Network security protection method and system
By introducing black hole routers and the BGP protocol into the network security protection system, generating and distributing black hole routes, and combining community attribute values to mark the danger level and effective scope of fraudulent IP addresses, the problem that DPI technology cannot effectively block fraudulent traffic under encrypted protocols is solved, and accurate and efficient fraudulent data packet discarding is achieved.
Patent Information
- Application Number
- CN202511781737.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-29
- Publication Date
- 2026-02-10
AI Technical Summary
Existing DPI technology cannot effectively block fraudulent traffic in scenarios with encrypted or connectionless protocols, resulting in incomplete blocking scope and insufficient accuracy.
By introducing black hole routers into the network security protection system, black hole routes are generated and distributed using the Border Gateway Protocol (BGP). Combined with community attribute values to mark the danger level and effective scope of fraudulent IP addresses, route-level blocking is achieved, and fraudulent data packets are directly dropped.
It achieves precise and efficient blocking of fraudulent traffic, improves the efficiency and accuracy of fraudulent data governance, and avoids the repeated identification process at the transport layer and application layer.
Smart Images

Figure CN121509022A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and particularly relates to a network security protection method and system. BACKGROUND
[0002] In the current Internet environment, operators mainly perform network supervision and security protection through a deep packet inspection (DPI) technology. The DPI technology is a network traffic analysis technology, which can analyze key information such as content, protocol type, and application characteristics of a payload layer of a data packet, rather than being limited to checking header information such as an IP address and a port of the data packet.
[0003] In the related art, a deployment mode of a DPI system includes a DPI series connection mode and a DPI parallel connection mode. In the DPI series connection mode or the DPI parallel connection mode, because the DPI system depends on deep analysis and redirection of a data packet payload, the DPI system has limited capability in an encrypted protocol or a connectionless protocol scenario, cannot comprehensively and effectively block fraud-related traffic, and causes the blocking range of the fraud-related traffic to be incomplete and the accuracy to be insufficient. SUMMARY
[0004] Therefore, the present application provides a network security protection method and system, which can efficiently and accurately block fraud-related traffic.
[0005] In a first aspect, the present application provides a network security protection method applied to a network security protection system. The network security protection system includes a routing domain. The routing domain is established by one or more autonomous domains based on a border gateway protocol. The autonomous domain includes a black hole router and a normal router. The method includes the following steps. The black hole router receives a fraud-related IP address and a group attribute value. The group attribute value is used to represent a dangerous degree and an effective range of the fraud-related IP address. The black hole router generates a black hole route according to the fraud-related IP address, and sends the black hole route and the group attribute value to a first router, so as to discard a data packet of the fraud-related IP address flowing through the first router based on the black hole route. The first router is a normal router in the routing domain that matches the group attribute value.
[0006] In some embodiments of the present application, the autonomous domain further includes a processing module. The processing module is in communication connection with the black hole router. The method further includes the following steps. The processing module receives fraud-related information. The fraud-related information includes a fraud-related IP address, a dangerous degree, and an effective range. The processing module maps the risk level and the effective range to the community attribute value according to a preset mapping table, and sends the fraud-related IP address and the community attribute value to the black hole router. The mapping table includes a mapping relationship between the risk level, the effective range, and the community attribute value; and the community attribute value is an attribute field used for marking a route in the border gateway protocol.
[0007] In some embodiments of the present disclosure, the processing module is in communication connection with an industry anti-fraud platform; and the method further includes: The processing module receives the fraud-related information issued by the industry anti-fraud platform.
[0008] In some embodiments of the present disclosure, the autonomous domain further includes a route reflector; the black hole router is in communication connection with the route reflector based on the border gateway protocol; and the method further includes: The black hole router marks the black hole route with the community attribute value, and sends the black hole route marked with the community attribute value to the route reflector; The route reflector sends the black hole route marked with the community attribute value to a general router in the autonomous domain.
[0009] In some embodiments of the present disclosure, the processing module is in communication connection with the general router; and the method further includes: The processing module sends a receiving strategy to the general router; the receiving strategy is based on a router role, a deployment position, and a belonging area of the general router; The general router receives the black hole route marked with the community attribute value, detects whether the community attribute value matches the receiving strategy, and in the case of matching, loads the black hole route to a local routing table.
[0010] In some embodiments of the present disclosure, the method further includes: The black hole router performs a mirroring operation on the data packet of the fraud-related IP address when receiving the data packet of the fraud-related IP address sent by the first router, obtains a mirrored data packet, and sends the mirrored data packet to the processing module; The processing module determines an access amount and an access range of the fraud-related IP address according to the mirrored data packet, updates the risk level based on the access amount, updates the effective range based on the access range, and updates the community attribute value based on the updated risk level and the effective range; The access amount is an amount of data interaction of the fraud-related IP address in a preset time period; and the access range is a network area and a network level covered by the fraud-related IP address in the network.
[0011] In some embodiments of the present disclosure, the processing module updates the danger level based on the access amount; and the method comprises: determining a preset access amount interval corresponding to different danger levels; updating the danger level of the fraud-related IP address according to the access amount interval in which the access amount is located.
[0012] In some embodiments of the present disclosure, the processing module determines the access range of the fraud-related IP address according to the mirror data packet; and the method comprises: detecting a source address of the mirror data packet; matching the source address with IP addresses in an address library to determine a network area and a network level of the source address; the address library comprises a corresponding relationship between IP addresses and network areas and network levels; summarizing the network area and the network level of the source address to obtain the access range of the fraud-related IP address.
[0013] In some embodiments of the present disclosure, the method further comprises: The black hole router receives the updated group attribute value, and sends the black hole routing and the updated group attribute value to a second router; the second router is a normal router in the routing domain that matches the updated group attribute value; The second router performs a discard operation on the data packet of the fraud-related IP address based on the black hole routing when receiving the data packet of the fraud-related IP address.
[0014] In a second aspect, the present disclosure provides a network security protection system, comprising a routing domain; the routing domain is established by one or more autonomous domains based on a border gateway protocol; the autonomous domain comprises a black hole router and a normal router; The black hole router is configured to receive a fraud-related IP address and a group attribute value; generate a black hole routing according to the fraud-related IP address, and send the black hole routing and the group attribute value to a first router to discard a data packet of the fraud-related IP address flowing through the first router based on the black hole routing; the group attribute value is used to represent a danger level and an effective range of the fraud-related IP address; and the first router is a normal router in the routing domain that matches the group attribute value.
[0015] By the technical scheme, the network security protection method and system provided by the application relate to the network security technical field, wherein the network security protection system comprises a routing domain, the routing domain is established by one or more autonomous domains based on a border gateway protocol, and the autonomous domain comprises a black hole router and a normal router.
[0016] In the technical scheme, the black hole router generates and distributes the black hole route based on the routing domain established by one or more autonomous domains based on the border gateway protocol (BGP), so that the data packets of the fraud IP address are directly discarded through the black hole route. Moreover, the danger degree and the effective range of the fraud IP address can be explicitly indicated through the community attribute value, so that the black hole route is accurately sent to the matching normal router (the first router) in the routing domain. The application realizes the route-level blocking through the BGP protocol, and the blocking action of the fraud IP address is sunk from the transport layer and the application layer to the network layer, so that the problem of the fraud data transmission can be completely solved at the network layer, and the identification of the fraud IP address, the protocol port and the fraud data at the transport layer and the application layer is not needed, the accurate and efficient blocking of the fraud IP address is realized, and the efficiency and the accuracy of the fraud data management are improved.
[0017] The above description is only a summary of the technical scheme of the application, in order to more clearly understand the technical means of the application, the specific embodiments of the application can be implemented according to the content of the specification, and in order to make the above and other purposes, characteristics and advantages of the application more obvious and easy to understand, the following specific embodiments of the application are described. BRIEF DESCRIPTION OF DRAWINGS
[0018] The drawings incorporated into the specification and forming a part of the specification, show embodiments consistent with the application, and together with the specification, serve to explain the principles of the application.
[0019] In order to more clearly illustrate the technical scheme in the embodiments of the application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced as follows, and obviously, other drawings can be obtained by those skilled in the art without creative labor.
[0020] Figure 1 Deployment schematic diagram of the DPI series mode provided by the embodiment of the present disclosure; Figure 2 A deployment schematic diagram of the DPI parallel mode provided by the embodiment of the present disclosure is provided. Figure 3 A flow schematic diagram of the network security protection method provided by the embodiment of the present disclosure is provided. Figure 4 An architecture diagram of the operator anti-fraud system provided by the embodiment of the present disclosure is provided. Figure 5 A network topology schematic diagram of the operator Internet provided by the embodiment of the present disclosure is provided. Figure 6 A diffusion flow schematic diagram of the black hole routing provided by the embodiment of the present disclosure is provided. Figure 7 A configuration flow schematic diagram of the receiving strategy provided by the embodiment of the present disclosure is provided. Figure 8 A dynamic adjustment flow schematic diagram of the danger degree and the effective range provided by the embodiment of the present disclosure is provided. Figure 9 An interval schematic diagram of the danger degree provided by the embodiment of the present disclosure is provided. Figure 10 A dynamic adjustment schematic diagram of the group attribute value provided by the embodiment of the present disclosure is provided. DETAILED DESCRIPTION
[0021] Embodiments of the present application will be described in more detail below with reference to the accompanying drawings. It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.
[0022] The embodiments of the present disclosure will be described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference signs represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary and are intended to explain the present disclosure, and cannot be understood as a limitation of the present disclosure.
[0023] The embodiments of the present disclosure are not exhaustive, but only a schematic of some embodiments, and are not specific limitations on the protection scope of the present disclosure. Each step in an embodiment can be implemented as an independent embodiment without conflict, and the steps can be combined arbitrarily, for example, the scheme after removing some steps in an embodiment can also be implemented as an independent embodiment, and the order of the steps in an embodiment can be exchanged arbitrarily, in addition, the optional implementation manners in an embodiment can be combined arbitrarily; in addition, the embodiments can be combined arbitrarily, for example, the steps of different embodiments or part or all of the steps of different embodiments can be combined arbitrarily, an embodiment can be combined with the optional implementation manners of other embodiments arbitrarily.
[0024] In the embodiments of the present disclosure, the terms and / or descriptions among the embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0025] The terms used in the embodiments of the present disclosure are only for the purpose of describing particular embodiments and are not used as limitations of the present disclosure.
[0026] In the embodiments of the present disclosure, unless otherwise specified, the elements expressed in singular form, such as "one", "a", "the", "above", "said", "preceding", "this" and the like, can represent "one and only one", or "one or more", "at least one" and the like. For example, in the case of using articles such as "a", "an", "the" in English in translation, the noun after the article can be understood as singular expression, or can be understood as plural expression.
[0027] In some embodiments, the terms "in response to", "in response to determining", "in the case of", "when", "when", "if", "if" and the like can be replaced with each other.
[0028] In some embodiments, the terms "greater than", "greater than or equal to", "not less than", "more than", "more than or equal to", "not less than", "higher than", "higher than or equal to", "not lower than", "above" and the like can be replaced with each other, and the terms "less than", "less than or equal to", "not greater than", "less than", "less than or equal to", "not more than", "lower than", "lower than or equal to", "not higher than", "below" and the like can be replaced with each other.
[0029] In the embodiments of the present disclosure, the prefix words "first", "second" and the like are only used to distinguish different description objects, and do not constitute limitations on the position, order, priority, quantity or content of the description objects. The description of the description object should be referred to the description in the context of the claims or embodiments, and should not constitute redundant limitations because of the use of the prefix word.
[0030] In the embodiments of the present disclosure, "a plurality of" means two or more.
[0031] In the embodiments of the present disclosure, the terms "import", "input", "read in" and the like can be replaced with each other.
[0032] Currently, operators primarily use Deep Packet Inspection (DPI) technology to block fraudulent Internet Protocol (IP) data to achieve network monitoring and security protection. DPI is a network traffic analysis technology that delves into the payload layer of data packets, accurately analyzing their content, protocol type, application characteristics, and other key information, rather than simply checking header information such as IP addresses and ports. The business process for implementing anti-fraud capabilities based on a DPI system is as follows: Packet capture: Copying or receiving data packets flowing through the network link without interfering with normal data transmission.
[0033] Protocol parsing: First, the underlying protocols are parsed, such as Ethernet frames, Internet Protocol (IP) headers, Transmission Control Protocol (TCP) or User Datagram Protocol (UDP) ports, etc., to determine basic transmission information. Then, the application layer protocols are parsed layer by layer, such as the Uniform Resource Locator (URL), request headers, and POST data of HyperText Transfer Protocol (HTTP).
[0034] Feature matching: The parsed content is compared with the built-in feature library to accurately identify key information such as the source IP address of illegal applications and malicious communications.
[0035] Policy execution: Based on the matching results, execute preset rules, such as blocking HTTP requests containing illegal content and malicious programs.
[0036] In related technologies, the anti-fraud system for operators, based on the differences in the deployment mode of the DPI system, has two specific implementation methods: DPI serial mode and DPI parallel mode, such as... Figure 1 , Figure 2 The diagram shows the deployment of DPI serial and parallel modes provided in this application embodiment. In DPI serial mode, the DPI system is directly connected in series in the data transmission path connecting the provincial internet network and the backbone network, ensuring that all network traffic must pass through the DPI device for detection and processing. In DPI parallel mode, the DPI system is connected in parallel outside the network transmission path. It can obtain network data packets through the traffic mirroring function of the provincial internet network exit router, only monitoring, analyzing, and recording traffic without directly intervening in the data transmission process.
[0037] The anti-fraud system of the operator comprises a system interface module and a service processing and presentation module. The system interface module serves as a data interaction bridge and is responsible for data docking between the DPI system and the anti-fraud system of the operator. The service processing and presentation module is used for service logic processing and visual presentation of the original data obtained from the DPI system.
[0038] However, in the DPI series mode, the DPI system handles TCP data by disassembling the connection to process IP packets. For internal users accessing HTTP, non-encrypted Websocket and other protocol connections of the fraud website, the anti-fraud IP address blocking can be directly performed. However, for internal users accessing the HyperText Transfer Protocol Secure (HTTPS), encrypted Websocket and other protocol connections of the fraud website, due to the encryption of data packets, it is not possible to forge a redirection packet, so the anti-fraud IP address blocking cannot be performed. For UDP data, since the UDP protocol is a connectionless data transmission method, in the DPI series mode, the traffic discard method can be used. For other transport layer protocols, detection and blocking are not supported.
[0039] In the DPI parallel mode, for TCP data, the handling method is similar to the DPI series mode, and the anti-fraud IP address blocking is not supported for encrypted data packets. For UDP data, since the UDP protocol is a connectionless data transmission method, it is not possible to forge a redirection packet during data transmission, so the anti-fraud IP address blocking cannot be performed in the DPI parallel mode. For other transport layer protocols, detection and blocking are not supported.
[0040] To solve the above problems, the network security protection method provided by the embodiments of the present application is applied to a network security protection system, the network security protection system comprises a routing domain, the routing domain is established by one or more autonomous domains based on a Border Gateway Protocol (BGP), and the autonomous domain comprises a black hole router and a normal router. As shown in Figure 3 The flowchart of the network security protection method provided by the embodiments of the present application is shown in the figure, which comprises the following steps: S101: The black hole router receives an anti-fraud IP address and a community attribute value.
[0041] The community attribute value is used to represent the danger degree and the effective range of the anti-fraud IP address. The community attribute value is an attribute field used to mark the route in the BGP protocol. It can be understood that the community attribute (Community Attribute) of the BGP protocol is an optional path attribute, which is used to mark or classify the BGP route, so as to simplify the configuration of route filtering, optimization, aggregation and the like.
[0042] S102: The black hole router generates a black hole route according to the fraud-related IP address.
[0043] The application adopts the black hole routing mode to block the fraud-related IP address. The black hole routing is a function of network equipment. By guiding the traffic of a specific IP address (fraud-related IP address) to a virtual null interface (such as Null0 interface), any data packet sent to the virtual null interface will be discarded by the router directly, and no feedback information will be generated, thereby realizing efficient traffic blocking.
[0044] S103: The black hole router sends the black hole route and the community attribute value to the first router, so as to discard the data packet of the fraud-related IP address flowing through the first router based on the black hole route.
[0045] The first router is a normal router in the routing domain matching the community attribute value. To realize flexible diffusion and fine control of the blocking policy in the network, the configured black hole route is injected into the BGP routing domain. The black hole route is updated and diffused to the corresponding BGP routing domain through the BGP protocol. When the black hole route is injected into the BGP routing domain, the black hole route is labeled by using the community attribute value of the BGP protocol. By setting different community attribute values for the black hole route containing the fraud-related IP address, the business-level blocking policy (danger level, effective range) is converted into a route label recognizable by the network equipment, so that the normal router in the BGP routing domain can selectively load the black hole route based on the local policy, thereby realizing dynamic distribution and adjustment of the fraud-related IP address blocking policy.
[0046] In the embodiment, the black hole route is generated and distributed by the black hole router relying on the routing domain established by one or more autonomous systems based on the border gateway protocol (BGP), so as to discard the data packet of the fraud-related IP address directly through the black hole route. Moreover, the danger level and the effective range of the fraud-related IP address can be explicitly indicated by the community attribute value, so that the black hole route is accurately sent only to the matching normal router (first router) in the routing domain. The application realizes the route-level blocking through the BGP protocol, and sinks the blocking action of the fraud-related IP address from the transport layer and the application layer to the network layer, so as to completely solve the problem of fraud-related data transmission from the network layer without the need for identification of the fraud-related IP address, protocol port and fraud-related data in the transport layer and the application layer. The application realizes accurate and efficient blocking of the fraud-related IP address, and improves the efficiency and accuracy of fraud-related data management as a whole.
[0047] The network security protection method provided in the present application can be applied in the network architecture of an operator, and relies on the multi-level autonomous domain and BGP routing system in the network architecture of the operator to achieve blocking of fraud-related traffic. As shown in Figure 4 The present application provides a framework diagram of an operator anti-fraud system, which includes a processing module, a black hole router and a general router. According to the hierarchical division of the network architecture of the operator, the processing module includes a system interface module, a business processing and presentation module, a management module of an Internet backbone network and an Internet (each) provincial network, a traffic analysis module of the Internet backbone network and the Internet (each) provincial network, the black hole router includes a black hole router of the backbone network and the (each) provincial network, and the general router includes a router of the backbone network and the (each) provincial network.
[0048] The system interface module is configured to perform data transmission between the standardized interface and the industry anti-fraud platform, and receive fraud-related information including fraud-related IP addresses, danger levels, effective ranges, etc.
[0049] The business processing and presentation module is configured to complete the processing, distribution, confirmation and statistics of the fraud-related information, and is connected to the system interface module in the north direction, and is responsible for information interaction with the Internet backbone network management module, the Internet backbone network traffic analysis module, the Internet provincial network management module and the Internet provincial network traffic analysis module in the south direction.
[0050] The management module of the Internet backbone network and the Internet (each) provincial network is configured to, after receiving the fraud-related information transmitted by the business processing and presentation module, use a southward interface protocol to issue a black hole routing configuration to the black hole router of the backbone network and the (each) provincial network, and issue a related configuration of a BGP protocol group attribute value to other general routers in the autonomous domain, so as to realize fine routing control.
[0051] The black hole router of the backbone network and the (each) provincial network receives the black hole routing configuration, generates a black hole routing after receiving the black hole routing configuration, updates its own routing table, and uses a route reflector to diffuse the black hole routing carrying the group attribute value to the entire autonomous domain. The fraud-related traffic directed to the fraud-related IP address can also be mirrored and copied once, and sent to the traffic analysis module of the Internet backbone network and the Internet (each) provincial network.
[0052] The traffic analysis module of the Internet backbone network and the Internet (each) provincial network is configured to receive the fraud-related traffic of the fraud-related IP address mirrored by the black hole router of the backbone network and the (each) provincial network, and perform statistics and analysis on the fraud-related traffic. The analysis result is used as key feedback information to provide data support for the upper business processing and presentation module to dynamically adjust the danger level and the effective range of the fraud-related IP address, so as to realize self-optimization and precise control of the system.
[0053] As shown in Figure 5As shown, the network topology diagram of the operator Internet provided by the embodiment of the application, the operator Internet autonomous domain adopts a multi-level structure, which is divided into a backbone network autonomous domain and a provincial network autonomous domain. Among them, the backbone network is an independent autonomous domain, which allocates a public autonomous domain number, and each provincial network is an independent autonomous domain, which can allocate a public autonomous domain number or a private autonomous domain number. In terms of routing protocol, different autonomous domains run an external border gateway protocol (eBGP). In each autonomous domain, an internal border gateway protocol (iBGP) and a related interior gateway protocol (IGP) are run. To solve the scalability problem caused by the requirement of full connection of the iBGP protocol and simplify the network complexity, a route reflector (RR) is deployed in each autonomous domain, which is referred to as an RR router, to efficiently synchronize routing information.
[0054] For the fraud IP address blocking scheme based on black hole routing, a pair of black hole routers is deployed in the operator backbone autonomous domain and all or part of the provincial network autonomous domain to eliminate the risk of single point failure. The black hole routers establish an iBGP neighbor relationship with the route reflector in the autonomous domain.
[0055] When the upper-layer business system receives the fraud IP address, the fraud IP address is converted into a black hole routing configuration and pushed to the black hole router. After receiving the configuration, the black hole router generates a black hole route pointing to a virtual null interface, and propagates the black hole route to all ordinary routers in the BGP routing domain through the route reflector.
[0056] Subsequently, when the ordinary router (first router) loaded with the black hole route in the autonomous domain receives a data packet of the fraud IP address, the data packet is guided to the virtual null interface to perform a discard operation. Or the data packet of the fraud IP address is led to the black hole router, and the black hole router (with the help of a related functional module) completes the traffic statistics and discard operation.
[0057] That is, when the first router receives a data packet of the fraud IP address, it can directly perform a discard operation on the data packet of the fraud IP address based on the black hole route, or send the data packet of the fraud IP address to the black hole route based on the black hole route, and the black hole route performs subsequent traffic analysis operation and discard operation on the data packet of the fraud IP address.
[0058] It can be understood that the fraud-related data is based on the operator's Internet network. If the identified fraud-related IP addresses are blocked in the operator's Internet network, and the associated data of all fraud-related IP addresses is disposed of by packet loss, the problem of fraud-related traffic transmission can be completely solved at the network layer without the need for identification of fraud-related IP addresses, protocol ports and fraud-related data at the transport layer and application layer, thereby improving the efficiency and accuracy of fraud-related data management as a whole.
[0059] In some embodiments, the fraud-related information transmitted by the industry anti-fraud platform to the system interface module of the operator anti-fraud system includes multiple information fields, such as fraud-related IP addresses, risk levels, and effective ranges.
[0060] The fraud-related IP address is an Internet Protocol Version 4 (IPv4) address represented in dotted decimal notation or an Internet Protocol Version 6 (IPv6) address represented in colon-separated hexadecimal notation. The risk level can be divided into four levels: no risk, low risk, medium risk, and high risk. The effective range refers to the range in which the fraud-related IP address needs to be blocked, and can be divided into provincial, municipal, and county ranges according to national administrative regions.
[0061] For the above key fields, the business processing and presentation module constructs the business logic according to the BGP protocol features and combined with the business characteristics as follows: For the risk level of the fraud-related IP address, combined with the extended community attribute of the BGP protocol, the black hole route containing fraud-related IP addresses of different risk levels is marked with different community attribute values when introduced into the BGP routing domain, which is used for filtering by ordinary routers (backbone routers or provincial network routers) when introducing route updates.
[0062] For the effective range of the fraud-related IP address, combined with the extended community attribute of the BGP protocol, the black hole route containing fraud-related IP addresses of different effective ranges is marked with different community attribute values when introduced into the BGP routing domain, which is used for filtering by ordinary routers (backbone routers or provincial network routers) when introducing route updates.
[0063] For ordinary routers in the operator's Internet, different BGP route receiving strategies are set for ordinary routers according to the router role of ordinary routers in the network, the deployment location and the belonging area in the data forwarding path, to ensure that ordinary routers only receive black hole routes of fraud-related IP addresses that meet the local receiving strategy requirements.
[0064] For statistical analysis of fraud-related traffic, the fraud-related traffic of the fraud-related IP address is collected based on the Internet backbone network traffic analysis module or the Internet provincial network traffic analysis module, and the traffic statistics and analysis are performed, so as to dynamically adjust the risk level and the effective range of the fraud-related IP address, thereby improving the accuracy of the fraud-related IP address blocking while maintaining the low load of the network router.
[0065] For the group attribute value, a mapping table can be preset to assist in generating the group attribute value, and the mapping table includes the mapping relationship between the risk level, the effective range and the group attribute value. For example, the mapping table is shown in the following table:
[0066] The above table shows the mapping relationship between the risk level, the effective range and the group attribute value, which provides a basis for accurate execution of the routing strategy. For the risk level, a fixed autonomous domain number (such as 65000) can be used in combination with different identifiers (such as 0, 1, 2, 3) to distinguish four risk level grades. For the effective range, different autonomous domain numbers (such as 65100 representing the backbone network and 65001 representing a certain specific province) can be used to distinguish different network areas, and different identifiers can be used to mark the network level (such as core, aggregation, access) or the network area (such as province, city, county) in the area, thereby achieving fine control of the blocking range.
[0067] In some embodiments, the black hole routing directs the fraud-related traffic of the fraud-related IP address to a virtual null interface (such as the Null0 interface), thereby achieving the effect of directly discarding the data packet. In specific implementation, the black hole routing configuration command containing the fraud-related IP address needs to be issued to the black hole router in the network, and the black hole router generates the black hole routing.
[0068] To achieve flexible diffusion and fine control of the blocking strategy in the network, in this embodiment, the configured black hole routing is injected into the BGP routing domain on the black hole router, and the black hole routing is updated and diffused to the corresponding BGP routing domain through the BGP protocol.
[0069] When the black hole routing is injected into the BGP routing domain, the black hole routing can be marked by using the extended group attribute of the BGP protocol according to the risk level and the effective range of the fraud-related IP address contained in the black hole routing. The ordinary router (the backbone network router and the provincial network router) can selectively receive and load the black hole routing according to its BGP routing receiving strategy, that is, the ordinary router only receives and loads the black hole routing whose group attribute value matches the local receiving strategy. The BGP routing receiving strategy and logical judgment of a certain ordinary router are as follows: Routing receiving principle = (“risk level”) and (“effective range”).
[0070] Through the above mechanism, the embodiment realizes controllable and accurate distribution of the fraud-related IP address blocking strategy in the network, ensures that only the ordinary routers meeting the risk degree and effective range requirements will apply the corresponding black hole routing, and thus optimizes the resource overhead of the network equipment while achieving the security target.
[0071] As shown in Figure 6 FIG. 1 is a diffusion process schematic diagram of the black hole routing provided by the embodiment of the application, including the following step contents: The system interface module receives the fraud-related information issued by the industry anti-fraud platform, and sends the fraud-related information to the business processing and presentation module. The fraud-related information includes the fraud-related IP address, the risk degree and the effective range.
[0072] The business processing and presentation module maps the risk degree and the effective range to the group attribute value according to the preset mapping table, and sends the fraud-related IP address and the group attribute value to the management module of the Internet backbone network and the provincial network.
[0073] The management module of the Internet backbone network and the provincial network generates a black hole routing configuration command carrying the fraud-related IP address and the group attribute value, and sends the black hole routing configuration command to the black hole router of the backbone network and the provincial network.
[0074] The black hole router of the backbone network and the provincial network generates a black hole routing in response to the black hole routing configuration command according to the fraud-related IP address, marks the black hole routing with the group attribute value when injecting the black hole routing into the BGP routing domain, and sends the black hole routing marked with the group attribute value to the route reflector in the autonomous domain by using the BGP protocol.
[0075] The route reflector diffuses the black hole routing marked with the group attribute value to all ordinary routers in the autonomous domain.
[0076] The ordinary routers in the autonomous domain receive the black hole routing marked with the group attribute value, select whether to filter the black hole routing based on the group attribute value, detect whether the group attribute value matches the preset receiving strategy of the ordinary routers, load the black hole routing to the local routing table and update the local routing table in the case of matching, and ignore the black hole routing and do not update the local routing table in the case of not matching.
[0077] The receiving policy is based on the router role (e.g., core, aggregation, access), deployment location (e.g., backbone network, specific provincial network), and region settings of the ordinary router. The receiving policy refers to the predefined BGP route filtering rules on the ordinary router, used to define the range of community attribute values, i.e., which blackhole routes marked with community attribute values the ordinary router should receive and load. Only when the community attribute value carried by the blackhole route meets the requirements of the receiving policy will the ordinary router load the blackhole route into its local routing table; otherwise, the route update is ignored.
[0078] like Figure 7 The diagram shown illustrates the configuration process of the receiving strategy provided in this application embodiment, including the following steps: The business processing and presentation module sets a receiving policy for each ordinary router based on its router role, deployment location, and region, and then sends the receiving policy to the management modules of the Internet backbone network and provincial networks.
[0079] The management modules of the internet backbone and provincial networks translate the receiving policies into specific router configurations and distribute them to the corresponding ordinary routers. After receiving and configuring the receiving policies, ordinary routers, upon receiving a black hole route carrying a community attribute value, will match the community attribute value with the locally configured receiving policy. Only if the community attribute value falls within the range defined by the receiving policy will the black hole route be loaded into the local routing table. This mechanism ensures the accurate delivery of blocking policies and avoids unnecessary load on network devices caused by invalid routing information.
[0080] In some embodiments, to achieve continuous optimization and adaptive adjustment of the blocking strategy for fraudulent IP addresses, a complete closed loop of traffic monitoring and dynamic analysis can be established. Since blackhole routing itself does not record traffic information, target traffic can be matched and logged first using access control lists or traffic policies, and then the traffic can be redirected to a virtual empty interface. Through traffic information statistics and analysis, the access volume and scope of fraudulent IP addresses in the network can be statistically analyzed, thereby dynamically tracking and adjusting the degree of harm and effective scope of fraudulent IP addresses. After the traffic information of the blackhole routing for fraudulent IP addresses is statistically analyzed, the relevant information can be sent to the upper-layer business processing platform using proactive polling or device reporting.
[0081] In practice, the traffic mirroring function for fraudulent IP addresses can be enabled in the black hole router. By using traffic policies, a copy of the data packets pointing to the fraudulent IP address is mirrored and forwarded to the traffic analysis module of the Internet backbone network or provincial networks. The traffic analysis module performs statistical analysis on the data packets of all fraudulent IP addresses and sends the traffic statistics information of the fraudulent IP addresses to the business processing and presentation module by means of polling or active reporting.
[0082] As Figure 8 shown, a dynamic adjustment process diagram of the risk level and the effective range provided by the embodiment of the present application includes the following steps: The system interface module receives the fraud-related information issued by the industry anti-fraud platform, and sends the fraud-related information to the business processing and presentation module. The fraud-related information includes the fraud-related IP address, the risk level and the effective range.
[0083] The business processing and presentation module maps the risk level and the effective range to the group attribute value according to the preset mapping table, and sends the fraud-related IP address and the group attribute value to the management module of the Internet backbone network and the provincial network.
[0084] The management module of the Internet backbone network and the provincial network generates a black hole routing configuration command carrying the fraud-related IP address and the group attribute value, and sends the black hole routing configuration command to the black hole router of the backbone network and the provincial network.
[0085] The black hole router of the backbone network and the provincial network determines the fraud-related IP address according to the black hole routing configuration command, and when receiving the data packet of the fraud-related IP address sent by the first router, performs a mirroring operation on the data packet of the fraud-related IP address to obtain a mirror data packet, and sends the mirror data packet to the corresponding traffic analysis module.
[0086] The traffic analysis module analyzes the mirror data packet to determine the access volume and the access range of the fraud-related IP address, and sends the access volume and the access range of the fraud-related IP address to the business processing and presentation module. The access volume is the data interaction volume of the fraud-related IP address within a preset time period, and the access range is the network area and network level covered by the fraud-related IP address in the network.
[0087] The business processing and presentation module updates the risk level of the fraud-related IP address based on the access volume according to the preset update strategy, updates the effective range of the fraud-related IP address based on the access range, updates the group attribute value of the fraud-related IP address based on the updated risk level and effective range, and sends the updated group attribute value to the management module of the Internet backbone network and the provincial network.
[0088] The management module of the Internet backbone network and the provincial network sends the updated group attribute value to the black hole router of the backbone network and the provincial network, which diffuses the update, and the subsequent routing update mode can refer to the above routing update process.
[0089] That is, the black hole router receives the updated group attribute value, and sends the black hole routing and the updated group attribute value to a second router, which is a normal router in the routing domain matching the updated group attribute value. After receiving and loading the black hole routing, when a data packet of a fraud-related IP address is received, the second router can perform a discard operation on the data packet of the fraud-related IP address based on the black hole routing.
[0090] In some embodiments, for dynamic adjustment of the risk level, the business processing and presentation module can preset access volume intervals corresponding to different risk levels, and dynamically update the risk level of the fraud-related IP address according to the access volume interval in which the access volume of the fraud-related IP address is located.
[0091] For example, as shown in FIG. 6, the business processing and presentation module can set multiple thresholds for the hit frequency of the fraud-related IP address, such as t1, t2, and t3, to define different risk level intervals, i.e., a no-risk interval, a low-risk interval, a medium-risk interval, and a high-risk interval, and automatically increase or decrease the risk level of the fraud-related IP address according to the interval in which the actual hit frequency falls. Figure 9 For example, when the hit frequency of a fraud-related IP address enters the high-risk interval from the low-risk interval, the risk level of the fraud-related IP address can be upgraded from low risk to high risk.
[0092] In some embodiments, for dynamic adjustment of the access range, the traffic analysis module can analyze and process the source addresses of the mirror data packets mirrored by the black hole router, and locate the access range of the fraud-related IP address based on the IP addresses in the address library. The address library includes the correspondence between IP addresses and network regions and network levels. By matching the source addresses with the IP addresses in the address library, the network region and the network level of the source addresses are determined, and the network region and the network level of all source addresses are summarized to obtain the access range of the fraud-related IP address.
[0093] The business processing and presentation module can dynamically update the effective range of the fraud-related IP address according to a preset scheme. The preset scheme can adopt the principle of upward aggregation, i.e., when fraud-related traffic of a fraud-related IP address is detected in multiple subordinate regions, the effective range is expanded to the common superior region of the subordinate regions, i.e., when fraud-related traffic is detected in multiple counties, the effective range is adjusted to the city level; when fraud-related traffic is detected in multiple cities, the effective range is adjusted to the provincial level; and when fraud-related traffic is detected in multiple provinces, the effective range is adjusted to the national level (backbone network). Conversely, the principle of downward refinement can also be adopted to narrow the effective range to optimize network resources.
[0094] For example, based on the dynamic adjustment mechanism of the risk level and the effective range of the above-mentioned suspicious IP address, for a suspicious IP address, combined with the mapping table of the group attribute value as shown in Figure 10 The suspicious information sent by the industry anti-fraud platform defines the risk level of the suspicious IP address as medium risk and the effective range as province 1 city 1. According to the mapping table of the group attribute value, the group attribute value is allocated as 65000:2, 65001:1002.
[0095] After the traffic analysis module performs traffic analysis and statistics, it is found that the hit frequency of the suspicious IP address is in the high risk interval, and no suspicious traffic of the suspicious IP address is found in other cities. According to the preset rule, the risk level is increased from medium risk to high risk, and the group attribute value is dynamically adjusted to 65000:3, 65001:1002.
[0096] After the traffic analysis module performs traffic analysis and statistics again, it is found that the hit frequency of the suspicious IP address is in the high risk interval, and suspicious traffic of the suspicious IP address is found in other cities at the same time. According to the upward collection principle, the effective range is dynamically adjusted to province 1, and the group attribute is dynamically adjusted to 65000:3, 65001:1.
[0097] The system pushes the above-mentioned adjustment of the group attribute value to the corresponding black hole router through the management module of the Internet backbone network or the provincial network, and diffuses it to the BGP routing domain by the black hole router, to realize the dynamic adjustment of the blocking range. By dynamically adjusting the risk level and the effective range of the suspicious IP address, the efficiency and accuracy of blocking the suspicious IP address are improved. At the same time, the risk level and the effective range of the adjusted suspicious IP address can be reported to the industry anti-fraud platform through the system interface module.
[0098] In the above-mentioned embodiment, the system interface module, the business processing and presentation module, the management module of the Internet backbone network and the provincial network, the traffic analysis module of the Internet backbone network and the provincial network, the black hole router of the Internet backbone network and the provincial network, etc. System or device, interface industry anti-fraud platform, block suspicious IP data from network layer through black hole routing, without the need to identify suspicious IP address, protocol port, suspicious data in transmission layer and application layer, completely solve the problem of suspicious data transmission, improve the efficiency and accuracy of suspicious data processing as a whole.
[0099] At the same time, based on the statistical analysis of the access volume and access range of the suspicious IP address, the risk level and the effective range of the suspicious IP address are dynamically adjusted, which can effectively improve the blocking efficiency and accuracy of the suspicious IP address, and reduce the business processing load of the router.
[0100] In this embodiment, for the DPI series mode and the DPI parallel mode, the fraud-related IP data blocking method based on the black hole routing can eliminate the problems of incomplete protocol support, invalid processing of encrypted traffic, and rough control means of the existing DPI technology. For TCP protocol, UDP protocol and other transport layer protocols, comprehensive and effective processing of fraud-related IP data can be achieved. For different dangerous levels (levels) and effective ranges of fraud-related IP addresses pushed by the industry anti-fraud platform, the blocking range of the fraud-related IP addresses can be dynamically adjusted by combining the access data of the local statistics of the fraud-related IP addresses of the operator, so as to meet the blocking requirements of the fraud-related IP addresses, take into account the number of router routing entries, reduce the load of the router, and improve the data forwarding efficiency.
[0101] In the technical solution of the present application, the black hole routing can block the fraud-related IP data from the network layer, improve the efficiency and accuracy of fraud-related data management, and thus better protect the sensitive data and property safety of customers and maintain a good corporate image. The preventive maintenance and effective access control of network security can also be based on the scheme of the present application to avoid data leakage and property loss caused by internal customer access to bad or fraud-related websites, reduce the corresponding security recovery and maintenance rectification costs, and effectively block fraud-related IP data to reduce the demand for security emergency response, thereby reducing the workload and cost of the security emergency response team and improving the quality and efficiency of network security protection.
[0102] According to the embodiments of the present disclosure, the present disclosure also provides a network security protection system. The network security protection system includes a routing domain established by one or more autonomous domains based on a BGP protocol, and the autonomous domain includes a black hole router and a normal router.
[0103] The black hole router is configured to receive a fraud-related IP address and a group attribute value, generate a black hole routing according to the fraud-related IP address, and send the black hole routing and the group attribute value to a first router.
[0104] The group attribute value is used to represent the dangerous level and the effective range of the fraud-related IP address, and the first router is a normal router in the routing domain that matches the group attribute value.
[0105] The first router is configured to perform a discard operation on a data packet of the fraud-related IP address based on the black hole routing when receiving the data packet of the fraud-related IP address.
[0106] In some embodiments, the autonomous domain further includes a processing module in communication connection with the black hole router. The processing module is configured to receive fraud-related information, the fraud-related information including a fraud-related IP address, a dangerous level and an effective range, map the dangerous level and the effective range to a group attribute value according to a preset mapping table, and send the fraud-related IP address and the group attribute value to the black hole router.
[0107] The mapping table includes a mapping relationship between the risk degree, the effective range and the community attribute value. The community attribute value is an attribute field used for marking a route in a BGP protocol.
[0108] In some embodiments, the processing module is in communication connection with the industry anti-fraud platform. The processing module is configured to receive anti-fraud information issued by the industry anti-fraud platform.
[0109] In some embodiments, the autonomous domain further includes a route reflector, and the black hole router is in communication connection with the route reflector based on a BGP protocol.
[0110] The black hole router is configured to mark a community attribute value for the black hole route, and send the black hole route marked with the community attribute value to the route reflector.
[0111] The route reflector is configured to send the black hole route marked with the community attribute value to a common router in the autonomous domain.
[0112] In some embodiments, the processing module is in communication connection with the common router. The processing module is configured to send a receiving strategy to the common router, the receiving strategy being based on a router role, a deployment position and a belonging region of the common router.
[0113] In some embodiments, the common router is configured to receive the black hole route marked with the community attribute value, detect whether the community attribute value matches a preset receiving strategy, and load the black hole route to a local routing table in a case where the community attribute value matches the preset receiving strategy.
[0114] In some embodiments, the black hole router is configured to perform a mirroring operation on a data packet of a fraudulent IP address to obtain a mirrored data packet when the data packet of the fraudulent IP address is received, and send the mirrored data packet to the processing module.
[0115] The processing module is configured to determine an access amount and an access range of the fraudulent IP address according to the mirrored data packet, update the risk degree based on the access amount, update the effective range based on the access range, and update the community attribute value based on the updated risk degree and the effective range.
[0116] The access amount is an amount of data interaction of the fraudulent IP address within a preset time period. The access range is a network region and a network level covered by the fraudulent IP address in a network.
[0117] In some embodiments, the processing module is configured to determine preset access amount intervals corresponding to different risk degrees, and update the risk degree of the fraudulent IP address according to an access amount interval in which the access amount is located.
[0118] In some embodiments, the processing module is configured to detect a source address of the mirror data packet, match the source address with IP addresses in the address library, determine a network region and a network level of the source address, aggregate the network region and the network level of the source address, and obtain an access range of the fraud-related IP address.
[0119] The address library comprises a corresponding relationship between the IP address and the network region and the network level.
[0120] In some embodiments, the black hole router is configured to receive the updated community attribute value, and send the black hole routing and the updated community attribute value to a second router. The second router is a normal router in the routing domain that matches the updated community attribute value.
[0121] The second router is configured to, when receiving the data packet of the fraud-related IP address, perform a discard operation on the data packet of the fraud-related IP address based on the black hole routing.
[0122] Various implementations of the systems and techniques described above can be realized in digital electronic circuitry, integrated circuitry, a Field Programmable Gate Array (FPGA), an Application-Specific Integrated Circuit (ASIC), an Application Specific Standard Product (ASSP), a System on a Chip (SOC), a Complex Programmable Logic Device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0123] Program code for carrying out methods of the present disclosure can be written in any combination of one or more programming languages. The program code can be provided to a processor or controller of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the program code, when executed by the processor or controller, produces the functions / operations specified in the flowcharts and / or block diagrams. The program code can be executed entirely on a machine, partially on a machine, partially on a machine as a stand-alone software package, partially on a machine and partially on a remote machine or entirely on a remote machine or server.
[0124] In the context of the present disclosure, a machine-readable medium can be a tangible medium that contains or stores a program for use by or in connection with an instruction execution system, apparatus, or device. The machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include but is not limited to an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium would include one or more lines of electrical wire, portable computer diskette, hard disk, RAM, ROM, EPROM (Erasable Programmable Read-Only-Memory) or flash memory, fiber optics, CD-ROM (Compact Disc Read-Only Memory), optical storage device, magnetic storage device, or any suitable combination of the foregoing.
[0125] To provide for interaction with a user, the systems and techniques described here can be implemented on a computer having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0126] The systems and techniques described here can be implemented in a computing system that includes a back end component, e.g., as a data server, or that includes a middleware component, e.g., an application server, or that includes a front end component, e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here, or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication, e.g., a communication network. Examples of communication networks include a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, and a blockchain network.
[0127] The computer system can include clients and servers. The clients and servers are generally remote from each other and typically interact through a communication network. The relationship of client and server is one of communication and distribution, with the server receiving requests from the client and transmitting responses via the communication network. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service ("Virtual Private Server", or simply "VPS"). The server can also be a server of a distributed system, or a server combined with a blockchain.
[0128] It should be noted that artificial intelligence is a discipline that studies enabling computers to simulate some thinking processes and intelligent behaviors of people (such as learning, reasoning, thinking, planning, etc.), both hardware and software technologies. Artificial intelligence hardware technology generally includes technologies such as sensors, special artificial intelligence chips, cloud computing, distributed storage, big data processing, etc.; artificial intelligence software technology mainly includes computer vision technology, speech recognition technology, natural language processing technology, and machine learning / deep learning, big data processing technology, knowledge graph technology, etc. several major directions.
[0129] It should be understood that the various forms of flow shown above can be used to reorder, add or delete steps. For example, each step described in the present disclosure can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions disclosed in the present disclosure can be achieved, which is not limited herein.
[0130] The above detailed description does not limit the scope of the disclosure. Various modifications, combinations, sub-combinations and alternatives can be made to the detailed description. Any modification, equivalent replacement and improvement etc. made within the spirit and principle of the disclosure shall be included in the scope of the disclosure.
Claims
1. A network security protection method, characterized in that, The method is applied to a network security protection system; the network security protection system includes a routing domain; the routing domain is established by one or more autonomous systems based on the Border Gateway Protocol; the autonomous system includes black hole routers and ordinary routers; the method includes: The black hole router receives the fraudulent IP address and the group attribute value; the group attribute value is used to indicate the degree of danger and scope of effectiveness of the fraudulent IP address. The black hole router generates a black hole route based on the fraudulent IP address and sends the black hole route and the community attribute value to the first router, so as to discard data packets of the fraudulent IP address flowing through the first router based on the black hole route; the first router is an ordinary router in the routing domain that matches the community attribute value.
2. The method according to claim 1, characterized in that, The autonomous system further includes a processing module; the processing module is communicatively connected to the black hole router, and the method further includes: The processing module receives fraud-related information; the fraud-related information includes the fraudulent IP address, the level of danger, and the scope of effectiveness. The processing module maps the degree of danger and the scope of effectiveness to the group attribute value according to a preset mapping table, and sends the fraudulent IP address and the group attribute value to the black hole router. The mapping table includes the mapping relationship between the degree of danger, the scope of effectiveness, and the community attribute value; the community attribute value is an attribute field used to mark routes in the border gateway protocol.
3. The method according to claim 2, characterized in that, The processing module is communicatively connected to the industry's anti-fraud platform; the method further includes: The processing module receives the fraud-related information issued by the industry anti-fraud platform.
4. The method according to claim 1 or 2, characterized in that, The autonomous domain further includes a route reflector; the black hole router establishes a communication connection with the route reflector based on the border gateway protocol; the method further includes: The black hole router marks the black hole route with the community attribute value, and sends the black hole route marked with the community attribute value to the route reflector; The route reflector sends the black hole route, marked with the community attribute value, to the regular routers within the autonomous system.
5. The method according to claim 4, characterized in that, The processing module is communicatively connected to the ordinary router; the method further includes: The processing module sends the receiving policy to the ordinary router; the receiving policy is based on the ordinary router's router role, deployment location, and region settings; The ordinary router receives the black hole route marked with the community attribute value, checks whether the community attribute value matches the receiving policy, and if they match, loads the black hole route into the local routing table.
6. The method according to claim 2, characterized in that, The method further includes: When the black hole router receives a data packet from the first router containing the fraudulent IP address, it performs a mirroring operation on the data packet containing the fraudulent IP address to obtain a mirrored data packet, and then sends the mirrored data packet to the processing module. The processing module determines the access volume and access range of the fraudulent IP address based on the mirrored data packet, updates the danger level based on the access volume, updates the effective range based on the access range, and updates the group attribute value based on the updated danger level and effective range. The access volume refers to the amount of data interaction of the fraudulent IP address within a preset time period; the access range refers to the network area and network layer covered by the fraudulent IP address in the network.
7. The method according to claim 6, characterized in that, The processing module updates the danger level based on the access volume; including: Determine preset access volume ranges corresponding to different levels of risk; The risk level of the suspected fraudulent IP address is updated based on the access volume range it falls within.
8. The method according to claim 6, characterized in that, The processing module determines the access range of the fraudulent IP address based on the mirrored data packet; including: Detect the source address of the image data packet; The source address is matched with IP addresses in the address database to determine the network region and network layer of the source address; the address database includes the correspondence between IP addresses and network regions and network layers. By summarizing the network regions and network layers of the source addresses, the access range of the fraudulent IP addresses can be obtained.
9. The method according to claim 6, characterized in that, The method further includes: The black hole router receives the updated community attribute value and sends the black hole route and the updated community attribute value to the second router; the second router is a regular router in the routing domain that matches the updated community attribute value; When the second router receives a data packet from the fraudulent IP address, it discards the data packet from the fraudulent IP address based on the black hole routing.
10. A network security protection system, characterized in that, The network security protection system includes a routing domain; the routing domain is established by one or more autonomous domains based on the Border Gateway Protocol; the autonomous domain includes black hole routers and ordinary routers; The black hole router is used to receive fraudulent IP addresses and group attribute values; Based on the suspected fraudulent IP address, a black hole route is generated, and the black hole route and the community attribute value are sent to the first router to discard data packets of the suspected fraudulent IP address flowing through the first router based on the black hole route; the community attribute value is used to indicate the degree of danger and scope of the suspected fraudulent IP address; the first router is an ordinary router in the routing domain that matches the community attribute value.
Citation Information
Patent Citations
Attack traffic protection system, method and device, electronic equipment and storage medium
CN111294365A
Cross-domain black hole route centralized management and control method and device
CN114124802A
Network defense method and device, equipment, storage medium and computer program product
CN120415875A
Distributed denial-of-service attack mitigation by selective black-holing in IP networks
US20060031575A1