Server-oriented network attack defense method, system and storage medium
By calculating the bandwidth of the live streaming server and the anomaly rate of viewer connections, and combining historical data and topic relevance, the DBSCAN clustering algorithm is used to identify abnormal traffic, solving the problem of distinguishing between real traffic and malicious attacks in live streaming scenarios, and achieving efficient network attack defense.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- RANGE TECH DEV CO LTD
- Filing Date
- 2026-01-29
- Publication Date
- 2026-05-29
Smart Images

Figure CN121619448B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network attack defense for live streaming rooms, and specifically to network attack defense methods, systems, and storage media for servers. Background Technology
[0002] For internet companies, in their live streaming business scenarios, servers need to maintain a large number of continuous connections and stable video stream delivery simultaneously. If subjected to a Distributed Denial of Service (DDoS) attack, it can lead to problems such as link congestion, server connection exhaustion, and saturation of origin bandwidth, causing delays, stuttering, or even interruptions in the transmission of live content, thus affecting user viewing experience and business continuity. Due to the strong real-time and high concurrency nature of live streaming, any degradation in service quality will immediately lead to user churn, termination of interaction, and damage to commercial revenue. Therefore, to ensure the stable availability of live streaming services, internet companies need to deploy high-performance, low-latency DDoS protection capabilities at the network edge, data transmission channels, and core service nodes to quickly identify and block abnormal access traffic, preventing malicious traffic from impacting critical business links.
[0003] In live streaming scenarios, a common type of DDoS attack is the bandwidth exhaustion attack. This type of attack rapidly saturates network bandwidth and server resources by sending massive amounts of invalid requests or abnormal data packets to the live streaming server, resulting in stuttering, increased latency, or service interruption. Such attacks often cause a sharp increase in overall bandwidth within a short period, externally resembling traffic spikes caused by popular streamers or trending events. Because the two attacks share highly overlapping statistical characteristics such as access patterns, connection counts, and data packet rates, existing protection technologies struggle to accurately distinguish between genuine business traffic growth and malicious attack traffic, leading to poor network attack defense effectiveness. Summary of the Invention
[0004] To address the problem that existing methods struggle to accurately distinguish between genuine business traffic growth and malicious attack traffic when defending against live streaming network attacks, resulting in poor network attack defense effectiveness, this invention aims to provide a server-side network attack defense method, system, and storage medium. The specific technical solution adopted is as follows:
[0005] In a first aspect, the present invention provides a network attack defense method for servers, the method comprising the following steps:
[0006] Obtain the bandwidth of each live streaming server and the connection status between viewers and the live streaming server;
[0007] Based on the bandwidth increase of the server at each moment during each connection between the viewer and each live streaming server, and the bandwidth within a local time period, the initial anomaly level of each connection between the viewer and each live streaming server is evaluated; suspected abnormal connections at each moment are screened based on the initial anomaly level.
[0008] The overall connection anomaly of each live stream room at each moment is obtained based on the difference between the initial anomaly of a single connection at a single moment and the initial anomaly of the connection at the corresponding moment during the historical broadcast of each live stream room, as well as the correlation between the live stream topic and the hot topic.
[0009] By combining the bandwidth rise time of all live streaming servers during the current live streaming process of the live streaming room to be defended, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connection, the overall anomaly index of the suspected abnormal connection of the live streaming room to be defended is determined.
[0010] Based on the overall anomaly index, defenses are implemented against network attacks on the server's live streaming service.
[0011] Preferably, the step of evaluating the initial anomaly level at each moment of each connection between the viewer and each live streaming server based on the bandwidth increase of the server at each time point during each connection and the bandwidth within a local time period includes:
[0012] For any live stream room:
[0013] The bandwidth increase rate of the server of any live room at the candidate time is determined based on the bandwidth increase of the candidate time relative to the previous time. The candidate time is any time in any connection between the viewer and the server of any live room.
[0014] Based on the downlink bandwidth corresponding to the viewer's IP connected to the server of any live room within a local time period of the candidate moment, and the bandwidth increase rate, the initial anomaly degree of the candidate moment in any connection between the viewer and the server of any live room is obtained.
[0015] Preferably, the step of filtering suspected abnormal connections at each time point based on the initial anomaly degree includes: if the initial anomaly degree is greater than a first anomaly degree threshold, then any connection between the viewer and the live streaming server is determined as a suspected abnormal connection at a candidate time point.
[0016] Preferably, the step of obtaining the comprehensive connection anomaly of each live stream room at each moment based on the difference between the initial anomaly of a connection at a single moment and the initial anomaly of the connection at the corresponding moment during the historical broadcasting process of each live stream room, as well as the correlation between the live stream topic and the hot topic, includes:
[0017] For any given moment:
[0018] The average of the initial anomalies of all connections at any given moment in the live stream to be analyzed is taken as the connection anomaly index at any given moment in the live stream to be analyzed.
[0019] The first difference between the connection anomaly index of the live stream to be analyzed at any given moment and the average connection anomaly index of all connections at the same time when the live stream to be analyzed reached the same broadcast duration during its historical broadcast process is used as the normalized result of the first difference as the initial connection anomaly degree of the live stream to be analyzed at any given moment.
[0020] By utilizing the correlation between the live topics in the live room to be analyzed and the trending topics, the initial connection anomaly score is corrected to obtain the comprehensive connection anomaly score of the live room to be analyzed at any given time.
[0021] The live stream room to be analyzed can be any live stream room.
[0022] Preferably, the step of correcting the initial connection anomaly score by utilizing the correlation between the live stream topic and trending topics in the live stream to obtain the comprehensive connection anomaly score of the live stream at any given time includes:
[0023] The difference between the constant 1 and the degree of correlation is used as a correction coefficient;
[0024] The initial connection anomaly score is corrected using the correction coefficient to obtain the comprehensive connection anomaly score of the live streaming room at any given time.
[0025] Preferably, the determination of the overall anomaly index of suspected abnormal connections in the live stream room to be defended, by combining the bandwidth rise time of all live stream servers during the current live stream of the live stream room to be defended, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connections, includes:
[0026] For any live stream currently being broadcast and subject to defense:
[0027] The moment when the bandwidth of the server reaches its maximum value during the current live broadcast of any of the live broadcast rooms to be defended is recorded as the end time of the rising interval; the minimum bandwidth of the server with the closest time interval before the end time of the rising interval is taken as the start time of the rising interval; the bandwidth rising interval of any live broadcast room is obtained based on the start time and the end time.
[0028] The normalized result of the difference in bandwidth between the servers of any live streaming room at the start time and the end time is determined as the degree of increase of any live streaming room in the bandwidth increase range.
[0029] The moment when the growth rate of the comprehensive connection anomaly degree of any of the live streaming rooms is the largest is recorded as the relevant judgment moment of any of the live streaming rooms.
[0030] Based on the time distribution of the relevant judgment time of any live room and the bandwidth increase interval of any live room, as well as the degree of increase, the abnormal increase correlation of any live room is determined.
[0031] By combining the similarity between the abnormal increase in correlation of the live room to be defended and the abnormal increase in correlation of other live rooms, and the initial abnormality of the suspected abnormal connections of the live room server at each time point, the overall abnormality index of the suspected abnormal connections of the live room to be defended is obtained.
[0032] Preferably, the overall anomaly index of the suspected abnormal connections of the live stream to be defended is obtained by combining the similarity of the abnormal increase in correlation between the live stream to be defended and other live streams, and the initial anomaly degree of each moment in the suspected abnormal connections of the live stream server to be defended, including:
[0033] Based on the abnormal increase correlation of each live room, the DBSCAN clustering algorithm is used to cluster all live rooms to obtain each cluster; the average abnormal increase correlation of the cluster with the largest average abnormal increase correlation is taken as the overall abnormal correction degree.
[0034] For any suspected abnormal connection of the live streaming server to be defended at the current moment, the product of the initial abnormality degree of the suspected abnormal connection of the live streaming server to be defended at the current moment and the overall abnormality correction degree is used as the overall abnormality index of the suspected abnormal connection of the live streaming server to be defended.
[0035] Preferably, the defense against network attacks on the server live streaming service based on the overall anomaly index includes:
[0036] If the overall anomaly index is greater than or equal to the preset anomaly threshold, the corresponding suspected abnormal connection will be intercepted.
[0037] If the overall anomaly index is less than the preset anomaly threshold, the corresponding suspected abnormal connection will be allowed to proceed.
[0038] Secondly, the present invention provides a server-oriented network attack defense system for implementing the method of the first aspect, the system comprising:
[0039] The data acquisition module is used to acquire the bandwidth of each live streaming server and the connection status between the audience and the live streaming server.
[0040] The suspected abnormal connection filtering module is used to evaluate the initial abnormality of each connection between the viewer and each live streaming server based on the bandwidth increase of the server at each moment during each connection and the bandwidth within a local time period; and to filter suspected abnormal connections at each moment based on the initial abnormality.
[0041] The comprehensive connection anomaly determination module is used to obtain the comprehensive connection anomaly of each live broadcast room at each moment based on the difference between the initial anomaly of the connection at a single moment and the initial anomaly of the connection at the corresponding moment during the historical broadcast of each live broadcast room, as well as the relevance of the live broadcast topic to the hot topic.
[0042] The overall anomaly index evaluation module is used to determine the overall anomaly index of the suspected abnormal connections of the live streaming room to be defended by combining the bandwidth rise time of all live streaming room servers during the current live streaming process, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connections.
[0043] The attack defense module is used to defend against network attacks on the server's live streaming service based on the overall anomaly index.
[0044] Thirdly, the present invention provides a storage medium storing a computer program that, when executed by a processor, implements a server-oriented network attack defense method as described in the first aspect.
[0045] The present invention has at least the following beneficial effects:
[0046] This invention, by combining the upward trend of live streaming server bandwidth with bandwidth data within a local time period, conducts a preliminary evaluation of the anomalies in the connection between viewers and the live streaming server, obtaining an initial anomaly score. It also performs preliminary screening of all connections, effectively identifying high-risk suspected anomaly connections. These high-risk connections can be analyzed and processed in depth without requiring comprehensive testing of all connections, thus significantly improving processing efficiency and real-time response capabilities while ensuring security. Furthermore, by combining the differences in initial anomaly scores during the historical broadcasts of the live streaming room with the relevance of the live streaming topic to trending topics, a comprehensive evaluation of traffic anomalies at each moment is obtained, yielding a comprehensive connection anomaly score. However, considering that if the comprehensive connection anomaly scores of multiple live streaming rooms simultaneously increase at a certain moment, corresponding to a sharp increase in the overall server bandwidth, it is said... The synchronous and concentrated nature of the abnormal traffic in these live streaming rooms suggests that they are more likely to originate from external attacks. If the overall bandwidth remains stable or shows an upward trend without a significant correlation with the anomalies in individual live streaming rooms, then the anomaly is more likely caused by changes in business traffic. Therefore, by further combining the bandwidth rise time, the overall connection anomaly degree, and the initial anomaly degree of suspected abnormal connections, the overall anomaly index of suspected abnormal connections in the live streaming rooms to be defended was determined. The overall anomaly index can accurately distinguish between normal traffic peaks and malicious attacks, reducing the false positive rate of malicious attacks. Therefore, the method provided by this invention can dynamically assess the overall security status of the server to be defended, achieve timely and effective interception of network attacks, improve the effectiveness of network attack defense, and ensure the continuity and stability of live streaming services. Attached Figure Description
[0047] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0048] Figure 1 A flowchart illustrating a server-oriented network attack defense method provided in an embodiment of the present invention;
[0049] Figure 2 This is a structural block diagram of a server-oriented network attack defense system provided in an embodiment of the present invention. Detailed Implementation
[0050] To further illustrate the technical means and effects adopted by the present invention to achieve the intended purpose, the following detailed description, in conjunction with the accompanying drawings and preferred embodiments, describes a server-oriented network attack defense method, system, and storage medium proposed according to the present invention.
[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.
[0052] The following description, in conjunction with the accompanying drawings, details a specific solution for a server-oriented network attack defense method, system, and storage medium provided by the present invention.
[0053] An embodiment of a server-oriented network attack defense method:
[0054] This embodiment proposes a server-oriented network attack defense method, such as... Figure 1 As shown, a server-oriented network attack defense method according to this embodiment includes the following steps:
[0055] Step S1: Obtain the bandwidth of each live streaming server and the connection status between the audience and the live streaming server.
[0056] The purpose of this embodiment is to defend against network attacks on the live streaming room to be defended. When determining whether there is a network attack on the live streaming room to be defended, it is necessary to combine the server status of other live streaming rooms during the current live streaming process of the live streaming room to be defended and the connection status of viewers with other live streaming rooms to distinguish between the real business traffic growth of the live streaming room to be defended and malicious attack traffic, so as to screen for malicious attacks and improve the accuracy of defense.
[0057] First, the bandwidth of all live streaming servers currently broadcasting in the live stream to be defended is obtained, as well as the downlink bandwidth connecting the viewer IPs entering each live stream to the live stream server during this process. The broadcast time of all live streams currently broadcasting in the live stream to be defended is also obtained. In this embodiment, the bandwidth data is collected once per second; in specific applications, the implementer can set this according to specific circumstances. It should be noted that once a viewer enters the live stream, a connection is established between the viewer and the live stream server.
[0058] Thus, this embodiment has obtained the bandwidth of each live streaming server and the connection status between the audience and the live streaming server at each moment during the current live streaming process of the live streaming room to be defended.
[0059] Step S2: Based on the bandwidth increase of the server at each moment in each connection between the viewer and each live streaming server and the bandwidth within a local time period, evaluate the initial anomaly level at each moment in each connection between the viewer and each live streaming server; filter suspected abnormal connections at each moment based on the initial anomaly level.
[0060] Considering that in live streaming or high-concurrency internet service scenarios, performing deep inspection on all traffic directly would increase access latency, consume significant computing resources, and negatively impact user experience, this embodiment will first conduct preliminary screening. On the server side, it will quickly utilize macroscopic traffic characteristics and single-source behavioral indicators to identify obviously abnormal or suspicious traffic, prioritizing its interception or placing it in a deep analysis queue. Meanwhile, most normal traffic will be allowed to pass directly, thereby improving protection speed and reducing access latency while ensuring effective interception.
[0061] When the overall server bandwidth increases rapidly, it indicates a possible abnormal increase in the total traffic of the live stream or service node. If, at this time, the downlink traffic of a particular IP is also abnormally high, it means that IP is significantly contributing to the overall traffic increase, and the number of connections it maintains may far exceed normal user behavior, thus posing a higher risk of DDoS attacks. Therefore, in the initial screening, combining the rate of increase in the server's overall bandwidth with the downlink traffic or active connection count of a single IP can quickly identify potential sources of anomalies. Since a DDoS attack directly manifests as an overall increase in server bandwidth, it is necessary to measure the degree of this overall increase.
[0062] Based on the above characteristics, we will first take one of the live streaming rooms currently in the process of being defended as an example for explanation. The method provided in this embodiment can be used to process other live streaming rooms.
[0063] Specifically, any moment in the connection between the viewer and the live streaming server is recorded as a candidate moment. The bandwidth increase rate of the live streaming server at each candidate moment is determined based on the bandwidth increase of the candidate moment relative to its previous moment.
[0064] As a specific example, the bandwidth increase rate of the live streaming server at a candidate time can be determined as follows: Specifically, the difference between the bandwidth of the live streaming server at the candidate time and the bandwidth at the time preceding the candidate time is calculated, and the normalized result of this difference is taken as the bandwidth increase rate of the live streaming server at the candidate time. When normalizing this difference, the maximum-minimum normalization method is used. The maximum-minimum normalization method is existing technology and will not be elaborated further here.
[0065] Based on the downlink bandwidth and bandwidth increase rate of the viewer IP connected to the live streaming server within a local time period of the candidate time, the initial anomaly degree of the candidate time in each connection between the viewer and the live streaming server is obtained.
[0066] As a concrete example, the specific formula for calculating the initial anomaly degree is given, where the audience and the live streaming server... The initial anomaly degree at time i in the secondary connection can be expressed as:
[0067]
[0068] in, This indicates the interaction between the viewer and the live stream server. The initial anomaly degree at time i in the second connection. This indicates the interaction between the viewer and the live stream server. The bandwidth of the server at the i-th moment in the first connection. This indicates the interaction between the viewer and the live stream server. The server's bandwidth at time i-1 in the next connection. This indicates the interaction between the viewer and the live stream server. The average downlink bandwidth corresponding to the viewer IP connected to the live streaming server during a local time period at time i in each connection. This represents the normalization function.
[0069] As a specific example, the method for obtaining a local time period of a moment is as follows: take that moment as the last moment in the local time period of that moment, and take a time period of 1 minute as the local time period of that moment.
[0070] This indicates the interaction between the viewer and the live stream server. The bandwidth increase rate of the live streaming server at the i-th time point in the first connection. A higher bandwidth increase rate for the live streaming server, coupled with a higher average downlink bandwidth for viewer IPs connected to the live streaming server within the local time period at that moment, indicates a more likely anomaly has occurred at that time, specifically a connection between the viewer and the live streaming server at the i-th time point. The larger the initial anomaly degree at time i in the secondary connection, the greater the anomaly degree.
[0071] In order to perform preliminary anomaly screening of traffic and thus improve the processing efficiency of non-abnormal traffic, it is necessary to allow low-abnormality traffic directly, while performing in-depth anomaly analysis on high-abnormality connections.
[0072] Taking candidate connection times as an example, if the initial anomaly score of a candidate connection time in each connection between the viewer and the live stream server is greater than the first anomaly score threshold, then the connection is determined to be a suspected abnormal connection for the candidate connection time and requires further screening. If the initial anomaly score of a candidate connection time in each connection between the viewer and the live stream server is less than or equal to the first anomaly score threshold, then the connection is determined to be a normal connection for the candidate connection time and is allowed to proceed directly.
[0073] As a concrete example, the first anomaly threshold can be determined as follows: Specifically, the initial anomaly levels at confirmed attack moments (abnormal connections) during historical live streams are collected. Then, the distribution characteristics of these initial anomaly levels are statistically analyzed. Based on these distribution characteristics, the first anomaly threshold is set to effectively distinguish between abnormal and normal connections. This method of determining the first anomaly threshold based on the statistical analysis results of the initial anomaly levels at confirmed abnormal connection moments during historical live streams allows the first anomaly threshold to better distinguish abnormal connections, improving the accuracy of subsequent attack defense. As another concrete example, the first anomaly threshold can also be directly set to an empirical value of 0.7.
[0074] By using the above methods, we can filter out suspected abnormal connections at each moment in each live stream that is currently broadcasting and needs to be protected.
[0075] Step S3: Based on the difference between the initial anomaly of a single connection at a given moment and the initial anomaly of the connection at the corresponding moment during the historical broadcasting process of each live room, as well as the correlation between the live topic and the hot topic, the comprehensive connection anomaly of each live room at each moment is obtained.
[0076] The initial anomaly level of each connection determined by the initial screening allows for rapid stratification of traffic based on risk level: connections with low initial anomaly levels indicate behavior similar to normal user characteristics and can be allowed to proceed directly to ensure service availability and access speed; while connections with high initial anomaly levels may exhibit abnormal or attack behavior and require in-depth analysis or further verification processes to determine their true nature through more refined detection methods, thereby improving interception accuracy while ensuring user experience.
[0077] The overall traffic of a live stream typically fluctuates with the popularity of the streamer. When a top streamer goes live, it attracts a large number of viewers to enter the live stream simultaneously, causing a rapid increase in the bandwidth of that live stream. Therefore, an increase in the rate of increase in the server's macro bandwidth does not necessarily mean that there is an attack. It could also be a normal traffic increase caused by a popular streamer going live. Therefore, it is necessary to combine single-source behavior and historical traffic patterns to distinguish between genuine peak traffic and potential abnormal traffic.
[0078] The following embodiment will still use a single live streaming room as an example for explanation. The method provided in this embodiment can be used to process other live streaming rooms.
[0079] Specifically, any live stream room will be designated as the live stream room to be analyzed.
[0080] For any given moment when the live stream to be analyzed begins: the average initial anomaly score of all connections in the live stream at that moment is taken as the connection anomaly index for that moment. A high connection anomaly index indicates that the overall initial anomaly score of connections within the live stream is high, meaning that some connections or IP sources are generating significantly higher-than-average downlink traffic or connection activity. This phenomenon typically indicates uneven traffic distribution, with downlink bandwidth concentrated on a few IPs, potentially indicating concentrated streaming, malicious requests, or abnormal access behavior. Therefore, an increase in the connection anomaly index can be seen as a signal that the live stream is experiencing potential abnormal traffic aggregation or attack tendencies at that moment.
[0081] In some network environments (such as carrier NAT, enterprise LANs, etc.), multiple real users may share the same IP address. In such cases, simply relying on the connection anomaly index may misjudge normal high-concurrency access as abnormal traffic. To avoid this, a historical comparison mechanism needs to be introduced. This involves assessing the difference or offset based on the recent connection anomaly index trends at multiple points in the live stream, thereby quantifying the degree of connection anomaly at that moment.
[0082] Specifically, the difference between the connection anomaly index of the live room to be analyzed at that moment and the average of the initial anomaly indices of all connections at the moments corresponding to the same broadcast duration during the historical broadcasting process of the live room to be analyzed is recorded as the first difference; the normalized result of the first difference is used as the initial connection anomaly degree of the live room to be analyzed at that moment.
[0083] If the initial connection anomaly of the live stream room at that moment differs significantly from the historical average or baseline, it is more likely to reflect abnormal clustering behavior; if the difference is small, it can be regarded as normal fluctuation, thus effectively distinguishing between normal traffic concentration and abnormal attack clustering, and improving the accuracy and stability of detection.
[0084] Given that the number of connections and bandwidth fluctuations in a live stream are closely related to the streamer's real-time popularity, and considering that in today's data-driven era, the spread of topics on social media, short video pushes, and changes in trending topics significantly impact a streamer's exposure and the speed of audience influx, thus causing instantaneous fluctuations in live stream traffic, indiscriminately treating these natural traffic spikes caused by social media as abnormal could easily lead to misjudgments. Therefore, it is necessary to conduct correlation analysis between streamers and social media information. By identifying trends in a streamer's popularity on social media platforms, their engagement in topics, or their content dissemination index, the rationality of their popularity fluctuations can be assessed. This allows for dynamic correction of the initially determined connection anomaly level, enabling the protection system to adapt to natural fluctuations in business popularity while maintaining interception accuracy.
[0085] The analysis process involves acquiring the livestream topic of the livestream room to be analyzed. The livestream topic can be determined through the livestream title, description, tags, and the broadcaster's semantics, such as extracting keywords. Simultaneously, it involves acquiring various trending topics in society. One implementation method is to use a temporal fusion multimodal model, employing a multi-head cross-attention mechanism to calculate the similarity between the livestream topic and each trending topic. The maximum similarity between the livestream topic and all trending topics is taken as the relevance between the livestream topic and the trending topics. Another implementation method is to calculate the similarity between the word vectors of the livestream topic and the word vectors of each trending topic, and take the maximum similarity as the relevance between the livestream topic and the trending topics. The relevance value ranges from [0, 1]. The method for obtaining word vectors is existing technology and will not be elaborated further here.
[0086] Then, by utilizing the relevance between the live stream topic and trending topics in the live stream to be analyzed, the initial connection anomaly of the live stream to be analyzed at that moment is corrected to obtain the comprehensive connection anomaly of the live stream to be analyzed at that moment.
[0087] As a specific example, the difference between the constant 1 and the correlation between the live topic and the trending topic in the live room to be analyzed is used as a correction coefficient; the initial connection anomaly is corrected using the correction coefficient to obtain the comprehensive connection anomaly of the live room to be analyzed at that moment.
[0088] As a concrete example, the specific formula for calculating the comprehensive connectivity anomaly is given. The comprehensive connectivity anomaly of the live stream at time b can be expressed as:
[0089]
[0090] in, This represents the overall connectivity anomaly score of the live stream at time b. This indicates the connection anomaly level of the live stream at time b. This represents the average initial anomaly score of all connections at the moment corresponding to the b-th moment of the live stream's historical broadcast history. This indicates the degree of relevance between the topics discussed in the live stream and trending topics to be analyzed. This represents the normalization function.
[0091] This represents the initial connection anomaly degree of the live stream at time b. This represents the correction factor.
[0092] As a specific example, the average initial anomaly score of all connections at the moment corresponding to the b-th moment of the live stream's historical broadcast history can be determined as follows: Specifically, the initial anomaly scores of all connections at the moment corresponding to the b-th moment of the live stream's historical broadcast history are obtained, and the average of these initial anomaly scores is taken as the average initial anomaly score of all connections at the moment corresponding to the b-th moment of the live stream's historical broadcast history.
[0093] If the correlation between the live stream topic and the trending topics in the live stream room to be analyzed is higher, it indicates that the live stream topic of the host in the live stream room is more correlated with the trending topics. The increase in connection anomaly is a normal phenomenon. Therefore, the correlation between the live stream topic and the trending topics in the live stream room to be analyzed is used to correct the initial connection anomaly and obtain the comprehensive connection anomaly.
[0094] Through the above steps, the overall connection anomaly level of each live broadcast room at each time was obtained.
[0095] Step S4: Combine the bandwidth rise time of all live streaming servers during the current live streaming process of the live streaming room to be defended, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connection to determine the overall anomaly index of the suspected abnormal connection of the live streaming room to be defended.
[0096] If, at a certain moment, the overall connection anomaly level of multiple live streaming rooms increases simultaneously, and this corresponds to a sharp increase in the overall server bandwidth, it indicates that the traffic anomalies in these live streaming rooms are synchronous and concentrated, and are more likely to originate from external attacks. Conversely, if the overall bandwidth remains stable or the upward trend is not significantly correlated with the anomalies in individual live streaming rooms, the anomaly is more likely caused by changes in business traffic. Therefore, it is necessary to perform a matching analysis between the overall connection anomaly level of each live streaming room and the overall server bandwidth increase rate to achieve a comprehensive judgment from local anomalies to global attacks, thereby enabling the screening of malicious attacks on the live streaming rooms to be defended.
[0097] For any live stream currently being broadcast and subject to defense:
[0098] The time when the server's bandwidth reaches its maximum value during the current live stream of the live stream to be defended is recorded as the end time of the rising interval. The minimum bandwidth of the server with the closest time interval before the end time of the rising interval is taken as the start time of the rising interval. The time interval between the start time and the end time is taken as the bandwidth rising interval of the live stream. The method for obtaining the minimum bandwidth of the server with the closest time interval before the end time of the rising interval is as follows: Curve fitting is performed on the bandwidth of the live stream at all times during the current live stream of the live stream to be defended, obtaining a fitted curve. The horizontal axis of the fitted curve represents time, and the vertical axis represents bandwidth. The minimum point on the fitted curve is obtained, and the first minimum point on the fitted curve is taken as the minimum bandwidth of the server with the closest time interval before the end time of the rising interval. This minimum point is a local minimum point, representing a low-water level state before the abnormal traffic surge, used to define the time span of the attack wave. The curve fitting and minimum point acquisition methods are existing technologies and will not be elaborated further here.
[0099] The normalized result of the difference in bandwidth between the start and end times of the live stream on the server of the live stream to be defended is determined as the degree of increase of the live stream in the bandwidth increase range; wherein, the difference in bandwidth between the start and end times of the live stream on the server of the live stream to be defended is the absolute value of the difference between the bandwidth of the server at these two times. In this embodiment, the normalization process for the data adopts the maximum-minimum value normalization method, which is a prior art and will not be described in detail here.
[0100] The moment when the overall connection anomaly of the live stream room increases at the highest rate is recorded as the relevant judgment moment for the live stream room. Based on the relevant judgment moment of the live stream room, the time distribution of the bandwidth increase interval of the live stream room, and the degree of increase of the live stream room within the bandwidth increase interval, the correlation of the abnormal increase of the live stream room is determined.
[0101] As a specific example, if the relevant judgment time of the live broadcast room is within the bandwidth increase range of the live broadcast room, then the product of the increase degree of the live broadcast room in the bandwidth increase range and the comprehensive connection anomaly degree of the relevant judgment time of the live broadcast room is taken as the abnormal increase correlation of the live broadcast room; if the relevant judgment time of the live broadcast room is not within the bandwidth increase range of the live broadcast room, then the abnormal increase correlation of the live broadcast room is set to 0.
[0102] Because DDoS attacks in live streaming scenarios are typically characterized by concentrated targeting and synchronized timing, attack traffic often concentrates on a small number of live streams, causing a synchronized increase in connection anomalies within these streams over a short period. Therefore, by clustering the correlation of anomalies across all live streams, groups of live streams with similar anomaly trends can be identified. If live streams in a certain cluster exhibit a high average anomaly correlation during bandwidth increases, it indicates that the anomalies in these live streams are consistent and highly likely to be caused by attacks from the same source or affected by the same wave of DDoS traffic. Based on this, the system can determine whether a server is under concentrated attack by using the average anomaly correlation of this cluster, thereby achieving more accurate anomaly identification and protection triggering.
[0103] Using the above methods, each live stream in the current live stream process of the defense live stream room is analyzed to obtain the abnormal increase correlation of each live stream room.
[0104] Furthermore, based on the abnormal upward correlation of each live stream, the DBSCAN clustering algorithm is used to cluster all live streams to obtain multiple clusters. The abnormal upward correlation of live streams within the same cluster is relatively similar, while the abnormal upward correlation of live streams in different clusters varies significantly. The average abnormal upward correlation of all live streams within each cluster is calculated, and the average abnormal upward correlation of the cluster with the highest average abnormal upward correlation is taken as the overall abnormal correction degree. In this embodiment, when using the DBSCAN clustering algorithm, the neighborhood radius of the DBSCAN algorithm is set to 0.05, indicating that when the absolute difference in the abnormal upward correlation of two live streams is less than 0.05, they are considered to be spatially adjacent; the minimum number of points is set to 3, indicating that a cluster contains at least 4 live streams; the DBSCAN clustering algorithm is existing technology and will not be described in detail here.
[0105] For any suspected abnormal connection to the live streaming server under defense at any given moment, the greater the overall anomaly correction degree of that suspected abnormal connection, the more likely the live streaming server is currently under attack, and the more necessary it is to intercept connections with high anomalies. Based on this characteristic, the product of the initial anomaly degree and the overall anomaly correction degree of that suspected abnormal connection at the current moment is used as the overall anomaly index of that suspected abnormal connection.
[0106] Using the above method, the overall anomaly index of each suspected abnormal connection in the live broadcast room to be defended at the current moment can be obtained.
[0107] Step S5: Defend against network attacks on the server's live streaming service based on the overall anomaly index.
[0108] The above steps obtained the overall anomaly index of each suspected abnormal connection in the live broadcast room to be defended at the current moment. The larger the overall anomaly index, the more likely the corresponding suspected abnormal connection is an abnormal attack.
[0109] As a specific example, for each suspected abnormal connection in the live stream to be defended at the current moment, if the overall abnormality index is greater than or equal to the preset abnormality threshold, it means that the corresponding suspected abnormal connection is a malicious attack rather than normal live stream viewing. Therefore, the corresponding suspected abnormal connection will be blocked. If the overall abnormality index is less than the preset abnormality threshold, it means that the corresponding suspected abnormal connection is normal live stream viewing behavior. Therefore, the corresponding suspected abnormal connection will be allowed to pass, that is, it will not be blocked.
[0110] As a concrete example, the preset anomaly threshold can be determined as follows: Specifically, collect the overall anomaly index of multiple connections confirmed to have malicious attacks (abnormal connections) during historical live streams. Then, statistically analyze the distribution characteristics of the overall anomaly index of all these abnormal connections. Based on this distribution characteristic, set the preset anomaly threshold to an overall anomaly index that can effectively distinguish between abnormal and normal connections. This method of determining the preset anomaly threshold based on the statistical analysis results of the overall anomaly index of confirmed abnormal connections during historical live streams allows the preset anomaly threshold to better filter abnormal connections and improve the accuracy of attack defense. As another concrete example, the preset anomaly threshold can also be directly set to an empirical value of 0.6.
[0111] Thus, the method provided in this embodiment has achieved defense against network attacks.
[0112] This embodiment combines the upward trend of the live stream server bandwidth with bandwidth data within a local time period to conduct a preliminary evaluation of the anomalies in the connection between the viewer and the live stream server, obtaining an initial anomaly score. It also performs preliminary screening of all connections, effectively identifying high-risk suspected anomaly connections. These high-risk connections can be analyzed and processed in depth without requiring comprehensive testing of all connections, thus significantly improving processing efficiency and real-time response capabilities while ensuring security. Furthermore, by combining the differences in initial anomaly scores during the historical broadcasts of the live stream with the relevance of the live stream topic to trending topics, a comprehensive evaluation of traffic anomalies at each moment is obtained, yielding a comprehensive connection anomaly score. However, considering that if the comprehensive connection anomaly scores of multiple live streams simultaneously increase at a certain moment, corresponding to a sharp increase in the overall server bandwidth, it is possible to... The synchronous and concentrated nature of the abnormal traffic in these live streaming rooms suggests that they are more likely to originate from external attacks. If the overall bandwidth remains stable or shows an upward trend without a significant correlation with the anomalies in individual live streaming rooms, then the anomaly is more likely caused by changes in business traffic. Therefore, by further combining the bandwidth rise time, the overall connection anomaly degree, and the initial anomaly degree of suspected abnormal connections, the overall anomaly index of suspected abnormal connections in the live streaming rooms to be defended was determined. The overall anomaly index can accurately distinguish between normal traffic peaks and malicious attacks, reducing the false positive rate of malicious attacks. Therefore, the method provided in this embodiment can dynamically assess the overall security status of the server to be defended, achieve timely and effective interception of network attacks, improve the effectiveness of network attack defense, and ensure the continuity and stability of the live streaming service.
[0113] An embodiment of a server-oriented network attack defense system:
[0114] See Figure 2 The diagram illustrates a structural block diagram of a server-oriented network attack defense system according to an embodiment of the present invention. The system may include a data acquisition module, a suspected abnormal connection screening module, a comprehensive connection anomaly determination module, an overall anomaly index evaluation module, and an attack defense module.
[0115] The data acquisition module is used to acquire the bandwidth of each live streaming server and the connection status between the audience and the live streaming server.
[0116] The suspected abnormal connection filtering module is used to evaluate the initial abnormality of each connection between the viewer and each live streaming server based on the bandwidth increase of the server at each moment during each connection and the bandwidth within a local time period; and to filter suspected abnormal connections at each moment based on the initial abnormality.
[0117] The comprehensive connection anomaly determination module is used to obtain the comprehensive connection anomaly of each live broadcast room at each moment based on the difference between the initial anomaly of the connection at a single moment and the initial anomaly of the connection at the corresponding moment during the historical broadcast of each live broadcast room, as well as the relevance of the live broadcast topic to the hot topic.
[0118] The overall anomaly index evaluation module is used to determine the overall anomaly index of the suspected abnormal connections of the live streaming room to be defended by combining the bandwidth rise time of all live streaming room servers during the current live streaming process, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connections.
[0119] The attack defense module is used to defend against network attacks on the server's live streaming service based on the overall anomaly index.
[0120] It should be understood that Figure 2 The structural block diagram and modules of the server-oriented network attack defense system shown can be implemented in various ways. For example, in some embodiments, the system and its modules can be implemented by hardware, software, or a combination of both. The hardware portion can be implemented using dedicated logic; the software portion can be stored in memory and executed by appropriate instructions, such as a microprocessor or dedicated hardware. Those skilled in the art will understand that the above-described methods and apparatus can be implemented using computer-executable instructions and / or included in processor control code, for example, such code provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The apparatus and modules of this specification can be implemented not only by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, or programmable hardware devices such as field-programmable gate arrays, programmable logic devices, etc., but also by software, for example, executed by various types of processors, or by a combination of the above-described hardware circuits and software (e.g., firmware).
[0121] For more details about the above modules, please refer to other parts of this manual; they will not be repeated here.
[0122] In other embodiments, a storage medium is also provided, which stores computer program code. When the computer program code is run on a computer, the computer executes the above-described method steps to implement the server-oriented network attack defense method provided in the above embodiments.
[0123] The system and storage medium provided are used to execute the corresponding methods described above. Therefore, the beneficial effects they can achieve can be referred to in the beneficial effects described in the corresponding methods described above, and will not be repeated here.
[0124] It should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A server-oriented network attack defense method, characterized in that, The method includes the following steps: Obtain the bandwidth of each live streaming server and the connection status between viewers and the live streaming server; Based on the bandwidth increase of the server at each moment during each connection between the viewer and each live streaming server, and the bandwidth within a local time period, the initial anomaly level of each connection between the viewer and each live streaming server is evaluated; suspected abnormal connections at each moment are screened based on the initial anomaly level. The overall connection anomaly of each live stream room at each moment is obtained based on the difference between the initial anomaly of a single connection at a single moment and the initial anomaly of the connection at the corresponding moment during the historical broadcast of each live stream room, as well as the correlation between the live stream topic and the hot topic. By combining the bandwidth rise time of all live streaming servers during the current live streaming process of the live streaming room to be defended, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connection, the overall anomaly index of the suspected abnormal connection of the live streaming room to be defended is determined. Based on the overall anomaly index, defenses are implemented against network attacks on the server's live streaming service.
2. The server-oriented network attack defense method according to claim 1, characterized in that, The evaluation of the initial anomaly level at each moment of each connection between the viewer and each live streaming server, based on the bandwidth increase of the server at each time point during each connection and the bandwidth within a local time period, includes: For any live stream room: The bandwidth increase rate of the server of any live room at the candidate time is determined based on the bandwidth increase of the candidate time relative to the previous time. The candidate time is any time in any connection between the viewer and the server of any live room. Based on the downlink bandwidth corresponding to the viewer's IP connected to the server of any live room within a local time period of the candidate moment, and the bandwidth increase rate, the initial anomaly degree of the candidate moment in any connection between the viewer and the server of any live room is obtained.
3. The server-oriented network attack defense method according to claim 2, characterized in that, The method of filtering suspected abnormal connections at each time point based on the initial abnormality includes: if the initial abnormality is greater than the first abnormality threshold, then the current connection between the viewer and the live streaming server is determined to be a suspected abnormal connection at the candidate time point.
4. The server-oriented network attack defense method according to claim 1, characterized in that, The comprehensive connection anomaly of each live stream at each moment is obtained based on the difference between the initial anomaly of a single connection at a given moment and the initial anomaly of the connection at the corresponding moment during the historical broadcasting process of each live stream room, as well as the correlation between the live stream topic and trending topics. This includes: For any given moment: The average of the initial anomalies of all connections at any given moment in the live stream to be analyzed is taken as the connection anomaly index at any given moment in the live stream to be analyzed. Calculate the first difference between the connection anomaly index of the live stream room to be analyzed at any given time and the average connection anomaly index of all connections at the time corresponding to the same broadcast duration during the historical broadcasting process of the live stream room to be analyzed; use the normalized result of the first difference as the initial connection anomaly degree of the live stream room to be analyzed at any given time. By utilizing the correlation between the live topics in the live room to be analyzed and the trending topics, the initial connection anomaly score is corrected to obtain the comprehensive connection anomaly score of the live room to be analyzed at any given time. The live stream room to be analyzed can be any live stream room.
5. The server-oriented network attack defense method according to claim 4, characterized in that, The process of correcting the initial connection anomaly score by utilizing the correlation between the live stream topic and trending topics in the live stream to obtain the comprehensive connection anomaly score of the live stream at any given time includes: The difference between the constant 1 and the degree of correlation is used as a correction coefficient; The initial connection anomaly score is corrected using the correction coefficient to obtain the comprehensive connection anomaly score of the live streaming room at any given time.
6. The server-oriented network attack defense method according to claim 1, characterized in that, The overall anomaly index of suspected abnormal connections in the live stream room to be defended is determined by combining the bandwidth rise time of all live stream servers during the current live stream, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connections. This includes: For any live stream currently being broadcast and subject to defense: Obtain the time when the bandwidth of the server reaches its maximum value during the current live broadcast of any live room to be defended, and record this time as the end time of the rising interval; take the minimum bandwidth of the server with the closest time interval before the end time of the rising interval as the start time of the rising interval; obtain the bandwidth rising interval of any live room based on the start time and the end time. The normalized result of the difference in bandwidth between the servers of any live streaming room at the start time and the end time is determined as the degree of increase of any live streaming room in the bandwidth increase range. The moment when the growth rate of the comprehensive connection anomaly degree of any of the live streaming rooms is the largest is recorded as the relevant judgment moment of any of the live streaming rooms. Based on the time distribution of the relevant judgment time of any live room and the bandwidth increase interval of any live room, as well as the degree of increase, the abnormal increase correlation of any live room is determined. By combining the similarity between the abnormal increase in correlation of the live room to be defended and the abnormal increase in correlation of other live rooms, and the initial abnormality of the suspected abnormal connections of the live room server at each time point, the overall abnormality index of the suspected abnormal connections of the live room to be defended is obtained.
7. The server-oriented network attack defense method according to claim 6, characterized in that, The overall anomaly index of the suspected abnormal connections in the live stream to be defended is obtained by considering the similarity between the abnormal increase in correlation of the live stream to be defended and other live streams, as well as the initial anomaly degree of each time point in the suspected abnormal connections of the live stream server to be defended. This index includes: Based on the abnormal increase correlation of each live room, the DBSCAN clustering algorithm is used to cluster all live rooms to obtain each cluster; the average abnormal increase correlation of the cluster with the largest average abnormal increase correlation is taken as the overall abnormal correction degree. For any suspected abnormal connection of the live streaming server to be defended at the current moment, the product of the initial abnormality degree of the suspected abnormal connection of the live streaming server to be defended at the current moment and the overall abnormality correction degree is used as the overall abnormality index of the suspected abnormal connection of the live streaming server to be defended.
8. The server-oriented network attack defense method according to claim 7, characterized in that, The defense against network attacks on the server live streaming service based on the overall anomaly index includes: If the overall anomaly index is greater than or equal to the preset anomaly threshold, the corresponding suspected abnormal connection will be intercepted. If the overall anomaly index is less than the preset anomaly threshold, the corresponding suspected abnormal connection will be allowed to proceed.
9. A server-oriented network attack defense system, the system being used to implement the method of claim 1, characterized in that, The system includes: The data acquisition module is used to acquire the bandwidth of each live streaming server and the connection status between the audience and the live streaming server. The suspected abnormal connection filtering module is used to evaluate the initial abnormality of each connection between the viewer and each live streaming server based on the bandwidth increase of the server at each moment during each connection and the bandwidth within a local time period; and to filter suspected abnormal connections at each moment based on the initial abnormality. The comprehensive connection anomaly determination module is used to obtain the comprehensive connection anomaly of each live broadcast room at each moment based on the difference between the initial anomaly of the connection at a single moment and the initial anomaly of the connection at the corresponding moment during the historical broadcast of each live broadcast room, as well as the relevance of the live broadcast topic to the hot topic. The overall anomaly index evaluation module is used to determine the overall anomaly index of the suspected abnormal connections of the live streaming room to be defended by combining the bandwidth rise time of all live streaming room servers during the current live streaming process, the comprehensive connection anomaly degree, and the initial anomaly degree of each moment in the suspected abnormal connections. The attack defense module is used to defend against network attacks on the server's live streaming service based on the overall anomaly index.
10. A storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements a server-oriented network attack defense method as described in claim 1.