Method and device for processing attack traffic

By constructing a network topology graph and utilizing graph attention networks to select paths, traffic is guided, cleaned, and reinjected, solving the service unavailability problem caused by DDoS attacks and achieving a highly efficient protection effect.

CN121509035APending Publication Date: 2026-02-10CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511791247.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-01
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing technologies lack effective protection against distributed denial-of-service (DDoS) attacks, resulting in target servers experiencing bandwidth saturation, slow response times, or unreachability.

Method used

A network topology graph is constructed, and traffic paths are determined through graph attention networks. Attack traffic is directed to cleaning devices for cleaning and then injected back to the target devices. Path selection is performed by combining node and edge features to achieve reachability, latency and stability from a global perspective.

Benefits of technology

From a global perspective, it balances reachability, latency, and stability, eliminates malicious packets, mitigates DDoS attacks, reduces end-to-end latency and packet loss risks, and improves service availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509035A_ABST
    Figure CN121509035A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a device for processing attack traffic, relates to the field of network security, and is used for protecting DDoS (Distributed Denial of Service) attacks. The method comprises the following steps: constructing a network topological graph from a first device as an attacker to a second device; nodes in the network topological graph represent any device from the first device to the second device, and edges in the network topological graph represent link connection relations between the devices; determining a flow path from the first device to the second device based on the node feature of each node and the edge feature of each edge in the network topological graph; the flow path is reinjected to the second equipment after the attack flow is cleaned by the third equipment in the network topological graph. Through the scheme, DDoS attacks can be protected.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security, and more particularly to a method and apparatus for processing attack traffic. Background Technology

[0002] Distributed Denial of Service (DDoS) is a type of network attack in which attackers control a large number of infected devices (such as botnets) and simultaneously launch massive requests or traffic towards a target server, network, or application, overwhelming bandwidth, connection limits, or processing resources, making it impossible for legitimate users to access the service or resulting in extremely slow access. Typical signs include a sudden slowdown or timeout in access, a spike in server load, abnormal bandwidth saturation, and requests in logs that are highly similar or originate from abnormally distributed IP addresses. Currently, there is a lack of protection against DDoS attacks.

[0003] Therefore, how to protect against DDoS attacks is an urgent problem that needs to be solved. Summary of the Invention

[0004] This invention provides a method and apparatus for processing attack traffic, used to protect against DDoS attacks.

[0005] In a first aspect, the present invention provides a method for processing attack traffic, the method comprising: constructing a network topology graph between a first device and a second device, which are the targets of the attack; nodes in the network topology graph represent any device from the first device to the second device, and edges in the network topology graph represent the link connection relationship between devices; determining a traffic path from the first device to the second device based on the node characteristics of each node and the edge characteristics of each edge in the network topology graph; the traffic path is to back-inject the attack traffic to the second device after cleaning it through a third device in the network topology graph.

[0006] The above scheme constructs a network topology map between the first and second devices (the targets of the attack) and represents any device along the path and its link connections in the form of "node-edges." This maps the originally dispersed network state into a computable global view, making path selection interpretable. Furthermore, attack traffic is diverted to a third device for cleaning before reaching the second device and then returned to the service side (the second device) along the injection link. This approach balances reachability, latency, and stability from a global perspective, promptly eliminating malicious packets and mitigating instantaneous impacts, thus providing protection against DDoS attacks.

[0007] Optionally, based on the node features of each node and the edge features of each edge in the network topology graph, the traffic path from the first device to the second device is determined, including: processing the node features of each node and the edge features of each edge in the network topology graph through a graph attention network to determine the attention weights between adjacent nodes from the first device to the second device; and determining the traffic path from the first device to the second device based on each attention weight.

[0008] The above scheme processes node and edge features in the network topology using a graph attention network, and quantifies the importance and reliability of paths using attention weights, thereby selecting traffic paths from the network topology. Compared to path selection methods that rely on fixed thresholds or single indicators, this invention can consider multiple factors such as bandwidth, load, latency, and stability, suppressing the interference of noise and local anomalies on decision-making, thus forming interpretable differentiated scores among candidate paths. Based on this, determining the target traffic path according to attention weights can prioritize the selection of high-quality links and nodes with processing advantages, making the path more consistent with the dynamic changes in the current network state, reducing the risk of end-to-end latency and packet loss caused by congestion and jitter, enhancing the resistance to abnormal traffic impacts, and improving overall service availability.

[0009] Optionally, the traffic path includes a traction path from the first device to the third device and a backflow path from the third device to the second device; through a graph attention network, the node features of each node and the edge features of each edge in the network topology graph are processed to determine the attention weights between adjacent nodes from the first device to the second device, including: determining any first path from the first device to the third device and / or any second path from the third device to the second device; through the graph attention network, the attention weights between adjacent nodes on the path are determined by the first node features and first edge features in the first path, and / or the second node features and second edge features in the second path.

[0010] By using the above scheme, the accuracy and robustness of path scoring can be significantly improved by dividing the traffic path into traction paths and injection paths, and by using a graph attention network to calculate the attention weights between adjacent nodes within the path at the granularity of the candidate first path and / or second path.

[0011] Optionally, the first node features and first edge features used in determining the traction path are not exactly the same as the node features and edge features used in determining the back injection path.

[0012] By employing different node and edge characteristics in the torrent and injection paths, the above approach allows for customized characterization of objectives and risk constraints at different stages, thereby improving the discriminative power and stage fit of path evaluation. In the torrent phase, focusing on sensitive factors reflecting the convergence and spread of attack flows (such as ingress bandwidth usage, abnormal connection rates, historical malicious traffic markings, and immediate edge congestion and packet loss) can more accurately suppress high-risk links and prioritize routing to nodes with better cleaning capabilities. In the injection phase, incorporating more business continuity-related factors (such as stability scores, end-to-end latency contribution, consistency with the original business route, and queuing risks caused by node ingress and egress degrees) can reduce jitter and retransmission probabilities during injection, improving the stability and timeliness of service recovery.

[0013] Optionally, the first node features include at least one of computing resources, remaining bandwidth, and current load; the first side features and / or the second side features include at least one of transmission delay, link utilization, and historical stability; the second node features include at least one of central processing unit (CPU) utilization, average forwarding delay, and whether malicious traffic has been forwarded.

[0014] By employing the above scheme, differentiating indicators that reflect the phase objectives in both the towing and injection phases make path evaluation more closely aligned with actual network conditions and improve discriminative power and stability. In the towing phase, computing resources, remaining bandwidth, and current load are used as the first node characteristics. This reflects the processing capacity and instantaneous availability of each node in handling attack traffic redirection, avoiding the inclusion of nodes with high loads or insufficient resources in the main towing path, thereby reducing congestion and packet loss risks. Transmission delay, link utilization, and historical stability are used as side characteristics to effectively measure the latency contribution and congestion trend of links, prioritizing links with low latency, low occupancy, and high historical stability, shortening end-to-end towing latency and improving path availability. In the injection phase, the second node characteristics are set as CPU utilization, average forwarding delay, and whether malicious traffic has been forwarded. This avoids nodes with high CPU utilization and high queuing latency when services recover, reducing injection jitter and retransmission probability. Simultaneously, based on the security indicator of "whether malicious traffic has been forwarded," potentially high-risk nodes are avoided, reducing the possibility of the injection path being interfered with again.

[0015] Optionally, the network topology diagram includes multiple cleaning devices; based on each attention weight, the traffic path from the first device to the second device is determined, including: based on the attention weight between adjacent nodes on each first path, the operating status of each cleaning device and the distance from the first device to the cleaning device, the third device in the traction path is determined from the multiple cleaning devices, thereby obtaining the traction path.

[0016] The above solutions prioritize the matching of cleaning equipment with more abundant resources, more suitable distances, and higher historical stability, thereby achieving adaptive load balancing, reducing overload at individual cleaning points, and improving throughput and steady-state performance.

[0017] Optionally, after determining the traffic path from the first device to the second device, the method further includes: obtaining the transmission effect of the attack traffic after it has been transmitted through the traffic path; adjusting the graph attention network based on the transmission effect, or switching the traffic path.

[0018] With the above approach, path selection and model parameters are no longer one-time static decisions, but can be adaptively optimized according to changes in the attack situation and network status.

[0019] In a second aspect, the present invention provides an apparatus for processing attack traffic, the apparatus comprising: The construction module is used to build a network topology graph between the first device and the second device, which are the targets of the attack. Nodes in the network topology graph represent any device from the first device to the second device, and edges in the network topology graph represent the link connections between devices. The determination module is used to determine the traffic path from the first device to the second device based on the node characteristics of each node and the edge characteristics of each edge in the network topology diagram; the traffic path is to clean the attack traffic through the third device in the network topology diagram and then inject it back into the second device.

[0020] In one possible implementation, the determination module is specifically used to: process the node features of each node and the edge features of each edge in the network topology graph through a graph attention network to determine the attention weights between adjacent nodes from the first device to the second device; and determine the traffic path from the first device to the second device based on each attention weight.

[0021] In one possible implementation, the traffic path includes a traction path from the first device to the third device and a reinjection path from the third device to the second device; the determination module is specifically used to: determine any first path from the first device to the third device and / or any second path from the third device to the second device; and through a graph attention network, determine the attention weights between adjacent nodes on the path based on the features of each first node and each first edge in the first path, and / or the features of each second node and each second edge in the second path.

[0022] In one possible implementation, the first node features and first edge features used to determine the traction path are not exactly the same as the node features and edge features used to determine the back injection path.

[0023] In one possible implementation, the first node features include at least one of computing resources, remaining bandwidth, and current load; the first side features and / or the second side features include at least one of transmission delay, link utilization, and historical stability; and the second node features include at least one of central processing unit (CPU) utilization, average forwarding delay, and whether malicious traffic has been forwarded.

[0024] In one possible implementation, the network topology graph includes multiple cleaning devices; the determining module is specifically used to: determine the third device in the traction path from the multiple cleaning devices based on the attention weights between adjacent nodes on each first path, the operating status of each cleaning device, and the distance from the first device to the cleaning device, thereby obtaining the traction path.

[0025] In one possible implementation, the determining module is also used to: obtain the transmission effect of the attack traffic after it has been transmitted through the traffic path; adjust the graph attention network based on the transmission effect, or switch the traffic path.

[0026] Thirdly, the present invention also provides an apparatus for processing attack traffic, the apparatus including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the method described in various possible designs of the first aspect.

[0027] Fourthly, the present invention also provides a computer-readable storage medium storing a computer program or instructions that, when executed by a processor, implement the method described in various possible designs of the first aspect.

[0028] Fifthly, the present invention also provides a computer program product that, when run on a computer, causes the computer to perform any of the methods described in the first aspect above.

[0029] These or other implementations of this application will become clearer and easier to understand in the following description of the embodiments. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0031] Figure 1 A schematic diagram illustrating an application scenario provided by an embodiment of the present invention; Figure 2A schematic diagram illustrating another application scenario provided by an embodiment of the present invention; Figure 3 A flowchart illustrating a method for processing attack traffic provided in an embodiment of the present invention; Figure 4 A flowchart illustrating another method for processing attack traffic provided in an embodiment of the present invention; Figure 5 A flowchart illustrating another method for processing attack traffic provided in an embodiment of the present invention; Figure 6 A schematic diagram of a network topology provided for an embodiment of the present invention; Figure 7 A schematic diagram of a device for processing attack traffic provided in an embodiment of the present invention; Figure 8 This is a schematic diagram of another device for processing attack traffic provided in an embodiment of the present invention. Detailed Implementation

[0032] To make the objectives, technical solutions, and beneficial effects of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0033] In this application, "at least one" means one or more, and "more than one" means two or more. "And / or" describes the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. " / " represents an OR relationship between the two.

[0034] The following provides explanations for some of the terms used in this application. It should be noted that these explanations are for the convenience of those skilled in the art and do not constitute a limitation on the scope of protection claimed in this application.

[0035] I. Traction.

[0036] "Traffic redirection" involves diverting identified attack traffic from its original path directly to the business, directing it to nodes or scrubbing centers with protection and processing capabilities. Common practices include BGP-based traffic redirection, DNS traffic scheduling, and Anycast / CDN redirection, with the aim of preventing malicious traffic from directly overwhelming the origin server.

[0037] II. Cleaning.

[0038] "Scrubbing" involves identifying and filtering the mixed traffic that has been redirected, discarding or rate-limiting attack packets, and allowing normal business traffic to flow. It typically combines multi-layered detection strategies and equipment, such as traffic feature matching, behavior / rate thresholds, protocol integrity verification, challenge verification, fingerprinting, and machine learning models, to maximize the elimination of malicious traffic without affecting genuine users.

[0039] III. Back betting.

[0040] "Re-injection" involves sending the cleaned traffic back to the nearest network ingress or origin link for the service, restoring service availability and minimizing latency. Common methods include establishing a reliable re-injection channel or dedicated line between the cleaning center and the service side, or using the Border Gateway Protocol (BGP) to redirect the clean traffic back to the target autonomous system and data center. The key to re-injection is path stability, controllable latency, and preventing the clean traffic from mixing with dirty traffic again.

[0041] With the rapid development of internet and IoT technologies, IoT devices are rapidly becoming widespread across various industries, and the growth rate of these devices is accelerating. Due to the increasing variety of internet services and application scenarios, IoT devices have different requirements in different scenarios. These devices are limited in terms of size, capacity, processing power, and manufacturing costs. Consequently, manufacturers often have to invest limited resources in the essential functions of the devices during production, rarely considering their cybersecurity attributes. This undoubtedly makes it easier for hackers to exploit these vulnerable and easily controlled IoT devices as botnets to launch DDoS attacks, turning the IoT into a carrier of DDoS attacks.

[0042] In large-scale internet service environments, DDoS attacks often generate sudden and massive abnormal traffic to target services through controlled botnets, consuming bandwidth and connection resources and causing service response to slow down significantly or become unreachable. To ensure business continuity, a closed-loop protection architecture of "traction-cleaning-reinjection" is typically constructed: First, suspicious traffic is tractioned based on mechanisms such as BGP, Domain Name System (DNS) scheduling, or Anycast and Content Delivery Network (CDN) to a cleaning center with processing capabilities; then, the cleaning center uses a combination of methods such as feature matching, behavioral thresholds, protocol consistency verification, and machine learning identification to remove malicious traffic and allow normal access; finally, the cleaned business traffic is stably injected back to the origin server or business entry point through the nearest link or dedicated line to restore service availability and minimize latency.

[0043] Please see Figure 1This diagram illustrates an application scenario. The left side shows the attack control center, where attackers use a controlled botnet to drive a large number of distributed terminals to generate abnormal requests or data packets, forming a DDoS attack flow directed towards the business side. The right side shows network devices deployed on the cloud or backbone side. These network devices are interconnected via dedicated links to form a highly available topology. The network devices include a scrubbing cluster, which contains multiple scrubbing nodes used to receive redirected suspicious traffic, perform feature identification and filtering, and output purified business flows. As mentioned in the background section, there is currently a lack of protection against DDoS attacks; therefore, how to protect against DDoS attacks is an urgent problem to be solved.

[0044] Based on this, the present invention provides a method for processing attack traffic, which coordinates the diversion, cleaning and reinjection of suspicious traffic by constructing a network topology graph.

[0045] The following is a detailed description of the proposed solution in conjunction with the accompanying drawings.

[0046] Please see Figure 2 This diagram illustrates another application scenario. It includes multiple attack source nodes (represented by "Attack Node 1," "Attack Node 2," and "Attack Node 3" as examples). These distributed nodes initiate large-volume requests to the service side, which includes the victim server (e.g., the target service entry point). Before reaching the service side, the victim traffic is diverted by the network side to the cleaning infrastructure (represented by "Cleansing Center 1" and "Cleansing Center 2" as examples).

[0047] Optionally, the cleaning centers are interconnected via links to achieve traffic sharing and redundancy switching. Traffic from different attack nodes can be imported into any cleaning center for identification and filtering, either individually or simultaneously. The cleaned business flow then flows back to the business entry point along the arrow pointing to the victim server, completing the "traction-cleaning-backflow" closed loop, thereby maintaining the availability and latency controllable of the target service in multi-source attack scenarios.

[0048] Please see Figure 3 The diagram illustrates a process for handling attack traffic, which includes the following steps: Step 310: Construct a network topology diagram between the first and second devices, which are the targets of the attack.

[0049] Here, the nodes in the network topology diagram represent any device from the first device to the second device, including but not limited to border routers, switches, scrubbing centers, etc., and the edges in the network topology diagram represent the link connections between devices.

[0050] For example, in one example, the current network is modeled as a graph network topology with attributes. , where the set of nodes An edge set represents a network of forwarding devices, routers, or edge gateways. This indicates the link connection relationship between them.

[0051] Step 320: Based on the node characteristics of each node and the edge characteristics of each edge in the network topology graph, determine the traffic path from the first device to the second device.

[0052] Specifically, the "traffic path" refers to the end-to-end transmission link from the first device, where suspicious or attack traffic is processed by the third device in the network topology diagram, and the purified traffic is then injected back to the second device.

[0053] Specifically, based on the network topology diagram from step 310, the node characteristics of each node and the edge characteristics of each edge are comprehensively measured to determine the target traffic path from the first device to the second device. Node characteristics may include remaining bandwidth, current load, computing resources, historical stability, latency, etc.; edge characteristics may include link bandwidth, latency, packet loss rate, jitter, and historical availability, etc. After evaluating the above characteristics, a path that meets the requirements for torrenting and processing is selected, so that the attack traffic from the direction of the first device is cleaned by the third device (e.g., a scrubbing center) in the network topology diagram, and the cleaned traffic is injected back to the second device along the path, thereby reducing end-to-end latency and improving path reliability while ensuring availability.

[0054] Optionally, based on the current network status and node / link characteristics, one or more optimal traffic paths can be selected from multiple possible paths to guide DDoS attack traffic to appropriate network nodes (such as scrubbing centers) to minimize the load pressure on the core network and victim servers.

[0055] Optionally, the third device can be a cleaning device, operating in a "traction-cleaning-reinjection" sequence. Specifically, traction is used to direct suspicious traffic from the direction of the first device to the third device according to routing or scheduling policies; cleaning is used within the third device to perform feature identification, protocol consistency verification, and rate control on the traffic to eliminate malicious packets and allow normal packets; reinjection is used to stably deliver the cleaned traffic to the second device through a selected reinjection link. Thus, the target "traffic path" not only covers the traction segment from the first device to the third device and the processing within the third device, but also includes the reinjection segment from the third device back to the second device, ensuring that end-to-end latency and abnormal interference are reduced while maintaining service availability.

[0056] The above scheme constructs a network topology map between the first and second devices (the targets of the attack) and represents any device along the path and its link connections in the form of "node-edges." This maps the originally dispersed network state into a computable global view, making path selection interpretable. Furthermore, attack traffic is diverted to a third device for cleaning before reaching the second device and then returned to the service side (the second device) along the injection link. This approach balances reachability, latency, and stability from a global perspective, promptly eliminating malicious packets and mitigating instantaneous impacts, thus providing protection against DDoS attacks.

[0057] Optionally, in step 320 above, the traffic path can be determined based on a graph attention mechanism. Specifically, step 320 includes: processing the node features of each node and the edge features of each edge in the network topology graph through a graph attention network to determine the attention weights between adjacent nodes from the first device to the second device; and determining the traffic path from the first device to the second device based on each attention weight.

[0058] For example, in one instance, adjacency encoding can be performed on the network topology graph. The node features of each node and the edge features of each edge are then input into a graph attention network for fusion calculation to obtain the attention weight of any pair of adjacent nodes on the path from the first device to the second device. This attention weight is used to measure the importance and reliability of adjacent nodes and their connecting edges during the traction and re-injection process. Based on the obtained attention weights, and combined with constraints such as cleaning capability, link latency, and stability, candidate paths are cumulatively scored and constrained for selection to determine the target traffic path from the first device to the second device.

[0059] Furthermore, optionally, to avoid the influence of noise, the attention weights can be normalized and multi-head attention can be used to improve robustness; when there are multiple paths with similar scores, the path with better cleaning ability and higher quality back-injection link can be selected as the target path.

[0060] The above scheme processes node and edge features in the network topology using a graph attention network, and quantifies the importance and reliability of paths using attention weights, thereby selecting traffic paths from the network topology. Compared to path selection methods that rely on fixed thresholds or single indicators, this invention can consider multiple factors such as bandwidth, load, latency, and stability, suppressing the interference of noise and local anomalies on decision-making, thus forming interpretable differentiated scores among candidate paths. Based on this, determining the target traffic path according to attention weights can prioritize the selection of high-quality links and nodes with processing advantages, making the path more consistent with the dynamic changes in the current network state, reducing the risk of end-to-end latency and packet loss caused by congestion and jitter, enhancing the resistance to abnormal traffic impacts, and improving overall service availability.

[0061] Further, optionally, the flow path includes a traction path from the first device to the third device and a reinjection path from the third device to the second device. Step 320 above includes: determining any first path from the first device to the third device and / or any second path from the third device to the second device; and using a graph attention network, determining the attention weights between adjacent nodes on the path based on the features of each first node and each first edge in the first path, and / or the features of each second node and each second edge in the second path.

[0062] Specifically, traffic paths include "traction paths" and "reinjection paths". A "traction path" refers to any routing sequence from the first device to the third device, and a "reinjection path" refers to any routing sequence from the third device to the second device.

[0063] By using the above scheme, the accuracy and robustness of path scoring can be significantly improved by dividing the traffic path into traction paths and injection paths, and by using a graph attention network to calculate the attention weights between adjacent nodes within the path at the granularity of the candidate first path and / or second path.

[0064] Furthermore, optionally, the first node features and first edge features used when determining the traction path are not entirely the same as those used when determining the injection path. Thus, by employing different node and edge features in the traction and injection path stages, customized characterization of objectives and risk constraints at different stages can be achieved, improving the discriminative power and stage fit of path evaluation. In the traction stage, focusing on sensitive elements reflecting the convergence and diffusion of attack flows (such as ingress bandwidth usage, abnormal connection rates, historical malicious traffic markings, and immediate edge congestion and packet loss) can more accurately suppress high-risk links and prioritize guiding traffic to nodes with better cleaning capabilities. In the injection stage, incorporating more business continuity-related elements (such as stability scores, end-to-end latency contribution, consistency with the original business route, and queuing risks caused by node ingress and egress degrees) can reduce jitter and retransmission probabilities during injection, improving the stability and timeliness of service recovery.

[0065] Optionally, the first node features include at least one of computing resources, remaining bandwidth, and current load; the first side features and / or the second side features include at least one of transmission delay, link utilization, and historical stability; the second node features include at least one of CPU utilization, average forwarding delay, and whether malicious traffic has been forwarded.

[0066] By employing the above scheme, differentiating indicators that reflect the phase objectives in both the towing and injection phases make path evaluation more closely aligned with actual network conditions and improve discriminative power and stability. In the towing phase, computing resources, remaining bandwidth, and current load are used as the first node characteristics. This reflects the processing capacity and instantaneous availability of each node in handling attack traffic redirection, avoiding the inclusion of nodes with high loads or insufficient resources in the main towing path, thereby reducing congestion and packet loss risks. Transmission delay, link utilization, and historical stability are used as side characteristics to effectively measure the latency contribution and congestion trend of links, prioritizing links with low latency, low occupancy, and high historical stability, shortening end-to-end towing latency and improving path availability. In the injection phase, the second node characteristics are set as CPU utilization, average forwarding delay, and whether malicious traffic has been forwarded. This avoids nodes with high CPU utilization and high queuing latency when services recover, reducing injection jitter and retransmission probability. Simultaneously, based on the security indicator of "whether malicious traffic has been forwarded," potentially high-risk nodes are avoided, reducing the possibility of the injection path being interfered with again.

[0067] Optionally, the network topology diagram includes multiple cleaning devices; determining the traffic path from the first device to the second device based on each attention weight includes: determining the third device in the traction path from the multiple cleaning devices based on the attention weights between adjacent nodes on each first path, the operating status of each cleaning device, and the distance from the first device to the cleaning device, thereby obtaining the traction path.

[0068] In other words, this invention can adopt a hierarchical decision-making mechanism of "first selecting cleaning nodes, then determining the traction path". Specifically, on several first paths obtained through enumeration or sampling, each first path is evaluated based on the attention weights between adjacent nodes within the path. Simultaneously, the operating status of each cleaning device (e.g., availability of computing / bandwidth resources, current load, recent stability performance, etc.) and the distance costs from the first device to each cleaning device (e.g., latency distance, hop count, or deviation from the original service route) are considered. Multiple cleaning devices are then jointly scored and ranked to determine the third device in the traction path as the target node for traffic convergence, and the corresponding traction path is obtained accordingly. Through this method, path evaluation is not limited to static topology relationships but integrates the contextual relevance and transmission quality represented by attention weights, the real-time carrying capacity of the cleaning devices, and the distance sensitivity from the source to the cleaning point. This ensures that, while maintaining real-time performance, the traction path better reflects the current network state and resource distribution.

[0069] The above solutions prioritize the matching of cleaning equipment with more abundant resources, more suitable distances, and higher historical stability, thereby achieving adaptive load balancing, reducing overload at individual cleaning points, and improving throughput and steady-state performance.

[0070] Optionally, after step 320, the method further includes: obtaining the transmission effect of the attack traffic after it has traveled through the traffic path; adjusting the graph attention network based on the transmission effect, or switching the traffic path. Through this approach, path selection and model parameters are no longer one-time static decisions, but can be adaptively optimized according to changes in the attack situation and network state.

[0071] Please see Figure 4 This illustrates a flowchart of another method for handling attack traffic, which includes the following steps: Step 401: Deploy functional modules to complete graph structure modeling.

[0072] The current network state is modeled as a graph structure, where nodes represent network devices or cleaning centers, and edges represent link connections. Both nodes and edges are accompanied by state characteristics (such as load, bandwidth, latency, etc.).

[0073] Step 402: Calculate weights and drive traffic using graph attention mechanism.

[0074] The graph attention network (GAT) mechanism is used to calculate the attention weight between each node and its neighbors, and to dynamically evaluate the importance of nodes and links in traction and scheduling.

[0075] Step 403: Match the cleaning center based on the status of the cleaning nodes.

[0076] For example, by combining the resource capacity and network distance of the cleaning nodes, the most suitable cleaning center can be matched to achieve a balanced distribution of scheduling pressure.

[0077] Step 404: Calculate the back-injection path again based on the graph attention mechanism.

[0078] Based on attention weight and node status, the optimal attack flow diversion path is selected to direct malicious traffic to a cleaning node with controllable load.

[0079] Step 405: Evaluate the effect and provide continuous feedback for adaptive testing.

[0080] After cleaning is completed, a highly reliable and low-latency reinjection path is selected based on the full map information to inject the cleaned traffic back into the normal network, thus achieving closed-loop recovery.

[0081] Steps 401-405 above can be referred to steps 310-320 above, and will not be repeated here.

[0082] Please see Figure 5 This illustrates a flowchart of another method for handling attack traffic, which includes the following steps: Step 510: Construct a network topology diagram between the first and second devices, which are the targets of the attack.

[0083] Model the current network as a graph network topology with attributes. , where the set of nodes An edge set represents a network of forwarding devices, routers, or edge gateways. This indicates the link connections between them. Each node Attached state feature vector , This includes the node's computing resources, remaining bandwidth, and current load. Each edge... It also includes link characteristics such as transmission delay, link utilization, and historical stability.

[0084] Optionally, will The values ​​of each dimension need to be normalized. This invention does not limit the specific implementation of normalization; the following is only an example of normalization:

[0085] Step 520: Using a graph attention network, process the node features of each node and the edge features of each edge in the network topology graph to determine the attention weights between adjacent nodes from the first device to the third device.

[0086] Based on the graph attention mechanism, for each node... neighboring nodes (in ) Calculate attention weights , used to represent neighbors in traffic path decision-making The relative importance of each. The weights are calculated as follows:

[0087] in , , This represents the normalized feature vector of a network node, which is periodically collected by a network monitoring system (such as Netflow, SNMP, or SDN controller). It is a weight matrix with compressed feature dimensions, learned by the GAT model through data. It does not depend on the network structure itself, but training depends on labeled data or objective functions (such as path optimality, blocking rate, etc.). It is a feature transformer that transforms the original state of each node in the network (such as bandwidth, CPU, number of connections, etc.) into a spatial representation that the neural network can understand, called embedding. Understandably, the data used to train GAT can come from a local network or from a public dataset.

[0088] also, Completed node and neighboring nodes The feature vectors are concatenated to represent the nodes. and neighboring nodes The importance of combination lays the groundwork for the subsequent computation of attention mechanisms. yes The transpose of this vector is also an attention weight vector, used to apply attention weights to nodes. and neighboring nodes This involves scoring the node pairs to determine which are key neighbors.

[0089] It is a type of activation function where the output equals the input when the input is positive, and the output is 0.01 times or less when the input is non-positive. GAT retains negatively correlated attention while avoiding the "neuron death" problem.

[0090] Step 530: Based on the attention weights between adjacent nodes on each first path, the operating status of each cleaning device, and the distance from the first device to the cleaning device, determine the third device in the traction path from among the multiple cleaning devices, thereby obtaining the traction path.

[0091] Optionally, the traction path can be determined first, followed by the determination of the third device, or vice versa. The latter will be used as an example below. The former approach is similar in principle and will not be repeated here.

[0092] Assuming the attack originates from the entry point node To candidate cleaning nodes One of the paths is Then, the total traffic score for this path can be obtained using the calculated attention weight statistics:

[0093] Understandably, the higher the relative importance of nodes, the higher the traffic path score. The higher the value, the better it is for attracting traffic. This is because the essence of the attention mechanism is modeling the value of information transmission. In the selection of traffic attraction paths, the path is composed of information transmission chains between multiple nodes. If the nodes on the path are highly interconnected, it means that the path has stronger coordination capabilities, stability, and scheduling potential under the current network conditions, and is therefore more suitable for undertaking traffic attraction tasks.

[0094] Optionally, the paths to all reachable cleaning nodes can be sorted by score, and the path with the highest score can be selected as the optimal alternative redirection path to guide attack traffic to the designated cleaning node. This mechanism allows for the adaptive selection of efficient, secure, and load-balanced redirection paths in complex network topologies, laying the foundation for subsequent cleaning center matching and injection path optimization.

[0095] After initially selecting the torrent path, it is necessary to choose the most suitable target node from multiple available scrubbing centers to handle the attack traffic. Let the set of scrubbing centers be... And each cleaning center Includes remaining resource capacity Current task load Maximum supported bandwidth , and nodes in the traction path distance .

[0096] Optionally, the score of the cleaning center closest to the network route distance can be calculated using the following formula:

[0097] in The size of the attack traffic, A coefficient used to control the importance of bandwidth factors in matching. This represents the relative pressure exerted by the cleaning nodes when processing the attack traffic. The above formula ensures that the attack traffic volume is at least less than or equal to the remaining resource capacity. Reduce current task load By lightweight matching of optimal cleaning center nodes, connecting the path traction and cleaning center functions, it ensures reasonable resource scheduling, load balancing, and scheduling robustness in environments with multiple attack sources and multiple cleaning nodes.

[0098] Optionally, the above clear center score can be used. With traffic score The weighted summation is performed to obtain the traction path score, and the traction path is determined based on the traction path score.

[0099] Step 540: Using a graph attention network, process the node features of each node and the edge features of each edge in the network topology graph to determine the attention weights between adjacent nodes from the third device to the second device.

[0100] After the attack traffic is filtered by the scrubbing center (third-party device), the legitimate business traffic needs to be effectively, securely, and with low latency injected back into the original network. At the same time, the transmission latency and congestion risk of the injection path should be minimized, vulnerable or high-load links should be avoided again, and the service quality (QoS) should be kept as consistent as possible with the original service route.

[0101] Optionally, the GAT model in attack traffic pulling can be reused again, while the feature vectors Several completely different dimensions are used, including but not limited to: current CPU utilization, average forwarding latency, in-degree and out-degree, and whether malicious traffic has been forwarded. This yields a new feature vector. After normalization, the following formula is used for calculation:

[0102] Step 550: Determine the back-injection path based on the attention weights between adjacent nodes on each second path.

[0103] Optionally, all possible cleaning centers can be used. (Third equipment) to the business target node The path for (the second device) is represented as follows: And calculate the appropriate re-injection score for each path:

[0104] The path with the highest score was ultimately selected as the injection path. This approach, through the construction of a GAT model with network nodes as the graph structure, extracts key features of each node (such as CPU utilization, average forwarding latency, topology connectivity, and historical attack records), calculates the attention weights between links, and evaluates the overall credibility score of the path. The selection of the path with the highest score as the injection path improves the reliability of traffic recovery and business continuity.

[0105] Step 560: Obtain the transmission effect of the attack traffic after it has been transmitted through the traffic path, and adjust the graph attention network or switch the traffic path based on the transmission effect.

[0106] Optionally, after completing a traction, cleaning, and reinjection process, key performance indicators for each stage are collected and analyzed, including attack mitigation rate, reinjection path stability, and changes in resource load at the cleaning center. Based on this feedback, the node feature weights in the graph attention network are dynamically adjusted or the model is retrained to adapt to the evolving network state.

[0107] Optionally, an anomaly triggering mechanism can be introduced to proactively shrink the scheduling scope or switch to alternative paths when drastic changes in the local network topology, frequent failures of certain types of links, or bottlenecks in cleaning capabilities are detected, ensuring the robust operation of the system. Through these solutions, the system shifts from "static planning" to "real-time optimization," achieving a highly adaptive response to resource coordination and path selection under complex attack scenarios.

[0108] The above describes methods for handling attack traffic. The following example illustrates these methods.

[0109] Please see Figure 6This diagram illustrates a network topology. Assume the network topology contains the following nodes: Node A (Affected Business Node): Remaining bandwidth 400Mbps, load 80%, CPU cores 2; Node B (relay routing node): Remaining bandwidth 600Mbps, load 50%, CPU cores 4; Node C (relay routing node): Remaining bandwidth 300Mbps, load 60%, CPU cores 3; Node D (Scrubbing Center): Remaining bandwidth 800Mbps, load 40%, CPU cores 8; Node E (Scrubbing Center): Remaining bandwidth 1000Mbps, load 30%, CPU cores 10; Node F (Business Server).

[0110] based on Figure 6 Given the network topology, the methods for handling attack traffic are as follows: The first step is to select a traction path that matches the cleaning center.

[0111] The GAT model calculates attention weights between adjacent nodes based on node feature vectors, which are used to evaluate traction priority. The calculation results are as follows: AB path attention weight: α AB =0.72; AC path attention weight: α AC =0.58; BD path attention weight: α BD =0.65; CE path attention weight: α CE =0.81.

[0112] The total score for the path is calculated as follows: ABD score is -0.759, and A→C→E score is -1.561.

[0113] The second step is to assess the resources of the cleaning center.

[0114] Cleaning Center D: Bandwidth score 0.8, load score 0.6, computing resource score 0.9, overall score 0.78 (remaining capacity 60%, CPU utilization 70%). Cleaning Center E: Bandwidth score 1.0, load score 0.7, computing resource score 1.0, overall score 0.9 (remaining capacity 90%, CPU utilization 50%).

[0115] Although path ABD has a high attention score (-0.759), cleaning center D faces significant resource pressure. Considering both path quality and resource availability, the system selects cleaning center E as the optimal target, and the final guiding path is ACE.

[0116] The third step is to optimize the injection path.

[0117] After the cleaning is completed, there are two candidate injection paths from the cleaning center E to the business server F: Path 1 (EBF): Average latency 30ms, historical stability 95%, historical attack interference rate 5%; Path 2 (ECF): Average latency 50ms, historical stability 98%, historical attack interference rate 10%.

[0118] After the GAT model comprehensively evaluates the credibility of the path, the system selects the path with the higher overall score (EBF) as the back injection path.

[0119] The fourth step is adaptive feedback adjustment.

[0120] After this round of scheduling was executed, real-time monitoring revealed that the load on cleaning node E rose to 75%; and a brief packet loss event occurred on the injection path EBF.

[0121] Based on the above feedback, an adaptive adjustment mechanism is triggered: the weight of the "stability" feature of node B is reduced, its priority in subsequent back-injection is decreased, and the selection probability of cleaning center D is increased to achieve load balancing. Path performance data is also recorded for incremental training and optimization of the GAT model.

[0122] This invention enables dynamic optimization of attack traffic scheduling paths and cleaning resource allocation. By introducing a graph attention mechanism, it accurately identifies the importance of nodes and links, and constructs a coordinated scheduling model that links attack traffic to cleaning center matching and back-injection path optimization. This effectively solves the problems of attack path selection lacking context awareness and cleaning node selection lacking dynamic adaptability, thereby achieving efficient guidance of attack traffic and ensuring network service continuity.

[0123] Based on the same concept, this application also provides an attack traffic processing device that can perform the attack traffic processing method described above.

[0124] Please see Figure 7 This application provides a schematic diagram of the structure of a device for processing attack traffic according to an embodiment of the present application, such as... Figure 7 As shown, the device for processing attack traffic includes: Module 701 is used to construct a network topology graph between the first device and the second device, which are the targets of the attack. Nodes in the network topology graph represent any device from the first device to the second device, and edges in the network topology graph represent the link connection relationship between devices. The determination module 702 is used to determine the traffic path from the first device to the second device based on the node characteristics of each node and the edge characteristics of each edge in the network topology diagram; the traffic path is to clean the attack traffic through the third device in the network topology diagram and then inject it back into the second device.

[0125] In one possible implementation, the determining module 702 is specifically used to: process the node features of each node and the edge features of each edge in the network topology graph through a graph attention network to determine the attention weights between adjacent nodes from the first device to the second device; and determine the traffic path from the first device to the second device based on each attention weight.

[0126] In one possible implementation, the traffic path includes a traction path from the first device to the third device and a reinjection path from the third device to the second device; the determination module 702 is specifically used to: determine any first path from the first device to the third device and / or any second path from the third device to the second device; and through a graph attention network, determine the attention weights between adjacent nodes on the path based on the features of each first node and each first edge in the first path, and / or the features of each second node and each second edge in the second path.

[0127] In one possible implementation, the first node features and first edge features used to determine the traction path are not exactly the same as the node features and edge features used to determine the back injection path.

[0128] In one possible implementation, the first node features include at least one of computing resources, remaining bandwidth, and current load; the first side features and / or the second side features include at least one of transmission delay, link utilization, and historical stability; and the second node features include at least one of CPU utilization, average forwarding delay, and whether malicious traffic has been forwarded.

[0129] In one possible implementation, the network topology graph includes multiple cleaning devices; the determining module 702 is specifically used to: determine the third device in the traction path from the multiple cleaning devices based on the attention weight between adjacent nodes on each first path, the operating status of each cleaning device and the distance from the first device to the cleaning device, thereby obtaining the traction path.

[0130] In one possible implementation, the determining module 702 is further configured to: obtain the transmission effect of the attack traffic after it has been transmitted through the traffic path; adjust the graph attention network based on the transmission effect, or switch the traffic path.

[0131] Please see Figure 8 This illustrates a schematic diagram of another attack traffic processing device provided in an embodiment of this application, such as... Figure 8 As shown, the attack traffic processing device includes a memory 801 and a processor 802, with the processor 802 coupled to the memory 801. The memory 801 stores program instructions, and the processor 802 calls the program instructions stored in the memory 801 to execute the aforementioned attack traffic processing method according to the obtained program.

[0132] Optionally, the attack traffic processing device may further include an interface circuit 803, which may be a transceiver or an input / output interface. The input / output interface is used for inputting and / or outputting information; output can be understood as sending, and input as receiving. The processor 802 can communicate with other devices in the attack traffic processing device or other devices besides the attack traffic processing device through the interface circuit 803 to obtain the information required to perform the above-described attack traffic processing method.

[0133] When the attack traffic processing device 800 is used to implement Figure 3 When the method is shown, the processor 802 is used to implement the functions of the above-mentioned building module 801 and determining module 802.

[0134] It is understood that the processor in the embodiments of this application may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor may be a microprocessor or any conventional processor.

[0135] The memory in the embodiments of this application may be random access memory, flash memory, read-only memory, programmable read-only memory, erasable programmable read-only memory, electrically erasable programmable read-only memory, registers, hard disk, portable hard disk, compact disc read-only memory (CD-ROM), or any other form of storage medium known in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. The storage medium may also be a component of the processor.

[0136] Based on the same technical concept, embodiments of the present invention also provide a computer-readable storage medium storing a computer program or instructions, which, when executed by a processor, causes the computer to perform the above-described method for processing attack traffic.

[0137] Based on the same technical concept, embodiments of the present invention also provide a computer-readable program product, which, when executed, causes a computer to perform the above-described method for processing attack traffic.

[0138] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0139] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0140] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0141] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1The steps of the function specified in one or more boxes.

[0142] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A method for processing attack traffic, characterized in that, include: Construct a network topology diagram between the first and second devices, which are the targets of the attack. The nodes in the network topology graph represent any device from the first device to the second device, and the edges in the network topology graph represent the link connection relationship between devices; Based on the node characteristics of each node and the edge characteristics of each edge in the network topology graph, a traffic path from the first device to the second device is determined; the traffic path is a path where the attack traffic is cleaned by the third device in the network topology graph and then injected back into the second device.

2. The method as described in claim 1, characterized in that, Determining the traffic path from the first device to the second device based on the node characteristics of each node and the edge characteristics of each edge in the network topology graph includes: By using a graph attention network, the node features of each node and the edge features of each edge in the network topology graph are processed to determine the attention weights between adjacent nodes from the first device to the second device. Based on each attention weight, the traffic path from the first device to the second device is determined.

3. The method as described in claim 2, characterized in that, The flow path includes a traction path from the first device to the third device and a reinjection path from the third device to the second device; The graph attention network processes the node features of each node and the edge features of each edge in the network topology graph to determine the attention weights between adjacent nodes from the first device to the second device, including: Determine any first path from the first device to the third device and / or any second path from the third device to the second device; Using a graph attention network, attention weights between adjacent nodes on the first path are determined for the features of each first node and each first edge in the first path, and / or the features of each second node and each second edge in the second path.

4. The method as described in claim 3, characterized in that, The first node features and first edge features used in determining the traction path are not exactly the same as the node features and edge features used in determining the reinjection path.

5. The method as described in claim 4, characterized in that, The first node features include at least one of computing resources, remaining bandwidth, and current load; The first-side feature and / or the second-side feature include at least one of transmission delay, link utilization, and historical stability; The second node features include at least one of the following: CPU utilization, average forwarding latency, and whether malicious traffic has been forwarded.

6. The method as described in claim 3, characterized in that, The network topology diagram includes multiple cleaning devices; determining the traffic path from the first device to the second device based on each attention weight includes: Based on the attention weights between adjacent nodes on each first path, the operating status of each cleaning device, and the distance from the first device to the cleaning device, the third device in the traction path is determined from the plurality of cleaning devices, thereby obtaining the traction path.

7. The method as described in claim 2, characterized in that, After determining the traffic path from the first device to the second device, the method further includes: Obtain the transmission effect of the attack traffic after it has traveled through the traffic path; Adjust the graph attention network based on the transmission effect, or switch the traffic path.

8. A device for processing attack traffic, characterized in that, include: A processor coupled to a memory for storing computer programs or instructions, the processor for executing the computer programs or instructions to implement the method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, It stores a computer program executable by a computer device, which, when run on the computer device, causes the computer device to perform the steps of any of the methods described in claims 1 to 6.

10. A computer program product, characterized in that, When it is run on a computer, it causes the computer to perform the method as described in any one of claims 1 to 6.