A centralized online source address verification false source detection method

CN121462307BActive Publication Date: 2026-09-15UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511834547.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-12-05
Publication Date
2026-09-15
Estimated Expiration
2045-12-05

AI Technical Summary

Technical Problem

[0004]缺乏实时性:在大规模网络流量环境下,检测延迟较高,难以及时预警;

Benefits of technology

[0035] 1) This invention proposes a centralized online source address verification method for detecting fake sources, providing an effective method for detecting fake sources in DDoS network attacks involving fake sources, such as reflection amplification attacks. This invention can analyze large amounts of network traffic in real time, achieving accurate identification of fake source traffic characteristics with an efficient detection method. This helps defense systems update intelligence in a timely manner, reduces manual intervention, improves the detection accuracy and response speed of fake sources, and thus enhances the overall network protection level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121462307B_ABST
    Figure CN121462307B_ABST
Patent Text Reader

Abstract

The application provides a false source detection method for centralized online source address verification, and belongs to the technical field of network security. The method comprises the following steps: a routing information receiving module distributes the router information of each router, and sends the routing information to a routing information management module; the routing information management module constructs a routing information tree based on a prefix dictionary tree according to the router information; a traffic information receiving module distributes the network traffic data passing through each interface, and sends the network traffic data to a false source attack identification module of a traffic information analysis module; the false source attack identification module receives the network traffic data, and matches and verifies the source IP address of the traffic in combination with the routing information tree, so as to determine whether there is false source traffic. The application has the characteristics of flexible deployment, high performance and fast response, can be distributed and centrally analyzed, can improve the detection and response capability of network false source address attack, and can stimulate the deployment of source address verification technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security technology, and in particular relates to a method for detecting fake sources through centralized online source address verification. Background Technology

[0002] Spoofed origins pose a significant threat to cybersecurity. In particular, reflection attacks exploit this vulnerability, where attackers forge source addresses to reflect traffic back to the target system. This amplifies small-scale malicious traffic by leveraging the target system's resources, resulting in a denial-of-service (DoS) attack. Reflective segment scanning attacks, on the other hand, scan a large number of IP addresses and forge source addresses to launch large-scale malicious traffic attacks, causing severe load pressure and security vulnerabilities to the target network.

[0003] Existing methods for detecting fake sources have the following shortcomings:

[0004] Lack of real-time capability: In environments with large-scale network traffic, the detection latency is high, making it difficult to issue timely warnings;

[0005] Low matching efficiency: The process of matching routing information and traffic data on the router interface is inefficient and cannot quickly complete source address verification in high-traffic environments;

[0006] The intelligence on false sources is not refined enough: Existing systems can often only make coarse-grained judgments on false sources, lacking the ability to perform fine-grained analysis on traffic type, intensity, and interface level. Summary of the Invention

[0007] The purpose of this invention is to provide a centralized source address verification method for detecting fake sources. By combining router interface routing information with real-time traffic data and utilizing an efficient prefix matching algorithm, it achieves efficient fake source detection and analysis, and generates refined fake source intelligence. This addresses the technical problems of untimely and inaccurate fake source intelligence in existing technologies, and promotes the application of source address verification technology.

[0008] To solve the above-mentioned technical problems, the specific technical solution of the present invention is as follows:

[0009] A centralized online source address verification method for detecting fake sources, the method comprising the following steps:

[0010] Step S1: The routing information receiving module sends query requests to all monitored routers via the SNMP protocol, collects router information from each router in a distributed manner, and sends the routing information to the routing information management module;

[0011] Step S2: The routing information management module receives router information and constructs a routing information tree based on the prefix trie according to the interface based on the router information;

[0012] Step S3: The traffic information receiving module continuously and distributedly collects network traffic data passing through each interface through NetFlow or sFlow, and sends the network traffic data to the fake source attack identification module of the traffic information analysis module.

[0013] Step S4: The fake source attack identification module receives network traffic data and, in conjunction with the routing information tree, centrally matches and verifies the source IP address of the traffic to determine whether fake source traffic exists.

[0014] Step S5: The attack situation analysis module identifies the traffic type and analyzes the intensity of the fake source attack traffic, and stores the attack information of the attack flow in the database;

[0015] Step S6: The attack information persistence module performs trend statistical analysis based on the attack information of the attack flow, generates attack intelligence, and displays alarms in a visual manner; and pushes the attack intelligence to other network security protection devices in real time.

[0016] Further, step S2 includes the following steps:

[0017] Step S21: Traverse each interface of each router and check if there is a routing information tree with the corresponding interface number. If not, initialize an empty prefix trie as the root node of the routing information tree for that interface based on the interface number.

[0018] Step S22: Traverse the routing entries in the routing table information corresponding to the interface, convert the IP address of each routing entry into a 32 or 128-bit binary string, and calculate the prefix length based on the subnet mask to obtain the binary prefix;

[0019] Step S23: Starting from the root node of the routing information tree, insert the binary prefix bit by bit into the routing information tree. If the node does not exist, create it. Set a valid flag bit at the end node of the prefix to identify the valid route corresponding to the prefix, and obtain the routing information tree.

[0020] Further, step S4 includes the following steps:

[0021] Step S41: Based on the ingress interface of the network traffic data, find the routing information tree of that interface; check whether the source IP address of the network traffic data exists in the routing information tree of that interface;

[0022] Step S42: Based on the outgoing interface of the network traffic data, find the routing information tree of that interface; check whether the source IP address of the network traffic data exists in the routing information tree of that interface;

[0023] Step S43: If the source IP address does not exist in the routing information tree of the inbound interface of the traffic, or if the source IP address exists in the routing information tree of the outbound interface of the traffic, then the traffic is determined to be fake source attack traffic.

[0024] Further, checking whether the source IP address of the network traffic data exists in the routing information tree of the interface includes the following steps:

[0025] Step S411: Obtain the root node of the routing information tree corresponding to the interface sequence number;

[0026] Step S412: Convert the source IP address to a 32- or 128-bit binary number;

[0027] Step S413: Search for branch nodes in the routing information tree from the high bit to the low bit of the binary number, and record the last successfully matched node; if a node with a valid flag bit exists, it is determined that the source IP address exists in the routing information tree of the interface and can be routed by the interface; otherwise, it is determined that there is no match.

[0028] Furthermore, step S5 is characterized by the following steps:

[0029] Step S51: Identify the attack type based on the protocol number and destination port number in the network traffic data;

[0030] Step S52: Calculate the attack strength index of the attack flow based on the number of data packets, the number of bytes, and the duration of the flow in the network traffic data;

[0031] Step S53: Store the attack information of the attack flow in the database.

[0032] Further, step S51 includes the following steps:

[0033] When the protocol is UDP, common reflection amplification attack types are further identified based on the destination port number. Traffic destined for port 53 is identified as a DNS service amplification attack; traffic destined for port 123 is identified as a Network Time Protocol (NAT) amplification attack; traffic destined for port 1900 is identified as a Simple Service Discovery Protocol (SLP) amplification attack; traffic destined for port 19 is identified as a Character Generator Protocol (SLP) amplification attack; traffic destined for port 161 is identified as a Simple Network Management Protocol (SMMP) amplification attack; traffic destined for port 389 is identified as a Lightweight Directory Access Protocol (LMAP) amplification attack; and traffic destined for port 112 is identified as a NAT amplification attack. Traffic with port 11 is identified as a distributed memory caching system amplification attack; traffic with destination port 137 is identified as a network basic name service amplification attack; traffic with destination port 3702 is identified as a web service discovery protocol amplification attack; traffic with destination port 5353 is identified as a multicast domain name system amplification attack; traffic with destination port 3389 is identified as a remote desktop protocol amplification attack; traffic with protocol number ICMP is identified as an Internet Control Message Protocol flooding attack; and other traffic with spoofed source addresses but not conforming to the above specific port characteristics is uniformly identified as an IP address spoofing attack.

[0034] Compared with the prior art, the present invention has the following beneficial technical effects:

[0035] 1) This invention proposes a centralized online source address verification method for detecting fake sources, providing an effective method for detecting fake sources in DDoS network attacks involving fake sources, such as reflection amplification attacks. This invention can analyze large amounts of network traffic in real time, achieving accurate identification of fake source traffic characteristics with an efficient detection method. This helps defense systems update intelligence in a timely manner, reduces manual intervention, improves the detection accuracy and response speed of fake sources, and thus enhances the overall network protection level.

[0036] 2) This invention features flexible deployment, high performance, and fast response. It has low deployment intrusion and does not require changes to existing network equipment during deployment, making incremental deployment easy. It can be deployed in a distributed manner according to network conditions and analyzed centrally, making it suitable for dealing with increasingly complex spoofing attacks. It can improve the detection and response capabilities of network spoofing source address attacks and is applicable to key industries such as government, finance, and telecommunications that have high requirements for network continuity and security, thereby improving the level of network security protection.

[0037] 3) The method described in this invention enables operators to achieve millisecond-level spoofing detection in large-scale traffic environments, accurately identify various threats such as reflection amplification attacks and spoofing flooding attacks, and generate refined intelligence at the interface level. This method effectively avoids the risks of false positives and false negatives, and by cooperating with existing defense equipment, it can form a distributed proactive defense system, significantly improving the network's security protection level.

[0038] 4) This invention can achieve efficient real-time detection. Through a routing information storage and matching algorithm based on a prefix trie, it can maintain high matching efficiency in a large-scale traffic environment.

[0039] 5) This invention can refine false source intelligence, and can output attack type, traffic intensity, false source interface information and timestamp, supporting source tracing and precise blocking;

[0040] 6) This invention features a centralized and scalable architecture that supports centralized data collection and processing from multiple routers, facilitating large-scale deployment. Attached Figure Description

[0041] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 This is a schematic diagram of the spoofing source detection method for centralized online source address verification according to the present invention.

[0043] Figure 2 This is a schematic diagram illustrating the implementation of the centralized online source address verification method for detecting fake sources according to the present invention. Detailed Implementation

[0044] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0045] To facilitate understanding, this invention first provides a brief introduction to the relevant technical terms:

[0046] Distributed Denial of Service (DDoS) attack: A DDoS attack is a type of network attack that uses a large number of controlled computers or devices to simultaneously send large amounts of data to a target, causing the target system or related network links to become overloaded, thereby preventing legitimate users from accessing or using the system normally.

[0047] IP spoofing: A network attack technique in which attackers forge the source IP address when sending network packets, making the packets appear to originate from a legitimate or trusted source. This technique is often used to launch a range of malicious activities, including denial-of-service (DoS) attacks, distributed denial-of-service (DDoS) attacks, session hijacking, and network intrusion.

[0048] SAVA (Source Address Validation Architecture) is an architectural framework and series of technologies used to ensure the authenticity of the source addresses of data packets on the Internet. This architecture primarily ensures the authenticity and reliability of the source addresses of data packets in the network, thereby improving network security and reducing the risk of network attacks.

[0049] Source Address Validation (SAV): Source address validation is a validation mechanism under SAVA that enables verification of the true source address in a network environment, thereby improving network security.

[0050] SNMP (Simple Network Management Protocol) is an application layer protocol used for monitoring and managing network devices such as routers, switches, and firewalls. SNMP allows administrators to remotely query device status, interface traffic, routing tables, and other information.

[0051] NetFlow (Network Traffic Analysis Technology): A network protocol proposed by Cisco for collecting network traffic information. NetFlow allows recording of each data flow (five-tuple) in the network, including source / destination IP, source / destination port, protocol, and data volume, making it an important tool for traffic analysis and anomaly detection.

[0052] Prefix Tree (Trie): An efficient tree data structure used to store a set of strings that can be quickly matched by prefixes. In this invention, the prefix tree is used for fast matching of routing tables to verify whether an IP address is within a reachable network of a certain interface.

[0053] A 5-tuple is a set of key fields that describe a network flow, typically including: source IP, destination IP, source port, destination port, and protocol number. A 5-tuple uniquely identifies a traffic session within a network and is commonly used for traffic identification and classification.

[0054] pps (Packets Per Second): The number of data packets transmitted per second, measuring the density or frequency of network traffic.

[0055] Bps (Bytes Per Second) / bps (Bits Per Second): These represent the number of bytes and bits transmitted per second, respectively, and are common units for measuring bandwidth utilization and traffic intensity.

[0056] Interface Index (ifIndex): A unique identifier for an interface in a network device, typically used in SNMP queries and traffic monitoring to identify a physical or logical interface.

[0057] This invention proposes a centralized online source address verification method for detecting fake sources, such as... Figure 1-2 As shown, the method includes the following steps:

[0058] Step S1: The routing information receiving module sends a query request to all monitored routers via the SNMP protocol, collects router information from each router in a distributed manner, and sends the routing information to the routing information management module.

[0059] Specifically, router information includes the router's IP address, interface information, and the number of interfaces.

[0060] Interface information includes interface number, interface name, interface IP address, interface status, routing table information, and number of routing entries.

[0061] The routing table information includes: multiple routing entries; each routing entry includes: destination IP address, subnet mask, route type, and next-hop address.

[0062] Step S2: The routing information management module receives router information and constructs a routing information tree based on the prefix trie according to the interface based on the router information.

[0063] Step S21: Traverse each interface of each router and check if there is a routing information tree with the corresponding interface number. If not, initialize an empty prefix trie as the root node of the routing information tree for that interface based on the interface number.

[0064] Step S22: Traverse the routing entries in the routing table information corresponding to the interface, convert the IP address of each routing entry into a 32 or 128-bit binary string, and calculate the prefix length based on the subnet mask to obtain the binary prefix.

[0065] Step S23: Starting from the root node of the routing information tree, insert the binary prefix bit by bit into the routing information tree. If the node does not exist, create it. Set a valid flag bit at the end node of the prefix to identify the valid route corresponding to the prefix, and obtain the routing information tree.

[0066] Specifically, during the construction of the routing information tree, after the prefix length calculated based on the subnet mask is determined, a binary prefix is ​​obtained. Starting from the most significant bit of the network address, the binary prefix is ​​inserted into the tree bit by bit. Specifically, for each bit being processed, if the bit is "0", the process moves to branch 0; if the bit is "1", the process moves to branch 1. During this process, if the child node of the target branch does not exist, it is created. When all bits of the prefix have been processed, i.e., when the process reaches the node corresponding to the last bit of the prefix, a valid flag (i.e., a Boolean flag set to true) is set at that node to indicate that the node corresponds to a complete and valid routing prefix, thus obtaining the routing information tree.

[0067] Therefore, an independent and efficient routing information tree is constructed for each interface, providing a fast matching foundation for subsequent real-time source address verification. The routing information tree for each interface is a binary prefix tree, with each tree node containing pointers to child nodes of branch 0, pointers to child nodes of branch 1, and a Boolean flag indicating whether it is a complete route prefix. By setting this flag at the precise end node of the prefix, it ensures that the complete route with the longest prefix match can be accurately identified during subsequent source address verification.

[0068] Step S3: The traffic information receiving module continuously and distributedly collects network traffic data passing through each interface via NetFlow or sFlow, and sends the network traffic data to the fake source attack identification module of the traffic information analysis module.

[0069] Network traffic data includes flow arrival time, source IP address, destination IP address, source port, destination port, protocol number, number of packets, number of bytes, flow start time, flow end time, ingress interface (the interface number through which the traffic enters the router) and egress interface (the interface number through which the traffic is forwarded from the router).

[0070] Step S4: The fake source attack identification module receives network traffic data and, in conjunction with the routing information tree, centrally matches and verifies the source IP address of the traffic to determine whether fake source traffic exists.

[0071] The fake origin attack detection module performs the following source IP address matching and verification steps for each received traffic data:

[0072] Step S41: Based on the ingress interface of the network traffic data, find the routing information tree of that interface; check whether the source IP address of the network traffic data exists in the routing information tree of that interface.

[0073] Step S411: Obtain the root node of the routing information tree corresponding to the interface sequence number.

[0074] Step S412: Convert the source IP address to a 32 or 128-bit binary number.

[0075] Step S413: Search for branch nodes in the routing information tree from the high bit to the low bit of the binary number, and record the last successfully matched node; if a node with a valid flag bit exists, it is determined that the source IP address exists in the routing information tree of the interface and can be routed by the interface; otherwise, it is determined that there is no match.

[0076] Specifically, the search proceeds bit by bit from the most significant bit to the least significant bit of the binary number. The specific search method is as follows: Starting from the root node of the routing information tree, for each bit being processed, its value (0 or 1) is extracted, and the node is then selected to proceed to the child node of the 0 or 1 branch. If the current node has a child node corresponding to its branch, the search continues to that child node; otherwise, further progress stops. Throughout the bit-by-bit search process, the last node with a valid flag (i.e., a node with a Boolean flag of true) is continuously recorded. This node corresponds to the longest complete route prefix matched so far. When all bits have been processed or further progress is impossible, if at least one node with a valid flag exists, the source IP address is considered to have successfully matched the routing information tree of that interface, meaning the source IP address can be routed by that interface; otherwise, it is considered a mismatch. This bit-by-bit binary search method ensures efficient implementation of the longest prefix matching, perfectly corresponds to the binary structure of the routing information tree, and can complete verification within a fixed depth, meeting real-time high-performance requirements.

[0077] A normal incoming traffic from this interface should have a source IP address that is within the reachable address range of the network to which this interface is connected.

[0078] Step S42: Based on the outgoing interface of the network traffic data, find the routing information tree of that interface; check whether the source IP address of the network traffic data exists in the routing information tree of that interface.

[0079] For normal traffic, the source IP should not be the address of the network to which the outgoing interface is connected.

[0080] Step S43: If the source IP address does not exist in the routing information tree of the inbound interface of the traffic, or if the source IP address exists in the routing information tree of the outbound interface of the traffic, then the traffic is determined to be fake source attack traffic.

[0081] This invention, through a design that separates the generation and use of the routing information tree, ensures both high-speed matching (fixed-depth lookup, almost unaffected by the size of the routing table) and centralized management of the verification logic, facilitating the deployment and maintenance of large-scale networks. Even with a large routing table, the matching speed remains constant, enabling millisecond-level detection in high-traffic environments.

[0082] Step S5: The attack situation analysis module identifies the traffic type and analyzes the intensity of the fake source attack traffic, and stores the attack information of the attack flow in the database.

[0083] Step S51: Identify the attack type based on the protocol number and destination port number in the network traffic data.

[0084] Attack types include, but are not limited to: Domain Name System (DNS) amplification attacks, Network Time Protocol (NTP) amplification attacks, Simple Service Discovery Protocol (SSDP) amplification attacks, Character Generator Protocol (CHARGEN) amplification attacks, Simple Network Management Protocol (SNMP) amplification attacks, Connection-less Lightweight Directory Access Protocol (CLDAP) amplification attacks, Memory Caching Daemon (Memcached) amplification attacks, NetBIOS Name Service (NBNS) amplification attacks, Web Services Dynamic Discovery (WS-Discovery) amplification attacks, Multicast Domain Name System (mDNS) amplification attacks, Remote Desktop Protocol (RDP) amplification attacks, Internet Control Message Protocol (ICMP) flood attacks, and Internet Protocol Spoofing (IP Spoofing) attacks.

[0085] Specifically, the identification of fake source attack traffic types is based on the protocol number and destination port number in the network traffic data. When the protocol number is UDP, common reflection amplification attack types are further identified based on the destination port number, including but not limited to: traffic with destination port number 53 is identified as a Domain Name System (DNS) amplification attack; traffic with destination port number 123 is identified as a Network Time Protocol (NTP) amplification attack; traffic with destination port number 1900 is identified as a Simple Service Discovery Protocol (SSDP) amplification attack; traffic with destination port number 19 is identified as a Character Generator Protocol (CHARGEN) amplification attack; traffic with destination port number 161 is identified as a Simple Network Management Protocol (SNMP) amplification attack; and traffic with destination port number 3... Traffic destined for port 89 is identified as a Lightweight Directory Access Protocol (CLDAP) amplification attack; traffic destined for port 11211 is identified as a Memcached distributed memory caching system amplification attack; traffic destined for port 137 is identified as a Network Basic Name Service (NBNS) amplification attack; traffic destined for port 3702 is identified as a Web Services Discovery Protocol (WS-Discovery) amplification attack; traffic destined for port 5353 is identified as a Multicast Domain Name System (mDNS) amplification attack; and traffic destined for port 3389 is identified as a Remote Desktop Protocol (RDP) amplification attack. Traffic with the protocol number ICMP is identified as an Internet Control Message Protocol flood (ICMP Flood) attack. Other traffic with spoofed source addresses but not conforming to the above specific port characteristics is uniformly identified as an IP address spoofing attack. This identification method covers common reflection amplification and flood attack types, ensuring comprehensive classification of spoofed source attacks.

[0086] Step S52: Calculate the attack strength index of the attack flow based on the number of data packets, the number of bytes, and the duration of the flow in the network traffic data.

[0087] Attack strength metrics include packets per second (pps), bytes per second (Bps), and bits per second (bps). These metrics quantify the scale of the attack and its bandwidth consumption.

[0088] The attack strength metrics are calculated using the following formulas: Packets per second (pps) is the number of data packets in the network traffic divided by the duration of the flow (in seconds); bytes per second (Bps) is the number of bytes in the network traffic divided by the duration of the flow (in seconds); bits per second (bps) is bytes per second multiplied by 8. To avoid division by zero errors, when the flow duration is less than or equal to zero, the duration can be treated as a very small positive value (e.g., 0.001 seconds) for calculation.

[0089] Step S53: Store the attack information of the attack flow in the database.

[0090] Attack information for the attack flow includes attack type, attack strength index, 5-tuple (source IP address, destination IP address, source port, destination port, protocol), entry interface, forwarding interface, and start and end timestamps of the attack flow. The start and end timestamps record the arrival times of the first and last packets of the attack flow, respectively, using Unix timestamp format (seconds or milliseconds since January 1, 1970, 00:00:00 UTC), for subsequent time series analysis.

[0091] The attack information of the attack flow is stored in the database using an auto-incrementing unique identifier as the primary key.

[0092] Furthermore, identifying spoofed source attack traffic can enhance defense by performing the following actions:

[0093] Step S6: The attack information persistence module performs trend statistical analysis based on the attack information of the attack flow, generates attack intelligence, and displays alarms in a visual manner; and pushes the attack intelligence to other network security protection devices in real time.

[0094] Trend statistical analysis is based on the attack records accumulated in the database. It uses aggregated queries to count the number of attacks, the distribution of attack types, the trend of intensity changes, and the hotspot distribution of affected interfaces within a specific time window. It supports the statistics of the total number and peak intensity of various attacks by hour, day, or week, thereby identifying the evolution of attack patterns and potential coordinated attack behaviors.

[0095] Structured attack intelligence is generated based on attack information extracted from a database. The generation process involves extracting recently identified attack records from the database, performing deduplication, aggregation, and priority sorting to form a standardized intelligence format. Attack details include core fields such as attack type, attack intensity index, source IP address, destination IP address, timestamp, and interface information, as well as optional source tracing tags and threat level assessments.

[0096] Attack intelligence is pushed in real time to other network security devices, such as firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS). Downstream devices can automatically generate blocking rules or execute traffic redirection strategies based on this precise attack intelligence, thereby achieving automated, coordinated defense across devices. This intelligence-sharing mechanism can not only mitigate and defend against ongoing attacks in a timely manner, but also provide a reference for defending against similar attacks in the future. Defense devices can automatically adjust their security policies based on the shared intelligence to achieve coordinated blocking, thereby improving response efficiency and security capabilities.

[0097] Application: A telecom operator's core network faced a large-scale DDoS attack with fake source addresses from outside. Attackers, by forging source IP addresses and combining this with reflection amplification techniques, injected massive amounts of attack traffic into multiple egress routers of the operator, causing congestion on some backbone links. The operator adopted the centralized online source address verification fake source detection method described in this invention for real-time detection and early warning of this type of attack.

[0098] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting fake sources using centralized online source address verification, characterized in that, The method includes the following steps: Step S1: The routing information receiving module sends query requests to all monitored routers via the SNMP protocol, collects router information from each router in a distributed manner, and sends the routing information to the routing information management module; Step S2: The routing information management module receives router information and constructs a routing information tree based on the prefix trie according to the interface based on the router information; Step S3: The traffic information receiving module continuously and distributedly collects network traffic data passing through each interface through NetFlow or sFlow, and sends the network traffic data to the fake source attack identification module of the traffic information analysis module. Step S4: The fake source attack identification module receives network traffic data and, in conjunction with the routing information tree, centrally matches and verifies the source IP address of the traffic to determine whether fake source traffic exists. Step S5: The attack situation analysis module identifies the traffic type and analyzes the intensity of the fake source attack traffic, and stores the attack information of the attack flow in the database; Step S6: The attack information persistence module performs trend statistical analysis based on the attack information of the attack flow, generates attack intelligence, and displays alarms in a visual manner; and pushes the attack intelligence to other network security protection devices in real time. Step S2 includes the following steps: Step S21: Traverse each interface of each router and check if there is a routing information tree with the corresponding interface number. If not, initialize an empty prefix trie as the root node of the routing information tree for that interface based on the interface number. Step S22: Traverse the routing entries in the routing table information corresponding to the interface, convert the IP address of each routing entry into a 32- or 128-bit binary string, and calculate the prefix length based on the subnet mask to obtain the binary prefix; Step S23: Starting from the root node of the routing information tree, insert the binary prefix bit by bit into the routing information tree. If the node does not exist, create it. Set the valid flag bit at the end node of the prefix to identify the valid route corresponding to the prefix, and obtain the routing information tree. Step S4 includes the following steps: Step S41: Based on the ingress interface of the network traffic data, find the routing information tree of that interface; check whether the source IP address of the network traffic data exists in the routing information tree of that interface; Step S42: Based on the outgoing interface of the network traffic data, find the routing information tree of that interface; check whether the source IP address of the network traffic data exists in the routing information tree of that interface; Step S43: If the source IP address does not exist in the routing information tree of the inbound interface of the traffic, or if the source IP address exists in the routing information tree of the outbound interface of the traffic, then the traffic is determined to be fake source attack traffic.

2. The method for detecting fake sources using centralized online source address verification according to claim 1, characterized in that, Checking whether the source IP address of the network traffic data exists in the routing information tree of this interface includes the following steps: Step S411: Obtain the root node of the routing information tree corresponding to the interface sequence number; Step S412: Convert the source IP address to a 32- or 128-bit binary number; Step S413: Search for branch nodes in the routing information tree from the most significant bit to the least significant bit of the binary number, and record the last successfully matched node; If a node with a valid flag is found, the source IP address is determined to exist in the routing information tree of that interface and can be routed through that interface; otherwise, a mismatch is determined.

3. The method for detecting fake sources using centralized online source address verification according to claim 1, characterized in that, Step S5 includes the following steps: Step S51: Identify the attack type based on the protocol number and destination port number in the network traffic data; Step S52: Calculate the attack strength index of the attack flow based on the number of data packets, the number of bytes, and the duration of the flow in the network traffic data; Step S53: Store the attack information of the attack flow in the database.

4. The method for detecting fake sources using centralized online source address verification according to claim 1, characterized in that, Step S51 includes the following steps: When the protocol number is UDP, common reflection amplification attack types are further identified based on the destination port number. Traffic with a destination port number of 53 is identified as a major attack on the domain name resolution service. Traffic destined for port 123 was identified as a Network Time Protocol (NTP) amplification attack. Traffic destined for port 1900 was identified as a Simple Service Discovery Protocol (SSP) amplification attack. Traffic destined for port 19 was identified as a character generator protocol amplification attack; Traffic destined for port 161 was identified as a Simple Network Management Protocol (SMMP) amplification attack; traffic destined for port 389 was identified as a Lightweight Directory Access Protocol (LAC) amplification attack; and traffic destined for port 11211 was identified as a Distributed Memory Caching System (DMC) amplification attack. Traffic destined for port 137 was identified as a Basic Name Service amplification attack. Traffic destined for port 3702 is identified as a Web Service Discovery Protocol amplification attack; traffic destined for port 5353 is identified as a Multicast Domain Name System amplification attack; traffic destined for port 3389 is identified as a Remote Desktop Protocol amplification attack; traffic with the protocol number ICMP is identified as an Internet Control Message Protocol flooding attack; and other traffic with spoofed source addresses but not conforming to the above port number characteristics is uniformly identified as an IP address spoofing attack.

Citation Information

Patent Citations

  • Network equipment performance analysis method, system and equipment and computer medium

    CN111698110A

  • Metropolitan area network routing flow false source address analysis method and device

    CN114006734A