Attack identification method and related apparatus

CN122845154APending Publication Date: 2026-09-29HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510392216.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-29
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0005]本申请提供一种攻击识别方法及相关装置,以解决DDoS攻击识别不准确,容易误告警的问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845154A_ABST
    Figure CN122845154A_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an attack identification device and related device to improve the accuracy of DDoS attack identification. The method comprises: counting statistical information of target packets flowing through a protection device within a time period, the target packets being packets with a target destination address and a target packet type, the statistical information comprising statistical values of at least one total traffic characteristic index, and the statistical information further comprising statistical values of at least one attack characteristic index; in response to a statistical value of one of the at least one total traffic characteristic index being greater than a corresponding total traffic characteristic threshold, determining whether a statistical value of one of the at least one attack characteristic index is beyond a corresponding baseline value; and in response to a statistical value of one of the at least one attack characteristic index being beyond a corresponding baseline value, determining that the target destination address is under attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet technology, and in particular to an attack identification method and related apparatus. Background Technology

[0002] A distributed denial-of-service (DDoS) attack is a type of network attack. The principle behind a DDoS attack is that an attacker controls a large number of botnet hosts to send a massive amount of packets to the target. This forces the target to process the large volume of packets from the attacker, exhausting its computing, network, and other system resources, ultimately preventing it from responding to service requests from legitimate users.

[0003] In some studies, to counter DDoS attacks and protect the security of computer system resources that may become targets, protective devices (such as dedicated DDoS protection devices or firewalls) are typically set up between the Internet and the protected network where the protected computer is located to reduce or eliminate the impact of DDoS attacks on the protected computer.

[0004] Protection devices detect whether a destination address is currently under a DDoS attack, issuing alerts and taking corresponding defensive measures. Common methods for detecting DDoS attacks include checking whether the rate / bandwidth of a specific type of packet exceeds a threshold. However, in scenarios facing sudden surges in traffic, checking whether the rate / bandwidth of a specific type of packet exceeds the threshold can easily generate false alarms. Summary of the Invention

[0005] This application provides an attack identification method and related apparatus to solve the problem of inaccurate DDoS attack identification and the tendency to generate false alarms.

[0006] The first aspect provides an attack identification method. This method is applied to a protection device or an analysis device connected to the protection device. The method includes: acquiring statistical information of target packets flowing through the protection device within a statistical period, wherein the target packets are packets with a destination address of a target destination address and a packet type of a target packet; the statistical information includes statistical values ​​of at least one total traffic characteristic indicator, the total traffic characteristic indicator including the total rate and / or the total bandwidth of the target packets; the statistical information also includes statistical values ​​of the at least one attack characteristic indicator; in response to the fact that the statistical value of one of the at least one total traffic characteristic indicator is greater than a corresponding total traffic characteristic threshold, determining whether the statistical value of one of the at least one attack characteristic indicator exceeds a corresponding baseline value; and in response to the fact that the statistical value of one of the at least one attack characteristic indicator exceeds the corresponding baseline value, determining that the target destination address has been attacked. Determining whether a target destination address has been attacked by using statistical values ​​of multiple dimensions of indicators such as total traffic characteristic indicators and attack characteristic indicators can improve the accuracy of DDoS attack identification and reduce the probability of false alarms.

[0007] In one possible implementation, the target message type is any one of the following message types: Synchronization Sequence Number (SYN) message, Synchronization Sequence Number Acknowledgment (SYN-ACK) message, Acknowledgment (ACK) message, Connection Termination (FIN) message, Connection Reset (RST) message, Hypertext Transfer Protocol (HTTP) request message, and Hypertext Transfer Protocol Security (HTTPS) request message. Thus, the protection device can identify various DDoS attacks, reducing the impact on the protected device.

[0008] In one possible implementation, the at least one attack characteristic indicator includes the fake source packet rate of a fake source target packet. The fake source target packet is a target packet outside of a real session, where the real session is a session that has completed a TCP three-way handshake. The fake source packet rate is the rate at which the fake source target packet flows through the protection device within the statistical duration. The baseline value corresponding to the fake source packet rate is a fake source packet rate threshold. Determining that the target destination address is under attack in response to the statistical value of one of the at least one attack characteristic indicators exceeding the corresponding baseline value includes: determining that the target destination address is under attack in response to the statistical value corresponding to the fake source packet rate being greater than the fake source packet rate threshold. Therefore, by using the magnitude of the statistical value of the fake source packet rate, it is possible to accurately determine whether the protected device has suffered a DDoS attack, improving the accuracy of DDoS attack identification and reducing the probability of false alarms.

[0009] In one possible implementation, the spoofed source target packet includes a first spoofed source target packet, which is the target packet in a session created by a packet other than a SYN packet and a SYN-ACK packet. The spoofed source packet rate includes a first spoofed source packet rate, which is the rate at which the first spoofed source target packet flows through the protection device within the statistical duration. The baseline value corresponding to the first spoofed source packet rate is a first spoofed source packet rate threshold. Determining that the target destination address has been attacked in response to the statistical value corresponding to the spoofed source packet rate being greater than the spoofed source packet rate threshold includes: determining that the target destination address has been attacked in response to the statistical value corresponding to the first spoofed source packet rate being greater than the first spoofed source packet rate threshold.

[0010] In one possible implementation, the target packet type is a FIN packet or an RST packet, the spoofed source target packet includes a second spoofed source target packet, the second spoofed source target packet being the target packet in a session created by a SYN packet or SYN-ACK packet but which has not yet completed a three-way handshake by the end of the statistical duration, the spoofed source packet rate includes a second spoofed source packet rate, the second spoofed source packet rate being the rate of the second spoofed source target packets flowing through the protection device within the statistical duration, and the baseline value corresponding to the second spoofed source packet rate being a second spoofed source packet rate threshold; determining that the target destination address has been attacked in response to the statistical value corresponding to the spoofed source packet rate being greater than the spoofed source packet rate threshold includes: determining that the target destination address has been attacked in response to the statistical value corresponding to the second spoofed source packet rate being greater than the second spoofed source packet rate threshold.

[0011] In one possible implementation, the target packet type is a FIN packet or an RST packet, the spoofed source target packet includes a third spoofed source target packet, the third spoofed source target packet is a target packet of a closed session, the spoofed source packet rate includes a third spoofed source packet rate, the third spoofed source packet rate is the rate of the third spoofed source target packet flowing through the protection device within the statistical duration, and the baseline value corresponding to the third spoofed source packet rate is a third spoofed source packet rate threshold; determining that the target destination address is attacked in response to the statistical value corresponding to the spoofed source packet rate being greater than the spoofed source packet rate threshold includes: determining that the target destination address is attacked in response to the statistical value corresponding to the third spoofed source packet rate being greater than the third spoofed source packet rate threshold.

[0012] In one possible implementation, the target packet type is an ACK packet, an HTTP request packet, or an HTTPS request packet. The at least one attack feature indicator includes an average packet length difference, which is the average of all packet length difference values ​​within the statistical period. The packet length difference value is the difference in packet length between two target packets received within the statistical period that belong to the same real session and are received at adjacent times. The real session is a session that has completed a TCP three-way handshake. The baseline boundary threshold corresponding to the average packet length difference is a packet length difference threshold. Determining that the target destination address is attacked in response to the statistical value of one of the at least one attack feature indicators exceeding the corresponding baseline value includes: determining that the target destination address is attacked in response to the statistical value corresponding to the average packet length difference being greater than the packet length difference threshold.

[0013] In one possible implementation, the target packet type is an ACK packet, and the at least one attack feature indicator includes the average target packet rate of active sessions. The active session is a session within the statistical duration in which the target packet flows through the protection device. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions within the statistical duration. The target packet rate corresponding to the active session is the rate of the target packet flowing through the protection device in the active session within the statistical duration. The baseline boundary threshold corresponding to the average target packet rate of the active session is a first rate threshold. Determining that the target destination address is attacked in response to the statistical value of one of the statistical values ​​of the at least one attack feature indicator exceeding the corresponding baseline value includes: determining that the target destination address is attacked in response to the statistical value corresponding to the average target packet rate of the active session being greater than the first rate threshold.

[0014] In one possible implementation, the target packet type is an HTTP request packet or an HTTPS request packet. The at least one attack feature indicator includes the average target packet rate of an active session. An active session is a session in which HTTP or HTTPS packets flow through the protection device within the statistical duration. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions within the statistical duration. The target packet rate corresponding to the active session is the number of target packets in the active session flowing through the protection device within the statistical duration. The baseline boundary threshold corresponding to the average target packet rate of the active session is a second rate threshold. Determining that the target destination address has been attacked in response to the statistical value of one of the statistical values ​​of the at least one attack feature indicator exceeding the corresponding baseline value includes: determining that the target destination address has been attacked in response to the statistical value corresponding to the average target packet rate of the active session being greater than the second rate threshold.

[0015] In one possible implementation, the target packet type is an ACK packet, an HTTP request packet, or an HTTPS request packet; the total traffic characteristic threshold corresponding to the total rate is a total rate threshold; and the total traffic characteristic threshold corresponding to the total bandwidth is a total bandwidth threshold. The method further includes: in response to the total rate being greater than the total rate threshold, determining whether the total rate is greater than n times the total rate threshold, where n is a positive number greater than 1; in response to the total rate being greater than n times the total rate threshold, determining that the target destination address is under attack; and / or in response to the total bandwidth being greater than the total bandwidth threshold, determining whether the total bandwidth is greater than m times the total bandwidth threshold, where m is a positive number greater than 1; in response to the total bandwidth being greater than m times the total bandwidth threshold, determining that the target destination address is under attack.

[0016] In one possible implementation, the method further includes: in response to the fact that the statistical values ​​of all total traffic characteristic indicators in the statistical values ​​of the at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, obtaining statistical information of target packets corresponding to K target statistical durations, wherein the K target statistical durations include the statistical duration, the target destination address is not attacked within the K target statistical durations, and K is an integer greater than or equal to 2; and determining the baseline value corresponding to each attack characteristic indicator based on the statistical value corresponding to each of the attack characteristic indicators within the K target statistical durations.

[0017] In one possible implementation, the baseline value corresponding to the attack feature index is the maximum and / or minimum value among the statistical values ​​corresponding to the attack feature index within the statistical duration of the K targets.

[0018] A second aspect provides an attack identification device, comprising a processing module. The processing module is used to acquire statistical information of target packets flowing through a protection device within a statistical period. The target packets are packets with a destination address of a target destination address and a packet type of a target packet. The statistical information includes statistical values ​​of at least one total traffic characteristic indicator, which includes the total rate and / or the total bandwidth of the target packets. The statistical information also includes statistical values ​​of the at least one attack characteristic indicator. The processing module is used to, in response to the presence of a statistical value of at least one total traffic characteristic indicator that is greater than a corresponding total traffic characteristic threshold, determine whether a statistical value of the at least one attack characteristic indicator exceeds a corresponding baseline value. The processing module is also used to, in response to the presence of a statistical value of at least one attack characteristic indicator that exceeds a corresponding baseline value, determine that the target destination address has been attacked.

[0019] In one possible implementation, the target message type is any one of the following message types: Synchronization Sequence Number (SYN) message, Synchronization Sequence Number Acknowledgment (SYN-ACK) message, Acknowledgment (ACK) message, Connection End (FIN) message, Connection Reset (RST) message, Hypertext Transfer Protocol (HTTP) request message, and Hypertext Transfer Protocol Security (HTTPS) request message.

[0020] In one possible implementation, the at least one attack characteristic indicator includes the fake source packet rate of a fake source target packet, wherein the fake source target packet is the target packet outside the real session, the real session is a session that has completed the Transmission Control Protocol (TCP) three-way handshake, the fake source packet rate is the rate of the fake source target packet flowing through the protection device within the statistical duration, and the baseline value corresponding to the fake source packet rate is a fake source packet rate threshold; the processing module is configured to: determine that the target destination address has been attacked in response to the statistical value corresponding to the fake source packet rate being greater than the fake source packet rate threshold.

[0021] In one possible implementation, the spoofed source target packet includes a first spoofed source target packet, which is the target packet in a session created by a packet other than a SYN packet and a SYN-ACK packet. The spoofed source packet rate includes a first spoofed source packet rate, which is the rate of the first spoofed source target packet flowing through the protection device within the statistical duration. The baseline value corresponding to the first spoofed source packet rate is a first spoofed source packet rate threshold. The processing module is configured to: determine that the target destination address is under attack in response to a statistical value corresponding to the first spoofed source packet rate being greater than the first spoofed source packet rate threshold.

[0022] In one possible implementation, the target packet type is a FIN packet or an RST packet, the spoofed source target packet includes a second spoofed source target packet, the second spoofed source target packet is the target packet in a session created by a SYN packet or SYN-ACK packet but still not completed a three-way handshake at the end of the statistical duration, the spoofed source packet rate includes a second spoofed source packet rate, the second spoofed source packet rate is the rate of the second spoofed source target packets flowing through the protection device within the statistical duration, the baseline value corresponding to the second spoofed source packet rate is a second spoofed source packet rate threshold; the processing module is used to: determine that the target destination address is under attack in response to the statistical value corresponding to the second spoofed source packet rate being greater than the second spoofed source packet rate threshold.

[0023] In one possible implementation, the target packet type is a FIN packet or an RST packet, the fake source target packet includes a third fake source target packet, the third fake source target packet is a target packet of a closed session, the fake source packet rate includes a third fake source packet rate, the third fake source packet rate is the rate of the third fake source target packet flowing through the protection device within the statistical duration, and the baseline value corresponding to the third fake source packet rate is a third fake source packet rate threshold; the processing module is used to: determine that the target destination address is under attack in response to the statistical value corresponding to the third fake source packet rate being greater than the third fake source packet rate threshold.

[0024] In one possible implementation, the target packet type is an ACK packet, an HTTP request packet, or an HTTPS request packet. The at least one attack characteristic indicator includes an average packet length difference, which is the average of all packet length differences within the statistical period. The packet length difference value is the difference in packet length between two target packets received within the statistical period that belong to the same real session and have adjacent reception times. The real session is a session that has completed a TCP three-way handshake. The baseline boundary threshold corresponding to the average packet length difference is a packet length difference threshold. The processing module is configured to: determine that the target destination address has been attacked in response to a statistical value corresponding to the average packet length difference being greater than the packet length difference threshold.

[0025] In one possible implementation, the target packet type is an ACK packet, and the at least one attack characteristic indicator includes the average target packet rate of active sessions. The active session is a session within the statistical duration in which the target packet flows through the protection device. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions within the statistical duration. The target packet rate corresponding to the active session is the rate of the target packet flowing through the protection device in the active session within the statistical duration. The baseline boundary threshold corresponding to the average target packet rate of the active session is a first rate threshold. The processing module is configured to: determine that the target destination address is under attack in response to a statistical value corresponding to the average target packet rate of the active session being greater than the first rate threshold.

[0026] In one possible implementation, the target packet type is an HTTP request packet or an HTTPS request packet, and the at least one attack characteristic indicator includes the average target packet rate of active sessions. An active session is a session within the statistical duration in which HTTP or HTTPS packets flow through the protection device. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions within the statistical duration. The target packet rate corresponding to the active session is the number of target packets in the active sessions flowing through the protection device within the statistical duration. The baseline boundary threshold corresponding to the average target packet rate of the active session is a second rate threshold. The processing module is configured to: determine that the target destination address has been attacked in response to a statistical value corresponding to the average target packet rate of the active session being greater than the second rate threshold.

[0027] In one possible implementation, the target packet type is an ACK packet, an HTTP request packet, or an HTTPS request packet; the total traffic characteristic threshold corresponding to the total rate is a total rate threshold; the total traffic characteristic threshold corresponding to the total bandwidth is a total bandwidth threshold; the processing module is configured to, in response to the total rate being greater than the total rate threshold, determine whether the total rate is greater than n times the total rate threshold, where n is a positive number greater than 1; the processing module is configured to, in response to the total rate being greater than n times the total rate threshold, determine that the target destination address has been attacked; and / or the processing module is configured to, in response to the total bandwidth being greater than the total bandwidth threshold, determine whether the total bandwidth is greater than m times the total bandwidth threshold, where m is a positive number greater than 1; the processing module is configured to, in response to the total bandwidth being greater than m times the total bandwidth threshold, determine that the target destination address has been attacked.

[0028] In one possible implementation, the processing module is configured to, in response to the fact that the statistical values ​​of all total traffic characteristic indicators in the statistical values ​​of the at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, obtain statistical information of target packets corresponding to K target statistical durations, wherein the K target statistical durations include the statistical duration, and the target destination address is not attacked within the K target statistical durations, and K is an integer greater than or equal to 2; the processing module is configured to determine the baseline value corresponding to each attack characteristic indicator based on the statistical value corresponding to each of the attack characteristic indicators within the K target statistical durations.

[0029] In one possible implementation, the baseline value corresponding to the attack feature index is the maximum and / or minimum value among the statistical values ​​corresponding to the attack feature index within the statistical duration of the K targets.

[0030] Thirdly, an attack identification device is provided, including a processor and an interface circuit. The interface circuit is used to receive signals from other devices outside the attack identification device and transmit them to the processor, or to send signals from the processor to other devices outside the attack identification device. The processor implements the methods described in the first aspect and any possible implementations thereof through logic circuits or executing code instructions. The attack identification device can be a copy unit, a memory controller, or a memory module.

[0031] Fourthly, a computer-readable storage medium is provided that stores a computer program or instructions that, when executed by a processor, implement the methods described in the first aspect and any possible implementation thereof.

[0032] Fifthly, a computer program product storing instructions is provided, which, when executed by a processor, implements the methods described in the first aspect and any possible implementation thereof.

[0033] Sixthly, a chip is provided, comprising a processor and potentially a memory, for implementing the methods described in the first aspect and any possible implementation thereof. The chip system may be composed of a chip or may include chips and other discrete devices. Attached Figure Description

[0034] Figure 1 This is a schematic diagram of a TCP packet structure;

[0035] Figure 2 This is a diagram illustrating the process of establishing a TCP connection;

[0036] Figure 3 This is a diagram illustrating the process of disconnecting a TCP connection.

[0037] Figure 4 This is a schematic diagram illustrating an application scenario provided in an embodiment of this application;

[0038] Figure 5 This is a schematic diagram illustrating another application scenario provided by an embodiment of this application; Figure 6 This is a schematic diagram illustrating another application scenario provided in the embodiments of this application;

[0039] Figure 7 This is a schematic diagram of the structure of a protective device provided in an embodiment of this application;

[0040] Figure 8 This is a flowchart illustrating an attack identification method provided in an embodiment of this application;

[0041] Figure 9 This is a flowchart illustrating another attack identification method provided in an embodiment of this application;

[0042] Figure 10 This is a flowchart illustrating another attack identification method provided in an embodiment of this application;

[0043] Figure 11 This is a flowchart illustrating another attack identification method provided in an embodiment of this application;

[0044] Figure 12 This is a flowchart illustrating another attack identification method provided in an embodiment of this application;

[0045] Figure 13 This is a flowchart illustrating another attack identification method provided in an embodiment of this application;

[0046] Figure 14 This is a schematic diagram of the structure of an attack identification device provided in an embodiment of this application. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.

[0048] To facilitate understanding of the technical solutions provided in the embodiments of this application, the relevant terms involved in this application are explained below.

[0049] 1. Transmission Control Protocol (TCP)

[0050] TCP is a connection-oriented protocol that provides ordered, reliable, full-duplex virtual circuit transmission services.

[0051] like Figure 1 As shown, Figure 1 This is a schematic diagram of a TCP packet structure. The fields in the TCP packet header and their meanings are as follows:

[0052] Source port, 16 bits. Identifies the port number of the application on the sending side. For example, HTTP uses port 80, HTTPS uses port 160, and the file transfer protocol (FTP) uses port 21, etc.

[0053] Destination port, 16 bits. Identifies the port number of the application on the receiving end.

[0054] Sequence number (Seq), 32 bits. Represents the position of the current packet within the packet stream; it can also be used to provide the initial sequence number when establishing a TCP connection.

[0055] The acknowledgment number (Ack) is 32 bits. It is used to acknowledge receipt of data from other communication devices. The acknowledgment number is only valid if the acknowledgment (ACK) bit is set in the control field, at which point it defines the sequence number of the next expected byte.

[0056] Header length, 4 digits.

[0057] Reserved, 6 bits. Reserved is unused; all 6 bits must be set to 0.

[0058] Control field, 6 bits. Includes 6 flag bits, namely:

[0059] Emergency flag (urgent, URG): If set (value 1), it indicates that the emergency pointer field is valid.

[0060] Acknowledgment flag ACK: If set (value is 1), it indicates that the acknowledgment number field is valid.

[0061] Push flag (push, PSH): If set (value is 1), it indicates that the push function can be used.

[0062] Reset flag (reset, RST): If set (value 1), it indicates that the connection should be reset.

[0063] Synchronization Flag SYN: If set (value 1), indicates the sequence number to be synchronized. This flag can be used when establishing a connection. When the SYN field is set to 1 and the ACK field is set to 0, it indicates a SYN packet requesting a connection; in this case, the sequence number in the sequence number field is the sequence number provided by the sender. When the SYN field is set to 1 and the ACK field is set to 1, it indicates a SYN-ACK packet acknowledging a SYN packet.

[0064] Termination flag (finish, FIN): If set (value 1), it indicates that the sender is no longer sending data and is used to terminate the connection.

[0065] Window size (16-bit). Defines the size of the sliding window, indicating the amount of data the receiver can receive.

[0066] Checksum, 16 bits. Used to verify the integrity of the TCP header and TCP data. If the checksum fails, the packet is discarded.

[0067] The urgent pointer, 16 bits. It is valid when the value of URG is set to 1, and the urgent pointer points to the last byte of urgent data.

[0068] Options, with a variable length, are used to provide extended functionality and support flexible configuration.

[0069] Padding is used to ensure that the length of the entire TCP header is a multiple of 4 bytes. Zero padding is typically used.

[0070] 2. TCP three-way handshake

[0071] In TCP, the two communicating parties use a three-way handshake to establish a connection.

[0072] The process of establishing a TCP connection is as follows Figure 2 As shown, during the first handshake, the client sends a synchronize sequence numbers (SYN) message to the server. The SYN flag in the SYN message is set to 1, and the value of the sequence number field in the SYN message is represented by X.

[0073] During the second handshake, after receiving the client's request, the server sends a synchronize sequence numbers acknowledgement (SYN-ACK) message to the client. In the SYN-ACK message, both the SYN and ACK flags are set to 1. The sequence number field in the SYN-ACK message is represented by Y, and the acknowledgment number field is X+1, indicating that the server has received the client's SYN message.

[0074] During the third handshake, after receiving the SYN-ACK packet from the server, the client checks if the value in the sequence number field of the SYN-ACK packet is correct, i.e., whether it is X+1. If correct, the client sends an ACK packet to the server, and the client enters the established state. The ACK flag in the ACK packet is set to 1, and the SYN flag is set to 0. The sequence number field in the ACK packet is X+1, and the acknowledgment number field is Y+1, indicating that the client has received the server's SYN-ACK packet. After receiving the ACK packet, the server checks if the value in the acknowledgment number field of the ACK packet is correct, i.e., whether it is Y+1. If correct, the client enters the established state. After the three-way handshake, the server and client establish a TCP connection.

[0075] If the value in the acknowledgment number field of the SYN-ACK packet is incorrect, the client will send an RST packet to the server to terminate the connection establishment process. Alternatively, if the value in the acknowledgment number field of the ACK packet is incorrect, the server will send an RST packet to the client to terminate the connection.

[0076] 3. TCP four-way handshake

[0077] The TCP four-way handshake is used to terminate a TCP connection. When closing a TCP connection, the client and server need to send a total of four packets to confirm the termination.

[0078] The process of disconnecting a TCP connection is as follows Figure 3 As shown. The first handshake: The party initiating the disconnection (which can be either a client or a server) sends a FIN packet to the other party to request disconnection. The FIN flag and ACK flag in this FIN packet are set to 1. The value in the sequence number field (Seq) is assumed to be 'a'. After sending the FIN packet, the party initiating the disconnection enters the disconnection wait-1 (FIN_WAIT_1) state, indicating that it has no business data to send to the other party and is preparing to close the TCP connection.

[0079] The second handshake: Under normal circumstances, after receiving the FIN disconnect request packet from the initiating disconnector, the passive disconnector sends an ACK packet to acknowledge the FIN packet. The ACK flag in this ACK packet is set to 1. The sequence number field of the ACK packet is 'b'. The acknowledgment number field (Ack) of the ACK packet is 'a+1', indicating that the passive disconnector agrees to the initiating disconnector's connection disconnection request. Afterward, the passive disconnector enters the close-wait (CLOSE-WAIT) state. The passive disconnector's CLOSE-WAIT state lasts for a period of time, which is the entire duration of the CLOSE-WAIT state.

[0080] After receiving the ACK message, the party that initiates the disconnection transitions from the FIN_WAIT_1 state to the FIN_WAIT_2 state.

[0081] The third handshake: After sending the ACK packet, the passively disconnecting party can continue sending service data. Once the remaining data is sent or the CLOSE-WAIT period ends, the passively disconnecting party will send a FIN packet to the actively disconnecting party, indicating that all data has been sent. Then, the passively disconnecting party enters the LAST_ACK state. The FIN flag and ACK flag in this FIN packet are set to 1, the sequence number field is assumed to be 'c', and the acknowledgment number field is 'a+1'.

[0082] The fourth handshake: After receiving the FIN packet from the passively disconnected party, the active disconnecting party needs to make a final confirmation by sending an ACK packet to the passively disconnecting party. Then, the active disconnecting party enters the TIME_WAIT state and closes the connection after the timeout. The ACK flag in the ACK packet is set to 1, the sequence number field is set to a+1, and the acknowledgment number field is set to c+1.

[0083] After the above four-way handshake process, the two communicating parties disconnected a TCP connection.

[0084] 4. Distributed Denial of Service (DDoS) Attack

[0085] A denial-of-service (DoS) attack is a type of network attack. The purpose of a DoS attack is to exhaust the network or system resources of the attacked party, thereby temporarily interrupting or stopping the services provided by the attacked party, preventing legitimate users from accessing the attacked party. When an attacker (also known as a hacker) uses two or more controlled computers on the network as the initiating force to launch a DoS attack against the attacked party, this type of attack is called a DDoS attack.

[0086] When an attacker launches a DDoS attack, they send a large number of messages to the target, such as User Datagram Protocol (UDP) messages, SYN messages, SYN-ACK messages, ACK messages, FIN messages, RST messages, Domain Name System (DNS) messages, Hypertext Transfer Protocol (HTTP) messages, Internet Control Message Protocol (ICMP) messages, Hypertext Transfer Protocol over Secure Socket Layer (HTTPS) messages, or Session Initiation Protocol (SIP) messages, to form various types of flood attacks.

[0087] From the perspective of protocol layering and attack damage, DDoS attacks can be divided into three main categories: network layer attacks, session exhaustion attacks, and application layer attacks. Network layer attacks: Attackers send a large number of network layer packets to the target through a botnet, creating massive bandwidth traffic and causing link bandwidth congestion in the target's network. Common network layer attacks include SYN-ACK flood attacks and ACK flood attacks. Session exhaustion attacks: Attackers send a large number of packets through a botnet, quickly exhausting the session resources of devices or target servers in the target's network that rely on session forwarding. Common session exhaustion attacks include SYN flood attacks and network layer CC (challenge collapsar) attacks. Application layer attacks: Attackers use a large number of bot hosts to establish TCP connections with the target, continuously initiating application layer business access requests, leading to resource exhaustion of the target's business system. Common application layer attacks include HTTP flood attacks and HTTPS flood attacks.

[0088] The following sections explain some typical DDoS attacks.

[0089] SYN flood attack. A typical example of a spoofed source attack, the most significant characteristic of this type of attack is the massive influx of packets with varying source or port values ​​to the victim host, exhausting the victim host's or network resources. SYN flood is based on TCP and attacks the server through the TCP three-way handshake mechanism. During the SYN flood three-way handshake, multiple half-open connections are created, thus consuming the server's connection limit. Specifically, the attacker forges the source IP address and sends a large number of SYN packets to the server, requesting to establish a three-way handshake. Because the source IP is forged, after the server responds with a SYN-ACK packet, the source IP does not continue to respond with ACK packets for confirmation. At this point, the server builds a large wait list, continuously sending SYN-ACK packets repeatedly, while the server occupies a large amount of resources that cannot be released. This causes the attacked server to be filled with malicious half-open connections, no longer accepting new SYN requests, while normal users cannot complete the three-way handshake to establish a TCP connection.

[0090] SYN-ACK flood attack. SYN-ACK packets appear in the second handshake to confirm the first handshake. Upon receiving a SYN-ACK packet, one party first determines if it falls within the scope of the three-way handshake. If the first handshake is still in progress when the second handshake packet is received, an RST packet is sent to the other party, informing them that the packet was erroneous and a connection cannot be established. A SYN-ACK flood attack involves attackers using tools or controlling botnets to send a large number of SYN-ACK packets to the target server. These packets appear out of nowhere in the second handshake, overwhelming the server with RST responses, leading to resource exhaustion and an inability to respond to legitimate requests.

[0091] ACK flood attack. In the TCP three-way handshake, the ACK packet appears in the third handshake to acknowledge the SYN-ACK packet in the second handshake. An ACK flood attack refers to an attacker using tools or manipulating botnets to send a large number of ACK packets to the target server. The server is busy replying to these unexpected third handshake packets, leading to resource exhaustion and inability to respond to normal requests.

[0092] FIN / RST flood attacks. During TCP communication, FIN and RST packets also exist. The FIN packet is used to close the TCP connection, and the RST packet is used to disconnect the TCP connection. These two packets can also be exploited by attackers to launch DDoS attacks, causing the target server to exhaust its resources and become unable to respond to legitimate requests.

[0093] HTTP flood attack. HTTP is a request / response protocol. After the two communicating parties complete the TCP three-way handshake, the client sends an HTTP request to the server, and the server returns a response to the client after receiving the HTTP request. Attackers use attack tools or manipulate botnets to send a large number of HTTP request messages, such as HTTP GET / POST request messages, to the target server. These request messages generally consume a lot of server system resources (such as requesting database operations), eventually causing the server system resources to be exhausted and unable to respond to normal requests.

[0094] HTTPS flood attacks are similar to HTTP flood attacks.

[0095] 5. Speed ​​and bandwidth

[0096] In this embodiment, the rate refers to the number of qualified messages received by the protection device per second.

[0097] Bandwidth refers to the cumulative number of bits per second that a protection device receives from eligible packets. Units of bandwidth include, for example, bits per second (bit / s or bps), kilobits per second (Kbps or Kb / s), megabits per second (Mbps or Mb / s), gigabits per second (Gbps or Gb / s), terabits per second (Tbps or Tb / s), or petabits per second (Pbps or Pb / s).

[0098] DDoS attacks can cause significant economic and brand damage to their targets, while also posing a risk of the theft of the victim's core business data. To counter DDoS attacks and protect the security of computer system resources that may become targets, protective devices (such as dedicated DDoS protection devices or firewalls) are typically installed between the internet and the protected network where the protected computer resides. DDoS detection algorithms are used to identify DDoS attacks, and corresponding defensive measures are implemented to mitigate or eliminate the impact of DDoS attacks on the protected computer.

[0099] Currently, common methods for detecting DDoS attacks include checking whether the rate / bandwidth of a specific type of packet exceeds a threshold. However, in scenarios facing sudden surges in business traffic, detecting whether the rate / bandwidth of a specific type of packet exceeds the threshold can easily generate false alarms. False alarms may increase packet forwarding latency, causing normal business traffic to be mistakenly blocked, leading to service interruptions or delays, and wasting human and time resources.

[0100] In view of this, embodiments of this application provide a scheme for identifying attacks by statistically analyzing the traffic flowing through a protection device. The protection device or an analysis device communicatively connected to the protection device implements this technical solution by statistically analyzing target packets of target packet types sent to the target destination address across different dimensions, obtaining statistical values ​​corresponding to each dimension's indicators, and identifying whether the target destination address is under a DDoS attack based on these statistical values.

[0101] The basic principle of the above technical solution for identifying DDoS attacks lies in statistically analyzing at least one total traffic characteristic indicator and at least one attack characteristic indicator of the target packets, obtaining statistical values ​​for each total traffic characteristic indicator and attack characteristic indicator. The total traffic characteristic indicator reflects the overall traffic situation of the target packets, such as the total rate or total bandwidth. However, it is difficult to distinguish between a DDoS attack and normal business traffic growth solely based on the statistical value of the total traffic characteristic indicator. Therefore, when the statistical value of a total traffic characteristic indicator exceeds its corresponding total traffic characteristic threshold, the statistical value of the attack characteristic indicator is further used to determine whether the target destination address has been attacked. The attack characteristic indicators are designed based on the behavioral characteristics of DDoS attacks, enabling more accurate identification of DDoS attacks. When the statistical value of an attack characteristic indicator exceeds its corresponding baseline value, it is determined that the target destination address is under DDoS attack. Thus, by using statistical values ​​from multiple dimensions of indicators, DDoS attacks can be identified more accurately, reducing the probability of incorrect DDoS attack identification.

[0102] This application embodiment is used to identify DDoS attacks. Optionally, this application embodiment is specifically used to identify flood attacks within DDoS attacks. The types of flood attacks identified by this application embodiment include, but are not limited to, TCP flood attacks, HTTP flood attacks, HTTPS flood attacks, etc. The identified TCP flood attacks include, but are not limited to, SYN flood attacks, SYN-ACK flood attacks, ACK flood attacks, FIN flood attacks, RST flood attacks, etc.

[0103] The following section provides a detailed introduction to this technical solution from multiple perspectives, including application scenarios, hardware devices, software devices, and methodologies.

[0104] The following are examples illustrating the application scenarios of embodiments of this application.

[0105] For example, Figure 4 This is a schematic diagram of an application scenario provided in an embodiment of this application. Figure 4 The application scenario shown is a typical DDoS protection scenario. For example... Figure 4As shown, the network deployment in this protection scenario mainly involves four network devices: a normal client, an attacker, a protection device, and a protected device. Examples of each of these four network devices are provided below.

[0106] (1) Normal client

[0107] The legitimate client initiates the business traffic. It generates and sends business traffic to the server to access services provided on the server. The legitimate client can be, for example, browser software or business client software. Optionally, the legitimate client is located on the internet. After a legitimate client on the internet initiates business traffic, the protection device intercepts the traffic and performs security checks. If the traffic is determined to be threatening, the protection device forwards it to a protected device within the protected network.

[0108] (2) Attacker

[0109] Attackers generate and send attack traffic to protected devices using tools, botnets, or proxies. Optionally, the attacker is located on the internet, meaning the attacker launches the attack from the internet to the protected device within the protected network.

[0110] (3) Protected equipment

[0111] The protected device resides within a protected network. From the perspective of the protected device, the protected network is the internal network, and the Internet is the external network. Optionally, the protected network includes one or more local area networks (LANs). The protected device is a protected server. Protected devices include, but are not limited to, application servers or web servers. Application servers include, but are not limited to, game servers, video application servers, file servers, search engine servers, instant messaging servers, etc. Web servers are also called World Wide Web (WWW) servers or website servers.

[0112] (4) Protective equipment

[0113] Protective devices are deployed between the internet and the protected network. In other words, they are deployed at the boundary of the protected network to protect the protected devices within it from attacks. These devices perform security checks on traffic entering the protected network to determine whether it is service traffic or attack traffic. Furthermore, they block attack traffic to ensure the security of the protected devices, while forwarding service traffic to ensure the protected devices can provide services. Protective devices include, but are not limited to, firewalls, security gateways (such as routers or switches), intrusion detection systems (IDS), intrusion prevention systems (IPS), unified threat management (UTM), anti-virus (AV), anti-DDoS devices, and next-generation firewalls (NGFW), or a combination of these.

[0114] For example, Figure 5 This is a schematic diagram of another application scenario provided by the embodiments of this application. Figure 5 The application scenario shown is another typical DDoS protection scenario. (Compared to...) Figure 4 The application scenarios shown are different. Figure 5 The application scenarios shown also include management devices. These management devices communicate with the protection devices. For example... Figure 5 As shown, the network deployment in this protection scenario mainly involves five network devices: normal client, attacker, protection device, protected device, and management device. Figure 5 Attackers, public servers, security devices, protected devices and Figure 4 Similarly, please refer to the above. Figure 4 The descriptions of normal clients, attackers, protective devices, and protected devices will not be repeated here.

[0115] Please see Figure 5The protected network comprises multiple local area networks (LANs), such as LAN A, LAN B, and LAN C. Optionally, these LANs are deployed in different regions; for example, LAN A is deployed in Shanghai, LAN B in Beijing, and LAN C in Guangzhou. Each LAN is connected to the Internet via a dedicated protection device. For instance, protection device A connects LAN A to the Internet and protects servers within LAN A; protection device B connects LAN B to the Internet and protects servers within LAN B; and protection device C connects LAN C to the Internet and protects servers within LAN C.

[0116] Please see Figure 5 The protected device is a server cluster distributed across multiple local area networks (LANs), such as server A1 in LAN A, server B1 in LAN B, and server C1 in LAN C. Servers A1, B1, and C1 present the same IP address to the outside world (i.e., the IP address of the same protected device, also known as the protection IP). Optionally, servers A1, B1, and C1 provide services through load balancing, or they provide services as independent resources. Normal clients on the external network can access the servers distributed across various LANs using the protected device's IP address. Attackers can launch attacks from different regions onto servers in different LANs.

[0117] Management devices typically refer to local network management systems or cloud-based device management systems, used to control or monitor protection devices. In this embodiment, the management device is used to manage multiple protection devices, for example, see [link to relevant documentation]. Figure 5 The management equipment is used to manage protective equipment A, protective equipment B, and protective equipment C.

[0118] Optionally, if there are multiple protected devices in the protected network, the protection device is used to protect multiple protection IPs, each protection IP referring to the IP address of a protected device. For example, Figure 6 This is a schematic diagram of another application scenario provided in the embodiments of this application. Figure 6 The application scenario shown is yet another typical DDoS protection scenario. (And...) Figure 5 The application scenarios shown are different. Figure 6 The application scenario shown involves N protected devices deployed in a distributed manner on servers in various local area networks, where N ≥ 2. Servers Am, Bm, and Cm belong to the same protected device, i.e., they share the same IP address, and 1 ≤ m ≤ N.

[0119] The following example illustrates the basic hardware structure of protective equipment.

[0120] For example, Figure 7 This is a schematic diagram of the structure of a protective device provided in an embodiment of this application. Figure 7 As shown, the protection device 700 includes a central processing unit (CPU) 701, a dedicated hardware chip 702, and at least one network interface 703. The CPU 701 and the dedicated hardware chip 702 can be collectively referred to as a processor. Optionally, combined with... Figure 4 Let's take a look. Figure 7 The protective equipment 700 is Figure 4 The protective equipment shown. Optionally, combined with Figure 5 Let's take a look. Figure 7 The protective equipment 700 is Figure 5 The protective equipment shown is A, B, or C. Optionally, it can be combined with... Figure 6 Let's take a look. Figure 7 The protective equipment 700 is Figure 6 The protective equipment shown is A, B, or C.

[0121] CPU 701 refers to a general-purpose central processing unit (CPU) with high scalability and flexibility. A CPU 701 can be a single-core processor or a multi-core processor.

[0122] The dedicated hardware chip 702 is a high-performance processing hardware module. The dedicated hardware chip 702 includes at least one of application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), or network processor (NP).

[0123] At least one network interface 703 includes, for example, Figure 7 Network interface 703 is designated as network interface 1, network interface 2, network interface 3... network interface n. Network interface 703 uses any transceiver-like device for communication with other devices or communication networks. For example, Figure 7 Network interface 1 communicates with the protected device. Figure 7Network interface 2 communicates with normal clients. Optionally, network interface 703 includes at least one of a wired network interface or a wireless network interface. The wired network interface is, for example, an Ethernet interface. The Ethernet interface is, for example, an optical interface, an electrical interface, or a combination thereof. The wireless network interface is, for example, a wireless protected local area networks (WLAN) interface, a cellular network interface, or a combination thereof.

[0124] At least one network interface 703 is connected to a dedicated hardware chip 702, and the dedicated hardware chip 702 is connected to a CPU 701 via an internal connection 704. The internal connection 704 includes a pathway for data transmission between the network interface 703, the dedicated hardware chip 702, and the CPU 701. Optionally, the internal connection 704 is a single board or a bus. For example, the internal connection 704 may be Ethernet, Fibre Channel, PCI-E (Peripheral Component Interconnect Express, PCI Express, a high-speed serial computer bus), RapidIO (a high-performance, low-pin-count, packet-switched interconnect architecture), InfiniBand, or an XAUI bus (an interface extender that connects the Ethernet media access control (MAC) layer to the physical layer).

[0125] Optionally, the protection device 700 also includes a content addressable memory (CAM) 705. The CAM 705 may be, for example, a ternary content addressable memory (TCAM). The CAM 705 is used to store the IP addresses of protected devices at risk of attack and / or the IP addresses of protected devices not at risk of attack. Optionally, the CAM 705 exists independently and is connected to the dedicated hardware chip 702 via the aforementioned internal connection 704. Alternatively, the CAM 705 and the dedicated hardware chip 702 are integrated, i.e., the CAM 705 serves as the internal memory of the dedicated hardware chip 702.

[0126] Optionally, the protection device 700 also includes a memory 706. The memory 706 may be, for example, a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions; a random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions; an electrically erasable programmable read-only memory (EEPROM); a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed discs, laser discs, optical discs, digital universal discs, Blu-ray discs, etc.); a magnetic disk storage medium; or any other medium capable of carrying or storing desired program code 708 in the form of instructions or data structures and accessible by a computer, but not limited thereto. Optionally, the memory 706 may also be used to store defense strategies corresponding to various message types. The defense strategies corresponding to various message types can be accessed by the CPU 701. The memory 706 may exist independently and be connected to the CPU 701 via internal connection 704. Alternatively, the memory 706 and the CPU 701 may be integrated together.

[0127] The memory 706 stores an operating system 707 and program code 708. Optionally, the CPU 701 reads the operating system 707 from the memory 706 and runs the operating system 707. The CPU 701 also reads the program code 708 from the memory 706 and implements the method provided in the embodiments of this application by running the program code 708 on the operating system 707. For example, the protective device 700 is... Figure 4 The protection device shown, during the execution of program code 708, CPU 701 performs the following process: Protection device 700 acquires statistical information of target packets flowing through the protection device within a statistical period. The target packets are packets with a destination address of the target destination address and a packet type of the target packet. The statistical information includes statistical values ​​of at least one total traffic characteristic indicator, which includes the total rate and / or the total bandwidth of the target packets. The statistical information also includes statistical values ​​of at least one attack characteristic indicator. In response to the fact that the statistical value of one of the at least one total traffic characteristic indicators is greater than the corresponding total traffic characteristic threshold, protection device 700 determines whether the statistical value of one of the at least one attack characteristic indicator exceeds the corresponding baseline value. In response to the fact that the statistical value of one of the at least one attack characteristic indicator exceeds the corresponding baseline value, protection device 700 determines that the target destination address has been attacked.

[0128] Optionally, the aforementioned devices are disposed on separate chips, or at least partially or entirely on the same chip. Whether the devices are disposed independently on different chips or integrated on one or more chips often depends on the needs of the product design. This application does not limit the specific implementation of the aforementioned devices.

[0129] The method flow of the embodiments of this application is illustrated below.

[0130] Figure 8 This is a flowchart illustrating an attack identification method provided in an embodiment of this application. The method includes the following steps S801 to S804.

[0131] Optionally, the network deployment scenario on which the method is based is such as Figure 4 As shown. The protective equipment in the method is... Figure 4 The protective equipment in the method. The flow rate through the protective equipment comes from... Figure 4 The protected device in the method is either a legitimate client or an attacker. Figure 4 Protected equipment in the system.

[0132] Optionally, the network deployment scenario on which the method is based is such as Figure 5 As shown. The protective equipment in the method is... Figure 5 The protective equipment in the method. The flow rate through the protective equipment comes from... Figure 5 The protected device in the method is either a legitimate client or an attacker. Figure 5 The protected devices include server A1, server B1, and server C1.

[0133] Optionally, the network deployment scenario on which the method is based is such as Figure 6 As shown. The protective equipment in the method is... Figure 6 The protective equipment in the method. The flow rate through the protective equipment comes from... Figure 6 The protected device in the method is either a legitimate client or an attacker. Figure 6 Any protected device in the system, such as server A1, server B1, server C1; or server A2, server B2, server C2; etc.

[0134] The protective devices in the method include, but are not limited to, a single physical device, or a distributed system (sometimes also called a protective system) comprising multiple physical devices. Optionally, the protective devices in the method have... Figure 7 The hardware structure shown.

[0135] S801, obtain statistical information of target packets flowing through the protection device within the statistical period. The target packet is a packet with a destination address of the target destination address and a packet type of the target packet. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target packet and / or the total bandwidth of the target packet. The statistical information also includes the statistical value of at least one attack characteristic indicator.

[0136] The destination address is the address of a protected device. For example, the destination address could be the Internet Protocol (IP) address of the protected device, or the Media Access Control (MAC) address of the protected device. The following explanation uses an IP address as the destination address.

[0137] In this embodiment, the target message type is a message type related to the establishment and release of TCP connections. For example, the target message type is any one of the following: SYN message, SYN-ACK message, ACK message, FIN message, RST message, etc. Alternatively, the target message type is a message type of a protocol built on top of the TCP protocol. For example, the target message type is an HTTP request message or an HTTPS request message. Thus, the protection device can analyze the statistical information of the target messages to determine whether an attacker has launched a SYN flood attack, SYN-ACK flood attack, ACK flood attack, FIN flood attack, RST flood attack, HTTP flood attack, or HTTPS flood attack against the protected device.

[0138] All packets of the target packet type sent by the client (attacker or normal client) to the protected device within the attack duration are considered target packets. Optionally, the statistical duration is in units of time, such as 1 second (s).

[0139] The messages flowing through the protection device within the statistical period may include messages of various different message types, and the messages flowing through the protection device may also include messages sent to other devices outside the protection device. Therefore, the protection device needs to identify the target message among multiple messages in order to obtain the statistical information of the target message.

[0140] Specifically, after receiving a packet (e.g., packet A), the protection device obtains the destination address from the destination IP address field in the IP header of packet A. If the destination address in the destination IP address field matches the target destination address, packet A is further parsed to obtain its TCP header.

[0141] like Figure 1As shown, the TCP header includes an acknowledgment flag, a reset flag, a synchronization flag, and a stop flag. If the synchronization flag is 1 and the acknowledgment flag is 0, the packet type of packet A is SYN. ​​If both the synchronization flag and the acknowledgment flag are 1, the packet type of packet A is SYN-ACK. If the synchronization flag is 0, the stop flag is 0, and the ACK flag is 1, the packet type of packet A is ACK. If the stop flag is 1, the packet type of packet A is FIN. If the reset flag is 1, the packet type of packet A is RST.

[0142] like Figure 1 As shown, the TCP header includes a destination port field. If the value of the destination port field is 80, we can determine that message A is an HTTP request message. If the value of the destination port field is 443, we can determine that message A is an HTTPS request message.

[0143] After determining the message type of message A, it is determined whether the message type of message A is the target message type. If the message type of message A is the target message type, then message A can be determined as the target message. Then, the target messages within the statistical period are statistically analyzed to obtain the statistical information of the target messages within the statistical period.

[0144] In this embodiment, statistics are performed on multiple dimensions of the target packet to obtain statistical information containing the statistical values ​​of multiple indicators. For example, statistics are performed on at least one total traffic characteristic indicator of the target packet to obtain the statistical value corresponding to each of the at least one total traffic characteristic indicator. The statistical value of the total traffic characteristic can reflect the overall traffic size of the current target packet, but when the statistical value of the total traffic characteristic exceeds the corresponding total traffic characteristic threshold, it is impossible to distinguish whether it is caused by a DDoS flood attack or a sudden burst of normal traffic.

[0145] In one possible implementation, at least one total traffic characteristic indicator includes the total rate of target packets. The total rate refers to the rate at which the protection device receives target packets within a statistical period, i.e., the number of all target packets received by the protection device within the statistical period divided by the statistical period (unit: seconds). When the statistical period is a unit of time, the total rate is the number of target packets received by the protection device within the statistical period.

[0146] In another possible implementation, at least one total traffic characteristic indicator includes the total bandwidth of the target packets. Total bandwidth refers to the bandwidth of the target packets received by the protection device within the statistical duration, which is the sum of the lengths (in bits) of all target packets received by the protection device within the statistical duration divided by the statistical duration (in seconds). When the statistical duration is a unit duration, the total bandwidth is the sum of the lengths of all target packets received by the protection device within the statistical duration.

[0147] In another possible implementation, at least one total traffic characteristic includes the total rate and total bandwidth of the target packets.

[0148] In this embodiment, in addition to statistically analyzing at least one total traffic characteristic indicator of the target packets, at least one attack characteristic indicator of the target packets is also statistically analyzed to obtain the statistical values ​​corresponding to each of the at least one attack characteristic indicator. Attack characteristic indicators are designed based on the characteristics of DDoS attack behavior. Under normal circumstances (when the protected device is not under DDoS attack), the statistical values ​​of attack characteristic indicators differ significantly from those under DDoS attack conditions. Therefore, the magnitude of the statistical values ​​of attack characteristic indicators can accurately identify whether the protected device is under DDoS attack. Compared to the total traffic characteristic indicator, which analyzes all target packets within the statistical period, the attack characteristic indicator analysis analyzes only a portion of the target packets within the statistical period, thus enabling more granular statistical analysis of the target packets and improving the accuracy of attack identification.

[0149] For example, the most significant characteristic of a spoofing origin attack is the massive influx of packets with varying origins or ports to the victim host, exhausting its resources or network resources. Another characteristic of spoofing origin attacks is that the spoofed origin packets are generated out of thin air; they cannot create a real session and do not belong to any real session. For instance, in a SYN flood attack, the attacker uses tools or manipulates botnets to send a large number of SYN packets to the target server. However, after the target server responds with a SYN-ACK packet, the attacker does not continue to respond with ACK packets for confirmation, preventing the completion of the three-way handshake to establish a TCP connection. Another example is when the attacker uses tools or manipulates botnets to send a large number of SYN-ACK packets to the target server. These packets are all out of thin air in the second handshake. After receiving the out-of-sight SYN-ACK packets, the target server sends an RST packet to the attacker, informing them that the packets sent were erroneous. The attacker does not continue to respond with RST packets, preventing the completion of the three-way handshake to establish a TCP connection. Spoofing origin attacks can be used for flooding attacks of various packet types, which will not be listed here.

[0150] In summary, spoofing attacks are characterized by two significant features: a large volume of spoofed source packets and spoofed source packets not belonging to a real session. Therefore, a corresponding attack characteristic indicator for spoofing attacks is, for example, the spoofed source packet rate of the target packets. Here, the spoofed source target packets are target packets outside of a real session. A real session is a session that has completed the TCP three-way handshake. The spoofed source packet rate is the rate at which spoofed source target packets flow through the protection device within a statistical duration, i.e., the number of spoofed source target packets flowing through the protection device within the statistical duration divided by the statistical duration (unit: seconds). When the statistical duration is in units of time, the spoofed source target packet rate is simply the number of spoofed source target packets flowing through the protection device within the statistical duration.

[0151] Therefore, based on the rate of the fake source packets, it is possible to determine whether the target destination address is currently under attack by a fake source.

[0152] The statistical methods for fake source target messages differ for different message types. The statistical methods for fake source target messages will be described in the embodiments corresponding to each message type below.

[0153] It's important to note that a "real session" refers to a session that has completed the TCP three-way handshake, but it doesn't mean that all packets in a real session are sent by a legitimate client. Attackers can also use a real IP address to establish a connection with a protected device through the three-way handshake, and then launch a DDoS attack against the protected device based on the TCP connection.

[0154] DDoS attacks based on real-time sessions can take many forms, such as fixed-payload attacks, small-payload attacks, large-payload attacks, high-speed attacks, and slow-speed attacks. Different attack behaviors correspond to different attack characteristic indicators. The following describes several types of DDoS attacks based on real-time sessions and their corresponding attack characteristic indicators.

[0155] 1. Fixed load attack

[0156] A fixed payload attack refers to an attacker sending a large number of identical target packets (consistent packet length / fixed payload) over a TCP connection in order to increase the speed of the attack, thereby exhausting the target server's bandwidth and system resources.

[0157] For attacks targeting fixed payloads where target packets have consistent lengths, a corresponding attack characteristic indicator is, for example, the average packet length difference. The average packet length difference is the average of all packet length differences within a statistical period. Specifically, the packet length difference is the difference in packet length between two target packets received within the same real session that are received at adjacent times. More specifically, the packet length difference is the absolute value of the difference between the first packet length of the first target packet and the second packet length of the second target packet. The first and second target packets are target packets within the same real session, and their reception times are adjacent in the time domain. Optionally, the reception time of the first target packet is earlier than that of the second target packet. Alternatively, the reception time of the second target packet is earlier than that of the first target packet. The following explanation uses the example of the second target packet being received earlier than the first target packet.

[0158] Optionally, for the first target packet (e.g., target packet D) received within a real session (e.g., real session C) during the statistical period, since no target packet in real session C was received earlier than target packet D, the packet length of target packet D can be used as the packet length difference value corresponding to target packet D; that is, the packet length difference value corresponding to target packet D is 0. A packet length difference value of 0 for target packet D does not introduce additional error and ensures the accuracy of the statistical value of the average packet length difference. Furthermore, the total number of target packets in all real sessions within the statistical period is the same as the total number of packet length difference values, facilitating the calculation of the average packet length difference.

[0159] Assuming the total number of target packets in all real sessions within the statistical duration is M, then M packet length difference values ​​can be calculated. The statistical value of the average packet length difference is the sum of the M packet length difference values ​​divided by M. Here, M is an integer greater than or equal to 2.

[0160] For example, suppose that within the statistical duration, target packets from two real sessions (e.g., real session 1 and real session 2) flow through the protection device. In real session 1, the target packets flowing through the protection device within the statistical duration are target packet 1, target packet 2, and target packet 3, respectively. In real session 2, the target packets flowing through the protection device within the statistical duration are target packets 4, target packet 5, target packet 6, and target packet 7, respectively. Based on the three target packets in real session 1, three packet length difference values ​​can be calculated: packet length difference 1 (which is 0, i.e., the packet length of target packet 1 minus the packet length of target packet 1), packet length difference 2 (the packet length of target packet 2 minus the packet length of target packet 1), and packet length difference 3 (the packet length of target packet 3 minus the packet length of target packet 2). Based on the four target packets in real session 2, four packet length difference values ​​can be calculated: packet length difference 4 (which is 0, i.e., the packet length of target packet 4 minus the packet length of target packet 4), packet length difference 5 (the packet length of target packet 5 minus the packet length of target packet 4), packet length difference 6 (the packet length of target packet 6 minus the packet length of target packet 5), and packet length difference 7 (the packet length of target packet 7 minus the packet length of target packet 6). The statistical value of the average packet length difference is the sum of the packet length difference values ​​1-7 divided by 7.

[0161] The average message length difference reflects the variation in message length between two target messages received at adjacent times within a real session. If a normal client sends target messages to a protected device, the lengths of different target messages within the same real session vary depending on business requirements; therefore, the message length difference between two target messages received at adjacent times may be large. The message length difference between attack messages with identical message lengths is 0. If an attacker sends multiple target messages with identical message lengths through the same real session, the message length difference between two target messages received at adjacent times will also be 0. Therefore, when an attacker launches a high-speed attack, sending a large number of target messages with fixed payloads to the protected device, the statistical value of the average message length difference obtained by the protection device will decrease significantly. Thus, based on the magnitude of the statistical value of the average message length difference, it is possible to identify whether an attacker has launched a fixed payload attack against the protected device.

[0162] 2. Small payload attacks and large payload attacks

[0163] Small payload attacks refer to attackers sending a large number of attack packets with small payloads over a TCP connection to increase attack speed. Large payload attacks refer to attackers sending a large number of attack packets with large payloads over a TCP connection to exhaust bandwidth resources. Both small and large payload attacks cause changes in average packet length. For example, when an attacker launches a small payload attack, a large number of small payload target packets will reduce the average packet length of the target packets in the actual session. When an attacker launches a large payload attack, a large number of large payload target packets will increase the average packet length of the target packets in the actual session.

[0164] Therefore, attack characteristic indicators corresponding to small payload attacks and large payload attacks include, for example, the average target packet length. The average target packet length refers to the average packet length of the target packets in all real sessions within the statistical period.

[0165] Small payload attacks will cause the average target packet length to decrease. Large payload attacks will cause the average target packet length to increase. Therefore, by observing the average target packet length, it is possible to determine whether an attacker has launched a small payload attack or a large payload attack against the protected device.

[0166] 3. High-speed attack and slow-speed attack

[0167] A high-speed attack refers to an attacker sending a large number of targeted packets to a protected device via a TCP connection in order to deplete the device's bandwidth and system resources. The target packet rate of a real session used by an attacker for a high-speed attack is significantly higher than the target packet rate of a normal real session.

[0168] A slow attack is a technique that creates a large number of real sessions, each simulating the packet rate of normal business operations to send target packets, thereby occupying session resources and consuming TCP connection resources for an extended period. The real sessions used by attackers in slow attacks have a low target packet rate.

[0169] Therefore, attack characteristic indicators corresponding to high-speed / slow-speed attacks include, for example, the average target packet rate or the average target packet bandwidth of active sessions. Here, an active session is defined as a session within the statistical period where target packets flow through the protection device. The average target packet rate of an active session is the average of the target packet rates corresponding to all active sessions within the statistical period, and the target packet rate corresponding to an active session is the rate of target packets flowing through the protection device within the statistical period. For example, assuming there are P (where P is an integer greater than or equal to 2) active sessions within the statistical period, the average target packet rate of an active session is the sum of the target packet rates corresponding to each of the P active sessions, divided by P.

[0170] The average target packet bandwidth of an active session is the average of the target packet bandwidths corresponding to all active sessions within the statistical period. The target packet bandwidth corresponding to an active session is the bandwidth of the target packets flowing through the protection device within the statistical period. For example, assuming there are P (where P is an integer greater than or equal to 2) active sessions within the statistical period, the average target packet bandwidth of an active session is the sum of the target packet bandwidths corresponding to each of the P active sessions, divided by P.

[0171] When an attacker launches a high-speed attack, they send a large number of target packets through a real session with the protected device. This real session between the attacker and the protected device is thus identified as an active session. Because the attacker sends a large number of target packets through this active session, the rate of target packets in the attacker's active session is significantly higher than the rate of target packets in an active session between a normal client and the protected device. Therefore, when an attacker launches a high-speed attack, the statistical value of the average target packet rate of the active session will be significantly increased.

[0172] When an attacker launches a slow attack, they create numerous sessions with the protected device, each sending a small number of target packets. When the actual sessions between the attacker and the protected device are identified as active sessions, the target packet rate of those active sessions is low. This means that within the statistical period, the attacker sends a small number (at least one) of target packets through active sessions with the protected device, resulting in a low target packet rate for those active sessions. Therefore, when an attacker launches a slow attack, the statistical value of the average target packet rate of active sessions will be significantly reduced. Thus, by using the statistical value of the average target packet rate of active sessions, it is possible to determine whether an attacker has launched a high-speed or slow attack against the protected device.

[0173] The attack signature indicators corresponding to different message types have been updated, and these indicators will be described below.

[0174] S802, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than the corresponding total flow characteristic threshold.

[0175] If yes, meaning that at least one of the total traffic characteristic indicators has a statistical value greater than the corresponding total traffic characteristic threshold, it indicates that the current target packet traffic is large, and there may be a DDoS attack. Further confirmation is required, i.e., execute S803. If no, meaning that none of the statistical values ​​of at least one total traffic characteristic indicator has a statistical value greater than the corresponding total traffic characteristic threshold, i.e., all the statistical values ​​of at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, execute S805.

[0176] For example, when at least one total flow characteristic includes only total rate, if the statistical value of the total rate is greater than the total flow characteristic threshold corresponding to the total rate (hereinafter referred to as the total rate threshold), execute S803. If the statistical value of the total rate is less than or equal to the total rate threshold, execute S805.

[0177] When at least one total traffic feature includes only total bandwidth, if the statistical value of total bandwidth is greater than the total traffic feature threshold corresponding to total bandwidth (hereinafter referred to as the total bandwidth threshold), execute S803. If the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S805.

[0178] When at least one total traffic characteristic includes total rate and total bandwidth, if the statistical value of total rate is greater than the total rate threshold, or the statistical value of total bandwidth is greater than the total bandwidth threshold, execute S803. If the statistical value of total rate is less than or equal to the total rate threshold, and the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S805.

[0179] S803, determine whether there is a statistical value of at least one attack feature indicator that exceeds the corresponding baseline value.

[0180] If so, that is, if at least one of the attack feature indicators has a statistical value that exceeds the corresponding baseline value, execute S804.

[0181] If not, that is, if none of the statistical values ​​of at least one attack feature indicator exceed the corresponding baseline value, execute S805.

[0182] Different attack characteristic indicators correspond to different baseline values. How to determine whether the statistical value of an attack characteristic indicator exceeds the corresponding baseline value will be described below.

[0183] S804 indicates that the target address has been attacked.

[0184] This means the protected device is currently under DDoS attack.

[0185] Optionally, after determining that the target address has been attacked, an alarm can be issued to alert the protected device that it is currently under DDoS attack.

[0186] Optionally, after determining that the target address has been attacked, corresponding defensive measures can be taken to ensure that the protected equipment can maintain normal business operations.

[0187] S805, confirming that the target address has not been attacked.

[0188] This means that the protected device is not currently under DDoS attack.

[0189] Optionally, the statistical information corresponding to the statistical duration indicates that the target address has not been attacked. The statistical values ​​of the attack characteristic indicators in the statistical information can represent the statistical values ​​when the protected device is not under DDoS attack. By combining the statistical information corresponding to multiple statistical durations determined to be free from DDoS attack, the range of statistical values ​​of the attack characteristic indicators when not under DDoS attack can be determined. If the statistical values ​​of the attack characteristic indicators exceed this range, it can be determined that the protected device is under DDoS attack. In other words, by using the statistical values ​​of multiple attack characteristic indicators when not under DDoS attack, a baseline value corresponding to the attack characteristic indicators can be determined. The baseline value is the boundary value for dividing whether the protected device is under DDoS attack. If the statistical values ​​of the statistical characteristic indicators exceed the baseline value, that is, the statistical values ​​of the attack characteristic indicators are outside the normal range, it can be determined that the protected device is under DDoS attack.

[0190] For example, after determining that the protected device has not been attacked within a statistical duration (e.g., statistical duration E), statistical information of the target packets corresponding to K target statistical durations is obtained. The target destination address is determined to have not been attacked within the target statistical duration. The K target statistical durations include statistical duration E. K is an integer greater than or equal to 2. Further, based on the statistical value corresponding to each attack characteristic indicator within the K target statistical durations, a baseline value corresponding to each attack characteristic indicator is determined.

[0191] Based on the statistical information corresponding to the statistical duration of K targets, the maximum and / or minimum values ​​of the statistical values ​​of each attack characteristic indicator can be obtained. Furthermore, based on the maximum and / or minimum values ​​of each attack characteristic indicator, the baseline value corresponding to each attack characteristic indicator can be determined.

[0192] The methods for determining the baseline values ​​corresponding to different attack characteristic indicators are different. The methods for determining the baseline values ​​corresponding to each attack characteristic indicator are described below.

[0193] In this embodiment, by acquiring statistical values ​​of multiple dimensions of indicators such as total traffic characteristic indicators and attack characteristic indicators, when the statistical value of a total traffic characteristic indicator is greater than the corresponding total traffic characteristic threshold, it is further determined whether the statistical value of an attack characteristic indicator exceeds the corresponding baseline value. When the statistical value of an attack characteristic indicator exceeds the corresponding baseline value, it is determined that the target destination address has been attacked, which can improve the accuracy of DDoS attack identification and reduce the probability of false alarms.

[0194] Figure 8 The corresponding implementation describes a general process for DDoS attack identification, applicable to different types of DDoS flood attacks. Since different message types occur at different stages of communication between the two parties, the corresponding DDoS attack methods also differ, resulting in different attack characteristic indicators for different message types. To more clearly describe the identification methods for different types of DDoS flood attacks, the following... Figures 9-13 The corresponding embodiments describe the identification methods for DDoS flood attacks of different message types.

[0195] like Figure 9 As shown, Figure 9 This is a flowchart illustrating another attack identification method provided in this application embodiment. In this embodiment, the target packet type is a SYN packet, meaning this embodiment is used to identify SYN flood attacks. This embodiment includes steps S901-S905.

[0196] S901, obtain statistical information of target SYN packets flowing through the protection device within the statistical period. The target packet is a SYN packet with the destination address as the target destination address. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target SYN packets and / or the total bandwidth of the target SYN packets. The statistical information also includes the statistical value of the rate of the spurious source target packets.

[0197] In this embodiment, a SYN packet with a destination address equal to the target destination address is referred to as a target SYN packet. That is, in Figure 9 In the corresponding embodiment, the target message is referred to as the target SYN message.

[0198] The SYN packet is the first packet in the TCP three-way handshake. A common attack method using SYN packets is a spoofed source attack. This involves an attacker sending a large number of spoofed source SYN packets to the protected device. After the protected device responds with a SYN-ACK packet, the attacker does not continue to respond with ACK packets to confirm, preventing the completion of the three-way handshake and the establishment of a TCP connection.

[0199] Therefore, the attack characteristic indicators corresponding to the target SYN packet include the rate of the spoofed source target packet. The statistical information of the target SYN packet includes the statistical value corresponding to the rate of the spoofed source target packet.

[0200] The method for obtaining statistical values ​​corresponding to the spurious source target packet rate of the target SYN packet is described below.

[0201] Because the number of target SYN packets received by the protection device is large, it is difficult for the protection device to track whether the three-way handshake has been completed for each target SYN packet's session. Therefore, this embodiment obtains the statistical value corresponding to the spurious source target packet rate of the target SYN packet through indirect calculation.

[0202] The statistical value of the total rate at which the protective device acquires target SYN packets. The statistical value of the total rate of target SYN packets is the number of target SYN packets flowing through the protective device within the statistical duration divided by the statistical duration (unit: seconds). If the statistical duration is a unit of time, then the statistical value of the total rate of target SYN packets is the number of target SYN packets flowing through the protective device within the statistical duration.

[0203] The protection device also obtains statistics on the rate of newly established TCP connections. The statistical value for the rate of newly established TCP connections is the number of sessions created by target SYN packets and the completion of a three-way handshake to establish a TCP connection within the statistical duration, divided by the statistical duration (unit: seconds). If the statistical duration is in units of time, then the statistical value for the rate of newly established TCP connections is the number of sessions created by SYN packets and the completion of a three-way handshake to establish a TCP connection.

[0204] Therefore, by subtracting the statistical value of the rate of newly established TCP connections from the statistical value of the total rate of target SYN packets, we obtain the statistical value of the rate of sessions created by target SYN packets but not completed with the three-way handshake within the statistical period, which is the statistical value of the rate of spurious source target packets corresponding to target SYN packets.

[0205] The following explains how the protection device determines that a session was created by a SYN packet. The protection device creates a session table. The five-tuple information in the session table includes: source IP address, destination IP address, source port, destination port, and protocol. The session table also records the reason for session creation, i.e., whether the session was created by a SYN packet, an ACK packet, etc. When a target SYN packet (e.g., target SYN packet F) flows through the protection device, the protection device checks the session table against the five-tuple information of target SYN packet F to see if a corresponding session record exists. Specifically, it checks if a session record with the same five-tuple information as target SYN packet F exists in the session table. If no session record matching the five-tuple information of target SYN packet F exists in the session table, the protection device creates a corresponding session record F. Session record F includes the five-tuple information of target SYN packet F and the reason for its creation: a SYN packet. When a subsequent ACK packet (e.g., ACK packet G) passes through the protection device, the device checks its session table against the 5-tuple information of ACK packet G to see if a corresponding session record exists. If the 5-tuple information of ACK packet G matches that of session record F, no session record needs to be created for ACK packet G in the session table. That is, one session record in the session table uniquely corresponds to one session, and the reason for session creation in the session record is the packet type of the packet that triggered the protection device to create the session record. Therefore, through the session table, the protection device can determine whether a session was created by a SYN packet.

[0206] S902, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than the corresponding total flow characteristic threshold.

[0207] If yes, meaning that at least one of the total traffic characteristic indicators has a statistical value greater than the corresponding total traffic characteristic threshold, it indicates that the current target SYN packet traffic is large, and there may be a SYN flood attack, requiring further confirmation, i.e., execute S903. If no, meaning that none of the statistical values ​​of at least one total traffic characteristic indicator has a statistical value greater than the corresponding total traffic characteristic threshold, i.e., all the statistical values ​​of at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, execute S905.

[0208] For example, when at least one total flow characteristic includes only total rate, if the statistical value of the total rate is greater than the total flow characteristic threshold corresponding to the total rate (hereinafter referred to as the total rate threshold), execute S903. If the statistical value of the total rate is less than or equal to the total rate threshold, execute S905.

[0209] When at least one total traffic feature includes only total bandwidth, if the statistical value of total bandwidth is greater than the total traffic feature threshold corresponding to total bandwidth (hereinafter referred to as the total bandwidth threshold), execute S903. If the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S905.

[0210] When at least one total traffic characteristic includes total rate and total bandwidth, if the statistical value of total rate is greater than the total rate threshold, or the statistical value of total bandwidth is greater than the total bandwidth threshold, execute S903. If the statistical value of total rate is less than or equal to the total rate threshold, and the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S905.

[0211] S903, determine whether the statistical value of the false source target packet rate corresponding to the target SYN packet is greater than the false source packet rate threshold corresponding to the target SYN packet.

[0212] If so, that is, if the statistical value of the false source target packet rate corresponding to the SYN packet is greater than the threshold of the false source packet rate corresponding to the target SYN packet, execute S904.

[0213] If not, i.e., the statistical value of the false source target packet rate corresponding to the SYN packet is less than or equal to the false source packet rate threshold corresponding to the target SYN packet, execute S905.

[0214] S904 indicates that the target address has been subjected to a SYN flood attack.

[0215] This means the protected device is currently under a SYN flood attack.

[0216] Optionally, after determining that the target address has been attacked, an alarm is issued to indicate that the protected device is currently under a DDoS attack. Optionally, the alarm may also include the type of DDoS attack currently being suffered, such as the protected device currently suffering a SYN flood attack.

[0217] Optionally, after determining that the target destination address has been attacked, corresponding defensive measures can be taken, such as discarding the first SYN packet in the session, to ensure that the protected device can maintain normal business operations.

[0218] S905, confirming that the target address has not been subjected to a SYN flood attack.

[0219] This means that the protected device was not attacked by a SYN flood within the statistical period.

[0220] Optionally, after determining that the protected device has not been attacked within a statistical duration (e.g., statistical duration F), statistical information of the target SYN packets corresponding to K target statistical durations is obtained. The target destination address is determined to be unattacked within the target statistical duration. The K target statistical durations include statistical duration F. Each statistical information includes a statistical value of the rate of the spoofed source target packet corresponding to the target SYN packet. Further, among the statistical values ​​of the rate of the spoofed source target packet corresponding to the target SYN packet within the K target statistical durations, the statistical value of the largest spoofed source target packet rate is determined as the baseline value of the rate of the spoofed source target packet corresponding to the target SYN packet.

[0221] In this embodiment, statistical values ​​of multiple dimensions of indicators, such as total traffic characteristic indicators and attack characteristic indicators of the target SYN packet, are obtained. When the statistical value of one total traffic characteristic indicator is greater than the corresponding total traffic characteristic threshold, it is further determined whether the statistical value of the fake source target packet rate corresponding to the target SYN packet is greater than the fake source packet rate threshold corresponding to the target SYN packet. When the statistical value of the fake source target packet rate corresponding to the target SYN packet is greater than the fake source packet rate threshold corresponding to the target SYN packet, it is determined that the target destination address has been attacked, thereby improving the accuracy of DDoS attack identification and reducing the probability of false alarms.

[0222] Besides SYN packets, SYN-ACK packets are also commonly used in DDoS attacks. The following describes methods for identifying SYN-ACK flood attacks. Figure 10 As shown, Figure 10 This is a flowchart illustrating another attack identification method provided in this application embodiment. In this embodiment, the target packet type is a SYN-ACK packet, meaning this embodiment is used to identify SYN-ACK flood attacks. This embodiment includes steps S1001-S1005.

[0223] S1001, Obtain statistical information of target SYN-ACK packets flowing through the protection device within the statistical period. The target packet is a SYN-ACK packet with the destination address as the target destination address. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target SYN-ACK packet and / or the total bandwidth of the target SYN-ACK packet. The statistical information also includes the statistical value of the rate of the spurious source target packet.

[0224] In this embodiment, a SYN-ACK packet with a destination address equal to the target destination address is referred to as a target SYN-ACK packet. That is, in Figure 10 In the corresponding embodiment, the target message is referred to as the target SYN-ACK message.

[0225] The SYN-ACK packet is the second packet in the TCP three-way handshake. In this embodiment, the target SYN-ACK packet may include a target SYN-ACK packet sent by a normal client to the protected device after receiving a SYN packet from the protected device. Because the forwarding path of the SYN packet sent by the protected device to the normal client may differ from the forwarding path of the target SYN-ACK packet sent by the normal client to the protected device—for example, the SYN packet sent by the protected device may not pass through the protection device—the protection device cannot create a corresponding session record in its session table based on the SYN packet sent by the protected device. After receiving the target SYN-ACK packet from the normal client, the protection device creates a corresponding session record in its session table based on the five-tuple information in the target SYN-ACK packet, and records the creation reason as a SYN-ACK packet. Therefore, a session whose session creation reason is a SYN-ACK packet and which completes the three-way handshake is also a real session.

[0226] The target SYN-ACK packet could also be a SYN-ACK packet sent by an attacker to the protected device using a fake source in a SYN-ACK Flood attack, or a SYN-ACK packet sent to a reflection node by forging the source IP (the victim's host IP), causing the reflection node to send a SYN-ACK packet to the forged source. In a SYN-ACK Flood attack, the target SYN-ACK packet is generated out of thin air for the protected device, making it impossible to complete the three-way handshake to establish a TCP connection.

[0227] In other words, the attack method for SYN-ACK packets is a spoofing attack. Therefore, the attack characteristic indicators corresponding to the target SYN-ACK packet include the rate of the spoofing target packet. The statistical information of the target SYN-ACK packet includes the statistical value corresponding to the rate of the spoofing target packet.

[0228] The method for obtaining the statistical values ​​corresponding to the spurious source target packet rate of the target SYN-ACK packet is described below.

[0229] The statistical value of the total rate at which the protective device acquires target SYN-ACK packets. The statistical value of the total rate of target SYN-ACK packets is the number of target SYN-ACK packets flowing through the protective device within the statistical duration divided by the statistical duration (unit: seconds). If the statistical duration is a unit of time, then the statistical value of the total rate of target SYN-ACK packets is the number of target SYN-ACK packets flowing through the protective device within the statistical duration.

[0230] The protection device also acquires statistics on the rate of newly established TCP connections. The statistical value for the rate of newly established TCP connections is the number of sessions created and TCP connections established via a three-way handshake by the target SYN-ACK packet within the statistical duration, divided by the statistical duration (unit: seconds). If the statistical duration is in units of time, then the statistical value for the rate of newly established TCP connections is the number of sessions created and TCP connections established via a three-way handshake by the target SYN-ACK packet.

[0231] Therefore, by subtracting the statistical value of the rate of newly established TCP connections from the statistical value of the total rate of target SYN-ACK packets, we obtain the statistical value of the rate of sessions created by target SYN-ACK packets but not completing the three-way handshake within the statistical period, which is the statistical value of the rate of spurious source target packets corresponding to target SYN-ACK packets.

[0232] S1002, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than the corresponding total flow characteristic threshold.

[0233] If yes, meaning that at least one of the total traffic characteristic indicators has a statistical value greater than the corresponding total traffic characteristic threshold, it indicates that the current target SYN-ACK packet traffic is large, and there may be a SYN-ACK flood attack, requiring further confirmation, i.e., proceed to S1003. If no, meaning that none of the statistical values ​​of at least one total traffic characteristic indicator has a statistical value greater than the corresponding total traffic characteristic threshold, i.e., all the statistical values ​​of at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, proceed to S1005.

[0234] For example, when at least one total flow characteristic includes only total rate, if the statistical value of the total rate is greater than the total flow characteristic threshold corresponding to the total rate (hereinafter referred to as the total rate threshold), execute S1003. If the statistical value of the total rate is less than or equal to the total rate threshold, execute S1005.

[0235] When at least one total traffic feature includes only total bandwidth, if the statistical value of total bandwidth is greater than the total traffic feature threshold corresponding to total bandwidth (hereinafter referred to as the total bandwidth threshold), execute S1003. If the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1005.

[0236] When at least one total traffic characteristic includes total rate and total bandwidth, if the statistical value of total rate is greater than the total rate threshold, or the statistical value of total bandwidth is greater than the total bandwidth threshold, execute S1003. If the statistical value of total rate is less than or equal to the total rate threshold, and the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1005.

[0237] S1003, determine whether the statistical value of the false source target packet rate corresponding to the target SYN-ACK packet is greater than the false source packet rate threshold corresponding to the target SYN-ACK packet.

[0238] If so, that is, if the statistical value of the false source target packet rate corresponding to the SYN-ACK packet is greater than the threshold of the false source packet rate corresponding to the target SYN-ACK packet, execute S1004.

[0239] If not, i.e., the statistical value of the false source target packet rate corresponding to the SYN-ACK packet is less than or equal to the false source packet rate threshold corresponding to the target SYN-ACK packet, execute S1005.

[0240] S1004 indicates that the target address has been subjected to a SYN-ACK flood attack.

[0241] This means the protected device is currently under a SYN-ACK flood attack.

[0242] Optionally, after determining that the target address has been attacked, an alarm is issued to indicate that the protected device is currently under a DDoS attack. Optionally, the alarm may also include the type of DDoS attack currently being suffered, such as the protected device currently suffering a SYN-ACK flood attack.

[0243] Optionally, after determining that the target destination address has been attacked, corresponding defensive measures can be taken, such as discarding the first SYN-ACK packet in the session, to ensure that the protected device can maintain normal business operations.

[0244] S1005, confirming that the target address has not been subjected to a SYN-ACK flood attack.

[0245] This means that the protected device was not subjected to a SYN-ACK flood attack within the statistical period.

[0246] Optionally, after determining that the protected device has not been attacked within a statistical duration (e.g., statistical duration H), statistical information of target SYN-ACK packets corresponding to K target statistical durations is obtained. The target destination address is determined to be unattacked within the target statistical duration. The K target statistical durations include statistical duration H. Each statistical information includes a statistical value of the rate of the spoofed source target packet corresponding to the target SYN-ACK packet. Further, among the statistical values ​​of the rate of the spoofed source target packet corresponding to the target SYN-ACK packet within the K target statistical durations, the statistical value of the largest spoofed source target packet rate is determined as the baseline value of the rate of the spoofed source target packet corresponding to the target SYN-ACK packet.

[0247] In this embodiment, statistical values ​​of multiple dimensions of indicators, such as total traffic characteristic indicators and attack characteristic indicators of the target SYN-ACK packet, are obtained. When the statistical value of one total traffic characteristic indicator is greater than the corresponding total traffic characteristic threshold, it is further determined whether the statistical value of the fake source target packet rate corresponding to the target SYN-ACK packet is greater than the fake source packet rate threshold corresponding to the target SYN-ACK packet. When the statistical value of the fake source target packet rate corresponding to the target SYN-ACK packet is greater than the fake source packet rate threshold corresponding to the target SYN-ACK packet, it is determined that the target destination address has been attacked, thereby improving the accuracy of DDoS attack identification and reducing the probability of false alarms.

[0248] Besides SYN and SYN-ACK packets, ACK packets are also frequently used in DDoS attacks. The following describes methods for identifying ACK flood attacks. Figure 11 As shown, Figure 11 This is a flowchart illustrating another attack identification method provided in this application. In this embodiment, the target packet type is an ACK packet, meaning this embodiment is used to identify ACK flood attacks. This embodiment includes steps S1101-S1105.

[0249] S1101, Obtain statistical information of target ACK packets flowing through the protection device within the statistical period. The target packet is an ACK packet with the destination address as the target destination address. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target ACK packet and / or the total bandwidth of the target ACK packet. The statistical information also includes the statistical value of the rate of the spurious source target packet.

[0250] In this embodiment, an ACK packet with a destination address equal to the target destination address is called a target ACK packet. That is, in Figure 11 In the corresponding embodiment, the target message is referred to as the target ACK message.

[0251] ACK Flood attacks include attacks using fake source-target ACK packets and attacks using target ACK packets based on real sessions.

[0252] The spoofed source-destination ACK packet attack refers to an attacker sending a large number of spoofed source-destination ACK packets to a protected device. These spoofed source-destination ACK packets are generated out of thin air and do not belong to the normal three-way handshake ACK packets. In other words, the spoofed source-destination ACK packets do not belong to any session created and completed by SYN or SYN-ACK. That is, the spoofed source-destination ACK packets do not belong to any real session.

[0253] Targeted ACK packet attacks based on real sessions refer to attacks launched against protected devices based on sessions that have completed a three-way handshake, including fixed-payload attacks, small-payload attacks, large-payload attacks, high-speed attacks, or slow-speed attacks.

[0254] Therefore, the attack signature indicators corresponding to the target ACK packet include at least one of the following indicators:

[0255] 1. False Source Packet Rate. The false source packet rate corresponding to the target ACK packet is the rate of false source ACK packets flowing through the protection device within the statistical duration. There are several methods to obtain the statistical value of the false source packet rate corresponding to the target ACK packet. For example, the number of sessions created by ACK packets within the statistical duration can be divided by the statistical duration to obtain the statistical value of the false source packet rate corresponding to the target ACK packet. Another example is to obtain the total rate of target ACK packets and the rate of real sessions created by SYN packets or SYN-ACK packets, and then subtract the rate of real sessions created by SYN packets or SYN-ACK packets from the total rate of target ACK packets to obtain the statistical value of the false source packet rate corresponding to the target ACK packet. The rate of real sessions created by SYN packets or SYN-ACK packets is obtained by dividing the number of sessions created by SYN packets or SYN-ACK packets and completing the three-way handshake within the statistical duration by the statistical duration.

[0256] 2. Average Message Length Difference. The statistical value of the average message length difference corresponding to the target ACK message is the average of all message length differences within the statistical period. Specifically, the message length difference is the difference in message length between two target ACK messages received within the statistical period that belong to the same real session and are received at adjacent times.

[0257] 3. Average Target Packet Length. The average target packet length corresponding to the target ACK packet is the average of the packet lengths of target ACK packets in all real sessions within the statistical period. The average target packet length is obtained by summing the packet lengths of target ACK packets in all real sessions within the statistical period and then dividing by the total number of target ACK packets in all real sessions.

[0258] 4. Average Target Packet Rate of Active Sessions. In this embodiment, the active session corresponding to the target ACK packet refers to a real session in which a target ACK packet flows through the protection device within the statistical duration. The statistical value of the average target packet rate of active sessions is the sum of the target ACK packet rates of all active sessions within the statistical duration divided by the number of active sessions. The target ACK packet rate of an active session (e.g., referred to as active session J) is the number of target ACK packets that flow through the protection device and belong to active session J within the statistical duration divided by the statistical duration.

[0259] 5. Average target packet bandwidth of active sessions. The average target packet bandwidth of active sessions is calculated by dividing the sum of the target ACK packet bandwidths of all active sessions within the statistical period by the number of active sessions. The target ACK packet bandwidth of an active session (e.g., active session J) is calculated by dividing the sum of the packet lengths of all target ACK packets that flow through the protection device and belong to active session J within the statistical period by the statistical period.

[0260] S1102, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than the corresponding total flow characteristic threshold.

[0261] If yes, meaning that at least one of the total traffic characteristic indicators has a statistical value greater than the corresponding total traffic characteristic threshold, it indicates that the current target ACK packet traffic is large, and there may be an ACK flood attack, requiring further confirmation, i.e., proceed to S1103. If no, meaning that none of the statistical values ​​of at least one total traffic characteristic indicator has a statistical value greater than the corresponding total traffic characteristic threshold, i.e., all the statistical values ​​of at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, proceed to S1106.

[0262] For example, when at least one total flow characteristic includes only total rate, if the statistical value of the total rate is greater than the total flow characteristic threshold corresponding to the total rate (hereinafter referred to as the total rate threshold), execute S1103. If the statistical value of the total rate is less than or equal to the total rate threshold, execute S1106.

[0263] When at least one total traffic feature includes only total bandwidth, if the statistical value of total bandwidth is greater than the total traffic feature threshold corresponding to total bandwidth (hereinafter referred to as the total bandwidth threshold), execute S1103. If the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1106.

[0264] When at least one total traffic characteristic includes total rate and total bandwidth, if the statistical value of total rate is greater than the total rate threshold, or the statistical value of total bandwidth is greater than the total bandwidth threshold, execute S1103. If the statistical value of total rate is less than or equal to the total rate threshold, and the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1106.

[0265] S1103, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than a preset multiple of the corresponding total flow characteristic threshold.

[0266] Specifically, the protection device determines whether the total rate is greater than n times the total rate threshold, and / or determines whether the total bandwidth is greater than m times the total bandwidth threshold.

[0267] In one possible scenario, attackers may combine multiple attack methods to target the protected device, such as a mix of fixed-payload, low-payload, and high-payload attacks, or a mix of high-speed and slow attacks. This makes it difficult to distinguish whether a DDoS attack is currently underway based solely on statistical values ​​of attack characteristic indicators. Therefore, by further determining whether the total rate is greater than n times the total rate threshold and / or whether the total bandwidth is greater than m times the total bandwidth threshold, it is possible to reduce false alarms and avoid missed alarms.

[0268] Where m and n are both positive numbers greater than 1. For example, m can be 1.1, 1.2, 1.5, 2, 3, or 5, etc. It should be noted that m and n can also be other values ​​greater than 1. The values ​​of m and n can be set according to the strictness of the detection; examples are not provided here.

[0269] If so, i.e., the total rate is greater than n times the total rate threshold, and / or the total bandwidth is greater than m times the total bandwidth threshold, it indicates that the target ACK packet traffic is large and there is a high possibility of being attacked by ACK flood, then execute S1105.

[0270] If not, that is, if none of the statistical values ​​of at least one total flow characteristic indicator are greater than a preset multiple of the corresponding total flow characteristic threshold, then execute S1104.

[0271] S1104, determine whether there is any attack feature indicator whose statistical value exceeds the corresponding attack feature threshold among the statistical values ​​of at least one attack feature indicator corresponding to the target ACK packet.

[0272] If not, that is, if none of the statistical values ​​of at least one attack feature indicator corresponding to the target ACK packet exceeds the corresponding attack feature threshold, then execute S1106.

[0273] If so, if at least one of the statistical values ​​of the attack feature indicators corresponding to the target ACK packet exceeds the corresponding attack feature threshold, execute S1105.

[0274] In other words, when multiple attack signature indicators correspond to a target ACK packet, if the statistical value of any one of the attack signature indicators exceeds the corresponding attack signature threshold, the protected device can be considered to be currently under an ACK flood attack. Similarly, if the statistical values ​​of multiple attack signature indicators corresponding to a target ACK packet exceed the corresponding attack signature threshold, the protected device is also considered to be currently under an ACK flood attack.

[0275] Specifically, S1105 is executed when any of the following conditions are met.

[0276] If the attack signature indicators include the rate of fake source packets corresponding to the target ACK packet, and the statistical value of the rate of fake source packets corresponding to the target ACK packet is greater than the threshold of the rate of fake source packets corresponding to the target ACK packet, then execute S1105.

[0277] If the attack signature indicators include the average difference in packet length corresponding to the target ACK packet, and the statistical value of the average difference in the length of the fake packet corresponding to the target ACK packet is greater than the threshold for the difference in packet length corresponding to the target ACK packet, then execute S1105.

[0278] If the attack signature indicators include the average target packet length corresponding to the target ACK packet, and the statistical value of the average target packet length corresponding to the target ACK packet is greater than the first packet length threshold or less than the second packet length threshold, then execute S1105. The first packet length threshold is greater than the second packet length threshold. The first packet length threshold can be understood as the upper boundary of the normal statistical value of the average target packet length. If the statistical value of the average target packet length is greater than the first packet length threshold, it can be considered that the attacker launched a large payload attack on the protected device based on a real session. The second packet length threshold can be understood as the lower boundary of the normal statistical value of the average target packet length. If the statistical value of the average target packet length is less than the second packet length threshold, it can be considered that the attacker launched a small payload attack on the protected device based on a real session.

[0279] If the attack signature indicators include the average target packet rate of the active session corresponding to the target ACK packet, and the statistical value of the average target packet rate of the active session corresponding to the target ACK packet is greater than the first rate threshold corresponding to the target ACK packet, then execute S1105. Alternatively, if the statistical value of the average target packet rate of the active session corresponding to the target ACK packet is less than the third rate threshold corresponding to the target ACK packet, then execute S1105. The first rate threshold is greater than the third rate threshold. The first rate threshold can be understood as the upper boundary of the normal statistical value of the average target packet rate. If the statistical value of the average target packet rate is greater than the first rate threshold, it can be considered that the attacker launched a high-speed attack on the protected device based on a real session. The third rate threshold can be understood as the lower boundary of the normal statistical value of the average target packet rate. If the statistical value of the average target packet rate is less than the third rate threshold, it can be considered that the attacker launched a low-speed attack on the protected device based on a real session.

[0280] If the attack signature indicators include the average target packet bandwidth of active sessions, then if the statistical value of the average target packet bandwidth corresponding to the target ACK packet is greater than the first bandwidth threshold corresponding to the target ACK packet, execute S1105. If the statistical value of the average target packet bandwidth corresponding to the target ACK packet is less than the second bandwidth threshold corresponding to the target ACK packet, execute S1105. The first bandwidth threshold is greater than the second bandwidth threshold.

[0281] S1105, the target address has been identified as being subjected to an ACK flood attack.

[0282] Optionally, after determining that the target address has been attacked, an alarm is issued to indicate that the protected device is currently under a DDoS attack. Optionally, the alarm may also include the type of DDoS attack currently being suffered, such as the protected device currently suffering an ACK flood attack.

[0283] Optionally, after determining that the target destination address has been attacked, corresponding defensive measures can be taken, such as directly discarding the target ACK packet if it does not match a session in the session table, so as to ensure that the protected device can maintain normal business operation.

[0284] S1106, confirmed that the target address was not subjected to an ACK flood attack.

[0285] Optionally, after determining that the protected device has not been attacked within a statistical duration (e.g., referred to as statistical duration R), statistical information of target ACK packets corresponding to K target statistical durations is obtained. The target destination address is determined to be unattacked within the target statistical duration. The K target statistical durations include the statistical duration R. Each statistical information includes the statistical value of at least one attack characteristic indicator corresponding to the target ACK packet. Further, among the statistical values ​​of attack characteristic indicators corresponding to the target ACK packets within the K target statistical durations, the statistical value of the maximum and / or minimum spoofing source target packet rate is determined as the baseline value of the spoofing source target packet rate corresponding to the target ACK packet.

[0286] In this embodiment, statistical values ​​of multiple dimensions of indicators, such as total traffic characteristic indicators and attack characteristic indicators of the target ACK packet, are obtained. When the statistical value of one total traffic characteristic indicator is greater than the corresponding total traffic characteristic threshold, it is further determined whether the statistical value of the fake source target packet rate corresponding to the target ACK packet is greater than the fake source packet rate threshold corresponding to the target ACK packet. When the statistical value of the fake source target packet rate corresponding to the target ACK packet is greater than the fake source packet rate threshold corresponding to the target ACK packet, it is determined that the target destination address has been attacked, thereby improving the accuracy of DDoS attack identification and reducing the probability of false alarms.

[0287] Besides SYN, SYN-ACK, and ACK packets, FIN / RST packets are also frequently used in DDoS attacks. The following describes methods for identifying FIN / RST flood attacks. Figure 12 As shown, Figure 12 This is a flowchart illustrating another attack identification method provided in this application. In this embodiment, the target packet type is a FIN / RST packet, meaning this embodiment is used to identify FIN / RST flood attacks. This embodiment includes steps S1201-S1205.

[0288] S1201, Obtain statistical information of target FIN / RST packets flowing through the protection device within the statistical period. The target packet is a FIN / RST packet with the destination address as the target destination address. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target FIN / RST packet and / or the total bandwidth of the target FIN / RST packet. The statistical information also includes the statistical value of the rate of the spurious source target packet.

[0289] In this embodiment, a FIN / RST packet with a destination address equal to the target destination address is referred to as a target FIN / RST packet. Figure 12 In the corresponding embodiment, the target message is referred to as the target FIN / RST message.

[0290] In a FIN / RST flood attack, the attacker sends a large number of target FIN / RST packets to the protected device using fake sources, consuming the protected device's resources and causing it to be unable to respond to normal requests. The fake source target FIN / RST packets do not belong to any real session.

[0291] Depending on the state of the session to which the fake source destination FIN / RST message belongs, a fake source destination FIN / RST message includes at least one of the following three types:

[0292] 1. False source target FIN / RST packets include the first false source target FIN / RST packet, which is the target FIN / RST packet in a session created by a packet other than a SYN packet or SYN-ACK packet. False source packet rate includes the first false source packet rate, which is the rate of the first false source target FIN / RST packets flowing through the protection device within the statistical duration. The baseline value corresponding to the first false source packet rate is the first false source packet rate threshold.

[0293] 2. The spurious source target FIN / RST message includes the second spurious source target FIN / RST message. The second spurious source target FIN / RST message is the target FIN / RST message in a session created by a SYN message or SYN-ACK message but which has not completed the three-way handshake by the end of the statistical duration. The spurious source message rate includes the second spurious source message rate, which is the rate of the second spurious source target FIN / RST message flowing through the protection device within the statistical duration. The baseline value corresponding to the second spurious source message rate is the second spurious source message rate threshold.

[0294] 3. The spurious source target FIN / RST message includes a third spurious source target FIN / RST message, which is the target FIN / RST message of a closed session. That is, when the protection device receives the third spurious source target FIN / RST message, the session matching the third spurious source target FIN / RST message is already in a closed state. The spurious source message rate includes the third spurious source message rate, which is the rate of third spurious source target FIN / RST messages flowing through the protection device within the statistical duration. The baseline value corresponding to the third spurious source message rate is the third spurious source message rate threshold.

[0295] S1202, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than the corresponding total flow characteristic threshold.

[0296] If yes, meaning that at least one of the total traffic characteristic indicators has a statistical value greater than the corresponding total traffic characteristic threshold, it indicates that the current target FIN / RST packet traffic is large, and there may be a FIN / RST flood attack, requiring further confirmation, i.e., execute S1203. If no, meaning that none of the statistical values ​​of at least one total traffic characteristic indicator has a statistical value greater than the corresponding total traffic characteristic threshold, i.e., all the statistical values ​​of at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, execute S1205.

[0297] For example, when at least one total flow characteristic includes only total rate, if the statistical value of the total rate is greater than the total flow characteristic threshold corresponding to the total rate (hereinafter referred to as the total rate threshold), execute S1203. If the statistical value of the total rate is less than or equal to the total rate threshold, execute S1205.

[0298] When at least one total traffic feature includes only total bandwidth, if the statistical value of total bandwidth is greater than the total traffic feature threshold corresponding to total bandwidth (hereinafter referred to as the total bandwidth threshold), execute S1203. If the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1205.

[0299] When at least one total traffic characteristic includes total rate and total bandwidth, if the statistical value of total rate is greater than the total rate threshold, or the statistical value of total bandwidth is greater than the total bandwidth threshold, execute S1203. If the statistical value of total rate is less than or equal to the total rate threshold, and the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1205.

[0300] S1203, determine whether the statistical value of the fake source packet rate corresponding to the fake source target FIN / RST packet is greater than the fake source packet rate threshold corresponding to the target FIN / RST packet.

[0301] In this embodiment, S1203 can be implemented in the following two ways:

[0302] In one possible implementation, it is determined whether the statistical value corresponding to the first spoofing source packet rate is greater than the first spoofing source packet rate threshold, whether the statistical value corresponding to the second spoofing source packet rate is greater than the second spoofing source packet rate threshold, and whether the statistical value corresponding to the second spoofing source packet rate is greater than the second spoofing source packet rate threshold. When the statistical value corresponding to the first spoofing source packet rate is greater than the first spoofing source packet rate threshold, or the statistical value corresponding to the second spoofing source packet rate is greater than the second spoofing source packet rate threshold, or the statistical value corresponding to the second spoofing source packet rate is greater than the second spoofing source packet rate threshold, it indicates that there are a large number of spoofing source target FIN / RST packets, and S1204 is executed.

[0303] In another possible implementation, the statistical values ​​corresponding to the first, second, and third spoofing source packet rates are added together to obtain the statistical value of the spoofing source packet rate corresponding to the target FIN / RST packet. The first, second, and third spoofing source packet rate thresholds are then added together to obtain the spoofing source packet rate threshold corresponding to the target FIN / RST packet. In response to the statistical value of the spoofing target packet rate corresponding to the FIN / RST packet being greater than the spoofing source packet rate threshold corresponding to the target FIN / RST packet, step S1204 is executed.

[0304] S1204 indicates that the target address has been subjected to a FIN / RST flood attack.

[0305] Optionally, after determining that the target address has been attacked, an alarm is issued to indicate that the protected device is currently under a DDoS attack. Optionally, the alarm may also include the type of DDoS attack currently being suffered, such as the protected device currently suffering a FIN / RST flood attack.

[0306] Optionally, after determining that the target destination address has been attacked, corresponding defensive measures can be taken, such as directly discarding the target FIN / RST packet if it does not match a session in the session table, so as to ensure that the protected device can maintain normal business operation.

[0307] S1205, confirming that the target address has not been subjected to a FIN / RST flood attack.

[0308] Optionally, after determining that the protected device has not been attacked within a statistical duration (e.g., statistical duration H), statistical information of the target FIN / RST packets corresponding to K target statistical durations is obtained. The target destination address is determined to have not been attacked within the target statistical duration. The K target statistical durations include statistical duration H. Each statistical information includes a statistical value of the rate of the spoofed source target packet corresponding to the target FIN / RST packet. Further, among the statistical values ​​of the rate of the spoofed source target packet corresponding to the target FIN / RST packet within the K target statistical durations, the statistical value of the largest spoofed source target packet rate is determined as the baseline value of the rate of the spoofed source target packet corresponding to the target FIN / RST packet.

[0309] In this embodiment, statistical values ​​of multiple dimensions of indicators, such as total traffic characteristic indicators and attack characteristic indicators of the target FIN / RST packet, are obtained. When the statistical value of one total traffic characteristic indicator is greater than the corresponding total traffic characteristic threshold, it is further determined whether the statistical value of the fake source target packet rate corresponding to the target FIN / RST packet is greater than the fake source packet rate threshold corresponding to the target FIN / RST packet. When the statistical value of the fake source target packet rate corresponding to the target FIN / RST packet is greater than the fake source packet rate threshold corresponding to the target FIN / RST packet, it is determined that the target destination address has been attacked, thereby improving the accuracy of DDoS attack identification and reducing the probability of false alarms.

[0310] Besides SYN, SYN-ACK, ACK, and FIN / RST messages, HTTP / HTTPS request messages are also frequently used in DDoS attacks. The following describes methods for identifying ACK flood attacks. Figure 13 As shown, Figure 13 This is a flowchart illustrating another attack identification method provided in this application. In this embodiment, the target message type is an HTTP / HTTPS message, meaning this embodiment is used to identify HTTP / HTTPS flood attacks. This embodiment includes steps S1301-S1305.

[0311] S1301, Obtain statistical information of target HTTP / HTTPS request packets flowing through the protection device within the statistical period. The target packets are HTTP / HTTPS request packets with the destination address as the target destination address. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target HTTP / HTTPS request packets and / or the total bandwidth of the target HTTP / HTTPS request packets. The statistical information also includes the statistical value of the rate of the fake source target packets.

[0312] In this embodiment, an HTTP / HTTPS request message with a destination address equal to the target destination address is referred to as the target HTTP / HTTPS message. That is, in Figure 13 In the corresponding embodiment, the target message is referred to as the target HTTP / HTTPS request message. An HTTP / HTTPS request message is a message identified as an HTTP protocol and carrying a method field, such as an HTTP / HTTPS GET request message or an HTTP / HTTPS POST request message.

[0313] HTTP / HTTPS Flood attacks include attacks targeting HTTP / HTTPS requests from fake origins and attacks targeting HTTP / HTTPS requests based on real sessions.

[0314] The spoofed origin and destination HTTP / HTTPS request message attack refers to an attacker sending a large number of spoofed origin and destination HTTP / HTTPS request messages to a protected device. Normally, a legitimate client establishes a connection with a protected device through a TCP three-way handshake before sending HTTP / HTTPS request messages. Spoofed origin and destination HTTP / HTTPS request messages are generated out of thin air and do not belong to any real session.

[0315] Targeted HTTP / HTTPS request message attacks based on real sessions refer to DDoS attacks, such as fixed payload attacks and high-speed attacks, launched against protected devices based on sessions that have completed a three-way handshake.

[0316] Therefore, the attack signature indicators corresponding to the target HTTP / HTTPS request message include at least one of the following indicators:

[0317] 1. Spoofed Source Packet Rate. The spoofed source packet rate corresponding to the target HTTP / HTTPS request packet is the rate of spoofed source HTTP / HTTPS request packets flowing through the protection device within the statistical period. After receiving a target HTTP / HTTPS request packet (e.g., referred to as target HTTP / HTTPS request packet T), the protection device checks if there is a session in the session table that matches the five-tuple information of target HTTP / HTTPS request packet T. If no session matches the five-tuple information of target HTTP / HTTPS request packet T, target HTTP / HTTPS request packet T can be determined as a spoofed source target HTTP / HTTPS request packet, and the number of spoofed source target HTTP / HTTPS request packets within the statistical period is incremented by 1. After the statistical period ends, the number of spoofed source target HTTP / HTTPS request packets within the statistical period can be obtained. Dividing the number of spoofed source target HTTP / HTTPS request packets within the statistical period by the statistical period yields the statistical value of the spoofed source packet rate corresponding to the target HTTP / HTTPS request packet.

[0318] 2. Average Message Length Difference. The statistical value of the average message length difference corresponding to the target HTTP / HTTPS request message is the average of all message length differences within the statistical period. Specifically, the message length difference is the difference in message length between two target HTTP / HTTPS request messages received within the statistical period that belong to the same real session and are received at adjacent times.

[0319] 3. Average Target Packet Rate of Active Sessions. In this embodiment, the active session corresponding to the target HTTP / HTTPS request packet refers to a real session that has HTTP / HTTPS packets flowing through the protection device within the statistical period. In this embodiment, an HTTP packet refers to a packet that identifies the HTTP protocol, and an HTTPS packet refers to a packet that identifies the HTTPS protocol. HTTP / HTTPS packets include HTTP / HTTPS request packets and HTTP / HTTPS response packets. The statistical value of the average target packet rate of active sessions is the sum of the target HTTP / HTTPS request packet rates of all active sessions within the statistical period, divided by the number of active sessions. The target HTTP / HTTPS request packet rate of an active session (e.g., referred to as active session U) is the number of target HTTP / HTTPS request packets that flow through the protection device within the statistical period and belong to active session U, divided by the statistical period.

[0320] S1302, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than the corresponding total flow characteristic threshold.

[0321] If yes, meaning that at least one of the total traffic characteristic indicators has a statistical value greater than the corresponding total traffic characteristic threshold, it indicates that the current target HTTP / HTTPS request packet traffic is large, and there may be an HTTP / HTTPS flood attack, requiring further confirmation, i.e., execute S1303. If no, meaning that none of the at least one total traffic characteristic indicator has a statistical value greater than the corresponding total traffic characteristic threshold, i.e., all the statistical values ​​of at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, execute S1306.

[0322] For example, when at least one total flow characteristic includes only total rate, if the statistical value of the total rate is greater than the total flow characteristic threshold corresponding to the total rate (hereinafter referred to as the total rate threshold), execute S1303. If the statistical value of the total rate is less than or equal to the total rate threshold, execute S1306.

[0323] When at least one total traffic feature includes only total bandwidth, if the statistical value of total bandwidth is greater than the total traffic feature threshold corresponding to total bandwidth (hereinafter referred to as the total bandwidth threshold), execute S1303. If the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1306.

[0324] When at least one total traffic characteristic includes total rate and total bandwidth, if the statistical value of total rate is greater than the total rate threshold, or the statistical value of total bandwidth is greater than the total bandwidth threshold, execute S1303. If the statistical value of total rate is less than or equal to the total rate threshold, and the statistical value of total bandwidth is less than or equal to the total bandwidth threshold, execute S1306.

[0325] S1303, determine whether there is a statistical value of at least one total flow characteristic indicator that is greater than a preset multiple of the corresponding total flow characteristic threshold.

[0326] In one possible scenario, attackers may combine multiple attack methods to target the protected device, such as a mix of fixed-payload, low-payload, and high-payload attacks, or a mix of high-speed and slow attacks. This makes it difficult to distinguish whether a DDoS attack is currently underway based solely on the statistical values ​​of attack characteristic indicators. Therefore, by further determining whether the statistical value of at least one total traffic characteristic indicator exceeds a preset multiple of the corresponding total traffic characteristic threshold, false alarms can be reduced while missed alarms can be avoided.

[0327] Determining whether there exists a statistical value of at least one total traffic characteristic indicator that is greater than a preset multiple of the corresponding total traffic characteristic threshold may include determining whether the total rate is greater than n times the total rate threshold, and / or whether the total bandwidth is greater than m times the total bandwidth threshold.

[0328] Where m and n are both positive numbers greater than 1. For example, m can be 1.1, 1.2, 1.5, 2, 3, or 5, etc. It should be noted that m and n can also be other values ​​greater than 1. The values ​​of m and n can be set according to the strictness of the detection; examples are not provided here.

[0329] If so, meaning that among the statistical values ​​of at least one total traffic characteristic indicator, there is one whose statistical value is greater than a preset multiple of the corresponding total traffic characteristic threshold. For example, if the total rate is greater than n times the total rate threshold, or the total bandwidth is greater than m times the total bandwidth threshold, it indicates that the target HTTP / HTTPS request packet traffic is large and the possibility of being attacked by an HTTP / HTTPS flood is high, then S1305 is executed.

[0330] If not, that is, if none of the statistical values ​​of at least one total flow characteristic indicator are greater than a preset multiple of the corresponding total flow characteristic threshold, then execute S1304.

[0331] S1304, determine whether there is a statistical value of an attack feature indicator that is greater than the corresponding attack feature threshold among the statistical values ​​of at least one attack feature indicator corresponding to the target HTTP / HTTPS request message.

[0332] If not, that is, if none of the statistical values ​​of at least one attack feature indicator corresponding to the target HTTP / HTTPS request message are greater than the corresponding attack feature threshold, execute S1306.

[0333] If so, that is, if among the statistical values ​​of at least one attack feature indicator corresponding to the target HTTP / HTTPS request message, there is one attack feature indicator whose statistical value is greater than the corresponding attack feature threshold, execute S1305.

[0334] In other words, when multiple attack signature indicators correspond to a target HTTP / HTTPS request message, if the statistical value of any one of these indicators exceeds the corresponding attack signature threshold, the protected device can be considered to be under an HTTP / HTTPS flood attack. Similarly, if multiple attack signature indicators correspond to a target HTTP / HTTPS request message and their statistical values ​​exceed the corresponding attack signature threshold, the protected device is also considered to be under an HTTP / HTTPS flood attack.

[0335] S1305, the target destination address has been identified as being subjected to an HTTP / HTTPS flood attack.

[0336] Optionally, after determining that the target address has been attacked, an alarm is issued to indicate that the protected device is currently under a DDoS attack. Optionally, the alarm may also include the type of DDoS attack currently being suffered, such as the protected device currently suffering an HTTP / HTTPS flood attack.

[0337] Optionally, after determining that the target destination address has been attacked, corresponding defensive measures can be taken, such as directly discarding the target HTTP / HTTPS request message if it does not match a session in the session table, so as to ensure that the protected device can maintain normal business operation.

[0338] S1306, It has been determined that the target destination address has not been subjected to an HTTP / HTTPS flood attack.

[0339] Optionally, after determining that the protected device has not been attacked within a statistical period (e.g., statistical period W), statistical information of target HTTP / HTTPS request packets corresponding to K target statistical periods is obtained. The target destination address is determined to be unattacked within the target statistical period. The K target statistical periods include the statistical period W. Each statistical information includes a statistical value of the fake source target packet rate corresponding to the target HTTP / HTTPS request packet. Further, among the statistical values ​​of the fake source target packet rate corresponding to the target HTTP / HTTPS request packet within the K target statistical periods, the statistical value of the largest fake source target packet rate is determined as the baseline value of the fake source target packet rate corresponding to the target HTTP / HTTPS request packet.

[0340] In this embodiment, statistical values ​​of multiple dimensions of indicators, such as total traffic characteristic indicators and attack characteristic indicators of the target HTTP / HTTPS request packets, are obtained. When the statistical value of one total traffic characteristic indicator is greater than the corresponding total traffic characteristic threshold, it is further determined whether the statistical value of the fake source target packet rate corresponding to the target HTTP / HTTPS request packet is greater than the fake source packet rate threshold corresponding to the target HTTP / HTTPS request packet. When the statistical value of the fake source target packet rate corresponding to the target HTTP / HTTPS request packet is greater than the fake source packet rate threshold corresponding to the target HTTP / HTTPS request packet, it is determined that the target destination address has been attacked, thereby improving the accuracy of DDoS attack identification and reducing the probability of false alarms.

[0341] The above passed Figures 9-13 The corresponding embodiments describe the identification methods for DDoS flood attacks of different message types. Figures 9-13 The corresponding embodiments cover attack identification methods for SYN flood attacks, SYN-ACK flood attacks, ACK flood attacks, FIN flood attacks, RST flood attacks, HTTP flood attacks, and HTTPS flood attacks. In one possible implementation, the protection device may only implement... Figures 9-13 The corresponding embodiment covers one of the various attack type identification methods. In another possible implementation, the protection device can implement... Figures 9-13 The corresponding embodiments cover multiple attack type identification methods, thereby providing more comprehensive protection for the protected device. For example, the protective device implements any two, three, four, five, or six attack type identification methods among SYN flood attacks, SYN-ACK flood attacks, ACK flood attacks, FIN flood attacks, RST flood attacks, HTTP flood attacks, and HTTPS flood attacks; or the protective device simultaneously implements attack identification methods for all attack types among SYN flood attacks, SYN-ACK flood attacks, ACK flood attacks, FIN flood attacks, RST flood attacks, HTTP flood attacks, and HTTPS flood attacks. This application does not impose any limitations on this.

[0342] When the protection device can identify multiple attack types, if the protection device determines that the protected device has been subjected to any type of DDoS attack, the protection device will issue a corresponding alarm and implement corresponding protection measures to ensure the normal operation of the protected device's business.

[0343] Based on the same inventive concept, this application also provides Figure 8-13 The corresponding embodiment shows a protective device. The attack identification device 1400 can be an analysis device connected to the protective device. For example... Figure 14 As shown, Figure 14 This is a schematic diagram of the structure of an attack identification device provided in an embodiment of this application.

[0344] The attack identification device 1400 includes a processing module 1401.

[0345] Processing module 1401 is used to acquire statistical information of target packets flowing through the protection device within a statistical period. The target packets are packets with a destination address of the target destination address and a packet type of the target packet. The statistical information includes statistical values ​​of at least one total traffic characteristic indicator, which includes the total rate and / or the total bandwidth of the target packets. The statistical information also includes statistical values ​​of the at least one attack characteristic indicator. Processing module 1401 is used to determine whether the statistical value of the at least one attack characteristic indicator exceeds the corresponding baseline value in response to the presence of a statistical value of the at least one total traffic characteristic indicator that is greater than the corresponding total traffic characteristic threshold. Processing module 1401 is used to determine that the target destination address is under attack in response to the presence of a statistical value of the at least one attack characteristic indicator that exceeds the corresponding baseline value.

[0346] In one possible implementation, the target message type is any one of the following message types: Synchronization Sequence Number (SYN) message, Synchronization Sequence Number Acknowledgment (SYN-ACK) message, Acknowledgment (ACK) message, Connection End (FIN) message, Connection Reset (RST) message, Hypertext Transfer Protocol (HTTP) request message, and Hypertext Transfer Protocol Security (HTTPS) request message.

[0347] In one possible implementation, the at least one attack characteristic indicator includes the fake source packet rate of a fake source target packet, wherein the fake source target packet is the target packet outside the real session, the real session is a session that has completed the Transmission Control Protocol (TCP) three-way handshake, the fake source packet rate is the rate of the fake source target packet flowing through the protection device within the statistical duration, and the baseline value corresponding to the fake source packet rate is a fake source packet rate threshold; the processing module 1401 is configured to: determine that the target destination address has been attacked in response to the statistical value corresponding to the fake source packet rate being greater than the fake source packet rate threshold.

[0348] In one possible implementation, the spoofed source target packet includes a first spoofed source target packet, which is the target packet in a session created by a packet other than a SYN packet and a SYN-ACK packet. The spoofed source packet rate includes a first spoofed source packet rate, which is the rate of the first spoofed source target packet flowing through the protection device within the statistical duration. The baseline value corresponding to the first spoofed source packet rate is a first spoofed source packet rate threshold. The processing module 1401 is configured to: determine that the target destination address is under attack in response to a statistical value corresponding to the first spoofed source packet rate being greater than the first spoofed source packet rate threshold.

[0349] In one possible implementation, the target packet type is a FIN packet or an RST packet, the fake source target packet includes a second fake source target packet, the second fake source target packet is the target packet in a session created by a SYN packet or SYN-ACK packet but still not completed a three-way handshake at the end of the statistical duration, the fake source packet rate includes a second fake source packet rate, the second fake source packet rate is the rate of the second fake source target packet flowing through the protection device within the statistical duration, the baseline value corresponding to the second fake source packet rate is a second fake source packet rate threshold; the processing module 1401 is used to: determine that the target destination address is attacked in response to the statistical value corresponding to the second fake source packet rate being greater than the second fake source packet rate threshold.

[0350] In one possible implementation, the target packet type is a FIN packet or an RST packet, the fake source target packet includes a third fake source target packet, the third fake source target packet is a target packet of a closed session, the fake source packet rate includes a third fake source packet rate, the third fake source packet rate is the rate of the third fake source target packet flowing through the protection device within the statistical duration, and the baseline value corresponding to the third fake source packet rate is a third fake source packet rate threshold; the processing module 1401 is used to: determine that the target destination address is attacked in response to the statistical value corresponding to the third fake source packet rate being greater than the third fake source packet rate threshold.

[0351] In one possible implementation, the target packet type is an ACK packet, an HTTP request packet, or an HTTPS request packet. The at least one attack characteristic indicator includes an average packet length difference, which is the average of all packet length difference values ​​within the statistical period. The packet length difference value is the difference in packet length between two target packets received within the statistical period that belong to the same real session and have adjacent reception times. The real session is a session that has completed a TCP three-way handshake. The baseline boundary threshold corresponding to the average packet length difference is a packet length difference threshold. The processing module 1401 is used to: determine that the target destination address has been attacked in response to the statistical value corresponding to the average packet length difference being greater than the packet length difference threshold.

[0352] In one possible implementation, the target packet type is an ACK packet, and the at least one attack characteristic indicator includes the average target packet rate of active sessions. The active session is a session within the statistical duration in which the target packet flows through the protection device. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions within the statistical duration. The target packet rate corresponding to the active session is the rate of the target packet flowing through the protection device in the active session within the statistical duration. The baseline boundary threshold corresponding to the average target packet rate of the active session is a first rate threshold. The processing module 1401 is configured to: determine that the target destination address is attacked in response to the statistical value corresponding to the average target packet rate of the active session being greater than the first rate threshold.

[0353] In one possible implementation, the target packet type is an HTTP request packet or an HTTPS request packet, and the at least one attack characteristic indicator includes the average target packet rate of active sessions. The active session is a session in which HTTP or HTTPS packets flow through the protection device within the statistical time period. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions within the statistical time period. The target packet rate corresponding to the active session is the number of target packets in the active session flowing through the protection device within the statistical time period. The baseline boundary threshold corresponding to the average target packet rate of the active session is a second rate threshold. The processing module 1401 is configured to: determine that the target destination address has been attacked in response to the statistical value corresponding to the average target packet rate of the active session being greater than the second rate threshold.

[0354] In one possible implementation, the target packet type is an ACK packet, an HTTP request packet, or an HTTPS request packet; the total traffic characteristic threshold corresponding to the total rate is a total rate threshold; the total traffic characteristic threshold corresponding to the total bandwidth is a total bandwidth threshold; the processing module 1401 is configured to, in response to the total rate being greater than the total rate threshold, determine whether the total rate is greater than n times the total rate threshold, where n is a positive number greater than 1; the processing module 1401 is configured to, in response to the total rate being greater than n times the total rate threshold, determine that the target destination address has been attacked; and / or the processing module 1401 is configured to, in response to the total bandwidth being greater than the total bandwidth threshold, determine whether the total bandwidth is greater than m times the total bandwidth threshold, where m is a positive number greater than 1; the processing module 1401 is configured to, in response to the total bandwidth being greater than m times the total bandwidth threshold, determine that the target destination address has been attacked.

[0355] In one possible implementation, the processing module 1401 is configured to, in response to the fact that the statistical values ​​of all total traffic characteristic indicators in the statistical values ​​of the at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, obtain statistical information of target packets corresponding to K target statistical durations, wherein the K target statistical durations include the statistical duration, and the target destination address is not attacked within the K target statistical durations, and K is an integer greater than or equal to 2; the processing module 1401 is configured to determine the baseline value corresponding to each attack characteristic indicator based on the statistical value corresponding to each of the attack characteristic indicators within the K target statistical durations.

[0356] In one possible implementation, the baseline value corresponding to the attack feature index is the maximum and / or minimum value among the statistical values ​​corresponding to the attack feature index within the statistical duration of the K targets.

[0357] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a computer, implements the experience evaluation method flow of the above-described method embodiments.

[0358] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0359] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a computer, implements the experience evaluation method flow of the above-described method embodiments.

[0360] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0361] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, indirect coupling or communication connection between devices or units, and may be electrical or other forms.

[0362] The units described as discrete components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0363] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0364] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the technical solution of this application can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

Claims

1. An attack identification method, characterized in that, The method includes: Obtain statistical information of target packets flowing through the protection device within a statistical period. The target packets are packets with a destination address of the target address and a packet type of the target packet. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target packets and / or the total bandwidth of the target packets. The statistical information also includes the statistical value of the at least one attack characteristic indicator. In response to the fact that the statistical value of one of the at least one total traffic characteristic indicators is greater than the corresponding total traffic characteristic threshold, it is determined whether the statistical value of one of the at least one attack characteristic indicators exceeds the corresponding baseline value. If, in response to the fact that the statistical value of one of the at least one attack feature indicators exceeds the corresponding baseline value, it is determined that the target destination address has been attacked.

2. The method according to claim 1, characterized in that, The target message type is any one of the following message types: Synchronization Sequence Number (SYN) message, Synchronization Sequence Number Acknowledgment (SYN-ACK) message, Acknowledgment (ACK) message, Connection End (FIN) message, Connection Reset (RST) message, Hypertext Transfer Protocol (HTTP) request message, and Hypertext Transfer Protocol Security (HTTPS) request message.

3. The method according to claim 1 or 2, characterized in that, The at least one attack feature indicator includes the fake source packet rate of the fake source target packet, wherein the fake source target packet is the target packet outside the real session, the real session is the session that has completed the Transmission Control Protocol TCP three-way handshake, the fake source packet rate is the rate of the fake source target packet flowing through the protection device within the statistical duration, and the baseline value corresponding to the fake source packet rate is the fake source packet rate threshold. The determination that the target destination address has been attacked, based on the fact that the statistical value of one of the at least one attack feature indicators exceeds the corresponding baseline value, includes: If the statistical value corresponding to the rate of the fake source packets is greater than the threshold of the fake source packet rate, it is determined that the target destination address has been attacked.

4. The method according to claim 3, characterized in that, The false source target packet includes a first false source target packet, which is the target packet in a session created by a packet other than a SYN packet and a SYN-ACK packet. The false source packet rate includes a first false source packet rate, which is the rate of the first false source target packet flowing through the protection device within the statistical duration. The baseline value corresponding to the first false source packet rate is a first false source packet rate threshold. The determination that the target destination address has been attacked in response to a statistical value corresponding to the rate of the fake source packet being greater than the threshold of the fake source packet rate includes: In response to the statistical value corresponding to the first fake source packet rate being greater than the first fake source packet rate threshold, it is determined that the target destination address has been attacked.

5. The method according to claim 3, characterized in that, The target packet type is a FIN packet or an RST packet. The false source target packet includes a second false source target packet. The second false source target packet is the target packet in a session created by a SYN packet or a SYN-ACK packet but which has not completed the three-way handshake by the end of the statistical duration. The false source packet rate includes a second false source packet rate. The second false source packet rate is the rate of the second false source target packet flowing through the protection device within the statistical duration. The baseline value corresponding to the second false source packet rate is a second false source packet rate threshold. The determination that the target destination address has been attacked in response to a statistical value corresponding to the rate of the fake source packet being greater than the threshold of the fake source packet rate includes: If the statistical value corresponding to the rate of the second fake source packet is greater than the threshold of the rate of the second fake source packet, it is determined that the target destination address has been attacked.

6. The method according to claim 3, characterized in that, The target message type is a FIN message or an RST message. The false source target message includes a third false source target message. The third false source target message is the target message of a closed session. The false source message rate includes a third false source message rate. The third false source message rate is the rate of the third false source target message flowing through the protection device within the statistical duration. The baseline value corresponding to the third false source message rate is the third false source message rate threshold. The determination that the target destination address has been attacked in response to a statistical value corresponding to the rate of the fake source packet being greater than the threshold of the fake source packet rate includes: If the statistical value corresponding to the rate of the third fake source packet is greater than the threshold of the rate of the third fake source packet, it is determined that the target destination address has been attacked.

7. The method according to claim 1 or 2, characterized in that, The target message type is an ACK message, an HTTP request message, or an HTTPS request message. The at least one attack feature indicator includes the average message length difference, which is the average of all message length difference values ​​within the statistical period. The message length difference value is the difference in message length between two target messages received within the statistical period that belong to the same real session and have adjacent reception times. The real session is a session that has completed a TCP three-way handshake. The baseline boundary threshold corresponding to the average message length difference is the message length difference threshold. The determination that the target destination address has been attacked, based on the fact that the statistical value of one of the at least one attack feature indicators exceeds the corresponding baseline value, includes: If the statistical value corresponding to the average difference in message length is greater than the message length difference threshold, it is determined that the target destination address has been attacked.

8. The method according to claim 1 or 2, characterized in that, The target packet type is an ACK packet, and the at least one attack characteristic indicator includes the average target packet rate of active sessions. The active session is a session in the statistical time period in which the target packet flows through the protection device. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions in the statistical time period. The target packet rate corresponding to the active session is the rate of the target packet in the active session that flows through the protection device in the statistical time period. The baseline boundary threshold corresponding to the average target packet rate of the active session is a first rate threshold. The determination that the target destination address has been attacked, based on the fact that the statistical value of one of the at least one attack feature indicators exceeds the corresponding baseline value, includes: If the statistical value corresponding to the average target packet rate of the active session is greater than the first rate threshold, it is determined that the target destination address has been attacked.

9. The method according to claim 1 or 2, characterized in that, The target message type is an HTTP request message or an HTTPS request message. The at least one attack characteristic indicator includes the average target message rate of active sessions. An active session is a session in which HTTP or HTTPS messages flow through the protection device within the statistical time period. The average target message rate of the active session is the average of the target message rates corresponding to all active sessions within the statistical time period. The target message rate corresponding to the active session is the number of target messages in the active sessions that flow through the protection device within the statistical time period. The baseline boundary threshold corresponding to the average target message rate of the active session is a second rate threshold. The determination that the target destination address has been attacked, based on the fact that the statistical value of one of the at least one attack feature indicators exceeds the corresponding baseline value, includes: If the statistical value corresponding to the average target packet rate of the active session is greater than the second rate threshold, it is determined that the target destination address has been attacked.

10. The method according to claim 1 or 2, characterized in that, The target message type is an ACK message, an HTTP request message, or an HTTPS request message; the total traffic characteristic threshold corresponding to the total rate is the total rate threshold; the total traffic characteristic threshold corresponding to the total bandwidth is the total bandwidth threshold; the method further includes: In response to the total rate being greater than a total rate threshold, it is determined whether the total rate is greater than n times the total rate threshold, where n is a positive number greater than 1; In response to the total rate being greater than n times the total rate threshold, it is determined that the target destination address is under attack; and / or In response to the total bandwidth being greater than a total bandwidth threshold, it is determined whether the total bandwidth is greater than m times the total bandwidth threshold, where m is a positive number greater than 1; In response to the total bandwidth being greater than m times the total bandwidth threshold, it is determined that the target destination address has been attacked.

11. The method according to any one of claims 1 to 10, characterized in that, The method further includes: In response to the fact that the statistical values ​​of all total traffic characteristic indicators in the statistical values ​​of the at least one total traffic characteristic indicator are less than or equal to the corresponding total traffic characteristic threshold, statistical information of target packets corresponding to K target statistical durations is obtained, wherein the K target statistical durations include the statistical duration, and the target destination address is not attacked within the K target statistical durations, where K is an integer greater than or equal to 2; Based on the statistical values ​​corresponding to each of the attack feature indicators within the statistical time period of the K targets, the baseline value corresponding to each of the attack feature indicators is determined.

12. The method according to claim 11, characterized in that, The baseline value corresponding to the attack feature index is the maximum and / or minimum value among the statistical values ​​corresponding to the attack feature index within the statistical time of the K targets.

13. An attack detection device, characterized in that, The device includes: The processing module is used to obtain statistical information of target packets flowing through the protection device within a statistical period. The target packets are packets with a destination address of the target destination address and a packet type of the target packet. The statistical information includes the statistical value of at least one total traffic characteristic indicator. The total traffic characteristic indicator includes the total rate of the target packets and / or the total bandwidth of the target packets. The statistical information also includes the statistical value of the at least one attack characteristic indicator. The processing module is configured to, in response to the fact that the statistical value of one of the at least one total traffic characteristic indicators is greater than the corresponding total traffic characteristic threshold, determine whether the statistical value of one of the at least one attack characteristic indicators exceeds the corresponding baseline value. The processing module is configured to determine that the target destination address has been attacked in response to the fact that the statistical value of one of the statistical values ​​of the at least one attack feature indicator exceeds the corresponding baseline value.

14. The apparatus according to claim 13, characterized in that, The at least one attack feature indicator includes the fake source packet rate of the fake source target packet, wherein the fake source target packet is the target packet outside the real session, the real session is the session that has completed the Transmission Control Protocol TCP three-way handshake, the fake source packet rate is the rate of the fake source target packet flowing through the protection device within the statistical duration, and the baseline value corresponding to the fake source packet rate is the fake source packet rate threshold. The processing module is configured to determine that the target destination address has been attacked in response to a statistical value corresponding to the rate of the fake source packets being greater than the threshold of the fake source packets.

15. The apparatus according to claim 13, characterized in that, The target message type is an ACK message, an HTTP request message, or an HTTPS request message. The at least one attack feature indicator includes the average message length difference, which is the average of all message length difference values ​​within the statistical period. The message length difference value is the difference in message length between two target messages received within the statistical period that belong to the same real session and have adjacent reception times. The real session is a session that has completed a TCP three-way handshake. The baseline boundary threshold corresponding to the average message length difference is the message length difference threshold. The processing module is configured to determine that the target destination address has been attacked in response to a statistical value corresponding to the average difference in message length being greater than the message length difference threshold.

16. The apparatus according to claim 13, characterized in that, The target packet type is an ACK packet, and the at least one attack characteristic indicator includes the average target packet rate of active sessions. The active session is a session in the statistical time period in which the target packet flows through the protection device. The average target packet rate of the active session is the average of the target packet rates corresponding to all active sessions in the statistical time period. The target packet rate corresponding to the active session is the rate of the target packet in the active session that flows through the protection device in the statistical time period. The baseline boundary threshold corresponding to the average target packet rate of the active session is a first rate threshold. The processing module is configured to determine that the target destination address has been attacked in response to a statistical value corresponding to the average target packet rate of the active session being greater than the first rate threshold.

17. The apparatus according to claim 13, characterized in that, The target message type is an HTTP request message or an HTTPS request message. The at least one attack characteristic indicator includes the average target message rate of active sessions. An active session is a session in which HTTP or HTTPS messages flow through the protection device within the statistical time period. The average target message rate of the active session is the average of the target message rates corresponding to all active sessions within the statistical time period. The target message rate corresponding to the active session is the number of target messages in the active sessions that flow through the protection device within the statistical time period. The baseline boundary threshold corresponding to the average target message rate of the active session is a second rate threshold. The processing module is configured to determine that the target destination address has been attacked in response to a statistical value corresponding to the average target packet rate of the active session being greater than the second rate threshold.

18. An attack detection device, characterized in that, Including processor and memory: The processor is configured to execute a computer program or instructions stored in the memory, wherein when the processor executes the computer program or instructions, the method described in any one of claims 1 to 12 is performed.

19. A chip, characterized in that, The method includes a processor coupled to a memory for executing a computer program or instructions stored in the memory, wherein when the processor executes the computer program or instructions, the method described in any one of claims 1 to 12 is performed.

20. A computer-readable storage medium, characterized in that, The computer stores instructions that, when executed on the computer, cause the computer to perform the method as described in any one of claims 1 to 12.

21. A computer program product, characterized in that, The device stores computer-readable instructions that, when read and executed by the attack identification device, cause the attack identification device to perform the method as described in any one of claims 1 to 12.