Data Processing Method, Apparatus, Device, and Storage Medium

A data processing method for network security systems improves network connection quality and user experience by using a security detection device to verify client legitimacy through out-of-window test messages, effectively mitigating ACK Flood attacks.

JP7711285B2Active Publication Date: 2025-07-22BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024146202
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-10-18
Filing Date
2024-08-28
Publication Date
2025-07-22
Estimated Expiration
2044-08-28

AI Technical Summary

Technical Problem

Existing TCP timeout retransmission mechanisms in network security systems cause lag in network connections, particularly affecting latency-sensitive services like games, and fail to effectively distinguish legitimate clients from attacking clients during ACK Flood attacks.

Method used

Implement a data processing method that uses a security detection device to identify network attacks and sends a test message with a sequence number outside the client's sliding window to trigger a verification message, allowing the security protection device to determine client legitimacy without disrupting the network connection.

Benefits of technology

Improves network connection quality and user experience by accurately identifying legitimate clients and preventing ACK Flood attacks without disconnecting clients, thus enhancing security and performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007711285000001
    Figure 0007711285000001
  • Figure 0007711285000002
    Figure 0007711285000002
  • Figure 0007711285000003
    Figure 0007711285000003
Patent Text Reader

Abstract

To provide a data processing method, apparatus, device, and storage medium for improving the quality of network connection in a network protection process.SOLUTION: A method includes the steps of: in response to receiving a data message sent from a client, detecting by a security detection device whether a destination server corresponding to the data message is under network attack; if the data message is under network attack, guiding the data message to a security protection device and sending a test message by the security protection device; verifying a verification message returned from the client side by the security protection device, and if the verification is passed, determining that the client side is a legitimate client side and sending the data message to the destination server, and if the verification is not passed, determining that the client side is an attacking client and discarding the data message.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the technical field of network security, and particularly to a data processing method, apparatus, device, and storage medium.

Background Art

[0002] ACK Flood is one of the currently common DDoS (Distributed Denial of Service Attack) attacks. Its main principle is to forge a large number of fake source IPs, and send a large number of ACK (Acknowledge character) messages to the server through the forged fake source IPs. The server is blocked by these malicious ACK messages, and further, it is an attack method for the server to deny service.

[0003] In the prior art, the TCP (Transmission Control Protocol) timeout retransmission mechanism can be used to verify whether the source IP of the client is legitimate. The specific steps are as follows: after an ACK Flood attack occurs, the protection system discards the ACK message. If the client retransmits the ACK message within a predetermined time, it is determined that the source IP of this client is legitimate; if the client does not retransmit the ACK message within a predetermined time, it is determined that the source IP of this client is not legitimate.

[0004] However, the inventor has found that in the prior art, since it is necessary to perform session timeout retransmission after starting the ACK retransmission algorithm, in this way, there is at least a technical problem that a short lag occurs in the client's network connection, and especially in the case of services sensitive to delay (such as games), the user experience is poor.

Summary of the Invention

[0005] Embodiments of the present disclosure provide a data processing method, apparatus, device, and storage medium that can improve the quality of network connections in a network security protection process and further improve the user experience.

[0006] In a first aspect, an embodiment of the present disclosure is a data processing method applied to a network protection system including a security detection device and a security protection device, responding to receiving a data message sent from a client, detecting, by the security detection device, whether a destination server corresponding to the data message is under a network attack; when it is detected that the destination server is under a network attack, guiding the data message to a security protection device, and transmitting, by the security protection device, a test message with a sequence number outside the client's sliding window to the client to trigger the client to return a verification message to the security protection device; verifying, by the security protection device, the verification message returned from the client, and when the verification passes, determining that the client is a legitimate client and transmitting the data message to the destination server, and when the verification fails, determining that the client is an attacking client and discarding the data message. A data processing method is provided that includes the above steps.

[0007] In a second aspect, an embodiment of the present disclosure is a data processing apparatus applied to a network protection system including a security detection device and a security protection device, a detection module for detecting, by the security detection device, whether a destination server corresponding to a data message sent from a client is under a network attack in response to receiving the data message; When it is detected that the destination server is under a network attack, the data message is guided to a security protection device, and in order to trigger the client to return a verification message to the security protection device, a transmission module for the security protection device to send a test message with a sequence number outside the sliding window of the client to the client, A verification module that verifies the verification message returned from the client by the security protection device, and if the verification passes, determines that the client is a legitimate client and sends the data message to the destination server, and if the verification fails, determines that the client is an attacking client and discards the data message, to provide a data processing device including the same.

[0008] In a third aspect, an embodiment of the present disclosure is An electronic device including a processor and a memory communicatively connected to the processor, The memory stores computer-executable instructions, The processor provides an electronic device that realizes the data processing method described in the first aspect by executing the computer-executable instructions stored in the memory.

[0009] In a fourth aspect, an embodiment of the present disclosure provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, realize the data processing method described in the first aspect.

[0010] In a fifth aspect, an embodiment of the present disclosure provides a computer program product including a computer program that, when executed by a processor, realizes the data processing method described in the first aspect.

[0011] In the data processing method, apparatus, device, and storage medium provided by this embodiment, the method includes: in response to receiving a data message sent from a client, detecting, by a security detection device, whether a destination server corresponding to the data message is under a network attack; when detecting that the destination server is under a network attack, guiding the data message to a security protection device, and triggering the client to return a verification message to the security protection device by sending, by the security protection device, a test message to the client, where a sequence number of the test message is located outside a sliding window of the client; verifying, by the security protection device, a verification message returned from the client, and when the verification passes, determining that the client is a legitimate client and sending the data message to the destination server, and when the verification fails, determining that the client is an attacking client and discarding the data message. In an embodiment of this application, when the destination server is under a network attack, the security protection device can send a test message to the client instead of the server, the sequence number of the test message is located outside the sliding window of the client, the client can be triggered to return a verification message, in this way, the security protection device verifies the verification message, further determines whether the client is legitimate, and in the process of verifying the verification message by the security protection device, there is no need to stop the network connection between the server and the client, and the quality of the network connection in the network security protection process can be improved, so the user experience is improved. Brief Description of the Drawings

[0012] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the drawings necessary for the description of the embodiments or the prior art are briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present disclosure, and those skilled in the art can obtain other drawings based on these drawings without creative efforts.

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Modes for Carrying Out the Invention

[0013] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.

[0014] Note that the user information (including, but not limited to, user device information, user personal information, etc.) and data (including, but not limited to, data for analysis, stored data, displayed data, etc.) related to this application are all information and data that have been authorized by the user or sufficiently permitted by the parties. The collection, use, and processing of related data must comply with relevant laws, regulations, and standards, and corresponding operation entries for the user to select permission or rejection shall be provided.

[0015] ACKFlood is one of the commonly seen DDoS (Distributed denial of service attack) attacks currently. Its main principle is to forge a large number of fake source IPs, and through the forged fake source IPs, send a large number of ACK (Acknowledge character) messages to the server, causing the server to be blocked by these malicious ACK messages, and further resulting in the server's denial of service attack method.

[0016] In the prior art, the timeout retransmission mechanism of TCP (Transmission Control Protocol) can be used to verify whether the source IP of the client is legitimate. The specific steps are as follows: after an ACKFlood attack occurs, the protection system discards the ACK message. If the client retransmits the ACK message within a predetermined time, it is determined that the source IP of this client is legitimate; if the client does not retransmit the ACK message within the predetermined time, it is determined that the source IP of this client is not legitimate.

[0017] However, after the ACK retransmission algorithm is activated, it is necessary to retransmit after the session times out. Thus, a short lag occurs in the client's network connection. Particularly in the case of services sensitive to latency (such as games), the user experience deteriorates. Also, for different clients, the timeout retransmission interval may be very short or very long. Since the time to retransmit the ACK message is long in this way, there is a possibility that the ACK message may be accidentally deleted, and the user experience also deteriorates.

[0018] Therefore, how to ensure network security and improve the quality of network connection is an urgent problem to be solved currently.

[0019] To solve the above problems, this embodiment provides the following technical idea. When the client and the server transmit data via TCP, TCP can perform transmission control by adopting a sliding window. That is, there is a sliding window of a specific size on the receiving side of the message. As the messages are received in order, the sliding window is moving. However, if the number of the message received by the receiving side is not within the range of the sliding window, it is called out of window (i.e., oow), where window refers to the sliding window. According to the regulations of the TCP protocol stack, when the receiving side (for example, the client) receives one oow message, the message is discarded, and one ack message is returned to the other side (for example, the server).

[0020] This application can verify whether the source IP of the client is legitimate by using the out of window mechanism and protect against ACK Flood attacks. Here, when a legitimate client receives one oow message, it can trigger the out of window mechanism and return one ack message. When an illegal client (or attacking client) receives one oow message, it does not trigger the out of window mechanism and does not return an ack message. Accordingly, the specific steps are as follows. First, in response to receiving the data message sent from the client, the security detection device detects whether the destination server corresponding to the data message is under a network attack. Next, if it is detected that the destination server is under a network attack, the data message is guided to the security protection device, and the security protection device sends a test message to the client (that is, the security protection device can send a test message to the client on behalf of the server). Here, the sequence number of the test message is located outside the sliding window of the client, and the out of window mechanism can be triggered so that the client returns a verification message to the security protection device. Finally, the security protection device verifies the verification message returned from the client. If the verification passes, it is determined that the client is a legitimate client and the data message is sent to the destination server. If the verification fails, it is determined that the client is an attacking client and the data message is discarded.

[0021] In this case, when the destination server is under a network attack, a security protection device can send a test message to the client on behalf of the server. Since the sequence number of the test message is located outside the client's sliding window, the client can be triggered to return a verification message. In this way, the security protection device verifies the verification message, further determines whether the client is legitimate, and in the process of verifying the verification message by the security protection device, without stopping the network connection between the server and the client, the quality of the network connection in the network security protection process can be improved, thus improving the user experience.

[0022] Hereinafter, the application scenarios of the embodiments of the present disclosure will be interpreted.

[0023] The data processing method provided by the embodiments of the present disclosure can be applied to a scenario where a network protection system provides security protection for a server. FIG. 1 is a schematic diagram of an application scenario of the data processing method provided by the embodiments of the present disclosure. As shown in FIG. 1, the network protection system includes a security detection device 101 and a security protection device 102. Here, the security detection device 101 detects whether the destination server is under a network attack. If a network attack is detected, it guides the data message to the security protection device 102, and the security protection device 102 verifies whether the client is legitimate. If it is determined that the client is a legitimate client, the data message is sent to the destination server. If it is determined that the client is an attacking client, the data message is discarded. Hereinafter, the data processing method provided by the embodiments of the present disclosure will be described in detail with specific embodiments.

[0024] FIG. 2 is a flowchart of a data processing method provided by an embodiment of the present disclosure. The information processing can be applied to a network protection system, and the network protection system includes a security detection device and a security protection device. As shown in FIG. 2, the method includes the following steps S201 to S203.

[0025] In S201, in response to receiving a data message sent from a client, a security detection device detects whether a destination server corresponding to the data message is under a network attack.

[0026] In an embodiment of the present disclosure, the data message sent from the client may be a message in any format. For example, the data message may be an ACK message or a PUSHACK (PUSH Acknowledge character) message. Optionally, in a network connection, the data message sent from the client is also traffic sent from the client. Optionally, the destination server corresponding to the data message is the server to which the client attempts to send the data message, that is, the server that receives the data message.

[0027] In some embodiments, the security detection device can determine whether the server is under a network attack based on information such as traffic, packet volume, and number of connections. Accordingly, the process of detecting whether the destination server corresponding to the data message is under a network attack by the security detection device includes the steps of detecting the number of messages, the number of data packets, and the number of connected clients of the destination server corresponding to the data message by the security detection device; determining that the destination server is under a network attack when the number of messages is greater than a first predetermined threshold, and / or the number of data packets is greater than a second predetermined threshold, and / or the number of connected clients is greater than a third predetermined threshold; and determining that the destination server is not under a network attack when the number of messages is less than or equal to the first predetermined threshold, the number of data packets is less than or equal to the second predetermined threshold, and the number of connected clients is less than or equal to the third predetermined threshold.

[0028] Here, the network attack may be a DDoS network attack including an ACK Flood attack. In the embodiments of the present disclosure, the numerical values of the first predetermined threshold, the second predetermined threshold, and the third predetermined threshold are not specifically limited and can be set and modified as needed.

[0029] Note that as shown in FIG. 5, the network protection system can further include an optical splitter. Accordingly, in response to receiving the data message sent from the client, the process of detecting whether the destination server corresponding to the data message is under a network attack by the security detection device includes the steps of copying the data message by the optical splitter in response to receiving the data message sent from the client, sending the copied data message to the security detection device, and detecting whether the destination server corresponding to the data message is under a network attack by the security detection device.

[0030] Here, the optical splitter is used to copy the data message, and the security detection device can immediately detect and analyze the data message sent from the client without affecting the original transmission link of the data message.

[0031] Furthermore, when the destination server detects that it is not under a network attack, the method may further include the step of sending the data message sent from the client to the destination server.

[0032] Here, since the optical splitter is provided to copy the data message, it is possible to perform a security inspection on the copied data message while the data message is being normally transmitted, that is, to perform a security inspection on the destination server corresponding to the data message under the condition that the normal transmission of the data message is not affected, so as to improve the transmission efficiency of the message data.

[0033] In S202, when it is detected that the destination server is under a network attack, in order to guide the data message to the security protection device and trigger the client to return a verification message to the security protection device, the security protection device sends a test message with a sequence number outside the client's sliding window to the client.

[0034] In an embodiment of the present disclosure, the sliding window may be a sliding window in a TCP connection. In addition, when the sequence number of the test message is outside the client's sliding window, it is determined that the test message is an oow (out of window) message. Based on the provisions of the TCP protocol stack, when the client receives one oow message, the message is discarded and one verification message is returned. Here, the test message may be a keepalive message, and the verification message may be a keepalive_ack message.

[0035] Here, in order to ensure that the client can receive the test message sent from the security protection device, before the security protection device sends the test message to the client, it is necessary to first limit some message information of the test message. Optionally, the step of constructing the test message by the security protection device includes determining the positive acknowledgment number of the data message sent from the client, and determining the sequence number of the test message as a value obtained by subtracting a predetermined value from the positive acknowledgment number of the data message, and / or determining the first session information of the data message sent from the client, including the source port, destination port, source address, destination address, and protocol type, and synchronizing the second session information of the test message with the first session information, and / or setting the setting method of the test message to only the ACK set, and / or setting the test message so that no payload data is carried.

[0036] Here, by determining the sequence number of the test message as a value obtained by subtracting a predetermined value from the positive response number of the data message, it is possible to ensure that the sequence number of the test message is located outside the client's sliding window, so as to trigger the client to return a verification message to the security protection device. In an embodiment of the present disclosure, the numerical value of the predetermined value is not specifically limited and can be set and modified as needed. Exemplarily, the predetermined value is 1, the sequence number can be represented by seq, the positive response number can be represented by ack, where seq = ack - 1. For example, the range of the sliding window is 33 to 40. The positive response number of the data message is 32. At this time, the sequence number of the test message is 31, which is located outside the range of the sliding window, and the client can be triggered to return a verification message to the security protection device.

[0037] Here, the first session information includes the source port, destination port, source address, destination address, and protocol type. By synchronizing the second session information of the test message as the first session information, it can be ensured that the test message and the received data message are in the same TCP session.

[0038] Here, by setting the setting method of the test message to only the ACK set, it can be ensured that the client receives the test message.

[0039] Here, by setting the test message so that no payload data is carried, it is possible to avoid the test message interfering with the original data of the client.

[0040] As shown in FIG. 3, after receiving the test message (e.g., keepalive message), the normal client returns one verification message to the security protection device. As shown in FIG. 4, since the attacking client is not a genuine client, it does not have the tcp out-of-window mechanism. Therefore, after receiving the test message, the attacking client does not return a verification message and continues to randomly send ACK messages or PUSHACK messages. In some embodiments, if the security protection device does not receive the verification message returned by the client within a predetermined time, it determines that the client is an attacking client and discards the data message. In the embodiments of the present disclosure, the numerical value of the predetermined time is not specifically limited and can be set and modified as needed. For example, the predetermined time may be 1 second, 2 seconds, or 3 seconds.

[0041] In some embodiments, as shown in FIG. 5, the network protection system further includes a control center device, where the control center device can send a protection command to the security protection device to control the security protection device to activate the protection mechanism.

[0042] Optionally, the step of guiding the data message to the security protection device is as follows. The security detection device sends attack warning information to the control center device, and the control center device is used to send a protection command to the security protection device in response to receiving the attack warning information. Here, the protection command carries the IP address information of the destination server corresponding to the data message. In response to receiving the protection command, the security protection device determines the routing device corresponding to the IP address information of the destination server, and the routing device guides the data message to the security protection device. Here, after guiding the data message to the security protection device, the security protection device can intercept the attack message in the data message and send the normal message to the corresponding destination server.

[0043] In S203, verify the verification message returned from the client by the security protection device. If the verification passes, determine that the client is a legitimate client, and send the data message to the destination server. If the verification fails, determine that the client is an attacking client and discard the data message.

[0044] In an embodiment of the present disclosure, the verification message can be verified based on the message information of the verification message. Accordingly, the step of verifying the verification message returned from the client by the security protection device includes the step of obtaining the message information of the verification message, and the security protection device determines whether the verification message is a keep-alive message based on the message information. If so, the verification passes; if not, the verification fails.

[0045] Here, the keep-alive message may be a Keepalive_ack message. After receiving the test message, a normal client returns one Keepalive_ack message to the security protection device. However, since the attacking client is not a genuine client, it does not return a verification message and continues to randomly send an ACK message or a PUSHACK message. At this time, the message returned from the attacking client is not a keep-alive message (Keepalive_ack message).

[0046] Optionally, the message information of the verification message includes one or more of session information, time-to-live information, setting method, whether it carries payload data, positive response number, and sequence number. Accordingly, the step of determining whether the verification message is a keep-alive message based on the message information by the security protection device can include the step of determining whether the verification message is a keep-alive message based on at least one piece of message information of the verification message by the security protection device.

[0047] When determining whether the verification message is a keep-alive message based on a plurality of message information, if it is determined based on any one of the message information that the verification message is not a keep-alive message, then it is determined that the verification message is not a keep-alive message. Only when it is determined based on all of the message information among the plurality of message information that the verification message is a keep-alive message, is it determined that the verification message is a keep-alive message.

[0048] Exemplarily, based on session information and survival time information, it is determined whether the verification message is a keep-alive message. Only when it is determined based on the session information that the verification message is a keep-alive message and it is determined based on the survival time information that the verification message is a keep-alive message, is it determined that the verification message is a keep-alive message. If it is determined based on the session information that the verification message is not a keep-alive message, or if it is determined based on the survival time information that the verification message is not a keep-alive message, then it is determined that the verification message is not a keep-alive message.

[0049] Hereinafter, specific steps for determining whether the verification message is a keep-alive message based on each message information will be described in detail.

[0050] Optionally, the specific steps for determining whether the verification message is a keep-alive message based on the session information are that the security protection device determines the third session information of the verification message, and if the third session information is the same as the second session information of the test message, it is determined that the verification message is a keep-alive message, and if they are different, it is determined that the verification message is not a keep-alive message.

[0051] Here, the second session information includes the source port, destination port, source address, destination address, and protocol type. If the third session information is the same as the second session information, it can be ensured that the verification message and the test message are in the same TCP session.

[0052] Optionally, based on the time-to-live information, the specific steps to determine whether the verification message is a keep-alive message are as follows: determine the first time-to-live information of the data message sent from the client by the security protection device and the second time-to-live information of the verification message. If the first time-to-live information is the same as the second time-to-live information, it is determined that the verification message is a keep-alive message; if they are different, the verification fails.

[0053] Here, the first time-to-live information of the data message can be represented by ttl. Here, the message randomly sent from the attacking client has randomness, and the session information may be the same as that of the test message. Therefore, in order to further improve security protection, the first time-to-live information and the second time-to-live information can be set. Note that since the attacking client sends messages randomly, the ttl of each message sent from the attacking client is different.

[0054] Optionally, by a setting method, the specific steps to determine whether the verification message is a keep-alive message are as follows: determine the setting method of the verification message by the security protection device. If the setting method of the verification message is only the ACK setting, the verification passes; if the setting method of the verification message is not only the ACK setting, the verification fails.

[0055] Here, by setting the setting method of the verification message to only the ACK setting, it can be ensured that the security protection device receives the verification message.

[0056] Optionally, based on whether the payload data is carried or not, the specific steps for determining whether the verification message is a keep-alive message are as follows: The security protection device determines whether the payload data is carried in the verification message. If no payload data is carried in the verification message, the verification passes; if payload data is carried in the verification message, the verification fails.

[0057] Here, by setting the verification message not to carry the payload data, it is possible to avoid the verification message interfering with the original data of the client.

[0058] Optionally, based on the positive response number, the specific steps for determining whether the verification message is a keep-alive message are as follows: The security protection device determines the positive response number of the verification message. If the positive response number of the verification message is equal to the sequence number of the test message plus 1, the verification passes; if not, the verification fails.

[0059] Here, when the positive response number of the verification message is equal to the sequence number of the test message plus 1, it can be ensured that the client has received the previous test message normally.

[0060] Optionally, based on the sequence number, the specific steps for determining whether the verification message is a keep-alive message are as follows: The security protection device determines the sequence number of the data message sent from the client, the length value of the payload data, and the sequence number of the verification message. If the sequence number of the verification message is equal to the sum of the sequence number of the data message sent from the client and the length value of the payload data, the verification passes; if not, the verification fails.

[0061] Here, when the sequence number of the verification message is equal to the sum of the sequence number of the data message sent from the client and the length value of the payload data, it can be ensured that the data message sent from the client is the payload and not an attack message.

[0062] It should be supplemented that verification only needs to be performed once for the same client. Accordingly, when the method passes the verification, it includes the steps of associating the first IP address information of the client with the first time-to-live information of the data message and adding it to the white list, determining the second IP address information of the client corresponding to the new data message and the third time-to-live information of the new data message in response to receiving the new data message, and directly sending the new data message to the corresponding destination server when the same first IP address information as the second IP address information exists in the white list and the first time-to-live information associated with the first IP address information is the same as the third time-to-live information.

[0063] Embodiments of the present disclosure include steps of: detecting, by a security detection device, whether a destination server corresponding to a data message is under a network attack in response to receiving the data message sent from a client; when detecting that the destination server is under a network attack, guiding the data message to a security protection device and triggering the client to return a verification message to the security protection device by sending, by the security protection device, a test message to the client, where a sequence number of the test message is located outside a sliding window of the client; verifying, by the security protection device, the verification message returned from the client, and when the verification passes, determining that the client is a legitimate client and sending the data message to the destination server, and when the verification fails, determining that the client is an attacking client and discarding the data message. In an embodiment of the present application, when the destination server is under a network attack, the security protection device can send a test message to the client instead of the server, the sequence number of the test message is located outside the sliding window of the client, the client can be triggered to return a verification message, and thus the security protection device verifies the verification message, further determines whether the client is legitimate, and in the process of verifying the verification message by the security protection device, it is not necessary to stop the network connection between the server and the client, and the quality of the network connection in the network security protection process can be improved, so the user experience is improved.

[0064] FIG. 6 is a structural block diagram of a data processing apparatus provided by an embodiment of the present disclosure. The data processing apparatus is applied to a network protection system, and the network protection system includes a security detection device and a security protection device. Referring to FIG. 6, the apparatus includes a detection module 601, a transmission module 602, and a verification module 603.

[0065] Here, in response to receiving the data message sent from the client, the detection module 601 is used to detect whether the destination server corresponding to the data message is under a network attack by the security detection device. When the transmission module 602 detects that the destination server is under a network attack, it guides the data message to the security protection device and triggers the client to return a verification message to the security protection device. For this purpose, it is used by the security protection device to send a test message to the client, where the sequence number of the test message is located outside the sliding window of the client. The verification module 603 verifies the verification message returned from the client by the security protection device. If the verification passes, it determines that the client is a legitimate client and sends the data message to the destination server. If the verification fails, it determines that the client is an attacking client and discards the data message.

[0066] According to one or more embodiments of the present disclosure, the device further includes a message generation module for determining the positive response number of the data message sent from the client, determining the sequence number of the test message as a value obtained by subtracting a predetermined value from the positive response number of the data message, and / or determining the first session information of the data message sent from the client, including the source port, destination port, source address, destination address, and protocol type, synchronizing the second session information of the test message with the first session information, and / or setting the setting method of the test message to only the ACK setting, and / or setting the test message so that no payload data is carried.

[0067] According to one or more embodiments of the present disclosure, the step of the verification module 603 verifying the verification message returned from the client by the security protection device specifically includes: obtaining the message information of the verification message; and determining, based on the message information of the verification message by the security protection device, whether the verification message is a keep-alive message. If so, the verification passes; otherwise, the verification fails.

[0068] According to one or more embodiments of the present disclosure, the message information of the verification message includes one or more of session information, time-to-live information, setting method, whether it carries payload data, positive response number, and sequence number. Accordingly, the step of the verification module 603 determining, based on the message information of the verification message by the security protection device, whether the verification message is a keep-alive message specifically includes: determining, based on at least one piece of message information of the verification message by the security protection device, whether the verification message is a keep-alive message.

[0069] According to one or more embodiments of the present disclosure, the network protection system further includes a control center device. The step of the transmission module 602 guiding the data message to the security protection device specifically includes: the security detection device transmitting attack warning information to the control center device. In response to receiving the attack warning information, the control center device is used to transmit a protection command to the security protection device, where the protection command carries the IP address information of the destination server corresponding to the data message; and in response to receiving the protection command, the security protection device determines the routing device corresponding to the IP address information of the destination server, and the routing device guides the data message to the security protection device.

[0070] According to one or more embodiments of the present disclosure, in the process where the detection module 601 detects whether the destination server corresponding to the data message is under a network attack by the security detection device, specifically, the steps include: detecting, by the security detection device, the number of messages, the number of data packets, and the number of connected clients of the destination server corresponding to the data message; determining that the destination server is under a network attack when the number of messages is greater than a first predetermined threshold, and / or the number of data packets is greater than a second predetermined threshold, and / or the number of connected clients is greater than a third predetermined threshold; and determining that the destination server is not under a network attack when the number of messages is less than or equal to the first predetermined threshold, the number of data packets is less than or equal to the second predetermined threshold, and the number of connected clients is less than or equal to the third predetermined threshold.

[0071] According to one or more embodiments of the present disclosure, the device further includes an additional module. When passing the verification, the additional module associates the first IP address information of the client with the first time-to-live information of the data message, adds it to the whitelist, determines the second IP address information of the client corresponding to the new data message and the third time-to-live information of the new data message in response to receiving the new data message, and is used to directly send the new data message to the corresponding destination server when the same first IP address information as the second IP address information exists in the whitelist and the first time-to-live information associated with the first IP address information is the same as the third time-to-live information.

[0072] According to one or more embodiments of the present disclosure, the device further includes a discard module, and when the discard module does not receive a verification message returned from the client within a predetermined time, the security protection device determines that the client is an attacking client, and is used to discard the data message.

[0073] According to one or more embodiments of the present disclosure, the network protection system further includes an optical splitter. In response to the detection module 601 receiving a data message sent from a client, the step of detecting by the security detection device whether the destination server corresponding to the data message is under a network attack specifically includes: in response to receiving a data message sent from a client, copying the data message by the optical splitter, sending the copied data message to the security detection device, and including the step of detecting by the security detection device whether the destination server corresponding to the data message is under a network attack. When the detection module 601 detects that the destination server is not under a network attack, the detection module 601 is further used to send the data message to the destination server.

[0074] Here, the detection module 601, the transmission module 602, and the verification module 603 are connected in sequence. The data processing device provided by this embodiment can execute the technical solution means of the above method embodiment, and its realization principle and technical effect are similar, and this embodiment will not be described in detail here.

[0075] FIG. 7 is a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present disclosure. Referring to FIG. 7, the electronic device 700 may be a terminal device or a server. Here, the terminal device may include, but is not limited to, mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, personal digital assistants (abbreviated as PDAs), tablet computers (abbreviated as PADs), portable media players (abbreviated as PMPs), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. The electronic device shown in FIG. 7 is only an example and does not limit the functions and usage scope of the embodiments of the present disclosure at all.

[0076] As shown in FIG. 7, the electronic device 700 may include a processing device (e.g., a central processing unit, an image processing device, etc.) 701, and can execute various appropriate operations and processes based on a program stored in a read-only memory (abbreviated as ROM) 702 or a program loaded from a storage device 708 into a random access memory (abbreviated as RAM) 703. Various programs and data required to operate the electronic device 700 are further stored in the RAM 703. The processing device 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0077] Generally, devices such as an input device 706 including a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc., an output device 707 including a liquid crystal display (abbreviated as LCD), a speaker, a vibrator, etc., a storage device 708 including a magnetic tape, a hard disk, etc., and a communication device 709 can be connected to the I / O interface 705. The communication device 709 can enable the electronic device 700 to communicate with other devices wirelessly or wiredly to exchange data. Although FIG. 7 shows an electronic device 700 having various devices, it should be understood that it is not required to implement or include all the shown devices. More or fewer devices may alternatively be implemented or included.

[0078] In particular, according to an embodiment of the present disclosure, the process described with reference to the above flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product including a computer program held in a computer-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network by the communication device 709, or installed from the storage device 708, or installed from the ROM 702. When the computer program is executed by the processing device 701, the above functions limited to the method of the embodiment of the present disclosure are executed.

[0079] Note that the computer-readable medium described in the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above two. The computer-readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above, but is not limited thereto. More specific examples of the computer-readable storage medium may include an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above, but is not limited thereto. In the present disclosure, the computer-readable storage medium may be any tangible medium that includes or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take various forms, including electromagnetic signals, optical signals, or any suitable combination of the above, but is not limited thereto. The computer-readable signal medium may be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium may transmit, propagate, or transmit a program used by or in combination with an instruction execution system, apparatus, or device. The program code included in the computer-readable medium can be transmitted through any suitable medium, and the above medium includes, but is not limited to, electric wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0080] The above computer-readable medium may be included in the above electronic device or may exist independently without being incorporated into the electronic device.

[0081] One or more programs are carried on the computer-readable medium, and when the one or more programs are executed by the electronic device, the electronic device is caused to execute the method shown in the above embodiment.

[0082] Computer program code for performing the operations of the present disclosure can be compiled in one or more programming languages or combinations thereof, and the programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user computer via any type of network including a Local Area Network (LAN) or a Wide Area Network (WAN), or may be connected to an external computer (for example, connected via the Internet using an Internet service provider).

[0083] Flowcharts and block diagrams in the drawings illustrate the architectures, functions, and operations achievable by systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram can represent a module, program segment, or portion of code that includes one or more executable instructions for implementing a given logical function. Note that in some alternative implementations, the functions assigned to the blocks may be implemented in an order different from the order shown in the drawings. For example, two consecutively shown blocks may actually be executed substantially in parallel, or depending on the functions, may be executed in the reverse order. Note that each block in the block diagram and / or flowchart diagram, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing a given function or operation, or may be implemented by a combination of dedicated hardware and computer instructions.

[0084] The units described in the embodiments of the present disclosure may be implemented in the form of software or in the form of hardware. Here, the name of the unit does not limit the unit itself in some cases. For example, the first acquisition unit may be described as "a unit that acquires at least two Internet protocol addresses".

[0085] The functions described above in this specification can be executed at least partially by one or more hardware logic components. For example, without limitation, typical types of hardware logic components that can be used include field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on chips (SOCs), complex programmable logic circuits (CPLDs), and the like.

[0086] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can embody or store a program used in or coupled to an instruction execution system, apparatus, or device. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of the machine-readable storage medium include electrical connections by one or more leads, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0087] In a first aspect, according to one or more embodiments of the present disclosure, there is provided a data processing method applied to a network protection system including a security detection device and a security protection device, the method comprising: detecting, by the security detection device, whether a destination server corresponding to the data message is under a network attack in response to receiving the data message sent from a client; when it is detected that the destination server is under a network attack, guiding the data message to the security protection device, and transmitting, by the security protection device, a test message with a sequence number located outside a sliding window of the client to the client to trigger the client to return a verification message to the security protection device; Verify the verification message returned from the client by the security protection device. If the verification passes, determine that the client is a legitimate client, send the data message to the destination server. If the verification fails, determine that the client is an attacking client and discard the data message. Provide a data processing method including the above steps.

[0088] According to one or more embodiments of the present disclosure, before the security protection device sends a test message to the client, determine the positive response number of the data message sent from the client, and determine the sequence number of the test message as a value obtained by subtracting a predetermined value from the positive response number of the data message, and / or determine the first session information of the data message sent from the client, including the source port, destination port, source address, destination address, and protocol type, and synchronize the second session information of the test message with the first session information, and / or set the setting method of the test message to only the ACK set, and / or further include the step of setting the test message so that no payload data is carried.

[0089] According to one or more embodiments of the present disclosure, the step of verifying the verification message returned from the client by the security protection device includes obtaining the message information of the verification message, and determining whether the verification message is a keep-alive message based on the message information of the verification message by the security protection device. If so, the verification passes. If not, the verification fails.

[0090] According to one or more embodiments of the present disclosure, the message information of the verification message includes one or more of session information, time-to-live information, setting method, whether it carries payload data, positive response number, and sequence number. Accordingly, the step of the security protection device determining whether the verification message is a keep-alive message based on the message information of the verification message includes the step of the security protection device determining whether the verification message is a keep-alive message based on at least one piece of message information of the verification message.

[0091] According to one or more embodiments of the present disclosure, the network protection system further includes a control center device. The step of guiding the data message to the security protection device includes the step of the security detection device sending attack warning information to the control center device. The control center device is used to send a protection command to the security protection device in response to receiving the attack warning information. Here, the protection command carries the IP address information of the destination server corresponding to the data message. In response to receiving the protection command, the security protection device determines a routing device corresponding to the IP address information of the destination server, and the routing device guides the data message to the security protection device.

[0092] According to one or more embodiments of the present disclosure, here, the process of detecting whether the destination server corresponding to the data message is under a network attack by the security detection device includes: detecting, by the security detection device, the number of messages, the number of data packets, and the number of connected clients of the destination server corresponding to the data message; and when the number of messages is greater than a first predetermined threshold, and / or the number of data packets is greater than a second predetermined threshold, and / or the number of connected clients is greater than a third predetermined threshold, determining that the destination server is under a network attack; and when the number of messages is less than or equal to the first predetermined threshold, the number of data packets is less than or equal to the second predetermined threshold, and the number of connected clients is less than or equal to the third predetermined threshold, determining that the destination server is not under a network attack.

[0093] According to one or more embodiments of the present disclosure, if the verification passes, associating the first IP address information of the client with the first time-to-live information of the data message and adding it to the whitelist; in response to receiving a new data message, determining the second IP address information of the client corresponding to the new data message and the third time-to-live information of the new data message; and when the same first IP address information as the second IP address information exists in the whitelist and the first time-to-live information associated with the first IP address information is the same as the third time-to-live information, directly sending the new data message to the corresponding destination server.

[0094] According to one or more embodiments of the present disclosure, the method further includes: when the security protection device does not receive a verification message returned from the client within a predetermined time, determining that the client is an attacking client and discarding the data message.

[0095] According to one or more embodiments of the present disclosure, the network protection system further includes an optical splitter, and accordingly, in response to receiving the data message sent from the client, the step of detecting whether the destination server corresponding to the data message is under a network attack by the security detection device includes, in response to receiving the data message sent from the client, copying the data message by the optical splitter, sending the copied data message to the security detection device, and including the step of detecting whether the destination server corresponding to the data message is under a network attack by the security detection device. The method further includes the step of sending the data message sent from the client to the destination server when it is detected that the destination server is not under a network attack.

[0096] According to one or more embodiments of the present disclosure, when it is detected that the destination server is not under a network attack, the method further includes the step of sending the data message to the destination server.

[0097] In a second aspect, according to one or more embodiments of the present disclosure, a data processing device applied to a network protection system including a security detection device and a security protection device, a detection module for detecting whether the destination server corresponding to the data message is under a network attack by the security detection device in response to receiving the data message sent from the client; a transmission module for sending, by the security protection device, a test message with a sequence number located outside the sliding window of the client to the client in order to guide the data message to the security protection device and trigger the client to return a verification message to the security protection device when it is detected that the destination server is under a network attack; Verify the verification message returned from the client by the security protection device. If the verification passes, determine that the client is a legitimate client, and send the data message to the destination server. If the verification fails, determine that the client is an attacking client, and provide a verification module for discarding the data message, including a data processing device.

[0098] According to one or more embodiments of the present disclosure, the device determines an affirmative response number of the data message sent from the client, determines the sequence number of the test message as a value obtained by subtracting a predetermined value from the affirmative response number of the data message, and / or determines first session information of the data message sent from the client, including the source port, destination port, source address, destination address, and protocol type, synchronizes the second session information of the test message with the first session information, and / or sets the setting method of the test message to only the ACK set, and / or further includes a message generation module for setting so that no payload data is carried in the test message.

[0099] According to one or more embodiments of the present disclosure, the step of the verification module verifying the verification message returned from the client by the security protection device specifically includes the step of obtaining the message information of the verification message, and determining whether the verification message is a keep-alive message based on the message information of the verification message by the security protection device. If so, the verification passes; otherwise, the verification fails.

[0100] According to one or more embodiments of the present disclosure, the message information of the verification message includes one or more of session information, time-to-live information, setting method, whether it carries payload data, positive response number, and sequence number. Accordingly, the step in which the verification module determines whether the verification message is a keep-alive message based on the message information of the verification message by the security protection device specifically includes the step of determining whether the verification message is a keep-alive message based on at least one piece of message information of the verification message by the security protection device.

[0101] According to one or more embodiments of the present disclosure, the network protection system further includes a control center device. The step in which the transmission module guides the data message to the security protection device specifically includes the step of the security detection device transmitting attack warning information to the control center device. The control center device is used to transmit a protection command to the security protection device in response to receiving the attack warning information. Here, the protection command carries IP address information of the destination server corresponding to the data message, and the step in which the security protection device determines a routing device corresponding to the IP address information of the destination server in response to receiving the protection command, and the routing device guides the data message to the security protection device.

[0102] According to one or more embodiments of the present disclosure, the process in which the detection module detects whether the destination server corresponding to the data message is under a network attack by the security detection device specifically includes: the step of detecting, by the security detection device, the number of messages, the number of data packets, and the number of connected clients of the destination server corresponding to the data message; when the number of messages is greater than a first predetermined threshold, and / or the number of data packets is greater than a second predetermined threshold, and / or the number of connected clients is greater than a third predetermined threshold, determining that the destination server is under a network attack; and when the number of messages is less than or equal to the first predetermined threshold, the number of data packets is less than or equal to the second predetermined threshold, and the number of connected clients is less than or equal to the third predetermined threshold, determining that the destination server is not under a network attack.

[0103] According to one or more embodiments of the present disclosure, the device further includes an additional module. When passing the verification, the additional module associates the first IP address information of the client with the first time-to-live information of the data message, adds it to the whitelist, and in response to receiving a new data message, determines the second IP address information of the client corresponding to the new data message and the third time-to-live information of the new data message. When the same first IP address information as the second IP address information exists in the whitelist and the first time-to-live information associated with the first IP address information is the same as the third time-to-live information, it is used to directly send the new data message to the corresponding destination server.

[0104] According to one or more embodiments of the present disclosure, the device further includes a discard module. When not receiving the verification message returned by the client within a predetermined time, the discard module determines that the client is an attack client by the security protection device and is used to discard the data message.

[0105] According to one or more embodiments of the present disclosure, the network protection system further includes an optical splitter. In response to the detection module receiving a data message sent from a client, the step of detecting whether the destination server corresponding to the data message is under a network attack by the security detection device specifically includes: in response to receiving the data message sent from the client, copying the data message by the optical splitter, sending the copied data message to the security detection device, and including the step of detecting whether the destination server corresponding to the data message is under a network attack by the security detection device.

[0106] When the detection module detects that the destination server is not under a network attack, it is further used to send the data message to the destination server.

[0107] In a third aspect, according to one or more embodiments of the present disclosure, there is provided an electronic device including a processor and a memory communicatively connected to the processor. The memory stores computer-executable instructions. The processor executes the computer-executable instructions stored in the memory to provide an electronic device that realizes the data processing method described in the first aspect and various possible designs of the first aspect.

[0108] In a fourth aspect, according to one or more embodiments of the present disclosure, there is provided a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, realize the data processing method described in the first aspect and various possible designs of the first aspect.

[0109] In a fifth aspect, an embodiment of the present disclosure provides a computer program product including a computer program that, when executed by a processor, implements the data processing method described in the first aspect and various possible designs of the first aspect.

[0110] The above description is only an explanation of the preferred embodiments of the present disclosure and the technical principles used. As understood by those skilled in the art, the disclosure scope involved in the present disclosure is not limited to the technical solutions formed by specific combinations of the above technical features. Without departing from the concept of the above disclosure, other technical solutions formed by arbitrarily combining the above technical features or their equivalent features should also be covered simultaneously. For example, technical solutions formed by mutually replacing the above features with technical features having similar functions disclosed in the present disclosure (but not limited thereto) should be covered.

[0111] Also, although each operation has been described in a specific order, this should not be understood as requiring that these operations be executed in the specific order or sequential order shown. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although the above considerations include multiple specific implementation details, these should not be construed as limitations on the scope of the present disclosure. Some features described in the context of individual embodiments may be further combined and implemented in a single embodiment. Conversely, various features described in the context of a single embodiment may be implemented in multiple embodiments individually or in any suitable sub-combination.

[0112] Although the subject matter has been described using language specific to structural features and / or methodological logical operations, it should be understood that the subject matter defined in the appended claims is not limited to the specific features or operations described above. On the contrary, the specific features and operations described above are merely exemplary forms for implementing the claims.

Claims

1. A data processing method applied to a network protection system including a security detection device and a security protection device, comprising: responding to receiving a data message sent from a client, detecting by the security detection device whether a destination server corresponding to the data message is under a network attack; when the security detection device detects that the destination server is under a network attack, guiding the data message to a security protection device, and in order to trigger the client to return a verification message to the security protection device, sending, by the security protection device, a test message whose sequence number is located outside the sliding window of the client to the client; verifying the verification message returned from the client by the security protection device, and if the verification passes, determining that the client is a legitimate client and sending the data message to the destination server, and if the verification fails, determining that the client is an attacking client and discarding the data message; comprising: the step of verifying the verification message returned from the client by the security protection device as described above: obtaining message information of the verification message; determining, based on the message information of the verification message by the security protection device, whether the verification message is a keep-alive message, and if so, passing the verification, and if not, failing the verification. A data processing method characterized by including this.

2. Before the security protection device sends a test message to the client as described above, determining an affirmative response number of the data message sent from the client, and determining the sequence number of the test message as a value obtained by subtracting a predetermined value from the affirmative response number of the data message, and / or Determining first session information of the data message sent from the client, including a source port, a destination port, a source address, a destination address, and a protocol type, and synchronizing second session information of the test message as the first session information, and / or, Setting the setting method of the test message to only the ACK set, and / or, The data processing method according to claim 1, further comprising the step of setting so that no payload data is carried in the test message.

3. The message information of the verification message includes one or more of session information, time-to-live information, setting method, whether payload data is carried, an affirmative response number, and a sequence number. Accordingly, the step of determining whether the verification message is a keep-alive message based on the message information of the verification message by the security protection device is The data processing method according to claim 1, comprising the step of determining whether the verification message is a keep-alive message based on at least one message information of the verification message by the security protection device.

4. The network protection system further includes a control center device, and the step of guiding the data message to the security protection device is The step of transmitting attack warning information to the control center device by the security detection device, wherein the control center device is used to transmit a protection command to the security protection device in response to receiving the attack warning information, and the protection command carries IP address information of a destination server corresponding to the data message, and The step of determining a routing device corresponding to the IP address information of the destination server in response to the security protection device receiving the protection command, and guiding the data message to the security protection device by the routing device. The data processing method according to claim 1 is characterized by including the above steps.

5. The process of detecting by the security detection device whether the destination server corresponding to the data message is under a network attack is The step of detecting, by the security detection device, the number of messages, the number of data packets, and the number of connected clients of the destination server corresponding to the data message; The step of determining that the destination server is under a network attack when the number of messages is greater than a first predetermined threshold, and / or the number of data packets is greater than a second predetermined threshold, and / or the number of connected clients is greater than a third predetermined threshold; The step of determining that the destination server is not under a network attack when the number of messages is less than or equal to the first predetermined threshold, the number of data packets is less than or equal to the second predetermined threshold, and the number of connected clients is less than or equal to the third predetermined threshold, wherein the data processing method according to claim 1 is characterized by including the above steps.

6. When passing the verification, the step of associating the first IP address information of the client with the first time-to-live information of the data message and adding it to the whitelist; In response to receiving a new data message, the step of determining the second IP address information of the client corresponding to the new data message and the third time-to-live information of the new data message; The step of directly transmitting the new data message to the corresponding destination server when the same first IP address information as the second IP address information exists in the whitelist and the first time-to-live information associated with the first IP address information is the same as the third time-to-live information, wherein the data processing method according to claim 1 is further characterized by including the above steps.

7. The data processing method according to any one of claims 1 to 6, further characterized by including the step of determining, by the security protection device, that the client is an attacking client and discarding the data message when the verification message returned from the client within a predetermined time has not been received.

8. The network protection system further includes an optical splitter, Accordingly, in response to receiving the data message transmitted from the client, the step of detecting, by the security detection device, whether the destination server corresponding to the data message is under a network attack is In response to receiving a data message sent from a client, copying the data message by an optical splitter, sending the copied data message to a security detection device, and including a step of detecting by the security detection device whether a destination server corresponding to the data message is under a network attack. The method further includes a step of sending the data message sent from the client to the destination server when it is detected that the destination server is not under a network attack, and is characterized in that it is the data processing method according to any one of claims 1 to 6.

9. An electronic device, comprising a processor and a memory communicatively connected to the processor. The memory stores computer-executable instructions. The processor is characterized in that it realizes the data processing method according to any one of claims 1 to 6 by executing the computer-executable instructions stored in the memory, and is an electronic device.

10. A computer-readable storage medium, characterized in that it stores computer-executable instructions that realize the data processing method according to any one of claims 1 to 6 when executed by a processor.

11. A computer program, characterized in that it realizes the data processing method according to any one of claims 1 to 6 when executed by a processor.

Citation Information

Patent Citations

  • Method and Apparatus for Probabilistic Matching to Authenticate Hosts During Distributed Denial of Service Attack

    US20130031605A1