Message transmission method and apparatus
By using the IPv6 address space in the security module of the server to assign preconfigured addresses to the client and verify the destination address of the service message, the problem of DDOS scanning attacks is solved, and effective prevention and mitigation of DDOS attacks is achieved.
Patent Information
- Application Number
- PCT/CN2024/097069
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-26
- Filing Date
- 2024-06-03
- Publication Date
- 2025-05-30
AI Technical Summary
The existing technology is difficult to effectively prevent or mitigate DDOS attacks, especially elephant stream attacks, real source attacks and scanned attacks, resulting in a large amount of server resources occupied and affecting the access of legitimate users.
By using the greatness of the IPv6 address space in the security module on the server, the client is assigned a preconfigured address and verify whether its destination address is a preconfigured address when receiving the service message. If not, the message will be blocked.
Effectively prevent or mitigate DDOS scan attacks, avoid attack sources from attacking the server through direct DDOS scan attacks, and ensure that the access of legitimate users is not affected.
Smart Images

Figure CN2024097069_30052025_PF_FP_ABST
Abstract
Description
Message transmission method and device
[0001] This application claims priority to Chinese patent application No. 202311563092.X, filed on November 21, 2023, entitled “A method, device and other equipment for data processing”, and claims priority to Chinese patent application No. 202410529260.1, filed on April 26, 2024, entitled “Message transmission method and device”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of security technology, and in particular to a message transmission method and device. Background Art
[0003] Distributed denial of service (DDOS) attacks are an old but still active attack method. DDOS attacks typically use legitimate service requests to occupy excessive service resources, preventing legitimate users from receiving service responses.
[0004] Common but difficult-to-defend DDOS attacks include, but are not limited to, elephant stream attacks, true source attacks, and sweep attacks. Elephant stream attacks involve a large number of continuous attempts to access a target service through a single network connection. Because elephant stream attacks focus on a single network connection, they are difficult to distribute to multiple central processing units (CPUs) for prevention. True source attacks involve attacks that use numerous real hosts as attack sources, making it difficult to distinguish the attacking behavior of these hosts from that of legitimate users. Sweep attacks fall somewhere between elephant stream attacks and true source attacks. Sweep attacks involve scanning continuous Internet Protocol (IP) address segments, distributing traffic across multiple target IP addresses. While the traffic attacking each target IP address is not large, the combined traffic attacking all target IP addresses is very large, making it difficult to detect attack patterns and prevent them.
[0005] Therefore, in the process of the client accessing the services provided by the server through business messages, how to effectively prevent or mitigate the DDOS attacks on the server by the attack source has become a technical problem that needs to be solved urgently.
[0006] Summary of the Invention
[0007] The present application provides a message transmission method and device, which can effectively prevent or alleviate typical DDOS attacks on the current Internet.
[0008] The technical solutions provided in this application are as follows:
[0009] In the first aspect, the present application provides a message transmission method, which is applied to a security module of a server, wherein the server is used to provide a target service to a client, the client is a registered user of the target service, and the target service runs on at least one server of at least one cloud data center located in one of multiple regions. The method comprises: receiving a target business message sent by the client for accessing the target service, the destination address of the target business message including a verification field; verifying the destination address of the target business message according to the verification field to determine that the destination address of the target business message is a preconfigured address; and sending the target business message to the server. The preconfigured address is an Internet Protocol version 6 (IPv6) address configured for the client to access the target service.
[0010] Through the method provided in this application, since the IPv6 address space is huge and many of them are idle addresses, when the huge IPv6 address space is used to allocate access addresses to the server that provides the target service, when the attack source attacks the target service provided by the server through a direct DDOS sweep attack, the direct DDOS sweep attack cannot be effectively carried out.
[0011] In one possible design, the method further includes: blocking the target service message when the destination address of the target service message is not a preconfigured address and / or when the destination address of the target service message is on a block list. The block list is used to record the destination addresses of service messages that are prohibited from being forwarded.
[0012] Through this possible design, it is achieved that the message that does not use the pre-configured address allocated for the target service to access the target service is blocked, thereby preventing illegal users from accessing the target service.
[0013] In another possible design method, the destination address of the target business message also includes a preset field. The above-mentioned verification of the destination address of the target business message according to the verification field to determine that the destination address of the target business message is a preconfigured address includes: obtaining a first preset rule corresponding to the preset field, the first preset rule being used to determine the verification field in the preconfigured address based on a logical operation; determining the target verification field according to the first preset rule; and determining that the destination address of the target business message is a preconfigured address when the verification field included in the destination address of the target business message is the same as the target verification field.
[0014] Through this possible design, the destination address of the target service message is verified.
[0015] In another possible design, the above method further includes: when the preset time is reached, receiving a second preset rule, where the second preset rule is a preset rule that updates the first preset rule.
[0016] Through this possible design, when the client periodically changes the destination address used to access the target service, the security module on the server side can periodically receive preset rules for verifying the destination address in the service message from the client, that is, the security module on the server side can timely update the preset rules for verifying the access address.
[0017] In another possible design, the security module of the server is deployed in a gateway of the server, and the above method further includes: sending the first preset rule to a forwarding node that can reach the gateway.
[0018] Through this possible design, the forwarding nodes close to the client can receive preset rules for verifying the destination address in the business message from the client, so that these forwarding nodes can forward or block the business message from the client by executing the method described in this application, thereby filtering the DDOS attack traffic at a location close to the client (i.e., the source end), thereby improving the impact of DDOS attacks on the communication network between the client and the service gateway.
[0019] In another possible design, the method further includes: determining that the number of blocked service messages sent by the same registered user through the client exceeds a preset threshold, and adding a user identifier (ID) of the same registered user to a user blacklist.
[0020] Through this possible design, the security module on the server side can collect a user blacklist that records the IDs of registered users who have maliciously accessed the back-end services. Subsequently, network security can be guaranteed by promptly discarding or isolating messages from malicious registered users. Malicious registered users can also be included in the security information system for reference by other attack prevention systems.
[0021] In another possible design, the server-side security module is deployed in a gateway of the server-side. The sending of the target service message to the server includes: performing network address translation (NAT) on the destination address of the target service message; and sending the NATed target service message to the server, where the NATed destination address of the target service message is the address of the server.
[0022] In another possible design, the address after NAT of the destination address of the target service message is an IPv6 address or an Internet Protocol version 4 (IPv4) address.
[0023] Through this possible design, the purpose of flexibly deploying the real IP address of the backend service can be achieved.
[0024] In a second aspect, the present application provides a message transmission method, which is applied to a client, where the client is a registered user of a target service provided by a server, and the server is used to provide the target service to the client, where the target service runs on at least one server in at least one cloud data center located in one of multiple regions. The method includes: obtaining a destination address of a target service message to be sent, where the destination address is one of preconfigured addresses, where the preconfigured address is an IPv6 address configured for the client to access the target service; and sending the target service message, where the target service message is used to access the target service.
[0025] The method provided by this application effectively prevents attackers from attacking the target service provided by the server through direct DDOS sweep attacks, as the IPv6 address space is vast and many of them are idle. Furthermore, the client can only obtain the pre-configured address assigned to the target service if it is a registered user of the target service, thus avoiding the real source attack in DDOS attacks.
[0026] In one possible design, the above-mentioned acquisition of the destination address of the target business message to be sent includes: obtaining a first preset rule, the first preset rule is used to determine the verification field in the preconfigured address based on a logical operation, and the verification field is used to verify whether the destination address of the target business message is the preconfigured address; according to the first preset rule, determine the verification field in the destination address; according to the verification field, obtain the destination address of the target business message.
[0027] In another possible design, the above method further includes: when the preset time is reached, receiving a second preset rule, where the second preset rule is a preset rule that updates the first preset rule.
[0028] With this possible design, when accessing a target service, the client periodically receives different preset rules, enabling the client to regularly update the pre-configured address used as the destination address when accessing the target service. This makes it difficult for an attacker to accurately parse the target service's access address and launch an attack against it.
[0029] In another possible design, before obtaining the destination address of the target business message to be sent, the method further includes: obtaining the access address of the registration service by accessing the portal service of the target service, the registration service being used to provide user registration services for users accessing the target service; and registering as a registered user of the target service based on the access address of the registration service.
[0030] In another possible design, a portal service device for providing portal services is configured with at least one access address of a registration service. The above-mentioned obtaining the access address of the registration service by accessing the portal service of the target service includes: receiving the access address of the registration service returned by the portal service device.
[0031] Through these two possible designs, the client needs to register as a registered user of the target service before obtaining the pre-configured address allocated for the target service, which can avoid the real source attack in the DDOS attack.
[0032] On the third aspect, the present application provides a message transmission device, which is applied to the security module of the server side, and the server side is used to provide the target service to the client side, and the client side is a registered user of the target service, and the target service runs on at least one server of at least one cloud data center located in one of multiple regions. The device includes: a receiving unit, which is used to receive a target business message sent by the client side for accessing the target service, and the destination address of the target business message includes a verification field; a processing unit, which is used to verify the destination address of the target business message according to the verification field to determine whether the destination address of the target business message is a preconfigured address; and a sending unit, which is used to send the target business message to the server side. The preconfigured address is an IPv6 address configured for the client side to access the target service.
[0033] In one possible design, the processing unit is further configured to block the target service message when the destination address of the target service message is not a preconfigured address and / or when the destination address of the target service message is on a block list. The block list is used to record the destination addresses of service messages that are prohibited from being forwarded.
[0034] In another possible design, the destination address of the target business message also includes a preset field, and the above-mentioned device also includes: an acquisition unit, used to obtain a first preset rule corresponding to the preset field, the first preset rule being used to determine the verification field in the preconfigured address based on a logical operation; a processing unit, further used to determine the target verification field according to the first preset rule, and to determine that the destination address of the target business message is a preconfigured address when the verification field included in the destination address of the target business message is the same as the target verification field.
[0035] In another possible design, the receiving unit is further configured to receive a second preset rule when the preset time period is reached, where the second preset rule is an updated version of the first preset rule.
[0036] In another possible design, the security module of the server is deployed in a gateway of the server, and the sending unit is further configured to send the first preset rule to a forwarding node that can reach the gateway.
[0037] In another possible design, the processing unit is further used to determine that the number of blocked service messages sent by the same registered user through the client exceeds a preset threshold, and to add the user ID of the same registered user to a user blacklist.
[0038] In another possible design, the server's security module is deployed in the server's gateway, and the processing unit is further configured to perform NAT on the destination address of the target service message. The sending unit is specifically configured to send the NATed target service message to the server, where the NATed destination address of the target service message is the server's address.
[0039] In another possible design, the address after NAT of the destination address of the target service message is an IPv6 address or an IPv4 address.
[0040] It can be understood that the beneficial effects achieved by the message transmission device provided by the third aspect and any possible design method in the third aspect can be referred to the technical effects of the corresponding solutions provided by the first aspect and any possible design method in the first aspect, and will not be repeated here.
[0041] In a fourth aspect, the present application provides a message transmission device, which is applied to a client, where the client is a registered user of a target service provided by a server, and the server is used to provide the target service to the client, where the target service runs on at least one server in at least one cloud data center located in one of multiple regions. The device includes: an acquisition unit, which is used to obtain a destination address of a target service message to be sent, where the destination address is one of the preconfigured addresses, where the preconfigured address is an IPv6 address configured for the client to access the target service; and a sending unit, which is used to send the target service message, where the target service message is used to access the target service.
[0042] In one possible design, the acquisition unit is further configured to acquire a first preset rule, the first preset rule being configured to determine a verification field in a preconfigured address based on a logical operation, the verification field being used to verify whether the destination address of the target service message is the preconfigured address. The apparatus further includes a processing unit configured to determine the verification field in the destination address based on the first preset rule, and to obtain the destination address of the target service message based on the verification field.
[0043] In another possible design, the apparatus further includes a receiving unit configured to receive a second preset rule when the preset time period is reached, where the second preset rule is an updated version of the first preset rule.
[0044] In another possible design, the acquisition unit is further configured to obtain an access address of a registration service by accessing a portal service of the target service before obtaining the destination address of the target service message to be sent. The processing unit is further configured to register as a registered user of the target service based on the access address of the registration service. The registration service is configured to provide user registration services for users accessing the target service.
[0045] In another possible design, the portal service device for providing the portal service is configured with at least one access address of the registration service. The receiving unit is further configured to receive the access address of the registration service returned by the portal service device.
[0046] It can be understood that the beneficial effects achieved by the message transmission device provided by the fourth aspect and any possible design method in the fourth aspect can be referred to the technical effects of the corresponding solutions provided by the second aspect and any possible design method in the second aspect, and will not be repeated here.
[0047] In a fifth aspect, the present application provides a computing device comprising: a memory, a communication interface, and one or more processors, wherein the one or more processors receive or send data through the communication interface, and the one or more processors are configured to read program instructions stored in the memory to execute the method provided in the first aspect and any possible design method of the first aspect, or to execute the method provided in the second aspect and any possible design method of the second aspect.
[0048] In a sixth aspect, the present application provides a computing device cluster, the computing device cluster comprising at least one computing device, each computing device comprising a processor and a memory. The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster performs the method provided in the first aspect and any possible design of the first aspect, or performs the method provided in the second aspect and any possible design of the second aspect.
[0049] In a seventh aspect, the present application provides a message transmission system, which includes a security module on the server side and a client side. The security module on the server side is used to execute the method provided in the first aspect and any possible design method in the first aspect. The client side is used to execute the method provided in the second aspect and any possible design method in the second aspect. In a specific design, the security module on the server side is implemented as the message transmission device provided in the third aspect or the fifth aspect, and the client side is implemented as the message transmission device provided in the fourth aspect or the fifth aspect.
[0050] In an eighth aspect, the present application provides a chip, which includes a processor. When the processor runs program instructions or codes, the chip including the processor or the device including the chip executes the method provided in the first aspect and any possible design method in the first aspect, or executes the method provided in the second aspect and any possible design method in the second aspect. Exemplarily, the chip also includes: an input interface, an output interface, and a memory. The input interface, output interface, processor, and memory of the chip are connected through the internal connection path of the chip, the memory in the chip is used to store the program instructions or codes run by the processor, and the input interface and output interface of the chip are used for connection and communication between the chip and other chips or devices.
[0051] In the ninth aspect, the present application provides a computer-readable storage medium, which is a non-volatile computer-readable storage medium, and the computer-readable storage medium includes computer program instructions. When the computer program instructions are executed by a computing device or a processor, the computing device or the processor executes the method provided in the first aspect and any possible design method in the first aspect, or executes the method provided in the second aspect and any possible design method in the second aspect.
[0052] In the tenth aspect, the present application provides a computer program product comprising instructions, which, when executed by a processor, causes a computing device or processor to execute a method as provided in the first aspect and any possible design method of the first aspect, or to execute a method as provided in the second aspect and any possible design method of the second aspect.
[0053] It can be understood that any of the message transmission devices, systems, computing device clusters, computer-readable storage media, computer program products or chips provided above can be applied to the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods and will not be repeated here.
[0054] In this application, the names of the above-mentioned message transmission device, message transmission system, etc. do not limit the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear with other names. As long as the functions of each device or functional module are similar to those of this application, they are all within the scope of protection of this application. BRIEF DESCRIPTION OF THE DRAWINGS
[0055] FIG1 is a schematic diagram of an implementation environment of the method provided in an embodiment of the present application;
[0056] FIG2 is a schematic diagram of another implementation environment of the method provided in an embodiment of the present application;
[0057] FIG3 is a flow chart of a message transmission method provided in an embodiment of the present application;
[0058] FIG4 is a schematic diagram of obtaining a first address provided in an embodiment of the present application;
[0059] FIG5 is a flow chart of another message transmission method provided in an embodiment of the present application;
[0060] FIG6 is a schematic diagram of a process of a client registering as a registered user of a target service according to an embodiment of the present application;
[0061] FIG7 is a schematic diagram of a portal service access page provided in an embodiment of the present application;
[0062] FIG8 is a schematic diagram of a client outputting registration page related information provided by an embodiment of the present application;
[0063] FIG9 is a process diagram of a message transmission method provided in an embodiment of the present application;
[0064] FIG10 is a schematic structural diagram of a message transmission device provided in an embodiment of the present application;
[0065] FIG11 is a schematic structural diagram of another message transmission device provided in an embodiment of the present application;
[0066] FIG12 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application;
[0067] FIG13 is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;
[0068] FIG14 is a schematic diagram of network connections of one or more computing devices in a computing device cluster provided by an embodiment of the present application. DETAILED DESCRIPTION
[0069] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.
[0070] To facilitate understanding, the technology and background involved in the embodiments of this application are explained below.
[0071] 1) Distributed denial of service (DDOS) attacks
[0072] A DDOS attack generally refers to a network attack that uses reasonable service requests to occupy excessive service resources, thereby preventing legitimate users from receiving service responses.
[0073] Common but difficult to defend against DDOS attacks include but are not limited to the following:
[0074] A. Elephant Flow Attack: This attack involves a large number of continuous attempts to access a target service through a single network connection. Because an Elephant Flow attack focuses on a single network connection, it is difficult to mitigate by distributing the attack to multiple central processing units (CPUs).
[0075] B. Real source attack: This refers to an attack using multiple real hosts as attack sources, making the attack behavior of these hosts difficult to distinguish from normal and legitimate users;
[0076] C. Segment sweep attack: Between the elephant flow attack and the real source attack, the segment sweep attack performs a scanning attack on continuous Internet Protocol (IP) address segments. Therefore, the traffic of the segment sweep attack is dispersed over multiple target IP addresses. The traffic attacking each target IP address is not large, but the traffic attacking all target IP addresses together is very large. It is generally difficult to detect the attack pattern and prevent it.
[0077] Among the current mainstream DDOS attacks, the gaming industry accounts for approximately half. Other targets include corporate websites and e-commerce networks. Corporate websites are generally accessible from any source IP address or user, without requiring pre-registration. However, gaming and e-commerce networks require pre-registration of users or source IP addresses, and only successfully registered users or source IP addresses are allowed access.
[0078] 2) Network Address Translation (NAT)
[0079] NAT is a technology used to use private addresses within a local network and global IP addresses when connecting to the Internet.
[0080] For example, when a host on a local network sends a message to the internet, a boundary device located at the edge of the local network uses NAT to translate the message's source address into the local network's global IP address on the internet. The pre-NAT source address in the message is the host's private address on the local network. For another example, when a message from the internet is sent to a host on a local network, a boundary device located at the edge of the local network uses NAT to translate the message's destination address into the host's private address on the local network. The pre-NAT destination address in the message is the local network's global IP address on the internet.
[0081] 3) Closed network
[0082] A closed network is one in which connections between nodes are relatively closed, meaning that connections between nodes are relatively independent and restricted. In a closed network, the connections between nodes are typically predetermined, and communication is often restricted to specific nodes. This type of network structure is commonly found in private and local area networks (LANs), such as corporate intranets and home networks.
[0083] Currently, preventing DDOS attacks typically requires significant CPU power for analysis and processing. Therefore, whether using general-purpose computing resources (on the cloud or on servers), the cost of preventing and processing DDOS attacks is extremely high. Furthermore, due to the characteristics of Internet Protocol version 4 (IPv4) addresses, IPv4-based sweep attacks are difficult to prevent. Furthermore, IPv4 addresses are expensive and costly.
[0084] In some related technologies, the service messages sent by the client to the server carry features pre-negotiated between the client and the server. Forwarding nodes identify these features in the service messages, filtering out normal service traffic and forwarding it, while blocking abnormal traffic, thereby preventing DDOS attacks. However, this approach requires implementation at the application layer, resulting in a high processing cost for forwarding nodes (such as routers or gateways) to identify these features in service messages.
[0085] Other related technologies build a tunnel between the client and server. When the server detects a DDOS attack, it migrates the tunnel between the client and server. Because the inner destination IP address of service packets transmitted through the tunnel remains unchanged, this approach can ensure service continuity for the client. However, building a tunnel between the client and server and subsequently migrating the tunnel in the event of a DDOS attack places high demands on the network and is technically complex to implement.
[0086] In other related technologies, a server providing services to clients deploys access gateways (or service gateways) in multiple locations, such as a multi-cloud deployment. When a DDOS attack is detected on one of the server's access gateways, traffic accessing the server's services is directed to bypass that access gateway and access the server's services through another access gateway. However, this approach is complex to manage and expensive.
[0087] Based on this, an embodiment of the present application provides a message transmission method, which pre-configures multiple Internet Protocol version 6 (IPv6) addresses (referred to as pre-configured addresses) for a target service, and detects whether the destination address of a target service message accessing the target service is the pre-configured address pre-issued to the client that initiated the target service message, and, when it is determined that the destination address of the target service message is the pre-configured address pre-issued to the client that initiated the target service message, forwards the target service message normally, for example, sends the target service message to the server that provides the target service. Through this method, since the IPv6 address space is huge and many of them are idle addresses, when a large number of pre-configured addresses are allocated to the server that provides the target service using the huge IPv6 address space, when the attack source attacks the target service provided by the server through a direct DDOS sweep attack, the direct DDOS sweep attack cannot be effectively carried out.
[0088] Refer to Figure 1, which is a schematic diagram of an implementation environment of the method provided by an embodiment of the present application. As shown in Figure 1, the implementation environment is implemented as a message transmission system including a client and a server. Among them, the client transmits business messages to the server through a network (such as the Internet) to access the services provided by the server. Optionally, the network to which the client shown in Figure 1 belongs and the network to which the server belongs may be the same or different. When the network to which the client shown in Figure 1 belongs and the network to which the server belongs are the same, it means that the network where the client and the server are located is a closed network. By applying the method provided by an embodiment of the present application in this system, it is possible that in the process of the client accessing the server through a business message, when the attack source attacks the service provided by the server through a direct DDOS sweep attack, the direct DDOS sweep attack cannot be effectively carried out.
[0089] Exemplarily, a server includes, but is not limited to, an application server that provides one or more services. The services provided by the application server include, but are not limited to, gaming services, e-commerce services, media services, social services, etc. Furthermore, an exemplary client includes, but is not limited to, a mobile phone, laptop computer, tablet computer, desktop computer, in-vehicle device, or other smart device that provides client functionality.
[0090] Illustratively, the service provided by the application server may be run on at least one server in at least one cloud data center located in one of the multiple regions, which is not limited to this.
[0091] Refer to Figure 2, which is a schematic diagram of another implementation environment of the method provided by the embodiment of the present application. In combination with Figure 1, as shown in Figure 2, the server of the message transmission system only provides services to registered users. Therefore, the client can first access the registration service through the portal service (such as the portal website of the game application, etc.) of the service provided by the server (such as the target service) to register as a registered user of the service provided by the server, and then the client accesses the target service as a registered user. When the method provided by the embodiment of the present application is applied when the client accesses the target service as a registered user, when the attack source attacks the target service through a direct DDOS sweep attack, the direct DDOS sweep attack cannot be carried out effectively. Among them, the portal service is provided by a portal service device, and the portal service device is, for example, a portal server, etc. The registration service is provided by a registration service device, and the registration service device is, for example, a registration server, etc.
[0092] It should be understood that the above content is an illustrative description of the implementation environment of the method provided in the embodiment of the present application, and does not constitute a limitation on the implementation environment of the method. A person skilled in the art will know that as business needs change, the implementation environment can be adjusted according to application requirements, and the embodiments of the present application do not list them one by one.
[0093] The present application also provides a message transmission device, which can be implemented in hardware and / or software. The message transmission device can be applied to a security module on a server or a client accessing services provided by the server, thereby causing the security module on the server and the client to perform the corresponding steps of the method described below. As an example, the server can be the server shown in Figure 1 or Figure 2, and the client can be the client shown in Figure 1 or Figure 2.
[0094] When the message transmission device is applied to a security module on the server side, the message transmission device can be implemented as a security module deployed on the server side or a functional module within the security module. For example, if the security module is a firewall installed on the server side, the message transmission device can be implemented as a functional module of the firewall.
[0095] Alternatively, when the message transmission device is implemented in a server-side security module, the message transmission device can also be implemented as a forwarding node or a functional module within the forwarding node that forwards service messages from the client to the server, without limitation. The forwarding node can be any node / device with message forwarding processing capabilities. By way of example, the forwarding node is a network device such as a router, switch, or gateway on the communication link between the client and the server, but is not limited thereto.
[0096] When a message transmission device is used as a client accessing services provided by a server, the device can be a terminal device used to implement client functions, or a functional module in the terminal device, without limitation. Terminal devices include, but are not limited to, mobile phones, laptops, tablets, desktop computers, in-vehicle devices, or other smart devices.
[0097] The following describes the implementation process of the message transmission method provided in the embodiment of the present application.
[0098] Referring to Figure 3, Figure 3 shows a flow chart of a message transmission method provided by an embodiment of the present application. Optionally, the method can be applied to the implementation environment shown in Figure 1 or Figure 2. For the sake of simplicity, the following description is taken as an example of a client accessing a certain service provided by a server (denoted as the target service) and the security module of the server executing the corresponding steps of the method described in the embodiment of the present application. Optionally, the target service can run on at least one server located in at least one cloud data center in one of multiple regions. As shown in Figure 3, the method includes the following steps.
[0099] Step 101: The client obtains a destination address of a target service message to be sent. The destination address is one of the preconfigured addresses. The preconfigured address is an IPv6 address configured for the client to access a target service.
[0100] The client is a registered user of the target service provided by the server. By accessing the pre-configured address, the client can access the target service provided by the server. Exemplary target services include but are not limited to gaming services, e-commerce services, media services, social services, etc.
[0101] In the embodiment of the present application, the preconfigured address is an IPv6 address with a length of 128 bits. Since the address space of IPv6 addresses is huge, the method of the embodiment of the present application can allocate a huge address space to the target service, thereby preventing the attack source from directly attacking the target service provided by the server through a direct DDOS sweep attack.
[0102] For any preconfigured address, the preconfigured address is composed of a pre-set field and a verification field. Therefore, when the length of the pre-set field is x bits, the length of the verification field is y=(128-x) bits.
[0103] Among them, the embodiment of the present application configures at least one preset field for the target service. In some examples, the preset field is the network prefix of the network where the server providing the target service is located (such as a network prefix with a length of 64 bits or 96 bits), or the preset field is composed of the network prefix of the network where the server providing the target service is located and the subnet address of the server in the network (such as a subnet address with a length of 16 bits or 32 bits), and there is no limitation on this. Optionally, different preset fields configured for the target service can be used to configure preconfigured addresses for accessing the target service for clients located in different regions.
[0104] In addition, the verification field in the preconfigured address can be calculated based on any of the following preset rules. Taking the length of the verification field as y bits as an example, the preset rules include but are not limited to: (1) the verification field is calculated based on the y bits in the source address of the client accessing the target service, a preset value of y bits in length, and any logical operation algorithm; (2) the verification field is calculated based on the y bits in the preset field configured for the target service, a preset value of y bits in length, and any logical operation algorithm; (3) the verification field is calculated based on the y bits in the source address of the client accessing the target service, the y bits in the preset field configured for the target service, and any logical operation algorithm. It can be seen that the preset rules are used to determine the verification field in the preconfigured address based on logical operations. Among them, the logical operations include but are not limited to logical AND operations, logical OR operations, or logical XOR operations. The source address of the client accessing the target service can be a 32-bit IPv4 address or a 128-bit IPv6 address, without limitation. In addition, the y bit in the client source address (or the preset field configured for the target service) can be the upper y bit in the client source address (or the preset field configured for the target service), the lower y bit in the client source address (or the preset field configured for the target service), or the middle y bit in the client source address (or the preset field configured for the target service). It should be understood that the y bit in the client source address (or the preset field configured for the target service) can be a continuous y bit in the client source address (or the preset field configured for the target service) or a discontinuous y bit, without limitation. In addition, the embodiments of the present application do not specifically limit the above-mentioned preset value.
[0105] Taking the preconfigured address as the destination address of the target service message as an example, the destination address is composed of a first preset field configured for the target service and a first verification field calculated according to a first preset rule. Referring to FIG4 , FIG4 shows a schematic diagram of obtaining the first address. As shown in FIG4 , when the source address of the client accessing the target service using the first address is a, the first preset field is the network prefix of the network where the server providing the target service is located (denoted as the server network prefix) b, the length x of b is 96 bits, the length y of the first verification field is (128-96=32) bits, and the first preset rule is based on the lower y bits of the source address of the client accessing the target service, the lower y bits of the first preset field configured for the target service, and a logical exclusive OR (symbol "⊕") operation to obtain the verification field, the first verification field c = (the lower 32 bits of a) ⊕ (the lower 32 bits of b), and the first address is formed by concatenating b and c. It should be understood that when x is 32 bits, the length of c is also 32 bits.
[0106] In the embodiments of the present application, a preset rule for calculating a validation field in a preconfigured address and a preset field in the preconfigured address are referred to as a set of preset rules and preset fields having a corresponding relationship, and are denoted as a combination. For example, a first preset rule for calculating a first validation field in a destination address of a target service message and a first preset field in the destination address are referred to as a first combination, and the first preset rule and the first preset field in the first combination have a corresponding relationship.
[0107] Specifically, when the client needs to access the target service provided by the server, it obtains the destination address of the target service message.
[0108] In the first possible implementation, the client obtains the destination address of the target service message, including: after the client determines that it has registered as a registered user of the target service, it obtains a first preset rule, determines a first verification field based on the obtained first preset rule, and determines the destination address of the target service message based on the first verification field. Among them, the first preset rule is used to determine the verification field (such as the first verification field) in the preconfigured address based on a logical operation, and the first verification field is used to verify whether the destination address of the target service message is a preconfigured address. The following describes the process of the client obtaining the destination address of the target service message under different situations (including situations 1 to 4) of this implementation.
[0109] In Case 1, the client pre-sets multiple combinations corresponding to the target service, each combination including one of multiple preset rules and one of multiple preset fields configured for the target service. In this case, the client obtains a first preset rule, including: selecting a combination from the multiple preset combinations as the first combination according to a first policy, determining the preset rule in the first combination as the first preset rule, and determining the preset field in the first combination as the first preset field. Furthermore, after the client determines the first verification field according to the first preset rule, the client determines the destination address of the target service message based on the first verification field, including: concatenating the first preset field and the first verification field to obtain the destination address of the target service message. The process of determining the first verification field according to the first preset rule by the client can be referred to the relevant description of FIG. 4 and will not be repeated here. Furthermore, the first policy is not specifically limited in this embodiment of the present application. For example, the first policy is a polling policy. For another example, the first policy includes: selecting combination 1 in time period 1, selecting combination 2 in time period 2, and so on. This is not a limitation.
[0110] In some examples, when the client accessing the target service and the server providing the target service belong to the same closed network, the client can obtain the destination address of the target service message using the method described in Case 1.
[0111] In case 2, the client has multiple preset rules pre-set, and the network control device or registration service device of the network where the server is located has multiple preset fields configured for the target service, or the domain name system (DNS) has multiple preset fields pre-set corresponding to the domain name of the target service. The multiple preset fields corresponding to the domain name of the target service are multiple preset fields configured for the target service. The network control device is the network control device of the network where the server providing the target service is located. The registration service device is used to provide user registration services for one or more services, including the target service. In this case, the client obtains a first preset rule, including selecting a preset rule from the multiple preset rules as the first preset rule according to the second policy. Next, the client sends an address acquisition request to the DNS, which carries the domain name of the target service and the first preset rule. The DNS then queries the multiple preset fields corresponding to the domain name of the target service carried in the address acquisition request, selects a preset field from the multiple preset fields according to the third policy, and returns it to the client as the first preset field. The DNS also sends the selected first preset field and the received first preset rule as a first combination to the gateway of the server providing the target service. Alternatively, the client sends an address acquisition request to the aforementioned network control device (or registration service device), the request carrying an identifier (ID) of the target service and a first preset rule. In this way, the network control device (or registration service device) queries multiple preset fields configured for the target service based on the target service ID carried in the address acquisition request, and selects a preset field from the multiple preset fields according to a third policy as the first preset field and returns it to the client. Furthermore, the network control device (or registration service device) also sends the selected first preset field and the received first preset rule as a first combination to the gateway of the server providing the target service. In response, the client receives the first preset field returned by the DNS or the network control device (or registration service device), and the gateway of the server receives the first combination. Furthermore, after the client determines the first verification field based on the first preset rule, the client determines the destination address of the target service message based on the first verification field, including: concatenating the first preset field and the first verification field to obtain the destination address of the target service message. The descriptions of the second and third policies refer to the description of the first policy and are not repeated here. It should be understood that the second strategy and the third strategy may be the same as or different from the first strategy, and this is not limited to this. For example, the second strategy or the third strategy may be a polling strategy. In another example, the second strategy may include: selecting preset rule 1 in time period 1, selecting preset rule 2 in time period 2, etc. In another example, the third strategy may include: selecting preset field 1 in time period 1, selecting preset field 2 in time period 2, etc.For another example, the third strategy includes: selecting preset field 1 when the client is located in area 1, selecting preset field 2 when the client is located in area 2, and so on.
[0112] Case 3: The client has multiple preset fields configured for the target service, and the network control device or registration service device of the network where the server is located has multiple preset rules preset, or the DNS has multiple preset rules corresponding to the domain name of the target service preset. In this case, the client obtains the first preset rule, including: the client selects a preset field from a plurality of preset fields as the first preset field according to the third policy; then, the client sends an address acquisition request to the DNS, the request carrying the domain name of the target service and the first preset field, so that the DNS queries multiple preset rules corresponding to the domain name of the target service carried in the address acquisition request, selects one preset rule from the multiple preset rules as the first preset rule according to the second policy and returns it to the client, and the DNS also sends the selected first preset rule and the received first preset field as a first combination to the gateway of the server providing the target service; or, the client sends an address acquisition request to the aforementioned network control device (or registration service device), the request carrying the first preset field, so that the network control device (or registration service device) selects one preset rule from the multiple preset rules as the first preset rule according to the second policy in response to the address acquisition request and returns it to the client, and the network control device (or registration service device) also sends the selected first preset rule and the received first preset field as a first combination to the gateway of the server providing the target service. In response, the client receives a first preset rule returned by the DNS or network control device (or registration service device). The server's gateway receives the first combination. Furthermore, after the client determines the first verification field based on the received first preset rule, the client determines the destination address of the target service message based on the first verification field, including: concatenating the first preset field and the first verification field to obtain the destination address of the target service message. The descriptions of the second and third strategies refer to the above and are not repeated here.
[0113] In case 4, a network control device, a registration service device, or a DNS in the network where the server is located presets multiple combinations corresponding to the target service, each combination including one of multiple preset rules and one of multiple preset fields configured for the target service. In this case, the client obtains the first preset rule, including: the client sends an address acquisition request to the DNS, the request carrying the domain name of the target service, so that the DNS queries multiple combinations corresponding to the target service represented by the domain name based on the domain name of the target service carried in the address acquisition request, and then selects a combination from the multiple combinations as the first combination according to a first strategy, and sends the first combination to the client and the gateway of the server providing the target service; or the client sends an address acquisition request to the aforementioned network control device (or registration service device), the request carrying the ID of the target service, so that the network control device (or registration service device) queries multiple combinations corresponding to the target service represented by the ID based on the ID of the target service carried in the address acquisition request, and then selects a combination from the multiple combinations as the first combination according to the first strategy, and sends the first combination to the client and the gateway of the server providing the target service. In response, the gateways of the client and the server both receive the first combination sent by the DNS or the network control device (or the registration service device). Thus, the client determines the preset field in the received first combination as the first preset field, and determines the preset rule in the first combination as the first preset rule. Furthermore, after the client determines the first verification field according to the first preset rule, the client determines the destination address of the target business message according to the first verification field, including: splicing the first preset field and the first verification field to obtain the destination address of the target business message. Among them, the description of the first strategy is referred to above and will not be repeated here.
[0114] The second possible implementation method is that the client is pre-set with multiple pre-configured addresses configured for the target service, and the multiple pre-configured addresses can be multiple discrete IPv6 addresses, or one or more continuous IPv6 addresses. In this case, the client obtains the destination address of the target service message, including: after the client determines that it has registered as a registered user of the target service, it selects a pre-configured address from the preset multiple pre-configured addresses as the destination address of the target service message according to the fourth strategy. Among them, the fourth strategy and the above-mentioned first strategy, second strategy, and third strategy can be the same or different (such as the fourth strategy is a random selection strategy, etc.), and detailed descriptions can be referred to the above description and will not be repeated here. In some examples, when the client accessing the target service and the server providing the target service belong to the same closed network, the client can use this implementation method to obtain the destination address of the target service message.
[0115] In a third possible implementation, the client obtains the destination address of the target service message, including: after the client determines that it has registered as a registered user of the target service, directly obtaining the destination address of the target service message from the DNS, the aforementioned network control device, or the registration service device. The following describes the process of the client directly obtaining the destination address of the target service message from the DNS, the aforementioned network control device, or the registration service device under different scenarios (including scenarios 5 to 7) in this implementation.
[0116] Case 5: Multiple preconfigured addresses configured for the target service are preset in the DNS, the above-mentioned network control device or the registration service device. The multiple preconfigured addresses can be multiple discrete IPv6 addresses, or one or more continuous IPv6 addresses, but are not limited thereto. In this case, the client directly obtains the destination address of the target service message from the DNS, the above-mentioned network control device, or the registration service device, including: the client sends an address acquisition request to the DNS, the request carrying the domain name of the target service, so that the DNS queries multiple pre-configured addresses configured for the target service represented by the domain name based on the domain name carried in the address acquisition request, selects a pre-configured address from the multiple pre-configured addresses as the destination address of the target service message according to the fourth strategy and returns it to the client, and sends the pre-configured address as the destination address of the target service message to the gateway of the server providing the target service; or, the client sends an address acquisition request to the network control device (or registration service device), the request carrying the ID of the target service, so that the network control device (or registration service device) queries multiple pre-configured addresses configured for the target service represented by the ID based on the ID of the target service carried in the address acquisition request, selects a pre-configured address from the multiple pre-configured addresses as the destination address of the target service message according to the fourth strategy and returns it to the client, and sends the pre-configured address as the destination address of the target service message to the gateway of the server providing the target service. In response, both the client and server gateways receive the pre-configured address sent by the DNS, network control device, or registration service device as the destination address of the target service message.
[0117] Case 6: Multiple combinations corresponding to the target service are preset in the DNS, the above-mentioned network control device or the registration service device, and each combination includes one preset rule among multiple preset rules and one preset field among multiple preset fields configured for the target service. In this case, the client directly obtains the destination address of the target service message from the DNS, the above-mentioned network control device or the registration service device, including: the client sends an address acquisition request to the DNS, and the request carries the domain name of the target service. In this way, the DNS queries the multiple combinations corresponding to the target service represented by the domain name according to the domain name carried in the address acquisition request, and selects one combination from the multiple combinations as the first combination according to the first strategy. Then, the DNS determines the first verification field according to the first preset rule in the first combination, and splices the first verification field and the first preset field in the first combination to obtain the destination address of the target service message. Then, the DNS returns the destination address to the client, and the DNS also sends the first combination or the destination address to the gateway of the server providing the target service; or, the client sends a query to the network The control device (or registration service device) sends an address acquisition request, which carries the ID of the target service. In this way, the network control device (or registration service device) queries multiple combinations corresponding to the target service represented by the ID of the target service carried in the address acquisition request, and selects one combination from the multiple combinations as the first combination according to the first strategy. Then, the network control device (or registration service device) determines the first verification field according to the first preset rule in the first combination, and splices the first verification field and the first preset field in the first combination to obtain the destination address of the target service message. Then, the network control device (or registration service device) returns the destination address to the client, and the network control device (or registration service device) also sends the first combination or the destination address to the gateway of the server providing the target service. In response, the client receives the destination address returned by the DNS, the network control device or the registration service device, and the gateway of the server receives the first combination or the destination address sent by the DNS, the network control device or the registration service device.
[0118] Case 7, each combination corresponding to the target service includes the above-mentioned preset rule and a preset field. For any combination, the preset rule and preset field in the combination are called two elements in the combination (recorded as the first element and the second element). In this case, when multiple first elements are preset in the client and multiple second elements are preset in the DNS, the above-mentioned network control device or the registration service device, the client directly obtains the destination address of the target service message from the DNS, the above-mentioned network control device or the registration service device, including: the client selects a first element from the preset multiple first elements according to the fifth strategy; in one example, the client then sends an address acquisition request to the DNS, which carries the domain name of the target service and the first element selected by the client. In this way, the DNS queries the multiple second elements corresponding to the target service represented by the domain name according to the domain name carried in the address acquisition request, and selects a second element from the multiple second elements according to the sixth strategy. Then, the DNS determines the destination address of the target service message based on the first combination composed of the received first element and the selected second element, and then, the DNS returns the destination address to the client. , and the DNS also sends the first combination or the destination address to the gateway of the server providing the target service; in another example, the client sends an address acquisition request to the network control device (or registration service device), which carries the ID of the target service and the first element selected by the client. In this way, the network control device queries multiple second elements corresponding to the target service represented by the ID based on the ID of the target service carried in the address acquisition request, and selects a second element from the multiple second elements according to the sixth strategy. Then, the network control device (or registration service device) determines the destination address of the target service message based on the first combination of the received first element and the selected second element. Then, the network control device (or registration service device) returns the destination address to the client, and the network control device (or registration service device) also sends the first combination or the destination address to the gateway of the server providing the target service. In response, the client receives the destination address returned by the DNS, the network control device, or the registration service device, and the gateway of the server receives the first combination or the destination address sent by the DNS, the network control device, or the registration service device. The detailed description of the fifth and sixth strategies can refer to the above description of the first, second, third and fourth strategies, which will not be repeated here.
[0119] It should be understood that, when in the first possible implementation method, the first preset rule obtained by the client is the first preset rule received from the DNS, network control device or registration service device, then when the preset duration is reached, the client may also receive the second preset rule, and the second preset rule is the preset rule after the first preset rule is updated. Alternatively, when the first preset field obtained by the client is the first preset field received from the DNS, network control device or registration service device, then when the preset duration is reached, the client may also receive the second preset rule and / or the second preset field. The second preset rule is the preset rule after the first preset rule is updated, and the second preset field is a field different from the first preset field. Furthermore, the client can determine the second verification field according to the second preset rule, and determine another destination address of the target service message according to the second verification field and the second preset field. The embodiment of the present application does not specifically limit the value of the preset duration.
[0120] In this way, when the client receives the preset rules and / or preset fields at regular intervals, it can periodically obtain different preconfigured addresses for accessing the target service. This allows the client to regularly update the preconfigured address used as the destination address when accessing the target service. This makes it difficult for attackers to accurately parse the target service's access address and launch attacks against it.
[0121] When, in a second possible implementation, the client obtains the destination address of the target service message from multiple pre-configured addresses preset by the client, upon expiration of a preset time period, the client obtains another destination address of the target service message from the multiple pre-configured addresses preset by the client. When, in a third possible implementation, the client obtains the destination address of the target service message directly from a DNS, the aforementioned network control device, or a registration service device, upon expiration of a preset time period, the client obtains another destination address of the target service message from the DNS, the aforementioned network control device, or the registration service device.
[0122] In this way, when the client directly obtains the preconfigured address for accessing the target service at regular intervals, it can periodically obtain different preconfigured addresses for accessing the target service. This allows the client to regularly update the preconfigured address used as the destination address when accessing the target service. This makes it difficult for attackers to accurately resolve the target service's access address and launch attacks against it.
[0123] It should be noted that, every time the client obtains a preconfigured address for accessing the target service from other devices / equipment (such as DNS, network control device, registration service device, etc.), and the other device / equipment is pre-set with multiple preconfigured addresses for accessing the target service, the other device / equipment will simultaneously send the preconfigured address sent to the client to the gateway of the server that provides the target service. Every time the client obtains a preconfigured address for accessing the target service from other devices / equipment, and the other device / equipment is pre-set with preset rules and / or preset fields for determining the preconfigured address, the other device / equipment will simultaneously send the preconfigured address sent to the client to the gateway of the server that provides the target service, or the other device / equipment will simultaneously send a combination of preset rules and / or preset fields sent to the client to the gateway of the server that provides the target service. For detailed descriptions, please refer to the relevant descriptions in "the first possible implementation method" to "the third possible implementation method", which will not be repeated here.
[0124] A fourth possible implementation method is that when a client needs to access a target service for the first time, it must first obtain the access address of the target service's registration service and register through the registration service, thereby becoming a registered user of the target service. The registration service device then configures and proactively sends the destination address of the target service message to the client that has become a registered user of the target service. Alternatively, the registration service device instructs the DNS or network control device to configure and proactively send the destination address of the target service message to the client that has become a registered user of the target service. In response, the client can obtain the destination address of the target service message sent by the registration service device, DNS, or network control device. The registration service device is used to provide user registration services for one or more services, including the target service. For example, the registration service device is a registration server that provides user registration functions for the service. The detailed process of the client obtaining the access address of the registration service and registering through the registration service, thereby becoming a registered user of the target service, is described below and will not be repeated here. In this way, by only sending the pre-configured address of the target service to registered users, it is possible to avoid real source attacks in DDOS attacks. The following takes the case where the registration service device proactively configures and sends the destination address of the target service message for the client as an example, and describes the process of the registration service device sending the destination address of the target service message under the following different situations (including situations 8 to 10).
[0125] In scenario 8, the registration service device has multiple preconfigured addresses configured for the target service. Therefore, after registering the client as a registered user of the target service, the registration service device selects one of the multiple preconfigured addresses according to the fourth policy as the destination address of the target service message and sends it to the client. The destination address is also sent to the gateway of the server providing the target service. In response, the client and the gateway of the server receive the destination address of the target service message for accessing the target service.
[0126] Optionally, after registering the client as a registered user of the target service, the registration service device may periodically select a different preconfigured address from the plurality of preconfigured addresses according to the fourth policy as the destination address of the target service message and send it to the client and server gateway. In response, the client and server gateway may periodically receive different preconfigured addresses for accessing the target service. Thus, when the client needs to access the target service, it determines the most recently received preconfigured address as the destination address of the target service message.
[0127] Case 9, the registration service device is pre-set with multiple combinations corresponding to the target service, and each combination includes a preset rule among multiple preset rules and a preset field among multiple preset fields configured for the target service. In this case, after the registration service device registers the client as a registered user of the target service, the registration service device selects a combination as the target combination (such as the first combination) from the multiple combinations corresponding to the target service according to the first strategy, and determines a pre-configured address as the destination address of the target business message according to the preset rules and preset fields in the target combination, and sends the pre-configured address to the client and the gateway of the server providing the target service. In response, the client and the gateway of the server receive a pre-configured address for accessing the target service. Among them, the process of the registration service device determining the first pre-configured address according to the preset rules and preset fields of the target combination can refer to the relevant description of determining the destination address of the target business message in Figure 4 above, and will not be repeated here.
[0128] Optionally, after registering the client as a registered user of the target service, the registration service device may also periodically determine different target combinations according to the first strategy, and determine a preconfigured address as the destination address of the target service message based on the preset rules and preset fields in the target combination determined in each cycle, and send the preconfigured address determined in each cycle to the client and the gateway of the server that provides the target service. In response, the client and the gateway of the server periodically receive the preconfigured address for accessing the target service sent by the registration service device. Thus, when the client needs to access the target service, it determines the most recently received preconfigured address as the destination address of the target service message.
[0129] Case 10: Multiple combinations corresponding to the target service are preset in the registration service device, and each combination includes a preset rule among multiple preset rules and a preset field among multiple preset fields configured for the target service. In this case, after the registration service device registers the client as a registered user of the target service, the registration service device selects a combination as the target combination (such as the first combination) from the multiple combinations corresponding to the target service according to the first strategy, and sends the target combination to the client and the gateway of the server that provides the target service. In response, the client and the gateway of the server receive the target combination. Furthermore, the client can determine the verification field according to the preset rules in the received target combination, and splice the verification field and the preset field in the target combination to obtain a preconfigured address for accessing the target service, and the preconfigured address is used as the destination address of the target service message.
[0130] Optionally, after registering the client as a registered user of the target service, the registration service device may also periodically select different target combinations from multiple combinations corresponding to the target service according to the first strategy, and send the target combination selected in each cycle to the client and the gateway of the server that provides the target service. In response, the client and the gateway of the server periodically receive different target combinations. Thus, when the client needs to access the target service, it determines the most recently received target combination as the first combination, and determines the destination address of the target service message based on the first preset field and the first preset rule in the first combination.
[0131] It can be understood that in a scenario where the server only provides the target service to registered users of the target service, when the registration service device periodically sends a preconfigured address and / or a combination of preset rules and preset fields to the client, the embodiment of the present application does not limit the specific value of the period duration.
[0132] As can be seen from the above, when the server only provides services to registered users of the target service, different registered users obtain different pre-configured addresses as the destination addresses of the target service messages. Therefore, even if a large number of registered users access the target service simultaneously, because these registered users obtain different pre-configured addresses for accessing the target service, each of these registered users establishes a network connection (such as a Transmission Control Protocol (TCP) connection or a User Datagram Protocol (UDP) connection) with the server providing the target service. As a result, the traffic accessing the target service can be dispersed across the network connections between different registered users and the server providing the target service. Furthermore, the server can distribute the traffic accessing the target service but located on different network connections across multiple CPUs for concurrent processing, thereby mitigating the elephant flow attack in DDOS attacks.
[0133] Optionally, in some embodiments, when obtaining the destination address of the target service message, the client also simultaneously obtains the destination port and / or communication protocol type used when accessing the target service, where the destination port and / or communication protocol type corresponds to the destination address of the target service message. The following uses Examples 1 to 4 to illustrate the process of a client obtaining the destination port and / or communication protocol type corresponding to the destination address of the target service message.
[0134] In Example 1, each of the multiple combinations preset by the client corresponding to the target service includes, in addition to a preset rule and a preset field configured for the target service, a port and / or a communication protocol type configured for the target service. Thus, when the client selects a first combination from the preset combinations, it can determine the port in the first combination as the destination port corresponding to the destination address of the target service message, and determine the communication protocol type in the first combination as the communication protocol type corresponding to the destination address of the target service message.
[0135] In Example 2, each of the multiple preconfigured addresses preset by the client is configured with a corresponding port and / or communication protocol type. Thus, when the client selects the destination address of a target service message from the preset preconfigured addresses, it can also determine the port and / or communication protocol type corresponding to the destination address of the target service message.
[0136] Example 3: Each of the multiple combinations corresponding to the target service pre-set in devices such as DNS / network control device / registration service device, in addition to including a preset rule and a preset field configured for the target service, also includes a port and / or a communication protocol type configured for the target service. In this way, the client can obtain a combination preset by these devices from devices such as DNS / network control device / registration service device, such as the first combination, so that the client determines the port in the first combination as the destination port corresponding to the destination address of the target business message, and determines the communication protocol type in the first combination as the communication protocol type corresponding to the destination address of the target business message.
[0137] In Example 4, each of the multiple preconfigured addresses preset by a device such as a DNS / network control device / registration service device is configured with a corresponding port and / or communication protocol type. Thus, when a client obtains a preconfigured address preset in the DNS / network control device / registration service device as the destination address of a service message, it also obtains the port and / or communication protocol type corresponding to the preconfigured address from the DNS / network control device / registration service device.
[0138] It should be noted that Examples 1 to 4 above are limited examples and do not constitute a limitation on the scope of protection of the examples of this application. Any method that enables a client to obtain the port and / or communication protocol type corresponding to a preconfigured address, or any method that enables a client to obtain a port and / or a communication protocol type in a combination of a preset rule and a preset field, is within the scope of protection of the embodiments of this application.
[0139] Step 102: The client sends a target service message, which is used to access a target service.
[0140] The client first generates a target service message based on the service content / data and the destination address of the newly acquired target service message, and then sends the target service message. Since the destination address of the target service message is one of the pre-configured addresses configured for the target service, the target service message is used to access the target service.
[0141] Optionally, when the client further obtains the destination port and / or communication protocol type corresponding to the destination address of the target service message in step 101, the IP header of the target service message further includes the destination port and / or communication protocol type.
[0142] Exemplarily, the client sends the target service message through its own communication interface.
[0143] Step 103: The security module of the server receives the target service message sent by the client.
[0144] Taking the example that the security module of the server is implemented by a gateway deployed on the server (denoted as a service gateway), in response to step 102, the service gateway receives the target service message sent by the client through its own communication interface.
[0145] Step 104: The security module of the server verifies the destination address of the target service message according to the verification field included in the destination address of the target service message to determine that the destination address of the target service message is a preconfigured address, and sends the target service message to the server.
[0146] For a detailed description of the pre-configured address, please refer to the relevant description of step 101 and will not be repeated here.
[0147] Taking the example of a service gateway implementing the security module on the server side, in an embodiment of the present application, the service gateway pre-acquires at least one combination corresponding to the target service, and / or the service gateway pre-acquires at least one pre-configured address configured for the target service. Each combination corresponding to the target service includes one of a plurality of pre-set rules and one of a plurality of pre-set fields configured for the target service. The set consisting of the plurality of pre-configured addresses pre-acquired by the service gateway is referred to as a release list.
[0148] Exemplarily, in some possible situations, when multiple combinations corresponding to the target service are pre-set in the client, such as the situation 1 described above, the server is also pre-configured (such as manually configured) with the multiple combinations. In other possible situations, such as situations 2 to 10 described above, the service gateway is able to receive the combination or pre-configured address corresponding to the target service sent by the DNS, network control device or registration service device. For detailed descriptions, please refer to the relevant descriptions of situations 2 to 10 above. In some other possible situations, when multiple pre-configured addresses configured for the target service are pre-set in the client, such as the situation described in the "second possible implementation method" above, the service gateway is also pre-configured (such as manually configured) with the multiple pre-configured addresses.
[0149] Optionally, when the client also obtains the destination port and / or communication protocol type corresponding to the destination address of the target service message in step 101, each combination of at least one combination corresponding to the target service pre-acquired by the service gateway includes, in addition to the preset fields and preset rules with corresponding relationships, the corresponding port and / or communication protocol type. When the service gateway pre-acquires the preconfigured address configured for the target service, it also obtains the port and / or communication protocol type configured for the preconfigured address.
[0150] As an example, in some possible situations, such as the situation described in Example 1 above, the service gateway is pre-set with combinations that are the same as those preset by the client, and each combination includes a preset rule, a preset field configured for the target service, and a port and / or a communication protocol type. In other possible situations, such as the situation described in Example 2 above, the service gateway is pre-set with pre-configured addresses that are the same as the pre-configured addresses preset by the client, and each pre-configured address is also configured with a corresponding port and / or communication protocol type. In some other possible situations, such as the situation in Example 3 described above, when the client obtains a combination from a device such as a DNS / network control device / registration service device, the DNS / network control device / registration service device and other devices will also send the combination to the service gateway, so that the service gateway obtains the combination. In some other possible situations, such as the situation in Example 4 described above, when the client obtains a preconfigured address and a port and / or communication protocol type corresponding to the preconfigured address from a device such as a DNS / network control device / registration service device, the DNS / network control device / registration service device and other devices will also send the preconfigured address and the port and / or communication protocol type corresponding to the preconfigured address to the service gateway.
[0151] Specifically, after receiving the target service message, the service gateway first extracts the destination address of the target service message. It should be understood that the destination address of the target service message received by the server-side security module includes a verification field and a preset field. For ease of description, the following description uses the example where the verification field included in the destination address of the target service message is the first verification field described above, and the preset field included in the destination address of the target service message is the first preset field described above.
[0152] Then, in a possible implementation, the service gateway obtains a first preset rule corresponding to the first preset field included in the destination address of the target service message, and the first preset rule is used to determine the verification field in the preconfigured address based on a logical operation. Specifically, the service gateway pre-acquires at least one combination corresponding to the target service. Therefore, after extracting the destination address of the target service message from the received target service message, the service gateway traverses the combination pre-acquired by the service gateway according to the first preset field in the destination address of the target service message, thereby querying the first combination including the first preset field, and the preset rule in the first combination is the first preset rule corresponding to the first preset field. Furthermore, the service gateway calculates the target verification field according to the first preset rule. The service gateway compares the calculated target verification field with the first verification field included in the destination address of the target service message, and processes the target service message according to the comparison result (recorded as the first comparison result). Optionally, when the client also obtains the destination port and / or communication protocol type corresponding to the destination address of the target business message in step 101, the service gateway also compares the destination port included in the target business message with the destination port in the first combination, and compares the communication protocol type included in the target business message with the communication protocol type in the first combination, and processes the target business message based on the comparison result (recorded as the second comparison result) and the aforementioned first comparison result.
[0153] When the first comparison result indicates that the target verification field calculated by the service gateway is the same as the first verification field included in the destination address of the target business message, the service gateway determines that the destination address of the target business message is a pre-configured address configured for the target service. At this point, the service gateway can determine that the target business message is a safe business message. Optionally, when the client also obtains a destination port and / or communication protocol corresponding to the destination address of the target business message in step 101, if the first comparison result indicates that the target verification field calculated by the service gateway is the same as the first verification field carried in the destination address of the target business message, and the second comparison result indicates that the destination port included in the target business message is the same as the destination port in the first combination, and indicates that the communication protocol type included in the target business message is the same as the communication protocol type in the first combination, then the service gateway determines that the target business message is a safe business message. Then, the service gateway forwards the target business message to the service end. Optionally, the service gateway also adds the destination address of the target business message to the release list, so that when a business message with the destination address being the destination address of the target business message is subsequently received, the release list can be directly queried, and the business message is forwarded to the server when the destination address of the target business message is included in the release list. Optionally, when the client also obtains the destination port and / or communication protocol corresponding to the destination address of the target business message in step 101, the service gateway also adds a triplet including the destination address of the target business message, the destination port corresponding to the destination address of the target business message, and the communication protocol type to the release list, so that when the triplet of the business message is subsequently received, the release list can be directly queried, and the business message is forwarded to the server when the triplet is included in the release list.
[0154] When the first comparison result indicates that the target verification field calculated by the service gateway is different from the first verification field included in the destination address of the target service message, the service gateway determines that the destination address of the target service message is not a pre-configured address configured for the target service. At this point, the service gateway determines that the target service message is not a secure service message. Optionally, when the client also obtains a destination port and / or communication protocol type corresponding to the destination address of the target service message in step 101, if the first comparison result indicates that the target verification field calculated by the service gateway is different from the first verification field included in the destination address of the target service message, and / or the second comparison result indicates that the destination port included in the target service message is different from the destination port in the first combination, and / or the second comparison result indicates that the communication protocol type included in the target service message is different from the communication protocol type in the first combination, then the service gateway determines that the target service message is not a secure service message. Then, the service gateway blocks the target service message. Here, blocking the target business message includes: discarding the target business message; or forwarding the target business message to the back-end network security device (such as a honeypot node, etc.) for collecting attack information. In this way, the network security device parses the target business message to obtain attack characteristics and related information related to the network attack, and subsequently applies these attack characteristics and related information related to the network attack to network security strategies, etc., which will not be repeated here.
[0155] In another possible implementation, the service gateway pre-acquires a pre-configured address configured for the target service. That is, the service gateway is configured with a release list consisting of multiple pre-configured addresses. In this case, after extracting the destination address of the target service message from the received target service message, the service gateway traverses the release list based on the destination address of the target service message to determine whether the destination address of the target service message exists in the release list.
[0156] When it is determined that the destination address of the target service message exists in the release list, and it is determined that the destination address of the target service message is a pre-configured address configured for the target service, the service gateway can determine that the target service message is a safe service message, and then the service gateway forwards the target service message to the server. Optionally, when the server also obtains the port and / or communication protocol type configured corresponding to the pre-configured address configured for the target service in advance, the release list includes at least one triple with a pre-configured address and a port and / or communication protocol type corresponding to the pre-configured address. Therefore, when the server also determines that the triple carried by the target service message exists in the release list, the service gateway forwards the target service message.
[0157] In some embodiments, if the service gateway determines that the destination address of the target service message is not on the release list, the service gateway may directly determine that the destination address of the target service message is not a pre-configured address configured for the target service, and in this case, the service gateway blocks the target service message. Alternatively, if the service gateway determines that the triplet carried by the target service message is not on the release list, the service gateway may directly determine that the triplet carried by the target service message is not a triplet configured for the target service, and in this case, the service gateway blocks the target service message.
[0158] In some other embodiments, the service gateway also pre-acquires at least one combination corresponding to the target service. At this time, after determining that the destination address of the target service message or the triplet carried by the target service message is not present in the release list, the service gateway can also traverse the combination pre-acquired by the service gateway based on the first preset field included in the destination address of the target service message extracted from the target service message to query whether there is a first combination including the first preset field in at least one combination pre-acquired corresponding to the target service, and the preset rule in the first combination is the first preset rule corresponding to the first preset field. Alternatively, the service gateway can also traverse the combination pre-acquired by the service gateway based on the first preset field, the destination port and the communication protocol type in the destination address of the target service message extracted from the target service message to determine whether there is a first combination including the first preset field, the destination port and the communication protocol type in at least one combination pre-acquired corresponding to the target service, and the preset rule in the first combination is the first preset rule corresponding to the first preset field. When the service gateway determines that the first combination does not exist in at least one combination pre-acquired corresponding to the target service, the service gateway blocks the target service message. When the service gateway determines that a first combination exists in at least one pre-acquired combination corresponding to the target service, the target verification field is calculated according to the first preset rule in the first combination. Then, the service gateway compares the calculated target verification field with the first verification field carried in the destination address of the target business message, and processes the target business message according to the comparison result, such as forwarding the target business message or blocking the target business message. For detailed instructions, please refer to the previous description and will not be repeated here.
[0159] In some embodiments provided herein, the service gateway is further configured with a blocking list, which is used to record the destination addresses of service messages that are prohibited from being forwarded. Exemplarily, the addresses in the blocking list can be IP addresses collected based on collected network attack information, or they can be the destination addresses of service messages that the service gateway has blocked historically. For example, if the service gateway blocks service messages sent to a certain destination address multiple times in a row according to the above implementation method, when the number of blocking times exceeds a threshold, the service gateway adds the destination address to the blocking list.
[0160] In this case, for the target service message received by the service gateway, the service gateway further traverses the blocking list based on the destination address of the target service message extracted from the target service message to determine whether the destination address of the target service message exists in the blocking list. When the service gateway determines that the destination address of the target service message exists in the blocking list, it indicates that the target service message with the destination address of the target service message is a message with a security issue, and the service gateway blocks the target service message.
[0161] It can be understood that the above-mentioned implementation methods of determining whether to forward or block a service message can be used alone or in combination, and there is no limitation on this.
[0162] Optionally, since in an embodiment of the present application the service end only provides the target service to the registered users of the target service, when the service gateway determines that the destination address of the target service message exists in the blocking list, the service gateway parses the target service message to obtain the user ID of the registered user who initiated the target service message, and determines the registered user represented by the user ID as a suspicious user, and records the suspicious user. In a possible implementation, the service gateway can record suspicious users through a suspicious user log. The suspicious user log includes at least one log record, and each log record is used to record a user ID determined by the service gateway as a suspicious user. In this way, after determining a suspicious user (such as the first user), the service gateway first traverses the suspicious user log based on the user ID of the first user (referred to as the first ID), and when there is no log record including the first ID in the suspicious user log, a new log record for recording the first ID is added to the suspicious user log.
[0163] Optionally, the service gateway also counts the number of times a suspicious user, as recorded in the suspicious user log, expects to access the back-end service via the service gateway. When the service gateway determines that the number of times the same registered user, as recorded in the suspicious user log, expects to access the back-end service via the service gateway exceeds a threshold, the service gateway determines the same user as a malicious user and adds the same registered user to a user blacklist. The user blacklist is used to record malicious users. In some examples, the user blacklist can be used as network security information in other security policies, which is not limited in the embodiments of the present application.
[0164] Exemplary, each log record in the suspicious user log is provided with a counter, and the counter is used to record the number of times that the suspicious user expects to access the back-end service through the service gateway. In this way, after determining a suspicious user (such as the first user), the service gateway traverses the suspicious user log based on the user ID of the first user (denoted as the first ID), and when there is no log record including the first ID in the suspicious user log, a new log record for recording the first ID is added in the suspicious user log, and a counter is set for the newly added log record. Thus, when the service gateway determines the first user as a suspicious user again according to the received business message, the service gateway traverses the suspicious user log according to the first ID, and when determining that there is a log record including the first ID in the suspicious user log, the counter of the log record is increased by one. When the service gateway determines that the current value of the counter of a certain log record in the suspicious user log and the difference between the initial value exceed a threshold value, it is determined that the number of times that the suspicious user expected to access the back-end service through the service gateway recorded by this log record exceeds the threshold value, thereby the service gateway determines the suspicious user as a malicious user, and adds the malicious user to the user blacklist.
[0165] Optionally, the service gateway can also be set to access the traffic limit of the target service within a preset duration for the same registered user. Since the service end only provides the target service to the registered users of the target service in the embodiment of the present application, the pre-configured addresses configured for the target service that different registered users obtain are different, and when a malicious user initiates a DDOS attack on the target service by communicating with the botnet, a large number of messages accessing the target service (i.e., DDOS attack messages) can be replayed. Therefore, by monitoring the size of the traffic of the target service accessed by a registered user within a preset duration, it is possible to identify whether the traffic is DDOS attack traffic. For example, when the size of the traffic of the target service accessed by a certain registered user within a preset duration exceeds a threshold, the service gateway determines that the traffic is DDOS attack traffic, so that the service gateway can determine the registered user who initiated the traffic as a malicious user, and add the malicious user to the above-mentioned user blacklist. In addition, by limiting the traffic limit of the target service accessed by the same registered user within a preset duration, the pressure on the back end (i.e., the service end) of the service gateway to process business messages can also be alleviated.
[0166] Optionally, the service gateway supports NAT translation. In this case, after determining that the destination address of the target service message is a pre-configured address configured for the target service, the service gateway performs NAT translation on the destination address of the target service message and uses the NATed address of the target service message as the new destination address of the target service message to send the target service message. In other words, the service gateway sends the target service message to the NATed address of the target service message. This will not be further described.
[0167] When the service gateway performs NAT translation on the message accessing the target service, the real IP address of the target service can be an IPv4 address or an IPv6 address, without limitation. It should be understood that the real IP address of the target service refers to the private network address of the server providing the target service in the network to which it belongs.
[0168] Through steps 101 to 104, due to the vast IPv6 address space, the embodiments of the present application can configure a large number of discrete preconfigured addresses for the target service by presetting or using the preset rules described above, and periodically send these discrete preconfigured addresses to the client. Since most of the addresses between the discrete preconfigured addresses are idle within the vast IPv6 address space, when the client uses the discrete preconfigured addresses configured for the target service to access the target service at different times, if the attack source attacks the target service through a direct DDOS sweep attack, the direct DDOS sweep attack will be ineffective.
[0169] In addition, since the service end only provides the target service to the registered users of the target service, the method provided by the embodiment of the present application can also identify and discover malicious users, thereby ensuring network security by timely discarding or isolating the messages of malicious users, and malicious users can also be included in the security information system for reference by other attack prevention systems. Since only registered users can obtain the pre-configured address configured for the target service, the real source attack in the DDOS attack can be avoided. In addition, when a large number of registered users access the target service at the same time, since the pre-configured addresses for accessing the target service obtained by these registered users are different, a network connection (such as a TCP connection or a UDP connection) is established between each of these registered users and the service end providing the target service, so that the traffic accessing the target service can be dispersed on the network connection between different registered users and the service end providing the target service, and then the service end can disperse the traffic accessing the target service but located on different network connections on multiple CPUs for concurrent processing, so that the elephant flow attack in the DDOS attack can be alleviated.
[0170] In other embodiments, in order to filter DDOS attack traffic at a location close to the source, refer to Figure 5, which shows a flow chart of another message transmission method provided by an embodiment of the present application. Optionally, the method can be applied to the implementation environment shown in Figure 1 or Figure 2. For simple description, the following is an example in which a client accessing a certain service provided by a server (denoted as the target service) and the security module of the server perform the corresponding steps of the method described in the embodiment of the present application, and the security module of the server is implemented by a service gateway. Optionally, the target service can run on at least one server in at least one cloud data center located in one of multiple regions. As shown in Figure 5, the method includes the following steps.
[0171] Step 201: The service gateway obtains at least one combination corresponding to a target service and / or at least one pre-configured address configured for the target service.
[0172] The service gateway obtains a detailed description of at least one combination corresponding to the target service and / or at least one preconfigured address configured for the target service. Please refer to the relevant description in step 104 above, which will not be repeated here.
[0173] Step 202: The service gateway sends at least one combination corresponding to the target service and / or at least one pre-configured address configured for the target service to a forwarding node reachable to the service gateway.
[0174] Since the set of multiple preconfigured addresses pre-acquired in the service gateway is called a release list, "the service gateway sends at least one combination corresponding to the target service and / or at least one preconfigured address configured for the target service to the forwarding node that is reachable to itself" can also be understood as the service gateway sending at least one combination corresponding to the target service or a release list to the forwarding node that is reachable to itself. For example, if the at least one combination corresponding to the target service acquired by the service gateway includes a first combination, and the first combination includes a first preset field and a first preset rule, then after acquiring the first combination, the service gateway can send the first preset rule and the first preset field in the first combination to the forwarding node that is reachable to itself.
[0175] Optionally, the forwarding nodes that can reach the service gateway include all nodes on the network that can reach the service gateway, or the forwarding nodes that can reach the service gateway include nodes that forward messages between the client accessing the target service and the service gateway. For example, the forwarding node is a message forwarding device such as a router or switch located in the Internet shown in Figure 1 or Figure 2, which is not limited to this.
[0176] Exemplarily, the service gateway can carry at least one combination and / or release list corresponding to the target service through the extended field of the border gateway protocol (BGP), thereby sending at least one combination or release list corresponding to the target service to the forwarding node that can reach itself.
[0177] By executing steps 201 to 202, after the forwarding nodes that forward messages between the client accessing the target service and the service gateway obtain at least one combination or release list corresponding to the target service, these forwarding nodes can execute step 104 described above for the received business messages, thereby forwarding or blocking these business messages, thereby filtering DDOS attack traffic at a location close to the client (i.e., the source end), thereby improving the impact of DDOS attacks on the communication network between the client and the service gateway.
[0178] The following detailed process of "a client obtaining the access address of a registration service and registering with the registration service to become a registered user of the target service" is described with reference to Figure 6 . Optionally, this process can be applied to the implementation environment shown in Figure 2 . As shown in Figure 6 , this process includes the following steps.
[0179] Step 301: The client sends a registration request to the portal service device.
[0180] For example, when the client needs to access the target service for the first time, it may first access the portal service of the target service, and in the process of accessing the portal service, send a registration request to the portal service device providing the portal service.
[0181] Referring to Figure 7, a schematic diagram of a portal service access page provided in an embodiment of the present application is shown. As shown in Figure 7, a client first searches the portal service's access address through a network search (web search) and then accesses the portal service's access address. The client then displays the portal service access page to the user via its own output interface (e.g., a display screen). For example, the client displays interface 700 shown in Figure 7 to the user via its own display screen. Interface 700 is the portal service's homepage. In this way, the client can communicate with the portal service device providing the portal service by responding to user input on the portal service access page.
[0182] Continuing with Figure 7, interface 700 may include a "Register" control, which is used to submit a registration request to the registration service. When a user using a client wishes to register as a registered user for a target service, the user performs an input operation (e.g., a click) on the "Register" control in interface 700 using an input interface of the client (e.g., a mouse, finger, stylus, etc.). In response to the user's input operation on the "Register" control in interface 700, the client sends a registration request to the portal service.
[0183] Step 302: In response to the received registration request, the portal service device obtains the access address of the registration service and returns the access address of the registration service to the client.
[0184] After receiving the registration request from the client, the portal service device obtains the access address of the registration service in response to the registration request.
[0185] Among them, when the portal service device is regarded as the client described in steps 101 to 104, the registration service is regarded as the target service described in steps 101 to 104, and the registration service device providing the registration service is regarded as the server providing the target service described in steps 101 to 104, the detailed description of how the portal service device obtains the access address of the registration service can refer to the description of how the client obtains the destination address of the target service message in step 101, and no further details are given.
[0186] After obtaining the access address, the portal service device returns the access address to the client that initiated the registration request.
[0187] Step 303: The client registers as a registered user of the target service based on the access address of the registration service.
[0188] When the client accesses the registration service based on the access address of the registration service, it first sends a first registration message with the destination address being the access address to the registration service device providing the registration service. The first registration message is used to obtain relevant information of the registration service access page (recorded as the registration page), and the registration page is used to receive registration information entered by the user. Exemplarily, the registration information includes but is not limited to the user nickname, account password, user identity ID, user region, user date of birth, etc. Among them, the process of the client sending the first registration message to the registration service device, and the process of the security module of the registration service device forwarding or blocking the first registration message, can all refer to the description of steps 102 to 104 above, and will not be repeated here. The method executed by the security module of the registration service device in the embodiment of the present application can refer to steps 103 to 104 and steps 201 to 202 executed by the service gateway above, and will not be repeated here. In this way, DDOS attacks on the registration service device by the attack source can be avoided or alleviated. For details, see the above description of the method of avoiding or alleviating DDOS attacks on the target service by the attack source in the embodiment of the present application, and will not be repeated here.
[0189] Furthermore, after the registration service device receives the first registration message and returns a response message to the first registration message (recorded as the first response message) to the client, the client receives the first response message and outputs the relevant information of the registration page carried by the first response message to the user through its own output interface (such as a display screen). As an example, referring to Figure 8, Figure 8 shows a schematic diagram of a client outputting relevant information of a registration page provided by an embodiment of the present application. As shown in Figure 8, the client can display the interface 800 shown in Figure 8 to the user on its own display screen based on the relevant information of the registration page carried by the first response message. Interface 800 is a registration page.
[0190] Next, the client obtains the user's registration information through the registration page and sends the registration information to the registration service device. The process of the client sending the registration information to the registration service device can also refer to the description of the client sending the target service message to the server in steps 102 to 104, which will not be repeated here.
[0191] Exemplarily, in conjunction with Figure 8, the interface 800 includes an input box for obtaining the user's registration information, an input box for the account password, and an input box for the user's region, etc. The embodiment of the present application does not limit the specific input form of the input box, and the input form includes but is not limited to filling in characters, selecting a drop-down menu, etc. The user performs information input operations (such as selecting and clicking operations, filling in characters, etc.) in each input box in the interface 800 through the input interface of the client (such as a mouse, finger, touch pen, etc.), and after completing the information input operation, performs an input operation (such as a click operation, etc.) on the "Submit" control. In response to the user's information input operation on the interface 800 and the input operation performed on the "Submit" control, the client sends the registration information entered by the user into the client through the information input operation to the registration service device.
[0192] Furthermore, the registration service device completes user registration based on the registration information. Exemplarily, the process of the registration service device completing user registration based on the registration information includes: the registration service device establishing a correspondence between the registration information and the target service, generating a corresponding registered user ID for the registration information, returning the registered user ID to the client, and sending the registration information and the registered user ID to the server.
[0193] Subsequently, the client can enter the login page of the target service through the access page of the portal service, and complete the authentication of the registered user based on the login information entered by the user on the login page, thereby entering the service page provided by the target service for the registered user. Exemplarily, in conjunction with Figure 7, the portal page 700 also includes a "login" control, and the "login" control is used to enter the login page of the target service. On the login page, the client obtains the login information entered by the user by responding to the user's operation of entering the account and password on the login page. The login information includes but is not limited to the user nickname and account password. The client then sends the login information to the server, so that the server authenticates the login information and enters the service page provided by the target service for the registered user after the authentication is passed.
[0194] Through the process described in steps 301 to 303, the client can register as a registered user of the target service. In scenarios where the server only provides services to registered users of the target service, the client of the registered user can obtain the preconfigured address of the target service as described in step 101 and access the target service through the methods described in steps 102 to 104. This prevents the target service from being attacked by the true source of a DDOS attack.
[0195] Optionally, after completing registration and logging into the target service's service page for registered users, the client can also perform a top-up operation. This verifies that the registered user logged in by the client is a real user, not a bot. Furthermore, in scenarios where the server only provides services to registered users of the target service, only the client of the real registered user who has successfully topped up can obtain the preconfigured address of the target service as described in step 101 and access the target service using the methods described in steps 102 to 104. This prevents the target service from being attacked by the true source of a DDOS attack.
[0196] In order to further deepen the understanding of the method provided in the embodiments of the present application, further explanation is provided below with reference to specific examples.
[0197] Referring to Figure 9 , a schematic diagram illustrating a message transmission method according to an embodiment of the present application is shown. As shown in Figure 9 , client 910 is implemented as a terminal device such as a mobile phone or a computer. Client 910 is capable of communicating with portal server 920, registration server 930, and application server 940 via the Internet. R1 is the gateway of client 910, R2 is the gateway of portal server 920, R3 is the gateway of registration server 930, and R4 is the gateway of application server 940.
[0198] When client 910 needs to access service 900 provided by application server 940 for the first time, client 910 communicates with portal server 920 via transmission links including R1 and R2 to execute steps 301-302. Client 910 communicates with registration server 930 via transmission links including R1 and R3 to execute step 303, thereby registering client 910 as a registered user of service 900. After successful registration, client 910 also recharges the registered user account to prove that client 910 is a real registered user.
[0199] The registration server 930 is pre-configured with multiple pre-configured addresses configured for service 900 (or multiple combinations of preset fields and preset rules are pre-configured for service 900). Therefore, after the registration server 930 completes the registration of the client 910 and the client 910 recharges the registered user account, the registration server 930 regularly sends the pre-configured addresses configured for service 900 (or sends the combination of preset fields and preset rules pre-configured for service 900) to the client 910 through the transmission links including R1 and R3. Furthermore, for any time that the registration server 930 sends a preconfigured address (or a combination of preset fields and preset rules) configured for service 900 to the client 910, when the registration server 930 sends the preconfigured address (e.g., IPv6 address 11) to the client 910 via the transmission link including R1 and R3, the registration server 930 simultaneously sends IPv6 address 11 to R4 via R3. Alternatively, when the registration server 930 sends a combination of preset fields and preset rules (e.g., combination 1) to the client 910 via the transmission link including R1 and R3, the registration server 930 simultaneously sends combination 1 to R4 via R3. For detailed explanations, please refer to the relevant description in step 101 and will not be repeated here. It can be seen that only the client where the actual registered user of service 900 is located can obtain the preconfigured address or the combination of preset fields and preset rules configured for service 900, which can prevent the real source attack in the DDOS attack on service 900.
[0200] After the client 910 receives the IPv6 address 11, it generates and sends a service message 11 with the destination address being the IPv6 address 11. The service message 11 is used to access the service 900. After receiving the IPv6 address 11 sent by the registration server 930, the gateway R4 of the application server 940 adds the IPv6 address 11 to the release list. Furthermore, when R4 receives any service message, such as the service message 11, R4 queries the release list based on the destination address IPv6 address 11 of the service message 11, and performs NAT on the destination address of the service message 11 when it determines that the IPv6 address 11 exists in the release list, and forwards the service message 11 to the application server 940 based on the NATed address. Of course, if R4 determines that the destination address of a service message does not exist in the release list, it directly blocks the service message. For a detailed description, please refer to the relevant description of steps 101 to 104, which will not be repeated here.
[0201] Alternatively, when the client receives combination 1, it generates an IPv6 address 21 based on combination 1, and generates and sends a service message 21 with the destination address being IPv6 address 21. Service message 21 is used to access service 900. For a detailed description, please refer to the relevant descriptions of steps 101 and 102, which will not be repeated here. Gateway R4 of application server 940 stores combination 1 after receiving combination 1 sent by registration server 930. Furthermore, when R4 receives any service message, such as service message 21, R4 queries its own pre-acquired combination based on the preset field in the destination address of service message 21. When R4 queries combination 1 containing the preset field based on the preset field in the destination address of service message 21, it calculates the verification field according to the preset rules in combination 1, and compares the calculated verification field with the verification field included in the destination address of service message 21. When R4 determines that the calculated verification field is the same as the verification field included in the destination address of the service message 21, R4 performs NAT on the destination address of the service message 21 and forwards the service message 21 to the application server 940 based on the NATed address. Optionally, R4 also adds the destination address of the service message 21 to the release list so that the service message with the destination address as the aforementioned destination address can be quickly forwarded or blocked later. When R4 determines that the calculated verification field is different from the verification field included in the destination address of the service message 21, R4 blocks the service message 21. For a detailed description, please refer to the relevant description of steps 101 to 104, which will not be repeated here.
[0202] Since the client 910 can regularly obtain the IPv6 address for accessing the service 900, and most of the addresses in the huge IPv6 address space are empty, when the client 910 uses different IPv6 addresses to access the service 900 at different times, when the attack source attacks the service 900 through a direct DDOS sweep attack, the direct DDOS sweep attack cannot be carried out effectively.
[0203] Optionally, after receiving the IPv6 address 11 (or combination 1) from the registration server 930, R4 also spreads the IPv6 address 11 (or combination 1) to all forwarding nodes on the Internet that can reach itself, so that the forwarding nodes that receive the IPv6 address 11 (or combination 1) execute the method described in the embodiment of the present application to transmit the message. For detailed description, please refer to the description of steps 201-202 and will not be repeated here. In this way, the service message sent by the client 910 can be forwarded or blocked at a location close to the client 910, thereby filtering the DDOS attack traffic at a location close to the client 910 (i.e., the source end), thereby improving the impact of the DDOS attack on the communication network between the client 910 and R4.
[0204] Optionally, R4 can also detect the traffic volume of service packets from client 910 used to access service 900, and when the traffic volume of service packets from client 910 used to access service 900 exceeds a threshold, block service packets from client 910 accessing service 900. This can alleviate the message processing pressure on application server 940.
[0205] Optionally, R4 can also identify a registered user of client 910 as a suspicious user if the destination address of the service message sent by the registered user is on the blocking list. Optionally, R4 can count the number of times service messages sent by the registered user are blocked. If the number of blocks exceeds a threshold, the registered user is identified as a malicious user and added to the user blacklist. By promptly discarding or isolating messages from malicious users, network security can be ensured. Malicious users can also be included in the security information system for reference by other attack prevention systems.
[0206] The above mainly introduces the solution provided in the embodiment of the present application from the perspective of method.
[0207] In order to achieve the above functions, refer to Figure 10, which shows a structural diagram of a message transmission device provided in an embodiment of the present application. As shown in Figure 10, the message transmission device 1000 is applied to the security module of the server, and the server is used to provide the target service to the client. The client is a registered user of the target service, and the target service runs on at least one server in at least one cloud data center located in one of the multiple regions. The message transmission device 1000 is specifically used to execute the message transmission method described above, for example, for executing the steps performed by the security module of the server in the method shown in Figure 3, Figure 5 or Figure 6. The message transmission device 1000 may include a receiving unit 1001, a processing unit 1002 and a sending unit 1003.
[0208] Receiving unit 1001 is configured to receive a target service message sent by a client for accessing a target service, wherein the destination address of the target service message includes a verification field. Processing unit 1002 is configured to verify the destination address of the target service message based on the verification field to determine whether the destination address of the target service message is a preconfigured address. Sending unit 1003 is configured to send the target service message to the server. The preconfigured address is the IPv6 address configured for the client to access the target service.
[0209] As an example, in conjunction with FIG3 , the receiving unit 1001 may be configured to execute step 103 , and the processing unit 1002 and the sending unit 1003 may be configured to execute step 104 .
[0210] Optionally, the processing unit 1002 is further configured to block the target service message when the destination address of the target service message is not a preconfigured address and / or when the destination address of the target service message is on a blocking list. The blocking list is used to record the destination addresses of service messages that are prohibited from being forwarded.
[0211] Optionally, the destination address of the target service message further includes a preset field, and the message transmission apparatus 1000 further includes an acquisition unit 1004. The acquisition unit 1004 is configured to acquire a first preset rule corresponding to the preset field, where the first preset rule is configured to determine a verification field in the preconfigured address based on a logical operation. The processing unit 1002 is further configured to determine a target verification field based on the first preset rule, and to determine that the destination address of the target service message is a preconfigured address when the verification field included in the destination address of the target service message is the same as the target verification field.
[0212] Optionally, the receiving unit 1001 is further configured to receive a second preset rule when the preset time period is reached, where the second preset rule is a preset rule that updates the first preset rule.
[0213] Optionally, the security module of the server is deployed in a gateway of the server, and the sending unit 1003 is further configured to send the first preset rule to a forwarding node that can reach the gateway.
[0214] As an example, in conjunction with FIG5 , the sending unit 1003 may be configured to execute step 202 .
[0215] Optionally, the processing unit 1002 is further configured to determine that the number of blocked service messages sent by the same registered user through the client exceeds a preset threshold, and add the user ID of the same registered user to a user blacklist.
[0216] Optionally, the security module of the server is deployed in the gateway of the server, and the processing unit 1002 is further configured to perform NAT on the destination address of the target service message. The sending unit 1003 is specifically configured to send the NATed target service message to the server, where the NATed destination address of the target service message is the address of the server.
[0217] Optionally, the address after NAT of the destination address of the target service packet is an IPv6 address or an IPv4 address.
[0218] For the detailed description of the above optional methods, please refer to the above method embodiments, which will not be repeated here. In addition, the explanation and description of the beneficial effects of any of the above message transmission devices 1000 can refer to the above corresponding method embodiments, which will not be repeated here.
[0219] As an example, in conjunction with FIG. 12 described below, the functions implemented by the receiving unit 1001 and the sending unit 1002 in the message transmission device 1000 can be implemented via the communication interface 1208 shown in FIG. The functions implemented by the processing unit 1002 in the message transmission device 1000 can be implemented by the processor 1204 in FIG. 12 executing the program code in the memory 1206 in FIG. The functions implemented by the acquiring unit 1004 in the message transmission device 1000 can be implemented via the communication interface 1208 shown in FIG. 12 or by the processor 1204 in FIG. 12 executing the program code in the memory 1206 in FIG. There is no limitation on this.
[0220] Referring to Figure 11, Figure 11 shows a schematic structural diagram of another message transmission device provided in an embodiment of the present application. As shown in Figure 11, the message transmission device 1100 is applied to the client, the client is a registered user of the target service provided by the server, and the server is used to provide the target service to the client, and the target service runs on at least one server in at least one cloud data center located in one of the multiple regions. The message transmission device 1100 is specifically used to execute the message transmission method described above, for example, for executing the steps performed by the client in the method shown in Figure 3, Figure 5 or Figure 6. The message transmission device 1100 may include an acquisition unit 1101 and a sending unit 1102.
[0221] The acquiring unit 1101 is configured to acquire a destination address of a target service message to be sent, where the destination address is one of the preconfigured addresses, which is an IPv6 address configured for the client to access the target service. The sending unit 1102 is configured to send the target service message, where the target service message is used to access the target service.
[0222] As an example, in conjunction with FIG3 , the acquiring unit 1101 may be used to execute step 101 , and the sending unit 1102 may be used to execute step 102 .
[0223] Optionally, the acquisition unit 1101 is further configured to acquire a first preset rule, the first preset rule being configured to determine a verification field in a preconfigured address based on a logical operation, the verification field being used to verify whether the destination address of the target service message is the preconfigured address. The message transmission apparatus 1100 further includes a processing unit 1103, configured to determine the verification field in the destination address according to the first preset rule, and to obtain the destination address of the target service message based on the verification field.
[0224] Optionally, the message transmission device 1100 further includes a receiving unit 1104, and the receiving unit 1104 is configured to receive a second preset rule when a preset time period is reached, where the second preset rule is a preset rule that updates the first preset rule.
[0225] Optionally, the acquisition unit 1101 is further configured to obtain an access address of a registration service by accessing a portal service of the target service before obtaining the destination address of the target service message to be sent. The processing unit 1103 is further configured to register as a registered user of the target service based on the access address of the registration service. The registration service is configured to provide user registration services for users accessing the target service.
[0226] As an example, in conjunction with FIG6 , the acquiring unit 1101 may be configured to execute steps 301 to 302 , and the processing unit 1103 may be configured to execute step 303 .
[0227] Optionally, the portal service device for providing the portal service is configured with at least one access address of the registration service. The receiving unit 1104 is further configured to receive the access address of the registration service returned by the portal service device.
[0228] For the detailed description of the above optional methods, please refer to the above method embodiments, which will not be repeated here. In addition, the explanation and description of the beneficial effects of any of the above message transmission devices 1100 can refer to the above corresponding method embodiments, which will not be repeated here.
[0229] As an example, in conjunction with FIG. 12 described below, the functions implemented by the sending unit 1102 and the receiving unit 1104 in the message transmission device 1100 can be implemented via the communication interface 1208 shown in FIG. The functions implemented by the processing unit 1003 in the message transmission device 1100 can be implemented by the processor 1204 in FIG. 12 executing the program code in the memory 1206 in FIG. The functions implemented by the acquiring unit 1101 in the message transmission device 1100 can be implemented via the communication interface 1208 shown in FIG. 12 or by the processor 1204 in FIG. 12 executing the program code in the memory 1206 in FIG. There is no limitation on this.
[0230] It should be readily apparent to those skilled in the art that, in combination with the units and algorithmic steps of the various examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is performed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0231] It should be noted that the division of modules / units in FIG10 or FIG11 is schematic and merely a logical functional division. In actual implementation, other divisions may be employed. For example, two or more functions may be integrated into a single processing module. Such integrated modules may be implemented in either hardware or software functional modules.
[0232] For example, the implementation of the processing unit 1002 of the message transmission device 1000 shown in FIG10 is described below. Similarly, the implementation of the receiving unit 1001, the sending unit 1003, and the obtaining unit 1004 shown in FIG10 can refer to the implementation of the processing unit 1002.
[0233] As an example of a software functional unit, the processing unit 1002 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance may be one or more. For example, the processing unit 1002 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple geographically close data centers. Typically, a region may include multiple AZs.
[0234] Similarly, multiple hosts / virtual machines / containers running the code can be distributed within the same virtual private cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.
[0235] As an example of a hardware functional unit, processing unit 1002 may include at least one computing device, such as a server. Alternatively, processing unit 1002 may be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0236] The multiple computing devices included in processing unit 1002 can be distributed in the same region or in different regions. The multiple computing devices included in processing unit 1002 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in processing unit 1002 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, GALs, and other computing devices.
[0237] It should be noted that, in other embodiments, the processing unit 1002 can be used to execute any step related to data / message processing in the message transmission method described in the embodiment of the present application, the receiving unit 1001 can be used to execute any step related to the receiving operation in the message transmission method described in the embodiment of the present application, the sending unit 1003 can be used to execute any step related to the sending operation in the message transmission method described in the embodiment of the present application, and the acquisition unit 1004 can be used to execute any step related to the acquisition operation in the message transmission method described in the embodiment of the present application. The steps that the receiving unit 1001, the processing unit 1002, the sending unit 1003 and the acquisition unit 1004 are responsible for implementing can be specified as needed. The receiving unit 1001, the processing unit 1002, the sending unit 1003 and the acquisition unit 1004 respectively implement different steps in the message transmission method described in the embodiment of the present application to realize all the functions of the message transmission device.
[0238] The present application also provides a message transmission system, comprising a server-side security module and a client-side client. The server-side security module is configured to execute the portion of the message transmission method described above that is executed by the server-side security module. The client-side client is configured to execute the portion of the message transmission method described above that is executed by the client-side client.
[0239] The server-side security module and the client-side security module can both be implemented in software or hardware. As an example, the implementation of the server-side security module is described below. Similarly, the implementation of the client-side security module can refer to the implementation of the server-side security module.
[0240] As an example of a software functional unit, the security module on the server side may include code running on a computing instance. The computing instance may be at least one of a physical host (computing device), a virtual machine, a container, and other computing devices. Furthermore, the above-mentioned computing device may be one or more. For example, the security module on the server side may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the application may be distributed in the same region or in different regions. The multiple hosts / virtual machines / containers used to run the code may be distributed in the same AZ or in different AZs, and each AZ includes one data center or multiple geographically close data centers. Generally, a region may include multiple AZs.
[0241] Similarly, the multiple hosts / virtual machines / containers running the code can be distributed within the same VPC or across multiple VPCs. Typically, a VPC is located within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.
[0242] As an example of a hardware functional unit, the server-side security module may include at least one computing device, such as a server. Alternatively, the server-side security module may be implemented using an ASIC or a PLD. The PLD may be implemented using a CPLD, FPGA, GAL, or any combination thereof.
[0243] The multiple computing devices included in the server's security module can be distributed in the same region or in different regions. The multiple computing devices included in the server's security module can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the server's security module can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, GALs, and other computing devices.
[0244] An embodiment of the present application provides a computing device. As shown in FIG12 , computing device 1200 includes a bus 1202, a processor 1204, a memory 1206, and a communication interface 1208. The processor 1204, the memory 1206, and the communication interface 1208 are communicatively connected to each other via the bus 1202. Optionally, computing device 1200 also includes an input / output interface 1210, which communicates with the processor 1204, the memory 1206, and the communication interface 1208 via the bus 1202.
[0245] Bus 1202 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG12 shows a single bus line, but this does not imply a single bus or type of bus. Bus 1202 may include a path for transmitting information between various components of computing device 1200 (e.g., memory 1206, processor 1204, and communication interface 1208).
[0246] The processor 1204 may include a general-purpose processor and / or a dedicated hardware chip. A general-purpose processor may include: a central processing unit (CPU), a microprocessor (MP) or a graphics processing unit (GPU). The CPU is, for example, a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A dedicated hardware chip is a hardware module for high-performance processing. Dedicated hardware chips include at least one of a digital signal processor (DSP), a data processing unit (DPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, a neural processing unit (NPU), a tensor processing unit (TPU), an artificial intelligence (artificial intelligent) chip or a network processor (NP). The processor 1204 may also be an integrated circuit chip with signal processing capabilities. During implementation, part or all of the functions of the method provided in the embodiment of the present application may be accomplished through hardware integrated logic circuits in the processor 1204 or instructions in software form.
[0247] The memory 1206 may include volatile memory, such as random access memory (RAM). The memory 1206 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0248] The memory 1206 stores executable program code, and the processor 1204 executes the executable program code to respectively implement the functions of the receiving unit 1001, the processing unit 1002, the sending unit 1003, and the obtaining unit 1004 shown in Figure 10, thereby implementing the method portion executed by the security module of the server in the message transmission method described in the embodiment of the present application. In other words, the memory 1206 stores instructions for executing the functions implemented by the receiving unit 1001, the processing unit 1002, the sending unit 1003, and the obtaining unit 1004 in the message transmission method described in the embodiment of the present application.
[0249] Alternatively, the memory 1206 stores executable code, and the processor 1204 executes the executable program code to respectively implement the functions of the acquisition unit 1101, the sending unit 1102, the processing unit 1103, and the receiving unit 1104 shown in Figure 11, thereby implementing the method portion executed by the client in the message transmission method described in the embodiment of the present application. That is, the memory 1206 stores instructions for executing the method functions implemented by the acquisition unit 1101, the sending unit 1102, the processing unit 1103, and the receiving unit 1104 in the message transmission method described in the embodiment of the present application.
[0250] Communication interface 1208 uses a transceiver module, such as, but not limited to, a transceiver, to communicate with other devices or communication networks. For example, communication interface 1208 can be any one or a combination of the following devices: a network interface (e.g., an Ethernet interface), a wireless network card, or other devices with network access capabilities. Communication interface 1208 includes a receiving unit for receiving data / messages and a transmitting unit for sending data / messages.
[0251] Input / output interface 1210 is used to implement human-computer interaction between a user and computing device 1200. For example, text or voice interaction between the user and computing device 1200 can be implemented. The input / output interface 1210 includes an input interface for enabling a user to input information to computing device 1200, and an output interface for enabling computing device 1200 to output information to the user. By way of example, input interfaces include, but are not limited to, a touch screen, keyboard, mouse, or microphone, and output interfaces include, but are not limited to, a display screen and speakers. A touch screen, keyboard, or mouse is used to input text / image information, a microphone is used to input voice information, a display screen is used to output text / image information, and a speaker is used to output voice information.
[0252] It should be noted that the above-mentioned multiple devices can be respectively arranged on independent chips, or at least partially or completely arranged on the same chip. Whether each device is independently arranged on different chips or integrated on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation form of the above-mentioned devices. The descriptions of the processes corresponding to the above-mentioned figures have different focuses. For parts that are not described in detail in a certain process, please refer to the relevant descriptions of other processes.
[0253] In the above embodiments, all or part of the embodiments may be implemented using software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments may be implemented in the form of a computer program product. The computer program product providing a program development platform includes one or more computer instructions. When these computer program instructions are loaded and executed on the computing device 1200, all or part of the functions of the message transmission method provided in the embodiments of the present application are implemented in whole or in part.
[0254] Furthermore, computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium stores computer program instructions that provide a program development platform.
[0255] Embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0256] As shown in Figure 13, the computing device cluster includes at least one computing device 1200. The memory 1206 in one or more computing devices 1200 in the computing device cluster may store the same instructions for executing the above-mentioned message transmission method.
[0257] In some possible implementations, the memory 1206 of one or more computing devices 1200 in the computing device cluster may also store instructions for executing the message transmission method described above. In other words, the combination of one or more computing devices 1200 can jointly execute instructions for executing the message transmission method described above.
[0258] It should be noted that the memory 1206 in different computing devices 1200 in the computing device cluster can store different instructions, each for executing part of the functions of the message transmission device described in FIG10 above. In other words, the instructions stored in the memory 1206 in different computing devices 1200 can implement the functions of one or more of the receiving unit 1001, processing unit 1002, sending unit 1003, and obtaining unit 1004 shown in FIG10.
[0259] Alternatively, the memory 1206 in different computing devices 1200 in the computing device cluster may store different instructions, each for executing part of the functions of the message transmission apparatus described in FIG11 . That is, the instructions stored in the memory 1206 in different computing devices 1200 may implement the functions of one or more of the acquisition unit 1101, sending unit 1102, processing unit 1103, and receiving unit 1104 shown in FIG11 .
[0260] In some possible implementations, one or more computing devices in a computing device cluster may be connected via a network. The network may be a wide area network or a local area network, etc. FIG14 shows a possible implementation. As shown in FIG14 , two computing devices 1200A and 1200B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this type of possible implementation, in conjunction with FIG10 , the memory 1206 in the computing device 1200A stores instructions for implementing the functions of the processing unit 1002 shown in FIG10 . At the same time, the memory 1206 in the computing device 1200B stores instructions for implementing the functions of the receiving unit 1001, the sending unit 1003, and the acquiring unit 1004 shown in FIG10 .
[0261] The connection method between the computing device clusters shown in Figure 14 can be based on the consideration that the method steps executed by the security module of the server in the message transmission method provided in the embodiment of the present application require relevant calculations for verifying the destination address of the received message. Therefore, it is considered that the functions implemented by the processing unit 1002 are handed over to the computing device 1200A for execution, and other operations (such as receiving, sending, etc.) are handed over to the computing device 1200B for execution.
[0262] It should be understood that the functions of the computing device 1200A shown in Figure 14 may also be completed by multiple computing devices 1200. Similarly, the functions of the computing device 1200B may also be completed by multiple computing devices 1200, without limitation.
[0263] The present application also provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to the connection method of the computing device cluster described in Figures 13 and 14. The difference is that the memory 1206 of one or more computing devices 1200 in the computing device cluster can store the same instructions for executing the message transmission method described in the present application embodiment.
[0264] In some possible implementations, the memory 1206 of one or more computing devices 1200 in the computing device cluster may also store partial instructions for executing the message transmission method described in the embodiments of the present application. In other words, the combination of one or more computing devices 1200 can jointly execute instructions for executing the message transmission method described in the embodiments of the present application.
[0265] It should be noted that the memory 1206 in different computing devices 1200 in the computing device cluster can store different instructions for executing some of the functions of the message transmission system described in the embodiments of the present application. In other words, the instructions stored in the memory 1206 in different computing devices 1200 can implement the functions of the security module on the server and one or more device modules on the client described above.
[0266] The present application also provides a computer program product including instructions. The computer program product may be software or a program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the message transmission method described in the present application.
[0267] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the message transmission method provided in the embodiment of the present application.
[0268] An embodiment of the present application also provides a chip, which includes a processor. When the processor runs a program instruction or code, the chip including the processor or the device including the chip executes the message transmission method described above. Exemplarily, the chip also includes: an input interface, an output interface, and a memory. Among them, the input interface, output interface, processor, and memory of the chip are connected through the internal connection path of the chip, the memory in the chip is used to store the program instructions or code run by the processor, and the input interface and output interface of the chip are used for the connection and communication between the chip and other chips or devices.
[0269] In the embodiments of the present application, the terms "first", "second" and "third" are used for descriptive purposes only and should not be understood as indicating or implying relative importance. The term "at least one" refers to one or more, and the term "plurality" refers to a plurality, unless otherwise expressly limited.
[0270] In this application, the term "and / or" simply describes an association between related objects, indicating that three possible relationships exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this document generally indicates that the related objects are in an "or" relationship.
[0271] It should be understood that the terminology used in the description of the various examples herein is for the purpose of describing particular examples only and is not intended to be limiting. As used in the description of the various examples and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0272] It should be understood that determining B based on A does not mean determining B based solely on A. B can also be determined based on A and / or other information.
[0273] It will be understood that the term “comprise” (also known as “includes,” “including,” “comprises,” and / or “comprising”) when used in this specification specifies the presence of stated features, integers, steps, operations, elements, and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0274] It should also be understood that in the various embodiments of the present application, the size of the serial number of each process does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0275] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concepts and principles of the present application shall be included in the scope of protection of the present application.
[0276] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.) and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.
[0277] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A message transmission method, characterized in that: A security module applied to a server, the server being used to provide a target service to a client, the client being a registered user of the target service, the target service running on at least one server in at least one cloud data center located in one of the multiple regions, the method comprising: receiving a target service message sent by a client, wherein the target service message is used to access the target service, wherein the destination address of the target service message includes a verification field; Verify, according to the verification field, the destination address of the target service message to determine that the destination address of the target service message is a preconfigured address, where the preconfigured address is an Internet Protocol version 6 IPv6 address configured for the client to access the target service; Send the target service message to the server.
2. The method according to claim 1, characterized in that The method further comprises: When the destination address of the target service message is not the preconfigured address, and / or when the destination address of the target service message exists in a blocking list, the target service message is blocked, and the blocking list is used to record the destination addresses of service messages that are prohibited from being forwarded.
3. The method according to claim 1 or 2, characterized in that The destination address of the target service message further includes a preset field, and the verifying the destination address of the target service message according to the verification field to determine that the destination address of the target service message is a preconfigured address includes: Acquire a first preset rule corresponding to the preset field, wherein the first preset rule is used to determine a verification field in the preconfigured address based on a logical operation; According to the first preset rule, determine the target verification field; In a case where the verification field included in the destination address of the target service message is the same as the target verification field, it is determined that the destination address of the target service message is the pre-configured address.
4. The method according to claim 3, characterized in that The method further comprises: When the preset time period is reached, a second preset rule is received, where the second preset rule is a preset rule that updates the first preset rule.
5. The method according to claim 3 or 4, characterized in that The security module is deployed in the gateway of the server, and the method further includes: The first preset rule is sent to a forwarding node that is reachable to the gateway.
6. The method according to claim 2, characterized in that The method further comprises: It is determined that the number of blocked service messages sent by the same registered user through the client exceeds a preset threshold, and the user identifier ID of the same registered user is added to a user blacklist.
7. A message transmission method, characterized in that: Applied to a client, the client is a registered user of a target service provided by a server, the server is used to provide the target service to the client, the target service is run on at least one server of at least one cloud data center located in one of multiple regions, the method comprising: Acquire a destination address of a target service message to be sent, wherein the destination address is one of preconfigured addresses, and the preconfigured address is an Internet Protocol version 6 IPv6 address configured for the client to access the target service; The target service message is sent, where the target service message is used to access the target service.
8. The method according to claim 7, characterized in that The obtaining of the destination address of the target service message to be sent includes: Obtain a first preset rule, where the first preset rule is used to determine a verification field in the preconfigured address based on a logical operation, where the verification field is used to verify whether the destination address of the target service message is the preconfigured address; Determine the verification field in the destination address according to the first preset rule; The destination address is obtained according to the verification field.
9. The method according to claim 8, characterized in that The method further comprises: When the preset time period is reached, a second preset rule is received, where the second preset rule is a preset rule that updates the first preset rule.
10. The method according to any one of claims 7 to 9, characterized in that Before obtaining the destination address of the target service message to be sent, the method further includes: By accessing the portal service of the target service, an access address of a registration service is obtained, wherein the registration service is used to provide user registration services for users accessing the target service; Based on the access address of the registration service, register as a registered user of the target service.
11. A message transmission device, characterized in that: A security module applied to a server, the server being used to provide a target service to a client, the client being a registered user of the target service, the target service running on at least one server in at least one cloud data center located in one of the multiple regions, the device comprising: A receiving unit, configured to receive a target service message sent by a client, wherein the target service message is used to access the target service, wherein the destination address of the target service message includes a verification field; a processing unit, configured to verify the destination address of the target service message according to the verification field to determine that the destination address of the target service message is a preconfigured address, wherein the preconfigured address is an Internet Protocol Version 6 IPv6 address configured for the client to access the target service; A sending unit is used to send the target service message to the server.
12. A message transmission device, characterized in that: Applied to a client, the client is a registered user of a target service provided by a server, the server is used to provide the target service to the client, the target service runs on at least one server of at least one cloud data center located in one of multiple regions, the device includes: an acquiring unit, configured to acquire a destination address of a target service message to be sent, wherein the destination address is one of preconfigured addresses, and the preconfigured address is an Internet Protocol version 6 IPv6 address configured for the client to access the target service; The sending unit is used to send the target service message, where the target service message is used to access the target service.
13. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1-6 or claims 7-10.
14. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device, the computing device is caused to perform the method according to any one of claims 1 to 6 or claims 7 to 10.
15. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device, the computing device performs the method according to any one of claims 1 to 6 or claims 7 to 10.
Citation Information
Patent Citations
Message transmission method and device
CN120034347A
Illegal external connection detection method and device
CN108881211A
Communication processing method and device, computer readable medium and electronic device
CN109889586A
Data transmission method and device, electronic equipment and storage medium
CN116633633A
Network access control method, apparatus and system
WO2018107943A1
Cited By
DDoS attack object identification method, device and equipment based on security agent
CN121333662A