Traffic reinjection method and device, computer equipment, readable storage medium and program product
By querying the public network protocol address table in the anti-attack switch to perform Layer 2 back injection, the problems of wasted public network IP resources and complex configuration in the existing technology are solved, and the configuration and efficient management of the cleaning server are simplified, supporting standardized deployment across clusters and regions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-05
- Publication Date
- 2026-03-10
AI Technical Summary
In existing Layer 2 back-injection schemes for anti-DDoS systems, the scrubbing server needs to be configured with a public IP address corresponding to the network segment of the business it serves, which leads to a waste of public IP address resources. Furthermore, the configuration and maintenance are complex, making it difficult to achieve flexible deployment and efficient management across clusters and regions.
By establishing a private network protocol connection between the cleaning server cluster and the anti-attack switch, the anti-attack switch queries the pre-configured public network protocol address table, identifies the target public network segment of compliant traffic, and performs Layer 2 back injection, thus avoiding the cleaning server from configuring public network segment addresses and centrally managing public network segment information.
It enables centralized management of public network address segments, simplifies the configuration and maintenance of cleaning servers, improves system flexibility and delivery efficiency, reduces configuration complexity, and supports standardized deployment across clusters and regions.
Smart Images

Figure CN121644176A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to a traffic back-annotating method and device, a computer device, a readable storage medium and a program product. BACKGROUND
[0002] With the development of cloud computing and Internet services, the security threats faced by network services are also increasingly severe. Among them, the distributed denial of service attack (DDoS) has become one of the key prevention objects due to its large attack strength and wide influence range. To cope with such attacks, the related technology usually adopts a two-layer back-annotation scheme of an Anti-DDoS protection system, which realizes the identification and filtering of abnormal traffic through traffic traction, cleaning and back-annotation mechanisms, and guarantees the continuity of normal services. However, the two-layer back-annotation scheme of the current Anti-DDoS system requires the cleaning server to be configured with a public network IP (Internet Protocol) address corresponding to the business network segment it serves, so as to correctly respond to the address resolution protocol request and participate in the two-layer back-annotation in the back-annotation process.
[0003] Therefore, the two-layer back-annotation scheme of the Anti-DDoS system of the related technology has the problem of waste of public network IP address resources. SUMMARY
[0004] Therefore, it is necessary to provide a traffic back-annotation method, device, computer device, computer readable storage medium and computer program product capable of reducing resource waste in view of the above technical problems.
[0005] In a first aspect, the present application provides a traffic back-annotation method, comprising:
[0006] In the case of abnormal traffic attack on the public network, compliant traffic back-annotated by a cleaning server cluster is received through a private network protocol; the cleaning server cluster is connected to the private network protocol configured by the back-annotation plane of the attack-resistant switch, and the cleaning server cluster includes a plurality of cleaning servers;
[0007] According to the compliant traffic, a target public network segment is obtained by querying a pre-configured public network protocol address table; the public network protocol address table includes a plurality of public network segments;
[0008] The compliant traffic is back-annotated to the protected network according to the target public network segment.
[0009] In one of the embodiments, before the compliant traffic back-annotated by the cleaning server cluster is received through the private network protocol in the case of abnormal traffic attack on the public network, the method further comprises:
[0010] Receive abnormal host routes from the cleaning server cluster;
[0011] The abnormal host route is sent to the core switch to instruct the core switch to redirect the abnormal traffic of the abnormal host route to the cleaning server cluster; the anti-attack switch is connected to the public network through the core switch.
[0012] In one embodiment, the step of querying a pre-configured public network protocol address table to obtain the target public network segment based on the compliant traffic includes:
[0013] The compliant traffic is parsed to obtain the target public IP address of the compliant traffic;
[0014] Based on the target public network protocol address, query the pre-configured public network protocol address table to obtain the target public network segment corresponding to the target public network protocol address.
[0015] In one embodiment, the step of injecting the compliant traffic back to the protected network via virtual routing according to the target public network segment includes:
[0016] The physical address of the protected network is determined by performing Layer 2 addressing based on the target public network segment.
[0017] Based on the physical address, the compliant traffic is injected back into the protected network via Layer 2.
[0018] In one embodiment, the flow reinjection method further includes:
[0019] When adding a new cleaning server to the cleaning server cluster, configure the private network protocol and gateway for the new cleaning server;
[0020] In this configuration, there is no conflict between the private network protocols of the various cleaning servers in the cleaning server cluster, and the gateways are configured identically.
[0021] In one embodiment, the flow reinjection method further includes:
[0022] In response to the public network segment update operation, the public network segment to be updated is obtained;
[0023] Based on the public network segment to be updated, the public network protocol address table is updated to obtain the updated public network protocol address table.
[0024] Secondly, this application also provides a traffic reinjection device for use in anti-attack switches, comprising:
[0025] The traffic receiving module is used to receive compliant traffic injected back from the scrubbing server cluster via a private network protocol in the event of abnormal traffic attacks on the public network. The scrubbing server cluster is connected to the private network protocol configured on the injection plane of the anti-attack switch, and the scrubbing server cluster includes multiple scrubbing servers.
[0026] The network segment determination module is used to query a pre-configured public network protocol address table based on the compliant traffic to obtain the target public network segment; the public network protocol address table includes multiple public network segments;
[0027] The traffic reinjection module is used to reinject the compliant traffic back to the protected network according to the target public network segment.
[0028] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0029] In the event of abnormal traffic attacks on the public network, compliant traffic is received from the scrubbing server cluster via a private network protocol; the scrubbing server cluster is connected to the private network protocol configured on the injection plane of the anti-attack switch, and the scrubbing server cluster includes multiple scrubbing servers.
[0030] Based on the compliant traffic, a pre-configured public network protocol address table is queried to obtain the target public network segment; the public network protocol address table includes multiple public network segments;
[0031] According to the target public network segment, the compliant traffic is injected back into the protected network.
[0032] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0033] In the event of abnormal traffic attacks on the public network, compliant traffic is received from the scrubbing server cluster via a private network protocol; the scrubbing server cluster is connected to the private network protocol configured on the injection plane of the anti-attack switch, and the scrubbing server cluster includes multiple scrubbing servers.
[0034] Based on the compliant traffic, a pre-configured public network protocol address table is queried to obtain the target public network segment; the public network protocol address table includes multiple public network segments;
[0035] According to the target public network segment, the compliant traffic is injected back into the protected network.
[0036] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, performs the following steps:
[0037] In the event of abnormal traffic attacks on the public network, compliant traffic is received from the scrubbing server cluster via a private network protocol; the scrubbing server cluster is connected to the private network protocol configured on the injection plane of the anti-attack switch, and the scrubbing server cluster includes multiple scrubbing servers.
[0038] Based on the compliant traffic, a pre-configured public network protocol address table is queried to obtain the target public network segment; the public network protocol address table includes multiple public network segments;
[0039] According to the target public network segment, the compliant traffic is injected back into the protected network.
[0040] The aforementioned traffic reinjection method, apparatus, computer equipment, computer-readable storage medium, and computer program product, wherein the method involves an anti-attack switch receiving compliant traffic reinjected by a scrubbing server cluster via a private network protocol when an abnormal traffic attack occurs on the public network, wherein the scrubbing server cluster is connected to the anti-attack switch via the private network protocol configured in the reinjection plane, and the scrubbing server cluster includes multiple scrubbing servers; furthermore, the anti-attack switch queries a pre-configured public network protocol address table based on the compliant traffic to obtain a target public network segment, wherein the public network protocol address table includes multiple public network segments, and reinjects the compliant traffic into the protected network according to the target public network segment. By connecting the scrubbing server cluster and the anti-attack switch based on a private network protocol, the scrubbing server cluster does not need to be configured with any public network address segments. It only needs to send the scrubbed and compliant traffic to the anti-attack switch through the private network channel. The anti-attack switch, by querying its pre-configured public network address table containing multiple public network segments, identifies the target public network segment to which the traffic belongs and completes Layer 2 back injection. This achieves centralized management of public network address segments, thereby avoiding the waste of public network address resources. At the same time, it simplifies the configuration and maintenance complexity of the scrubbing server, greatly improves flexibility and delivery efficiency, and enables the standardization of configuration that traditional Layer 2 back injection schemes cannot achieve. Attached Figure Description
[0041] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0042] Figure 1 This is a diagram illustrating the application environment of the flow reinjection method in one embodiment;
[0043] Figure 2 This is a flowchart illustrating a flow reinjection method in one embodiment;
[0044] Figure 3 This is a schematic diagram of a system architecture for defending against distributed denial-of-service attacks in one embodiment;
[0045] Figure 4 This is a structural block diagram of a flow reinjection device in one embodiment;
[0046] Figure 5 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0047] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0048] As described in the background section, the traffic re-injection methods of related technologies suffer from problems such as wasted public IP addresses, difficult configuration and maintenance, and low delivery efficiency. The inventors have discovered that these problems arise because, with the development of cloud computing and internet services, network services face increasingly severe security threats. Among these, distributed denial-of-service (DDoS) attacks, due to their high attack intensity and wide impact, have become a key target for prevention. To combat such attacks, related technologies typically employ anti-DDoS protection systems, using mechanisms such as traffic redirection, cleaning, and re-injection to identify and filter abnormal traffic, ensuring the continuity of normal business operations. However, in current anti-DDoS Layer 2 re-injection schemes, the cleaning server needs to be configured with a public IP address corresponding to the network segment it serves in order to correctly respond to Address Resolution Protocol (ARP) requests and participate in Layer 2 re-injection during the re-injection process. The current Layer 2 re-injection schemes have the following significant drawbacks: In the current Layer 2 re-injection schemes, each cleaning server needs to be configured with an IP address for each public network segment in the resource pool to achieve Layer 2 forwarding of business traffic during re-injection. For example, if a scrubbing cluster contains 4 scrubbing servers and the resource pool has 6 public network service segments, it will consume a total of 4 × 6 = 24 public IP addresses. These addresses are not used for actual services in business operations, but are only consumed for Layer 2 injection functionality, resulting in a waste of public IP resources. Furthermore, when business network segments are added, deleted, or adjusted, operations personnel must synchronously modify the IP configuration of each scrubbing server. In scenarios with a large number of scrubbing servers or frequent changes in business network segments, such operations are not only labor-intensive but also prone to injection anomalies due to inconsistent configurations, which will directly lead to business interruptions. If the scrubbing cluster needs to be expanded, i.e., adding scrubbing servers, the new servers still need to be allocated public IP addresses for all business network segments, further increasing configuration complexity and address management burden. Since the business network segments of different resource pools are different, scrubbing servers must be configured with corresponding public IP addresses for each cluster individually, making it impossible to form a unified configuration template. This increases the configuration difficulty of anti-DDoS systems when deployed across clusters and regions, reduces delivery efficiency, and is also detrimental to later maintenance and automated management. In multi-layer or hybrid network scenarios, such as when multiple resource pools are connected to a core switch, traditional Layer 2 back-injection solutions are often inflexible and require a lot of manual configuration and policy adjustment, which is difficult to implement and prone to errors.
[0049] For the reasons mentioned above, this application provides a traffic back-injection method, which aims to reduce resource waste, lower configuration and maintenance complexity, improve configuration flexibility, enhance scheme adaptability, and enable configuration standardization that cannot be achieved by traditional Layer 2 back-injection schemes.
[0050] The flow reinjection method provided in this application embodiment can be applied to, for example, Figure 1The application environment shown includes: an anti-attack switch 101, a cleaning server cluster 102, a core switch 103, a public network 104, and a protected network 105. The anti-attack switch 101 and the cleaning server cluster 102 are connected via a private network protocol. The anti-attack switch 101 is connected to both the core switch 103 and the protected network via the network, and the core switch 103 is connected to both the public network 104 and the protected network 105 via the network. The cleaning server cluster 102 can be a server cluster or a distributed system consisting of multiple servers.
[0051] based on Figure 1 In the application environment shown, under the condition of abnormal traffic attack on public network 104, the anti-attack switch 101 receives compliant traffic injected back by the cleaning server cluster 102 through a private network protocol. The cleaning server cluster 102 is connected to the anti-attack switch through the private network protocol and includes multiple cleaning servers. The anti-attack switch 101 queries a pre-configured public network protocol address table based on the compliant traffic to obtain the target public network segment. The public network protocol address table includes multiple public network segments. The anti-attack switch injects the compliant traffic back to the protected network 105 through virtual routing according to the target public network segment.
[0052] In one exemplary embodiment, such as Figure 2 As shown, a flow reinjection method is provided, which can be applied to... Figure 1 Taking the anti-attack switch 101 as an example, the explanation includes the following steps S202 to S206. Wherein:
[0053] Step S202: In the event of an abnormal traffic attack on the public network, receive compliant traffic injected back by the cleaning server cluster via a private network protocol.
[0054] The scrubbing server cluster comprises multiple scrubbing servers. The anti-DDoS switch is a network device with advanced routing control and VRF (Virtual Routing and Forwarding) isolation capabilities. As the core of the anti-DDoS system's traffic scheduling, it is responsible for reinjecting scrubbed, compliant traffic back to the original network. In essence, by binding VRF functionality, the anti-DDoS switch can isolate the redirected traffic from the compliant traffic to be reinjected, preventing anomalies. Its key functions include BGP (Border Gateway Protocol) routing control, VRF management, and Layer 2 proxy forwarding.
[0055] Among them, "public network" can refer to the public network space of the Internet, which uses globally routable public IP addresses for communication, and specifically refers to the network environment in which user services provide services to the outside world; "abnormal traffic" can refer to malicious and illegal network data streams caused by DDoS attacks.
[0056] The cleaning server cluster is connected to the injection plane of the anti-attack switch via a private network protocol.
[0057] Private network protocols refer to the network and transport layer mechanisms that enable communication between the scrubbing server cluster and the anti-attack switch based on private IP address ranges. These mechanisms mainly include using private IP addresses for communication, configuring a default gateway to point to the anti-attack switch, and possibly combining IBGP (Internal BGP) to achieve routing interaction, thereby ensuring secure connectivity between the control plane and the data plane. Compliant traffic refers to legitimate user request traffic that has been processed by the scrubbing server cluster, with all attack components removed, and conforming to the characteristics of normal business communication.
[0058] Optionally, the detection server of the anti-DDoS system detects traffic on the public network. If abnormal traffic attacks are detected, the detection server issues a traffic diversion policy to the cleaning server cluster, instructing the cleaning server cluster to divert the abnormal traffic to the cleaning server cluster for abnormal traffic cleaning. Furthermore, the anti-attack switch receives compliant traffic that has been cleaned and processed by the cleaning server cluster after being injected by the cleaning server cluster through a private network protocol.
[0059] Traffic redirection refers to the process of dynamically redirecting all traffic corresponding to a public network route from its original public network path to a scrubbing server cluster when an attack is detected. This process is achieved by publishing precise 32-bit host routes, ensuring that only the traffic of the target route is redirected, while other services remain unaffected. The traffic redirection strategy can be a set of rules that guides when to initiate traffic redirection and which IPs to protect. In this embodiment, the traffic redirection strategy is triggered by the anti-attack switch, manifested as the scrubbing server announcing a / 32-bit host route for a specific public network IP to the anti-attack switch, which then passes this information to the core switch to change the routing path.
[0060] It is understandable that, in addition to the traffic diversion method where the detection server performs anomaly detection on public network traffic and dynamically redirects it, a static traffic diversion method can also be used, which involves diverting all public network traffic destined for the protected network to the cleaning server cluster for cleaning processing without any specific restrictions.
[0061] Step S204: Based on the compliant traffic, query the pre-configured public network protocol address table to obtain the target public network segment.
[0062] The public network address table includes multiple public network segments, containing the public network service subnets to be protected and their interface binding relationships. All compliant traffic injection operations are completed within the VRF to avoid conflicts with the public network routing table. The public network segment can refer to a legitimate IPv4 (Internet Protocol version 4) public network subnet allocated to customer services. These segments represent different business systems or tenants, and in traditional solutions, they need to be repeatedly configured on each scrubbing server. However, in this invention, they are only centrally configured in the VRF instance of the anti-attack switch. The target public network segment can refer to the specific public network subnet to which the destination IP of the currently processed compliant traffic belongs.
[0063] Optionally, the anti-attack switch queries a pre-configured public network protocol address table based on the compliant traffic to obtain the target public network segment. The anti-attack switch parses the destination network protocol address of the compliant traffic and performs longest prefix matching in the pre-configured public network protocol address table to find the corresponding directly connected public network subnet, thereby determining the target public network segment to which the compliant traffic belongs. For example, when the destination IP address of the compliant traffic is 100.0.0.100, the switch matches the configured 100.0.0.0 / 24 network segment in the public network protocol address table, thus determining that this network segment is the target public network segment, and triggering the subsequent Layer 2 injection process.
[0064] Step S206: According to the target public network segment, inject compliant traffic back into the protected network.
[0065] The protected network can refer to the specific customer business network that needs to be protected against DDoS attacks. It is usually a local area network that has deployed a server with a public IP address. This network is connected to the public network through a core switch and is the original destination to which the traffic after cleaning needs to be restored.
[0066] Optionally, the anti-attack switch redirects compliant traffic back to the protected network based on the target public network segment. The anti-attack switch encapsulates the compliant traffic and forwards it directly to the protected network on the corresponding outgoing interface in the public IP address table, according to the target public network segment. This process is completed within a VRF isolation environment and does not change the original IP address.
[0067] In the above traffic reinjection method, when an abnormal traffic attack occurs on the public network, the anti-attack switch receives compliant traffic reinjected by the scrubbing server cluster via a private network protocol. The scrubbing server cluster is connected to the anti-attack switch via the private network protocol configured in the reinjection plane, and the scrubbing server cluster includes multiple scrubbing servers. Further, the anti-attack switch queries a pre-configured public network protocol address table based on the compliant traffic to obtain a target public network segment. The public network protocol address table includes multiple public network segments. Then, according to the target public network segment, the compliant traffic is reinjected into the protected network. By connecting the scrubbing server cluster and the anti-attack switch based on a private network protocol, the scrubbing server cluster does not need to be configured with any public network address segments. It only needs to send the scrubbed and compliant traffic to the anti-attack switch through the private network channel. The anti-attack switch, by querying its pre-configured public network address table containing multiple public network segments, identifies the target public network segment to which the traffic belongs and completes Layer 2 back injection. This achieves centralized management of public network address segments, thereby avoiding the waste of public network address resources. At the same time, it simplifies the configuration and maintenance complexity of the scrubbing server, greatly improves flexibility and delivery efficiency, and enables the standardization of configuration that traditional Layer 2 back injection schemes cannot achieve.
[0068] In an exemplary embodiment, before receiving compliant traffic injected back from the cleaning server cluster via a private network protocol in the event of an abnormal traffic attack on the public network, step S202 further includes:
[0069] Receive abnormal host routes from the cleaning server cluster; send the abnormal host routes to the core switch to instruct the core switch to redirect the abnormal traffic of the abnormal host routes to the cleaning server cluster.
[0070] Among them, the anti-attack switch is connected to the public network through the core switch.
[0071] Among them, abnormal host routing can refer to the precise routing entry of a single attacked public IP. This route is generated by the scrubbing server and sent to the anti-attack switch via IBGP, and then sent to the core switch via EBGP (Exterior Border Gateway Protocol), thereby achieving precise traffic redirection for the IP.
[0072] Optionally, in the event of an abnormal traffic attack on the public network, the detection server of the anti-DDoS system sends a traffic redirection policy to the cleaning server cluster. After receiving the traffic redirection policy, the cleaning server cluster automatically generates an abnormal host route (32-bit host towing route). The anti-attack switch receives the abnormal host route from the cleaning server cluster and sends the abnormal host route to the core switch to instruct the core switch to redirect the abnormal traffic of the abnormal host route to the cleaning server cluster.
[0073] In this embodiment, the detection server actively issues a traffic redirection strategy, coordinates the cleaning server cluster to dynamically generate and transmit abnormal host routes, and then the anti-attack switch announces the routes to the core switch. This achieves precise and rapid traffic redirection of attacked routes. Compared with traditional manual configuration or static redirection methods, this mechanism has the advantages of timely response, flexible control, and high degree of automation. It avoids the resource waste caused by redirecting traffic across the entire network segment, and only directs abnormal traffic to the cleaning server cluster, ensuring that other normal services are not affected. At the same time, the entire interaction process between the anti-attack switch and the cleaning server cluster is based on the standard BGP protocol, which has strong compatibility and does not require modification of the existing network architecture, thus improving the linkage efficiency and maintenance convenience of the anti-DDoS system.
[0074] In an exemplary embodiment, step S204 queries a pre-configured public network protocol address table based on compliant traffic to obtain the target public network segment, including:
[0075] The compliant traffic is parsed to obtain the target public network address of the compliant traffic; based on the target public network address, the pre-configured public network address table is queried to obtain the target public network segment corresponding to the target public network address.
[0076] The target public IP address can be the destination IP address carried in compliant traffic. It is a specific public IPv4 address that identifies the business server to which the traffic should ultimately be delivered.
[0077] Optionally, the anti-attack switch parses the compliant traffic to obtain the target public network protocol address of the compliant traffic, thereby determining the purpose of the compliant traffic. Further, the anti-attack switch performs longest prefix matching in the pre-configured public network protocol address table based on the target public network protocol address to find the directly connected public network subnet corresponding to it, thereby determining the target public network segment to which the traffic belongs and obtaining the target public network segment corresponding to the target public network protocol address.
[0078] In this embodiment, the anti-DDoS switch performs target public network protocol address resolution on the compliant traffic returned after cleaning, and accurately identifies the target public network segment to which the traffic belongs based on a pre-configured public network protocol address table, realizing intelligent path decision-making during the injection process. Since all public network segment information is centrally managed in the public network protocol address table, the cleaning server does not need to configure any public network segments, further reducing the complexity of device configuration and the consumption of public network segment resources. At the same time, this mechanism supports the dynamic coexistence and rapid lookup of multiple service network segments, ensuring the accuracy and real-time nature of the injection, and improving the scalability and operational efficiency of the anti-DDoS system.
[0079] In an exemplary embodiment, step S206, according to the target public network segment, injects compliant traffic back into the protected network via virtual routing, including:
[0080] Based on the target public network segment, perform Layer 2 addressing to determine the physical address of the protected network; according to the physical address, inject compliant traffic back to the protected network via Layer 2.
[0081] Layer 2 addressing can refer to the process of locating a target device connected to a protected network at the data link layer using its MAC address (Media Access Control Address).
[0082] The physical address can be a MAC address, which is a unique hardware identifier for a network device's network card. It is a six-byte hexadecimal number and, in this embodiment, refers to the actual MAC address of the target server or next-hop device in the protected network.
[0083] Layer 2 back injection can bypass Layer 3 routing and forwarding, and instead complete the encapsulation and delivery of frames directly at the data link layer, making the traffic appear as if it has never left the local network, achieving transparent, efficient, and low-latency restoration.
[0084] Optionally, the anti-attack switch performs Layer 2 addressing based on the target public network segment to determine the physical address of the protected network. Specifically, the anti-attack switch obtains the MAC address of the target server through ARP (Address Resolution Protocol) resolution or proxy response on the outgoing interface corresponding to the public network protocol address table. Based on the physical address, the compliant traffic is injected back to the network device in the protected network corresponding to the physical address at Layer 2.
[0085] In this embodiment, by mapping the interface in the public IP address table of the anti-attack switch, the physical address of the network device in the protected network is actively obtained. Based on this physical address, compliant traffic is directly injected back to the destination network device in a Layer 2 injection manner, achieving transparent injection without crossing Layer 3 routing. Since the injection process is completed in the isolated environment of virtual routing, it ensures the logical independence and security between different service network segments, and avoids the participation of the scrubbing server in public IP processing, significantly reducing configuration complexity and resource overhead. At the same time, Layer 2 injection has the advantages of low latency, fast forwarding, and controllable path, improving the efficiency and reliability of traffic restoration, and is particularly suitable for rapid deployment and large-scale anti-DDoS system construction in scenarios without an egress router.
[0086] In one exemplary embodiment, the flow reinjection method described above further includes:
[0087] When adding a new cleaning server to a cleaning server cluster, configure the private network protocol and gateway for the new cleaning server.
[0088] In this cluster, there are no conflicts in the private network protocols between the cleaning servers, and the gateway configurations are identical.
[0089] In this context, the gateway can refer to the next-hop address pointed to by its default route, i.e., the private network interface on the anti-attack switch, which is used to send out compliant traffic.
[0090] Optionally, when adding a new cleaning server to the cleaning server cluster, the anti-DDoS switch acts as the new cleaning server. Only the private network protocol and gateway need to be configured to extend the anti-DDoS system. Specifically, the following provides an example of the configuration principles for the anti-DDoS switch and the cleaning server:
[0091] Key configurations for the anti-attack switch traffic redirection plane:
[0092] interface vlan 1006;
[0093] IP address 172.16.1.22 30;
[0094] #
[0095] interface vlan 751;
[0096] IP address 192.168.1.254;
[0097] Key configurations for the anti-attack switch injection plane:
[0098] interface vlan 10;
[0099] ip binding vpn-instance DDOS;
[0100] IP address 100.0.0.253 24;
[0101] ip address 100.0.1.253 24 sub;
[0102] #
[0103] interface vlan 1007;
[0104] ip binding vpn-instance DDOS;
[0105] IP address 10.0.0.254 24;
[0106] #
[0107] IP VPN instance DDoS attack;
[0108] rd 100:100;
[0109] #
[0110] Cleaning server configuration (understandably, in some embodiments, to achieve standardization, the entire cleaning server cluster may be kept consistent):
[0111] bond0.1007 10.0.0.1 / 24; (The second cleaning server is configured as 10.0.0.2 / 24, and so on).
[0112] bond0.751 192.168.1.1 / 24; (The second cleaning server is configured with 192.168.1.2 / 24, and so on).
[0113] Gateway: 10.0.0.254; (Therefore, the cleaning servers are uniformly configured with this gateway, indicating that traffic injection is uniformly sent to the anti-attack switch).
[0114] The key configuration section of the traffic redirection plane mainly describes the critical interface configurations for the traffic redirection path of the anti-attack switch. A private network address range is configured on the VLAN1006 interface to establish an EBGP neighbor relationship with the core switch, serving as the traffic redirection control channel. The VLAN751 interface is configured to belong to an internal management or interconnection subnet. This interface is used to establish an IBGP neighbor relationship with the scrubbing server cluster and receive 32-bit host routes sent from the scrubbing server. This allows the scrubbing server to actively advertise the target IPs to be redirected to the anti-attack switch, which then uniformly forwards them to the core switch to complete global traffic redirection. The key configuration of the anti-attack switch's injection plane mainly involves building an independent VRF injection plane on the anti-attack switch, using private network addresses for communication, avoiding the scrubbing server directly configuring a public IP. The scrubbing server uses a standardized and unified configuration template, applicable to all resource pool environments; the bond0.1007 interface (injection plane) has sub-interfaces carrying VLAN1007 traffic. The private network address 10.0.0.1 / 24 is assigned, which is on the same subnet as the VLAN 1007 interface of the anti-attack switch. All compliant traffic after scrubbing is sent from this interface, with the next hop being 10.0.0.254 (the VRF interface on the anti-attack switch). The bond0.751 interface (traffic redirection control plane) carries VLAN 751 traffic. It is configured with the address 192.168.1.1 / 24, communicating with the VLAN 751 interface of the anti-attack switch. It is used to establish IBGP neighbor relationships with the anti-attack switch, actively advertising the 32-bit host routes to be redirected (e.g., xxxx / 32), triggering traffic redirection. The default gateway is set to 10.0.0.254, pointing to the VLAN 1007 interface of the anti-attack switch (located within the VRF DDoS). This indicates that all back-injection traffic should be sent to the anti-attack switch for processing, where it performs the actual public network back-injection operation.
[0115] In this embodiment, when adding a new cleaning server to the cleaning server cluster, only a private network protocol and a default gateway (pointing to the anti-DDoS switch) need to be configured for it. There is no need to allocate a public IP address or simultaneously configure multiple service network segments, simplifying the expansion operation of the cleaning server cluster. Since the carrying and injection functions of all public network segments are centrally handled by the anti-DDoS switch, new servers can be plugged in and automatically integrated into the existing protection system. This significantly improves the scalability, deployment efficiency, and ease of operation and maintenance of the anti-DDoS system. At the same time, it avoids the IP resource waste and configuration inconsistencies caused by adding servers in traditional solutions, which is conducive to the standardized and large-scale construction of cleaning clusters.
[0116] In one exemplary embodiment, the flow reinjection method described above further includes:
[0117] In response to the public network segment update operation, the public network segment to be updated is obtained; based on the public network segment to be updated, the public network protocol address table is updated to obtain the updated public network protocol address table.
[0118] Among them, the public network segment to be updated can refer to the public network segment that needs to be added, deleted or modified in the configuration of the anti-attack switch due to business adjustments.
[0119] Optionally, in response to a public network segment update operation, the anti-attack switch determines the public network segment to be updated. This public network segment to be updated can be a new segment that does not exist in the public network protocol address table or an existing segment. Based on the public network segment to be updated, the anti-attack switch updates its configured public network protocol address table, including adding, revoking, or modifying it, to obtain an updated public network protocol address table. In the case of adding a new public network segment, an IP address from the new public network segment is allocated to update the configuration on the anti-attack switch, enabling it to have the ability to inject the new network segment.
[0120] In this embodiment, the anti-DDoS switch responds to changes in public network segments and dynamically updates its public network protocol address table. This supports flexible addition, deletion, and modification of newly accessed or adjusted public network segments, enabling the anti-DDoS system to quickly adapt to changes in network topology. Since all public network segment information is centrally managed on the anti-DDoS switch side, the cleaning server does not need to be aware of any changes, avoiding the cumbersome maintenance problem of modifying server configurations one by one due to business adjustments in traditional solutions. This not only reduces configuration complexity and error risk but also improves the maintainability and elastic scalability of the system, enabling anti-DDoS protection to seamlessly match the dynamic evolution needs of customer businesses, further enhancing the practicality and engineering implementation value of the overall solution.
[0121] In one exemplary embodiment, another flow reinjection method is provided, applicable to, for example... Figure 3 The system architecture for defending against distributed denial-of-service attacks shown includes:
[0122] Step 1: The cleaning server sends a 32-bit host routing message to the anti-attack switch. The anti-attack switch then forwards the route to the core switch. The traffic is routed through the public plane of both the core switch and the anti-attack switch.
[0123] Among them, the core switch and the anti-attack switch establish EBGP through vlanif1006, and the scrubbing server and the anti-attack switch establish IBGP through vlanif751, forming an abnormal traffic redirection from the public network to the core switch, the anti-attack switch, and the scrubbing server.
[0124] Step 2: The cleaning server completes the cleaning and sends the traffic to the gateway 10.0.0.254. The gateway is bound to VRF: DDoS. In the DDoS plane, there are only direct routes and no 32-bit host routes. Therefore, the anti-attack switch directly completes the back injection through Layer 2.
[0125] Specifically, after the cleaning server completes the traffic cleaning, it needs to send the traffic back to the business server. Since the cleaning server is configured with the IP of each business network segment (public network segment), the cleaning server can find the MAC address of the business server through Layer 2 addressing to complete the Layer 2 traffic reinjection. Layer 2 reachability exists between the cleaning server and the business server.
[0126] Understandably, by configuring a back-injection plane on the anti-attack switch and uniformly configuring the service network segment IPs on the anti-attack switch, the complexity of back-injection is completely shielded from the scrubbing server. This saves public IPs, greatly simplifies configuration and maintenance complexity, and significantly enhances scalability. Adding or reclaiming network segment scrubbing servers in the cluster can be done without synchronously modifying configurations, and adding new scrubbing servers no longer requires reassigning public IPs. This embodiment is easy to implement and maintain, and can be standardized. The business scenarios involved in this embodiment require cloud resource pools with public network egress to deploy anti-DDoS security products. Anti-DDoS involves traffic redirection from abnormal IPs and traffic back-injection after scrubbing. When the cluster architecture is relatively simple and there is no egress switch or router, only a Layer 2 back-injection solution can typically be used. The current Layer 2 back-injection scheme requires each cleaning server to be configured with an IP address for each public network segment of the resource pool. If the cluster has four cleaning servers and six public network segments, it will consume 24 public IP addresses and is very troublesome to maintain. With this scheme, not only is it possible to save public IP addresses by not configuring them on each server, but it is also much simpler to maintain.
[0127] In this embodiment, the traffic redirection plane of the anti-DDoS system remains unchanged. The back-injection plane of the scrubbing server only needs to be configured with a private network address, the gateway points to the anti-attack switch, and the anti-attack switch is configured with the service network segment IP. Layer 2 back-injection is implemented on the anti-attack switch. This solution achieves the following: it eliminates the need to configure a public network IP for each scrubbing server, greatly saving public network IPs; the back-injection plane of the scrubbing server only needs to be configured with a private network address and gateway, without needing to pay attention to the service network segment, and subsequent network segment adjustments do not require synchronous adjustments, greatly simplifying configuration and maintenance work; it can form a unified standardized configuration scheme for all clusters, greatly simplifying delivery work; for complex networking scenarios, the scrubbing server does not need to be aware of the complexity of the network at all. This solution can flexibly meet the needs of various scenarios, greatly improving flexibility and delivery efficiency, and enabling the standardization of configuration that traditional Layer 2 back-injection schemes cannot achieve.
[0128] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0129] Based on the same inventive concept, this application also provides a flow reinjection device for implementing the flow reinjection method described above. The solution provided by this device is similar to the solution described in the above method; therefore, the specific limitations of one or more flow reinjection device embodiments provided below can be found in the limitations of the flow reinjection method described above, and will not be repeated here.
[0130] In one exemplary embodiment, such as Figure 4 As shown, a traffic reinjection device 400 is provided, including: a traffic receiving module 401, a network segment determination module 402, and a traffic reinjection module 403, wherein:
[0131] The traffic receiving module 401 is used to receive compliant traffic injected back from the cleaning server cluster via a private network protocol in the event of abnormal traffic attacks on the public network. The cleaning server cluster is connected to the injection plane of the anti-attack switch via a private network protocol, and the cleaning server cluster includes multiple cleaning servers.
[0132] The network segment determination module 402 is used to query a pre-configured public network protocol address table based on compliant traffic to obtain the target public network segment; the public network protocol address table includes multiple public network segments;
[0133] The traffic reinjection module 403 is used to inject compliant traffic back to the protected network according to the target public network segment.
[0134] Furthermore, in one embodiment, the traffic receiving module 401 is also used to receive abnormal host routes of the cleaning server cluster; send the abnormal host routes to the core switch to instruct the core switch to divert the abnormal traffic of the abnormal host routes to the cleaning server cluster; and the anti-attack switch is connected to the public network through the core switch.
[0135] Furthermore, in one embodiment, the network segment determination module 402 is also used to parse the compliant traffic to obtain the target public network protocol address of the compliant traffic; and to query a pre-configured public network protocol address table based on the target public network protocol address to obtain the target public network segment corresponding to the target public network protocol address.
[0136] Furthermore, in one embodiment, the traffic reinjection module 403 is also used to perform Layer 2 addressing based on the target public network segment to determine the physical address of the protected network; and to reinject compliant traffic into the protected network at Layer 2 according to the physical address.
[0137] Furthermore, in one embodiment, the traffic reinjection device 400 further includes a configuration update module, used to configure a private network protocol and gateway for a new cleaning server when a new cleaning server is added to the cleaning server cluster; wherein the private network protocols of the cleaning servers in the cleaning server cluster do not conflict, and the gateway configurations are the same.
[0138] Furthermore, in one embodiment, the configuration update module is also used to respond to the public network segment update operation to obtain the public network segment to be updated; and to update the public network protocol address table according to the public network segment to be updated to obtain the updated public network protocol address table.
[0139] Each module of the aforementioned flow reinjection device 400 can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0140] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 5 As shown, this computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores data such as public network protocol address tables and public network segments. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communication with external terminals via a network connection. When executed by the processor, the computer program implements a traffic reinjection method.
[0141] Those skilled in the art will understand that Figure 5 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0142] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0143] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0144] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0145] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0146] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0147] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0148] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A flow reinjection method characterized by, The method applied to an anti-attack switch comprises the following steps: In the case that there is an abnormal traffic attack on a public network, compliant traffic returned by a cleaning server cluster is received through a private network protocol; the cleaning server cluster is connected with the private network protocol configured on a return plane of the anti-attack switch, and the cleaning server cluster comprises a plurality of cleaning servers; According to the compliant traffic, a target public network segment is obtained by querying a pre-configured public network protocol address table; the public network protocol address table comprises a plurality of public network segments; The compliant traffic is returned to a protected network according to the target public network segment.
2. The method of claim 1, wherein, Before the step of receiving the compliant traffic returned by the cleaning server cluster through the private network protocol in the case that there is an abnormal traffic attack on the public network, the following steps are further included: An abnormal host route of the cleaning server cluster is received; The abnormal host route is sent to a core switch to instruct the core switch to divert abnormal traffic of the abnormal host route to the cleaning server cluster; the anti-attack switch is connected with the public network through the core switch.
3. The method of claim 1, wherein, The step of obtaining the target public network segment by querying the pre-configured public network protocol address table according to the compliant traffic comprises the following steps: The compliant traffic is analyzed to obtain a target public network protocol address of the compliant traffic; According to the target public network protocol address, a target public network segment corresponding to the target public network protocol address is obtained by querying the pre-configured public network protocol address table.
4. The method of claim 1, wherein, The step of returning the compliant traffic to the protected network according to the target public network segment comprises the following steps: A physical address of the protected network is determined according to the target public network segment through layer 2 addressing; The compliant traffic is returned to the protected network through layer 2 according to the physical address.
5. The method according to any one of claims 1 to 4, characterized in that, The method further comprises the following steps: In the case that a new cleaning server is added to the cleaning server cluster, the private network protocol and a gateway are configured for the new cleaning server; The private network protocol between each cleaning server in the cleaning server cluster does not conflict, and the configuration of the gateway is the same.
6. The method according to any one of claims 1 to 4, characterized in that, The method further comprises the following steps: In response to a public network segment updating operation, a to-be-updated public network segment is obtained; According to the to-be-updated public network segment, the public network protocol address table is updated to obtain an updated public network protocol address table.
7. A flow reinjection apparatus characterized by, The device applied to an anti-attack switch comprises the following modules: A traffic receiving module is configured to receive compliant traffic returned by a cleaning server cluster through a private network protocol in the case that there is an abnormal traffic attack on a public network; the cleaning server cluster is connected with the private network protocol configured on a return plane of the anti-attack switch, and the cleaning server cluster comprises a plurality of cleaning servers; A network segment determining module is configured to obtain a target public network segment by querying a pre-configured public network protocol address table according to the compliant traffic; the public network protocol address table comprises a plurality of public network segments; A traffic returning module is configured to return the compliant traffic to a protected network according to the target public network segment.
8. A computer device comprising a memory and a processor, the memory storing a computer program, characterized in that, The processor implements the steps of the method of any one of claims 1 to 6 when executing the computer program. The processor implements the steps of the method of any one of claims 1 to 6 when executing the computer program.
9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program, which when executed by a processor, implements the steps of the method of any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, The computer program, which when executed by a processor, implements the steps of the method of any one of claims 1 to 6.