Operation type software defined wide area network attack tracing system and method
By introducing three-dimensional tracing anchors and a multi-module tracing system into operational software-defined wide area networks, the accuracy and efficiency of attack tracing in multi-tenant environments have been solved. This enables efficient tracing from shared PoP2 IPs to specific tenants, branch offices, dedicated CPEs, and customer internal PC terminals, thereby improving network security protection capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- BEIJING QINGWANG TECH CORP
- Filing Date
- 2026-02-12
- Publication Date
- 2026-05-12
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing technologies cannot efficiently and accurately trace the source of an attack to a specific tenant, branch office, dedicated CPE, or customer's internal PC terminal in an operational software-defined wide area network. Furthermore, in a multi-tenant environment, there are issues with traffic obfuscation and low tracing efficiency.
The system employs a three-dimensional source tracing anchor point (tenant code, branch office code, and session code) generation and data transmission module, combined with a link aggregation and path reconstruction module. It uses a PoP2 shared public network IP for reverse source tracing, utilizes a tenant-organization-CPE positioning module to achieve precise location of the attack path, and obtains the final source tracing result through a verification module.
It enables precise traceability from the shared public IP address of PoP2 to specific tenants, branch offices, dedicated CPEs, and customer internal PC terminals, improving traceability efficiency and accuracy, reducing operation and maintenance costs, and ensuring network security and stability.
Smart Images

Figure CN122027291A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cybersecurity, and in particular to an operational software-defined wide area network attack tracing system and method. Background Technology
[0002] The core business link of an operational Software-Defined Wide Area Network (SD-WAN) is: Personal Computer (PC) --- Customer Premises Equipment (CPE) --- PoP1 --- PoP2 --- Software-as-a-Service (SaaS) / Internet. The link characteristics are as follows: 1. From PC to CPE is the customer's internal network; the CPE is a dedicated, single tenant, handling PC terminal traffic. 2. From CPE to PoP2, tenant-isolated traffic is transmitted through a dedicated tunnel; PoP1 is only responsible for traffic forwarding. 3. From PoP2 to SaaS / Internet is an Internet link; the public IP address of PoP2 is shared by multiple tenants and is the only visible node identifier after an attack on the SaaS / Internet side.
[0003] With the widespread adoption of SD-WAN multi-tenant services, attack attribution has become a core pain point. Currently, attack attribution mainly employs the following two methods: (1) The core technical solution of the SD-WAN distributed log tracing solution is: CPE / PoP devices generate audit logs in a custom format and upload them to Orch's log server regularly; after an attack occurs, the administrator manually filters logs by source IP and time range through Orch's log retrieval function; combined with the tenant IP segment table, the attack path is manually pieced together to locate the tenant to which the attack source belongs. This solution has the following defects due to the lack of a unified multi-tenant traffic differentiation identifier and cross-device data association mechanism: ① High multi-tenant confusion rate: PoP2 public network IP is shared by multiple tenants, and the traffic of different tenants cannot be distinguished by the IP segment table alone. When the tenant's private network IP overlaps, the attack responsibility misjudgment rate is high; ② Attack chain break: It is impossible to trace back to the upstream PoP1, tenant CPE and customer's internal PC through the shared IP of PoP2. The tracing can only reach the PoP2 node and cannot locate the real attack source; ③ Extremely low tracing efficiency: The whole process relies on manual filtering of logs and piecing together of attack paths. The tracing cost is high and the efficiency is low, which cannot meet the needs of emergency response.
[0004] (2) The core technical solution of the SD-WAN tenant isolation and tracing solution is: Orch allocates an independent log storage partition for each tenant; when CPE / PoP uploads logs, it carries a tenant ID tag and the logs are automatically stored in the corresponding tenant partition; after an attack occurs, Orch filters logs by tenant ID to narrow down the tracing scope, and then manually extracts the source IP. This solution only introduces a single identifier of tenant ID and does not associate session and terminal information, resulting in the following defects: ① Lack of branch office (Site) level and PC level positioning: It can only locate the tenant, and cannot further lock the Site to which the attack source belongs and the customer's internal PC terminal; ② It cannot distinguish different attack events of the same tenant: without associating session ID, multiple attack logs within the same tenant are confused and cannot accurately match attack sessions; ③ Manual intervention is still required: the tenant log partition only narrows down the scope, and the source IP and PC terminal information still need to be manually filtered, which has limited efficiency improvement.
[0005] Therefore, when the SaaS / Internet side is attacked, only the common public IP of PoP2 can be obtained. However, the existing technology cannot distinguish the specific tenant corresponding to the IP, nor can it trace back to the tenant CPE and the attacking PC inside the customer along the tunnel link. At the same time, the existing technology relies on manual collection of CPE / PoP logs, which is inefficient for tracing the source. Moreover, the overlap of private network IPs of multiple tenants leads to a high rate of misjudgment, which cannot meet the needs of emergency response. Summary of the Invention
[0006] The purpose of this application is to provide an operational software-defined wide area network attack tracing system and method, which can trace the attack back to a specific tenant, branch office, dedicated CPE and customer internal PC terminal through the shared public IP of PoP2, and obtain the real public IP of the attack and the complete attack path.
[0007] To achieve the above objectives, this application provides the following solution: Firstly, this application provides an operational software-defined wide area network attack tracing system, comprising: The anchor point acquisition module is used to generate three-dimensional source tracing anchor points based on the original acquisition dataset, and remove normal business traffic data from the original acquisition dataset to obtain anchor-based attack audit data; the original acquisition dataset includes real-time raw traffic data and device-specific information collected by CPE devices, PoP1 devices, and PoP2 devices; the three-dimensional source tracing anchor points include tenant codes, branch office codes, and session codes. The data transmission module is used to transmit the anchoring attack audit data to Orch storage; The link aggregation and path reconstruction module is used to filter out the corresponding attack session data from Orch based on the attack warning information of SaaS / Internet, and extract the attack path to obtain the full link aggregation dataset and attack path map. The tenant-organization-CPE localization module is used to locate attacks based on the full-link aggregated dataset, the attack path map, and the mapping relationship between tenants, organizations, and CPEs, and to obtain an attack localization result set. The verification module is used to retrieve the corresponding anchored attack audit logs and PC terminal information from Orch based on the attack location result set, filter and verify the IPs, and obtain the final source tracing result. The final source tracing result includes attack tenant information, attack branch information, attack-specific CPE information, attack terminal information, attack real source IP, attack path and key attack information.
[0008] Secondly, this application provides a method for attribution of attacks on operational software-defined wide area networks, including: A three-dimensional source tracing anchor point is generated based on the original collected dataset, and normal business traffic data in the original collected dataset is removed to obtain anchor-based attack audit data; the original collected dataset includes the original traffic data and inherent device information collected in real time by CPE devices, PoP1 devices and PoP2 devices; the three-dimensional source tracing anchor point includes tenant code, branch office code and session code. The anchoring attack audit data is transmitted to Orch storage; Based on the attack warning information from SaaS / Internet, the corresponding attack session data is filtered out from Orch, and the attack path is extracted to obtain the full-link aggregated dataset and attack path map. Attack localization is performed based on the full-link aggregated dataset, the attack path map, and the tenant-organization-CPE mapping relationship to obtain an attack localization result set; Based on the attack location result set, the corresponding anchored attack audit logs and PC terminal information are retrieved from Orch and the IPs are filtered and verified to obtain the final source tracing result. The final source tracing result includes attack tenant information, attack branch information, attack-specific CPE information, attack terminal information, attack real source IP, attack path, and key attack information.
[0009] According to the specific embodiments provided in this application, this application achieves the following technical effects: It generates three-dimensional source tracing anchor points for tenants, branch offices, and sessions using an anchor point acquisition module, eliminating normal business traffic and improving the accuracy of multi-tenant traffic differentiation. The data transmission module ensures reliable storage of anchor-based data. The link aggregation and path restoration module combines attack warning information to filter attack sessions and restore attack paths, forming a full-link aggregation dataset and a visualized attack path map. The tenant-organization-CPE positioning module achieves precise attack location based on mapping relationships. The verification module further retrieves audit logs and terminal information to filter and verify IPs, ensuring the comprehensiveness and accuracy of the final source tracing results, covering the attacking tenant, branch office, dedicated CPE, terminal, real source IP, attack path, and key information. This system can efficiently complete the accurate source tracing of SD-WAN network attacks, significantly improving the security protection capabilities of operational SD-WAN networks, reducing the source tracing costs and time costs for maintenance personnel, and providing reliable security guarantees for the continuous and stable operation of the network. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a schematic diagram of the functional modules of an operational software-defined wide area network attack tracing system provided in an embodiment of this application.
[0012] Figure 2 This is a flowchart illustrating an operational software-defined wide area network (SDB) attack tracing method provided in one embodiment of this application. Detailed Implementation
[0013] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0014] Addressing the core shortcomings of existing technologies, such as multi-tenant traffic obfuscation, attack chain breakage, low tracing efficiency, and inability to locate PC terminals, this application achieves four major objectives by combining the link characteristics of PC-CPE-PoP1-PoP2-SaaS / Internet: (1) Based on three-dimensional tracing anchor points, it achieves accurate differentiation of shared PoP2 multi-tenant traffic, reducing the obfuscation rate to 0; (2) It automatically restores the complete attack path of "PC→CPE→PoP1→PoP2→SaaS / Internet" without any tracing blind spots; (3) It reverses the tracing from the shared public IP of PoP2, accurately locating the four levels of targets: attack tenant, branch office, dedicated CPE, and customer internal PC terminal; (4) It achieves fully automated tracing with low latency and accurate extraction of source IP and PC terminal information.
[0015] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0016] First, some technical terms involved in the embodiments of this application will be introduced.
[0017] SD-WAN: In operational scenarios, it is a naturally isolated architecture for multi-tenants, where tenant traffic is transmitted through dedicated tunnels without interference.
[0018] CPE: SD-WAN access device, dedicated to a single tenant, deployed in the tenant's branch office, to collect audit data containing information about the customer's internal PC terminals.
[0019] Network access node (Point of Presence, PoP): a shared device for multiple tenants; PoP1 is the access node, aggregating CPE traffic; PoP2 is the egress node, a shared public IP address for multiple tenants, and is the only visible attack source identifier on the SaaS / Internet side.
[0020] Orch (Orchestrator): SD-WAN orchestrator, the core management hub of the system, responsible for audit data aggregation, attack path reconstruction, and accurate tracing of tenants and PC terminals.
[0021] 3D traceability anchor point: A unique identifier composed of tenant code (Customer ID), branch office code (Site ID), and session ID. It is the core index for distinguishing multi-tenant traffic and associating data across devices.
[0022] SaaS: Cloud-based application platforms are common external targets for attack traffic.
[0023] In one exemplary embodiment, such as Figure 1As shown, an operational software-defined wide area network (SDN) attack tracing system is provided, in which each functional module is executed by computer equipment. The operational SDN attack tracing system is based on the core logic of "CPE / PoP anchor point collection → data transmission → Orch full-link aggregation → tenant / site location → source IP and PC terminal extraction," and is designed with five functional modules: anchor point collection module 101, data transmission module 102, link aggregation and path reconstruction module 103, tenant-organization-CPE location module 104, and verification module 105. The anchor point collection module 101 is deployed in the CPE, PoP1, and PoP2 devices, i.e., it adopts a locally embedded deployment. The data transmission module 102 is deployed in the CPE / PoP and Orch. The link aggregation and path reconstruction module 103, the tenant-organization-CPE location module 104, and the verification module 105 are all deployed on the local server of the Orch orchestration.
[0024] The anchor point acquisition module 101 is used to generate three-dimensional source tracing anchor points based on the original acquisition dataset, and remove normal business traffic data from the original acquisition dataset to obtain anchor point-based attack audit data.
[0025] The business process of the anchor point acquisition module 101 is as follows: acquire raw data → generate unique three-dimensional traceability anchor points → bind data → filter attack data → output anchor-based attack audit data, which is the source of data for the entire system.
[0026] In a specific application example, the anchor point acquisition module 101 includes: an audit data acquisition unit, a three-dimensional anchor point generation unit, and an attack data filtering unit.
[0027] The audit data acquisition unit is used to obtain raw traffic data and device-specific information collected in real time from CPE devices, PoP1 devices, and PoP2 devices to obtain raw data sets.
[0028] The raw data set includes real-time raw traffic data and device-specific information collected by CPE devices, PoP1 devices, and PoP2 devices. Specifically, the real-time raw traffic data collected by CPE devices includes: the source IP port of the attack traffic, the destination IP port of the attack traffic, the protocol, timestamps, and security policy trigger records. The real-time raw traffic data collected by PoP1 devices includes: PoP1 forwarding records and tenant isolation traffic identifiers. The real-time raw traffic data collected by PoP2 devices includes: PoP2 forwarding records, tenant isolation traffic identifiers, and PoP2 public network exit IP. Device-specific information includes CPE device-specific information and PC terminal information.
[0029] Specifically, the content collected from the CPE includes: customer internal PC terminal information (source IP, MAC address, and access process of the PC terminal), CPE device-specific information (CPE-specific Customer ID, Site ID, and tunnel link information between CPE and PoP2), and CPE traffic information (source / destination IP, port, protocol, timestamp, and security policy trigger records of attack traffic).
[0030] The content collected from PoP1 includes: PoP1 forwarding records (inbound / outbound interfaces of attack traffic, next-hop nodes, and traffic forwarding timestamps) and tenant isolation traffic identifiers (unique identifiers of tenant traffic bound to CPE tunnel links).
[0031] The content collected from PoP2 includes: PoP2 forwarding records (inbound / outbound interfaces of attack traffic, tunnel exit information, traffic forwarding timestamps), tenant isolation traffic identifiers, and core key information (PoP2's public network exit IP, shared by multiple tenants).
[0032] The audit data acquisition unit collects all the above raw data in real time at a frequency of 1 second / time, forming a raw acquisition dataset, which is then directly output to the 3D anchor point generation unit.
[0033] The 3D anchor point generation unit extracts fixed and dynamic factors from the original acquired dataset, concatenates the fixed and dynamic factors to obtain 3D traceability anchor points, and embeds these anchor points into the original acquired dataset to obtain an anchor point-bound structured dataset. The 3D traceability anchor points include tenant codes, branch office codes, and session codes.
[0034] The fixed factors include tenant codes (e.g., C001) and branch office codes (e.g., S001). The dynamic factors include timestamps, tenant codes, and traffic characteristics. The generation rule for dynamic factors is: YYYYMMDDHHMMSS + Customer ID + random 6-digit number + last 4 digits of the PoP2 egress IP (e.g., 20260104100000 + C001 + 689521 + 11310), ensuring that the IDs of different attack sessions within the same tenant at the same time are unique, and that IDs are not repeated across tenants.
[0035] The format of the 3D traceability anchor is Customer ID-Site ID-Session ID (e.g., C001-S001-20260104100000C00168952111310).
[0036] The generated 3D source tracing anchor points are bound one by one to all the original collected datasets and embedded into the header of each original data, forming structured data of anchor points + original data. This provides structured data with anchor point markings for subsequent attack data filtering. The anchor point-bound structured dataset is the core index for subsequent cross-device data association and attack session filtering.
[0037] This application generates a globally unique three-dimensional traceability anchor point by using a three-dimensional hard identifier of Customer ID-Site ID-Session ID and embedding it into CPE / PoP audit data. This achieves a three-in-one function of multi-tenant traffic differentiation, cross-device (PoP2→PoP1→CPE) data association, and PC terminal (IP, MAC, access process) information binding. At the same time, this anchor point can serve as a unique index to support subsequent operations such as accurate filtering of attack sessions and retrieval of dedicated logs.
[0038] The attack data filtering unit is used to remove normal business traffic data from the anchor-bound structured dataset based on preset filtering rules, obtaining anchor-based attack audit data. This anchor-based attack audit data still fully carries the three-dimensional source tracing anchor and the core information originally collected. The anchor-based attack audit data includes the three-dimensional source tracing anchor, customer internal PC terminal information, Customer ID, Site ID, attack-related traffic data for CPE / PoP1 / PoP2, PoP2 egress public IP address, and tunnel link information.
[0039] The criteria for determining attack data include: ① Security policy triggering: CPE / PoP device firewall blocking records, intrusion detection (IDS / IPS) alarm records, brute-force attack / port scan records. ② Traffic anomalies: sudden increase in single-session traffic (e.g., ≥100Mbps), surge in the number of connections in a short period of time (e.g., ≥1000 connections / second), abnormal protocol traffic (e.g., malicious UDP flood). ③ Attack signatures: traffic carrying malicious signature codes, traffic with source IP addresses in the blacklist.
[0040] The data transmission module 102 is used to transmit the anchored attack audit data to Orch storage. Specifically, the data transmission module 102 transmits the anchored attack audit data securely, completely, and efficiently to Orch, solving the problems of data transmission loss and high bandwidth consumption.
[0041] In a specific application example, the data transmission module 102 includes: an incremental push unit and a breakpoint resume unit.
[0042] The incremental push unit is used to determine new attack data based on the anchored attack audit data.
[0043] Specifically, the incremental push unit directly interfaces with the attack data filtering unit, receiving only the final output anchored attack audit data. New attack data refers to anchored attack audit data that has not been transmitted to Orch (based solely on the 3D source tracing anchor point; if the 3D source tracing anchor point does not exist in the Orch database, it is considered new data). This application employs a real-time incremental push mechanism. For each anchored attack audit data generated by the anchor point acquisition module 101, the incremental push unit immediately pushes one, without batch transmission or duplicate transmission (through anchor point deduplication), and only transmits attack-related data, excluding normal traffic data, to reduce bandwidth usage.
[0044] The breakpoint resume unit is used to store the newly added attack data in a local temporary cache database and transfer the data in the local temporary cache database to Orch storage.
[0045] Specifically, when the network is normal, the interrupted transmission unit transmits the data in the local temporary cache database to Orch in real time, and deletes the data in the local temporary cache database after the transmission is completed. When the network is interrupted, the data transmission is paused, and after the network is restored, the data in the local temporary cache database is transmitted to Orch in chronological order.
[0046] The breakpoint resumption unit establishes a temporary cache database locally on the CPE / PoP. New attack data is first stored in this temporary cache database before being transmitted to Orch. A transmission status tag is added to the three-dimensional source tracing anchor point of each data entry in the temporary cache database, categorized as pending transmission, in transit, and transmission complete. When the network is normal, data in the temporary cache database is transmitted to Orch in real time. Upon completion of transmission, it is marked as complete and deleted from the local cache. In the event of a network interruption, transmission is immediately paused, and all untransmitted data is stored in the temporary cache database (cache validity ≥ 72 hours), marked as pending transmission. After the network recovers, the unit automatically scans the temporary cache database for pending or in-transmission data and re-pushes it in chronological order until all data transmission is complete.
[0047] The link aggregation and path restoration module 103 is used to filter corresponding attack session data from Orch based on attack warning information from SaaS / Internet, extract attack paths, and obtain a full-link aggregation dataset and attack path map. Specifically, the business process of the link aggregation and path restoration module 103 is as follows: parsing anchor points + matching PoP2 IPs + associating full-link data + restoring attack paths to solve the problems of multi-tenant traffic differentiation and attack chain breakage.
[0048] In a specific application example, the link aggregation and path restoration module 103 includes: an anchor point resolution unit, a PoP2 IP-tenant matching unit, and an anchor point association engine unit.
[0049] The anchor point parsing unit extracts core key fields from Orch and binds these core key fields with anchor-based attack audit data to obtain the anchor point parsing dataset. The core key fields include 3D source tracing anchors, PoP2 egress public IP addresses, PC terminal information (IP / MAC / process), tenant codes, branch office codes, CPE / PoP1 / PoP2 tunnel link information, and attack traffic characteristics. Specifically, the core key fields are bound to the anchor-based attack audit data and stored in Orch's full-link audit database, establishing an index relationship between 3D source tracing anchors and the entire dataset for easy and rapid querying. The Orch full-link audit database stores the anchor point parsing dataset (including anchors, core key fields, and raw data indexes) in a structured manner.
[0050] The PoP2 IP-tenant matching unit is used to extract core matching factors from attack warning information from SaaS / Internet, and to filter anchored attack audit data corresponding to the core matching factors from the anchor parsing dataset to obtain a multi-tenant traffic dataset. The core matching factors include the shared public IP address of PoP2 and the attack time range.
[0051] Specifically, the PoP2 IP-tenant matching unit performs precise filtering in the anchor resolution dataset based on the shared public IP address of PoP2 and the attack time range. It selects all anchor-based attack audit data of the tenants transmitted by the PoP2 IP during the attack time, and uses it as a multi-tenant traffic dataset. The multi-tenant traffic dataset is then temporarily stored in Orch's temporary matching database.
[0052] The attack warning information for SaaS / Internet includes: ① Source of attack alert: The security protection system of the SaaS / Internet target (such as the firewall, DDoS protection system, and intrusion detection system of the SaaS platform). ② Content of attack alert: Core tracing information, including the shared public IP address of PoP2, the time range of the attack, and the attack type (such as brute force / DDoS). ③ Alert transmission method: The SaaS / Internet security protection system establishes a real-time alert interface with Orch, and the alert is pushed to this unit immediately after the attack occurs.
[0053] This application receives real-time push SaaS / Internet alarms containing shared PoP2 public IP addresses, attack time ranges, and attack types through a PoP2 IP-tenant matching unit. It then performs multi-condition precise filtering based on the anchor point parsing dataset to obtain the multi-tenant traffic dataset corresponding to the shared PoP2 IP address. Finally, using the three-dimensional source tracing anchor point as the unique index, it filters out the uniquely matching attack session data, thus achieving precise matching and deduplication from shared PoP2 public IP addresses to specific tenants.
[0054] The anchor point association engine unit is used to filter out attack session data that matches the attack alarm from the multi-tenant traffic dataset, extract tunnel link information from the attack session data, and use the three-dimensional source tracing anchor point as a global index to reverse associate the full-link anchored attack audit data in Orch to obtain the full-link aggregated dataset and attack path map.
[0055] Specifically, firstly, attack traffic characteristics are matched for each data point from the multi-tenant traffic dataset based on attack time range and attack type. Then, using the uniqueness of the 3D source tracing anchor point as the core, a unique attack session data matching the attack alarm is selected (i.e., the anchored data of the tenant who actually initiated the attack; other tenant data is irrelevant and automatically discarded). Next, tunnel link information (PoP2 tunnel exit → PoP1 tunnel entrance → CPE tunnel entrance) is extracted from the selected attack session data. Using the 3D source tracing anchor point as a global index, the full-link anchored attack audit data of PoP2 → PoP1 → CPE is reverse-linked in the Orch full-link audit database (i.e., CPE / PoP1 / PoP2 data under the same anchor point) is linked. Finally, the full-link data is concatenated according to time series to reconstruct the attack traffic transmission trajectory, forming a complete attack path: customer internal PC terminal → CPE → PoP1 → PoP2 → SaaS / Internet. The attack path map includes full-link data of the attack session, the attack path, the 3D source tracing anchor point, PoP2 IP, etc.
[0056] This application relies on the attack session data output by the PoP IP-tenant matching unit to extract the tunnel link information, and reverse-correlates the full-link anchored attack audit data along the PoP2→PoP1→CPE tunnel link. The data of each node are connected in sequence according to the time series to restore the complete attack path and generate a visualized attack path map, thus eliminating the source tracing breakpoints.
[0057] The tenant-organization-CPE location module 104 is used to locate attacks based on the full-link aggregated dataset, the attack path map, and the mapping relationship between tenants, organizations, and CPEs, and obtain an attack location result set. Specifically, the tenant-organization-CPE location module 104 can accurately locate attacking tenants, branch offices, and dedicated CPEs, solving the problem of insufficient location granularity.
[0058] In a specific application example, the tenant-organization-CPE positioning module 104 includes: a tenant mapping unit and an anchor point matching and parsing unit.
[0059] The tenant mapping unit is used to obtain the global mapping relationship between tenants, branches, and CPEs provided by the SD-WAN tenant management system, and obtain a three-level mapping relationship dataset.
[0060] The format of the global tenant-branch office-CPE mapping relationship provided by the SD-WAN tenant management system is as follows: Level 1: Customer ID (Tenant Code): C001 → Tenant Name: Enterprise Z; Level 2: Site ID (Branch Office Code): S001 → Branch Office Name: Branch Office in a Certain Location; Level 3: CPE ID (CPE device code): CPE3001 → CPE device address / identifier: 10.0.0.1 / device serial number XXX.
[0061] Level 1: Customer ID: C002 → Tenant Name: Enterprise Y Level 2: Site ID: S002 → Branch Name: Local Branch Level 3: CPE ID: CPE3002 → CPE device address / identifier: 10.0.0.2 / device serial number YYY.
[0062] The tenant mapping unit stores the aforementioned three-level mapping relationship into Orch's tenant mapping database, establishing a unique index for CustomerID→Site ID→CPE ID, supporting fast querying and parsing. Furthermore, it synchronizes in real-time with the SD-WAN tenant management system; when Customer / Site / CPE information changes, the mapping database is automatically updated, ultimately outputting a structured three-level mapping relationship dataset from the Orch tenant mapping database.
[0063] The anchor point matching and parsing unit is used to extract three-dimensional source tracing anchor points from the full-link aggregated dataset, and to match the tenant code and branch code in the three-dimensional source tracing anchor points in the three-level mapping relationship dataset to determine the corresponding attack tenant information, attack branch information and attack-specific CPE information, and to determine the attack location result set in combination with the attack path map.
[0064] Specifically, the anchor point matching and parsing unit first extracts the three-dimensional source tracing anchor points from the full-link aggregated dataset and then splits the Customer ID and Site ID from the three-dimensional source tracing anchor points (e.g., anchor point C001-S001-XXX, split into CustomerID=C001 and Site ID=S001). Then, the split Customer ID / Site ID is precisely matched in the three-level mapping relationship dataset to query the corresponding tenant name, branch office name, and dedicated CPE device ID / identifier. Next, combined with the attack path graph, it confirms that the starting node of the attack traffic is the dedicated CPE device under this Site (i.e., the attack traffic originates from this CPE and is transmitted to SaaS / Internet via PoP1 / PoP2). Finally, it outputs the attack location result set, including: ① Attack tenant information: Customer ID, tenant name; ② Attack branch office information: Site ID, branch office name; ③ Attack dedicated CPE information: CPE ID, CPE device identifier / address; ④ Attack path graph: the complete path PC→CPE→PoP1→PoP2→SaaS / Internet.
[0065] The verification module 105 is used to retrieve the corresponding anchored attack audit logs and PC terminal information from Orch based on the attack location result set, filter and verify the IPs, and obtain the final source tracing result. Specifically, the core functions of the verification module 105 include: retrieving logs, extracting PC information, verifying the real source IP, and outputting the final source tracing result, thus completing the full-link source tracing from the PoP2 IP to the PC terminal.
[0066] In a specific application example, the verification module 105 includes: an anchor log retrieval unit, a PC terminal information extraction unit, and a real source IP verification unit.
[0067] The anchor log retrieval unit is used to retrieve the corresponding anchored attack audit logs in Orch based on the attack location result set, using CPE encoding and 3D source tracing anchors as filtering conditions, to obtain the target CPE-specific attack session logs. Specifically, the anchor log retrieval unit is directly connected to the anchor matching and parsing unit upstream, receiving the attack location result set. It uses the CPE ID + 3D source tracing anchor in the attack location result set as the core retrieval basis, the target CPE ID as the device filtering condition, and the 3D source tracing anchor as the data filtering condition, performing precise retrieval under these two conditions. In Orch's full-link audit database, based on the condition that CPE ID = target CPE ID and 3D source tracing anchor = attack anchor, it precisely retrieves the anchored attack audit logs (including PC terminal information, original source IP, attack traffic characteristics, etc.) collected by the CPE device that uniquely corresponds to this attack session.
[0068] The PC terminal information extraction unit is used to filter the target CPE-specific attack session logs according to the three-dimensional tracing anchor points, retain only the log records that match the current attack session, and extract PC terminal information from the filtered log records to obtain the PC terminal information set.
[0069] Specifically, the system performs precise filtering within the target CPE's dedicated attack session logs based on the three-dimensional source tracing anchor points, retaining only log records matching the current attack session (since the three-dimensional source tracing anchor points are unique, the filtering result is a single log entry). From the filtered log records, the system automatically extracts the core identification information of the customer's internal PC terminal, including: ① PC terminal source IP address (customer's internal private IP, such as 192.168.3.50); ② PC terminal MAC address (unique hardware identifier, such as 00-1B-44-11-3A-B7); ③ PC terminal access process (the application initiating the attack, such as a brute-force client / malicious script process). The final output is a set of PC terminal information (including PC IP / MAC / access process).
[0070] The real source IP verification unit is used to extract the original source IP from the target CPE's dedicated attack session log, parse the original source IP to obtain the real public network source IP, and verify the real public network source IP to obtain the final source tracing result.
[0071] Among them, regular expressions or flow feature matching can be used to extract the original source IP based on the traffic feature library, which can identify the source IP of encrypted traffic.
[0072] Specifically, the process begins with filtering private IPs to address the issue of internal IPs being untraceable to the public internet. The original source IP is extracted from the target CPE's dedicated attack session logs. If it's a private IP (e.g., the PC terminal's IP is 192.168.3.50), it automatically enters X-Forwarded-For (XFF) header resolution to extract the real public internet source IP, resolving IP spoofing or proxy forwarding issues. If it's a public internet IP, it's directly used as the real public internet source IP. Then, the extracted real public internet source IP is verified to be a valid public internet IP (not a reserved address, not a private address), and valid public internet IPs are retained. According to industry standards, private IPs include private IP network segments such as 192.168.0.0 / 16, 10.0.0.0 / 8, and 172.16.0.0 / 12.
[0073] The XFF header originates from the XFF request headers automatically recorded by the CPE device during attack traffic collection within the HTTP / HTTPS protocol. This header information records all proxy / gateway IP addresses the traffic passes through. Following the standard XFF header format (IP1, IP2, IP3...), the leftmost public IP address is extracted; this IP is the actual public IP address used by the client's internal PC terminal to access the public network. Example: If the XFF header is 110.120.130.140, 10.0.0.1, 192.168.3.50, then the leftmost address, 110.120.130.140, is extracted as the actual public IP address.
[0074] The final source tracing results include: ① Attack tenant information: Customer ID, tenant name; ② Attack branch information: Site ID, branch name; ③ Attack-specific CPE information: CPE ID, CPE device identifier / address; ④ Attack terminal information: Source IP, MAC address, and access process of the customer's internal PC terminal; ⑥ Attack the real source IP: The real public IP of the PC terminal (without spoofing or proxy). ⑦ Attack path: Visualized path map of PC terminal → CPE → PoP1 → PoP2 → SaaS / Internet; ⑧ Key attack information: attack time, attack type, and shared public IP address for PoP2.
[0075] This application uses CPE ID + three-dimensional source tracing anchor as dual conditions to retrieve the target CPE's exclusive attack session logs, extracts the PC terminal's IP, MAC, and access process information from a single matching log, and then uses a three-layer verification process of private IP network segment filtering, X-Forwarded-For request header parsing, and public IP validity verification to ensure the reliability and accuracy of the attack traffic's real public network source IP and PC terminal information.
[0076] Furthermore, the final source tracing results will be output to the operation and maintenance platform or emergency response system, allowing administrators to view and quickly handle attack incidents with one click.
[0077] The operational software-defined wide area network attack tracing system provided in this application can trace the attack back to a specific tenant, site, dedicated CPE, and customer's internal PC terminal through the shared public IP address of PoP2, and obtain the real public IP address of the attack and the complete attack path.
[0078] Based on the same inventive concept, such as Figure 2As shown in the embodiment of this application, a method for tracing the source of attacks on operational software-defined wide area networks is also provided, including the following steps 201 to 205.
[0079] Step 201: Generate three-dimensional source tracing anchors based on the original collected dataset, and remove normal business traffic data from the original collected dataset to obtain anchored attack audit data. The original collected dataset includes real-time raw traffic data and device-specific information collected by CPE devices, PoP1 devices, and PoP2 devices; the three-dimensional source tracing anchors include tenant codes, branch office codes, and session codes.
[0080] Step 202: Transfer the anchored attack audit data to Orch storage.
[0081] Step 203: Based on the attack warning information from SaaS / Internet, filter out the corresponding attack session data from Orch and extract the attack path to obtain the full-link aggregated dataset and attack path map.
[0082] Step 204: Based on the full-link aggregated dataset, the attack path map, and the tenant-organization-CPE mapping relationship, attack localization is performed to obtain the attack localization result set.
[0083] Step 205: Based on the attack location result set, retrieve the corresponding anchored attack audit logs and PC terminal information from Orch, filter and verify the IPs, and obtain the final source tracing result. The final source tracing result includes attack tenant information, attack branch information, attack-specific CPE information, attack terminal information, the real source IP of the attack, the attack path, and key attack information.
[0084] The following section uses a real-world attack scenario as an example to detail the execution flow of the operational software-defined wide area network (SaaS) attack tracing method. The core application scenario of this application is a brute-force attack on a customer's internal PC terminal → CPE → PoP1 → PoP2 → SaaS platform. The SaaS platform only reports a shared IP address for PoP2, requiring tracing back to the PC terminal.
[0085] The basic parameters of the scene include: (1) SD-WAN system architecture: 1 Orch orchestrator, 2 shared PoP nodes (PoP1 = access node, PoP2 = egress node), 50 CPE devices (belonging to 10 tenants, single tenant single CPE).
[0086] (2) Tenant information: Attacking tenant = Enterprise Z (Customer ID=C001), Branch office = Branch office in a certain location (SiteID=S001), Dedicated CPE = CPE3001 (Device ID=10.0.0.1).
[0087] (3) Link information: CPE3001 communicates with PoP2 through a dedicated IPsec tunnel. PoP2 shares a public IP address of 203.0.113.10 (shared by 10 tenants).
[0088] (4) Attacking terminal: Client's internal PC terminal (IP=192.168.3.50, MAC=00-1B-44-11-3A-B7, access process=brute force client).
[0089] (5) Attack behavior: The PC terminal initiated an SSH brute-force attack on the cloud-based financial SaaS platform. The SaaS platform only reported the attacking IP=203.0.113.10.
[0090] (6) Tracing target: From the shared IP of PoP2=203.0.113.10, trace back to enterprise Z+a branch office in a certain place+CPE3001+PC terminal+real public network IP.
[0091] The specific implementation steps are as follows: Step 1: Anchor point attack audit data collection, executed by anchor point collection module 101.
[0092] Input data: Raw traffic data collected by CPE3001 / PoP1 / PoP2 + PC terminal attack traffic.
[0093] Processing actions (executed according to the logic of anchor point acquisition module 101): ①The audit data acquisition unit collects PC terminal information (192.168.3.50 / 00-1B-44-11-3A-B7 / brute-force cracking process) + C001 / S001 + PoP2 IP=203.0.113.10 + tunnel link information.
[0094] ② The 3D anchor point generation unit generates anchor points: extract C001 / S001, generate session ID=20260104100000C00168952111310, anchor point=C001-S001-20260104100000C00168952111310, and bind all collected data.
[0095] ③ The attack data filtering unit performs filtering: only brute-force attack data is retained, normal traffic is filtered, and anchored attack audit data is generated.
[0096] Output data: The anchor point acquisition module 101 finally outputs anchor point attack audit data (including C001-S001 anchor points + PC information + PoP2 IP=203.0.113.10).
[0097] Step 2: Incremental breakpoint resume transmission to Orch, executed by data transmission module 102.
[0098] Input data: Anchor point attack audit data output by anchor point acquisition module 101.
[0099] Processing actions (executed according to the logic of data transmission module 102): ① The incremental push unit performs incremental push: using the three-dimensional source tracing anchor point as the unique identifier, it pushes newly added attack data without duplicate transmission.
[0100] ② The breakpoint resume unit performs breakpoint resume: local cache data, and real-time transmission to Orch when the network is normal, ensuring no data loss.
[0101] Output data: The data transmission module 102 ultimately outputs complete and lossless anchored attack audit data to Orch.
[0102] Step 3: Orch anchor resolution + IP matching + path restoration, executed by the link aggregation and path restoration module 103.
[0103] Input data: Core data output by data transmission module 102 + SaaS platform attack alarms (including 203.0.113.10 + brute force attack + 202601041000-1030).
[0104] Processing actions (executed according to the logic of link aggregation and path restoration module 103): ① The anchor point parsing unit performs parsing: extracts the anchor point C001-S001-XXX+PoP2 IP=203.0.113.10+PC information and stores it in the Orch database.
[0105] ② Matching by PoP2 IP-tenant matching unit: Filter the traffic data of 10 tenants under the PoP2 IP = 203.0.113.10 + time range.
[0106] ③ Anchor point association engine unit association: Using the three-dimensional source tracing anchor point as the index, filter out the attack traffic of enterprise Z, reverse associate PoP2→PoP1→CPE3001 data, and restore the attack path: PC→CPE3001→PoP1→PoP2→SaaS platform.
[0107] Output data: Full-link aggregated dataset and attack path map.
[0108] Step 4: Precise location of tenant-site-CPE, executed by tenant-organization-CPE location module 104.
[0109] Input data: Full-link aggregation dataset, attack path map, and hierarchical mapping relationship dataset (C001→S001→CPE3001) output by the link aggregation and path restoration module 103.
[0110] Processing actions (executed according to the tenant-organization-CPE location module 104 logic): ① Tenant mapping unit retrieves mapping library: retrieves the three-level mapping relationship of C001→S001→CPE3001.
[0111] ② Anchor point matching parsing unit parses anchor points: split anchor points to get C001 / S001, match mapping library, confirm attack tenant = enterprise Z, site = branch office in a certain location, CPE = CPE3001.
[0112] Output data: Attack location result set (including Customer / Site / CPE information).
[0113] Step 5: PC terminal + real source IP extraction and verification, the execution subject is verification module 105.
[0114] Input data: Attack location result set output by tenant-organization-CPE location module 104 + Orch full-link audit database.
[0115] Processing actions (executed according to the logic of verification module 105): ① Anchor point log retrieval unit retrieves logs: Retrieve dedicated attack session logs by using CPE3001+ 3D source tracing anchor point.
[0116] ② PC terminal information extraction unit extracts PC information: PC IP=192.168.3.50, MAC=00-1B-44-11-3A-B7, process=brute force client.
[0117] ③ The real source IP verification unit verifies the source IP: filters private IPs, parses the XFF header = 110.120.130.140, 10.0.0.1, 192.168.3.50, and extracts the real public IP = 110.120.130.140.
[0118] Output data: Final tracing results.
[0119] Step 6: Output the tracing results to the operation and maintenance platform.
[0120] Processing Action: Orch outputs the final traceability results to the operations and maintenance platform in the form of a visual report, which administrators can view and quickly handle with one click.
[0121] Traceability results: Fully automated, 100% accurate, with no human intervention.
[0122] In summary, compared with the prior art, the beneficial effects of this application include at least the following: (1) The accuracy of multi-tenant traffic differentiation can reach 100%: The three-dimensional source tracing anchor uniquely identifies traffic from three dimensions: tenant, site, and session, which completely solves the confusion problem of shared IP in PoP2 and the responsibility definition is zero error.
[0123] (2) Complete restoration of the attack chain: For the first time, it is possible to trace back from the shared IP of PoP2 to the customer's internal PC terminal, filling the gap in the existing technology of tracing the source.
[0124] (3) The entire process is automated, which improves the efficiency of traceability.
[0125] (4) Improved accuracy of source IP and PC information: The verification mechanism eliminates IP spoofing interference, and the extracted PC terminal information can directly support attack handling.
[0126] (5) Reduced deployment costs: No need to modify the existing SD-WAN architecture, only deploy a lightweight acquisition module in CPE / PoP, with strong compatibility.
[0127] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0128] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM).
[0129] The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, etc., and are not limited to these.
[0130] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0131] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. An operational software-defined wide area network (SDB) attack tracing system, wherein the core business link of the operational SDB is PC-CPE-PoP1-PoP2-SaaS / Internet, characterized in that, The operational software-defined wide area network attack attribution system includes: The anchor point acquisition module is used to generate three-dimensional source tracing anchor points based on the original acquisition dataset, and remove normal business traffic data from the original acquisition dataset to obtain anchor-based attack audit data; the original acquisition dataset includes real-time raw traffic data and device-specific information collected by CPE devices, PoP1 devices, and PoP2 devices; the three-dimensional source tracing anchor points include tenant codes, branch office codes, and session codes. The data transmission module is used to transmit the anchoring attack audit data to Orch storage; The link aggregation and path reconstruction module is used to filter out the corresponding attack session data from Orch based on the attack warning information of SaaS / Internet, and extract the attack path to obtain the full link aggregation dataset and attack path map. The tenant-organization-CPE localization module is used to locate attacks based on the full-link aggregated dataset, the attack path map, and the mapping relationship between tenants, organizations, and CPEs, and to obtain an attack localization result set. The verification module is used to retrieve the corresponding anchored attack audit logs and PC terminal information from Orch based on the attack location result set, filter and verify the IPs, and obtain the final source tracing result. The final source tracing result includes attack tenant information, attack branch information, attack-specific CPE information, attack terminal information, attack real source IP, attack path and key attack information.
2. The operational software-defined wide area network attack tracing system according to claim 1, characterized in that, The raw traffic data collected in real time by the CPE device includes: the source IP port of the attack traffic, the destination IP port of the attack traffic, the protocol, the timestamp, and the security policy trigger record; The raw traffic data collected in real time by the PoP1 device includes: PoP1 forwarding records and tenant isolation traffic identifiers; The raw traffic data collected in real time by the PoP2 device includes: PoP2 forwarding records, tenant isolation traffic identifiers, and PoP2 public network exit IPs; The inherent information of the device includes the inherent information of the CPE device and the information of the PC terminal.
3. The operational software-defined wide area network attack tracing system according to claim 1, characterized in that, The anchor point acquisition module includes: The audit data acquisition unit is used to acquire raw traffic data and device-specific information collected in real time from CPE devices, PoP1 devices and PoP2 devices to obtain raw data sets. A 3D anchor point generation unit is used to extract fixed factors and dynamic factors from the original data collection dataset, and concatenate the fixed factors with the dynamic factors to obtain 3D source tracing anchor points. The 3D source tracing anchor points are then embedded into the original data collection dataset to obtain an anchor point-bound structured dataset. The fixed factors include tenant codes and branch codes; the dynamic factors include timestamps, tenant codes, and traffic features. The attack data filtering unit is used to remove normal business traffic data from the anchor-bound structured dataset based on preset filtering rules, thereby obtaining anchor-bound attack audit data.
4. The operational software-defined wide area network attack tracing system according to claim 1, characterized in that, The data transmission module includes: The incremental push unit is used to determine new attack data based on the anchored attack audit data; The breakpoint resume unit is used to store the newly added attack data in a local temporary cache database and transfer the data in the local temporary cache database to Orch storage.
5. The operational software-defined wide area network attack tracing system according to claim 4, characterized in that, When the network is normal, the interrupted transmission unit transmits the data in the local temporary cache database to Orch in real time, and deletes the data in the local temporary cache database after the transmission is completed. When the network is interrupted, the data transmission is paused, and after the network is restored, the data in the local temporary cache database is transmitted to Orch in chronological order.
6. The operational software-defined wide area network attack tracing system according to claim 1, characterized in that, The link aggregation and path restoration module includes: Anchor point parsing unit is used to extract core key fields from Orch and bind the core key fields with anchored attack audit data to obtain anchor point parsing dataset; the core key fields include three-dimensional source tracing anchor points, PoP2 egress public network IP, PC terminal information, tenant code, branch office code, tunnel link information and attack traffic characteristics; The PoP2 IP-tenant matching unit is used to extract core matching factors from SaaS / Internet attack warning information and filter anchored attack audit data corresponding to the core matching factors from the anchor parsing dataset to obtain a multi-tenant traffic dataset; the core matching factors include the PoP2 shared public IP and the attack time range. The anchor point association engine unit is used to filter out attack session data that matches the attack alarm from the multi-tenant traffic dataset, extract tunnel link information from the attack session data, and use the three-dimensional source tracing anchor point as a global index to reverse associate the full-link anchor-based attack audit data in Orch to obtain the full-link aggregated dataset and attack path map.
7. The operational software-defined wide area network attack tracing system according to claim 1, characterized in that, The tenant-organization-CPE location module includes: The tenant mapping unit is used to obtain the global mapping relationship between tenants, branch offices, and CPEs provided by the SD-WAN tenant management system, and to obtain a three-level mapping relationship dataset. Anchor point matching and parsing unit is used to extract three-dimensional source tracing anchor points from the full-link aggregated dataset, and match the tenant code and branch code in the three-dimensional source tracing anchor points in the three-level mapping relationship dataset to determine the corresponding attack tenant information, attack branch information and attack-specific CPE information, and combine the attack path map to determine the attack location result set.
8. The operational software-defined wide area network attack tracing system according to claim 1, characterized in that, The verification module includes: Anchor point log retrieval unit is used to retrieve the corresponding anchor point-based attack audit log in Orch based on the attack location result set, using CPE encoding and three-dimensional source tracing anchor points as filtering conditions, to obtain the target CPE-specific attack session log. The PC terminal information extraction unit is used to filter the target CPE-specific attack session log according to the three-dimensional source tracing anchor point, retain only the log records that match the current attack session, and extract PC terminal information from the filtered log records to obtain the PC terminal information set. The real source IP verification unit is used to extract the original source IP from the target CPE's dedicated attack session log, parse the original source IP to obtain the real public network source IP, and verify the real public network source IP to obtain the final tracing result.
9. The operational software-defined wide area network attack tracing system according to claim 1, characterized in that, The anchor point acquisition module is deployed in CPE, PoP1 and PoP2 devices, and the link aggregation and path restoration module, the tenant-organization-CPE positioning module and the verification module are all deployed on Orch orchestration's local server.
10. A method for tracing the source of attacks on operational software-defined wide area networks (SDWs), using the operational SWD attack tracing system as described in any one of claims 1-9, characterized in that... The operational software-defined wide area network attack attribution method includes: A three-dimensional source tracing anchor point is generated based on the original collected dataset, and normal business traffic data in the original collected dataset is removed to obtain anchor-based attack audit data; the original collected dataset includes the original traffic data and inherent device information collected in real time by CPE devices, PoP1 devices and PoP2 devices; the three-dimensional source tracing anchor point includes tenant code, branch office code and session code. The anchoring attack audit data is transmitted to Orch storage; Based on the attack warning information from SaaS / Internet, the corresponding attack session data is filtered out from Orch, and the attack path is extracted to obtain the full-link aggregated dataset and attack path map. Attack localization is performed based on the full-link aggregated dataset, the attack path map, and the tenant-organization-CPE mapping relationship to obtain an attack localization result set; Based on the attack location result set, the corresponding anchored attack audit logs and PC terminal information are retrieved from Orch and the IPs are filtered and verified to obtain the final source tracing result. The final source tracing result includes attack tenant information, attack branch information, attack-specific CPE information, attack terminal information, attack real source IP, attack path, and key attack information.