each business object, as a sub-association degree, thereby obtaining at least two association degrees between each business object and the sweeping DDoS attack based on at least two dimensions. Subsequently, the security agent can, for example, determine the weighted sum of the at least two sub-associations based on a first weighting reorganization, thereby obtaining the association degree between each business object and the sweeping DDoS attack. Through the association degree technical solution of at least one embodiment of this disclosure, the association degree between a business object and a sweeping DDoS attack can be evaluated from multiple dimensions, and different weights can be set for different dimensions through the first weighting reorganization, so that the determined association degree can better reflect the association relationship between the business object and the sweeping DDoS attack, which is beneficial to improving the accuracy of the identified attack business object.
[0110] In at least one embodiment of this disclosure, at least two dimensions may include, for example, dimensions corresponding to L4 attacks, dimensions corresponding to L7 attacks, dimensions corresponding to query flooding attacks launched against the domain name resolution system, address information dimensions, and business attribute attack dimensions corresponding to each business object. The security risk association information obtained for each business object may include, for example, the following association sub-information: the number of times each business object has been subjected to L4 attacks in the past 7 days; the number of times each business object has been subjected to L7 attacks in the past 7 days; the number of domain names associated with each business object among the attack domain names involved in historical query flooding attacks suffered by the local DNS server and authoritative DNS server in the past 7 days; the number of IP addresses in the first IP address network segment allocated to each business object in the past 7 days; and whether there is malicious competition or changes in the industry or business form to which the business operated by each business object belongs in the past 7 days.
[0111] For example, in at least one embodiment of this disclosure, a mapping relationship between the associated sub-information and the sub-association degree can be established for each dimension's associated sub-information. After obtaining each associated sub-information, this embodiment can determine the sub-association degree between the business object and the sweeping DDoS attack for each dimension based on the mapping relationship. For example, when the associated sub-information is the number of attacks, the number of IP addresses, and the number of domain names, the sub-association degree can be positively correlated with the value of the associated sub-information. For example, when the associated sub-information indicates malicious competition or changes, the sub-association degree between the business object and the sweeping DDoS attack can be determined to be 1 for the dimension of business attribute attack corresponding to each business object. For example, the value range of each sub-association degree can be [0, 1].
[0112] In at least one embodiment of this disclosure, when the obtained security risk association information consists of quantified data such as the number of attacks, the number of IP addresses, and the number of domain names, the security agent can, for example, determine the correlation between each business object and the sweeping DDoS attack based on security risk association information related to the first IP address network segment and security risk association information corresponding to each business object. This allows the final determined correlation to reflect the differences in the correlation between different business objects and the sweeping DDoS attack, improving the comparability of the determined correlations between at least two business objects and the at least two business objects, and thus improving the accuracy of the final identified attack business objects.
[0113] In at least one embodiment of this disclosure, for each business object, the sub-association degree W1 determined in the dimension corresponding to the L4 attack can be, for example, the ratio between the number of times each business object has been subjected to an L4 attack in the past 7 days and the sum of the number of times all business objects in at least two business objects have been subjected to an L4 attack in the past 7 days. This sub-association degree can, for example, represent the severity of the L4 attack on each business object relative to all business objects.
[0114] In at least one embodiment of this disclosure, for each business object, the sub-association degree W2 determined in the dimension corresponding to the L7 attack can be, for example, the ratio between the number of times each business object has been subjected to an L7 attack in the past 7 days and the sum of the number of times all business objects in at least two business objects have been subjected to an L7 attack in the past 7 days. This sub-association degree can, for example, represent the severity of the L7 attack on each business object relative to all business objects.
[0115] In at least one embodiment of this disclosure, for each business object, the sub-association degree W3 determined under the dimension corresponding to the query flooding attack launched against the domain name resolution system can, for example, be the ratio of the number of domain names associated with each business object among the attack domain names involved in historical query flooding attacks suffered by the local DNS server and the authoritative DNS server in the past 7 days, to the total number of domain names associated with all business objects in at least two business objects. This sub-association degree can, for example, represent the severity of the query flooding attack on each business object relative to all business objects.
[0116] In at least one embodiment of this disclosure, for each business object, the sub-association degree W4 determined under the address information dimension can be, for example, the ratio between the number of IP addresses in the first IP address network segment allocated to each business object in the past 7 days and the total number of IP addresses in the first IP address network segment allocated to all business objects in at least two business objects in the past 7 days. This sub-association degree can, for example, represent the time coincidence between the time when each business object newly purchases an IP address and the time when a sweeping DDoS attack targeting the first IP address network segment occurs.
[0117] In at least one embodiment of this disclosure, for each business object, the sub-association degree W5 under the dimension of business attribute attack corresponding to each business object can, for example, represent whether the industry or business form to which the business operated by each business object belongs has been attacked in threat intelligence.
[0118] In at least one embodiment of this disclosure, the first weight reassembly includes weights D1 to D5, each corresponding one-to-one with the aforementioned sub-associations W1 to W5. The correlation score between each service object and a segment-scanning DDoS attack targeting the first IP address network segment can be calculated, for example, using the following formula: Score = D1*W1 + D2*W2 + D3*W3 + D4*W4 + D5*W5. For example, the values of D1 to D5 can be set according to actual needs, and the embodiments of this disclosure do not limit this.
[0119] In at least one embodiment of this disclosure, after obtaining the first service object targeted by the sweeping DDoS attack as determined by the security agent, information that can characterize the first service object as an attacking service object of the sweeping DDoS attack, such as the identification information of the first service object, can be pushed to security operations personnel. This allows security operations personnel to use various protection measures to ensure that the services of other service objects associated with the first IP address network segment, excluding the first service object, are not affected. For example, security operations personnel can migrate the IP address assigned to the first service object to a new network segment.
[0120] In at least one embodiment of this disclosure, in response to obtaining correction information obtained from correcting the first service object targeted by a segment-scanning DDoS attack, the correction information can be fed back to the security agent, so that the security agent can adjust the first weight reassembly based on the correction information. For example, after implementing various protection measures, security operators can determine whether the first service object is the actual attacking service object of a segment-scanning DDoS attack targeting the first IP address network segment based on the protection results. If not, the actual attacking service object of the segment-scanning DDoS attack targeting the first IP address network segment can be manually determined, and the first service object can be corrected based on the actual attacking service object.
[0121] In at least one embodiment of this disclosure, after feeding back the correction information to the security agent, the security agent can, for example, optimize itself based on the correction information. For instance, this embodiment can use the first attack information of a segment-scanning DDoS attack targeting a first IP address network segment as training data, and feed back the correction information as a label to the training data to the security agent, enabling the security agent to autonomously optimize itself based on the training data and the label. During this autonomous optimization process, the first weight group and each network parameter in the large model can be used as parameters to be adjusted, thereby adjusting the first weight group and continuously improving the accuracy of the security agent in identifying attack targets, thus improving the precision of the security agent.
[0122] In at least one embodiment of this disclosure, after implementing various protective measures, security operators can determine the feedback information obtained from attack protection based on the protection results, using the first business object as the basis. This feedback information is then provided to a system capable of analyzing attack information and locating the business object targeted by the attack. This system then feeds the feedback information back to the security agent, enabling the security agent to optimize itself and the first weighted reorganization based on this feedback. Through this embodiment, the security agent can optimize itself based on the principles of reinforcement learning. In at least one embodiment of this disclosure, the feedback information can be, for example, a reward value used to evaluate the accuracy of the security agent in locating the attack target. The principle for determining this feedback information can be set according to actual needs, and can be based on a value function-based strategy evaluation, etc. This disclosure does not limit this approach.
[0123] In at least one embodiment of this disclosure, the security agent may, for example, continuously update the knowledge graph based on feedback information, so that the information represented by the knowledge graph is richer and can represent updated information, thereby improving the accuracy of the determined information dimensions, and thus improving the effectiveness of the security risk association information obtained and improving the accuracy of the determined attack targets.
[0124] Figure 6 The schematic diagram illustrates the implementation principle of the DDoS attack target identification method based on a security intelligent agent provided in at least one embodiment of the present disclosure.
[0125] In at least one embodiment of this disclosure, such as Figure 6 As shown, when a sweeping DDoS attack is detected using techniques for detecting sweeping DDoS attacks, attack information can be obtained and fed back to the security agent. This attack information can characterize the IP address network segment affected by the sweeping DDoS attack and the attack time. After receiving the attack information, the security agent can initiate the attack target analysis process. For example, the security agent can first query related information based on the attacked IP address network segment, specifically querying historical L4 attack events, historical L7 attack events, historical DNS attack events (i.e., query flooding attacks launched against DNS), address information of IP addresses purchased by various business objects associated with the IP address network segment, and threat intelligence information of the industries or business models associated with the various business objects associated with the IP address network segment. This queried information, along with the attack information, is used as the "context data" for the detected sweeping DDoS attack. Subsequently, the security agent can obtain security risk association information corresponding to each business object associated with the IP address network segment from the context data. For example, a security agent can read related information and obtain security risk related information based on injected knowledge and attack information. The injected knowledge can be knowledge obtained by querying a knowledge graph, and in some embodiments, it can be information dimensions. After obtaining the related information, the security agent can combine the security risk related information to determine the attack target and details of the detected sweeping DDoS attack (also known as the reasoning basis), and output information representing the attack target and the details of the determination.
[0126] In at least one embodiment of this disclosure, security operators can isolate attack targets from the attacked IP address network segment based on the attack targets represented by the information output by the security agent, and migrate them to a high-defense data center with stronger protection capabilities. The accuracy of the attack target assessment by the security agent can then be determined by whether the attack also migrates to the high-defense data center. If inaccurate assessment is confirmed, the security agent can, for example, provide feedback on the protection effect based on the attack target, allowing for autonomous optimization. For instance, security operators can also dynamically optimize the knowledge based on the actual protection effect.
[0127] In at least one embodiment of this disclosure, the prompt word template may be, for example, the template shown below:
[0128] Please strictly adhere to the "Segment-Based DDoS Attack Target Identification Method.docx" and use the 'XXXX address'.
[0129] Taking a network segment suffering a segment-sweeping DDoS attack as a scenario, the complete reproduction solution includes: Context data collection → Data...
[0130] The entire process is based on correlation analysis → target inference → attack handling and feedback:
[0131] Contextual data collection: Lists 5 types of data (attack information of the current sweeping DDoS attack, historical data, etc.).
[0132] The specific details of L4 / L7 / DNS attack incidents, IP address information, and threat intelligence must include...
[0133] Key data of business objects in the document (such as 90 L4 attacks and 15 DNS attacks);
[0134] Data correlation analysis: Calculate the W1-W5 correlation degree for each business object, and clarify the subdivision of each correlation degree.
[0135] Subtotal (data of a specific customer), denominator (data of a specific business object plus total data of other business objects), and calculation result;
[0136] Target inference: Substituting the default weights D1 = 0.3, D2 = 0.3, D3 = 0.2, D4 = 0.1, D5 = 0.1, write...
[0137] Provide the complete calculation process and results of the score value for a certain business object;
[0138] Attack Handling and Feedback: This section describes the results verification after manually migrating a specific business object to a high-defense data center.
[0139] Methods (how to determine if the judgment is correct), and specific actions of the security agent based on the feedback optimization model (such as...)
[0140] Adjusting weights and updating the knowledge graph.
[0141] Requirements: All content must originate from the document, without adding any information outside the document, and without using vague expressions.
[0142] (e.g., “a certain data” needs to be replaced with the specific value in the document).
[0143] In at least one embodiment of this disclosure, based on the above-described prompt word template, the information output by the security agent may include, for example, the following:
[0144] • Targeted IP address range: XXX.XXX.XX / XX
[0145] • IP address network segment information: Business object A has 6 IP addresses, business object B has 3 IP addresses, and the remaining business objects each have 1 to 2 IP addresses.
[0146] Target customer: Business object A (Score = 0.885) is the most likely to be attacked.
[0147] Business object A needs to remain isolated to avoid affecting other business objects A on the same IP address network segment.
[0148] • Basis for judgment:
[0149] • Business object A experienced 90 L4 DDoS attacks in the past 7 days, accounting for 90% of all business objects; business object A also experienced 5 L7 DDoS attacks in the past 7 days, accounting for 83.3% of all business objects.
[0150] Business object A had 15 DNS query flood records in the past 7 days, accounting for 100% of all business objects; business object A also purchased 6 new IP addresses in the attacked IP address segment within the past 7 days.
[0151] These dimensions indicate that the time when a customer purchases a new IP address coincides with the time when the IP address segment is subjected to a sweeping DDoS attack.
[0152] He Gao; Finally, business client A, belonging to industry XX, has experienced a large-scale [situation] in the last 7 days due to vicious industry competition.
[0153] The database contains records of mutual DDoS attacks. Therefore, based on the above, business object A is most likely the target of the attack.
[0154] The DDoS attack target identification method based on a security agent, provided in at least one embodiment of this disclosure, can proactively and collaboratively process multi-source heterogeneous data and dynamically supplement missing data. Furthermore, it can achieve self-optimization of the security agent, such as dynamically iterating weights to adapt to new attacks. By relying on the security agent to determine the attack target, the output content can be set as needed, and multiple types of defense devices can be automatically linked. It can reduce manual intervention through autonomous learning. When applying this DDoS attack target identification method based on a security agent to new scenarios, frequent code modifications are unnecessary, which helps improve the robustness of the method.
[0155] The DDoS attack target identification method based on security intelligent agents provided in at least one embodiment of this disclosure can perform multi-level and multi-dimensional coordinated analysis of related data, thereby overcoming the limitations of technical solutions that "only rely on real-time traffic". Furthermore, it can achieve full automation from data collection to correlation analysis to target inference. The implementation process of the DDoS attack target identification method based on security intelligent agents requires no manual intervention, and the response time for identifying the attack target can be shortened from several hours to within minutes. Moreover, by combining rule weights and autonomous optimization through machine learning, the accuracy of the initial inference can be guaranteed, and the inference accuracy can be improved through iteration using historical cases to adapt to different scenarios of sweeping DDoS attacks.
[0156] Based on the DDoS attack target identification method based on a security agent provided in at least one embodiment of this disclosure, at least one embodiment of this disclosure also provides a DDoS attack target identification device based on a security agent. The following will be combined with... Figure 7 This paper provides a detailed description of the DDoS attack target identification device based on a security intelligent agent.
[0157] Figure 7 The schematic diagram illustrates the structure of a DDoS attack target identification device based on a security intelligent agent provided in at least one embodiment of the present disclosure.
[0158] like Figure 7 As shown, the DDoS attack target identification device 700 based on a security intelligent agent in this embodiment includes an attack information acquisition module 710 and a business target determination module 720. For example, these units or modules can be implemented by hardware (e.g., circuit) modules or software modules, etc. The following embodiments are similar and will not be repeated. For example, these units or modules can be implemented by a central processing unit (CPU), a general-purpose graphics processor (GPGPU), a graphics processing unit (GPU), a tensor processor (TPU), a field-programmable gate array (FPGA), or other forms of processing units with data processing capabilities and / or instruction execution capabilities, as well as corresponding computer instructions.
[0159] The attack information acquisition module 710 is configured to acquire first attack information of the sweeping DDoS attack in response to the detection of a segment-scanning DDoS attack targeting a first IP address network segment. For example, if the IP addresses in the first IP address network segment are assigned to at least two service objects, the first attack information includes at least the first IP address network segment. Exemplarily, the attack information acquisition module 710 can be configured to execute step S210 described above. The specific implementation principle can be found in the relevant description of step S210, and will not be repeated here.
[0160] The object determination module 720 is configured to input first attack information into the security agent and obtain the first business object targeted by the sweeping DDoS attack from at least two business objects determined by the security agent. For example, the security agent obtains security risk association information related to a first IP address network segment based on the first attack information, and determines the first business object based on the security risk association information related to the first IP address network segment. Exemplarily, the business object determination module 720 can be configured to execute step S220 described above. The specific implementation principle can be referred to the relevant description of step S220, which will not be repeated here.
[0161] In at least one embodiment of this disclosure, the security risk association information associated with the first IP address network segment includes at least one of the following: second attack information on historical attacks against each of at least two business objects, the historical attacks including at least one of the following: attacks against the transport layer, attacks against the application layer, and a first query flooding attack launched against the domain name resolution system, wherein the attack domain name in the first query flooding attack includes the domain name associated with each business object; address information of the IP address allocated to each business object in the first IP address network segment; and historical attack information on business attribute attacks corresponding to each business object.
[0162] In at least one embodiment of this disclosure, the aforementioned security agent obtains security risk association information related to the first IP address network segment based on the first attack information, including: the security agent queries a knowledge graph based on historical attacks based on the first attack information to determine the information dimension of the security risk association information; and the security agent obtains security risk association information related to the first IP address network segment based on the information dimension and the first attack information.
[0163] In at least one embodiment of this disclosure, the security risk association information related to the first IP address network segment may include security risk association information corresponding to each of the at least two business objects; for example, the security agent determines the first business object based on the security risk association information, including: for each of the at least two business objects, the security agent determines the degree of association between each business object and the sweeping DDoS attack based on the security risk association information corresponding to each business object; and the security agent determines the first business object based on at least two degrees of association between the at least two business objects and the sweeping DDoS attack.
[0164] In at least one embodiment of this disclosure, the security risk association information corresponding to each business object includes at least two dimensions of association sub-information. For example, the security agent determines the degree of association between each business object and a sweeping DDoS attack based on the security risk association information corresponding to each business object, including: for each of the at least two dimensions, the security agent determines the sub-association degree between each business object and a sweeping DDoS attack based on the association sub-information of each dimension corresponding to each business object; and the security agent determines the weighted sum of the at least two sub-associations determined for the at least two dimensions based on a first weighted reassembly to obtain the degree of association between each business object and a sweeping DDoS attack.
[0165] In at least one embodiment of this disclosure, the aforementioned DDoS attack target identification 700 based on a security agent may further include a feedback module, configured to, in response to obtaining feedback information obtained from attack protection based on a first business object, feed the feedback information back to the security agent, so that the security agent adjusts the first weight reorganization based on the feedback information.
[0166] In at least one embodiment of this disclosure, the aforementioned security agent obtains security risk association information related to the first IP address network segment based on information dimensions and first attack information, including: the security agent determining the time range for the security risk association information based on the first attack information; and the security agent obtaining security risk association information related to the first IP address network segment based on the time range and information dimensions.
[0167] In at least one embodiment of this disclosure, the information dimension includes the dimension of historical attacks against each business object. For example, the security agent obtains security risk association information related to the first IP address network segment based on the time range and information dimension, including: for each business object, the security agent obtains second attack information on historical attacks against each business object based on the time range.
[0168] In at least one embodiment of this disclosure, the dimensions of historical attacks against each business object include at least two dimensions corresponding to at least two attack types. The aforementioned acquisition of the second attack information for historical attacks against each business object based on a time range includes: for each of the at least two dimensions, acquiring the number of historical attacks of the attack type corresponding to each dimension based on a time range, thus obtaining at least two attack counts corresponding to each of the at least two dimensions. For example, the at least two attack types include at least two of the following: attacks against the transport layer, attacks against the application layer, and a first query flooding attack launched against the domain name resolution system, wherein the attacking domain name in the first query flooding attack includes a domain name associated with each business object.
[0169] In at least one embodiment of this disclosure, the information dimension includes the address information dimension. The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension, including: for each business object, obtaining the address information of the IP address allocated to each business object in the first IP address network segment based on the time range.
[0170] In at least one embodiment of this disclosure, the security agent determines the degree of association between each business object and a segment-based DDoS attack based on security risk association information corresponding to each business object, including: the security agent determines the degree of association between each business object and a segment-based DDoS attack based on security risk association information related to a first IP address network segment and security risk association information corresponding to each business object.
[0171] In at least one embodiment of this disclosure, the information dimension includes the dimension of business attribute attacks corresponding to each business object. For example, the security agent obtains security risk association information related to the first IP address network segment based on the time range and information dimension, including: for each business object, obtaining historical attack information of business attribute attacks corresponding to each business object based on the time range.
[0172] In at least one embodiment of this disclosure, the object determination module 720 may be further configured to: input first attack information into a security agent to obtain inference information generated by the security agent. For example, the inference information includes inference results and inference basis, wherein the inference results characterize the first business object.
[0173] In at least one embodiment of this disclosure, the DDoS attack target identification device 700 based on the security agent may further include a feedback module, configured to feed back the feedback information to the security agent in response to obtaining feedback information obtained from attack protection based on the first business object, so that the security agent can optimize itself based on the feedback information.
[0174] It should be noted that, for clarity and brevity, this disclosure does not provide all the constituent units of the DDoS attack target identification device 700 based on a security intelligent agent. To achieve the necessary functions of the DDoS attack target identification device based on a security intelligent agent, those skilled in the art can provide and configure other constituent units (not shown) according to specific needs, and this disclosure does not impose any limitations on this.
[0175] At least one embodiment of this disclosure also provides an electronic device, including: a processing device; a storage device including one or more computer program modules; wherein the one or more computer program modules are stored in the storage device and configured to be executed by the processing device, and the one or more computer program modules are used to implement the business object determination method provided in any embodiment of this disclosure.
[0176] For example, the processing device may include a processor, such as a central processing unit (CPU), digital signal processor (DSP), image processor (GPU), general-purpose graphics processor (GPGPU), or other form of processing unit with data processing capabilities and / or instruction execution capabilities. It may be a general-purpose processor or a dedicated processor, and may control other components in the electronic device to perform the desired functions.
[0177] For example, the storage device may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), hard disk, flash memory, etc. One or more computer program instructions may be stored on the computer-readable storage medium, which a processing device may execute to implement the functions (implemented by the processing device) in the embodiments of this disclosure and / or other desired functions, such as a DDoS attack target identification method based on a security agent. Various applications and various data may also be stored in the computer-readable storage medium, such as the mapping relationship between IP addresses and business objects, prompt word templates, attack logs, etc.
[0178] The following is for reference. Figure 8 This illustration shows a structural diagram of an electronic device (e.g., a terminal device or a server) 800 suitable for implementing embodiments of the present disclosure. The terminal device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 8 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0179] like Figure 8As shown, the electronic device 800 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage device 808 into a random access memory (RAM) 803. The RAM 803 also stores various programs and data required for the operation of the electronic device 800. The processing device 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0180] Typically, the following devices can be connected to I / O interface 805: input devices 806 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 807 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 808 including, for example, magnetic tapes, hard disks, etc.; and communication devices 809. Communication device 809 allows electronic device 800 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 8 An electronic device 800 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.
[0181] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 809, or installed from a storage device 808, or installed from a ROM 802. When the computer program is executed by a processing device 801, it performs the functions defined in the methods of embodiments of this disclosure.
[0182] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0183] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0184] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0185] The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: in response to detecting a segment-scanning DDoS attack targeting a first IP address network segment, acquire first attack information of the segment-scanning DDoS attack, wherein IP addresses in the first IP address network segment are assigned to at least two business objects, and the first attack information includes at least the first IP address network segment; and input the first attack information into a security agent to acquire the first business object targeted by the segment-scanning DDoS attack among the at least two business objects determined by the security agent, wherein the security agent acquires security risk association information related to the first IP address network segment based on the first attack information, and determines the first business object based on the security risk association information related to the first IP address network segment.
[0186] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including but not limited to business-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0187] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0188] The units or modules described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units or modules do not necessarily constitute a limitation on the unit or module itself.
[0189] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0190] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0191] According to one or more embodiments of this disclosure, Example 1 provides a method for identifying DDoS attack targets based on a security intelligent agent, including:
[0192] In response to detecting a segment-scanning DDoS attack targeting a first IP address network segment, first attack information of the segment-scanning DDoS attack is obtained, wherein IP addresses in the first IP address network segment are assigned to at least two service objects, and the first attack information includes at least the first IP address network segment; and
[0193] The first attack information is input into the security agent to obtain the first business object targeted by the segment-scanning DDoS attack among the at least two business objects determined by the security agent. The security agent obtains security risk association information related to the first IP address network segment based on the first attack information, and determines the first business object based on the security risk association information related to the first IP address network segment.
[0194] According to one or more embodiments of this disclosure, Example 2 provides the security risk association information related to the first IP address network segment in Example 1, including at least one of the following:
[0195] Second attack information regarding historical attacks against each of the at least two business objects; the historical attacks include at least one of the following: attacks against the transport layer, attacks against the application layer, and a first query flooding attack launched against the domain name resolution system, wherein the attack domain name in the first query flooding attack includes the domain name associated with each of the business objects;
[0196] The address information of the IP address allocated to each service object in the first IP address network segment;
[0197] Historical attack information for business attribute attacks corresponding to each business object.
[0198] According to one or more embodiments of this disclosure, Example 3 provides that the security agent described in Example 1 or Example 2 obtains security risk association information related to the first IP address network segment based on the first attack information, including:
[0199] The security agent queries a knowledge graph based on historical attacks using the first attack information to determine the information dimensions of the security risk association information; and
[0200] The security agent obtains security risk association information related to the first IP address network segment based on the information dimension and the first attack information.
[0201] According to one or more embodiments of this disclosure, Example 4 provides that the security risk association information related to the first IP address network segment in Example 3 includes security risk association information corresponding to each of the at least two business objects;
[0202] The security intelligent agent determines the first business object based on the security risk association information, including:
[0203] For each of the at least two business objects, the security agent determines the correlation between each business object and the sweeping DDoS attack based on the security risk association information corresponding to each business object; and
[0204] The security agent determines the first business object based on at least two correlations between the at least two business objects and the sweeping DDoS attack.
[0205] According to one or more embodiments of this disclosure, Example 5 provides that the security risk association information corresponding to each business object in Example 4 includes at least two dimensions of association sub-information;
[0206] The security agent determines the correlation between each business object and the sweeping DDoS attack based on security risk association information corresponding to each business object, including:
[0207] For each of the at least two dimensions, the security agent determines the sub-association degree between each business object and the sweeping DDoS attack based on the association sub-information corresponding to each dimension for each business object; and
[0208] The security agent determines the weighted sum of at least two sub-associations for the at least two dimensions based on the first weighted reorganization, thereby obtaining the association degree between each business object and the sweeping DDoS attack.
[0209] According to one or more embodiments of this disclosure, Example Six provides the DDoS attack target identification method of Example Five, further comprising: in response to obtaining feedback information obtained from attack protection based on the first business object, feeding back the feedback information to the security agent, so that the security agent adjusts at least one of the following based on the feedback information: the first weight reassembly, the knowledge graph.
[0210] According to one or more embodiments of this disclosure, Example 7 provides that the security agent in Example 4 obtains security risk association information related to the first IP address network segment based on the information dimension and the first attack information, including:
[0211] The security agent determines the time range for the security risk association information based on the first attack information; and
[0212] The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension.
[0213] According to one or more embodiments of this disclosure, Example 8 provides that the information dimension in Example 7 includes a dimension of historical attacks against each of the business objects;
[0214] The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension, including:
[0215] The security agent acquires second attack information on historical attacks against each business object based on the time range.
[0216] According to one or more embodiments of this disclosure, Example 9 provides that the dimensions of historical attacks against each business object in Example 8 include at least two dimensions corresponding to at least two attack types respectively;
[0217] The second attack information, obtained based on the time range, regarding historical attacks against each business object, includes:
[0218] For each of the at least two dimensions, based on the time range, obtain the historical attack counts for the attack type corresponding to each dimension, thus obtaining at least two attack counts corresponding to each of the at least two dimensions.
[0219] The at least two attack types include at least two of the following: attacks targeting the transport layer, attacks targeting the application layer, and a first query flooding attack launched against the domain name resolution system, wherein the attack domain name in the first query flooding attack includes the domain name associated with each of the business objects.
[0220] According to one or more embodiments of this disclosure, Example 10 provides that the information dimension in Example 4 includes a dimension of address information;
[0221] The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension, including:
[0222] For each business object, the address information of the IP address allocated to each business object in the first IP address network segment is obtained based on the time range.
[0223] According to one or more embodiments of this disclosure, Example 11 provides that the security agent of any of Examples 8 to 10 determines the correlation between each business object and the sweeping DDoS attack based on security risk association information corresponding to each business object, including:
[0224] The security agent determines the correlation between each business object and the segment-scanning DDoS attack based on security risk association information related to the first IP address network segment and security risk association information corresponding to each business object.
[0225] According to one or more embodiments of this disclosure, Example Twelve provides that the information dimension of any of Examples Seven to Ten includes a dimension of business attribute attacks corresponding to each business object.
[0226] The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension, including:
[0227] For each business object, historical attack information on business attribute attacks corresponding to each business object is obtained based on the time range.
[0228] According to one or more embodiments of this disclosure, Example Thirteen provides the method described in Example One of inputting the first attack information into the security agent to obtain the first business object targeted by the sweeping DDoS attack among the at least two business objects determined by the security agent, including:
[0229] The first attack information is input into the security agent to obtain the reasoning information generated by the security agent, wherein the reasoning information includes the reasoning result and the reasoning basis, and the reasoning result represents the first business object.
[0230] According to one or more embodiments of this disclosure, Example Fourteen provides the DDoS attack target identification method described in Example One, further comprising:
[0231] In response to receiving feedback information obtained from attack protection based on the first business object, the feedback information is fed back to the security agent, so that the security agent can optimize itself based on the feedback information.
[0232] According to one or more embodiments of this disclosure, Example Fifteen provides a DDoS attack target identification device based on a security intelligent agent, comprising:
[0233] The attack information acquisition module is configured to, in response to detecting a segment-scanning DDoS attack targeting a first IP address network segment, acquire first attack information of the segment-scanning DDoS attack, wherein IP addresses in the first IP address network segment are assigned to at least two service objects, and the first attack information includes at least the first IP address network segment; and
[0234] The object determination module is configured to input the first attack information into the security agent, obtain the first business object targeted by the segment-scanning DDoS attack from the at least two business objects determined by the security agent, wherein the security agent obtains security risk association information related to the first IP address network segment based on the first attack information, and determines the first business object based on the security risk association information related to the first IP address network segment.
[0235] According to one or more embodiments of this disclosure, Example Sixteen provides an electronic device comprising:
[0236] Processing device; and
[0237] Storage device, including one or more computer program instructions;
[0238] The one or more computer program instructions are executed by the processing device to perform the DDoS attack target identification method based on a security intelligent agent provided in at least one embodiment of the present disclosure.
[0239] According to one or more embodiments of the present disclosure, Example Seventeen provides a computer-readable storage medium that non-transitory stores computer-readable instructions, wherein when the computer-readable instructions are executed by a processor, they implement the DDoS attack target identification method based on a secure intelligent agent provided in at least one embodiment of the present disclosure.
[0240] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features disclosed in this disclosure that have similar functions.
[0241] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0242] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A method for identifying DDoS attack targets based on a security intelligent agent, comprising: In response to detecting a segment-scanning DDoS attack targeting a first IP address network segment, first attack information of the segment-scanning DDoS attack is obtained, wherein IP addresses in the first IP address network segment are assigned to at least two service objects, and the first attack information includes at least the first IP address network segment; and The first attack information is input into the security agent to obtain the first business object targeted by the sweeping DDoS attack among the at least two business objects determined by the security agent. The security agent obtains security risk association information related to the first IP address network segment based on the first attack information and determines the first business object based on the security risk association information related to the first IP address network segment. The security risk association information includes information related to network attacks; determining the first service object based on the security risk association information related to the first IP address network segment includes: Based on the security risk association information, determine the degree of association between each of the at least two business objects and the sweeping DDoS attack; and The first business object is determined based on at least two correlations between the at least two business objects and the sweeping DDoS attack.
2. The DDoS attack target identification method according to claim 1, wherein, The security risk association information related to the first IP address network segment includes at least one of the following: Second attack information regarding historical attacks against each of the at least two business objects; the historical attacks include at least one of the following: attacks against the transport layer, attacks against the application layer, and a first query flooding attack launched against the domain name resolution system, wherein the attack domain name in the first query flooding attack includes the domain name associated with each of the business objects; The address information of the IP address allocated to each service object in the first IP address network segment; Historical attack information for business attribute attacks corresponding to each business object.
3. The DDoS attack target identification method according to claim 1 or 2, wherein, The security agent obtains security risk association information related to the first IP address network segment based on the first attack information, including: The security agent queries a knowledge graph based on historical attacks using the first attack information to determine the information dimensions of security risk association information; and The security agent obtains security risk association information related to the first IP address network segment based on the information dimension and the first attack information.
4. The DDoS attack target identification method according to claim 3, wherein, The security risk association information related to the first IP address network segment includes security risk association information corresponding to each of the at least two business objects; The step of determining the correlation between each of the at least two business objects and the sweeping DDoS attack based on the security risk association information includes: For each of the at least two business objects, the security agent determines the degree of correlation between each business object and the segment-scanning DDoS attack based on the security risk association information corresponding to each business object.
5. The DDoS attack target identification method according to claim 4, wherein, The security risk association information corresponding to each business object includes at least two dimensions of association sub-information; The security agent determines the correlation between each business object and the sweeping DDoS attack based on security risk association information corresponding to each business object, including: For each of the at least two dimensions, the security agent determines the sub-association degree between each business object and the sweeping DDoS attack based on the association sub-information corresponding to each dimension for each business object; and The security agent determines the weighted sum of at least two sub-associations for the at least two dimensions based on the first weighted reorganization, thereby obtaining the association degree between each business object and the sweeping DDoS attack.
6. The DDoS attack target identification method according to claim 5 further includes: In response to receiving feedback information obtained from attack protection based on the first business object, the feedback information is fed back to the security agent, so that the security agent adjusts at least one of the following based on the feedback information: the first weight reassembly, the knowledge graph.
7. The DDoS attack target identification method according to claim 4, wherein, The security agent obtains security risk association information related to the first IP address network segment based on the information dimension and the first attack information, including: The security agent determines the time range for the security risk association information based on the first attack information; and The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension.
8. The DDoS attack target identification method according to claim 7, wherein, The information dimension includes the dimension of historical attacks against each of the business objects; The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension, including: The security agent acquires second attack information on historical attacks against each business object based on the time range.
9. The DDoS attack target identification method according to claim 8, wherein, The dimensions of historical attacks for each business object include at least two dimensions corresponding to at least two attack types respectively; The second attack information, obtained based on the time range, regarding historical attacks against each business object, includes: For each of the at least two dimensions, based on the time range, obtain the historical attack counts for the attack type corresponding to each dimension, thus obtaining at least two attack counts corresponding to each of the at least two dimensions. The at least two attack types include at least two of the following: attacks targeting the transport layer, attacks targeting the application layer, and a first query flooding attack launched against the domain name resolution system; the attack domain name in the first query flooding attack includes the domain name associated with each of the business objects.
10. The DDoS attack target identification method according to claim 7, wherein, The information dimension includes the address information dimension; The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension, including: For each business object, the address information of the IP address allocated to each business object in the first IP address network segment is obtained based on the time range.
11. The DDoS attack target identification method according to any one of claims 8 to 10, wherein, The security agent determines the correlation between each business object and the sweeping DDoS attack based on the security risk association information corresponding to each business object, including: The security agent determines the correlation between each business object and the segment-scanning DDoS attack based on security risk association information related to the first IP address network segment and security risk association information corresponding to each business object.
12. The DDoS attack target identification method according to any one of claims 7 to 10, wherein, The information dimension includes the dimension of business attribute attacks corresponding to each business object. The security agent obtains security risk association information related to the first IP address network segment based on the time range and the information dimension, including: For each business object, historical attack information on business attribute attacks corresponding to each business object is obtained based on the time range.
13. The DDoS attack target identification method according to claim 1, wherein, The step of inputting the first attack information into the security agent and obtaining the first business object targeted by the sweeping DDoS attack from the at least two business objects determined by the security agent includes: The first attack information is input into the security agent to obtain the reasoning information generated by the security agent, wherein the reasoning information includes the reasoning result and the reasoning basis, and the reasoning result represents the first business object.
14. The DDoS attack target identification method according to claim 1 further includes: In response to receiving feedback information obtained from attack protection based on the first business object, the feedback information is fed back to the security agent, so that the security agent can optimize itself based on the feedback information.
15. A DDoS attack target identification device based on a security intelligent agent, comprising: The attack information acquisition module is configured to, in response to detecting a segment-scanning DDoS attack targeting a first IP address network segment, acquire first attack information of the segment-scanning DDoS attack, wherein IP addresses in the first IP address network segment are assigned to at least two service objects, and the first attack information includes at least the first IP address network segment; and The object determination module is configured to input the first attack information into the security agent, obtain the first business object targeted by the segment-scanning DDoS attack among the at least two business objects determined by the security agent, wherein the security agent obtains security risk association information related to the first IP address network segment based on the first attack information, and determines the first business object based on the security risk association information related to the first IP address network segment. The security risk association information includes information related to network attacks; determining the first service object based on the security risk association information related to the first IP address network segment includes: Based on the security risk association information, determine the degree of association between each of the at least two business objects and the sweeping DDoS attack; and The first business object is determined based on at least two correlations between the at least two business objects and the sweeping DDoS attack.
16. An electronic device comprising: Processing device; as well as Storage device, including one or more computer program instructions; The one or more computer program instructions are executed by the processing device during operation according to the DDoS attack target identification method according to any one of claims 1 to 14.
17. A computer-readable storage medium for non-transitory storage of computer-readable instructions, wherein, When the computer-readable instructions are executed by a processor, the DDoS attack target identification method according to any one of claims 1 to 14 is implemented.
Citation Information
Patent Citations
Attack defense method and device, electronic equipment and storage medium
CN115987639A
Password plaintext risk monitoring system and method based on traffic analysis and large model
CN120710785A