Attack defense method and apparatus
By implementing two judgment methods in network devices, the legality of the control packets is determined, and the problem of high firewall resource consumption when protecting stateful protocol attacks in the prior art is solved, and accurate defense against stateful protocol attacks and security improvement of network devices is achieved.
Patent Information
- Application Number
- PCT/CN2024/126464
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-31
- Filing Date
- 2024-10-22
- Publication Date
- 2025-05-08
AI Technical Summary
In the prior art, when protecting against attacks of stateful protocols, the firewall needs to maintain the connection status with the server and the host, and perform TCP serial number conversion when forwarding data packets, resulting in huge overhead and making it difficult to use the network processor in network equipment for protection.
By implementing two judgments in a network device, first, it is determined to be a pre-legal message based on the status of the first flow identification and control message, and then it is determined to be a legal message based on the first flow identification and serial number, and it is sent to the CPU only if the legal message is, otherwise it will be discarded.
It realizes accurate identification and discarding of attack packets of stateful protocols, reduces CPU identification and processing resource consumption, avoids CPU paralysis, and improves the security and reliability of network devices.
Smart Images

Figure CN2024126464_08052025_PF_FP_ABST
Abstract
Description
Attack defense method and device
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on October 31, 2023, with application number 202311444266.0 and invention name “A Method and Device for Attack Defense”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of security technology, and in particular to an attack defense method and device. Background Art
[0003] As network scale increases, stateful protocol attacks, such as distributed denial-of-service (DDoS), are becoming more frequent, diverse, and powerful, posing significant challenges to network security. Attackers often use botnets or forged source addresses to send large numbers of packets to network devices. These packets are inadequate for the central processing unit (CPU) of a network device, causing it to become overwhelmed. Therefore, protecting against stateful protocol attacks is crucial for network devices.
[0004] Currently, to protect against stateful protocol attacks, a firewall's synchronize (SYN) proxy technology is used. Specifically, a firewall is deployed between the server and the host. The firewall intercepts the first SYN packet sent by the server when establishing a connection and replies with a SYN-ACK packet on behalf of the host. After receiving the ACK packet from the server, the firewall verifies the server's authenticity and legitimacy, thereby performing a handshake with the host on behalf of the server. However, the connection between the server and the host established using this SYN proxy technology, as well as all interactions between the server and the host, must be forwarded through the firewall. Because the firewall's Transmission Control Protocol (TCP) sequence number differs from that of the server and host, the firewall must perform TCP sequence number conversion when forwarding data packets.
[0005] It can be seen that in this protection method, the firewall needs to maintain the connection status with the server and the host, and needs to convert the TCP sequence number when forwarding data packets. The overhead is huge and it is not suitable for the network processor (Network Processing Unit, NP) in the network device to protect against stateful protocol attacks.
[0006] Summary of the Invention
[0007] Based on this, the present application provides an attack defense method and apparatus, in which the network device determines whether the received control message is legal through two judgments, thereby achieving effective protection against attacks on stateful protocols.
[0008] In the first aspect, the present application provides an attack defense method, which is applied to a network device. The method may include, for example: after the network device receives a first control message including a first sequence number, first, based on the first flow identifier and the state of the first control message, determining whether the first control message is a pre-legal message, and then, if it is determined that the first control message is a pre-legal message, determining whether the pre-legal first control message is a legal message based on the first flow identifier and the first sequence number. In this way, the network device can perform a "two-level judgment" on the received control message to analyze whether the control message is a legal message. If the control message is a legal message, the NP in the network device will send the control message to the CPU of the network device. Once it is determined that the control message is not a pre-legal message or is not a legal message, the control message will be discarded to achieve accurate identification of attack messages of stateful protocols, thereby effectively defending against attacks on stateful protocols.
[0009] It is understood that the network device's determination that the first control message is a pre-validated message is a preliminary assessment of the validity of the first control message, which can be considered an intermediate assessment of the validity. Based on the first flow identifier and the status of the first control message, the network device can determine whether the first control message belongs to the first flow indicated by the first flow identifier.
[0010] In some implementations, taking the case where the basis of the "two-level judgment" is carried in the form of a flow table as an example, the "one-time judgment" in the "two-level judgment" means that the network device determines that the first control message is a pre-legal message based on the first flow identifier and the status of the first control message. For example, it may include: the network device obtains the first flow identifier of the first control message and the status of the first control message, and the first flow identifier is used to indicate the first flow to which the first control message belongs; if the first flow identifier does not exist in the first flow table, and the status of the first control message belongs to the preset state, the network device determines that the first control message is a pre-legal message. The first flow table is used to record the flow identifier of the control message received in the preset state, and the preset state is the state corresponding to the TCP handshake message received by the network device. The "second judgment" in the "two-level judgment" means that the network device determines that the pre-legal message is a legal message based on the first flow identifier and the first sequence number. For example, it may include: if the first flow identifier exists in the first flow table, and the correspondence between the first flow identifier and the second sequence number exists in the second flow table, and the state of the first control message does not belong to the preset state, then the network device verifies the first sequence number based on the second sequence number, and in response to the verification being passed, determines that the first control message is a legal message. Among them, the TCP handshake message may include, for example, a SYN message, a SYN-ACK message, or an ACK message. In this way, through the first flow table and the second flow table, the method provided in the present application can be implemented to ensure efficient and accurate defense against attack messages of stateful protocols and improve the security of network devices.
[0011] As an example, the first flow table may be a hash table or a Bloom filter table, and the second flow table may be a hash table.
[0012] As an example, the network device verifies the first sequence number based on the second sequence number, which may include: first, the network device determines a sequence number range based on the second sequence number and a preset threshold; then, the network device determines whether the first sequence number falls within the sequence number range; if so, determines that the verification is successful; if not, determines that the verification is unsuccessful. The preset threshold may be, for example, the maximum allowable length of a preset number of messages. If the maximum allowable length of each message is 1500 bits and the preset number is 4, then the preset threshold may be 4*1500 bits = 6000 bits.
[0013] As another example, the network device verifies the first sequence number based on the second sequence number, which may include: first, the network device calculates the difference between the second sequence number and the first sequence number; then, the network device determines whether the difference is less than or equal to a preset length range; if so, determines that the verification is successful; if not, determines that the verification is unsuccessful. The preset length range may be, for example, a preset multiple of the maximum message length. For example, if the maximum allowable length of each message is 1500 bits and the preset multiple is 4, the preset length range may be equal to (1500*4) bits = 6000 bits.
[0014] As an example, after the network device determines that the first control message is a legal message, the method may also include: the network device updates the second flow table based on the first sequence number, and the updated second flow table includes the correspondence between the first flow identifier and the first sequence number. It should be noted that the network device updates the correspondence of each legal message in the second flow table; or, for the same flow, the network device may update the correspondence related to the flow in the second flow table once every M legal messages, where M is less than or equal to the preset number corresponding to the preset threshold, or M is less than or equal to a preset multiple. In this way, it can be ensured that the verification of whether the sequence number carried in the received control message is legal based on the sequence number in the second flow table is accurate.
[0015] As an example, after the network device determines that the first control message is a legitimate message, the method may further include: the NP of the network device sending the first control message to the CPU of the network device; and the CPU of the network device processing the first control message. If the method provided in this application determines that the first control message is not a legitimate message, the NP of the network device discards the first control message and does not send the first control message to the CPU of the network device. This conserves CPU resources for identifying and processing the first control message, avoids CPU paralysis due to receiving too many attack messages, and improves the reliability of the network device.
[0016] As an example, the method may further include: if the network device receives a second control message belonging to the first flow and the first flow identifier exists in the first flow table and the status of the second control message is in a preset state, the network device may determine that the second control message is not a legitimate message and discard the second control message. In this way, based on the first flow table and the status of the received control message, the network device can determine whether the control message is an attack message. For example, a second control message that has already been received and is in the state corresponding to a TCP handshake message may be directly determined as an attack message and not sent to the CPU, thereby preventing the CPU from crashing due to receiving a large number of attack messages disguised as TCP handshake messages.
[0017] As an example, the method may also include: the network device, for a received third control message, first obtains a second flow identifier of the third control message, where the second flow identifier is used to indicate the second flow to which the third control message belongs; then, if the second flow identifier does not exist in the first flow table and the state of the third control message belongs to the preset state, the network device records the second flow identifier in the first flow table. This facilitates the network device to determine whether other control messages subsequently received belonging to the second flow are pre-legalized messages based on the first flow table, thus preparing the network device for implementing the method provided in this application on control messages belonging to the second flow.
[0018] As an example, the method may further include: after the network device receives the fourth control message belonging to the second flow, if it determines that the TCP link establishment for the second flow is successful, the network device records the correspondence between the second flow identifier and the third sequence number carried by the fourth control message in the second flow table. This facilitates the network device to determine whether other control messages subsequently received belonging to the second flow are legitimate messages based on the second flow table, thereby preparing the network device for subsequently implementing the method provided in this application on control messages belonging to the second flow.
[0019] The successful TCP connection establishment may refer to a TCP connection being established between the network device and the peer device for the second flow. Specifically, this may include: after the network device sends a SYN packet to the peer device, it receives a SYN-ACK packet in response from the peer device, and then the network device sends an ACK packet to the peer device, thereby completing the TCP handshake between the network device and the peer device for the second flow; or after the peer device sends a SYN packet to the network device, the peer device receives a SYN-ACK packet in response from the network device, and then the peer device sends an ACK packet to the network device, thereby completing the TCP handshake between the network device and the peer device for the second flow. In one embodiment, when the CPU of the network device determines that the TCP connection establishment for the second flow is successful, it sends a notification message to the NP, notifying the NP of the successful TCP connection establishment for the second flow, so that the NP records the second flow identifier in the second flow table based on the notification message. In another embodiment, when the CPU of the network device determines that the TCP connection establishment for the second flow is successful, the CPU creates a second flow table including the second flow identifier and sends the second flow table to the NP. In this way, the second flow table of the NP includes the second flow identifier. Afterwards, if the NP of the network device receives a protocol message belonging to the second flow, the sequence number corresponding to the second flow identifier in the second flow table is refreshed based on the sequence number of the protocol message, and the subsequently received protocol messages are legally verified based on the corresponding relationship including the second flow identifier in the second flow table.
[0020] In a second aspect, the present application provides an attack defense device, applied to a network device, which may include: a receiving unit and a processing unit. The receiving unit is configured to receive a first control message, wherein the first control message includes a first sequence number; the processing unit is configured to determine, based on a first flow identifier and a status of the first control message, whether the first control message is a pre-legalized message; and the processing unit is further configured to determine, based on the first flow identifier and the first sequence number, whether the pre-legalized message is a legitimate message.
[0021] In some implementations, the processing unit is specifically configured to: obtain the first flow identifier of the first control message and the state of the first control message, where the first flow identifier is used to indicate the first flow to which the first control message belongs; if the first flow identifier does not exist in the first flow table and the state of the first control message belongs to a preset state, determine that the first control message is a pre-legal message, and the first flow table is used to record the flow identifier of the received control message in the preset state, where the preset state is the state corresponding to the TCP handshake message received by the network device;
[0022] The processing unit is specifically used to: if the first flow identifier exists in the first flow table, there is a correspondence between the first flow identifier and the second sequence number in the second flow table, and the state of the first control message does not belong to the preset state, then verify the first sequence number based on the second sequence number, and in response to the verification being passed, determine that the first control message is a legal message.
[0023] In some implementations, the processing unit is specifically configured to: determine a serial number range based on the second serial number and a preset threshold; and determine whether the first serial number belongs to the serial number range; if so, determine that the verification is passed; and if not, determine that the verification is failed.
[0024] In some implementations, the processing unit is specifically used to: calculate the difference between the second serial number and the first serial number; determine whether the difference is less than or equal to a preset length range, if so, determine that the verification is passed; if not, determine that the verification is failed.
[0025] In some implementations, the processing unit is further configured to: update the second flow table based on the first sequence number, wherein the updated second flow table includes a correspondence between the first flow identifier and the first sequence number.
[0026] In some implementations, the receiving unit is further used to: receive a second control message, where the second control message belongs to the first flow; the processing unit is further used to: if the first flow identifier exists in the first flow table and the status of the second control message belongs to the preset status, determine that the second control message is not a legal message and discard the second control message.
[0027] In some implementations, the receiving unit is further used to: receive a third control message; the processing unit is further used to: obtain a second flow identifier of the third control message, wherein the second flow identifier is used to indicate the second flow to which the third control message belongs, and if the second flow identifier does not exist in the first flow table and the status of the third control message belongs to the preset status, then the second flow identifier is recorded in the first flow table.
[0028] In some implementations, the receiving unit is further used to: receive a fourth control message, the fourth control message belongs to the second flow, and the fourth control message includes a third sequence number; the processing unit is further used to: if it is determined that the TCP link establishment for the second flow is successful, record the correspondence between the second flow identifier and the third sequence number in the second flow table.
[0029] In some implementations, the first flow table may be a hash table or a Bloom filter table, and the second flow table may be a hash table.
[0030] In some implementations, the TCP handshake message includes a SYN message, a SYN-ACK message, or an ACK message.
[0031] In some implementations, the NP in the device sends the first control message to the CPU in the device; and the CPU in the device processes the first control message.
[0032] It should be noted that the specific implementation method and technical effects achieved by the device provided in this application can be found in the method provided in the first aspect.
[0033] In a third aspect, the present application provides a network device, comprising an NP and a CPU, wherein the NP performs the method of the first aspect or any possible implementation of the first aspect. Optionally, the NP is further configured to send a first control message determined to be legitimate to the CPU; and the CPU is configured to process the first control message.
[0034] In a fourth aspect, the present application provides a network device, comprising a processor and a memory, the memory being used to store instructions or program codes, and the processor being used to call and run the instructions or program codes from the memory to execute the method in the first aspect or any possible implementation of the first aspect.
[0035] In a fifth aspect, the present application provides a storage medium comprising instructions, programs or codes, which, when executed on a processor, enables the processor to execute the method in the first aspect or any possible implementation of the first aspect.
[0036] In a sixth aspect, the present application provides a program product, which, when running on a processor, enables the processor to execute the method in the first aspect or any possible implementation of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] FIG1 is a schematic diagram of a possible applicable scenario in an embodiment of the present application;
[0038] FIG2 is a schematic diagram of possible situations in the scenario of FIG1 in an embodiment of the present application;
[0039] FIG3 is a flow chart of an attack defense method 100 according to an embodiment of the present application;
[0040] FIG4 is a schematic diagram of a first flow table in an embodiment of the present application;
[0041] FIG5 is a schematic structural diagram of an attack defense device 500 according to an embodiment of the present application;
[0042] FIG6 is a schematic structural diagram of a network device 600 according to an embodiment of the present application;
[0043] FIG7 is a schematic structural diagram of a network device 700 according to an embodiment of the present application;
[0044] FIG8 is a schematic structural diagram of another network device 800 in an embodiment of the present application. DETAILED DESCRIPTION
[0045] If a network device's network processing unit (NP) cannot accurately identify and discard attack packets from stateful protocols like DDoS, it will treat them as normal control packets and send them to the device's CPU. Because attack packets are often numerous and the CPU cannot process them, this can easily cause the CPU to crash. Therefore, it is crucial for the NP to effectively identify attack packets from stateful protocols.
[0046] Based on this, an attack defense method is provided in an embodiment of the present application. The method may include, for example: after a network device receives a first control message including a first sequence number, first, based on the first flow identifier and the state of the first control message, determining that the first control message is a pre-legal message; then, based on the first flow identifier and the first sequence number, determining that the first control message is a legal message. In this way, the network device can perform a "two-level judgment" on the received control message to analyze whether the control message is a legal message. If the control message is a legal message, the NP in the network device will send the control message to the CPU of the network device. Once it is determined that the control message is not a pre-legal message or a legal message, the control message will be discarded to achieve accurate identification of attack messages of stateful protocols, thereby effectively defending against attacks on stateful protocols.
[0047] It should be noted that, compared to recording the flow identifier and sequence number of each received control message, each newly received control message is identified as an attack message based on the sequence number carried by itself and compared with the recorded sequence number associated with the corresponding flow identifier. The "two-level judgment" in the embodiment of the present application is first based on the "primary judgment" to determine whether other control messages of the flow to which the control message belongs have been received by the network device, and the status of the control message is as expected. Thus, the control message is determined to be a preliminary legal (i.e., pre-legal) message, triggering the "secondary judgment". Otherwise, if it is determined that the control message is not a preliminary legal message, the control message can be directly discarded without entering the "secondary judgment"; for the case of entering the "secondary judgment", it is considered that the flow to which the control message belongs is a flow for which the connection has been established, and based on the flow identifier of the control message and the sequence number carried in the control message, the control message is determined to be a legal message. Among them, in the "first judgment", only the flow identifier of each received control message needs to be recorded, without the serial number, for the initial screening of the control messages received subsequently; for the flow with successful connection establishment, the flow identifier and serial number used for the "second judgment" are recorded to reconfirm the control messages that have passed the initial screening. This can save the storage and computing resources of network equipment to a certain extent, making the defense against attacks on stateful protocols more intelligent and accurate.
[0048] In the embodiment of the present application, the network device may be, for example, a switch, a router, or other device including at least an NP and a CPU. The embodiment of the present application may be implemented, for example, as an NP in a network device.
[0049] In the embodiment of the present application, control messages can be understood as a general term for protocol messages and TCP handshake messages. Among them, TCP handshake messages may include messages exchanged by network devices during the TCP handshake phase, for example, they may include: SYN messages, SYN-ACK messages or ACK messages. Protocol messages may refer to messages that require the CPU in the network device to perform control plane processing, for example, they may be messages related to the Border Gateway Protocol (BGP) routing protocol or messages related to the Interior Gateway Protocol (IGP) routing protocol. Network devices first need to exchange TCP handshake messages to establish a TCP connection, and then after the TCP connection is successfully established, they can exchange protocol messages to complete various protocol configurations.
[0050] In an embodiment of the present application, the flow identifier of the control message is used to uniquely identify the flow to which the control message belongs. The network device may process (e.g., perform a hash operation) all or part of the characteristics of the received control message (e.g., a five-tuple (i.e., source Internet Protocol (IP) address, destination IP address, source port number, destination port number, and transport protocol)) to obtain the flow identifier of the control message; alternatively, the control message may also carry the flow identifier, and the network device may directly obtain the flow identifier of the control message by parsing the received control message.
[0051] In the embodiment of the present application, the status of the control message can be indicated by a status flag of the control message. The status of the control message may include, but is not limited to, SYN, SYN-ACK, and ACK. When the status of the control message is not SYN, SYN-ACK, or ACK, it is considered that the control message is not a TCP handshake message, but a protocol message.
[0052] In the embodiment of the present application, the sequence number refers to a field carried in a message for tracking the byte range of message transmission to ensure that the order of loss and message transmission can be detected. If a message is lost or arrives at the destination out of order, the message can be retransmitted or the original order of the message can be restored based on the sequence number of the message. If the sequence number of message 1 transmitted by the network device is x, and the length of message 1 is y bits, then the sequence number of message 2 transmitted by the network device immediately after message 1 can be (x+y). In the embodiment of the present application, judging whether a control message is a legitimate message based on the sequence number can refer to verifying the sequence number 2 carried in the control message based on the sequence number 1 corresponding to the stream to which the control message belongs, which has been recorded. If the verification is successful, the control message is considered to be a legitimate message. Among them, the sequence number 1 can be the sequence number carried in other control messages belonging to the same stream as the control message received by the network device before the control message is received. The principle behind verifying sequence number 2 based on sequence number 1 is that the sequence numbers of control messages belonging to the same flow received by a network device should satisfy a certain numerical relationship. For example, a preset threshold is the sum of the lengths of a preset number (e.g., 4) of control messages of the maximum possible length (e.g., 1500 bits) (e.g., 4*1500 bits = 6000 bits). In this case, sequence number 1±6000 bits can be used as a reasonable sequence number range to determine whether sequence number 2 falls within (sequence number 1-6000 bits, sequence number 1+6000 bits). If so, verification is considered successful; otherwise, verification is considered unsuccessful. For another example, the difference between sequence numbers 1 and 2 can be calculated to determine whether the difference is less than or equal to a preset multiple (e.g., 4 times) of the maximum possible length of the control message (e.g., 1500 bits). If so, verification is considered successful; otherwise, verification is considered unsuccessful.
[0053] FIG1 is a schematic diagram of a scenario in which an embodiment of the present application may be applicable. Referring to FIG1 , the scenario may include: a network device 10 and a network device 20. Network device 10 may include at least an NP 11 and a CPU 12, and network device 20 may include at least an NP 21 and a CPU 22. NP 11 in network device 10 and NP 21 in network device 20 may both implement the method provided in the embodiment of the present application to implement attack defense against received control messages. The following description of the method provided in the embodiment of the present application is provided by way of example, using NP 21 in network device 20 as an example.
[0054] For example, referring to the scenario shown in FIG1 , assuming that the network device 10 initiates a TCP connection with the network device 20, then the normal interaction between the network device 10 and the network device 20 may include: S11, the network device 10 sends a SYN message 1 to the NP 21 of the network device 20; S12, the NP 21 determines that the flow identifier of the SYN message 1 is the flow identifier 1, and the flow table 1 does not include the flow identifier 1, so the NP 21 records the flow identifier 1 in the flow table 1; S13, the network device 20 sends a SYN-ACK message 1 to the network device 10; S14, the network device 10 sends an ACK message 1 to the NP 21 of the network device 20; S15, the NP 21 sends the ACK message 1 to the CPU 22, and the CPU 22 determines that the TCP link establishment between the network device 10 and the network device 20 regarding the flow 1 indicated by the flow identifier 1 is successful. Then, in one case, the CPU 22 sends a notification message to the NP 21, which is used to inform the NP In the example, CPU 22 establishes a TCP link for flow 1 successfully, so NP 21 records flow ID 1 in flow table 2 based on the notification message. Alternatively, CPU 22 establishes flow table 2 that includes flow ID 1 and sends flow table 2 to NP 21. In this way, flow ID 1 is included in flow table 2 of NP 21. Subsequently, if NP 21 receives a protocol packet belonging to flow 1, the sequence number corresponding to flow ID 1 in flow table 2 is updated based on the sequence number of the protocol packet. NP 21 then performs validation on subsequently received protocol packets based on the correspondence with flow ID 2 in flow table 2.
[0055] As an example, after S15, for a control message 1 transmitted from the network device 10 to the NP 21 of the network device 20 and belonging to the flow 1 indicated by the flow identifier 1, the attack defense process of the NP 21 may include: S16, the NP 21 determines that the flow identifier of the control message 1 is the flow identifier 1, the control message 1 carries the sequence number 2, and the state of the control message 1 is the state 1; S17, the NP 21 determines that both the flow table 1 and the flow table 2 include the flow identifier 1, and if the state 1 is SYN, SYN-ACK, or ACK, the control message 1 is determined to be an attack message, and thus, the NP 21 discards the control message 1 without sending the control message 1 to the CPU 22; if the state 1 is not SYN, SYN-ACK, or ACK, the control message 1 is determined to be a pre-legal message, and thus S18 is executed; S18, the NP NP 21 verifies sequence number 2 based on sequence number 1 according to the correspondence between flow identifier 1 and sequence number 1 included in flow table 2. If the verification succeeds, control message 1 is determined to be a legitimate message, and thus control message 1 is sent to CPU 22. If the verification fails, control message 1 is determined to be an attack message rather than a legitimate message, and thus NP 21 discards control message 1 without sending it to CPU 22.
[0056] As another example, referring to FIG2 , after S15 , for a control message 2 transmitted from network device 10 to NP 21 of network device 20 and belonging to flow 2 indicated by flow ID 2, NP 21's attack defense process may include: S21 , NP 21 determines that the flow ID of control message 2 is flow ID 2, that control message 2 carries sequence number 3, and that the state of control message 2 is state 2. Depending on the state 2, various attack defense processes may be described in S22 to S29 below. For case 1 where state 2 is SYN, see S22 to S23 below: S22 , NP 21 determines that flow table 1 does not include flow ID 2, determines that control message 2 is a pre-validated message, records flow ID 2 and the SYN state in flow table 1, and sends control message 2 to CPU 22. S23 , NP 21 determines that flow table 1 includes flow ID 2, determines that control message 2 is an attack message, and discards control message 2 without sending it to CPU 22. For the second case where state 2 is SYN-ACK, refer to the following S24 to S25: S24, NP 21 determines that flow table 1 does not include flow identifier 2, and then determines that control message 2 is not a pre-legal message but an attack message, so NP 21 discards control message 2 without sending the control message 2 to CPU 22, and NP 21 records flow identifier 2 and SYN-ACK state in flow table 1; S25, NP 21 determines that flow table 1 includes flow identifier 2, and then determines that control message 2 is a pre-legal message, so it determines whether the state corresponding to flow identifier 2 in flow table 1 is SYN-ACK. If so, it discards control message 2. If not, it continues to determine whether flow table 2 includes flow identifier 2. If so, it means that the TCP link for flow 2 has been successfully established, so NP 21 discards control message 2 without sending it to CPU 22 sends the control message 2. If it does not include it, it determines that the control message 2 is a legal message, adds the SYN-ACK state corresponding to the flow identifier 2 in the flow table 2, and sends the control message 2 to the CPU 22.For the third case where state 2 is ACK, refer to the following S26-S27: S26, NP 21 determines that flow table 1 does not include flow ID 2, and determines that control message 2 is not a pre-legal message but an attack message, so NP 21 discards control message 2 without sending the control message 2 to CPU 22, and NP 21 records flow ID 2 and ACK status in flow table 1; S27, NP 21 determines that flow table 1 includes flow ID 2, and determines that control message 2 is a pre-legal message, so it judges whether the state corresponding to flow ID 2 in flow table 1 is ACK, if so, discards control message 2, if not, continues to judge whether flow table 2 includes flow ID 2, if included, it means that the TCP link for flow 2 has been successfully established, so NP 21 discards control message 2 without sending the control message 2 to CPU 22, if not included, it determines that control message 2 is a legal message, adds the ACK state corresponding to flow ID 2 in flow table 2, and sends a message to CPU 22 sends the control message 2. For the fourth case where state 2 indicates that the control message 2 is a protocol message (i.e., state 2 is not SYN, SYN-ACK, or ACK), refer to the following S28-S29: S28, NP 21 determines that flow table 2 does not include flow ID 2, and therefore determines that control message 2 is not a legitimate message but an attack message. Therefore, NP 21 discards control message 2 and does not send the control message 2 to CPU 22. S29, NP 21 determines that flow table 2 includes flow ID 2, and then verifies sequence number 3 based on sequence number 4 corresponding to flow ID 2 included in flow table 2. If the verification succeeds, it determines that control message 2 is a legitimate message, and thus sends the control message 2 to CPU 22. If the verification fails, it determines that control message 2 is not a legitimate message but an attack message. Therefore, NP 21 discards control message 2 and does not send the control message 2 to CPU 22. Optionally, in S29, when it is determined that the control message 2 is a legitimate message, the sequence number 4 corresponding to the flow identifier 2 in the flow table 2 can also be updated to the sequence number 3 carried by the control message 2, so as to achieve more accurate attack defense against subsequent protocol messages.
[0057] It should be noted that in the embodiment shown in Figure 2, the status of the latest TCP handshake message received by each flow in the TCP handshake phase is recorded in flow table 1, making the attack defense process more secure and preventing attackers from creating TCP handshake messages in various states as attack messages to carry out attacks.
[0058] It should be noted that the above-mentioned "two-level judgment" in the method provided in the embodiment of the present application is based on flow table 1 and flow table 2 as an example for explanation, wherein flow table 1 may include the flow identifiers of all control messages received by network device 20. Optionally, flow table 1 may also include the status of the most recently received TCP handshake message; flow table 2 may include the correspondence between the flow identifiers and sequence numbers of the control messages in the flow for which a TCP connection has been established (i.e., TCP link establishment is successful). Flow table 1 may be a hash table or Bloom filter table maintained on network device 20, and flow table 2 may be a hash table maintained on network device 20.
[0059] In order to more clearly introduce the embodiment of the present application, the attack defense method provided in the embodiment of the present application is described below with reference to FIG3 .
[0060] FIG3 is a flow chart illustrating an attack defense method 100 provided in an embodiment of the present application. In this method 100, the present embodiment is described with a network device as the execution subject. For example, the network device may be network device 10 or network device 20 in the scenario shown in FIG1 . For example, this method 100 can be understood as being implemented by an NP in the network device. In the example shown in FIG2 , this can be understood as NP 21 in network device 20 implementing this method 100.
[0061] As shown in FIG3 , the method 100 may include, for example, the following steps S101 to S103 :
[0062] S101: A network device receives a first control message, where the first control message includes a first sequence number.
[0063] The first control message may be a TCP handshake message or a protocol message.
[0064] The first control message may include at least a first sequence number. Optionally, the first control message may further include: information for determining a first flow identifier, and / or information for determining a status of the first control message. The information for determining the first flow identifier may be information in the first control message that can indicate characteristics of the first flow to which the first control message belongs, such as all or part of the first control message's quintuple (i.e., source IP address, destination IP address, source port number, destination port number, and transport protocol); or the information for determining the first flow identifier may be the first flow identifier itself. The information for determining the status of the first control message may be the value of a Status Flag field in the first control message, which indicates the status of the first control message. The status of the first control message may include, but is not limited to, SYN, SYN-ACK, and ACK. When the status of the first control message is not SYN, SYN-ACK, or ACK, the first control message is considered not to be a TCP handshake message, but rather a protocol message.
[0065] As an example, after a network device receives a first control message, the NP in the network device needs to first identify whether the first control message is a legitimate message based on method 100. If the first control message is determined to be a legitimate message, the NP in the network device can send the first control message to the CPU of the network device so that the CPU can process the first control message. If the first control message is determined not to be a legitimate message, it can be determined to be an attack message. The NP in the network device can directly discard the first control message without sending the first control message to the CPU of the network device. In this way, the NP in the network device can effectively identify and process attack messages based on method 100, preventing a large number of attack messages from being sent to the CPU as legitimate messages, causing the CPU to crash, and achieving accurate defense against attacks on stateful protocols.
[0066] S102: The network device determines, according to the first flow identifier and the state of the first control message, that the first control message is a pre-legalized message.
[0067] It can be understood that judging whether the first control message is a pre-legal message based on S102 is the "first judgment" in the "two-level judgment" of method 100. If it is determined through S102 that the first control message is a pre-legal message, the "second judgment" will be performed, that is, S103 will be continued to judge whether the first control message is a legal message; if it is determined through S102 that the first control message is not a pre-legal message, S103 will no longer be executed, but the first control message will be directly discarded.
[0068] A pre-validated message can be understood as a message that has been preliminarily validated by the "primary validation" in the "two-stage validation" process, and is a prerequisite for executing the "secondary validation" in S103. Determining that the first control message is a pre-validated message in S102 can also be understood as determining that the first control message belongs to the first flow indicated by the first flow identifier.
[0069] In some possible implementations, the basis for "one-time judgment" can be carried in the form of a flow table, which will be described below using the first flow table as an example. Before S102, the method 100 may also include: when the first flow table maintained on the network device does not include the first flow identifier, the NP of the network device receives the control message 1, and if the status of the control message 1 is SYN, SYN-ACK or ACK, it is determined that the control message 1 is a pre-legal message, the first flow identifier is recorded in the first flow table, and the control message 1 is sent to the CPU of the network device so that the CPU can process the control message 1. The first flow identifier is used to indicate the first flow, and the control message 1 and the first control message in S102 both belong to the first flow.
[0070] As an example, when the first flow table does not include the first flow identifier, S102 may include: S1021, obtaining the first flow identifier of the first control message and the status of the first control message; S1022, if the first flow identifier does not exist in the first flow table and the status of the first control message is in a preset state, determining that the first control message is a pre-legalized message. The first flow table is used to record the flow identifier of the received control message in the preset state. The preset state is the state corresponding to the TCP handshake message received by the network device. The TCP handshake message may be a SYN message, a SYN-ACK message, or an ACK message. For example, when a network device initiates establishment of a TCP connection, after the network device sends a SYN message to the peer end of the TCP connection, the network device receives a SYN-ACK message from the peer end. In this case, the preset state may include SYN-ACK. Alternatively, when the peer end initiates establishment of a TCP connection to the network device, the network device receives a SYN message from the peer end. In this case, the preset state may include SYN.
[0071] As another example, the method 100 may further include: the network device receives a second control message belonging to the first flow; if the first flow identifier exists in the first flow table and the state of the second control message is in a preset state, determining that the second control message is not a legitimate message and discarding the second control message. This is because: when the first flow identifier already exists in the first flow table, it means that the network device has already received a TCP handshake message belonging to the first flow. If the network device receives a TCP handshake message belonging to the first flow again in this situation, the network device considers the received TCP handshake message belonging to the first flow to be an attack message rather than a legitimate message, and thus discards the message.
[0072] In order to save storage resources, the first flow table may be a hash table or a Bloom filter table.
[0073] If the first flow table is a hash table, then the flow identifier stored in the first flow table may be a hash value obtained by hashing the flow identifier obtained from the control message. The flow identifier obtained from the control message may refer to: Case 1, where the control message includes the flow identifier and the network device directly obtains the flow identifier by parsing the control message; Case 2, where the control message does not include the flow identifier and the network device obtains a target feature from the control message's features for calculating the flow identifier, and obtains the flow identifier by calculating the target feature. Therefore, the process of obtaining the first flow identifier of the first control message in S1021 may correspond to the process of storing the flow identifier in the first flow table.
[0074] The first flow table is a Bloom filter table, which can further save storage resources compared to a hash table. If the first flow table is a Bloom filter table, then the flow identifier stored in the first flow table can be: multiple hash values obtained by performing multiple hash calculations on the flow identifier obtained from the control message, the multiple hash values are respectively mapped to corresponding bits, and the values of the corresponding bits are set to 1. For example, the Bloom filter table includes n bits (n is an integer greater than 0), and the flow identifier obtained from the control message is hashed four times to obtain four hash values {1, 4, 18, n-2} respectively. Then, after the flow identifier of the control message is recorded in the first flow table, the first bit, the fourth bit, the 18th bit, and the (n-2)th bit in the first flow table are 1, as shown in Figure 4. After four hash calculations, it can be ensured that the bits corresponding to different flow identifiers in the Bloom filter table are as different as possible, thereby enabling the Bloom filter table to more accurately store a large number of flow identifiers. Then, the process of obtaining the first flow identifier of the first control message in S1021 may correspond to the process of storing the flow identifier in the first flow table.
[0075] After S102 determines that the first control message is a pre-legal message, a preliminary screening is performed to execute the next step of judgment (ie, execution of S103), which can effectively save computing resources in the embodiment of the present application.
[0076] S103: The network device determines that the pre-legalization message is a legal message based on the first flow identifier and the first sequence number.
[0077] In some possible implementations, the basis for the "secondary determination" can also be carried in the form of a flow table. The following description uses the second flow table as an example. Prior to S103, method 100 may further include: if the CPU of the network device determines that the TCP link establishment for the first flow is successful, then, in one scenario, the CPU sends a notification message to the NP, notifying the NP of the successful TCP link establishment for the first flow, so that the NP records the first flow identifier in a second flow table based on the notification message; in another scenario, the CPU establishes a second flow table including the first flow identifier and sends the second flow table to the NP. Thus, the second flow table maintained by the NP includes the first flow identifier. Subsequently, if the NP of the network device receives protocol packet 1 belonging to the first flow, the NP updates the correspondence between the first flow identifier in the second flow table based on sequence number 1 of protocol packet 1. After the update, the second flow table includes the correspondence between the first flow identifier and sequence number 1. Subsequently, if the NP of the network device receives protocol packet 2 belonging to the first flow, the NP verifies sequence number 2 carried in protocol packet 2 based on sequence number 1 corresponding to the first flow identifier in the second flow table. If the verification succeeds, the protocol packet 2 is determined to be a valid packet.
[0078] As an example, if the second flow table includes a correspondence between the first flow identifier and the second sequence number, and the first control message does not belong to the preset state, then S103 may include, for example: the network device verifies the first sequence number based on the second sequence number, and in response to the verification being successful, determines that the first control message is a legitimate message. The principle of verifying the first sequence number based on the second sequence number is that the second sequence number is the sequence number of a control message that has been determined to be legitimate, and the control messages exchanged between the two devices have a certain regularity in terms of time sequence. Generally, the sequence number of the subsequent control message is the sum of the sequence number of the previous control message and the message length of the subsequent control message. Therefore, the sequence number of the control message transmitted after the previous legitimate message should be within a certain numerical range. If it is not, it can be directly determined to be an attack message forged by an attacker, rather than a legitimate message.
[0079] For example, a network device verifies a first sequence number based on a second sequence number, which may include: first, the network device determines a sequence number range based on the second sequence number and a preset threshold; then, the network device determines whether the first sequence number falls within the sequence number range; if so, the verification is determined to be successful; if not, the verification is determined to be unsuccessful. The preset threshold may be, for example, the maximum allowable length of a preset number of messages. Assuming the maximum allowable length of each message is 1500 bits and the preset number is 4, then the preset threshold may be 4*1500 bits=6000 bits. Assuming the second sequence number is a and the first sequence number is b, then the sequence number range may be (a-6000, a+6000). If b∈(a-6000, a+6000), then the verification is determined to be successful; otherwise, the verification is determined to be unsuccessful.
[0080] For another example, the network device verifies the first sequence number based on the second sequence number, which may include: first, the network device calculates the difference between the second sequence number and the first sequence number; then, the network device determines whether the difference is less than or equal to a preset length range. If so, it is determined that the verification is successful; if not, it is determined that the verification is unsuccessful. The preset length range can be, for example, a preset multiple of the maximum message length. Assuming that the maximum allowable length of each message is 1500 bits and the preset multiple is 4, then the preset length range can be equal to (1500*4) bits = 6000 bits. Assuming that the second sequence number is a and the first sequence number is b, then |ab| is calculated and it is determined whether |ab| is less than or equal to 6000 bits. If so, it is determined that the verification is successful; otherwise, it is determined that the verification is unsuccessful.
[0081] In some implementations, if the first control message is determined to be a legitimate message at step S103, the NP of the network device may send the first control message to the CPU of the network device so that the CPU can process the first control message. If the first control message is determined not to be a legitimate message at step S103, the NP of the network device discards the first control message and does not send the first control message to the CPU of the network device. This conserves CPU resources for identifying and processing the first control message, prevents CPU paralysis due to receiving too many attack messages, and improves the reliability of the network device.
[0082] In some implementations, if it is determined through S103 that the first control message is a legal message, then the method 100 may further include: the network device updates the second flow table based on the first sequence number, and the updated second flow table includes the correspondence between the first flow identifier and the first sequence number. In this way, it can be ensured that the verification of whether the sequence number carried in the received control message is legal based on the sequence number in the second flow table is accurate. It should be noted that the network device updates the correspondence of each legal message in the second flow table; or, for the same flow, the network device may also update the correspondence related to the flow in the second flow table once every M legal messages, where M is less than or equal to the preset number corresponding to the preset threshold, or M is less than or equal to the preset multiple.
[0083] In order to save storage resources, the second flow table may be a hash table.
[0084] If the second flow table is a hash table, then, in the correspondence between flow identifiers and sequence numbers stored in the second flow table, only the flow identifier may be a hash value, and the sequence number may be the sequence number itself carried in the control message.
[0085] In other possible implementations, the attack defense scheme for other flows is similar to that for the first flow. Taking the second flow as an example, method 100 may further include: the network device receiving a third control message; the network device obtaining a second flow identifier of the third control message, where the second flow identifier indicates the second flow to which the third control message belongs; if the second flow identifier does not exist in the first flow table and the third control message is in a preset state, the network device recording the second flow identifier in the first flow table. Furthermore, the NP of the network device also sends the third control message to the CPU of the network device. The preset state is SYN, SYN-ACK, or ACK.
[0086] As an example, method 100 may further include: the network device receiving a fourth control message belonging to the second flow, the fourth control message including the third sequence number; if it is determined that the TCP link establishment for the second flow is successful, the network device recording the correspondence between the second flow identifier and the third sequence number in the second flow table. Furthermore, the NP of the network device further sends the fourth control message to the CPU of the network device.
[0087] As another example, the method 100 may also include: the network device receives a fifth control message belonging to the second flow, and the fifth control message includes a fourth sequence number; if the status of the fifth control message does not belong to the preset state, and the second flow table includes a correspondence between the second flow identifier and the third sequence number, the network device verifies the fourth sequence number based on the third sequence number, and if the verification succeeds, it is determined that the fifth control message is a legal message, and the NP of the network device also sends the fifth control message to the CPU of the network device; if the verification fails, it is determined that the fifth control message is not a legal message, and the NP of the network device discards the fifth control message.
[0088] It can be seen that through this method 100, after the network device receives the first control message including the first sequence number, it first determines that the first control message is a pre-legalized message based on the first flow identifier and the status of the first control message; then, based on the first flow identifier and the first sequence number, it determines that the pre-legalized first control message is a legal message. In this way, the network device can perform a "two-level judgment" on the received control message to analyze whether the control message is a legal message. If the control message is a legal message, the NP in the network device will send the control message to the CPU of the network device. Once it is determined that the control message is not a pre-legalized message or a legal message, the control message will be discarded to achieve accurate identification of attack messages of stateful protocols, thereby effectively defending against attacks on stateful protocols.
[0089] Accordingly, the embodiment of the present application further provides an attack defense device 500, which is applied to a network device, as shown in FIG5 . The device 500 may include: a receiving unit 501 and a processing unit 502.
[0090] The receiving unit 501 is configured to receive a first control message including a first sequence number. The receiving unit 501 may execute S101 shown in FIG3 .
[0091] The processing unit 502 is configured to determine, based on the first flow identifier and the state of the first control message, whether the first control message is a pre-validated message. The processing unit 502 may execute S102 shown in FIG3 .
[0092] The processing unit 502 is further configured to determine, based on the first flow identifier and the first sequence number, that the pre-validation message is a valid message. The processing unit 502 may also execute S103 shown in FIG3 .
[0093] In some implementations, the processing unit 502 is specifically used to: obtain the first flow identifier of the first control message and the status of the first control message, the first flow identifier is used to indicate the first flow to which the first control message belongs; if the first flow identifier does not exist in the first flow table, and the status of the first control message belongs to a preset state, then determine that the first control message is a pre-legal message, and the first flow table is used to record the flow identifier of the received control message in the preset state, and the preset state is the state corresponding to the TCP handshake message received by the network device.
[0094] The processing unit 502 is specifically used to: if the first flow identifier exists in the first flow table, there is a correspondence between the first flow identifier and the second sequence number in the second flow table, and the state of the first control message does not belong to the preset state, then verify the first sequence number based on the second sequence number, and in response to the verification being passed, determine that the first control message is a legal message.
[0095] In some implementations, the processing unit 502 is specifically configured to: determine a sequence number range based on the second sequence number and a preset threshold; determine whether the first sequence number belongs to the sequence number range, and if so, determine that the verification is passed; if not, determine that the verification is failed.
[0096] In some implementations, the processing unit 502 is specifically used to: calculate the difference between the second serial number and the first serial number; determine whether the difference is less than or equal to a preset length range, if so, determine that the verification is passed; if not, determine that the verification is failed.
[0097] In some implementations, the processing unit 502 is further configured to: update the second flow table based on the first sequence number, wherein the updated second flow table includes a correspondence between the first flow identifier and the first sequence number.
[0098] In some implementations, the receiving unit 501 is further used to: receive a second control message, where the second control message belongs to the first flow; the processing unit 502 is further used to: if the first flow identifier exists in the first flow table and the status of the second control message belongs to the preset status, determine that the second control message is not a legal message and discard the second control message.
[0099] In some implementations, the receiving unit 501 is further used to: receive a third control message; the processing unit 502 is further used to: obtain a second flow identifier of the third control message, wherein the second flow identifier is used to indicate the second flow to which the third control message belongs, and if the second flow identifier does not exist in the first flow table and the status of the third control message belongs to the preset status, the second flow identifier is recorded in the first flow table.
[0100] In some implementations, the receiving unit 501 is further used to: receive a fourth control message, the fourth control message belongs to the second flow, and the fourth control message includes a third sequence number; the processing unit 502 is further used to: if it is determined that the TCP link establishment for the second flow is successful, record the correspondence between the second flow identifier and the third sequence number in the second flow table.
[0101] In some implementations, the first flow table may be a hash table or a Bloom filter table, and the second flow table may be a hash table.
[0102] In some implementations, the TCP handshake message includes a SYN message, a SYN-ACK message, or an ACK message.
[0103] In some implementations, the NP in the apparatus 500 sends the first control message to the CPU in the apparatus 500; and the CPU in the apparatus 500 processes the first control message.
[0104] It should be noted that the specific implementation method and technical effects achieved by the device 500 provided in the embodiment of the present application can be found in the relevant description of the network device implementation steps in the method 100 shown in Figure 3.
[0105] 6 , an embodiment of the present application further provides a network device 600, which may include: an NP 601 and a CPU 602. The NP 601 is configured to execute the method 100 provided in any possible implementation of the method 100 shown in FIG3 .
[0106] Optionally, the NP 601 is further configured to send the first control message determined to be legal to the CPU 602; and the CPU 602 is configured to process the first control message.
[0107] Referring to Figure 7 , an embodiment of the present application provides a network device 700. Network device 700 may be any of the network devices described in the aforementioned embodiments, such as network device 10 or network device 20 in Figure 1 ; or the network device in Figure 3 . Network device 700 may implement the functions of the various network devices described in the aforementioned embodiments. Network device 700 includes at least one processor 701, a bus system 702, a memory 703, and at least one communication interface 704.
[0108] The network device 700 is a hardware device that can be used to implement the functional modules of the attack defense device 500 shown in Figure 5. For example, those skilled in the art will appreciate that the processing unit 502 in the attack defense device 500 shown in Figure 5 can be implemented by the at least one processor 701 calling code in the memory 703. Alternatively, the network device 700 is a hardware device that can be used to implement the functional modules of the NP 601 in the network device 600 shown in Figure 6.
[0109] Optionally, the network device 700 may also be used to implement the functions of the network device in any of the above embodiments.
[0110] Optionally, the processor 701 may be a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.
[0111] The bus system 702 may include a path for transmitting information between the components.
[0112] The communication interface 704 is used to communicate with other devices or communication networks.
[0113] The above-mentioned memory 703 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to this. The memory can exist independently and be connected to the processor through a bus. The memory can also be integrated with the processor.
[0114] The memory 703 is used to store application code for executing the solution of the present application, and the execution is controlled by the processor 701. The processor 701 is used to execute the application code stored in the memory 703, thereby realizing the functions of the method of the present application.
[0115] In a specific implementation, as an embodiment, the processor 701 may include one or more CPUs, such as CPU0 and CPU1 in FIG. 7 .
[0116] In a specific implementation, as an embodiment, the network device 700 may include multiple processors, such as processor 701 and processor 707 in Figure 7. Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0117] FIG8 is a schematic diagram of the structure of another network device 800 provided in an embodiment of the present application. Network device 800 may be any of the network devices in any of the aforementioned embodiments, such as network device 10 or network device 20 in FIG1 , or the network device in FIG3 . Network device 800 may implement the functions of the network devices in the aforementioned embodiments.
[0118] The network device 800 includes a main control board 810 and an interface board 830 .
[0119] Main control board 810, also known as the main processing unit (MPU) or route processor card, controls and manages various components in network device 800, including routing calculations, device management, device maintenance, and protocol processing. Main control board 810 includes a central processing unit (CPU) 811 and memory 812.
[0120] Interface board 830 is also known as a line processing unit (LPU), line card, or service board. It provides various service interfaces and implements data packet forwarding. Service interfaces include, but are not limited to, Ethernet interfaces and POS (Packet over SONET / SDH) interfaces. Ethernet interfaces, for example, are Flexible Ethernet Clients (FlexE Clients). Interface board 830 includes a central processing unit (CPU) 831, a network processor (NPU) 832, a forwarding table memory 834, and a physical interface card (PIC) 833.
[0121] The central processing unit 831 on the interface board 830 is used to control and manage the interface board 830 and communicate with the central processing unit 811 on the main control board 810 .
[0122] The network processor 832 is used to implement packet forwarding processing. The network processor 832 can be in the form of a forwarding chip. Specifically, the processing of uplink packets includes: processing of the packet input interface and forwarding table lookup; the processing of downlink packets includes: forwarding table lookup, etc.
[0123] The physical interface card 833 is used to implement the physical layer docking function. The original traffic enters the interface board 830 from this, and the processed message is sent from the physical interface card 833. The physical interface card 833 includes at least one physical interface, which is also called a physical port. The physical interface card 833 corresponds to the FlexE physical interface in the system architecture. The physical interface card 833, also known as a daughter card, can be installed on the interface board 830. It is responsible for converting the optical and electrical signals into messages and performing a validity check on the messages before forwarding them to the network processor 832 for processing. In some embodiments, the central processing unit 831 of the interface board 830 can also perform the functions of the network processor 832, such as implementing software forwarding based on a general-purpose CPU, so that the network processor 832 is not required in the physical interface card 833.
[0124] Optionally, the network device 800 includes multiple interface boards. For example, the network device 800 further includes an interface board 840 . The interface board 840 includes a central processing unit 841 , a network processor 842 , a forwarding table memory 844 , and a physical interface card 843 .
[0125] Optionally, the network device 800 further includes a switching fabric board 820. The switching fabric board 820 may also be referred to as a switch fabric unit (SFU). If the network device has multiple interface boards 830, the switching fabric board 820 is used to exchange data between the interface boards. For example, the interface board 830 and the interface board 840 can communicate via the switching fabric board 820.
[0126] The main control board 810 and the interface board 830 are coupled. For example, the main control board 810, the interface board 830, the interface board 840, and the switching network board 820 are connected to the system backplane via a system bus to achieve intercommunication. In one possible implementation, an inter-process communication (IPC) channel is established between the main control board 810 and the interface board 830, and communication between the main control board 810 and the interface board 830 is performed via the IPC channel.
[0127] Logically, network device 800 includes a control plane and a forwarding plane. The control plane includes a main control board 810 and a central processing unit 831. The forwarding plane includes various components that perform forwarding, such as a forwarding table entry memory 834, a physical interface card 833, and a network processor 832. The control plane performs functions such as routing, generating forwarding tables, processing signaling and protocol messages, and configuring and maintaining device status. The control plane sends the generated forwarding tables to the forwarding plane. On the forwarding plane, the network processor 832 forwards messages received by the physical interface card 833 based on the forwarding tables sent by the control plane. The forwarding tables sent by the control plane can be stored in the forwarding table entry memory 834. In some embodiments, the control plane and forwarding plane can be completely separate and not located on the same device.
[0128] If the network device 800 is configured as the network device shown in Figure 3, the network processor 832 can trigger the physical interface card 833 to receive a first control message, which includes a first sequence number; the central processor 811 can determine that the first control message is a pre-legal message based on the first flow identifier and the status of the first control message, and then determine that the pre-legal message is a legal message based on the first flow identifier and the first sequence number.
[0129] It should be understood that the receiving unit 501 in the attack defense device 500 and the communication interface 704 in the network device 700 can be equivalent to the physical interface card 833 or the physical interface card 843 in the network device 800; the processing unit 502 in the attack defense device 500 and the processor 701 in the network device 700 can be equivalent to the central processing unit 811 or the central processing unit 831 in the network device 800.
[0130] It should be understood that the operations on interface board 840 in the embodiments of the present application are consistent with those on interface board 830 and, for the sake of brevity, will not be described in detail here. The network device 800 of this embodiment may correspond to the attack defense device 500 or network device 700 in the various embodiments described above. The main control board 810, interface board 830, and / or interface board 840 in the network device 800 may implement the functions and / or various steps performed by the attack defense device 500 or network device 700 in the various embodiments described above. For the sake of brevity, detailed descriptions are not given here.
[0131] It should be understood that there may be one or more main control boards, and when there are multiple boards, they may include a primary main control board and a backup main control board. There may be one or more interface boards. The stronger the data processing capability of the network device, the more interface boards are provided. There may also be one or more physical interface cards on the interface board. There may be no switching network board, or there may be one or more switching network boards. When there are multiple switching network boards, they can jointly achieve load sharing and redundant backup. In a centralized forwarding architecture, the network device may not need a switching network board, and the interface board is responsible for processing the business data of the entire system. In a distributed forwarding architecture, the network device can have at least one switching network board, which realizes data exchange between multiple interface boards through the switching network board, providing large-capacity data exchange and processing capabilities. Therefore, the data access and processing capabilities of network devices with a distributed architecture are greater than those of devices with a centralized architecture. Alternatively, a network device can consist of a single card, without a switching fabric board (SFB), integrating the functions of the interface board and the main control board. In this case, the CPUs on the interface board and the main control board can be combined into a single CPU, performing the combined functions of the two. This type of device has lower data exchange and processing capabilities (for example, low-end network devices such as switches or routers). The specific architecture used depends on the specific network deployment scenario.
[0132] In some possible embodiments, each of the above-mentioned network devices or network devices can be implemented as a virtualized device. For example, a virtualized device can be a virtual machine (English: Virtual Machine, VM) running a program for sending message functions, and the virtual machine is deployed on a hardware device (for example, a physical server). A virtual machine refers to a complete computer system with complete hardware system functions simulated by software and running in a completely isolated environment. The virtual machine can be configured as each network device in the embodiments of the present application. For example, each network device or network device can be implemented based on a general physical server in combination with Network Function Virtualization (NFV) technology. Each network device or network device is a virtual host, a virtual router or a virtual switch. Those skilled in the art can virtualize each network device or network device with the above-mentioned functions on a general physical server in combination with NFV technology by reading this application, and will not be repeated here.
[0133] It should be understood that the network devices in the various product forms mentioned above respectively have any functions of the network devices or communication devices in the above method embodiments, which will not be described in detail here.
[0134] The present application also provides a chip comprising a processor and an interface circuit, the interface circuit being configured to receive instructions and transmit them to the processor; the processor, which may be, for example, a specific implementation of the message processing device in the present application, being configured to execute the aforementioned routing method. The processor is coupled to a memory configured to store programs or instructions. When the programs or instructions are executed by the processor, the chip system implements the method in any of the aforementioned method embodiments.
[0135] Optionally, there may be one or more processors in the chip system. The processor may be implemented in hardware or software. When implemented in hardware, the processor may be a logic circuit, an integrated circuit, etc. When implemented in software, the processor may be a general-purpose processor implemented by reading software code stored in a memory.
[0136] Optionally, the memory in the chip system may be one or more memories. The memory may be integrated with the processor or may be provided separately from the processor, which is not limited in this application. For example, the memory may be a non-transient processor, such as a read-only memory (ROM), which may be integrated with the processor on the same chip or provided on different chips. This application does not specifically limit the type of memory or the configuration of the memory and the processor.
[0137] Exemplarily, the chip system can be a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on chip (SoC), a central processor unit (CPU), a network processor (NP), a digital signal processor (DSP), a microcontroller unit (MCU), a programmable logic device (PLD) or other integrated chips.
[0138] In addition, an embodiment of the present application also provides a readable storage medium, which stores program code or instructions. When the program code or instructions are executed on a processor, the processor executes a method in any one of the implementation modes in the embodiment shown in FIG. 3 above.
[0139] In addition, an embodiment of the present application also provides a program product, which, when executed on a processor, enables the processor to execute any one of the implementation methods of the aforementioned method 100.
[0140] It should be understood that "based on determining B according to A" mentioned in the embodiments of the present application does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0141] The "first" in the names of "first control message" and "first flow identifier" mentioned in this application is only used as a name identifier and does not mean the first in order. The same rule applies to "second" and so on.
[0142] Through the description of the above embodiments, it can be known that those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment or certain parts of the embodiments of the present application.
[0143] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system embodiments and device embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The device and system embodiments described above are merely schematic. The modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without making any creative effort.
[0144] The above description is only a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application. It should be noted that those skilled in the art may make several improvements and modifications without departing from the scope of protection of the present application, and such improvements and modifications should also be considered as within the scope of protection of the present application.
Claims
1. An attack defense method, characterized in that: Applied to network equipment, including: Receiving a first control message, wherein the first control message includes a first sequence number; Determining, according to the first flow identifier and the state of the first control message, that the first control message is a pre-legalized message; Based on the first flow identifier and the first sequence number, it is determined that the pre-legalized message is a legal message.
2. The method according to claim 1, characterized in that The determining, according to the first flow identifier and the state of the first control message, that the first control message is a pre-legal message includes: Acquire the first flow identifier of the first control message and the state of the first control message, where the first flow identifier is used to indicate a first flow to which the first control message belongs; If the first flow identifier does not exist in the first flow table, and the state of the first control message belongs to a preset state, it is determined that the first control message is a pre-legal message, and the first flow table is used to record the flow identifier of the received control message of the preset state, and the preset state is a state corresponding to the transmission control protocol TCP handshake message received by the network device; The determining, based on the first flow identifier and the first sequence number, that the pre-legalized message is a legal message includes: If the first flow identifier exists in the first flow table, there is a correspondence between the first flow identifier and the second sequence number in the second flow table, and the state of the first control message does not belong to the preset state, the first sequence number is verified based on the second sequence number, and in response to the verification being successful, it is determined that the first control message is a legal message.
3. The method according to claim 2, characterized in that The verifying the first serial number based on the second serial number includes: Determining a sequence number range according to the second sequence number and a preset threshold; It is determined whether the first serial number belongs to the serial number range, if so, it is determined that the verification is passed, if not, it is determined that the verification is failed.
4. The method according to claim 2, characterized in that: The verifying the first serial number based on the second serial number includes: Calculating a difference between the second sequence number and the first sequence number; It is determined whether the difference is less than or equal to a preset length range, if so, it is determined that the verification is passed, if not, it is determined that the verification is not passed.
5. The method according to any one of claims 2 to 4, characterized in that: The method further comprises: The second flow table is updated based on the first sequence number, and the updated second flow table includes a correspondence between the first flow identifier and the first sequence number.
6. The method according to any one of claims 2 to 5, characterized in that: The method further comprises: receiving a second control message, where the second control message belongs to the first flow; If the first flow identifier exists in the first flow table and the state of the second control message belongs to the preset state, it is determined that the second control message is not a legal message, and the second control message is discarded.
7. The method according to any one of claims 2 to 6, characterized in that: The method further comprises: receiving a third control message; Acquire a second flow identifier of the third control message, where the second flow identifier is used to indicate a second flow to which the third control message belongs; If the second flow identifier does not exist in the first flow table, and the state of the third control message belongs to the preset state, the second flow identifier is recorded in the first flow table.
8. The method according to claim 7, characterized in that The method further comprises: receiving a fourth control message, the fourth control message belonging to the second flow, the fourth control message including a third sequence number; If it is determined that the TCP link establishment for the second flow is successful, the corresponding relationship between the second flow identifier and the third sequence number is recorded in the second flow table.
9. The method according to any one of claims 2 to 8, characterized in that: The first flow table is a hash table or a Bloom filter table, and the second flow table is a hash table.
10. The method according to any one of claims 2 to 9, characterized in that: The TCP handshake message includes a synchronization SYN message, a synchronization-acknowledgement SYN-ACK message or an acknowledgement ACK message.
11. The method according to any one of claims 1 to 10, characterized in that: The method further comprises: The network processor NP of the network device sends the first control message to the central processing unit CPU of the network device; The CPU of the network device processes the first control message.
12. A network processor NP, comprising: A processing unit, configured to perform other operations except the receiving operation and the sending operation in the method according to any one of claims 1 to 11; A transceiver unit, used to perform the receiving operation and the sending operation in the method described in any one of claims 1-11.
13. A network device, characterized in that: include: A processing unit, configured to perform other operations except the receiving operation and the sending operation in the method according to any one of claims 1 to 11; A transceiver unit, used to perform the receiving operation and the sending operation in the method described in any one of claims 1-11.
14. A network device, characterized in that: The network device includes a memory and a processor; The memory is used to store instructions; The processor is used to execute the instructions in the memory and perform the method according to any one of claims 1 to 11.
15. A storage medium, characterized in that: The storage medium includes instructions, and when the instructions are executed on a processor, the processor is caused to execute the method according to any one of claims 1 to 11.
16. A program product, characterized in that The program product comprises a program, and when the program is run on a processor, the method according to any one of claims 1 to 11 is executed.
Citation Information
Patent Citations
Attack defense method and device
CN119921966A
ACK Flood attack protection method and device, equipment and medium
CN109936543A
DDoS attack detection method, system, device and medium
CN115714685A
CC attack interception method and device of network layer and server
CN116684132A
System for controlling network access of application on basis of TCP session control, and method related thereto
WO2023033586A1