Attack detection method and apparatus, and electronic device
By sampling network data packet feature information and calculating traffic differences, low-speed DDoS hybrid attacks are identified, solving the problem of difficulty in detecting low-speed DDoS attacks in existing technologies, and achieving higher detection accuracy and wider applicability.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- CHINA TELECOM NETWORK SECURITY TECH CO LTD
- Filing Date
- 2025-11-03
- Publication Date
- 2026-05-21
AI Technical Summary
Existing DDoS attack detection methods struggle to identify low-speed DDoS attacks, especially mixed low-speed DDoS attacks, which cannot be effectively detected using traditional traffic thresholding methods.
By sampling the characteristic information of data packets in the network, comprehensive traffic data of each network protocol in each time period is obtained. By utilizing the differences between traffic correlation characteristics and reference traffic data, the traffic difference degree is calculated, thereby identifying attacks.
It improves the accuracy of attack detection, can flexibly identify attacks of various network protocols, reduces detection complexity and system overhead, and is not limited to specific attack protocol types.
Smart Images

Figure CN2025132208_21052026_PF_FP_ABST
Abstract
Description
An attack detection method, apparatus, and electronic device
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese Patent Application No. 202411606031.1, filed on November 12, 2024, with the State Intellectual Property Office of the People's Republic of China, entitled "An Attack Detection Method, Apparatus, Electronic Device and Storage Medium", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of cybersecurity technology, and in particular to an attack detection method, apparatus, and electronic device. Background Technology
[0004] A Distributed Denial of Service (DDoS) attack is a type of network attack. Its purpose is to overload a target server or network resource with a large amount of network traffic or requests, thereby preventing legitimate users from accessing or using these resources.
[0005] Existing DDoS attack detection methods primarily target traditional high-speed DDoS attacks. They determine the presence of a DDoS attack by setting a total traffic threshold, where the current traffic exceeds the threshold.
[0006] However, with the continuous development of attack methods, low-speed DDoS attacks have emerged, which use low-rate data packets. Since this type of attack does not rely on massive traffic floods, it can avoid triggering traffic thresholds. Low-speed DDoS attacks are difficult to detect based on traffic thresholds.
[0007] In conclusion, improving the accuracy of DDoS attack detection has become an urgent problem to be solved. Summary of the Invention
[0008] This application provides an attack detection method, apparatus, and electronic device to improve the accuracy of attack detection.
[0009] An attack detection method provided in this application includes:
[0010] According to a preset time period, the feature information of data packets in the network is sampled to obtain a set of feature information sampled in each time period. The feature information includes: sub-traffic data of the corresponding data packet and the network protocol used.
[0011] For each set of feature information, perform the following operations:
[0012] Based on a set of feature information, sub-traffic data of data packets using various network protocols are used to obtain comprehensive traffic data of each network protocol within the time period corresponding to the set of feature information. The comprehensive traffic data is used to characterize the traffic situation of data packets using the corresponding network protocol.
[0013] Based on the differences between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, the traffic difference degree corresponding to the feature information set is obtained.
[0014] Attack detection results are obtained based on the traffic difference degree corresponding to each feature information set.
[0015] Optionally, the reference traffic data is obtained based on historical traffic data within each historical time period according to the corresponding network protocol;
[0016] The step of obtaining the traffic difference degree corresponding to the feature information set based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data includes:
[0017] Based on the historical traffic datasets of each network protocol, the traffic correlation characteristics among the network protocols are obtained.
[0018] Based on the traffic correlation characteristics and the differences between the reference traffic data and the corresponding comprehensive traffic data of each network protocol, the traffic difference degree corresponding to the feature information set is obtained.
[0019] Optionally, obtaining the traffic correlation characteristics between the network protocols based on their respective historical traffic datasets includes:
[0020] Each historical traffic vector is obtained based on each historical traffic dataset, and the elements in the historical traffic vector are the historical traffic data in the corresponding historical traffic dataset.
[0021] Based on the correlation between the historical traffic vectors, the traffic correlation features are obtained.
[0022] Optionally, obtaining the traffic difference degree corresponding to the feature information set based on the traffic correlation characteristics and the difference between the reference traffic data and the corresponding comprehensive traffic data of each network protocol includes:
[0023] A comprehensive traffic vector is obtained based on each comprehensive traffic data, and a reference traffic vector is obtained based on each reference traffic data. The position of the comprehensive traffic data corresponding to the same network protocol in the comprehensive traffic vector is the same as the position of the reference traffic data in the reference traffic vector.
[0024] Based on the difference vector between the comprehensive traffic vector and the reference traffic vector, and the traffic correlation features, the traffic difference degree corresponding to the feature information set is obtained.
[0025] Optionally, before obtaining the traffic difference degree corresponding to the feature information set based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, the method further includes:
[0026] For each network protocol, the overall traffic data of the network protocol is adjusted based on the historical traffic data of the network protocol in each historical time period to obtain the adjusted overall traffic data.
[0027] Optionally, obtaining the traffic difference degree corresponding to the feature information set based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data includes:
[0028] Based on the difference between the reference traffic data of each network protocol and the corresponding adjusted comprehensive traffic data, the traffic difference degree corresponding to the feature information set is obtained.
[0029] Optionally, obtaining the attack detection result based on the traffic difference degree corresponding to each feature information set includes:
[0030] Determine the mean of the difference based on the differences in each flow rate;
[0031] The ratio between each traffic difference degree and the mean difference degree is determined respectively. If there is a first ratio greater than the first value among the obtained first ratios, the attack detection result is determined to be that an attack exists.
[0032] Optionally, after determining that the attack detection result indicates the existence of an attack, the method further includes:
[0033] For each network protocol, a reference traffic data for that network protocol is determined, and the difference between the reference traffic data for that network protocol and the comprehensive traffic data for that network protocol in each time period is determined. A second ratio between each difference and the reference difference is then determined. Based on each second ratio, a target ratio for that network protocol is determined.
[0034] Based on the target ratio of each network protocol, network protocols with a target ratio greater than the second value are selected, and attack protection measures are implemented according to the selected network protocols.
[0035] An attack detection device provided in this application includes:
[0036] The sampling unit is used to sample the feature information of data packets in the network according to a preset time period to obtain a set of feature information sampled in each time period. The feature information includes: sub-traffic data of the corresponding data packet and the network protocol used.
[0037] The statistical unit is used to perform the following operations for each set of feature information:
[0038] Based on a set of feature information, sub-traffic data of data packets using various network protocols are used to obtain comprehensive traffic data of each network protocol within the time period corresponding to the set of feature information. The comprehensive traffic data is used to characterize the traffic situation of data packets using the corresponding network protocol.
[0039] Based on the differences between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, the traffic difference degree corresponding to the feature information set is obtained.
[0040] The detection unit is used to obtain attack detection results based on the traffic difference degree corresponding to each feature information set.
[0041] Optionally, the reference traffic data is obtained based on historical traffic data within each historical time period according to the corresponding network protocol;
[0042] The statistical unit is specifically used for:
[0043] Based on the historical traffic datasets of each network protocol, the traffic correlation characteristics among the network protocols are obtained.
[0044] Based on the traffic correlation characteristics and the differences between the reference traffic data and the corresponding comprehensive traffic data of each network protocol, the traffic difference degree corresponding to the feature information set is obtained.
[0045] Optionally, the statistical unit is specifically used for:
[0046] Each historical traffic vector is obtained based on each historical traffic dataset, and the elements in the historical traffic vector are the historical traffic data in the corresponding historical traffic dataset.
[0047] Based on the correlation between the historical traffic vectors, the traffic correlation features are obtained.
[0048] Optionally, the statistical unit is specifically used for:
[0049] A comprehensive traffic vector is obtained based on each comprehensive traffic data, and a reference traffic vector is obtained based on each reference traffic data. The position of the comprehensive traffic data corresponding to the same network protocol in the comprehensive traffic vector is the same as the position of the reference traffic data in the reference traffic vector.
[0050] Based on the difference vector between the comprehensive traffic vector and the reference traffic vector, and the traffic correlation features, the traffic difference degree corresponding to the feature information set is obtained.
[0051] Optionally, the device further includes an adjustment unit for:
[0052] For each network protocol, the overall traffic data of the network protocol is adjusted based on the historical traffic data of the network protocol in each historical time period to obtain the adjusted overall traffic data.
[0053] Optionally, the statistical unit is specifically used for:
[0054] Based on the difference between the reference traffic data of each network protocol and the corresponding adjusted comprehensive traffic data, the traffic difference degree corresponding to the feature information set is obtained.
[0055] Optionally, the detection unit is specifically used for:
[0056] Determine the mean of the difference based on the differences in each flow rate;
[0057] The ratio between each traffic difference degree and the mean difference degree is determined respectively. If there is a first ratio greater than the first value among the obtained first ratios, the attack detection result is determined to be that an attack exists.
[0058] Optionally, the device further includes a screening unit for:
[0059] For each network protocol, a reference traffic data for that network protocol is determined, and the difference between the reference traffic data for that network protocol and the comprehensive traffic data for that network protocol in each time period is determined. A second ratio between each difference and the reference difference is then determined. Based on each second ratio, a target ratio for that network protocol is determined.
[0060] Based on the target ratio of each network protocol, network protocols with a target ratio greater than the second value are selected, and attack protection measures are implemented according to the selected network protocols.
[0061] An electronic device provided in this application includes a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of any of the above-described attack detection methods.
[0062] This application provides a computer-readable storage medium including a computer program. When the computer program is run on an electronic device, the computer program is used to cause the electronic device to perform the steps of any of the above-described attack detection methods.
[0063] This application provides a computer program product, which includes a computer program stored in a computer-readable storage medium. When the processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, causing the electronic device to perform the steps of any of the above-described attack detection methods.
[0064] The beneficial effects of this application are as follows:
[0065] This application provides an attack detection method, apparatus, and electronic device. By sampling the feature information of data packets in a network, comprehensive traffic data for each network protocol within each time period is obtained. Based on the difference between the reference traffic data for each network protocol and the corresponding comprehensive traffic data, the traffic difference degree corresponding to each feature information set can be obtained, thereby obtaining the attack detection result. Based on the above method, by utilizing the traffic correlation under the same network protocol and comparing the difference between the comprehensive traffic data and reference traffic data under the same network protocol, attacks can be identified more flexibly, improving the accuracy of attack detection. It is not limited to identifying specific attack protocol types and can identify attacks on multiple network protocols, thus having a wider range of applications. Furthermore, it does not require the use of the entire data packet; only the feature information of the data packet is sampled for detection, reducing the complexity of detection and system overhead.
[0066] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description
[0067] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0068] Figure 1 is a schematic diagram of an optional application scenario in an embodiment of this application;
[0069] Figure 2 is a flowchart illustrating the implementation of an attack detection method in an embodiment of this application;
[0070] Figure 3 is an overall flowchart of an attack detection method in an embodiment of this application;
[0071] Figure 4 is a schematic diagram of an attack detection device according to an embodiment of this application;
[0072] Figure 5 is a schematic diagram of the hardware structure of an electronic device using an embodiment of this application;
[0073] Figure 6 is a schematic diagram of the hardware structure of another electronic device using an embodiment of this application. Detailed Implementation
[0074] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this application. Obviously, the described embodiments are only some embodiments of the technical solutions of this application, and not all embodiments. Based on the embodiments recorded in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the technical solutions of this application.
[0075] The following describes some of the concepts involved in the embodiments of this application.
[0076] Low-speed DDoS hybrid attacks: This is a more complex form of attack that combines multiple attack techniques and strategies to circumvent traditional DDoS defense mechanisms. This type of attack typically does not rely on massive traffic flooding, but rather uses low-rate packet transmission, making it more difficult to detect and block.
[0077] Net Flow data is a standard protocol used for network traffic monitoring and analysis. By collecting and aggregating network traffic data from network devices (such as routers and switches), it helps network administrators better understand data flow behavior within the network. Net Flow data can provide important information about network traffic, such as packet direction, source address, destination address, protocol type, and port number. The feature information in this application embodiment can be Net Flow data.
[0078] Sliding window smoothing is a technique used in time series analysis to smooth data, typically to reduce noise or highlight trends. This method obtains a smoothed data series by applying a sliding window to the data series and calculating the mean or other statistics within each window.
[0079] Mahalanobis distance is a method for measuring the distance between two data points, taking into account the covariance structure of the data. Unlike Euclidean distance, Mahalanobis distance measures not only the straight-line distance between two points but also the distribution of the dataset. Therefore, it is very useful for dealing with correlated multidimensional data.
[0080] Z-score, also known as the standard score, is a statistic used to measure how far a value is from the mean of its sample or population, usually expressed in units of standard deviation. The Z-score helps understand the relative position of a data point within the data distribution and is an important concept in statistical analysis and data standardization.
[0081] The preferred embodiments of this application are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments and features in the embodiments of this application can be combined with each other without conflict.
[0082] Figure 1 illustrates an application scenario of an embodiment of this application. The application scenario includes two terminal devices 110 and one server 120.
[0083] In this application embodiment, the terminal device includes, but is not limited to, mobile phones, tablets, laptops, desktop computers, e-book readers, smart voice interaction devices, smart home appliances, and in-vehicle terminals. The terminal device may have an attack detection-related client installed. This client can be software (such as a browser, attack detection software, etc.), or a webpage, mini-program, etc. The server is the backend server corresponding to the software, webpage, mini-program, etc., or a server specifically used for attack detection; this application does not impose specific limitations. The server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0084] It should be noted that the attack detection method in this application embodiment can be executed by an electronic device, which can be a server or a terminal device. That is, the method can be executed by the server or the terminal device alone, or by the server and the terminal device together.
[0085] In one alternative implementation, the terminal device and the server can communicate via a communication network.
[0086] In one alternative implementation, the communication network is a wired network or a wireless network.
[0087] It should be noted that Figure 1 is only an example, and in reality, the number of terminal devices and servers is not limited, and no specific limitation is made in this embodiment.
[0088] The attack detection method provided by the exemplary embodiments of this application will be described below with reference to the accompanying drawings and the application scenarios described above. It should be noted that the application scenarios described above are only shown to facilitate understanding of the spirit and principles of this application, and the embodiments of this application are not limited in any way in this respect.
[0089] Referring to Figure 2, which is a flowchart of an attack detection method provided in this application embodiment, taking the server as the executing entity as an example, the specific implementation process of this method includes the following steps S21-S23:
[0090] S21: The server samples the feature information of data packets in the network according to a preset time period to obtain the set of feature information sampled in each time period;
[0091] This involves periodically collecting Net Flow traffic data from the network. Net Flow traffic data can include information such as source address, destination address, source port number, destination port number, number of packets, and packet size. Net Flow traffic data can be directly used as a feature set, or feature sets can be extracted from it. It supports the detection of low-speed DDoS hybrid attacks at the flow level, eliminating the need for full traffic data, thus reducing system complexity and overhead, and making the solution more feasible.
[0092] The data packet's characteristic information includes the packet's sub-flow data and the network protocol used. The sub-flow data may include the number of bytes in the packet, and the network protocol used may be Simple Service Discovery Protocol (SSDP), Transmission Control Protocol (TCP) Synchronize, Network Time Protocol (NTP), TCP Reset, User Datagram Protocol (UDP), etc., without specific limitations here.
[0093] Multiple feature information sets can be obtained within each time period, and each feature information set contains feature information from multiple data packets. For example, if the time period is 1 day, feature information sets 1, 2, and 3 are sampled on the first day, feature information sets 4, 5, and 6 are sampled on the second day, and feature information sets 7 and 8 are sampled on the third day.
[0094] S22: The server performs the following operations for each set of feature information:
[0095] S221: Based on a set of feature information, using the sub-traffic data of data packets from each network protocol, obtain the comprehensive traffic data of each network protocol within the time period corresponding to the set of feature information;
[0096] For example, the characteristic information set 1 contains characteristic information 1 of data packet 1, characteristic information 2 of data packet 2, characteristic information 3 of data packet 3, and characteristic information 4 of data packet 4. Data packet 1 uses network protocol 1 and its sub-traffic data is 64 bytes. Data packet 2 uses network protocol 1 and its sub-traffic data is 64 bytes. Data packet 3 uses network protocol 2 and its sub-traffic data is 128 bytes. Data packet 4 uses network protocol 1 and its sub-traffic data is 64 bytes. The comprehensive traffic data is used to characterize the traffic of data packets using the corresponding network protocol. The comprehensive traffic data of network protocol 1 is 192 bytes and can be represented as
[0192] . The comprehensive traffic data of network protocol 2 is 128 bytes and can be represented as
[0128] .
[0097] Furthermore, the overall traffic data can also include the number of data packets using network protocols. Taking the above network protocols as an example, if the number of data packets using network protocol 1 is 3 and the number of data packets using network protocol 2 is 1, then the overall traffic data of network protocol 1 can be represented as [3, 192] and the overall traffic data of network protocol 2 can be represented as [1, 128].
[0098] In this embodiment, five common low-speed DDoS mixed attack protocol types—SSDP, TCP SYN, NTP, TCP RST, and UDP—are used as examples, with the number of data packets and bytes included in the comprehensive traffic data as an example. For each network protocol, two types of protocol data are statistically analyzed: the number of data packets and the number of bytes. The following attack protocol type list 1 can be established:
[0099] Table 1
[0100] In practice, NetFlow traffic data is periodically collected from the network and categorized according to the protocols defined in the attack protocol type list. The protocol type in the NetFlow traffic data is determined based on information such as the transport layer protocol type, port number, and protocol flags. For example, SSDP is determined by NetFlow traffic port 1900 and the UDP protocol type, while TCP SYN is determined by the TCP protocol and data where the TCP_FLAGS flag is set to SYN.
[0101] After classifying the traffic data, the number of data packets for each protocol in the attack protocol type list is counted (x). p and number of bytes x b The different protocol data from a single sampling result are combined into a vector X: = (x1, x2, x3, x4, x5, x6, x7, x8, x9, x10)
[0102] Where x1 and x2 represent the number of data packets and bytes of protocol 1, x3 and x4 represent the number of data packets and bytes of protocol 2, and so on. The protocol type corresponding to the data in the vector of X, TCP SYN, can be obtained by querying the attack protocol type list 1 through protocol number 2.
[0103] Net Flow data was collected multiple times in the same time period, with 12 sampling times. After protocol classification and statistics, the 12 sampling results X1, X2, ..., X12 were obtained.
[0104] Optionally, after obtaining the comprehensive traffic data, for each network protocol, the comprehensive traffic data of the network protocol is adjusted based on the historical traffic data of the network protocol in each historical time period to obtain the adjusted comprehensive traffic data.
[0105] Specifically, for each network protocol, comprehensive traffic data within the current time period is obtained. Historical traffic data can also be used to smooth the comprehensive traffic data. The historical time period is the time period before the current time period. In this embodiment, the historical time period is the seven time periods before the current time period, i.e., the sliding window is eight. The specific number can be set according to the needs and is not specifically limited here.
[0106] Optionally, the average of multiple historical traffic data and aggregated traffic data of a network protocol can be used as the adjusted aggregated traffic data.
[0107] For example, the overall traffic data of network protocol 1 within time period 25 is [3, 256], where 3 represents the number of data packets and 256 represents the number of bytes. The historical time periods are time periods 18-24. The historical traffic data of time period 18 is [3, 256], the historical traffic data of time period 19 is [4, 256], the historical traffic data of time period 20 is [6, 448], the historical traffic data of time period 21 is [2, 128], the historical traffic data of time period 22 is [4, 320], the historical traffic data of time period 23 is [8, 256], and the historical traffic data of time period 24 is [2, 192]. In the overall traffic data after adjustment for time period 25, the number of data packets is the average number of data packets in time periods 18-25, and the number of bytes is the average number of bytes in time periods 18-25. Therefore, the overall traffic data after adjustment for time period 25 is [4, 264].
[0108] S222: Based on the differences between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, obtain the traffic difference degree corresponding to a set of feature information;
[0109] Specifically, for each network protocol, corresponding reference traffic data is predetermined. The reference traffic data is the reference value of the comprehensive traffic data. For example, network protocol 1 corresponds to reference traffic data 1 and comprehensive traffic data 1, network protocol 2 corresponds to reference traffic data 2 and comprehensive traffic data 2, and network protocol 3 corresponds to reference traffic data 3 and comprehensive traffic data 3. Then, based on the differences between reference traffic data 1 and comprehensive traffic data 1, the differences between reference traffic data 2 and comprehensive traffic data 2, and the differences between reference traffic data 3 and comprehensive traffic data 3, the traffic difference degree is obtained.
[0110] Optionally, the reference traffic data is obtained based on historical traffic data for each historical time period according to the corresponding network protocol.
[0111] Specifically, historical traffic data for a historical time period refers to traffic data within time periods prior to the current time period that has been detected as free of attacks; it can also be called normal traffic data. For example, for network protocol 1, if the current time period is time period 10, then the historical traffic data within the historical time period can be traffic data from time period 1, time period 2, and time period 3, without further specific limitations. This application primarily uses the example of reference traffic data obtained based on historical traffic data within 12 historical time periods for illustration. The reference traffic data can be any one of the 12 historical traffic data points, or it can be the average of the 12 historical traffic data points; no specific limitations are imposed here.
[0112] For example, for Net Flow traffic data X1, X2, ... X sampled 12 times... 12 The mean of the sampled results is calculated as follows: The mean of the j-th protocol data is
[0113] Optionally, step S222 can be implemented as steps 1-2:
[0114] Step 1: Based on the historical traffic datasets of each network protocol, obtain the traffic correlation characteristics between the network protocols;
[0115] Step 2: Based on the traffic correlation characteristics and the differences between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, obtain the traffic difference degree corresponding to a set of feature information.
[0116] Specifically, the historical traffic dataset for each network protocol contains corresponding historical traffic data. Taking a dataset containing 12 historical traffic data as an example, we extract the correlation features of each historical traffic data to obtain traffic correlation features, and then obtain the traffic difference degree based on the traffic correlation features. The traffic difference degree can characterize the difference between the reference traffic data and the comprehensive traffic data.
[0117] Optionally, step 1 can be implemented as follows:
[0118] Based on each historical traffic dataset, we obtain each historical traffic vector, and based on the correlation between each historical traffic vector, we obtain traffic correlation features.
[0119] Specifically, the elements in the historical traffic vector are the historical traffic data in the corresponding historical traffic dataset. The comprehensive traffic data was used as an example above. In fact, the historical traffic data and the comprehensive traffic data contain the same elements, namely the number of data packets and the number of bytes. For example, the historical traffic dataset contains historical traffic data 1-5. Historical traffic data 1 is [1, 64], historical traffic data 2 is [2, 128], historical traffic data 3 is [3, 192], historical traffic data 4 is [4, 256], and historical traffic data 5 is [5, 320]. Based on historical traffic dataset 1, the historical traffic vector 1 [1, 64, 2, 128, 3, 192, 4, 256, 5, 320] is obtained. By extracting the correlation features of each historical traffic vector, the traffic correlation features are obtained.
[0120] In this embodiment, the calculation of the covariance matrix of historical traffic vectors is used as an example to illustrate the traffic correlation feature. The number of historical traffic vectors is 12, that is, the number of samples is 12. Each historical traffic vector contains 10 elements, so the dimension of the covariance matrix C is 10×10. cij =Cov(x i ,x j Cov(x) i ,x j )=E[(x i -μ i (x) j -μ j )]
[0121] Where i, j = 1, 2, ..., k, k = 10, μ i For x i The mean, μ j For x j The mean, i.e., μ i For x i Reference traffic data.
[0122] When the current traffic is detected as normal traffic data, the covariance matrix and reference traffic data (normal traffic parameters) are continuously updated based on the latest collected normal traffic data, so that the normal traffic parameters can be updated as the traffic changes.
[0123] By continuously updating normal traffic parameters, changes in normal traffic can be tracked, enabling the detection of abnormal attacks to have adaptive adjustment capabilities. This can reduce false alarms caused by changes in normal traffic and improve the accuracy of identifying low-speed DDoS hybrid attacks.
[0124] Optionally, step 2 can be implemented as follows:
[0125] A comprehensive traffic vector is obtained based on each comprehensive traffic data, and a reference traffic vector is obtained based on each reference traffic data. Based on the difference vector between the comprehensive traffic vector and the reference traffic vector, as well as the traffic correlation features, a traffic difference degree corresponding to a feature information set is obtained.
[0126] The position of the comprehensive traffic data corresponding to the same network protocol in the comprehensive traffic vector is the same as the position of the reference traffic data in the reference traffic vector. The method of obtaining the comprehensive traffic vector and the reference traffic vector is the same as the method of obtaining the historical traffic vector. For example, comprehensive traffic data 1 is [1, 64], comprehensive traffic data 2 is [2, 128], comprehensive traffic data 3 is [3, 192], comprehensive traffic data 4 is [4, 256], and comprehensive traffic data 5 is [5, 320]. Based on comprehensive traffic data 1-5, comprehensive traffic vector 1 is obtained as [1, 64, 2, 128, 3, 192, 4, 256, 5, 320].
[0127] For the comprehensive flow vector X = (x1, x2, ... x... 10 ) TAssume the reference flow vector is: μ = (μ1, μ2, ... μ) 10 ) T
[0128] The covariance matrix is:
[0129] Calculate the Mahalanobis distance between the aggregated traffic data and the normal traffic data, and use the calculated Mahalanobis distance as the traffic difference degree:
[0130] Among them, D m Let X represent the Mahalanobis distance, X-μ represent the difference vector between the composite flow vector and the reference flow vector, and C represent the difference vector between the composite flow vector and the reference flow vector. -1 is the inverse of the covariance matrix.
[0131] Optionally, after adjusting the comprehensive traffic data, based on the differences between the reference traffic data of each network protocol and the corresponding adjusted comprehensive traffic data, a traffic difference degree corresponding to a set of feature information is obtained.
[0132] S23: The server obtains the attack detection results based on the traffic difference degree corresponding to each feature information set.
[0133] Specifically, a difference threshold can be set. If the difference of each traffic exceeds the difference threshold, it is determined that there is no attack. Alternatively, if the difference of each traffic is less than the difference threshold, it is determined that there is an attack. Or, if there is a traffic difference that is less than the difference threshold, it is determined that there is an attack. No specific limitation is made here.
[0134] In this embodiment, by sampling the feature information of data packets in the network, comprehensive traffic data for each network protocol within each time period is obtained. Based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, the traffic difference degree corresponding to each feature information set can be obtained, thereby obtaining the attack detection result. Based on the above method, by utilizing the traffic correlation under the same network protocol and comparing the difference between the comprehensive traffic data and the reference traffic data under the same network protocol, attacks can be identified more flexibly, improving the accuracy of attack detection. It is not limited to identifying specific attack protocol types and can identify attacks on multiple network protocols, thus having a wider range of applications. Furthermore, it does not require the use of the entire data packet; only the feature information of the data packet is sampled for detection, reducing the complexity of detection and system overhead.
[0135] Optionally, step S23 can be implemented as follows:
[0136] S231: Determine the mean of the difference based on the difference in each flow rate;
[0137] S232: Determine the ratio between each traffic difference degree and the mean difference degree, and if there is a first ratio greater than the first value among the obtained first ratios, determine that the attack detection result is that an attack exists.
[0138] Specifically, regarding the obtained traffic difference degree D m1 D m2 ,...D m12 Calculate the mean:
[0139] Then calculate D. m There exists any D m When the value is greater than the Mahalanobis distance threshold E (first ratio), an attack is confirmed.
[0140] Based on the above approach, when an attack occurs, the changes in various network protocols in the traffic are identified, and the changes in multi-dimensional data of common mixed attack protocols (which can be cross-layer protocol mixtures) in NetFlow traffic are fully detected. At the same time, the influence of traffic correlation between different network layer protocols and different data dimension measurement scales can be reduced, making the judgment of the degree of deviation between attack traffic and normal traffic more accurate.
[0141] Optionally, after confirming the presence of an attack, for each network protocol, the difference between the reference traffic data of the network protocol and the comprehensive traffic data of the network protocol in each time period is determined, and a second ratio between each difference and the reference difference is determined; based on each second ratio, the target ratio of the network protocol is determined; based on the target ratio of each network protocol, network protocols with a target ratio greater than the second value are selected, and attack protection measures are implemented according to the selected network protocols.
[0142] Specifically, when an attack is confirmed, the z-score (target ratio) of a network protocol is calculated over 12 time periods. The reference difference is the standard deviation of each reference traffic data point. For the 12 sampled reference traffic data points X1, X2, ..., X12, the standard deviation of the sampling results is calculated as: σ = (σ1, σ2, ..., σ12) j ,...σ 10 )
[0143] Wherein, the standard deviation of the j-th network protocol is That is, the reference difference for each network protocol is the standard deviation of the corresponding 12 historical traffic data.
[0144] For network protocol j, its z-score is z j =(x j -μ j ) / σ j x jFor comprehensive traffic data, μ j For reference traffic data, σ j The standard deviation, or reference deviation, is the value of the 12 historical flow data points. Calculate the comprehensive flow vector X = (x1, x2, ... x...). 10 The z-scores of all protocols in the given set are used to obtain Z = (z1, z2, ... z). 10 After calculating the z-score values of the 12 integrated flow vectors, Z1, Z2, ... Z are obtained. 12 For Z = (z1, z2, ... z) 10 ), calculate the mean z-score of protocol j. L is the second value, here we assume A suspected attack protocol has been identified.
[0145] in Obtain the attack protocol data numbers 1, 2, and 4. Based on the protocol numbers, search for the protocol names in the attack protocol type list 1. The search results show the attack protocols SSDP and TCP SYN used in this low-speed DDoS hybrid attack, and attack protection measures can be taken.
[0146] Based on the above approach, the problem of difficulty in identifying low-speed DDoS hybrid attacks is solved. In the detection of low-speed DDoS hybrid attacks, it can identify attack methods with arbitrary combinations of multiple protocols, without limiting the combination of a specific attack protocol type, and has the ability to automatically identify various attack protocols in hybrid attacks.
[0147] Figure 3 shows a schematic diagram of the overall process of the attack detection method implemented in this application, including:
[0148] S301: Sample the feature information set within 12 time periods according to the preset time period;
[0149] S302: Calculate the comprehensive flow vector for each feature information set;
[0150] S303: Calculate the traffic difference degree of each feature information set based on the reference traffic vector, comprehensive traffic vector and traffic correlation features of each feature information set respectively;
[0151] S304: Determine the mean of the difference based on the difference in each flow rate;
[0152] S305: Determine the ratio between each traffic difference degree and the average difference degree, and if there is a first ratio greater than the first value among the obtained first ratios, determine that an attack exists;
[0153] S306: Calculate the target ratio for each network protocol, filter out the network protocols whose target ratio is greater than the second value, and implement attack protection measures based on the filtered network protocols.
[0154] In practical implementation, the attack detection method in this application can be executed by the following modules:
[0155] Data acquisition and classification module: Used to collect Net Flow traffic data from the gateway, classify it according to different network protocols in the traffic, and statistically analyze multi-dimensional data for each protocol, such as the number of data packets and the size of data packets.
[0156] The data preprocessing module smooths the collected NetFlow traffic using a sliding window approach, smoothing several consecutive NetFlow traffic data points to reduce the impact of outliers. The window size can be determined based on the sampling frequency and the tolerable error. Other outlier handling methods can also be used.
[0157] Parameter Calculation Module: Used to calculate the covariance matrix parameters of each network protocol in NetFlow traffic data during normal traffic data. It uses preprocessed continuous traffic data as sample points to calculate the covariance matrix parameters between protocols in the traffic data and continuously updates the parameters.
[0158] Mahalanobis distance calculation module: Used to calculate the Mahalanobis distance between the latest traffic data and the current normal traffic sample. It calculates the Mahalanobis distance using the latest preprocessed traffic data and the parameters of the latest normal traffic sample, identifying points with abnormally large results.
[0159] Attack Protocol Analysis Module: Used to analyze specific attack protocols in abnormal traffic. When the Mahalanobis distance of multiple consecutive sampling points increases abnormally, the Z-score value of each protocol in the Net Flow data is calculated. When the Z-score values of multiple protocols increase abnormally, it is determined that a DDoS hybrid attack exists, and these protocols are identified as the attack protocols used in this hybrid attack.
[0160] Based on the same inventive concept, this application also provides an attack detection device. As shown in Figure 4, which is a schematic diagram of the attack detection device 400, it may include:
[0161] The sampling unit 401 is used to sample the feature information of data packets in the network according to a preset time period to obtain a set of feature information sampled in each time period. The feature information includes: sub-traffic data of the corresponding data packet and the network protocol used.
[0162] Statistical unit 402 is used to perform the following operations for each set of feature information:
[0163] Based on the sub-traffic data of data packets using various network protocols in a feature information set, the comprehensive traffic data of each network protocol within the time period corresponding to the feature information set is obtained. The comprehensive traffic data is used to characterize the traffic situation of data packets using the corresponding network protocol.
[0164] Based on the differences between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, a traffic difference degree corresponding to a set of feature information is obtained.
[0165] The detection unit 403 is used to obtain attack detection results based on the traffic difference degree corresponding to each feature information set.
[0166] Optionally, the reference traffic data is obtained based on historical traffic data for each historical time period according to the corresponding network protocol;
[0167] The statistical unit 402 is specifically used for:
[0168] Based on the historical traffic datasets of each network protocol, the traffic correlation characteristics between the network protocols are obtained.
[0169] Based on traffic correlation characteristics and the differences between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, a traffic difference degree corresponding to a set of feature information is obtained.
[0170] Optionally, the statistical unit 402 is specifically used for:
[0171] Based on each historical traffic dataset, obtain each historical traffic vector, where the elements in the historical traffic vector are the historical traffic data from the corresponding historical traffic dataset;
[0172] Traffic correlation features are obtained based on the correlation between historical traffic vectors.
[0173] Optionally, the statistical unit 402 is specifically used for:
[0174] A comprehensive traffic vector is obtained based on each comprehensive traffic data, and a reference traffic vector is obtained based on each reference traffic data. The position of the comprehensive traffic data corresponding to the same network protocol in the comprehensive traffic vector is the same as the position of the reference traffic data in the reference traffic vector.
[0175] Based on the difference vector between the comprehensive flow vector and the reference flow vector, as well as the flow correlation features, a flow difference degree corresponding to a set of feature information is obtained.
[0176] Optionally, the device also includes an adjustment unit 404 for:
[0177] For each network protocol, the overall traffic data of the network protocol is adjusted based on the historical traffic data of the network protocol in each historical time period to obtain the adjusted overall traffic data.
[0178] Optionally, the statistical unit 402 is specifically used for:
[0179] Based on the differences between the reference traffic data of each network protocol and the corresponding adjusted comprehensive traffic data, a traffic difference degree corresponding to a set of feature information is obtained.
[0180] Optionally, the detection unit 403 is specifically used for:
[0181] Determine the mean of the difference based on the differences in each flow rate;
[0182] Determine the ratio between each traffic difference degree and the mean difference degree, and if there is a first ratio greater than the first value among the obtained first ratios, determine that an attack has been detected.
[0183] Optionally, the device also includes a screening unit 405 for:
[0184] For each network protocol, a reference traffic data for the network protocol is determined, and the difference between the reference traffic data of the network protocol and the comprehensive traffic data of the network protocol in each time period is determined. A second ratio between each difference and the reference difference is determined. Based on each second ratio, a target ratio for the network protocol is determined.
[0185] Based on the target ratio of each network protocol, network protocols with a target ratio greater than the second value are selected, and attack protection measures are implemented according to the selected network protocols.
[0186] For ease of description, the above sections are divided into modules (or units) according to their functions and described separately. Of course, in implementing this application, the functions of each module (or unit) can be implemented in one or more software or hardware components.
[0187] In this application embodiment, the terms "module" or "unit" refer to a computer program or part of a computer program that has a predetermined function and works with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can be part of an overall module or unit that includes the functionality of that module or unit.
[0188] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."
[0189] Based on the same inventive concept as the above-described method embodiments, this application also provides an electronic device. In one embodiment, the electronic device may be a server, as shown in FIG1. In this embodiment, the structure of the electronic device may be as shown in FIG5, including a memory 501, a communication module 503, and one or more processors 502.
[0190] The memory 501 is used to store computer programs executed by the processor 502. The memory 501 may mainly include a program storage area and a data storage area. The program storage area may store the operating system and programs required to run instant messaging functions, etc.; the data storage area may store various instant messaging information and operation instruction sets, etc.
[0191] Memory 501 may be volatile memory, such as random-access memory (RAM); memory 501 may also be non-volatile memory, such as read-only memory, flash memory, hard disk drive (HDD), or solid-state drive (SSD); or memory 501 may be any other medium capable of carrying or storing a desired computer program having the form of instructions or data structures and accessible by a computer, but is not limited thereto. Memory 501 may be a combination of the above-described memories.
[0192] Processor 502 may include one or more central processing units (CPUs) or digital processing units, etc. Processor 502 is used to implement the above-mentioned attack detection method when calling computer programs stored in memory 501.
[0193] The communication module 503 is used to communicate with terminal devices and other servers.
[0194] This application embodiment does not limit the specific connection medium between the memory 501, communication module 503, and processor 502. In this application embodiment, the memory 501 and processor 502 are connected via a bus 504 in Figure 5. The bus 504 is depicted as a thick line in Figure 5. The connection methods between other components are only illustrative and are not intended to be limiting. The bus 504 can be divided into address bus, data bus, control bus, etc. For ease of description, only one thick line is used to describe it in Figure 5, but it does not indicate that there is only one bus or one type of bus.
[0195] The memory 501 stores a computer storage medium containing computer-executable instructions for implementing the attack detection method of this application embodiment. The processor 502 executes the attack detection method described above, as shown in FIG2.
[0196] In another embodiment, the electronic device can also be other electronic devices, such as the terminal device shown in FIG1. In this embodiment, the structure of the electronic device can be as shown in FIG6, including: a communication component 610, a memory 620, a display unit 630, a camera 640, a sensor 650, an audio circuit 660, a Bluetooth module 670, a processor 680, and other components.
[0197] The communication component 610 is used to communicate with the server. In some embodiments, it may include a Circuit-Wireless Fidelity (WiFi) module, which is a short-range wireless transmission technology. Electronic devices can use the WiFi module to help users send and receive information.
[0198] The memory 620 can be used to store software programs and data. The processor 680 executes various functions of the terminal device and data processing by running the software programs or data stored in the memory 620. The memory 620 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. The memory 620 stores an operating system that enables the terminal device to run. In this application, the memory 620 can store the operating system and various application programs, and may also store computer programs that execute the attack detection method of the embodiments of this application.
[0199] The display unit 630 can also be used to display information input by the user or information provided to the user, as well as various menus of the terminal device, forming a graphical user interface (GUI). Specifically, the display unit 630 may include a display screen 632 disposed on the front of the terminal device. The display screen 632 may be configured as a liquid crystal display, a light-emitting diode, or the like. The display unit 630 can be used to display the attack detection user interface, etc., as described in the embodiments of this application.
[0200] The display unit 630 can also be used to receive input digital or character information and generate signal inputs related to user settings and function control of the terminal device. Specifically, the display unit 630 may include a touch screen 631 disposed on the front of the terminal device, which can collect touch operations of the user on or near it, such as clicking a button, dragging a scroll box, etc.
[0201] The touchscreen 631 can be placed on top of the display screen 632, or the touchscreen 631 and the display screen 632 can be integrated to realize the input and output functions of the terminal device. After integration, it can be referred to as a touch display screen. In this application, the display unit 630 can display the application program and the corresponding operation steps.
[0202] Camera 640 can be used to capture still images, which users can then post comments on via the application. There can be one or multiple cameras 640. An object is projected onto a photosensitive element through a lens, generating an optical image. This photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then transmitted to a processor 680 to be converted into a digital image signal.
[0203] The terminal device may also include at least one sensor 650, such as an accelerometer 651, a proximity sensor 652, a fingerprint sensor 653, and a temperature sensor 654. The terminal device may also be equipped with other sensors such as a gyroscope, barometer, hygrometer, thermometer, infrared sensor, light sensor, and motion sensor.
[0204] Audio circuit 660, speaker 661, and microphone 662 provide an audio interface between the user and the terminal device. Audio circuit 660 converts received audio data into electrical signals, which are then transmitted to speaker 661, where they are converted into sound signals for output. The terminal device can also be equipped with volume buttons for adjusting the volume of the sound signal. On the other hand, microphone 662 converts collected sound signals into electrical signals, which are received by audio circuit 660, converted into audio data, and then output to communication component 610 for transmission to, for example, another terminal device, or to memory 620 for further processing.
[0205] The Bluetooth module 670 is used to interact with other Bluetooth devices that also have a Bluetooth module via the Bluetooth protocol. For example, a terminal device can establish a Bluetooth connection with a wearable electronic device (such as a smartwatch) that also has a Bluetooth module through the Bluetooth module 670, thereby exchanging data.
[0206] The processor 680 is the control center of the terminal device, connecting various parts of the terminal through various interfaces and lines. It executes software programs stored in the memory 620 and calls data stored in the memory 620 to perform various functions and process data. In some embodiments, the processor 680 may include one or more processing units; the processor 680 may also integrate an application processor and a baseband processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the baseband processor mainly handles wireless communication. It is understood that the baseband processor may not be integrated into the processor 680. In this application, the processor 680 can run the operating system, applications, user interface display and touch response, as well as the attack detection method of this application embodiment. Furthermore, the processor 680 is coupled to the display unit 630.
[0207] In some possible implementations, various aspects of the attack detection method provided in this application may also be implemented in the form of a program product, which includes a computer program. When the program product is run on an electronic device, the computer program is used to cause the electronic device to perform the steps in the attack detection method according to various exemplary embodiments of this application described above. For example, the electronic device may perform the steps shown in FIG2.
[0208] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0209] The program product of the embodiments of this application may employ a portable compact disc read-only memory (CD-ROM) and include a computer program, and may run on an electronic device. However, the program product of this application is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program that may be used by or in conjunction with a command execution system, apparatus, or device.
[0210] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying a readable computer program. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with a command execution system, apparatus, or device.
[0211] Computer programs contained on readable media may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0212] Computer programs for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The computer program can execute entirely on the user's electronic device, partially on the user's device, as a standalone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving remote electronic devices, the remote electronic device can be connected to the user's electronic device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external electronic device (e.g., via the Internet using an Internet service provider).
[0213] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.
[0214] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.
[0215] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing a computer-usable computer program.
[0216] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.
[0217] These computer program commands may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the commands stored in the computer-readable storage medium produce an article of manufacture including command means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0218] These computer program commands may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the commands executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0219] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0220] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. An attack detection method characterized by, The method includes: According to a preset time period, the feature information of data packets in the network is sampled to obtain a set of feature information sampled in each time period. The feature information includes: sub-traffic data of the corresponding data packet and the network protocol used. For each set of feature information, perform the following operations: Based on a set of feature information, sub-traffic data of data packets using various network protocols are used to obtain comprehensive traffic data of each network protocol within the time period corresponding to the set of feature information. The comprehensive traffic data is used to characterize the traffic situation of data packets using the corresponding network protocol. Based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, the traffic difference degree corresponding to the feature information set is obtained; the reference traffic data is obtained based on the historical traffic data of the corresponding network protocol in each historical time period. Attack detection results are obtained based on the traffic difference degree corresponding to each feature information set; The process of obtaining the traffic difference degree corresponding to the feature information set based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data includes: Based on the historical traffic datasets of each network protocol, traffic correlation features between the network protocols are obtained; a comprehensive traffic vector is obtained based on each comprehensive traffic data, and a reference traffic vector is obtained based on each reference traffic data; based on the difference vector between the comprehensive traffic vector and the reference traffic vector, and the traffic correlation features, the traffic difference degree corresponding to the feature information set is obtained; wherein, the position of the comprehensive traffic data corresponding to the same network protocol in the comprehensive traffic vector is the same as the position of the reference traffic data in the reference traffic vector.
2. The method of claim 1, wherein, The step of obtaining traffic correlation characteristics among the network protocols based on their respective historical traffic datasets includes: Each historical traffic vector is obtained based on each historical traffic dataset, and the elements in the historical traffic vector are the historical traffic data in the corresponding historical traffic dataset. Based on the correlation between the historical traffic vectors, the traffic correlation features are obtained.
3. The method of claim 1, wherein, Before obtaining the traffic difference degree corresponding to the feature information set based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, the method further includes: For each network protocol, the overall traffic data of the network protocol is adjusted based on the historical traffic data of the network protocol in each historical time period to obtain the adjusted overall traffic data.
4. The method of claim 3, wherein, The step of obtaining the traffic difference degree corresponding to the feature information set based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data includes: Based on the difference between the reference traffic data of each network protocol and the corresponding adjusted comprehensive traffic data, the traffic difference degree corresponding to the feature information set is obtained.
5. The method according to any one of claims 1 to 4, characterized in that, The attack detection result is obtained based on the traffic difference degree corresponding to each feature information set, including: Determine the mean of the difference based on the differences in each flow rate; The ratio between each traffic difference degree and the mean difference degree is determined respectively. If there is a first ratio greater than the first value among the obtained first ratios, the attack detection result is determined to be that an attack exists.
6. The method of claim 5, wherein, After determining that the attack detection result indicates the existence of an attack, the method further includes: For each network protocol, a reference traffic data for that network protocol is determined, and the difference between the reference traffic data for that network protocol and the comprehensive traffic data for that network protocol in each time period is determined. A second ratio between each difference and the reference difference is then determined. Based on each second ratio, a target ratio for that network protocol is determined. Based on the target ratio of each network protocol, network protocols with a target ratio greater than the second value are selected, and attack protection measures are implemented according to the selected network protocols.
7. An attack detection apparatus characterized by comprising: include: The sampling unit is used to sample the feature information of data packets in the network according to a preset time period to obtain a set of feature information sampled in each time period. The feature information includes: sub-traffic data of the corresponding data packet and the network protocol used. The statistical unit is used to perform the following operations for each set of feature information: Based on a set of feature information, sub-traffic data of data packets using various network protocols are used to obtain comprehensive traffic data of each network protocol within the time period corresponding to the set of feature information. The comprehensive traffic data is used to characterize the traffic situation of data packets using the corresponding network protocol. Based on the difference between the reference traffic data of each network protocol and the corresponding comprehensive traffic data, the traffic difference degree corresponding to the feature information set is obtained; the reference traffic data is obtained based on the historical traffic data of the corresponding network protocol in each historical time period. The detection unit is used to obtain attack detection results based on the traffic difference degree corresponding to each feature information set; The statistical unit is specifically used for: Based on the historical traffic datasets of each network protocol, the traffic correlation characteristics among the network protocols are obtained. A comprehensive traffic vector is obtained based on each comprehensive traffic data, and a reference traffic vector is obtained based on each reference traffic data. Based on the difference vector between the comprehensive traffic vector and the reference traffic vector, and the traffic correlation features, the traffic difference degree corresponding to the feature information set is obtained; wherein, the position of the comprehensive traffic data corresponding to the same network protocol in the comprehensive traffic vector is the same as the position of the reference traffic data in the reference traffic vector.
8. An electronic device, comprising: It includes a processor and a memory, wherein the memory stores a computer program that, when executed by the processor, causes the processor to perform the steps of any one of the methods described in claims 1 to 6.